MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dcb2e53eaeb334e77769eede9700b4a544e013b70c337a61ebb0513243393ac2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: dcb2e53eaeb334e77769eede9700b4a544e013b70c337a61ebb0513243393ac2
SHA3-384 hash: 1dbbfaf4914924af83b275af1a5613945ef376fb690b663c40c62a5655d87e936ee9b59d8e1c245f541cf771fe1751fa
SHA1 hash: 09465c01dc4e1f5248c9c2a34d77e4942ef1dea5
MD5 hash: ada20efcff540ff37f4c0801e6aed04f
humanhash: lithium-oscar-ceiling-robert
File name:ok
Download: download sample
Signature Mirai
File size:1'584 bytes
First seen:2026-06-24 00:04:57 UTC
Last seen:2026-06-24 23:01:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:U076oR3U6776uBWbIr6Vvt7wi60kGai6aeEx6di6dmmr89a6ARI6RgnR/065Hd6y:d5Kt7HXxyTm+8pnh0YH2HN5rGBwBen
TLSH T1D5311ADE46111A352602CADD77B3368DA50C93EF2C9BC3809D4C1EED82896CCB265BD5
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.182.210.61/c42e24n/an/aelf ua-wget
http://5.182.210.61/a14b12n/an/aelf ua-wget
http://5.182.210.61/108b2an/an/aelf ua-wget
http://5.182.210.61/09a96cn/an/aelf ua-wget
http://5.182.210.61/c3312an/an/aelf ua-wget
http://5.182.210.61/418957n/an/aelf ua-wget
http://5.182.210.61/7d200en/an/aelf ua-wget
http://5.182.210.61/53d8b8n/an/aelf ua-wget
http://5.182.210.61/fdbcb8n/an/aelf ua-wget
http://5.182.210.61/e08f7en/an/aelf ua-wget
http://5.182.210.61/752cf3n/an/aelf ua-wget
http://5.182.210.61/36778cn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
142
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-23T21:11:00Z UTC
Last seen:
2026-06-23T22:42:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=6938d22b-1a00-0000-c085-4b81a30f0000 pid=4003 /usr/bin/sudo guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013 /tmp/sample.bin guuid=6938d22b-1a00-0000-c085-4b81a30f0000 pid=4003->guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013 execve guuid=11b5e42e-1a00-0000-c085-4b81b10f0000 pid=4017 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=11b5e42e-1a00-0000-c085-4b81b10f0000 pid=4017 execve guuid=6a36d133-1a00-0000-c085-4b81bd0f0000 pid=4029 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=6a36d133-1a00-0000-c085-4b81bd0f0000 pid=4029 execve guuid=bac9763d-1a00-0000-c085-4b81d70f0000 pid=4055 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=bac9763d-1a00-0000-c085-4b81d70f0000 pid=4055 execve guuid=02e0153e-1a00-0000-c085-4b81db0f0000 pid=4059 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=02e0153e-1a00-0000-c085-4b81db0f0000 pid=4059 clone guuid=eb3fc43e-1a00-0000-c085-4b81e00f0000 pid=4064 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=eb3fc43e-1a00-0000-c085-4b81e00f0000 pid=4064 execve guuid=fdaf113f-1a00-0000-c085-4b81e10f0000 pid=4065 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=fdaf113f-1a00-0000-c085-4b81e10f0000 pid=4065 execve guuid=39a1683f-1a00-0000-c085-4b81e20f0000 pid=4066 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=39a1683f-1a00-0000-c085-4b81e20f0000 pid=4066 execve guuid=96db4243-1a00-0000-c085-4b81ea0f0000 pid=4074 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=96db4243-1a00-0000-c085-4b81ea0f0000 pid=4074 execve guuid=9c998c48-1a00-0000-c085-4b81f20f0000 pid=4082 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=9c998c48-1a00-0000-c085-4b81f20f0000 pid=4082 execve guuid=42430e49-1a00-0000-c085-4b81f40f0000 pid=4084 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=42430e49-1a00-0000-c085-4b81f40f0000 pid=4084 clone guuid=6f326649-1a00-0000-c085-4b81f70f0000 pid=4087 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=6f326649-1a00-0000-c085-4b81f70f0000 pid=4087 execve guuid=d277e549-1a00-0000-c085-4b81fb0f0000 