MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f2f79124ff3353081958be3b250441b8bdac0d73e790c0efc225287a462690e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 8f2f79124ff3353081958be3b250441b8bdac0d73e790c0efc225287a462690e
SHA3-384 hash: 1aae68c5077de5810f49f6dcee349042841e72d1a2c8eacda6e6a2f6cc580e31c80df0657a586f3d1d4dfbbca15ebf94
SHA1 hash: f037b2d03aefa3da282b8cf41437f5e6f74588e8
MD5 hash: 13f222112b6cda32fdbbf92735a20dfe
humanhash: king-september-alaska-oxygen
File name:goon.sh
Download: download sample
Signature Mirai
File size:1'128 bytes
First seen:2025-10-16 05:40:43 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:t/ddrNIvoK8AZpWk1q/6NNI7tfKAet8NWd:tjkpj1qy4tfphNWd
TLSH T1CF21F69F5971274B8CC8FDC6717219486019E3C638D20BDBFD9C14B942A9D98F051B87
Magika batch
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://23.177.185.39/garmn/an/aelf ua-wget
http://23.177.185.39/garm558b3a79908d27434eeca74e2c54476fb38b2b93b540abc04f7315bde694a914a Miraiarm elf geofenced mirai ua-wget USA
http://23.177.185.39/garm60c1313445a60d4b30b3f7f51f71a338ed42422d5f28e200a40ef259a40eeee4a Gafgytarm elf gafgyt geofenced ua-wget USA
http://23.177.185.39/garm770116c88989dac84c982c6bcd364ee6f6a5b9dd22e8a295d209ce8cc72ab2124 Miraiarm elf geofenced mirai ua-wget USA
http://23.177.185.39/gmips7ad355b06d01dd98b4eb6edb6415cd4642d328a2925ec3cd70ebf6b871ffc04e Miraielf geofenced mips mirai ua-wget USA
http://23.177.185.39/gmpslba80287beeb7e1e12ee4af4cd70084a313da19733bc37bb52d8e79ecbc0b48ba Miraielf geofenced mips mirai ua-wget USA
http://23.177.185.39/x86_647e02164c352397c011317df0cff9c6b3ec66eb749f5c68dcca67c3c6f50f86a6 Miraielf mirai ua-wget
http://23.177.185.39/armf6038ff963fc43473bd69ee8b571b6bcdc88d7bb3231ec5727e835232edee6a7 Miraielf mirai ua-wget
http://23.177.185.39/arm5b5f97c4c0ff408de365da6735bf940d1a6a7f7465be68509db8e313f3dcf174f Miraielf gafgyt mirai ua-wget
http://23.177.185.39/arm6625c60b9a8b0347d5a3988d73bf19d9c5bc9bf126fa8720dd28c648edb4a0975 Miraielf gafgyt mirai ua-wget
http://23.177.185.39/arm7ffe536b3d11dd297b8155ecf55695ef88518cc6e35976efed155b6328444bfb5 Miraielf mirai ua-wget
http://23.177.185.39/mips2cae01a9c5ccb06c91d94ba45a9aaec9f804f60f9bf86cdf97daf5ceacae8f4f Mirai32-bit elf gafgyt mirai Mozi
http://23.177.185.39/mpsl9b9764585122f6e0d842fb301963fed0cb6cba5a12740fec2c660d1f636bafd5 Miraielf gafgyt mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-10-16T03:45:00Z UTC
Last seen:
2025-10-16T04:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=1eaf5f3f-1a00-0000-2058-bbcd120a0000 pid=2578 /usr/bin/sudo guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584 /tmp/sample.bin guuid=1eaf5f3f-1a00-0000-2058-bbcd120a0000 pid=2578->guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584 execve guuid=4a044841-1a00-0000-2058-bbcd190a0000 pid=2585 /usr/bin/mkdir guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=4a044841-1a00-0000-2058-bbcd190a0000 pid=2585 execve guuid=2b0fbb41-1a00-0000-2058-bbcd1c0a0000 pid=2588 /usr/bin/wget net send-data guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=2b0fbb41-1a00-0000-2058-bbcd1c0a0000 pid=2588 execve guuid=00e33a54-1a00-0000-2058-bbcd570a0000 pid=2647 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=00e33a54-1a00-0000-2058-bbcd570a0000 pid=2647 