MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 93e71b122a432c2b7acf6a5db6ee3e42e792ef240acee466c4310b052e2416db. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 93e71b122a432c2b7acf6a5db6ee3e42e792ef240acee466c4310b052e2416db
SHA3-384 hash: a5370e51ac46283cd6497acfbe9dc7862bd0a6a66d7713b4a9233ba2a52a93cdaea6a37cb976ad3bb6d54fc10bf51827
SHA1 hash: 67d3521e93081f62d8827392cf946bfcbadda041
MD5 hash: d7b744ff3009216a5453685a23d292e5
humanhash: beer-oranges-wisconsin-eighteen
File name:re.sh
Download: download sample
File size:2'321 bytes
First seen:2026-06-09 02:32:22 UTC
Last seen:2026-06-09 17:53:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:WZExgiRiKbWIo7lSOYFYQjpoJQQEPpmEcDRw+ETL:74KbWIW0HZ
TLSH T1C441419BE1F4C2A1CC734D00B0515AD461EB979A1FB81766D6DC286EA0CFEC07C0DA2D
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://83.168.110.191/updaterros.x86_64f193db11dceb855f8b50a6dc966164199282a0a9eff24fa1d859913370205443 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.aarch6421e99667e2f0e73d12aae89f8cabd338426ab1fe4ce828ec93c07de615ef754c Miraielf mirai ua-wget
http://83.168.110.191/updaterros.m68k6aa904125beb01924243b0dd04e0988b16b8bccd5479224f8bbcd762814b303e Miraielf mirai ua-wget
http://83.168.110.191/updaterros.mips3910f46fe809d723d169b5723e0724dba7aed441a065b53b98e2f1b0a9736569 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.mipselcc653189103bd14e46958bae5f37f94852b7d54ced5662bf7858801c138645a8 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.powerpc122d401e549ed15c3a1da53b6f042852f03fab7af4b7fba71d8a58311ec404f3 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.sparc95077aa12ee9e710746f896a03728e2bbd0199eb24d228ffc9254f8721e0684b Miraielf mirai ua-wget
http://83.168.110.191/updaterros.sh43da4118754c0efb0d55883df372d0a2281a9cbb86dafe3cbdacfe60f2b0d6d16 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.arceda32690d58912c7af348e5bb86b5c512a92df36c6a25940462c51aef165d8e4 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.i486a07d9f4ec6ec082b328409b6e9b881d4d2f01ccfb9635e0013daf9eac495c16a Miraielf mirai ua-wget
http://83.168.110.191/updaterros.armv4ln/an/aelf ua-wget
http://83.168.110.191/updaterros.armv5ldb438a070bf17891aae00a7fc9ce6abe7d799dbbf8320de74e0ba807ed54db24 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.armv6la74490f7f69e7eb40e827f00ffcd1194861fde9bf94521ec004fd81e66d92779 Miraielf mirai ua-wget
http://83.168.110.191/updaterros.armv7ld3b35febaaa3842282e923a8bb9dc954ca172cf0f8ffd9a6b85761175913d6ec Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-08T23:38:00Z UTC
Last seen:
2026-06-11T00:22:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=37a94865-1900-0000-0e39-5671640b0000 pid=2916 /usr/bin/sudo guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918 /tmp/sample.bin guuid=37a94865-1900-0000-0e39-5671640b0000 pid=2916->guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918 execve guuid=43f32b69-1900-0000-0e39-5671670b0000 pid=2919 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=43f32b69-1900-0000-0e39-5671670b0000 pid=2919 execve guuid=4f4ded73-1900-0000-0e39-5671730b0000 pid=2931 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=4f4ded73-1900-0000-0e39-5671730b0000 pid=2931 execve guuid=8a6d4074-1900-0000-0e39-5671750b0000 pid=2933 /home/sandbox/updaterros.x86_64 mprotect-exec guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=8a6d4074-1900-0000-0e39-5671750b0000 pid=2933 execve guuid=04fa8f75-1900-0000-0e39-5671790b0000 pid=2937 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=04fa8f75-1900-0000-0e39-5671790b0000 pid=2937 execve guuid=19802780-1900-0000-0e39-56718c0b0000 pid=2956 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=19802780-1900-0000-0e39-56718c0b0000 pid=2956 execve guuid=37f36a80-1900-0000-0e39-56718d0b0000 pid=2957 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=37f36a80-1900-0000-0e39-56718d0b0000 pid=2957 clone guuid=31270681-1900-0000-0e39-56718f0b0000 pid=2959 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=31270681-1900-0000-0e39-56718f0b0000 pid=2959 execve guuid=66c0c58a-1900-0000-0e39-5671a40b0000 pid=2980 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=66c0c58a-1900-0000-0e39-5671a40b0000 