MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b67542ebf7ea604cd661298d3e8dfb0e49592ea342267a4c1320363cd0afed50. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: b67542ebf7ea604cd661298d3e8dfb0e49592ea342267a4c1320363cd0afed50
SHA3-384 hash: 3c3cb688853697dccf27a26df3b27cd77d74ff19f6f959f46e0e4f68208340f042002cb7a1f380d657cf74598d0a98cb
SHA1 hash: 00d39e462c1b4ed7e528cac6c07a97075fe2a9f2
MD5 hash: 494c35b1e8cf30ba061b5e8427935c02
humanhash: hawaii-golf-south-xray
File name:ok
Download: download sample
Signature Mirai
File size:1'584 bytes
First seen:2026-06-20 21:09:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:UxL6x5B15j69SOnX76UAgcy6z6iiAVKHx659ZMGlr6XX23w3i63/oJNWI6NWf4y2:eI5B1AnAghKjUGA23aNgmcfzQIW5KXVo
TLSH T18F3181DA01245A396202EFEE77B32548701DC5EB285BC7A5DC4C0EDD52489CCB265BC9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/1380fen/an/aelf ua-wget
http://5.182.210.61/f4081dn/an/aelf ua-wget
http://5.182.210.61/59fa88n/an/aelf ua-wget
http://5.182.210.61/2ebec0n/an/aelf ua-wget
http://5.182.210.61/b6bcbdn/an/aelf ua-wget
http://5.182.210.61/27a229n/an/aelf ua-wget
http://5.182.210.61/e44caan/an/aelf ua-wget
http://5.182.210.61/d4c213n/an/aelf ua-wget
http://5.182.210.61/162d73n/an/aelf ua-wget
http://5.182.210.61/7a8187n/an/aelf ua-wget
http://5.182.210.61/d9cbabn/an/aelf ua-wget
http://5.182.210.61/ae8560n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=a8dc0a61-1900-0000-1f4e-08722d140000 pid=5165 /usr/bin/sudo guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166 /tmp/sample.bin guuid=a8dc0a61-1900-0000-1f4e-08722d140000 pid=5165->guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166 execve guuid=51aba764-1900-0000-1f4e-08722f140000 pid=5167 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=51aba764-1900-0000-1f4e-08722f140000 pid=5167 execve guuid=662c8975-1900-0000-1f4e-087230140000 pid=5168 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=662c8975-1900-0000-1f4e-087230140000 pid=5168 execve guuid=3e339a7e-1900-0000-1f4e-087231140000 pid=5169 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=3e339a7e-1900-0000-1f4e-087231140000 pid=5169 execve guuid=90a9ea7e-1900-0000-1f4e-087232140000 pid=5170 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=90a9ea7e-1900-0000-1f4e-087232140000 pid=5170 clone guuid=fd33287f-1900-0000-1f4e-087234140000 pid=5172 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=fd33287f-1900-0000-1f4e-087234140000 pid=5172 execve guuid=01a0797f-1900-0000-1f4e-087235140000 pid=5173 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=01a0797f-1900-0000-1f4e-087235140000 pid=5173 execve guuid=7631d67f-1900-0000-1f4e-087236140000 pid=5174 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=7631d67f-1900-0000-1f4e-087236140000 pid=5174 execve guuid=05efa182-1900-0000-1f4e-087237140000 pid=5175 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=05efa182-1900-0000-1f4e-087237140000 pid=5175 execve guuid=5b4d3f86-1900-0000-1f4e-087238140000 pid=5176 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=5b4d3f86-1900-0000-1f4e-087238140000 pid=5176 execve guuid=78198f86-1900-0000-1f4e-087239140000 pid=5177 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=78198f86-1900-0000-1f4e-087239140000 pid=5177 clone guuid=fb25cb86-1900-0000-1f4e-08723b140000 pid=5179 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=fb25cb86-1900-0000-1f4e-08723b140000 pid=5179 execve guuid=98131687-1900-0000-1f4e-08723c140000 pid=5180 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=98131687-1900-0000-1f4e-08723c140000 pid=5180 execve guuid=edc05d87-1900-0000-1f4e-08723d140000 pid=5181 