MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75f73b0f495e4f4d6b3cc152a166e3a41790ddacba2655b8284cd66dfc426866. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 75f73b0f495e4f4d6b3cc152a166e3a41790ddacba2655b8284cd66dfc426866
SHA3-384 hash: 6907fccd15fe91771fa671a51f1a72e478d68893d041f04a80c5f863bf4a8b417fa620a2dec5d8399aa06bb690ad6b93
SHA1 hash: 9f79f8e42855f711b159d77d3e8b1cb783421b3d
MD5 hash: 863f9f5a4ace0915089739bdceec5476
humanhash: oklahoma-fillet-may-kansas
File name:massload
Download: download sample
Signature Mirai
File size:2'223 bytes
First seen:2025-12-20 06:12:26 UTC
Last seen:2025-12-21 01:19:28 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:z5EMy0MBIWiRFcG0a0RKY6pqufKXRC8Y8i3/D/coT0ET0RUgHBGgHB6vE0EufKX7:z56JjH49KxNVHfHsTGmTPQuLeu4
TLSH T1F741C4EC3EB17B738582CF04B4734ABD705BA9D466904EECA4BE14F9C5BC914B830A19
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://6yd.ru/mips7650d567c04ce00a1fa50841f42593319fa13f99c94daefc0febae5b48ab00d4 Mirai32-bit elf mirai ua-wget
http://6yd.ru/mpsl9597a80f69b1dcf45c78cbb72cc519e19c4299eef0d2b3e6c3bdc9aa19210255 Miraielf mirai ua-wget
http://6yd.ru/arm4n/an/aelf mirai ua-wget
http://6yd.ru/arm5371e0cffe2f794224ef69193da697e7d2a8a18b6df44d4f90488797e3630143c Miraielf mirai ua-wget
http://6yd.ru/arm7da83bdfce452041df71007b1463e562cc3403c9d01ed9fd97e6bc96ea47d2e36 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-20T04:22:00Z UTC
Last seen:
2025-12-21T02:00:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=c14fcbd4-1600-0000-30e0-e798080e0000 pid=3592 /usr/bin/sudo guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598 /tmp/sample.bin guuid=c14fcbd4-1600-0000-30e0-e798080e0000 pid=3592->guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598 execve guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599 clone guuid=bf2cc8d8-1600-0000-30e0-e798170e0000 pid=3607 /usr/bin/cp write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=bf2cc8d8-1600-0000-30e0-e798170e0000 pid=3607 execve guuid=ce7a04de-1600-0000-30e0-e798250e0000 pid=3621 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=ce7a04de-1600-0000-30e0-e798250e0000 pid=3621 execve guuid=e25d8ade-1600-0000-30e0-e798280e0000 pid=3624 /usr/bin/rm delete-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=e25d8ade-1600-0000-30e0-e798280e0000 pid=3624 execve guuid=c2c8e1de-1600-0000-30e0-e7982c0e0000 pid=3628 /usr/bin/rm delete-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=c2c8e1de-1600-0000-30e0-e7982c0e0000 pid=3628 execve guuid=6de681e0-1600-0000-30e0-e798340e0000 pid=3636 /usr/bin/wget dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=6de681e0-1600-0000-30e0-e798340e0000 pid=3636 execve guuid=0ef84aeb-1600-0000-30e0-e798520e0000 pid=3666 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=0ef84aeb-1600-0000-30e0-e798520e0000 pid=3666 execve guuid=268b8ceb-1600-0000-30e0-e798540e0000 pid=3668 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=268b8ceb-1600-0000-30e0-e798540e0000 pid=3668 clone guuid=8a3e1fec-1600-0000-30e0-e798570e0000 pid=3671 /usr/bin/wget dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=8a3e1fec-1600-0000-30e0-e798570e0000 pid=3671 execve guuid=465093f3-1600-0000-30e0-e7985a0e0000 pid=3674 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=465093f3-1600-0000-30e0-e7985a0e0000 pid=3674 execve guuid=5cb3dbf3-1600-0000-30e0-e7985b0e0000 pid=3675 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=5cb3dbf3-1600-0000-30e0-e7985b0e0000 pid=3675 clone guuid=ef116df4-1600-0000-30e0-e7985d0e0000 pid=3677 /usr/bin/wget dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=ef116df4-1600-0000-30e0-e7985d0e0000 pid=3677 execve guuid=22dfdcfb-1600-0000-30e0-e7986a0e0000 pid=3690 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=22dfdcfb-1600-0000-30e0-e7986a0e0000 pid=3690 execve