MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9f45aa714e603901aa6c7627fab86a1def241ecb30dea3575fbbb8c8269bc4b9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 9f45aa714e603901aa6c7627fab86a1def241ecb30dea3575fbbb8c8269bc4b9
SHA3-384 hash: 2999f5b6d77f2d065cf52d87e1e8952969f84407d5382ccbcdb1331bc87c9237729b4fdd260a6a78fb55acfd3267a2bf
SHA1 hash: 2290d549f7b7cbee7433ea0353170cc6cb583537
MD5 hash: a4a3eae4b1b1b77307bf8652df69a639
humanhash: blossom-ohio-alpha-glucose
File name:w.sh
Download: download sample
Signature Mirai
File size:1'121 bytes
First seen:2025-12-25 19:18:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:oF1iHWW5hbSWWflwWW29NIl56WWQCa0LKbWW1NgOyWWjJiRWWZO7fWWWSvSWW9Nc:ygMl1NI74KCdiWQA2Nt6dO0PNf7
TLSH T10F21D1CF21910FB148488E0CB973841855C6A9D4FC422EEC168E19764D97B78B62AFA9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.90/bins/arme0844b0cdf611d8a7521ff37ca40ab691a2c2c3e28a4b9571ff9456d5b5a2b77 Miraielf ua-wget
http://94.156.152.90/bins/arm5f6fbf730c614f55b266174036c98d1827bc602c3c830ccff25454272c694b91f Miraielf ua-wget
http://94.156.152.90/bins/arm646588e27520d4ff181d33bc7ff021903d1ecd13f376657f5db7af180ca2e3ac6 Miraielf mirai ua-wget
http://94.156.152.90/bins/arm7c05ee431ce3abe70afdbf9710b0ab3864ecdd8de9f8697c077f956a39bdf8217 Miraielf ua-wget
http://94.156.152.90/bins/m68k0fc0c0aa10d7f989ee6709c50908144d95b2c62ad512419f690652c906db8ed5 Miraielf mirai ua-wget
http://94.156.152.90/bins/mips0f8f041acce3852c7ee78caffddcb4e941206b3c5b905bb5e6c061285ce08852 Miraielf ua-wget
http://94.156.152.90/bins/mpsld80d236e16bfef3dd5b8aacb4aff4226616be790c3b5dc2325af73e71d61441c Miraielf mirai ua-wget
http://94.156.152.90/bins/ppc14d5f0267f0ca1c67bdd8e3075ee3598e2ae7444c7f87bab0b862b3b5ee6ced7 Miraielf ua-wget
http://94.156.152.90/bins/sh4439b5691344326a2b67d18c5414f27c50d2b5be2bba021a6c74fbd718fd956ce Miraielf ua-wget
http://94.156.152.90/bins/spc2951437574f0b44b68855462c650bc1d7b10fbaf36ed86e7a45faec38b87ee6e Miraielf ua-wget
http://94.156.152.90/bins/x8603ecda01330d867752a09c2e6118fed74a061d4f5222d492ab43640e0d36e6c4 Miraielf mirai ua-wget
http://94.156.152.90/bins/x86_64c0fe3a9a893f48296e27f62bb47a35480d0255c5df46d2185963ce8552004535 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-25T16:34:00Z UTC
Last seen:
2025-12-26T17:41:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=1b773816-1800-0000-d5bf-15fce7070000 pid=2023 /usr/bin/sudo guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030 /tmp/sample.bin guuid=1b773816-1800-0000-d5bf-15fce7070000 pid=2023->guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030 execve guuid=7dda6318-1800-0000-d5bf-15fcf1070000 pid=2033 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=7dda6318-1800-0000-d5bf-15fcf1070000 pid=2033 execve guuid=5fddf824-1800-0000-d5bf-15fc0a080000 pid=2058 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=5fddf824-1800-0000-d5bf-15fc0a080000 pid=2058 execve guuid=5e995e25-1800-0000-d5bf-15fc0c080000 pid=2060 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=5e995e25-1800-0000-d5bf-15fc0c080000 pid=2060 clone guuid=93780826-1800-0000-d5bf-15fc11080000 pid=2065 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=93780826-1800-0000-d5bf-15fc11080000 pid=2065 execve guuid=64d68532-1800-0000-d5bf-15fc2a080000 pid=2090 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=64d68532-1800-0000-d5bf-15fc2a080000 pid=2090 execve guuid=1eb6ed32-1800-0000-d5bf-15fc2b080000 pid=2091 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=1eb6ed32-1800-0000-d5bf-15fc2b080000 pid=2091 clone guuid=2efbd634-1800-0000-d5bf-15fc2f080000 pid=2095 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=2efbd634-1800-0000-d5bf-15fc2f080000 pid=2095 execve guuid=6cf9c644-1800-0000-d5bf-15fc52080000 pid=2130 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=6cf9c644-1800-0000-d5bf-15fc52080000 pid=2130 execve guuid=11700545-1800-0000-d5bf-15fc54080000 pid=2132 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=11700545-1800-0000-d5bf-15fc54080000 pid=2132 clone guuid=8d185646-1800-0000-d5bf-15fc59080000 pid=2137 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=8d185646-1800-0000-d5bf-15fc59080000 pid=2137 execve guuid=16619056-1800-0000-d5bf-15fc8a080000 pid=2186 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=16619056-1800-0000-d5bf-15fc8a080000 pid=2186 execve