MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f256da4be409350fadc4620c8b977355181562fd787fd3652f47080a5af54725. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: f256da4be409350fadc4620c8b977355181562fd787fd3652f47080a5af54725
SHA3-384 hash: 9459659a6c482282e65c43bb30722ede2f73f39e1536309d4b9898c2c31a85df583d92ac06e2d043f0b537f41ae16249
SHA1 hash: 906f0776a913f7b52a2d8176b36e7bc6710371a8
MD5 hash: cab1af79e501983b896a51e6bf5e25e0
humanhash: twelve-eleven-cat-oregon
File name:all.sh
Download: download sample
Signature Mirai
File size:1'560 bytes
First seen:2026-04-05 07:17:17 UTC
Last seen:2026-04-06 03:14:12 UTC
File type: sh
MIME type:text/plain
ssdeep 24:sF+RxvFtP3kF8MgApn0ttRV/5BCBMNzFEXUd5AOq:eEDt3kKMnp0tVxBCSNFGE5rq
TLSH T1353190C651E2546A3DE8D94AB16FCC1E7446768E25CA5F49B8CC30F6A88CD40F0C1F57
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.67/x86_647a416069805e038aa1000e43b18aac8107502b1d5cc2ef223d294d1d55ad2719 Miraicensys elf mirai ua-wget
http://176.65.139.67/mpsla0b8e360dacef8f07ad5376f24c32db347dbac14b9b9b0c94c9b43d478686edc Miraicensys elf mirai ua-wget
http://176.65.139.67/mipse08406f2e345c2687c8b3b89c83e2e12aa44af75d66267c9c4e4bd023f3a369a Miraicensys elf mirai ua-wget
http://176.65.139.67/arm4n/an/acensys elf ua-wget
http://176.65.139.67/arm5cebc631971fb334a22a64f013505ff0bfd90b4ce1455db1085f40775d178aa80 Miraicensys elf mirai ua-wget
http://176.65.139.67/arm6d9cf616d3ee2e3876c290d87b32ee7ae84d0bdbaabaad7e2345e85a480e2004e Miraicensys elf mirai ua-wget
http://176.65.139.67/arm7d5ba31f3cc0a1ac9ae8e0f31c93aa8d730f47d9ed4241cba168c69547711d916 Miraicensys elf mirai ua-wget
http://176.65.139.67/m68k8bfb00aa025648f1baf72ee0328199fbdb8409a62267c8d42a6496feaa3b17ce Miraicensys elf mirai ua-wget
http://176.65.139.67/x863ae5fe39220114be834f20f83580c0b4f2bf3f12131a6b3c13bcc42dd6f1444f Miraicensys elf mirai ua-wget
http://176.65.139.67/spcn/an/acensys elf ua-wget
http://176.65.139.67/ppc08892b942d00c640a81cdede68d06e5616cf080b6362b0c1dbc7ec9f2ce7a8d1 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2026-04-05T04:26:00Z UTC
Last seen:
2026-04-05T06:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=10693204-1800-0000-beed-431b840b0000 pid=2948 /usr/bin/sudo guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953 /tmp/sample.bin guuid=10693204-1800-0000-beed-431b840b0000 pid=2948->guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953 execve guuid=6edf4206-1800-0000-beed-431b8b0b0000 pid=2955 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=6edf4206-1800-0000-beed-431b8b0b0000 pid=2955 execve guuid=3f908006-1800-0000-beed-431b8d0b0000 pid=2957 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=3f908006-1800-0000-beed-431b8d0b0000 pid=2957 execve guuid=a4aaae0c-1800-0000-beed-431b9d0b0000 pid=2973 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=a4aaae0c-1800-0000-beed-431b9d0b0000 pid=2973 execve guuid=5fe6e40c-1800-0000-beed-431b9f0b0000 pid=2975 /tmp/x86_64 net guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=5fe6e40c-1800-0000-beed-431b9f0b0000 pid=2975 execve guuid=1ab2160d-1800-0000-beed-431ba10b0000 pid=2977 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=1ab2160d-1800-0000-beed-431ba10b0000 pid=2977 execve guuid=fcdf940d-1800-0000-beed-431ba60b0000 pid=2982 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=fcdf940d-1800-0000-beed-431ba60b0000 pid=2982 execve guuid=2945d612-1800-0000-beed-431bb80b0000 pid=3000 