MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a96f132025ca1ec8c7efa747c130bffb7e39fb1992e8d08db20926e9f494dbe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Ngioweb


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4a96f132025ca1ec8c7efa747c130bffb7e39fb1992e8d08db20926e9f494dbe
SHA3-384 hash: eb8651fca292388143755b08a52c62e77535eb3175c0e7b3cd2097ddfb505f50f985cb9d73438a2b4f5091879abf7826
SHA1 hash: 6dc94d7e6e722caeb477eeebd921d9ade9b72b85
MD5 hash: 08f6ef6eca372c7a95dcb3e52896bd6f
humanhash: aspen-uniform-fix-carpet
File name:router.lblink-rep.sh
Download: download sample
Signature Ngioweb
File size:832 bytes
First seen:2025-11-08 06:39:29 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:78CN7cTCI7cTC37cTCB7cTCXq7cTCJ7cTC7bE7cTC7kE7Q:pNoWIoW3oWBoW6oWJoWvEoW4E0
TLSH T1710165AE31018993870CC700BD6EF414F119825748C3BB6886AD0E39C6BA915BB51F75
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.80/frost.armv7d0ca62e68e235aca958e3877ae7ed505c5667207c95d34907bc806e5ffa0b21b Ngiowebelf geofenced Ngioweb ua-wget USA
http://87.121.84.80/frost.armv6f08d8c43beedbc8d45ea133b44dd09e13d80d725846eac7615141dee9064907e Ngiowebelf geofenced Ngioweb ua-wget USA
http://87.121.84.80/frost.armv5966770e3938bb350119a960948a15421d9c6e0944c4d49f5aa631d3bd9fee703 Ngiowebelf geofenced Ngioweb ua-wget USA
http://87.121.84.80/frost.mipsn/an/aelf geofenced ua-wget USA
http://87.121.84.80/frost.mipsel8758eddd99d34eae170f69fe5c58231a546fef0f56a7e30eefac59ef10ca906b Miraielf geofenced mirai ua-wget USA
http://87.121.84.80/frost.aarch647997eca9041eb31e0264e9273d28e3b672f6f6cb206919ea1167610cfa601f93 Miraielf geofenced mirai ua-wget USA
http://87.121.84.80/frost.x86296d6af5b711aada05ec72d517af8b677c32d4f894fda2934ad5289b7f671619 Miraielf geofenced mirai ua-wget USA
http://87.121.84.80/frost.x86_64a85c562d0b13602adfad63635f895ba1fcd8f4780121f7f98febc10fbfba1819 Miraielf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-08T04:15:00Z UTC
Last seen:
2025-11-08T06:37:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=2f63b0e9-1600-0000-037f-a801f10d0000 pid=3569 /usr/bin/sudo guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577 /tmp/sample.bin guuid=2f63b0e9-1600-0000-037f-a801f10d0000 pid=3569->guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577 execve guuid=54f4edeb-1600-0000-037f-a801fa0d0000 pid=3578 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=54f4edeb-1600-0000-037f-a801fa0d0000 pid=3578 execve guuid=7500dcf2-1600-0000-037f-a8010c0e0000 pid=3596 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=7500dcf2-1600-0000-037f-a8010c0e0000 pid=3596 execve guuid=9fb70ff3-1600-0000-037f-a8010d0e0000 pid=3597 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=9fb70ff3-1600-0000-037f-a8010d0e0000 pid=3597 clone guuid=138290f3-1600-0000-037f-a801100e0000 pid=3600 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=138290f3-1600-0000-037f-a801100e0000 pid=3600 execve guuid=e06b06f4-1600-0000-037f-a801130e0000 pid=3603 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=e06b06f4-1600-0000-037f-a801130e0000 pid=3603 execve guuid=0e746cfe-1600-0000-037f-a801330e0000 pid=3635 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=0e746cfe-1600-0000-037f-a801330e0000 pid=3635 execve guuid=f336a6fe-1600-0000-037f-a801370e0000 pid=3639 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=f336a6fe-1600-0000-037f-a801370e0000 pid=3639 clone guuid=30ce2dff-1600-0000-037f-a801390e0000 pid=3641 