MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc0b0ba344048bac47a4928efc1b87046f12c85656224096b637b8a6e9d59c31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: dc0b0ba344048bac47a4928efc1b87046f12c85656224096b637b8a6e9d59c31
SHA3-384 hash: cde97f86322d8fec416fafaf7c2491c51dca494b88954a61e7032671bcaf9192d5f9ca8a50e7af8513ba99bea915dd84
SHA1 hash: 6e45d08f1fdcc49a95fdc2218c07e421c644fc86
MD5 hash: a2913a2ccbe45c273287dd285c0e54e1
humanhash: blue-nine-failed-autumn
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'845 bytes
First seen:2026-02-12 06:30:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:A/C/m/I/2/R/3i/Q/w1H/R/gT/N/HS/E/O/A/2/l/6/M/So7Q/L/Pi/6/i/d/u/o:GMQOg13sWw1f1gbx86YGgJkCSnTUksBZ
TLSH T1DA31D68E70B49B69C5CCEF01B0E58AC87717F590F2B5C632FD421E6AA0D9D543819A3A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://34.107.120.7/iran.x86_640b86883c6e07f93c2fc256aae323340bffc6cc0b9cb753f361831b01d2c3183b Miraielf ua-wget
http://34.107.120.7/iran.aarch648bc0a92bf66caf01130502dd61f9de4424f152aadd4b3c58b1cfcda4d8c9ff72 Miraielf mirai ua-wget
http://34.107.120.7/iran.m68k597d8bc2e54eeed35c57970686e1b96a83814e6937d4c05da0cdd3f3c3139815 Miraielf mirai ua-wget
http://34.107.120.7/iran.mipsad9dbf2200d4b998f20540d08b5d8f0b4a2f3e8938efa20e1663a6e7648557df Miraielf mirai ua-wget
http://34.107.120.7/iran.mipsel07e5ddab4f8f4aa4c80c0e5aa275269e2394a91436d052e1f2e576d2297c9570 Miraielf ua-wget
http://34.107.120.7/iran.powerpc096a6b15204ce9ced41f97e4dae2c6837a1907e8ccddfbe80e914de49f08bf9a Miraielf ua-wget
http://34.107.120.7/iran.sparce6a8843d347dd57213f4b032b2cdc64f42a853120b78174d0704afb5246cc69e Miraielf mirai ua-wget
http://34.107.120.7/iran.sh4c9e26efcaafe9ce1dc2681a463ada5c8cc94839227c61d018be7fa0b5dff5170 Miraielf mirai ua-wget
http://34.107.120.7/iran.arcf0a0c9e3741457cafafd59cb2b675834b58584ac7c28d4d121b29701a52b57cf Miraielf mirai ua-wget
http://34.107.120.7/iran.i486692d565c13e6fc343860452caa828b402168d6f8dc4efbb81e289f469f5c6b02 Miraielf mirai ua-wget
http://34.107.120.7/iran.armv4ldf615a805418129319ddafe0e720642309762546cbc2fac69db279bccd8dc4fe Miraielf ua-wget
http://34.107.120.7/iran.armv5lac2df5d9e7e1e117d3f8a1ccecd1b8d9fa5e90322ac161b08f40be76537910cf Miraielf mirai ua-wget
http://34.107.120.7/iran.armv6l659a0bff891c385f87965e94700bce2cb5adf29dd2d5d52ac9db8d081535d250 Miraielf mirai ua-wget
http://34.107.120.7/iran.armv7la6cadd3627a088f1a80c557edfc6fbece78ec246d1c01b717ce8e5b8693db8c2 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
27
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-02-12T03:37:00Z UTC
Last seen:
2026-02-12T03:37:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=693e7176-1c00-0000-8a91-04476e090000 pid=2414 /usr/bin/sudo guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418 /tmp/sample.bin guuid=693e7176-1c00-0000-8a91-04476e090000 pid=2414->guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418 execve guuid=371e3979-1c00-0000-8a91-044773090000 pid=2419 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=371e3979-1c00-0000-8a91-044773090000 pid=2419 execve guuid=a592aa7c-1c00-0000-8a91-04477d090000 pid=2429 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=a592aa7c-1c00-0000-8a91-04477d090000 pid=2429 execve guuid=c1afe77c-1c00-0000-8a91-04477e090000 pid=2430 /home/sandbox/iran.x86_64 mprotect-exec guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=c1afe77c-1c00-0000-8a91-04477e090000 pid=2430 execve guuid=fa959e7d-1c00-0000-8a91-044782090000 pid=2434 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=fa959e7d-1c00-0000-8a91-044782090000 pid=2434 execve guuid=07e26a80-1c00-0000-8a91-04478a090000 pid=2442 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=07e26a80-1c00-0000-8a91-04478a090000 pid=2442 execve guuid=d957ae80-1c00-0000-8a91-04478c090000 pid=2444 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=d957ae80-1c00-0000-8a91-04478c090000 pid=2444 clone guuid=ea2a7081-1c00-0000-8a91-044790090000 pid=2448 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=ea2a7081-1c00-0000-8a91-044790090000 pid=2448 execve guuid=b2d58d85-1c00-0000-8a91-044799090000 pid=2457 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=b2d58d85-1c00-0000-8a91-044799090000 