MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 10510d1fd3ff4e050340fa0d620f7ef0b3b232203a0edd5afac7a1aa55d244d5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 10510d1fd3ff4e050340fa0d620f7ef0b3b232203a0edd5afac7a1aa55d244d5
SHA3-384 hash: 56130982738067a32a1c756dbda3281920b709edf1d9203e843477235f985d41f47ed0f13949b168511b958f8c94dab6
SHA1 hash: 6df40ef8942f6b64349615a96490bf34255a3eaa
MD5 hash: 8d84b47d9593c97b4736e27b48899a05
humanhash: don-grey-nuts-cardinal
File name:1.sh
Download: download sample
Signature Mirai
File size:3'164 bytes
First seen:2026-02-18 18:31:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:isFfsy9sjrsqoYs05sYJsbTbLshvsIlLsthJsydsW1svrsfbsK7W:io9KpnrAYvL6Fba8tW
TLSH T1F451D9CE12C587B15E6E4967B365E48A7C9DD4992087DF36CEE834E3044DD08205D7FA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=cb39a3fe-1a00-0000-b32a-187cc20b0000 pid=3010 /usr/bin/sudo guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016 /tmp/sample.bin guuid=cb39a3fe-1a00-0000-b32a-187cc20b0000 pid=3010->guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016 execve guuid=dfd9dd00-1b00-0000-b32a-187cc90b0000 pid=3017 /usr/bin/cp guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=dfd9dd00-1b00-0000-b32a-187cc90b0000 pid=3017 execve guuid=671da305-1b00-0000-b32a-187cd30b0000 pid=3027 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=671da305-1b00-0000-b32a-187cd30b0000 pid=3027 execve guuid=2ec37945-1b00-0000-b32a-187c6c0c0000 pid=3180 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2ec37945-1b00-0000-b32a-187c6c0c0000 pid=3180 execve guuid=e1a31e86-1b00-0000-b32a-187ca20c0000 pid=3234 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=e1a31e86-1b00-0000-b32a-187ca20c0000 pid=3234 execve guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235 /tmp/rizzx.x86 net guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235 execve guuid=5befeeb3-1c00-0000-b32a-187cf70e0000 pid=3831 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=5befeeb3-1c00-0000-b32a-187cf70e0000 pid=3831 execve guuid=8848aeb4-1c00-0000-b32a-187cf90e0000 pid=3833 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=8848aeb4-1c00-0000-b32a-187cf90e0000 pid=3833 execve guuid=76f9040b-1d00-0000-b32a-187cd40f0000 pid=4052 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=76f9040b-1d00-0000-b32a-187cd40f0000 pid=4052 execve guuid=295c2165-1d00-0000-b32a-187ce0100000 pid=4320 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=295c2165-1d00-0000-b32a-187ce0100000 pid=4320 execve guuid=36a28065-1d00-0000-b32a-187ce2100000 pid=4322 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=36a28065-1d00-0000-b32a-187ce2100000 pid=4322 clone guuid=0dac3c67-1d00-0000-b32a-187ceb100000 pid=4331 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=0dac3c67-1d00-0000-b32a-187ceb100000 pid=4331 execve guuid=f77d7468-1d00-0000-b32a-187cef100000 pid=4335 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=f77d7468-1d00-0000-b32a-187cef100000 pid=4335 execve guuid=977d76d0-1d00-0000-b32a-187c47120000 pid=4679 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=977d76d0-1d00-0000-b32a-187c47120000 pid=4679 execve guuid=86dd7e39-1e00-0000-b32a-187c84130000 pid=4996 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=86dd7e39-1e00-0000-b32a-187c84130000 pid=4996 execve guuid=2008da39-1e00-0000-b32a-187c86130000 pid=4998 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2008da39-1e00-0000-b32a-187c86130000 pid=4998 clone guuid=83de7e3a-1e00-0000-b32a-187c8a130000 pid=5002 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=83de7e3a-1e00-0000-b32a-187c8a130000 pid=5002 execve guuid=1b5cd23a-1e00-0000-b32a-187c8c130000 pid=5004 /usr/bin/wget net send-data guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=1b5cd23a-1e00-0000-b32a-187c8c130000 pid=5004 execve guuid=91b4d062-1e00-0000-b32a-187c15140000 pid=5141 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=91b4d062-1e00-0000-b32a-187c15140000 pid=5141 execve guuid=ca74358f-1e00-0000-b32a-187c81140000 pid=5249 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=ca74358f-1e00-0000-b32a-187c81140000 pid=5249 execve guuid=29719c8f-1e00-0000-b32a-187c82140000 