MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a23fbf034154fb243d6f8971eb5da56a214f2ca58635a9bd1f6bd6d00e371916. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: a23fbf034154fb243d6f8971eb5da56a214f2ca58635a9bd1f6bd6d00e371916
SHA3-384 hash: c2ee01cdc96d22acb674089a8e1ca7fb8e815c14f5dd09a0826a226c305c147cdaadda0d3a5028b9ed59ae8b73104643
SHA1 hash: 82d7ebae0d6e4d310be8c51b6e5b7ab2de6d8bd2
MD5 hash: 6461bcafd685ffe7c9e211780bb31ff4
humanhash: venus-stairway-equal-fillet
File name:asus.sh
Download: download sample
Signature Mirai
File size:3'037 bytes
First seen:2025-12-24 12:21:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:BLsSlfNjxFiVOyoOVTKJFgDRX7RoNgmG9/BKd6iSQWrT/m:djxHyoOVTKJFgDRX7RoNgmDd6ipWri
TLSH T1BB51E4CE2175203ABC548AEDE6A3DAF3BACF4F74D88508C4C4E76455347C58EA8E8E11
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://81.88.18.108/bins/shadow.x866e01176ce19a409441cadb631f5f0c9b51705a99ebeac50cfae65de383b2e4d4 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.mips7a84fe422301a21cbbb8dd3cdc0e643ee0b9c1aadffa8c57398fd62ea4b58c4b Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.mpsl7a1849017c0684337d85b2aa8a730c4fee62486f444c675e8414b97c50cfb5a8 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.armeb9e1cf68eb14e4adcdfa704496393a5650750460d44a27fc6810a8fb943c18d Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm54d5a9a2f2e81daf2490c91bbc8f8a9363cea14da81749fa0131ba80512542b30 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm601a6e4d8e80b7090e1287238fce08de7bf135d537438845cbb3283f0c17f2d95 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm7a9e36e6d5c7b89b86270b0ea4d1363cd83e1f8efdabd7331c76ce3e1c64a3539 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.ppc72f8dcac376fa2861c1a6591953d2c4ad3eed9c634938b3a04388603121ac424 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.sh49db2cdc377de44600f2bd4ea70114ef56ca00c876e0577899288782fd8b11fbd Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.x86_647c4d404b0e75f2e8a13e6d396544a04667a28b0d73f2baf2ee11d715d09c52e1 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm645ee3a4aec9a92a62c5d308a2ec541372ab4bacf3fa05e833d880935cf46d0721 Miraiarm elf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-22T22:15:00Z UTC
Last seen:
2025-12-24T02:28:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=a5e7140b-1a00-0000-a08c-65823b090000 pid=2363 /usr/bin/sudo guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366 /tmp/sample.bin guuid=a5e7140b-1a00-0000-a08c-65823b090000 pid=2363->guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366 execve guuid=0d71360e-1a00-0000-a08c-658240090000 pid=2368 /usr/bin/killall guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=0d71360e-1a00-0000-a08c-658240090000 pid=2368 execve guuid=a56c0e0f-1a00-0000-a08c-658243090000 pid=2371 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=a56c0e0f-1a00-0000-a08c-658243090000 pid=2371 execve guuid=ded2450f-1a00-0000-a08c-658245090000 pid=2373 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=ded2450f-1a00-0000-a08c-658245090000 pid=2373 execve guuid=4f81b816-1a00-0000-a08c-658256090000 pid=2390 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=4f81b816-1a00-0000-a08c-658256090000 pid=2390 execve guuid=3e5f0d17-1a00-0000-a08c-658257090000 pid=2391 /tmp/shadow.x86 delete-file net guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3e5f0d17-1a00-0000-a08c-658257090000 pid=2391 execve guuid=3d5d1917-1a00-0000-a08c-658258090000 pid=2392 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3d5d1917-1a00-0000-a08c-658258090000 pid=2392 execve guuid=07ce5a53-1a00-0000-a08c-6582a3090000 pid=2467 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=07ce5a53-1a00-0000-a08c-6582a3090000 pid=2467 execve guuid=5813ac53-1a00-0000-a08c-6582a4090000 pid=2468 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=5813ac53-1a00-0000-a08c-6582a4090000 pid=2468 execve guuid=0ae6f653-1a00-0000-a08c-6582a5090000 pid=2469 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=0ae6f653-1a00-0000-a08c-6582a5090000 pid=2469 execve guuid=fee04b59-1a00-0000-a08c-6582b2090000 pid=2482 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=fee04b59-1a00-0000-a08c-6582b2090000 pid=2482 execve guuid=66e3f359-1a00-0000-a08c-6582b5090000 