🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ef9dd729814f6833e41ddc99e6fcd1b1a12fe7d0d60f954335c0b4a7a56d9adc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: ef9dd729814f6833e41ddc99e6fcd1b1a12fe7d0d60f954335c0b4a7a56d9adc
SHA3-384 hash: df3a45be26aba64279b9a864e23492ec2a62e15a4788f49b336bafbd1552f22ec138782a55f17376f5ed34a1e3fc0718
SHA1 hash: eb3f11d7e9bf10604fffdb2f121df3f03af7f134
MD5 hash: f56ad74e7514e61f455a7b79aa6368bb
humanhash: bluebird-single-queen-item
File name:v.sh
Download: download sample
Signature Mirai
File size:284 bytes
First seen:2026-06-03 19:23:50 UTC
Last seen:2026-06-04 07:47:32 UTC
File type: sh
MIME type:text/plain
ssdeep 6:ebnySvygBXXQOvPBENI3gHd9XQOvPBENgHd9XQOvPBEnXPHdy:kvyLOvPBENI3g9aOvPBENg9aOvPBEXP0
TLSH T12AD0CDEE4042903554845E8EFCB53C104742E1C034711F287FC124B1E0C9D55B231A97
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://195.96.132.13/lul.arm7d241994cd6b7f0bc29cdb25f1e909de0ba8bc25c2cdd45cdc76381c951ac46c8 Miraielf mirai ua-wget
http://195.96.132.13/lul.arm1635f339c767ba9575a5c021db422a495d41d5006f46bb3c084228ade1349d4d Miraielf mirai ua-wget
http://195.96.132.13/lul.arm5cec38d757d53e6f2ba2724afd2cdb42176dd91a3251812d92f0a7c574d93d30c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
text
First seen:
2026-06-03T18:30:00Z UTC
Last seen:
2026-06-04T20:17:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=20b7a48a-1600-0000-7112-b0e9050d0000 pid=3333 /usr/bin/sudo guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338 /tmp/sample.bin guuid=20b7a48a-1600-0000-7112-b0e9050d0000 pid=3333->guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338 execve guuid=917ff28c-1600-0000-7112-b0e90c0d0000 pid=3340 /usr/bin/wget net send-data write-file guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=917ff28c-1600-0000-7112-b0e90c0d0000 pid=3340 execve guuid=42af3e9d-1600-0000-7112-b0e92e0d0000 pid=3374 /usr/bin/chmod guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=42af3e9d-1600-0000-7112-b0e92e0d0000 pid=3374 execve guuid=d3c0809d-1600-0000-7112-b0e9300d0000 pid=3376 /usr/bin/dash guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=d3c0809d-1600-0000-7112-b0e9300d0000 pid=3376 clone guuid=e0b7169e-1600-0000-7112-b0e9340d0000 pid=3380 /usr/bin/wget net send-data write-file guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=e0b7169e-1600-0000-7112-b0e9340d0000 pid=3380 execve guuid=bb585eab-1600-0000-7112-b0e95f0d0000 pid=3423 /usr/bin/chmod guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=bb585eab-1600-0000-7112-b0e95f0d0000 pid=3423 execve guuid=2baf93ab-1600-0000-7112-b0e9600d0000 pid=3424 /usr/bin/dash guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=2baf93ab-1600-0000-7112-b0e9600d0000 pid=3424 clone guuid=72b515ac-1600-0000-7112-b0e9650d0000 pid=3429 /usr/bin/wget net send-data write-file guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=72b515ac-1600-0000-7112-b0e9650d0000 pid=3429 execve guuid=d985c2ba-1600-0000-7112-b0e99d0d0000 pid=3485 /usr/bin/chmod guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=d985c2ba-1600-0000-7112-b0e99d0d0000 pid=3485 execve guuid=8f85f8ba-1600-0000-7112-b0e99f0d0000 pid=3487 /usr/bin/dash guuid=afc4838c-1600-0000-7112-b0e90a0d0000 pid=3338->guuid=8f85f8ba-1600-0000-7112-b0e99f0d0000 pid=3487 clone 64fe253b-db51-504c-837e-9f888b7c378c 195.96.132.13:80 guuid=917ff28c-1600-0000-7112-b0e90c0d0000 pid=3340->64fe253b-db51-504c-837e-9f888b7c378c send: 136B guuid=e0b7169e-1600-0000-7112-b0e9340d0000 pid=3380->64fe253b-db51-504c-837e-9f888b7c378c send: 135B guuid=72b515ac-1600-0000-7112-b0e9650d0000 pid=3429->64fe253b-db51-504c-837e-9f888b7c378c send: 136B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-03 19:24:29 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ef9dd729814f6833e41ddc99e6fcd1b1a12fe7d0d60f954335c0b4a7a56d9adc

(this sample)

  
Delivery method
Distributed via web download

Comments