MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bee288e19bd82db0ffe4c2eb1d95d4c5ed63cd4640a75608e8c6006ae409c1b6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: bee288e19bd82db0ffe4c2eb1d95d4c5ed63cd4640a75608e8c6006ae409c1b6
SHA3-384 hash: 4806a9e22334dc6d1bbcb7a31c17360ccfba537652657e55766891a2f02910bf97263ddb267abe32f668dc6ee5fc2875
SHA1 hash: 40d81cd5871af96a34b2b4c4a5aab67d8f1a45bf
MD5 hash: 302c161d30d6185f568d2c8b73185d7c
humanhash: venus-papa-romeo-thirteen
File name:1.sh
Download: download sample
Signature Mirai
File size:2'283 bytes
First seen:2026-05-09 12:04:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:2ntDn8x/nQ0unGpneQeJIn1T15Egnqo6nIQINIIInU1KEnHQHMInBnn7H979Ym1C:25wKuef2NP6KIUbHe557J9Y+sTOP4
TLSH T17141E9CA00F25945CDA5CE04E7BBC9445900C59A3386FBEDDEFA08AB65C86443D5DF8B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-09T09:09:00Z UTC
Last seen:
2026-05-09T09:40:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=ee10c640-1c00-0000-8ae6-a09e050e0000 pid=3589 /usr/bin/sudo guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594 /tmp/sample.bin guuid=ee10c640-1c00-0000-8ae6-a09e050e0000 pid=3589->guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594 execve guuid=78c50443-1c00-0000-8ae6-a09e0c0e0000 pid=3596 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=78c50443-1c00-0000-8ae6-a09e0c0e0000 pid=3596 execve guuid=67ec6065-1c00-0000-8ae6-a09e520e0000 pid=3666 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=67ec6065-1c00-0000-8ae6-a09e520e0000 pid=3666 execve guuid=66121c72-1c00-0000-8ae6-a09e5f0e0000 pid=3679 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=66121c72-1c00-0000-8ae6-a09e5f0e0000 pid=3679 execve guuid=812c7d72-1c00-0000-8ae6-a09e600e0000 pid=3680 /manji.x86 guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=812c7d72-1c00-0000-8ae6-a09e600e0000 pid=3680 execve guuid=9866a672-1c00-0000-8ae6-a09e620e0000 pid=3682 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=9866a672-1c00-0000-8ae6-a09e620e0000 pid=3682 execve guuid=8498fe72-1c00-0000-8ae6-a09e630e0000 pid=3683 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=8498fe72-1c00-0000-8ae6-a09e630e0000 pid=3683 execve guuid=e4f1b0b2-1c00-0000-8ae6-a09e1a0f0000 pid=3866 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=e4f1b0b2-1c00-0000-8ae6-a09e1a0f0000 pid=3866 execve guuid=40a7cbca-1c00-0000-8ae6-a09e580f0000 pid=3928 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=40a7cbca-1c00-0000-8ae6-a09e580f0000 pid=3928 execve guuid=8bfb58cb-1c00-0000-8ae6-a09e5c0f0000 pid=3932 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=8bfb58cb-1c00-0000-8ae6-a09e5c0f0000 pid=3932 clone guuid=e67da2cc-1c00-0000-8ae6-a09e650f0000 pid=3941 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=e67da2cc-1c00-0000-8ae6-a09e650f0000 pid=3941 execve guuid=8450fdcc-1c00-0000-8ae6-a09e660f0000 pid=3942 /usr/bin/wget net send-data guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=8450fdcc-1c00-0000-8ae6-a09e660f0000 pid=3942 execve guuid=c5a076d0-1c00-0000-8ae6-a09e730f0000 pid=3955 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=c5a076d0-1c00-0000-8ae6-a09e730f0000 pid=3955 execve guuid=1e0172d6-1c00-0000-8ae6-a09e870f0000 pid=3975 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=1e0172d6-1c00-0000-8ae6-a09e870f0000 pid=3975 execve guuid=4f3dded6-1c00-0000-8ae6-a09e8b0f0000 pid=3979 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=4f3dded6-1c00-0000-8ae6-a09e8b0f0000 pid=3979 clone guuid=1b39fad6-1c00-0000-8ae6-a09e8c0f0000 pid=3980 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=1b39fad6-1c00-0000-8ae6-a09e8c0f0000 pid=3980 execve guuid=7b1769d7-1c00-0000-8ae6-a09e8e0f0000 