MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ad1d841e47273d9b9150d8eea3e53cabf4c9fe224e7ae90a13197ef7f070a557. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: ad1d841e47273d9b9150d8eea3e53cabf4c9fe224e7ae90a13197ef7f070a557
SHA3-384 hash: 460b8ed5e3ade9610fc3bf3997cca4e995faa0b61958ba8c43db210c26ec9cf4f1d326072b5ea45b9c265b431b2aa09a
SHA1 hash: 08689c638898d56999659fc64abb0abb2165de22
MD5 hash: 4eb8d73c3580e8b6a53d417e54a2516d
humanhash: vermont-chicken-early-washington
File name:tplink.sh
Download: download sample
Signature Mirai
File size:1'091 bytes
First seen:2025-09-30 05:32:58 UTC
Last seen:2025-09-30 23:05:33 UTC
File type: sh
MIME type:text/plain
ssdeep 12:A+G+paSKY+JNIQA+SvKKY+r+T+UY+n++I+NE+tT+WzCEh:wdNIBKXvF
TLSH T14B1104F9001D91041814EB50B0560C29ECBBF7A672A69AF5947FF423A98B9B07B21F39
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.44/UnHAnaAW.arma0822f8acdc5b0d20b2bd2bcc92a2c341c18ee04e38fae3407d3d1ff9eef85a1 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm5dceec67b91a53c720d94e3bbf5a7081b389bbf3c8fc616487730da3e8ae280b7 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm63a7134b8240e560d81d4a1effbb04a8f873e34ad332212b62de07807212f1b82 Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.arm7e63475639ec1c8ec9643203a4902fbc59e7c8272cadd7db355c5da6ba6ea98ed Miraiarm elf geofenced mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.sh49311cc7b2b4f4777b9ffbf50978f85055aed70ea42bac6be542cb66d8de2de0f Miraielf geofenced mirai opendir SuperH ua-wget USA
http://213.209.143.44/UnHAnaAW.ppcfb5e0ae697fafd5f58e98e0b74d9160cf8ed08c73fc329d02e4cdb4739485804 Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://213.209.143.44/UnHAnaAW.mips91e7b4318985ce375aef13265584ffb72b936593a99d10e6ff98305d962c2623 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.mpslb7e145aa84a71ee51c3f45351d82d2aaa179562dacc4547efc2f06e30664e2d4 Miraielf geofenced mips mirai opendir ua-wget USA
http://213.209.143.44/UnHAnaAW.spcb536d143397fd3c4c964adeeebc4935d7c5ca8ce21de1ff035a94862161d3d19 Miraielf geofenced mirai opendir sparc ua-wget USA
http://213.209.143.44/UnHAnaAW.x863fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf geofenced mirai opendir ua-wget USA x86
http://213.209.143.44/UnHAnaAW.x86_643fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf mirai ua-wget
http://213.209.143.44/UnHAnaAW.i5863fa5a4a14056a35151506bab32705cdaabaac752616a425d913ab6c7299162e5 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
ps1
First seen:
2025-09-30T02:52:00Z UTC
Last seen:
2025-09-30T02:52:00Z UTC
Hits:
~10
Detections:
HEUR:Backdoor.Linux.Mirai.ba HEUR:Backdoor.Linux.Mirai.b HEUR:Backdoor.Linux.Mirai.au HEUR:Trojan-Downloader.Shell.Agent.cl HEUR:Exploit.Linux.CVE-2017-17215.a
Status:
terminated
Behavior Graph:
%3 guuid=454ef207-1700-0000-ad1b-a9775c0a0000 pid=2652 /usr/bin/sudo guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660 /tmp/sample.bin guuid=454ef207-1700-0000-ad1b-a9775c0a0000 pid=2652->guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660 execve guuid=623ca20a-1700-0000-ad1b-a977650a0000 pid=2661 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=623ca20a-1700-0000-ad1b-a977650a0000 pid=2661 execve guuid=2ea6cc10-1700-0000-ad1b-a977770a0000 pid=2679 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=2ea6cc10-1700-0000-ad1b-a977770a0000 pid=2679 execve guuid=a7521a11-1700-0000-ad1b-a977790a0000 pid=2681 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=a7521a11-1700-0000-ad1b-a977790a0000 pid=2681 clone guuid=1c91bc11-1700-0000-ad1b-a9777d0a0000 pid=2685 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=1c91bc11-1700-0000-ad1b-a9777d0a0000 pid=2685 execve guuid=de8c521b-1700-0000-ad1b-a977960a0000 pid=2710 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=de8c521b-1700-0000-ad1b-a977960a0000 pid=2710 execve guuid=665d9f1b-1700-0000-ad1b-a977980a0000 pid=2712 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=665d9f1b-1700-0000-ad1b-a977980a0000 