MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e06319a2a6d0f18a56e46139d3d51a334dbafb491c0c8bbe8f08a504e45dbdb1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: e06319a2a6d0f18a56e46139d3d51a334dbafb491c0c8bbe8f08a504e45dbdb1
SHA3-384 hash: 2fc83281ec85a2652eed50bd4fc8232dcb5f62322b27bab554cba7bcbe45ca1af4c72596c38c606cc0eb4adbe35173a9
SHA1 hash: 62e1978bacfaf484fe455adbf3b00e09a6dc505c
MD5 hash: 6ddfbc58ddae3e4ba11337765cd3f53c
humanhash: double-sierra-hydrogen-moon
File name:f
Download: download sample
Signature Mirai
File size:1'010 bytes
First seen:2026-01-21 13:43:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:H7NASa7AQSa72Sa7DSa7vR+Sa7bSa7gDSa7bDSa7rSa73ASa7neST:HzaMa/aqabhaaaNaeaiaLhaHT
TLSH T1A811515F0245AD94C08DD47A37D2870DB4844FCD287B0657AD6240B940E06CE773895A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.64/zerarm6409cd5aa866c9f8708b95beb77a017dd2a6174fbf8f224ddad64a69552aead9 Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm5e5223faab1dd8f3a7bbf4739935b5c5460489bfce96ac36bef86a8d2435a900e Miraielf gafgyt mirai ua-wget
http://130.12.180.64/zerarm6e295d162049669301f8fd374f811ea9417d892962ead03204f06e9b9dd1ee8dd Miraielf mirai ua-wget
http://130.12.180.64/zerarm7873da354093954fa3b896dd5bc5f93c9236a2c523471f61d1362cda6f787ba20 Miraielf mirai ua-wget
http://130.12.180.64/zerm68k8895afdf7c48e61ce84e791f2242add856dca46dcaeaef1c59297465d173ae5a Miraielf mirai ua-wget
http://130.12.180.64/zermipsc53ddf5b78c75a44e89c8b5b2ade8f8c18939a43f9821412ca6986926a83c0d3 Miraielf mirai ua-wget
http://130.12.180.64/zermpsl2ebd09e601effd14eb25b4059f5fb59226a3feca88a6ee5ff6a893a76d181232 Miraielf mirai ua-wget
http://130.12.180.64/zerppc370229274d88299cafc47bacd0e23ec2d9a7f4c7e552232cc6f53d7f200b0c78 Miraielf mirai ua-wget
http://130.12.180.64/zersh4e916e50468ab757bd4f0fd560268b9f411031d8eeb0a47906fabc83a6bf890d6 Miraielf mirai ua-wget
http://130.12.180.64/zerspc43e5b41e762555bd3b3af1cdd32a1eb7137470ceb4175e380e70a4118bffba5e Miraielf mirai ua-wget
http://130.12.180.64/zerx86c3960241a657fd76a114452ad9a3bebd9d7db943e335f69a12ecc9e2ea76c3e2 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-21T11:31:00Z UTC
Last seen:
2026-01-21T12:50:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=500583a6-1700-0000-bf4a-856b290c0000 pid=3113 /usr/bin/sudo guuid=920931a8-1700-0000-bf4a-856b2f0c0000 pid=3119 /tmp/sample.bin guuid=500583a6-1700-0000-bf4a-856b290c0000 pid=3113->guuid=920931a8-1700-0000-bf4a-856b2f0c0000 pid=3119 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-01-21 14:21:16 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e06319a2a6d0f18a56e46139d3d51a334dbafb491c0c8bbe8f08a504e45dbdb1

(this sample)

  
Delivery method
Distributed via web download

Comments