MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 82a993ef227ffb60c9a48b56e8d329b9331223008d6d40954d3ad4fd57169b79. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 82a993ef227ffb60c9a48b56e8d329b9331223008d6d40954d3ad4fd57169b79
SHA3-384 hash: 82d3918ac7fafe5b2d425b5aa49efe6f8c3c34e69e5379f8ab9fdfd3e3053811a12a67a92079299eb558b91bc5e7f8a1
SHA1 hash: 008f2006dfc1ff2b3a4210f723b90409740aec9d
MD5 hash: 5218856f4936c448cbb7c0b3671ae91e
humanhash: monkey-bulldog-earth-yellow
File name:toto.sh
Download: download sample
Signature Mirai
File size:1'053 bytes
First seen:2025-09-30 05:30:22 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:A+v99+pa39+JNIQr9+SvKQ9+29++9+Yr9+nMK9+J99+V9+t+9+WwDv:gNIYK1sqwDv
TLSH T16C1181F9001AA12414006F12715608356CBBF7E692339AF9947FE423E9CB5E03B21EB5
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.44/UnHAnaAW.arma0822f8acdc5b0d20b2bd2bcc92a2c341c18ee04e38fae3407d3d1ff9eef85a1 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm5dceec67b91a53c720d94e3bbf5a7081b389bbf3c8fc616487730da3e8ae280b7 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm63a7134b8240e560d81d4a1effbb04a8f873e34ad332212b62de07807212f1b82 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm7e63475639ec1c8ec9643203a4902fbc59e7c8272cadd7db355c5da6ba6ea98ed Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.sh49311cc7b2b4f4777b9ffbf50978f85055aed70ea42bac6be542cb66d8de2de0f Miraielf geofenced mirai opendir SuperH ua-wget USA
http://213.209.143.44/UnHAnaAW.ppcfb5e0ae697fafd5f58e98e0b74d9160cf8ed08c73fc329d02e4cdb4739485804 Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://213.209.143.44/UnHAnaAW.mips91e7b4318985ce375aef13265584ffb72b936593a99d10e6ff98305d962c2623 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.mpslb7e145aa84a71ee51c3f45351d82d2aaa179562dacc4547efc2f06e30664e2d4 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.spcb536d143397fd3c4c964adeeebc4935d7c5ca8ce21de1ff035a94862161d3d19 Miraielf geofenced mirai opendir sparc ua-wget USA
http://213.209.143.44/UnHAnaAW.x863fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.44/UnHAnaAW.x86_643fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf mirai ua-wget
http://213.209.143.44/UnHAnaAW.i5863fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-30T02:52:00Z UTC
Last seen:
2025-09-30T02:52:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.ba HEUR:Backdoor.Linux.Mirai.b HEUR:Backdoor.Linux.Mirai.au HEUR:Trojan-Downloader.Shell.Agent.cl HEUR:Exploit.Linux.CVE-2017-17215.a
Status:
terminated
Behavior Graph:
%3 guuid=2e65576c-1900-0000-ea46-bbbaee110000 pid=4590 /usr/bin/sudo guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599 /tmp/sample.bin guuid=2e65576c-1900-0000-ea46-bbbaee110000 pid=4590->guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599 execve guuid=0e980c6e-1900-0000-ea46-bbbaf9110000 pid=4601 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=0e980c6e-1900-0000-ea46-bbbaf9110000 pid=4601 execve guuid=3a701578-1900-0000-ea46-bbba16120000 pid=4630 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=3a701578-1900-0000-ea46-bbba16120000 pid=4630 execve guuid=45ce9f78-1900-0000-ea46-bbba19120000 pid=4633 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=45ce9f78-1900-0000-ea46-bbba19120000 pid=4633 clone guuid=5ce3137b-1900-0000-ea46-bbba26120000 pid=4646 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=5ce3137b-1900-0000-ea46-bbba26120000 pid=4646 execve guuid=77be767f-1900-0000-ea46-bbba35120000 pid=4661 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=77be767f-1900-0000-ea46-bbba35120000 pid=4661 execve guuid=5d92b77f-1900-0000-ea46-bbba37120000 pid=4663 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=5d92b77f-1900-0000-ea46-bbba37120000 pid=4663 clone guuid=12013981-1900-0000-ea46-bbba3d120000 pid=4669 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=12013981-1900-0000-ea46-bbba3d120000 pid=4669 execve guuid=01b89085-1900-0000-ea46-bbba52120000 pid=4690 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=01b89085-1900-0000-ea46-bbba52120000 pid=4690 execve guuid=f90cd885-1900-0000-ea46-bbba54120000 pid=4692 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=f90cd885-1900-0000-ea46-bbba54120000 pid=4692 clone guuid=7dee1087-1900-0000-ea46-bbba5a120000 pid=4698 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=7dee1087-1900-0000-ea46-bbba5a120000 pid=4698 execve guuid=352c7192-1900-0000-ea46-bbba83120000 pid=4739 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=352c7192-1900-0000-ea46-bbba83120000 pid=4739 execve guuid=4beee692-1900-0000-ea46-bbba85120000 pid=4741 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=4beee692-1900-0000-ea46-bbba85120000 pid=4741 clone guuid=61d5bb93-1900-0000-ea46-bbba89120000 pid=4745 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=61d5bb93-1900-0000-ea46-bbba89120000 pid=4745 execve guuid=cf308899-1900-0000-ea46-bbba8d120000 pid=4749 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=cf308899-1900-0000-ea46-bbba8d120000 pid=4749 execve guuid=d8f6cb99-1900-0000-ea46-bbba90120000 