MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0779e3aaecf413f7e1cf4bda84bdbd020093977742df6889dcf6cf535070690e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 0779e3aaecf413f7e1cf4bda84bdbd020093977742df6889dcf6cf535070690e
SHA3-384 hash: 39db775053e91a8ce6626651e41ed14fb2f1dc055b4758410674df99d32a92ea88791bc8fcb910e238dbe27390dda566
SHA1 hash: 49a90cc34adaa6f508fda84d9963bf4a6003c191
MD5 hash: f39d54871f6b5ca8163460e2ff0e256b
humanhash: snake-echo-avocado-washington
File name:lol.sh
Download: download sample
Signature Mirai
File size:3'874 bytes
First seen:2025-10-26 22:43:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItrsZyV5bZ8sUYo7vJFC0CLF8O8NIuHksLsK6wCsLqYYO7/NYGsM:igZSNZRUYo7BILLcJ6+LqYD7/NYGsM
TLSH T1F5815A8D24565F7358ADAF62E26A054B7357649186CF8F06FBCC68E98088D0E7304BCD
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.102/windyluvexecutor/executor.x86865a75b150a813340a7104d5560a85cd6d67a2356222dcc869996f5a4419517e MiraiDEU elf geofenced mirai ua-wget USA x86
http://143.20.185.102/windyluvexecutor/executor.mipsdc64c12b0ec473e915c9d177dd4731f88e8d3d50e6eb0c5dbd2f5d37c9a4da35 Miraielf geofenced mips mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.arc7f379aa86e371fdc573095e500828b2e143a1fb77c11a8223216d0d96786739a Miraiarc elf geofenced mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.i468n/an/aDEU elf geofenced ua-wget
http://143.20.185.102/windyluvexecutor/executor.i68623c81b361a96e2884bb187ba241e751cdab9f5da2f1dde37dd2c9c8e1505f9c8 Miraielf geofenced mirai ua-wget USA x86
http://143.20.185.102/windyluvexecutor/executor.x86_6403796d3a2d2ab7dbd786648e5d972f5a8456bb61cc635f34797dd7d63d95126b Miraielf geofenced mirai ua-wget USA x86
http://143.20.185.102/windyluvexecutor/executor.mpslc0e9a142c33347f399bfdf1069309e9a8eed39e79ee22e494ffd58af2631abc8 Miraielf geofenced mips mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.armbac5d8c3e9b94bae1a46746647843b0432cad631c81ce78a0119c3528c2fd9a3 Miraiarm DEU elf geofenced mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.arm58cd3535da95571a635a3237a6442789af1b8f8876c5fc14b085b09b2bc18f21e Miraiarm DEU elf geofenced mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.arm6e5b9b14bbee46a556b83c426ae2ff1333002d8af8a05dd500dd764338950cfcc Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.arm7ce7ea8c1648fcb4720e47f3d08356f74b58dcf4f4d5030f970ffb5a8d5f23385 Miraiarm DEU elf geofenced mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.ppc25065b23fd9d6e28220ff769f3277344ea8237999862953f9bbb546744c1dccf Miraielf geofenced mirai PowerPC ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.spced18b58920110d347404ee4367ba6e198ea83c37bdac26d989ec2429e443ce18 Miraielf geofenced mirai sparc ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.m68k8dc34fdd0f9b236af5d88c1d4e8fb06381488dc70903f16c106d5393da816f14 Miraielf geofenced m68k mirai ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.sh48b72d37d2e563142a0bcafc4b1e4cd7a9b1e4f97fd906e799b4a4bf8d9c250e6 MiraiDEU elf geofenced mirai SuperH ua-wget USA
http://143.20.185.102/windyluvexecutor/executor.arm64148ddb73e5415fcb6564679c37c9361615d6d9c1650a1060e076b25ce28fc1d2 Miraiarm DEU elf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-26T04:18:00Z UTC
Last seen:
2025-10-27T10:13:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=57545c7a-1b00-0000-01a3-f1080e0b0000 pid=2830 /usr/bin/sudo guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833 /tmp/sample.bin guuid=57545c7a-1b00-0000-01a3-f1080e0b0000 pid=2830->guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833 execve guuid=e8f79a7c-1b00-0000-01a3-f108130b0000 pid=2835 /usr/bin/cp guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=e8f79a7c-1b00-0000-01a3-f108130b0000 pid=2835 execve guuid=e3541c82-1b00-0000-01a3-f1081e0b0000 pid=2846 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=e3541c82-1b00-0000-01a3-f1081e0b0000 pid=2846 execve guuid=a1897c94-1b00-0000-01a3-f108410b0000 pid=2881 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=a1897c94-1b00-0000-01a3-f108410b0000 pid=2881 execve guuid=0cda45a8-1b00-0000-01a3-f108680b0000 