MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 083fcecbe81d2d8312afa5f2ea3a18c9e4d295f0f5e5064497f70a07054b7931. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 083fcecbe81d2d8312afa5f2ea3a18c9e4d295f0f5e5064497f70a07054b7931
SHA3-384 hash: 560bd29fcac94737d1155ccfe6d2fdb71da76224384cc0f0224a668c9ebc911d1966898ab7b6ce3d3be2ae96a5afab4a
SHA1 hash: 236e64584c15623b621f812e862e5aeee5651f96
MD5 hash: 8e3f8addc54e753c481f023cd9f0ef87
humanhash: jersey-venus-alabama-johnny
File name:baby.sh
Download: download sample
Signature Mirai
File size:2'550 bytes
First seen:2025-10-20 04:32:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vkivkTTkMbkHrkZbktnkq7Rk6jkVXkAc6k8Y82khrkUnkuBkNw:v9mD2YcF9M7lJ2ez1N
TLSH T1F751AECD31A10A34AC67D9B633A658CE318D58AEB9C1BF0C48DCB4E4E14FF492480647
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.241.62.243/133709/x86ccd768ece45b96ee896f0362e82cf319bb9b4a0a0e58f7df9d9d2f6d766ea2b7 Mirai32-bit elf mirai Mozi
http://188.241.62.243/133709/mips8b3ca7a69f3b263ed9142fc2efb3667fcb84ad46b0f0ec5c9b7ce13e4a94160b Mirai32-bit elf mirai Mozi
http://188.241.62.243/133709/arc97ac57ee40d432d1c0fd6924f6e781d813d99ccfa5b860699deb5d3b1da3116f Miraielf mirai ua-wget
http://188.241.62.243/133709/i468n/an/aelf ua-wget
http://188.241.62.243/133709/i686n/an/aelf ua-wget
http://188.241.62.243/133709/x86_64n/an/aelf ua-wget
http://188.241.62.243/133709/mpsla9218c45cb43d92c4af32f345784ae4d25f6a2b2c7b8f9569ecd308ae6a7499f Miraielf mirai ua-wget
http://188.241.62.243/133709/arme968d3d6b0c7d3ed0e9324b70dc3e6f48cb31e126dda25000565391b9b2367a2 Mirai32-bit elf mirai Mozi
http://188.241.62.243/133709/arm5b0a0dab197f82c70bb151e53ab029eb142ba240805302dca2557a0e2ba91e5fd Miraielf mirai ua-wget
http://188.241.62.243/133709/arm61f336bca145367482fda8282648fedcded36dde0c9cda3e3dfef508ef1b0b980 Miraielf mirai ua-wget
http://188.241.62.243/133709/arm71175fc303aeb2eef917c697436f60baf69b2508f8d00a0a9753d0ed036c07e4a Miraielf mirai ua-wget
http://188.241.62.243/133709/ppc47cab0080127b802a11eac5a40635967cd75ba25bf5755595b1be51567164301 Miraielf mirai ua-wget
http://188.241.62.243/133709/spc3d382c6c309b821e096bdfa45cde182cb9e7812fc2cf99e9f2105b203d0bd4cd Miraielf mirai ua-wget
http://188.241.62.243/133709/m68kfc3a399adefb7406f39b0cbf392e4cfc0814ae8ca9745406100a413b816a2712 Miraielf mirai ua-wget
http://188.241.62.243/133709/sh4a4c107e94a89776368a9138227553aa903774e50338e4bfe60eb4567e54c3ef4 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-20T02:01:00Z UTC
Last seen:
2025-10-20T02:35:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f7381a4e-1600-0000-5cdb-0f02f20c0000 pid=3314 /usr/bin/sudo guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318 /tmp/sample.bin guuid=f7381a4e-1600-0000-5cdb-0f02f20c0000 pid=3314->guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318 execve guuid=283a8650-1600-0000-5cdb-0f02f80c0000 pid=3320 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=283a8650-1600-0000-5cdb-0f02f80c0000 pid=3320 execve guuid=289a0b69-1600-0000-5cdb-0f022b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=289a0b69-1600-0000-5cdb-0f022b0d0000 pid=3371 execve guuid=988ead85-1600-0000-5cdb-0f026e0d0000 pid=3438 /usr/bin/cat guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=988ead85-1600-0000-5cdb-0f026e0d0000 pid=3438 execve guuid=dd2c2f86-1600-0000-5cdb-0f02700d0000 pid=3440 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=dd2c2f86-1600-0000-5cdb-0f02700d0000 pid=3440 execve guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442 execve guuid=af572487-1600-0000-5cdb-0f02760d0000 pid=3446 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=af572487-1600-0000-5cdb-0f02760d0000 pid=3446 execve guuid=e459e59f-1600-0000-5cdb-0f029f0d0000 pid=3487 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=e459e59f-1600-0000-5cdb-0f029f0d0000 pid=3487 execve guuid=b8530fb8-1600-0000-5cdb-0f02bf0d0000 pid=3519 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b8530fb8-1600-0000-5cdb-0f02bf0d0000 pid=3519 clone guuid=bc444ab8-1600-0000-5cdb-0f02c10d0000 pid=3521 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=bc444ab8-1600-0000-5cdb-0f02c10d0000 pid=3521 execve guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523 execve guuid=d0054fb9-1600-0000-5cdb-0f02c80d0000 pid=3528 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=d0054fb9-1600-0000-5cdb-0f02c80d0000 pid=3528 execve guuid=6611a5e1-1600-0000-5cdb-0f02fd0d0000 pid=3581 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=6611a5e1-1600-0000-5cdb-0f02fd0d0000 pid=3581 execve guuid=162bd708-1700-0000-5cdb-0f02530e0000 pid=3667 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=162bd708-1700-0000-5cdb-0f02530e0000 pid=3667 clone guuid=7905ff08-1700-0000-5cdb-0f02540e0000 pid=3668 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=7905ff08-1700-0000-5cdb-0f02540e0000 pid=3668 execve guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669 execve guuid=2773200a-1700-0000-5cdb-0f02590e0000 pid=3673 /usr/bin/wget net send-data guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=2773200a-1700-0000-5cdb-0f02590e0000 pid=3673 execve guuid=8692111a-1700-0000-5cdb-0f02830e0000 pid=3715 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=8692111a-1700-0000-5cdb-0f02830e0000 pid=3715 execve guuid=d459502a-1700-0000-5cdb-0f02be0e0000 pid=3774 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=d459502a-1700-0000-5cdb-0f02be0e0000 pid=3774 clone guuid=1360782a-1700-0000-5cdb-0f02bf0e0000 pid=3775 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=1360782a-1700-0000-5cdb-0f02bf0e0000 pid=3775 execve guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777 execve guuid=88955e2b-1700-0000-5cdb-0f02c60e0000 pid=3782 /usr/bin/wget net send-data guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=88955e2b-1700-0000-5cdb-0f02c60e0000 pid=3782 execve guuid=cff13d3c-1700-0000-5cdb-0f021a0f0000 pid=3866 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=cff13d3c-1700-0000-5cdb-0f021a0f0000 pid=3866 execve guuid=c9d6f24c-1700-0000-5cdb-0f024c0f0000 pid=3916 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=c9d6f24c-1700-0000-5cdb-0f024c0f0000 pid=3916 clone guuid=75a61e4d-1700-0000-5cdb-0f024d0f0000 pid=3917 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=75a61e4d-1700-0000-5cdb-0f024d0f0000 pid=3917 execve guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921 execve guuid=9859054e-1700-0000-5cdb-0f02550f0000 pid=3925 /usr/bin/wget net send-data guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=9859054e-1700-0000-5cdb-0f02550f0000 pid=3925 execve guuid=b23f935d-1700-0000-5cdb-0f02830f0000 pid=3971 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b23f935d-1700-0000-5cdb-0f02830f0000 pid=3971 execve guuid=6d8ea46e-1700-0000-5cdb-0f02c80f0000 pid=4040 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=6d8ea46e-1700-0000-5cdb-0f02c80f0000 pid=4040 clone guuid=2bf8c86e-1700-0000-5cdb-0f02ca0f0000 pid=4042 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=2bf8c86e-1700-0000-5cdb-0f02ca0f0000 pid=4042 execve guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043 execve guuid=28b4ab6f-1700-0000-5cdb-0f02d00f0000 pid=4048 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=28b4ab6f-1700-0000-5cdb-0f02d00f0000 pid=4048 execve guuid=b4e3dc86-1700-0000-5cdb-0f020f100000 pid=4111 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b4e3dc86-1700-0000-5cdb-0f020f100000 pid=4111 execve guuid=1568b99f-1700-0000-5cdb-0f0252100000 pid=4178 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=1568b99f-1700-0000-5cdb-0f0252100000 pid=4178 clone guuid=8f59f09f-1700-0000-5cdb-0f0253100000 pid=4179 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=8f59f09f-1700-0000-5cdb-0f0253100000 