MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0452e5f363cfc17bf436564ac2cf30e71f7ee30d2d5d66768482c45f8a734d12. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 0452e5f363cfc17bf436564ac2cf30e71f7ee30d2d5d66768482c45f8a734d12
SHA3-384 hash: 7ab77e615701fa7788eade2c0c6cf7c368feb018ca82148a302444ddea6ff6669684c87f43ce758747766c1346c41949
SHA1 hash: d720d71aeed228b3f81e75d3d04c050bda260b87
MD5 hash: 5c152227f91af4ec7999c4489acdfd86
humanhash: green-alpha-violet-eight
File name:ok
Download: download sample
Signature Mirai
File size:1'608 bytes
First seen:2026-06-08 01:46:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:9BsVz+YhcHf0I4OGOt1ydTnp9ZaBEky5dQVNn2:HsVz+YhxxPs85+8
TLSH T1C93175EB0F197ACD5104DD7573A53548D090A7DF248FE794FB884C7AA2C854C3259F0A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/651f02n/an/aelf ua-wget
http://45.205.1.59/b1e0edn/an/aelf ua-wget
http://45.205.1.59/89d453n/an/aelf ua-wget
http://45.205.1.59/3aad49n/an/aelf ua-wget
http://45.205.1.59/87b3cdn/an/aelf ua-wget
http://45.205.1.59/c93d53n/an/aelf ua-wget
http://45.205.1.59/5c7dfen/an/aelf ua-wget
http://45.205.1.59/88c338n/an/aelf ua-wget
http://45.205.1.59/fa4204n/an/aelf ua-wget
http://45.205.1.59/078541n/an/aelf ua-wget
http://45.205.1.59/98be53n/an/aelf ua-wget
http://45.205.1.59/cb8729n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-07T22:51:00Z UTC
Last seen:
2026-06-09T20:25:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=245bbe5a-2100-0000-8d4e-09f20a070000 pid=1802 /usr/bin/sudo guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808 /tmp/sample.bin guuid=245bbe5a-2100-0000-8d4e-09f20a070000 pid=1802->guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808 execve guuid=4dfeb55d-2100-0000-8d4e-09f211070000 pid=1809 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=4dfeb55d-2100-0000-8d4e-09f211070000 pid=1809 execve guuid=4a98977b-2100-0000-8d4e-09f259070000 pid=1881 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=4a98977b-2100-0000-8d4e-09f259070000 pid=1881 execve guuid=df33279c-2100-0000-8d4e-09f2a1070000 pid=1953 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=df33279c-2100-0000-8d4e-09f2a1070000 pid=1953 execve guuid=52c87a9c-2100-0000-8d4e-09f2a2070000 pid=1954 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=52c87a9c-2100-0000-8d4e-09f2a2070000 pid=1954 clone guuid=e4a1c09c-2100-0000-8d4e-09f2a5070000 pid=1957 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=e4a1c09c-2100-0000-8d4e-09f2a5070000 pid=1957 execve guuid=9e2d129d-2100-0000-8d4e-09f2a7070000 pid=1959 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=9e2d129d-2100-0000-8d4e-09f2a7070000 pid=1959 execve guuid=3fd5639d-2100-0000-8d4e-09f2a9070000 pid=1961 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=3fd5639d-2100-0000-8d4e-09f2a9070000 pid=1961 execve guuid=92eca6b8-2100-0000-8d4e-09f2d7070000 pid=2007 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=92eca6b8-2100-0000-8d4e-09f2d7070000 pid=2007 execve guuid=47afede1-2100-0000-8d4e-09f2e9070000 pid=2025 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=47afede1-2100-0000-8d4e-09f2e9070000 pid=2025 execve guuid=a2d943e2-2100-0000-8d4e-09f2ea070000 pid=2026 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=a2d943e2-2100-0000-8d4e-09f2ea070000 pid=2026 clone guuid=cf059fe2-2100-0000-8d4e-09f2ec070000 pid=2028 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=cf059fe2-2100-0000-8d4e-09f2ec070000 pid=2028 execve guuid=22b1ece2-2100-0000-8d4e-09f2ed070000 pid=2029 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=22b1ece2-2100-0000-8d4e-09f2ed070000 pid=2029 execve