🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0dc6e9ab513cbaf8d0acb430f535aa2e172b39bddee095325da2d3ab0b20360b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA 1 File information Comments

SHA256 hash: 0dc6e9ab513cbaf8d0acb430f535aa2e172b39bddee095325da2d3ab0b20360b
SHA3-384 hash: 51626d2f599514f43ecc4dc1674af313f0478a7c8be8efecf820be825799c8ada6539b4e85a69ba14c59e1c41a2a1c34
SHA1 hash: 6d9c929ace5be3bf6281821fa033b47814e1d00f
MD5 hash: 5b2e202006abca7ada3da8713ea00756
humanhash: oranges-romeo-carolina-monkey
File name:w.sh
Download: download sample
Signature Mirai
File size:1'032 bytes
First seen:2026-10-08 06:32:42 UTC
Last seen:2026-10-08 06:59:04 UTC
File type: sh
MIME type:text/plain
ssdeep 24:8GcVc1NIhcPKiclcqq/vEcvcjQcCcJgckS2:8GcVcmcPbclcT8cvcjQcCcqc/2
TLSH T1AA11FBCA0398E012C5FECF84355A8808F6448AE278DF5A6DA88C9DF5A5C5A18F176F4C
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.206/bins/byte.arm646d2c2b982fa7f0a03758e2ed510e62fe83f7615439a0a87c21871f97be21d3 Miraimirai
http://176.65.139.206/bins/byte.arm557f18c9421269aa939e0c5d486ef6ee893e63b8328bdaf2bf858c8afbd795a1e Miraimirai
http://176.65.139.206/bins/byte.arm666ea28fece6226bd17f4cc9ce6bfa4c345298512aaf98ae9a95ea050bebe147b Miraimirai
http://176.65.139.206/bins/byte.arm721492d4240365a15d22cc2a3ac6514e0b79e99f98187424f280d191b3de3d150 Miraimirai
http://176.65.139.206/bins/byte.i486n/an/an/a
http://176.65.139.206/bins/byte.powerpcn/an/an/a
http://176.65.139.206/bins/byte.mipsc2a818ea8a264fd9d077ddf02a3a81c8c2f044313df985528744e376898fc634 Miraimirai
http://176.65.139.206/bins/byte.mpsleaf5c116efff46d774786e528fa62edb32274396116b8361ff47c4c9d6c43849 Miraimirai
http://176.65.139.206/bins/byte.i586n/an/an/a
http://176.65.139.206/bins/byte.x8673ec11b932a4ee1a575b6fd4268151532bb89c1d1f0b9a5893fd0c96e4db06c8 Miraimirai
http://176.65.139.206/bins/byte.sh4cdc890877ccbe9d0388524061a79a7789e4629f48d5863480e8ee544db6cd055 Miraimirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=605ef087-1600-0000-6ab0-f819490c0000 pid=3145 /usr/bin/sudo guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158 /tmp/sample.bin guuid=605ef087-1600-0000-6ab0-f819490c0000 pid=3145->guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158 execve guuid=306d018d-1600-0000-6ab0-f819580c0000 pid=3160 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=306d018d-1600-0000-6ab0-f819580c0000 pid=3160 execve guuid=17f76a90-1600-0000-6ab0-f819640c0000 pid=3172 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=17f76a90-1600-0000-6ab0-f819640c0000 pid=3172 execve guuid=09609c90-1600-0000-6ab0-f819660c0000 pid=3174 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=09609c90-1600-0000-6ab0-f819660c0000 pid=3174 clone guuid=94414b92-1600-0000-6ab0-f8196b0c0000 pid=3179 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=94414b92-1600-0000-6ab0-f8196b0c0000 pid=3179 execve guuid=b89e7296-1600-0000-6ab0-f819730c0000 pid=3187 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=b89e7296-1600-0000-6ab0-f819730c0000 pid=3187 execve guuid=749a7097-1600-0000-6ab0-f819750c0000 pid=3189 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=749a7097-1600-0000-6ab0-f819750c0000 pid=3189 clone guuid=97bd2299-1600-0000-6ab0-f819780c0000 pid=3192 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=97bd2299-1600-0000-6ab0-f819780c0000 pid=3192 execve guuid=0d249b9d-1600-0000-6ab0-f819810c0000 pid=3201 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=0d249b9d-1600-0000-6ab0-f819810c0000 pid=3201 execve guuid=20d8e69d-1600-0000-6ab0-f819830c0000 pid=3203 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=20d8e69d-1600-0000-6ab0-f819830c0000 pid=3203 clone guuid=08dc7c9e-1600-0000-6ab0-f819860c0000 pid=3206 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=08dc7c9e-1600-0000-6ab0-f819860c0000 pid=3206 execve guuid=ddfca4a2-1600-0000-6ab0-f819930c0000 