MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 438a8f83d6a441a94a2220155439a171df2ae3e7e96eb932fd3c6848537c8f44. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 438a8f83d6a441a94a2220155439a171df2ae3e7e96eb932fd3c6848537c8f44
SHA3-384 hash: 9cbebfebbb04df2922f1b2740d033bc17576251375a1496da8631c9ec8d4bc86dda5282b50559f191a69c08170cefbd5
SHA1 hash: 85b0ad8753f0425838f06080713d7a0ca16b5082
MD5 hash: 7b268ec5bb08fb01d92f0dd4b1d715aa
humanhash: hotel-timing-yellow-angel
File name:n.sh
Download: download sample
Signature Mirai
File size:1'283 bytes
First seen:2025-12-24 13:25:09 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:od7R76dejudiOiNI8dEGdMr7Dgdf0dIqdcOcNvdaadGCG7xdOKdvv:oCv6BhyBuFNv/ux/V
TLSH T1AE2154CE100ED721364E6EA073F7F96455F2E8A21E560D33DFE448A6C4E8A4077ACAD0
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.127/ntarm37490b35b3b2ad15b38e07c6d2614e277d2a43c76355f140c7c7ef6d7cf0f5ac Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm5e5e9346a47bce22519a79482111400fa4d1cb57614773f44d27c47574d1fa442 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm64822e668692794fad83477e8ba761b11c25d57428ee6665f0f0cef3e7ba4873a Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntarm781aad7c6c7e13e69d0759539801b14a00e44d1363adf39ba5ecddb1874709e91 Miraiarm elf geofenced mirai ua-wget USA
http://130.12.180.127/ntsh4b7f840ae5abdf8f07a1ec90a5841a7f875ccec5c064482eee8f935d12f9c8fa6 Miraielf geofenced mirai SuperH ua-wget USA
http://130.12.180.127/ntarcn/an/aelf ua-wget
http://130.12.180.127/ntmips67d445a8aafcd3e7c47746cfcda4ad4a92f00fe2b67fb4f4564d9a5b6f219491 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.127/ntmpsla97f2be659972982b61aee906b13d8ea4e9e16a2d1284c33f8ed99d8ea41ff59 Miraielf geofenced mips mirai ua-wget USA
http://130.12.180.127/ntsparcn/an/aelf ua-wget
http://130.12.180.127/ntx868198e09fd8d9e79cd05d5b00f01c4199706fc156a45ac0bf74f251c8f36d385e Miraielf geofenced mirai ua-wget USA x86
http://130.12.180.127/nti686n/an/aelf ua-wget
http://130.12.180.127/nti586n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=8b46b238-1a00-0000-63ec-299e7a0b0000 pid=2938 /usr/bin/sudo guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942 /tmp/sample.bin guuid=8b46b238-1a00-0000-63ec-299e7a0b0000 pid=2938->guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942 execve guuid=e9ffc23a-1a00-0000-63ec-299e7f0b0000 pid=2943 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=e9ffc23a-1a00-0000-63ec-299e7f0b0000 pid=2943 execve guuid=c48c5940-1a00-0000-63ec-299e870b0000 pid=2951 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=c48c5940-1a00-0000-63ec-299e870b0000 pid=2951 execve guuid=ef08a661-1a00-0000-63ec-299ea20b0000 pid=2978 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=ef08a661-1a00-0000-63ec-299ea20b0000 pid=2978 execve guuid=b94d0862-1a00-0000-63ec-299ea30b0000 pid=2979 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=b94d0862-1a00-0000-63ec-299ea30b0000 pid=2979 clone guuid=1530b663-1a00-0000-63ec-299ea60b0000 pid=2982 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=1530b663-1a00-0000-63ec-299ea60b0000 pid=2982 execve guuid=71926667-1a00-0000-63ec-299eae0b0000 pid=2990 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=71926667-1a00-0000-63ec-299eae0b0000 pid=2990 execve guuid=17b89a6e-1a00-0000-63ec-299ebb0b0000 pid=3003 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=17b89a6e-1a00-0000-63ec-299ebb0b0000 pid=3003 execve guuid=9b7af96e-1a00-0000-63ec-299ebd0b0000 pid=3005 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=9b7af96e-1a00-0000-63ec-299ebd0b0000 pid=3005 clone guuid=987ac36f-1a00-0000-63ec-299ec10b0000 pid=3009 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=987ac36f-1a00-0000-63ec-299ec10b0000 pid=3009 execve guuid=8a238c73-1a00-0000-63ec-299eca0b0000 pid=3018 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=8a238c73-1a00-0000-63ec-299eca0b0000 pid=3018 execve guuid=60f60778-1a00-0000-63ec-299ed60b0000 pid=3030 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=60f60778-1a00-0000-63ec-299ed60b0000 pid=3030 execve guuid=3eaf5b78-1a00-0000-63ec-299ed80b0000 pid=3032 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=3eaf5b78-1a00-0000-63ec-299ed80b0000 pid=3032 clone guuid=563bbf79-1a00-0000-63ec-299ede0b0000 pid=3038 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=563bbf79-1a00-0000-63ec-299ede0b0000 pid=3038 execve guuid=6f92697e-1a00-0000-63ec-299eea0b0000 pid=3050 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=6f92697e-1a00-0000-63ec-299eea0b0000 pid=3050 execve guuid=aff6a487-1a00-0000-63ec-299e030c0000 pid=3075 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=aff6a487-1a00-0000-63ec-299e030c0000 