MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab60ddea7281cd4fc39d94668a431f7e23159a4430f504c83be30ba27c511ff7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ab60ddea7281cd4fc39d94668a431f7e23159a4430f504c83be30ba27c511ff7
SHA3-384 hash: c75c9f797d097f56fff26f88074c0ea1b9436da8af0810ac25f9a0ed0a1c16002412cda2d09c95cdb2c52fe35db65962
SHA1 hash: bac66884058f4f82d3eb0496022fc30f1b0cbd10
MD5 hash: 2c135e3d6ec2cbf9535b071f09b2576c
humanhash: mississippi-alpha-triple-purple
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'831 bytes
First seen:2026-04-30 06:03:56 UTC
Last seen:2026-05-01 00:45:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:3xdTPtTa8CTnQ14Ta2CTmnBT7rZTXtTu3ZTTyo7PTsvyCT5SCT22CT7b:n1+RIvgC
TLSH T11931158B60749065C584DE15B1F4EBC4D325B69963F4063AFCD10D6AB08AD54306FEFD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://31.59.104.25/iran.x86_64c2a18aa6bc7c130cba97b02b96f47b3b3e71f08e4b4b48fe678ab70ac2aa21d8 Miraielf mirai ua-wget
http://31.59.104.25/iran.aarch64n/an/aelf ua-wget
http://31.59.104.25/iran.m68k8fb4a0f1aa646ac1f2af66eb5b888e38f1ad63a809087b60a93f78db4087801c Miraielf mirai ua-wget
http://31.59.104.25/iran.mipse47146ccd375c8b273930571807f437c80cb682bb41e76b9773396b4ca0f7235 Miraielf mips mirai ua-wget
http://31.59.104.25/iran.mipsel913ce9b38b2132729be84626fe4606f5b5364058e706d5af2d8ba529fd4da6f1 Miraielf mips mirai ua-wget
http://31.59.104.25/iran.powerpc0735d9d662be4a6e5033a4e926f6a1a4d7221114aeb6aa5fcdbf3d21346efc4d Miraielf mirai ua-wget
http://31.59.104.25/iran.sparcdb2272ccd055b6524c8360d0c8fa126670a8e1c2f783091436e2adf002a026c3 Miraielf mirai ua-wget
http://31.59.104.25/iran.sh49dd2cd073a0dc4eba7f048a541dd85fd859e2b22cff43053f9dcea6dc1a70ee5 Miraielf mirai ua-wget
http://31.59.104.25/iran.arcn/an/aelf ua-wget
http://31.59.104.25/iran.i486d13be1b0704a68fa2a9ab3a5e6dd9d618d003949e1844548e747b4f1fe6af861 Miraielf mirai ua-wget
http://31.59.104.25/iran.armv4l10433914187823e5c4ee9f83f9c270ce6a0fcc66fcf4f13e6f64e6142754a5c6 Miraielf mirai ua-wget
http://31.59.104.25/iran.armv5l53ce494336ade6fb34f1fef2a7099cf981a6b52351353c9b9f41f15d2c5c10ac Miraielf mirai ua-wget
http://31.59.104.25/iran.armv6l043a247df856e148233519e579641420046dfd9696305b62369090274166dede Miraielf mirai ua-wget
http://31.59.104.25/iran.armv7ld3ffce49fd6a0bd2e63253b722dd48420116c5ce73a8894b4afe73afd3732db1 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
54
Origin country :
SK SK
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-30T03:07:00Z UTC
Last seen:
2026-04-30T12:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4701fef3-1600-0000-d6b6-2313c60c0000 pid=3270 /usr/bin/sudo guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277 /tmp/sample.bin guuid=4701fef3-1600-0000-d6b6-2313c60c0000 pid=3270->guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277 execve guuid=3ddbf0f5-1600-0000-d6b6-2313cf0c0000 pid=3279 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3ddbf0f5-1600-0000-d6b6-2313cf0c0000 pid=3279 execve guuid=dc503603-1700-0000-d6b6-2313ea0c0000 pid=3306 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=dc503603-1700-0000-d6b6-2313ea0c0000 pid=3306 execve guuid=48fd8303-1700-0000-d6b6-2313ec0c0000 pid=3308 /home/sandbox/iran.x86_64 guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=48fd8303-1700-0000-d6b6-2313ec0c0000 pid=3308 execve guuid=82d31104-1700-0000-d6b6-2313ef0c0000 pid=3311 /usr/bin/wget net send-data guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=82d31104-1700-0000-d6b6-2313ef0c0000 pid=3311 execve guuid=fd637809-1700-0000-d6b6-2313fe0c0000 pid=3326 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=fd637809-1700-0000-d6b6-2313fe0c0000 pid=3326 execve guuid=abd95e12-1700-0000-d6b6-2313110d0000 pid=3345 