MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d8d4f606300d2a89e47705813ab1355357032215fe352ff48626f1b17966af9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 6d8d4f606300d2a89e47705813ab1355357032215fe352ff48626f1b17966af9
SHA3-384 hash: ff83fa272cf1ce29d56111950d2f917ce477e99d8b4df5c5abe14c9dde81e29a5e75a56f48db3037e5813ec1823759a3
SHA1 hash: f05edc50baba73912d52291a99228c1b77780d12
MD5 hash: 5ebbdc49637e8e54bddb334f1f0b774e
humanhash: summer-avocado-five-four
File name:tuxbot.sh
Download: download sample
Signature Mirai
File size:2'154 bytes
First seen:2026-01-13 17:32:05 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:IJeO3hUnZm8PfZEGtQYWQQjJaNP6lKMYwNIfXknlqK1XxlHV3oVUnHXcq3:KZGuvhtliXPq33
TLSH T148412BDD329208762E54ED9BF979C4A4B189DD8799C27E2CD5DC78ED40AED0C30406D7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://217.60.199.86/bins/x8654092bf9a09d18fdf8bc83b7ca915641cf21255a3c989aaa2e30dfa25293506f Miraimirai opendir
http://217.60.199.86/bins/mipsc2aff2660d8b5ea827f8a5bf9401affb2994d66239e8628fbd1e9e2a914094bc Miraimirai opendir
http://217.60.199.86/bins/x86_64274d5b2af811b6926f5db8ffec75ad24d13b346ec9f50932e05b1a25336aaa33 Miraimirai opendir
http://217.60.199.86/bins/mpsln/an/aua-wget
http://217.60.199.86/bins/armd034c7d719e318421a3b53628c01a391e5ed12e9aab094bd92d2f0bdaedac930 Miraimirai opendir
http://217.60.199.86/bins/arm5e2748be8a9347cab41dff679342c23bea8f5acfcb054647b74e75c96acaa3ce9 Miraimirai opendir
http://217.60.199.86/bins/arm6d365cdf89d8938f69d1fe85b257f95bc271d881446af9159d17de248857bb308 Miraimirai opendir
http://217.60.199.86/bins/arm76442d8181b8ccd02286b222cb6400d50a8df9e17af67ad605d7ac3a67849d2a4 Miraimirai opendir
http://217.60.199.86/bins/ppc6f81a648d0f60af32ae52c3a72c94372f20982cc8becf201ec8d36650a1b9cee Miraimirai opendir
http://217.60.199.86/bins/spcd1feceb6547770de7a5ec0f980dbdcf1de1a416c0af9e112c51df6efdb905199 Miraimirai opendir
http://217.60.199.86/bins/m68kb28a25ae14facd9f3268dffa9e3a8d3a91a8552fe0c09c4a6e65f9633d1f5d7d Miraimirai opendir
http://217.60.199.86/bins/sh46efca9a211962bc442bbb5597ea193a3454457079608f09f0e959fa569079f6e Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-13T14:43:00Z UTC
Last seen:
2026-01-13T23:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.cx
Status:
terminated
Behavior Graph:
%3 guuid=c03bff81-1800-0000-0628-e942b90c0000 pid=3257 /usr/bin/sudo guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263 /tmp/sample.bin guuid=c03bff81-1800-0000-0628-e942b90c0000 pid=3257->guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263 execve guuid=ba1db484-1800-0000-0628-e942c20c0000 pid=3266 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=ba1db484-1800-0000-0628-e942c20c0000 pid=3266 execve guuid=0256b589-1800-0000-0628-e942cc0c0000 pid=3276 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=0256b589-1800-0000-0628-e942cc0c0000 pid=3276 execve guuid=af97fd90-1800-0000-0628-e942df0c0000 pid=3295 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=af97fd90-1800-0000-0628-e942df0c0000 pid=3295 execve guuid=5b534791-1800-0000-0628-e942e10c0000 pid=3297 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=5b534791-1800-0000-0628-e942e10c0000 pid=3297 clone guuid=aa1fd691-1800-0000-0628-e942e50c0000 pid=3301 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=aa1fd691-1800-0000-0628-e942e50c0000 pid=3301 execve guuid=eb071e92-1800-0000-0628-e942e70c0000 pid=3303 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=eb071e92-1800-0000-0628-e942e70c0000 pid=3303 execve guuid=74320694-1800-0000-0628-e942ea0c0000 pid=3306 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=74320694-1800-0000-0628-e942ea0c0000 pid=3306 execve guuid=665b1a98-1800-0000-0628-e942f90c0000 pid=3321 