MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 51e37873ee8098d11b8f6aef0b75fd3979cf8ab70c0f507d3e7354dcaf5d7473. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 51e37873ee8098d11b8f6aef0b75fd3979cf8ab70c0f507d3e7354dcaf5d7473
SHA3-384 hash: d153ca794a6ec36d175b6828d502477035967718c919281a7c2a0ea4b8c064ef0a7aa5d29e52b6b4d9409a147b915e86
SHA1 hash: 72655b656a9fa6449e72c561fe807333837231a0
MD5 hash: 52cf7293ddc6c890dd09b90d0da0dad8
humanhash: north-papa-orange-december
File name:cnr.sh
Download: download sample
Signature Mirai
File size:2'387 bytes
First seen:2025-10-13 20:30:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ScWYAjHk+n5kmPwkI0EpUI0KlPueqx4TSDn498cGAjN6x4T1:ScWYuHk+kmPwkI0EuI0YGeqx4TSU98cp
TLSH T13741F4CF7522062A914F9E4BB3F5A4F87033C4D720418B29EECC38A9F398D9A7044E25
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/arm1c6ad7da3701f41af453d1701d5656e256a6dcf08023270b2926685b82a19d07 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget
http://45.125.66.56/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraiddos DEU elf gafgyt geofenced mirai
http://45.125.66.56/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 MiraiDEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
UnixScript
First seen:
2025-10-13T10:32:00Z UTC
Last seen:
2025-10-13T10:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a0aa62c1-1600-0000-f299-acbfb80c0000 pid=3256 /usr/bin/sudo guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262 /tmp/sample.bin guuid=a0aa62c1-1600-0000-f299-acbfb80c0000 pid=3256->guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262 execve guuid=8ec111c4-1600-0000-f299-acbfc00c0000 pid=3264 /usr/bin/cp guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=8ec111c4-1600-0000-f299-acbfc00c0000 pid=3264 execve guuid=a479cac8-1600-0000-f299-acbfcc0c0000 pid=3276 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a479cac8-1600-0000-f299-acbfcc0c0000 pid=3276 execve guuid=825822cc-1600-0000-f299-acbfd50c0000 pid=3285 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=825822cc-1600-0000-f299-acbfd50c0000 pid=3285 execve guuid=73bd4ed4-1600-0000-f299-acbfe80c0000 pid=3304 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=73bd4ed4-1600-0000-f299-acbfe80c0000 pid=3304 clone guuid=6cd57ed4-1600-0000-f299-acbfe90c0000 pid=3305 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=6cd57ed4-1600-0000-f299-acbfe90c0000 pid=3305 execve guuid=b0ec03d5-1600-0000-f299-acbfeb0c0000 pid=3307 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=b0ec03d5-1600-0000-f299-acbfeb0c0000 pid=3307 clone guuid=5b7721d5-1600-0000-f299-acbfed0c0000 pid=3309 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=5b7721d5-1600-0000-f299-acbfed0c0000 pid=3309 execve guuid=30b96ed5-1600-0000-f299-acbfef0c0000 pid=3311 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=30b96ed5-1600-0000-f299-acbfef0c0000 pid=3311 execve guuid=ed1488d8-1600-0000-f299-acbff70c0000 pid=3319 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ed1488d8-1600-0000-f299-acbff70c0000 pid=3319 execve guuid=c84bafdd-1600-0000-f299-acbffc0c0000 pid=3324 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=c84bafdd-1600-0000-f299-acbffc0c0000 pid=3324 clone guuid=181ad3dd-1600-0000-f299-acbffd0c0000 pid=3325 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=181ad3dd-1600-0000-f299-acbffd0c0000 pid=3325 execve guuid=a28d2ade-1600-0000-f299-acbffe0c0000 pid=3326 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a28d2ade-1600-0000-f299-acbffe0c0000 pid=3326 clone guuid=2f504bde-1600-0000-f299-acbfff0c0000 pid=3327 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=2f504bde-1600-0000-f299-acbfff0c0000 pid=3327 execve guuid=f8ff9fde-1600-0000-f299-acbf000d0000 pid=3328 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=f8ff9fde-1600-0000-f299-acbf000d0000 pid=3328 execve guuid=ec40c8e1-1600-0000-f299-acbf080d0000 