execve guuid=5ff67a54-1a00-0000-2058-bbcd580a0000 pid=2648 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=5ff67a54-1a00-0000-2058-bbcd580a0000 pid=2648 clone guuid=c1328954-1a00-0000-2058-bbcd590a0000 pid=2649 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=c1328954-1a00-0000-2058-bbcd590a0000 pid=2649 execve guuid=a296c654-1a00-0000-2058-bbcd5a0a0000 pid=2650 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=a296c654-1a00-0000-2058-bbcd5a0a0000 pid=2650 execve guuid=f76fec7f-1a00-0000-2058-bbcdc40a0000 pid=2756 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=f76fec7f-1a00-0000-2058-bbcdc40a0000 pid=2756 execve guuid=07d94c80-1a00-0000-2058-bbcdc50a0000 pid=2757 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=07d94c80-1a00-0000-2058-bbcdc50a0000 pid=2757 clone guuid=cd5cda80-1a00-0000-2058-bbcdc80a0000 pid=2760 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=cd5cda80-1a00-0000-2058-bbcdc80a0000 pid=2760 execve guuid=109b1681-1a00-0000-2058-bbcdca0a0000 pid=2762 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=109b1681-1a00-0000-2058-bbcdca0a0000 pid=2762 execve guuid=7a71b6ac-1a00-0000-2058-bbcd1c0b0000 pid=2844 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=7a71b6ac-1a00-0000-2058-bbcd1c0b0000 pid=2844 execve guuid=2f00f1ac-1a00-0000-2058-bbcd1d0b0000 pid=2845 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=2f00f1ac-1a00-0000-2058-bbcd1d0b0000 pid=2845 clone guuid=49dc74ad-1a00-0000-2058-bbcd200b0000 pid=2848 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=49dc74ad-1a00-0000-2058-bbcd200b0000 pid=2848 execve guuid=d8eac6ad-1a00-0000-2058-bbcd220b0000 pid=2850 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=d8eac6ad-1a00-0000-2058-bbcd220b0000 pid=2850 execve guuid=e29a2cda-1a00-0000-2058-bbcd850b0000 pid=2949 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=e29a2cda-1a00-0000-2058-bbcd850b0000 pid=2949 execve guuid=a7f8c5da-1a00-0000-2058-bbcd860b0000 pid=2950 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=a7f8c5da-1a00-0000-2058-bbcd860b0000 pid=2950 clone guuid=c833b6db-1a00-0000-2058-bbcd8a0b0000 pid=2954 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=c833b6db-1a00-0000-2058-bbcd8a0b0000 pid=2954 execve guuid=f17311dc-1a00-0000-2058-bbcd8c0b0000 pid=2956 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=f17311dc-1a00-0000-2058-bbcd8c0b0000 pid=2956 execve guuid=9dcaa509-1b00-0000-2058-bbcdc00b0000 pid=3008 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=9dcaa509-1b00-0000-2058-bbcdc00b0000 pid=3008 execve guuid=4379ea09-1b00-0000-2058-bbcdc20b0000 pid=3010 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=4379ea09-1b00-0000-2058-bbcdc20b0000 pid=3010 clone guuid=d835a70a-1b00-0000-2058-bbcdc60b0000 pid=3014 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=d835a70a-1b00-0000-2058-bbcdc60b0000 pid=3014 execve guuid=74d5fe0a-1b00-0000-2058-bbcdc80b0000 pid=3016 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=74d5fe0a-1b00-0000-2058-bbcdc80b0000 pid=3016 execve guuid=c6a0aa3e-1b00-0000-2058-bbcd1a0c0000 pid=3098 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=c6a0aa3e-1b00-0000-2058-bbcd1a0c0000 pid=3098 execve guuid=e9cd1c3f-1b00-0000-2058-bbcd1c0c0000 pid=3100 