MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c586b34636d436e99d319b8de9c6c44bb187b13c0b88d8472b7cb2cfcefff0dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: c586b34636d436e99d319b8de9c6c44bb187b13c0b88d8472b7cb2cfcefff0dd
SHA3-384 hash: 7af1a42cfd10e1533a99fc0b55b7422c5fa9d7ccaded8f5b8168710ed57ebe67a590b2236c46489cd8db2b6384bffe53
SHA1 hash: 0015d78ceac08617af7977b07fed072ad155cda8
MD5 hash: 6c6ef370af412611d8974eb40874d7f8
humanhash: minnesota-bravo-oregon-early
File name:newreaxe.sh
Download: download sample
Signature Mirai
File size:3'183 bytes
First seen:2026-02-21 14:17:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:i+/RKQYaY+ukO4VYhAuGCLmJmxuUqTRTo36jpX:iSYaYUQGCLkmxmdo3gF
TLSH T1B661B8F693D246305EE55633A378AD04BD89E1E3B0862E209CEB25FEF84CE047005E97
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.x869d4303eab069f7f9052f482f94a2cf36d007bc8273348f007e2fb31659fcc255 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.mipsf037b103394bc2621207bfc87a644c2d3921db5f0bc8830e22758038b9af6296 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.arc31e871bf22741430a6da836e773480da675d3094e573cc0776645ba206578293 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.i686e77b92e6a48b0db91fa71a25942b9944cd9e954413c87ef00b65a4e48e4d0757 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.x86_64eade00d4707df8586ecdf50ef9860931f8200fa8067f5b2ac03a6cc317a42c59 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.mpsld91b528a22124afd79cdc73a5ed158f43b6c07bf90fa854aab581ce151abfec6 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.arm4b7d3b3cb2b1399e9f86a5e84691c33d3a4f806a65eec0c2e113cce4a9324182 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.arm5c83eeb7ecd43733b6531c7c91ae8fbc7e964b33542a0187461006a039b869daf Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.arm6a60936c68f3e00253a0befa778d9517e15e8c8352f728c22b4a64378c6bca8a5 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.arm7232faafe013b8a3895383311e3668777bff983272d144a63843b4cffa261c911 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.ppc61ea6093dea9f115fc84463f00f4466a9904156cad729b88701a8d89a8866383 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.spc2f94a82d6fa107ca045c7f6bc371d42d4900c4e2548502c23c47b490a8784aa1 Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.m68kc73c4346f62573bc8eea16c12e3b3dd57d7f5d08d9f61bea278c08fe819709fa Miraielf mirai ua-wget
http://192.3.154.52/x7k2m9v8b/m9x7k2v8b3.sh478f538eb0cfe15a3e91abf300dc80724a15025d4466b1a70c17bfdb3d0d985e4 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=087bcad1-1900-0000-926d-430ffe090000 pid=2558 /usr/bin/sudo guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568 /tmp/sample.bin guuid=087bcad1-1900-0000-926d-430ffe090000 pid=2558->guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568 execve guuid=2ca6aed4-1900-0000-926d-430f0a0a0000 pid=2570 /usr/bin/cp guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=2ca6aed4-1900-0000-926d-430f0a0a0000 pid=2570 execve guuid=b2bbf3d9-1900-0000-926d-430f160a0000 pid=2582 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=b2bbf3d9-1900-0000-926d-430f160a0000 pid=2582 execve guuid=57500df4-1900-0000-926d-430f6b0a0000 pid=2667 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=57500df4-1900-0000-926d-430f6b0a0000 pid=2667 execve guuid=03a78b10-1a00-0000-926d-430fb40a0000 pid=2740 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=03a78b10-1a00-0000-926d-430fb40a0000 pid=2740 execve guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742 /tmp/m9x7k2v8b3.x86 net guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742 execve