MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 44dca0ac7852590a803d7119795bfdfc15c2ee009c0ca4a4400c3f5befdb26f5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 44dca0ac7852590a803d7119795bfdfc15c2ee009c0ca4a4400c3f5befdb26f5
SHA3-384 hash: e3dddb9ab78b3e4d27f777dda5d6fdc3981eef9ecffbbde01de6957f91ea32e91740ccb5050eb2a619ed41dd4a7c82a3
SHA1 hash: ed655b62e21c1de8dc20764e481ffa6363ff2356
MD5 hash: cc22b0c8c54a47693d2ccad2ffa9807c
humanhash: victor-winner-oven-south
File name:cat.sh
Download: download sample
Signature Mirai
File size:910 bytes
First seen:2026-06-05 11:05:04 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:tmxTQJKF1JQ397TQIQJIQA3Q+7qtOek3Q+7qtOfy:toTMG1Ji7T9wIPaGDy
TLSH T16C110AF44370A0F39595103F7785EE60388100D39C8CF87D6C6A5E21CBA064CB586AED
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.144/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox opendir
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-29T17:36:00Z UTC
Last seen:
2026-06-05T13:04:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=56eb966a-1b00-0000-8c6f-2ce1cd0a0000 pid=2765 /usr/bin/sudo guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770 /tmp/sample.bin guuid=56eb966a-1b00-0000-8c6f-2ce1cd0a0000 pid=2765->guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770 execve guuid=40c2806c-1b00-0000-8c6f-2ce1d40a0000 pid=2772 /usr/bin/wget net send-data write-file guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770->guuid=40c2806c-1b00-0000-8c6f-2ce1d40a0000 pid=2772 execve guuid=a4027374-1b00-0000-8c6f-2ce1de0a0000 pid=2782 /usr/bin/chmod guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770->guuid=a4027374-1b00-0000-8c6f-2ce1de0a0000 pid=2782 execve guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784 /tmp/bot net guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770->guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784 execve guuid=f57a52ec-1b00-0000-8c6f-2ce1bf0b0000 pid=3007 /usr/bin/rm delete-file guuid=3a49406c-1b00-0000-8c6f-2ce1d20a0000 pid=2770->guuid=f57a52ec-1b00-0000-8c6f-2ce1bf0b0000 pid=3007 execve 7ffd75cd-29ce-5847-9dc7-ea4e373368ce 176.65.139.144:80 guuid=40c2806c-1b00-0000-8c6f-2ce1d40a0000 pid=2772->7ffd75cd-29ce-5847-9dc7-ea4e373368ce send: 140B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d57ffd74-1b00-0000-8c6f-2ce1e20a0000 pid=2786 /tmp/bot guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784->guuid=d57ffd74-1b00-0000-8c6f-2ce1e20a0000 pid=2786 clone guuid=2887a3b0-1b00-0000-8c6f-2ce1470b0000 pid=2887 /tmp/bot guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784->guuid=2887a3b0-1b00-0000-8c6f-2ce1470b0000 pid=2887 clone guuid=2f4447ec-1b00-0000-8c6f-2ce1bc0b0000 pid=3004 /tmp/bot guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784->guuid=2f4447ec-1b00-0000-8c6f-2ce1bc0b0000 pid=3004 clone guuid=36b149ec-1b00-0000-8c6f-2ce1bd0b0000 pid=3005 /tmp/bot net zombie guuid=c8bdde74-1b00-0000-8c6f-2ce1e00a0000 pid=2784->guuid=36b149ec-1b00-0000-8c6f-2ce1bd0b0000 pid=3005 clone 498bdfdc-b7fa-5b8c-949e-907de2a6a834 176.65.139.144:1999 guuid=36b149ec-1b00-0000-8c6f-2ce1bd0b0000 pid=3005->498bdfdc-b7fa-5b8c-949e-907de2a6a834 con
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments