T1059.004 Unix Shell in real malware
ATT&CK technique T1059.004 Unix Shell appears in 222 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Mirai.
Tactics: execution
Prevalence in the corpus
- Samples exhibiting T1059.004: 222
- Share of analyzed corpus: 0.2%
- Last 7 days: 0 · prior 7 days: 0 (flat)
Malware families using T1059.004
- Mirai - 82 samples
Example samples
- a.tmp - suspicious
- a.tmp - suspicious
- a.tmp - suspicious
- Instructions.iso - malicious
- Linux.Mirai.B.elf - malicious
- 3b1399d8b25d4997def28ed4e902dcc3d9fcea6d24fcc95712cb132fc4ee5b36.elf - malicious
- 39cabb912975a2b1cda1c50d9b6c62974738e4d66ac6d804fcfb30aa2764240f.sh - malicious
- 325577d0992787903200173260d99c345d5ee7c39edc864cca64cbc7e3366095.sh - malicious
- 318d66e1c137f9f3659954f2f9f986344e443a929abd3ff2518b1515e8f72227.elf - malicious
- 315fa8d33d11b7a85de622b12f3584d5e4bd9c1befd257e8b66de9f14616dcbf.pyw - suspicious
- 2fdd106b92b92d7cea977680e9890f8fe2fbb3adde1628edbb1c2b1a5587e60e.elf - suspicious
- 30a18c85fbf3beb4f8cd1940e9cc1dcd78f92f4e9e531f9f3cc615f67b53f582.sh - malicious
- b3eed9a4d98b4c8bc465513812b81395d8359ef6eb77327328e4a6dbc5237044 - suspicious
- 2a0c538ab255516216e1d4fbf8dbc45c88c9eb14cc3d1d39eaa3de7584266596.sh - suspicious
- 2725a1500f52a82974960a23290f901043903d45fef12441f46932233b98938b.sh - malicious
- 3b2c633fa05702c9ac57af246bac72f9c301c85a05b72266699f0bfb4a9b4d9b - suspicious
- 9584b66a21940d3f5a9007c7b8540696127ea05bfcb08ee9943afde47b640648 - suspicious
- 2424f532db6b5f4dac152f0e6d28bbb93f3ffdb2a6f88902d1d00dfe7b1fd1f9.elf - malicious
- 217ecebcd7218b8157fd7a64ec82943b88191dab7f04fa89e717aa5e9c8fefe2.elf - malicious
- 212da075160d4822800ad3b7a6eabfe77561b1efed9413fbac7aa985550efe1a.elf - malicious
- 3e3a8f75ee84ce5115bf16cb79ed3d3233b45365e774d76caebc7b8dad617992 - suspicious
- c5510b067dac6e4cff91a5cf3a3200b3114146c5e7a2260c03d69449ca667c4e - malicious
- f2ac70c374ba327e06d7ee7452ac26c2b9ef52835ad2383d5728063f88a66bb0 - suspicious
- aca8d820afc61815a276f4810f5effaf71ad5dc8990b60323a1d1361654c63e3 - malicious
- b9c6e33646e254ca52f576f723b02a8b8209a550ec473b9893eb765db55e3e17 - malicious
Canonical technique definition: MITRE ATT&CK T1059.004 (ATT&CK v19.1, CC BY 4.0).
Frequently asked about T1059.004
- How common is ATT&CK T1059.004 (Unix Shell) in real malware?
- ATT&CK technique T1059.004 Unix Shell appears in 222 publicly analyzed samples on MalwareAnalyzer by Cyble, 0.2% of the analyzed corpus. Seven-day prevalence is flat (0 recent vs 0 prior). Most associated families: Mirai.
- Which malware families use T1059.004?
- In this corpus T1059.004 is most associated with Mirai (82). Counts are analyzed samples per family in which the technique was observed.
- What share of analyzed samples use T1059.004?
- 0.2% of the publicly analyzed corpus (222 of 100981 samples) exhibits T1059.004. Technique attribution comes from behavior captured during real sandbox detonation and from static analysis, not from a vendor label.
All ATT&CK techniques in the corpus · Latest analyzed threats