MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 351ba524ddb47bfe00a8801d7b8f866967ee5756f5dfccf8c3dfee8c3f05b7a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 351ba524ddb47bfe00a8801d7b8f866967ee5756f5dfccf8c3dfee8c3f05b7a9
SHA3-384 hash: 7585b8281d4428929859238e8a00a19a3db615b7df31bcaa9fac02f83ab2f0fb560da7c173f1df0fc6cf8658103c6812
SHA1 hash: 91dcf2b021ad6aa28f379b75fdc51f3621de3578
MD5 hash: 4269ea8b1787afb0c8dc4ada78a452ba
humanhash: fifteen-cup-music-harry
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'866 bytes
First seen:2026-04-05 07:08:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vPmD0PPW9bPfAfFahPgAgFLhPdUfPlsHPZep4PiXsP90/PO7WPjy9PPWPPkR+PIu:vPmD0PPW9bP4NGPXu9PdUfPlsHPMp4Pe
TLSH T1A4517786003157781CF7AB2FF6F56198B0D1506634E56F48C6D839B54F8ED54BC40767
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://162.215.170.152/hiddenbin/main_x864711da2fc9115e785a39c018b44de80e32822045724c48c6be6d6e52211aa1b7 Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_mipsa2e39a970e40ea24d2516d09447a186147c4b123b38707406f0e7daa2e664692 Miraimirai
http://162.215.170.152/hiddenbin/main_arcn/an/acensys elf ua-wget
http://162.215.170.152/hiddenbin/main_i468n/an/acensys elf ua-wget
http://162.215.170.152/hiddenbin/main_i686n/an/acensys elf ua-wget
http://162.215.170.152/hiddenbin/main_x86_6440c529d64204c7c638484669b041c290a966b093effbcef4074f6035ef68322c Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_mpslfb9d7e25e0a20a3d6031f5574763b5998687797df354f79dbd1838a7e7057930 Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_arm8399ce18d178b03fbbfdaf775e576255732064b492680fca51ae1b8f3efda5d2 Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_arm57575765147a3af17e5e83196091ea140c1e1aaf1bc179a516972e9fafff8b74e Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_arm62fb1251286098d07723b3d9c94db25b72ab25ae837575c1d7bb2ecd1d2bcb54f Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_arm7d05fce1f1f8766e748257480a472d1cdabc039b578e86d1a381b590b82c6c01b Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_ppc0d6de37790878c4eb5eef3191215e6d5258136db59240b699dd131a481e01236 Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_spcn/an/acensys elf ua-wget
http://162.215.170.152/hiddenbin/main_m68k0b21d3e3198185fdc466db84c25a778ce20ee14f0a3218f102a68632cb276597 Miraicensys elf mirai ua-wget
http://162.215.170.152/hiddenbin/main_sh4fbf6c5ee6886c58db833a2801eac9f6fe2ba8b299c3af140aa1026e8360cbc5c Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Gathering data
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-05T04:07:00Z UTC
Last seen:
2026-04-05T04:08:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=263b4d26-2100-0000-ed9a-005a850a0000 pid=2693 /usr/bin/sudo guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701 /tmp/sample.bin guuid=263b4d26-2100-0000-ed9a-005a850a0000 pid=2693->guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701 execve guuid=90da5829-2100-0000-ed9a-005a8f0a0000 pid=2703 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=90da5829-2100-0000-ed9a-005a8f0a0000 pid=2703 execve guuid=743af04e-2100-0000-ed9a-005ad70a0000 pid=2775 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=743af04e-2100-0000-ed9a-005ad70a0000 pid=2775 execve guuid=28a44975-2100-0000-ed9a-005a130b0000 pid=2835 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=28a44975-2100-0000-ed9a-005a130b0000 pid=2835 execve guuid=6581bf75-2100-0000-ed9a-005a140b0000 pid=2836 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=6581bf75-2100-0000-ed9a-005a140b0000 pid=2836 execve guuid=b66f3976-2100-0000-ed9a-005a160b0000 pid=2838 /tmp/WTF delete-file net guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=b66f3976-2100-0000-ed9a-005a160b0000 pid=2838 execve guuid=53d87376-2100-0000-ed9a-005a180b0000 pid=2840 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=53d87376-2100-0000-ed9a-005a180b0000 pid=2840 execve guuid=5c159fa1-2100-0000-ed9a-005a720b0000 