MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d66b9558caa4bbab31fb9de655c289ffa98e26e78dbb3de1932d5fbeff3b7906. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: d66b9558caa4bbab31fb9de655c289ffa98e26e78dbb3de1932d5fbeff3b7906
SHA3-384 hash: 2027806942fc2ee7086344df34ba8b09f0a19fe8668ba020e71208ab70fd1b4ab9bce437a228d16976ff71709a7ea3f1
SHA1 hash: ddbf7ccca855d8f1b23f319323027548fc6e0d32
MD5 hash: 72656c336adf5736194e991a362d4dc5
humanhash: autumn-friend-aspen-two
File name:f
Download: download sample
Signature Mirai
File size:994 bytes
First seen:2026-01-05 01:06:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:HO7NvVa7AfVa7hVa7SVa7vRpVa7qVa7gSVa7bSVa7aVa73vVa7nJVT:u5VaIVatVa+VabvVauVaDVaqVaWVaLve
TLSH T18411215E1201ADA4848DD47A37D2C30CB8C04FCD297B16555DA341B954E16CE737892A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/zerarmcd842724860f779c36af17c7efd82bd1d30072eb82fe5928709a0d45baa70f48 Gafgytelf gafgyt mirai ua-wget
http://130.12.180.64/zerarm52d8d693bcabad58aacc93cc761358fecb32dedc0cae414bae9e0e391dadf063e Gafgytelf gafgyt mirai ua-wget
http://130.12.180.64/zerarm6b93e2579ab4519af1030d2b4a9c944ab34a0fb98e9a6b437f642a491893b983f Miraielf mirai ua-wget
http://130.12.180.64/zerarm7834a6fa65bb91a3dda20b9ab8d0b3dca1ad48e4a1fdfc0f87d0daffdd1087186 Miraielf mirai ua-wget
http://130.12.180.64/zerm68kef7626fd23876e0f1fb0518187a1c9e6603b1e9f02223cea583ad5e3b1ae8801 Miraielf mirai ua-wget
http://130.12.180.64/zermips830347c0f5b17d94408f3193920a0a18bdd3529ec1209c2da0aa1f075e05c097 Miraielf mirai ua-wget
http://130.12.180.64/zermpslde71729181d88344ce47a4ddb700831459e29e12ed51442250bf896eda9f9f87 Miraielf mirai ua-wget
http://130.12.180.64/zerppc13b44dacddb434887b2051cde0e92042b72e79e15d90f139b2311d503700bcf1 Miraielf mirai ua-wget
http://130.12.180.64/zersh45ebe294e0803b4ffeaf16ea0190b77f984c62f0dff192df7af385f00d63b02fc Miraielf mirai ua-wget
http://130.12.180.64/zerspc3868d2a747e0d7081bbcebdeb01625acbedc34e92e7de6171d1a4515c7b721e5 Miraielf mirai ua-wget
http://130.12.180.64/zerx865a86309059f0c8bb1e9e6ae80e0c9ce33eebdcaaf40be2751c055192250dae0e Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
87
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-05T06:43:00Z UTC
Last seen:
2026-01-05T18:42:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=56c30e3a-4e00-0000-e21c-f405ea030000 pid=1002 /usr/bin/sudo guuid=fe08103d-4e00-0000-e21c-f405eb030000 pid=1003 /tmp/sample.bin guuid=56c30e3a-4e00-0000-e21c-f405ea030000 pid=1002->guuid=fe08103d-4e00-0000-e21c-f405eb030000 pid=1003 execve
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-05 01:10:10 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d66b9558caa4bbab31fb9de655c289ffa98e26e78dbb3de1932d5fbeff3b7906

(this sample)

  
Delivery method
Distributed via web download

Comments