MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d025eb12dc4be6b1183406858e9e6cc4564788928e678db1b6bb218c70bf8c28. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: d025eb12dc4be6b1183406858e9e6cc4564788928e678db1b6bb218c70bf8c28
SHA3-384 hash: 89f73c62f67c89c69a663fc1b3d4e75e698dbb383358ca8d9d5fd40d15103e47f5041627fcb03a5614844914dd135033
SHA1 hash: 82e6bbc7ad55c67b7e5960c065d8ed85b5a2cf22
MD5 hash: 8aa5bfb0ed7cda49f63516b9657ea248
humanhash: social-blossom-thirteen-snake
File name:lol.sh
Download: download sample
Signature Mirai
File size:5'730 bytes
First seen:2026-03-30 06:58:20 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:475vJGdU+Zu8dJ4JB+fijIRqqJHcZEqqZpZcXHKvJ:ivwdUE7
TLSH T11BC1A4861145CF33BE08ED16B9A55D0830D02AF0DC96FF4AD4F755A3FA5DE88A802E27
TrID 50.0% (.SH) Linux/UNIX shell script (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://142.248.80.144/lemperluvkurayami/kurayami.x8678b1f087230ead241657141b363d532ed48e35cab865bf5e27ef4f761ddd476c Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.mips9e7cc1831e5868453091082155ef59935f54edcb988d5533221e6a7d42c28c8a Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.arc3efe93f0c0b131fa6458770452eb2fe66d070cdd79e80140c677f974334f5c48 Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.i468n/an/aua-wget
http://142.248.80.144/lemperluvkurayami/kurayami.i68606349156d85a3a8577ac8cfd03c84ae468b5b0be477fafdeb7ce7892a55ddd29 Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.x86_64640aae768ed104fb6c8f5fc5693d3984d52c3656b418ff55b8bff5b69250294e Miraimirai
http://142.248.80.144/lemperluvkurayami/kurayami.mpsl9235accd29bcbfe4b8025dffa72efa87762e11fb303d779420ddfb53039c7d7e Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.armec75e884f1f7033aed21f3d93c893239c349efba5d799b8d34c67be61c6d1592 Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.arm543929c55f1ce5cd5b573960734f53b3295a27b0c8e994b2a62aa7be767899e8f Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.arm637586b88969bb679d2baa26a5385ef70bfcf239015d53f40f8113197e01c515a Miraimirai
http://142.248.80.144/lemperluvkurayami/kurayami.arm793da1b21340a94e2ae7e298b9129697b90972ac017ecad792cbbf64ed15952b3 Miraimirai
http://142.248.80.144/lemperluvkurayami/kurayami.ppc4ef8ad9cf632ce26be2f565262ded3a22842c586313a16d38ee4777e5f85f96d Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.spcn/an/aua-wget
http://142.248.80.144/lemperluvkurayami/kurayami.m68kd2985fa008e8fa04fa8666c2f2fb5d447a9acc1c85b610e57923ab73d411b5d2 Mirain/a
http://142.248.80.144/lemperluvkurayami/kurayami.sh41721839af55e4fe4e24b9e54dff63fb2ba371944be41f6341b916a65a277c9c3 Miraimirai
http://142.248.80.144/lemperluvkurayami/kurayami.arm6493d7a9c209ac7237b01b19faa467ffdee41d1b4392ee84c007457302be44f390 Mirain/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
NL NL
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=3d142d6e-1a00-0000-85de-53cdd80a0000 pid=2776 /usr/bin/sudo guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782 /tmp/sample.bin guuid=3d142d6e-1a00-0000-85de-53cdd80a0000 pid=2776->guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782 execve guuid=1a929871-1a00-0000-85de-53cde10a0000 pid=2785 /usr/bin/cp guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=1a929871-1a00-0000-85de-53cde10a0000 pid=2785 execve guuid=f6c76a74-1a00-0000-85de-53cde50a0000 pid=2789 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f6c76a74-1a00-0000-85de-53cde50a0000 pid=2789 execve guuid=de9c3475-1a00-0000-85de-53cde60a0000 pid=2790 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=de9c3475-1a00-0000-85de-53cde60a0000 pid=2790 execve guuid=88dfe593-1a00-0000-85de-53cd130b0000 pid=2835 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=88dfe593-1a00-0000-85de-53cd130b0000 pid=2835 execve guuid=16be6db7-1a00-0000-85de-53cd580b0000 pid=2904 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=16be6db7-1a00-0000-85de-53cd580b0000 