MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e4374bfdcc87adbb1948c4d94c7a5cd37a4041e0d82a93eb69a0d72b75093bb2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: e4374bfdcc87adbb1948c4d94c7a5cd37a4041e0d82a93eb69a0d72b75093bb2
SHA3-384 hash: 0e8054e76a399b280c931b495a7e5c7505e5729b0670fba9b887a0c9a70c3ad8b5e8fa4fcb921c11f3fc690bb4a3eb90
SHA1 hash: ac545697e41b1fca094c23eaec62fe034b9ea592
MD5 hash: c100bdb1224091875f790a52363fe0a7
humanhash: east-william-bakerloo-saturn
File name:run.sh
Download: download sample
Signature Mirai
File size:1'665 bytes
First seen:2026-02-16 04:20:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:1z5TGNIWxIK5GhGXFHIHvcFoRikBjSuF7THy:RxQikFoRBguU
TLSH T1653147D631303EDAC351CE9DFB70C8084EEE80E7ED5B279AD75B075D888920E3949A61
Magika shell
Reporter adliwahid
URLMalware sample (SHA256 hash)SignatureTags
http://87.106.146.195/bins/narm373a50f9d62f471cfb23b05a3ab79cbc345255c1e9a91846d7ad9a26d9d8f2c1 Miraimirai
http://87.106.146.195/bins/narm5ff884b18295b7250a7f0b09d235839cc3c8a3e80355f3d19dbe72965d62796bd Miraimirai
http://87.106.146.195/bins/narm692108a42515284c8a5225e35d8d5be2fc77e56e58c45a6c217d80e70a6cd098d Miraimirai
http://87.106.146.195/bins/narm7f039d8d34cf6d07cd8c9dac16e7d886691a08c7ae2a75483487df9f061108ab5 Miraimirai
http://87.106.146.195/bins/nm68kc2b548e96d92872e073db11c2098e3b369d261aa23225e4eb4316423e90442b7 Miraimirai
http://87.106.146.195/bins/nmipsbf663d0a11eaf9ba7c676d2de4724eabc26c6ea47ee389935412deaed20f26ea Miraimirai
http://87.106.146.195/bins/nmpsl76f9c5aa8dab0c57211b0d51ecd0306606a852bcdefaeb08ce3245b5f3384b13 Miraimirai
http://87.106.146.195/bins/nppc45bb4a5b31189d1cad986509739acfb6d25ba1e212a9efa2e3a429d9d8d495ad Miraimirai
http://87.106.146.195/bins/nppc440495058786666d3baa811c488a19fb88be607a9d9cdcbe8a7223c2e4b75a3f4b1 Miraimirai
http://87.106.146.195/bins/nsh409b11dffefc60d5aeff9f8abee9a95aa5682731ae098e7cc32a856c0c5239104 Miraimirai
http://87.106.146.195/bins/nx486b2feaaf1ca43452cbb5aa24d6100cffaa704b6ec196e2f35e528c034308d05e9 Miraimirai
http://87.106.146.195/bins/nx6860086b623fe36ab4a7b6ef1f8a3bd7d6a88a99a24169ffc1037d8b3399ee05d85 Miraimirai
http://87.106.146.195/bins/nx86d7bdee44442f5548ff81564d4df5f84efcf7b57e19a0557c97b9c29afcc4946d Miraimirai
http://87.106.146.195/bins/nx86_64fa7ce9e3232f1d0b8c990220bc40e65ba4d26a3bceadc648964cbdc15ad3fa06 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f5f1fe20-1700-0000-5d9a-aee36b0e0000 pid=3691 /usr/bin/sudo guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702 /tmp/sample.bin guuid=f5f1fe20-1700-0000-5d9a-aee36b0e0000 pid=3691->guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702 execve guuid=3424a323-1700-0000-5d9a-aee3770e0000 pid=3703 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=3424a323-1700-0000-5d9a-aee3770e0000 pid=3703 execve guuid=983b3d2d-1700-0000-5d9a-aee39c0e0000 pid=3740 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=983b3d2d-1700-0000-5d9a-aee39c0e0000 pid=3740 execve guuid=682d5838-1700-0000-5d9a-aee3ce0e0000 pid=3790 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=682d5838-1700-0000-5d9a-aee3ce0e0000 pid=3790 execve guuid=e51a9638-1700-0000-5d9a-aee3d00e0000 pid=3792 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e51a9638-1700-0000-5d9a-aee3d00e0000 pid=3792 clone guuid=6ac62239-1700-0000-5d9a-aee3d50e0000 pid=3797 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=6ac62239-1700-0000-5d9a-aee3d50e0000 pid=3797 execve guuid=744a6539-1700-0000-5d9a-aee3d80e0000 pid=3800 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=744a6539-1700-0000-5d9a-aee3d80e0000 pid=3800 execve guuid=7065c940-1700-0000-5d9a-aee3ed0e0000 pid=3821 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=7065c940-1700-0000-5d9a-aee3ed0e0000 pid=3821 execve guuid=b11fd549-1700-0000-5d9a-aee3ef0e0000 pid=3823 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=b11fd549-1700-0000-5d9a-aee3ef0e0000 