pid=3336 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ec40c8e1-1600-0000-f299-acbf080d0000 pid=3336 execve guuid=967f08e7-1600-0000-f299-acbf140d0000 pid=3348 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=967f08e7-1600-0000-f299-acbf140d0000 pid=3348 clone guuid=701021e7-1600-0000-f299-acbf150d0000 pid=3349 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=701021e7-1600-0000-f299-acbf150d0000 pid=3349 execve guuid=78897ce7-1600-0000-f299-acbf160d0000 pid=3350 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=78897ce7-1600-0000-f299-acbf160d0000 pid=3350 clone guuid=c3e29be7-1600-0000-f299-acbf170d0000 pid=3351 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=c3e29be7-1600-0000-f299-acbf170d0000 pid=3351 execve guuid=87bcf6e7-1600-0000-f299-acbf190d0000 pid=3353 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=87bcf6e7-1600-0000-f299-acbf190d0000 pid=3353 execve guuid=bf89ba27-1700-0000-f299-acbf980d0000 pid=3480 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=bf89ba27-1700-0000-f299-acbf980d0000 pid=3480 execve guuid=2ee3c468-1700-0000-f299-acbf060e0000 pid=3590 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=2ee3c468-1700-0000-f299-acbf060e0000 pid=3590 clone guuid=a220f268-1700-0000-f299-acbf070e0000 pid=3591 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a220f268-1700-0000-f299-acbf070e0000 pid=3591 execve guuid=99556a69-1700-0000-f299-acbf090e0000 pid=3593 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=99556a69-1700-0000-f299-acbf090e0000 pid=3593 clone guuid=e16d9a69-1700-0000-f299-acbf0a0e0000 pid=3594 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=e16d9a69-1700-0000-f299-acbf0a0e0000 pid=3594 execve guuid=81befd69-1700-0000-f299-acbf0c0e0000 pid=3596 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=81befd69-1700-0000-f299-acbf0c0e0000 pid=3596 execve guuid=7dc871a9-1700-0000-f299-acbf8f0e0000 pid=3727 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=7dc871a9-1700-0000-f299-acbf8f0e0000 pid=3727 execve guuid=e37257ee-1700-0000-f299-acbf340f0000 pid=3892 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=e37257ee-1700-0000-f299-acbf340f0000 pid=3892 clone guuid=c54985ee-1700-0000-f299-acbf350f0000 pid=3893 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=c54985ee-1700-0000-f299-acbf350f0000 pid=3893 execve guuid=b4a005ef-1700-0000-f299-acbf370f0000 pid=3895 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=b4a005ef-1700-0000-f299-acbf370f0000 pid=3895 clone guuid=289637ef-1700-0000-f299-acbf380f0000 pid=3896 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=289637ef-1700-0000-f299-acbf380f0000 pid=3896 execve guuid=99bdbcef-1700-0000-f299-acbf3a0f0000 pid=3898 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=99bdbcef-1700-0000-f299-acbf3a0f0000 pid=3898 execve guuid=20efca32-1800-0000-f299-acbfd60f0000 pid=4054 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=20efca32-1800-0000-f299-acbfd60f0000 pid=4054 execve guuid=3fd67338-1800-0000-f299-acbfe10f0000 pid=4065 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=3fd67338-1800-0000-f299-acbfe10f0000 pid=4065 clone guuid=548da038-1800-0000-f299-acbfe20f0000 pid=4066 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=548da038-1800-0000-f299-acbfe20f0000 pid=4066 execve guuid=2f681c39-1800-0000-f299-acbfe30f0000 pid=4067 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=2f681c39-1800-0000-f299-acbfe30f0000 pid=4067 clone guuid=441e4a39-1800-0000-f299-acbfe40f0000 pid=4068 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=441e4a39-1800-0000-f299-acbfe40f0000 pid=4068 execve guuid=2f6cd639-1800-0000-f299-acbfe70f0000 pid=4071 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=2f6cd639-1800-0000-f299-acbfe70f0000 pid=4071 execve guuid=81d13d7b-1800-0000-f299-acbf77100000 pid=4215 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=81d13d7b-1800-0000-f299-acbf77100000 