MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cadf82600085db2bd650c43d6323f2383f7696805a7cd26a2744f2f01743c8b2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: cadf82600085db2bd650c43d6323f2383f7696805a7cd26a2744f2f01743c8b2
SHA3-384 hash: 56648649b4f1dc23d819398608d047c184c04f93448f52ebbc0d36bfb05a924b525a5371c8d7e73bbf2718f5f3fa60f0
SHA1 hash: 59ff7f6c8e10a7ba0a7d174d28fe425a66954621
MD5 hash: af101253c384a312845ce430aa860fc0
humanhash: mango-william-september-freddie
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'017 bytes
First seen:2025-12-25 19:18:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:oMywWW5hbUWWflaWW29NIl5MWWQCa0LKVWW1NgO0WWjJibWWZO7ZWWWSvUWW9Nt4:TulbNI7mKUzi8WAMNt0HO0PDf7
TLSH T1DA11B9CF31911FF148089E0CF9770428558785D8FE626EA857871C3A4CDB72C7938EA6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.156.152.90/bins/arme0844b0cdf611d8a7521ff37ca40ab691a2c2c3e28a4b9571ff9456d5b5a2b77 Miraielf ua-wget
http://94.156.152.90/bins/arm5f6fbf730c614f55b266174036c98d1827bc602c3c830ccff25454272c694b91f Miraielf ua-wget
http://94.156.152.90/bins/arm646588e27520d4ff181d33bc7ff021903d1ecd13f376657f5db7af180ca2e3ac6 Miraielf mirai ua-wget
http://94.156.152.90/bins/arm7c05ee431ce3abe70afdbf9710b0ab3864ecdd8de9f8697c077f956a39bdf8217 Miraielf ua-wget
http://94.156.152.90/bins/m68k0fc0c0aa10d7f989ee6709c50908144d95b2c62ad512419f690652c906db8ed5 Miraielf mirai ua-wget
http://94.156.152.90/bins/mips0f8f041acce3852c7ee78caffddcb4e941206b3c5b905bb5e6c061285ce08852 Miraielf ua-wget
http://94.156.152.90/bins/mpsld80d236e16bfef3dd5b8aacb4aff4226616be790c3b5dc2325af73e71d61441c Miraielf mirai ua-wget
http://94.156.152.90/bins/ppc14d5f0267f0ca1c67bdd8e3075ee3598e2ae7444c7f87bab0b862b3b5ee6ced7 Miraielf ua-wget
http://94.156.152.90/bins/sh4439b5691344326a2b67d18c5414f27c50d2b5be2bba021a6c74fbd718fd956ce Miraielf ua-wget
http://94.156.152.90/bins/spc2951437574f0b44b68855462c650bc1d7b10fbaf36ed86e7a45faec38b87ee6e Miraielf ua-wget
http://94.156.152.90/bins/x8603ecda01330d867752a09c2e6118fed74a061d4f5222d492ab43640e0d36e6c4 Miraielf mirai ua-wget
http://94.156.152.90/bins/x86_64c0fe3a9a893f48296e27f62bb47a35480d0255c5df46d2185963ce8552004535 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-25T16:25:00Z UTC
Last seen:
2025-12-27T12:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=216a401a-1b00-0000-e73d-e70be10a0000 pid=2785 /usr/bin/sudo guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790 /tmp/sample.bin guuid=216a401a-1b00-0000-e73d-e70be10a0000 pid=2785->guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790 execve guuid=60eb181d-1b00-0000-e73d-e70be80a0000 pid=2792 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=60eb181d-1b00-0000-e73d-e70be80a0000 pid=2792 execve guuid=a159fa2d-1b00-0000-e73d-e70bfd0a0000 pid=2813 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=a159fa2d-1b00-0000-e73d-e70bfd0a0000 pid=2813 execve guuid=564d5e2e-1b00-0000-e73d-e70bff0a0000 pid=2815 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=564d5e2e-1b00-0000-e73d-e70bff0a0000 pid=2815 clone guuid=29452d2f-1b00-0000-e73d-e70b030b0000 pid=2819 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=29452d2f-1b00-0000-e73d-e70b030b0000 pid=2819 execve guuid=d733893d-1b00-0000-e73d-e70b1f0b0000 pid=2847 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=d733893d-1b00-0000-e73d-e70b1f0b0000 pid=2847 execve guuid=150bec3d-1b00-0000-e73d-e70b200b0000 pid=2848 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=150bec3d-1b00-0000-e73d-e70b200b0000 pid=2848 clone guuid=27eaa83e-1b00-0000-e73d-e70b240b0000 pid=2852 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=27eaa83e-1b00-0000-e73d-e70b240b0000 pid=2852 execve guuid=e18b534e-1b00-0000-e73d-e70b450b0000 pid=2885 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=e18b534e-1b00-0000-e73d-e70b450b0000 pid=2885 execve guuid=2786bf4e-1b00-0000-e73d-e70b480b0000 pid=2888 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=2786bf4e-1b00-0000-e73d-e70b480b0000 pid=2888 clone guuid=c98e814f-1b00-0000-e73d-e70b4d0b0000 pid=2893 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=c98e814f-1b00-0000-e73d-e70b4d0b0000 pid=2893 execve guuid=5d97bf60-1b00-0000-e73d-e70b700b0000 pid=2928 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=5d97bf60-1b00-0000-e73d-e70b700b0000 pid=2928 execve