MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c0329f89241d49944a32012adee4b2eb5b66f94935a39b9a999b1ce171029fd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 1c0329f89241d49944a32012adee4b2eb5b66f94935a39b9a999b1ce171029fd
SHA3-384 hash: e84e795af7dd4ec3eabf715479be1e83747fab5583f88719c9d9974570468b70534c961bb292baa3149658481d567da1
SHA1 hash: c2b9f44e8eb4c2690a47a42ece36a859ba38fb35
MD5 hash: 249bcbf97ad77c7a9167b7c125b6f7e1
humanhash: friend-whiskey-pluto-nineteen
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'385 bytes
First seen:2025-11-23 09:05:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:Ifzp2fIdzGSSXaex5J2NrV/w2zheR922/j1G52012WNOHs2IOrhOl8S273HMDo4v:i2a6MZy71AJNODNN1Mku10+VlmPSd
TLSH T161217E8F559A1AD303098F6BB371D2D8E808C38F20E3E644FCAB4C318E959A53614E17
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.153.34.63/x86_64b3a59c31bb2b2caa6dc0806400ff5623b33016eca39113afedd8af71ce49c5bc Miraielf mirai ua-wget
http://45.153.34.63/aarch64af945e8087d7948e30bdbb92e64039714ae50a581b34f35c17cf78923c03674f Miraielf mirai ua-wget
http://45.153.34.63/armhf794e555182b294e74a7d9ea364566bb85458df33b93a25a16db1eae7a8406732 Miraielf mirai ua-wget
http://45.153.34.63/armb1c682128658c5d48b4b75876bac6e48f709e691305c4d643433a8b372ab7ae7 Miraielf mirai ua-wget
http://45.153.34.63/i686304780cc651bebe053d8ed919f1241a1677be6a12bd4087b9918f21b49d83dd4 Miraielf mirai ua-wget
http://45.153.34.63/m68k9c6c44ffea2996fa81cf14c10347e82792541fa447878a90271ff342a7aad76c Miraielf mirai ua-wget
http://45.153.34.63/mips099d29f38684c1e01d3d51d661678fafcf10e36cfc9bacc8be783c934dcb7b1e Miraielf mirai ua-wget
http://45.153.34.63/mipsel8f595816b847e22356a442bc2d58d50daacde42d6cefeeee46b64b6616313e04 Miraielf mirai ua-wget
http://45.153.34.63/powerpc64bd8203ba8b6ead4e07ccab3d85bb1a7790e60b4686644cfa5d54c56511ab753f Miraielf mirai ua-wget
http://45.153.34.63/sparccf6d394bf6a00f7bfba853d95af329da39c2016f8b7d91852ecff96eaf28630d Miraielf mirai ua-wget
http://45.153.34.63/sh4953c9e1fd3b31e50ea71020d0bde3bf8077a2383a51c7380208262598e574819 Miraielf mirai ua-wget
http://45.153.34.63/arc83e74b3614a3e21867e8d4baebcd131e81a6d9695f3d68fb1bce9a766f0c0efc Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-20T22:21:00Z UTC
Last seen:
2025-11-24T05:37:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=d6e38c5a-1a00-0000-24bc-ea58b50a0000 pid=2741 /usr/bin/sudo guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746 /tmp/sample.bin guuid=d6e38c5a-1a00-0000-24bc-ea58b50a0000 pid=2741->guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746 execve guuid=4a69e25e-1a00-0000-24bc-ea58be0a0000 pid=2750 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=4a69e25e-1a00-0000-24bc-ea58be0a0000 pid=2750 execve guuid=05bd206b-1a00-0000-24bc-ea58c70a0000 pid=2759 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=05bd206b-1a00-0000-24bc-ea58c70a0000 pid=2759 execve guuid=af9d2584-1a00-0000-24bc-ea58e10a0000 pid=2785 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=af9d2584-1a00-0000-24bc-ea58e10a0000 pid=2785 execve guuid=abcb9084-1a00-0000-24bc-ea58e30a0000 pid=2787 /home/sandbox/x86_64 guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=abcb9084-1a00-0000-24bc-ea58e30a0000 pid=2787 execve guuid=6e1dbf84-1a00-0000-24bc-ea58e60a0000 pid=2790 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=6e1dbf84-1a00-0000-24bc-ea58e60a0000 pid=2790 execve guuid=bc78fb84-1a00-0000-24bc-ea58e80a0000 pid=2792 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=bc78fb84-1a00-0000-24bc-ea58e80a0000 pid=2792 execve guuid=d70acf8c-1a00-0000-24bc-ea58f40a0000 pid=2804 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=d70acf8c-1a00-0000-24bc-ea58f40a0000 pid=2804 execve guuid=c4451b96-1a00-0000-24bc-ea58060b0000 pid=2822 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=c4451b96-1a00-0000-24bc-ea58060b0000 pid=2822 execve guuid=33937d96-1a00-0000-24bc-ea58070b0000 pid=2823 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=33937d96-1a00-0000-24bc-ea58070b0000 pid=2823 clone guuid=b5441e98-1a00-0000-24bc-ea580c0b0000 pid=2828 