MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c970c135eaa6231d37c8ffc38a8a4e0af01807d0831a48254b013e1012942be9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: c970c135eaa6231d37c8ffc38a8a4e0af01807d0831a48254b013e1012942be9
SHA3-384 hash: 6a9d50d6afa5a0d477d615e911ac4d8214716bb6a856749ff12444da8807d51a329e96591b8f98d43a0b638044ccb10a
SHA1 hash: b1a80494011648aad602c6f2ae19a0d749fcaa1c
MD5 hash: d7188d83b5d4304a1e3fd81fb8bdfe25
humanhash: enemy-may-snake-cardinal
File name:wget_telnet.sh
Download: download sample
Signature Mirai
File size:1'954 bytes
First seen:2025-12-23 09:41:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:pIbdnsJavnhhapwMZBZZhVfRl7AF3OHnENMZ:pc9+u/aGuBvhtHWS
TLSH T1C241EDED12811B7B30064A29A3E355AD9C468FD1718A576CD5897C1B8C0F71C7BF9E83
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.35.154/powerpc.uhavenobotsxdfc48390d60758ec26e3a1c1314ce538802079dd154494300fdd281745d9ac090 Miraielf geofenced mirai PowerPC ua-wget USA
http://94.154.35.154/mips.uhavenobotsxd44fb5cec7763ef8e3dfc5b574cd8118e4ba2ed38a4eaf72d4ce0ba6d13d99c73 Miraielf geofenced mips mirai ua-wget USA
http://94.154.35.154/mipsel.uhavenobotsxd595e67a0aa012fa9f2a9ad2919987dd362429b9eca1d5e94343a7fc64ca6bbc4 Miraielf geofenced mips mirai ua-wget USA
http://94.154.35.154/arm.uhavenobotsxd9e2ebe9f81e7b1fe0b3e25cdb4b43ab7bf8af4126e52ec9ccbb0333e24215ff7 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm5.uhavenobotsxdbbb67b5361c5abd6ac16953cb8947448c9b3df5386effa20da4ccf8adc36634a Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm6.uhavenobotsxd629a8a33e8baf5a26c87e3e026222fefa0a60da32c392f14a3b7d8913276e57f Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm7.uhavenobotsxdadbbe9fff1c2e36174fc27bc1f6e5dcdb8338fc59e86b75a85857e444600e8d1 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/sparc.uhavenobotsxdn/an/aelf ua-wget
http://94.154.35.154/m68k.uhavenobotsxdn/an/aelf ua-wget
http://94.154.35.154/sh4.uhavenobotsxdn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-23T06:50:00Z UTC
Last seen:
2025-12-23T09:35:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=b7fab97a-1900-0000-a586-7a5968140000 pid=5224 /usr/bin/sudo guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225 /tmp/sample.bin guuid=b7fab97a-1900-0000-a586-7a5968140000 pid=5224->guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225 execve guuid=4aac1c7e-1900-0000-a586-7a596a140000 pid=5226 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=4aac1c7e-1900-0000-a586-7a596a140000 pid=5226 execve guuid=a6847c9e-1900-0000-a586-7a596b140000 pid=5227 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=a6847c9e-1900-0000-a586-7a596b140000 pid=5227 execve guuid=a3334bb5-1900-0000-a586-7a596c140000 pid=5228 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=a3334bb5-1900-0000-a586-7a596c140000 pid=5228 execve guuid=38fda2b5-1900-0000-a586-7a596d140000 pid=5229 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=38fda2b5-1900-0000-a586-7a596d140000 pid=5229 clone guuid=68926db7-1900-0000-a586-7a596f140000 pid=5231 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=68926db7-1900-0000-a586-7a596f140000 pid=5231 execve guuid=6b97cbb7-1900-0000-a586-7a5970140000 pid=5232 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=6b97cbb7-1900-0000-a586-7a5970140000 pid=5232 execve guuid=5d398bca-1900-0000-a586-7a5971140000 pid=5233 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=5d398bca-1900-0000-a586-7a5971140000 pid=5233 execve guuid=3b0d34e0-1900-0000-a586-7a5972140000 pid=5234 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=3b0d34e0-1900-0000-a586-7a5972140000 pid=5234 execve guuid=107be0e0-1900-0000-a586-7a5973140000 pid=5235 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=107be0e0-1900-0000-a586-7a5973140000 pid=5235 clone guuid=42f059e2-1900-0000-a586-7a5975140000 pid=5237 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=42f059e2-1900-0000-a586-7a5975140000 pid=5237 execve guuid=65e6d5e2-1900-0000-a586-7a5976140000 pid=5238 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=65e6d5e2-1900-0000-a586-7a5976140000 pid=5238 execve guuid=dd9bfff4-1900-0000-a586-7a597e140000 pid=5246 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=dd9bfff4-1900-0000-a586-7a597e140000 pid=5246 execve guuid=24f3e50c-1a00-0000-a586-7a597f140000 pid=5247 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=24f3e50c-1a00-0000-a586-7a597f140000 pid=5247 execve