MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 140097b303ea8e3cb68287ee7fae37ce03eb2606519ae80f8f04a4b9cd40a88d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 140097b303ea8e3cb68287ee7fae37ce03eb2606519ae80f8f04a4b9cd40a88d
SHA3-384 hash: a5f4fdbabf501775a6901665ed841316a2761746746599b97a74f745b692bb8a30d98f8c9dc04c34020d9ff691416fd9
SHA1 hash: c9a0350ca0cf43d72768942afefb0079c8d7b4c4
MD5 hash: 4210691b5f7fb9b11a2ad20a423dc175
humanhash: johnny-lake-two-emma
File name:bins.sh
Download: download sample
Signature Mirai
File size:1'154 bytes
First seen:2025-10-15 15:33:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:t/dhrNIvgKOpbZpWFMH6NNI79fKXses8NNLd:tr5pCMa49fh6NNd
TLSH T17821309F98513B8A4DD4FF897171480C7019D38B28E64BD9EDAD54BD81BD5183027B87
Magika csv
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://23.177.185.39/garmn/an/aelf ua-wget
http://23.177.185.39/garm558b3a79908d27434eeca74e2c54476fb38b2b93b540abc04f7315bde694a914a Miraiarm elf geofenced mirai ua-wget USA
http://23.177.185.39/garm60c1313445a60d4b30b3f7f51f71a338ed42422d5f28e200a40ef259a40eeee4a Gafgytarm elf gafgyt geofenced ua-wget USA
http://23.177.185.39/garm770116c88989dac84c982c6bcd364ee6f6a5b9dd22e8a295d209ce8cc72ab2124 Miraiarm elf geofenced mirai ua-wget USA
http://23.177.185.39/gmips7ad355b06d01dd98b4eb6edb6415cd4642d328a2925ec3cd70ebf6b871ffc04e Miraielf geofenced mips mirai ua-wget USA
http://23.177.185.39/gmpslba80287beeb7e1e12ee4af4cd70084a313da19733bc37bb52d8e79ecbc0b48ba Miraielf geofenced mips mirai ua-wget USA
http://23.177.185.39/x86_647e02164c352397c011317df0cff9c6b3ec66eb749f5c68dcca67c3c6f50f86a6 Miraielf mirai ua-wget
http://23.177.185.39/armf6038ff963fc43473bd69ee8b571b6bcdc88d7bb3231ec5727e835232edee6a7 Miraielf mirai ua-wget
http://23.177.185.39/arm5b5f97c4c0ff408de365da6735bf940d1a6a7f7465be68509db8e313f3dcf174f Miraielf gafgyt mirai ua-wget
http://23.177.185.39/arm6625c60b9a8b0347d5a3988d73bf19d9c5bc9bf126fa8720dd28c648edb4a0975 Miraielf gafgyt mirai ua-wget
http://23.177.185.39/arm7ffe536b3d11dd297b8155ecf55695ef88518cc6e35976efed155b6328444bfb5 Miraielf mirai ua-wget
http://23.177.185.39/mips2cae01a9c5ccb06c91d94ba45a9aaec9f804f60f9bf86cdf97daf5ceacae8f4f Mirai32-bit elf gafgyt mirai Mozi
http://23.177.185.39/mpsl9b9764585122f6e0d842fb301963fed0cb6cba5a12740fec2c660d1f636bafd5 Miraielf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
text
First seen:
2025-10-15T08:47:00Z UTC
Last seen:
2025-10-16T18:24:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2ecce6ca-1600-0000-8b0d-2f64fa0c0000 pid=3322 /usr/bin/sudo guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326 /tmp/sample.bin guuid=2ecce6ca-1600-0000-8b0d-2f64fa0c0000 pid=3322->guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326 execve guuid=ab154acd-1600-0000-8b0d-2f64000d0000 pid=3328 /usr/bin/mkdir guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=ab154acd-1600-0000-8b0d-2f64000d0000 pid=3328 execve guuid=93eba3cd-1600-0000-8b0d-2f64020d0000 pid=3330 /usr/bin/wget net send-data guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=93eba3cd-1600-0000-8b0d-2f64020d0000 pid=3330 execve guuid=c862e7e0-1600-0000-8b0d-2f642d0d0000 pid=3373 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=c862e7e0-1600-0000-8b0d-2f642d0d0000 