pid=4091 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=d277e549-1a00-0000-c085-4b81fb0f0000 pid=4091 execve guuid=21614a4a-1a00-0000-c085-4b81fc0f0000 pid=4092 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=21614a4a-1a00-0000-c085-4b81fc0f0000 pid=4092 execve guuid=e565694d-1a00-0000-c085-4b8109100000 pid=4105 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=e565694d-1a00-0000-c085-4b8109100000 pid=4105 execve guuid=07a94751-1a00-0000-c085-4b8116100000 pid=4118 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=07a94751-1a00-0000-c085-4b8116100000 pid=4118 execve guuid=c8b4ab51-1a00-0000-c085-4b8118100000 pid=4120 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=c8b4ab51-1a00-0000-c085-4b8118100000 pid=4120 clone guuid=188a0452-1a00-0000-c085-4b811b100000 pid=4123 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=188a0452-1a00-0000-c085-4b811b100000 pid=4123 execve guuid=c432f252-1a00-0000-c085-4b811f100000 pid=4127 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=c432f252-1a00-0000-c085-4b811f100000 pid=4127 execve guuid=48746e53-1a00-0000-c085-4b8121100000 pid=4129 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=48746e53-1a00-0000-c085-4b8121100000 pid=4129 execve guuid=333dda56-1a00-0000-c085-4b812a100000 pid=4138 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=333dda56-1a00-0000-c085-4b812a100000 pid=4138 execve guuid=87657a60-1a00-0000-c085-4b813a100000 pid=4154 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=87657a60-1a00-0000-c085-4b813a100000 pid=4154 execve guuid=545ae660-1a00-0000-c085-4b813c100000 pid=4156 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=545ae660-1a00-0000-c085-4b813c100000 pid=4156 clone guuid=352e4e61-1a00-0000-c085-4b813e100000 pid=4158 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=352e4e61-1a00-0000-c085-4b813e100000 pid=4158 execve guuid=1624c061-1a00-0000-c085-4b8140100000 pid=4160 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=1624c061-1a00-0000-c085-4b8140100000 pid=4160 execve guuid=4a0e2862-1a00-0000-c085-4b8142100000 pid=4162 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=4a0e2862-1a00-0000-c085-4b8142100000 pid=4162 execve guuid=11e97365-1a00-0000-c085-4b814f100000 pid=4175 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=11e97365-1a00-0000-c085-4b814f100000 pid=4175 execve guuid=4edab569-1a00-0000-c085-4b815e100000 pid=4190 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=4edab569-1a00-0000-c085-4b815e100000 pid=4190 execve guuid=0264106a-1a00-0000-c085-4b8160100000 pid=4192 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=0264106a-1a00-0000-c085-4b8160100000 pid=4192 clone guuid=ee81586a-1a00-0000-c085-4b8165100000 pid=4197 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=ee81586a-1a00-0000-c085-4b8165100000 pid=4197 execve guuid=fd39b96a-1a00-0000-c085-4b8169100000 pid=4201 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=fd39b96a-1a00-0000-c085-4b8169100000 pid=4201 execve guuid=15c5136b-1a00-0000-c085-4b816b100000 pid=4203 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=15c5136b-1a00-0000-c085-4b816b100000 pid=4203 execve guuid=730ae86d-1a00-0000-c085-4b8176100000 pid=4214 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=730ae86d-1a00-0000-c085-4b8176100000 pid=4214 execve guuid=9fd70073-1a00-0000-c085-4b818a100000 pid=4234 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=9fd70073-1a00-0000-c085-4b818a100000 pid=4234 execve guuid=f83b6673-1a00-0000-c085-4b818d100000 pid=4237 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=f83b6673-1a00-0000-c085-4b818d100000 pid=4237 clone guuid=bb789873-1a00-0000-c085-4b818f100000 pid=4239 