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=30ce2dff-1600-0000-037f-a801390e0000 pid=3641 execve guuid=4b556dff-1600-0000-037f-a8013d0e0000 pid=3645 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=4b556dff-1600-0000-037f-a8013d0e0000 pid=3645 execve guuid=8db0fc0a-1700-0000-037f-a801520e0000 pid=3666 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=8db0fc0a-1700-0000-037f-a801520e0000 pid=3666 execve guuid=4adbc60b-1700-0000-037f-a801530e0000 pid=3667 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=4adbc60b-1700-0000-037f-a801530e0000 pid=3667 clone guuid=f84d140d-1700-0000-037f-a801550e0000 pid=3669 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=f84d140d-1700-0000-037f-a801550e0000 pid=3669 execve guuid=7513a30d-1700-0000-037f-a801560e0000 pid=3670 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=7513a30d-1700-0000-037f-a801560e0000 pid=3670 execve guuid=d030a12a-1700-0000-037f-a801970e0000 pid=3735 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=d030a12a-1700-0000-037f-a801970e0000 pid=3735 execve guuid=d21ce52a-1700-0000-037f-a801990e0000 pid=3737 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=d21ce52a-1700-0000-037f-a801990e0000 pid=3737 clone guuid=6083872b-1700-0000-037f-a8019e0e0000 pid=3742 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=6083872b-1700-0000-037f-a8019e0e0000 pid=3742 execve guuid=f5b8d02b-1700-0000-037f-a801a20e0000 pid=3746 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=f5b8d02b-1700-0000-037f-a801a20e0000 pid=3746 execve guuid=be96a742-1700-0000-037f-a801ed0e0000 pid=3821 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=be96a742-1700-0000-037f-a801ed0e0000 pid=3821 execve guuid=5ab41243-1700-0000-037f-a801ef0e0000 pid=3823 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=5ab41243-1700-0000-037f-a801ef0e0000 pid=3823 clone guuid=032b0944-1700-0000-037f-a801f40e0000 pid=3828 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=032b0944-1700-0000-037f-a801f40e0000 pid=3828 execve guuid=d7527b44-1700-0000-037f-a801fb0e0000 pid=3835 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=d7527b44-1700-0000-037f-a801fb0e0000 pid=3835 execve guuid=cea8cb53-1700-0000-037f-a801270f0000 pid=3879 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=cea8cb53-1700-0000-037f-a801270f0000 pid=3879 execve guuid=dcd31f54-1700-0000-037f-a801290f0000 pid=3881 /usr/bin/dash guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=dcd31f54-1700-0000-037f-a801290f0000 pid=3881 clone guuid=d4edf254-1700-0000-037f-a8012d0f0000 pid=3885 /usr/bin/rm delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=d4edf254-1700-0000-037f-a8012d0f0000 pid=3885 execve guuid=1cb96055-1700-0000-037f-a8012f0f0000 pid=3887 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=1cb96055-1700-0000-037f-a8012f0f0000 pid=3887 execve guuid=34a2de69-1700-0000-037f-a801660f0000 pid=3942 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=34a2de69-1700-0000-037f-a801660f0000 pid=3942 execve guuid=85d55d6a-1700-0000-037f-a801690f0000 pid=3945 /tmp/hrvq delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=85d55d6a-1700-0000-037f-a801690f0000 pid=3945 execve guuid=f15f976a-1700-0000-037f-a8016c0f0000 pid=3948 /usr/bin/rm guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=f15f976a-1700-0000-037f-a8016c0f0000 pid=3948 execve guuid=774d096b-1700-0000-037f-a8016d0f0000 pid=3949 /usr/bin/wget net send-data write-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=774d096b-1700-0000-037f-a8016d0f0000 pid=3949 execve