MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1748ecc88d7151843531fcfa01058abd145011f2fcc59e14d9fd0b18e53c4e2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 1748ecc88d7151843531fcfa01058abd145011f2fcc59e14d9fd0b18e53c4e2f
SHA3-384 hash: c027b71ac3302f1b71b671d3f54d74b2a157d4257c7fbac96afa80f9960b9178086ddd144195cb49ad54d2d9e824c317
SHA1 hash: bbb37508d2146c267e8c9d0135d9e9e081c82060
MD5 hash: 05a8eabcca0a97da38a38ae5b47694d7
humanhash: gee-delaware-berlin-mobile
File name:dl201
Download: download sample
Signature Mirai
File size:3'741 bytes
First seen:2025-09-22 10:22:46 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:tFmMLcYVIw9RSXfj9tD6BgA1jefRGNvGMT/K:vTe
TLSH T1BF71929803E111519303364F7BF927A4AE6487F2AD7B0F95F861CAA8647459CF235B1C
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://31.170.22.205/bins/whisper.armv555d6cc5c314be3c2c988a797eeed584c7844549513e5eb9106a3a266f5c9c527 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.armv62b4c87240aaf767982d676933e628f8bf2957c931d906a90c88ccf3a18dc55ce DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.armv7e97da696893a2a090ac962789c524119aacab5583df1f2074c081295a0f582e3 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.aarch6438b7cbe9ff53cec015d67d04da59bcced70fae6c7e1d15baf95abc34035cc862 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.aarch64be5b489dfd7395de9106468d7b92374c56d30af994b4ea06be6c77e98ba540cf6a DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.arcle750d6001350ab65adfd7a9e0fca7560c49fc5d8f6e96939f1bdb630599e5fb902a14 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.arclehs381a3c8f2dbd32b05b5dc1c7ebd3b5cdaaf24fb5296978e6061671edca802a41f4 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.mips3d0ff85391334a8130b92bf85bb1b760f7f060508a5bfaab3ff7eb9a2ca53b0a DDoSAgentDDoSAgent elf mirai opendir
http://31.170.22.205/bins/whisper.mips64b8c1191781c9feb322cfcacf40f4f1d207a09af4d786e26a7455e8a36afd4a1c DDoSAgentDDoSAgent elf mirai opendir
http://31.170.22.205/bins/whisper.mips64le527a822afceebc65d8926a1dd0c3c97862f3e114db26f104797c58f45a2e609c DDoSAgentDDoSAgent elf mirai opendir
http://31.170.22.205/bins/whisper.mips64len32c6a1cd7348531c4c0db50ecf21f64e444b33a3ff194ed55a467adb938ec22408 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.mips64n3290676d5a951bfb339c20472a0d3ff253767268f54be520eb6410522eeba9741e DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.mipslee479f82af03dd6087f688cd398fc792a6443e362c9a36348ab53a3f6ddc591a2 DDoSAgentDDoSAgent elf mirai opendir
http://31.170.22.205/bins/whisper.riscv3245ca399bc539910e391f87bb398acac0f5c47410acb0d329ea3bf82406b3c189 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.riscv6484dbcc96a5ede7cb185d06f1116aee3bbe07e85ab020e86b5d4bfa9dcc6e60e1 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.m68kc304b1825bfe337bc1801440ca0bb1cda35aa96672d60952b852a5b2e3255f06 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.sh4n/an/aelf
http://31.170.22.205/bins/whisper.i6862ba541b4a6c62619d785852c86d67829118e70a52105ef37f32010aecb64784b DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.x6411742623bba0e1ca221814a36cd8239be94898c59fcc61c1328a6230a9981219 DDoSAgentDDoSAgent elf mirai opendir
http://31.170.22.205/bins/whisper.powerpc440fp197455fb6ac704dea344ee392427a842c243f6919c6886965b9586424b65e00b DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpc64e55001033d5f5d215d7df4d05737606f8323406eaeb9c215e1308fe48e77aba6f00f4 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpc64e6500a97c72cdfb63586cf2bbf84c6839b38eaf7af1a474d6f5f27af0b11f7140f067 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpc64lepower84d5ef555aac80b752223c279e28e49de774e1a68309e426095c52690a105f313 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpc64power8e3ed9343357d6cb963060d7908aa2637165f89cf21a4eb8f7538bb2ddb79e54f DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpce300c395d23e5693047c429dcf68baf9141ee074a578d08d434f6e1ae520374d0c7928 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.powerpce500mc189b5636d5a9a46a6ed38a7fdcd6b4f063fd7abc292363ff9ef7ac77852eae49 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.sparc25bf2d5845b6d3497bbceeeda40ba99a78e27f8ca88ec2efb690d919b4c5b8f6 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.sparc640e7338e304ae5c960e232d80d98edb0a281d03c974ab13c6de4b0596fd0557c9 DDoSAgentDDoSAgent elf
