MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fca0b419653c29b2b3c30df673d8810227ed32743035f7f063f005c540a6f45e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: fca0b419653c29b2b3c30df673d8810227ed32743035f7f063f005c540a6f45e
SHA3-384 hash: de189c0b73b88cb7a7b8eeb6af221b6c62dfa036d620044c20efb9f91ebb86f01b1f5cf73f52e078f9b22181a21e1cbf
SHA1 hash: 68037301289ffebb5187eab921171a297b5cd7a3
MD5 hash: 2c57715711dd9d1da1c02bee5f2ac7df
humanhash: diet-oklahoma-missouri-carbon
File name:massload
Download: download sample
Signature Mirai
File size:2'583 bytes
First seen:2025-12-19 05:21:20 UTC
Last seen:2025-12-19 14:41:10 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:z5EMy0MBkUtU7xU+UVaUCU9WUbUVJU5UzKXRCAUTAU73XU8XUVozUQzU9UgHhUFW:z563mjCBHFHmbOOjuoXT4
TLSH T1125150B829719F374C65DF8770224BB9740FACCFE8A48B5C949F24FC8E6A505741071A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.208.158.242/mips0e1ab2890eef2d63ca248b23f71f63b0bb2654799a9147843f9a7fa197fe0818 Mirai32-bit elf mirai Mozi
http://185.208.158.242/mpslf717ada653d0adf9a0f1a7c338c9b03521fdc0d8a78356dffc7226c47588dea7 Miraielf geofenced mips mirai ua-wget USA
http://185.208.158.242/arm4n/an/aelf ua-wget
http://185.208.158.242/arm5fd853807beb17822d8654b02f8ab34feb54f60e2d844cdce29a0a4976725739c Miraiarm elf geofenced mirai ua-wget USA
http://185.208.158.242/arm7c819cd3e58864a49bd657b76cf4d8959b82e39ce99acd9e2cfd4658172aa5d64 Miraiarm elf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-19T03:15:00Z UTC
Last seen:
2025-12-20T12:21:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=3160467d-1900-0000-ad38-f9385b100000 pid=4187 /usr/bin/sudo guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196 /tmp/sample.bin guuid=3160467d-1900-0000-ad38-f9385b100000 pid=4187->guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196 execve guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197 clone guuid=a8ab0b80-1900-0000-ad38-f9386d100000 pid=4205 /usr/bin/cp write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=a8ab0b80-1900-0000-ad38-f9386d100000 pid=4205 execve guuid=f347db84-1900-0000-ad38-f93882100000 pid=4226 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=f347db84-1900-0000-ad38-f93882100000 pid=4226 execve guuid=98872885-1900-0000-ad38-f93883100000 pid=4227 /usr/bin/rm delete-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=98872885-1900-0000-ad38-f93883100000 pid=4227 execve guuid=01ad6e85-1900-0000-ad38-f93886100000 pid=4230 /usr/bin/rm delete-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=01ad6e85-1900-0000-ad38-f93886100000 pid=4230 execve guuid=e0331187-1900-0000-ad38-f9388f100000 pid=4239 /usr/bin/wget net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=e0331187-1900-0000-ad38-f9388f100000 pid=4239 execve guuid=9a7d4791-1900-0000-ad38-f938b7100000 pid=4279 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=9a7d4791-1900-0000-ad38-f938b7100000 pid=4279 execve guuid=50aca991-1900-0000-ad38-f938b9100000 pid=4281 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=50aca991-1900-0000-ad38-f938b9100000 pid=4281 clone guuid=4fc91793-1900-0000-ad38-f938bd100000 pid=4285 /usr/bin/wget net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=4fc91793-1900-0000-ad38-f938bd100000 pid=4285 execve guuid=1977ed9b-1900-0000-ad38-f938dd100000 pid=4317 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=1977ed9b-1900-0000-ad38-f938dd100000 pid=4317 