guuid=91119070-1700-0000-037f-a801800f0000 pid=3968 /usr/bin/chmod guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=91119070-1700-0000-037f-a801800f0000 pid=3968 execve guuid=26620771-1700-0000-037f-a801820f0000 pid=3970 /tmp/hrvq delete-file guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=26620771-1700-0000-037f-a801820f0000 pid=3970 execve guuid=27cd2e71-1700-0000-037f-a801840f0000 pid=3972 /usr/bin/rm guuid=733fb2eb-1600-0000-037f-a801f90d0000 pid=3577->guuid=27cd2e71-1700-0000-037f-a801840f0000 pid=3972 execve 8a0fa304-c855-5f37-833d-84ef77e0b826 87.121.84.80:80 guuid=54f4edeb-1600-0000-037f-a801fa0d0000 pid=3578->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 138B guuid=e06b06f4-1600-0000-037f-a801130e0000 pid=3603->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 138B guuid=4b556dff-1600-0000-037f-a8013d0e0000 pid=3645->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 138B guuid=7513a30d-1700-0000-037f-a801560e0000 pid=3670->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 137B guuid=f5b8d02b-1700-0000-037f-a801a20e0000 pid=3746->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 139B guuid=d7527b44-1700-0000-037f-a801fb0e0000 pid=3835->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 140B guuid=1cb96055-1700-0000-037f-a8012f0f0000 pid=3887->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 136B guuid=e0927c6a-1700-0000-037f-a8016b0f0000 pid=3947 /tmp/hrvq net send-data zombie guuid=85d55d6a-1700-0000-037f-a801690f0000 pid=3945->guuid=e0927c6a-1700-0000-037f-a8016b0f0000 pid=3947 clone 5964582a-537a-5ab9-bea4-3571985c6152 69.5.189.168:5555 guuid=e0927c6a-1700-0000-037f-a8016b0f0000 pid=3947->5964582a-537a-5ab9-bea4-3571985c6152 con 74e4e219-c467-5008-a212-50a3f10516d3 114.114.115.115:53 guuid=e0927c6a-1700-0000-037f-a8016b0f0000 pid=3947->74e4e219-c467-5008-a212-50a3f10516d3 send: 27B guuid=774d096b-1700-0000-037f-a8016d0f0000 pid=3949->8a0fa304-c855-5f37-833d-84ef77e0b826 send: 139B guuid=e1812171-1700-0000-037f-a801830f0000 pid=3971 /tmp/hrvq net send-data zombie guuid=26620771-1700-0000-037f-a801820f0000 pid=3970->guuid=e1812171-1700-0000-037f-a801830f0000 pid=3971 clone guuid=e1812171-1700-0000-037f-a801830f0000 pid=3971->5964582a-537a-5ab9-bea4-3571985c6152 send: 68B ab7b7b79-1dfc-52b2-b0c8-4756a62bd7f5 208.67.220.220:53 guuid=e1812171-1700-0000-037f-a801830f0000 pid=3971->ab7b7b79-1dfc-52b2-b0c8-4756a62bd7f5 send: 27B guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123 /tmp/hrvq net net-scan send-data zombie guuid=e1812171-1700-0000-037f-a801830f0000 pid=3971->guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0e5bcc14-2e4c-5622-9a4f-2e198388d298 156.251.154.223:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->0e5bcc14-2e4c-5622-9a4f-2e198388d298 send: 128B be77ccee-31fb-59e3-99e1-77023e65c7b5 100.24.98.26:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->be77ccee-31fb-59e3-99e1-77023e65c7b5 send: 122B a548563c-a66e-5ebc-9a05-2d8b4b963c65 18.172.203.47:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->a548563c-a66e-5ebc-9a05-2d8b4b963c65 send: 124B 2047bcf3-1882-57f3-a83a-b56b51c13587 194.143.235.248:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->2047bcf3-1882-57f3-a83a-b56b51c13587 send: 128B 10337722-f791-56d9-be5c-d775ca6b1ec8 184.29.95.64:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->10337722-f791-56d9-be5c-d775ca6b1ec8 send: 122B 4d5b05f7-6289-5a3d-ab88-653013e87195 24.144.81.73:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->4d5b05f7-6289-5a3d-ab88-653013e87195 