guuid=ea3fdc56-1800-0000-d5bf-15fc8c080000 pid=2188 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=ea3fdc56-1800-0000-d5bf-15fc8c080000 pid=2188 clone guuid=7176f757-1800-0000-d5bf-15fc91080000 pid=2193 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=7176f757-1800-0000-d5bf-15fc91080000 pid=2193 execve guuid=b440dc66-1800-0000-d5bf-15fcba080000 pid=2234 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=b440dc66-1800-0000-d5bf-15fcba080000 pid=2234 execve guuid=d0134467-1800-0000-d5bf-15fcbc080000 pid=2236 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=d0134467-1800-0000-d5bf-15fcbc080000 pid=2236 clone guuid=a68ecb68-1800-0000-d5bf-15fcc2080000 pid=2242 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=a68ecb68-1800-0000-d5bf-15fcc2080000 pid=2242 execve guuid=18c8f97d-1800-0000-d5bf-15fce0080000 pid=2272 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=18c8f97d-1800-0000-d5bf-15fce0080000 pid=2272 execve guuid=6f9f597e-1800-0000-d5bf-15fce1080000 pid=2273 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=6f9f597e-1800-0000-d5bf-15fce1080000 pid=2273 clone guuid=67e3ff7f-1800-0000-d5bf-15fce8080000 pid=2280 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=67e3ff7f-1800-0000-d5bf-15fce8080000 pid=2280 execve guuid=57cd008f-1800-0000-d5bf-15fcff080000 pid=2303 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=57cd008f-1800-0000-d5bf-15fcff080000 pid=2303 execve guuid=93ce708f-1800-0000-d5bf-15fc00090000 pid=2304 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=93ce708f-1800-0000-d5bf-15fc00090000 pid=2304 clone guuid=5d915090-1800-0000-d5bf-15fc02090000 pid=2306 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=5d915090-1800-0000-d5bf-15fc02090000 pid=2306 execve guuid=5d9c2ea0-1800-0000-d5bf-15fc04090000 pid=2308 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=5d9c2ea0-1800-0000-d5bf-15fc04090000 pid=2308 execve guuid=1a579ca0-1800-0000-d5bf-15fc05090000 pid=2309 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=1a579ca0-1800-0000-d5bf-15fc05090000 pid=2309 clone guuid=5596bea2-1800-0000-d5bf-15fc0d090000 pid=2317 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=5596bea2-1800-0000-d5bf-15fc0d090000 pid=2317 execve guuid=2f8b2aaf-1800-0000-d5bf-15fc26090000 pid=2342 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=2f8b2aaf-1800-0000-d5bf-15fc26090000 pid=2342 execve guuid=926f7eaf-1800-0000-d5bf-15fc28090000 pid=2344 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=926f7eaf-1800-0000-d5bf-15fc28090000 pid=2344 clone guuid=05a2b1b0-1800-0000-d5bf-15fc2c090000 pid=2348 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=05a2b1b0-1800-0000-d5bf-15fc2c090000 pid=2348 execve guuid=b1f837be-1800-0000-d5bf-15fc49090000 pid=2377 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=b1f837be-1800-0000-d5bf-15fc49090000 pid=2377 execve guuid=efee7dbe-1800-0000-d5bf-15fc4b090000 pid=2379 /usr/bin/bash guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=efee7dbe-1800-0000-d5bf-15fc4b090000 pid=2379 clone guuid=976a1bbf-1800-0000-d5bf-15fc4f090000 pid=2383 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=976a1bbf-1800-0000-d5bf-15fc4f090000 pid=2383 execve guuid=3bc2cecb-1800-0000-d5bf-15fc6a090000 pid=2410 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=3bc2cecb-1800-0000-d5bf-15fc6a090000 pid=2410 execve guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412 /tmp/x86 net guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412 execve guuid=9613bf43-1900-0000-d5bf-15fc770a0000 pid=2679 /usr/bin/busybox net send-data write-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=9613bf43-1900-0000-d5bf-15fc770a0000 pid=2679 execve guuid=b9f9f153-1900-0000-d5bf-15fca20a0000 pid=2722 /usr/bin/chmod guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=b9f9f153-1900-0000-d5bf-15fca20a0000 pid=2722 execve guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724 /tmp/x86_64 net guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724 execve guuid=4e60fecb-1900-0000-d5bf-15fc9b0b0000 pid=2971 /usr/bin/rm delete-file guuid=97a2e117-1800-0000-d5bf-15fcee070000 pid=2030->guuid=4e60fecb-1900-0000-d5bf-15fc9b0b0000 pid=2971 execve e217ae65-493d-53f3-ad87-163d1acdbb8a 94.156.152.90:80 guuid=7dda6318-1800-0000-d5bf-15fcf1070000 pid=2033->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 84B guuid=93780826-1800-0000-d5bf-15fc11080000 