MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f02636d03d8016446a1df6bf3976255a99740b48ad838eb53eb1cdc083a0d3f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 2f02636d03d8016446a1df6bf3976255a99740b48ad838eb53eb1cdc083a0d3f
SHA3-384 hash: fad4bd99cfaad8597b4026fd3a2b3d3278ece22a33bd66a7ddb5fa98029fb4a0ad6b4db018cf66657382eaef9baffd53
SHA1 hash: 18af3539ea65e4839db921eae18853530176d460
MD5 hash: 94a1e3c513bc6eef0fa18060e9d4d4a7
humanhash: nitrogen-ack-football-leopard
File name:and
Download: download sample
Signature Mirai
File size:3'736 bytes
First seen:2025-07-10 06:02:56 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:RCwsW0MyRfmWLbETGNI6mvKXgN+lf2Qs4Mdm4QZfDLyhb7zWOYgG15bXIL7VvEED:gwsW7Wf32DN+7xBHA/BG15jI7h+o7L3
TLSH T1FA7192FF2342682F4666DAE038918509A25469C3B8CC3374DBAC9532DDC1EDEBDC599C
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.44/00101010101001/an/an/aelf ua-wget
http://87.121.84.44/00101010101001/morte.armc323ffb320b490e697419b50310aa8c2ac72447123f637404aab870431f2af02 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.arm50af60479a4f52295d54a989ef3857f327e29129759094bd299d232f6b7b27396 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.arm6c0a05e039d5c3eb2be10b4bf48a58684466b52387506db4ca927b34220777c49 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.arm7aa7a00f2e8fa6079833b368bb53e0379df669d09f5490e578568e00c3b486f17 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.m68kac5c338c558a7b2679876efa6965ad0fa2868cd2d42288e2492113c619622134 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.mipsb3211943b1a91fb0f11eb32a0d5e74ae9eb4ae7df45daf3f368ba6216c63a739 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.mpsl388fca18d135e0355f1d8f0b6d72583d868fdedfd94e4433c13cabf2e22293ac Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.ppcb05136041ee5e91d5a13ef2e542bd5e2a99a7c671a7b223db60edfc83e0ed94c Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.sh4ba212c7156c961b97874657e81393cb6b94eef969c3e0b6e744956770d8f394a Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.spca5096a6f6f1d1a3a6cec37e9739eec6a57b20cb9a36cc36c36b6ad5b5876b953 Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.x862640512201ae2a0f515b0cc9d8cb8bba20c440aef5c91d0f7632d5f12b1bc01e Miraielf mirai ua-wget
http://87.121.84.44/00101010101001/morte.x86_644fa0b919f29ce04e492564cdc7fd04493f3c0fe4936f540b832fbbbb91ebd224 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
97.4%
Tags:
downloader ransomware trojan mirai
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=26b99151-1a00-0000-c4f2-d48faf0a0000 pid=2735 /usr/bin/sudo guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741 /tmp/sample.bin guuid=26b99151-1a00-0000-c4f2-d48faf0a0000 pid=2735->guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741 execve guuid=f21ff553-1a00-0000-c4f2-d48fb60a0000 pid=2742 /usr/bin/pgrep guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=f21ff553-1a00-0000-c4f2-d48fb60a0000 pid=2742 execve guuid=a11c7258-1a00-0000-c4f2-d48fbe0a0000 pid=2750 /usr/bin/pgrep guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=a11c7258-1a00-0000-c4f2-d48fbe0a0000 pid=2750 execve guuid=c4eac85a-1a00-0000-c4f2-d48fc60a0000 pid=2758 /usr/bin/pgrep guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=c4eac85a-1a00-0000-c4f2-d48fc60a0000 pid=2758 execve