MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c8f85a30c8bb2727770f8967bb92eb91df4744ccaa5bd447eff39a98eca4b5b3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: c8f85a30c8bb2727770f8967bb92eb91df4744ccaa5bd447eff39a98eca4b5b3
SHA3-384 hash: ebc65facc1154968189c99ac3b6782e69d9e48f57d959b0dfbc612a65157eb20a07ef771a5627e116987196f4a9c428d
SHA1 hash: c5a420feab1dd4ca1149d52b87ec49d150309af9
MD5 hash: 3f129bcfe68569647bddf58e332bf035
humanhash: cold-sierra-king-friend
File name:1.sh
Download: download sample
Signature Mirai
File size:3'704 bytes
First seen:2026-05-03 14:25:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:imd1msjmrRm0TmW/mivm/RmxNmSTLmVBm8zmYH3mP0om/VmUvk:vdEs6rY0KWui+/YxMS2Vo8qYHWP0N/kd
TLSH T163714F8F100F5BB05D969EA372EF035C2D9690A7ECD69F03548C2AE4084BD19BD79973
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://80.241.218.210/wowiloveyou/runningaway.x8610695fc02fb7ed9d92802952c0af862d94b4fe4589f7ace5df7af2ba36ca3635 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.mips97ac484aa74fbe17a47ef1637f00374d3ebd2dfb783dc569fee50725c21a1373 Miraimirai
http://80.241.218.210/wowiloveyou/runningaway.arc570313c87ec20fefef12a164641621ab746b91362934a5f8a1553a615e253670 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.i468n/an/aelf ua-wget
http://80.241.218.210/wowiloveyou/runningaway.i6860a858cdb538c785c97631057073ebd5f65ec08e193cdd2ab3b2d97a875b216cb Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.x86_640eed41a6d3f5f77f1bdf1a9a51d13d9a892e76b1cbb5c97cb7981632f65cdb8d Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.mpslaeb87d989b47b8d9c3196d16b5bbea1a0eac94676a3c7aabb8686941592095ac Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.arme40922de45ba21f8f8077965a3b9597e46fac1d54d30827d5e4c932b50e0ea78 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.arm5f225e98fcf789f9479199ce38f6e6d0a1641c8e2348b9f7248657db9e8f9fa00 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.arm680eb6884cd0be934f31a22031b72e78d502eef1a9e0586a72e1d8127a5f4ef2d Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.arm71cdd2e48884da407e44e6e6010095ebb70015f3fd34548e6ff513d84b2548740 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.ppca422461b7167cb33800acb20c618a603537afc109048fcdc5cccce56fbbd7981 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.spc8db9f46f0d378287d2232193125965f36976f570182c47dae2ed7e63027cabc5 Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.m68kc277d2fb689f4cdd1a9a99dfea9990f38c024bc90d7e57e5435fea2910ab4bed Miraielf mirai opendir ua-wget
http://80.241.218.210/wowiloveyou/runningaway.sh4f087b6a25ecf7485382cfdcf2b85e2cda5c5aeb3592e3f3c5ddf801cd627d374 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-03T05:44:00Z UTC
Last seen:
2026-05-03T07:02:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=88b24957-2e00-0000-7327-b1b7a8030000 pid=936 /usr/bin/sudo guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937 /tmp/sample.bin guuid=88b24957-2e00-0000-7327-b1b7a8030000 pid=936->guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937 execve guuid=fe585b5a-2e00-0000-7327-b1b7aa030000 pid=938 /usr/bin/cp guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=fe585b5a-2e00-0000-7327-b1b7aa030000 pid=938 execve guuid=52770b5e-2e00-0000-7327-b1b7ab030000 pid=939 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=52770b5e-2e00-0000-7327-b1b7ab030000 pid=939 execve guuid=a59e69e2-2e00-0000-7327-b1b7ac030000 pid=940 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=a59e69e2-2e00-0000-7327-b1b7ac030000 pid=940 execve guuid=d2dabe30-2f00-0000-7327-b1b7ad030000 pid=941 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=d2dabe30-2f00-0000-7327-b1b7ad030000 pid=941 execve guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942 /tmp/runningaway.x86 net guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942 