MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d36f0bc22c7bd42ac4bfd449d1163dbe7b21e709e2d4f49febcb151c963a6ca2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: d36f0bc22c7bd42ac4bfd449d1163dbe7b21e709e2d4f49febcb151c963a6ca2
SHA3-384 hash: 843b88b03f7d86c2a5534ed239586e3528cc5aebf95472043b86f254cc8832e8ac313636d2a1e11e4f1567addd322e4c
SHA1 hash: 43978306f0f235eab2ffd1bb7611fd1831c26c0e
MD5 hash: 72aca74c21050854c924765413177dec
humanhash: tennis-ohio-utah-football
File name:1.sh
Download: download sample
Signature Mirai
File size:2'959 bytes
First seen:2025-12-26 19:53:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iKxhmlKHnElKSCXlKWePlKa7azvZlKadaFvjlK9NV9z4gelKLjclKCSvlKj7jzqg:iWmlKElwXlAPlj2zvZljsFvjlUxz4ZlJ
TLSH T150511B879251567138E7BA27FDF98F1CB1C1A29128923F16EBDC28E5528ED883046F46
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://178.16.137.37/hiddenbin/Space.arcn/an/an/a
http://178.16.137.37/hiddenbin/Space.x862a00a074a3e1143ec9a46b575cb4715b925a7d0031fa0a1f24739eb4ec36f67c Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.x86_64n/an/an/a
http://178.16.137.37/hiddenbin/Space.i686n/an/an/a
http://178.16.137.37/hiddenbin/Space.mipsab3a7a4f9fce0a9545fa14a706acd016ff59d1b8664965bd704e17c5a73c9ff3 Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.mips64n/an/an/a
http://178.16.137.37/hiddenbin/Space.mpsl35db76d2c564d985c876c51594fb5553dd96d5835a4ce984fd0d811b28206f5b Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.arm3b5d7f5f190805cc54f302a0cdcbd25b348f7cbb151252999fc244eb09f26d15 Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.arm5f9c786be9378b45248330d42a89ba3d7193f994b229793bc35ab9974e042e700 Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.arm60a65b71c102bd9fe2e76c6ccd7a14f19a809857518be7579f99d62bf5b25e412 Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.arm7b61252cfaa435d6261cb339cd57c2d1912bb0e9cbe1e2e2b3532f4458f3b2c5a Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.ppc8556b314fd3c94aa8c1d44412a855ac13634786081b1d04b3d4804ca6c95a8ae Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.sparcn/an/an/a
http://178.16.137.37/hiddenbin/Space.m68k0ae402dd53979452462cc3328f4420e2a300dfef8ccb4729c72b5fc9c36a3fc6 Miraimirai opendir
http://178.16.137.37/hiddenbin/Space.sh4cf1bafc5d49488a28551a0f89bfeed48765e0955e7a8448e50003c25ac4de0a7 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=04ec925c-1a00-0000-e9e3-e37cbe0a0000 pid=2750 /usr/bin/sudo guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755 /tmp/sample.bin guuid=04ec925c-1a00-0000-e9e3-e37cbe0a0000 pid=2750->guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755 execve guuid=bcbb1060-1a00-0000-e9e3-e37cc60a0000 pid=2758 /usr/bin/cp guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=bcbb1060-1a00-0000-e9e3-e37cc60a0000 pid=2758 execve guuid=3b8aa066-1a00-0000-e9e3-e37ccf0a0000 pid=2767 /usr/bin/wget net send-data guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=3b8aa066-1a00-0000-e9e3-e37ccf0a0000 pid=2767 execve guuid=50f9a77b-1a00-0000-e9e3-e37cf10a0000 pid=2801 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=50f9a77b-1a00-0000-e9e3-e37cf10a0000 pid=2801 execve guuid=e4d40792-1a00-0000-e9e3-e37c170b0000 pid=2839 /usr/bin/cat guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=e4d40792-1a00-0000-e9e3-e37c170b0000 pid=2839 execve guuid=7fe27b92-1a00-0000-e9e3-e37c190b0000 pid=2841 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=7fe27b92-1a00-0000-e9e3-e37c190b0000 pid=2841 execve guuid=7693ea92-1a00-0000-e9e3-e37c1b0b0000 pid=2843 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=7693ea92-1a00-0000-e9e3-e37c1b0b0000 