MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e45e21eafca4ff66e1457fea7ea9975ce46c81015574c246de5ba2cb8e967db4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: e45e21eafca4ff66e1457fea7ea9975ce46c81015574c246de5ba2cb8e967db4
SHA3-384 hash: cd34d39dae268d51fe88b6417dee5484af3c0e585414117e6a16e9493ffa83729a74d3963d274b6b81ec6f580a427b11
SHA1 hash: 656e1c5b8ac6c51d8e18ccb3bd38e0caba345352
MD5 hash: 801525593823fd29a44e4074f6f6efd3
humanhash: pizza-crazy-pasta-eleven
File name:ipcams.sh
Download: download sample
Signature Mirai
File size:4'504 bytes
First seen:2026-03-16 17:23:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZboGEHYFYFWFFFjsBtUoYtzEFt4t+t+t0t0t0LtIFYFWFFFptitgt5sPpoUxE7fO:ZbNEHuZnEpiu9Eq4s1
TLSH T1969117CC7021842758C68E4CA46AD3A753D893A5D99CC01C55A8FE3B3192FFA78FAF01
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://88.214.20.14/bins/tuxnokill.x86a9c595b2c94cbcd3c93fdc72705b502080848f45f41a4142ad77c5a5f4326b0b Miraimirai
http://88.214.20.14/bins/tuxnokill.mips3b7d02c7d5fae025badfbb801059183029189d85d00aac04311247e4f5f4030a Miraimirai
http://88.214.20.14/bins/tuxnokill.mpsl234f547c6940b136c16b743950b1b503fffb0fa852b123a107b883a2161b8e5f Miraimirai
http://88.214.20.14/bins/tuxnokill.arm409c149979a739286e87e55f730410fbc14fe39a2685135b21f7cf6f51bcf466 Miraimirai
http://88.214.20.14/bins/tuxnokill.arc557a7680cac8a83c98f5059b6c11dda33df085e931a53817685ad6427645a3c9 Miraimirai
http://88.214.20.14/bins/tuxnokill.arm4n/an/aelf ua-wget
http://88.214.20.14/bins/tuxnokill.arm595d0933e9e2906f5f5df011e5afd2e04161dbac4d4618e0b2ebcee54e91bff5d Miraimirai
http://88.214.20.14/bins/tuxnokill.arm6501776d5ac80fb72e7c11ce98e4b1cfb16615d76293166a864ba05a62e7f4ff3 Miraimirai
http://88.214.20.14/bins/tuxnokill.arm7c6535cc21940b7be719621fd9b791ddbc33d9be9b4ac050a23d8542c82cae9d6 Miraimirai
http://88.214.20.14/bins/tuxnokill.ppc8cff96f1e570b6eae7b433cebaffc9a6d6a32f6927271ed2e5c3e3866f35ef6c Miraimirai
http://88.214.20.14/bins/tuxnokill.m68ka065f1dd35f3bf8f2dc8b25a09273b751fee7a4dba6623b41be874bf42aa5185 Miraimirai
http://88.214.20.14/bins/tuxnokill.sh4ddba21e124054e17b84c367320b1e9dcbc8354c39895b6f1eca489841e8eade0 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
78
Origin country :
CZ CZ
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=1312ae9a-1900-0000-c14f-e8f6e7070000 pid=2023 /usr/bin/sudo guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025 /tmp/sample.bin guuid=1312ae9a-1900-0000-c14f-e8f6e7070000 pid=2023->guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025 execve guuid=ce85459d-1900-0000-c14f-e8f6ea070000 pid=2026 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=ce85459d-1900-0000-c14f-e8f6ea070000 pid=2026 execve guuid=71c6cea1-1900-0000-c14f-e8f6f4070000 pid=2036 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=71c6cea1-1900-0000-c14f-e8f6f4070000 pid=2036 execve guuid=089117a2-1900-0000-c14f-e8f6f6070000 pid=2038 /home/sandbox/tuxnokill.x86 net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=089117a2-1900-0000-c14f-e8f6f6070000 pid=2038 execve guuid=d45845a2-1900-0000-c14f-e8f6f8070000 pid=2040 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=d45845a2-1900-0000-c14f-e8f6f8070000 pid=2040 execve guuid=984ee0ab-1900-0000-c14f-e8f602080000 pid=2050 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=984ee0ab-1900-0000-c14f-e8f602080000 pid=2050 execve guuid=33301bac-1900-0000-c14f-e8f604080000 pid=2052 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=33301bac-1900-0000-c14f-e8f604080000 pid=2052 clone guuid=b35ebeac-1900-0000-c14f-e8f608080000 pid=2056 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=b35ebeac-1900-0000-c14f-e8f608080000 pid=2056 execve guuid=bfbfcab1-1900-0000-c14f-e8f611080000 pid=2065 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=bfbfcab1-1900-0000-c14f-e8f611080000 pid=2065 