MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4e27e0a50c2e828644da7f0478a0c9a6e4a4afafd78905305310d43f25771de0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4e27e0a50c2e828644da7f0478a0c9a6e4a4afafd78905305310d43f25771de0
SHA3-384 hash: 98b800206586bea5576927f03a9ac2bef2f79dd67dd26e6a9cf2765e6fd707d6caa60fdc417dbfefdff00f37279feeaf
SHA1 hash: 1a85176cfdaaba14323ec17d1f5599f1d012ad73
MD5 hash: ce2e29262b8633444f1ba71bfb34ff6e
humanhash: artist-gee-comet-april
File name:bins.sh
Download: download sample
Signature Mirai
File size:911 bytes
First seen:2025-11-05 17:16:32 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:XjI/syYzZ3OhXvuS9dLa+Jdz7+y5yswTm6:XU/J430vu4usdzzoJB
TLSH T1981170505C95158768DBFE1C712A53F231412C74E590123DD2A7EE16C87EE32B50E671
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-05T15:26:00Z UTC
Last seen:
2025-11-05T15:53:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=eba613a5-1800-0000-eeea-3b6d6e0d0000 pid=3438 /usr/bin/sudo guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446 /tmp/sample.bin guuid=eba613a5-1800-0000-eeea-3b6d6e0d0000 pid=3438->guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446 execve guuid=6c1887a7-1800-0000-eeea-3b6d780d0000 pid=3448 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=6c1887a7-1800-0000-eeea-3b6d780d0000 pid=3448 execve guuid=07e1a7b7-1800-0000-eeea-3b6d9d0d0000 pid=3485 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=07e1a7b7-1800-0000-eeea-3b6d9d0d0000 pid=3485 execve guuid=4cf0edb7-1800-0000-eeea-3b6d9e0d0000 pid=3486 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=4cf0edb7-1800-0000-eeea-3b6d9e0d0000 pid=3486 clone guuid=f96771b8-1800-0000-eeea-3b6da30d0000 pid=3491 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=f96771b8-1800-0000-eeea-3b6da30d0000 pid=3491 execve guuid=9d4e4cd1-1800-0000-eeea-3b6dc70d0000 pid=3527 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=9d4e4cd1-1800-0000-eeea-3b6dc70d0000 pid=3527 execve guuid=b53f97d1-1800-0000-eeea-3b6dc80d0000 pid=3528 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=b53f97d1-1800-0000-eeea-3b6dc80d0000 pid=3528 clone guuid=77e61bd2-1800-0000-eeea-3b6dcc0d0000 pid=3532 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=77e61bd2-1800-0000-eeea-3b6dcc0d0000 pid=3532 execve guuid=311708e1-1800-0000-eeea-3b6df50d0000 pid=3573 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=311708e1-1800-0000-eeea-3b6df50d0000 pid=3573 execve guuid=0d574de1-1800-0000-eeea-3b6df70d0000 pid=3575 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=0d574de1-1800-0000-eeea-3b6df70d0000 pid=3575 clone guuid=9802f0e1-1800-0000-eeea-3b6dfb0d0000 pid=3579 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=9802f0e1-1800-0000-eeea-3b6dfb0d0000 pid=3579 execve guuid=3a5a4af1-1800-0000-eeea-3b6d170e0000 pid=3607 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=3a5a4af1-1800-0000-eeea-3b6d170e0000 pid=3607 execve guuid=ec7196f1-1800-0000-eeea-3b6d180e0000 pid=3608 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=ec7196f1-1800-0000-eeea-3b6d180e0000 pid=3608 clone guuid=942548f2-1800-0000-eeea-3b6d1b0e0000 pid=3611 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=942548f2-1800-0000-eeea-3b6d1b0e0000 pid=3611 execve guuid=b807d101-1900-0000-eeea-3b6d440e0000 pid=3652 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=b807d101-1900-0000-eeea-3b6d440e0000 pid=3652 execve guuid=6d810f02-1900-0000-eeea-3b6d460e0000 pid=3654 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=6d810f02-1900-0000-eeea-3b6d460e0000 pid=3654 