execve guuid=c724299c-1900-0000-ad38-f938df100000 pid=4319 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=c724299c-1900-0000-ad38-f938df100000 pid=4319 clone guuid=9185c89c-1900-0000-ad38-f938e2100000 pid=4322 /usr/bin/wget net send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=9185c89c-1900-0000-ad38-f938e2100000 pid=4322 execve guuid=956329a1-1900-0000-ad38-f938f4100000 pid=4340 /usr/bin/busybox net send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=956329a1-1900-0000-ad38-f938f4100000 pid=4340 execve guuid=4d9c43a4-1900-0000-ad38-f93801110000 pid=4353 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=4d9c43a4-1900-0000-ad38-f93801110000 pid=4353 execve guuid=454e84a4-1900-0000-ad38-f93803110000 pid=4355 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=454e84a4-1900-0000-ad38-f93803110000 pid=4355 clone guuid=e22093a4-1900-0000-ad38-f93804110000 pid=4356 /usr/bin/wget net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=e22093a4-1900-0000-ad38-f93804110000 pid=4356 execve guuid=d278b5ac-1900-0000-ad38-f9382a110000 pid=4394 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=d278b5ac-1900-0000-ad38-f9382a110000 pid=4394 execve guuid=60dfe6ac-1900-0000-ad38-f9382c110000 pid=4396 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=60dfe6ac-1900-0000-ad38-f9382c110000 pid=4396 clone guuid=59db99ad-1900-0000-ad38-f93830110000 pid=4400 /usr/bin/wget net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=59db99ad-1900-0000-ad38-f93830110000 pid=4400 execve guuid=57131eb5-1900-0000-ad38-f93851110000 pid=4433 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=57131eb5-1900-0000-ad38-f93851110000 pid=4433 execve guuid=cf5f54b5-1900-0000-ad38-f93852110000 pid=4434 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=cf5f54b5-1900-0000-ad38-f93852110000 pid=4434 clone guuid=5c37dbb5-1900-0000-ad38-f93857110000 pid=4439 /usr/bin/curl net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=5c37dbb5-1900-0000-ad38-f93857110000 pid=4439 execve guuid=0fe6e2c0-1900-0000-ad38-f93886110000 pid=4486 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=0fe6e2c0-1900-0000-ad38-f93886110000 pid=4486 execve guuid=24da1ec1-1900-0000-ad38-f93887110000 pid=4487 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=24da1ec1-1900-0000-ad38-f93887110000 pid=4487 clone guuid=90471dc2-1900-0000-ad38-f9388e110000 pid=4494 /usr/bin/curl net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=90471dc2-1900-0000-ad38-f9388e110000 pid=4494 execve guuid=5e4b6bce-1900-0000-ad38-f938b2110000 pid=4530 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=5e4b6bce-1900-0000-ad38-f938b2110000 pid=4530 execve guuid=14d1abce-1900-0000-ad38-f938b4110000 pid=4532 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=14d1abce-1900-0000-ad38-f938b4110000 pid=4532 clone guuid=30eb91cf-1900-0000-ad38-f938b7110000 pid=4535 /usr/bin/curl net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=30eb91cf-1900-0000-ad38-f938b7110000 pid=4535 execve guuid=726f53d5-1900-0000-ad38-f938c9110000 pid=4553 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=726f53d5-1900-0000-ad38-f938c9110000 pid=4553 execve guuid=09aca1d5-1900-0000-ad38-f938ca110000 pid=4554 /dev/arm4 guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=09aca1d5-1900-0000-ad38-f938ca110000 pid=4554 execve guuid=943ddcd5-1900-0000-ad38-f938ce110000 pid=4558 /usr/bin/curl