MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4cd465ecc8e6022579105e247cef98e5fcc418b84eb5857a642bb179f74ae356. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 4cd465ecc8e6022579105e247cef98e5fcc418b84eb5857a642bb179f74ae356
SHA3-384 hash: 5455fcdc2550bda15046380fa8f6859cfdc531fbdf23aa5ac0dc7aa11b397ec7d69ae179cdbc188871f288f82d9c4cd4
SHA1 hash: 1caeddd6847e52c6b45fa0f6e1b642f6112db436
MD5 hash: 321109554233cc67a316b812131e1bc3
humanhash: blue-yellow-nineteen-mobile
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'901 bytes
First seen:2026-04-27 13:30:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:spKpGpkpWpLp3qp8pw1lpLpg5pvpHapop+pspWp3pSpApSo78phpPqpSpqp/pep8:KoUikt3Iaw1Htg7RYmMKk5weSfDgwIhN
TLSH T12641FFCE60F46043E6DCDE0470F58DCB6706959163DF2A7AED812E67C4C9D54702AB3A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.177/iran.x86_643164f6882b65bbf58d08919d3ea1b69f00e2757e6e4a8b76e8af1a057ae707cd Mirai64-bit elf mirai x86-64
http://176.65.139.177/iran.aarch649c766990cdd7d73c4a1d8c00e281a05a194f7a3f3ae58629beba202e847696a2 Miraielf mirai ua-wget
http://176.65.139.177/iran.m68kc06a2446a9d8680f7ecd2e453daa5472af2dd9a93579b793241de3f861fa7d0b Miraielf mirai ua-wget
http://176.65.139.177/iran.mips961082df4ef13fd7cc589ffc7091d2764ca6f5f6f2af0416f4c76b2de1a781ed Miraielf mirai ua-wget
http://176.65.139.177/iran.mipsel919b062d23bcfa0968319f56967965ffe8ecdbbc3ced30521d7448fa6433d7d4 Miraielf mirai ua-wget
http://176.65.139.177/iran.powerpce76c1268558776e81ddaad587a8aeef906bd4c67ec133ab8532bc3757d974722 Miraielf mirai ua-wget
http://176.65.139.177/iran.sparcad358a598bc9c8b45b0009e78f4f535614227c617f3aef8b0b7c5bcec5d5229a Miraielf mirai ua-wget
http://176.65.139.177/iran.sh418ff201b2a1eddf913af74a02ac80eb3d17f7a759c23a101c11c2027dc29c58d Miraielf mirai ua-wget
http://176.65.139.177/iran.arcd68e81c8ecf018e3202812329344122ebfe5f41782243ae4b7231fbbce92059b Miraielf mirai ua-wget
http://176.65.139.177/iran.i4864dfc4b56da42b47dafaefd6e3c15272cf64918d6ee666957f126cb652e7b2312 Miraielf mirai ua-wget
http://176.65.139.177/iran.armv4lc36d042bd9352b86858d03984e2a3f7000e31cf3308a50e7dadb3b8011c00f3c Miraielf mirai ua-wget
http://176.65.139.177/iran.armv5l378cc36e46b6aa98c6ff65e2de5cc64b03ec1af15aac3ce61faa86ef425b986a Miraielf mirai ua-wget
http://176.65.139.177/iran.armv6l46f5bb5a40a2e136b6b111b650795d3560f0ff670717da1103d71f0be73e9a49 Miraielf mirai ua-wget
http://176.65.139.177/iran.armv7l7c74da0acdc43b599890548f5c3849eb96b4df63cf8ce8de6ddccaa300a682b3 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-26T22:28:00Z UTC
Last seen:
2026-04-27T12:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9454d3ba-1900-0000-9091-c650cf090000 pid=2511 /usr/bin/sudo guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516 /tmp/sample.bin guuid=9454d3ba-1900-0000-9091-c650cf090000 pid=2511->guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516 execve guuid=dfc305bd-1900-0000-9091-c650d6090000 pid=2518 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=dfc305bd-1900-0000-9091-c650d6090000 pid=2518 execve guuid=5bfdb8c1-1900-0000-9091-c650e3090000 pid=2531 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=5bfdb8c1-1900-0000-9091-c650e3090000 pid=2531 execve guuid=343a0bc2-1900-0000-9091-c650e5090000 pid=2533 /home/sandbox/iran.x86_64 mprotect-exec guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=343a0bc2-1900-0000-9091-c650e5090000 pid=2533 execve guuid=4689c3c2-1900-0000-9091-c650e9090000 pid=2537 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=4689c3c2-1900-0000-9091-c650e9090000 pid=2537 execve guuid=8855f3c8-1900-0000-9091-c650fa090000 pid=2554 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=8855f3c8-1900-0000-9091-c650fa090000 pid=2554 execve guuid=5fc22fc9-1900-0000-9091-c650fc090000 pid=2556 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=5fc22fc9-1900-0000-9091-c650fc090000 pid=2556 clone guuid=84a0b5c9-1900-0000-9091-c650ff090000 pid=2559 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=84a0b5c9-1900-0000-9091-c650ff090000 pid=2559 execve guuid=d0cd37cf-1900-0000-9091-c6500e0a0000 pid=2574 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=d0cd37cf-1900-0000-9091-c6500e0a0000 pid=2574 