MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad9f4e2c0ab954083fd8f92ca9b4e819ba2ea6c096fdd47e912ea6066592e724. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: ad9f4e2c0ab954083fd8f92ca9b4e819ba2ea6c096fdd47e912ea6066592e724
SHA3-384 hash: 8765918aca43556bc63f19edc061f729397f7b5cb9f18b1d9d9d6eadacde0f403e39bb1cacea73d8e7bba1e80f8f4324
SHA1 hash: 785e057766e0b7f38478112f9564b62482130197
MD5 hash: 1c6dc286f66b5d50576f4091a94b0562
humanhash: salami-thirteen-diet-comet
File name:ok
Download: download sample
Signature Mirai
File size:1'608 bytes
First seen:2026-06-06 17:08:23 UTC
Last seen:2026-06-07 09:03:39 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5GxrG2223cGmr1fMWPGTHrPGTtKBlyrV4xr4oY+YYDrHHC3sracinriuyEoHCzoX:0E25ifMR6ZTuiz0ylGPoPVi9tQy
TLSH T1FD3196AF0B19369C0801ED76B3A12198E4B5DAEE214FD760FF595CBEF1C80483255F0A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/35cdda56163abfecf275a40e2b6a4aea702e2f1ea9d65e4de316a425d3cad688963937 Miraielf mirai ua-wget
http://45.205.1.59/1fbb476e7bd8c8d18f8b22e8606be23e7f73f3fb53fdaf5294e20a79b5290c94294075 Miraielf mirai ua-wget
http://45.205.1.59/2fc2f312283c0fc21a542597f32acb609620860e25fc2edf31e919ced80d1a92680a24 Miraielf mirai ua-wget
http://45.205.1.59/7dc165cc9f61599c20cb015cade6e6daacb69c67712032b89003cbedfceb0ab49335c8 Miraielf mirai ua-wget
http://45.205.1.59/18a84fdb347e049c6eb7dc2a5b63fe0d6c71ee775e77e75b3131834d35e24a43906e69 Miraielf mirai ua-wget
http://45.205.1.59/1bedf9603b6edb14da45403a10552f23f254dcb9e4665e151a0d82d4b3dbc0b4c0d494 Miraielf mirai ua-wget
http://45.205.1.59/f79a438f3ac0def67df4e389797b5dc092ccbadab2ee5f00f347ca544180174f8fbd90 Miraielf mirai ua-wget
http://45.205.1.59/badf9be58df93dd08f29c8565cb3164d0d98164bd9f5aeed817680aed0a8504979cef9 Miraielf mirai ua-wget
http://45.205.1.59/f9460d06662ba903df0638cfe4d0a59165f6c0df842e82ffe51f7e05e043aa7b1e2205 Miraielf mirai ua-wget
http://45.205.1.59/8f4c61a6adbd35f72813ee6adb0d725f55c80c6e439ba89fa1527e3a09472b7a2dc538 Miraielf mirai ua-wget
http://45.205.1.59/4de1fbc91a922543d0cb30e112e0e9d5d475974eab37f764ce172bad0a0f5affa85835 Miraielf mirai ua-wget
http://45.205.1.59/cff527b87570fe382a02b2f3359fe527347b19073222c95adb6bb172144765eb75b822 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
4
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=877af28c-1700-0000-c09b-5764160f0000 pid=3862 /usr/bin/sudo guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873 /tmp/sample.bin guuid=877af28c-1700-0000-c09b-5764160f0000 pid=3862->guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873 execve guuid=add3608f-1700-0000-c09b-5764230f0000 pid=3875 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=add3608f-1700-0000-c09b-5764230f0000 pid=3875 execve guuid=59a059ac-1700-0000-c09b-5764830f0000 pid=3971 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=59a059ac-1700-0000-c09b-5764830f0000 pid=3971 execve guuid=d10516cb-1700-0000-c09b-5764ee0f0000 pid=4078 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d10516cb-1700-0000-c09b-5764ee0f0000 pid=4078 execve guuid=690cadcb-1700-0000-c09b-5764f20f0000 pid=4082 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=690cadcb-1700-0000-c09b-5764f20f0000 pid=4082 clone guuid=9ec766cc-1700-0000-c09b-5764f40f0000 pid=4084 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=9ec766cc-1700-0000-c09b-5764f40f0000 pid=4084 execve guuid=d0bac0cc-1700-0000-c09b-5764f60f0000 pid=4086 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d0bac0cc-1700-0000-c09b-5764f60f0000 pid=4086 execve guuid=3f4614cd-1700-0000-c09b-5764f80f0000 pid=4088 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=3f4614cd-1700-0000-c09b-5764f80f0000 pid=4088 execve guuid=81cc92e9-1700-0000-c09b-576443100000 pid=4163 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=81cc92e9-1700-0000-c09b-576443100000 