pid=2920 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=0cda45a8-1b00-0000-01a3-f108680b0000 pid=2920 execve guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921 /tmp/executor.x86 net guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921 execve guuid=f344b4d5-1c00-0000-01a3-f108b10d0000 pid=3505 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=f344b4d5-1c00-0000-01a3-f108b10d0000 pid=3505 execve guuid=9a9c25d6-1c00-0000-01a3-f108b40d0000 pid=3508 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9a9c25d6-1c00-0000-01a3-f108b40d0000 pid=3508 execve guuid=835f8ce7-1c00-0000-01a3-f108cf0d0000 pid=3535 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=835f8ce7-1c00-0000-01a3-f108cf0d0000 pid=3535 execve guuid=a4ebfdf9-1c00-0000-01a3-f108fa0d0000 pid=3578 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=a4ebfdf9-1c00-0000-01a3-f108fa0d0000 pid=3578 execve guuid=50e972fa-1c00-0000-01a3-f108fc0d0000 pid=3580 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=50e972fa-1c00-0000-01a3-f108fc0d0000 pid=3580 clone guuid=1b3a7ffb-1c00-0000-01a3-f108fe0d0000 pid=3582 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=1b3a7ffb-1c00-0000-01a3-f108fe0d0000 pid=3582 execve guuid=9c5ef217-1d00-0000-01a3-f108ff0d0000 pid=3583 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9c5ef217-1d00-0000-01a3-f108ff0d0000 pid=3583 execve guuid=d915562c-1d00-0000-01a3-f108330e0000 pid=3635 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=d915562c-1d00-0000-01a3-f108330e0000 pid=3635 execve guuid=8c79f43f-1d00-0000-01a3-f1085c0e0000 pid=3676 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=8c79f43f-1d00-0000-01a3-f1085c0e0000 pid=3676 execve guuid=55775640-1d00-0000-01a3-f1085d0e0000 pid=3677 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=55775640-1d00-0000-01a3-f1085d0e0000 pid=3677 clone guuid=90aa3841-1d00-0000-01a3-f1085f0e0000 pid=3679 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=90aa3841-1d00-0000-01a3-f1085f0e0000 pid=3679 execve guuid=d1f2a541-1d00-0000-01a3-f108600e0000 pid=3680 /usr/bin/wget net send-data guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=d1f2a541-1d00-0000-01a3-f108600e0000 pid=3680 execve guuid=b41ff746-1d00-0000-01a3-f1086d0e0000 pid=3693 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=b41ff746-1d00-0000-01a3-f1086d0e0000 pid=3693 execve guuid=06df6c4f-1d00-0000-01a3-f108810e0000 pid=3713 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=06df6c4f-1d00-0000-01a3-f108810e0000 pid=3713 execve guuid=476bb74f-1d00-0000-01a3-f108830e0000 pid=3715 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=476bb74f-1d00-0000-01a3-f108830e0000 pid=3715 clone guuid=11a4df4f-1d00-0000-01a3-f108860e0000 pid=3718 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=11a4df4f-1d00-0000-01a3-f108860e0000 pid=3718 execve guuid=aa0c2f50-1d00-0000-01a3-f108880e0000 pid=3720 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=aa0c2f50-1d00-0000-01a3-f108880e0000 pid=3720 execve guuid=4b406f60-1d00-0000-01a3-f108c30e0000 pid=3779 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=4b406f60-1d00-0000-01a3-f108c30e0000 pid=3779 execve guuid=882d0472-1d00-0000-01a3-f108030f0000 pid=3843 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=882d0472-1d00-0000-01a3-f108030f0000 pid=3843 execve guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846 /tmp/executor.i686 net guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846 execve guuid=55c1249f-1e00-0000-01a3-f1086c120000 pid=4716 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=55c1249f-1e00-0000-01a3-f1086c120000 pid=4716 execve guuid=2c0ba19f-1e00-0000-01a3-f1086e120000 pid=4718 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=2c0ba19f-1e00-0000-01a3-f1086e120000 pid=4718 execve guuid=34361caf-1e00-0000-01a3-f1089d120000 pid=4765 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=34361caf-1e00-0000-01a3-f1089d120000 pid=4765 execve guuid=74300fc0-1e00-0000-01a3-f108cc120000 pid=4812 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=74300fc0-1e00-0000-01a3-f108cc120000 pid=4812 execve guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814 /tmp/executor.x86_64 mprotect-exec net guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814 execve guuid=074bcbeb-1f00-0000-01a3-f10895140000 pid=5269 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=074bcbeb-1f00-0000-01a3-f10895140000 pid=5269 execve guuid=5c69a2ec-1f00-0000-01a3-f10896140000 pid=5270 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=5c69a2ec-1f00-0000-01a3-f10896140000 pid=5270 execve guuid=f7046bfd-1f00-0000-01a3-f10897140000 pid=5271 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=f7046bfd-1f00-0000-01a3-f10897140000 pid=5271 execve guuid=fc5b300f-2000-0000-01a3-f10898140000 pid=5272 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=fc5b300f-2000-0000-01a3-f10898140000 pid=5272 execve guuid=71af850f-2000-0000-01a3-f10899140000 pid=5273 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=71af850f-2000-0000-01a3-f10899140000 pid=5273 clone guuid=779cbd10-2000-0000-01a3-f1089b140000 pid=5275 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=779cbd10-2000-0000-01a3-f1089b140000 pid=5275 execve guuid=ffd41511-2000-0000-01a3-f1089c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=ffd41511-2000-0000-01a3-f1089c140000 pid=5276 execve guuid=80d8511e-2000-0000-01a3-f1089d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=80d8511e-2000-0000-01a3-f1089d140000 pid=5277 execve guuid=6305382e-2000-0000-01a3-f1089e140000 pid=5278 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=6305382e-2000-0000-01a3-f1089e140000 pid=5278 execve guuid=fa858c2e-2000-0000-01a3-f1089f140000 pid=5279 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=fa858c2e-2000-0000-01a3-f1089f140000 pid=5279 clone guuid=b97b7530-2000-0000-01a3-f108a1140000 pid=5281 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=b97b7530-2000-0000-01a3-f108a1140000 pid=5281 execve guuid=34127b31-2000-0000-01a3-f108a2140000 pid=5282 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=34127b31-2000-0000-01a3-f108a2140000 pid=5282 execve guuid=c4050b3e-2000-0000-01a3-f108a3140000 pid=5283 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=c4050b3e-2000-0000-01a3-f108a3140000 pid=5283 execve guuid=e679d94d-2000-0000-01a3-f108a4140000 pid=5284 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=e679d94d-2000-0000-01a3-f108a4140000 pid=5284 execve guuid=eec43d4e-2000-0000-01a3-f108a5140000 pid=5285 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=eec43d4e-2000-0000-01a3-f108a5140000 pid=5285 clone guuid=1a90ed4e-2000-0000-01a3-f108a7140000 pid=5287 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=1a90ed4e-2000-0000-01a3-f108a7140000 pid=5287 execve guuid=a923414f-2000-0000-01a3-f108a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=a923414f-2000-0000-01a3-f108a8140000 pid=5288 execve guuid=2606eb5d-2000-0000-01a3-f108a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=2606eb5d-2000-0000-01a3-f108a9140000 pid=5289 execve guuid=333fba6c-2000-0000-01a3-f108aa140000 pid=5290 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=333fba6c-2000-0000-01a3-f108aa140000 pid=5290 execve guuid=5b51136d-2000-0000-01a3-f108ab140000 pid=5291 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=5b51136d-2000-0000-01a3-f108ab140000 pid=5291 clone guuid=99bfcd6d-2000-0000-01a3-f108ad140000 pid=5293 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=99bfcd6d-2000-0000-01a3-f108ad140000 pid=5293 execve guuid=c6404a70-2000-0000-01a3-f108ae140000 pid=5294 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=c6404a70-2000-0000-01a3-f108ae140000 pid=5294 execve guuid=ace68f81-2000-0000-01a3-f108af140000 pid=5295 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=ace68f81-2000-0000-01a3-f108af140000 pid=5295 execve guuid=647e7b94-2000-0000-01a3-f108b7140000 pid=5303 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=647e7b94-2000-0000-01a3-f108b7140000 pid=5303 execve guuid=64bc3195-2000-0000-01a3-f108b8140000 pid=5304 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=64bc3195-2000-0000-01a3-f108b8140000 pid=5304 clone guuid=4f8a5997-2000-0000-01a3-f108ba140000 