MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e68fa32bc597f446d92b7f9a3e103acc07bc3f57984ddb21e9535ffa49264d8c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: e68fa32bc597f446d92b7f9a3e103acc07bc3f57984ddb21e9535ffa49264d8c
SHA3-384 hash: 1bda5dc82eddbdf70cb6cc8b70a52ffde8b461c800dc664544e18543abed3d9cbce8af4c5e110ab99f3292892cbe89c6
SHA1 hash: cbaea5a2ce7341a39649e6da64e98648418119e7
MD5 hash: f81b61b83af8df90d72bdbb249948b4f
humanhash: alabama-south-yankee-pluto
File name:cn
Download: download sample
File size:529 bytes
First seen:2026-06-12 09:28:22 UTC
Last seen:2026-06-13 08:40:18 UTC
File type: sh
MIME type:text/plain
ssdeep 12:8VTNXGcm2Xh5PeX91eoXQiNIbMXv5P7XI:8VTFGcjh5PI9hQiNIbWv57I
TLSH T14CF06288FA22B952092CFD1DB67759DEA452C3CC4C0757EE2CC10C3AB058D4CB029A44
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.83.134.26/mipsn/an/aelf mirai ua-wget
http://5.83.134.26/mpsln/an/aelf mirai ua-wget
http://5.83.134.26/arm4cbc569dc1b472d6c8c01c9a50e28a8753289c65a57ba9c79ac79f59d958c6e1b Miraibotnet mirai
http://5.83.134.26/arm5391f08b27458f868bcf38007fa015a229daf3f32de37ea021479956742ae8189 Miraielf mirai ua-wget
http://5.83.134.26/arm6a8ddbb33054073ca1597ecb2ca5d164374d35f0695f1193bcf6131886d39ebda Miraimirai
http://5.83.134.26/arm768e7cfa7ad230f942b6d6e1a634d24becfb6904b87e67b389c98cd1b86710c5b Miraimirai

