MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 da104a20960f8c7d057849001fa35fb7fb1ea09ea38357f7e5333ef9542dddaa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: da104a20960f8c7d057849001fa35fb7fb1ea09ea38357f7e5333ef9542dddaa
SHA3-384 hash: 1d01567ecedbaa1558c267f96c36b518c0d14524dac29230a140ad18d94f3bf75dab1d2d15e1f4d1e038e0d5fa525cac
SHA1 hash: 6ddbdae9ca888497ff46043e692e437caa931783
MD5 hash: ff4dc4a191014da18364cacc2eefeaa2
humanhash: six-hydrogen-hawaii-carbon
File name:toto
Download: download sample
Signature Mirai
File size:1'634 bytes
First seen:2025-08-11 11:42:33 UTC
Last seen:2025-08-12 04:27:08 UTC
File type: sh
MIME type:text/plain
ssdeep 48:QvZi4wh3G1949Q9Y9M9e6L8qSL8qy8qnb8qWF8qV5:AZi2QYwE3LWLOjbCFp5
TLSH T1703146EF4B54B9F46686C8EAF1635B399998D9E30CC10D28E6ACA5A31C9CC2C3125DD0
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.188.83.28/lmips4cc60746df828d8a6d7bc51881a1078a4f8854a5b7ebd7df9ac3855e8b10817f Gafgytelf gafgyt ua-wget
http://103.188.83.28/lmpsl9996d7334c378cb7a5fe762694784d903da1465eddaaf48f7a3c251d3402aea1 Gafgytelf gafgyt ua-wget
http://103.188.83.28/larm4e2614e30221d3aa30eab0871a643e49ffccead7538bcc58563cafc87f854467a Miraielf mirai ua-wget
http://103.188.83.28/larm5377eb7d0dbf209450e4c6cbfd5db6c1789e53b3f71149cfc61a3ca7982ff6d44 Miraielf mirai ua-wget
http://103.188.83.28/larm739deb6b227df9d3ceda2c754d72c8485d2aa739af2303403665d769e3be9ff9c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
5
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=26f4d766-1900-0000-a5fe-35dd66140000 pid=5222 /usr/bin/sudo guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223 /tmp/sample.bin guuid=26f4d766-1900-0000-a5fe-35dd66140000 pid=5222->guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223 execve guuid=172ebf69-1900-0000-a5fe-35dd68140000 pid=5224 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=172ebf69-1900-0000-a5fe-35dd68140000 pid=5224 execve guuid=d0e31c6a-1900-0000-a5fe-35dd69140000 pid=5225 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=d0e31c6a-1900-0000-a5fe-35dd69140000 pid=5225 execve guuid=fb79716a-1900-0000-a5fe-35dd6a140000 pid=5226 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fb79716a-1900-0000-a5fe-35dd6a140000 pid=5226 execve guuid=da46ca6a-1900-0000-a5fe-35dd6b140000 pid=5227 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=da46ca6a-1900-0000-a5fe-35dd6b140000 pid=5227 execve guuid=246f256b-1900-0000-a5fe-35dd6c140000 pid=5228 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=246f256b-1900-0000-a5fe-35dd6c140000 pid=5228 execve guuid=2b998e6b-1900-0000-a5fe-35dd6d140000 pid=5229 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=2b998e6b-1900-0000-a5fe-35dd6d140000 pid=5229 execve guuid=807ced6b-1900-0000-a5fe-35dd6e140000 pid=5230 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=807ced6b-1900-0000-a5fe-35dd6e140000 pid=5230 execve guuid=3642b36c-1900-0000-a5fe-35dd6f140000 pid=5231 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=3642b36c-1900-0000-a5fe-35dd6f140000 pid=5231 execve guuid=596d636d-1900-0000-a5fe-35dd70140000 pid=5232 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=596d636d-1900-0000-a5fe-35dd70140000 pid=5232 execve guuid=f9ef0b6e-1900-0000-a5fe-35dd71140000 pid=5233 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f9ef0b6e-1900-0000-a5fe-35dd71140000 pid=5233 execve guuid=c581b46e-1900-0000-a5fe-35dd72140000 pid=5234 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c581b46e-1900-0000-a5fe-35dd72140000 pid=5234 execve guuid=5f42706f-1900-0000-a5fe-35dd73140000 pid=5235 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=5f42706f-1900-0000-a5fe-35dd73140000 pid=5235 execve guuid=b5f50070-1900-0000-a5fe-35dd74140000 pid=5236 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=b5f50070-1900-0000-a5fe-35dd74140000 