MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd94dbbff5b06684c9366467bf6030abe96ad0e6d232d31240e5e23e6ba1f6c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: fd94dbbff5b06684c9366467bf6030abe96ad0e6d232d31240e5e23e6ba1f6c6
SHA3-384 hash: 49aa2fbd594a198c51bd71d597683cb350389162ee1c40696e02dc83959e0ad2bafed0d897f7967ee290d6b072b62dc3
SHA1 hash: b55232ceb9cb1f92a3e2aef8cb83cee379c85560
MD5 hash: 9190d1f66f25ab4841c28978c7559c01
humanhash: oxygen-red-mountain-march
File name:wget.sh
Download: download sample
Signature Mirai
File size:914 bytes
First seen:2026-01-26 18:18:05 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:yw1YhalN9NIl5iCa0LKvNgOF9JM/O7tjLSOZhNtYif2G9aftVv:BzljNI7/KeI7B5LlbNtYiO0afLv
TLSH T1D81198DD2591A36E06899D08FC710C4EB108C1C9A4F52F74ED49587E89D77057425FE7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://147.135.3.192/bins/arm1396d4e1232caaf2f1a4ef6cfb0f6d1e1be161ffde737df4b1dcb2de7977e68f Miraiarm elf geofenced mirai opendir ua-wget USA
http://147.135.3.192/bins/arm518b715dbe9d54e5aacaa0ff45c569ec651e9cd8f618195a104317b0dc2f54f70 Miraiarm elf geofenced mirai opendir ua-wget USA
http://147.135.3.192/bins/arm6a9477a12b3f266a05f62e5eff528e8162e2cd36e0e0b891d5ad088d33c4b79d1 Miraiarm elf geofenced mirai opendir ua-wget USA
http://147.135.3.192/bins/arm793b9307448b4b74889840101b77336a5153e5f07c13d368445f29a881079bd40 Miraiarm elf geofenced mirai opendir ua-wget USA
http://147.135.3.192/bins/m68k2d3089c3fe4d0a894c8a526545aa53b1d1271b411be14f5c665df690d173a916 Miraielf geofenced m68k mirai opendir ua-wget USA
http://147.135.3.192/bins/mipsd02346db29ea7d2673b5a77f4db60be737f8dfef0201bdbeaf2d57076190c97f Miraielf geofenced mips mirai opendir ua-wget USA
http://147.135.3.192/bins/mpsln/an/ageofenced ua-wget USA
http://147.135.3.192/bins/ppc717afd051e5da8bda3f26ebb733732c8f672db20b544aab2d23e924dcf9f596a Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://147.135.3.192/bins/sh4ec1c1f0f7bfc129b1f6ce18609f137795b9d332d91c2d6adce581081dffbbd25 Miraielf geofenced mirai opendir SuperH ua-wget USA
http://147.135.3.192/bins/spcb44cb571bd84e3a4b06c7260a8bd68c98e647d4cb68c3629f2c7263e88126a7d Miraielf geofenced mirai opendir sparc ua-wget USA
http://147.135.3.192/bins/x863ca32132130a999b589e3da4dfb47ddc44527b8e6ee15176bf6b9354cd62ae67 Miraielf geofenced mirai opendir ua-wget USA x86
http://147.135.3.192/bins/x86_64239d22c2de73458f22e29788e84a4405791d7b744142568949f0e9d2f098a4cd Miraielf geofenced mirai opendir ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-25T10:02:00Z UTC
Last seen:
2026-01-27T21:39:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=0aa2d787-1900-0000-3005-99c11d0a0000 pid=2589 /usr/bin/sudo guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599 /tmp/sample.bin guuid=0aa2d787-1900-0000-3005-99c11d0a0000 pid=2589->guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599 execve guuid=37453e8b-1900-0000-3005-99c1290a0000 pid=2601 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=37453e8b-1900-0000-3005-99c1290a0000 pid=2601 execve guuid=f74de0a9-1900-0000-3005-99c17c0a0000 pid=2684 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=f74de0a9-1900-0000-3005-99c17c0a0000 pid=2684 execve guuid=c44e4baa-1900-0000-3005-99c17e0a0000 pid=2686 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=c44e4baa-1900-0000-3005-99c17e0a0000 pid=2686 clone guuid=ee83d9ac-1900-0000-3005-99c1850a0000 pid=2693 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=ee83d9ac-1900-0000-3005-99c1850a0000 pid=2693 execve guuid=0c099cc3-1900-0000-3005-99c1b90a0000 pid=2745 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=0c099cc3-1900-0000-3005-99c1b90a0000 pid=2745 execve guuid=5c6ef9c3-1900-0000-3005-99c1bb0a0000 pid=2747 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=5c6ef9c3-1900-0000-3005-99c1bb0a0000 pid=2747 clone guuid=515decc4-1900-0000-3005-99c1c00a0000 pid=2752 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=515decc4-1900-0000-3005-99c1c00a0000 pid=2752 execve guuid=078893e1-1900-0000-3005-99c1e80a0000 pid=2792 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=078893e1-1900-0000-3005-99c1e80a0000 pid=2792 execve guuid=c00606e2-1900-0000-3005-99c1e90a0000 pid=2793 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=c00606e2-1900-0000-3005-99c1e90a0000 pid=2793 clone guuid=fd69f5e3-1900-0000-3005-99c1ee0a0000 pid=2798 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=fd69f5e3-1900-0000-3005-99c1ee0a0000 pid=2798 execve