MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f587df60a5f86c7d2905b958a2af6a5440bb4e51f5e9e65585e1c51588ecf6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0f587df60a5f86c7d2905b958a2af6a5440bb4e51f5e9e65585e1c51588ecf6d
SHA3-384 hash: e2592516831fae8e4c85d7ff263d8403a9d0615ed9236d3ff0375b205489a8598295237d5f86832ca28b50d128e07ec0
SHA1 hash: 3b850a17539443ff587f07faa261e24ffd886e30
MD5 hash: 539f64cb1d697a2b697ebf6cbe44fd59
humanhash: six-magazine-one-enemy
File name:infect.sh
Download: download sample
Signature Mirai
File size:285 bytes
First seen:2025-12-17 18:23:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hZA1o7qG3u5qFHpo7qGSSu5Eb7gK7qCvclBNu5AA9:2gppFHpgpXxvky
TLSH T1AAD012FCD5244173324FC53C715DA4782DBB5C9E24AC3509515387F1516E08DE60EBB9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://boberkurwa.phoneparts.icu:80/gay.shn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox opendir
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-17T16:34:00Z UTC
Last seen:
2025-12-18T20:57:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=2906117c-1b00-0000-c4a3-b05a5a0d0000 pid=3418 /usr/bin/sudo guuid=64beda7e-1b00-0000-c4a3-b05a640d0000 pid=3428 /tmp/sample.bin guuid=2906117c-1b00-0000-c4a3-b05a5a0d0000 pid=3418->guuid=64beda7e-1b00-0000-c4a3-b05a640d0000 pid=3428 execve guuid=5686227f-1b00-0000-c4a3-b05a660d0000 pid=3430 /usr/bin/wget dns net send-data write-file guuid=64beda7e-1b00-0000-c4a3-b05a640d0000 pid=3428->guuid=5686227f-1b00-0000-c4a3-b05a660d0000 pid=3430 execve guuid=de657789-1b00-0000-c4a3-b05a810d0000 pid=3457 /usr/bin/chmod guuid=64beda7e-1b00-0000-c4a3-b05a640d0000 pid=3428->guuid=de657789-1b00-0000-c4a3-b05a810d0000 pid=3457 execve guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458 /tmp/gay.sh write-file guuid=64beda7e-1b00-0000-c4a3-b05a640d0000 pid=3428->guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=5686227f-1b00-0000-c4a3-b05a660d0000 pid=3430->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 86B 9a60c8a8-f371-5857-8593-5251af805ff1 boberkurwa.phoneparts.icu:80 guuid=5686227f-1b00-0000-c4a3-b05a660d0000 pid=3430->9a60c8a8-f371-5857-8593-5251af805ff1 send: 146B guuid=df69028a-1b00-0000-c4a3-b05a840d0000 pid=3460 /usr/bin/pgrep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=df69028a-1b00-0000-c4a3-b05a840d0000 pid=3460 execve guuid=c666ce8d-1b00-0000-c4a3-b05a8d0d0000 pid=3469 /usr/bin/ps guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=c666ce8d-1b00-0000-c4a3-b05a8d0d0000 pid=3469 execve guuid=a5fcd98d-1b00-0000-c4a3-b05a8e0d0000 pid=3470 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=a5fcd98d-1b00-0000-c4a3-b05a8e0d0000 pid=3470 execve guuid=e785e68d-1b00-0000-c4a3-b05a8f0d0000 pid=3471 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=e785e68d-1b00-0000-c4a3-b05a8f0d0000 pid=3471 execve guuid=2846ad95-1b00-0000-c4a3-b05aa60d0000 pid=3494 /usr/bin/pgrep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=2846ad95-1b00-0000-c4a3-b05aa60d0000 pid=3494 execve guuid=eb3c3f99-1b00-0000-c4a3-b05aa70d0000 pid=3495 /usr/bin/ps guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=eb3c3f99-1b00-0000-c4a3-b05aa70d0000 pid=3495 execve