MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 04b678c432faa97ffc08295ab79b08b5112e05e710d33d9452f229d905a6f3bb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 04b678c432faa97ffc08295ab79b08b5112e05e710d33d9452f229d905a6f3bb
SHA3-384 hash: 822acd6ec8a754f583832570698886b7c86a045668fca53638dfaa24db265868e7997e24eda7528859572c602e5e93f4
SHA1 hash: 0af993e3d02564ef074b9753d62abf04ac45a2dd
MD5 hash: e572bd38325694ca8f6cbf04d9a39718
humanhash: bacon-black-quiet-robin
File name:cache
Download: download sample
Signature Mirai
File size:4'230 bytes
First seen:2025-12-30 21:19:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vIULU+3lUEUWEUcUbUdUGUJUuUiUBURUnn:vIULUeUEUWEUcUbUdUGUJUuUiUBURUnn
TLSH T1CE91C6CA268347E43E7D99126ADDC618734848DA8D80BF85F5EEF5F14E8CDC62F88152
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.x860df73efae0aa434ef3ddee8230e0f9ade11e68f250e9c2491408439f96588bab Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.mips2554c816d666d91ec33d6116c6e4652d8e18b9a46df9f185360b1a614ddacc27 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.mpsl6a62d17a8f55a32c23e984468fd9d372c7a01508563a7c71da37f901384eb0ce Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.armd4d7b9b0377b3474ad5a3ad1862a71d6e92a4f7886c08045782f319befd0ec0e Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm5db7ddb446de639e7aeb450253ecde3d5c953c2cf53b5d034e8329ac77bd97e48 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm6ece2dff0367c776d34c59cee90b38a31bcf44e1ff8c734cf6dbadccbd2a5b304 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arm7b8092f3e0a5d0de77b5ddf3493ed5a2ab44a066ca85c95c64cf09f4871f148a8 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.ppcd78467b2efb42d5efdb88a8cdb44023df3b69ec22faccce57f646fac179d45f2 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.m68kd26b3a43548233e92b587858b11d5af13919fd48d860e9641e63dac08868a172 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.sh4ffa8532cd34c7e9a8efb776be026dc5bb06f74564b3b12a460843e24cd3b7bee Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.spc8469faa6b6fc5d886ce0ca171adfe31d3e107f57286311d695a8fae2b61e2f96 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.arc4d345ecc5e6050ada4f78395a2aeb68a24ef4aee4a471b464c3048da36a3ab41 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.x86_641340a32317df99872698a53f81c29e843065ed10b1ca82009b0646d87a69310d Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.i686a7082837a38e7e3987e2545b4c49b904b044205a6afc13203955f499b0ef0a11 Miraielf mirai ua-wget
http://130.12.180.28/z0l1mxjm4mdl4jjfjf7sb2vdmv/MMaaRRiiOisecTanee.i4869de387977796a0996b1e221c77c44190c947845841f280b691bb2a6b3ea56e9a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=65ee96fd-1800-0000-aab0-55c836090000 pid=2358 /usr/bin/sudo guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366 /tmp/sample.bin guuid=65ee96fd-1800-0000-aab0-55c836090000 pid=2358->guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366 execve guuid=79ea3201-1900-0000-aab0-55c842090000 pid=2370 /usr/bin/wget net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=79ea3201-1900-0000-aab0-55c842090000 pid=2370 execve guuid=99e33b08-1900-0000-aab0-55c84a090000 pid=2378 /usr/bin/curl net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=99e33b08-1900-0000-aab0-55c84a090000 pid=2378 execve guuid=44ca4114-1900-0000-aab0-55c85a090000 pid=2394 /usr/bin/cat guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=44ca4114-1900-0000-aab0-55c85a090000 pid=2394 execve guuid=7dadac14-1900-0000-aab0-55c85c090000 pid=2396 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=7dadac14-1900-0000-aab0-55c85c090000 pid=2396 execve guuid=0c1b2f15-1900-0000-aab0-55c85e090000 pid=2398 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=0c1b2f15-1900-0000-aab0-55c85e090000 pid=2398 execve guuid=0585d315-1900-0000-aab0-55c862090000 pid=2402 /usr/bin/wget net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=0585d315-1900-0000-aab0-55c862090000 pid=2402 execve guuid=99089f21-1900-0000-aab0-55c87a090000 pid=2426 /usr/bin/curl net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=99089f21-1900-0000-aab0-55c87a090000 pid=2426 execve guuid=dadb8a2a-1900-0000-aab0-55c88f090000 pid=2447 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=dadb8a2a-1900-0000-aab0-55c88f090000 pid=2447 clone guuid=5c98bc2a-1900-0000-aab0-55c891090000 