MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 874a06388ef6532595962a7d25418b60da0559560a5f296a00ca3fc7846718bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 874a06388ef6532595962a7d25418b60da0559560a5f296a00ca3fc7846718bf
SHA3-384 hash: 981cfa91694f6ac64d2dcfb7badb99e6c1bbb47be381251d67996039eb492d70c2f42b93e9b6dc17875a43dcdd77aee9
SHA1 hash: bb67cc17ef08db160c3ebb21e60e21062ae0e293
MD5 hash: 863ceee8a3825046ded89f512fabb719
humanhash: yellow-tennessee-single-lamp
File name:jaws.sh
Download: download sample
Signature Mirai
File size:1'630 bytes
First seen:2025-08-10 05:40:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:I9dprQkLrHObNI7LkgLCqKgSgay97oNsf5i6YithnnzG6utb:SdtBrHRL5LCq3fayJoNIPvnzG6ub
TLSH T15631CCCE991062120DCDEE29B3B6F8895019C5D721D30E6BDD89A43BCACFA44718FF14
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.11.62.4/armn/an/aMozi
http://141.11.62.4/arm5n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/arm6n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/arm7n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/i586n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/m68kn/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/mipsn/an/aMozi
http://141.11.62.4/mpsln/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/ppcn/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/sh4n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/spcn/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/x86_64n/an/aelf geofenced GorillaBotnet ua-wget USA
http://141.11.62.4/x86n/an/aMozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=33cef8df-1800-0000-f7ed-50dd3c0d0000 pid=3388 /usr/bin/sudo guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395 /tmp/sample.bin guuid=33cef8df-1800-0000-f7ed-50dd3c0d0000 pid=3388->guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395 execve guuid=a87404e2-1800-0000-f7ed-50dd450d0000 pid=3397 /usr/bin/cp guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=a87404e2-1800-0000-f7ed-50dd450d0000 pid=3397 execve guuid=985f96e9-1800-0000-f7ed-50dd5c0d0000 pid=3420 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=985f96e9-1800-0000-f7ed-50dd5c0d0000 pid=3420 execve guuid=5426a3ef-1800-0000-f7ed-50dd6f0d0000 pid=3439 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5426a3ef-1800-0000-f7ed-50dd6f0d0000 pid=3439 execve guuid=c081ab03-1900-0000-f7ed-50dda10d0000 pid=3489 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c081ab03-1900-0000-f7ed-50dda10d0000 pid=3489 execve guuid=9da32704-1900-0000-f7ed-50dda20d0000 pid=3490 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=9da32704-1900-0000-f7ed-50dda20d0000 pid=3490 clone guuid=c5680905-1900-0000-f7ed-50dda40d0000 pid=3492 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c5680905-1900-0000-f7ed-50dda40d0000 pid=3492 execve guuid=5d186b05-1900-0000-f7ed-50dda50d0000 pid=3493 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5d186b05-1900-0000-f7ed-50dda50d0000 pid=3493 execve guuid=25894b09-1900-0000-f7ed-50dda90d0000 pid=3497 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=25894b09-1900-0000-f7ed-50dda90d0000 pid=3497 execve guuid=c8aa3d0f-1900-0000-f7ed-50ddb40d0000 pid=3508 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c8aa3d0f-1900-0000-f7ed-50ddb40d0000 pid=3508 execve guuid=df55a00f-1900-0000-f7ed-50ddb50d0000 pid=3509 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=df55a00f-1900-0000-f7ed-50ddb50d0000 pid=3509 clone guuid=5226fc10-1900-0000-f7ed-50ddb70d0000 pid=3511 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5226fc10-1900-0000-f7ed-50ddb70d0000 pid=3511 execve guuid=3643df12-1900-0000-f7ed-50ddb80d0000 pid=3512 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=3643df12-1900-0000-f7ed-50ddb80d0000 