🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bb68d4336197cd242f9c0552f3485f697522957aa9c304548cdbb48ef81ebdb5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: bb68d4336197cd242f9c0552f3485f697522957aa9c304548cdbb48ef81ebdb5
SHA3-384 hash: 334b1fcb5d74cd8872333a89ad19754ebd6808e024e237d8ceeeda59456011b9189013f4eaf527196ce05c8bbf53cccb
SHA1 hash: 10f9248b2a23009993caf1afa9440a8685a6cc18
MD5 hash: 91c6187323377c912c4f4fe99634617e
humanhash: comet-jersey-mango-march
File name:bins.sh
Download: download sample
Signature Mirai
File size:1'924 bytes
First seen:2026-10-03 10:55:08 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:fOJPqI0LPYB/uNIqNIsKPkKPf2vk2vB3cHRlL:MPqP+/gKPkKPf2vk2vaHRlL
TLSH T1A241D68B37601DB3880DDE45F36414E4F08B86C2A1678EFAF4B65E73199920CF596A70
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.117/x86905e5071aa07a3c2707fe2c6fb873bfc0bd1efeb2a35dddaaa478944b5bf2f4f MiraiGo GoDDoSAgent
http://94.154.43.117/i386n/an/aGo GoDDoSAgent
http://94.154.43.117/amd64n/an/aGo GoDDoSAgent
http://94.154.43.117/armcd705e091f97f09a0e608d611e920d9b373889590a2a5247dd2ce3251a875f12 MiraiGo GoDDoSAgent
http://94.154.43.117/armv7lcd705e091f97f09a0e608d611e920d9b373889590a2a5247dd2ce3251a875f12 MiraiGo GoDDoSAgent
http://94.154.43.117/arm508ff1a293519f919c4fce850a6794a4df1f1b12e4aa3d6a29ee2ae30ff948278 MiraiGo GoDDoSAgent
http://94.154.43.117/arm6n/an/aGo GoDDoSAgent
http://94.154.43.117/arm64n/an/aGo GoDDoSAgent
http://94.154.43.117/android_arm6429b93634edff0608276bfd35b1b2e32ce6e04ac824c27a93ab3cb02cb85148fd MiraiGo GoDDoSAgent
http://94.154.43.117/mipsn/an/aGo GoDDoSAgent
http://94.154.43.117/mipslef9f50ec2eb5b92848d162b6c26d81d3a24670657f1d465b50ae35c70aace6948 MiraiGo GoDDoSAgent
http://94.154.43.117/bot.exen/an/aGo GoDDoSAgent

Intelligence


File Origin
# of uploads :
1
# of downloads :
73
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-10-02T23:05:00Z UTC
Last seen:
2026-10-04T18:51:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a5a3c830-1900-0000-417a-e26d89070000 pid=1929 /usr/bin/sudo guuid=12472a36-1900-0000-417a-e26d90070000 pid=1936 /tmp/sample.bin guuid=a5a3c830-1900-0000-417a-e26d89070000 pid=1929->guuid=12472a36-1900-0000-417a-e26d90070000 pid=1936 execve guuid=9a6fe436-1900-0000-417a-e26d91070000 pid=1937 /usr/bin/wget net send-data write-file guuid=12472a36-1900-0000-417a-e26d90070000 pid=1936->guuid=9a6fe436-1900-0000-417a-e26d91070000 pid=1937 execve guuid=be8b099f-1900-0000-417a-e26dd1070000 pid=2001 /usr/bin/chmod guuid=12472a36-1900-0000-417a-e26d90070000 pid=1936->guuid=be8b099f-1900-0000-417a-e26dd1070000 pid=2001 execve guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003 /tmp/x86 delete-file net send-data write-config write-file guuid=12472a36-1900-0000-417a-e26d90070000 pid=1936->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003 execve 1ac9ed75-196f-5aa1-8f2d-deed0e6f8663 94.154.43.117:80 guuid=9a6fe436-1900-0000-417a-e26d91070000 pid=1937->1ac9ed75-196f-5aa1-8f2d-deed0e6f8663 send: 131B b6ab8f3f-e278-5377-82f6-3b442fe53489 94.154.43.117:9111 guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 108B guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2014 /tmp/x86 guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2014 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2015 /tmp/x86 send-data guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2015 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2016 /tmp/x86 send-data guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2016 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2017 /tmp/x86 send-data guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2017 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2086 /tmp/x86 send-data guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2086 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2214 /tmp/x86 send-data guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2003->guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2214 clone guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2015->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 106B guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2016->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 178B guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2017->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 108B guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2086->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 213B guuid=c8e809a0-1900-0000-417a-e26dd3070000 pid=2214->b6ab8f3f-e278-5377-82f6-3b442fe53489 send: 179B
Gathering data
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-10-03 02:20:07 UTC
File Type:
Text (Shell)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
goddosagent
Score:
  10/10
Tags:
family:goddosagent antivm botnet defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Modifies Bash startup script
Creates/modifies environment variables
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Detects GoDDoSAgent
Family: GoDDoSAgent
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bb68d4336197cd242f9c0552f3485f697522957aa9c304548cdbb48ef81ebdb5

(this sample)

  
Delivery method
Distributed via web download

Comments