pid=5250 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=29719c8f-1e00-0000-b32a-187c82140000 pid=5250 clone guuid=ded4bf8f-1e00-0000-b32a-187c83140000 pid=5251 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=ded4bf8f-1e00-0000-b32a-187c83140000 pid=5251 execve guuid=81f31f90-1e00-0000-b32a-187c84140000 pid=5252 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=81f31f90-1e00-0000-b32a-187c84140000 pid=5252 execve guuid=2b62fbce-1e00-0000-b32a-187c8d140000 pid=5261 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2b62fbce-1e00-0000-b32a-187c8d140000 pid=5261 execve guuid=48bb360e-1f00-0000-b32a-187c8e140000 pid=5262 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=48bb360e-1f00-0000-b32a-187c8e140000 pid=5262 execve guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263 /tmp/rizzx.i686 net guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263 execve guuid=9ed9d13c-2000-0000-b32a-187c9c140000 pid=5276 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=9ed9d13c-2000-0000-b32a-187c9c140000 pid=5276 execve guuid=c2be5d3e-2000-0000-b32a-187c9d140000 pid=5277 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=c2be5d3e-2000-0000-b32a-187c9d140000 pid=5277 execve guuid=7bb8677d-2000-0000-b32a-187c9f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=7bb8677d-2000-0000-b32a-187c9f140000 pid=5279 execve guuid=6da565bc-2000-0000-b32a-187caf140000 pid=5295 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=6da565bc-2000-0000-b32a-187caf140000 pid=5295 execve guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296 /tmp/rizzx.x86_64 mprotect-exec net guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296 execve guuid=fd1017e8-2100-0000-b32a-187cc6140000 pid=5318 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=fd1017e8-2100-0000-b32a-187cc6140000 pid=5318 execve guuid=1fccc6e8-2100-0000-b32a-187cc7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=1fccc6e8-2100-0000-b32a-187cc7140000 pid=5319 execve guuid=8f323639-2200-0000-b32a-187cc8140000 pid=5320 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=8f323639-2200-0000-b32a-187cc8140000 pid=5320 execve guuid=2ae5ba8e-2200-0000-b32a-187cc9140000 pid=5321 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2ae5ba8e-2200-0000-b32a-187cc9140000 pid=5321 execve guuid=465f568f-2200-0000-b32a-187cca140000 pid=5322 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=465f568f-2200-0000-b32a-187cca140000 pid=5322 clone guuid=b8727490-2200-0000-b32a-187ccc140000 pid=5324 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=b8727490-2200-0000-b32a-187ccc140000 pid=5324 execve guuid=f5570791-2200-0000-b32a-187ccd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=f5570791-2200-0000-b32a-187ccd140000 pid=5325 execve guuid=d6b1ded0-2200-0000-b32a-187cce140000 pid=5326 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=d6b1ded0-2200-0000-b32a-187cce140000 pid=5326 execve guuid=10706518-2300-0000-b32a-187ccf140000 pid=5327 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=10706518-2300-0000-b32a-187ccf140000 pid=5327 execve guuid=2114ae18-2300-0000-b32a-187cd0140000 pid=5328 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2114ae18-2300-0000-b32a-187cd0140000 pid=5328 clone guuid=7ffa5119-2300-0000-b32a-187cd2140000 pid=5330 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=7ffa5119-2300-0000-b32a-187cd2140000 pid=5330 execve guuid=17a30d1b-2300-0000-b32a-187cd3140000 pid=5331 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=17a30d1b-2300-0000-b32a-187cd3140000 pid=5331 execve guuid=d5207a59-2300-0000-b32a-187cd4140000 pid=5332 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=d5207a59-2300-0000-b32a-187cd4140000 pid=5332 execve guuid=6aad289b-2300-0000-b32a-187cd5140000 pid=5333 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=6aad289b-2300-0000-b32a-187cd5140000 pid=5333 execve guuid=5c33c59b-2300-0000-b32a-187cd6140000 pid=5334 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=5c33c59b-2300-0000-b32a-187cd6140000 pid=5334 clone guuid=81c7539d-2300-0000-b32a-187cd8140000 pid=5336 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=81c7539d-2300-0000-b32a-187cd8140000 