MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5326ebdce9e78b303f5d690a10dee74f5c512f820a1ae6929473b6121760f979. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 5326ebdce9e78b303f5d690a10dee74f5c512f820a1ae6929473b6121760f979
SHA3-384 hash: 9dfd58a0d473f5d64badf9350410e7431f707043f099c92d20dc6ffd20580794718db4e80fa8fd3baf35563aa1a0e3f9
SHA1 hash: bf05aeaaf04ac2bf912b2ba0e0040bd4dd7cd91f
MD5 hash: d47fe69df2cb214d09f83518bba4e6bb
humanhash: winter-island-shade-purple
File name:akhenaton
Download: download sample
Signature Mirai
File size:2'214 bytes
First seen:2025-07-29 06:42:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:l3H3QV3h3KT3s3J03m3jq73px3paVnwyy3pI3pVVUWrz3poa3po3VX0Ci3ng3ntf:l3H3QV3h3KT3s3J03m3jq7373ES3e3bS
TLSH T1E14198C540A56C1122435D8EFB02490A398150C9752B637E6EBCACB9BC8ADC6F377E76
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=26f421c9-1900-0000-0416-22dd97090000 pid=2455 /usr/bin/sudo guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460 /tmp/sample.bin guuid=26f421c9-1900-0000-0416-22dd97090000 pid=2455->guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460 execve guuid=b42dd7cb-1900-0000-0416-22dd9e090000 pid=2462 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=b42dd7cb-1900-0000-0416-22dd9e090000 pid=2462 execve guuid=5d7dfacf-1900-0000-0416-22ddad090000 pid=2477 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=5d7dfacf-1900-0000-0416-22ddad090000 pid=2477 execve guuid=10c19dda-1900-0000-0416-22ddc3090000 pid=2499 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=10c19dda-1900-0000-0416-22ddc3090000 pid=2499 execve guuid=cb2120db-1900-0000-0416-22ddc5090000 pid=2501 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=cb2120db-1900-0000-0416-22ddc5090000 pid=2501 clone guuid=124cd2db-1900-0000-0416-22ddc8090000 pid=2504 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=124cd2db-1900-0000-0416-22ddc8090000 pid=2504 execve guuid=a72d39dc-1900-0000-0416-22ddca090000 pid=2506 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=a72d39dc-1900-0000-0416-22ddca090000 pid=2506 execve guuid=9b4eafdc-1900-0000-0416-22ddcc090000 pid=2508 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=9b4eafdc-1900-0000-0416-22ddcc090000 pid=2508 execve guuid=d4a83edf-1900-0000-0416-22ddd1090000 pid=2513 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=d4a83edf-1900-0000-0416-22ddd1090000 pid=2513 execve guuid=517fa1e5-1900-0000-0416-22dddf090000 pid=2527 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=517fa1e5-1900-0000-0416-22dddf090000 pid=2527 execve guuid=8cabf5e5-1900-0000-0416-22dde1090000 pid=2529 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=8cabf5e5-1900-0000-0416-22dde1090000 pid=2529 clone guuid=3c7b95e6-1900-0000-0416-22dde5090000 pid=2533 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=3c7b95e6-1900-0000-0416-22dde5090000 pid=2533 execve guuid=2758a4e9-1900-0000-0416-22ddec090000 pid=2540 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=2758a4e9-1900-0000-0416-22ddec090000 pid=2540 execve guuid=67eb0dea-1900-0000-0416-22dded090000 pid=2541 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=67eb0dea-1900-0000-0416-22dded090000 pid=2541 execve guuid=ec6ba9ec-1900-0000-0416-22ddf6090000 pid=2550 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=ec6ba9ec-1900-0000-0416-22ddf6090000 pid=2550 execve guuid=38e9fbef-1900-0000-0416-22ddff090000 pid=2559 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=38e9fbef-1900-0000-0416-22ddff090000 pid=2559 execve guuid=6fe153f0-1900-0000-0416-22dd020a0000 pid=2562 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=6fe153f0-1900-0000-0416-22dd020a0000 pid=2562 clone guuid=285062f2-1900-0000-0416-22dd090a0000 