MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad3ac83dde69091d05f96343db6fbbb0acdd262f8d7ed4069bcfcea044164f94. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: ad3ac83dde69091d05f96343db6fbbb0acdd262f8d7ed4069bcfcea044164f94
SHA3-384 hash: 35d1ce12f3513751e5c4c96ff133249eb5da0dbcf944ba60b9e96bfceaf8c9952ff3233a97c285d210f532702c6eec71
SHA1 hash: 0734968f3ecc928f7eef2a7395d9a5c59c54c3b5
MD5 hash: 341b80250dc371ffb13aa0ccde873d0e
humanhash: september-india-happy-princess
File name:kla.sh
Download: download sample
Signature Mirai
File size:333 bytes
First seen:2026-02-22 14:03:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:tYM3FicfVQgNUzFGaQMVeMTyMcIaoef1Jf7FKiE5TZHhyMVeMTyI6Iaoef1JfN:Mcq5GcVkVxoefDoHBxVkI6xoefDN
TLSH T10BE026801430D81B0E80480DF111CC9DBC4EB0967DD20A1C6A4E8AA24BD6FE830457A3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.103.101.235/bins/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=0495c146-1900-0000-a523-a5068a090000 pid=2442 /usr/bin/sudo guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446 /tmp/sample.bin guuid=0495c146-1900-0000-a523-a5068a090000 pid=2442->guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446 execve guuid=770ed94a-1900-0000-a523-a50694090000 pid=2452 /usr/bin/wget net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=770ed94a-1900-0000-a523-a50694090000 pid=2452 execve guuid=9f33de65-1900-0000-a523-a506c9090000 pid=2505 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=9f33de65-1900-0000-a523-a506c9090000 pid=2505 execve guuid=66605a66-1900-0000-a523-a506ca090000 pid=2506 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=66605a66-1900-0000-a523-a506ca090000 pid=2506 clone guuid=92540867-1900-0000-a523-a506cd090000 pid=2509 /usr/bin/curl net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=92540867-1900-0000-a523-a506cd090000 pid=2509 execve guuid=ade8c176-1900-0000-a523-a506ef090000 pid=2543 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=ade8c176-1900-0000-a523-a506ef090000 pid=2543 execve guuid=4b261e77-1900-0000-a523-a506f1090000 pid=2545 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=4b261e77-1900-0000-a523-a506f1090000 pid=2545 clone guuid=f653d477-1900-0000-a523-a506f5090000 pid=2549 /usr/bin/wget net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=f653d477-1900-0000-a523-a506f5090000 pid=2549 execve guuid=b1bbf380-1900-0000-a523-a5060b0a0000 pid=2571 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=b1bbf380-1900-0000-a523-a5060b0a0000 pid=2571 execve guuid=263e5a81-1900-0000-a523-a5060d0a0000 pid=2573 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=263e5a81-1900-0000-a523-a5060d0a0000 pid=2573 clone guuid=fd442a82-1900-0000-a523-a506120a0000 pid=2578 /usr/bin/curl net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=fd442a82-1900-0000-a523-a506120a0000 pid=2578 execve guuid=7af2698f-1900-0000-a523-a506370a0000 pid=2615 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=7af2698f-1900-0000-a523-a506370a0000 pid=2615 execve guuid=7077c68f-1900-0000-a523-a5063a0a0000 pid=2618 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=7077c68f-1900-0000-a523-a5063a0a0000 pid=2618 clone guuid=c2196390-1900-0000-a523-a5063e0a0000 pid=2622 /usr/bin/wget net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=c2196390-1900-0000-a523-a5063e0a0000 pid=2622 execve guuid=dd085a97-1900-0000-a523-a506540a0000 pid=2644 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=dd085a97-1900-0000-a523-a506540a0000 pid=2644 execve guuid=1708c297-1900-0000-a523-a506560a0000 pid=2646 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=1708c297-1900-0000-a523-a506560a0000 pid=2646 clone guuid=c0334798-1900-0000-a523-a5065a0a0000 pid=2650 /usr/bin/curl net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=c0334798-1900-0000-a523-a5065a0a0000 pid=2650 execve guuid=b6ffc0a0-1900-0000-a523-a506710a0000 pid=2673 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=b6ffc0a0-1900-0000-a523-a506710a0000 pid=2673 execve guuid=462825a1-1900-0000-a523-a506730a0000 pid=2675 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=462825a1-1900-0000-a523-a506730a0000 pid=2675 clone guuid=10a1b8a1-1900-0000-a523-a506770a0000 pid=2679 /usr/bin/wget net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=10a1b8a1-1900-0000-a523-a506770a0000 pid=2679 execve guuid=6a380aaa-1900-0000-a523-a5068f0a0000 pid=2703 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=6a380aaa-1900-0000-a523-a5068f0a0000 pid=2703 execve guuid=426e49aa-1900-0000-a523-a506910a0000 pid=2705 /dev/r delete-file net guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=426e49aa-1900-0000-a523-a506910a0000 pid=2705 execve guuid=becc7faa-1900-0000-a523-a506940a0000 pid=2708 /usr/bin/curl net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=becc7faa-1900-0000-a523-a506940a0000 