pid=2485 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=66e3f359-1a00-0000-a08c-6582b5090000 pid=2485 clone guuid=fedaf959-1a00-0000-a08c-6582b6090000 pid=2486 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=fedaf959-1a00-0000-a08c-6582b6090000 pid=2486 execve guuid=4c6af595-1a00-0000-a08c-6582430a0000 pid=2627 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=4c6af595-1a00-0000-a08c-6582430a0000 pid=2627 execve guuid=30205f96-1a00-0000-a08c-6582450a0000 pid=2629 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=30205f96-1a00-0000-a08c-6582450a0000 pid=2629 execve guuid=f2f7b696-1a00-0000-a08c-6582470a0000 pid=2631 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=f2f7b696-1a00-0000-a08c-6582470a0000 pid=2631 execve guuid=1b0b6b9b-1a00-0000-a08c-6582540a0000 pid=2644 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=1b0b6b9b-1a00-0000-a08c-6582540a0000 pid=2644 execve guuid=036ca69b-1a00-0000-a08c-6582560a0000 pid=2646 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=036ca69b-1a00-0000-a08c-6582560a0000 pid=2646 clone guuid=abb9a89b-1a00-0000-a08c-6582570a0000 pid=2647 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=abb9a89b-1a00-0000-a08c-6582570a0000 pid=2647 execve guuid=bf8181d7-1a00-0000-a08c-6582f20a0000 pid=2802 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=bf8181d7-1a00-0000-a08c-6582f20a0000 pid=2802 execve guuid=fdb9c0d7-1a00-0000-a08c-6582f40a0000 pid=2804 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=fdb9c0d7-1a00-0000-a08c-6582f40a0000 pid=2804 execve guuid=ba7afed7-1a00-0000-a08c-6582f50a0000 pid=2805 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=ba7afed7-1a00-0000-a08c-6582f50a0000 pid=2805 execve guuid=26b34fdc-1a00-0000-a08c-6582010b0000 pid=2817 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=26b34fdc-1a00-0000-a08c-6582010b0000 pid=2817 execve guuid=6ff4a0dc-1a00-0000-a08c-6582020b0000 pid=2818 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=6ff4a0dc-1a00-0000-a08c-6582020b0000 pid=2818 clone guuid=3d8fa4dc-1a00-0000-a08c-6582040b0000 pid=2820 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3d8fa4dc-1a00-0000-a08c-6582040b0000 pid=2820 execve guuid=69ec8118-1b00-0000-a08c-65828a0b0000 pid=2954 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=69ec8118-1b00-0000-a08c-65828a0b0000 pid=2954 execve guuid=ebc9c118-1b00-0000-a08c-65828c0b0000 pid=2956 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=ebc9c118-1b00-0000-a08c-65828c0b0000 pid=2956 execve guuid=5fce2819-1b00-0000-a08c-65828e0b0000 pid=2958 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=5fce2819-1b00-0000-a08c-65828e0b0000 pid=2958 execve guuid=1309761d-1b00-0000-a08c-6582970b0000 pid=2967 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=1309761d-1b00-0000-a08c-6582970b0000 pid=2967 execve guuid=3551b91d-1b00-0000-a08c-6582990b0000 pid=2969 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3551b91d-1b00-0000-a08c-6582990b0000 pid=2969 clone guuid=b227be1d-1b00-0000-a08c-65829a0b0000 pid=2970 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=b227be1d-1b00-0000-a08c-65829a0b0000 pid=2970 execve guuid=e5d0b959-1b00-0000-a08c-6582280c0000 pid=3112 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=e5d0b959-1b00-0000-a08c-6582280c0000 pid=3112 execve guuid=6bab425a-1b00-0000-a08c-65822a0c0000 pid=3114 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=6bab425a-1b00-0000-a08c-65822a0c0000 pid=3114 execve guuid=8e66945a-1b00-0000-a08c-65822c0c0000 pid=3116 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=8e66945a-1b00-0000-a08c-65822c0c0000 pid=3116 execve guuid=5739535f-1b00-0000-a08c-6582370c0000 pid=3127 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=5739535f-1b00-0000-a08c-6582370c0000 pid=3127 execve guuid=fc00ab5f-1b00-0000-a08c-65823a0c0000 pid=3130 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=fc00ab5f-1b00-0000-a08c-65823a0c0000 pid=3130 clone guuid=a704af5f-1b00-0000-a08c-65823b0c0000 pid=3131 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=a704af5f-1b00-0000-a08c-65823b0c0000 pid=3131 execve guuid=d8c0b69b-1b00-0000-a08c-6582b80c0000 pid=3256 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=d8c0b69b-1b00-0000-a08c-6582b80c0000 pid=3256 execve