MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 83b628a580c1fb473a0a55efb1dad03f6a81f1a5c1e0ae99f550a764fd9d9efe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 83b628a580c1fb473a0a55efb1dad03f6a81f1a5c1e0ae99f550a764fd9d9efe
SHA3-384 hash: 2ed0c4677d3abf64c0df45fce75e672dc5ad9060c5360d85d16a4757d38de7aa4f43ba7b8167a5d9e25076b4beb6a2a6
SHA1 hash: dbad998fd60417d391617caee2e1704f7287cdb1
MD5 hash: d0b199da5555da703148de7cc7d93962
humanhash: finch-autumn-oven-iowa
File name:run.sh
Download: download sample
Signature Mirai
File size:2'907 bytes
First seen:2025-11-21 08:41:27 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:6P2JMOIbiBG5uZxEaEnE2EhEkuQbw5KJUflChM34:6P2JMOIbiBG5uZxxcvyqQbwRChM34
TLSH T1625124BB01094B359609864FF7F875B4722BB5D796EBCE04E944281E5FC5D5C3292E40
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnaarch64xnxn907ef6f74b4e5d5956e55b1f4660768aa918d87df53fa00cf4b59263b5d4189a Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxni386xnxnn/an/aelf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnloongarch64xnxna8fd940dc918666f47dc4fa9e351ac9ad6a969a17cdf58871cc724f92ac54637 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnm68kxnxn8f6ce0ae66f7f696d896f6b19234582bbd7969d34218f428e29b4ec186c46132 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnmicroblazexnxn6e7e0ac426f07cfdc6a16e9ebbb1435e3978bb19f4b5085adc01b2daaec5e264 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnmipsxnxn2ac83497640ee4e731ca43d4514a8c1620bc7d0b6d80fb6719b5a789b017efe4 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnor1kxnxn91760e6e4bad4055c443905910909e18562feff8cf286f4f3359964cb8f702a0 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnpowerpcxnxn9f38218a5f5f1f12cf6b46cf32a5ebca3dcf7d2f216713e4bb6e67d49b37db49 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnriscv32xnxn92de153ffaa61982a25d254735a86e4f42d9674011dfa41ba33e44369524d996 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnriscv64xnxn97967f261cf233e64c897eacece81f6c96ffba7f59eea619376de5d92603b34e Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnsh2xnxn0686b04b788e2fc7df3ced2d123052976b3ff0ee640a61e41554392dca507d0b Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnsh4xnxn2ede46d54cc0573ef26ebd2a3e1ce6fb89c9768c9e453cd10b42ab6951b6fb34 Miraielf mirai
http://213.209.143.33/bins/xnxnxnxnxnxnxnxnx86_64xnxn00f6a25ffc788301e3e08d527f02834c12c7c945bb64c0c8267efb05146f0804 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-15T22:55:00Z UTC
Last seen:
2025-11-23T01:47:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=d9048936-1c00-0000-8092-623d9e0c0000 pid=3230 /usr/bin/sudo guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231 /tmp/sample.bin guuid=d9048936-1c00-0000-8092-623d9e0c0000 pid=3230->guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231 execve guuid=c734ba3a-1c00-0000-8092-623da00c0000 pid=3232 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=c734ba3a-1c00-0000-8092-623da00c0000 pid=3232 execve guuid=33385941-1c00-0000-8092-623da80c0000 pid=3240 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=33385941-1c00-0000-8092-623da80c0000 pid=3240 execve guuid=f241484c-1c00-0000-8092-623db70c0000 pid=3255 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=f241484c-1c00-0000-8092-623db70c0000 pid=3255 execve guuid=18b9aa4c-1c00-0000-8092-623db80c0000 pid=3256 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=18b9aa4c-1c00-0000-8092-623db80c0000 pid=3256 clone guuid=1c51504d-1c00-0000-8092-623dbb0c0000 pid=3259 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=1c51504d-1c00-0000-8092-623dbb0c0000 pid=3259 execve guuid=acc1954d-1c00-0000-8092-623dbc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=acc1954d-1c00-0000-8092-623dbc0c0000 pid=3260 execve guuid=f44c0d52-1c00-0000-8092-623dca0c0000 pid=3274 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=f44c0d52-1c00-0000-8092-623dca0c0000 pid=3274 execve guuid=fcbbf158-1c00-0000-8092-623ddd0c0000 pid=3293 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=fcbbf158-1c00-0000-8092-623ddd0c0000 pid=3293 execve guuid=51703459-1c00-0000-8092-623ddf0c0000 pid=3295 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=51703459-1c00-0000-8092-623ddf0c0000 pid=3295 execve guuid=9f1a4f5a-1c00-0000-8092-623de40c0000 pid=3300 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=9f1a4f5a-1c00-0000-8092-623de40c0000 pid=3300 execve guuid=1feb825a-1c00-0000-8092-623de70c0000 pid=3303 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=1feb825a-1c00-0000-8092-623de70c0000 pid=3303 execve guuid=94e05860-1c00-0000-8092-623df30c0000 pid=3315 /usr/bin/curl net guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=94e05860-1c00-0000-8092-623df30c0000 pid=3315 execve guuid=11bf5c65-1c00-0000-8092-623d010d0000 pid=3329 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=11bf5c65-1c00-0000-8092-623d010d0000 pid=3329 execve guuid=678ab265-1c00-0000-8092-623d030d0000 pid=3331 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=678ab265-1c00-0000-8092-623d030d0000 pid=3331 clone guuid=69fa6366-1c00-0000-8092-623d060d0000 pid=3334 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=69fa6366-1c00-0000-8092-623d060d0000 pid=3334 execve guuid=41c6b466-1c00-0000-8092-623d080d0000 pid=3336 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=41c6b466-1c00-0000-8092-623d080d0000 pid=3336 execve guuid=c9cec56b-1c00-0000-8092-623d120d0000 pid=3346 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=c9cec56b-1c00-0000-8092-623d120d0000 pid=3346 execve guuid=b4d27974-1c00-0000-8092-623d140d0000 pid=3348 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=b4d27974-1c00-0000-8092-623d140d0000 pid=3348 execve guuid=7867c774-1c00-0000-8092-623d160d0000 pid=3350 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=7867c774-1c00-0000-8092-623d160d0000 pid=3350 clone guuid=b82a6a77-1c00-0000-8092-623d1e0d0000 pid=3358 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=b82a6a77-1c00-0000-8092-623d1e0d0000 pid=3358 execve guuid=44e0d077-1c00-0000-8092-623d200d0000 pid=3360 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=44e0d077-1c00-0000-8092-623d200d0000 pid=3360 execve guuid=6031197e-1c00-0000-8092-623d2b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=6031197e-1c00-0000-8092-623d2b0d0000 pid=3371 execve guuid=ccce7185-1c00-0000-8092-623d360d0000 pid=3382 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=ccce7185-1c00-0000-8092-623d360d0000 pid=3382 execve guuid=449bc385-1c00-0000-8092-623d380d0000 pid=3384 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=449bc385-1c00-0000-8092-623d380d0000 pid=3384 clone guuid=9d448e87-1c00-0000-8092-623d3d0d0000 pid=3389 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=9d448e87-1c00-0000-8092-623d3d0d0000 pid=3389 execve guuid=94f3d987-1c00-0000-8092-623d3f0d0000 pid=3391 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=94f3d987-1c00-0000-8092-623d3f0d0000 pid=3391 execve guuid=eb16588c-1c00-0000-8092-623d4a0d0000 pid=3402 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=eb16588c-1c00-0000-8092-623d4a0d0000 pid=3402 execve guuid=667ba692-1c00-0000-8092-623d580d0000 pid=3416 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=667ba692-1c00-0000-8092-623d580d0000 pid=3416 execve guuid=3ccc2e93-1c00-0000-8092-623d5a0d0000 pid=3418 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=3ccc2e93-1c00-0000-8092-623d5a0d0000 pid=3418 clone guuid=6b2dfb93-1c00-0000-8092-623d5e0d0000 pid=3422 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=6b2dfb93-1c00-0000-8092-623d5e0d0000 pid=3422 execve guuid=30f09194-1c00-0000-8092-623d600d0000 pid=3424 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=30f09194-1c00-0000-8092-623d600d0000 pid=3424 execve guuid=154a189b-1c00-0000-8092-623d6d0d0000 pid=3437 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=154a189b-1c00-0000-8092-623d6d0d0000 pid=3437 execve guuid=6b8ffba4-1c00-0000-8092-623d870d0000 pid=3463 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=6b8ffba4-1c00-0000-8092-623d870d0000 pid=3463 execve guuid=3a5362a5-1c00-0000-8092-623d8a0d0000 pid=3466 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=3a5362a5-1c00-0000-8092-623d8a0d0000 pid=3466 clone guuid=69c0cea6-1c00-0000-8092-623d8f0d0000 pid=3471 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=69c0cea6-1c00-0000-8092-623d8f0d0000 pid=3471 execve guuid=919422a7-1c00-0000-8092-623d910d0000 pid=3473 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=919422a7-1c00-0000-8092-623d910d0000 pid=3473 execve guuid=f3aeb5ab-1c00-0000-8092-623d9e0d0000 pid=3486 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=f3aeb5ab-1c00-0000-8092-623d9e0d0000 pid=3486 execve guuid=2587feb2-1c00-0000-8092-623db00d0000 pid=3504 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=2587feb2-1c00-0000-8092-623db00d0000 pid=3504 execve guuid=d0cd53b3-1c00-0000-8092-623db20d0000 pid=3506 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=d0cd53b3-1c00-0000-8092-623db20d0000 pid=3506 clone guuid=65086fb4-1c00-0000-8092-623db70d0000 pid=3511 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=65086fb4-1c00-0000-8092-623db70d0000 pid=3511 execve guuid=841bc1b4-1c00-0000-8092-623db90d0000 pid=3513 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=841bc1b4-1c00-0000-8092-623db90d0000 