MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a8d754d93a4316ee36de8020e49a46c6985f33f70db95a8899ccb3decc7ced3d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: a8d754d93a4316ee36de8020e49a46c6985f33f70db95a8899ccb3decc7ced3d
SHA3-384 hash: a52fd6f4aa8cba94fa0e3a08cfaa581015f7ea50bbcda6e038cbe99f58c81459f30715a62d545adf482af4e80a0fa50b
SHA1 hash: 84ebfe797ca901ba60b7f6bf084d35485ee0da91
MD5 hash: 44dd6a3d5b73b3c39e8f97e0c1c1388c
humanhash: kitten-queen-ink-hamper
File name:adb-soap.sh
Download: download sample
Signature Mirai
File size:1'111 bytes
First seen:2026-02-14 21:09:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:OB/iQNIByKRAwkAGw/hU3hSkhIAhE5Fc/Z+1lU:+vG5UxSiI2EwgU
TLSH T17B2184CE704D657D7A490E8270E0AA44A504FAE69D9F0E18BE4C0472FDC6E3037AEA5C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.151/file/data.arm47b86f1e1139d7f15e0163c1b1a96bceff557613454a1cead677b28f922370956 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.151/file/data.arm51f8080e52d6a3a5e3b51f0da10e612f67f961cb0bc0d0af01d83f91504bb1b0a Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.151/file/data.arm6598f8eee7ec2822c9ebfcdd75debc7b014b19a70954e9d8e8767594a7d2d585e Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.151/file/data.arm7e1e04cc4713e0d53d7596622b452ac1ed56eaebff81a59a984ae8e305138e78d Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.151/file/data.aarch6468ecdd1eb9ab0caff1227717b21508d64db456aeebd7552f6efc515ead7876c7 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.151/file/data.mips2df731ccffaac8a175a9c410f0351ba537771c6873345ccc14090c7c10bdfc32 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.151/file/data.mipsel7b4fb33ebd901223b53cdcc7ccd6e2b83e26a10fa5c40626a3497ad841482dd5 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.151/file/data.mips-uclibc41b45799bc85d2c743a2ace4fd9407b52eeafb0d9a9b765d9c18d2cd41f38435 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.151/file/data.mipsel-uclibcf6c7fecae7241b42ed82bc0109013da46fce46cae827954f8fd07ce0a9ba6759 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.151/file/data.powerpc8f17f85085f91981089860713c6ae572db5bacc4f5338b1c58d06ae1b7bff5e2 Gafgytelf gafgyt geofenced mirai PowerPC ua-wget USA
http://130.12.180.151/file/data.x86cdb0690dace0c8f548441901f74051dc23f1e22d0720743b66581426072c5ae0 Miraielf geofenced mirai ua-wget USA x86
http://130.12.180.151/file/data.x86_646c6db7fabf43b3b7d926414342072db1cfeb9596c62c9448a1ad38c3ab991ca4 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f5405fff-1800-0000-98fc-25209c090000 pid=2460 /usr/bin/sudo guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470 /tmp/sample.bin guuid=f5405fff-1800-0000-98fc-25209c090000 pid=2460->guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470 execve guuid=2aa87802-1900-0000-98fc-2520a9090000 pid=2473 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=2aa87802-1900-0000-98fc-2520a9090000 pid=2473 execve guuid=36d65b0d-1900-0000-98fc-2520c2090000 pid=2498 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=36d65b0d-1900-0000-98fc-2520c2090000 pid=2498 execve guuid=d1b89f0d-1900-0000-98fc-2520c4090000 pid=2500 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=d1b89f0d-1900-0000-98fc-2520c4090000 pid=2500 clone guuid=6417150f-1900-0000-98fc-2520ca090000 pid=2506 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=6417150f-1900-0000-98fc-2520ca090000 pid=2506 execve guuid=b3a5121a-1900-0000-98fc-2520e2090000 pid=2530 