MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a77bd0ca74b9f7f03088814ecd0a7c3fb31d4ae6ebd6b40f2686a45b50eda87. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 9a77bd0ca74b9f7f03088814ecd0a7c3fb31d4ae6ebd6b40f2686a45b50eda87
SHA3-384 hash: 6301924f7743fc49268513ae848b11d232ef15bc53e300915ffbcd21d0611c359b0bfa0c8208fea963c237c3db3c62d8
SHA1 hash: ec593293c574a90c2812af91b53e004cd1bf7aba
MD5 hash: 0a0bb23a3d81b5fdd515173ee4269427
humanhash: friend-south-fix-georgia
File name:nvr.sh
Download: download sample
Signature Mirai
File size:4'396 bytes
First seen:2026-03-16 17:23:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZbAEtrZFYFWFFFiUMzEUXVVjUY0qIFYFWFFFoZvlp6xEy2guKb0+bcZF6FYFWFF6:ZbAE1twE9CQEK1i
TLSH T1B491E7CC3121982788C68E0CB45AD39753D893A5D9ACC01C55A4FE3B3191FEAB9FAF41
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://88.214.20.14/bins/tuxnokill.x86a9c595b2c94cbcd3c93fdc72705b502080848f45f41a4142ad77c5a5f4326b0b Miraimirai
http://88.214.20.14/bins/tuxnokill.mips3b7d02c7d5fae025badfbb801059183029189d85d00aac04311247e4f5f4030a Miraimirai
http://88.214.20.14/bins/tuxnokill.mpsl234f547c6940b136c16b743950b1b503fffb0fa852b123a107b883a2161b8e5f Miraimirai
http://88.214.20.14/bins/tuxnokill.arm409c149979a739286e87e55f730410fbc14fe39a2685135b21f7cf6f51bcf466 Miraimirai
http://88.214.20.14/bins/tuxnokill.arc557a7680cac8a83c98f5059b6c11dda33df085e931a53817685ad6427645a3c9 Miraimirai
http://88.214.20.14/bins/tuxnokill.arm4n/an/aelf ua-wget
http://88.214.20.14/bins/tuxnokill.arm595d0933e9e2906f5f5df011e5afd2e04161dbac4d4618e0b2ebcee54e91bff5d Miraimirai
http://88.214.20.14/bins/tuxnokill.arm6501776d5ac80fb72e7c11ce98e4b1cfb16615d76293166a864ba05a62e7f4ff3 Miraimirai
http://88.214.20.14/bins/tuxnokill.arm7c6535cc21940b7be719621fd9b791ddbc33d9be9b4ac050a23d8542c82cae9d6 Miraimirai
http://88.214.20.14/bins/tuxnokill.ppc8cff96f1e570b6eae7b433cebaffc9a6d6a32f6927271ed2e5c3e3866f35ef6c Miraimirai
http://88.214.20.14/bins/tuxnokill.m68ka065f1dd35f3bf8f2dc8b25a09273b751fee7a4dba6623b41be874bf42aa5185 Miraimirai
http://88.214.20.14/bins/tuxnokill.sh4ddba21e124054e17b84c367320b1e9dcbc8354c39895b6f1eca489841e8eade0 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
86
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=2cc7a43a-1a00-0000-e1b7-02da44090000 pid=2372 /usr/bin/sudo guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373 /tmp/sample.bin guuid=2cc7a43a-1a00-0000-e1b7-02da44090000 pid=2372->guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373 execve guuid=fa7a103f-1a00-0000-e1b7-02da46090000 pid=2374 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=fa7a103f-1a00-0000-e1b7-02da46090000 pid=2374 execve guuid=3e9f7f43-1a00-0000-e1b7-02da47090000 pid=2375 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=3e9f7f43-1a00-0000-e1b7-02da47090000 pid=2375 execve guuid=edf32744-1a00-0000-e1b7-02da48090000 pid=2376 /home/sandbox/tuxnokill.x86 net guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=edf32744-1a00-0000-e1b7-02da48090000 pid=2376 execve guuid=bd977044-1a00-0000-e1b7-02da4b090000 pid=2379 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=bd977044-1a00-0000-e1b7-02da4b090000 pid=2379 execve guuid=276b6a50-1a00-0000-e1b7-02da4d090000 pid=2381 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=276b6a50-1a00-0000-e1b7-02da4d090000 pid=2381 execve guuid=670cc750-1a00-0000-e1b7-02da4e090000 pid=2382 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=670cc750-1a00-0000-e1b7-02da4e090000 pid=2382 clone guuid=a416d152-1a00-0000-e1b7-02da51090000 pid=2385 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=a416d152-1a00-0000-e1b7-02da51090000 pid=2385 execve guuid=521ce357-1a00-0000-e1b7-02da5c090000 pid=2396 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=521ce357-1a00-0000-e1b7-02da5c090000 pid=2396 execve guuid=61b14358-1a00-0000-e1b7-02da5e090000 pid=2398 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=61b14358-1a00-0000-e1b7-02da5e090000 