guuid=03922061-1b00-0000-e73d-e70b710b0000 pid=2929 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=03922061-1b00-0000-e73d-e70b710b0000 pid=2929 clone guuid=20eef161-1b00-0000-e73d-e70b740b0000 pid=2932 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=20eef161-1b00-0000-e73d-e70b740b0000 pid=2932 execve guuid=1f49e572-1b00-0000-e73d-e70b8a0b0000 pid=2954 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=1f49e572-1b00-0000-e73d-e70b8a0b0000 pid=2954 execve guuid=c9cb5073-1b00-0000-e73d-e70b8d0b0000 pid=2957 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=c9cb5073-1b00-0000-e73d-e70b8d0b0000 pid=2957 clone guuid=ebcf1074-1b00-0000-e73d-e70b900b0000 pid=2960 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=ebcf1074-1b00-0000-e73d-e70b900b0000 pid=2960 execve guuid=523fcf82-1b00-0000-e73d-e70ba90b0000 pid=2985 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=523fcf82-1b00-0000-e73d-e70ba90b0000 pid=2985 execve guuid=ba9a3f83-1b00-0000-e73d-e70bab0b0000 pid=2987 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=ba9a3f83-1b00-0000-e73d-e70bab0b0000 pid=2987 clone guuid=0d353685-1b00-0000-e73d-e70baf0b0000 pid=2991 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=0d353685-1b00-0000-e73d-e70baf0b0000 pid=2991 execve guuid=11b24893-1b00-0000-e73d-e70bc90b0000 pid=3017 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=11b24893-1b00-0000-e73d-e70bc90b0000 pid=3017 execve guuid=be1d9b93-1b00-0000-e73d-e70bcb0b0000 pid=3019 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=be1d9b93-1b00-0000-e73d-e70bcb0b0000 pid=3019 clone guuid=f3cb1e95-1b00-0000-e73d-e70bce0b0000 pid=3022 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=f3cb1e95-1b00-0000-e73d-e70bce0b0000 pid=3022 execve guuid=25e386a4-1b00-0000-e73d-e70beb0b0000 pid=3051 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=25e386a4-1b00-0000-e73d-e70beb0b0000 pid=3051 execve guuid=bb4cf2a4-1b00-0000-e73d-e70bed0b0000 pid=3053 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=bb4cf2a4-1b00-0000-e73d-e70bed0b0000 pid=3053 clone guuid=2fb618a6-1b00-0000-e73d-e70bf10b0000 pid=3057 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=2fb618a6-1b00-0000-e73d-e70bf10b0000 pid=3057 execve guuid=c91e5cb4-1b00-0000-e73d-e70b140c0000 pid=3092 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=c91e5cb4-1b00-0000-e73d-e70b140c0000 pid=3092 execve guuid=f523a8b4-1b00-0000-e73d-e70b150c0000 pid=3093 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=f523a8b4-1b00-0000-e73d-e70b150c0000 pid=3093 clone guuid=6ac4a1b5-1b00-0000-e73d-e70b190c0000 pid=3097 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=6ac4a1b5-1b00-0000-e73d-e70b190c0000 pid=3097 execve guuid=395b89c4-1b00-0000-e73d-e70b3e0c0000 pid=3134 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=395b89c4-1b00-0000-e73d-e70b3e0c0000 pid=3134 execve guuid=094180c5-1b00-0000-e73d-e70b410c0000 pid=3137 /usr/bin/bash guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=094180c5-1b00-0000-e73d-e70b410c0000 pid=3137 clone guuid=a45232c6-1b00-0000-e73d-e70b440c0000 pid=3140 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=a45232c6-1b00-0000-e73d-e70b440c0000 pid=3140 execve guuid=f488bed4-1b00-0000-e73d-e70b610c0000 pid=3169 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=f488bed4-1b00-0000-e73d-e70b610c0000 pid=3169 execve guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171 /tmp/x86 net guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171 execve guuid=51241b4d-1c00-0000-e73d-e70b240d0000 pid=3364 /usr/bin/wget net send-data write-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=51241b4d-1c00-0000-e73d-e70b240d0000 pid=3364 execve guuid=b3c8995a-1c00-0000-e73d-e70b350d0000 pid=3381 /usr/bin/chmod guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=b3c8995a-1c00-0000-e73d-e70b350d0000 pid=3381 execve guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382 /tmp/x86_64 net guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382 execve guuid=dd9d8cd2-1c00-0000-e73d-e70b3c0e0000 pid=3644 /usr/bin/rm delete-file guuid=6b0bab1c-1b00-0000-e73d-e70be60a0000 pid=2790->guuid=dd9d8cd2-1c00-0000-e73d-e70b3c0e0000 pid=3644 execve e217ae65-493d-53f3-ad87-163d1acdbb8a 94.156.152.90:80 guuid=60eb181d-1b00-0000-e73d-e70be80a0000 pid=2792->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 136B