MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cfa4ea1258ff0593aafdd9c1ec4505cbb2ca6e170bcfe142c32ae088cd63398. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 0cfa4ea1258ff0593aafdd9c1ec4505cbb2ca6e170bcfe142c32ae088cd63398
SHA3-384 hash: 96279ae94abd8d7d1ab12a42848f512ce0287cf1a393cd7f40d727b378c0b58ce5f02db82e74bb791d4dd48081a89500
SHA1 hash: 051ddd02fbf6bb76b659d1f6a4ebffe911894990
MD5 hash: 28ed3e9d5424718af1c95009f0fcad6c
humanhash: bravo-alanine-winner-floor
File name:payload.sh
Download: download sample
Signature Mirai
File size:463 bytes
First seen:2025-12-23 21:25:12 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:8aWAvDf5xZ2A5nFF3q1UUSYyEZ5yaa6yH++:8x2f5+qnFoDLanZ
TLSH T18EF0A7F7A820C47D3A4B4C3FF69AC6D46882086B74993D28B50BDC131B1C8C82179632
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-23T18:48:00Z UTC
Last seen:
2025-12-24T12:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5700d886-1b00-0000-ec1f-4374d10c0000 pid=3281 /usr/bin/sudo guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293 /tmp/sample.bin guuid=5700d886-1b00-0000-ec1f-4374d10c0000 pid=3281->guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293 execve guuid=f6fb548a-1b00-0000-ec1f-4374df0c0000 pid=3295 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=f6fb548a-1b00-0000-ec1f-4374df0c0000 pid=3295 execve guuid=af5758b1-1b00-0000-ec1f-4374210d0000 pid=3361 /home/sandbox/i686 delete-file net guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=af5758b1-1b00-0000-ec1f-4374210d0000 pid=3361 execve guuid=40bc5db1-1b00-0000-ec1f-4374220d0000 pid=3362 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=40bc5db1-1b00-0000-ec1f-4374220d0000 pid=3362 execve guuid=11e39fc8-1b00-0000-ec1f-4374590d0000 pid=3417 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=11e39fc8-1b00-0000-ec1f-4374590d0000 pid=3417 execve guuid=a517efc8-1b00-0000-ec1f-43745a0d0000 pid=3418 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=a517efc8-1b00-0000-ec1f-43745a0d0000 pid=3418 execve guuid=5d6595ef-1b00-0000-ec1f-4374b60d0000 pid=3510 /home/sandbox/i586 net guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=5d6595ef-1b00-0000-ec1f-4374b60d0000 pid=3510 execve guuid=659b98ef-1b00-0000-ec1f-4374b70d0000 pid=3511 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=659b98ef-1b00-0000-ec1f-4374b70d0000 pid=3511 execve guuid=d573be01-1c00-0000-ec1f-4374e10d0000 pid=3553 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=d573be01-1c00-0000-ec1f-4374e10d0000 pid=3553 execve guuid=3d8d4802-1c00-0000-ec1f-4374e40d0000 pid=3556 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=3d8d4802-1c00-0000-ec1f-4374e40d0000 pid=3556 execve guuid=790fe327-1c00-0000-ec1f-43744f0e0000 pid=3663 /home/sandbox/i486 delete-file net guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=790fe327-1c00-0000-ec1f-43744f0e0000 pid=3663 execve guuid=6887e627-1c00-0000-ec1f-4374500e0000 pid=3664 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=6887e627-1c00-0000-ec1f-4374500e0000 pid=3664 execve guuid=d75d213a-1c00-0000-ec1f-4374730e0000 pid=3699 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=d75d213a-1c00-0000-ec1f-4374730e0000 pid=3699 execve guuid=54d79e3a-1c00-0000-ec1f-4374740e0000 pid=3700 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=54d79e3a-1c00-0000-ec1f-4374740e0000 pid=3700 execve guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843 /home/sandbox/x86_64 net guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843 execve guuid=04f70562-1c00-0000-ec1f-4374040f0000 pid=3844 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=04f70562-1c00-0000-ec1f-4374040f0000 pid=3844 execve guuid=72d13574-1c00-0000-ec1f-4374330f0000 pid=3891 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=72d13574-1c00-0000-ec1f-4374330f0000 pid=3891 execve guuid=576b7874-1c00-0000-ec1f-4374350f0000 pid=3893 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=576b7874-1c00-0000-ec1f-4374350f0000 pid=3893 execve guuid=c0dfaba1-1c00-0000-ec1f-4374c50f0000 pid=4037 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=c0dfaba1-1c00-0000-ec1f-4374c50f0000 pid=4037 clone guuid=2497b0a1-1c00-0000-ec1f-4374c60f0000 pid=4038 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=2497b0a1-1c00-0000-ec1f-4374c60f0000 pid=4038 execve guuid=a1f7f8b3-1c00-0000-ec1f-43740b100000 pid=4107 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=a1f7f8b3-1c00-0000-ec1f-43740b100000 pid=4107 execve guuid=a2d75cb4-1c00-0000-ec1f-43740d100000 pid=4109 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=a2d75cb4-1c00-0000-ec1f-43740d100000 pid=4109 execve guuid=88a635e5-1c00-0000-ec1f-437495100000 pid=4245 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=88a635e5-1c00-0000-ec1f-437495100000 pid=4245 clone guuid=1e7a3ae5-1c00-0000-ec1f-437496100000 pid=4246 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=1e7a3ae5-1c00-0000-ec1f-437496100000 pid=4246 execve guuid=b75b7ff7-1c00-0000-ec1f-4374dd100000 pid=4317 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=b75b7ff7-1c00-0000-ec1f-4374dd100000 pid=4317 execve guuid=e50bb9f7-1c00-0000-ec1f-4374df100000 pid=4319 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=e50bb9f7-1c00-0000-ec1f-4374df100000 pid=4319 execve guuid=4e3b3d1e-1d00-0000-ec1f-437469110000 pid=4457 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=4e3b3d1e-1d00-0000-ec1f-437469110000 pid=4457 clone guuid=1105411e-1d00-0000-ec1f-43746a110000 pid=4458 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=1105411e-1d00-0000-ec1f-43746a110000 pid=4458 execve guuid=d99e6e30-1d00-0000-ec1f-4374a9110000 pid=4521 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=d99e6e30-1d00-0000-ec1f-4374a9110000 pid=4521 execve guuid=08d9d630-1d00-0000-ec1f-4374ac110000 pid=4524 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=08d9d630-1d00-0000-ec1f-4374ac110000 pid=4524 execve guuid=79fc0958-1d00-0000-ec1f-437420120000 pid=4640 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=79fc0958-1d00-0000-ec1f-437420120000 pid=4640 clone guuid=66ac0d58-1d00-0000-ec1f-437421120000 pid=4641 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=66ac0d58-1d00-0000-ec1f-437421120000 pid=4641 execve guuid=55e22c6a-1d00-0000-ec1f-437461120000 pid=4705 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=55e22c6a-1d00-0000-ec1f-437461120000 pid=4705 execve guuid=bd9a876a-1d00-0000-ec1f-437463120000 pid=4707 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=bd9a876a-1d00-0000-ec1f-437463120000 pid=4707 execve guuid=01ac1c9a-1d00-0000-ec1f-437418130000 pid=4888 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=01ac1c9a-1d00-0000-ec1f-437418130000 pid=4888 clone guuid=82e0219a-1d00-0000-ec1f-43741a130000 pid=4890 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=82e0219a-1d00-0000-ec1f-43741a130000 