MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bdde7805820e3ba5101df7f9a6de339dfd32c368d3128346ecdccdc5f9c09474. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: bdde7805820e3ba5101df7f9a6de339dfd32c368d3128346ecdccdc5f9c09474
SHA3-384 hash: 6c6f44416196869504f4c099bfcb123d380fb8ddc20ceeed0265fd8a76ed4f8753a33c58a2c3b70d73d69d88f9a09cd0
SHA1 hash: 234531cb7c65e51f9e1e26934e4581c996448212
MD5 hash: bb0a2bb7304992e73886b92269022727
humanhash: aspen-stream-hydrogen-triple
File name:wget.sh
Download: download sample
File size:530 bytes
First seen:2026-07-27 06:35:07 UTC
Last seen:2026-07-27 11:02:28 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:KSs6wZ5ANyHe0f5A+sw5AequSYeJB/5AAWzpk:KSKZb/sweIpk
TLSH T174F090CD41523F6D45CDC90F7653894C904693CE568F97CA3C9D0826A5C5BB8F858E6C
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://95.133.245.15/arm59d8e694d18e3c976b45ada0041ae3f756ef7c795089c05537396dbe89d929262 Miraielf mirai ua-wget
http://95.133.245.15/arm701d5fba3c3906d1fb26a6697644610f0f9f02140720de49edf907091669dbb8b Miraielf ua-wget
http://95.133.245.15/mips06c4ddabac5e976f152f482a47581313fdb95e2cbee564d56279648bbaf5694a Miraielf ua-wget
http://95.133.245.15/mipseln/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=5ff5be44-1b00-0000-47fd-e32c0d0c0000 pid=3085 /usr/bin/sudo guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093 /tmp/sample.bin guuid=5ff5be44-1b00-0000-47fd-e32c0d0c0000 pid=3085->guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093 execve guuid=a21b464a-1b00-0000-47fd-e32c160c0000 pid=3094 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=a21b464a-1b00-0000-47fd-e32c160c0000 pid=3094 execve guuid=d899154b-1b00-0000-47fd-e32c170c0000 pid=3095 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=d899154b-1b00-0000-47fd-e32c170c0000 pid=3095 execve guuid=9125774b-1b00-0000-47fd-e32c180c0000 pid=3096 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=9125774b-1b00-0000-47fd-e32c180c0000 pid=3096 execve guuid=8482e04b-1b00-0000-47fd-e32c190c0000 pid=3097 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=8482e04b-1b00-0000-47fd-e32c190c0000 pid=3097 execve guuid=5d031d4c-1b00-0000-47fd-e32c1a0c0000 pid=3098 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=5d031d4c-1b00-0000-47fd-e32c1a0c0000 pid=3098 execve guuid=0b85574c-1b00-0000-47fd-e32c1b0c0000 pid=3099 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=0b85574c-1b00-0000-47fd-e32c1b0c0000 pid=3099 execve guuid=5dc89d4c-1b00-0000-47fd-e32c1c0c0000 pid=3100 /usr/bin/rm guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=5dc89d4c-1b00-0000-47fd-e32c1c0c0000 pid=3100 execve guuid=2a2be14c-1b00-0000-47fd-e32c1d0c0000 pid=3101 /usr/bin/cp guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=2a2be14c-1b00-0000-47fd-e32c1d0c0000 pid=3101 execve guuid=b698a353-1b00-0000-47fd-e32c1e0c0000 pid=3102 /usr/bin/busybox net send-data write-file guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=b698a353-1b00-0000-47fd-e32c1e0c0000 pid=3102 execve guuid=16b9f35c-1b00-0000-47fd-e32c1f0c0000 pid=3103 /usr/bin/chmod guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=16b9f35c-1b00-0000-47fd-e32c1f0c0000 pid=3103 execve guuid=b8d9845d-1b00-0000-47fd-e32c200c0000 pid=3104 /usr/bin/dash guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=b8d9845d-1b00-0000-47fd-e32c200c0000 pid=3104 clone guuid=a3332760-1b00-0000-47fd-e32c220c0000 pid=3106 /usr/bin/busybox net send-data write-file guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=a3332760-1b00-0000-47fd-e32c220c0000 pid=3106 execve guuid=51fe0168-1b00-0000-47fd-e32c2a0c0000 pid=3114 /usr/bin/chmod guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=51fe0168-1b00-0000-47fd-e32c2a0c0000 pid=3114 execve guuid=065a7d68-1b00-0000-47fd-e32c2b0c0000 pid=3115 /usr/bin/dash guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=065a7d68-1b00-0000-47fd-e32c2b0c0000 pid=3115 clone guuid=fd196a69-1b00-0000-47fd-e32c2e0c0000 pid=3118 /usr/bin/busybox net send-data write-file guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=fd196a69-1b00-0000-47fd-e32c2e0c0000 pid=3118 execve guuid=ba999272-1b00-0000-47fd-e32c3c0c0000 pid=3132 /usr/bin/chmod guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=ba999272-1b00-0000-47fd-e32c3c0c0000 pid=3132 execve guuid=05493573-1b00-0000-47fd-e32c3d0c0000 pid=3133 /usr/bin/dash guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=05493573-1b00-0000-47fd-e32c3d0c0000 pid=3133 clone guuid=c566f473-1b00-0000-47fd-e32c3f0c0000 pid=3135 /usr/bin/busybox net send-data guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=c566f473-1b00-0000-47fd-e32c3f0c0000 pid=3135 execve guuid=417c8177-1b00-0000-47fd-e32c400c0000 pid=3136 /usr/bin/chmod guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=417c8177-1b00-0000-47fd-e32c400c0000 pid=3136 execve guuid=84890278-1b00-0000-47fd-e32c410c0000 pid=3137 /home/sandbox/WLOPKJ guuid=44599049-1b00-0000-47fd-e32c150c0000 pid=3093->guuid=84890278-1b00-0000-47fd-e32c410c0000 pid=3137 execve 51575c4a-4a0a-563f-9f96-7267b970b28e 95.133.245.15:80 guuid=b698a353-1b00-0000-47fd-e32c1e0c0000 pid=3102->51575c4a-4a0a-563f-9f96-7267b970b28e send: 80B guuid=a3332760-1b00-0000-47fd-e32c220c0000 pid=3106->51575c4a-4a0a-563f-9f96-7267b970b28e send: 80B guuid=fd196a69-1b00-0000-47fd-e32c2e0c0000 pid=3118->51575c4a-4a0a-563f-9f96-7267b970b28e send: 80B guuid=c566f473-1b00-0000-47fd-e32c3f0c0000 pid=3135->51575c4a-4a0a-563f-9f96-7267b970b28e send: 82B
Gathering data
Result
Malware family:
n/a
Score:
  9/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Contacts a large (61297) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bdde7805820e3ba5101df7f9a6de339dfd32c368d3128346ecdccdc5f9c09474

(this sample)

  
Delivery method
Distributed via web download

Comments