MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 acd9ccbdbdc9ede9f179d833be92d2316aad67882a753c79e85de84f928ea44f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: acd9ccbdbdc9ede9f179d833be92d2316aad67882a753c79e85de84f928ea44f
SHA3-384 hash: f2119a0021919ec89f161cb208f29a8b5feec3c978f7abaa15cf79a12d0a17e644491a1152446519c796b9a1587fb57b
SHA1 hash: c9ebd9232a21cd7310634dbc6919fd3552976124
MD5 hash: 5ce3cb3b69b4f74d0f135914b9e5b38b
humanhash: lactose-paris-delta-uncle
File name:milan.sh
Download: download sample
Signature Mirai
File size:855 bytes
First seen:2025-11-13 18:35:13 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:uui1i8ejC7ZX18qt0Fn4QBsUXpIvRffiFl3zUzE1tjhIBsr:uuS7qCRe+8n4Qq7yFxdhIqr
TLSH T1A411E9D5350784B2DDEE9E377562DC90D000E3C9B8C07938E8BB642B1C4676DB45BD59
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://154.6.197.52:6677/bins/arm5d1c47329cd0bab9d5d7d9518869c2ae0d6da0d62a4dc052f07ed3c39057bd2d6 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-13T15:57:00Z UTC
Last seen:
2025-11-15T05:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=911c9171-1a00-0000-bb70-0f67fd0a0000 pid=2813 /usr/bin/sudo guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814 /tmp/sample.bin guuid=911c9171-1a00-0000-bb70-0f67fd0a0000 pid=2813->guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814 execve guuid=a8711875-1a00-0000-bb70-0f67010b0000 pid=2817 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=a8711875-1a00-0000-bb70-0f67010b0000 pid=2817 execve guuid=5d5cd1f1-1a00-0000-bb70-0f67070c0000 pid=3079 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=5d5cd1f1-1a00-0000-bb70-0f67070c0000 pid=3079 execve guuid=2957e56f-1b00-0000-bb70-0f67b80c0000 pid=3256 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=2957e56f-1b00-0000-bb70-0f67b80c0000 pid=3256 execve guuid=36feb39f-1b00-0000-bb70-0f67f60c0000 pid=3318 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=36feb39f-1b00-0000-bb70-0f67f60c0000 pid=3318 execve guuid=4e6140c9-1b00-0000-bb70-0f67270d0000 pid=3367 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=4e6140c9-1b00-0000-bb70-0f67270d0000 pid=3367 execve guuid=66e463f2-1b00-0000-bb70-0f67930d0000 pid=3475 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=66e463f2-1b00-0000-bb70-0f67930d0000 pid=3475 execve guuid=b8ade214-1c00-0000-bb70-0f67ec0d0000 pid=3564 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=b8ade214-1c00-0000-bb70-0f67ec0d0000 pid=3564 execve guuid=8edd1d3e-1c00-0000-bb70-0f674b0e0000 pid=3659 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=8edd1d3e-1c00-0000-bb70-0f674b0e0000 pid=3659 execve guuid=2e216b67-1c00-0000-bb70-0f67b90e0000 pid=3769 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=2e216b67-1c00-0000-bb70-0f67b90e0000 pid=3769 execve guuid=6c4e8392-1c00-0000-bb70-0f67470f0000 pid=3911 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=6c4e8392-1c00-0000-bb70-0f67470f0000 pid=3911 execve guuid=1ff7e3bb-1c00-0000-bb70-0f67ca0f0000 pid=4042 /usr/bin/wget net send-data write-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=1ff7e3bb-1c00-0000-bb70-0f67ca0f0000 pid=4042 execve guuid=56b23fe7-1c00-0000-bb70-0f670c100000 pid=4108 /usr/bin/chmod guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=56b23fe7-1c00-0000-bb70-0f670c100000 