MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a3cb19457bef557ede860ec1b92aad9e82b48764e783bfbc5fc88a2918b36dd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4a3cb19457bef557ede860ec1b92aad9e82b48764e783bfbc5fc88a2918b36dd
SHA3-384 hash: e2940d87bf12d713ca390c21b1ec9d7b980483a11fa56ba9800dc4c8d5d467f08b62b66f2463983748457302bc5a58b0
SHA1 hash: eadaf6b5ebd9f1688b17e90c94bff18059f2eec8
MD5 hash: e3f441ef9e56b4d368b6c2301ce31bda
humanhash: blue-kitten-asparagus-twelve
File name:1.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2025-11-23 15:52:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vl7k7N7hlv6GlgXzPlfKWlhoUl7h7o7Ulfq3bl09RlNcgl4pVlXSOl7+Cl6fTlCW:vl7k7N7hlv6GlgXzPlfKWlhoUl7h7o7O
TLSH T1755184CD71440C3459B3EA13FAB7F12C32C9919219ED7B9699E4BAF4839ED143A40B63
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.111/hiddenbin/boatnet.x864ecaa18a5b022c8a5117c58255403f0895c4dc50420fad611813b42e089349f8 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.mipsc1d2c0bd3e06459f996a3ff76393d713e6b247b8abc6faae99cef0d5f6d53f3a Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.arc85498378057cb52b5ace62d7002de39fe4dc1cb85f87d4431ad016933cadb889 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://87.121.84.111/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://87.121.84.111/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://87.121.84.111/hiddenbin/boatnet.mpsl0bf8d4c96479982a4659168b3d6af9e32735bf6d7543051483b9b3605b6c6f84 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.armfee40bafac78ddf07a4ab46a06d65a5f883248e5eaec69a75f737fc58910af41 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.arm54159d8e199ee13ea7ec2355317cae2fca4cd49a27c44adea6dc9c0b7a6b52732 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.arm6cfb9703c836214ea39423eccb616af841f5f484a6e989b7cd3796113e70aaec4 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.arm7a209de0c1e19da5680dbaf81ac8bf49bfd772f574aa6906ba7b0b8e2de1cc374 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.ppc8aee5d92f69ee92a841a5e6333839009a628559f28ccedf6ba652dabf7222dcf Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.spc48e878a69ec02c9e6abe9766c12aa07f9872406c90b3152ead895d5c038afb52 Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.m68k4cced9b97754b924fe13183a07afb0fca7ba9ee3773ea1fccc6e00a29002e48f Miraielf mirai ua-wget
http://87.121.84.111/hiddenbin/boatnet.sh4061469b2aa9aa1528f939be37ac60a60fc7c3c3ef3290968ace82b8ad9bc751f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=6b62fd03-1700-0000-93d9-86945f0d0000 pid=3423 /usr/bin/sudo guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430 /tmp/sample.bin guuid=6b62fd03-1700-0000-93d9-86945f0d0000 pid=3423->guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430 execve guuid=d35e0c06-1700-0000-93d9-8694690d0000 pid=3433 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=d35e0c06-1700-0000-93d9-8694690d0000 pid=3433 execve guuid=9b720e0c-1700-0000-93d9-86947c0d0000 pid=3452 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=9b720e0c-1700-0000-93d9-86947c0d0000 pid=3452 execve guuid=9f757c19-1700-0000-93d9-86949f0d0000 pid=3487 /usr/bin/cat guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=9f757c19-1700-0000-93d9-86949f0d0000 pid=3487 execve guuid=c59ddf19-1700-0000-93d9-8694a30d0000 pid=3491 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=c59ddf19-1700-0000-93d9-8694a30d0000 pid=3491 execve guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492 execve guuid=d5e48a1a-1700-0000-93d9-8694a80d0000 pid=3496 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=d5e48a1a-1700-0000-93d9-8694a80d0000 pid=3496 execve guuid=54d4a81e-1700-0000-93d9-8694a90d0000 pid=3497 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=54d4a81e-1700-0000-93d9-8694a90d0000 pid=3497 execve guuid=bd7f5a24-1700-0000-93d9-8694b30d0000 pid=3507 