MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 213972db5e81a5b87f8da392cbc8bd2f16f05b32ca9308e5260ebcbcf2116dd5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 213972db5e81a5b87f8da392cbc8bd2f16f05b32ca9308e5260ebcbcf2116dd5
SHA3-384 hash: 5922b997054d81c47a32ddde9ede720c1b0c0686a7eea9863f50a1243d6730ee6e51e9b614f647663f161ee42bbe1eaa
SHA1 hash: 144f3a224d827f4227989b01db920dffe54887af
MD5 hash: e67505b4e2937cd41ff4604a1dadbb51
humanhash: kitten-gee-eight-kitten
File name:dck
Download: download sample
Signature Mirai
File size:1'522 bytes
First seen:2026-06-03 16:44:49 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:NZW6FJmJNIBt7bdKA5tWz65jz9nmnWCK/+6hXjSOU4bJOOa6bFmFWnGYPcwLuoq:NZWCkYbd3WqjBnmnTK/+aTSGbJO7MgW+
TLSH T14D3161DF01039B0235A9DDDD7BA240894413DCEB258FD34DFD48152D778898932ECEAA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=00edc523-1700-0000-5d75-7d36110d0000 pid=3345 /usr/bin/sudo guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349 /tmp/sample.bin guuid=00edc523-1700-0000-5d75-7d36110d0000 pid=3345->guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349 execve guuid=5aeab925-1700-0000-5d75-7d36170d0000 pid=3351 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=5aeab925-1700-0000-5d75-7d36170d0000 pid=3351 execve guuid=9a2628d6-1700-0000-5d75-7d36510e0000 pid=3665 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=9a2628d6-1700-0000-5d75-7d36510e0000 pid=3665 execve guuid=a3c2f55c-1800-0000-5d75-7d366a0f0000 pid=3946 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=a3c2f55c-1800-0000-5d75-7d366a0f0000 pid=3946 execve guuid=4722545d-1800-0000-5d75-7d366c0f0000 pid=3948 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=4722545d-1800-0000-5d75-7d366c0f0000 pid=3948 clone guuid=6324d25e-1800-0000-5d75-7d366f0f0000 pid=3951 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=6324d25e-1800-0000-5d75-7d366f0f0000 pid=3951 execve guuid=ed7f585f-1800-0000-5d75-7d36720f0000 pid=3954 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=ed7f585f-1800-0000-5d75-7d36720f0000 pid=3954 execve guuid=ca96d05f-1800-0000-5d75-7d36760f0000 pid=3958 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=ca96d05f-1800-0000-5d75-7d36760f0000 pid=3958 execve guuid=0681cb91-1800-0000-5d75-7d36fa0f0000 pid=4090 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=0681cb91-1800-0000-5d75-7d36fa0f0000 pid=4090 execve guuid=b282964c-1900-0000-5d75-7d3668120000 pid=4712 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=b282964c-1900-0000-5d75-7d3668120000 pid=4712 execve guuid=2fa2f94c-1900-0000-5d75-7d366c120000 pid=4716 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=2fa2f94c-1900-0000-5d75-7d366c120000 pid=4716 clone guuid=acdf3b4e-1900-0000-5d75-7d3671120000 pid=4721 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=acdf3b4e-1900-0000-5d75-7d3671120000 pid=4721 execve guuid=a327bc4e-1900-0000-5d75-7d3673120000 pid=4723 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=a327bc4e-1900-0000-5d75-7d3673120000 pid=4723 execve guuid=9b0d434f-1900-0000-5d75-7d3675120000 pid=4725 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=9b0d434f-1900-0000-5d75-7d3675120000 pid=4725 execve guuid=f29eb3ae-1900-0000-5d75-7d3660130000 pid=4960 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=f29eb3ae-1900-0000-5d75-7d3660130000 pid=4960 execve guuid=f1eef927-1a00-0000-5d75-7d366f140000 pid=5231 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=f1eef927-1a00-0000-5d75-7d366f140000 pid=5231 execve guuid=10374128-1a00-0000-5d75-7d3670140000 pid=5232 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=10374128-1a00-0000-5d75-7d3670140000 pid=5232 clone guuid=a0b1db28-1a00-0000-5d75-7d3672140000 pid=5234 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=a0b1db28-1a00-0000-5d75-7d3672140000 pid=5234 execve guuid=d815152e-1a00-0000-5d75-7d3673140000 pid=5235 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=d815152e-1a00-0000-5d75-7d3673140000 pid=5235 execve guuid=9625a82e-1a00-0000-5d75-7d3674140000 pid=5236 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=9625a82e-1a00-0000-5d75-7d3674140000 pid=5236 execve