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=abd95e12-1700-0000-d6b6-2313110d0000 pid=3345 execve guuid=3839ab12-1700-0000-d6b6-2313130d0000 pid=3347 /home/sandbox/iran.aarch64 guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3839ab12-1700-0000-d6b6-2313130d0000 pid=3347 execve guuid=071fe012-1700-0000-d6b6-2313150d0000 pid=3349 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=071fe012-1700-0000-d6b6-2313150d0000 pid=3349 execve guuid=bbdefb22-1700-0000-d6b6-2313380d0000 pid=3384 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=bbdefb22-1700-0000-d6b6-2313380d0000 pid=3384 execve guuid=f5033023-1700-0000-d6b6-23133a0d0000 pid=3386 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=f5033023-1700-0000-d6b6-23133a0d0000 pid=3386 clone guuid=438ea823-1700-0000-d6b6-23133e0d0000 pid=3390 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=438ea823-1700-0000-d6b6-23133e0d0000 pid=3390 execve guuid=dbfd4230-1700-0000-d6b6-2313610d0000 pid=3425 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=dbfd4230-1700-0000-d6b6-2313610d0000 pid=3425 execve guuid=91cf8230-1700-0000-d6b6-2313630d0000 pid=3427 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=91cf8230-1700-0000-d6b6-2313630d0000 pid=3427 clone guuid=e5620531-1700-0000-d6b6-2313670d0000 pid=3431 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=e5620531-1700-0000-d6b6-2313670d0000 pid=3431 execve guuid=b8a72a3e-1700-0000-d6b6-23138b0d0000 pid=3467 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=b8a72a3e-1700-0000-d6b6-23138b0d0000 pid=3467 execve guuid=a48f633e-1700-0000-d6b6-23138d0d0000 pid=3469 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=a48f633e-1700-0000-d6b6-23138d0d0000 pid=3469 clone guuid=9b2edd3e-1700-0000-d6b6-2313910d0000 pid=3473 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=9b2edd3e-1700-0000-d6b6-2313910d0000 pid=3473 execve guuid=50dd4949-1700-0000-d6b6-2313af0d0000 pid=3503 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=50dd4949-1700-0000-d6b6-2313af0d0000 pid=3503 execve guuid=f6709759-1700-0000-d6b6-2313c40d0000 pid=3524 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=f6709759-1700-0000-d6b6-2313c40d0000 pid=3524 execve guuid=3aa5db59-1700-0000-d6b6-2313c50d0000 pid=3525 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3aa5db59-1700-0000-d6b6-2313c50d0000 pid=3525 clone guuid=2c2b675a-1700-0000-d6b6-2313c70d0000 pid=3527 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=2c2b675a-1700-0000-d6b6-2313c70d0000 pid=3527 execve guuid=eea87262-1700-0000-d6b6-2313da0d0000 pid=3546 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=eea87262-1700-0000-d6b6-2313da0d0000 pid=3546 execve guuid=563eac62-1700-0000-d6b6-2313dc0d0000 pid=3548 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=563eac62-1700-0000-d6b6-2313dc0d0000 pid=3548 clone guuid=afcf2863-1700-0000-d6b6-2313e00d0000 pid=3552 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=afcf2863-1700-0000-d6b6-2313e00d0000 pid=3552 execve guuid=e09eba87-1700-0000-d6b6-2313530e0000 pid=3667 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=e09eba87-1700-0000-d6b6-2313530e0000 pid=3667 execve guuid=a7ebdca0-1700-0000-d6b6-23138f0e0000 pid=3727 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=a7ebdca0-1700-0000-d6b6-23138f0e0000 pid=3727 execve guuid=d48424a1-1700-0000-d6b6-2313910e0000 pid=3729 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=d48424a1-1700-0000-d6b6-2313910e0000 pid=3729 clone guuid=2849c5a1-1700-0000-d6b6-2313970e0000 pid=3735 /usr/bin/wget net send-data guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=2849c5a1-1700-0000-d6b6-2313970e0000 pid=3735 execve guuid=766a9da6-1700-0000-d6b6-2313ae0e0000 pid=3758 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=766a9da6-1700-0000-d6b6-2313ae0e0000 