MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8cd4879abceee6ebd845fb50ca693303450e349514f080c3ffc27d1605ce3d86. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8cd4879abceee6ebd845fb50ca693303450e349514f080c3ffc27d1605ce3d86
SHA3-384 hash: c7b226702fba2fd4a214fc12aed0e16e7fae08e08778037828322314a6473b5dbe33dbdfa549d00499190d652fcaae2f
SHA1 hash: 483f1256415489948de4bebc4ba4bfdf568e7eae
MD5 hash: 32132476a828a44ffdb1f0d35628fa4b
humanhash: bravo-orange-fourteen-chicken
File name:gay.sh
Download: download sample
Signature Mirai
File size:8'385 bytes
First seen:2025-12-17 18:24:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:bg3hRE9OBP8/xXABDXAUXs4bwmYf/rx9ViIpy3v5zR8VWyS:bUh24d8/ywZ7/E3v5wS
TLSH T11D0253E679A0EC35358C583E5B8998882D5B127B043A7B04B49D783C3FBC614F5B87E9
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-17T16:37:00Z UTC
Last seen:
2025-12-19T05:17:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=fe0ec006-1900-0000-414f-7f0e1b080000 pid=2075 /usr/bin/sudo guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082 /tmp/sample.bin write-file guuid=fe0ec006-1900-0000-414f-7f0e1b080000 pid=2075->guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082 execve guuid=25385209-1900-0000-414f-7f0e23080000 pid=2083 /usr/bin/pgrep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=25385209-1900-0000-414f-7f0e23080000 pid=2083 execve guuid=5fb52e10-1900-0000-414f-7f0e34080000 pid=2100 /usr/bin/ps guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=5fb52e10-1900-0000-414f-7f0e34080000 pid=2100 execve guuid=644b3510-1900-0000-414f-7f0e35080000 pid=2101 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=644b3510-1900-0000-414f-7f0e35080000 pid=2101 execve guuid=ad093910-1900-0000-414f-7f0e36080000 pid=2102 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=ad093910-1900-0000-414f-7f0e36080000 pid=2102 execve guuid=bf355017-1900-0000-414f-7f0e4a080000 pid=2122 /usr/bin/pgrep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=bf355017-1900-0000-414f-7f0e4a080000 pid=2122 execve guuid=1d949e19-1900-0000-414f-7f0e51080000 pid=2129 /usr/bin/ps guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=1d949e19-1900-0000-414f-7f0e51080000 pid=2129 execve guuid=fe9da819-1900-0000-414f-7f0e52080000 pid=2130 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=fe9da819-1900-0000-414f-7f0e52080000 pid=2130 execve guuid=3b2daf19-1900-0000-414f-7f0e53080000 pid=2131 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=3b2daf19-1900-0000-414f-7f0e53080000 pid=2131 execve guuid=3d5c2e1c-1900-0000-414f-7f0e5a080000 pid=2138 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=3d5c2e1c-1900-0000-414f-7f0e5a080000 pid=2138 clone guuid=3b5ab61c-1900-0000-414f-7f0e5f080000 pid=2143 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=3b5ab61c-1900-0000-414f-7f0e5f080000 pid=2143 clone guuid=9512bf1c-1900-0000-414f-7f0e60080000 pid=2144 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=9512bf1c-1900-0000-414f-7f0e60080000 pid=2144 execve guuid=113d071d-1900-0000-414f-7f0e62080000 pid=2146 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=113d071d-1900-0000-414f-7f0e62080000 pid=2146 clone guuid=cabe0b1d-1900-0000-414f-7f0e63080000 pid=2147 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=cabe0b1d-1900-0000-414f-7f0e63080000 pid=2147 execve guuid=e1db561d-1900-0000-414f-7f0e65080000 pid=2149 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=e1db561d-1900-0000-414f-7f0e65080000 pid=2149 clone guuid=23aa5a1d-1900-0000-414f-7f0e66080000 pid=2150 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=23aa5a1d-1900-0000-414f-7f0e66080000 pid=2150 execve