MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 05b42d715d54d8323e5880d2e8081ad1fbe2a1ecbdb6f125cfcca011a042079e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 05b42d715d54d8323e5880d2e8081ad1fbe2a1ecbdb6f125cfcca011a042079e
SHA3-384 hash: 111da7d77c2ce6cc33ebb56db6e93631d4eaa40cabb88a0870d0ab8272556d86804cac4f623f25b67a6eac63b8c9faf6
SHA1 hash: 097b0b61638fdbdfa8f8e21e72dd00737b5209e4
MD5 hash: 71075cdbcc330b42f0ae68be6ff44ea3
humanhash: autumn-carbon-minnesota-sixteen
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'901 bytes
First seen:2026-03-25 21:34:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:3Ddc21aa/BM/h9C1bua2wo6fQo7+gKXJB4DH9:G21a9No7+I
TLSH T14641088E70B42B418D9CCE0071E149CA7707A5A3A6A787F3E94D0EF68899D4A741DA37
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.249.228.212/iran.x86_64n/an/an/a
http://94.249.228.212/iran.aarch64n/an/an/a
http://94.249.228.212/iran.m68kn/an/an/a
http://94.249.228.212/iran.mipsn/an/an/a
http://94.249.228.212/iran.mipselb59627803c1e36b3dce1b27831f01e70ad9c0a754dd02200ec58f9c271574430 Miraielf mirai ua-wget
http://94.249.228.212/iran.powerpcefa1a2bfb85f8d16c46e879bad1c786c26df58377f346bba92b515e07abf4189 Miraielf mirai ua-wget
http://94.249.228.212/iran.sparcd739cf94dce3ff153cc22a4b8af4c4fe4fc82cb3ca132f23faa77c9beffa7306 Miraielf mirai ua-wget
http://94.249.228.212/iran.sh4dfd4e8bf4ee5b630791cd1f0bbfffdd2146bde0c28fdd241fc818b7fbc1e9e8a Miraielf mirai ua-wget
http://94.249.228.212/iran.arc62ea0dff63ad36645cff88b905c3fb0096c92db4bf571ddc312b20142cc0c03f Miraielf mirai ua-wget
http://94.249.228.212/iran.i486501a02eba46a0e103b38964a2e6a9bc1b0a8f53824544f84e8a12b41d562c313 Miraielf mirai ua-wget
http://94.249.228.212/iran.armv4l42258aad7bdd5e063523159905dbf35a87b4a9e13a091d9d9e17f030dfe9af6a Miraielf mirai ua-wget
http://94.249.228.212/iran.armv5l98bc000407544dd8e14d30a3c90ae5422076bdcbd0afb6976729a2c4ccb3c54b Miraielf mirai ua-wget
http://94.249.228.212/iran.armv6l0a05916360192b441abe9eb1aa42f3b12c963d22a92893aa62a07afce26dbc27 Miraielf mirai ua-wget
http://94.249.228.212/iran.armv7l8d13aea9c3759414f1888998dd75f3f52d027587cf010f9570adccce8b96301b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=66efbcea-1700-0000-7d63-2281980c0000 pid=3224 /usr/bin/sudo guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227 /tmp/sample.bin guuid=66efbcea-1700-0000-7d63-2281980c0000 pid=3224->guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227 execve guuid=0335d9ec-1700-0000-7d63-22819c0c0000 pid=3228 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=0335d9ec-1700-0000-7d63-22819c0c0000 pid=3228 execve guuid=61ec8df3-1700-0000-7d63-2281a10c0000 pid=3233 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=61ec8df3-1700-0000-7d63-2281a10c0000 pid=3233 execve guuid=d4831df4-1700-0000-7d63-2281a20c0000 pid=3234 /home/sandbox/iran.x86_64 mprotect-exec guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=d4831df4-1700-0000-7d63-2281a20c0000 pid=3234 execve guuid=ae1238f5-1700-0000-7d63-2281a40c0000 pid=3236 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=ae1238f5-1700-0000-7d63-2281a40c0000 pid=3236 execve guuid=ade776fb-1700-0000-7d63-2281ae0c0000 pid=3246 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=ade776fb-1700-0000-7d63-2281ae0c0000 pid=3246 execve guuid=0a9dcafb-1700-0000-7d63-2281af0c0000 pid=3247 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=0a9dcafb-1700-0000-7d63-2281af0c0000 pid=3247 clone guuid=cb2caefc-1700-0000-7d63-2281b20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=cb2caefc-1700-0000-7d63-2281b20c0000 pid=3250 execve guuid=84edfa03-1800-0000-7d63-2281bf0c0000 pid=3263 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=84edfa03-1800-0000-7d63-2281bf0c0000 pid=3263 execve guuid=25314d04-1800-0000-7d63-2281c00c0000 pid=3264 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=25314d04-1800-0000-7d63-2281c00c0000 pid=3264 clone guuid=fcb6f904-1800-0000-7d63-2281c20c0000 pid=3266 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=fcb6f904-1800-0000-7d63-2281c20c0000 