MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 725e6681c2ee8b785825687ecf79a3ced0bf2e9ccf283ca7f5b4efa0bb45ef0a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 725e6681c2ee8b785825687ecf79a3ced0bf2e9ccf283ca7f5b4efa0bb45ef0a
SHA3-384 hash: d2266e0e84f006f70a4428cb53f5fe8bae1474c938be5534d7d69dffd888dacf7048d425ca314446c9f0d8d073d4e202
SHA1 hash: e407c651bed4881e1f4d9accf3ccdb2ab9c0ced3
MD5 hash: bb85a52d6803c673b19674b33c8f572b
humanhash: berlin-pizza-october-beryllium
File name:update.sh
Download: download sample
Signature Mirai
File size:3'656 bytes
First seen:2025-10-10 21:33:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:lD1xVSIMutWXvj2whmmmg3Bja9dfdpeKdk1gpvaBdAWdfaGlrsKsaRYlhJe3OJeD:lV58iwoOeM8+lYlhJZJKsZZg2sylu9o0
TLSH T1BB71F7C522D310FDA188CA1B7A6A4D0C920861C779D9B35CE77ACCEA235C76D33C069E
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.253.86.21/bins/keksec.mipsn/an/aelf ua-wget
http://5.253.86.21/bins/keksec.mpsln/an/aelf ua-wget
http://5.253.86.21/bins/keksec.sh4n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.x86n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.arm7n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.x64n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.ppcn/an/aelf ua-wget
http://5.253.86.21/bins/keksec.i586n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.m68kn/an/aelf ua-wget
http://5.253.86.21/bins/keksec.spcn/an/aelf ua-wget
http://5.253.86.21/bins/keksec.armn/an/aelf ua-wget
http://5.253.86.21/bins/keksec.arm5n/an/aelf ua-wget
http://5.253.86.21/bins/keksec.ppc-440fpn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-10T18:52:00Z UTC
Last seen:
2025-10-10T19:38:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f93d9fb7-1a00-0000-9244-f98d690a0000 pid=2665 /usr/bin/sudo guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675 /tmp/sample.bin guuid=f93d9fb7-1a00-0000-9244-f98d690a0000 pid=2665->guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675 execve guuid=c96c48ba-1a00-0000-9244-f98d740a0000 pid=2676 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c96c48ba-1a00-0000-9244-f98d740a0000 pid=2676 execve guuid=1321abc3-1a00-0000-9244-f98d900a0000 pid=2704 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=1321abc3-1a00-0000-9244-f98d900a0000 pid=2704 execve guuid=9477f9c3-1a00-0000-9244-f98d920a0000 pid=2706 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=9477f9c3-1a00-0000-9244-f98d920a0000 pid=2706 execve guuid=da344ac7-1a00-0000-9244-f98d9e0a0000 pid=2718 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=da344ac7-1a00-0000-9244-f98d9e0a0000 pid=2718 execve guuid=a2f66dc9-1a00-0000-9244-f98da60a0000 pid=2726 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a2f66dc9-1a00-0000-9244-f98da60a0000 pid=2726 execve guuid=c5d0f1c9-1a00-0000-9244-f98da80a0000 pid=2728 /tmp/keksec.mips guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c5d0f1c9-1a00-0000-9244-f98da80a0000 pid=2728 execve guuid=110f48cc-1a00-0000-9244-f98daf0a0000 pid=2735 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=110f48cc-1a00-0000-9244-f98daf0a0000 pid=2735 execve guuid=de9bb1cc-1a00-0000-9244-f98db10a0000 pid=2737 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=de9bb1cc-1a00-0000-9244-f98db10a0000 pid=2737 execve guuid=137b3fd3-1a00-0000-9244-f98dc10a0000 pid=2753 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=137b3fd3-1a00-0000-9244-f98dc10a0000 pid=2753 execve guuid=3db36ed3-1a00-0000-9244-f98dc20a0000 pid=2754 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=3db36ed3-1a00-0000-9244-f98dc20a0000 pid=2754 execve guuid=ddc477d6-1a00-0000-9244-f98dca0a0000 pid=2762 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=ddc477d6-1a00-0000-9244-f98dca0a0000 pid=2762 execve guuid=8a8c88d8-1a00-0000-9244-f98dd10a0000 pid=2769 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=8a8c88d8-1a00-0000-9244-f98dd10a0000 pid=2769 execve guuid=3316ccd8-1a00-0000-9244-f98dd20a0000 pid=2770 /tmp/keksec.mpsl guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=3316ccd8-1a00-0000-9244-f98dd20a0000 pid=2770 execve guuid=c06790d9-1a00-0000-9244-f98dd40a0000 pid=2772 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c06790d9-1a00-0000-9244-f98dd40a0000 pid=2772 