MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 df709c844a5be6aeaeaa6a585e73e2706883e170ee3880e923d4147db2d5596a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: df709c844a5be6aeaeaa6a585e73e2706883e170ee3880e923d4147db2d5596a
SHA3-384 hash: fbe308f618c76317d4950e4ac082d50feca4958fbd340ac5e1c0141d4f6479b557e1221df99cd090eead4e19ea761f6c
SHA1 hash: 8a9b6d390bcf3676ebbf5523ecb4ed94227fa3a7
MD5 hash: d129ff831bb3a7ffed1efdc4ed87d154
humanhash: video-michigan-sierra-skylark
File name:p
Download: download sample
Signature Mirai
File size:830 bytes
First seen:2026-06-23 04:24:40 UTC
Last seen:2026-06-23 13:09:36 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohaLFOoDkbXEARF8X389Pf7:e9Qp+MsxtkbXE0FG381D
TLSH T19801ABD68410A9204419DA1D22CB5150F440C3CF5A4B0F687F9C6E7EFBA8E14B026F85
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://129.121.114.124/9DB959160a685c30b77db8bbd554f2f1bc6e095944bf4bf3daab7c277bac7fca5fb5 Miraiarm elf mirai ua-wget
http://129.121.114.124/OIx2d8f91170a27ded0f31aa44ae7afa77c68fe2ca41b4d52750cb3d8cbaaefd2b5 Miraiarm elf mirai ua-wget
http://129.121.114.124/QICb67f4541aa89e84cd5df5c7d4b3dbaaf86808bfabc3047488abf91c15e7a62a2 Miraiarm elf mirai ua-wget
http://129.121.114.124/3kjEe3e19b2eafce2b14f27b9a9891496baab47ed18a3b4c1b8634af97581347c36a Miraielf mips mirai ua-wget
http://129.121.114.124/Nwk989b055516ad13b8f28ce06db256e45db0135e19b91980fae419514ea4abf8b8 Miraielf mips mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=0d0fc2ad-1900-0000-6782-45138b100000 pid=4235 /usr/bin/sudo guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246 /tmp/sample.bin write-file guuid=0d0fc2ad-1900-0000-6782-45138b100000 pid=4235->guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246 execve guuid=4cb549b0-1900-0000-6782-451398100000 pid=4248 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=4cb549b0-1900-0000-6782-451398100000 pid=4248 execve guuid=741827b1-1900-0000-6782-45139a100000 pid=4250 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=741827b1-1900-0000-6782-45139a100000 pid=4250 execve guuid=ea0baab1-1900-0000-6782-45139b100000 pid=4251 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=ea0baab1-1900-0000-6782-45139b100000 pid=4251 execve guuid=799839b2-1900-0000-6782-45139c100000 pid=4252 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=799839b2-1900-0000-6782-45139c100000 pid=4252 execve guuid=6379b9b2-1900-0000-6782-45139d100000 pid=4253 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=6379b9b2-1900-0000-6782-45139d100000 pid=4253 execve guuid=64c936b3-1900-0000-6782-45139e100000 pid=4254 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=64c936b3-1900-0000-6782-45139e100000 pid=4254 execve guuid=a7149db3-1900-0000-6782-4513a2100000 pid=4258 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=a7149db3-1900-0000-6782-4513a2100000 pid=4258 execve guuid=8ede0ab4-1900-0000-6782-4513a3100000 pid=4259 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=8ede0ab4-1900-0000-6782-4513a3100000 pid=4259 execve guuid=05e1b5b4-1900-0000-6782-4513a8100000 pid=4264 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=05e1b5b4-1900-0000-6782-4513a8100000 pid=4264 execve guuid=08603fb5-1900-0000-6782-4513aa100000 pid=4266 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=08603fb5-1900-0000-6782-4513aa100000 pid=4266 execve guuid=e9a7bbb5-1900-0000-6782-4513ae100000 pid=4270 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=e9a7bbb5-1900-0000-6782-4513ae100000 pid=4270 execve guuid=776c1fb6-1900-0000-6782-4513b2100000 pid=4274 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=776c1fb6-1900-0000-6782-4513b2100000 pid=4274 execve guuid=a26e7ab6-1900-0000-6782-4513b4100000 pid=4276 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=a26e7ab6-1900-0000-6782-4513b4100000 pid=4276 execve guuid=bab2e5b6-1900-0000-6782-4513b6100000 pid=4278 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=bab2e5b6-1900-0000-6782-4513b6100000 pid=4278 execve guuid=0f9863b7-1900-0000-6782-4513b9100000 pid=4281 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0f9863b7-1900-0000-6782-4513b9100000 pid=4281 execve guuid=235ccbb7-1900-0000-6782-4513bb100000 pid=4283 