pid=2398 clone guuid=78efff59-1a00-0000-e1b7-02da63090000 pid=2403 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=78efff59-1a00-0000-e1b7-02da63090000 pid=2403 execve guuid=6cb42c5e-1a00-0000-e1b7-02da6b090000 pid=2411 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=6cb42c5e-1a00-0000-e1b7-02da6b090000 pid=2411 execve guuid=c3f8b85e-1a00-0000-e1b7-02da6c090000 pid=2412 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=c3f8b85e-1a00-0000-e1b7-02da6c090000 pid=2412 clone guuid=2952cf60-1a00-0000-e1b7-02da6f090000 pid=2415 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=2952cf60-1a00-0000-e1b7-02da6f090000 pid=2415 execve guuid=0a155465-1a00-0000-e1b7-02da78090000 pid=2424 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=0a155465-1a00-0000-e1b7-02da78090000 pid=2424 execve guuid=69f1e465-1a00-0000-e1b7-02da79090000 pid=2425 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=69f1e465-1a00-0000-e1b7-02da79090000 pid=2425 clone guuid=bb5df166-1a00-0000-e1b7-02da7c090000 pid=2428 /usr/bin/busybox net send-data guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=bb5df166-1a00-0000-e1b7-02da7c090000 pid=2428 execve guuid=02e72a69-1a00-0000-e1b7-02da82090000 pid=2434 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=02e72a69-1a00-0000-e1b7-02da82090000 pid=2434 execve guuid=cb02436d-1a00-0000-e1b7-02da8e090000 pid=2446 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=cb02436d-1a00-0000-e1b7-02da8e090000 pid=2446 execve guuid=f755af6d-1a00-0000-e1b7-02da90090000 pid=2448 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=f755af6d-1a00-0000-e1b7-02da90090000 pid=2448 clone guuid=a412a56f-1a00-0000-e1b7-02da95090000 pid=2453 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=a412a56f-1a00-0000-e1b7-02da95090000 pid=2453 execve guuid=2adc7d74-1a00-0000-e1b7-02daa2090000 pid=2466 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=2adc7d74-1a00-0000-e1b7-02daa2090000 pid=2466 execve guuid=1bbdec74-1a00-0000-e1b7-02daa4090000 pid=2468 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=1bbdec74-1a00-0000-e1b7-02daa4090000 pid=2468 clone guuid=4e43a675-1a00-0000-e1b7-02daa8090000 pid=2472 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=4e43a675-1a00-0000-e1b7-02daa8090000 pid=2472 execve guuid=af4ba27a-1a00-0000-e1b7-02dab1090000 pid=2481 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=af4ba27a-1a00-0000-e1b7-02dab1090000 pid=2481 execve guuid=9f1de17a-1a00-0000-e1b7-02dab3090000 pid=2483 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=9f1de17a-1a00-0000-e1b7-02dab3090000 pid=2483 clone guuid=0a4b6b7b-1a00-0000-e1b7-02dab7090000 pid=2487 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=0a4b6b7b-1a00-0000-e1b7-02dab7090000 pid=2487 execve guuid=1d446e7f-1a00-0000-e1b7-02dac3090000 pid=2499 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=1d446e7f-1a00-0000-e1b7-02dac3090000 pid=2499 execve guuid=0ecfb27f-1a00-0000-e1b7-02dac5090000 pid=2501 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=0ecfb27f-1a00-0000-e1b7-02dac5090000 pid=2501 clone guuid=25b54f80-1a00-0000-e1b7-02dac8090000 pid=2504 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=25b54f80-1a00-0000-e1b7-02dac8090000 pid=2504 execve guuid=c5ef6a84-1a00-0000-e1b7-02dad4090000 pid=2516 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=c5ef6a84-1a00-0000-e1b7-02dad4090000 pid=2516 execve guuid=1453ad84-1a00-0000-e1b7-02dad5090000 pid=2517 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=1453ad84-1a00-0000-e1b7-02dad5090000 pid=2517 clone guuid=be312686-1a00-0000-e1b7-02dad9090000 pid=2521 /usr/bin/busybox net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=be312686-1a00-0000-e1b7-02dad9090000 pid=2521 execve guuid=6dc91c8f-1a00-0000-e1b7-02dae7090000 pid=2535 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=6dc91c8f-1a00-0000-e1b7-02dae7090000 pid=2535 execve