MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5d6e35d16cea8448b7e3faaddea0e855ea1d47838e27555a7c2433f31159a30. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: f5d6e35d16cea8448b7e3faaddea0e855ea1d47838e27555a7c2433f31159a30
SHA3-384 hash: f3b200f6b0464463e74ebd0119d747754c6e3a02a2aee8105dfb1625214156b3151567acb107db3491cc834fbc3bb9cd
SHA1 hash: faff8a259c803c1237c811f1e2a98caa4185bb2e
MD5 hash: 75b2ef77b19d207e1288784f3c5cdce6
humanhash: oven-tennis-oven-nebraska
File name:massload
Download: download sample
Signature Mirai
File size:2'504 bytes
First seen:2026-02-17 13:30:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:z56fS7fyBH7HgrfST9TzPf1PdBwQmKmBxbi:F6+ftfST9TzPtPdBvmKmBJi
TLSH T1EB5182BC6AF26E37C665CF0870614A79F00BE5C86CE3CED8D47E18E8856B705B210E15
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.69/mips8da7611d1eea41efa82bf6e4c76f502677a4464f63f608536255a1c56140e59d Miraielf geofenced mips mirai ua-wget USA
http://158.94.208.69/mpsle0c583ba57d7db5e75a042c850a8c82091026915e8de232c8143cde9e5bcc34d Miraielf geofenced mips mirai ua-wget USA
http://158.94.208.69/arm45205d6ba7f178eef4f5bf57bed13f771baf0746d2508e936f0c065436daaeb2f Miraiarm elf geofenced mirai ua-wget USA
http://158.94.208.69/arm507dda2df14aba27bd8442744ce6833e521176a95805429b4195b9a534045d072 Miraiarm elf geofenced mirai ua-wget USA
http://158.94.208.69/arm7d58f2346469f40aabffd75c02c953fa036ea71bae80441cca37f2482d1f0635a Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
101
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Status:
terminated
Behavior Graph:
%3 guuid=7e11025f-1a00-0000-d278-b5f4660c0000 pid=3174 /usr/bin/sudo guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182 /tmp/sample.bin guuid=7e11025f-1a00-0000-d278-b5f4660c0000 pid=3174->guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182 execve guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184 clone guuid=f6654f62-1a00-0000-d278-b5f4770c0000 pid=3191 /usr/bin/cp write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f6654f62-1a00-0000-d278-b5f4770c0000 pid=3191 execve guuid=6a642566-1a00-0000-d278-b5f4810c0000 pid=3201 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=6a642566-1a00-0000-d278-b5f4810c0000 pid=3201 execve guuid=f01ba766-1a00-0000-d278-b5f4820c0000 pid=3202 /usr/bin/rm delete-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f01ba766-1a00-0000-d278-b5f4820c0000 pid=3202 execve guuid=4edbf066-1a00-0000-d278-b5f4840c0000 pid=3204 /usr/bin/rm delete-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=4edbf066-1a00-0000-d278-b5f4840c0000 pid=3204 execve guuid=eb884d69-1a00-0000-d278-b5f48a0c0000 pid=3210 /usr/bin/wget net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=eb884d69-1a00-0000-d278-b5f48a0c0000 pid=3210 execve guuid=1c4c117c-1a00-0000-d278-b5f4960c0000 pid=3222 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=1c4c117c-1a00-0000-d278-b5f4960c0000 pid=3222 execve guuid=cbcf947c-1a00-0000-d278-b5f4970c0000 pid=3223 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=cbcf947c-1a00-0000-d278-b5f4970c0000 pid=3223 clone guuid=327cee7d-1a00-0000-d278-b5f4990c0000 pid=3225 /usr/bin/wget net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=327cee7d-1a00-0000-d278-b5f4990c0000 pid=3225 execve guuid=193f708f-1a00-0000-d278-b5f4af0c0000 pid=3247 