guuid=e9c5a01d-1900-0000-414f-7f0e68080000 pid=2152 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=e9c5a01d-1900-0000-414f-7f0e68080000 pid=2152 clone guuid=37d7a41d-1900-0000-414f-7f0e69080000 pid=2153 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=37d7a41d-1900-0000-414f-7f0e69080000 pid=2153 execve guuid=9353051e-1900-0000-414f-7f0e6c080000 pid=2156 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=9353051e-1900-0000-414f-7f0e6c080000 pid=2156 clone guuid=f8f50c1e-1900-0000-414f-7f0e6d080000 pid=2157 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=f8f50c1e-1900-0000-414f-7f0e6d080000 pid=2157 execve guuid=5e07861e-1900-0000-414f-7f0e6f080000 pid=2159 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=5e07861e-1900-0000-414f-7f0e6f080000 pid=2159 clone guuid=c4288a1e-1900-0000-414f-7f0e70080000 pid=2160 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=c4288a1e-1900-0000-414f-7f0e70080000 pid=2160 execve guuid=b0ffd11e-1900-0000-414f-7f0e72080000 pid=2162 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=b0ffd11e-1900-0000-414f-7f0e72080000 pid=2162 clone guuid=bc83d81e-1900-0000-414f-7f0e73080000 pid=2163 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=bc83d81e-1900-0000-414f-7f0e73080000 pid=2163 execve guuid=62ed241f-1900-0000-414f-7f0e75080000 pid=2165 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=62ed241f-1900-0000-414f-7f0e75080000 pid=2165 clone guuid=a1912b1f-1900-0000-414f-7f0e76080000 pid=2166 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=a1912b1f-1900-0000-414f-7f0e76080000 pid=2166 execve guuid=eddea01f-1900-0000-414f-7f0e78080000 pid=2168 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=eddea01f-1900-0000-414f-7f0e78080000 pid=2168 clone guuid=d4dfa41f-1900-0000-414f-7f0e79080000 pid=2169 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=d4dfa41f-1900-0000-414f-7f0e79080000 pid=2169 execve guuid=53edec1f-1900-0000-414f-7f0e7b080000 pid=2171 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=53edec1f-1900-0000-414f-7f0e7b080000 pid=2171 clone guuid=ead9f01f-1900-0000-414f-7f0e7c080000 pid=2172 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=ead9f01f-1900-0000-414f-7f0e7c080000 pid=2172 execve guuid=711a3720-1900-0000-414f-7f0e7e080000 pid=2174 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=711a3720-1900-0000-414f-7f0e7e080000 pid=2174 clone guuid=8fa13a20-1900-0000-414f-7f0e7f080000 pid=2175 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=8fa13a20-1900-0000-414f-7f0e7f080000 pid=2175 execve guuid=82918220-1900-0000-414f-7f0e81080000 pid=2177 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=82918220-1900-0000-414f-7f0e81080000 pid=2177 clone guuid=967e8d20-1900-0000-414f-7f0e83080000 pid=2179 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=967e8d20-1900-0000-414f-7f0e83080000 pid=2179 execve guuid=68ded420-1900-0000-414f-7f0e85080000 pid=2181 /usr/bin/dash guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=68ded420-1900-0000-414f-7f0e85080000 pid=2181 clone guuid=b4493521-1900-0000-414f-7f0e88080000 pid=2184 /usr/bin/wget dns net send-data write-file guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=b4493521-1900-0000-414f-7f0e88080000 pid=2184 execve guuid=04d84a2f-1900-0000-414f-7f0ead080000 pid=2221 /usr/bin/chmod guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=04d84a2f-1900-0000-414f-7f0ead080000 pid=2221 execve guuid=d9cfab2f-1900-0000-414f-7f0eaf080000 pid=2223 /usr/bin/pgrep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=d9cfab2f-1900-0000-414f-7f0eaf080000 pid=2223 execve guuid=18fc4333-1900-0000-414f-7f0ebb080000 pid=2235 /usr/bin/ps guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=18fc4333-1900-0000-414f-7f0ebb080000 pid=2235 execve guuid=27ee4c33-1900-0000-414f-7f0ebc080000 pid=2236 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=27ee4c33-1900-0000-414f-7f0ebc080000 pid=2236 execve guuid=671d5433-1900-0000-414f-7f0ebd080000 pid=2237 /usr/bin/grep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=671d5433-1900-0000-414f-7f0ebd080000 pid=2237 execve guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248 /tmp/592ucwu dns net send-data write-config write-file guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248 execve guuid=beae8d37-1900-0000-414f-7f0ec9080000 pid=2249 /usr/bin/sleep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=beae8d37-1900-0000-414f-7f0ec9080000 pid=2249 execve guuid=c9a2cbea-1900-0000-414f-7f0ead0a0000 pid=2733 /usr/bin/pgrep guuid=ec88fb08-1900-0000-414f-7f0e22080000 pid=2082->guuid=c9a2cbea-1900-0000-414f-7f0ead0a0000 pid=2733 execve guuid=ff48381c-1900-0000-414f-7f0e5b080000 pid=2139 /usr/bin/cat guuid=3d5c2e1c-1900-0000-414f-7f0e5a080000 pid=2138->guuid=ff48381c-1900-0000-414f-7f0e5b080000 pid=2139 execve guuid=6592431c-1900-0000-414f-7f0e5d080000 pid=2141 /usr/bin/head guuid=3d5c2e1c-1900-0000-414f-7f0e5a080000 pid=2138->guuid=6592431c-1900-0000-414f-7f0e5d080000 pid=2141 execve guuid=041edd20-1900-0000-414f-7f0e86080000 pid=2182 /usr/bin/uname guuid=68ded420-1900-0000-414f-7f0e85080000 pid=2181->guuid=041edd20-1900-0000-414f-7f0e86080000 pid=2182 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=b4493521-1900-0000-414f-7f0e88080000 pid=2184->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 86B 9a60c8a8-f371-5857-8593-5251af805ff1 boberkurwa.phoneparts.icu:80 guuid=b4493521-1900-0000-414f-7f0e88080000 pid=2184->9a60c8a8-f371-5857-8593-5251af805ff1 send: 148B guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ac67e739-1900-0000-414f-7f0ed1080000 pid=2257 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=ac67e739-1900-0000-414f-7f0ed1080000 pid=2257 execve guuid=7b90a23a-1900-0000-414f-7f0ed5080000 pid=2261 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=7b90a23a-1900-0000-414f-7f0ed5080000 pid=2261 execve guuid=f507ed76-1900-0000-414f-7f0e5e090000 pid=2398 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=f507ed76-1900-0000-414f-7f0e5e090000 pid=2398 execve guuid=167af879-1900-0000-414f-7f0e69090000 pid=2409 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=167af879-1900-0000-414f-7f0e69090000 pid=2409 execve guuid=6dbe807a-1900-0000-414f-7f0e6b090000 pid=2411 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=6dbe807a-1900-0000-414f-7f0e6b090000 pid=2411 execve guuid=b142287b-1900-0000-414f-7f0e6f090000 pid=2415 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=b142287b-1900-0000-414f-7f0e6f090000 pid=2415 execve guuid=1256987b-1900-0000-414f-7f0e71090000 pid=2417 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=1256987b-1900-0000-414f-7f0e71090000 pid=2417 execve guuid=8217367c-1900-0000-414f-7f0e75090000 pid=2421 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=8217367c-1900-0000-414f-7f0e75090000 pid=2421 execve guuid=5a5df17c-1900-0000-414f-7f0e79090000 pid=2425 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=5a5df17c-1900-0000-414f-7f0e79090000 pid=2425 execve guuid=38479e7d-1900-0000-414f-7f0e7c090000 pid=2428 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=38479e7d-1900-0000-414f-7f0e7c090000 pid=2428 execve guuid=116ea47e-1900-0000-414f-7f0e81090000 pid=2433 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=116ea47e-1900-0000-414f-7f0e81090000 pid=2433 execve guuid=595d927f-1900-0000-414f-7f0e86090000 pid=2438 