MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ab96f447a3fe783269b9bebea3c02ced3338ac4948da8b84a29664cfa2c509b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4ab96f447a3fe783269b9bebea3c02ced3338ac4948da8b84a29664cfa2c509b
SHA3-384 hash: 6697f3359fbe33de72261ea2a484215fc8f65e9694e313cb6de592b4f6efd855b8f700a436c5bf8659de351b5a92c26a
SHA1 hash: 6e6d12cadbdf94ae96176e6d522068cc9a1c6bc8
MD5 hash: 54121bde7c78e9f309af7c566ef5f54c
humanhash: wolfram-sweet-oregon-glucose
File name:all.sh
Download: download sample
Signature Mirai
File size:942 bytes
First seen:2026-06-05 01:49:54 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:xpZSFNIstLKuavD9jXWkdM9ISRpK2EduXU:xp8FNImKuAyRpKGU
TLSH T1E711BADE30EF24B55C02BE42B05188D4F549F2DBB9A69F48FC848EB18597BB5302CB85
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.175.223.249/data_arm4ebcbc9ed3fc243326104277396da19e8a96927936e1d48c2b79f06385f80e93c Miraielf mirai ua-wget
http://5.175.223.249/data_arm5c99bda9c36167aec7d2e0543eae7290a9e6f128da87b688559208bcb02938aa1 Miraielf mirai ua-wget
http://5.175.223.249/data_arm6n/an/aelf ua-wget
http://5.175.223.249/data_arm7ce30abebd7c1e9fe5b016ae13bc72a9ab154d9293b5df8b0f45904e05dd5d89b Miraielf mirai ua-wget
http://5.175.223.249/data_aarch646d8fdf8f5886c594e4705cc207f70c979293c28a59d3fd27fac7ae617e469038 Miraielf mirai ua-wget
http://5.175.223.249/data_mipsc72fd954187659d1c9a9ac03c8711944061b26007d5f30f471ef148bc354aa00 Miraielf mirai ua-wget
http://5.175.223.249/data_mipselc7b379b588dcd3801157e0cfb817bf0484839be8a2e8515654e7a78d17bf3744 Miraielf mirai ua-wget
http://5.175.223.249/data_mips-uclibcb847130751c20bd5f4c6e4309d928dcee7620d4dc94bcdbc46c03bbc17543edb Miraielf mirai ua-wget
http://5.175.223.249/data_mipsel-uclibce28a394b2e5c3d1627c75b81af09c2b0206905f168b55b6722a303b52022d815 Miraielf mirai ua-wget
http://5.175.223.249/data_powerpc3352f2ce5764e2875177af4eeb54c2fb92072326ee84e9ee65de86738f73824d Miraielf mirai ua-wget
http://5.175.223.249/data_x868a4d59c745036a82a74cace444ba9a20dcd909d5637eba03cdcd2971d42707bb Miraielf mirai ua-wget
http://5.175.223.249/data_x86_640e5416385b4d4ae5a00d3bdfd7d38bf44d8582a71a23be5c2e0b160afce2edee Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=44cd0405-1700-0000-35ab-ec37dd0e0000 pid=3805 /usr/bin/sudo guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813 /tmp/sample.bin guuid=44cd0405-1700-0000-35ab-ec37dd0e0000 pid=3805->guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813 execve guuid=2458e207-1700-0000-35ab-ec37e60e0000 pid=3814 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=2458e207-1700-0000-35ab-ec37e60e0000 pid=3814 clone guuid=34060d08-1700-0000-35ab-ec37e90e0000 pid=3817 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=34060d08-1700-0000-35ab-ec37e90e0000 pid=3817 execve guuid=75b6a323-1700-0000-35ab-ec37300f0000 pid=3888 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=75b6a323-1700-0000-35ab-ec37300f0000 pid=3888 execve guuid=24a6ed23-1700-0000-35ab-ec37310f0000 pid=3889 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=24a6ed23-1700-0000-35ab-ec37310f0000 pid=3889 clone guuid=e6dd9124-1700-0000-35ab-ec37350f0000 pid=3893 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=e6dd9124-1700-0000-35ab-ec37350f0000 pid=3893 execve guuid=b3a4542f-1700-0000-35ab-ec37590f0000 pid=3929 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=b3a4542f-1700-0000-35ab-ec37590f0000 pid=3929 execve guuid=26f2c32f-1700-0000-35ab-ec375b0f0000 pid=3931 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=26f2c32f-1700-0000-35ab-ec375b0f0000 pid=3931 clone guuid=57fdaf30-1700-0000-35ab-ec37610f0000 pid=3937 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=57fdaf30-1700-0000-35ab-ec37610f0000 pid=3937 execve guuid=75c5a73b-1700-0000-35ab-ec37830f0000 pid=3971 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=75c5a73b-1700-0000-35ab-ec37830f0000 pid=3971 execve guuid=9e78173c-1700-0000-35ab-ec37850f0000 pid=3973 