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=193f708f-1a00-0000-d278-b5f4af0c0000 pid=3247 execve guuid=d0780490-1a00-0000-d278-b5f4b00c0000 pid=3248 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=d0780490-1a00-0000-d278-b5f4b00c0000 pid=3248 clone guuid=7904bd92-1a00-0000-d278-b5f4b20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=7904bd92-1a00-0000-d278-b5f4b20c0000 pid=3250 execve guuid=263f3ba0-1a00-0000-d278-b5f4c10c0000 pid=3265 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=263f3ba0-1a00-0000-d278-b5f4c10c0000 pid=3265 execve guuid=4e44f7a0-1a00-0000-d278-b5f4c20c0000 pid=3266 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=4e44f7a0-1a00-0000-d278-b5f4c20c0000 pid=3266 clone guuid=9016d8a1-1a00-0000-d278-b5f4c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=9016d8a1-1a00-0000-d278-b5f4c50c0000 pid=3269 execve guuid=e1fe6caf-1a00-0000-d278-b5f4d70c0000 pid=3287 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=e1fe6caf-1a00-0000-d278-b5f4d70c0000 pid=3287 execve guuid=f24003b0-1a00-0000-d278-b5f4d90c0000 pid=3289 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f24003b0-1a00-0000-d278-b5f4d90c0000 pid=3289 clone guuid=d9ecb0b0-1a00-0000-d278-b5f4dd0c0000 pid=3293 /usr/bin/wget net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=d9ecb0b0-1a00-0000-d278-b5f4dd0c0000 pid=3293 execve guuid=901708c1-1a00-0000-d278-b5f4fa0c0000 pid=3322 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=901708c1-1a00-0000-d278-b5f4fa0c0000 pid=3322 execve guuid=51125cc1-1a00-0000-d278-b5f4fc0c0000 pid=3324 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=51125cc1-1a00-0000-d278-b5f4fc0c0000 pid=3324 clone guuid=52e2fdc1-1a00-0000-d278-b5f4000d0000 pid=3328 /usr/bin/curl net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=52e2fdc1-1a00-0000-d278-b5f4000d0000 pid=3328 execve guuid=95ba7cd6-1a00-0000-d278-b5f41b0d0000 pid=3355 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=95ba7cd6-1a00-0000-d278-b5f41b0d0000 pid=3355 execve guuid=f1ec41d7-1a00-0000-d278-b5f41c0d0000 pid=3356 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f1ec41d7-1a00-0000-d278-b5f41c0d0000 pid=3356 clone guuid=238d8cd9-1a00-0000-d278-b5f41e0d0000 pid=3358 /usr/bin/curl net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=238d8cd9-1a00-0000-d278-b5f41e0d0000 pid=3358 execve guuid=e4f9baed-1a00-0000-d278-b5f4420d0000 pid=3394 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=e4f9baed-1a00-0000-d278-b5f4420d0000 pid=3394 execve guuid=cd9564ee-1a00-0000-d278-b5f4440d0000 pid=3396 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=cd9564ee-1a00-0000-d278-b5f4440d0000 pid=3396 clone guuid=9cc780ef-1a00-0000-d278-b5f4470d0000 pid=3399 /usr/bin/curl net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=9cc780ef-1a00-0000-d278-b5f4470d0000 pid=3399 execve guuid=43539100-1b00-0000-d278-b5f4770d0000 pid=3447 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=43539100-1b00-0000-d278-b5f4770d0000 pid=3447 execve guuid=fdc8e100-1b00-0000-d278-b5f4790d0000 pid=3449 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=fdc8e100-1b00-0000-d278-b5f4790d0000 pid=3449 clone guuid=a484a202-1b00-0000-d278-b5f47f0d0000 pid=3455 /usr/bin/curl net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=a484a202-1b00-0000-d278-b5f47f0d0000 pid=3455 execve