MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a2dd8c859251c361c46d3670536e81d85acaa44ac938f3057bcecdf50b2ad5ee. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a2dd8c859251c361c46d3670536e81d85acaa44ac938f3057bcecdf50b2ad5ee
SHA3-384 hash: 0b93b512d27e736ebfd8502a64cc5e4168eaa628c22b5107e787199329497af16380f740b0a9d02f75807cdb4c0f47ed
SHA1 hash: 89f9503020ff989369627a45d786c56a11d6a40b
MD5 hash: ac6af3156b38400a15e7bcba1524bccd
humanhash: blossom-minnesota-lima-nebraska
File name:telnet.sh
Download: download sample
File size:1'834 bytes
First seen:2026-07-17 23:09:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:+kfc0dtnNaKl6KODOmLxf/TK1Sk1YgVbVVb1LBCN0UN0KvtuFe77bLBNCSwlLPTX:TfxHFmDzLxKUkb3A2U2Mtrbr0
TLSH T10E3101CD32B09251C649FF01F3E1CBD6AE45FDC866940E7AE4C11CB1486DE8D3865A36
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.83.87.122/iran.x86_64b1a6dba6636b519d76d7219f6264ac9f1456681c0855baef954fb435d3e25ce5 Miraielf mirai ua-wget
http://103.83.87.122/iran.aarch64bf38b3e5d645c78377599a6c218a347312c5a3daef693c7931f2710806d85317 Miraielf mirai ua-wget
http://103.83.87.122/iran.m68kf5cb6dadaee4399a1f014ef5946d0a4c1af578d15ff078e725e0757f28dc8493 Miraielf mirai ua-wget
http://103.83.87.122/iran.mipse987bb8b32facef51c3cc5a94bd51e01d8c3be8a19c106de70147ab5ce84dc66 Miraielf mirai ua-wget
http://103.83.87.122/iran.mipsel6e709fb9b09d9f8318724a8620812f55411a3ea49de6319c4832885547773ddd Miraielf mirai ua-wget
http://103.83.87.122/iran.powerpc0d64cd75599dea5b8cf393b6e2b709f51b3971e64b96920e0707020e22ee7953 Miraielf mirai ua-wget
http://103.83.87.122/iran.sparcf38d748d9ea29424c28744c52bcd1d14328d49fcb604ca08fab3547ec500d6f0 Miraielf mirai ua-wget
http://103.83.87.122/iran.sh4b4acd1ab65624b694946b1181bba0732bb63c88c51b8334914c26c1805b2e1aa Miraielf mirai ua-wget
http://103.83.87.122/iran.arc21c5f4a04173a5176d60b06095bf5d25e0022ffbe304601e368eccf718587dc8 Miraielf mirai ua-wget
http://103.83.87.122/iran.i486ec442a132f27486d1dfa3faa92c03e10012afe2b8de39fa9b42b367f7971c989 Miraielf mirai ua-wget
http://103.83.87.122/iran.armv4l9538c8a2edeaa8667134a469d03a7057ddc1e753ce1e5250f92f01c1097fcb1d Miraielf mirai ua-wget
http://103.83.87.122/iran.armv5ld8cd1d9f8c092aa4a6c1b1b2b97c7de71d55c2af8332532d2956e4f5becac17e Miraielf mirai ua-wget
http://103.83.87.122/iran.armv6l95f5bd70c4e40f9663b67d40d23a46ca21d97448f9a609be10b12837e6a59805 Miraielf mirai ua-wget
http://103.83.87.122/iran.armv7lb1f2808e05cb42894790c12172ffacf8673a0a7e14c7af5ad43d5bedfa62a5e4 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-07-17T21:07:00Z UTC
Last seen:
2026-07-18T19:44:00Z UTC
Hits:
~10
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-07-17 23:12:44 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
Modifies init.d
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a2dd8c859251c361c46d3670536e81d85acaa44ac938f3057bcecdf50b2ad5ee

(this sample)

  
Delivery method
Distributed via web download

Comments