MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0bc4cf3fed9fd5c474fd5a3cfd4b8b47b3f559942eeecad0066bb507a1e0e25f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0bc4cf3fed9fd5c474fd5a3cfd4b8b47b3f559942eeecad0066bb507a1e0e25f
SHA3-384 hash: 5f911f685021965916c175f7a0f4bf48c8a548cfd054fd02ec3455022cd64b3e58e6955f9124143427d0331a76615a1b
SHA1 hash: 8e75b2d56b133b2ed15ccd29dd628c113300900e
MD5 hash: 2fe3d750709af03393841e535a0c38ef
humanhash: helium-muppet-fruit-cat
File name:ok
Download: download sample
Signature Mirai
File size:1'584 bytes
First seen:2026-06-22 16:25:38 UTC
Last seen:2026-06-22 18:23:28 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UHL6HF13Qr6rT0dKwCx6CK7lQC26COEiI6Ei3pC9tDu6EDbi+6iTYlC96ur6CEMN:vT01UEFQ9wTYlC9REMdsJ/Q8TWFf92x2
TLSH T1DC310C9F00106F792257CADE77B33948780CC2FF2C8BD7A499480EA986495C8B5A5BE5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/3dfa29n/an/aelf ua-wget
http://5.182.210.61/c482f7n/an/aelf ua-wget
http://5.182.210.61/1453ben/an/aelf ua-wget
http://5.182.210.61/76f105n/an/aelf ua-wget
http://5.182.210.61/5eab74n/an/aelf ua-wget
http://5.182.210.61/259653n/an/aelf ua-wget
http://5.182.210.61/e5a1f7n/an/aelf ua-wget
http://5.182.210.61/fa906bn/an/aelf ua-wget
http://5.182.210.61/d34e03n/an/aelf ua-wget
http://5.182.210.61/37bdbcn/an/aelf ua-wget
http://5.182.210.61/7ceda2n/an/an/a
http://5.182.210.61/21ab20n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=9cb0d94e-1900-0000-b760-b84a170f0000 pid=3863 /usr/bin/sudo guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876 /tmp/sample.bin guuid=9cb0d94e-1900-0000-b760-b84a170f0000 pid=3863->guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876 execve guuid=98cff351-1900-0000-b760-b84a260f0000 pid=3878 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=98cff351-1900-0000-b760-b84a260f0000 pid=3878 execve guuid=a83f4556-1900-0000-b760-b84a330f0000 pid=3891 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=a83f4556-1900-0000-b760-b84a330f0000 pid=3891 execve guuid=18611b60-1900-0000-b760-b84a4d0f0000 pid=3917 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=18611b60-1900-0000-b760-b84a4d0f0000 pid=3917 execve guuid=e6977760-1900-0000-b760-b84a4f0f0000 pid=3919 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=e6977760-1900-0000-b760-b84a4f0f0000 pid=3919 clone guuid=1a07c960-1900-0000-b760-b84a520f0000 pid=3922 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=1a07c960-1900-0000-b760-b84a520f0000 pid=3922 execve guuid=2bb94c61-1900-0000-b760-b84a550f0000 pid=3925 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=2bb94c61-1900-0000-b760-b84a550f0000 pid=3925 execve guuid=7530c761-1900-0000-b760-b84a570f0000 pid=3927 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=7530c761-1900-0000-b760-b84a570f0000 pid=3927 execve guuid=9ad58865-1900-0000-b760-b84a620f0000 pid=3938 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=9ad58865-1900-0000-b760-b84a620f0000 pid=3938 execve guuid=12093d6a-1900-0000-b760-b84a760f0000 pid=3958 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=12093d6a-1900-0000-b760-b84a760f0000 pid=3958 execve guuid=cade816a-1900-0000-b760-b84a7a0f0000 pid=3962 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=cade816a-1900-0000-b760-b84a7a0f0000 pid=3962 clone guuid=3463b96a-1900-0000-b760-b84a7c0f0000 pid=3964 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=3463b96a-1900-0000-b760-b84a7c0f0000 pid=3964 execve guuid=a952026b-1900-0000-b760-b84a7d0f0000 pid=3965 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=a952026b-1900-0000-b760-b84a7d0f0000 pid=3965 execve guuid=76924e6b-1900-0000-b760-b84a7e0f0000 