pid=3373 execve guuid=470761e1-1600-0000-8b0d-2f64300d0000 pid=3376 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=470761e1-1600-0000-8b0d-2f64300d0000 pid=3376 clone guuid=ba0371e1-1600-0000-8b0d-2f64310d0000 pid=3377 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=ba0371e1-1600-0000-8b0d-2f64310d0000 pid=3377 execve guuid=c549e6e1-1600-0000-8b0d-2f64330d0000 pid=3379 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=c549e6e1-1600-0000-8b0d-2f64330d0000 pid=3379 execve guuid=5586b512-1700-0000-8b0d-2f648e0d0000 pid=3470 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=5586b512-1700-0000-8b0d-2f648e0d0000 pid=3470 execve guuid=a8373813-1700-0000-8b0d-2f64900d0000 pid=3472 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=a8373813-1700-0000-8b0d-2f64900d0000 pid=3472 clone guuid=63481d14-1700-0000-8b0d-2f64940d0000 pid=3476 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=63481d14-1700-0000-8b0d-2f64940d0000 pid=3476 execve guuid=4d937614-1700-0000-8b0d-2f64960d0000 pid=3478 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=4d937614-1700-0000-8b0d-2f64960d0000 pid=3478 execve guuid=0b80c940-1700-0000-8b0d-2f64ec0d0000 pid=3564 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=0b80c940-1700-0000-8b0d-2f64ec0d0000 pid=3564 execve guuid=b41f3141-1700-0000-8b0d-2f64ee0d0000 pid=3566 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=b41f3141-1700-0000-8b0d-2f64ee0d0000 pid=3566 clone guuid=612ff441-1700-0000-8b0d-2f64f10d0000 pid=3569 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=612ff441-1700-0000-8b0d-2f64f10d0000 pid=3569 execve guuid=005a6742-1700-0000-8b0d-2f64f30d0000 pid=3571 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=005a6742-1700-0000-8b0d-2f64f30d0000 pid=3571 execve guuid=aadb026f-1700-0000-8b0d-2f64430e0000 pid=3651 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=aadb026f-1700-0000-8b0d-2f64430e0000 pid=3651 execve guuid=61f17a6f-1700-0000-8b0d-2f64450e0000 pid=3653 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=61f17a6f-1700-0000-8b0d-2f64450e0000 pid=3653 clone guuid=205a7570-1700-0000-8b0d-2f64480e0000 pid=3656 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=205a7570-1700-0000-8b0d-2f64480e0000 pid=3656 execve guuid=6749ef70-1700-0000-8b0d-2f64490e0000 pid=3657 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=6749ef70-1700-0000-8b0d-2f64490e0000 pid=3657 execve guuid=6f5d249e-1700-0000-8b0d-2f64b60e0000 pid=3766 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=6f5d249e-1700-0000-8b0d-2f64b60e0000 pid=3766 execve guuid=3c8e959e-1700-0000-8b0d-2f64b80e0000 pid=3768 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=3c8e959e-1700-0000-8b0d-2f64b80e0000 pid=3768 clone guuid=8578879f-1700-0000-8b0d-2f64bc0e0000 pid=3772 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=8578879f-1700-0000-8b0d-2f64bc0e0000 pid=3772 execve guuid=79daed9f-1700-0000-8b0d-2f64be0e0000 pid=3774 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=79daed9f-1700-0000-8b0d-2f64be0e0000 pid=3774 execve guuid=144f3bd4-1700-0000-8b0d-2f644c0f0000 pid=3916 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=144f3bd4-1700-0000-8b0d-2f644c0f0000 pid=3916 execve guuid=036cb4d4-1700-0000-8b0d-2f644e0f0000 pid=3918 