MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 473961d2cdfd1285563626458ba7bd8aeb2285e32351f5c63c5ad2914698527e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 473961d2cdfd1285563626458ba7bd8aeb2285e32351f5c63c5ad2914698527e
SHA3-384 hash: 119bdc0d1586879a3622c2592103bebbb4b1ec0c3f5f849e57c550ab7df8cc46a0156ce0c0ad3c1ee9d66ff24680a1ad
SHA1 hash: f7e4f3ca467e3b7333e3b83633635feb32ccf2b5
MD5 hash: 45a160258e51e30c74ec313f452dbe89
humanhash: jig-blue-video-sweet
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'901 bytes
First seen:2026-06-04 16:21:11 UTC
Last seen:2026-06-04 19:24:54 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:sJrJzIOq/H1lQp5OwaBbp7+fD9o78igqxv4DPy:4e1OrU
TLSH T1F141EECE60F4A143CAEEEE0070E58DC86316B59271DE2B3AEDC12E67C4C9D547129B36
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.121/iran.x86_64fdb23bb9b3ae0a735a7d266aad0270c4d15e6eedf2b55e2191a2827adb42bf6e Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.aarch6470a2c694f99f71b9f50687160576df946aa0913e690ee7ab7c782e639ab57252 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.m68k89ae81fd7960d65e1af50b4c0f67165844fbc3d482096d2d01c8ba05a2a0602d Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.mips4112cdba058d75bde177300a5f2b39cda82064ffe3321f01052eaa91437671d6 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.mipseln/an/a176-65-139-121 elf ua-wget
http://176.65.139.121/iran.powerpcn/an/a176-65-139-121 elf ua-wget
http://176.65.139.121/iran.sparced7d5573aa0ace39b03111f592c40c347ba755f2c78f2e1c59afe0bdc5fb2fec Mirai176-65-139-121 elf ua-wget
http://176.65.139.121/iran.sh47420c8efb8f5506d6537b529b0a8258148a944e51e18a6308a02e8c97c6e0e90 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.arc643961437fea0c9ffa8a92c11ef4ea86368941d2a900032a62c9648e188c5ba5 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.i486cd011ab180e993cd2561ec94cb3974c13c0f088ba1f0974c6f5c1921aa733e65 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.armv4lbe0dcb5bac5a78f56d5db1dc395d5b2668bbeb351a328e93ff3685a353887a4f Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.armv5lff821dfed03f88a2a57934f3b9dbaca04b7a03ccb732542e5f6fa8bac25c5a12 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.armv6le491eededd994278e57901d82b0a110ad90c4f55cf87e1536312d8f413e24ba1 Mirai176-65-139-121 elf mirai ua-wget
http://176.65.139.121/iran.armv7l9962949f5efc98de597354485cbbf487516cbd50379f0d0393ff341e61188f82 Mirai176-65-139-121 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
58
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-03T21:02:00Z UTC
Last seen:
2026-06-06T01:24:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=7d932b1f-1700-0000-f1c9-6618b30d0000 pid=3507 /usr/bin/sudo guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514 /tmp/sample.bin guuid=7d932b1f-1700-0000-f1c9-6618b30d0000 pid=3507->guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514 execve guuid=b989e920-1700-0000-f1c9-6618bc0d0000 pid=3516 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=b989e920-1700-0000-f1c9-6618bc0d0000 pid=3516 execve guuid=dabe7425-1700-0000-f1c9-6618cb0d0000 pid=3531 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=dabe7425-1700-0000-f1c9-6618cb0d0000 pid=3531 execve guuid=95a1ad25-1700-0000-f1c9-6618cd0d0000 pid=3533 /home/sandbox/iran.x86_64 mprotect-exec guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=95a1ad25-1700-0000-f1c9-6618cd0d0000 pid=3533 execve guuid=1b377126-1700-0000-f1c9-6618d20d0000 pid=3538 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=1b377126-1700-0000-f1c9-6618d20d0000 pid=3538 execve guuid=2d86b62b-1700-0000-f1c9-6618e40d0000 pid=3556 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=2d86b62b-1700-0000-f1c9-6618e40d0000 pid=3556 execve guuid=7591102c-1700-0000-f1c9-6618e70d0000 pid=3559 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=7591102c-1700-0000-f1c9-6618e70d0000 pid=3559 clone guuid=5ee8a72c-1700-0000-f1c9-6618ea0d0000 pid=3562 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=5ee8a72c-1700-0000-f1c9-6618ea0d0000 pid=3562 execve guuid=3160fe31-1700-0000-f1c9-6618fb0d0000 pid=3579 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=3160fe31-1700-0000-f1c9-6618fb0d0000 pid=3579 execve