MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fbc9d3b461fd05685a0e760d3f6e7f4e06647bfadea71302be7277d35fcea91. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 1fbc9d3b461fd05685a0e760d3f6e7f4e06647bfadea71302be7277d35fcea91
SHA3-384 hash: 80f3e4e94525aa899dc9ff094ff6f49cd19cd6e7be26c11be13beb3c5abb296a769c795177e3f0f750ebb3d19b4d8fdc
SHA1 hash: b8be68b2a3a1007fe742556fa2f2168f4ded085e
MD5 hash: 926e6a3293a8a382b0407edfeb791982
humanhash: ten-mountain-leopard-ceiling
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'433 bytes
First seen:2026-01-18 18:14:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:82a3PBy/1U1nNOhNJWsNM9ohtch10+RsZFSd:Dapy+1nE7Gitch10++a
TLSH T15321B6EED1B51BD545098F66FE715B785A2A87C320DB0A44D9C8AC3DC0B9D853630A1D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://208.84.101.162/x86_64d9eddbbc1e56a52d4419e98cfcc208f6091f77c14b038c467fa89026021e9cd8 Miraielf mirai ua-wget
http://208.84.101.162/aarch64d010b47f44bb079dfa4b5aa5a030c08e017a8a53a23aad58421192a9afbea6da Miraielf mirai ua-wget
http://208.84.101.162/armhf50934bea88366c111ff1cc62337ac849460d29497bb9d11ceb6bc1b4921ec885 Miraielf mirai ua-wget
http://208.84.101.162/armb29a3acbcf0bf44e5a281ebb00076734f7411d3ac3739fcb8f8af7d53940e2d0 Miraielf mirai ua-wget
http://208.84.101.162/i686259910bc66ad7527820f8b2c2647266732af4235c99a22d997bffa2ad00b9e87 Miraielf mirai ua-wget
http://208.84.101.162/m68k0935c58a45487fdb52516c3c4af92090bdaa982129716f60be3aef1659f41373 Miraielf mirai ua-wget
http://208.84.101.162/mipse54e863418e25c7aca34c8f2dbfee4b90b71a1e6b6465d3235e6737d89a7e3d4 Miraielf mirai ua-wget
http://208.84.101.162/mipsel7dd2a61406fa696c7fa34f7df6349f0adad8135442ec776f5a89760c683bcc8d Miraielf geofenced mips mirai ua-wget USA
http://208.84.101.162/powerpc646d078105d9e6dba8e5811ae30e15b2b9990ae9013e583f661ce6cab3f81517c4 Miraielf mirai ua-wget
http://208.84.101.162/sparc79ca3d40c53be071bf3e5764e934b32a907094742ac8cc885e34ab33fd999523 Miraielf mirai ua-wget
http://208.84.101.162/sh4d93bda010dfaaf2c41a842b3283d7dcfccf7d7d15c22b723b2594395da7004cf Miraielf mirai ua-wget
http://208.84.101.162/arcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-18T15:19:00Z UTC
Last seen:
2026-01-19T12:53:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f95b0bb3-1900-0000-0cab-a0d7340a0000 pid=2612 /usr/bin/sudo guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619 /tmp/sample.bin guuid=f95b0bb3-1900-0000-0cab-a0d7340a0000 pid=2612->guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619 execve guuid=0ea9d3b5-1900-0000-0cab-a0d73e0a0000 pid=2622 /usr/bin/wget net send-data write-file guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=0ea9d3b5-1900-0000-0cab-a0d73e0a0000 pid=2622 execve guuid=20732045-1a00-0000-0cab-a0d7570b0000 pid=2903 /usr/bin/curl net send-data write-file guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=20732045-1a00-0000-0cab-a0d7570b0000 pid=2903 execve guuid=2052f00c-1b00-0000-0cab-a0d7a30c0000 pid=3235 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=2052f00c-1b00-0000-0cab-a0d7a30c0000 pid=3235 execve guuid=952f500d-1b00-0000-0cab-a0d7a40c0000 pid=3236 /home/sandbox/x86_64 guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=952f500d-1b00-0000-0cab-a0d7a40c0000 pid=3236 execve guuid=c715850d-1b00-0000-0cab-a0d7a60c0000 pid=3238 /usr/bin/rm delete-file guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=c715850d-1b00-0000-0cab-a0d7a60c0000 pid=3238 execve guuid=f9010f0e-1b00-0000-0cab-a0d7a80c0000 pid=3240 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=f9010f0e-1b00-0000-0cab-a0d7a80c0000 pid=3240 clone guuid=a7933c0e-1b00-0000-0cab-a0d7aa0c0000 pid=3242 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=a7933c0e-1b00-0000-0cab-a0d7aa0c0000 pid=3242 clone guuid=b81a630e-1b00-0000-0cab-a0d7ab0c0000 pid=3243 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=b81a630e-1b00-0000-0cab-a0d7ab0c0000 pid=3243 execve guuid=19d5e00e-1b00-0000-0cab-a0d7ad0c0000 pid=3245 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=19d5e00e-1b00-0000-0cab-a0d7ad0c0000 pid=3245 clone guuid=73b6020f-1b00-0000-0cab-a0d7af0c0000 pid=3247 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=73b6020f-1b00-0000-0cab-a0d7af0c0000 pid=3247 execve guuid=f8905d0f-1b00-0000-0cab-a0d7b10c0000 pid=3249 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=f8905d0f-1b00-0000-0cab-a0d7b10c0000 pid=3249 clone guuid=d32e830f-1b00-0000-0cab-a0d7b20c0000 pid=3250 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=d32e830f-1b00-0000-0cab-a0d7b20c0000 pid=3250 clone guuid=d2aa9e0f-1b00-0000-0cab-a0d7b40c0000 pid=3252 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=d2aa9e0f-1b00-0000-0cab-a0d7b40c0000 pid=3252 execve guuid=8623e40f-1b00-0000-0cab-a0d7b60c0000 pid=3254 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=8623e40f-1b00-0000-0cab-a0d7b60c0000 pid=3254 clone guuid=7f690610-1b00-0000-0cab-a0d7b70c0000 pid=3255 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=7f690610-1b00-0000-0cab-a0d7b70c0000 pid=3255 execve guuid=16474e10-1b00-0000-0cab-a0d7b80c0000 pid=3256 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=16474e10-1b00-0000-0cab-a0d7b80c0000 pid=3256 clone guuid=c18b6310-1b00-0000-0cab-a0d7ba0c0000 pid=3258 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=c18b6310-1b00-0000-0cab-a0d7ba0c0000 pid=3258 clone guuid=f08f8410-1b00-0000-0cab-a0d7bb0c0000 pid=3259 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=f08f8410-1b00-0000-0cab-a0d7bb0c0000 pid=3259 execve guuid=26dfdb10-1b00-0000-0cab-a0d7bc0c0000 pid=3260 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=26dfdb10-1b00-0000-0cab-a0d7bc0c0000 pid=3260 clone guuid=6d70fe10-1b00-0000-0cab-a0d7bd0c0000 pid=3261 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=6d70fe10-1b00-0000-0cab-a0d7bd0c0000 pid=3261 execve guuid=f5316c11-1b00-0000-0cab-a0d7c00c0000 pid=3264 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=f5316c11-1b00-0000-0cab-a0d7c00c0000 pid=3264 clone guuid=0bb28b11-1b00-0000-0cab-a0d7c10c0000 pid=3265 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=0bb28b11-1b00-0000-0cab-a0d7c10c0000 pid=3265 clone guuid=85c4ab11-1b00-0000-0cab-a0d7c20c0000 pid=3266 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=85c4ab11-1b00-0000-0cab-a0d7c20c0000 pid=3266 execve guuid=87d1f311-1b00-0000-0cab-a0d7c40c0000 pid=3268 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=87d1f311-1b00-0000-0cab-a0d7c40c0000 pid=3268 clone guuid=17f50f12-1b00-0000-0cab-a0d7c50c0000 pid=3269 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=17f50f12-1b00-0000-0cab-a0d7c50c0000 pid=3269 execve guuid=74425412-1b00-0000-0cab-a0d7c70c0000 pid=3271 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=74425412-1b00-0000-0cab-a0d7c70c0000 pid=3271 