MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 360467c3b733513c922b90d0e222067509df6481636926fa1786d0273169f4da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 360467c3b733513c922b90d0e222067509df6481636926fa1786d0273169f4da
SHA3-384 hash: 231e74fe5926199e6dd75534995710e87abcb32a38fdbc62ac5dd2b13cdc983ba1ba3e8776d075d68afb1ae74c8bd960
SHA1 hash: bcd6d4f9725a0e5af57c1283892b4474b467069f
MD5 hash: baf0a66fcbad46f82afca7e98c467449
humanhash: magazine-florida-uncle-bacon
File name:tol.sh
Download: download sample
Signature Mirai
File size:5'027 bytes
First seen:2026-01-25 19:17:09 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:rfLklqkfm9+Ftflq38SfkfcrPfcH0zHfvAhugfz8tiMfkfcrsGf16HsifaZK5Jft:i
TLSH T109A1B36150114FF2DE0E8E16A9744F0A358857892992BE48DFFA39DBD6CFFCA3105E90
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.100.228/mamakmukekkontol/zerobotv9.x8664c1492109495906dfedbdf64d99a0b80d5c32ac8a5665135b000624ad2eccbe Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.mipsdeb70af83a9b3bb8f9424b709c3f6342d0c63aa10e7f8df43dd7a457bda8f060 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.arc5c96edcd514733da92b19c23a0f6ec4f99532dae7d9dc7fc134746b01431eebd Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.i686f0da131e151040febbf2741de344d2dd7084d48da6c6b8ec3990cf34a84540c3 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.x86_64d7112dd3220ccb0b3e757b006acf9b92af466a285bbb0674258bcc9ad463f616 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.mpsl6e4e797262c80b9117aded5d25ff2752cd83abe631096b66e120cc3599a82e4e Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.armc1f986b48e1d56d6a39d21fbc618411713d0d24a97b96f73c0fff554d271e86d Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.arm5263a363e2483bf9fd9f915527f5b5255daa42bbfa1e606403169575d6555a58c Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.arm6045a1e42cb64e4aa91601f65a80ec5bd040ea4024c6d3b051cb1a6aa15d03b57 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.arm7c8e8b627398ece071a3a148d6f38e46763dc534f9bfd967ebc8ac3479540111f Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.ppcc4c160602e5d637c6367908715b4dd4a4423ddf007d53a5db132663eb95bc6dd Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.spccc1efbca0da739b7784d833e56a22063ec4719cd095b16e3e10f77efd4277e24 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.m68kd024039824db6fe535ddd51bc81099c946871e4e280c48ed6e90dada79ccfcc7 Miraielf geofenced mirai ua-wget USA
http://144.172.100.228/mamakmukekkontol/zerobotv9.sh4a0f0495ab470e4ee7e8f3dff17fe1eb0e42936fd968d2ea8a0fa279563594da7 Miraielf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-12T21:16:00Z UTC
Last seen:
2026-01-27T12:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9f3a51cc-1600-0000-ae51-a189340f0000 pid=3892 /usr/bin/sudo guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902 /tmp/sample.bin guuid=9f3a51cc-1600-0000-ae51-a189340f0000 pid=3892->guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902 execve guuid=faa19ece-1600-0000-ae51-a189420f0000 pid=3906 /usr/bin/cp guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=faa19ece-1600-0000-ae51-a189420f0000 pid=3906 execve guuid=2c3680d3-1600-0000-ae51-a189520f0000 pid=3922 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=2c3680d3-1600-0000-ae51-a189520f0000 pid=3922 execve guuid=a454c7d3-1600-0000-ae51-a189540f0000 pid=3924 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=a454c7d3-1600-0000-ae51-a189540f0000 pid=3924 execve guuid=ac66544c-1700-0000-ae51-a18910110000 pid=4368 /usr/bin/curl net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=ac66544c-1700-0000-ae51-a18910110000 pid=4368 execve guuid=36dcb796-1700-0000-ae51-a1893f120000 