pid=2449 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=5c98bc2a-1900-0000-aab0-55c891090000 pid=2449 execve guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450 execve guuid=244fe15a-1a00-0000-aab0-55c8190c0000 pid=3097 /usr/bin/wget net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=244fe15a-1a00-0000-aab0-55c8190c0000 pid=3097 execve guuid=cd25645c-1a00-0000-aab0-55c8210c0000 pid=3105 /usr/bin/curl net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=cd25645c-1a00-0000-aab0-55c8210c0000 pid=3105 execve guuid=fffabf61-1a00-0000-aab0-55c82b0c0000 pid=3115 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=fffabf61-1a00-0000-aab0-55c82b0c0000 pid=3115 clone guuid=12c9d261-1a00-0000-aab0-55c82c0c0000 pid=3116 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=12c9d261-1a00-0000-aab0-55c82c0c0000 pid=3116 execve guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118 execve guuid=98ece50b-2000-0000-aab0-55c890140000 pid=5264 /usr/bin/wget net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=98ece50b-2000-0000-aab0-55c890140000 pid=5264 execve guuid=2abd3b0d-2000-0000-aab0-55c894140000 pid=5268 /usr/bin/curl net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=2abd3b0d-2000-0000-aab0-55c894140000 pid=5268 execve guuid=bbc8fc0e-2000-0000-aab0-55c895140000 pid=5269 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=bbc8fc0e-2000-0000-aab0-55c895140000 pid=5269 clone guuid=e716130f-2000-0000-aab0-55c896140000 pid=5270 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=e716130f-2000-0000-aab0-55c896140000 pid=5270 execve guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271 execve guuid=24e7bac2-2500-0000-aab0-55c8ae140000 pid=5294 /usr/bin/wget net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=24e7bac2-2500-0000-aab0-55c8ae140000 pid=5294 execve guuid=3bee88c4-2500-0000-aab0-55c8b2140000 pid=5298 /usr/bin/curl net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=3bee88c4-2500-0000-aab0-55c8b2140000 pid=5298 execve guuid=ee7affc6-2500-0000-aab0-55c8b3140000 pid=5299 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=ee7affc6-2500-0000-aab0-55c8b3140000 pid=5299 clone guuid=e2a912c7-2500-0000-aab0-55c8b4140000 pid=5300 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=e2a912c7-2500-0000-aab0-55c8b4140000 pid=5300 execve guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301 execve guuid=d3ab3c6c-2b00-0000-aab0-55c8b9140000 pid=5305 /usr/bin/wget net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=d3ab3c6c-2b00-0000-aab0-55c8b9140000 pid=5305 execve guuid=dad9896e-2b00-0000-aab0-55c8bd140000 pid=5309 /usr/bin/curl net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=dad9896e-2b00-0000-aab0-55c8bd140000 pid=5309 execve guuid=c8b45a70-2b00-0000-aab0-55c8be140000 pid=5310 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=c8b45a70-2b00-0000-aab0-55c8be140000 pid=5310 clone guuid=e1ff7270-2b00-0000-aab0-55c8bf140000 pid=5311 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=e1ff7270-2b00-0000-aab0-55c8bf140000 pid=5311 execve guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312 execve guuid=735e79dd-2c00-0000-aab0-55c8d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=735e79dd-2c00-0000-aab0-55c8d2140000 pid=5330 execve guuid=74d5c2e3-2c00-0000-aab0-55c8d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=74d5c2e3-2c00-0000-aab0-55c8d3140000 pid=5331 execve guuid=7df9dbea-2c00-0000-aab0-55c8d4140000 pid=5332 /usr/bin/bash guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=7df9dbea-2c00-0000-aab0-55c8d4140000 pid=5332 clone guuid=1fd5faea-2c00-0000-aab0-55c8d5140000 pid=5333 /usr/bin/chmod guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=1fd5faea-2c00-0000-aab0-55c8d5140000 pid=5333 execve guuid=c57b44eb-2c00-0000-aab0-55c8d6140000 pid=5334 /tmp/lovers net guuid=9f007f00-1900-0000-aab0-55c83e090000 pid=2366->guuid=c57b44eb-2c00-0000-aab0-55c8d6140000 pid=5334 execve b6a64ba0-71d1-5d3d-a9f9-c19471e8250a 130.12.180.28:80 guuid=79ea3201-1900-0000-aab0-55c842090000 pid=2370->b6a64ba0-71d1-5d3d-a9f9-c19471e8250a send: 177B guuid=99e33b08-1900-0000-aab0-55c84a090000 pid=2378->b6a64ba0-71d1-5d3d-a9f9-c19471e8250a send: 126B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=0c1b2f15-1900-0000-aab0-55c85e090000 pid=2398->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eb33ac15-1900-0000-aab0-55c860090000 