MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6da0119c77ab207e20ddbfafdfe08ea40980433e8f18d915f3a3e95a90aace55. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 6da0119c77ab207e20ddbfafdfe08ea40980433e8f18d915f3a3e95a90aace55
SHA3-384 hash: 8f354c3df386033cf8bc9f4a70712a184d5d047d90013c44885a880d4e00ba21f7f4cb79c039ba541985ab521632f478
SHA1 hash: ab642d2d359314ac645b53c35a4ba828beea310d
MD5 hash: 1d8b75d9fbf7f79776889982c3eb2cd1
humanhash: seven-wisconsin-pip-fanta
File name:kla.sh
Download: download sample
Signature Mirai
File size:5'155 bytes
First seen:2026-05-03 18:36:02 UTC
Last seen:2026-05-04 14:17:39 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:2RKhEcfEnsTE11CxPCx9uqQY0MWickGyE8go:2MW
TLSH T15DB1B1C812A318717DF68E67B169CA24B8C9B181DDC58F80D0EDF4F9198CF09B954AB3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.107.133/bins/px867a71a50005dfa90d36e25147c9ee7718e9f650f1af14bc08a1a71e59df3b61b2 Miraielf mirai ua-wget
http://196.251.107.133/bins/pmips93fd5d044909555935ed9a14e895f470efa5ac1553365937d0486e063f0839cc Miraielf mirai ua-wget
http://196.251.107.133/bins/pmpsl5f320c2c06b5cf0d494f311cdf118e294868d0181560104c02d6f05eef1e9e3b Miraielf mirai ua-wget
http://196.251.107.133/bins/parm064fc04504e868ec0f453d426b77a25fdeaeda9abb9dc72ec5dcede19bdf157f Miraielf mirai ua-wget
http://196.251.107.133/bins/parm516aca11323d8bb11a76352e9385a808925492c0e06d4fa9b240f4a130e1e85c3 Miraielf mirai ua-wget
http://196.251.107.133/bins/parm6bc0cb910005577e7c03e54c3330eb941224c795b4cbd9b1ae7efa9fc1c721893 Miraielf mirai ua-wget
http://196.251.107.133/bins/parm78ce0d00d3e6f03a3d44a605a331ada378787c2518e41945695494d0c84aa19ec Miraielf mirai ua-wget
http://196.251.107.133/bins/pm68kaa640ee976ff58f087abcd029c2ca2db1c6a4c56220a093b54f1362460fad53f Miraielf mirai ua-wget
http://196.251.107.133/bins/psh4303bf1629f8a98593d5b774c3e42e86ae2c68aa981066c4995fbb2870c004dd0 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-03T15:40:00Z UTC
Last seen:
2026-05-05T02:00:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=3975a5bc-1900-0000-aa99-454a500b0000 pid=2896 /usr/bin/sudo guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901 /tmp/sample.bin guuid=3975a5bc-1900-0000-aa99-454a500b0000 pid=2896->guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901 execve guuid=648922bf-1900-0000-aa99-454a570b0000 pid=2903 /usr/bin/cp guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=648922bf-1900-0000-aa99-454a570b0000 pid=2903 execve guuid=bc4209c6-1900-0000-aa99-454a660b0000 pid=2918 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=bc4209c6-1900-0000-aa99-454a660b0000 pid=2918 execve guuid=c86a57cb-1900-0000-aa99-454a670b0000 pid=2919 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c86a57cb-1900-0000-aa99-454a670b0000 pid=2919 execve guuid=c73b61d9-1900-0000-aa99-454a7d0b0000 pid=2941 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c73b61d9-1900-0000-aa99-454a7d0b0000 pid=2941 execve guuid=219f29da-1900-0000-aa99-454a7f0b0000 pid=2943 /tmp/robben delete-file net guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=219f29da-1900-0000-aa99-454a7f0b0000 pid=2943 execve guuid=517381e5-1900-0000-aa99-454a8b0b0000 pid=2955 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=517381e5-1900-0000-aa99-454a8b0b0000 pid=2955 execve guuid=ebb641ea-1900-0000-aa99-454a950b0000 pid=2965 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=ebb641ea-1900-0000-aa99-454a950b0000 pid=2965 execve guuid=6ed400f2-1900-0000-aa99-454aa90b0000 pid=2985 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=6ed400f2-1900-0000-aa99-454aa90b0000 pid=2985 execve guuid=e7d418f3-1900-0000-aa99-454aae0b0000 pid=2990 /tmp/robben delete-file net guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=e7d418f3-1900-0000-aa99-454aae0b0000 pid=2990 execve guuid=4af1291e-1b00-0000-aa99-454ac20d0000 pid=3522 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=4af1291e-1b00-0000-aa99-454ac20d0000 pid=3522 execve