execve guuid=44397bcf-1900-0000-9091-c650100a0000 pid=2576 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=44397bcf-1900-0000-9091-c650100a0000 pid=2576 clone guuid=a69d79d0-1900-0000-9091-c650140a0000 pid=2580 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=a69d79d0-1900-0000-9091-c650140a0000 pid=2580 execve guuid=e166f4d5-1900-0000-9091-c650250a0000 pid=2597 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=e166f4d5-1900-0000-9091-c650250a0000 pid=2597 execve guuid=c09134d6-1900-0000-9091-c650270a0000 pid=2599 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=c09134d6-1900-0000-9091-c650270a0000 pid=2599 clone guuid=5974f8d6-1900-0000-9091-c6502c0a0000 pid=2604 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=5974f8d6-1900-0000-9091-c6502c0a0000 pid=2604 execve guuid=cfe8fddb-1900-0000-9091-c6503c0a0000 pid=2620 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=cfe8fddb-1900-0000-9091-c6503c0a0000 pid=2620 execve guuid=a6a443dc-1900-0000-9091-c6503d0a0000 pid=2621 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=a6a443dc-1900-0000-9091-c6503d0a0000 pid=2621 clone guuid=360feadc-1900-0000-9091-c650410a0000 pid=2625 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=360feadc-1900-0000-9091-c650410a0000 pid=2625 execve guuid=228546e2-1900-0000-9091-c6504f0a0000 pid=2639 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=228546e2-1900-0000-9091-c6504f0a0000 pid=2639 execve guuid=733fb0e2-1900-0000-9091-c650500a0000 pid=2640 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=733fb0e2-1900-0000-9091-c650500a0000 pid=2640 clone guuid=49ef5ee3-1900-0000-9091-c650540a0000 pid=2644 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=49ef5ee3-1900-0000-9091-c650540a0000 pid=2644 execve guuid=aa6abce6-1900-0000-9091-c6505e0a0000 pid=2654 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=aa6abce6-1900-0000-9091-c6505e0a0000 pid=2654 execve guuid=9c8512e7-1900-0000-9091-c650600a0000 pid=2656 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=9c8512e7-1900-0000-9091-c650600a0000 pid=2656 clone guuid=09abe1e7-1900-0000-9091-c650640a0000 pid=2660 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=09abe1e7-1900-0000-9091-c650640a0000 pid=2660 execve guuid=ba5869f0-1900-0000-9091-c650790a0000 pid=2681 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=ba5869f0-1900-0000-9091-c650790a0000 pid=2681 execve guuid=acefcef0-1900-0000-9091-c6507b0a0000 pid=2683 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=acefcef0-1900-0000-9091-c6507b0a0000 pid=2683 clone guuid=8c6762f1-1900-0000-9091-c6507f0a0000 pid=2687 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=8c6762f1-1900-0000-9091-c6507f0a0000 pid=2687 execve guuid=057f58f7-1900-0000-9091-c6508f0a0000 pid=2703 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=057f58f7-1900-0000-9091-c6508f0a0000 pid=2703 execve guuid=3a61bef7-1900-0000-9091-c650910a0000 pid=2705 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=3a61bef7-1900-0000-9091-c650910a0000 pid=2705 clone guuid=31cd8af8-1900-0000-9091-c650950a0000 pid=2709 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=31cd8af8-1900-0000-9091-c650950a0000 pid=2709 execve guuid=015c29fd-1900-0000-9091-c650a30a0000 pid=2723 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=015c29fd-1900-0000-9091-c650a30a0000 pid=2723 execve guuid=ca6674fd-1900-0000-9091-c650a40a0000 pid=2724 /home/sandbox/iran.i486 guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=ca6674fd-1900-0000-9091-c650a40a0000 pid=2724 execve guuid=a6f0c0fd-1900-0000-9091-c650a80a0000 pid=2728 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=a6f0c0fd-1900-0000-9091-c650a80a0000 pid=2728 execve guuid=91887003-1a00-0000-9091-c650b70a0000 pid=2743 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=91887003-1a00-0000-9091-c650b70a0000 pid=2743 execve guuid=4ba4ae03-1a00-0000-9091-c650b80a0000 pid=2744 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=4ba4ae03-1a00-0000-9091-c650b80a0000 pid=2744 clone guuid=88043304-1a00-0000-9091-c650bb0a0000 pid=2747 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=88043304-1a00-0000-9091-c650bb0a0000 pid=2747 execve guuid=25ba3609-1a00-0000-9091-c650cc0a0000 pid=2764 