guuid=d4e9dd7b-1a00-0000-5d75-7d367d140000 pid=5245 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=d4e9dd7b-1a00-0000-5d75-7d367d140000 pid=5245 execve guuid=50c6b0b1-1a00-0000-5d75-7d367e140000 pid=5246 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=50c6b0b1-1a00-0000-5d75-7d367e140000 pid=5246 execve guuid=a1ea37b2-1a00-0000-5d75-7d367f140000 pid=5247 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=a1ea37b2-1a00-0000-5d75-7d367f140000 pid=5247 clone guuid=711db7b4-1a00-0000-5d75-7d3681140000 pid=5249 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=711db7b4-1a00-0000-5d75-7d3681140000 pid=5249 execve guuid=237307b5-1a00-0000-5d75-7d3682140000 pid=5250 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=237307b5-1a00-0000-5d75-7d3682140000 pid=5250 execve guuid=dd1153b5-1a00-0000-5d75-7d3683140000 pid=5251 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=dd1153b5-1a00-0000-5d75-7d3683140000 pid=5251 execve guuid=89d7e973-1b00-0000-5d75-7d368b140000 pid=5259 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=89d7e973-1b00-0000-5d75-7d368b140000 pid=5259 execve guuid=c7dcc0c8-1b00-0000-5d75-7d368c140000 pid=5260 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=c7dcc0c8-1b00-0000-5d75-7d368c140000 pid=5260 execve guuid=b94dfdc8-1b00-0000-5d75-7d368d140000 pid=5261 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=b94dfdc8-1b00-0000-5d75-7d368d140000 pid=5261 clone guuid=59157ac9-1b00-0000-5d75-7d368f140000 pid=5263 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=59157ac9-1b00-0000-5d75-7d368f140000 pid=5263 execve guuid=4addb7c9-1b00-0000-5d75-7d3690140000 pid=5264 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=4addb7c9-1b00-0000-5d75-7d3690140000 pid=5264 execve guuid=ee41f3c9-1b00-0000-5d75-7d3691140000 pid=5265 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=ee41f3c9-1b00-0000-5d75-7d3691140000 pid=5265 execve guuid=227fc794-1c00-0000-5d75-7d36b2140000 pid=5298 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=227fc794-1c00-0000-5d75-7d36b2140000 pid=5298 execve guuid=ef7d37e8-1c00-0000-5d75-7d36b3140000 pid=5299 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=ef7d37e8-1c00-0000-5d75-7d36b3140000 pid=5299 execve guuid=867bcbe8-1c00-0000-5d75-7d36b4140000 pid=5300 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=867bcbe8-1c00-0000-5d75-7d36b4140000 pid=5300 clone guuid=e86900ea-1c00-0000-5d75-7d36b6140000 pid=5302 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=e86900ea-1c00-0000-5d75-7d36b6140000 pid=5302 execve guuid=d1c58aea-1c00-0000-5d75-7d36b7140000 pid=5303 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=d1c58aea-1c00-0000-5d75-7d36b7140000 pid=5303 execve guuid=ee8815eb-1c00-0000-5d75-7d36b8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=ee8815eb-1c00-0000-5d75-7d36b8140000 pid=5304 execve guuid=308d3f95-1d00-0000-5d75-7d36b9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=308d3f95-1d00-0000-5d75-7d36b9140000 pid=5305 execve guuid=357b5608-1e00-0000-5d75-7d36ba140000 pid=5306 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=357b5608-1e00-0000-5d75-7d36ba140000 pid=5306 execve guuid=7f2fa408-1e00-0000-5d75-7d36bb140000 pid=5307 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=7f2fa408-1e00-0000-5d75-7d36bb140000 pid=5307 clone guuid=be9c4e09-1e00-0000-5d75-7d36bd140000 pid=5309 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=be9c4e09-1e00-0000-5d75-7d36bd140000 pid=5309 execve guuid=aa073f0a-1e00-0000-5d75-7d36be140000 pid=5310 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=aa073f0a-1e00-0000-5d75-7d36be140000 pid=5310 execve guuid=9784840a-1e00-0000-5d75-7d36bf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=9784840a-1e00-0000-5d75-7d36bf140000 pid=5311 execve guuid=b768613d-1e00-0000-5d75-7d36c0140000 pid=5312 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=b768613d-1e00-0000-5d75-7d36c0140000 pid=5312 execve guuid=5f626785-1e00-0000-5d75-7d36c1140000 pid=5313 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=5f626785-1e00-0000-5d75-7d36c1140000 pid=5313 execve guuid=2c4d0b86-1e00-0000-5d75-7d36c2140000 pid=5314 