guuid=003b5213-1b00-0000-d278-b5f4ac0d0000 pid=3500 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=003b5213-1b00-0000-d278-b5f4ac0d0000 pid=3500 execve guuid=8ab7cf13-1b00-0000-d278-b5f4ae0d0000 pid=3502 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=8ab7cf13-1b00-0000-d278-b5f4ae0d0000 pid=3502 clone guuid=44248714-1b00-0000-d278-b5f4b20d0000 pid=3506 /usr/bin/curl net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=44248714-1b00-0000-d278-b5f4b20d0000 pid=3506 execve guuid=4a810627-1b00-0000-d278-b5f4d60d0000 pid=3542 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=4a810627-1b00-0000-d278-b5f4d60d0000 pid=3542 execve guuid=82785b27-1b00-0000-d278-b5f4d80d0000 pid=3544 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=82785b27-1b00-0000-d278-b5f4d80d0000 pid=3544 clone guuid=df0e0028-1b00-0000-d278-b5f4dc0d0000 pid=3548 /usr/bin/busybox net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=df0e0028-1b00-0000-d278-b5f4dc0d0000 pid=3548 execve guuid=f2cee552-1b00-0000-d278-b5f4220e0000 pid=3618 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f2cee552-1b00-0000-d278-b5f4220e0000 pid=3618 execve guuid=e7916553-1b00-0000-d278-b5f4230e0000 pid=3619 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=e7916553-1b00-0000-d278-b5f4230e0000 pid=3619 clone guuid=2eaf6d54-1b00-0000-d278-b5f4250e0000 pid=3621 /usr/bin/busybox net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=2eaf6d54-1b00-0000-d278-b5f4250e0000 pid=3621 execve guuid=6777b280-1b00-0000-d278-b5f4810e0000 pid=3713 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=6777b280-1b00-0000-d278-b5f4810e0000 pid=3713 execve guuid=9c96f080-1b00-0000-d278-b5f4820e0000 pid=3714 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=9c96f080-1b00-0000-d278-b5f4820e0000 pid=3714 clone guuid=e9533f82-1b00-0000-d278-b5f4840e0000 pid=3716 /usr/bin/busybox net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=e9533f82-1b00-0000-d278-b5f4840e0000 pid=3716 execve guuid=611cd9aa-1b00-0000-d278-b5f4dd0e0000 pid=3805 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=611cd9aa-1b00-0000-d278-b5f4dd0e0000 pid=3805 execve guuid=f64939ab-1b00-0000-d278-b5f4df0e0000 pid=3807 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f64939ab-1b00-0000-d278-b5f4df0e0000 pid=3807 clone guuid=824a04ac-1b00-0000-d278-b5f4e30e0000 pid=3811 /usr/bin/busybox net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=824a04ac-1b00-0000-d278-b5f4e30e0000 pid=3811 execve guuid=3a34aad3-1b00-0000-d278-b5f44d0f0000 pid=3917 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=3a34aad3-1b00-0000-d278-b5f44d0f0000 pid=3917 execve guuid=fd4bf6d3-1b00-0000-d278-b5f44f0f0000 pid=3919 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=fd4bf6d3-1b00-0000-d278-b5f44f0f0000 pid=3919 clone guuid=05f9c7d4-1b00-0000-d278-b5f4520f0000 pid=3922 /usr/bin/busybox net send-data write-file guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=05f9c7d4-1b00-0000-d278-b5f4520f0000 pid=3922 execve guuid=f77a2eff-1b00-0000-d278-b5f4e20f0000 pid=4066 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=f77a2eff-1b00-0000-d278-b5f4e20f0000 pid=4066 execve guuid=64ef8aff-1b00-0000-d278-b5f4e30f0000 pid=4067 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=64ef8aff-1b00-0000-d278-b5f4e30f0000 pid=4067 clone guuid=cd674f00-1c00-0000-d278-b5f4e90f0000 