guuid=7e8336e3-2100-0000-8d4e-09f2ee070000 pid=2030 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=7e8336e3-2100-0000-8d4e-09f2ee070000 pid=2030 execve guuid=b2a9cbfe-2100-0000-8d4e-09f223080000 pid=2083 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=b2a9cbfe-2100-0000-8d4e-09f223080000 pid=2083 execve guuid=e46a3d1e-2200-0000-8d4e-09f26c080000 pid=2156 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=e46a3d1e-2200-0000-8d4e-09f26c080000 pid=2156 execve guuid=f846a01e-2200-0000-8d4e-09f26e080000 pid=2158 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=f846a01e-2200-0000-8d4e-09f26e080000 pid=2158 clone guuid=ed6cd81e-2200-0000-8d4e-09f271080000 pid=2161 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=ed6cd81e-2200-0000-8d4e-09f271080000 pid=2161 execve guuid=89c71f1f-2200-0000-8d4e-09f273080000 pid=2163 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=89c71f1f-2200-0000-8d4e-09f273080000 pid=2163 execve guuid=325e611f-2200-0000-8d4e-09f275080000 pid=2165 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=325e611f-2200-0000-8d4e-09f275080000 pid=2165 execve guuid=3a14923a-2200-0000-8d4e-09f2d7080000 pid=2263 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=3a14923a-2200-0000-8d4e-09f2d7080000 pid=2263 execve guuid=7606a958-2200-0000-8d4e-09f21c090000 pid=2332 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=7606a958-2200-0000-8d4e-09f21c090000 pid=2332 execve guuid=29c21859-2200-0000-8d4e-09f21d090000 pid=2333 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=29c21859-2200-0000-8d4e-09f21d090000 pid=2333 clone guuid=5c219d59-2200-0000-8d4e-09f21f090000 pid=2335 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=5c219d59-2200-0000-8d4e-09f21f090000 pid=2335 execve guuid=9d0d1d5a-2200-0000-8d4e-09f220090000 pid=2336 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=9d0d1d5a-2200-0000-8d4e-09f220090000 pid=2336 execve guuid=f0377d5a-2200-0000-8d4e-09f222090000 pid=2338 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=f0377d5a-2200-0000-8d4e-09f222090000 pid=2338 execve guuid=a4346376-2200-0000-8d4e-09f256090000 pid=2390 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=a4346376-2200-0000-8d4e-09f256090000 pid=2390 execve guuid=59e99593-2200-0000-8d4e-09f27a090000 pid=2426 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=59e99593-2200-0000-8d4e-09f27a090000 pid=2426 execve guuid=94193794-2200-0000-8d4e-09f27b090000 pid=2427 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=94193794-2200-0000-8d4e-09f27b090000 pid=2427 clone guuid=2ecfa094-2200-0000-8d4e-09f27d090000 pid=2429 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=2ecfa094-2200-0000-8d4e-09f27d090000 pid=2429 execve guuid=780bf394-2200-0000-8d4e-09f27f090000 pid=2431 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=780bf394-2200-0000-8d4e-09f27f090000 pid=2431 execve guuid=49495995-2200-0000-8d4e-09f280090000 pid=2432 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=49495995-2200-0000-8d4e-09f280090000 pid=2432 execve guuid=6c2b7ab1-2200-0000-8d4e-09f2b2090000 pid=2482 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=6c2b7ab1-2200-0000-8d4e-09f2b2090000 pid=2482 execve guuid=77c04acf-2200-0000-8d4e-09f2e5090000 pid=2533 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=77c04acf-2200-0000-8d4e-09f2e5090000 pid=2533 execve guuid=7e36c7cf-2200-0000-8d4e-09f2e7090000 pid=2535 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=7e36c7cf-2200-0000-8d4e-09f2e7090000 pid=2535 clone guuid=88c122d0-2200-0000-8d4e-09f2e9090000 pid=2537 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=88c122d0-2200-0000-8d4e-09f2e9090000 