pid=5236 execve guuid=294c7870-1900-0000-a5fe-35dd75140000 pid=5237 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=294c7870-1900-0000-a5fe-35dd75140000 pid=5237 execve guuid=bdfbe770-1900-0000-a5fe-35dd76140000 pid=5238 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=bdfbe770-1900-0000-a5fe-35dd76140000 pid=5238 execve guuid=1c174f71-1900-0000-a5fe-35dd77140000 pid=5239 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=1c174f71-1900-0000-a5fe-35dd77140000 pid=5239 execve guuid=4caac671-1900-0000-a5fe-35dd78140000 pid=5240 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4caac671-1900-0000-a5fe-35dd78140000 pid=5240 execve guuid=d4894572-1900-0000-a5fe-35dd79140000 pid=5241 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=d4894572-1900-0000-a5fe-35dd79140000 pid=5241 execve guuid=af61c072-1900-0000-a5fe-35dd7a140000 pid=5242 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=af61c072-1900-0000-a5fe-35dd7a140000 pid=5242 execve guuid=36553673-1900-0000-a5fe-35dd7b140000 pid=5243 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=36553673-1900-0000-a5fe-35dd7b140000 pid=5243 execve guuid=bf88ab73-1900-0000-a5fe-35dd7c140000 pid=5244 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=bf88ab73-1900-0000-a5fe-35dd7c140000 pid=5244 execve guuid=17a51f74-1900-0000-a5fe-35dd7d140000 pid=5245 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=17a51f74-1900-0000-a5fe-35dd7d140000 pid=5245 execve guuid=4a868774-1900-0000-a5fe-35dd7e140000 pid=5246 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4a868774-1900-0000-a5fe-35dd7e140000 pid=5246 execve guuid=65fbea74-1900-0000-a5fe-35dd7f140000 pid=5247 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=65fbea74-1900-0000-a5fe-35dd7f140000 pid=5247 execve guuid=75785275-1900-0000-a5fe-35dd80140000 pid=5248 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=75785275-1900-0000-a5fe-35dd80140000 pid=5248 execve guuid=80adb475-1900-0000-a5fe-35dd81140000 pid=5249 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=80adb475-1900-0000-a5fe-35dd81140000 pid=5249 execve guuid=4d6c1176-1900-0000-a5fe-35dd82140000 pid=5250 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4d6c1176-1900-0000-a5fe-35dd82140000 pid=5250 execve guuid=2e2e7776-1900-0000-a5fe-35dd83140000 pid=5251 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=2e2e7776-1900-0000-a5fe-35dd83140000 pid=5251 execve guuid=a7afe476-1900-0000-a5fe-35dd84140000 pid=5252 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=a7afe476-1900-0000-a5fe-35dd84140000 pid=5252 execve guuid=98e44f77-1900-0000-a5fe-35dd85140000 pid=5253 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=98e44f77-1900-0000-a5fe-35dd85140000 pid=5253 execve guuid=98e3a078-1900-0000-a5fe-35dd86140000 pid=5254 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=98e3a078-1900-0000-a5fe-35dd86140000 pid=5254 execve guuid=4ecc9579-1900-0000-a5fe-35dd87140000 pid=5255 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4ecc9579-1900-0000-a5fe-35dd87140000 pid=5255 execve guuid=04b5a37a-1900-0000-a5fe-35dd88140000 pid=5256 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=04b5a37a-1900-0000-a5fe-35dd88140000 pid=5256 execve guuid=55a9a67b-1900-0000-a5fe-35dd89140000 pid=5257 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=55a9a67b-1900-0000-a5fe-35dd89140000 pid=5257 execve guuid=21242a7c-1900-0000-a5fe-35dd8a140000 pid=5258 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=21242a7c-1900-0000-a5fe-35dd8a140000 pid=5258 execve guuid=478fd87c-1900-0000-a5fe-35dd8b140000 pid=5259 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=478fd87c-1900-0000-a5fe-35dd8b140000 pid=5259 execve guuid=9f07667d-1900-0000-a5fe-35dd8c140000 pid=5260 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=9f07667d-1900-0000-a5fe-35dd8c140000 