MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 078298d36b7f48cd85cfda47b966cea366857c5873f133b884fef2190be59245. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 078298d36b7f48cd85cfda47b966cea366857c5873f133b884fef2190be59245
SHA3-384 hash: 351c453732e9e204ccb2c5172e5c936f87d00c8a1c28b257ad9dd945c8df18a25fc2efda5ffb7d6f5ef1281c89b97c58
SHA1 hash: 974bbb65848d38d4837fc5e7bb7ea0fece6b36f0
MD5 hash: 9bef120f2a67da197178a36dba4ae29c
humanhash: hotel-ink-solar-oscar
File name:wget_telnet.sh
Download: download sample
Signature Mirai
File size:1'943 bytes
First seen:2025-10-24 23:04:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:pIIdYsIaMnh2apwMZByZhV8R47AF3OH8ENpB:pZexP0aGuBwhqSdJ
TLSH T1C341ECED02812F7B34068A25A3E355AC9C468FD2718A179CD48A7C1B8C0F61C7BF9D83
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.35.154/powerpc.uhavenobotsxd4eb0f092558c445bfe6499074fec4f9501988f680c9977ea59b413de6c328c23 Miraielf geofenced mirai PowerPC ua-wget USA
http://94.154.35.154/mips.uhavenobotsxd32ed54ada1301070e35d2f16dc923ee745b8512e7886f0826a5acaad80ab82a1 Miraielf geofenced mips mirai ua-wget USA
http://94.154.35.154/mipsel.uhavenobotsxd63e9b33978e589360315683699ecc30aae88ffac38ad12a9fabf9b88d185676a Miraielf geofenced mips mirai ua-wget USA
http://94.154.35.154/arm.uhavenobotsxd1fb350e213500aa096d34afa25b2f4a4040a8cd497487546860873ceeb1f583b Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm5.uhavenobotsxdc3477c76a49468aa394c9103c7f696729e38c93de3730cd490a7ad86deb23751 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm6.uhavenobotsxd1350b69358cc22c12111c5f2f37c0ed39434c0345de97116aada4bf84d5ebc49 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm7.uhavenobotsxdc7b31d4e86d88a05365b4212c291834562b1693093c208339e53c2a037760f5f Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/sparc.uhavenobotsxdn/an/aelf ua-wget
http://94.154.35.154/m68k.uhavenobotsxdn/an/aelf ua-wget
http://94.154.35.154/sh4.uhavenobotsxdn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-24T20:46:00Z UTC
Last seen:
2025-10-24T22:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=584abf63-1800-0000-30f0-29e8ae0d0000 pid=3502 /usr/bin/sudo guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504 /tmp/sample.bin guuid=584abf63-1800-0000-30f0-29e8ae0d0000 pid=3502->guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504 execve guuid=2415b866-1800-0000-30f0-29e8b10d0000 pid=3505 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=2415b866-1800-0000-30f0-29e8b10d0000 pid=3505 execve guuid=ac191f90-1800-0000-30f0-29e8090e0000 pid=3593 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=ac191f90-1800-0000-30f0-29e8090e0000 pid=3593 execve guuid=8b8057a6-1800-0000-30f0-29e8410e0000 pid=3649 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=8b8057a6-1800-0000-30f0-29e8410e0000 pid=3649 execve guuid=0e6abca6-1800-0000-30f0-29e8430e0000 pid=3651 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=0e6abca6-1800-0000-30f0-29e8430e0000 pid=3651 clone guuid=8766c5a7-1800-0000-30f0-29e8480e0000 pid=3656 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=8766c5a7-1800-0000-30f0-29e8480e0000 pid=3656 execve guuid=16273da8-1800-0000-30f0-29e84a0e0000 pid=3658 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=16273da8-1800-0000-30f0-29e84a0e0000 pid=3658 execve guuid=e44ce5bc-1800-0000-30f0-29e8630e0000 pid=3683 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=e44ce5bc-1800-0000-30f0-29e8630e0000 pid=3683 execve guuid=454d21d4-1800-0000-30f0-29e89f0e0000 pid=3743 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=454d21d4-1800-0000-30f0-29e89f0e0000 pid=3743 execve guuid=65bcaad4-1800-0000-30f0-29e8a00e0000 pid=3744 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=65bcaad4-1800-0000-30f0-29e8a00e0000 pid=3744 clone guuid=c41f67d6-1800-0000-30f0-29e8a50e0000 pid=3749 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=c41f67d6-1800-0000-30f0-29e8a50e0000 pid=3749 execve guuid=5c554de6-1800-0000-30f0-29e8a60e0000 pid=3750 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=5c554de6-1800-0000-30f0-29e8a60e0000 pid=3750 execve guuid=ebfb5ffa-1800-0000-30f0-29e8cf0e0000 pid=3791 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=ebfb5ffa-1800-0000-30f0-29e8cf0e0000 pid=3791 execve guuid=a2d00510-1900-0000-30f0-29e80c0f0000 pid=3852 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=a2d00510-1900-0000-30f0-29e80c0f0000 pid=3852 execve