pid=2537 execve guuid=307e8ed0-2200-0000-8d4e-09f2eb090000 pid=2539 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=307e8ed0-2200-0000-8d4e-09f2eb090000 pid=2539 execve guuid=ecb5f9d0-2200-0000-8d4e-09f2ed090000 pid=2541 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=ecb5f9d0-2200-0000-8d4e-09f2ed090000 pid=2541 execve guuid=32815eed-2200-0000-8d4e-09f22e0a0000 pid=2606 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=32815eed-2200-0000-8d4e-09f22e0a0000 pid=2606 execve guuid=b59eac11-2300-0000-8d4e-09f2940a0000 pid=2708 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=b59eac11-2300-0000-8d4e-09f2940a0000 pid=2708 execve guuid=aae81812-2300-0000-8d4e-09f2960a0000 pid=2710 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=aae81812-2300-0000-8d4e-09f2960a0000 pid=2710 clone guuid=badf6b12-2300-0000-8d4e-09f2990a0000 pid=2713 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=badf6b12-2300-0000-8d4e-09f2990a0000 pid=2713 execve guuid=92e5c912-2300-0000-8d4e-09f29b0a0000 pid=2715 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=92e5c912-2300-0000-8d4e-09f29b0a0000 pid=2715 execve guuid=1ec12313-2300-0000-8d4e-09f29d0a0000 pid=2717 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=1ec12313-2300-0000-8d4e-09f29d0a0000 pid=2717 execve guuid=58d5482f-2300-0000-8d4e-09f2d50a0000 pid=2773 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=58d5482f-2300-0000-8d4e-09f2d50a0000 pid=2773 execve guuid=661ec64d-2300-0000-8d4e-09f2e80a0000 pid=2792 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=661ec64d-2300-0000-8d4e-09f2e80a0000 pid=2792 execve guuid=d1d34f4e-2300-0000-8d4e-09f2e90a0000 pid=2793 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=d1d34f4e-2300-0000-8d4e-09f2e90a0000 pid=2793 clone guuid=e706ac4e-2300-0000-8d4e-09f2ec0a0000 pid=2796 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=e706ac4e-2300-0000-8d4e-09f2ec0a0000 pid=2796 execve guuid=1f86284f-2300-0000-8d4e-09f2ed0a0000 pid=2797 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=1f86284f-2300-0000-8d4e-09f2ed0a0000 pid=2797 execve guuid=5481b64f-2300-0000-8d4e-09f2ef0a0000 pid=2799 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=5481b64f-2300-0000-8d4e-09f2ef0a0000 pid=2799 execve guuid=c94c396c-2300-0000-8d4e-09f2180b0000 pid=2840 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=c94c396c-2300-0000-8d4e-09f2180b0000 pid=2840 execve guuid=c3ac7689-2300-0000-8d4e-09f2480b0000 pid=2888 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=c3ac7689-2300-0000-8d4e-09f2480b0000 pid=2888 execve guuid=c591f689-2300-0000-8d4e-09f24a0b0000 pid=2890 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=c591f689-2300-0000-8d4e-09f24a0b0000 pid=2890 clone guuid=70ba648a-2300-0000-8d4e-09f24c0b0000 pid=2892 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=70ba648a-2300-0000-8d4e-09f24c0b0000 pid=2892 execve guuid=2ee70e8b-2300-0000-8d4e-09f24d0b0000 pid=2893 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=2ee70e8b-2300-0000-8d4e-09f24d0b0000 pid=2893 execve guuid=3f3f7b8b-2300-0000-8d4e-09f24f0b0000 pid=2895 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=3f3f7b8b-2300-0000-8d4e-09f24f0b0000 pid=2895 execve guuid=d3ca49a7-2300-0000-8d4e-09f2930b0000 pid=2963 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=d3ca49a7-2300-0000-8d4e-09f2930b0000 pid=2963 execve guuid=3bc3f9c3-2300-0000-8d4e-09f2c50b0000 pid=3013 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=3bc3f9c3-2300-0000-8d4e-09f2c50b0000 pid=3013 execve guuid=72cc6dc4-2300-0000-8d4e-09f2c70b0000 pid=3015 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=72cc6dc4-2300-0000-8d4e-09f2c70b0000 