http://31.170.22.205/bins/whisper.armv4n/an/aelf

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
Detection(s):
URLhaus.3462419.UNOFFICIAL
URLhaus.3462413.UNOFFICIAL
URLhaus.3462403.UNOFFICIAL
URLhaus.3462409.UNOFFICIAL
URLhaus.3462416.UNOFFICIAL
URLhaus.3462399.UNOFFICIAL
URLhaus.3462402.UNOFFICIAL
URLhaus.3447675.UNOFFICIAL
URLhaus.3447676.UNOFFICIAL
URLhaus.3447679.UNOFFICIAL
URLhaus.3462417.UNOFFICIAL
URLhaus.3462395.UNOFFICIAL
URLhaus.3447674.UNOFFICIAL
URLhaus.3462404.UNOFFICIAL
URLhaus.3462410.UNOFFICIAL
URLhaus.3462418.UNOFFICIAL
URLhaus.3462407.UNOFFICIAL
URLhaus.3462397.UNOFFICIAL
URLhaus.3447677.UNOFFICIAL
URLhaus.3462398.UNOFFICIAL
URLhaus.3462400.UNOFFICIAL
URLhaus.3462415.UNOFFICIAL
URLhaus.3462406.UNOFFICIAL
URLhaus.3462405.UNOFFICIAL
URLhaus.3462401.UNOFFICIAL
URLhaus.3462396.UNOFFICIAL
URLhaus.3462412.UNOFFICIAL
URLhaus.3462408.UNOFFICIAL
URLhaus.3462414.UNOFFICIAL
Verdict:
Malicious
File Type:
text
First seen:
2025-09-22T08:45:00Z UTC
Last seen:
2025-09-22T08:45:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=98ac987a-1700-0000-e39f-75484f0b0000 pid=2895 /usr/bin/sudo guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900 /tmp/sample.bin guuid=98ac987a-1700-0000-e39f-75484f0b0000 pid=2895->guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900 execve guuid=69a9537c-1700-0000-e39f-7548560b0000 pid=2902 /usr/bin/rm guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=69a9537c-1700-0000-e39f-7548560b0000 pid=2902 execve guuid=6bd8057d-1700-0000-e39f-7548580b0000 pid=2904 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=6bd8057d-1700-0000-e39f-7548580b0000 pid=2904 execve guuid=c7b3fd8b-1700-0000-e39f-7548710b0000 pid=2929 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=c7b3fd8b-1700-0000-e39f-7548710b0000 pid=2929 execve guuid=c1c15c8c-1700-0000-e39f-7548740b0000 pid=2932 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=c1c15c8c-1700-0000-e39f-7548740b0000 pid=2932 clone guuid=0844ec8d-1700-0000-e39f-7548770b0000 pid=2935 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0844ec8d-1700-0000-e39f-7548770b0000 pid=2935 execve guuid=0f562d8e-1700-0000-e39f-7548790b0000 pid=2937 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0f562d8e-1700-0000-e39f-7548790b0000 pid=2937 execve guuid=cbf79e98-1700-0000-e39f-7548910b0000 pid=2961 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=cbf79e98-1700-0000-e39f-7548910b0000 pid=2961 execve guuid=53f6e198-1700-0000-e39f-7548930b0000 pid=2963 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=53f6e198-1700-0000-e39f-7548930b0000 pid=2963 clone guuid=4f6e8699-1700-0000-e39f-7548970b0000 pid=2967 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=4f6e8699-1700-0000-e39f-7548970b0000 pid=2967 execve guuid=dfb8e099-1700-0000-e39f-7548980b0000 pid=2968 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=dfb8e099-1700-0000-e39f-7548980b0000 pid=2968 execve guuid=89d08fa3-1700-0000-e39f-7548b60b0000 pid=2998 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=89d08fa3-1700-0000-e39f-7548b60b0000 pid=2998 execve guuid=66f7cba3-1700-0000-e39f-7548b70b0000 pid=2999 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=66f7cba3-1700-0000-e39f-7548b70b0000 pid=2999 clone guuid=6a4652a4-1700-0000-e39f-7548ba0b0000 pid=3002 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=6a4652a4-1700-0000-e39f-7548ba0b0000 pid=3002 execve guuid=677ca0a4-1700-0000-e39f-7548bb0b0000 pid=3003 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=677ca0a4-1700-0000-e39f-7548bb0b0000 pid=3003 execve guuid=fd3da7ad-1700-0000-e39f-7548d80b0000 pid=3032 