pid=2904 execve guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905 /tmp/kurayami.x86 net guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905 execve guuid=264e17e5-1b00-0000-85de-53cd3e0d0000 pid=3390 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=264e17e5-1b00-0000-85de-53cd3e0d0000 pid=3390 execve guuid=dff66fe5-1b00-0000-85de-53cd3f0d0000 pid=3391 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=dff66fe5-1b00-0000-85de-53cd3f0d0000 pid=3391 execve guuid=eab9e7e5-1b00-0000-85de-53cd420d0000 pid=3394 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=eab9e7e5-1b00-0000-85de-53cd420d0000 pid=3394 execve guuid=270ef401-1c00-0000-85de-53cd8b0d0000 pid=3467 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=270ef401-1c00-0000-85de-53cd8b0d0000 pid=3467 execve guuid=c56ba51f-1c00-0000-85de-53cdcd0d0000 pid=3533 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c56ba51f-1c00-0000-85de-53cdcd0d0000 pid=3533 execve guuid=3254e71f-1c00-0000-85de-53cdcf0d0000 pid=3535 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=3254e71f-1c00-0000-85de-53cdcf0d0000 pid=3535 clone guuid=e66aba20-1c00-0000-85de-53cdd50d0000 pid=3541 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=e66aba20-1c00-0000-85de-53cdd50d0000 pid=3541 execve guuid=088bfe20-1c00-0000-85de-53cdd60d0000 pid=3542 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=088bfe20-1c00-0000-85de-53cdd60d0000 pid=3542 execve guuid=f79f4421-1c00-0000-85de-53cdd80d0000 pid=3544 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f79f4421-1c00-0000-85de-53cdd80d0000 pid=3544 execve guuid=2d154344-1c00-0000-85de-53cd290e0000 pid=3625 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=2d154344-1c00-0000-85de-53cd290e0000 pid=3625 execve guuid=838bb26e-1c00-0000-85de-53cda90e0000 pid=3753 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=838bb26e-1c00-0000-85de-53cda90e0000 pid=3753 execve guuid=385f096f-1c00-0000-85de-53cdaa0e0000 pid=3754 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=385f096f-1c00-0000-85de-53cdaa0e0000 pid=3754 clone guuid=a97cf06f-1c00-0000-85de-53cdb00e0000 pid=3760 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=a97cf06f-1c00-0000-85de-53cdb00e0000 pid=3760 execve guuid=25e76070-1c00-0000-85de-53cdb40e0000 pid=3764 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=25e76070-1c00-0000-85de-53cdb40e0000 pid=3764 execve guuid=6f2fb070-1c00-0000-85de-53cdb50e0000 pid=3765 /usr/bin/wget net send-data guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=6f2fb070-1c00-0000-85de-53cdb50e0000 pid=3765 execve guuid=e516267f-1c00-0000-85de-53cde50e0000 pid=3813 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=e516267f-1c00-0000-85de-53cde50e0000 pid=3813 execve guuid=6f878b92-1c00-0000-85de-53cd1e0f0000 pid=3870 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=6f878b92-1c00-0000-85de-53cd1e0f0000 pid=3870 execve guuid=edb5f492-1c00-0000-85de-53cd210f0000 pid=3873 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=edb5f492-1c00-0000-85de-53cd210f0000 pid=3873 clone guuid=d96a1793-1c00-0000-85de-53cd230f0000 pid=3875 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=d96a1793-1c00-0000-85de-53cd230f0000 pid=3875 execve guuid=624b8593-1c00-0000-85de-53cd270f0000 pid=3879 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=624b8593-1c00-0000-85de-53cd270f0000 pid=3879 execve guuid=96f3d393-1c00-0000-85de-53cd280f0000 pid=3880 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=96f3d393-1c00-0000-85de-53cd280f0000 pid=3880 execve guuid=13a4f6af-1c00-0000-85de-53cd900f0000 pid=3984 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=13a4f6af-1c00-0000-85de-53cd900f0000 pid=3984 execve guuid=376f43d0-1c00-0000-85de-53cdfb0f0000 pid=4091 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=376f43d0-1c00-0000-85de-53cdfb0f0000 pid=4091 execve guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092 /tmp/kurayami.i686 net guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092 execve guuid=710a82fe-1d00-0000-85de-53cd8b130000 pid=5003 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=710a82fe-1d00-0000-85de-53cd8b130000 pid=5003 execve guuid=8d920aff-1d00-0000-85de-53cd8e130000 pid=5006 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=8d920aff-1d00-0000-85de-53cd8e130000 pid=5006 execve guuid=4919d8ff-1d00-0000-85de-53cd92130000 pid=5010 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=4919d8ff-1d00-0000-85de-53cd92130000 pid=5010 execve guuid=f24a1b1f-1e00-0000-85de-53cde2130000 pid=5090 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f24a1b1f-1e00-0000-85de-53cde2130000 pid=5090 execve guuid=007d633f-1e00-0000-85de-53cd24140000 pid=5156 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=007d633f-1e00-0000-85de-53cd24140000 pid=5156 execve guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160 /tmp/kurayami.x86_64 mprotect-exec net guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160 execve guuid=8050f46d-1f00-0000-85de-53cda7140000 pid=5287 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=8050f46d-1f00-0000-85de-53cda7140000 pid=5287 execve guuid=cd27866e-1f00-0000-85de-53cda8140000 pid=5288 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=cd27866e-1f00-0000-85de-53cda8140000 pid=5288 execve guuid=056a896f-1f00-0000-85de-53cda9140000 pid=5289 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=056a896f-1f00-0000-85de-53cda9140000 pid=5289 execve guuid=c7fcd38c-1f00-0000-85de-53cdaa140000 pid=5290 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c7fcd38c-1f00-0000-85de-53cdaa140000 pid=5290 execve guuid=749efbcf-1f00-0000-85de-53cdb1140000 pid=5297 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=749efbcf-1f00-0000-85de-53cdb1140000 pid=5297 execve guuid=7185cbd0-1f00-0000-85de-53cdb2140000 pid=5298 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=7185cbd0-1f00-0000-85de-53cdb2140000 pid=5298 clone guuid=b11677d2-1f00-0000-85de-53cdb4140000 pid=5300 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=b11677d2-1f00-0000-85de-53cdb4140000 pid=5300 execve guuid=983d59d3-1f00-0000-85de-53cdb5140000 pid=5301 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=983d59d3-1f00-0000-85de-53cdb5140000 pid=5301 execve guuid=0ea0cbd4-1f00-0000-85de-53cdb7140000 pid=5303 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=0ea0cbd4-1f00-0000-85de-53cdb7140000 pid=5303 execve guuid=419104f2-1f00-0000-85de-53cdb8140000 pid=5304 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=419104f2-1f00-0000-85de-53cdb8140000 pid=5304 execve guuid=2b4dfa13-2000-0000-85de-53cdb9140000 pid=5305 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=2b4dfa13-2000-0000-85de-53cdb9140000 pid=5305 execve guuid=1322e614-2000-0000-85de-53cdba140000 pid=5306 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=1322e614-2000-0000-85de-53cdba140000 pid=5306 clone guuid=c9353721-2000-0000-85de-53cdbc140000 pid=5308 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c9353721-2000-0000-85de-53cdbc140000 pid=5308 execve guuid=79c8b528-2000-0000-85de-53cdbd140000 pid=5309 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=79c8b528-2000-0000-85de-53cdbd140000 pid=5309 execve guuid=3855362a-2000-0000-85de-53cdbe140000 pid=5310 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=3855362a-2000-0000-85de-53cdbe140000 pid=5310 execve guuid=21895248-2000-0000-85de-53cdbf140000 pid=5311 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=21895248-2000-0000-85de-53cdbf140000 pid=5311 execve guuid=38d25368-2000-0000-85de-53cdc0140000 pid=5312 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=38d25368-2000-0000-85de-53cdc0140000 pid=5312 execve guuid=e387ba6a-2000-0000-85de-53cdc1140000 pid=5313 