MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2990ecb627c39d0c0d987c7dd00f0bae177b0b5a2411f736439e86004d5d6e93. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 2990ecb627c39d0c0d987c7dd00f0bae177b0b5a2411f736439e86004d5d6e93
SHA3-384 hash: 843e692bcf4ed8c881b5e05ee3cf94b14d70228315fad09db671e3b64c0b72d9534ee44ec0ddf854bcc4a84645de7b90
SHA1 hash: cad27b060fb4c357888a1e200bd8493de0ca0ba2
MD5 hash: 15c8ba6dfb03c4abe97885ab23be5f34
humanhash: music-video-sixteen-queen
File name:sshbins.sh
Download: download sample
Signature Mirai
File size:3'496 bytes
First seen:2026-03-21 08:38:05 UTC
Last seen:2026-03-23 05:08:12 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:Za1zqf2lveezXQScxkcJ+Yu/YwV41z/0EqFEQKtYZ/D5+O:Za1zqf2xJzCXsv4zicy5n
TLSH T1DA71A6C4C830A4375C868A0BF561C6AA6DDC93E599B4C16C53A99E3712E1F3D7C8B643
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://88.214.20.143/bins/tux.x86ce86f67220e57e39fe2cf009b28c45742e371ab3a5445cf304af0c29a6c5c8ab Miraielf ua-wget
http://88.214.20.143/bins/tux.mipsc031158e151eb44a8274a09628409f4ca1e6800796846e765b04ec236b458595 Miraielf ua-wget
http://88.214.20.143/bins/tux.mpsl837cbeb0525af6bcba6f8f1c21dc015282dcd5656f666e5b1061459fc4046140 Miraielf ua-wget
http://88.214.20.143/bins/tux.arm7083d76b20f2e852a32ca482fcc68aee6f0d809872aaf2c9ef55b7c9159e10bb Miraielf ua-wget
http://88.214.20.143/bins/tux.arcn/an/aelf ua-wget
http://88.214.20.143/bins/tux.arm4n/an/aelf ua-wget
http://88.214.20.143/bins/tux.arm5e98188fb59ac4ace244eaedacb7eb765b3cdca29bae74ce59ed7a2137c2afacf Miraielf ua-wget
http://88.214.20.143/bins/tux.arm64c2b21c9b013305c1f7d40351b1692dee7c86c72785ce53e27da621900b78ad5 Miraielf ua-wget
http://88.214.20.143/bins/tux.arm76ba5c3ac96539322332397adecb18cbace6f57ae9cfd509bb3600c7ead29d319 Miraielf ua-wget
http://88.214.20.143/bins/tux.ppc24517ddb231e26591cc6225c747f8a422e53546d16410c82d4919728849e4668 Miraielf ua-wget
http://88.214.20.143/bins/tux.m68k03b36e3abd751b69530806a45611ddb81841e7ad414ab076ae20b1ea3991987b Miraielf ua-wget
http://88.214.20.143/bins/tux.sh447fcc3426f3d0e563b5c7692b0ea2a22321fa804747d7228c93a2c9dd45b7bc1 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=8c851de8-1700-0000-dbb0-acaa800c0000 pid=3200 /usr/bin/sudo guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201 /tmp/sample.bin guuid=8c851de8-1700-0000-dbb0-acaa800c0000 pid=3200->guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201 execve guuid=eb57deeb-1700-0000-dbb0-acaa820c0000 pid=3202 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=eb57deeb-1700-0000-dbb0-acaa820c0000 pid=3202 execve guuid=4d7b5ff0-1700-0000-dbb0-acaa840c0000 pid=3204 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=4d7b5ff0-1700-0000-dbb0-acaa840c0000 pid=3204 execve guuid=8c6d9cf0-1700-0000-dbb0-acaa850c0000 pid=3205 /home/sandbox/tux.x86 net guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=8c6d9cf0-1700-0000-dbb0-acaa850c0000 pid=3205 execve guuid=37fbd6f0-1700-0000-dbb0-acaa870c0000 pid=3207 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=37fbd6f0-1700-0000-dbb0-acaa870c0000 pid=3207 execve guuid=4c2527f7-1700-0000-dbb0-acaa970c0000 pid=3223 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=4c2527f7-1700-0000-dbb0-acaa970c0000 pid=3223 execve guuid=354661f7-1700-0000-dbb0-acaa980c0000 pid=3224 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=354661f7-1700-0000-dbb0-acaa980c0000 pid=3224 clone guuid=8c28fdf8-1700-0000-dbb0-acaa9b0c0000 pid=3227 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=8c28fdf8-1700-0000-dbb0-acaa9b0c0000 pid=3227 execve guuid=6cf9e4fd-1700-0000-dbb0-acaaa20c0000 pid=3234 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=6cf9e4fd-1700-0000-dbb0-acaaa20c0000 pid=3234 execve guuid=4a172afe-1700-0000-dbb0-acaaa30c0000 pid=3235 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=4a172afe-1700-0000-dbb0-acaaa30c0000 pid=3235 clone