MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 620e9a7dc1090c48edae5bb3374b9b0a7fc7fa3d1f4063f49e9fb10d11df8b15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 620e9a7dc1090c48edae5bb3374b9b0a7fc7fa3d1f4063f49e9fb10d11df8b15
SHA3-384 hash: c9bd3415ed52dde25243c1548b94d8fa785c2c6ae3e268cf1ae7c4497367d2fcd48dcdd9aaec438ecbae969d7712528a
SHA1 hash: d9313fcea6c221a4f634eeb3ddff27007e3c76e2
MD5 hash: 95353f04087412d8adf9c9c4f01a1fc3
humanhash: april-fish-quiet-victor
File name:620e9a7dc1090c48edae5bb3374b9b0a7fc7fa3d1f4063f49e9fb10d11df8b15
Download: download sample
Signature Mirai
File size:1'845 bytes
First seen:2026-05-28 22:30:29 UTC
Last seen:2026-05-29 13:24:09 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:T+kuoDdBHWtIf1CvRWFPFBM/hf/u/1bC/2/2waZf6fF81o7jt4gKJWwJbHR4BYWd:qq1m5No72A
TLSH T1C831CA9AA0B891418588CE40B0F54DCF773BA69061A5463AF8433EB780C9D6A311DAFF
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter c2hunter
Tags:31-56-209-72 sh wraith
URLMalware sample (SHA256 hash)SignatureTags
http://31.56.209.72/iran.x86_64ac0fa0ac1a0e8e7f17328b85565988fc635f3c6298219779071ac06b0176a082 Miraimirai wraith
http://31.56.209.72/iran.aarch64a685313f3a72b5ad36df2c040aefab162bfd50c5914296a64bc298502091f00b Miraimirai wraith
http://31.56.209.72/iran.m68k5f7aad3cd758c51387940f9899324d461bfc58cedf819594f3b002b42ddbd4cd Miraimirai wraith
http://31.56.209.72/iran.mips3a06875b9404a65b68a43ddeebb17ae3e7569f0a003df2ee2f673ec591727dcd Miraimirai wraith
http://31.56.209.72/iran.mipsel36839038451f5ab313a47212fd7d904f668fd449383017a9b4696f1ef42dc5ac Miraimirai wraith
http://31.56.209.72/iran.powerpc4701e50221f07b0f642dc8b1793e8759bd722d192d514740132ac54fc16c7f6e Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.sparcca7500cb2ded4077485e952dd953ec6c56a7064967a813c0d06bacfa26765854 Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.sh4cc39b770d4557969d538258e162a86c7698d86af53665a105d648b0ae0d85de0 Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.arce2542debca5a511aa354fa38329b819194c7a044191f70e0840ac678a8f1baff Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.i4861a1016c10626697a229d879faf65881c8a53a74136e59ebc5197c500d448d8d7 Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.armv4l1164d0e17da932bb76bfe1797943dfadcb26eab5306366ca61353a6d7735076c Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.armv5l06cd8b579b111c6b1c2d75b41f792908fec69cf8406fc6745043101aac53c599 Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.armv6l20727a163bcbe6aca6dfdde726d7049df53a93d08d238aec93266e1ef11d9206 Mirai31-56-209-72 elf mirai ua-wget
http://31.56.209.72/iran.armv7l1eb3f62d55cf55412c164fa7cd891d40225066d391ea54363de788f29f20d8c1 Mirai31-56-209-72 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
6
# of downloads :
84
Origin country :
US US
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-28T19:38:00Z UTC
Last seen:
2026-05-29T05:40:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=a7eb9f11-2000-0000-a57b-6a63e1090000 pid=2529 /usr/bin/sudo guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534 /tmp/sample.bin guuid=a7eb9f11-2000-0000-a57b-6a63e1090000 pid=2529->guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534 execve guuid=f4133514-2000-0000-a57b-6a63e7090000 pid=2535 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=f4133514-2000-0000-a57b-6a63e7090000 pid=2535 execve guuid=59ced61b-2000-0000-a57b-6a63f4090000 pid=2548 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=59ced61b-2000-0000-a57b-6a63f4090000 pid=2548 execve guuid=4f4b441c-2000-0000-a57b-6a63f6090000 pid=2550 /home/sandbox/iran.x86_64 mprotect-exec guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=4f4b441c-2000-0000-a57b-6a63f6090000 pid=2550 execve guuid=24047a1d-2000-0000-a57b-6a63fb090000 pid=2555 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=24047a1d-2000-0000-a57b-6a63fb090000 pid=2555 execve guuid=d1d30b24-2000-0000-a57b-6a63070a0000 pid=2567 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=d1d30b24-2000-0000-a57b-6a63070a0000 pid=2567 execve guuid=78478424-2000-0000-a57b-6a63080a0000 pid=2568 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=78478424-2000-0000-a57b-6a63080a0000 pid=2568 clone guuid=fc228425-2000-0000-a57b-6a630b0a0000 pid=2571 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=fc228425-2000-0000-a57b-6a630b0a0000 