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=bb789873-1a00-0000-c085-4b818f100000 pid=4239 execve guuid=0f08fe73-1a00-0000-c085-4b8193100000 pid=4243 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=0f08fe73-1a00-0000-c085-4b8193100000 pid=4243 execve guuid=5aca6574-1a00-0000-c085-4b8197100000 pid=4247 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=5aca6574-1a00-0000-c085-4b8197100000 pid=4247 execve guuid=eb9b7277-1a00-0000-c085-4b81a1100000 pid=4257 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=eb9b7277-1a00-0000-c085-4b81a1100000 pid=4257 execve guuid=f9d9c47c-1a00-0000-c085-4b81b2100000 pid=4274 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=f9d9c47c-1a00-0000-c085-4b81b2100000 pid=4274 execve guuid=4767127d-1a00-0000-c085-4b81b5100000 pid=4277 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=4767127d-1a00-0000-c085-4b81b5100000 pid=4277 clone guuid=c316557d-1a00-0000-c085-4b81b7100000 pid=4279 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=c316557d-1a00-0000-c085-4b81b7100000 pid=4279 execve guuid=8cffc57d-1a00-0000-c085-4b81ba100000 pid=4282 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=8cffc57d-1a00-0000-c085-4b81ba100000 pid=4282 execve guuid=0caf407e-1a00-0000-c085-4b81bc100000 pid=4284 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=0caf407e-1a00-0000-c085-4b81bc100000 pid=4284 execve guuid=e1e8c380-1a00-0000-c085-4b81c7100000 pid=4295 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=e1e8c380-1a00-0000-c085-4b81c7100000 pid=4295 execve guuid=e1920187-1a00-0000-c085-4b81d9100000 pid=4313 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=e1920187-1a00-0000-c085-4b81d9100000 pid=4313 execve guuid=0adc4587-1a00-0000-c085-4b81db100000 pid=4315 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=0adc4587-1a00-0000-c085-4b81db100000 pid=4315 clone guuid=0266a287-1a00-0000-c085-4b81df100000 pid=4319 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=0266a287-1a00-0000-c085-4b81df100000 pid=4319 execve guuid=d3e3fe87-1a00-0000-c085-4b81e0100000 pid=4320 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=d3e3fe87-1a00-0000-c085-4b81e0100000 pid=4320 execve guuid=81db5388-1a00-0000-c085-4b81e1100000 pid=4321 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=81db5388-1a00-0000-c085-4b81e1100000 pid=4321 execve guuid=a0403f8b-1a00-0000-c085-4b81ee100000 pid=4334 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=a0403f8b-1a00-0000-c085-4b81ee100000 pid=4334 execve guuid=ee5ae290-1a00-0000-c085-4b8102110000 pid=4354 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=ee5ae290-1a00-0000-c085-4b8102110000 pid=4354 execve guuid=3bba2591-1a00-0000-c085-4b8104110000 pid=4356 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=3bba2591-1a00-0000-c085-4b8104110000 pid=4356 clone guuid=d1096891-1a00-0000-c085-4b8109110000 pid=4361 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=d1096891-1a00-0000-c085-4b8109110000 pid=4361 execve guuid=ef6ca791-1a00-0000-c085-4b810a110000 pid=4362 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=ef6ca791-1a00-0000-c085-4b810a110000 pid=4362 execve guuid=9e35e991-1a00-0000-c085-4b810e110000 pid=4366 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=9e35e991-1a00-0000-c085-4b810e110000 pid=4366 execve guuid=5b63c294-1a00-0000-c085-4b8116110000 pid=4374 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=5b63c294-1a00-0000-c085-4b8116110000 pid=4374 execve guuid=54278498-1a00-0000-c085-4b8126110000 pid=4390 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=54278498-1a00-0000-c085-4b8126110000 pid=4390 execve guuid=b179cf98-1a00-0000-c085-4b8129110000 pid=4393 