MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5bd2982940016bf69dddbc83300e500c4ee67a5629ec2cf16f2d2ce99519df6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5bd2982940016bf69dddbc83300e500c4ee67a5629ec2cf16f2d2ce99519df6a
SHA3-384 hash: c6cbcab7eb46a1d0b6c499f4783da59064399f59a4469c631674fd9a59dd59e0c2f0a6d01ab38ed04fd36c9cce271725
SHA1 hash: 35f9d5099bcb44217b9c5d4f068eaa620fe246da
MD5 hash: 4d7a3cc52ced06edee118360d5584358
humanhash: two-butter-nineteen-sad
File name:a.sh
Download: download sample
Signature Mirai
File size:1'718 bytes
First seen:2026-08-12 14:54:25 UTC
Last seen:2026-08-13 00:27:50 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:5XREx+DvhXxFwhSxU9htxH+pJ5LpCoSvi8m9qGEqG+MGRIO1QxqqxGxF5ZMFds4f:fevopHLgo3ht/jw/j
TLSH T16B315C863511BE71E96F6F08F2649B6D910773B0ADFF2A4298624C033896580F9DBD30
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.76/miron.armv4l1311c2f8cc6176c6aac03d055d30656039717b1e96f719b7cfe329ca52cd02ed Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.armv5l39e632ae0014657c8a3934da83be6e3a4466536f0463bcae6c10fde37ff1ff8a Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.armv6lf95fbaf1f96a73bdea5a3f90b2c1ed8a2e33dc77a644034976a23b6f5862bd53 Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.armv7lc32ba3b5f562be2e32dc4556fecde6f5e040767d80be676bf7c74d53365cc2fb Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.i4866a1aa262ce658a42362fd7489415cb93e34b7415ab972d78c63f09f413af5b55 Miraielf mirai ua-wget
http://94.154.43.76/miron.m68k09768b33697871b52d87d6422395568155e6bd39950785adf4d7dcd603c88470 Miraielf ua-wget
http://94.154.43.76/miron.mipscb9c5a44de04796ec2bcf12a7d2251cbb43e9a833773b5a5eeecf2a65851b9b4 Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.mipsel358853b9a5dc5fd36ffdc7cd399834888450805bfdcb6a1059302d2fcaf87bf1 Mirai94-154-43-76 elf mirai ua-wget
http://94.154.43.76/miron.mipsroutercb9c5a44de04796ec2bcf12a7d2251cbb43e9a833773b5a5eeecf2a65851b9b4 Miraielf mirai ua-wget
http://94.154.43.76/miron.powerpce9ef72852871ea19efabf62c7a6300602f5a40fa393ead99e80cb998b09e5644 Miraielf ua-wget
http://94.154.43.76/miron.sh4ca93431a830b141f45a3a0dbd6190389f209f8eaebba8c6b7ed93481943264c8 Miraielf mirai ua-wget
http://94.154.43.76/miron.sparc81edc0b4af09f855d026fac7cb8612cc760be4bda58bd5b6242effee69ea9bde Miraielf ua-wget
http://94.154.43.76/miron.x86_64d700571b75a3126ffd00c3ae8eae567e58f77a0619d18d2d27c59ebd7006e486 Mirai94-154-43-76 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-12T12:15:00Z UTC
Last seen:
2026-08-12T23:07:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f78e3bf6-1600-0000-fedc-119ea50d0000 pid=3493 /usr/bin/sudo guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503 /tmp/sample.bin guuid=f78e3bf6-1600-0000-fedc-119ea50d0000 pid=3493->guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503 execve guuid=6b1d06f8-1600-0000-fedc-119eb30d0000 pid=3507 /usr/bin/rm guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=6b1d06f8-1600-0000-fedc-119eb30d0000 pid=3507 execve guuid=b03e5af8-1600-0000-fedc-119eb50d0000 pid=3509 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=b03e5af8-1600-0000-fedc-119eb50d0000 pid=3509 execve guuid=2377cafd-1600-0000-fedc-119ec50d0000 pid=3525 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=2377cafd-1600-0000-fedc-119ec50d0000 pid=3525 execve guuid=5f79a401-1700-0000-fedc-119ecf0d0000 pid=3535 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=5f79a401-1700-0000-fedc-119ecf0d0000 