pid=2712 clone guuid=fd407e1c-1700-0000-ad1b-a9779c0a0000 pid=2716 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=fd407e1c-1700-0000-ad1b-a9779c0a0000 pid=2716 execve guuid=f2b5ad25-1700-0000-ad1b-a977bc0a0000 pid=2748 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=f2b5ad25-1700-0000-ad1b-a977bc0a0000 pid=2748 execve guuid=3fa5e225-1700-0000-ad1b-a977be0a0000 pid=2750 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=3fa5e225-1700-0000-ad1b-a977be0a0000 pid=2750 clone guuid=878e5d26-1700-0000-ad1b-a977c20a0000 pid=2754 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=878e5d26-1700-0000-ad1b-a977c20a0000 pid=2754 execve guuid=d2c75131-1700-0000-ad1b-a977e10a0000 pid=2785 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=d2c75131-1700-0000-ad1b-a977e10a0000 pid=2785 execve guuid=cf498e31-1700-0000-ad1b-a977e20a0000 pid=2786 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=cf498e31-1700-0000-ad1b-a977e20a0000 pid=2786 clone guuid=22ca2032-1700-0000-ad1b-a977e50a0000 pid=2789 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=22ca2032-1700-0000-ad1b-a977e50a0000 pid=2789 execve guuid=9dbc173b-1700-0000-ad1b-a977030b0000 pid=2819 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=9dbc173b-1700-0000-ad1b-a977030b0000 pid=2819 execve guuid=72fa513b-1700-0000-ad1b-a977050b0000 pid=2821 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=72fa513b-1700-0000-ad1b-a977050b0000 pid=2821 clone guuid=e308cb3b-1700-0000-ad1b-a977090b0000 pid=2825 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=e308cb3b-1700-0000-ad1b-a977090b0000 pid=2825 execve guuid=17461c40-1700-0000-ad1b-a977150b0000 pid=2837 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=17461c40-1700-0000-ad1b-a977150b0000 pid=2837 execve guuid=e8c75740-1700-0000-ad1b-a977170b0000 pid=2839 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=e8c75740-1700-0000-ad1b-a977170b0000 pid=2839 clone guuid=c65f6340-1700-0000-ad1b-a977180b0000 pid=2840 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=c65f6340-1700-0000-ad1b-a977180b0000 pid=2840 execve guuid=35814645-1700-0000-ad1b-a977270b0000 pid=2855 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=35814645-1700-0000-ad1b-a977270b0000 pid=2855 execve guuid=bc559945-1700-0000-ad1b-a977290b0000 pid=2857 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=bc559945-1700-0000-ad1b-a977290b0000 pid=2857 clone guuid=802fa046-1700-0000-ad1b-a9772d0b0000 pid=2861 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=802fa046-1700-0000-ad1b-a9772d0b0000 pid=2861 execve guuid=38bc804b-1700-0000-ad1b-a9773c0b0000 pid=2876 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=38bc804b-1700-0000-ad1b-a9773c0b0000 pid=2876 execve guuid=a6a2b54b-1700-0000-ad1b-a9773e0b0000 pid=2878 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=a6a2b54b-1700-0000-ad1b-a9773e0b0000 pid=2878 clone guuid=b450284c-1700-0000-ad1b-a977410b0000 pid=2881 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=b450284c-1700-0000-ad1b-a977410b0000 pid=2881 execve guuid=c4f53a50-1700-0000-ad1b-a977500b0000 pid=2896 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=c4f53a50-1700-0000-ad1b-a977500b0000 pid=2896 execve guuid=702d7450-1700-0000-ad1b-a977520b0000 pid=2898 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=702d7450-1700-0000-ad1b-a977520b0000 pid=2898 clone guuid=b9fdf150-1700-0000-ad1b-a977560b0000 pid=2902 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=b9fdf150-1700-0000-ad1b-a977560b0000 pid=2902 execve guuid=6ccf9855-1700-0000-ad1b-a977690b0000 pid=2921 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=6ccf9855-1700-0000-ad1b-a977690b0000 pid=2921 execve guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923 /home/sandbox/UnHAnaAW.x86 net guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923 execve guuid=763cfd55-1700-0000-ad1b-a977700b0000 pid=2928 /usr/bin/wget net send-data write-file guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=763cfd55-1700-0000-ad1b-a977700b0000 pid=2928 execve guuid=99ee9369-1700-0000-ad1b-a977950b0000 pid=2965 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=99ee9369-1700-0000-ad1b-a977950b0000 pid=2965 execve guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966 /home/sandbox/UnHAnaAW.x86_64 net guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966 execve guuid=743e2cd7-1800-0000-ad1b-a977ab0e0000 pid=3755 /usr/bin/wget net guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=743e2cd7-1800-0000-ad1b-a977ab0e0000 pid=3755 execve guuid=6c6820de-1800-0000-ad1b-a977be0e0000 pid=3774 /usr/bin/chmod guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=6c6820de-1800-0000-ad1b-a977be0e0000 pid=3774 execve guuid=8ff5c0de-1800-0000-ad1b-a977c40e0000 pid=3780 /usr/bin/dash guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=8ff5c0de-1800-0000-ad1b-a977c40e0000 pid=3780 clone guuid=20b801df-1800-0000-ad1b-a977c50e0000 pid=3781 /usr/bin/rm guuid=e7075d0a-1700-0000-ad1b-a977640a0000 pid=2660->guuid=20b801df-1800-0000-ad1b-a977c50e0000 pid=3781 execve 9a5bfd7d-6ca1-5e69-b1de-790583636c52 213.209.143.44:80 guuid=623ca20a-1700-0000-ad1b-a977650a0000 pid=2661->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=1c91bc11-1700-0000-ad1b-a9777d0a0000 pid=2685->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=fd407e1c-1700-0000-ad1b-a9779c0a0000 pid=2716->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=878e5d26-1700-0000-ad1b-a977c20a0000 pid=2754->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=22ca2032-1700-0000-ad1b-a977e50a0000 pid=2789->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=e308cb3b-1700-0000-ad1b-a977090b0000 pid=2825->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=c65f6340-1700-0000-ad1b-a977180b0000 pid=2840->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=802fa046-1700-0000-ad1b-a9772d0b0000 pid=2861->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 142B guuid=b450284c-1700-0000-ad1b-a977410b0000 pid=2881->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B guuid=b9fdf150-1700-0000-ad1b-a977560b0000 pid=2902->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 141B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7599ee55-1700-0000-ad1b-a9776d0b0000 pid=2925 /home/sandbox/UnHAnaAW.x86 guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923->guuid=7599ee55-1700-0000-ad1b-a9776d0b0000 pid=2925 clone guuid=a6ccf255-1700-0000-ad1b-a9776e0b0000 pid=2926 /home/sandbox/UnHAnaAW.x86 guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923->guuid=a6ccf255-1700-0000-ad1b-a9776e0b0000 pid=2926 clone guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927 /home/sandbox/UnHAnaAW.x86 net send-data zombie guuid=555ad355-1700-0000-ad1b-a9776b0b0000 pid=2923->guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927 clone guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 795831f1-3652-5898-8295-aba18a81ec9e 213.209.143.44:1024 guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->795831f1-3652-5898-8295-aba18a81ec9e send: 12B guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929 clone guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930 clone guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931 clone guuid=f8bc0956-1700-0000-ad1b-a977740b0000 pid=2932 /home/sandbox/UnHAnaAW.x86 guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=f8bc0956-1700-0000-ad1b-a977740b0000 pid=2932 clone guuid=0bb70c56-1700-0000-ad1b-a977750b0000 pid=2933 /home/sandbox/UnHAnaAW.x86 guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=0bb70c56-1700-0000-ad1b-a977750b0000 pid=2933 clone guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934 /home/sandbox/UnHAnaAW.x86 net net-scan send-data guuid=26f5f555-1700-0000-ad1b-a9776f0b0000 pid=2927->guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934 clone guuid=763cfd55-1700-0000-ad1b-a977700b0000 