pid=3982 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7b1769d7-1c00-0000-8ae6-a09e8e0f0000 pid=3982 execve guuid=882d05dd-1c00-0000-8ae6-a09ea10f0000 pid=4001 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=882d05dd-1c00-0000-8ae6-a09ea10f0000 pid=4001 execve guuid=33936ce3-1c00-0000-8ae6-a09eb60f0000 pid=4022 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=33936ce3-1c00-0000-8ae6-a09eb60f0000 pid=4022 execve guuid=7932ade3-1c00-0000-8ae6-a09eb70f0000 pid=4023 /manji.i686 guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7932ade3-1c00-0000-8ae6-a09eb70f0000 pid=4023 execve guuid=10bccbe3-1c00-0000-8ae6-a09eba0f0000 pid=4026 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=10bccbe3-1c00-0000-8ae6-a09eba0f0000 pid=4026 execve guuid=267b19e4-1c00-0000-8ae6-a09ebb0f0000 pid=4027 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=267b19e4-1c00-0000-8ae6-a09ebb0f0000 pid=4027 execve guuid=14ec25fa-1c00-0000-8ae6-a09efa0f0000 pid=4090 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=14ec25fa-1c00-0000-8ae6-a09efa0f0000 pid=4090 execve guuid=6361d217-1d00-0000-8ae6-a09e50100000 pid=4176 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=6361d217-1d00-0000-8ae6-a09e50100000 pid=4176 execve guuid=d2ca4b18-1d00-0000-8ae6-a09e53100000 pid=4179 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=d2ca4b18-1d00-0000-8ae6-a09e53100000 pid=4179 clone guuid=738fc01a-1d00-0000-8ae6-a09e5b100000 pid=4187 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=738fc01a-1d00-0000-8ae6-a09e5b100000 pid=4187 execve guuid=14135b1b-1d00-0000-8ae6-a09e5c100000 pid=4188 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=14135b1b-1d00-0000-8ae6-a09e5c100000 pid=4188 execve guuid=ad984753-1d00-0000-8ae6-a09e0a110000 pid=4362 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=ad984753-1d00-0000-8ae6-a09e0a110000 pid=4362 execve guuid=9cba9165-1d00-0000-8ae6-a09e4a110000 pid=4426 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=9cba9165-1d00-0000-8ae6-a09e4a110000 pid=4426 execve guuid=9ba0e565-1d00-0000-8ae6-a09e4c110000 pid=4428 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=9ba0e565-1d00-0000-8ae6-a09e4c110000 pid=4428 clone guuid=173a1967-1d00-0000-8ae6-a09e52110000 pid=4434 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=173a1967-1d00-0000-8ae6-a09e52110000 pid=4434 execve guuid=0ee86767-1d00-0000-8ae6-a09e56110000 pid=4438 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=0ee86767-1d00-0000-8ae6-a09e56110000 pid=4438 execve guuid=e816ada0-1d00-0000-8ae6-a09e19120000 pid=4633 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=e816ada0-1d00-0000-8ae6-a09e19120000 pid=4633 execve guuid=e92fa3b8-1d00-0000-8ae6-a09e5b120000 pid=4699 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=e92fa3b8-1d00-0000-8ae6-a09e5b120000 pid=4699 execve guuid=7c9726b9-1d00-0000-8ae6-a09e5f120000 pid=4703 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7c9726b9-1d00-0000-8ae6-a09e5f120000 pid=4703 clone guuid=93874eba-1d00-0000-8ae6-a09e61120000 pid=4705 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=93874eba-1d00-0000-8ae6-a09e61120000 pid=4705 execve guuid=a770dbba-1d00-0000-8ae6-a09e64120000 pid=4708 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=a770dbba-1d00-0000-8ae6-a09e64120000 pid=4708 execve guuid=233b8ce8-1d00-0000-8ae6-a09eda120000 pid=4826 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=233b8ce8-1d00-0000-8ae6-a09eda120000 pid=4826 execve guuid=72edaefa-1d00-0000-8ae6-a09e06130000 pid=4870 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=72edaefa-1d00-0000-8ae6-a09e06130000 pid=4870 execve guuid=546b33fb-1d00-0000-8ae6-a09e08130000 pid=4872 