guuid=0d642660-1a00-0000-c4f2-d48fc80a0000 pid=2760 /usr/bin/pgrep guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=0d642660-1a00-0000-c4f2-d48fc80a0000 pid=2760 execve guuid=e5819362-1a00-0000-c4f2-d48fcf0a0000 pid=2767 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e5819362-1a00-0000-c4f2-d48fcf0a0000 pid=2767 execve guuid=d42f7063-1a00-0000-c4f2-d48fd10a0000 pid=2769 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=d42f7063-1a00-0000-c4f2-d48fd10a0000 pid=2769 execve guuid=d2383b64-1a00-0000-c4f2-d48fd20a0000 pid=2770 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=d2383b64-1a00-0000-c4f2-d48fd20a0000 pid=2770 execve guuid=72962465-1a00-0000-c4f2-d48fd30a0000 pid=2771 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=72962465-1a00-0000-c4f2-d48fd30a0000 pid=2771 execve guuid=852ecb65-1a00-0000-c4f2-d48fd60a0000 pid=2774 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=852ecb65-1a00-0000-c4f2-d48fd60a0000 pid=2774 execve guuid=e5843d66-1a00-0000-c4f2-d48fd90a0000 pid=2777 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e5843d66-1a00-0000-c4f2-d48fd90a0000 pid=2777 execve guuid=07339066-1a00-0000-c4f2-d48fda0a0000 pid=2778 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=07339066-1a00-0000-c4f2-d48fda0a0000 pid=2778 execve guuid=d74ae066-1a00-0000-c4f2-d48fdc0a0000 pid=2780 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=d74ae066-1a00-0000-c4f2-d48fdc0a0000 pid=2780 execve guuid=e53caa6a-1a00-0000-c4f2-d48fe60a0000 pid=2790 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e53caa6a-1a00-0000-c4f2-d48fe60a0000 pid=2790 execve guuid=2117ed6a-1a00-0000-c4f2-d48fe70a0000 pid=2791 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=2117ed6a-1a00-0000-c4f2-d48fe70a0000 pid=2791 execve guuid=491e2e6b-1a00-0000-c4f2-d48fe80a0000 pid=2792 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=491e2e6b-1a00-0000-c4f2-d48fe80a0000 pid=2792 execve guuid=867b7f6f-1a00-0000-c4f2-d48ff40a0000 pid=2804 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=867b7f6f-1a00-0000-c4f2-d48ff40a0000 pid=2804 execve guuid=a7290e70-1a00-0000-c4f2-d48ff50a0000 pid=2805 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=a7290e70-1a00-0000-c4f2-d48ff50a0000 pid=2805 clone guuid=47327571-1a00-0000-c4f2-d48ff90a0000 pid=2809 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=47327571-1a00-0000-c4f2-d48ff90a0000 pid=2809 execve guuid=e331aa7a-1a00-0000-c4f2-d48ffe0a0000 pid=2814 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e331aa7a-1a00-0000-c4f2-d48ffe0a0000 pid=2814 execve guuid=8d00367b-1a00-0000-c4f2-d48fff0a0000 pid=2815 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=8d00367b-1a00-0000-c4f2-d48fff0a0000 pid=2815 clone guuid=779a5c7e-1a00-0000-c4f2-d48f020b0000 pid=2818 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=779a5c7e-1a00-0000-c4f2-d48f020b0000 pid=2818 execve guuid=5dc6e483-1a00-0000-c4f2-d48f0a0b0000 pid=2826 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=5dc6e483-1a00-0000-c4f2-d48f0a0b0000 pid=2826 execve guuid=d56a4784-1a00-0000-c4f2-d48f0d0b0000 pid=2829 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=d56a4784-1a00-0000-c4f2-d48f0d0b0000 pid=2829 clone guuid=1ac69085-1a00-0000-c4f2-d48f120b0000 pid=2834 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=1ac69085-1a00-0000-c4f2-d48f120b0000 