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=235ccbb7-1900-0000-6782-4513bb100000 pid=4283 execve guuid=53a22eb8-1900-0000-6782-4513be100000 pid=4286 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=53a22eb8-1900-0000-6782-4513be100000 pid=4286 execve guuid=6c2d9cb8-1900-0000-6782-4513bf100000 pid=4287 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=6c2d9cb8-1900-0000-6782-4513bf100000 pid=4287 execve guuid=612c40b9-1900-0000-6782-4513c3100000 pid=4291 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=612c40b9-1900-0000-6782-4513c3100000 pid=4291 execve guuid=215bbbb9-1900-0000-6782-4513c6100000 pid=4294 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=215bbbb9-1900-0000-6782-4513c6100000 pid=4294 execve guuid=c3d842ba-1900-0000-6782-4513cb100000 pid=4299 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=c3d842ba-1900-0000-6782-4513cb100000 pid=4299 execve guuid=d79129bb-1900-0000-6782-4513cf100000 pid=4303 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=d79129bb-1900-0000-6782-4513cf100000 pid=4303 execve guuid=7511bdbb-1900-0000-6782-4513d3100000 pid=4307 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=7511bdbb-1900-0000-6782-4513d3100000 pid=4307 execve guuid=2ffb42bc-1900-0000-6782-4513d5100000 pid=4309 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=2ffb42bc-1900-0000-6782-4513d5100000 pid=4309 execve guuid=d26dbcbc-1900-0000-6782-4513da100000 pid=4314 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=d26dbcbc-1900-0000-6782-4513da100000 pid=4314 execve guuid=2eb62fbd-1900-0000-6782-4513db100000 pid=4315 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=2eb62fbd-1900-0000-6782-4513db100000 pid=4315 execve guuid=1b039abd-1900-0000-6782-4513dc100000 pid=4316 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1b039abd-1900-0000-6782-4513dc100000 pid=4316 execve guuid=968501be-1900-0000-6782-4513e0100000 pid=4320 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=968501be-1900-0000-6782-4513e0100000 pid=4320 execve guuid=185c67be-1900-0000-6782-4513e1100000 pid=4321 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=185c67be-1900-0000-6782-4513e1100000 pid=4321 execve guuid=1e53cdbe-1900-0000-6782-4513e4100000 pid=4324 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1e53cdbe-1900-0000-6782-4513e4100000 pid=4324 execve guuid=aaafd4bf-1900-0000-6782-4513e8100000 pid=4328 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=aaafd4bf-1900-0000-6782-4513e8100000 pid=4328 execve guuid=e33949c0-1900-0000-6782-4513eb100000 pid=4331 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=e33949c0-1900-0000-6782-4513eb100000 pid=4331 execve guuid=b38fc3c0-1900-0000-6782-4513ef100000 pid=4335 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b38fc3c0-1900-0000-6782-4513ef100000 pid=4335 execve guuid=4db358c1-1900-0000-6782-4513f0100000 pid=4336 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=4db358c1-1900-0000-6782-4513f0100000 pid=4336 execve guuid=7a260cc2-1900-0000-6782-4513f4100000 pid=4340 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=7a260cc2-1900-0000-6782-4513f4100000 pid=4340 execve guuid=61b773c2-1900-0000-6782-4513f8100000 pid=4344 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=61b773c2-1900-0000-6782-4513f8100000 pid=4344 execve guuid=a618cfc2-1900-0000-6782-4513fc100000 pid=4348 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=a618cfc2-1900-0000-6782-4513fc100000 pid=4348 execve guuid=925e5ec3-1900-0000-6782-451300110000 pid=4352 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=925e5ec3-1900-0000-6782-451300110000 pid=4352 execve guuid=c2f7e3c3-1900-0000-6782-451303110000 pid=4355 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=c2f7e3c3-1900-0000-6782-451303110000 pid=4355 execve guuid=fe3d3fc4-1900-0000-6782-451307110000 pid=4359 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=fe3d3fc4-1900-0000-6782-451307110000 pid=4359 execve guuid=fc499dc4-1900-0000-6782-45130b110000 pid=4363 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=fc499dc4-1900-0000-6782-45130b110000 pid=4363 execve guuid=c967fac4-1900-0000-6782-45130d110000 pid=4365 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=c967fac4-1900-0000-6782-45130d110000 