execve guuid=700e055f-3000-0000-7327-b1b7b4030000 pid=948 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=700e055f-3000-0000-7327-b1b7b4030000 pid=948 execve guuid=18f51360-3000-0000-7327-b1b7b5030000 pid=949 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=18f51360-3000-0000-7327-b1b7b5030000 pid=949 execve guuid=bfdbbf64-3000-0000-7327-b1b7b6030000 pid=950 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=bfdbbf64-3000-0000-7327-b1b7b6030000 pid=950 execve guuid=e0ab696b-3000-0000-7327-b1b7b7030000 pid=951 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=e0ab696b-3000-0000-7327-b1b7b7030000 pid=951 execve guuid=bbb6cd6b-3000-0000-7327-b1b7b8030000 pid=952 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=bbb6cd6b-3000-0000-7327-b1b7b8030000 pid=952 clone guuid=e51f9e6d-3000-0000-7327-b1b7ba030000 pid=954 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=e51f9e6d-3000-0000-7327-b1b7ba030000 pid=954 execve guuid=1d36256e-3000-0000-7327-b1b7bb030000 pid=955 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=1d36256e-3000-0000-7327-b1b7bb030000 pid=955 execve guuid=a8ad7f72-3000-0000-7327-b1b7bc030000 pid=956 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=a8ad7f72-3000-0000-7327-b1b7bc030000 pid=956 execve guuid=b8d4d177-3000-0000-7327-b1b7bd030000 pid=957 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=b8d4d177-3000-0000-7327-b1b7bd030000 pid=957 execve guuid=72612678-3000-0000-7327-b1b7be030000 pid=958 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=72612678-3000-0000-7327-b1b7be030000 pid=958 clone guuid=be73d278-3000-0000-7327-b1b7c0030000 pid=960 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=be73d278-3000-0000-7327-b1b7c0030000 pid=960 execve guuid=344d2779-3000-0000-7327-b1b7c1030000 pid=961 /usr/bin/wget net send-data guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=344d2779-3000-0000-7327-b1b7c1030000 pid=961 execve guuid=7ecdcf7c-3000-0000-7327-b1b7c2030000 pid=962 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=7ecdcf7c-3000-0000-7327-b1b7c2030000 pid=962 execve guuid=4fc0f980-3000-0000-7327-b1b7c3030000 pid=963 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=4fc0f980-3000-0000-7327-b1b7c3030000 pid=963 execve guuid=10dc4c81-3000-0000-7327-b1b7c4030000 pid=964 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=10dc4c81-3000-0000-7327-b1b7c4030000 pid=964 clone guuid=f02c8a81-3000-0000-7327-b1b7c5030000 pid=965 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=f02c8a81-3000-0000-7327-b1b7c5030000 pid=965 execve guuid=0a91e181-3000-0000-7327-b1b7c6030000 pid=966 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=0a91e181-3000-0000-7327-b1b7c6030000 pid=966 execve guuid=c1702eab-3000-0000-7327-b1b7c7030000 pid=967 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=c1702eab-3000-0000-7327-b1b7c7030000 pid=967 execve guuid=e0a1acb0-3000-0000-7327-b1b7c8030000 pid=968 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=e0a1acb0-3000-0000-7327-b1b7c8030000 pid=968 execve guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969 /tmp/runningaway.i686 net guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969 execve guuid=b1906bde-3100-0000-7327-b1b7f2040000 pid=1266 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=b1906bde-3100-0000-7327-b1b7f2040000 pid=1266 execve guuid=2379b5de-3100-0000-7327-b1b7f4040000 pid=1268 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=2379b5de-3100-0000-7327-b1b7f4040000 pid=1268 execve guuid=09c154e1-3100-0000-7327-b1b7fb040000 pid=1275 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=09c154e1-3100-0000-7327-b1b7fb040000 pid=1275 execve guuid=6bc7e2e4-3100-0000-7327-b1b707050000 pid=1287 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=6bc7e2e4-3100-0000-7327-b1b707050000 pid=1287 execve guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289 /tmp/runningaway.x86_64 mprotect-exec net guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289 execve guuid=49593510-3300-0000-7327-b1b76b060000 pid=1643 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=49593510-3300-0000-7327-b1b76b060000 pid=1643 execve guuid=477f8110-3300-0000-7327-b1b76c060000 pid=1644 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=477f8110-3300-0000-7327-b1b76c060000 pid=1644 execve guuid=c9eb4c14-3300-0000-7327-b1b779060000 pid=1657 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=c9eb4c14-3300-0000-7327-b1b779060000 pid=1657 execve guuid=26d0f318-3300-0000-7327-b1b786060000 pid=1670 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=26d0f318-3300-0000-7327-b1b786060000 pid=1670 execve guuid=90a56519-3300-0000-7327-b1b789060000 pid=1673 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=90a56519-3300-0000-7327-b1b789060000 pid=1673 clone guuid=677d0e1a-3300-0000-7327-b1b78d060000 pid=1677 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=677d0e1a-3300-0000-7327-b1b78d060000 pid=1677 execve guuid=329d0328-3300-0000-7327-b1b7b4060000 pid=1716 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=329d0328-3300-0000-7327-b1b7b4060000 pid=1716 execve guuid=87d09a2b-3300-0000-7327-b1b7bd060000 pid=1725 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=87d09a2b-3300-0000-7327-b1b7bd060000 pid=1725 execve guuid=32580430-3300-0000-7327-b1b7ca060000 pid=1738 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=32580430-3300-0000-7327-b1b7ca060000 pid=1738 execve guuid=a1af5630-3300-0000-7327-b1b7cc060000 pid=1740 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=a1af5630-3300-0000-7327-b1b7cc060000 pid=1740 clone guuid=e8d42c31-3300-0000-7327-b1b7d0060000 pid=1744 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=e8d42c31-3300-0000-7327-b1b7d0060000 pid=1744 execve guuid=d37f994e-3300-0000-7327-b1b7e7060000 pid=1767 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=d37f994e-3300-0000-7327-b1b7e7060000 pid=1767 execve guuid=736dfc52-3300-0000-7327-b1b7f1060000 pid=1777 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=736dfc52-3300-0000-7327-b1b7f1060000 pid=1777 execve guuid=fec76658-3300-0000-7327-b1b7fe060000 pid=1790 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=fec76658-3300-0000-7327-b1b7fe060000 pid=1790 execve guuid=eb44c758-3300-0000-7327-b1b700070000 pid=1792 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=eb44c758-3300-0000-7327-b1b700070000 pid=1792 clone guuid=a9ff5a59-3300-0000-7327-b1b704070000 pid=1796 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=a9ff5a59-3300-0000-7327-b1b704070000 pid=1796 execve guuid=7e5fb659-3300-0000-7327-b1b706070000 pid=1798 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=7e5fb659-3300-0000-7327-b1b706070000 pid=1798 execve guuid=b7920d5d-3300-0000-7327-b1b70f070000 pid=1807 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=b7920d5d-3300-0000-7327-b1b70f070000 pid=1807 execve guuid=57439261-3300-0000-7327-b1b71b070000 pid=1819 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=57439261-3300-0000-7327-b1b71b070000 pid=1819 execve guuid=dddaeb61-3300-0000-7327-b1b71d070000 pid=1821 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=dddaeb61-3300-0000-7327-b1b71d070000 pid=1821 clone guuid=53e08d62-3300-0000-7327-b1b71f070000 pid=1823 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=53e08d62-3300-0000-7327-b1b71f070000 pid=1823 execve guuid=bf9ace8c-3300-0000-7327-b1b720070000 pid=1824 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=bf9ace8c-3300-0000-7327-b1b720070000 pid=1824 execve guuid=33b11f91-3300-0000-7327-b1b729070000 pid=1833 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=33b11f91-3300-0000-7327-b1b729070000 pid=1833 execve guuid=60b09dca-3300-0000-7327-b1b735070000 pid=1845 