MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b47a10b306b5ff2fdb805c2e1f79391cdc168d3519ac45eb47f20185f7b43c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 6b47a10b306b5ff2fdb805c2e1f79391cdc168d3519ac45eb47f20185f7b43c8
SHA3-384 hash: 7402002d46789ffd85a51b0201b992ff9b007570e02da0115b407a6a38f1c344ead3c2a6a9c61266d04c4c22681d0ab2
SHA1 hash: 480223dce6adcb29b2532810ab85061b4f751b07
MD5 hash: 63ab22a642310deff918bbdb1f03f818
humanhash: kentucky-music-undress-helium
File name:cat.sh
Download: download sample
Signature Mirai
File size:1'954 bytes
First seen:2025-09-19 05:57:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:3fGdt/Ey6NaKp6PODORsbzfQ+o1m1FdLB8DFsF/tc43i77ZnyQNT0T7LBDCpwHdR:3fKJEyoFpD9/oQ2yZtc4IZny32sd8+
TLSH T1C74119C935A1CF52828B8E14FB7387EA984B5D85E39F4F70980B6C2AF94F9407035619
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.77.241.144/x86_64n/an/aelf ua-wget
http://103.77.241.144/aarch646fa043849b7eaf72769786c99d693c11ee82b885250fad3f7dd4ade24866267a Miraielf mirai ua-wget
http://103.77.241.144/m68kn/an/aelf ua-wget
http://103.77.241.144/mipsn/an/aelf ua-wget
http://103.77.241.144/mipseln/an/aelf ua-wget
http://103.77.241.144/powerpcn/an/aelf ua-wget
http://103.77.241.144/sparcn/an/aelf ua-wget
http://103.77.241.144/sh4n/an/aelf ua-wget
http://103.77.241.144/arc5048384c6a681d9b5df1dfce60ef133a9c0c6a3331db8389a56dcd1a51fb9b08 Miraielf mirai ua-wget
http://103.77.241.144/cskyn/an/aelf ua-wget
http://103.77.241.144/i486fed5e3d463fd7910f72e2ceb6e8168e6d69f03506e8a605a1af53d6c2c0a8c8c Miraielf mirai ua-wget
http://103.77.241.144/armv4ln/an/aelf ua-wget
http://103.77.241.144/armv5ln/an/aelf ua-wget
http://103.77.241.144/armv6ln/an/aelf ua-wget
http://103.77.241.144/armv7lfb0253b7a03d2e92011dabf070cc491c1e5f8573a0402486f1daf4a705d1a9d9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-18T15:18:00Z UTC
Last seen:
2025-09-18T15:18:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=1d14a004-1900-0000-3ddf-28bef0100000 pid=4336 /usr/bin/sudo guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350 /tmp/sample.bin guuid=1d14a004-1900-0000-3ddf-28bef0100000 pid=4336->guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350 execve guuid=cdff3207-1900-0000-3ddf-28be01110000 pid=4353 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=cdff3207-1900-0000-3ddf-28be01110000 pid=4353 execve guuid=27a25724-1900-0000-3ddf-28be60110000 pid=4448 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=27a25724-1900-0000-3ddf-28be60110000 pid=4448 execve guuid=b7e85745-1900-0000-3ddf-28bec0110000 pid=4544 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=b7e85745-1900-0000-3ddf-28bec0110000 pid=4544 execve guuid=79e2ee45-1900-0000-3ddf-28bec2110000 pid=4546 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=79e2ee45-1900-0000-3ddf-28bec2110000 pid=4546 clone guuid=ab983946-1900-0000-3ddf-28bec4110000 pid=4548 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=ab983946-1900-0000-3ddf-28bec4110000 pid=4548 execve guuid=da11ba46-1900-0000-3ddf-28bec8110000 pid=4552 /usr/bin/wget net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=da11ba46-1900-0000-3ddf-28bec8110000 pid=4552 execve guuid=01a624ad-1900-0000-3ddf-28be2f120000 pid=4655 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=01a624ad-1900-0000-3ddf-28be2f120000 pid=4655 execve guuid=bb2a83ad-1900-0000-3ddf-28be31120000 pid=4657 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=bb2a83ad-1900-0000-3ddf-28be31120000 pid=4657 clone