MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dd47b5f7dda2ade9c11ef05158d62d5d5f63bc909cfce42a03008f7e1b1928ff. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: dd47b5f7dda2ade9c11ef05158d62d5d5f63bc909cfce42a03008f7e1b1928ff
SHA3-384 hash: e688ef813da4ce0297fbc1485e013f3adbf76201d895ee9e1469150d99ff4ce2dc8a75f0daf22c64aeacf92c1eb592fd
SHA1 hash: 1559bd551946945a3cafcdb5f3761edef8b194d2
MD5 hash: 70301f60cfa959142e2d21c4538330cd
humanhash: twenty-magnesium-sad-coffee
File name:bins.sh
Download: download sample
Signature Mirai
File size:910 bytes
First seen:2025-11-05 04:28:52 UTC
Last seen:2025-11-05 16:03:32 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:XtA/syYzZ3OhXvuS9dLa+Jdz7+y5yswTm6:XtA/J430vu4usdzzoJB
TLSH T146117C906C851587A8DBFE1C712A93F231412C74E5A0123DD2A7EE16C87EE32B90E631
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-03T10:14:00Z UTC
Last seen:
2025-11-07T00:44:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Mirai.a
Status:
terminated
Behavior Graph:
%3 guuid=5dcbcbe8-1b00-0000-deb0-b5cc4e0a0000 pid=2638 /usr/bin/sudo guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647 /tmp/sample.bin guuid=5dcbcbe8-1b00-0000-deb0-b5cc4e0a0000 pid=2638->guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647 execve guuid=abd52dec-1b00-0000-deb0-b5cc590a0000 pid=2649 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=abd52dec-1b00-0000-deb0-b5cc590a0000 pid=2649 execve guuid=9651e4f7-1b00-0000-deb0-b5cc770a0000 pid=2679 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=9651e4f7-1b00-0000-deb0-b5cc770a0000 pid=2679 execve guuid=9b9d27f8-1b00-0000-deb0-b5cc790a0000 pid=2681 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=9b9d27f8-1b00-0000-deb0-b5cc790a0000 pid=2681 clone guuid=485fdcf8-1b00-0000-deb0-b5cc7e0a0000 pid=2686 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=485fdcf8-1b00-0000-deb0-b5cc7e0a0000 pid=2686 execve guuid=0444300a-1c00-0000-deb0-b5ccb50a0000 pid=2741 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0444300a-1c00-0000-deb0-b5ccb50a0000 pid=2741 execve guuid=4628830a-1c00-0000-deb0-b5ccb60a0000 pid=2742 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=4628830a-1c00-0000-deb0-b5ccb60a0000 pid=2742 clone guuid=8e4c190b-1c00-0000-deb0-b5ccb90a0000 pid=2745 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=8e4c190b-1c00-0000-deb0-b5ccb90a0000 pid=2745 execve guuid=a1c0aa15-1c00-0000-deb0-b5ccd50a0000 pid=2773 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=a1c0aa15-1c00-0000-deb0-b5ccd50a0000 pid=2773 execve guuid=116aea15-1c00-0000-deb0-b5ccd60a0000 pid=2774 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=116aea15-1c00-0000-deb0-b5ccd60a0000 pid=2774 clone guuid=fad47416-1c00-0000-deb0-b5ccda0a0000 pid=2778 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=fad47416-1c00-0000-deb0-b5ccda0a0000 pid=2778 execve guuid=73a2e725-1c00-0000-deb0-b5ccf90a0000 pid=2809 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=73a2e725-1c00-0000-deb0-b5ccf90a0000 pid=2809 execve guuid=b1903b26-1c00-0000-deb0-b5ccfa0a0000 pid=2810 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=b1903b26-1c00-0000-deb0-b5ccfa0a0000 pid=2810 clone guuid=5ac8ef26-1c00-0000-deb0-b5ccfe0a0000 pid=2814 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=5ac8ef26-1c00-0000-deb0-b5ccfe0a0000 pid=2814 execve guuid=3065de32-1c00-0000-deb0-b5cc1a0b0000 pid=2842 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=3065de32-1c00-0000-deb0-b5cc1a0b0000 pid=2842 execve guuid=986f1b33-1c00-0000-deb0-b5cc1c0b0000 pid=2844 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=986f1b33-1c00-0000-deb0-b5cc1c0b0000 