guuid=24b13b32-1700-0000-f1c9-6618fd0d0000 pid=3581 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=24b13b32-1700-0000-f1c9-6618fd0d0000 pid=3581 clone guuid=253fc932-1700-0000-f1c9-6618000e0000 pid=3584 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=253fc932-1700-0000-f1c9-6618000e0000 pid=3584 execve guuid=d3fd2738-1700-0000-f1c9-6618130e0000 pid=3603 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=d3fd2738-1700-0000-f1c9-6618130e0000 pid=3603 execve guuid=0b7d5d38-1700-0000-f1c9-6618140e0000 pid=3604 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=0b7d5d38-1700-0000-f1c9-6618140e0000 pid=3604 clone guuid=ebe7e638-1700-0000-f1c9-6618180e0000 pid=3608 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=ebe7e638-1700-0000-f1c9-6618180e0000 pid=3608 execve guuid=4499033e-1700-0000-f1c9-6618280e0000 pid=3624 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=4499033e-1700-0000-f1c9-6618280e0000 pid=3624 execve guuid=65b73c3e-1700-0000-f1c9-6618290e0000 pid=3625 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=65b73c3e-1700-0000-f1c9-6618290e0000 pid=3625 clone guuid=bcbab03e-1700-0000-f1c9-66182d0e0000 pid=3629 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=bcbab03e-1700-0000-f1c9-66182d0e0000 pid=3629 execve guuid=b0f9aa43-1700-0000-f1c9-6618440e0000 pid=3652 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=b0f9aa43-1700-0000-f1c9-6618440e0000 pid=3652 execve guuid=cd18eb43-1700-0000-f1c9-6618460e0000 pid=3654 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=cd18eb43-1700-0000-f1c9-6618460e0000 pid=3654 clone guuid=3d127144-1700-0000-f1c9-6618490e0000 pid=3657 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=3d127144-1700-0000-f1c9-6618490e0000 pid=3657 execve guuid=f3470f47-1700-0000-f1c9-6618560e0000 pid=3670 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=f3470f47-1700-0000-f1c9-6618560e0000 pid=3670 execve guuid=1bba4547-1700-0000-f1c9-6618580e0000 pid=3672 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=1bba4547-1700-0000-f1c9-6618580e0000 pid=3672 clone guuid=6c6fba47-1700-0000-f1c9-66185b0e0000 pid=3675 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=6c6fba47-1700-0000-f1c9-66185b0e0000 pid=3675 execve guuid=f933af4c-1700-0000-f1c9-6618700e0000 pid=3696 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=f933af4c-1700-0000-f1c9-6618700e0000 pid=3696 execve guuid=3fb2e94c-1700-0000-f1c9-6618720e0000 pid=3698 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=3fb2e94c-1700-0000-f1c9-6618720e0000 pid=3698 clone guuid=d15f6b4d-1700-0000-f1c9-6618760e0000 pid=3702 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=d15f6b4d-1700-0000-f1c9-6618760e0000 pid=3702 execve guuid=e2428652-1700-0000-f1c9-66187c0e0000 pid=3708 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=e2428652-1700-0000-f1c9-66187c0e0000 pid=3708 execve guuid=3b8bc452-1700-0000-f1c9-66187f0e0000 pid=3711 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=3b8bc452-1700-0000-f1c9-66187f0e0000 pid=3711 clone guuid=74d1e053-1700-0000-f1c9-6618840e0000 pid=3716 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=74d1e053-1700-0000-f1c9-6618840e0000 pid=3716 execve guuid=cf510559-1700-0000-f1c9-6618930e0000 pid=3731 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=cf510559-1700-0000-f1c9-6618930e0000 pid=3731 execve guuid=0adf3c59-1700-0000-f1c9-6618940e0000 pid=3732 /home/sandbox/iran.i486 guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=0adf3c59-1700-0000-f1c9-6618940e0000 pid=3732 execve guuid=b718a059-1700-0000-f1c9-6618960e0000 pid=3734 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=b718a059-1700-0000-f1c9-6618960e0000 pid=3734 execve guuid=fe29d05e-1700-0000-f1c9-6618ac0e0000 pid=3756 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=fe29d05e-1700-0000-f1c9-6618ac0e0000 pid=3756 execve guuid=f8dd1d5f-1700-0000-f1c9-6618ae0e0000 pid=3758 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=f8dd1d5f-1700-0000-f1c9-6618ae0e0000 pid=3758 clone guuid=4d238760-1700-0000-f1c9-6618b70e0000 pid=3767 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=4d238760-1700-0000-f1c9-6618b70e0000 pid=3767 execve guuid=fd3a0066-1700-0000-f1c9-6618cd0e0000 pid=3789 