guuid=5f9b4599-1b00-0000-c4a3-b05aa80d0000 pid=3496 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=5f9b4599-1b00-0000-c4a3-b05aa80d0000 pid=3496 execve guuid=a7f34899-1b00-0000-c4a3-b05aa90d0000 pid=3497 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=a7f34899-1b00-0000-c4a3-b05aa90d0000 pid=3497 execve guuid=11db449c-1b00-0000-c4a3-b05aaa0d0000 pid=3498 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=11db449c-1b00-0000-c4a3-b05aaa0d0000 pid=3498 clone guuid=a091d59c-1b00-0000-c4a3-b05ab00d0000 pid=3504 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=a091d59c-1b00-0000-c4a3-b05ab00d0000 pid=3504 clone guuid=9321db9c-1b00-0000-c4a3-b05ab10d0000 pid=3505 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9321db9c-1b00-0000-c4a3-b05ab10d0000 pid=3505 execve guuid=9de0369d-1b00-0000-c4a3-b05ab20d0000 pid=3506 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9de0369d-1b00-0000-c4a3-b05ab20d0000 pid=3506 clone guuid=efdf3c9d-1b00-0000-c4a3-b05ab30d0000 pid=3507 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=efdf3c9d-1b00-0000-c4a3-b05ab30d0000 pid=3507 execve guuid=1d6f969d-1b00-0000-c4a3-b05ab50d0000 pid=3509 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=1d6f969d-1b00-0000-c4a3-b05ab50d0000 pid=3509 clone guuid=35d99f9d-1b00-0000-c4a3-b05ab60d0000 pid=3510 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=35d99f9d-1b00-0000-c4a3-b05ab60d0000 pid=3510 execve guuid=67d00b9e-1b00-0000-c4a3-b05ab90d0000 pid=3513 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=67d00b9e-1b00-0000-c4a3-b05ab90d0000 pid=3513 clone guuid=0ca9159e-1b00-0000-c4a3-b05aba0d0000 pid=3514 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=0ca9159e-1b00-0000-c4a3-b05aba0d0000 pid=3514 execve guuid=5be56b9e-1b00-0000-c4a3-b05abc0d0000 pid=3516 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=5be56b9e-1b00-0000-c4a3-b05abc0d0000 pid=3516 clone guuid=de79799e-1b00-0000-c4a3-b05abd0d0000 pid=3517 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=de79799e-1b00-0000-c4a3-b05abd0d0000 pid=3517 execve guuid=9066c79e-1b00-0000-c4a3-b05abf0d0000 pid=3519 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9066c79e-1b00-0000-c4a3-b05abf0d0000 pid=3519 clone guuid=cb44cf9e-1b00-0000-c4a3-b05ac00d0000 pid=3520 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=cb44cf9e-1b00-0000-c4a3-b05ac00d0000 pid=3520 execve guuid=ac15169f-1b00-0000-c4a3-b05ac20d0000 pid=3522 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=ac15169f-1b00-0000-c4a3-b05ac20d0000 pid=3522 clone guuid=7da31d9f-1b00-0000-c4a3-b05ac30d0000 pid=3523 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=7da31d9f-1b00-0000-c4a3-b05ac30d0000 pid=3523 execve guuid=37766a9f-1b00-0000-c4a3-b05ac50d0000 pid=3525 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=37766a9f-1b00-0000-c4a3-b05ac50d0000 pid=3525 clone guuid=157d6e9f-1b00-0000-c4a3-b05ac60d0000 pid=3526 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=157d6e9f-1b00-0000-c4a3-b05ac60d0000 pid=3526 execve guuid=fae40da0-1b00-0000-c4a3-b05ac80d0000 pid=3528 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=fae40da0-1b00-0000-c4a3-b05ac80d0000 pid=3528 clone