pid=2844 clone guuid=511fa133-1c00-0000-deb0-b5cc1e0b0000 pid=2846 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=511fa133-1c00-0000-deb0-b5cc1e0b0000 pid=2846 execve guuid=0243043e-1c00-0000-deb0-b5cc380b0000 pid=2872 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0243043e-1c00-0000-deb0-b5cc380b0000 pid=2872 execve guuid=558b423e-1c00-0000-deb0-b5cc390b0000 pid=2873 /home/sandbox/dvrHelper delete-file net guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=558b423e-1c00-0000-deb0-b5cc390b0000 pid=2873 execve guuid=ab51753e-1c00-0000-deb0-b5cc3c0b0000 pid=2876 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=ab51753e-1c00-0000-deb0-b5cc3c0b0000 pid=2876 execve guuid=92ec5d4a-1c00-0000-deb0-b5cc630b0000 pid=2915 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=92ec5d4a-1c00-0000-deb0-b5cc630b0000 pid=2915 execve guuid=d5c09e4a-1c00-0000-deb0-b5cc640b0000 pid=2916 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=d5c09e4a-1c00-0000-deb0-b5cc640b0000 pid=2916 clone guuid=0b8d254b-1c00-0000-deb0-b5cc680b0000 pid=2920 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0b8d254b-1c00-0000-deb0-b5cc680b0000 pid=2920 execve guuid=37d52a5c-1c00-0000-deb0-b5cc900b0000 pid=2960 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=37d52a5c-1c00-0000-deb0-b5cc900b0000 pid=2960 execve guuid=9e656a5c-1c00-0000-deb0-b5cc910b0000 pid=2961 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=9e656a5c-1c00-0000-deb0-b5cc910b0000 pid=2961 clone guuid=722d8b5d-1c00-0000-deb0-b5cc970b0000 pid=2967 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=722d8b5d-1c00-0000-deb0-b5cc970b0000 pid=2967 execve guuid=d1d3e06a-1c00-0000-deb0-b5ccae0b0000 pid=2990 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=d1d3e06a-1c00-0000-deb0-b5ccae0b0000 pid=2990 execve guuid=29f4576b-1c00-0000-deb0-b5ccb00b0000 pid=2992 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=29f4576b-1c00-0000-deb0-b5ccb00b0000 pid=2992 clone guuid=f4005c6d-1c00-0000-deb0-b5ccb50b0000 pid=2997 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=f4005c6d-1c00-0000-deb0-b5ccb50b0000 pid=2997 execve guuid=f35d3479-1c00-0000-deb0-b5ccd20b0000 pid=3026 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=f35d3479-1c00-0000-deb0-b5ccd20b0000 pid=3026 execve guuid=58648079-1c00-0000-deb0-b5ccd30b0000 pid=3027 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=58648079-1c00-0000-deb0-b5ccd30b0000 pid=3027 clone guuid=23f9477a-1c00-0000-deb0-b5ccd60b0000 pid=3030 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=23f9477a-1c00-0000-deb0-b5ccd60b0000 pid=3030 execve guuid=0fe47986-1c00-0000-deb0-b5ccf10b0000 pid=3057 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0fe47986-1c00-0000-deb0-b5ccf10b0000 pid=3057 execve guuid=63c1fe86-1c00-0000-deb0-b5ccf30b0000 pid=3059 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=63c1fe86-1c00-0000-deb0-b5ccf30b0000 pid=3059 clone guuid=30f0c587-1c00-0000-deb0-b5ccf80b0000 pid=3064 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=30f0c587-1c00-0000-deb0-b5ccf80b0000 pid=3064 execve guuid=d04d1697-1c00-0000-deb0-b5cc260c0000 pid=3110 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=d04d1697-1c00-0000-deb0-b5cc260c0000 pid=3110 execve guuid=0a3e5797-1c00-0000-deb0-b5cc270c0000 pid=3111 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0a3e5797-1c00-0000-deb0-b5cc270c0000 pid=3111 clone guuid=c5246d98-1c00-0000-deb0-b5cc2d0c0000 pid=3117 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=c5246d98-1c00-0000-deb0-b5cc2d0c0000 pid=3117 execve guuid=b0db76a5-1c00-0000-deb0-b5cc450c0000 