pid=4108 execve guuid=61d788e7-1c00-0000-bb70-0f670e100000 pid=4110 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=61d788e7-1c00-0000-bb70-0f670e100000 pid=4110 clone guuid=a2eb91e7-1c00-0000-bb70-0f670f100000 pid=4111 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=a2eb91e7-1c00-0000-bb70-0f670f100000 pid=4111 clone guuid=666597e7-1c00-0000-bb70-0f6710100000 pid=4112 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=666597e7-1c00-0000-bb70-0f6710100000 pid=4112 clone guuid=85209ee7-1c00-0000-bb70-0f6712100000 pid=4114 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=85209ee7-1c00-0000-bb70-0f6712100000 pid=4114 clone guuid=aba3dee7-1c00-0000-bb70-0f6714100000 pid=4116 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=aba3dee7-1c00-0000-bb70-0f6714100000 pid=4116 clone guuid=ee5e0ce8-1c00-0000-bb70-0f6717100000 pid=4119 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=ee5e0ce8-1c00-0000-bb70-0f6717100000 pid=4119 clone guuid=28c787e8-1c00-0000-bb70-0f671c100000 pid=4124 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=28c787e8-1c00-0000-bb70-0f671c100000 pid=4124 clone guuid=6f2c34e9-1c00-0000-bb70-0f6722100000 pid=4130 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=6f2c34e9-1c00-0000-bb70-0f6722100000 pid=4130 clone guuid=676716eb-1c00-0000-bb70-0f672a100000 pid=4138 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=676716eb-1c00-0000-bb70-0f672a100000 pid=4138 clone guuid=07d83eeb-1c00-0000-bb70-0f672b100000 pid=4139 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=07d83eeb-1c00-0000-bb70-0f672b100000 pid=4139 clone guuid=0d512ded-1c00-0000-bb70-0f6734100000 pid=4148 /usr/bin/bash guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=0d512ded-1c00-0000-bb70-0f6734100000 pid=4148 clone guuid=b08f3ded-1c00-0000-bb70-0f6736100000 pid=4150 /usr/bin/sleep guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=b08f3ded-1c00-0000-bb70-0f6736100000 pid=4150 execve guuid=7da94f42-1f00-0000-bb70-0f6797140000 pid=5271 /usr/bin/rm guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=7da94f42-1f00-0000-bb70-0f6797140000 pid=5271 execve guuid=40da9c42-1f00-0000-bb70-0f679a140000 pid=5274 /usr/bin/rm delete-file guuid=5ec0d273-1a00-0000-bb70-0f67fe0a0000 pid=2814->guuid=40da9c42-1f00-0000-bb70-0f679a140000 pid=5274 execve 2734a4d2-125a-529a-8695-e0c6e64d0445 154.6.197.52:6677 guuid=a8711875-1a00-0000-bb70-0f67010b0000 pid=2817->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 140B guuid=5d5cd1f1-1a00-0000-bb70-0f67070c0000 pid=3079->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 140B guuid=2957e56f-1b00-0000-bb70-0f67b80c0000 pid=3256->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=36feb39f-1b00-0000-bb70-0f67f60c0000 pid=3318->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 143B guuid=4e6140c9-1b00-0000-bb70-0f67270d0000 pid=3367->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=66e463f2-1b00-0000-bb70-0f67930d0000 pid=3475->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 140B guuid=b8ade214-1c00-0000-bb70-0f67ec0d0000 pid=3564->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=8edd1d3e-1c00-0000-bb70-0f674b0e0000 pid=3659->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 140B