MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1e9bddb6ecbfa47df9c31065029ee428f45f312f12afcef6875b8a92ce3c8612. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 1e9bddb6ecbfa47df9c31065029ee428f45f312f12afcef6875b8a92ce3c8612
SHA3-384 hash: fbf72e0a2432d9593b5517d1871227a351138f9b29c7e66066af5b4e8c614dadf42099d57d337f9dfd9f743b0288bbe6
SHA1 hash: 3c070704478fab1a733ba5ac47cf5f40e83cd5e5
MD5 hash: 109e5ffbac69909df7ad9dfb59eac1f7
humanhash: indigo-carbon-december-ohio
File name:ok
Download: download sample
Signature Mirai
File size:1'608 bytes
First seen:2026-06-07 17:39:08 UTC
Last seen:2026-06-07 23:36:08 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:zmsE5QVDuKwi1MV0fV0/ctbAUsZTKIu7lSCWmZ+Hh1:75uXIsVZTKIu7lZZ+7
TLSH T10B310AAF0B0A3ACD5109EA7573621559D064EACA209FE760FF8D0D7BB1885483359B0F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/fa4cc9n/an/an/a
http://45.205.1.59/697157n/an/an/a
http://45.205.1.59/0e6dben/an/an/a
http://45.205.1.59/d5cc63n/an/an/a
http://45.205.1.59/6fb4fdn/an/an/a
http://45.205.1.59/b0d000n/an/an/a
http://45.205.1.59/1a076bn/an/an/a
http://45.205.1.59/42f6efn/an/an/a
http://45.205.1.59/d037d3n/an/an/a
http://45.205.1.59/4c4cf6n/an/an/a
http://45.205.1.59/a9709cn/an/an/a
http://45.205.1.59/5d7e1en/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=e1ce3a63-1800-0000-b210-84635d0c0000 pid=3165 /usr/bin/sudo guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173 /tmp/sample.bin guuid=e1ce3a63-1800-0000-b210-84635d0c0000 pid=3165->guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173 execve guuid=ecec5066-1800-0000-b210-8463660c0000 pid=3174 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=ecec5066-1800-0000-b210-8463660c0000 pid=3174 execve guuid=f2d84c9e-1800-0000-b210-8463970c0000 pid=3223 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f2d84c9e-1800-0000-b210-8463970c0000 pid=3223 execve guuid=716895d9-1800-0000-b210-8463dd0c0000 pid=3293 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=716895d9-1800-0000-b210-8463dd0c0000 pid=3293 execve guuid=d26d30da-1800-0000-b210-8463df0c0000 pid=3295 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=d26d30da-1800-0000-b210-8463df0c0000 pid=3295 clone guuid=2b62eddb-1800-0000-b210-8463e10c0000 pid=3297 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=2b62eddb-1800-0000-b210-8463e10c0000 pid=3297 execve guuid=6100c4e0-1800-0000-b210-8463e20c0000 pid=3298 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=6100c4e0-1800-0000-b210-8463e20c0000 pid=3298 execve guuid=0aa554e1-1800-0000-b210-8463e40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=0aa554e1-1800-0000-b210-8463e40c0000 pid=3300 execve guuid=74242f18-1900-0000-b210-8463330d0000 pid=3379 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=74242f18-1900-0000-b210-8463330d0000 pid=3379 execve guuid=dea63a51-1900-0000-b210-8463b00d0000 pid=3504 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=dea63a51-1900-0000-b210-8463b00d0000 pid=3504 execve guuid=3bb78651-1900-0000-b210-8463b10d0000 pid=3505 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=3bb78651-1900-0000-b210-8463b10d0000 pid=3505 clone guuid=bd531f52-1900-0000-b210-8463b50d0000 pid=3509 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=bd531f52-1900-0000-b210-8463b50d0000 pid=3509 execve guuid=02e48857-1900-0000-b210-8463ba0d0000 pid=3514 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=02e48857-1900-0000-b210-8463ba0d0000 pid=3514 execve guuid=167ce557-1900-0000-b210-8463bb0d0000 pid=3515 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=167ce557-1900-0000-b210-8463bb0d0000 pid=3515 execve guuid=9ee8b78e-1900-0000-b210-8463220e0000 pid=3618 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=9ee8b78e-1900-0000-b210-8463220e0000 pid=3618 execve guuid=e2a51dc6-1900-0000-b210-8463f70e0000 pid=3831 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=e2a51dc6-1900-0000-b210-8463f70e0000 pid=3831 execve guuid=47166ec6-1900-0000-b210-8463f80e0000 pid=3832 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=47166ec6-1900-0000-b210-8463f80e0000 pid=3832 