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=fd3da7ad-1700-0000-e39f-7548d80b0000 pid=3032 execve guuid=f0a7dfad-1700-0000-e39f-7548da0b0000 pid=3034 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f0a7dfad-1700-0000-e39f-7548da0b0000 pid=3034 clone guuid=2203b1ae-1700-0000-e39f-7548df0b0000 pid=3039 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=2203b1ae-1700-0000-e39f-7548df0b0000 pid=3039 execve guuid=2cdde6ae-1700-0000-e39f-7548e10b0000 pid=3041 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=2cdde6ae-1700-0000-e39f-7548e10b0000 pid=3041 execve guuid=440275b7-1700-0000-e39f-7548070c0000 pid=3079 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=440275b7-1700-0000-e39f-7548070c0000 pid=3079 execve guuid=d102adb7-1700-0000-e39f-7548080c0000 pid=3080 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d102adb7-1700-0000-e39f-7548080c0000 pid=3080 clone guuid=fd7907b9-1700-0000-e39f-75480f0c0000 pid=3087 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=fd7907b9-1700-0000-e39f-75480f0c0000 pid=3087 execve guuid=89473ab9-1700-0000-e39f-7548110c0000 pid=3089 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=89473ab9-1700-0000-e39f-7548110c0000 pid=3089 execve guuid=f16c82c2-1700-0000-e39f-75482c0c0000 pid=3116 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f16c82c2-1700-0000-e39f-75482c0c0000 pid=3116 execve guuid=3025d3c2-1700-0000-e39f-75482f0c0000 pid=3119 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=3025d3c2-1700-0000-e39f-75482f0c0000 pid=3119 clone guuid=af5246c3-1700-0000-e39f-7548320c0000 pid=3122 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=af5246c3-1700-0000-e39f-7548320c0000 pid=3122 execve guuid=d9cc80c3-1700-0000-e39f-7548340c0000 pid=3124 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d9cc80c3-1700-0000-e39f-7548340c0000 pid=3124 execve guuid=0e538ecd-1700-0000-e39f-7548570c0000 pid=3159 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0e538ecd-1700-0000-e39f-7548570c0000 pid=3159 execve guuid=f6e8cacd-1700-0000-e39f-7548590c0000 pid=3161 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f6e8cacd-1700-0000-e39f-7548590c0000 pid=3161 clone guuid=408a0dcf-1700-0000-e39f-75485f0c0000 pid=3167 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=408a0dcf-1700-0000-e39f-75485f0c0000 pid=3167 execve guuid=106f48cf-1700-0000-e39f-7548630c0000 pid=3171 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=106f48cf-1700-0000-e39f-7548630c0000 pid=3171 execve guuid=fe1a9cd8-1700-0000-e39f-7548750c0000 pid=3189 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=fe1a9cd8-1700-0000-e39f-7548750c0000 pid=3189 execve guuid=d45a20d9-1700-0000-e39f-7548770c0000 pid=3191 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d45a20d9-1700-0000-e39f-7548770c0000 pid=3191 clone guuid=a0fa1eda-1700-0000-e39f-75487a0c0000 pid=3194 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=a0fa1eda-1700-0000-e39f-75487a0c0000 pid=3194 execve guuid=c1ce77da-1700-0000-e39f-75487c0c0000 pid=3196 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=c1ce77da-1700-0000-e39f-75487c0c0000 pid=3196 execve guuid=cbeee4e4-1700-0000-e39f-7548880c0000 pid=3208 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=cbeee4e4-1700-0000-e39f-7548880c0000 pid=3208 execve guuid=86dd86e5-1700-0000-e39f-7548890c0000 pid=3209 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=86dd86e5-1700-0000-e39f-7548890c0000 pid=3209 clone guuid=bba452e6-1700-0000-e39f-75488b0c0000 pid=3211 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=bba452e6-1700-0000-e39f-75488b0c0000 pid=3211 execve guuid=275db7e6-1700-0000-e39f-75488c0c0000 pid=3212 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=275db7e6-1700-0000-e39f-75488c0c0000 pid=3212 execve guuid=e2d28bf0-1700-0000-e39f-7548930c0000 pid=3219 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=e2d28bf0-1700-0000-e39f-7548930c0000 pid=3219 execve guuid=a4bddaf0-1700-0000-e39f-7548960c0000 pid=3222 