🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 669d311967eb7abe0f2b1a8155f5f90d8042b657c97943d9b448da8a62595bc7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 669d311967eb7abe0f2b1a8155f5f90d8042b657c97943d9b448da8a62595bc7
SHA3-384 hash: 86bd5bf747edd8c501dd4b03c39e11ac101b3a0ab28a92e17bafa9dd49117ee418e0e041759870c4e6d03e7357211a95
SHA1 hash: 28c0344ebd66a837787a7fe034a74626797dd78c
MD5 hash: d8324f553a62e387101c4ca2f00d9f96
humanhash: nine-venus-arkansas-asparagus
File name:womp
Download: download sample
Signature Mirai
File size:1'905 bytes
First seen:2026-06-18 07:24:16 UTC
Last seen:2026-06-18 08:21:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:973PpZSG7MvNIsV0LKucaSrbiL97iXWZ9M9VyRpKbwinuQpZSFNIstLKuavD9jX/:Jp8pNI3K3pP2RpKs6p8FNImKuAyRpKGU
TLSH T14C41DBDD30EF24B65D02BE42B15188D4F549F2EBB8969F44FC448EB1C597AB6302CB84
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.175.223.249/data_arm4ec32ee9f654e4817249df530db663c775b81e11868c7c087888eb49f5e7485dc Miraielf mirai ua-wget
http://5.175.223.249/data_arm50d7e6368812054f582aeebc64894770bc09353f074fb26a0281cf79e395f4963 Miraielf mirai ua-wget
http://5.175.223.249/data_arm680826c175e9ba582279f1f5b14e4aff7540aea8c8d125ae029dffdeb1235de08 Miraielf mirai ua-wget
http://5.175.223.249/data_arm79ba2316d355bef23251b64d0f39abd38b25685f5d7db78b3b4be73d1eda5dbe4 Miraielf mirai ua-wget
http://5.175.223.249/data_aarch645fb8f703c58eb7a26db0565a95dd120eec4ef55c3380fba1dd267b302f921c3c Miraielf mirai ua-wget
http://5.175.223.249/data_mips6d95be925f16dbe7cdd83de323b9a22659c2754718642c34947d15034f704b62 Miraielf mirai ua-wget
http://5.175.223.249/data_mipsel7cc6bffe4402d553bb262c06a6e531a50962c756b667740dffc1f6595a57d45d Miraielf mirai ua-wget
http://5.175.223.249/data_mips-uclibc599fea2f9d0ca4a75c5826d8df45d7deab9d9f03d8f4928166ffefddce58218d Miraielf mirai ua-wget
http://5.175.223.249/data_mipsel-uclibcaf46ef9ec0e2095be44fa101c3109cc7a98aa82977dc4fabf5ee37bdabea0dd1 Miraielf mirai ua-wget
http://5.175.223.249/data_powerpc7cb98e74bd2710be1e515ea8d1a54f7608c4d026230076faef5e779407544b47 Miraielf mirai ua-wget
http://5.175.223.249/data_x86ea47c0cf85318989bcb625474229bd9b5ab0263f8a79eb6231b44c3a0ca6bf25 Miraielf mirai ua-wget
http://5.175.223.249/data_x86_64758bfd53af3403244492a07a78388568547092bd62207b48f8f438a3afa9cb3b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-18T04:34:00Z UTC
Last seen:
2026-06-19T21:08:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=6f7d5130-1900-0000-65a0-35bb2f140000 pid=5167 /usr/bin/sudo guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168 /tmp/sample.bin guuid=6f7d5130-1900-0000-65a0-35bb2f140000 pid=5167->guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168 execve guuid=9c537432-1900-0000-65a0-35bb31140000 pid=5169 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=9c537432-1900-0000-65a0-35bb31140000 pid=5169 execve guuid=86aa4050-1900-0000-65a0-35bb32140000 pid=5170 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=86aa4050-1900-0000-65a0-35bb32140000 pid=5170 execve guuid=67a89650-1900-0000-65a0-35bb33140000 pid=5171 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=67a89650-1900-0000-65a0-35bb33140000 pid=5171 clone guuid=f15a2b51-1900-0000-65a0-35bb35140000 pid=5173 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=f15a2b51-1900-0000-65a0-35bb35140000 pid=5173 execve guuid=9aa5575c-1900-0000-65a0-35bb36140000 pid=5174 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=9aa5575c-1900-0000-65a0-35bb36140000 pid=5174 execve guuid=a36ba15c-1900-0000-65a0-35bb37140000 pid=5175 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=a36ba15c-1900-0000-65a0-35bb37140000 pid=5175 clone guuid=ff85445d-1900-0000-65a0-35bb39140000 pid=5177 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=ff85445d-1900-0000-65a0-35bb39140000 pid=5177 execve guuid=d328e567-1900-0000-65a0-35bb3a140000 pid=5178 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=d328e567-1900-0000-65a0-35bb3a140000 pid=5178 execve guuid=e9962868-1900-0000-65a0-35bb3b140000 pid=5179 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=e9962868-1900-0000-65a0-35bb3b140000 