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=665b1a98-1800-0000-0628-e942f90c0000 pid=3321 execve guuid=5f655698-1800-0000-0628-e942fb0c0000 pid=3323 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=5f655698-1800-0000-0628-e942fb0c0000 pid=3323 clone guuid=31e1d498-1800-0000-0628-e942ff0c0000 pid=3327 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=31e1d498-1800-0000-0628-e942ff0c0000 pid=3327 execve guuid=12e70f99-1800-0000-0628-e942010d0000 pid=3329 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=12e70f99-1800-0000-0628-e942010d0000 pid=3329 execve guuid=62e2ea9a-1800-0000-0628-e942030d0000 pid=3331 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=62e2ea9a-1800-0000-0628-e942030d0000 pid=3331 execve guuid=93ca889d-1800-0000-0628-e9420a0d0000 pid=3338 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=93ca889d-1800-0000-0628-e9420a0d0000 pid=3338 execve guuid=5bb6da9d-1800-0000-0628-e9420b0d0000 pid=3339 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=5bb6da9d-1800-0000-0628-e9420b0d0000 pid=3339 clone guuid=79d9119f-1800-0000-0628-e9420d0d0000 pid=3341 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=79d9119f-1800-0000-0628-e9420d0d0000 pid=3341 execve guuid=471b6b9f-1800-0000-0628-e9420e0d0000 pid=3342 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=471b6b9f-1800-0000-0628-e9420e0d0000 pid=3342 execve guuid=f56084a1-1800-0000-0628-e9420f0d0000 pid=3343 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=f56084a1-1800-0000-0628-e9420f0d0000 pid=3343 execve guuid=34d1b4a4-1800-0000-0628-e942100d0000 pid=3344 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=34d1b4a4-1800-0000-0628-e942100d0000 pid=3344 execve guuid=6ae90ba5-1800-0000-0628-e942110d0000 pid=3345 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=6ae90ba5-1800-0000-0628-e942110d0000 pid=3345 clone guuid=c28681a6-1800-0000-0628-e942140d0000 pid=3348 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=c28681a6-1800-0000-0628-e942140d0000 pid=3348 execve guuid=5ca7d5a6-1800-0000-0628-e942150d0000 pid=3349 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=5ca7d5a6-1800-0000-0628-e942150d0000 pid=3349 execve guuid=c10acaa8-1800-0000-0628-e9421d0d0000 pid=3357 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=c10acaa8-1800-0000-0628-e9421d0d0000 pid=3357 execve guuid=1fc70dad-1800-0000-0628-e942260d0000 pid=3366 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=1fc70dad-1800-0000-0628-e942260d0000 pid=3366 execve guuid=be1453ad-1800-0000-0628-e942290d0000 pid=3369 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=be1453ad-1800-0000-0628-e942290d0000 pid=3369 clone guuid=6bf225ae-1800-0000-0628-e9422c0d0000 pid=3372 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=6bf225ae-1800-0000-0628-e9422c0d0000 pid=3372 execve guuid=111965ae-1800-0000-0628-e9422d0d0000 pid=3373 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=111965ae-1800-0000-0628-e9422d0d0000 pid=3373 execve guuid=10f621b0-1800-0000-0628-e942340d0000 pid=3380 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=10f621b0-1800-0000-0628-e942340d0000 pid=3380 execve guuid=241530b4-1800-0000-0628-e942410d0000 pid=3393 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=241530b4-1800-0000-0628-e942410d0000 pid=3393 execve guuid=c2a670b4-1800-0000-0628-e942420d0000 pid=3394 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=c2a670b4-1800-0000-0628-e942420d0000 pid=3394 clone guuid=84eb35b5-1800-0000-0628-e942470d0000 pid=3399 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=84eb35b5-1800-0000-0628-e942470d0000 pid=3399 execve guuid=67749eb5-1800-0000-0628-e942490d0000 pid=3401 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=67749eb5-1800-0000-0628-e942490d0000 