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=bd7f5a24-1700-0000-93d9-8694b30d0000 pid=3507 clone guuid=f9cc7624-1700-0000-93d9-8694b50d0000 pid=3509 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=f9cc7624-1700-0000-93d9-8694b50d0000 pid=3509 execve guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510 execve guuid=4a901f25-1700-0000-93d9-8694bc0d0000 pid=3516 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=4a901f25-1700-0000-93d9-8694bc0d0000 pid=3516 execve guuid=2cfd252b-1700-0000-93d9-8694c90d0000 pid=3529 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=2cfd252b-1700-0000-93d9-8694c90d0000 pid=3529 execve guuid=5c44543b-1700-0000-93d9-8694f20d0000 pid=3570 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=5c44543b-1700-0000-93d9-8694f20d0000 pid=3570 clone guuid=6e27823b-1700-0000-93d9-8694f30d0000 pid=3571 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=6e27823b-1700-0000-93d9-8694f30d0000 pid=3571 execve guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573 execve guuid=027d5f3c-1700-0000-93d9-8694fa0d0000 pid=3578 /usr/bin/wget net send-data guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=027d5f3c-1700-0000-93d9-8694fa0d0000 pid=3578 execve guuid=0ccd513f-1700-0000-93d9-8694010e0000 pid=3585 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=0ccd513f-1700-0000-93d9-8694010e0000 pid=3585 execve guuid=c19c8c43-1700-0000-93d9-86940c0e0000 pid=3596 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=c19c8c43-1700-0000-93d9-86940c0e0000 pid=3596 clone guuid=228db143-1700-0000-93d9-86940d0e0000 pid=3597 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=228db143-1700-0000-93d9-86940d0e0000 pid=3597 execve guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599 execve guuid=da745a44-1700-0000-93d9-8694130e0000 pid=3603 /usr/bin/wget net send-data guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=da745a44-1700-0000-93d9-8694130e0000 pid=3603 execve guuid=0fa98f47-1700-0000-93d9-86941c0e0000 pid=3612 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=0fa98f47-1700-0000-93d9-86941c0e0000 pid=3612 execve guuid=18fe8e4b-1700-0000-93d9-8694270e0000 pid=3623 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=18fe8e4b-1700-0000-93d9-8694270e0000 pid=3623 clone guuid=eefaa44b-1700-0000-93d9-8694280e0000 pid=3624 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=eefaa44b-1700-0000-93d9-8694280e0000 pid=3624 execve guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625 execve guuid=5b78204c-1700-0000-93d9-86942d0e0000 pid=3629 /usr/bin/wget net send-data guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=5b78204c-1700-0000-93d9-86942d0e0000 pid=3629 execve guuid=3527004f-1700-0000-93d9-8694380e0000 pid=3640 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=3527004f-1700-0000-93d9-8694380e0000 pid=3640 execve guuid=a753c452-1700-0000-93d9-8694440e0000 pid=3652 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=a753c452-1700-0000-93d9-8694440e0000 pid=3652 clone guuid=02a9e252-1700-0000-93d9-8694470e0000 pid=3655 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=02a9e252-1700-0000-93d9-8694470e0000 pid=3655 execve guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657 execve guuid=52036153-1700-0000-93d9-86944d0e0000 pid=3661 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=52036153-1700-0000-93d9-86944d0e0000 pid=3661 execve guuid=68862b57-1700-0000-93d9-8694610e0000 pid=3681 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=68862b57-1700-0000-93d9-8694610e0000 pid=3681 execve guuid=e23dd25b-1700-0000-93d9-8694770e0000 pid=3703 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=e23dd25b-1700-0000-93d9-8694770e0000 pid=3703 clone guuid=4a22e75b-1700-0000-93d9-8694790e0000 pid=3705 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=4a22e75b-1700-0000-93d9-8694790e0000 pid=3705 execve guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707 execve guuid=8a4c885c-1700-0000-93d9-8694800e0000 pid=3712 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=8a4c885c-1700-0000-93d9-8694800e0000 pid=3712 execve guuid=ae0b4560-1700-0000-93d9-86948a0e0000 pid=3722 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=ae0b4560-1700-0000-93d9-86948a0e0000 pid=3722 execve guuid=d215b264-1700-0000-93d9-86949b0e0000 pid=3739 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=d215b264-1700-0000-93d9-86949b0e0000 pid=3739 clone guuid=6111cf64-1700-0000-93d9-86949c0e0000 pid=3740 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=6111cf64-1700-0000-93d9-86949c0e0000 pid=3740 execve guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743 execve guuid=bfac6765-1700-0000-93d9-8694a40e0000 pid=3748 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=bfac6765-1700-0000-93d9-8694a40e0000 pid=3748 execve guuid=a7023a69-1700-0000-93d9-8694b40e0000 pid=3764 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=a7023a69-1700-0000-93d9-8694b40e0000 pid=3764 execve guuid=7daed36f-1700-0000-93d9-8694d40e0000 pid=3796 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=7daed36f-1700-0000-93d9-8694d40e0000 pid=3796 clone guuid=4363f46f-1700-0000-93d9-8694d50e0000 pid=3797 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=4363f46f-1700-0000-93d9-8694d50e0000 pid=3797 execve guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799 execve guuid=43ed8770-1700-0000-93d9-8694dc0e0000 pid=3804 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=43ed8770-1700-0000-93d9-8694dc0e0000 pid=3804 execve guuid=10279a74-1700-0000-93d9-8694eb0e0000 pid=3819 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=10279a74-1700-0000-93d9-8694eb0e0000 pid=3819 execve guuid=690b5379-1700-0000-93d9-8694fc0e0000 pid=3836 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=690b5379-1700-0000-93d9-8694fc0e0000 pid=3836 clone guuid=4a646b79-1700-0000-93d9-8694fd0e0000 pid=3837 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=4a646b79-1700-0000-93d9-8694fd0e0000 pid=3837 execve guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840 execve guuid=a1df017a-1700-0000-93d9-8694040f0000 pid=3844 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=a1df017a-1700-0000-93d9-8694040f0000 pid=3844 execve guuid=dbbfed7e-1700-0000-93d9-86941a0f0000 pid=3866 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=dbbfed7e-1700-0000-93d9-86941a0f0000 pid=3866 execve guuid=a9e6a585-1700-0000-93d9-8694390f0000 pid=3897 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=a9e6a585-1700-0000-93d9-8694390f0000 pid=3897 clone guuid=39bac985-1700-0000-93d9-86943a0f0000 pid=3898 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=39bac985-1700-0000-93d9-86943a0f0000 pid=3898 execve guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899 execve guuid=3eba6286-1700-0000-93d9-8694410f0000 pid=3905 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=3eba6286-1700-0000-93d9-8694410f0000 pid=3905 execve guuid=ad20598a-1700-0000-93d9-86944c0f0000 pid=3916 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=ad20598a-1700-0000-93d9-86944c0f0000 pid=3916 execve guuid=c7045e8f-1700-0000-93d9-8694610f0000 pid=3937 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=c7045e8f-1700-0000-93d9-8694610f0000 pid=3937 clone guuid=673c818f-1700-0000-93d9-8694620f0000 pid=3938 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=673c818f-1700-0000-93d9-8694620f0000 pid=3938 execve guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939 execve guuid=611b5190-1700-0000-93d9-8694670f0000 pid=3943 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=611b5190-1700-0000-93d9-8694670f0000 pid=3943 execve guuid=78d12495-1700-0000-93d9-8694760f0000 pid=3958 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=78d12495-1700-0000-93d9-8694760f0000 pid=3958 execve