MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 856afa5da4d31cc2c425228bd4f37894834fe2659119a957a796dee1b3fc3fac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 856afa5da4d31cc2c425228bd4f37894834fe2659119a957a796dee1b3fc3fac
SHA3-384 hash: 91ab89b613046561bd06ee962953eb16a8b15890af0535f6aeffc1cc52dd85de584b9aaa9f4c3313918434cecc1581ea
SHA1 hash: 604b9e2c3c6b272a9082fcd5fb7886eb1c38d881
MD5 hash: fcfd7d0d99957e88640d3bb41df23c5e
humanhash: triple-march-eleven-spring
File name:p
Download: download sample
Signature Mirai
File size:830 bytes
First seen:2026-06-07 08:00:37 UTC
Last seen:2026-06-07 19:27:47 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:dOXOsYxcysE+vhCFN0zvy/RQvZowHkaqIx2FOI1HvVPs6IJGbAIybeRFIoGauD:kXCKysE2hi0ziQvZohaq5o69H1Mqjy7
TLSH T13301AFCDC013D6604289DCAE27EB61C07421C3CB15564BF87F9C543DDB69B48B065F84
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/U8F1cccafa115636781e60fab004bd5192b150fc8fa11cf5d5cac38349d9b702f92 Miraielf ua-wget
http://188.132.232.81/gsUn/an/aelf ua-wget
http://188.132.232.81/4qo5n/an/aelf ua-wget
http://188.132.232.81/Y2Jtn/an/aelf ua-wget
http://188.132.232.81/e3G271edf373744cdabfe017a9f12c18311e68569c59311bf27aeff538107d15f7c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-07T05:07:00Z UTC
Last seen:
2026-06-07T05:07:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c2276ffe-1600-0000-d3ab-d4f4e20e0000 pid=3810 /usr/bin/sudo guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811 /tmp/sample.bin write-file guuid=c2276ffe-1600-0000-d3ab-d4f4e20e0000 pid=3810->guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811 execve guuid=8d3d6702-1700-0000-d3ab-d4f4e60e0000 pid=3814 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=8d3d6702-1700-0000-d3ab-d4f4e60e0000 pid=3814 execve guuid=a8221503-1700-0000-d3ab-d4f4e70e0000 pid=3815 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a8221503-1700-0000-d3ab-d4f4e70e0000 pid=3815 execve guuid=ad5ea003-1700-0000-d3ab-d4f4ea0e0000 pid=3818 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ad5ea003-1700-0000-d3ab-d4f4ea0e0000 pid=3818 execve guuid=0f421904-1700-0000-d3ab-d4f4ec0e0000 pid=3820 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0f421904-1700-0000-d3ab-d4f4ec0e0000 pid=3820 execve guuid=2bc99304-1700-0000-d3ab-d4f4ef0e0000 pid=3823 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=2bc99304-1700-0000-d3ab-d4f4ef0e0000 pid=3823 execve guuid=477a1a05-1700-0000-d3ab-d4f4f10e0000 pid=3825 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=477a1a05-1700-0000-d3ab-d4f4f10e0000 pid=3825 execve guuid=fb993706-1700-0000-d3ab-d4f4f60e0000 pid=3830 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=fb993706-1700-0000-d3ab-d4f4f60e0000 pid=3830 execve guuid=28c3b506-1700-0000-d3ab-d4f4fa0e0000 pid=3834 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=28c3b506-1700-0000-d3ab-d4f4fa0e0000 pid=3834 execve guuid=8ef63007-1700-0000-d3ab-d4f4fe0e0000 pid=3838 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=8ef63007-1700-0000-d3ab-d4f4fe0e0000 pid=3838 execve guuid=f86ab707-1700-0000-d3ab-d4f4000f0000 pid=3840 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=f86ab707-1700-0000-d3ab-d4f4000f0000 pid=3840 execve guuid=a07d3b08-1700-0000-d3ab-d4f4030f0000 pid=3843 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a07d3b08-1700-0000-d3ab-d4f4030f0000 pid=3843 execve guuid=5c46b608-1700-0000-d3ab-d4f4070f0000 pid=3847 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=5c46b608-1700-0000-d3ab-d4f4070f0000 pid=3847 execve guuid=77fb3909-1700-0000-d3ab-d4f40a0f0000 pid=3850 