MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a7caebf876aa6addee9de8a1acfb274bed980759e124dc48896891aad612093. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 9a7caebf876aa6addee9de8a1acfb274bed980759e124dc48896891aad612093
SHA3-384 hash: 8097f99908423a7bedbec39ef6f95adb9e5e4c7b80624a067661b0ea01ef291b040d7245cfba076d9158a843b75c4b4a
SHA1 hash: 78d4e965d9b5e5264157bd6f80cac5fb3f8efea0
MD5 hash: 8e9a75a9f8e1bc5d30f45d33eabae6bc
humanhash: bakerloo-kentucky-nebraska-west
File name:Sakura.sh
Download: download sample
Signature Mirai
File size:2'269 bytes
First seen:2026-03-02 18:31:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Qci1vd8jOMkO51rOzOtiO5OcOeXEI2rxkshIW/yUgIVLj4fcnWn3LbT1VhPPPV5D:Q5d8y0iittQ/4gTV2CULPhnbz
TLSH T1C341AF9B016407F79F839A34B77152C0E3DC0094A4E69E27B548CE129E7B8FC6DD9744
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://80.71.224.166/m-i.p-s.Sakuraddd5674c37f5e99822fec74d5a2e01797c033aa9e326b4e4ebb73922286b675d Miraielf mirai ua-wget
http://80.71.224.166/m-p.s-l.Sakura366958c7ec6a9f5525a7394dcb7ad5d049dee87b71723e3a984c76a23b4c631b Miraielf mirai ua-wget
http://80.71.224.166/s-h.4-.Sakura5b315a1fe133916b5a01612f22278cdbec98d579d97774f6a10518f9ccb54cbf Miraielf mirai ua-wget
http://80.71.224.166/x-8.6-.Sakurad824113be81330ca7157e736c37b1435b3b284e4e1c6417bc571caef98b5889a Miraielf mirai ua-wget
http://80.71.224.166/a-r.m-6.Sakura7aba71a2a0246c795162f83f4f059cb7fbfe5e6b78f321801848cba4c00a98d1 Miraielf mirai ua-wget
http://80.71.224.166/x-3.2-.Sakura505860c334f196ad99155b6a7fc383d6ad08af28beee6010e831e5354d6ff403 Miraielf mirai ua-wget
http://80.71.224.166/a-r.m-7.Sakurad79349a91bdd78758db0a82c82a3f6aeff82f3423acdcd96ae2803e842a18502 Miraielf mirai ua-wget
http://80.71.224.166/p-p.c-.Sakurabaafa477327da9b272dac56da68fa9bd3efeea45bf02751ab7ef940561a23582 Miraielf mirai ua-wget
http://80.71.224.166/i-5.8-6.Sakurae925b2b7922b98a1605c12c41f79cab73c138ada8cfd75cf60737065eae1f54e Miraielf mirai ua-wget
http://80.71.224.166/m-6.8-k.Sakura8969075ed74594cf2537fa1c28bb0d499422b01317830c70c0e5d5cd8c065bef Miraielf mirai ua-wget
http://80.71.224.166/a-r.m-4.Sakura16fcc12d6af8dfe811de7193f6f46f2e266d78db13d2f095f3b10d5aa1d73f8c Miraielf mirai ua-wget
http://80.71.224.166/a-r.m-5.Sakura9e0c49d81c9b5e13aee1b6d294651473e96b0c876ffc1552d10ce5cf017a509f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=58bc05f2-1900-0000-258c-c0ddd20a0000 pid=2770 /usr/bin/sudo guuid=8a3fddf3-1900-0000-258c-c0ddd60a0000 pid=2774 /tmp/sample.bin guuid=58bc05f2-1900-0000-258c-c0ddd20a0000 pid=2770->guuid=8a3fddf3-1900-0000-258c-c0ddd60a0000 pid=2774 execve guuid=a45762f4-1900-0000-258c-c0ddd70a0000 pid=2775 /usr/bin/wget guuid=8a3fddf3-1900-0000-258c-c0ddd60a0000 pid=2774->guuid=a45762f4-1900-0000-258c-c0ddd70a0000 pid=2775 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-03-02 18:26:59 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads system network configuration
Creates a large amount of network flows
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9a7caebf876aa6addee9de8a1acfb274bed980759e124dc48896891aad612093

(this sample)

  
Delivery method
Distributed via web download

Comments