MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f12f9d78647954e925d8dc9d33ad21daf8e47bb8f404520f45361f68250aa06. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 3f12f9d78647954e925d8dc9d33ad21daf8e47bb8f404520f45361f68250aa06
SHA3-384 hash: de1076fe7b67918d0304efb46975a3230ea5bff4cccd94e45e8587ad6369d10f81cb66fe530bada03ab6215375537bdf
SHA1 hash: 789624f948e4a47cc5cdd649c7ce0253ff1ec4ae
MD5 hash: 0516da876e3d3d2489945d62c8da7a87
humanhash: bluebird-pasta-lemon-foxtrot
File name:dsfdsfdsf.sh
Download: download sample
File size:1'620 bytes
First seen:2026-03-25 20:59:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:1nOJE8MIaBZSBZsNI0NIuKPqKPN2vC2vbx:qhkZ4ZmKPqKPN2vC2vbx
TLSH T1C83185CB637042B36816CD47F35414D5E4EE89C369E79FF8B6248DA3115964CB1A2FE0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.175.192.186/x86n/an/aelf ua-wget
http://5.175.192.186/i386n/an/aelf ua-wget
http://5.175.192.186/amd64n/an/aelf ua-wget
http://5.175.192.186/armn/an/aelf ua-wget
http://5.175.192.186/armv7ln/an/aelf ua-wget
http://5.175.192.186/arm5n/an/aelf ua-wget
http://5.175.192.186/arm6n/an/aelf ua-wget
http://5.175.192.186/arm64n/an/aelf ua-wget
http://5.175.192.186/android_arm64n/an/aelf ua-wget
http://5.175.192.186/bot.exen/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=dbab0018-1700-0000-9f02-dfe4210d0000 pid=3361 /usr/bin/sudo guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368 /tmp/sample.bin guuid=dbab0018-1700-0000-9f02-dfe4210d0000 pid=3361->guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368 execve guuid=cb0fa31a-1700-0000-9f02-dfe4290d0000 pid=3369 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=cb0fa31a-1700-0000-9f02-dfe4290d0000 pid=3369 execve guuid=8987f31d-1700-0000-9f02-dfe4360d0000 pid=3382 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8987f31d-1700-0000-9f02-dfe4360d0000 pid=3382 execve guuid=85102a1e-1700-0000-9f02-dfe4370d0000 pid=3383 /tmp/x86 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=85102a1e-1700-0000-9f02-dfe4370d0000 pid=3383 execve guuid=f689bd1e-1700-0000-9f02-dfe43c0d0000 pid=3388 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=f689bd1e-1700-0000-9f02-dfe43c0d0000 pid=3388 execve guuid=6fd0fe1e-1700-0000-9f02-dfe43d0d0000 pid=3389 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=6fd0fe1e-1700-0000-9f02-dfe43d0d0000 pid=3389 execve guuid=63ea8823-1700-0000-9f02-dfe44c0d0000 pid=3404 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=63ea8823-1700-0000-9f02-dfe44c0d0000 pid=3404 execve guuid=d1e6be23-1700-0000-9f02-dfe44d0d0000 pid=3405 /tmp/x86 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=d1e6be23-1700-0000-9f02-dfe44d0d0000 pid=3405 execve guuid=4af5f623-1700-0000-9f02-dfe44e0d0000 pid=3406 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=4af5f623-1700-0000-9f02-dfe44e0d0000 pid=3406 execve guuid=e63b6324-1700-0000-9f02-dfe4510d0000 pid=3409 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=e63b6324-1700-0000-9f02-dfe4510d0000 pid=3409 execve guuid=83232d27-1700-0000-9f02-dfe4590d0000 pid=3417 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=83232d27-1700-0000-9f02-dfe4590d0000 pid=3417 execve guuid=8d3c8027-1700-0000-9f02-dfe45b0d0000 pid=3419 /tmp/i386 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8d3c8027-1700-0000-9f02-dfe45b0d0000 pid=3419 execve guuid=18406028-1700-0000-9f02-dfe45f0d0000 pid=3423 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=18406028-1700-0000-9f02-dfe45f0d0000 