execve guuid=8c881db2-1900-0000-c14f-e8f612080000 pid=2066 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=8c881db2-1900-0000-c14f-e8f612080000 pid=2066 clone guuid=7da1c0b3-1900-0000-c14f-e8f617080000 pid=2071 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=7da1c0b3-1900-0000-c14f-e8f617080000 pid=2071 execve guuid=7a0733b8-1900-0000-c14f-e8f620080000 pid=2080 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=7a0733b8-1900-0000-c14f-e8f620080000 pid=2080 execve guuid=ecef9cb8-1900-0000-c14f-e8f623080000 pid=2083 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=ecef9cb8-1900-0000-c14f-e8f623080000 pid=2083 clone guuid=0cca81b9-1900-0000-c14f-e8f627080000 pid=2087 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=0cca81b9-1900-0000-c14f-e8f627080000 pid=2087 execve guuid=3663d3bd-1900-0000-c14f-e8f62e080000 pid=2094 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=3663d3bd-1900-0000-c14f-e8f62e080000 pid=2094 execve guuid=dd4139be-1900-0000-c14f-e8f630080000 pid=2096 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=dd4139be-1900-0000-c14f-e8f630080000 pid=2096 clone guuid=bb1c37bf-1900-0000-c14f-e8f632080000 pid=2098 /usr/bin/busybox net send-data guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=bb1c37bf-1900-0000-c14f-e8f632080000 pid=2098 execve guuid=ff89d5c1-1900-0000-c14f-e8f637080000 pid=2103 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=ff89d5c1-1900-0000-c14f-e8f637080000 pid=2103 execve guuid=256393c6-1900-0000-c14f-e8f642080000 pid=2114 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=256393c6-1900-0000-c14f-e8f642080000 pid=2114 execve guuid=d4ef3cc7-1900-0000-c14f-e8f644080000 pid=2116 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=d4ef3cc7-1900-0000-c14f-e8f644080000 pid=2116 clone guuid=c78277c9-1900-0000-c14f-e8f64b080000 pid=2123 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=c78277c9-1900-0000-c14f-e8f64b080000 pid=2123 execve guuid=06c5fccd-1900-0000-c14f-e8f654080000 pid=2132 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=06c5fccd-1900-0000-c14f-e8f654080000 pid=2132 execve guuid=e42555ce-1900-0000-c14f-e8f655080000 pid=2133 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=e42555ce-1900-0000-c14f-e8f655080000 pid=2133 clone guuid=475fface-1900-0000-c14f-e8f659080000 pid=2137 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=475fface-1900-0000-c14f-e8f659080000 pid=2137 execve guuid=b80659d4-1900-0000-c14f-e8f663080000 pid=2147 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=b80659d4-1900-0000-c14f-e8f663080000 pid=2147 execve guuid=b1dba8d4-1900-0000-c14f-e8f665080000 pid=2149 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=b1dba8d4-1900-0000-c14f-e8f665080000 pid=2149 clone guuid=fcff1ed6-1900-0000-c14f-e8f668080000 pid=2152 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=fcff1ed6-1900-0000-c14f-e8f668080000 pid=2152 execve guuid=48d0d3da-1900-0000-c14f-e8f672080000 pid=2162 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=48d0d3da-1900-0000-c14f-e8f672080000 pid=2162 execve guuid=748022db-1900-0000-c14f-e8f673080000 pid=2163 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=748022db-1900-0000-c14f-e8f673080000 pid=2163 clone guuid=f8ca2add-1900-0000-c14f-e8f67b080000 pid=2171 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=f8ca2add-1900-0000-c14f-e8f67b080000 pid=2171 execve guuid=3ffdf3e1-1900-0000-c14f-e8f688080000 pid=2184 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=3ffdf3e1-1900-0000-c14f-e8f688080000 pid=2184 execve guuid=6c5e57e2-1900-0000-c14f-e8f689080000 pid=2185 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=6c5e57e2-1900-0000-c14f-e8f689080000 pid=2185 clone guuid=95018ce3-1900-0000-c14f-e8f68e080000 pid=2190 /usr/bin/busybox net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=95018ce3-1900-0000-c14f-e8f68e080000 