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=60b09dca-3300-0000-7327-b1b735070000 pid=1845 execve guuid=3a4328cb-3300-0000-7327-b1b736070000 pid=1846 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=3a4328cb-3300-0000-7327-b1b736070000 pid=1846 clone guuid=2460f7cb-3300-0000-7327-b1b738070000 pid=1848 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=2460f7cb-3300-0000-7327-b1b738070000 pid=1848 execve guuid=eede57ce-3300-0000-7327-b1b739070000 pid=1849 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=eede57ce-3300-0000-7327-b1b739070000 pid=1849 execve guuid=267464d1-3300-0000-7327-b1b73d070000 pid=1853 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=267464d1-3300-0000-7327-b1b73d070000 pid=1853 execve guuid=6a0b49d6-3300-0000-7327-b1b749070000 pid=1865 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=6a0b49d6-3300-0000-7327-b1b749070000 pid=1865 execve guuid=7962a6d6-3300-0000-7327-b1b74b070000 pid=1867 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=7962a6d6-3300-0000-7327-b1b74b070000 pid=1867 clone guuid=b02951d7-3300-0000-7327-b1b74e070000 pid=1870 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=b02951d7-3300-0000-7327-b1b74e070000 pid=1870 execve guuid=5cabb1f5-3300-0000-7327-b1b750070000 pid=1872 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=5cabb1f5-3300-0000-7327-b1b750070000 pid=1872 execve guuid=8bdf16fb-3300-0000-7327-b1b757070000 pid=1879 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=8bdf16fb-3300-0000-7327-b1b757070000 pid=1879 execve guuid=5d983c03-3400-0000-7327-b1b766070000 pid=1894 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=5d983c03-3400-0000-7327-b1b766070000 pid=1894 execve guuid=7d199503-3400-0000-7327-b1b767070000 pid=1895 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=7d199503-3400-0000-7327-b1b767070000 pid=1895 clone guuid=e9f85b04-3400-0000-7327-b1b769070000 pid=1897 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=e9f85b04-3400-0000-7327-b1b769070000 pid=1897 execve guuid=5f933b18-3400-0000-7327-b1b76a070000 pid=1898 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=5f933b18-3400-0000-7327-b1b76a070000 pid=1898 execve guuid=af6be01b-3400-0000-7327-b1b772070000 pid=1906 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=af6be01b-3400-0000-7327-b1b772070000 pid=1906 execve guuid=8731d924-3400-0000-7327-b1b782070000 pid=1922 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=8731d924-3400-0000-7327-b1b782070000 pid=1922 execve guuid=32002825-3400-0000-7327-b1b784070000 pid=1924 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=32002825-3400-0000-7327-b1b784070000 pid=1924 clone guuid=690abe25-3400-0000-7327-b1b788070000 pid=1928 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=690abe25-3400-0000-7327-b1b788070000 pid=1928 execve guuid=0c7e0726-3400-0000-7327-b1b78a070000 pid=1930 /usr/bin/wget net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=0c7e0726-3400-0000-7327-b1b78a070000 pid=1930 execve guuid=f08b6a29-3400-0000-7327-b1b793070000 pid=1939 /usr/bin/curl net send-data write-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=f08b6a29-3400-0000-7327-b1b793070000 pid=1939 execve guuid=812c7430-3400-0000-7327-b1b7a1070000 pid=1953 /usr/bin/chmod guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=812c7430-3400-0000-7327-b1b7a1070000 pid=1953 execve guuid=4bece130-3400-0000-7327-b1b7a3070000 pid=1955 /usr/bin/bash guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=4bece130-3400-0000-7327-b1b7a3070000 pid=1955 clone guuid=4826c331-3400-0000-7327-b1b7a7070000 pid=1959 /usr/bin/rm delete-file guuid=ee427a59-2e00-0000-7327-b1b7a9030000 pid=937->guuid=4826c331-3400-0000-7327-b1b7a7070000 pid=1959 execve 91c7ec4b-425c-5967-af94-f220c588d2f5 80.241.218.210:80 guuid=52770b5e-2e00-0000-7327-b1b7ab030000 pid=939->91c7ec4b-425c-5967-af94-f220c588d2f5 