MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 52f43bc81b293b009c9c6d57faa58960ae5b95662ac2ab9844f4009dbbf2ea1f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 52f43bc81b293b009c9c6d57faa58960ae5b95662ac2ab9844f4009dbbf2ea1f
SHA3-384 hash: 540fc5095231932bfd6a1b458c6a4ef5f4916a84e7c632d39696a44be2c8d07ef08b12a6e4ffdf9fc9e4c6552b013493
SHA1 hash: e3b6ce97bd24dd2eccf3e3d94fa1f4ef0b0e38ea
MD5 hash: 626b9b1f88f888a21d5dbaf66af97bb6
humanhash: helium-mirror-texas-monkey
File name:jack5tr.sh
Download: download sample
Signature Mirai
File size:2'002 bytes
First seen:2026-01-20 21:00:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vcsRssyd/scBQ/scY2L/scsysRld/scu1hM/scqBG/scf8/scY1wHZ/scQoQN/s2:vN+nGKFNrrGP/tRUwHKtB2ydt6gR
TLSH T17D4129DF23810435ECAA9AF3F3B9062436C4D8E994D86EC459EC7CF4568ED24718AA43
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.124.93.149/x8610a06336fbd2fb352d25b78d3d91c1fb5686801ac5a433a1cd06f8deceb79ce0 Miraicensys elf mirai ua-wget
http://103.124.93.149/mips2f3cfe5b368c6f39b329d6b72be6dfdf90458f42f21bc30ca32c811b8b74ffc3 Miraicensys elf mirai ua-wget
http://103.124.93.149/arcn/an/aelf ua-wget
http://103.124.93.149/x86_64a13cac5be7cec9f671cea5f395d04a327f032fe1ccb0d1edbecf1082f217cbff Miraicensys elf mirai ua-wget
http://103.124.93.149/mpslb704fd1611df32c2c2268493314eef146d109f0031fddf40d9a340149c87ab3f Miraicensys elf mirai ua-wget
http://103.124.93.149/arm4deaf19c7c5a846b1a19cbff89b37db8bf6b412af536959ccd493aac328cbe07 Miraicensys elf mirai ua-wget
http://103.124.93.149/arm5adcd5e80c9dcedbfb122821ca7c4cd11e9598f43107d698c159c935c224988da Miraicensys elf mirai ua-wget
http://103.124.93.149/arm6625fd5598d8d85faf92a0fba142f6691f181f76812132acb0c2126296a1590a2 Miraicensys elf mirai ua-wget
http://103.124.93.149/arm7155a361e94b6bb078a0032b2bf24f0e862390fe0f23202f9c15407a875b56a73 Miraicensys elf mirai ua-wget
http://103.124.93.149/ppc92c26520a7c037036c0ef2c8e09618a905b41ee64da4391b3e07535888e20e40 Miraicensys elf mirai ua-wget
http://103.124.93.149/spc6f82cb7a593b1919f1f07f9777c6d6ff49ef1ac5a24115277eaf81f68d198df6 Miraicensys elf mirai ua-wget
http://103.124.93.149/m68k60c79549a63ed8d2dd76a5b21ad62c1126bcaaf72336ea36a777d9cd653b2d8f Miraicensys elf mirai ua-wget
http://103.124.93.149/sh4d39793f13da943383a698b5339acc0a8cb22a39630272a2554f657803794acf7 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-20T18:13:00Z UTC
Last seen:
2026-01-21T12:58:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=607becc2-1900-0000-f772-d17e8f0a0000 pid=2703 /usr/bin/sudo guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710 /tmp/sample.bin guuid=607becc2-1900-0000-f772-d17e8f0a0000 pid=2703->guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710 execve guuid=cbee38c6-1900-0000-f772-d17e990a0000 pid=2713 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=cbee38c6-1900-0000-f772-d17e990a0000 pid=2713 execve guuid=3ee7c402-1a00-0000-f772-d17ed00a0000 pid=2768 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=3ee7c402-1a00-0000-f772-d17ed00a0000 pid=2768 execve guuid=652d3939-1a00-0000-f772-d17e2a0b0000 pid=2858 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=652d3939-1a00-0000-f772-d17e2a0b0000 pid=2858 execve guuid=99cab539-1a00-0000-f772-d17e2c0b0000 pid=2860 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=99cab539-1a00-0000-f772-d17e2c0b0000 pid=2860 execve guuid=d6542a3a-1a00-0000-f772-d17e2e0b0000 pid=2862 /tmp/RUN net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=d6542a3a-1a00-0000-f772-d17e2e0b0000 