pid=3966 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=76924e6b-1900-0000-b760-b84a7e0f0000 pid=3966 execve guuid=a347d46d-1900-0000-b760-b84a8a0f0000 pid=3978 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=a347d46d-1900-0000-b760-b84a8a0f0000 pid=3978 execve guuid=c1617371-1900-0000-b760-b84a9d0f0000 pid=3997 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=c1617371-1900-0000-b760-b84a9d0f0000 pid=3997 execve guuid=7f30c071-1900-0000-b760-b84a9f0f0000 pid=3999 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=7f30c071-1900-0000-b760-b84a9f0f0000 pid=3999 clone guuid=0af3f571-1900-0000-b760-b84aa20f0000 pid=4002 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=0af3f571-1900-0000-b760-b84aa20f0000 pid=4002 execve guuid=17243d72-1900-0000-b760-b84aa30f0000 pid=4003 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=17243d72-1900-0000-b760-b84aa30f0000 pid=4003 execve guuid=d483bc72-1900-0000-b760-b84aa70f0000 pid=4007 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=d483bc72-1900-0000-b760-b84aa70f0000 pid=4007 execve guuid=63742676-1900-0000-b760-b84ab70f0000 pid=4023 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=63742676-1900-0000-b760-b84ab70f0000 pid=4023 execve guuid=59fb7179-1900-0000-b760-b84ac60f0000 pid=4038 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=59fb7179-1900-0000-b760-b84ac60f0000 pid=4038 execve guuid=e04bae79-1900-0000-b760-b84ac70f0000 pid=4039 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=e04bae79-1900-0000-b760-b84ac70f0000 pid=4039 clone guuid=9259e579-1900-0000-b760-b84aca0f0000 pid=4042 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=9259e579-1900-0000-b760-b84aca0f0000 pid=4042 execve guuid=5e2c297a-1900-0000-b760-b84acc0f0000 pid=4044 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=5e2c297a-1900-0000-b760-b84acc0f0000 pid=4044 execve guuid=c4236f7a-1900-0000-b760-b84ace0f0000 pid=4046 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=c4236f7a-1900-0000-b760-b84ace0f0000 pid=4046 execve guuid=d367137d-1900-0000-b760-b84ad70f0000 pid=4055 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=d367137d-1900-0000-b760-b84ad70f0000 pid=4055 execve guuid=4a0fa880-1900-0000-b760-b84ae30f0000 pid=4067 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=4a0fa880-1900-0000-b760-b84ae30f0000 pid=4067 execve guuid=2894e780-1900-0000-b760-b84ae70f0000 pid=4071 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=2894e780-1900-0000-b760-b84ae70f0000 pid=4071 clone guuid=f8182581-1900-0000-b760-b84ae90f0000 pid=4073 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=f8182581-1900-0000-b760-b84ae90f0000 pid=4073 execve guuid=26566a81-1900-0000-b760-b84aeb0f0000 pid=4075 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=26566a81-1900-0000-b760-b84aeb0f0000 pid=4075 execve guuid=de4cb581-1900-0000-b760-b84aed0f0000 pid=4077 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=de4cb581-1900-0000-b760-b84aed0f0000 pid=4077 execve guuid=50783c84-1900-0000-b760-b84af70f0000 pid=4087 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=50783c84-1900-0000-b760-b84af70f0000 pid=4087 execve guuid=5ee10b88-1900-0000-b760-b84a08100000 pid=4104 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=5ee10b88-1900-0000-b760-b84a08100000 pid=4104 execve guuid=6d5d5c88-1900-0000-b760-b84a09100000 pid=4105 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=6d5d5c88-1900-0000-b760-b84a09100000 pid=4105 clone guuid=fd9ca188-1900-0000-b760-b84a0e100000 pid=4110 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=fd9ca188-1900-0000-b760-b84a0e100000 pid=4110 