MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13965237353de749da4cd8bd464341ac00c1bd447205948f4eaab8ad4128575f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 13965237353de749da4cd8bd464341ac00c1bd447205948f4eaab8ad4128575f
SHA3-384 hash: fbe274f988fec2ba420824c742cda84a9c2d1d3cc3428442ded84e04266d361ee0d18d3cd81a3997d8dd345e07199357
SHA1 hash: ad19b58a40299e0a26dabf01b92474865148b148
MD5 hash: 806b797577e19a74d195f4355e390a70
humanhash: fish-bulldog-glucose-mockingbird
File name:wg.sh
Download: download sample
Signature Mirai
File size:1'800 bytes
First seen:2025-09-05 14:59:01 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:fzR5dkMA5lssKgGH/C8NzR5dkMA5lsCnJUgGH/C8+S:VVNfyJUNuS
TLSH T17B31A2FF5393EA03C43BCFD63497D458A00AC18FA5DC4F7A15DA897A44C860474A5E9A
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.24/bins/morte.x86_64dc42dab20737c30846d8cd5245c92f7a2de2a99dee368e0e1b722171575f9b70 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.x868ed8684e37fed57d6a517549a3c33a47c965bd2c1b749477065300cd3befb8a8 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.armfd66075653adb6af129688520f493763553558fe461dde1e1e6b7f37cc9a7f67 Miraicensys elf mirai opendir ua-wget
http://196.251.73.24/bins/morte.arm5316f2dbc5ce4d44982adf97aa64de4669a0050862b5d42b31d23c32e5c22c743 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm6d8c6a66e47b848a317a4a40a216e1cb227d10276b7bd73bf89c1da8d35f24902 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm72a7e7542927ad5a3fbfa0700d1008e57a0581534f1b347b9f10ab1cf2b8d45d0 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.i6869f95429199df814af4b249582f306e331931a5b1589cc0253a3fe1cf00729a32 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mips1bf649de3be52962fc4aae70aea0274646316556a3dd0bad8571ffa8bdf0d05a Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.m68kaefc54f8202f34d24d309cb7a2e6c9cfe70b07f5f8ed4ba0835ca3b531e4896e Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mpslb05eb83d4502f8d974ff67d2e6e39eab2854f903990a30e216fee23eb96cf0f4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.ppcdd6578f10f62f72e47533dfac771693a49d9f99f29a72b125455165c75254abc Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.sh45e69cd3c506f77714a43ba8b887d565eb16780549a54ef3626678bc5c22caab9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-05T16:18:00Z UTC
Last seen:
2025-09-05T16:18:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5f55e739-1900-0000-8f35-a31765140000 pid=5221 /usr/bin/sudo guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222 /tmp/sample.bin guuid=5f55e739-1900-0000-8f35-a31765140000 pid=5221->guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222 execve guuid=c98b043c-1900-0000-8f35-a31767140000 pid=5223 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=c98b043c-1900-0000-8f35-a31767140000 pid=5223 execve guuid=57e4a341-1900-0000-8f35-a31768140000 pid=5224 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=57e4a341-1900-0000-8f35-a31768140000 pid=5224 execve guuid=8800e541-1900-0000-8f35-a31769140000 pid=5225 /home/sandbox/morte.x86_64 mprotect-exec net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=8800e541-1900-0000-8f35-a31769140000 pid=5225 execve guuid=b8ec5842-1900-0000-8f35-a3176b140000 pid=5227 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=b8ec5842-1900-0000-8f35-a3176b140000 pid=5227 execve guuid=7ff27747-1900-0000-8f35-a31770140000 pid=5232 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=7ff27747-1900-0000-8f35-a31770140000 pid=5232 execve guuid=b0d6bf47-1900-0000-8f35-a31771140000 pid=5233 /home/sandbox/morte.x86 