guuid=6542179c-1b00-0000-a08c-6582b90c0000 pid=3257 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=6542179c-1b00-0000-a08c-6582b90c0000 pid=3257 execve guuid=f5985f9c-1b00-0000-a08c-6582ba0c0000 pid=3258 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=f5985f9c-1b00-0000-a08c-6582ba0c0000 pid=3258 execve guuid=ae956aa1-1b00-0000-a08c-6582c80c0000 pid=3272 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=ae956aa1-1b00-0000-a08c-6582c80c0000 pid=3272 execve guuid=66de08a2-1b00-0000-a08c-6582ca0c0000 pid=3274 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=66de08a2-1b00-0000-a08c-6582ca0c0000 pid=3274 clone guuid=b37c0ea2-1b00-0000-a08c-6582cb0c0000 pid=3275 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=b37c0ea2-1b00-0000-a08c-6582cb0c0000 pid=3275 execve guuid=66de2cde-1b00-0000-a08c-6582390d0000 pid=3385 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=66de2cde-1b00-0000-a08c-6582390d0000 pid=3385 execve guuid=1058eade-1b00-0000-a08c-65823b0d0000 pid=3387 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=1058eade-1b00-0000-a08c-65823b0d0000 pid=3387 execve guuid=ee7a3ddf-1b00-0000-a08c-65823c0d0000 pid=3388 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=ee7a3ddf-1b00-0000-a08c-65823c0d0000 pid=3388 execve guuid=396f69e4-1b00-0000-a08c-6582450d0000 pid=3397 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=396f69e4-1b00-0000-a08c-6582450d0000 pid=3397 execve guuid=6604ade4-1b00-0000-a08c-6582470d0000 pid=3399 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=6604ade4-1b00-0000-a08c-6582470d0000 pid=3399 clone guuid=a448b1e4-1b00-0000-a08c-6582480d0000 pid=3400 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=a448b1e4-1b00-0000-a08c-6582480d0000 pid=3400 execve guuid=19d88520-1c00-0000-a08c-6582e00d0000 pid=3552 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=19d88520-1c00-0000-a08c-6582e00d0000 pid=3552 execve guuid=e0b0eb20-1c00-0000-a08c-6582e20d0000 pid=3554 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=e0b0eb20-1c00-0000-a08c-6582e20d0000 pid=3554 execve guuid=4fa24521-1c00-0000-a08c-6582e40d0000 pid=3556 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=4fa24521-1c00-0000-a08c-6582e40d0000 pid=3556 execve guuid=3396c925-1c00-0000-a08c-6582eb0d0000 pid=3563 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3396c925-1c00-0000-a08c-6582eb0d0000 pid=3563 execve guuid=94411c26-1c00-0000-a08c-6582ed0d0000 pid=3565 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=94411c26-1c00-0000-a08c-6582ed0d0000 pid=3565 clone guuid=3c532126-1c00-0000-a08c-6582ee0d0000 pid=3566 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3c532126-1c00-0000-a08c-6582ee0d0000 pid=3566 execve guuid=9b7d0862-1c00-0000-a08c-6582780e0000 pid=3704 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=9b7d0862-1c00-0000-a08c-6582780e0000 pid=3704 execve guuid=d5786c62-1c00-0000-a08c-65827a0e0000 pid=3706 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=d5786c62-1c00-0000-a08c-65827a0e0000 pid=3706 execve guuid=0562fc62-1c00-0000-a08c-65827d0e0000 pid=3709 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=0562fc62-1c00-0000-a08c-65827d0e0000 pid=3709 execve guuid=b6a69d67-1c00-0000-a08c-65828d0e0000 pid=3725 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=b6a69d67-1c00-0000-a08c-65828d0e0000 pid=3725 execve guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726 /tmp/shadow.x86_64 delete-file net send-data zombie guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726 execve guuid=4f43de67-1c00-0000-a08c-65828f0e0000 pid=3727 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=4f43de67-1c00-0000-a08c-65828f0e0000 pid=3727 execve guuid=5517c3a3-1c00-0000-a08c-6582300f0000 pid=3888 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=5517c3a3-1c00-0000-a08c-6582300f0000 pid=3888 execve guuid=3f7b3fa4-1c00-0000-a08c-6582320f0000 pid=3890 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=3f7b3fa4-1c00-0000-a08c-6582320f0000 pid=3890 execve guuid=923eb7a4-1c00-0000-a08c-6582340f0000 pid=3892 /usr/bin/wget net send-data write-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=923eb7a4-1c00-0000-a08c-6582340f0000 pid=3892 execve guuid=fad9ecab-1c00-0000-a08c-65824a0f0000 pid=3914 /usr/bin/chmod guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=fad9ecab-1c00-0000-a08c-65824a0f0000 pid=3914 execve guuid=d1a052ac-1c00-0000-a08c-65824c0f0000 pid=3916 /usr/bin/dash guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=d1a052ac-1c00-0000-a08c-65824c0f0000 pid=3916 clone guuid=159a5eac-1c00-0000-a08c-65824e0f0000 pid=3918 /usr/bin/sleep guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=159a5eac-1c00-0000-a08c-65824e0f0000 pid=3918 execve guuid=836294e8-1c00-0000-a08c-6582f00f0000 pid=4080 /usr/bin/rm delete-file guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=836294e8-1c00-0000-a08c-6582f00f0000 pid=4080 execve guuid=81871ae9-1c00-0000-a08c-6582f40f0000 pid=4084 /usr/bin/rm guuid=1b4fdd0d-1a00-0000-a08c-65823e090000 pid=2366->guuid=81871ae9-1c00-0000-a08c-6582f40f0000 pid=4084 execve eeec4aa2-e72a-5b27-bcb1-92cd6476f418 81.88.18.108:80 guuid=ded2450f-1a00-0000-a08c-658245090000 pid=2373->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3e5f0d17-1a00-0000-a08c-658257090000 pid=2391->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7ae55417-1a00-0000-a08c-658259090000 pid=2393 /tmp/shadow.x86 write-file zombie guuid=3e5f0d17-1a00-0000-a08c-658257090000 pid=2391->guuid=7ae55417-1a00-0000-a08c-658259090000 pid=2393 clone guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394 /tmp/shadow.x86 dns net send-data guuid=7ae55417-1a00-0000-a08c-658259090000 pid=2393->guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394 clone guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394->54d92a3b-1447-55af-b534-047898c60c8d send: 26B c610bf36-1f00-5bc3-ae18-24f0473b35c2 81.88.18.108:6767 guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 9B guuid=fb337a17-1a00-0000-a08c-65825b090000 pid=2395 /tmp/shadow.x86 guuid=98436c17-1a00-0000-a08c-65825a090000 pid=2394->guuid=fb337a17-1a00-0000-a08c-65825b090000 pid=2395 clone guuid=0ae6f653-1a00-0000-a08c-6582a5090000 pid=2469->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=f2f7b696-1a00-0000-a08c-6582470a0000 pid=2631->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=ba7afed7-1a00-0000-a08c-6582f50a0000 pid=2805->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=5fce2819-1b00-0000-a08c-65828e0b0000 pid=2958->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=8e66945a-1b00-0000-a08c-65822c0c0000 pid=3116->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=f5985f9c-1b00-0000-a08c-6582ba0c0000 pid=3258->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=ee7a3ddf-1b00-0000-a08c-65823c0d0000 pid=3388->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=4fa24521-1c00-0000-a08c-6582e40d0000 pid=3556->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=0562fc62-1c00-0000-a08c-65827d0e0000 pid=3709->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 145B guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ff25191-b423-5251-a735-2378c22ab12a 0.0.0.0:48101 guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726->8ff25191-b423-5251-a735-2378c22ab12a con 230551d6-3124-51d2-b63c-f814e1d0d1f9 127.0.0.1:48101 guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726->230551d6-3124-51d2-b63c-f814e1d0d1f9 send: 4B guuid=ad0e3f93-1d00-0000-a08c-6582e8110000 pid=4584 /tmp/shadow.x86_64 write-file zombie guuid=15a5d967-1c00-0000-a08c-65828e0e0000 pid=3726->guuid=ad0e3f93-1d00-0000-a08c-6582e8110000 pid=4584 clone guuid=923eb7a4-1c00-0000-a08c-6582340f0000 pid=3892->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 144B guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585 /tmp/shadow.x86_64 dns net send-data guuid=ad0e3f93-1d00-0000-a08c-6582e8110000 pid=4584->guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585 clone guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585->54d92a3b-1447-55af-b534-047898c60c8d send: 26B guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 11B guuid=cda35393-1d00-0000-a08c-6582ea110000 pid=4586 /tmp/shadow.x86_64 guuid=03284e93-1d00-0000-a08c-6582e9110000 pid=4585->guuid=cda35393-1d00-0000-a08c-6582ea110000 pid=4586 clone
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-12-23 03:21:37 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a23fbf034154fb243d6f8971eb5da56a214f2ca58635a9bd1f6bd6d00e371916

(this sample)

  
Delivery method
Distributed via web download

Comments