pid=3401 execve guuid=0dc9cfb7-1800-0000-0628-e9424f0d0000 pid=3407 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=0dc9cfb7-1800-0000-0628-e9424f0d0000 pid=3407 execve guuid=0d8cadba-1800-0000-0628-e9425a0d0000 pid=3418 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=0d8cadba-1800-0000-0628-e9425a0d0000 pid=3418 execve guuid=b0feecba-1800-0000-0628-e9425c0d0000 pid=3420 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=b0feecba-1800-0000-0628-e9425c0d0000 pid=3420 clone guuid=361867bb-1800-0000-0628-e942600d0000 pid=3424 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=361867bb-1800-0000-0628-e942600d0000 pid=3424 execve guuid=9ddda1bb-1800-0000-0628-e942620d0000 pid=3426 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=9ddda1bb-1800-0000-0628-e942620d0000 pid=3426 execve guuid=de4369bd-1800-0000-0628-e942660d0000 pid=3430 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=de4369bd-1800-0000-0628-e942660d0000 pid=3430 execve guuid=7e9045c0-1800-0000-0628-e942710d0000 pid=3441 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=7e9045c0-1800-0000-0628-e942710d0000 pid=3441 execve guuid=85f483c0-1800-0000-0628-e942730d0000 pid=3443 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=85f483c0-1800-0000-0628-e942730d0000 pid=3443 clone guuid=4f1602c1-1800-0000-0628-e942770d0000 pid=3447 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=4f1602c1-1800-0000-0628-e942770d0000 pid=3447 execve guuid=ef6a3ec1-1800-0000-0628-e942780d0000 pid=3448 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=ef6a3ec1-1800-0000-0628-e942780d0000 pid=3448 execve guuid=4880f6c2-1800-0000-0628-e942800d0000 pid=3456 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=4880f6c2-1800-0000-0628-e942800d0000 pid=3456 execve guuid=d1ffc7c5-1800-0000-0628-e9428a0d0000 pid=3466 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=d1ffc7c5-1800-0000-0628-e9428a0d0000 pid=3466 execve guuid=ec210dc6-1800-0000-0628-e9428c0d0000 pid=3468 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=ec210dc6-1800-0000-0628-e9428c0d0000 pid=3468 clone guuid=5c9daac6-1800-0000-0628-e942900d0000 pid=3472 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=5c9daac6-1800-0000-0628-e942900d0000 pid=3472 execve guuid=cdfdf3c6-1800-0000-0628-e942920d0000 pid=3474 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=cdfdf3c6-1800-0000-0628-e942920d0000 pid=3474 execve guuid=b0557ac9-1800-0000-0628-e9429b0d0000 pid=3483 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=b0557ac9-1800-0000-0628-e9429b0d0000 pid=3483 execve guuid=af46c5cd-1800-0000-0628-e942ab0d0000 pid=3499 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=af46c5cd-1800-0000-0628-e942ab0d0000 pid=3499 execve guuid=7f9919ce-1800-0000-0628-e942ad0d0000 pid=3501 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=7f9919ce-1800-0000-0628-e942ad0d0000 pid=3501 clone guuid=900cc0ce-1800-0000-0628-e942b20d0000 pid=3506 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=900cc0ce-1800-0000-0628-e942b20d0000 pid=3506 execve guuid=bc2128cf-1800-0000-0628-e942b40d0000 pid=3508 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=bc2128cf-1800-0000-0628-e942b40d0000 pid=3508 execve guuid=d6d554d1-1800-0000-0628-e942bd0d0000 pid=3517 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=d6d554d1-1800-0000-0628-e942bd0d0000 pid=3517 execve guuid=675ba4d4-1800-0000-0628-e942c90d0000 pid=3529 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=675ba4d4-1800-0000-0628-e942c90d0000 pid=3529 execve guuid=3fe6ebd4-1800-0000-0628-e942cc0d0000 pid=3532 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=3fe6ebd4-1800-0000-0628-e942cc0d0000 pid=3532 clone guuid=60acd9d5-1800-0000-0628-e942d10d0000 pid=3537 