MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fe1f6a9fa4f17f52f6dc426da7fd08547bf533c8a65a4de0ab1dda879a77dae6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: fe1f6a9fa4f17f52f6dc426da7fd08547bf533c8a65a4de0ab1dda879a77dae6
SHA3-384 hash: 5e8c47764dc59e251b757c2b5f52c4213d8f1e65d4bd8d7921adc7d34500b629f95e43bc225f72dbbf370f09f1c382aa
SHA1 hash: acaf64907b86bfe282e611809e9bd910c01edec8
MD5 hash: b94939373a9171000f7bba72876c2633
humanhash: juliet-alaska-ceiling-edward
File name:a.sh
Download: download sample
Signature Mirai
File size:987 bytes
First seen:2026-07-31 01:45:32 UTC
Last seen:2026-07-31 05:17:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:5wEREwgaTaT4aqgA8T3TXhqbME/EE2tEE8EKL5kPDEKEqxBw:1aFuu4LgA8DXAbDcDtbzsLNqHw
TLSH T12911ADAF4454290ED6039D03F174D32FB26BBFED2EB62B04D68A2563E08D55030326DD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.195.127/zero.armv7l3b520f138b30704f7a94682b10912ccbed47e33a8fe9445ab6c8ca681d3e8bb2 Mirai217-60-195-127 elf mirai
http://217.60.195.127/zero.mipse202969e703aa1cffa4932c7dfba8b667e99f8c9cc556497223f5bc08e0756ea Mirai217-60-195-127 elf mirai
http://217.60.195.127/zero.mipself6343ec28a56575486792998c0cad6e7d86747e93a97c93867af0cc4c780156c Mirai217-60-195-127 elf mirai
http://217.60.195.127/zero.armv5lf64699cfd4a393749820a7cc2ec9c0dc5be5bc4515bfd2c0c3303d083390ef52 Mirai217-60-195-127 elf mirai
http://217.60.195.127/zero.armv6lfdfee70d879c9ae74ccb8e35c59aebb21ef9e304c7d0f26b0c8dab696c7f5c93 Mirai217-60-195-127 elf mirai
http://217.60.195.127/zero.x86_6474ecb5e2241b2214f426a3de6aefdd49d3d32df47563d18eb3eaca908149cd00 Miraielf mirai ua-wget
http://217.60.195.127/zero.armv4l54ec6f6ae01bac05e426f43ae669d15c459cc5beebc329f93948e7a4feace334 Mirai217-60-195-127 elf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=9b4f40b3-1900-0000-11c8-b916e5080000 pid=2277 /usr/bin/sudo guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279 /tmp/sample.bin guuid=9b4f40b3-1900-0000-11c8-b916e5080000 pid=2277->guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279 execve guuid=6ada9ab7-1900-0000-11c8-b916e8080000 pid=2280 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=6ada9ab7-1900-0000-11c8-b916e8080000 pid=2280 execve guuid=29ccbdc0-1900-0000-11c8-b916f2080000 pid=2290 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=29ccbdc0-1900-0000-11c8-b916f2080000 pid=2290 execve guuid=5ecafbc1-1900-0000-11c8-b916f3080000 pid=2291 /usr/bin/dash guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=5ecafbc1-1900-0000-11c8-b916f3080000 pid=2291 clone guuid=e4b319c2-1900-0000-11c8-b916f4080000 pid=2292 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=e4b319c2-1900-0000-11c8-b916f4080000 pid=2292 execve guuid=6f578fc8-1900-0000-11c8-b91600090000 pid=2304 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=6f578fc8-1900-0000-11c8-b91600090000 pid=2304 execve guuid=429624c9-1900-0000-11c8-b91602090000 pid=2306 /usr/bin/dash guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=429624c9-1900-0000-11c8-b91602090000 pid=2306 clone guuid=de1931c9-1900-0000-11c8-b91603090000 pid=2307 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=de1931c9-1900-0000-11c8-b91603090000 pid=2307 execve guuid=3a55c1ce-1900-0000-11c8-b91611090000 pid=2321 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=3a55c1ce-1900-0000-11c8-b91611090000 pid=2321 execve guuid=10ee21cf-1900-0000-11c8-b91614090000 pid=2324 /usr/bin/dash guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=10ee21cf-1900-0000-11c8-b91614090000 pid=2324 clone guuid=e0dc25cf-1900-0000-11c8-b91615090000 pid=2325 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=e0dc25cf-1900-0000-11c8-b91615090000 pid=2325 execve guuid=b5c7dad3-1900-0000-11c8-b91624090000 pid=2340 