clone guuid=b93c9c02-1900-0000-eeea-3b6d490e0000 pid=3657 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=b93c9c02-1900-0000-eeea-3b6d490e0000 pid=3657 execve guuid=fe4a7522-1900-0000-eeea-3b6d7a0e0000 pid=3706 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=fe4a7522-1900-0000-eeea-3b6d7a0e0000 pid=3706 execve guuid=1d16aa22-1900-0000-eeea-3b6d7c0e0000 pid=3708 /home/sandbox/dvrHelper delete-file net guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=1d16aa22-1900-0000-eeea-3b6d7c0e0000 pid=3708 execve guuid=168ad722-1900-0000-eeea-3b6d7f0e0000 pid=3711 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=168ad722-1900-0000-eeea-3b6d7f0e0000 pid=3711 execve guuid=c8ae1633-1900-0000-eeea-3b6dc50e0000 pid=3781 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=c8ae1633-1900-0000-eeea-3b6dc50e0000 pid=3781 execve guuid=86546833-1900-0000-eeea-3b6dc60e0000 pid=3782 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=86546833-1900-0000-eeea-3b6dc60e0000 pid=3782 clone guuid=e4041034-1900-0000-eeea-3b6dca0e0000 pid=3786 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=e4041034-1900-0000-eeea-3b6dca0e0000 pid=3786 execve guuid=4737c149-1900-0000-eeea-3b6d160f0000 pid=3862 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=4737c149-1900-0000-eeea-3b6d160f0000 pid=3862 execve guuid=40f8124a-1900-0000-eeea-3b6d170f0000 pid=3863 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=40f8124a-1900-0000-eeea-3b6d170f0000 pid=3863 clone guuid=c9b3aa4a-1900-0000-eeea-3b6d1f0f0000 pid=3871 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=c9b3aa4a-1900-0000-eeea-3b6d1f0f0000 pid=3871 execve guuid=87b20459-1900-0000-eeea-3b6d490f0000 pid=3913 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=87b20459-1900-0000-eeea-3b6d490f0000 pid=3913 execve guuid=e79b7759-1900-0000-eeea-3b6d4b0f0000 pid=3915 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=e79b7759-1900-0000-eeea-3b6d4b0f0000 pid=3915 clone guuid=5ae3595a-1900-0000-eeea-3b6d500f0000 pid=3920 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=5ae3595a-1900-0000-eeea-3b6d500f0000 pid=3920 execve guuid=01342d69-1900-0000-eeea-3b6d7e0f0000 pid=3966 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=01342d69-1900-0000-eeea-3b6d7e0f0000 pid=3966 execve guuid=080f6969-1900-0000-eeea-3b6d800f0000 pid=3968 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=080f6969-1900-0000-eeea-3b6d800f0000 pid=3968 clone guuid=116f376a-1900-0000-eeea-3b6d850f0000 pid=3973 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=116f376a-1900-0000-eeea-3b6d850f0000 pid=3973 execve guuid=2e668c79-1900-0000-eeea-3b6db40f0000 pid=4020 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=2e668c79-1900-0000-eeea-3b6db40f0000 pid=4020 execve guuid=8dc0fb79-1900-0000-eeea-3b6db50f0000 pid=4021 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=8dc0fb79-1900-0000-eeea-3b6db50f0000 pid=4021 clone guuid=4f974c7b-1900-0000-eeea-3b6dbb0f0000 pid=4027 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=4f974c7b-1900-0000-eeea-3b6dbb0f0000 pid=4027 execve guuid=60e00d8d-1900-0000-eeea-3b6df40f0000 pid=4084 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=60e00d8d-1900-0000-eeea-3b6df40f0000 pid=4084 execve guuid=061c748d-1900-0000-eeea-3b6df80f0000 pid=4088 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=061c748d-1900-0000-eeea-3b6df80f0000 pid=4088 clone guuid=2254768e-1900-0000-eeea-3b6dfc0f0000 pid=4092 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=2254768e-1900-0000-eeea-3b6dfc0f0000 pid=4092 execve