send: 122B e37fb7e8-b621-58f8-9ed9-c553c62a9947 210.43.144.207:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->e37fb7e8-b621-58f8-9ed9-c553c62a9947 send: 126B 8d18eccd-3bad-5697-8e74-c5b66d561a4b 156.226.101.74:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->8d18eccd-3bad-5697-8e74-c5b66d561a4b send: 126B e344c482-2bf8-5c38-bad7-ec1894335050 18.238.127.246:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->e344c482-2bf8-5c38-bad7-ec1894335050 send: 126B 1a450cd5-6e9b-5b3a-985b-fe43c5a28bda 210.152.13.244:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->1a450cd5-6e9b-5b3a-985b-fe43c5a28bda send: 126B b10ccf8c-ca04-5589-8cbe-62a62f38bc86 24.199.108.44:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->b10ccf8c-ca04-5589-8cbe-62a62f38bc86 send: 124B d8f81643-81f9-5ff3-9652-2abb01940b8f 190.92.224.237:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->d8f81643-81f9-5ff3-9652-2abb01940b8f send: 126B 133bb012-6671-532a-a626-c71335f4512f 4.227.71.220:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->133bb012-6671-532a-a626-c71335f4512f send: 122B 3ed796a9-f34c-5ca2-9af6-13e56bb0089c 156.247.123.25:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->3ed796a9-f34c-5ca2-9af6-13e56bb0089c send: 126B bfde6265-4fcb-5337-8a0a-7cf9702707a6 204.148.83.106:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->bfde6265-4fcb-5337-8a0a-7cf9702707a6 send: 126B 6834768c-0fcf-5a16-bdfa-ba6d026809e0 34.8.249.141:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->6834768c-0fcf-5a16-bdfa-ba6d026809e0 send: 122B 0fa44303-7f07-5902-acc8-8915673af394 52.11.233.154:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->0fa44303-7f07-5902-acc8-8915673af394 send: 124B a7afd875-3fa9-592d-99ec-c267fc759ffb 204.62.13.44:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->a7afd875-3fa9-592d-99ec-c267fc759ffb send: 122B 151bf84c-a143-5547-8a34-d38768bc6524 166.178.113.192:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->151bf84c-a143-5547-8a34-d38768bc6524 send: 128B 490fe52f-3b1c-5bc9-91d2-4f7d9125e31a 52.84.205.213:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->490fe52f-3b1c-5bc9-91d2-4f7d9125e31a send: 124B 4960a595-9790-5721-b072-df80f525bcb4 4.245.180.14:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->4960a595-9790-5721-b072-df80f525bcb4 send: 122B b8b86881-f9ce-55fe-a2f6-b25aafbe3678 80.74.136.18:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->b8b86881-f9ce-55fe-a2f6-b25aafbe3678 send: 122B 34739479-3a39-5e66-8182-3f5b4168bd2f 78.186.253.35:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->34739479-3a39-5e66-8182-3f5b4168bd2f send: 124B 3ea3bb4b-31b4-529c-bc89-e9127b692162 66.42.125.67:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->3ea3bb4b-31b4-529c-bc89-e9127b692162 send: 122B 925f094b-7746-5771-9a4d-8d212d327c02 52.208.130.188:80 guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->925f094b-7746-5771-9a4d-8d212d327c02 send: 83B guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123|send-data send-data to 4048 IP addresses review logs to see them all guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123->guuid=e1812171-1700-0000-037f-a801830f0000 pid=4123|send-data send
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-11-08 06:40:22 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Ngioweb

sh 4a96f132025ca1ec8c7efa747c130bffb7e39fb1992e8d08db20926e9f494dbe

(this sample)

  
Delivery method
Distributed via web download

Comments