MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82520882c22e2b0143bcd35e9f0ecb21d0d626491b68b980b988997bd70eae2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 82520882c22e2b0143bcd35e9f0ecb21d0d626491b68b980b988997bd70eae2f
SHA3-384 hash: f952164ee6f9c4e6b607261f380c5096daf79e6f811fe94ace1e399da6024444bd15a97c9384e37b4a8655804d324620
SHA1 hash: 61d573454f617f3420b01d01d2ffe14a8008ccb8
MD5 hash: 24132b42556cd86765c9c51a62e5c1c3
humanhash: nineteen-arkansas-cat-minnesota
File name:tplink.sh
Download: download sample
Signature Mirai
File size:1'091 bytes
First seen:2025-10-02 05:46:37 UTC
Last seen:2025-10-05 02:30:24 UTC
File type: sh
MIME type:text/plain
ssdeep 12:AJoaSKYWNIQA7vKKYoS1Yg+rgEuTJzCEh:45NIpK3LF
TLSH T17A11E5F9101951261214EB50B0660C39ECBBF7E270B69AF494BFF42355CB9A07722F39
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.62/UnHAnaAW.arm22902a825f4b5e45d050e75fd997518f670dcc1ed147719e025a97334e1fcd91 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm54bab044accc55cd8b091514d74bfb44eaaea95272ee653e93948925e24b25c7a Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm69f32df4b92beb06bfed9f04284c434379715cfcba0a62fa6bd568928c146dfd4 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.arm751bb3572999cd4a4b25fd0cc06b061674df3373767c789ceff16b677a2e4bdc5 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.sh4139cf5e5c3b4a3175dfda683eaefe4e6bd5310afa3d6d679363a224a6c69feea Miraielf geofenced mirai opendir SuperH ua-wget USA
http://213.209.143.62/UnHAnaAW.ppc74e244774df73843123066181b2bb2ee1b7a62fedc22e6e936adc6e21307e42c Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://213.209.143.62/UnHAnaAW.mips1aeffd0f72ac38ac1af0f86a925957eb88cff0184d6628b48ee9f452dcf8ce9c Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.mpslf91fa8a4c5e27570471adaa1d53a68ad32a4c38f8f9f12d74bbf5614b3baaf14 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.62/UnHAnaAW.spcb19d8245d8adeb27944deefd2ae7662e4bda0c3098c964e94b5326acbec78755 Miraielf geofenced mirai opendir sparc ua-wget USA
http://213.209.143.62/UnHAnaAW.x8642efa473fa16cd174a1394892b7163f4e47c0434d1138d120135451514465617 Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.62/UnHAnaAW.x86_645c4b64e559c1332e9f65c611909524c68ad73d63878cd6e36602c17303d0985b Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.62/UnHAnaAW.i586n/an/aelf

Intelligence


File Origin
# of uploads :
3
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai opendir opendir
Verdict:
Malicious
File Type:
ps1
First seen:
2025-10-02T03:22:00Z UTC
Last seen:
2025-10-03T01:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=415d0305-1a00-0000-3f1d-6efde3090000 pid=2531 /usr/bin/sudo guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536 /tmp/sample.bin guuid=415d0305-1a00-0000-3f1d-6efde3090000 pid=2531->guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536 execve guuid=86103207-1a00-0000-3f1d-6efdea090000 pid=2538 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=86103207-1a00-0000-3f1d-6efdea090000 pid=2538 execve guuid=34adc80d-1a00-0000-3f1d-6efdf9090000 pid=2553 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=34adc80d-1a00-0000-3f1d-6efdf9090000 pid=2553 execve guuid=ee23020e-1a00-0000-3f1d-6efdfb090000 pid=2555 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=ee23020e-1a00-0000-3f1d-6efdfb090000 pid=2555 clone guuid=6d185d0f-1a00-0000-3f1d-6efd010a0000 pid=2561 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=6d185d0f-1a00-0000-3f1d-6efd010a0000 pid=2561 execve guuid=81aa5d13-1a00-0000-3f1d-6efd0d0a0000 pid=2573 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=81aa5d13-1a00-0000-3f1d-6efd0d0a0000 pid=2573 execve guuid=b580d813-1a00-0000-3f1d-6efd0f0a0000 pid=2575 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=b580d813-1a00-0000-3f1d-6efd0f0a0000 pid=2575 clone guuid=926d9914-1a00-0000-3f1d-6efd130a0000 pid=2579 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=926d9914-1a00-0000-3f1d-6efd130a0000 pid=2579 execve guuid=f4ca4f19-1a00-0000-3f1d-6efd220a0000 pid=2594 