MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f9908c8ac9b790c9725b1c504cedb149908eebb90277bf8058103c7112ca44ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: f9908c8ac9b790c9725b1c504cedb149908eebb90277bf8058103c7112ca44ba
SHA3-384 hash: f28a981202f7a709872f66dea7d0b26bd335aed06ecb343f5649314e92d51cebd3e87bb22bc6759ed7ef36ab86b4fb87
SHA1 hash: 9aecc8ef93d7e4ab3b4f4a7e7c90f6d317e35bb1
MD5 hash: ce4d0fb6c1bac64b685a0eaba0aac2fa
humanhash: fix-eighteen-apart-cat
File name:1.sh
Download: download sample
Signature Mirai
File size:6'418 bytes
First seen:2025-08-18 16:36:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:gp/p3mBdpgpOBqEphpp83Hp8pC12Ipepk7sKpypgnA2p3pPOZlp3pPOZlp6pofIi:Ah3mB/AOBqcLp83J0C12o2k7sKSgnAuF
TLSH T15CD15FF2B4C552BCDE9FCD3A6111697D2089BA8B268B4D658BED2465BC89FCC1C10DC3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86f4aff0e81cd7554eade8effb47903983caa0001fd7a12f829cea316826e6670d Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mipscf2c0cf841a3711763d606cb2713611da2248ca021067e8846ea5a8eaca2bf62 Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arcf00a12a77946cd4adc50bbe45aa958ece8c962f337cfcf080b5a77d896f77030 Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i468n/an/aelf ua-wget
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.i6862f2f1d3747fe2a9b67d0aadf81904c6e14f51f67a1976effc8a7fd7d24b81b6d Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.x86_6429499a50ee8192eebed270c3823a9387fd591be9ea31adeeda0162eb31e1021d Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.mpsl38e6b6cf698fcc0ea5e8397e7376e3c80e87201caa0901f9e13931d815525fe4 Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm55cfdcc9ef16ceaa10faae7160332dd13756ac02f24ab8e907063f49ccf3e9c6 Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm597486451f4027c87159a9893c129fcd2255ab390515eb2afb0f332671ee8fe55 Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm63d6e830d7a9a9fe1d3ed7b0b08f886945ab5703d0295350617adc4b3eefb214a Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.arm7323f4d7fc643b4e2304504434c5ec5d97d3b337b7acb4208df98ae9a5b94691a Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.ppca5ae767ec9d1c7921e83748e514e3a40f5de1045058a481ac0efc7d1b14e44bd Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.spc267b2a7bc7b0ad26d623357fad6b5a74e88261ab65eba5d8519581236601f5ab Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.m68kf190f11c91d51d401f5dc29f7420640f786b2d6d6f921fb1f4ae4d7e0bdad82a Miraimirai opendir
http://181.214.231.124/001010101010010110101011101010101101010111010101/nwfaiehg4ewijfgriehgirehaughrarg.sh4e72836abb33eb7f3e747e90b62a2cdfaf453977dc44c861b6c5c62221a3c5627 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-08-18 16:39:38 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Deletes Audit logs
Deletes journal logs
Deletes system logs
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f9908c8ac9b790c9725b1c504cedb149908eebb90277bf8058103c7112ca44ba

(this sample)

Comments