guuid=15cf829f-1900-0000-eeea-3b6d39100000 pid=4153 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=15cf829f-1900-0000-eeea-3b6d39100000 pid=4153 execve guuid=3b7acc9f-1900-0000-eeea-3b6d3d100000 pid=4157 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=3b7acc9f-1900-0000-eeea-3b6d3d100000 pid=4157 clone guuid=7f0751a2-1900-0000-eeea-3b6d48100000 pid=4168 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=7f0751a2-1900-0000-eeea-3b6d48100000 pid=4168 execve guuid=5830d0ba-1900-0000-eeea-3b6d8b100000 pid=4235 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=5830d0ba-1900-0000-eeea-3b6d8b100000 pid=4235 execve guuid=e1792cbb-1900-0000-eeea-3b6d8d100000 pid=4237 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=e1792cbb-1900-0000-eeea-3b6d8d100000 pid=4237 clone guuid=cfc7eabb-1900-0000-eeea-3b6d91100000 pid=4241 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=cfc7eabb-1900-0000-eeea-3b6d91100000 pid=4241 execve guuid=ab9ee6ca-1900-0000-eeea-3b6dbd100000 pid=4285 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=ab9ee6ca-1900-0000-eeea-3b6dbd100000 pid=4285 execve guuid=645932cb-1900-0000-eeea-3b6dc1100000 pid=4289 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=645932cb-1900-0000-eeea-3b6dc1100000 pid=4289 clone guuid=03f5ddcc-1900-0000-eeea-3b6dc7100000 pid=4295 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=03f5ddcc-1900-0000-eeea-3b6dc7100000 pid=4295 execve guuid=b555d1db-1900-0000-eeea-3b6df5100000 pid=4341 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=b555d1db-1900-0000-eeea-3b6df5100000 pid=4341 execve guuid=4f8532dc-1900-0000-eeea-3b6df7100000 pid=4343 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=4f8532dc-1900-0000-eeea-3b6df7100000 pid=4343 clone guuid=7d5f62de-1900-0000-eeea-3b6d01110000 pid=4353 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=7d5f62de-1900-0000-eeea-3b6d01110000 pid=4353 execve guuid=536327ef-1900-0000-eeea-3b6d32110000 pid=4402 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=536327ef-1900-0000-eeea-3b6d32110000 pid=4402 execve guuid=527c81ef-1900-0000-eeea-3b6d33110000 pid=4403 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=527c81ef-1900-0000-eeea-3b6d33110000 pid=4403 clone guuid=c0683bf0-1900-0000-eeea-3b6d39110000 pid=4409 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=c0683bf0-1900-0000-eeea-3b6d39110000 pid=4409 execve guuid=a74955ff-1900-0000-eeea-3b6d63110000 pid=4451 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=a74955ff-1900-0000-eeea-3b6d63110000 pid=4451 execve guuid=3919a6ff-1900-0000-eeea-3b6d65110000 pid=4453 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=3919a6ff-1900-0000-eeea-3b6d65110000 pid=4453 clone guuid=e27e4b00-1a00-0000-eeea-3b6d68110000 pid=4456 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=e27e4b00-1a00-0000-eeea-3b6d68110000 pid=4456 execve guuid=42b69b10-1a00-0000-eeea-3b6d8e110000 pid=4494 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=42b69b10-1a00-0000-eeea-3b6d8e110000 pid=4494 execve guuid=06a7fb10-1a00-0000-eeea-3b6d91110000 pid=4497 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=06a7fb10-1a00-0000-eeea-3b6d91110000 pid=4497 clone guuid=3358d611-1a00-0000-eeea-3b6d94110000 pid=4500 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=3358d611-1a00-0000-eeea-3b6d94110000 pid=4500 execve guuid=2e018e20-1a00-0000-eeea-3b6dbf110000 pid=4543 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=2e018e20-1a00-0000-eeea-3b6dbf110000 pid=4543 execve guuid=c706e720-1a00-0000-eeea-3b6dc1110000 pid=4545 