MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3fd9994b16dc9b14c29f7faf7b5f6c84f44b06fccf82f0031a0871ce5e20e17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: d3fd9994b16dc9b14c29f7faf7b5f6c84f44b06fccf82f0031a0871ce5e20e17
SHA3-384 hash: ef10c738ce3f09b827dc91a31d761e8d33d6a9c7ea2209d85b217691ec4a907478e0d25516ce6dd5e8fb69ae24dfedb0
SHA1 hash: 03ba2d1342c3e37f2043cc58c09ba35e1f3cdfc1
MD5 hash: 39eac7b1423dc42a1a5ad571d62d87a8
humanhash: may-berlin-south-berlin
File name:Pandora.sh
Download: download sample
Signature Mirai
File size:363 bytes
First seen:2026-01-27 23:39:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:IOnFfljMo3FOJ+pUtsAMr70XTR0GONX9faapqR0GONXKsfaaLv:dSJ+uA70DR0GONXtpqR0GONXNLv
TLSH T11BE0DFDB786418BAEEC44F3AB0218084E9CD24A62B903A84E06A7893489CC88309163A
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=313887a8-1600-0000-e44b-f114bc0c0000 pid=3260 /usr/bin/sudo guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267 /tmp/sample.bin guuid=313887a8-1600-0000-e44b-f114bc0c0000 pid=3260->guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267 execve guuid=93e775aa-1600-0000-e44b-f114c60c0000 pid=3270 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=93e775aa-1600-0000-e44b-f114c60c0000 pid=3270 clone guuid=c25d92aa-1600-0000-e44b-f114c70c0000 pid=3271 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=c25d92aa-1600-0000-e44b-f114c70c0000 pid=3271 clone guuid=67e5bfaa-1600-0000-e44b-f114c90c0000 pid=3273 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=67e5bfaa-1600-0000-e44b-f114c90c0000 pid=3273 clone guuid=f50fe5aa-1600-0000-e44b-f114cb0c0000 pid=3275 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=f50fe5aa-1600-0000-e44b-f114cb0c0000 pid=3275 clone guuid=1be510ab-1600-0000-e44b-f114cd0c0000 pid=3277 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=1be510ab-1600-0000-e44b-f114cd0c0000 pid=3277 clone guuid=da2d81ab-1600-0000-e44b-f114d00c0000 pid=3280 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=da2d81ab-1600-0000-e44b-f114d00c0000 pid=3280 clone guuid=feb0adab-1600-0000-e44b-f114d10c0000 pid=3281 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=feb0adab-1600-0000-e44b-f114d10c0000 pid=3281 clone guuid=3c5ccfab-1600-0000-e44b-f114d40c0000 pid=3284 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=3c5ccfab-1600-0000-e44b-f114d40c0000 pid=3284 clone guuid=d4093cac-1600-0000-e44b-f114d70c0000 pid=3287 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=d4093cac-1600-0000-e44b-f114d70c0000 pid=3287 clone guuid=601d5fac-1600-0000-e44b-f114d90c0000 pid=3289 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=601d5fac-1600-0000-e44b-f114d90c0000 pid=3289 clone guuid=4207d9ad-1600-0000-e44b-f114e00c0000 pid=3296 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=4207d9ad-1600-0000-e44b-f114e00c0000 pid=3296 clone guuid=68a8efad-1600-0000-e44b-f114e10c0000 pid=3297 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=68a8efad-1600-0000-e44b-f114e10c0000 pid=3297 clone guuid=a5d41cae-1600-0000-e44b-f114e20c0000 