pid=2843 clone guuid=f94e1f93-1a00-0000-e9e3-e37c1d0b0000 pid=2845 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=f94e1f93-1a00-0000-e9e3-e37c1d0b0000 pid=2845 execve guuid=a19890aa-1a00-0000-e9e3-e37c5b0b0000 pid=2907 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a19890aa-1a00-0000-e9e3-e37c5b0b0000 pid=2907 execve guuid=cd3112c4-1a00-0000-e9e3-e37c720b0000 pid=2930 /usr/bin/cat guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=cd3112c4-1a00-0000-e9e3-e37c720b0000 pid=2930 execve guuid=d8606ec4-1a00-0000-e9e3-e37c740b0000 pid=2932 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=d8606ec4-1a00-0000-e9e3-e37c740b0000 pid=2932 execve guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933 execve guuid=c934aef1-1b00-0000-e9e3-e37c670d0000 pid=3431 /usr/bin/wget net send-data guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=c934aef1-1b00-0000-e9e3-e37c670d0000 pid=3431 execve guuid=6ee38c02-1c00-0000-e9e3-e37c960d0000 pid=3478 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=6ee38c02-1c00-0000-e9e3-e37c960d0000 pid=3478 execve guuid=752c6f14-1c00-0000-e9e3-e37cbf0d0000 pid=3519 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=752c6f14-1c00-0000-e9e3-e37cbf0d0000 pid=3519 clone guuid=eebc8c14-1c00-0000-e9e3-e37cc00d0000 pid=3520 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=eebc8c14-1c00-0000-e9e3-e37cc00d0000 pid=3520 execve guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522 execve guuid=3d121841-1d00-0000-e9e3-e37cd4100000 pid=4308 /usr/bin/wget net send-data guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=3d121841-1d00-0000-e9e3-e37cd4100000 pid=4308 execve guuid=81862851-1d00-0000-e9e3-e37c00110000 pid=4352 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=81862851-1d00-0000-e9e3-e37c00110000 pid=4352 execve guuid=42887670-1d00-0000-e9e3-e37c02110000 pid=4354 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=42887670-1d00-0000-e9e3-e37c02110000 pid=4354 clone guuid=68c39370-1d00-0000-e9e3-e37c04110000 pid=4356 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=68c39370-1d00-0000-e9e3-e37c04110000 pid=4356 execve guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358 execve guuid=4e428b9e-1e00-0000-e9e3-e37c3d140000 pid=5181 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=4e428b9e-1e00-0000-e9e3-e37c3d140000 pid=5181 execve guuid=f982ceb7-1e00-0000-e9e3-e37c8a140000 pid=5258 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=f982ceb7-1e00-0000-e9e3-e37c8a140000 pid=5258 execve guuid=34318cd5-1e00-0000-e9e3-e37c8e140000 pid=5262 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=34318cd5-1e00-0000-e9e3-e37c8e140000 pid=5262 clone guuid=9897add5-1e00-0000-e9e3-e37c8f140000 pid=5263 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=9897add5-1e00-0000-e9e3-e37c8f140000 pid=5263 execve guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264 execve guuid=76cafb02-2000-0000-e9e3-e37ca5140000 pid=5285 /usr/bin/wget net send-data guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=76cafb02-2000-0000-e9e3-e37ca5140000 pid=5285 execve guuid=a35a1a15-2000-0000-e9e3-e37ca6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a35a1a15-2000-0000-e9e3-e37ca6140000 pid=5286 execve guuid=3673e62a-2000-0000-e9e3-e37ca7140000 pid=5287 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=3673e62a-2000-0000-e9e3-e37ca7140000 pid=5287 clone guuid=549c422b-2000-0000-e9e3-e37ca8140000 pid=5288 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=549c422b-2000-0000-e9e3-e37ca8140000 pid=5288 execve guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289 execve guuid=0b3f3d5b-2100-0000-e9e3-e37ccf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=0b3f3d5b-2100-0000-e9e3-e37ccf140000 pid=5327 execve guuid=a6fa4473-2100-0000-e9e3-e37cd0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a6fa4473-2100-0000-e9e3-e37cd0140000 pid=5328 execve guuid=d2e7e08b-2100-0000-e9e3-e37cd1140000 pid=5329 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=d2e7e08b-2100-0000-e9e3-e37cd1140000 pid=5329 clone guuid=95431c8c-2100-0000-e9e3-e37cd2140000 pid=5330 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=95431c8c-2100-0000-e9e3-e37cd2140000 pid=5330 execve guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331 execve guuid=36a23bba-2200-0000-e9e3-e37cd9140000 pid=5337 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=36a23bba-2200-0000-e9e3-e37cd9140000 pid=5337 execve guuid=bdb47ed2-2200-0000-e9e3-e37cda140000 pid=5338 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=bdb47ed2-2200-0000-e9e3-e37cda140000 pid=5338 execve guuid=d68af7ea-2200-0000-e9e3-e37cdb140000 pid=5339 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=d68af7ea-2200-0000-e9e3-e37cdb140000 pid=5339 clone guuid=9d2f12eb-2200-0000-e9e3-e37cdc140000 pid=5340 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=9d2f12eb-2200-0000-e9e3-e37cdc140000 pid=5340 execve guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341 execve guuid=e6348f17-2400-0000-e9e3-e37ce3140000 pid=5347 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=e6348f17-2400-0000-e9e3-e37ce3140000 pid=5347 execve guuid=2670b22e-2400-0000-e9e3-e37ce4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=2670b22e-2400-0000-e9e3-e37ce4140000 pid=5348 execve guuid=9bf34f47-2400-0000-e9e3-e37ce5140000 pid=5349 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=9bf34f47-2400-0000-e9e3-e37ce5140000 pid=5349 clone guuid=f38d8a47-2400-0000-e9e3-e37ce6140000 pid=5350 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=f38d8a47-2400-0000-e9e3-e37ce6140000 pid=5350 execve guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351 execve guuid=f8a45d76-2500-0000-e9e3-e37ced140000 pid=5357 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=f8a45d76-2500-0000-e9e3-e37ced140000 pid=5357 execve guuid=31fc6493-2500-0000-e9e3-e37cee140000 pid=5358 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=31fc6493-2500-0000-e9e3-e37cee140000 pid=5358 execve guuid=8934daab-2500-0000-e9e3-e37cef140000 pid=5359 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=8934daab-2500-0000-e9e3-e37cef140000 pid=5359 clone guuid=2cc823ac-2500-0000-e9e3-e37cf0140000 pid=5360 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=2cc823ac-2500-0000-e9e3-e37cf0140000 pid=5360 execve guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361 execve guuid=885e89da-2600-0000-e9e3-e37cf7140000 pid=5367 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=885e89da-2600-0000-e9e3-e37cf7140000 pid=5367 execve guuid=dd5bfff9-2600-0000-e9e3-e37cf8140000 pid=5368 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=dd5bfff9-2600-0000-e9e3-e37cf8140000 pid=5368 execve guuid=65b49918-2700-0000-e9e3-e37cf9140000 pid=5369 /usr/bin/bash guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=65b49918-2700-0000-e9e3-e37cf9140000 pid=5369 clone guuid=cebab818-2700-0000-e9e3-e37cfa140000 pid=5370 /usr/bin/chmod guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=cebab818-2700-0000-e9e3-e37cfa140000 pid=5370 execve guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371 /tmp/Space net guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371 