MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6887cfa51d87a3cc2393531076c5b7f2a0a2cd06d2fe9705c7b262e90fc26715. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6887cfa51d87a3cc2393531076c5b7f2a0a2cd06d2fe9705c7b262e90fc26715
SHA3-384 hash: 258e2324fd02217e8b5afbd7ab00480b233767c9b8d82b8b8ccb6c0dd18a4d94b18a91164ebd7c87d39566bbae98ffcc
SHA1 hash: 3a54be4ae839ecc9158062ffd3f539f575398705
MD5 hash: d26585bba5183aaf58a229796d82ea61
humanhash: kentucky-angel-lemon-failed
File name:w.sh
Download: download sample
File size:943 bytes
First seen:2026-03-19 08:46:07 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:GzFEIUfEE9KNI5rE+3cKrEj+kafaE+EDI/D7HFIsnIqNedIIeIJc/wWIl6I7XU:ENIGKrkAGEUb7SsIoEpc/ZGU
TLSH T1241181DD7169643DAC119F4174928D60A104F2D75DAB9F89AC8C4D71F48B7B4303AF89
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.175.223.124/data.arm44c9c451ee9fce127dae278eeac763dae233d09d227711c556f7a8941d5c37eb5 Miraielf mirai ua-wget
http://5.175.223.124/data.arm5b2a5a733664ac0b32a407a55760e8568d80c318354e1bad0d5d5719d8806d1ab Miraielf mirai ua-wget
http://5.175.223.124/data.arm665d7c59c8a21d2ed3a427fccfab4ba18227a6fd5d737257870a39dc69f12e03d Miraielf mirai ua-wget
http://5.175.223.124/data.arm76dfa1e31b246ddcc95bd98c8267e2742ec72eb42193b7bcf06a7326df74e2ae8 Miraielf mirai ua-wget
http://5.175.223.124/data.aarch64080bed1a4b9a6a34911ac0a043e5138cc6801a326062b9ebfa4e3cd4ef57ec05 Miraielf mirai ua-wget
http://5.175.223.124/data.mips76f0338622519a764eeea04c0ef8176aa3ffa35bae8d350bc7f358ff024f3d21 Gafgytelf gafgyt mips ua-wget
http://5.175.223.124/data.mipsel675645d67ee6eadfc44657fd4c10e660496b13375b69e086cd4d9d5038239fa7 Gafgytelf gafgyt mips ua-wget
http://5.175.223.124/data.mips-uclibcfdea4b7688114a4edf26deb83a1a24bdd5d3edb3755d28da514f2ff7a7423a66 DDoSAgentDDoSAgent elf ua-wget
http://5.175.223.124/data.mipsel-uclibc9435f5f34f606fe496c779c808b033d86c63b2a71a2b7d3c6617c43df9226762 Miraielf geofenced mips mirai ua-wget USA
http://5.175.223.124/data.powerpcc3b91aa16dbe60c55799392b2ab1d739692203672fb4f2f14ff1b3e2d0558bfe Miraielf mirai ua-wget
http://5.175.223.124/data.x865d84a43059e40879ce7dfa16f3c0d0607904aa1ab7434f0dfb5228289f55ddff DDoSAgentDDoSAgent elf ua-wget
http://5.175.223.124/data.x86_64f02a038797f449d63d32d2eae14ddab662c6f14e9e279ef1eaa01a400fdbefb0 DDoSAgentDDoSAgent elf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=603287fe-1600-0000-f19b-9ed2f70d0000 pid=3575 /usr/bin/sudo guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576 /tmp/sample.bin guuid=603287fe-1600-0000-f19b-9ed2f70d0000 pid=3575->guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576 execve guuid=aede5602-1700-0000-f19b-9ed2f90d0000 pid=3577 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=aede5602-1700-0000-f19b-9ed2f90d0000 pid=3577 execve guuid=909fe2b8-1700-0000-f19b-9ed265100000 pid=4197 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=909fe2b8-1700-0000-f19b-9ed265100000 pid=4197 execve guuid=fdf248b9-1700-0000-f19b-9ed269100000 pid=4201 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=fdf248b9-1700-0000-f19b-9ed269100000 pid=4201 clone guuid=250a11ba-1700-0000-f19b-9ed26e100000 pid=4206 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=250a11ba-1700-0000-f19b-9ed26e100000 pid=4206 execve guuid=0893acd8-1700-0000-f19b-9ed2f9100000 pid=4345 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=0893acd8-1700-0000-f19b-9ed2f9100000 pid=4345 execve guuid=d16ae7d8-1700-0000-f19b-9ed2fa100000 pid=4346 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=d16ae7d8-1700-0000-f19b-9ed2fa100000 pid=4346 clone guuid=e9b869d9-1700-0000-f19b-9ed2fe100000 pid=4350 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=e9b869d9-1700-0000-f19b-9ed2fe100000 pid=4350 execve guuid=d0725616-1800-0000-f19b-9ed295110000 pid=4501 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=d0725616-1800-0000-f19b-9ed295110000 pid=4501 execve guuid=6fe80417-1800-0000-f19b-9ed296110000 pid=4502 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=6fe80417-1800-0000-f19b-9ed296110000 