pid=5260 execve guuid=eecefc7d-1900-0000-a5fe-35dd8d140000 pid=5261 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=eecefc7d-1900-0000-a5fe-35dd8d140000 pid=5261 execve guuid=c540697e-1900-0000-a5fe-35dd8e140000 pid=5262 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c540697e-1900-0000-a5fe-35dd8e140000 pid=5262 execve guuid=f5b3d67e-1900-0000-a5fe-35dd8f140000 pid=5263 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f5b3d67e-1900-0000-a5fe-35dd8f140000 pid=5263 execve guuid=5a90377f-1900-0000-a5fe-35dd90140000 pid=5264 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=5a90377f-1900-0000-a5fe-35dd90140000 pid=5264 execve guuid=4f74957f-1900-0000-a5fe-35dd91140000 pid=5265 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4f74957f-1900-0000-a5fe-35dd91140000 pid=5265 execve guuid=4225f97f-1900-0000-a5fe-35dd92140000 pid=5266 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4225f97f-1900-0000-a5fe-35dd92140000 pid=5266 execve guuid=d3465a80-1900-0000-a5fe-35dd93140000 pid=5267 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=d3465a80-1900-0000-a5fe-35dd93140000 pid=5267 execve guuid=9105b680-1900-0000-a5fe-35dd94140000 pid=5268 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=9105b680-1900-0000-a5fe-35dd94140000 pid=5268 execve guuid=c6d01581-1900-0000-a5fe-35dd95140000 pid=5269 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c6d01581-1900-0000-a5fe-35dd95140000 pid=5269 execve guuid=67bbd381-1900-0000-a5fe-35dd96140000 pid=5270 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=67bbd381-1900-0000-a5fe-35dd96140000 pid=5270 execve guuid=863f9a82-1900-0000-a5fe-35dd97140000 pid=5271 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=863f9a82-1900-0000-a5fe-35dd97140000 pid=5271 execve guuid=67886383-1900-0000-a5fe-35dd98140000 pid=5272 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=67886383-1900-0000-a5fe-35dd98140000 pid=5272 execve guuid=47bb1584-1900-0000-a5fe-35dd99140000 pid=5273 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=47bb1584-1900-0000-a5fe-35dd99140000 pid=5273 execve guuid=e6cebc84-1900-0000-a5fe-35dd9a140000 pid=5274 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=e6cebc84-1900-0000-a5fe-35dd9a140000 pid=5274 execve guuid=edca5785-1900-0000-a5fe-35dd9b140000 pid=5275 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=edca5785-1900-0000-a5fe-35dd9b140000 pid=5275 execve guuid=6c9ff085-1900-0000-a5fe-35dd9c140000 pid=5276 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=6c9ff085-1900-0000-a5fe-35dd9c140000 pid=5276 execve guuid=42907986-1900-0000-a5fe-35dd9d140000 pid=5277 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=42907986-1900-0000-a5fe-35dd9d140000 pid=5277 execve guuid=a546fb86-1900-0000-a5fe-35dd9e140000 pid=5278 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=a546fb86-1900-0000-a5fe-35dd9e140000 pid=5278 execve guuid=33257a87-1900-0000-a5fe-35dd9f140000 pid=5279 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=33257a87-1900-0000-a5fe-35dd9f140000 pid=5279 execve guuid=f1f3ec87-1900-0000-a5fe-35dda0140000 pid=5280 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f1f3ec87-1900-0000-a5fe-35dda0140000 pid=5280 execve guuid=f6795e88-1900-0000-a5fe-35dda1140000 pid=5281 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f6795e88-1900-0000-a5fe-35dda1140000 pid=5281 execve guuid=8bd8cd88-1900-0000-a5fe-35dda2140000 pid=5282 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8bd8cd88-1900-0000-a5fe-35dda2140000 pid=5282 execve guuid=c9e43789-1900-0000-a5fe-35dda3140000 pid=5283 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c9e43789-1900-0000-a5fe-35dda3140000 pid=5283 execve guuid=71239c89-1900-0000-a5fe-35dda4140000 pid=5284 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=71239c89-1900-0000-a5fe-35dda4140000 