MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 494f4666fe448e63d37a3d62b1a008aa8f1e2b234469703d321bdd877baaf38e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 494f4666fe448e63d37a3d62b1a008aa8f1e2b234469703d321bdd877baaf38e
SHA3-384 hash: 383da35042e504889a4c91b9a4e59a732ba308586eeb10506138a5215918d30657ad9714ac2f5f66ca5b45936e9d946f
SHA1 hash: 712f8dac62d790602b7bb5c9e026ac53ef3ee2bb
MD5 hash: b228d31b6630a892200b4be0a4396c0f
humanhash: kilo-finch-wolfram-three
File name:run.sh
Download: download sample
Signature Mirai
File size:1'875 bytes
First seen:2026-07-06 01:01:45 UTC
Last seen:2026-07-07 00:29:24 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:+kfc0dt6hrNaKOOE6KODOqiDU7f/MGyK1Sk1ZSVbVVb1LBqSN0UN0KvtIQFe77X6:TfxcfFO0DYb/KUkK3D2U2MtwWAhYD
TLSH T156312ECD3170D211C288FF01F3A18BE65A46FDC97A940EBAE4C11DB988ADD4D3425A35
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.83.87.122/iran.x86_64b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 Miraielf mirai ua-wget
http://103.83.87.122/iran.aarch64bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317 Miraielf mirai ua-wget
http://103.83.87.122/iran.m68kf5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493 Miraielf mirai ua-wget
http://103.83.87.122/iran.mipse987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66 Miraielf mirai ua-wget
http://103.83.87.122/iran.mipsel6e709fb9b09d9f8318724a8620812f55411a3ea49de6319c4832885547773ddd Miraielf mirai ua-wget
http://103.83.87.122/iran.powerpc0d64cd75599dea5b8cf393b6e2b709f51b3971e64b96920e0707020e22ee7953 Miraielf mirai ua-wget
http://103.83.87.122/iran.sparcf38d748d9ea29424c28744c52bcd1d14328d49fcb604ca08fab3547ec500d6f0 Miraielf mirai ua-wget
http://103.83.87.122/iran.sh4b4acd1ab65624b694946b1181bba0732bb63c88c51b8334914c26c1805b2e1aa Miraielf mirai ua-wget
http://103.83.87.122/iran.arc21c5f4a04173a5176d60b06095bf5d25e0022ffbe304601e368eccf718587dc8 Miraielf mirai ua-wget
http://103.83.87.122/iran.i486ec442a132f27486d1dfa3faa92c03e10012afe2b8de39fa9b42b367f7971c989 Miraielf mirai ua-wget
http://103.83.87.122/iran.armv4l9538c8a2edeaa8667134a469d03a7057ddc1e753ce1e5250f92f01c1097fcb1d Miraielf mirai ua-wget
http://103.83.87.122/iran.armv5ld8cd1d9f8c092aa4a6c1b1b2b97c7de71d55c2af8332532d2956e4f5becac17e Miraielf mirai ua-wget
http://103.83.87.122/iran.armv6l95f5bd70c4e40f9663b67d40d23a46ca21d97448f9a609be10b12837e6a59805 Miraielf mirai ua-wget
http://103.83.87.122/iran.armv7lb1f2808e05cb42894790c12172ffacf8673a0a7e14c7af5ad43d5bedfa62a5e4 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-05T22:07:00Z UTC
Last seen:
2026-07-05T23:41:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2026-07-06 01:02:27 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
Modifies init.d
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 494f4666fe448e63d37a3d62b1a008aa8f1e2b234469703d321bdd877baaf38e

(this sample)

  
Delivery method
Distributed via web download

Comments