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=a4bddaf0-1700-0000-e39f-7548960c0000 pid=3222 clone guuid=6f622ff2-1700-0000-e39f-75489a0c0000 pid=3226 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=6f622ff2-1700-0000-e39f-75489a0c0000 pid=3226 execve guuid=607570f2-1700-0000-e39f-75489b0c0000 pid=3227 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=607570f2-1700-0000-e39f-75489b0c0000 pid=3227 execve guuid=34cc0dfc-1700-0000-e39f-7548ae0c0000 pid=3246 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=34cc0dfc-1700-0000-e39f-7548ae0c0000 pid=3246 execve guuid=189548fc-1700-0000-e39f-7548b00c0000 pid=3248 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=189548fc-1700-0000-e39f-7548b00c0000 pid=3248 clone guuid=8884c5fd-1700-0000-e39f-7548b30c0000 pid=3251 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=8884c5fd-1700-0000-e39f-7548b30c0000 pid=3251 execve guuid=4de72afe-1700-0000-e39f-7548b60c0000 pid=3254 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=4de72afe-1700-0000-e39f-7548b60c0000 pid=3254 execve guuid=1d30c608-1800-0000-e39f-7548bb0c0000 pid=3259 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=1d30c608-1800-0000-e39f-7548bb0c0000 pid=3259 execve guuid=194f4609-1800-0000-e39f-7548bc0c0000 pid=3260 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=194f4609-1800-0000-e39f-7548bc0c0000 pid=3260 clone guuid=f230fb09-1800-0000-e39f-7548be0c0000 pid=3262 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f230fb09-1800-0000-e39f-7548be0c0000 pid=3262 execve guuid=5609ac0a-1800-0000-e39f-7548bf0c0000 pid=3263 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=5609ac0a-1800-0000-e39f-7548bf0c0000 pid=3263 execve guuid=0ceee714-1800-0000-e39f-7548c80c0000 pid=3272 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0ceee714-1800-0000-e39f-7548c80c0000 pid=3272 execve guuid=82222e15-1800-0000-e39f-7548c90c0000 pid=3273 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=82222e15-1800-0000-e39f-7548c90c0000 pid=3273 clone guuid=7fa12f16-1800-0000-e39f-7548cc0c0000 pid=3276 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=7fa12f16-1800-0000-e39f-7548cc0c0000 pid=3276 execve guuid=623a8b16-1800-0000-e39f-7548ce0c0000 pid=3278 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=623a8b16-1800-0000-e39f-7548ce0c0000 pid=3278 execve guuid=5b2f5321-1800-0000-e39f-7548db0c0000 pid=3291 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=5b2f5321-1800-0000-e39f-7548db0c0000 pid=3291 execve guuid=d5e99e21-1800-0000-e39f-7548dc0c0000 pid=3292 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d5e99e21-1800-0000-e39f-7548dc0c0000 pid=3292 clone guuid=0c886822-1800-0000-e39f-7548df0c0000 pid=3295 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0c886822-1800-0000-e39f-7548df0c0000 pid=3295 execve guuid=17e3a822-1800-0000-e39f-7548e10c0000 pid=3297 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=17e3a822-1800-0000-e39f-7548e10c0000 pid=3297 execve guuid=e3632b2d-1800-0000-e39f-7548f40c0000 pid=3316 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=e3632b2d-1800-0000-e39f-7548f40c0000 pid=3316 execve guuid=6f30e02d-1800-0000-e39f-7548f50c0000 pid=3317 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=6f30e02d-1800-0000-e39f-7548f50c0000 pid=3317 clone guuid=ebac8e2f-1800-0000-e39f-7548f70c0000 pid=3319 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=ebac8e2f-1800-0000-e39f-7548f70c0000 pid=3319 execve guuid=b1441c30-1800-0000-e39f-7548f80c0000 pid=3320 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=b1441c30-1800-0000-e39f-7548f80c0000 pid=3320 execve guuid=dd643e3a-1800-0000-e39f-75480d0d0000 pid=3341 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=dd643e3a-1800-0000-e39f-75480d0d0000 pid=3341 execve guuid=01089a3a-1800-0000-e39f-75480f0d0000 pid=3343 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=01089a3a-1800-0000-e39f-75480f0d0000 pid=3343 clone guuid=cfaa6f3b-1800-0000-e39f-7548120d0000 pid=3346 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=cfaa6f3b-1800-0000-e39f-7548120d0000 