guuid=59638e8f-1a00-0000-e1b7-02dae9090000 pid=2537 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=59638e8f-1a00-0000-e1b7-02dae9090000 pid=2537 clone guuid=91d28491-1a00-0000-e1b7-02daec090000 pid=2540 /usr/bin/wget guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=91d28491-1a00-0000-e1b7-02daec090000 pid=2540 execve guuid=2b65a493-1a00-0000-e1b7-02daf2090000 pid=2546 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=2b65a493-1a00-0000-e1b7-02daf2090000 pid=2546 execve guuid=492cda99-1a00-0000-e1b7-02da030a0000 pid=2563 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=492cda99-1a00-0000-e1b7-02da030a0000 pid=2563 execve guuid=a3d73c9a-1a00-0000-e1b7-02da040a0000 pid=2564 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=a3d73c9a-1a00-0000-e1b7-02da040a0000 pid=2564 clone guuid=493ee09a-1a00-0000-e1b7-02da060a0000 pid=2566 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=493ee09a-1a00-0000-e1b7-02da060a0000 pid=2566 execve guuid=ce616ba0-1a00-0000-e1b7-02da140a0000 pid=2580 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=ce616ba0-1a00-0000-e1b7-02da140a0000 pid=2580 execve guuid=c11dada0-1a00-0000-e1b7-02da160a0000 pid=2582 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=c11dada0-1a00-0000-e1b7-02da160a0000 pid=2582 clone guuid=56d09fa2-1a00-0000-e1b7-02da1b0a0000 pid=2587 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=56d09fa2-1a00-0000-e1b7-02da1b0a0000 pid=2587 execve guuid=d42de4a7-1a00-0000-e1b7-02da240a0000 pid=2596 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=d42de4a7-1a00-0000-e1b7-02da240a0000 pid=2596 execve guuid=7dcd33a8-1a00-0000-e1b7-02da260a0000 pid=2598 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=7dcd33a8-1a00-0000-e1b7-02da260a0000 pid=2598 clone guuid=0864eaa8-1a00-0000-e1b7-02da2a0a0000 pid=2602 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=0864eaa8-1a00-0000-e1b7-02da2a0a0000 pid=2602 execve guuid=02d29bad-1a00-0000-e1b7-02da380a0000 pid=2616 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=02d29bad-1a00-0000-e1b7-02da380a0000 pid=2616 execve guuid=6e9fe4ad-1a00-0000-e1b7-02da3a0a0000 pid=2618 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=6e9fe4ad-1a00-0000-e1b7-02da3a0a0000 pid=2618 clone guuid=3e5692ae-1a00-0000-e1b7-02da3d0a0000 pid=2621 /usr/bin/wget net send-data guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=3e5692ae-1a00-0000-e1b7-02da3d0a0000 pid=2621 execve guuid=d523d0b1-1a00-0000-e1b7-02da460a0000 pid=2630 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=d523d0b1-1a00-0000-e1b7-02da460a0000 pid=2630 execve guuid=fe47d4b6-1a00-0000-e1b7-02da540a0000 pid=2644 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=fe47d4b6-1a00-0000-e1b7-02da540a0000 pid=2644 execve guuid=c78552b7-1a00-0000-e1b7-02da560a0000 pid=2646 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=c78552b7-1a00-0000-e1b7-02da560a0000 pid=2646 clone guuid=f4cba2b8-1a00-0000-e1b7-02da5b0a0000 pid=2651 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=f4cba2b8-1a00-0000-e1b7-02da5b0a0000 pid=2651 execve guuid=bcc3c2bd-1a00-0000-e1b7-02da6b0a0000 pid=2667 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=bcc3c2bd-1a00-0000-e1b7-02da6b0a0000 pid=2667 execve guuid=f3f105be-1a00-0000-e1b7-02da6d0a0000 pid=2669 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=f3f105be-1a00-0000-e1b7-02da6d0a0000 pid=2669 clone guuid=6b3ab2be-1a00-0000-e1b7-02da710a0000 pid=2673 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=6b3ab2be-1a00-0000-e1b7-02da710a0000 pid=2673 execve guuid=aa8fbbc4-1a00-0000-e1b7-02da840a0000 pid=2692 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=aa8fbbc4-1a00-0000-e1b7-02da840a0000 pid=2692 execve guuid=b58c01c5-1a00-0000-e1b7-02da850a0000 pid=2693 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=b58c01c5-1a00-0000-e1b7-02da850a0000 pid=2693 clone guuid=2806a3c5-1a00-0000-e1b7-02da890a0000 pid=2697 /usr/bin/wget