MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 49c9a1b4a3f7f5b5badaccf2e837e90c9067b207a5d5ff941f1383a2ee70ccdf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 49c9a1b4a3f7f5b5badaccf2e837e90c9067b207a5d5ff941f1383a2ee70ccdf
SHA3-384 hash: 52712132a9ba2b03b5587cb631e76e762e26dfb36412e6066fba23642c91a2278fd0050c5a00b82c1c6bf05a510f9b95
SHA1 hash: c21182c2c66d51ad0e59d5ba159b35c186293027
MD5 hash: fc453bc95d34da863f4c3d1cbec45df7
humanhash: maine-indigo-happy-nuts
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'887 bytes
First seen:2026-02-22 08:50:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:fzDdl3Cw14HCnvBM/hb1m1bEZ1O2wOxx6fnZOo7PCgK+CZJwCR42C5HZ:ff3Cw14HCSBVZXMZOo7PCyCMCfCb
TLSH T114417F8EB17082C1868CCF4B71F449C67705A693F1F46A72ECC12D7A8899E48356DEB7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://140.233.190.82/iran.x86_64336826db561250198b6bf289998ac94c504929984f5f2b80406307dd240d2a08 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.aarch64e35d6edd468c3b13c909bd91c7bac21491acfea4e9a43387770b5b82f06280f1 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.m68k5efc9e0edb71af4a3c4590a998ee393ccf1692fdbfeeb9ecb6eff6300f26b3b9 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.mips5eb4a749b0390cd3afb22f5d4ac9f9776a70037fe2bb4ce2ac2fe158fabf6015 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.mipsel504b10cb02d1ca93f1ed87aa310f23aa6947a1912c746db53a5287a41b745ab5 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.powerpced2a969282cd755d934c153096c680a4270633e4a92a39703c086ecd9e910fb8 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.sparc1c3f751ebcc3b3120ed9bfe25055f3c4783d5201528d6a977e921413ab8d564e Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.sh45ec789decb23daf80798176bbae0ab69298127e8ff1977bb9c50c012e7e1de7d Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.arcb6a9fd633492c3d43a91c1516e7e2f84e272c38b73355c886fba15ece5e65d9d Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.i48621d8b4b092cef625032a9fdc22317954a1641f348fdf0c7da90416ca7a459b35 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.armv4lb2c1ec5f468e7b2c6938fc46746d85c0adf717fa510fa4ba05a7c058de9cfa42 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.armv5laf00e8b3f24ba4d386ab459e94bbe906043e4cd4efc3f5e8c2f8a89016a89039 Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.armv6lc8434d4800bf13bb1c4779ccfc1cf7d2df0ffa705d2d28c01d4bd69f8877f5ed Miraicensys elf mirai ua-wget
http://140.233.190.82/iran.armv7l210fef0b7498cf8883987ed45e45b7cc2b679ea556da2e632df82c77cbfb1012 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=da70c259-1a00-0000-87a4-c890840a0000 pid=2692 /usr/bin/sudo guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699 /tmp/sample.bin guuid=da70c259-1a00-0000-87a4-c890840a0000 pid=2692->guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699 execve guuid=cacceb5b-1a00-0000-87a4-c8908d0a0000 pid=2701 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=cacceb5b-1a00-0000-87a4-c8908d0a0000 pid=2701 execve guuid=bc567e70-1a00-0000-87a4-c890c40a0000 pid=2756 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=bc567e70-1a00-0000-87a4-c890c40a0000 pid=2756 execve guuid=b5aec670-1a00-0000-87a4-c890c60a0000 pid=2758 /home/sandbox/iran.x86_64 guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=b5aec670-1a00-0000-87a4-c890c60a0000 pid=2758 execve guuid=69221c71-1a00-0000-87a4-c890c90a0000 pid=2761 /usr/bin/wget net send-data guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=69221c71-1a00-0000-87a4-c890c90a0000 pid=2761 