pid=3512 execve guuid=77797a16-1900-0000-f7ed-50ddc00d0000 pid=3520 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=77797a16-1900-0000-f7ed-50ddc00d0000 pid=3520 execve guuid=4c511c1c-1900-0000-f7ed-50ddc90d0000 pid=3529 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=4c511c1c-1900-0000-f7ed-50ddc90d0000 pid=3529 execve guuid=9dd9951c-1900-0000-f7ed-50ddcb0d0000 pid=3531 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=9dd9951c-1900-0000-f7ed-50ddcb0d0000 pid=3531 clone guuid=71d1491d-1900-0000-f7ed-50ddcf0d0000 pid=3535 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=71d1491d-1900-0000-f7ed-50ddcf0d0000 pid=3535 execve guuid=43d2a71f-1900-0000-f7ed-50ddd10d0000 pid=3537 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=43d2a71f-1900-0000-f7ed-50ddd10d0000 pid=3537 execve guuid=833a6d23-1900-0000-f7ed-50ddd80d0000 pid=3544 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=833a6d23-1900-0000-f7ed-50ddd80d0000 pid=3544 execve guuid=c8d3d22a-1900-0000-f7ed-50dded0d0000 pid=3565 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c8d3d22a-1900-0000-f7ed-50dded0d0000 pid=3565 execve guuid=1975232b-1900-0000-f7ed-50ddee0d0000 pid=3566 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=1975232b-1900-0000-f7ed-50ddee0d0000 pid=3566 clone guuid=5e0d612d-1900-0000-f7ed-50ddf60d0000 pid=3574 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5e0d612d-1900-0000-f7ed-50ddf60d0000 pid=3574 execve guuid=4727d430-1900-0000-f7ed-50ddfe0d0000 pid=3582 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=4727d430-1900-0000-f7ed-50ddfe0d0000 pid=3582 execve guuid=ce668534-1900-0000-f7ed-50dd070e0000 pid=3591 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=ce668534-1900-0000-f7ed-50dd070e0000 pid=3591 execve guuid=57eb643b-1900-0000-f7ed-50dd190e0000 pid=3609 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=57eb643b-1900-0000-f7ed-50dd190e0000 pid=3609 execve guuid=5e67bf3b-1900-0000-f7ed-50dd1a0e0000 pid=3610 /tmp/i586 delete-file net guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5e67bf3b-1900-0000-f7ed-50dd1a0e0000 pid=3610 execve guuid=53150c3d-1900-0000-f7ed-50dd1d0e0000 pid=3613 /usr/bin/rm guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=53150c3d-1900-0000-f7ed-50dd1d0e0000 pid=3613 execve guuid=138ca83d-1900-0000-f7ed-50dd1e0e0000 pid=3614 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=138ca83d-1900-0000-f7ed-50dd1e0e0000 pid=3614 execve guuid=c5c18b41-1900-0000-f7ed-50dd270e0000 pid=3623 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c5c18b41-1900-0000-f7ed-50dd270e0000 pid=3623 execve guuid=8f0fc046-1900-0000-f7ed-50dd320e0000 pid=3634 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=8f0fc046-1900-0000-f7ed-50dd320e0000 pid=3634 execve guuid=feea3047-1900-0000-f7ed-50dd340e0000 pid=3636 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=feea3047-1900-0000-f7ed-50dd340e0000 pid=3636 clone guuid=ed138048-1900-0000-f7ed-50dd3a0e0000 pid=3642 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=ed138048-1900-0000-f7ed-50dd3a0e0000 pid=3642 execve guuid=824bf748-1900-0000-f7ed-50dd3c0e0000 pid=3644 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=824bf748-1900-0000-f7ed-50dd3c0e0000 pid=3644 execve guuid=81f7544c-1900-0000-f7ed-50dd4b0e0000 pid=3659 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=81f7544c-1900-0000-f7ed-50dd4b0e0000 pid=3659 execve guuid=6850a653-1900-0000-f7ed-50dd5e0e0000 pid=3678 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=6850a653-1900-0000-f7ed-50dd5e0e0000 pid=3678 execve guuid=1ca5e653-1900-0000-f7ed-50dd5f0e0000 pid=3679 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=1ca5e653-1900-0000-f7ed-50dd5f0e0000 pid=3679 clone