pid=2190 execve guuid=16b0feed-1900-0000-c14f-e8f6a9080000 pid=2217 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=16b0feed-1900-0000-c14f-e8f6a9080000 pid=2217 execve guuid=859b69ee-1900-0000-c14f-e8f6ab080000 pid=2219 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=859b69ee-1900-0000-c14f-e8f6ab080000 pid=2219 clone guuid=a1c90cef-1900-0000-c14f-e8f6ae080000 pid=2222 /usr/bin/wget guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=a1c90cef-1900-0000-c14f-e8f6ae080000 pid=2222 execve guuid=1bb7e4f1-1900-0000-c14f-e8f6b6080000 pid=2230 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=1bb7e4f1-1900-0000-c14f-e8f6b6080000 pid=2230 execve guuid=c7739bf7-1900-0000-c14f-e8f6c7080000 pid=2247 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=c7739bf7-1900-0000-c14f-e8f6c7080000 pid=2247 execve guuid=d7add9f7-1900-0000-c14f-e8f6c9080000 pid=2249 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=d7add9f7-1900-0000-c14f-e8f6c9080000 pid=2249 clone guuid=89415ff8-1900-0000-c14f-e8f6cc080000 pid=2252 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=89415ff8-1900-0000-c14f-e8f6cc080000 pid=2252 execve guuid=db9aedfd-1900-0000-c14f-e8f6dd080000 pid=2269 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=db9aedfd-1900-0000-c14f-e8f6dd080000 pid=2269 execve guuid=7dc64bfe-1900-0000-c14f-e8f6df080000 pid=2271 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=7dc64bfe-1900-0000-c14f-e8f6df080000 pid=2271 clone guuid=00120c00-1a00-0000-c14f-e8f6e6080000 pid=2278 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=00120c00-1a00-0000-c14f-e8f6e6080000 pid=2278 execve guuid=51bfc805-1a00-0000-c14f-e8f6f6080000 pid=2294 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=51bfc805-1a00-0000-c14f-e8f6f6080000 pid=2294 execve guuid=9aaa1006-1a00-0000-c14f-e8f6f8080000 pid=2296 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=9aaa1006-1a00-0000-c14f-e8f6f8080000 pid=2296 clone guuid=611c6207-1a00-0000-c14f-e8f6fe080000 pid=2302 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=611c6207-1a00-0000-c14f-e8f6fe080000 pid=2302 execve guuid=1013820c-1a00-0000-c14f-e8f60a090000 pid=2314 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=1013820c-1a00-0000-c14f-e8f60a090000 pid=2314 execve guuid=f73ac80c-1a00-0000-c14f-e8f60c090000 pid=2316 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=f73ac80c-1a00-0000-c14f-e8f60c090000 pid=2316 clone guuid=a00f530d-1a00-0000-c14f-e8f610090000 pid=2320 /usr/bin/wget net send-data guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=a00f530d-1a00-0000-c14f-e8f610090000 pid=2320 execve guuid=6c16f510-1a00-0000-c14f-e8f614090000 pid=2324 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=6c16f510-1a00-0000-c14f-e8f614090000 pid=2324 execve guuid=e8250f16-1a00-0000-c14f-e8f616090000 pid=2326 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=e8250f16-1a00-0000-c14f-e8f616090000 pid=2326 execve guuid=6fe87916-1a00-0000-c14f-e8f618090000 pid=2328 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=6fe87916-1a00-0000-c14f-e8f618090000 pid=2328 clone guuid=bb718d18-1a00-0000-c14f-e8f61e090000 pid=2334 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=bb718d18-1a00-0000-c14f-e8f61e090000 pid=2334 execve guuid=d87f171e-1a00-0000-c14f-e8f629090000 pid=2345 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=d87f171e-1a00-0000-c14f-e8f629090000 pid=2345 execve guuid=6aa77627-1a00-0000-c14f-e8f630090000 pid=2352 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=6aa77627-1a00-0000-c14f-e8f630090000 pid=2352 clone guuid=e416f928-1a00-0000-c14f-e8f632090000 pid=2354 /usr/bin/wget net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=e416f928-1a00-0000-c14f-e8f632090000 pid=2354 execve guuid=7796432c-1a00-0000-c14f-e8f634090000 pid=2356 /usr/bin/wget net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=7796432c-1a00-0000-c14f-e8f634090000 