pid=5306 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=4f8a5997-2000-0000-01a3-f108ba140000 pid=5306 execve guuid=ce8d3b98-2000-0000-01a3-f108bb140000 pid=5307 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=ce8d3b98-2000-0000-01a3-f108bb140000 pid=5307 execve guuid=9cd64ea8-2000-0000-01a3-f108bc140000 pid=5308 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9cd64ea8-2000-0000-01a3-f108bc140000 pid=5308 execve guuid=066ca1b8-2000-0000-01a3-f108bd140000 pid=5309 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=066ca1b8-2000-0000-01a3-f108bd140000 pid=5309 execve guuid=de691cb9-2000-0000-01a3-f108be140000 pid=5310 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=de691cb9-2000-0000-01a3-f108be140000 pid=5310 clone guuid=84db01ba-2000-0000-01a3-f108c0140000 pid=5312 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=84db01ba-2000-0000-01a3-f108c0140000 pid=5312 execve guuid=1b9e6cdd-2000-0000-01a3-f108c1140000 pid=5313 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=1b9e6cdd-2000-0000-01a3-f108c1140000 pid=5313 execve guuid=1b59e6fc-2000-0000-01a3-f108c2140000 pid=5314 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=1b59e6fc-2000-0000-01a3-f108c2140000 pid=5314 execve guuid=2d88e610-2100-0000-01a3-f108c3140000 pid=5315 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=2d88e610-2100-0000-01a3-f108c3140000 pid=5315 execve guuid=a6d4cf11-2100-0000-01a3-f108c4140000 pid=5316 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=a6d4cf11-2100-0000-01a3-f108c4140000 pid=5316 clone guuid=cf0f3d13-2100-0000-01a3-f108c6140000 pid=5318 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=cf0f3d13-2100-0000-01a3-f108c6140000 pid=5318 execve guuid=03b3b713-2100-0000-01a3-f108c7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=03b3b713-2100-0000-01a3-f108c7140000 pid=5319 execve guuid=275fad27-2100-0000-01a3-f108c8140000 pid=5320 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=275fad27-2100-0000-01a3-f108c8140000 pid=5320 execve guuid=8509643c-2100-0000-01a3-f108c9140000 pid=5321 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=8509643c-2100-0000-01a3-f108c9140000 pid=5321 execve guuid=264bf93c-2100-0000-01a3-f108ca140000 pid=5322 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=264bf93c-2100-0000-01a3-f108ca140000 pid=5322 clone guuid=b9510241-2100-0000-01a3-f108cc140000 pid=5324 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=b9510241-2100-0000-01a3-f108cc140000 pid=5324 execve guuid=c53e7041-2100-0000-01a3-f108cd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=c53e7041-2100-0000-01a3-f108cd140000 pid=5325 execve guuid=6ee40753-2100-0000-01a3-f108ce140000 pid=5326 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=6ee40753-2100-0000-01a3-f108ce140000 pid=5326 execve guuid=909cca66-2100-0000-01a3-f108cf140000 pid=5327 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=909cca66-2100-0000-01a3-f108cf140000 pid=5327 execve guuid=9cf02e67-2100-0000-01a3-f108d0140000 pid=5328 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9cf02e67-2100-0000-01a3-f108d0140000 pid=5328 clone guuid=a825dd68-2100-0000-01a3-f108d2140000 pid=5330 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=a825dd68-2100-0000-01a3-f108d2140000 pid=5330 execve guuid=bfe63669-2100-0000-01a3-f108d3140000 pid=5331 /usr/bin/wget net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=bfe63669-2100-0000-01a3-f108d3140000 pid=5331 execve guuid=62fa487e-2100-0000-01a3-f108d4140000 pid=5332 /usr/bin/curl net send-data write-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=62fa487e-2100-0000-01a3-f108d4140000 pid=5332 execve guuid=babdda9f-2100-0000-01a3-f108db140000 pid=5339 /usr/bin/chmod guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=babdda9f-2100-0000-01a3-f108db140000 pid=5339 execve guuid=445423a0-2100-0000-01a3-f108dc140000 pid=5340 /usr/bin/bash guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=445423a0-2100-0000-01a3-f108dc140000 pid=5340 clone guuid=9193c5a0-2100-0000-01a3-f108de140000 pid=5342 /usr/bin/rm delete-file guuid=6f9f297c-1b00-0000-01a3-f108110b0000 