MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80
SHA3-384 hash: 74acd77c3c11018746912b81fa77462c3c1d21bddf55f09adbec33a8257de4ce553d8a1827224c8e7c174a25e33c9d88
SHA1 hash: eff46afe789c44e50be84cf405ea88adf7c9128d
MD5 hash: f86dab9f11ba4aa886550c7a141f6f3a
humanhash: angel-robert-berlin-don
File name:cat.sh
Download: download sample
Signature Mirai
File size:3'120 bytes
First seen:2026-04-05 01:54:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:fiLElAgybCbrnRnEL+V6fT2IJCCCrlClrpsgx/C/V1Tb2TI:yJ+P2I
TLSH T12451D28E125240F9BC45EE17F4669F9078A09FDA4EE38F4EDEDD2B5251CCC146834672
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.130.214.71:1212/mirai.apkf4b3f661c0002caeae308e75a5473b96c78c0513eed795121f10cfafaf6bdf77 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm459d5de268d7695d2b3238ce264d6e9826cc1ad5d4871d0789b81cc9ac02a7228 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm54d3030180b580cb608199dfbb1b67381e77587ba0290fe881372ef1c4711c3ee Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm644f3e4569e2a76356e5d8195d97398119ac763c1b47a9f941eb98fa71e7dcfa0 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm7f4b3f661c0002caeae308e75a5473b96c78c0513eed795121f10cfafaf6bdf77 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.dbgb81062b3d00b297bfed142f5c79435678528dfb19d32adc576dcd94e21f41ded Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.i486aa2f6b54aa1f2d1f179924b1e5cd00167d9c1842fef9e756b285494ebd4af3ba Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.i686e37daef1c9ee225871ec67e761085f1e86d6b82e53d5f8a0c8635d8997ee2eff Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.m68k1725c67bdd98feb0c6bd2ae568ee2a959e9b564f1e533f1cff8ec87bb2ce9c72 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.mipsc02ae9d038a511028b7c58c9aea89f42b0dda0f1f3898fa1b87260355b14e8b3 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.mpslb505b3e61184d7406491ff14a04d79092dc5a5ee9efb24173ee3b86c1d00994a Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.sh467d3e6a4b65761fccb08e8cc5d63d76fc1a460f6b7e191fdeca7ad1f55a6cc72 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.spc620ec0155acd9685c771a82e794da688dd0e278bed61ea9da89925453f8d336c Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.x64e37e149e08f5beae7d219bac7a070e72676251410c483b5f367c42e4ec752eca Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.x86579e0bb67f37d7ca86a9e093f471bfa5505200de9ae05753e758b6980706bce3 Miraielf mirai ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-04T23:02:00Z UTC
Last seen:
2026-04-04T23:23:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=74a9762d-1a00-0000-c621-d15b94090000 pid=2452 /usr/bin/sudo guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461 /tmp/sample.bin guuid=74a9762d-1a00-0000-c621-d15b94090000 pid=2452->guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461 execve guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463 clone guuid=91981d65-1a00-0000-c621-d15b030a0000 pid=2563 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=91981d65-1a00-0000-c621-d15b030a0000 pid=2563 execve guuid=e8dbcf65-1a00-0000-c621-d15b040a0000 pid=2564 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=e8dbcf65-1a00-0000-c621-d15b040a0000 pid=2564 clone guuid=34e6f766-1a00-0000-c621-d15b090a0000 pid=2569 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=34e6f766-1a00-0000-c621-d15b090a0000 pid=2569 execve guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572 clone guuid=19037299-1a00-0000-c621-d15b8b0a0000 pid=2699 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=19037299-1a00-0000-c621-d15b8b0a0000 pid=2699 execve guuid=d45adb99-1a00-0000-c621-d15b8d0a0000 pid=2701 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d45adb99-1a00-0000-c621-d15b8d0a0000 pid=2701 clone guuid=b694dc9a-1a00-0000-c621-d15b920a0000 pid=2706 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b694dc9a-1a00-0000-c621-d15b920a0000 pid=2706 execve guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708 clone guuid=ced495c1-1a00-0000-c621-d15bce0a0000 pid=2766 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=ced495c1-1a00-0000-c621-d15bce0a0000 pid=2766 execve guuid=b493f4c1-1a00-0000-c621-d15bcf0a0000 pid=2767 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b493f4c1-1a00-0000-c621-d15bcf0a0000 pid=2767 clone guuid=0abde1c2-1a00-0000-c621-d15bd10a0000 pid=2769 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0abde1c2-1a00-0000-c621-d15bd10a0000 pid=2769 execve guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770 clone guuid=bc9ed2f5-1a00-0000-c621-d15b0a0b0000 pid=2826 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bc9ed2f5-1a00-0000-c621-d15b0a0b0000 pid=2826 execve guuid=6cd041f6-1a00-0000-c621-d15b0b0b0000 pid=2827 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=6cd041f6-1a00-0000-c621-d15b0b0b0000 pid=2827 clone guuid=67d01ff8-1a00-0000-c621-d15b0f0b0000 