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=2945d612-1800-0000-beed-431bb80b0000 pid=3000 execve guuid=a0a31813-1800-0000-beed-431bb90b0000 pid=3001 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=a0a31813-1800-0000-beed-431bb90b0000 pid=3001 clone guuid=47a68a14-1800-0000-beed-431bbf0b0000 pid=3007 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=47a68a14-1800-0000-beed-431bbf0b0000 pid=3007 execve guuid=c93cc014-1800-0000-beed-431bc10b0000 pid=3009 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=c93cc014-1800-0000-beed-431bc10b0000 pid=3009 execve guuid=e025e919-1800-0000-beed-431bd20b0000 pid=3026 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=e025e919-1800-0000-beed-431bd20b0000 pid=3026 execve guuid=caee1d1a-1800-0000-beed-431bd60b0000 pid=3030 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=caee1d1a-1800-0000-beed-431bd60b0000 pid=3030 clone guuid=77dd971a-1800-0000-beed-431bdd0b0000 pid=3037 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=77dd971a-1800-0000-beed-431bdd0b0000 pid=3037 execve guuid=77b3d81a-1800-0000-beed-431bdf0b0000 pid=3039 /usr/bin/busybox net send-data guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=77b3d81a-1800-0000-beed-431bdf0b0000 pid=3039 execve guuid=6418a01c-1800-0000-beed-431be50b0000 pid=3045 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=6418a01c-1800-0000-beed-431be50b0000 pid=3045 execve guuid=875cdd1c-1800-0000-beed-431be70b0000 pid=3047 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=875cdd1c-1800-0000-beed-431be70b0000 pid=3047 clone guuid=07a9ed1c-1800-0000-beed-431be80b0000 pid=3048 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=07a9ed1c-1800-0000-beed-431be80b0000 pid=3048 execve guuid=8b7c2b1d-1800-0000-beed-431bea0b0000 pid=3050 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=8b7c2b1d-1800-0000-beed-431bea0b0000 pid=3050 execve guuid=0ca73d22-1800-0000-beed-431bfb0b0000 pid=3067 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=0ca73d22-1800-0000-beed-431bfb0b0000 pid=3067 execve guuid=69348922-1800-0000-beed-431bfd0b0000 pid=3069 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=69348922-1800-0000-beed-431bfd0b0000 pid=3069 clone guuid=4a503a23-1800-0000-beed-431b010c0000 pid=3073 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=4a503a23-1800-0000-beed-431b010c0000 pid=3073 execve guuid=8e927f23-1800-0000-beed-431b020c0000 pid=3074 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=8e927f23-1800-0000-beed-431b020c0000 pid=3074 execve guuid=3054cd28-1800-0000-beed-431b120c0000 pid=3090 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=3054cd28-1800-0000-beed-431b120c0000 pid=3090 execve guuid=53742d29-1800-0000-beed-431b140c0000 pid=3092 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=53742d29-1800-0000-beed-431b140c0000 pid=3092 clone guuid=25ace42a-1800-0000-beed-431b1a0c0000 pid=3098 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=25ace42a-1800-0000-beed-431b1a0c0000 pid=3098 execve guuid=6c77292b-1800-0000-beed-431b1c0c0000 pid=3100 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=6c77292b-1800-0000-beed-431b1c0c0000 pid=3100 execve guuid=41db2d30-1800-0000-beed-431b290c0000 pid=3113 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=41db2d30-1800-0000-beed-431b290c0000 pid=3113 execve guuid=4531a130-1800-0000-beed-431b2a0c0000 pid=3114 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=4531a130-1800-0000-beed-431b2a0c0000 