MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fda70b0e00e2ffce03dce52b4c04e4776ffc6a8230faf995e3b0c4071e3aa609. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: fda70b0e00e2ffce03dce52b4c04e4776ffc6a8230faf995e3b0c4071e3aa609
SHA3-384 hash: 79cd9f3104cc89fdf224dec7dc9aab3eddbcf43036ba69f70e952ab569e610fed3f32082aff068890ba9180a624a7462
SHA1 hash: d88e11b92ea85cbcd537d31a1d9a8fdff427fa38
MD5 hash: 14b16370785d5fed2787a8725b9c7b50
humanhash: mirror-skylark-texas-bulldog
File name:bl
Download: download sample
Signature Mirai
File size:993 bytes
First seen:2025-09-09 06:17:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:6Y6dQhBh9Mk8QoeWcOij3qKiiNI7p6rbDGJkOuGQ:6ehL8Qoeti30ia
TLSH T11911D39DB45292A24C6CBF11B4E2C480501683C723618E2AFC565E377CEC706F46CF7A
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.250.134.48/mpslfc2117cb6a4433fc0a3711ce912f4a1794741dfe467cf7c64ac9250e125b927c Miraielf geofenced mips mirai ua-wget USA
http://160.250.134.48/mipsfd75057993af111cf29aeb0924554d01ad28c071fb20cf9700831fd4402fbaf2 Miraielf gafgyt geofenced mips mirai ua-wget USA
http://160.250.134.48/arm76509f8d5312e74b83dcc973477b33d6a439bc050545d2bc54962f9b43d8ddf88 Miraiarm elf geofenced mirai ua-wget USA
http://160.250.134.48/arm6n/an/aelf ua-wget
http://160.250.134.48/arm5ef0759560923799625dbffbc95e23935d0c09da4aad0e7e285a24510c1255a97 Miraiarm elf geofenced mirai ua-wget USA
http://160.250.134.48/arm4e16a5e543be159372994cf2bd528b703cfc4ebe667e153a34de20e13de0bc265 Miraielf mirai ua-wget
http://160.250.134.48/arme16a5e543be159372994cf2bd528b703cfc4ebe667e153a34de20e13de0bc265 Miraiarm elf geofenced mirai ua-wget USA
http://160.250.134.48/x86n/an/aelf ua-wget
http://160.250.134.48/ppcn/an/aelf ua-wget
http://160.250.134.48/spcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-09T04:23:00Z UTC
Last seen:
2025-09-09T04:23:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-09 06:00:21 UTC
File Type:
Text (Shell)
AV detection:
14 of 38 (36.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fda70b0e00e2ffce03dce52b4c04e4776ffc6a8230faf995e3b0c4071e3aa609

(this sample)

  
Delivery method
Distributed via web download

Comments