MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f4831d6685b10793fcdf3fcac397864e1e62ede9ca4e11b70c41bb1611dcbb3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5f4831d6685b10793fcdf3fcac397864e1e62ede9ca4e11b70c41bb1611dcbb3
SHA3-384 hash: 4b2389fcdd64ebb22155e5612ea286095403a5d836805a47094ade46f845df484d95300a58c565c144eb6d380edd3846
SHA1 hash: e686fa27b0ee4136e3d48d68e4e03ece8bc1ec62
MD5 hash: 512d04136ae4334537722c4ca4a7d5c4
humanhash: oxygen-lactose-double-bravo
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'014 bytes
First seen:2025-12-21 13:26:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:ywQwJlPq9YhhzlFy9NIl5mkCa0LK2ZNgOFanJMS9O7tjRaSOZ8pNtf5Ssf2G9Fxo:EwPSMlUNI7MKJIYm5slONtx1O0Hf8jn
TLSH T1EE1196DE359153A2854CDF88AF79046D9028BAC4A9B0CF349CD6583ECCEE7487439B56
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.78/bins/arm8a6ddd16ceeec5a114f3e8319a225ce5f75cba9225d79855231de0b113472d1f Miraielf mirai ua-wget
http://143.20.185.78/bins/arm5d2a961569e9ce75e16e24f1ce9614e45a83ce50d90dc0af52347cffb33e30509 Miraielf mirai ua-wget
http://143.20.185.78/bins/arm69c8738bb0a3663b08bbd4a0b78db2d4d1204f120c959717a7471864828956655 Miraielf mirai ua-wget
http://143.20.185.78/bins/arm7263f89416439f5e9d7c35621153981655eec33e46fb7f7eb70ad43357d0cfad6 Miraielf mirai ua-wget
http://143.20.185.78/bins/m68k6c109c0a95546cb495003464b596291095e5fc0a9502644b99eaa5cb5f1c0c3e Miraielf mirai ua-wget
http://143.20.185.78/bins/mips97f6da2917e358287321571ea5aca6dcd706d8791e52f882c39937b347169b21 Miraielf mirai ua-wget
http://143.20.185.78/bins/mpsln/an/aelf ua-wget
http://143.20.185.78/bins/ppc27d0189c10636921860c51dcb5f48dbae0ebcb5871713973b6a1b194e5a9b761 Miraielf mirai ua-wget
http://143.20.185.78/bins/sh4002bc08e9e4252f58e402d64fb46bb1d4ed3acf453bbd69d2a1f8888ed16616e Miraielf mirai ua-wget
http://143.20.185.78/bins/spc85d24859f9da4218bc6cd4c98243c62530c4a7a7b71407a3628eebe85dd06e91 Miraielf mirai ua-wget
http://143.20.185.78/bins/x869ebe58ec528e0153eb1113aec8024c58d21a0d513912a496ff4daf1b8c8393f5 Miraielf mirai ua-wget
http://143.20.185.78/bins/x86_644e8f0ba152cffbf54a5c44fbd3253a3979326bf455120a6bbb6e749a090f9fff Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T11:02:00Z UTC
Last seen:
2025-12-21T12:52:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=e2e484e6-1800-0000-993e-ba075d140000 pid=5213 /usr/bin/sudo guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214 /tmp/sample.bin guuid=e2e484e6-1800-0000-993e-ba075d140000 pid=5213->guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214 execve guuid=2f2c25ea-1800-0000-993e-ba075f140000 pid=5215 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=2f2c25ea-1800-0000-993e-ba075f140000 pid=5215 execve guuid=7213bdfa-1800-0000-993e-ba0760140000 pid=5216 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=7213bdfa-1800-0000-993e-ba0760140000 pid=5216 execve guuid=873313fb-1800-0000-993e-ba0761140000 pid=5217 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=873313fb-1800-0000-993e-ba0761140000 pid=5217 clone guuid=e40ecbfb-1800-0000-993e-ba0763140000 pid=5219 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=e40ecbfb-1800-0000-993e-ba0763140000 pid=5219 execve guuid=640dc00a-1900-0000-993e-ba0764140000 pid=5220 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=640dc00a-1900-0000-993e-ba0764140000 pid=5220 execve guuid=ec3b1e0b-1900-0000-993e-ba0765140000 pid=5221 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=ec3b1e0b-1900-0000-993e-ba0765140000 pid=5221 clone guuid=c503c60b-1900-0000-993e-ba0767140000 pid=5223 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=c503c60b-1900-0000-993e-ba0767140000 pid=5223 execve guuid=78e9381d-1900-0000-993e-ba0768140000 pid=5224 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=78e9381d-1900-0000-993e-ba0768140000 pid=5224 execve guuid=b784f71d-1900-0000-993e-ba0769140000 pid=5225 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=b784f71d-1900-0000-993e-ba0769140000 pid=5225 clone guuid=6e7a3e1f-1900-0000-993e-ba076b140000 pid=5227 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=6e7a3e1f-1900-0000-993e-ba076b140000 pid=5227 execve guuid=e5c8462e-1900-0000-993e-ba076c140000 pid=5228 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=e5c8462e-1900-0000-993e-ba076c140000 pid=5228 execve guuid=3fb8e22e-1900-0000-993e-ba076d140000 pid=5229 