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=b5441e98-1a00-0000-24bc-ea580c0b0000 pid=2828 execve guuid=3d329498-1a00-0000-24bc-ea580f0b0000 pid=2831 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=3d329498-1a00-0000-24bc-ea580f0b0000 pid=2831 execve guuid=82d5839f-1a00-0000-24bc-ea581e0b0000 pid=2846 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=82d5839f-1a00-0000-24bc-ea581e0b0000 pid=2846 execve guuid=1cf393a8-1a00-0000-24bc-ea58320b0000 pid=2866 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=1cf393a8-1a00-0000-24bc-ea58320b0000 pid=2866 execve guuid=76b2eea8-1a00-0000-24bc-ea58340b0000 pid=2868 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=76b2eea8-1a00-0000-24bc-ea58340b0000 pid=2868 clone guuid=4d1f7ea9-1a00-0000-24bc-ea58380b0000 pid=2872 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=4d1f7ea9-1a00-0000-24bc-ea58380b0000 pid=2872 execve guuid=3b58e9a9-1a00-0000-24bc-ea583a0b0000 pid=2874 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=3b58e9a9-1a00-0000-24bc-ea583a0b0000 pid=2874 execve guuid=87fcfbb0-1a00-0000-24bc-ea584d0b0000 pid=2893 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=87fcfbb0-1a00-0000-24bc-ea584d0b0000 pid=2893 execve guuid=c5039fb9-1a00-0000-24bc-ea58630b0000 pid=2915 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=c5039fb9-1a00-0000-24bc-ea58630b0000 pid=2915 execve guuid=9639f1b9-1a00-0000-24bc-ea58640b0000 pid=2916 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=9639f1b9-1a00-0000-24bc-ea58640b0000 pid=2916 clone guuid=8fb677ba-1a00-0000-24bc-ea58670b0000 pid=2919 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=8fb677ba-1a00-0000-24bc-ea58670b0000 pid=2919 execve guuid=cb3eb7ba-1a00-0000-24bc-ea58690b0000 pid=2921 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=cb3eb7ba-1a00-0000-24bc-ea58690b0000 pid=2921 execve guuid=9eb718c3-1a00-0000-24bc-ea58800b0000 pid=2944 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=9eb718c3-1a00-0000-24bc-ea58800b0000 pid=2944 execve guuid=655c71cf-1a00-0000-24bc-ea58900b0000 pid=2960 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=655c71cf-1a00-0000-24bc-ea58900b0000 pid=2960 execve guuid=5a51e3cf-1a00-0000-24bc-ea58910b0000 pid=2961 /home/sandbox/i686 guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=5a51e3cf-1a00-0000-24bc-ea58910b0000 pid=2961 execve guuid=192223d0-1a00-0000-24bc-ea58930b0000 pid=2963 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=192223d0-1a00-0000-24bc-ea58930b0000 pid=2963 execve guuid=48f337d7-1a00-0000-24bc-ea589b0b0000 pid=2971 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=48f337d7-1a00-0000-24bc-ea589b0b0000 pid=2971 execve guuid=79d934e0-1a00-0000-24bc-ea58aa0b0000 pid=2986 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=79d934e0-1a00-0000-24bc-ea58aa0b0000 pid=2986 execve guuid=482d5ce8-1a00-0000-24bc-ea58b90b0000 pid=3001 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=482d5ce8-1a00-0000-24bc-ea58b90b0000 pid=3001 execve guuid=909cd4e8-1a00-0000-24bc-ea58ba0b0000 pid=3002 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=909cd4e8-1a00-0000-24bc-ea58ba0b0000 pid=3002 clone guuid=5316a3e9-1a00-0000-24bc-ea58bf0b0000 pid=3007 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=5316a3e9-1a00-0000-24bc-ea58bf0b0000 pid=3007 execve guuid=e0f8ece9-1a00-0000-24bc-ea58c00b0000 pid=3008 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=e0f8ece9-1a00-0000-24bc-ea58c00b0000 pid=3008 execve guuid=0c0090f1-1a00-0000-24bc-ea58d10b0000 pid=3025 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=0c0090f1-1a00-0000-24bc-ea58d10b0000 pid=3025 execve guuid=86bcd9f9-1a00-0000-24bc-ea58dd0b0000 pid=3037 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=86bcd9f9-1a00-0000-24bc-ea58dd0b0000 pid=3037 execve guuid=76ce36fa-1a00-0000-24bc-ea58df0b0000 pid=3039 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=76ce36fa-1a00-0000-24bc-ea58df0b0000 pid=3039 clone guuid=47fd54fb-1a00-0000-24bc-ea58e50b0000 pid=3045 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=47fd54fb-1a00-0000-24bc-ea58e50b0000 pid=3045 execve guuid=0d8dbefb-1a00-0000-24bc-ea58e70b0000 pid=3047 