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=546b33fb-1d00-0000-8ae6-a09e08130000 pid=4872 clone guuid=7272d0fb-1d00-0000-8ae6-a09e0c130000 pid=4876 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7272d0fb-1d00-0000-8ae6-a09e0c130000 pid=4876 execve guuid=4f821d57-1e00-0000-8ae6-a09ec5130000 pid=5061 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=4f821d57-1e00-0000-8ae6-a09ec5130000 pid=5061 execve guuid=227e1091-1e00-0000-8ae6-a09ee2130000 pid=5090 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=227e1091-1e00-0000-8ae6-a09ee2130000 pid=5090 execve guuid=cc8e20ad-1e00-0000-8ae6-a09e31140000 pid=5169 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=cc8e20ad-1e00-0000-8ae6-a09e31140000 pid=5169 execve guuid=945868ad-1e00-0000-8ae6-a09e33140000 pid=5171 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=945868ad-1e00-0000-8ae6-a09e33140000 pid=5171 clone guuid=0ed824ae-1e00-0000-8ae6-a09e37140000 pid=5175 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=0ed824ae-1e00-0000-8ae6-a09e37140000 pid=5175 execve guuid=2a2c84ae-1e00-0000-8ae6-a09e39140000 pid=5177 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=2a2c84ae-1e00-0000-8ae6-a09e39140000 pid=5177 execve guuid=76e12cc5-1e00-0000-8ae6-a09e7a140000 pid=5242 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=76e12cc5-1e00-0000-8ae6-a09e7a140000 pid=5242 execve guuid=d9499cee-1e00-0000-8ae6-a09ea5140000 pid=5285 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=d9499cee-1e00-0000-8ae6-a09ea5140000 pid=5285 execve guuid=da5109ef-1e00-0000-8ae6-a09ea6140000 pid=5286 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=da5109ef-1e00-0000-8ae6-a09ea6140000 pid=5286 clone guuid=7a1cbaef-1e00-0000-8ae6-a09ea8140000 pid=5288 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7a1cbaef-1e00-0000-8ae6-a09ea8140000 pid=5288 execve guuid=fdf129f0-1e00-0000-8ae6-a09ea9140000 pid=5289 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=fdf129f0-1e00-0000-8ae6-a09ea9140000 pid=5289 execve guuid=415b950c-1f00-0000-8ae6-a09eaa140000 pid=5290 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=415b950c-1f00-0000-8ae6-a09eaa140000 pid=5290 execve guuid=9865363c-1f00-0000-8ae6-a09eab140000 pid=5291 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=9865363c-1f00-0000-8ae6-a09eab140000 pid=5291 execve guuid=7b99883c-1f00-0000-8ae6-a09eac140000 pid=5292 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7b99883c-1f00-0000-8ae6-a09eac140000 pid=5292 clone guuid=f9312c3d-1f00-0000-8ae6-a09eae140000 pid=5294 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=f9312c3d-1f00-0000-8ae6-a09eae140000 pid=5294 execve guuid=32eb7a3d-1f00-0000-8ae6-a09eaf140000 pid=5295 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=32eb7a3d-1f00-0000-8ae6-a09eaf140000 pid=5295 execve guuid=47c52854-1f00-0000-8ae6-a09eb0140000 pid=5296 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=47c52854-1f00-0000-8ae6-a09eb0140000 pid=5296 execve guuid=048fcc71-1f00-0000-8ae6-a09eb1140000 pid=5297 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=048fcc71-1f00-0000-8ae6-a09eb1140000 pid=5297 execve guuid=e39a2872-1f00-0000-8ae6-a09eb2140000 pid=5298 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=e39a2872-1f00-0000-8ae6-a09eb2140000 pid=5298 clone guuid=6ebad972-1f00-0000-8ae6-a09eb4140000 pid=5300 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=6ebad972-1f00-0000-8ae6-a09eb4140000 pid=5300 execve guuid=b2ea2673-1f00-0000-8ae6-a09eb5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=b2ea2673-1f00-0000-8ae6-a09eb5140000 pid=5301 execve guuid=15f1d9a1-1f00-0000-8ae6-a09eb6140000 pid=5302 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=15f1d9a1-1f00-0000-8ae6-a09eb6140000 