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=e387ba6a-2000-0000-85de-53cdc1140000 pid=5313 clone guuid=cd4a3d6e-2000-0000-85de-53cdc3140000 pid=5315 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=cd4a3d6e-2000-0000-85de-53cdc3140000 pid=5315 execve guuid=fc42e56e-2000-0000-85de-53cdc4140000 pid=5316 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=fc42e56e-2000-0000-85de-53cdc4140000 pid=5316 execve guuid=42153170-2000-0000-85de-53cdc5140000 pid=5317 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=42153170-2000-0000-85de-53cdc5140000 pid=5317 execve guuid=71681b91-2000-0000-85de-53cdc6140000 pid=5318 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=71681b91-2000-0000-85de-53cdc6140000 pid=5318 execve guuid=da3840bd-2000-0000-85de-53cdc7140000 pid=5319 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=da3840bd-2000-0000-85de-53cdc7140000 pid=5319 execve guuid=c97de6bd-2000-0000-85de-53cdc8140000 pid=5320 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c97de6bd-2000-0000-85de-53cdc8140000 pid=5320 clone guuid=e05507c2-2000-0000-85de-53cdca140000 pid=5322 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=e05507c2-2000-0000-85de-53cdca140000 pid=5322 execve guuid=c920bac2-2000-0000-85de-53cdcb140000 pid=5323 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c920bac2-2000-0000-85de-53cdcb140000 pid=5323 execve guuid=c255a3c4-2000-0000-85de-53cdcc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c255a3c4-2000-0000-85de-53cdcc140000 pid=5324 execve guuid=08b393e2-2000-0000-85de-53cdcd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=08b393e2-2000-0000-85de-53cdcd140000 pid=5325 execve guuid=09e88308-2100-0000-85de-53cdce140000 pid=5326 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=09e88308-2100-0000-85de-53cdce140000 pid=5326 execve guuid=20d63609-2100-0000-85de-53cdcf140000 pid=5327 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=20d63609-2100-0000-85de-53cdcf140000 pid=5327 clone guuid=1483860d-2100-0000-85de-53cdd1140000 pid=5329 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=1483860d-2100-0000-85de-53cdd1140000 pid=5329 execve guuid=a80d3d0e-2100-0000-85de-53cdd2140000 pid=5330 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=a80d3d0e-2100-0000-85de-53cdd2140000 pid=5330 execve guuid=f0b86c0f-2100-0000-85de-53cdd3140000 pid=5331 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f0b86c0f-2100-0000-85de-53cdd3140000 pid=5331 execve guuid=02c88d33-2100-0000-85de-53cdd4140000 pid=5332 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=02c88d33-2100-0000-85de-53cdd4140000 pid=5332 execve guuid=289a2553-2100-0000-85de-53cdd5140000 pid=5333 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=289a2553-2100-0000-85de-53cdd5140000 pid=5333 execve guuid=80516753-2100-0000-85de-53cdd6140000 pid=5334 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=80516753-2100-0000-85de-53cdd6140000 pid=5334 clone guuid=a939f053-2100-0000-85de-53cdd8140000 pid=5336 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=a939f053-2100-0000-85de-53cdd8140000 pid=5336 execve guuid=06de3354-2100-0000-85de-53cdd9140000 pid=5337 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=06de3354-2100-0000-85de-53cdd9140000 pid=5337 execve guuid=793ecc54-2100-0000-85de-53cdda140000 pid=5338 /usr/bin/wget net send-data guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=793ecc54-2100-0000-85de-53cdda140000 pid=5338 execve guuid=31014e63-2100-0000-85de-53cddb140000 pid=5339 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=31014e63-2100-0000-85de-53cddb140000 pid=5339 execve guuid=03977a73-2100-0000-85de-53cddc140000 pid=5340 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=03977a73-2100-0000-85de-53cddc140000 pid=5340 execve guuid=963eec73-2100-0000-85de-53cddd140000 pid=5341 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=963eec73-2100-0000-85de-53cddd140000 pid=5341 clone