MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d50233080ff5c17b616e685d46b1c868cafdfff45395e5952d8156f8a75abe31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d50233080ff5c17b616e685d46b1c868cafdfff45395e5952d8156f8a75abe31
SHA3-384 hash: f6445da8c7c8e2f529d1925dbcc618acf11c908fd3ce8c1187604dc86309b5cbe4637802a1c0df8d97977d32daa93a96
SHA1 hash: 2b107e30b109f3fb7fbf69e5ea4ea1462d0cb351
MD5 hash: 10ae98d96d1cb9c67480ce3f543611b9
humanhash: paris-july-mike-kentucky
File name:yarn
Download: download sample
Signature Mirai
File size:2'136 bytes
First seen:2025-06-05 09:58:33 UTC
Last seen:2025-06-05 18:54:58 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vgUdOHQL6qlJWZ8Wwpi9jgziAZeXk32TP+ACTcsVuft:vgeOwL6wWOWAi9MGke032yAKcquF
TLSH T1B0417ECE12531ABDACEA9F2E71F9C04571A4E0A636C0AF05D9D838B7688FE553C50B46
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://152.89.170.15/main_arm22f667e0a671977aabb06dbddf5098ccf968dedfeead6de499a411c0a7cc2bcd Miraielf mirai ua-wget
http://152.89.170.15/main_arm50bb7ae61f82553675cb1f2e8de6baf5cb6e23b9167e745849aecbb18ba7792d1 Miraielf mirai ua-wget
http://152.89.170.15/main_arm609345f643f2aa77df4aa0b80fc7e20aacd9e0f11019346eeeacbed6c44de66ba Miraielf mirai ua-wget
http://152.89.170.15/main_arm7b7b564b80bb2784c76155230e6c6b3b135255f6939829dd115054539e7ff1135 Miraielf mirai ua-wget
http://152.89.170.15/main_m68k7756f534414530f998fbee175285442c66671ef908d04672d98fdcba59fdb6bf Miraielf mirai ua-wget
http://152.89.170.15/main_mipsd3e83cab074a13642ea549bf1f043bc9401a27372d910151aa7605e0276b26d9 Miraielf mirai ua-wget
http://152.89.170.15/main_mpsl00624bb777664e814fafa82af75a69494724c22482fcd79eb4cd9c0e28a49ed8 Miraielf mirai ua-wget
http://152.89.170.15/main_ppc612a1af3276c3aff19435f1788f0c1944b1d88a1ab9b9fbf7a69a55751c0f88c Miraielf mirai ua-wget
http://152.89.170.15/main_sh4d6f74c0a5f3fb8e78729fe2dc3bb4c329f931cbf21f14112d81c4008ecdc407a Miraielf mirai ua-wget
http://152.89.170.15/main_spc258227034178fafa463fde3c438c182bf6ac8681baa26d07bfd7767f7fe07c24 Miraielf mirai ua-wget
http://152.89.170.15/main_x861bfeada59790096161306f969c3b631b2f4098b4d0269a97c4e9518618d6eac2 Miraielf mirai ua-wget
http://152.89.170.15/main_x86_6440eb38c996d59b03de13e8df4585f6d994f1d085ed48669b4f97a6cf31d6e562 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
trojandownloader trojware agent
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-06-05 09:25:29 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
net.drillrp.com
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d50233080ff5c17b616e685d46b1c868cafdfff45395e5952d8156f8a75abe31

(this sample)

Comments