MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ffc06c389aee18730f939be78e9cc436e20887bce312d97ba55a424262ef11d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ffc06c389aee18730f939be78e9cc436e20887bce312d97ba55a424262ef11d2
SHA3-384 hash: 4dd6142fdb37b8594de3f4f3f8d792671ab0027c7f90b927ea7a83631feef3a52e79543a0aaa5a4bdb502647c57127c5
SHA1 hash: 53ab9169af60c7460d931f45f1ccf7c045a6e30e
MD5 hash: 987ae39ee6f926b2f25605046afca3ae
humanhash: lactose-ack-mango-pluto
File name:byte
Download: download sample
File size:293 bytes
First seen:2025-10-19 20:47:54 UTC
Last seen:2025-10-21 04:29:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hftJ+pUKUF2RVYx8iHYf53IeRd3FoF/fkVKhOXqIKXD73IKX+N1IEWYq1IKBKW:ZtJ+jRE8KYLkF0ghsOTh4WYO8W
TLSH T1BCE0C299F8520C3678788CB9B7DB2491A50BA20E6E0A558E3189520BAAE4950A050893
Magika shell
Reporter juroots
Tags:sh

Intelligence


File Origin
# of uploads :
5
# of downloads :
35
Origin country :
CH CH
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-19T18:49:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=3095627a-1a00-0000-1d1f-1db254090000 pid=2388 /usr/bin/sudo guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395 /tmp/sample.bin guuid=3095627a-1a00-0000-1d1f-1db254090000 pid=2388->guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395 execve guuid=86241f7d-1a00-0000-1d1f-1db25d090000 pid=2397 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=86241f7d-1a00-0000-1d1f-1db25d090000 pid=2397 execve guuid=104f248e-1a00-0000-1d1f-1db26d090000 pid=2413 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=104f248e-1a00-0000-1d1f-1db26d090000 pid=2413 execve guuid=8b22678e-1a00-0000-1d1f-1db26f090000 pid=2415 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=8b22678e-1a00-0000-1d1f-1db26f090000 pid=2415 clone guuid=90a8548f-1a00-0000-1d1f-1db273090000 pid=2419 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=90a8548f-1a00-0000-1d1f-1db273090000 pid=2419 execve guuid=c5f7b08f-1a00-0000-1d1f-1db275090000 pid=2421 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=c5f7b08f-1a00-0000-1d1f-1db275090000 pid=2421 execve guuid=4cc834a0-1a00-0000-1d1f-1db296090000 pid=2454 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=4cc834a0-1a00-0000-1d1f-1db296090000 pid=2454 execve guuid=f42a73a0-1a00-0000-1d1f-1db297090000 pid=2455 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=f42a73a0-1a00-0000-1d1f-1db297090000 pid=2455 clone guuid=816afca0-1a00-0000-1d1f-1db29b090000 pid=2459 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=816afca0-1a00-0000-1d1f-1db29b090000 pid=2459 execve guuid=4e8145a1-1a00-0000-1d1f-1db29d090000 pid=2461 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=4e8145a1-1a00-0000-1d1f-1db29d090000 pid=2461 execve guuid=da25b9ac-1a00-0000-1d1f-1db2b9090000 pid=2489 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=da25b9ac-1a00-0000-1d1f-1db2b9090000 pid=2489 execve guuid=61ed18ad-1a00-0000-1d1f-1db2bb090000 pid=2491 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=61ed18ad-1a00-0000-1d1f-1db2bb090000 pid=2491 clone guuid=fa010dae-1a00-0000-1d1f-1db2bf090000 pid=2495 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=fa010dae-1a00-0000-1d1f-1db2bf090000 pid=2495 execve guuid=327f6aae-1a00-0000-1d1f-1db2c1090000 pid=2497 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=327f6aae-1a00-0000-1d1f-1db2c1090000 pid=2497 execve guuid=d17785bb-1a00-0000-1d1f-1db2da090000 pid=2522 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=d17785bb-1a00-0000-1d1f-1db2da090000 pid=2522 execve guuid=6114cebb-1a00-0000-1d1f-1db2db090000 pid=2523 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=6114cebb-1a00-0000-1d1f-1db2db090000 