guuid=3c486c54-1900-0000-f7ed-50dd620e0000 pid=3682 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=3c486c54-1900-0000-f7ed-50dd620e0000 pid=3682 execve guuid=eeae3855-1900-0000-f7ed-50dd660e0000 pid=3686 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=eeae3855-1900-0000-f7ed-50dd660e0000 pid=3686 execve guuid=bebcb058-1900-0000-f7ed-50dd730e0000 pid=3699 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=bebcb058-1900-0000-f7ed-50dd730e0000 pid=3699 execve guuid=c8b9db5d-1900-0000-f7ed-50dd770e0000 pid=3703 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c8b9db5d-1900-0000-f7ed-50dd770e0000 pid=3703 execve guuid=d0033a5e-1900-0000-f7ed-50dd780e0000 pid=3704 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=d0033a5e-1900-0000-f7ed-50dd780e0000 pid=3704 clone guuid=b33bb55f-1900-0000-f7ed-50dd7a0e0000 pid=3706 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=b33bb55f-1900-0000-f7ed-50dd7a0e0000 pid=3706 execve guuid=2e577063-1900-0000-f7ed-50dd7e0e0000 pid=3710 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=2e577063-1900-0000-f7ed-50dd7e0e0000 pid=3710 execve guuid=fc8c0a67-1900-0000-f7ed-50dd880e0000 pid=3720 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=fc8c0a67-1900-0000-f7ed-50dd880e0000 pid=3720 execve guuid=10eaec6b-1900-0000-f7ed-50dd8d0e0000 pid=3725 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=10eaec6b-1900-0000-f7ed-50dd8d0e0000 pid=3725 execve guuid=64c6696c-1900-0000-f7ed-50dd900e0000 pid=3728 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=64c6696c-1900-0000-f7ed-50dd900e0000 pid=3728 clone guuid=af85d96e-1900-0000-f7ed-50dd950e0000 pid=3733 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=af85d96e-1900-0000-f7ed-50dd950e0000 pid=3733 execve guuid=6557716f-1900-0000-f7ed-50dd980e0000 pid=3736 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=6557716f-1900-0000-f7ed-50dd980e0000 pid=3736 execve guuid=09587572-1900-0000-f7ed-50dd9e0e0000 pid=3742 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=09587572-1900-0000-f7ed-50dd9e0e0000 pid=3742 execve guuid=9ba34676-1900-0000-f7ed-50ddab0e0000 pid=3755 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=9ba34676-1900-0000-f7ed-50ddab0e0000 pid=3755 execve guuid=4997b276-1900-0000-f7ed-50ddad0e0000 pid=3757 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=4997b276-1900-0000-f7ed-50ddad0e0000 pid=3757 clone guuid=e5606777-1900-0000-f7ed-50ddb20e0000 pid=3762 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=e5606777-1900-0000-f7ed-50ddb20e0000 pid=3762 execve guuid=652f9978-1900-0000-f7ed-50ddb80e0000 pid=3768 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=652f9978-1900-0000-f7ed-50ddb80e0000 pid=3768 execve guuid=3534c37c-1900-0000-f7ed-50ddc70e0000 pid=3783 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=3534c37c-1900-0000-f7ed-50ddc70e0000 pid=3783 execve guuid=42b33a82-1900-0000-f7ed-50ddd90e0000 pid=3801 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=42b33a82-1900-0000-f7ed-50ddd90e0000 pid=3801 execve guuid=9cca7d82-1900-0000-f7ed-50ddda0e0000 pid=3802 /usr/bin/bash guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=9cca7d82-1900-0000-f7ed-50ddda0e0000 pid=3802 clone guuid=a7411283-1900-0000-f7ed-50dddd0e0000 pid=3805 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=a7411283-1900-0000-f7ed-50dddd0e0000 pid=3805 execve guuid=f1cb3e86-1900-0000-f7ed-50dde60e0000 pid=3814 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=f1cb3e86-1900-0000-f7ed-50dde60e0000 pid=3814 execve guuid=c01a8b8a-1900-0000-f7ed-50ddf30e0000 pid=3827 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=c01a8b8a-1900-0000-f7ed-50ddf30e0000 pid=3827 execve guuid=f57a1b90-1900-0000-f7ed-50dd0d0f0000 pid=3853 