clone guuid=e4cd0ac7-1900-0000-b210-8463fb0e0000 pid=3835 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=e4cd0ac7-1900-0000-b210-8463fb0e0000 pid=3835 execve guuid=122757c7-1900-0000-b210-8463fd0e0000 pid=3837 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=122757c7-1900-0000-b210-8463fd0e0000 pid=3837 execve guuid=10deebc7-1900-0000-b210-8463ff0e0000 pid=3839 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=10deebc7-1900-0000-b210-8463ff0e0000 pid=3839 execve guuid=761a21ff-1900-0000-b210-8463900f0000 pid=3984 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=761a21ff-1900-0000-b210-8463900f0000 pid=3984 execve guuid=c3dc8536-1a00-0000-b210-846337100000 pid=4151 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=c3dc8536-1a00-0000-b210-846337100000 pid=4151 execve guuid=e0fa2537-1a00-0000-b210-84633b100000 pid=4155 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=e0fa2537-1a00-0000-b210-84633b100000 pid=4155 clone guuid=c92b5438-1a00-0000-b210-84633d100000 pid=4157 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=c92b5438-1a00-0000-b210-84633d100000 pid=4157 execve guuid=41d0ec3a-1a00-0000-b210-846346100000 pid=4166 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=41d0ec3a-1a00-0000-b210-846346100000 pid=4166 execve guuid=3203713b-1a00-0000-b210-846349100000 pid=4169 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=3203713b-1a00-0000-b210-846349100000 pid=4169 execve guuid=eab82273-1a00-0000-b210-8463f0100000 pid=4336 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=eab82273-1a00-0000-b210-8463f0100000 pid=4336 execve guuid=235019ab-1a00-0000-b210-846396110000 pid=4502 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=235019ab-1a00-0000-b210-846396110000 pid=4502 execve guuid=f6f989ab-1a00-0000-b210-846397110000 pid=4503 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f6f989ab-1a00-0000-b210-846397110000 pid=4503 clone guuid=0255c1ac-1a00-0000-b210-84639f110000 pid=4511 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=0255c1ac-1a00-0000-b210-84639f110000 pid=4511 execve guuid=87aa3cb2-1a00-0000-b210-8463ab110000 pid=4523 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=87aa3cb2-1a00-0000-b210-8463ab110000 pid=4523 execve guuid=eb5bb8b2-1a00-0000-b210-8463ac110000 pid=4524 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=eb5bb8b2-1a00-0000-b210-8463ac110000 pid=4524 execve guuid=8a1085dc-1a00-0000-b210-846322120000 pid=4642 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=8a1085dc-1a00-0000-b210-846322120000 pid=4642 execve guuid=cfbc2f07-1b00-0000-b210-84638c120000 pid=4748 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=cfbc2f07-1b00-0000-b210-84638c120000 pid=4748 execve guuid=968fb007-1b00-0000-b210-84638e120000 pid=4750 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=968fb007-1b00-0000-b210-84638e120000 pid=4750 clone guuid=cfdfc108-1b00-0000-b210-846393120000 pid=4755 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=cfdfc108-1b00-0000-b210-846393120000 pid=4755 execve guuid=b8793009-1b00-0000-b210-846397120000 pid=4759 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=b8793009-1b00-0000-b210-846397120000 pid=4759 execve guuid=0c0db009-1b00-0000-b210-846398120000 pid=4760 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=0c0db009-1b00-0000-b210-846398120000 pid=4760 execve guuid=a6cb5f41-1b00-0000-b210-846308130000 pid=4872 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=a6cb5f41-1b00-0000-b210-846308130000 pid=4872 execve guuid=6fcec97a-1b00-0000-b210-84639c130000 pid=5020 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=6fcec97a-1b00-0000-b210-84639c130000 pid=5020 execve guuid=319c0a7b-1b00-0000-b210-84639e130000 pid=5022 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=319c0a7b-1b00-0000-b210-84639e130000 pid=5022 clone guuid=358f4f7d-1b00-0000-b210-8463a8130000 pid=5032 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=358f4f7d-1b00-0000-b210-8463a8130000 pid=5032 execve guuid=dc8dae80-1b00-0000-b210-8463b0130000 pid=5040 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=dc8dae80-1b00-0000-b210-8463b0130000 