MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d128c8e07d969d43afce0bf3906aaa6761ef1df20b3e8e0ca87a16109a3a728. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3d128c8e07d969d43afce0bf3906aaa6761ef1df20b3e8e0ca87a16109a3a728
SHA3-384 hash: 56d584c858f911c53d8329b503ff3f6a0d0bbde643a0708254635a27c6f7240ffa7816d0c73e7d9e80fdc55216b90725
SHA1 hash: 2e1c93e1a738483e395151e0e643fa37b06a873f
MD5 hash: 9e26d47c42fe2d4a432862aaf3f40bb9
humanhash: foxtrot-oxygen-texas-oscar
File name:kozak.sh
Download: download sample
Signature Mirai
File size:700 bytes
First seen:2026-06-06 15:17:37 UTC
Last seen:2026-06-07 10:21:37 UTC
File type: sh
MIME type:text/plain
ssdeep 12:nBSn6v/P3rvZBGFGgHGj0Xbc0/WHnA6d2QzNI1dT1BdRBM5dF:BDz9RwKtXNIjNMfF
TLSH T11E011EBF02236B019DA2CD5C79728CE06017E1C1E699DE49FD44052ABAC86873074EC7
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.202.246.143/bins/px86aae409e4581181da21ff16c3a5d37f3174e452efdc931d24b7c7d6e1c8fa8e8b Miraielf mirai opendir ua-wget x86
http://45.202.246.143/bins/pspc061e27e0e97210daa13bd25f0e9890ae201a2686660450c9271497b205ddb7bb Miraielf mirai opendir sparc ua-wget
http://45.202.246.143/bins/psh4e837348b80609cc32cbdd458e8aae513e8da0118f8df1058828cbfc41d13e80c Miraielf mirai opendir SuperH ua-wget
http://45.202.246.143/bins/pppc5ab013ae83e454d3a194668932415d7e58a4b74f9607d59d5926960772467352 Miraielf mirai opendir PowerPC ua-wget
http://45.202.246.143/bins/pmpsl270fde17a9f061cff46f5eae65620245e8928be6e8b05481915d42671a3c92ac Miraielf mips mirai opendir ua-wget
http://45.202.246.143/bins/pmipsa54dea35ca01c650d35d385bfa81f3761136cf726b15e1bf48ccd00943730742 Miraielf mips mirai opendir ua-wget
http://45.202.246.143/bins/pm68k0d15fb0861bfba3672af309c97476da396ecd5fab4861be5e5af536bc9043884 Miraielf m68k mirai opendir ua-wget
http://45.202.246.143/bins/parm720001163c5501357c08b00ad9ff0139be8c0c048d9e8f5325fcfd11e79759c14 Miraiarm elf mirai opendir ua-wget
http://45.202.246.143/bins/parm6e95bf884f199174ae9fffa4faca0d18318491211c6bb5496d1e06aedbdc6be8d Miraiarm elf mirai opendir ua-wget
http://45.202.246.143/bins/parm54041e6034b940d0d487dd1f8b2108ef7d25f0f1c22997dc3c77601e0fc003d97 Miraiarm elf mirai opendir ua-wget
http://45.202.246.143/bins/parm54b8a11267ae2127a5f7101f90addee26b0e29ebd99af449557e6e7f917486b1 Miraiarm elf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
5
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash evasive lolbin
Verdict:
Malicious
File Type:
text
First seen:
2026-06-06T10:56:00Z UTC
Last seen:
2026-06-06T11:22:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c5c876d9-1900-0000-ea52-bad00c080000 pid=2060 /usr/bin/sudo guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068 /tmp/sample.bin guuid=c5c876d9-1900-0000-ea52-bad00c080000 pid=2060->guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068 execve guuid=be4e51dc-1900-0000-ea52-bad016080000 pid=2070 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=be4e51dc-1900-0000-ea52-bad016080000 pid=2070 execve guuid=61fc8011-1a00-0000-ea52-bad084080000 pid=2180 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=61fc8011-1a00-0000-ea52-bad084080000 pid=2180 execve guuid=61ad0012-1a00-0000-ea52-bad086080000 pid=2182 /home/sandbox/px86 delete-file net guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=61ad0012-1a00-0000-ea52-bad086080000 pid=2182 execve guuid=02d03312-1a00-0000-ea52-bad089080000 pid=2185 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=02d03312-1a00-0000-ea52-bad089080000 pid=2185 execve guuid=a6e14a51-1a00-0000-ea52-bad026090000 pid=2342 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=a6e14a51-1a00-0000-ea52-bad026090000 pid=2342 execve guuid=244d8451-1a00-0000-ea52-bad028090000 pid=2344 