MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b22fb4cf24c96da28ed1cc3e5f5514b33fdcbc3af13fe9733acea6b328ceccac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: b22fb4cf24c96da28ed1cc3e5f5514b33fdcbc3af13fe9733acea6b328ceccac
SHA3-384 hash: e26d48429ebe052b7099f27c162b71b7ca4ba426d23e349b27907abcac608a945e4528279900f1cdd52890fc059b6413
SHA1 hash: aa6e50ab1febbb6bf3cce1a9ddbb00faeff6e9f6
MD5 hash: e6ac4beb231201daffbdcd76d8889ebc
humanhash: shade-ack-delaware-island
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'901 bytes
First seen:2026-05-14 11:28:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:slfNHEyqzj1lEt5q8aVvVfyDvZo78OMqND0HbW:gW1OT0
TLSH T18B41FFCEA0F8A143C6DEEF0074E58DC86316959271DE2B3AEDC12E67C4C9D547029B36
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.161/iran.x86_64n/an/aelf ua-wget
http://176.65.139.161/iran.aarch644d29ab52898976ab806adb6bd60e1a090902415f728b08c67f260d200fa50f93 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.m68k09135d0430d10182d9c324aee5e51d9d3943f638e928c365db59d42e412213f9 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.mipsb453283c59da4f35ccffa9a894843e7590ca8fe80e64bc38d55b15b7963a8fd4 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.mipsela4e240796c803d6da03f21b5ba1d60216b752ccc345c64a6af55e47bc50f72a1 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.powerpc88fc1d117bf3352cf4b881df7bd5d1d1d99d16a3d07ef6c5a7ab5e4c84db4a33 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.sparc8b10722f9c4b4d8c54ef722fd695fe75fbb8e9ef53a8a0863d6e4510f54e1f55 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.sh4568b29251f96b4130a6a508fdd1a4fd2e55ecdd5791206172126118a88a38b51 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.arcd375985b8bb77cd2ef801e66844823fcf9f6e94869a182ce352261fee42cff8f Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.i4864fdbd07e9b649126b8351953462e477192313037469d0647a82c9627e599c4ad Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.armv4l572ec4aef59476a80e73005fe75020eaefb981cced28f93ca21693e20dec1515 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.armv5l9c841796f660355e6d516fc6cef6f101e40d1cf41067c4a1d9b0dea13fa1b30f Miraielf ua-wget
http://176.65.139.161/iran.armv6l3df614a61618462df246beb436b097afd782bea357764d7350fd4ee2ba86d0b8 Mirai176-65-139-161 elf mirai ua-wget
http://176.65.139.161/iran.armv7l581490b846dcd45d241e94930a0e86bf04c99777346bcfe107561bdae728afa8 Mirai176-65-139-161 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
US US
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=58b25e9c-1a00-0000-52f8-65abfb0a0000 pid=2811 /usr/bin/sudo guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819 /tmp/sample.bin guuid=58b25e9c-1a00-0000-52f8-65abfb0a0000 pid=2811->guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819 execve guuid=a455639f-1a00-0000-52f8-65ab040b0000 pid=2820 /usr/bin/wget net send-data guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=a455639f-1a00-0000-52f8-65ab040b0000 pid=2820 execve guuid=2db5cba2-1a00-0000-52f8-65ab0b0b0000 pid=2827 /usr/bin/curl net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=2db5cba2-1a00-0000-52f8-65ab0b0b0000 pid=2827 execve guuid=a3d589ac-1a00-0000-52f8-65ab1c0b0000 pid=2844 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=a3d589ac-1a00-0000-52f8-65ab1c0b0000 pid=2844 execve guuid=d2e019ad-1a00-0000-52f8-65ab1e0b0000 pid=2846 /home/sandbox/iran.x86_64 guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=d2e019ad-1a00-0000-52f8-65ab1e0b0000 pid=2846 execve guuid=b12e7ead-1a00-0000-52f8-65ab200b0000 pid=2848 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=b12e7ead-1a00-0000-52f8-65ab200b0000 pid=2848 execve guuid=07bbdeb3-1a00-0000-52f8-65ab280b0000 pid=2856 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=07bbdeb3-1a00-0000-52f8-65ab280b0000 pid=2856 execve guuid=400819b4-1a00-0000-52f8-65ab2a0b0000 pid=2858 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=400819b4-1a00-0000-52f8-65ab2a0b0000 pid=2858 clone guuid=cf968eb4-1a00-0000-52f8-65ab2d0b0000 pid=2861 