MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 633c48ec794472eb428b2e0f3f5efd04cf6b1d961ffbcc3a0df5110b5fba6075. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 633c48ec794472eb428b2e0f3f5efd04cf6b1d961ffbcc3a0df5110b5fba6075
SHA3-384 hash: aa6fe188d394177d10b838f023ccc460053586fa2c9f725a3c3647323abd6d1943ee07d75d764f8ef639f9debfaceda6
SHA1 hash: 58a82da7781d213b4c474b779ca7f672ce495105
MD5 hash: 60b84b3f06fb5b994e4c3f7bdfd868b8
humanhash: hotel-kentucky-eleven-batman
File name:massload
Download: download sample
Signature Mirai
File size:2'453 bytes
First seen:2025-12-18 07:08:06 UTC
Last seen:2025-12-18 19:37:38 UTC
File type: sh
MIME type:text/plain
ssdeep 24:Qva5EMy0MBy5qiPomoTgTCEi6Xk6KXRCm5emi3FoyFoToZjZCUgHfGgHf6v+0+6s:Qva56aoQN2ThHZHSTWOntli
TLSH T16451EBFD3A6167374545CF47B1B25AFD702BE8C854908F58A69E34E8F678904B02163B
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm4a3d5e3c3e422d72ef0e095e164f2706e250839eaf52e24dd7624f6e3e250f8da Miraiarm elf geofenced mirai ua-wget USA
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-18T07:37:00Z UTC
Last seen:
2025-12-18T08:08:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f27b4e80-1f00-0000-8085-0a60440a0000 pid=2628 /usr/bin/sudo guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636 /tmp/sample.bin guuid=f27b4e80-1f00-0000-8085-0a60440a0000 pid=2628->guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636 execve guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638 clone guuid=24eb7485-1f00-0000-8085-0a60580a0000 pid=2648 /usr/bin/cp write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=24eb7485-1f00-0000-8085-0a60580a0000 pid=2648 execve guuid=ab13758a-1f00-0000-8085-0a60690a0000 pid=2665 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=ab13758a-1f00-0000-8085-0a60690a0000 pid=2665 execve guuid=1e26ed8a-1f00-0000-8085-0a606c0a0000 pid=2668 /usr/bin/rm delete-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=1e26ed8a-1f00-0000-8085-0a606c0a0000 pid=2668 execve guuid=10f73a8b-1f00-0000-8085-0a606e0a0000 pid=2670 /usr/bin/rm delete-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=10f73a8b-1f00-0000-8085-0a606e0a0000 pid=2670 execve guuid=2a52d88c-1f00-0000-8085-0a60740a0000 pid=2676 /usr/bin/wget net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2a52d88c-1f00-0000-8085-0a60740a0000 pid=2676 execve guuid=3e5c7ea8-1f00-0000-8085-0a60be0a0000 pid=2750 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=3e5c7ea8-1f00-0000-8085-0a60be0a0000 pid=2750 execve guuid=e0bdb6a8-1f00-0000-8085-0a60bf0a0000 pid=2751 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=e0bdb6a8-1f00-0000-8085-0a60bf0a0000 pid=2751 clone guuid=48753ca9-1f00-0000-8085-0a60c30a0000 pid=2755 /usr/bin/wget net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=48753ca9-1f00-0000-8085-0a60c30a0000 pid=2755 execve guuid=cacd1abc-1f00-0000-8085-0a60e10a0000 pid=2785 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=cacd1abc-1f00-0000-8085-0a60e10a0000 pid=2785 execve guuid=e5a27bbc-1f00-0000-8085-0a60e20a0000 pid=2786 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=e5a27bbc-1f00-0000-8085-0a60e20a0000 pid=2786 clone guuid=9ec52abe-1f00-0000-8085-0a60e60a0000 pid=2790 /usr/bin/wget net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=9ec52abe-1f00-0000-8085-0a60e60a0000 pid=2790 execve guuid=042912cb-1f00-0000-8085-0a60fe0a0000 pid=2814 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=042912cb-1f00-0000-8085-0a60fe0a0000 pid=2814 execve guuid=deb38acb-1f00-0000-8085-0a60ff0a0000 pid=2815 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=deb38acb-1f00-0000-8085-0a60ff0a0000 pid=2815 clone guuid=07c76acc-1f00-0000-8085-0a60010b0000 pid=2817 /usr/bin/wget net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=07c76acc-1f00-0000-8085-0a60010b0000 pid=2817 execve guuid=2e0fc6e3-1f00-0000-8085-0a60260b0000 pid=2854 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2e0fc6e3-1f00-0000-8085-0a60260b0000 pid=2854 execve