MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f4570f98ddcbaa032069fcb94608143078eab427008519169c32d8662563bc0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 0f4570f98ddcbaa032069fcb94608143078eab427008519169c32d8662563bc0
SHA3-384 hash: 18b75f342a8b3808766d3b54de9c0c2a412f7f28fa98a11e93f4678440aba7a28993bd57d17ae4e1795acc27b0a95716
SHA1 hash: 33e6177536ae9ffd4b5a5c41248d6061da7dec0d
MD5 hash: a79e5e642c04a8ad2f83a969c71857e4
humanhash: mexico-green-table-solar
File name:b.sh
Download: download sample
Signature Mirai
File size:1'310 bytes
First seen:2025-12-18 21:16:13 UTC
Last seen:2025-12-18 22:27:13 UTC
File type: sh
MIME type:text/plain
ssdeep 12:oXjBgIUGgsiGNI1dgiL6YgLDCrxDSi7g9Jbgyiwg7GihGgd1gLraLxra5655gBxc:oG1stNIIfL2dsEzCrxLgkUlCeT4haV
TLSH T1E421DFC90011D7165E6B9F1863BBEA94D102F8D227C68E27ECC40D37CC8DA157D46EC9
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.37.154/xparm0580273c3f41f5025401e4836e4eaab1fda97f11b92a9ed215aef432e8151ec9 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.37.154/xparm5249bc7c5f69ca45551a7b7c35076a8a63b9c6de3d5228ca3006bd92583351fcf Miraiarm elf geofenced mirai ua-wget USA
http://143.20.37.154/xparm607ae848cc5ba570446b2e3e1ec560c6bb7f05e810a84a77a71f19c3f43270d65 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.37.154/xparm79c2c71084ec60f3df3fb5593d171e415af377298eff7f4bc4475be22cddbab25 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.37.154/xpsh4b1fc3796b8cb3d426fc74e6d9f06637ab1643f071283dd63ac8a1ce5a26f0834 Miraielf geofenced mirai SuperH ua-wget USA
http://143.20.37.154/xparcn/an/aelf ua-wget
http://143.20.37.154/xpmips2b63ef456fbcfaa61cac464fd974a01fc3e8c77f378ae83bcaa52b66e5f3db0c Miraielf geofenced mips mirai ua-wget USA
http://143.20.37.154/xpmpsl7ef1315c3e6667d670dfc11e07302c845b41f1e4643a0ca4c42e0d5390ad5080 Miraielf geofenced mips mirai ua-wget USA
http://143.20.37.154/xpsparcn/an/aelf ua-wget
http://143.20.37.154/xpx86a76639e5ec05e6394636795bb2873c0127b0aa340d9f0f0067377263008d9dad Miraielf geofenced mirai ua-wget USA x86
http://143.20.37.154/xpi686n/an/aelf ua-wget
http://143.20.37.154/xpi586n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-18T19:33:00Z UTC
Last seen:
2025-12-19T00:17:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=91db7161-1900-0000-f840-4fb7bb090000 pid=2491 /usr/bin/sudo guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498 /tmp/sample.bin guuid=91db7161-1900-0000-f840-4fb7bb090000 pid=2491->guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498 execve guuid=97582764-1900-0000-f840-4fb7c4090000 pid=2500 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=97582764-1900-0000-f840-4fb7c4090000 pid=2500 execve guuid=08e1f967-1900-0000-f840-4fb7ca090000 pid=2506 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=08e1f967-1900-0000-f840-4fb7ca090000 pid=2506 execve guuid=a0521278-1900-0000-f840-4fb7ea090000 pid=2538 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=a0521278-1900-0000-f840-4fb7ea090000 pid=2538 execve guuid=988c9b78-1900-0000-f840-4fb7ec090000 pid=2540 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=988c9b78-1900-0000-f840-4fb7ec090000 pid=2540 clone guuid=35817279-1900-0000-f840-4fb7ee090000 pid=2542 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=35817279-1900-0000-f840-4fb7ee090000 pid=2542 execve guuid=a769aa7b-1900-0000-f840-4fb7f5090000 pid=2549 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=a769aa7b-1900-0000-f840-4fb7f5090000 pid=2549 execve guuid=4cbbaa84-1900-0000-f840-4fb70e0a0000 pid=2574 