pid=4215 execve guuid=ef651ac0-1800-0000-f299-acbf3d110000 pid=4413 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ef651ac0-1800-0000-f299-acbf3d110000 pid=4413 clone guuid=7f375ac0-1800-0000-f299-acbf3e110000 pid=4414 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=7f375ac0-1800-0000-f299-acbf3e110000 pid=4414 execve guuid=48ffc5c0-1800-0000-f299-acbf40110000 pid=4416 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=48ffc5c0-1800-0000-f299-acbf40110000 pid=4416 clone guuid=0be0e4c0-1800-0000-f299-acbf41110000 pid=4417 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=0be0e4c0-1800-0000-f299-acbf41110000 pid=4417 execve guuid=a5915cc1-1800-0000-f299-acbf45110000 pid=4421 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a5915cc1-1800-0000-f299-acbf45110000 pid=4421 execve guuid=8aceaf04-1900-0000-f299-acbfe6110000 pid=4582 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=8aceaf04-1900-0000-f299-acbfe6110000 pid=4582 execve guuid=87bb6349-1900-0000-f299-acbf8e120000 pid=4750 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=87bb6349-1900-0000-f299-acbf8e120000 pid=4750 clone guuid=a20a8949-1900-0000-f299-acbf91120000 pid=4753 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a20a8949-1900-0000-f299-acbf91120000 pid=4753 execve guuid=ef94084a-1900-0000-f299-acbf93120000 pid=4755 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ef94084a-1900-0000-f299-acbf93120000 pid=4755 clone guuid=ac482d4a-1900-0000-f299-acbf94120000 pid=4756 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ac482d4a-1900-0000-f299-acbf94120000 pid=4756 execve guuid=58e3ac4a-1900-0000-f299-acbf96120000 pid=4758 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=58e3ac4a-1900-0000-f299-acbf96120000 pid=4758 execve guuid=4602e88d-1900-0000-f299-acbf3a130000 pid=4922 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=4602e88d-1900-0000-f299-acbf3a130000 pid=4922 execve guuid=21e0f3ce-1900-0000-f299-acbfa3130000 pid=5027 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=21e0f3ce-1900-0000-f299-acbfa3130000 pid=5027 clone guuid=370f39cf-1900-0000-f299-acbfa5130000 pid=5029 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=370f39cf-1900-0000-f299-acbfa5130000 pid=5029 execve guuid=1b3514d0-1900-0000-f299-acbfa8130000 pid=5032 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=1b3514d0-1900-0000-f299-acbfa8130000 pid=5032 clone guuid=265645d0-1900-0000-f299-acbfa9130000 pid=5033 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=265645d0-1900-0000-f299-acbfa9130000 pid=5033 execve guuid=a9254fd1-1900-0000-f299-acbfab130000 pid=5035 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=a9254fd1-1900-0000-f299-acbfab130000 pid=5035 execve guuid=45029fd5-1900-0000-f299-acbfb6130000 pid=5046 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=45029fd5-1900-0000-f299-acbfb6130000 pid=5046 execve guuid=e0477717-1a00-0000-f299-acbf44140000 pid=5188 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=e0477717-1a00-0000-f299-acbf44140000 pid=5188 clone guuid=6f08aa17-1a00-0000-f299-acbf45140000 pid=5189 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=6f08aa17-1a00-0000-f299-acbf45140000 pid=5189 execve guuid=c2763318-1a00-0000-f299-acbf47140000 pid=5191 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=c2763318-1a00-0000-f299-acbf47140000 pid=5191 clone guuid=53c86018-1a00-0000-f299-acbf48140000 pid=5192 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=53c86018-1a00-0000-f299-acbf48140000 pid=5192 execve guuid=ef9ef318-1a00-0000-f299-acbf4b140000 pid=5195 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ef9ef318-1a00-0000-f299-acbf4b140000 pid=5195 execve guuid=7b140758-1a00-0000-f299-acbf9c140000 pid=5276 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=7b140758-1a00-0000-f299-acbf9c140000 pid=5276 execve guuid=5946fa98-1a00-0000-f299-acbf9d140000 pid=5277 