guuid=423914a0-1b00-0000-c4a3-b05ac90d0000 pid=3529 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=423914a0-1b00-0000-c4a3-b05ac90d0000 pid=3529 execve guuid=9c3b72a0-1b00-0000-c4a3-b05acb0d0000 pid=3531 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9c3b72a0-1b00-0000-c4a3-b05acb0d0000 pid=3531 clone guuid=fa1879a0-1b00-0000-c4a3-b05acc0d0000 pid=3532 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=fa1879a0-1b00-0000-c4a3-b05acc0d0000 pid=3532 execve guuid=1b12c0a0-1b00-0000-c4a3-b05ace0d0000 pid=3534 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=1b12c0a0-1b00-0000-c4a3-b05ace0d0000 pid=3534 clone guuid=872ac7a0-1b00-0000-c4a3-b05acf0d0000 pid=3535 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=872ac7a0-1b00-0000-c4a3-b05acf0d0000 pid=3535 execve guuid=89f354a1-1b00-0000-c4a3-b05ad00d0000 pid=3536 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=89f354a1-1b00-0000-c4a3-b05ad00d0000 pid=3536 clone guuid=db645aa1-1b00-0000-c4a3-b05ad10d0000 pid=3537 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=db645aa1-1b00-0000-c4a3-b05ad10d0000 pid=3537 execve guuid=2e56e0a1-1b00-0000-c4a3-b05ad20d0000 pid=3538 /usr/bin/dash guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=2e56e0a1-1b00-0000-c4a3-b05ad20d0000 pid=3538 clone guuid=2cfc51a2-1b00-0000-c4a3-b05ad50d0000 pid=3541 /usr/bin/wget dns net send-data write-file guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=2cfc51a2-1b00-0000-c4a3-b05ad50d0000 pid=3541 execve guuid=a786fcae-1b00-0000-c4a3-b05aeb0d0000 pid=3563 /usr/bin/chmod guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=a786fcae-1b00-0000-c4a3-b05aeb0d0000 pid=3563 execve guuid=f51e50af-1b00-0000-c4a3-b05aed0d0000 pid=3565 /usr/bin/pgrep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=f51e50af-1b00-0000-c4a3-b05aed0d0000 pid=3565 execve guuid=9a012cb4-1b00-0000-c4a3-b05aef0d0000 pid=3567 /usr/bin/ps guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9a012cb4-1b00-0000-c4a3-b05aef0d0000 pid=3567 execve guuid=9c2432b4-1b00-0000-c4a3-b05af00d0000 pid=3568 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=9c2432b4-1b00-0000-c4a3-b05af00d0000 pid=3568 execve guuid=188638b4-1b00-0000-c4a3-b05af10d0000 pid=3569 /usr/bin/grep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=188638b4-1b00-0000-c4a3-b05af10d0000 pid=3569 execve guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571 /tmp/592ucwu dns net send-data write-config write-file guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571 execve guuid=165100b8-1b00-0000-c4a3-b05af40d0000 pid=3572 /usr/bin/sleep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=165100b8-1b00-0000-c4a3-b05af40d0000 pid=3572 execve guuid=b20b4b6b-1c00-0000-c4a3-b05a4a100000 pid=4170 /usr/bin/pgrep guuid=d14fc089-1b00-0000-c4a3-b05a820d0000 pid=3458->guuid=b20b4b6b-1c00-0000-c4a3-b05a4a100000 pid=4170 execve guuid=4b05509c-1b00-0000-c4a3-b05aab0d0000 pid=3499 /usr/bin/cat guuid=11db449c-1b00-0000-c4a3-b05aaa0d0000 pid=3498->guuid=4b05509c-1b00-0000-c4a3-b05aab0d0000 pid=3499 execve guuid=6ce4559c-1b00-0000-c4a3-b05aac0d0000 pid=3500 /usr/bin/head guuid=11db449c-1b00-0000-c4a3-b05aaa0d0000 pid=3498->guuid=6ce4559c-1b00-0000-c4a3-b05aac0d0000 