guuid=192a6ffc-1600-0000-30e0-e7986b0e0000 pid=3691 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=192a6ffc-1600-0000-30e0-e7986b0e0000 pid=3691 clone guuid=e050f0fd-1600-0000-30e0-e7986d0e0000 pid=3693 /usr/bin/wget dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=e050f0fd-1600-0000-30e0-e7986d0e0000 pid=3693 execve guuid=3b23ea04-1700-0000-30e0-e7987b0e0000 pid=3707 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=3b23ea04-1700-0000-30e0-e7987b0e0000 pid=3707 execve guuid=b8503605-1700-0000-30e0-e7987d0e0000 pid=3709 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=b8503605-1700-0000-30e0-e7987d0e0000 pid=3709 clone guuid=9aa8d606-1700-0000-30e0-e798810e0000 pid=3713 /usr/bin/wget dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=9aa8d606-1700-0000-30e0-e798810e0000 pid=3713 execve guuid=278cc00d-1700-0000-30e0-e798990e0000 pid=3737 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=278cc00d-1700-0000-30e0-e798990e0000 pid=3737 execve guuid=cc42240e-1700-0000-30e0-e7989b0e0000 pid=3739 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=cc42240e-1700-0000-30e0-e7989b0e0000 pid=3739 clone guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3744 /usr/bin/curl net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3744 execve guuid=7c000919-1700-0000-30e0-e798c30e0000 pid=3779 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=7c000919-1700-0000-30e0-e798c30e0000 pid=3779 execve guuid=7cc24e19-1700-0000-30e0-e798c50e0000 pid=3781 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=7cc24e19-1700-0000-30e0-e798c50e0000 pid=3781 clone guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3785 /usr/bin/curl net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3785 execve guuid=d9c1f723-1700-0000-30e0-e798de0e0000 pid=3806 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=d9c1f723-1700-0000-30e0-e798de0e0000 pid=3806 execve guuid=742d4924-1700-0000-30e0-e798e10e0000 pid=3809 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=742d4924-1700-0000-30e0-e798e10e0000 pid=3809 clone guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3813 /usr/bin/curl net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3813 execve guuid=c9346b2d-1700-0000-30e0-e798110f0000 pid=3857 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=c9346b2d-1700-0000-30e0-e798110f0000 pid=3857 execve guuid=3c87c72d-1700-0000-30e0-e798120f0000 pid=3858 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=3c87c72d-1700-0000-30e0-e798120f0000 pid=3858 clone guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3860 /usr/bin/curl net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3860 execve guuid=851d1836-1700-0000-30e0-e798320f0000 pid=3890 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=851d1836-1700-0000-30e0-e798320f0000 pid=3890 execve guuid=fd285036-1700-0000-30e0-e798340f0000 pid=3892 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=fd285036-1700-0000-30e0-e798340f0000 pid=3892 clone guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3896 /usr/bin/curl net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3896 execve guuid=22c1853e-1700-0000-30e0-e798490f0000 pid=3913 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=22c1853e-1700-0000-30e0-e798490f0000 pid=3913 execve guuid=a717d03e-1700-0000-30e0-e7984a0f0000 pid=3914 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=a717d03e-1700-0000-30e0-e7984a0f0000 pid=3914 clone guuid=d47dc73f-1700-0000-30e0-e7984c0f0000 pid=3916 /usr/bin/busybox dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=d47dc73f-1700-0000-30e0-e7984c0f0000 pid=3916 execve guuid=8e40c14d-1700-0000-30e0-e798600f0000 pid=3936 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=8e40c14d-1700-0000-30e0-e798600f0000 pid=3936 execve guuid=3497104e-1700-0000-30e0-e798630f0000 pid=3939 