MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f8e2d3a3a3db818c52bf4dc4ab6ba9ce6e8195cf1977ff13d889eb635d7c81f1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: f8e2d3a3a3db818c52bf4dc4ab6ba9ce6e8195cf1977ff13d889eb635d7c81f1
SHA3-384 hash: 8f0c331efbf14227fff5c29038b5b29535937a58d899735a7d673d5a37801233ff16484f7429c4ab66101f44760be759
SHA1 hash: 105e2b5742689ef0a1cd76e7bd232eb007b8a76f
MD5 hash: a6b3467c5712207eb73b25ef9d400496
humanhash: carbon-seventeen-earth-mexico
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:632 bytes
First seen:2026-04-01 22:49:01 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:t71GTvuFf8bCqjbOVJ761IHWKx6lU6IjpkYMJv:t71cWF0bBGvV2YU
TLSH T10CF002D7E285043B6CB901F3DFC19A582084308B1CD06F50B45DA1F11798C10A621307
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
77
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=0679cb08-1800-0000-5290-6387eb0b0000 pid=3051 /usr/bin/sudo guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058 /tmp/sample.bin guuid=0679cb08-1800-0000-5290-6387eb0b0000 pid=3051->guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058 execve guuid=0aa1590c-1800-0000-5290-6387f40b0000 pid=3060 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=0aa1590c-1800-0000-5290-6387f40b0000 pid=3060 execve guuid=e0d2f513-1800-0000-5290-6387050c0000 pid=3077 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=e0d2f513-1800-0000-5290-6387050c0000 pid=3077 execve guuid=8d045b14-1800-0000-5290-6387060c0000 pid=3078 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=8d045b14-1800-0000-5290-6387060c0000 pid=3078 clone guuid=02bb6414-1800-0000-5290-6387070c0000 pid=3079 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=02bb6414-1800-0000-5290-6387070c0000 pid=3079 execve guuid=da786e19-1800-0000-5290-6387120c0000 pid=3090 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=da786e19-1800-0000-5290-6387120c0000 pid=3090 execve guuid=37f4c519-1800-0000-5290-6387140c0000 pid=3092 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=37f4c519-1800-0000-5290-6387140c0000 pid=3092 clone guuid=9f7aca19-1800-0000-5290-6387150c0000 pid=3093 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=9f7aca19-1800-0000-5290-6387150c0000 pid=3093 execve guuid=1f69c51d-1800-0000-5290-6387210c0000 pid=3105 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=1f69c51d-1800-0000-5290-6387210c0000 pid=3105 execve guuid=ef18121e-1800-0000-5290-6387230c0000 pid=3107 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=ef18121e-1800-0000-5290-6387230c0000 pid=3107 clone guuid=3d4d161e-1800-0000-5290-6387240c0000 pid=3108 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=3d4d161e-1800-0000-5290-6387240c0000 pid=3108 execve guuid=84d3a622-1800-0000-5290-6387330c0000 pid=3123 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=84d3a622-1800-0000-5290-6387330c0000 pid=3123 execve guuid=7581e422-1800-0000-5290-6387350c0000 pid=3125 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=7581e422-1800-0000-5290-6387350c0000 pid=3125 clone guuid=6bc3e822-1800-0000-5290-6387360c0000 pid=3126 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=6bc3e822-1800-0000-5290-6387360c0000 pid=3126 execve guuid=8cfb622d-1800-0000-5290-6387570c0000 pid=3159 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=8cfb622d-1800-0000-5290-6387570c0000 pid=3159 execve guuid=2dc0ea2d-1800-0000-5290-6387580c0000 pid=3160 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=2dc0ea2d-1800-0000-5290-6387580c0000 pid=3160 clone guuid=a2d7ee2d-1800-0000-5290-6387590c0000 pid=3161 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=a2d7ee2d-1800-0000-5290-6387590c0000 pid=3161 execve guuid=d5125a32-1800-0000-5290-6387620c0000 pid=3170 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=d5125a32-1800-0000-5290-6387620c0000 pid=3170 execve guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171 /tmp/bot.i486 net guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171 execve guuid=b08da232-1800-0000-5290-6387640c0000 pid=3172 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=b08da232-1800-0000-5290-6387640c0000 pid=3172 execve guuid=baf31f36-1800-0000-5290-6387710c0000 pid=3185 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=baf31f36-1800-0000-5290-6387710c0000 pid=3185 execve guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186 /tmp/bot.i686 net guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186 execve guuid=4acf6036-1800-0000-5290-6387730c0000 pid=3187 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=4acf6036-1800-0000-5290-6387730c0000 