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=b3a5121a-1900-0000-98fc-2520e2090000 pid=2530 execve guuid=9ef54a1a-1900-0000-98fc-2520e4090000 pid=2532 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=9ef54a1a-1900-0000-98fc-2520e4090000 pid=2532 clone guuid=6b2fd81a-1900-0000-98fc-2520e7090000 pid=2535 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=6b2fd81a-1900-0000-98fc-2520e7090000 pid=2535 execve guuid=db52ad25-1900-0000-98fc-2520fd090000 pid=2557 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=db52ad25-1900-0000-98fc-2520fd090000 pid=2557 execve guuid=e35d1c26-1900-0000-98fc-2520ff090000 pid=2559 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=e35d1c26-1900-0000-98fc-2520ff090000 pid=2559 clone guuid=fa2b8427-1900-0000-98fc-2520020a0000 pid=2562 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=fa2b8427-1900-0000-98fc-2520020a0000 pid=2562 execve guuid=2442c533-1900-0000-98fc-2520170a0000 pid=2583 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=2442c533-1900-0000-98fc-2520170a0000 pid=2583 execve guuid=82244034-1900-0000-98fc-2520190a0000 pid=2585 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=82244034-1900-0000-98fc-2520190a0000 pid=2585 clone guuid=181e9f35-1900-0000-98fc-25201d0a0000 pid=2589 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=181e9f35-1900-0000-98fc-25201d0a0000 pid=2589 execve guuid=639e2542-1900-0000-98fc-2520340a0000 pid=2612 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=639e2542-1900-0000-98fc-2520340a0000 pid=2612 execve guuid=7ac29142-1900-0000-98fc-2520360a0000 pid=2614 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=7ac29142-1900-0000-98fc-2520360a0000 pid=2614 clone guuid=9979b044-1900-0000-98fc-25203b0a0000 pid=2619 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=9979b044-1900-0000-98fc-25203b0a0000 pid=2619 execve guuid=337fec4e-1900-0000-98fc-2520520a0000 pid=2642 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=337fec4e-1900-0000-98fc-2520520a0000 pid=2642 execve guuid=d6e1504f-1900-0000-98fc-2520540a0000 pid=2644 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=d6e1504f-1900-0000-98fc-2520540a0000 pid=2644 clone guuid=585a6551-1900-0000-98fc-2520590a0000 pid=2649 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=585a6551-1900-0000-98fc-2520590a0000 pid=2649 execve guuid=5df0745b-1900-0000-98fc-2520710a0000 pid=2673 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=5df0745b-1900-0000-98fc-2520710a0000 pid=2673 execve guuid=e482d95b-1900-0000-98fc-2520730a0000 pid=2675 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=e482d95b-1900-0000-98fc-2520730a0000 pid=2675 clone guuid=a35ed75c-1900-0000-98fc-2520770a0000 pid=2679 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=a35ed75c-1900-0000-98fc-2520770a0000 pid=2679 execve guuid=30ea1367-1900-0000-98fc-2520900a0000 pid=2704 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=30ea1367-1900-0000-98fc-2520900a0000 pid=2704 execve guuid=1e015d67-1900-0000-98fc-2520920a0000 pid=2706 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=1e015d67-1900-0000-98fc-2520920a0000 pid=2706 clone guuid=6060f567-1900-0000-98fc-2520950a0000 pid=2709 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=6060f567-1900-0000-98fc-2520950a0000 pid=2709 execve guuid=b9540872-1900-0000-98fc-2520af0a0000 pid=2735 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=b9540872-1900-0000-98fc-2520af0a0000 pid=2735 execve guuid=ccb94772-1900-0000-98fc-2520b00a0000 pid=2736 