MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6956dbac3319b8acbb5bef935e05da5b2de2e429812a7a632b32ae6d745f5dc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6956dbac3319b8acbb5bef935e05da5b2de2e429812a7a632b32ae6d745f5dc9
SHA3-384 hash: 652fa38b124b87d95f7241a6e808be7ccd81df06ebbcdecb86650b120c927357b752c2f6250f8400f39fd7ab85667a37
SHA1 hash: 6130738cc6bdc76e1c2b5dc97911568669720f36
MD5 hash: cc8dafe0c108a5d2fd857a89e229cf76
humanhash: lamp-fish-pizza-ink
File name:run.sh
Download: download sample
Signature Mirai
File size:2'907 bytes
First seen:2025-11-04 00:50:38 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:OCT0a02JMcdGdbiBop9puZwIEfIEnE2EhEZYLvA9Abw5NzvzLGLJUfokv/a/hM3Y:gx2JMkSbiBEjuZvvcvyYObwbUhM3Y
TLSH T10B516D9E0200DB31D60CDE4FF7F2B134610FA182A7DEDA45B9900E6C0EC9D4CA685E61
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnaarch64xnxn82fc91467ae3118635d5baf0c4a1b8e2985f81aff6f14dc104ff437a159e0869 Miraiarm elf geofenced mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxni386xnxnf8ea21971d321e0acaebb05c9b4f1d83df638d72dee68acd9c031fe47c1e689b Miraielf geofenced mirai ua-wget USA x86
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnloongarch64xnxnd4d15b10f86194f4526390a76687063937d910dc744d770fbc4a646d7d8e49ea Miraielf geofenced mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnm68kxnxne75d1e9b8b075abfc60c3db669af4c073efd35d94f2aca3e528f3af6e3eea772 Miraielf geofenced m68k mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnmicroblazexnxnf7efc9025574ceacaba61d1cb5d62cc80f4396bd5e42766a9e0254d2f6aa8d3a Miraielf geofenced mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnmipsxnxn23e8188ff6a5422aa9a12a008406d166d10ceb6f5db08183acbd65a6898d3e7e Miraielf geofenced mips mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnor1kxnxn52af6dd63be1b558d11570db5111b06a4fe6707593167c3a91f69f5e6dc156fe Miraielf geofenced mirai ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnpowerpcxnxn9e5647981fd2d0a93efa242dfaf007bf4c983e2677db31e4f3ac2437db290bac Miraielf geofenced mirai PowerPC ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnriscv32xnxnf1db9998646df4dfc57937b2b5df86ed03d5b55001319741405fc2025308c520 Miraielf mirai ua-wget
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnriscv64xnxnc3417dee4858027801671539b5d663158f65f8e0f99d30715f0117d2857cdcc5 Miraielf geofenced mirai RISC-V ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnsh2xnxn349d2a4ef7d1928bb8c8c8db8aa1114e48af7a4595e195bda21e0e3803dc13f6 Miraielf geofenced mirai SuperH ua-wget USA
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnsh4xnxn573ed9dde72bdbf9fd366ba569e819c517c1c8795b8a24eefa415716dec13318 Miraielf mirai ua-wget
http://196.251.87.194/bins/xnxnxnxnxnxnxnxnx86_64xnxnc5a64433d8e8865032a3edd2db818c0e379073c65497e2742ba002f4c6a2315c Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-11-03T23:06:00Z UTC
Last seen:
2025-11-04T00:12:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0efe83dc-1700-0000-b480-5f4ac50c0000 pid=3269 /usr/bin/sudo guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279 /tmp/sample.bin guuid=0efe83dc-1700-0000-b480-5f4ac50c0000 pid=3269->guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279 execve guuid=be1539df-1700-0000-b480-5f4ad10c0000 pid=3281 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=be1539df-1700-0000-b480-5f4ad10c0000 pid=3281 execve guuid=f376e6e4-1700-0000-b480-5f4adb0c0000 pid=3291 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=f376e6e4-1700-0000-b480-5f4adb0c0000 pid=3291 execve guuid=87366cee-1700-0000-b480-5f4af20c0000 pid=3314 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=87366cee-1700-0000-b480-5f4af20c0000 pid=3314 execve guuid=171ab9ee-1700-0000-b480-5f4af30c0000 pid=3315 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=171ab9ee-1700-0000-b480-5f4af30c0000 