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=0d8dbefb-1a00-0000-24bc-ea58e70b0000 pid=3047 execve guuid=eb5a2303-1b00-0000-24bc-ea58f50b0000 pid=3061 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=eb5a2303-1b00-0000-24bc-ea58f50b0000 pid=3061 execve guuid=be2d190b-1b00-0000-24bc-ea58090c0000 pid=3081 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=be2d190b-1b00-0000-24bc-ea58090c0000 pid=3081 execve guuid=dc7d6f0b-1b00-0000-24bc-ea580b0c0000 pid=3083 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=dc7d6f0b-1b00-0000-24bc-ea580b0c0000 pid=3083 clone guuid=336c320c-1b00-0000-24bc-ea580e0c0000 pid=3086 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=336c320c-1b00-0000-24bc-ea580e0c0000 pid=3086 execve guuid=3f88910c-1b00-0000-24bc-ea58100c0000 pid=3088 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=3f88910c-1b00-0000-24bc-ea58100c0000 pid=3088 execve guuid=2c446f15-1b00-0000-24bc-ea582a0c0000 pid=3114 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=2c446f15-1b00-0000-24bc-ea582a0c0000 pid=3114 execve guuid=aca0fb21-1b00-0000-24bc-ea584c0c0000 pid=3148 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=aca0fb21-1b00-0000-24bc-ea584c0c0000 pid=3148 execve guuid=bcc34f22-1b00-0000-24bc-ea584d0c0000 pid=3149 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=bcc34f22-1b00-0000-24bc-ea584d0c0000 pid=3149 clone guuid=acace922-1b00-0000-24bc-ea58510c0000 pid=3153 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=acace922-1b00-0000-24bc-ea58510c0000 pid=3153 execve guuid=206b6423-1b00-0000-24bc-ea58530c0000 pid=3155 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=206b6423-1b00-0000-24bc-ea58530c0000 pid=3155 execve guuid=97f2222b-1b00-0000-24bc-ea58660c0000 pid=3174 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=97f2222b-1b00-0000-24bc-ea58660c0000 pid=3174 execve guuid=2f61b534-1b00-0000-24bc-ea58820c0000 pid=3202 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=2f61b534-1b00-0000-24bc-ea58820c0000 pid=3202 execve guuid=602ef734-1b00-0000-24bc-ea58830c0000 pid=3203 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=602ef734-1b00-0000-24bc-ea58830c0000 pid=3203 clone guuid=9e70e335-1b00-0000-24bc-ea58870c0000 pid=3207 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=9e70e335-1b00-0000-24bc-ea58870c0000 pid=3207 execve guuid=5bf83036-1b00-0000-24bc-ea58890c0000 pid=3209 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=5bf83036-1b00-0000-24bc-ea58890c0000 pid=3209 execve guuid=6a8cd23d-1b00-0000-24bc-ea589d0c0000 pid=3229 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=6a8cd23d-1b00-0000-24bc-ea589d0c0000 pid=3229 execve guuid=76306747-1b00-0000-24bc-ea58a70c0000 pid=3239 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=76306747-1b00-0000-24bc-ea58a70c0000 pid=3239 execve guuid=9870c147-1b00-0000-24bc-ea58a80c0000 pid=3240 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=9870c147-1b00-0000-24bc-ea58a80c0000 pid=3240 clone guuid=541d7948-1b00-0000-24bc-ea58aa0c0000 pid=3242 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=541d7948-1b00-0000-24bc-ea58aa0c0000 pid=3242 execve guuid=e0f6d848-1b00-0000-24bc-ea58ab0c0000 pid=3243 /usr/bin/wget net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=e0f6d848-1b00-0000-24bc-ea58ab0c0000 pid=3243 execve guuid=918e3d4e-1b00-0000-24bc-ea58ac0c0000 pid=3244 /usr/bin/curl net send-data write-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=918e3d4e-1b00-0000-24bc-ea58ac0c0000 pid=3244 execve guuid=1cc66d55-1b00-0000-24bc-ea58b80c0000 pid=3256 /usr/bin/chmod guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=1cc66d55-1b00-0000-24bc-ea58b80c0000 pid=3256 execve guuid=6503b355-1b00-0000-24bc-ea58ba0c0000 pid=3258 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=6503b355-1b00-0000-24bc-ea58ba0c0000 pid=3258 clone guuid=7f6b5356-1b00-0000-24bc-ea58be0c0000 pid=3262 /usr/bin/rm delete-file guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=7f6b5356-1b00-0000-24bc-ea58be0c0000 pid=3262 execve guuid=798dc456-1b00-0000-24bc-ea58c00c0000 pid=3264 /usr/bin/bash guuid=61dc8a5d-1a00-0000-24bc-ea58ba0a0000 pid=2746->guuid=798dc456-1b00-0000-24bc-ea58c00c0000 