pid=3298 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=a5d41cae-1600-0000-e44b-f114e20c0000 pid=3298 clone guuid=21b1acaf-1600-0000-e44b-f114ea0c0000 pid=3306 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=21b1acaf-1600-0000-e44b-f114ea0c0000 pid=3306 clone guuid=ff915bb1-1600-0000-e44b-f114ec0c0000 pid=3308 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=ff915bb1-1600-0000-e44b-f114ec0c0000 pid=3308 clone guuid=077068b1-1600-0000-e44b-f114ed0c0000 pid=3309 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=077068b1-1600-0000-e44b-f114ed0c0000 pid=3309 clone guuid=a33f7cb3-1600-0000-e44b-f114f40c0000 pid=3316 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=a33f7cb3-1600-0000-e44b-f114f40c0000 pid=3316 clone guuid=c148a3b3-1600-0000-e44b-f114f60c0000 pid=3318 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=c148a3b3-1600-0000-e44b-f114f60c0000 pid=3318 clone guuid=ff372ab5-1600-0000-e44b-f114fb0c0000 pid=3323 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=ff372ab5-1600-0000-e44b-f114fb0c0000 pid=3323 clone guuid=b72d50b5-1600-0000-e44b-f114fc0c0000 pid=3324 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=b72d50b5-1600-0000-e44b-f114fc0c0000 pid=3324 clone guuid=32bdc6b7-1600-0000-e44b-f114ff0c0000 pid=3327 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=32bdc6b7-1600-0000-e44b-f114ff0c0000 pid=3327 clone guuid=50adebb7-1600-0000-e44b-f114000d0000 pid=3328 /usr/bin/bash zombie guuid=79bb0baa-1600-0000-e44b-f114c30c0000 pid=3267->guuid=50adebb7-1600-0000-e44b-f114000d0000 pid=3328 clone guuid=43a0a0aa-1600-0000-e44b-f114c80c0000 pid=3272 /usr/bin/wget net send-data write-file guuid=93e775aa-1600-0000-e44b-f114c60c0000 pid=3270->guuid=43a0a0aa-1600-0000-e44b-f114c80c0000 pid=3272 execve guuid=4e5a9db9-1600-0000-e44b-f114060d0000 pid=3334 /usr/bin/chmod guuid=93e775aa-1600-0000-e44b-f114c60c0000 pid=3270->guuid=4e5a9db9-1600-0000-e44b-f114060d0000 pid=3334 execve guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341 /tmp/px86 net guuid=93e775aa-1600-0000-e44b-f114c60c0000 pid=3270->guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341 execve guuid=27353bab-1600-0000-e44b-f114ce0c0000 pid=3278 /usr/bin/curl net send-data guuid=c25d92aa-1600-0000-e44b-f114c70c0000 pid=3271->guuid=27353bab-1600-0000-e44b-f114ce0c0000 pid=3278 execve 9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb 87.106.143.220:80 guuid=43a0a0aa-1600-0000-e44b-f114c80c0000 pid=3272->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 153B guuid=1ad6edaa-1600-0000-e44b-f114cc0c0000 pid=3276 /usr/bin/wget net send-data write-file guuid=67e5bfaa-1600-0000-e44b-f114c90c0000 pid=3273->guuid=1ad6edaa-1600-0000-e44b-f114cc0c0000 pid=3276 execve guuid=ac94decb-1600-0000-e44b-f114270d0000 pid=3367 /usr/bin/chmod guuid=67e5bfaa-1600-0000-e44b-f114c90c0000 pid=3273->guuid=ac94decb-1600-0000-e44b-f114270d0000 pid=3367 execve guuid=e17325cf-1600-0000-e44b-f114310d0000 pid=3377 /usr/bin/bash guuid=67e5bfaa-1600-0000-e44b-f114c90c0000 