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=edc05d87-1900-0000-1f4e-08723d140000 pid=5181 execve guuid=09eaef89-1900-0000-1f4e-08723e140000 pid=5182 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=09eaef89-1900-0000-1f4e-08723e140000 pid=5182 execve guuid=6ac29f8d-1900-0000-1f4e-08723f140000 pid=5183 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=6ac29f8d-1900-0000-1f4e-08723f140000 pid=5183 execve guuid=822ef78d-1900-0000-1f4e-087240140000 pid=5184 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=822ef78d-1900-0000-1f4e-087240140000 pid=5184 clone guuid=ec05018f-1900-0000-1f4e-087242140000 pid=5186 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=ec05018f-1900-0000-1f4e-087242140000 pid=5186 execve guuid=d6b6608f-1900-0000-1f4e-087243140000 pid=5187 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=d6b6608f-1900-0000-1f4e-087243140000 pid=5187 execve guuid=a18fbd8f-1900-0000-1f4e-087244140000 pid=5188 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=a18fbd8f-1900-0000-1f4e-087244140000 pid=5188 execve guuid=caf84f93-1900-0000-1f4e-087245140000 pid=5189 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=caf84f93-1900-0000-1f4e-087245140000 pid=5189 execve guuid=61d40199-1900-0000-1f4e-087246140000 pid=5190 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=61d40199-1900-0000-1f4e-087246140000 pid=5190 execve guuid=c61b5a99-1900-0000-1f4e-087247140000 pid=5191 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=c61b5a99-1900-0000-1f4e-087247140000 pid=5191 clone guuid=b5c7a099-1900-0000-1f4e-087249140000 pid=5193 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=b5c7a099-1900-0000-1f4e-087249140000 pid=5193 execve guuid=6784029a-1900-0000-1f4e-08724a140000 pid=5194 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=6784029a-1900-0000-1f4e-08724a140000 pid=5194 execve guuid=da65579a-1900-0000-1f4e-08724b140000 pid=5195 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=da65579a-1900-0000-1f4e-08724b140000 pid=5195 execve guuid=bdcce79c-1900-0000-1f4e-08724c140000 pid=5196 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=bdcce79c-1900-0000-1f4e-08724c140000 pid=5196 execve guuid=25875ea0-1900-0000-1f4e-08724d140000 pid=5197 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=25875ea0-1900-0000-1f4e-08724d140000 pid=5197 execve guuid=12dbb5a0-1900-0000-1f4e-08724e140000 pid=5198 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=12dbb5a0-1900-0000-1f4e-08724e140000 pid=5198 clone guuid=cc4518a1-1900-0000-1f4e-087250140000 pid=5200 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=cc4518a1-1900-0000-1f4e-087250140000 pid=5200 execve guuid=028b70a1-1900-0000-1f4e-087251140000 pid=5201 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=028b70a1-1900-0000-1f4e-087251140000 pid=5201 execve guuid=53d3d1a1-1900-0000-1f4e-087252140000 pid=5202 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=53d3d1a1-1900-0000-1f4e-087252140000 pid=5202 execve guuid=b6a571a4-1900-0000-1f4e-087253140000 pid=5203 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=b6a571a4-1900-0000-1f4e-087253140000 pid=5203 execve guuid=ad55f2a7-1900-0000-1f4e-087254140000 pid=5204 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=ad55f2a7-1900-0000-1f4e-087254140000 pid=5204 execve guuid=d46a8da8-1900-0000-1f4e-087255140000 pid=5205 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=d46a8da8-1900-0000-1f4e-087255140000 pid=5205 clone guuid=9ad0f0a8-1900-0000-1f4e-087257140000 pid=5207 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=9ad0f0a8-1900-0000-1f4e-087257140000 pid=5207 execve guuid=006a7ba9-1900-0000-1f4e-087258140000 