execve guuid=93b96b76-1a00-0000-87a4-c890d60a0000 pid=2774 /usr/bin/curl net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=93b96b76-1a00-0000-87a4-c890d60a0000 pid=2774 execve guuid=ea037090-1a00-0000-87a4-c890070b0000 pid=2823 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=ea037090-1a00-0000-87a4-c890070b0000 pid=2823 execve guuid=5f11c490-1a00-0000-87a4-c890090b0000 pid=2825 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=5f11c490-1a00-0000-87a4-c890090b0000 pid=2825 clone guuid=70297591-1a00-0000-87a4-c8900e0b0000 pid=2830 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=70297591-1a00-0000-87a4-c8900e0b0000 pid=2830 execve guuid=49e7a5a4-1a00-0000-87a4-c8902d0b0000 pid=2861 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=49e7a5a4-1a00-0000-87a4-c8902d0b0000 pid=2861 execve guuid=26255ea5-1a00-0000-87a4-c8902f0b0000 pid=2863 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=26255ea5-1a00-0000-87a4-c8902f0b0000 pid=2863 clone guuid=a28de7a6-1a00-0000-87a4-c890310b0000 pid=2865 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=a28de7a6-1a00-0000-87a4-c890310b0000 pid=2865 execve guuid=8def08be-1a00-0000-87a4-c890620b0000 pid=2914 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=8def08be-1a00-0000-87a4-c890620b0000 pid=2914 execve guuid=72c966be-1a00-0000-87a4-c890640b0000 pid=2916 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=72c966be-1a00-0000-87a4-c890640b0000 pid=2916 clone guuid=65f300bf-1a00-0000-87a4-c890670b0000 pid=2919 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=65f300bf-1a00-0000-87a4-c890670b0000 pid=2919 execve guuid=5f710bd4-1a00-0000-87a4-c8908a0b0000 pid=2954 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=5f710bd4-1a00-0000-87a4-c8908a0b0000 pid=2954 execve guuid=1aa884d4-1a00-0000-87a4-c8908b0b0000 pid=2955 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=1aa884d4-1a00-0000-87a4-c8908b0b0000 pid=2955 clone guuid=6ec32ed5-1a00-0000-87a4-c8908e0b0000 pid=2958 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=6ec32ed5-1a00-0000-87a4-c8908e0b0000 pid=2958 execve guuid=4d070ceb-1a00-0000-87a4-c890b70b0000 pid=2999 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=4d070ceb-1a00-0000-87a4-c890b70b0000 pid=2999 execve guuid=7a7b69eb-1a00-0000-87a4-c890b80b0000 pid=3000 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=7a7b69eb-1a00-0000-87a4-c890b80b0000 pid=3000 clone guuid=6720cdec-1a00-0000-87a4-c890bb0b0000 pid=3003 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=6720cdec-1a00-0000-87a4-c890bb0b0000 pid=3003 execve guuid=d7e07afb-1a00-0000-87a4-c890cf0b0000 pid=3023 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=d7e07afb-1a00-0000-87a4-c890cf0b0000 pid=3023 execve guuid=db03dafb-1a00-0000-87a4-c890d00b0000 pid=3024 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=db03dafb-1a00-0000-87a4-c890d00b0000 pid=3024 clone guuid=ee57cafc-1a00-0000-87a4-c890d30b0000 pid=3027 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=ee57cafc-1a00-0000-87a4-c890d30b0000 pid=3027 execve guuid=7860620f-1b00-0000-87a4-c890f50b0000 pid=3061 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=7860620f-1b00-0000-87a4-c890f50b0000 pid=3061 execve guuid=8176b70f-1b00-0000-87a4-c890f70b0000 pid=3063 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=8176b70f-1b00-0000-87a4-c890f70b0000 pid=3063 clone guuid=cf7e3b11-1b00-0000-87a4-c890fc0b0000 pid=3068 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=cf7e3b11-1b00-0000-87a4-c890fc0b0000 pid=3068 execve guuid=56689b23-1b00-0000-87a4-c890230c0000 