pid=2980 execve guuid=5244078b-1900-0000-0e39-5671a60b0000 pid=2982 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=5244078b-1900-0000-0e39-5671a60b0000 pid=2982 clone guuid=9db68b8b-1900-0000-0e39-5671a90b0000 pid=2985 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=9db68b8b-1900-0000-0e39-5671a90b0000 pid=2985 execve guuid=5acfad95-1900-0000-0e39-5671be0b0000 pid=3006 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=5acfad95-1900-0000-0e39-5671be0b0000 pid=3006 execve guuid=4d5eec95-1900-0000-0e39-5671c00b0000 pid=3008 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=4d5eec95-1900-0000-0e39-5671c00b0000 pid=3008 clone guuid=04a68c96-1900-0000-0e39-5671c40b0000 pid=3012 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=04a68c96-1900-0000-0e39-5671c40b0000 pid=3012 execve guuid=1004b3a0-1900-0000-0e39-5671d80b0000 pid=3032 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=1004b3a0-1900-0000-0e39-5671d80b0000 pid=3032 execve guuid=22740aa1-1900-0000-0e39-5671da0b0000 pid=3034 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=22740aa1-1900-0000-0e39-5671da0b0000 pid=3034 clone guuid=58d7a3a1-1900-0000-0e39-5671de0b0000 pid=3038 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=58d7a3a1-1900-0000-0e39-5671de0b0000 pid=3038 execve guuid=d9eb97ab-1900-0000-0e39-5671f70b0000 pid=3063 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=d9eb97ab-1900-0000-0e39-5671f70b0000 pid=3063 execve guuid=6510e4ab-1900-0000-0e39-5671f90b0000 pid=3065 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=6510e4ab-1900-0000-0e39-5671f90b0000 pid=3065 clone guuid=921b7fac-1900-0000-0e39-5671fc0b0000 pid=3068 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=921b7fac-1900-0000-0e39-5671fc0b0000 pid=3068 execve guuid=3da0e0b2-1900-0000-0e39-5671100c0000 pid=3088 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=3da0e0b2-1900-0000-0e39-5671100c0000 pid=3088 execve guuid=a02239b3-1900-0000-0e39-5671120c0000 pid=3090 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=a02239b3-1900-0000-0e39-5671120c0000 pid=3090 clone guuid=6601a6b4-1900-0000-0e39-5671160c0000 pid=3094 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=6601a6b4-1900-0000-0e39-5671160c0000 pid=3094 execve guuid=a9ff8dc4-1900-0000-0e39-5671260c0000 pid=3110 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=a9ff8dc4-1900-0000-0e39-5671260c0000 pid=3110 execve guuid=ebfafdc4-1900-0000-0e39-5671270c0000 pid=3111 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=ebfafdc4-1900-0000-0e39-5671270c0000 pid=3111 clone guuid=4a050ec6-1900-0000-0e39-5671290c0000 pid=3113 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=4a050ec6-1900-0000-0e39-5671290c0000 pid=3113 execve guuid=0c45b0d0-1900-0000-0e39-56713f0c0000 pid=3135 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=0c45b0d0-1900-0000-0e39-56713f0c0000 pid=3135 execve guuid=3df602d1-1900-0000-0e39-5671410c0000 pid=3137 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=3df602d1-1900-0000-0e39-5671410c0000 pid=3137 clone guuid=cf62c2d1-1900-0000-0e39-5671450c0000 pid=3141 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=cf62c2d1-1900-0000-0e39-5671450c0000 pid=3141 execve guuid=e3f6f9d9-1900-0000-0e39-56715a0c0000 pid=3162 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=e3f6f9d9-1900-0000-0e39-56715a0c0000 pid=3162 execve guuid=7ac34eda-1900-0000-0e39-56715c0c0000 pid=3164 /home/sandbox/updaterros.i486 guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=7ac34eda-1900-0000-0e39-56715c0c0000 pid=3164 execve guuid=4d7229dc-1900-0000-0e39-5671640c0000 pid=3172 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=4d7229dc-1900-0000-0e39-5671640c0000 pid=3172 execve guuid=32095ce6-1900-0000-0e39-56717e0c0000 pid=3198 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=32095ce6-1900-0000-0e39-56717e0c0000 pid=3198 execve guuid=28f3b1e6-1900-0000-0e39-56717f0c0000 pid=3199 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=28f3b1e6-1900-0000-0e39-56717f0c0000 pid=3199 clone guuid=e35e74e7-1900-0000-0e39-5671810c0000 pid=3201 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=e35e74e7-1900-0000-0e39-5671810c0000 pid=3201 execve