guuid=808e5c38-1b00-0000-aa99-454aed0d0000 pid=3565 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=808e5c38-1b00-0000-aa99-454aed0d0000 pid=3565 execve guuid=654bec3d-1b00-0000-aa99-454af70d0000 pid=3575 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=654bec3d-1b00-0000-aa99-454af70d0000 pid=3575 execve guuid=90cd373e-1b00-0000-aa99-454af90d0000 pid=3577 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=90cd373e-1b00-0000-aa99-454af90d0000 pid=3577 clone guuid=86dfdb3e-1b00-0000-aa99-454afc0d0000 pid=3580 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=86dfdb3e-1b00-0000-aa99-454afc0d0000 pid=3580 execve guuid=302a7e42-1b00-0000-aa99-454a050e0000 pid=3589 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=302a7e42-1b00-0000-aa99-454a050e0000 pid=3589 execve guuid=20abd04c-1b00-0000-aa99-454a210e0000 pid=3617 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=20abd04c-1b00-0000-aa99-454a210e0000 pid=3617 execve guuid=f0e82b4d-1b00-0000-aa99-454a230e0000 pid=3619 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=f0e82b4d-1b00-0000-aa99-454a230e0000 pid=3619 clone guuid=1029ee4d-1b00-0000-aa99-454a250e0000 pid=3621 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=1029ee4d-1b00-0000-aa99-454a250e0000 pid=3621 execve guuid=975de455-1b00-0000-aa99-454a3d0e0000 pid=3645 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=975de455-1b00-0000-aa99-454a3d0e0000 pid=3645 execve guuid=648b1d5a-1b00-0000-aa99-454a4c0e0000 pid=3660 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=648b1d5a-1b00-0000-aa99-454a4c0e0000 pid=3660 execve guuid=ea7b855a-1b00-0000-aa99-454a4d0e0000 pid=3661 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=ea7b855a-1b00-0000-aa99-454a4d0e0000 pid=3661 clone guuid=c87d565b-1b00-0000-aa99-454a4f0e0000 pid=3663 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c87d565b-1b00-0000-aa99-454a4f0e0000 pid=3663 execve guuid=4fbabd5e-1b00-0000-aa99-454a610e0000 pid=3681 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=4fbabd5e-1b00-0000-aa99-454a610e0000 pid=3681 execve guuid=847d1c63-1b00-0000-aa99-454a6b0e0000 pid=3691 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=847d1c63-1b00-0000-aa99-454a6b0e0000 pid=3691 execve guuid=29ba7d63-1b00-0000-aa99-454a6c0e0000 pid=3692 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=29ba7d63-1b00-0000-aa99-454a6c0e0000 pid=3692 clone guuid=8d14af64-1b00-0000-aa99-454a6e0e0000 pid=3694 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=8d14af64-1b00-0000-aa99-454a6e0e0000 pid=3694 execve guuid=f0025968-1b00-0000-aa99-454a6f0e0000 pid=3695 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=f0025968-1b00-0000-aa99-454a6f0e0000 pid=3695 execve guuid=23794e73-1b00-0000-aa99-454a7f0e0000 pid=3711 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=23794e73-1b00-0000-aa99-454a7f0e0000 pid=3711 execve guuid=d0589173-1b00-0000-aa99-454a800e0000 pid=3712 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d0589173-1b00-0000-aa99-454a800e0000 pid=3712 clone guuid=b2e42674-1b00-0000-aa99-454a850e0000 pid=3717 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=b2e42674-1b00-0000-aa99-454a850e0000 pid=3717 execve guuid=48018f7c-1b00-0000-aa99-454aa20e0000 pid=3746 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=48018f7c-1b00-0000-aa99-454aa20e0000 pid=3746 execve guuid=da0aba81-1b00-0000-aa99-454abd0e0000 pid=3773 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=da0aba81-1b00-0000-aa99-454abd0e0000 pid=3773 execve guuid=4655ff81-1b00-0000-aa99-454abf0e0000 pid=3775 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=4655ff81-1b00-0000-aa99-454abf0e0000 pid=3775 clone guuid=4d6d9f82-1b00-0000-aa99-454ac40e0000 pid=3780 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=4d6d9f82-1b00-0000-aa99-454ac40e0000 pid=3780 execve guuid=c5a75785-1b00-0000-aa99-454ad00e0000 pid=3792 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c5a75785-1b00-0000-aa99-454ad00e0000 pid=3792 execve guuid=55e9fc8d-1b00-0000-aa99-454ae90e0000 