pid=2862 execve guuid=0b2e8b3c-1a00-0000-f772-d17e3b0b0000 pid=2875 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=0b2e8b3c-1a00-0000-f772-d17e3b0b0000 pid=2875 execve guuid=17347671-1a00-0000-f772-d17e9b0b0000 pid=2971 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=17347671-1a00-0000-f772-d17e9b0b0000 pid=2971 execve guuid=71f924a9-1a00-0000-f772-d17e250c0000 pid=3109 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=71f924a9-1a00-0000-f772-d17e250c0000 pid=3109 execve guuid=a57983a9-1a00-0000-f772-d17e270c0000 pid=3111 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=a57983a9-1a00-0000-f772-d17e270c0000 pid=3111 execve guuid=1136cfa9-1a00-0000-f772-d17e290c0000 pid=3113 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=1136cfa9-1a00-0000-f772-d17e290c0000 pid=3113 clone guuid=024284aa-1a00-0000-f772-d17e2d0c0000 pid=3117 /usr/bin/wget net send-data guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=024284aa-1a00-0000-f772-d17e2d0c0000 pid=3117 execve guuid=8a022ec7-1a00-0000-f772-d17e6f0c0000 pid=3183 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=8a022ec7-1a00-0000-f772-d17e6f0c0000 pid=3183 execve guuid=a40397e6-1a00-0000-f772-d17e930c0000 pid=3219 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=a40397e6-1a00-0000-f772-d17e930c0000 pid=3219 execve guuid=2aa0e9e6-1a00-0000-f772-d17e950c0000 pid=3221 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=2aa0e9e6-1a00-0000-f772-d17e950c0000 pid=3221 execve guuid=15db4de7-1a00-0000-f772-d17e970c0000 pid=3223 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=15db4de7-1a00-0000-f772-d17e970c0000 pid=3223 clone guuid=990a82e7-1a00-0000-f772-d17e990c0000 pid=3225 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=990a82e7-1a00-0000-f772-d17e990c0000 pid=3225 execve guuid=52745a23-1b00-0000-f772-d17ed70c0000 pid=3287 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=52745a23-1b00-0000-f772-d17ed70c0000 pid=3287 execve guuid=2227c564-1b00-0000-f772-d17e420d0000 pid=3394 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=2227c564-1b00-0000-f772-d17e420d0000 pid=3394 execve guuid=e4181465-1b00-0000-f772-d17e430d0000 pid=3395 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=e4181465-1b00-0000-f772-d17e430d0000 pid=3395 execve guuid=65f45c65-1b00-0000-f772-d17e440d0000 pid=3396 /tmp/RUN net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=65f45c65-1b00-0000-f772-d17e440d0000 pid=3396 execve guuid=12604967-1b00-0000-f772-d17e510d0000 pid=3409 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=12604967-1b00-0000-f772-d17e510d0000 pid=3409 execve guuid=86cb98b0-1b00-0000-f772-d17ef20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=86cb98b0-1b00-0000-f772-d17ef20d0000 pid=3570 execve guuid=d3454bec-1b00-0000-f772-d17e7d0e0000 pid=3709 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=d3454bec-1b00-0000-f772-d17e7d0e0000 pid=3709 execve guuid=f7d4bbec-1b00-0000-f772-d17e800e0000 pid=3712 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=f7d4bbec-1b00-0000-f772-d17e800e0000 pid=3712 execve guuid=b91800ed-1b00-0000-f772-d17e820e0000 pid=3714 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=b91800ed-1b00-0000-f772-d17e820e0000 pid=3714 clone guuid=4c668aed-1b00-0000-f772-d17e850e0000 pid=3717 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=4c668aed-1b00-0000-f772-d17e850e0000 pid=3717 execve guuid=d4da7bee-1b00-0000-f772-d17e890e0000 pid=3721 