guuid=13390af2-1900-0000-0e39-5671970c0000 pid=3223 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=13390af2-1900-0000-0e39-5671970c0000 pid=3223 execve guuid=74a18ef2-1900-0000-0e39-5671980c0000 pid=3224 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=74a18ef2-1900-0000-0e39-5671980c0000 pid=3224 clone guuid=9ce8b3f3-1900-0000-0e39-56719a0c0000 pid=3226 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=9ce8b3f3-1900-0000-0e39-56719a0c0000 pid=3226 execve guuid=51e96cfe-1900-0000-0e39-56719b0c0000 pid=3227 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=51e96cfe-1900-0000-0e39-56719b0c0000 pid=3227 execve guuid=d752c8fe-1900-0000-0e39-56719c0c0000 pid=3228 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=d752c8fe-1900-0000-0e39-56719c0c0000 pid=3228 clone guuid=e6b3eaff-1900-0000-0e39-56719e0c0000 pid=3230 /usr/bin/wget net send-data write-file guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=e6b3eaff-1900-0000-0e39-56719e0c0000 pid=3230 execve guuid=92efe709-1a00-0000-0e39-5671a90c0000 pid=3241 /usr/bin/chmod guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=92efe709-1a00-0000-0e39-5671a90c0000 pid=3241 execve guuid=4a8d600a-1a00-0000-0e39-5671ab0c0000 pid=3243 /usr/bin/dash guuid=e484a768-1900-0000-0e39-5671660b0000 pid=2918->guuid=4a8d600a-1a00-0000-0e39-5671ab0c0000 pid=3243 clone 95ee53cd-bf83-5fcf-8a24-68305030540a 83.168.110.191:80 guuid=43f32b69-1900-0000-0e39-5671670b0000 pid=2919->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B guuid=35207d75-1900-0000-0e39-5671780b0000 pid=2936 /home/sandbox/updaterros.x86_64 zombie guuid=8a6d4074-1900-0000-0e39-5671750b0000 pid=2933->guuid=35207d75-1900-0000-0e39-5671780b0000 pid=2936 clone guuid=1fec9575-1900-0000-0e39-56717a0b0000 pid=2938 /home/sandbox/updaterros.x86_64 delete-file net send-data zombie guuid=35207d75-1900-0000-0e39-5671780b0000 pid=2936->guuid=1fec9575-1900-0000-0e39-56717a0b0000 pid=2938 clone guuid=04fa8f75-1900-0000-0e39-5671790b0000 pid=2937->95ee53cd-bf83-5fcf-8a24-68305030540a send: 147B 56477de4-0fe9-5b32-aa12-4711c34bdaca 83.168.110.191:1336 guuid=1fec9575-1900-0000-0e39-56717a0b0000 pid=2938->56477de4-0fe9-5b32-aa12-4711c34bdaca send: 35B guuid=31270681-1900-0000-0e39-56718f0b0000 pid=2959->95ee53cd-bf83-5fcf-8a24-68305030540a send: 144B guuid=9db68b8b-1900-0000-0e39-5671a90b0000 pid=2985->95ee53cd-bf83-5fcf-8a24-68305030540a send: 144B guuid=04a68c96-1900-0000-0e39-5671c40b0000 pid=3012->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B guuid=58d7a3a1-1900-0000-0e39-5671de0b0000 pid=3038->95ee53cd-bf83-5fcf-8a24-68305030540a send: 147B guuid=921b7fac-1900-0000-0e39-5671fc0b0000 pid=3068->95ee53cd-bf83-5fcf-8a24-68305030540a send: 145B guuid=6601a6b4-1900-0000-0e39-5671160c0000 pid=3094->95ee53cd-bf83-5fcf-8a24-68305030540a send: 143B guuid=4a050ec6-1900-0000-0e39-5671290c0000 pid=3113->95ee53cd-bf83-5fcf-8a24-68305030540a send: 143B guuid=cf62c2d1-1900-0000-0e39-5671450c0000 pid=3141->95ee53cd-bf83-5fcf-8a24-68305030540a send: 144B guuid=6baf21dc-1900-0000-0e39-5671630c0000 pid=3171 /home/sandbox/updaterros.i486 guuid=7ac34eda-1900-0000-0e39-56715c0c0000 pid=3164->guuid=6baf21dc-1900-0000-0e39-5671630c0000 pid=3171 clone guuid=363a2bdc-1900-0000-0e39-5671650c0000 pid=3173 /home/sandbox/updaterros.i486 delete-file net send-data zombie guuid=6baf21dc-1900-0000-0e39-5671630c0000 pid=3171->guuid=363a2bdc-1900-0000-0e39-5671650c0000 pid=3173 clone guuid=4d7229dc-1900-0000-0e39-5671640c0000 pid=3172->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B guuid=363a2bdc-1900-0000-0e39-5671650c0000 pid=3173->56477de4-0fe9-5b32-aa12-4711c34bdaca send: 280B guuid=e35e74e7-1900-0000-0e39-5671810c0000 pid=3201->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B guuid=9ce8b3f3-1900-0000-0e39-56719a0c0000 pid=3226->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B guuid=e6b3eaff-1900-0000-0e39-56719e0c0000 pid=3230->95ee53cd-bf83-5fcf-8a24-68305030540a send: 146B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-09 02:33:35 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 93e71b122a432c2b7acf6a5db6ee3e42e792ef240acee466c4310b052e2416db

(this sample)

  
Delivery method
Distributed via web download

Comments