MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fdee6844b2e2283990ac0eb316eb3f6d2f752cf7a273420d8b16358a3fcc4f52. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: fdee6844b2e2283990ac0eb316eb3f6d2f752cf7a273420d8b16358a3fcc4f52
SHA3-384 hash: 7340e5271720c98c6aa56792ffa3f975c9666dbd93a6c5ec56e03ffdcbf938a3619117f09ecffa85b2e030e29254c7f8
SHA1 hash: e7cbacc6d9c3b6fb0947e51a43db5ccd3ed8eaa6
MD5 hash: c3f6d8c008c918bf2a0f37a4074f7ccb
humanhash: low-cup-carbon-social
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2025-12-24 03:21:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vsF+79F+7N7hsF+mF+6GsF+guF+zPsF+2F+KWsF+QF+oUsF+7QF+7o7UsF+fTF+i:vG+7L+7N7hG+o+6GG+gQ+zPG+4+KWG+h
TLSH T15A51848661474E7019A7AE17F7B741283082D061A9E9FFE5DEC8B7F809AED143241B93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://157.15.98.82/hiddenbin/boatnet.x86n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.mipsn/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.arcn/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.mpsln/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.arm71273fc6e6e74de25a906878045fb4acce682c2873bea9f90bbbbbdf32fc738f Mirai32-bit elf mirai Mozi
http://157.15.98.82/hiddenbin/boatnet.arm5n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.arm6n/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.arm7395006c72090f8f0313cef21dc9c104d5176f7d837a3e21cca99016fe705c538 Mirai32-bit elf mirai Mozi
http://157.15.98.82/hiddenbin/boatnet.ppcn/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.m68kn/an/aelf ua-wget
http://157.15.98.82/hiddenbin/boatnet.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-24T00:28:00Z UTC
Last seen:
2025-12-24T00:28:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=5eb26b4b-1900-0000-4346-ea6a67140000 pid=5223 /usr/bin/sudo guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224 /tmp/sample.bin guuid=5eb26b4b-1900-0000-4346-ea6a67140000 pid=5223->guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224 execve guuid=02562a4f-1900-0000-4346-ea6a69140000 pid=5225 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=02562a4f-1900-0000-4346-ea6a69140000 pid=5225 execve guuid=59504e7f-1900-0000-4346-ea6a6a140000 pid=5226 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=59504e7f-1900-0000-4346-ea6a6a140000 pid=5226 execve guuid=91c3adb4-1900-0000-4346-ea6a6b140000 pid=5227 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=91c3adb4-1900-0000-4346-ea6a6b140000 pid=5227 execve guuid=06bc5cb5-1900-0000-4346-ea6a6c140000 pid=5228 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=06bc5cb5-1900-0000-4346-ea6a6c140000 pid=5228 execve guuid=6ba704b6-1900-0000-4346-ea6a6d140000 pid=5229 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=6ba704b6-1900-0000-4346-ea6a6d140000 pid=5229 clone guuid=5bb558b6-1900-0000-4346-ea6a6e140000 pid=5230 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=5bb558b6-1900-0000-4346-ea6a6e140000 pid=5230 execve guuid=1e03c4cd-1900-0000-4346-ea6a6f140000 pid=5231 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=1e03c4cd-1900-0000-4346-ea6a6f140000 pid=5231 execve guuid=abf133e3-1900-0000-4346-ea6a77140000 pid=5239 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=abf133e3-1900-0000-4346-ea6a77140000 pid=5239 execve guuid=868334e5-1900-0000-4346-ea6a78140000 pid=5240 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=868334e5-1900-0000-4346-ea6a78140000 pid=5240 execve guuid=966f4ce6-1900-0000-4346-ea6a79140000 pid=5241 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=966f4ce6-1900-0000-4346-ea6a79140000 pid=5241 clone guuid=63909ce6-1900-0000-4346-ea6a7a140000 pid=5242 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=63909ce6-1900-0000-4346-ea6a7a140000 pid=5242 execve guuid=32c3d5f8-1900-0000-4346-ea6a7b140000 pid=5243 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=32c3d5f8-1900-0000-4346-ea6a7b140000 pid=5243 execve guuid=c37f0c11-1a00-0000-4346-ea6a7c140000 pid=5244 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=c37f0c11-1a00-0000-4346-ea6a7c140000 pid=5244 execve guuid=44697911-1a00-0000-4346-ea6a7d140000 pid=5245 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=44697911-1a00-0000-4346-ea6a7d140000 pid=5245 execve guuid=34bbd211-1a00-0000-4346-ea6a7e140000 pid=5246 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=34bbd211-1a00-0000-4346-ea6a7e140000 