pid=4365 execve guuid=29b760c5-1900-0000-6782-45130f110000 pid=4367 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=29b760c5-1900-0000-6782-45130f110000 pid=4367 execve guuid=4a0cc1c5-1900-0000-6782-451313110000 pid=4371 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=4a0cc1c5-1900-0000-6782-451313110000 pid=4371 execve guuid=8c6427c6-1900-0000-6782-451317110000 pid=4375 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=8c6427c6-1900-0000-6782-451317110000 pid=4375 execve guuid=b7b990c6-1900-0000-6782-451319110000 pid=4377 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b7b990c6-1900-0000-6782-451319110000 pid=4377 execve guuid=766efec6-1900-0000-6782-45131c110000 pid=4380 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=766efec6-1900-0000-6782-45131c110000 pid=4380 execve guuid=64b46bc7-1900-0000-6782-45131e110000 pid=4382 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=64b46bc7-1900-0000-6782-45131e110000 pid=4382 execve guuid=ea55d5c7-1900-0000-6782-451321110000 pid=4385 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=ea55d5c7-1900-0000-6782-451321110000 pid=4385 execve guuid=cc7537c8-1900-0000-6782-451323110000 pid=4387 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=cc7537c8-1900-0000-6782-451323110000 pid=4387 execve guuid=82da8fc8-1900-0000-6782-451327110000 pid=4391 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=82da8fc8-1900-0000-6782-451327110000 pid=4391 execve guuid=4a8600c9-1900-0000-6782-451329110000 pid=4393 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=4a8600c9-1900-0000-6782-451329110000 pid=4393 execve guuid=b4f465c9-1900-0000-6782-45132c110000 pid=4396 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b4f465c9-1900-0000-6782-45132c110000 pid=4396 execve guuid=e12ecec9-1900-0000-6782-45132f110000 pid=4399 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=e12ecec9-1900-0000-6782-45132f110000 pid=4399 execve guuid=e37f3dca-1900-0000-6782-451331110000 pid=4401 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=e37f3dca-1900-0000-6782-451331110000 pid=4401 execve guuid=7c1998ca-1900-0000-6782-451335110000 pid=4405 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=7c1998ca-1900-0000-6782-451335110000 pid=4405 execve guuid=0362f3ca-1900-0000-6782-451339110000 pid=4409 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0362f3ca-1900-0000-6782-451339110000 pid=4409 execve guuid=243262cb-1900-0000-6782-45133a110000 pid=4410 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=243262cb-1900-0000-6782-45133a110000 pid=4410 execve guuid=dc4ac0cb-1900-0000-6782-45133d110000 pid=4413 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=dc4ac0cb-1900-0000-6782-45133d110000 pid=4413 execve guuid=4bd117cc-1900-0000-6782-451341110000 pid=4417 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=4bd117cc-1900-0000-6782-451341110000 pid=4417 execve guuid=673f6ecc-1900-0000-6782-451345110000 pid=4421 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=673f6ecc-1900-0000-6782-451345110000 pid=4421 execve guuid=b926c6cc-1900-0000-6782-451346110000 pid=4422 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b926c6cc-1900-0000-6782-451346110000 pid=4422 execve guuid=d37724cd-1900-0000-6782-451347110000 pid=4423 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=d37724cd-1900-0000-6782-451347110000 pid=4423 execve guuid=277984cd-1900-0000-6782-451349110000 pid=4425 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=277984cd-1900-0000-6782-451349110000 pid=4425 execve guuid=0569d4cd-1900-0000-6782-45134c110000 pid=4428 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0569d4cd-1900-0000-6782-45134c110000 pid=4428 execve guuid=80213ace-1900-0000-6782-45134e110000 pid=4430 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=80213ace-1900-0000-6782-45134e110000 pid=4430 execve guuid=28669fce-1900-0000-6782-451351110000 pid=4433 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=28669fce-1900-0000-6782-451351110000 pid=4433 execve guuid=77d7fbce-1900-0000-6782-451353110000 pid=4435 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=77d7fbce-1900-0000-6782-451353110000 pid=4435 execve