execve guuid=f74cee88-1900-0000-b760-b84a10100000 pid=4112 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=f74cee88-1900-0000-b760-b84a10100000 pid=4112 execve guuid=b5b13289-1900-0000-b760-b84a12100000 pid=4114 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=b5b13289-1900-0000-b760-b84a12100000 pid=4114 execve guuid=b549168c-1900-0000-b760-b84a1f100000 pid=4127 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=b549168c-1900-0000-b760-b84a1f100000 pid=4127 execve guuid=fa7a918f-1900-0000-b760-b84a2c100000 pid=4140 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=fa7a918f-1900-0000-b760-b84a2c100000 pid=4140 execve guuid=777dd88f-1900-0000-b760-b84a2e100000 pid=4142 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=777dd88f-1900-0000-b760-b84a2e100000 pid=4142 clone guuid=8b751990-1900-0000-b760-b84a30100000 pid=4144 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=8b751990-1900-0000-b760-b84a30100000 pid=4144 execve guuid=b6216e90-1900-0000-b760-b84a31100000 pid=4145 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=b6216e90-1900-0000-b760-b84a31100000 pid=4145 execve guuid=f221c690-1900-0000-b760-b84a32100000 pid=4146 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=f221c690-1900-0000-b760-b84a32100000 pid=4146 execve guuid=dff38193-1900-0000-b760-b84a36100000 pid=4150 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=dff38193-1900-0000-b760-b84a36100000 pid=4150 execve guuid=54024098-1900-0000-b760-b84a4b100000 pid=4171 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=54024098-1900-0000-b760-b84a4b100000 pid=4171 execve guuid=b3be9e98-1900-0000-b760-b84a4c100000 pid=4172 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=b3be9e98-1900-0000-b760-b84a4c100000 pid=4172 clone guuid=cbdcd198-1900-0000-b760-b84a51100000 pid=4177 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=cbdcd198-1900-0000-b760-b84a51100000 pid=4177 execve guuid=f8812499-1900-0000-b760-b84a55100000 pid=4181 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=f8812499-1900-0000-b760-b84a55100000 pid=4181 execve guuid=e0ca6499-1900-0000-b760-b84a56100000 pid=4182 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=e0ca6499-1900-0000-b760-b84a56100000 pid=4182 execve guuid=0c59f69b-1900-0000-b760-b84a5c100000 pid=4188 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=0c59f69b-1900-0000-b760-b84a5c100000 pid=4188 execve guuid=cb28e3a0-1900-0000-b760-b84a6e100000 pid=4206 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=cb28e3a0-1900-0000-b760-b84a6e100000 pid=4206 execve guuid=396831a1-1900-0000-b760-b84a70100000 pid=4208 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=396831a1-1900-0000-b760-b84a70100000 pid=4208 clone guuid=9ddd97a1-1900-0000-b760-b84a73100000 pid=4211 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=9ddd97a1-1900-0000-b760-b84a73100000 pid=4211 execve guuid=9f2f17a2-1900-0000-b760-b84a75100000 pid=4213 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=9f2f17a2-1900-0000-b760-b84a75100000 pid=4213 execve guuid=042d64a2-1900-0000-b760-b84a77100000 pid=4215 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=042d64a2-1900-0000-b760-b84a77100000 pid=4215 execve guuid=7f10faa4-1900-0000-b760-b84a80100000 pid=4224 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=7f10faa4-1900-0000-b760-b84a80100000 pid=4224 execve guuid=6ac9d2a9-1900-0000-b760-b84a98100000 pid=4248 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=6ac9d2a9-1900-0000-b760-b84a98100000 pid=4248 execve guuid=5e1e11aa-1900-0000-b760-b84a9b100000 pid=4251 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=5e1e11aa-1900-0000-b760-b84a9b100000 