pid=2569 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=285062f2-1900-0000-0416-22dd090a0000 pid=2569 execve guuid=ade5d5f2-1900-0000-0416-22dd0b0a0000 pid=2571 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=ade5d5f2-1900-0000-0416-22dd0b0a0000 pid=2571 execve guuid=e8892af3-1900-0000-0416-22dd0d0a0000 pid=2573 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e8892af3-1900-0000-0416-22dd0d0a0000 pid=2573 execve guuid=65231ff6-1900-0000-0416-22dd160a0000 pid=2582 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=65231ff6-1900-0000-0416-22dd160a0000 pid=2582 execve guuid=37ccecf9-1900-0000-0416-22dd230a0000 pid=2595 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=37ccecf9-1900-0000-0416-22dd230a0000 pid=2595 execve guuid=b5e647fa-1900-0000-0416-22dd250a0000 pid=2597 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=b5e647fa-1900-0000-0416-22dd250a0000 pid=2597 clone guuid=f66818fb-1900-0000-0416-22dd290a0000 pid=2601 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=f66818fb-1900-0000-0416-22dd290a0000 pid=2601 execve guuid=50d734fd-1900-0000-0416-22dd320a0000 pid=2610 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=50d734fd-1900-0000-0416-22dd320a0000 pid=2610 execve guuid=ecc07efd-1900-0000-0416-22dd330a0000 pid=2611 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=ecc07efd-1900-0000-0416-22dd330a0000 pid=2611 execve guuid=7f648300-1a00-0000-0416-22dd3c0a0000 pid=2620 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=7f648300-1a00-0000-0416-22dd3c0a0000 pid=2620 execve guuid=3f273704-1a00-0000-0416-22dd460a0000 pid=2630 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=3f273704-1a00-0000-0416-22dd460a0000 pid=2630 execve guuid=f0cea104-1a00-0000-0416-22dd480a0000 pid=2632 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=f0cea104-1a00-0000-0416-22dd480a0000 pid=2632 clone guuid=b5813e05-1a00-0000-0416-22dd4c0a0000 pid=2636 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=b5813e05-1a00-0000-0416-22dd4c0a0000 pid=2636 execve guuid=873b9605-1a00-0000-0416-22dd4e0a0000 pid=2638 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=873b9605-1a00-0000-0416-22dd4e0a0000 pid=2638 execve guuid=36bdd605-1a00-0000-0416-22dd500a0000 pid=2640 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=36bdd605-1a00-0000-0416-22dd500a0000 pid=2640 execve guuid=9ed7f008-1a00-0000-0416-22dd580a0000 pid=2648 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=9ed7f008-1a00-0000-0416-22dd580a0000 pid=2648 execve guuid=e4476b0e-1a00-0000-0416-22dd690a0000 pid=2665 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e4476b0e-1a00-0000-0416-22dd690a0000 pid=2665 execve guuid=912ec00e-1a00-0000-0416-22dd6b0a0000 pid=2667 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=912ec00e-1a00-0000-0416-22dd6b0a0000 pid=2667 clone guuid=2a99730f-1a00-0000-0416-22dd700a0000 pid=2672 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=2a99730f-1a00-0000-0416-22dd700a0000 pid=2672 execve guuid=e5df7314-1a00-0000-0416-22dd7f0a0000 pid=2687 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e5df7314-1a00-0000-0416-22dd7f0a0000 pid=2687 execve guuid=2c41cb14-1a00-0000-0416-22dd810a0000 pid=2689 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=2c41cb14-1a00-0000-0416-22dd810a0000 pid=2689 execve guuid=29750f18-1a00-0000-0416-22dd890a0000 pid=2697 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=29750f18-1a00-0000-0416-22dd890a0000 pid=2697 execve guuid=451d351f-1a00-0000-0416-22dd9e0a0000 pid=2718 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=451d351f-1a00-0000-0416-22dd9e0a0000 pid=2718 execve guuid=0d9c921f-1a00-0000-0416-22dda00a0000 pid=2720 