pid=5246 clone guuid=fd170212-1a00-0000-4346-ea6a7f140000 pid=5247 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=fd170212-1a00-0000-4346-ea6a7f140000 pid=5247 execve guuid=c4f42a24-1a00-0000-4346-ea6a80140000 pid=5248 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=c4f42a24-1a00-0000-4346-ea6a80140000 pid=5248 execve guuid=3e968a3a-1a00-0000-4346-ea6a81140000 pid=5249 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=3e968a3a-1a00-0000-4346-ea6a81140000 pid=5249 execve guuid=d94cfa3a-1a00-0000-4346-ea6a82140000 pid=5250 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=d94cfa3a-1a00-0000-4346-ea6a82140000 pid=5250 execve guuid=0e8c583b-1a00-0000-4346-ea6a83140000 pid=5251 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=0e8c583b-1a00-0000-4346-ea6a83140000 pid=5251 clone guuid=e18e9f3b-1a00-0000-4346-ea6a84140000 pid=5252 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=e18e9f3b-1a00-0000-4346-ea6a84140000 pid=5252 execve guuid=5298a04d-1a00-0000-4346-ea6a85140000 pid=5253 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=5298a04d-1a00-0000-4346-ea6a85140000 pid=5253 execve guuid=f33d526a-1a00-0000-4346-ea6a86140000 pid=5254 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=f33d526a-1a00-0000-4346-ea6a86140000 pid=5254 execve guuid=ed2eaf6a-1a00-0000-4346-ea6a87140000 pid=5255 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=ed2eaf6a-1a00-0000-4346-ea6a87140000 pid=5255 execve guuid=16ce316b-1a00-0000-4346-ea6a88140000 pid=5256 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=16ce316b-1a00-0000-4346-ea6a88140000 pid=5256 clone guuid=e0edcc6b-1a00-0000-4346-ea6a89140000 pid=5257 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=e0edcc6b-1a00-0000-4346-ea6a89140000 pid=5257 execve guuid=30e64380-1a00-0000-4346-ea6a8a140000 pid=5258 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=30e64380-1a00-0000-4346-ea6a8a140000 pid=5258 execve guuid=9af2ee92-1a00-0000-4346-ea6a8b140000 pid=5259 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=9af2ee92-1a00-0000-4346-ea6a8b140000 pid=5259 execve guuid=481b6b93-1a00-0000-4346-ea6a8c140000 pid=5260 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=481b6b93-1a00-0000-4346-ea6a8c140000 pid=5260 execve guuid=0793c793-1a00-0000-4346-ea6a8d140000 pid=5261 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=0793c793-1a00-0000-4346-ea6a8d140000 pid=5261 clone guuid=caff1b94-1a00-0000-4346-ea6a8e140000 pid=5262 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=caff1b94-1a00-0000-4346-ea6a8e140000 pid=5262 execve guuid=0892fca7-1a00-0000-4346-ea6a8f140000 pid=5263 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=0892fca7-1a00-0000-4346-ea6a8f140000 pid=5263 execve guuid=aabc7cba-1a00-0000-4346-ea6a90140000 pid=5264 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=aabc7cba-1a00-0000-4346-ea6a90140000 pid=5264 execve guuid=2f9ee3ba-1a00-0000-4346-ea6a91140000 pid=5265 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=2f9ee3ba-1a00-0000-4346-ea6a91140000 pid=5265 execve guuid=253a6cbb-1a00-0000-4346-ea6a93140000 pid=5267 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=253a6cbb-1a00-0000-4346-ea6a93140000 pid=5267 clone guuid=0f85b0bb-1a00-0000-4346-ea6a94140000 pid=5268 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=0f85b0bb-1a00-0000-4346-ea6a94140000 pid=5268 execve guuid=85c9f8ce-1a00-0000-4346-ea6a9a140000 pid=5274 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=85c9f8ce-1a00-0000-4346-ea6a9a140000 pid=5274 execve guuid=083b53e6-1a00-0000-4346-ea6aa2140000 pid=5282 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=083b53e6-1a00-0000-4346-ea6aa2140000 pid=5282 execve guuid=8d6702e7-1a00-0000-4346-ea6aa3140000 pid=5283 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=8d6702e7-1a00-0000-4346-ea6aa3140000 pid=5283 execve guuid=a65419e8-1a00-0000-4346-ea6aa4140000 pid=5284 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=a65419e8-1a00-0000-4346-ea6aa4140000 pid=5284 clone guuid=3e8946e8-1a00-0000-4346-ea6aa5140000 pid=5285 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=3e8946e8-1a00-0000-4346-ea6aa5140000 pid=5285 execve guuid=46fdbef9-1a00-0000-4346-ea6aa8140000 pid=5288 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=46fdbef9-1a00-0000-4346-ea6aa8140000 pid=5288 execve guuid=cc6b2d0c-1b00-0000-4346-ea6aaa140000 