pid=3266 execve guuid=844a350b-1800-0000-7d63-2281ca0c0000 pid=3274 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=844a350b-1800-0000-7d63-2281ca0c0000 pid=3274 execve guuid=980b790b-1800-0000-7d63-2281cc0c0000 pid=3276 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=980b790b-1800-0000-7d63-2281cc0c0000 pid=3276 clone guuid=8035d70d-1800-0000-7d63-2281d30c0000 pid=3283 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=8035d70d-1800-0000-7d63-2281d30c0000 pid=3283 execve guuid=cc8d3014-1800-0000-7d63-2281e50c0000 pid=3301 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=cc8d3014-1800-0000-7d63-2281e50c0000 pid=3301 execve guuid=71228914-1800-0000-7d63-2281e80c0000 pid=3304 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=71228914-1800-0000-7d63-2281e80c0000 pid=3304 clone guuid=a4f54c15-1800-0000-7d63-2281ed0c0000 pid=3309 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=a4f54c15-1800-0000-7d63-2281ed0c0000 pid=3309 execve guuid=5e98d01a-1800-0000-7d63-2281fb0c0000 pid=3323 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=5e98d01a-1800-0000-7d63-2281fb0c0000 pid=3323 execve guuid=f0050c1b-1800-0000-7d63-2281fc0c0000 pid=3324 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=f0050c1b-1800-0000-7d63-2281fc0c0000 pid=3324 clone guuid=dbcf841b-1800-0000-7d63-2281000d0000 pid=3328 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=dbcf841b-1800-0000-7d63-2281000d0000 pid=3328 execve guuid=9d53491e-1800-0000-7d63-2281090d0000 pid=3337 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=9d53491e-1800-0000-7d63-2281090d0000 pid=3337 execve guuid=403c831e-1800-0000-7d63-22810b0d0000 pid=3339 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=403c831e-1800-0000-7d63-22810b0d0000 pid=3339 clone guuid=40c13020-1800-0000-7d63-2281120d0000 pid=3346 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=40c13020-1800-0000-7d63-2281120d0000 pid=3346 execve guuid=678dfa25-1800-0000-7d63-22811a0d0000 pid=3354 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=678dfa25-1800-0000-7d63-22811a0d0000 pid=3354 execve guuid=13244726-1800-0000-7d63-22811b0d0000 pid=3355 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=13244726-1800-0000-7d63-22811b0d0000 pid=3355 clone guuid=8375e826-1800-0000-7d63-22811d0d0000 pid=3357 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=8375e826-1800-0000-7d63-22811d0d0000 pid=3357 execve guuid=f653c72d-1800-0000-7d63-2281270d0000 pid=3367 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=f653c72d-1800-0000-7d63-2281270d0000 pid=3367 execve guuid=fee4002e-1800-0000-7d63-2281290d0000 pid=3369 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=fee4002e-1800-0000-7d63-2281290d0000 pid=3369 clone guuid=47b5812e-1800-0000-7d63-22812c0d0000 pid=3372 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=47b5812e-1800-0000-7d63-22812c0d0000 pid=3372 execve guuid=b3124c33-1800-0000-7d63-2281350d0000 pid=3381 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=b3124c33-1800-0000-7d63-2281350d0000 pid=3381 execve guuid=849a9a33-1800-0000-7d63-2281360d0000 pid=3382 /home/sandbox/iran.i486 guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=849a9a33-1800-0000-7d63-2281360d0000 pid=3382 execve guuid=89f10e34-1800-0000-7d63-2281390d0000 pid=3385 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=89f10e34-1800-0000-7d63-2281390d0000 pid=3385 execve guuid=9c25a539-1800-0000-7d63-2281490d0000 pid=3401 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=9c25a539-1800-0000-7d63-2281490d0000 pid=3401 execve guuid=648a003a-1800-0000-7d63-22814b0d0000 pid=3403 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=648a003a-1800-0000-7d63-22814b0d0000 pid=3403 clone guuid=8de8a83a-1800-0000-7d63-22814f0d0000 pid=3407 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=8de8a83a-1800-0000-7d63-22814f0d0000 pid=3407 execve guuid=8e83d940-1800-0000-7d63-2281590d0000 pid=3417 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=8e83d940-1800-0000-7d63-2281590d0000 