pid=4179 execve guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181 execve guuid=c8a9c9a0-1700-0000-5cdb-0f025a100000 pid=4186 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=c8a9c9a0-1700-0000-5cdb-0f025a100000 pid=4186 execve guuid=62d961b8-1700-0000-5cdb-0f029d100000 pid=4253 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=62d961b8-1700-0000-5cdb-0f029d100000 pid=4253 execve guuid=265861d2-1700-0000-5cdb-0f02e4100000 pid=4324 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=265861d2-1700-0000-5cdb-0f02e4100000 pid=4324 clone guuid=e4f7a2d2-1700-0000-5cdb-0f02e7100000 pid=4327 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=e4f7a2d2-1700-0000-5cdb-0f02e7100000 pid=4327 execve guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328 execve guuid=2ef77fd3-1700-0000-5cdb-0f02ec100000 pid=4332 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=2ef77fd3-1700-0000-5cdb-0f02ec100000 pid=4332 execve guuid=e11ce7ec-1700-0000-5cdb-0f0214110000 pid=4372 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=e11ce7ec-1700-0000-5cdb-0f0214110000 pid=4372 execve guuid=d3d89708-1800-0000-5cdb-0f023c110000 pid=4412 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=d3d89708-1800-0000-5cdb-0f023c110000 pid=4412 clone guuid=7232cc08-1800-0000-5cdb-0f023d110000 pid=4413 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=7232cc08-1800-0000-5cdb-0f023d110000 pid=4413 execve guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417 execve guuid=51f5190a-1800-0000-5cdb-0f0245110000 pid=4421 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=51f5190a-1800-0000-5cdb-0f0245110000 pid=4421 execve guuid=bd01d823-1800-0000-5cdb-0f02b2110000 pid=4530 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=bd01d823-1800-0000-5cdb-0f02b2110000 pid=4530 execve guuid=9e0fbd3b-1800-0000-5cdb-0f02e9110000 pid=4585 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=9e0fbd3b-1800-0000-5cdb-0f02e9110000 pid=4585 clone guuid=dface23b-1800-0000-5cdb-0f02ec110000 pid=4588 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=dface23b-1800-0000-5cdb-0f02ec110000 pid=4588 execve guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590 execve guuid=7084c83c-1800-0000-5cdb-0f02f5110000 pid=4597 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=7084c83c-1800-0000-5cdb-0f02f5110000 pid=4597 execve guuid=21b5f35a-1800-0000-5cdb-0f0249120000 pid=4681 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=21b5f35a-1800-0000-5cdb-0f0249120000 pid=4681 execve guuid=9d18117b-1800-0000-5cdb-0f029e120000 pid=4766 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=9d18117b-1800-0000-5cdb-0f029e120000 pid=4766 clone guuid=0916387b-1800-0000-5cdb-0f02a1120000 pid=4769 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=0916387b-1800-0000-5cdb-0f02a1120000 pid=4769 execve guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770 execve guuid=65cdb97b-1800-0000-5cdb-0f02a8120000 pid=4776 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=65cdb97b-1800-0000-5cdb-0f02a8120000 pid=4776 execve guuid=acd31094-1800-0000-5cdb-0f02e5120000 pid=4837 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=acd31094-1800-0000-5cdb-0f02e5120000 pid=4837 execve guuid=b328a9af-1800-0000-5cdb-0f0229130000 pid=4905 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=b328a9af-1800-0000-5cdb-0f0229130000 pid=4905 clone guuid=a719d8af-1800-0000-5cdb-0f022b130000 pid=4907 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=a719d8af-1800-0000-5cdb-0f022b130000 pid=4907 execve guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909 execve guuid=ba0c0cb1-1800-0000-5cdb-0f0232130000 pid=4914 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=ba0c0cb1-1800-0000-5cdb-0f0232130000 pid=4914 execve guuid=0a5c67cf-1800-0000-5cdb-0f0272130000 pid=4978 