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=77fb3909-1700-0000-d3ab-d4f40a0f0000 pid=3850 execve guuid=11a9bf09-1700-0000-d3ab-d4f40c0f0000 pid=3852 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=11a9bf09-1700-0000-d3ab-d4f40c0f0000 pid=3852 execve guuid=2953470a-1700-0000-d3ab-d4f40f0f0000 pid=3855 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=2953470a-1700-0000-d3ab-d4f40f0f0000 pid=3855 execve guuid=bc89c40a-1700-0000-d3ab-d4f4110f0000 pid=3857 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=bc89c40a-1700-0000-d3ab-d4f4110f0000 pid=3857 execve guuid=1ea34e0b-1700-0000-d3ab-d4f4140f0000 pid=3860 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1ea34e0b-1700-0000-d3ab-d4f4140f0000 pid=3860 execve guuid=23def20b-1700-0000-d3ab-d4f4180f0000 pid=3864 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=23def20b-1700-0000-d3ab-d4f4180f0000 pid=3864 execve guuid=b52c700c-1700-0000-d3ab-d4f41c0f0000 pid=3868 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=b52c700c-1700-0000-d3ab-d4f41c0f0000 pid=3868 execve guuid=0ed3e40c-1700-0000-d3ab-d4f41e0f0000 pid=3870 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0ed3e40c-1700-0000-d3ab-d4f41e0f0000 pid=3870 execve guuid=1a5b530d-1700-0000-d3ab-d4f4200f0000 pid=3872 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1a5b530d-1700-0000-d3ab-d4f4200f0000 pid=3872 execve guuid=8900c10d-1700-0000-d3ab-d4f4230f0000 pid=3875 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=8900c10d-1700-0000-d3ab-d4f4230f0000 pid=3875 execve guuid=51bf1f0e-1700-0000-d3ab-d4f4250f0000 pid=3877 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=51bf1f0e-1700-0000-d3ab-d4f4250f0000 pid=3877 execve guuid=d2c6960e-1700-0000-d3ab-d4f4280f0000 pid=3880 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d2c6960e-1700-0000-d3ab-d4f4280f0000 pid=3880 execve guuid=380c080f-1700-0000-d3ab-d4f42a0f0000 pid=3882 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=380c080f-1700-0000-d3ab-d4f42a0f0000 pid=3882 execve guuid=ee00800f-1700-0000-d3ab-d4f42e0f0000 pid=3886 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ee00800f-1700-0000-d3ab-d4f42e0f0000 pid=3886 execve guuid=94bff50f-1700-0000-d3ab-d4f4300f0000 pid=3888 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=94bff50f-1700-0000-d3ab-d4f4300f0000 pid=3888 execve guuid=f6636a10-1700-0000-d3ab-d4f4330f0000 pid=3891 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=f6636a10-1700-0000-d3ab-d4f4330f0000 pid=3891 execve guuid=5588dc10-1700-0000-d3ab-d4f4360f0000 pid=3894 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=5588dc10-1700-0000-d3ab-d4f4360f0000 pid=3894 execve guuid=e5cf5511-1700-0000-d3ab-d4f43a0f0000 pid=3898 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e5cf5511-1700-0000-d3ab-d4f43a0f0000 pid=3898 execve guuid=a721e811-1700-0000-d3ab-d4f43e0f0000 pid=3902 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a721e811-1700-0000-d3ab-d4f43e0f0000 pid=3902 execve guuid=6f708a12-1700-0000-d3ab-d4f4400f0000 pid=3904 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6f708a12-1700-0000-d3ab-d4f4400f0000 pid=3904 execve guuid=1d791113-1700-0000-d3ab-d4f4430f0000 pid=3907 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1d791113-1700-0000-d3ab-d4f4430f0000 pid=3907 execve guuid=b2b29513-1700-0000-d3ab-d4f4450f0000 pid=3909 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=b2b29513-1700-0000-d3ab-d4f4450f0000 pid=3909 execve guuid=e16c1314-1700-0000-d3ab-d4f4480f0000 pid=3912 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e16c1314-1700-0000-d3ab-d4f4480f0000 pid=3912 execve guuid=008d9814-1700-0000-d3ab-d4f44c0f0000 pid=3916 