pid=2930 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=5c159fa1-2100-0000-ed9a-005a720b0000 pid=2930 execve guuid=9d6deae0-2100-0000-ed9a-005aa00b0000 pid=2976 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=9d6deae0-2100-0000-ed9a-005aa00b0000 pid=2976 execve guuid=61fd88e1-2100-0000-ed9a-005aa30b0000 pid=2979 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=61fd88e1-2100-0000-ed9a-005aa30b0000 pid=2979 execve guuid=254d04e2-2100-0000-ed9a-005aa60b0000 pid=2982 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=254d04e2-2100-0000-ed9a-005aa60b0000 pid=2982 clone guuid=d8882be3-2100-0000-ed9a-005aab0b0000 pid=2987 /usr/bin/wget net send-data guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d8882be3-2100-0000-ed9a-005aab0b0000 pid=2987 execve guuid=cd2c2cf5-2100-0000-ed9a-005acf0b0000 pid=3023 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=cd2c2cf5-2100-0000-ed9a-005acf0b0000 pid=3023 execve guuid=dd7eda0b-2200-0000-ed9a-005a090c0000 pid=3081 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=dd7eda0b-2200-0000-ed9a-005a090c0000 pid=3081 execve guuid=ee97480c-2200-0000-ed9a-005a0c0c0000 pid=3084 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=ee97480c-2200-0000-ed9a-005a0c0c0000 pid=3084 execve guuid=e5b2b20c-2200-0000-ed9a-005a0d0c0000 pid=3085 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=e5b2b20c-2200-0000-ed9a-005a0d0c0000 pid=3085 clone guuid=99c2e50c-2200-0000-ed9a-005a0f0c0000 pid=3087 /usr/bin/wget net send-data guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=99c2e50c-2200-0000-ed9a-005a0f0c0000 pid=3087 execve guuid=f7e3621f-2200-0000-ed9a-005a3b0c0000 pid=3131 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=f7e3621f-2200-0000-ed9a-005a3b0c0000 pid=3131 execve guuid=bff19d33-2200-0000-ed9a-005a660c0000 pid=3174 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=bff19d33-2200-0000-ed9a-005a660c0000 pid=3174 execve guuid=5e2e0434-2200-0000-ed9a-005a690c0000 pid=3177 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=5e2e0434-2200-0000-ed9a-005a690c0000 pid=3177 execve guuid=a4265c34-2200-0000-ed9a-005a6b0c0000 pid=3179 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=a4265c34-2200-0000-ed9a-005a6b0c0000 pid=3179 clone guuid=855d8534-2200-0000-ed9a-005a6c0c0000 pid=3180 /usr/bin/wget net send-data guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=855d8534-2200-0000-ed9a-005a6c0c0000 pid=3180 execve guuid=171c7146-2200-0000-ed9a-005a7d0c0000 pid=3197 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=171c7146-2200-0000-ed9a-005a7d0c0000 pid=3197 execve guuid=177cd35f-2200-0000-ed9a-005aa20c0000 pid=3234 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=177cd35f-2200-0000-ed9a-005aa20c0000 pid=3234 execve guuid=a9d32160-2200-0000-ed9a-005aa30c0000 pid=3235 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=a9d32160-2200-0000-ed9a-005aa30c0000 pid=3235 execve guuid=540c9560-2200-0000-ed9a-005aa40c0000 pid=3236 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=540c9560-2200-0000-ed9a-005aa40c0000 pid=3236 clone guuid=0606c660-2200-0000-ed9a-005aa50c0000 pid=3237 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=0606c660-2200-0000-ed9a-005aa50c0000 pid=3237 execve guuid=e6450c8b-2200-0000-ed9a-005abd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=e6450c8b-2200-0000-ed9a-005abd0c0000 pid=3261 execve guuid=623fd1ba-2200-0000-ed9a-005afe0c0000 pid=3326 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=623fd1ba-2200-0000-ed9a-005afe0c0000 pid=3326 execve guuid=86fe9dbb-2200-0000-ed9a-005a000d0000 pid=3328 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=86fe9dbb-2200-0000-ed9a-005a000d0000 pid=3328 execve guuid=037ff1bb-2200-0000-ed9a-005a020d0000 pid=3330 /tmp/WTF delete-file net guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=037ff1bb-2200-0000-ed9a-005a020d0000 pid=3330 execve guuid=2f302cbc-2200-0000-ed9a-005a040d0000 pid=3332 