MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b0f66b45f70e1976a61be44739d0e1f2a554a6b314ae4237d670a02e4614fe5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 5b0f66b45f70e1976a61be44739d0e1f2a554a6b314ae4237d670a02e4614fe5
SHA3-384 hash: 3cbc60915c9965c3d19d6582263778ad162be04e17036df4f14a8ca42578fb3696a39098f4e933cdc94e2e01bdcfc70d
SHA1 hash: 1881ec168b62ad8b87ada9a3e61cc7da760120e8
MD5 hash: 8a39789b544c9fe848a679ac094f620d
humanhash: three-autumn-twelve-eleven
File name:peak.sh
Download: download sample
Signature Mirai
File size:793 bytes
First seen:2026-07-22 21:05:46 UTC
Last seen:2026-07-23 17:31:23 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hZAU0CiG8pKgOoShGSbTgFGpjo9yXuiG9yZJNHu6WKofVxaGfPkdVkCf9FLGERBf:ECinwHBPcyjeyZCAQy24fL3+pH8r
TLSH T14D01A9C531907FF3EC049F08FA72466950C7EAE9A2CF07E094C66E155D9D644F917A08
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.164/armv4lef42e6fd238baa990731f2ab20d130c489c1689588c5842713f28b4e90724019 Miraimirai wraith
http://94.154.43.164/armv5l150609a660a659b9be9fc7c6b7846c0a94eb81cdd7a0ce848855a78be8239267 Miraimirai wraith
http://94.154.43.164/armv7la81f233036fc9ef73c2284fd74d1e08ce74d9dd87e858a17d0bed45d23d26b3b Miraiarm elf mirai opendir ua-wget
http://94.154.43.164/mips980a7bfa9dd517f3b934f61e23d9e277bf222ce9b1cb055eecd1c7f87b35d7fc Miraimirai wraith
http://94.154.43.164/mipsel226d5f0493530a890fe642db959232b63ba8b7be48ea94a65cc68f8437b10ae5 Miraimirai wraith
http://94.154.43.164/i686b754fed0b006adb9323a64a198ba2a968aa43712f506ecce0730d23da5765fe6 Miraimirai wraith