pid=3273->guuid=e17325cf-1600-0000-e44b-f114310d0000 pid=3377 clone guuid=a087e9ab-1600-0000-e44b-f114d50c0000 pid=3285 /usr/bin/curl net send-data write-file guuid=f50fe5aa-1600-0000-e44b-f114cb0c0000 pid=3275->guuid=a087e9ab-1600-0000-e44b-f114d50c0000 pid=3285 execve guuid=e16a23d8-1600-0000-e44b-f114530d0000 pid=3411 /usr/bin/chmod guuid=f50fe5aa-1600-0000-e44b-f114cb0c0000 pid=3275->guuid=e16a23d8-1600-0000-e44b-f114530d0000 pid=3411 execve guuid=23875ad9-1600-0000-e44b-f114580d0000 pid=3416 /usr/bin/bash guuid=f50fe5aa-1600-0000-e44b-f114cb0c0000 pid=3275->guuid=23875ad9-1600-0000-e44b-f114580d0000 pid=3416 clone guuid=1ad6edaa-1600-0000-e44b-f114cc0c0000 pid=3276->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=1af4c4ab-1600-0000-e44b-f114d30c0000 pid=3283 /usr/bin/wget net send-data write-file guuid=1be510ab-1600-0000-e44b-f114cd0c0000 pid=3277->guuid=1af4c4ab-1600-0000-e44b-f114d30c0000 pid=3283 execve guuid=6c0c3ecc-1600-0000-e44b-f114290d0000 pid=3369 /usr/bin/chmod guuid=1be510ab-1600-0000-e44b-f114cd0c0000 pid=3277->guuid=6c0c3ecc-1600-0000-e44b-f114290d0000 pid=3369 execve guuid=bd96f6d1-1600-0000-e44b-f1143e0d0000 pid=3390 /usr/bin/bash guuid=1be510ab-1600-0000-e44b-f114cd0c0000 pid=3277->guuid=bd96f6d1-1600-0000-e44b-f1143e0d0000 pid=3390 clone guuid=27353bab-1600-0000-e44b-f114ce0c0000 pid=3278->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 102B guuid=ee0b13ad-1600-0000-e44b-f114dd0c0000 pid=3293 /usr/bin/curl net send-data write-file guuid=da2d81ab-1600-0000-e44b-f114d00c0000 pid=3280->guuid=ee0b13ad-1600-0000-e44b-f114dd0c0000 pid=3293 execve guuid=902e6ddb-1600-0000-e44b-f114640d0000 pid=3428 /usr/bin/chmod guuid=da2d81ab-1600-0000-e44b-f114d00c0000 pid=3280->guuid=902e6ddb-1600-0000-e44b-f114640d0000 pid=3428 execve guuid=2e2e37dc-1600-0000-e44b-f1146b0d0000 pid=3435 /usr/bin/bash guuid=da2d81ab-1600-0000-e44b-f114d00c0000 pid=3280->guuid=2e2e37dc-1600-0000-e44b-f1146b0d0000 pid=3435 clone guuid=36fbb9ac-1600-0000-e44b-f114db0c0000 pid=3291 /usr/bin/wget net send-data write-file guuid=feb0adab-1600-0000-e44b-f114d10c0000 pid=3281->guuid=36fbb9ac-1600-0000-e44b-f114db0c0000 pid=3291 execve guuid=ee9d1ecc-1600-0000-e44b-f114280d0000 pid=3368 /usr/bin/chmod guuid=feb0adab-1600-0000-e44b-f114d10c0000 pid=3281->guuid=ee9d1ecc-1600-0000-e44b-f114280d0000 pid=3368 execve guuid=0e249cce-1600-0000-e44b-f1142e0d0000 pid=3374 /usr/bin/bash guuid=feb0adab-1600-0000-e44b-f114d10c0000 pid=3281->guuid=0e249cce-1600-0000-e44b-f1142e0d0000 pid=3374 clone guuid=1af4c4ab-1600-0000-e44b-f114d30c0000 pid=3283->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=5f6f3dac-1600-0000-e44b-f114d80c0000 pid=3288 /usr/bin/curl net send-data write-file guuid=3c5ccfab-1600-0000-e44b-f114d40c0000 pid=3284->guuid=5f6f3dac-1600-0000-e44b-f114d80c0000 pid=3288 execve guuid=a7fafbdf-1600-0000-e44b-f114850d0000 pid=3461 /usr/bin/chmod guuid=3c5ccfab-1600-0000-e44b-f114d40c0000 pid=3284->guuid=a7fafbdf-1600-0000-e44b-f114850d0000 pid=3461 execve guuid=a8f149e0-1600-0000-e44b-f114860d0000 pid=3462 /usr/bin/bash guuid=3c5ccfab-1600-0000-e44b-f114d40c0000 pid=3284->guuid=a8f149e0-1600-0000-e44b-f114860d0000 pid=3462 clone guuid=a087e9ab-1600-0000-e44b-f114d50c0000 pid=3285->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B guuid=72dc42ae-1600-0000-e44b-f114e40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=d4093cac-1600-0000-e44b-f114d70c0000 pid=3287->guuid=72dc42ae-1600-0000-e44b-f114e40c0000 pid=3300 execve guuid=db1560d1-1600-0000-e44b-f1143c0d0000 pid=3388 /usr/bin/chmod guuid=d4093cac-1600-0000-e44b-f114d70c0000 pid=3287->guuid=db1560d1-1600-0000-e44b-f1143c0d0000 pid=3388 execve guuid=a2b7a9d3-1600-0000-e44b-f114470d0000 pid=3399 /usr/bin/bash guuid=d4093cac-1600-0000-e44b-f114d70c0000 pid=3287->guuid=a2b7a9d3-1600-0000-e44b-f114470d0000 pid=3399 clone guuid=5f6f3dac-1600-0000-e44b-f114d80c0000 pid=3288->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 102B guuid=d34acfac-1600-0000-e44b-f114dc0c0000 pid=3292 /usr/bin/curl net send-data guuid=601d5fac-1600-0000-e44b-f114d90c0000 pid=3289->guuid=d34acfac-1600-0000-e44b-f114dc0c0000 pid=3292 execve guuid=36fbb9ac-1600-0000-e44b-f114db0c0000 pid=3291->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 153B guuid=d34acfac-1600-0000-e44b-f114dc0c0000 pid=3292->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B guuid=ee0b13ad-1600-0000-e44b-f114dd0c0000 pid=3293->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B guuid=67ed4eaf-1600-0000-e44b-f114e80c0000 pid=3304 /usr/bin/wget net send-data write-file guuid=4207d9ad-1600-0000-e44b-f114e00c0000 pid=3296->guuid=67ed4eaf-1600-0000-e44b-f114e80c0000 pid=3304 execve guuid=38db02d2-1600-0000-e44b-f114400d0000 pid=3392 /usr/bin/chmod guuid=4207d9ad-1600-0000-e44b-f114e00c0000 pid=3296->guuid=38db02d2-1600-0000-e44b-f114400d0000 pid=3392 execve guuid=efa705d4-1600-0000-e44b-f1144b0d0000 pid=3403 /usr/bin/bash guuid=4207d9ad-1600-0000-e44b-f114e00c0000 pid=3296->guuid=efa705d4-1600-0000-e44b-f1144b0d0000 pid=3403 clone guuid=ddfe84af-1600-0000-e44b-f114e90c0000 pid=3305 /usr/bin/curl net send-data write-file guuid=68a8efad-1600-0000-e44b-f114e10c0000 pid=3297->guuid=ddfe84af-1600-0000-e44b-f114e90c0000 pid=3305 execve guuid=27adb1d9-1600-0000-e44b-f1145a0d0000 pid=3418 /usr/bin/chmod guuid=68a8efad-1600-0000-e44b-f114e10c0000 pid=3297->guuid=27adb1d9-1600-0000-e44b-f1145a0d0000 pid=3418 execve guuid=2e22b9db-1600-0000-e44b-f114680d0000 pid=3432 /usr/bin/bash guuid=68a8efad-1600-0000-e44b-f114e10c0000 pid=3297->guuid=2e22b9db-1600-0000-e44b-f114680d0000 pid=3432 clone guuid=ccab21af-1600-0000-e44b-f114e70c0000 pid=3303 /usr/bin/wget net send-data write-file guuid=a5d41cae-1600-0000-e44b-f114e20c0000 pid=3298->guuid=ccab21af-1600-0000-e44b-f114e70c0000 pid=3303 execve guuid=5cd2e8cc-1600-0000-e44b-f1142a0d0000 pid=3370 /usr/bin/chmod guuid=a5d41cae-1600-0000-e44b-f114e20c0000 pid=3298->guuid=5cd2e8cc-1600-0000-e44b-f1142a0d0000 pid=3370 execve guuid=daac2ed0-1600-0000-e44b-f114370d0000 pid=3383 /usr/bin/bash guuid=a5d41cae-1600-0000-e44b-f114e20c0000 