execve guuid=a292e445-2800-0000-e9e3-e37c03150000 pid=5379 /usr/bin/wget net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=a292e445-2800-0000-e9e3-e37c03150000 pid=5379 execve guuid=d8fc2d5d-2800-0000-e9e3-e37c0c150000 pid=5388 /usr/bin/curl net send-data write-file guuid=4f22595f-1a00-0000-e9e3-e37cc30a0000 pid=2755->guuid=d8fc2d5d-2800-0000-e9e3-e37c0c150000 pid=5388 execve ea727370-676a-5361-abb1-6788552f4e79 178.16.137.37:80 guuid=3b8aa066-1a00-0000-e9e3-e37ccf0a0000 pid=2767->ea727370-676a-5361-abb1-6788552f4e79 send: 147B guuid=50f9a77b-1a00-0000-e9e3-e37cf10a0000 pid=2801->ea727370-676a-5361-abb1-6788552f4e79 send: 96B guuid=f94e1f93-1a00-0000-e9e3-e37c1d0b0000 pid=2845->ea727370-676a-5361-abb1-6788552f4e79 send: 147B guuid=a19890aa-1a00-0000-e9e3-e37c5b0b0000 pid=2907->ea727370-676a-5361-abb1-6788552f4e79 send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f38a27c5-1a00-0000-e9e3-e37c770b0000 pid=2935 /tmp/Space guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933->guuid=f38a27c5-1a00-0000-e9e3-e37c770b0000 pid=2935 clone guuid=046c97f1-1b00-0000-e9e3-e37c650d0000 pid=3429 /tmp/Space guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933->guuid=046c97f1-1b00-0000-e9e3-e37c650d0000 pid=3429 clone guuid=32c09ef1-1b00-0000-e9e3-e37c660d0000 pid=3430 /tmp/Space net zombie guuid=8e18b0c4-1a00-0000-e9e3-e37c750b0000 pid=2933->guuid=32c09ef1-1b00-0000-e9e3-e37c660d0000 pid=3430 clone guuid=b0862dc5-1a00-0000-e9e3-e37c780b0000 pid=2936 /tmp/Space guuid=f38a27c5-1a00-0000-e9e3-e37c770b0000 pid=2935->guuid=b0862dc5-1a00-0000-e9e3-e37c780b0000 pid=2936 clone guuid=980034c5-1a00-0000-e9e3-e37c790b0000 pid=2937 /tmp/Space net zombie guuid=f38a27c5-1a00-0000-e9e3-e37c770b0000 pid=2935->guuid=980034c5-1a00-0000-e9e3-e37c790b0000 pid=2937 clone ee115d00-b1a4-565e-90e2-a5283776ece2 178.16.137.37:3778 guuid=980034c5-1a00-0000-e9e3-e37c790b0000 pid=2937->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=32c09ef1-1b00-0000-e9e3-e37c660d0000 pid=3430->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=c934aef1-1b00-0000-e9e3-e37c670d0000 pid=3431->ea727370-676a-5361-abb1-6788552f4e79 send: 150B guuid=6ee38c02-1c00-0000-e9e3-e37c960d0000 pid=3478->ea727370-676a-5361-abb1-6788552f4e79 send: 99B guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=57085315-1c00-0000-e9e3-e37cc50d0000 pid=3525 /tmp/Space guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522->guuid=57085315-1c00-0000-e9e3-e37cc50d0000 pid=3525 clone guuid=32450a41-1d00-0000-e9e3-e37cd2100000 pid=4306 /tmp/Space guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522->guuid=32450a41-1d00-0000-e9e3-e37cd2100000 pid=4306 clone guuid=f8140e41-1d00-0000-e9e3-e37cd3100000 pid=4307 /tmp/Space net zombie guuid=fc9bd514-1c00-0000-e9e3-e37cc20d0000 pid=3522->guuid=f8140e41-1d00-0000-e9e3-e37cd3100000 pid=4307 clone guuid=acf05715-1c00-0000-e9e3-e37cc60d0000 pid=3526 /tmp/Space guuid=57085315-1c00-0000-e9e3-e37cc50d0000 pid=3525->guuid=acf05715-1c00-0000-e9e3-e37cc60d0000 pid=3526 clone guuid=5a875c15-1c00-0000-e9e3-e37cc70d0000 pid=3527 /tmp/Space net zombie guuid=57085315-1c00-0000-e9e3-e37cc50d0000 pid=3525->guuid=5a875c15-1c00-0000-e9e3-e37cc70d0000 pid=3527 clone guuid=5a875c15-1c00-0000-e9e3-e37cc70d0000 pid=3527->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=f8140e41-1d00-0000-e9e3-e37cd3100000 pid=4307->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=3d121841-1d00-0000-e9e3-e37cd4100000 pid=4308->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=81862851-1d00-0000-e9e3-e37c00110000 pid=4352->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8295c171-1d00-0000-e9e3-e37c0a110000 