🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7d479a9f348ca2f64e26a75eb1ac5451cc98d2a2919973b700f4eaabc5678ccc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 7d479a9f348ca2f64e26a75eb1ac5451cc98d2a2919973b700f4eaabc5678ccc
SHA3-384 hash: 439724cadac8847af57198ff9a7b2fd25a0a52f8ab51371d7ac53c75acf966eae42ff15062a14f2426a894ee1e78c034
SHA1 hash: 6d192170a1946ed06671c9f9d8800621b22b4fa9
MD5 hash: 3856377fc629e356ef03dbb441741073
humanhash: stairway-michigan-uranus-grey
File name:w.sh
Download: download sample
Signature Mirai
File size:1'045 bytes
First seen:2026-10-04 07:04:40 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:siVTxCWEfNI9kxwAEySKxWHFxRI4qKAaGoBWnXPCRoeVn68x7+cAGJeqyFUv:XhONIq+Kxi1xrfWG4GJv
TLSH T1B51159CC3254A684041ECEC6375D4D0CA2449EE0E8D49B39A89E0EB77AD6F24FD45F1D
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.154.42/bins/bot.armn/an/aelf ua-wget
http://143.20.154.42/bins/bot.arm5749b170f0b22c17e812bc46a2eae2bd2aa262107e1ad8b82a5685cb6f1485504 Miraicowrie honeypot
http://143.20.154.42/bins/bot.arm6a5a3748bd02cd2fdd437f1951ab8649107d76c942f9717a4197fcd5e0a2ab09f Miraicowrie honeypot
http://143.20.154.42/bins/bot.arm7c680d68751452168707fb5235bacbcfe766bb34ad2b7d14f04c4746a14c1735a Miraicowrie honeypot
http://143.20.154.42/bins/bot.sh43e5ecb384cf34e56b7b77db65dc2d3780b0e192aa174a5c34efaa678a5e59b44 Miraielf ua-wget
http://143.20.154.42/bins/bot.arc07fc2e0cdebffaa01fb8bdccdb16e89db4653b6d0bfa56d182c31e0ceff82282 Miraicowrie honeypot
http://143.20.154.42/bins/bot.mips9d95e2ad6eff4c6763624ee22b30e593e3cc437dcac1ea507bdd4b4bfb1d3c70 Miraicowrie honeypot
http://143.20.154.42/bins/bot.mpsl1edf639a68f13c8be1f3ad91f7687953c4c49d7988903e8edfb3fd2a6fdc14a7 Miraielf ua-wget
http://143.20.154.42/bins/bot.ppc7de3374ebf3967054093d99ecd0df2cdea9db5edf1634b5bbd216c59842af244 Miraielf ua-wget
http://143.20.154.42/bins/bot.x86e3c4eab8fdd4782669a2101e8ead8fabf8f24f65da4099e31be43b4fc5c32658 Miraielf ua-wget
http://143.20.154.42/bins/bot.spc5abf5f183d69b05feed570c1c52fb216fa0aeab4a714e7bebbad1f885251184c Miraielf ua-wget
http://143.20.154.42/bins/bot.m68kaf750bda6c631c6dd416775b92a14b558ddfec18ce5721c9cde4b8bb222450ed Miraicowrie honeypot

