MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 948d6dbdf5723d97aa8523006220517cea031e9b3133bf28878566bbd71b65da. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 948d6dbdf5723d97aa8523006220517cea031e9b3133bf28878566bbd71b65da
SHA3-384 hash: bb964a05d5c2c9fac1c2da967f23f8506fb511e4a04b1d5610bf4fc3be9f14565083aac15bbe002462e39a1f681f951f
SHA1 hash: ec73aa8d9603438a2f36912d103d69760713480f
MD5 hash: 8a059f24b35dc6dd0018532ccfde1ff7
humanhash: two-india-wolfram-paris
File name:wget.sh
Download: download sample
Signature Mirai
File size:1'661 bytes
First seen:2025-09-25 10:17:04 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:M0XJByX/KXKJ2XbyX2q+MX1XAXfXf10XmByXYKX3J2X0yXTq+MXK7X9XcXfn:pMELg2q+Wdy/QT72LTq+WKT1mf
TLSH T1BD31B6DED2D2BD62846CDD1AB933069C2006C28E6CAB8FDFFC7614B458E3A5071D4E85
Magika txt
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.209.216/arcee9180bd2b165795dfaaf5d6de60148d34353c66373cc322e49eaf532de435f9 Miraielf mirai
http://158.94.209.216/arm14883298489d57b2242533f561769e8f21737126e8560c4b9955dc701478c23e Mirai32-bit elf mirai Mozi
http://158.94.209.216/arm582ee72be70e8dce122910449268514083943892258ea9b9d21068e03286d03f8 Miraielf mirai
http://158.94.209.216/arm657a6ba282a2ffad3469d83844906606272225fdaeb15c2e2043a11978240de4b Miraielf mirai
http://158.94.209.216/arm75a469ba94c55f39fdf0656a0a1b98c988d699569397587d8e1141a0d928b9eea Miraielf mirai
http://158.94.209.216/mips77637c28bd5ccda2ad3c90c2d34e879fa7e10f1abe04520e5bda11cd7ed69c8e Gafgyt32-bit elf gafgyt Mozi
http://158.94.209.216/mpslafe59ccdfac00527b2983101bc1e5d91361609b4753962e0cb2cc890b8a35d2f Gafgytelf gafgyt
http://158.94.209.216/ppca8de55bad2e1d7f6821139880b74b7345a242dd8f6296f626cdceb07d5f5742e Miraielf mirai
http://158.94.209.216/sh471cf2bcec3f927abc59bb4a57e950a1685ce005380b6a2e3dad891788828dc07 Gafgytelf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
text
First seen:
2025-09-25T07:37:00Z UTC
Last seen:
2025-09-25T07:37:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4c03f6d3-1700-0000-623f-2cf1b60b0000 pid=2998 /usr/bin/sudo guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006 /tmp/sample.bin guuid=4c03f6d3-1700-0000-623f-2cf1b60b0000 pid=2998->guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006 execve guuid=2c0760d6-1700-0000-623f-2cf1bf0b0000 pid=3007 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=2c0760d6-1700-0000-623f-2cf1bf0b0000 pid=3007 execve guuid=cc3b53e3-1700-0000-623f-2cf1e90b0000 pid=3049 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=cc3b53e3-1700-0000-623f-2cf1e90b0000 pid=3049 execve guuid=1187b1e3-1700-0000-623f-2cf1eb0b0000 pid=3051 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=1187b1e3-1700-0000-623f-2cf1eb0b0000 pid=3051 clone guuid=b28a79e4-1700-0000-623f-2cf1ee0b0000 pid=3054 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=b28a79e4-1700-0000-623f-2cf1ee0b0000 pid=3054 execve guuid=68e9c4e4-1700-0000-623f-2cf1f00b0000 pid=3056 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=68e9c4e4-1700-0000-623f-2cf1f00b0000 pid=3056 execve guuid=a0eb0ff2-1700-0000-623f-2cf1120c0000 pid=3090 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=a0eb0ff2-1700-0000-623f-2cf1120c0000 pid=3090 execve guuid=257b5cf2-1700-0000-623f-2cf1140c0000 pid=3092 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=257b5cf2-1700-0000-623f-2cf1140c0000 pid=3092 clone guuid=8f020af4-1700-0000-623f-2cf11b0c0000 pid=3099 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=8f020af4-1700-0000-623f-2cf11b0c0000 pid=3099 execve guuid=33d94ff4-1700-0000-623f-2cf11c0c0000 pid=3100 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=33d94ff4-1700-0000-623f-2cf11c0c0000 pid=3100 execve guuid=f41afb01-1800-0000-623f-2cf13b0c0000 pid=3131 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f41afb01-1800-0000-623f-2cf13b0c0000 pid=3131 execve guuid=633f3e02-1800-0000-623f-2cf13d0c0000 pid=3133 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=633f3e02-1800-0000-623f-2cf13d0c0000 