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=5946fa98-1a00-0000-f299-acbf9d140000 pid=5277 clone guuid=15e51499-1a00-0000-f299-acbf9e140000 pid=5278 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=15e51499-1a00-0000-f299-acbf9e140000 pid=5278 execve guuid=e4916199-1a00-0000-f299-acbf9f140000 pid=5279 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=e4916199-1a00-0000-f299-acbf9f140000 pid=5279 clone guuid=c5d37b99-1a00-0000-f299-acbfa0140000 pid=5280 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=c5d37b99-1a00-0000-f299-acbfa0140000 pid=5280 execve guuid=2aa4c399-1a00-0000-f299-acbfa1140000 pid=5281 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=2aa4c399-1a00-0000-f299-acbfa1140000 pid=5281 execve guuid=b3daccd9-1a00-0000-f299-acbfa2140000 pid=5282 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=b3daccd9-1a00-0000-f299-acbfa2140000 pid=5282 execve guuid=710bd21a-1b00-0000-f299-acbfaa140000 pid=5290 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=710bd21a-1b00-0000-f299-acbfaa140000 pid=5290 clone guuid=0cadf61a-1b00-0000-f299-acbfab140000 pid=5291 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=0cadf61a-1b00-0000-f299-acbfab140000 pid=5291 execve guuid=ec9e571b-1b00-0000-f299-acbfac140000 pid=5292 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ec9e571b-1b00-0000-f299-acbfac140000 pid=5292 clone guuid=03f77c1b-1b00-0000-f299-acbfad140000 pid=5293 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=03f77c1b-1b00-0000-f299-acbfad140000 pid=5293 execve guuid=7fa9df1b-1b00-0000-f299-acbfae140000 pid=5294 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=7fa9df1b-1b00-0000-f299-acbfae140000 pid=5294 execve guuid=002f7e5b-1b00-0000-f299-acbfaf140000 pid=5295 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=002f7e5b-1b00-0000-f299-acbfaf140000 pid=5295 execve guuid=6fe91aa0-1b00-0000-f299-acbfb0140000 pid=5296 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=6fe91aa0-1b00-0000-f299-acbfb0140000 pid=5296 clone guuid=fede78a0-1b00-0000-f299-acbfb1140000 pid=5297 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=fede78a0-1b00-0000-f299-acbfb1140000 pid=5297 execve guuid=99fa30a1-1b00-0000-f299-acbfb2140000 pid=5298 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=99fa30a1-1b00-0000-f299-acbfb2140000 pid=5298 clone guuid=bb25aaa1-1b00-0000-f299-acbfb3140000 pid=5299 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=bb25aaa1-1b00-0000-f299-acbfb3140000 pid=5299 execve guuid=d8bc21a2-1b00-0000-f299-acbfb4140000 pid=5300 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=d8bc21a2-1b00-0000-f299-acbfb4140000 pid=5300 execve guuid=fed7d3e4-1b00-0000-f299-acbfb5140000 pid=5301 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=fed7d3e4-1b00-0000-f299-acbfb5140000 pid=5301 execve guuid=23358229-1c00-0000-f299-acbfc6140000 pid=5318 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=23358229-1c00-0000-f299-acbfc6140000 pid=5318 clone guuid=f118b929-1c00-0000-f299-acbfc7140000 pid=5319 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=f118b929-1c00-0000-f299-acbfc7140000 pid=5319 execve guuid=4a444b2a-1c00-0000-f299-acbfc8140000 pid=5320 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=4a444b2a-1c00-0000-f299-acbfc8140000 pid=5320 clone guuid=921c7c2a-1c00-0000-f299-acbfc9140000 pid=5321 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=921c7c2a-1c00-0000-f299-acbfc9140000 pid=5321 execve guuid=600bf62a-1c00-0000-f299-acbfca140000 pid=5322 /usr/bin/wget net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=600bf62a-1c00-0000-f299-acbfca140000 pid=5322 execve guuid=fac3b52e-1c00-0000-f299-acbfce140000 pid=5326 /usr/bin/curl net guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=fac3b52e-1c00-0000-f299-acbfce140000 pid=5326 execve guuid=816a4172-1c00-0000-f299-acbfdc140000 pid=5340 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=816a4172-1c00-0000-f299-acbfdc140000 