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=e9cd1c3f-1b00-0000-2058-bbcd1c0c0000 pid=3100 clone guuid=cf551d41-1b00-0000-2058-bbcd230c0000 pid=3107 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=cf551d41-1b00-0000-2058-bbcd230c0000 pid=3107 execve guuid=624e5641-1b00-0000-2058-bbcd240c0000 pid=3108 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=624e5641-1b00-0000-2058-bbcd240c0000 pid=3108 execve guuid=514fd66c-1b00-0000-2058-bbcd860c0000 pid=3206 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=514fd66c-1b00-0000-2058-bbcd860c0000 pid=3206 execve guuid=6247696d-1b00-0000-2058-bbcd870c0000 pid=3207 /tmp/1/x86_64 net guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=6247696d-1b00-0000-2058-bbcd870c0000 pid=3207 execve guuid=fef9b66d-1b00-0000-2058-bbcd890c0000 pid=3209 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=fef9b66d-1b00-0000-2058-bbcd890c0000 pid=3209 execve guuid=57532a6e-1b00-0000-2058-bbcd8a0c0000 pid=3210 /usr/bin/wget net send-data guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=57532a6e-1b00-0000-2058-bbcd8a0c0000 pid=3210 execve guuid=4033d980-1b00-0000-2058-bbcda80c0000 pid=3240 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=4033d980-1b00-0000-2058-bbcda80c0000 pid=3240 execve guuid=b5aa3181-1b00-0000-2058-bbcdaa0c0000 pid=3242 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=b5aa3181-1b00-0000-2058-bbcdaa0c0000 pid=3242 clone guuid=5bce3f81-1b00-0000-2058-bbcdab0c0000 pid=3243 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=5bce3f81-1b00-0000-2058-bbcdab0c0000 pid=3243 execve guuid=4cc18881-1b00-0000-2058-bbcdae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=4cc18881-1b00-0000-2058-bbcdae0c0000 pid=3246 execve guuid=508b66ad-1b00-0000-2058-bbcdd90c0000 pid=3289 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=508b66ad-1b00-0000-2058-bbcdd90c0000 pid=3289 execve guuid=06c8a6ad-1b00-0000-2058-bbcddb0c0000 pid=3291 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=06c8a6ad-1b00-0000-2058-bbcddb0c0000 pid=3291 clone guuid=3a8f36ae-1b00-0000-2058-bbcdde0c0000 pid=3294 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=3a8f36ae-1b00-0000-2058-bbcdde0c0000 pid=3294 execve guuid=283f95ae-1b00-0000-2058-bbcde00c0000 pid=3296 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=283f95ae-1b00-0000-2058-bbcde00c0000 pid=3296 execve guuid=d6f21fda-1b00-0000-2058-bbcd310d0000 pid=3377 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=d6f21fda-1b00-0000-2058-bbcd310d0000 pid=3377 execve guuid=75216fda-1b00-0000-2058-bbcd330d0000 pid=3379 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=75216fda-1b00-0000-2058-bbcd330d0000 pid=3379 clone guuid=93fa26db-1b00-0000-2058-bbcd350d0000 pid=3381 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=93fa26db-1b00-0000-2058-bbcd350d0000 pid=3381 execve guuid=404077db-1b00-0000-2058-bbcd370d0000 pid=3383 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=404077db-1b00-0000-2058-bbcd370d0000 pid=3383 execve guuid=c7d20707-1c00-0000-2058-bbcda30d0000 pid=3491 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=c7d20707-1c00-0000-2058-bbcda30d0000 pid=3491 execve guuid=13544507-1c00-0000-2058-bbcda40d0000 pid=3492 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=13544507-1c00-0000-2058-bbcda40d0000 pid=3492 clone