MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fcbde44de84bd52312b5497108ff960b1c3b83a1a760535571dc7e3676e8b708. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: fcbde44de84bd52312b5497108ff960b1c3b83a1a760535571dc7e3676e8b708
SHA3-384 hash: 5f5a395f5d5b69414816b994a61a6db0074a1a5f8b78ad0a549137c303365bb84cba02e9c9e8aab987116160e9bba129
SHA1 hash: 512efac5c999cccdc4336eb7529a7c66ad21dca4
MD5 hash: 56c7916816349aebe450a16257b8448c
humanhash: rugby-william-shade-shade
File name:cat.sh
Download: download sample
File size:4'029 bytes
First seen:2026-04-11 09:14:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:faHhTshhdYgEhqmThP/R/Wh/EECEPhErQ8QpjhQpfL4h+IvIshICIqI3hIDIVNIy:EQ0T6/Vjgchwsy/H3yEVuVSyVNv0++
TLSH T15F81F68E235281F96C48ED17F471DF9078D09DD20DDB8F88CECD6B52A58CD647439AA1
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.130.214.71:1212/zyre.apk5a9596683c81795db6460a46bf2815d5add974f9abf647886d8c3a8adaf2223c Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.arm4e9cff21e91ce80f33761642ee8dd103de41ba0c185e2b63e10bdee9fb5bbe52f Gafgytelf gafgyt ua-wget
http://103.130.214.71:1212/zyre.arm53a39371ec2159897202d4711af93d6fb8bc6512733aeb2891d5f08a35bfd76ee Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.arm6f4e22081613108997397cb9f06a085560dc0b5df24bcadf95b19b7d7eddf8977 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.arm7bae9f047a954897fd367e3d7b796fe7821356c6ad4da521f42e044fd56bc9312 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.dbg831743b8b8e86014ce0837f05e12210794426f0751744492b23bb3b27fb1abba Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.i486c9ebb56f8b65387714a3d34a13605144f72b4d0c3e6aac21b1dd7e7406efbb29 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.i686f3e0e3a64129d9ab9f1f5f63c3234fc8cfefecd2e42e0e048fc04eb35be3094e Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.m68k8b20f7796ccace087779e32e7b76d010fc216419f48cda872b7f21e51f961e07 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.mipsf353dfd83a50b2924f183f6b7bd4bbd9b8fe77698156b11d85959f86cac18c2e Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.mpsl280b43127e0ec992fcf8675ccdfca0f947bda32ba72a085c013a003051f9be84 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.sh4a4dd867f512c7fb2d17eccb98829c74d6df637f1acb66313dbece5d061c4f8b6 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.spc51a9f4cce2454c7b20323181b042cc33c60820e639c9783b3bea4720162da753 Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.x64e428787b8ef1a9817f5f3629a1ecdd3271c368783153acdcea6ab35aa142f07a Miraielf mirai ua-wget
http://103.130.214.71:1212/zyre.x86324f1f8d21316886aac155d7fe025d4d138b045a980add95d9100c036d0099d0 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-08T20:55:00Z UTC
Last seen:
2026-04-13T02:50:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9b299dac-1600-0000-10ce-c616770e0000 pid=3703 /usr/bin/sudo guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712 /tmp/sample.bin guuid=9b299dac-1600-0000-10ce-c616770e0000 pid=3703->guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712 execve guuid=fea346af-1600-0000-10ce-c616820e0000 pid=3714 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=fea346af-1600-0000-10ce-c616820e0000 pid=3714 clone guuid=53cc6fed-1600-0000-10ce-c616480f0000 pid=3912 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=53cc6fed-1600-0000-10ce-c616480f0000 pid=3912 execve guuid=c6bbf4ed-1600-0000-10ce-c6164a0f0000 pid=3914 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=c6bbf4ed-1600-0000-10ce-c6164a0f0000 pid=3914 clone guuid=1128f5ee-1600-0000-10ce-c6164e0f0000 pid=3918 