pid=3423 execve guuid=dc38ad28-1700-0000-9f02-dfe4610d0000 pid=3425 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=dc38ad28-1700-0000-9f02-dfe4610d0000 pid=3425 execve guuid=bb43b02c-1700-0000-9f02-dfe46d0d0000 pid=3437 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=bb43b02c-1700-0000-9f02-dfe46d0d0000 pid=3437 execve guuid=fd0de82c-1700-0000-9f02-dfe46f0d0000 pid=3439 /tmp/i386 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=fd0de82c-1700-0000-9f02-dfe46f0d0000 pid=3439 execve guuid=efa9272d-1700-0000-9f02-dfe4710d0000 pid=3441 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=efa9272d-1700-0000-9f02-dfe4710d0000 pid=3441 execve guuid=59cd7a2d-1700-0000-9f02-dfe4730d0000 pid=3443 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=59cd7a2d-1700-0000-9f02-dfe4730d0000 pid=3443 execve guuid=62e42330-1700-0000-9f02-dfe47c0d0000 pid=3452 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=62e42330-1700-0000-9f02-dfe47c0d0000 pid=3452 execve guuid=7e7e6730-1700-0000-9f02-dfe47e0d0000 pid=3454 /tmp/amd64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=7e7e6730-1700-0000-9f02-dfe47e0d0000 pid=3454 execve guuid=7d5d0931-1700-0000-9f02-dfe4820d0000 pid=3458 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=7d5d0931-1700-0000-9f02-dfe4820d0000 pid=3458 execve guuid=a0ce4931-1700-0000-9f02-dfe4840d0000 pid=3460 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=a0ce4931-1700-0000-9f02-dfe4840d0000 pid=3460 execve guuid=ca60a634-1700-0000-9f02-dfe48f0d0000 pid=3471 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=ca60a634-1700-0000-9f02-dfe48f0d0000 pid=3471 execve guuid=1b1df234-1700-0000-9f02-dfe4910d0000 pid=3473 /tmp/amd64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=1b1df234-1700-0000-9f02-dfe4910d0000 pid=3473 execve guuid=3b893135-1700-0000-9f02-dfe4920d0000 pid=3474 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=3b893135-1700-0000-9f02-dfe4920d0000 pid=3474 execve guuid=680e7e35-1700-0000-9f02-dfe4940d0000 pid=3476 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=680e7e35-1700-0000-9f02-dfe4940d0000 pid=3476 execve guuid=c2bc4638-1700-0000-9f02-dfe49e0d0000 pid=3486 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=c2bc4638-1700-0000-9f02-dfe49e0d0000 pid=3486 execve guuid=b8b47c38-1700-0000-9f02-dfe4a00d0000 pid=3488 /tmp/arm guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=b8b47c38-1700-0000-9f02-dfe4a00d0000 pid=3488 execve guuid=57ac1b39-1700-0000-9f02-dfe4a40d0000 pid=3492 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=57ac1b39-1700-0000-9f02-dfe4a40d0000 pid=3492 execve guuid=3e145939-1700-0000-9f02-dfe4a60d0000 pid=3494 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=3e145939-1700-0000-9f02-dfe4a60d0000 pid=3494 execve guuid=3612a93c-1700-0000-9f02-dfe4b40d0000 pid=3508 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=3612a93c-1700-0000-9f02-dfe4b40d0000 pid=3508 execve guuid=9a01ed3c-1700-0000-9f02-dfe4b60d0000 pid=3510 /tmp/arm guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=9a01ed3c-1700-0000-9f02-dfe4b60d0000 pid=3510 execve guuid=65891b3d-1700-0000-9f02-dfe4b80d0000 pid=3512 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=65891b3d-1700-0000-9f02-dfe4b80d0000 pid=3512 execve guuid=6954553d-1700-0000-9f02-dfe4ba0d0000 pid=3514 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=6954553d-1700-0000-9f02-dfe4ba0d0000 