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=4cbbaa84-1900-0000-f840-4fb70e0a0000 pid=2574 execve guuid=09980985-1900-0000-f840-4fb7100a0000 pid=2576 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=09980985-1900-0000-f840-4fb7100a0000 pid=2576 clone guuid=18638785-1900-0000-f840-4fb7140a0000 pid=2580 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=18638785-1900-0000-f840-4fb7140a0000 pid=2580 execve guuid=e4b98587-1900-0000-f840-4fb71a0a0000 pid=2586 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=e4b98587-1900-0000-f840-4fb71a0a0000 pid=2586 execve guuid=4ec2c28a-1900-0000-f840-4fb7240a0000 pid=2596 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=4ec2c28a-1900-0000-f840-4fb7240a0000 pid=2596 execve guuid=b9c9ff8a-1900-0000-f840-4fb7260a0000 pid=2598 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=b9c9ff8a-1900-0000-f840-4fb7260a0000 pid=2598 clone guuid=2522998b-1900-0000-f840-4fb7290a0000 pid=2601 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=2522998b-1900-0000-f840-4fb7290a0000 pid=2601 execve guuid=fcd9188e-1900-0000-f840-4fb7310a0000 pid=2609 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=fcd9188e-1900-0000-f840-4fb7310a0000 pid=2609 execve guuid=d3c72393-1900-0000-f840-4fb7400a0000 pid=2624 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=d3c72393-1900-0000-f840-4fb7400a0000 pid=2624 execve guuid=cf536f93-1900-0000-f840-4fb7420a0000 pid=2626 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=cf536f93-1900-0000-f840-4fb7420a0000 pid=2626 clone guuid=599dfe93-1900-0000-f840-4fb7460a0000 pid=2630 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=599dfe93-1900-0000-f840-4fb7460a0000 pid=2630 execve guuid=03b1b997-1900-0000-f840-4fb7510a0000 pid=2641 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=03b1b997-1900-0000-f840-4fb7510a0000 pid=2641 execve guuid=334b829c-1900-0000-f840-4fb75e0a0000 pid=2654 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=334b829c-1900-0000-f840-4fb75e0a0000 pid=2654 execve guuid=f65dda9c-1900-0000-f840-4fb7600a0000 pid=2656 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=f65dda9c-1900-0000-f840-4fb7600a0000 pid=2656 clone guuid=87516c9d-1900-0000-f840-4fb7640a0000 pid=2660 /usr/bin/wget net send-data guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=87516c9d-1900-0000-f840-4fb7640a0000 pid=2660 execve guuid=0b89c0a0-1900-0000-f840-4fb7720a0000 pid=2674 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=0b89c0a0-1900-0000-f840-4fb7720a0000 pid=2674 execve guuid=643653a5-1900-0000-f840-4fb77f0a0000 pid=2687 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=643653a5-1900-0000-f840-4fb77f0a0000 pid=2687 execve guuid=fc06c3a5-1900-0000-f840-4fb7810a0000 pid=2689 /tmp/xparc guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=fc06c3a5-1900-0000-f840-4fb7810a0000 pid=2689 execve guuid=8dd517a6-1900-0000-f840-4fb7830a0000 pid=2691 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=8dd517a6-1900-0000-f840-4fb7830a0000 pid=2691 execve guuid=85786aab-1900-0000-f840-4fb7940a0000 pid=2708 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=85786aab-1900-0000-f840-4fb7940a0000 pid=2708 execve guuid=39949eaf-1900-0000-f840-4fb7a10a0000 pid=2721 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=39949eaf-1900-0000-f840-4fb7a10a0000 pid=2721 execve guuid=656eedaf-1900-0000-f840-4fb7a30a0000 pid=2723 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=656eedaf-1900-0000-f840-4fb7a30a0000 pid=2723 clone guuid=81c6aeb0-1900-0000-f840-4fb7a80a0000 pid=2728 