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=1128f5ee-1600-0000-10ce-c6164e0f0000 pid=3918 execve guuid=de1556ef-1600-0000-10ce-c616520f0000 pid=3922 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=de1556ef-1600-0000-10ce-c616520f0000 pid=3922 clone guuid=a3f0792b-1700-0000-10ce-c616f50f0000 pid=4085 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=a3f0792b-1700-0000-10ce-c616f50f0000 pid=4085 execve guuid=7367ee2b-1700-0000-10ce-c616f60f0000 pid=4086 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=7367ee2b-1700-0000-10ce-c616f60f0000 pid=4086 clone guuid=f1e4eb2c-1700-0000-10ce-c616fc0f0000 pid=4092 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=f1e4eb2c-1700-0000-10ce-c616fc0f0000 pid=4092 execve guuid=f0db522d-1700-0000-10ce-c616fe0f0000 pid=4094 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=f0db522d-1700-0000-10ce-c616fe0f0000 pid=4094 clone guuid=1aa51660-1700-0000-10ce-c61686100000 pid=4230 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=1aa51660-1700-0000-10ce-c61686100000 pid=4230 execve guuid=9d2db660-1700-0000-10ce-c61687100000 pid=4231 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=9d2db660-1700-0000-10ce-c61687100000 pid=4231 clone guuid=7af4d861-1700-0000-10ce-c6168b100000 pid=4235 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=7af4d861-1700-0000-10ce-c6168b100000 pid=4235 execve guuid=d91b8062-1700-0000-10ce-c6168f100000 pid=4239 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=d91b8062-1700-0000-10ce-c6168f100000 pid=4239 clone guuid=3a25559e-1700-0000-10ce-c61654110000 pid=4436 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=3a25559e-1700-0000-10ce-c61654110000 pid=4436 execve guuid=80ad989e-1700-0000-10ce-c61657110000 pid=4439 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=80ad989e-1700-0000-10ce-c61657110000 pid=4439 clone guuid=8c96339f-1700-0000-10ce-c6165d110000 pid=4445 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=8c96339f-1700-0000-10ce-c6165d110000 pid=4445 execve guuid=6f56769f-1700-0000-10ce-c6165f110000 pid=4447 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=6f56769f-1700-0000-10ce-c6165f110000 pid=4447 clone guuid=49d1f4db-1700-0000-10ce-c61633120000 pid=4659 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=49d1f4db-1700-0000-10ce-c61633120000 pid=4659 execve guuid=b5417ddc-1700-0000-10ce-c61636120000 pid=4662 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=b5417ddc-1700-0000-10ce-c61636120000 pid=4662 clone guuid=628b94dd-1700-0000-10ce-c6163b120000 pid=4667 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=628b94dd-1700-0000-10ce-c6163b120000 pid=4667 execve guuid=fec228de-1700-0000-10ce-c6163e120000 pid=4670 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=fec228de-1700-0000-10ce-c6163e120000 pid=4670 clone guuid=72269926-1800-0000-10ce-c616f8120000 pid=4856 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=72269926-1800-0000-10ce-c616f8120000 pid=4856 execve guuid=867d1a27-1800-0000-10ce-c616fa120000 pid=4858 /tmp/target net send-data guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=867d1a27-1800-0000-10ce-c616fa120000 pid=4858 execve guuid=213e9633-1800-0000-10ce-c6160d130000 pid=4877 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=213e9633-1800-0000-10ce-c6160d130000 pid=4877 execve guuid=9652ed5a-1800-0000-10ce-c6160f130000 pid=4879 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=9652ed5a-1800-0000-10ce-c6160f130000 pid=4879 clone guuid=a347988b-1800-0000-10ce-c61679130000 pid=4985 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=a347988b-1800-0000-10ce-c61679130000 pid=4985 