pid=3015 clone guuid=d6abd8c4-2300-0000-8d4e-09f2ca0b0000 pid=3018 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=d6abd8c4-2300-0000-8d4e-09f2ca0b0000 pid=3018 execve guuid=0d6648c5-2300-0000-8d4e-09f2cc0b0000 pid=3020 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=0d6648c5-2300-0000-8d4e-09f2cc0b0000 pid=3020 execve guuid=d638a7c5-2300-0000-8d4e-09f2ce0b0000 pid=3022 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=d638a7c5-2300-0000-8d4e-09f2ce0b0000 pid=3022 execve guuid=23f501e2-2300-0000-8d4e-09f2030c0000 pid=3075 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=23f501e2-2300-0000-8d4e-09f2030c0000 pid=3075 execve guuid=b71ec7fe-2300-0000-8d4e-09f2460c0000 pid=3142 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=b71ec7fe-2300-0000-8d4e-09f2460c0000 pid=3142 execve guuid=faf774ff-2300-0000-8d4e-09f2480c0000 pid=3144 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=faf774ff-2300-0000-8d4e-09f2480c0000 pid=3144 clone guuid=f3cac6ff-2300-0000-8d4e-09f24a0c0000 pid=3146 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=f3cac6ff-2300-0000-8d4e-09f24a0c0000 pid=3146 execve guuid=a1273b00-2400-0000-8d4e-09f24c0c0000 pid=3148 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=a1273b00-2400-0000-8d4e-09f24c0c0000 pid=3148 execve guuid=761eaa00-2400-0000-8d4e-09f24e0c0000 pid=3150 /usr/bin/wget net send-data guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=761eaa00-2400-0000-8d4e-09f24e0c0000 pid=3150 execve guuid=4f606e1c-2400-0000-8d4e-09f2880c0000 pid=3208 /usr/bin/curl net send-data write-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=4f606e1c-2400-0000-8d4e-09f2880c0000 pid=3208 execve guuid=668b463a-2400-0000-8d4e-09f2a60c0000 pid=3238 /usr/bin/chmod guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=668b463a-2400-0000-8d4e-09f2a60c0000 pid=3238 execve guuid=7193ad3a-2400-0000-8d4e-09f2a80c0000 pid=3240 /usr/bin/bash guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=7193ad3a-2400-0000-8d4e-09f2a80c0000 pid=3240 clone guuid=9956283b-2400-0000-8d4e-09f2ab0c0000 pid=3243 /usr/bin/rm delete-file guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=9956283b-2400-0000-8d4e-09f2ab0c0000 pid=3243 execve guuid=efcf913b-2400-0000-8d4e-09f2ad0c0000 pid=3245 /usr/bin/rm guuid=c4043f5d-2100-0000-8d4e-09f210070000 pid=1808->guuid=efcf913b-2400-0000-8d4e-09f2ad0c0000 pid=3245 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=4dfeb55d-2100-0000-8d4e-09f211070000 pid=1809->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4a98977b-2100-0000-8d4e-09f259070000 pid=1881->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3f749d9c-2100-0000-8d4e-09f2a3070000 pid=1955 /usr/bin/bash guuid=52c87a9c-2100-0000-8d4e-09f2a2070000 pid=1954->guuid=3f749d9c-2100-0000-8d4e-09f2a3070000 pid=1955 clone guuid=3fd5639d-2100-0000-8d4e-09f2a9070000 pid=1961->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=92eca6b8-2100-0000-8d4e-09f2d7070000 pid=2007->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=21b85fe2-2100-0000-8d4e-09f2eb070000 pid=2027 /usr/bin/bash guuid=a2d943e2-2100-0000-8d4e-09f2ea070000 pid=2026->guuid=21b85fe2-2100-0000-8d4e-09f2eb070000 pid=2027 clone guuid=7e8336e3-2100-0000-8d4e-09f2ee070000 pid=2030->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b2a9cbfe-2100-0000-8d4e-09f223080000 pid=2083->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=edb0b81e-2200-0000-8d4e-09f270080000 pid=2160 /usr/bin/bash guuid=f846a01e-2200-0000-8d4e-09f26e080000 pid=2158->guuid=edb0b81e-2200-0000-8d4e-09f270080000 pid=2160 clone guuid=325e611f-2200-0000-8d4e-09f275080000 