pid=4073 /usr/bin/busybox send-data guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=cd674f00-1c00-0000-d278-b5f4e90f0000 pid=4073 execve guuid=7d416403-1f00-0000-d278-b5f4f6130000 pid=5110 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=7d416403-1f00-0000-d278-b5f4f6130000 pid=5110 execve guuid=5fd1af03-1f00-0000-d278-b5f4f7130000 pid=5111 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=5fd1af03-1f00-0000-d278-b5f4f7130000 pid=5111 clone guuid=6e995105-1f00-0000-d278-b5f4f9130000 pid=5113 /usr/bin/busybox send-data guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=6e995105-1f00-0000-d278-b5f4f9130000 pid=5113 execve guuid=a01a9608-2200-0000-d278-b5f41a140000 pid=5146 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=a01a9608-2200-0000-d278-b5f41a140000 pid=5146 execve guuid=c6e12909-2200-0000-d278-b5f41b140000 pid=5147 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=c6e12909-2200-0000-d278-b5f41b140000 pid=5147 clone guuid=c3cd9a0a-2200-0000-d278-b5f41d140000 pid=5149 /usr/bin/busybox send-data guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=c3cd9a0a-2200-0000-d278-b5f41d140000 pid=5149 execve guuid=5a13190e-2500-0000-d278-b5f41e140000 pid=5150 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=5a13190e-2500-0000-d278-b5f41e140000 pid=5150 execve guuid=39b6a50e-2500-0000-d278-b5f41f140000 pid=5151 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=39b6a50e-2500-0000-d278-b5f41f140000 pid=5151 clone guuid=970cde0f-2500-0000-d278-b5f421140000 pid=5153 /usr/bin/busybox send-data guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=970cde0f-2500-0000-d278-b5f421140000 pid=5153 execve guuid=9e3a6b13-2800-0000-d278-b5f422140000 pid=5154 /usr/bin/chmod guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=9e3a6b13-2800-0000-d278-b5f422140000 pid=5154 execve guuid=68c0c613-2800-0000-d278-b5f423140000 pid=5155 /usr/bin/dash guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=68c0c613-2800-0000-d278-b5f423140000 pid=5155 clone guuid=10394814-2800-0000-d278-b5f425140000 pid=5157 /usr/bin/busybox send-data guuid=230cf660-1a00-0000-d278-b5f46e0c0000 pid=3182->guuid=10394814-2800-0000-d278-b5f425140000 pid=5157 execve guuid=e4bc4b61-1a00-0000-d278-b5f4710c0000 pid=3185 /usr/bin/cat guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184->guuid=e4bc4b61-1a00-0000-d278-b5f4710c0000 pid=3185 execve guuid=22245c61-1a00-0000-d278-b5f4720c0000 pid=3186 /usr/bin/grep guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184->guuid=22245c61-1a00-0000-d278-b5f4720c0000 pid=3186 execve guuid=af476661-1a00-0000-d278-b5f4730c0000 pid=3187 /usr/bin/grep guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184->guuid=af476661-1a00-0000-d278-b5f4730c0000 pid=3187 execve guuid=415b7061-1a00-0000-d278-b5f4740c0000 pid=3188 /usr/bin/grep guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184->guuid=415b7061-1a00-0000-d278-b5f4740c0000 pid=3188 execve guuid=208eb361-1a00-0000-d278-b5f4760c0000 pid=3190 /usr/bin/cut guuid=88cc3f61-1a00-0000-d278-b5f4700c0000 pid=3184->guuid=208eb361-1a00-0000-d278-b5f4760c0000 pid=3190 execve 4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 158.94.208.69:80 guuid=eb884d69-1a00-0000-d278-b5f48a0c0000 pid=3210->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 132B guuid=327cee7d-1a00-0000-d278-b5f4990c0000 