pid=5302 execve guuid=26784fb0-1f00-0000-8ae6-a09ebc140000 pid=5308 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=26784fb0-1f00-0000-8ae6-a09ebc140000 pid=5308 execve guuid=be9bbeb0-1f00-0000-8ae6-a09ebd140000 pid=5309 /manji.dbg guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=be9bbeb0-1f00-0000-8ae6-a09ebd140000 pid=5309 execve guuid=9194e2b0-1f00-0000-8ae6-a09ebe140000 pid=5310 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=9194e2b0-1f00-0000-8ae6-a09ebe140000 pid=5310 execve guuid=f5c85eb1-1f00-0000-8ae6-a09ebf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=f5c85eb1-1f00-0000-8ae6-a09ebf140000 pid=5311 execve guuid=7e8d31d1-1f00-0000-8ae6-a09ec2140000 pid=5314 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=7e8d31d1-1f00-0000-8ae6-a09ec2140000 pid=5314 execve guuid=fbb53be3-1f00-0000-8ae6-a09ec3140000 pid=5315 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=fbb53be3-1f00-0000-8ae6-a09ec3140000 pid=5315 execve guuid=8411e9e3-1f00-0000-8ae6-a09ec4140000 pid=5316 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=8411e9e3-1f00-0000-8ae6-a09ec4140000 pid=5316 clone guuid=c22042e6-1f00-0000-8ae6-a09ec6140000 pid=5318 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=c22042e6-1f00-0000-8ae6-a09ec6140000 pid=5318 execve guuid=b909b5e6-1f00-0000-8ae6-a09ec7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=b909b5e6-1f00-0000-8ae6-a09ec7140000 pid=5319 execve guuid=561cb6f5-1f00-0000-8ae6-a09ec8140000 pid=5320 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=561cb6f5-1f00-0000-8ae6-a09ec8140000 pid=5320 execve guuid=ac7fa65b-2000-0000-8ae6-a09ec9140000 pid=5321 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=ac7fa65b-2000-0000-8ae6-a09ec9140000 pid=5321 execve guuid=f22b015c-2000-0000-8ae6-a09eca140000 pid=5322 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=f22b015c-2000-0000-8ae6-a09eca140000 pid=5322 clone guuid=d014105d-2000-0000-8ae6-a09ecc140000 pid=5324 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=d014105d-2000-0000-8ae6-a09ecc140000 pid=5324 execve guuid=289c3f60-2000-0000-8ae6-a09ecd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=289c3f60-2000-0000-8ae6-a09ecd140000 pid=5325 execve guuid=cd54c46b-2000-0000-8ae6-a09ece140000 pid=5326 /usr/bin/curl net send-data write-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=cd54c46b-2000-0000-8ae6-a09ece140000 pid=5326 execve guuid=c3203d81-2000-0000-8ae6-a09ecf140000 pid=5327 /usr/bin/chmod guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=c3203d81-2000-0000-8ae6-a09ecf140000 pid=5327 execve guuid=2c800a82-2000-0000-8ae6-a09ed0140000 pid=5328 /usr/bin/bash guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=2c800a82-2000-0000-8ae6-a09ed0140000 pid=5328 clone guuid=3754c684-2000-0000-8ae6-a09ed2140000 pid=5330 /usr/bin/rm delete-file guuid=c76b7742-1c00-0000-8ae6-a09e0a0e0000 pid=3594->guuid=3754c684-2000-0000-8ae6-a09ed2140000 pid=5330 execve dfc47e25-92ff-5564-add8-d07b7eeb210c 156.226.174.212:80 guuid=78c50443-1c00-0000-8ae6-a09e0c0e0000 pid=3596->dfc47e25-92ff-5564-add8-d07b7eeb210c send: 139B guuid=67ec6065-1c00-0000-8ae6-a09e520e0000 pid=3666->dfc47e25-92ff-5564-add8-d07b7eeb210c send: 88B guuid=e9419a72-1c00-0000-8ae6-a09e610e0000 pid=3681 /manji.x86 dns net send-data write-file zombie guuid=812c7d72-1c00-0000-8ae6-a09e600e0000 pid=3680->guuid=e9419a72-1c00-0000-8ae6-a09e610e0000 pid=3681 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e9419a72-1c00-0000-8ae6-a09e610e0000 pid=3681->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 496B 43701de0-3cf5-5e04-89d5-86946c0a8329 202604157.xyz:6621 guuid=e9419a72-1c00-0000-8ae6-a09e610e0000 