pid=2165->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=3a14923a-2200-0000-8d4e-09f2d7080000 pid=2263->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=8d4c4159-2200-0000-8d4e-09f21e090000 pid=2334 /usr/bin/bash guuid=29c21859-2200-0000-8d4e-09f21d090000 pid=2333->guuid=8d4c4159-2200-0000-8d4e-09f21e090000 pid=2334 clone guuid=f0377d5a-2200-0000-8d4e-09f222090000 pid=2338->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a4346376-2200-0000-8d4e-09f256090000 pid=2390->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d4247594-2200-0000-8d4e-09f27c090000 pid=2428 /usr/bin/bash guuid=94193794-2200-0000-8d4e-09f27b090000 pid=2427->guuid=d4247594-2200-0000-8d4e-09f27c090000 pid=2428 clone guuid=49495995-2200-0000-8d4e-09f280090000 pid=2432->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=6c2b7ab1-2200-0000-8d4e-09f2b2090000 pid=2482->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=b174f2cf-2200-0000-8d4e-09f2e8090000 pid=2536 /usr/bin/bash guuid=7e36c7cf-2200-0000-8d4e-09f2e7090000 pid=2535->guuid=b174f2cf-2200-0000-8d4e-09f2e8090000 pid=2536 clone guuid=ecb5f9d0-2200-0000-8d4e-09f2ed090000 pid=2541->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=32815eed-2200-0000-8d4e-09f22e0a0000 pid=2606->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=68e23912-2300-0000-8d4e-09f2970a0000 pid=2711 /usr/bin/bash guuid=aae81812-2300-0000-8d4e-09f2960a0000 pid=2710->guuid=68e23912-2300-0000-8d4e-09f2970a0000 pid=2711 clone guuid=1ec12313-2300-0000-8d4e-09f29d0a0000 pid=2717->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=58d5482f-2300-0000-8d4e-09f2d50a0000 pid=2773->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9da9724e-2300-0000-8d4e-09f2eb0a0000 pid=2795 /usr/bin/bash guuid=d1d34f4e-2300-0000-8d4e-09f2e90a0000 pid=2793->guuid=9da9724e-2300-0000-8d4e-09f2eb0a0000 pid=2795 clone guuid=5481b64f-2300-0000-8d4e-09f2ef0a0000 pid=2799->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=c94c396c-2300-0000-8d4e-09f2180b0000 pid=2840->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d7e72a8a-2300-0000-8d4e-09f24b0b0000 pid=2891 /usr/bin/bash guuid=c591f689-2300-0000-8d4e-09f24a0b0000 pid=2890->guuid=d7e72a8a-2300-0000-8d4e-09f24b0b0000 pid=2891 clone guuid=3f3f7b8b-2300-0000-8d4e-09f24f0b0000 pid=2895->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=d3ca49a7-2300-0000-8d4e-09f2930b0000 pid=2963->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=796195c4-2300-0000-8d4e-09f2c80b0000 pid=3016 /usr/bin/bash guuid=72cc6dc4-2300-0000-8d4e-09f2c70b0000 pid=3015->guuid=796195c4-2300-0000-8d4e-09f2c80b0000 pid=3016 clone guuid=d638a7c5-2300-0000-8d4e-09f2ce0b0000 pid=3022->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=23f501e2-2300-0000-8d4e-09f2030c0000 pid=3075->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=977d96ff-2300-0000-8d4e-09f2490c0000 pid=3145 /usr/bin/bash guuid=faf774ff-2300-0000-8d4e-09f2480c0000 pid=3144->guuid=977d96ff-2300-0000-8d4e-09f2490c0000 pid=3145 clone guuid=761eaa00-2400-0000-8d4e-09f24e0c0000 pid=3150->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4f606e1c-2400-0000-8d4e-09f2880c0000 pid=3208->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=9e40d63a-2400-0000-8d4e-09f2a90c0000 pid=3241 /usr/bin/bash guuid=7193ad3a-2400-0000-8d4e-09f2a80c0000 pid=3240->guuid=9e40d63a-2400-0000-8d4e-09f2a90c0000 pid=3241 clone
Threat name:
Script.Downloader.Malgent
Status:
Malicious
First seen:
2026-06-08 01:47:35 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0452e5f363cfc17bf436564ac2cf30e71f7ee30d2d5d66768482c45f8a734d12

(this sample)

  
Delivery method
Distributed via web download

Comments