pid=4890 execve guuid=2d0b5eac-1d00-0000-ec1f-437459130000 pid=4953 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=2d0b5eac-1d00-0000-ec1f-437459130000 pid=4953 execve guuid=4d299aac-1d00-0000-ec1f-43745b130000 pid=4955 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=4d299aac-1d00-0000-ec1f-43745b130000 pid=4955 execve guuid=59b7e7d9-1d00-0000-ec1f-4374ec130000 pid=5100 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=59b7e7d9-1d00-0000-ec1f-4374ec130000 pid=5100 clone guuid=6fb4ebd9-1d00-0000-ec1f-4374ed130000 pid=5101 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=6fb4ebd9-1d00-0000-ec1f-4374ed130000 pid=5101 execve guuid=973318ec-1d00-0000-ec1f-437432140000 pid=5170 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=973318ec-1d00-0000-ec1f-437432140000 pid=5170 execve guuid=6add56ec-1d00-0000-ec1f-437434140000 pid=5172 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=6add56ec-1d00-0000-ec1f-437434140000 pid=5172 execve guuid=b31fd922-1e00-0000-ec1f-43745d140000 pid=5213 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=b31fd922-1e00-0000-ec1f-43745d140000 pid=5213 clone guuid=a936e122-1e00-0000-ec1f-43745e140000 pid=5214 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=a936e122-1e00-0000-ec1f-43745e140000 pid=5214 execve guuid=67584e35-1e00-0000-ec1f-4374ab140000 pid=5291 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=67584e35-1e00-0000-ec1f-4374ab140000 pid=5291 execve guuid=6214e435-1e00-0000-ec1f-4374ac140000 pid=5292 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=6214e435-1e00-0000-ec1f-4374ac140000 pid=5292 execve guuid=28492073-1e00-0000-ec1f-4374b0140000 pid=5296 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=28492073-1e00-0000-ec1f-4374b0140000 pid=5296 clone guuid=53a62373-1e00-0000-ec1f-4374b1140000 pid=5297 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=53a62373-1e00-0000-ec1f-4374b1140000 pid=5297 execve guuid=67065e85-1e00-0000-ec1f-4374bc140000 pid=5308 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=67065e85-1e00-0000-ec1f-4374bc140000 pid=5308 execve guuid=913f9e85-1e00-0000-ec1f-4374bd140000 pid=5309 /usr/bin/wget net send-data write-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=913f9e85-1e00-0000-ec1f-4374bd140000 pid=5309 execve guuid=4dcb0bac-1e00-0000-ec1f-4374be140000 pid=5310 /usr/bin/dash guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=4dcb0bac-1e00-0000-ec1f-4374be140000 pid=5310 clone guuid=353212ac-1e00-0000-ec1f-4374bf140000 pid=5311 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=353212ac-1e00-0000-ec1f-4374bf140000 pid=5311 execve guuid=dfc66dbe-1e00-0000-ec1f-4374c2140000 pid=5314 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=dfc66dbe-1e00-0000-ec1f-4374c2140000 pid=5314 execve guuid=60f9c8be-1e00-0000-ec1f-4374c3140000 pid=5315 /usr/bin/sleep guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=60f9c8be-1e00-0000-ec1f-4374c3140000 pid=5315 execve guuid=4c70cbfa-1e00-0000-ec1f-4374c4140000 pid=5316 /usr/bin/rm delete-file guuid=54fafa89-1b00-0000-ec1f-4374dd0c0000 pid=3293->guuid=4c70cbfa-1e00-0000-ec1f-4374c4140000 pid=5316 execve b515acf9-8d75-595b-a1f2-944e9d4a9d71 107.174.76.246:80 guuid=f6fb548a-1b00-0000-ec1f-4374df0c0000 pid=3295->b515acf9-8d75-595b-a1f2-944e9d4a9d71 send: 133B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=af5758b1-1b00-0000-ec1f-4374210d0000 