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=2c4d0b86-1e00-0000-5d75-7d36c2140000 pid=5314 clone guuid=aef56887-1e00-0000-5d75-7d36c4140000 pid=5316 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=aef56887-1e00-0000-5d75-7d36c4140000 pid=5316 execve guuid=a204ff87-1e00-0000-5d75-7d36c5140000 pid=5317 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=a204ff87-1e00-0000-5d75-7d36c5140000 pid=5317 execve guuid=83f59f88-1e00-0000-5d75-7d36c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=83f59f88-1e00-0000-5d75-7d36c6140000 pid=5318 execve guuid=5fa379fc-1e00-0000-5d75-7d36c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=5fa379fc-1e00-0000-5d75-7d36c7140000 pid=5319 execve guuid=c3ad4b32-1f00-0000-5d75-7d36c8140000 pid=5320 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=c3ad4b32-1f00-0000-5d75-7d36c8140000 pid=5320 execve guuid=e5fcfa32-1f00-0000-5d75-7d36c9140000 pid=5321 /usr/bin/bash guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=e5fcfa32-1f00-0000-5d75-7d36c9140000 pid=5321 clone guuid=2c6e6c34-1f00-0000-5d75-7d36cb140000 pid=5323 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=2c6e6c34-1f00-0000-5d75-7d36cb140000 pid=5323 execve guuid=f1db0135-1f00-0000-5d75-7d36cc140000 pid=5324 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=f1db0135-1f00-0000-5d75-7d36cc140000 pid=5324 execve guuid=4f099335-1f00-0000-5d75-7d36cd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=4f099335-1f00-0000-5d75-7d36cd140000 pid=5325 execve guuid=83938693-1f00-0000-5d75-7d36ce140000 pid=5326 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=83938693-1f00-0000-5d75-7d36ce140000 pid=5326 execve guuid=429b0fd4-1f00-0000-5d75-7d36cf140000 pid=5327 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=429b0fd4-1f00-0000-5d75-7d36cf140000 pid=5327 execve guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328 /home/sandbox/zakx64 net guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328 execve guuid=dd4c2cd5-1f00-0000-5d75-7d36d6140000 pid=5334 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=dd4c2cd5-1f00-0000-5d75-7d36d6140000 pid=5334 execve guuid=8d84b7d5-1f00-0000-5d75-7d36d7140000 pid=5335 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=8d84b7d5-1f00-0000-5d75-7d36d7140000 pid=5335 execve guuid=724640d6-1f00-0000-5d75-7d36d8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=724640d6-1f00-0000-5d75-7d36d8140000 pid=5336 execve guuid=64a6f41c-2000-0000-5d75-7d36d9140000 pid=5337 /usr/bin/curl net send-data write-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=64a6f41c-2000-0000-5d75-7d36d9140000 pid=5337 execve guuid=08a662db-2000-0000-5d75-7d36da140000 pid=5338 /usr/bin/chmod guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=08a662db-2000-0000-5d75-7d36da140000 pid=5338 execve guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339 /home/sandbox/zakx86 net guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339 execve guuid=026f65dc-2000-0000-5d75-7d36df140000 pid=5343 /usr/bin/rm delete-file guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=026f65dc-2000-0000-5d75-7d36df140000 pid=5343 execve guuid=7ab5f0dc-2000-0000-5d75-7d36e2140000 pid=5346 /usr/bin/rm guuid=c25d6e25-1700-0000-5d75-7d36150d0000 pid=3349->guuid=7ab5f0dc-2000-0000-5d75-7d36e2140000 pid=5346 execve b7286980-675b-5765-83ec-9cdfb34e7337 45.202.249.34:80 guuid=5aeab925-1700-0000-5d75-7d36170d0000 pid=3351->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=9a2628d6-1700-0000-5d75-7d36510e0000 pid=3665->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=ca96d05f-1800-0000-5d75-7d36760f0000 pid=3958->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=0681cb91-1800-0000-5d75-7d36fa0f0000 pid=4090->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=9b0d434f-1900-0000-5d75-7d3675120000 pid=4725->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=f29eb3ae-1900-0000-5d75-7d3660130000 pid=4960->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=9625a82e-1a00-0000-5d75-7d3674140000 pid=5236->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=d4e9dd7b-1a00-0000-5d75-7d367d140000 pid=5245->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=dd1153b5-1a00-0000-5d75-7d3683140000 