pid=3514 execve guuid=dc90fa3f-1700-0000-9f02-dfe4c50d0000 pid=3525 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=dc90fa3f-1700-0000-9f02-dfe4c50d0000 pid=3525 execve guuid=551d3240-1700-0000-9f02-dfe4c70d0000 pid=3527 /tmp/armv7l guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=551d3240-1700-0000-9f02-dfe4c70d0000 pid=3527 execve guuid=6135c740-1700-0000-9f02-dfe4cb0d0000 pid=3531 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=6135c740-1700-0000-9f02-dfe4cb0d0000 pid=3531 execve guuid=ea3f0441-1700-0000-9f02-dfe4cd0d0000 pid=3533 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=ea3f0441-1700-0000-9f02-dfe4cd0d0000 pid=3533 execve guuid=41235244-1700-0000-9f02-dfe4da0d0000 pid=3546 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=41235244-1700-0000-9f02-dfe4da0d0000 pid=3546 execve guuid=5be38f44-1700-0000-9f02-dfe4dc0d0000 pid=3548 /tmp/armv7l guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=5be38f44-1700-0000-9f02-dfe4dc0d0000 pid=3548 execve guuid=f567c544-1700-0000-9f02-dfe4de0d0000 pid=3550 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=f567c544-1700-0000-9f02-dfe4de0d0000 pid=3550 execve guuid=98980645-1700-0000-9f02-dfe4e00d0000 pid=3552 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=98980645-1700-0000-9f02-dfe4e00d0000 pid=3552 execve guuid=1c19b447-1700-0000-9f02-dfe4e50d0000 pid=3557 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=1c19b447-1700-0000-9f02-dfe4e50d0000 pid=3557 execve guuid=15d4f247-1700-0000-9f02-dfe4e60d0000 pid=3558 /tmp/arm5 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=15d4f247-1700-0000-9f02-dfe4e60d0000 pid=3558 execve guuid=50899348-1700-0000-9f02-dfe4e80d0000 pid=3560 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=50899348-1700-0000-9f02-dfe4e80d0000 pid=3560 execve guuid=c05cd148-1700-0000-9f02-dfe4e90d0000 pid=3561 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=c05cd148-1700-0000-9f02-dfe4e90d0000 pid=3561 execve guuid=4acd284c-1700-0000-9f02-dfe4f20d0000 pid=3570 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=4acd284c-1700-0000-9f02-dfe4f20d0000 pid=3570 execve guuid=4baa644c-1700-0000-9f02-dfe4f40d0000 pid=3572 /tmp/arm5 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=4baa644c-1700-0000-9f02-dfe4f40d0000 pid=3572 execve guuid=8f56974c-1700-0000-9f02-dfe4f60d0000 pid=3574 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8f56974c-1700-0000-9f02-dfe4f60d0000 pid=3574 execve guuid=f609d74c-1700-0000-9f02-dfe4f70d0000 pid=3575 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=f609d74c-1700-0000-9f02-dfe4f70d0000 pid=3575 execve guuid=e429f74f-1700-0000-9f02-dfe4fe0d0000 pid=3582 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=e429f74f-1700-0000-9f02-dfe4fe0d0000 pid=3582 execve guuid=af863850-1700-0000-9f02-dfe4000e0000 pid=3584 /tmp/arm6 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=af863850-1700-0000-9f02-dfe4000e0000 pid=3584 execve guuid=b90de850-1700-0000-9f02-dfe4020e0000 pid=3586 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=b90de850-1700-0000-9f02-dfe4020e0000 pid=3586 execve guuid=e1aa4958-1700-0000-9f02-dfe4030e0000 pid=3587 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=e1aa4958-1700-0000-9f02-dfe4030e0000 pid=3587 execve guuid=84eb235d-1700-0000-9f02-dfe40d0e0000 pid=3597 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=84eb235d-1700-0000-9f02-dfe40d0e0000 pid=3597 execve