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=3497104e-1700-0000-30e0-e798630f0000 pid=3939 clone guuid=96249b4e-1700-0000-30e0-e798670f0000 pid=3943 /usr/bin/busybox dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=96249b4e-1700-0000-30e0-e798670f0000 pid=3943 execve guuid=b852585d-1700-0000-30e0-e798a80f0000 pid=4008 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=b852585d-1700-0000-30e0-e798a80f0000 pid=4008 execve guuid=663eac5d-1700-0000-30e0-e798aa0f0000 pid=4010 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=663eac5d-1700-0000-30e0-e798aa0f0000 pid=4010 clone guuid=33bd355e-1700-0000-30e0-e798ad0f0000 pid=4013 /usr/bin/busybox dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=33bd355e-1700-0000-30e0-e798ad0f0000 pid=4013 execve guuid=9adcc36c-1700-0000-30e0-e798f10f0000 pid=4081 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=9adcc36c-1700-0000-30e0-e798f10f0000 pid=4081 execve guuid=e9d9f96c-1700-0000-30e0-e798f20f0000 pid=4082 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=e9d9f96c-1700-0000-30e0-e798f20f0000 pid=4082 clone guuid=82256f6d-1700-0000-30e0-e798f60f0000 pid=4086 /usr/bin/busybox dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=82256f6d-1700-0000-30e0-e798f60f0000 pid=4086 execve guuid=52306a7b-1700-0000-30e0-e79838100000 pid=4152 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=52306a7b-1700-0000-30e0-e79838100000 pid=4152 execve guuid=53c3a57b-1700-0000-30e0-e79839100000 pid=4153 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=53c3a57b-1700-0000-30e0-e79839100000 pid=4153 clone guuid=5791237c-1700-0000-30e0-e7983e100000 pid=4158 /usr/bin/busybox dns net send-data write-file guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=5791237c-1700-0000-30e0-e7983e100000 pid=4158 execve guuid=f9ea5d8a-1700-0000-30e0-e79872100000 pid=4210 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=f9ea5d8a-1700-0000-30e0-e79872100000 pid=4210 execve guuid=0411bc8a-1700-0000-30e0-e79875100000 pid=4213 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=0411bc8a-1700-0000-30e0-e79875100000 pid=4213 clone guuid=d746748b-1700-0000-30e0-e79879100000 pid=4217 /usr/bin/busybox dns net send-data guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=d746748b-1700-0000-30e0-e79879100000 pid=4217 execve guuid=fc56a690-1a00-0000-30e0-e798fc130000 pid=5116 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=fc56a690-1a00-0000-30e0-e798fc130000 pid=5116 execve guuid=7326f990-1a00-0000-30e0-e798fd130000 pid=5117 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=7326f990-1a00-0000-30e0-e798fd130000 pid=5117 clone guuid=0da9ef91-1a00-0000-30e0-e798ff130000 pid=5119 /usr/bin/busybox dns net send-data guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=0da9ef91-1a00-0000-30e0-e798ff130000 pid=5119 execve guuid=02175a97-1d00-0000-30e0-e79820140000 pid=5152 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=02175a97-1d00-0000-30e0-e79820140000 pid=5152 execve guuid=670fe197-1d00-0000-30e0-e79821140000 pid=5153 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=670fe197-1d00-0000-30e0-e79821140000 pid=5153 clone guuid=1db3fc98-1d00-0000-30e0-e79823140000 pid=5155 /usr/bin/busybox dns net send-data guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=1db3fc98-1d00-0000-30e0-e79823140000 pid=5155 execve guuid=c612989e-2000-0000-30e0-e79824140000 pid=5156 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=c612989e-2000-0000-30e0-e79824140000 pid=5156 execve guuid=3cc51d9f-2000-0000-30e0-e79825140000 pid=5157 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=3cc51d9f-2000-0000-30e0-e79825140000 pid=5157 clone guuid=f64c35a0-2000-0000-30e0-e79827140000 pid=5159 /usr/bin/busybox dns net send-data guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=f64c35a0-2000-0000-30e0-e79827140000 pid=5159 execve