pid=5251->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=89d7e973-1b00-0000-5d75-7d368b140000 pid=5259->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=ee41f3c9-1b00-0000-5d75-7d3691140000 pid=5265->b7286980-675b-5765-83ec-9cdfb34e7337 send: 135B guuid=227fc794-1c00-0000-5d75-7d36b2140000 pid=5298->b7286980-675b-5765-83ec-9cdfb34e7337 send: 84B guuid=ee8815eb-1c00-0000-5d75-7d36b8140000 pid=5304->b7286980-675b-5765-83ec-9cdfb34e7337 send: 134B guuid=308d3f95-1d00-0000-5d75-7d36b9140000 pid=5305->b7286980-675b-5765-83ec-9cdfb34e7337 send: 83B guuid=9784840a-1e00-0000-5d75-7d36bf140000 pid=5311->b7286980-675b-5765-83ec-9cdfb34e7337 send: 134B guuid=b768613d-1e00-0000-5d75-7d36c0140000 pid=5312->b7286980-675b-5765-83ec-9cdfb34e7337 send: 83B guuid=83f59f88-1e00-0000-5d75-7d36c6140000 pid=5318->b7286980-675b-5765-83ec-9cdfb34e7337 send: 134B guuid=5fa379fc-1e00-0000-5d75-7d36c7140000 pid=5319->b7286980-675b-5765-83ec-9cdfb34e7337 send: 83B guuid=4f099335-1f00-0000-5d75-7d36cd140000 pid=5325->b7286980-675b-5765-83ec-9cdfb34e7337 send: 134B guuid=83938693-1f00-0000-5d75-7d36ce140000 pid=5326->b7286980-675b-5765-83ec-9cdfb34e7337 send: 83B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3e3cf9d4-1f00-0000-5d75-7d36d1140000 pid=5329 /home/sandbox/zakx64 zombie guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328->guuid=3e3cf9d4-1f00-0000-5d75-7d36d1140000 pid=5329 clone guuid=19bb00d5-1f00-0000-5d75-7d36d2140000 pid=5330 /home/sandbox/zakx64 guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328->guuid=19bb00d5-1f00-0000-5d75-7d36d2140000 pid=5330 clone guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331 /home/sandbox/zakx64 dns net send-data zombie guuid=5b57cdd4-1f00-0000-5d75-7d36d0140000 pid=5328->guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331 clone guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 190B 55cbc08e-3b1e-59dc-b9ec-c0b36fb394fe sopa1805.duckdns.org:8080 guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331->55cbc08e-3b1e-59dc-b9ec-c0b36fb394fe send: 8B guuid=97b416d5-1f00-0000-5d75-7d36d4140000 pid=5332 /home/sandbox/zakx64 guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331->guuid=97b416d5-1f00-0000-5d75-7d36d4140000 pid=5332 clone guuid=150e20d5-1f00-0000-5d75-7d36d5140000 pid=5333 /home/sandbox/zakx64 guuid=ebb805d5-1f00-0000-5d75-7d36d3140000 pid=5331->guuid=150e20d5-1f00-0000-5d75-7d36d5140000 pid=5333 clone guuid=724640d6-1f00-0000-5d75-7d36d8140000 pid=5336->b7286980-675b-5765-83ec-9cdfb34e7337 send: 134B guuid=64a6f41c-2000-0000-5d75-7d36d9140000 pid=5337->b7286980-675b-5765-83ec-9cdfb34e7337 send: 83B guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=deeb3ddc-2000-0000-5d75-7d36dc140000 pid=5340 /home/sandbox/zakx86 zombie guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339->guuid=deeb3ddc-2000-0000-5d75-7d36dc140000 pid=5340 clone guuid=397248dc-2000-0000-5d75-7d36dd140000 pid=5341 /home/sandbox/zakx86 guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339->guuid=397248dc-2000-0000-5d75-7d36dd140000 pid=5341 clone guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342 /home/sandbox/zakx86 dns net send-data zombie guuid=f376fddb-2000-0000-5d75-7d36db140000 pid=5339->guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342 clone guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342->55cbc08e-3b1e-59dc-b9ec-c0b36fb394fe send: 8B guuid=392d70dc-2000-0000-5d75-7d36e0140000 pid=5344 /home/sandbox/zakx86 guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342->guuid=392d70dc-2000-0000-5d75-7d36e0140000 pid=5344 clone guuid=eac077dc-2000-0000-5d75-7d36e1140000 pid=5345 /home/sandbox/zakx86 guuid=ade552dc-2000-0000-5d75-7d36de140000 pid=5342->guuid=eac077dc-2000-0000-5d75-7d36e1140000 pid=5345 clone
Threat name:
Document-HTML.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-03 16:45:48 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Malware Config
C2 Extraction:
sopa1805.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 213972db5e81a5b87f8da392cbc8bd2f16f05b32ca9308e5260ebcbcf2116dd5

(this sample)

  
Delivery method
Distributed via web download

Comments