pid=3298->guuid=daac2ed0-1600-0000-e44b-f114370d0000 pid=3383 clone guuid=72dc42ae-1600-0000-e44b-f114e40c0000 pid=3300->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=ccab21af-1600-0000-e44b-f114e70c0000 pid=3303->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=67ed4eaf-1600-0000-e44b-f114e80c0000 pid=3304->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=ddfe84af-1600-0000-e44b-f114e90c0000 pid=3305->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B guuid=853fd4b1-1600-0000-e44b-f114ee0c0000 pid=3310 /usr/bin/curl net send-data write-file guuid=21b1acaf-1600-0000-e44b-f114ea0c0000 pid=3306->guuid=853fd4b1-1600-0000-e44b-f114ee0c0000 pid=3310 execve guuid=64eaccdd-1600-0000-e44b-f114760d0000 pid=3446 /usr/bin/chmod guuid=21b1acaf-1600-0000-e44b-f114ea0c0000 pid=3306->guuid=64eaccdd-1600-0000-e44b-f114760d0000 pid=3446 execve guuid=cb9d97de-1600-0000-e44b-f1147a0d0000 pid=3450 /usr/bin/bash guuid=21b1acaf-1600-0000-e44b-f114ea0c0000 pid=3306->guuid=cb9d97de-1600-0000-e44b-f1147a0d0000 pid=3450 clone guuid=ec761fb3-1600-0000-e44b-f114f10c0000 pid=3313 /usr/bin/wget net send-data write-file guuid=ff915bb1-1600-0000-e44b-f114ec0c0000 pid=3308->guuid=ec761fb3-1600-0000-e44b-f114f10c0000 pid=3313 execve guuid=b2d57cdb-1600-0000-e44b-f114650d0000 pid=3429 /usr/bin/chmod guuid=ff915bb1-1600-0000-e44b-f114ec0c0000 pid=3308->guuid=b2d57cdb-1600-0000-e44b-f114650d0000 pid=3429 execve guuid=8a1941dc-1600-0000-e44b-f1146d0d0000 pid=3437 /usr/bin/bash guuid=ff915bb1-1600-0000-e44b-f114ec0c0000 pid=3308->guuid=8a1941dc-1600-0000-e44b-f1146d0d0000 pid=3437 clone guuid=aa0662b3-1600-0000-e44b-f114f30c0000 pid=3315 /usr/bin/curl net send-data write-file guuid=077068b1-1600-0000-e44b-f114ed0c0000 pid=3309->guuid=aa0662b3-1600-0000-e44b-f114f30c0000 pid=3315 execve guuid=0c1e8dd9-1600-0000-e44b-f114590d0000 pid=3417 /usr/bin/chmod guuid=077068b1-1600-0000-e44b-f114ed0c0000 pid=3309->guuid=0c1e8dd9-1600-0000-e44b-f114590d0000 pid=3417 execve guuid=d8c83cda-1600-0000-e44b-f1145e0d0000 pid=3422 /usr/bin/bash guuid=077068b1-1600-0000-e44b-f114ed0c0000 pid=3309->guuid=d8c83cda-1600-0000-e44b-f1145e0d0000 pid=3422 clone guuid=853fd4b1-1600-0000-e44b-f114ee0c0000 pid=3310->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B guuid=ec761fb3-1600-0000-e44b-f114f10c0000 pid=3313->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 153B guuid=aa0662b3-1600-0000-e44b-f114f30c0000 pid=3315->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 102B guuid=a7c7f8b4-1600-0000-e44b-f114fa0c0000 pid=3322 /usr/bin/wget net send-data write-file guuid=a33f7cb3-1600-0000-e44b-f114f40c0000 pid=3316->guuid=a7c7f8b4-1600-0000-e44b-f114fa0c0000 pid=3322 execve guuid=1b3735d1-1600-0000-e44b-f1143a0d0000 pid=3386 /usr/bin/chmod guuid=a33f7cb3-1600-0000-e44b-f114f40c0000 pid=3316->guuid=1b3735d1-1600-0000-e44b-f1143a0d0000 pid=3386 execve guuid=076df6d2-1600-0000-e44b-f114430d0000 pid=3395 /usr/bin/bash guuid=a33f7cb3-1600-0000-e44b-f114f40c0000 pid=3316->guuid=076df6d2-1600-0000-e44b-f114430d0000 pid=3395 