pid=3500 execve guuid=c906eea1-1b00-0000-c4a3-b05ad40d0000 pid=3540 /usr/bin/uname guuid=2e56e0a1-1b00-0000-c4a3-b05ad20d0000 pid=3538->guuid=c906eea1-1b00-0000-c4a3-b05ad40d0000 pid=3540 execve guuid=2cfc51a2-1b00-0000-c4a3-b05ad50d0000 pid=3541->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 86B guuid=2cfc51a2-1b00-0000-c4a3-b05ad50d0000 pid=3541->9a60c8a8-f371-5857-8593-5251af805ff1 send: 148B guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=089850bb-1b00-0000-c4a3-b05afb0d0000 pid=3579 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=089850bb-1b00-0000-c4a3-b05afb0d0000 pid=3579 execve guuid=af6901bc-1b00-0000-c4a3-b05aff0d0000 pid=3583 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=af6901bc-1b00-0000-c4a3-b05aff0d0000 pid=3583 execve guuid=cef8e1fd-1b00-0000-c4a3-b05a920e0000 pid=3730 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=cef8e1fd-1b00-0000-c4a3-b05a920e0000 pid=3730 execve guuid=0ef18301-1c00-0000-c4a3-b05aa10e0000 pid=3745 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=0ef18301-1c00-0000-c4a3-b05aa10e0000 pid=3745 execve guuid=09d5fa02-1c00-0000-c4a3-b05aa40e0000 pid=3748 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=09d5fa02-1c00-0000-c4a3-b05aa40e0000 pid=3748 execve guuid=5176d803-1c00-0000-c4a3-b05aa90e0000 pid=3753 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=5176d803-1c00-0000-c4a3-b05aa90e0000 pid=3753 execve guuid=03bf6404-1c00-0000-c4a3-b05aaf0e0000 pid=3759 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=03bf6404-1c00-0000-c4a3-b05aaf0e0000 pid=3759 execve guuid=2c10eb04-1c00-0000-c4a3-b05ab30e0000 pid=3763 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=2c10eb04-1c00-0000-c4a3-b05ab30e0000 pid=3763 execve guuid=96cc6305-1c00-0000-c4a3-b05ab70e0000 pid=3767 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=96cc6305-1c00-0000-c4a3-b05ab70e0000 pid=3767 execve guuid=d9f8e805-1c00-0000-c4a3-b05abc0e0000 pid=3772 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=d9f8e805-1c00-0000-c4a3-b05abc0e0000 pid=3772 execve guuid=4ed17c06-1c00-0000-c4a3-b05ac00e0000 pid=3776 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=4ed17c06-1c00-0000-c4a3-b05ac00e0000 pid=3776 execve guuid=7381f406-1c00-0000-c4a3-b05ac30e0000 pid=3779 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=7381f406-1c00-0000-c4a3-b05ac30e0000 pid=3779 execve guuid=45866207-1c00-0000-c4a3-b05ac70e0000 pid=3783 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=45866207-1c00-0000-c4a3-b05ac70e0000 pid=3783 execve guuid=c0ce0f08-1c00-0000-c4a3-b05ace0e0000 pid=3790 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=c0ce0f08-1c00-0000-c4a3-b05ace0e0000 pid=3790 execve guuid=c4c67d08-1c00-0000-c4a3-b05ad20e0000 pid=3794 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=c4c67d08-1c00-0000-c4a3-b05ad20e0000 pid=3794 execve guuid=5cc77c09-1c00-0000-c4a3-b05ad90e0000 pid=3801 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=5cc77c09-1c00-0000-c4a3-b05ad90e0000 pid=3801 execve guuid=6afdf209-1c00-0000-c4a3-b05adf0e0000 pid=3807 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=6afdf209-1c00-0000-c4a3-b05adf0e0000 pid=3807 execve