MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 652285d260515c08cfe146ebdd2f5a4977ec490a608c57007abcb5b6f4fd4975. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 652285d260515c08cfe146ebdd2f5a4977ec490a608c57007abcb5b6f4fd4975
SHA3-384 hash: f0680a61ccc4280fbd8b7f657ec3074b5f1d7fc9d457fc31e50617b786c2b9e9210fe36c85c3d29ed4e2bca23e0e7ecd
SHA1 hash: de7096f04340ac22c2dcfd08237c5d00e687840f
MD5 hash: b8264a3c5d5897320cf7549c149e0052
humanhash: lake-illinois-india-virginia
File name:bins.sh
Download: download sample
Signature Mirai
File size:909 bytes
First seen:2025-11-07 13:08:09 UTC
Last seen:2025-11-08 05:08:49 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:XbI/syYzZ3OhXvuS9dLa+Jdz7+y5yswTm6:XbI/J430vu4usdzzoJB
TLSH T1B1117C906C951587A8DBFE1CB12A53F231512C74E5A0127DC2B7EE16C87EE32B90E771
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-07T10:17:00Z UTC
Last seen:
2025-11-08T04:37:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Mirai.a
Status:
terminated
Behavior Graph:
%3 guuid=7056f0c0-1600-0000-dadc-6b43940c0000 pid=3220 /usr/bin/sudo guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223 /tmp/sample.bin guuid=7056f0c0-1600-0000-dadc-6b43940c0000 pid=3220->guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223 execve guuid=c1b2d1c3-1600-0000-dadc-6b43980c0000 pid=3224 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=c1b2d1c3-1600-0000-dadc-6b43980c0000 pid=3224 execve guuid=c8a617da-1600-0000-dadc-6b43ad0c0000 pid=3245 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=c8a617da-1600-0000-dadc-6b43ad0c0000 pid=3245 execve guuid=9755a0da-1600-0000-dadc-6b43af0c0000 pid=3247 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=9755a0da-1600-0000-dadc-6b43af0c0000 pid=3247 clone guuid=93782adc-1600-0000-dadc-6b43b50c0000 pid=3253 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=93782adc-1600-0000-dadc-6b43b50c0000 pid=3253 execve guuid=578c9ef8-1600-0000-dadc-6b43ea0c0000 pid=3306 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=578c9ef8-1600-0000-dadc-6b43ea0c0000 pid=3306 execve guuid=8a5006f9-1600-0000-dadc-6b43ec0c0000 pid=3308 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=8a5006f9-1600-0000-dadc-6b43ec0c0000 pid=3308 clone guuid=9c2ae5f9-1600-0000-dadc-6b43ef0c0000 pid=3311 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=9c2ae5f9-1600-0000-dadc-6b43ef0c0000 pid=3311 execve guuid=25ea5e0c-1700-0000-dadc-6b43040d0000 pid=3332 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=25ea5e0c-1700-0000-dadc-6b43040d0000 pid=3332 execve guuid=0ac2a70c-1700-0000-dadc-6b43060d0000 pid=3334 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=0ac2a70c-1700-0000-dadc-6b43060d0000 pid=3334 clone guuid=c0935b0e-1700-0000-dadc-6b43090d0000 pid=3337 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=c0935b0e-1700-0000-dadc-6b43090d0000 pid=3337 execve guuid=67378820-1700-0000-dadc-6b43290d0000 pid=3369 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=67378820-1700-0000-dadc-6b43290d0000 pid=3369 execve guuid=9ba41c21-1700-0000-dadc-6b432c0d0000 pid=3372 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=9ba41c21-1700-0000-dadc-6b432c0d0000 pid=3372 clone guuid=6d3ae121-1700-0000-dadc-6b432f0d0000 pid=3375 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=6d3ae121-1700-0000-dadc-6b432f0d0000 pid=3375 execve guuid=5214c336-1700-0000-dadc-6b435b0d0000 pid=3419 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=5214c336-1700-0000-dadc-6b435b0d0000 pid=3419 execve guuid=2f121637-1700-0000-dadc-6b435d0d0000 pid=3421 