MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f9a69d4bbd3bc25af67944316a7df6e4e15b20366064f06a144f4fa55c57685c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f9a69d4bbd3bc25af67944316a7df6e4e15b20366064f06a144f4fa55c57685c
SHA3-384 hash: 64425f43ab42d9cc3a4b889124b46a71b0a06a7433e4364afec966a70b545bb954ec2dfa5e1bec3e41476fd0f52465d7
SHA1 hash: 4f44420b4e56febed881568cd8af317b496f81e8
MD5 hash: 68c4c8ae1e2c3712cdb613676ed5e2af
humanhash: nebraska-zulu-delta-missouri
File name:n3881.sh
Download: download sample
Signature Mirai
File size:546 bytes
First seen:2025-01-20 21:17:19 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:XVE8bELQGkEd8k7uGEkKyEXUrEqX3HGKzAxNIxEnXdPkva+EkX0:lE8eQGkEGk7fEkSiEqnHGKzUNIxEntP7
TLSH T101F0968845D33706042E9CF6F5F728653022CAC9965F9FCFED5A4438CC5BA24F938A08
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.143.1.54/nabmips464b767532880910ad5a615225792238f340f8c020f31599b39bc1e3fc97209d Mirai501 censys elf mirai ua-wget
http://193.143.1.54/nabmpsl5a188fb57cf62e7accc4eca0e37b7ccdec300c6c966dec2531b4e5bd745f369d Mirai501 censys elf mirai ua-wget
http://193.143.1.54/nabarmffe4b4ff099a31da367a0360163f2bde0d1efbdd6743fc7bf17f327c75f9a723 Mirai501 censys elf mirai ua-wget
http://193.143.1.54/nabarm588894ed9b6f7cc1c27ad76365efb8bdcabdc2a3010a79a9d3a740ffa275123c1 Mirai501 censys elf mirai ua-wget
http://193.143.1.54/nabarm62b7e7f9f0f86bbf70b01a526c11e745350d20675e6766bb9e0dfc4b5350f7408 Mirai501 censys elf mirai ua-wget
http://193.143.1.54/nabarm7d08bbb8bdf7ad6597616cef31af12c1c73b0cb138b60bd084b8e89bbee0cfc3a Mirai501 censys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
106
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Verdict:
UNKNOWN
Threat name:
Script.Trojan.Heuristic
Status:
Malicious
First seen:
2025-01-20 21:11:48 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery
Behaviour
Modifies registry class
Suspicious behavior: GetForegroundWindowSpam
Suspicious use of SetWindowsHookEx
Suspicious use of WriteProcessMemory
Enumerates physical storage devices
System Location Discovery: System Language Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f9a69d4bbd3bc25af67944316a7df6e4e15b20366064f06a144f4fa55c57685c

(this sample)

Comments