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=60acd9d5-1800-0000-0628-e942d10d0000 pid=3537 execve guuid=bdf11ad6-1800-0000-0628-e942d30d0000 pid=3539 /usr/bin/wget net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=bdf11ad6-1800-0000-0628-e942d30d0000 pid=3539 execve guuid=6bedf6d7-1800-0000-0628-e942da0d0000 pid=3546 /usr/bin/curl net guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=6bedf6d7-1800-0000-0628-e942da0d0000 pid=3546 execve guuid=758fd2da-1800-0000-0628-e942e30d0000 pid=3555 /usr/bin/chmod guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=758fd2da-1800-0000-0628-e942e30d0000 pid=3555 execve guuid=cd0819db-1800-0000-0628-e942e40d0000 pid=3556 /usr/bin/bash guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=cd0819db-1800-0000-0628-e942e40d0000 pid=3556 clone guuid=37b293db-1800-0000-0628-e942e60d0000 pid=3558 /usr/bin/rm delete-file guuid=5286d083-1800-0000-0628-e942bf0c0000 pid=3263->guuid=37b293db-1800-0000-0628-e942e60d0000 pid=3558 execve 83324ce6-a6b3-5f6e-96be-a02d63266f86 217.60.199.86:80 guuid=ba1db484-1800-0000-0628-e942c20c0000 pid=3266->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=0256b589-1800-0000-0628-e942cc0c0000 pid=3276->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=eb071e92-1800-0000-0628-e942e70c0000 pid=3303->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=74320694-1800-0000-0628-e942ea0c0000 pid=3306->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=12e70f99-1800-0000-0628-e942010d0000 pid=3329->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=62e2ea9a-1800-0000-0628-e942030d0000 pid=3331->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=471b6b9f-1800-0000-0628-e9420e0d0000 pid=3342->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=f56084a1-1800-0000-0628-e9420f0d0000 pid=3343->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=5ca7d5a6-1800-0000-0628-e942150d0000 pid=3349->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=c10acaa8-1800-0000-0628-e9421d0d0000 pid=3357->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=111965ae-1800-0000-0628-e9422d0d0000 pid=3373->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=10f621b0-1800-0000-0628-e942340d0000 pid=3380->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=67749eb5-1800-0000-0628-e942490d0000 pid=3401->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=0dc9cfb7-1800-0000-0628-e9424f0d0000 pid=3407->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=9ddda1bb-1800-0000-0628-e942620d0000 pid=3426->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=de4369bd-1800-0000-0628-e942660d0000 pid=3430->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=ef6a3ec1-1800-0000-0628-e942780d0000 pid=3448->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=4880f6c2-1800-0000-0628-e942800d0000 pid=3456->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=cdfdf3c6-1800-0000-0628-e942920d0000 pid=3474->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=b0557ac9-1800-0000-0628-e9429b0d0000 pid=3483->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=bc2128cf-1800-0000-0628-e942b40d0000 pid=3508->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=d6d554d1-1800-0000-0628-e942bd0d0000 pid=3517->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=bdf11ad6-1800-0000-0628-e942d30d0000 pid=3539->83324ce6-a6b3-5f6e-96be-a02d63266f86 con guuid=6bedf6d7-1800-0000-0628-e942da0d0000 pid=3546->83324ce6-a6b3-5f6e-96be-a02d63266f86 con
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2026-01-13 17:32:38 UTC
File Type:
Text (Shell)
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6d8d4f606300d2a89e47705813ab1355357032215fe352ff48626f1b17966af9

(this sample)

  
Delivery method
Distributed via web download

Comments