net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=943ddcd5-1900-0000-ad38-f938ce110000 pid=4558 execve guuid=41e965de-1900-0000-ad38-f938fa110000 pid=4602 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=41e965de-1900-0000-ad38-f938fa110000 pid=4602 execve guuid=9986b7de-1900-0000-ad38-f938fc110000 pid=4604 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=9986b7de-1900-0000-ad38-f938fc110000 pid=4604 clone guuid=20d5aadf-1900-0000-ad38-f93801120000 pid=4609 /usr/bin/curl net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=20d5aadf-1900-0000-ad38-f93801120000 pid=4609 execve guuid=262ebfe9-1900-0000-ad38-f93826120000 pid=4646 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=262ebfe9-1900-0000-ad38-f93826120000 pid=4646 execve guuid=064275ea-1900-0000-ad38-f9382a120000 pid=4650 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=064275ea-1900-0000-ad38-f9382a120000 pid=4650 clone guuid=e77ca2eb-1900-0000-ad38-f9382e120000 pid=4654 /usr/bin/busybox net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=e77ca2eb-1900-0000-ad38-f9382e120000 pid=4654 execve guuid=cba9b0fe-1900-0000-ad38-f93860120000 pid=4704 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=cba9b0fe-1900-0000-ad38-f93860120000 pid=4704 execve guuid=cf5520ff-1900-0000-ad38-f93862120000 pid=4706 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=cf5520ff-1900-0000-ad38-f93862120000 pid=4706 clone guuid=3efba900-1a00-0000-ad38-f93868120000 pid=4712 /usr/bin/busybox net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=3efba900-1a00-0000-ad38-f93868120000 pid=4712 execve guuid=aa2a3715-1a00-0000-ad38-f938a8120000 pid=4776 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=aa2a3715-1a00-0000-ad38-f938a8120000 pid=4776 execve guuid=433d9c15-1a00-0000-ad38-f938a9120000 pid=4777 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=433d9c15-1a00-0000-ad38-f938a9120000 pid=4777 clone guuid=c4357316-1a00-0000-ad38-f938ad120000 pid=4781 /usr/bin/busybox net send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=c4357316-1a00-0000-ad38-f938ad120000 pid=4781 execve guuid=527e4624-1a00-0000-ad38-f938c7120000 pid=4807 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=527e4624-1a00-0000-ad38-f938c7120000 pid=4807 execve guuid=8616c524-1a00-0000-ad38-f938ca120000 pid=4810 /dev/arm4 guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=8616c524-1a00-0000-ad38-f938ca120000 pid=4810 execve guuid=f11d3125-1a00-0000-ad38-f938cc120000 pid=4812 /usr/bin/busybox net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=f11d3125-1a00-0000-ad38-f938cc120000 pid=4812 execve guuid=b2c69338-1a00-0000-ad38-f938fa120000 pid=4858 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=b2c69338-1a00-0000-ad38-f938fa120000 pid=4858 execve guuid=392a4339-1a00-0000-ad38-f938fc120000 pid=4860 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=392a4339-1a00-0000-ad38-f938fc120000 pid=4860 clone guuid=5fbd7c3b-1a00-0000-ad38-f93802130000 pid=4866 /usr/bin/busybox net send-data write-file guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=5fbd7c3b-1a00-0000-ad38-f93802130000 pid=4866 execve guuid=c6d7354f-1a00-0000-ad38-f9382b130000 pid=4907 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=c6d7354f-1a00-0000-ad38-f9382b130000 pid=4907 execve guuid=5c37d74f-1a00-0000-ad38-f9382e130000 pid=4910 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=5c37d74f-1a00-0000-ad38-f9382e130000 pid=4910 