pid=4251 clone guuid=db7849aa-1900-0000-b760-b84a9e100000 pid=4254 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=db7849aa-1900-0000-b760-b84a9e100000 pid=4254 execve guuid=680398aa-1900-0000-b760-b84aa0100000 pid=4256 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=680398aa-1900-0000-b760-b84aa0100000 pid=4256 execve guuid=3e6adaaa-1900-0000-b760-b84aa2100000 pid=4258 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=3e6adaaa-1900-0000-b760-b84aa2100000 pid=4258 execve guuid=558a86ad-1900-0000-b760-b84ab1100000 pid=4273 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=558a86ad-1900-0000-b760-b84ab1100000 pid=4273 execve guuid=71e8acb2-1900-0000-b760-b84ac2100000 pid=4290 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=71e8acb2-1900-0000-b760-b84ac2100000 pid=4290 execve guuid=129014b3-1900-0000-b760-b84ac4100000 pid=4292 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=129014b3-1900-0000-b760-b84ac4100000 pid=4292 clone guuid=ca067cb3-1900-0000-b760-b84ac6100000 pid=4294 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=ca067cb3-1900-0000-b760-b84ac6100000 pid=4294 execve guuid=6a7006b4-1900-0000-b760-b84ac8100000 pid=4296 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=6a7006b4-1900-0000-b760-b84ac8100000 pid=4296 execve guuid=f42da0b4-1900-0000-b760-b84acb100000 pid=4299 /usr/bin/wget net send-data guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=f42da0b4-1900-0000-b760-b84acb100000 pid=4299 execve guuid=81b898b7-1900-0000-b760-b84ad8100000 pid=4312 /usr/bin/curl net send-data write-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=81b898b7-1900-0000-b760-b84ad8100000 pid=4312 execve guuid=2e2fb7bb-1900-0000-b760-b84aed100000 pid=4333 /usr/bin/chmod guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=2e2fb7bb-1900-0000-b760-b84aed100000 pid=4333 execve guuid=1548f2bb-1900-0000-b760-b84aee100000 pid=4334 /usr/bin/bash guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=1548f2bb-1900-0000-b760-b84aee100000 pid=4334 clone guuid=9eed21bc-1900-0000-b760-b84af1100000 pid=4337 /usr/bin/rm delete-file guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=9eed21bc-1900-0000-b760-b84af1100000 pid=4337 execve guuid=bdd960bc-1900-0000-b760-b84af3100000 pid=4339 /usr/bin/rm guuid=f0806d51-1900-0000-b760-b84a240f0000 pid=3876->guuid=bdd960bc-1900-0000-b760-b84af3100000 pid=4339 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=98cff351-1900-0000-b760-b84a260f0000 pid=3878->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=a83f4556-1900-0000-b760-b84a330f0000 pid=3891->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e516a160-1900-0000-b760-b84a500f0000 pid=3920 /usr/bin/bash guuid=e6977760-1900-0000-b760-b84a4f0f0000 pid=3919->guuid=e516a160-1900-0000-b760-b84a500f0000 pid=3920 clone guuid=7530c761-1900-0000-b760-b84a570f0000 pid=3927->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=9ad58865-1900-0000-b760-b84a620f0000 pid=3938->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=86e0986a-1900-0000-b760-b84a7b0f0000 pid=3963 /usr/bin/bash guuid=cade816a-1900-0000-b760-b84a7a0f0000 pid=3962->guuid=86e0986a-1900-0000-b760-b84a7b0f0000 pid=3963 clone guuid=76924e6b-1900-0000-b760-b84a7e0f0000 pid=3966->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=a347d46d-1900-0000-b760-b84a8a0f0000 pid=3978->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=7d5cda71-1900-0000-b760-b84aa00f0000 pid=4000 /usr/bin/bash guuid=7f30c071-1900-0000-b760-b84a9f0f0000 pid=3999->guuid=7d5cda71-1900-0000-b760-b84aa00f0000 pid=4000 clone guuid=d483bc72-1900-0000-b760-b84aa70f0000 