net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=b0d6bf47-1900-0000-8f35-a31771140000 pid=5233 execve guuid=a7e76148-1900-0000-8f35-a31773140000 pid=5235 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=a7e76148-1900-0000-8f35-a31773140000 pid=5235 execve guuid=39d4364e-1900-0000-8f35-a31777140000 pid=5239 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=39d4364e-1900-0000-8f35-a31777140000 pid=5239 execve guuid=bdb7014f-1900-0000-8f35-a31778140000 pid=5240 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=bdb7014f-1900-0000-8f35-a31778140000 pid=5240 clone guuid=42ed3751-1900-0000-8f35-a3177b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=42ed3751-1900-0000-8f35-a3177b140000 pid=5243 execve guuid=e4c2ea56-1900-0000-8f35-a3177c140000 pid=5244 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=e4c2ea56-1900-0000-8f35-a3177c140000 pid=5244 execve guuid=adcc6357-1900-0000-8f35-a3177d140000 pid=5245 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=adcc6357-1900-0000-8f35-a3177d140000 pid=5245 clone guuid=5c5cc759-1900-0000-8f35-a3177f140000 pid=5247 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=5c5cc759-1900-0000-8f35-a3177f140000 pid=5247 execve guuid=b886ad5f-1900-0000-8f35-a31780140000 pid=5248 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=b886ad5f-1900-0000-8f35-a31780140000 pid=5248 execve guuid=00390360-1900-0000-8f35-a31781140000 pid=5249 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=00390360-1900-0000-8f35-a31781140000 pid=5249 clone guuid=238fa560-1900-0000-8f35-a31783140000 pid=5251 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=238fa560-1900-0000-8f35-a31783140000 pid=5251 execve guuid=f45ef666-1900-0000-8f35-a31784140000 pid=5252 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=f45ef666-1900-0000-8f35-a31784140000 pid=5252 execve guuid=ca3a3d67-1900-0000-8f35-a31785140000 pid=5253 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ca3a3d67-1900-0000-8f35-a31785140000 pid=5253 clone guuid=1d8de867-1900-0000-8f35-a31787140000 pid=5255 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=1d8de867-1900-0000-8f35-a31787140000 pid=5255 execve guuid=c642a96c-1900-0000-8f35-a31788140000 pid=5256 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=c642a96c-1900-0000-8f35-a31788140000 pid=5256 execve guuid=9a62f16c-1900-0000-8f35-a31789140000 pid=5257 /home/sandbox/morte.i686 net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=9a62f16c-1900-0000-8f35-a31789140000 pid=5257 execve guuid=988d846d-1900-0000-8f35-a3178b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=988d846d-1900-0000-8f35-a3178b140000 pid=5259 execve guuid=c928a373-1900-0000-8f35-a3178f140000 pid=5263 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=c928a373-1900-0000-8f35-a3178f140000 pid=5263 execve guuid=81e1e373-1900-0000-8f35-a31791140000 pid=5265 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=81e1e373-1900-0000-8f35-a31791140000 pid=5265 clone guuid=8a507275-1900-0000-8f35-a31793140000 pid=5267 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=8a507275-1900-0000-8f35-a31793140000 pid=5267 execve guuid=13e6f97b-1900-0000-8f35-a31794140000 pid=5268 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=13e6f97b-1900-0000-8f35-a31794140000 pid=5268 execve guuid=e5be3f7c-1900-0000-8f35-a31795140000 pid=5269 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=e5be3f7c-1900-0000-8f35-a31795140000 pid=5269 clone guuid=3fc6e37c-1900-0000-8f35-a31797140000 pid=5271 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=3fc6e37c-1900-0000-8f35-a31797140000 pid=5271 