MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd87268f4a26a7e79d563499b24a54d36fed4d97a99e7dd307ff73691c328cf5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: dd87268f4a26a7e79d563499b24a54d36fed4d97a99e7dd307ff73691c328cf5
SHA3-384 hash: 94148a03c840e513d40b50d16a0d8d4a59f55df2c42be072e79ebc94b4022b2abb5780f68e8581ae2266a5478de7eb96
SHA1 hash: 629414c2581fb703036aaffd877a9ef831f261f7
MD5 hash: 63aa96941bbf04a8bf9bcec3e9295e67
humanhash: three-bluebird-september-quebec
File name:bork
Download: download sample
Signature Mirai
File size:1'072 bytes
First seen:2025-12-21 15:13:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:k7NWa7M5fWa7pWa7CWa7V9Wa7yWa7bWa7mWa7KWa7rWa7bdWs:kBWawhWa9WaWWa/WauWa/WayWa+WaXWq
TLSH T10F11546F0185AD90888CD53977D1911CB4C14BDA1A7F4AB42FA601BF24F07EE7339E15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/splarm5043a5466b9db58f8447782a2b157458a6925fb6c265c29269725400b8ffa50d Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm5fa467e4779f753364fa0cd7d033074789b1b8887cd0c2706fd30ed1928acc9d9 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/splarm63f0d64a6bb8e252e6b43d084b1e178a08d3c5dbe004348c3b8d49c2d8e42d08a Miraielf mirai ua-wget
http://130.12.180.64/splarm7931917f50a7edf09174f1f55566b709d8a4a53afd78906960d9269f0f1b0f4c3 Miraielf mirai ua-wget
http://130.12.180.64/splm68k8590fca6bd80f48e8a59389a4a6c2cac78525f4108282f52f8736e596978b9be Miraielf mirai ua-wget
http://130.12.180.64/splmipsa3142b278719fc6b9cdf0548aa3152df9c65fbec928eced1cbce607dbf8600fd Miraielf mirai ua-wget
http://130.12.180.64/splmpslf471f2a42ec508d5d23a3516f1d22c28343a756afa44b62b7c72f72d67231586 Miraielf mirai ua-wget
http://130.12.180.64/splppcf6eab22b07f5ad176d203e61e883cfc90d312b7e7619b5123e671db9d4c45cca Miraielf mirai ua-wget
http://130.12.180.64/splsh4a6cd99999efd842a4e6d53a098b615c8709138a87b9f20b63c704e021f542aeb Miraielf mirai ua-wget
http://130.12.180.64/splspcf612866af6e3ca3fdf3ec528ff1512cd76c810c3afc2b38fd80d9169f5108b91 Miraielf mirai ua-wget
http://130.12.180.64/splx864f555fb649aa4632ec420b52bd34e69d5cfe86f1245f4ea7f7fdc6f10a955bae Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:31:00Z UTC
Last seen:
2025-12-23T12:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=33ac9bd0-1900-0000-b179-53a4cb0a0000 pid=2763 /usr/bin/sudo guuid=de1fe3d3-1900-0000-b179-53a4ce0a0000 pid=2766 /tmp/sample.bin guuid=33ac9bd0-1900-0000-b179-53a4cb0a0000 pid=2763->guuid=de1fe3d3-1900-0000-b179-53a4ce0a0000 pid=2766 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-21 15:30:35 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dd87268f4a26a7e79d563499b24a54d36fed4d97a99e7dd307ff73691c328cf5

(this sample)

  
Delivery method
Distributed via web download

Comments