pid=3823 execve guuid=98703d4a-1700-0000-5d9a-aee3f10e0000 pid=3825 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=98703d4a-1700-0000-5d9a-aee3f10e0000 pid=3825 clone guuid=6d6d244b-1700-0000-5d9a-aee3f40e0000 pid=3828 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=6d6d244b-1700-0000-5d9a-aee3f40e0000 pid=3828 execve guuid=c2279c4b-1700-0000-5d9a-aee3f60e0000 pid=3830 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=c2279c4b-1700-0000-5d9a-aee3f60e0000 pid=3830 execve guuid=08016053-1700-0000-5d9a-aee30c0f0000 pid=3852 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=08016053-1700-0000-5d9a-aee30c0f0000 pid=3852 execve guuid=e9575a5b-1700-0000-5d9a-aee32e0f0000 pid=3886 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e9575a5b-1700-0000-5d9a-aee32e0f0000 pid=3886 execve guuid=56428c5b-1700-0000-5d9a-aee3300f0000 pid=3888 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=56428c5b-1700-0000-5d9a-aee3300f0000 pid=3888 clone guuid=ac69075c-1700-0000-5d9a-aee3340f0000 pid=3892 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=ac69075c-1700-0000-5d9a-aee3340f0000 pid=3892 execve guuid=9aef3d5c-1700-0000-5d9a-aee3360f0000 pid=3894 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=9aef3d5c-1700-0000-5d9a-aee3360f0000 pid=3894 execve guuid=517a3d62-1700-0000-5d9a-aee34f0f0000 pid=3919 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=517a3d62-1700-0000-5d9a-aee34f0f0000 pid=3919 execve guuid=32681b69-1700-0000-5d9a-aee36d0f0000 pid=3949 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=32681b69-1700-0000-5d9a-aee36d0f0000 pid=3949 execve guuid=c4786f69-1700-0000-5d9a-aee36f0f0000 pid=3951 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=c4786f69-1700-0000-5d9a-aee36f0f0000 pid=3951 clone guuid=f1e5246a-1700-0000-5d9a-aee3740f0000 pid=3956 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=f1e5246a-1700-0000-5d9a-aee3740f0000 pid=3956 execve guuid=e131836a-1700-0000-5d9a-aee3760f0000 pid=3958 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e131836a-1700-0000-5d9a-aee3760f0000 pid=3958 execve guuid=f5120972-1700-0000-5d9a-aee39a0f0000 pid=3994 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=f5120972-1700-0000-5d9a-aee39a0f0000 pid=3994 execve guuid=a151137a-1700-0000-5d9a-aee3bf0f0000 pid=4031 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=a151137a-1700-0000-5d9a-aee3bf0f0000 pid=4031 execve guuid=2f75587a-1700-0000-5d9a-aee3c10f0000 pid=4033 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=2f75587a-1700-0000-5d9a-aee3c10f0000 pid=4033 clone guuid=96fdde7a-1700-0000-5d9a-aee3c50f0000 pid=4037 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=96fdde7a-1700-0000-5d9a-aee3c50f0000 pid=4037 execve guuid=e9a5227b-1700-0000-5d9a-aee3c70f0000 pid=4039 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e9a5227b-1700-0000-5d9a-aee3c70f0000 pid=4039 execve guuid=927fbc83-1700-0000-5d9a-aee3e80f0000 pid=4072 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=927fbc83-1700-0000-5d9a-aee3e80f0000 pid=4072 execve guuid=37e4978c-1700-0000-5d9a-aee308100000 pid=4104 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=37e4978c-1700-0000-5d9a-aee308100000 pid=4104 execve guuid=32c5e08c-1700-0000-5d9a-aee309100000 pid=4105 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=32c5e08c-1700-0000-5d9a-aee309100000 pid=4105 clone guuid=96bc7c8d-1700-0000-5d9a-aee30f100000 pid=4111 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=96bc7c8d-1700-0000-5d9a-aee30f100000 pid=4111 execve guuid=ce34ea8d-1700-0000-5d9a-aee313100000 pid=4115 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=ce34ea8d-1700-0000-5d9a-aee313100000 pid=4115 execve guuid=520b9d96-1700-0000-5d9a-aee32b100000 pid=4139 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=520b9d96-1700-0000-5d9a-aee32b100000 pid=4139 execve