MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d002c7bdc30f530c5861afeb56d6ad69bc33cddafda93d1beca8700c68cde488. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d002c7bdc30f530c5861afeb56d6ad69bc33cddafda93d1beca8700c68cde488
SHA3-384 hash: 27f2d4d90983f3d9bf46578d204256718b8d03ba58f24601ea1ed5d316c4d364584f7c0c89b54fc802564d1d71cf2188
SHA1 hash: 8c1e3910d6b4b08adebe99c3a0ea4fa83d9571c7
MD5 hash: 46018e1fe4256c21d28a97170532fc01
humanhash: eight-echo-vegan-washington
File name:wget.sh
Download: download sample
Signature Mirai
File size:790 bytes
First seen:2025-02-24 18:36:44 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:YhX/NNIl5r0LK5gOFbeM5ONtjKaGZetQ2xVv:0FNI7mKCIq55+ItQ2fv
TLSH T1EA0148EF2BE112864D48CE0C786F0F445646EEC7E6740B1A5885B43E91ED708B471F66
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://209.141.40.81/bins/arm33a2ea0efb7de27da9096b23328fdb832cc22a9a02e36d35c3dfebd1e1b98182 Miraielf mirai opendir
http://209.141.40.81/bins/arm5065e0aed94d29627fe5201a1f18ef334484463d7f2f612ac7fcc14090ca8a6a1 Miraielf mirai opendir
http://209.141.40.81/bins/arm6f370a8f6eca136db1bdad535722d407856cba62629dc91ba9b8899d27c28f424 Miraielf mirai opendir
http://209.141.40.81/bins/arm75e4b02509600ea4461bac895713bb9bdb57863d37ad8ec9f034efeadbf528ea9 Miraielf mirai opendir
http://209.141.40.81/bins/m68k0fd852a9a3d77e4b990a8a7cf2633b1a80b75411566b1f77308854bfe0b6d9b3 Miraielf mirai opendir
http://209.141.40.81/bins/mipsbbe3caa99dcd6d17f332752288ca3e9319cf58e8fa89b29af5f965435545f240 Miraielf mirai opendir
http://209.141.40.81/bins/mpsl3e16690b1d55793a7a763029f9eae90b4a5ba81f8a3ea63f1b8148769bea3669 Miraielf mirai opendir
http://209.141.40.81/bins/star.ppc67611e40586aa50ef2d45576803ad6f73ac0439776668a78f1071a0fac84f976 Miraielf mirai opendir
http://209.141.40.81/bins/sh4cf4abb7399914579e78de3086d550b2fbbcb7d06575e6ab260ec66558d9ade74 Miraielf mirai opendir
http://209.141.40.81/bins/spc9f9c8d7cf5cc76f5496da68b53c3166d5471236f02ed03721e77a0a1e8c10c34 Miraielf mirai opendir
http://209.141.40.81/bins/x86721fb5f5845f8a728f4f9ee050ea4c6cc3723f558bbe839b9253753015d8a867 Miraielf mirai opendir
http://209.141.40.81/bins/x86_644e4d54d0303d1f8eddd79df29e645c16faab4f7b2a4c720bd63c869075177f33 Miraielf mirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader mirai agent overt
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive lolbin mirai remote
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-02-24 20:08:29 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d002c7bdc30f530c5861afeb56d6ad69bc33cddafda93d1beca8700c68cde488

(this sample)

  
Delivery method
Distributed via web download

Comments