guuid=9d744c3e-1b00-0000-926d-430fcf0c0000 pid=3279 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=9d744c3e-1b00-0000-926d-430fcf0c0000 pid=3279 execve guuid=a8d3db3e-1b00-0000-926d-430fd00c0000 pid=3280 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=a8d3db3e-1b00-0000-926d-430fd00c0000 pid=3280 execve guuid=0584bb5e-1b00-0000-926d-430f050d0000 pid=3333 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=0584bb5e-1b00-0000-926d-430f050d0000 pid=3333 execve guuid=456e977f-1b00-0000-926d-430f2d0d0000 pid=3373 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=456e977f-1b00-0000-926d-430f2d0d0000 pid=3373 execve guuid=8d030680-1b00-0000-926d-430f300d0000 pid=3376 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=8d030680-1b00-0000-926d-430f300d0000 pid=3376 clone guuid=3c2fa080-1b00-0000-926d-430f340d0000 pid=3380 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=3c2fa080-1b00-0000-926d-430f340d0000 pid=3380 execve guuid=37e60287-1b00-0000-926d-430f380d0000 pid=3384 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=37e60287-1b00-0000-926d-430f380d0000 pid=3384 execve guuid=ffab18a6-1b00-0000-926d-430f690d0000 pid=3433 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=ffab18a6-1b00-0000-926d-430f690d0000 pid=3433 execve guuid=99ecedc7-1b00-0000-926d-430fb40d0000 pid=3508 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=99ecedc7-1b00-0000-926d-430fb40d0000 pid=3508 execve guuid=071257c8-1b00-0000-926d-430fb60d0000 pid=3510 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=071257c8-1b00-0000-926d-430fb60d0000 pid=3510 clone guuid=9ee4bfca-1b00-0000-926d-430fbc0d0000 pid=3516 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=9ee4bfca-1b00-0000-926d-430fbc0d0000 pid=3516 execve guuid=def334cb-1b00-0000-926d-430fbf0d0000 pid=3519 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=def334cb-1b00-0000-926d-430fbf0d0000 pid=3519 execve guuid=18c040ea-1b00-0000-926d-430ff30d0000 pid=3571 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=18c040ea-1b00-0000-926d-430ff30d0000 pid=3571 execve guuid=6f30db09-1c00-0000-926d-430f430e0000 pid=3651 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=6f30db09-1c00-0000-926d-430f430e0000 pid=3651 execve guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654 /tmp/m9x7k2v8b3.i686 net guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654 execve guuid=f695e426-1e00-0000-926d-430f79140000 pid=5241 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=f695e426-1e00-0000-926d-430f79140000 pid=5241 execve guuid=41434b27-1e00-0000-926d-430f7a140000 pid=5242 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=41434b27-1e00-0000-926d-430f7a140000 pid=5242 execve guuid=9fc4ef45-1e00-0000-926d-430f86140000 pid=5254 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=9fc4ef45-1e00-0000-926d-430f86140000 pid=5254 execve guuid=b71d4c65-1e00-0000-926d-430f87140000 pid=5255 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=b71d4c65-1e00-0000-926d-430f87140000 pid=5255 execve guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256 /tmp/m9x7k2v8b3.x86_64 net guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256 execve guuid=57807d7f-2000-0000-926d-430fb5140000 pid=5301 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=57807d7f-2000-0000-926d-430fb5140000 pid=5301 execve guuid=931d1680-2000-0000-926d-430fb6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=931d1680-2000-0000-926d-430fb6140000 pid=5302 execve guuid=10318c9f-2000-0000-926d-430fb7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=10318c9f-2000-0000-926d-430fb7140000 pid=5303 execve guuid=020d18c0-2000-0000-926d-430fb8140000 pid=5304 