pid=2833->guuid=9193c5a0-2100-0000-01a3-f108de140000 pid=5342 execve 2cc8cf6d-69d5-523d-8fdf-822a9cc79ab7 143.20.185.102:80 guuid=e3541c82-1b00-0000-01a3-f1081e0b0000 pid=2846->2cc8cf6d-69d5-523d-8fdf-822a9cc79ab7 send: 158B guuid=a1897c94-1b00-0000-01a3-f108410b0000 pid=2881->2cc8cf6d-69d5-523d-8fdf-822a9cc79ab7 send: 107B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=289652a9-1b00-0000-01a3-f1086a0b0000 pid=2922 /tmp/executor.x86 guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921->guuid=289652a9-1b00-0000-01a3-f1086a0b0000 pid=2922 clone guuid=4f6494d5-1c00-0000-01a3-f108af0d0000 pid=3503 /tmp/executor.x86 guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921->guuid=4f6494d5-1c00-0000-01a3-f108af0d0000 pid=3503 clone guuid=7df599d5-1c00-0000-01a3-f108b00d0000 pid=3504 /tmp/executor.x86 net send-data zombie guuid=2b22a1a8-1b00-0000-01a3-f108690b0000 pid=2921->guuid=7df599d5-1c00-0000-01a3-f108b00d0000 pid=3504 clone guuid=d2725ba9-1b00-0000-01a3-f1086b0b0000 pid=2923 /tmp/executor.x86 guuid=289652a9-1b00-0000-01a3-f1086a0b0000 pid=2922->guuid=d2725ba9-1b00-0000-01a3-f1086b0b0000 pid=2923 clone guuid=78f660a9-1b00-0000-01a3-f1086c0b0000 pid=2924 /tmp/executor.x86 dns net send-data zombie guuid=289652a9-1b00-0000-01a3-f1086a0b0000 pid=2922->guuid=78f660a9-1b00-0000-01a3-f1086c0b0000 pid=2924 clone guuid=78f660a9-1b00-0000-01a3-f1086c0b0000 pid=2924->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 37B c20d0917-ae21-50f3-ba53-8c69e0cc77fe new.executor.qzz.io:6769 guuid=78f660a9-1b00-0000-01a3-f1086c0b0000 pid=2924->c20d0917-ae21-50f3-ba53-8c69e0cc77fe send: 22B guuid=7df599d5-1c00-0000-01a3-f108b00d0000 pid=3504->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 950B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=7df599d5-1c00-0000-01a3-f108b00d0000 pid=3504->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B de8aa0c0-e956-5bf9-8267-e76802a46948 new.executor.qzz.io:80 guuid=9a9c25d6-1c00-0000-01a3-f108b40d0000 pid=3508->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=835f8ce7-1c00-0000-01a3-f108cf0d0000 pid=3535->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=9c5ef217-1d00-0000-01a3-f108ff0d0000 pid=3583->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 158B guuid=d915562c-1d00-0000-01a3-f108330e0000 pid=3635->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 107B guuid=d1f2a541-1d00-0000-01a3-f108600e0000 pid=3680->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=b41ff746-1d00-0000-01a3-f1086d0e0000 pid=3693->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=aa0c2f50-1d00-0000-01a3-f108880e0000 pid=3720->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=4b406f60-1d00-0000-01a3-f108c30e0000 pid=3779->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1d3ff072-1d00-0000-01a3-f108070f0000 pid=3847 /tmp/executor.i686 guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846->guuid=1d3ff072-1d00-0000-01a3-f108070f0000 pid=3847 clone guuid=59c50e9f-1e00-0000-01a3-f1086a120000 pid=4714 /tmp/executor.i686 guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846->guuid=59c50e9f-1e00-0000-01a3-f1086a120000 pid=4714 clone guuid=5353179f-1e00-0000-01a3-f1086b120000 pid=4715 /tmp/executor.i686 net send-data zombie guuid=9cad5472-1d00-0000-01a3-f108060f0000 pid=3846->guuid=5353179f-1e00-0000-01a3-f1086b120000 pid=4715 clone guuid=98eef872-1d00-0000-01a3-f108080f0000 pid=3848 /tmp/executor.i686 guuid=1d3ff072-1d00-0000-01a3-f108070f0000 pid=3847->guuid=98eef872-1d00-0000-01a3-f108080f0000 pid=3848 clone guuid=00d8fe72-1d00-0000-01a3-f108090f0000 pid=3849 /tmp/executor.i686 dns net send-data zombie guuid=1d3ff072-1d00-0000-01a3-f108070f0000 pid=3847->guuid=00d8fe72-1d00-0000-01a3-f108090f0000 pid=3849 clone guuid=00d8fe72-1d00-0000-01a3-f108090f0000 pid=3849->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 74B guuid=00d8fe72-1d00-0000-01a3-f108090f0000 pid=3849->c20d0917-ae21-50f3-ba53-8c69e0cc77fe send: 42B guuid=5353179f-1e00-0000-01a3-f1086b120000 pid=4715->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 950B guuid=5353179f-1e00-0000-01a3-f1086b120000 