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=0a5c67cf-1800-0000-5cdb-0f0272130000 pid=4978 execve guuid=0bb217ef-1800-0000-5cdb-0f02b8130000 pid=5048 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=0bb217ef-1800-0000-5cdb-0f02b8130000 pid=5048 clone guuid=a60847ef-1800-0000-5cdb-0f02b9130000 pid=5049 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=a60847ef-1800-0000-5cdb-0f02b9130000 pid=5049 execve guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051 execve guuid=908455f0-1800-0000-5cdb-0f02c0130000 pid=5056 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=908455f0-1800-0000-5cdb-0f02c0130000 pid=5056 execve guuid=0fe7fe0e-1900-0000-5cdb-0f02ff130000 pid=5119 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=0fe7fe0e-1900-0000-5cdb-0f02ff130000 pid=5119 execve guuid=75cc7539-1900-0000-5cdb-0f0256140000 pid=5206 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=75cc7539-1900-0000-5cdb-0f0256140000 pid=5206 clone guuid=0289b039-1900-0000-5cdb-0f0257140000 pid=5207 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=0289b039-1900-0000-5cdb-0f0257140000 pid=5207 execve guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209 execve guuid=4669273b-1900-0000-5cdb-0f025f140000 pid=5215 /usr/bin/wget net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=4669273b-1900-0000-5cdb-0f025f140000 pid=5215 execve guuid=4c148d59-1900-0000-5cdb-0f0291140000 pid=5265 /usr/bin/curl net send-data write-file guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=4c148d59-1900-0000-5cdb-0f0291140000 pid=5265 execve guuid=ce988179-1900-0000-5cdb-0f02c5140000 pid=5317 /usr/bin/bash guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=ce988179-1900-0000-5cdb-0f02c5140000 pid=5317 clone guuid=61d8ae79-1900-0000-5cdb-0f02c6140000 pid=5318 /usr/bin/chmod guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=61d8ae79-1900-0000-5cdb-0f02c6140000 pid=5318 execve guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319 /tmp/bins net guuid=75c21750-1600-0000-5cdb-0f02f60c0000 pid=3318->guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319 execve a39441f7-c52f-5f95-a587-51fd27fcf5dd 188.241.62.243:80 guuid=283a8650-1600-0000-5cdb-0f02f80c0000 pid=3320->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=289a0b69-1600-0000-5cdb-0f022b0d0000 pid=3371->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d2ecff86-1600-0000-5cdb-0f02730d0000 pid=3443 /tmp/bins guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442->guuid=d2ecff86-1600-0000-5cdb-0f02730d0000 pid=3443 clone guuid=5c4f0687-1600-0000-5cdb-0f02740d0000 pid=3444 /tmp/bins guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442->guuid=5c4f0687-1600-0000-5cdb-0f02740d0000 pid=3444 clone guuid=cdf30b87-1600-0000-5cdb-0f02750d0000 pid=3445 /tmp/bins net zombie guuid=f8d19e86-1600-0000-5cdb-0f02720d0000 pid=3442->guuid=cdf30b87-1600-0000-5cdb-0f02750d0000 pid=3445 clone 29f976b2-d2ad-58cb-af97-1fcd651559e7 188.241.62.243:3778 guuid=cdf30b87-1600-0000-5cdb-0f02750d0000 pid=3445->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=af572487-1600-0000-5cdb-0f02760d0000 pid=3446->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=e459e59f-1600-0000-5cdb-0f029f0d0000 pid=3487->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a4ec34b9-1600-0000-5cdb-0f02c40d0000 pid=3524 /tmp/bins guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523->guuid=a4ec34b9-1600-0000-5cdb-0f02c40d0000 pid=3524 clone guuid=a9703ab9-1600-0000-5cdb-0f02c60d0000 pid=3526 /tmp/bins guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523->guuid=a9703ab9-1600-0000-5cdb-0f02c60d0000 pid=3526 clone guuid=099f40b9-1600-0000-5cdb-0f02c70d0000 pid=3527 /tmp/bins net zombie guuid=80d6d1b8-1600-0000-5cdb-0f02c30d0000 pid=3523->guuid=099f40b9-1600-0000-5cdb-0f02c70d0000 pid=3527 clone guuid=099f40b9-1600-0000-5cdb-0f02c70d0000 