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=0d9c921f-1a00-0000-0416-22dda00a0000 pid=2720 clone guuid=64646720-1a00-0000-0416-22dda50a0000 pid=2725 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=64646720-1a00-0000-0416-22dda50a0000 pid=2725 execve guuid=31bce228-1a00-0000-0416-22ddc10a0000 pid=2753 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=31bce228-1a00-0000-0416-22ddc10a0000 pid=2753 execve guuid=99156629-1a00-0000-0416-22ddc40a0000 pid=2756 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=99156629-1a00-0000-0416-22ddc40a0000 pid=2756 execve guuid=0a58fd2b-1a00-0000-0416-22ddce0a0000 pid=2766 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=0a58fd2b-1a00-0000-0416-22ddce0a0000 pid=2766 execve guuid=dbf0e42f-1a00-0000-0416-22ddd90a0000 pid=2777 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=dbf0e42f-1a00-0000-0416-22ddd90a0000 pid=2777 execve guuid=8f172930-1a00-0000-0416-22dddb0a0000 pid=2779 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=8f172930-1a00-0000-0416-22dddb0a0000 pid=2779 clone guuid=e56cee30-1a00-0000-0416-22dddd0a0000 pid=2781 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e56cee30-1a00-0000-0416-22dddd0a0000 pid=2781 execve guuid=af0e9633-1a00-0000-0416-22ddde0a0000 pid=2782 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=af0e9633-1a00-0000-0416-22ddde0a0000 pid=2782 execve guuid=79cae733-1a00-0000-0416-22dde00a0000 pid=2784 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=79cae733-1a00-0000-0416-22dde00a0000 pid=2784 execve guuid=9aa82436-1a00-0000-0416-22dde70a0000 pid=2791 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=9aa82436-1a00-0000-0416-22dde70a0000 pid=2791 execve guuid=bab9023a-1a00-0000-0416-22ddef0a0000 pid=2799 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=bab9023a-1a00-0000-0416-22ddef0a0000 pid=2799 execve guuid=00d1563a-1a00-0000-0416-22ddf10a0000 pid=2801 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=00d1563a-1a00-0000-0416-22ddf10a0000 pid=2801 clone guuid=cd32013b-1a00-0000-0416-22ddf50a0000 pid=2805 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=cd32013b-1a00-0000-0416-22ddf50a0000 pid=2805 execve guuid=0cfcdb3b-1a00-0000-0416-22ddf60a0000 pid=2806 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=0cfcdb3b-1a00-0000-0416-22ddf60a0000 pid=2806 execve guuid=4e33303c-1a00-0000-0416-22ddf80a0000 pid=2808 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=4e33303c-1a00-0000-0416-22ddf80a0000 pid=2808 execve guuid=902f9d3e-1a00-0000-0416-22ddff0a0000 pid=2815 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=902f9d3e-1a00-0000-0416-22ddff0a0000 pid=2815 execve guuid=a8626944-1a00-0000-0416-22dd070b0000 pid=2823 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=a8626944-1a00-0000-0416-22dd070b0000 pid=2823 execve guuid=bedbba44-1a00-0000-0416-22dd080b0000 pid=2824 /usr/bin/bash guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=bedbba44-1a00-0000-0416-22dd080b0000 pid=2824 clone guuid=e7ce9b45-1a00-0000-0416-22dd0a0b0000 pid=2826 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e7ce9b45-1a00-0000-0416-22dd0a0b0000 pid=2826 execve guuid=f3112a46-1a00-0000-0416-22dd0b0b0000 pid=2827 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=f3112a46-1a00-0000-0416-22dd0b0b0000 pid=2827 execve guuid=d843eb46-1a00-0000-0416-22dd0c0b0000 pid=2828 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=d843eb46-1a00-0000-0416-22dd0c0b0000 pid=2828 execve guuid=305d124a-1a00-0000-0416-22dd0f0b0000 pid=2831 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=305d124a-1a00-0000-0416-22dd0f0b0000 pid=2831 execve guuid=4f856f4d-1a00-0000-0416-22dd160b0000 pid=2838 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=4f856f4d-1a00-0000-0416-22dd160b0000 