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=2f302cbc-2200-0000-ed9a-005a040d0000 pid=3332 execve guuid=4b2d40e8-2200-0000-ed9a-005a490d0000 pid=3401 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=4b2d40e8-2200-0000-ed9a-005a490d0000 pid=3401 execve guuid=41975017-2300-0000-ed9a-005aa60d0000 pid=3494 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=41975017-2300-0000-ed9a-005aa60d0000 pid=3494 execve guuid=a8dec817-2300-0000-ed9a-005aa80d0000 pid=3496 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=a8dec817-2300-0000-ed9a-005aa80d0000 pid=3496 execve guuid=02753218-2300-0000-ed9a-005aaa0d0000 pid=3498 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=02753218-2300-0000-ed9a-005aaa0d0000 pid=3498 clone guuid=d03c3219-2300-0000-ed9a-005aae0d0000 pid=3502 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d03c3219-2300-0000-ed9a-005aae0d0000 pid=3502 execve guuid=0fe13d44-2300-0000-ed9a-005a040e0000 pid=3588 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=0fe13d44-2300-0000-ed9a-005a040e0000 pid=3588 execve guuid=fba62e71-2300-0000-ed9a-005a750e0000 pid=3701 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=fba62e71-2300-0000-ed9a-005a750e0000 pid=3701 execve guuid=ee8f9071-2300-0000-ed9a-005a760e0000 pid=3702 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=ee8f9071-2300-0000-ed9a-005a760e0000 pid=3702 execve guuid=4b83ec71-2300-0000-ed9a-005a770e0000 pid=3703 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=4b83ec71-2300-0000-ed9a-005a770e0000 pid=3703 clone guuid=d62fd972-2300-0000-ed9a-005a7d0e0000 pid=3709 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d62fd972-2300-0000-ed9a-005a7d0e0000 pid=3709 execve guuid=b1b8879d-2300-0000-ed9a-005af00e0000 pid=3824 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=b1b8879d-2300-0000-ed9a-005af00e0000 pid=3824 execve guuid=c76cf7ca-2300-0000-ed9a-005a720f0000 pid=3954 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=c76cf7ca-2300-0000-ed9a-005a720f0000 pid=3954 execve guuid=605773cb-2300-0000-ed9a-005a760f0000 pid=3958 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=605773cb-2300-0000-ed9a-005a760f0000 pid=3958 execve guuid=e81ae8cb-2300-0000-ed9a-005a770f0000 pid=3959 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=e81ae8cb-2300-0000-ed9a-005a770f0000 pid=3959 clone guuid=1aa4b3cd-2300-0000-ed9a-005a820f0000 pid=3970 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=1aa4b3cd-2300-0000-ed9a-005a820f0000 pid=3970 execve guuid=009fa8f8-2300-0000-ed9a-005a0b100000 pid=4107 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=009fa8f8-2300-0000-ed9a-005a0b100000 pid=4107 execve guuid=de22d933-2400-0000-ed9a-005a6c100000 pid=4204 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=de22d933-2400-0000-ed9a-005a6c100000 pid=4204 execve guuid=a4504134-2400-0000-ed9a-005a6d100000 pid=4205 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=a4504134-2400-0000-ed9a-005a6d100000 pid=4205 execve guuid=f39acf34-2400-0000-ed9a-005a6e100000 pid=4206 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=f39acf34-2400-0000-ed9a-005a6e100000 pid=4206 clone guuid=7b558836-2400-0000-ed9a-005a70100000 pid=4208 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=7b558836-2400-0000-ed9a-005a70100000 pid=4208 execve guuid=6710d161-2400-0000-ed9a-005ae5100000 pid=4325 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=6710d161-2400-0000-ed9a-005ae5100000 pid=4325 execve guuid=f9bb768f-2400-0000-ed9a-005a78110000 pid=4472 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=f9bb768f-2400-0000-ed9a-005a78110000 pid=4472 execve guuid=9717ff8f-2400-0000-ed9a-005a79110000 pid=4473 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=9717ff8f-2400-0000-ed9a-005a79110000 pid=4473 execve guuid=34346b90-2400-0000-ed9a-005a7d110000 pid=4477 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=34346b90-2400-0000-ed9a-005a7d110000 pid=4477 clone guuid=86b29891-2400-0000-ed9a-005a82110000 pid=4482 