pid=3527->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=d0054fb9-1600-0000-5cdb-0f02c80d0000 pid=3528->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=6611a5e1-1600-0000-5cdb-0f02fd0d0000 pid=3581->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c465030a-1700-0000-5cdb-0f02560e0000 pid=3670 /tmp/bins guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669->guuid=c465030a-1700-0000-5cdb-0f02560e0000 pid=3670 clone guuid=33730c0a-1700-0000-5cdb-0f02570e0000 pid=3671 /tmp/bins guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669->guuid=33730c0a-1700-0000-5cdb-0f02570e0000 pid=3671 clone guuid=dbde130a-1700-0000-5cdb-0f02580e0000 pid=3672 /tmp/bins net zombie guuid=856e7e09-1700-0000-5cdb-0f02550e0000 pid=3669->guuid=dbde130a-1700-0000-5cdb-0f02580e0000 pid=3672 clone guuid=dbde130a-1700-0000-5cdb-0f02580e0000 pid=3672->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=2773200a-1700-0000-5cdb-0f02590e0000 pid=3673->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=8692111a-1700-0000-5cdb-0f02830e0000 pid=3715->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=87b63a2b-1700-0000-5cdb-0f02c30e0000 pid=3779 /tmp/bins guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777->guuid=87b63a2b-1700-0000-5cdb-0f02c30e0000 pid=3779 clone guuid=9257402b-1700-0000-5cdb-0f02c40e0000 pid=3780 /tmp/bins guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777->guuid=9257402b-1700-0000-5cdb-0f02c40e0000 pid=3780 clone guuid=c64e492b-1700-0000-5cdb-0f02c50e0000 pid=3781 /tmp/bins net zombie guuid=b28cf32a-1700-0000-5cdb-0f02c10e0000 pid=3777->guuid=c64e492b-1700-0000-5cdb-0f02c50e0000 pid=3781 clone guuid=c64e492b-1700-0000-5cdb-0f02c50e0000 pid=3781->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=88955e2b-1700-0000-5cdb-0f02c60e0000 pid=3782->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=cff13d3c-1700-0000-5cdb-0f021a0f0000 pid=3866->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a2bfe44d-1700-0000-5cdb-0f02520f0000 pid=3922 /tmp/bins guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921->guuid=a2bfe44d-1700-0000-5cdb-0f02520f0000 pid=3922 clone guuid=a9c9eb4d-1700-0000-5cdb-0f02530f0000 pid=3923 /tmp/bins guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921->guuid=a9c9eb4d-1700-0000-5cdb-0f02530f0000 pid=3923 clone guuid=ade2f04d-1700-0000-5cdb-0f02540f0000 pid=3924 /tmp/bins net zombie guuid=ceed964d-1700-0000-5cdb-0f02510f0000 pid=3921->guuid=ade2f04d-1700-0000-5cdb-0f02540f0000 pid=3924 clone guuid=ade2f04d-1700-0000-5cdb-0f02540f0000 pid=3924->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=9859054e-1700-0000-5cdb-0f02550f0000 pid=3925->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 142B guuid=b23f935d-1700-0000-5cdb-0f02830f0000 pid=3971->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 91B guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=60ad8c6f-1700-0000-5cdb-0f02cd0f0000 pid=4045 /tmp/bins guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043->guuid=60ad8c6f-1700-0000-5cdb-0f02cd0f0000 pid=4045 clone guuid=392e976f-1700-0000-5cdb-0f02ce0f0000 pid=4046 /tmp/bins guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043->guuid=392e976f-1700-0000-5cdb-0f02ce0f0000 pid=4046 clone guuid=48279d6f-1700-0000-5cdb-0f02cf0f0000 pid=4047 /tmp/bins net zombie guuid=b6a1436f-1700-0000-5cdb-0f02cb0f0000 pid=4043->guuid=48279d6f-1700-0000-5cdb-0f02cf0f0000 pid=4047 clone guuid=48279d6f-1700-0000-5cdb-0f02cf0f0000 pid=4047->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=28b4ab6f-1700-0000-5cdb-0f02d00f0000 pid=4048->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=b4e3dc86-1700-0000-5cdb-0f020f100000 pid=4111->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=913db4a0-1700-0000-5cdb-0f0257100000 pid=4183 /tmp/bins guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181->guuid=913db4a0-1700-0000-5cdb-0f0257100000 