Intelligence


File Origin
# of uploads :
7
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-22T18:36:00Z UTC
Last seen:
2026-07-24T12:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=9e0cd097-1800-0000-d9be-4d65b80c0000 pid=3256 /usr/bin/sudo guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263 /tmp/sample.bin guuid=9e0cd097-1800-0000-d9be-4d65b80c0000 pid=3256->guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263 execve guuid=ca20829a-1800-0000-d9be-4d65c10c0000 pid=3265 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=ca20829a-1800-0000-d9be-4d65c10c0000 pid=3265 execve guuid=da3787a1-1800-0000-d9be-4d65d00c0000 pid=3280 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=da3787a1-1800-0000-d9be-4d65d00c0000 pid=3280 execve guuid=5d4cd0a1-1800-0000-d9be-4d65d20c0000 pid=3282 /usr/bin/dash guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=5d4cd0a1-1800-0000-d9be-4d65d20c0000 pid=3282 clone guuid=af36a1a3-1800-0000-d9be-4d65d90c0000 pid=3289 /usr/bin/rm delete-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=af36a1a3-1800-0000-d9be-4d65d90c0000 pid=3289 execve guuid=dcbfeba3-1800-0000-d9be-4d65db0c0000 pid=3291 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=dcbfeba3-1800-0000-d9be-4d65db0c0000 pid=3291 execve guuid=b3cdb7aa-1800-0000-d9be-4d65ee0c0000 pid=3310 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=b3cdb7aa-1800-0000-d9be-4d65ee0c0000 pid=3310 execve guuid=9c3832ab-1800-0000-d9be-4d65f00c0000 pid=3312 /usr/bin/dash guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=9c3832ab-1800-0000-d9be-4d65f00c0000 pid=3312 clone guuid=245043ac-1800-0000-d9be-4d65f50c0000 pid=3317 /usr/bin/rm delete-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=245043ac-1800-0000-d9be-4d65f50c0000 pid=3317 execve guuid=5c8384ac-1800-0000-d9be-4d65f70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=5c8384ac-1800-0000-d9be-4d65f70c0000 pid=3319 execve guuid=dcec0fb2-1800-0000-d9be-4d65040d0000 pid=3332 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=dcec0fb2-1800-0000-d9be-4d65040d0000 pid=3332 execve guuid=bbd56ab2-1800-0000-d9be-4d65060d0000 pid=3334 /usr/bin/dash guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=bbd56ab2-1800-0000-d9be-4d65060d0000 pid=3334 clone guuid=bd3920b3-1800-0000-d9be-4d650a0d0000 pid=3338 /usr/bin/rm delete-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=bd3920b3-1800-0000-d9be-4d650a0d0000 pid=3338 execve guuid=130a75b3-1800-0000-d9be-4d650c0d0000 pid=3340 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=130a75b3-1800-0000-d9be-4d650c0d0000 pid=3340 execve guuid=308e3cbc-1800-0000-d9be-4d65260d0000 pid=3366 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=308e3cbc-1800-0000-d9be-4d65260d0000 pid=3366 execve guuid=d31779bc-1800-0000-d9be-4d65270d0000 pid=3367 /usr/bin/dash guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=d31779bc-1800-0000-d9be-4d65270d0000 pid=3367 clone guuid=bb0789bc-1800-0000-d9be-4d65280d0000 pid=3368 /usr/bin/rm delete-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=bb0789bc-1800-0000-d9be-4d65280d0000 pid=3368 execve guuid=9486c1bc-1800-0000-d9be-4d652a0d0000 pid=3370 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=9486c1bc-1800-0000-d9be-4d652a0d0000 pid=3370 execve guuid=d571a1c6-1800-0000-d9be-4d653e0d0000 pid=3390 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=d571a1c6-1800-0000-d9be-4d653e0d0000 pid=3390 execve guuid=0e0409c8-1800-0000-d9be-4d653f0d0000 pid=3391 /usr/bin/dash guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=0e0409c8-1800-0000-d9be-4d653f0d0000 pid=3391 clone guuid=cf351fc9-1800-0000-d9be-4d65440d0000 pid=3396 /usr/bin/rm delete-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=cf351fc9-1800-0000-d9be-4d65440d0000 pid=3396 execve guuid=1143d9c9-1800-0000-d9be-4d65450d0000 pid=3397 /usr/bin/wget net send-data write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=1143d9c9-1800-0000-d9be-4d65450d0000 pid=3397 execve guuid=1e5df5d1-1800-0000-d9be-4d65540d0000 pid=3412 /usr/bin/chmod guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=1e5df5d1-1800-0000-d9be-4d65540d0000 pid=3412 execve guuid=009a32d2-1800-0000-d9be-4d65560d0000 pid=3414 /home/sandbox/i686 write-file guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=009a32d2-1800-0000-d9be-4d65560d0000 