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=2f121637-1700-0000-dadc-6b435d0d0000 pid=3421 clone guuid=10adbf37-1700-0000-dadc-6b43600d0000 pid=3424 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=10adbf37-1700-0000-dadc-6b43600d0000 pid=3424 execve guuid=ec5f9748-1700-0000-dadc-6b43850d0000 pid=3461 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=ec5f9748-1700-0000-dadc-6b43850d0000 pid=3461 execve guuid=eea31e49-1700-0000-dadc-6b43870d0000 pid=3463 /home/sandbox/dvrHelper delete-file net guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=eea31e49-1700-0000-dadc-6b43870d0000 pid=3463 execve guuid=b3a77b49-1700-0000-dadc-6b438a0d0000 pid=3466 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=b3a77b49-1700-0000-dadc-6b438a0d0000 pid=3466 execve guuid=ea48455b-1700-0000-dadc-6b43bd0d0000 pid=3517 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=ea48455b-1700-0000-dadc-6b43bd0d0000 pid=3517 execve guuid=3dc1985b-1700-0000-dadc-6b43be0d0000 pid=3518 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=3dc1985b-1700-0000-dadc-6b43be0d0000 pid=3518 clone guuid=a6575b5c-1700-0000-dadc-6b43c10d0000 pid=3521 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=a6575b5c-1700-0000-dadc-6b43c10d0000 pid=3521 execve guuid=8256d380-1700-0000-dadc-6b43090e0000 pid=3593 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=8256d380-1700-0000-dadc-6b43090e0000 pid=3593 execve guuid=b7135281-1700-0000-dadc-6b430b0e0000 pid=3595 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=b7135281-1700-0000-dadc-6b430b0e0000 pid=3595 clone guuid=f9e54282-1700-0000-dadc-6b430f0e0000 pid=3599 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=f9e54282-1700-0000-dadc-6b430f0e0000 pid=3599 execve guuid=e80f7093-1700-0000-dadc-6b43310e0000 pid=3633 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=e80f7093-1700-0000-dadc-6b43310e0000 pid=3633 execve guuid=d87ead93-1700-0000-dadc-6b43330e0000 pid=3635 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=d87ead93-1700-0000-dadc-6b43330e0000 pid=3635 clone guuid=0f002e94-1700-0000-dadc-6b43370e0000 pid=3639 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=0f002e94-1700-0000-dadc-6b43370e0000 pid=3639 execve guuid=3425dca4-1700-0000-dadc-6b437b0e0000 pid=3707 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=3425dca4-1700-0000-dadc-6b437b0e0000 pid=3707 execve guuid=aaac23a5-1700-0000-dadc-6b437d0e0000 pid=3709 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=aaac23a5-1700-0000-dadc-6b437d0e0000 pid=3709 clone guuid=99b2ada5-1700-0000-dadc-6b43810e0000 pid=3713 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=99b2ada5-1700-0000-dadc-6b43810e0000 pid=3713 execve guuid=f8cbadbb-1700-0000-dadc-6b43c50e0000 pid=3781 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=f8cbadbb-1700-0000-dadc-6b43c50e0000 pid=3781 execve guuid=dd0625bc-1700-0000-dadc-6b43c70e0000 pid=3783 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=dd0625bc-1700-0000-dadc-6b43c70e0000 pid=3783 clone guuid=ee731fbd-1700-0000-dadc-6b43cb0e0000 pid=3787 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=ee731fbd-1700-0000-dadc-6b43cb0e0000 pid=3787 execve guuid=532869ce-1700-0000-dadc-6b43fb0e0000 pid=3835 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=532869ce-1700-0000-dadc-6b43fb0e0000 pid=3835 execve guuid=af50dece-1700-0000-dadc-6b43fe0e0000 pid=3838 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=af50dece-1700-0000-dadc-6b43fe0e0000 pid=3838 clone guuid=6c84abcf-1700-0000-dadc-6b43030f0000 pid=3843 