🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c2490973c357f0586349a22fd890577c53f0ecf42e537abe103c41d5154c2b98. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: c2490973c357f0586349a22fd890577c53f0ecf42e537abe103c41d5154c2b98
SHA3-384 hash: 8f4187b708a3541a0af8ce5c9c366396515dae8ed29b3ab0668b1269121bdd26bbfad1d22d85d8a83666f04b27d4f2c3
SHA1 hash: ede3218f2ba0ee7aa26ccf80b5ae63c8afe0c0b1
MD5 hash: d08edf66b8710449e2b2bc386d703f7b
humanhash: sodium-shade-alanine-gee
File name:lilin.sh
Download: download sample
Signature Mirai
File size:803 bytes
First seen:2025-08-16 13:14:15 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:dZoJ2egeKNWKDbnPZM5ZMoOF7+MB05L7GtOx7GtNDNkL7G9vx7G9MDNkL7GGyTxs:E22IbO5zOt+MB0hR+kLspsmkLGhkV
TLSH T177016BCE56A59C71D8940CDA32564918A8CEC4D817CB8E89A1C90439D0CDD0470A3FA9
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.51.126.131/v/armv4le333d6098ba7af114b4e8b290f0e587592067b8e153798bf4763262d2074ad96 Miraielf mirai ua-wget
http://158.51.126.131/v/armv5l79d810e67c7bd6c6669214c1c4b631829d90726886b4167a232813d8434ef3f7 Miraielf mirai ua-wget
http://158.51.126.131/v/armv7lc3788d92bfc3a08dbcca4476832c46b099bcad182c56cdbccf837eb0edb6cd77 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=3cc044ea-1800-0000-7c3c-7081c00a0000 pid=2752 /usr/bin/sudo guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756 /tmp/sample.bin guuid=3cc044ea-1800-0000-7c3c-7081c00a0000 pid=2752->guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756 execve guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757 clone guuid=4c5ec7ed-1800-0000-7c3c-7081cb0a0000 pid=2763 /usr/bin/rm delete-file guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=4c5ec7ed-1800-0000-7c3c-7081cb0a0000 pid=2763 execve guuid=2e933eee-1800-0000-7c3c-7081cc0a0000 pid=2764 /usr/bin/rm delete-file guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=2e933eee-1800-0000-7c3c-7081cc0a0000 pid=2764 execve guuid=ea54bbee-1800-0000-7c3c-7081cd0a0000 pid=2765 /usr/bin/rm delete-file guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=ea54bbee-1800-0000-7c3c-7081cd0a0000 pid=2765 execve guuid=fbc398ef-1800-0000-7c3c-7081ce0a0000 pid=2766 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=fbc398ef-1800-0000-7c3c-7081ce0a0000 pid=2766 clone guuid=68f28ff0-1800-0000-7c3c-7081d10a0000 pid=2769 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=68f28ff0-1800-0000-7c3c-7081d10a0000 pid=2769 clone guuid=37dee1f0-1800-0000-7c3c-7081d30a0000 pid=2771 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=37dee1f0-1800-0000-7c3c-7081d30a0000 pid=2771 clone guuid=69637716-1900-0000-7c3c-7081110b0000 pid=2833 /usr/bin/chmod guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=69637716-1900-0000-7c3c-7081110b0000 pid=2833 execve guuid=2fac0f17-1900-0000-7c3c-7081130b0000 pid=2835 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=2fac0f17-1900-0000-7c3c-7081130b0000 pid=2835 clone guuid=2418d517-1900-0000-7c3c-7081160b0000 pid=2838 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=2418d517-1900-0000-7c3c-7081160b0000 pid=2838 clone guuid=134e8843-1900-0000-7c3c-70817b0b0000 pid=2939 /usr/bin/chmod guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=134e8843-1900-0000-7c3c-70817b0b0000 