pid=4671 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=36dcb796-1700-0000-ae51-a1893f120000 pid=4671 execve guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675 /tmp/zerobotv9.x86 net guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675 execve guuid=ee6ab3c3-1800-0000-ae51-a18989140000 pid=5257 /usr/bin/rm delete-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=ee6ab3c3-1800-0000-ae51-a18989140000 pid=5257 execve guuid=c8f904c4-1800-0000-ae51-a1898a140000 pid=5258 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=c8f904c4-1800-0000-ae51-a1898a140000 pid=5258 execve guuid=cfa1d0c4-1800-0000-ae51-a1898b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=cfa1d0c4-1800-0000-ae51-a1898b140000 pid=5259 execve guuid=93bf5814-1900-0000-ae51-a1898c140000 pid=5260 /usr/bin/curl net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=93bf5814-1900-0000-ae51-a1898c140000 pid=5260 execve guuid=5c41cf74-1900-0000-ae51-a18994140000 pid=5268 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=5c41cf74-1900-0000-ae51-a18994140000 pid=5268 execve guuid=d7288575-1900-0000-ae51-a18995140000 pid=5269 /usr/bin/bash guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=d7288575-1900-0000-ae51-a18995140000 pid=5269 clone guuid=85a8ae76-1900-0000-ae51-a18997140000 pid=5271 /usr/bin/rm delete-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=85a8ae76-1900-0000-ae51-a18997140000 pid=5271 execve guuid=f3bd2f77-1900-0000-ae51-a18998140000 pid=5272 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=f3bd2f77-1900-0000-ae51-a18998140000 pid=5272 execve guuid=f70aa677-1900-0000-ae51-a18999140000 pid=5273 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=f70aa677-1900-0000-ae51-a18999140000 pid=5273 execve guuid=26c70ae7-1900-0000-ae51-a1899a140000 pid=5274 /usr/bin/curl net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=26c70ae7-1900-0000-ae51-a1899a140000 pid=5274 execve guuid=96ee6c54-1a00-0000-ae51-a189a1140000 pid=5281 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=96ee6c54-1a00-0000-ae51-a189a1140000 pid=5281 execve guuid=576db654-1a00-0000-ae51-a189a2140000 pid=5282 /usr/bin/bash guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=576db654-1a00-0000-ae51-a189a2140000 pid=5282 clone guuid=201f4455-1a00-0000-ae51-a189a4140000 pid=5284 /usr/bin/rm delete-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=201f4455-1a00-0000-ae51-a189a4140000 pid=5284 execve guuid=7f529355-1a00-0000-ae51-a189a5140000 pid=5285 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=7f529355-1a00-0000-ae51-a189a5140000 pid=5285 execve guuid=0ad90c56-1a00-0000-ae51-a189a6140000 pid=5286 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=0ad90c56-1a00-0000-ae51-a189a6140000 pid=5286 execve guuid=03b5a4ab-1a00-0000-ae51-a189c1140000 pid=5313 /usr/bin/curl net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=03b5a4ab-1a00-0000-ae51-a189c1140000 pid=5313 execve guuid=e57df302-1b00-0000-ae51-a189c2140000 pid=5314 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=e57df302-1b00-0000-ae51-a189c2140000 pid=5314 execve guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315 /tmp/zerobotv9.i686 net guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315 execve guuid=66d9e42f-1c00-0000-ae51-a189c9140000 pid=5321 /usr/bin/rm delete-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=66d9e42f-1c00-0000-ae51-a189c9140000 pid=5321 execve guuid=f17c7230-1c00-0000-ae51-a189ca140000 pid=5322 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=f17c7230-1c00-0000-ae51-a189ca140000 pid=5322 execve guuid=6e354231-1c00-0000-ae51-a189cb140000 pid=5323 