MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72eff03b8573329818b38185074aa763e99d15f5709fecc44f9afece21dc06d8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 72eff03b8573329818b38185074aa763e99d15f5709fecc44f9afece21dc06d8
SHA3-384 hash: 6cb8ae1b7cef092cca0a2318da6343e71c82de6a12dedc534da5dadd0876ba6f7f26046c8f4665c169caf2e269709f48
SHA1 hash: 1a6bf8ceeb92a03c7143db9eb1f7dbf80a73ba7c
MD5 hash: a78df4a4e52e25cff44712ee65503dce
humanhash: artist-chicken-georgia-single
File name:sshbins.sh
Download: download sample
Signature Mirai
File size:3'460 bytes
First seen:2026-03-16 03:06:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZFazPMBcGeLzXb17xnPI+75sYFs4az/hxxFRQn0YKQDO+l:ZFazPMBxWzpe1JNzFTAOO
TLSH T1E06154D4C83094378C868A0BF561E29A5DDC93E599E0C12C57A8DE3711E2F3E7C9FA42
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://88.214.20.14/bins/tux.x864e51e9939761fa2348056923c01c52c22f7504db578032cd60ced6fc6fd6ef21 Miraimirai
http://88.214.20.14/bins/tux.mipsa9c17380091a7393278d5a6e712e10eb5895894bcc581a6fe0572a4fd63e7f15 Miraimirai
http://88.214.20.14/bins/tux.mpslf10369703a0a762d12401c40b0c0c0b8b89f4179c1e14714182b4eabaf9253c1 Miraimirai
http://88.214.20.14/bins/tux.arm824264de5a67cd58bd91d70f82bbe817d727ff641135dc9e0b199a7f8633224e Miraimirai
http://88.214.20.14/bins/tux.arc1467464238cd5701035429e38da6dccd94824ae384a0ea0b479d8106cc63ffe8 Miraimirai
http://88.214.20.14/bins/tux.arm4n/an/an/a
http://88.214.20.14/bins/tux.arm5e2334ec8f063439a2d3287a8f4570f1a939dd30c93ca75b15574a4fa4a2803b5 Miraimirai
http://88.214.20.14/bins/tux.arm622565595c04aeb2ce3468ce8212164bf7747f693e1ae180c1636adabd50c1381 Miraimirai
http://88.214.20.14/bins/tux.arm701cbaaa24b9edf6b9c5a5b1410f9d5744303c27e3bd8403677c2fd6708ae5e4e Miraimirai
http://88.214.20.14/bins/tux.ppc00cb050a8c83d1250ad1d33c2a07a1c393de621d48c70f6113927a81eea52822 Miraimirai
http://88.214.20.14/bins/tux.m68k0a92d0246341763621a5b0808df4fabd035c323e50354c6d6a2fc457b5ec61fb Miraimirai
http://88.214.20.14/bins/tux.sh4a8c55e579790c6ffe5239b837488f71456bde46f3b89a3ec31bf37aa9ebd2686 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
91
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=1e8f3465-1600-0000-ddcc-efba850f0000 pid=3973 /usr/bin/sudo guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981 /tmp/sample.bin guuid=1e8f3465-1600-0000-ddcc-efba850f0000 pid=3973->guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981 execve guuid=2b1a4767-1600-0000-ddcc-efba910f0000 pid=3985 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=2b1a4767-1600-0000-ddcc-efba910f0000 pid=3985 execve guuid=ccd45d6b-1600-0000-ddcc-efbaa20f0000 pid=4002 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=ccd45d6b-1600-0000-ddcc-efbaa20f0000 pid=4002 execve guuid=3988956b-1600-0000-ddcc-efbaa30f0000 pid=4003 /home/sandbox/tux.x86 net guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=3988956b-1600-0000-ddcc-efbaa30f0000 pid=4003 execve guuid=4956be6b-1600-0000-ddcc-efbaa80f0000 pid=4008 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=4956be6b-1600-0000-ddcc-efbaa80f0000 pid=4008 execve guuid=fcb64c76-1600-0000-ddcc-efbace0f0000 pid=4046 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=fcb64c76-1600-0000-ddcc-efbace0f0000 pid=4046 execve guuid=41a5ae76-1600-0000-ddcc-efbad20f0000 pid=4050 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=41a5ae76-1600-0000-ddcc-efbad20f0000 pid=4050 clone guuid=568a8f78-1600-0000-ddcc-efbada0f0000 pid=4058 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=568a8f78-1600-0000-ddcc-efbada0f0000 pid=4058 execve guuid=c259b97d-1600-0000-ddcc-efbaf00f0000 pid=4080 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=c259b97d-1600-0000-ddcc-efbaf00f0000 pid=4080 execve guuid=e12def7d-1600-0000-ddcc-efbaf20f0000 pid=4082 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=e12def7d-1600-0000-ddcc-efbaf20f0000 pid=4082 clone guuid=cc2ff07e-1600-0000-ddcc-efbaf70f0000 pid=4087 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=cc2ff07e-1600-0000-ddcc-efbaf70f0000 pid=4087 execve guuid=0ecb3183-1600-0000-ddcc-efba09100000 pid=4105 