guuid=9c29aa0a-1c00-0000-c4a3-b05ae60e0000 pid=3814 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=9c29aa0a-1c00-0000-c4a3-b05ae60e0000 pid=3814 execve guuid=a0b0250b-1c00-0000-c4a3-b05aeb0e0000 pid=3819 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=a0b0250b-1c00-0000-c4a3-b05aeb0e0000 pid=3819 execve guuid=7856e80b-1c00-0000-c4a3-b05af30e0000 pid=3827 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=7856e80b-1c00-0000-c4a3-b05af30e0000 pid=3827 execve guuid=3dd0580c-1c00-0000-c4a3-b05af80e0000 pid=3832 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=3dd0580c-1c00-0000-c4a3-b05af80e0000 pid=3832 execve guuid=39cc180d-1c00-0000-c4a3-b05aff0e0000 pid=3839 /usr/bin/dash guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=39cc180d-1c00-0000-c4a3-b05aff0e0000 pid=3839 execve guuid=8371b70d-1c00-0000-c4a3-b05a050f0000 pid=3845 /tmp/592ucwu dns net send-data zombie guuid=1a9df6b7-1b00-0000-c4a3-b05af30d0000 pid=3571->guuid=8371b70d-1c00-0000-c4a3-b05a050f0000 pid=3845 clone guuid=a8e27fbb-1b00-0000-c4a3-b05afd0d0000 pid=3581 /usr/bin/grep guuid=089850bb-1b00-0000-c4a3-b05afb0d0000 pid=3579->guuid=a8e27fbb-1b00-0000-c4a3-b05afd0d0000 pid=3581 execve guuid=92402dbc-1b00-0000-c4a3-b05a010e0000 pid=3585 /usr/bin/systemctl guuid=af6901bc-1b00-0000-c4a3-b05aff0d0000 pid=3583->guuid=92402dbc-1b00-0000-c4a3-b05a010e0000 pid=3585 execve guuid=cfb520fe-1b00-0000-c4a3-b05a930e0000 pid=3731 /usr/bin/systemctl guuid=cef8e1fd-1b00-0000-c4a3-b05a920e0000 pid=3730->guuid=cfb520fe-1b00-0000-c4a3-b05a930e0000 pid=3731 execve guuid=822fab01-1c00-0000-c4a3-b05aa20e0000 pid=3746 /usr/bin/grep guuid=0ef18301-1c00-0000-c4a3-b05aa10e0000 pid=3745->guuid=822fab01-1c00-0000-c4a3-b05aa20e0000 pid=3746 execve guuid=43a55903-1c00-0000-c4a3-b05aa50e0000 pid=3749 /usr/bin/grep guuid=09d5fa02-1c00-0000-c4a3-b05aa40e0000 pid=3748->guuid=43a55903-1c00-0000-c4a3-b05aa50e0000 pid=3749 execve guuid=69af1404-1c00-0000-c4a3-b05aad0e0000 pid=3757 /usr/bin/grep guuid=5176d803-1c00-0000-c4a3-b05aa90e0000 pid=3753->guuid=69af1404-1c00-0000-c4a3-b05aad0e0000 pid=3757 execve guuid=1a9e8904-1c00-0000-c4a3-b05ab10e0000 pid=3761 /usr/bin/grep guuid=03bf6404-1c00-0000-c4a3-b05aaf0e0000 pid=3759->guuid=1a9e8904-1c00-0000-c4a3-b05ab10e0000 pid=3761 execve guuid=b7121705-1c00-0000-c4a3-b05ab50e0000 pid=3765 /usr/bin/grep guuid=2c10eb04-1c00-0000-c4a3-b05ab30e0000 pid=3763->guuid=b7121705-1c00-0000-c4a3-b05ab50e0000 pid=3765 execve guuid=a3a68905-1c00-0000-c4a3-b05ab90e0000 pid=3769 /usr/bin/grep guuid=96cc6305-1c00-0000-c4a3-b05ab70e0000 pid=3767->guuid=a3a68905-1c00-0000-c4a3-b05ab90e0000 pid=3769 execve guuid=2a481006-1c00-0000-c4a3-b05abd0e0000 pid=3773 /usr/bin/grep guuid=d9f8e805-1c00-0000-c4a3-b05abc0e0000 pid=3772->guuid=2a481006-1c00-0000-c4a3-b05abd0e0000 pid=3773 execve guuid=6ef9a606-1c00-0000-c4a3-b05ac10e0000 pid=3777 /usr/bin/grep guuid=4ed17c06-1c00-0000-c4a3-b05ac00e0000 pid=3776->guuid=6ef9a606-1c00-0000-c4a3-b05ac10e0000 pid=3777 execve guuid=f01b1b07-1c00-0000-c4a3-b05ac50e0000 pid=3781 /usr/bin/grep guuid=7381f406-1c00-0000-c4a3-b05ac30e0000 pid=3779->guuid=f01b1b07-1c00-0000-c4a3-b05ac50e0000 pid=3781 execve