🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f1cfd0a8a372bc87c384b08714414bebfccef308bfa50a87f8cc7ebd6825b22. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 9f1cfd0a8a372bc87c384b08714414bebfccef308bfa50a87f8cc7ebd6825b22
SHA3-384 hash: 783b2e2a47aa3c1daf094ad0da7fac72829d6702c442973ae071ced5ebf415b2068d52026c79314625b4b6d404a8b4d5
SHA1 hash: db4b726278b48127e592293976bdddd1cf5ab489
MD5 hash: 98000f99d9a9f11f5463d4a13a6a2183
humanhash: colorado-neptune-charlie-west
File name:lterouter
Download: download sample
File size:5'180 bytes
First seen:2026-09-08 04:41:34 UTC
Last seen:2026-09-08 05:54:12 UTC
File type: sh
MIME type:text/plain
ssdeep 96:awDQZXyJs1I2CZ8LmQhyUhVm38kIyZSDXojW1+wEZ+LMmhy+hVc38Cpbo3oXZaH/:awDQZXyJs1I2CZqmkyYVmMkIyZSDXojy
TLSH T171B1959D5BB7520086887E7074FF21C850E35E8527A40E2DF6DAAC71C88B9C1F17AB1A
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.119.71.134/n2/nw/aarch64n/an/amirai
http://160.119.71.134/n2/nw/armv4ln/an/amirai
http://160.119.71.134/n2/nw/armv5ln/an/amirai
http://160.119.71.134/n2/nw/armv6l3d87b3473361a35d6396945e1caea24db09119201ea868cfea1a06a1c95c828b Miraimirai
http://160.119.71.134/n2/nw/armv7l18b815b7fc95dc03cc978ed3bdfc52aa18c8613bbd92643310350acfed044ac1 Miraimirai
http://160.119.71.134/n2/nw/m68k928a8dfedb8ba0ea6c425e61c250e6f6fc4e120fbd2f468d0b3d8a8ed6d9e0c9 Miraimirai
http://160.119.71.134/n2/nw/mips64n/an/an/a
http://160.119.71.134/n2/nw/mips64l8ea5fe9dba1fc6f845f8ee1b5697733b04d96d638b79ed5f275d8d47bfbd591d Miraimirai
http://160.119.71.134/n2/nw/mips64b7a95e6de72616d5f010e6a450840791a4cb1451650073a55fd2685cafd7e6a08 Miraimirai
http://160.119.71.134/n2/nw/ppcn/an/amirai
http://160.119.71.134/n2/nw/sh4b34a84cef3a7389a0e24c2601c1ae54f7c126a76e8424afc45769241b606fdd2 Miraimirai
http://160.119.71.134/n2/nw/mips3e4edea73034a6c38930330413d745cddc0c4c0bf206cb259bc4a827fd13d6d3 Miraimirai
http://160.119.71.134/n2/nw/mpsl31a7ccef0d26c71a9239119993a5325bb6bd8da2339586b2f7b352457fdea85e Miraimirai
http://160.119.71.134/n2/nw/x86_64n/an/amirai
http://160.119.71.134/n2/nw/x86n/an/amirai
http://160.119.71.134/n2/nw/xtensan/an/an/a
http://160.119.71.134/n2/nw/sparcn/an/an/a

Intelligence


File Origin
# of uploads :
4
# of downloads :
2
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader evasive expand lolbin mirai
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-09-08 05:57:23 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
execution
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Executes a command shell one-liner
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 9f1cfd0a8a372bc87c384b08714414bebfccef308bfa50a87f8cc7ebd6825b22

(this sample)

  
Delivery method
Distributed via web download

Comments