MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795
SHA3-384 hash: 359c299a1deecfa8405a38b3631179ee58fb1921ce05a0807f77266579691fcaf052e3fda01e7bb081dd44b539fe52be
SHA1 hash: 26d6a04fcccf7c49b2e3fac7a6499bc6a027b1ff
MD5 hash: adce1fd24040e16bb1f4d381b8388cf7
humanhash: west-green-nebraska-dakota
File name:massload
Download: download sample
Signature Mirai
File size:2'409 bytes
First seen:2025-12-30 01:00:46 UTC
Last seen:2025-12-30 03:13:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:r05pELMk0aC5EMy0MBIWiRFcG0a0RKY6pqufKXRC8Y8i3/D/coT0ET0RUgHBGgHD:rMpzaC56JjH49KxNVHfHsTGmTPQuLeui
TLSH T1D241E4EC3AB17B738582CF04F0734ABD701BA9D466904EACA4BE14B9D5BC914B830A16
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://6yd.ru/mipsf4e57df4db85e8cb9bf6993b1d5eeae6ebdebbd9a21fb564f6fc0bddaf21f311 Mirai32-bit elf mirai ua-wget
http://6yd.ru/mpsl656ae07d01153528d7a28fc4c91438a1425101c459a256fdbb49263e1b15faac Miraielf gafgyt mirai ua-wget
http://6yd.ru/arm425d072e9eaea6369c210422bb438740671a54d2aa54efd9bbb828b20cac4d69d Miraielf mirai ua-wget
http://6yd.ru/arm5da7cdc7ebe8f9f6f8e1a6b31e63a7ff718c31758bb14418369c4864a7408230a Miraielf mirai ua-wget
http://6yd.ru/arm7c329cbdcfb92555ba6a5693ddf7c9a39c641c8b8434638284c9e87915e9f87b9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-29T23:15:00Z UTC
Last seen:
2025-12-30T21:42:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ecfd008a-1700-0000-4670-56ae050c0000 pid=3077 /usr/bin/sudo guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083 /tmp/sample.bin guuid=ecfd008a-1700-0000-4670-56ae050c0000 pid=3077->guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083 execve guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244 clone guuid=dd61b4f2-1700-0000-4670-56aeb40c0000 pid=3252 /usr/bin/cp write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=dd61b4f2-1700-0000-4670-56aeb40c0000 pid=3252 execve guuid=b22b5cf8-1700-0000-4670-56aebc0c0000 pid=3260 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b22b5cf8-1700-0000-4670-56aebc0c0000 pid=3260 execve guuid=630cbbf8-1700-0000-4670-56aebd0c0000 pid=3261 /usr/bin/rm delete-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=630cbbf8-1700-0000-4670-56aebd0c0000 pid=3261 execve guuid=db8029f9-1700-0000-4670-56aebe0c0000 pid=3262 /usr/bin/rm delete-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=db8029f9-1700-0000-4670-56aebe0c0000 pid=3262 execve guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264 execve guuid=19c58d05-1800-0000-4670-56aeda0c0000 pid=3290 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=19c58d05-1800-0000-4670-56aeda0c0000 pid=3290 execve guuid=b865e805-1800-0000-4670-56aedc0c0000 pid=3292 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b865e805-1800-0000-4670-56aedc0c0000 pid=3292 clone guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296 execve guuid=aae13c0f-1800-0000-4670-56aef10c0000 pid=3313 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=aae13c0f-1800-0000-4670-56aef10c0000 pid=3313 execve guuid=b1f2b90f-1800-0000-4670-56aef20c0000 pid=3314 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=b1f2b90f-1800-0000-4670-56aef20c0000 pid=3314 clone guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318 execve guuid=15dc6718-1800-0000-4670-56ae080d0000 pid=3336 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=15dc6718-1800-0000-4670-56ae080d0000 pid=3336 execve guuid=20fdf618-1800-0000-4670-56ae0a0d0000 pid=3338 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=20fdf618-1800-0000-4670-56ae0a0d0000 pid=3338 clone guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341 execve guuid=e9d4d220-1800-0000-4670-56ae130d0000 pid=3347 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e9d4d220-1800-0000-4670-56ae130d0000 pid=3347 execve guuid=e4c52521-1800-0000-4670-56ae140d0000 pid=3348 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e4c52521-1800-0000-4670-56ae140d0000 pid=3348 clone guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350 /usr/bin/wget dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350 execve guuid=95f6da2a-1800-0000-4670-56ae220d0000 pid=3362 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95f6da2a-1800-0000-4670-56ae220d0000 pid=3362 execve guuid=ca11422b-1800-0000-4670-56ae240d0000 pid=3364 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ca11422b-1800-0000-4670-56ae240d0000 pid=3364 clone guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371 execve guuid=e2880f3e-1800-0000-4670-56ae4d0d0000 pid=3405 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e2880f3e-1800-0000-4670-56ae4d0d0000 pid=3405 execve guuid=0d1e7b3e-1800-0000-4670-56ae4f0d0000 pid=3407 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=0d1e7b3e-1800-0000-4670-56ae4f0d0000 pid=3407 clone guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410 execve guuid=4eebd44b-1800-0000-4670-56ae700d0000 pid=3440 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=4eebd44b-1800-0000-4670-56ae700d0000 