guuid=f1ae5da6-2300-0000-30e0-e79828140000 pid=5160 /usr/bin/chmod guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=f1ae5da6-2300-0000-30e0-e79828140000 pid=5160 execve guuid=ca54eda6-2300-0000-30e0-e79829140000 pid=5161 /usr/bin/dash guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=ca54eda6-2300-0000-30e0-e79829140000 pid=5161 clone guuid=7e7105a8-2300-0000-30e0-e7982b140000 pid=5163 /usr/bin/busybox dns net send-data guuid=7146ecd6-1600-0000-30e0-e7980e0e0000 pid=3598->guuid=7e7105a8-2300-0000-30e0-e7982b140000 pid=5163 execve guuid=439064d7-1600-0000-30e0-e798100e0000 pid=3600 /usr/bin/cat guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599->guuid=439064d7-1600-0000-30e0-e798100e0000 pid=3600 execve guuid=0bff6fd7-1600-0000-30e0-e798110e0000 pid=3601 /usr/bin/grep guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599->guuid=0bff6fd7-1600-0000-30e0-e798110e0000 pid=3601 execve guuid=15637bd7-1600-0000-30e0-e798120e0000 pid=3602 /usr/bin/grep guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599->guuid=15637bd7-1600-0000-30e0-e798120e0000 pid=3602 execve guuid=669681d7-1600-0000-30e0-e798130e0000 pid=3603 /usr/bin/grep guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599->guuid=669681d7-1600-0000-30e0-e798130e0000 pid=3603 execve guuid=b1f38ed7-1600-0000-30e0-e798140e0000 pid=3604 /usr/bin/cut guuid=12b154d7-1600-0000-30e0-e7980f0e0000 pid=3599->guuid=b1f38ed7-1600-0000-30e0-e798140e0000 pid=3604 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=6de681e0-1600-0000-30e0-e798340e0000 pid=3636->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B a426af05-0fe5-5064-9002-84e3f002b7b9 6yd.ru:80 guuid=6de681e0-1600-0000-30e0-e798340e0000 pid=3636->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=8a3e1fec-1600-0000-30e0-e798570e0000 pid=3671->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=8a3e1fec-1600-0000-30e0-e798570e0000 pid=3671->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=ef116df4-1600-0000-30e0-e7985d0e0000 pid=3677->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=ef116df4-1600-0000-30e0-e7985d0e0000 pid=3677->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=e050f0fd-1600-0000-30e0-e7986d0e0000 pid=3693->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=e050f0fd-1600-0000-30e0-e7986d0e0000 pid=3693->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=9aa8d606-1700-0000-30e0-e798810e0000 pid=3713->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=9aa8d606-1700-0000-30e0-e798810e0000 pid=3713->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 125B guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3744->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3756 /usr/bin/curl dns net send-data guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3744->guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3756 clone guuid=42e0f70e-1700-0000-30e0-e798a00e0000 pid=3756->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3785->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3792 /usr/bin/curl dns net send-data guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3785->guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3792 clone guuid=9028fe19-1700-0000-30e0-e798c90e0000 pid=3792->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3813->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3824 /usr/bin/curl dns net send-data guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3813->guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3824 clone guuid=bbabf624-1700-0000-30e0-e798e50e0000 pid=3824->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3860->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3863 /usr/bin/curl dns net send-data guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3860->guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3863 clone