MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 941ef0028ee51d84bea103270e3e65089d029b19decad4a1136ba325d3df41fc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 941ef0028ee51d84bea103270e3e65089d029b19decad4a1136ba325d3df41fc
SHA3-384 hash: 3918378080c3716b7978b39ad5668fc6e8c4446dc52a3223296ff04e6c9119dcf7200059fd2aa8e679c43ca8d586a79b
SHA1 hash: a00bcaadb7928a3316f20175413ef3b82f54a99c
MD5 hash: b4f51f5cc63464ecb276431a679ebe97
humanhash: mike-iowa-london-freddie
File name:auto
Download: download sample
Signature Mirai
File size:413 bytes
First seen:2026-01-13 16:19:42 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:Ygv9CJJ96GesZe4N6lf0e4NG6uNOCY9dRLGesZeiKFYlf0eiKFM6uNOwvn:YO92J9tLu+HCY9dYL6F8lFdHan
TLSH T128E02BEA30380BC3032E46D434664CED162410346FE45E16C2836DFE252A5F8345F311
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://77.221.152.211/check1.shbd81875f09c4eb86c1b4322491af6c12bcb4a21141edfcb49431780b214d8467 Miraish ua-wget
http://77.221.152.211/check.sh53554c8b213ad04cd5c7a14edfc92cef19d19060acef548091a4a3504aeb5941 Miraish ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-13T13:32:00Z UTC
Last seen:
2026-01-15T07:01:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=9da8e408-1a00-0000-ffdf-3e42550b0000 pid=2901 /usr/bin/sudo guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907 /tmp/sample.bin guuid=9da8e408-1a00-0000-ffdf-3e42550b0000 pid=2901->guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907 execve guuid=4fbeaa16-1a00-0000-ffdf-3e42620b0000 pid=2914 /usr/bin/uname guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907->guuid=4fbeaa16-1a00-0000-ffdf-3e42620b0000 pid=2914 execve guuid=b1ca0717-1a00-0000-ffdf-3e42630b0000 pid=2915 /usr/bin/curl net send-data guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907->guuid=b1ca0717-1a00-0000-ffdf-3e42630b0000 pid=2915 execve guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916 /usr/bin/bash guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907->guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916 execve guuid=f6b1f5e2-1d00-0000-ffdf-3e4237100000 pid=4151 /usr/bin/bash guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907->guuid=f6b1f5e2-1d00-0000-ffdf-3e4237100000 pid=4151 execve guuid=916b01e3-1d00-0000-ffdf-3e4238100000 pid=4152 /usr/bin/bash guuid=ad0ace0a-1a00-0000-ffdf-3e425b0b0000 pid=2907->guuid=916b01e3-1d00-0000-ffdf-3e4238100000 pid=4152 execve 66bedfa7-f5b5-5fb6-937f-c65dc36db775 77.221.152.211:80 guuid=b1ca0717-1a00-0000-ffdf-3e42630b0000 pid=2915->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 86B guuid=6640071f-1a00-0000-ffdf-3e42700b0000 pid=2928 /usr/bin/bash guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=6640071f-1a00-0000-ffdf-3e42700b0000 pid=2928 clone guuid=16d4451f-1a00-0000-ffdf-3e42710b0000 pid=2929 /usr/bin/grep guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=16d4451f-1a00-0000-ffdf-3e42710b0000 pid=2929 execve guuid=73232e20-1a00-0000-ffdf-3e42720b0000 pid=2930 /usr/bin/bash guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=73232e20-1a00-0000-ffdf-3e42720b0000 pid=2930 clone guuid=fdf93f20-1a00-0000-ffdf-3e42730b0000 pid=2931 /usr/bin/bash guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=fdf93f20-1a00-0000-ffdf-3e42730b0000 pid=2931 clone guuid=8e72e520-1a00-0000-ffdf-3e42750b0000 pid=2933 /usr/bin/pgrep guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=8e72e520-1a00-0000-ffdf-3e42750b0000 pid=2933 execve guuid=46acdc24-1a00-0000-ffdf-3e42770b0000 pid=2935 /usr/bin/rm delete-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=46acdc24-1a00-0000-ffdf-3e42770b0000 pid=2935 execve guuid=73e5ac2a-1a00-0000-ffdf-3e42830b0000 pid=2947 /usr/bin/sleep guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=73e5ac2a-1a00-0000-ffdf-3e42830b0000 pid=2947 execve guuid=216a2d55-1b00-0000-ffdf-3e42a40d0000 pid=3492 /usr/bin/curl net send-data write-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=216a2d55-1b00-0000-ffdf-3e42a40d0000 pid=3492 execve guuid=a29b837b-1b00-0000-ffdf-3e42e40d0000 pid=3556 /usr/bin/wget net send-data write-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=a29b837b-1b00-0000-ffdf-3e42e40d0000 pid=3556 execve guuid=2aafb5b7-1b00-0000-ffdf-3e42610e0000 pid=3681 /usr/bin/sleep guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=2aafb5b7-1b00-0000-ffdf-3e42610e0000 pid=3681 execve guuid=0e0e91a6-1c00-0000-ffdf-3e42e60f0000 pid=4070 /usr/bin/chmod guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=0e0e91a6-1c00-0000-ffdf-3e42e60f0000 pid=4070 execve guuid=1a2d3aa7-1c00-0000-ffdf-3e42e70f0000 pid=4071 /var/tmp/syst3md mprotect-exec guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=1a2d3aa7-1c00-0000-ffdf-3e42e70f0000 pid=4071 execve guuid=a3d7d1b4-1c00-0000-ffdf-3e42f10f0000 pid=4081 /usr/bin/rm guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=a3d7d1b4-1c00-0000-ffdf-3e42f10f0000 pid=4081 execve guuid=aa7232b5-1c00-0000-ffdf-3e42f40f0000 pid=4084 /usr/bin/sleep guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=aa7232b5-1c00-0000-ffdf-3e42f40f0000 pid=4084 execve guuid=bc879ddf-1d00-0000-ffdf-3e4230100000 pid=4144 /usr/bin/rm guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=bc879ddf-1d00-0000-ffdf-3e4230100000 pid=4144 execve guuid=64560ae0-1d00-0000-ffdf-3e4231100000 pid=4145 /usr/bin/rm delete-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=64560ae0-1d00-0000-ffdf-3e4231100000 pid=4145 execve guuid=cee88be0-1d00-0000-ffdf-3e4232100000 pid=4146 /usr/bin/rm delete-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=cee88be0-1d00-0000-ffdf-3e4232100000 pid=4146 execve guuid=134ef8e0-1d00-0000-ffdf-3e4233100000 pid=4147 /usr/bin/rm delete-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=134ef8e0-1d00-0000-ffdf-3e4233100000 pid=4147 execve guuid=a2b96fe1-1d00-0000-ffdf-3e4234100000 pid=4148 /usr/bin/rm delete-file guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=a2b96fe1-1d00-0000-ffdf-3e4234100000 pid=4148 execve guuid=f905c7e1-1d00-0000-ffdf-3e4235100000 pid=4149 /usr/bin/rm guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=f905c7e1-1d00-0000-ffdf-3e4235100000 pid=4149 execve guuid=19ef31e2-1d00-0000-ffdf-3e4236100000 pid=4150 /usr/bin/clear guuid=3af81317-1a00-0000-ffdf-3e42640b0000 pid=2916->guuid=19ef31e2-1d00-0000-ffdf-3e4236100000 pid=4150 execve guuid=cf494120-1a00-0000-ffdf-3e42740b0000 pid=2932 /usr/bin/bash guuid=73232e20-1a00-0000-ffdf-3e42720b0000 pid=2930->guuid=cf494120-1a00-0000-ffdf-3e42740b0000 pid=2932 clone guuid=216a2d55-1b00-0000-ffdf-3e42a40d0000 pid=3492->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 85B guuid=a29b837b-1b00-0000-ffdf-3e42e40d0000 pid=3556->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 136B guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080 /var/tmp/syst3md net send-data zombie guuid=1a2d3aa7-1c00-0000-ffdf-3e42e70f0000 pid=4071->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080 clone 264d1a60-de56-5988-9f1d-ff71ad4aa4d6 141.94.96.71:3333 guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->264d1a60-de56-5988-9f1d-ff71ad4aa4d6 send: 546B guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4083 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4083 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4085 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4085 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4086 