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=fd3a0066-1700-0000-f1c9-6618cd0e0000 pid=3789 execve guuid=36c55e66-1700-0000-f1c9-6618ce0e0000 pid=3790 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=36c55e66-1700-0000-f1c9-6618ce0e0000 pid=3790 clone guuid=df6af666-1700-0000-f1c9-6618d10e0000 pid=3793 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=df6af666-1700-0000-f1c9-6618d10e0000 pid=3793 execve guuid=2147f16b-1700-0000-f1c9-6618de0e0000 pid=3806 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=2147f16b-1700-0000-f1c9-6618de0e0000 pid=3806 execve guuid=9bb0516c-1700-0000-f1c9-6618e10e0000 pid=3809 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=9bb0516c-1700-0000-f1c9-6618e10e0000 pid=3809 clone guuid=041eeb6d-1700-0000-f1c9-6618e60e0000 pid=3814 /usr/bin/wget net send-data write-file guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=041eeb6d-1700-0000-f1c9-6618e60e0000 pid=3814 execve guuid=fe233a72-1700-0000-f1c9-6618f90e0000 pid=3833 /usr/bin/chmod guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=fe233a72-1700-0000-f1c9-6618f90e0000 pid=3833 execve guuid=3079c672-1700-0000-f1c9-6618fe0e0000 pid=3838 /usr/bin/dash guuid=7275b820-1700-0000-f1c9-6618ba0d0000 pid=3514->guuid=3079c672-1700-0000-f1c9-6618fe0e0000 pid=3838 clone 1d7bf28b-6ddb-5e47-86a8-756dcbfab639 176.65.139.121:80 guuid=b989e920-1700-0000-f1c9-6618bc0d0000 pid=3516->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B guuid=9a136a26-1700-0000-f1c9-6618d10d0000 pid=3537 /home/sandbox/iran.x86_64 zombie guuid=95a1ad25-1700-0000-f1c9-6618cd0d0000 pid=3533->guuid=9a136a26-1700-0000-f1c9-6618d10d0000 pid=3537 clone guuid=369f7426-1700-0000-f1c9-6618d30d0000 pid=3539 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=9a136a26-1700-0000-f1c9-6618d10d0000 pid=3537->guuid=369f7426-1700-0000-f1c9-6618d30d0000 pid=3539 clone guuid=1b377126-1700-0000-f1c9-6618d20d0000 pid=3538->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 141B 6df13ef4-d91e-50b1-8d2d-27084993b18f 176.65.139.121:7080 guuid=369f7426-1700-0000-f1c9-6618d30d0000 pid=3539->6df13ef4-d91e-50b1-8d2d-27084993b18f send: 297B guuid=5ee8a72c-1700-0000-f1c9-6618ea0d0000 pid=3562->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 138B guuid=253fc932-1700-0000-f1c9-6618000e0000 pid=3584->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 138B guuid=ebe7e638-1700-0000-f1c9-6618180e0000 pid=3608->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B guuid=bcbab03e-1700-0000-f1c9-66182d0e0000 pid=3629->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 141B guuid=3d127144-1700-0000-f1c9-6618490e0000 pid=3657->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 139B guuid=6c6fba47-1700-0000-f1c9-66185b0e0000 pid=3675->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 137B guuid=d15f6b4d-1700-0000-f1c9-6618760e0000 pid=3702->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 137B guuid=74d1e053-1700-0000-f1c9-6618840e0000 pid=3716->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 138B guuid=b53f9959-1700-0000-f1c9-6618950e0000 pid=3733 /home/sandbox/iran.i486 guuid=0adf3c59-1700-0000-f1c9-6618940e0000 pid=3732->guuid=b53f9959-1700-0000-f1c9-6618950e0000 pid=3733 clone guuid=02b8a659-1700-0000-f1c9-6618970e0000 pid=3735 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=b53f9959-1700-0000-f1c9-6618950e0000 pid=3733->guuid=02b8a659-1700-0000-f1c9-6618970e0000 pid=3735 clone guuid=b718a059-1700-0000-f1c9-6618960e0000 pid=3734->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B guuid=02b8a659-1700-0000-f1c9-6618970e0000 pid=3735->6df13ef4-d91e-50b1-8d2d-27084993b18f send: 1102B guuid=4d238760-1700-0000-f1c9-6618b70e0000 pid=3767->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B guuid=df6af666-1700-0000-f1c9-6618d10e0000 pid=3793->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B guuid=041eeb6d-1700-0000-f1c9-6618e60e0000 pid=3814->1d7bf28b-6ddb-5e47-86a8-756dcbfab639 send: 140B
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-06-04 00:46:32 UTC
File Type:
Text (Shell)
AV detection:
10 of 23 (43.48%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 473961d2cdfd1285563626458ba7bd8aeb2285e32351f5c63c5ad2914698527e

(this sample)

  
Delivery method
Distributed via web download

Comments