pid=2834 execve guuid=c330d28a-1a00-0000-c4f2-d48f170b0000 pid=2839 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=c330d28a-1a00-0000-c4f2-d48f170b0000 pid=2839 execve guuid=8ad2308b-1a00-0000-c4f2-d48f190b0000 pid=2841 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=8ad2308b-1a00-0000-c4f2-d48f190b0000 pid=2841 clone guuid=79ae508c-1a00-0000-c4f2-d48f1d0b0000 pid=2845 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=79ae508c-1a00-0000-c4f2-d48f1d0b0000 pid=2845 execve guuid=c8364491-1a00-0000-c4f2-d48f280b0000 pid=2856 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=c8364491-1a00-0000-c4f2-d48f280b0000 pid=2856 execve guuid=209b9791-1a00-0000-c4f2-d48f290b0000 pid=2857 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=209b9791-1a00-0000-c4f2-d48f290b0000 pid=2857 clone guuid=25f28892-1a00-0000-c4f2-d48f2c0b0000 pid=2860 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=25f28892-1a00-0000-c4f2-d48f2c0b0000 pid=2860 execve guuid=28fe9696-1a00-0000-c4f2-d48f330b0000 pid=2867 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=28fe9696-1a00-0000-c4f2-d48f330b0000 pid=2867 execve guuid=aebfed96-1a00-0000-c4f2-d48f340b0000 pid=2868 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=aebfed96-1a00-0000-c4f2-d48f340b0000 pid=2868 clone guuid=9664dd97-1a00-0000-c4f2-d48f380b0000 pid=2872 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=9664dd97-1a00-0000-c4f2-d48f380b0000 pid=2872 execve guuid=fa787a9e-1a00-0000-c4f2-d48f440b0000 pid=2884 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=fa787a9e-1a00-0000-c4f2-d48f440b0000 pid=2884 execve guuid=4ae6e59e-1a00-0000-c4f2-d48f460b0000 pid=2886 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=4ae6e59e-1a00-0000-c4f2-d48f460b0000 pid=2886 clone guuid=c22704a0-1a00-0000-c4f2-d48f490b0000 pid=2889 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=c22704a0-1a00-0000-c4f2-d48f490b0000 pid=2889 execve guuid=858f2aa4-1a00-0000-c4f2-d48f510b0000 pid=2897 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=858f2aa4-1a00-0000-c4f2-d48f510b0000 pid=2897 execve guuid=28df91a4-1a00-0000-c4f2-d48f520b0000 pid=2898 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=28df91a4-1a00-0000-c4f2-d48f520b0000 pid=2898 clone guuid=65e877a5-1a00-0000-c4f2-d48f560b0000 pid=2902 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=65e877a5-1a00-0000-c4f2-d48f560b0000 pid=2902 execve guuid=790b05aa-1a00-0000-c4f2-d48f610b0000 pid=2913 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=790b05aa-1a00-0000-c4f2-d48f610b0000 pid=2913 execve guuid=9b3752aa-1a00-0000-c4f2-d48f630b0000 pid=2915 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=9b3752aa-1a00-0000-c4f2-d48f630b0000 pid=2915 clone guuid=05c454ab-1a00-0000-c4f2-d48f670b0000 pid=2919 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=05c454ab-1a00-0000-c4f2-d48f670b0000 pid=2919 execve guuid=e43c2cb3-1a00-0000-c4f2-d48f7f0b0000 pid=2943 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e43c2cb3-1a00-0000-c4f2-d48f7f0b0000 pid=2943 execve guuid=0c05b2b3-1a00-0000-c4f2-d48f810b0000 pid=2945 /usr/bin/dash guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=0c05b2b3-1a00-0000-c4f2-d48f810b0000 pid=2945 clone guuid=1276cab4-1a00-0000-c4f2-d48f830b0000 pid=2947 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=1276cab4-1a00-0000-c4f2-d48f830b0000 