MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4b074e84c2ecee4258eb25f97e47ec0bdfb2eda90b5d883a1f29f6da461c903. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e4b074e84c2ecee4258eb25f97e47ec0bdfb2eda90b5d883a1f29f6da461c903
SHA3-384 hash: 4da190f0203124e5cd9571b8625ef9a3b08973c707c4393ae6a1f0f4bd4a13e603561faf40e9f7e8a90edfbddae27767
SHA1 hash: 522c53a8eb4822cd799f4cf41215446d00209c6e
MD5 hash: d363eebd0300e09d0df17bab4e27bdf9
humanhash: magnesium-minnesota-social-pennsylvania
File name:w.sh
Download: download sample
Signature Mirai
File size:937 bytes
First seen:2025-03-24 04:07:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:kExqMaRHMrNIjlTBAM4iKl2EMedKAMeSEMf9qMuFG10qMtM5h7IAMX1MKllAUn:bxMGNIp/Klq6MVDAlXn
TLSH T1181188C9427067250A4C8D1DB62F990854869ED0B7210E4CDC8C04FBAEE8E97F156F5B
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.32.162.27/bins/parm08984a611ad4418504d468a1fe64b509c03a5248d221ceb548a618309cb6dee1 Miraielf mirai
http://193.32.162.27/bins/parm57086e3187ff903595871f8f2cd65c37275efc5348591c3fa6508ccd665f2abaf Miraielf mirai
http://193.32.162.27/bins/parm679e10cafec2223778f3c8e792d64cd4f71fc1328e47cb28a3f377bc2680561d7 Miraielf mirai
http://193.32.162.27/bins/parm7b81bb64eb774619193e55844ab2cedd1df6f7393dadbde64dd3f346c1a0f740a Miraielf mirai
http://193.32.162.27/bins/psh43ca4e81d75c1e5676528a887cfdd04a6811f38098d14d2c92abb861aae2eb820 Miraielf mirai
http://193.32.162.27/bins/pppcacbcff5c1ed25d46c41a7ddb6412fecc83b7452d4c6641d3a41fc92c97dd8508 Miraielf mirai
http://193.32.162.27/bins/pmipsc90123178eb93e2fa8c843507d8c388b6cc5331c0e130a11e44c5f009d721394 Miraielf mirai
http://193.32.162.27/bins/pmpsl6802100b58427ba2a7551675a48db11f6961452b50081f44ec429aaec9a523b8 Miraielf mirai
http://193.32.162.27/bins/pspccd16e244412355b703d39015aae6803d32307f831af3f8ac41155e3c7d97d8f3 Miraielf mirai
http://193.32.162.27/bins/px86a2d91163eeefbc033b7f4aad57635df36c770a8a2f7864e78d8831739c1d9da6 Miraielf mirai
http://193.32.162.27/bins/pm68k24828c3fe8d2f32b541a50c4f34b94ee93241d40e23ed027e8b203f7655b7c7e Miraielf mirai
http://193.32.162.27/bins/pi586n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
95.7%
Tags:
backdoor mirai hype sage
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
lolbin remote
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Alevaul
Status:
Malicious
First seen:
2025-03-24 04:08:12 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e4b074e84c2ecee4258eb25f97e47ec0bdfb2eda90b5d883a1f29f6da461c903

(this sample)

  
Delivery method
Distributed via web download

Comments