guuid=d7a1642e-1700-0000-30e0-e798140f0000 pid=3863->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3896->a426af05-0fe5-5064-9002-84e3f002b7b9 send: 74B guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3903 /usr/bin/curl dns net send-data guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3896->guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3903 clone guuid=1914c736-1700-0000-30e0-e798380f0000 pid=3903->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=d47dc73f-1700-0000-30e0-e7984c0f0000 pid=3916->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 8c845f28-3b01-599d-863e-2a81a3ac53cf 6yd.ru:21 guuid=d47dc73f-1700-0000-30e0-e7984c0f0000 pid=3916->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 3b48211c-8a2a-5143-b7ad-7b75967b46b9 6yd.ru:36489 guuid=d47dc73f-1700-0000-30e0-e7984c0f0000 pid=3916->3b48211c-8a2a-5143-b7ad-7b75967b46b9 con guuid=96249b4e-1700-0000-30e0-e798670f0000 pid=3943->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=96249b4e-1700-0000-30e0-e798670f0000 pid=3943->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 38ea3231-298a-50bb-9b45-8e0dd11d52fd 6yd.ru:42115 guuid=96249b4e-1700-0000-30e0-e798670f0000 pid=3943->38ea3231-298a-50bb-9b45-8e0dd11d52fd con guuid=33bd355e-1700-0000-30e0-e798ad0f0000 pid=4013->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=33bd355e-1700-0000-30e0-e798ad0f0000 pid=4013->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 9f208fe7-670c-5506-9ce8-892fff5b21fc 6yd.ru:45697 guuid=33bd355e-1700-0000-30e0-e798ad0f0000 pid=4013->9f208fe7-670c-5506-9ce8-892fff5b21fc con guuid=82256f6d-1700-0000-30e0-e798f60f0000 pid=4086->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=82256f6d-1700-0000-30e0-e798f60f0000 pid=4086->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 2fc60733-1fa5-5444-8603-a8a96c3ff4b8 6yd.ru:41671 guuid=82256f6d-1700-0000-30e0-e798f60f0000 pid=4086->2fc60733-1fa5-5444-8603-a8a96c3ff4b8 con guuid=5791237c-1700-0000-30e0-e7983e100000 pid=4158->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=5791237c-1700-0000-30e0-e7983e100000 pid=4158->8c845f28-3b01-599d-863e-2a81a3ac53cf send: 78B 4df3b010-99d0-5fb0-a95a-d4bd3eaa1c78 6yd.ru:44135 guuid=5791237c-1700-0000-30e0-e7983e100000 pid=4158->4df3b010-99d0-5fb0-a95a-d4bd3eaa1c78 con guuid=d746748b-1700-0000-30e0-e79879100000 pid=4217->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B 0c3824ad-d5d2-5b86-a353-5231416ae6a5 6yd.ru:69 guuid=d746748b-1700-0000-30e0-e79879100000 pid=4217->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=0da9ef91-1a00-0000-30e0-e798ff130000 pid=5119->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=0da9ef91-1a00-0000-30e0-e798ff130000 pid=5119->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=1db3fc98-1d00-0000-30e0-e79823140000 pid=5155->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=1db3fc98-1d00-0000-30e0-e79823140000 pid=5155->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=f64c35a0-2000-0000-30e0-e79827140000 pid=5159->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=f64c35a0-2000-0000-30e0-e79827140000 pid=5159->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 252B guuid=7e7105a8-2300-0000-30e0-e7982b140000 pid=5163->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 48B guuid=7e7105a8-2300-0000-30e0-e7982b140000 pid=5163->0c3824ad-d5d2-5b86-a353-5231416ae6a5 send: 189B
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-20 07:10:32 UTC
AV detection:
9 of 36 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  10/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Renames itself
Unexpected DNS network traffic destination
Contacts a large (31206) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 75f73b0f495e4f4d6b3cc152a166e3a41790ddacba2655b8284cd66dfc426866

(this sample)

  
Delivery method
Distributed via web download

Comments