pid=3346 execve guuid=f5e5cd3b-1800-0000-e39f-7548140d0000 pid=3348 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f5e5cd3b-1800-0000-e39f-7548140d0000 pid=3348 execve guuid=197a7b45-1800-0000-e39f-75482c0d0000 pid=3372 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=197a7b45-1800-0000-e39f-75482c0d0000 pid=3372 execve guuid=df3dbd45-1800-0000-e39f-75482e0d0000 pid=3374 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=df3dbd45-1800-0000-e39f-75482e0d0000 pid=3374 clone guuid=34455b46-1800-0000-e39f-7548310d0000 pid=3377 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=34455b46-1800-0000-e39f-7548310d0000 pid=3377 execve guuid=2b029c46-1800-0000-e39f-7548330d0000 pid=3379 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=2b029c46-1800-0000-e39f-7548330d0000 pid=3379 execve guuid=d3634351-1800-0000-e39f-75484a0d0000 pid=3402 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d3634351-1800-0000-e39f-75484a0d0000 pid=3402 execve guuid=e7da9351-1800-0000-e39f-75484b0d0000 pid=3403 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=e7da9351-1800-0000-e39f-75484b0d0000 pid=3403 clone guuid=08c83552-1800-0000-e39f-75484d0d0000 pid=3405 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=08c83552-1800-0000-e39f-75484d0d0000 pid=3405 execve guuid=65d48752-1800-0000-e39f-75484e0d0000 pid=3406 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=65d48752-1800-0000-e39f-75484e0d0000 pid=3406 execve guuid=9c92315c-1800-0000-e39f-75485a0d0000 pid=3418 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=9c92315c-1800-0000-e39f-75485a0d0000 pid=3418 execve guuid=6d86ab5c-1800-0000-e39f-75485c0d0000 pid=3420 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=6d86ab5c-1800-0000-e39f-75485c0d0000 pid=3420 clone guuid=e1de205e-1800-0000-e39f-75485f0d0000 pid=3423 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=e1de205e-1800-0000-e39f-75485f0d0000 pid=3423 execve guuid=005d685e-1800-0000-e39f-7548610d0000 pid=3425 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=005d685e-1800-0000-e39f-7548610d0000 pid=3425 execve guuid=983af569-1800-0000-e39f-75487b0d0000 pid=3451 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=983af569-1800-0000-e39f-75487b0d0000 pid=3451 execve guuid=c41e316a-1800-0000-e39f-75487d0d0000 pid=3453 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=c41e316a-1800-0000-e39f-75487d0d0000 pid=3453 clone guuid=beefbd6a-1800-0000-e39f-7548800d0000 pid=3456 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=beefbd6a-1800-0000-e39f-7548800d0000 pid=3456 execve guuid=010b456b-1800-0000-e39f-7548820d0000 pid=3458 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=010b456b-1800-0000-e39f-7548820d0000 pid=3458 execve guuid=bf9deb76-1800-0000-e39f-7548a00d0000 pid=3488 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=bf9deb76-1800-0000-e39f-7548a00d0000 pid=3488 execve guuid=80b03577-1800-0000-e39f-7548a20d0000 pid=3490 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=80b03577-1800-0000-e39f-7548a20d0000 pid=3490 clone guuid=501fbf77-1800-0000-e39f-7548a60d0000 pid=3494 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=501fbf77-1800-0000-e39f-7548a60d0000 pid=3494 execve guuid=8ee5f877-1800-0000-e39f-7548a80d0000 pid=3496 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=8ee5f877-1800-0000-e39f-7548a80d0000 pid=3496 execve guuid=2bc9fc80-1800-0000-e39f-7548c20d0000 pid=3522 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=2bc9fc80-1800-0000-e39f-7548c20d0000 pid=3522 execve guuid=b1b04981-1800-0000-e39f-7548c30d0000 pid=3523 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=b1b04981-1800-0000-e39f-7548c30d0000 pid=3523 clone guuid=a844be81-1800-0000-e39f-7548c60d0000 pid=3526 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=a844be81-1800-0000-e39f-7548c60d0000 pid=3526 execve guuid=f909fc81-1800-0000-e39f-7548c90d0000 pid=3529 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f909fc81-1800-0000-e39f-7548c90d0000 