guuid=3a00a0a0-1700-0000-5d9a-aee34f100000 pid=4175 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=3a00a0a0-1700-0000-5d9a-aee34f100000 pid=4175 execve guuid=dfa615a1-1700-0000-5d9a-aee351100000 pid=4177 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=dfa615a1-1700-0000-5d9a-aee351100000 pid=4177 clone guuid=8345fea1-1700-0000-5d9a-aee357100000 pid=4183 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=8345fea1-1700-0000-5d9a-aee357100000 pid=4183 execve guuid=1bfb70a2-1700-0000-5d9a-aee35a100000 pid=4186 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=1bfb70a2-1700-0000-5d9a-aee35a100000 pid=4186 execve guuid=e66351aa-1700-0000-5d9a-aee374100000 pid=4212 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e66351aa-1700-0000-5d9a-aee374100000 pid=4212 execve guuid=e6b150b3-1700-0000-5d9a-aee398100000 pid=4248 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=e6b150b3-1700-0000-5d9a-aee398100000 pid=4248 execve guuid=0e6d93b3-1700-0000-5d9a-aee399100000 pid=4249 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=0e6d93b3-1700-0000-5d9a-aee399100000 pid=4249 clone guuid=84621cb4-1700-0000-5d9a-aee39d100000 pid=4253 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=84621cb4-1700-0000-5d9a-aee39d100000 pid=4253 execve guuid=138b57b4-1700-0000-5d9a-aee39f100000 pid=4255 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=138b57b4-1700-0000-5d9a-aee39f100000 pid=4255 execve guuid=2b1892bb-1700-0000-5d9a-aee3bf100000 pid=4287 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=2b1892bb-1700-0000-5d9a-aee3bf100000 pid=4287 execve guuid=b4df63c4-1700-0000-5d9a-aee3db100000 pid=4315 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=b4df63c4-1700-0000-5d9a-aee3db100000 pid=4315 execve guuid=9b68cdc4-1700-0000-5d9a-aee3dc100000 pid=4316 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=9b68cdc4-1700-0000-5d9a-aee3dc100000 pid=4316 clone guuid=184577c5-1700-0000-5d9a-aee3e0100000 pid=4320 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=184577c5-1700-0000-5d9a-aee3e0100000 pid=4320 execve guuid=2cc3d2c5-1700-0000-5d9a-aee3e2100000 pid=4322 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=2cc3d2c5-1700-0000-5d9a-aee3e2100000 pid=4322 execve guuid=39e1c6ce-1700-0000-5d9a-aee3fc100000 pid=4348 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=39e1c6ce-1700-0000-5d9a-aee3fc100000 pid=4348 execve guuid=84aa4bd7-1700-0000-5d9a-aee315110000 pid=4373 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=84aa4bd7-1700-0000-5d9a-aee315110000 pid=4373 execve guuid=c615ccd7-1700-0000-5d9a-aee316110000 pid=4374 /usr/bin/dash guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=c615ccd7-1700-0000-5d9a-aee316110000 pid=4374 clone guuid=3c78bcd8-1700-0000-5d9a-aee31b110000 pid=4379 /usr/bin/rm delete-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=3c78bcd8-1700-0000-5d9a-aee31b110000 pid=4379 execve guuid=730a1bd9-1700-0000-5d9a-aee31e110000 pid=4382 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=730a1bd9-1700-0000-5d9a-aee31e110000 pid=4382 execve guuid=9de659df-1700-0000-5d9a-aee332110000 pid=4402 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=9de659df-1700-0000-5d9a-aee332110000 pid=4402 execve guuid=57fe18e8-1700-0000-5d9a-aee34f110000 pid=4431 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=57fe18e8-1700-0000-5d9a-aee34f110000 pid=4431 execve guuid=f95c89e8-1700-0000-5d9a-aee353110000 pid=4435 /home/sandbox/nx486 net guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=f95c89e8-1700-0000-5d9a-aee353110000 pid=4435 execve guuid=581bc4e8-1700-0000-5d9a-aee358110000 pid=4440 /usr/bin/rm guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=581bc4e8-1700-0000-5d9a-aee358110000 pid=4440 execve guuid=3fdf06e9-1700-0000-5d9a-aee359110000 pid=4441 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=3fdf06e9-1700-0000-5d9a-aee359110000 pid=4441 execve