clone guuid=3ff9a450-1a00-0000-ad38-f93832130000 pid=4914 /usr/bin/busybox send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=3ff9a450-1a00-0000-ad38-f93832130000 pid=4914 execve guuid=6c92d853-1d00-0000-ad38-f938d5140000 pid=5333 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=6c92d853-1d00-0000-ad38-f938d5140000 pid=5333 execve guuid=2bc56254-1d00-0000-ad38-f938d6140000 pid=5334 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=2bc56254-1d00-0000-ad38-f938d6140000 pid=5334 clone guuid=b0599255-1d00-0000-ad38-f938d8140000 pid=5336 /usr/bin/busybox send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=b0599255-1d00-0000-ad38-f938d8140000 pid=5336 execve guuid=f2b82059-2000-0000-ad38-f938d9140000 pid=5337 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=f2b82059-2000-0000-ad38-f938d9140000 pid=5337 execve guuid=aca8a759-2000-0000-ad38-f938da140000 pid=5338 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=aca8a759-2000-0000-ad38-f938da140000 pid=5338 clone guuid=1446cb5a-2000-0000-ad38-f938dc140000 pid=5340 /usr/bin/busybox send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=1446cb5a-2000-0000-ad38-f938dc140000 pid=5340 execve guuid=91f64b5e-2300-0000-ad38-f938dd140000 pid=5341 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=91f64b5e-2300-0000-ad38-f938dd140000 pid=5341 execve guuid=6472cc5e-2300-0000-ad38-f938de140000 pid=5342 /dev/arm4 guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=6472cc5e-2300-0000-ad38-f938de140000 pid=5342 execve guuid=4f8b4d5f-2300-0000-ad38-f938df140000 pid=5343 /usr/bin/busybox send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=4f8b4d5f-2300-0000-ad38-f938df140000 pid=5343 execve guuid=b3bbcd62-2600-0000-ad38-f938e0140000 pid=5344 /usr/bin/chmod guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=b3bbcd62-2600-0000-ad38-f938e0140000 pid=5344 execve guuid=ab311363-2600-0000-ad38-f938e1140000 pid=5345 /usr/bin/dash guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=ab311363-2600-0000-ad38-f938e1140000 pid=5345 clone guuid=9a5aa863-2600-0000-ad38-f938e3140000 pid=5347 /usr/bin/busybox send-data guuid=d1f6ee7e-1900-0000-ad38-f93864100000 pid=4196->guuid=9a5aa863-2600-0000-ad38-f938e3140000 pid=5347 execve guuid=d23b277f-1900-0000-ad38-f93866100000 pid=4198 /usr/bin/cat guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197->guuid=d23b277f-1900-0000-ad38-f93866100000 pid=4198 execve guuid=af742c7f-1900-0000-ad38-f93867100000 pid=4199 /usr/bin/grep guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197->guuid=af742c7f-1900-0000-ad38-f93867100000 pid=4199 execve guuid=e3bc2f7f-1900-0000-ad38-f93868100000 pid=4200 /usr/bin/grep guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197->guuid=e3bc2f7f-1900-0000-ad38-f93868100000 pid=4200 execve guuid=2aab357f-1900-0000-ad38-f93869100000 pid=4201 /usr/bin/grep guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197->guuid=2aab357f-1900-0000-ad38-f93869100000 pid=4201 execve guuid=730c3b7f-1900-0000-ad38-f9386a100000 pid=4202 /usr/bin/cut guuid=54aa207f-1900-0000-ad38-f93865100000 pid=4197->guuid=730c3b7f-1900-0000-ad38-f9386a100000 pid=4202 execve eb09858a-0b1f-5324-bcea-dad94e0f7bd5 185.208.158.242:80 guuid=e0331187-1900-0000-ad38-f9388f100000 pid=4239->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 134B guuid=4fc91793-1900-0000-ad38-f938bd100000 pid=4285->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 