pid=3187 execve guuid=4a4c813a-1800-0000-5290-6387800c0000 pid=3200 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=4a4c813a-1800-0000-5290-6387800c0000 pid=3200 execve guuid=3196c23a-1800-0000-5290-6387820c0000 pid=3202 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=3196c23a-1800-0000-5290-6387820c0000 pid=3202 clone guuid=14f6c63a-1800-0000-5290-6387830c0000 pid=3203 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=14f6c63a-1800-0000-5290-6387830c0000 pid=3203 execve guuid=192e463e-1800-0000-5290-63878a0c0000 pid=3210 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=192e463e-1800-0000-5290-63878a0c0000 pid=3210 execve guuid=32a1dd3e-1800-0000-5290-63878b0c0000 pid=3211 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=32a1dd3e-1800-0000-5290-63878b0c0000 pid=3211 clone guuid=edd4e43e-1800-0000-5290-63878c0c0000 pid=3212 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=edd4e43e-1800-0000-5290-63878c0c0000 pid=3212 execve guuid=eb3de142-1800-0000-5290-63878e0c0000 pid=3214 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=eb3de142-1800-0000-5290-63878e0c0000 pid=3214 execve guuid=9ad76043-1800-0000-5290-63878f0c0000 pid=3215 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=9ad76043-1800-0000-5290-63878f0c0000 pid=3215 clone guuid=6f286643-1800-0000-5290-6387900c0000 pid=3216 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=6f286643-1800-0000-5290-6387900c0000 pid=3216 execve guuid=7e94f647-1800-0000-5290-6387920c0000 pid=3218 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=7e94f647-1800-0000-5290-6387920c0000 pid=3218 execve guuid=39e47648-1800-0000-5290-6387930c0000 pid=3219 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=39e47648-1800-0000-5290-6387930c0000 pid=3219 clone guuid=ea6d8148-1800-0000-5290-6387940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=ea6d8148-1800-0000-5290-6387940c0000 pid=3220 execve guuid=b34e9c4d-1800-0000-5290-6387960c0000 pid=3222 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=b34e9c4d-1800-0000-5290-6387960c0000 pid=3222 execve guuid=5d27f74d-1800-0000-5290-6387970c0000 pid=3223 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=5d27f74d-1800-0000-5290-6387970c0000 pid=3223 clone guuid=b271fe4d-1800-0000-5290-6387980c0000 pid=3224 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=b271fe4d-1800-0000-5290-6387980c0000 pid=3224 execve guuid=48cf6953-1800-0000-5290-6387a20c0000 pid=3234 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=48cf6953-1800-0000-5290-6387a20c0000 pid=3234 execve guuid=f87fa653-1800-0000-5290-6387a40c0000 pid=3236 /usr/bin/dash guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=f87fa653-1800-0000-5290-6387a40c0000 pid=3236 clone guuid=feedab53-1800-0000-5290-6387a50c0000 pid=3237 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=feedab53-1800-0000-5290-6387a50c0000 pid=3237 execve guuid=32896857-1800-0000-5290-6387b10c0000 pid=3249 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=32896857-1800-0000-5290-6387b10c0000 pid=3249 execve guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251 /tmp/bot.x86 net guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251 execve guuid=4d61ce57-1800-0000-5290-6387b50c0000 pid=3253 /usr/bin/wget net send-data write-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=4d61ce57-1800-0000-5290-6387b50c0000 pid=3253 execve guuid=de13135b-1800-0000-5290-6387bf0c0000 pid=3263 /usr/bin/chmod guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=de13135b-1800-0000-5290-6387bf0c0000 pid=3263 execve guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264 /tmp/bot.x86_64 mprotect-exec net guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264 execve guuid=db37665b-1800-0000-5290-6387c20c0000 pid=3266 /usr/bin/rm delete-file guuid=17e6ab0b-1800-0000-5290-6387f20b0000 pid=3058->guuid=db37665b-1800-0000-5290-6387c20c0000 pid=3266 execve 40d66be2-de25-513e-9984-047c1ab266b3 176.65.139.81:80 guuid=0aa1590c-1800-0000-5290-6387f40b0000 pid=3060->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=02bb6414-1800-0000-5290-6387070c0000 pid=3079->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=9f7aca19-1800-0000-5290-6387150c0000 pid=3093->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=3d4d161e-1800-0000-5290-6387240c0000 pid=3108->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=6bc3e822-1800-0000-5290-6387360c0000 pid=3126->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=a2d7ee2d-1800-0000-5290-6387590c0000 