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=008d9814-1700-0000-d3ab-d4f44c0f0000 pid=3916 execve guuid=c7861015-1700-0000-d3ab-d4f44f0f0000 pid=3919 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c7861015-1700-0000-d3ab-d4f44f0f0000 pid=3919 execve guuid=70d59715-1700-0000-d3ab-d4f4520f0000 pid=3922 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=70d59715-1700-0000-d3ab-d4f4520f0000 pid=3922 execve guuid=9dcd1b16-1700-0000-d3ab-d4f4540f0000 pid=3924 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=9dcd1b16-1700-0000-d3ab-d4f4540f0000 pid=3924 execve guuid=3fdc9e16-1700-0000-d3ab-d4f4580f0000 pid=3928 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3fdc9e16-1700-0000-d3ab-d4f4580f0000 pid=3928 execve guuid=80831b17-1700-0000-d3ab-d4f45c0f0000 pid=3932 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=80831b17-1700-0000-d3ab-d4f45c0f0000 pid=3932 execve guuid=14d89617-1700-0000-d3ab-d4f45e0f0000 pid=3934 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=14d89617-1700-0000-d3ab-d4f45e0f0000 pid=3934 execve guuid=44df1318-1700-0000-d3ab-d4f4610f0000 pid=3937 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=44df1318-1700-0000-d3ab-d4f4610f0000 pid=3937 execve guuid=e73b8d18-1700-0000-d3ab-d4f4640f0000 pid=3940 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e73b8d18-1700-0000-d3ab-d4f4640f0000 pid=3940 execve guuid=0e480119-1700-0000-d3ab-d4f4660f0000 pid=3942 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0e480119-1700-0000-d3ab-d4f4660f0000 pid=3942 execve guuid=aa787b19-1700-0000-d3ab-d4f4690f0000 pid=3945 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=aa787b19-1700-0000-d3ab-d4f4690f0000 pid=3945 execve guuid=2258f219-1700-0000-d3ab-d4f46a0f0000 pid=3946 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=2258f219-1700-0000-d3ab-d4f46a0f0000 pid=3946 execve guuid=e947691a-1700-0000-d3ab-d4f46c0f0000 pid=3948 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e947691a-1700-0000-d3ab-d4f46c0f0000 pid=3948 execve guuid=9c3ad51a-1700-0000-d3ab-d4f46f0f0000 pid=3951 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=9c3ad51a-1700-0000-d3ab-d4f46f0f0000 pid=3951 execve guuid=36632f1b-1700-0000-d3ab-d4f4710f0000 pid=3953 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=36632f1b-1700-0000-d3ab-d4f4710f0000 pid=3953 execve guuid=4d59821b-1700-0000-d3ab-d4f4740f0000 pid=3956 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=4d59821b-1700-0000-d3ab-d4f4740f0000 pid=3956 execve guuid=a2e5e01b-1700-0000-d3ab-d4f4750f0000 pid=3957 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a2e5e01b-1700-0000-d3ab-d4f4750f0000 pid=3957 execve guuid=71594a1c-1700-0000-d3ab-d4f4790f0000 pid=3961 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=71594a1c-1700-0000-d3ab-d4f4790f0000 pid=3961 execve guuid=39a59e1c-1700-0000-d3ab-d4f47c0f0000 pid=3964 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=39a59e1c-1700-0000-d3ab-d4f47c0f0000 pid=3964 execve guuid=de160f1d-1700-0000-d3ab-d4f4800f0000 pid=3968 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=de160f1d-1700-0000-d3ab-d4f4800f0000 pid=3968 execve guuid=98f1721d-1700-0000-d3ab-d4f4820f0000 pid=3970 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=98f1721d-1700-0000-d3ab-d4f4820f0000 pid=3970 execve guuid=143fd01d-1700-0000-d3ab-d4f4860f0000 pid=3974 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=143fd01d-1700-0000-d3ab-d4f4860f0000 pid=3974 execve guuid=68631d1e-1700-0000-d3ab-d4f48a0f0000 pid=3978 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=68631d1e-1700-0000-d3ab-d4f48a0f0000 pid=3978 execve guuid=6ef0771e-1700-0000-d3ab-d4f48c0f0000 