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=036cb4d4-1700-0000-8b0d-2f644e0f0000 pid=3918 clone guuid=1e8b17d7-1700-0000-8b0d-2f64520f0000 pid=3922 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=1e8b17d7-1700-0000-8b0d-2f64520f0000 pid=3922 execve guuid=094ca0d7-1700-0000-8b0d-2f64530f0000 pid=3923 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=094ca0d7-1700-0000-8b0d-2f64530f0000 pid=3923 execve guuid=8a1d7e03-1800-0000-8b0d-2f64bf0f0000 pid=4031 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=8a1d7e03-1800-0000-8b0d-2f64bf0f0000 pid=4031 execve guuid=401bf203-1800-0000-8b0d-2f64c10f0000 pid=4033 /tmp/1/x86_64 net guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=401bf203-1800-0000-8b0d-2f64c10f0000 pid=4033 execve guuid=f3b42504-1800-0000-8b0d-2f64c30f0000 pid=4035 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=f3b42504-1800-0000-8b0d-2f64c30f0000 pid=4035 execve guuid=82908204-1800-0000-8b0d-2f64c50f0000 pid=4037 /usr/bin/wget net send-data guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=82908204-1800-0000-8b0d-2f64c50f0000 pid=4037 execve guuid=ef3d6718-1800-0000-8b0d-2f640f100000 pid=4111 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=ef3d6718-1800-0000-8b0d-2f640f100000 pid=4111 execve guuid=8557b818-1800-0000-8b0d-2f6411100000 pid=4113 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=8557b818-1800-0000-8b0d-2f6411100000 pid=4113 clone guuid=31d0c818-1800-0000-8b0d-2f6412100000 pid=4114 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=31d0c818-1800-0000-8b0d-2f6412100000 pid=4114 execve guuid=ce541819-1800-0000-8b0d-2f6414100000 pid=4116 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=ce541819-1800-0000-8b0d-2f6414100000 pid=4116 execve guuid=9c69e644-1800-0000-8b0d-2f6478100000 pid=4216 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=9c69e644-1800-0000-8b0d-2f6478100000 pid=4216 execve guuid=f6866545-1800-0000-8b0d-2f647a100000 pid=4218 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=f6866545-1800-0000-8b0d-2f647a100000 pid=4218 clone guuid=9b2aa547-1800-0000-8b0d-2f647f100000 pid=4223 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=9b2aa547-1800-0000-8b0d-2f647f100000 pid=4223 execve guuid=2cfa1048-1800-0000-8b0d-2f6481100000 pid=4225 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=2cfa1048-1800-0000-8b0d-2f6481100000 pid=4225 execve guuid=b873d674-1800-0000-8b0d-2f64f1100000 pid=4337 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=b873d674-1800-0000-8b0d-2f64f1100000 pid=4337 execve guuid=0ff74275-1800-0000-8b0d-2f64f5100000 pid=4341 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=0ff74275-1800-0000-8b0d-2f64f5100000 pid=4341 clone guuid=e462fc75-1800-0000-8b0d-2f64f8100000 pid=4344 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=e462fc75-1800-0000-8b0d-2f64f8100000 pid=4344 execve guuid=2ca85176-1800-0000-8b0d-2f64fa100000 pid=4346 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=2ca85176-1800-0000-8b0d-2f64fa100000 pid=4346 execve guuid=24f4f5a2-1800-0000-8b0d-2f646c110000 pid=4460 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=24f4f5a2-1800-0000-8b0d-2f646c110000 pid=4460 execve guuid=62f54ca3-1800-0000-8b0d-2f6470110000 pid=4464 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=62f54ca3-1800-0000-8b0d-2f6470110000 