pid=3075 execve guuid=553ff187-1a00-0000-63ec-299e050c0000 pid=3077 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=553ff187-1a00-0000-63ec-299e050c0000 pid=3077 clone guuid=3a40a888-1a00-0000-63ec-299e090c0000 pid=3081 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=3a40a888-1a00-0000-63ec-299e090c0000 pid=3081 execve guuid=cd10598d-1a00-0000-63ec-299e150c0000 pid=3093 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=cd10598d-1a00-0000-63ec-299e150c0000 pid=3093 execve guuid=c3e4de93-1a00-0000-63ec-299e260c0000 pid=3110 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=c3e4de93-1a00-0000-63ec-299e260c0000 pid=3110 execve guuid=37062694-1a00-0000-63ec-299e270c0000 pid=3111 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=37062694-1a00-0000-63ec-299e270c0000 pid=3111 clone guuid=4afc3494-1a00-0000-63ec-299e280c0000 pid=3112 /usr/bin/wget net send-data guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=4afc3494-1a00-0000-63ec-299e280c0000 pid=3112 execve guuid=1e043597-1a00-0000-63ec-299e2a0c0000 pid=3114 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=1e043597-1a00-0000-63ec-299e2a0c0000 pid=3114 execve guuid=ac539a9b-1a00-0000-63ec-299e350c0000 pid=3125 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=ac539a9b-1a00-0000-63ec-299e350c0000 pid=3125 execve guuid=34f7da9b-1a00-0000-63ec-299e370c0000 pid=3127 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=34f7da9b-1a00-0000-63ec-299e370c0000 pid=3127 clone guuid=1b20e59b-1a00-0000-63ec-299e380c0000 pid=3128 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=1b20e59b-1a00-0000-63ec-299e380c0000 pid=3128 execve guuid=e46d9b9f-1a00-0000-63ec-299e420c0000 pid=3138 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=e46d9b9f-1a00-0000-63ec-299e420c0000 pid=3138 execve guuid=7183e6a4-1a00-0000-63ec-299e4d0c0000 pid=3149 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=7183e6a4-1a00-0000-63ec-299e4d0c0000 pid=3149 execve guuid=6c0d4ba5-1a00-0000-63ec-299e4f0c0000 pid=3151 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=6c0d4ba5-1a00-0000-63ec-299e4f0c0000 pid=3151 clone guuid=9e6a20a6-1a00-0000-63ec-299e530c0000 pid=3155 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=9e6a20a6-1a00-0000-63ec-299e530c0000 pid=3155 execve guuid=017f28aa-1a00-0000-63ec-299e5d0c0000 pid=3165 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=017f28aa-1a00-0000-63ec-299e5d0c0000 pid=3165 execve guuid=f0c781af-1a00-0000-63ec-299e6b0c0000 pid=3179 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=f0c781af-1a00-0000-63ec-299e6b0c0000 pid=3179 execve guuid=5cd9dbaf-1a00-0000-63ec-299e6d0c0000 pid=3181 /usr/bin/dash guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=5cd9dbaf-1a00-0000-63ec-299e6d0c0000 pid=3181 clone guuid=3e39adb0-1a00-0000-63ec-299e710c0000 pid=3185 /usr/bin/wget net send-data guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=3e39adb0-1a00-0000-63ec-299e710c0000 pid=3185 execve guuid=0c9cabb3-1a00-0000-63ec-299e790c0000 pid=3193 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=0c9cabb3-1a00-0000-63ec-299e790c0000 pid=3193 execve guuid=542e0bb8-1a00-0000-63ec-299e820c0000 pid=3202 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=542e0bb8-1a00-0000-63ec-299e820c0000 pid=3202 execve guuid=863f48b8-1a00-0000-63ec-299e840c0000 pid=3204 /tmp/ntsparc guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=863f48b8-1a00-0000-63ec-299e840c0000 pid=3204 execve guuid=60778ab8-1a00-0000-63ec-299e850c0000 pid=3205 /usr/bin/wget net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=60778ab8-1a00-0000-63ec-299e850c0000 pid=3205 execve guuid=fcab47bc-1a00-0000-63ec-299e880c0000 pid=3208 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=fcab47bc-1a00-0000-63ec-299e880c0000 pid=3208 execve guuid=d464e1c3-1a00-0000-63ec-299e970c0000 pid=3223 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=d464e1c3-1a00-0000-63ec-299e970c0000 pid=3223 execve guuid=9d6859c4-1a00-0000-63ec-299e980c0000 pid=3224 /tmp/ntx86 delete-file net guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=9d6859c4-1a00-0000-63ec-299e980c0000 pid=3224 execve guuid=df18bcc4-1a00-0000-63ec-299e9a0c0000 pid=3226 /usr/bin/wget net send-data guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=df18bcc4-1a00-0000-63ec-299e9a0c0000 pid=3226 execve guuid=a84d9cca-1a00-0000-63ec-299e9e0c0000 pid=3230 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=a84d9cca-1a00-0000-63ec-299e9e0c0000 pid=3230 execve guuid=1791d2cf-1a00-0000-63ec-299ea40c0000 pid=3236 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=1791d2cf-1a00-0000-63ec-299ea40c0000 pid=3236 execve