pid=3361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=866265b1-1b00-0000-ec1f-4374230d0000 pid=3363 /usr/bin/chmod guuid=af5758b1-1b00-0000-ec1f-4374210d0000 pid=3361->guuid=866265b1-1b00-0000-ec1f-4374230d0000 pid=3363 execve guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373 /home/sandbox/i686 dns net send-data zombie guuid=af5758b1-1b00-0000-ec1f-4374210d0000 pid=3361->guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373 clone guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B c7c48527-3535-5a70-bf5e-944cdfe4cb9d alanbotnet.dpdns.org:55650 guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373->c7c48527-3535-5a70-bf5e-944cdfe4cb9d send: 6B guuid=5246bcb4-1b00-0000-ec1f-43742e0d0000 pid=3374 /home/sandbox/i686 guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373->guuid=5246bcb4-1b00-0000-ec1f-43742e0d0000 pid=3374 clone guuid=daf6cdb4-1b00-0000-ec1f-43742f0d0000 pid=3375 /home/sandbox/i686 guuid=d443afb4-1b00-0000-ec1f-43742d0d0000 pid=3373->guuid=daf6cdb4-1b00-0000-ec1f-43742f0d0000 pid=3375 clone 9507b11d-2d12-5217-a6fa-1701344b126d alanbotnet.dpdns.org:80 guuid=a517efc8-1b00-0000-ec1f-43745a0d0000 pid=3418->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=5d6595ef-1b00-0000-ec1f-4374b60d0000 pid=3510->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 54f17738-18c5-5646-9557-5c2a2e511ac6 0.0.0.0:22992 guuid=5d6595ef-1b00-0000-ec1f-4374b60d0000 pid=3510->54f17738-18c5-5646-9557-5c2a2e511ac6 con guuid=696fa2ef-1b00-0000-ec1f-4374b80d0000 pid=3512 /usr/bin/chmod guuid=5d6595ef-1b00-0000-ec1f-4374b60d0000 pid=3510->guuid=696fa2ef-1b00-0000-ec1f-4374b80d0000 pid=3512 execve guuid=3d8d4802-1c00-0000-ec1f-4374e40d0000 pid=3556->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=790fe327-1c00-0000-ec1f-43744f0e0000 pid=3663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=65b0ec27-1c00-0000-ec1f-4374510e0000 pid=3665 /usr/bin/chmod guuid=790fe327-1c00-0000-ec1f-43744f0e0000 pid=3663->guuid=65b0ec27-1c00-0000-ec1f-4374510e0000 pid=3665 execve guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668 /home/sandbox/i486 dns net send-data zombie guuid=790fe327-1c00-0000-ec1f-43744f0e0000 pid=3663->guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668 clone guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668->c7c48527-3535-5a70-bf5e-944cdfe4cb9d send: 6B guuid=cd7d5e28-1c00-0000-ec1f-4374550e0000 pid=3669 /home/sandbox/i486 guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668->guuid=cd7d5e28-1c00-0000-ec1f-4374550e0000 pid=3669 clone guuid=7af66828-1c00-0000-ec1f-4374560e0000 pid=3670 /home/sandbox/i486 guuid=32d85328-1c00-0000-ec1f-4374540e0000 pid=3668->guuid=7af66828-1c00-0000-ec1f-4374560e0000 pid=3670 clone guuid=54d79e3a-1c00-0000-ec1f-4374740e0000 pid=3700->9507b11d-2d12-5217-a6fa-1701344b126d send: 135B guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843->54f17738-18c5-5646-9557-5c2a2e511ac6 con guuid=043c0662-1c00-0000-ec1f-4374050f0000 pid=3845 /usr/bin/chmod guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843->guuid=043c0662-1c00-0000-ec1f-4374050f0000 pid=3845 execve guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835 /home/sandbox/x86_64 dns net send-data zombie guuid=364efb61-1c00-0000-ec1f-4374030f0000 pid=3843->guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835 clone guuid=576b7874-1c00-0000-ec1f-4374350f0000 