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=b5c7dad3-1900-0000-11c8-b91624090000 pid=2340 execve guuid=15972cd4-1900-0000-11c8-b91625090000 pid=2341 /usr/bin/dash guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=15972cd4-1900-0000-11c8-b91625090000 pid=2341 clone guuid=e7d131d4-1900-0000-11c8-b91626090000 pid=2342 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=e7d131d4-1900-0000-11c8-b91626090000 pid=2342 execve guuid=6a92c1d8-1900-0000-11c8-b91633090000 pid=2355 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=6a92c1d8-1900-0000-11c8-b91633090000 pid=2355 execve guuid=226c28d9-1900-0000-11c8-b91635090000 pid=2357 /usr/bin/dash guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=226c28d9-1900-0000-11c8-b91635090000 pid=2357 clone guuid=d30b2fd9-1900-0000-11c8-b91636090000 pid=2358 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=d30b2fd9-1900-0000-11c8-b91636090000 pid=2358 execve guuid=316d2bdf-1900-0000-11c8-b91643090000 pid=2371 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=316d2bdf-1900-0000-11c8-b91643090000 pid=2371 execve guuid=f842a1df-1900-0000-11c8-b91644090000 pid=2372 /tmp/zero.x86_64 mprotect-exec net guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=f842a1df-1900-0000-11c8-b91644090000 pid=2372 execve guuid=3b36a8df-1900-0000-11c8-b91645090000 pid=2373 /usr/bin/wget net send-data write-file guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=3b36a8df-1900-0000-11c8-b91645090000 pid=2373 execve guuid=8e2ab4e4-1900-0000-11c8-b91654090000 pid=2388 /usr/bin/chmod guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=8e2ab4e4-1900-0000-11c8-b91654090000 pid=2388 execve guuid=3c9412e5-1900-0000-11c8-b91655090000 pid=2389 /usr/bin/dash zombie guuid=30e4c5b6-1900-0000-11c8-b916e7080000 pid=2279->guuid=3c9412e5-1900-0000-11c8-b91655090000 pid=2389 clone d2e925fc-254b-5165-9d90-3c1825679e5e 217.60.195.127:80 guuid=6ada9ab7-1900-0000-11c8-b916e8080000 pid=2280->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B guuid=e4b319c2-1900-0000-11c8-b916f4080000 pid=2292->d2e925fc-254b-5165-9d90-3c1825679e5e send: 138B guuid=de1931c9-1900-0000-11c8-b91603090000 pid=2307->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B guuid=e0dc25cf-1900-0000-11c8-b91615090000 pid=2325->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B guuid=e7d131d4-1900-0000-11c8-b91626090000 pid=2342->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B guuid=d30b2fd9-1900-0000-11c8-b91636090000 pid=2358->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f842a1df-1900-0000-11c8-b91644090000 pid=2372->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376 /tmp/zero.x86_64 net send-data zombie guuid=f842a1df-1900-0000-11c8-b91644090000 pid=2372->guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376 clone guuid=3b36a8df-1900-0000-11c8-b91645090000 pid=2373->d2e925fc-254b-5165-9d90-3c1825679e5e send: 140B guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f7c851d3-52f8-572a-9c7b-d8da31d0b740 217.60.195.127:7249 guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376->f7c851d3-52f8-572a-9c7b-d8da31d0b740 send: 7B guuid=610eb8e0-1900-0000-11c8-b9164a090000 pid=2378 /tmp/zero.x86_64 guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376->guuid=610eb8e0-1900-0000-11c8-b9164a090000 pid=2378 clone guuid=f5e2bde0-1900-0000-11c8-b9164b090000 pid=2379 /tmp/zero.x86_64 guuid=a8a39ce0-1900-0000-11c8-b91648090000 pid=2376->guuid=f5e2bde0-1900-0000-11c8-b9164b090000 pid=2379 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-07-31 01:46:31 UTC
File Type:
Text (Shell)
AV detection:
11 of 36 (30.56%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fe1f6a9fa4f17f52f6dc426da7fd08547bf533c8a65a4de0ab1dda879a77dae6

(this sample)

  
Delivery method
Distributed via web download

Comments