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=9e78173c-1700-0000-35ab-ec37850f0000 pid=3973 clone guuid=409af13c-1700-0000-35ab-ec37890f0000 pid=3977 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=409af13c-1700-0000-35ab-ec37890f0000 pid=3977 execve guuid=c6337747-1700-0000-35ab-ec37a80f0000 pid=4008 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=c6337747-1700-0000-35ab-ec37a80f0000 pid=4008 execve guuid=2eb0c647-1700-0000-35ab-ec37aa0f0000 pid=4010 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=2eb0c647-1700-0000-35ab-ec37aa0f0000 pid=4010 clone guuid=1599b048-1700-0000-35ab-ec37ad0f0000 pid=4013 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=1599b048-1700-0000-35ab-ec37ad0f0000 pid=4013 execve guuid=e380d454-1700-0000-35ab-ec37d40f0000 pid=4052 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=e380d454-1700-0000-35ab-ec37d40f0000 pid=4052 execve guuid=043b0f55-1700-0000-35ab-ec37d60f0000 pid=4054 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=043b0f55-1700-0000-35ab-ec37d60f0000 pid=4054 clone guuid=3c7b8f55-1700-0000-35ab-ec37da0f0000 pid=4058 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=3c7b8f55-1700-0000-35ab-ec37da0f0000 pid=4058 execve guuid=69221560-1700-0000-35ab-ec3707100000 pid=4103 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=69221560-1700-0000-35ab-ec3707100000 pid=4103 execve guuid=7f1b5460-1700-0000-35ab-ec3708100000 pid=4104 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=7f1b5460-1700-0000-35ab-ec3708100000 pid=4104 clone guuid=88f12361-1700-0000-35ab-ec370c100000 pid=4108 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=88f12361-1700-0000-35ab-ec370c100000 pid=4108 execve guuid=f2f9296d-1700-0000-35ab-ec3739100000 pid=4153 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=f2f9296d-1700-0000-35ab-ec3739100000 pid=4153 execve guuid=3efc8f6d-1700-0000-35ab-ec373c100000 pid=4156 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=3efc8f6d-1700-0000-35ab-ec373c100000 pid=4156 clone guuid=b6f5956e-1700-0000-35ab-ec3742100000 pid=4162 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=b6f5956e-1700-0000-35ab-ec3742100000 pid=4162 execve guuid=e3c6ec79-1700-0000-35ab-ec375f100000 pid=4191 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=e3c6ec79-1700-0000-35ab-ec375f100000 pid=4191 execve guuid=8231397a-1700-0000-35ab-ec3760100000 pid=4192 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=8231397a-1700-0000-35ab-ec3760100000 pid=4192 clone guuid=f0f1f07a-1700-0000-35ab-ec3765100000 pid=4197 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=f0f1f07a-1700-0000-35ab-ec3765100000 pid=4197 execve guuid=15897789-1700-0000-35ab-ec3790100000 pid=4240 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=15897789-1700-0000-35ab-ec3790100000 pid=4240 execve guuid=f73aef89-1700-0000-35ab-ec3792100000 pid=4242 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=f73aef89-1700-0000-35ab-ec3792100000 pid=4242 clone guuid=d6a7b88a-1700-0000-35ab-ec3795100000 pid=4245 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=d6a7b88a-1700-0000-35ab-ec3795100000 pid=4245 execve guuid=cbe9e497-1700-0000-35ab-ec37bf100000 pid=4287 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=cbe9e497-1700-0000-35ab-ec37bf100000 pid=4287 execve guuid=3e213b98-1700-0000-35ab-ec37c1100000 pid=4289 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=3e213b98-1700-0000-35ab-ec37c1100000 pid=4289 clone guuid=28211999-1700-0000-35ab-ec37c7100000 pid=4295 /usr/bin/wget net send-data write-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=28211999-1700-0000-35ab-ec37c7100000 pid=4295 execve guuid=090355a7-1700-0000-35ab-ec37eb100000 pid=4331 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=090355a7-1700-0000-35ab-ec37eb100000 pid=4331 execve guuid=985a9ea7-1700-0000-35ab-ec37ed100000 pid=4333 /home/sandbox/data_x86 net guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=985a9ea7-1700-0000-35ab-ec37ed100000 pid=4333 