MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cce7e68e0b7c086bb358f7b158a406f6f89a7875d4fc0a603f30c42cb00ea91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 0cce7e68e0b7c086bb358f7b158a406f6f89a7875d4fc0a603f30c42cb00ea91
SHA3-384 hash: cdfb7a0821e82939231b1d852c1f9f97a02e2eeda9cb0795d18a7c599ac3f82aaa284fc3a4490817c03e36a3cef0c033
SHA1 hash: 59128c14427ed45d9d7c454c229504cfef31abd3
MD5 hash: e0b18c44aca13bbba16e57e308aa61d6
humanhash: sierra-skylark-potato-autumn
File name:kla.sh
Download: download sample
Signature Mirai
File size:3'037 bytes
First seen:2026-08-11 10:52:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:2RKhEcfEnsTE1hxzTfTT9zsTYz1T/zHTlzKTCzT3Tpz0TgzwTkzlTvzcTC:2RKhEcfEnsTE1DXf
TLSH T156516FC8119268717CF69C2772698854F8C47582EDCA6F05E8DCB4F998CCF0AB515BB3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.196/bins/px86e4cd66ba7e44b256b91b283dce904958d9b1c85a9965a4bebe47b083db5ff895 Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/pmips873df9f9b60344695b19bcdc2d8f6a110a9ea91450002e0b459b2a70eb56356e Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/pmpsl3b4b7f01fa9afb83a6f113ce0a1d3c9a99a3e6e96270fe0bd727132f0e7709fb Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/parmdeb4f056a5af396e45dd7cf16ab50668c61b87a16936174f79bf8e1f55e5e0ff Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/parm5839bb3c86603faa0a64b4ff57cbe1155c313e48be2350ab240918869e6c476ca Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/parm6b0e480d15a4175e1d6959523be61637d1316edd2dacc29a60959338197b62ae4 Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/parm7c99d0a338e78aa0bfbdf9af89333c38d8bcb79f3493e9eb083e17252c34b0fbe Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/pppca50465a50e203741124b3914c4ec7d46b94ec9af2437febab3803000e79e9c82 Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/pm68k34a7a0c034006b793876421ee00f70a5318a65b15837f11e77d4f7d5e7b33ac5 Mirai176-65-139-196 elf mirai ua-wget
http://176.65.139.196/bins/psh45461c955af9b8b817fcd6185e12d2a1d728b4b55752a35b45fd117e273e02340 Mirai176-65-139-196 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox downloader evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-11T08:10:00Z UTC
Last seen:
2026-08-11T17:40:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=738514ca-2000-0000-d71d-4123c9090000 pid=2505 /usr/bin/sudo guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509 /tmp/sample.bin guuid=738514ca-2000-0000-d71d-4123c9090000 pid=2505->guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509 execve guuid=8303fecb-2000-0000-d71d-4123cf090000 pid=2511 /usr/bin/cp guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=8303fecb-2000-0000-d71d-4123cf090000 pid=2511 execve guuid=b6da3dcd-2000-0000-d71d-4123d2090000 pid=2514 /usr/bin/bash guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=b6da3dcd-2000-0000-d71d-4123d2090000 pid=2514 clone guuid=c0015bf1-2000-0000-d71d-4123300a0000 pid=2608 /usr/bin/chmod guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=c0015bf1-2000-0000-d71d-4123300a0000 pid=2608 execve guuid=539299f1-2000-0000-d71d-4123320a0000 pid=2610 /tmp/robben delete-file net guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=539299f1-2000-0000-d71d-4123320a0000 pid=2610 execve guuid=db15dff1-2000-0000-d71d-4123340a0000 pid=2612 /usr/bin/bash guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=db15dff1-2000-0000-d71d-4123340a0000 pid=2612 clone guuid=b07a50f8-2000-0000-d71d-4123490a0000 pid=2633 /usr/bin/bash guuid=aa31b1cb-2000-0000-d71d-4123cd090000 pid=2509->guuid=b07a50f8-2000-0000-d71d-4123490a0000 pid=2633 clone guuid=1d6849cd-2000-0000-d71d-4123d3090000 pid=2515 /usr/bin/wget net send-data write-file guuid=b6da3dcd-2000-0000-d71d-4123d2090000 pid=2514->guuid=1d6849cd-2000-0000-d71d-4123d3090000 pid=2515 execve dce5612b-bba8-57fb-9780-82391742e9de 176.65.139.196:80 guuid=1d6849cd-2000-0000-d71d-4123d3090000 pid=2515->dce5612b-bba8-57fb-9780-82391742e9de send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=539299f1-2000-0000-d71d-4123320a0000 pid=2610->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611 /tmp/robben net send-data zombie guuid=539299f1-2000-0000-d71d-4123320a0000 pid=2610->guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611 clone guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 6156d5e1-f80b-5d5a-92c7-6baaea1eca19 176.65.139.196:18129 guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611->6156d5e1-f80b-5d5a-92c7-6baaea1eca19 send: 13B guuid=3743e7f1-2000-0000-d71d-4123350a0000 pid=2613 /tmp/robben guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611->guuid=3743e7f1-2000-0000-d71d-4123350a0000 pid=2613 clone guuid=8831edf1-2000-0000-d71d-4123370a0000 pid=2615 /tmp/robben delete-file guuid=c710cef1-2000-0000-d71d-4123330a0000 pid=2611->guuid=8831edf1-2000-0000-d71d-4123370a0000 pid=2615 clone guuid=1813edf1-2000-0000-d71d-4123360a0000 pid=2614 /usr/bin/wget net send-data write-file guuid=db15dff1-2000-0000-d71d-4123340a0000 pid=2612->guuid=1813edf1-2000-0000-d71d-4123360a0000 pid=2614 execve guuid=1813edf1-2000-0000-d71d-4123360a0000 pid=2614->dce5612b-bba8-57fb-9780-82391742e9de send: 139B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-11 10:49:48 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0cce7e68e0b7c086bb358f7b158a406f6f89a7875d4fc0a603f30c42cb00ea91

(this sample)

  
Delivery method
Distributed via web download

Comments