guuid=cad5ca07-1c00-0000-2058-bbcda80d0000 pid=3496 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=cad5ca07-1c00-0000-2058-bbcda80d0000 pid=3496 execve guuid=99491c08-1c00-0000-2058-bbcdaa0d0000 pid=3498 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=99491c08-1c00-0000-2058-bbcdaa0d0000 pid=3498 execve guuid=b86aa333-1c00-0000-2058-bbcd0d0e0000 pid=3597 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=b86aa333-1c00-0000-2058-bbcd0d0e0000 pid=3597 execve guuid=9b53ec33-1c00-0000-2058-bbcd0e0e0000 pid=3598 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=9b53ec33-1c00-0000-2058-bbcd0e0e0000 pid=3598 clone guuid=82d16e34-1c00-0000-2058-bbcd110e0000 pid=3601 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=82d16e34-1c00-0000-2058-bbcd110e0000 pid=3601 execve guuid=e24eb134-1c00-0000-2058-bbcd130e0000 pid=3603 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=e24eb134-1c00-0000-2058-bbcd130e0000 pid=3603 execve guuid=d6304c60-1c00-0000-2058-bbcd920e0000 pid=3730 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=d6304c60-1c00-0000-2058-bbcd920e0000 pid=3730 execve guuid=87b9ba60-1c00-0000-2058-bbcd950e0000 pid=3733 /usr/bin/dash guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=87b9ba60-1c00-0000-2058-bbcd950e0000 pid=3733 clone guuid=95f56961-1c00-0000-2058-bbcd980e0000 pid=3736 /usr/bin/rm guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=95f56961-1c00-0000-2058-bbcd980e0000 pid=3736 execve guuid=7799d161-1c00-0000-2058-bbcd990e0000 pid=3737 /usr/bin/wget net send-data write-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=7799d161-1c00-0000-2058-bbcd990e0000 pid=3737 execve guuid=d5891e8d-1c00-0000-2058-bbcd070f0000 pid=3847 /usr/bin/chmod guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=d5891e8d-1c00-0000-2058-bbcd070f0000 pid=3847 execve guuid=e5f6938d-1c00-0000-2058-bbcd090f0000 pid=3849 /tmp/1/x86_64 net guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=e5f6938d-1c00-0000-2058-bbcd090f0000 pid=3849 execve guuid=6cf32b43-1d00-0000-2058-bbcdd6100000 pid=4310 /usr/bin/rm delete-file guuid=9a7d0341-1a00-0000-2058-bbcd180a0000 pid=2584->guuid=6cf32b43-1d00-0000-2058-bbcdd6100000 pid=4310 execve ba55188c-1d8c-531d-84cb-0b022f7a1844 23.177.185.39:80 guuid=2b0fbb41-1a00-0000-2058-bbcd1c0a0000 pid=2588->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=a296c654-1a00-0000-2058-bbcd5a0a0000 pid=2650->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=109b1681-1a00-0000-2058-bbcdca0a0000 pid=2762->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=d8eac6ad-1a00-0000-2058-bbcd220b0000 pid=2850->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=f17311dc-1a00-0000-2058-bbcd8c0b0000 pid=2956->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=74d5fe0a-1b00-0000-2058-bbcdc80b0000 pid=3016->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 133B guuid=624e5641-1b00-0000-2058-bbcd240c0000 pid=3108->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 134B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6247696d-1b00-0000-2058-bbcd870c0000 pid=3207->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dd419d6d-1b00-0000-2058-bbcd880c0000 pid=3208 /tmp/1/x86_64 dns net send-data zombie guuid=6247696d-1b00-0000-2058-bbcd870c0000 pid=3207->guuid=dd419d6d-1b00-0000-2058-bbcd880c0000 