guuid=0426aef0-1700-0000-5d9a-aee372110000 pid=4466 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=0426aef0-1700-0000-5d9a-aee372110000 pid=4466 execve guuid=912cfef8-1700-0000-5d9a-aee38c110000 pid=4492 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=912cfef8-1700-0000-5d9a-aee38c110000 pid=4492 execve guuid=082a76f9-1700-0000-5d9a-aee390110000 pid=4496 /home/sandbox/nx686 net guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=082a76f9-1700-0000-5d9a-aee390110000 pid=4496 execve guuid=48dd4028-1900-0000-5d9a-aee3a1140000 pid=5281 /usr/bin/rm guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=48dd4028-1900-0000-5d9a-aee3a1140000 pid=5281 execve guuid=9344d128-1900-0000-5d9a-aee3a2140000 pid=5282 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=9344d128-1900-0000-5d9a-aee3a2140000 pid=5282 execve guuid=33170933-1900-0000-5d9a-aee3a6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=33170933-1900-0000-5d9a-aee3a6140000 pid=5286 execve guuid=3928583d-1900-0000-5d9a-aee3af140000 pid=5295 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=3928583d-1900-0000-5d9a-aee3af140000 pid=5295 execve guuid=a155973d-1900-0000-5d9a-aee3b0140000 pid=5296 /home/sandbox/nx86 net guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=a155973d-1900-0000-5d9a-aee3b0140000 pid=5296 execve guuid=f1b10070-1a00-0000-5d9a-aee3b9140000 pid=5305 /usr/bin/rm guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=f1b10070-1a00-0000-5d9a-aee3b9140000 pid=5305 execve guuid=787b4e70-1a00-0000-5d9a-aee3ba140000 pid=5306 /usr/bin/wget net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=787b4e70-1a00-0000-5d9a-aee3ba140000 pid=5306 execve guuid=6863fa91-1a00-0000-5d9a-aee3bb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=6863fa91-1a00-0000-5d9a-aee3bb140000 pid=5307 execve guuid=aa24c19b-1a00-0000-5d9a-aee3bc140000 pid=5308 /usr/bin/chmod guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=aa24c19b-1a00-0000-5d9a-aee3bc140000 pid=5308 execve guuid=6e8f019c-1a00-0000-5d9a-aee3bd140000 pid=5309 /home/sandbox/nx86_64 net guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=6e8f019c-1a00-0000-5d9a-aee3bd140000 pid=5309 execve guuid=1da53fc7-1b00-0000-5d9a-aee3df140000 pid=5343 /usr/bin/rm guuid=14825d23-1700-0000-5d9a-aee3760e0000 pid=3702->guuid=1da53fc7-1b00-0000-5d9a-aee3df140000 pid=5343 execve 0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e 87.106.146.195:80 guuid=3424a323-1700-0000-5d9a-aee3770e0000 pid=3703->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 138B guuid=983b3d2d-1700-0000-5d9a-aee39c0e0000 pid=3740->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 87B guuid=744a6539-1700-0000-5d9a-aee3d80e0000 pid=3800->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=7065c940-1700-0000-5d9a-aee3ed0e0000 pid=3821->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=c2279c4b-1700-0000-5d9a-aee3f60e0000 pid=3830->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=08016053-1700-0000-5d9a-aee30c0f0000 pid=3852->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=9aef3d5c-1700-0000-5d9a-aee3360f0000 pid=3894->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=517a3d62-1700-0000-5d9a-aee34f0f0000 pid=3919->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=e131836a-1700-0000-5d9a-aee3760f0000 pid=3958->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=f5120972-1700-0000-5d9a-aee39a0f0000 pid=3994->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=e9a5227b-1700-0000-5d9a-aee3c70f0000 pid=4039->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=927fbc83-1700-0000-5d9a-aee3e80f0000 pid=4072->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=ce34ea8d-1700-0000-5d9a-aee313100000 pid=4115->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=520b9d96-1700-0000-5d9a-aee32b100000 pid=4139->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=1bfb70a2-1700-0000-5d9a-aee35a100000 