MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 98b06255620ffca97cd23a94135f8da4e48233e0998b715005dfbc7df7b02da7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 98b06255620ffca97cd23a94135f8da4e48233e0998b715005dfbc7df7b02da7
SHA3-384 hash: 902b7442c95922c16722a70cfb0d0548bc1257b9beffdcec5f9fe6d7bac3c94b2a28eb426bb9c4e676474707ef5d8a60
SHA1 hash: d03b5bb60d7d0fb952d09843ab171260e4be076a
MD5 hash: 6ddf4992880cad458ad46c0e8dab8226
humanhash: coffee-ink-massachusetts-summer
File name:bins.sh
Download: download sample
File size:324 bytes
First seen:2026-08-11 09:46:45 UTC
Last seen:2026-08-11 10:13:32 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hqyBolfUzB+QFnTAJ3lqLeBsA+TxafpJTxe5plVOCfRX50:8yiRpQFn8J3lfcafpbgpTOsk
TLSH T167E02682341241328ECDD45B415BC498F08221833C817A2CE42B66324A9C1E4F262FA4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.118.132.61/release/n/an/abotnet mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=791b6e7b-1b00-0000-b55d-261778090000 pid=2424 /usr/bin/sudo guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429 /tmp/sample.bin guuid=791b6e7b-1b00-0000-b55d-261778090000 pid=2424->guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429 execve guuid=3fde367d-1b00-0000-b55d-26177f090000 pid=2431 /usr/bin/wget net send-data write-file guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=3fde367d-1b00-0000-b55d-26177f090000 pid=2431 execve guuid=a39e15ce-1b00-0000-b55d-26172b0a0000 pid=2603 /usr/bin/chmod guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=a39e15ce-1b00-0000-b55d-26172b0a0000 pid=2603 execve guuid=81806fce-1b00-0000-b55d-26172d0a0000 pid=2605 /usr/bin/dash guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=81806fce-1b00-0000-b55d-26172d0a0000 pid=2605 clone guuid=b7e9a4cf-1b00-0000-b55d-2617300a0000 pid=2608 /usr/bin/wget net send-data write-file guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=b7e9a4cf-1b00-0000-b55d-2617300a0000 pid=2608 execve guuid=de8d1416-1c00-0000-b55d-2617aa0a0000 pid=2730 /usr/bin/chmod guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=de8d1416-1c00-0000-b55d-2617aa0a0000 pid=2730 execve guuid=7aec5116-1c00-0000-b55d-2617ab0a0000 pid=2731 /usr/bin/dash guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=7aec5116-1c00-0000-b55d-2617ab0a0000 pid=2731 clone guuid=2e76cb16-1c00-0000-b55d-2617ad0a0000 pid=2733 /usr/bin/wget net send-data write-file guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=2e76cb16-1c00-0000-b55d-2617ad0a0000 pid=2733 execve guuid=0386cd5e-1c00-0000-b55d-2617fc0a0000 pid=2812 /usr/bin/chmod guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=0386cd5e-1c00-0000-b55d-2617fc0a0000 pid=2812 execve guuid=6a4f075f-1c00-0000-b55d-2617fe0a0000 pid=2814 /usr/bin/dash guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=6a4f075f-1c00-0000-b55d-2617fe0a0000 pid=2814 clone guuid=f8f6885f-1c00-0000-b55d-2617000b0000 pid=2816 /usr/bin/wget net send-data write-file guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=f8f6885f-1c00-0000-b55d-2617000b0000 pid=2816 execve guuid=58e193a4-1c00-0000-b55d-26173d0b0000 pid=2877 /usr/bin/chmod guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=58e193a4-1c00-0000-b55d-26173d0b0000 pid=2877 execve guuid=7de3fba4-1c00-0000-b55d-26173e0b0000 pid=2878 /usr/bin/dash guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=7de3fba4-1c00-0000-b55d-26173e0b0000 pid=2878 clone guuid=85c0bba5-1c00-0000-b55d-2617430b0000 pid=2883 /usr/bin/wget net send-data write-file guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=85c0bba5-1c00-0000-b55d-2617430b0000 pid=2883 execve guuid=534e37e1-1c00-0000-b55d-2617c30b0000 pid=3011 /usr/bin/chmod guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=534e37e1-1c00-0000-b55d-2617c30b0000 pid=3011 execve guuid=dc727ee1-1c00-0000-b55d-2617c50b0000 pid=3013 /tmp/x86 dns net send-data guuid=8969047d-1b00-0000-b55d-26177d090000 pid=2429->guuid=dc727ee1-1c00-0000-b55d-2617c50b0000 pid=3013 execve 1a27baa6-a77c-559c-974d-a82f396ef47f 64.118.132.61:80 guuid=3fde367d-1b00-0000-b55d-26177f090000 pid=2431->1a27baa6-a77c-559c-974d-a82f396ef47f send: 139B guuid=b7e9a4cf-1b00-0000-b55d-2617300a0000 pid=2608->1a27baa6-a77c-559c-974d-a82f396ef47f send: 140B guuid=2e76cb16-1c00-0000-b55d-2617ad0a0000 pid=2733->1a27baa6-a77c-559c-974d-a82f396ef47f send: 140B guuid=f8f6885f-1c00-0000-b55d-2617000b0000 pid=2816->1a27baa6-a77c-559c-974d-a82f396ef47f send: 140B guuid=85c0bba5-1c00-0000-b55d-2617430b0000 pid=2883->1a27baa6-a77c-559c-974d-a82f396ef47f send: 139B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=dc727ee1-1c00-0000-b55d-2617c50b0000 pid=3013->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 23673f67-ea10-5708-a16a-00f2bddb7291 112.213.35.91:53 guuid=dc727ee1-1c00-0000-b55d-2617c50b0000 pid=3013->23673f67-ea10-5708-a16a-00f2bddb7291 send: 32B 770a0148-5bff-573f-96d1-675a35a7e965 voltagec2.tech:35342 guuid=dc727ee1-1c00-0000-b55d-2617c50b0000 pid=3013->770a0148-5bff-573f-96d1-675a35a7e965 send: 38B
Threat name:
Script-Shell.Browser.MiraiB
Status:
Malicious
First seen:
2026-08-11 09:48:38 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  4/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion linux
Behaviour
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 98b06255620ffca97cd23a94135f8da4e48233e0998b715005dfbc7df7b02da7

(this sample)

  
Delivery method
Distributed via web download

Comments