guuid=9c22d3fe-1700-0000-dbb0-acaaa50c0000 pid=3237 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=9c22d3fe-1700-0000-dbb0-acaaa50c0000 pid=3237 execve guuid=49b09503-1800-0000-dbb0-acaaad0c0000 pid=3245 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=49b09503-1800-0000-dbb0-acaaad0c0000 pid=3245 execve guuid=2c2bd003-1800-0000-dbb0-acaaae0c0000 pid=3246 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=2c2bd003-1800-0000-dbb0-acaaae0c0000 pid=3246 clone guuid=4cf30105-1800-0000-dbb0-acaab10c0000 pid=3249 /usr/bin/busybox net send-data guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=4cf30105-1800-0000-dbb0-acaab10c0000 pid=3249 execve guuid=e19d2207-1800-0000-dbb0-acaab80c0000 pid=3256 /usr/bin/busybox net send-data guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=e19d2207-1800-0000-dbb0-acaab80c0000 pid=3256 execve guuid=0e2b5709-1800-0000-dbb0-acaaba0c0000 pid=3258 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=0e2b5709-1800-0000-dbb0-acaaba0c0000 pid=3258 execve guuid=fc05330e-1800-0000-dbb0-acaac10c0000 pid=3265 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=fc05330e-1800-0000-dbb0-acaac10c0000 pid=3265 execve guuid=7950da0e-1800-0000-dbb0-acaac20c0000 pid=3266 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=7950da0e-1800-0000-dbb0-acaac20c0000 pid=3266 clone guuid=32c1a00f-1800-0000-dbb0-acaac40c0000 pid=3268 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=32c1a00f-1800-0000-dbb0-acaac40c0000 pid=3268 execve guuid=c1fc7714-1800-0000-dbb0-acaacc0c0000 pid=3276 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=c1fc7714-1800-0000-dbb0-acaacc0c0000 pid=3276 execve guuid=ec0de114-1800-0000-dbb0-acaace0c0000 pid=3278 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=ec0de114-1800-0000-dbb0-acaace0c0000 pid=3278 clone guuid=40c7e115-1800-0000-dbb0-acaad20c0000 pid=3282 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=40c7e115-1800-0000-dbb0-acaad20c0000 pid=3282 execve guuid=d88f821b-1800-0000-dbb0-acaadf0c0000 pid=3295 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d88f821b-1800-0000-dbb0-acaadf0c0000 pid=3295 execve guuid=19a0b91b-1800-0000-dbb0-acaae00c0000 pid=3296 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=19a0b91b-1800-0000-dbb0-acaae00c0000 pid=3296 clone guuid=1883571d-1800-0000-dbb0-acaae80c0000 pid=3304 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=1883571d-1800-0000-dbb0-acaae80c0000 pid=3304 execve guuid=409dcd21-1800-0000-dbb0-acaaf60c0000 pid=3318 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=409dcd21-1800-0000-dbb0-acaaf60c0000 pid=3318 execve guuid=448a1c22-1800-0000-dbb0-acaaf80c0000 pid=3320 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=448a1c22-1800-0000-dbb0-acaaf80c0000 pid=3320 clone guuid=8b8c6723-1800-0000-dbb0-acaafd0c0000 pid=3325 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=8b8c6723-1800-0000-dbb0-acaafd0c0000 pid=3325 execve guuid=04d04828-1800-0000-dbb0-acaa0b0d0000 pid=3339 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=04d04828-1800-0000-dbb0-acaa0b0d0000 pid=3339 execve guuid=32b88828-1800-0000-dbb0-acaa0d0d0000 pid=3341 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=32b88828-1800-0000-dbb0-acaa0d0d0000 pid=3341 clone guuid=e22e0429-1800-0000-dbb0-acaa100d0000 pid=3344 /usr/bin/busybox net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=e22e0429-1800-0000-dbb0-acaa100d0000 pid=3344 execve guuid=d623f32c-1800-0000-dbb0-acaa1b0d0000 pid=3355 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d623f32c-1800-0000-dbb0-acaa1b0d0000 pid=3355 execve guuid=8b6d302d-1800-0000-dbb0-acaa1d0d0000 pid=3357 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=8b6d302d-1800-0000-dbb0-acaa1d0d0000 pid=3357 clone guuid=4f37bd2d-1800-0000-dbb0-acaa1f0d0000 pid=3359 /usr/bin/wget guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=4f37bd2d-1800-0000-dbb0-acaa1f0d0000 pid=3359 execve