pid=3529 execve guuid=71e2288b-1800-0000-e39f-7548eb0d0000 pid=3563 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=71e2288b-1800-0000-e39f-7548eb0d0000 pid=3563 execve guuid=e676658b-1800-0000-e39f-7548ed0d0000 pid=3565 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=e676658b-1800-0000-e39f-7548ed0d0000 pid=3565 clone guuid=1b1c178c-1800-0000-e39f-7548f00d0000 pid=3568 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=1b1c178c-1800-0000-e39f-7548f00d0000 pid=3568 execve guuid=5f4d688c-1800-0000-e39f-7548f20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=5f4d688c-1800-0000-e39f-7548f20d0000 pid=3570 execve guuid=0563b495-1800-0000-e39f-75480b0e0000 pid=3595 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0563b495-1800-0000-e39f-75480b0e0000 pid=3595 execve guuid=86b3ec95-1800-0000-e39f-75480c0e0000 pid=3596 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=86b3ec95-1800-0000-e39f-75480c0e0000 pid=3596 clone guuid=b6a76496-1800-0000-e39f-75480e0e0000 pid=3598 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=b6a76496-1800-0000-e39f-75480e0e0000 pid=3598 execve guuid=890a9996-1800-0000-e39f-75480f0e0000 pid=3599 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=890a9996-1800-0000-e39f-75480f0e0000 pid=3599 execve guuid=d046299f-1800-0000-e39f-7548240e0000 pid=3620 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d046299f-1800-0000-e39f-7548240e0000 pid=3620 execve guuid=199e939f-1800-0000-e39f-7548260e0000 pid=3622 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=199e939f-1800-0000-e39f-7548260e0000 pid=3622 clone guuid=7da077a0-1800-0000-e39f-7548280e0000 pid=3624 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=7da077a0-1800-0000-e39f-7548280e0000 pid=3624 execve guuid=db3f00a1-1800-0000-e39f-75482a0e0000 pid=3626 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=db3f00a1-1800-0000-e39f-75482a0e0000 pid=3626 execve guuid=c3fdd8ac-1800-0000-e39f-75484d0e0000 pid=3661 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=c3fdd8ac-1800-0000-e39f-75484d0e0000 pid=3661 execve guuid=0b5318ad-1800-0000-e39f-75484f0e0000 pid=3663 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=0b5318ad-1800-0000-e39f-75484f0e0000 pid=3663 clone guuid=35c7b1ad-1800-0000-e39f-7548530e0000 pid=3667 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=35c7b1ad-1800-0000-e39f-7548530e0000 pid=3667 execve guuid=f212efad-1800-0000-e39f-7548550e0000 pid=3669 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=f212efad-1800-0000-e39f-7548550e0000 pid=3669 execve guuid=97f5ceb7-1800-0000-e39f-7548700e0000 pid=3696 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=97f5ceb7-1800-0000-e39f-7548700e0000 pid=3696 execve guuid=09af2eb8-1800-0000-e39f-7548710e0000 pid=3697 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=09af2eb8-1800-0000-e39f-7548710e0000 pid=3697 clone guuid=b7f0adb9-1800-0000-e39f-7548770e0000 pid=3703 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=b7f0adb9-1800-0000-e39f-7548770e0000 pid=3703 execve guuid=7fd6f5b9-1800-0000-e39f-7548790e0000 pid=3705 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=7fd6f5b9-1800-0000-e39f-7548790e0000 pid=3705 execve guuid=5c6acbc2-1800-0000-e39f-7548940e0000 pid=3732 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=5c6acbc2-1800-0000-e39f-7548940e0000 pid=3732 execve guuid=73fa01c3-1800-0000-e39f-7548950e0000 pid=3733 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=73fa01c3-1800-0000-e39f-7548950e0000 pid=3733 clone guuid=010576c3-1800-0000-e39f-7548990e0000 pid=3737 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=010576c3-1800-0000-e39f-7548990e0000 pid=3737 execve guuid=1a6faec3-1800-0000-e39f-75489b0e0000 pid=3739 /usr/bin/curl net send-data write-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=1a6faec3-1800-0000-e39f-75489b0e0000 pid=3739 execve guuid=98bfd4cc-1800-0000-e39f-7548bc0e0000 pid=3772 /usr/bin/chmod guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=98bfd4cc-1800-0000-e39f-7548bc0e0000 