guuid=887702e4-1f00-0000-8085-0a60280b0000 pid=2856 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=887702e4-1f00-0000-8085-0a60280b0000 pid=2856 clone guuid=9b839ae4-1f00-0000-8085-0a602b0b0000 pid=2859 /usr/bin/wget net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=9b839ae4-1f00-0000-8085-0a602b0b0000 pid=2859 execve guuid=04786ef1-1f00-0000-8085-0a60440b0000 pid=2884 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=04786ef1-1f00-0000-8085-0a60440b0000 pid=2884 execve guuid=7637aef1-1f00-0000-8085-0a60460b0000 pid=2886 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=7637aef1-1f00-0000-8085-0a60460b0000 pid=2886 clone guuid=a26930f2-1f00-0000-8085-0a604a0b0000 pid=2890 /usr/bin/curl net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=a26930f2-1f00-0000-8085-0a604a0b0000 pid=2890 execve guuid=9d11d910-2000-0000-8085-0a60840b0000 pid=2948 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=9d11d910-2000-0000-8085-0a60840b0000 pid=2948 execve guuid=22a63611-2000-0000-8085-0a60850b0000 pid=2949 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=22a63611-2000-0000-8085-0a60850b0000 pid=2949 clone guuid=fde7f412-2000-0000-8085-0a60880b0000 pid=2952 /usr/bin/curl net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=fde7f412-2000-0000-8085-0a60880b0000 pid=2952 execve guuid=4ff64d25-2000-0000-8085-0a609d0b0000 pid=2973 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=4ff64d25-2000-0000-8085-0a609d0b0000 pid=2973 execve guuid=7dddc025-2000-0000-8085-0a609e0b0000 pid=2974 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=7dddc025-2000-0000-8085-0a609e0b0000 pid=2974 clone guuid=30c9d727-2000-0000-8085-0a60a00b0000 pid=2976 /usr/bin/curl net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=30c9d727-2000-0000-8085-0a60a00b0000 pid=2976 execve guuid=ca82b437-2000-0000-8085-0a60b50b0000 pid=2997 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=ca82b437-2000-0000-8085-0a60b50b0000 pid=2997 execve guuid=05d32338-2000-0000-8085-0a60b80b0000 pid=3000 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=05d32338-2000-0000-8085-0a60b80b0000 pid=3000 clone guuid=8797ba38-2000-0000-8085-0a60bb0b0000 pid=3003 /usr/bin/curl net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=8797ba38-2000-0000-8085-0a60bb0b0000 pid=3003 execve guuid=2619c054-2000-0000-8085-0a60fe0b0000 pid=3070 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2619c054-2000-0000-8085-0a60fe0b0000 pid=3070 execve guuid=5d0e1355-2000-0000-8085-0a60000c0000 pid=3072 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=5d0e1355-2000-0000-8085-0a60000c0000 pid=3072 clone guuid=125dde55-2000-0000-8085-0a60050c0000 pid=3077 /usr/bin/curl net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=125dde55-2000-0000-8085-0a60050c0000 pid=3077 execve guuid=6664e063-2000-0000-8085-0a602f0c0000 pid=3119 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=6664e063-2000-0000-8085-0a602f0c0000 pid=3119 execve guuid=17151964-2000-0000-8085-0a60310c0000 pid=3121 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=17151964-2000-0000-8085-0a60310c0000 pid=3121 clone guuid=4100ab64-2000-0000-8085-0a60340c0000 pid=3124 /usr/bin/busybox net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=4100ab64-2000-0000-8085-0a60340c0000 pid=3124 execve guuid=6b70ed90-2000-0000-8085-0a60990c0000 pid=3225 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=6b70ed90-2000-0000-8085-0a60990c0000 pid=3225 execve guuid=d3e54891-2000-0000-8085-0a609a0c0000 pid=3226 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=d3e54891-2000-0000-8085-0a609a0c0000 pid=3226 clone guuid=81cd4f93-2000-0000-8085-0a609c0c0000 pid=3228 /usr/bin/busybox net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=81cd4f93-2000-0000-8085-0a609c0c0000 pid=3228 execve guuid=17a3e5b5-2000-0000-8085-0a60c10c0000 pid=3265 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=17a3e5b5-2000-0000-8085-0a60c10c0000 pid=3265 execve guuid=078b65b6-2000-0000-8085-0a60c20c0000 