pid=3315 clone guuid=c6c961ef-1700-0000-b480-5f4af70c0000 pid=3319 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c6c961ef-1700-0000-b480-5f4af70c0000 pid=3319 execve guuid=34daa8ef-1700-0000-b480-5f4af80c0000 pid=3320 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=34daa8ef-1700-0000-b480-5f4af80c0000 pid=3320 execve guuid=d438c5f3-1700-0000-b480-5f4af90c0000 pid=3321 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=d438c5f3-1700-0000-b480-5f4af90c0000 pid=3321 execve guuid=b075f7fb-1700-0000-b480-5f4a080d0000 pid=3336 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=b075f7fb-1700-0000-b480-5f4a080d0000 pid=3336 execve guuid=c9e832fc-1700-0000-b480-5f4a0a0d0000 pid=3338 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c9e832fc-1700-0000-b480-5f4a0a0d0000 pid=3338 execve guuid=9973fbfc-1700-0000-b480-5f4a0f0d0000 pid=3343 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=9973fbfc-1700-0000-b480-5f4a0f0d0000 pid=3343 execve guuid=e4df38fd-1700-0000-b480-5f4a110d0000 pid=3345 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=e4df38fd-1700-0000-b480-5f4a110d0000 pid=3345 execve guuid=8ff81803-1800-0000-b480-5f4a170d0000 pid=3351 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=8ff81803-1800-0000-b480-5f4a170d0000 pid=3351 execve guuid=9c2d850a-1800-0000-b480-5f4a2b0d0000 pid=3371 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=9c2d850a-1800-0000-b480-5f4a2b0d0000 pid=3371 execve guuid=70a6b50a-1800-0000-b480-5f4a2d0d0000 pid=3373 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=70a6b50a-1800-0000-b480-5f4a2d0d0000 pid=3373 clone guuid=9eb44c0b-1800-0000-b480-5f4a310d0000 pid=3377 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=9eb44c0b-1800-0000-b480-5f4a310d0000 pid=3377 execve guuid=a40e3d0d-1800-0000-b480-5f4a340d0000 pid=3380 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a40e3d0d-1800-0000-b480-5f4a340d0000 pid=3380 execve guuid=2a324512-1800-0000-b480-5f4a440d0000 pid=3396 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=2a324512-1800-0000-b480-5f4a440d0000 pid=3396 execve guuid=a41f1918-1800-0000-b480-5f4a560d0000 pid=3414 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a41f1918-1800-0000-b480-5f4a560d0000 pid=3414 execve guuid=abee5418-1800-0000-b480-5f4a580d0000 pid=3416 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=abee5418-1800-0000-b480-5f4a580d0000 pid=3416 clone guuid=22d1dd18-1800-0000-b480-5f4a5c0d0000 pid=3420 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=22d1dd18-1800-0000-b480-5f4a5c0d0000 pid=3420 execve guuid=6fc41a19-1800-0000-b480-5f4a5e0d0000 pid=3422 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=6fc41a19-1800-0000-b480-5f4a5e0d0000 pid=3422 execve guuid=97a7251f-1800-0000-b480-5f4a700d0000 pid=3440 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=97a7251f-1800-0000-b480-5f4a700d0000 pid=3440 execve guuid=8e758525-1800-0000-b480-5f4a860d0000 pid=3462 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=8e758525-1800-0000-b480-5f4a860d0000 pid=3462 execve guuid=8b0d0726-1800-0000-b480-5f4a880d0000 pid=3464 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=8b0d0726-1800-0000-b480-5f4a880d0000 pid=3464 clone guuid=9866af26-1800-0000-b480-5f4a8c0d0000 pid=3468 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=9866af26-1800-0000-b480-5f4a8c0d0000 pid=3468 execve guuid=bebfee26-1800-0000-b480-5f4a8e0d0000 pid=3470 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=bebfee26-1800-0000-b480-5f4a8e0d0000 pid=3470 execve guuid=675f402b-1800-0000-b480-5f4a9d0d0000 pid=3485 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=675f402b-1800-0000-b480-5f4a9d0d0000 pid=3485 execve guuid=c7ee4d30-1800-0000-b480-5f4ab10d0000 pid=3505 