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=244d8451-1a00-0000-ea52-bad028090000 pid=2344 clone guuid=a2d81052-1a00-0000-ea52-bad02c090000 pid=2348 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=a2d81052-1a00-0000-ea52-bad02c090000 pid=2348 execve guuid=50d0e384-1a00-0000-ea52-bad094090000 pid=2452 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=50d0e384-1a00-0000-ea52-bad094090000 pid=2452 execve guuid=90f44b85-1a00-0000-ea52-bad096090000 pid=2454 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=90f44b85-1a00-0000-ea52-bad096090000 pid=2454 clone guuid=d8b90e86-1a00-0000-ea52-bad09b090000 pid=2459 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=d8b90e86-1a00-0000-ea52-bad09b090000 pid=2459 execve guuid=4e7942c1-1a00-0000-ea52-bad01d0a0000 pid=2589 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=4e7942c1-1a00-0000-ea52-bad01d0a0000 pid=2589 execve guuid=2e2dcfc1-1a00-0000-ea52-bad01f0a0000 pid=2591 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=2e2dcfc1-1a00-0000-ea52-bad01f0a0000 pid=2591 clone guuid=04645bc2-1a00-0000-ea52-bad0220a0000 pid=2594 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=04645bc2-1a00-0000-ea52-bad0220a0000 pid=2594 execve guuid=7324a800-1b00-0000-ea52-bad0cc0a0000 pid=2764 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=7324a800-1b00-0000-ea52-bad0cc0a0000 pid=2764 execve guuid=fc713901-1b00-0000-ea52-bad0ce0a0000 pid=2766 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=fc713901-1b00-0000-ea52-bad0ce0a0000 pid=2766 clone guuid=c34bfc01-1b00-0000-ea52-bad0d20a0000 pid=2770 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=c34bfc01-1b00-0000-ea52-bad0d20a0000 pid=2770 execve guuid=c32fc03b-1b00-0000-ea52-bad0300b0000 pid=2864 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=c32fc03b-1b00-0000-ea52-bad0300b0000 pid=2864 execve guuid=2d84f33c-1b00-0000-ea52-bad0320b0000 pid=2866 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=2d84f33c-1b00-0000-ea52-bad0320b0000 pid=2866 clone guuid=9e80de3d-1b00-0000-ea52-bad0360b0000 pid=2870 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=9e80de3d-1b00-0000-ea52-bad0360b0000 pid=2870 execve guuid=ab90fd78-1b00-0000-ea52-bad0aa0b0000 pid=2986 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=ab90fd78-1b00-0000-ea52-bad0aa0b0000 pid=2986 execve guuid=9a795879-1b00-0000-ea52-bad0ab0b0000 pid=2987 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=9a795879-1b00-0000-ea52-bad0ab0b0000 pid=2987 clone guuid=816c057a-1b00-0000-ea52-bad0ad0b0000 pid=2989 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=816c057a-1b00-0000-ea52-bad0ad0b0000 pid=2989 execve guuid=0982f2bd-1b00-0000-ea52-bad0480c0000 pid=3144 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=0982f2bd-1b00-0000-ea52-bad0480c0000 pid=3144 execve guuid=8f7445be-1b00-0000-ea52-bad04a0c0000 pid=3146 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=8f7445be-1b00-0000-ea52-bad04a0c0000 pid=3146 clone guuid=457de4be-1b00-0000-ea52-bad04e0c0000 pid=3150 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=457de4be-1b00-0000-ea52-bad04e0c0000 pid=3150 execve guuid=1517e4f6-1b00-0000-ea52-bad09c0c0000 pid=3228 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=1517e4f6-1b00-0000-ea52-bad09c0c0000 pid=3228 execve guuid=94354cf7-1b00-0000-ea52-bad09e0c0000 pid=3230 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=94354cf7-1b00-0000-ea52-bad09e0c0000 pid=3230 clone guuid=98c8ecf7-1b00-0000-ea52-bad0a10c0000 pid=3233 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=98c8ecf7-1b00-0000-ea52-bad0a10c0000 pid=3233 execve guuid=016b832c-1c00-0000-ea52-bad0dd0c0000 pid=3293 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=016b832c-1c00-0000-ea52-bad0dd0c0000 pid=3293 