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=3fb8e22e-1900-0000-993e-ba076d140000 pid=5229 clone guuid=aec7fd2f-1900-0000-993e-ba076f140000 pid=5231 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=aec7fd2f-1900-0000-993e-ba076f140000 pid=5231 execve guuid=a000a141-1900-0000-993e-ba0770140000 pid=5232 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=a000a141-1900-0000-993e-ba0770140000 pid=5232 execve guuid=a9ca4f42-1900-0000-993e-ba0771140000 pid=5233 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=a9ca4f42-1900-0000-993e-ba0771140000 pid=5233 clone guuid=02510643-1900-0000-993e-ba0773140000 pid=5235 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=02510643-1900-0000-993e-ba0773140000 pid=5235 execve guuid=62a93a63-1900-0000-993e-ba0774140000 pid=5236 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=62a93a63-1900-0000-993e-ba0774140000 pid=5236 execve guuid=24b99263-1900-0000-993e-ba0775140000 pid=5237 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=24b99263-1900-0000-993e-ba0775140000 pid=5237 clone guuid=4b923764-1900-0000-993e-ba0777140000 pid=5239 /usr/bin/wget net send-data guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=4b923764-1900-0000-993e-ba0777140000 pid=5239 execve guuid=e9c07c6a-1900-0000-993e-ba0778140000 pid=5240 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=e9c07c6a-1900-0000-993e-ba0778140000 pid=5240 execve guuid=3f0fd26a-1900-0000-993e-ba0779140000 pid=5241 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=3f0fd26a-1900-0000-993e-ba0779140000 pid=5241 clone guuid=5471796b-1900-0000-993e-ba077b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=5471796b-1900-0000-993e-ba077b140000 pid=5243 execve guuid=0d73577b-1900-0000-993e-ba0783140000 pid=5251 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=0d73577b-1900-0000-993e-ba0783140000 pid=5251 execve guuid=48bd587c-1900-0000-993e-ba0784140000 pid=5252 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=48bd587c-1900-0000-993e-ba0784140000 pid=5252 clone guuid=ff5a707e-1900-0000-993e-ba0786140000 pid=5254 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=ff5a707e-1900-0000-993e-ba0786140000 pid=5254 execve guuid=d5c2ff8c-1900-0000-993e-ba0787140000 pid=5255 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=d5c2ff8c-1900-0000-993e-ba0787140000 pid=5255 execve guuid=84c91d8e-1900-0000-993e-ba0788140000 pid=5256 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=84c91d8e-1900-0000-993e-ba0788140000 pid=5256 clone guuid=e24b7c90-1900-0000-993e-ba078a140000 pid=5258 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=e24b7c90-1900-0000-993e-ba078a140000 pid=5258 execve guuid=8773c6a3-1900-0000-993e-ba078b140000 pid=5259 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=8773c6a3-1900-0000-993e-ba078b140000 pid=5259 execve guuid=54808aa4-1900-0000-993e-ba078c140000 pid=5260 /usr/bin/bash guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=54808aa4-1900-0000-993e-ba078c140000 pid=5260 clone guuid=ce5535a6-1900-0000-993e-ba078e140000 pid=5262 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=ce5535a6-1900-0000-993e-ba078e140000 pid=5262 execve guuid=b0f89fb6-1900-0000-993e-ba078f140000 pid=5263 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=b0f89fb6-1900-0000-993e-ba078f140000 pid=5263 execve guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264 /home/sandbox/x86 net guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264 execve guuid=fc48b52f-1a00-0000-993e-ba0796140000 pid=5270 /usr/bin/wget net send-data write-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=fc48b52f-1a00-0000-993e-ba0796140000 pid=5270 execve guuid=b1453f42-1a00-0000-993e-ba0797140000 pid=5271 /usr/bin/chmod guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=b1453f42-1a00-0000-993e-ba0797140000 pid=5271 execve guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272 /home/sandbox/x86_64 net guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272 execve guuid=88e11eba-1a00-0000-993e-ba07ad140000 pid=5293 /usr/bin/rm delete-file guuid=19f048e9-1800-0000-993e-ba075e140000 pid=5214->guuid=88e11eba-1a00-0000-993e-ba07ad140000 pid=5293 execve 697679a7-cc0f-5478-83af-785833bd0767 143.20.185.78:80 guuid=2f2c25ea-1800-0000-993e-ba075f140000 pid=5215->697679a7-cc0f-5478-83af-785833bd0767 send: 136B guuid=e40ecbfb-1800-0000-993e-ba0763140000 