guuid=27e553cf-1900-0000-6782-451357110000 pid=4439 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=27e553cf-1900-0000-6782-451357110000 pid=4439 execve guuid=2b1eafcf-1900-0000-6782-451358110000 pid=4440 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=2b1eafcf-1900-0000-6782-451358110000 pid=4440 execve guuid=44d111d0-1900-0000-6782-45135a110000 pid=4442 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=44d111d0-1900-0000-6782-45135a110000 pid=4442 execve guuid=57867ad0-1900-0000-6782-45135d110000 pid=4445 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=57867ad0-1900-0000-6782-45135d110000 pid=4445 execve guuid=df03f2d0-1900-0000-6782-451361110000 pid=4449 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=df03f2d0-1900-0000-6782-451361110000 pid=4449 execve guuid=74f653d1-1900-0000-6782-451362110000 pid=4450 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=74f653d1-1900-0000-6782-451362110000 pid=4450 execve guuid=eeabced1-1900-0000-6782-451366110000 pid=4454 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=eeabced1-1900-0000-6782-451366110000 pid=4454 execve guuid=098d47d2-1900-0000-6782-45136a110000 pid=4458 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=098d47d2-1900-0000-6782-45136a110000 pid=4458 execve guuid=3a31d0d2-1900-0000-6782-45136c110000 pid=4460 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3a31d0d2-1900-0000-6782-45136c110000 pid=4460 execve guuid=79464dd3-1900-0000-6782-451371110000 pid=4465 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=79464dd3-1900-0000-6782-451371110000 pid=4465 execve guuid=794ad0d3-1900-0000-6782-451375110000 pid=4469 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=794ad0d3-1900-0000-6782-451375110000 pid=4469 execve guuid=426135d4-1900-0000-6782-451376110000 pid=4470 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=426135d4-1900-0000-6782-451376110000 pid=4470 execve guuid=499a94d4-1900-0000-6782-451379110000 pid=4473 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=499a94d4-1900-0000-6782-451379110000 pid=4473 execve guuid=2d27f1d4-1900-0000-6782-45137d110000 pid=4477 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=2d27f1d4-1900-0000-6782-45137d110000 pid=4477 execve guuid=53f050d5-1900-0000-6782-451381110000 pid=4481 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=53f050d5-1900-0000-6782-451381110000 pid=4481 execve guuid=6856aad5-1900-0000-6782-451382110000 pid=4482 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=6856aad5-1900-0000-6782-451382110000 pid=4482 execve guuid=995d0fd6-1900-0000-6782-451384110000 pid=4484 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=995d0fd6-1900-0000-6782-451384110000 pid=4484 execve guuid=cbd578d6-1900-0000-6782-451387110000 pid=4487 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=cbd578d6-1900-0000-6782-451387110000 pid=4487 execve guuid=5da1e9d6-1900-0000-6782-45138a110000 pid=4490 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=5da1e9d6-1900-0000-6782-45138a110000 pid=4490 execve guuid=65be4ad7-1900-0000-6782-45138e110000 pid=4494 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=65be4ad7-1900-0000-6782-45138e110000 pid=4494 execve guuid=b40ba9d7-1900-0000-6782-451390110000 pid=4496 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b40ba9d7-1900-0000-6782-451390110000 pid=4496 execve guuid=ea9213d8-1900-0000-6782-451395110000 pid=4501 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=ea9213d8-1900-0000-6782-451395110000 pid=4501 execve guuid=1988afd8-1900-0000-6782-451399110000 pid=4505 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1988afd8-1900-0000-6782-451399110000 pid=4505 execve guuid=861927d9-1900-0000-6782-45139c110000 pid=4508 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=861927d9-1900-0000-6782-45139c110000 pid=4508 execve guuid=0cbc96d9-1900-0000-6782-45139e110000 pid=4510 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0cbc96d9-1900-0000-6782-45139e110000 pid=4510 execve guuid=86c6f7d9-1900-0000-6782-4513a1110000 pid=4513 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=86c6f7d9-1900-0000-6782-4513a1110000 pid=4513 execve guuid=0f6076da-1900-0000-6782-4513a3110000 pid=4515 