pid=3817 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=55e9fc8d-1b00-0000-aa99-454ae90e0000 pid=3817 execve guuid=d7f9508e-1b00-0000-aa99-454aeb0e0000 pid=3819 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d7f9508e-1b00-0000-aa99-454aeb0e0000 pid=3819 clone guuid=7a46f38e-1b00-0000-aa99-454aed0e0000 pid=3821 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=7a46f38e-1b00-0000-aa99-454aed0e0000 pid=3821 execve guuid=9a908bb0-1b00-0000-aa99-454af20e0000 pid=3826 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=9a908bb0-1b00-0000-aa99-454af20e0000 pid=3826 execve guuid=da16a9df-1b00-0000-aa99-454af50e0000 pid=3829 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=da16a9df-1b00-0000-aa99-454af50e0000 pid=3829 execve guuid=7bfc19e0-1b00-0000-aa99-454af60e0000 pid=3830 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=7bfc19e0-1b00-0000-aa99-454af60e0000 pid=3830 clone guuid=86611ae1-1b00-0000-aa99-454af80e0000 pid=3832 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=86611ae1-1b00-0000-aa99-454af80e0000 pid=3832 execve guuid=c2f024ed-1b00-0000-aa99-454a210f0000 pid=3873 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c2f024ed-1b00-0000-aa99-454a210f0000 pid=3873 execve guuid=1cf2b0f6-1b00-0000-aa99-454a390f0000 pid=3897 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=1cf2b0f6-1b00-0000-aa99-454a390f0000 pid=3897 execve guuid=c0ccf1f6-1b00-0000-aa99-454a3b0f0000 pid=3899 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=c0ccf1f6-1b00-0000-aa99-454a3b0f0000 pid=3899 clone guuid=50cb80f7-1b00-0000-aa99-454a3f0f0000 pid=3903 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=50cb80f7-1b00-0000-aa99-454a3f0f0000 pid=3903 execve guuid=d82c26ff-1b00-0000-aa99-454a5a0f0000 pid=3930 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d82c26ff-1b00-0000-aa99-454a5a0f0000 pid=3930 execve guuid=95d2c503-1c00-0000-aa99-454a750f0000 pid=3957 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=95d2c503-1c00-0000-aa99-454a750f0000 pid=3957 execve guuid=ceac0404-1c00-0000-aa99-454a770f0000 pid=3959 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=ceac0404-1c00-0000-aa99-454a770f0000 pid=3959 clone guuid=e8af9e04-1c00-0000-aa99-454a7b0f0000 pid=3963 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=e8af9e04-1c00-0000-aa99-454a7b0f0000 pid=3963 execve guuid=d3ec870c-1c00-0000-aa99-454a9e0f0000 pid=3998 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d3ec870c-1c00-0000-aa99-454a9e0f0000 pid=3998 execve guuid=d7e6a011-1c00-0000-aa99-454ab60f0000 pid=4022 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d7e6a011-1c00-0000-aa99-454ab60f0000 pid=4022 execve guuid=41151412-1c00-0000-aa99-454aba0f0000 pid=4026 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=41151412-1c00-0000-aa99-454aba0f0000 pid=4026 clone guuid=9447cf12-1c00-0000-aa99-454abf0f0000 pid=4031 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=9447cf12-1c00-0000-aa99-454abf0f0000 pid=4031 execve guuid=65469316-1c00-0000-aa99-454ad00f0000 pid=4048 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=65469316-1c00-0000-aa99-454ad00f0000 pid=4048 execve guuid=2f65d11a-1c00-0000-aa99-454ae20f0000 pid=4066 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=2f65d11a-1c00-0000-aa99-454ae20f0000 pid=4066 execve guuid=5b7a371b-1c00-0000-aa99-454ae40f0000 pid=4068 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=5b7a371b-1c00-0000-aa99-454ae40f0000 pid=4068 clone guuid=1659ff1b-1c00-0000-aa99-454ae80f0000 pid=4072 /usr/bin/wget net send-data guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=1659ff1b-1c00-0000-aa99-454ae80f0000 pid=4072 execve guuid=60bc261e-1c00-0000-aa99-454af10f0000 pid=4081 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=60bc261e-1c00-0000-aa99-454af10f0000 pid=4081 execve guuid=cbff6023-1c00-0000-aa99-454a08100000 pid=4104 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=cbff6023-1c00-0000-aa99-454a08100000 pid=4104 execve guuid=5852b123-1c00-0000-aa99-454a0c100000 