pid=3980 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6ef0771e-1700-0000-d3ab-d4f48c0f0000 pid=3980 execve guuid=3780ca1e-1700-0000-d3ab-d4f48e0f0000 pid=3982 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3780ca1e-1700-0000-d3ab-d4f48e0f0000 pid=3982 execve guuid=6032191f-1700-0000-d3ab-d4f4920f0000 pid=3986 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6032191f-1700-0000-d3ab-d4f4920f0000 pid=3986 execve guuid=873f711f-1700-0000-d3ab-d4f4950f0000 pid=3989 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=873f711f-1700-0000-d3ab-d4f4950f0000 pid=3989 execve guuid=3368c81f-1700-0000-d3ab-d4f4970f0000 pid=3991 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3368c81f-1700-0000-d3ab-d4f4970f0000 pid=3991 execve guuid=73eb1520-1700-0000-d3ab-d4f49a0f0000 pid=3994 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=73eb1520-1700-0000-d3ab-d4f49a0f0000 pid=3994 execve guuid=ef4f6420-1700-0000-d3ab-d4f49d0f0000 pid=3997 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ef4f6420-1700-0000-d3ab-d4f49d0f0000 pid=3997 execve guuid=b04bcb20-1700-0000-d3ab-d4f49f0f0000 pid=3999 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=b04bcb20-1700-0000-d3ab-d4f49f0f0000 pid=3999 execve guuid=a2842721-1700-0000-d3ab-d4f4a10f0000 pid=4001 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a2842721-1700-0000-d3ab-d4f4a10f0000 pid=4001 execve guuid=ed848921-1700-0000-d3ab-d4f4a40f0000 pid=4004 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ed848921-1700-0000-d3ab-d4f4a40f0000 pid=4004 execve guuid=1fc5e921-1700-0000-d3ab-d4f4a60f0000 pid=4006 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1fc5e921-1700-0000-d3ab-d4f4a60f0000 pid=4006 execve guuid=044d4922-1700-0000-d3ab-d4f4a90f0000 pid=4009 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=044d4922-1700-0000-d3ab-d4f4a90f0000 pid=4009 execve guuid=ba78a822-1700-0000-d3ab-d4f4ab0f0000 pid=4011 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ba78a822-1700-0000-d3ab-d4f4ab0f0000 pid=4011 execve guuid=a8060323-1700-0000-d3ab-d4f4ae0f0000 pid=4014 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a8060323-1700-0000-d3ab-d4f4ae0f0000 pid=4014 execve guuid=41d35923-1700-0000-d3ab-d4f4b10f0000 pid=4017 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=41d35923-1700-0000-d3ab-d4f4b10f0000 pid=4017 execve guuid=488baf23-1700-0000-d3ab-d4f4b60f0000 pid=4022 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=488baf23-1700-0000-d3ab-d4f4b60f0000 pid=4022 execve guuid=eb070224-1700-0000-d3ab-d4f4b70f0000 pid=4023 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=eb070224-1700-0000-d3ab-d4f4b70f0000 pid=4023 execve guuid=14c15a24-1700-0000-d3ab-d4f4bb0f0000 pid=4027 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=14c15a24-1700-0000-d3ab-d4f4bb0f0000 pid=4027 execve guuid=d62fb024-1700-0000-d3ab-d4f4bf0f0000 pid=4031 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d62fb024-1700-0000-d3ab-d4f4bf0f0000 pid=4031 execve guuid=3f180625-1700-0000-d3ab-d4f4c10f0000 pid=4033 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3f180625-1700-0000-d3ab-d4f4c10f0000 pid=4033 execve guuid=c3aa5a25-1700-0000-d3ab-d4f4c30f0000 pid=4035 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c3aa5a25-1700-0000-d3ab-d4f4c30f0000 pid=4035 execve guuid=32bfb325-1700-0000-d3ab-d4f4c60f0000 pid=4038 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=32bfb325-1700-0000-d3ab-d4f4c60f0000 pid=4038 execve guuid=96eb0926-1700-0000-d3ab-d4f4c80f0000 pid=4040 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=96eb0926-1700-0000-d3ab-d4f4c80f0000 pid=4040 execve