pid=3219 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=ddfca4a2-1600-0000-6ab0-f819930c0000 pid=3219 execve guuid=326adaa2-1600-0000-6ab0-f819950c0000 pid=3221 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=326adaa2-1600-0000-6ab0-f819950c0000 pid=3221 clone guuid=2e1480a4-1600-0000-6ab0-f819990c0000 pid=3225 /usr/bin/busybox net send-data guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=2e1480a4-1600-0000-6ab0-f819990c0000 pid=3225 execve guuid=303768a6-1600-0000-6ab0-f8199a0c0000 pid=3226 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=303768a6-1600-0000-6ab0-f8199a0c0000 pid=3226 execve guuid=4a37d6a6-1600-0000-6ab0-f8199b0c0000 pid=3227 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=4a37d6a6-1600-0000-6ab0-f8199b0c0000 pid=3227 clone guuid=b641e9a6-1600-0000-6ab0-f8199c0c0000 pid=3228 /usr/bin/busybox net send-data guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=b641e9a6-1600-0000-6ab0-f8199c0c0000 pid=3228 execve guuid=4f5de9a8-1600-0000-6ab0-f8199d0c0000 pid=3229 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=4f5de9a8-1600-0000-6ab0-f8199d0c0000 pid=3229 execve guuid=f6895aa9-1600-0000-6ab0-f8199e0c0000 pid=3230 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=f6895aa9-1600-0000-6ab0-f8199e0c0000 pid=3230 clone guuid=f41d6aa9-1600-0000-6ab0-f8199f0c0000 pid=3231 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=f41d6aa9-1600-0000-6ab0-f8199f0c0000 pid=3231 execve guuid=faa27dad-1600-0000-6ab0-f819a20c0000 pid=3234 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=faa27dad-1600-0000-6ab0-f819a20c0000 pid=3234 execve guuid=c1c2bead-1600-0000-6ab0-f819a40c0000 pid=3236 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=c1c2bead-1600-0000-6ab0-f819a40c0000 pid=3236 clone guuid=ef8093ae-1600-0000-6ab0-f819a80c0000 pid=3240 /usr/bin/busybox net send-data write-file guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=ef8093ae-1600-0000-6ab0-f819a80c0000 pid=3240 execve guuid=61b111b3-1600-0000-6ab0-f819af0c0000 pid=3247 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=61b111b3-1600-0000-6ab0-f819af0c0000 pid=3247 execve guuid=656d95b3-1600-0000-6ab0-f819b10c0000 pid=3249 /usr/bin/dash guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=656d95b3-1600-0000-6ab0-f819b10c0000 pid=3249 clone guuid=ff3209b5-1600-0000-6ab0-f819b80c0000 pid=3256 /usr/bin/busybox net send-data guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=ff3209b5-1600-0000-6ab0-f819b80c0000 pid=3256 execve guuid=b68ddcb6-1600-0000-6ab0-f819bc0c0000 pid=3260 /usr/bin/chmod guuid=18c4aa8c-1600-0000-6ab0-f819560c0000 pid=3158->guuid=b68ddcb6-1600-0000-6ab0-f819bc0c0000 pid=3260 execve 154ae0c8-0a48-5314-8e17-6b610ebcef8a 176.65.139.206:80 guuid=306d018d-1600-0000-6ab0-f819580c0000 pid=3160->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 90B guuid=94414b92-1600-0000-6ab0-f8196b0c0000 pid=3179->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=97bd2299-1600-0000-6ab0-f819780c0000 pid=3192->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=08dc7c9e-1600-0000-6ab0-f819860c0000 pid=3206->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=2e1480a4-1600-0000-6ab0-f819990c0000 pid=3225->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=b641e9a6-1600-0000-6ab0-f8199c0c0000 pid=3228->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 94B guuid=f41d6aa9-1600-0000-6ab0-f8199f0c0000 pid=3231->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=ef8093ae-1600-0000-6ab0-f819a80c0000 pid=3240->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B guuid=ff3209b5-1600-0000-6ab0-f819b80c0000 pid=3256->154ae0c8-0a48-5314-8e17-6b610ebcef8a send: 91B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0dc6e9ab513cbaf8d0acb430f535aa2e172b39bddee095325da2d3ab0b20360b

(this sample)

  
Delivery method
Distributed via web download

Comments