clone guuid=59986e12-1b00-0000-0cab-a0d7c80c0000 pid=3272 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=59986e12-1b00-0000-0cab-a0d7c80c0000 pid=3272 clone guuid=1ce58712-1b00-0000-0cab-a0d7ca0c0000 pid=3274 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=1ce58712-1b00-0000-0cab-a0d7ca0c0000 pid=3274 execve guuid=fd60fa12-1b00-0000-0cab-a0d7cc0c0000 pid=3276 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=fd60fa12-1b00-0000-0cab-a0d7cc0c0000 pid=3276 clone guuid=13fc1b13-1b00-0000-0cab-a0d7cd0c0000 pid=3277 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=13fc1b13-1b00-0000-0cab-a0d7cd0c0000 pid=3277 execve guuid=61907813-1b00-0000-0cab-a0d7ce0c0000 pid=3278 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=61907813-1b00-0000-0cab-a0d7ce0c0000 pid=3278 clone guuid=0650a813-1b00-0000-0cab-a0d7d00c0000 pid=3280 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=0650a813-1b00-0000-0cab-a0d7d00c0000 pid=3280 clone guuid=df6dc413-1b00-0000-0cab-a0d7d10c0000 pid=3281 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=df6dc413-1b00-0000-0cab-a0d7d10c0000 pid=3281 execve guuid=c70f4e14-1b00-0000-0cab-a0d7d30c0000 pid=3283 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=c70f4e14-1b00-0000-0cab-a0d7d30c0000 pid=3283 clone guuid=dac36f14-1b00-0000-0cab-a0d7d50c0000 pid=3285 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=dac36f14-1b00-0000-0cab-a0d7d50c0000 pid=3285 execve guuid=64d3bf14-1b00-0000-0cab-a0d7d60c0000 pid=3286 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=64d3bf14-1b00-0000-0cab-a0d7d60c0000 pid=3286 clone guuid=1aa9de14-1b00-0000-0cab-a0d7d70c0000 pid=3287 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=1aa9de14-1b00-0000-0cab-a0d7d70c0000 pid=3287 clone guuid=354ff414-1b00-0000-0cab-a0d7d80c0000 pid=3288 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=354ff414-1b00-0000-0cab-a0d7d80c0000 pid=3288 execve guuid=fc267915-1b00-0000-0cab-a0d7db0c0000 pid=3291 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=fc267915-1b00-0000-0cab-a0d7db0c0000 pid=3291 clone guuid=58ec9a15-1b00-0000-0cab-a0d7dd0c0000 pid=3293 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=58ec9a15-1b00-0000-0cab-a0d7dd0c0000 pid=3293 execve guuid=1984de15-1b00-0000-0cab-a0d7de0c0000 pid=3294 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=1984de15-1b00-0000-0cab-a0d7de0c0000 pid=3294 clone guuid=6920f515-1b00-0000-0cab-a0d7e00c0000 pid=3296 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=6920f515-1b00-0000-0cab-a0d7e00c0000 pid=3296 clone guuid=6cbf0616-1b00-0000-0cab-a0d7e10c0000 pid=3297 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=6cbf0616-1b00-0000-0cab-a0d7e10c0000 pid=3297 execve guuid=96697e16-1b00-0000-0cab-a0d7e20c0000 pid=3298 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=96697e16-1b00-0000-0cab-a0d7e20c0000 pid=3298 clone guuid=70489c16-1b00-0000-0cab-a0d7e30c0000 pid=3299 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=70489c16-1b00-0000-0cab-a0d7e30c0000 pid=3299 execve guuid=98584c17-1b00-0000-0cab-a0d7e40c0000 pid=3300 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=98584c17-1b00-0000-0cab-a0d7e40c0000 pid=3300 clone guuid=6ae27b17-1b00-0000-0cab-a0d7e50c0000 pid=3301 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=6ae27b17-1b00-0000-0cab-a0d7e50c0000 pid=3301 clone guuid=00aab217-1b00-0000-0cab-a0d7e60c0000 pid=3302 