guuid=7b183f74-2100-0000-85de-53cdde140000 pid=5342 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=7b183f74-2100-0000-85de-53cdde140000 pid=5342 execve guuid=ee96aa74-2100-0000-85de-53cddf140000 pid=5343 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=ee96aa74-2100-0000-85de-53cddf140000 pid=5343 execve guuid=75f68575-2100-0000-85de-53cde0140000 pid=5344 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=75f68575-2100-0000-85de-53cde0140000 pid=5344 execve guuid=91aa22a7-2100-0000-85de-53cde7140000 pid=5351 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=91aa22a7-2100-0000-85de-53cde7140000 pid=5351 execve guuid=f78dd8cb-2100-0000-85de-53cdef140000 pid=5359 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f78dd8cb-2100-0000-85de-53cdef140000 pid=5359 execve guuid=bef11fcc-2100-0000-85de-53cdf0140000 pid=5360 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=bef11fcc-2100-0000-85de-53cdf0140000 pid=5360 clone guuid=fd95a9cc-2100-0000-85de-53cdf2140000 pid=5362 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=fd95a9cc-2100-0000-85de-53cdf2140000 pid=5362 execve guuid=b42bf6cc-2100-0000-85de-53cdf3140000 pid=5363 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=b42bf6cc-2100-0000-85de-53cdf3140000 pid=5363 execve guuid=ff8941cd-2100-0000-85de-53cdf4140000 pid=5364 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=ff8941cd-2100-0000-85de-53cdf4140000 pid=5364 execve guuid=f45739f0-2100-0000-85de-53cdfe140000 pid=5374 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=f45739f0-2100-0000-85de-53cdfe140000 pid=5374 execve guuid=c7b7f215-2200-0000-85de-53cd09150000 pid=5385 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=c7b7f215-2200-0000-85de-53cd09150000 pid=5385 execve guuid=bc389716-2200-0000-85de-53cd0a150000 pid=5386 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=bc389716-2200-0000-85de-53cd0a150000 pid=5386 clone guuid=3ddde317-2200-0000-85de-53cd0c150000 pid=5388 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=3ddde317-2200-0000-85de-53cd0c150000 pid=5388 execve guuid=77006e18-2200-0000-85de-53cd0d150000 pid=5389 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=77006e18-2200-0000-85de-53cd0d150000 pid=5389 execve guuid=3a573619-2200-0000-85de-53cd0e150000 pid=5390 /usr/bin/wget net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=3a573619-2200-0000-85de-53cd0e150000 pid=5390 execve guuid=aa772343-2200-0000-85de-53cd0f150000 pid=5391 /usr/bin/curl net send-data write-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=aa772343-2200-0000-85de-53cd0f150000 pid=5391 execve guuid=7cb6df6f-2200-0000-85de-53cd10150000 pid=5392 /usr/bin/chmod guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=7cb6df6f-2200-0000-85de-53cd10150000 pid=5392 execve guuid=7c8e2e70-2200-0000-85de-53cd11150000 pid=5393 /usr/bin/bash guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=7c8e2e70-2200-0000-85de-53cd11150000 pid=5393 clone guuid=da183271-2200-0000-85de-53cd13150000 pid=5395 /usr/bin/rm delete-file guuid=0e541671-1a00-0000-85de-53cdde0a0000 pid=2782->guuid=da183271-2200-0000-85de-53cd13150000 pid=5395 execve 20a3e4c7-4097-5a6d-858d-457b67dd57ee 142.248.80.144:80 guuid=de9c3475-1a00-0000-85de-53cde60a0000 pid=2790->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=88dfe593-1a00-0000-85de-53cd130b0000 pid=2835->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=96de9ab8-1a00-0000-85de-53cd5a0b0000 pid=2906 /tmp/kurayami.x86 guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905->guuid=96de9ab8-1a00-0000-85de-53cd5a0b0000 pid=2906 clone guuid=3224fae4-1b00-0000-85de-53cd3c0d0000 pid=3388 /tmp/kurayami.x86 guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905->guuid=3224fae4-1b00-0000-85de-53cd3c0d0000 pid=3388 clone guuid=8f8afee4-1b00-0000-85de-53cd3d0d0000 pid=3389 /tmp/kurayami.x86 net send-data zombie guuid=ec9cc0b7-1a00-0000-85de-53cd590b0000 