execve guuid=3f22198c-1800-0000-10ce-c6167b130000 pid=4987 /tmp/target net send-data guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=3f22198c-1800-0000-10ce-c6167b130000 pid=4987 execve guuid=637c8798-1800-0000-10ce-c61698130000 pid=5016 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=637c8798-1800-0000-10ce-c61698130000 pid=5016 execve guuid=62521399-1800-0000-10ce-c6169a130000 pid=5018 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=62521399-1800-0000-10ce-c6169a130000 pid=5018 clone guuid=faa862d3-1800-0000-10ce-c61617140000 pid=5143 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=faa862d3-1800-0000-10ce-c61617140000 pid=5143 execve guuid=a965f3d3-1800-0000-10ce-c6161a140000 pid=5146 /tmp/target net send-data guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=a965f3d3-1800-0000-10ce-c6161a140000 pid=5146 execve guuid=c221bce1-1800-0000-10ce-c61633140000 pid=5171 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=c221bce1-1800-0000-10ce-c61633140000 pid=5171 execve guuid=7eef54e2-1800-0000-10ce-c61635140000 pid=5173 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=7eef54e2-1800-0000-10ce-c61635140000 pid=5173 clone guuid=36e7181f-1900-0000-10ce-c6168e140000 pid=5262 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=36e7181f-1900-0000-10ce-c6168e140000 pid=5262 execve guuid=76b46f1f-1900-0000-10ce-c61690140000 pid=5264 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=76b46f1f-1900-0000-10ce-c61690140000 pid=5264 clone guuid=0793ff1f-1900-0000-10ce-c61692140000 pid=5266 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=0793ff1f-1900-0000-10ce-c61692140000 pid=5266 execve guuid=aedc5120-1900-0000-10ce-c61694140000 pid=5268 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=aedc5120-1900-0000-10ce-c61694140000 pid=5268 clone guuid=c3211164-1900-0000-10ce-c6169e140000 pid=5278 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=c3211164-1900-0000-10ce-c6169e140000 pid=5278 execve guuid=d4726764-1900-0000-10ce-c6169f140000 pid=5279 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=d4726764-1900-0000-10ce-c6169f140000 pid=5279 clone guuid=994b3666-1900-0000-10ce-c616a1140000 pid=5281 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=994b3666-1900-0000-10ce-c616a1140000 pid=5281 execve guuid=17619466-1900-0000-10ce-c616a2140000 pid=5282 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=17619466-1900-0000-10ce-c616a2140000 pid=5282 clone guuid=11e371a3-1900-0000-10ce-c616a4140000 pid=5284 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=11e371a3-1900-0000-10ce-c616a4140000 pid=5284 execve guuid=ab7ed7a3-1900-0000-10ce-c616a5140000 pid=5285 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=ab7ed7a3-1900-0000-10ce-c616a5140000 pid=5285 clone guuid=91d39ca4-1900-0000-10ce-c616a7140000 pid=5287 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=91d39ca4-1900-0000-10ce-c616a7140000 pid=5287 execve guuid=5784f3a4-1900-0000-10ce-c616a8140000 pid=5288 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=5784f3a4-1900-0000-10ce-c616a8140000 pid=5288 clone guuid=66dae2d6-1900-0000-10ce-c616aa140000 pid=5290 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=66dae2d6-1900-0000-10ce-c616aa140000 pid=5290 execve guuid=a884aad7-1900-0000-10ce-c616ab140000 pid=5291 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=a884aad7-1900-0000-10ce-c616ab140000 pid=5291 clone guuid=aec070d8-1900-0000-10ce-c616ad140000 pid=5293 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=aec070d8-1900-0000-10ce-c616ad140000 pid=5293 execve guuid=3b7fccd8-1900-0000-10ce-c616ae140000 pid=5294 