pid=5040 execve guuid=209b2381-1b00-0000-b210-8463b2130000 pid=5042 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=209b2381-1b00-0000-b210-8463b2130000 pid=5042 execve guuid=306c4aaa-1b00-0000-b210-846327140000 pid=5159 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=306c4aaa-1b00-0000-b210-846327140000 pid=5159 execve guuid=cb19a3d6-1b00-0000-b210-846390140000 pid=5264 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=cb19a3d6-1b00-0000-b210-846390140000 pid=5264 execve guuid=7a8d64d7-1b00-0000-b210-846391140000 pid=5265 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=7a8d64d7-1b00-0000-b210-846391140000 pid=5265 clone guuid=53a148d8-1b00-0000-b210-846393140000 pid=5267 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=53a148d8-1b00-0000-b210-846393140000 pid=5267 execve guuid=f0ba4cda-1b00-0000-b210-846394140000 pid=5268 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f0ba4cda-1b00-0000-b210-846394140000 pid=5268 execve guuid=2621a7da-1b00-0000-b210-846395140000 pid=5269 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=2621a7da-1b00-0000-b210-846395140000 pid=5269 execve guuid=f3e54803-1c00-0000-b210-8463a1140000 pid=5281 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f3e54803-1c00-0000-b210-8463a1140000 pid=5281 execve guuid=40e7332f-1c00-0000-b210-8463a2140000 pid=5282 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=40e7332f-1c00-0000-b210-8463a2140000 pid=5282 execve guuid=94538e2f-1c00-0000-b210-8463a3140000 pid=5283 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=94538e2f-1c00-0000-b210-8463a3140000 pid=5283 clone guuid=b01f4930-1c00-0000-b210-8463a5140000 pid=5285 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=b01f4930-1c00-0000-b210-8463a5140000 pid=5285 execve guuid=1fd02d35-1c00-0000-b210-8463a6140000 pid=5286 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=1fd02d35-1c00-0000-b210-8463a6140000 pid=5286 execve guuid=f9088a35-1c00-0000-b210-8463a7140000 pid=5287 /usr/bin/wget net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f9088a35-1c00-0000-b210-8463a7140000 pid=5287 execve guuid=7a16435f-1c00-0000-b210-8463a8140000 pid=5288 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=7a16435f-1c00-0000-b210-8463a8140000 pid=5288 execve guuid=0515217f-1c00-0000-b210-8463a9140000 pid=5289 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=0515217f-1c00-0000-b210-8463a9140000 pid=5289 execve guuid=58d17c7f-1c00-0000-b210-8463aa140000 pid=5290 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=58d17c7f-1c00-0000-b210-8463aa140000 pid=5290 clone guuid=8a35e07f-1c00-0000-b210-8463ac140000 pid=5292 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=8a35e07f-1c00-0000-b210-8463ac140000 pid=5292 execve guuid=54ec3780-1c00-0000-b210-8463ad140000 pid=5293 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=54ec3780-1c00-0000-b210-8463ad140000 pid=5293 execve guuid=80918480-1c00-0000-b210-8463ae140000 pid=5294 /usr/bin/wget net send-data guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=80918480-1c00-0000-b210-8463ae140000 pid=5294 execve guuid=8e4c989c-1c00-0000-b210-8463af140000 pid=5295 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=8e4c989c-1c00-0000-b210-8463af140000 pid=5295 execve guuid=83b060ba-1c00-0000-b210-8463b7140000 pid=5303 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=83b060ba-1c00-0000-b210-8463b7140000 pid=5303 execve guuid=9a6cc3ba-1c00-0000-b210-8463b8140000 pid=5304 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=9a6cc3ba-1c00-0000-b210-8463b8140000 pid=5304 clone guuid=b6253abb-1c00-0000-b210-8463ba140000 pid=5306 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=b6253abb-1c00-0000-b210-8463ba140000 pid=5306 execve guuid=5b2ca3bb-1c00-0000-b210-8463bb140000 pid=5307 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=5b2ca3bb-1c00-0000-b210-8463bb140000 pid=5307 execve guuid=19a306bc-1c00-0000-b210-8463bc140000 pid=5308 /usr/bin/wget net send-data guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=19a306bc-1c00-0000-b210-8463bc140000 pid=5308 