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=25ba3609-1a00-0000-9091-c650cc0a0000 pid=2764 execve guuid=60e87709-1a00-0000-9091-c650ce0a0000 pid=2766 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=60e87709-1a00-0000-9091-c650ce0a0000 pid=2766 clone guuid=c1a0ff09-1a00-0000-9091-c650d10a0000 pid=2769 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=c1a0ff09-1a00-0000-9091-c650d10a0000 pid=2769 execve guuid=c822ee0f-1a00-0000-9091-c650e40a0000 pid=2788 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=c822ee0f-1a00-0000-9091-c650e40a0000 pid=2788 execve guuid=37ba4810-1a00-0000-9091-c650e60a0000 pid=2790 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=37ba4810-1a00-0000-9091-c650e60a0000 pid=2790 clone guuid=42a7e910-1a00-0000-9091-c650ea0a0000 pid=2794 /usr/bin/wget net send-data write-file guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=42a7e910-1a00-0000-9091-c650ea0a0000 pid=2794 execve guuid=36a83715-1a00-0000-9091-c650f60a0000 pid=2806 /usr/bin/chmod guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=36a83715-1a00-0000-9091-c650f60a0000 pid=2806 execve guuid=39477815-1a00-0000-9091-c650f70a0000 pid=2807 /usr/bin/dash guuid=d563cabc-1900-0000-9091-c650d4090000 pid=2516->guuid=39477815-1a00-0000-9091-c650f70a0000 pid=2807 clone a318185b-039b-5e42-bab5-947d8a30ffd4 176.65.139.177:80 guuid=dfc305bd-1900-0000-9091-c650d6090000 pid=2518->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B guuid=a0acbbc2-1900-0000-9091-c650e8090000 pid=2536 /home/sandbox/iran.x86_64 zombie guuid=343a0bc2-1900-0000-9091-c650e5090000 pid=2533->guuid=a0acbbc2-1900-0000-9091-c650e8090000 pid=2536 clone guuid=adabcbc2-1900-0000-9091-c650ea090000 pid=2538 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=a0acbbc2-1900-0000-9091-c650e8090000 pid=2536->guuid=adabcbc2-1900-0000-9091-c650ea090000 pid=2538 clone guuid=4689c3c2-1900-0000-9091-c650e9090000 pid=2537->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 141B 4b8d9389-9061-5ffc-8593-155ba93831be 176.65.139.177:7080 guuid=adabcbc2-1900-0000-9091-c650ea090000 pid=2538->4b8d9389-9061-5ffc-8593-155ba93831be send: 244B guuid=84a0b5c9-1900-0000-9091-c650ff090000 pid=2559->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 138B guuid=a69d79d0-1900-0000-9091-c650140a0000 pid=2580->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 138B guuid=5974f8d6-1900-0000-9091-c6502c0a0000 pid=2604->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B guuid=360feadc-1900-0000-9091-c650410a0000 pid=2625->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 141B guuid=49ef5ee3-1900-0000-9091-c650540a0000 pid=2644->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 139B guuid=09abe1e7-1900-0000-9091-c650640a0000 pid=2660->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 137B guuid=8c6762f1-1900-0000-9091-c6507f0a0000 pid=2687->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 137B guuid=31cd8af8-1900-0000-9091-c650950a0000 pid=2709->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 138B guuid=4104bcfd-1900-0000-9091-c650a60a0000 pid=2726 /home/sandbox/iran.i486 guuid=ca6674fd-1900-0000-9091-c650a40a0000 pid=2724->guuid=4104bcfd-1900-0000-9091-c650a60a0000 pid=2726 clone guuid=b736c3fd-1900-0000-9091-c650a90a0000 pid=2729 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=4104bcfd-1900-0000-9091-c650a60a0000 pid=2726->guuid=b736c3fd-1900-0000-9091-c650a90a0000 pid=2729 clone guuid=a6f0c0fd-1900-0000-9091-c650a80a0000 pid=2728->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B guuid=b736c3fd-1900-0000-9091-c650a90a0000 pid=2729->4b8d9389-9061-5ffc-8593-155ba93831be send: 19B guuid=88043304-1a00-0000-9091-c650bb0a0000 pid=2747->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B guuid=c1a0ff09-1a00-0000-9091-c650d10a0000 pid=2769->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B guuid=42a7e910-1a00-0000-9091-c650ea0a0000 pid=2794->a318185b-039b-5e42-bab5-947d8a30ffd4 send: 140B
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-04-27 02:28:27 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4cd465ecc8e6022579105e247cef98e5fcc418b84eb5857a642bb179f74ae356

(this sample)

  
Delivery method
Distributed via web download

Comments