MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db32c415d5bb72cbafdf8f149d2c24565304a0e54221321266192ab94e47c55e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: db32c415d5bb72cbafdf8f149d2c24565304a0e54221321266192ab94e47c55e
SHA3-384 hash: b33370277635567e995e7911c6129e5e623863662c40089cc2679977f0ae989c4eadfdf85d1e009aaace2d6162b99187
SHA1 hash: c50afb2e71cd1cb6295f446f5918c3e8df58d0d1
MD5 hash: 8a161346f8d6dca60ed72d4025038f76
humanhash: violet-cola-fruit-low
File name:lol.sh
Download: download sample
Signature Mirai
File size:1'776 bytes
First seen:2025-08-01 22:03:30 UTC
Last seen:2025-08-02 20:48:30 UTC
File type: sh
MIME type:text/plain
ssdeep 48:olqnzvahPpTipQoRS5fS/1B3evk+Ho9h3mLOg01OFJ+jSWd8gv:oSGD2WeXOK9BmeIGbv
TLSH T1303193CE5941621299CACF15E3BAF989914D81D228C30E7ADD597C3E864FB5C705FF20
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://141.11.62.4/x86_64.nnfbe1aaa1037ddceae279745c7ec4435ca2a343e78fa766113e40332b26f15625 Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/x86_34.nnn/an/aelf geofenced ua-wget USA
http://141.11.62.4/powerpc.nne367518f1343b4196c8e32207ea7fee2ed374fc6cf556768e76365372b2f6af5 Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/mips.nnb2ad71184d7ccc265f7d4f9ba366a5c173eab687e6b52615d409a42dac540288 Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/mipsel.nn84e2dcd4f9377d758a3e0ad2f26aff33a990c9967de82beda592e44cca0183dd Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/arm.nn86a77643ac33e490cf49512d223e3c9b167337875ea727751cb1560d1a1460e0 Miraiarm elf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/arm5.nn68a2d3abee5f7b71c5428ec744712d36c9a24f3a323fad4c4bb3b8cea2993b5a Miraiarm elf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/arm6.nnf1590dbb7f242d7a8212a1108ced0b2feff991ba958b2109e826fa35b6f6fe70 Miraiarm elf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/arm7.nn7fa61d96545d9723646d109fa0303ea8c97adb12f411f3b44f49e178b7922d74 Miraiarm elf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/sparc.nnbcaf40809284280b10b48a7b78bb9fbb04f8a0f1341ecddaa18ed286def8f26e Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/m68k.nn4316a20821a1eba161a7ab18b4a3efa763310cf5e91dff83fb61cbbfba7c5fa6 Miraielf geofenced GorillaBotnet mirai ua-wget USA
http://141.11.62.4/sh4.nn1dbe006076a725cf351e32e38688e035b7c3b7f87a3e15937b0bda163b0812c9 Miraielf geofenced GorillaBotnet mirai ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=fc31755f-1b00-0000-e9ac-fff8530c0000 pid=3155 /usr/bin/sudo guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162 /tmp/sample.bin guuid=fc31755f-1b00-0000-e9ac-fff8530c0000 pid=3155->guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162 execve guuid=1c3c5f63-1b00-0000-e9ac-fff85b0c0000 pid=3163 /usr/bin/wget net send-data write-file guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=1c3c5f63-1b00-0000-e9ac-fff85b0c0000 pid=3163 execve guuid=eeec316e-1b00-0000-e9ac-fff8670c0000 pid=3175 /usr/bin/curl net send-data write-file guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=eeec316e-1b00-0000-e9ac-fff8670c0000 pid=3175 execve guuid=e2f5437b-1b00-0000-e9ac-fff86a0c0000 pid=3178 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e2f5437b-1b00-0000-e9ac-fff86a0c0000 pid=3178 execve guuid=3aa19b7b-1b00-0000-e9ac-fff86b0c0000 pid=3179 /tmp/x86_64.nn delete-file net write-config guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=3aa19b7b-1b00-0000-e9ac-fff86b0c0000 pid=3179 execve guuid=db8e9481-1b00-0000-e9ac-fff86e0c0000 pid=3182 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=db8e9481-1b00-0000-e9ac-fff86e0c0000 pid=3182 execve guuid=486f0382-1b00-0000-e9ac-fff86f0c0000 pid=3183 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=486f0382-1b00-0000-e9ac-fff86f0c0000 pid=3183 execve