guuid=0d726232-1800-0000-dbb0-acaa200d0000 pid=3360 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=0d726232-1800-0000-dbb0-acaa200d0000 pid=3360 execve guuid=5f417f38-1800-0000-dbb0-acaa220d0000 pid=3362 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=5f417f38-1800-0000-dbb0-acaa220d0000 pid=3362 execve guuid=1ac00e39-1800-0000-dbb0-acaa230d0000 pid=3363 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=1ac00e39-1800-0000-dbb0-acaa230d0000 pid=3363 clone guuid=d67f133a-1800-0000-dbb0-acaa250d0000 pid=3365 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d67f133a-1800-0000-dbb0-acaa250d0000 pid=3365 execve guuid=9591c83f-1800-0000-dbb0-acaa340d0000 pid=3380 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=9591c83f-1800-0000-dbb0-acaa340d0000 pid=3380 execve guuid=ed5e1240-1800-0000-dbb0-acaa360d0000 pid=3382 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=ed5e1240-1800-0000-dbb0-acaa360d0000 pid=3382 clone guuid=68818c40-1800-0000-dbb0-acaa3a0d0000 pid=3386 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=68818c40-1800-0000-dbb0-acaa3a0d0000 pid=3386 execve guuid=7d970946-1800-0000-dbb0-acaa430d0000 pid=3395 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=7d970946-1800-0000-dbb0-acaa430d0000 pid=3395 execve guuid=0f465d46-1800-0000-dbb0-acaa440d0000 pid=3396 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=0f465d46-1800-0000-dbb0-acaa440d0000 pid=3396 clone guuid=e68e1147-1800-0000-dbb0-acaa470d0000 pid=3399 /usr/bin/wget net send-data guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=e68e1147-1800-0000-dbb0-acaa470d0000 pid=3399 execve guuid=8de82d4a-1800-0000-dbb0-acaa4f0d0000 pid=3407 /usr/bin/wget net send-data guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=8de82d4a-1800-0000-dbb0-acaa4f0d0000 pid=3407 execve guuid=96be804d-1800-0000-dbb0-acaa550d0000 pid=3413 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=96be804d-1800-0000-dbb0-acaa550d0000 pid=3413 execve guuid=1606dd52-1800-0000-dbb0-acaa640d0000 pid=3428 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=1606dd52-1800-0000-dbb0-acaa640d0000 pid=3428 execve guuid=de8b1d53-1800-0000-dbb0-acaa660d0000 pid=3430 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=de8b1d53-1800-0000-dbb0-acaa660d0000 pid=3430 clone guuid=f0695d54-1800-0000-dbb0-acaa6c0d0000 pid=3436 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=f0695d54-1800-0000-dbb0-acaa6c0d0000 pid=3436 execve guuid=ca14bf59-1800-0000-dbb0-acaa790d0000 pid=3449 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=ca14bf59-1800-0000-dbb0-acaa790d0000 pid=3449 execve guuid=679c0e5a-1800-0000-dbb0-acaa7b0d0000 pid=3451 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=679c0e5a-1800-0000-dbb0-acaa7b0d0000 pid=3451 clone guuid=000ceb5b-1800-0000-dbb0-acaa810d0000 pid=3457 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=000ceb5b-1800-0000-dbb0-acaa810d0000 pid=3457 execve guuid=d43dc861-1800-0000-dbb0-acaa910d0000 pid=3473 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d43dc861-1800-0000-dbb0-acaa910d0000 pid=3473 execve guuid=37b32c62-1800-0000-dbb0-acaa920d0000 pid=3474 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=37b32c62-1800-0000-dbb0-acaa920d0000 pid=3474 clone guuid=e1d1ca62-1800-0000-dbb0-acaa960d0000 pid=3478 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=e1d1ca62-1800-0000-dbb0-acaa960d0000 pid=3478 execve guuid=fcf2a667-1800-0000-dbb0-acaaa40d0000 pid=3492 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=fcf2a667-1800-0000-dbb0-acaaa40d0000 pid=3492 execve guuid=a297ee67-1800-0000-dbb0-acaaa60d0000 pid=3494 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=a297ee67-1800-0000-dbb0-acaaa60d0000 pid=3494 clone guuid=d20b9a68-1800-0000-dbb0-acaaaa0d0000 pid=3498 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d20b9a68-1800-0000-dbb0-acaaaa0d0000 pid=3498 execve guuid=b780086e-1800-0000-dbb0-acaabb0d0000 