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=86b29891-2400-0000-ed9a-005a82110000 pid=4482 execve guuid=ad4d5dbd-2400-0000-ed9a-005a07120000 pid=4615 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=ad4d5dbd-2400-0000-ed9a-005a07120000 pid=4615 execve guuid=410844ea-2400-0000-ed9a-005a91120000 pid=4753 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=410844ea-2400-0000-ed9a-005a91120000 pid=4753 execve guuid=80d4b1ea-2400-0000-ed9a-005a92120000 pid=4754 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=80d4b1ea-2400-0000-ed9a-005a92120000 pid=4754 execve guuid=d9b01aeb-2400-0000-ed9a-005a96120000 pid=4758 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d9b01aeb-2400-0000-ed9a-005a96120000 pid=4758 clone guuid=a77c02ed-2400-0000-ed9a-005a9e120000 pid=4766 /usr/bin/wget net send-data guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=a77c02ed-2400-0000-ed9a-005a9e120000 pid=4766 execve guuid=110352ff-2400-0000-ed9a-005ad2120000 pid=4818 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=110352ff-2400-0000-ed9a-005ad2120000 pid=4818 execve guuid=2e617216-2500-0000-ed9a-005a13130000 pid=4883 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=2e617216-2500-0000-ed9a-005a13130000 pid=4883 execve guuid=c650c516-2500-0000-ed9a-005a15130000 pid=4885 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=c650c516-2500-0000-ed9a-005a15130000 pid=4885 execve guuid=baf37817-2500-0000-ed9a-005a18130000 pid=4888 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=baf37817-2500-0000-ed9a-005a18130000 pid=4888 clone guuid=3649e917-2500-0000-ed9a-005a1a130000 pid=4890 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=3649e917-2500-0000-ed9a-005a1a130000 pid=4890 execve guuid=d757414e-2500-0000-ed9a-005a96130000 pid=5014 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d757414e-2500-0000-ed9a-005a96130000 pid=5014 execve guuid=9de9a9a1-2500-0000-ed9a-005aef130000 pid=5103 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=9de9a9a1-2500-0000-ed9a-005aef130000 pid=5103 execve guuid=985a8ba6-2500-0000-ed9a-005a06140000 pid=5126 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=985a8ba6-2500-0000-ed9a-005a06140000 pid=5126 execve guuid=3effd2a6-2500-0000-ed9a-005a07140000 pid=5127 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=3effd2a6-2500-0000-ed9a-005a07140000 pid=5127 clone guuid=65d7afa7-2500-0000-ed9a-005a0c140000 pid=5132 /usr/bin/wget net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=65d7afa7-2500-0000-ed9a-005a0c140000 pid=5132 execve guuid=fd57e2d2-2500-0000-ed9a-005a90140000 pid=5264 /usr/bin/curl net send-data write-file guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=fd57e2d2-2500-0000-ed9a-005a90140000 pid=5264 execve guuid=f2bf51ff-2500-0000-ed9a-005ab8140000 pid=5304 /usr/bin/cat guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=f2bf51ff-2500-0000-ed9a-005ab8140000 pid=5304 execve guuid=7328e1ff-2500-0000-ed9a-005ab9140000 pid=5305 /usr/bin/chmod guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=7328e1ff-2500-0000-ed9a-005ab9140000 pid=5305 execve guuid=d8485a00-2600-0000-ed9a-005aba140000 pid=5306 /usr/bin/bash guuid=41e2f728-2100-0000-ed9a-005a8d0a0000 pid=2701->guuid=d8485a00-2600-0000-ed9a-005aba140000 pid=5306 clone 36436154-f549-505e-b6db-e05b56f8817f 162.215.170.152:80 guuid=90da5829-2100-0000-ed9a-005a8f0a0000 pid=2703->36436154-f549-505e-b6db-e05b56f8817f send: 148B guuid=743af04e-2100-0000-ed9a-005ad70a0000 pid=2775->36436154-f549-505e-b6db-e05b56f8817f send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b66f3976-2100-0000-ed9a-005a160b0000 pid=2838->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=34c36576-2100-0000-ed9a-005a170b0000 pid=2839 /tmp/WTF dns net send-data zombie guuid=b66f3976-2100-0000-ed9a-005a160b0000 pid=2838->guuid=34c36576-2100-0000-ed9a-005a170b0000 pid=2839 clone guuid=34c36576-2100-0000-ed9a-005a170b0000 pid=2839->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B 