pid=3758 execve guuid=e17ef0ac-1700-0000-d6b6-2313c50e0000 pid=3781 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=e17ef0ac-1700-0000-d6b6-2313c50e0000 pid=3781 execve guuid=269230ad-1700-0000-d6b6-2313c70e0000 pid=3783 /home/sandbox/iran.arc guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=269230ad-1700-0000-d6b6-2313c70e0000 pid=3783 execve guuid=d8f26aad-1700-0000-d6b6-2313c80e0000 pid=3784 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=d8f26aad-1700-0000-d6b6-2313c80e0000 pid=3784 execve guuid=f2b22cb9-1700-0000-d6b6-2313ef0e0000 pid=3823 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=f2b22cb9-1700-0000-d6b6-2313ef0e0000 pid=3823 execve guuid=1b7684b9-1700-0000-d6b6-2313f20e0000 pid=3826 /home/sandbox/iran.i486 guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=1b7684b9-1700-0000-d6b6-2313f20e0000 pid=3826 execve guuid=237909ba-1700-0000-d6b6-2313f60e0000 pid=3830 /usr/bin/wget net send-data guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=237909ba-1700-0000-d6b6-2313f60e0000 pid=3830 execve guuid=5dc94cbe-1700-0000-d6b6-23130d0f0000 pid=3853 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=5dc94cbe-1700-0000-d6b6-23130d0f0000 pid=3853 execve guuid=902fcdcd-1700-0000-d6b6-2313440f0000 pid=3908 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=902fcdcd-1700-0000-d6b6-2313440f0000 pid=3908 execve guuid=3c9715ce-1700-0000-d6b6-2313450f0000 pid=3909 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3c9715ce-1700-0000-d6b6-2313450f0000 pid=3909 clone guuid=f661a3ce-1700-0000-d6b6-2313470f0000 pid=3911 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=f661a3ce-1700-0000-d6b6-2313470f0000 pid=3911 execve guuid=8e837cdb-1700-0000-d6b6-2313720f0000 pid=3954 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=8e837cdb-1700-0000-d6b6-2313720f0000 pid=3954 execve guuid=9544bfdb-1700-0000-d6b6-2313730f0000 pid=3955 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=9544bfdb-1700-0000-d6b6-2313730f0000 pid=3955 clone guuid=db7373dc-1700-0000-d6b6-2313750f0000 pid=3957 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=db7373dc-1700-0000-d6b6-2313750f0000 pid=3957 execve guuid=3dc4a1e8-1700-0000-d6b6-23139e0f0000 pid=3998 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3dc4a1e8-1700-0000-d6b6-23139e0f0000 pid=3998 execve guuid=5aa2f0e8-1700-0000-d6b6-23139f0f0000 pid=3999 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=5aa2f0e8-1700-0000-d6b6-23139f0f0000 pid=3999 clone guuid=c7367ee9-1700-0000-d6b6-2313a10f0000 pid=4001 /usr/bin/wget net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=c7367ee9-1700-0000-d6b6-2313a10f0000 pid=4001 execve guuid=d85145fc-1700-0000-d6b6-2313e00f0000 pid=4064 /usr/bin/curl net send-data write-file guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=d85145fc-1700-0000-d6b6-2313e00f0000 pid=4064 execve guuid=3b945c0c-1800-0000-d6b6-231316100000 pid=4118 /usr/bin/chmod guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=3b945c0c-1800-0000-d6b6-231316100000 pid=4118 execve guuid=e02f990c-1800-0000-d6b6-231318100000 pid=4120 /usr/bin/dash guuid=4619aef5-1600-0000-d6b6-2313cd0c0000 pid=3277->guuid=e02f990c-1800-0000-d6b6-231318100000 pid=4120 clone 90011e67-fbbc-56cc-a24f-e0936a104bfc 31.59.104.25:80 guuid=3ddbf0f5-1600-0000-d6b6-2313cf0c0000 pid=3279->90011e67-fbbc-56cc-a24f-e0936a104bfc send: 138B guuid=a8bbf903-1700-0000-d6b6-2313ee0c0000 pid=3310 /home/sandbox/iran.x86_64 zombie guuid=48fd8303-1700-0000-d6b6-2313ec0c0000 pid=3308->guuid=a8bbf903-1700-0000-d6b6-2313ee0c0000 pid=3310 clone guuid=96661a04-1700-0000-d6b6-2313f00c0000 pid=3312 /home/sandbox/iran.x86_64 delete-file dns net send-data zombie guuid=a8bbf903-1700-0000-d6b6-2313ee0c0000 pid=3310->guuid=96661a04-1700-0000-d6b6-2313f00c0000 pid=3312 