pid=3440 execve guuid=30fd464c-1800-0000-4670-56ae720d0000 pid=3442 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=30fd464c-1800-0000-4670-56ae720d0000 pid=3442 clone guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445 execve guuid=14b95959-1800-0000-4670-56ae950d0000 pid=3477 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=14b95959-1800-0000-4670-56ae950d0000 pid=3477 execve guuid=eb1ecf59-1800-0000-4670-56ae980d0000 pid=3480 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=eb1ecf59-1800-0000-4670-56ae980d0000 pid=3480 clone guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483 execve guuid=c1c0c362-1800-0000-4670-56aeb70d0000 pid=3511 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c1c0c362-1800-0000-4670-56aeb70d0000 pid=3511 execve guuid=47890563-1800-0000-4670-56aeb90d0000 pid=3513 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=47890563-1800-0000-4670-56aeb90d0000 pid=3513 clone guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517 /usr/bin/curl net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517 execve guuid=cc59566c-1800-0000-4670-56aed30d0000 pid=3539 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=cc59566c-1800-0000-4670-56aed30d0000 pid=3539 execve guuid=c263906c-1800-0000-4670-56aed40d0000 pid=3540 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c263906c-1800-0000-4670-56aed40d0000 pid=3540 clone guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542 execve guuid=318fb27b-1800-0000-4670-56aeef0d0000 pid=3567 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=318fb27b-1800-0000-4670-56aeef0d0000 pid=3567 execve guuid=95a27a7c-1800-0000-4670-56aef10d0000 pid=3569 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=95a27a7c-1800-0000-4670-56aef10d0000 pid=3569 clone guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573 execve guuid=1741158d-1800-0000-4670-56ae100e0000 pid=3600 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1741158d-1800-0000-4670-56ae100e0000 pid=3600 execve guuid=d119948d-1800-0000-4670-56ae120e0000 pid=3602 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=d119948d-1800-0000-4670-56ae120e0000 pid=3602 clone guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608 execve guuid=e501a49f-1800-0000-4670-56ae2c0e0000 pid=3628 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=e501a49f-1800-0000-4670-56ae2c0e0000 pid=3628 execve guuid=312023a0-1800-0000-4670-56ae2d0e0000 pid=3629 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=312023a0-1800-0000-4670-56ae2d0e0000 pid=3629 clone guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631 execve guuid=8bc122b1-1800-0000-4670-56ae3e0e0000 pid=3646 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8bc122b1-1800-0000-4670-56ae3e0e0000 pid=3646 execve guuid=cfdaa9b1-1800-0000-4670-56ae400e0000 pid=3648 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=cfdaa9b1-1800-0000-4670-56ae400e0000 pid=3648 clone guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651 /usr/bin/busybox dns net send-data write-file guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651 execve guuid=656b7cc1-1800-0000-4670-56ae5b0e0000 pid=3675 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=656b7cc1-1800-0000-4670-56ae5b0e0000 pid=3675 execve guuid=272ad0c1-1800-0000-4670-56ae5c0e0000 pid=3676 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=272ad0c1-1800-0000-4670-56ae5c0e0000 pid=3676 clone guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684 execve guuid=8a6cd3c9-1b00-0000-4670-56aef4130000 pid=5108 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=8a6cd3c9-1b00-0000-4670-56aef4130000 pid=5108 execve guuid=eab313ca-1b00-0000-4670-56aef5130000 pid=5109 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=eab313ca-1b00-0000-4670-56aef5130000 pid=5109 clone guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111 execve guuid=aa5667d0-1e00-0000-4670-56ae1f140000 pid=5151 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=aa5667d0-1e00-0000-4670-56ae1f140000 pid=5151 execve guuid=f535edd0-1e00-0000-4670-56ae20140000 pid=5152 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=f535edd0-1e00-0000-4670-56ae20140000 pid=5152 clone guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154 execve guuid=1d7fccd7-2100-0000-4670-56ae23140000 pid=5155 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=1d7fccd7-2100-0000-4670-56ae23140000 pid=5155 execve guuid=58664bd8-2100-0000-4670-56ae24140000 pid=5156 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=58664bd8-2100-0000-4670-56ae24140000 pid=5156 clone guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158 execve guuid=847e14df-2400-0000-4670-56ae27140000 pid=5159 /usr/bin/chmod guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=847e14df-2400-0000-4670-56ae27140000 pid=5159 execve guuid=f1479bdf-2400-0000-4670-56ae28140000 pid=5160 /usr/bin/dash guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=f1479bdf-2400-0000-4670-56ae28140000 