134B guuid=9185c89c-1900-0000-ad38-f938e2100000 pid=4322->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 134B guuid=956329a1-1900-0000-ad38-f938f4100000 pid=4340->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 82B guuid=e22093a4-1900-0000-ad38-f93804110000 pid=4356->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 134B guuid=59db99ad-1900-0000-ad38-f93830110000 pid=4400->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 134B guuid=5c37dbb5-1900-0000-ad38-f93857110000 pid=4439->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 83B guuid=90471dc2-1900-0000-ad38-f9388e110000 pid=4494->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 83B guuid=30eb91cf-1900-0000-ad38-f938b7110000 pid=4535->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 83B guuid=943ddcd5-1900-0000-ad38-f938ce110000 pid=4558->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 83B guuid=20d5aadf-1900-0000-ad38-f93801120000 pid=4609->eb09858a-0b1f-5324-bcea-dad94e0f7bd5 send: 83B 8f7e109d-be55-57f3-bece-0f2d04166848 185.208.158.242:21 guuid=e77ca2eb-1900-0000-ad38-f9382e120000 pid=4654->8f7e109d-be55-57f3-bece-0f2d04166848 send: 78B 6c8233e4-7db0-567d-ace5-5df9210d9c3b 185.208.158.242:36463 guuid=e77ca2eb-1900-0000-ad38-f9382e120000 pid=4654->6c8233e4-7db0-567d-ace5-5df9210d9c3b con guuid=3efba900-1a00-0000-ad38-f93868120000 pid=4712->8f7e109d-be55-57f3-bece-0f2d04166848 send: 78B 9a92f9a5-7d8c-5496-a5f4-f1209feb0672 185.208.158.242:38023 guuid=3efba900-1a00-0000-ad38-f93868120000 pid=4712->9a92f9a5-7d8c-5496-a5f4-f1209feb0672 con guuid=c4357316-1a00-0000-ad38-f938ad120000 pid=4781->8f7e109d-be55-57f3-bece-0f2d04166848 send: 72B 6b760c79-7e58-523d-a215-188307d9101b 185.208.158.242:44103 guuid=c4357316-1a00-0000-ad38-f938ad120000 pid=4781->6b760c79-7e58-523d-a215-188307d9101b con guuid=f11d3125-1a00-0000-ad38-f938cc120000 pid=4812->8f7e109d-be55-57f3-bece-0f2d04166848 send: 78B c5bec686-1e86-5024-97dd-f2293400c67c 185.208.158.242:36753 guuid=f11d3125-1a00-0000-ad38-f938cc120000 pid=4812->c5bec686-1e86-5024-97dd-f2293400c67c con guuid=5fbd7c3b-1a00-0000-ad38-f93802130000 pid=4866->8f7e109d-be55-57f3-bece-0f2d04166848 send: 78B 70a21d3a-06cd-5a84-b00b-29f0980b3a8a 185.208.158.242:34899 guuid=5fbd7c3b-1a00-0000-ad38-f93802130000 pid=4866->70a21d3a-06cd-5a84-b00b-29f0980b3a8a con 78e8123d-bcb7-5c2b-876e-888a3066add6 185.208.158.242:69 guuid=3ff9a450-1a00-0000-ad38-f93832130000 pid=4914->78e8123d-bcb7-5c2b-876e-888a3066add6 send: 252B guuid=b0599255-1d00-0000-ad38-f938d8140000 pid=5336->78e8123d-bcb7-5c2b-876e-888a3066add6 send: 252B guuid=1446cb5a-2000-0000-ad38-f938dc140000 pid=5340->78e8123d-bcb7-5c2b-876e-888a3066add6 send: 252B guuid=4f8b4d5f-2300-0000-ad38-f938df140000 pid=5343->78e8123d-bcb7-5c2b-876e-888a3066add6 send: 252B guuid=9a5aa863-2600-0000-ad38-f938e3140000 pid=5347->78e8123d-bcb7-5c2b-876e-888a3066add6 send: 189B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-19 06:18:18 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Checks CPU configuration
Reads process memory
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Deletes system logs
Executes dropped EXE
Renames itself
Unexpected DNS network traffic destination
Contacts a large (29041) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fca0b419653c29b2b3c30df673d8810227ed32743035f7f063f005c540a6f45e

(this sample)

  
Delivery method
Distributed via web download

Comments