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=cf968eb4-1a00-0000-52f8-65ab2d0b0000 pid=2861 execve guuid=90beb5b9-1a00-0000-52f8-65ab370b0000 pid=2871 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=90beb5b9-1a00-0000-52f8-65ab370b0000 pid=2871 execve guuid=b8e4f1b9-1a00-0000-52f8-65ab390b0000 pid=2873 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=b8e4f1b9-1a00-0000-52f8-65ab390b0000 pid=2873 clone guuid=9aee77ba-1a00-0000-52f8-65ab3c0b0000 pid=2876 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=9aee77ba-1a00-0000-52f8-65ab3c0b0000 pid=2876 execve guuid=adbd27c0-1a00-0000-52f8-65ab4c0b0000 pid=2892 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=adbd27c0-1a00-0000-52f8-65ab4c0b0000 pid=2892 execve guuid=39e187c0-1a00-0000-52f8-65ab4e0b0000 pid=2894 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=39e187c0-1a00-0000-52f8-65ab4e0b0000 pid=2894 clone guuid=333555c1-1a00-0000-52f8-65ab520b0000 pid=2898 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=333555c1-1a00-0000-52f8-65ab520b0000 pid=2898 execve guuid=c903cfc6-1a00-0000-52f8-65ab600b0000 pid=2912 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=c903cfc6-1a00-0000-52f8-65ab600b0000 pid=2912 execve guuid=658b08c7-1a00-0000-52f8-65ab620b0000 pid=2914 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=658b08c7-1a00-0000-52f8-65ab620b0000 pid=2914 clone guuid=209989c7-1a00-0000-52f8-65ab660b0000 pid=2918 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=209989c7-1a00-0000-52f8-65ab660b0000 pid=2918 execve guuid=d93e8bcc-1a00-0000-52f8-65ab6f0b0000 pid=2927 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=d93e8bcc-1a00-0000-52f8-65ab6f0b0000 pid=2927 execve guuid=85cac1cc-1a00-0000-52f8-65ab700b0000 pid=2928 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=85cac1cc-1a00-0000-52f8-65ab700b0000 pid=2928 clone guuid=872cafce-1a00-0000-52f8-65ab760b0000 pid=2934 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=872cafce-1a00-0000-52f8-65ab760b0000 pid=2934 execve guuid=44a567df-1a00-0000-52f8-65ab7d0b0000 pid=2941 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=44a567df-1a00-0000-52f8-65ab7d0b0000 pid=2941 execve guuid=975bc5df-1a00-0000-52f8-65ab7e0b0000 pid=2942 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=975bc5df-1a00-0000-52f8-65ab7e0b0000 pid=2942 clone guuid=3a129ee0-1a00-0000-52f8-65ab810b0000 pid=2945 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=3a129ee0-1a00-0000-52f8-65ab810b0000 pid=2945 execve guuid=4776dce5-1a00-0000-52f8-65ab8c0b0000 pid=2956 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=4776dce5-1a00-0000-52f8-65ab8c0b0000 pid=2956 execve guuid=b2bb4fe6-1a00-0000-52f8-65ab8d0b0000 pid=2957 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=b2bb4fe6-1a00-0000-52f8-65ab8d0b0000 pid=2957 clone guuid=72b0e3e7-1a00-0000-52f8-65ab8f0b0000 pid=2959 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=72b0e3e7-1a00-0000-52f8-65ab8f0b0000 pid=2959 execve guuid=02978aed-1a00-0000-52f8-65ab950b0000 pid=2965 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=02978aed-1a00-0000-52f8-65ab950b0000 pid=2965 execve guuid=7403d2ed-1a00-0000-52f8-65ab960b0000 pid=2966 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=7403d2ed-1a00-0000-52f8-65ab960b0000 pid=2966 clone guuid=2c9887ee-1a00-0000-52f8-65ab9a0b0000 pid=2970 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=2c9887ee-1a00-0000-52f8-65ab9a0b0000 pid=2970 execve guuid=9ecef4f2-1a00-0000-52f8-65aba20b0000 pid=2978 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=9ecef4f2-1a00-0000-52f8-65aba20b0000 pid=2978 execve guuid=1e847ef3-1a00-0000-52f8-65aba30b0000 pid=2979 /home/sandbox/iran.i486 guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=1e847ef3-1a00-0000-52f8-65aba30b0000 pid=2979 execve guuid=407840f4-1a00-0000-52f8-65aba70b0000 pid=2983 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=407840f4-1a00-0000-52f8-65aba70b0000 pid=2983 execve guuid=e6b35afb-1a00-0000-52f8-65abb40b0000 pid=2996 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=e6b35afb-1a00-0000-52f8-65abb40b0000 pid=2996 execve guuid=5b5fbafb-1a00-0000-52f8-65abb60b0000 