guuid=2a8215af-1900-0000-3ddf-28be3c120000 pid=4668 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=2a8215af-1900-0000-3ddf-28be3c120000 pid=4668 execve guuid=f02d57af-1900-0000-3ddf-28be3d120000 pid=4669 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=f02d57af-1900-0000-3ddf-28be3d120000 pid=4669 execve guuid=b6f316cc-1900-0000-3ddf-28be9c120000 pid=4764 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=b6f316cc-1900-0000-3ddf-28be9c120000 pid=4764 execve guuid=3c8064ea-1900-0000-3ddf-28bee4120000 pid=4836 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=3c8064ea-1900-0000-3ddf-28bee4120000 pid=4836 execve guuid=ece5e6ea-1900-0000-3ddf-28bee6120000 pid=4838 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=ece5e6ea-1900-0000-3ddf-28bee6120000 pid=4838 clone guuid=a6112deb-1900-0000-3ddf-28bee7120000 pid=4839 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=a6112deb-1900-0000-3ddf-28bee7120000 pid=4839 execve guuid=044cbeeb-1900-0000-3ddf-28beea120000 pid=4842 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=044cbeeb-1900-0000-3ddf-28beea120000 pid=4842 execve guuid=1dcf910a-1a00-0000-3ddf-28be2d130000 pid=4909 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=1dcf910a-1a00-0000-3ddf-28be2d130000 pid=4909 execve guuid=decee127-1a00-0000-3ddf-28be6d130000 pid=4973 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=decee127-1a00-0000-3ddf-28be6d130000 pid=4973 execve guuid=60a06528-1a00-0000-3ddf-28be70130000 pid=4976 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=60a06528-1a00-0000-3ddf-28be70130000 pid=4976 clone guuid=03d1a628-1a00-0000-3ddf-28be71130000 pid=4977 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=03d1a628-1a00-0000-3ddf-28be71130000 pid=4977 execve guuid=b22a6429-1a00-0000-3ddf-28be74130000 pid=4980 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=b22a6429-1a00-0000-3ddf-28be74130000 pid=4980 execve guuid=e2d23147-1a00-0000-3ddf-28beb2130000 pid=5042 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=e2d23147-1a00-0000-3ddf-28beb2130000 pid=5042 execve guuid=cd90df64-1a00-0000-3ddf-28be17140000 pid=5143 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=cd90df64-1a00-0000-3ddf-28be17140000 pid=5143 execve guuid=35402165-1a00-0000-3ddf-28be18140000 pid=5144 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=35402165-1a00-0000-3ddf-28be18140000 pid=5144 clone guuid=9c654a65-1a00-0000-3ddf-28be1a140000 pid=5146 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=9c654a65-1a00-0000-3ddf-28be1a140000 pid=5146 execve guuid=ee069765-1a00-0000-3ddf-28be1b140000 pid=5147 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=ee069765-1a00-0000-3ddf-28be1b140000 pid=5147 execve guuid=efeee481-1a00-0000-3ddf-28be6e140000 pid=5230 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=efeee481-1a00-0000-3ddf-28be6e140000 pid=5230 execve guuid=da66989e-1a00-0000-3ddf-28be7a140000 pid=5242 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=da66989e-1a00-0000-3ddf-28be7a140000 pid=5242 execve guuid=9a29d39e-1a00-0000-3ddf-28be7b140000 pid=5243 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=9a29d39e-1a00-0000-3ddf-28be7b140000 pid=5243 clone guuid=f36dee9e-1a00-0000-3ddf-28be7c140000 pid=5244 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=f36dee9e-1a00-0000-3ddf-28be7c140000 pid=5244 execve guuid=2ce52a9f-1a00-0000-3ddf-28be7d140000 pid=5245 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=2ce52a9f-1a00-0000-3ddf-28be7d140000 pid=5245 execve guuid=2a98cdbc-1a00-0000-3ddf-28be7e140000 