MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 94649e2369719ae4e2c4b49d6a30f8dfdbb6cc097bffd2ecef6831998300368c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 94649e2369719ae4e2c4b49d6a30f8dfdbb6cc097bffd2ecef6831998300368c
SHA3-384 hash: 01eca24d9ac0acc10d0c0889a29854cbf479fdd503b8cd7fad7fd24d6af93f03245eb1445a9270d42166ef48d696b984
SHA1 hash: 8b5cd742bd38aa1c5878729e67774f74d2a47f8f
MD5 hash: 42a540f2524721e31e5f32a5e8792f2b
humanhash: comet-king-batman-black
File name:ok
Download: download sample
Signature Mirai
File size:1'644 bytes
First seen:2026-06-17 02:29:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:D8oHIXLw4YS6BpRFPYJFaFmrWhWVyhBX0BMa:AXL1YScnA9yXIMa
TLSH T19231A1CB85241E396702CADE73B6354C720D81EB294FE7D0DD6D1EAD428C6D8B252F91
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/62ae5dn/an/aua-wget
http://5.182.210.61/a09043n/an/aua-wget
http://5.182.210.61/bd448fn/an/aua-wget
http://5.182.210.61/c57301n/an/aua-wget
http://5.182.210.61/5c77b8n/an/aua-wget
http://5.182.210.61/58f304n/an/aua-wget
http://5.182.210.61/e78f55n/an/aua-wget
http://5.182.210.61/c3a0e5n/an/aua-wget
http://5.182.210.61/26ad7dn/an/aua-wget
http://5.182.210.61/dbf80dn/an/aua-wget
http://5.182.210.61/bae5fan/an/aua-wget
http://5.182.210.61/45fb47n/an/aua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
95
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-16T23:36:00Z UTC
Last seen:
2026-06-17T01:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=630022b9-1e00-0000-a925-f3c86e0b0000 pid=2926 /usr/bin/sudo guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933 /tmp/sample.bin guuid=630022b9-1e00-0000-a925-f3c86e0b0000 pid=2926->guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933 execve guuid=951b75bb-1e00-0000-a925-f3c8760b0000 pid=2934 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=951b75bb-1e00-0000-a925-f3c8760b0000 pid=2934 execve guuid=d6c563c1-1e00-0000-a925-f3c8810b0000 pid=2945 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d6c563c1-1e00-0000-a925-f3c8810b0000 pid=2945 execve guuid=5302eae3-1e00-0000-a925-f3c8890b0000 pid=2953 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=5302eae3-1e00-0000-a925-f3c8890b0000 pid=2953 execve guuid=4a78f4e4-1e00-0000-a925-f3c88b0b0000 pid=2955 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=4a78f4e4-1e00-0000-a925-f3c88b0b0000 pid=2955 clone guuid=001853e5-1e00-0000-a925-f3c88e0b0000 pid=2958 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=001853e5-1e00-0000-a925-f3c88e0b0000 pid=2958 execve guuid=325ca4e5-1e00-0000-a925-f3c88f0b0000 pid=2959 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=325ca4e5-1e00-0000-a925-f3c88f0b0000 pid=2959 execve guuid=968deee5-1e00-0000-a925-f3c8910b0000 pid=2961 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=968deee5-1e00-0000-a925-f3c8910b0000 pid=2961 execve guuid=46026be8-1e00-0000-a925-f3c8980b0000 pid=2968 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=46026be8-1e00-0000-a925-f3c8980b0000 pid=2968 execve guuid=068904ec-1e00-0000-a925-f3c8a10b0000 pid=2977 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=068904ec-1e00-0000-a925-f3c8a10b0000 pid=2977 execve guuid=2c4e4eec-1e00-0000-a925-f3c8a20b0000 pid=2978 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=2c4e4eec-1e00-0000-a925-f3c8a20b0000 pid=2978 clone guuid=ca588dec-1e00-0000-a925-f3c8a50b0000 pid=2981 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=ca588dec-1e00-0000-a925-f3c8a50b0000 pid=2981 execve guuid=3f56d7ec-1e00-0000-a925-f3c8a70b0000 pid=2983 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=3f56d7ec-1e00-0000-a925-f3c8a70b0000 pid=2983 execve