MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 855dc153454ecfbc18dc29fbea1d29e93be3a241b75d9c3a2fcb1321e9d4a2cb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 855dc153454ecfbc18dc29fbea1d29e93be3a241b75d9c3a2fcb1321e9d4a2cb
SHA3-384 hash: 1bc06c1874053fc8cc57a69327f2415548fd24d14c715bd2a23fce8b0245826b1fa085d1b4369e693c10b8e1d17acdfb
SHA1 hash: 6b866f23ab45dbbf77b81d20113095442fd3d6bb
MD5 hash: c42784a9ab9ab85399517be1c5281906
humanhash: delta-carolina-lemon-mango
File name:adb
Download: download sample
File size:292 bytes
First seen:2025-10-19 20:47:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYx8iHYf53IY0ZL3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBKW:ZtJ+jRE8KYp0ZKF0ghsOTh4WYO8W
TLSH T14BE0C299F852483278758CB9B7DB2452950B920E6F0A559E7189520BAAE4950A050453
Magika shell
Reporter juroots
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-19T18:51:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=210095bd-1a00-0000-facd-b36ed9090000 pid=2521 /usr/bin/sudo guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527 /tmp/sample.bin guuid=210095bd-1a00-0000-facd-b36ed9090000 pid=2521->guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527 execve guuid=111839c0-1a00-0000-facd-b36ee1090000 pid=2529 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=111839c0-1a00-0000-facd-b36ee1090000 pid=2529 execve guuid=e9cd70d3-1a00-0000-facd-b36e0c0a0000 pid=2572 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=e9cd70d3-1a00-0000-facd-b36e0c0a0000 pid=2572 execve guuid=a5bd15d4-1a00-0000-facd-b36e0f0a0000 pid=2575 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=a5bd15d4-1a00-0000-facd-b36e0f0a0000 pid=2575 clone guuid=8c58b0d4-1a00-0000-facd-b36e130a0000 pid=2579 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=8c58b0d4-1a00-0000-facd-b36e130a0000 pid=2579 execve guuid=951bfbd4-1a00-0000-facd-b36e140a0000 pid=2580 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=951bfbd4-1a00-0000-facd-b36e140a0000 pid=2580 execve guuid=9ce0b8e3-1a00-0000-facd-b36e3c0a0000 pid=2620 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=9ce0b8e3-1a00-0000-facd-b36e3c0a0000 pid=2620 execve guuid=1d6367e4-1a00-0000-facd-b36e3e0a0000 pid=2622 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=1d6367e4-1a00-0000-facd-b36e3e0a0000 pid=2622 clone guuid=c30865e5-1a00-0000-facd-b36e430a0000 pid=2627 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=c30865e5-1a00-0000-facd-b36e430a0000 pid=2627 execve guuid=dfbab0e5-1a00-0000-facd-b36e450a0000 pid=2629 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=dfbab0e5-1a00-0000-facd-b36e450a0000 pid=2629 execve guuid=b154dff1-1a00-0000-facd-b36e640a0000 pid=2660 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=b154dff1-1a00-0000-facd-b36e640a0000 pid=2660 execve guuid=cb621bf2-1a00-0000-facd-b36e660a0000 pid=2662 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=cb621bf2-1a00-0000-facd-b36e660a0000 pid=2662 clone guuid=dba137f3-1a00-0000-facd-b36e6b0a0000 pid=2667 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=dba137f3-1a00-0000-facd-b36e6b0a0000 pid=2667 execve guuid=c5237df3-1a00-0000-facd-b36e6d0a0000 pid=2669 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=c5237df3-1a00-0000-facd-b36e6d0a0000 pid=2669 execve guuid=bcf42aff-1a00-0000-facd-b36e8e0a0000 pid=2702 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=bcf42aff-1a00-0000-facd-b36e8e0a0000 pid=2702 execve guuid=d9fc70ff-1a00-0000-facd-b36e900a0000 pid=2704 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=d9fc70ff-1a00-0000-facd-b36e900a0000 pid=2704 clone guuid=2d4a0500-1b00-0000-facd-b36e940a0000 pid=2708 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=2d4a0500-1b00-0000-facd-b36e940a0000 pid=2708 execve guuid=6cc34600-1b00-0000-facd-b36e960a0000 pid=2710 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=6cc34600-1b00-0000-facd-b36e960a0000 pid=2710 execve guuid=28b2f60d-1b00-0000-facd-b36eba0a0000 pid=2746 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=28b2f60d-1b00-0000-facd-b36eba0a0000 pid=2746 execve guuid=fe16400e-1b00-0000-facd-b36ebb0a0000 pid=2747 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=fe16400e-1b00-0000-facd-b36ebb0a0000 pid=2747 clone guuid=510dce0e-1b00-0000-facd-b36ec00a0000 pid=2752 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=510dce0e-1b00-0000-facd-b36ec00a0000 pid=2752 execve guuid=9fac1a0f-1b00-0000-facd-b36ec10a0000 pid=2753 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=9fac1a0f-1b00-0000-facd-b36ec10a0000 pid=2753 execve guuid=134c4d1e-1b00-0000-facd-b36ee10a0000 pid=2785 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=134c4d1e-1b00-0000-facd-b36ee10a0000 pid=2785 execve guuid=f659971e-1b00-0000-facd-b36ee20a0000 pid=2786 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=f659971e-1b00-0000-facd-b36ee20a0000 pid=2786 clone guuid=0d13531f-1b00-0000-facd-b36ee40a0000 pid=2788 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=0d13531f-1b00-0000-facd-b36ee40a0000 pid=2788 execve guuid=02e8ae1f-1b00-0000-facd-b36ee50a0000 pid=2789 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=02e8ae1f-1b00-0000-facd-b36ee50a0000 