pid=3893->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=75ffb3a1-1c00-0000-ec1f-4374c70f0000 pid=4039 /usr/bin/chmod guuid=c0dfaba1-1c00-0000-ec1f-4374c50f0000 pid=4037->guuid=75ffb3a1-1c00-0000-ec1f-4374c70f0000 pid=4039 execve guuid=a2d75cb4-1c00-0000-ec1f-43740d100000 pid=4109->9507b11d-2d12-5217-a6fa-1701344b126d send: 135B guuid=dba242e5-1c00-0000-ec1f-437497100000 pid=4247 /usr/bin/chmod guuid=88a635e5-1c00-0000-ec1f-437495100000 pid=4245->guuid=dba242e5-1c00-0000-ec1f-437497100000 pid=4247 execve guuid=e50bb9f7-1c00-0000-ec1f-4374df100000 pid=4319->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=44db4b1e-1d00-0000-ec1f-43746c110000 pid=4460 /usr/bin/chmod guuid=4e3b3d1e-1d00-0000-ec1f-437469110000 pid=4457->guuid=44db4b1e-1d00-0000-ec1f-43746c110000 pid=4460 execve guuid=08d9d630-1d00-0000-ec1f-4374ac110000 pid=4524->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=03651358-1d00-0000-ec1f-437423120000 pid=4643 /usr/bin/chmod guuid=79fc0958-1d00-0000-ec1f-437420120000 pid=4640->guuid=03651358-1d00-0000-ec1f-437423120000 pid=4643 execve guuid=bd9a876a-1d00-0000-ec1f-437463120000 pid=4707->9507b11d-2d12-5217-a6fa-1701344b126d send: 133B guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835->c7c48527-3535-5a70-bf5e-944cdfe4cb9d send: 8B guuid=a174df8c-1d00-0000-ec1f-4374e4120000 pid=4836 /home/sandbox/x86_64 guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835->guuid=a174df8c-1d00-0000-ec1f-4374e4120000 pid=4836 clone guuid=b663e88c-1d00-0000-ec1f-4374e5120000 pid=4837 /home/sandbox/x86_64 guuid=8f5dd88c-1d00-0000-ec1f-4374e3120000 pid=4835->guuid=b663e88c-1d00-0000-ec1f-4374e5120000 pid=4837 clone guuid=a8d5299a-1d00-0000-ec1f-43741b130000 pid=4891 /usr/bin/chmod guuid=01ac1c9a-1d00-0000-ec1f-437418130000 pid=4888->guuid=a8d5299a-1d00-0000-ec1f-43741b130000 pid=4891 execve guuid=4d299aac-1d00-0000-ec1f-43745b130000 pid=4955->9507b11d-2d12-5217-a6fa-1701344b126d send: 132B guuid=391df4d9-1d00-0000-ec1f-4374ee130000 pid=5102 /usr/bin/chmod guuid=59b7e7d9-1d00-0000-ec1f-4374ec130000 pid=5100->guuid=391df4d9-1d00-0000-ec1f-4374ee130000 pid=5102 execve guuid=6add56ec-1d00-0000-ec1f-437434140000 pid=5172->9507b11d-2d12-5217-a6fa-1701344b126d send: 134B guuid=2dede322-1e00-0000-ec1f-43745f140000 pid=5215 /usr/bin/chmod guuid=b31fd922-1e00-0000-ec1f-43745d140000 pid=5213->guuid=2dede322-1e00-0000-ec1f-43745f140000 pid=5215 execve guuid=6214e435-1e00-0000-ec1f-4374ac140000 pid=5292->9507b11d-2d12-5217-a6fa-1701344b126d send: 134B guuid=0bd43f73-1e00-0000-ec1f-4374b2140000 pid=5298 /usr/bin/chmod guuid=28492073-1e00-0000-ec1f-4374b0140000 pid=5296->guuid=0bd43f73-1e00-0000-ec1f-4374b2140000 pid=5298 execve guuid=913f9e85-1e00-0000-ec1f-4374bd140000 pid=5309->9507b11d-2d12-5217-a6fa-1701344b126d send: 136B guuid=3f0e1cac-1e00-0000-ec1f-4374c0140000 pid=5312 /usr/bin/chmod guuid=4dcb0bac-1e00-0000-ec1f-4374be140000 pid=5310->guuid=3f0e1cac-1e00-0000-ec1f-4374c0140000 pid=5312 execve
Threat name:
Script-Shell.Malware.MiraiB
Status:
Malicious
First seen:
2025-12-23 21:25:22 UTC
File Type:
Text (Shell)
AV detection:
3 of 36 (8.33%)
Threat level:
  2/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
alanbotnet.dpdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0cfa4ea1258ff0593aafdd9c1ec4505cbb2ca6e170bcfe142c32ae088cd63398

(this sample)

  
Delivery method
Distributed via web download

Comments