pid=5284 execve guuid=faad068a-1900-0000-a5fe-35dda5140000 pid=5285 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=faad068a-1900-0000-a5fe-35dda5140000 pid=5285 execve guuid=10816e8a-1900-0000-a5fe-35dda6140000 pid=5286 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=10816e8a-1900-0000-a5fe-35dda6140000 pid=5286 execve guuid=fe39d58a-1900-0000-a5fe-35dda7140000 pid=5287 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fe39d58a-1900-0000-a5fe-35dda7140000 pid=5287 execve guuid=4c164d8b-1900-0000-a5fe-35dda8140000 pid=5288 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4c164d8b-1900-0000-a5fe-35dda8140000 pid=5288 execve guuid=f06ab98b-1900-0000-a5fe-35dda9140000 pid=5289 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f06ab98b-1900-0000-a5fe-35dda9140000 pid=5289 execve guuid=fe12248c-1900-0000-a5fe-35ddaa140000 pid=5290 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fe12248c-1900-0000-a5fe-35ddaa140000 pid=5290 execve guuid=ca4e8c8c-1900-0000-a5fe-35ddab140000 pid=5291 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=ca4e8c8c-1900-0000-a5fe-35ddab140000 pid=5291 execve guuid=9d2dfa8c-1900-0000-a5fe-35ddac140000 pid=5292 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=9d2dfa8c-1900-0000-a5fe-35ddac140000 pid=5292 execve guuid=c151688d-1900-0000-a5fe-35ddad140000 pid=5293 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c151688d-1900-0000-a5fe-35ddad140000 pid=5293 execve guuid=5c81d28d-1900-0000-a5fe-35ddae140000 pid=5294 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=5c81d28d-1900-0000-a5fe-35ddae140000 pid=5294 execve guuid=dbe03a8e-1900-0000-a5fe-35ddaf140000 pid=5295 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=dbe03a8e-1900-0000-a5fe-35ddaf140000 pid=5295 execve guuid=48b3a18e-1900-0000-a5fe-35ddb0140000 pid=5296 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=48b3a18e-1900-0000-a5fe-35ddb0140000 pid=5296 execve guuid=de0d108f-1900-0000-a5fe-35ddb1140000 pid=5297 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=de0d108f-1900-0000-a5fe-35ddb1140000 pid=5297 execve guuid=cbca768f-1900-0000-a5fe-35ddb2140000 pid=5298 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=cbca768f-1900-0000-a5fe-35ddb2140000 pid=5298 execve guuid=6402ea8f-1900-0000-a5fe-35ddb3140000 pid=5299 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=6402ea8f-1900-0000-a5fe-35ddb3140000 pid=5299 execve guuid=811c5890-1900-0000-a5fe-35ddb4140000 pid=5300 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=811c5890-1900-0000-a5fe-35ddb4140000 pid=5300 execve guuid=049acd90-1900-0000-a5fe-35ddb5140000 pid=5301 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=049acd90-1900-0000-a5fe-35ddb5140000 pid=5301 execve guuid=c53b3f91-1900-0000-a5fe-35ddb6140000 pid=5302 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c53b3f91-1900-0000-a5fe-35ddb6140000 pid=5302 execve guuid=4cdcb791-1900-0000-a5fe-35ddb7140000 pid=5303 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4cdcb791-1900-0000-a5fe-35ddb7140000 pid=5303 execve guuid=41da3192-1900-0000-a5fe-35ddb8140000 pid=5304 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=41da3192-1900-0000-a5fe-35ddb8140000 pid=5304 execve guuid=47d2ad92-1900-0000-a5fe-35ddb9140000 pid=5305 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=47d2ad92-1900-0000-a5fe-35ddb9140000 pid=5305 execve guuid=86872593-1900-0000-a5fe-35ddba140000 pid=5306 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=86872593-1900-0000-a5fe-35ddba140000 pid=5306 execve guuid=8dd3a793-1900-0000-a5fe-35ddbb140000 pid=5307 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8dd3a793-1900-0000-a5fe-35ddbb140000 pid=5307 execve guuid=61461a94-1900-0000-a5fe-35ddbc140000 pid=5308 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=61461a94-1900-0000-a5fe-35ddbc140000 