pid=4362 /tmp/Space guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358->guuid=8295c171-1d00-0000-e9e3-e37c0a110000 pid=4362 clone guuid=f4aa7a9e-1e00-0000-e9e3-e37c3b140000 pid=5179 /tmp/Space guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358->guuid=f4aa7a9e-1e00-0000-e9e3-e37c3b140000 pid=5179 clone guuid=8044819e-1e00-0000-e9e3-e37c3c140000 pid=5180 /tmp/Space net zombie guuid=a983d270-1d00-0000-e9e3-e37c06110000 pid=4358->guuid=8044819e-1e00-0000-e9e3-e37c3c140000 pid=5180 clone guuid=34c2cb71-1d00-0000-e9e3-e37c0b110000 pid=4363 /tmp/Space guuid=8295c171-1d00-0000-e9e3-e37c0a110000 pid=4362->guuid=34c2cb71-1d00-0000-e9e3-e37c0b110000 pid=4363 clone guuid=af43d271-1d00-0000-e9e3-e37c0c110000 pid=4364 /tmp/Space net zombie guuid=8295c171-1d00-0000-e9e3-e37c0a110000 pid=4362->guuid=af43d271-1d00-0000-e9e3-e37c0c110000 pid=4364 clone guuid=af43d271-1d00-0000-e9e3-e37c0c110000 pid=4364->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=8044819e-1e00-0000-e9e3-e37c3c140000 pid=5180->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=4e428b9e-1e00-0000-e9e3-e37c3d140000 pid=5181->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=f982ceb7-1e00-0000-e9e3-e37c8a140000 pid=5258->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e87390d6-1e00-0000-e9e3-e37c91140000 pid=5265 /tmp/Space guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264->guuid=e87390d6-1e00-0000-e9e3-e37c91140000 pid=5265 clone guuid=f947c202-2000-0000-e9e3-e37ca3140000 pid=5283 /tmp/Space guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264->guuid=f947c202-2000-0000-e9e3-e37ca3140000 pid=5283 clone guuid=5c2cce02-2000-0000-e9e3-e37ca4140000 pid=5284 /tmp/Space net zombie guuid=f83810d6-1e00-0000-e9e3-e37c90140000 pid=5264->guuid=5c2cce02-2000-0000-e9e3-e37ca4140000 pid=5284 clone guuid=ba4497d6-1e00-0000-e9e3-e37c92140000 pid=5266 /tmp/Space guuid=e87390d6-1e00-0000-e9e3-e37c91140000 pid=5265->guuid=ba4497d6-1e00-0000-e9e3-e37c92140000 pid=5266 clone guuid=7e5f9ed6-1e00-0000-e9e3-e37c93140000 pid=5267 /tmp/Space net zombie guuid=e87390d6-1e00-0000-e9e3-e37c91140000 pid=5265->guuid=7e5f9ed6-1e00-0000-e9e3-e37c93140000 pid=5267 clone guuid=7e5f9ed6-1e00-0000-e9e3-e37c93140000 pid=5267->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=5c2cce02-2000-0000-e9e3-e37ca4140000 pid=5284->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=76cafb02-2000-0000-e9e3-e37ca5140000 pid=5285->ea727370-676a-5361-abb1-6788552f4e79 send: 150B guuid=a35a1a15-2000-0000-e9e3-e37ca6140000 pid=5286->ea727370-676a-5361-abb1-6788552f4e79 send: 99B guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f3e8d2d-2000-0000-e9e3-e37caa140000 pid=5290 /tmp/Space guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289->guuid=2f3e8d2d-2000-0000-e9e3-e37caa140000 pid=5290 clone guuid=49240f5b-2100-0000-e9e3-e37ccd140000 pid=5325 /tmp/Space guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289->guuid=49240f5b-2100-0000-e9e3-e37ccd140000 pid=5325 clone guuid=48231b5b-2100-0000-e9e3-e37cce140000 pid=5326 /tmp/Space net zombie guuid=af03362c-2000-0000-e9e3-e37ca9140000 pid=5289->guuid=48231b5b-2100-0000-e9e3-e37cce140000 pid=5326 clone guuid=3260972d-2000-0000-e9e3-e37cab140000 pid=5291 /tmp/Space guuid=2f3e8d2d-2000-0000-e9e3-e37caa140000 pid=5290->guuid=3260972d-2000-0000-e9e3-e37cab140000 pid=5291 clone guuid=8a37a32d-2000-0000-e9e3-e37cac140000 pid=5292 /tmp/Space net zombie guuid=2f3e8d2d-2000-0000-e9e3-e37caa140000 pid=5290->guuid=8a37a32d-2000-0000-e9e3-e37cac140000 pid=5292 clone guuid=8a37a32d-2000-0000-e9e3-e37cac140000 