MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cf9382f6d6cf5296bf1fbda49a772b9924dd932d77b4ed974e3c2e8bc493c789. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: cf9382f6d6cf5296bf1fbda49a772b9924dd932d77b4ed974e3c2e8bc493c789
SHA3-384 hash: bd5220b0aa659de40c58f35498ec8c16b6e1e2f2bc417e76032a152a84c4e5292fb9b7a24b4af823c6f2a53d665cbed4
SHA1 hash: 8e1df842174015871c037f95eec059e680e6b167
MD5 hash: 5c3e27fb3101c29817a6c942df01af14
humanhash: william-undress-zebra-solar
File name:cn
Download: download sample
Signature Mirai
File size:1'060 bytes
First seen:2025-12-21 15:14:10 UTC
Last seen:2025-12-21 17:34:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:k74Va7M5OVa7kVa7rVa7VIVa77Va7KVa7PVa7jVa76Va7boVl:ksVawMVaIVafVauVanVauVa7VaXVaWVx
TLSH T17611425E15259D90849CD43A3793C108B8844BEE1D7B5AA81E9702BE24E09CE733CE15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarmd0fa73dfe2c6b4d49c31db63d4424506b62fae9d95a32134d44e4b76cf3745cd Miraielf mirai ua-wget
http://130.12.180.64/splarm50b8b4be3fec08aaec58830ce72504f9b393eab3a8190dcd14a7886aef07e28a9 Miraielf mirai ua-wget
http://130.12.180.64/splarm6bc8e090af02223041507c811baf2d718101317807f87bf13fc12bc99dc6e460f Miraielf mirai ua-wget
http://130.12.180.64/splarm7ebd1877912ec628403d89fec591218730dfb454d5616e877ed2a70d12edbeedd Miraielf mirai ua-wget
http://130.12.180.64/splm68k3dd45858083a326da734a9697b80642764b3fd8d5327ed4a9bd473f4acb756b4 Miraielf mirai ua-wget
http://130.12.180.64/splmips2928a4694f399990791e7d0c00cb21c7fe852654df493d541097b7ce85815ec5 Miraielf mirai ua-wget
http://130.12.180.64/splmpsl3cd8a62933ca2ee92f4a556c9d59ae1679070eec6343b38d6ef6f75cf5190ced Miraielf mirai ua-wget
http://130.12.180.64/splppc80a87c2b18d33755c77fa96134821885941bcf94a04548edebe5e0cd1a2edb73 Miraielf mirai ua-wget
http://130.12.180.64/splsh413f61233c15e5b506231b6ff9478ff3e355466bd82fa5527f2c7f2b4e33f153a Miraielf mirai ua-wget
http://130.12.180.64/splspc4a60b417b0a3a559a666787305d91514c5e88d00158943ed988867db3a53cc27 Miraielf mirai ua-wget
http://130.12.180.64/splx8661a776ec0d0312cc0f02bc82198fd7abc5633f3e96d9ed4c31acae20e6790239 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:31:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c67b57dc-1a00-0000-24f3-6554bc0d0000 pid=3516 /usr/bin/sudo guuid=e49487de-1a00-0000-24f3-6554c20d0000 pid=3522 /tmp/sample.bin guuid=c67b57dc-1a00-0000-24f3-6554bc0d0000 pid=3516->guuid=e49487de-1a00-0000-24f3-6554c20d0000 pid=3522 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:34:17 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cf9382f6d6cf5296bf1fbda49a772b9924dd932d77b4ed974e3c2e8bc493c789

(this sample)

  
Delivery method
Distributed via web download

Comments