pid=4464 clone guuid=7ff948a4-1800-0000-8b0d-2f6474110000 pid=4468 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=7ff948a4-1800-0000-8b0d-2f6474110000 pid=4468 execve guuid=4d999ca4-1800-0000-8b0d-2f6476110000 pid=4470 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=4d999ca4-1800-0000-8b0d-2f6476110000 pid=4470 execve guuid=4fb4d5d9-1800-0000-8b0d-2f64fb110000 pid=4603 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=4fb4d5d9-1800-0000-8b0d-2f64fb110000 pid=4603 execve guuid=644854da-1800-0000-8b0d-2f64fd110000 pid=4605 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=644854da-1800-0000-8b0d-2f64fd110000 pid=4605 clone guuid=fb3660db-1800-0000-8b0d-2f6403120000 pid=4611 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=fb3660db-1800-0000-8b0d-2f6403120000 pid=4611 execve guuid=1844d3db-1800-0000-8b0d-2f6404120000 pid=4612 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=1844d3db-1800-0000-8b0d-2f6404120000 pid=4612 execve guuid=27cbe809-1900-0000-8b0d-2f6471120000 pid=4721 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=27cbe809-1900-0000-8b0d-2f6471120000 pid=4721 execve guuid=6984610a-1900-0000-8b0d-2f6472120000 pid=4722 /usr/bin/dash guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=6984610a-1900-0000-8b0d-2f6472120000 pid=4722 clone guuid=e7263f0c-1900-0000-8b0d-2f6477120000 pid=4727 /usr/bin/rm guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=e7263f0c-1900-0000-8b0d-2f6477120000 pid=4727 execve guuid=cbf6a40c-1900-0000-8b0d-2f6479120000 pid=4729 /usr/bin/wget net send-data write-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=cbf6a40c-1900-0000-8b0d-2f6479120000 pid=4729 execve guuid=733c823a-1900-0000-8b0d-2f64e9120000 pid=4841 /usr/bin/chmod guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=733c823a-1900-0000-8b0d-2f64e9120000 pid=4841 execve guuid=0c1bfc3a-1900-0000-8b0d-2f64eb120000 pid=4843 /tmp/1/x86_64 net guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=0c1bfc3a-1900-0000-8b0d-2f64eb120000 pid=4843 execve guuid=d42fd4ee-1900-0000-8b0d-2f6428140000 pid=5160 /usr/bin/rm delete-file guuid=00f30ecd-1600-0000-8b0d-2f64fe0c0000 pid=3326->guuid=d42fd4ee-1900-0000-8b0d-2f6428140000 pid=5160 execve ba55188c-1d8c-531d-84cb-0b022f7a1844 23.177.185.39:80 guuid=93eba3cd-1600-0000-8b0d-2f64020d0000 pid=3330->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=c549e6e1-1600-0000-8b0d-2f64330d0000 pid=3379->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=4d937614-1700-0000-8b0d-2f64960d0000 pid=3478->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=005a6742-1700-0000-8b0d-2f64f30d0000 pid=3571->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=6749ef70-1700-0000-8b0d-2f64490e0000 pid=3657->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=79daed9f-1700-0000-8b0d-2f64be0e0000 pid=3774->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=094ca0d7-1700-0000-8b0d-2f64530f0000 pid=3923->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 134B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=401bf203-1800-0000-8b0d-2f64c10f0000 pid=4033->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e4481504-1800-0000-8b0d-2f64c20f0000 pid=4034 /tmp/1/x86_64 dns net send-data zombie guuid=401bf203-1800-0000-8b0d-2f64c10f0000 