pid=5208 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=006a7ba9-1900-0000-1f4e-087258140000 pid=5208 execve guuid=9bcaf8a9-1900-0000-1f4e-087259140000 pid=5209 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=9bcaf8a9-1900-0000-1f4e-087259140000 pid=5209 execve guuid=330178ad-1900-0000-1f4e-08725a140000 pid=5210 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=330178ad-1900-0000-1f4e-08725a140000 pid=5210 execve guuid=8ba01db2-1900-0000-1f4e-08725b140000 pid=5211 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=8ba01db2-1900-0000-1f4e-08725b140000 pid=5211 execve guuid=0f93ffb2-1900-0000-1f4e-08725c140000 pid=5212 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=0f93ffb2-1900-0000-1f4e-08725c140000 pid=5212 clone guuid=f95c47b3-1900-0000-1f4e-08725e140000 pid=5214 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=f95c47b3-1900-0000-1f4e-08725e140000 pid=5214 execve guuid=c77c97b3-1900-0000-1f4e-08725f140000 pid=5215 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=c77c97b3-1900-0000-1f4e-08725f140000 pid=5215 execve guuid=21a8e7b3-1900-0000-1f4e-087260140000 pid=5216 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=21a8e7b3-1900-0000-1f4e-087260140000 pid=5216 execve guuid=afbd7eb6-1900-0000-1f4e-087261140000 pid=5217 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=afbd7eb6-1900-0000-1f4e-087261140000 pid=5217 execve guuid=604b48ba-1900-0000-1f4e-087262140000 pid=5218 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=604b48ba-1900-0000-1f4e-087262140000 pid=5218 execve guuid=1c819fba-1900-0000-1f4e-087263140000 pid=5219 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=1c819fba-1900-0000-1f4e-087263140000 pid=5219 clone guuid=15a5ddba-1900-0000-1f4e-087265140000 pid=5221 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=15a5ddba-1900-0000-1f4e-087265140000 pid=5221 execve guuid=d81241bb-1900-0000-1f4e-087266140000 pid=5222 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=d81241bb-1900-0000-1f4e-087266140000 pid=5222 execve guuid=df6d99bb-1900-0000-1f4e-087267140000 pid=5223 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=df6d99bb-1900-0000-1f4e-087267140000 pid=5223 execve guuid=679c56be-1900-0000-1f4e-087268140000 pid=5224 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=679c56be-1900-0000-1f4e-087268140000 pid=5224 execve guuid=7f558dc2-1900-0000-1f4e-087269140000 pid=5225 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=7f558dc2-1900-0000-1f4e-087269140000 pid=5225 execve guuid=1a22f1c2-1900-0000-1f4e-08726a140000 pid=5226 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=1a22f1c2-1900-0000-1f4e-08726a140000 pid=5226 clone guuid=32352fc3-1900-0000-1f4e-08726d140000 pid=5229 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=32352fc3-1900-0000-1f4e-08726d140000 pid=5229 execve guuid=eed87fc3-1900-0000-1f4e-08726e140000 pid=5230 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=eed87fc3-1900-0000-1f4e-08726e140000 pid=5230 execve guuid=654ee9c3-1900-0000-1f4e-08726f140000 pid=5231 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=654ee9c3-1900-0000-1f4e-08726f140000 pid=5231 execve guuid=bd51cec6-1900-0000-1f4e-087273140000 pid=5235 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=bd51cec6-1900-0000-1f4e-087273140000 pid=5235 execve guuid=cfea4ecb-1900-0000-1f4e-087277140000 pid=5239 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=cfea4ecb-1900-0000-1f4e-087277140000 pid=5239 execve guuid=e1d8b4cb-1900-0000-1f4e-087278140000 pid=5240 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=e1d8b4cb-1900-0000-1f4e-087278140000 pid=5240 clone