MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d58e5b80d49922818707768a15c5053486eb8adfbef242264d08f7a87e1bfdf6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: d58e5b80d49922818707768a15c5053486eb8adfbef242264d08f7a87e1bfdf6
SHA3-384 hash: 17ac0f5210312b8729c39e8ab7662d82cdd98fb8a38a19dc566f13006230caf26b28240ad332f26b980d1917e61da0e4
SHA1 hash: de5419a3114668909b9778b93f667ce52617a02e
MD5 hash: a695a523bca2d73ba45006a1f88cef09
humanhash: jupiter-nitrogen-bacon-lactose
File name:r.sh
Download: download sample
Signature Mirai
File size:983 bytes
First seen:2025-02-04 17:11:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:lD5SRg8H0aKLK6AJXVNIh5VAgTX4sDXnDXkhFIX17EOF8bsXSoV/XQsbXFieR2:lD5DK/NIfVNMF2wTkmNl
TLSH T1B81198C476630A764D895CCFB92A699C316EE0C70D175FEC3EFCA06DA2ECC60E000104
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
ftp://3.188.82.218:21/ppcn/an/an/a
ftp://3.188.82.218:21/arm7n/an/an/a
ftp://3.188.83.11:21/arm6n/an/an/a
ftp://3.188.83.11:21/arm5n/an/an/a
ftp://3.188.83.11:21/arm4n/an/an/a
ftp://3.188.83.11:21/armn/an/an/a
ftp://3.188.83.11:21/mipsn/an/an/a
ftp://3.188.83.11:21/mpsln/an/an/a
ftp://3.188.83.11:21/sh4n/an/an/a
ftp://3.188.83.11:21/x86n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
90
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox evasive
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-02-04 17:12:13 UTC
File Type:
Text (Python)
AV detection:
7 of 24 (29.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d58e5b80d49922818707768a15c5053486eb8adfbef242264d08f7a87e1bfdf6

(this sample)

  
Delivery method
Distributed via web download

Comments