pid=5246 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=2a98cdbc-1a00-0000-3ddf-28be7e140000 pid=5246 execve guuid=dc3599d9-1a00-0000-3ddf-28be7f140000 pid=5247 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=dc3599d9-1a00-0000-3ddf-28be7f140000 pid=5247 execve guuid=0fb0e3d9-1a00-0000-3ddf-28be80140000 pid=5248 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=0fb0e3d9-1a00-0000-3ddf-28be80140000 pid=5248 clone guuid=ade10bda-1a00-0000-3ddf-28be81140000 pid=5249 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=ade10bda-1a00-0000-3ddf-28be81140000 pid=5249 execve guuid=585852da-1a00-0000-3ddf-28be82140000 pid=5250 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=585852da-1a00-0000-3ddf-28be82140000 pid=5250 execve guuid=8c5b3ef7-1a00-0000-3ddf-28be83140000 pid=5251 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=8c5b3ef7-1a00-0000-3ddf-28be83140000 pid=5251 execve guuid=f69f2815-1b00-0000-3ddf-28be84140000 pid=5252 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=f69f2815-1b00-0000-3ddf-28be84140000 pid=5252 execve guuid=5a957215-1b00-0000-3ddf-28be85140000 pid=5253 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=5a957215-1b00-0000-3ddf-28be85140000 pid=5253 clone guuid=54d69615-1b00-0000-3ddf-28be86140000 pid=5254 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=54d69615-1b00-0000-3ddf-28be86140000 pid=5254 execve guuid=839be115-1b00-0000-3ddf-28be87140000 pid=5255 /usr/bin/wget net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=839be115-1b00-0000-3ddf-28be87140000 pid=5255 execve guuid=d3878461-1b00-0000-3ddf-28be8b140000 pid=5259 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=d3878461-1b00-0000-3ddf-28be8b140000 pid=5259 execve guuid=797ad861-1b00-0000-3ddf-28be8c140000 pid=5260 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=797ad861-1b00-0000-3ddf-28be8c140000 pid=5260 clone guuid=ac1f8b62-1b00-0000-3ddf-28be92140000 pid=5266 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=ac1f8b62-1b00-0000-3ddf-28be92140000 pid=5266 execve guuid=8c8be462-1b00-0000-3ddf-28be93140000 pid=5267 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=8c8be462-1b00-0000-3ddf-28be93140000 pid=5267 execve guuid=0c66ee7d-1b00-0000-3ddf-28be94140000 pid=5268 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=0c66ee7d-1b00-0000-3ddf-28be94140000 pid=5268 execve guuid=f0ca279b-1b00-0000-3ddf-28be95140000 pid=5269 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=f0ca279b-1b00-0000-3ddf-28be95140000 pid=5269 execve guuid=eab5829b-1b00-0000-3ddf-28be96140000 pid=5270 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=eab5829b-1b00-0000-3ddf-28be96140000 pid=5270 clone guuid=a8aeb09b-1b00-0000-3ddf-28be97140000 pid=5271 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=a8aeb09b-1b00-0000-3ddf-28be97140000 pid=5271 execve guuid=6350109c-1b00-0000-3ddf-28be98140000 pid=5272 /usr/bin/wget net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=6350109c-1b00-0000-3ddf-28be98140000 pid=5272 execve guuid=74cc24f0-1b00-0000-3ddf-28be99140000 pid=5273 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=74cc24f0-1b00-0000-3ddf-28be99140000 pid=5273 execve guuid=7a0fd0f0-1b00-0000-3ddf-28be9a140000 pid=5274 /usr/bin/dbus-daemon write-config guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=7a0fd0f0-1b00-0000-3ddf-28be9a140000 pid=5274 execve guuid=b31fc0f7-1b00-0000-3ddf-28be9d140000 pid=5277 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=b31fc0f7-1b00-0000-3ddf-28be9d140000 