pid=2939 execve guuid=15b0e943-1900-0000-7c3c-70817d0b0000 pid=2941 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=15b0e943-1900-0000-7c3c-70817d0b0000 pid=2941 clone guuid=858e7f44-1900-0000-7c3c-7081800b0000 pid=2944 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=858e7f44-1900-0000-7c3c-7081800b0000 pid=2944 clone guuid=1499f86e-1900-0000-7c3c-7081d40b0000 pid=3028 /usr/bin/chmod guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=1499f86e-1900-0000-7c3c-7081d40b0000 pid=3028 execve guuid=de543d6f-1900-0000-7c3c-7081d50b0000 pid=3029 /usr/bin/dash guuid=5bf933ec-1800-0000-7c3c-7081c40a0000 pid=2756->guuid=de543d6f-1900-0000-7c3c-7081d50b0000 pid=3029 clone guuid=8b78acec-1800-0000-7c3c-7081c60a0000 pid=2758 /usr/bin/cat guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757->guuid=8b78acec-1800-0000-7c3c-7081c60a0000 pid=2758 execve guuid=0b9bbdec-1800-0000-7c3c-7081c70a0000 pid=2759 /usr/bin/grep guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757->guuid=0b9bbdec-1800-0000-7c3c-7081c70a0000 pid=2759 execve guuid=939ec8ec-1800-0000-7c3c-7081c80a0000 pid=2760 /usr/bin/grep guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757->guuid=939ec8ec-1800-0000-7c3c-7081c80a0000 pid=2760 execve guuid=6a96d8ec-1800-0000-7c3c-7081c90a0000 pid=2761 /usr/bin/grep guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757->guuid=6a96d8ec-1800-0000-7c3c-7081c90a0000 pid=2761 execve guuid=0a07e8ec-1800-0000-7c3c-7081ca0a0000 pid=2762 /usr/bin/cut guuid=32cc98ec-1800-0000-7c3c-7081c50a0000 pid=2757->guuid=0a07e8ec-1800-0000-7c3c-7081ca0a0000 pid=2762 execve guuid=11f6a3ef-1800-0000-7c3c-7081cf0a0000 pid=2767 /usr/bin/cp write-file guuid=fbc398ef-1800-0000-7c3c-7081ce0a0000 pid=2766->guuid=11f6a3ef-1800-0000-7c3c-7081cf0a0000 pid=2767 execve guuid=f2549af0-1800-0000-7c3c-7081d20a0000 pid=2770 /usr/bin/chmod guuid=68f28ff0-1800-0000-7c3c-7081d10a0000 pid=2769->guuid=f2549af0-1800-0000-7c3c-7081d20a0000 pid=2770 execve guuid=0876f0f0-1800-0000-7c3c-7081d40a0000 pid=2772 /usr/bin/wget net send-data write-file guuid=37dee1f0-1800-0000-7c3c-7081d30a0000 pid=2771->guuid=0876f0f0-1800-0000-7c3c-7081d40a0000 pid=2772 execve 2beca644-24da-5e18-bc49-c06b8c4a111d 158.51.126.131:80 guuid=0876f0f0-1800-0000-7c3c-7081d40a0000 pid=2772->2beca644-24da-5e18-bc49-c06b8c4a111d send: 137B guuid=f813dd17-1900-0000-7c3c-7081170b0000 pid=2839 /usr/bin/wget net send-data write-file guuid=2418d517-1900-0000-7c3c-7081160b0000 pid=2838->guuid=f813dd17-1900-0000-7c3c-7081170b0000 pid=2839 execve guuid=f813dd17-1900-0000-7c3c-7081170b0000 pid=2839->2beca644-24da-5e18-bc49-c06b8c4a111d send: 137B guuid=3fcd8744-1900-0000-7c3c-7081810b0000 pid=2945 /usr/bin/wget net send-data write-file guuid=858e7f44-1900-0000-7c3c-7081800b0000 pid=2944->guuid=3fcd8744-1900-0000-7c3c-7081810b0000 pid=2945 execve guuid=3fcd8744-1900-0000-7c3c-7081810b0000 pid=2945->2beca644-24da-5e18-bc49-c06b8c4a111d send: 137B
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-16 01:13:40 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c2490973c357f0586349a22fd890577c53f0ecf42e537abe103c41d5154c2b98

(this sample)

  
Delivery method
Distributed via web download

Comments