pid=2998 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=5b5fbafb-1a00-0000-52f8-65abb60b0000 pid=2998 clone guuid=8b06a6fc-1a00-0000-52f8-65abba0b0000 pid=3002 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=8b06a6fc-1a00-0000-52f8-65abba0b0000 pid=3002 execve guuid=7ea7f901-1b00-0000-52f8-65abc30b0000 pid=3011 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=7ea7f901-1b00-0000-52f8-65abc30b0000 pid=3011 execve guuid=82d24002-1b00-0000-52f8-65abc50b0000 pid=3013 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=82d24002-1b00-0000-52f8-65abc50b0000 pid=3013 clone guuid=37f1ec02-1b00-0000-52f8-65abc80b0000 pid=3016 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=37f1ec02-1b00-0000-52f8-65abc80b0000 pid=3016 execve guuid=a02baf09-1b00-0000-52f8-65abd50b0000 pid=3029 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=a02baf09-1b00-0000-52f8-65abd50b0000 pid=3029 execve guuid=802c330a-1b00-0000-52f8-65abd70b0000 pid=3031 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=802c330a-1b00-0000-52f8-65abd70b0000 pid=3031 clone guuid=cefdc60a-1b00-0000-52f8-65abdb0b0000 pid=3035 /usr/bin/wget net send-data write-file guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=cefdc60a-1b00-0000-52f8-65abdb0b0000 pid=3035 execve guuid=85763f0f-1b00-0000-52f8-65abe60b0000 pid=3046 /usr/bin/chmod guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=85763f0f-1b00-0000-52f8-65abe60b0000 pid=3046 execve guuid=a70ca70f-1b00-0000-52f8-65abe80b0000 pid=3048 /usr/bin/dash guuid=b20c279f-1a00-0000-52f8-65ab030b0000 pid=2819->guuid=a70ca70f-1b00-0000-52f8-65abe80b0000 pid=3048 clone 72a78419-8065-5ec7-93ba-cdb426fb221b 176.65.139.161:80 guuid=a455639f-1a00-0000-52f8-65ab040b0000 pid=2820->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B guuid=2db5cba2-1a00-0000-52f8-65ab0b0b0000 pid=2827->72a78419-8065-5ec7-93ba-cdb426fb221b send: 89B guuid=b12e7ead-1a00-0000-52f8-65ab200b0000 pid=2848->72a78419-8065-5ec7-93ba-cdb426fb221b send: 141B guuid=cf968eb4-1a00-0000-52f8-65ab2d0b0000 pid=2861->72a78419-8065-5ec7-93ba-cdb426fb221b send: 138B guuid=9aee77ba-1a00-0000-52f8-65ab3c0b0000 pid=2876->72a78419-8065-5ec7-93ba-cdb426fb221b send: 138B guuid=333555c1-1a00-0000-52f8-65ab520b0000 pid=2898->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B guuid=209989c7-1a00-0000-52f8-65ab660b0000 pid=2918->72a78419-8065-5ec7-93ba-cdb426fb221b send: 141B guuid=872cafce-1a00-0000-52f8-65ab760b0000 pid=2934->72a78419-8065-5ec7-93ba-cdb426fb221b send: 139B guuid=3a129ee0-1a00-0000-52f8-65ab810b0000 pid=2945->72a78419-8065-5ec7-93ba-cdb426fb221b send: 137B guuid=72b0e3e7-1a00-0000-52f8-65ab8f0b0000 pid=2959->72a78419-8065-5ec7-93ba-cdb426fb221b send: 137B guuid=2c9887ee-1a00-0000-52f8-65ab9a0b0000 pid=2970->72a78419-8065-5ec7-93ba-cdb426fb221b send: 138B guuid=72bc34f4-1a00-0000-52f8-65aba50b0000 pid=2981 /home/sandbox/iran.i486 guuid=1e847ef3-1a00-0000-52f8-65aba30b0000 pid=2979->guuid=72bc34f4-1a00-0000-52f8-65aba50b0000 pid=2981 clone guuid=d0f53ef4-1a00-0000-52f8-65aba60b0000 pid=2982 /home/sandbox/iran.i486 delete-file net zombie guuid=72bc34f4-1a00-0000-52f8-65aba50b0000 pid=2981->guuid=d0f53ef4-1a00-0000-52f8-65aba60b0000 pid=2982 clone d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 176.65.139.161:25596 guuid=d0f53ef4-1a00-0000-52f8-65aba60b0000 pid=2982->d9f20b8d-9abf-5808-8fe1-e50e32c0bc21 con guuid=407840f4-1a00-0000-52f8-65aba70b0000 pid=2983->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B guuid=8b06a6fc-1a00-0000-52f8-65abba0b0000 pid=3002->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B guuid=37f1ec02-1b00-0000-52f8-65abc80b0000 pid=3016->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B guuid=cefdc60a-1b00-0000-52f8-65abdb0b0000 pid=3035->72a78419-8065-5ec7-93ba-cdb426fb221b send: 140B
Threat name:
Script.Downloader.Iranbot
Status:
Malicious
First seen:
2026-05-14 11:03:49 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b22fb4cf24c96da28ed1cc3e5f5514b33fdcbc3af13fe9733acea6b328ceccac

(this sample)

  
Delivery method
Distributed via web download

Comments