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=020d18c0-2000-0000-926d-430fb8140000 pid=5304 execve guuid=33aab3c0-2000-0000-926d-430fb9140000 pid=5305 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=33aab3c0-2000-0000-926d-430fb9140000 pid=5305 clone guuid=84c9fbc1-2000-0000-926d-430fbb140000 pid=5307 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=84c9fbc1-2000-0000-926d-430fbb140000 pid=5307 execve guuid=15d185c2-2000-0000-926d-430fbc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=15d185c2-2000-0000-926d-430fbc140000 pid=5308 execve guuid=1d4945e1-2000-0000-926d-430fbd140000 pid=5309 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=1d4945e1-2000-0000-926d-430fbd140000 pid=5309 execve guuid=34dbdb01-2100-0000-926d-430fbe140000 pid=5310 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=34dbdb01-2100-0000-926d-430fbe140000 pid=5310 execve guuid=e2be7202-2100-0000-926d-430fbf140000 pid=5311 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=e2be7202-2100-0000-926d-430fbf140000 pid=5311 clone guuid=8e54ae03-2100-0000-926d-430fc1140000 pid=5313 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=8e54ae03-2100-0000-926d-430fc1140000 pid=5313 execve guuid=58184a04-2100-0000-926d-430fc2140000 pid=5314 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=58184a04-2100-0000-926d-430fc2140000 pid=5314 execve guuid=57076a1d-2100-0000-926d-430fc3140000 pid=5315 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=57076a1d-2100-0000-926d-430fc3140000 pid=5315 execve guuid=1ede8c38-2100-0000-926d-430fc4140000 pid=5316 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=1ede8c38-2100-0000-926d-430fc4140000 pid=5316 execve guuid=ef1a1939-2100-0000-926d-430fc5140000 pid=5317 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=ef1a1939-2100-0000-926d-430fc5140000 pid=5317 clone guuid=f8c83c3a-2100-0000-926d-430fc7140000 pid=5319 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=f8c83c3a-2100-0000-926d-430fc7140000 pid=5319 execve guuid=3d1bcf3a-2100-0000-926d-430fc8140000 pid=5320 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=3d1bcf3a-2100-0000-926d-430fc8140000 pid=5320 execve guuid=c561525d-2100-0000-926d-430fc9140000 pid=5321 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=c561525d-2100-0000-926d-430fc9140000 pid=5321 execve guuid=a1916f7e-2100-0000-926d-430fca140000 pid=5322 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=a1916f7e-2100-0000-926d-430fca140000 pid=5322 execve guuid=8ff8007f-2100-0000-926d-430fcb140000 pid=5323 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=8ff8007f-2100-0000-926d-430fcb140000 pid=5323 clone guuid=6e412380-2100-0000-926d-430fcd140000 pid=5325 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=6e412380-2100-0000-926d-430fcd140000 pid=5325 execve guuid=2a28b480-2100-0000-926d-430fce140000 pid=5326 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=2a28b480-2100-0000-926d-430fce140000 pid=5326 execve guuid=7e2446a0-2100-0000-926d-430fcf140000 pid=5327 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=7e2446a0-2100-0000-926d-430fcf140000 pid=5327 execve guuid=449133c1-2100-0000-926d-430fd0140000 pid=5328 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=449133c1-2100-0000-926d-430fd0140000 pid=5328 execve guuid=342dc2c1-2100-0000-926d-430fd1140000 pid=5329 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=342dc2c1-2100-0000-926d-430fd1140000 pid=5329 clone guuid=e22fe9c2-2100-0000-926d-430fd3140000 pid=5331 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=e22fe9c2-2100-0000-926d-430fd3140000 pid=5331 execve guuid=2ee683c3-2100-0000-926d-430fd4140000 pid=5332 