MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6ead92bad5d294a8703f854acb7a08eff3fbd8f1ec213c05b66a746449eb511e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 6ead92bad5d294a8703f854acb7a08eff3fbd8f1ec213c05b66a746449eb511e
SHA3-384 hash: 8942885c1d84452b2e13ef8c27de50f4a9850dd20053dc0ea670d00f0d8207642ed668345b214f7d01c71155cca81ebd
SHA1 hash: ec79e5f497c3e8ba74bbaea5d8fb5d8cb74996ae
MD5 hash: 4a941fbe43be6cfc1f0cc39a918e5239
humanhash: spaghetti-summer-stream-carolina
File name:l.sh
Download: download sample
File size:1'945 bytes
First seen:2026-02-20 07:54:03 UTC
Last seen:2026-02-21 04:35:35 UTC
File type: sh
MIME type:text/plain
ssdeep 24:fNVEcqBCdFpFABBzdEBOPqBdTZNH/qBOdkB7Lx18B4biXqTBEZp2ByULQWf423Bk:FACIsHdNd63748NdyihygC
TLSH T1384125C8A1A045F388C89A597D63423C71AD0EE1BED27FD8684DC89D6F437A7F548B84
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.214.30.5/bins/StormStresser.arm6edb0b5e6bc05322b0f389bb03734dcfff721dfad89af8ca5c5b87c1d935700bf Miraimirai
http://188.214.30.5/bins/StormStresser.arm756b5a310c383c4f5e609ab09f0c441b781a8628f45c879fd4f268113a347f5ac Miraimirai
http://188.214.30.5/bins/StormStresser.m68k5c8d71d5c6523e8092e097bbcc5ecbdc3081b02d7e3e902089beef0333f4b0a7 Miraimirai
http://188.214.30.5/bins/StormStresser.mipsb8990787c2e9d8f1fc852b645aca2704bb4f7dc1a9cf54896b3c3d9a6d23efb6 Miraimirai
http://188.214.30.5/bins/StormStresser.mpsl94492a228b98982f5a075e792239ba6b7c41366551df182ec6b07270770d744d Miraimirai
http://188.214.30.5/bins/StormStresser.ppc3248d8503d5742ecffadc4739878835719fbf76f91c4e8b6d4f3cc304655fe7e Miraimirai
http://188.214.30.5/bins/StormStresser.sh4c62c7c9567099175754f0ea1e0ba39ed0341a237600a838eaa1fa4f10f3ec805 Miraimirai
http://188.214.30.5/bins/StormStresser.spc917f055a7ea82558a1ce794eb798c471e9dc30ead4a867b92c0f863b7b320f29 Miraimirai
http://188.214.30.5/bins/StormStresser.x86c28e7804ea2a28fab3f53b5c740acaddece03c4427bfec92e0ab3e4997abf5cb Miraimirai
http://188.214.30.5/bins/x86_6462905f8a3507c4ad44848de30017efd4c89eb4f34a746eecc10600a91aafdf0a Miraimirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=2debc2df-1800-0000-4ec7-45fb1a070000 pid=1818 /usr/bin/sudo guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823 /tmp/sample.bin guuid=2debc2df-1800-0000-4ec7-45fb1a070000 pid=1818->guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823 execve guuid=699770e1-1800-0000-4ec7-45fb21070000 pid=1825 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=699770e1-1800-0000-4ec7-45fb21070000 pid=1825 execve guuid=92561eea-1800-0000-4ec7-45fb38070000 pid=1848 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=92561eea-1800-0000-4ec7-45fb38070000 pid=1848 execve guuid=73535cea-1800-0000-4ec7-45fb39070000 pid=1849 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=73535cea-1800-0000-4ec7-45fb39070000 pid=1849 clone guuid=646f15eb-1800-0000-4ec7-45fb3b070000 pid=1851 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=646f15eb-1800-0000-4ec7-45fb3b070000 pid=1851 execve guuid=abde57eb-1800-0000-4ec7-45fb3c070000 pid=1852 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=abde57eb-1800-0000-4ec7-45fb3c070000 pid=1852 execve guuid=65bad5f6-1800-0000-4ec7-45fb57070000 pid=1879 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=65bad5f6-1800-0000-4ec7-45fb57070000 pid=1879 execve guuid=15ce02f7-1800-0000-4ec7-45fb59070000 pid=1881 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=15ce02f7-1800-0000-4ec7-45fb59070000 pid=1881 clone guuid=7fc8d0f7-1800-0000-4ec7-45fb5c070000 pid=1884 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=7fc8d0f7-1800-0000-4ec7-45fb5c070000 pid=1884 execve guuid=595d00f8-1800-0000-4ec7-45fb5d070000 pid=1885 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=595d00f8-1800-0000-4ec7-45fb5d070000 pid=1885 execve guuid=5eb34501-1900-0000-4ec7-45fb73070000 pid=1907 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=5eb34501-1900-0000-4ec7-45fb73070000 pid=1907 execve guuid=12e58901-1900-0000-4ec7-45fb75070000 pid=1909 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=12e58901-1900-0000-4ec7-45fb75070000 pid=1909 clone guuid=4cc20e03-1900-0000-4ec7-45fb7a070000 pid=1914 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=4cc20e03-1900-0000-4ec7-45fb7a070000 pid=1914 execve guuid=23a23703-1900-0000-4ec7-45fb7b070000 pid=1915 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=23a23703-1900-0000-4ec7-45fb7b070000 