pid=2400 /tmp/lovers guuid=0c1b2f15-1900-0000-aab0-55c85e090000 pid=2398->guuid=eb33ac15-1900-0000-aab0-55c860090000 pid=2400 clone guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401 /tmp/lovers dns net send-data zombie guuid=0c1b2f15-1900-0000-aab0-55c85e090000 pid=2398->guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401 clone guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B 9cc227d1-c89a-5495-be19-d3b5e6414756 lmfao.school-kids.space:60195 guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->9cc227d1-c89a-5495-be19-d3b5e6414756 con guuid=4d752616-1900-0000-aab0-55c864090000 pid=2404 /tmp/lovers guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->guuid=4d752616-1900-0000-aab0-55c864090000 pid=2404 clone guuid=14f73316-1900-0000-aab0-55c865090000 pid=2405 /tmp/lovers guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->guuid=14f73316-1900-0000-aab0-55c865090000 pid=2405 clone guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406 /tmp/lovers net net-scan send-data guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406 clone guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407 /tmp/lovers net net-scan send-data guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407 clone guuid=c700f541-1a00-0000-aab0-55c8d00b0000 pid=3024 /tmp/lovers net guuid=94eeb515-1900-0000-aab0-55c861090000 pid=2401->guuid=c700f541-1a00-0000-aab0-55c8d00b0000 pid=3024 clone guuid=0585d315-1900-0000-aab0-55c862090000 pid=2402->b6a64ba0-71d1-5d3d-a9f9-c19471e8250a send: 178B guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406|send-data send-data to 800 IP addresses review logs to see them all guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406->guuid=fb7e3716-1900-0000-aab0-55c866090000 pid=2406|send-data send guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407|send-data send-data to 1280 IP addresses review logs to see them all guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407->guuid=57f73a16-1900-0000-aab0-55c867090000 pid=2407|send-data send guuid=99089f21-1900-0000-aab0-55c87a090000 pid=2426->b6a64ba0-71d1-5d3d-a9f9-c19471e8250a send: 127B guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b2d8e54b-c731-5e9d-91ce-9be6b900c2bd 0.0.0.0:63841 guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=1ffbd25a-1a00-0000-aab0-55c8170c0000 pid=3095 /tmp/lovers guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450->guuid=1ffbd25a-1a00-0000-aab0-55c8170c0000 pid=3095 clone guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096 /tmp/lovers dns net send-data zombie guuid=1078292b-1900-0000-aab0-55c892090000 pid=2450->guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096 clone guuid=c700f541-1a00-0000-aab0-55c8d00b0000 pid=3024->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->9cc227d1-c89a-5495-be19-d3b5e6414756 con guuid=6860e55a-1a00-0000-aab0-55c81a0c0000 pid=3098 /tmp/lovers guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->guuid=6860e55a-1a00-0000-aab0-55c81a0c0000 pid=3098 clone guuid=e8f2ef5a-1a00-0000-aab0-55c81b0c0000 pid=3099 /tmp/lovers guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->guuid=e8f2ef5a-1a00-0000-aab0-55c81b0c0000 pid=3099 clone guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100 /tmp/lovers net net-scan send-data zombie guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100 clone guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101 /tmp/lovers net net-scan send-data zombie guuid=5faad65a-1a00-0000-aab0-55c8180c0000 pid=3096->guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101 clone 72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d lmfao.school-kids.space:80 guuid=244fe15a-1a00-0000-aab0-55c8190c0000 pid=3097->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100|send-data send-data to 2720 IP addresses review logs to see them all guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100->guuid=a697f45a-1a00-0000-aab0-55c81c0c0000 pid=3100|send-data send guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101|send-data send-data to 4097 IP addresses review logs to see them all guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101->guuid=5200fe5a-1a00-0000-aab0-55c81d0c0000 pid=3101|send-data send guuid=cd25645c-1a00-0000-aab0-55c8210c0000 