🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8ff55a036caba3a2dfdf4d6eb73d243f7b74f363a6d60ef39f3f7ed73b1bea8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f8ff55a036caba3a2dfdf4d6eb73d243f7b74f363a6d60ef39f3f7ed73b1bea8
SHA3-384 hash: c98d7941157def894aca19ca98760729f021f26b4db07b2ed7172fce203fba68cfcbf9d92872e00c72c36acf46f1c690
SHA1 hash: 229a498ee3aa93fda1065236c2e21bfaebc9d474
MD5 hash: 6fc1850b0c7af6e51004b95193ef16ef
humanhash: missouri-xray-triple-alpha
File name:c.sh
Download: download sample
Signature Mirai
File size:840 bytes
First seen:2024-12-22 14:45:57 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:3J3CzXJQfNI7WHKXThPIRjqbTtBSRNpPHA:8zXJQ+WHAThARjWHSRvPg
TLSH T1C401CCED2AD5628E1A0CCE0CB46A820C674A8BC6F4750917F054BD7A65DD308F0B5F76
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://209.141.47.117/bins/arm27d13d2f3ecfa851961cceee52850b9a1a18a0acd72cd9a6c0e1d1ee13ff3715 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/arm57aead7f883ad2f95d7924111f5c35349ee8b250bc0d3846b34ff148f2a081ebc Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/arm60fe42c6bace1aafe91e7320d353c1ca482aca127bb11cef80a374eb7fb92c1df Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/arm7d1eb6155452f3ab97e2df1311a93514c6c4be839810a31307404b22a21ca400f Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/m68k1f8dd777f2b7d73d80edd4838c967ecbda52329a4655a88232bc99c4d9938765 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/mips3a890af148ebca93bf4df29e95edb3e6a0c60f924124cb0bac553cd024bfe420 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/mpslf14ffa7195b4dcf5a946577b7ea5014da5b84f0489dfeb2d013aa4dec7fedbe6 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/ppcn/an/an/a
http://209.141.47.117/bins/sh452bbe544185e3ffbca2a31a4da7ee50163dd744ea2645b69d6d437547536aca7 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/spc9d7bcbd227ddec00a4fd7b3892eba60d55f72d379d2031e459097f025d7c1792 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/x863490c02550d5d70c0900ac64d14b4ef284e0ad0fae16fdb6765d1d66baade075 Mirai1049h censys elf mirai opendir StarCNC
http://209.141.47.117/bins/x86_64cab713be24d5b1c7320d93a1957937a3dc472d1cd9f3fdc48d10a08cfa01b8c2 Mirai1049h censys elf mirai opendir StarCNC

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
mirai agent hype sage
Threat name:
Linux.Downloader.Mirai
Status:
Malicious
First seen:
2024-12-22 14:46:05 UTC
File Type:
Text
AV detection:
12 of 38 (31.58%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f8ff55a036caba3a2dfdf4d6eb73d243f7b74f363a6d60ef39f3f7ed73b1bea8

(this sample)

  
Delivery method
Distributed via web download

Comments