guuid=db20cf9a-1700-0000-93d9-86948e0f0000 pid=3982 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=db20cf9a-1700-0000-93d9-86948e0f0000 pid=3982 clone guuid=14d6e59a-1700-0000-93d9-8694900f0000 pid=3984 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=14d6e59a-1700-0000-93d9-8694900f0000 pid=3984 execve guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987 execve guuid=90636b9b-1700-0000-93d9-8694980f0000 pid=3992 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=90636b9b-1700-0000-93d9-8694980f0000 pid=3992 execve guuid=a67c48a0-1700-0000-93d9-8694a80f0000 pid=4008 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=a67c48a0-1700-0000-93d9-8694a80f0000 pid=4008 execve guuid=35d179a6-1700-0000-93d9-8694bb0f0000 pid=4027 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=35d179a6-1700-0000-93d9-8694bb0f0000 pid=4027 clone guuid=2d8696a6-1700-0000-93d9-8694bc0f0000 pid=4028 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=2d8696a6-1700-0000-93d9-8694bc0f0000 pid=4028 execve guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029 execve guuid=954a3ba7-1700-0000-93d9-8694c40f0000 pid=4036 /usr/bin/wget net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=954a3ba7-1700-0000-93d9-8694c40f0000 pid=4036 execve guuid=fcd20dac-1700-0000-93d9-8694d80f0000 pid=4056 /usr/bin/curl net send-data write-file guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=fcd20dac-1700-0000-93d9-8694d80f0000 pid=4056 execve guuid=878c88b1-1700-0000-93d9-8694f00f0000 pid=4080 /usr/bin/bash guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=878c88b1-1700-0000-93d9-8694f00f0000 pid=4080 clone guuid=6a80a5b1-1700-0000-93d9-8694f10f0000 pid=4081 /usr/bin/chmod guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=6a80a5b1-1700-0000-93d9-8694f10f0000 pid=4081 execve guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085 /tmp/WTF net guuid=5389ad05-1700-0000-93d9-8694660d0000 pid=3430->guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085 execve 3c9cf1b4-e372-55da-9b98-da9ce4abcb12 87.121.84.111:80 guuid=d35e0c06-1700-0000-93d9-8694690d0000 pid=3433->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=9b720e0c-1700-0000-93d9-86947c0d0000 pid=3452->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B 9b330b3e-90c0-50bc-87ad-e38c03085da1 89.35.130.116:53 guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=760b771a-1700-0000-93d9-8694a50d0000 pid=3493 /tmp/WTF guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492->guuid=760b771a-1700-0000-93d9-8694a50d0000 pid=3493 clone guuid=8aa77a1a-1700-0000-93d9-8694a60d0000 pid=3494 /tmp/WTF guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492->guuid=8aa77a1a-1700-0000-93d9-8694a60d0000 pid=3494 clone guuid=f2b77f1a-1700-0000-93d9-8694a70d0000 pid=3495 /tmp/WTF net send-data zombie guuid=f134311a-1700-0000-93d9-8694a40d0000 pid=3492->guuid=f2b77f1a-1700-0000-93d9-8694a70d0000 pid=3495 clone 853ec484-78ec-5337-b43c-fe26dbf04d9c 89.35.130.116:3778 guuid=f2b77f1a-1700-0000-93d9-8694a70d0000 pid=3495->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=d5e48a1a-1700-0000-93d9-8694a80d0000 pid=3496->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=54d4a81e-1700-0000-93d9-8694a90d0000 pid=3497->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=bfe30d25-1700-0000-93d9-8694b80d0000 pid=3512 /tmp/WTF guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510->guuid=bfe30d25-1700-0000-93d9-8694b80d0000 pid=3512 clone guuid=979e1125-1700-0000-93d9-8694b90d0000 pid=3513 /tmp/WTF guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510->guuid=979e1125-1700-0000-93d9-8694b90d0000 pid=3513 clone guuid=23341525-1700-0000-93d9-8694ba0d0000 pid=3514 /tmp/WTF net send-data zombie guuid=6a34cf24-1700-0000-93d9-8694b60d0000 pid=3510->guuid=23341525-1700-0000-93d9-8694ba0d0000 pid=3514 clone guuid=23341525-1700-0000-93d9-8694ba0d0000 