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=d4da7bee-1b00-0000-f772-d17e890e0000 pid=3721 execve guuid=76585ff0-1b00-0000-f772-d17e910e0000 pid=3729 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=76585ff0-1b00-0000-f772-d17e910e0000 pid=3729 execve guuid=e8a6bbf0-1b00-0000-f772-d17e930e0000 pid=3731 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=e8a6bbf0-1b00-0000-f772-d17e930e0000 pid=3731 execve guuid=e14401f1-1b00-0000-f772-d17e950e0000 pid=3733 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=e14401f1-1b00-0000-f772-d17e950e0000 pid=3733 clone guuid=c8b9aaf1-1b00-0000-f772-d17e980e0000 pid=3736 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=c8b9aaf1-1b00-0000-f772-d17e980e0000 pid=3736 execve guuid=617bd3f2-1b00-0000-f772-d17e9c0e0000 pid=3740 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=617bd3f2-1b00-0000-f772-d17e9c0e0000 pid=3740 execve guuid=7b79d4f4-1b00-0000-f772-d17ea20e0000 pid=3746 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=7b79d4f4-1b00-0000-f772-d17ea20e0000 pid=3746 execve guuid=df8825f5-1b00-0000-f772-d17ea40e0000 pid=3748 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=df8825f5-1b00-0000-f772-d17ea40e0000 pid=3748 execve guuid=64d37cf5-1b00-0000-f772-d17ea60e0000 pid=3750 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=64d37cf5-1b00-0000-f772-d17ea60e0000 pid=3750 clone guuid=b50723f6-1b00-0000-f772-d17eaa0e0000 pid=3754 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=b50723f6-1b00-0000-f772-d17eaa0e0000 pid=3754 execve guuid=b88158f7-1b00-0000-f772-d17eb00e0000 pid=3760 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=b88158f7-1b00-0000-f772-d17eb00e0000 pid=3760 execve guuid=9b65a6f9-1b00-0000-f772-d17eba0e0000 pid=3770 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=9b65a6f9-1b00-0000-f772-d17eba0e0000 pid=3770 execve guuid=b1ad12fa-1b00-0000-f772-d17ebc0e0000 pid=3772 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=b1ad12fa-1b00-0000-f772-d17ebc0e0000 pid=3772 execve guuid=4cae80fa-1b00-0000-f772-d17ebe0e0000 pid=3774 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=4cae80fa-1b00-0000-f772-d17ebe0e0000 pid=3774 clone guuid=22e116fb-1b00-0000-f772-d17ec30e0000 pid=3779 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=22e116fb-1b00-0000-f772-d17ec30e0000 pid=3779 execve guuid=ad0d8743-1c00-0000-f772-d17e9e0f0000 pid=3998 /usr/bin/curl net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=ad0d8743-1c00-0000-f772-d17e9e0f0000 pid=3998 execve guuid=d4fdc485-1c00-0000-f772-d17e6e100000 pid=4206 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=d4fdc485-1c00-0000-f772-d17e6e100000 pid=4206 execve guuid=dd8c3586-1c00-0000-f772-d17e70100000 pid=4208 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=dd8c3586-1c00-0000-f772-d17e70100000 pid=4208 execve guuid=529ca586-1c00-0000-f772-d17e72100000 pid=4210 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=529ca586-1c00-0000-f772-d17e72100000 pid=4210 clone guuid=e728d78a-1c00-0000-f772-d17e77100000 pid=4215 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=e728d78a-1c00-0000-f772-d17e77100000 pid=4215 execve guuid=1823568c-1c00-0000-f772-d17e7e100000 pid=4222 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=1823568c-1c00-0000-f772-d17e7e100000 pid=4222 execve guuid=c55e9090-1c00-0000-f772-d17e85100000 pid=4229 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=c55e9090-1c00-0000-f772-d17e85100000 pid=4229 execve guuid=54781291-1c00-0000-f772-d17e86100000 