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=0ecb3183-1600-0000-ddcc-efba09100000 pid=4105 execve guuid=16566f83-1600-0000-ddcc-efba0a100000 pid=4106 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=16566f83-1600-0000-ddcc-efba0a100000 pid=4106 clone guuid=50060085-1600-0000-ddcc-efba12100000 pid=4114 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=50060085-1600-0000-ddcc-efba12100000 pid=4114 execve guuid=1fff1289-1600-0000-ddcc-efba22100000 pid=4130 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=1fff1289-1600-0000-ddcc-efba22100000 pid=4130 execve guuid=23d04d89-1600-0000-ddcc-efba24100000 pid=4132 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=23d04d89-1600-0000-ddcc-efba24100000 pid=4132 clone guuid=1bac338a-1600-0000-ddcc-efba2c100000 pid=4140 /usr/bin/busybox net send-data guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=1bac338a-1600-0000-ddcc-efba2c100000 pid=4140 execve guuid=0e504b8c-1600-0000-ddcc-efba37100000 pid=4151 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=0e504b8c-1600-0000-ddcc-efba37100000 pid=4151 execve guuid=15365e90-1600-0000-ddcc-efba48100000 pid=4168 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=15365e90-1600-0000-ddcc-efba48100000 pid=4168 execve guuid=292ea490-1600-0000-ddcc-efba4b100000 pid=4171 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=292ea490-1600-0000-ddcc-efba4b100000 pid=4171 clone guuid=aa412d92-1600-0000-ddcc-efba51100000 pid=4177 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=aa412d92-1600-0000-ddcc-efba51100000 pid=4177 execve guuid=e2f77996-1600-0000-ddcc-efba5a100000 pid=4186 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=e2f77996-1600-0000-ddcc-efba5a100000 pid=4186 execve guuid=7925af96-1600-0000-ddcc-efba5c100000 pid=4188 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=7925af96-1600-0000-ddcc-efba5c100000 pid=4188 clone guuid=bdc73998-1600-0000-ddcc-efba61100000 pid=4193 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=bdc73998-1600-0000-ddcc-efba61100000 pid=4193 execve guuid=559e399d-1600-0000-ddcc-efba7a100000 pid=4218 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=559e399d-1600-0000-ddcc-efba7a100000 pid=4218 execve guuid=5f02789d-1600-0000-ddcc-efba7c100000 pid=4220 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=5f02789d-1600-0000-ddcc-efba7c100000 pid=4220 clone guuid=e588a59e-1600-0000-ddcc-efba81100000 pid=4225 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=e588a59e-1600-0000-ddcc-efba81100000 pid=4225 execve guuid=64de6ea3-1600-0000-ddcc-efba98100000 pid=4248 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=64de6ea3-1600-0000-ddcc-efba98100000 pid=4248 execve guuid=54caaea3-1600-0000-ddcc-efba9b100000 pid=4251 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=54caaea3-1600-0000-ddcc-efba9b100000 pid=4251 clone guuid=3f6660a4-1600-0000-ddcc-efba9e100000 pid=4254 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=3f6660a4-1600-0000-ddcc-efba9e100000 pid=4254 execve guuid=c46927a9-1600-0000-ddcc-efbabb100000 pid=4283 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=c46927a9-1600-0000-ddcc-efbabb100000 pid=4283 execve guuid=6c3e5da9-1600-0000-ddcc-efbabd100000 pid=4285 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=6c3e5da9-1600-0000-ddcc-efbabd100000 pid=4285 clone guuid=5e5a88aa-1600-0000-ddcc-efbac5100000 pid=4293 /usr/bin/busybox net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=5e5a88aa-1600-0000-ddcc-efbac5100000 pid=4293 execve guuid=f454bbae-1600-0000-ddcc-efbadb100000 pid=4315 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=f454bbae-1600-0000-ddcc-efbadb100000 pid=4315 execve guuid=30d5eeae-1600-0000-ddcc-efbadd100000 pid=4317 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=30d5eeae-1600-0000-ddcc-efbadd100000 pid=4317 clone guuid=418453b0-1600-0000-ddcc-efbae2100000 pid=4322 /usr/bin/wget guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=418453b0-1600-0000-ddcc-efbae2100000 pid=4322 execve guuid=c4053ab5-1600-0000-ddcc-efbaf8100000 pid=4344 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=c4053ab5-1600-0000-ddcc-efbaf8100000 pid=4344 execve guuid=4fda72bd-1600-0000-ddcc-efba12110000 