execve guuid=d0a7e0d9-1a00-0000-9244-f98dd50a0000 pid=2773 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=d0a7e0d9-1a00-0000-9244-f98dd50a0000 pid=2773 execve guuid=625989df-1a00-0000-9244-f98ddc0a0000 pid=2780 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=625989df-1a00-0000-9244-f98ddc0a0000 pid=2780 execve guuid=68c7b3df-1a00-0000-9244-f98ddd0a0000 pid=2781 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=68c7b3df-1a00-0000-9244-f98ddd0a0000 pid=2781 execve guuid=3b88b2e2-1a00-0000-9244-f98de50a0000 pid=2789 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=3b88b2e2-1a00-0000-9244-f98de50a0000 pid=2789 execve guuid=25cfcae4-1a00-0000-9244-f98de90a0000 pid=2793 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=25cfcae4-1a00-0000-9244-f98de90a0000 pid=2793 execve guuid=ca2519e5-1a00-0000-9244-f98deb0a0000 pid=2795 /tmp/keksec.sh4 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=ca2519e5-1a00-0000-9244-f98deb0a0000 pid=2795 execve guuid=8e7be4e5-1a00-0000-9244-f98def0a0000 pid=2799 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=8e7be4e5-1a00-0000-9244-f98def0a0000 pid=2799 execve guuid=6c976ae6-1a00-0000-9244-f98df10a0000 pid=2801 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=6c976ae6-1a00-0000-9244-f98df10a0000 pid=2801 execve guuid=738135ed-1a00-0000-9244-f98d010b0000 pid=2817 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=738135ed-1a00-0000-9244-f98d010b0000 pid=2817 execve guuid=5bf75ded-1a00-0000-9244-f98d020b0000 pid=2818 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=5bf75ded-1a00-0000-9244-f98d020b0000 pid=2818 execve guuid=d15c17f2-1a00-0000-9244-f98d080b0000 pid=2824 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=d15c17f2-1a00-0000-9244-f98d080b0000 pid=2824 execve guuid=c7fd97f4-1a00-0000-9244-f98d0f0b0000 pid=2831 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c7fd97f4-1a00-0000-9244-f98d0f0b0000 pid=2831 execve guuid=b1c9eef4-1a00-0000-9244-f98d110b0000 pid=2833 /tmp/keksec.x86 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=b1c9eef4-1a00-0000-9244-f98d110b0000 pid=2833 execve guuid=cc1615f7-1a00-0000-9244-f98d160b0000 pid=2838 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=cc1615f7-1a00-0000-9244-f98d160b0000 pid=2838 execve guuid=e17766f7-1a00-0000-9244-f98d180b0000 pid=2840 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e17766f7-1a00-0000-9244-f98d180b0000 pid=2840 execve guuid=c2b12efd-1a00-0000-9244-f98d260b0000 pid=2854 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c2b12efd-1a00-0000-9244-f98d260b0000 pid=2854 execve guuid=e0d85bfd-1a00-0000-9244-f98d270b0000 pid=2855 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e0d85bfd-1a00-0000-9244-f98d270b0000 pid=2855 execve guuid=27045f00-1b00-0000-9244-f98d2f0b0000 pid=2863 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=27045f00-1b00-0000-9244-f98d2f0b0000 pid=2863 execve guuid=20c88202-1b00-0000-9244-f98d350b0000 pid=2869 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=20c88202-1b00-0000-9244-f98d350b0000 pid=2869 execve guuid=6f2dc002-1b00-0000-9244-f98d370b0000 pid=2871 /tmp/keksec.arm7 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=6f2dc002-1b00-0000-9244-f98d370b0000 pid=2871 execve guuid=7b8e8703-1b00-0000-9244-f98d3b0b0000 pid=2875 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=7b8e8703-1b00-0000-9244-f98d3b0b0000 pid=2875 execve guuid=9985cb03-1b00-0000-9244-f98d3d0b0000 pid=2877 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=9985cb03-1b00-0000-9244-f98d3d0b0000 pid=2877 execve guuid=560f5b08-1b00-0000-9244-f98d480b0000 pid=2888 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=560f5b08-1b00-0000-9244-f98d480b0000 pid=2888 execve guuid=7e208b08-1b00-0000-9244-f98d490b0000 pid=2889 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=7e208b08-1b00-0000-9244-f98d490b0000 pid=2889 execve guuid=43595f0b-1b00-0000-9244-f98d4f0b0000 pid=2895 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=43595f0b-1b00-0000-9244-f98d4f0b0000 pid=2895 execve guuid=8aa27c0d-1b00-0000-9244-f98d560b0000 pid=2902 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=8aa27c0d-1b00-0000-9244-f98d560b0000 pid=2902 execve guuid=a9a2c20d-1b00-0000-9244-f98d570b0000 pid=2903 /tmp/keksec.x64 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a9a2c20d-1b00-0000-9244-f98d570b0000 pid=2903 execve guuid=d253660e-1b00-0000-9244-f98d5a0b0000 pid=2906 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=d253660e-1b00-0000-9244-f98d5a0b0000 pid=2906 execve guuid=ba37a60e-1b00-0000-9244-f98d5c0b0000 pid=2908 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=ba37a60e-1b00-0000-9244-f98d5c0b0000 pid=2908 execve guuid=1ca39d14-1b00-0000-9244-f98d6a0b0000 pid=2922 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=1ca39d14-1b00-0000-9244-f98d6a0b0000 pid=2922 execve guuid=aa88d914-1b00-0000-9244-f98d6c0b0000 pid=2924 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=aa88d914-1b00-0000-9244-f98d6c0b0000 pid=2924 execve guuid=a380e517-1b00-0000-9244-f98d750b0000 pid=2933 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a380e517-1b00-0000-9244-f98d750b0000 pid=2933 execve guuid=fdf3ed19-1b00-0000-9244-f98d7b0b0000 pid=2939 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=fdf3ed19-1b00-0000-9244-f98d7b0b0000 pid=2939 execve guuid=51ca571a-1b00-0000-9244-f98d7d0b0000 pid=2941 /tmp/keksec.ppc guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=51ca571a-1b00-0000-9244-f98d7d0b0000 pid=2941 execve guuid=aff3591c-1b00-0000-9244-f98d850b0000 pid=2949 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=aff3591c-1b00-0000-9244-f98d850b0000 pid=2949 execve guuid=2dfb901c-1b00-0000-9244-f98d860b0000 pid=2950 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=2dfb901c-1b00-0000-9244-f98d860b0000 pid=2950 execve guuid=43f53820-1b00-0000-9244-f98d910b0000 pid=2961 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=43f53820-1b00-0000-9244-f98d910b0000 pid=2961 execve guuid=57735d20-1b00-0000-9244-f98d930b0000 pid=2963 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=57735d20-1b00-0000-9244-f98d930b0000 pid=2963 execve guuid=da1c0f23-1b00-0000-9244-f98d9b0b0000 pid=2971 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=da1c0f23-1b00-0000-9244-f98d9b0b0000 pid=2971 execve guuid=a7281325-1b00-0000-9244-f98da10b0000 pid=2977 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a7281325-1b00-0000-9244-f98da10b0000 pid=2977 execve guuid=e2604c25-1b00-0000-9244-f98da30b0000 pid=2979 /tmp/keksec.i586 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e2604c25-1b00-0000-9244-f98da30b0000 pid=2979 execve guuid=cd11f925-1b00-0000-9244-f98da50b0000 pid=2981 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=cd11f925-1b00-0000-9244-f98da50b0000 pid=2981 execve guuid=4c7a4f26-1b00-0000-9244-f98da60b0000 pid=2982 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=4c7a4f26-1b00-0000-9244-f98da60b0000 pid=2982 execve guuid=8dd5082c-1b00-0000-9244-f98dab0b0000 pid=2987 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=8dd5082c-1b00-0000-9244-f98dab0b0000 pid=2987 execve guuid=34fc302c-1b00-0000-9244-f98dac0b0000 pid=2988 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=34fc302c-1b00-0000-9244-f98dac0b0000 pid=2988 execve guuid=f617122f-1b00-0000-9244-f98db10b0000 pid=2993 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=f617122f-1b00-0000-9244-f98db10b0000 pid=2993 execve guuid=fa4c3831-1b00-0000-9244-f98db70b0000 pid=2999 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=fa4c3831-1b00-0000-9244-f98db70b0000 pid=2999 execve guuid=01d08231-1b00-0000-9244-f98db90b0000 pid=3001 /tmp/keksec.m68k guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=01d08231-1b00-0000-9244-f98db90b0000 pid=3001 execve guuid=d41a4932-1b00-0000-9244-f98dbc0b0000 pid=3004 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=d41a4932-1b00-0000-9244-f98dbc0b0000 pid=3004 execve guuid=98479132-1b00-0000-9244-f98dbe0b0000 pid=3006 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=98479132-1b00-0000-9244-f98dbe0b0000 pid=3006 execve guuid=f8f92538-1b00-0000-9244-f98dca0b0000 pid=3018 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=f8f92538-1b00-0000-9244-f98dca0b0000 pid=3018 execve guuid=8e2f5938-1b00-0000-9244-f98dcb0b0000 pid=3019 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=8e2f5938-1b00-0000-9244-f98dcb0b0000 pid=3019 execve guuid=4171493b-1b00-0000-9244-f98dd50b0000 pid=3029 