guuid=887507cc-1900-0000-1f4e-08727a140000 pid=5242 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=887507cc-1900-0000-1f4e-08727a140000 pid=5242 execve guuid=1bed77cc-1900-0000-1f4e-08727b140000 pid=5243 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=1bed77cc-1900-0000-1f4e-08727b140000 pid=5243 execve guuid=f7cbe7cc-1900-0000-1f4e-08727c140000 pid=5244 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=f7cbe7cc-1900-0000-1f4e-08727c140000 pid=5244 execve guuid=39e047d0-1900-0000-1f4e-08727d140000 pid=5245 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=39e047d0-1900-0000-1f4e-08727d140000 pid=5245 execve guuid=d5d78ad6-1900-0000-1f4e-08727e140000 pid=5246 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=d5d78ad6-1900-0000-1f4e-08727e140000 pid=5246 execve guuid=780af9d6-1900-0000-1f4e-08727f140000 pid=5247 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=780af9d6-1900-0000-1f4e-08727f140000 pid=5247 clone guuid=7feb73d7-1900-0000-1f4e-087281140000 pid=5249 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=7feb73d7-1900-0000-1f4e-087281140000 pid=5249 execve guuid=4dede0d7-1900-0000-1f4e-087282140000 pid=5250 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=4dede0d7-1900-0000-1f4e-087282140000 pid=5250 execve guuid=564f48d8-1900-0000-1f4e-087283140000 pid=5251 /usr/bin/wget net send-data guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=564f48d8-1900-0000-1f4e-087283140000 pid=5251 execve guuid=ba5f4edb-1900-0000-1f4e-087284140000 pid=5252 /usr/bin/curl net send-data write-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=ba5f4edb-1900-0000-1f4e-087284140000 pid=5252 execve guuid=58147adf-1900-0000-1f4e-087285140000 pid=5253 /usr/bin/chmod guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=58147adf-1900-0000-1f4e-087285140000 pid=5253 execve guuid=b94be5df-1900-0000-1f4e-087286140000 pid=5254 /usr/bin/bash guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=b94be5df-1900-0000-1f4e-087286140000 pid=5254 clone guuid=77de6ee0-1900-0000-1f4e-087288140000 pid=5256 /usr/bin/rm delete-file guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=77de6ee0-1900-0000-1f4e-087288140000 pid=5256 execve guuid=d11ad4e0-1900-0000-1f4e-087289140000 pid=5257 /usr/bin/rm guuid=3d6bc163-1900-0000-1f4e-08722e140000 pid=5166->guuid=d11ad4e0-1900-0000-1f4e-087289140000 pid=5257 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=51aba764-1900-0000-1f4e-08722f140000 pid=5167->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=662c8975-1900-0000-1f4e-087230140000 pid=5168->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a8db057f-1900-0000-1f4e-087233140000 pid=5171 /usr/bin/bash guuid=90a9ea7e-1900-0000-1f4e-087232140000 pid=5170->guuid=a8db057f-1900-0000-1f4e-087233140000 pid=5171 clone guuid=7631d67f-1900-0000-1f4e-087236140000 pid=5174->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=05efa182-1900-0000-1f4e-087237140000 pid=5175->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=708faa86-1900-0000-1f4e-08723a140000 pid=5178 /usr/bin/bash guuid=78198f86-1900-0000-1f4e-087239140000 pid=5177->guuid=708faa86-1900-0000-1f4e-08723a140000 pid=5178 clone guuid=edc05d87-1900-0000-1f4e-08723d140000 pid=5181->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=09eaef89-1900-0000-1f4e-08723e140000 pid=5182->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=9e28b98e-1900-0000-1f4e-087241140000 pid=5185 /usr/bin/bash guuid=822ef78d-1900-0000-1f4e-087240140000 pid=5184->guuid=9e28b98e-1900-0000-1f4e-087241140000 pid=5185 clone guuid=a18fbd8f-1900-0000-1f4e-087244140000 pid=5188->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=caf84f93-1900-0000-1f4e-087245140000 