pid=3105->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=dea5d00b-2000-0000-aab0-55c88d140000 pid=5261 /tmp/lovers guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118->guuid=dea5d00b-2000-0000-aab0-55c88d140000 pid=5261 clone guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262 /tmp/lovers net send-data zombie guuid=fa9f1262-1a00-0000-aab0-55c82e0c0000 pid=3118->guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262 clone guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B guuid=f3bae10b-2000-0000-aab0-55c88f140000 pid=5263 /tmp/lovers guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262->guuid=f3bae10b-2000-0000-aab0-55c88f140000 pid=5263 clone guuid=931ee60b-2000-0000-aab0-55c891140000 pid=5265 /tmp/lovers guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262->guuid=931ee60b-2000-0000-aab0-55c891140000 pid=5265 clone guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266 /tmp/lovers net net-scan send-data zombie guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262->guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266 clone guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267 /tmp/lovers net net-scan send-data zombie guuid=9f2bd60b-2000-0000-aab0-55c88e140000 pid=5262->guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267 clone guuid=98ece50b-2000-0000-aab0-55c890140000 pid=5264->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266|send-data send-data to 2720 IP addresses review logs to see them all guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266->guuid=e1a1e90b-2000-0000-aab0-55c892140000 pid=5266|send-data send guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267|send-data send-data to 4097 IP addresses review logs to see them all guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267->guuid=7c0ced0b-2000-0000-aab0-55c893140000 pid=5267|send-data send guuid=2abd3b0d-2000-0000-aab0-55c894140000 pid=5268->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=66bf8ec2-2500-0000-aab0-55c8ab140000 pid=5291 /tmp/lovers guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271->guuid=66bf8ec2-2500-0000-aab0-55c8ab140000 pid=5291 clone guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292 /tmp/lovers net send-data zombie guuid=e4182e1a-2000-0000-aab0-55c897140000 pid=5271->guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292 clone guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B guuid=116db3c2-2500-0000-aab0-55c8ad140000 pid=5293 /tmp/lovers guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292->guuid=116db3c2-2500-0000-aab0-55c8ad140000 pid=5293 clone guuid=0bd0bbc2-2500-0000-aab0-55c8af140000 pid=5295 /tmp/lovers guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292->guuid=0bd0bbc2-2500-0000-aab0-55c8af140000 pid=5295 clone guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296 /tmp/lovers net net-scan send-data zombie guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292->guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296 clone guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297 /tmp/lovers net net-scan send-data zombie guuid=83149ac2-2500-0000-aab0-55c8ac140000 pid=5292->guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297 clone guuid=24e7bac2-2500-0000-aab0-55c8ae140000 pid=5294->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296|send-data send-data to 2720 IP addresses review logs to see them all guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296->guuid=319dc2c2-2500-0000-aab0-55c8b0140000 pid=5296|send-data send guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297|send-data send-data to 4097 IP addresses review logs to see them all guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297->guuid=d8fdc9c2-2500-0000-aab0-55c8b1140000 pid=5297|send-data send guuid=3bee88c4-2500-0000-aab0-55c8b2140000 pid=5298->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=af7d286c-2b00-0000-aab0-55c8b6140000 pid=5302 /tmp/lovers guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301->guuid=af7d286c-2b00-0000-aab0-55c8b6140000 pid=5302 clone guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303 /tmp/lovers dns net send-data zombie guuid=b80982c7-2500-0000-aab0-55c8b5140000 pid=5301->guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303 clone guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->9cc227d1-c89a-5495-be19-d3b5e6414756 