pid=4230 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=54781291-1c00-0000-f772-d17e86100000 pid=4230 execve guuid=d97c7191-1c00-0000-f772-d17e87100000 pid=4231 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=d97c7191-1c00-0000-f772-d17e87100000 pid=4231 clone guuid=805d5c92-1c00-0000-f772-d17e89100000 pid=4233 /usr/bin/wget net send-data write-file guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=805d5c92-1c00-0000-f772-d17e89100000 pid=4233 execve guuid=bdb7f1c9-1c00-0000-f772-d17e3a110000 pid=4410 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=bdb7f1c9-1c00-0000-f772-d17e3a110000 pid=4410 execve guuid=6056f7cc-1c00-0000-f772-d17e46110000 pid=4422 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=6056f7cc-1c00-0000-f772-d17e46110000 pid=4422 execve guuid=6b7257cd-1c00-0000-f772-d17e47110000 pid=4423 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=6b7257cd-1c00-0000-f772-d17e47110000 pid=4423 execve guuid=5e66a3cd-1c00-0000-f772-d17e49110000 pid=4425 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=5e66a3cd-1c00-0000-f772-d17e49110000 pid=4425 clone guuid=ea56c7ce-1c00-0000-f772-d17e4f110000 pid=4431 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=ea56c7ce-1c00-0000-f772-d17e4f110000 pid=4431 execve guuid=7d871fd0-1c00-0000-f772-d17e55110000 pid=4437 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=7d871fd0-1c00-0000-f772-d17e55110000 pid=4437 execve guuid=ae7673d3-1c00-0000-f772-d17e63110000 pid=4451 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=ae7673d3-1c00-0000-f772-d17e63110000 pid=4451 execve guuid=fb8eb8d3-1c00-0000-f772-d17e65110000 pid=4453 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=fb8eb8d3-1c00-0000-f772-d17e65110000 pid=4453 execve guuid=fa851ad4-1c00-0000-f772-d17e69110000 pid=4457 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=fa851ad4-1c00-0000-f772-d17e69110000 pid=4457 clone guuid=beaca3d4-1c00-0000-f772-d17e6e110000 pid=4462 /usr/bin/wget net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=beaca3d4-1c00-0000-f772-d17e6e110000 pid=4462 execve guuid=5d3198d5-1c00-0000-f772-d17e71110000 pid=4465 /usr/bin/curl net guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=5d3198d5-1c00-0000-f772-d17e71110000 pid=4465 execve guuid=90cb80d7-1c00-0000-f772-d17e7b110000 pid=4475 /usr/bin/cat guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=90cb80d7-1c00-0000-f772-d17e7b110000 pid=4475 execve guuid=84f3c4d7-1c00-0000-f772-d17e7d110000 pid=4477 /usr/bin/chmod guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=84f3c4d7-1c00-0000-f772-d17e7d110000 pid=4477 execve guuid=902b04d8-1c00-0000-f772-d17e7f110000 pid=4479 /usr/bin/bash guuid=bc4d81c5-1900-0000-f772-d17e960a0000 pid=2710->guuid=902b04d8-1c00-0000-f772-d17e7f110000 pid=4479 clone e9272886-a735-5495-acea-11202e0d0fe3 103.124.93.149:80 guuid=cbee38c6-1900-0000-f772-d17e990a0000 pid=2713->e9272886-a735-5495-acea-11202e0d0fe3 send: 132B guuid=3ee7c402-1a00-0000-f772-d17ed00a0000 pid=2768->e9272886-a735-5495-acea-11202e0d0fe3 send: 81B 75e02d42-b51b-5d27-8d02-47737f4115cc 103.124.93.149:53 guuid=d6542a3a-1a00-0000-f772-d17e2e0b0000 pid=2862->75e02d42-b51b-5d27-8d02-47737f4115cc con guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863 /usr/bin/dash guuid=d6542a3a-1a00-0000-f772-d17e2e0b0000 pid=2862->guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863 execve guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874 /tmp/bin/busybox dns net send-data zombie