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c7ee4d30-1800-0000-b480-5f4ab10d0000 pid=3505 execve guuid=c8e08430-1800-0000-b480-5f4ab30d0000 pid=3507 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c8e08430-1800-0000-b480-5f4ab30d0000 pid=3507 clone guuid=bd6d0431-1800-0000-b480-5f4ab70d0000 pid=3511 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=bd6d0431-1800-0000-b480-5f4ab70d0000 pid=3511 execve guuid=2bc33a31-1800-0000-b480-5f4abc0d0000 pid=3516 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=2bc33a31-1800-0000-b480-5f4abc0d0000 pid=3516 execve guuid=a62fcf35-1800-0000-b480-5f4abd0d0000 pid=3517 /usr/bin/curl guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a62fcf35-1800-0000-b480-5f4abd0d0000 pid=3517 execve guuid=7ae4fd37-1800-0000-b480-5f4ac20d0000 pid=3522 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=7ae4fd37-1800-0000-b480-5f4ac20d0000 pid=3522 execve guuid=ef365e38-1800-0000-b480-5f4ac50d0000 pid=3525 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=ef365e38-1800-0000-b480-5f4ac50d0000 pid=3525 clone guuid=3d08d338-1800-0000-b480-5f4ac90d0000 pid=3529 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=3d08d338-1800-0000-b480-5f4ac90d0000 pid=3529 execve guuid=266a0539-1800-0000-b480-5f4acb0d0000 pid=3531 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=266a0539-1800-0000-b480-5f4acb0d0000 pid=3531 execve guuid=05d2df3c-1800-0000-b480-5f4ad40d0000 pid=3540 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=05d2df3c-1800-0000-b480-5f4ad40d0000 pid=3540 execve guuid=319d1042-1800-0000-b480-5f4ae40d0000 pid=3556 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=319d1042-1800-0000-b480-5f4ae40d0000 pid=3556 execve guuid=a6924542-1800-0000-b480-5f4ae60d0000 pid=3558 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a6924542-1800-0000-b480-5f4ae60d0000 pid=3558 clone guuid=a0a5ca42-1800-0000-b480-5f4aea0d0000 pid=3562 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a0a5ca42-1800-0000-b480-5f4aea0d0000 pid=3562 execve guuid=00de0743-1800-0000-b480-5f4aec0d0000 pid=3564 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=00de0743-1800-0000-b480-5f4aec0d0000 pid=3564 execve guuid=96379747-1800-0000-b480-5f4af90d0000 pid=3577 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=96379747-1800-0000-b480-5f4af90d0000 pid=3577 execve guuid=4401b44e-1800-0000-b480-5f4a120e0000 pid=3602 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=4401b44e-1800-0000-b480-5f4a120e0000 pid=3602 execve guuid=c621034f-1800-0000-b480-5f4a130e0000 pid=3603 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c621034f-1800-0000-b480-5f4a130e0000 pid=3603 clone guuid=ff8fa44f-1800-0000-b480-5f4a170e0000 pid=3607 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=ff8fa44f-1800-0000-b480-5f4a170e0000 pid=3607 execve guuid=d31fef4f-1800-0000-b480-5f4a190e0000 pid=3609 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=d31fef4f-1800-0000-b480-5f4a190e0000 pid=3609 execve guuid=27348054-1800-0000-b480-5f4a260e0000 pid=3622 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=27348054-1800-0000-b480-5f4a260e0000 pid=3622 execve guuid=15fad059-1800-0000-b480-5f4a360e0000 pid=3638 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=15fad059-1800-0000-b480-5f4a360e0000 pid=3638 execve guuid=a978145a-1800-0000-b480-5f4a380e0000 pid=3640 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=a978145a-1800-0000-b480-5f4a380e0000 pid=3640 clone guuid=c4dbe05a-1800-0000-b480-5f4a3d0e0000 pid=3645 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c4dbe05a-1800-0000-b480-5f4a3d0e0000 pid=3645 execve guuid=37fe665b-1800-0000-b480-5f4a3f0e0000 pid=3647 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=37fe665b-1800-0000-b480-5f4a3f0e0000 pid=3647 execve guuid=c510b460-1800-0000-b480-5f4a4e0e0000 pid=3662 