pid=5308 execve guuid=95669394-1900-0000-a5fe-35ddbd140000 pid=5309 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=95669394-1900-0000-a5fe-35ddbd140000 pid=5309 execve guuid=2c840095-1900-0000-a5fe-35ddbe140000 pid=5310 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=2c840095-1900-0000-a5fe-35ddbe140000 pid=5310 execve guuid=53c37695-1900-0000-a5fe-35ddbf140000 pid=5311 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=53c37695-1900-0000-a5fe-35ddbf140000 pid=5311 execve guuid=0a78e795-1900-0000-a5fe-35ddc0140000 pid=5312 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=0a78e795-1900-0000-a5fe-35ddc0140000 pid=5312 execve guuid=863a5c96-1900-0000-a5fe-35ddc1140000 pid=5313 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=863a5c96-1900-0000-a5fe-35ddc1140000 pid=5313 execve guuid=7c7ed696-1900-0000-a5fe-35ddc2140000 pid=5314 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=7c7ed696-1900-0000-a5fe-35ddc2140000 pid=5314 execve guuid=386a4097-1900-0000-a5fe-35ddc3140000 pid=5315 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=386a4097-1900-0000-a5fe-35ddc3140000 pid=5315 execve guuid=0a72af97-1900-0000-a5fe-35ddc4140000 pid=5316 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=0a72af97-1900-0000-a5fe-35ddc4140000 pid=5316 execve guuid=690b2898-1900-0000-a5fe-35ddc5140000 pid=5317 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=690b2898-1900-0000-a5fe-35ddc5140000 pid=5317 execve guuid=43bd9d98-1900-0000-a5fe-35ddc6140000 pid=5318 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=43bd9d98-1900-0000-a5fe-35ddc6140000 pid=5318 execve guuid=c12c0f99-1900-0000-a5fe-35ddc7140000 pid=5319 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c12c0f99-1900-0000-a5fe-35ddc7140000 pid=5319 execve guuid=590d8599-1900-0000-a5fe-35ddc8140000 pid=5320 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=590d8599-1900-0000-a5fe-35ddc8140000 pid=5320 execve guuid=cdadf099-1900-0000-a5fe-35ddc9140000 pid=5321 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=cdadf099-1900-0000-a5fe-35ddc9140000 pid=5321 execve guuid=c0420d9b-1900-0000-a5fe-35ddca140000 pid=5322 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c0420d9b-1900-0000-a5fe-35ddca140000 pid=5322 execve guuid=518e059c-1900-0000-a5fe-35ddcb140000 pid=5323 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=518e059c-1900-0000-a5fe-35ddcb140000 pid=5323 execve guuid=1341049d-1900-0000-a5fe-35ddcc140000 pid=5324 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=1341049d-1900-0000-a5fe-35ddcc140000 pid=5324 execve guuid=c0d0c59d-1900-0000-a5fe-35ddcd140000 pid=5325 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c0d0c59d-1900-0000-a5fe-35ddcd140000 pid=5325 execve guuid=73757b9e-1900-0000-a5fe-35ddce140000 pid=5326 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=73757b9e-1900-0000-a5fe-35ddce140000 pid=5326 execve guuid=2c443f9f-1900-0000-a5fe-35ddcf140000 pid=5327 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=2c443f9f-1900-0000-a5fe-35ddcf140000 pid=5327 execve guuid=f614c79f-1900-0000-a5fe-35ddd0140000 pid=5328 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f614c79f-1900-0000-a5fe-35ddd0140000 pid=5328 execve guuid=81ae4fa0-1900-0000-a5fe-35ddd1140000 pid=5329 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=81ae4fa0-1900-0000-a5fe-35ddd1140000 pid=5329 execve guuid=f1c4c6a0-1900-0000-a5fe-35ddd2140000 pid=5330 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f1c4c6a0-1900-0000-a5fe-35ddd2140000 pid=5330 execve guuid=7f7c3aa1-1900-0000-a5fe-35ddd3140000 pid=5331 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=7f7c3aa1-1900-0000-a5fe-35ddd3140000 pid=5331 execve guuid=c0aaaaa1-1900-0000-a5fe-35ddd4140000 pid=5332 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c0aaaaa1-1900-0000-a5fe-35ddd4140000 