guuid=13b6450d-1a00-0000-a586-7a5980140000 pid=5248 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=13b6450d-1a00-0000-a586-7a5980140000 pid=5248 clone guuid=cbc5100e-1a00-0000-a586-7a5982140000 pid=5250 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=cbc5100e-1a00-0000-a586-7a5982140000 pid=5250 execve guuid=447a9f0e-1a00-0000-a586-7a5983140000 pid=5251 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=447a9f0e-1a00-0000-a586-7a5983140000 pid=5251 execve guuid=ab212d20-1a00-0000-a586-7a5984140000 pid=5252 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=ab212d20-1a00-0000-a586-7a5984140000 pid=5252 execve guuid=8019a835-1a00-0000-a586-7a5985140000 pid=5253 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=8019a835-1a00-0000-a586-7a5985140000 pid=5253 execve guuid=78115c36-1a00-0000-a586-7a5986140000 pid=5254 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=78115c36-1a00-0000-a586-7a5986140000 pid=5254 clone guuid=d832a338-1a00-0000-a586-7a5988140000 pid=5256 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=d832a338-1a00-0000-a586-7a5988140000 pid=5256 execve guuid=9bcfda39-1a00-0000-a586-7a5989140000 pid=5257 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=9bcfda39-1a00-0000-a586-7a5989140000 pid=5257 execve guuid=e85f4064-1a00-0000-a586-7a598a140000 pid=5258 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=e85f4064-1a00-0000-a586-7a598a140000 pid=5258 execve guuid=2b54be80-1a00-0000-a586-7a598b140000 pid=5259 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=2b54be80-1a00-0000-a586-7a598b140000 pid=5259 execve guuid=77c92b81-1a00-0000-a586-7a598c140000 pid=5260 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=77c92b81-1a00-0000-a586-7a598c140000 pid=5260 clone guuid=fcc7a983-1a00-0000-a586-7a598e140000 pid=5262 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=fcc7a983-1a00-0000-a586-7a598e140000 pid=5262 execve guuid=ffa14384-1a00-0000-a586-7a598f140000 pid=5263 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=ffa14384-1a00-0000-a586-7a598f140000 pid=5263 execve guuid=286ded9a-1a00-0000-a586-7a5990140000 pid=5264 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=286ded9a-1a00-0000-a586-7a5990140000 pid=5264 execve guuid=cb5049ae-1a00-0000-a586-7a5991140000 pid=5265 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=cb5049ae-1a00-0000-a586-7a5991140000 pid=5265 execve guuid=724090ae-1a00-0000-a586-7a5992140000 pid=5266 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=724090ae-1a00-0000-a586-7a5992140000 pid=5266 clone guuid=755e15af-1a00-0000-a586-7a5994140000 pid=5268 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=755e15af-1a00-0000-a586-7a5994140000 pid=5268 execve guuid=b2324eaf-1a00-0000-a586-7a5995140000 pid=5269 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=b2324eaf-1a00-0000-a586-7a5995140000 pid=5269 execve guuid=03a2a8c1-1a00-0000-a586-7a5996140000 pid=5270 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=03a2a8c1-1a00-0000-a586-7a5996140000 pid=5270 execve guuid=04963cd5-1a00-0000-a586-7a5997140000 pid=5271 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=04963cd5-1a00-0000-a586-7a5997140000 pid=5271 execve guuid=7e9d40d6-1a00-0000-a586-7a5998140000 pid=5272 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=7e9d40d6-1a00-0000-a586-7a5998140000 pid=5272 clone guuid=64f870d7-1a00-0000-a586-7a599a140000 pid=5274 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=64f870d7-1a00-0000-a586-7a599a140000 pid=5274 execve guuid=1064dfd7-1a00-0000-a586-7a599b140000 pid=5275 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=1064dfd7-1a00-0000-a586-7a599b140000 pid=5275 execve guuid=04ac37ea-1a00-0000-a586-7a59a1140000 pid=5281 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=04ac37ea-1a00-0000-a586-7a59a1140000 pid=5281 execve guuid=8ce7aeff-1a00-0000-a586-7a59a3140000 pid=5283 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=8ce7aeff-1a00-0000-a586-7a59a3140000 pid=5283 execve guuid=b3183b00-1b00-0000-a586-7a59a4140000 pid=5284 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=b3183b00-1b00-0000-a586-7a59a4140000 pid=5284 clone guuid=67d6cd00-1b00-0000-a586-7a59a6140000 pid=5286 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=67d6cd00-1b00-0000-a586-7a59a6140000 pid=5286 execve guuid=87254f01-1b00-0000-a586-7a59a7140000 pid=5287 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=87254f01-1b00-0000-a586-7a59a7140000 pid=5287 execve