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=4171493b-1b00-0000-9244-f98dd50b0000 pid=3029 execve guuid=944f5a3d-1b00-0000-9244-f98ddc0b0000 pid=3036 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=944f5a3d-1b00-0000-9244-f98ddc0b0000 pid=3036 execve guuid=9405963d-1b00-0000-9244-f98dde0b0000 pid=3038 /tmp/keksec.spc guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=9405963d-1b00-0000-9244-f98dde0b0000 pid=3038 execve guuid=5a22353e-1b00-0000-9244-f98de20b0000 pid=3042 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=5a22353e-1b00-0000-9244-f98de20b0000 pid=3042 execve guuid=54b5723e-1b00-0000-9244-f98de40b0000 pid=3044 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=54b5723e-1b00-0000-9244-f98de40b0000 pid=3044 execve guuid=e6662542-1b00-0000-9244-f98dee0b0000 pid=3054 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e6662542-1b00-0000-9244-f98dee0b0000 pid=3054 execve guuid=a0a74c42-1b00-0000-9244-f98def0b0000 pid=3055 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a0a74c42-1b00-0000-9244-f98def0b0000 pid=3055 execve guuid=6b65fc44-1b00-0000-9244-f98df80b0000 pid=3064 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=6b65fc44-1b00-0000-9244-f98df80b0000 pid=3064 execve guuid=731ff946-1b00-0000-9244-f98dfd0b0000 pid=3069 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=731ff946-1b00-0000-9244-f98dfd0b0000 pid=3069 execve guuid=ab4f5847-1b00-0000-9244-f98dff0b0000 pid=3071 /tmp/keksec.arm guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=ab4f5847-1b00-0000-9244-f98dff0b0000 pid=3071 execve guuid=ed964948-1b00-0000-9244-f98d010c0000 pid=3073 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=ed964948-1b00-0000-9244-f98d010c0000 pid=3073 execve guuid=e04f8c48-1b00-0000-9244-f98d030c0000 pid=3075 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e04f8c48-1b00-0000-9244-f98d030c0000 pid=3075 execve guuid=3526e64c-1b00-0000-9244-f98d100c0000 pid=3088 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=3526e64c-1b00-0000-9244-f98d100c0000 pid=3088 execve guuid=c3aa1a4d-1b00-0000-9244-f98d120c0000 pid=3090 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=c3aa1a4d-1b00-0000-9244-f98d120c0000 pid=3090 execve guuid=0c21f74f-1b00-0000-9244-f98d1b0c0000 pid=3099 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=0c21f74f-1b00-0000-9244-f98d1b0c0000 pid=3099 execve guuid=6e041a52-1b00-0000-9244-f98d210c0000 pid=3105 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=6e041a52-1b00-0000-9244-f98d210c0000 pid=3105 execve guuid=04cd5652-1b00-0000-9244-f98d220c0000 pid=3106 /tmp/keksec.arm5 guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=04cd5652-1b00-0000-9244-f98d220c0000 pid=3106 execve guuid=b0b28b53-1b00-0000-9244-f98d270c0000 pid=3111 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=b0b28b53-1b00-0000-9244-f98d270c0000 pid=3111 execve guuid=9534d153-1b00-0000-9244-f98d290c0000 pid=3113 /usr/bin/curl net send-data write-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=9534d153-1b00-0000-9244-f98d290c0000 pid=3113 execve guuid=585aff57-1b00-0000-9244-f98d360c0000 pid=3126 /usr/bin/busybox guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=585aff57-1b00-0000-9244-f98d360c0000 pid=3126 execve guuid=91d05458-1b00-0000-9244-f98d380c0000 pid=3128 /usr/bin/wget net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=91d05458-1b00-0000-9244-f98d380c0000 pid=3128 execve guuid=adffd15c-1b00-0000-9244-f98d460c0000 pid=3142 /usr/bin/busybox net send-data guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=adffd15c-1b00-0000-9244-f98d460c0000 pid=3142 execve guuid=08053f5f-1b00-0000-9244-f98d4e0c0000 pid=3150 /usr/bin/chmod guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=08053f5f-1b00-0000-9244-f98d4e0c0000 pid=3150 execve guuid=e4ba6d6b-1b00-0000-9244-f98d5c0c0000 pid=3164 /tmp/keksec.ppc-440fp guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=e4ba6d6b-1b00-0000-9244-f98d5c0c0000 pid=3164 execve guuid=a875436d-1b00-0000-9244-f98d620c0000 pid=3170 /usr/bin/rm delete-file guuid=28a20aba-1a00-0000-9244-f98d730a0000 pid=2675->guuid=a875436d-1b00-0000-9244-f98d620c0000 pid=3170 execve 4ae8723e-9585-54ee-ab1f-aea28f023f45 5.253.86.21:80 guuid=c96c48ba-1a00-0000-9244-f98d740a0000 