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=6e354231-1c00-0000-ae51-a189cb140000 pid=5323 execve guuid=0284b87d-1c00-0000-ae51-a189cc140000 pid=5324 /usr/bin/curl net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=0284b87d-1c00-0000-ae51-a189cc140000 pid=5324 execve guuid=dc7af7ca-1c00-0000-ae51-a189cd140000 pid=5325 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=dc7af7ca-1c00-0000-ae51-a189cd140000 pid=5325 execve guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326 /tmp/zerobotv9.x86_64 mprotect-exec net guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326 execve guuid=43664ff6-1d00-0000-ae51-a189d4140000 pid=5332 /usr/bin/rm delete-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=43664ff6-1d00-0000-ae51-a189d4140000 pid=5332 execve guuid=ecc309f7-1d00-0000-ae51-a189d5140000 pid=5333 /usr/bin/chmod guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=ecc309f7-1d00-0000-ae51-a189d5140000 pid=5333 execve guuid=f1e8c4f7-1d00-0000-ae51-a189d6140000 pid=5334 /usr/bin/wget net send-data write-file guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=f1e8c4f7-1d00-0000-ae51-a189d6140000 pid=5334 execve guuid=872bff93-1e00-0000-ae51-a189d7140000 pid=5335 /usr/bin/curl net send-data guuid=e63243ce-1600-0000-ae51-a1893e0f0000 pid=3902->guuid=872bff93-1e00-0000-ae51-a189d7140000 pid=5335 execve 6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 144.172.100.228:80 guuid=a454c7d3-1600-0000-ae51-a189540f0000 pid=3924->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 160B guuid=ac66544c-1700-0000-ae51-a18910110000 pid=4368->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 109B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c78a7e97-1700-0000-ae51-a18945120000 pid=4677 /tmp/zerobotv9.x86 guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675->guuid=c78a7e97-1700-0000-ae51-a18945120000 pid=4677 clone guuid=429b94c3-1800-0000-ae51-a18987140000 pid=5255 /tmp/zerobotv9.x86 guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675->guuid=429b94c3-1800-0000-ae51-a18987140000 pid=5255 clone guuid=1db3a0c3-1800-0000-ae51-a18988140000 pid=5256 /tmp/zerobotv9.x86 net send-data zombie guuid=fd0dfd96-1700-0000-ae51-a18943120000 pid=4675->guuid=1db3a0c3-1800-0000-ae51-a18988140000 pid=5256 clone guuid=57048597-1700-0000-ae51-a18946120000 pid=4678 /tmp/zerobotv9.x86 guuid=c78a7e97-1700-0000-ae51-a18945120000 pid=4677->guuid=57048597-1700-0000-ae51-a18946120000 pid=4678 clone guuid=20de8897-1700-0000-ae51-a18947120000 pid=4679 /tmp/zerobotv9.x86 dns net send-data zombie guuid=c78a7e97-1700-0000-ae51-a18945120000 pid=4677->guuid=20de8897-1700-0000-ae51-a18947120000 pid=4679 clone guuid=20de8897-1700-0000-ae51-a18947120000 pid=4679->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B b1abbe8e-0646-592b-9857-1c11944b1212 0bot.qzz.io:69 guuid=20de8897-1700-0000-ae51-a18947120000 pid=4679->b1abbe8e-0646-592b-9857-1c11944b1212 send: 23B guuid=1db3a0c3-1800-0000-ae51-a18988140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=1db3a0c3-1800-0000-ae51-a18988140000 pid=5256->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=cfa1d0c4-1800-0000-ae51-a1898b140000 pid=5259->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 161B guuid=93bf5814-1900-0000-ae51-a1898c140000 pid=5260->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 110B guuid=f70aa677-1900-0000-ae51-a18999140000 pid=5273->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 160B guuid=26c70ae7-1900-0000-ae51-a1899a140000 pid=5274->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 109B guuid=0ad90c56-1a00-0000-ae51-a189a6140000 pid=5286->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 161B guuid=03b5a4ab-1a00-0000-ae51-a189c1140000 