pid=4163 execve guuid=ab3c0b08-1800-0000-c09b-5764ad100000 pid=4269 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=ab3c0b08-1800-0000-c09b-5764ad100000 pid=4269 execve guuid=edc84f08-1800-0000-c09b-5764ae100000 pid=4270 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=edc84f08-1800-0000-c09b-5764ae100000 pid=4270 clone guuid=d59e8908-1800-0000-c09b-5764b3100000 pid=4275 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d59e8908-1800-0000-c09b-5764b3100000 pid=4275 execve guuid=6a76cc08-1800-0000-c09b-5764b4100000 pid=4276 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=6a76cc08-1800-0000-c09b-5764b4100000 pid=4276 execve guuid=caab0a09-1800-0000-c09b-5764b6100000 pid=4278 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=caab0a09-1800-0000-c09b-5764b6100000 pid=4278 execve guuid=2f21b624-1800-0000-c09b-576404110000 pid=4356 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=2f21b624-1800-0000-c09b-576404110000 pid=4356 execve guuid=9a4c8e44-1800-0000-c09b-576470110000 pid=4464 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=9a4c8e44-1800-0000-c09b-576470110000 pid=4464 execve guuid=0f14ec44-1800-0000-c09b-576471110000 pid=4465 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=0f14ec44-1800-0000-c09b-576471110000 pid=4465 clone guuid=b0ac2f45-1800-0000-c09b-576476110000 pid=4470 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=b0ac2f45-1800-0000-c09b-576476110000 pid=4470 execve guuid=127a8f45-1800-0000-c09b-576478110000 pid=4472 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=127a8f45-1800-0000-c09b-576478110000 pid=4472 execve guuid=a351f845-1800-0000-c09b-57647a110000 pid=4474 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=a351f845-1800-0000-c09b-57647a110000 pid=4474 execve guuid=d5c36a61-1800-0000-c09b-5764d3110000 pid=4563 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d5c36a61-1800-0000-c09b-5764d3110000 pid=4563 execve guuid=d77d477e-1800-0000-c09b-576422120000 pid=4642 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d77d477e-1800-0000-c09b-576422120000 pid=4642 execve guuid=94d3c97e-1800-0000-c09b-576425120000 pid=4645 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=94d3c97e-1800-0000-c09b-576425120000 pid=4645 clone guuid=55531a7f-1800-0000-c09b-576427120000 pid=4647 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=55531a7f-1800-0000-c09b-576427120000 pid=4647 execve guuid=7b29727f-1800-0000-c09b-576429120000 pid=4649 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=7b29727f-1800-0000-c09b-576429120000 pid=4649 execve guuid=d001c57f-1800-0000-c09b-57642a120000 pid=4650 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d001c57f-1800-0000-c09b-57642a120000 pid=4650 execve guuid=1412f59b-1800-0000-c09b-57644a120000 pid=4682 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=1412f59b-1800-0000-c09b-57644a120000 pid=4682 execve guuid=5901b9b8-1800-0000-c09b-5764a3120000 pid=4771 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=5901b9b8-1800-0000-c09b-5764a3120000 pid=4771 execve guuid=dd1519b9-1800-0000-c09b-5764a5120000 pid=4773 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=dd1519b9-1800-0000-c09b-5764a5120000 pid=4773 clone guuid=517451b9-1800-0000-c09b-5764a7120000 pid=4775 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=517451b9-1800-0000-c09b-5764a7120000 pid=4775 execve guuid=cc96b5b9-1800-0000-c09b-5764a9120000 pid=4777 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=cc96b5b9-1800-0000-c09b-5764a9120000 pid=4777 execve guuid=318a0fba-1800-0000-c09b-5764ac120000 pid=4780 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=318a0fba-1800-0000-c09b-5764ac120000 pid=4780 execve guuid=2027cad6-1800-0000-c09b-5764fd120000 pid=4861 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=2027cad6-1800-0000-c09b-5764fd120000 