pid=4033->guuid=e4481504-1800-0000-8b0d-2f64c20f0000 pid=4034 clone ac0b4284-2aa4-5c89-80a0-995c690355af 81.169.136.222:53 guuid=e4481504-1800-0000-8b0d-2f64c20f0000 pid=4034->ac0b4284-2aa4-5c89-80a0-995c690355af send: 34B 48d6144b-2bcb-5105-880a-b486b4d6b787 loadingboats.dyn:5667 guuid=e4481504-1800-0000-8b0d-2f64c20f0000 pid=4034->48d6144b-2bcb-5105-880a-b486b4d6b787 send: 37B guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040 /tmp/1/x86_64 net guuid=e4481504-1800-0000-8b0d-2f64c20f0000 pid=4034->guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040 clone guuid=82908204-1800-0000-8b0d-2f64c50f0000 pid=4037->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 131B 114d3c68-7578-5d97-aa3f-3b17a04daf8c 188.166.240.30:2222 guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->114d3c68-7578-5d97-aa3f-3b17a04daf8c con guuid=69393805-1800-0000-8b0d-2f64c90f0000 pid=4041 /usr/bin/dash guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->guuid=69393805-1800-0000-8b0d-2f64c90f0000 pid=4041 execve guuid=97f7af12-1800-0000-8b0d-2f64ee0f0000 pid=4078 /usr/bin/dash guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->guuid=97f7af12-1800-0000-8b0d-2f64ee0f0000 pid=4078 execve guuid=fe343313-1800-0000-8b0d-2f64f30f0000 pid=4083 /usr/bin/dash guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->guuid=fe343313-1800-0000-8b0d-2f64f30f0000 pid=4083 execve guuid=3a8aa213-1800-0000-8b0d-2f64f80f0000 pid=4088 /usr/bin/dash guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->guuid=3a8aa213-1800-0000-8b0d-2f64f80f0000 pid=4088 execve guuid=1c46d313-1800-0000-8b0d-2f64fa0f0000 pid=4090 /usr/bin/dash guuid=41da2905-1800-0000-8b0d-2f64c80f0000 pid=4040->guuid=1c46d313-1800-0000-8b0d-2f64fa0f0000 pid=4090 execve guuid=a18ba505-1800-0000-8b0d-2f64cb0f0000 pid=4043 /usr/sbin/xtables-nft-multi guuid=69393805-1800-0000-8b0d-2f64c90f0000 pid=4041->guuid=a18ba505-1800-0000-8b0d-2f64cb0f0000 pid=4043 execve guuid=4e06d512-1800-0000-8b0d-2f64f10f0000 pid=4081 /usr/bin/busybox guuid=97f7af12-1800-0000-8b0d-2f64ee0f0000 pid=4078->guuid=4e06d512-1800-0000-8b0d-2f64f10f0000 pid=4081 execve guuid=34278213-1800-0000-8b0d-2f64f50f0000 pid=4085 /usr/bin/dash guuid=fe343313-1800-0000-8b0d-2f64f30f0000 pid=4083->guuid=34278213-1800-0000-8b0d-2f64f50f0000 pid=4085 clone guuid=550fc413-1800-0000-8b0d-2f64f90f0000 pid=4089 /usr/bin/dash guuid=3a8aa213-1800-0000-8b0d-2f64f80f0000 pid=4088->guuid=550fc413-1800-0000-8b0d-2f64f90f0000 pid=4089 clone guuid=11880d14-1800-0000-8b0d-2f64fe0f0000 pid=4094 /usr/bin/busybox guuid=1c46d313-1800-0000-8b0d-2f64fa0f0000 pid=4090->guuid=11880d14-1800-0000-8b0d-2f64fe0f0000 pid=4094 execve guuid=ce541819-1800-0000-8b0d-2f6414100000 pid=4116->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=2cfa1048-1800-0000-8b0d-2f6481100000 pid=4225->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=2ca85176-1800-0000-8b0d-2f64fa100000 pid=4346->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=4d999ca4-1800-0000-8b0d-2f6476110000 pid=4470->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=1844d3db-1800-0000-8b0d-2f6404120000 pid=4612->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=cbf6a40c-1900-0000-8b0d-2f6479120000 pid=4729->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 