pid=5332 execve guuid=930216a2-1900-0000-a5fe-35ddd5140000 pid=5333 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=930216a2-1900-0000-a5fe-35ddd5140000 pid=5333 execve guuid=994481a2-1900-0000-a5fe-35ddd6140000 pid=5334 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=994481a2-1900-0000-a5fe-35ddd6140000 pid=5334 execve guuid=2b77e8a2-1900-0000-a5fe-35ddd7140000 pid=5335 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=2b77e8a2-1900-0000-a5fe-35ddd7140000 pid=5335 execve guuid=6d8953a3-1900-0000-a5fe-35ddd8140000 pid=5336 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=6d8953a3-1900-0000-a5fe-35ddd8140000 pid=5336 execve guuid=d448bea3-1900-0000-a5fe-35ddd9140000 pid=5337 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=d448bea3-1900-0000-a5fe-35ddd9140000 pid=5337 execve guuid=fb2021a4-1900-0000-a5fe-35ddda140000 pid=5338 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fb2021a4-1900-0000-a5fe-35ddda140000 pid=5338 execve guuid=07c483a4-1900-0000-a5fe-35dddb140000 pid=5339 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=07c483a4-1900-0000-a5fe-35dddb140000 pid=5339 execve guuid=c9b8e4a4-1900-0000-a5fe-35dddc140000 pid=5340 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=c9b8e4a4-1900-0000-a5fe-35dddc140000 pid=5340 execve guuid=0fd74ea5-1900-0000-a5fe-35dddd140000 pid=5341 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=0fd74ea5-1900-0000-a5fe-35dddd140000 pid=5341 execve guuid=d06dbca5-1900-0000-a5fe-35ddde140000 pid=5342 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=d06dbca5-1900-0000-a5fe-35ddde140000 pid=5342 execve guuid=b01726a6-1900-0000-a5fe-35dddf140000 pid=5343 /usr/bin/ls guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=b01726a6-1900-0000-a5fe-35dddf140000 pid=5343 execve guuid=0c969da6-1900-0000-a5fe-35dde0140000 pid=5344 /usr/bin/rm guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=0c969da6-1900-0000-a5fe-35dde0140000 pid=5344 execve guuid=0f2be9a6-1900-0000-a5fe-35dde1140000 pid=5345 /usr/bin/wget net send-data write-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=0f2be9a6-1900-0000-a5fe-35dde1140000 pid=5345 execve guuid=139c61f6-1900-0000-a5fe-35dde2140000 pid=5346 /usr/bin/chmod guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=139c61f6-1900-0000-a5fe-35dde2140000 pid=5346 execve guuid=9756a9f6-1900-0000-a5fe-35dde3140000 pid=5347 /usr/bin/dash guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=9756a9f6-1900-0000-a5fe-35dde3140000 pid=5347 clone guuid=467043f7-1900-0000-a5fe-35dde5140000 pid=5349 /usr/bin/rm delete-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=467043f7-1900-0000-a5fe-35dde5140000 pid=5349 execve guuid=fa518ef7-1900-0000-a5fe-35dde6140000 pid=5350 /usr/bin/wget net send-data write-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fa518ef7-1900-0000-a5fe-35dde6140000 pid=5350 execve guuid=75c1c140-1a00-0000-a5fe-35ddee140000 pid=5358 /usr/bin/chmod guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=75c1c140-1a00-0000-a5fe-35ddee140000 pid=5358 execve guuid=4d3f8641-1a00-0000-a5fe-35ddef140000 pid=5359 /usr/bin/dash guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4d3f8641-1a00-0000-a5fe-35ddef140000 pid=5359 clone guuid=1b334343-1a00-0000-a5fe-35ddf1140000 pid=5361 /usr/bin/rm delete-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=1b334343-1a00-0000-a5fe-35ddf1140000 pid=5361 execve guuid=8a8cb043-1a00-0000-a5fe-35ddf2140000 pid=5362 /usr/bin/wget net send-data write-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8a8cb043-1a00-0000-a5fe-35ddf2140000 pid=5362 execve guuid=fa83488c-1a00-0000-a5fe-35ddf3140000 pid=5363 /usr/bin/chmod guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=fa83488c-1a00-0000-a5fe-35ddf3140000 pid=5363 execve