pid=4007->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=63742676-1900-0000-b760-b84ab70f0000 pid=4023->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ab23c579-1900-0000-b760-b84ac90f0000 pid=4041 /usr/bin/bash guuid=e04bae79-1900-0000-b760-b84ac70f0000 pid=4039->guuid=ab23c579-1900-0000-b760-b84ac90f0000 pid=4041 clone guuid=c4236f7a-1900-0000-b760-b84ace0f0000 pid=4046->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d367137d-1900-0000-b760-b84ad70f0000 pid=4055->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c7bffd80-1900-0000-b760-b84ae80f0000 pid=4072 /usr/bin/bash guuid=2894e780-1900-0000-b760-b84ae70f0000 pid=4071->guuid=c7bffd80-1900-0000-b760-b84ae80f0000 pid=4072 clone guuid=de4cb581-1900-0000-b760-b84aed0f0000 pid=4077->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=50783c84-1900-0000-b760-b84af70f0000 pid=4087->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d5d37588-1900-0000-b760-b84a0d100000 pid=4109 /usr/bin/bash guuid=6d5d5c88-1900-0000-b760-b84a09100000 pid=4105->guuid=d5d37588-1900-0000-b760-b84a0d100000 pid=4109 clone guuid=b5b13289-1900-0000-b760-b84a12100000 pid=4114->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=b549168c-1900-0000-b760-b84a1f100000 pid=4127->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=cb18f38f-1900-0000-b760-b84a2f100000 pid=4143 /usr/bin/bash guuid=777dd88f-1900-0000-b760-b84a2e100000 pid=4142->guuid=cb18f38f-1900-0000-b760-b84a2f100000 pid=4143 clone guuid=f221c690-1900-0000-b760-b84a32100000 pid=4146->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=dff38193-1900-0000-b760-b84a36100000 pid=4150->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=242ab898-1900-0000-b760-b84a50100000 pid=4176 /usr/bin/bash guuid=b3be9e98-1900-0000-b760-b84a4c100000 pid=4172->guuid=242ab898-1900-0000-b760-b84a50100000 pid=4176 clone guuid=e0ca6499-1900-0000-b760-b84a56100000 pid=4182->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=0c59f69b-1900-0000-b760-b84a5c100000 pid=4188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=77e15fa1-1900-0000-b760-b84a71100000 pid=4209 /usr/bin/bash guuid=396831a1-1900-0000-b760-b84a70100000 pid=4208->guuid=77e15fa1-1900-0000-b760-b84a71100000 pid=4209 clone guuid=042d64a2-1900-0000-b760-b84a77100000 pid=4215->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=7f10faa4-1900-0000-b760-b84a80100000 pid=4224->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=61ea26aa-1900-0000-b760-b84a9d100000 pid=4253 /usr/bin/bash guuid=5e1e11aa-1900-0000-b760-b84a9b100000 pid=4251->guuid=61ea26aa-1900-0000-b760-b84a9d100000 pid=4253 clone guuid=3e6adaaa-1900-0000-b760-b84aa2100000 pid=4258->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=558a86ad-1900-0000-b760-b84ab1100000 pid=4273->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e49140b3-1900-0000-b760-b84ac5100000 pid=4293 /usr/bin/bash guuid=129014b3-1900-0000-b760-b84ac4100000 pid=4292->guuid=e49140b3-1900-0000-b760-b84ac5100000 pid=4293 clone guuid=f42da0b4-1900-0000-b760-b84acb100000 pid=4299->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=81b898b7-1900-0000-b760-b84ad8100000 pid=4312->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=823608bc-1900-0000-b760-b84af0100000 pid=4336 /usr/bin/bash guuid=1548f2bb-1900-0000-b760-b84aee100000 pid=4334->guuid=823608bc-1900-0000-b760-b84af0100000 pid=4336 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-06-22 16:26:45 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0bc4cf3fed9fd5c474fd5a3cfd4b8b47b3f559942eeecad0066bb507a1e0e25f

(this sample)

  
Delivery method
Distributed via web download

Comments