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=f4ca4f19-1a00-0000-3f1d-6efd220a0000 pid=2594 execve guuid=d6b9a419-1a00-0000-3f1d-6efd250a0000 pid=2597 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=d6b9a419-1a00-0000-3f1d-6efd250a0000 pid=2597 clone guuid=8d532e1a-1a00-0000-3f1d-6efd290a0000 pid=2601 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=8d532e1a-1a00-0000-3f1d-6efd290a0000 pid=2601 execve guuid=58e40525-1a00-0000-3f1d-6efd4e0a0000 pid=2638 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=58e40525-1a00-0000-3f1d-6efd4e0a0000 pid=2638 execve guuid=c56b4325-1a00-0000-3f1d-6efd4f0a0000 pid=2639 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=c56b4325-1a00-0000-3f1d-6efd4f0a0000 pid=2639 clone guuid=6e06c825-1a00-0000-3f1d-6efd530a0000 pid=2643 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=6e06c825-1a00-0000-3f1d-6efd530a0000 pid=2643 execve guuid=8c2eed2e-1a00-0000-3f1d-6efd6d0a0000 pid=2669 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=8c2eed2e-1a00-0000-3f1d-6efd6d0a0000 pid=2669 execve guuid=460d3d2f-1a00-0000-3f1d-6efd6e0a0000 pid=2670 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=460d3d2f-1a00-0000-3f1d-6efd6e0a0000 pid=2670 clone guuid=3b4bdf2f-1a00-0000-3f1d-6efd720a0000 pid=2674 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=3b4bdf2f-1a00-0000-3f1d-6efd720a0000 pid=2674 execve guuid=3e4b1339-1a00-0000-3f1d-6efd8b0a0000 pid=2699 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=3e4b1339-1a00-0000-3f1d-6efd8b0a0000 pid=2699 execve guuid=603e7d39-1a00-0000-3f1d-6efd8d0a0000 pid=2701 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=603e7d39-1a00-0000-3f1d-6efd8d0a0000 pid=2701 clone guuid=5ce48439-1a00-0000-3f1d-6efd8f0a0000 pid=2703 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=5ce48439-1a00-0000-3f1d-6efd8f0a0000 pid=2703 execve guuid=1ae6d443-1a00-0000-3f1d-6efdaa0a0000 pid=2730 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=1ae6d443-1a00-0000-3f1d-6efdaa0a0000 pid=2730 execve guuid=2c6d2944-1a00-0000-3f1d-6efdac0a0000 pid=2732 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=2c6d2944-1a00-0000-3f1d-6efdac0a0000 pid=2732 clone guuid=1268e244-1a00-0000-3f1d-6efdb00a0000 pid=2736 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=1268e244-1a00-0000-3f1d-6efdb00a0000 pid=2736 execve guuid=40455f4e-1a00-0000-3f1d-6efdcb0a0000 pid=2763 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=40455f4e-1a00-0000-3f1d-6efdcb0a0000 pid=2763 execve guuid=ba0ac64e-1a00-0000-3f1d-6efdcc0a0000 pid=2764 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=ba0ac64e-1a00-0000-3f1d-6efdcc0a0000 pid=2764 clone guuid=93aa9d50-1a00-0000-3f1d-6efdd10a0000 pid=2769 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=93aa9d50-1a00-0000-3f1d-6efdd10a0000 pid=2769 execve guuid=4cdd1355-1a00-0000-3f1d-6efdda0a0000 pid=2778 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=4cdd1355-1a00-0000-3f1d-6efdda0a0000 pid=2778 execve guuid=7c558e55-1a00-0000-3f1d-6efddb0a0000 pid=2779 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=7c558e55-1a00-0000-3f1d-6efddb0a0000 pid=2779 clone guuid=6e856f56-1a00-0000-3f1d-6efddf0a0000 pid=2783 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=6e856f56-1a00-0000-3f1d-6efddf0a0000 pid=2783 execve guuid=82ae935a-1a00-0000-3f1d-6efde50a0000 pid=2789 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=82ae935a-1a00-0000-3f1d-6efde50a0000 pid=2789 execve guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791 /home/sandbox/UnHAnaAW.x86 net guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791 execve guuid=53780c5b-1a00-0000-3f1d-6efdec0a0000 pid=2796 /usr/bin/wget net send-data write-file guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=53780c5b-1a00-0000-3f1d-6efdec0a0000 pid=2796 execve guuid=42a3066e-1a00-0000-3f1d-6efdfe0a0000 pid=2814 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=42a3066e-1a00-0000-3f1d-6efdfe0a0000 pid=2814 execve guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815 /home/sandbox/UnHAnaAW.x86_64 net guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815 execve guuid=3ce2c1da-1b00-0000-3f1d-6efde00c0000 pid=3296 /usr/bin/wget net guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=3ce2c1da-1b00-0000-3f1d-6efde00c0000 pid=3296 execve guuid=de9b1adf-1b00-0000-3f1d-6efdec0c0000 pid=3308 /usr/bin/chmod guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=de9b1adf-1b00-0000-3f1d-6efdec0c0000 pid=3308 execve guuid=1bacb3df-1b00-0000-3f1d-6efded0c0000 pid=3309 /usr/bin/dash guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=1bacb3df-1b00-0000-3f1d-6efded0c0000 pid=3309 clone guuid=1f23d6df-1b00-0000-3f1d-6efdee0c0000 pid=3310 /usr/bin/rm guuid=e1aef106-1a00-0000-3f1d-6efde8090000 pid=2536->guuid=1f23d6df-1b00-0000-3f1d-6efdee0c0000 pid=3310 execve eaaaaddb-f5f1-5090-9f4d-096f63c93adc 213.209.143.62:80 guuid=86103207-1a00-0000-3f1d-6efdea090000 pid=2538->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=6d185d0f-1a00-0000-3f1d-6efd010a0000 pid=2561->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=926d9914-1a00-0000-3f1d-6efd130a0000 pid=2579->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=8d532e1a-1a00-0000-3f1d-6efd290a0000 pid=2601->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=6e06c825-1a00-0000-3f1d-6efd530a0000 pid=2643->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=3b4bdf2f-1a00-0000-3f1d-6efd720a0000 pid=2674->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=5ce48439-1a00-0000-3f1d-6efd8f0a0000 pid=2703->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=1268e244-1a00-0000-3f1d-6efdb00a0000 pid=2736->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=93aa9d50-1a00-0000-3f1d-6efdd10a0000 pid=2769->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=6e856f56-1a00-0000-3f1d-6efddf0a0000 pid=2783->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=64a1f95a-1a00-0000-3f1d-6efde90a0000 pid=2793 /home/sandbox/UnHAnaAW.x86 guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791->guuid=64a1f95a-1a00-0000-3f1d-6efde90a0000 pid=2793 clone guuid=613efe5a-1a00-0000-3f1d-6efdea0a0000 pid=2794 /home/sandbox/UnHAnaAW.x86 guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791->guuid=613efe5a-1a00-0000-3f1d-6efdea0a0000 pid=2794 clone guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795 /home/sandbox/UnHAnaAW.x86 net send-data zombie guuid=02a2d65a-1a00-0000-3f1d-6efde70a0000 pid=2791->guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795 clone guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 1491f2a5-a4ef-5eb9-bced-3da3f0c99427 213.209.143.62:1024 guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->1491f2a5-a4ef-5eb9-bced-3da3f0c99427 send: 12B guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797 clone guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798 clone guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799 clone guuid=e592205b-1a00-0000-3f1d-6efdf00a0000 pid=2800 /home/sandbox/UnHAnaAW.x86 guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=e592205b-1a00-0000-3f1d-6efdf00a0000 pid=2800 clone guuid=4c9f235b-1a00-0000-3f1d-6efdf20a0000 pid=2802 /home/sandbox/UnHAnaAW.x86 guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=4c9f235b-1a00-0000-3f1d-6efdf20a0000 pid=2802 clone guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=2103065b-1a00-0000-3f1d-6efdeb0a0000 pid=2795->guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803 clone guuid=53780c5b-1a00-0000-3f1d-6efdec0a0000 pid=2796->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 144B guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797|send-data send-data to 160 IP addresses review logs to see them all guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797->guuid=d835125b-1a00-0000-3f1d-6efded0a0000 pid=2797|send-data send guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798|send-data send-data to 160 IP addresses review logs to see them all guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798->guuid=08bd165b-1a00-0000-3f1d-6efdee0a0000 pid=2798|send-data send guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799|send-data send-data to 1024 IP addresses review logs to see them all guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799->guuid=ead41b5b-1a00-0000-3f1d-6efdef0a0000 pid=2799|send-data send guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803|send-data send-data to 384 IP addresses review logs to see them all guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803->guuid=03b9265b-1a00-0000-3f1d-6efdf30a0000 pid=2803|send-data send guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 191dff31-3ba9-595b-9e5c-dc6cfa1beabf 0.0.0.0:23455 guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815->191dff31-3ba9-595b-9e5c-dc6cfa1beabf con guuid=105cb0da-1b00-0000-3f1d-6efddd0c0000 pid=3293 /home/sandbox/UnHAnaAW.x86_64 guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815->guuid=105cb0da-1b00-0000-3f1d-6efddd0c0000 pid=3293 clone guuid=b1c7b3da-1b00-0000-3f1d-6efdde0c0000 pid=3294 /home/sandbox/UnHAnaAW.x86_64 guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815->guuid=b1c7b3da-1b00-0000-3f1d-6efdde0c0000 pid=3294 clone guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295 /home/sandbox/UnHAnaAW.x86_64 net send-data zombie guuid=53bd9f6e-1a00-0000-3f1d-6efdff0a0000 pid=2815->guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295 clone guuid=6983ba38-2600-0000-3f1d-6efdd8140000 pid=5336 /home/sandbox/UnHAnaAW.x86_64 guuid=105cb0da-1b00-0000-3f1d-6efddd0c0000 pid=3293->guuid=6983ba38-2600-0000-3f1d-6efdd8140000 pid=5336 clone guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337 /home/sandbox/UnHAnaAW.x86_64 net zombie guuid=105cb0da-1b00-0000-3f1d-6efddd0c0000 pid=3293->guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337 clone guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->1491f2a5-a4ef-5eb9-bced-3da3f0c99427 send: 16B guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297 clone guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298 clone guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299 clone guuid=c6f4d2da-1b00-0000-3f1d-6efde40c0000 pid=3300 /home/sandbox/UnHAnaAW.x86_64 net guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=c6f4d2da-1b00-0000-3f1d-6efde40c0000 pid=3300 clone guuid=63fed6da-1b00-0000-3f1d-6efde50c0000 pid=3301 /home/sandbox/UnHAnaAW.x86_64 guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=63fed6da-1b00-0000-3f1d-6efde50c0000 pid=3301 clone guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=ea63b8da-1b00-0000-3f1d-6efddf0c0000 pid=3295->guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302 clone guuid=3ce2c1da-1b00-0000-3f1d-6efde00c0000 pid=3296->eaaaaddb-f5f1-5090-9f4d-096f63c93adc con guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297|send-data send-data to 4097 IP addresses review logs to see them all guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297->guuid=771ec4da-1b00-0000-3f1d-6efde10c0000 pid=3297|send-data send guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 59ad614f-a2f7-5b4e-8ddc-063f1a877a18 95.217.13.211:80 guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298->59ad614f-a2f7-5b4e-8ddc-063f1a877a18 send: 40B guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298|send-data send-data to 4097 IP addresses review logs to see them all guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298->guuid=1970c7da-1b00-0000-3f1d-6efde20c0000 pid=3298|send-data send guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299|send-data send-data to 4097 IP addresses review logs to see them all guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299->guuid=5c35cdda-1b00-0000-3f1d-6efde30c0000 pid=3299|send-data send guuid=c6f4d2da-1b00-0000-3f1d-6efde40c0000 pid=3300->1491f2a5-a4ef-5eb9-bced-3da3f0c99427 con guuid=8c575931-2600-0000-3f1d-6efdd6140000 pid=5334 /home/sandbox/UnHAnaAW.x86_64 guuid=c6f4d2da-1b00-0000-3f1d-6efde40c0000 pid=3300->guuid=8c575931-2600-0000-3f1d-6efdd6140000 pid=5334 clone guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=c6f4d2da-1b00-0000-3f1d-6efde40c0000 