pid=2789 execve guuid=17060f2b-1b00-0000-facd-b36ef50a0000 pid=2805 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=17060f2b-1b00-0000-facd-b36ef50a0000 pid=2805 execve guuid=bc8e5c2b-1b00-0000-facd-b36ef70a0000 pid=2807 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=bc8e5c2b-1b00-0000-facd-b36ef70a0000 pid=2807 clone guuid=2d27242c-1b00-0000-facd-b36efc0a0000 pid=2812 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=2d27242c-1b00-0000-facd-b36efc0a0000 pid=2812 execve guuid=0a736f2c-1b00-0000-facd-b36efe0a0000 pid=2814 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=0a736f2c-1b00-0000-facd-b36efe0a0000 pid=2814 execve guuid=9599103b-1b00-0000-facd-b36e120b0000 pid=2834 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=9599103b-1b00-0000-facd-b36e120b0000 pid=2834 execve guuid=b135553b-1b00-0000-facd-b36e140b0000 pid=2836 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=b135553b-1b00-0000-facd-b36e140b0000 pid=2836 clone guuid=e51e843c-1b00-0000-facd-b36e170b0000 pid=2839 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=e51e843c-1b00-0000-facd-b36e170b0000 pid=2839 execve guuid=893ad53c-1b00-0000-facd-b36e190b0000 pid=2841 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=893ad53c-1b00-0000-facd-b36e190b0000 pid=2841 execve guuid=4fc96348-1b00-0000-facd-b36e2f0b0000 pid=2863 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=4fc96348-1b00-0000-facd-b36e2f0b0000 pid=2863 execve guuid=461ed948-1b00-0000-facd-b36e310b0000 pid=2865 /tmp/adb.exploit guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=461ed948-1b00-0000-facd-b36e310b0000 pid=2865 execve guuid=e34bf148-1b00-0000-facd-b36e330b0000 pid=2867 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=e34bf148-1b00-0000-facd-b36e330b0000 pid=2867 execve guuid=84212f49-1b00-0000-facd-b36e360b0000 pid=2870 /usr/bin/wget net send-data write-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=84212f49-1b00-0000-facd-b36e360b0000 pid=2870 execve guuid=4755ad55-1b00-0000-facd-b36e4a0b0000 pid=2890 /usr/bin/chmod guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=4755ad55-1b00-0000-facd-b36e4a0b0000 pid=2890 execve guuid=fc73f755-1b00-0000-facd-b36e4b0b0000 pid=2891 /usr/bin/dash guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=fc73f755-1b00-0000-facd-b36e4b0b0000 pid=2891 clone guuid=9134be56-1b00-0000-facd-b36e4e0b0000 pid=2894 /usr/bin/rm delete-file guuid=2e8bd0bf-1a00-0000-facd-b36edf090000 pid=2527->guuid=9134be56-1b00-0000-facd-b36e4e0b0000 pid=2894 execve ce2040a6-1382-57a9-8f72-87c510446939 91.92.241.8:80 guuid=111839c0-1a00-0000-facd-b36ee1090000 pid=2529->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=951bfbd4-1a00-0000-facd-b36e140a0000 pid=2580->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=dfbab0e5-1a00-0000-facd-b36e450a0000 pid=2629->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=c5237df3-1a00-0000-facd-b36e6d0a0000 pid=2669->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=6cc34600-1b00-0000-facd-b36e960a0000 pid=2710->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=9fac1a0f-1b00-0000-facd-b36ec10a0000 pid=2753->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=02e8ae1f-1b00-0000-facd-b36ee50a0000 pid=2789->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=0a736f2c-1b00-0000-facd-b36efe0a0000 pid=2814->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=893ad53c-1b00-0000-facd-b36e190b0000 pid=2841->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=1e08e948-1b00-0000-facd-b36e320b0000 pid=2866 /tmp/adb.exploit zombie guuid=461ed948-1b00-0000-facd-b36e310b0000 pid=2865->guuid=1e08e948-1b00-0000-facd-b36e320b0000 pid=2866 clone guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868 /tmp/adb.exploit dns net send-data zombie guuid=1e08e948-1b00-0000-facd-b36e320b0000 pid=2866->guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995 /tmp/adb.exploit net net-scan send-data guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868->guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995 clone guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996 /tmp/adb.exploit net net-scan send-data guuid=c8f7f248-1b00-0000-facd-b36e340b0000 pid=2868->guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=84212f49-1b00-0000-facd-b36e360b0000 pid=2870->5747732c-f603-51c6-9252-e264289619bd send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995|send-data send-data to 4097 IP addresses review logs to see them all guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995->guuid=6a96a893-1b00-0000-facd-b36eb30b0000 pid=2995|send-data send guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996|send-data send-data to 4094 IP addresses review logs to see them all guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996->guuid=5ff6b993-1b00-0000-facd-b36eb40b0000 pid=2996|send-data send
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-10-19 21:10:39 UTC
AV detection:
15 of 38 (39.47%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 855dc153454ecfbc18dc29fbea1d29e93be3a241b75d9c3a2fcb1321e9d4a2cb

(this sample)

  
Delivery method
Distributed via web download

Comments