pid=2457 execve guuid=791bdd85-1c00-0000-8a91-04479a090000 pid=2458 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=791bdd85-1c00-0000-8a91-04479a090000 pid=2458 clone guuid=40189986-1c00-0000-8a91-04479c090000 pid=2460 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=40189986-1c00-0000-8a91-04479c090000 pid=2460 execve guuid=95449a8a-1c00-0000-8a91-0447a4090000 pid=2468 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=95449a8a-1c00-0000-8a91-0447a4090000 pid=2468 execve guuid=9895cf8a-1c00-0000-8a91-0447a6090000 pid=2470 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=9895cf8a-1c00-0000-8a91-0447a6090000 pid=2470 clone guuid=5b4a4f8b-1c00-0000-8a91-0447a9090000 pid=2473 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=5b4a4f8b-1c00-0000-8a91-0447a9090000 pid=2473 execve guuid=d26c808e-1c00-0000-8a91-0447b1090000 pid=2481 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=d26c808e-1c00-0000-8a91-0447b1090000 pid=2481 execve guuid=5f6ad28e-1c00-0000-8a91-0447b3090000 pid=2483 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=5f6ad28e-1c00-0000-8a91-0447b3090000 pid=2483 clone guuid=fd00568f-1c00-0000-8a91-0447b7090000 pid=2487 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=fd00568f-1c00-0000-8a91-0447b7090000 pid=2487 execve guuid=deac9492-1c00-0000-8a91-0447c2090000 pid=2498 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=deac9492-1c00-0000-8a91-0447c2090000 pid=2498 execve guuid=5952df92-1c00-0000-8a91-0447c4090000 pid=2500 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=5952df92-1c00-0000-8a91-0447c4090000 pid=2500 clone guuid=ab097693-1c00-0000-8a91-0447c7090000 pid=2503 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=ab097693-1c00-0000-8a91-0447c7090000 pid=2503 execve guuid=eeb9a395-1c00-0000-8a91-0447cc090000 pid=2508 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=eeb9a395-1c00-0000-8a91-0447cc090000 pid=2508 execve guuid=6c28e995-1c00-0000-8a91-0447cd090000 pid=2509 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=6c28e995-1c00-0000-8a91-0447cd090000 pid=2509 clone guuid=ecf47596-1c00-0000-8a91-0447d1090000 pid=2513 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=ecf47596-1c00-0000-8a91-0447d1090000 pid=2513 execve guuid=9bad5799-1c00-0000-8a91-0447db090000 pid=2523 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=9bad5799-1c00-0000-8a91-0447db090000 pid=2523 execve guuid=761aa799-1c00-0000-8a91-0447dc090000 pid=2524 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=761aa799-1c00-0000-8a91-0447dc090000 pid=2524 clone guuid=d989559a-1c00-0000-8a91-0447df090000 pid=2527 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=d989559a-1c00-0000-8a91-0447df090000 pid=2527 execve guuid=3ede809d-1c00-0000-8a91-0447e6090000 pid=2534 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=3ede809d-1c00-0000-8a91-0447e6090000 pid=2534 execve guuid=ab0abc9d-1c00-0000-8a91-0447e8090000 pid=2536 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=ab0abc9d-1c00-0000-8a91-0447e8090000 pid=2536 clone guuid=c718789e-1c00-0000-8a91-0447ec090000 pid=2540 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=c718789e-1c00-0000-8a91-0447ec090000 pid=2540 execve guuid=c4b2d1a0-1c00-0000-8a91-0447ef090000 pid=2543 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=c4b2d1a0-1c00-0000-8a91-0447ef090000 pid=2543 execve guuid=e2001aa1-1c00-0000-8a91-0447f0090000 pid=2544 /home/sandbox/iran.i486 guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=e2001aa1-1c00-0000-8a91-0447f0090000 pid=2544 execve guuid=f40270a1-1c00-0000-8a91-0447f2090000 pid=2546 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=f40270a1-1c00-0000-8a91-0447f2090000 pid=2546 execve guuid=744760a4-1c00-0000-8a91-0447fc090000 pid=2556 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=744760a4-1c00-0000-8a91-0447fc090000 pid=2556 execve guuid=552bada4-1c00-0000-8a91-0447fe090000 pid=2558 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=552bada4-1c00-0000-8a91-0447fe090000 pid=2558 clone guuid=0cae5ba5-1c00-0000-8a91-0447010a0000 pid=2561 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=0cae5ba5-1c00-0000-8a91-0447010a0000 pid=2561 execve guuid=4d0e96a8-1c00-0000-8a91-0447070a0000 