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=ccb94772-1900-0000-98fc-2520b00a0000 pid=2736 clone guuid=a531ea73-1900-0000-98fc-2520b60a0000 pid=2742 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=a531ea73-1900-0000-98fc-2520b60a0000 pid=2742 execve guuid=cdd3ee7d-1900-0000-98fc-2520d20a0000 pid=2770 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=cdd3ee7d-1900-0000-98fc-2520d20a0000 pid=2770 execve guuid=e0f0387e-1900-0000-98fc-2520d40a0000 pid=2772 /usr/bin/dash guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=e0f0387e-1900-0000-98fc-2520d40a0000 pid=2772 clone guuid=e4c0d37f-1900-0000-98fc-2520d80a0000 pid=2776 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=e4c0d37f-1900-0000-98fc-2520d80a0000 pid=2776 execve guuid=1cebc48c-1900-0000-98fc-2520ed0a0000 pid=2797 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=1cebc48c-1900-0000-98fc-2520ed0a0000 pid=2797 execve guuid=bba9168d-1900-0000-98fc-2520ee0a0000 pid=2798 /home/sandbox/data.x86 net guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=bba9168d-1900-0000-98fc-2520ee0a0000 pid=2798 execve guuid=08e94e8d-1900-0000-98fc-2520f00a0000 pid=2800 /usr/bin/busybox net send-data write-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=08e94e8d-1900-0000-98fc-2520f00a0000 pid=2800 execve guuid=23866c9a-1900-0000-98fc-25200b0b0000 pid=2827 /usr/bin/chmod guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=23866c9a-1900-0000-98fc-25200b0b0000 pid=2827 execve guuid=1156c99a-1900-0000-98fc-25200e0b0000 pid=2830 /home/sandbox/data.x86_64 net guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=1156c99a-1900-0000-98fc-25200e0b0000 pid=2830 execve guuid=3c821b9b-1900-0000-98fc-2520110b0000 pid=2833 /usr/bin/rm delete-file guuid=ef5d2a02-1900-0000-98fc-2520a6090000 pid=2470->guuid=3c821b9b-1900-0000-98fc-2520110b0000 pid=2833 execve 9310fc78-cd7b-5834-a26b-9a68a9b5ed2f 130.12.180.151:80 guuid=2aa87802-1900-0000-98fc-2520a9090000 pid=2473->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 91B guuid=6417150f-1900-0000-98fc-2520ca090000 pid=2506->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 91B guuid=6b2fd81a-1900-0000-98fc-2520e7090000 pid=2535->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 91B guuid=fa2b8427-1900-0000-98fc-2520020a0000 pid=2562->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 91B guuid=181e9f35-1900-0000-98fc-25201d0a0000 pid=2589->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 94B guuid=9979b044-1900-0000-98fc-25203b0a0000 pid=2619->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 91B guuid=585a6551-1900-0000-98fc-2520590a0000 pid=2649->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 93B guuid=a35ed75c-1900-0000-98fc-2520770a0000 pid=2679->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 98B guuid=6060f567-1900-0000-98fc-2520950a0000 pid=2709->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 100B guuid=a531ea73-1900-0000-98fc-2520b60a0000 pid=2742->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 94B guuid=e4c0d37f-1900-0000-98fc-2520d80a0000 pid=2776->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=bba9168d-1900-0000-98fc-2520ee0a0000 pid=2798->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1ddc438d-1900-0000-98fc-2520ef0a0000 pid=2799 /home/sandbox/data.x86 guuid=bba9168d-1900-0000-98fc-2520ee0a0000 pid=2798->guuid=1ddc438d-1900-0000-98fc-2520ef0a0000 pid=2799 clone guuid=fc4e528d-1900-0000-98fc-2520f10a0000 pid=2801 /home/sandbox/data.x86 guuid=1ddc438d-1900-0000-98fc-2520ef0a0000 