pid=5292->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=48231b5b-2100-0000-e9e3-e37cce140000 pid=5326->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=0b3f3d5b-2100-0000-e9e3-e37ccf140000 pid=5327->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=a6fa4473-2100-0000-e9e3-e37cd0140000 pid=5328->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=88fcac8d-2100-0000-e9e3-e37cd4140000 pid=5332 /tmp/Space guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331->guuid=88fcac8d-2100-0000-e9e3-e37cd4140000 pid=5332 clone guuid=90a213ba-2200-0000-e9e3-e37cd7140000 pid=5335 /tmp/Space guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331->guuid=90a213ba-2200-0000-e9e3-e37cd7140000 pid=5335 clone guuid=91451eba-2200-0000-e9e3-e37cd8140000 pid=5336 /tmp/Space net zombie guuid=1e6daa8c-2100-0000-e9e3-e37cd3140000 pid=5331->guuid=91451eba-2200-0000-e9e3-e37cd8140000 pid=5336 clone guuid=65c6b78d-2100-0000-e9e3-e37cd5140000 pid=5333 /tmp/Space guuid=88fcac8d-2100-0000-e9e3-e37cd4140000 pid=5332->guuid=65c6b78d-2100-0000-e9e3-e37cd5140000 pid=5333 clone guuid=bc49c48d-2100-0000-e9e3-e37cd6140000 pid=5334 /tmp/Space net zombie guuid=88fcac8d-2100-0000-e9e3-e37cd4140000 pid=5332->guuid=bc49c48d-2100-0000-e9e3-e37cd6140000 pid=5334 clone guuid=bc49c48d-2100-0000-e9e3-e37cd6140000 pid=5334->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=91451eba-2200-0000-e9e3-e37cd8140000 pid=5336->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=36a23bba-2200-0000-e9e3-e37cd9140000 pid=5337->ea727370-676a-5361-abb1-6788552f4e79 send: 147B guuid=bdb47ed2-2200-0000-e9e3-e37cda140000 pid=5338->ea727370-676a-5361-abb1-6788552f4e79 send: 96B guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=34c9cbeb-2200-0000-e9e3-e37cde140000 pid=5342 /tmp/Space guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341->guuid=34c9cbeb-2200-0000-e9e3-e37cde140000 pid=5342 clone guuid=dc1f7a17-2400-0000-e9e3-e37ce1140000 pid=5345 /tmp/Space guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341->guuid=dc1f7a17-2400-0000-e9e3-e37ce1140000 pid=5345 clone guuid=7d368017-2400-0000-e9e3-e37ce2140000 pid=5346 /tmp/Space net zombie guuid=e36d5aeb-2200-0000-e9e3-e37cdd140000 pid=5341->guuid=7d368017-2400-0000-e9e3-e37ce2140000 pid=5346 clone guuid=1b8ad3eb-2200-0000-e9e3-e37cdf140000 pid=5343 /tmp/Space guuid=34c9cbeb-2200-0000-e9e3-e37cde140000 pid=5342->guuid=1b8ad3eb-2200-0000-e9e3-e37cdf140000 pid=5343 clone guuid=396edbeb-2200-0000-e9e3-e37ce0140000 pid=5344 /tmp/Space net zombie guuid=34c9cbeb-2200-0000-e9e3-e37cde140000 pid=5342->guuid=396edbeb-2200-0000-e9e3-e37ce0140000 pid=5344 clone guuid=396edbeb-2200-0000-e9e3-e37ce0140000 pid=5344->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=7d368017-2400-0000-e9e3-e37ce2140000 pid=5346->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=e6348f17-2400-0000-e9e3-e37ce3140000 pid=5347->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=2670b22e-2400-0000-e9e3-e37ce4140000 pid=5348->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c2041a49-2400-0000-e9e3-e37ce8140000 pid=5352 /tmp/Space guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351->guuid=c2041a49-2400-0000-e9e3-e37ce8140000 pid=5352 clone guuid=0aff3c76-2500-0000-e9e3-e37ceb140000 pid=5355 /tmp/Space guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351->guuid=0aff3c76-2500-0000-e9e3-e37ceb140000 pid=5355 clone guuid=57744576-2500-0000-e9e3-e37cec140000 pid=5356 /tmp/Space net zombie guuid=a5d52848-2400-0000-e9e3-e37ce7140000 pid=5351->guuid=57744576-2500-0000-e9e3-e37cec140000 pid=5356 clone