guuid=6b1918ed-1e00-0000-a925-f3c8a90b0000 pid=2985 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=6b1918ed-1e00-0000-a925-f3c8a90b0000 pid=2985 execve guuid=19b1a1ef-1e00-0000-a925-f3c8ae0b0000 pid=2990 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=19b1a1ef-1e00-0000-a925-f3c8ae0b0000 pid=2990 execve guuid=989e59f4-1e00-0000-a925-f3c8b90b0000 pid=3001 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=989e59f4-1e00-0000-a925-f3c8b90b0000 pid=3001 execve guuid=13d3a7f4-1e00-0000-a925-f3c8ba0b0000 pid=3002 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=13d3a7f4-1e00-0000-a925-f3c8ba0b0000 pid=3002 clone guuid=974ceaf4-1e00-0000-a925-f3c8bc0b0000 pid=3004 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=974ceaf4-1e00-0000-a925-f3c8bc0b0000 pid=3004 execve guuid=dfbd3bf5-1e00-0000-a925-f3c8be0b0000 pid=3006 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=dfbd3bf5-1e00-0000-a925-f3c8be0b0000 pid=3006 execve guuid=96cb7ff5-1e00-0000-a925-f3c8c00b0000 pid=3008 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=96cb7ff5-1e00-0000-a925-f3c8c00b0000 pid=3008 execve guuid=785fbcf8-1e00-0000-a925-f3c8c80b0000 pid=3016 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=785fbcf8-1e00-0000-a925-f3c8c80b0000 pid=3016 execve guuid=a25eccfd-1e00-0000-a925-f3c8d50b0000 pid=3029 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=a25eccfd-1e00-0000-a925-f3c8d50b0000 pid=3029 execve guuid=aa3025fe-1e00-0000-a925-f3c8d70b0000 pid=3031 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=aa3025fe-1e00-0000-a925-f3c8d70b0000 pid=3031 clone guuid=d78968fe-1e00-0000-a925-f3c8da0b0000 pid=3034 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d78968fe-1e00-0000-a925-f3c8da0b0000 pid=3034 execve guuid=6a9ebbfe-1e00-0000-a925-f3c8dc0b0000 pid=3036 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=6a9ebbfe-1e00-0000-a925-f3c8dc0b0000 pid=3036 execve guuid=d3160fff-1e00-0000-a925-f3c8de0b0000 pid=3038 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d3160fff-1e00-0000-a925-f3c8de0b0000 pid=3038 execve guuid=62ffc401-1f00-0000-a925-f3c8e40b0000 pid=3044 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=62ffc401-1f00-0000-a925-f3c8e40b0000 pid=3044 execve guuid=9ed73905-1f00-0000-a925-f3c8ed0b0000 pid=3053 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=9ed73905-1f00-0000-a925-f3c8ed0b0000 pid=3053 execve guuid=5bbc9905-1f00-0000-a925-f3c8ee0b0000 pid=3054 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=5bbc9905-1f00-0000-a925-f3c8ee0b0000 pid=3054 clone guuid=b50ae005-1f00-0000-a925-f3c8f10b0000 pid=3057 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=b50ae005-1f00-0000-a925-f3c8f10b0000 pid=3057 execve guuid=d20e4806-1f00-0000-a925-f3c8f30b0000 pid=3059 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d20e4806-1f00-0000-a925-f3c8f30b0000 pid=3059 execve guuid=4b4da806-1f00-0000-a925-f3c8f60b0000 pid=3062 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=4b4da806-1f00-0000-a925-f3c8f60b0000 pid=3062 execve guuid=25454f09-1f00-0000-a925-f3c8fd0b0000 pid=3069 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=25454f09-1f00-0000-a925-f3c8fd0b0000 pid=3069 execve guuid=5699860f-1f00-0000-a925-f3c80f0c0000 pid=3087 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=5699860f-1f00-0000-a925-f3c80f0c0000 pid=3087 execve guuid=3494d30f-1f00-0000-a925-f3c8110c0000 pid=3089 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=3494d30f-1f00-0000-a925-f3c8110c0000 pid=3089 clone guuid=1d0d3210-1f00-0000-a925-f3c8140c0000 pid=3092 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=1d0d3210-1f00-0000-a925-f3c8140c0000 pid=3092 execve