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=e59a69d3-1900-0000-d092-942806080000 pid=2054 /usr/bin/sudo guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064 /tmp/sample.bin guuid=e59a69d3-1900-0000-d092-942806080000 pid=2054->guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064 execve guuid=e813d8d6-1900-0000-d092-942811080000 pid=2065 /usr/bin/busybox net send-data guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=e813d8d6-1900-0000-d092-942811080000 pid=2065 execve guuid=8661dad9-1900-0000-d092-942819080000 pid=2073 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=8661dad9-1900-0000-d092-942819080000 pid=2073 execve guuid=4af13dda-1900-0000-d092-94281b080000 pid=2075 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=4af13dda-1900-0000-d092-94281b080000 pid=2075 clone guuid=d95154da-1900-0000-d092-94281c080000 pid=2076 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=d95154da-1900-0000-d092-94281c080000 pid=2076 execve guuid=1cf96ee4-1900-0000-d092-942835080000 pid=2101 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=1cf96ee4-1900-0000-d092-942835080000 pid=2101 execve guuid=d4a1dfe4-1900-0000-d092-942837080000 pid=2103 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=d4a1dfe4-1900-0000-d092-942837080000 pid=2103 clone guuid=c17910e6-1900-0000-d092-94283c080000 pid=2108 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=c17910e6-1900-0000-d092-94283c080000 pid=2108 execve guuid=9958c4eb-1900-0000-d092-942847080000 pid=2119 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=9958c4eb-1900-0000-d092-942847080000 pid=2119 execve guuid=9ba21aec-1900-0000-d092-942849080000 pid=2121 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=9ba21aec-1900-0000-d092-942849080000 pid=2121 clone guuid=045483ed-1900-0000-d092-94284e080000 pid=2126 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=045483ed-1900-0000-d092-94284e080000 pid=2126 execve guuid=7f547cf2-1900-0000-d092-94285b080000 pid=2139 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=7f547cf2-1900-0000-d092-94285b080000 pid=2139 execve guuid=6350baf2-1900-0000-d092-94285c080000 pid=2140 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=6350baf2-1900-0000-d092-94285c080000 pid=2140 clone guuid=eb9527f4-1900-0000-d092-942861080000 pid=2145 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=eb9527f4-1900-0000-d092-942861080000 pid=2145 execve guuid=d56136f9-1900-0000-d092-94286a080000 pid=2154 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=d56136f9-1900-0000-d092-94286a080000 pid=2154 execve guuid=26139ff9-1900-0000-d092-94286c080000 pid=2156 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=26139ff9-1900-0000-d092-94286c080000 pid=2156 clone guuid=eb6c21fb-1900-0000-d092-942872080000 pid=2162 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=eb6c21fb-1900-0000-d092-942872080000 pid=2162 execve guuid=f1e83800-1a00-0000-d092-942877080000 pid=2167 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=f1e83800-1a00-0000-d092-942877080000 pid=2167 execve guuid=847e3201-1a00-0000-d092-94287a080000 pid=2170 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=847e3201-1a00-0000-d092-94287a080000 pid=2170 clone guuid=ae81f903-1a00-0000-d092-942880080000 pid=2176 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=ae81f903-1a00-0000-d092-942880080000 pid=2176 execve guuid=5943f108-1a00-0000-d092-942886080000 pid=2182 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=5943f108-1a00-0000-d092-942886080000 pid=2182 execve guuid=5c2a5409-1a00-0000-d092-942887080000 pid=2183 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=5c2a5409-1a00-0000-d092-942887080000 pid=2183 clone guuid=8e062a0b-1a00-0000-d092-94288c080000 pid=2188 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=8e062a0b-1a00-0000-d092-94288c080000 pid=2188 execve guuid=38012e10-1a00-0000-d092-942892080000 pid=2194 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=38012e10-1a00-0000-d092-942892080000 pid=2194 execve guuid=d206bc10-1a00-0000-d092-942893080000 pid=2195 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=d206bc10-1a00-0000-d092-942893080000 pid=2195 clone guuid=e703b111-1a00-0000-d092-942896080000 pid=2198 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=e703b111-1a00-0000-d092-942896080000 pid=2198 execve guuid=5ddf5616-1a00-0000-d092-9428a0080000 pid=2208 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=5ddf5616-1a00-0000-d092-9428a0080000 pid=2208 execve guuid=57c8e716-1a00-0000-d092-9428a1080000 pid=2209 /usr/bin/dash guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=57c8e716-1a00-0000-d092-9428a1080000 pid=2209 clone guuid=eb4e8718-1a00-0000-d092-9428a4080000 pid=2212 /usr/bin/busybox net send-data write-file guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=eb4e8718-1a00-0000-d092-9428a4080000 pid=2212 execve guuid=eae0a41d-1a00-0000-d092-9428ac080000 pid=2220 /usr/bin/chmod guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=eae0a41d-1a00-0000-d092-9428ac080000 pid=2220 execve guuid=70742b1e-1a00-0000-d092-9428ad080000 pid=2221 /home/sandbox/bot.x86 delete-file net send-data guuid=e21b91d6-1900-0000-d092-942810080000 pid=2064->guuid=70742b1e-1a00-0000-d092-9428ad080000 pid=2221 execve c393f8b5-eb07-5bf2-8a45-29d2f80599cf 143.20.154.42:80 guuid=e813d8d6-1900-0000-d092-942811080000 pid=2065->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 88B guuid=d95154da-1900-0000-d092-94281c080000 pid=2076->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 89B guuid=c17910e6-1900-0000-d092-94283c080000 pid=2108->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 89B guuid=045483ed-1900-0000-d092-94284e080000 pid=2126->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 89B guuid=eb9527f4-1900-0000-d092-942861080000 pid=2145->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 88B guuid=eb6c21fb-1900-0000-d092-942872080000 pid=2162->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 88B guuid=ae81f903-1a00-0000-d092-942880080000 pid=2176->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 89B guuid=8e062a0b-1a00-0000-d092-94288c080000 pid=2188->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 89B guuid=e703b111-1a00-0000-d092-942896080000 pid=2198->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 88B guuid=eb4e8718-1a00-0000-d092-9428a4080000 pid=2212->c393f8b5-eb07-5bf2-8a45-29d2f80599cf send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=70742b1e-1a00-0000-d092-9428ad080000 pid=2221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e16056eb-da4c-5126-84a5-d3080bdf070b 91.92.47.97:23004 guuid=70742b1e-1a00-0000-d092-9428ad080000 pid=2221->e16056eb-da4c-5126-84a5-d3080bdf070b send: 43B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-10-03 22:53:20 UTC
File Type:
Text (Shell)
AV detection:
16 of 36 (44.44%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7d479a9f348ca2f64e26a75eb1ac5451cc98d2a2919973b700f4eaabc5678ccc

(this sample)

  
Delivery method
Distributed via web download

Comments