pid=4502 clone guuid=bea04418-1800-0000-f19b-9ed298110000 pid=4504 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=bea04418-1800-0000-f19b-9ed298110000 pid=4504 execve guuid=c10fa443-1800-0000-f19b-9ed217120000 pid=4631 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=c10fa443-1800-0000-f19b-9ed217120000 pid=4631 execve guuid=88d7f243-1800-0000-f19b-9ed219120000 pid=4633 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=88d7f243-1800-0000-f19b-9ed219120000 pid=4633 clone guuid=a7069645-1800-0000-f19b-9ed21d120000 pid=4637 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=a7069645-1800-0000-f19b-9ed21d120000 pid=4637 execve guuid=1a28b27b-1a00-0000-f19b-9ed27e140000 pid=5246 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=1a28b27b-1a00-0000-f19b-9ed27e140000 pid=5246 execve guuid=487d507c-1a00-0000-f19b-9ed27f140000 pid=5247 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=487d507c-1a00-0000-f19b-9ed27f140000 pid=5247 clone guuid=fe28717e-1a00-0000-f19b-9ed281140000 pid=5249 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=fe28717e-1a00-0000-f19b-9ed281140000 pid=5249 execve guuid=9711fdfe-1a00-0000-f19b-9ed282140000 pid=5250 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=9711fdfe-1a00-0000-f19b-9ed282140000 pid=5250 execve guuid=af4952ff-1a00-0000-f19b-9ed283140000 pid=5251 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=af4952ff-1a00-0000-f19b-9ed283140000 pid=5251 clone guuid=c7098800-1b00-0000-f19b-9ed285140000 pid=5253 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=c7098800-1b00-0000-f19b-9ed285140000 pid=5253 execve guuid=ed426827-1b00-0000-f19b-9ed286140000 pid=5254 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=ed426827-1b00-0000-f19b-9ed286140000 pid=5254 execve guuid=f2c6b927-1b00-0000-f19b-9ed287140000 pid=5255 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=f2c6b927-1b00-0000-f19b-9ed287140000 pid=5255 clone guuid=dd21b228-1b00-0000-f19b-9ed289140000 pid=5257 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=dd21b228-1b00-0000-f19b-9ed289140000 pid=5257 execve guuid=612348c1-1b00-0000-f19b-9ed2aa140000 pid=5290 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=612348c1-1b00-0000-f19b-9ed2aa140000 pid=5290 execve guuid=96edd9c1-1b00-0000-f19b-9ed2ab140000 pid=5291 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=96edd9c1-1b00-0000-f19b-9ed2ab140000 pid=5291 clone guuid=eee6fac2-1b00-0000-f19b-9ed2ad140000 pid=5293 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=eee6fac2-1b00-0000-f19b-9ed2ad140000 pid=5293 execve guuid=f1efdf3e-1d00-0000-f19b-9ed2ae140000 pid=5294 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=f1efdf3e-1d00-0000-f19b-9ed2ae140000 pid=5294 execve guuid=106f713f-1d00-0000-f19b-9ed2af140000 pid=5295 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=106f713f-1d00-0000-f19b-9ed2af140000 pid=5295 clone guuid=90f1aa40-1d00-0000-f19b-9ed2b1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=90f1aa40-1d00-0000-f19b-9ed2b1140000 pid=5297 execve guuid=efbe2278-1d00-0000-f19b-9ed2b2140000 pid=5298 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=efbe2278-1d00-0000-f19b-9ed2b2140000 pid=5298 execve guuid=366bb378-1d00-0000-f19b-9ed2b3140000 pid=5299 /usr/bin/dash guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=366bb378-1d00-0000-f19b-9ed2b3140000 pid=5299 clone guuid=6710d279-1d00-0000-f19b-9ed2b5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=6710d279-1d00-0000-f19b-9ed2b5140000 pid=5301 execve guuid=546a8efd-2300-0000-f19b-9ed2b6140000 pid=5302 /usr/bin/chmod guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=546a8efd-2300-0000-f19b-9ed2b6140000 pid=5302 execve guuid=af5b13fe-2300-0000-f19b-9ed2b7140000 pid=5303 /home/sandbox/data.x86 net guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=af5b13fe-2300-0000-f19b-9ed2b7140000 pid=5303 execve guuid=27556ffe-2300-0000-f19b-9ed2b9140000 pid=5305 /usr/bin/wget net send-data write-file guuid=3e9afa01-1700-0000-f19b-9ed2f80d0000 