guuid=d6542a3a-1a00-0000-f772-d17e2e0b0000 pid=2862->guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874 clone guuid=4be7a33a-1a00-0000-f772-d17e310b0000 pid=2865 /usr/bin/rm guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863->guuid=4be7a33a-1a00-0000-f772-d17e310b0000 pid=2865 execve guuid=6b83fe3a-1a00-0000-f772-d17e330b0000 pid=2867 /usr/bin/mkdir guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863->guuid=6b83fe3a-1a00-0000-f772-d17e330b0000 pid=2867 execve guuid=fd157a3b-1a00-0000-f772-d17e360b0000 pid=2870 /usr/bin/mv guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863->guuid=fd157a3b-1a00-0000-f772-d17e360b0000 pid=2870 execve guuid=cb0eff3b-1a00-0000-f772-d17e380b0000 pid=2872 /usr/bin/chmod guuid=3ecd5c3a-1a00-0000-f772-d17e2f0b0000 pid=2863->guuid=cb0eff3b-1a00-0000-f772-d17e380b0000 pid=2872 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B d57a74f8-c390-5ef0-a056-525f371ee375 bot.taphoanxn.cfd:56999 guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874->d57a74f8-c390-5ef0-a056-525f371ee375 send: 7B 52572bc8-10a5-5075-af21-133a5c079c93 bot.taphoanxn.cfd:53 guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=cb268c3c-1a00-0000-f772-d17e3c0b0000 pid=2876 /tmp/bin/busybox guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874->guuid=cb268c3c-1a00-0000-f772-d17e3c0b0000 pid=2876 clone guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877 /tmp/bin/busybox net net-scan send-data guuid=e3a8763c-1a00-0000-f772-d17e3a0b0000 pid=2874->guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877 clone 563f4588-1a35-5b6c-ac87-745d295586e8 bot.taphoanxn.cfd:80 guuid=0b2e8b3c-1a00-0000-f772-d17e3b0b0000 pid=2875->563f4588-1a35-5b6c-ac87-745d295586e8 send: 133B guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877->75e02d42-b51b-5d27-8d02-47737f4115cc con guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877|send-data send-data to 3148 IP addresses review logs to see them all guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877->guuid=fec1903c-1a00-0000-f772-d17e3d0b0000 pid=2877|send-data send guuid=17347671-1a00-0000-f772-d17e9b0b0000 pid=2971->563f4588-1a35-5b6c-ac87-745d295586e8 send: 82B guuid=024284aa-1a00-0000-f772-d17e2d0c0000 pid=3117->563f4588-1a35-5b6c-ac87-745d295586e8 send: 132B guuid=8a022ec7-1a00-0000-f772-d17e6f0c0000 pid=3183->563f4588-1a35-5b6c-ac87-745d295586e8 send: 81B guuid=990a82e7-1a00-0000-f772-d17e990c0000 pid=3225->563f4588-1a35-5b6c-ac87-745d295586e8 send: 135B guuid=52745a23-1b00-0000-f772-d17ed70c0000 pid=3287->563f4588-1a35-5b6c-ac87-745d295586e8 send: 84B guuid=65f45c65-1b00-0000-f772-d17e440d0000 pid=3396->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397 /usr/bin/dash guuid=65f45c65-1b00-0000-f772-d17e440d0000 pid=3396->guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397 execve guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407 /tmp/bin/watchdog dns net send-data zombie guuid=65f45c65-1b00-0000-f772-d17e440d0000 pid=3396->guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407 clone guuid=43fea565-1b00-0000-f772-d17e470d0000 pid=3399 /usr/bin/rm guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397->guuid=43fea565-1b00-0000-f772-d17e470d0000 pid=3399 execve guuid=8cf9ef65-1b00-0000-f772-d17e480d0000 pid=3400 /usr/bin/mkdir guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397->guuid=8cf9ef65-1b00-0000-f772-d17e480d0000 pid=3400 execve guuid=634e6066-1b00-0000-f772-d17e4a0d0000 pid=3402 /usr/bin/mv guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397->guuid=634e6066-1b00-0000-f772-d17e4a0d0000 pid=3402 execve guuid=d0ded766-1b00-0000-f772-d17e4d0d0000 pid=3405 /usr/bin/chmod guuid=62807265-1b00-0000-f772-d17e450d0000 pid=3397->guuid=d0ded766-1b00-0000-f772-d17e4d0d0000 pid=3405 execve guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 420B guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407->d57a74f8-c390-5ef0-a056-525f371ee375 send: 5B guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=db444a67-1b00-0000-f772-d17e520d0000 pid=3410 /tmp/bin/watchdog guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407->guuid=db444a67-1b00-0000-f772-d17e520d0000 pid=3410 clone guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411 /tmp/bin/watchdog net net-scan send-data guuid=72e63767-1b00-0000-f772-d17e4f0d0000 pid=3407->guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411 clone guuid=12604967-1b00-0000-f772-d17e510d0000 pid=3409->563f4588-1a35-5b6c-ac87-745d295586e8 send: 133B guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411->52572bc8-10a5-5075-af21-133a5c079c93 con guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411|send-data send-data to 3054 IP addresses review logs to see them all guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411->guuid=6dcb4c67-1b00-0000-f772-d17e530d0000 pid=3411|send-data send guuid=86cb98b0-1b00-0000-f772-d17ef20d0000 pid=3570->563f4588-1a35-5b6c-ac87-745d295586e8 send: 82B guuid=4c668aed-1b00-0000-f772-d17e850e0000 pid=3717->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=d4da7bee-1b00-0000-f772-d17e890e0000 pid=3721->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=c8b9aaf1-1b00-0000-f772-d17e980e0000 pid=3736->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=617bd3f2-1b00-0000-f772-d17e9c0e0000 pid=3740->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=b50723f6-1b00-0000-f772-d17eaa0e0000 pid=3754->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=b88158f7-1b00-0000-f772-d17eb00e0000 pid=3760->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=22e116fb-1b00-0000-f772-d17ec30e0000 pid=3779->563f4588-1a35-5b6c-ac87-745d295586e8 send: 133B guuid=ad0d8743-1c00-0000-f772-d17e9e0f0000 pid=3998->563f4588-1a35-5b6c-ac87-745d295586e8 send: 82B guuid=e728d78a-1c00-0000-f772-d17e77100000 pid=4215->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=1823568c-1c00-0000-f772-d17e7e100000 pid=4222->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=805d5c92-1c00-0000-f772-d17e89100000 pid=4233->563f4588-1a35-5b6c-ac87-745d295586e8 send: 132B guuid=bdb7f1c9-1c00-0000-f772-d17e3a110000 pid=4410->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=ea56c7ce-1c00-0000-f772-d17e4f110000 pid=4431->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=7d871fd0-1c00-0000-f772-d17e55110000 pid=4437->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=beaca3d4-1c00-0000-f772-d17e6e110000 pid=4462->563f4588-1a35-5b6c-ac87-745d295586e8 con guuid=5d3198d5-1c00-0000-f772-d17e71110000 pid=4465->563f4588-1a35-5b6c-ac87-745d295586e8 con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-20 21:08:11 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Contacts a large (298450) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
bot.taphoanxn.cfd
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 52f43bc81b293b009c9c6d57faa58960ae5b95662ac2ab9844f4009dbbf2ea1f

(this sample)

  
Delivery method
Distributed via web download

Comments