guuid=2e216b67-1c00-0000-bb70-0f67b90e0000 pid=3769->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=6c4e8392-1c00-0000-bb70-0f67470f0000 pid=3911->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=1ff7e3bb-1c00-0000-bb70-0f67ca0f0000 pid=4042->2734a4d2-125a-529a-8695-e0c6e64d0445 send: 141B guuid=faf998e7-1c00-0000-bb70-0f6711100000 pid=4113 /tmp/x86 guuid=61d788e7-1c00-0000-bb70-0f670e100000 pid=4110->guuid=faf998e7-1c00-0000-bb70-0f6711100000 pid=4113 execve guuid=c4811de8-1c00-0000-bb70-0f6719100000 pid=4121 /tmp/x32 guuid=a2eb91e7-1c00-0000-bb70-0f670f100000 pid=4111->guuid=c4811de8-1c00-0000-bb70-0f6719100000 pid=4121 execve guuid=50a966e8-1c00-0000-bb70-0f671b100000 pid=4123 /usr/bin/bash guuid=666597e7-1c00-0000-bb70-0f6710100000 pid=4112->guuid=50a966e8-1c00-0000-bb70-0f671b100000 pid=4123 clone guuid=f511dde7-1c00-0000-bb70-0f6713100000 pid=4115 /tmp/x86 zombie guuid=faf998e7-1c00-0000-bb70-0f6711100000 pid=4113->guuid=f511dde7-1c00-0000-bb70-0f6713100000 pid=4115 clone guuid=0f3eb2e8-1c00-0000-bb70-0f671e100000 pid=4126 /usr/bin/bash guuid=85209ee7-1c00-0000-bb70-0f6712100000 pid=4114->guuid=0f3eb2e8-1c00-0000-bb70-0f671e100000 pid=4126 clone guuid=7eed11e8-1c00-0000-bb70-0f6718100000 pid=4120 /tmp/x86 guuid=f511dde7-1c00-0000-bb70-0f6713100000 pid=4115->guuid=7eed11e8-1c00-0000-bb70-0f6718100000 pid=4120 clone guuid=e7bd00e8-1c00-0000-bb70-0f6716100000 pid=4118 /usr/bin/bash guuid=aba3dee7-1c00-0000-bb70-0f6714100000 pid=4116->guuid=e7bd00e8-1c00-0000-bb70-0f6716100000 pid=4118 clone guuid=94eef7e8-1c00-0000-bb70-0f6720100000 pid=4128 /usr/bin/bash guuid=ee5e0ce8-1c00-0000-bb70-0f6717100000 pid=4119->guuid=94eef7e8-1c00-0000-bb70-0f6720100000 pid=4128 clone guuid=a0e99be9-1c00-0000-bb70-0f6724100000 pid=4132 /tmp/x32 zombie guuid=c4811de8-1c00-0000-bb70-0f6719100000 pid=4121->guuid=a0e99be9-1c00-0000-bb70-0f6724100000 pid=4132 clone guuid=7342a1e8-1c00-0000-bb70-0f671d100000 pid=4125 /usr/bin/bash guuid=28c787e8-1c00-0000-bb70-0f671c100000 pid=4124->guuid=7342a1e8-1c00-0000-bb70-0f671d100000 pid=4125 clone guuid=9971d7e9-1c00-0000-bb70-0f6725100000 pid=4133 /usr/bin/bash guuid=6f2c34e9-1c00-0000-bb70-0f6722100000 pid=4130->guuid=9971d7e9-1c00-0000-bb70-0f6725100000 pid=4133 clone guuid=4d0dffe9-1c00-0000-bb70-0f6729100000 pid=4137 /tmp/x32 guuid=a0e99be9-1c00-0000-bb70-0f6724100000 pid=4132->guuid=4d0dffe9-1c00-0000-bb70-0f6729100000 pid=4137 clone guuid=b60fefec-1c00-0000-bb70-0f6732100000 pid=4146 /usr/bin/bash guuid=676716eb-1c00-0000-bb70-0f672a100000 pid=4138->guuid=b60fefec-1c00-0000-bb70-0f6732100000 pid=4146 clone guuid=a13680eb-1c00-0000-bb70-0f672d100000 pid=4141 /usr/bin/bash guuid=07d83eeb-1c00-0000-bb70-0f672b100000 pid=4139->guuid=a13680eb-1c00-0000-bb70-0f672d100000 pid=4141 clone guuid=4a5b68ed-1c00-0000-bb70-0f6737100000 pid=4151 /usr/bin/bash guuid=0d512ded-1c00-0000-bb70-0f6734100000 pid=4148->guuid=4a5b68ed-1c00-0000-bb70-0f6737100000 pid=4151 clone
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-13 18:36:26 UTC
File Type:
Text (Shell)
AV detection:
12 of 37 (32.43%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh acd9ccbdbdc9ede9f179d833be92d2316aad67882a753c79e85de84f928ea44f

(this sample)

  
Delivery method
Distributed via web download

Comments