pid=3535 execve guuid=52e4c505-1700-0000-fedc-119ed90d0000 pid=3545 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=52e4c505-1700-0000-fedc-119ed90d0000 pid=3545 execve guuid=487f5a09-1700-0000-fedc-119eda0d0000 pid=3546 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=487f5a09-1700-0000-fedc-119eda0d0000 pid=3546 execve guuid=6df45a0d-1700-0000-fedc-119ee20d0000 pid=3554 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=6df45a0d-1700-0000-fedc-119ee20d0000 pid=3554 execve guuid=da189412-1700-0000-fedc-119eee0d0000 pid=3566 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=da189412-1700-0000-fedc-119eee0d0000 pid=3566 execve guuid=25043517-1700-0000-fedc-119ef60d0000 pid=3574 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=25043517-1700-0000-fedc-119ef60d0000 pid=3574 execve guuid=7ebc6d1b-1700-0000-fedc-119efc0d0000 pid=3580 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=7ebc6d1b-1700-0000-fedc-119efc0d0000 pid=3580 execve guuid=8fce6d20-1700-0000-fedc-119e050e0000 pid=3589 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=8fce6d20-1700-0000-fedc-119e050e0000 pid=3589 execve guuid=93220c25-1700-0000-fedc-119e180e0000 pid=3608 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=93220c25-1700-0000-fedc-119e180e0000 pid=3608 execve guuid=faa5652a-1700-0000-fedc-119e330e0000 pid=3635 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=faa5652a-1700-0000-fedc-119e330e0000 pid=3635 execve guuid=452c5b2d-1700-0000-fedc-119e3c0e0000 pid=3644 /usr/bin/wget net send-data write-file guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=452c5b2d-1700-0000-fedc-119e3c0e0000 pid=3644 execve guuid=43b3f030-1700-0000-fedc-119e470e0000 pid=3655 /usr/bin/chmod guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=43b3f030-1700-0000-fedc-119e470e0000 pid=3655 execve guuid=a8074231-1700-0000-fedc-119e490e0000 pid=3657 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=a8074231-1700-0000-fedc-119e490e0000 pid=3657 clone guuid=ef4ce131-1700-0000-fedc-119e4c0e0000 pid=3660 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=ef4ce131-1700-0000-fedc-119e4c0e0000 pid=3660 clone guuid=a34f6a32-1700-0000-fedc-119e4e0e0000 pid=3662 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=a34f6a32-1700-0000-fedc-119e4e0e0000 pid=3662 clone guuid=13cef732-1700-0000-fedc-119e510e0000 pid=3665 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=13cef732-1700-0000-fedc-119e510e0000 pid=3665 clone guuid=979a8b33-1700-0000-fedc-119e540e0000 pid=3668 /tmp/miron.i486 net guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=979a8b33-1700-0000-fedc-119e540e0000 pid=3668 execve guuid=6e7ff833-1700-0000-fedc-119e570e0000 pid=3671 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=6e7ff833-1700-0000-fedc-119e570e0000 pid=3671 clone guuid=16e68734-1700-0000-fedc-119e590e0000 pid=3673 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=16e68734-1700-0000-fedc-119e590e0000 pid=3673 clone guuid=30ac0d35-1700-0000-fedc-119e5d0e0000 pid=3677 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=30ac0d35-1700-0000-fedc-119e5d0e0000 pid=3677 clone guuid=4f809f35-1700-0000-fedc-119e620e0000 pid=3682 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=4f809f35-1700-0000-fedc-119e620e0000 pid=3682 clone guuid=82f62536-1700-0000-fedc-119e650e0000 pid=3685 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=82f62536-1700-0000-fedc-119e650e0000 pid=3685 clone guuid=2e96a836-1700-0000-fedc-119e6a0e0000 pid=3690 