pid=2676->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=9477f9c3-1a00-0000-9244-f98d920a0000 pid=2706->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=da344ac7-1a00-0000-9244-f98d9e0a0000 pid=2718->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=de9bb1cc-1a00-0000-9244-f98db10a0000 pid=2737->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=3db36ed3-1a00-0000-9244-f98dc20a0000 pid=2754->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=ddc477d6-1a00-0000-9244-f98dca0a0000 pid=2762->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=d0a7e0d9-1a00-0000-9244-f98dd50a0000 pid=2773->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=68c7b3df-1a00-0000-9244-f98ddd0a0000 pid=2781->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=3b88b2e2-1a00-0000-9244-f98de50a0000 pid=2789->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=6c976ae6-1a00-0000-9244-f98df10a0000 pid=2801->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=5bf75ded-1a00-0000-9244-f98d020b0000 pid=2818->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=d15c17f2-1a00-0000-9244-f98d080b0000 pid=2824->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=e17766f7-1a00-0000-9244-f98d180b0000 pid=2840->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=e0d85bfd-1a00-0000-9244-f98d270b0000 pid=2855->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=27045f00-1b00-0000-9244-f98d2f0b0000 pid=2863->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=9985cb03-1b00-0000-9244-f98d3d0b0000 pid=2877->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=7e208b08-1b00-0000-9244-f98d490b0000 pid=2889->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=43595f0b-1b00-0000-9244-f98d4f0b0000 pid=2895->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=ba37a60e-1b00-0000-9244-f98d5c0b0000 pid=2908->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=aa88d914-1b00-0000-9244-f98d6c0b0000 pid=2924->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=a380e517-1b00-0000-9244-f98d750b0000 pid=2933->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=2dfb901c-1b00-0000-9244-f98d860b0000 pid=2950->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=57735d20-1b00-0000-9244-f98d930b0000 pid=2963->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=da1c0f23-1b00-0000-9244-f98d9b0b0000 pid=2971->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=4c7a4f26-1b00-0000-9244-f98da60b0000 pid=2982->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=34fc302c-1b00-0000-9244-f98dac0b0000 pid=2988->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=f617122f-1b00-0000-9244-f98db10b0000 pid=2993->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=98479132-1b00-0000-9244-f98dbe0b0000 pid=3006->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=8e2f5938-1b00-0000-9244-f98dcb0b0000 pid=3019->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=4171493b-1b00-0000-9244-f98dd50b0000 pid=3029->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=54b5723e-1b00-0000-9244-f98de40b0000 pid=3044->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=a0a74c42-1b00-0000-9244-f98def0b0000 pid=3055->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 141B guuid=6b65fc44-1b00-0000-9244-f98df80b0000 pid=3064->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 89B guuid=e04f8c48-1b00-0000-9244-f98d030c0000 pid=3075->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 91B guuid=c3aa1a4d-1b00-0000-9244-f98d120c0000 pid=3090->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 142B guuid=0c21f74f-1b00-0000-9244-f98d1b0c0000 pid=3099->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 90B guuid=9534d153-1b00-0000-9244-f98d290c0000 pid=3113->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 96B guuid=91d05458-1b00-0000-9244-f98d380c0000 pid=3128->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 147B guuid=adffd15c-1b00-0000-9244-f98d460c0000 pid=3142->4ae8723e-9585-54ee-ab1f-aea28f023f45 send: 95B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-10-10 21:35:50 UTC
File Type:
Text (Shell)
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 725e6681c2ee8b785825687ecf79a3ced0bf2e9ccf283ca7f5b4efa0bb45ef0a

(this sample)

  
Delivery method
Distributed via web download

Comments