send: 156B guuid=a59e69e2-2e00-0000-7327-b1b7ac030000 pid=940->91c7ec4b-425c-5967-af94-f220c588d2f5 send: 105B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0a44f731-2f00-0000-7327-b1b7af030000 pid=943 /tmp/runningaway.x86 guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942->guuid=0a44f731-2f00-0000-7327-b1b7af030000 pid=943 clone guuid=2535e15e-3000-0000-7327-b1b7b2030000 pid=946 /tmp/runningaway.x86 guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942->guuid=2535e15e-3000-0000-7327-b1b7b2030000 pid=946 clone guuid=4100ed5e-3000-0000-7327-b1b7b3030000 pid=947 /tmp/runningaway.x86 net send-data zombie guuid=ca7a3c31-2f00-0000-7327-b1b7ae030000 pid=942->guuid=4100ed5e-3000-0000-7327-b1b7b3030000 pid=947 clone guuid=df4f0032-2f00-0000-7327-b1b7b0030000 pid=944 /tmp/runningaway.x86 guuid=0a44f731-2f00-0000-7327-b1b7af030000 pid=943->guuid=df4f0032-2f00-0000-7327-b1b7b0030000 pid=944 clone guuid=26090532-2f00-0000-7327-b1b7b1030000 pid=945 /tmp/runningaway.x86 dns net send-data zombie guuid=0a44f731-2f00-0000-7327-b1b7af030000 pid=943->guuid=26090532-2f00-0000-7327-b1b7b1030000 pid=945 clone guuid=26090532-2f00-0000-7327-b1b7b1030000 pid=945->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B 347a3ebf-6db5-563f-9d27-5497a533528d wowo.biz.id:69 guuid=26090532-2f00-0000-7327-b1b7b1030000 pid=945->347a3ebf-6db5-563f-9d27-5497a533528d send: 25B guuid=4100ed5e-3000-0000-7327-b1b7b3030000 pid=947->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=4100ed5e-3000-0000-7327-b1b7b3030000 pid=947->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B 7e04c0a7-154d-541f-a118-6205f5790212 wowo.biz.id:80 guuid=18f51360-3000-0000-7327-b1b7b5030000 pid=949->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=bfdbbf64-3000-0000-7327-b1b7b6030000 pid=950->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=1d36256e-3000-0000-7327-b1b7bb030000 pid=955->7e04c0a7-154d-541f-a118-6205f5790212 send: 156B guuid=a8ad7f72-3000-0000-7327-b1b7bc030000 pid=956->7e04c0a7-154d-541f-a118-6205f5790212 send: 105B guuid=344d2779-3000-0000-7327-b1b7c1030000 pid=961->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=7ecdcf7c-3000-0000-7327-b1b7c2030000 pid=962->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=0a91e181-3000-0000-7327-b1b7c6030000 pid=966->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=c1702eab-3000-0000-7327-b1b7c7030000 pid=967->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d42308b2-3000-0000-7327-b1b7ca030000 pid=970 /tmp/runningaway.i686 guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969->guuid=d42308b2-3000-0000-7327-b1b7ca030000 pid=970 clone guuid=8d9357de-3100-0000-7327-b1b7f0040000 pid=1264 /tmp/runningaway.i686 guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969->guuid=8d9357de-3100-0000-7327-b1b7f0040000 pid=1264 clone guuid=ff885cde-3100-0000-7327-b1b7f1040000 pid=1265 /tmp/runningaway.i686 net send-data zombie guuid=cc0436b1-3000-0000-7327-b1b7c9030000 pid=969->guuid=ff885cde-3100-0000-7327-b1b7f1040000 pid=1265 clone guuid=e1ee12b2-3000-0000-7327-b1b7cb030000 pid=971 /tmp/runningaway.i686 guuid=d42308b2-3000-0000-7327-b1b7ca030000 pid=970->guuid=e1ee12b2-3000-0000-7327-b1b7cb030000 pid=971 clone guuid=20dd1cb2-3000-0000-7327-b1b7cc030000 pid=972 /tmp/runningaway.i686 dns net send-data zombie guuid=d42308b2-3000-0000-7327-b1b7ca030000 pid=970->guuid=20dd1cb2-3000-0000-7327-b1b7cc030000 pid=972 clone guuid=20dd1cb2-3000-0000-7327-b1b7cc030000 pid=972->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B guuid=20dd1cb2-3000-0000-7327-b1b7cc030000 pid=972->347a3ebf-6db5-563f-9d27-5497a533528d send: 26B guuid=ff885cde-3100-0000-7327-b1b7f1040000 pid=1265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B guuid=ff885cde-3100-0000-7327-b1b7f1040000 pid=1265->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2379b5de-3100-0000-7327-b1b7f4040000 