guuid=2d6aa2d0-1a00-0000-63ec-299ea50c0000 pid=3237 /tmp/nti686 guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=2d6aa2d0-1a00-0000-63ec-299ea50c0000 pid=3237 execve guuid=fe9d7ad1-1a00-0000-63ec-299ea60c0000 pid=3238 /usr/bin/wget net send-data guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=fe9d7ad1-1a00-0000-63ec-299ea60c0000 pid=3238 execve guuid=498ee7d6-1a00-0000-63ec-299ea70c0000 pid=3239 /usr/bin/curl net send-data write-file guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=498ee7d6-1a00-0000-63ec-299ea70c0000 pid=3239 execve guuid=5139a5df-1a00-0000-63ec-299eaa0c0000 pid=3242 /usr/bin/chmod guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=5139a5df-1a00-0000-63ec-299eaa0c0000 pid=3242 execve guuid=98f0cde0-1a00-0000-63ec-299ead0c0000 pid=3245 /tmp/nti586 guuid=64b67f3a-1a00-0000-63ec-299e7e0b0000 pid=2942->guuid=98f0cde0-1a00-0000-63ec-299ead0c0000 pid=3245 execve 5e5f7305-15b5-5488-9f49-ae1b177ec723 130.12.180.127:80 guuid=e9ffc23a-1a00-0000-63ec-299e7f0b0000 pid=2943->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 134B guuid=c48c5940-1a00-0000-63ec-299e870b0000 pid=2951->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=1530b663-1a00-0000-63ec-299ea60b0000 pid=2982->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=71926667-1a00-0000-63ec-299eae0b0000 pid=2990->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=987ac36f-1a00-0000-63ec-299ec10b0000 pid=3009->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=8a238c73-1a00-0000-63ec-299eca0b0000 pid=3018->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=563bbf79-1a00-0000-63ec-299ede0b0000 pid=3038->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=6f92697e-1a00-0000-63ec-299eea0b0000 pid=3050->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=3a40a888-1a00-0000-63ec-299e090c0000 pid=3081->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 134B guuid=cd10598d-1a00-0000-63ec-299e150c0000 pid=3093->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=4afc3494-1a00-0000-63ec-299e280c0000 pid=3112->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 134B guuid=1e043597-1a00-0000-63ec-299e2a0c0000 pid=3114->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B guuid=1b20e59b-1a00-0000-63ec-299e380c0000 pid=3128->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=e46d9b9f-1a00-0000-63ec-299e420c0000 pid=3138->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=9e6a20a6-1a00-0000-63ec-299e530c0000 pid=3155->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=017f28aa-1a00-0000-63ec-299e5d0c0000 pid=3165->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=3e39adb0-1a00-0000-63ec-299e710c0000 pid=3185->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 136B guuid=0c9cabb3-1a00-0000-63ec-299e790c0000 pid=3193->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 85B guuid=60778ab8-1a00-0000-63ec-299e850c0000 pid=3205->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 134B guuid=fcab47bc-1a00-0000-63ec-299e880c0000 pid=3208->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 83B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9d6859c4-1a00-0000-63ec-299e980c0000 pid=3224->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225 /tmp/ntx86 net send-data zombie guuid=9d6859c4-1a00-0000-63ec-299e980c0000 pid=3224->guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225 clone guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 9c578459-fc2d-5995-9925-ebe708f9b2a3 94.156.152.67:18129 guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225->9c578459-fc2d-5995-9925-ebe708f9b2a3 send: 10B guuid=51bfc2c4-1a00-0000-63ec-299e9b0c0000 pid=3227 /tmp/ntx86 guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225->guuid=51bfc2c4-1a00-0000-63ec-299e9b0c0000 pid=3227 clone guuid=482fc7c4-1a00-0000-63ec-299e9c0c0000 pid=3228 /tmp/ntx86 guuid=9cf7b1c4-1a00-0000-63ec-299e990c0000 pid=3225->guuid=482fc7c4-1a00-0000-63ec-299e9c0c0000 pid=3228 clone guuid=df18bcc4-1a00-0000-63ec-299e9a0c0000 pid=3226->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=a84d9cca-1a00-0000-63ec-299e9e0c0000 pid=3230->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B guuid=fe9d7ad1-1a00-0000-63ec-299ea60c0000 pid=3238->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 135B guuid=498ee7d6-1a00-0000-63ec-299ea70c0000 pid=3239->5e5f7305-15b5-5488-9f49-ae1b177ec723 send: 84B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-24 12:51:58 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  3/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 438a8f83d6a441a94a2220155439a171df2ae3e7e96eb932fd3c6848537c8f44

(this sample)

  
Delivery method
Distributed via web download

Comments