execve guuid=497a2c83-1900-0000-8f35-a31798140000 pid=5272 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=497a2c83-1900-0000-8f35-a31798140000 pid=5272 execve guuid=54583784-1900-0000-8f35-a31799140000 pid=5273 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=54583784-1900-0000-8f35-a31799140000 pid=5273 clone guuid=fd1fdd84-1900-0000-8f35-a3179b140000 pid=5275 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=fd1fdd84-1900-0000-8f35-a3179b140000 pid=5275 execve guuid=ddfe6e8a-1900-0000-8f35-a3179c140000 pid=5276 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ddfe6e8a-1900-0000-8f35-a3179c140000 pid=5276 execve guuid=ff05d38a-1900-0000-8f35-a3179d140000 pid=5277 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ff05d38a-1900-0000-8f35-a3179d140000 pid=5277 clone guuid=f4adb18b-1900-0000-8f35-a3179f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=f4adb18b-1900-0000-8f35-a3179f140000 pid=5279 execve guuid=4b947c92-1900-0000-8f35-a317a0140000 pid=5280 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=4b947c92-1900-0000-8f35-a317a0140000 pid=5280 execve guuid=be47cb92-1900-0000-8f35-a317a1140000 pid=5281 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=be47cb92-1900-0000-8f35-a317a1140000 pid=5281 clone guuid=f7fe6493-1900-0000-8f35-a317a3140000 pid=5283 /usr/bin/rm delete-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=f7fe6493-1900-0000-8f35-a317a3140000 pid=5283 execve guuid=bc97e193-1900-0000-8f35-a317a4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=bc97e193-1900-0000-8f35-a317a4140000 pid=5284 execve guuid=2850cd98-1900-0000-8f35-a317a5140000 pid=5285 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=2850cd98-1900-0000-8f35-a317a5140000 pid=5285 execve guuid=1bd61099-1900-0000-8f35-a317a6140000 pid=5286 /tmp/morte.x86_64 mprotect-exec net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=1bd61099-1900-0000-8f35-a317a6140000 pid=5286 execve guuid=24277d99-1900-0000-8f35-a317a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=24277d99-1900-0000-8f35-a317a8140000 pid=5288 execve guuid=c4a9739e-1900-0000-8f35-a317ad140000 pid=5293 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=c4a9739e-1900-0000-8f35-a317ad140000 pid=5293 execve guuid=3f54d89e-1900-0000-8f35-a317ae140000 pid=5294 /tmp/morte.x86 net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=3f54d89e-1900-0000-8f35-a317ae140000 pid=5294 execve guuid=986d939f-1900-0000-8f35-a317b1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=986d939f-1900-0000-8f35-a317b1140000 pid=5297 execve guuid=e7379aa4-1900-0000-8f35-a317b4140000 pid=5300 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=e7379aa4-1900-0000-8f35-a317b4140000 pid=5300 execve guuid=72d0f2a4-1900-0000-8f35-a317b5140000 pid=5301 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=72d0f2a4-1900-0000-8f35-a317b5140000 pid=5301 clone guuid=794cd7a5-1900-0000-8f35-a317b8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=794cd7a5-1900-0000-8f35-a317b8140000 pid=5304 execve guuid=ab4480aa-1900-0000-8f35-a317b9140000 pid=5305 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ab4480aa-1900-0000-8f35-a317b9140000 pid=5305 execve guuid=944ac2aa-1900-0000-8f35-a317ba140000 pid=5306 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=944ac2aa-1900-0000-8f35-a317ba140000 pid=5306 clone guuid=627e59ab-1900-0000-8f35-a317bc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=627e59ab-1900-0000-8f35-a317bc140000 pid=5308 execve guuid=b6f383b1-1900-0000-8f35-a317bd140000 pid=5309 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=b6f383b1-1900-0000-8f35-a317bd140000 