clone 7b011dff-30f0-593a-a642-00682d8cb065 iran.tmarket.store:80 guuid=82d31104-1700-0000-d6b6-2313ef0c0000 pid=3311->7b011dff-30f0-593a-a642-00682d8cb065 send: 139B d03d1195-ffe1-53c2-89c7-435989603215 iran.tmarket.store:7080 guuid=96661a04-1700-0000-d6b6-2313f00c0000 pid=3312->d03d1195-ffe1-53c2-89c7-435989603215 send: 14B a0528efd-1018-56b4-b518-221acb0fa7ca 9.9.9.9:53 guuid=96661a04-1700-0000-d6b6-2313f00c0000 pid=3312->a0528efd-1018-56b4-b518-221acb0fa7ca send: 72B guuid=781ea004-1700-0000-d6b6-2313f20c0000 pid=3314 /home/sandbox/iran.x86_64 guuid=96661a04-1700-0000-d6b6-2313f00c0000 pid=3312->guuid=781ea004-1700-0000-d6b6-2313f20c0000 pid=3314 clone guuid=7cf22205-1700-0000-d6b6-2313f50c0000 pid=3317 /home/sandbox/iran.x86_64 guuid=781ea004-1700-0000-d6b6-2313f20c0000 pid=3314->guuid=7cf22205-1700-0000-d6b6-2313f50c0000 pid=3317 clone guuid=fd637809-1700-0000-d6b6-2313fe0c0000 pid=3326->7b011dff-30f0-593a-a642-00682d8cb065 send: 88B guuid=071fe012-1700-0000-d6b6-2313150d0000 pid=3349->7b011dff-30f0-593a-a642-00682d8cb065 send: 136B guuid=438ea823-1700-0000-d6b6-23133e0d0000 pid=3390->7b011dff-30f0-593a-a642-00682d8cb065 send: 136B guuid=e5620531-1700-0000-d6b6-2313670d0000 pid=3431->7b011dff-30f0-593a-a642-00682d8cb065 send: 138B guuid=9b2edd3e-1700-0000-d6b6-2313910d0000 pid=3473->7b011dff-30f0-593a-a642-00682d8cb065 send: 139B guuid=50dd4949-1700-0000-d6b6-2313af0d0000 pid=3503->7b011dff-30f0-593a-a642-00682d8cb065 send: 88B guuid=2c2b675a-1700-0000-d6b6-2313c70d0000 pid=3527->7b011dff-30f0-593a-a642-00682d8cb065 send: 137B guuid=afcf2863-1700-0000-d6b6-2313e00d0000 pid=3552->7b011dff-30f0-593a-a642-00682d8cb065 send: 135B guuid=e09eba87-1700-0000-d6b6-2313530e0000 pid=3667->7b011dff-30f0-593a-a642-00682d8cb065 send: 84B guuid=2849c5a1-1700-0000-d6b6-2313970e0000 pid=3735->7b011dff-30f0-593a-a642-00682d8cb065 send: 135B guuid=766a9da6-1700-0000-d6b6-2313ae0e0000 pid=3758->7b011dff-30f0-593a-a642-00682d8cb065 send: 84B guuid=d8f26aad-1700-0000-d6b6-2313c80e0000 pid=3784->7b011dff-30f0-593a-a642-00682d8cb065 send: 136B guuid=0dfaffb9-1700-0000-d6b6-2313f50e0000 pid=3829 /home/sandbox/iran.i486 guuid=1b7684b9-1700-0000-d6b6-2313f20e0000 pid=3826->guuid=0dfaffb9-1700-0000-d6b6-2313f50e0000 pid=3829 clone guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3831 /home/sandbox/iran.i486 delete-file dns net send-data zombie guuid=0dfaffb9-1700-0000-d6b6-2313f50e0000 pid=3829->guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3831 clone guuid=237909ba-1700-0000-d6b6-2313f60e0000 pid=3830->7b011dff-30f0-593a-a642-00682d8cb065 send: 138B guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3831->d03d1195-ffe1-53c2-89c7-435989603215 send: 12B guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3831->a0528efd-1018-56b4-b518-221acb0fa7ca send: 72B guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3832 /home/sandbox/iran.i486 zombie guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3831->guuid=0b7e0aba-1700-0000-d6b6-2313f70e0000 pid=3832 clone guuid=5dc94cbe-1700-0000-d6b6-23130d0f0000 pid=3853->7b011dff-30f0-593a-a642-00682d8cb065 send: 87B guuid=f661a3ce-1700-0000-d6b6-2313470f0000 pid=3911->7b011dff-30f0-593a-a642-00682d8cb065 send: 138B guuid=db7373dc-1700-0000-d6b6-2313750f0000 pid=3957->7b011dff-30f0-593a-a642-00682d8cb065 send: 138B guuid=c7367ee9-1700-0000-d6b6-2313a10f0000 pid=4001->7b011dff-30f0-593a-a642-00682d8cb065 send: 138B guuid=d85145fc-1700-0000-d6b6-2313e00f0000 pid=4064->7b011dff-30f0-593a-a642-00682d8cb065 send: 87B
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-04-30 06:01:43 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ab60ddea7281cd4fc39d94668a431f7e23159a4430f504c83be30ba27c511ff7

(this sample)

  
Delivery method
Distributed via web download

Comments