pid=4108 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=5852b123-1c00-0000-aa99-454a0c100000 pid=4108 clone guuid=79376d27-1c00-0000-aa99-454a17100000 pid=4119 /usr/bin/wget net send-data guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=79376d27-1c00-0000-aa99-454a17100000 pid=4119 execve guuid=bbee8629-1c00-0000-aa99-454a20100000 pid=4128 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=bbee8629-1c00-0000-aa99-454a20100000 pid=4128 execve guuid=b365ad2e-1c00-0000-aa99-454a35100000 pid=4149 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=b365ad2e-1c00-0000-aa99-454a35100000 pid=4149 execve guuid=998c022f-1c00-0000-aa99-454a37100000 pid=4151 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=998c022f-1c00-0000-aa99-454a37100000 pid=4151 clone guuid=0edd222f-1c00-0000-aa99-454a39100000 pid=4153 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=0edd222f-1c00-0000-aa99-454a39100000 pid=4153 execve guuid=a8457d38-1c00-0000-aa99-454a5b100000 pid=4187 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=a8457d38-1c00-0000-aa99-454a5b100000 pid=4187 execve guuid=d3cf2d43-1c00-0000-aa99-454a85100000 pid=4229 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=d3cf2d43-1c00-0000-aa99-454a85100000 pid=4229 execve guuid=ae217643-1c00-0000-aa99-454a86100000 pid=4230 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=ae217643-1c00-0000-aa99-454a86100000 pid=4230 clone guuid=3b2e4344-1c00-0000-aa99-454a8c100000 pid=4236 /usr/bin/wget net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=3b2e4344-1c00-0000-aa99-454a8c100000 pid=4236 execve guuid=fd515c48-1c00-0000-aa99-454a99100000 pid=4249 /usr/bin/curl net send-data write-file guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=fd515c48-1c00-0000-aa99-454a99100000 pid=4249 execve guuid=e37e8d54-1c00-0000-aa99-454ac6100000 pid=4294 /usr/bin/chmod guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=e37e8d54-1c00-0000-aa99-454ac6100000 pid=4294 execve guuid=fd3de054-1c00-0000-aa99-454ac7100000 pid=4295 /usr/bin/bash guuid=baf6a4be-1900-0000-aa99-454a550b0000 pid=2901->guuid=fd3de054-1c00-0000-aa99-454ac7100000 pid=4295 clone a440794d-b90c-5e2c-a2ca-7c3cac666c21 196.251.107.133:80 guuid=bc4209c6-1900-0000-aa99-454a660b0000 pid=2918->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=c86a57cb-1900-0000-aa99-454a670b0000 pid=2919->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=219f29da-1900-0000-aa99-454a7f0b0000 pid=2943->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952 /tmp/robben net send-data zombie guuid=219f29da-1900-0000-aa99-454a7f0b0000 pid=2943->guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952 clone guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con bafb902f-2fbe-592f-8080-d95cd4976752 196.251.107.133:18129 guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952->bafb902f-2fbe-592f-8080-d95cd4976752 send: 11B guuid=8a4754e5-1900-0000-aa99-454a890b0000 pid=2953 /tmp/robben guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952->guuid=8a4754e5-1900-0000-aa99-454a890b0000 pid=2953 clone guuid=57c859e5-1900-0000-aa99-454a8a0b0000 pid=2954 /tmp/robben guuid=7eff34e5-1900-0000-aa99-454a880b0000 pid=2952->guuid=57c859e5-1900-0000-aa99-454a8a0b0000 pid=2954 clone guuid=517381e5-1900-0000-aa99-454a8b0b0000 pid=2955->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=ebb641ea-1900-0000-aa99-454a950b0000 pid=2965->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B guuid=e7d418f3-1900-0000-aa99-454aae0b0000 pid=2990->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0637bfa0-18a1-551d-95eb-ed76e272eef1 0.0.0.0:18129 guuid=e7d418f3-1900-0000-aa99-454aae0b0000 pid=2990->0637bfa0-18a1-551d-95eb-ed76e272eef1 con guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519 /tmp/robben net send-data zombie guuid=e7d418f3-1900-0000-aa99-454aae0b0000 pid=2990->guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519 clone guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519->bafb902f-2fbe-592f-8080-d95cd4976752 