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=2ee683c3-2100-0000-926d-430fd4140000 pid=5332 execve guuid=3f08ede2-2100-0000-926d-430fd5140000 pid=5333 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=3f08ede2-2100-0000-926d-430fd5140000 pid=5333 execve guuid=caba1804-2200-0000-926d-430fd6140000 pid=5334 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=caba1804-2200-0000-926d-430fd6140000 pid=5334 execve guuid=ababa304-2200-0000-926d-430fd7140000 pid=5335 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=ababa304-2200-0000-926d-430fd7140000 pid=5335 clone guuid=4b0ed705-2200-0000-926d-430fd9140000 pid=5337 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=4b0ed705-2200-0000-926d-430fd9140000 pid=5337 execve guuid=fbe87206-2200-0000-926d-430fda140000 pid=5338 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=fbe87206-2200-0000-926d-430fda140000 pid=5338 execve guuid=d61ada25-2200-0000-926d-430fdb140000 pid=5339 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=d61ada25-2200-0000-926d-430fdb140000 pid=5339 execve guuid=785ed346-2200-0000-926d-430fdc140000 pid=5340 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=785ed346-2200-0000-926d-430fdc140000 pid=5340 execve guuid=2cc61747-2200-0000-926d-430fdd140000 pid=5341 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=2cc61747-2200-0000-926d-430fdd140000 pid=5341 clone guuid=e93dae47-2200-0000-926d-430fdf140000 pid=5343 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=e93dae47-2200-0000-926d-430fdf140000 pid=5343 execve guuid=37e9f947-2200-0000-926d-430fe0140000 pid=5344 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=37e9f947-2200-0000-926d-430fe0140000 pid=5344 execve guuid=c13a0666-2200-0000-926d-430fe1140000 pid=5345 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=c13a0666-2200-0000-926d-430fe1140000 pid=5345 execve guuid=bb50e784-2200-0000-926d-430fe2140000 pid=5346 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=bb50e784-2200-0000-926d-430fe2140000 pid=5346 execve guuid=47a48585-2200-0000-926d-430fe3140000 pid=5347 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=47a48585-2200-0000-926d-430fe3140000 pid=5347 clone guuid=4df0c686-2200-0000-926d-430fe5140000 pid=5349 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=4df0c686-2200-0000-926d-430fe5140000 pid=5349 execve guuid=53f50d88-2200-0000-926d-430fe6140000 pid=5350 /usr/bin/wget net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=53f50d88-2200-0000-926d-430fe6140000 pid=5350 execve guuid=d203c7a1-2200-0000-926d-430fe7140000 pid=5351 /usr/bin/curl net send-data write-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=d203c7a1-2200-0000-926d-430fe7140000 pid=5351 execve guuid=b53ff5bc-2200-0000-926d-430fe8140000 pid=5352 /usr/bin/chmod guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=b53ff5bc-2200-0000-926d-430fe8140000 pid=5352 execve guuid=b61d98bd-2200-0000-926d-430fe9140000 pid=5353 /usr/bin/bash guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=b61d98bd-2200-0000-926d-430fe9140000 pid=5353 clone guuid=e03ddbbe-2200-0000-926d-430feb140000 pid=5355 /usr/bin/rm delete-file guuid=e2a13fd4-1900-0000-926d-430f080a0000 pid=2568->guuid=e03ddbbe-2200-0000-926d-430feb140000 pid=5355 execve 1a25d009-e9f5-535b-9794-133757a79f2f 192.3.154.52:80 guuid=b2bbf3d9-1900-0000-926d-430f160a0000 pid=2582->1a25d009-e9f5-535b-9794-133757a79f2f send: 151B guuid=57500df4-1900-0000-926d-430f6b0a0000 pid=2667->1a25d009-e9f5-535b-9794-133757a79f2f send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9faec211-1a00-0000-926d-430fba0a0000 pid=2746 /tmp/m9x7k2v8b3.x86 guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742->guuid=9faec211-1a00-0000-926d-430fba0a0000 pid=2746 clone guuid=6a1f2c3e-1b00-0000-926d-430fcd0c0000 pid=3277 /tmp/m9x7k2v8b3.x86 guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742->guuid=6a1f2c3e-1b00-0000-926d-430fcd0c0000 pid=3277 clone guuid=f45b343e-1b00-0000-926d-430fce0c0000 pid=3278 /tmp/m9x7k2v8b3.x86 net send-data zombie guuid=74d6cd10-1a00-0000-926d-430fb60a0000 pid=2742->guuid=f45b343e-1b00-0000-926d-430fce0c0000 pid=3278 clone guuid=90accd11-1a00-0000-926d-430fbb0a0000 pid=2747 /tmp/m9x7k2v8b3.x86 guuid=9faec211-1a00-0000-926d-430fba0a0000 pid=2746->guuid=90accd11-1a00-0000-926d-430fbb0a0000 pid=2747 clone guuid=45ead511-1a00-0000-926d-430fbc0a0000 pid=2748 /tmp/m9x7k2v8b3.x86 dns net send-data zombie guuid=9faec211-1a00-0000-926d-430fba0a0000 pid=2746->guuid=45ead511-1a00-0000-926d-430fbc0a0000 pid=2748 clone guuid=45ead511-1a00-0000-926d-430fbc0a0000 pid=2748->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B 852eada3-51ac-5275-909a-778490b5e6b0 play.mclighthouse.ir:6742 guuid=45ead511-1a00-0000-926d-430fbc0a0000 pid=2748->852eada3-51ac-5275-909a-778490b5e6b0 send: 14B guuid=f45b343e-1b00-0000-926d-430fce0c0000 pid=3278->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 390B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=f45b343e-1b00-0000-926d-430fce0c0000 pid=3278->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B ad785374-9e7c-5217-acbe-83a9cb2f51b9 play.mclighthouse.ir:80 guuid=a8d3db3e-1b00-0000-926d-430fd00c0000 pid=3280->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=0584bb5e-1b00-0000-926d-430f050d0000 pid=3333->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=37e60287-1b00-0000-926d-430f380d0000 pid=3384->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=ffab18a6-1b00-0000-926d-430f690d0000 pid=3433->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=def334cb-1b00-0000-926d-430fbf0d0000 pid=3519->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=18c040ea-1b00-0000-926d-430ff30d0000 pid=3571->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e0bf5d61-49c5-55e5-bd8d-1372a3652280 127.0.0.1:69 guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654->e0bf5d61-49c5-55e5-bd8d-1372a3652280 con guuid=6c3b52fa-1c00-0000-926d-430fbe100000 pid=4286 /tmp/m9x7k2v8b3.i686 guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654->guuid=6c3b52fa-1c00-0000-926d-430fbe100000 pid=4286 clone guuid=2576c826-1e00-0000-926d-430f77140000 pid=5239 /tmp/m9x7k2v8b3.i686 guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654->guuid=2576c826-1e00-0000-926d-430f77140000 pid=5239 clone guuid=4a7ed426-1e00-0000-926d-430f78140000 pid=5240 /tmp/m9x7k2v8b3.i686 net send-data zombie guuid=3ea5660a-1c00-0000-926d-430f460e0000 pid=3654->guuid=4a7ed426-1e00-0000-926d-430f78140000 pid=5240 clone guuid=648559fa-1c00-0000-926d-430fbf100000 pid=4287 /tmp/m9x7k2v8b3.i686 guuid=6c3b52fa-1c00-0000-926d-430fbe100000 pid=4286->guuid=648559fa-1c00-0000-926d-430fbf100000 pid=4287 clone guuid=06215efa-1c00-0000-926d-430fc0100000 pid=4288 /tmp/m9x7k2v8b3.i686 dns net send-data zombie guuid=6c3b52fa-1c00-0000-926d-430fbe100000 pid=4286->guuid=06215efa-1c00-0000-926d-430fc0100000 pid=4288 clone guuid=06215efa-1c00-0000-926d-430fc0100000 pid=4288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=06215efa-1c00-0000-926d-430fc0100000 pid=4288->852eada3-51ac-5275-909a-778490b5e6b0 send: 16B guuid=4a7ed426-1e00-0000-926d-430f78140000 pid=5240->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B guuid=4a7ed426-1e00-0000-926d-430f78140000 pid=5240->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=41434b27-1e00-0000-926d-430f7a140000 