MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e9d5e38a71253bccedee22ddf38c4e661e1190dfdf890a527b174e8a0b5b971d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: e9d5e38a71253bccedee22ddf38c4e661e1190dfdf890a527b174e8a0b5b971d
SHA3-384 hash: 653df49811e67d47cbf259843ed4c55a0b50ddd82280e929fb60d5a18f6bd9b54c10f87acd31ba2a18e09cea3e2f5bc8
SHA1 hash: 12994d53b950251a220ca5044a308aff6ab54f25
MD5 hash: 216a7c88d629b7cb401c7a2792e6cf45
humanhash: winner-papa-foxtrot-king
File name:8UsA.sh
Download: download sample
Signature Mirai
File size:1'620 bytes
First seen:2026-01-01 12:31:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:v3vQFskoLBSOSuJJgAssqEAYL83AdksDAkhzxN4Ihq+S:v3dVSAJvssqrYLzdJEkbTo
TLSH T1CB3132D959B74D76AFB5996A72F504547180E08A2ED3EDC8E8FC34E8488FD447086EC3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.27/px8681aa3a1cec78008abbe0506a44c20fc80efe006f5c4d84fdec6c8ed9d84521d6 Miraielf mirai ua-wget
http://158.94.208.27/pmips648a1ad85e1ef2c1306e922cb9fee502490224f527dfbcbd9397c11a1db03cb1 Miraielf mirai ua-wget
http://158.94.208.27/pmpsl46280c6dceff8fe250699ec09396d2170a5ef12e74ffcca4a3c4ccbb839cc1d3 Miraielf mirai ua-wget
http://158.94.208.27/parm4n/an/aelf ua-wget
http://158.94.208.27/parm5a94d7cbe81a0cbd11fb01bd07ecaeac53841be51de978edcbcd45d38ab37b6d3 Miraielf mirai ua-wget
http://158.94.208.27/parm69094de5be92f576714964acc02d13a91a68c814057560adf46d81866965ac872 Miraielf mirai ua-wget
http://158.94.208.27/parm78027c6f089be296b3961b35fd9f4dc03edd64d05288e5e51ded9a3a25c0ab6b3 Miraielf mirai ua-wget
http://158.94.208.27/pppc34f26a27851b45174339853cff95b2f4aaa810397b1461dc5bccaefb79c3fc4d Miraielf mirai ua-wget
http://158.94.208.27/pm68k72bf7021a323e4f8668499f2c124973c6d4744abddab61449824d7b5334249f6 Miraielf mirai ua-wget
http://158.94.208.27/psh44e49fbeee717728935e64e493d8b0685c0da63b15b10c5c8875f1499e8a89a92 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-01T09:37:00Z UTC
Last seen:
2026-01-03T03:16:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-01 12:31:20 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Creates/modifies Cron job
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
158.94.208.27
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e9d5e38a71253bccedee22ddf38c4e661e1190dfdf890a527b174e8a0b5b971d

(this sample)

  
Delivery method
Distributed via web download

Comments