pid=5290 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=cc6b2d0c-1b00-0000-4346-ea6aaa140000 pid=5290 execve guuid=4f64b80c-1b00-0000-4346-ea6aab140000 pid=5291 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=4f64b80c-1b00-0000-4346-ea6aab140000 pid=5291 execve guuid=4e7c2e0d-1b00-0000-4346-ea6aac140000 pid=5292 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=4e7c2e0d-1b00-0000-4346-ea6aac140000 pid=5292 clone guuid=d5fa6a0d-1b00-0000-4346-ea6aad140000 pid=5293 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=d5fa6a0d-1b00-0000-4346-ea6aad140000 pid=5293 execve guuid=d2174f24-1b00-0000-4346-ea6abe140000 pid=5310 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=d2174f24-1b00-0000-4346-ea6abe140000 pid=5310 execve guuid=c6c1fc3b-1b00-0000-4346-ea6abf140000 pid=5311 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=c6c1fc3b-1b00-0000-4346-ea6abf140000 pid=5311 execve guuid=1de1a83c-1b00-0000-4346-ea6ac0140000 pid=5312 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=1de1a83c-1b00-0000-4346-ea6ac0140000 pid=5312 execve guuid=69343a3d-1b00-0000-4346-ea6ac1140000 pid=5313 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=69343a3d-1b00-0000-4346-ea6ac1140000 pid=5313 clone guuid=c3ac8f3d-1b00-0000-4346-ea6ac2140000 pid=5314 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=c3ac8f3d-1b00-0000-4346-ea6ac2140000 pid=5314 execve guuid=567a0e51-1b00-0000-4346-ea6ac3140000 pid=5315 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=567a0e51-1b00-0000-4346-ea6ac3140000 pid=5315 execve guuid=2b79a564-1b00-0000-4346-ea6ac4140000 pid=5316 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=2b79a564-1b00-0000-4346-ea6ac4140000 pid=5316 execve guuid=f7574365-1b00-0000-4346-ea6ac5140000 pid=5317 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=f7574365-1b00-0000-4346-ea6ac5140000 pid=5317 execve guuid=7188d965-1b00-0000-4346-ea6ac6140000 pid=5318 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=7188d965-1b00-0000-4346-ea6ac6140000 pid=5318 clone guuid=038e2b66-1b00-0000-4346-ea6ac7140000 pid=5319 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=038e2b66-1b00-0000-4346-ea6ac7140000 pid=5319 execve guuid=bf37ee7e-1b00-0000-4346-ea6ac8140000 pid=5320 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=bf37ee7e-1b00-0000-4346-ea6ac8140000 pid=5320 execve guuid=a871f992-1b00-0000-4346-ea6ac9140000 pid=5321 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=a871f992-1b00-0000-4346-ea6ac9140000 pid=5321 execve guuid=b202b793-1b00-0000-4346-ea6aca140000 pid=5322 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=b202b793-1b00-0000-4346-ea6aca140000 pid=5322 execve guuid=029b4894-1b00-0000-4346-ea6acb140000 pid=5323 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=029b4894-1b00-0000-4346-ea6acb140000 pid=5323 clone guuid=06329b94-1b00-0000-4346-ea6acc140000 pid=5324 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=06329b94-1b00-0000-4346-ea6acc140000 pid=5324 execve guuid=cfec22ad-1b00-0000-4346-ea6acd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=cfec22ad-1b00-0000-4346-ea6acd140000 pid=5325 execve guuid=c504a1c1-1b00-0000-4346-ea6ace140000 pid=5326 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=c504a1c1-1b00-0000-4346-ea6ace140000 pid=5326 execve guuid=47b04cc2-1b00-0000-4346-ea6acf140000 pid=5327 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=47b04cc2-1b00-0000-4346-ea6acf140000 pid=5327 execve guuid=574fddc2-1b00-0000-4346-ea6ad0140000 pid=5328 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=574fddc2-1b00-0000-4346-ea6ad0140000 pid=5328 clone guuid=b24c2fc3-1b00-0000-4346-ea6ad1140000 pid=5329 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=b24c2fc3-1b00-0000-4346-ea6ad1140000 pid=5329 execve guuid=20d877d6-1b00-0000-4346-ea6ad2140000 pid=5330 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=20d877d6-1b00-0000-4346-ea6ad2140000 pid=5330 execve guuid=25b51bea-1b00-0000-4346-ea6ad3140000 pid=5331 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=25b51bea-1b00-0000-4346-ea6ad3140000 pid=5331 execve guuid=e784c4ea-1b00-0000-4346-ea6ad4140000 pid=5332 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=e784c4ea-1b00-0000-4346-ea6ad4140000 pid=5332 execve guuid=86f94eeb-1b00-0000-4346-ea6ad5140000 pid=5333 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=86f94eeb-1b00-0000-4346-ea6ad5140000 