pid=3208 clone 110bde38-bfc1-5ad0-be72-0de631caf90c 51.77.149.139:53 guuid=dd419d6d-1b00-0000-2058-bbcd880c0000 pid=3208->110bde38-bfc1-5ad0-be72-0de631caf90c send: 34B 48d6144b-2bcb-5105-880a-b486b4d6b787 loadingboats.dyn:5667 guuid=dd419d6d-1b00-0000-2058-bbcd880c0000 pid=3208->48d6144b-2bcb-5105-880a-b486b4d6b787 send: 35B guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211 /tmp/1/x86_64 net guuid=dd419d6d-1b00-0000-2058-bbcd880c0000 pid=3208->guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211 clone guuid=57532a6e-1b00-0000-2058-bbcd8a0c0000 pid=3210->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 131B 114d3c68-7578-5d97-aa3f-3b17a04daf8c 188.166.240.30:2222 guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->114d3c68-7578-5d97-aa3f-3b17a04daf8c con guuid=212b0f6f-1b00-0000-2058-bbcd8c0c0000 pid=3212 /usr/bin/dash guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->guuid=212b0f6f-1b00-0000-2058-bbcd8c0c0000 pid=3212 execve guuid=e601857e-1b00-0000-2058-bbcd9b0c0000 pid=3227 /usr/bin/dash guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->guuid=e601857e-1b00-0000-2058-bbcd9b0c0000 pid=3227 execve guuid=101b327f-1b00-0000-2058-bbcd9e0c0000 pid=3230 /usr/bin/dash guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->guuid=101b327f-1b00-0000-2058-bbcd9e0c0000 pid=3230 execve guuid=cc0ea07f-1b00-0000-2058-bbcda00c0000 pid=3232 /usr/bin/dash guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->guuid=cc0ea07f-1b00-0000-2058-bbcda00c0000 pid=3232 execve guuid=7c7be57f-1b00-0000-2058-bbcda20c0000 pid=3234 /usr/bin/dash guuid=550ffc6e-1b00-0000-2058-bbcd8b0c0000 pid=3211->guuid=7c7be57f-1b00-0000-2058-bbcda20c0000 pid=3234 execve guuid=9592656f-1b00-0000-2058-bbcd8d0c0000 pid=3213 /usr/sbin/xtables-nft-multi guuid=212b0f6f-1b00-0000-2058-bbcd8c0c0000 pid=3212->guuid=9592656f-1b00-0000-2058-bbcd8d0c0000 pid=3213 execve guuid=21f3ba7e-1b00-0000-2058-bbcd9c0c0000 pid=3228 /usr/bin/busybox guuid=e601857e-1b00-0000-2058-bbcd9b0c0000 pid=3227->guuid=21f3ba7e-1b00-0000-2058-bbcd9c0c0000 pid=3228 execve guuid=dc8a887f-1b00-0000-2058-bbcd9f0c0000 pid=3231 /usr/bin/dash guuid=101b327f-1b00-0000-2058-bbcd9e0c0000 pid=3230->guuid=dc8a887f-1b00-0000-2058-bbcd9f0c0000 pid=3231 clone guuid=6761cf7f-1b00-0000-2058-bbcda10c0000 pid=3233 /usr/bin/dash guuid=cc0ea07f-1b00-0000-2058-bbcda00c0000 pid=3232->guuid=6761cf7f-1b00-0000-2058-bbcda10c0000 pid=3233 clone guuid=2d642880-1b00-0000-2058-bbcda40c0000 pid=3236 /usr/bin/busybox guuid=7c7be57f-1b00-0000-2058-bbcda20c0000 pid=3234->guuid=2d642880-1b00-0000-2058-bbcda40c0000 pid=3236 execve guuid=4cc18881-1b00-0000-2058-bbcdae0c0000 pid=3246->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=283f95ae-1b00-0000-2058-bbcde00c0000 pid=3296->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=404077db-1b00-0000-2058-bbcd370d0000 pid=3383->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=99491c08-1c00-0000-2058-bbcdaa0d0000 pid=3498->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=e24eb134-1c00-0000-2058-bbcd130e0000 pid=3603->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 132B guuid=7799d161-1c00-0000-2058-bbcd990e0000 pid=3737->ba55188c-1d8c-531d-84cb-0b022f7a1844 send: 134B guuid=e5f6938d-1c00-0000-2058-bbcd090f0000 