pid=2928->9a5bfd7d-6ca1-5e69-b1de-790583636c52 send: 144B guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929|send-data send-data to 160 IP addresses review logs to see them all guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929->guuid=6feafe55-1700-0000-ad1b-a977710b0000 pid=2929|send-data send guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930|send-data send-data to 160 IP addresses review logs to see them all guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930->guuid=8ed90256-1700-0000-ad1b-a977720b0000 pid=2930|send-data send guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931|send-data send-data to 1024 IP addresses review logs to see them all guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931->guuid=5cf30556-1700-0000-ad1b-a977730b0000 pid=2931|send-data send guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934|send-data send-data to 384 IP addresses review logs to see them all guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934->guuid=a5261256-1700-0000-ad1b-a977760b0000 pid=2934|send-data send guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 191dff31-3ba9-595b-9e5c-dc6cfa1beabf 0.0.0.0:23455 guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966->191dff31-3ba9-595b-9e5c-dc6cfa1beabf con guuid=2f0814d7-1800-0000-ad1b-a977a80e0000 pid=3752 /home/sandbox/UnHAnaAW.x86_64 guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966->guuid=2f0814d7-1800-0000-ad1b-a977a80e0000 pid=3752 clone guuid=bb5a1dd7-1800-0000-ad1b-a977a90e0000 pid=3753 /home/sandbox/UnHAnaAW.x86_64 guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966->guuid=bb5a1dd7-1800-0000-ad1b-a977a90e0000 pid=3753 clone guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754 /home/sandbox/UnHAnaAW.x86_64 net send-data zombie guuid=2c7cdf69-1700-0000-ad1b-a977960b0000 pid=2966->guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754 clone guuid=df00c37b-2200-0000-ad1b-a977d8140000 pid=5336 /home/sandbox/UnHAnaAW.x86_64 guuid=2f0814d7-1800-0000-ad1b-a977a80e0000 pid=3752->guuid=df00c37b-2200-0000-ad1b-a977d8140000 pid=5336 clone guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337 /home/sandbox/UnHAnaAW.x86_64 net zombie guuid=2f0814d7-1800-0000-ad1b-a977a80e0000 pid=3752->guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337 clone guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->795831f1-3652-5898-8295-aba18a81ec9e send: 14B guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756 clone guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757 clone guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758 clone guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759 /home/sandbox/UnHAnaAW.x86_64 net send-data guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759 clone guuid=59dc3fd7-1800-0000-ad1b-a977b00e0000 pid=3760 /home/sandbox/UnHAnaAW.x86_64 guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=59dc3fd7-1800-0000-ad1b-a977b00e0000 pid=3760 clone guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=b5b024d7-1800-0000-ad1b-a977aa0e0000 pid=3754->guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761 clone guuid=743e2cd7-1800-0000-ad1b-a977ab0e0000 pid=3755->9a5bfd7d-6ca1-5e69-b1de-790583636c52 con guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756|send-data send-data to 4097 IP addresses review logs to see them all guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756->guuid=e82f2ed7-1800-0000-ad1b-a977ac0e0000 pid=3756|send-data send guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757|send-data send-data to 4097 IP addresses review logs to see them all guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757->guuid=a60d32d7-1800-0000-ad1b-a977ad0e0000 pid=3757|send-data send guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758|send-data send-data to 4097 IP addresses review logs to see them all guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758->guuid=493f35d7-1800-0000-ad1b-a977ae0e0000 