pid=3133 clone guuid=88cda803-1800-0000-623f-2cf1420c0000 pid=3138 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=88cda803-1800-0000-623f-2cf1420c0000 pid=3138 execve guuid=46c71804-1800-0000-623f-2cf1440c0000 pid=3140 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=46c71804-1800-0000-623f-2cf1440c0000 pid=3140 execve guuid=ab613511-1800-0000-623f-2cf1550c0000 pid=3157 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=ab613511-1800-0000-623f-2cf1550c0000 pid=3157 execve guuid=3043bb11-1800-0000-623f-2cf1570c0000 pid=3159 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=3043bb11-1800-0000-623f-2cf1570c0000 pid=3159 clone guuid=08036213-1800-0000-623f-2cf15c0c0000 pid=3164 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=08036213-1800-0000-623f-2cf15c0c0000 pid=3164 execve guuid=39deb613-1800-0000-623f-2cf15d0c0000 pid=3165 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=39deb613-1800-0000-623f-2cf15d0c0000 pid=3165 execve guuid=9c5f8d23-1800-0000-623f-2cf1730c0000 pid=3187 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=9c5f8d23-1800-0000-623f-2cf1730c0000 pid=3187 execve guuid=fe803224-1800-0000-623f-2cf1750c0000 pid=3189 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=fe803224-1800-0000-623f-2cf1750c0000 pid=3189 clone guuid=18200f27-1800-0000-623f-2cf1770c0000 pid=3191 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=18200f27-1800-0000-623f-2cf1770c0000 pid=3191 execve guuid=54f07a27-1800-0000-623f-2cf1780c0000 pid=3192 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=54f07a27-1800-0000-623f-2cf1780c0000 pid=3192 execve guuid=92f27f37-1800-0000-623f-2cf1830c0000 pid=3203 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=92f27f37-1800-0000-623f-2cf1830c0000 pid=3203 execve guuid=37c6f937-1800-0000-623f-2cf1840c0000 pid=3204 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=37c6f937-1800-0000-623f-2cf1840c0000 pid=3204 clone guuid=3360ee38-1800-0000-623f-2cf1860c0000 pid=3206 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=3360ee38-1800-0000-623f-2cf1860c0000 pid=3206 execve guuid=92625f39-1800-0000-623f-2cf1880c0000 pid=3208 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=92625f39-1800-0000-623f-2cf1880c0000 pid=3208 execve guuid=8682c149-1800-0000-623f-2cf1a20c0000 pid=3234 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=8682c149-1800-0000-623f-2cf1a20c0000 pid=3234 execve guuid=90734a4a-1800-0000-623f-2cf1a30c0000 pid=3235 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=90734a4a-1800-0000-623f-2cf1a30c0000 pid=3235 clone guuid=28e0b14b-1800-0000-623f-2cf1a50c0000 pid=3237 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=28e0b14b-1800-0000-623f-2cf1a50c0000 pid=3237 execve guuid=f5ba034c-1800-0000-623f-2cf1a60c0000 pid=3238 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f5ba034c-1800-0000-623f-2cf1a60c0000 pid=3238 execve guuid=f660c158-1800-0000-623f-2cf1a80c0000 pid=3240 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f660c158-1800-0000-623f-2cf1a80c0000 pid=3240 execve guuid=49241c59-1800-0000-623f-2cf1a90c0000 pid=3241 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=49241c59-1800-0000-623f-2cf1a90c0000 pid=3241 clone guuid=f6b8f659-1800-0000-623f-2cf1ac0c0000 pid=3244 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f6b8f659-1800-0000-623f-2cf1ac0c0000 pid=3244 execve guuid=79a3375a-1800-0000-623f-2cf1ad0c0000 pid=3245 /usr/bin/busybox net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=79a3375a-1800-0000-623f-2cf1ad0c0000 pid=3245 execve guuid=21dd5168-1800-0000-623f-2cf1c10c0000 pid=3265 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=21dd5168-1800-0000-623f-2cf1c10c0000 pid=3265 execve guuid=59d77369-1800-0000-623f-2cf1c20c0000 pid=3266 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=59d77369-1800-0000-623f-2cf1c20c0000 pid=3266 clone guuid=6d431b6c-1800-0000-623f-2cf1c40c0000 pid=3268 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=6d431b6c-1800-0000-623f-2cf1c40c0000 