pid=2838 execve guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839 /home/sandbox/Akhenaton3ATOx64 net guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839 execve guuid=2fcb124e-1a00-0000-0416-22dd1b0b0000 pid=2843 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=2fcb124e-1a00-0000-0416-22dd1b0b0000 pid=2843 execve guuid=e5998e4e-1a00-0000-0416-22dd1f0b0000 pid=2847 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e5998e4e-1a00-0000-0416-22dd1f0b0000 pid=2847 execve guuid=4295004f-1a00-0000-0416-22dd210b0000 pid=2849 /usr/bin/wget net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=4295004f-1a00-0000-0416-22dd210b0000 pid=2849 execve guuid=44ff7f51-1a00-0000-0416-22dd260b0000 pid=2854 /usr/bin/curl net send-data write-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=44ff7f51-1a00-0000-0416-22dd260b0000 pid=2854 execve guuid=78fc1555-1a00-0000-0416-22dd2b0b0000 pid=2859 /usr/bin/chmod guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=78fc1555-1a00-0000-0416-22dd2b0b0000 pid=2859 execve guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861 /home/sandbox/Akhenaton3ATOx86 net guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861 execve guuid=e7e1a755-1a00-0000-0416-22dd310b0000 pid=2865 /usr/bin/rm delete-file guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=e7e1a755-1a00-0000-0416-22dd310b0000 pid=2865 execve guuid=d6b00256-1a00-0000-0416-22dd350b0000 pid=2869 /usr/bin/rm guuid=ca916bcb-1900-0000-0416-22dd9c090000 pid=2460->guuid=d6b00256-1a00-0000-0416-22dd350b0000 pid=2869 execve 62d372f6-98c4-5a8c-81c3-c777b3229bcb 45.135.194.13:80 guuid=b42dd7cb-1900-0000-0416-22dd9e090000 pid=2462->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=5d7dfacf-1900-0000-0416-22ddad090000 pid=2477->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B guuid=9b4eafdc-1900-0000-0416-22ddcc090000 pid=2508->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=d4a83edf-1900-0000-0416-22ddd1090000 pid=2513->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=67eb0dea-1900-0000-0416-22dded090000 pid=2541->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=ec6ba9ec-1900-0000-0416-22ddf6090000 pid=2550->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=e8892af3-1900-0000-0416-22dd0d0a0000 pid=2573->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=65231ff6-1900-0000-0416-22dd160a0000 pid=2582->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=ecc07efd-1900-0000-0416-22dd330a0000 pid=2611->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=7f648300-1a00-0000-0416-22dd3c0a0000 pid=2620->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=36bdd605-1a00-0000-0416-22dd500a0000 pid=2640->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=9ed7f008-1a00-0000-0416-22dd580a0000 pid=2648->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=2c41cb14-1a00-0000-0416-22dd810a0000 pid=2689->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 145B guuid=29750f18-1a00-0000-0416-22dd890a0000 pid=2697->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 94B guuid=99156629-1a00-0000-0416-22ddc40a0000 pid=2756->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=0a58fd2b-1a00-0000-0416-22ddce0a0000 pid=2766->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B guuid=79cae733-1a00-0000-0416-22dde00a0000 pid=2784->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=9aa82436-1a00-0000-0416-22dde70a0000 pid=2791->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B guuid=4e33303c-1a00-0000-0416-22ddf80a0000 pid=2808->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=902f9d3e-1a00-0000-0416-22ddff0a0000 pid=2815->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B