pid=3417 execve guuid=acc22941-1800-0000-7d63-22815b0d0000 pid=3419 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=acc22941-1800-0000-7d63-22815b0d0000 pid=3419 clone guuid=0ffccd41-1800-0000-7d63-22815f0d0000 pid=3423 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=0ffccd41-1800-0000-7d63-22815f0d0000 pid=3423 execve guuid=df34cc47-1800-0000-7d63-2281750d0000 pid=3445 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=df34cc47-1800-0000-7d63-2281750d0000 pid=3445 execve guuid=1f5d0b48-1800-0000-7d63-2281760d0000 pid=3446 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=1f5d0b48-1800-0000-7d63-2281760d0000 pid=3446 clone guuid=f3068e48-1800-0000-7d63-22817a0d0000 pid=3450 /usr/bin/wget net send-data write-file guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=f3068e48-1800-0000-7d63-22817a0d0000 pid=3450 execve guuid=c328fc4d-1800-0000-7d63-22818f0d0000 pid=3471 /usr/bin/chmod guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=c328fc4d-1800-0000-7d63-22818f0d0000 pid=3471 execve guuid=0593374e-1800-0000-7d63-2281910d0000 pid=3473 /usr/bin/dash guuid=336fa3ec-1700-0000-7d63-22819b0c0000 pid=3227->guuid=0593374e-1800-0000-7d63-2281910d0000 pid=3473 clone 13b61a20-73c3-532b-a681-77884528fd4d 94.249.228.212:80 guuid=0335d9ec-1700-0000-7d63-22819c0c0000 pid=3228->13b61a20-73c3-532b-a681-77884528fd4d send: 140B guuid=df7b2cf5-1700-0000-7d63-2281a30c0000 pid=3235 /home/sandbox/iran.x86_64 zombie guuid=d4831df4-1700-0000-7d63-2281a20c0000 pid=3234->guuid=df7b2cf5-1700-0000-7d63-2281a30c0000 pid=3235 clone guuid=02e73ff5-1700-0000-7d63-2281a50c0000 pid=3237 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=df7b2cf5-1700-0000-7d63-2281a30c0000 pid=3235->guuid=02e73ff5-1700-0000-7d63-2281a50c0000 pid=3237 clone guuid=ae1238f5-1700-0000-7d63-2281a40c0000 pid=3236->13b61a20-73c3-532b-a681-77884528fd4d send: 141B 91fd5ef1-d330-5ca9-bbc8-e3be2a174ffb 94.249.228.212:6767 guuid=02e73ff5-1700-0000-7d63-2281a50c0000 pid=3237->91fd5ef1-d330-5ca9-bbc8-e3be2a174ffb send: 413B guuid=cb2caefc-1700-0000-7d63-2281b20c0000 pid=3250->13b61a20-73c3-532b-a681-77884528fd4d send: 138B guuid=fcb6f904-1800-0000-7d63-2281c20c0000 pid=3266->13b61a20-73c3-532b-a681-77884528fd4d send: 138B guuid=8035d70d-1800-0000-7d63-2281d30c0000 pid=3283->13b61a20-73c3-532b-a681-77884528fd4d send: 140B guuid=a4f54c15-1800-0000-7d63-2281ed0c0000 pid=3309->13b61a20-73c3-532b-a681-77884528fd4d send: 141B guuid=dbcf841b-1800-0000-7d63-2281000d0000 pid=3328->13b61a20-73c3-532b-a681-77884528fd4d send: 139B guuid=40c13020-1800-0000-7d63-2281120d0000 pid=3346->13b61a20-73c3-532b-a681-77884528fd4d send: 137B guuid=8375e826-1800-0000-7d63-22811d0d0000 pid=3357->13b61a20-73c3-532b-a681-77884528fd4d send: 137B guuid=47b5812e-1800-0000-7d63-22812c0d0000 pid=3372->13b61a20-73c3-532b-a681-77884528fd4d send: 138B guuid=43a80134-1800-0000-7d63-2281370d0000 pid=3383 /home/sandbox/iran.i486 guuid=849a9a33-1800-0000-7d63-2281360d0000 pid=3382->guuid=43a80134-1800-0000-7d63-2281370d0000 pid=3383 clone guuid=41a90e34-1800-0000-7d63-2281380d0000 pid=3384 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=43a80134-1800-0000-7d63-2281370d0000 pid=3383->guuid=41a90e34-1800-0000-7d63-2281380d0000 pid=3384 clone guuid=41a90e34-1800-0000-7d63-2281380d0000 pid=3384->91fd5ef1-d330-5ca9-bbc8-e3be2a174ffb send: 1102B guuid=89f10e34-1800-0000-7d63-2281390d0000 pid=3385->13b61a20-73c3-532b-a681-77884528fd4d send: 140B guuid=8de8a83a-1800-0000-7d63-22814f0d0000 pid=3407->13b61a20-73c3-532b-a681-77884528fd4d send: 140B guuid=0ffccd41-1800-0000-7d63-22815f0d0000 pid=3423->13b61a20-73c3-532b-a681-77884528fd4d send: 140B guuid=f3068e48-1800-0000-7d63-22817a0d0000 pid=3450->13b61a20-73c3-532b-a681-77884528fd4d send: 140B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-03-25 21:35:39 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 05b42d715d54d8323e5880d2e8081ad1fbe2a1ecbdb6f125cfcca011a042079e

(this sample)

  
Delivery method
Distributed via web download

Comments