guuid=bf064a10-1900-0000-30f0-29e80e0f0000 pid=3854 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=bf064a10-1900-0000-30f0-29e80e0f0000 pid=3854 clone guuid=3f14df10-1900-0000-30f0-29e8120f0000 pid=3858 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=3f14df10-1900-0000-30f0-29e8120f0000 pid=3858 execve guuid=11c32211-1900-0000-30f0-29e8140f0000 pid=3860 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=11c32211-1900-0000-30f0-29e8140f0000 pid=3860 execve guuid=ae338a24-1900-0000-30f0-29e85d0f0000 pid=3933 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=ae338a24-1900-0000-30f0-29e85d0f0000 pid=3933 execve guuid=b69db83a-1900-0000-30f0-29e8950f0000 pid=3989 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=b69db83a-1900-0000-30f0-29e8950f0000 pid=3989 execve guuid=5ec73a3b-1900-0000-30f0-29e8970f0000 pid=3991 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=5ec73a3b-1900-0000-30f0-29e8970f0000 pid=3991 clone guuid=02fd923c-1900-0000-30f0-29e89b0f0000 pid=3995 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=02fd923c-1900-0000-30f0-29e89b0f0000 pid=3995 execve guuid=33093941-1900-0000-30f0-29e8a70f0000 pid=4007 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=33093941-1900-0000-30f0-29e8a70f0000 pid=4007 execve guuid=ca94fc52-1900-0000-30f0-29e8f00f0000 pid=4080 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=ca94fc52-1900-0000-30f0-29e8f00f0000 pid=4080 execve guuid=d10d4566-1900-0000-30f0-29e832100000 pid=4146 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=d10d4566-1900-0000-30f0-29e832100000 pid=4146 execve guuid=c6dcd566-1900-0000-30f0-29e836100000 pid=4150 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=c6dcd566-1900-0000-30f0-29e836100000 pid=4150 clone guuid=ca17d267-1900-0000-30f0-29e83c100000 pid=4156 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=ca17d267-1900-0000-30f0-29e83c100000 pid=4156 execve guuid=7b591868-1900-0000-30f0-29e83e100000 pid=4158 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=7b591868-1900-0000-30f0-29e83e100000 pid=4158 execve guuid=9449627a-1900-0000-30f0-29e875100000 pid=4213 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=9449627a-1900-0000-30f0-29e875100000 pid=4213 execve guuid=5a05448e-1900-0000-30f0-29e8b7100000 pid=4279 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=5a05448e-1900-0000-30f0-29e8b7100000 pid=4279 execve guuid=5bb6b58e-1900-0000-30f0-29e8b9100000 pid=4281 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=5bb6b58e-1900-0000-30f0-29e8b9100000 pid=4281 clone guuid=a458ac8f-1900-0000-30f0-29e8bf100000 pid=4287 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=a458ac8f-1900-0000-30f0-29e8bf100000 pid=4287 execve guuid=18341a90-1900-0000-30f0-29e8c3100000 pid=4291 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=18341a90-1900-0000-30f0-29e8c3100000 pid=4291 execve guuid=c42817a6-1900-0000-30f0-29e8fa100000 pid=4346 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=c42817a6-1900-0000-30f0-29e8fa100000 pid=4346 execve guuid=b22181bf-1900-0000-30f0-29e854110000 pid=4436 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=b22181bf-1900-0000-30f0-29e854110000 pid=4436 execve guuid=af51c7bf-1900-0000-30f0-29e856110000 pid=4438 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=af51c7bf-1900-0000-30f0-29e856110000 pid=4438 clone guuid=815d5ac0-1900-0000-30f0-29e85b110000 pid=4443 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=815d5ac0-1900-0000-30f0-29e85b110000 pid=4443 execve guuid=0b1b0cf3-1900-0000-30f0-29e89f110000 pid=4511 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=0b1b0cf3-1900-0000-30f0-29e89f110000 pid=4511 execve guuid=78f75009-1a00-0000-30f0-29e8a1110000 pid=4513 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=78f75009-1a00-0000-30f0-29e8a1110000 pid=4513 execve guuid=f11a2e19-1a00-0000-30f0-29e8be110000 pid=4542 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=f11a2e19-1a00-0000-30f0-29e8be110000 pid=4542 execve guuid=71c6aa19-1a00-0000-30f0-29e8c0110000 pid=4544 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=71c6aa19-1a00-0000-30f0-29e8c0110000 pid=4544 clone guuid=cc2a071a-1a00-0000-30f0-29e8c3110000 pid=4547 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=cc2a071a-1a00-0000-30f0-29e8c3110000 pid=4547 execve guuid=90ac741a-1a00-0000-30f0-29e8c5110000 pid=4549 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=90ac741a-1a00-0000-30f0-29e8c5110000 