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=3b7fccd8-1900-0000-10ce-c616ae140000 pid=5294 clone guuid=8bcd2f17-1a00-0000-10ce-c616b7140000 pid=5303 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=8bcd2f17-1a00-0000-10ce-c616b7140000 pid=5303 execve guuid=daa49017-1a00-0000-10ce-c616b8140000 pid=5304 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=daa49017-1a00-0000-10ce-c616b8140000 pid=5304 clone guuid=aa57a118-1a00-0000-10ce-c616ba140000 pid=5306 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=aa57a118-1a00-0000-10ce-c616ba140000 pid=5306 execve guuid=2c551b19-1a00-0000-10ce-c616bb140000 pid=5307 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=2c551b19-1a00-0000-10ce-c616bb140000 pid=5307 clone guuid=8fea2f4b-1a00-0000-10ce-c616bd140000 pid=5309 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=8fea2f4b-1a00-0000-10ce-c616bd140000 pid=5309 execve guuid=eddfb34b-1a00-0000-10ce-c616be140000 pid=5310 /tmp/target net send-data guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=eddfb34b-1a00-0000-10ce-c616be140000 pid=5310 execve guuid=b77c3159-1a00-0000-10ce-c616c0140000 pid=5312 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=b77c3159-1a00-0000-10ce-c616c0140000 pid=5312 execve guuid=4a34556c-1a00-0000-10ce-c616c1140000 pid=5313 /usr/bin/bash guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=4a34556c-1a00-0000-10ce-c616c1140000 pid=5313 clone guuid=e09911a0-1a00-0000-10ce-c616c3140000 pid=5315 /usr/bin/chmod guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=e09911a0-1a00-0000-10ce-c616c3140000 pid=5315 execve guuid=8dea4ea0-1a00-0000-10ce-c616c4140000 pid=5316 /tmp/target net send-data guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=8dea4ea0-1a00-0000-10ce-c616c4140000 pid=5316 execve guuid=9a7c3fad-1a00-0000-10ce-c616c6140000 pid=5318 /usr/bin/rm delete-file guuid=ce89ebae-1600-0000-10ce-c616800e0000 pid=3712->guuid=9a7c3fad-1a00-0000-10ce-c616c6140000 pid=5318 execve guuid=4ada73af-1600-0000-10ce-c616830e0000 pid=3715 /usr/bin/wget net send-data write-file guuid=fea346af-1600-0000-10ce-c616820e0000 pid=3714->guuid=4ada73af-1600-0000-10ce-c616830e0000 pid=3715 execve 9d944b7b-5602-507b-b9b6-87b651bc0ff5 103.130.214.71:1212 guuid=4ada73af-1600-0000-10ce-c616830e0000 pid=3715->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B guuid=458b96ef-1600-0000-10ce-c616530f0000 pid=3923 /usr/bin/wget net send-data write-file guuid=de1556ef-1600-0000-10ce-c616520f0000 pid=3922->guuid=458b96ef-1600-0000-10ce-c616530f0000 pid=3923 execve guuid=458b96ef-1600-0000-10ce-c616530f0000 pid=3923->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=bf43642d-1700-0000-10ce-c616ff0f0000 pid=4095 /usr/bin/wget net send-data write-file guuid=f0db522d-1700-0000-10ce-c616fe0f0000 pid=4094->guuid=bf43642d-1700-0000-10ce-c616ff0f0000 pid=4095 execve guuid=bf43642d-1700-0000-10ce-c616ff0f0000 pid=4095->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=2e029762-1700-0000-10ce-c61690100000 pid=4240 /usr/bin/wget net send-data write-file guuid=d91b8062-1700-0000-10ce-c6168f100000 pid=4239->guuid=2e029762-1700-0000-10ce-c61690100000 pid=4240 execve guuid=2e029762-1700-0000-10ce-c61690100000 pid=4240->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=8285889f-1700-0000-10ce-c61662110000 pid=4450 /usr/bin/wget net send-data write-file guuid=6f56769f-1700-0000-10ce-c6165f110000 pid=4447->guuid=8285889f-1700-0000-10ce-c61662110000 pid=4450 execve guuid=8285889f-1700-0000-10ce-c61662110000 pid=4450->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=3e8843de-1700-0000-10ce-c6163f120000 