pid=5242->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 154B guuid=9fc4ef45-1e00-0000-926d-430f86140000 pid=5254->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 103B guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256->e0bf5d61-49c5-55e5-bd8d-1372a3652280 con guuid=f313a954-1f00-0000-926d-430f90140000 pid=5264 /tmp/m9x7k2v8b3.x86_64 guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256->guuid=f313a954-1f00-0000-926d-430f90140000 pid=5264 clone guuid=4bd5567f-2000-0000-926d-430fb3140000 pid=5299 /tmp/m9x7k2v8b3.x86_64 guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256->guuid=4bd5567f-2000-0000-926d-430fb3140000 pid=5299 clone guuid=2cb05f7f-2000-0000-926d-430fb4140000 pid=5300 /tmp/m9x7k2v8b3.x86_64 dns net send-data zombie guuid=1f40ba65-1e00-0000-926d-430f88140000 pid=5256->guuid=2cb05f7f-2000-0000-926d-430fb4140000 pid=5300 clone guuid=1f524755-1f00-0000-926d-430f91140000 pid=5265 /tmp/m9x7k2v8b3.x86_64 guuid=f313a954-1f00-0000-926d-430f90140000 pid=5264->guuid=1f524755-1f00-0000-926d-430f91140000 pid=5265 clone guuid=5cb94d55-1f00-0000-926d-430f92140000 pid=5266 /tmp/m9x7k2v8b3.x86_64 dns net send-data zombie guuid=f313a954-1f00-0000-926d-430f90140000 pid=5264->guuid=5cb94d55-1f00-0000-926d-430f92140000 pid=5266 clone guuid=5cb94d55-1f00-0000-926d-430f92140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=5cb94d55-1f00-0000-926d-430f92140000 pid=5266->852eada3-51ac-5275-909a-778490b5e6b0 send: 16B guuid=2cb05f7f-2000-0000-926d-430fb4140000 pid=5300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=2cb05f7f-2000-0000-926d-430fb4140000 pid=5300->852eada3-51ac-5275-909a-778490b5e6b0 send: 16B guuid=931d1680-2000-0000-926d-430fb6140000 pid=5302->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=10318c9f-2000-0000-926d-430fb7140000 pid=5303->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=15d185c2-2000-0000-926d-430fbc140000 pid=5308->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=1d4945e1-2000-0000-926d-430fbd140000 pid=5309->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=58184a04-2100-0000-926d-430fc2140000 pid=5314->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=57076a1d-2100-0000-926d-430fc3140000 pid=5315->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=3d1bcf3a-2100-0000-926d-430fc8140000 pid=5320->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=c561525d-2100-0000-926d-430fc9140000 pid=5321->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=2a28b480-2100-0000-926d-430fce140000 pid=5326->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=7e2446a0-2100-0000-926d-430fcf140000 pid=5327->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=2ee683c3-2100-0000-926d-430fd4140000 pid=5332->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=3f08ede2-2100-0000-926d-430fd5140000 pid=5333->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=fbe87206-2200-0000-926d-430fda140000 pid=5338->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=d61ada25-2200-0000-926d-430fdb140000 pid=5339->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=37e9f947-2200-0000-926d-430fe0140000 pid=5344->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=c13a0666-2200-0000-926d-430fe1140000 pid=5345->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=53f50d88-2200-0000-926d-430fe6140000 pid=5350->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=d203c7a1-2200-0000-926d-430fe7140000 pid=5351->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c586b34636d436e99d319b8de9c6c44bb187b13c0b88d8472b7cb2cfcefff0dd

(this sample)

  
Delivery method
Distributed via web download

Comments