pid=3514->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=4a901f25-1700-0000-93d9-8694bc0d0000 pid=3516->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=2cfd252b-1700-0000-93d9-8694c90d0000 pid=3529->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=64e4433c-1700-0000-93d9-8694f70d0000 pid=3575 /tmp/WTF guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573->guuid=64e4433c-1700-0000-93d9-8694f70d0000 pid=3575 clone guuid=9cd04b3c-1700-0000-93d9-8694f80d0000 pid=3576 /tmp/WTF guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573->guuid=9cd04b3c-1700-0000-93d9-8694f80d0000 pid=3576 clone guuid=bebd533c-1700-0000-93d9-8694f90d0000 pid=3577 /tmp/WTF net send-data zombie guuid=5d28f33b-1700-0000-93d9-8694f50d0000 pid=3573->guuid=bebd533c-1700-0000-93d9-8694f90d0000 pid=3577 clone guuid=bebd533c-1700-0000-93d9-8694f90d0000 pid=3577->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=027d5f3c-1700-0000-93d9-8694fa0d0000 pid=3578->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=0ccd513f-1700-0000-93d9-8694010e0000 pid=3585->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=c08b3144-1700-0000-93d9-8694100e0000 pid=3600 /tmp/WTF guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599->guuid=c08b3144-1700-0000-93d9-8694100e0000 pid=3600 clone guuid=cb8f3544-1700-0000-93d9-8694110e0000 pid=3601 /tmp/WTF guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599->guuid=cb8f3544-1700-0000-93d9-8694110e0000 pid=3601 clone guuid=c61a3944-1700-0000-93d9-8694120e0000 pid=3602 /tmp/WTF net send-data zombie guuid=d8250044-1700-0000-93d9-86940f0e0000 pid=3599->guuid=c61a3944-1700-0000-93d9-8694120e0000 pid=3602 clone guuid=c61a3944-1700-0000-93d9-8694120e0000 pid=3602->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=da745a44-1700-0000-93d9-8694130e0000 pid=3603->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=0fa98f47-1700-0000-93d9-86941c0e0000 pid=3612->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=ada3114c-1700-0000-93d9-86942a0e0000 pid=3626 /tmp/WTF guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625->guuid=ada3114c-1700-0000-93d9-86942a0e0000 pid=3626 clone guuid=c85b154c-1700-0000-93d9-86942b0e0000 pid=3627 /tmp/WTF guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625->guuid=c85b154c-1700-0000-93d9-86942b0e0000 pid=3627 clone guuid=ca73184c-1700-0000-93d9-86942c0e0000 pid=3628 /tmp/WTF net send-data zombie guuid=e68ae64b-1700-0000-93d9-8694290e0000 pid=3625->guuid=ca73184c-1700-0000-93d9-86942c0e0000 pid=3628 clone guuid=ca73184c-1700-0000-93d9-86942c0e0000 pid=3628->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=5b78204c-1700-0000-93d9-86942d0e0000 pid=3629->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 152B guuid=3527004f-1700-0000-93d9-8694380e0000 pid=3640->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 101B guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=f5fd4f53-1700-0000-93d9-86944a0e0000 pid=3658 /tmp/WTF guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657->guuid=f5fd4f53-1700-0000-93d9-86944a0e0000 pid=3658 clone guuid=aed95353-1700-0000-93d9-86944b0e0000 pid=3659 /tmp/WTF guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657->guuid=aed95353-1700-0000-93d9-86944b0e0000 pid=3659 clone guuid=9db15853-1700-0000-93d9-86944c0e0000 pid=3660 /tmp/WTF net send-data zombie guuid=6acd2153-1700-0000-93d9-8694490e0000 pid=3657->guuid=9db15853-1700-0000-93d9-86944c0e0000 pid=3660 clone guuid=9db15853-1700-0000-93d9-86944c0e0000 pid=3660->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=52036153-1700-0000-93d9-86944d0e0000 pid=3661->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=68862b57-1700-0000-93d9-8694610e0000 pid=3681->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=f1b26e5c-1700-0000-93d9-86947c0e0000 pid=3708 /tmp/WTF guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707->guuid=f1b26e5c-1700-0000-93d9-86947c0e0000 