pid=3141 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=b0db76a5-1c00-0000-deb0-b5cc450c0000 pid=3141 execve guuid=1175eca5-1c00-0000-deb0-b5cc480c0000 pid=3144 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=1175eca5-1c00-0000-deb0-b5cc480c0000 pid=3144 clone guuid=706382a6-1c00-0000-deb0-b5cc4a0c0000 pid=3146 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=706382a6-1c00-0000-deb0-b5cc4a0c0000 pid=3146 execve guuid=966d58b6-1c00-0000-deb0-b5cc6e0c0000 pid=3182 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=966d58b6-1c00-0000-deb0-b5cc6e0c0000 pid=3182 execve guuid=faffd4b6-1c00-0000-deb0-b5cc700c0000 pid=3184 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=faffd4b6-1c00-0000-deb0-b5cc700c0000 pid=3184 clone guuid=aa64dcb7-1c00-0000-deb0-b5cc740c0000 pid=3188 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=aa64dcb7-1c00-0000-deb0-b5cc740c0000 pid=3188 execve guuid=891a81c2-1c00-0000-deb0-b5cc8f0c0000 pid=3215 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=891a81c2-1c00-0000-deb0-b5cc8f0c0000 pid=3215 execve guuid=524ec2c2-1c00-0000-deb0-b5cc900c0000 pid=3216 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=524ec2c2-1c00-0000-deb0-b5cc900c0000 pid=3216 clone guuid=7ad93fc3-1c00-0000-deb0-b5cc940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=7ad93fc3-1c00-0000-deb0-b5cc940c0000 pid=3220 execve guuid=1e087ace-1c00-0000-deb0-b5cca70c0000 pid=3239 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=1e087ace-1c00-0000-deb0-b5cca70c0000 pid=3239 execve guuid=6abc11cf-1c00-0000-deb0-b5cca80c0000 pid=3240 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=6abc11cf-1c00-0000-deb0-b5cca80c0000 pid=3240 clone guuid=0392bfcf-1c00-0000-deb0-b5ccaa0c0000 pid=3242 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0392bfcf-1c00-0000-deb0-b5ccaa0c0000 pid=3242 execve guuid=852241db-1c00-0000-deb0-b5ccab0c0000 pid=3243 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=852241db-1c00-0000-deb0-b5ccab0c0000 pid=3243 execve guuid=252ea0db-1c00-0000-deb0-b5ccac0c0000 pid=3244 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=252ea0db-1c00-0000-deb0-b5ccac0c0000 pid=3244 clone guuid=3db27ddc-1c00-0000-deb0-b5ccae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=3db27ddc-1c00-0000-deb0-b5ccae0c0000 pid=3246 execve guuid=23103bef-1c00-0000-deb0-b5ccba0c0000 pid=3258 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=23103bef-1c00-0000-deb0-b5ccba0c0000 pid=3258 execve guuid=4fa487ef-1c00-0000-deb0-b5ccbc0c0000 pid=3260 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=4fa487ef-1c00-0000-deb0-b5ccbc0c0000 pid=3260 clone guuid=b2314af1-1c00-0000-deb0-b5ccc10c0000 pid=3265 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=b2314af1-1c00-0000-deb0-b5ccc10c0000 pid=3265 execve guuid=ebc564fc-1c00-0000-deb0-b5ccd30c0000 pid=3283 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=ebc564fc-1c00-0000-deb0-b5ccd30c0000 pid=3283 execve guuid=f068aefc-1c00-0000-deb0-b5ccd50c0000 pid=3285 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=f068aefc-1c00-0000-deb0-b5ccd50c0000 pid=3285 clone guuid=a0ca33fd-1c00-0000-deb0-b5ccd90c0000 pid=3289 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=a0ca33fd-1c00-0000-deb0-b5ccd90c0000 pid=3289 execve guuid=cbefee0c-1d00-0000-deb0-b5ccdb0c0000 pid=3291 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=cbefee0c-1d00-0000-deb0-b5ccdb0c0000 pid=3291 execve guuid=22d77b0d-1d00-0000-deb0-b5ccdc0c0000 pid=3292 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=22d77b0d-1d00-0000-deb0-b5ccdc0c0000 pid=3292 clone guuid=1d95920f-1d00-0000-deb0-b5ccde0c0000 