MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11bd0fb5a8a00f4908e32d16772401dfa2ad8f1cac9e7106268517ae5bde57a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 11bd0fb5a8a00f4908e32d16772401dfa2ad8f1cac9e7106268517ae5bde57a2
SHA3-384 hash: 2cbe529009587a05ef178dd0d7f83287af7ac3af43be93cb2fa7e42f320847cf26b744f28c9ad002a95a07c97c030ece
SHA1 hash: 144f319045a2a1728de7ed4b623a5c3f670a06f6
MD5 hash: 26655d6071cca71b169fe4bc5dbbb17a
humanhash: hamper-high-tango-jig
File name:payloads.sh
Download: download sample
Signature Mirai
File size:1'580 bytes
First seen:2026-08-02 10:04:26 UTC
Last seen:2026-08-02 16:15:27 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:TxoDJAbnrPfJ1Vws0Dl3h81dV1RnIDzF1iecFFY1vexPS+p:TxoDJAbnrPfJ1Cs0Dl3h8rnBIDzF1GF5
TLSH T1EE315EED6020915316C9DE22B3B249ADA017AEEE34E88EFBFC655C325C88740F139B45
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.25.217.70/x86n/an/aelf ua-wget
http://193.25.217.70/i5865631a8bec0425290ca8f34b1804334e9f9c110f07c05af808acc6ec994e82ad3 Miraielf mirai ua-wget
http://193.25.217.70/i686n/an/an/a
http://193.25.217.70/x86_644e247c3ac69c652cba2a80e221d0eb18200da8464f90eed71f949db0d3b20b65 Miraielf mirai ua-wget x86
http://193.25.217.70/mips76750b809eeafa56c877a2b31af1fd62c05244a0cd6438aedfbc9c385c771abc Miraielf mirai ua-wget
http://193.25.217.70/mpsl6bc5a031131d30d056fd21d268c5e2978667f8cd811f7ed4e726177118778f61 Miraielf mirai ua-wget
http://193.25.217.70/ppc6ec5efb339a2245d1f851077a603fea742bddf17fb88072a6ba0281cf43b392f Miraielf mirai ua-wget
http://193.25.217.70/sh4n/an/aelf ua-wget
http://193.25.217.70/arm727bb0d66f46ca65b38bb39eda4e98fe35a9da523a9af0c6dee5855f345295ad Miraielf mirai ua-wget
http://193.25.217.70/arm52279e2d6c16091785e5ddf12e446f096ff8e78b64ddee0b4ebbebd6a322b76e7 Miraielf mirai ua-wget
http://193.25.217.70/arm6eb18799c60c7673c3dffef1c45f35afb8c65439490bf4086e11fba5687ec967d Miraielf mirai ua-wget
http://193.25.217.70/arm77a3e260d7dec64aee8169ab40edacb787462470fb6e1ba47119b022fd8143501 Miraielf iot mirai
http://193.25.217.70/arm64n/an/aelf ua-wget
http://193.25.217.70/arc919ec6711eccb134db1ec8df1c0804538e5188286203e17b36a5a9b1289038bd Miraielf mirai ua-wget
http://193.25.217.70/spcn/an/aelf ua-wget
http://193.25.217.70/m68kn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-01T04:52:00Z UTC
Last seen:
2026-08-03T01:33:00Z UTC
Hits:
~10
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-08-01 19:02:00 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 11bd0fb5a8a00f4908e32d16772401dfa2ad8f1cac9e7106268517ae5bde57a2

(this sample)

  
Delivery method
Distributed via web download

Comments