pid=2708 execve guuid=b2df0bb6-1900-0000-a523-a506b60a0000 pid=2742 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=b2df0bb6-1900-0000-a523-a506b60a0000 pid=2742 execve guuid=92a662b6-1900-0000-a523-a506b80a0000 pid=2744 /dev/r delete-file net guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=92a662b6-1900-0000-a523-a506b80a0000 pid=2744 execve guuid=496ddbe0-1a00-0000-a523-a506da0c0000 pid=3290 /usr/bin/wget net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=496ddbe0-1a00-0000-a523-a506da0c0000 pid=3290 execve guuid=b78793ec-1a00-0000-a523-a506f50c0000 pid=3317 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=b78793ec-1a00-0000-a523-a506f50c0000 pid=3317 execve guuid=8e1677ed-1a00-0000-a523-a506f90c0000 pid=3321 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=8e1677ed-1a00-0000-a523-a506f90c0000 pid=3321 clone guuid=0c4b68ef-1a00-0000-a523-a506ff0c0000 pid=3327 /usr/bin/curl net send-data write-file guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=0c4b68ef-1a00-0000-a523-a506ff0c0000 pid=3327 execve guuid=7cdbb206-1b00-0000-a523-a506270d0000 pid=3367 /usr/bin/chmod guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=7cdbb206-1b00-0000-a523-a506270d0000 pid=3367 execve guuid=29a21207-1b00-0000-a523-a506280d0000 pid=3368 /usr/bin/bash guuid=bd238249-1900-0000-a523-a5068e090000 pid=2446->guuid=29a21207-1b00-0000-a523-a506280d0000 pid=3368 clone fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 185.103.101.235:80 guuid=770ed94a-1900-0000-a523-a50694090000 pid=2452->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 139B guuid=92540867-1900-0000-a523-a506cd090000 pid=2509->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 88B guuid=f653d477-1900-0000-a523-a506f5090000 pid=2549->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 139B guuid=fd442a82-1900-0000-a523-a506120a0000 pid=2578->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 88B guuid=c2196390-1900-0000-a523-a5063e0a0000 pid=2622->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 139B guuid=c0334798-1900-0000-a523-a5065a0a0000 pid=2650->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 88B guuid=10a1b8a1-1900-0000-a523-a506770a0000 pid=2679->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 138B c1d217c9-65fe-519e-9e84-de3f19213f6b 185.103.101.235:53 guuid=426e49aa-1900-0000-a523-a506910a0000 pid=2705->c1d217c9-65fe-519e-9e84-de3f19213f6b con guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706 /dev/r net send-data zombie guuid=426e49aa-1900-0000-a523-a506910a0000 pid=2705->guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706 clone guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706->c1d217c9-65fe-519e-9e84-de3f19213f6b con 9a1975b8-e8eb-5e55-9083-27397a11b6e0 185.103.101.235:18129 guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706->9a1975b8-e8eb-5e55-9083-27397a11b6e0 send: 12B guuid=d7217eaa-1900-0000-a523-a506930a0000 pid=2707 /dev/r guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706->guuid=d7217eaa-1900-0000-a523-a506930a0000 pid=2707 clone guuid=4abc82aa-1900-0000-a523-a506950a0000 pid=2709 /dev/r guuid=408971aa-1900-0000-a523-a506920a0000 pid=2706->guuid=4abc82aa-1900-0000-a523-a506950a0000 pid=2709 clone guuid=becc7faa-1900-0000-a523-a506940a0000 pid=2708->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 87B guuid=92a662b6-1900-0000-a523-a506b80a0000 pid=2744->c1d217c9-65fe-519e-9e84-de3f19213f6b con 0637bfa0-18a1-551d-95eb-ed76e272eef1 0.0.0.0:18129 guuid=92a662b6-1900-0000-a523-a506b80a0000 pid=2744->0637bfa0-18a1-551d-95eb-ed76e272eef1 con guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287 /dev/r net send-data zombie guuid=92a662b6-1900-0000-a523-a506b80a0000 pid=2744->guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287 clone guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287->c1d217c9-65fe-519e-9e84-de3f19213f6b con guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287->9a1975b8-e8eb-5e55-9083-27397a11b6e0 send: 14B guuid=519cd2e0-1a00-0000-a523-a506d80c0000 pid=3288 /dev/r guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287->guuid=519cd2e0-1a00-0000-a523-a506d80c0000 pid=3288 clone guuid=e8fbd6e0-1a00-0000-a523-a506d90c0000 pid=3289 /dev/r guuid=412bb8e0-1a00-0000-a523-a506d70c0000 pid=3287->guuid=e8fbd6e0-1a00-0000-a523-a506d90c0000 pid=3289 clone guuid=496ddbe0-1a00-0000-a523-a506da0c0000 pid=3290->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 139B guuid=0c4b68ef-1a00-0000-a523-a506ff0c0000 pid=3327->fa57aa7e-f09b-51e4-a9d1-f937b4867ca8 send: 88B
Threat name:
Script-Shell.Malware.MiraiB
Status:
Malicious
First seen:
2026-02-21 18:18:34 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ad3ac83dde69091d05f96343db6fbbb0acdd262f8d7ed4069bcfcea044164f94

(this sample)

  
Delivery method
Distributed via web download

Comments