pid=3772 execve guuid=d08b0dcd-1800-0000-e39f-7548bd0e0000 pid=3773 /usr/bin/dash guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d08b0dcd-1800-0000-e39f-7548bd0e0000 pid=3773 clone guuid=d19c5bce-1800-0000-e39f-7548c30e0000 pid=3779 /usr/bin/rm delete-file guuid=4d271a7c-1700-0000-e39f-7548540b0000 pid=2900->guuid=d19c5bce-1800-0000-e39f-7548c30e0000 pid=3779 execve 4466a7ec-d357-5dbd-9f7f-c7e61f48c387 31.170.22.205:80 guuid=6bd8057d-1700-0000-e39f-7548580b0000 pid=2904->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 95B guuid=0f562d8e-1700-0000-e39f-7548790b0000 pid=2937->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 95B guuid=dfb8e099-1700-0000-e39f-7548980b0000 pid=2968->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 95B guuid=677ca0a4-1700-0000-e39f-7548bb0b0000 pid=3003->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 97B guuid=2cdde6ae-1700-0000-e39f-7548e10b0000 pid=3041->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 99B guuid=89473ab9-1700-0000-e39f-7548110c0000 pid=3089->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 99B guuid=d9cc80c3-1700-0000-e39f-7548340c0000 pid=3124->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 99B guuid=106f48cf-1700-0000-e39f-7548630c0000 pid=3171->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 94B guuid=c1ce77da-1700-0000-e39f-75487c0c0000 pid=3196->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 96B guuid=275db7e6-1700-0000-e39f-75488c0c0000 pid=3212->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 98B guuid=607570f2-1700-0000-e39f-75489b0c0000 pid=3227->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 101B guuid=4de72afe-1700-0000-e39f-7548b60c0000 pid=3254->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 99B guuid=5609ac0a-1800-0000-e39f-7548bf0c0000 pid=3263->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 96B guuid=623a8b16-1800-0000-e39f-7548ce0c0000 pid=3278->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 97B guuid=17e3a822-1800-0000-e39f-7548e10c0000 pid=3297->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 97B guuid=b1441c30-1800-0000-e39f-7548f80c0000 pid=3320->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 94B guuid=f5e5cd3b-1800-0000-e39f-7548140d0000 pid=3348->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 93B guuid=2b029c46-1800-0000-e39f-7548330d0000 pid=3379->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 94B guuid=65d48752-1800-0000-e39f-75484e0d0000 pid=3406->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 93B guuid=005d685e-1800-0000-e39f-7548610d0000 pid=3425->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 102B guuid=010b456b-1800-0000-e39f-7548820d0000 pid=3458->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 104B guuid=8ee5f877-1800-0000-e39f-7548a80d0000 pid=3496->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 104B guuid=f909fc81-1800-0000-e39f-7548c90d0000 pid=3529->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 107B guuid=5f4d688c-1800-0000-e39f-7548f20d0000 pid=3570->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 105B guuid=890a9996-1800-0000-e39f-75480f0e0000 pid=3599->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 103B guuid=db3f00a1-1800-0000-e39f-75482a0e0000 pid=3626->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 103B guuid=f212efad-1800-0000-e39f-7548550e0000 pid=3669->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 95B guuid=7fd6f5b9-1800-0000-e39f-7548790e0000 pid=3705->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 97B guuid=1a6faec3-1800-0000-e39f-75489b0e0000 pid=3739->4466a7ec-d357-5dbd-9f7f-c7e61f48c387 send: 95B
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-09-22 11:10:11 UTC
File Type:
Text (Shell)
AV detection:
8 of 23 (34.78%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1748ecc88d7151843531fcfa01058abd145011f2fcc59e14d9fd0b18e53c4e2f

(this sample)

  
Delivery method
Distributed via web download

Comments