Intelligence


File Origin
# of uploads :
135
# of downloads :
4
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=6e0598a3-1600-0000-27ad-ec7baa0c0000 pid=3242 /usr/bin/sudo guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243 /tmp/sample.bin guuid=6e0598a3-1600-0000-27ad-ec7baa0c0000 pid=3242->guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243 execve guuid=884c30a6-1600-0000-27ad-ec7bac0c0000 pid=3244 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=884c30a6-1600-0000-27ad-ec7bac0c0000 pid=3244 execve guuid=f7d70cae-1600-0000-27ad-ec7bbf0c0000 pid=3263 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=f7d70cae-1600-0000-27ad-ec7bbf0c0000 pid=3263 execve guuid=d5414eae-1600-0000-27ad-ec7bc00c0000 pid=3264 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=d5414eae-1600-0000-27ad-ec7bc00c0000 pid=3264 clone guuid=2b23e4ae-1600-0000-27ad-ec7bc40c0000 pid=3268 /usr/bin/rm delete-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=2b23e4ae-1600-0000-27ad-ec7bc40c0000 pid=3268 execve guuid=f64041af-1600-0000-27ad-ec7bc50c0000 pid=3269 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=f64041af-1600-0000-27ad-ec7bc50c0000 pid=3269 execve guuid=a62094af-1600-0000-27ad-ec7bc70c0000 pid=3271 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=a62094af-1600-0000-27ad-ec7bc70c0000 pid=3271 execve guuid=9d47a0b5-1600-0000-27ad-ec7bd80c0000 pid=3288 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=9d47a0b5-1600-0000-27ad-ec7bd80c0000 pid=3288 execve guuid=bcc72fb6-1600-0000-27ad-ec7bda0c0000 pid=3290 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=bcc72fb6-1600-0000-27ad-ec7bda0c0000 pid=3290 clone guuid=56cea9b7-1600-0000-27ad-ec7bdf0c0000 pid=3295 /usr/bin/rm delete-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=56cea9b7-1600-0000-27ad-ec7bdf0c0000 pid=3295 execve guuid=2910e3b7-1600-0000-27ad-ec7be10c0000 pid=3297 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=2910e3b7-1600-0000-27ad-ec7be10c0000 pid=3297 execve guuid=ab1818b8-1600-0000-27ad-ec7be30c0000 pid=3299 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=ab1818b8-1600-0000-27ad-ec7be30c0000 pid=3299 execve guuid=2e649fbd-1600-0000-27ad-ec7bef0c0000 pid=3311 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=2e649fbd-1600-0000-27ad-ec7bef0c0000 pid=3311 execve guuid=e49ddabd-1600-0000-27ad-ec7bf10c0000 pid=3313 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=e49ddabd-1600-0000-27ad-ec7bf10c0000 pid=3313 clone guuid=4a1be0bd-1600-0000-27ad-ec7bf20c0000 pid=3314 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=4a1be0bd-1600-0000-27ad-ec7bf20c0000 pid=3314 execve guuid=28de1dbe-1600-0000-27ad-ec7bf30c0000 pid=3315 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=28de1dbe-1600-0000-27ad-ec7bf30c0000 pid=3315 execve guuid=ebe35dbe-1600-0000-27ad-ec7bf50c0000 pid=3317 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=ebe35dbe-1600-0000-27ad-ec7bf50c0000 pid=3317 execve guuid=2559acc4-1600-0000-27ad-ec7b000d0000 pid=3328 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=2559acc4-1600-0000-27ad-ec7b000d0000 pid=3328 execve guuid=9ccc2ec5-1600-0000-27ad-ec7b030d0000 pid=3331 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=9ccc2ec5-1600-0000-27ad-ec7b030d0000 pid=3331 clone guuid=3d7be8c6-1600-0000-27ad-ec7b080d0000 pid=3336 /usr/bin/rm delete-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=3d7be8c6-1600-0000-27ad-ec7b080d0000 pid=3336 execve guuid=ca2a26c7-1600-0000-27ad-ec7b090d0000 pid=3337 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=ca2a26c7-1600-0000-27ad-ec7b090d0000 pid=3337 execve guuid=d75a92c7-1600-0000-27ad-ec7b0a0d0000 pid=3338 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=d75a92c7-1600-0000-27ad-ec7b0a0d0000 pid=3338 execve guuid=8fe445ce-1600-0000-27ad-ec7b0b0d0000 pid=3339 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=8fe445ce-1600-0000-27ad-ec7b0b0d0000 pid=3339 execve guuid=cfddbcce-1600-0000-27ad-ec7b0c0d0000 pid=3340 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=cfddbcce-1600-0000-27ad-ec7b0c0d0000 pid=3340 clone guuid=69f2abcf-1600-0000-27ad-ec7b0e0d0000 pid=3342 /usr/bin/rm delete-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=69f2abcf-1600-0000-27ad-ec7b0e0d0000 pid=3342 execve guuid=ad0445d0-1600-0000-27ad-ec7b100d0000 pid=3344 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=ad0445d0-1600-0000-27ad-ec7b100d0000 pid=3344 execve guuid=d47b90d0-1600-0000-27ad-ec7b110d0000 pid=3345 /usr/bin/wget net send-data write-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=d47b90d0-1600-0000-27ad-ec7b110d0000 pid=3345 execve guuid=b9ceafd7-1600-0000-27ad-ec7b1e0d0000 pid=3358 /usr/bin/chmod guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=b9ceafd7-1600-0000-27ad-ec7b1e0d0000 pid=3358 execve guuid=3450ebd7-1600-0000-27ad-ec7b1f0d0000 pid=3359 /usr/bin/dash guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=3450ebd7-1600-0000-27ad-ec7b1f0d0000 pid=3359 clone guuid=a0a979d9-1600-0000-27ad-ec7b260d0000 pid=3366 /usr/bin/rm delete-file guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=a0a979d9-1600-0000-27ad-ec7b260d0000 pid=3366 execve guuid=38a1b5d9-1600-0000-27ad-ec7b270d0000 pid=3367 /usr/bin/rm guuid=d7b8f4a5-1600-0000-27ad-ec7bab0c0000 pid=3243->guuid=38a1b5d9-1600-0000-27ad-ec7b270d0000 pid=3367 execve 0cc76706-e9e8-53b6-82b1-adadec74dbb6 5.83.134.26:80 guuid=884c30a6-1600-0000-27ad-ec7bac0c0000 pid=3244->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B guuid=a62094af-1600-0000-27ad-ec7bc70c0000 pid=3271->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B guuid=ab1818b8-1600-0000-27ad-ec7be30c0000 pid=3299->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B guuid=ebe35dbe-1600-0000-27ad-ec7bf50c0000 pid=3317->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B guuid=d75a92c7-1600-0000-27ad-ec7b0a0d0000 pid=3338->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B guuid=d47b90d0-1600-0000-27ad-ec7b110d0000 pid=3345->0cc76706-e9e8-53b6-82b1-adadec74dbb6 send: 130B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-06-12 12:51:06 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e68fa32bc597f446d92b7f9a3e103acc07bc3f57984ddb21e9535ffa49264d8c

(this sample)

  
Delivery method
Distributed via web download

Comments