pid=3513 execve guuid=a96ed1bb-1c00-0000-8092-623dcb0d0000 pid=3531 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=a96ed1bb-1c00-0000-8092-623dcb0d0000 pid=3531 execve guuid=8e6421c3-1c00-0000-8092-623dd70d0000 pid=3543 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=8e6421c3-1c00-0000-8092-623dd70d0000 pid=3543 execve guuid=ed855cc3-1c00-0000-8092-623dd90d0000 pid=3545 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=ed855cc3-1c00-0000-8092-623dd90d0000 pid=3545 clone guuid=9dedf6c3-1c00-0000-8092-623ddd0d0000 pid=3549 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=9dedf6c3-1c00-0000-8092-623ddd0d0000 pid=3549 execve guuid=22e986c4-1c00-0000-8092-623de00d0000 pid=3552 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=22e986c4-1c00-0000-8092-623de00d0000 pid=3552 execve guuid=7505aac8-1c00-0000-8092-623ded0d0000 pid=3565 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=7505aac8-1c00-0000-8092-623ded0d0000 pid=3565 execve guuid=b043aecf-1c00-0000-8092-623dfd0d0000 pid=3581 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=b043aecf-1c00-0000-8092-623dfd0d0000 pid=3581 execve guuid=8ff7eccf-1c00-0000-8092-623dfe0d0000 pid=3582 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=8ff7eccf-1c00-0000-8092-623dfe0d0000 pid=3582 clone guuid=d85168d0-1c00-0000-8092-623d010e0000 pid=3585 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=d85168d0-1c00-0000-8092-623d010e0000 pid=3585 execve guuid=ea5bc9d0-1c00-0000-8092-623d030e0000 pid=3587 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=ea5bc9d0-1c00-0000-8092-623d030e0000 pid=3587 execve guuid=b83f48d6-1c00-0000-8092-623d070e0000 pid=3591 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=b83f48d6-1c00-0000-8092-623d070e0000 pid=3591 execve guuid=a33cf7e5-1c00-0000-8092-623d270e0000 pid=3623 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=a33cf7e5-1c00-0000-8092-623d270e0000 pid=3623 execve guuid=5d015be6-1c00-0000-8092-623d280e0000 pid=3624 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=5d015be6-1c00-0000-8092-623d280e0000 pid=3624 clone guuid=672e29e8-1c00-0000-8092-623d2a0e0000 pid=3626 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=672e29e8-1c00-0000-8092-623d2a0e0000 pid=3626 execve guuid=ebe022e9-1c00-0000-8092-623d2b0e0000 pid=3627 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=ebe022e9-1c00-0000-8092-623d2b0e0000 pid=3627 execve guuid=4bddf7ee-1c00-0000-8092-623d350e0000 pid=3637 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=4bddf7ee-1c00-0000-8092-623d350e0000 pid=3637 execve guuid=d6654df6-1c00-0000-8092-623d480e0000 pid=3656 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=d6654df6-1c00-0000-8092-623d480e0000 pid=3656 execve guuid=78229cf6-1c00-0000-8092-623d490e0000 pid=3657 /usr/bin/dash guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=78229cf6-1c00-0000-8092-623d490e0000 pid=3657 clone guuid=2ff23af7-1c00-0000-8092-623d4d0e0000 pid=3661 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=2ff23af7-1c00-0000-8092-623d4d0e0000 pid=3661 execve guuid=316a7ff7-1c00-0000-8092-623d4e0e0000 pid=3662 /usr/bin/wget net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=316a7ff7-1c00-0000-8092-623d4e0e0000 pid=3662 execve guuid=dc4c19fc-1c00-0000-8092-623d570e0000 pid=3671 /usr/bin/curl net send-data write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=dc4c19fc-1c00-0000-8092-623d570e0000 pid=3671 execve guuid=2a73f901-1d00-0000-8092-623d650e0000 pid=3685 /usr/bin/chmod guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=2a73f901-1d00-0000-8092-623d650e0000 pid=3685 execve guuid=232f4e02-1d00-0000-8092-623d660e0000 pid=3686 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn write-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=232f4e02-1d00-0000-8092-623d660e0000 pid=3686 execve guuid=d2cb0b03-1d00-0000-8092-623d690e0000 pid=3689 /usr/bin/rm delete-file guuid=9da2693a-1c00-0000-8092-623d9f0c0000 pid=3231->guuid=d2cb0b03-1d00-0000-8092-623d690e0000 pid=3689 execve d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a 213.209.143.33:80 guuid=c734ba3a-1c00-0000-8092-623da00c0000 pid=3232->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 161B guuid=33385941-1c00-0000-8092-623da80c0000 pid=3240->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 110B guuid=acc1954d-1c00-0000-8092-623dbc0c0000 pid=3260->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 158B guuid=f44c0d52-1c00-0000-8092-623dca0c0000 pid=3274->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 107B guuid=0503465a-1c00-0000-8092-623de30c0000 pid=3299 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=51703459-1c00-0000-8092-623ddf0c0000 