guuid=e4ee8c10-1f00-0000-a925-f3c8160c0000 pid=3094 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=e4ee8c10-1f00-0000-a925-f3c8160c0000 pid=3094 execve guuid=54c2d810-1f00-0000-a925-f3c8180c0000 pid=3096 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=54c2d810-1f00-0000-a925-f3c8180c0000 pid=3096 execve guuid=64635013-1f00-0000-a925-f3c8220c0000 pid=3106 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=64635013-1f00-0000-a925-f3c8220c0000 pid=3106 execve guuid=56b9e917-1f00-0000-a925-f3c82f0c0000 pid=3119 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=56b9e917-1f00-0000-a925-f3c82f0c0000 pid=3119 execve guuid=f1572c18-1f00-0000-a925-f3c8310c0000 pid=3121 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=f1572c18-1f00-0000-a925-f3c8310c0000 pid=3121 clone guuid=c1536218-1f00-0000-a925-f3c8340c0000 pid=3124 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=c1536218-1f00-0000-a925-f3c8340c0000 pid=3124 execve guuid=2acebf18-1f00-0000-a925-f3c8350c0000 pid=3125 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=2acebf18-1f00-0000-a925-f3c8350c0000 pid=3125 execve guuid=39f90419-1f00-0000-a925-f3c8370c0000 pid=3127 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=39f90419-1f00-0000-a925-f3c8370c0000 pid=3127 execve guuid=113ac01b-1f00-0000-a925-f3c8410c0000 pid=3137 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=113ac01b-1f00-0000-a925-f3c8410c0000 pid=3137 execve guuid=1b183d21-1f00-0000-a925-f3c8530c0000 pid=3155 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=1b183d21-1f00-0000-a925-f3c8530c0000 pid=3155 execve guuid=d4b38721-1f00-0000-a925-f3c8550c0000 pid=3157 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d4b38721-1f00-0000-a925-f3c8550c0000 pid=3157 clone guuid=d5dec421-1f00-0000-a925-f3c8570c0000 pid=3159 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d5dec421-1f00-0000-a925-f3c8570c0000 pid=3159 execve guuid=357c1d22-1f00-0000-a925-f3c8580c0000 pid=3160 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=357c1d22-1f00-0000-a925-f3c8580c0000 pid=3160 execve guuid=6ae06722-1f00-0000-a925-f3c8590c0000 pid=3161 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=6ae06722-1f00-0000-a925-f3c8590c0000 pid=3161 execve guuid=5653f124-1f00-0000-a925-f3c8600c0000 pid=3168 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=5653f124-1f00-0000-a925-f3c8600c0000 pid=3168 execve guuid=63d38f28-1f00-0000-a925-f3c86c0c0000 pid=3180 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=63d38f28-1f00-0000-a925-f3c86c0c0000 pid=3180 execve guuid=6788f028-1f00-0000-a925-f3c86e0c0000 pid=3182 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=6788f028-1f00-0000-a925-f3c86e0c0000 pid=3182 clone guuid=135e3629-1f00-0000-a925-f3c8700c0000 pid=3184 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=135e3629-1f00-0000-a925-f3c8700c0000 pid=3184 execve guuid=14677829-1f00-0000-a925-f3c8720c0000 pid=3186 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=14677829-1f00-0000-a925-f3c8720c0000 pid=3186 execve guuid=f7b8bf29-1f00-0000-a925-f3c8740c0000 pid=3188 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=f7b8bf29-1f00-0000-a925-f3c8740c0000 pid=3188 execve guuid=b3c7642c-1f00-0000-a925-f3c87d0c0000 pid=3197 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=b3c7642c-1f00-0000-a925-f3c87d0c0000 pid=3197 execve guuid=71c9d22f-1f00-0000-a925-f3c8870c0000 pid=3207 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=71c9d22f-1f00-0000-a925-f3c8870c0000 pid=3207 execve guuid=29fd1630-1f00-0000-a925-f3c8890c0000 pid=3209 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=29fd1630-1f00-0000-a925-f3c8890c0000 pid=3209 clone