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=b179cf98-1a00-0000-c085-4b8129110000 pid=4393 clone guuid=242a1b99-1a00-0000-c085-4b812d110000 pid=4397 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=242a1b99-1a00-0000-c085-4b812d110000 pid=4397 execve guuid=5def7c99-1a00-0000-c085-4b812f110000 pid=4399 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=5def7c99-1a00-0000-c085-4b812f110000 pid=4399 execve guuid=6f3ed299-1a00-0000-c085-4b8133110000 pid=4403 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=6f3ed299-1a00-0000-c085-4b8133110000 pid=4403 execve guuid=29bac39c-1a00-0000-c085-4b8141110000 pid=4417 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=29bac39c-1a00-0000-c085-4b8141110000 pid=4417 execve guuid=f53d63a2-1a00-0000-c085-4b815b110000 pid=4443 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=f53d63a2-1a00-0000-c085-4b815b110000 pid=4443 execve guuid=adeca4a2-1a00-0000-c085-4b815c110000 pid=4444 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=adeca4a2-1a00-0000-c085-4b815c110000 pid=4444 clone guuid=47b4dda2-1a00-0000-c085-4b815f110000 pid=4447 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=47b4dda2-1a00-0000-c085-4b815f110000 pid=4447 execve guuid=41344aa3-1a00-0000-c085-4b8161110000 pid=4449 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=41344aa3-1a00-0000-c085-4b8161110000 pid=4449 execve guuid=de1db3a3-1a00-0000-c085-4b8164110000 pid=4452 /usr/bin/wget net send-data guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=de1db3a3-1a00-0000-c085-4b8164110000 pid=4452 execve guuid=790e47a6-1a00-0000-c085-4b816c110000 pid=4460 /usr/bin/curl net send-data write-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=790e47a6-1a00-0000-c085-4b816c110000 pid=4460 execve guuid=c4fabaab-1a00-0000-c085-4b8180110000 pid=4480 /usr/bin/chmod guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=c4fabaab-1a00-0000-c085-4b8180110000 pid=4480 execve guuid=a43505ac-1a00-0000-c085-4b8182110000 pid=4482 /usr/bin/bash guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=a43505ac-1a00-0000-c085-4b8182110000 pid=4482 clone guuid=a2383bac-1a00-0000-c085-4b8185110000 pid=4485 /usr/bin/rm delete-file guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=a2383bac-1a00-0000-c085-4b8185110000 pid=4485 execve guuid=b85086ac-1a00-0000-c085-4b8189110000 pid=4489 /usr/bin/rm guuid=ec71882e-1a00-0000-c085-4b81ad0f0000 pid=4013->guuid=b85086ac-1a00-0000-c085-4b8189110000 pid=4489 execve 9e33e6d7-6ac7-5a65-88f4-941337e56821 5.182.210.61:80 guuid=11b5e42e-1a00-0000-c085-4b81b10f0000 pid=4017->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=6a36d133-1a00-0000-c085-4b81bd0f0000 pid=4029->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=0166403e-1a00-0000-c085-4b81dd0f0000 pid=4061 /usr/bin/bash guuid=02e0153e-1a00-0000-c085-4b81db0f0000 pid=4059->guuid=0166403e-1a00-0000-c085-4b81dd0f0000 pid=4061 clone guuid=39a1683f-1a00-0000-c085-4b81e20f0000 pid=4066->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=96db4243-1a00-0000-c085-4b81ea0f0000 pid=4074->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=41283649-1a00-0000-c085-4b81f60f0000 pid=4086 /usr/bin/bash guuid=42430e49-1a00-0000-c085-4b81f40f0000 pid=4084->guuid=41283649-1a00-0000-c085-4b81f60f0000 pid=4086 clone guuid=21614a4a-1a00-0000-c085-4b81fc0f0000 pid=4092->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=e565694d-1a00-0000-c085-4b8109100000 pid=4105->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=e74cd251-1a00-0000-c085-4b811a100000 pid=4122 /usr/bin/bash guuid=c8b4ab51-1a00-0000-c085-4b8118100000 pid=4120->guuid=e74cd251-1a00-0000-c085-4b811a100000 pid=4122 clone