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=c706e720-1a00-0000-eeea-3b6dc1110000 pid=4545 clone guuid=b4c2e822-1a00-0000-eeea-3b6dc6110000 pid=4550 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=b4c2e822-1a00-0000-eeea-3b6dc6110000 pid=4550 execve guuid=adfdd852-1a00-0000-eeea-3b6d0a120000 pid=4618 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=adfdd852-1a00-0000-eeea-3b6d0a120000 pid=4618 execve guuid=71ce6b53-1a00-0000-eeea-3b6d0d120000 pid=4621 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=71ce6b53-1a00-0000-eeea-3b6d0d120000 pid=4621 clone guuid=9dd21754-1a00-0000-eeea-3b6d10120000 pid=4624 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=9dd21754-1a00-0000-eeea-3b6d10120000 pid=4624 execve guuid=2cfd6980-1a00-0000-eeea-3b6d75120000 pid=4725 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=2cfd6980-1a00-0000-eeea-3b6d75120000 pid=4725 execve guuid=4676b880-1a00-0000-eeea-3b6d77120000 pid=4727 /usr/bin/dash guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=4676b880-1a00-0000-eeea-3b6d77120000 pid=4727 clone guuid=d2f1a682-1a00-0000-eeea-3b6d80120000 pid=4736 /usr/bin/wget net send-data write-file guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=d2f1a682-1a00-0000-eeea-3b6d80120000 pid=4736 execve guuid=f21a3991-1a00-0000-eeea-3b6dab120000 pid=4779 /usr/bin/chmod guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=f21a3991-1a00-0000-eeea-3b6dab120000 pid=4779 execve guuid=83179891-1a00-0000-eeea-3b6dad120000 pid=4781 /home/sandbox/dvrHelper delete-file net guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=83179891-1a00-0000-eeea-3b6dad120000 pid=4781 execve guuid=eeec25cc-1b00-0000-eeea-3b6dc5140000 pid=5317 /usr/bin/rm guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=eeec25cc-1b00-0000-eeea-3b6dc5140000 pid=5317 execve guuid=9a4a98cc-1b00-0000-eeea-3b6dc7140000 pid=5319 /usr/bin/rm guuid=717137a7-1800-0000-eeea-3b6d760d0000 pid=3446->guuid=9a4a98cc-1b00-0000-eeea-3b6dc7140000 pid=5319 execve 5cb08fbf-0445-5f0e-a6c3-0615adeee424 194.156.102.210:80 guuid=6c1887a7-1800-0000-eeea-3b6d780d0000 pid=3448->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 146B guuid=f96771b8-1800-0000-eeea-3b6da30d0000 pid=3491->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 147B guuid=77e61bd2-1800-0000-eeea-3b6dcc0d0000 pid=3532->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 145B guuid=9802f0e1-1800-0000-eeea-3b6dfb0d0000 pid=3579->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 145B guuid=942548f2-1800-0000-eeea-3b6d1b0e0000 pid=3611->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 144B guuid=b93c9c02-1900-0000-eeea-3b6d490e0000 pid=3657->5cb08fbf-0445-5f0e-a6c3-0615adeee424 send: 144B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1d16aa22-1900-0000-eeea-3b6d7c0e0000 pid=3708->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710 /home/sandbox/dvrHelper dns net send-data zombie guuid=1d16aa22-1900-0000-eeea-3b6d7c0e0000 pid=3708->guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710 clone guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 hxipzknrsojnitzv.zip:23 guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 send: 5B guuid=244add22-1900-0000-eeea-3b6d800e0000 pid=3712 /home/sandbox/dvrHelper guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710->guuid=244add22-1900-0000-eeea-3b6d800e0000 pid=3712 clone guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713 /home/sandbox/dvrHelper net net-scan send-data guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710->guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713 