261970ca-c3f5-5b2b-ba30-1844d212e888 cnc.xenema.vip:1995 guuid=34c36576-2100-0000-ed9a-005a170b0000 pid=2839->261970ca-c3f5-5b2b-ba30-1844d212e888 send: 7B 7829d215-981a-5771-b1e8-88d6ec8b38bf cnc.xenema.vip:80 guuid=53d87376-2100-0000-ed9a-005a180b0000 pid=2840->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=5c159fa1-2100-0000-ed9a-005a720b0000 pid=2930->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=d8882be3-2100-0000-ed9a-005aab0b0000 pid=2987->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 148B guuid=cd2c2cf5-2100-0000-ed9a-005acf0b0000 pid=3023->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 97B guuid=99c2e50c-2200-0000-ed9a-005a0f0c0000 pid=3087->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=f7e3621f-2200-0000-ed9a-005a3b0c0000 pid=3131->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=855d8534-2200-0000-ed9a-005a6c0c0000 pid=3180->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=171c7146-2200-0000-ed9a-005a7d0c0000 pid=3197->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=0606c660-2200-0000-ed9a-005aa50c0000 pid=3237->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 151B guuid=e6450c8b-2200-0000-ed9a-005abd0c0000 pid=3261->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 100B guuid=037ff1bb-2200-0000-ed9a-005a020d0000 pid=3330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f931abc-2200-0000-ed9a-005a030d0000 pid=3331 /tmp/WTF delete-file dns net send-data zombie guuid=037ff1bb-2200-0000-ed9a-005a020d0000 pid=3330->guuid=2f931abc-2200-0000-ed9a-005a030d0000 pid=3331 clone guuid=2f931abc-2200-0000-ed9a-005a030d0000 pid=3331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B guuid=2f931abc-2200-0000-ed9a-005a030d0000 pid=3331->261970ca-c3f5-5b2b-ba30-1844d212e888 send: 7B guuid=2f302cbc-2200-0000-ed9a-005a040d0000 pid=3332->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=4b2d40e8-2200-0000-ed9a-005a490d0000 pid=3401->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=d03c3219-2300-0000-ed9a-005aae0d0000 pid=3502->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 148B guuid=0fe13d44-2300-0000-ed9a-005a040e0000 pid=3588->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 97B guuid=d62fd972-2300-0000-ed9a-005a7d0e0000 pid=3709->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=b1b8879d-2300-0000-ed9a-005af00e0000 pid=3824->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=1aa4b3cd-2300-0000-ed9a-005a820f0000 pid=3970->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=009fa8f8-2300-0000-ed9a-005a0b100000 pid=4107->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=7b558836-2400-0000-ed9a-005a70100000 pid=4208->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=6710d161-2400-0000-ed9a-005ae5100000 pid=4325->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=86b29891-2400-0000-ed9a-005a82110000 pid=4482->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 148B guuid=ad4d5dbd-2400-0000-ed9a-005a07120000 pid=4615->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 97B guuid=a77c02ed-2400-0000-ed9a-005a9e120000 pid=4766->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 148B guuid=110352ff-2400-0000-ed9a-005ad2120000 pid=4818->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 97B guuid=3649e917-2500-0000-ed9a-005a1a130000 pid=4890->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 149B guuid=d757414e-2500-0000-ed9a-005a96130000 pid=5014->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 98B guuid=65d7afa7-2500-0000-ed9a-005a0c140000 pid=5132->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 148B guuid=fd57e2d2-2500-0000-ed9a-005a90140000 pid=5264->7829d215-981a-5771-b1e8-88d6ec8b38bf send: 97B
Gathering data
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
cnc.xenema.vip
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 351ba524ddb47bfe00a8801d7b8f866967ee5756f5dfccf8c3dfee8c3f05b7a9

(this sample)

  
Delivery method
Distributed via web download

Comments