guuid=48746e53-1a00-0000-c085-4b8121100000 pid=4129->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=333dda56-1a00-0000-c085-4b812a100000 pid=4138->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c3190d61-1a00-0000-c085-4b813d100000 pid=4157 /usr/bin/bash guuid=545ae660-1a00-0000-c085-4b813c100000 pid=4156->guuid=c3190d61-1a00-0000-c085-4b813d100000 pid=4157 clone guuid=4a0e2862-1a00-0000-c085-4b8142100000 pid=4162->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=11e97365-1a00-0000-c085-4b814f100000 pid=4175->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=59062d6a-1a00-0000-c085-4b8164100000 pid=4196 /usr/bin/bash guuid=0264106a-1a00-0000-c085-4b8160100000 pid=4192->guuid=59062d6a-1a00-0000-c085-4b8164100000 pid=4196 clone guuid=15c5136b-1a00-0000-c085-4b816b100000 pid=4203->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=730ae86d-1a00-0000-c085-4b8176100000 pid=4214->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c3487973-1a00-0000-c085-4b818e100000 pid=4238 /usr/bin/bash guuid=f83b6673-1a00-0000-c085-4b818d100000 pid=4237->guuid=c3487973-1a00-0000-c085-4b818e100000 pid=4238 clone guuid=5aca6574-1a00-0000-c085-4b8197100000 pid=4247->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=eb9b7277-1a00-0000-c085-4b81a1100000 pid=4257->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=ec94327d-1a00-0000-c085-4b81b6100000 pid=4278 /usr/bin/bash guuid=4767127d-1a00-0000-c085-4b81b5100000 pid=4277->guuid=ec94327d-1a00-0000-c085-4b81b6100000 pid=4278 clone guuid=0caf407e-1a00-0000-c085-4b81bc100000 pid=4284->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=e1e8c380-1a00-0000-c085-4b81c7100000 pid=4295->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=a4027487-1a00-0000-c085-4b81de100000 pid=4318 /usr/bin/bash guuid=0adc4587-1a00-0000-c085-4b81db100000 pid=4315->guuid=a4027487-1a00-0000-c085-4b81de100000 pid=4318 clone guuid=81db5388-1a00-0000-c085-4b81e1100000 pid=4321->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=a0403f8b-1a00-0000-c085-4b81ee100000 pid=4334->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=38394391-1a00-0000-c085-4b8105110000 pid=4357 /usr/bin/bash guuid=3bba2591-1a00-0000-c085-4b8104110000 pid=4356->guuid=38394391-1a00-0000-c085-4b8105110000 pid=4357 clone guuid=9e35e991-1a00-0000-c085-4b810e110000 pid=4366->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=5b63c294-1a00-0000-c085-4b8116110000 pid=4374->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=86c4f298-1a00-0000-c085-4b812a110000 pid=4394 /usr/bin/bash guuid=b179cf98-1a00-0000-c085-4b8129110000 pid=4393->guuid=86c4f298-1a00-0000-c085-4b812a110000 pid=4394 clone guuid=6f3ed299-1a00-0000-c085-4b8133110000 pid=4403->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=29bac39c-1a00-0000-c085-4b8141110000 pid=4417->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=c30bbba2-1a00-0000-c085-4b815d110000 pid=4445 /usr/bin/bash guuid=adeca4a2-1a00-0000-c085-4b815c110000 pid=4444->guuid=c30bbba2-1a00-0000-c085-4b815d110000 pid=4445 clone guuid=de1db3a3-1a00-0000-c085-4b8164110000 pid=4452->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 133B guuid=790e47a6-1a00-0000-c085-4b816c110000 pid=4460->9e33e6d7-6ac7-5a65-88f4-941337e56821 send: 82B guuid=f0a91fac-1a00-0000-c085-4b8183110000 pid=4483 /usr/bin/bash guuid=a43505ac-1a00-0000-c085-4b8182110000 pid=4482->guuid=f0a91fac-1a00-0000-c085-4b8183110000 pid=4483 clone
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-24 00:06:01 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dcb2e53eaeb334e77769eede9700b4a544e013b70c337a61ebb0513243393ac2

(this sample)

  
Delivery method
Distributed via web download

Comments