pid=5336 execve guuid=4fd1ee9d-2300-0000-b32a-187cd9140000 pid=5337 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=4fd1ee9d-2300-0000-b32a-187cd9140000 pid=5337 execve guuid=d17140ef-2300-0000-b32a-187cda140000 pid=5338 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=d17140ef-2300-0000-b32a-187cda140000 pid=5338 execve guuid=2c354b3f-2400-0000-b32a-187cdb140000 pid=5339 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=2c354b3f-2400-0000-b32a-187cdb140000 pid=5339 execve guuid=0f8fda3f-2400-0000-b32a-187cdc140000 pid=5340 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=0f8fda3f-2400-0000-b32a-187cdc140000 pid=5340 clone guuid=bb900841-2400-0000-b32a-187cde140000 pid=5342 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=bb900841-2400-0000-b32a-187cde140000 pid=5342 execve guuid=b24b9941-2400-0000-b32a-187cdf140000 pid=5343 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=b24b9941-2400-0000-b32a-187cdf140000 pid=5343 execve guuid=692eb295-2400-0000-b32a-187ce0140000 pid=5344 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=692eb295-2400-0000-b32a-187ce0140000 pid=5344 execve guuid=f5d0fee7-2400-0000-b32a-187ce1140000 pid=5345 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=f5d0fee7-2400-0000-b32a-187ce1140000 pid=5345 execve guuid=47e550e8-2400-0000-b32a-187ce2140000 pid=5346 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=47e550e8-2400-0000-b32a-187ce2140000 pid=5346 clone guuid=7519e6e8-2400-0000-b32a-187ce4140000 pid=5348 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=7519e6e8-2400-0000-b32a-187ce4140000 pid=5348 execve guuid=d38534e9-2400-0000-b32a-187ce5140000 pid=5349 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=d38534e9-2400-0000-b32a-187ce5140000 pid=5349 execve guuid=7e252327-2500-0000-b32a-187ce6140000 pid=5350 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=7e252327-2500-0000-b32a-187ce6140000 pid=5350 execve guuid=45e63c66-2500-0000-b32a-187ce7140000 pid=5351 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=45e63c66-2500-0000-b32a-187ce7140000 pid=5351 execve guuid=c531d066-2500-0000-b32a-187ce8140000 pid=5352 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=c531d066-2500-0000-b32a-187ce8140000 pid=5352 clone guuid=3882f867-2500-0000-b32a-187cea140000 pid=5354 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=3882f867-2500-0000-b32a-187cea140000 pid=5354 execve guuid=eee59568-2500-0000-b32a-187ceb140000 pid=5355 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=eee59568-2500-0000-b32a-187ceb140000 pid=5355 execve guuid=f107f3cd-2500-0000-b32a-187cec140000 pid=5356 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=f107f3cd-2500-0000-b32a-187cec140000 pid=5356 execve guuid=a42fc434-2600-0000-b32a-187ced140000 pid=5357 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=a42fc434-2600-0000-b32a-187ced140000 pid=5357 execve guuid=0cfa1435-2600-0000-b32a-187cee140000 pid=5358 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=0cfa1435-2600-0000-b32a-187cee140000 pid=5358 clone guuid=e70aab35-2600-0000-b32a-187cf0140000 pid=5360 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=e70aab35-2600-0000-b32a-187cf0140000 pid=5360 execve guuid=1b17f235-2600-0000-b32a-187cf1140000 pid=5361 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=1b17f235-2600-0000-b32a-187cf1140000 pid=5361 execve guuid=6d775c9d-2600-0000-b32a-187cf2140000 pid=5362 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=6d775c9d-2600-0000-b32a-187cf2140000 pid=5362 execve guuid=dc3452f0-2600-0000-b32a-187cf3140000 pid=5363 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=dc3452f0-2600-0000-b32a-187cf3140000 pid=5363 execve guuid=598e9af0-2600-0000-b32a-187cf4140000 pid=5364 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=598e9af0-2600-0000-b32a-187cf4140000 pid=5364 clone guuid=edc443f1-2600-0000-b32a-187cf6140000 pid=5366 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=edc443f1-2600-0000-b32a-187cf6140000 pid=5366 execve guuid=cfe495f1-2600-0000-b32a-187cf7140000 pid=5367 /usr/bin/wget net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=cfe495f1-2600-0000-b32a-187cf7140000 pid=5367 execve