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c510b460-1800-0000-b480-5f4a4e0e0000 pid=3662 execve guuid=67a83b66-1800-0000-b480-5f4a620e0000 pid=3682 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=67a83b66-1800-0000-b480-5f4a620e0000 pid=3682 execve guuid=7fc07366-1800-0000-b480-5f4a640e0000 pid=3684 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=7fc07366-1800-0000-b480-5f4a640e0000 pid=3684 clone guuid=f1bb0767-1800-0000-b480-5f4a680e0000 pid=3688 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=f1bb0767-1800-0000-b480-5f4a680e0000 pid=3688 execve guuid=ded54367-1800-0000-b480-5f4a6a0e0000 pid=3690 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=ded54367-1800-0000-b480-5f4a6a0e0000 pid=3690 execve guuid=c921e26b-1800-0000-b480-5f4a7a0e0000 pid=3706 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=c921e26b-1800-0000-b480-5f4a7a0e0000 pid=3706 execve guuid=e4e7e771-1800-0000-b480-5f4a870e0000 pid=3719 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=e4e7e771-1800-0000-b480-5f4a870e0000 pid=3719 execve guuid=21fc3772-1800-0000-b480-5f4a880e0000 pid=3720 /usr/bin/dash guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=21fc3772-1800-0000-b480-5f4a880e0000 pid=3720 clone guuid=7512c373-1800-0000-b480-5f4a8a0e0000 pid=3722 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=7512c373-1800-0000-b480-5f4a8a0e0000 pid=3722 execve guuid=17541774-1800-0000-b480-5f4a8b0e0000 pid=3723 /usr/bin/wget net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=17541774-1800-0000-b480-5f4a8b0e0000 pid=3723 execve guuid=9b389478-1800-0000-b480-5f4a920e0000 pid=3730 /usr/bin/curl net send-data write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=9b389478-1800-0000-b480-5f4a920e0000 pid=3730 execve guuid=076fc47d-1800-0000-b480-5f4a990e0000 pid=3737 /usr/bin/chmod guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=076fc47d-1800-0000-b480-5f4a990e0000 pid=3737 execve guuid=6ae8467e-1800-0000-b480-5f4a9a0e0000 pid=3738 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn write-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=6ae8467e-1800-0000-b480-5f4a9a0e0000 pid=3738 execve guuid=ea96507f-1800-0000-b480-5f4a9f0e0000 pid=3743 /usr/bin/rm delete-file guuid=2c29f5de-1700-0000-b480-5f4acf0c0000 pid=3279->guuid=ea96507f-1800-0000-b480-5f4a9f0e0000 pid=3743 execve 6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac 196.251.87.194:80 guuid=be1539df-1700-0000-b480-5f4ad10c0000 pid=3281->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 161B guuid=f376e6e4-1700-0000-b480-5f4adb0c0000 pid=3291->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 110B guuid=34daa8ef-1700-0000-b480-5f4af80c0000 pid=3320->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 158B guuid=d438c5f3-1700-0000-b480-5f4af90c0000 pid=3321->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 107B guuid=b6ecf6fc-1700-0000-b480-5f4a0e0d0000 pid=3342 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=c9e832fc-1700-0000-b480-5f4a0a0d0000 pid=3338->guuid=b6ecf6fc-1700-0000-b480-5f4a0e0d0000 pid=3342 clone guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3344 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn send-data zombie guuid=b6ecf6fc-1700-0000-b480-5f4a0e0d0000 pid=3342->guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3344 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3344->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 39B guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3346 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3344->guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3346 clone guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3347 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn zombie guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3344->guuid=d5d4fefc-1700-0000-b480-5f4a100d0000 