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=2e96a836-1700-0000-fedc-119e6a0e0000 pid=3690 clone guuid=fe503737-1700-0000-fedc-119e700e0000 pid=3696 /usr/bin/dash guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=fe503737-1700-0000-fedc-119e700e0000 pid=3696 clone guuid=c501bb37-1700-0000-fedc-119e740e0000 pid=3700 /tmp/miron.x86_64 mprotect-exec net guuid=14ccc9f7-1600-0000-fedc-119eaf0d0000 pid=3503->guuid=c501bb37-1700-0000-fedc-119e740e0000 pid=3700 execve 4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a 94.154.43.76:80 guuid=b03e5af8-1600-0000-fedc-119eb50d0000 pid=3509->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B guuid=2377cafd-1600-0000-fedc-119ec50d0000 pid=3525->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B guuid=5f79a401-1700-0000-fedc-119ecf0d0000 pid=3535->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B guuid=52e4c505-1700-0000-fedc-119ed90d0000 pid=3545->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B guuid=487f5a09-1700-0000-fedc-119eda0d0000 pid=3546->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 137B guuid=6df45a0d-1700-0000-fedc-119ee20d0000 pid=3554->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 137B guuid=da189412-1700-0000-fedc-119eee0d0000 pid=3566->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 137B guuid=25043517-1700-0000-fedc-119ef60d0000 pid=3574->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B guuid=7ebc6d1b-1700-0000-fedc-119efc0d0000 pid=3580->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 143B guuid=8fce6d20-1700-0000-fedc-119e050e0000 pid=3589->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 140B guuid=93220c25-1700-0000-fedc-119e180e0000 pid=3608->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 136B guuid=faa5652a-1700-0000-fedc-119e330e0000 pid=3635->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 138B guuid=452c5b2d-1700-0000-fedc-119e3c0e0000 pid=3644->4c28ea18-67a0-5fc2-8704-1b50cd6c1a9a send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=979a8b33-1700-0000-fedc-119e540e0000 pid=3668->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=889fee33-1700-0000-fedc-119e560e0000 pid=3670 /tmp/miron.i486 net send-data zombie guuid=979a8b33-1700-0000-fedc-119e540e0000 pid=3668->guuid=889fee33-1700-0000-fedc-119e560e0000 pid=3670 clone guuid=889fee33-1700-0000-fedc-119e560e0000 pid=3670->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 7b0f7029-06b1-5dc5-8dda-0fa611d91195 94.154.43.76:1312 guuid=889fee33-1700-0000-fedc-119e560e0000 pid=3670->7b0f7029-06b1-5dc5-8dda-0fa611d91195 send: 23B guuid=c501bb37-1700-0000-fedc-119e740e0000 pid=3700->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6ce52d38-1700-0000-fedc-119e770e0000 pid=3703 /tmp/miron.x86_64 net send-data zombie guuid=c501bb37-1700-0000-fedc-119e740e0000 pid=3700->guuid=6ce52d38-1700-0000-fedc-119e770e0000 pid=3703 clone guuid=6ce52d38-1700-0000-fedc-119e770e0000 pid=3703->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6ce52d38-1700-0000-fedc-119e770e0000 pid=3703->7b0f7029-06b1-5dc5-8dda-0fa611d91195 send: 23B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-08-12 14:27:28 UTC
AV detection:
4 of 38 (10.53%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Family: Mirai
Malware Config
C2 Extraction:
94.154.43.76
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5bd2982940016bf69dddbc83300e500c4ee67a5629ec2cf16f2d2ce99519df6a

(this sample)

  
Delivery method
Distributed via web download

Comments