execve guuid=437b88a8-1700-0000-35ab-ec37f5100000 pid=4341 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=437b88a8-1700-0000-35ab-ec37f5100000 pid=4341 clone guuid=a3819ba8-1700-0000-35ab-ec37f6100000 pid=4342 /usr/bin/chmod guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=a3819ba8-1700-0000-35ab-ec37f6100000 pid=4342 execve guuid=e6cb83a9-1700-0000-35ab-ec37fa100000 pid=4346 /usr/bin/dash guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=e6cb83a9-1700-0000-35ab-ec37fa100000 pid=4346 clone guuid=a1208ca9-1700-0000-35ab-ec37fb100000 pid=4347 /usr/bin/rm delete-file guuid=a9019307-1700-0000-35ab-ec37e50e0000 pid=3813->guuid=a1208ca9-1700-0000-35ab-ec37fb100000 pid=4347 execve 16272418-1aa7-5a5b-8d52-420e83ac841c 5.175.223.249:80 guuid=34060d08-1700-0000-35ab-ec37e90e0000 pid=3817->16272418-1aa7-5a5b-8d52-420e83ac841c send: 137B guuid=e6dd9124-1700-0000-35ab-ec37350f0000 pid=3893->16272418-1aa7-5a5b-8d52-420e83ac841c send: 137B guuid=57fdaf30-1700-0000-35ab-ec37610f0000 pid=3937->16272418-1aa7-5a5b-8d52-420e83ac841c send: 137B guuid=409af13c-1700-0000-35ab-ec37890f0000 pid=3977->16272418-1aa7-5a5b-8d52-420e83ac841c send: 137B guuid=1599b048-1700-0000-35ab-ec37ad0f0000 pid=4013->16272418-1aa7-5a5b-8d52-420e83ac841c send: 140B guuid=3c7b8f55-1700-0000-35ab-ec37da0f0000 pid=4058->16272418-1aa7-5a5b-8d52-420e83ac841c send: 137B guuid=88f12361-1700-0000-35ab-ec370c100000 pid=4108->16272418-1aa7-5a5b-8d52-420e83ac841c send: 139B guuid=b6f5956e-1700-0000-35ab-ec3742100000 pid=4162->16272418-1aa7-5a5b-8d52-420e83ac841c send: 144B guuid=f0f1f07a-1700-0000-35ab-ec3765100000 pid=4197->16272418-1aa7-5a5b-8d52-420e83ac841c send: 146B guuid=d6a7b88a-1700-0000-35ab-ec3795100000 pid=4245->16272418-1aa7-5a5b-8d52-420e83ac841c send: 140B guuid=28211999-1700-0000-35ab-ec37c7100000 pid=4295->16272418-1aa7-5a5b-8d52-420e83ac841c send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=985a9ea7-1700-0000-35ab-ec37ed100000 pid=4333->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6510cfa7-1700-0000-35ab-ec37ef100000 pid=4335 /home/sandbox/data_x86 guuid=985a9ea7-1700-0000-35ab-ec37ed100000 pid=4333->guuid=6510cfa7-1700-0000-35ab-ec37ef100000 pid=4335 clone guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336 /home/sandbox/data_x86 net send-data write-file zombie guuid=6510cfa7-1700-0000-35ab-ec37ef100000 pid=4335->guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336 clone guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 154B 1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 46.247.108.74:8082 guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336->1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 send: 20B guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4337 /home/sandbox/data_x86 send-data zombie guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336->guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4337 clone guuid=ae3a10a8-1700-0000-35ab-ec37f2100000 pid=4338 /home/sandbox/data_x86 net write-file guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336->guuid=ae3a10a8-1700-0000-35ab-ec37f2100000 pid=4338 clone guuid=161320a8-1700-0000-35ab-ec37f3100000 pid=4339 /home/sandbox/data_x86 delete-file net send-data guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4336->guuid=161320a8-1700-0000-35ab-ec37f3100000 pid=4339 clone guuid=1bb6dca7-1700-0000-35ab-ec37f0100000 pid=4337->1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 send: 2749B a15c7036-706e-5ee9-888f-734cbb9e72e7 127.0.0.1:30565 guuid=ae3a10a8-1700-0000-35ab-ec37f2100000 pid=4338->a15c7036-706e-5ee9-888f-734cbb9e72e7 con guuid=161320a8-1700-0000-35ab-ec37f3100000 pid=4339->a15c7036-706e-5ee9-888f-734cbb9e72e7 send: 2749B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-05 01:50:50 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4ab96f447a3fe783269b9bebea3c02ced3338ac4948da8b84a29664cfa2c509b

(this sample)

  
Delivery method
Distributed via web download

Comments