pid=3266 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=078b65b6-2000-0000-8085-0a60c20c0000 pid=3266 clone guuid=b7194eb7-2000-0000-8085-0a60c40c0000 pid=3268 /usr/bin/busybox net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=b7194eb7-2000-0000-8085-0a60c40c0000 pid=3268 execve guuid=050a4fd6-2000-0000-8085-0a60ef0c0000 pid=3311 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=050a4fd6-2000-0000-8085-0a60ef0c0000 pid=3311 execve guuid=013febd6-2000-0000-8085-0a60f00c0000 pid=3312 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=013febd6-2000-0000-8085-0a60f00c0000 pid=3312 clone guuid=be5ac3d8-2000-0000-8085-0a60f30c0000 pid=3315 /usr/bin/busybox net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=be5ac3d8-2000-0000-8085-0a60f30c0000 pid=3315 execve guuid=a5c88c01-2100-0000-8085-0a603a0d0000 pid=3386 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=a5c88c01-2100-0000-8085-0a603a0d0000 pid=3386 execve guuid=2643e901-2100-0000-8085-0a603b0d0000 pid=3387 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2643e901-2100-0000-8085-0a603b0d0000 pid=3387 clone guuid=07fe0a04-2100-0000-8085-0a603d0d0000 pid=3389 /usr/bin/busybox net send-data write-file guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=07fe0a04-2100-0000-8085-0a603d0d0000 pid=3389 execve guuid=fa68be22-2100-0000-8085-0a607e0d0000 pid=3454 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=fa68be22-2100-0000-8085-0a607e0d0000 pid=3454 execve guuid=17af1323-2100-0000-8085-0a60800d0000 pid=3456 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=17af1323-2100-0000-8085-0a60800d0000 pid=3456 clone guuid=2b383a24-2100-0000-8085-0a60840d0000 pid=3460 /usr/bin/busybox send-data guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2b383a24-2100-0000-8085-0a60840d0000 pid=3460 execve guuid=df283927-2400-0000-8085-0a60ee130000 pid=5102 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=df283927-2400-0000-8085-0a60ee130000 pid=5102 execve guuid=2115a427-2400-0000-8085-0a60ef130000 pid=5103 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=2115a427-2400-0000-8085-0a60ef130000 pid=5103 clone guuid=f6447329-2400-0000-8085-0a60f1130000 pid=5105 /usr/bin/busybox send-data guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=f6447329-2400-0000-8085-0a60f1130000 pid=5105 execve guuid=e0ed9f2c-2700-0000-8085-0a6019140000 pid=5145 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=e0ed9f2c-2700-0000-8085-0a6019140000 pid=5145 execve guuid=088d052d-2700-0000-8085-0a601a140000 pid=5146 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=088d052d-2700-0000-8085-0a601a140000 pid=5146 clone guuid=6f9ffc2d-2700-0000-8085-0a601c140000 pid=5148 /usr/bin/busybox send-data guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=6f9ffc2d-2700-0000-8085-0a601c140000 pid=5148 execve guuid=c90b4731-2a00-0000-8085-0a601d140000 pid=5149 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=c90b4731-2a00-0000-8085-0a601d140000 pid=5149 execve guuid=732de531-2a00-0000-8085-0a601e140000 pid=5150 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=732de531-2a00-0000-8085-0a601e140000 pid=5150 clone guuid=6aec0133-2a00-0000-8085-0a6020140000 pid=5152 /usr/bin/busybox send-data guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=6aec0133-2a00-0000-8085-0a6020140000 pid=5152 execve guuid=1d56c138-2d00-0000-8085-0a6021140000 pid=5153 /usr/bin/chmod guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=1d56c138-2d00-0000-8085-0a6021140000 pid=5153 execve guuid=9b5d4a39-2d00-0000-8085-0a6022140000 pid=5154 /usr/bin/dash guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=9b5d4a39-2d00-0000-8085-0a6022140000 pid=5154 clone guuid=bcba083b-2d00-0000-8085-0a6024140000 pid=5156 /usr/bin/busybox send-data guuid=92413d83-1f00-0000-8085-0a604c0a0000 pid=2636->guuid=bcba083b-2d00-0000-8085-0a6024140000 pid=5156 execve guuid=166f9e83-1f00-0000-8085-0a604f0a0000 pid=2639 /usr/bin/cat guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638->guuid=166f9e83-1f00-0000-8085-0a604f0a0000 pid=2639 execve guuid=aa55ad83-1f00-0000-8085-0a60500a0000 pid=2640 /usr/bin/grep guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638->guuid=aa55ad83-1f00-0000-8085-0a60500a0000 pid=2640 execve guuid=2a56b983-1f00-0000-8085-0a60510a0000 pid=2641 /usr/bin/grep guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638->guuid=2a56b983-1f00-0000-8085-0a60510a0000 pid=2641 execve guuid=7f59c483-1f00-0000-8085-0a60530a0000 pid=2643 /usr/bin/grep guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638->guuid=7f59c483-1f00-0000-8085-0a60530a0000 pid=2643 execve guuid=16edd483-1f00-0000-8085-0a60540a0000 pid=2644 /usr/bin/cut guuid=56aa8583-1f00-0000-8085-0a604e0a0000 pid=2638->guuid=16edd483-1f00-0000-8085-0a60540a0000 pid=2644 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=2a52d88c-1f00-0000-8085-0a60740a0000 pid=2676->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=48753ca9-1f00-0000-8085-0a60c30a0000 pid=2755->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=9ec52abe-1f00-0000-8085-0a60e60a0000 pid=2790->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=07c76acc-1f00-0000-8085-0a60010b0000 pid=2817->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=9b839ae4-1f00-0000-8085-0a602b0b0000 pid=2859->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=a26930f2-1f00-0000-8085-0a604a0b0000 pid=2890->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=fde7f412-2000-0000-8085-0a60880b0000 pid=2952->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=30c9d727-2000-0000-8085-0a60a00b0000 pid=2976->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=8797ba38-2000-0000-8085-0a60bb0b0000 pid=3003->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=125dde55-2000-0000-8085-0a60050c0000 pid=3077->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B b0cf3289-92f5-5539-a0e5-1b38dad07c60 45.125.66.56:21 guuid=4100ab64-2000-0000-8085-0a60340c0000 pid=3124->b0cf3289-92f5-5539-a0e5-1b38dad07c60 send: 78B 75d96e4e-a79e-550e-8b57-7aee3fa860fa 45.125.66.56:12343 guuid=4100ab64-2000-0000-8085-0a60340c0000 pid=3124->75d96e4e-a79e-550e-8b57-7aee3fa860fa con guuid=81cd4f93-2000-0000-8085-0a609c0c0000 pid=3228->b0cf3289-92f5-5539-a0e5-1b38dad07c60 send: 78B 05052187-1654-5943-976f-3f4ad9daba69 45.125.66.56:57349 guuid=81cd4f93-2000-0000-8085-0a609c0c0000 pid=3228->05052187-1654-5943-976f-3f4ad9daba69 con guuid=b7194eb7-2000-0000-8085-0a60c40c0000 pid=3268->b0cf3289-92f5-5539-a0e5-1b38dad07c60 send: 78B 6fce6417-383d-5b0a-81a5-cb04bb328094 45.125.66.56:23583 guuid=b7194eb7-2000-0000-8085-0a60c40c0000 pid=3268->6fce6417-383d-5b0a-81a5-cb04bb328094 con guuid=be5ac3d8-2000-0000-8085-0a60f30c0000 pid=3315->b0cf3289-92f5-5539-a0e5-1b38dad07c60 send: 78B 0f53c6b8-911a-51c8-8d09-6eb80e41bd09 45.125.66.56:22022 guuid=be5ac3d8-2000-0000-8085-0a60f30c0000 pid=3315->0f53c6b8-911a-51c8-8d09-6eb80e41bd09 con guuid=07fe0a04-2100-0000-8085-0a603d0d0000 pid=3389->b0cf3289-92f5-5539-a0e5-1b38dad07c60 send: 78B 9557779c-6b39-55cb-84df-9722dac907cb 45.125.66.56:42674 guuid=07fe0a04-2100-0000-8085-0a603d0d0000 pid=3389->9557779c-6b39-55cb-84df-9722dac907cb con cff0b52d-97e9-52b6-b5e3-47daee1b02bc 45.125.66.56:69 guuid=2b383a24-2100-0000-8085-0a60840d0000 pid=3460->cff0b52d-97e9-52b6-b5e3-47daee1b02bc send: 252B guuid=f6447329-2400-0000-8085-0a60f1130000 pid=5105->cff0b52d-97e9-52b6-b5e3-47daee1b02bc send: 252B guuid=6f9ffc2d-2700-0000-8085-0a601c140000 pid=5148->cff0b52d-97e9-52b6-b5e3-47daee1b02bc send: 252B guuid=6aec0133-2a00-0000-8085-0a6020140000 pid=5152->cff0b52d-97e9-52b6-b5e3-47daee1b02bc send: 252B guuid=bcba083b-2d00-0000-8085-0a6024140000 pid=5156->cff0b52d-97e9-52b6-b5e3-47daee1b02bc send: 126B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-18 07:13:17 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 633c48ec794472eb428b2e0f3f5efd04cf6b1d961ffbcc3a0df5110b5fba6075

(this sample)

  
Delivery method
Distributed via web download

Comments