pid=3295->guuid=0503465a-1c00-0000-8092-623de30c0000 pid=3299 clone guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn net send-data zombie guuid=0503465a-1c00-0000-8092-623de30c0000 pid=3299->guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301 clone 0b4a2f1e-009c-5ff8-b1fb-f51b6c0e839b 213.209.143.33:54128 guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301->0b4a2f1e-009c-5ff8-b1fb-f51b6c0e839b send: 21B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3304 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301->guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3304 clone guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3306 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn zombie guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3301->guuid=fa9c4f5a-1c00-0000-8092-623de50c0000 pid=3306 clone guuid=1feb825a-1c00-0000-8092-623de70c0000 pid=3303->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 165B guuid=94e05860-1c00-0000-8092-623df30c0000 pid=3315->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a con guuid=41c6b466-1c00-0000-8092-623d080d0000 pid=3336->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 158B guuid=c9cec56b-1c00-0000-8092-623d120d0000 pid=3346->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 107B guuid=44e0d077-1c00-0000-8092-623d200d0000 pid=3360->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 164B guuid=6031197e-1c00-0000-8092-623d2b0d0000 pid=3371->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 113B guuid=94f3d987-1c00-0000-8092-623d3f0d0000 pid=3391->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 158B guuid=eb16588c-1c00-0000-8092-623d4a0d0000 pid=3402->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 107B guuid=30f09194-1c00-0000-8092-623d600d0000 pid=3424->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 158B guuid=154a189b-1c00-0000-8092-623d6d0d0000 pid=3437->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 107B guuid=919422a7-1c00-0000-8092-623d910d0000 pid=3473->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 161B guuid=f3aeb5ab-1c00-0000-8092-623d9e0d0000 pid=3486->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 110B guuid=841bc1b4-1c00-0000-8092-623db90d0000 pid=3513->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 161B guuid=a96ed1bb-1c00-0000-8092-623dcb0d0000 pid=3531->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 110B guuid=22e986c4-1c00-0000-8092-623de00d0000 pid=3552->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 161B guuid=7505aac8-1c00-0000-8092-623ded0d0000 pid=3565->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 110B guuid=ea5bc9d0-1c00-0000-8092-623d030e0000 pid=3587->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 157B guuid=b83f48d6-1c00-0000-8092-623d070e0000 pid=3591->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 106B guuid=ebe022e9-1c00-0000-8092-623d2b0e0000 pid=3627->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 157B guuid=4bddf7ee-1c00-0000-8092-623d350e0000 pid=3637->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 106B guuid=316a7ff7-1c00-0000-8092-623d4e0e0000 pid=3662->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 160B guuid=dc4c19fc-1c00-0000-8092-623d570e0000 pid=3671->d716dbc8-df7a-5b60-ba09-4d1aa4b15a7a send: 109B guuid=1c2b0103-1d00-0000-8092-623d680e0000 pid=3688 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn zombie guuid=232f4e02-1d00-0000-8092-623d660e0000 pid=3686->guuid=1c2b0103-1d00-0000-8092-623d680e0000 pid=3688 clone guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn delete-file net send-data zombie guuid=1c2b0103-1d00-0000-8092-623d680e0000 pid=3688->guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690 clone guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690->0b4a2f1e-009c-5ff8-b1fb-f51b6c0e839b send: 79B guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 38B guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3691 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690->guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3691 clone guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3692 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn zombie guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3690->guuid=f2961903-1d00-0000-8092-623d6a0e0000 pid=3692 clone
Threat name:
Script-Shell.Trojan.Heuristic
Status:
Malicious
First seen:
2025-11-16 03:47:54 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 83b628a580c1fb473a0a55efb1dad03f6a81f1a5c1e0ae99f550a764fd9d9efe

(this sample)

  
Delivery method
Distributed via web download

Comments