pid=4752 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=d8f6cb99-1900-0000-ea46-bbba90120000 pid=4752 clone guuid=a2c9759a-1900-0000-ea46-bbba94120000 pid=4756 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=a2c9759a-1900-0000-ea46-bbba94120000 pid=4756 execve guuid=2477f0a3-1900-0000-ea46-bbbaac120000 pid=4780 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=2477f0a3-1900-0000-ea46-bbbaac120000 pid=4780 execve guuid=b67e52a4-1900-0000-ea46-bbbaae120000 pid=4782 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=b67e52a4-1900-0000-ea46-bbbaae120000 pid=4782 clone guuid=289b65a4-1900-0000-ea46-bbbaaf120000 pid=4783 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=289b65a4-1900-0000-ea46-bbbaaf120000 pid=4783 execve guuid=3c111cb1-1900-0000-ea46-bbbacf120000 pid=4815 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=3c111cb1-1900-0000-ea46-bbbacf120000 pid=4815 execve guuid=e8fa66b1-1900-0000-ea46-bbbad1120000 pid=4817 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=e8fa66b1-1900-0000-ea46-bbbad1120000 pid=4817 clone guuid=e727f6b1-1900-0000-ea46-bbbad5120000 pid=4821 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=e727f6b1-1900-0000-ea46-bbbad5120000 pid=4821 execve guuid=53b87dbe-1900-0000-ea46-bbbaff120000 pid=4863 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=53b87dbe-1900-0000-ea46-bbbaff120000 pid=4863 execve guuid=805ceebe-1900-0000-ea46-bbba02130000 pid=4866 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=805ceebe-1900-0000-ea46-bbba02130000 pid=4866 clone guuid=d46bd4bf-1900-0000-ea46-bbba08130000 pid=4872 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=d46bd4bf-1900-0000-ea46-bbba08130000 pid=4872 execve guuid=8ff61fc9-1900-0000-ea46-bbba25130000 pid=4901 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=8ff61fc9-1900-0000-ea46-bbba25130000 pid=4901 execve guuid=1f0a5cc9-1900-0000-ea46-bbba27130000 pid=4903 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=1f0a5cc9-1900-0000-ea46-bbba27130000 pid=4903 clone guuid=140bf6c9-1900-0000-ea46-bbba2b130000 pid=4907 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=140bf6c9-1900-0000-ea46-bbba2b130000 pid=4907 execve guuid=22d95dce-1900-0000-ea46-bbba3c130000 pid=4924 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=22d95dce-1900-0000-ea46-bbba3c130000 pid=4924 execve guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926 /home/sandbox/UnHAnaAW.x86 net guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926 execve guuid=0717e1ce-1900-0000-ea46-bbba43130000 pid=4931 /usr/bin/wget net send-data write-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=0717e1ce-1900-0000-ea46-bbba43130000 pid=4931 execve guuid=84b04bdd-1900-0000-ea46-bbba80130000 pid=4992 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=84b04bdd-1900-0000-ea46-bbba80130000 pid=4992 execve guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994 /home/sandbox/UnHAnaAW.x86_64 net guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994 execve guuid=b97bab4b-1b00-0000-ea46-bbbaa5140000 pid=5285 /usr/bin/wget net guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=b97bab4b-1b00-0000-ea46-bbbaa5140000 pid=5285 execve guuid=5c565453-1b00-0000-ea46-bbbaac140000 pid=5292 /usr/bin/chmod guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=5c565453-1b00-0000-ea46-bbbaac140000 pid=5292 execve guuid=0d206b54-1b00-0000-ea46-bbbaad140000 pid=5293 /usr/bin/dash guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=0d206b54-1b00-0000-ea46-bbbaad140000 pid=5293 clone guuid=dafdb954-1b00-0000-ea46-bbbaae140000 pid=5294 /usr/bin/rm delete-file guuid=aceed96d-1900-0000-ea46-bbbaf7110000 pid=4599->guuid=dafdb954-1b00-0000-ea46-bbbaae140000 pid=5294 execve 9a5bfd7d-6ca1-5e69-b1de-790583636c52 213.209.143.44:80 guuid=0e980c6e-1900-0000-ea46-bbbaf9110000 pid=4601->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=5ce3137b-1900-0000-ea46-bbba26120000 pid=4646->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=12013981-1900-0000-ea46-bbba3d120000 pid=4669->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=7dee1087-1900-0000-ea46-bbba5a120000 pid=4698->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=61d5bb93-1900-0000-ea46-bbba89120000 pid=4745->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=a2c9759a-1900-0000-ea46-bbba94120000 pid=4756->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=289b65a4-1900-0000-ea46-bbbaaf120000 pid=4783->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=e727f6b1-1900-0000-ea46-bbbad5120000 pid=4821->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=d46bd4bf-1900-0000-ea46-bbba08130000 pid=4872->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=140bf6c9-1900-0000-ea46-bbba2b130000 pid=4907->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dd88ccce-1900-0000-ea46-bbba3f130000 pid=4927 /home/sandbox/UnHAnaAW.x86 guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926->guuid=dd88ccce-1900-0000-ea46-bbba3f130000 pid=4927 clone guuid=5733d1ce-1900-0000-ea46-bbba40130000 pid=4928 /home/sandbox/UnHAnaAW.x86 guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926->guuid=5733d1ce-1900-0000-ea46-bbba40130000 pid=4928 clone guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929 /home/sandbox/UnHAnaAW.x86 net send-data zombie guuid=a118a7ce-1900-0000-ea46-bbba3e130000 pid=4926->guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929 clone guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 795831f1-3652-5898-8295-aba18a81ec9e 213.209.143.44:1024 guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->795831f1-3652-5898-8295-aba18a81ec9e send: 9B guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932 clone guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933 clone guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934 clone guuid=5859f0ce-1900-0000-ea46-bbba47130000 pid=4935 /home/sandbox/UnHAnaAW.x86 guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=5859f0ce-1900-0000-ea46-bbba47130000 pid=4935 clone guuid=80daf3ce-1900-0000-ea46-bbba48130000 pid=4936 /home/sandbox/UnHAnaAW.x86 guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=80daf3ce-1900-0000-ea46-bbba48130000 pid=4936 clone guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=6950d9ce-1900-0000-ea46-bbba41130000 pid=4929->guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937 clone guuid=0717e1ce-1900-0000-ea46-bbba43130000 pid=4931->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 144B guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932|send-data send-data to 160 IP addresses review logs to see them all guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932->guuid=a3d7e3ce-1900-0000-ea46-bbba44130000 pid=4932|send-data send guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933|send-data send-data to 160 IP addresses review logs to see them all guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933->guuid=45f6e7ce-1900-0000-ea46-bbba45130000 pid=4933|send-data send guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934|send-data send-data to 1024 IP addresses review logs to see them all guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934->guuid=519eebce-1900-0000-ea46-bbba46130000 pid=4934|send-data send guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937|send-data send-data to 384 IP addresses review logs to see them all guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937->guuid=95f1f8ce-1900-0000-ea46-bbba49130000 pid=4937|send-data send guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 191dff31-3ba9-595b-9e5c-dc6cfa1beabf 0.0.0.0:23455 guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994->191dff31-3ba9-595b-9e5c-dc6cfa1beabf con guuid=1ef2984b-1b00-0000-ea46-bbbaa2140000 pid=5282 /home/sandbox/UnHAnaAW.x86_64 guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994->guuid=1ef2984b-1b00-0000-ea46-bbbaa2140000 pid=5282 clone guuid=91d29e4b-1b00-0000-ea46-bbbaa3140000 pid=5283 /home/sandbox/UnHAnaAW.x86_64 guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994->guuid=91d29e4b-1b00-0000-ea46-bbbaa3140000 pid=5283 clone guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284 /home/sandbox/UnHAnaAW.x86_64 net send-data zombie guuid=fecc87dd-1900-0000-ea46-bbba82130000 pid=4994->guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284 clone guuid=296de413-2300-0000-ea46-bbbacf140000 pid=5327 /home/sandbox/UnHAnaAW.x86_64 guuid=1ef2984b-1b00-0000-ea46-bbbaa2140000 pid=5282->guuid=296de413-2300-0000-ea46-bbbacf140000 pid=5327 clone guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328 /home/sandbox/UnHAnaAW.x86_64 net zombie guuid=1ef2984b-1b00-0000-ea46-bbbaa2140000 pid=5282->guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328 clone guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->795831f1-3652-5898-8295-aba18a81ec9e send: 13B guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286 clone guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287 clone guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288 clone guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289 /home/sandbox/UnHAnaAW.x86_64 net send-data guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289 clone guuid=5355f34b-1b00-0000-ea46-bbbaaa140000 pid=5290 /home/sandbox/UnHAnaAW.x86_64 guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=5355f34b-1b00-0000-ea46-bbbaaa140000 pid=5290 clone guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=d93fa44b-1b00-0000-ea46-bbbaa4140000 pid=5284->guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291 clone guuid=b97bab4b-1b00-0000-ea46-bbbaa5140000 pid=5285->9a5bfd7d-6ca1-5e69-b1de-790583636c52 con guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286|send-data send-data to 4096 IP addresses review logs to see them all guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286->guuid=413ac84b-1b00-0000-ea46-bbbaa6140000 pid=5286|send-data send guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287|send-data send-data to 4096 IP addresses review logs to see them all guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287->guuid=2de8cd4b-1b00-0000-ea46-bbbaa7140000 