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=595d927f-1900-0000-414f-7f0e86090000 pid=2438 execve guuid=11805780-1900-0000-414f-7f0e89090000 pid=2441 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=11805780-1900-0000-414f-7f0e89090000 pid=2441 execve guuid=f7e57181-1900-0000-414f-7f0e90090000 pid=2448 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=f7e57181-1900-0000-414f-7f0e90090000 pid=2448 execve guuid=17ea0882-1900-0000-414f-7f0e93090000 pid=2451 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=17ea0882-1900-0000-414f-7f0e93090000 pid=2451 execve guuid=16b3fe82-1900-0000-414f-7f0e97090000 pid=2455 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=16b3fe82-1900-0000-414f-7f0e97090000 pid=2455 execve guuid=9c5d8d83-1900-0000-414f-7f0e9b090000 pid=2459 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=9c5d8d83-1900-0000-414f-7f0e9b090000 pid=2459 execve guuid=2bc0e784-1900-0000-414f-7f0ea2090000 pid=2466 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=2bc0e784-1900-0000-414f-7f0ea2090000 pid=2466 execve guuid=42569585-1900-0000-414f-7f0ea6090000 pid=2470 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=42569585-1900-0000-414f-7f0ea6090000 pid=2470 execve guuid=f950c886-1900-0000-414f-7f0eab090000 pid=2475 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=f950c886-1900-0000-414f-7f0eab090000 pid=2475 execve guuid=d7fa9787-1900-0000-414f-7f0eaf090000 pid=2479 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=d7fa9787-1900-0000-414f-7f0eaf090000 pid=2479 execve guuid=75078f88-1900-0000-414f-7f0eb4090000 pid=2484 /usr/bin/dash guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=75078f88-1900-0000-414f-7f0eb4090000 pid=2484 execve guuid=0d914389-1900-0000-414f-7f0eb8090000 pid=2488 /tmp/592ucwu dns net send-data zombie guuid=06628937-1900-0000-414f-7f0ec8080000 pid=2248->guuid=0d914389-1900-0000-414f-7f0eb8090000 pid=2488 clone guuid=253a283a-1900-0000-414f-7f0ed3080000 pid=2259 /usr/bin/grep guuid=ac67e739-1900-0000-414f-7f0ed1080000 pid=2257->guuid=253a283a-1900-0000-414f-7f0ed3080000 pid=2259 execve guuid=2d34d03a-1900-0000-414f-7f0ed7080000 pid=2263 /usr/bin/systemctl guuid=7b90a23a-1900-0000-414f-7f0ed5080000 pid=2261->guuid=2d34d03a-1900-0000-414f-7f0ed7080000 pid=2263 execve guuid=d5e91a77-1900-0000-414f-7f0e60090000 pid=2400 /usr/bin/systemctl guuid=f507ed76-1900-0000-414f-7f0e5e090000 pid=2398->guuid=d5e91a77-1900-0000-414f-7f0e60090000 pid=2400 execve guuid=68c9267a-1900-0000-414f-7f0e6a090000 pid=2410 /usr/bin/grep guuid=167af879-1900-0000-414f-7f0e69090000 pid=2409->guuid=68c9267a-1900-0000-414f-7f0e6a090000 pid=2410 execve guuid=4244a67a-1900-0000-414f-7f0e6d090000 pid=2413 /usr/bin/grep guuid=6dbe807a-1900-0000-414f-7f0e6b090000 pid=2411->guuid=4244a67a-1900-0000-414f-7f0e6d090000 pid=2413 execve guuid=88554c7b-1900-0000-414f-7f0e70090000 pid=2416 /usr/bin/grep guuid=b142287b-1900-0000-414f-7f0e6f090000 pid=2415->guuid=88554c7b-1900-0000-414f-7f0e70090000 pid=2416 execve guuid=8fcfc57b-1900-0000-414f-7f0e73090000 pid=2419 /usr/bin/grep guuid=1256987b-1900-0000-414f-7f0e71090000 pid=2417->guuid=8fcfc57b-1900-0000-414f-7f0e73090000 pid=2419 execve guuid=fda46c7c-1900-0000-414f-7f0e77090000 pid=2423 /usr/bin/grep guuid=8217367c-1900-0000-414f-7f0e75090000 pid=2421->guuid=fda46c7c-1900-0000-414f-7f0e77090000 pid=2423 execve guuid=64211e7d-1900-0000-414f-7f0e7a090000 pid=2426 /usr/bin/grep guuid=5a5df17c-1900-0000-414f-7f0e79090000 pid=2425->guuid=64211e7d-1900-0000-414f-7f0e7a090000 pid=2426 execve guuid=1a6fe37d-1900-0000-414f-7f0e7e090000 pid=2430 /usr/bin/grep guuid=38479e7d-1900-0000-414f-7f0e7c090000 pid=2428->guuid=1a6fe37d-1900-0000-414f-7f0e7e090000 