MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 857a7bd53687d574906c513adbcff9fecb1269a69756446327e6cee07980e817. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 857a7bd53687d574906c513adbcff9fecb1269a69756446327e6cee07980e817
SHA3-384 hash: 2c3a85263c3033bd02abac7b646d6093b6e8cbec21ff0fb60669bb4f88a30b61baab989e6b3a0445ddcb2f15999013c3
SHA1 hash: 04f894cbfbca34e8bf5db8506dd8d5ac9bf5267d
MD5 hash: 2b1931ca78a0c1832deb0d154fbd17a1
humanhash: failed-mars-virginia-utah
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'901 bytes
First seen:2026-02-25 06:20:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:U/+/C/s/S/b/3e/k/w1Z/b/gl/3/HO/4/6/U/S///m/Q/So7k/N/Pe/m/e/H/a/C:U/+/C/s/S/b/3e/k/w1Z/b/gl/3/u/4S
TLSH T1D44173BE70F04841A98CDE1170E18DCA6329B5E167F0EE7ADD722EE36499D44740DE39
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://134.199.219.57/iran.x86_642b40237fa268dd81ec44e10f185d10da344d116dd8e566dbb18ec61a15590609 Miraielf mirai ua-wget
http://134.199.219.57/iran.aarch64a4f7b8c997d248e9c5dd3eeebca12c564ac98d6240e3b115e51f6c0f4693aa5d Miraielf mirai ua-wget
http://134.199.219.57/iran.m68k9fc56422a874797270f38452ad65be9a9e5626aa8ea3ab0daa0ba52daec931ed Miraielf mirai ua-wget
http://134.199.219.57/iran.mips40e8cff1533cadd997f406fae014328c48b30b46f4d3f56166605daed077ae28 Miraielf mirai ua-wget
http://134.199.219.57/iran.mipsel333cb5f771c828d85004e9842dbd1c01edd7b7295e2d0c1fb8d32b112a2be9e6 Miraielf mirai ua-wget
http://134.199.219.57/iran.powerpc5b3dce5e66f16d232532c34188f6cebebc0fc5b987bb1d2a426d92d148a706f1 Miraielf mirai ua-wget
http://134.199.219.57/iran.sparc22ffc6049a2dcf9ea8aef5bb95367f820cce4b220fdfff739010456ab278134e Miraielf mirai ua-wget
http://134.199.219.57/iran.sh4ebd0f4b199ef35e23850d170d92436058e7beb3fd4a37291e0c4304dcd96564d Miraielf mirai ua-wget
http://134.199.219.57/iran.arc1fa43c3b5fcf1f01c4a9d961fa7c97b53103ea65bf27e4815e55d4ec4f5be497 Miraielf mirai ua-wget
http://134.199.219.57/iran.i486b683f75b4d148ee87892db75e268901702d9c126548aac22654ee8b061eea6ce Miraielf mirai ua-wget
http://134.199.219.57/iran.armv4l90b66cc73c8b1746d91b9e5247e6827499c9d99a94912d29a0f437c6a8ab5507 Miraielf mirai ua-wget
http://134.199.219.57/iran.armv5le62fb431f629a2237769068064f7d01c932a3b467581b2dc99ac807f3542f999 Miraielf mirai ua-wget
http://134.199.219.57/iran.armv6l6ddafb2228db6334f44afd23775fec15477d7bf128986d7ba1214dd2999c9f78 Miraielf mirai ua-wget
http://134.199.219.57/iran.armv7l57a20a038a9dffe4a120cfb2c7bbc871d241c7121752208d9f07d889742d6bcc Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
92
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9022ae20-1700-0000-f3ba-350a4b110000 pid=4427 /usr/bin/sudo guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438 /tmp/sample.bin guuid=9022ae20-1700-0000-f3ba-350a4b110000 pid=4427->guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438 execve guuid=6f476223-1700-0000-f3ba-350a59110000 pid=4441 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=6f476223-1700-0000-f3ba-350a59110000 pid=4441 execve guuid=0f3a9848-1700-0000-f3ba-350afe110000 pid=4606 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=0f3a9848-1700-0000-f3ba-350afe110000 pid=4606 execve guuid=d9c6fc48-1700-0000-f3ba-350a01120000 pid=4609 /home/sandbox/iran.x86_64 mprotect-exec guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=d9c6fc48-1700-0000-f3ba-350a01120000 pid=4609 execve guuid=1128514a-1700-0000-f3ba-350a07120000 pid=4615 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=1128514a-1700-0000-f3ba-350a07120000 pid=4615 execve guuid=b5617575-1700-0000-f3ba-350ace120000 pid=4814 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=b5617575-1700-0000-f3ba-350ace120000 pid=4814 execve guuid=be3ab175-1700-0000-f3ba-350ad0120000 pid=4816 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=be3ab175-1700-0000-f3ba-350ad0120000 pid=4816 clone guuid=ddc14a76-1700-0000-f3ba-350ad4120000 pid=4820 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=ddc14a76-1700-0000-f3ba-350ad4120000 pid=4820 execve guuid=1c8527a1-1700-0000-f3ba-350a7d130000 pid=4989 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=1c8527a1-1700-0000-f3ba-350a7d130000 