134B guuid=0c1bfc3a-1900-0000-8b0d-2f64eb120000 pid=4843->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 257d31dd-cb0d-573a-8e60-d7fe3e6be32a 127.0.0.1:1422 guuid=0c1bfc3a-1900-0000-8b0d-2f64eb120000 pid=4843->257d31dd-cb0d-573a-8e60-d7fe3e6be32a con guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158 /tmp/1/x86_64 dns net send-data zombie guuid=0c1bfc3a-1900-0000-8b0d-2f64eb120000 pid=4843->guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158 clone guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158->48d6144b-2bcb-5105-880a-b486b4d6b787 send: 76B 5b027a48-7b62-54dd-bd92-302c77ae3608 194.36.144.87:53 guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158->5b027a48-7b62-54dd-bd92-302c77ae3608 send: 34B 1916c8ac-07bf-5360-a6f3-e42acfa320ef 91.217.137.37:53 guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158->1916c8ac-07bf-5360-a6f3-e42acfa320ef send: 170B guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164 /tmp/1/x86_64 net guuid=a9eacdee-1900-0000-8b0d-2f6426140000 pid=5158->guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164 clone guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->114d3c68-7578-5d97-aa3f-3b17a04daf8c con guuid=6a27ccef-1900-0000-8b0d-2f642d140000 pid=5165 /usr/bin/dash guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->guuid=6a27ccef-1900-0000-8b0d-2f642d140000 pid=5165 execve guuid=19cb49f0-1900-0000-8b0d-2f6431140000 pid=5169 /usr/bin/dash guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->guuid=19cb49f0-1900-0000-8b0d-2f6431140000 pid=5169 execve guuid=9cd69cf0-1900-0000-8b0d-2f6433140000 pid=5171 /usr/bin/dash guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->guuid=9cd69cf0-1900-0000-8b0d-2f6433140000 pid=5171 execve guuid=1eead7f0-1900-0000-8b0d-2f6436140000 pid=5174 /usr/bin/dash guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->guuid=1eead7f0-1900-0000-8b0d-2f6436140000 pid=5174 execve guuid=38a316f1-1900-0000-8b0d-2f6438140000 pid=5176 /usr/bin/dash guuid=27e2c6ef-1900-0000-8b0d-2f642c140000 pid=5164->guuid=38a316f1-1900-0000-8b0d-2f6438140000 pid=5176 execve guuid=d6def0ef-1900-0000-8b0d-2f642f140000 pid=5167 /usr/sbin/xtables-nft-multi guuid=6a27ccef-1900-0000-8b0d-2f642d140000 pid=5165->guuid=d6def0ef-1900-0000-8b0d-2f642f140000 pid=5167 execve guuid=21246ff0-1900-0000-8b0d-2f6432140000 pid=5170 /usr/bin/busybox guuid=19cb49f0-1900-0000-8b0d-2f6431140000 pid=5169->guuid=21246ff0-1900-0000-8b0d-2f6432140000 pid=5170 execve guuid=cd16c5f0-1900-0000-8b0d-2f6435140000 pid=5173 /usr/bin/dash guuid=9cd69cf0-1900-0000-8b0d-2f6433140000 pid=5171->guuid=cd16c5f0-1900-0000-8b0d-2f6435140000 pid=5173 clone guuid=3ebd03f1-1900-0000-8b0d-2f6437140000 pid=5175 /usr/bin/dash guuid=1eead7f0-1900-0000-8b0d-2f6436140000 pid=5174->guuid=3ebd03f1-1900-0000-8b0d-2f6437140000 pid=5175 clone guuid=23c941f1-1900-0000-8b0d-2f643a140000 pid=5178 /usr/bin/busybox guuid=38a316f1-1900-0000-8b0d-2f6438140000 pid=5176->guuid=23c941f1-1900-0000-8b0d-2f643a140000 pid=5178 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-10-15 13:41:59 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 140097b303ea8e3cb68287ee7fae37ce03eb2606519ae80f8f04a4b9cd40a88d

(this sample)

  
Delivery method
Distributed via web download

Comments