guuid=c9395c26-1700-0000-d3ab-d4f4cb0f0000 pid=4043 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c9395c26-1700-0000-d3ab-d4f4cb0f0000 pid=4043 execve guuid=b038b226-1700-0000-d3ab-d4f4cd0f0000 pid=4045 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=b038b226-1700-0000-d3ab-d4f4cd0f0000 pid=4045 execve guuid=76ce0427-1700-0000-d3ab-d4f4d10f0000 pid=4049 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=76ce0427-1700-0000-d3ab-d4f4d10f0000 pid=4049 execve guuid=a4c15b27-1700-0000-d3ab-d4f4d40f0000 pid=4052 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a4c15b27-1700-0000-d3ab-d4f4d40f0000 pid=4052 execve guuid=5b86b627-1700-0000-d3ab-d4f4d60f0000 pid=4054 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=5b86b627-1700-0000-d3ab-d4f4d60f0000 pid=4054 execve guuid=726c2628-1700-0000-d3ab-d4f4d90f0000 pid=4057 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=726c2628-1700-0000-d3ab-d4f4d90f0000 pid=4057 execve guuid=71418428-1700-0000-d3ab-d4f4dc0f0000 pid=4060 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=71418428-1700-0000-d3ab-d4f4dc0f0000 pid=4060 execve guuid=c8cfe928-1700-0000-d3ab-d4f4de0f0000 pid=4062 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c8cfe928-1700-0000-d3ab-d4f4de0f0000 pid=4062 execve guuid=6c9d5729-1700-0000-d3ab-d4f4e10f0000 pid=4065 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6c9d5729-1700-0000-d3ab-d4f4e10f0000 pid=4065 execve guuid=f4ebc029-1700-0000-d3ab-d4f4e30f0000 pid=4067 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=f4ebc029-1700-0000-d3ab-d4f4e30f0000 pid=4067 execve guuid=81592e2a-1700-0000-d3ab-d4f4e70f0000 pid=4071 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=81592e2a-1700-0000-d3ab-d4f4e70f0000 pid=4071 execve guuid=1e508c2a-1700-0000-d3ab-d4f4eb0f0000 pid=4075 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1e508c2a-1700-0000-d3ab-d4f4eb0f0000 pid=4075 execve guuid=2b0fe62a-1700-0000-d3ab-d4f4ed0f0000 pid=4077 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=2b0fe62a-1700-0000-d3ab-d4f4ed0f0000 pid=4077 execve guuid=44b3412b-1700-0000-d3ab-d4f4ef0f0000 pid=4079 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=44b3412b-1700-0000-d3ab-d4f4ef0f0000 pid=4079 execve guuid=8b049c2b-1700-0000-d3ab-d4f4f30f0000 pid=4083 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=8b049c2b-1700-0000-d3ab-d4f4f30f0000 pid=4083 execve guuid=ec09032c-1700-0000-d3ab-d4f4f70f0000 pid=4087 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ec09032c-1700-0000-d3ab-d4f4f70f0000 pid=4087 execve guuid=d33d632c-1700-0000-d3ab-d4f4f90f0000 pid=4089 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d33d632c-1700-0000-d3ab-d4f4f90f0000 pid=4089 execve guuid=e12abb2c-1700-0000-d3ab-d4f4fc0f0000 pid=4092 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e12abb2c-1700-0000-d3ab-d4f4fc0f0000 pid=4092 execve guuid=d3de172d-1700-0000-d3ab-d4f4fe0f0000 pid=4094 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d3de172d-1700-0000-d3ab-d4f4fe0f0000 pid=4094 execve guuid=3b65782d-1700-0000-d3ab-d4f401100000 pid=4097 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3b65782d-1700-0000-d3ab-d4f401100000 pid=4097 execve guuid=a8f1d22d-1700-0000-d3ab-d4f403100000 pid=4099 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a8f1d22d-1700-0000-d3ab-d4f403100000 pid=4099 execve guuid=c1c0272e-1700-0000-d3ab-d4f405100000 pid=4101 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c1c0272e-1700-0000-d3ab-d4f405100000 pid=4101 execve guuid=da4c7a2e-1700-0000-d3ab-d4f409100000 pid=4105 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=da4c7a2e-1700-0000-d3ab-d4f409100000 pid=4105 