MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA File information Comments

SHA256 hash: ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2
SHA3-384 hash: 3f1d91f132b531e8a851c867cb3ec778e62ce29bae1d374c309bcd7533b65abe7ce5fc817fb96d75d3ce7a5aa100705c
SHA1 hash: db0a369df0887febacb3800f4c6f0b81a1f68351
MD5 hash: 05f3e94487bf02c65f08cbed72943ce0
humanhash: black-may-low-fish
File name:huh
Download: download sample
Signature Mirai
File size:3'684 bytes
First seen:2024-12-30 06:47:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:2msXsbrK3s6+ssxs+s7s1s0sJsEs8NsZsVsTsF:23cq8T6/wuZCp82SOYF
TLSH T167717DC52BEC12342CDA851FB768CED971DA909394D31E2495AC78F8C16EF4E7482E93
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://92.118.56.203/bins/vcimanagement.x8644c45d6b511582fa946786726aef772d7f0596116d836a7dfa1d98531c467369 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.mips153f6c799071e51090c0bf34137a14fe9b1df5a6e0ffc7d3d1d9923ba303de3c Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.mpsl4954ee06d2e03a9519fa80beca52dcc4897c3162f70463106af4771f13e95f58 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.arm44d1974dc0dcf7ce07da8b58c25844513ef7dd148e570e7601d61ddf740cade3 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.arm5d9f599fa80b068ad77f18d7ff2793a1bd68b45555091a2985d04cb2316c6272c Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.arm6244a20f296d451ee99530a25ecbc784530ca899ebbf78c5f30a8ff53561a9256 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.arm7b30be7ce7a47773e6d8ecd0ced684ad6f4e2eb6d1096091d137bb95f39111d12 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.ppc0b26a84b8e79d256cf8df06aba79d7b7e10d85731d853ec07887c6a6d1dacd19 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.m68k65d5de1588622161778067a4a00bcf03b5bbfb908b1c65eafd8efe8b19b15ab4 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.sh47ddd640ad18766525101fd7d7ac5a0d429eb18a3b400c95f82d3109a2d52a6a4 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.spc3e7c86dc6bfcdebb5e408419ca0f8dde1bd1f8f4b51a21a5d5563a37dc4bae64 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.arc3e7c86dc6bfcdebb5e408419ca0f8dde1bd1f8f4b51a21a5d5563a37dc4bae64 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.x86_643e7c86dc6bfcdebb5e408419ca0f8dde1bd1f8f4b51a21a5d5563a37dc4bae64 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.i68631c47fa7daca0812b6c1b4706c02ea41123a830b07b25bacc73b5c4e6b8583c7 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.i48631c47fa7daca0812b6c1b4706c02ea41123a830b07b25bacc73b5c4e6b8583c7 Miraielf mirai opendir
http://92.118.56.203/bins/vcimanagement.mips6431c47fa7daca0812b6c1b4706c02ea41123a830b07b25bacc73b5c4e6b8583c7 Miraielf mirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
123
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
downloader agent overt
Result
Verdict:
MALICIOUS
Threat name:
Win32.Trojan.Mirai
Status:
Malicious
First seen:
2024-12-30 03:04:08 UTC
File Type:
Text (Shell)
AV detection:
15 of 23 (65.22%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:echobot family:mirai antivm botnet defense_evasion discovery linux trojan
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (253624) amount of remote hosts
Creates a large amount of network flows
Detected Echobot
Echobot
Echobot family
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ec46f105b049d6674acbf45639883623f2f1cb3eed50eedb4b0e25a27a7b67e2

(this sample)

  
Delivery method
Distributed via web download

Comments