pid=5160 clone guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162 /usr/bin/busybox dns net send-data guuid=8556938b-1700-0000-4670-56ae0b0c0000 pid=3083->guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162 execve guuid=62a69df1-1700-0000-4670-56aeae0c0000 pid=3246 /usr/bin/cat guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=62a69df1-1700-0000-4670-56aeae0c0000 pid=3246 execve guuid=12efa7f1-1700-0000-4670-56aeaf0c0000 pid=3247 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=12efa7f1-1700-0000-4670-56aeaf0c0000 pid=3247 execve guuid=0ac5b4f1-1700-0000-4670-56aeb00c0000 pid=3248 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=0ac5b4f1-1700-0000-4670-56aeb00c0000 pid=3248 execve guuid=9f10caf1-1700-0000-4670-56aeb10c0000 pid=3249 /usr/bin/grep guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=9f10caf1-1700-0000-4670-56aeb10c0000 pid=3249 execve guuid=42e2ddf1-1700-0000-4670-56aeb20c0000 pid=3250 /usr/bin/cut guuid=b8357bf1-1700-0000-4670-56aeac0c0000 pid=3244->guuid=42e2ddf1-1700-0000-4670-56aeb20c0000 pid=3250 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B a426af05-0fe5-5064-9002-84e3f002b7b9 6yd.ru:80 guuid=810fd1fa-1700-0000-4670-56aec00c0000 pid=3264->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=e7e3d406-1800-0000-4670-56aee00c0000 pid=3296->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=e0e87c10-1800-0000-4670-56aef60c0000 pid=3318->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=9c2b8719-1800-0000-4670-56ae0d0d0000 pid=3341->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=95631922-1800-0000-4670-56ae160d0000 pid=3350->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384 /usr/bin/curl dns net send-data guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3371->guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384 clone guuid=ae061f2d-1800-0000-4670-56ae2b0d0000 pid=3384->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423 /usr/bin/curl dns net send-data guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3410->guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423 clone guuid=d5450b3f-1800-0000-4670-56ae520d0000 pid=3423->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459 /usr/bin/curl dns net send-data guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3445->guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459 clone guuid=571e3c4d-1800-0000-4670-56ae750d0000 pid=3459->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490 /usr/bin/curl dns net send-data guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3483->guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490 clone guuid=ac88945a-1800-0000-4670-56ae9b0d0000 pid=3490->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525 /usr/bin/curl dns net send-data guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3517->guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525 clone guuid=63449f63-1800-0000-4670-56aebd0d0000 pid=3525->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 8c845f28-3b01-599d-863e-2a81a3ac53cf 6yd.ru:21 guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 94022332-c464-5ce3-99e3-f0080714c713 6yd.ru:37453 guuid=301f0e6d-1800-0000-4670-56aed60d0000 pid=3542->94022332-c464-5ce3-99e3-f0080714c713 con guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 73caa5fa-a45b-5e96-a01d-3c8b81723886 6yd.ru:42017 guuid=6ac76d7d-1800-0000-4670-56aef50d0000 pid=3573->73caa5fa-a45b-5e96-a01d-3c8b81723886 con guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 6ee76812-18cd-58e5-a8cd-634c683c6d6a 6yd.ru:36243 guuid=8bda3890-1800-0000-4670-56ae180e0000 pid=3608->6ee76812-18cd-58e5-a8cd-634c683c6d6a con guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 32695d35-ba7a-5ca0-937e-28b449c8df27 6yd.ru:36183 guuid=100381a2-1800-0000-4670-56ae2f0e0000 pid=3631->32695d35-ba7a-5ca0-937e-28b449c8df27 con guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B d3f382e7-57d2-5a44-bb94-c20b4065faff 6yd.ru:34545 guuid=6733aeb2-1800-0000-4670-56ae430e0000 pid=3651->d3f382e7-57d2-5a44-bb94-c20b4065faff con guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 0c3824ad-d5d2-5b86-a353-5231416ae6a5 6yd.ru:69 guuid=1d31b1c4-1800-0000-4670-56ae640e0000 pid=3684->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=c72a87cb-1b00-0000-4670-56aef7130000 pid=5111->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=dc5f11d2-1e00-0000-4670-56ae22140000 pid=5154->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=44415ed9-2100-0000-4670-56ae26140000 pid=5158->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=a1f0b4e0-2400-0000-4670-56ae2a140000 pid=5162->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 168B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-30 01:10:16 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 64c9fcad635eedde53759d816444f3bfa046b2394295cde03a7d4dc173555795

(this sample)

  
Delivery method
Distributed via web download

Comments