pid=3294 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=1d95920f-1d00-0000-deb0-b5ccde0c0000 pid=3294 execve guuid=82fcda1d-1d00-0000-deb0-b5ccf00c0000 pid=3312 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=82fcda1d-1d00-0000-deb0-b5ccf00c0000 pid=3312 execve guuid=15993b1e-1d00-0000-deb0-b5ccf10c0000 pid=3313 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=15993b1e-1d00-0000-deb0-b5ccf10c0000 pid=3313 clone guuid=fd7b1420-1d00-0000-deb0-b5ccf70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=fd7b1420-1d00-0000-deb0-b5ccf70c0000 pid=3319 execve guuid=293b872b-1d00-0000-deb0-b5cc060d0000 pid=3334 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=293b872b-1d00-0000-deb0-b5cc060d0000 pid=3334 execve guuid=804bd52b-1d00-0000-deb0-b5cc070d0000 pid=3335 /usr/bin/dash guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=804bd52b-1d00-0000-deb0-b5cc070d0000 pid=3335 clone guuid=f507c32c-1d00-0000-deb0-b5cc090d0000 pid=3337 /usr/bin/wget net send-data write-file guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=f507c32c-1d00-0000-deb0-b5cc090d0000 pid=3337 execve guuid=40d18038-1d00-0000-deb0-b5cc120d0000 pid=3346 /usr/bin/chmod guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=40d18038-1d00-0000-deb0-b5cc120d0000 pid=3346 execve guuid=0e32f638-1d00-0000-deb0-b5cc140d0000 pid=3348 /home/sandbox/dvrHelper delete-file net guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=0e32f638-1d00-0000-deb0-b5cc140d0000 pid=3348 execve guuid=e6884474-1e00-0000-deb0-b5ccfa0f0000 pid=4090 /usr/bin/rm guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=e6884474-1e00-0000-deb0-b5ccfa0f0000 pid=4090 execve guuid=5e838174-1e00-0000-deb0-b5ccfd0f0000 pid=4093 /usr/bin/rm guuid=e318d7eb-1b00-0000-deb0-b5cc570a0000 pid=2647->guuid=5e838174-1e00-0000-deb0-b5ccfd0f0000 pid=4093 execve ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 45.133.119.221:80 guuid=abd52dec-1b00-0000-deb0-b5cc590a0000 pid=2649->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 145B guuid=485fdcf8-1b00-0000-deb0-b5cc7e0a0000 pid=2686->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 146B guuid=8e4c190b-1c00-0000-deb0-b5ccb90a0000 pid=2745->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 144B guuid=fad47416-1c00-0000-deb0-b5ccda0a0000 pid=2778->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 144B guuid=5ac8ef26-1c00-0000-deb0-b5ccfe0a0000 pid=2814->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 143B guuid=511fa133-1c00-0000-deb0-b5cc1e0b0000 pid=2846->ad4938b2-ecd1-5777-9ed2-07a22b0f5a62 send: 143B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=558b423e-1c00-0000-deb0-b5cc390b0000 pid=2873->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875 /home/sandbox/dvrHelper dns net send-data zombie guuid=558b423e-1c00-0000-deb0-b5cc390b0000 pid=2873->guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875 clone guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 hxipzknrsojnitzv.zip:23 guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 con guuid=ac41813e-1c00-0000-deb0-b5cc3d0b0000 pid=2877 /home/sandbox/dvrHelper guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875->guuid=ac41813e-1c00-0000-deb0-b5cc3d0b0000 pid=2877 clone guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878 /home/sandbox/dvrHelper net net-scan send-data guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875->guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878 clone guuid=707a36a8-1d00-0000-deb0-b5cc100e0000 pid=3600 /home/sandbox/dvrHelper guuid=6196703e-1c00-0000-deb0-b5cc3b0b0000 