pid=4183 clone guuid=dc0eb9a0-1700-0000-5cdb-0f0258100000 pid=4184 /tmp/bins guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181->guuid=dc0eb9a0-1700-0000-5cdb-0f0258100000 pid=4184 clone guuid=65a5bda0-1700-0000-5cdb-0f0259100000 pid=4185 /tmp/bins net zombie guuid=b20b65a0-1700-0000-5cdb-0f0255100000 pid=4181->guuid=65a5bda0-1700-0000-5cdb-0f0259100000 pid=4185 clone guuid=65a5bda0-1700-0000-5cdb-0f0259100000 pid=4185->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=c8a9c9a0-1700-0000-5cdb-0f025a100000 pid=4186->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=62d961b8-1700-0000-5cdb-0f029d100000 pid=4253->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=707667d3-1700-0000-5cdb-0f02e9100000 pid=4329 /tmp/bins guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328->guuid=707667d3-1700-0000-5cdb-0f02e9100000 pid=4329 clone guuid=45bb6cd3-1700-0000-5cdb-0f02ea100000 pid=4330 /tmp/bins guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328->guuid=45bb6cd3-1700-0000-5cdb-0f02ea100000 pid=4330 clone guuid=18aa71d3-1700-0000-5cdb-0f02eb100000 pid=4331 /tmp/bins net zombie guuid=528c15d3-1700-0000-5cdb-0f02e8100000 pid=4328->guuid=18aa71d3-1700-0000-5cdb-0f02eb100000 pid=4331 clone guuid=18aa71d3-1700-0000-5cdb-0f02eb100000 pid=4331->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=2ef77fd3-1700-0000-5cdb-0f02ec100000 pid=4332->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=e11ce7ec-1700-0000-5cdb-0f0214110000 pid=4372->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=895de709-1800-0000-5cdb-0f0242110000 pid=4418 /tmp/bins guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417->guuid=895de709-1800-0000-5cdb-0f0242110000 pid=4418 clone guuid=e314ef09-1800-0000-5cdb-0f0243110000 pid=4419 /tmp/bins guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417->guuid=e314ef09-1800-0000-5cdb-0f0243110000 pid=4419 clone guuid=c535f809-1800-0000-5cdb-0f0244110000 pid=4420 /tmp/bins net zombie guuid=4c138109-1800-0000-5cdb-0f0241110000 pid=4417->guuid=c535f809-1800-0000-5cdb-0f0244110000 pid=4420 clone guuid=c535f809-1800-0000-5cdb-0f0244110000 pid=4420->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=51f5190a-1800-0000-5cdb-0f0245110000 pid=4421->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=bd01d823-1800-0000-5cdb-0f02b2110000 pid=4530->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a470943c-1800-0000-5cdb-0f02f1110000 pid=4593 /tmp/bins guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590->guuid=a470943c-1800-0000-5cdb-0f02f1110000 pid=4593 clone guuid=0875983c-1800-0000-5cdb-0f02f3110000 pid=4595 /tmp/bins guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590->guuid=0875983c-1800-0000-5cdb-0f02f3110000 pid=4595 clone guuid=d5ac9f3c-1800-0000-5cdb-0f02f4110000 pid=4596 /tmp/bins net zombie guuid=d355563c-1800-0000-5cdb-0f02ee110000 pid=4590->guuid=d5ac9f3c-1800-0000-5cdb-0f02f4110000 pid=4596 clone guuid=d5ac9f3c-1800-0000-5cdb-0f02f4110000 pid=4596->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=7084c83c-1800-0000-5cdb-0f02f5110000 pid=4597->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=21b5f35a-1800-0000-5cdb-0f0249120000 pid=4681->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ebe6a67b-1800-0000-5cdb-0f02a3120000 pid=4771 /tmp/bins guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770->guuid=ebe6a67b-1800-0000-5cdb-0f02a3120000 pid=4771 clone guuid=f049aa7b-1800-0000-5cdb-0f02a4120000 pid=4772 /tmp/bins guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770->guuid=f049aa7b-1800-0000-5cdb-0f02a4120000 pid=4772 clone guuid=d741ae7b-1800-0000-5cdb-0f02a6120000 pid=4774 /tmp/bins net zombie guuid=849a7a7b-1800-0000-5cdb-0f02a2120000 pid=4770->guuid=d741ae7b-1800-0000-5cdb-0f02a6120000 pid=4774 clone guuid=d741ae7b-1800-0000-5cdb-0f02a6120000 