MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6e972dfd7408b7146a3c9a14357c8d08f4a18947100d93b87bd8ddfe30a635ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 6e972dfd7408b7146a3c9a14357c8d08f4a18947100d93b87bd8ddfe30a635ce
SHA3-384 hash: b516db9d3e224072ddba4559626e9f73ae6942bac981a3a2d17a1b4e4860f28eaa46853f2bf59303bf41a2f4fdc10a2a
SHA1 hash: 6056928038eefd057f09c67f32e21b119a6d62d2
MD5 hash: 6731eb9c45ba9ae3c22db23fcfcb31cb
humanhash: winner-berlin-pasta-victor
File name:bins.sh
Download: download sample
Signature Mirai
File size:1'948 bytes
First seen:2026-05-17 06:55:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZBcvrejr8rHrBIrvrxrfprRprU8rgrnrTKPprjKP8rj2v9rL2v4dtSHpy8lXE:Dc0cL+DhfJ/JIrI7YCHU8U
TLSH T1D741D6CB22E150B3C4A9DD41F35694D4D08C46E761EB6EBEFCA87836489900CF1B6B54
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.114/x866284fecc9516722ad6cf2e7b61e6e6f8c8db3c6b243dc11efd42b346497caa56 Miraimirai
http://176.65.139.114/i3866284fecc9516722ad6cf2e7b61e6e6f8c8db3c6b243dc11efd42b346497caa56 Miraimirai
http://176.65.139.114/amd644621fcacc022fe14da47b19bda1dbbab159fbc0c08460054d49b27030dfb1f7d Miraimirai
http://176.65.139.114/arme79d5ff3cebb9f7947d7a327627cef568b0008e853ad35d9bdc1b905aed6f94b Miraimirai
http://176.65.139.114/armv7le79d5ff3cebb9f7947d7a327627cef568b0008e853ad35d9bdc1b905aed6f94b Miraielf mirai ua-wget
http://176.65.139.114/arm552607d8ced931e757174c848c7825edcd003a1089eb3e225fe2bfbc102fa913a Miraimirai
http://176.65.139.114/arm6d9b6163b214089b5750aaea361ce2fb13adecded607e844379c9d1cd51be6dc3 Miraimirai
http://176.65.139.114/arm6412478c6bab64b04e8dbc9aef2fe82e2bb5e4f468fa44e5c1f2dd792b39c7f93a Miraimirai
http://176.65.139.114/android_arm64e7470dcfebed68d5c3c3eec26c5afecf8a35263965e198717ff68453116bd705 Miraimirai
http://176.65.139.114/mips03c55ab94e9101c946c90ab30e08175f84292c0c995aadb44601014b90c09561 Miraimirai
http://176.65.139.114/mipsled60c3f8a7e2376f5b35bc3ae3e524530aa3ed4f4d142bc875f2ede218abb4fab Miraimirai
http://176.65.139.114/bot.exen/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-17T04:02:00Z UTC
Last seen:
2026-05-17T05:16:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=00f87510-1c00-0000-0df5-2e68290c0000 pid=3113 /usr/bin/sudo guuid=26e72f12-1c00-0000-0df5-2e68300c0000 pid=3120 /tmp/sample.bin guuid=00f87510-1c00-0000-0df5-2e68290c0000 pid=3113->guuid=26e72f12-1c00-0000-0df5-2e68300c0000 pid=3120 execve guuid=2ec87412-1c00-0000-0df5-2e68320c0000 pid=3122 /usr/bin/wget net send-data write-file guuid=26e72f12-1c00-0000-0df5-2e68300c0000 pid=3120->guuid=2ec87412-1c00-0000-0df5-2e68320c0000 pid=3122 execve guuid=6a8e8b31-1c00-0000-0df5-2e68660c0000 pid=3174 /usr/bin/chmod guuid=26e72f12-1c00-0000-0df5-2e68300c0000 pid=3120->guuid=6a8e8b31-1c00-0000-0df5-2e68660c0000 pid=3174 execve guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175 /tmp/x86 delete-file net send-data write-config write-file guuid=26e72f12-1c00-0000-0df5-2e68300c0000 pid=3120->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175 execve f40cad64-7a4e-50d7-8367-776eda873ca9 176.65.139.114:80 guuid=2ec87412-1c00-0000-0df5-2e68320c0000 pid=3122->f40cad64-7a4e-50d7-8367-776eda873ca9 send: 132B 7e111765-6aa3-5a33-abcf-4c4ca8a0089a 176.65.139.114:9111 guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 36B 4fdfc865-815d-593f-8489-3466d510c38a 216.198.255.125:30000 guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->4fdfc865-815d-593f-8489-3466d510c38a con 0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 103.231.201.202:443 guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5734400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3176 /tmp/x86 guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3176 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3179 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3179 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3199 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3199 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3676 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3676 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5237 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5237 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5238 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5238 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5239 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5239 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5240 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5240 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5241 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5241 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5243 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5243 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5244 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5244 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5246 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5246 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5247 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5247 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5248 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5248 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5249 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5249 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5250 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5250 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5251 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5251 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5252 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5252 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5253 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5253 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5254 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5254 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5255 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5255 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5256 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5256 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5260 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5260 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5266 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5266 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5267 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5267 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5280 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5280 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5281 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5281 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5282 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5282 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5283 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5283 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5284 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5284 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5285 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5285 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5286 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5286 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5287 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5287 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5288 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5288 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5289 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5289 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5290 /tmp/x86 net send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5290 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5291 /tmp/x86 send-data guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3175->guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5291 clone guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 72B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177->4fdfc865-815d-593f-8489-3466d510c38a con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5733000B 783dddc9-4d78-5edd-87d8-d94904c2c690 34.18.29.29:9030 guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3177->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 36B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178->4fdfc865-815d-593f-8489-3466d510c38a con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5734400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3178->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3179->4fdfc865-815d-593f-8489-3466d510c38a con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3179->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5735800B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3199->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 37B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3199->4fdfc865-815d-593f-8489-3466d510c38a