pid=3576->guuid=27556ffe-2300-0000-f19b-9ed2b9140000 pid=5305 execve 5668ce23-1c09-5b92-b500-f59a8ec6b05f 5.175.223.124:80 guuid=aede5602-1700-0000-f19b-9ed2f90d0000 pid=3577->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 137B guuid=250a11ba-1700-0000-f19b-9ed26e100000 pid=4206->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 137B guuid=e9b869d9-1700-0000-f19b-9ed2fe100000 pid=4350->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 137B guuid=bea04418-1800-0000-f19b-9ed298110000 pid=4504->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 137B guuid=a7069645-1800-0000-f19b-9ed21d120000 pid=4637->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 140B guuid=fe28717e-1a00-0000-f19b-9ed281140000 pid=5249->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 137B guuid=c7098800-1b00-0000-f19b-9ed285140000 pid=5253->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 139B guuid=dd21b228-1b00-0000-f19b-9ed289140000 pid=5257->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 144B guuid=eee6fac2-1b00-0000-f19b-9ed2ad140000 pid=5293->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 146B guuid=90f1aa40-1d00-0000-f19b-9ed2b1140000 pid=5297->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 140B guuid=6710d279-1d00-0000-f19b-9ed2b5140000 pid=5301->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=af5b13fe-2300-0000-f19b-9ed2b7140000 pid=5303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=af3460fe-2300-0000-f19b-9ed2b8140000 pid=5304 /home/sandbox/data.x86 guuid=af5b13fe-2300-0000-f19b-9ed2b7140000 pid=5303->guuid=af3460fe-2300-0000-f19b-9ed2b8140000 pid=5304 clone guuid=488e7afe-2300-0000-f19b-9ed2ba140000 pid=5306 /home/sandbox/data.x86 write-file zombie guuid=af3460fe-2300-0000-f19b-9ed2b8140000 pid=5304->guuid=488e7afe-2300-0000-f19b-9ed2ba140000 pid=5306 clone guuid=27556ffe-2300-0000-f19b-9ed2b9140000 pid=5305->5668ce23-1c09-5b92-b500-f59a8ec6b05f send: 139B guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307 /home/sandbox/data.x86 net send-data zombie guuid=488e7afe-2300-0000-f19b-9ed2ba140000 pid=5306->guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307 clone guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 79330709-4ba7-5769-b683-21ef3c41191a 45.131.65.74:8082 guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->79330709-4ba7-5769-b683-21ef3c41191a send: 9B guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5308 /home/sandbox/data.x86 send-data zombie guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5308 clone guuid=ffbb4fff-2300-0000-f19b-9ed2bd140000 pid=5309 /home/sandbox/data.x86 net send-data write-file guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->guuid=ffbb4fff-2300-0000-f19b-9ed2bd140000 pid=5309 clone guuid=bfee1100-2400-0000-f19b-9ed2be140000 pid=5310 /usr/bin/dash guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->guuid=bfee1100-2400-0000-f19b-9ed2be140000 pid=5310 execve guuid=cee6fd07-2400-0000-f19b-9ed2c3140000 pid=5315 /usr/bin/dash guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5307->guuid=cee6fd07-2400-0000-f19b-9ed2c3140000 pid=5315 execve 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=561a35ff-2300-0000-f19b-9ed2bb140000 pid=5308->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 106B a15c7036-706e-5ee9-888f-734cbb9e72e7 127.0.0.1:30565 guuid=ffbb4fff-2300-0000-f19b-9ed2bd140000 pid=5309->a15c7036-706e-5ee9-888f-734cbb9e72e7 send: 106B guuid=d8c74e00-2400-0000-f19b-9ed2bf140000 pid=5311 /usr/sbin/xtables-nft-multi guuid=bfee1100-2400-0000-f19b-9ed2be140000 pid=5310->guuid=d8c74e00-2400-0000-f19b-9ed2bf140000 pid=5311 execve guuid=a3d72808-2400-0000-f19b-9ed2c4140000 pid=5316 /usr/sbin/xtables-nft-multi guuid=cee6fd07-2400-0000-f19b-9ed2c3140000 pid=5315->guuid=a3d72808-2400-0000-f19b-9ed2c4140000 pid=5316 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6887cfa51d87a3cc2393531076c5b7f2a0a2cd06d2fe9705c7b262e90fc26715

(this sample)

  
Delivery method
Distributed via web download

Comments