execve guuid=2418452d-1c00-0000-ea52-bad0de0c0000 pid=3294 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=2418452d-1c00-0000-ea52-bad0de0c0000 pid=3294 clone guuid=e954352f-1c00-0000-ea52-bad0e10c0000 pid=3297 /usr/bin/wget net send-data write-file guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=e954352f-1c00-0000-ea52-bad0e10c0000 pid=3297 execve guuid=4690c264-1c00-0000-ea52-bad0410d0000 pid=3393 /usr/bin/chmod guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=4690c264-1c00-0000-ea52-bad0410d0000 pid=3393 execve guuid=05c70665-1c00-0000-ea52-bad0430d0000 pid=3395 /usr/bin/dash guuid=957a17dc-1900-0000-ea52-bad014080000 pid=2068->guuid=05c70665-1c00-0000-ea52-bad0430d0000 pid=3395 clone 0c274d21-7053-5e37-b6df-fe24c4c7ffe3 45.202.246.143:80 guuid=be4e51dc-1900-0000-ea52-bad016080000 pid=2070->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 138B 2ec39ec7-c296-5492-8742-85dfe2e7968c 45.202.246.143:53 guuid=61ad0012-1a00-0000-ea52-bad086080000 pid=2182->2ec39ec7-c296-5492-8742-85dfe2e7968c con guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184 /home/sandbox/px86 net send-data zombie guuid=61ad0012-1a00-0000-ea52-bad086080000 pid=2182->guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184 clone guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184->2ec39ec7-c296-5492-8742-85dfe2e7968c con 87cd5a1c-49cb-5568-be7a-c03badc3c0ca 45.202.246.143:18129 guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184->87cd5a1c-49cb-5568-be7a-c03badc3c0ca send: 10B guuid=e4543b12-1a00-0000-ea52-bad08a080000 pid=2186 /home/sandbox/px86 guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184->guuid=e4543b12-1a00-0000-ea52-bad08a080000 pid=2186 clone guuid=033a4112-1a00-0000-ea52-bad08b080000 pid=2187 /home/sandbox/px86 guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184->guuid=033a4112-1a00-0000-ea52-bad08b080000 pid=2187 clone guuid=7b77f660-2300-0000-ea52-bad0bd140000 pid=5309 /home/sandbox/px86 send-data guuid=c73e2d12-1a00-0000-ea52-bad088080000 pid=2184->guuid=7b77f660-2300-0000-ea52-bad0bd140000 pid=5309 clone guuid=02d03312-1a00-0000-ea52-bad089080000 pid=2185->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 138B guuid=a2d81052-1a00-0000-ea52-bad02c090000 pid=2348->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 138B guuid=d8b90e86-1a00-0000-ea52-bad09b090000 pid=2459->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 138B guuid=04645bc2-1a00-0000-ea52-bad0220a0000 pid=2594->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=c34bfc01-1b00-0000-ea52-bad0d20a0000 pid=2770->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=9e80de3d-1b00-0000-ea52-bad0360b0000 pid=2870->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=816c057a-1b00-0000-ea52-bad0ad0b0000 pid=2989->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=457de4be-1b00-0000-ea52-bad04e0c0000 pid=3150->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=98c8ecf7-1b00-0000-ea52-bad0a10c0000 pid=3233->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 139B guuid=e954352f-1c00-0000-ea52-bad0e10c0000 pid=3297->0c274d21-7053-5e37-b6df-fe24c4c7ffe3 send: 138B 3d51a1ed-40ed-5e60-a4d7-c4689978a312 50.7.22.221:80 guuid=7b77f660-2300-0000-ea52-bad0bd140000 pid=5309->3d51a1ed-40ed-5e60-a4d7-c4689978a312 send: 6096336B guuid=3e050161-2300-0000-ea52-bad0be140000 pid=5310 /home/sandbox/px86 guuid=7b77f660-2300-0000-ea52-bad0bd140000 pid=5309->guuid=3e050161-2300-0000-ea52-bad0be140000 pid=5310 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-06 15:14:40 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3d128c8e07d969d43afce0bf3906aaa6761ef1df20b3e8e0ca87a16109a3a728

(this sample)

  
Delivery method
Distributed via web download

Comments