pid=3264 clone b4772b93-56fe-5fc1-87ec-1f88c85ae73d 45.153.34.63:80 guuid=4a69e25e-1a00-0000-24bc-ea58be0a0000 pid=2750->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 133B guuid=05bd206b-1a00-0000-24bc-ea58c70a0000 pid=2759->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 82B guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2789 /home/sandbox/x86_64 net write-file zombie guuid=abcb9084-1a00-0000-24bc-ea58e30a0000 pid=2787->guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2789 clone c015b0a4-f60c-532c-b5c1-9ec2e7482329 45.153.34.63:1337 guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2789->c015b0a4-f60c-532c-b5c1-9ec2e7482329 con guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2791 /home/sandbox/x86_64 guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2789->guuid=5762af84-1a00-0000-24bc-ea58e50a0000 pid=2791 clone guuid=bc78fb84-1a00-0000-24bc-ea58e80a0000 pid=2792->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 134B guuid=d70acf8c-1a00-0000-24bc-ea58f40a0000 pid=2804->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 83B guuid=3d329498-1a00-0000-24bc-ea580f0b0000 pid=2831->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 132B guuid=82d5839f-1a00-0000-24bc-ea581e0b0000 pid=2846->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 81B guuid=3b58e9a9-1a00-0000-24bc-ea583a0b0000 pid=2874->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 130B guuid=87fcfbb0-1a00-0000-24bc-ea584d0b0000 pid=2893->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 79B guuid=cb3eb7ba-1a00-0000-24bc-ea58690b0000 pid=2921->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 131B guuid=9eb718c3-1a00-0000-24bc-ea58800b0000 pid=2944->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 80B guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2962 /home/sandbox/i686 delete-file net write-file zombie guuid=5a51e3cf-1a00-0000-24bc-ea58910b0000 pid=2961->guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2962 clone guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2962->c015b0a4-f60c-532c-b5c1-9ec2e7482329 con guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2964 /home/sandbox/i686 guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2962->guuid=b68517d0-1a00-0000-24bc-ea58920b0000 pid=2964 clone guuid=48f337d7-1a00-0000-24bc-ea589b0b0000 pid=2971->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 131B guuid=79d934e0-1a00-0000-24bc-ea58aa0b0000 pid=2986->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 80B guuid=e0f8ece9-1a00-0000-24bc-ea58c00b0000 pid=3008->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 131B guuid=0c0090f1-1a00-0000-24bc-ea58d10b0000 pid=3025->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 80B guuid=0d8dbefb-1a00-0000-24bc-ea58e70b0000 pid=3047->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 133B guuid=eb5a2303-1b00-0000-24bc-ea58f50b0000 pid=3061->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 82B guuid=3f88910c-1b00-0000-24bc-ea58100c0000 pid=3088->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 136B guuid=2c446f15-1b00-0000-24bc-ea582a0c0000 pid=3114->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 85B guuid=206b6423-1b00-0000-24bc-ea58530c0000 pid=3155->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 132B guuid=97f2222b-1b00-0000-24bc-ea58660c0000 pid=3174->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 81B guuid=5bf83036-1b00-0000-24bc-ea58890c0000 pid=3209->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 130B guuid=6a8cd23d-1b00-0000-24bc-ea589d0c0000 pid=3229->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 79B guuid=e0f6d848-1b00-0000-24bc-ea58ab0c0000 pid=3243->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 130B guuid=918e3d4e-1b00-0000-24bc-ea58ac0c0000 pid=3244->b4772b93-56fe-5fc1-87ec-1f88c85ae73d send: 79B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2025-11-21 03:15:25 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1c0329f89241d49944a32012adee4b2eb5b66f94935a39b9a999b1ce171029fd

(this sample)

  
Delivery method
Distributed via web download

Comments