pid=3268 execve guuid=a2e57f6c-1800-0000-623f-2cf1c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=a2e57f6c-1800-0000-623f-2cf1c50c0000 pid=3269 execve guuid=2fd08c7c-1800-0000-623f-2cf1db0c0000 pid=3291 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=2fd08c7c-1800-0000-623f-2cf1db0c0000 pid=3291 execve guuid=db0a777e-1800-0000-623f-2cf1dc0c0000 pid=3292 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=db0a777e-1800-0000-623f-2cf1dc0c0000 pid=3292 clone guuid=66971d80-1800-0000-623f-2cf1df0c0000 pid=3295 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=66971d80-1800-0000-623f-2cf1df0c0000 pid=3295 execve guuid=e3486a80-1800-0000-623f-2cf1e00c0000 pid=3296 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=e3486a80-1800-0000-623f-2cf1e00c0000 pid=3296 execve guuid=bb636992-1800-0000-623f-2cf1ff0c0000 pid=3327 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=bb636992-1800-0000-623f-2cf1ff0c0000 pid=3327 execve guuid=e4cfe092-1800-0000-623f-2cf1010d0000 pid=3329 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=e4cfe092-1800-0000-623f-2cf1010d0000 pid=3329 clone guuid=71afb494-1800-0000-623f-2cf1050d0000 pid=3333 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=71afb494-1800-0000-623f-2cf1050d0000 pid=3333 execve guuid=1235ef94-1800-0000-623f-2cf1060d0000 pid=3334 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=1235ef94-1800-0000-623f-2cf1060d0000 pid=3334 execve guuid=b0cf68a3-1800-0000-623f-2cf1240d0000 pid=3364 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=b0cf68a3-1800-0000-623f-2cf1240d0000 pid=3364 execve guuid=f97bf0a3-1800-0000-623f-2cf1260d0000 pid=3366 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f97bf0a3-1800-0000-623f-2cf1260d0000 pid=3366 clone guuid=a9297da4-1800-0000-623f-2cf1290d0000 pid=3369 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=a9297da4-1800-0000-623f-2cf1290d0000 pid=3369 execve guuid=f3e13fa5-1800-0000-623f-2cf12b0d0000 pid=3371 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=f3e13fa5-1800-0000-623f-2cf12b0d0000 pid=3371 execve guuid=d1b534b4-1800-0000-623f-2cf13a0d0000 pid=3386 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=d1b534b4-1800-0000-623f-2cf13a0d0000 pid=3386 execve guuid=a90d99b4-1800-0000-623f-2cf13b0d0000 pid=3387 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=a90d99b4-1800-0000-623f-2cf13b0d0000 pid=3387 clone guuid=c0d981b5-1800-0000-623f-2cf13f0d0000 pid=3391 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=c0d981b5-1800-0000-623f-2cf13f0d0000 pid=3391 execve guuid=ee6fecb5-1800-0000-623f-2cf1400d0000 pid=3392 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=ee6fecb5-1800-0000-623f-2cf1400d0000 pid=3392 execve guuid=d2e85ac7-1800-0000-623f-2cf15c0d0000 pid=3420 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=d2e85ac7-1800-0000-623f-2cf15c0d0000 pid=3420 execve guuid=ddc494c7-1800-0000-623f-2cf15e0d0000 pid=3422 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=ddc494c7-1800-0000-623f-2cf15e0d0000 pid=3422 clone guuid=9c452cc8-1800-0000-623f-2cf1610d0000 pid=3425 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=9c452cc8-1800-0000-623f-2cf1610d0000 pid=3425 execve guuid=c65a9ac8-1800-0000-623f-2cf1630d0000 pid=3427 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=c65a9ac8-1800-0000-623f-2cf1630d0000 pid=3427 execve guuid=af1eebd9-1800-0000-623f-2cf1820d0000 pid=3458 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=af1eebd9-1800-0000-623f-2cf1820d0000 pid=3458 execve guuid=6ed4bada-1800-0000-623f-2cf1840d0000 pid=3460 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=6ed4bada-1800-0000-623f-2cf1840d0000 pid=3460 clone guuid=139982dc-1800-0000-623f-2cf18a0d0000 pid=3466 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=139982dc-1800-0000-623f-2cf18a0d0000 pid=3466 execve guuid=16c7c8dc-1800-0000-623f-2cf18c0d0000 pid=3468 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=16c7c8dc-1800-0000-623f-2cf18c0d0000 pid=3468 