pid=5309 execve guuid=5faffcb1-1900-0000-8f35-a317be140000 pid=5310 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=5faffcb1-1900-0000-8f35-a317be140000 pid=5310 clone guuid=46428cb2-1900-0000-8f35-a317c0140000 pid=5312 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=46428cb2-1900-0000-8f35-a317c0140000 pid=5312 execve guuid=dcecfeb8-1900-0000-8f35-a317c1140000 pid=5313 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=dcecfeb8-1900-0000-8f35-a317c1140000 pid=5313 execve guuid=ce0e50b9-1900-0000-8f35-a317c2140000 pid=5314 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ce0e50b9-1900-0000-8f35-a317c2140000 pid=5314 clone guuid=0e7613ba-1900-0000-8f35-a317c4140000 pid=5316 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=0e7613ba-1900-0000-8f35-a317c4140000 pid=5316 execve guuid=7bc23ebf-1900-0000-8f35-a317c5140000 pid=5317 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=7bc23ebf-1900-0000-8f35-a317c5140000 pid=5317 execve guuid=441d9bbf-1900-0000-8f35-a317c6140000 pid=5318 /tmp/morte.i686 net guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=441d9bbf-1900-0000-8f35-a317c6140000 pid=5318 execve guuid=15ff1ec0-1900-0000-8f35-a317c8140000 pid=5320 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=15ff1ec0-1900-0000-8f35-a317c8140000 pid=5320 execve guuid=1cb7e4c7-1900-0000-8f35-a317cd140000 pid=5325 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=1cb7e4c7-1900-0000-8f35-a317cd140000 pid=5325 execve guuid=a02149c8-1900-0000-8f35-a317ce140000 pid=5326 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=a02149c8-1900-0000-8f35-a317ce140000 pid=5326 clone guuid=ae9229c9-1900-0000-8f35-a317d0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=ae9229c9-1900-0000-8f35-a317d0140000 pid=5328 execve guuid=a41b6dcf-1900-0000-8f35-a317d1140000 pid=5329 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=a41b6dcf-1900-0000-8f35-a317d1140000 pid=5329 execve guuid=86e5c9cf-1900-0000-8f35-a317d2140000 pid=5330 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=86e5c9cf-1900-0000-8f35-a317d2140000 pid=5330 clone guuid=19fa9ad0-1900-0000-8f35-a317d4140000 pid=5332 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=19fa9ad0-1900-0000-8f35-a317d4140000 pid=5332 execve guuid=79fae0d6-1900-0000-8f35-a317d5140000 pid=5333 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=79fae0d6-1900-0000-8f35-a317d5140000 pid=5333 execve guuid=8d4430d7-1900-0000-8f35-a317d6140000 pid=5334 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=8d4430d7-1900-0000-8f35-a317d6140000 pid=5334 clone guuid=8874ccd7-1900-0000-8f35-a317d8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=8874ccd7-1900-0000-8f35-a317d8140000 pid=5336 execve guuid=c89695dc-1900-0000-8f35-a317d9140000 pid=5337 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=c89695dc-1900-0000-8f35-a317d9140000 pid=5337 execve guuid=3957e0dc-1900-0000-8f35-a317da140000 pid=5338 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=3957e0dc-1900-0000-8f35-a317da140000 pid=5338 clone guuid=5396abde-1900-0000-8f35-a317dc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=5396abde-1900-0000-8f35-a317dc140000 pid=5340 execve guuid=d90960e5-1900-0000-8f35-a317dd140000 pid=5341 /usr/bin/chmod guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=d90960e5-1900-0000-8f35-a317dd140000 pid=5341 execve guuid=2ab0bde5-1900-0000-8f35-a317de140000 pid=5342 /usr/bin/dash guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=2ab0bde5-1900-0000-8f35-a317de140000 pid=5342 clone guuid=753462e6-1900-0000-8f35-a317e0140000 pid=5344 /usr/bin/rm