con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3199->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5734400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3676->4fdfc865-815d-593f-8489-3466d510c38a con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3676->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 5735800B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=3676->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5237->4fdfc865-815d-593f-8489-3466d510c38a send: 5882112B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5237->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 141400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5237->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5238->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 37B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5238->4fdfc865-815d-593f-8489-3466d510c38a send: 5174080B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5238->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 39415B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5239->4fdfc865-815d-593f-8489-3466d510c38a send: 6027840B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5239->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 2800B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5239->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5240->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 37B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5240->4fdfc865-815d-593f-8489-3466d510c38a send: 2701120B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5240->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 120213B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5241->4fdfc865-815d-593f-8489-3466d510c38a send: 5530304B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5241->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 74200B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 36B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242->4fdfc865-815d-593f-8489-3466d510c38a send: 5386048B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 29400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5242->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 27694B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5243->4fdfc865-815d-593f-8489-3466d510c38a send: 5756992B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5243->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 13073B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5244->4fdfc865-815d-593f-8489-3466d510c38a send: 6030784B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245->7e111765-6aa3-5a33-abcf-4c4ca8a0089a send: 37B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245->4fdfc865-815d-593f-8489-3466d510c38a send: 5756992B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 259000B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5245->783dddc9-4d78-5edd-87d8-d94904c2c690 con guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5246->4fdfc865-815d-593f-8489-3466d510c38a send: 4333568B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5247->4fdfc865-815d-593f-8489-3466d510c38a send: 4521984B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5247->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 21000B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5247->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 71477B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5248->4fdfc865-815d-593f-8489-3466d510c38a send: 4622080B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5248->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 68600B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5248->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 61701B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5249->4fdfc865-815d-593f-8489-3466d510c38a send: 5746688B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5249->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 13375B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5250->4fdfc865-815d-593f-8489-3466d510c38a send: 5355136B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5250->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 25200B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5250->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 30228B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5251->4fdfc865-815d-593f-8489-3466d510c38a send: 3276672B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5251->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 40600B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5252->4fdfc865-815d-593f-8489-3466d510c38a send: 5159360B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5252->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 42861B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5253->4fdfc865-815d-593f-8489-3466d510c38a send: 4208448B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5253->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 11360B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5254->4fdfc865-815d-593f-8489-3466d510c38a send: 4807552B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5254->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 72800B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5254->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 55818B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5255->4fdfc865-815d-593f-8489-3466d510c38a send: 5936576B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5255->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 3971B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5256->4fdfc865-815d-593f-8489-3466d510c38a send: 4320320B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5256->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 9368B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5260->4fdfc865-815d-593f-8489-3466d510c38a send: 4492544B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5260->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 15343B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5266->4fdfc865-815d-593f-8489-3466d510c38a send: 3362048B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5267->4fdfc865-815d-593f-8489-3466d510c38a send: 3794816B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5267->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 10998B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5280->4fdfc865-815d-593f-8489-3466d510c38a send: 647680B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5281->4fdfc865-815d-593f-8489-3466d510c38a send: 4410112B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5281->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 47935B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5282->4fdfc865-815d-593f-8489-3466d510c38a send: 3183936B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5282->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 14231B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5283->4fdfc865-815d-593f-8489-3466d510c38a send: 2037248B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5283->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 10682B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5284->4fdfc865-815d-593f-8489-3466d510c38a send: 638848B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5285->4fdfc865-815d-593f-8489-3466d510c38a send: 3734464B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5285->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 6791B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5286->4fdfc865-815d-593f-8489-3466d510c38a send: 2833600B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5286->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 130200B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5287->4fdfc865-815d-593f-8489-3466d510c38a send: 1469056B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5287->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 100957B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5288->4fdfc865-815d-593f-8489-3466d510c38a send: 535808B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5288->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 50400B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5289->4fdfc865-815d-593f-8489-3466d510c38a send: 1959232B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5289->0e0f0cbf-4a68-5cb1-8645-6c3e02c3db51 send: 109200B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5289->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 23334B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5290->4fdfc865-815d-593f-8489-3466d510c38a send: 761024B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5290->783dddc9-4d78-5edd-87d8-d94904c2c690 send: 51377B guuid=cf6ae931-1c00-0000-0df5-2e68670c0000 pid=5291->4fdfc865-815d-593f-8489-3466d510c38a send: 2409664B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-17 06:57:22 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Modifies Bash startup script
Creates/modifies environment variables
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6e972dfd7408b7146a3c9a14357c8d08f4a18947100d93b87bd8ddfe30a635ce

(this sample)

  
Delivery method
Distributed via web download

Comments