pid=2831 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=67d01ff8-1a00-0000-c621-d15b0f0b0000 pid=2831 execve guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833 clone guuid=bf7c932a-1b00-0000-c621-d15b7e0b0000 pid=2942 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bf7c932a-1b00-0000-c621-d15b7e0b0000 pid=2942 execve guuid=285fd82a-1b00-0000-c621-d15b7f0b0000 pid=2943 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=285fd82a-1b00-0000-c621-d15b7f0b0000 pid=2943 clone guuid=0a09ac2b-1b00-0000-c621-d15b820b0000 pid=2946 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0a09ac2b-1b00-0000-c621-d15b820b0000 pid=2946 execve guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948 clone guuid=c699b168-1b00-0000-c621-d15beb0b0000 pid=3051 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=c699b168-1b00-0000-c621-d15beb0b0000 pid=3051 execve guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053 execve guuid=966d1569-1b00-0000-c621-d15bef0b0000 pid=3055 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=966d1569-1b00-0000-c621-d15bef0b0000 pid=3055 execve guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057 clone guuid=e18bd99a-1b00-0000-c621-d15b770c0000 pid=3191 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=e18bd99a-1b00-0000-c621-d15b770c0000 pid=3191 execve guuid=bc1d209b-1b00-0000-c621-d15b780c0000 pid=3192 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bc1d209b-1b00-0000-c621-d15b780c0000 pid=3192 execve guuid=723f379b-1b00-0000-c621-d15b7a0c0000 pid=3194 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=723f379b-1b00-0000-c621-d15b7a0c0000 pid=3194 execve guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195 clone guuid=8c9c8cce-1b00-0000-c621-d15bb50c0000 pid=3253 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8c9c8cce-1b00-0000-c621-d15bb50c0000 pid=3253 execve guuid=533a24cf-1b00-0000-c621-d15bb70c0000 pid=3255 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=533a24cf-1b00-0000-c621-d15bb70c0000 pid=3255 execve guuid=539d5ccf-1b00-0000-c621-d15bb90c0000 pid=3257 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=539d5ccf-1b00-0000-c621-d15bb90c0000 pid=3257 execve guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259 clone guuid=3492b201-1c00-0000-c621-d15b110d0000 pid=3345 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=3492b201-1c00-0000-c621-d15b110d0000 pid=3345 execve guuid=7f980502-1c00-0000-c621-d15b130d0000 pid=3347 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7f980502-1c00-0000-c621-d15b130d0000 pid=3347 clone guuid=1b0cc802-1c00-0000-c621-d15b170d0000 pid=3351 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=1b0cc802-1c00-0000-c621-d15b170d0000 pid=3351 execve guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353 clone guuid=8dc9d936-1c00-0000-c621-d15b720d0000 pid=3442 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8dc9d936-1c00-0000-c621-d15b720d0000 pid=3442 execve guuid=78103437-1c00-0000-c621-d15b740d0000 pid=3444 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=78103437-1c00-0000-c621-d15b740d0000 pid=3444 clone guuid=86467f38-1c00-0000-c621-d15b7a0d0000 pid=3450 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=86467f38-1c00-0000-c621-d15b7a0d0000 pid=3450 execve guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452 clone guuid=d955726c-1c00-0000-c621-d15bf20d0000 pid=3570 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d955726c-1c00-0000-c621-d15bf20d0000 pid=3570 execve guuid=d974d06c-1c00-0000-c621-d15bf30d0000 pid=3571 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d974d06c-1c00-0000-c621-d15bf30d0000 pid=3571 clone guuid=d318ee6d-1c00-0000-c621-d15bf50d0000 pid=3573 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d318ee6d-1c00-0000-c621-d15bf50d0000 pid=3573 execve guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574 clone guuid=b966d99f-1c00-0000-c621-d15b630e0000 pid=3683 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b966d99f-1c00-0000-c621-d15b630e0000 pid=3683 execve guuid=1c7c4ea0-1c00-0000-c621-d15b650e0000 pid=3685 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=1c7c4ea0-1c00-0000-c621-d15b650e0000 pid=3685 clone guuid=f5d4f0a1-1c00-0000-c621-d15b6b0e0000 pid=3691 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=f5d4f0a1-1c00-0000-c621-d15b6b0e0000 pid=3691 execve guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693 clone guuid=9674d6d4-1c00-0000-c621-d15bdb0e0000 pid=3803 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=9674d6d4-1c00-0000-c621-d15bdb0e0000 pid=3803 execve guuid=d92b24d5-1c00-0000-c621-d15bdd0e0000 pid=3805 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d92b24d5-1c00-0000-c621-d15bdd0e0000 pid=3805 clone guuid=50fcf1d5-1c00-0000-c621-d15be20e0000 pid=3810 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=50fcf1d5-1c00-0000-c621-d15be20e0000 pid=3810 execve guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814 clone guuid=fd659a08-1d00-0000-c621-d15b7f0f0000 pid=3967 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=fd659a08-1d00-0000-c621-d15b7f0f0000 pid=3967 execve guuid=4b03f308-1d00-0000-c621-d15b830f0000 pid=3971 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=4b03f308-1d00-0000-c621-d15b830f0000 pid=3971 execve guuid=5dc70f09-1d00-0000-c621-d15b840f0000 pid=3972 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=5dc70f09-1d00-0000-c621-d15b840f0000 pid=3972 execve guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973 clone guuid=d999103d-1d00-0000-c621-d15b22100000 pid=4130 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d999103d-1d00-0000-c621-d15b22100000 pid=4130 execve guuid=f6888c3d-1d00-0000-c621-d15b26100000 pid=4134 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=f6888c3d-1d00-0000-c621-d15b26100000 pid=4134 execve guuid=7f01bc3d-1d00-0000-c621-d15b27100000 pid=4135 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7f01bc3d-1d00-0000-c621-d15b27100000 pid=4135 execve guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464 /usr/bin/wget net send-data write-file guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463->guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464 execve 9d944b7b-5602-507b-b9b6-87b651bc0ff5 103.130.214.71:1212 guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574 /usr/bin/wget net send-data write-file guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572->guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574 execve guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709 /usr/bin/wget net send-data write-file guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708->guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709 execve guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771 /usr/bin/wget net send-data write-file guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770->guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771 execve guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834 /usr/bin/wget net send-data write-file guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833->guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834 execve guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950 /usr/bin/wget net send-data write-file guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948->guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950 execve guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054 /tmp/target net send-data zombie guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053->guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e1dfe4ad-bd09-520e-b47b-5f4160545e50 103.130.214.71:9506 guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 121B guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058 /usr/bin/wget net send-data write-file guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057->guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058 execve guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196 /usr/bin/wget net send-data write-file guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195->guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196 execve guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259->guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260 execve guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354 /usr/bin/wget net send-data write-file guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353->guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354 execve guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453 /usr/bin/wget net send-data write-file guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452->guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453 execve guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575 /usr/bin/wget net send-data write-file guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574->guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575 execve guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695 /usr/bin/wget net send-data write-file guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693->guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695 execve guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815 /usr/bin/wget net send-data write-file guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814->guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815 execve guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974 /usr/bin/wget net send-data write-file guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973->guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974 execve guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-05 01:55:31 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80

(this sample)

  
Delivery method
Distributed via web download

Comments