pid=4671 /usr/bin/wget net send-data write-file guuid=fec228de-1700-0000-10ce-c6163e120000 pid=4670->guuid=3e8843de-1700-0000-10ce-c6163f120000 pid=4671 execve guuid=3e8843de-1700-0000-10ce-c6163f120000 pid=4671->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=867d1a27-1800-0000-10ce-c616fa120000 pid=4858->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e1dfe4ad-bd09-520e-b47b-5f4160545e50 103.130.214.71:9506 guuid=867d1a27-1800-0000-10ce-c616fa120000 pid=4858->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 56B guuid=4ba77333-1800-0000-10ce-c6160c130000 pid=4876 /tmp/target dns net send-data zombie guuid=867d1a27-1800-0000-10ce-c616fa120000 pid=4858->guuid=4ba77333-1800-0000-10ce-c6160c130000 pid=4876 clone guuid=4ba77333-1800-0000-10ce-c6160c130000 pid=4876->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 840B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=4ba77333-1800-0000-10ce-c6160c130000 pid=4876->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 450B 3f9a79fa-056a-5670-856e-9fd851fb4504 pastebin.com:80 guuid=4ba77333-1800-0000-10ce-c6160c130000 pid=4876->3f9a79fa-056a-5670-856e-9fd851fb4504 send: 690B guuid=8884025b-1800-0000-10ce-c61610130000 pid=4880 /usr/bin/wget net send-data write-file guuid=9652ed5a-1800-0000-10ce-c6160f130000 pid=4879->guuid=8884025b-1800-0000-10ce-c61610130000 pid=4880 execve guuid=8884025b-1800-0000-10ce-c61610130000 pid=4880->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=3f22198c-1800-0000-10ce-c6167b130000 pid=4987->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3f22198c-1800-0000-10ce-c6167b130000 pid=4987->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 57B guuid=66046f98-1800-0000-10ce-c61696130000 pid=5014 /tmp/target dns net send-data zombie guuid=3f22198c-1800-0000-10ce-c6167b130000 pid=4987->guuid=66046f98-1800-0000-10ce-c61696130000 pid=5014 clone guuid=66046f98-1800-0000-10ce-c61696130000 pid=5014->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 855B guuid=66046f98-1800-0000-10ce-c61696130000 pid=5014->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 450B guuid=66046f98-1800-0000-10ce-c61696130000 pid=5014->3f9a79fa-056a-5670-856e-9fd851fb4504 send: 345B guuid=48e52a99-1800-0000-10ce-c6169b130000 pid=5019 /usr/bin/wget net send-data write-file guuid=62521399-1800-0000-10ce-c6169a130000 pid=5018->guuid=48e52a99-1800-0000-10ce-c6169b130000 pid=5019 execve guuid=48e52a99-1800-0000-10ce-c6169b130000 pid=5019->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=a965f3d3-1800-0000-10ce-c6161a140000 pid=5146->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a965f3d3-1800-0000-10ce-c6161a140000 pid=5146->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 57B guuid=dcf0a5e1-1800-0000-10ce-c61632140000 pid=5170 /tmp/target dns net send-data zombie guuid=a965f3d3-1800-0000-10ce-c6161a140000 pid=5146->guuid=dcf0a5e1-1800-0000-10ce-c61632140000 pid=5170 clone guuid=dcf0a5e1-1800-0000-10ce-c61632140000 pid=5170->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 798B guuid=dcf0a5e1-1800-0000-10ce-c61632140000 pid=5170->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 420B guuid=dcf0a5e1-1800-0000-10ce-c61632140000 pid=5170->3f9a79fa-056a-5670-856e-9fd851fb4504 send: 414B guuid=35d6a2e2-1800-0000-10ce-c61636140000 pid=5174 /usr/bin/wget net send-data write-file guuid=7eef54e2-1800-0000-10ce-c61635140000 pid=5173->guuid=35d6a2e2-1800-0000-10ce-c61636140000 pid=5174 execve guuid=35d6a2e2-1800-0000-10ce-c61636140000 pid=5174->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=a55fa520-1900-0000-10ce-c61695140000 pid=5269 /usr/bin/wget