pid=2905->guuid=8f8afee4-1b00-0000-85de-53cd3d0d0000 pid=3389 clone guuid=c056a6b8-1a00-0000-85de-53cd5b0b0000 pid=2907 /tmp/kurayami.x86 guuid=96de9ab8-1a00-0000-85de-53cd5a0b0000 pid=2906->guuid=c056a6b8-1a00-0000-85de-53cd5b0b0000 pid=2907 clone guuid=f8ccaeb8-1a00-0000-85de-53cd5c0b0000 pid=2908 /tmp/kurayami.x86 net send-data zombie guuid=96de9ab8-1a00-0000-85de-53cd5a0b0000 pid=2906->guuid=f8ccaeb8-1a00-0000-85de-53cd5c0b0000 pid=2908 clone guuid=f8ccaeb8-1a00-0000-85de-53cd5c0b0000 pid=2908->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5b1fbf77-b20c-52ab-bd01-8608ea336134 142.248.80.144:69 guuid=f8ccaeb8-1a00-0000-85de-53cd5c0b0000 pid=2908->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 40B guuid=94caa6cd-1d00-0000-85de-53cd07130000 pid=4871 /tmp/kurayami.x86 net send-data guuid=f8ccaeb8-1a00-0000-85de-53cd5c0b0000 pid=2908->guuid=94caa6cd-1d00-0000-85de-53cd07130000 pid=4871 clone guuid=8f8afee4-1b00-0000-85de-53cd3d0d0000 pid=3389->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8f8afee4-1b00-0000-85de-53cd3d0d0000 pid=3389->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 18B guuid=eab9e7e5-1b00-0000-85de-53cd420d0000 pid=3394->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=270ef401-1c00-0000-85de-53cd8b0d0000 pid=3467->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=f79f4421-1c00-0000-85de-53cdd80d0000 pid=3544->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=2d154344-1c00-0000-85de-53cd290e0000 pid=3625->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B guuid=6f2fb070-1c00-0000-85de-53cdb50e0000 pid=3765->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=e516267f-1c00-0000-85de-53cde50e0000 pid=3813->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=96f3d393-1c00-0000-85de-53cd280f0000 pid=3880->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=13a4f6af-1c00-0000-85de-53cd900f0000 pid=3984->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9704bcd1-1c00-0000-85de-53cd03100000 pid=4099 /tmp/kurayami.i686 guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092->guuid=9704bcd1-1c00-0000-85de-53cd03100000 pid=4099 clone guuid=49aa69fe-1d00-0000-85de-53cd89130000 pid=5001 /tmp/kurayami.i686 guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092->guuid=49aa69fe-1d00-0000-85de-53cd89130000 pid=5001 clone guuid=830173fe-1d00-0000-85de-53cd8a130000 pid=5002 /tmp/kurayami.i686 net send-data zombie guuid=a13994d0-1c00-0000-85de-53cdfc0f0000 pid=4092->guuid=830173fe-1d00-0000-85de-53cd8a130000 pid=5002 clone guuid=bf3bc9d1-1c00-0000-85de-53cd04100000 pid=4100 /tmp/kurayami.i686 guuid=9704bcd1-1c00-0000-85de-53cd03100000 pid=4099->guuid=bf3bc9d1-1c00-0000-85de-53cd04100000 pid=4100 clone guuid=388bced1-1c00-0000-85de-53cd05100000 pid=4101 /tmp/kurayami.i686 net send-data zombie guuid=9704bcd1-1c00-0000-85de-53cd03100000 pid=4099->guuid=388bced1-1c00-0000-85de-53cd05100000 pid=4101 clone guuid=388bced1-1c00-0000-85de-53cd05100000 pid=4101->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=388bced1-1c00-0000-85de-53cd05100000 pid=4101->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 19B 681a27be-d72b-59ac-a996-07312f73d8f7 38.49.215.226:53 guuid=94caa6cd-1d00-0000-85de-53cd07130000 pid=4871->681a27be-d72b-59ac-a996-07312f73d8f7 send: 20485B guuid=f2b8adcd-1d00-0000-85de-53cd08130000 pid=4872 /tmp/kurayami.x86 guuid=94caa6cd-1d00-0000-85de-53cd07130000 pid=4871->guuid=f2b8adcd-1d00-0000-85de-53cd08130000 pid=4872 clone guuid=830173fe-1d00-0000-85de-53cd8a130000 pid=5002->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=830173fe-1d00-0000-85de-53cd8a130000 pid=5002->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 19B guuid=4919d8ff-1d00-0000-85de-53cd92130000 pid=5010->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 162B guuid=f24a1b1f-1e00-0000-85de-53cde2130000 pid=5090->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 