delete-file guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=753462e6-1900-0000-8f35-a317e0140000 pid=5344 execve guuid=4396d9e6-1900-0000-8f35-a317e1140000 pid=5345 /usr/bin/rm guuid=4975b03b-1900-0000-8f35-a31766140000 pid=5222->guuid=4396d9e6-1900-0000-8f35-a317e1140000 pid=5345 execve 6beadc35-efc4-5e26-84e6-0089cd490f0e 196.251.73.24:80 guuid=c98b043c-1900-0000-8f35-a31767140000 pid=5223->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 145B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8800e541-1900-0000-8f35-a31769140000 pid=5225->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98b44f42-1900-0000-8f35-a3176a140000 pid=5226 /home/sandbox/morte.x86_64 zombie guuid=8800e541-1900-0000-8f35-a31769140000 pid=5225->guuid=98b44f42-1900-0000-8f35-a3176a140000 pid=5226 clone guuid=4d0c5e42-1900-0000-8f35-a3176c140000 pid=5228 /home/sandbox/morte.x86_64 write-config zombie guuid=98b44f42-1900-0000-8f35-a3176a140000 pid=5226->guuid=4d0c5e42-1900-0000-8f35-a3176c140000 pid=5228 clone guuid=b8ec5842-1900-0000-8f35-a3176b140000 pid=5227->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=72e7b342-1900-0000-8f35-a3176d140000 pid=5229 /usr/bin/dash guuid=4d0c5e42-1900-0000-8f35-a3176c140000 pid=5228->guuid=72e7b342-1900-0000-8f35-a3176d140000 pid=5229 execve guuid=45599e43-1900-0000-8f35-a3176f140000 pid=5231 /home/sandbox/morte.x86_64 delete-file dns net send-data zombie guuid=4d0c5e42-1900-0000-8f35-a3176c140000 pid=5228->guuid=45599e43-1900-0000-8f35-a3176f140000 pid=5231 clone guuid=ca59e842-1900-0000-8f35-a3176e140000 pid=5230 /usr/bin/cp guuid=72e7b342-1900-0000-8f35-a3176d140000 pid=5229->guuid=ca59e842-1900-0000-8f35-a3176e140000 pid=5230 execve guuid=45599e43-1900-0000-8f35-a3176f140000 pid=5231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 725B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=45599e43-1900-0000-8f35-a3176f140000 pid=5231->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=b0d6bf47-1900-0000-8f35-a31771140000 pid=5233->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7fcf5848-1900-0000-8f35-a31772140000 pid=5234 /home/sandbox/morte.x86 guuid=b0d6bf47-1900-0000-8f35-a31771140000 pid=5233->guuid=7fcf5848-1900-0000-8f35-a31772140000 pid=5234 clone guuid=ac8a9c48-1900-0000-8f35-a31774140000 pid=5236 /home/sandbox/morte.x86 write-config zombie guuid=7fcf5848-1900-0000-8f35-a31772140000 pid=5234->guuid=ac8a9c48-1900-0000-8f35-a31774140000 pid=5236 clone guuid=a7e76148-1900-0000-8f35-a31773140000 pid=5235->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=6522b94c-1900-0000-8f35-a31775140000 pid=5237 /usr/bin/dash guuid=ac8a9c48-1900-0000-8f35-a31774140000 pid=5236->guuid=6522b94c-1900-0000-8f35-a31775140000 pid=5237 execve guuid=9add8d4f-1900-0000-8f35-a3177a140000 pid=5242 /home/sandbox/morte.x86 guuid=ac8a9c48-1900-0000-8f35-a31774140000 pid=5236->guuid=9add8d4f-1900-0000-8f35-a3177a140000 pid=5242 clone guuid=6220064d-1900-0000-8f35-a31776140000 pid=5238 /usr/bin/cp guuid=6522b94c-1900-0000-8f35-a31775140000 pid=5237->guuid=6220064d-1900-0000-8f35-a31776140000 pid=5238 execve guuid=42ed3751-1900-0000-8f35-a3177b140000 pid=5243->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=5c5cc759-1900-0000-8f35-a3177f140000 pid=5247->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=238fa560-1900-0000-8f35-a31783140000 pid=5251->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=1d8de867-1900-0000-8f35-a31787140000 pid=5255->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=9a62f16c-1900-0000-8f35-a31789140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=45a17c6d-1900-0000-8f35-a3178a140000 