pid=1915 execve guuid=62e5b30b-1900-0000-4ec7-45fb91070000 pid=1937 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=62e5b30b-1900-0000-4ec7-45fb91070000 pid=1937 execve guuid=0cd0ed0b-1900-0000-4ec7-45fb93070000 pid=1939 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=0cd0ed0b-1900-0000-4ec7-45fb93070000 pid=1939 clone guuid=c0dc320d-1900-0000-4ec7-45fb97070000 pid=1943 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=c0dc320d-1900-0000-4ec7-45fb97070000 pid=1943 execve guuid=c61c5d0d-1900-0000-4ec7-45fb99070000 pid=1945 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=c61c5d0d-1900-0000-4ec7-45fb99070000 pid=1945 execve guuid=c99d5116-1900-0000-4ec7-45fbaf070000 pid=1967 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=c99d5116-1900-0000-4ec7-45fbaf070000 pid=1967 execve guuid=23978b16-1900-0000-4ec7-45fbb1070000 pid=1969 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=23978b16-1900-0000-4ec7-45fbb1070000 pid=1969 clone guuid=3f4c6317-1900-0000-4ec7-45fbb4070000 pid=1972 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=3f4c6317-1900-0000-4ec7-45fbb4070000 pid=1972 execve guuid=ec2c9e17-1900-0000-4ec7-45fbb6070000 pid=1974 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=ec2c9e17-1900-0000-4ec7-45fbb6070000 pid=1974 execve guuid=f33a8f20-1900-0000-4ec7-45fbc2070000 pid=1986 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=f33a8f20-1900-0000-4ec7-45fbc2070000 pid=1986 execve guuid=95f4d520-1900-0000-4ec7-45fbc3070000 pid=1987 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=95f4d520-1900-0000-4ec7-45fbc3070000 pid=1987 clone guuid=b0028721-1900-0000-4ec7-45fbc5070000 pid=1989 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=b0028721-1900-0000-4ec7-45fbc5070000 pid=1989 execve guuid=fb70b921-1900-0000-4ec7-45fbc6070000 pid=1990 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=fb70b921-1900-0000-4ec7-45fbc6070000 pid=1990 execve guuid=b18f762a-1900-0000-4ec7-45fbd9070000 pid=2009 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=b18f762a-1900-0000-4ec7-45fbd9070000 pid=2009 execve guuid=17cbb12a-1900-0000-4ec7-45fbda070000 pid=2010 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=17cbb12a-1900-0000-4ec7-45fbda070000 pid=2010 clone guuid=7f82d92c-1900-0000-4ec7-45fbdc070000 pid=2012 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=7f82d92c-1900-0000-4ec7-45fbdc070000 pid=2012 execve guuid=44cf152d-1900-0000-4ec7-45fbdd070000 pid=2013 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=44cf152d-1900-0000-4ec7-45fbdd070000 pid=2013 execve guuid=1ceb8835-1900-0000-4ec7-45fbdf070000 pid=2015 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=1ceb8835-1900-0000-4ec7-45fbdf070000 pid=2015 execve guuid=3823cd35-1900-0000-4ec7-45fbe0070000 pid=2016 /usr/bin/dash guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=3823cd35-1900-0000-4ec7-45fbe0070000 pid=2016 clone guuid=5ce5cf37-1900-0000-4ec7-45fbe6070000 pid=2022 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=5ce5cf37-1900-0000-4ec7-45fbe6070000 pid=2022 execve guuid=95100c38-1900-0000-4ec7-45fbe8070000 pid=2024 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=95100c38-1900-0000-4ec7-45fbe8070000 pid=2024 execve guuid=a64b4b41-1900-0000-4ec7-45fbf8070000 pid=2040 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=a64b4b41-1900-0000-4ec7-45fbf8070000 pid=2040 execve guuid=7d7b7941-1900-0000-4ec7-45fbf9070000 pid=2041 /home/sandbox/x86 net guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=7d7b7941-1900-0000-4ec7-45fbf9070000 pid=2041 execve guuid=801ba741-1900-0000-4ec7-45fbfb070000 pid=2043 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=801ba741-1900-0000-4ec7-45fbfb070000 pid=2043 execve guuid=b7abde41-1900-0000-4ec7-45fbfe070000 pid=2046 /usr/bin/busybox net send-data write-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=b7abde41-1900-0000-4ec7-45fbfe070000 pid=2046 execve guuid=2d804050-1900-0000-4ec7-45fb0e080000 pid=2062 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=2d804050-1900-0000-4ec7-45fb0e080000 pid=2062 execve guuid=f2ce7b50-1900-0000-4ec7-45fb10080000 pid=2064 /home/sandbox/x86_64 net guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=f2ce7b50-1900-0000-4ec7-45fb10080000 pid=2064 execve guuid=50e07384-1d00-0000-4ec7-45fbf2100000 pid=4338 /usr/bin/busybox delete-file guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=50e07384-1d00-0000-4ec7-45fbf2100000 pid=4338 execve guuid=e5eda384-1d00-0000-4ec7-45fbf4100000 pid=4340 /usr/bin/busybox guuid=14713ce1-1800-0000-4ec7-45fb1f070000 pid=1823->guuid=e5eda384-1d00-0000-4ec7-45fbf4100000 pid=4340 execve e4f6d7ff-98f5-5057-aa15-d7fef91e9249 188.214.30.5:80 guuid=699770e1-1800-0000-4ec7-45fb21070000 pid=1825->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 98B guuid=abde57eb-1800-0000-4ec7-45fb3c070000 pid=1852->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 98B guuid=595d00f8-1800-0000-4ec7-45fb5d070000 pid=1885->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 98B guuid=23a23703-1900-0000-4ec7-45fb7b070000 pid=1915->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 98B guuid=c61c5d0d-1900-0000-4ec7-45fb99070000 pid=1945->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 98B guuid=ec2c9e17-1900-0000-4ec7-45fbb6070000 pid=1974->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 97B guuid=fb70b921-1900-0000-4ec7-45fbc6070000 pid=1990->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 97B guuid=44cf152d-1900-0000-4ec7-45fbdd070000 pid=2013->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 97B guuid=95100c38-1900-0000-4ec7-45fbe8070000 pid=2024->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7d7b7941-1900-0000-4ec7-45fbf9070000 pid=2041->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d9949e41-1900-0000-4ec7-45fbfa070000 pid=2042 /home/sandbox/x86 net send-data zombie guuid=7d7b7941-1900-0000-4ec7-45fbf9070000 pid=2041->guuid=d9949e41-1900-0000-4ec7-45fbfa070000 pid=2042 clone guuid=d9949e41-1900-0000-4ec7-45fbfa070000 pid=2042->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 86B guuid=0f95ab41-1900-0000-4ec7-45fbfc070000 pid=2044 /home/sandbox/x86 guuid=d9949e41-1900-0000-4ec7-45fbfa070000 pid=2042->guuid=0f95ab41-1900-0000-4ec7-45fbfc070000 pid=2044 clone guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045 /home/sandbox/x86 net net-scan send-data zombie guuid=d9949e41-1900-0000-4ec7-45fbfa070000 pid=2042->guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045 clone guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e0a4a352-a236-5f6f-8053-0a85dc1f7a08 191.61.49.250:23 guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045->e0a4a352-a236-5f6f-8053-0a85dc1f7a08 send: 40B guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045|send-data send-data to 4097 IP addresses review logs to see them all guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045->guuid=f389b341-1900-0000-4ec7-45fbfd070000 pid=2045|send-data send guuid=b7abde41-1900-0000-4ec7-45fbfe070000 pid=2046->e4f6d7ff-98f5-5057-aa15-d7fef91e9249 send: 86B guuid=f2ce7b50-1900-0000-4ec7-45fb10080000 pid=2064->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4945e811-daa2-5999-bd89-4cdaa6badb43 0.0.0.0:8345 guuid=f2ce7b50-1900-0000-4ec7-45fb10080000 pid=2064->4945e811-daa2-5999-bd89-4cdaa6badb43 con guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336 /home/sandbox/x86_64 net send-data zombie guuid=f2ce7b50-1900-0000-4ec7-45fb10080000 pid=2064->guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336 clone guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 559B 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 con guuid=d2507084-1d00-0000-4ec7-45fbf1100000 pid=4337 /home/sandbox/x86_64 guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336->guuid=d2507084-1d00-0000-4ec7-45fbf1100000 pid=4337 clone guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339 /home/sandbox/x86_64 net net-scan send-data guuid=6e166384-1d00-0000-4ec7-45fbf0100000 pid=4336->guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339 clone guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 570c82e9-b9e2-578a-bab1-7349f0ba3903 160.218.106.89:23 guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339->570c82e9-b9e2-578a-bab1-7349f0ba3903 con guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339|send-data send-data to 4097 IP addresses review logs to see them all guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339->guuid=14127d84-1d00-0000-4ec7-45fbf3100000 pid=4339|send-data send
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6ead92bad5d294a8703f854acb7a08eff3fbd8f1ec213c05b66a746449eb511e

(this sample)

  
Delivery method
Distributed via web download

Comments