MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3ee803dfc08cd7385b83fa53296f806f37015762c023933647bc60e8d7a209d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 3ee803dfc08cd7385b83fa53296f806f37015762c023933647bc60e8d7a209d8
SHA3-384 hash: 17d43a7c85cb28202a13ddcc62b2e4bf8acf84a87fd59ef69f28f1a4bfb270563bfec325ae810d0774f6773597fe40bb
SHA1 hash: c3fd5a6a5bf5a4e34a68eaa8668b1ebe45123348
MD5 hash: e6019ad71a3c2d1770f686c7bac62cab
humanhash: oven-table-finch-sweet
File name:payloads.sh
Download: download sample
Signature Mirai
File size:1'486 bytes
First seen:2026-08-02 13:53:40 UTC
Last seen:2026-08-03 07:19:44 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:TDJ44eltnrPf75z1VwEF0E7G/lft1h81dV5/RnTNI7DzK0NfiecFFYbJvA/xPS+p:TDJAbnrPfJ1Vws0Dl3h81dV1RnIDzF1g
TLSH T18D314FED6020905316C9DE22B3B245ADA017AEEE34E88EF7FC655C325C98740F139B41
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://193.25.217.70/i5865631a8bec0425290ca8f34b1804334e9f9c110f07c05af808acc6ec994e82ad3 Miraielf mirai ua-wget
http://193.25.217.70/i686n/an/an/a
http://193.25.217.70/x86_644e247c3ac69c652cba2a80e221d0eb18200da8464f90eed71f949db0d3b20b65 Miraielf mirai ua-wget x86
http://193.25.217.70/mips76750b809eeafa56c877a2b31af1fd62c05244a0cd6438aedfbc9c385c771abc Miraielf mirai ua-wget
http://193.25.217.70/mpsl6bc5a031131d30d056fd21d268c5e2978667f8cd811f7ed4e726177118778f61 Miraielf mirai ua-wget
http://193.25.217.70/ppc6ec5efb339a2245d1f851077a603fea742bddf17fb88072a6ba0281cf43b392f Miraielf mirai ua-wget
http://193.25.217.70/sh4n/an/aelf ua-wget
http://193.25.217.70/arm727bb0d66f46ca65b38bb39eda4e98fe35a9da523a9af0c6dee5855f345295ad Miraielf mirai ua-wget
http://193.25.217.70/arm52279e2d6c16091785e5ddf12e446f096ff8e78b64ddee0b4ebbebd6a322b76e7 Miraielf mirai ua-wget
http://193.25.217.70/arm6eb18799c60c7673c3dffef1c45f35afb8c65439490bf4086e11fba5687ec967d Miraielf mirai ua-wget
http://193.25.217.70/arm77a3e260d7dec64aee8169ab40edacb787462470fb6e1ba47119b022fd8143501 Miraielf iot mirai
http://193.25.217.70/arm64n/an/aelf ua-wget
http://193.25.217.70/arc919ec6711eccb134db1ec8df1c0804538e5188286203e17b36a5a9b1289038bd Miraielf mirai ua-wget
http://193.25.217.70/spcn/an/aelf ua-wget
http://193.25.217.70/m68kn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-02T11:24:00Z UTC
Last seen:
2026-08-02T12:38:00Z UTC
Hits:
~10
Threat name:
Linux.Trojan.Ravartar
Status:
Malicious
First seen:
2026-08-02 13:55:52 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3ee803dfc08cd7385b83fa53296f806f37015762c023933647bc60e8d7a209d8

(this sample)

  
Delivery method
Distributed via web download

Comments