net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=2806a3c5-1a00-0000-e1b7-02da890a0000 pid=2697 execve guuid=b816b6ca-1a00-0000-e1b7-02da970a0000 pid=2711 /usr/bin/chmod guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=b816b6ca-1a00-0000-e1b7-02da970a0000 pid=2711 execve guuid=4f57f4ca-1a00-0000-e1b7-02da980a0000 pid=2712 /usr/bin/dash guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=4f57f4ca-1a00-0000-e1b7-02da980a0000 pid=2712 clone guuid=3f2f91cb-1a00-0000-e1b7-02da9a0a0000 pid=2714 /usr/bin/wget net guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=3f2f91cb-1a00-0000-e1b7-02da9a0a0000 pid=2714 execve guuid=623a4dcc-1a00-0000-e1b7-02da9c0a0000 pid=2716 /usr/bin/wget net guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=623a4dcc-1a00-0000-e1b7-02da9c0a0000 pid=2716 execve guuid=e6e408cd-1a00-0000-e1b7-02da9d0a0000 pid=2717 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=e6e408cd-1a00-0000-e1b7-02da9d0a0000 pid=2717 execve guuid=e66419d7-1a00-0000-e1b7-02dab50a0000 pid=2741 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=e66419d7-1a00-0000-e1b7-02dab50a0000 pid=2741 execve guuid=278954de-1a00-0000-e1b7-02dac50a0000 pid=2757 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=278954de-1a00-0000-e1b7-02dac50a0000 pid=2757 execve guuid=abf417e5-1a00-0000-e1b7-02dad40a0000 pid=2772 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=abf417e5-1a00-0000-e1b7-02dad40a0000 pid=2772 execve guuid=c3c4a8ed-1a00-0000-e1b7-02daeb0a0000 pid=2795 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=c3c4a8ed-1a00-0000-e1b7-02daeb0a0000 pid=2795 execve guuid=160b67f3-1a00-0000-e1b7-02dafa0a0000 pid=2810 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=160b67f3-1a00-0000-e1b7-02dafa0a0000 pid=2810 execve guuid=65f584f7-1a00-0000-e1b7-02dafb0a0000 pid=2811 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=65f584f7-1a00-0000-e1b7-02dafb0a0000 pid=2811 execve guuid=8f1afe00-1b00-0000-e1b7-02da090b0000 pid=2825 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=8f1afe00-1b00-0000-e1b7-02da090b0000 pid=2825 execve guuid=b9da1d07-1b00-0000-e1b7-02da170b0000 pid=2839 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=b9da1d07-1b00-0000-e1b7-02da170b0000 pid=2839 execve guuid=d790340e-1b00-0000-e1b7-02da200b0000 pid=2848 /usr/bin/curl net guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=d790340e-1b00-0000-e1b7-02da200b0000 pid=2848 execve guuid=10beb511-1b00-0000-e1b7-02da270b0000 pid=2855 /usr/bin/curl net guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=10beb511-1b00-0000-e1b7-02da270b0000 pid=2855 execve guuid=996c7815-1b00-0000-e1b7-02da2c0b0000 pid=2860 /usr/bin/curl net send-data write-file guuid=c09bc03e-1a00-0000-e1b7-02da45090000 pid=2373->guuid=996c7815-1b00-0000-e1b7-02da2c0b0000 pid=2860 execve 07e21ec3-fc3f-5553-b548-91445caa8634 88.214.20.14:80 guuid=fa7a103f-1a00-0000-e1b7-02da46090000 pid=2374->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=edf32744-1a00-0000-e1b7-02da48090000 pid=2376->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377 /home/sandbox/tuxnokill.x86 net send-data zombie guuid=edf32744-1a00-0000-e1b7-02da48090000 pid=2376->guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377 clone guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5ce35052-8cf1-5e61-9192-ecdca327d1ce 64.89.161.130:44300 guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377->5ce35052-8cf1-5e61-9192-ecdca327d1ce send: 12B guuid=27756d44-1a00-0000-e1b7-02da4a090000 pid=2378 /home/sandbox/tuxnokill.x86 guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377->guuid=27756d44-1a00-0000-e1b7-02da4a090000 pid=2378 clone guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380 /home/sandbox/tuxnokill.x86 net net-scan send-data guuid=02986344-1a00-0000-e1b7-02da49090000 pid=2377->guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380 clone guuid=bd977044-1a00-0000-e1b7-02da4b090000 