pid=5277 execve guuid=55fe2cf8-1b00-0000-3ddf-28be9e140000 pid=5278 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=55fe2cf8-1b00-0000-3ddf-28be9e140000 pid=5278 execve guuid=77fcb814-1c00-0000-3ddf-28be9f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=77fcb814-1c00-0000-3ddf-28be9f140000 pid=5279 execve guuid=5589e332-1c00-0000-3ddf-28bea0140000 pid=5280 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=5589e332-1c00-0000-3ddf-28bea0140000 pid=5280 execve guuid=b5b65d33-1c00-0000-3ddf-28bea1140000 pid=5281 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=b5b65d33-1c00-0000-3ddf-28bea1140000 pid=5281 clone guuid=0362b933-1c00-0000-3ddf-28bea2140000 pid=5282 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=0362b933-1c00-0000-3ddf-28bea2140000 pid=5282 execve guuid=c4904b34-1c00-0000-3ddf-28bea3140000 pid=5283 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=c4904b34-1c00-0000-3ddf-28bea3140000 pid=5283 execve guuid=54cd9051-1c00-0000-3ddf-28beaa140000 pid=5290 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=54cd9051-1c00-0000-3ddf-28beaa140000 pid=5290 execve guuid=6303fa6e-1c00-0000-3ddf-28beb2140000 pid=5298 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=6303fa6e-1c00-0000-3ddf-28beb2140000 pid=5298 execve guuid=dd50926f-1c00-0000-3ddf-28beb3140000 pid=5299 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=dd50926f-1c00-0000-3ddf-28beb3140000 pid=5299 clone guuid=e3a4e66f-1c00-0000-3ddf-28beb4140000 pid=5300 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=e3a4e66f-1c00-0000-3ddf-28beb4140000 pid=5300 execve guuid=a10d8c70-1c00-0000-3ddf-28beb5140000 pid=5301 /usr/bin/wget net send-data guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=a10d8c70-1c00-0000-3ddf-28beb5140000 pid=5301 execve guuid=894d608c-1c00-0000-3ddf-28beb9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=894d608c-1c00-0000-3ddf-28beb9140000 pid=5305 execve guuid=623d26ab-1c00-0000-3ddf-28beca140000 pid=5322 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=623d26ab-1c00-0000-3ddf-28beca140000 pid=5322 execve guuid=1b3ab1ab-1c00-0000-3ddf-28becb140000 pid=5323 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=1b3ab1ab-1c00-0000-3ddf-28becb140000 pid=5323 clone guuid=d5bbfeab-1c00-0000-3ddf-28becc140000 pid=5324 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=d5bbfeab-1c00-0000-3ddf-28becc140000 pid=5324 execve guuid=71298dac-1c00-0000-3ddf-28becd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=71298dac-1c00-0000-3ddf-28becd140000 pid=5325 execve guuid=96a46bf3-1c00-0000-3ddf-28bece140000 pid=5326 /usr/bin/chmod guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=96a46bf3-1c00-0000-3ddf-28bece140000 pid=5326 execve guuid=06e205f4-1c00-0000-3ddf-28becf140000 pid=5327 /usr/bin/bash guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=06e205f4-1c00-0000-3ddf-28becf140000 pid=5327 clone guuid=0f0036f5-1c00-0000-3ddf-28bed1140000 pid=5329 /usr/bin/rm delete-file guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=0f0036f5-1c00-0000-3ddf-28bed1140000 pid=5329 execve guuid=dc71c2f5-1c00-0000-3ddf-28bed2140000 pid=5330 /usr/bin/bash zombie guuid=c271c606-1900-0000-3ddf-28befe100000 pid=4350->guuid=dc71c2f5-1c00-0000-3ddf-28bed2140000 pid=5330 clone 8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 103.77.241.144:80 guuid=cdff3207-1900-0000-3ddf-28be01110000 pid=4353->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B guuid=27a25724-1900-0000-3ddf-28be60110000 