send: 13B guuid=bc68251e-1b00-0000-aa99-454ac00d0000 pid=3520 /tmp/robben guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519->guuid=bc68251e-1b00-0000-aa99-454ac00d0000 pid=3520 clone guuid=53c0291e-1b00-0000-aa99-454ac10d0000 pid=3521 /tmp/robben guuid=e0fe111e-1b00-0000-aa99-454abf0d0000 pid=3519->guuid=53c0291e-1b00-0000-aa99-454ac10d0000 pid=3521 clone guuid=4af1291e-1b00-0000-aa99-454ac20d0000 pid=3522->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=808e5c38-1b00-0000-aa99-454aed0d0000 pid=3565->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=86dfdb3e-1b00-0000-aa99-454afc0d0000 pid=3580->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=302a7e42-1b00-0000-aa99-454a050e0000 pid=3589->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=1029ee4d-1b00-0000-aa99-454a250e0000 pid=3621->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=975de455-1b00-0000-aa99-454a3d0e0000 pid=3645->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=c87d565b-1b00-0000-aa99-454a4f0e0000 pid=3663->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=4fbabd5e-1b00-0000-aa99-454a610e0000 pid=3681->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=8d14af64-1b00-0000-aa99-454a6e0e0000 pid=3694->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=f0025968-1b00-0000-aa99-454a6f0e0000 pid=3695->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B guuid=b2e42674-1b00-0000-aa99-454a850e0000 pid=3717->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=48018f7c-1b00-0000-aa99-454aa20e0000 pid=3746->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B guuid=4d6d9f82-1b00-0000-aa99-454ac40e0000 pid=3780->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=c5a75785-1b00-0000-aa99-454ad00e0000 pid=3792->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=7a46f38e-1b00-0000-aa99-454aed0e0000 pid=3821->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=9a908bb0-1b00-0000-aa99-454af20e0000 pid=3826->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=86611ae1-1b00-0000-aa99-454af80e0000 pid=3832->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=c2f024ed-1b00-0000-aa99-454a210f0000 pid=3873->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=50cb80f7-1b00-0000-aa99-454a3f0f0000 pid=3903->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=d82c26ff-1b00-0000-aa99-454a5a0f0000 pid=3930->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=e8af9e04-1c00-0000-aa99-454a7b0f0000 pid=3963->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=d3ec870c-1c00-0000-aa99-454a9e0f0000 pid=3998->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=9447cf12-1c00-0000-aa99-454abf0f0000 pid=4031->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=65469316-1c00-0000-aa99-454ad00f0000 pid=4048->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=1659ff1b-1c00-0000-aa99-454ae80f0000 pid=4072->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=60bc261e-1c00-0000-aa99-454af10f0000 pid=4081->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=79376d27-1c00-0000-aa99-454a17100000 pid=4119->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 140B guuid=bbee8629-1c00-0000-aa99-454a20100000 pid=4128->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 89B guuid=0edd222f-1c00-0000-aa99-454a39100000 pid=4153->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=a8457d38-1c00-0000-aa99-454a5b100000 pid=4187->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B guuid=3b2e4344-1c00-0000-aa99-454a8c100000 pid=4236->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 139B guuid=fd515c48-1c00-0000-aa99-454a99100000 pid=4249->a440794d-b90c-5e2c-a2ca-7c3cac666c21 send: 88B
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2026-05-03 18:36:38 UTC
File Type:
Text (Shell)
AV detection:
7 of 24 (29.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6da0119c77ab207e20ddbfafdfe08ea40980433e8f18d915f3a3e95a90aace55

(this sample)

  
Delivery method
Distributed via web download

Comments