pid=5313->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 110B guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5bf0fb03-1b00-0000-ae51-a189c4140000 pid=5316 /tmp/zerobotv9.i686 guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315->guuid=5bf0fb03-1b00-0000-ae51-a189c4140000 pid=5316 clone guuid=b515d22f-1c00-0000-ae51-a189c7140000 pid=5319 /tmp/zerobotv9.i686 guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315->guuid=b515d22f-1c00-0000-ae51-a189c7140000 pid=5319 clone guuid=f61ed72f-1c00-0000-ae51-a189c8140000 pid=5320 /tmp/zerobotv9.i686 net send-data zombie guuid=6f324803-1b00-0000-ae51-a189c3140000 pid=5315->guuid=f61ed72f-1c00-0000-ae51-a189c8140000 pid=5320 clone guuid=4e600304-1b00-0000-ae51-a189c5140000 pid=5317 /tmp/zerobotv9.i686 guuid=5bf0fb03-1b00-0000-ae51-a189c4140000 pid=5316->guuid=4e600304-1b00-0000-ae51-a189c5140000 pid=5317 clone guuid=35590904-1b00-0000-ae51-a189c6140000 pid=5318 /tmp/zerobotv9.i686 dns net send-data zombie guuid=5bf0fb03-1b00-0000-ae51-a189c4140000 pid=5316->guuid=35590904-1b00-0000-ae51-a189c6140000 pid=5318 clone guuid=35590904-1b00-0000-ae51-a189c6140000 pid=5318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 87B guuid=35590904-1b00-0000-ae51-a189c6140000 pid=5318->b1abbe8e-0646-592b-9857-1c11944b1212 send: 62B guuid=f61ed72f-1c00-0000-ae51-a189c8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 600B guuid=f61ed72f-1c00-0000-ae51-a189c8140000 pid=5320->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=6e354231-1c00-0000-ae51-a189cb140000 pid=5323->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 163B guuid=0284b87d-1c00-0000-ae51-a189cc140000 pid=5324->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 112B guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1c9ab5cb-1c00-0000-ae51-a189cf140000 pid=5327 /tmp/zerobotv9.x86_64 guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326->guuid=1c9ab5cb-1c00-0000-ae51-a189cf140000 pid=5327 clone guuid=25c921f6-1d00-0000-ae51-a189d2140000 pid=5330 /tmp/zerobotv9.x86_64 guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326->guuid=25c921f6-1d00-0000-ae51-a189d2140000 pid=5330 clone guuid=22b732f6-1d00-0000-ae51-a189d3140000 pid=5331 /tmp/zerobotv9.x86_64 net send-data zombie guuid=19d43ccb-1c00-0000-ae51-a189ce140000 pid=5326->guuid=22b732f6-1d00-0000-ae51-a189d3140000 pid=5331 clone guuid=2bc0bccb-1c00-0000-ae51-a189d0140000 pid=5328 /tmp/zerobotv9.x86_64 guuid=1c9ab5cb-1c00-0000-ae51-a189cf140000 pid=5327->guuid=2bc0bccb-1c00-0000-ae51-a189d0140000 pid=5328 clone guuid=8de7c0cb-1c00-0000-ae51-a189d1140000 pid=5329 /tmp/zerobotv9.x86_64 net send-data zombie guuid=1c9ab5cb-1c00-0000-ae51-a189cf140000 pid=5327->guuid=8de7c0cb-1c00-0000-ae51-a189d1140000 pid=5329 clone guuid=8de7c0cb-1c00-0000-ae51-a189d1140000 pid=5329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 580B guuid=8de7c0cb-1c00-0000-ae51-a189d1140000 pid=5329->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=22b732f6-1d00-0000-ae51-a189d3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 435B guuid=22b732f6-1d00-0000-ae51-a189d3140000 pid=5331->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=f1e8c4f7-1d00-0000-ae51-a189d6140000 pid=5334->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 161B guuid=872bff93-1e00-0000-ae51-a189d7140000 pid=5335->6dbc8a1a-6bb7-582a-a1cc-bbfa88035b51 send: 110B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-01-13 02:31:17 UTC
File Type:
Text (Shell)
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 360467c3b733513c922b90d0e222067509df6481636926fa1786d0273169f4da

(this sample)

  
Delivery method
Distributed via web download

Comments