111B guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be260f42-1e00-0000-85de-53cd30140000 pid=5168 /tmp/kurayami.x86_64 guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160->guuid=be260f42-1e00-0000-85de-53cd30140000 pid=5168 clone guuid=a807d26d-1f00-0000-85de-53cda5140000 pid=5285 /tmp/kurayami.x86_64 guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160->guuid=a807d26d-1f00-0000-85de-53cda5140000 pid=5285 clone guuid=f2a5d86d-1f00-0000-85de-53cda6140000 pid=5286 /tmp/kurayami.x86_64 net send-data zombie guuid=4f1d3640-1e00-0000-85de-53cd28140000 pid=5160->guuid=f2a5d86d-1f00-0000-85de-53cda6140000 pid=5286 clone guuid=53e60343-1e00-0000-85de-53cd35140000 pid=5173 /tmp/kurayami.x86_64 guuid=be260f42-1e00-0000-85de-53cd30140000 pid=5168->guuid=53e60343-1e00-0000-85de-53cd35140000 pid=5173 clone guuid=947c0c43-1e00-0000-85de-53cd36140000 pid=5174 /tmp/kurayami.x86_64 net send-data zombie guuid=be260f42-1e00-0000-85de-53cd30140000 pid=5168->guuid=947c0c43-1e00-0000-85de-53cd36140000 pid=5174 clone guuid=947c0c43-1e00-0000-85de-53cd36140000 pid=5174->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=947c0c43-1e00-0000-85de-53cd36140000 pid=5174->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 21B guuid=f2a5d86d-1f00-0000-85de-53cda6140000 pid=5286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f2a5d86d-1f00-0000-85de-53cda6140000 pid=5286->5b1fbf77-b20c-52ab-bd01-8608ea336134 send: 42B guuid=056a896f-1f00-0000-85de-53cda9140000 pid=5289->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=c7fcd38c-1f00-0000-85de-53cdaa140000 pid=5290->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=0ea0cbd4-1f00-0000-85de-53cdb7140000 pid=5303->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=419104f2-1f00-0000-85de-53cdb8140000 pid=5304->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B guuid=3855362a-2000-0000-85de-53cdbe140000 pid=5310->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=21895248-2000-0000-85de-53cdbf140000 pid=5311->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=42153170-2000-0000-85de-53cdc5140000 pid=5317->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=71681b91-2000-0000-85de-53cdc6140000 pid=5318->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=c255a3c4-2000-0000-85de-53cdcc140000 pid=5324->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=08b393e2-2000-0000-85de-53cdcd140000 pid=5325->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=f0b86c0f-2100-0000-85de-53cdd3140000 pid=5331->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=02c88d33-2100-0000-85de-53cdd4140000 pid=5332->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B guuid=793ecc54-2100-0000-85de-53cdda140000 pid=5338->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=31014e63-2100-0000-85de-53cddb140000 pid=5339->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B guuid=75f68575-2100-0000-85de-53cde0140000 pid=5344->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 160B guuid=91aa22a7-2100-0000-85de-53cde7140000 pid=5351->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 109B guuid=ff8941cd-2100-0000-85de-53cdf4140000 pid=5364->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 159B guuid=f45739f0-2100-0000-85de-53cdfe140000 pid=5374->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 108B guuid=3a573619-2200-0000-85de-53cd0e150000 pid=5390->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 161B guuid=aa772343-2200-0000-85de-53cd0f150000 pid=5391->20a3e4c7-4097-5a6d-858d-457b67dd57ee send: 110B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-03-30 03:09:52 UTC
File Type:
Text (Shell)
AV detection:
10 of 36 (27.78%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d025eb12dc4be6b1183406858e9e6cc4564788928e678db1b6bb218c70bf8c28

(this sample)

  
Delivery method
Distributed via web download

Comments