execve guuid=a4db5fd8-1c00-0000-b210-8463bd140000 pid=5309 /usr/bin/curl net send-data write-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=a4db5fd8-1c00-0000-b210-8463bd140000 pid=5309 execve guuid=9d3af7f9-1c00-0000-b210-8463be140000 pid=5310 /usr/bin/chmod guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=9d3af7f9-1c00-0000-b210-8463be140000 pid=5310 execve guuid=13355cfa-1c00-0000-b210-8463bf140000 pid=5311 /usr/bin/bash guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=13355cfa-1c00-0000-b210-8463bf140000 pid=5311 clone guuid=f1c9b1fa-1c00-0000-b210-8463c1140000 pid=5313 /usr/bin/rm delete-file guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=f1c9b1fa-1c00-0000-b210-8463c1140000 pid=5313 execve guuid=33ed44fb-1c00-0000-b210-8463c2140000 pid=5314 /usr/bin/rm guuid=1c26f165-1800-0000-b210-8463650c0000 pid=3173->guuid=33ed44fb-1c00-0000-b210-8463c2140000 pid=5314 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=ecec5066-1800-0000-b210-8463660c0000 pid=3174->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f2d84c9e-1800-0000-b210-8463970c0000 pid=3223->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=0aa554e1-1800-0000-b210-8463e40c0000 pid=3300->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=74242f18-1900-0000-b210-8463330d0000 pid=3379->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=167ce557-1900-0000-b210-8463bb0d0000 pid=3515->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=9ee8b78e-1900-0000-b210-8463220e0000 pid=3618->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=10deebc7-1900-0000-b210-8463ff0e0000 pid=3839->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=761a21ff-1900-0000-b210-8463900f0000 pid=3984->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3203713b-1a00-0000-b210-846349100000 pid=4169->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=eab82273-1a00-0000-b210-8463f0100000 pid=4336->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=eb5bb8b2-1a00-0000-b210-8463ac110000 pid=4524->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=8a1085dc-1a00-0000-b210-846322120000 pid=4642->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=0c0db009-1b00-0000-b210-846398120000 pid=4760->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a6cb5f41-1b00-0000-b210-846308130000 pid=4872->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=209b2381-1b00-0000-b210-8463b2130000 pid=5042->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=306c4aaa-1b00-0000-b210-846327140000 pid=5159->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=2621a7da-1b00-0000-b210-846395140000 pid=5269->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f3e54803-1c00-0000-b210-8463a1140000 pid=5281->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f9088a35-1c00-0000-b210-8463a7140000 pid=5287->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=7a16435f-1c00-0000-b210-8463a8140000 pid=5288->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=01039c7f-1c00-0000-b210-8463ab140000 pid=5291 /usr/bin/bash guuid=58d17c7f-1c00-0000-b210-8463aa140000 pid=5290->guuid=01039c7f-1c00-0000-b210-8463ab140000 pid=5291 clone guuid=80918480-1c00-0000-b210-8463ae140000 pid=5294->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=8e4c989c-1c00-0000-b210-8463af140000 pid=5295->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=e031e8ba-1c00-0000-b210-8463b9140000 pid=5305 /usr/bin/bash guuid=9a6cc3ba-1c00-0000-b210-8463b8140000 pid=5304->guuid=e031e8ba-1c00-0000-b210-8463b9140000 pid=5305 clone guuid=19a306bc-1c00-0000-b210-8463bc140000 pid=5308->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a4db5fd8-1c00-0000-b210-8463bd140000 pid=5309->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=96698ffa-1c00-0000-b210-8463c0140000 pid=5312 /usr/bin/bash guuid=13355cfa-1c00-0000-b210-8463bf140000 pid=5311->guuid=96698ffa-1c00-0000-b210-8463c0140000 pid=5312 clone
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1e9bddb6ecbfa47df9c31065029ee428f45f312f12afcef6875b8a92ce3c8612

(this sample)

  
Delivery method
Distributed via web download

Comments