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4086 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4087 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4087 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4088 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4088 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4091 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4091 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4092 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4092 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4093 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4093 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4094 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4094 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4100 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4100 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4101 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4101 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4102 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4102 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4103 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4103 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4104 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4104 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4105 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4105 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4106 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4106 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4107 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4107 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4108 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4108 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4109 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4109 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4110 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4110 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4111 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4111 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4112 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4112 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4113 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4113 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4114 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4114 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4115 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4115 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4116 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4116 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4117 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4117 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4118 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4118 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4119 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4119 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4120 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4120 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4121 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4121 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4122 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4122 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4123 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4123 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4124 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4124 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4125 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4125 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4126 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4126 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4127 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4127 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4128 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4128 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4129 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4129 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4130 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4130 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4131 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4131 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4132 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4132 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4133 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4133 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4134 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4134 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4135 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4135 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4136 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4136 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4137 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4137 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4138 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4138 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4139 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4139 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4140 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4140 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4141 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4141 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4142 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4142 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4143 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4143 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4154 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4154 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4155 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4155 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4156 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4156 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4157 /var/tmp/syst3md zombie guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4157 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4158 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4158 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4159 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4159 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4160 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4160 clone guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4161 /var/tmp/syst3md guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4080->guuid=96d1acb4-1c00-0000-ffdf-3e42f00f0000 pid=4161 clone guuid=3b8a08e3-1d00-0000-ffdf-3e4239100000 pid=4153 /usr/bin/wget net send-data write-file guuid=f6b1f5e2-1d00-0000-ffdf-3e4237100000 pid=4151->guuid=3b8a08e3-1d00-0000-ffdf-3e4239100000 pid=4153 execve guuid=3b8a08e3-1d00-0000-ffdf-3e4239100000 pid=4153->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 137B
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 941ef0028ee51d84bea103270e3e65089d029b19decad4a1136ba325d3df41fc

(this sample)

  
Delivery method
Distributed via web download

Comments