pid=2875->guuid=707a36a8-1d00-0000-deb0-b5cc100e0000 pid=3600 clone 91ace30b-3d9f-522c-9672-99f62740d927 hxipzknrsojnitzv.zip:80 guuid=ab51753e-1c00-0000-deb0-b5cc3c0b0000 pid=2876->91ace30b-3d9f-522c-9672-99f62740d927 send: 147B guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con d8bd55f7-c47e-58e1-999e-70e447848040 31.44.129.237:23 guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878->d8bd55f7-c47e-58e1-999e-70e447848040 send: 40B guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878|send-data send-data to 1120 IP addresses review logs to see them all guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878->guuid=7f108c3e-1c00-0000-deb0-b5cc3e0b0000 pid=2878|send-data send guuid=0b8d254b-1c00-0000-deb0-b5cc680b0000 pid=2920->91ace30b-3d9f-522c-9672-99f62740d927 send: 148B guuid=722d8b5d-1c00-0000-deb0-b5cc970b0000 pid=2967->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=f4005c6d-1c00-0000-deb0-b5ccb50b0000 pid=2997->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=23f9477a-1c00-0000-deb0-b5ccd60b0000 pid=3030->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=30f0c587-1c00-0000-deb0-b5ccf80b0000 pid=3064->91ace30b-3d9f-522c-9672-99f62740d927 send: 143B guuid=c5246d98-1c00-0000-deb0-b5cc2d0c0000 pid=3117->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=706382a6-1c00-0000-deb0-b5cc4a0c0000 pid=3146->91ace30b-3d9f-522c-9672-99f62740d927 send: 149B guuid=aa64dcb7-1c00-0000-deb0-b5cc740c0000 pid=3188->91ace30b-3d9f-522c-9672-99f62740d927 send: 144B guuid=7ad93fc3-1c00-0000-deb0-b5cc940c0000 pid=3220->91ace30b-3d9f-522c-9672-99f62740d927 send: 143B guuid=0392bfcf-1c00-0000-deb0-b5ccaa0c0000 pid=3242->91ace30b-3d9f-522c-9672-99f62740d927 send: 143B guuid=3db27ddc-1c00-0000-deb0-b5ccae0c0000 pid=3246->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=b2314af1-1c00-0000-deb0-b5ccc10c0000 pid=3265->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=a0ca33fd-1c00-0000-deb0-b5ccd90c0000 pid=3289->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=1d95920f-1d00-0000-deb0-b5ccde0c0000 pid=3294->91ace30b-3d9f-522c-9672-99f62740d927 send: 146B guuid=fd7b1420-1d00-0000-deb0-b5ccf70c0000 pid=3319->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=f507c32c-1d00-0000-deb0-b5cc090d0000 pid=3337->91ace30b-3d9f-522c-9672-99f62740d927 send: 145B guuid=0e32f638-1d00-0000-deb0-b5cc140d0000 pid=3348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ff25191-b423-5251-a735-2378c22ab12a 0.0.0.0:48101 guuid=0e32f638-1d00-0000-deb0-b5cc140d0000 pid=3348->8ff25191-b423-5251-a735-2378c22ab12a con guuid=8b633e74-1e00-0000-deb0-b5ccf90f0000 pid=4089 /home/sandbox/dvrHelper dns net send-data zombie guuid=0e32f638-1d00-0000-deb0-b5cc140d0000 pid=3348->guuid=8b633e74-1e00-0000-deb0-b5ccf90f0000 pid=4089 clone guuid=8b633e74-1e00-0000-deb0-b5ccf90f0000 pid=4089->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 380B guuid=8b633e74-1e00-0000-deb0-b5ccf90f0000 pid=4089->c2fe4d9c-be92-56e6-bcbc-5f48f7ff04e5 con guuid=bea54774-1e00-0000-deb0-b5ccfb0f0000 pid=4091 /home/sandbox/dvrHelper guuid=8b633e74-1e00-0000-deb0-b5ccf90f0000 pid=4089->guuid=bea54774-1e00-0000-deb0-b5ccfb0f0000 pid=4091 clone
Threat name:
Linux.Browser.Downlaoder
Status:
Malicious
First seen:
2025-11-05 04:12:01 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Creates a large amount of network flows
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (4008) amount of remote hosts
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dd47b5f7dda2ade9c11ef05158d62d5d5f63bc909cfce42a03008f7e1b1928ff

(this sample)

  
Delivery method
Distributed via web download

Comments