clone guuid=2f360a92-1a00-0000-eeea-3b6daf120000 pid=4783 /home/sandbox/dvrHelper net guuid=40f1d122-1900-0000-eeea-3b6d7e0e0000 pid=3710->guuid=2f360a92-1a00-0000-eeea-3b6daf120000 pid=4783 clone 91ace30b-3d9f-522c-9672-99f62740d927 hxipzknrsojnitzv.zip:80 guuid=168ad722-1900-0000-eeea-3b6d7f0e0000 pid=3711->91ace30b-3d9f-522c-9672-99f62740d927 send: 148B guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713|send-data send-data to 960 IP addresses review logs to see them all guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713->guuid=d1f4e022-1900-0000-eeea-3b6d810e0000 pid=3713|send-data send guuid=e4041034-1900-0000-eeea-3b6dca0e0000 pid=3786->91ace30b-3d9f-522c-9672-99f62740d927 send: 149B guuid=c9b3aa4a-1900-0000-eeea-3b6d1f0f0000 pid=3871->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=5ae3595a-1900-0000-eeea-3b6d500f0000 pid=3920->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=116f376a-1900-0000-eeea-3b6d850f0000 pid=3973->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=4f974c7b-1900-0000-eeea-3b6dbb0f0000 pid=4027->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=2254768e-1900-0000-eeea-3b6dfc0f0000 pid=4092->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=7f0751a2-1900-0000-eeea-3b6d48100000 pid=4168->91ace30b-3d9f-522c-9672-99f62740d927 send: 150B guuid=cfc7eabb-1900-0000-eeea-3b6d91100000 pid=4241->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=03f5ddcc-1900-0000-eeea-3b6dc7100000 pid=4295->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=7d5f62de-1900-0000-eeea-3b6d01110000 pid=4353->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=c0683bf0-1900-0000-eeea-3b6d39110000 pid=4409->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=e27e4b00-1a00-0000-eeea-3b6d68110000 pid=4456->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=3358d611-1a00-0000-eeea-3b6d94110000 pid=4500->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=b4c2e822-1a00-0000-eeea-3b6dc6110000 pid=4550->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=9dd21754-1a00-0000-eeea-3b6d10120000 pid=4624->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=d2f1a682-1a00-0000-eeea-3b6d80120000 pid=4736->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=83179891-1a00-0000-eeea-3b6dad120000 pid=4781->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ff25191-b423-5251-a735-2378c22ab12a 0.0.0.0:48101 guuid=83179891-1a00-0000-eeea-3b6dad120000 pid=4781->8ff25191-b423-5251-a735-2378c22ab12a con guuid=9e1f17cc-1b00-0000-eeea-3b6dc4140000 pid=5316 /home/sandbox/dvrHelper dns net send-data zombie guuid=83179891-1a00-0000-eeea-3b6dad120000 pid=4781->guuid=9e1f17cc-1b00-0000-eeea-3b6dc4140000 pid=5316 clone guuid=2f360a92-1a00-0000-eeea-3b6daf120000 pid=4783->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9e1f17cc-1b00-0000-eeea-3b6dc4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=9e1f17cc-1b00-0000-eeea-3b6dc4140000 pid=5316->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 send: 7B guuid=276e37cc-1b00-0000-eeea-3b6dc6140000 pid=5318 /home/sandbox/dvrHelper guuid=9e1f17cc-1b00-0000-eeea-3b6dc4140000 pid=5316->guuid=276e37cc-1b00-0000-eeea-3b6dc6140000 pid=5318 clone
Threat name:
Linux.Browser.Downlaoder
Status:
Malicious
First seen:
2025-11-05 17:17:14 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (1130) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4e27e0a50c2e828644da7f0478a0c9a6e4a4afafd78905305310d43f25771de0

(this sample)

  
Delivery method
Distributed via web download

Comments