🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7fe13d9b94fc0c9b77595756f26764c23624dfa8df2d273727fcfd1c8f13b6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: b7fe13d9b94fc0c9b77595756f26764c23624dfa8df2d273727fcfd1c8f13b6d
SHA3-384 hash: 08d95c03ce88b649f0808a5e460d2dbe7bb97c107c906b93bc1d7e31ff752cd64add89e591cde132ecff55ad4a0f710f
SHA1 hash: c0f9655deb2ffd9aea7741ed3919af94681bcd6f
MD5 hash: 099747bf245bfc8285448f9fd07882f0
humanhash: london-fruit-cola-london
File name:run.sh
Download: download sample
Signature Mirai
File size:712 bytes
First seen:2026-09-01 15:44:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:z6PiLUUVHU8WEVHGWGzSYZ3LV9gfLlitzuvzuzJXkWAXp0HzNlQQ7zNlU5uG:WP8UUXzgzSYpLSKzuvzuz5kWAX+HRlBw
TLSH T18F0197D1FCA0817BB84C8328EA948040598E1C7F48E43A1D70FE9E6A3B2C8382469733
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
AT AT
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-09-01T13:02:00Z UTC
Last seen:
2026-09-02T18:03:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2c12668d-1a00-0000-1e40-1c023d080000 pid=2109 /usr/bin/sudo guuid=b67d6290-1a00-0000-1e40-1c0241080000 pid=2113 /tmp/sample.bin guuid=2c12668d-1a00-0000-1e40-1c023d080000 pid=2109->guuid=b67d6290-1a00-0000-1e40-1c0241080000 pid=2113 execve guuid=4ef5bd90-1a00-0000-1e40-1c0242080000 pid=2114 /usr/bin/wget net send-data write-file guuid=b67d6290-1a00-0000-1e40-1c0241080000 pid=2113->guuid=4ef5bd90-1a00-0000-1e40-1c0242080000 pid=2114 execve guuid=15861d95-1a00-0000-1e40-1c024b080000 pid=2123 /usr/bin/chmod guuid=b67d6290-1a00-0000-1e40-1c0241080000 pid=2113->guuid=15861d95-1a00-0000-1e40-1c024b080000 pid=2123 execve guuid=372e8d95-1a00-0000-1e40-1c024d080000 pid=2125 /usr/bin/dash guuid=b67d6290-1a00-0000-1e40-1c0241080000 pid=2113->guuid=372e8d95-1a00-0000-1e40-1c024d080000 pid=2125 clone 494048df-cc03-5e15-983c-45b09c778cbd 94.26.106.80:80 guuid=4ef5bd90-1a00-0000-1e40-1c0242080000 pid=2114->494048df-cc03-5e15-983c-45b09c778cbd send: 136B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-09-01 15:42:44 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet defense_evasion linux
Behaviour
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Family: Mirai
Malware Config
C2 Extraction:
94.26.106.80
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments