MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bdd2bb96e851e982f26c080a0d65ca49251a3a6eee4c3f12489c34899b6d306e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: bdd2bb96e851e982f26c080a0d65ca49251a3a6eee4c3f12489c34899b6d306e
SHA3-384 hash: 5078ce778a28fab21b7c8221fc306117fe4f0bc442556e74bc04f2ae3790ad3b4ff0bf91d4dcca44cb8f41606cd26d36
SHA1 hash: 7ecbc4b7a4fb6ec41bd604fa262fa95de27be98f
MD5 hash: 7851a2211999232df0fc25e70a3d11af
humanhash: mockingbird-lemon-two-september
File name:docker
Download: download sample
Signature Mirai
File size:2'382 bytes
First seen:2026-01-13 01:41:17 UTC
Last seen:2026-01-13 02:11:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:gYFywir3bBaKfEXYcRMTwJQlQWcRqbsisrb0SoREKTCsKxcDcgrB4iG0ai0arnaD:gYFywir3bBaKfEXYcRMTwJcRcRqblWA0
TLSH T12B41435E0F5069831500E87AEA69E6DC0411C8F76C7FEB92ACEB06B7C1740AC753E718
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://newbinhost.giize.com:8083/SupplySrvarmbc8e56b086d6dff8c4bbc0024306f2f368dad282fb69e01f832facedd66f52c5 Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvarm63be70fc3e9f54f38da5acb854babcce2bea80d5a38987dabd9d60c9dde6d917c Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvarm5n/an/aelf geofenced opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvarm7n/an/aelf geofenced opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvm68k37444aaf2a15551e182f35b0501adb44ae52705c0b385d709e822ee18ae6b286 Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvmips8751b7895a6f1b8b37e6024b7477fd5c979a351ee3d073ca415a7ded3387f786 Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvmpsle33743491df24ba92b79656fea6b398302042a6d07bbff9bbf254243317b1f7e Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvppc964b22f03b8c29dd5a24b8b2bd5648eaec1a750ada4e0f1a4a001e9f2dc27bb7 Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvsh4a22da1d4612d40341e19294ada8de0e399d56de4da6d2ae5bdb62d228072861b Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvspc24b8846706503e38321a71be85d68169326030a20a8efb64bedc8145103d22ee Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvx6416b870f6de57049a36b6a8b6c8ce5610efa69cb5b6d6495d82d549cb74bd38bb Miraielf geofenced mirai opendir ua-wget USA
http://newbinhost.giize.com:8083/SupplySrvx86dddd16cb5c5e035211360a5458544611738fc8571ced8ba4138e5e13158c9cbe Miraielf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
139
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=389ba268-1600-0000-14f3-7692c90c0000 pid=3273 /usr/bin/sudo guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281 /tmp/sample.bin guuid=389ba268-1600-0000-14f3-7692c90c0000 pid=3273->guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281 execve guuid=4ab3c56a-1600-0000-14f3-7692d30c0000 pid=3283 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=4ab3c56a-1600-0000-14f3-7692d30c0000 pid=3283 execve guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3369 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3369 execve guuid=2bef33e5-1600-0000-14f3-7692a30d0000 pid=3491 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=2bef33e5-1600-0000-14f3-7692a30d0000 pid=3491 execve guuid=49da77e5-1600-0000-14f3-7692a50d0000 pid=3493 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=49da77e5-1600-0000-14f3-7692a50d0000 pid=3493 clone guuid=544e0fe6-1600-0000-14f3-7692a90d0000 pid=3497 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=544e0fe6-1600-0000-14f3-7692a90d0000 pid=3497 execve guuid=d1124be7-1600-0000-14f3-7692ab0d0000 pid=3499 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=d1124be7-1600-0000-14f3-7692ab0d0000 pid=3499 execve guuid=ecaeaee7-1600-0000-14f3-7692ac0d0000 pid=3500 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=ecaeaee7-1600-0000-14f3-7692ac0d0000 pid=3500 execve guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3605 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3605 execve guuid=19ea855a-1700-0000-14f3-7692ab0e0000 pid=3755 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=19ea855a-1700-0000-14f3-7692ab0e0000 pid=3755 execve guuid=43eff55a-1700-0000-14f3-7692ad0e0000 pid=3757 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=43eff55a-1700-0000-14f3-7692ad0e0000 pid=3757 clone guuid=24ceb75b-1700-0000-14f3-7692b10e0000 pid=3761 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=24ceb75b-1700-0000-14f3-7692b10e0000 pid=3761 execve guuid=49541e5c-1700-0000-14f3-7692b30e0000 pid=3763 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=49541e5c-1700-0000-14f3-7692b30e0000 pid=3763 execve guuid=31b77d5c-1700-0000-14f3-7692b50e0000 pid=3765 /usr/bin/wget dns net send-data guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=31b77d5c-1700-0000-14f3-7692b50e0000 pid=3765 execve guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3851 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3851 execve guuid=54dfc099-1700-0000-14f3-76925d0f0000 pid=3933 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=54dfc099-1700-0000-14f3-76925d0f0000 pid=3933 execve guuid=cc6c1b9a-1700-0000-14f3-76925f0f0000 pid=3935 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=cc6c1b9a-1700-0000-14f3-76925f0f0000 pid=3935 clone guuid=b3ca699a-1700-0000-14f3-7692620f0000 pid=3938 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=b3ca699a-1700-0000-14f3-7692620f0000 pid=3938 execve guuid=dde2cb9a-1700-0000-14f3-7692640f0000 pid=3940 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=dde2cb9a-1700-0000-14f3-7692640f0000 pid=3940 execve guuid=94c5289b-1700-0000-14f3-7692680f0000 pid=3944 /usr/bin/wget dns net send-data guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=94c5289b-1700-0000-14f3-7692680f0000 pid=3944 execve guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4039 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4039 execve guuid=49be3ed6-1700-0000-14f3-769219100000 pid=4121 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=49be3ed6-1700-0000-14f3-769219100000 pid=4121 execve guuid=05a5c0d6-1700-0000-14f3-76921b100000 pid=4123 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=05a5c0d6-1700-0000-14f3-76921b100000 pid=4123 clone guuid=666127d7-1700-0000-14f3-76921e100000 pid=4126 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=666127d7-1700-0000-14f3-76921e100000 pid=4126 execve guuid=b6e0acd7-1700-0000-14f3-769221100000 pid=4129 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=b6e0acd7-1700-0000-14f3-769221100000 pid=4129 execve guuid=37ee1ad8-1700-0000-14f3-769225100000 pid=4133 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=37ee1ad8-1700-0000-14f3-769225100000 pid=4133 execve guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4263 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4263 execve guuid=92b16a4d-1800-0000-14f3-769231110000 pid=4401 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=92b16a4d-1800-0000-14f3-769231110000 pid=4401 execve guuid=b050ed4d-1800-0000-14f3-769235110000 pid=4405 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=b050ed4d-1800-0000-14f3-769235110000 pid=4405 clone guuid=6f640950-1800-0000-14f3-76923a110000 pid=4410 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=6f640950-1800-0000-14f3-76923a110000 pid=4410 execve guuid=79df8650-1800-0000-14f3-76923c110000 pid=4412 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=79df8650-1800-0000-14f3-76923c110000 pid=4412 execve guuid=dae70a51-1800-0000-14f3-76923e110000 pid=4414 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=dae70a51-1800-0000-14f3-76923e110000 pid=4414 execve guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4532 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4532 execve guuid=c14aa9c3-1800-0000-14f3-769236120000 pid=4662 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=c14aa9c3-1800-0000-14f3-769236120000 pid=4662 execve guuid=7fdf05c4-1800-0000-14f3-769239120000 pid=4665 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=7fdf05c4-1800-0000-14f3-769239120000 pid=4665 clone guuid=88d663c5-1800-0000-14f3-769242120000 pid=4674 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=88d663c5-1800-0000-14f3-769242120000 pid=4674 execve guuid=0539bbc5-1800-0000-14f3-769246120000 pid=4678 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=0539bbc5-1800-0000-14f3-769246120000 pid=4678 execve guuid=853cfac5-1800-0000-14f3-769247120000 pid=4679 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=853cfac5-1800-0000-14f3-769247120000 pid=4679 execve guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4842 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4842 execve guuid=c30a0939-1900-0000-14f3-769268130000 pid=4968 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=c30a0939-1900-0000-14f3-769268130000 pid=4968 execve guuid=a7599e39-1900-0000-14f3-76926a130000 pid=4970 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=a7599e39-1900-0000-14f3-76926a130000 pid=4970 clone guuid=7bbfab3a-1900-0000-14f3-76926e130000 pid=4974 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=7bbfab3a-1900-0000-14f3-76926e130000 pid=4974 execve guuid=96ca593c-1900-0000-14f3-769272130000 pid=4978 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=96ca593c-1900-0000-14f3-769272130000 pid=4978 execve guuid=dfb1f43c-1900-0000-14f3-769274130000 pid=4980 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=dfb1f43c-1900-0000-14f3-769274130000 pid=4980 execve guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5073 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5073 execve guuid=eed06799-1900-0000-14f3-76923b140000 pid=5179 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=eed06799-1900-0000-14f3-76923b140000 pid=5179 execve guuid=1f07a19a-1900-0000-14f3-76923d140000 pid=5181 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=1f07a19a-1900-0000-14f3-76923d140000 pid=5181 clone guuid=a481b19b-1900-0000-14f3-769241140000 pid=5185 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=a481b19b-1900-0000-14f3-769241140000 pid=5185 execve guuid=de9328a0-1900-0000-14f3-76924e140000 pid=5198 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=de9328a0-1900-0000-14f3-76924e140000 pid=5198 execve guuid=68a28aa0-1900-0000-14f3-769250140000 pid=5200 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=68a28aa0-1900-0000-14f3-769250140000 pid=5200 execve guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5272 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5272 execve guuid=d971acf7-1900-0000-14f3-7692a2140000 pid=5282 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=d971acf7-1900-0000-14f3-7692a2140000 pid=5282 execve guuid=6125fbf7-1900-0000-14f3-7692a3140000 pid=5283 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=6125fbf7-1900-0000-14f3-7692a3140000 pid=5283 clone guuid=a7d095f8-1900-0000-14f3-7692a5140000 pid=5285 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=a7d095f8-1900-0000-14f3-7692a5140000 pid=5285 execve guuid=2310a7f9-1900-0000-14f3-7692a6140000 pid=5286 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=2310a7f9-1900-0000-14f3-7692a6140000 pid=5286 execve guuid=b0ddf2f9-1900-0000-14f3-7692a7140000 pid=5287 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=b0ddf2f9-1900-0000-14f3-7692a7140000 pid=5287 execve guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5288 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5288 execve guuid=9b9e1e6d-1a00-0000-14f3-7692aa140000 pid=5290 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=9b9e1e6d-1a00-0000-14f3-7692aa140000 pid=5290 execve guuid=68687b6d-1a00-0000-14f3-7692ab140000 pid=5291 /usr/bin/bash guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=68687b6d-1a00-0000-14f3-7692ab140000 pid=5291 clone guuid=bd25236e-1a00-0000-14f3-7692ad140000 pid=5293 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=bd25236e-1a00-0000-14f3-7692ad140000 pid=5293 execve guuid=5145ed6e-1a00-0000-14f3-7692ae140000 pid=5294 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=5145ed6e-1a00-0000-14f3-7692ae140000 pid=5294 execve guuid=3457a76f-1a00-0000-14f3-7692af140000 pid=5295 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=3457a76f-1a00-0000-14f3-7692af140000 pid=5295 execve guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5303 execve guuid=440cdee0-1a00-0000-14f3-7692b9140000 pid=5305 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=440cdee0-1a00-0000-14f3-7692b9140000 pid=5305 execve guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306 /home/sandbox/SupplySrvx64 net guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306 execve guuid=bd44ece1-1a00-0000-14f3-7692be140000 pid=5310 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=bd44ece1-1a00-0000-14f3-7692be140000 pid=5310 execve guuid=c3da9ae2-1a00-0000-14f3-7692c1140000 pid=5313 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=c3da9ae2-1a00-0000-14f3-7692c1140000 pid=5313 execve guuid=0b204be3-1a00-0000-14f3-7692c2140000 pid=5314 /usr/bin/wget dns net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=0b204be3-1a00-0000-14f3-7692c2140000 pid=5314 execve guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5315 /usr/bin/curl net send-data write-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5315 execve guuid=66400149-1b00-0000-14f3-7692c5140000 pid=5317 /usr/bin/chmod guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=66400149-1b00-0000-14f3-7692c5140000 pid=5317 execve guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318 /home/sandbox/SupplySrvx86 net guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318 execve guuid=c06bb149-1b00-0000-14f3-7692ca140000 pid=5322 /usr/bin/rm delete-file guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=c06bb149-1b00-0000-14f3-7692ca140000 pid=5322 execve guuid=cfb1fe49-1b00-0000-14f3-7692cd140000 pid=5325 /usr/bin/rm guuid=3d97456a-1600-0000-14f3-7692d10c0000 pid=3281->guuid=cfb1fe49-1b00-0000-14f3-7692cd140000 pid=5325 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4ab3c56a-1600-0000-14f3-7692d30c0000 pid=3283->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B f254e63d-a4cf-5629-a517-b92fda25262d newbinhost.giize.com:8083 guuid=4ab3c56a-1600-0000-14f3-7692d30c0000 pid=3283->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3369->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3378 /usr/bin/curl dns net send-data guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3369->guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3378 clone guuid=95d0c8a8-1600-0000-14f3-7692290d0000 pid=3378->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=ecaeaee7-1600-0000-14f3-7692ac0d0000 pid=3500->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=ecaeaee7-1600-0000-14f3-7692ac0d0000 pid=3500->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3605->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3611 /usr/bin/curl dns net send-data guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3605->guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3611 clone guuid=40f0db1f-1700-0000-14f3-7692150e0000 pid=3611->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=31b77d5c-1700-0000-14f3-7692b50e0000 pid=3765->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=31b77d5c-1700-0000-14f3-7692b50e0000 pid=3765->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3851->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3859 /usr/bin/curl dns net send-data guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3851->guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3859 clone guuid=a9d3837a-1700-0000-14f3-76920b0f0000 pid=3859->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=f7ab379a-1700-0000-14f3-7692600f0000 pid=3936 /usr/bin/bash guuid=cc6c1b9a-1700-0000-14f3-76925f0f0000 pid=3935->guuid=f7ab379a-1700-0000-14f3-7692600f0000 pid=3936 clone guuid=94c5289b-1700-0000-14f3-7692680f0000 pid=3944->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=94c5289b-1700-0000-14f3-7692680f0000 pid=3944->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4039->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4048 /usr/bin/curl dns net send-data guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4039->guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4048 clone guuid=dc2fb2b8-1700-0000-14f3-7692c70f0000 pid=4048->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=3134eed6-1700-0000-14f3-76921c100000 pid=4124 /usr/bin/bash guuid=05a5c0d6-1700-0000-14f3-76921b100000 pid=4123->guuid=3134eed6-1700-0000-14f3-76921c100000 pid=4124 clone guuid=37ee1ad8-1700-0000-14f3-769225100000 pid=4133->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=37ee1ad8-1700-0000-14f3-769225100000 pid=4133->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4263->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4275 /usr/bin/curl dns net send-data guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4263->guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4275 clone guuid=aac9a510-1800-0000-14f3-7692a7100000 pid=4275->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=dae70a51-1800-0000-14f3-76923e110000 pid=4414->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=dae70a51-1800-0000-14f3-76923e110000 pid=4414->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4532->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4537 /usr/bin/curl dns net send-data guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4532->guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4537 clone guuid=e1058e8a-1800-0000-14f3-7692b4110000 pid=4537->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=853cfac5-1800-0000-14f3-769247120000 pid=4679->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=853cfac5-1800-0000-14f3-769247120000 pid=4679->f254e63d-a4cf-5629-a517-b92fda25262d send: 153B guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4842->f254e63d-a4cf-5629-a517-b92fda25262d send: 102B guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4853 /usr/bin/curl dns net send-data guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4842->guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4853 clone guuid=577379fd-1800-0000-14f3-7692ea120000 pid=4853->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=dfb1f43c-1900-0000-14f3-769274130000 pid=4980->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=dfb1f43c-1900-0000-14f3-769274130000 pid=4980->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5073->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5081 /usr/bin/curl dns net send-data guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5073->guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5081 clone guuid=09497e68-1900-0000-14f3-7692d1130000 pid=5081->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=68a28aa0-1900-0000-14f3-769250140000 pid=5200->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=68a28aa0-1900-0000-14f3-769250140000 pid=5200->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5272->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5273 /usr/bin/curl dns net send-data guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5272->guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5273 clone guuid=3c1ac4cb-1900-0000-14f3-769298140000 pid=5273->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=b0ddf2f9-1900-0000-14f3-7692a7140000 pid=5287->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=b0ddf2f9-1900-0000-14f3-7692a7140000 pid=5287->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5288->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5289 /usr/bin/curl dns net send-data guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5288->guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5289 clone guuid=52bcc630-1a00-0000-14f3-7692a8140000 pid=5289->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=3457a76f-1a00-0000-14f3-7692af140000 pid=5295->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=3457a76f-1a00-0000-14f3-7692af140000 pid=5295->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5303->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5304 /usr/bin/curl dns net send-data guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5303->guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5304 clone guuid=353ccfa7-1a00-0000-14f3-7692b7140000 pid=5304->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1cdbd8e1-1a00-0000-14f3-7692bb140000 pid=5307 /home/sandbox/SupplySrvx64 zombie guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306->guuid=1cdbd8e1-1a00-0000-14f3-7692bb140000 pid=5307 clone guuid=3765dee1-1a00-0000-14f3-7692bc140000 pid=5308 /home/sandbox/SupplySrvx64 zombie guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306->guuid=3765dee1-1a00-0000-14f3-7692bc140000 pid=5308 clone guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309 /home/sandbox/SupplySrvx64 dns net send-data zombie guuid=68f88be1-1a00-0000-14f3-7692ba140000 pid=5306->guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309 clone guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 39B c866238d-8c90-58a8-b672-c5945d484a39 sophos1997.camdvr.org:13471 guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309->c866238d-8c90-58a8-b672-c5945d484a39 send: 10B guuid=f79b04e2-1a00-0000-14f3-7692bf140000 pid=5311 /home/sandbox/SupplySrvx64 guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309->guuid=f79b04e2-1a00-0000-14f3-7692bf140000 pid=5311 clone guuid=1e3b0fe2-1a00-0000-14f3-7692c0140000 pid=5312 /home/sandbox/SupplySrvx64 guuid=b39ae2e1-1a00-0000-14f3-7692bd140000 pid=5309->guuid=1e3b0fe2-1a00-0000-14f3-7692c0140000 pid=5312 clone guuid=0b204be3-1a00-0000-14f3-7692c2140000 pid=5314->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=0b204be3-1a00-0000-14f3-7692c2140000 pid=5314->f254e63d-a4cf-5629-a517-b92fda25262d send: 152B guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5315->f254e63d-a4cf-5629-a517-b92fda25262d send: 101B guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5316 /usr/bin/curl dns net send-data guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5315->guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5316 clone guuid=90b91514-1b00-0000-14f3-7692c3140000 pid=5316->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 76B guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=10b79049-1b00-0000-14f3-7692c7140000 pid=5319 /home/sandbox/SupplySrvx86 zombie guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318->guuid=10b79049-1b00-0000-14f3-7692c7140000 pid=5319 clone guuid=c0c09349-1b00-0000-14f3-7692c8140000 pid=5320 /home/sandbox/SupplySrvx86 guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318->guuid=c0c09349-1b00-0000-14f3-7692c8140000 pid=5320 clone guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321 /home/sandbox/SupplySrvx86 dns net send-data zombie guuid=acb64549-1b00-0000-14f3-7692c6140000 pid=5318->guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321 clone guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 39B guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321->c866238d-8c90-58a8-b672-c5945d484a39 send: 10B guuid=b0fab249-1b00-0000-14f3-7692cb140000 pid=5323 /home/sandbox/SupplySrvx86 guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321->guuid=b0fab249-1b00-0000-14f3-7692cb140000 pid=5323 clone guuid=29ceb749-1b00-0000-14f3-7692cc140000 pid=5324 /home/sandbox/SupplySrvx86 guuid=f0ef9649-1b00-0000-14f3-7692c9140000 pid=5321->guuid=29ceb749-1b00-0000-14f3-7692cc140000 pid=5324 clone
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2026-01-13 01:42:26 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Mirai
Mirai family
Malware Config
C2 Extraction:
sophos1997.camdvr.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bdd2bb96e851e982f26c080a0d65ca49251a3a6eee4c3f12489c34899b6d306e

(this sample)

  
Delivery method
Distributed via web download

Comments