guuid=c66e8a07-1c00-0000-c4a3-b05ac90e0000 pid=3785 /usr/bin/cp guuid=45866207-1c00-0000-c4a3-b05ac70e0000 pid=3783->guuid=c66e8a07-1c00-0000-c4a3-b05ac90e0000 pid=3785 execve guuid=06f7d907-1c00-0000-c4a3-b05acd0e0000 pid=3789 /usr/bin/chmod guuid=45866207-1c00-0000-c4a3-b05ac70e0000 pid=3783->guuid=06f7d907-1c00-0000-c4a3-b05acd0e0000 pid=3789 execve guuid=f3793708-1c00-0000-c4a3-b05acf0e0000 pid=3791 /usr/bin/grep guuid=c0ce0f08-1c00-0000-c4a3-b05ace0e0000 pid=3790->guuid=f3793708-1c00-0000-c4a3-b05acf0e0000 pid=3791 execve guuid=9381a108-1c00-0000-c4a3-b05ad40e0000 pid=3796 /usr/bin/cp guuid=c4c67d08-1c00-0000-c4a3-b05ad20e0000 pid=3794->guuid=9381a108-1c00-0000-c4a3-b05ad40e0000 pid=3796 execve guuid=8cdb3409-1c00-0000-c4a3-b05ad80e0000 pid=3800 /usr/bin/chmod guuid=c4c67d08-1c00-0000-c4a3-b05ad20e0000 pid=3794->guuid=8cdb3409-1c00-0000-c4a3-b05ad80e0000 pid=3800 execve guuid=97dda509-1c00-0000-c4a3-b05add0e0000 pid=3805 /usr/bin/grep guuid=5cc77c09-1c00-0000-c4a3-b05ad90e0000 pid=3801->guuid=97dda509-1c00-0000-c4a3-b05add0e0000 pid=3805 execve guuid=34f6190a-1c00-0000-c4a3-b05ae20e0000 pid=3810 /usr/bin/cp guuid=6afdf209-1c00-0000-c4a3-b05adf0e0000 pid=3807->guuid=34f6190a-1c00-0000-c4a3-b05ae20e0000 pid=3810 execve guuid=465e6c0a-1c00-0000-c4a3-b05ae40e0000 pid=3812 /usr/bin/chmod guuid=6afdf209-1c00-0000-c4a3-b05adf0e0000 pid=3807->guuid=465e6c0a-1c00-0000-c4a3-b05ae40e0000 pid=3812 execve guuid=47e2d60a-1c00-0000-c4a3-b05aea0e0000 pid=3818 /usr/bin/grep guuid=9c29aa0a-1c00-0000-c4a3-b05ae60e0000 pid=3814->guuid=47e2d60a-1c00-0000-c4a3-b05aea0e0000 pid=3818 execve guuid=7401530b-1c00-0000-c4a3-b05aef0e0000 pid=3823 /usr/bin/cp guuid=a0b0250b-1c00-0000-c4a3-b05aeb0e0000 pid=3819->guuid=7401530b-1c00-0000-c4a3-b05aef0e0000 pid=3823 execve guuid=488dac0b-1c00-0000-c4a3-b05af10e0000 pid=3825 /usr/bin/chmod guuid=a0b0250b-1c00-0000-c4a3-b05aeb0e0000 pid=3819->guuid=488dac0b-1c00-0000-c4a3-b05af10e0000 pid=3825 execve guuid=8db3110c-1c00-0000-c4a3-b05af50e0000 pid=3829 /usr/bin/grep guuid=7856e80b-1c00-0000-c4a3-b05af30e0000 pid=3827->guuid=8db3110c-1c00-0000-c4a3-b05af50e0000 pid=3829 execve guuid=2da7820c-1c00-0000-c4a3-b05afc0e0000 pid=3836 /usr/bin/cp guuid=3dd0580c-1c00-0000-c4a3-b05af80e0000 pid=3832->guuid=2da7820c-1c00-0000-c4a3-b05afc0e0000 pid=3836 execve guuid=d4e8d30c-1c00-0000-c4a3-b05afe0e0000 pid=3838 /usr/bin/chmod guuid=3dd0580c-1c00-0000-c4a3-b05af80e0000 pid=3832->guuid=d4e8d30c-1c00-0000-c4a3-b05afe0e0000 pid=3838 execve guuid=16bf410d-1c00-0000-c4a3-b05a000f0000 pid=3840 /usr/bin/grep guuid=39cc180d-1c00-0000-c4a3-b05aff0e0000 pid=3839->guuid=16bf410d-1c00-0000-c4a3-b05a000f0000 pid=3840 execve guuid=8371b70d-1c00-0000-c4a3-b05a050f0000 pid=3845->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B 41a640a2-e439-5bd5-a73e-310f0a6373f1 boberkurwa.phoneparts.icu:32465 guuid=8371b70d-1c00-0000-c4a3-b05a050f0000 pid=3845->41a640a2-e439-5bd5-a73e-310f0a6373f1 con
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:wicked antivm botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0f587df60a5f86c7d2905b958a2af6a5440bb4e51f5e9e65585e1c51588ecf6d

(this sample)

  
Delivery method
Distributed via web download

Comments