guuid=c3440906-1a00-0000-3005-99c1280b0000 pid=2856 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=c3440906-1a00-0000-3005-99c1280b0000 pid=2856 execve guuid=41f56906-1a00-0000-3005-99c12a0b0000 pid=2858 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=41f56906-1a00-0000-3005-99c12a0b0000 pid=2858 clone guuid=12725107-1a00-0000-3005-99c12e0b0000 pid=2862 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=12725107-1a00-0000-3005-99c12e0b0000 pid=2862 execve guuid=eb399a23-1a00-0000-3005-99c16d0b0000 pid=2925 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=eb399a23-1a00-0000-3005-99c16d0b0000 pid=2925 execve guuid=41ede123-1a00-0000-3005-99c16f0b0000 pid=2927 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=41ede123-1a00-0000-3005-99c16f0b0000 pid=2927 clone guuid=74c88024-1a00-0000-3005-99c1720b0000 pid=2930 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=74c88024-1a00-0000-3005-99c1720b0000 pid=2930 execve guuid=d3951b43-1a00-0000-3005-99c19d0b0000 pid=2973 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=d3951b43-1a00-0000-3005-99c19d0b0000 pid=2973 execve guuid=0db69543-1a00-0000-3005-99c19f0b0000 pid=2975 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=0db69543-1a00-0000-3005-99c19f0b0000 pid=2975 clone guuid=f5cd3c44-1a00-0000-3005-99c1a30b0000 pid=2979 /usr/bin/wget net send-data guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=f5cd3c44-1a00-0000-3005-99c1a30b0000 pid=2979 execve guuid=e2eb5051-1a00-0000-3005-99c1b80b0000 pid=3000 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=e2eb5051-1a00-0000-3005-99c1b80b0000 pid=3000 execve guuid=b09bdc51-1a00-0000-3005-99c1bb0b0000 pid=3003 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=b09bdc51-1a00-0000-3005-99c1bb0b0000 pid=3003 clone guuid=3f2cf253-1a00-0000-3005-99c1c00b0000 pid=3008 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=3f2cf253-1a00-0000-3005-99c1c00b0000 pid=3008 execve guuid=23336b70-1a00-0000-3005-99c1010c0000 pid=3073 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=23336b70-1a00-0000-3005-99c1010c0000 pid=3073 execve guuid=3ee7c670-1a00-0000-3005-99c1020c0000 pid=3074 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=3ee7c670-1a00-0000-3005-99c1020c0000 pid=3074 clone guuid=82068a71-1a00-0000-3005-99c1060c0000 pid=3078 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=82068a71-1a00-0000-3005-99c1060c0000 pid=3078 execve guuid=b528648f-1a00-0000-3005-99c1520c0000 pid=3154 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=b528648f-1a00-0000-3005-99c1520c0000 pid=3154 execve guuid=dbbaab8f-1a00-0000-3005-99c1540c0000 pid=3156 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=dbbaab8f-1a00-0000-3005-99c1540c0000 pid=3156 clone guuid=c2bc5b90-1a00-0000-3005-99c1580c0000 pid=3160 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=c2bc5b90-1a00-0000-3005-99c1580c0000 pid=3160 execve guuid=99a614ad-1a00-0000-3005-99c18f0c0000 pid=3215 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=99a614ad-1a00-0000-3005-99c18f0c0000 pid=3215 execve guuid=b85e80ad-1a00-0000-3005-99c1910c0000 pid=3217 /usr/bin/bash guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=b85e80ad-1a00-0000-3005-99c1910c0000 pid=3217 clone guuid=ea3c5cae-1a00-0000-3005-99c1940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=ea3c5cae-1a00-0000-3005-99c1940c0000 pid=3220 execve guuid=0cbc64cb-1a00-0000-3005-99c1ae0c0000 pid=3246 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=0cbc64cb-1a00-0000-3005-99c1ae0c0000 pid=3246 execve guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247 /home/sandbox/x86 net guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247 execve guuid=0a5e6643-1b00-0000-3005-99c14d0d0000 pid=3405 /usr/bin/wget net send-data write-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=0a5e6643-1b00-0000-3005-99c14d0d0000 pid=3405 execve guuid=600c2861-1b00-0000-3005-99c1890d0000 pid=3465 /usr/bin/chmod guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=600c2861-1b00-0000-3005-99c1890d0000 pid=3465 execve guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467 /home/sandbox/x86_64 net guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467 execve guuid=c3f35dd9-1b00-0000-3005-99c1880e0000 pid=3720 /usr/bin/rm delete-file guuid=0ee1cc8a-1900-0000-3005-99c1270a0000 pid=2599->guuid=c3f35dd9-1b00-0000-3005-99c1880e0000 pid=3720 execve aa53e2c3-834a-572c-afda-3a782093cafd 147.135.3.192:80 guuid=37453e8b-1900-0000-3005-99c1290a0000 