pid=2379->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e8dc38a8-e357-54b1-8025-6649b5a6dc4a 187.63.229.164:23 guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380->e8dc38a8-e357-54b1-8025-6649b5a6dc4a con guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380|send-data send-data to 4097 IP addresses review logs to see them all guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380->guuid=8a767244-1a00-0000-e1b7-02da4c090000 pid=2380|send-data send guuid=a416d152-1a00-0000-e1b7-02da51090000 pid=2385->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=78efff59-1a00-0000-e1b7-02da63090000 pid=2403->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=2952cf60-1a00-0000-e1b7-02da6f090000 pid=2415->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=bb5df166-1a00-0000-e1b7-02da7c090000 pid=2428->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=02e72a69-1a00-0000-e1b7-02da82090000 pid=2434->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=a412a56f-1a00-0000-e1b7-02da95090000 pid=2453->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=4e43a675-1a00-0000-e1b7-02daa8090000 pid=2472->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=0a4b6b7b-1a00-0000-e1b7-02dab7090000 pid=2487->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=25b54f80-1a00-0000-e1b7-02dac8090000 pid=2504->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=be312686-1a00-0000-e1b7-02dad9090000 pid=2521->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=2b65a493-1a00-0000-e1b7-02daf2090000 pid=2546->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=493ee09a-1a00-0000-e1b7-02da060a0000 pid=2566->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=56d09fa2-1a00-0000-e1b7-02da1b0a0000 pid=2587->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=0864eaa8-1a00-0000-e1b7-02da2a0a0000 pid=2602->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=3e5692ae-1a00-0000-e1b7-02da3d0a0000 pid=2621->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=d523d0b1-1a00-0000-e1b7-02da460a0000 pid=2630->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=f4cba2b8-1a00-0000-e1b7-02da5b0a0000 pid=2651->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=6b3ab2be-1a00-0000-e1b7-02da710a0000 pid=2673->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=2806a3c5-1a00-0000-e1b7-02da890a0000 pid=2697->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=3f2f91cb-1a00-0000-e1b7-02da9a0a0000 pid=2714->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=623a4dcc-1a00-0000-e1b7-02da9c0a0000 pid=2716->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=e6e408cd-1a00-0000-e1b7-02da9d0a0000 pid=2717->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=e66419d7-1a00-0000-e1b7-02dab50a0000 pid=2741->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=278954de-1a00-0000-e1b7-02dac50a0000 pid=2757->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=abf417e5-1a00-0000-e1b7-02dad40a0000 pid=2772->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=c3c4a8ed-1a00-0000-e1b7-02daeb0a0000 pid=2795->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=160b67f3-1a00-0000-e1b7-02dafa0a0000 pid=2810->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=65f584f7-1a00-0000-e1b7-02dafb0a0000 pid=2811->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=8f1afe00-1b00-0000-e1b7-02da090b0000 pid=2825->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=b9da1d07-1b00-0000-e1b7-02da170b0000 pid=2839->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=d790340e-1b00-0000-e1b7-02da200b0000 pid=2848->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=10beb511-1b00-0000-e1b7-02da270b0000 pid=2855->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=996c7815-1b00-0000-e1b7-02da2c0b0000 pid=2860->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (87613) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 9a77bd0ca74b9f7f03088814ecd0a7c3fb31d4ae6ebd6b40f2686a45b50eda87

(this sample)

Comments