pid=4715->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2c0ba19f-1e00-0000-01a3-f1086e120000 pid=4718->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 161B guuid=34361caf-1e00-0000-01a3-f1089d120000 pid=4765->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 110B guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=28271bc1-1e00-0000-01a3-f108d0120000 pid=4816 /tmp/executor.x86_64 guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814->guuid=28271bc1-1e00-0000-01a3-f108d0120000 pid=4816 clone guuid=c736b7eb-1f00-0000-01a3-f10893140000 pid=5267 /tmp/executor.x86_64 guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814->guuid=c736b7eb-1f00-0000-01a3-f10893140000 pid=5267 clone guuid=1522beeb-1f00-0000-01a3-f10894140000 pid=5268 /tmp/executor.x86_64 net send-data zombie guuid=7be06dc0-1e00-0000-01a3-f108ce120000 pid=4814->guuid=1522beeb-1f00-0000-01a3-f10894140000 pid=5268 clone guuid=9fcc23c1-1e00-0000-01a3-f108d1120000 pid=4817 /tmp/executor.x86_64 guuid=28271bc1-1e00-0000-01a3-f108d0120000 pid=4816->guuid=9fcc23c1-1e00-0000-01a3-f108d1120000 pid=4817 clone guuid=0a7f2bc1-1e00-0000-01a3-f108d2120000 pid=4818 /tmp/executor.x86_64 net send-data zombie guuid=28271bc1-1e00-0000-01a3-f108d0120000 pid=4816->guuid=0a7f2bc1-1e00-0000-01a3-f108d2120000 pid=4818 clone guuid=0a7f2bc1-1e00-0000-01a3-f108d2120000 pid=4818->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 925B guuid=0a7f2bc1-1e00-0000-01a3-f108d2120000 pid=4818->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=1522beeb-1f00-0000-01a3-f10894140000 pid=5268->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 740B guuid=1522beeb-1f00-0000-01a3-f10894140000 pid=5268->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=5c69a2ec-1f00-0000-01a3-f10896140000 pid=5270->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=f7046bfd-1f00-0000-01a3-f10897140000 pid=5271->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=ffd41511-2000-0000-01a3-f1089c140000 pid=5276->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 158B guuid=80d8511e-2000-0000-01a3-f1089d140000 pid=5277->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 107B guuid=34127b31-2000-0000-01a3-f108a2140000 pid=5282->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=c4050b3e-2000-0000-01a3-f108a3140000 pid=5283->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=a923414f-2000-0000-01a3-f108a8140000 pid=5288->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=2606eb5d-2000-0000-01a3-f108a9140000 pid=5289->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=c6404a70-2000-0000-01a3-f108ae140000 pid=5294->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=ace68f81-2000-0000-01a3-f108af140000 pid=5295->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=ce8d3b98-2000-0000-01a3-f108bb140000 pid=5307->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 158B guuid=9cd64ea8-2000-0000-01a3-f108bc140000 pid=5308->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 107B guuid=1b9e6cdd-2000-0000-01a3-f108c1140000 pid=5313->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 158B guuid=1b59e6fc-2000-0000-01a3-f108c2140000 pid=5314->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 107B guuid=03b3b713-2100-0000-01a3-f108c7140000 pid=5319->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 159B guuid=275fad27-2100-0000-01a3-f108c8140000 pid=5320->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 108B guuid=c53e7041-2100-0000-01a3-f108cd140000 pid=5325->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 158B guuid=6ee40753-2100-0000-01a3-f108ce140000 pid=5326->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 107B guuid=bfe63669-2100-0000-01a3-f108d3140000 pid=5331->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 160B guuid=62fa487e-2100-0000-01a3-f108d4140000 pid=5332->de8aa0c0-e956-5bf9-8267-e76802a46948 send: 109B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-26 09:10:19 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0779e3aaecf413f7e1cf4bda84bdbd020093977742df6889dcf6cf535070690e

(this sample)

  
Delivery method
Distributed via web download

Comments