pid=2567 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=4d0e96a8-1c00-0000-8a91-0447070a0000 pid=2567 execve guuid=a846dfa8-1c00-0000-8a91-0447080a0000 pid=2568 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=a846dfa8-1c00-0000-8a91-0447080a0000 pid=2568 clone guuid=3aeb6ca9-1c00-0000-8a91-04470b0a0000 pid=2571 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=3aeb6ca9-1c00-0000-8a91-04470b0a0000 pid=2571 execve guuid=e24b57ac-1c00-0000-8a91-0447120a0000 pid=2578 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=e24b57ac-1c00-0000-8a91-0447120a0000 pid=2578 execve guuid=6024c0ac-1c00-0000-8a91-0447130a0000 pid=2579 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=6024c0ac-1c00-0000-8a91-0447130a0000 pid=2579 clone guuid=245773ad-1c00-0000-8a91-0447150a0000 pid=2581 /usr/bin/wget net send-data write-file guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=245773ad-1c00-0000-8a91-0447150a0000 pid=2581 execve guuid=4a9d29b0-1c00-0000-8a91-04471d0a0000 pid=2589 /usr/bin/chmod guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=4a9d29b0-1c00-0000-8a91-04471d0a0000 pid=2589 execve guuid=a0758ab0-1c00-0000-8a91-04471f0a0000 pid=2591 /usr/bin/dash guuid=eceeea78-1c00-0000-8a91-044772090000 pid=2418->guuid=a0758ab0-1c00-0000-8a91-04471f0a0000 pid=2591 clone 992a4a77-fc40-5bbb-b213-ba15d9cb2788 34.107.120.7:80 guuid=371e3979-1c00-0000-8a91-044773090000 pid=2419->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B guuid=9daf987d-1c00-0000-8a91-044781090000 pid=2433 /home/sandbox/iran.x86_64 zombie guuid=c1afe77c-1c00-0000-8a91-04477e090000 pid=2430->guuid=9daf987d-1c00-0000-8a91-044781090000 pid=2433 clone guuid=c9eea27d-1c00-0000-8a91-044783090000 pid=2435 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=9daf987d-1c00-0000-8a91-044781090000 pid=2433->guuid=c9eea27d-1c00-0000-8a91-044783090000 pid=2435 clone guuid=fa959e7d-1c00-0000-8a91-044782090000 pid=2434->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 139B 2381a04b-9bd7-5d23-95d8-0851edd30435 34.107.120.7:1150 guuid=c9eea27d-1c00-0000-8a91-044783090000 pid=2435->2381a04b-9bd7-5d23-95d8-0851edd30435 send: 420B guuid=ea2a7081-1c00-0000-8a91-044790090000 pid=2448->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 136B guuid=40189986-1c00-0000-8a91-04479c090000 pid=2460->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 136B guuid=5b4a4f8b-1c00-0000-8a91-0447a9090000 pid=2473->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B guuid=fd00568f-1c00-0000-8a91-0447b7090000 pid=2487->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 139B guuid=ab097693-1c00-0000-8a91-0447c7090000 pid=2503->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 137B guuid=ecf47596-1c00-0000-8a91-0447d1090000 pid=2513->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 135B guuid=d989559a-1c00-0000-8a91-0447df090000 pid=2527->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 135B guuid=c718789e-1c00-0000-8a91-0447ec090000 pid=2540->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 136B guuid=315a68a1-1c00-0000-8a91-0447f1090000 pid=2545 /home/sandbox/iran.i486 guuid=e2001aa1-1c00-0000-8a91-0447f0090000 pid=2544->guuid=315a68a1-1c00-0000-8a91-0447f1090000 pid=2545 clone guuid=13fa71a1-1c00-0000-8a91-0447f3090000 pid=2547 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=315a68a1-1c00-0000-8a91-0447f1090000 pid=2545->guuid=13fa71a1-1c00-0000-8a91-0447f3090000 pid=2547 clone guuid=f40270a1-1c00-0000-8a91-0447f2090000 pid=2546->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B guuid=13fa71a1-1c00-0000-8a91-0447f3090000 pid=2547->2381a04b-9bd7-5d23-95d8-0851edd30435 send: 1121B guuid=0cae5ba5-1c00-0000-8a91-0447010a0000 pid=2561->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B guuid=3aeb6ca9-1c00-0000-8a91-04470b0a0000 pid=2571->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B guuid=245773ad-1c00-0000-8a91-0447150a0000 pid=2581->992a4a77-fc40-5bbb-b213-ba15d9cb2788 send: 138B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-11 09:29:14 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dc0b0ba344048bac47a4928efc1b87046f12c85656224096b637b8a6e9d59c31

(this sample)

  
Delivery method
Distributed via web download

Comments