pid=5340 clone guuid=4ffd7a72-1c00-0000-f299-acbfdd140000 pid=5341 /usr/bin/chmod guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=4ffd7a72-1c00-0000-f299-acbfdd140000 pid=5341 execve guuid=ed860e73-1c00-0000-f299-acbfde140000 pid=5342 /usr/bin/bash guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=ed860e73-1c00-0000-f299-acbfde140000 pid=5342 clone guuid=9f474473-1c00-0000-f299-acbfdf140000 pid=5343 /usr/bin/rm guuid=e3e594c3-1600-0000-f299-acbfbe0c0000 pid=3262->guuid=9f474473-1c00-0000-f299-acbfdf140000 pid=5343 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=a479cac8-1600-0000-f299-acbfcc0c0000 pid=3276->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=825822cc-1600-0000-f299-acbfd50c0000 pid=3285->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=30b96ed5-1600-0000-f299-acbfef0c0000 pid=3311->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=ed1488d8-1600-0000-f299-acbff70c0000 pid=3319->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=f8ff9fde-1600-0000-f299-acbf000d0000 pid=3328->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=ec40c8e1-1600-0000-f299-acbf080d0000 pid=3336->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=87bcf6e7-1600-0000-f299-acbf190d0000 pid=3353->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=bf89ba27-1700-0000-f299-acbf980d0000 pid=3480->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=81befd69-1700-0000-f299-acbf0c0e0000 pid=3596->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=7dc871a9-1700-0000-f299-acbf8f0e0000 pid=3727->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=99bdbcef-1700-0000-f299-acbf3a0f0000 pid=3898->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=20efca32-1800-0000-f299-acbfd60f0000 pid=4054->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=2f6cd639-1800-0000-f299-acbfe70f0000 pid=4071->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=81d13d7b-1800-0000-f299-acbf77100000 pid=4215->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=a5915cc1-1800-0000-f299-acbf45110000 pid=4421->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=8aceaf04-1900-0000-f299-acbfe6110000 pid=4582->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=58e3ac4a-1900-0000-f299-acbf96120000 pid=4758->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=4602e88d-1900-0000-f299-acbf3a130000 pid=4922->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=a9254fd1-1900-0000-f299-acbfab130000 pid=5035->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=45029fd5-1900-0000-f299-acbfb6130000 pid=5046->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=ef9ef318-1a00-0000-f299-acbf4b140000 pid=5195->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=7b140758-1a00-0000-f299-acbf9c140000 pid=5276->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=2aa4c399-1a00-0000-f299-acbfa1140000 pid=5281->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=b3daccd9-1a00-0000-f299-acbfa2140000 pid=5282->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=7fa9df1b-1b00-0000-f299-acbfae140000 pid=5294->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=002f7e5b-1b00-0000-f299-acbfaf140000 pid=5295->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=d8bc21a2-1b00-0000-f299-acbfb4140000 pid=5300->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=fed7d3e4-1b00-0000-f299-acbfb5140000 pid=5301->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=600bf62a-1c00-0000-f299-acbfca140000 pid=5322->28318de2-8d63-5b31-be23-c532c58983b9 con guuid=fac3b52e-1c00-0000-f299-acbfce140000 pid=5326->28318de2-8d63-5b31-be23-c532c58983b9 con
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-13 19:34:44 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 51e37873ee8098d11b8f6aef0b75fd3979cf8ab70c0f507d3e7354dcaf5d7473

(this sample)

  
Delivery method
Distributed via web download

Comments