pid=5179 clone guuid=dae0c168-1900-0000-65a0-35bb3d140000 pid=5181 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=dae0c168-1900-0000-65a0-35bb3d140000 pid=5181 execve guuid=785f7e73-1900-0000-65a0-35bb3e140000 pid=5182 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=785f7e73-1900-0000-65a0-35bb3e140000 pid=5182 execve guuid=8cb6c373-1900-0000-65a0-35bb3f140000 pid=5183 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=8cb6c373-1900-0000-65a0-35bb3f140000 pid=5183 clone guuid=49825274-1900-0000-65a0-35bb41140000 pid=5185 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=49825274-1900-0000-65a0-35bb41140000 pid=5185 execve guuid=dd670984-1900-0000-65a0-35bb42140000 pid=5186 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=dd670984-1900-0000-65a0-35bb42140000 pid=5186 execve guuid=27dc5584-1900-0000-65a0-35bb43140000 pid=5187 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=27dc5584-1900-0000-65a0-35bb43140000 pid=5187 clone guuid=b3aa3c86-1900-0000-65a0-35bb45140000 pid=5189 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=b3aa3c86-1900-0000-65a0-35bb45140000 pid=5189 execve guuid=66153f91-1900-0000-65a0-35bb4a140000 pid=5194 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=66153f91-1900-0000-65a0-35bb4a140000 pid=5194 execve guuid=bccda291-1900-0000-65a0-35bb4b140000 pid=5195 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=bccda291-1900-0000-65a0-35bb4b140000 pid=5195 clone guuid=d7f17892-1900-0000-65a0-35bb50140000 pid=5200 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=d7f17892-1900-0000-65a0-35bb50140000 pid=5200 execve guuid=db26279e-1900-0000-65a0-35bb51140000 pid=5201 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=db26279e-1900-0000-65a0-35bb51140000 pid=5201 execve guuid=67f18e9e-1900-0000-65a0-35bb52140000 pid=5202 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=67f18e9e-1900-0000-65a0-35bb52140000 pid=5202 clone guuid=211ba1a0-1900-0000-65a0-35bb54140000 pid=5204 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=211ba1a0-1900-0000-65a0-35bb54140000 pid=5204 execve guuid=01aa7fac-1900-0000-65a0-35bb55140000 pid=5205 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=01aa7fac-1900-0000-65a0-35bb55140000 pid=5205 execve guuid=bfe603ad-1900-0000-65a0-35bb56140000 pid=5206 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=bfe603ad-1900-0000-65a0-35bb56140000 pid=5206 clone guuid=bc96f0ad-1900-0000-65a0-35bb58140000 pid=5208 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=bc96f0ad-1900-0000-65a0-35bb58140000 pid=5208 execve guuid=65d846b9-1900-0000-65a0-35bb59140000 pid=5209 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=65d846b9-1900-0000-65a0-35bb59140000 pid=5209 execve guuid=bd6ffcb9-1900-0000-65a0-35bb5a140000 pid=5210 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=bd6ffcb9-1900-0000-65a0-35bb5a140000 pid=5210 clone guuid=5a767dbc-1900-0000-65a0-35bb5c140000 pid=5212 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=5a767dbc-1900-0000-65a0-35bb5c140000 pid=5212 execve guuid=71ac33ca-1900-0000-65a0-35bb5d140000 pid=5213 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=71ac33ca-1900-0000-65a0-35bb5d140000 pid=5213 execve guuid=59068aca-1900-0000-65a0-35bb5e140000 pid=5214 /usr/bin/dash guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=59068aca-1900-0000-65a0-35bb5e140000 pid=5214 clone guuid=c3d0b0cc-1900-0000-65a0-35bb60140000 pid=5216 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=c3d0b0cc-1900-0000-65a0-35bb60140000 pid=5216 execve guuid=8f25f5f6-1900-0000-65a0-35bb61140000 pid=5217 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=8f25f5f6-1900-0000-65a0-35bb61140000 pid=5217 execve guuid=7efe3ff7-1900-0000-65a0-35bb62140000 pid=5218 /home/sandbox/data_x86 net guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=7efe3ff7-1900-0000-65a0-35bb62140000 pid=5218 execve guuid=af8480f7-1900-0000-65a0-35bb64140000 pid=5220 /usr/bin/curl net send-data write-file guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=af8480f7-1900-0000-65a0-35bb64140000 pid=5220 execve guuid=d53a3e07-1a00-0000-65a0-35bb6b140000 pid=5227 /usr/bin/chmod guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=d53a3e07-1a00-0000-65a0-35bb6b140000 pid=5227 execve guuid=eb0c1709-1a00-0000-65a0-35bb6c140000 pid=5228 /home/sandbox/data_x86_64 net guuid=d4333a32-1900-0000-65a0-35bb30140000 pid=5168->guuid=eb0c1709-1a00-0000-65a0-35bb6c140000 pid=5228 execve 16272418-1aa7-5a5b-8d52-420e83ac841c 5.175.223.249:80 guuid=9c537432-1900-0000-65a0-35bb31140000 pid=5169->16272418-1aa7-5a5b-8d52-420e83ac841c send: 86B guuid=f15a2b51-1900-0000-65a0-35bb35140000 pid=5173->16272418-1aa7-5a5b-8d52-420e83ac841c send: 86B guuid=ff85445d-1900-0000-65a0-35bb39140000 pid=5177->16272418-1aa7-5a5b-8d52-420e83ac841c send: 86B guuid=dae0c168-1900-0000-65a0-35bb3d140000 pid=5181->16272418-1aa7-5a5b-8d52-420e83ac841c send: 86B guuid=49825274-1900-0000-65a0-35bb41140000 pid=5185->16272418-1aa7-5a5b-8d52-420e83ac841c send: 89B guuid=b3aa3c86-1900-0000-65a0-35bb45140000 pid=5189->16272418-1aa7-5a5b-8d52-420e83ac841c send: 86B guuid=d7f17892-1900-0000-65a0-35bb50140000 pid=5200->16272418-1aa7-5a5b-8d52-420e83ac841c send: 88B guuid=211ba1a0-1900-0000-65a0-35bb54140000 pid=5204->16272418-1aa7-5a5b-8d52-420e83ac841c send: 93B guuid=bc96f0ad-1900-0000-65a0-35bb58140000 pid=5208->16272418-1aa7-5a5b-8d52-420e83ac841c send: 95B guuid=5a767dbc-1900-0000-65a0-35bb5c140000 pid=5212->16272418-1aa7-5a5b-8d52-420e83ac841c send: 89B guuid=c3d0b0cc-1900-0000-65a0-35bb60140000 pid=5216->16272418-1aa7-5a5b-8d52-420e83ac841c send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7efe3ff7-1900-0000-65a0-35bb62140000 pid=5218->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c45278f7-1900-0000-65a0-35bb63140000 pid=5219 /home/sandbox/data_x86 guuid=7efe3ff7-1900-0000-65a0-35bb62140000 pid=5218->guuid=c45278f7-1900-0000-65a0-35bb63140000 pid=5219 clone guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221 /home/sandbox/data_x86 net send-data write-file zombie guuid=c45278f7-1900-0000-65a0-35bb63140000 pid=5219->guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221 clone guuid=af8480f7-1900-0000-65a0-35bb64140000 pid=5220->16272418-1aa7-5a5b-8d52-420e83ac841c send: 88B guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 66B 1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 46.247.108.74:8082 guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221->1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 send: 11B guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5222 /home/sandbox/data_x86 send-data zombie guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221->guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5222 clone guuid=feac79f8-1900-0000-65a0-35bb67140000 pid=5223 /home/sandbox/data_x86 net send-data write-file guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221->guuid=feac79f8-1900-0000-65a0-35bb67140000 pid=5223 clone guuid=4c747cf8-1900-0000-65a0-35bb68140000 pid=5224 /home/sandbox/data_x86 net guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5221->guuid=4c747cf8-1900-0000-65a0-35bb68140000 pid=5224 clone guuid=62f952f8-1900-0000-65a0-35bb65140000 pid=5222->1cc2f53a-48d9-56e5-b7b8-c5e2ef72e5a8 send: 690B 24dfe4cf-f936-5f15-9f37-19347cbf3522 127.0.0.1:30566 guuid=feac79f8-1900-0000-65a0-35bb67140000 pid=5223->24dfe4cf-f936-5f15-9f37-19347cbf3522 send: 690B guuid=4c747cf8-1900-0000-65a0-35bb68140000 pid=5224->24dfe4cf-f936-5f15-9f37-19347cbf3522 con guuid=eb0c1709-1a00-0000-65a0-35bb6c140000 pid=5228->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7aaf6709-1a00-0000-65a0-35bb6d140000 pid=5229 /home/sandbox/data_x86_64 zombie guuid=eb0c1709-1a00-0000-65a0-35bb6c140000 pid=5228->guuid=7aaf6709-1a00-0000-65a0-35bb6d140000 pid=5229 clone guuid=2d747f0a-1a00-0000-65a0-35bb6e140000 pid=5230 /home/sandbox/data_x86_64 write-file zombie guuid=7aaf6709-1a00-0000-65a0-35bb6d140000 pid=5229->guuid=2d747f0a-1a00-0000-65a0-35bb6e140000 pid=5230 clone
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-18 07:29:24 UTC
File Type:
Text (Shell)
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 669d311967eb7abe0f2b1a8155f5f90d8042b657c97943d9b448da8a62595bc7

(this sample)

  
Delivery method
Distributed via web download

Comments