pid=2065->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=2efbd634-1800-0000-d5bf-15fc2f080000 pid=2095->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=8d185646-1800-0000-d5bf-15fc59080000 pid=2137->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=7176f757-1800-0000-d5bf-15fc91080000 pid=2193->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=a68ecb68-1800-0000-d5bf-15fcc2080000 pid=2242->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=67e3ff7f-1800-0000-d5bf-15fce8080000 pid=2280->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 85B guuid=5d915090-1800-0000-d5bf-15fc02090000 pid=2306->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 84B guuid=5596bea2-1800-0000-d5bf-15fc0d090000 pid=2317->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 84B guuid=05a2b1b0-1800-0000-d5bf-15fc2c090000 pid=2348->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 84B guuid=976a1bbf-1800-0000-d5bf-15fc4f090000 pid=2383->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 84B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=17db3acc-1800-0000-d5bf-15fc6e090000 pid=2414 /tmp/x86 guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412->guuid=17db3acc-1800-0000-d5bf-15fc6e090000 pid=2414 clone guuid=b5bce607-1900-0000-d5bf-15fcef090000 pid=2543 /tmp/x86 guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412->guuid=b5bce607-1900-0000-d5bf-15fcef090000 pid=2543 clone guuid=e3229c43-1900-0000-d5bf-15fc740a0000 pid=2676 /tmp/x86 guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412->guuid=e3229c43-1900-0000-d5bf-15fc740a0000 pid=2676 clone guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677 /tmp/x86 dns net send-data zombie guuid=9b750fcc-1800-0000-d5bf-15fc6c090000 pid=2412->guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677 clone guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1900B 6272d858-80a1-5f9b-be28-4d6aceb31fbd niggabot.windy.my.id:23 guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=c65fb443-1900-0000-d5bf-15fc760a0000 pid=2678 /tmp/x86 guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677->guuid=c65fb443-1900-0000-d5bf-15fc760a0000 pid=2678 clone guuid=dcdf617f-1900-0000-d5bf-15fc010b0000 pid=2817 /tmp/x86 guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677->guuid=dcdf617f-1900-0000-d5bf-15fc010b0000 pid=2817 clone guuid=b8c31abb-1900-0000-d5bf-15fc6b0b0000 pid=2923 /tmp/x86 guuid=49cfa743-1900-0000-d5bf-15fc750a0000 pid=2677->guuid=b8c31abb-1900-0000-d5bf-15fc6b0b0000 pid=2923 clone guuid=9613bf43-1900-0000-d5bf-15fc770a0000 pid=2679->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 87B guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70669654-1900-0000-d5bf-15fca60a0000 pid=2726 /tmp/x86_64 guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724->guuid=70669654-1900-0000-d5bf-15fca60a0000 pid=2726 clone guuid=0fe03a90-1900-0000-d5bf-15fc240b0000 pid=2852 /tmp/x86_64 guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724->guuid=0fe03a90-1900-0000-d5bf-15fc240b0000 pid=2852 clone guuid=e51be3cb-1900-0000-d5bf-15fc980b0000 pid=2968 /tmp/x86_64 guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724->guuid=e51be3cb-1900-0000-d5bf-15fc980b0000 pid=2968 clone guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969 /tmp/x86_64 dns net send-data zombie guuid=a9cc6054-1900-0000-d5bf-15fca40a0000 pid=2724->guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969 clone guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1710B guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=9ae0f1cb-1900-0000-d5bf-15fc9a0b0000 pid=2970 /tmp/x86_64 guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969->guuid=9ae0f1cb-1900-0000-d5bf-15fc9a0b0000 pid=2970 clone guuid=a4b09e07-1a00-0000-d5bf-15fc2c0c0000 pid=3116 /tmp/x86_64 guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969->guuid=a4b09e07-1a00-0000-d5bf-15fc2c0c0000 pid=3116 clone guuid=dc1b4d43-1a00-0000-d5bf-15fcaa0c0000 pid=3242 /tmp/x86_64 guuid=682fe6cb-1900-0000-d5bf-15fc990b0000 pid=2969->guuid=dc1b4d43-1a00-0000-d5bf-15fcaa0c0000 pid=3242 clone
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-25 19:19:34 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9f45aa714e603901aa6c7627fab86a1def241ecb30dea3575fbbb8c8269bc4b9

(this sample)

  
Delivery method
Distributed via web download

Comments