pid=3758|send-data send guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759->795831f1-3652-5898-8295-aba18a81ec9e send: 12B guuid=701a1679-2200-0000-ad1b-a977d6140000 pid=5334 /home/sandbox/UnHAnaAW.x86_64 guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759->guuid=701a1679-2200-0000-ad1b-a977d6140000 pid=5334 clone guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=27c23bd7-1800-0000-ad1b-a977af0e0000 pid=3759->guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335 clone guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761|send-data send-data to 4097 IP addresses review logs to see them all guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761->guuid=2f7544d7-1800-0000-ad1b-a977b10e0000 pid=3761|send-data send guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335|send-data send-data to 4097 IP addresses review logs to see them all guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335->guuid=f5db1b79-2200-0000-ad1b-a977d7140000 pid=5335|send-data send guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->795831f1-3652-5898-8295-aba18a81ec9e con guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338 clone guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339 clone guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340 clone guuid=fd84df7b-2200-0000-ad1b-a977dd140000 pid=5341 /home/sandbox/UnHAnaAW.x86_64 net guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=fd84df7b-2200-0000-ad1b-a977dd140000 pid=5341 clone guuid=e9b3e27b-2200-0000-ad1b-a977de140000 pid=5342 /home/sandbox/UnHAnaAW.x86_64 guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=e9b3e27b-2200-0000-ad1b-a977de140000 pid=5342 clone guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=041bc67b-2200-0000-ad1b-a977d9140000 pid=5337->guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343 clone guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338|send-data send-data to 2240 IP addresses review logs to see them all guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338->guuid=2daad47b-2200-0000-ad1b-a977da140000 pid=5338|send-data send guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339|send-data send-data to 2240 IP addresses review logs to see them all guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339->guuid=f0b5d77b-2200-0000-ad1b-a977db140000 pid=5339|send-data send guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340|send-data send-data to 4097 IP addresses review logs to see them all guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340->guuid=2ca8db7b-2200-0000-ad1b-a977dc140000 pid=5340|send-data send guuid=fd84df7b-2200-0000-ad1b-a977dd140000 pid=5341->795831f1-3652-5898-8295-aba18a81ec9e con guuid=ba907da6-2300-0000-ad1b-a977e0140000 pid=5344 /home/sandbox/UnHAnaAW.x86_64 guuid=fd84df7b-2200-0000-ad1b-a977dd140000 pid=5341->guuid=ba907da6-2300-0000-ad1b-a977e0140000 pid=5344 clone guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345 /home/sandbox/UnHAnaAW.x86_64 net net-scan send-data guuid=fd84df7b-2200-0000-ad1b-a977dd140000 pid=5341->guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345 clone guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343|send-data send-data to 4097 IP addresses review logs to see them all guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343->guuid=c9c7e57b-2200-0000-ad1b-a977df140000 pid=5343|send-data send guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345|send-data send-data to 3456 IP addresses review logs to see them all guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345->guuid=968182a6-2300-0000-ad1b-a977e1140000 pid=5345|send-data send
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-30 05:34:23 UTC
File Type:
Text (JavaScript)
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ad1d841e47273d9b9150d8eea3e53cabf4c9fe224e7ae90a13197ef7f070a557

(this sample)

  
Delivery method
Distributed via web download

Comments