pid=5258 /home/sandbox/morte.i686 guuid=9a62f16c-1900-0000-8f35-a31789140000 pid=5257->guuid=45a17c6d-1900-0000-8f35-a3178a140000 pid=5258 clone guuid=9ec68a6d-1900-0000-8f35-a3178c140000 pid=5260 /home/sandbox/morte.i686 write-config zombie guuid=45a17c6d-1900-0000-8f35-a3178a140000 pid=5258->guuid=9ec68a6d-1900-0000-8f35-a3178c140000 pid=5260 clone guuid=988d846d-1900-0000-8f35-a3178b140000 pid=5259->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=605c1571-1900-0000-8f35-a3178d140000 pid=5261 /usr/bin/dash guuid=9ec68a6d-1900-0000-8f35-a3178c140000 pid=5260->guuid=605c1571-1900-0000-8f35-a3178d140000 pid=5261 execve guuid=d8f1c473-1900-0000-8f35-a31790140000 pid=5264 /home/sandbox/morte.i686 guuid=9ec68a6d-1900-0000-8f35-a3178c140000 pid=5260->guuid=d8f1c473-1900-0000-8f35-a31790140000 pid=5264 clone guuid=5651e241-1b00-0000-8f35-a317f9140000 pid=5369 /home/sandbox/morte.i686 dns net send-data guuid=9ec68a6d-1900-0000-8f35-a3178c140000 pid=5260->guuid=5651e241-1b00-0000-8f35-a317f9140000 pid=5369 clone guuid=b5925571-1900-0000-8f35-a3178e140000 pid=5262 /usr/bin/cp guuid=605c1571-1900-0000-8f35-a3178d140000 pid=5261->guuid=b5925571-1900-0000-8f35-a3178e140000 pid=5262 execve guuid=8a507275-1900-0000-8f35-a31793140000 pid=5267->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=3fc6e37c-1900-0000-8f35-a31797140000 pid=5271->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=fd1fdd84-1900-0000-8f35-a3179b140000 pid=5275->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=f4adb18b-1900-0000-8f35-a3179f140000 pid=5279->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=bc97e193-1900-0000-8f35-a317a4140000 pid=5284->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 145B guuid=1bd61099-1900-0000-8f35-a317a6140000 pid=5286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2a1a7499-1900-0000-8f35-a317a7140000 pid=5287 /tmp/morte.x86_64 zombie guuid=1bd61099-1900-0000-8f35-a317a6140000 pid=5286->guuid=2a1a7499-1900-0000-8f35-a317a7140000 pid=5287 clone guuid=218f8099-1900-0000-8f35-a317a9140000 pid=5289 /tmp/morte.x86_64 write-config zombie guuid=2a1a7499-1900-0000-8f35-a317a7140000 pid=5287->guuid=218f8099-1900-0000-8f35-a317a9140000 pid=5289 clone guuid=24277d99-1900-0000-8f35-a317a8140000 pid=5288->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=a160ba99-1900-0000-8f35-a317aa140000 pid=5290 /usr/bin/dash guuid=218f8099-1900-0000-8f35-a317a9140000 pid=5289->guuid=a160ba99-1900-0000-8f35-a317aa140000 pid=5290 execve guuid=3f97c39a-1900-0000-8f35-a317ac140000 pid=5292 /tmp/morte.x86_64 zombie guuid=218f8099-1900-0000-8f35-a317a9140000 pid=5289->guuid=3f97c39a-1900-0000-8f35-a317ac140000 pid=5292 clone guuid=5a2ade99-1900-0000-8f35-a317ab140000 pid=5291 /usr/bin/cp guuid=a160ba99-1900-0000-8f35-a317aa140000 pid=5290->guuid=5a2ade99-1900-0000-8f35-a317ab140000 pid=5291 execve guuid=3f54d89e-1900-0000-8f35-a317ae140000 pid=5294->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=638e859f-1900-0000-8f35-a317af140000 pid=5295 /tmp/morte.x86 guuid=3f54d89e-1900-0000-8f35-a317ae140000 pid=5294->guuid=638e859f-1900-0000-8f35-a317af140000 pid=5295 clone guuid=cd19929f-1900-0000-8f35-a317b0140000 pid=5296 /tmp/morte.x86 write-config zombie guuid=638e859f-1900-0000-8f35-a317af140000 pid=5295->guuid=cd19929f-1900-0000-8f35-a317b0140000 pid=5296 clone guuid=8c3f07a3-1900-0000-8f35-a317b2140000 pid=5298 /usr/bin/dash guuid=cd19929f-1900-0000-8f35-a317b0140000 pid=5296->guuid=8c3f07a3-1900-0000-8f35-a317b2140000 pid=5298 execve guuid=b4479ca5-1900-0000-8f35-a317b7140000 pid=5303 /tmp/morte.x86 guuid=cd19929f-1900-0000-8f35-a317b0140000 pid=5296->guuid=b4479ca5-1900-0000-8f35-a317b7140000 pid=5303 clone guuid=986d939f-1900-0000-8f35-a317b1140000 pid=5297->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=b3a44ca3-1900-0000-8f35-a317b3140000 pid=5299 /usr/bin/cp guuid=8c3f07a3-1900-0000-8f35-a317b2140000 pid=5298->guuid=b3a44ca3-1900-0000-8f35-a317b3140000 pid=5299 execve guuid=794cd7a5-1900-0000-8f35-a317b8140000 pid=5304->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=627e59ab-1900-0000-8f35-a317bc140000 pid=5308->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=46428cb2-1900-0000-8f35-a317c0140000 pid=5312->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=0e7613ba-1900-0000-8f35-a317c4140000 pid=5316->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=441d9bbf-1900-0000-8f35-a317c6140000 pid=5318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=066817c0-1900-0000-8f35-a317c7140000 pid=5319 /tmp/morte.i686 guuid=441d9bbf-1900-0000-8f35-a317c6140000 pid=5318->guuid=066817c0-1900-0000-8f35-a317c7140000 pid=5319 clone guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321 /tmp/morte.i686 write-config zombie guuid=066817c0-1900-0000-8f35-a317c7140000 pid=5319->guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321 clone guuid=15ff1ec0-1900-0000-8f35-a317c8140000 pid=5320->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=e38eddc3-1900-0000-8f35-a317ca140000 pid=5322 /usr/bin/dash guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321->guuid=e38eddc3-1900-0000-8f35-a317ca140000 pid=5322 execve guuid=590dc8c6-1900-0000-8f35-a317cc140000 pid=5324 /tmp/morte.i686 guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321->guuid=590dc8c6-1900-0000-8f35-a317cc140000 pid=5324 clone guuid=a773407a-1c00-0000-8f35-a3170a150000 pid=5386 /tmp/morte.i686 dns net send-data guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321->guuid=a773407a-1c00-0000-8f35-a3170a150000 pid=5386 clone guuid=cd7fac30-2400-0000-8f35-a3170b150000 pid=5387 /tmp/morte.i686 dns net send-data guuid=03dd21c0-1900-0000-8f35-a317c9140000 pid=5321->guuid=cd7fac30-2400-0000-8f35-a3170b150000 pid=5387 clone guuid=9dfc52c4-1900-0000-8f35-a317cb140000 pid=5323 /usr/bin/cp guuid=e38eddc3-1900-0000-8f35-a317ca140000 pid=5322->guuid=9dfc52c4-1900-0000-8f35-a317cb140000 pid=5323 execve guuid=ae9229c9-1900-0000-8f35-a317d0140000 pid=5328->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=19fa9ad0-1900-0000-8f35-a317d4140000 pid=5332->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=8874ccd7-1900-0000-8f35-a317d8140000 pid=5336->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=5396abde-1900-0000-8f35-a317dc140000 pid=5340->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=5651e241-1b00-0000-8f35-a317f9140000 pid=5369->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1450B guuid=5651e241-1b00-0000-8f35-a317f9140000 pid=5369->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=a773407a-1c00-0000-8f35-a3170a150000 pid=5386->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2175B guuid=a773407a-1c00-0000-8f35-a3170a150000 pid=5386->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=cd7fac30-2400-0000-8f35-a3170b150000 pid=5387->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1450B guuid=cd7fac30-2400-0000-8f35-a3170b150000 pid=5387->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-25 06:55:32 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 13965237353de749da4cd8bd464341ac00c1bd447205948f4eaab8ad4128575f

(this sample)

  
Delivery method
Distributed via web download

Comments