execve guuid=9b5324ed-1800-0000-623f-2cf1c10d0000 pid=3521 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=9b5324ed-1800-0000-623f-2cf1c10d0000 pid=3521 execve guuid=b88564ed-1800-0000-623f-2cf1c20d0000 pid=3522 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=b88564ed-1800-0000-623f-2cf1c20d0000 pid=3522 clone guuid=bad1e8ed-1800-0000-623f-2cf1c60d0000 pid=3526 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=bad1e8ed-1800-0000-623f-2cf1c60d0000 pid=3526 execve guuid=e0c722ee-1800-0000-623f-2cf1c80d0000 pid=3528 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=e0c722ee-1800-0000-623f-2cf1c80d0000 pid=3528 execve guuid=be8eb2fb-1800-0000-623f-2cf1e80d0000 pid=3560 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=be8eb2fb-1800-0000-623f-2cf1e80d0000 pid=3560 execve guuid=d1bf14fc-1800-0000-623f-2cf1e90d0000 pid=3561 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=d1bf14fc-1800-0000-623f-2cf1e90d0000 pid=3561 clone guuid=aa7aaffc-1800-0000-623f-2cf1eb0d0000 pid=3563 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=aa7aaffc-1800-0000-623f-2cf1eb0d0000 pid=3563 execve guuid=d65beffc-1800-0000-623f-2cf1ec0d0000 pid=3564 /usr/bin/wget net send-data write-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=d65beffc-1800-0000-623f-2cf1ec0d0000 pid=3564 execve guuid=0fb67a0a-1900-0000-623f-2cf1030e0000 pid=3587 /usr/bin/chmod guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=0fb67a0a-1900-0000-623f-2cf1030e0000 pid=3587 execve guuid=0550bc0a-1900-0000-623f-2cf1050e0000 pid=3589 /usr/bin/dash guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=0550bc0a-1900-0000-623f-2cf1050e0000 pid=3589 clone guuid=5c3b4c0b-1900-0000-623f-2cf1090e0000 pid=3593 /usr/bin/rm delete-file guuid=ff5b26d6-1700-0000-623f-2cf1be0b0000 pid=3006->guuid=5c3b4c0b-1900-0000-623f-2cf1090e0000 pid=3593 execve 09d65e53-632c-52c6-b821-8fe0f69e747e 158.94.209.216:80 guuid=2c0760d6-1700-0000-623f-2cf1bf0b0000 pid=3007->09d65e53-632c-52c6-b821-8fe0f69e747e send: 80B guuid=68e9c4e4-1700-0000-623f-2cf1f00b0000 pid=3056->09d65e53-632c-52c6-b821-8fe0f69e747e send: 80B guuid=33d94ff4-1700-0000-623f-2cf11c0c0000 pid=3100->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=46c71804-1800-0000-623f-2cf1440c0000 pid=3140->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=39deb613-1800-0000-623f-2cf15d0c0000 pid=3165->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=54f07a27-1800-0000-623f-2cf1780c0000 pid=3192->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=92625f39-1800-0000-623f-2cf1880c0000 pid=3208->09d65e53-632c-52c6-b821-8fe0f69e747e send: 81B guuid=f5ba034c-1800-0000-623f-2cf1a60c0000 pid=3238->09d65e53-632c-52c6-b821-8fe0f69e747e send: 80B guuid=79a3375a-1800-0000-623f-2cf1ad0c0000 pid=3245->09d65e53-632c-52c6-b821-8fe0f69e747e send: 80B guuid=a2e57f6c-1800-0000-623f-2cf1c50c0000 pid=3269->09d65e53-632c-52c6-b821-8fe0f69e747e send: 132B guuid=e3486a80-1800-0000-623f-2cf1e00c0000 pid=3296->09d65e53-632c-52c6-b821-8fe0f69e747e send: 132B guuid=1235ef94-1800-0000-623f-2cf1060d0000 pid=3334->09d65e53-632c-52c6-b821-8fe0f69e747e send: 133B guuid=f3e13fa5-1800-0000-623f-2cf12b0d0000 pid=3371->09d65e53-632c-52c6-b821-8fe0f69e747e send: 133B guuid=ee6fecb5-1800-0000-623f-2cf1400d0000 pid=3392->09d65e53-632c-52c6-b821-8fe0f69e747e send: 133B guuid=c65a9ac8-1800-0000-623f-2cf1630d0000 pid=3427->09d65e53-632c-52c6-b821-8fe0f69e747e send: 133B guuid=16c7c8dc-1800-0000-623f-2cf18c0d0000 pid=3468->09d65e53-632c-52c6-b821-8fe0f69e747e send: 133B guuid=e0c722ee-1800-0000-623f-2cf1c80d0000 pid=3528->09d65e53-632c-52c6-b821-8fe0f69e747e send: 132B guuid=d65beffc-1800-0000-623f-2cf1ec0d0000 pid=3564->09d65e53-632c-52c6-b821-8fe0f69e747e send: 132B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2025-09-25 10:18:27 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 948d6dbdf5723d97aa8523006220517cea031e9b3133bf28878566bbd71b65da

(this sample)

  
Delivery method
Distributed via web download

Comments