pid=3708 clone guuid=8058725c-1700-0000-93d9-86947e0e0000 pid=3710 /tmp/WTF guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707->guuid=8058725c-1700-0000-93d9-86947e0e0000 pid=3710 clone guuid=a6ec775c-1700-0000-93d9-86947f0e0000 pid=3711 /tmp/WTF net send-data zombie guuid=88c5385c-1700-0000-93d9-86947b0e0000 pid=3707->guuid=a6ec775c-1700-0000-93d9-86947f0e0000 pid=3711 clone guuid=a6ec775c-1700-0000-93d9-86947f0e0000 pid=3711->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=8a4c885c-1700-0000-93d9-8694800e0000 pid=3712->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=ae0b4560-1700-0000-93d9-86948a0e0000 pid=3722->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=fc944f65-1700-0000-93d9-8694a00e0000 pid=3744 /tmp/WTF guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743->guuid=fc944f65-1700-0000-93d9-8694a00e0000 pid=3744 clone guuid=2d915865-1700-0000-93d9-8694a10e0000 pid=3745 /tmp/WTF guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743->guuid=2d915865-1700-0000-93d9-8694a10e0000 pid=3745 clone guuid=f5e95b65-1700-0000-93d9-8694a20e0000 pid=3746 /tmp/WTF net send-data zombie guuid=fe101f65-1700-0000-93d9-86949f0e0000 pid=3743->guuid=f5e95b65-1700-0000-93d9-8694a20e0000 pid=3746 clone guuid=f5e95b65-1700-0000-93d9-8694a20e0000 pid=3746->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=bfac6765-1700-0000-93d9-8694a40e0000 pid=3748->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=a7023a69-1700-0000-93d9-8694b40e0000 pid=3764->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=09f07470-1700-0000-93d9-8694d90e0000 pid=3801 /tmp/WTF guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799->guuid=09f07470-1700-0000-93d9-8694d90e0000 pid=3801 clone guuid=82df7770-1700-0000-93d9-8694da0e0000 pid=3802 /tmp/WTF guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799->guuid=82df7770-1700-0000-93d9-8694da0e0000 pid=3802 clone guuid=f8587c70-1700-0000-93d9-8694db0e0000 pid=3803 /tmp/WTF net send-data zombie guuid=2a5a4d70-1700-0000-93d9-8694d70e0000 pid=3799->guuid=f8587c70-1700-0000-93d9-8694db0e0000 pid=3803 clone guuid=f8587c70-1700-0000-93d9-8694db0e0000 pid=3803->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=43ed8770-1700-0000-93d9-8694dc0e0000 pid=3804->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=10279a74-1700-0000-93d9-8694eb0e0000 pid=3819->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=0128f279-1700-0000-93d9-8694010f0000 pid=3841 /tmp/WTF guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840->guuid=0128f279-1700-0000-93d9-8694010f0000 pid=3841 clone guuid=383bf679-1700-0000-93d9-8694020f0000 pid=3842 /tmp/WTF guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840->guuid=383bf679-1700-0000-93d9-8694020f0000 pid=3842 clone guuid=b72cfa79-1700-0000-93d9-8694030f0000 pid=3843 /tmp/WTF net send-data zombie guuid=bd2fb179-1700-0000-93d9-8694000f0000 pid=3840->guuid=b72cfa79-1700-0000-93d9-8694030f0000 pid=3843 clone guuid=b72cfa79-1700-0000-93d9-8694030f0000 pid=3843->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=a1df017a-1700-0000-93d9-8694040f0000 pid=3844->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=dbbfed7e-1700-0000-93d9-86941a0f0000 pid=3866->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=ae204e86-1700-0000-93d9-86943e0f0000 pid=3902 /tmp/WTF guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899->guuid=ae204e86-1700-0000-93d9-86943e0f0000 pid=3902 clone guuid=83bb5286-1700-0000-93d9-86943f0f0000 pid=3903 /tmp/WTF guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899->guuid=83bb5286-1700-0000-93d9-86943f0f0000 pid=3903 clone guuid=d2215886-1700-0000-93d9-8694400f0000 pid=3904 /tmp/WTF net send-data zombie guuid=f8e51586-1700-0000-93d9-86943b0f0000 pid=3899->guuid=d2215886-1700-0000-93d9-8694400f0000 pid=3904 clone guuid=d2215886-1700-0000-93d9-8694400f0000 