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=f57a1b90-1900-0000-f7ed-50dd0d0f0000 pid=3853 execve guuid=5ec06990-1900-0000-f7ed-50dd0f0f0000 pid=3855 /tmp/x86_64 guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=5ec06990-1900-0000-f7ed-50dd0f0f0000 pid=3855 execve guuid=af165d91-1900-0000-f7ed-50dd170f0000 pid=3863 /usr/bin/rm delete-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=af165d91-1900-0000-f7ed-50dd170f0000 pid=3863 execve guuid=6f10b291-1900-0000-f7ed-50dd190f0000 pid=3865 /usr/bin/wget net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=6f10b291-1900-0000-f7ed-50dd190f0000 pid=3865 execve guuid=1af63599-1900-0000-f7ed-50dd380f0000 pid=3896 /usr/bin/curl net send-data write-file guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=1af63599-1900-0000-f7ed-50dd380f0000 pid=3896 execve guuid=0094319e-1900-0000-f7ed-50dd510f0000 pid=3921 /usr/bin/chmod guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=0094319e-1900-0000-f7ed-50dd510f0000 pid=3921 execve guuid=22d4919e-1900-0000-f7ed-50dd540f0000 pid=3924 /tmp/x86 delete-file net guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=22d4919e-1900-0000-f7ed-50dd540f0000 pid=3924 execve guuid=a401ba9e-1900-0000-f7ed-50dd560f0000 pid=3926 /usr/bin/rm guuid=908fb0e1-1800-0000-f7ed-50dd430d0000 pid=3395->guuid=a401ba9e-1900-0000-f7ed-50dd560f0000 pid=3926 execve 2f4c6a83-4d14-5a59-8b91-657286c69cbc 141.11.62.4:80 guuid=985f96e9-1800-0000-f7ed-50dd5c0d0000 pid=3420->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 129B guuid=5426a3ef-1800-0000-f7ed-50dd6f0d0000 pid=3439->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 78B guuid=5d186b05-1900-0000-f7ed-50dda50d0000 pid=3493->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=25894b09-1900-0000-f7ed-50dda90d0000 pid=3497->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=3643df12-1900-0000-f7ed-50ddb80d0000 pid=3512->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=77797a16-1900-0000-f7ed-50ddc00d0000 pid=3520->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=43d2a71f-1900-0000-f7ed-50ddd10d0000 pid=3537->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=833a6d23-1900-0000-f7ed-50ddd80d0000 pid=3544->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=4727d430-1900-0000-f7ed-50ddfe0d0000 pid=3582->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=ce668534-1900-0000-f7ed-50dd070e0000 pid=3591->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5e67bf3b-1900-0000-f7ed-50dd1a0e0000 pid=3610->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7e16e63c-1900-0000-f7ed-50dd1b0e0000 pid=3611 /tmp/i586 guuid=5e67bf3b-1900-0000-f7ed-50dd1a0e0000 pid=3610->guuid=7e16e63c-1900-0000-f7ed-50dd1b0e0000 pid=3611 clone guuid=acdbef3c-1900-0000-f7ed-50dd1c0e0000 pid=3612 /tmp/i586 net send-data zombie guuid=5e67bf3b-1900-0000-f7ed-50dd1a0e0000 pid=3610->guuid=acdbef3c-1900-0000-f7ed-50dd1c0e0000 pid=3612 clone guuid=acdbef3c-1900-0000-f7ed-50dd1c0e0000 pid=3612->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con c41bd86a-d676-55f9-8fe7-1c41abc334fa 94.131.120.156:10024 guuid=acdbef3c-1900-0000-f7ed-50dd1c0e0000 pid=3612->c41bd86a-d676-55f9-8fe7-1c41abc334fa send: 3149B guuid=138ca83d-1900-0000-f7ed-50dd1e0e0000 pid=3614->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=c5c18b41-1900-0000-f7ed-50dd270e0000 pid=3623->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=824bf748-1900-0000-f7ed-50dd3c0e0000 pid=3644->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=81f7544c-1900-0000-f7ed-50dd4b0e0000 pid=3659->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=eeae3855-1900-0000-f7ed-50dd660e0000 pid=3686->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 130B guuid=bebcb058-1900-0000-f7ed-50dd730e0000 