pid=2523 clone guuid=2046a4bc-1a00-0000-1d1f-1db2dd090000 pid=2525 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=2046a4bc-1a00-0000-1d1f-1db2dd090000 pid=2525 execve guuid=787214bd-1a00-0000-1d1f-1db2df090000 pid=2527 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=787214bd-1a00-0000-1d1f-1db2df090000 pid=2527 execve guuid=3c3c28c9-1a00-0000-1d1f-1db2fe090000 pid=2558 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=3c3c28c9-1a00-0000-1d1f-1db2fe090000 pid=2558 execve guuid=b7125fc9-1a00-0000-1d1f-1db2000a0000 pid=2560 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=b7125fc9-1a00-0000-1d1f-1db2000a0000 pid=2560 clone guuid=ec9017cb-1a00-0000-1d1f-1db2040a0000 pid=2564 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=ec9017cb-1a00-0000-1d1f-1db2040a0000 pid=2564 execve guuid=94e659cb-1a00-0000-1d1f-1db2060a0000 pid=2566 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=94e659cb-1a00-0000-1d1f-1db2060a0000 pid=2566 execve guuid=809924d9-1a00-0000-1d1f-1db2260a0000 pid=2598 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=809924d9-1a00-0000-1d1f-1db2260a0000 pid=2598 execve guuid=24df7dd9-1a00-0000-1d1f-1db2280a0000 pid=2600 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=24df7dd9-1a00-0000-1d1f-1db2280a0000 pid=2600 clone guuid=47ea2bda-1a00-0000-1d1f-1db22c0a0000 pid=2604 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=47ea2bda-1a00-0000-1d1f-1db22c0a0000 pid=2604 execve guuid=a24480da-1a00-0000-1d1f-1db22e0a0000 pid=2606 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=a24480da-1a00-0000-1d1f-1db22e0a0000 pid=2606 execve guuid=bc2b9ae7-1a00-0000-1d1f-1db2540a0000 pid=2644 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=bc2b9ae7-1a00-0000-1d1f-1db2540a0000 pid=2644 execve guuid=2bf4fbe7-1a00-0000-1d1f-1db2560a0000 pid=2646 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=2bf4fbe7-1a00-0000-1d1f-1db2560a0000 pid=2646 clone guuid=6cdfc6e8-1a00-0000-1d1f-1db2590a0000 pid=2649 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=6cdfc6e8-1a00-0000-1d1f-1db2590a0000 pid=2649 execve guuid=0c6a2ae9-1a00-0000-1d1f-1db25c0a0000 pid=2652 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=0c6a2ae9-1a00-0000-1d1f-1db25c0a0000 pid=2652 execve guuid=e9d667f5-1a00-0000-1d1f-1db27e0a0000 pid=2686 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=e9d667f5-1a00-0000-1d1f-1db27e0a0000 pid=2686 execve guuid=ac0fa7f5-1a00-0000-1d1f-1db2800a0000 pid=2688 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=ac0fa7f5-1a00-0000-1d1f-1db2800a0000 pid=2688 clone guuid=049c2df6-1a00-0000-1d1f-1db2830a0000 pid=2691 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=049c2df6-1a00-0000-1d1f-1db2830a0000 pid=2691 execve guuid=090572f6-1a00-0000-1d1f-1db2850a0000 pid=2693 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=090572f6-1a00-0000-1d1f-1db2850a0000 pid=2693 execve guuid=ff17b502-1b00-0000-1d1f-1db2a70a0000 pid=2727 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=ff17b502-1b00-0000-1d1f-1db2a70a0000 pid=2727 execve guuid=6a61f502-1b00-0000-1d1f-1db2a90a0000 pid=2729 /tmp/byte.exploit guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=6a61f502-1b00-0000-1d1f-1db2a90a0000 pid=2729 execve guuid=52d40a03-1b00-0000-1d1f-1db2ab0a0000 pid=2731 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=52d40a03-1b00-0000-1d1f-1db2ab0a0000 pid=2731 execve guuid=a2485a03-1b00-0000-1d1f-1db2af0a0000 pid=2735 /usr/bin/wget net send-data write-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=a2485a03-1b00-0000-1d1f-1db2af0a0000 pid=2735 execve guuid=f224e80e-1b00-0000-1d1f-1db2d00a0000 pid=2768 /usr/bin/chmod guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=f224e80e-1b00-0000-1d1f-1db2d00a0000 pid=2768 execve guuid=b95c2e0f-1b00-0000-1d1f-1db2d20a0000 pid=2770 /usr/bin/dash guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=b95c2e0f-1b00-0000-1d1f-1db2d20a0000 pid=2770 clone guuid=ab86ab10-1b00-0000-1d1f-1db2d70a0000 pid=2775 /usr/bin/rm delete-file guuid=6fb0cb7c-1a00-0000-1d1f-1db25b090000 pid=2395->guuid=ab86ab10-1b00-0000-1d1f-1db2d70a0000 pid=2775 execve ce2040a6-1382-57a9-8f72-87c510446939 91.92.241.8:80 guuid=86241f7d-1a00-0000-1d1f-1db25d090000 pid=2397->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=c5f7b08f-1a00-0000-1d1f-1db275090000 pid=2421->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=4e8145a1-1a00-0000-1d1f-1db29d090000 pid=2461->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=327f6aae-1a00-0000-1d1f-1db2c1090000 pid=2497->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=787214bd-1a00-0000-1d1f-1db2df090000 pid=2527->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=94e659cb-1a00-0000-1d1f-1db2060a0000 pid=2566->ce2040a6-1382-57a9-8f72-87c510446939 send: 139B guuid=a24480da-1a00-0000-1d1f-1db22e0a0000 pid=2606->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=0c6a2ae9-1a00-0000-1d1f-1db25c0a0000 pid=2652->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=090572f6-1a00-0000-1d1f-1db2850a0000 pid=2693->ce2040a6-1382-57a9-8f72-87c510446939 send: 138B guuid=fcdb0403-1b00-0000-1d1f-1db2aa0a0000 pid=2730 /tmp/byte.exploit zombie guuid=6a61f502-1b00-0000-1d1f-1db2a90a0000 pid=2729->guuid=fcdb0403-1b00-0000-1d1f-1db2aa0a0000 pid=2730 clone guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732 /tmp/byte.exploit dns net send-data zombie guuid=fcdb0403-1b00-0000-1d1f-1db2aa0a0000 pid=2730->guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 35B 3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 auth.binaries.lol:41323 guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732->3eea8321-7a1a-53e3-8cc5-fd3fbfba42a6 send: 11B guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888 /tmp/byte.exploit net net-scan send-data guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732->guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888 clone guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889 /tmp/byte.exploit net net-scan send-data guuid=86ef0c03-1b00-0000-1d1f-1db2ac0a0000 pid=2732->guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889 clone 5747732c-f603-51c6-9252-e264289619bd auth.binaries.lol:80 guuid=a2485a03-1b00-0000-1d1f-1db2af0a0000 pid=2735->5747732c-f603-51c6-9252-e264289619bd send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888|send-data send-data to 4097 IP addresses review logs to see them all guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888->guuid=90790250-1b00-0000-1d1f-1db2480b0000 pid=2888|send-data send guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 1ed62289-4f1b-542c-816d-2d6f23d562c5 156.77.131.72:37215 guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889->1ed62289-4f1b-542c-816d-2d6f23d562c5 send: 863B guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889|send-data send-data to 4093 IP addresses review logs to see them all guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889->guuid=fd140d50-1b00-0000-1d1f-1db2490b0000 pid=2889|send-data send
Threat name:
Linux.Downloader.MiraiB
Status:
Malicious
First seen:
2025-10-19 21:10:39 UTC
AV detection:
15 of 38 (39.47%)
Threat level:
  3/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh ffc06c389aee18730f939be78e9cc436e20887bce312d97ba55a424262ef11d2

(this sample)

  
Delivery method
Distributed via web download

Comments