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=00aab217-1b00-0000-0cab-a0d7e60c0000 pid=3302 execve guuid=e1dd7f18-1b00-0000-0cab-a0d7e70c0000 pid=3303 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=e1dd7f18-1b00-0000-0cab-a0d7e70c0000 pid=3303 clone guuid=99c1c418-1b00-0000-0cab-a0d7e80c0000 pid=3304 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=99c1c418-1b00-0000-0cab-a0d7e80c0000 pid=3304 execve guuid=73193419-1b00-0000-0cab-a0d7e90c0000 pid=3305 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=73193419-1b00-0000-0cab-a0d7e90c0000 pid=3305 clone guuid=d57c6c19-1b00-0000-0cab-a0d7ea0c0000 pid=3306 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=d57c6c19-1b00-0000-0cab-a0d7ea0c0000 pid=3306 clone guuid=c5669a19-1b00-0000-0cab-a0d7eb0c0000 pid=3307 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=c5669a19-1b00-0000-0cab-a0d7eb0c0000 pid=3307 execve guuid=7d24381a-1b00-0000-0cab-a0d7ec0c0000 pid=3308 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=7d24381a-1b00-0000-0cab-a0d7ec0c0000 pid=3308 clone guuid=1d18661a-1b00-0000-0cab-a0d7ed0c0000 pid=3309 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=1d18661a-1b00-0000-0cab-a0d7ed0c0000 pid=3309 execve guuid=e8f3db1a-1b00-0000-0cab-a0d7ee0c0000 pid=3310 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=e8f3db1a-1b00-0000-0cab-a0d7ee0c0000 pid=3310 clone guuid=077c031b-1b00-0000-0cab-a0d7f00c0000 pid=3312 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=077c031b-1b00-0000-0cab-a0d7f00c0000 pid=3312 clone guuid=e88f251b-1b00-0000-0cab-a0d7f10c0000 pid=3313 /usr/bin/chmod guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=e88f251b-1b00-0000-0cab-a0d7f10c0000 pid=3313 execve guuid=71906c1b-1b00-0000-0cab-a0d7f20c0000 pid=3314 /usr/bin/bash guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=71906c1b-1b00-0000-0cab-a0d7f20c0000 pid=3314 clone guuid=073fc41b-1b00-0000-0cab-a0d7f30c0000 pid=3315 /usr/bin/rm guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=073fc41b-1b00-0000-0cab-a0d7f30c0000 pid=3315 execve guuid=eb65351c-1b00-0000-0cab-a0d7f50c0000 pid=3317 /usr/bin/bash zombie guuid=579631b5-1900-0000-0cab-a0d73b0a0000 pid=2619->guuid=eb65351c-1b00-0000-0cab-a0d7f50c0000 pid=3317 clone ab75d910-ce2f-5d24-8f1d-1983612e259b 208.84.101.162:80 guuid=0ea9d3b5-1900-0000-0cab-a0d73e0a0000 pid=2622->ab75d910-ce2f-5d24-8f1d-1983612e259b send: 135B guuid=20732045-1a00-0000-0cab-a0d7570b0000 pid=2903->ab75d910-ce2f-5d24-8f1d-1983612e259b send: 84B guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3237 /home/sandbox/x86_64 net write-file zombie guuid=952f500d-1b00-0000-0cab-a0d7a40c0000 pid=3236->guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3237 clone 336f3693-9c09-5a97-a146-075a23fff33a 208.84.101.162:1150 guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3237->336f3693-9c09-5a97-a146-075a23fff33a con guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3239 /home/sandbox/x86_64 guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3237->guuid=0a53770d-1b00-0000-0cab-a0d7a50c0000 pid=3239 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-18 18:07:47 UTC
File Type:
Text (Shell)
AV detection:
14 of 37 (37.84%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1fbc9d3b461fd05685a0e760d3f6e7f4e06647bfadea71302be7277d35fcea91

(this sample)

  
Delivery method
Distributed via web download

Comments