pid=3904->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=3eba6286-1700-0000-93d9-8694410f0000 pid=3905->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=ad20598a-1700-0000-93d9-86944c0f0000 pid=3916->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=e8b92d90-1700-0000-93d9-8694640f0000 pid=3940 /tmp/WTF guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939->guuid=e8b92d90-1700-0000-93d9-8694640f0000 pid=3940 clone guuid=ee503290-1700-0000-93d9-8694650f0000 pid=3941 /tmp/WTF guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939->guuid=ee503290-1700-0000-93d9-8694650f0000 pid=3941 clone guuid=57b74090-1700-0000-93d9-8694660f0000 pid=3942 /tmp/WTF net send-data zombie guuid=52a7ea8f-1700-0000-93d9-8694630f0000 pid=3939->guuid=57b74090-1700-0000-93d9-8694660f0000 pid=3942 clone guuid=57b74090-1700-0000-93d9-8694660f0000 pid=3942->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=611b5190-1700-0000-93d9-8694670f0000 pid=3943->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=78d12495-1700-0000-93d9-8694760f0000 pid=3958->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=343c559b-1700-0000-93d9-8694940f0000 pid=3988 /tmp/WTF guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987->guuid=343c559b-1700-0000-93d9-8694940f0000 pid=3988 clone guuid=dc595d9b-1700-0000-93d9-8694960f0000 pid=3990 /tmp/WTF guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987->guuid=dc595d9b-1700-0000-93d9-8694960f0000 pid=3990 clone guuid=fc24649b-1700-0000-93d9-8694970f0000 pid=3991 /tmp/WTF net send-data zombie guuid=82052a9b-1700-0000-93d9-8694930f0000 pid=3987->guuid=fc24649b-1700-0000-93d9-8694970f0000 pid=3991 clone guuid=fc24649b-1700-0000-93d9-8694970f0000 pid=3991->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=90636b9b-1700-0000-93d9-8694980f0000 pid=3992->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 150B guuid=a67c48a0-1700-0000-93d9-8694a80f0000 pid=4008->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 99B guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=3fe72aa7-1700-0000-93d9-8694c10f0000 pid=4033 /tmp/WTF guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029->guuid=3fe72aa7-1700-0000-93d9-8694c10f0000 pid=4033 clone guuid=3b172fa7-1700-0000-93d9-8694c20f0000 pid=4034 /tmp/WTF guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029->guuid=3b172fa7-1700-0000-93d9-8694c20f0000 pid=4034 clone guuid=969033a7-1700-0000-93d9-8694c30f0000 pid=4035 /tmp/WTF net send-data zombie guuid=00b2fea6-1700-0000-93d9-8694bd0f0000 pid=4029->guuid=969033a7-1700-0000-93d9-8694c30f0000 pid=4035 clone guuid=969033a7-1700-0000-93d9-8694c30f0000 pid=4035->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B guuid=954a3ba7-1700-0000-93d9-8694c40f0000 pid=4036->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 149B guuid=fcd20dac-1700-0000-93d9-8694d80f0000 pid=4056->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 98B guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085->9b330b3e-90c0-50bc-87ad-e38c03085da1 con guuid=fd771eb2-1700-0000-93d9-8694f60f0000 pid=4086 /tmp/WTF guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085->guuid=fd771eb2-1700-0000-93d9-8694f60f0000 pid=4086 clone guuid=7d0e22b2-1700-0000-93d9-8694f70f0000 pid=4087 /tmp/WTF guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085->guuid=7d0e22b2-1700-0000-93d9-8694f70f0000 pid=4087 clone guuid=7a8929b2-1700-0000-93d9-8694f80f0000 pid=4088 /tmp/WTF net send-data zombie guuid=d000eeb1-1700-0000-93d9-8694f50f0000 pid=4085->guuid=7a8929b2-1700-0000-93d9-8694f80f0000 pid=4088 clone guuid=7a8929b2-1700-0000-93d9-8694f80f0000 pid=4088->853ec484-78ec-5337-b43c-fe26dbf04d9c send: 2B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-23 15:53:17 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4a3cb19457bef557ede860ec1b92aad9e82b48764e783bfbc5fc88a2918b36dd

(this sample)

Comments