pid=3515 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=b780086e-1800-0000-dbb0-acaabb0d0000 pid=3515 execve guuid=3be1466e-1800-0000-dbb0-acaabd0d0000 pid=3517 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=3be1466e-1800-0000-dbb0-acaabd0d0000 pid=3517 clone guuid=9daee26e-1800-0000-dbb0-acaac00d0000 pid=3520 /usr/bin/wget net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=9daee26e-1800-0000-dbb0-acaac00d0000 pid=3520 execve guuid=00078e73-1800-0000-dbb0-acaad20d0000 pid=3538 /usr/bin/chmod guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=00078e73-1800-0000-dbb0-acaad20d0000 pid=3538 execve guuid=89dece73-1800-0000-dbb0-acaad30d0000 pid=3539 /usr/bin/dash guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=89dece73-1800-0000-dbb0-acaad30d0000 pid=3539 clone guuid=07947274-1800-0000-dbb0-acaad80d0000 pid=3544 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=07947274-1800-0000-dbb0-acaad80d0000 pid=3544 execve guuid=9e81937c-1800-0000-dbb0-acaaea0d0000 pid=3562 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=9e81937c-1800-0000-dbb0-acaaea0d0000 pid=3562 execve guuid=1e1ae782-1800-0000-dbb0-acaaf50d0000 pid=3573 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=1e1ae782-1800-0000-dbb0-acaaf50d0000 pid=3573 execve guuid=ef3b288a-1800-0000-dbb0-acaa030e0000 pid=3587 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=ef3b288a-1800-0000-dbb0-acaa030e0000 pid=3587 execve guuid=d84cd593-1800-0000-dbb0-acaa130e0000 pid=3603 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=d84cd593-1800-0000-dbb0-acaa130e0000 pid=3603 execve guuid=9ba32399-1800-0000-dbb0-acaa200e0000 pid=3616 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=9ba32399-1800-0000-dbb0-acaa200e0000 pid=3616 execve guuid=c35c6e9d-1800-0000-dbb0-acaa2c0e0000 pid=3628 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=c35c6e9d-1800-0000-dbb0-acaa2c0e0000 pid=3628 execve guuid=ffe69fa3-1800-0000-dbb0-acaa3f0e0000 pid=3647 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=ffe69fa3-1800-0000-dbb0-acaa3f0e0000 pid=3647 execve guuid=175b2dae-1800-0000-dbb0-acaa560e0000 pid=3670 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=175b2dae-1800-0000-dbb0-acaa560e0000 pid=3670 execve guuid=5bb843b5-1800-0000-dbb0-acaa670e0000 pid=3687 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=5bb843b5-1800-0000-dbb0-acaa670e0000 pid=3687 execve guuid=1300f7ba-1800-0000-dbb0-acaa7d0e0000 pid=3709 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=1300f7ba-1800-0000-dbb0-acaa7d0e0000 pid=3709 execve guuid=f3b94ec4-1800-0000-dbb0-acaa920e0000 pid=3730 /usr/bin/curl net send-data write-file guuid=bc20f4ea-1700-0000-dbb0-acaa810c0000 pid=3201->guuid=f3b94ec4-1800-0000-dbb0-acaa920e0000 pid=3730 execve 2dbd41cb-cede-5124-a798-671cc26b1394 88.214.20.143:80 guuid=eb57deeb-1700-0000-dbb0-acaa820c0000 pid=3202->2dbd41cb-cede-5124-a798-671cc26b1394 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8c6d9cf0-1700-0000-dbb0-acaa850c0000 pid=3205->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206 /home/sandbox/tux.x86 net send-data zombie guuid=8c6d9cf0-1700-0000-dbb0-acaa850c0000 pid=3205->guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206 clone guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5ce35052-8cf1-5e61-9192-ecdca327d1ce 64.89.161.130:44300 guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206->5ce35052-8cf1-5e61-9192-ecdca327d1ce send: 22B guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208 /home/sandbox/tux.x86 net net-scan send-data guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206->guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208 clone guuid=7ce7e8f0-1700-0000-dbb0-acaa890c0000 pid=3209 /home/sandbox/tux.x86 guuid=2824cdf0-1700-0000-dbb0-acaa860c0000 pid=3206->guuid=7ce7e8f0-1700-0000-dbb0-acaa890c0000 pid=3209 clone guuid=37fbd6f0-1700-0000-dbb0-acaa870c0000 