pid=3225->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 132B guuid=7904bd92-1a00-0000-d278-b5f4b20c0000 pid=3250->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 132B guuid=9016d8a1-1a00-0000-d278-b5f4c50c0000 pid=3269->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 132B guuid=d9ecb0b0-1a00-0000-d278-b5f4dd0c0000 pid=3293->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 132B guuid=52e2fdc1-1a00-0000-d278-b5f4000d0000 pid=3328->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 81B guuid=238d8cd9-1a00-0000-d278-b5f41e0d0000 pid=3358->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 81B guuid=9cc780ef-1a00-0000-d278-b5f4470d0000 pid=3399->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 81B guuid=a484a202-1b00-0000-d278-b5f47f0d0000 pid=3455->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 81B guuid=44248714-1b00-0000-d278-b5f4b20d0000 pid=3506->4df1c8e6-9b24-5aa9-8764-26a4593ed2a5 send: 81B 3a83ea15-c768-546e-9bd9-20995f88268d 158.94.208.69:21 guuid=df0e0028-1b00-0000-d278-b5f4dc0d0000 pid=3548->3a83ea15-c768-546e-9bd9-20995f88268d send: 78B 6a49ab3d-f1bc-555d-ac34-e3c074a1b596 158.94.208.69:40063 guuid=df0e0028-1b00-0000-d278-b5f4dc0d0000 pid=3548->6a49ab3d-f1bc-555d-ac34-e3c074a1b596 con guuid=2eaf6d54-1b00-0000-d278-b5f4250e0000 pid=3621->3a83ea15-c768-546e-9bd9-20995f88268d send: 78B 709758a6-0c55-5949-a1e1-b736c3389e86 158.94.208.69:34169 guuid=2eaf6d54-1b00-0000-d278-b5f4250e0000 pid=3621->709758a6-0c55-5949-a1e1-b736c3389e86 con guuid=e9533f82-1b00-0000-d278-b5f4840e0000 pid=3716->3a83ea15-c768-546e-9bd9-20995f88268d send: 78B 9c677bfd-95fb-5a71-b9c4-e3cd3cc81a94 158.94.208.69:37349 guuid=e9533f82-1b00-0000-d278-b5f4840e0000 pid=3716->9c677bfd-95fb-5a71-b9c4-e3cd3cc81a94 con guuid=824a04ac-1b00-0000-d278-b5f4e30e0000 pid=3811->3a83ea15-c768-546e-9bd9-20995f88268d send: 78B 9205957a-f8a7-59b4-8754-6ddebdc28934 158.94.208.69:41451 guuid=824a04ac-1b00-0000-d278-b5f4e30e0000 pid=3811->9205957a-f8a7-59b4-8754-6ddebdc28934 con guuid=05f9c7d4-1b00-0000-d278-b5f4520f0000 pid=3922->3a83ea15-c768-546e-9bd9-20995f88268d send: 78B d4185335-92db-56a3-a945-22a19692a39f 158.94.208.69:46247 guuid=05f9c7d4-1b00-0000-d278-b5f4520f0000 pid=3922->d4185335-92db-56a3-a945-22a19692a39f con 2e3d310b-f930-56a5-aaab-4481d28a209a 158.94.208.69:69 guuid=cd674f00-1c00-0000-d278-b5f4e90f0000 pid=4073->2e3d310b-f930-56a5-aaab-4481d28a209a send: 252B guuid=6e995105-1f00-0000-d278-b5f4f9130000 pid=5113->2e3d310b-f930-56a5-aaab-4481d28a209a send: 252B guuid=c3cd9a0a-2200-0000-d278-b5f41d140000 pid=5149->2e3d310b-f930-56a5-aaab-4481d28a209a send: 252B guuid=970cde0f-2500-0000-d278-b5f421140000 pid=5153->2e3d310b-f930-56a5-aaab-4481d28a209a send: 252B guuid=10394814-2800-0000-d278-b5f425140000 pid=5157->2e3d310b-f930-56a5-aaab-4481d28a209a send: 126B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-02-15 19:17:59 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
hailbot
Score:
  10/10
Tags:
family:hailbot botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Contacts a large (771) amount of remote hosts
Detects HailBot ARM
Hailbot
Hailbot family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f5d6e35d16cea8448b7e3faaddea0e855ea1d47838e27555a7c2433f31159a30

(this sample)

  
Delivery method
Distributed via web download

Comments