MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ebfd8dc756fd0b490fe0f383a4bd0ede36a86335eced53f47ef13baebf6746d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: ebfd8dc756fd0b490fe0f383a4bd0ede36a86335eced53f47ef13baebf6746d3
SHA3-384 hash: 3075b76d81e29ca735f74d3c4d8584f0cce4d0bdf0abba46d3b36c10cbba947bb49f2e8c6ef9d081adfb9b87c9deb6cd
SHA1 hash: ef991784653b9e69e8304c761f384344ff49db98
MD5 hash: a0676e759d8aaa966afacd0abcd1dfcc
humanhash: quebec-green-jupiter-grey
File name:auto
Download: download sample
Signature Mirai
File size:413 bytes
First seen:2026-02-26 04:33:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:YO92J9tLxUbc4Ub9HCY9dYLxUbgF84UbgFdHan:YO92J9tLxUbHUbUY9dYLxUbAnUbAAn
TLSH T1ECE022FC00768AC7030D06E0706585FE262C1492AFF04E18C1866DFE1C2B5A8388F34B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.208.159.67/check1.sh6574e3e5a6e0167077dde72bcd72e1fd3a79e61aa9e6e76ab6329c13ca7ea6e4 Miraish ua-wget
http://185.208.159.67/check.sh1941d079381cc9937ce5259d0219144ebb1645bf8a500ba9d31288c45f9439fa Miraish ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
107
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin
Result
Gathering data
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ebfd8dc756fd0b490fe0f383a4bd0ede36a86335eced53f47ef13baebf6746d3

(this sample)

  
Delivery method
Distributed via web download

Comments