guuid=68419c5d-1700-0000-9f02-dfe40f0e0000 pid=3599 /tmp/arm6 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=68419c5d-1700-0000-9f02-dfe40f0e0000 pid=3599 execve guuid=b551015e-1700-0000-9f02-dfe4100e0000 pid=3600 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=b551015e-1700-0000-9f02-dfe4100e0000 pid=3600 execve guuid=7247705e-1700-0000-9f02-dfe4120e0000 pid=3602 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=7247705e-1700-0000-9f02-dfe4120e0000 pid=3602 execve guuid=1da7c961-1700-0000-9f02-dfe41c0e0000 pid=3612 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=1da7c961-1700-0000-9f02-dfe41c0e0000 pid=3612 execve guuid=9bf21062-1700-0000-9f02-dfe41d0e0000 pid=3613 /tmp/arm64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=9bf21062-1700-0000-9f02-dfe41d0e0000 pid=3613 execve guuid=8ab3ce62-1700-0000-9f02-dfe4200e0000 pid=3616 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8ab3ce62-1700-0000-9f02-dfe4200e0000 pid=3616 execve guuid=66551563-1700-0000-9f02-dfe4210e0000 pid=3617 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=66551563-1700-0000-9f02-dfe4210e0000 pid=3617 execve guuid=5bbda066-1700-0000-9f02-dfe42f0e0000 pid=3631 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=5bbda066-1700-0000-9f02-dfe42f0e0000 pid=3631 execve guuid=64fff366-1700-0000-9f02-dfe4310e0000 pid=3633 /tmp/arm64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=64fff366-1700-0000-9f02-dfe4310e0000 pid=3633 execve guuid=af012767-1700-0000-9f02-dfe4330e0000 pid=3635 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=af012767-1700-0000-9f02-dfe4330e0000 pid=3635 execve guuid=fa3f6c67-1700-0000-9f02-dfe4350e0000 pid=3637 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=fa3f6c67-1700-0000-9f02-dfe4350e0000 pid=3637 execve guuid=5228046a-1700-0000-9f02-dfe43f0e0000 pid=3647 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=5228046a-1700-0000-9f02-dfe43f0e0000 pid=3647 execve guuid=8534416a-1700-0000-9f02-dfe4410e0000 pid=3649 /tmp/android_arm64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8534416a-1700-0000-9f02-dfe4410e0000 pid=3649 execve guuid=79b6e76a-1700-0000-9f02-dfe4450e0000 pid=3653 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=79b6e76a-1700-0000-9f02-dfe4450e0000 pid=3653 execve guuid=a45a446b-1700-0000-9f02-dfe44a0e0000 pid=3658 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=a45a446b-1700-0000-9f02-dfe44a0e0000 pid=3658 execve guuid=314b8170-1700-0000-9f02-dfe4590e0000 pid=3673 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=314b8170-1700-0000-9f02-dfe4590e0000 pid=3673 execve guuid=e0c3ba70-1700-0000-9f02-dfe45b0e0000 pid=3675 /tmp/android_arm64 guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=e0c3ba70-1700-0000-9f02-dfe45b0e0000 pid=3675 execve guuid=9306ee70-1700-0000-9f02-dfe45d0e0000 pid=3677 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=9306ee70-1700-0000-9f02-dfe45d0e0000 pid=3677 execve guuid=a4b82a71-1700-0000-9f02-dfe45e0e0000 pid=3678 /usr/bin/wget net send-data guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=a4b82a71-1700-0000-9f02-dfe45e0e0000 pid=3678 execve guuid=8924c373-1700-0000-9f02-dfe4680e0000 pid=3688 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=8924c373-1700-0000-9f02-dfe4680e0000 pid=3688 execve guuid=10340174-1700-0000-9f02-dfe4690e0000 pid=3689 /tmp/bot.exe guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=10340174-1700-0000-9f02-dfe4690e0000 pid=3689 