guuid=9d763a44-2700-0000-b32a-187cf8140000 pid=5368 /usr/bin/curl net send-data write-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=9d763a44-2700-0000-b32a-187cf8140000 pid=5368 execve guuid=cd8eae96-2700-0000-b32a-187cf9140000 pid=5369 /usr/bin/chmod guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=cd8eae96-2700-0000-b32a-187cf9140000 pid=5369 execve guuid=f88cfc96-2700-0000-b32a-187cfa140000 pid=5370 /usr/bin/bash guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=f88cfc96-2700-0000-b32a-187cfa140000 pid=5370 clone guuid=8ae79c97-2700-0000-b32a-187cfc140000 pid=5372 /usr/bin/rm delete-file guuid=4ae26a00-1b00-0000-b32a-187cc80b0000 pid=3016->guuid=8ae79c97-2700-0000-b32a-187cfc140000 pid=5372 execve ea612c79-4764-51d4-a174-9be21b31ead6 157.230.43.57:80 guuid=671da305-1b00-0000-b32a-187cd30b0000 pid=3027->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=2ec37945-1b00-0000-b32a-187c6c0c0000 pid=3180->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3add4387-1b00-0000-b32a-187ca70c0000 pid=3239 /tmp/rizzx.x86 guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235->guuid=3add4387-1b00-0000-b32a-187ca70c0000 pid=3239 clone guuid=dff8cdb3-1c00-0000-b32a-187cf50e0000 pid=3829 /tmp/rizzx.x86 guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235->guuid=dff8cdb3-1c00-0000-b32a-187cf50e0000 pid=3829 clone guuid=6be3deb3-1c00-0000-b32a-187cf60e0000 pid=3830 /tmp/rizzx.x86 net send-data zombie guuid=520d7c86-1b00-0000-b32a-187ca30c0000 pid=3235->guuid=6be3deb3-1c00-0000-b32a-187cf60e0000 pid=3830 clone guuid=90034d87-1b00-0000-b32a-187ca80c0000 pid=3240 /tmp/rizzx.x86 guuid=3add4387-1b00-0000-b32a-187ca70c0000 pid=3239->guuid=90034d87-1b00-0000-b32a-187ca80c0000 pid=3240 clone guuid=2e705087-1b00-0000-b32a-187ca90c0000 pid=3241 /tmp/rizzx.x86 dns net send-data zombie guuid=3add4387-1b00-0000-b32a-187ca70c0000 pid=3239->guuid=2e705087-1b00-0000-b32a-187ca90c0000 pid=3241 clone guuid=2e705087-1b00-0000-b32a-187ca90c0000 pid=3241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 5b063f5c-af84-587e-9321-c96a2d578797 pls.ddosme.web.id:69 guuid=2e705087-1b00-0000-b32a-187ca90c0000 pid=3241->5b063f5c-af84-587e-9321-c96a2d578797 send: 19B guuid=6be3deb3-1c00-0000-b32a-187cf60e0000 pid=3830->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 875B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=6be3deb3-1c00-0000-b32a-187cf60e0000 pid=3830->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=8848aeb4-1c00-0000-b32a-187cf90e0000 pid=3833->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=76f9040b-1d00-0000-b32a-187cd40f0000 pid=4052->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=f77d7468-1d00-0000-b32a-187cef100000 pid=4335->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=977d76d0-1d00-0000-b32a-187c47120000 pid=4679->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B guuid=1b5cd23a-1e00-0000-b32a-187c8c130000 pid=5004->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=91b4d062-1e00-0000-b32a-187c15140000 pid=5141->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=81f31f90-1e00-0000-b32a-187c84140000 pid=5252->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=2b62fbce-1e00-0000-b32a-187c8d140000 pid=5261->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7f8eb90f-1f00-0000-b32a-187c90140000 pid=5264 /tmp/rizzx.i686 guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263->guuid=7f8eb90f-1f00-0000-b32a-187c90140000 pid=5264 clone guuid=a04abe3c-2000-0000-b32a-187c9a140000 pid=5274 /tmp/rizzx.i686 guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263->guuid=a04abe3c-2000-0000-b32a-187c9a140000 pid=5274 clone guuid=04efc63c-2000-0000-b32a-187c9b140000 pid=5275 /tmp/rizzx.i686 net send-data zombie guuid=3f33ce0e-1f00-0000-b32a-187c8f140000 pid=5263->guuid=04efc63c-2000-0000-b32a-187c9b140000 pid=5275 clone guuid=aeb3c30f-1f00-0000-b32a-187c91140000 pid=5265 /tmp/rizzx.i686 guuid=7f8eb90f-1f00-0000-b32a-187c90140000 pid=5264->guuid=aeb3c30f-1f00-0000-b32a-187c91140000 pid=5265 clone guuid=0b43ca0f-1f00-0000-b32a-187c92140000 pid=5266 /tmp/rizzx.i686 dns net send-data zombie guuid=7f8eb90f-1f00-0000-b32a-187c90140000 