guuid=18967230-1f00-0000-a925-f3c88c0c0000 pid=3212 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=18967230-1f00-0000-a925-f3c88c0c0000 pid=3212 execve guuid=183eb930-1f00-0000-a925-f3c88e0c0000 pid=3214 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=183eb930-1f00-0000-a925-f3c88e0c0000 pid=3214 execve guuid=98ed0231-1f00-0000-a925-f3c8900c0000 pid=3216 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=98ed0231-1f00-0000-a925-f3c8900c0000 pid=3216 execve guuid=20b18433-1f00-0000-a925-f3c89a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=20b18433-1f00-0000-a925-f3c89a0c0000 pid=3226 execve guuid=4638ba36-1f00-0000-a925-f3c8a60c0000 pid=3238 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=4638ba36-1f00-0000-a925-f3c8a60c0000 pid=3238 execve guuid=c5c70037-1f00-0000-a925-f3c8a80c0000 pid=3240 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=c5c70037-1f00-0000-a925-f3c8a80c0000 pid=3240 clone guuid=051d4637-1f00-0000-a925-f3c8ad0c0000 pid=3245 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=051d4637-1f00-0000-a925-f3c8ad0c0000 pid=3245 execve guuid=d33bb337-1f00-0000-a925-f3c8ae0c0000 pid=3246 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=d33bb337-1f00-0000-a925-f3c8ae0c0000 pid=3246 execve guuid=31d2fb37-1f00-0000-a925-f3c8af0c0000 pid=3247 /usr/bin/wget net send-data guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=31d2fb37-1f00-0000-a925-f3c8af0c0000 pid=3247 execve guuid=08eef63a-1f00-0000-a925-f3c8b90c0000 pid=3257 /usr/bin/curl net send-data write-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=08eef63a-1f00-0000-a925-f3c8b90c0000 pid=3257 execve guuid=38e8783f-1f00-0000-a925-f3c8c20c0000 pid=3266 /usr/bin/chmod guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=38e8783f-1f00-0000-a925-f3c8c20c0000 pid=3266 execve guuid=4d82de3f-1f00-0000-a925-f3c8c30c0000 pid=3267 /usr/bin/bash guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=4d82de3f-1f00-0000-a925-f3c8c30c0000 pid=3267 clone guuid=a8ba2a40-1f00-0000-a925-f3c8c50c0000 pid=3269 /usr/bin/rm delete-file guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=a8ba2a40-1f00-0000-a925-f3c8c50c0000 pid=3269 execve guuid=9adc7a40-1f00-0000-a925-f3c8c70c0000 pid=3271 /usr/bin/rm guuid=0c380fbb-1e00-0000-a925-f3c8750b0000 pid=2933->guuid=9adc7a40-1f00-0000-a925-f3c8c70c0000 pid=3271 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=951b75bb-1e00-0000-a925-f3c8760b0000 pid=2934->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=d6c563c1-1e00-0000-a925-f3c8810b0000 pid=2945->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=65ed2be5-1e00-0000-a925-f3c88c0b0000 pid=2956 /usr/bin/bash guuid=4a78f4e4-1e00-0000-a925-f3c88b0b0000 pid=2955->guuid=65ed2be5-1e00-0000-a925-f3c88c0b0000 pid=2956 clone guuid=968deee5-1e00-0000-a925-f3c8910b0000 pid=2961->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=46026be8-1e00-0000-a925-f3c8980b0000 pid=2968->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=dde769ec-1e00-0000-a925-f3c8a40b0000 pid=2980 /usr/bin/bash guuid=2c4e4eec-1e00-0000-a925-f3c8a20b0000 pid=2978->guuid=dde769ec-1e00-0000-a925-f3c8a40b0000 pid=2980 clone guuid=6b1918ed-1e00-0000-a925-f3c8a90b0000 pid=2985->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=19b1a1ef-1e00-0000-a925-f3c8ae0b0000 pid=2990->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e2c3c3f4-1e00-0000-a925-f3c8bb0b0000 pid=3003 /usr/bin/bash guuid=13d3a7f4-1e00-0000-a925-f3c8ba0b0000 pid=3002->guuid=e2c3c3f4-1e00-0000-a925-f3c8bb0b0000 pid=3003 clone guuid=96cb7ff5-1e00-0000-a925-f3c8c00b0000 pid=3008->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=785fbcf8-1e00-0000-a925-f3c8c80b0000 