MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 913738ca6e5e394e41a9a243e07d7864bf4073fa6abbc780bc0d5c3fd0c4ab28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 913738ca6e5e394e41a9a243e07d7864bf4073fa6abbc780bc0d5c3fd0c4ab28
SHA3-384 hash: 9541d1dad0e9a3b01a63cf5bf9331230536cd398ced51730b96450dde2de69cb1d7917c7b686fbdbee6c0541b0f85add
SHA1 hash: fa085d032972f145bd2b521cf42137e5cf9dd4e9
MD5 hash: e5ec609a9b55791ff3c06948b285be34
humanhash: beer-mexico-timing-finch
File name:exodus.sh
Download: download sample
Signature Mirai
File size:802 bytes
First seen:2026-08-05 04:05:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:mSp4RaDKkJQBsUXpIvRffiFl3zUzE1tjhISZBsr:Sa/Qq7yFxdhBqr
TLSH T14601A18926452972CFEC9B1CB8534CF0E08933C9E4D3067894A67CAA1D95B2CBD0BD0B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.236/bins/x86668d048f71dcd3c9ad7aea64b28c944e86806ed200fd2cb76bc6a511ee570048 Miraielf ua-wget
http://94.154.43.236/bins/x32668d048f71dcd3c9ad7aea64b28c944e86806ed200fd2cb76bc6a511ee570048 Miraielf ua-wget
http://94.154.43.236/bins/mips7b50e4b46def7510b0adcf2a30c354c5641de17e89f3b60e4fc920c9f632945b Miraielf ua-wget
http://94.154.43.236/bins/mipselc16c65bbfbbdd5b1cbf140be9770b8240d4e67f1697df3f55452185183111409 Miraielf ua-wget
http://94.154.43.236/bins/arm7feb637f11f2e3e560c248ee1340751ba163db5504a5ab934aafd741dd0bf2bb8 Miraielf ua-wget
http://94.154.43.236/bins/sh43a07c06437a6d8ab4f3abab5d7246a0425161826ad54f809c0f4fac1aa6c3299 Miraielf ua-wget
http://94.154.43.236/bins/arm6c5fb7dc78ff2f03cbe493a5d77a68543af4a8e91093b6ed0b5b74e525b1dfbba Miraielf ua-wget
http://94.154.43.236/bins/ppce27ae838a219c644b4d96ef15d1d847804099daab9acbff78d91d529f733f878 Miraielf ua-wget
http://94.154.43.236/bins/m68k0461f91f0a48757234668f5b908b2c25d9c43035288ea40a0c68c90339a47710 Miraielf ua-wget
http://94.154.43.236/bins/arm4f5cdc12db4618fea080a8721459d6e6afdff43516a05761974bcb462d668e134 Miraielf ua-wget
http://94.154.43.236/bins/arm5ae9c890eb876f0c8fc70e44111a57687339c2f446e16ae3e41ab15a6620456cc Miraielf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
68
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-05T01:35:00Z UTC
Last seen:
2026-08-05T12:59:00Z UTC
Hits:
~10
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-08-05 04:00:38 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 913738ca6e5e394e41a9a243e07d7864bf4073fa6abbc780bc0d5c3fd0c4ab28

(this sample)

  
Delivery method
Distributed via web download

Comments