MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e870f9a29df45e40b6f99c2cb7ad4bd04e56e397fbf0fbed8f3db11765cf4d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



RondoDox


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 5e870f9a29df45e40b6f99c2cb7ad4bd04e56e397fbf0fbed8f3db11765cf4d6
SHA3-384 hash: e3a41ad9c7c7cf4147fccec8eda79ac9a5da31a69f46599ee6ea3adb29ba5882142f4bd090dd1c0231d125b14e329f78
SHA1 hash: 7ad7fdc0ed05a93719a3328f4cc9cfa0d5147f7c
MD5 hash: 212b7d12e9878eb908b17a060adea7c9
humanhash: bulldog-uniform-sink-utah
File name:rondo.aqu.sh
Download: download sample
Signature RondoDox
File size:10'876 bytes
First seen:2026-01-11 13:21:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:hiOfWVc1dZd4cjzlZ16EMvyK6tTVRei0E3alsqHyxI/mteVql42eCsq+0zo+Az:hs9W7I1vVYTSPvCZ8
TLSH T11F2216F831F021F626E548D261AF827CAD48C1E96166BDB9F44848F29FFEA4C607D741
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai RondoDox sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i68617f7ae49f8e81015b4ad26357507a65afc167c3d64e057ef68dc45b30ad51c3c Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc7005c962dd26e5abde76e00bc103556830877f1d918e1a0a2a1ed7651bc9a2bed20 Miraimirai ua-wget
http://41.231.37.153/rondo.sh4a65e69fc4d85ca011f2ea990f0c60e0354eced0b48823af44baa4e9c7c291426 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc56b4cd8885adff593836b6b6d6c205b2001df64cd47c4d0d0d16a65898a6b0aa Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68kb1cb071443ab306df0445b74bcbe27535153c2178561be77f58ee03002fa9d00 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive masquerade soft-404
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-01-11 13:22:27 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm credential_access defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads process memory
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Modifies init.d
Modifies rc script
Reads hardware information
Reads list of loaded kernel modules
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Renames itself
XMRig Miner payload
Xmrig family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

RondoDox

sh 5e870f9a29df45e40b6f99c2cb7ad4bd04e56e397fbf0fbed8f3db11765cf4d6

(this sample)

  
Delivery method
Distributed via web download

Comments