pid=4448->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 84B guuid=da11ba46-1900-0000-3ddf-28bec8110000 pid=4552->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 136B guuid=f02d57af-1900-0000-3ddf-28be3d120000 pid=4669->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 133B guuid=b6f316cc-1900-0000-3ddf-28be9c120000 pid=4764->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 82B guuid=044cbeeb-1900-0000-3ddf-28beea120000 pid=4842->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 133B guuid=1dcf910a-1a00-0000-3ddf-28be2d130000 pid=4909->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 82B guuid=b22a6429-1a00-0000-3ddf-28be74130000 pid=4980->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B guuid=e2d23147-1a00-0000-3ddf-28beb2130000 pid=5042->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 84B guuid=ee069765-1a00-0000-3ddf-28be1b140000 pid=5147->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 136B guuid=efeee481-1a00-0000-3ddf-28be6e140000 pid=5230->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 85B guuid=2ce52a9f-1a00-0000-3ddf-28be7d140000 pid=5245->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 134B guuid=2a98cdbc-1a00-0000-3ddf-28be7e140000 pid=5246->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 83B guuid=585852da-1a00-0000-3ddf-28be82140000 pid=5250->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 132B guuid=8c5b3ef7-1a00-0000-3ddf-28be83140000 pid=5251->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 81B guuid=839be115-1b00-0000-3ddf-28be87140000 pid=5255->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 132B guuid=8c8be462-1b00-0000-3ddf-28be93140000 pid=5267->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 133B guuid=0c66ee7d-1b00-0000-3ddf-28be94140000 pid=5268->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 82B guuid=6350109c-1b00-0000-3ddf-28be98140000 pid=5272->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 133B guuid=d0f83bf1-1b00-0000-3ddf-28be9b140000 pid=5275 /usr/bin/dash guuid=7a0fd0f0-1b00-0000-3ddf-28be9a140000 pid=5274->guuid=d0f83bf1-1b00-0000-3ddf-28be9b140000 pid=5275 execve guuid=ea26f7f1-1b00-0000-3ddf-28be9c140000 pid=5276 /usr/bin/cp guuid=d0f83bf1-1b00-0000-3ddf-28be9b140000 pid=5275->guuid=ea26f7f1-1b00-0000-3ddf-28be9c140000 pid=5276 execve guuid=55fe2cf8-1b00-0000-3ddf-28be9e140000 pid=5278->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B guuid=77fcb814-1c00-0000-3ddf-28be9f140000 pid=5279->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 84B guuid=c4904b34-1c00-0000-3ddf-28bea3140000 pid=5283->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B guuid=54cd9051-1c00-0000-3ddf-28beaa140000 pid=5290->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 84B guuid=a10d8c70-1c00-0000-3ddf-28beb5140000 pid=5301->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B guuid=894d608c-1c00-0000-3ddf-28beb9140000 pid=5305->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 84B guuid=71298dac-1c00-0000-3ddf-28becd140000 pid=5325->8339bf61-d5d0-5d3e-bdae-2b1ca3dd64d3 send: 135B
Threat name:
Document-HTML.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-18 21:44:41 UTC
File Type:
Text (Shell)
AV detection:
18 of 38 (47.37%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Modifies init.d
Modifies rc script
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6b47a10b306b5ff2fdb805c2e1f79391cdc168d3519ac45eb47f20185f7b43c8

(this sample)

  
Delivery method
Distributed via web download

Comments