pid=2601->aa53e2c3-834a-572c-afda-3a782093cafd send: 136B guuid=ee83d9ac-1900-0000-3005-99c1850a0000 pid=2693->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=515decc4-1900-0000-3005-99c1c00a0000 pid=2752->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=fd69f5e3-1900-0000-3005-99c1ee0a0000 pid=2798->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=12725107-1a00-0000-3005-99c12e0b0000 pid=2862->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=74c88024-1a00-0000-3005-99c1720b0000 pid=2930->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=f5cd3c44-1a00-0000-3005-99c1a30b0000 pid=2979->aa53e2c3-834a-572c-afda-3a782093cafd send: 137B guuid=3f2cf253-1a00-0000-3005-99c1c00b0000 pid=3008->aa53e2c3-834a-572c-afda-3a782093cafd send: 136B guuid=82068a71-1a00-0000-3005-99c1060c0000 pid=3078->aa53e2c3-834a-572c-afda-3a782093cafd send: 136B guuid=c2bc5b90-1a00-0000-3005-99c1580c0000 pid=3160->aa53e2c3-834a-572c-afda-3a782093cafd send: 136B guuid=ea3c5cae-1a00-0000-3005-99c1940c0000 pid=3220->aa53e2c3-834a-572c-afda-3a782093cafd send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f4d2f8cb-1a00-0000-3005-99c1b10c0000 pid=3249 /home/sandbox/x86 guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247->guuid=f4d2f8cb-1a00-0000-3005-99c1b10c0000 pid=3249 clone guuid=345fa407-1b00-0000-3005-99c1f10c0000 pid=3313 /home/sandbox/x86 guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247->guuid=345fa407-1b00-0000-3005-99c1f10c0000 pid=3313 clone guuid=0f854f43-1b00-0000-3005-99c14a0d0000 pid=3402 /home/sandbox/x86 guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247->guuid=0f854f43-1b00-0000-3005-99c14a0d0000 pid=3402 clone guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403 /home/sandbox/x86 net send-data zombie guuid=4857b8cb-1a00-0000-3005-99c1af0c0000 pid=3247->guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403 clone guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 34db9d5e-bfcd-52fb-9c64-4aec081654cf 147.135.3.192:1999 guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403->34db9d5e-bfcd-52fb-9c64-4aec081654cf send: 168B guuid=ab486643-1b00-0000-3005-99c14c0d0000 pid=3404 /home/sandbox/x86 guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403->guuid=ab486643-1b00-0000-3005-99c14c0d0000 pid=3404 clone guuid=dcb50d7f-1b00-0000-3005-99c1d20d0000 pid=3538 /home/sandbox/x86 guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403->guuid=dcb50d7f-1b00-0000-3005-99c1d20d0000 pid=3538 clone guuid=cc10b9ba-1b00-0000-3005-99c1450e0000 pid=3653 /home/sandbox/x86 guuid=31985643-1b00-0000-3005-99c14b0d0000 pid=3403->guuid=cc10b9ba-1b00-0000-3005-99c1450e0000 pid=3653 clone guuid=0a5e6643-1b00-0000-3005-99c14d0d0000 pid=3405->aa53e2c3-834a-572c-afda-3a782093cafd send: 139B guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=666cee61-1b00-0000-3005-99c18c0d0000 pid=3468 /home/sandbox/x86_64 guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467->guuid=666cee61-1b00-0000-3005-99c18c0d0000 pid=3468 clone guuid=9d07949d-1b00-0000-3005-99c1010e0000 pid=3585 /home/sandbox/x86_64 guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467->guuid=9d07949d-1b00-0000-3005-99c1010e0000 pid=3585 clone guuid=e49144d9-1b00-0000-3005-99c1860e0000 pid=3718 /home/sandbox/x86_64 zombie guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467->guuid=e49144d9-1b00-0000-3005-99c1860e0000 pid=3718 clone guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719 /home/sandbox/x86_64 net send-data zombie guuid=888fb261-1b00-0000-3005-99c18b0d0000 pid=3467->guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719 clone guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719->34db9d5e-bfcd-52fb-9c64-4aec081654cf send: 242B guuid=730e92d9-1b00-0000-3005-99c1890e0000 pid=3721 /home/sandbox/x86_64 guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719->guuid=730e92d9-1b00-0000-3005-99c1890e0000 pid=3721 clone guuid=dde13715-1c00-0000-3005-99c12c0f0000 pid=3884 /home/sandbox/x86_64 guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719->guuid=dde13715-1c00-0000-3005-99c12c0f0000 pid=3884 clone guuid=0a9ddb50-1c00-0000-3005-99c1f10f0000 pid=4081 /home/sandbox/x86_64 guuid=690e4ad9-1b00-0000-3005-99c1870e0000 pid=3719->guuid=0a9ddb50-1c00-0000-3005-99c1f10f0000 pid=4081 clone
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-01-25 13:26:05 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fd94dbbff5b06684c9366467bf6030abe96ad0e6d232d31240e5e23e6ba1f6c6

(this sample)

Comments