guuid=cf52f982-1b00-0000-e9ac-fff8710c0000 pid=3185 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=cf52f982-1b00-0000-e9ac-fff8710c0000 pid=3185 execve guuid=a5d52d83-1b00-0000-e9ac-fff8720c0000 pid=3186 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=a5d52d83-1b00-0000-e9ac-fff8720c0000 pid=3186 execve guuid=e8b0bf83-1b00-0000-e9ac-fff8730c0000 pid=3187 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e8b0bf83-1b00-0000-e9ac-fff8730c0000 pid=3187 clone guuid=8a8dce83-1b00-0000-e9ac-fff8740c0000 pid=3188 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=8a8dce83-1b00-0000-e9ac-fff8740c0000 pid=3188 execve guuid=a9cf0e84-1b00-0000-e9ac-fff8760c0000 pid=3190 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=a9cf0e84-1b00-0000-e9ac-fff8760c0000 pid=3190 execve guuid=6efb2884-1b00-0000-e9ac-fff8780c0000 pid=3192 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=6efb2884-1b00-0000-e9ac-fff8780c0000 pid=3192 execve guuid=7e964484-1b00-0000-e9ac-fff8790c0000 pid=3193 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=7e964484-1b00-0000-e9ac-fff8790c0000 pid=3193 execve guuid=9d54a584-1b00-0000-e9ac-fff87b0c0000 pid=3195 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=9d54a584-1b00-0000-e9ac-fff87b0c0000 pid=3195 clone guuid=45b8b884-1b00-0000-e9ac-fff87d0c0000 pid=3197 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=45b8b884-1b00-0000-e9ac-fff87d0c0000 pid=3197 execve guuid=6629ef84-1b00-0000-e9ac-fff87e0c0000 pid=3198 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=6629ef84-1b00-0000-e9ac-fff87e0c0000 pid=3198 execve guuid=64c70685-1b00-0000-e9ac-fff8800c0000 pid=3200 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=64c70685-1b00-0000-e9ac-fff8800c0000 pid=3200 execve guuid=e36f2385-1b00-0000-e9ac-fff8810c0000 pid=3201 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e36f2385-1b00-0000-e9ac-fff8810c0000 pid=3201 execve guuid=bee88185-1b00-0000-e9ac-fff8830c0000 pid=3203 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=bee88185-1b00-0000-e9ac-fff8830c0000 pid=3203 clone guuid=b86c8d85-1b00-0000-e9ac-fff8850c0000 pid=3205 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=b86c8d85-1b00-0000-e9ac-fff8850c0000 pid=3205 execve guuid=03d4de85-1b00-0000-e9ac-fff8870c0000 pid=3207 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=03d4de85-1b00-0000-e9ac-fff8870c0000 pid=3207 execve guuid=1eebf985-1b00-0000-e9ac-fff8880c0000 pid=3208 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=1eebf985-1b00-0000-e9ac-fff8880c0000 pid=3208 execve guuid=2eeb1486-1b00-0000-e9ac-fff8890c0000 pid=3209 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=2eeb1486-1b00-0000-e9ac-fff8890c0000 pid=3209 execve guuid=920e5686-1b00-0000-e9ac-fff88b0c0000 pid=3211 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=920e5686-1b00-0000-e9ac-fff88b0c0000 pid=3211 clone guuid=e6e76686-1b00-0000-e9ac-fff88c0c0000 pid=3212 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e6e76686-1b00-0000-e9ac-fff88c0c0000 pid=3212 execve guuid=01669f86-1b00-0000-e9ac-fff88d0c0000 pid=3213 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=01669f86-1b00-0000-e9ac-fff88d0c0000 pid=3213 execve guuid=fb19c886-1b00-0000-e9ac-fff88f0c0000 pid=3215 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=fb19c886-1b00-0000-e9ac-fff88f0c0000 pid=3215 execve guuid=1ac2e886-1b00-0000-e9ac-fff8900c0000 pid=3216 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=1ac2e886-1b00-0000-e9ac-fff8900c0000 pid=3216 execve guuid=c4493e87-1b00-0000-e9ac-fff8920c0000 pid=3218 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=c4493e87-1b00-0000-e9ac-fff8920c0000 pid=3218 clone guuid=0fec4a87-1b00-0000-e9ac-fff8930c0000 pid=3219 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=0fec4a87-1b00-0000-e9ac-fff8930c0000 