clone guuid=cf683eb4-1600-0000-e44b-f114f80c0000 pid=3320 /usr/bin/curl net send-data write-file guuid=c148a3b3-1600-0000-e44b-f114f60c0000 pid=3318->guuid=cf683eb4-1600-0000-e44b-f114f80c0000 pid=3320 execve guuid=5689c2de-1600-0000-e44b-f1147b0d0000 pid=3451 /usr/bin/chmod guuid=c148a3b3-1600-0000-e44b-f114f60c0000 pid=3318->guuid=5689c2de-1600-0000-e44b-f1147b0d0000 pid=3451 execve guuid=a4ad5fdf-1600-0000-e44b-f114800d0000 pid=3456 /usr/bin/bash guuid=c148a3b3-1600-0000-e44b-f114f60c0000 pid=3318->guuid=a4ad5fdf-1600-0000-e44b-f114800d0000 pid=3456 clone guuid=cf683eb4-1600-0000-e44b-f114f80c0000 pid=3320->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 102B guuid=a7c7f8b4-1600-0000-e44b-f114fa0c0000 pid=3322->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 153B guuid=3fdfb5b6-1600-0000-e44b-f114fe0c0000 pid=3326 /usr/bin/wget net send-data write-file guuid=ff372ab5-1600-0000-e44b-f114fb0c0000 pid=3323->guuid=3fdfb5b6-1600-0000-e44b-f114fe0c0000 pid=3326 execve guuid=789c95c5-1600-0000-e44b-f114250d0000 pid=3365 /usr/bin/chmod guuid=ff372ab5-1600-0000-e44b-f114fb0c0000 pid=3323->guuid=789c95c5-1600-0000-e44b-f114250d0000 pid=3365 execve guuid=7f335dc9-1600-0000-e44b-f114260d0000 pid=3366 /usr/bin/bash guuid=ff372ab5-1600-0000-e44b-f114fb0c0000 pid=3323->guuid=7f335dc9-1600-0000-e44b-f114260d0000 pid=3366 clone guuid=65a517bb-1600-0000-e44b-f1140b0d0000 pid=3339 /usr/bin/curl net send-data write-file guuid=b72d50b5-1600-0000-e44b-f114fc0c0000 pid=3324->guuid=65a517bb-1600-0000-e44b-f1140b0d0000 pid=3339 execve guuid=16fca1dd-1600-0000-e44b-f114730d0000 pid=3443 /usr/bin/chmod guuid=b72d50b5-1600-0000-e44b-f114fc0c0000 pid=3324->guuid=16fca1dd-1600-0000-e44b-f114730d0000 pid=3443 execve guuid=b63e33de-1600-0000-e44b-f114780d0000 pid=3448 /usr/bin/bash guuid=b72d50b5-1600-0000-e44b-f114fc0c0000 pid=3324->guuid=b63e33de-1600-0000-e44b-f114780d0000 pid=3448 clone guuid=3fdfb5b6-1600-0000-e44b-f114fe0c0000 pid=3326->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 154B guuid=73f7cbb8-1600-0000-e44b-f114030d0000 pid=3331 /usr/bin/wget net send-data write-file guuid=32bdc6b7-1600-0000-e44b-f114ff0c0000 pid=3327->guuid=73f7cbb8-1600-0000-e44b-f114030d0000 pid=3331 execve guuid=5aeeeada-1600-0000-e44b-f114610d0000 pid=3425 /usr/bin/chmod guuid=32bdc6b7-1600-0000-e44b-f114ff0c0000 pid=3327->guuid=5aeeeada-1600-0000-e44b-f114610d0000 pid=3425 execve guuid=c8869bdb-1600-0000-e44b-f114670d0000 pid=3431 /usr/bin/bash guuid=32bdc6b7-1600-0000-e44b-f114ff0c0000 pid=3327->guuid=c8869bdb-1600-0000-e44b-f114670d0000 pid=3431 clone guuid=eda5cdb9-1600-0000-e44b-f114070d0000 pid=3335 /usr/bin/curl net send-data write-file guuid=50adebb7-1600-0000-e44b-f114000d0000 pid=3328->guuid=eda5cdb9-1600-0000-e44b-f114070d0000 pid=3335 execve guuid=315e27e1-1600-0000-e44b-f1148a0d0000 pid=3466 /usr/bin/chmod guuid=50adebb7-1600-0000-e44b-f114000d0000 pid=3328->guuid=315e27e1-1600-0000-e44b-f1148a0d0000 pid=3466 execve guuid=1bf166e1-1600-0000-e44b-f1148c0d0000 pid=3468 /usr/bin/bash