pid=2430 execve guuid=645fed7e-1900-0000-414f-7f0e83090000 pid=2435 /usr/bin/grep guuid=116ea47e-1900-0000-414f-7f0e81090000 pid=2433->guuid=645fed7e-1900-0000-414f-7f0e83090000 pid=2435 execve guuid=5c87dc7f-1900-0000-414f-7f0e87090000 pid=2439 /usr/bin/grep guuid=595d927f-1900-0000-414f-7f0e86090000 pid=2438->guuid=5c87dc7f-1900-0000-414f-7f0e87090000 pid=2439 execve guuid=6e90a380-1900-0000-414f-7f0e8b090000 pid=2443 /usr/bin/cp guuid=11805780-1900-0000-414f-7f0e89090000 pid=2441->guuid=6e90a380-1900-0000-414f-7f0e8b090000 pid=2443 execve guuid=3ee02781-1900-0000-414f-7f0e8e090000 pid=2446 /usr/bin/chmod guuid=11805780-1900-0000-414f-7f0e89090000 pid=2441->guuid=3ee02781-1900-0000-414f-7f0e8e090000 pid=2446 execve guuid=7db3a381-1900-0000-414f-7f0e91090000 pid=2449 /usr/bin/grep guuid=f7e57181-1900-0000-414f-7f0e90090000 pid=2448->guuid=7db3a381-1900-0000-414f-7f0e91090000 pid=2449 execve guuid=dd103a82-1900-0000-414f-7f0e94090000 pid=2452 /usr/bin/cp guuid=17ea0882-1900-0000-414f-7f0e93090000 pid=2451->guuid=dd103a82-1900-0000-414f-7f0e94090000 pid=2452 execve guuid=7e13ad82-1900-0000-414f-7f0e95090000 pid=2453 /usr/bin/chmod guuid=17ea0882-1900-0000-414f-7f0e93090000 pid=2451->guuid=7e13ad82-1900-0000-414f-7f0e95090000 pid=2453 execve guuid=55d92e83-1900-0000-414f-7f0e99090000 pid=2457 /usr/bin/grep guuid=16b3fe82-1900-0000-414f-7f0e97090000 pid=2455->guuid=55d92e83-1900-0000-414f-7f0e99090000 pid=2457 execve guuid=a491f183-1900-0000-414f-7f0e9d090000 pid=2461 /usr/bin/cp guuid=9c5d8d83-1900-0000-414f-7f0e9b090000 pid=2459->guuid=a491f183-1900-0000-414f-7f0e9d090000 pid=2461 execve guuid=3db07b84-1900-0000-414f-7f0e9f090000 pid=2463 /usr/bin/chmod guuid=9c5d8d83-1900-0000-414f-7f0e9b090000 pid=2459->guuid=3db07b84-1900-0000-414f-7f0e9f090000 pid=2463 execve guuid=1da92a85-1900-0000-414f-7f0ea3090000 pid=2467 /usr/bin/grep guuid=2bc0e784-1900-0000-414f-7f0ea2090000 pid=2466->guuid=1da92a85-1900-0000-414f-7f0ea3090000 pid=2467 execve guuid=f535d985-1900-0000-414f-7f0ea8090000 pid=2472 /usr/bin/cp guuid=42569585-1900-0000-414f-7f0ea6090000 pid=2470->guuid=f535d985-1900-0000-414f-7f0ea8090000 pid=2472 execve guuid=45746a86-1900-0000-414f-7f0eaa090000 pid=2474 /usr/bin/chmod guuid=42569585-1900-0000-414f-7f0ea6090000 pid=2470->guuid=45746a86-1900-0000-414f-7f0eaa090000 pid=2474 execve guuid=eab30c87-1900-0000-414f-7f0eac090000 pid=2476 /usr/bin/grep guuid=f950c886-1900-0000-414f-7f0eab090000 pid=2475->guuid=eab30c87-1900-0000-414f-7f0eac090000 pid=2476 execve guuid=eeacca87-1900-0000-414f-7f0eb0090000 pid=2480 /usr/bin/cp guuid=d7fa9787-1900-0000-414f-7f0eaf090000 pid=2479->guuid=eeacca87-1900-0000-414f-7f0eb0090000 pid=2480 execve guuid=a9d83d88-1900-0000-414f-7f0eb3090000 pid=2483 /usr/bin/chmod guuid=d7fa9787-1900-0000-414f-7f0eaf090000 pid=2479->guuid=a9d83d88-1900-0000-414f-7f0eb3090000 pid=2483 execve guuid=9d35c088-1900-0000-414f-7f0eb6090000 pid=2486 /usr/bin/grep guuid=75078f88-1900-0000-414f-7f0eb4090000 pid=2484->guuid=9d35c088-1900-0000-414f-7f0eb6090000 pid=2486 execve guuid=0d914389-1900-0000-414f-7f0eb8090000 pid=2488->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B 41a640a2-e439-5bd5-a73e-310f0a6373f1 boberkurwa.phoneparts.icu:32465 guuid=0d914389-1900-0000-414f-7f0eb8090000 pid=2488->41a640a2-e439-5bd5-a73e-310f0a6373f1 con
Threat name:
Linux.Downloader.ShellAgnt
Status:
Malicious
First seen:
2025-12-17 18:26:29 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:wicked antivm botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8cd4879abceee6ebd845fb50ca693303450e349514f080c3ffc27d1605ce3d86

(this sample)

  
Delivery method
Distributed via web download

Comments