pid=3107 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=56689b23-1b00-0000-87a4-c890230c0000 pid=3107 execve guuid=86945924-1b00-0000-87a4-c890250c0000 pid=3109 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=86945924-1b00-0000-87a4-c890250c0000 pid=3109 clone guuid=cc8b5726-1b00-0000-87a4-c8902b0c0000 pid=3115 /usr/bin/wget net send-data guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=cc8b5726-1b00-0000-87a4-c8902b0c0000 pid=3115 execve guuid=8bb5ed2b-1b00-0000-87a4-c890370c0000 pid=3127 /usr/bin/curl net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=8bb5ed2b-1b00-0000-87a4-c890370c0000 pid=3127 execve guuid=37f4bc40-1b00-0000-87a4-c8905d0c0000 pid=3165 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=37f4bc40-1b00-0000-87a4-c8905d0c0000 pid=3165 execve guuid=7ea63d41-1b00-0000-87a4-c8905f0c0000 pid=3167 /home/sandbox/iran.i486 guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=7ea63d41-1b00-0000-87a4-c8905f0c0000 pid=3167 execve guuid=7341d641-1b00-0000-87a4-c890620c0000 pid=3170 /usr/bin/wget net guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=7341d641-1b00-0000-87a4-c890620c0000 pid=3170 execve guuid=1005c844-1b00-0000-87a4-c8906d0c0000 pid=3181 /usr/bin/curl net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=1005c844-1b00-0000-87a4-c8906d0c0000 pid=3181 execve guuid=d69b685a-1b00-0000-87a4-c8909c0c0000 pid=3228 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=d69b685a-1b00-0000-87a4-c8909c0c0000 pid=3228 execve guuid=5751c75a-1b00-0000-87a4-c8909e0c0000 pid=3230 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=5751c75a-1b00-0000-87a4-c8909e0c0000 pid=3230 clone guuid=e5e1675b-1b00-0000-87a4-c890a20c0000 pid=3234 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=e5e1675b-1b00-0000-87a4-c890a20c0000 pid=3234 execve guuid=60a15b6e-1b00-0000-87a4-c890ae0c0000 pid=3246 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=60a15b6e-1b00-0000-87a4-c890ae0c0000 pid=3246 execve guuid=430fe46e-1b00-0000-87a4-c890af0c0000 pid=3247 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=430fe46e-1b00-0000-87a4-c890af0c0000 pid=3247 clone guuid=da3fb26f-1b00-0000-87a4-c890b30c0000 pid=3251 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=da3fb26f-1b00-0000-87a4-c890b30c0000 pid=3251 execve guuid=728c1082-1b00-0000-87a4-c890cc0c0000 pid=3276 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=728c1082-1b00-0000-87a4-c890cc0c0000 pid=3276 execve guuid=f7916582-1b00-0000-87a4-c890cd0c0000 pid=3277 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=f7916582-1b00-0000-87a4-c890cd0c0000 pid=3277 clone guuid=a4069683-1b00-0000-87a4-c890cf0c0000 pid=3279 /usr/bin/wget net send-data write-file guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=a4069683-1b00-0000-87a4-c890cf0c0000 pid=3279 execve guuid=8dacd296-1b00-0000-87a4-c890de0c0000 pid=3294 /usr/bin/chmod guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=8dacd296-1b00-0000-87a4-c890de0c0000 pid=3294 execve guuid=1f4c2a97-1b00-0000-87a4-c890e00c0000 pid=3296 /usr/bin/dash guuid=d880b45b-1a00-0000-87a4-c8908b0a0000 pid=2699->guuid=1f4c2a97-1b00-0000-87a4-c890e00c0000 pid=3296 clone ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 140.233.190.82:80 guuid=cacceb5b-1a00-0000-87a4-c8908d0a0000 pid=2701->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 140B guuid=19a81471-1a00-0000-87a4-c890c80a0000 pid=2760 /home/sandbox/iran.x86_64 zombie guuid=b5aec670-1a00-0000-87a4-c890c60a0000 pid=2758->guuid=19a81471-1a00-0000-87a4-c890c80a0000 pid=2760 