pid=3699->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 79B guuid=2e577063-1900-0000-f7ed-50dd7e0e0000 pid=3710->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 129B guuid=fc8c0a67-1900-0000-f7ed-50dd880e0000 pid=3720->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 78B guuid=6557716f-1900-0000-f7ed-50dd980e0000 pid=3736->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 129B guuid=09587572-1900-0000-f7ed-50dd9e0e0000 pid=3742->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 78B guuid=652f9978-1900-0000-f7ed-50ddb80e0000 pid=3768->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 129B guuid=3534c37c-1900-0000-f7ed-50ddc70e0000 pid=3783->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 78B guuid=f1cb3e86-1900-0000-f7ed-50dde60e0000 pid=3814->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 132B guuid=c01a8b8a-1900-0000-f7ed-50ddf30e0000 pid=3827->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 81B guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861 /tmp/x86_64 net send-data zombie guuid=5ec06990-1900-0000-f7ed-50dd0f0f0000 pid=3855->guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861 clone guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ec24d88-10a2-533e-9815-5add425c4ddb 109.248.162.59:1025 guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->8ec24d88-10a2-533e-9815-5add425c4ddb send: 23B ea494a48-4f87-555b-a374-5bcf7d498d0d 51.83.147.130:1025 guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->ea494a48-4f87-555b-a374-5bcf7d498d0d con c6203332-51f0-5ada-b496-18efd14e4d3d 217.60.249.53:1025 guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->c6203332-51f0-5ada-b496-18efd14e4d3d con b2c2ad8f-4321-5ca8-994b-072c20344629 31.59.120.38:1025 guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->b2c2ad8f-4321-5ca8-994b-072c20344629 con guuid=b35eb891-1900-0000-f7ed-50dd1a0f0000 pid=3866 /tmp/x86_64 guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->guuid=b35eb891-1900-0000-f7ed-50dd1a0f0000 pid=3866 clone guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867 /tmp/x86_64 net net-scan send-data guuid=ba695591-1900-0000-f7ed-50dd150f0000 pid=3861->guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867 clone guuid=6f10b291-1900-0000-f7ed-50dd190f0000 pid=3865->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 129B guuid=ff3d1c92-1900-0000-f7ed-50dd1e0f0000 pid=3870 /tmp/x86_64 guuid=b35eb891-1900-0000-f7ed-50dd1a0f0000 pid=3866->guuid=ff3d1c92-1900-0000-f7ed-50dd1e0f0000 pid=3870 clone guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867|send-data send-data to 4097 IP addresses review logs to see them all guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867->guuid=82a8ba91-1900-0000-f7ed-50dd1b0f0000 pid=3867|send-data send guuid=1af63599-1900-0000-f7ed-50dd380f0000 pid=3896->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 78B guuid=22d4919e-1900-0000-f7ed-50dd540f0000 pid=3924->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf30ad9e-1900-0000-f7ed-50dd550f0000 pid=3925 /tmp/x86 net send-data zombie guuid=22d4919e-1900-0000-f7ed-50dd540f0000 pid=3924->guuid=cf30ad9e-1900-0000-f7ed-50dd550f0000 pid=3925 clone guuid=cf30ad9e-1900-0000-f7ed-50dd550f0000 pid=3925->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf30ad9e-1900-0000-f7ed-50dd550f0000 pid=3925->c41bd86a-d676-55f9-8fe7-1c41abc334fa send: 3082B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2025-08-10 05:41:33 UTC
File Type:
Text (Shell)
AV detection:
16 of 23 (69.57%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (72662) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 874a06388ef6532595962a7d25418b60da0559560a5f296a00ca3fc7846718bf

(this sample)

  
Delivery method
Distributed via web download

Comments