net send-data write-file guuid=aedc5120-1900-0000-10ce-c61694140000 pid=5268->guuid=a55fa520-1900-0000-10ce-c61695140000 pid=5269 execve guuid=a55fa520-1900-0000-10ce-c61695140000 pid=5269->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=7ca3a766-1900-0000-10ce-c616a3140000 pid=5283 /usr/bin/wget net send-data write-file guuid=17619466-1900-0000-10ce-c616a2140000 pid=5282->guuid=7ca3a766-1900-0000-10ce-c616a3140000 pid=5283 execve guuid=7ca3a766-1900-0000-10ce-c616a3140000 pid=5283->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=0f3e00a5-1900-0000-10ce-c616a9140000 pid=5289 /usr/bin/wget net send-data write-file guuid=5784f3a4-1900-0000-10ce-c616a8140000 pid=5288->guuid=0f3e00a5-1900-0000-10ce-c616a9140000 pid=5289 execve guuid=0f3e00a5-1900-0000-10ce-c616a9140000 pid=5289->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B guuid=129bdfd8-1900-0000-10ce-c616af140000 pid=5295 /usr/bin/wget net send-data write-file guuid=3b7fccd8-1900-0000-10ce-c616ae140000 pid=5294->guuid=129bdfd8-1900-0000-10ce-c616af140000 pid=5295 execve guuid=129bdfd8-1900-0000-10ce-c616af140000 pid=5295->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B guuid=76b13319-1a00-0000-10ce-c616bc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=2c551b19-1a00-0000-10ce-c616bb140000 pid=5307->guuid=76b13319-1a00-0000-10ce-c616bc140000 pid=5308 execve guuid=76b13319-1a00-0000-10ce-c616bc140000 pid=5308->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B guuid=eddfb34b-1a00-0000-10ce-c616be140000 pid=5310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eddfb34b-1a00-0000-10ce-c616be140000 pid=5310->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 56B guuid=5b071359-1a00-0000-10ce-c616bf140000 pid=5311 /tmp/target dns net send-data zombie guuid=eddfb34b-1a00-0000-10ce-c616be140000 pid=5310->guuid=5b071359-1a00-0000-10ce-c616bf140000 pid=5311 clone guuid=5b071359-1a00-0000-10ce-c616bf140000 pid=5311->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 672B guuid=5b071359-1a00-0000-10ce-c616bf140000 pid=5311->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 390B guuid=5b071359-1a00-0000-10ce-c616bf140000 pid=5311->3f9a79fa-056a-5670-856e-9fd851fb4504 send: 483B guuid=fce56b6c-1a00-0000-10ce-c616c2140000 pid=5314 /usr/bin/wget net send-data write-file guuid=4a34556c-1a00-0000-10ce-c616c1140000 pid=5313->guuid=fce56b6c-1a00-0000-10ce-c616c2140000 pid=5314 execve guuid=fce56b6c-1a00-0000-10ce-c616c2140000 pid=5314->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 142B guuid=8dea4ea0-1a00-0000-10ce-c616c4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8dea4ea0-1a00-0000-10ce-c616c4140000 pid=5316->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 56B guuid=356427ad-1a00-0000-10ce-c616c5140000 pid=5317 /tmp/target dns net send-data zombie guuid=8dea4ea0-1a00-0000-10ce-c616c4140000 pid=5316->guuid=356427ad-1a00-0000-10ce-c616c5140000 pid=5317 clone guuid=356427ad-1a00-0000-10ce-c616c5140000 pid=5317->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 672B guuid=356427ad-1a00-0000-10ce-c616c5140000 pid=5317->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 360B guuid=356427ad-1a00-0000-10ce-c616c5140000 pid=5317->3f9a79fa-056a-5670-856e-9fd851fb4504 send: 483B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-10 02:56:43 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Contacts third-party web service commonly abused for C2
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh fcbde44de84bd52312b5497108ff960b1c3b83a1a760535571dc7e3676e8b708

(this sample)

  
Delivery method
Distributed via web download

Comments