pid=3161->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0c96c332-1800-0000-5290-6387650c0000 pid=3173 /tmp/bot.i486 zombie guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171->guuid=0c96c332-1800-0000-5290-6387650c0000 pid=3173 clone guuid=095bc632-1800-0000-5290-6387660c0000 pid=3174 /tmp/bot.i486 guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171->guuid=095bc632-1800-0000-5290-6387660c0000 pid=3174 clone guuid=221ac932-1800-0000-5290-6387670c0000 pid=3175 /tmp/bot.i486 net send-data zombie guuid=3b819c32-1800-0000-5290-6387630c0000 pid=3171->guuid=221ac932-1800-0000-5290-6387670c0000 pid=3175 clone guuid=b08da232-1800-0000-5290-6387640c0000 pid=3172->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=221ac932-1800-0000-5290-6387670c0000 pid=3175->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ca6eb703-52b1-5df7-b46e-190fd0fd968a 176.65.139.81:3778 guuid=221ac932-1800-0000-5290-6387670c0000 pid=3175->ca6eb703-52b1-5df7-b46e-190fd0fd968a send: 11B guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=43f59236-1800-0000-5290-6387750c0000 pid=3189 /tmp/bot.i686 guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186->guuid=43f59236-1800-0000-5290-6387750c0000 pid=3189 clone guuid=f29a9a36-1800-0000-5290-6387760c0000 pid=3190 /tmp/bot.i686 guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186->guuid=f29a9a36-1800-0000-5290-6387760c0000 pid=3190 clone guuid=85519e36-1800-0000-5290-6387770c0000 pid=3191 /tmp/bot.i686 net send-data zombie guuid=f8685c36-1800-0000-5290-6387720c0000 pid=3186->guuid=85519e36-1800-0000-5290-6387770c0000 pid=3191 clone guuid=4acf6036-1800-0000-5290-6387730c0000 pid=3187->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=85519e36-1800-0000-5290-6387770c0000 pid=3191->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=85519e36-1800-0000-5290-6387770c0000 pid=3191->ca6eb703-52b1-5df7-b46e-190fd0fd968a send: 11B guuid=14f6c63a-1800-0000-5290-6387830c0000 pid=3203->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=edd4e43e-1800-0000-5290-63878c0c0000 pid=3212->40d66be2-de25-513e-9984-047c1ab266b3 send: 150B guuid=6f286643-1800-0000-5290-6387900c0000 pid=3216->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=ea6d8148-1800-0000-5290-6387940c0000 pid=3220->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=b271fe4d-1800-0000-5290-6387980c0000 pid=3224->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=feedab53-1800-0000-5290-6387a50c0000 pid=3237->40d66be2-de25-513e-9984-047c1ab266b3 send: 149B guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c1aff657-1800-0000-5290-6387b60c0000 pid=3254 /tmp/bot.x86 guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251->guuid=c1aff657-1800-0000-5290-6387b60c0000 pid=3254 clone guuid=6eaffa57-1800-0000-5290-6387b70c0000 pid=3255 /tmp/bot.x86 guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251->guuid=6eaffa57-1800-0000-5290-6387b70c0000 pid=3255 clone guuid=1a8ffe57-1800-0000-5290-6387b80c0000 pid=3256 /tmp/bot.x86 net send-data zombie guuid=1142c857-1800-0000-5290-6387b30c0000 pid=3251->guuid=1a8ffe57-1800-0000-5290-6387b80c0000 pid=3256 clone guuid=4d61ce57-1800-0000-5290-6387b50c0000 pid=3253->40d66be2-de25-513e-9984-047c1ab266b3 send: 152B guuid=1a8ffe57-1800-0000-5290-6387b80c0000 pid=3256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1a8ffe57-1800-0000-5290-6387b80c0000 pid=3256->ca6eb703-52b1-5df7-b46e-190fd0fd968a send: 8B guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5686895b-1800-0000-5290-6387c30c0000 pid=3267 /tmp/bot.x86_64 guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264->guuid=5686895b-1800-0000-5290-6387c30c0000 pid=3267 clone guuid=efe58c5b-1800-0000-5290-6387c40c0000 pid=3268 /tmp/bot.x86_64 zombie guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264->guuid=efe58c5b-1800-0000-5290-6387c40c0000 pid=3268 clone guuid=6431905b-1800-0000-5290-6387c50c0000 pid=3269 /tmp/bot.x86_64 net send-data zombie guuid=ed85565b-1800-0000-5290-6387c00c0000 pid=3264->guuid=6431905b-1800-0000-5290-6387c50c0000 pid=3269 clone guuid=6431905b-1800-0000-5290-6387c50c0000 pid=3269->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6431905b-1800-0000-5290-6387c50c0000 pid=3269->ca6eb703-52b1-5df7-b46e-190fd0fd968a send: 11B
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2026-04-01 22:49:20 UTC
File Type:
Text (Shell)
AV detection:
1 of 36 (2.78%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f8e2d3a3a3db818c52bf4dc4ab6ba9ce6e8195cf1977ff13d889eb635d7c81f1

(this sample)

  
Delivery method
Distributed via web download

Comments