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=6c84abcf-1700-0000-dadc-6b43030f0000 pid=3843 execve guuid=34116ce1-1700-0000-dadc-6b43300f0000 pid=3888 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=34116ce1-1700-0000-dadc-6b43300f0000 pid=3888 execve guuid=581df5e1-1700-0000-dadc-6b43320f0000 pid=3890 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=581df5e1-1700-0000-dadc-6b43320f0000 pid=3890 clone guuid=42c141e3-1700-0000-dadc-6b433a0f0000 pid=3898 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=42c141e3-1700-0000-dadc-6b433a0f0000 pid=3898 execve guuid=a8325b00-1800-0000-dadc-6b437a0f0000 pid=3962 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=a8325b00-1800-0000-dadc-6b437a0f0000 pid=3962 execve guuid=4488a400-1800-0000-dadc-6b437d0f0000 pid=3965 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=4488a400-1800-0000-dadc-6b437d0f0000 pid=3965 clone guuid=075f4501-1800-0000-dadc-6b43820f0000 pid=3970 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=075f4501-1800-0000-dadc-6b43820f0000 pid=3970 execve guuid=bed60415-1800-0000-dadc-6b43b50f0000 pid=4021 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=bed60415-1800-0000-dadc-6b43b50f0000 pid=4021 execve guuid=25737915-1800-0000-dadc-6b43b70f0000 pid=4023 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=25737915-1800-0000-dadc-6b43b70f0000 pid=4023 clone guuid=9cdee817-1800-0000-dadc-6b43bd0f0000 pid=4029 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=9cdee817-1800-0000-dadc-6b43bd0f0000 pid=4029 execve guuid=e6b62929-1800-0000-dadc-6b43ec0f0000 pid=4076 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=e6b62929-1800-0000-dadc-6b43ec0f0000 pid=4076 execve guuid=50cc8329-1800-0000-dadc-6b43ed0f0000 pid=4077 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=50cc8329-1800-0000-dadc-6b43ed0f0000 pid=4077 clone guuid=92bc452a-1800-0000-dadc-6b43f10f0000 pid=4081 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=92bc452a-1800-0000-dadc-6b43f10f0000 pid=4081 execve guuid=b33dd15f-1800-0000-dadc-6b436a100000 pid=4202 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=b33dd15f-1800-0000-dadc-6b436a100000 pid=4202 execve guuid=831d7960-1800-0000-dadc-6b436d100000 pid=4205 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=831d7960-1800-0000-dadc-6b436d100000 pid=4205 clone guuid=cc7d1f63-1800-0000-dadc-6b4373100000 pid=4211 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=cc7d1f63-1800-0000-dadc-6b4373100000 pid=4211 execve guuid=a0295774-1800-0000-dadc-6b439c100000 pid=4252 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=a0295774-1800-0000-dadc-6b439c100000 pid=4252 execve guuid=de2cb574-1800-0000-dadc-6b439f100000 pid=4255 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=de2cb574-1800-0000-dadc-6b439f100000 pid=4255 clone guuid=9f938875-1800-0000-dadc-6b43a2100000 pid=4258 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=9f938875-1800-0000-dadc-6b43a2100000 pid=4258 execve guuid=e3dd6b88-1800-0000-dadc-6b43de100000 pid=4318 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=e3dd6b88-1800-0000-dadc-6b43de100000 pid=4318 execve guuid=3b81d088-1800-0000-dadc-6b43e2100000 pid=4322 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=3b81d088-1800-0000-dadc-6b43e2100000 pid=4322 clone guuid=d4a27d89-1800-0000-dadc-6b43e7100000 pid=4327 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=d4a27d89-1800-0000-dadc-6b43e7100000 pid=4327 execve guuid=02255e9a-1800-0000-dadc-6b4311110000 pid=4369 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=02255e9a-1800-0000-dadc-6b4311110000 