pid=4370 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=4fda72bd-1600-0000-ddcc-efba12110000 pid=4370 execve guuid=5a8bb9bd-1600-0000-ddcc-efba14110000 pid=4372 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=5a8bb9bd-1600-0000-ddcc-efba14110000 pid=4372 clone guuid=302f05bf-1600-0000-ddcc-efba1d110000 pid=4381 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=302f05bf-1600-0000-ddcc-efba1d110000 pid=4381 execve guuid=430332c8-1600-0000-ddcc-efba44110000 pid=4420 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=430332c8-1600-0000-ddcc-efba44110000 pid=4420 execve guuid=84296ec8-1600-0000-ddcc-efba45110000 pid=4421 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=84296ec8-1600-0000-ddcc-efba45110000 pid=4421 clone guuid=91e7ffc8-1600-0000-ddcc-efba4b110000 pid=4427 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=91e7ffc8-1600-0000-ddcc-efba4b110000 pid=4427 execve guuid=0ba081cf-1600-0000-ddcc-efba6b110000 pid=4459 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=0ba081cf-1600-0000-ddcc-efba6b110000 pid=4459 execve guuid=165dbfcf-1600-0000-ddcc-efba6c110000 pid=4460 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=165dbfcf-1600-0000-ddcc-efba6c110000 pid=4460 clone guuid=25102fd0-1600-0000-ddcc-efba71110000 pid=4465 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=25102fd0-1600-0000-ddcc-efba71110000 pid=4465 execve guuid=6f53f9d4-1600-0000-ddcc-efba8b110000 pid=4491 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=6f53f9d4-1600-0000-ddcc-efba8b110000 pid=4491 execve guuid=9c434ad5-1600-0000-ddcc-efba8c110000 pid=4492 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=9c434ad5-1600-0000-ddcc-efba8c110000 pid=4492 clone guuid=6a183ed6-1600-0000-ddcc-efba93110000 pid=4499 /usr/bin/wget net send-data guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=6a183ed6-1600-0000-ddcc-efba93110000 pid=4499 execve guuid=3c82b8d9-1600-0000-ddcc-efbaa4110000 pid=4516 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=3c82b8d9-1600-0000-ddcc-efbaa4110000 pid=4516 execve guuid=fbf26ae0-1600-0000-ddcc-efbab8110000 pid=4536 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=fbf26ae0-1600-0000-ddcc-efbab8110000 pid=4536 execve guuid=9e1fbde0-1600-0000-ddcc-efbaba110000 pid=4538 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=9e1fbde0-1600-0000-ddcc-efbaba110000 pid=4538 clone guuid=692b64e1-1600-0000-ddcc-efbabe110000 pid=4542 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=692b64e1-1600-0000-ddcc-efbabe110000 pid=4542 execve guuid=5d7fece7-1600-0000-ddcc-efbacf110000 pid=4559 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=5d7fece7-1600-0000-ddcc-efbacf110000 pid=4559 execve guuid=06762de8-1600-0000-ddcc-efbad1110000 pid=4561 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=06762de8-1600-0000-ddcc-efbad1110000 pid=4561 clone guuid=9c0fa8e8-1600-0000-ddcc-efbad7110000 pid=4567 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=9c0fa8e8-1600-0000-ddcc-efbad7110000 pid=4567 execve guuid=764f07f4-1600-0000-ddcc-efba02120000 pid=4610 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=764f07f4-1600-0000-ddcc-efba02120000 pid=4610 execve guuid=66b7f8ff-1600-0000-ddcc-efba0b120000 pid=4619 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=66b7f8ff-1600-0000-ddcc-efba0b120000 pid=4619 clone guuid=ce48ca00-1700-0000-ddcc-efba0f120000 pid=4623 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=ce48ca00-1700-0000-ddcc-efba0f120000 pid=4623 execve guuid=2567a507-1700-0000-ddcc-efba25120000 pid=4645 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=2567a507-1700-0000-ddcc-efba25120000 pid=4645 execve guuid=6370fb07-1700-0000-ddcc-efba26120000 pid=4646 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=6370fb07-1700-0000-ddcc-efba26120000 pid=4646 clone guuid=4eafca08-1700-0000-ddcc-efba2a120000 pid=4650 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=4eafca08-1700-0000-ddcc-efba2a120000 pid=4650 execve guuid=52875611-1700-0000-ddcc-efba4b120000 pid=4683 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=52875611-1700-0000-ddcc-efba4b120000 pid=4683 execve