pid=5219->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=c503c60b-1900-0000-993e-ba0767140000 pid=5223->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=6e7a3e1f-1900-0000-993e-ba076b140000 pid=5227->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=aec7fd2f-1900-0000-993e-ba076f140000 pid=5231->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=02510643-1900-0000-993e-ba0773140000 pid=5235->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=4b923764-1900-0000-993e-ba0777140000 pid=5239->697679a7-cc0f-5478-83af-785833bd0767 send: 137B guuid=5471796b-1900-0000-993e-ba077b140000 pid=5243->697679a7-cc0f-5478-83af-785833bd0767 send: 136B guuid=ff5a707e-1900-0000-993e-ba0786140000 pid=5254->697679a7-cc0f-5478-83af-785833bd0767 send: 136B guuid=e24b7c90-1900-0000-993e-ba078a140000 pid=5258->697679a7-cc0f-5478-83af-785833bd0767 send: 136B guuid=ce5535a6-1900-0000-993e-ba078e140000 pid=5262->697679a7-cc0f-5478-83af-785833bd0767 send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0f142db7-1900-0000-993e-ba0791140000 pid=5265 /home/sandbox/x86 guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264->guuid=0f142db7-1900-0000-993e-ba0791140000 pid=5265 clone guuid=fa12d6f2-1900-0000-993e-ba0792140000 pid=5266 /home/sandbox/x86 guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264->guuid=fa12d6f2-1900-0000-993e-ba0792140000 pid=5266 clone guuid=57367e2e-1a00-0000-993e-ba0793140000 pid=5267 /home/sandbox/x86 guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264->guuid=57367e2e-1a00-0000-993e-ba0793140000 pid=5267 clone guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268 /home/sandbox/x86 net zombie guuid=d329f4b6-1900-0000-993e-ba0790140000 pid=5264->guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268 clone a7b3d5bf-498c-5749-9bad-9fa497b96e1d 143.20.185.78:1999 guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268->a7b3d5bf-498c-5749-9bad-9fa497b96e1d con guuid=5f15c32e-1a00-0000-993e-ba0795140000 pid=5269 /home/sandbox/x86 guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268->guuid=5f15c32e-1a00-0000-993e-ba0795140000 pid=5269 clone guuid=799a6d6a-1a00-0000-993e-ba079a140000 pid=5274 /home/sandbox/x86 guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268->guuid=799a6d6a-1a00-0000-993e-ba079a140000 pid=5274 clone guuid=f13d23a6-1a00-0000-993e-ba07a2140000 pid=5282 /home/sandbox/x86 guuid=2c638b2e-1a00-0000-993e-ba0794140000 pid=5268->guuid=f13d23a6-1a00-0000-993e-ba07a2140000 pid=5282 clone guuid=fc48b52f-1a00-0000-993e-ba0796140000 pid=5270->697679a7-cc0f-5478-83af-785833bd0767 send: 139B guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9ba99f42-1a00-0000-993e-ba0799140000 pid=5273 /home/sandbox/x86_64 guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272->guuid=9ba99f42-1a00-0000-993e-ba0799140000 pid=5273 clone guuid=f2d1477e-1a00-0000-993e-ba079b140000 pid=5275 /home/sandbox/x86_64 guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272->guuid=f2d1477e-1a00-0000-993e-ba079b140000 pid=5275 clone guuid=3adffab9-1a00-0000-993e-ba07aa140000 pid=5290 /home/sandbox/x86_64 guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272->guuid=3adffab9-1a00-0000-993e-ba07aa140000 pid=5290 clone guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291 /home/sandbox/x86_64 net zombie guuid=f55f8342-1a00-0000-993e-ba0798140000 pid=5272->guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291 clone guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291->a7b3d5bf-498c-5749-9bad-9fa497b96e1d con guuid=78ec14ba-1a00-0000-993e-ba07ac140000 pid=5292 /home/sandbox/x86_64 guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291->guuid=78ec14ba-1a00-0000-993e-ba07ac140000 pid=5292 clone guuid=9102c3f5-1a00-0000-993e-ba07c1140000 pid=5313 /home/sandbox/x86_64 guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291->guuid=9102c3f5-1a00-0000-993e-ba07c1140000 pid=5313 clone guuid=ed2d6a31-1b00-0000-993e-ba07c2140000 pid=5314 /home/sandbox/x86_64 guuid=8b6704ba-1a00-0000-993e-ba07ab140000 pid=5291->guuid=ed2d6a31-1b00-0000-993e-ba07c2140000 pid=5314 clone
Threat name:
Script-Shell.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-21 13:27:16 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5f4831d6685b10793fcdf3fcac397864e1e62ede9ca4e11b70c41bb1611dcbb3

(this sample)

  
Delivery method
Distributed via web download

Comments