guuid=d659911a-1b00-0000-a586-7a59b0140000 pid=5296 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=d659911a-1b00-0000-a586-7a59b0140000 pid=5296 execve guuid=d5f70e26-1b00-0000-a586-7a59b2140000 pid=5298 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=d5f70e26-1b00-0000-a586-7a59b2140000 pid=5298 execve guuid=ee419d26-1b00-0000-a586-7a59b3140000 pid=5299 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=ee419d26-1b00-0000-a586-7a59b3140000 pid=5299 clone guuid=229d0b27-1b00-0000-a586-7a59b5140000 pid=5301 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=229d0b27-1b00-0000-a586-7a59b5140000 pid=5301 execve guuid=ba14a727-1b00-0000-a586-7a59b6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=ba14a727-1b00-0000-a586-7a59b6140000 pid=5302 execve guuid=aba8263b-1b00-0000-a586-7a59ba140000 pid=5306 /usr/bin/curl net send-data write-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=aba8263b-1b00-0000-a586-7a59ba140000 pid=5306 execve guuid=2f7cea46-1b00-0000-a586-7a59c6140000 pid=5318 /usr/bin/chmod guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=2f7cea46-1b00-0000-a586-7a59c6140000 pid=5318 execve guuid=404d5547-1b00-0000-a586-7a59c7140000 pid=5319 /usr/bin/bash guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=404d5547-1b00-0000-a586-7a59c7140000 pid=5319 clone guuid=2556af47-1b00-0000-a586-7a59ca140000 pid=5322 /usr/bin/rm delete-file guuid=4107a17d-1900-0000-a586-7a5969140000 pid=5225->guuid=2556af47-1b00-0000-a586-7a59ca140000 pid=5322 execve 64a07662-ebdf-52ea-9140-fd99af91f8af 94.154.35.154:80 guuid=4aac1c7e-1900-0000-a586-7a596a140000 pid=5226->64a07662-ebdf-52ea-9140-fd99af91f8af send: 149B guuid=a6847c9e-1900-0000-a586-7a596b140000 pid=5227->64a07662-ebdf-52ea-9140-fd99af91f8af send: 98B guuid=6b97cbb7-1900-0000-a586-7a5970140000 pid=5232->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=5d398bca-1900-0000-a586-7a5971140000 pid=5233->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=65e6d5e2-1900-0000-a586-7a5976140000 pid=5238->64a07662-ebdf-52ea-9140-fd99af91f8af send: 148B guuid=dd9bfff4-1900-0000-a586-7a597e140000 pid=5246->64a07662-ebdf-52ea-9140-fd99af91f8af send: 97B guuid=447a9f0e-1a00-0000-a586-7a5983140000 pid=5251->64a07662-ebdf-52ea-9140-fd99af91f8af send: 145B guuid=ab212d20-1a00-0000-a586-7a5984140000 pid=5252->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B guuid=9bcfda39-1a00-0000-a586-7a5989140000 pid=5257->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=e85f4064-1a00-0000-a586-7a598a140000 pid=5258->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=ffa14384-1a00-0000-a586-7a598f140000 pid=5263->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=286ded9a-1a00-0000-a586-7a5990140000 pid=5264->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=b2324eaf-1a00-0000-a586-7a5995140000 pid=5269->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=03a2a8c1-1a00-0000-a586-7a5996140000 pid=5270->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=1064dfd7-1a00-0000-a586-7a599b140000 pid=5275->64a07662-ebdf-52ea-9140-fd99af91f8af send: 282B guuid=04ac37ea-1a00-0000-a586-7a59a1140000 pid=5281->64a07662-ebdf-52ea-9140-fd99af91f8af send: 96B guuid=933d8100-1b00-0000-a586-7a59a5140000 pid=5285 /usr/bin/bash guuid=b3183b00-1b00-0000-a586-7a59a4140000 pid=5284->guuid=933d8100-1b00-0000-a586-7a59a5140000 pid=5285 clone guuid=87254f01-1b00-0000-a586-7a59a7140000 pid=5287->64a07662-ebdf-52ea-9140-fd99af91f8af send: 281B guuid=d659911a-1b00-0000-a586-7a59b0140000 pid=5296->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=d389cc26-1b00-0000-a586-7a59b4140000 pid=5300 /usr/bin/bash guuid=ee419d26-1b00-0000-a586-7a59b3140000 pid=5299->guuid=d389cc26-1b00-0000-a586-7a59b4140000 pid=5300 clone guuid=ba14a727-1b00-0000-a586-7a59b6140000 pid=5302->64a07662-ebdf-52ea-9140-fd99af91f8af send: 280B guuid=aba8263b-1b00-0000-a586-7a59ba140000 pid=5306->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B guuid=c9ab7547-1b00-0000-a586-7a59c9140000 pid=5321 /usr/bin/bash guuid=404d5547-1b00-0000-a586-7a59c7140000 pid=5319->guuid=c9ab7547-1b00-0000-a586-7a59c9140000 pid=5321 clone
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2025-12-23 09:42:16 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Deletes log files
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c970c135eaa6231d37c8ffc38a8a4e0af01807d0831a48254b013e1012942be9

(this sample)

  
Delivery method
Distributed via web download

Comments