guuid=50adebb7-1600-0000-e44b-f114000d0000 pid=3328->guuid=1bf166e1-1600-0000-e44b-f1148c0d0000 pid=3468 clone guuid=73f7cbb8-1600-0000-e44b-f114030d0000 pid=3331->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 153B guuid=eda5cdb9-1600-0000-e44b-f114070d0000 pid=3335->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 102B guuid=65a517bb-1600-0000-e44b-f1140b0d0000 pid=3339->9e9c0a9c-c4ab-5441-8da9-c9da7c8c13bb send: 103B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=897679be-1600-0000-e44b-f114170d0000 pid=3351 /tmp/px86 zombie guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341->guuid=897679be-1600-0000-e44b-f114170d0000 pid=3351 clone guuid=748f81be-1600-0000-e44b-f114180d0000 pid=3352 /tmp/px86 guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341->guuid=748f81be-1600-0000-e44b-f114180d0000 pid=3352 clone guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353 /tmp/px86 net send-data zombie guuid=fd2f8abb-1600-0000-e44b-f1140d0d0000 pid=3341->guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353 clone guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 7ffbe0fe-3af4-5653-ad38-6efd0c10027d 87.106.143.220:1791 guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->7ffbe0fe-3af4-5653-ad38-6efd0c10027d send: 9B guuid=5ee0eebf-1600-0000-e44b-f1141c0d0000 pid=3356 /tmp/px86 guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->guuid=5ee0eebf-1600-0000-e44b-f1141c0d0000 pid=3356 clone guuid=3112f7bf-1600-0000-e44b-f1141d0d0000 pid=3357 /tmp/px86 guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->guuid=3112f7bf-1600-0000-e44b-f1141d0d0000 pid=3357 clone guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358 /tmp/px86 net net-scan send-data guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358 clone guuid=fb4b1a59-1d00-0000-e44b-f114f1140000 pid=5361 /tmp/px86 net send-data guuid=0e888bbe-1600-0000-e44b-f114190d0000 pid=3353->guuid=fb4b1a59-1d00-0000-e44b-f114f1140000 pid=5361 clone guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con fbe1e2e5-b822-59e8-8e9c-abc0f6157413 34.96.122.236:23 guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358->fbe1e2e5-b822-59e8-8e9c-abc0f6157413 send: 40B guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358|send-data send-data to 4097 IP addresses review logs to see them all guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358->guuid=7b0704c0-1600-0000-e44b-f1141e0d0000 pid=3358|send-data send 93e3b2b7-c72e-547e-b75c-5b1472b746fe 171.225.223.53:80 guuid=fb4b1a59-1d00-0000-e44b-f114f1140000 pid=5361->93e3b2b7-c72e-547e-b75c-5b1472b746fe send: 16781312B guuid=5b582e59-1d00-0000-e44b-f114f2140000 pid=5362 /tmp/px86 guuid=fb4b1a59-1d00-0000-e44b-f114f1140000 pid=5361->guuid=5b582e59-1d00-0000-e44b-f114f2140000 pid=5362 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-27 23:40:47 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (20512) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d3fd9994b16dc9b14c29f7faf7b5f6c84f44b06fccf82f0031a0871ce5e20e17

(this sample)

Comments