clone guuid=49c01e71-1a00-0000-87a4-c890ca0a0000 pid=2762 /home/sandbox/iran.x86_64 delete-file net send-data zombie guuid=19a81471-1a00-0000-87a4-c890c80a0000 pid=2760->guuid=49c01e71-1a00-0000-87a4-c890ca0a0000 pid=2762 clone guuid=69221c71-1a00-0000-87a4-c890c90a0000 pid=2761->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 141B b29c73e7-e8fa-54c6-9079-544985ba8278 140.233.190.82:7080 guuid=49c01e71-1a00-0000-87a4-c890ca0a0000 pid=2762->b29c73e7-e8fa-54c6-9079-544985ba8278 send: 756B guuid=f24f3e71-1a00-0000-87a4-c890cc0a0000 pid=2764 /home/sandbox/iran.x86_64 guuid=49c01e71-1a00-0000-87a4-c890ca0a0000 pid=2762->guuid=f24f3e71-1a00-0000-87a4-c890cc0a0000 pid=2764 clone guuid=853c4471-1a00-0000-87a4-c890cd0a0000 pid=2765 /home/sandbox/iran.x86_64 guuid=f24f3e71-1a00-0000-87a4-c890cc0a0000 pid=2764->guuid=853c4471-1a00-0000-87a4-c890cd0a0000 pid=2765 clone guuid=93b96b76-1a00-0000-87a4-c890d60a0000 pid=2774->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 90B guuid=70297591-1a00-0000-87a4-c8900e0b0000 pid=2830->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 138B guuid=a28de7a6-1a00-0000-87a4-c890310b0000 pid=2865->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 138B guuid=65f300bf-1a00-0000-87a4-c890670b0000 pid=2919->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 140B guuid=6ec32ed5-1a00-0000-87a4-c8908e0b0000 pid=2958->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 141B guuid=6720cdec-1a00-0000-87a4-c890bb0b0000 pid=3003->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 139B guuid=ee57cafc-1a00-0000-87a4-c890d30b0000 pid=3027->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 137B guuid=cf7e3b11-1b00-0000-87a4-c890fc0b0000 pid=3068->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 137B guuid=cc8b5726-1b00-0000-87a4-c8902b0c0000 pid=3115->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 138B guuid=8bb5ed2b-1b00-0000-87a4-c890370c0000 pid=3127->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 87B guuid=5283c741-1b00-0000-87a4-c890610c0000 pid=3169 /home/sandbox/iran.i486 guuid=7ea63d41-1b00-0000-87a4-c8905f0c0000 pid=3167->guuid=5283c741-1b00-0000-87a4-c890610c0000 pid=3169 clone guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3171 /home/sandbox/iran.i486 delete-file net send-data zombie guuid=5283c741-1b00-0000-87a4-c890610c0000 pid=3169->guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3171 clone guuid=7341d641-1b00-0000-87a4-c890620c0000 pid=3170->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 con guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3171->b29c73e7-e8fa-54c6-9079-544985ba8278 send: 612B guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3172 /home/sandbox/iran.i486 zombie guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3171->guuid=6fddd641-1b00-0000-87a4-c890630c0000 pid=3172 clone guuid=1005c844-1b00-0000-87a4-c8906d0c0000 pid=3181->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 89B guuid=e5e1675b-1b00-0000-87a4-c890a20c0000 pid=3234->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 140B guuid=da3fb26f-1b00-0000-87a4-c890b30c0000 pid=3251->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 140B guuid=a4069683-1b00-0000-87a4-c890cf0c0000 pid=3279->ffe6d77b-9a3e-59fe-8a6e-d50c7077f491 send: 140B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-02-22 08:51:13 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 49c9a1b4a3f7f5b5badaccf2e837e90c9067b207a5d5ff941f1383a2ee70ccdf

(this sample)

  
Delivery method
Distributed via web download

Comments