pid=5264->guuid=0b43ca0f-1f00-0000-b32a-187c92140000 pid=5266 clone guuid=0b43ca0f-1f00-0000-b32a-187c92140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=0b43ca0f-1f00-0000-b32a-187c92140000 pid=5266->5b063f5c-af84-587e-9321-c96a2d578797 send: 18B guuid=04efc63c-2000-0000-b32a-187c9b140000 pid=5275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 700B guuid=04efc63c-2000-0000-b32a-187c9b140000 pid=5275->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=c2be5d3e-2000-0000-b32a-187c9d140000 pid=5277->ea612c79-4764-51d4-a174-9be21b31ead6 send: 150B guuid=7bb8677d-2000-0000-b32a-187c9f140000 pid=5279->ea612c79-4764-51d4-a174-9be21b31ead6 send: 99B guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1fd072bd-2000-0000-b32a-187cb1140000 pid=5297 /tmp/rizzx.x86_64 guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296->guuid=1fd072bd-2000-0000-b32a-187cb1140000 pid=5297 clone guuid=e04aeee7-2100-0000-b32a-187cc4140000 pid=5316 /tmp/rizzx.x86_64 guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296->guuid=e04aeee7-2100-0000-b32a-187cc4140000 pid=5316 clone guuid=7850f9e7-2100-0000-b32a-187cc5140000 pid=5317 /tmp/rizzx.x86_64 net send-data zombie guuid=2b60d8bc-2000-0000-b32a-187cb0140000 pid=5296->guuid=7850f9e7-2100-0000-b32a-187cc5140000 pid=5317 clone guuid=9a337cbd-2000-0000-b32a-187cb2140000 pid=5298 /tmp/rizzx.x86_64 guuid=1fd072bd-2000-0000-b32a-187cb1140000 pid=5297->guuid=9a337cbd-2000-0000-b32a-187cb2140000 pid=5298 clone guuid=4fa183bd-2000-0000-b32a-187cb3140000 pid=5299 /tmp/rizzx.x86_64 net send-data zombie guuid=1fd072bd-2000-0000-b32a-187cb1140000 pid=5297->guuid=4fa183bd-2000-0000-b32a-187cb3140000 pid=5299 clone guuid=4fa183bd-2000-0000-b32a-187cb3140000 pid=5299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 700B guuid=4fa183bd-2000-0000-b32a-187cb3140000 pid=5299->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=7850f9e7-2100-0000-b32a-187cc5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 525B guuid=7850f9e7-2100-0000-b32a-187cc5140000 pid=5317->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=1fccc6e8-2100-0000-b32a-187cc7140000 pid=5319->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=8f323639-2200-0000-b32a-187cc8140000 pid=5320->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=f5570791-2200-0000-b32a-187ccd140000 pid=5325->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=d6b1ded0-2200-0000-b32a-187cce140000 pid=5326->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B guuid=17a30d1b-2300-0000-b32a-187cd3140000 pid=5331->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=d5207a59-2300-0000-b32a-187cd4140000 pid=5332->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=4fd1ee9d-2300-0000-b32a-187cd9140000 pid=5337->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=d17140ef-2300-0000-b32a-187cda140000 pid=5338->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=b24b9941-2400-0000-b32a-187cdf140000 pid=5343->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=692eb295-2400-0000-b32a-187ce0140000 pid=5344->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=d38534e9-2400-0000-b32a-187ce5140000 pid=5349->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=7e252327-2500-0000-b32a-187ce6140000 pid=5350->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B guuid=eee59568-2500-0000-b32a-187ceb140000 pid=5355->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=f107f3cd-2500-0000-b32a-187cec140000 pid=5356->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B guuid=1b17f235-2600-0000-b32a-187cf1140000 pid=5361->ea612c79-4764-51d4-a174-9be21b31ead6 send: 148B guuid=6d775c9d-2600-0000-b32a-187cf2140000 pid=5362->ea612c79-4764-51d4-a174-9be21b31ead6 send: 97B guuid=cfe495f1-2600-0000-b32a-187cf7140000 pid=5367->ea612c79-4764-51d4-a174-9be21b31ead6 send: 147B guuid=9d763a44-2700-0000-b32a-187cf8140000 pid=5368->ea612c79-4764-51d4-a174-9be21b31ead6 send: 96B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-18 19:15:11 UTC
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 10510d1fd3ff4e050340fa0d620f7ef0b3b232203a0edd5afac7a1aa55d244d5

(this sample)

  
Delivery method
Distributed via web download

Comments