MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795
SHA3-384 hash: 359c299a1deecfa8405a38b3631179ee58fb1921ce05a0807f77266579691fcaf052e3fda01e7bb081dd44b539fe52be
SHA1 hash: 26d6a04fcccf7c49b2e3fac7a6499bc6a027b1ff
MD5 hash: adce1fd24040e16bb1f4d381b8388cf7
humanhash: west-green-nebraska-dakota
File name:massload
Download: download sample
Signature Mirai
File size:2'409 bytes
First seen:2025-12-30 01:00:46 UTC
Last seen:2025-12-30 03:13:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:r05pELMk0aC5EMy0MBIWiRFcG0a0RKY6pqufKXRC8Y8i3/D/coT0ET0RUgHBGgHD:rMpzaC56JjH49KxNVHfHsTGmTPQuLeui
TLSH T1D241E4EC3AB17B738582CF04F0734ABD701BA9D466904EACA4BE14B9D5BC914B830A16
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://6yd.ru/mips6091591c65e708bb1c7b6912438880bc14992de4e04939eec216a6ecd6dd93e0 Mirai32-bit elf mirai ua-wget
http://6yd.ru/mpsl79f5ca34a62727003ef76416baa6ece3b7644a6e9d6e581efc32025df3bd86ac Miraielf gafgyt mirai ua-wget
http://6yd.ru/arm4c17940c3b5f774b7d1b24542010805eb200cdeefc89f7c6f89244bc16b3dc02f Miraielf mirai ua-wget
http://6yd.ru/arm5a5202dbe81c29fc2800a3dc5bd72a5968b541ca66af2b08f49aa6dafd94f5236 Miraielf mirai ua-wget
http://6yd.ru/arm730c1fa4827381cc432b67aa1c1608170be61258bddd3a7fba2c66443e7ed88f3 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-29T23:15:00Z UTC
Last seen:
2025-12-30T21:42:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ecfd008a-1700-0000-4670-56ae050c0000 pid=3077 /usr/bin/sudo guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083 /tmp/sample.bin guuid=ecfd008a-1700-0000-4670-56ae050c0000 pid=3077->guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083 execve guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244 clone guuid=dd61b4f2-1700-0000-4670-56aeb40c0000 pid=3252 /usr/bin/cp write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=dd61b4f2-1700-0000-4670-56aeb40c0000 pid=3252 execve guuid=b22b5cf8-1700-0000-4670-56aebc0c0000 pid=3260 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b22b5cf8-1700-0000-4670-56aebc0c0000 pid=3260 execve guuid=630cbbf8-1700-0000-4670-56aebd0c0000 pid=3261 /usr/bin/rm delete-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=630cbbf8-1700-0000-4670-56aebd0c0000 pid=3261 execve guuid=db8029f9-1700-0000-4670-56aebe0c0000 pid=3262 /usr/bin/rm delete-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=db8029f9-1700-0000-4670-56aebe0c0000 pid=3262 execve guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264 execve guuid=19c58d05-1800-0000-4670-56aeda0c0000 pid=3290 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=19c58d05-1800-0000-4670-56aeda0c0000 pid=3290 execve guuid=b865e805-1800-0000-4670-56aedc0c0000 pid=3292 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b865e805-1800-0000-4670-56aedc0c0000 pid=3292 clone guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296 execve guuid=aae13c0f-1800-0000-4670-56aef10c0000 pid=3313 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=aae13c0f-1800-0000-4670-56aef10c0000 pid=3313 execve guuid=b1f2b90f-1800-0000-4670-56aef20c0000 pid=3314 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b1f2b90f-1800-0000-4670-56aef20c0000 pid=3314 clone guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318 execve guuid=15dc6718-1800-0000-4670-56ae080d0000 pid=3336 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=15dc6718-1800-0000-4670-56ae080d0000 pid=3336 execve guuid=20fdf618-1800-0000-4670-56ae0a0d0000 pid=3338 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=20fdf618-1800-0000-4670-56ae0a0d0000 pid=3338 clone guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341 execve guuid=e9d4d220-1800-0000-4670-56ae130d0000 pid=3347 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e9d4d220-1800-0000-4670-56ae130d0000 pid=3347 execve guuid=e4c52521-1800-0000-4670-56ae140d0000 pid=3348 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e4c52521-1800-0000-4670-56ae140d0000 pid=3348 clone guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350 execve guuid=95f6da2a-1800-0000-4670-56ae220d0000 pid=3362 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95f6da2a-1800-0000-4670-56ae220d0000 pid=3362 execve guuid=ca11422b-1800-0000-4670-56ae240d0000 pid=3364 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ca11422b-1800-0000-4670-56ae240d0000 pid=3364 clone guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371 execve guuid=e2880f3e-1800-0000-4670-56ae4d0d0000 pid=3405 