pid=4186->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 138B guuid=e66351aa-1700-0000-5d9a-aee374100000 pid=4212->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 87B guuid=138b57b4-1700-0000-5d9a-aee39f100000 pid=4255->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 141B guuid=2b1892bb-1700-0000-5d9a-aee3bf100000 pid=4287->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 90B guuid=2cc3d2c5-1700-0000-5d9a-aee3e2100000 pid=4322->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 138B guuid=39e1c6ce-1700-0000-5d9a-aee3fc100000 pid=4348->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 87B guuid=730a1bd9-1700-0000-5d9a-aee31e110000 pid=4382->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=9de659df-1700-0000-5d9a-aee332110000 pid=4402->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f95c89e8-1700-0000-5d9a-aee353110000 pid=4435->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2398bde8-1700-0000-5d9a-aee355110000 pid=4437 /home/sandbox/. net send-data zombie guuid=f95c89e8-1700-0000-5d9a-aee353110000 pid=4435->guuid=2398bde8-1700-0000-5d9a-aee355110000 pid=4437 clone 1c83aa22-d411-54c3-a03a-fe8b1093d6ed 87.106.142.201:46852 guuid=2398bde8-1700-0000-5d9a-aee355110000 pid=4437->1c83aa22-d411-54c3-a03a-fe8b1093d6ed send: 23B guuid=3fdf06e9-1700-0000-5d9a-aee359110000 pid=4441->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 139B guuid=0426aef0-1700-0000-5d9a-aee372110000 pid=4466->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 88B guuid=082a76f9-1700-0000-5d9a-aee390110000 pid=4496->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 97497738-7071-57ac-8c74-3f2ec4ae1c6d 0.0.0.0:1234 guuid=082a76f9-1700-0000-5d9a-aee390110000 pid=4496->97497738-7071-57ac-8c74-3f2ec4ae1c6d con guuid=256f3528-1900-0000-5d9a-aee3a0140000 pid=5280 /home/sandbox/. net send-data zombie guuid=082a76f9-1700-0000-5d9a-aee390110000 pid=4496->guuid=256f3528-1900-0000-5d9a-aee3a0140000 pid=5280 clone 6573d971-3bb6-52fe-afc6-93ea55e93d93 87.106.142.201:61543 guuid=256f3528-1900-0000-5d9a-aee3a0140000 pid=5280->6573d971-3bb6-52fe-afc6-93ea55e93d93 send: 23B guuid=9344d128-1900-0000-5d9a-aee3a2140000 pid=5282->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 138B guuid=33170933-1900-0000-5d9a-aee3a6140000 pid=5286->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 87B guuid=a155973d-1900-0000-5d9a-aee3b0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a155973d-1900-0000-5d9a-aee3b0140000 pid=5296->97497738-7071-57ac-8c74-3f2ec4ae1c6d con guuid=1f71f16f-1a00-0000-5d9a-aee3b8140000 pid=5304 /home/sandbox/. net send-data zombie guuid=a155973d-1900-0000-5d9a-aee3b0140000 pid=5296->guuid=1f71f16f-1a00-0000-5d9a-aee3b8140000 pid=5304 clone 3352b7ce-1e83-59c5-bf07-7373d7ae073a 87.106.142.201:23789 guuid=1f71f16f-1a00-0000-5d9a-aee3b8140000 pid=5304->3352b7ce-1e83-59c5-bf07-7373d7ae073a send: 23B guuid=787b4e70-1a00-0000-5d9a-aee3ba140000 pid=5306->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 141B guuid=6863fa91-1a00-0000-5d9a-aee3bb140000 pid=5307->0f0fd3d7-b523-533e-8f1e-f1d2ea3b239e send: 90B guuid=6e8f019c-1a00-0000-5d9a-aee3bd140000 pid=5309->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6e8f019c-1a00-0000-5d9a-aee3bd140000 pid=5309->97497738-7071-57ac-8c74-3f2ec4ae1c6d con guuid=36612cc7-1b00-0000-5d9a-aee3de140000 pid=5342 /home/sandbox/. net send-data zombie guuid=6e8f019c-1a00-0000-5d9a-aee3bd140000 pid=5309->guuid=36612cc7-1b00-0000-5d9a-aee3de140000 pid=5342 clone e78bd063-abd6-5a1d-bc66-5553adbeecb0 87.106.142.201:49376 guuid=36612cc7-1b00-0000-5d9a-aee3de140000 pid=5342->e78bd063-abd6-5a1d-bc66-5553adbeecb0 send: 25B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-02-15 21:30:53 UTC
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh e4374bfdcc87adbb1948c4d94c7a5cd37a4041e0d82a93eb69a0d72b75093bb2

(this sample)

Comments