pid=3207->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208|send-data send-data to 4097 IP addresses review logs to see them all guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208->guuid=d697daf0-1700-0000-dbb0-acaa880c0000 pid=3208|send-data send guuid=8c28fdf8-1700-0000-dbb0-acaa9b0c0000 pid=3227->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=9c22d3fe-1700-0000-dbb0-acaaa50c0000 pid=3237->2dbd41cb-cede-5124-a798-671cc26b1394 send: 88B guuid=4cf30105-1800-0000-dbb0-acaab10c0000 pid=3249->2dbd41cb-cede-5124-a798-671cc26b1394 send: 88B guuid=e19d2207-1800-0000-dbb0-acaab80c0000 pid=3256->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=0e2b5709-1800-0000-dbb0-acaaba0c0000 pid=3258->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=32c1a00f-1800-0000-dbb0-acaac40c0000 pid=3268->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=40c7e115-1800-0000-dbb0-acaad20c0000 pid=3282->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=1883571d-1800-0000-dbb0-acaae80c0000 pid=3304->2dbd41cb-cede-5124-a798-671cc26b1394 send: 88B guuid=8b8c6723-1800-0000-dbb0-acaafd0c0000 pid=3325->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=e22e0429-1800-0000-dbb0-acaa100d0000 pid=3344->2dbd41cb-cede-5124-a798-671cc26b1394 send: 88B guuid=0d726232-1800-0000-dbb0-acaa200d0000 pid=3360->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=d67f133a-1800-0000-dbb0-acaa250d0000 pid=3365->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=68818c40-1800-0000-dbb0-acaa3a0d0000 pid=3386->2dbd41cb-cede-5124-a798-671cc26b1394 send: 140B guuid=e68e1147-1800-0000-dbb0-acaa470d0000 pid=3399->2dbd41cb-cede-5124-a798-671cc26b1394 send: 140B guuid=8de82d4a-1800-0000-dbb0-acaa4f0d0000 pid=3407->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=96be804d-1800-0000-dbb0-acaa550d0000 pid=3413->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=f0695d54-1800-0000-dbb0-acaa6c0d0000 pid=3436->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=000ceb5b-1800-0000-dbb0-acaa810d0000 pid=3457->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=e1d1ca62-1800-0000-dbb0-acaa960d0000 pid=3478->2dbd41cb-cede-5124-a798-671cc26b1394 send: 140B guuid=d20b9a68-1800-0000-dbb0-acaaaa0d0000 pid=3498->2dbd41cb-cede-5124-a798-671cc26b1394 send: 141B guuid=9daee26e-1800-0000-dbb0-acaac00d0000 pid=3520->2dbd41cb-cede-5124-a798-671cc26b1394 send: 140B guuid=07947274-1800-0000-dbb0-acaad80d0000 pid=3544->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=9e81937c-1800-0000-dbb0-acaaea0d0000 pid=3562->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=1e1ae782-1800-0000-dbb0-acaaf50d0000 pid=3573->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=ef3b288a-1800-0000-dbb0-acaa030e0000 pid=3587->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=d84cd593-1800-0000-dbb0-acaa130e0000 pid=3603->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=9ba32399-1800-0000-dbb0-acaa200e0000 pid=3616->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=c35c6e9d-1800-0000-dbb0-acaa2c0e0000 pid=3628->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=ffe69fa3-1800-0000-dbb0-acaa3f0e0000 pid=3647->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=175b2dae-1800-0000-dbb0-acaa560e0000 pid=3670->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=5bb843b5-1800-0000-dbb0-acaa670e0000 pid=3687->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B guuid=1300f7ba-1800-0000-dbb0-acaa7d0e0000 pid=3709->2dbd41cb-cede-5124-a798-671cc26b1394 send: 90B guuid=f3b94ec4-1800-0000-dbb0-acaa920e0000 pid=3730->2dbd41cb-cede-5124-a798-671cc26b1394 send: 89B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-21 08:12:35 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (23847) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2990ecb627c39d0c0d987c7dd00f0bae177b0b5a2411f736439e86004d5d6e93

(this sample)

  
Delivery method
Distributed via web download

Comments