pid=3114 clone guuid=95415531-1800-0000-beed-431b2d0c0000 pid=3117 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=95415531-1800-0000-beed-431b2d0c0000 pid=3117 execve guuid=a4b4ac31-1800-0000-beed-431b2f0c0000 pid=3119 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=a4b4ac31-1800-0000-beed-431b2f0c0000 pid=3119 execve guuid=c6b00a37-1800-0000-beed-431b3b0c0000 pid=3131 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=c6b00a37-1800-0000-beed-431b3b0c0000 pid=3131 execve guuid=40726437-1800-0000-beed-431b3c0c0000 pid=3132 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=40726437-1800-0000-beed-431b3c0c0000 pid=3132 clone guuid=0bfe1238-1800-0000-beed-431b3f0c0000 pid=3135 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=0bfe1238-1800-0000-beed-431b3f0c0000 pid=3135 execve guuid=fb2c5e38-1800-0000-beed-431b400c0000 pid=3136 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=fb2c5e38-1800-0000-beed-431b400c0000 pid=3136 execve guuid=f19f383d-1800-0000-beed-431b4b0c0000 pid=3147 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=f19f383d-1800-0000-beed-431b4b0c0000 pid=3147 execve guuid=1703df3d-1800-0000-beed-431b4d0c0000 pid=3149 /tmp/x86 net guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=1703df3d-1800-0000-beed-431b4d0c0000 pid=3149 execve guuid=3fe580f1-1800-0000-beed-431b290d0000 pid=3369 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=3fe580f1-1800-0000-beed-431b290d0000 pid=3369 execve guuid=2aec06f2-1800-0000-beed-431b2c0d0000 pid=3372 /usr/bin/busybox net send-data guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=2aec06f2-1800-0000-beed-431b2c0d0000 pid=3372 execve guuid=a4317cf4-1800-0000-beed-431b380d0000 pid=3384 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=a4317cf4-1800-0000-beed-431b380d0000 pid=3384 execve guuid=077afff4-1800-0000-beed-431b3d0d0000 pid=3389 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=077afff4-1800-0000-beed-431b3d0d0000 pid=3389 clone guuid=08f90ef5-1800-0000-beed-431b3e0d0000 pid=3390 /usr/bin/rm guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=08f90ef5-1800-0000-beed-431b3e0d0000 pid=3390 execve guuid=e69a6ef5-1800-0000-beed-431b400d0000 pid=3392 /usr/bin/busybox net send-data write-file guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=e69a6ef5-1800-0000-beed-431b400d0000 pid=3392 execve guuid=e95f19fb-1800-0000-beed-431b490d0000 pid=3401 /usr/bin/chmod guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=e95f19fb-1800-0000-beed-431b490d0000 pid=3401 execve guuid=df8bc2fb-1800-0000-beed-431b4a0d0000 pid=3402 /usr/bin/dash guuid=64b6fd05-1800-0000-beed-431b890b0000 pid=2953->guuid=df8bc2fb-1800-0000-beed-431b4a0d0000 pid=3402 clone 6c41c2cd-8068-525f-9229-995adab0aeae 176.65.139.67:80 guuid=3f908006-1800-0000-beed-431b8d0b0000 pid=2957->6c41c2cd-8068-525f-9229-995adab0aeae send: 82B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5fe6e40c-1800-0000-beed-431b9f0b0000 pid=2975->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976 /tmp/x86_64 dns net send-data zombie guuid=5fe6e40c-1800-0000-beed-431b9f0b0000 pid=2975->guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976 clone 5b027a48-7b62-54dd-bd92-302c77ae3608 194.36.144.87:53 guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976->5b027a48-7b62-54dd-bd92-302c77ae3608 send: 185B 5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 0.0.0.0:0 guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 con 87c2dbf2-2b8a-5511-a250-d778ce5cd415 185.181.61.24:53 guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976->87c2dbf2-2b8a-5511-a250-d778ce5cd415 send: 185B guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979 /tmp/x86_64 net guuid=71caf90c-1800-0000-beed-431ba00b0000 pid=2976->guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979 clone 18292567-24c1-5786-a609-043bbf84884e 212.118.43.167:2222 guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->18292567-24c1-5786-a609-043bbf84884e con guuid=9a3e6f0d-1800-0000-beed-431ba40b0000 pid=2980 /usr/bin/dash guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->guuid=9a3e6f0d-1800-0000-beed-431ba40b0000 pid=2980 execve guuid=bdf04e19-1800-0000-beed-431bcd0b0000 pid=3021 /usr/bin/dash guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->guuid=bdf04e19-1800-0000-beed-431bcd0b0000 pid=3021 execve guuid=dbe2a719-1800-0000-beed-431bd00b0000 pid=3024 /usr/bin/dash guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->guuid=dbe2a719-1800-0000-beed-431bd00b0000 pid=3024 execve guuid=8fa7ff19-1800-0000-beed-431bd40b0000 pid=3028 /usr/bin/dash guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->guuid=8fa7ff19-1800-0000-beed-431bd40b0000 pid=3028 execve guuid=ea80301a-1800-0000-beed-431bd90b0000 pid=3033 /usr/bin/dash guuid=59fc620d-1800-0000-beed-431ba30b0000 pid=2979->guuid=ea80301a-1800-0000-beed-431bd90b0000 pid=3033 execve guuid=b7fa980d-1800-0000-beed-431ba70b0000 pid=2983 /usr/sbin/xtables-nft-multi guuid=9a3e6f0d-1800-0000-beed-431ba40b0000 pid=2980->guuid=b7fa980d-1800-0000-beed-431ba70b0000 pid=2983 execve guuid=fcdf940d-1800-0000-beed-431ba60b0000 pid=2982->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=c93cc014-1800-0000-beed-431bc10b0000 pid=3009->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=16317a19-1800-0000-beed-431bce0b0000 pid=3022 /usr/bin/busybox guuid=bdf04e19-1800-0000-beed-431bcd0b0000 pid=3021->guuid=16317a19-1800-0000-beed-431bce0b0000 pid=3022 execve guuid=344ef419-1800-0000-beed-431bd30b0000 pid=3027 /usr/bin/dash guuid=dbe2a719-1800-0000-beed-431bd00b0000 pid=3024->guuid=344ef419-1800-0000-beed-431bd30b0000 pid=3027 clone guuid=0308271a-1800-0000-beed-431bd80b0000 pid=3032 /usr/bin/dash guuid=8fa7ff19-1800-0000-beed-431bd40b0000 pid=3028->guuid=0308271a-1800-0000-beed-431bd80b0000 pid=3032 clone guuid=9038591a-1800-0000-beed-431bdb0b0000 pid=3035 /usr/bin/busybox guuid=ea80301a-1800-0000-beed-431bd90b0000 pid=3033->guuid=9038591a-1800-0000-beed-431bdb0b0000 pid=3035 execve guuid=77b3d81a-1800-0000-beed-431bdf0b0000 pid=3039->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=8b7c2b1d-1800-0000-beed-431bea0b0000 pid=3050->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=8e927f23-1800-0000-beed-431b020c0000 pid=3074->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=6c77292b-1800-0000-beed-431b1c0c0000 pid=3100->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=a4b4ac31-1800-0000-beed-431b2f0c0000 pid=3119->6c41c2cd-8068-525f-9229-995adab0aeae send: 80B guuid=fb2c5e38-1800-0000-beed-431b400c0000 pid=3136->6c41c2cd-8068-525f-9229-995adab0aeae send: 79B guuid=1703df3d-1800-0000-beed-431b4d0c0000 pid=3149->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 1d28f9db-477c-5fe6-a1c6-862cbe5680b8 127.0.0.1:6521 guuid=1703df3d-1800-0000-beed-431b4d0c0000 pid=3149->1d28f9db-477c-5fe6-a1c6-862cbe5680b8 con guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368 /tmp/x86 dns net send-data zombie guuid=1703df3d-1800-0000-beed-431b4d0c0000 pid=3149->guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368 clone guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->5b027a48-7b62-54dd-bd92-302c77ae3608 send: 185B guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->5a1eed8a-85fe-5cc9-b13b-21dc70289ae4 con 3b60cfb2-6ce4-568a-bb03-bf9c526c5851 51.254.162.59:53 guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->3b60cfb2-6ce4-568a-bb03-bf9c526c5851 send: 185B 1916c8ac-07bf-5360-a6f3-e42acfa320ef 91.217.137.37:53 guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->1916c8ac-07bf-5360-a6f3-e42acfa320ef send: 185B 997a677b-e2e3-587d-b712-9bb3900e9b02 51.158.108.203:53 guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->997a677b-e2e3-587d-b712-9bb3900e9b02 send: 185B guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370 /tmp/x86 net guuid=305d71f1-1800-0000-beed-431b280d0000 pid=3368->guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370 clone guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->18292567-24c1-5786-a609-043bbf84884e con guuid=d25906f2-1800-0000-beed-431b2b0d0000 pid=3371 /usr/bin/dash guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->guuid=d25906f2-1800-0000-beed-431b2b0d0000 pid=3371 execve guuid=8568f3f2-1800-0000-beed-431b300d0000 pid=3376 /usr/bin/dash guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->guuid=8568f3f2-1800-0000-beed-431b300d0000 pid=3376 execve guuid=645f70f3-1800-0000-beed-431b330d0000 pid=3379 /usr/bin/dash guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->guuid=645f70f3-1800-0000-beed-431b330d0000 pid=3379 execve guuid=3120fcf3-1800-0000-beed-431b370d0000 pid=3383 /usr/bin/dash guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->guuid=3120fcf3-1800-0000-beed-431b370d0000 pid=3383 execve guuid=16fabcf4-1800-0000-beed-431b3a0d0000 pid=3386 /usr/bin/dash guuid=90c3fcf1-1800-0000-beed-431b2a0d0000 pid=3370->guuid=16fabcf4-1800-0000-beed-431b3a0d0000 pid=3386 execve guuid=2dc836f2-1800-0000-beed-431b2d0d0000 pid=3373 /usr/sbin/xtables-nft-multi guuid=d25906f2-1800-0000-beed-431b2b0d0000 pid=3371->guuid=2dc836f2-1800-0000-beed-431b2d0d0000 pid=3373 execve guuid=2aec06f2-1800-0000-beed-431b2c0d0000 pid=3372->6c41c2cd-8068-525f-9229-995adab0aeae send: 79B guuid=56f126f3-1800-0000-beed-431b310d0000 pid=3377 /usr/bin/busybox guuid=8568f3f2-1800-0000-beed-431b300d0000 pid=3376->guuid=56f126f3-1800-0000-beed-431b310d0000 pid=3377 execve guuid=838cdef3-1800-0000-beed-431b350d0000 pid=3381 /usr/bin/dash guuid=645f70f3-1800-0000-beed-431b330d0000 pid=3379->guuid=838cdef3-1800-0000-beed-431b350d0000 pid=3381 clone guuid=e4c2a0f4-1800-0000-beed-431b390d0000 pid=3385 /usr/bin/dash guuid=3120fcf3-1800-0000-beed-431b370d0000 pid=3383->guuid=e4c2a0f4-1800-0000-beed-431b390d0000 pid=3385 clone guuid=70b3f6f4-1800-0000-beed-431b3c0d0000 pid=3388 /usr/bin/busybox guuid=16fabcf4-1800-0000-beed-431b3a0d0000 pid=3386->guuid=70b3f6f4-1800-0000-beed-431b3c0d0000 pid=3388 execve guuid=e69a6ef5-1800-0000-beed-431b400d0000 pid=3392->6c41c2cd-8068-525f-9229-995adab0aeae send: 79B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-04-05 07:18:54 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f256da4be409350fadc4620c8b977355181562fd787fd3652f47080a5af54725

(this sample)

  
Delivery method
Distributed via web download

Comments