pid=5189->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=72eb7799-1900-0000-1f4e-087248140000 pid=5192 /usr/bin/bash guuid=c61b5a99-1900-0000-1f4e-087247140000 pid=5191->guuid=72eb7799-1900-0000-1f4e-087248140000 pid=5192 clone guuid=da65579a-1900-0000-1f4e-08724b140000 pid=5195->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=bdcce79c-1900-0000-1f4e-08724c140000 pid=5196->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=10e3d6a0-1900-0000-1f4e-08724f140000 pid=5199 /usr/bin/bash guuid=12dbb5a0-1900-0000-1f4e-08724e140000 pid=5198->guuid=10e3d6a0-1900-0000-1f4e-08724f140000 pid=5199 clone guuid=53d3d1a1-1900-0000-1f4e-087252140000 pid=5202->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=b6a571a4-1900-0000-1f4e-087253140000 pid=5203->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ef11c1a8-1900-0000-1f4e-087256140000 pid=5206 /usr/bin/bash guuid=d46a8da8-1900-0000-1f4e-087255140000 pid=5205->guuid=ef11c1a8-1900-0000-1f4e-087256140000 pid=5206 clone guuid=9bcaf8a9-1900-0000-1f4e-087259140000 pid=5209->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=330178ad-1900-0000-1f4e-08725a140000 pid=5210->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=43f61ab3-1900-0000-1f4e-08725d140000 pid=5213 /usr/bin/bash guuid=0f93ffb2-1900-0000-1f4e-08725c140000 pid=5212->guuid=43f61ab3-1900-0000-1f4e-08725d140000 pid=5213 clone guuid=21a8e7b3-1900-0000-1f4e-087260140000 pid=5216->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=afbd7eb6-1900-0000-1f4e-087261140000 pid=5217->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=698dbbba-1900-0000-1f4e-087264140000 pid=5220 /usr/bin/bash guuid=1c819fba-1900-0000-1f4e-087263140000 pid=5219->guuid=698dbbba-1900-0000-1f4e-087264140000 pid=5220 clone guuid=df6d99bb-1900-0000-1f4e-087267140000 pid=5223->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=679c56be-1900-0000-1f4e-087268140000 pid=5224->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=558409c3-1900-0000-1f4e-08726b140000 pid=5227 /usr/bin/bash guuid=1a22f1c2-1900-0000-1f4e-08726a140000 pid=5226->guuid=558409c3-1900-0000-1f4e-08726b140000 pid=5227 clone guuid=654ee9c3-1900-0000-1f4e-08726f140000 pid=5231->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=bd51cec6-1900-0000-1f4e-087273140000 pid=5235->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=3507d7cb-1900-0000-1f4e-087279140000 pid=5241 /usr/bin/bash guuid=e1d8b4cb-1900-0000-1f4e-087278140000 pid=5240->guuid=3507d7cb-1900-0000-1f4e-087279140000 pid=5241 clone guuid=f7cbe7cc-1900-0000-1f4e-08727c140000 pid=5244->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=39e047d0-1900-0000-1f4e-08727d140000 pid=5245->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=165e1cd7-1900-0000-1f4e-087280140000 pid=5248 /usr/bin/bash guuid=780af9d6-1900-0000-1f4e-08727f140000 pid=5247->guuid=165e1cd7-1900-0000-1f4e-087280140000 pid=5248 clone guuid=564f48d8-1900-0000-1f4e-087283140000 pid=5251->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=ba5f4edb-1900-0000-1f4e-087284140000 pid=5252->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=de650de0-1900-0000-1f4e-087287140000 pid=5255 /usr/bin/bash guuid=b94be5df-1900-0000-1f4e-087286140000 pid=5254->guuid=de650de0-1900-0000-1f4e-087287140000 pid=5255 clone
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-20 21:10:28 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  1/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b67542ebf7ea604cd661298d3e8dfb0e49592ea342267a4c1320363cd0afed50

(this sample)

  
Delivery method
Distributed via web download

Comments