pid=4549 execve guuid=0f5b472f-1a00-0000-30f0-29e8ff110000 pid=4607 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=0f5b472f-1a00-0000-30f0-29e8ff110000 pid=4607 execve guuid=f20e943c-1a00-0000-30f0-29e82e120000 pid=4654 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=f20e943c-1a00-0000-30f0-29e82e120000 pid=4654 execve guuid=7afff63c-1a00-0000-30f0-29e82f120000 pid=4655 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=7afff63c-1a00-0000-30f0-29e82f120000 pid=4655 clone guuid=4a44503d-1a00-0000-30f0-29e832120000 pid=4658 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=4a44503d-1a00-0000-30f0-29e832120000 pid=4658 execve guuid=9c34df3d-1a00-0000-30f0-29e833120000 pid=4659 /usr/bin/wget net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=9c34df3d-1a00-0000-30f0-29e833120000 pid=4659 execve guuid=9f13f151-1a00-0000-30f0-29e85c120000 pid=4700 /usr/bin/curl net send-data write-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=9f13f151-1a00-0000-30f0-29e85c120000 pid=4700 execve guuid=bfb6e460-1a00-0000-30f0-29e884120000 pid=4740 /usr/bin/chmod guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=bfb6e460-1a00-0000-30f0-29e884120000 pid=4740 execve guuid=2b965461-1a00-0000-30f0-29e885120000 pid=4741 /usr/bin/bash guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=2b965461-1a00-0000-30f0-29e885120000 pid=4741 clone guuid=28faa561-1a00-0000-30f0-29e88a120000 pid=4746 /usr/bin/rm delete-file guuid=d3950e66-1800-0000-30f0-29e8b00d0000 pid=3504->guuid=28faa561-1a00-0000-30f0-29e88a120000 pid=4746 execve 64a07662-ebdf-52ea-9140-fd99af91f8af 94.154.35.154:80 guuid=2415b866-1800-0000-30f0-29e8b10d0000 pid=3505->64a07662-ebdf-52ea-9140-fd99af91f8af send: 149B guuid=ac191f90-1800-0000-30f0-29e8090e0000 pid=3593->64a07662-ebdf-52ea-9140-fd99af91f8af send: 98B guuid=16273da8-1800-0000-30f0-29e84a0e0000 pid=3658->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=e44ce5bc-1800-0000-30f0-29e8630e0000 pid=3683->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=5c554de6-1800-0000-30f0-29e8a60e0000 pid=3750->64a07662-ebdf-52ea-9140-fd99af91f8af send: 148B guuid=ebfb5ffa-1800-0000-30f0-29e8cf0e0000 pid=3791->64a07662-ebdf-52ea-9140-fd99af91f8af send: 97B guuid=11c32211-1900-0000-30f0-29e8140f0000 pid=3860->64a07662-ebdf-52ea-9140-fd99af91f8af send: 145B guuid=ae338a24-1900-0000-30f0-29e85d0f0000 pid=3933->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B guuid=33093941-1900-0000-30f0-29e8a70f0000 pid=4007->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=ca94fc52-1900-0000-30f0-29e8f00f0000 pid=4080->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=7b591868-1900-0000-30f0-29e83e100000 pid=4158->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=9449627a-1900-0000-30f0-29e875100000 pid=4213->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=18341a90-1900-0000-30f0-29e8c3100000 pid=4291->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=c42817a6-1900-0000-30f0-29e8fa100000 pid=4346->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=0b1b0cf3-1900-0000-30f0-29e89f110000 pid=4511->64a07662-ebdf-52ea-9140-fd99af91f8af send: 282B guuid=78f75009-1a00-0000-30f0-29e8a1110000 pid=4513->64a07662-ebdf-52ea-9140-fd99af91f8af send: 96B guuid=8149cf19-1a00-0000-30f0-29e8c2110000 pid=4546 /usr/bin/bash guuid=71c6aa19-1a00-0000-30f0-29e8c0110000 pid=4544->guuid=8149cf19-1a00-0000-30f0-29e8c2110000 pid=4546 clone guuid=90ac741a-1a00-0000-30f0-29e8c5110000 pid=4549->64a07662-ebdf-52ea-9140-fd99af91f8af send: 281B guuid=0f5b472f-1a00-0000-30f0-29e8ff110000 pid=4607->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=59d01f3d-1a00-0000-30f0-29e831120000 pid=4657 /usr/bin/bash guuid=7afff63c-1a00-0000-30f0-29e82f120000 pid=4655->guuid=59d01f3d-1a00-0000-30f0-29e831120000 pid=4657 clone guuid=9c34df3d-1a00-0000-30f0-29e833120000 pid=4659->64a07662-ebdf-52ea-9140-fd99af91f8af send: 280B guuid=9f13f151-1a00-0000-30f0-29e85c120000 pid=4700->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B guuid=3b3a7d61-1a00-0000-30f0-29e886120000 pid=4742 /usr/bin/bash guuid=2b965461-1a00-0000-30f0-29e885120000 pid=4741->guuid=3b3a7d61-1a00-0000-30f0-29e886120000 pid=4742 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-24 23:05:41 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 078298d36b7f48cd85cfda47b966cea366857c5873f133b884fef2190be59245

(this sample)

  
Delivery method
Distributed via web download

Comments