pid=2356 execve guuid=152c902d-1a00-0000-c14f-e8f635090000 pid=2357 /usr/bin/wget net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=152c902d-1a00-0000-c14f-e8f635090000 pid=2357 execve guuid=2627c52e-1a00-0000-c14f-e8f637090000 pid=2359 /usr/bin/wget net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=2627c52e-1a00-0000-c14f-e8f637090000 pid=2359 execve guuid=b1020634-1a00-0000-c14f-e8f642090000 pid=2370 /usr/bin/chmod guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=b1020634-1a00-0000-c14f-e8f642090000 pid=2370 execve guuid=77189534-1a00-0000-c14f-e8f643090000 pid=2371 /usr/bin/dash guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=77189534-1a00-0000-c14f-e8f643090000 pid=2371 clone guuid=ef0b7535-1a00-0000-c14f-e8f646090000 pid=2374 /usr/bin/curl net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=ef0b7535-1a00-0000-c14f-e8f646090000 pid=2374 execve guuid=655cd33f-1a00-0000-c14f-e8f65c090000 pid=2396 /usr/bin/curl net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=655cd33f-1a00-0000-c14f-e8f65c090000 pid=2396 execve guuid=5127f746-1a00-0000-c14f-e8f666090000 pid=2406 /usr/bin/curl net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=5127f746-1a00-0000-c14f-e8f666090000 pid=2406 execve guuid=6619875c-1a00-0000-c14f-e8f667090000 pid=2407 /usr/bin/curl net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=6619875c-1a00-0000-c14f-e8f667090000 pid=2407 execve guuid=9ff78964-1a00-0000-c14f-e8f677090000 pid=2423 /usr/bin/curl net send-data write-file guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=9ff78964-1a00-0000-c14f-e8f677090000 pid=2423 execve guuid=dcd8156b-1a00-0000-c14f-e8f684090000 pid=2436 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=dcd8156b-1a00-0000-c14f-e8f684090000 pid=2436 execve guuid=d949b36d-1a00-0000-c14f-e8f68e090000 pid=2446 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=d949b36d-1a00-0000-c14f-e8f68e090000 pid=2446 execve guuid=c6faff71-1a00-0000-c14f-e8f694090000 pid=2452 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=c6faff71-1a00-0000-c14f-e8f694090000 pid=2452 execve guuid=04fb0477-1a00-0000-c14f-e8f69f090000 pid=2463 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=04fb0477-1a00-0000-c14f-e8f69f090000 pid=2463 execve guuid=602f8479-1a00-0000-c14f-e8f6a6090000 pid=2470 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=602f8479-1a00-0000-c14f-e8f6a6090000 pid=2470 execve guuid=a75b187e-1a00-0000-c14f-e8f6b3090000 pid=2483 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=a75b187e-1a00-0000-c14f-e8f6b3090000 pid=2483 execve guuid=0b247980-1a00-0000-c14f-e8f6b7090000 pid=2487 /usr/bin/curl net guuid=d5dcf89c-1900-0000-c14f-e8f6e9070000 pid=2025->guuid=0b247980-1a00-0000-c14f-e8f6b7090000 pid=2487 execve 07e21ec3-fc3f-5553-b548-91445caa8634 88.214.20.14:80 guuid=ce85459d-1900-0000-c14f-e8f6ea070000 pid=2026->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=089117a2-1900-0000-c14f-e8f6f6070000 pid=2038->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039 /home/sandbox/tuxnokill.x86 net send-data zombie guuid=089117a2-1900-0000-c14f-e8f6f6070000 pid=2038->guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039 clone guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5ce35052-8cf1-5e61-9192-ecdca327d1ce 64.89.161.130:44300 guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039->5ce35052-8cf1-5e61-9192-ecdca327d1ce send: 15B guuid=bb6b51a2-1900-0000-c14f-e8f6f9070000 pid=2041 /home/sandbox/tuxnokill.x86 guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039->guuid=bb6b51a2-1900-0000-c14f-e8f6f9070000 pid=2041 clone guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042 /home/sandbox/tuxnokill.x86 net net-scan send-data guuid=ff1838a2-1900-0000-c14f-e8f6f7070000 pid=2039->guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042 