pid=2571 execve guuid=f21e432b-2000-0000-a57b-6a63160a0000 pid=2582 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=f21e432b-2000-0000-a57b-6a63160a0000 pid=2582 execve guuid=46d0952b-2000-0000-a57b-6a63180a0000 pid=2584 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=46d0952b-2000-0000-a57b-6a63180a0000 pid=2584 clone guuid=bf96372c-2000-0000-a57b-6a631b0a0000 pid=2587 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=bf96372c-2000-0000-a57b-6a631b0a0000 pid=2587 execve guuid=df02ea31-2000-0000-a57b-6a63290a0000 pid=2601 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=df02ea31-2000-0000-a57b-6a63290a0000 pid=2601 execve guuid=9fb64832-2000-0000-a57b-6a632c0a0000 pid=2604 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=9fb64832-2000-0000-a57b-6a632c0a0000 pid=2604 clone guuid=50d6a534-2000-0000-a57b-6a63330a0000 pid=2611 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=50d6a534-2000-0000-a57b-6a63330a0000 pid=2611 execve guuid=1e61b33a-2000-0000-a57b-6a63430a0000 pid=2627 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=1e61b33a-2000-0000-a57b-6a63430a0000 pid=2627 execve guuid=34132d3b-2000-0000-a57b-6a63450a0000 pid=2629 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=34132d3b-2000-0000-a57b-6a63450a0000 pid=2629 clone guuid=3c936b3c-2000-0000-a57b-6a63490a0000 pid=2633 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=3c936b3c-2000-0000-a57b-6a63490a0000 pid=2633 execve guuid=38b65442-2000-0000-a57b-6a63580a0000 pid=2648 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=38b65442-2000-0000-a57b-6a63580a0000 pid=2648 execve guuid=3f07c142-2000-0000-a57b-6a635a0a0000 pid=2650 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=3f07c142-2000-0000-a57b-6a635a0a0000 pid=2650 clone guuid=812b9543-2000-0000-a57b-6a635e0a0000 pid=2654 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=812b9543-2000-0000-a57b-6a635e0a0000 pid=2654 execve guuid=dd1deb46-2000-0000-a57b-6a63670a0000 pid=2663 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=dd1deb46-2000-0000-a57b-6a63670a0000 pid=2663 execve guuid=3a604347-2000-0000-a57b-6a63690a0000 pid=2665 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=3a604347-2000-0000-a57b-6a63690a0000 pid=2665 clone guuid=559af847-2000-0000-a57b-6a636c0a0000 pid=2668 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=559af847-2000-0000-a57b-6a636c0a0000 pid=2668 execve guuid=f61a9b4d-2000-0000-a57b-6a63790a0000 pid=2681 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=f61a9b4d-2000-0000-a57b-6a63790a0000 pid=2681 execve guuid=ed7b004e-2000-0000-a57b-6a637b0a0000 pid=2683 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=ed7b004e-2000-0000-a57b-6a637b0a0000 pid=2683 clone guuid=8b5b024f-2000-0000-a57b-6a63800a0000 pid=2688 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=8b5b024f-2000-0000-a57b-6a63800a0000 pid=2688 execve guuid=d240aa54-2000-0000-a57b-6a638f0a0000 pid=2703 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=d240aa54-2000-0000-a57b-6a638f0a0000 pid=2703 execve guuid=f1747355-2000-0000-a57b-6a63920a0000 pid=2706 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=f1747355-2000-0000-a57b-6a63920a0000 pid=2706 clone guuid=ca75cb57-2000-0000-a57b-6a639b0a0000 pid=2715 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=ca75cb57-2000-0000-a57b-6a639b0a0000 pid=2715 execve guuid=a8fe225c-2000-0000-a57b-6a63a70a0000 pid=2727 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=a8fe225c-2000-0000-a57b-6a63a70a0000 pid=2727 execve guuid=477a7f5c-2000-0000-a57b-6a63a90a0000 pid=2729 /home/sandbox/iran.i486 guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=477a7f5c-2000-0000-a57b-6a63a90a0000 pid=2729 execve guuid=668fd15c-2000-0000-a57b-6a63ac0a0000 pid=2732 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=668fd15c-2000-0000-a57b-6a63ac0a0000 pid=2732 execve guuid=ff75ad63-2000-0000-a57b-6a63c00a0000 pid=2752 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=ff75ad63-2000-0000-a57b-6a63c00a0000 pid=2752 execve guuid=004bf163-2000-0000-a57b-6a63c10a0000 pid=2753 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=004bf163-2000-0000-a57b-6a63c10a0000 pid=2753 clone guuid=bb9d9f64-2000-0000-a57b-6a63c50a0000 pid=2757 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=bb9d9f64-2000-0000-a57b-6a63c50a0000 