pid=3016->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=cc1144fe-1e00-0000-a925-f3c8d90b0000 pid=3033 /usr/bin/bash guuid=aa3025fe-1e00-0000-a925-f3c8d70b0000 pid=3031->guuid=cc1144fe-1e00-0000-a925-f3c8d90b0000 pid=3033 clone guuid=d3160fff-1e00-0000-a925-f3c8de0b0000 pid=3038->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=62ffc401-1f00-0000-a925-f3c8e40b0000 pid=3044->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=fa6ab605-1f00-0000-a925-f3c8ef0b0000 pid=3055 /usr/bin/bash guuid=5bbc9905-1f00-0000-a925-f3c8ee0b0000 pid=3054->guuid=fa6ab605-1f00-0000-a925-f3c8ef0b0000 pid=3055 clone guuid=4b4da806-1f00-0000-a925-f3c8f60b0000 pid=3062->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=25454f09-1f00-0000-a925-f3c8fd0b0000 pid=3069->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=3d3eed0f-1f00-0000-a925-f3c8120c0000 pid=3090 /usr/bin/bash guuid=3494d30f-1f00-0000-a925-f3c8110c0000 pid=3089->guuid=3d3eed0f-1f00-0000-a925-f3c8120c0000 pid=3090 clone guuid=54c2d810-1f00-0000-a925-f3c8180c0000 pid=3096->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=64635013-1f00-0000-a925-f3c8220c0000 pid=3106->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a8cb4118-1f00-0000-a925-f3c8320c0000 pid=3122 /usr/bin/bash guuid=f1572c18-1f00-0000-a925-f3c8310c0000 pid=3121->guuid=a8cb4118-1f00-0000-a925-f3c8320c0000 pid=3122 clone guuid=39f90419-1f00-0000-a925-f3c8370c0000 pid=3127->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=113ac01b-1f00-0000-a925-f3c8410c0000 pid=3137->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b836a321-1f00-0000-a925-f3c8560c0000 pid=3158 /usr/bin/bash guuid=d4b38721-1f00-0000-a925-f3c8550c0000 pid=3157->guuid=b836a321-1f00-0000-a925-f3c8560c0000 pid=3158 clone guuid=6ae06722-1f00-0000-a925-f3c8590c0000 pid=3161->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=5653f124-1f00-0000-a925-f3c8600c0000 pid=3168->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=d2920a29-1f00-0000-a925-f3c86f0c0000 pid=3183 /usr/bin/bash guuid=6788f028-1f00-0000-a925-f3c86e0c0000 pid=3182->guuid=d2920a29-1f00-0000-a925-f3c86f0c0000 pid=3183 clone guuid=f7b8bf29-1f00-0000-a925-f3c8740c0000 pid=3188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=b3c7642c-1f00-0000-a925-f3c87d0c0000 pid=3197->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=b6b73330-1f00-0000-a925-f3c88a0c0000 pid=3210 /usr/bin/bash guuid=29fd1630-1f00-0000-a925-f3c8890c0000 pid=3209->guuid=b6b73330-1f00-0000-a925-f3c88a0c0000 pid=3210 clone guuid=98ed0231-1f00-0000-a925-f3c8900c0000 pid=3216->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=20b18433-1f00-0000-a925-f3c89a0c0000 pid=3226->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=14be2537-1f00-0000-a925-f3c8ac0c0000 pid=3244 /usr/bin/bash guuid=c5c70037-1f00-0000-a925-f3c8a80c0000 pid=3240->guuid=14be2537-1f00-0000-a925-f3c8ac0c0000 pid=3244 clone guuid=31d2fb37-1f00-0000-a925-f3c8af0c0000 pid=3247->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=08eef63a-1f00-0000-a925-f3c8b90c0000 pid=3257->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=95e10040-1f00-0000-a925-f3c8c40c0000 pid=3268 /usr/bin/bash guuid=4d82de3f-1f00-0000-a925-f3c8c30c0000 pid=3267->guuid=95e10040-1f00-0000-a925-f3c8c40c0000 pid=3268 clone
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-17 02:30:44 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Contacts a large (780) amount of remote hosts
Creates a large amount of network flows
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 94649e2369719ae4e2c4b49d6a30f8dfdbb6cc097bffd2ecef6831998300368c

(this sample)

  
Delivery method
Distributed via web download

Comments