guuid=29452d2f-1b00-0000-e73d-e70b030b0000 pid=2819->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=27eaa83e-1b00-0000-e73d-e70b240b0000 pid=2852->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=c98e814f-1b00-0000-e73d-e70b4d0b0000 pid=2893->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=20eef161-1b00-0000-e73d-e70b740b0000 pid=2932->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=ebcf1074-1b00-0000-e73d-e70b900b0000 pid=2960->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=0d353685-1b00-0000-e73d-e70baf0b0000 pid=2991->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 137B guuid=f3cb1e95-1b00-0000-e73d-e70bce0b0000 pid=3022->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 136B guuid=2fb618a6-1b00-0000-e73d-e70bf10b0000 pid=3057->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 136B guuid=6ac4a1b5-1b00-0000-e73d-e70b190c0000 pid=3097->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 136B guuid=a45232c6-1b00-0000-e73d-e70b440c0000 pid=3140->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba0bb5d5-1b00-0000-e73d-e70b660c0000 pid=3174 /tmp/x86 guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171->guuid=ba0bb5d5-1b00-0000-e73d-e70b660c0000 pid=3174 clone guuid=74175f11-1c00-0000-e73d-e70bc10c0000 pid=3265 /tmp/x86 guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171->guuid=74175f11-1c00-0000-e73d-e70bc10c0000 pid=3265 clone guuid=ffb3064d-1c00-0000-e73d-e70b200d0000 pid=3360 /tmp/x86 guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171->guuid=ffb3064d-1c00-0000-e73d-e70b200d0000 pid=3360 clone guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362 /tmp/x86 dns net send-data zombie guuid=68b545d5-1b00-0000-e73d-e70b630c0000 pid=3171->guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362 clone guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2090B 6272d858-80a1-5f9b-be28-4d6aceb31fbd niggabot.windy.my.id:23 guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=756d1a4d-1c00-0000-e73d-e70b230d0000 pid=3363 /tmp/x86 guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362->guuid=756d1a4d-1c00-0000-e73d-e70b230d0000 pid=3363 clone guuid=fd8fc288-1c00-0000-e73d-e70b960d0000 pid=3478 /tmp/x86 guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362->guuid=fd8fc288-1c00-0000-e73d-e70b960d0000 pid=3478 clone guuid=d8146cc4-1c00-0000-e73d-e70b120e0000 pid=3602 /tmp/x86 guuid=7b550b4d-1c00-0000-e73d-e70b220d0000 pid=3362->guuid=d8146cc4-1c00-0000-e73d-e70b120e0000 pid=3602 clone guuid=51241b4d-1c00-0000-e73d-e70b240d0000 pid=3364->e217ae65-493d-53f3-ad87-163d1acdbb8a send: 139B guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=791e1f5b-1c00-0000-e73d-e70b370d0000 pid=3383 /tmp/x86_64 guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382->guuid=791e1f5b-1c00-0000-e73d-e70b370d0000 pid=3383 clone guuid=46d6c596-1c00-0000-e73d-e70bbe0d0000 pid=3518 /tmp/x86_64 guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382->guuid=46d6c596-1c00-0000-e73d-e70bbe0d0000 pid=3518 clone guuid=e02d6fd2-1c00-0000-e73d-e70b380e0000 pid=3640 /tmp/x86_64 guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382->guuid=e02d6fd2-1c00-0000-e73d-e70b380e0000 pid=3640 clone guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641 /tmp/x86_64 dns net send-data zombie guuid=f370fa5a-1c00-0000-e73d-e70b360d0000 pid=3382->guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641 clone guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1900B guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641->6272d858-80a1-5f9b-be28-4d6aceb31fbd con guuid=771c85d2-1c00-0000-e73d-e70b3a0e0000 pid=3642 /tmp/x86_64 guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641->guuid=771c85d2-1c00-0000-e73d-e70b3a0e0000 pid=3642 clone guuid=ec122a0e-1d00-0000-e73d-e70bc40e0000 pid=3780 /tmp/x86_64 guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641->guuid=ec122a0e-1d00-0000-e73d-e70bc40e0000 pid=3780 clone guuid=f57cd949-1d00-0000-e73d-e70b2c0f0000 pid=3884 /tmp/x86_64 guuid=bec075d2-1c00-0000-e73d-e70b390e0000 pid=3641->guuid=f57cd949-1d00-0000-e73d-e70b2c0f0000 pid=3884 clone
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-12-25 19:19:38 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cadf82600085db2bd650c43d6323f2383f7696805a7cd26a2744f2f01743c8b2

(this sample)

  
Delivery method
Distributed via web download

Comments