pid=4774->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=65cdb97b-1800-0000-5cdb-0f02a8120000 pid=4776->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=acd31094-1800-0000-5cdb-0f02e5120000 pid=4837->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f2fedb0-1800-0000-5cdb-0f022f130000 pid=4911 /tmp/bins guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909->guuid=2f2fedb0-1800-0000-5cdb-0f022f130000 pid=4911 clone guuid=d006f4b0-1800-0000-5cdb-0f0230130000 pid=4912 /tmp/bins guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909->guuid=d006f4b0-1800-0000-5cdb-0f0230130000 pid=4912 clone guuid=f967feb0-1800-0000-5cdb-0f0231130000 pid=4913 /tmp/bins net zombie guuid=e29b93b0-1800-0000-5cdb-0f022d130000 pid=4909->guuid=f967feb0-1800-0000-5cdb-0f0231130000 pid=4913 clone guuid=f967feb0-1800-0000-5cdb-0f0231130000 pid=4913->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=ba0c0cb1-1800-0000-5cdb-0f0232130000 pid=4914->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=0a5c67cf-1800-0000-5cdb-0f0272130000 pid=4978->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=090b2cf0-1800-0000-5cdb-0f02bd130000 pid=5053 /tmp/bins guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051->guuid=090b2cf0-1800-0000-5cdb-0f02bd130000 pid=5053 clone guuid=fd0732f0-1800-0000-5cdb-0f02be130000 pid=5054 /tmp/bins guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051->guuid=fd0732f0-1800-0000-5cdb-0f02be130000 pid=5054 clone guuid=610d3af0-1800-0000-5cdb-0f02bf130000 pid=5055 /tmp/bins net zombie guuid=83b1cfef-1800-0000-5cdb-0f02bb130000 pid=5051->guuid=610d3af0-1800-0000-5cdb-0f02bf130000 pid=5055 clone guuid=610d3af0-1800-0000-5cdb-0f02bf130000 pid=5055->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=908455f0-1800-0000-5cdb-0f02c0130000 pid=5056->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 140B guuid=0fe7fe0e-1900-0000-5cdb-0f02ff130000 pid=5119->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 89B guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f6b6f63a-1900-0000-5cdb-0f025c140000 pid=5212 /tmp/bins guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209->guuid=f6b6f63a-1900-0000-5cdb-0f025c140000 pid=5212 clone guuid=1d95fe3a-1900-0000-5cdb-0f025d140000 pid=5213 /tmp/bins guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209->guuid=1d95fe3a-1900-0000-5cdb-0f025d140000 pid=5213 clone guuid=6e91133b-1900-0000-5cdb-0f025e140000 pid=5214 /tmp/bins net zombie guuid=973c753a-1900-0000-5cdb-0f0259140000 pid=5209->guuid=6e91133b-1900-0000-5cdb-0f025e140000 pid=5214 clone guuid=6e91133b-1900-0000-5cdb-0f025e140000 pid=5214->29f976b2-d2ad-58cb-af97-1fcd651559e7 con guuid=4669273b-1900-0000-5cdb-0f025f140000 pid=5215->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 139B guuid=4c148d59-1900-0000-5cdb-0f0291140000 pid=5265->a39441f7-c52f-5f95-a587-51fd27fcf5dd send: 88B guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0d4a7e7a-1900-0000-5cdb-0f02c8140000 pid=5320 /tmp/bins guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319->guuid=0d4a7e7a-1900-0000-5cdb-0f02c8140000 pid=5320 clone guuid=7519857a-1900-0000-5cdb-0f02c9140000 pid=5321 /tmp/bins guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319->guuid=7519857a-1900-0000-5cdb-0f02c9140000 pid=5321 clone guuid=c946907a-1900-0000-5cdb-0f02ca140000 pid=5322 /tmp/bins net zombie guuid=276a257a-1900-0000-5cdb-0f02c7140000 pid=5319->guuid=c946907a-1900-0000-5cdb-0f02ca140000 pid=5322 clone guuid=c946907a-1900-0000-5cdb-0f02ca140000 pid=5322->29f976b2-d2ad-58cb-af97-1fcd651559e7 con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-20 04:33:26 UTC
File Type:
Text (Shell)
AV detection:
23 of 37 (62.16%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 083fcecbe81d2d8312afa5f2ea3a18c9e4d295f0f5e5064497f70a07054b7931

(this sample)

  
Delivery method
Distributed via web download

Comments