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=81c6aeb0-1900-0000-f840-4fb7a80a0000 pid=2728 execve guuid=c836d6b3-1900-0000-f840-4fb7b30a0000 pid=2739 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=c836d6b3-1900-0000-f840-4fb7b30a0000 pid=2739 execve guuid=fd691dba-1900-0000-f840-4fb7c70a0000 pid=2759 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=fd691dba-1900-0000-f840-4fb7c70a0000 pid=2759 execve guuid=41687fba-1900-0000-f840-4fb7c80a0000 pid=2760 /usr/bin/dash guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=41687fba-1900-0000-f840-4fb7c80a0000 pid=2760 clone guuid=eab167bc-1900-0000-f840-4fb7ca0a0000 pid=2762 /usr/bin/wget net send-data guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=eab167bc-1900-0000-f840-4fb7ca0a0000 pid=2762 execve guuid=d9a50dbe-1900-0000-f840-4fb7cb0a0000 pid=2763 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=d9a50dbe-1900-0000-f840-4fb7cb0a0000 pid=2763 execve guuid=52dde1c3-1900-0000-f840-4fb7d80a0000 pid=2776 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=52dde1c3-1900-0000-f840-4fb7d80a0000 pid=2776 execve guuid=b54e20c4-1900-0000-f840-4fb7da0a0000 pid=2778 /tmp/xpsparc guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=b54e20c4-1900-0000-f840-4fb7da0a0000 pid=2778 execve guuid=7d9c4ec4-1900-0000-f840-4fb7db0a0000 pid=2779 /usr/bin/wget net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=7d9c4ec4-1900-0000-f840-4fb7db0a0000 pid=2779 execve guuid=9b6451c6-1900-0000-f840-4fb7de0a0000 pid=2782 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=9b6451c6-1900-0000-f840-4fb7de0a0000 pid=2782 execve guuid=feac78c9-1900-0000-f840-4fb7e50a0000 pid=2789 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=feac78c9-1900-0000-f840-4fb7e50a0000 pid=2789 execve guuid=73b4cfc9-1900-0000-f840-4fb7e70a0000 pid=2791 /tmp/xpx86 delete-file net guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=73b4cfc9-1900-0000-f840-4fb7e70a0000 pid=2791 execve guuid=3ef713ca-1900-0000-f840-4fb7e90a0000 pid=2793 /usr/bin/wget net send-data guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=3ef713ca-1900-0000-f840-4fb7e90a0000 pid=2793 execve guuid=4133e0cc-1900-0000-f840-4fb7f10a0000 pid=2801 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=4133e0cc-1900-0000-f840-4fb7f10a0000 pid=2801 execve guuid=b9cb48d1-1900-0000-f840-4fb7f70a0000 pid=2807 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=b9cb48d1-1900-0000-f840-4fb7f70a0000 pid=2807 execve guuid=eb0191d1-1900-0000-f840-4fb7f80a0000 pid=2808 /tmp/xpi686 guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=eb0191d1-1900-0000-f840-4fb7f80a0000 pid=2808 execve guuid=e1bb1bd2-1900-0000-f840-4fb7fa0a0000 pid=2810 /usr/bin/wget net send-data guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=e1bb1bd2-1900-0000-f840-4fb7fa0a0000 pid=2810 execve guuid=b77188d6-1900-0000-f840-4fb7fe0a0000 pid=2814 /usr/bin/curl net send-data write-file guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=b77188d6-1900-0000-f840-4fb7fe0a0000 pid=2814 execve guuid=cb69aedb-1900-0000-f840-4fb7060b0000 pid=2822 /usr/bin/chmod guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=cb69aedb-1900-0000-f840-4fb7060b0000 pid=2822 execve guuid=0bcb09dc-1900-0000-f840-4fb7070b0000 pid=2823 /tmp/xpi586 guuid=b6a1ed63-1900-0000-f840-4fb7c2090000 pid=2498->guuid=0bcb09dc-1900-0000-f840-4fb7070b0000 pid=2823 execve 1761238b-cda9-5bdb-a690-4f2e3689b082 143.20.37.154:80 guuid=97582764-1900-0000-f840-4fb7c4090000 pid=2500->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 133B guuid=08e1f967-1900-0000-f840-4fb7ca090000 