pid=5287|send-data send guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 22266ee8-94d4-590c-93c9-7bdc24223ed0 85.185.229.167:8080 guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288->22266ee8-94d4-590c-93c9-7bdc24223ed0 con guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288|send-data send-data to 4097 IP addresses review logs to see them all guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288->guuid=f566db4b-1b00-0000-ea46-bbbaa8140000 pid=5288|send-data send guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289->795831f1-3652-5898-8295-aba18a81ec9e send: 9B guuid=55b66a26-2300-0000-ea46-bbbad7140000 pid=5335 /home/sandbox/UnHAnaAW.x86_64 guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289->guuid=55b66a26-2300-0000-ea46-bbbad7140000 pid=5335 clone guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=789dea4b-1b00-0000-ea46-bbbaa9140000 pid=5289->guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336 clone guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291|send-data send-data to 4097 IP addresses review logs to see them all guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291->guuid=2f93044c-1b00-0000-ea46-bbbaab140000 pid=5291|send-data send guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->795831f1-3652-5898-8295-aba18a81ec9e con guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329 clone guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330 clone guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331 clone guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332 /home/sandbox/UnHAnaAW.x86_64 net send-data guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332 clone guuid=c96f0f14-2300-0000-ea46-bbbad5140000 pid=5333 /home/sandbox/UnHAnaAW.x86_64 guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=c96f0f14-2300-0000-ea46-bbbad5140000 pid=5333 clone guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=33c2e913-2300-0000-ea46-bbbad0140000 pid=5328->guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334 clone guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329|send-data send-data to 4097 IP addresses review logs to see them all guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329->guuid=b6c6fb13-2300-0000-ea46-bbbad1140000 pid=5329|send-data send guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330|send-data send-data to 4097 IP addresses review logs to see them all guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330->guuid=be1e0014-2300-0000-ea46-bbbad2140000 pid=5330|send-data send guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 756f2d04-ea6c-59ed-b8f4-e6dc6c7666ab 94.110.128.214:8080 guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->756f2d04-ea6c-59ed-b8f4-e6dc6c7666ab con 512b4b85-ed6e-5b65-a8dc-dd8ba2555497 94.123.26.159:8080 guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->512b4b85-ed6e-5b65-a8dc-dd8ba2555497 con ea4d97a5-27ed-535d-af8e-554c5c879f48 94.123.191.115:8080 guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->ea4d97a5-27ed-535d-af8e-554c5c879f48 con 42d415fb-f166-58a2-ad9d-a2bd7419bd15 62.150.151.52:8080 guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->42d415fb-f166-58a2-ad9d-a2bd7419bd15 con guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331|send-data send-data to 4097 IP addresses review logs to see them all guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331->guuid=69d20414-2300-0000-ea46-bbbad3140000 pid=5331|send-data send guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332->795831f1-3652-5898-8295-aba18a81ec9e send: 9B guuid=7c37353e-2400-0000-ea46-bbbad9140000 pid=5337 /home/sandbox/UnHAnaAW.x86_64 guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332->guuid=7c37353e-2400-0000-ea46-bbbad9140000 pid=5337 clone guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=d1430914-2300-0000-ea46-bbbad4140000 pid=5332->guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338 clone guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334|send-data send-data to 4097 IP addresses review logs to see them all guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334->guuid=201b1314-2300-0000-ea46-bbbad6140000 pid=5334|send-data send guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336|send-data send-data to 4097 IP addresses review logs to see them all guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336->guuid=35117326-2300-0000-ea46-bbbad8140000 pid=5336|send-data send guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338|send-data send-data to 4097 IP addresses review logs to see them all guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338->guuid=7ac8393e-2400-0000-ea46-bbbada140000 pid=5338|send-data send
Threat name:
Linux.Trojan.Egairtigado
Status:
Malicious
First seen:
2025-09-30 05:31:25 UTC
File Type:
Text (Shell)
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 82a993ef227ffb60c9a48b56e8d329b9331223008d6d40954d3ad4fd57169b79

(this sample)

  
Delivery method
Distributed via web download

Comments