pid=3219 execve guuid=e25b8c87-1b00-0000-e9ac-fff8950c0000 pid=3221 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e25b8c87-1b00-0000-e9ac-fff8950c0000 pid=3221 execve guuid=4812a087-1b00-0000-e9ac-fff8960c0000 pid=3222 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=4812a087-1b00-0000-e9ac-fff8960c0000 pid=3222 execve guuid=a087bc87-1b00-0000-e9ac-fff8970c0000 pid=3223 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=a087bc87-1b00-0000-e9ac-fff8970c0000 pid=3223 execve guuid=e63b0288-1b00-0000-e9ac-fff8990c0000 pid=3225 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e63b0288-1b00-0000-e9ac-fff8990c0000 pid=3225 clone guuid=1f0d0e88-1b00-0000-e9ac-fff89a0c0000 pid=3226 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=1f0d0e88-1b00-0000-e9ac-fff89a0c0000 pid=3226 execve guuid=3c834488-1b00-0000-e9ac-fff89c0c0000 pid=3228 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=3c834488-1b00-0000-e9ac-fff89c0c0000 pid=3228 execve guuid=2b216d88-1b00-0000-e9ac-fff89e0c0000 pid=3230 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=2b216d88-1b00-0000-e9ac-fff89e0c0000 pid=3230 execve guuid=dd97b588-1b00-0000-e9ac-fff8a00c0000 pid=3232 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=dd97b588-1b00-0000-e9ac-fff8a00c0000 pid=3232 execve guuid=78ec1989-1b00-0000-e9ac-fff8a20c0000 pid=3234 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=78ec1989-1b00-0000-e9ac-fff8a20c0000 pid=3234 clone guuid=eb2b2c89-1b00-0000-e9ac-fff8a30c0000 pid=3235 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=eb2b2c89-1b00-0000-e9ac-fff8a30c0000 pid=3235 execve guuid=37897c89-1b00-0000-e9ac-fff8a50c0000 pid=3237 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=37897c89-1b00-0000-e9ac-fff8a50c0000 pid=3237 execve guuid=a3e59f89-1b00-0000-e9ac-fff8a60c0000 pid=3238 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=a3e59f89-1b00-0000-e9ac-fff8a60c0000 pid=3238 execve guuid=88e9c789-1b00-0000-e9ac-fff8a70c0000 pid=3239 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=88e9c789-1b00-0000-e9ac-fff8a70c0000 pid=3239 execve guuid=3f98018a-1b00-0000-e9ac-fff8a90c0000 pid=3241 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=3f98018a-1b00-0000-e9ac-fff8a90c0000 pid=3241 clone guuid=96e4098a-1b00-0000-e9ac-fff8aa0c0000 pid=3242 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=96e4098a-1b00-0000-e9ac-fff8aa0c0000 pid=3242 execve guuid=8e883f8a-1b00-0000-e9ac-fff8ac0c0000 pid=3244 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=8e883f8a-1b00-0000-e9ac-fff8ac0c0000 pid=3244 execve guuid=ea8c558a-1b00-0000-e9ac-fff8ad0c0000 pid=3245 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=ea8c558a-1b00-0000-e9ac-fff8ad0c0000 pid=3245 execve guuid=f7c8748a-1b00-0000-e9ac-fff8af0c0000 pid=3247 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=f7c8748a-1b00-0000-e9ac-fff8af0c0000 pid=3247 execve guuid=9927b18a-1b00-0000-e9ac-fff8b00c0000 pid=3248 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=9927b18a-1b00-0000-e9ac-fff8b00c0000 pid=3248 clone guuid=a666ba8a-1b00-0000-e9ac-fff8b20c0000 pid=3250 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=a666ba8a-1b00-0000-e9ac-fff8b20c0000 pid=3250 execve guuid=065bf18a-1b00-0000-e9ac-fff8b30c0000 pid=3251 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=065bf18a-1b00-0000-e9ac-fff8b30c0000 pid=3251 execve guuid=65b8088b-1b00-0000-e9ac-fff8b50c0000 pid=3253 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=65b8088b-1b00-0000-e9ac-fff8b50c0000 pid=3253 execve guuid=cf3b1d8b-1b00-0000-e9ac-fff8b60c0000 pid=3254 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=cf3b1d8b-1b00-0000-e9ac-fff8b60c0000 pid=3254 execve guuid=4cee5d8b-1b00-0000-e9ac-fff8b80c0000 pid=3256 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=4cee5d8b-1b00-0000-e9ac-fff8b80c0000 