execve guuid=e43fcd2e-1700-0000-d3ab-d4f40d100000 pid=4109 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=e43fcd2e-1700-0000-d3ab-d4f40d100000 pid=4109 execve guuid=ead6372f-1700-0000-d3ab-d4f40f100000 pid=4111 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=ead6372f-1700-0000-d3ab-d4f40f100000 pid=4111 execve guuid=d20d912f-1700-0000-d3ab-d4f412100000 pid=4114 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d20d912f-1700-0000-d3ab-d4f412100000 pid=4114 execve guuid=eb83e42f-1700-0000-d3ab-d4f414100000 pid=4116 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=eb83e42f-1700-0000-d3ab-d4f414100000 pid=4116 execve guuid=08aa3c30-1700-0000-d3ab-d4f416100000 pid=4118 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=08aa3c30-1700-0000-d3ab-d4f416100000 pid=4118 execve guuid=8c4b9230-1700-0000-d3ab-d4f419100000 pid=4121 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=8c4b9230-1700-0000-d3ab-d4f419100000 pid=4121 execve guuid=6bfeeb30-1700-0000-d3ab-d4f41b100000 pid=4123 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6bfeeb30-1700-0000-d3ab-d4f41b100000 pid=4123 execve guuid=d5504231-1700-0000-d3ab-d4f41f100000 pid=4127 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=d5504231-1700-0000-d3ab-d4f41f100000 pid=4127 execve guuid=f9ba9931-1700-0000-d3ab-d4f423100000 pid=4131 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=f9ba9931-1700-0000-d3ab-d4f423100000 pid=4131 execve guuid=c310f731-1700-0000-d3ab-d4f425100000 pid=4133 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=c310f731-1700-0000-d3ab-d4f425100000 pid=4133 execve guuid=02865232-1700-0000-d3ab-d4f427100000 pid=4135 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=02865232-1700-0000-d3ab-d4f427100000 pid=4135 execve guuid=a2a8ab32-1700-0000-d3ab-d4f42b100000 pid=4139 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=a2a8ab32-1700-0000-d3ab-d4f42b100000 pid=4139 execve guuid=1bda3733-1700-0000-d3ab-d4f42f100000 pid=4143 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1bda3733-1700-0000-d3ab-d4f42f100000 pid=4143 execve guuid=6fedcc33-1700-0000-d3ab-d4f433100000 pid=4147 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=6fedcc33-1700-0000-d3ab-d4f433100000 pid=4147 execve guuid=56c02934-1700-0000-d3ab-d4f435100000 pid=4149 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=56c02934-1700-0000-d3ab-d4f435100000 pid=4149 execve guuid=1335b534-1700-0000-d3ab-d4f438100000 pid=4152 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1335b534-1700-0000-d3ab-d4f438100000 pid=4152 execve guuid=32153e35-1700-0000-d3ab-d4f43b100000 pid=4155 /usr/bin/ls guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=32153e35-1700-0000-d3ab-d4f43b100000 pid=4155 execve guuid=9a569735-1700-0000-d3ab-d4f43d100000 pid=4157 /usr/bin/rm guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=9a569735-1700-0000-d3ab-d4f43d100000 pid=4157 execve guuid=09b4ce35-1700-0000-d3ab-d4f441100000 pid=4161 /usr/bin/wget net send-data write-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=09b4ce35-1700-0000-d3ab-d4f441100000 pid=4161 execve guuid=44f9599f-1800-0000-d3ab-d4f438140000 pid=5176 /usr/bin/chmod guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=44f9599f-1800-0000-d3ab-d4f438140000 pid=5176 execve guuid=3c9bd19f-1800-0000-d3ab-d4f43a140000 pid=5178 /usr/bin/dash guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3c9bd19f-1800-0000-d3ab-d4f43a140000 pid=5178 clone guuid=532a06a1-1800-0000-d3ab-d4f43d140000 pid=5181 /usr/bin/rm guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=532a06a1-1800-0000-d3ab-d4f43d140000 pid=5181 execve