pid=1268->7e04c0a7-154d-541f-a118-6205f5790212 send: 159B guuid=09c154e1-3100-0000-7327-b1b7fb040000 pid=1275->7e04c0a7-154d-541f-a118-6205f5790212 send: 108B guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba43a2e5-3100-0000-7327-b1b70b050000 pid=1291 /tmp/runningaway.x86_64 guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289->guuid=ba43a2e5-3100-0000-7327-b1b70b050000 pid=1291 clone guuid=52c12710-3300-0000-7327-b1b768060000 pid=1640 /tmp/runningaway.x86_64 guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289->guuid=52c12710-3300-0000-7327-b1b768060000 pid=1640 clone guuid=6ab22b10-3300-0000-7327-b1b769060000 pid=1641 /tmp/runningaway.x86_64 net send-data zombie guuid=804929e5-3100-0000-7327-b1b709050000 pid=1289->guuid=6ab22b10-3300-0000-7327-b1b769060000 pid=1641 clone guuid=34b0a9e5-3100-0000-7327-b1b70c050000 pid=1292 /tmp/runningaway.x86_64 guuid=ba43a2e5-3100-0000-7327-b1b70b050000 pid=1291->guuid=34b0a9e5-3100-0000-7327-b1b70c050000 pid=1292 clone guuid=db1fade5-3100-0000-7327-b1b70d050000 pid=1293 /tmp/runningaway.x86_64 net send-data zombie guuid=ba43a2e5-3100-0000-7327-b1b70b050000 pid=1291->guuid=db1fade5-3100-0000-7327-b1b70d050000 pid=1293 clone guuid=db1fade5-3100-0000-7327-b1b70d050000 pid=1293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 725B guuid=db1fade5-3100-0000-7327-b1b70d050000 pid=1293->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=6ab22b10-3300-0000-7327-b1b769060000 pid=1641->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 580B guuid=6ab22b10-3300-0000-7327-b1b769060000 pid=1641->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=477f8110-3300-0000-7327-b1b76c060000 pid=1644->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=c9eb4c14-3300-0000-7327-b1b779060000 pid=1657->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=329d0328-3300-0000-7327-b1b7b4060000 pid=1716->7e04c0a7-154d-541f-a118-6205f5790212 send: 156B guuid=87d09a2b-3300-0000-7327-b1b7bd060000 pid=1725->7e04c0a7-154d-541f-a118-6205f5790212 send: 105B guuid=d37f994e-3300-0000-7327-b1b7e7060000 pid=1767->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=736dfc52-3300-0000-7327-b1b7f1060000 pid=1777->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=7e5fb659-3300-0000-7327-b1b706070000 pid=1798->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=b7920d5d-3300-0000-7327-b1b70f070000 pid=1807->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=bf9ace8c-3300-0000-7327-b1b720070000 pid=1824->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=33b11f91-3300-0000-7327-b1b729070000 pid=1833->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=eede57ce-3300-0000-7327-b1b739070000 pid=1849->7e04c0a7-154d-541f-a118-6205f5790212 send: 156B guuid=267464d1-3300-0000-7327-b1b73d070000 pid=1853->7e04c0a7-154d-541f-a118-6205f5790212 send: 105B guuid=5cabb1f5-3300-0000-7327-b1b750070000 pid=1872->7e04c0a7-154d-541f-a118-6205f5790212 send: 156B guuid=8bdf16fb-3300-0000-7327-b1b757070000 pid=1879->7e04c0a7-154d-541f-a118-6205f5790212 send: 105B guuid=5f933b18-3400-0000-7327-b1b76a070000 pid=1898->7e04c0a7-154d-541f-a118-6205f5790212 send: 157B guuid=af6be01b-3400-0000-7327-b1b772070000 pid=1906->7e04c0a7-154d-541f-a118-6205f5790212 send: 106B guuid=0c7e0726-3400-0000-7327-b1b78a070000 pid=1930->7e04c0a7-154d-541f-a118-6205f5790212 send: 156B guuid=f08b6a29-3400-0000-7327-b1b793070000 pid=1939->7e04c0a7-154d-541f-a118-6205f5790212 send: 105B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-05-03 14:27:47 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Malware Config
C2 Extraction:
wowo.biz.id
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c8f85a30c8bb2727770f8967bb92eb91df4744ccaa5bd447eff39a98eca4b5b3

(this sample)

  
Delivery method
Distributed via web download

Comments