pid=4989 execve guuid=52505ca1-1700-0000-f3ba-350a7f130000 pid=4991 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=52505ca1-1700-0000-f3ba-350a7f130000 pid=4991 clone guuid=e1b0e4a1-1700-0000-f3ba-350a84130000 pid=4996 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=e1b0e4a1-1700-0000-f3ba-350a84130000 pid=4996 execve guuid=8436aecc-1700-0000-f3ba-350a17140000 pid=5143 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=8436aecc-1700-0000-f3ba-350a17140000 pid=5143 execve guuid=0babe4cc-1700-0000-f3ba-350a19140000 pid=5145 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=0babe4cc-1700-0000-f3ba-350a19140000 pid=5145 clone guuid=3ba056cd-1700-0000-f3ba-350a1c140000 pid=5148 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=3ba056cd-1700-0000-f3ba-350a1c140000 pid=5148 execve guuid=7daa9dfe-1700-0000-f3ba-350a71140000 pid=5233 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=7daa9dfe-1700-0000-f3ba-350a71140000 pid=5233 execve guuid=64e3fefe-1700-0000-f3ba-350a72140000 pid=5234 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=64e3fefe-1700-0000-f3ba-350a72140000 pid=5234 clone guuid=06a1afff-1700-0000-f3ba-350a74140000 pid=5236 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=06a1afff-1700-0000-f3ba-350a74140000 pid=5236 execve guuid=5496a92a-1800-0000-f3ba-350a7d140000 pid=5245 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=5496a92a-1800-0000-f3ba-350a7d140000 pid=5245 execve guuid=e3d4042b-1800-0000-f3ba-350a7e140000 pid=5246 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=e3d4042b-1800-0000-f3ba-350a7e140000 pid=5246 clone guuid=9cbaa92d-1800-0000-f3ba-350a80140000 pid=5248 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=9cbaa92d-1800-0000-f3ba-350a80140000 pid=5248 execve guuid=a80d2b41-1800-0000-f3ba-350a81140000 pid=5249 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=a80d2b41-1800-0000-f3ba-350a81140000 pid=5249 execve guuid=c71c7841-1800-0000-f3ba-350a82140000 pid=5250 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=c71c7841-1800-0000-f3ba-350a82140000 pid=5250 clone guuid=56ff1d42-1800-0000-f3ba-350a84140000 pid=5252 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=56ff1d42-1800-0000-f3ba-350a84140000 pid=5252 execve guuid=64a4086d-1800-0000-f3ba-350a85140000 pid=5253 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=64a4086d-1800-0000-f3ba-350a85140000 pid=5253 execve guuid=c7b8546d-1800-0000-f3ba-350a86140000 pid=5254 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=c7b8546d-1800-0000-f3ba-350a86140000 pid=5254 clone guuid=f32c326e-1800-0000-f3ba-350a88140000 pid=5256 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=f32c326e-1800-0000-f3ba-350a88140000 pid=5256 execve guuid=e093f99a-1800-0000-f3ba-350a89140000 pid=5257 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=e093f99a-1800-0000-f3ba-350a89140000 pid=5257 execve guuid=d047459b-1800-0000-f3ba-350a8a140000 pid=5258 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=d047459b-1800-0000-f3ba-350a8a140000 pid=5258 clone guuid=d0a9e39b-1800-0000-f3ba-350a8c140000 pid=5260 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=d0a9e39b-1800-0000-f3ba-350a8c140000 pid=5260 execve guuid=07d0c7be-1800-0000-f3ba-350a8d140000 pid=5261 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=07d0c7be-1800-0000-f3ba-350a8d140000 pid=5261 execve guuid=c00632bf-1800-0000-f3ba-350a8e140000 pid=5262 /home/sandbox/iran.i486 guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=c00632bf-1800-0000-f3ba-350a8e140000 pid=5262 execve guuid=4803e3bf-1800-0000-f3ba-350a90140000 pid=5264 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=4803e3bf-1800-0000-f3ba-350a90140000 pid=5264 execve guuid=c220beed-1800-0000-f3ba-350a99140000 pid=5273 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=c220beed-1800-0000-f3ba-350a99140000 pid=5273 execve guuid=eb191aee-1800-0000-f3ba-350a9a140000 pid=5274 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=eb191aee-1800-0000-f3ba-350a9a140000 pid=5274 clone guuid=f15658ef-1800-0000-f3ba-350a9c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=f15658ef-1800-0000-f3ba-350a9c140000 pid=5276 execve