guuid=08577ba1-1800-0000-d3ab-d4f43f140000 pid=5183 /usr/bin/wget net send-data write-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=08577ba1-1800-0000-d3ab-d4f43f140000 pid=5183 execve guuid=0f4e1f8c-1900-0000-d3ab-d4f4e5140000 pid=5349 /usr/bin/chmod guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0f4e1f8c-1900-0000-d3ab-d4f4e5140000 pid=5349 execve guuid=1eb7798c-1900-0000-d3ab-d4f4e6140000 pid=5350 /usr/bin/dash guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1eb7798c-1900-0000-d3ab-d4f4e6140000 pid=5350 clone guuid=92af3e8d-1900-0000-d3ab-d4f4e8140000 pid=5352 /usr/bin/rm guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=92af3e8d-1900-0000-d3ab-d4f4e8140000 pid=5352 execve guuid=3088a48d-1900-0000-d3ab-d4f4e9140000 pid=5353 /usr/bin/wget net send-data write-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=3088a48d-1900-0000-d3ab-d4f4e9140000 pid=5353 execve guuid=1e00185e-1a00-0000-d3ab-d4f4f1140000 pid=5361 /usr/bin/chmod guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=1e00185e-1a00-0000-d3ab-d4f4f1140000 pid=5361 execve guuid=355f555e-1a00-0000-d3ab-d4f4f2140000 pid=5362 /usr/bin/dash guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=355f555e-1a00-0000-d3ab-d4f4f2140000 pid=5362 clone guuid=0a6be55e-1a00-0000-d3ab-d4f4f4140000 pid=5364 /usr/bin/rm guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0a6be55e-1a00-0000-d3ab-d4f4f4140000 pid=5364 execve guuid=75681a5f-1a00-0000-d3ab-d4f4f5140000 pid=5365 /usr/bin/wget net send-data write-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=75681a5f-1a00-0000-d3ab-d4f4f5140000 pid=5365 execve guuid=41c9d0e9-1a00-0000-d3ab-d4f412150000 pid=5394 /usr/bin/chmod guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=41c9d0e9-1a00-0000-d3ab-d4f412150000 pid=5394 execve guuid=71c323ea-1a00-0000-d3ab-d4f414150000 pid=5396 /usr/bin/dash guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=71c323ea-1a00-0000-d3ab-d4f414150000 pid=5396 clone guuid=9e4ab8ea-1a00-0000-d3ab-d4f417150000 pid=5399 /usr/bin/rm guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=9e4ab8ea-1a00-0000-d3ab-d4f417150000 pid=5399 execve guuid=887b20eb-1a00-0000-d3ab-d4f419150000 pid=5401 /usr/bin/wget net send-data write-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=887b20eb-1a00-0000-d3ab-d4f419150000 pid=5401 execve guuid=44c66b25-1b00-0000-d3ab-d4f41b150000 pid=5403 /usr/bin/chmod guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=44c66b25-1b00-0000-d3ab-d4f41b150000 pid=5403 execve guuid=0f3df125-1b00-0000-d3ab-d4f41c150000 pid=5404 /usr/bin/dash guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=0f3df125-1b00-0000-d3ab-d4f41c150000 pid=5404 clone guuid=79a63b27-1b00-0000-d3ab-d4f41e150000 pid=5406 /usr/bin/rm delete-file guuid=dde31602-1700-0000-d3ab-d4f4e30e0000 pid=3811->guuid=79a63b27-1b00-0000-d3ab-d4f41e150000 pid=5406 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=09b4ce35-1700-0000-d3ab-d4f441100000 pid=4161->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=08577ba1-1800-0000-d3ab-d4f43f140000 pid=5183->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=3088a48d-1900-0000-d3ab-d4f4e9140000 pid=5353->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=75681a5f-1a00-0000-d3ab-d4f4f5140000 pid=5365->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=887b20eb-1a00-0000-d3ab-d4f419150000 pid=5401->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-07 08:01:46 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 856afa5da4d31cc2c425228bd4f37894834fe2659119a957a796dee1b3fc3fac

(this sample)

  
Delivery method
Distributed via web download

Comments