MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c9cd39d22617cb2ce272ae4ec3af1391d9dbfe01a6df192844eea2ec8872623c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c9cd39d22617cb2ce272ae4ec3af1391d9dbfe01a6df192844eea2ec8872623c
SHA3-384 hash: 16c076b65864abe8f6e453f76c94354ab77a3aef4e1898ce8338826af1871e528eb01ff6218d7307eb45666f3a5440f0
SHA1 hash: e14f47965c10e02a736ac7e25063dca1a0ec6bcd
MD5 hash: e5f73b088c998e1d118d450cd779b1b2
humanhash: echo-north-quebec-equal
File name:w.sh
Download: download sample
Signature Mirai
File size:1'065 bytes
First seen:2025-05-11 18:02:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:0PLU0USNIVUPU+UMgU87xU2lUbU6U0gUjpAfHR:0zU0UFUPU+UMgU87xU2lUlU7Uwx
TLSH T1E9118ECF2218F280DCDD0E903497480B2314AED4A8559F9CDA885FBBD3CDA197899E29
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.146.122/bins/kwari.armcce4688d4d9c29ff50b45c38f5bd8cf3ff66fa09f103b39f3acb621191bb9e96 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.arm5097973533a01a94b6c3ade1375ffd4aee0e04e864cd787806ba065b5a0c255e1 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.arm6c2ac5831e856f594c5dac316eca8aa4ba24da5f24540abf52d6e1f8b13624e39 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.m68kef906fa4a74b74191f010b71ddcebb300d1cda75f27d9813118a76a4d02f7ebe Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.mipsf61f893193aa92ec80060d7767cc59d710d361d03812016fe70cf48188817745 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.mpsld41d5685a57d498900a664ba40fde9cbfaec97a836bd3585ececfc93772784c5 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.ppca036cb6c15b94d3cded0a8f6d62b12ed9749ae0b1c33b320ba6a832095a8700d Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.sh45d5ed44746beb2e63e24442d48fb9edf5e29e323738d3b989c73120198b5e695 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.spca48603342f476d289d98f9be175aa2f7ff7456fb013a473d97d1d900677164cc Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.x866c2501e799bb226173c61611d1fe3ae9b66121dad047227c1aabcd552ce23460 Miraielf mirai ua-wget
http://160.187.146.122/bins/kwari.x86_64n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
144
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
downloader trojan overt
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-05-11 18:03:17 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c9cd39d22617cb2ce272ae4ec3af1391d9dbfe01a6df192844eea2ec8872623c

(this sample)

  
Delivery method
Distributed via web download

Comments