pid=5333 clone guuid=f5a99ceb-1b00-0000-4346-ea6ad6140000 pid=5334 /usr/bin/wget net send-data guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=f5a99ceb-1b00-0000-4346-ea6ad6140000 pid=5334 execve guuid=3780d804-1c00-0000-4346-ea6ad7140000 pid=5335 /usr/bin/curl net send-data write-file guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=3780d804-1c00-0000-4346-ea6ad7140000 pid=5335 execve guuid=55c0d01a-1c00-0000-4346-ea6ad8140000 pid=5336 /usr/bin/cat guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=55c0d01a-1c00-0000-4346-ea6ad8140000 pid=5336 execve guuid=4efe871b-1c00-0000-4346-ea6ad9140000 pid=5337 /usr/bin/chmod guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=4efe871b-1c00-0000-4346-ea6ad9140000 pid=5337 execve guuid=ff92221c-1c00-0000-4346-ea6ada140000 pid=5338 /usr/bin/bash guuid=1355ea4d-1900-0000-4346-ea6a68140000 pid=5224->guuid=ff92221c-1c00-0000-4346-ea6ada140000 pid=5338 clone d3a71e2d-da4c-5679-8184-6b49ed538329 157.15.98.82:80 guuid=02562a4f-1900-0000-4346-ea6a69140000 pid=5225->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=59504e7f-1900-0000-4346-ea6a6a140000 pid=5226->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B guuid=5bb558b6-1900-0000-4346-ea6a6e140000 pid=5230->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=1e03c4cd-1900-0000-4346-ea6a6f140000 pid=5231->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=63909ce6-1900-0000-4346-ea6a7a140000 pid=5242->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=32c3d5f8-1900-0000-4346-ea6a7b140000 pid=5243->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B guuid=fd170212-1a00-0000-4346-ea6a7f140000 pid=5247->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=c4f42a24-1a00-0000-4346-ea6a80140000 pid=5248->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=e18e9f3b-1a00-0000-4346-ea6a84140000 pid=5252->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=5298a04d-1a00-0000-4346-ea6a85140000 pid=5253->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=e0edcc6b-1a00-0000-4346-ea6a89140000 pid=5257->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 151B guuid=30e64380-1a00-0000-4346-ea6a8a140000 pid=5258->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 100B guuid=caff1b94-1a00-0000-4346-ea6a8e140000 pid=5262->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=0892fca7-1a00-0000-4346-ea6a8f140000 pid=5263->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=0f85b0bb-1a00-0000-4346-ea6a94140000 pid=5268->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=85c9f8ce-1a00-0000-4346-ea6a9a140000 pid=5274->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B guuid=3e8946e8-1a00-0000-4346-ea6aa5140000 pid=5285->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=46fdbef9-1a00-0000-4346-ea6aa8140000 pid=5288->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=d5fa6a0d-1b00-0000-4346-ea6aad140000 pid=5293->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=d2174f24-1b00-0000-4346-ea6abe140000 pid=5310->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=c3ac8f3d-1b00-0000-4346-ea6ac2140000 pid=5314->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=567a0e51-1b00-0000-4346-ea6ac3140000 pid=5315->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=038e2b66-1b00-0000-4346-ea6ac7140000 pid=5319->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=bf37ee7e-1b00-0000-4346-ea6ac8140000 pid=5320->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B guuid=06329b94-1b00-0000-4346-ea6acc140000 pid=5324->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=cfec22ad-1b00-0000-4346-ea6acd140000 pid=5325->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B guuid=b24c2fc3-1b00-0000-4346-ea6ad1140000 pid=5329->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 149B guuid=20d877d6-1b00-0000-4346-ea6ad2140000 pid=5330->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 98B guuid=f5a99ceb-1b00-0000-4346-ea6ad6140000 pid=5334->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 148B guuid=3780d804-1c00-0000-4346-ea6ad7140000 pid=5335->d3a71e2d-da4c-5679-8184-6b49ed538329 send: 97B
Gathering data
Gathering data
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fdee6844b2e2283990ac0eb316eb3f6d2f752cf7a273420d8b16358a3fcc4f52

(this sample)

  
Delivery method
Distributed via web download

Comments