con guuid=ca583a6c-2b00-0000-aab0-55c8b8140000 pid=5304 /tmp/lovers guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->guuid=ca583a6c-2b00-0000-aab0-55c8b8140000 pid=5304 clone guuid=9bbc3f6c-2b00-0000-aab0-55c8ba140000 pid=5306 /tmp/lovers guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->guuid=9bbc3f6c-2b00-0000-aab0-55c8ba140000 pid=5306 clone guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307 /tmp/lovers net net-scan send-data guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307 clone guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308 /tmp/lovers net net-scan send-data guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308 clone guuid=36cf8897-2c00-0000-aab0-55c8cb140000 pid=5323 /tmp/lovers net guuid=619b2e6c-2b00-0000-aab0-55c8b7140000 pid=5303->guuid=36cf8897-2c00-0000-aab0-55c8cb140000 pid=5323 clone guuid=d3ab3c6c-2b00-0000-aab0-55c8b9140000 pid=5305->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307|send-data send-data to 800 IP addresses review logs to see them all guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307->guuid=a507436c-2b00-0000-aab0-55c8bb140000 pid=5307|send-data send guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308|send-data send-data to 1280 IP addresses review logs to see them all guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308->guuid=2e05486c-2b00-0000-aab0-55c8bc140000 pid=5308|send-data send guuid=dad9896e-2b00-0000-aab0-55c8bd140000 pid=5309->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d con guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=043bb69e-2c00-0000-aab0-55c8cc140000 pid=5324 /tmp/lovers guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312->guuid=043bb69e-2c00-0000-aab0-55c8cc140000 pid=5324 clone guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325 /tmp/lovers dns net send-data zombie guuid=0b0fcc70-2b00-0000-aab0-55c8c0140000 pid=5312->guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325 clone guuid=36cf8897-2c00-0000-aab0-55c8cb140000 pid=5323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->9cc227d1-c89a-5495-be19-d3b5e6414756 send: 13B guuid=d0d7c89e-2c00-0000-aab0-55c8ce140000 pid=5326 /tmp/lovers guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->guuid=d0d7c89e-2c00-0000-aab0-55c8ce140000 pid=5326 clone guuid=eb1ece9e-2c00-0000-aab0-55c8cf140000 pid=5327 /tmp/lovers guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->guuid=eb1ece9e-2c00-0000-aab0-55c8cf140000 pid=5327 clone guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328 /tmp/lovers net net-scan send-data guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328 clone guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329 /tmp/lovers net net-scan send-data guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329 clone guuid=cfd471eb-2c00-0000-aab0-55c8d7140000 pid=5335 /tmp/lovers net guuid=ac59bb9e-2c00-0000-aab0-55c8cd140000 pid=5325->guuid=cfd471eb-2c00-0000-aab0-55c8d7140000 pid=5335 clone guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328|send-data send-data to 320 IP addresses review logs to see them all guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328->guuid=fc17d49e-2c00-0000-aab0-55c8d0140000 pid=5328|send-data send guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329|send-data send-data to 512 IP addresses review logs to see them all guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329->guuid=2712d89e-2c00-0000-aab0-55c8d1140000 pid=5329|send-data send guuid=735e79dd-2c00-0000-aab0-55c8d2140000 pid=5330->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d send: 178B guuid=74d5c2e3-2c00-0000-aab0-55c8d3140000 pid=5331->72b5e8ae-5c10-5f90-93a7-80ea2f9eba9d send: 127B guuid=c57b44eb-2c00-0000-aab0-55c8d6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c57b44eb-2c00-0000-aab0-55c8d6140000 pid=5334->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=cfd471eb-2c00-0000-aab0-55c8d7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-30 21:20:20 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (35620) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
lmfao.school-kids.space
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 04b678c432faa97ffc08295ab79b08b5112e05e710d33d9452f229d905a6f3bb

(this sample)

  
Delivery method
Distributed via web download

Comments