pid=4369 execve guuid=0417a79a-1800-0000-dadc-6b4312110000 pid=4370 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=0417a79a-1800-0000-dadc-6b4312110000 pid=4370 clone guuid=4c0c8e9b-1800-0000-dadc-6b4317110000 pid=4375 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=4c0c8e9b-1800-0000-dadc-6b4317110000 pid=4375 execve guuid=08c3f2ad-1800-0000-dadc-6b4343110000 pid=4419 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=08c3f2ad-1800-0000-dadc-6b4343110000 pid=4419 execve guuid=d23173ae-1800-0000-dadc-6b4345110000 pid=4421 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=d23173ae-1800-0000-dadc-6b4345110000 pid=4421 clone guuid=400c86af-1800-0000-dadc-6b4348110000 pid=4424 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=400c86af-1800-0000-dadc-6b4348110000 pid=4424 execve guuid=ca1f89c2-1800-0000-dadc-6b437b110000 pid=4475 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=ca1f89c2-1800-0000-dadc-6b437b110000 pid=4475 execve guuid=3dc8f0c2-1800-0000-dadc-6b437d110000 pid=4477 /usr/bin/dash guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=3dc8f0c2-1800-0000-dadc-6b437d110000 pid=4477 clone guuid=d87089c3-1800-0000-dadc-6b4382110000 pid=4482 /usr/bin/wget net send-data write-file guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=d87089c3-1800-0000-dadc-6b4382110000 pid=4482 execve guuid=7aaf92d8-1800-0000-dadc-6b43c0110000 pid=4544 /usr/bin/chmod guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=7aaf92d8-1800-0000-dadc-6b43c0110000 pid=4544 execve guuid=c13c01d9-1800-0000-dadc-6b43c2110000 pid=4546 /home/sandbox/dvrHelper delete-file net guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=c13c01d9-1800-0000-dadc-6b43c2110000 pid=4546 execve guuid=daea0012-1a00-0000-dadc-6b43b3140000 pid=5299 /usr/bin/rm guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=daea0012-1a00-0000-dadc-6b43b3140000 pid=5299 execve guuid=03703512-1a00-0000-dadc-6b43b5140000 pid=5301 /usr/bin/rm guuid=c20f39c3-1600-0000-dadc-6b43970c0000 pid=3223->guuid=03703512-1a00-0000-dadc-6b43b5140000 pid=5301 execve 9137f642-db3c-55f2-bad9-be08b04aa621 5.178.101.166:80 guuid=c1b2d1c3-1600-0000-dadc-6b43980c0000 pid=3224->9137f642-db3c-55f2-bad9-be08b04aa621 send: 144B guuid=93782adc-1600-0000-dadc-6b43b50c0000 pid=3253->9137f642-db3c-55f2-bad9-be08b04aa621 send: 145B guuid=9c2ae5f9-1600-0000-dadc-6b43ef0c0000 pid=3311->9137f642-db3c-55f2-bad9-be08b04aa621 send: 143B guuid=c0935b0e-1700-0000-dadc-6b43090d0000 pid=3337->9137f642-db3c-55f2-bad9-be08b04aa621 send: 143B guuid=6d3ae121-1700-0000-dadc-6b432f0d0000 pid=3375->9137f642-db3c-55f2-bad9-be08b04aa621 send: 142B guuid=10adbf37-1700-0000-dadc-6b43600d0000 pid=3424->9137f642-db3c-55f2-bad9-be08b04aa621 send: 142B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=eea31e49-1700-0000-dadc-6b43870d0000 pid=3463->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465 /home/sandbox/dvrHelper dns net send-data zombie guuid=eea31e49-1700-0000-dadc-6b43870d0000 pid=3463->guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465 clone guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 hxipzknrsojnitzv.zip:23 guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 send: 5B guuid=e2d18449-1700-0000-dadc-6b438b0d0000 pid=3467 /home/sandbox/dvrHelper guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465->guuid=e2d18449-1700-0000-dadc-6b438b0d0000 pid=3467 clone guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468 /home/sandbox/dvrHelper net net-scan send-data guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465->guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468 