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0f6076da-1900-0000-6782-4513a3110000 pid=4515 execve guuid=0c40d9da-1900-0000-6782-4513a5110000 pid=4517 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0c40d9da-1900-0000-6782-4513a5110000 pid=4517 execve guuid=eeb436db-1900-0000-6782-4513a7110000 pid=4519 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=eeb436db-1900-0000-6782-4513a7110000 pid=4519 execve guuid=9102a2db-1900-0000-6782-4513aa110000 pid=4522 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=9102a2db-1900-0000-6782-4513aa110000 pid=4522 execve guuid=9d220cdc-1900-0000-6782-4513ab110000 pid=4523 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=9d220cdc-1900-0000-6782-4513ab110000 pid=4523 execve guuid=dd9e66dc-1900-0000-6782-4513ad110000 pid=4525 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=dd9e66dc-1900-0000-6782-4513ad110000 pid=4525 execve guuid=6981d1dc-1900-0000-6782-4513af110000 pid=4527 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=6981d1dc-1900-0000-6782-4513af110000 pid=4527 execve guuid=3dc83fdd-1900-0000-6782-4513b4110000 pid=4532 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3dc83fdd-1900-0000-6782-4513b4110000 pid=4532 execve guuid=f5b513de-1900-0000-6782-4513b6110000 pid=4534 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=f5b513de-1900-0000-6782-4513b6110000 pid=4534 execve guuid=ce6892de-1900-0000-6782-4513ba110000 pid=4538 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=ce6892de-1900-0000-6782-4513ba110000 pid=4538 execve guuid=3d19ffde-1900-0000-6782-4513bb110000 pid=4539 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3d19ffde-1900-0000-6782-4513bb110000 pid=4539 execve guuid=70ef70df-1900-0000-6782-4513bc110000 pid=4540 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=70ef70df-1900-0000-6782-4513bc110000 pid=4540 execve guuid=b66edadf-1900-0000-6782-4513bf110000 pid=4543 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b66edadf-1900-0000-6782-4513bf110000 pid=4543 execve guuid=1f979fe0-1900-0000-6782-4513c1110000 pid=4545 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1f979fe0-1900-0000-6782-4513c1110000 pid=4545 execve guuid=0ab2fee0-1900-0000-6782-4513c4110000 pid=4548 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0ab2fee0-1900-0000-6782-4513c4110000 pid=4548 execve guuid=2eee5de1-1900-0000-6782-4513c6110000 pid=4550 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=2eee5de1-1900-0000-6782-4513c6110000 pid=4550 execve guuid=c6b4bbe1-1900-0000-6782-4513c7110000 pid=4551 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=c6b4bbe1-1900-0000-6782-4513c7110000 pid=4551 execve guuid=27231fe2-1900-0000-6782-4513c9110000 pid=4553 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=27231fe2-1900-0000-6782-4513c9110000 pid=4553 execve guuid=588b80e2-1900-0000-6782-4513ca110000 pid=4554 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=588b80e2-1900-0000-6782-4513ca110000 pid=4554 execve guuid=a73adee2-1900-0000-6782-4513cc110000 pid=4556 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=a73adee2-1900-0000-6782-4513cc110000 pid=4556 execve guuid=87c848e3-1900-0000-6782-4513d1110000 pid=4561 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=87c848e3-1900-0000-6782-4513d1110000 pid=4561 execve guuid=b60dc8e3-1900-0000-6782-4513d2110000 pid=4562 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b60dc8e3-1900-0000-6782-4513d2110000 pid=4562 execve guuid=6aa336e4-1900-0000-6782-4513d3110000 pid=4563 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=6aa336e4-1900-0000-6782-4513d3110000 pid=4563 execve guuid=7be295e4-1900-0000-6782-4513d4110000 pid=4564 /usr/bin/ls guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=7be295e4-1900-0000-6782-4513d4110000 pid=4564 execve guuid=1133f0e4-1900-0000-6782-4513d6110000 pid=4566 /usr/bin/rm guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1133f0e4-1900-0000-6782-4513d6110000 pid=4566 execve guuid=b81d30e5-1900-0000-6782-4513d8110000 pid=4568 /usr/bin/wget net send-data write-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b81d30e5-1900-0000-6782-4513d8110000 pid=4568 execve guuid=31fef2fd-1900-0000-6782-451338120000 pid=4664 /usr/bin/chmod guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=31fef2fd-1900-0000-6782-451338120000 pid=4664 execve guuid=fd4043fe-1900-0000-6782-45133a120000 pid=4666 /usr/bin/dash guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=fd4043fe-1900-0000-6782-45133a120000 pid=4666 clone guuid=31f4e8fe-1900-0000-6782-451340120000 pid=4672 /usr/bin/rm guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=31f4e8fe-1900-0000-6782-451340120000 pid=4672 execve guuid=3a763fff-1900-0000-6782-451341120000 pid=4673 /usr/bin/wget net send-data write-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3a763fff-1900-0000-6782-451341120000 pid=4673 execve guuid=b2a4ef19-1a00-0000-6782-451395120000 pid=4757 /usr/bin/chmod guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b2a4ef19-1a00-0000-6782-451395120000 pid=4757 execve guuid=d0803a1a-1a00-0000-6782-451397120000 pid=4759 /usr/bin/dash guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=d0803a1a-1a00-0000-6782-451397120000 pid=4759 clone guuid=eb50e81b-1a00-0000-6782-45139e120000 pid=4766 /usr/bin/rm guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=eb50e81b-1a00-0000-6782-45139e120000 pid=4766 execve guuid=e504231c-1a00-0000-6782-45139f120000 pid=4767 /usr/bin/wget net send-data write-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=e504231c-1a00-0000-6782-45139f120000 pid=4767 execve guuid=1bd1e44f-1a00-0000-6782-4513d5120000 pid=4821 /usr/bin/chmod guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1bd1e44f-1a00-0000-6782-4513d5120000 pid=4821 execve guuid=0b655850-1a00-0000-6782-4513d6120000 pid=4822 /usr/bin/dash guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=0b655850-1a00-0000-6782-4513d6120000 pid=4822 clone guuid=3a115b52-1a00-0000-6782-4513dc120000 pid=4828 /usr/bin/rm guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3a115b52-1a00-0000-6782-4513dc120000 pid=4828 execve guuid=336dc852-1a00-0000-6782-4513de120000 pid=4830 /usr/bin/wget net send-data write-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=336dc852-1a00-0000-6782-4513de120000 pid=4830 execve guuid=b4b56972-1a00-0000-6782-45131e130000 pid=4894 /usr/bin/chmod guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b4b56972-1a00-0000-6782-45131e130000 pid=4894 execve guuid=3e5ed472-1a00-0000-6782-451320130000 pid=4896 /usr/bin/dash guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=3e5ed472-1a00-0000-6782-451320130000 pid=4896 clone guuid=1355ad73-1a00-0000-6782-451323130000 pid=4899 /usr/bin/rm guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=1355ad73-1a00-0000-6782-451323130000 pid=4899 execve guuid=d234f873-1a00-0000-6782-451325130000 pid=4901 /usr/bin/wget net send-data write-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=d234f873-1a00-0000-6782-451325130000 pid=4901 execve guuid=b643ae95-1a00-0000-6782-451373130000 pid=4979 /usr/bin/chmod guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b643ae95-1a00-0000-6782-451373130000 pid=4979 execve guuid=b547ed95-1a00-0000-6782-451375130000 pid=4981 /usr/bin/dash guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=b547ed95-1a00-0000-6782-451375130000 pid=4981 clone guuid=5a60a997-1a00-0000-6782-45137c130000 pid=4988 /usr/bin/rm delete-file guuid=6f7f01b0-1900-0000-6782-451396100000 pid=4246->guuid=5a60a997-1a00-0000-6782-45137c130000 pid=4988 execve 801186e6-5fe8-5959-a7b4-832d8d66e7aa 129.121.114.124:80 guuid=b81d30e5-1900-0000-6782-4513d8110000 pid=4568->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=3a763fff-1900-0000-6782-451341120000 pid=4673->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=e504231c-1a00-0000-6782-45139f120000 pid=4767->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B guuid=336dc852-1a00-0000-6782-4513de120000 pid=4830->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 134B guuid=d234f873-1a00-0000-6782-451325130000 pid=4901->801186e6-5fe8-5959-a7b4-832d8d66e7aa send: 133B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
Reads runtime system information
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh df709c844a5be6aeaeaa6a585e73e2706883e170ee3880e923d4147db2d5596a

(this sample)

  
Delivery method
Distributed via web download

Comments