pid=4861 execve guuid=b02c79f5-1800-0000-c09b-57645f130000 pid=4959 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=b02c79f5-1800-0000-c09b-57645f130000 pid=4959 execve guuid=f96ceff5-1800-0000-c09b-576461130000 pid=4961 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=f96ceff5-1800-0000-c09b-576461130000 pid=4961 clone guuid=e1a833f6-1800-0000-c09b-576464130000 pid=4964 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=e1a833f6-1800-0000-c09b-576464130000 pid=4964 execve guuid=ccc87cf6-1800-0000-c09b-576466130000 pid=4966 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=ccc87cf6-1800-0000-c09b-576466130000 pid=4966 execve guuid=dacbc6f6-1800-0000-c09b-576469130000 pid=4969 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=dacbc6f6-1800-0000-c09b-576469130000 pid=4969 execve guuid=42192512-1900-0000-c09b-5764b6130000 pid=5046 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=42192512-1900-0000-c09b-5764b6130000 pid=5046 execve guuid=99d7ae2f-1900-0000-c09b-576415140000 pid=5141 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=99d7ae2f-1900-0000-c09b-576415140000 pid=5141 execve guuid=b4162d30-1900-0000-c09b-576417140000 pid=5143 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=b4162d30-1900-0000-c09b-576417140000 pid=5143 clone guuid=f9898630-1900-0000-c09b-576419140000 pid=5145 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=f9898630-1900-0000-c09b-576419140000 pid=5145 execve guuid=241e1f31-1900-0000-c09b-57641b140000 pid=5147 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=241e1f31-1900-0000-c09b-57641b140000 pid=5147 execve guuid=6c887e31-1900-0000-c09b-57641d140000 pid=5149 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=6c887e31-1900-0000-c09b-57641d140000 pid=5149 execve guuid=740ded4c-1900-0000-c09b-576458140000 pid=5208 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=740ded4c-1900-0000-c09b-576458140000 pid=5208 execve guuid=ad1ce06a-1900-0000-c09b-57648d140000 pid=5261 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=ad1ce06a-1900-0000-c09b-57648d140000 pid=5261 execve guuid=8c93826b-1900-0000-c09b-57648e140000 pid=5262 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=8c93826b-1900-0000-c09b-57648e140000 pid=5262 clone guuid=0607eb6b-1900-0000-c09b-576490140000 pid=5264 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=0607eb6b-1900-0000-c09b-576490140000 pid=5264 execve guuid=014c7d6c-1900-0000-c09b-576491140000 pid=5265 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=014c7d6c-1900-0000-c09b-576491140000 pid=5265 execve guuid=86ebe76c-1900-0000-c09b-576492140000 pid=5266 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=86ebe76c-1900-0000-c09b-576492140000 pid=5266 execve guuid=4d8ff088-1900-0000-c09b-57649e140000 pid=5278 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=4d8ff088-1900-0000-c09b-57649e140000 pid=5278 execve guuid=01d778a6-1900-0000-c09b-57649f140000 pid=5279 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=01d778a6-1900-0000-c09b-57649f140000 pid=5279 execve guuid=cfb8d4a6-1900-0000-c09b-5764a0140000 pid=5280 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=cfb8d4a6-1900-0000-c09b-5764a0140000 pid=5280 clone guuid=5a5169a7-1900-0000-c09b-5764a2140000 pid=5282 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=5a5169a7-1900-0000-c09b-5764a2140000 pid=5282 execve guuid=4e3bbfa7-1900-0000-c09b-5764a3140000 pid=5283 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=4e3bbfa7-1900-0000-c09b-5764a3140000 pid=5283 execve guuid=678512a8-1900-0000-c09b-5764a4140000 pid=5284 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=678512a8-1900-0000-c09b-5764a4140000 pid=5284 execve guuid=a49edcc4-1900-0000-c09b-5764a5140000 pid=5285 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=a49edcc4-1900-0000-c09b-5764a5140000 pid=5285 execve guuid=7229e1e5-1900-0000-c09b-5764a6140000 pid=5286 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=7229e1e5-1900-0000-c09b-5764a6140000 pid=5286 execve guuid=3f9933e7-1900-0000-c09b-5764a7140000 pid=5287 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=3f9933e7-1900-0000-c09b-5764a7140000 pid=5287 clone guuid=3463d9e7-1900-0000-c09b-5764a9140000 pid=5289 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=3463d9e7-1900-0000-c09b-5764a9140000 pid=5289 execve guuid=af7899e8-1900-0000-c09b-5764aa140000 pid=5290 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=af7899e8-1900-0000-c09b-5764aa140000 pid=5290 execve guuid=b6b055e9-1900-0000-c09b-5764ab140000 pid=5291 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=b6b055e9-1900-0000-c09b-5764ab140000 pid=5291 execve guuid=19becc05-1a00-0000-c09b-5764ac140000 pid=5292 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=19becc05-1a00-0000-c09b-5764ac140000 pid=5292 execve guuid=0c839c23-1a00-0000-c09b-5764ad140000 pid=5293 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=0c839c23-1a00-0000-c09b-5764ad140000 pid=5293 execve guuid=b6f3eb23-1a00-0000-c09b-5764ae140000 pid=5294 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=b6f3eb23-1a00-0000-c09b-5764ae140000 pid=5294 clone guuid=2ff63324-1a00-0000-c09b-5764b0140000 pid=5296 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=2ff63324-1a00-0000-c09b-5764b0140000 pid=5296 execve guuid=d0ef8724-1a00-0000-c09b-5764b1140000 pid=5297 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=d0ef8724-1a00-0000-c09b-5764b1140000 pid=5297 execve guuid=e814e824-1a00-0000-c09b-5764b2140000 pid=5298 /usr/bin/wget net send-data guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=e814e824-1a00-0000-c09b-5764b2140000 pid=5298 execve guuid=dd366140-1a00-0000-c09b-5764b3140000 pid=5299 /usr/bin/curl net send-data write-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=dd366140-1a00-0000-c09b-5764b3140000 pid=5299 execve guuid=7cd2e25e-1a00-0000-c09b-5764bb140000 pid=5307 /usr/bin/chmod guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=7cd2e25e-1a00-0000-c09b-5764bb140000 pid=5307 execve guuid=09bf435f-1a00-0000-c09b-5764bc140000 pid=5308 /usr/bin/bash guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=09bf435f-1a00-0000-c09b-5764bc140000 pid=5308 clone guuid=c01dbd5f-1a00-0000-c09b-5764be140000 pid=5310 /usr/bin/rm delete-file guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=c01dbd5f-1a00-0000-c09b-5764be140000 pid=5310 execve guuid=e1b13a60-1a00-0000-c09b-5764bf140000 pid=5311 /usr/bin/rm guuid=9c48068f-1700-0000-c09b-5764210f0000 pid=3873->guuid=e1b13a60-1a00-0000-c09b-5764bf140000 pid=5311 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=add3608f-1700-0000-c09b-5764230f0000 pid=3875->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=59a059ac-1700-0000-c09b-5764830f0000 pid=3971->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=25be2ecc-1700-0000-c09b-5764f30f0000 pid=4083 /usr/bin/bash guuid=690cadcb-1700-0000-c09b-5764f20f0000 pid=4082->guuid=25be2ecc-1700-0000-c09b-5764f30f0000 pid=4083 clone guuid=3f4614cd-1700-0000-c09b-5764f80f0000 pid=4088->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=81cc92e9-1700-0000-c09b-576443100000 pid=4163->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=72f46808-1800-0000-c09b-5764af100000 pid=4271 /usr/bin/bash guuid=edc84f08-1800-0000-c09b-5764ae100000 pid=4270->guuid=72f46808-1800-0000-c09b-5764af100000 pid=4271 clone guuid=caab0a09-1800-0000-c09b-5764b6100000 pid=4278->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=2f21b624-1800-0000-c09b-576404110000 pid=4356->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=84db0e45-1800-0000-c09b-576475110000 pid=4469 /usr/bin/bash guuid=0f14ec44-1800-0000-c09b-576471110000 pid=4465->guuid=84db0e45-1800-0000-c09b-576475110000 pid=4469 clone guuid=a351f845-1800-0000-c09b-57647a110000 pid=4474->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=d5c36a61-1800-0000-c09b-5764d3110000 pid=4563->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=3431f47e-1800-0000-c09b-576426120000 pid=4646 /usr/bin/bash guuid=94d3c97e-1800-0000-c09b-576425120000 pid=4645->guuid=3431f47e-1800-0000-c09b-576426120000 pid=4646 clone guuid=d001c57f-1800-0000-c09b-57642a120000 pid=4650->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=1412f59b-1800-0000-c09b-57644a120000 pid=4682->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=06f12eb9-1800-0000-c09b-5764a6120000 pid=4774 /usr/bin/bash guuid=dd1519b9-1800-0000-c09b-5764a5120000 pid=4773->guuid=06f12eb9-1800-0000-c09b-5764a6120000 pid=4774 clone guuid=318a0fba-1800-0000-c09b-5764ac120000 pid=4780->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=2027cad6-1800-0000-c09b-5764fd120000 pid=4861->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=472f06f6-1800-0000-c09b-576462130000 pid=4962 /usr/bin/bash guuid=f96ceff5-1800-0000-c09b-576461130000 pid=4961->guuid=472f06f6-1800-0000-c09b-576462130000 pid=4962 clone guuid=dacbc6f6-1800-0000-c09b-576469130000 pid=4969->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=42192512-1900-0000-c09b-5764b6130000 pid=5046->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=581e5d30-1900-0000-c09b-576418140000 pid=5144 /usr/bin/bash guuid=b4162d30-1900-0000-c09b-576417140000 pid=5143->guuid=581e5d30-1900-0000-c09b-576418140000 pid=5144 clone guuid=6c887e31-1900-0000-c09b-57641d140000 pid=5149->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=740ded4c-1900-0000-c09b-576458140000 pid=5208->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=fef9b36b-1900-0000-c09b-57648f140000 pid=5263 /usr/bin/bash guuid=8c93826b-1900-0000-c09b-57648e140000 pid=5262->guuid=fef9b36b-1900-0000-c09b-57648f140000 pid=5263 clone guuid=86ebe76c-1900-0000-c09b-576492140000 pid=5266->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4d8ff088-1900-0000-c09b-57649e140000 pid=5278->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=56fc11a7-1900-0000-c09b-5764a1140000 pid=5281 /usr/bin/bash guuid=cfb8d4a6-1900-0000-c09b-5764a0140000 pid=5280->guuid=56fc11a7-1900-0000-c09b-5764a1140000 pid=5281 clone guuid=678512a8-1900-0000-c09b-5764a4140000 pid=5284->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=a49edcc4-1900-0000-c09b-5764a5140000 pid=5285->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=a30d81e7-1900-0000-c09b-5764a8140000 pid=5288 /usr/bin/bash guuid=3f9933e7-1900-0000-c09b-5764a7140000 pid=5287->guuid=a30d81e7-1900-0000-c09b-5764a8140000 pid=5288 clone guuid=b6b055e9-1900-0000-c09b-5764ab140000 pid=5291->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=19becc05-1a00-0000-c09b-5764ac140000 pid=5292->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=6d710c24-1a00-0000-c09b-5764af140000 pid=5295 /usr/bin/bash guuid=b6f3eb23-1a00-0000-c09b-5764ae140000 pid=5294->guuid=6d710c24-1a00-0000-c09b-5764af140000 pid=5295 clone guuid=e814e824-1a00-0000-c09b-5764b2140000 pid=5298->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=dd366140-1a00-0000-c09b-5764b3140000 pid=5299->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=f4276b5f-1a00-0000-c09b-5764bd140000 pid=5309 /usr/bin/bash guuid=09bf435f-1a00-0000-c09b-5764bc140000 pid=5308->guuid=f4276b5f-1a00-0000-c09b-5764bd140000 pid=5309 clone
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-06 17:10:55 UTC
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ad9f4e2c0ab954083fd8f92ca9b4e819ba2ea6c096fdd47e912ea6066592e724

(this sample)

  
Delivery method
Distributed via web download

Comments