pid=2799->guuid=fc4e528d-1900-0000-98fc-2520f10a0000 pid=2801 clone guuid=08e94e8d-1900-0000-98fc-2520f00a0000 pid=2800->9310fc78-cd7b-5834-a26b-9a68a9b5ed2f send: 93B guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802 /home/sandbox/data.x86 send-data guuid=fc4e528d-1900-0000-98fc-2520f10a0000 pid=2801->guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802 clone guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=5aada38d-1900-0000-98fc-2520f30a0000 pid=2803 /home/sandbox/data.x86 guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802->guuid=5aada38d-1900-0000-98fc-2520f30a0000 pid=2803 clone guuid=d5573c8e-1900-0000-98fc-2520f70a0000 pid=2807 /usr/bin/dash guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802->guuid=d5573c8e-1900-0000-98fc-2520f70a0000 pid=2807 execve guuid=202ad29d-1900-0000-98fc-25201b0b0000 pid=2843 /usr/bin/dash zombie guuid=01e59b8d-1900-0000-98fc-2520f20a0000 pid=2802->guuid=202ad29d-1900-0000-98fc-25201b0b0000 pid=2843 execve guuid=d3addd8e-1900-0000-98fc-2520f90a0000 pid=2809 /usr/sbin/xtables-nft-multi guuid=d5573c8e-1900-0000-98fc-2520f70a0000 pid=2807->guuid=d3addd8e-1900-0000-98fc-2520f90a0000 pid=2809 execve guuid=1156c99a-1900-0000-98fc-25200e0b0000 pid=2830->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2b62fb9a-1900-0000-98fc-25200f0b0000 pid=2831 /home/sandbox/data.x86_64 zombie guuid=1156c99a-1900-0000-98fc-25200e0b0000 pid=2830->guuid=2b62fb9a-1900-0000-98fc-25200f0b0000 pid=2831 clone guuid=3a4d049b-1900-0000-98fc-2520100b0000 pid=2832 /home/sandbox/data.x86_64 zombie guuid=2b62fb9a-1900-0000-98fc-25200f0b0000 pid=2831->guuid=3a4d049b-1900-0000-98fc-2520100b0000 pid=2832 clone guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834 /home/sandbox/data.x86_64 net send-data zombie guuid=3a4d049b-1900-0000-98fc-2520100b0000 pid=2832->guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834 clone guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B f2c16dc2-d4dc-5494-a798-2106ccbc4c65 130.12.180.151:25565 guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834->f2c16dc2-d4dc-5494-a798-2106ccbc4c65 send: 14B guuid=4a78429b-1900-0000-98fc-2520130b0000 pid=2835 /home/sandbox/data.x86_64 guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834->guuid=4a78429b-1900-0000-98fc-2520130b0000 pid=2835 clone guuid=ffc6049d-1900-0000-98fc-2520170b0000 pid=2839 /usr/bin/dash guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834->guuid=ffc6049d-1900-0000-98fc-2520170b0000 pid=2839 execve guuid=f345d79d-1900-0000-98fc-25201c0b0000 pid=2844 /usr/bin/dash guuid=44b5369b-1900-0000-98fc-2520120b0000 pid=2834->guuid=f345d79d-1900-0000-98fc-25201c0b0000 pid=2844 execve guuid=c8444b9d-1900-0000-98fc-2520190b0000 pid=2841 /usr/sbin/xtables-nft-multi guuid=ffc6049d-1900-0000-98fc-2520170b0000 pid=2839->guuid=c8444b9d-1900-0000-98fc-2520190b0000 pid=2841 execve guuid=4869fd9d-1900-0000-98fc-25201e0b0000 pid=2846 /usr/sbin/xtables-nft-multi guuid=202ad29d-1900-0000-98fc-25201b0b0000 pid=2843->guuid=4869fd9d-1900-0000-98fc-25201e0b0000 pid=2846 execve guuid=e257759e-1900-0000-98fc-2520200b0000 pid=2848 /usr/sbin/xtables-nft-multi guuid=f345d79d-1900-0000-98fc-25201c0b0000 pid=2844->guuid=e257759e-1900-0000-98fc-2520200b0000 pid=2848 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-02-14 21:22:21 UTC
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a8d754d93a4316ee36de8020e49a46c6985f33f70db95a8899ccb3decc7ced3d

(this sample)

  
Delivery method
Distributed via web download

Comments