pid=3347 clone guuid=e4df38fd-1700-0000-b480-5f4a110d0000 pid=3345->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 165B guuid=8ff81803-1800-0000-b480-5f4a170d0000 pid=3351->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 114B guuid=a40e3d0d-1800-0000-b480-5f4a340d0000 pid=3380->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 158B guuid=2a324512-1800-0000-b480-5f4a440d0000 pid=3396->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 107B guuid=6fc41a19-1800-0000-b480-5f4a5e0d0000 pid=3422->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 164B guuid=97a7251f-1800-0000-b480-5f4a700d0000 pid=3440->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 113B guuid=bebfee26-1800-0000-b480-5f4a8e0d0000 pid=3470->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 158B guuid=675f402b-1800-0000-b480-5f4a9d0d0000 pid=3485->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 107B guuid=2bc33a31-1800-0000-b480-5f4abc0d0000 pid=3516->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 158B guuid=266a0539-1800-0000-b480-5f4acb0d0000 pid=3531->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 161B guuid=05d2df3c-1800-0000-b480-5f4ad40d0000 pid=3540->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 110B guuid=00de0743-1800-0000-b480-5f4aec0d0000 pid=3564->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 161B guuid=96379747-1800-0000-b480-5f4af90d0000 pid=3577->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 110B guuid=d31fef4f-1800-0000-b480-5f4a190e0000 pid=3609->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 161B guuid=27348054-1800-0000-b480-5f4a260e0000 pid=3622->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 110B guuid=37fe665b-1800-0000-b480-5f4a3f0e0000 pid=3647->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 157B guuid=c510b460-1800-0000-b480-5f4a4e0e0000 pid=3662->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 106B guuid=ded54367-1800-0000-b480-5f4a6a0e0000 pid=3690->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 157B guuid=c921e26b-1800-0000-b480-5f4a7a0e0000 pid=3706->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 106B guuid=17541774-1800-0000-b480-5f4a8b0e0000 pid=3723->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 160B guuid=9b389478-1800-0000-b480-5f4a920e0000 pid=3730->6f2106cc-ce3e-50ab-bf1f-1a3fa7971eac send: 109B guuid=8785467f-1800-0000-b480-5f4a9e0e0000 pid=3742 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn zombie guuid=6ae8467e-1800-0000-b480-5f4a9a0e0000 pid=3738->guuid=8785467f-1800-0000-b480-5f4a9e0e0000 pid=3742 clone guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn delete-file net send-data zombie guuid=8785467f-1800-0000-b480-5f4a9e0e0000 pid=3742->guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744 clone guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 195B 856e96dc-c5b4-5a21-a13d-2303ab5a77ba 196.251.87.194:54128 guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744->856e96dc-c5b4-5a21-a13d-2303ab5a77ba send: 145B guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3745 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744->guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3745 clone guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3746 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn zombie guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3744->guuid=69b3527f-1800-0000-b480-5f4aa00e0000 pid=3746 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-11-04 00:53:39 UTC
File Type:
Text (Shell)
AV detection:
4 of 24 (16.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6956dbac3319b8acbb5bef935e05da5b2de2e429812a7a632b32ae6d745f5dc9

(this sample)

  
Delivery method
Distributed via web download

Comments