clone guuid=464a51d9-1800-0000-dadc-6b43c4110000 pid=4548 /home/sandbox/dvrHelper guuid=f0316b49-1700-0000-dadc-6b43890d0000 pid=3465->guuid=464a51d9-1800-0000-dadc-6b43c4110000 pid=4548 clone 91ace30b-3d9f-522c-9672-99f62740d927 hxipzknrsojnitzv.zip:80 guuid=b3a77b49-1700-0000-dadc-6b438a0d0000 pid=3466->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468|send-data send-data to 1120 IP addresses review logs to see them all guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468->guuid=96458d49-1700-0000-dadc-6b438c0d0000 pid=3468|send-data send guuid=a6575b5c-1700-0000-dadc-6b43c10d0000 pid=3521->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=f9e54282-1700-0000-dadc-6b430f0e0000 pid=3599->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=0f002e94-1700-0000-dadc-6b43370e0000 pid=3639->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=99b2ada5-1700-0000-dadc-6b43810e0000 pid=3713->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=ee731fbd-1700-0000-dadc-6b43cb0e0000 pid=3787->91ace30b-3d9f-522c-9672-99f62740d927 send: 142B guuid=6c84abcf-1700-0000-dadc-6b43030f0000 pid=3843->91ace30b-3d9f-522c-9672-99f62740d927 send: 143B guuid=42c141e3-1700-0000-dadc-6b433a0f0000 pid=3898->91ace30b-3d9f-522c-9672-99f62740d927 send: 148B guuid=075f4501-1800-0000-dadc-6b43820f0000 pid=3970->91ace30b-3d9f-522c-9672-99f62740d927 send: 143B guuid=9cdee817-1800-0000-dadc-6b43bd0f0000 pid=4029->91ace30b-3d9f-522c-9672-99f62740d927 send: 142B guuid=92bc452a-1800-0000-dadc-6b43f10f0000 pid=4081->91ace30b-3d9f-522c-9672-99f62740d927 send: 142B guuid=cc7d1f63-1800-0000-dadc-6b4373100000 pid=4211->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=9f938875-1800-0000-dadc-6b43a2100000 pid=4258->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=d4a27d89-1800-0000-dadc-6b43e7100000 pid=4327->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=4c0c8e9b-1800-0000-dadc-6b4317110000 pid=4375->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=400c86af-1800-0000-dadc-6b4348110000 pid=4424->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=d87089c3-1800-0000-dadc-6b4382110000 pid=4482->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=c13c01d9-1800-0000-dadc-6b43c2110000 pid=4546->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ff25191-b423-5251-a735-2378c22ab12a 0.0.0.0:48101 guuid=c13c01d9-1800-0000-dadc-6b43c2110000 pid=4546->8ff25191-b423-5251-a735-2378c22ab12a con guuid=0835f911-1a00-0000-dadc-6b43b2140000 pid=5298 /home/sandbox/dvrHelper dns net send-data zombie guuid=c13c01d9-1800-0000-dadc-6b43c2110000 pid=4546->guuid=0835f911-1a00-0000-dadc-6b43b2140000 pid=5298 clone guuid=0835f911-1a00-0000-dadc-6b43b2140000 pid=5298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=0835f911-1a00-0000-dadc-6b43b2140000 pid=5298->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 send: 7B guuid=27f70512-1a00-0000-dadc-6b43b4140000 pid=5300 /home/sandbox/dvrHelper guuid=0835f911-1a00-0000-dadc-6b43b2140000 pid=5298->guuid=27f70512-1a00-0000-dadc-6b43b4140000 pid=5300 clone
Threat name:
Linux.Browser.Downlaoder
Status:
Malicious
First seen:
2025-11-07 13:08:19 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Creates a large amount of network flows
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (1128) amount of remote hosts
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 652285d260515c08cfe146ebdd2f5a4977ec490a608c57007abcb5b6f4fd4975

(this sample)

  
Delivery method
Distributed via web download

Comments