guuid=5f092949-2400-0000-e9e3-e37ce9140000 pid=5353 /tmp/Space guuid=c2041a49-2400-0000-e9e3-e37ce8140000 pid=5352->guuid=5f092949-2400-0000-e9e3-e37ce9140000 pid=5353 clone guuid=e0f23149-2400-0000-e9e3-e37cea140000 pid=5354 /tmp/Space net zombie guuid=c2041a49-2400-0000-e9e3-e37ce8140000 pid=5352->guuid=e0f23149-2400-0000-e9e3-e37cea140000 pid=5354 clone guuid=e0f23149-2400-0000-e9e3-e37cea140000 pid=5354->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=57744576-2500-0000-e9e3-e37cec140000 pid=5356->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=f8a45d76-2500-0000-e9e3-e37ced140000 pid=5357->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=31fc6493-2500-0000-e9e3-e37cee140000 pid=5358->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aa44bead-2500-0000-e9e3-e37cf2140000 pid=5362 /tmp/Space guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361->guuid=aa44bead-2500-0000-e9e3-e37cf2140000 pid=5362 clone guuid=e64172da-2600-0000-e9e3-e37cf5140000 pid=5365 /tmp/Space guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361->guuid=e64172da-2600-0000-e9e3-e37cf5140000 pid=5365 clone guuid=b36777da-2600-0000-e9e3-e37cf6140000 pid=5366 /tmp/Space net zombie guuid=9530c6ac-2500-0000-e9e3-e37cf1140000 pid=5361->guuid=b36777da-2600-0000-e9e3-e37cf6140000 pid=5366 clone guuid=5538cdad-2500-0000-e9e3-e37cf3140000 pid=5363 /tmp/Space guuid=aa44bead-2500-0000-e9e3-e37cf2140000 pid=5362->guuid=5538cdad-2500-0000-e9e3-e37cf3140000 pid=5363 clone guuid=e576d8ad-2500-0000-e9e3-e37cf4140000 pid=5364 /tmp/Space net zombie guuid=aa44bead-2500-0000-e9e3-e37cf2140000 pid=5362->guuid=e576d8ad-2500-0000-e9e3-e37cf4140000 pid=5364 clone guuid=e576d8ad-2500-0000-e9e3-e37cf4140000 pid=5364->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=b36777da-2600-0000-e9e3-e37cf6140000 pid=5366->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=885e89da-2600-0000-e9e3-e37cf7140000 pid=5367->ea727370-676a-5361-abb1-6788552f4e79 send: 148B guuid=dd5bfff9-2600-0000-e9e3-e37cf8140000 pid=5368->ea727370-676a-5361-abb1-6788552f4e79 send: 97B guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d8527719-2700-0000-e9e3-e37cfc140000 pid=5372 /tmp/Space guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371->guuid=d8527719-2700-0000-e9e3-e37cfc140000 pid=5372 clone guuid=2143ca45-2800-0000-e9e3-e37c01150000 pid=5377 /tmp/Space guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371->guuid=2143ca45-2800-0000-e9e3-e37c01150000 pid=5377 clone guuid=5c84d145-2800-0000-e9e3-e37c02150000 pid=5378 /tmp/Space net zombie guuid=a58dfe18-2700-0000-e9e3-e37cfb140000 pid=5371->guuid=5c84d145-2800-0000-e9e3-e37c02150000 pid=5378 clone guuid=046a7e19-2700-0000-e9e3-e37cfd140000 pid=5373 /tmp/Space guuid=d8527719-2700-0000-e9e3-e37cfc140000 pid=5372->guuid=046a7e19-2700-0000-e9e3-e37cfd140000 pid=5373 clone guuid=48ab8a19-2700-0000-e9e3-e37cfe140000 pid=5374 /tmp/Space net zombie guuid=d8527719-2700-0000-e9e3-e37cfc140000 pid=5372->guuid=48ab8a19-2700-0000-e9e3-e37cfe140000 pid=5374 clone guuid=48ab8a19-2700-0000-e9e3-e37cfe140000 pid=5374->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=5c84d145-2800-0000-e9e3-e37c02150000 pid=5378->ee115d00-b1a4-565e-90e2-a5283776ece2 con guuid=a292e445-2800-0000-e9e3-e37c03150000 pid=5379->ea727370-676a-5361-abb1-6788552f4e79 send: 147B guuid=d8fc2d5d-2800-0000-e9e3-e37c0c150000 pid=5388->ea727370-676a-5361-abb1-6788552f4e79 send: 96B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d36f0bc22c7bd42ac4bfd449d1163dbe7b21e709e2d4f49febcb151c963a6ca2

(this sample)

  
Delivery method
Distributed via web download

Comments