guuid=22ba591c-1900-0000-f3ba-350a9d140000 pid=5277 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=22ba591c-1900-0000-f3ba-350a9d140000 pid=5277 execve guuid=6b93c31c-1900-0000-f3ba-350a9e140000 pid=5278 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=6b93c31c-1900-0000-f3ba-350a9e140000 pid=5278 clone guuid=26139f1d-1900-0000-f3ba-350aa0140000 pid=5280 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=26139f1d-1900-0000-f3ba-350aa0140000 pid=5280 execve guuid=a03c6849-1900-0000-f3ba-350aa1140000 pid=5281 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=a03c6849-1900-0000-f3ba-350aa1140000 pid=5281 execve guuid=b62b0a4a-1900-0000-f3ba-350aa2140000 pid=5282 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=b62b0a4a-1900-0000-f3ba-350aa2140000 pid=5282 clone guuid=a2f2144d-1900-0000-f3ba-350aa4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=a2f2144d-1900-0000-f3ba-350aa4140000 pid=5284 execve guuid=e6248170-1900-0000-f3ba-350aa5140000 pid=5285 /usr/bin/chmod guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=e6248170-1900-0000-f3ba-350aa5140000 pid=5285 execve guuid=aefd2371-1900-0000-f3ba-350aa6140000 pid=5286 /usr/bin/dash guuid=578b1f23-1700-0000-f3ba-350a56110000 pid=4438->guuid=aefd2371-1900-0000-f3ba-350aa6140000 pid=5286 clone 24e510f5-4849-5b5d-9499-93bc9107d34b 134.199.219.57:80 guuid=6f476223-1700-0000-f3ba-350a59110000 pid=4441->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B guuid=0743464a-1700-0000-f3ba-350a05120000 pid=4613 /home/sandbox/iran.x86_64 zombie guuid=d9c6fc48-1700-0000-f3ba-350a01120000 pid=4609->guuid=0743464a-1700-0000-f3ba-350a05120000 pid=4613 clone guuid=1a364f4a-1700-0000-f3ba-350a06120000 pid=4614 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=0743464a-1700-0000-f3ba-350a05120000 pid=4613->guuid=1a364f4a-1700-0000-f3ba-350a06120000 pid=4614 clone c1d30aec-c2bf-5986-a54f-223c1f729707 134.199.219.57:6060 guuid=1a364f4a-1700-0000-f3ba-350a06120000 pid=4614->c1d30aec-c2bf-5986-a54f-223c1f729707 send: 226B guuid=1128514a-1700-0000-f3ba-350a07120000 pid=4615->24e510f5-4849-5b5d-9499-93bc9107d34b send: 141B guuid=ddc14a76-1700-0000-f3ba-350ad4120000 pid=4820->24e510f5-4849-5b5d-9499-93bc9107d34b send: 138B guuid=e1b0e4a1-1700-0000-f3ba-350a84130000 pid=4996->24e510f5-4849-5b5d-9499-93bc9107d34b send: 138B guuid=3ba056cd-1700-0000-f3ba-350a1c140000 pid=5148->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B guuid=06a1afff-1700-0000-f3ba-350a74140000 pid=5236->24e510f5-4849-5b5d-9499-93bc9107d34b send: 141B guuid=9cbaa92d-1800-0000-f3ba-350a80140000 pid=5248->24e510f5-4849-5b5d-9499-93bc9107d34b send: 139B guuid=56ff1d42-1800-0000-f3ba-350a84140000 pid=5252->24e510f5-4849-5b5d-9499-93bc9107d34b send: 137B guuid=f32c326e-1800-0000-f3ba-350a88140000 pid=5256->24e510f5-4849-5b5d-9499-93bc9107d34b send: 137B guuid=d0a9e39b-1800-0000-f3ba-350a8c140000 pid=5260->24e510f5-4849-5b5d-9499-93bc9107d34b send: 138B guuid=1900dbbf-1800-0000-f3ba-350a8f140000 pid=5263 /home/sandbox/iran.i486 guuid=c00632bf-1800-0000-f3ba-350a8e140000 pid=5262->guuid=1900dbbf-1800-0000-f3ba-350a8f140000 pid=5263 clone guuid=6632eebf-1800-0000-f3ba-350a91140000 pid=5265 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=1900dbbf-1800-0000-f3ba-350a8f140000 pid=5263->guuid=6632eebf-1800-0000-f3ba-350a91140000 pid=5265 clone guuid=4803e3bf-1800-0000-f3ba-350a90140000 pid=5264->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B guuid=6632eebf-1800-0000-f3ba-350a91140000 pid=5265->c1d30aec-c2bf-5986-a54f-223c1f729707 send: 798B guuid=f15658ef-1800-0000-f3ba-350a9c140000 pid=5276->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B guuid=26139f1d-1900-0000-f3ba-350aa0140000 pid=5280->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B guuid=a2f2144d-1900-0000-f3ba-350aa4140000 pid=5284->24e510f5-4849-5b5d-9499-93bc9107d34b send: 140B
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2026-02-25 06:21:36 UTC
File Type:
Text (Shell)
AV detection:
16 of 38 (42.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 857a7bd53687d574906c513adbcff9fecb1269a69756446327e6cee07980e817

(this sample)

  
Delivery method
Distributed via web download

Comments