pid=3414 execve guuid=4b7066d2-1800-0000-d9be-4d65580d0000 pid=3416 /usr/bin/rm guuid=a813339a-1800-0000-d9be-4d65bf0c0000 pid=3263->guuid=4b7066d2-1800-0000-d9be-4d65580d0000 pid=3416 execve a841048d-32ac-56e9-8a5e-52f69cef6467 94.154.43.164:80 guuid=ca20829a-1800-0000-d9be-4d65c10c0000 pid=3265->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 134B guuid=dcbfeba3-1800-0000-d9be-4d65db0c0000 pid=3291->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 134B guuid=5c8384ac-1800-0000-d9be-4d65f70c0000 pid=3319->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 134B guuid=130a75b3-1800-0000-d9be-4d650c0d0000 pid=3340->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 132B guuid=9486c1bc-1800-0000-d9be-4d652a0d0000 pid=3370->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 134B guuid=1143d9c9-1800-0000-d9be-4d65450d0000 pid=3397->a841048d-32ac-56e9-8a5e-52f69cef6467 send: 132B guuid=08575dd2-1800-0000-d9be-4d65570d0000 pid=3415 /home/sandbox/libcow.so zombie guuid=009a32d2-1800-0000-d9be-4d65560d0000 pid=3414->guuid=08575dd2-1800-0000-d9be-4d65570d0000 pid=3415 clone guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418 /home/sandbox/libcow.so dns net send-data guuid=08575dd2-1800-0000-d9be-4d65570d0000 pid=3415->guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 75B 2ab18665-5ff8-5713-96da-62f159626e58 198.98.53.100:8001 guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418->2ab18665-5ff8-5713-96da-62f159626e58 send: 671B 7f30281f-6565-565b-903e-76ab0b9d4286 stun.l.google.com:19302 guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418->7f30281f-6565-565b-903e-76ab0b9d4286 send: 20B guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501 /home/sandbox/libcow.so dns net send-data guuid=cb6f7fd2-1800-0000-d9be-4d655a0d0000 pid=3418->guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501 clone guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 534B a4109754-3997-5f42-83f5-f487770de60e dualstack.zd.map.fastly.net:80 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->a4109754-3997-5f42-83f5-f487770de60e send: 115B 921a04ef-3c51-5677-b941-9a83ce9db0e6 speedtest-nl.digiturunc.com:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->921a04ef-3c51-5677-b941-9a83ce9db0e6 send: 120B ca98a048-1f0d-5b4c-ae03-21c4a205645f nkf-ams.speedtest.royalehosting.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->ca98a048-1f0d-5b4c-ae03-21c4a205645f send: 128B 236acd13-3db7-566f-aedc-326282d2c4ef speedtest.duocast.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->236acd13-3db7-566f-aedc-326282d2c4ef send: 114B ea6a0693-6988-5d32-9f7d-d4d3ebdb2aed speedtest.tngnet.com:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->ea6a0693-6988-5d32-9f7d-d4d3ebdb2aed send: 113B ff01b81f-694b-5ee5-a14a-b7b10967b99d ams.speedtest.clouvider.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->ff01b81f-694b-5ee5-a14a-b7b10967b99d send: 120B 9819c6dd-ee9e-578b-a664-df61ebfb752c speedtest.eu.kamatera.com:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->9819c6dd-ee9e-578b-a664-df61ebfb752c send: 281300B 9a753fe6-f0b6-5c0a-8693-1ddc6134e058 speedtest-ams-nl.as215248.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->9a753fe6-f0b6-5c0a-8693-1ddc6134e058 send: 122B f105897d-f29a-5805-8e81-a62a27a41974 speedtest.as215296.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->f105897d-f29a-5805-8e81-a62a27a41974 send: 115B 99771222-feb3-5c04-a284-fb65a1feae3c speedtest.ams1.hivelocity.net:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->99771222-feb3-5c04-a284-fb65a1feae3c send: 122B 8e9cbe9c-abff-5841-acad-5c263ec92bc0 speedtest.xsnews.nl:8080 guuid=4a0f1cef-1800-0000-d9be-4d65ad0d0000 pid=3501->8e9cbe9c-abff-5841-acad-5c263ec92bc0 send: 112B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-07-22 21:06:52 UTC
File Type:
Text (Shell)
AV detection:
15 of 38 (39.47%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Enumerates running processes
Reads MAC address of network interface
Reads network interface configuration
File and Directory Permissions Modification
Executes dropped EXE
Renames itself
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5b0f66b45f70e1976a61be44739d0e1f2a554a6b314ae4237d670a02e4614fe5

(this sample)

  
Delivery method
Distributed via web download

Comments