guuid=aea7358d-1a00-0000-a5fe-35ddf4140000 pid=5364 /usr/bin/dash guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=aea7358d-1a00-0000-a5fe-35ddf4140000 pid=5364 clone guuid=ed55d68e-1a00-0000-a5fe-35ddf6140000 pid=5366 /usr/bin/rm delete-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=ed55d68e-1a00-0000-a5fe-35ddf6140000 pid=5366 execve guuid=31a7f9a0-1a00-0000-a5fe-35ddf7140000 pid=5367 /usr/bin/wget net send-data write-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=31a7f9a0-1a00-0000-a5fe-35ddf7140000 pid=5367 execve guuid=e4639be4-1a00-0000-a5fe-35ddf8140000 pid=5368 /usr/bin/chmod guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=e4639be4-1a00-0000-a5fe-35ddf8140000 pid=5368 execve guuid=b73324e5-1a00-0000-a5fe-35ddf9140000 pid=5369 /usr/bin/dash guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=b73324e5-1a00-0000-a5fe-35ddf9140000 pid=5369 clone guuid=26d98ce9-1a00-0000-a5fe-35ddfb140000 pid=5371 /usr/bin/rm delete-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=26d98ce9-1a00-0000-a5fe-35ddfb140000 pid=5371 execve guuid=434015ea-1a00-0000-a5fe-35ddfc140000 pid=5372 /usr/bin/wget net send-data write-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=434015ea-1a00-0000-a5fe-35ddfc140000 pid=5372 execve guuid=3b499f43-1b00-0000-a5fe-35dd09150000 pid=5385 /usr/bin/chmod guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=3b499f43-1b00-0000-a5fe-35dd09150000 pid=5385 execve guuid=f09f0c44-1b00-0000-a5fe-35dd0a150000 pid=5386 /usr/bin/dash guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=f09f0c44-1b00-0000-a5fe-35dd0a150000 pid=5386 clone guuid=8548f544-1b00-0000-a5fe-35dd0d150000 pid=5389 /usr/bin/rm delete-file guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8548f544-1b00-0000-a5fe-35dd0d150000 pid=5389 execve guuid=8c413448-1b00-0000-a5fe-35dd0e150000 pid=5390 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8c413448-1b00-0000-a5fe-35dd0e150000 pid=5390 execve guuid=de187b58-1b00-0000-a5fe-35dd13150000 pid=5395 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=de187b58-1b00-0000-a5fe-35dd13150000 pid=5395 execve guuid=8e2b655f-1b00-0000-a5fe-35dd17150000 pid=5399 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=8e2b655f-1b00-0000-a5fe-35dd17150000 pid=5399 execve guuid=4e06d25f-1b00-0000-a5fe-35dd18150000 pid=5400 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=4e06d25f-1b00-0000-a5fe-35dd18150000 pid=5400 execve guuid=70f93360-1b00-0000-a5fe-35dd19150000 pid=5401 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=70f93360-1b00-0000-a5fe-35dd19150000 pid=5401 execve guuid=06029b60-1b00-0000-a5fe-35dd1a150000 pid=5402 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=06029b60-1b00-0000-a5fe-35dd1a150000 pid=5402 execve guuid=ab145968-1b00-0000-a5fe-35dd1d150000 pid=5405 /usr/sbin/xtables-nft-multi guuid=bcbe8269-1900-0000-a5fe-35dd67140000 pid=5223->guuid=ab145968-1b00-0000-a5fe-35dd1d150000 pid=5405 execve f77871c8-0687-5455-9dce-96fa4ef16894 103.188.83.28:80 guuid=0f2be9a6-1900-0000-a5fe-35dde1140000 pid=5345->f77871c8-0687-5455-9dce-96fa4ef16894 send: 133B guuid=fa518ef7-1900-0000-a5fe-35dde6140000 pid=5350->f77871c8-0687-5455-9dce-96fa4ef16894 send: 133B guuid=8a8cb043-1a00-0000-a5fe-35ddf2140000 pid=5362->f77871c8-0687-5455-9dce-96fa4ef16894 send: 133B guuid=31a7f9a0-1a00-0000-a5fe-35ddf7140000 pid=5367->f77871c8-0687-5455-9dce-96fa4ef16894 send: 133B guuid=434015ea-1a00-0000-a5fe-35ddfc140000 pid=5372->f77871c8-0687-5455-9dce-96fa4ef16894 send: 133B
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-08-11 13:32:24 UTC
File Type:
Text (Shell)
AV detection:
9 of 24 (37.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh da104a20960f8c7d057849001fa35fb7fb1ea09ea38357f7e5333ef9542dddaa

(this sample)

  
Delivery method
Distributed via web download

Comments