pid=3849->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 257d31dd-cb0d-573a-8e60-d7fe3e6be32a 127.0.0.1:1422 guuid=e5f6938d-1c00-0000-2058-bbcd090f0000 pid=3849->257d31dd-cb0d-573a-8e60-d7fe3e6be32a con guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309 /tmp/1/x86_64 dns net send-data zombie guuid=e5f6938d-1c00-0000-2058-bbcd090f0000 pid=3849->guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309 clone guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309->48d6144b-2bcb-5105-880a-b486b4d6b787 send: 37B 1953617f-bd2b-56a9-9ede-0bea1c944f64 178.254.22.166:53 guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309->1953617f-bd2b-56a9-9ede-0bea1c944f64 send: 170B 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 con ac0b4284-2aa4-5c89-80a0-995c690355af 81.169.136.222:53 guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309->ac0b4284-2aa4-5c89-80a0-995c690355af send: 34B guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317 /tmp/1/x86_64 net guuid=02ce2243-1d00-0000-2058-bbcdd5100000 pid=4309->guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317 clone guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->114d3c68-7578-5d97-aa3f-3b17a04daf8c con guuid=5dc48d44-1d00-0000-2058-bbcdde100000 pid=4318 /usr/bin/dash guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->guuid=5dc48d44-1d00-0000-2058-bbcdde100000 pid=4318 execve guuid=7fcb5f45-1d00-0000-2058-bbcde2100000 pid=4322 /usr/bin/dash guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->guuid=7fcb5f45-1d00-0000-2058-bbcde2100000 pid=4322 execve guuid=7043dc45-1d00-0000-2058-bbcde7100000 pid=4327 /usr/bin/dash guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->guuid=7043dc45-1d00-0000-2058-bbcde7100000 pid=4327 execve guuid=e51d4246-1d00-0000-2058-bbcde9100000 pid=4329 /usr/bin/dash guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->guuid=e51d4246-1d00-0000-2058-bbcde9100000 pid=4329 execve guuid=d6c9bb46-1d00-0000-2058-bbcdee100000 pid=4334 /usr/bin/dash guuid=d5787f44-1d00-0000-2058-bbcddd100000 pid=4317->guuid=d6c9bb46-1d00-0000-2058-bbcdee100000 pid=4334 execve guuid=3c42d844-1d00-0000-2058-bbcde0100000 pid=4320 /usr/sbin/xtables-nft-multi guuid=5dc48d44-1d00-0000-2058-bbcdde100000 pid=4318->guuid=3c42d844-1d00-0000-2058-bbcde0100000 pid=4320 execve guuid=da3fa445-1d00-0000-2058-bbcde5100000 pid=4325 /usr/bin/busybox guuid=7fcb5f45-1d00-0000-2058-bbcde2100000 pid=4322->guuid=da3fa445-1d00-0000-2058-bbcde5100000 pid=4325 execve guuid=d5521a46-1d00-0000-2058-bbcde8100000 pid=4328 /usr/bin/dash guuid=7043dc45-1d00-0000-2058-bbcde7100000 pid=4327->guuid=d5521a46-1d00-0000-2058-bbcde8100000 pid=4328 clone guuid=dab98346-1d00-0000-2058-bbcded100000 pid=4333 /usr/bin/dash guuid=e51d4246-1d00-0000-2058-bbcde9100000 pid=4329->guuid=dab98346-1d00-0000-2058-bbcded100000 pid=4333 clone guuid=8ff00c47-1d00-0000-2058-bbcdef100000 pid=4335 /usr/bin/busybox guuid=d6c9bb46-1d00-0000-2058-bbcdee100000 pid=4334->guuid=8ff00c47-1d00-0000-2058-bbcdef100000 pid=4335 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-10-16 06:05:44 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8f2f79124ff3353081958be3b250441b8bdac0d73e790c0efc225287a462690e

(this sample)

  
Delivery method
Distributed via web download

Comments