pid=2947 execve guuid=a77c19b8-1a00-0000-c4f2-d48f8b0b0000 pid=2955 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=a77c19b8-1a00-0000-c4f2-d48f8b0b0000 pid=2955 execve guuid=569c95b8-1a00-0000-c4f2-d48f8d0b0000 pid=2957 /home/sandbox/morte.x86 net guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=569c95b8-1a00-0000-c4f2-d48f8d0b0000 pid=2957 execve guuid=d9f9e2b8-1a00-0000-c4f2-d48f910b0000 pid=2961 /usr/bin/busybox net send-data write-file guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=d9f9e2b8-1a00-0000-c4f2-d48f910b0000 pid=2961 execve guuid=99af49bf-1a00-0000-c4f2-d48f9f0b0000 pid=2975 /usr/bin/chmod guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=99af49bf-1a00-0000-c4f2-d48f9f0b0000 pid=2975 execve guuid=a6d7b3bf-1a00-0000-c4f2-d48fa10b0000 pid=2977 /home/sandbox/morte.x86_64 mprotect-exec net guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=a6d7b3bf-1a00-0000-c4f2-d48fa10b0000 pid=2977 execve guuid=ad058a37-1b00-0000-c4f2-d48f850c0000 pid=3205 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=ad058a37-1b00-0000-c4f2-d48f850c0000 pid=3205 execve guuid=8c700d38-1b00-0000-c4f2-d48f860c0000 pid=3206 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=8c700d38-1b00-0000-c4f2-d48f860c0000 pid=3206 execve guuid=791e8738-1b00-0000-c4f2-d48f870c0000 pid=3207 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=791e8738-1b00-0000-c4f2-d48f870c0000 pid=3207 execve guuid=3ab70739-1b00-0000-c4f2-d48f890c0000 pid=3209 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=3ab70739-1b00-0000-c4f2-d48f890c0000 pid=3209 execve guuid=25da8b39-1b00-0000-c4f2-d48f8c0c0000 pid=3212 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=25da8b39-1b00-0000-c4f2-d48f8c0c0000 pid=3212 execve guuid=7fc6e93a-1b00-0000-c4f2-d48f900c0000 pid=3216 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=7fc6e93a-1b00-0000-c4f2-d48f900c0000 pid=3216 execve guuid=60b28d3b-1b00-0000-c4f2-d48f930c0000 pid=3219 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=60b28d3b-1b00-0000-c4f2-d48f930c0000 pid=3219 execve guuid=3f7f313c-1b00-0000-c4f2-d48f960c0000 pid=3222 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=3f7f313c-1b00-0000-c4f2-d48f960c0000 pid=3222 execve guuid=5514a93c-1b00-0000-c4f2-d48f970c0000 pid=3223 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=5514a93c-1b00-0000-c4f2-d48f970c0000 pid=3223 execve guuid=4f703c3d-1b00-0000-c4f2-d48f990c0000 pid=3225 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=4f703c3d-1b00-0000-c4f2-d48f990c0000 pid=3225 execve guuid=b67fbe3d-1b00-0000-c4f2-d48f9a0c0000 pid=3226 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=b67fbe3d-1b00-0000-c4f2-d48f9a0c0000 pid=3226 execve guuid=6a87b03e-1b00-0000-c4f2-d48f9b0c0000 pid=3227 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=6a87b03e-1b00-0000-c4f2-d48f9b0c0000 pid=3227 execve guuid=ab788e3f-1b00-0000-c4f2-d48f9d0c0000 pid=3229 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=ab788e3f-1b00-0000-c4f2-d48f9d0c0000 pid=3229 execve guuid=ca2d0740-1b00-0000-c4f2-d48fa00c0000 pid=3232 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=ca2d0740-1b00-0000-c4f2-d48fa00c0000 pid=3232 execve guuid=c4106e40-1b00-0000-c4f2-d48fa20c0000 pid=3234 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=c4106e40-1b00-0000-c4f2-d48fa20c0000 