pid=3256 clone guuid=d99e6a8b-1b00-0000-e9ac-fff8b90c0000 pid=3257 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=d99e6a8b-1b00-0000-e9ac-fff8b90c0000 pid=3257 execve guuid=7266c78b-1b00-0000-e9ac-fff8ba0c0000 pid=3258 /usr/bin/wget guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=7266c78b-1b00-0000-e9ac-fff8ba0c0000 pid=3258 execve guuid=1364e28b-1b00-0000-e9ac-fff8bb0c0000 pid=3259 /usr/bin/curl guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=1364e28b-1b00-0000-e9ac-fff8bb0c0000 pid=3259 execve guuid=e5b6048c-1b00-0000-e9ac-fff8bc0c0000 pid=3260 /usr/bin/chmod guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=e5b6048c-1b00-0000-e9ac-fff8bc0c0000 pid=3260 execve guuid=7906568c-1b00-0000-e9ac-fff8bd0c0000 pid=3261 /usr/bin/dash guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=7906568c-1b00-0000-e9ac-fff8bd0c0000 pid=3261 clone guuid=4b205f8c-1b00-0000-e9ac-fff8be0c0000 pid=3262 /usr/bin/rm guuid=ebcbc362-1b00-0000-e9ac-fff85a0c0000 pid=3162->guuid=4b205f8c-1b00-0000-e9ac-fff8be0c0000 pid=3262 execve 2f4c6a83-4d14-5a59-8b91-657286c69cbc 141.11.62.4:80 guuid=1c3c5f63-1b00-0000-e9ac-fff85b0c0000 pid=3163->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 135B guuid=eeec316e-1b00-0000-e9ac-fff8670c0000 pid=3175->2f4c6a83-4d14-5a59-8b91-657286c69cbc send: 84B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3aa19b7b-1b00-0000-e9ac-fff86b0c0000 pid=3179->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180 /tmp/x86_64.nn net send-data zombie guuid=3aa19b7b-1b00-0000-e9ac-fff86b0c0000 pid=3179->guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180 clone 60d89362-3e94-581f-9d5b-254db367cf9b 194.113.37.21:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->60d89362-3e94-581f-9d5b-254db367cf9b send: 1566B 0e8d3471-406a-5f59-8b06-1e10d054a8b2 217.60.248.199:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->0e8d3471-406a-5f59-8b06-1e10d054a8b2 send: 110B 166e262e-6b56-5f67-b714-f3b91a78f396 104.252.127.190:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->166e262e-6b56-5f67-b714-f3b91a78f396 send: 220B 04e4850f-aca3-5034-8c08-b1220c6f1903 103.136.69.242:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->04e4850f-aca3-5034-8c08-b1220c6f1903 send: 220B e55b4096-bef5-5bc1-a4a1-4b1542311f08 217.60.249.53:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->e55b4096-bef5-5bc1-a4a1-4b1542311f08 send: 110B c31a0fe6-5b7c-56d4-a7a1-3eb1d3b3b1ac 31.59.120.38:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->c31a0fe6-5b7c-56d4-a7a1-3eb1d3b3b1ac send: 110B 2c132907-aa23-5403-977b-719bf1b927ad 109.248.162.59:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->2c132907-aa23-5403-977b-719bf1b927ad send: 110B bec59696-0853-5b69-9aa0-87290f542371 45.145.7.100:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->bec59696-0853-5b69-9aa0-87290f542371 send: 110B 6de0e0a4-c4ff-52be-80b1-d0ca94f2e4b5 217.60.248.115:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->6de0e0a4-c4ff-52be-80b1-d0ca94f2e4b5 con 2e6ab615-9d56-5c60-8fa4-ac1cd9c81407 255.255.255.255:38242 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->2e6ab615-9d56-5c60-8fa4-ac1cd9c81407 con 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 send: 29B guuid=c4a8037f-1b00-0000-e9ac-fff86d0c0000 pid=3181 /tmp/x86_64.nn guuid=98ef177d-1b00-0000-e9ac-fff86c0c0000 pid=3180->guuid=c4a8037f-1b00-0000-e9ac-fff86d0c0000 pid=3181 clone
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Geninst
Status:
Malicious
First seen:
2025-08-01 22:04:20 UTC
File Type:
Text (Shell)
AV detection:
13 of 23 (56.52%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh db32c415d5bb72cbafdf8f149d2c24565304a0e54221321266192ab94e47c55e

(this sample)

  
Delivery method
Distributed via web download

Comments