clone guuid=d45845a2-1900-0000-c14f-e8f6f8070000 pid=2040->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042|send-data send-data to 4097 IP addresses review logs to see them all guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042->guuid=e9c254a2-1900-0000-c14f-e8f6fa070000 pid=2042|send-data send guuid=b35ebeac-1900-0000-c14f-e8f608080000 pid=2056->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=7da1c0b3-1900-0000-c14f-e8f617080000 pid=2071->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=0cca81b9-1900-0000-c14f-e8f627080000 pid=2087->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=bb1c37bf-1900-0000-c14f-e8f632080000 pid=2098->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=ff89d5c1-1900-0000-c14f-e8f637080000 pid=2103->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=c78277c9-1900-0000-c14f-e8f64b080000 pid=2123->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=475fface-1900-0000-c14f-e8f659080000 pid=2137->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=fcff1ed6-1900-0000-c14f-e8f668080000 pid=2152->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=f8ca2add-1900-0000-c14f-e8f67b080000 pid=2171->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=95018ce3-1900-0000-c14f-e8f68e080000 pid=2190->07e21ec3-fc3f-5553-b548-91445caa8634 send: 93B guuid=1bb7e4f1-1900-0000-c14f-e8f6b6080000 pid=2230->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=89415ff8-1900-0000-c14f-e8f6cc080000 pid=2252->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=00120c00-1a00-0000-c14f-e8f6e6080000 pid=2278->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=611c6207-1a00-0000-c14f-e8f6fe080000 pid=2302->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=a00f530d-1a00-0000-c14f-e8f610090000 pid=2320->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=6c16f510-1a00-0000-c14f-e8f614090000 pid=2324->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=bb718d18-1a00-0000-c14f-e8f61e090000 pid=2334->07e21ec3-fc3f-5553-b548-91445caa8634 send: 146B guuid=e416f928-1a00-0000-c14f-e8f632090000 pid=2354->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=7796432c-1a00-0000-c14f-e8f634090000 pid=2356->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=152c902d-1a00-0000-c14f-e8f635090000 pid=2357->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=2627c52e-1a00-0000-c14f-e8f637090000 pid=2359->07e21ec3-fc3f-5553-b548-91445caa8634 send: 145B guuid=ef0b7535-1a00-0000-c14f-e8f646090000 pid=2374->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=655cd33f-1a00-0000-c14f-e8f65c090000 pid=2396->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=5127f746-1a00-0000-c14f-e8f666090000 pid=2406->07e21ec3-fc3f-5553-b548-91445caa8634 send: 95B guuid=6619875c-1a00-0000-c14f-e8f667090000 pid=2407->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=9ff78964-1a00-0000-c14f-e8f677090000 pid=2423->07e21ec3-fc3f-5553-b548-91445caa8634 send: 94B guuid=dcd8156b-1a00-0000-c14f-e8f684090000 pid=2436->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=d949b36d-1a00-0000-c14f-e8f68e090000 pid=2446->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=c6faff71-1a00-0000-c14f-e8f694090000 pid=2452->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=04fb0477-1a00-0000-c14f-e8f69f090000 pid=2463->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=602f8479-1a00-0000-c14f-e8f6a6090000 pid=2470->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=a75b187e-1a00-0000-c14f-e8f6b3090000 pid=2483->07e21ec3-fc3f-5553-b548-91445caa8634 con guuid=0b247980-1a00-0000-c14f-e8f6b7090000 pid=2487->07e21ec3-fc3f-5553-b548-91445caa8634 con
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (85850) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh e45e21eafca4ff66e1457fea7ea9975ce46c81015574c246de5ba2cb8e967db4

(this sample)

Comments