pid=2506->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 82B guuid=35817279-1900-0000-f840-4fb7ee090000 pid=2542->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=a769aa7b-1900-0000-f840-4fb7f5090000 pid=2549->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=18638785-1900-0000-f840-4fb7140a0000 pid=2580->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=e4b98587-1900-0000-f840-4fb71a0a0000 pid=2586->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=2522998b-1900-0000-f840-4fb7290a0000 pid=2601->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=fcd9188e-1900-0000-f840-4fb7310a0000 pid=2609->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=599dfe93-1900-0000-f840-4fb7460a0000 pid=2630->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 133B guuid=03b1b997-1900-0000-f840-4fb7510a0000 pid=2641->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 82B guuid=87516c9d-1900-0000-f840-4fb7640a0000 pid=2660->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 133B guuid=0b89c0a0-1900-0000-f840-4fb7720a0000 pid=2674->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 82B guuid=8dd517a6-1900-0000-f840-4fb7830a0000 pid=2691->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=85786aab-1900-0000-f840-4fb7940a0000 pid=2708->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=81c6aeb0-1900-0000-f840-4fb7a80a0000 pid=2728->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=c836d6b3-1900-0000-f840-4fb7b30a0000 pid=2739->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=eab167bc-1900-0000-f840-4fb7ca0a0000 pid=2762->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 135B guuid=d9a50dbe-1900-0000-f840-4fb7cb0a0000 pid=2763->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 84B guuid=7d9c4ec4-1900-0000-f840-4fb7db0a0000 pid=2779->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 133B guuid=9b6451c6-1900-0000-f840-4fb7de0a0000 pid=2782->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 82B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=73b4cfc9-1900-0000-f840-4fb7e70a0000 pid=2791->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792 /tmp/xpx86 net send-data zombie guuid=73b4cfc9-1900-0000-f840-4fb7e70a0000 pid=2791->guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792 clone guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 9c578459-fc2d-5995-9925-ebe708f9b2a3 94.156.152.67:18129 guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792->9c578459-fc2d-5995-9925-ebe708f9b2a3 send: 14B guuid=ae1d16ca-1900-0000-f840-4fb7ea0a0000 pid=2794 /tmp/xpx86 guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792->guuid=ae1d16ca-1900-0000-f840-4fb7ea0a0000 pid=2794 clone guuid=d07a1bca-1900-0000-f840-4fb7eb0a0000 pid=2795 /tmp/xpx86 guuid=8e6309ca-1900-0000-f840-4fb7e80a0000 pid=2792->guuid=d07a1bca-1900-0000-f840-4fb7eb0a0000 pid=2795 clone guuid=3ef713ca-1900-0000-f840-4fb7e90a0000 pid=2793->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=4133e0cc-1900-0000-f840-4fb7f10a0000 pid=2801->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B guuid=e1bb1bd2-1900-0000-f840-4fb7fa0a0000 pid=2810->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 134B guuid=b77188d6-1900-0000-f840-4fb7fe0a0000 pid=2814->1761238b-cda9-5bdb-a690-4f2e3689b082 send: 83B
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-18 21:17:16 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0f4570f98ddcbaa032069fcb94608143078eab427008519169c32d8662563bc0

(this sample)

  
Delivery method
Distributed via web download

Comments