guuid=b9cceb11-1700-0000-ddcc-efba4e120000 pid=4686 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=b9cceb11-1700-0000-ddcc-efba4e120000 pid=4686 clone guuid=ae93af12-1700-0000-ddcc-efba52120000 pid=4690 /usr/bin/wget net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=ae93af12-1700-0000-ddcc-efba52120000 pid=4690 execve guuid=66df8c19-1700-0000-ddcc-efba5f120000 pid=4703 /usr/bin/chmod guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=66df8c19-1700-0000-ddcc-efba5f120000 pid=4703 execve guuid=174fdd19-1700-0000-ddcc-efba60120000 pid=4704 /usr/bin/dash guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=174fdd19-1700-0000-ddcc-efba60120000 pid=4704 clone guuid=a74e9b1a-1700-0000-ddcc-efba64120000 pid=4708 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=a74e9b1a-1700-0000-ddcc-efba64120000 pid=4708 execve guuid=dc267e23-1700-0000-ddcc-efba8a120000 pid=4746 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=dc267e23-1700-0000-ddcc-efba8a120000 pid=4746 execve guuid=61766f2c-1700-0000-ddcc-efbaaf120000 pid=4783 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=61766f2c-1700-0000-ddcc-efbaaf120000 pid=4783 execve guuid=7a205135-1700-0000-ddcc-efbad3120000 pid=4819 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=7a205135-1700-0000-ddcc-efbad3120000 pid=4819 execve guuid=71d5273d-1700-0000-ddcc-efbaf3120000 pid=4851 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=71d5273d-1700-0000-ddcc-efbaf3120000 pid=4851 execve guuid=823b8e43-1700-0000-ddcc-efba10130000 pid=4880 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=823b8e43-1700-0000-ddcc-efba10130000 pid=4880 execve guuid=72fc6347-1700-0000-ddcc-efba21130000 pid=4897 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=72fc6347-1700-0000-ddcc-efba21130000 pid=4897 execve guuid=9045c44e-1700-0000-ddcc-efba40130000 pid=4928 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=9045c44e-1700-0000-ddcc-efba40130000 pid=4928 execve guuid=593fdd56-1700-0000-ddcc-efba62130000 pid=4962 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=593fdd56-1700-0000-ddcc-efba62130000 pid=4962 execve guuid=8cc49062-1700-0000-ddcc-efba94130000 pid=5012 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=8cc49062-1700-0000-ddcc-efba94130000 pid=5012 execve guuid=6d63336c-1700-0000-ddcc-efbabb130000 pid=5051 /usr/bin/curl net send-data write-file guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=6d63336c-1700-0000-ddcc-efbabb130000 pid=5051 execve guuid=5dcf3e75-1700-0000-ddcc-efbade130000 pid=5086 /usr/bin/curl net guuid=c04c0d67-1600-0000-ddcc-efba8d0f0000 pid=3981->guuid=5dcf3e75-1700-0000-ddcc-efbade130000 pid=5086 execve 07e21ec3-fc3f-5553-b548-91445caa8634 88.214.20.14:80 guuid=2b1a4767-1600-0000-ddcc-efba910f0000 pid=3985->07e21ec3-fc3f-5553-b548-91445caa8634 send: 87B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3988956b-1600-0000-ddcc-efbaa30f0000 pid=4003->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006 /home/sandbox/tux.x86 net send-data zombie guuid=3988956b-1600-0000-ddcc-efbaa30f0000 pid=4003->guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006 clone guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5ce35052-8cf1-5e61-9192-ecdca327d1ce 64.89.161.130:44300 guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006->5ce35052-8cf1-5e61-9192-ecdca327d1ce send: 12B guuid=0751c16b-1600-0000-ddcc-efbaa90f0000 pid=4009 /home/sandbox/tux.x86 guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006->guuid=0751c16b-1600-0000-ddcc-efbaa90f0000 pid=4009 clone guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010 /home/sandbox/tux.x86 net net-scan send-data guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006->guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010 clone guuid=02dcc86b-1600-0000-ddcc-efbaab0f0000 pid=4011 /home/sandbox/tux.x86 guuid=ef56b86b-1600-0000-ddcc-efbaa60f0000 pid=4006->guuid=02dcc86b-1600-0000-ddcc-efbaab0f0000 pid=4011 clone guuid=4956be6b-1600-0000-ddcc-efbaa80f0000 pid=4008->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 80d35b58-8ce8-5a26-826a-211e01b9b3ca 147.127.33.124:23 guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010->80d35b58-8ce8-5a26-826a-211e01b9b3ca send: 40B d455090a-513f-5c42-ad3a-d0af2a72add0 185.14.68.146:23 guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010->d455090a-513f-5c42-ad3a-d0af2a72add0 send: 40B guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010|send-data send-data to 4097 IP addresses review logs to see them all guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010->guuid=266ec46b-1600-0000-ddcc-efbaaa0f0000 pid=4010|send-data send guuid=568a8f78-1600-0000-ddcc-efbada0f0000 pid=4058->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=cc2ff07e-1600-0000-ddcc-efbaf70f0000 pid=4087->07e21ec3-fc3f-5553-b548-91445caa8634 send: 87B guuid=50060085-1600-0000-ddcc-efba12100000 pid=4114->07e21ec3-fc3f-5553-b548-91445caa8634 send: 87B guuid=1bac338a-1600-0000-ddcc-efba2c100000 pid=4140->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=0e504b8c-1600-0000-ddcc-efba37100000 pid=4151->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=aa412d92-1600-0000-ddcc-efba51100000 pid=4177->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=bdc73998-1600-0000-ddcc-efba61100000 pid=4193->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=e588a59e-1600-0000-ddcc-efba81100000 pid=4225->07e21ec3-fc3f-5553-b548-91445caa8634 send: 87B guuid=3f6660a4-1600-0000-ddcc-efba9e100000 pid=4254->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=5e5a88aa-1600-0000-ddcc-efbac5100000 pid=4293->07e21ec3-fc3f-5553-b548-91445caa8634 send: 87B guuid=c4053ab5-1600-0000-ddcc-efbaf8100000 pid=4344->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=302f05bf-1600-0000-ddcc-efba1d110000 pid=4381->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=91e7ffc8-1600-0000-ddcc-efba4b110000 pid=4427->07e21ec3-fc3f-5553-b548-91445caa8634 send: 139B guuid=25102fd0-1600-0000-ddcc-efba71110000 pid=4465->07e21ec3-fc3f-5553-b548-91445caa8634 send: 139B guuid=6a183ed6-1600-0000-ddcc-efba93110000 pid=4499->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=3c82b8d9-1600-0000-ddcc-efbaa4110000 pid=4516->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=692b64e1-1600-0000-ddcc-efbabe110000 pid=4542->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=9c0fa8e8-1600-0000-ddcc-efbad7110000 pid=4567->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=ce48ca00-1700-0000-ddcc-efba0f120000 pid=4623->07e21ec3-fc3f-5553-b548-91445caa8634 send: 139B guuid=4eafca08-1700-0000-ddcc-efba2a120000 pid=4650->07e21ec3-fc3f-5553-b548-91445caa8634 send: 140B guuid=ae93af12-1700-0000-ddcc-efba52120000 pid=4690->07e21ec3-fc3f-5553-b548-91445caa8634 send: 139B guuid=a74e9b1a-1700-0000-ddcc-efba64120000 pid=4708->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=dc267e23-1700-0000-ddcc-efba8a120000 pid=4746->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=61766f2c-1700-0000-ddcc-efbaaf120000 pid=4783->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=7a205135-1700-0000-ddcc-efbad3120000 pid=4819->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=71d5273d-1700-0000-ddcc-efbaf3120000 pid=4851->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=823b8e43-1700-0000-ddcc-efba10130000 pid=4880->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=72fc6347-1700-0000-ddcc-efba21130000 pid=4897->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=9045c44e-1700-0000-ddcc-efba40130000 pid=4928->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=593fdd56-1700-0000-ddcc-efba62130000 pid=4962->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=8cc49062-1700-0000-ddcc-efba94130000 pid=5012->07e21ec3-fc3f-5553-b548-91445caa8634 send: 88B guuid=6d63336c-1700-0000-ddcc-efbabb130000 pid=5051->07e21ec3-fc3f-5553-b548-91445caa8634 send: 89B guuid=5dcf3e75-1700-0000-ddcc-efbade130000 pid=5086->07e21ec3-fc3f-5553-b548-91445caa8634 con
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-16 03:07:22 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (87612) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 72eff03b8573329818b38185074aa763e99d15f5709fecc44f9afece21dc06d8

(this sample)

  
Delivery method
Distributed via web download

Comments