guuid=d843eb46-1a00-0000-0416-22dd0c0b0000 pid=2828->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=305d124a-1a00-0000-0416-22dd0f0b0000 pid=2831->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=23c4f54d-1a00-0000-0416-22dd180b0000 pid=2840 /home/sandbox/Akhenaton3ATOx64 zombie guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839->guuid=23c4f54d-1a00-0000-0416-22dd180b0000 pid=2840 clone guuid=13d2fb4d-1a00-0000-0416-22dd190b0000 pid=2841 /home/sandbox/Akhenaton3ATOx64 zombie guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839->guuid=13d2fb4d-1a00-0000-0416-22dd190b0000 pid=2841 clone guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842 /home/sandbox/Akhenaton3ATOx64 net send-data zombie guuid=24adc94d-1a00-0000-0416-22dd170b0000 pid=2839->guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842 clone guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b 45.135.194.13:34711 guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b send: 10B guuid=05b72e4e-1a00-0000-0416-22dd1c0b0000 pid=2844 /home/sandbox/Akhenaton3ATOx64 guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->guuid=05b72e4e-1a00-0000-0416-22dd1c0b0000 pid=2844 clone guuid=b1eb384e-1a00-0000-0416-22dd1d0b0000 pid=2845 /home/sandbox/Akhenaton3ATOx64 guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->guuid=b1eb384e-1a00-0000-0416-22dd1d0b0000 pid=2845 clone guuid=ee69a98f-2400-0000-0416-22ddf3140000 pid=5363 /home/sandbox/Akhenaton3ATOx64 net send-data guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->guuid=ee69a98f-2400-0000-0416-22ddf3140000 pid=5363 clone guuid=51a15996-2400-0000-0416-22ddf6140000 pid=5366 /home/sandbox/Akhenaton3ATOx64 net send-data guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->guuid=51a15996-2400-0000-0416-22ddf6140000 pid=5366 clone guuid=99a0829d-2400-0000-0416-22ddfa140000 pid=5370 /home/sandbox/Akhenaton3ATOx64 net send-data guuid=936c054e-1a00-0000-0416-22dd1a0b0000 pid=2842->guuid=99a0829d-2400-0000-0416-22ddfa140000 pid=5370 clone guuid=4295004f-1a00-0000-0416-22dd210b0000 pid=2849->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 144B guuid=44ff7f51-1a00-0000-0416-22dd260b0000 pid=2854->62d372f6-98c4-5a8c-81c3-c777b3229bcb send: 93B guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=21369255-1a00-0000-0416-22dd2e0b0000 pid=2862 /home/sandbox/Akhenaton3ATOx86 zombie guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861->guuid=21369255-1a00-0000-0416-22dd2e0b0000 pid=2862 clone guuid=78669755-1a00-0000-0416-22dd2f0b0000 pid=2863 /home/sandbox/Akhenaton3ATOx86 guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861->guuid=78669755-1a00-0000-0416-22dd2f0b0000 pid=2863 clone guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864 /home/sandbox/Akhenaton3ATOx86 net send-data zombie guuid=6bd26955-1a00-0000-0416-22dd2d0b0000 pid=2861->guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864 clone guuid=c6343970-2600-0000-0416-22ddfe140000 pid=5374 /home/sandbox/Akhenaton3ATOx86 guuid=21369255-1a00-0000-0416-22dd2e0b0000 pid=2862->guuid=c6343970-2600-0000-0416-22ddfe140000 pid=5374 clone guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375 /home/sandbox/Akhenaton3ATOx86 net send-data zombie guuid=21369255-1a00-0000-0416-22dd2e0b0000 pid=2862->guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375 clone guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b send: 10B guuid=2743b755-1a00-0000-0416-22dd320b0000 pid=2866 /home/sandbox/Akhenaton3ATOx86 net guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->guuid=2743b755-1a00-0000-0416-22dd320b0000 pid=2866 clone guuid=6438be55-1a00-0000-0416-22dd330b0000 pid=2867 /home/sandbox/Akhenaton3ATOx86 guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->guuid=6438be55-1a00-0000-0416-22dd330b0000 pid=2867 clone guuid=76d88a8f-2400-0000-0416-22ddf1140000 pid=5361 /home/sandbox/Akhenaton3ATOx86 net send-data guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->guuid=76d88a8f-2400-0000-0416-22ddf1140000 pid=5361 clone guuid=13c95496-2400-0000-0416-22ddf5140000 pid=5365 /home/sandbox/Akhenaton3ATOx86 net send-data guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->guuid=13c95496-2400-0000-0416-22ddf5140000 pid=5365 clone guuid=fd377d9d-2400-0000-0416-22ddf9140000 pid=5369 /home/sandbox/Akhenaton3ATOx86 net send-data guuid=87d39d55-1a00-0000-0416-22dd300b0000 pid=2864->guuid=fd377d9d-2400-0000-0416-22ddf9140000 pid=5369 clone guuid=2743b755-1a00-0000-0416-22dd320b0000 pid=2866->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2743b755-1a00-0000-0416-22dd320b0000 pid=2866->8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b con 805a8b81-4974-545e-aff2-d563c69bdda9 172.56.33.188:53 guuid=76d88a8f-2400-0000-0416-22ddf1140000 pid=5361->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=c047a98f-2400-0000-0416-22ddf2140000 pid=5362 /home/sandbox/Akhenaton3ATOx86 guuid=76d88a8f-2400-0000-0416-22ddf1140000 pid=5361->guuid=c047a98f-2400-0000-0416-22ddf2140000 pid=5362 clone guuid=ee69a98f-2400-0000-0416-22ddf3140000 pid=5363->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=c948b38f-2400-0000-0416-22ddf4140000 pid=5364 /home/sandbox/Akhenaton3ATOx64 guuid=ee69a98f-2400-0000-0416-22ddf3140000 pid=5363->guuid=c948b38f-2400-0000-0416-22ddf4140000 pid=5364 clone guuid=13c95496-2400-0000-0416-22ddf5140000 pid=5365->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=b55c5e96-2400-0000-0416-22ddf7140000 pid=5367 /home/sandbox/Akhenaton3ATOx86 guuid=13c95496-2400-0000-0416-22ddf5140000 pid=5365->guuid=b55c5e96-2400-0000-0416-22ddf7140000 pid=5367 clone guuid=51a15996-2400-0000-0416-22ddf6140000 pid=5366->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=4c6c8a96-2400-0000-0416-22ddf8140000 pid=5368 /home/sandbox/Akhenaton3ATOx64 guuid=51a15996-2400-0000-0416-22ddf6140000 pid=5366->guuid=4c6c8a96-2400-0000-0416-22ddf8140000 pid=5368 clone guuid=fd377d9d-2400-0000-0416-22ddf9140000 pid=5369->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=d127ed9d-2400-0000-0416-22ddfc140000 pid=5372 /home/sandbox/Akhenaton3ATOx86 guuid=fd377d9d-2400-0000-0416-22ddf9140000 pid=5369->guuid=d127ed9d-2400-0000-0416-22ddfc140000 pid=5372 clone guuid=99a0829d-2400-0000-0416-22ddfa140000 pid=5370->805a8b81-4974-545e-aff2-d563c69bdda9 send: 2097664B guuid=8a75eb9d-2400-0000-0416-22ddfb140000 pid=5371 /home/sandbox/Akhenaton3ATOx64 guuid=99a0829d-2400-0000-0416-22ddfa140000 pid=5370->guuid=8a75eb9d-2400-0000-0416-22ddfb140000 pid=5371 clone guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375->8065ac23-a9b1-5cd7-b7c5-35b0acf50b7b send: 8B guuid=09afe070-2600-0000-0416-22dd00150000 pid=5376 /home/sandbox/Akhenaton3ATOx86 guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375->guuid=09afe070-2600-0000-0416-22dd00150000 pid=5376 clone guuid=a917e470-2600-0000-0416-22dd01150000 pid=5377 /home/sandbox/Akhenaton3ATOx86 guuid=d0e83e70-2600-0000-0416-22ddff140000 pid=5375->guuid=a917e470-2600-0000-0416-22dd01150000 pid=5377 clone
Threat name:
Script-Shell.Trojan.Multiverze
Status:
Malicious
First seen:
2025-07-29 06:43:51 UTC
File Type:
Text (Shell)
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
newageofkifirempire.camdvr.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5326ebdce9e78b303f5d690a10dee74f5c512f820a1ae6929473b6121760f979

(this sample)

  
Delivery method
Distributed via web download

Comments