pid=3234 execve guuid=09d9d240-1b00-0000-c4f2-d48fa40c0000 pid=3236 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=09d9d240-1b00-0000-c4f2-d48fa40c0000 pid=3236 execve guuid=2bc04a41-1b00-0000-c4f2-d48fa60c0000 pid=3238 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=2bc04a41-1b00-0000-c4f2-d48fa60c0000 pid=3238 execve guuid=024fbf41-1b00-0000-c4f2-d48fa70c0000 pid=3239 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=024fbf41-1b00-0000-c4f2-d48fa70c0000 pid=3239 execve guuid=2c7f4142-1b00-0000-c4f2-d48fa90c0000 pid=3241 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=2c7f4142-1b00-0000-c4f2-d48fa90c0000 pid=3241 execve guuid=24cec942-1b00-0000-c4f2-d48faa0c0000 pid=3242 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=24cec942-1b00-0000-c4f2-d48faa0c0000 pid=3242 execve guuid=cf7a8d43-1b00-0000-c4f2-d48fac0c0000 pid=3244 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=cf7a8d43-1b00-0000-c4f2-d48fac0c0000 pid=3244 execve guuid=46e9e243-1b00-0000-c4f2-d48fae0c0000 pid=3246 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=46e9e243-1b00-0000-c4f2-d48fae0c0000 pid=3246 execve guuid=17893d44-1b00-0000-c4f2-d48fb00c0000 pid=3248 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=17893d44-1b00-0000-c4f2-d48fb00c0000 pid=3248 execve guuid=96d19344-1b00-0000-c4f2-d48fb20c0000 pid=3250 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=96d19344-1b00-0000-c4f2-d48fb20c0000 pid=3250 execve guuid=f16af044-1b00-0000-c4f2-d48fb50c0000 pid=3253 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=f16af044-1b00-0000-c4f2-d48fb50c0000 pid=3253 execve guuid=41064d45-1b00-0000-c4f2-d48fb60c0000 pid=3254 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=41064d45-1b00-0000-c4f2-d48fb60c0000 pid=3254 execve guuid=de65af45-1b00-0000-c4f2-d48fb80c0000 pid=3256 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=de65af45-1b00-0000-c4f2-d48fb80c0000 pid=3256 execve guuid=9dd22f46-1b00-0000-c4f2-d48fb90c0000 pid=3257 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=9dd22f46-1b00-0000-c4f2-d48fb90c0000 pid=3257 execve guuid=737b9846-1b00-0000-c4f2-d48fbb0c0000 pid=3259 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=737b9846-1b00-0000-c4f2-d48fbb0c0000 pid=3259 execve guuid=e27cf746-1b00-0000-c4f2-d48fbd0c0000 pid=3261 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e27cf746-1b00-0000-c4f2-d48fbd0c0000 pid=3261 execve guuid=57525e47-1b00-0000-c4f2-d48fc00c0000 pid=3264 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=57525e47-1b00-0000-c4f2-d48fc00c0000 pid=3264 execve guuid=e7f41b48-1b00-0000-c4f2-d48fc30c0000 pid=3267 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e7f41b48-1b00-0000-c4f2-d48fc30c0000 pid=3267 execve guuid=82d79b48-1b00-0000-c4f2-d48fc40c0000 pid=3268 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=82d79b48-1b00-0000-c4f2-d48fc40c0000 pid=3268 execve guuid=42002049-1b00-0000-c4f2-d48fc50c0000 pid=3269 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=42002049-1b00-0000-c4f2-d48fc50c0000 pid=3269 execve guuid=76e09c49-1b00-0000-c4f2-d48fc60c0000 pid=3270 /usr/bin/su guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=76e09c49-1b00-0000-c4f2-d48fc60c0000 pid=3270 execve guuid=e389174a-1b00-0000-c4f2-d48fc70c0000 pid=3271 /usr/bin/rm guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=e389174a-1b00-0000-c4f2-d48fc70c0000 pid=3271 execve guuid=410a9c4a-1b00-0000-c4f2-d48fc80c0000 pid=3272 /usr/bin/rm guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=410a9c4a-1b00-0000-c4f2-d48fc80c0000 pid=3272 execve guuid=7238ef4a-1b00-0000-c4f2-d48fc90c0000 pid=3273 /usr/bin/rm guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=7238ef4a-1b00-0000-c4f2-d48fc90c0000 pid=3273 execve guuid=a5b8604b-1b00-0000-c4f2-d48fca0c0000 pid=3274 /usr/bin/rm guuid=f7ebba53-1a00-0000-c4f2-d48fb50a0000 pid=2741->guuid=a5b8604b-1b00-0000-c4f2-d48fca0c0000 pid=3274 execve 11793493-ec19-521c-b424-e4936d1f1fea 87.121.84.44:80 guuid=d74ae066-1a00-0000-c4f2-d48fdc0a0000 pid=2780->11793493-ec19-521c-b424-e4936d1f1fea send: 91B guuid=491e2e6b-1a00-0000-c4f2-d48fe80a0000 pid=2792->11793493-ec19-521c-b424-e4936d1f1fea send: 99B guuid=47327571-1a00-0000-c4f2-d48ff90a0000 pid=2809->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=779a5c7e-1a00-0000-c4f2-d48f020b0000 pid=2818->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=1ac69085-1a00-0000-c4f2-d48f120b0000 pid=2834->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=79ae508c-1a00-0000-c4f2-d48f1d0b0000 pid=2845->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=25f28892-1a00-0000-c4f2-d48f2c0b0000 pid=2860->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=9664dd97-1a00-0000-c4f2-d48f380b0000 pid=2872->11793493-ec19-521c-b424-e4936d1f1fea send: 100B guuid=c22704a0-1a00-0000-c4f2-d48f490b0000 pid=2889->11793493-ec19-521c-b424-e4936d1f1fea send: 99B guuid=65e877a5-1a00-0000-c4f2-d48f560b0000 pid=2902->11793493-ec19-521c-b424-e4936d1f1fea send: 99B guuid=05c454ab-1a00-0000-c4f2-d48f670b0000 pid=2919->11793493-ec19-521c-b424-e4936d1f1fea send: 99B guuid=1276cab4-1a00-0000-c4f2-d48f830b0000 pid=2947->11793493-ec19-521c-b424-e4936d1f1fea send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=569c95b8-1a00-0000-c4f2-d48f8d0b0000 pid=2957->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d8e4d7b8-1a00-0000-c4f2-d48f8f0b0000 pid=2959 /home/sandbox/morte.x86 guuid=569c95b8-1a00-0000-c4f2-d48f8d0b0000 pid=2957->guuid=d8e4d7b8-1a00-0000-c4f2-d48f8f0b0000 pid=2959 clone guuid=5aafdcb8-1a00-0000-c4f2-d48f900b0000 pid=2960 /home/sandbox/morte.x86 dns net send-data zombie guuid=569c95b8-1a00-0000-c4f2-d48f8d0b0000 pid=2957->guuid=5aafdcb8-1a00-0000-c4f2-d48f900b0000 pid=2960 clone guuid=5aafdcb8-1a00-0000-c4f2-d48f900b0000 pid=2960->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 78B c704064b-1a2c-51c7-9b3a-3e87e81215f5 bot.nightbotnet.my.id:12121 guuid=5aafdcb8-1a00-0000-c4f2-d48f900b0000 pid=2960->c704064b-1a2c-51c7-9b3a-3e87e81215f5 con ee5cff79-d1e5-59fd-8763-15423efcfc34 bot.nightbotnet.my.id:80 guuid=d9f9e2b8-1a00-0000-c4f2-d48f910b0000 pid=2961->ee5cff79-d1e5-59fd-8763-15423efcfc34 send: 102B guuid=a6d7b3bf-1a00-0000-c4f2-d48fa10b0000 pid=2977->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=a6d7b3bf-1a00-0000-c4f2-d48fa10b0000 pid=2977->f77ebf5e-2af7-5b09-86f4-388588a8b445 con
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-07-10 06:07:19 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2f02636d03d8016446a1df6bf3976255a99740b48ad838eb53eb1cdc083a0d3f

(this sample)

  
Delivery method
Distributed via web download

Comments