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e2880f3e-1800-0000-4670-56ae4d0d0000 pid=3405 execve guuid=0d1e7b3e-1800-0000-4670-56ae4f0d0000 pid=3407 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=0d1e7b3e-1800-0000-4670-56ae4f0d0000 pid=3407 clone guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410 execve guuid=4eebd44b-1800-0000-4670-56ae700d0000 pid=3440 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=4eebd44b-1800-0000-4670-56ae700d0000 pid=3440 execve guuid=30fd464c-1800-0000-4670-56ae720d0000 pid=3442 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=30fd464c-1800-0000-4670-56ae720d0000 pid=3442 clone guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445 execve guuid=14b95959-1800-0000-4670-56ae950d0000 pid=3477 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=14b95959-1800-0000-4670-56ae950d0000 pid=3477 execve guuid=eb1ecf59-1800-0000-4670-56ae980d0000 pid=3480 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=eb1ecf59-1800-0000-4670-56ae980d0000 pid=3480 clone guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483 execve guuid=c1c0c362-1800-0000-4670-56aeb70d0000 pid=3511 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c1c0c362-1800-0000-4670-56aeb70d0000 pid=3511 execve guuid=47890563-1800-0000-4670-56aeb90d0000 pid=3513 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=47890563-1800-0000-4670-56aeb90d0000 pid=3513 clone guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517 execve guuid=cc59566c-1800-0000-4670-56aed30d0000 pid=3539 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=cc59566c-1800-0000-4670-56aed30d0000 pid=3539 execve guuid=c263906c-1800-0000-4670-56aed40d0000 pid=3540 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c263906c-1800-0000-4670-56aed40d0000 pid=3540 clone guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542 execve guuid=318fb27b-1800-0000-4670-56aeef0d0000 pid=3567 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=318fb27b-1800-0000-4670-56aeef0d0000 pid=3567 execve guuid=95a27a7c-1800-0000-4670-56aef10d0000 pid=3569 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95a27a7c-1800-0000-4670-56aef10d0000 pid=3569 clone guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573 execve guuid=1741158d-1800-0000-4670-56ae100e0000 pid=3600 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1741158d-1800-0000-4670-56ae100e0000 pid=3600 execve guuid=d119948d-1800-0000-4670-56ae120e0000 pid=3602 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=d119948d-1800-0000-4670-56ae120e0000 pid=3602 clone guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608 execve guuid=e501a49f-1800-0000-4670-56ae2c0e0000 pid=3628 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e501a49f-1800-0000-4670-56ae2c0e0000 pid=3628 execve guuid=312023a0-1800-0000-4670-56ae2d0e0000 pid=3629 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=312023a0-1800-0000-4670-56ae2d0e0000 pid=3629 clone guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631 execve guuid=8bc122b1-1800-0000-4670-56ae3e0e0000 pid=3646 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8bc122b1-1800-0000-4670-56ae3e0e0000 pid=3646 execve guuid=cfdaa9b1-1800-0000-4670-56ae400e0000 pid=3648 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=cfdaa9b1-1800-0000-4670-56ae400e0000 pid=3648 clone guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651 execve guuid=656b7cc1-1800-0000-4670-56ae5b0e0000 pid=3675 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=656b7cc1-1800-0000-4670-56ae5b0e0000 pid=3675 execve guuid=272ad0c1-1800-0000-4670-56ae5c0e0000 pid=3676 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=272ad0c1-1800-0000-4670-56ae5c0e0000 pid=3676 clone guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684 execve guuid=8a6cd3c9-1b00-0000-4670-56aef4130000 pid=5108 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8a6cd3c9-1b00-0000-4670-56aef4130000 pid=5108 execve guuid=eab313ca-1b00-0000-4670-56aef5130000 pid=5109 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=eab313ca-1b00-0000-4670-56aef5130000 pid=5109 clone guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111 execve guuid=aa5667d0-1e00-0000-4670-56ae1f140000 pid=5151 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=aa5667d0-1e00-0000-4670-56ae1f140000 pid=5151 execve guuid=f535edd0-1e00-0000-4670-56ae20140000 pid=5152 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=f535edd0-1e00-0000-4670-56ae20140000 pid=5152 