execve guuid=97d8a574-1700-0000-9f02-dfe46d0e0000 pid=3693 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=97d8a574-1700-0000-9f02-dfe46d0e0000 pid=3693 execve guuid=4039de74-1700-0000-9f02-dfe46f0e0000 pid=3695 /usr/bin/curl net send-data write-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=4039de74-1700-0000-9f02-dfe46f0e0000 pid=3695 execve guuid=0ba1dd79-1700-0000-9f02-dfe47d0e0000 pid=3709 /usr/bin/chmod guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=0ba1dd79-1700-0000-9f02-dfe47d0e0000 pid=3709 execve guuid=ae50217a-1700-0000-9f02-dfe47e0e0000 pid=3710 /tmp/bot.exe guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=ae50217a-1700-0000-9f02-dfe47e0e0000 pid=3710 execve guuid=606b527a-1700-0000-9f02-dfe4800e0000 pid=3712 /usr/bin/rm delete-file guuid=8d5b5d1a-1700-0000-9f02-dfe4280d0000 pid=3368->guuid=606b527a-1700-0000-9f02-dfe4800e0000 pid=3712 execve c73a18f4-e7db-57d6-91dc-4739c1a97c7e 5.175.192.186:80 guuid=cb0fa31a-1700-0000-9f02-dfe4290d0000 pid=3369->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 131B guuid=6fd0fe1e-1700-0000-9f02-dfe43d0d0000 pid=3389->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 80B guuid=e63b6324-1700-0000-9f02-dfe4510d0000 pid=3409->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 132B guuid=dc38ad28-1700-0000-9f02-dfe4610d0000 pid=3425->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 81B guuid=59cd7a2d-1700-0000-9f02-dfe4730d0000 pid=3443->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 133B guuid=a0ce4931-1700-0000-9f02-dfe4840d0000 pid=3460->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 82B guuid=680e7e35-1700-0000-9f02-dfe4940d0000 pid=3476->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 131B guuid=3e145939-1700-0000-9f02-dfe4a60d0000 pid=3494->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 80B guuid=6954553d-1700-0000-9f02-dfe4ba0d0000 pid=3514->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 134B guuid=ea3f0441-1700-0000-9f02-dfe4cd0d0000 pid=3533->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 83B guuid=98980645-1700-0000-9f02-dfe4e00d0000 pid=3552->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 132B guuid=c05cd148-1700-0000-9f02-dfe4e90d0000 pid=3561->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 81B guuid=f609d74c-1700-0000-9f02-dfe4f70d0000 pid=3575->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 132B guuid=e1aa4958-1700-0000-9f02-dfe4030e0000 pid=3587->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 81B guuid=7247705e-1700-0000-9f02-dfe4120e0000 pid=3602->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 133B guuid=66551563-1700-0000-9f02-dfe4210e0000 pid=3617->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 82B guuid=fa3f6c67-1700-0000-9f02-dfe4350e0000 pid=3637->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 141B guuid=a45a446b-1700-0000-9f02-dfe44a0e0000 pid=3658->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 90B guuid=a4b82a71-1700-0000-9f02-dfe45e0e0000 pid=3678->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 135B guuid=4039de74-1700-0000-9f02-dfe46f0e0000 pid=3695->c73a18f4-e7db-57d6-91dc-4739c1a97c7e send: 84B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-25 21:00:43 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3f12f9d78647954e925d8dc9d33ad21daf8e47bb8f404520f45361f68250aa06

(this sample)

  
Delivery method
Distributed via web download

Comments