pid=3681->43701de0-3cf5-5e04-89d5-86946c0a8329 send: 24B 4a808cca-efd6-528b-8215-1abdd6a9284d 202604157.xyz:80 guuid=8498fe72-1c00-0000-8ae6-a09e630e0000 pid=3683->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=e4f1b0b2-1c00-0000-8ae6-a09e1a0f0000 pid=3866->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=8450fdcc-1c00-0000-8ae6-a09e660f0000 pid=3942->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=c5a076d0-1c00-0000-8ae6-a09e730f0000 pid=3955->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=7b1769d7-1c00-0000-8ae6-a09e8e0f0000 pid=3982->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=882d05dd-1c00-0000-8ae6-a09ea10f0000 pid=4001->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=258bbce3-1c00-0000-8ae6-a09eb80f0000 pid=4024 /manji.i686 guuid=7932ade3-1c00-0000-8ae6-a09eb70f0000 pid=4023->guuid=258bbce3-1c00-0000-8ae6-a09eb80f0000 pid=4024 clone guuid=267b19e4-1c00-0000-8ae6-a09ebb0f0000 pid=4027->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=14ec25fa-1c00-0000-8ae6-a09efa0f0000 pid=4090->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=14135b1b-1d00-0000-8ae6-a09e5c100000 pid=4188->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=ad984753-1d00-0000-8ae6-a09e0a110000 pid=4362->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=0ee86767-1d00-0000-8ae6-a09e56110000 pid=4438->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=e816ada0-1d00-0000-8ae6-a09e19120000 pid=4633->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=a770dbba-1d00-0000-8ae6-a09e64120000 pid=4708->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=233b8ce8-1d00-0000-8ae6-a09eda120000 pid=4826->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=4f821d57-1e00-0000-8ae6-a09ec5130000 pid=5061->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=227e1091-1e00-0000-8ae6-a09ee2130000 pid=5090->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=2a2c84ae-1e00-0000-8ae6-a09e39140000 pid=5177->4a808cca-efd6-528b-8215-1abdd6a9284d send: 142B guuid=76e12cc5-1e00-0000-8ae6-a09e7a140000 pid=5242->4a808cca-efd6-528b-8215-1abdd6a9284d send: 91B guuid=fdf129f0-1e00-0000-8ae6-a09ea9140000 pid=5289->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=415b950c-1f00-0000-8ae6-a09eaa140000 pid=5290->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=32eb7a3d-1f00-0000-8ae6-a09eaf140000 pid=5295->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=47c52854-1f00-0000-8ae6-a09eb0140000 pid=5296->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=b2ea2673-1f00-0000-8ae6-a09eb5140000 pid=5301->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=15f1d9a1-1f00-0000-8ae6-a09eb6140000 pid=5302->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=f5c85eb1-1f00-0000-8ae6-a09ebf140000 pid=5311->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=7e8d31d1-1f00-0000-8ae6-a09ec2140000 pid=5314->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=b909b5e6-1f00-0000-8ae6-a09ec7140000 pid=5319->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=561cb6f5-1f00-0000-8ae6-a09ec8140000 pid=5320->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=289c3f60-2000-0000-8ae6-a09ecd140000 pid=5325->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=cd54c46b-2000-0000-8ae6-a09ece140000 pid=5326->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2026-05-09 12:06:14 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Traces itself
Family: Mirai
Malware Config
C2 Extraction:
boats.dogmuncher.xyz
89.190.156.145
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bee288e19bd82db0ffe4c2eb1d95d4c5ed63cd4640a75608e8c6006ae409c1b6

(this sample)

  
Delivery method
Distributed via web download

Comments