pid=2757 execve guuid=2c65d269-2000-0000-a57b-6a63d50a0000 pid=2773 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=2c65d269-2000-0000-a57b-6a63d50a0000 pid=2773 execve guuid=2c17306a-2000-0000-a57b-6a63d80a0000 pid=2776 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=2c17306a-2000-0000-a57b-6a63d80a0000 pid=2776 clone guuid=ad42b86a-2000-0000-a57b-6a63dc0a0000 pid=2780 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=ad42b86a-2000-0000-a57b-6a63dc0a0000 pid=2780 execve guuid=220c0270-2000-0000-a57b-6a63e90a0000 pid=2793 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=220c0270-2000-0000-a57b-6a63e90a0000 pid=2793 execve guuid=f8c65770-2000-0000-a57b-6a63eb0a0000 pid=2795 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=f8c65770-2000-0000-a57b-6a63eb0a0000 pid=2795 clone guuid=7791e770-2000-0000-a57b-6a63ee0a0000 pid=2798 /usr/bin/wget net send-data write-file guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=7791e770-2000-0000-a57b-6a63ee0a0000 pid=2798 execve guuid=bad67075-2000-0000-a57b-6a63f80a0000 pid=2808 /usr/bin/chmod guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=bad67075-2000-0000-a57b-6a63f80a0000 pid=2808 execve guuid=1b9edc75-2000-0000-a57b-6a63f90a0000 pid=2809 /usr/bin/dash guuid=a78eb513-2000-0000-a57b-6a63e6090000 pid=2534->guuid=1b9edc75-2000-0000-a57b-6a63f90a0000 pid=2809 clone 8bd99f5f-012e-5440-a94c-d890af1e1fcc 31.56.209.72:80 guuid=f4133514-2000-0000-a57b-6a63e7090000 pid=2535->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B guuid=c3826d1d-2000-0000-a57b-6a63fa090000 pid=2554 /home/sandbox/iran.x86_64 zombie guuid=4f4b441c-2000-0000-a57b-6a63f6090000 pid=2550->guuid=c3826d1d-2000-0000-a57b-6a63fa090000 pid=2554 clone guuid=4c847e1d-2000-0000-a57b-6a63fd090000 pid=2557 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=c3826d1d-2000-0000-a57b-6a63fa090000 pid=2554->guuid=4c847e1d-2000-0000-a57b-6a63fd090000 pid=2557 clone guuid=24047a1d-2000-0000-a57b-6a63fb090000 pid=2555->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 139B 040883b6-b66d-5410-b15d-96476649d826 31.56.209.72:621 guuid=4c847e1d-2000-0000-a57b-6a63fd090000 pid=2557->040883b6-b66d-5410-b15d-96476649d826 send: 413B guuid=fc228425-2000-0000-a57b-6a630b0a0000 pid=2571->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 136B guuid=bf96372c-2000-0000-a57b-6a631b0a0000 pid=2587->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 136B guuid=50d6a534-2000-0000-a57b-6a63330a0000 pid=2611->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B guuid=3c936b3c-2000-0000-a57b-6a63490a0000 pid=2633->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 139B guuid=812b9543-2000-0000-a57b-6a635e0a0000 pid=2654->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 137B guuid=559af847-2000-0000-a57b-6a636c0a0000 pid=2668->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 135B guuid=8b5b024f-2000-0000-a57b-6a63800a0000 pid=2688->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 135B guuid=ca75cb57-2000-0000-a57b-6a639b0a0000 pid=2715->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 136B guuid=7b3dc85c-2000-0000-a57b-6a63ab0a0000 pid=2731 /home/sandbox/iran.i486 guuid=477a7f5c-2000-0000-a57b-6a63a90a0000 pid=2729->guuid=7b3dc85c-2000-0000-a57b-6a63ab0a0000 pid=2731 clone guuid=5c31d55c-2000-0000-a57b-6a63ad0a0000 pid=2733 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=7b3dc85c-2000-0000-a57b-6a63ab0a0000 pid=2731->guuid=5c31d55c-2000-0000-a57b-6a63ad0a0000 pid=2733 clone guuid=668fd15c-2000-0000-a57b-6a63ac0a0000 pid=2732->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B guuid=5c31d55c-2000-0000-a57b-6a63ad0a0000 pid=2733->040883b6-b66d-5410-b15d-96476649d826 send: 1102B guuid=bb9d9f64-2000-0000-a57b-6a63c50a0000 pid=2757->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B guuid=ad42b86a-2000-0000-a57b-6a63dc0a0000 pid=2780->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B guuid=7791e770-2000-0000-a57b-6a63ee0a0000 pid=2798->8bd99f5f-012e-5440-a94c-d890af1e1fcc send: 138B
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-05-28 22:30:44 UTC
File Type:
Text (Shell)
AV detection:
16 of 38 (42.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 620e9a7dc1090c48edae5bb3374b9b0a7fc7fa3d1f4063f49e9fb10d11df8b15

(this sample)

  
Delivery method
Distributed via web download

Comments