pid=3300->guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335 clone guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302|send-data send-data to 4097 IP addresses review logs to see them all guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302->guuid=071adfda-1b00-0000-3f1d-6efde60c0000 pid=3302|send-data send guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335|send-data send-data to 4097 IP addresses review logs to see them all guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335->guuid=48f86131-2600-0000-3f1d-6efdd7140000 pid=5335|send-data send guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->1491f2a5-a4ef-5eb9-bced-3da3f0c99427 con guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338 clone guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339 clone guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340 clone guuid=6a49ed38-2600-0000-3f1d-6efddd140000 pid=5341 /home/sandbox/UnHAnaAW.x86_64 net guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=6a49ed38-2600-0000-3f1d-6efddd140000 pid=5341 clone guuid=a6eff538-2600-0000-3f1d-6efdde140000 pid=5342 /home/sandbox/UnHAnaAW.x86_64 guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=a6eff538-2600-0000-3f1d-6efdde140000 pid=5342 clone guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=5219c038-2600-0000-3f1d-6efdd9140000 pid=5337->guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343 clone guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338|send-data send-data to 4097 IP addresses review logs to see them all guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338->guuid=846dd638-2600-0000-3f1d-6efdda140000 pid=5338|send-data send guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0be8c074-4bb8-5e95-a071-b013438b2ae0 88.223.82.162:80 guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339->0be8c074-4bb8-5e95-a071-b013438b2ae0 con 04327185-90df-5767-9f37-f69ad3055186 88.221.250.109:80 guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339->04327185-90df-5767-9f37-f69ad3055186 con guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339|send-data send-data to 4097 IP addresses review logs to see them all guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339->guuid=8703de38-2600-0000-3f1d-6efddb140000 pid=5339|send-data send guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con d53d1b23-1540-56e9-baee-1e6ea00e5188 94.190.81.160:8080 guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340->d53d1b23-1540-56e9-baee-1e6ea00e5188 con guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340|send-data send-data to 4097 IP addresses review logs to see them all guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340->guuid=5b6ee638-2600-0000-3f1d-6efddc140000 pid=5340|send-data send guuid=6a49ed38-2600-0000-3f1d-6efddd140000 pid=5341->1491f2a5-a4ef-5eb9-bced-3da3f0c99427 con guuid=38151c63-2700-0000-3f1d-6efde0140000 pid=5344 /home/sandbox/UnHAnaAW.x86_64 guuid=6a49ed38-2600-0000-3f1d-6efddd140000 pid=5341->guuid=38151c63-2700-0000-3f1d-6efde0140000 pid=5344 clone guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=6a49ed38-2600-0000-3f1d-6efddd140000 pid=5341->guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345 clone guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343|send-data send-data to 4097 IP addresses review logs to see them all guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343->guuid=59e7fa38-2600-0000-3f1d-6efddf140000 pid=5343|send-data send guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345|send-data send-data to 4097 IP addresses review logs to see them all guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345->guuid=eea42163-2700-0000-3f1d-6efde1140000 pid=5345|send-data send
Threat name:
Document-HTML.Trojan.Heuristic
Status:
Malicious
First seen:
2025-10-02 05:47:36 UTC
File Type:
Text (JavaScript)
AV detection:
14 of 36 (38.89%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 82520882c22e2b0143bcd35e9f0ecb21d0d626491b68b980b988997bd70eae2f

(this sample)

Comments