clone guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154 execve guuid=1d7fccd7-2100-0000-4670-56ae23140000 pid=5155 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1d7fccd7-2100-0000-4670-56ae23140000 pid=5155 execve guuid=58664bd8-2100-0000-4670-56ae24140000 pid=5156 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=58664bd8-2100-0000-4670-56ae24140000 pid=5156 clone guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158 execve guuid=847e14df-2400-0000-4670-56ae27140000 pid=5159 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=847e14df-2400-0000-4670-56ae27140000 pid=5159 execve guuid=f1479bdf-2400-0000-4670-56ae28140000 pid=5160 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=f1479bdf-2400-0000-4670-56ae28140000 pid=5160 clone guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162 execve guuid=62a69df1-1700-0000-4670-56aeae0c0000 pid=3246 /usr/bin/cat guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=62a69df1-1700-0000-4670-56aeae0c0000 pid=3246 execve guuid=12efa7f1-1700-0000-4670-56aeaf0c0000 pid=3247 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=12efa7f1-1700-0000-4670-56aeaf0c0000 pid=3247 execve guuid=0ac5b4f1-1700-0000-4670-56aeb00c0000 pid=3248 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=0ac5b4f1-1700-0000-4670-56aeb00c0000 pid=3248 execve guuid=9f10caf1-1700-0000-4670-56aeb10c0000 pid=3249 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=9f10caf1-1700-0000-4670-56aeb10c0000 pid=3249 execve guuid=42e2ddf1-1700-0000-4670-56aeb20c0000 pid=3250 /usr/bin/cut guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=42e2ddf1-1700-0000-4670-56aeb20c0000 pid=3250 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B a426af05-0fe5-5064-9002-84e3f002b7b9 6yd.ru:80 guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384 /usr/bin/curl dns net send-data guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371->guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384 clone guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423 /usr/bin/curl dns net send-data guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410->guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423 clone guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459 /usr/bin/curl dns net send-data guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445->guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459 clone guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490 /usr/bin/curl dns net send-data guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483->guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490 clone guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525 /usr/bin/curl dns net send-data guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517->guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525 clone guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 8c845f28-3b01-599d-863e-2a81a3ac53cf 6yd.ru:21 guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 94022332-c464-5ce3-99e3-f0080714c713 6yd.ru:37453 guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->94022332-c464-5ce3-99e3-f0080714c713 con guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 73caa5fa-a45b-5e96-a01d-3c8b81723886 6yd.ru:42017 guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->73caa5fa-a45b-5e96-a01d-3c8b81723886 con guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 6ee76812-18cd-58e5-a8cd-634c683c6d6a 6yd.ru:36243 guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->6ee76812-18cd-58e5-a8cd-634c683c6d6a con guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 32695d35-ba7a-5ca0-937e-28b449c8df27 6yd.ru:36183 guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->32695d35-ba7a-5ca0-937e-28b449c8df27 con guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B d3f382e7-57d2-5a44-bb94-c20b4065faff 6yd.ru:34545 guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->d3f382e7-57d2-5a44-bb94-c20b4065faff con guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 0c3824ad-d5d2-5b86-a353-5231416ae6a5 6yd.ru:69 guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 168B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-30 01:10:16 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes system logs
Executes dropped EXE
Renames itself
Contacts a large (33243) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795

(this sample)

  
Delivery method
Distributed via web download

Comments