MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1551d33d26531767211244f0e646501a707170399859c9866ac1e704888d1939. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 1551d33d26531767211244f0e646501a707170399859c9866ac1e704888d1939
SHA3-384 hash: f90f80a5602c16aefb2b32de4aef74b35aacea52c2c4a672dae285ac706fd4f94196d921cd6f1184bc1a82006d5dd14f
SHA1 hash: 95339e0e5a5e8d50828c94fcebbc4465cf83fe01
MD5 hash: 3b33f816b3b545c43bf80fb6a461a133
humanhash: pip-july-single-july
File name:test.sh
Download: download sample
Signature Mirai
File size:2'583 bytes
First seen:2025-09-29 18:21:49 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:UaebsLsa7U/sQ0sNshs/DBslY0sfsnsGYsH/sdf:UaeQAaG2q/DKeUsGtUN
TLSH T1805153C9277267352C56DA7273AF8808B2B1E0AA70CA1F4769DC38F5C48DE053275EB5
Magika txt
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.149.138/systemcl/arc62fe11867609d9e615a9e4356e2770c1186cf083109c2aa6e06bd3273969246c Miraielf mirai
http://161.97.149.138/systemcl/arm0aa6fd4f78bcee9f77a93153de85f0db4aa2e42464afcad9564ef46528697d44 Mirai32-bit elf mirai Mozi
http://161.97.149.138/systemcl/arm54b3fafa6af227c69f3164a2b4f85e7024361a714347c7f691099ed80736916ab Miraielf mirai
http://161.97.149.138/systemcl/arm6899c7e47c4e8f921e14bed7dcca677ed995ead6369168433011cac67ef6e5a59 Miraielf mirai
http://161.97.149.138/systemcl/arm7527debaef309134677a1c3a450dc5aea1f3a2a6f742fad86a20c80274c749630 Miraielf mirai
http://161.97.149.138/systemcl/m68kb819a17fd9314f13890dce05291b4c14b40477f0546c7481b4c2af576928244e Miraielf mirai
http://161.97.149.138/systemcl/mipsdc49d000be3daa749c372da39aad50bc49e8d944c7c868fb70b7d15e159d79d3 Mirai32-bit elf mirai Mozi
http://161.97.149.138/systemcl/mpslc5da1b833565988e4bb1729244b07d55ff21148392a7143ff5aab70f43788d6b Miraielf mirai
http://161.97.149.138/systemcl/ppcdcd7d4b917223e33897da06b7fdb676d16aa4d7afc0276bb4525c275b0a45b10 Miraielf mirai
http://161.97.149.138/systemcl/sh4n/an/aelf ua-wget
http://161.97.149.138/systemcl/spcn/an/aelf ua-wget
http://161.97.149.138/systemcl/x86d167fe5abe306825e029bd799bb645048ccae15dca31ea4ac9fcb8b416142a3a Mirai32-bit elf mirai Mozi
http://161.97.149.138/systemcl/x86_64d167fe5abe306825e029bd799bb645048ccae15dca31ea4ac9fcb8b416142a3a Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a7a26dbb-1700-0000-b9d8-13e1d00d0000 pid=3536 /usr/bin/sudo guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544 /tmp/sample.bin guuid=a7a26dbb-1700-0000-b9d8-13e1d00d0000 pid=3536->guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544 execve guuid=eb7f54bd-1700-0000-b9d8-13e1da0d0000 pid=3546 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=eb7f54bd-1700-0000-b9d8-13e1da0d0000 pid=3546 execve guuid=ccf322c1-1700-0000-b9d8-13e1e70d0000 pid=3559 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=ccf322c1-1700-0000-b9d8-13e1e70d0000 pid=3559 execve guuid=d9fddedb-1700-0000-b9d8-13e1fd0d0000 pid=3581 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=d9fddedb-1700-0000-b9d8-13e1fd0d0000 pid=3581 execve guuid=9ee039dc-1700-0000-b9d8-13e1ff0d0000 pid=3583 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=9ee039dc-1700-0000-b9d8-13e1ff0d0000 pid=3583 execve guuid=3c1982dc-1700-0000-b9d8-13e1010e0000 pid=3585 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=3c1982dc-1700-0000-b9d8-13e1010e0000 pid=3585 clone guuid=cfb135dd-1700-0000-b9d8-13e1040e0000 pid=3588 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=cfb135dd-1700-0000-b9d8-13e1040e0000 pid=3588 execve guuid=27a78add-1700-0000-b9d8-13e1050e0000 pid=3589 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=27a78add-1700-0000-b9d8-13e1050e0000 pid=3589 execve guuid=64a9f9df-1700-0000-b9d8-13e10a0e0000 pid=3594 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=64a9f9df-1700-0000-b9d8-13e10a0e0000 pid=3594 execve guuid=9258dde5-1700-0000-b9d8-13e1170e0000 pid=3607 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=9258dde5-1700-0000-b9d8-13e1170e0000 pid=3607 execve guuid=551f39e6-1700-0000-b9d8-13e1190e0000 pid=3609 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=551f39e6-1700-0000-b9d8-13e1190e0000 pid=3609 execve guuid=f18c97e6-1700-0000-b9d8-13e11b0e0000 pid=3611 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=f18c97e6-1700-0000-b9d8-13e11b0e0000 pid=3611 clone guuid=37805be8-1700-0000-b9d8-13e1230e0000 pid=3619 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=37805be8-1700-0000-b9d8-13e1230e0000 pid=3619 execve guuid=3f4ea4e8-1700-0000-b9d8-13e1250e0000 pid=3621 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=3f4ea4e8-1700-0000-b9d8-13e1250e0000 pid=3621 execve guuid=a40056ed-1700-0000-b9d8-13e1340e0000 pid=3636 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a40056ed-1700-0000-b9d8-13e1340e0000 pid=3636 execve guuid=ac5f38f3-1700-0000-b9d8-13e14b0e0000 pid=3659 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=ac5f38f3-1700-0000-b9d8-13e14b0e0000 pid=3659 execve guuid=53f473f3-1700-0000-b9d8-13e14c0e0000 pid=3660 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=53f473f3-1700-0000-b9d8-13e14c0e0000 pid=3660 execve guuid=e571aef3-1700-0000-b9d8-13e14e0e0000 pid=3662 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=e571aef3-1700-0000-b9d8-13e14e0e0000 pid=3662 clone guuid=4316d4f4-1700-0000-b9d8-13e1550e0000 pid=3669 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=4316d4f4-1700-0000-b9d8-13e1550e0000 pid=3669 execve guuid=dd510bf5-1700-0000-b9d8-13e1590e0000 pid=3673 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=dd510bf5-1700-0000-b9d8-13e1590e0000 pid=3673 execve guuid=97ddd5f7-1700-0000-b9d8-13e1600e0000 pid=3680 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=97ddd5f7-1700-0000-b9d8-13e1600e0000 pid=3680 execve guuid=5308e5fd-1700-0000-b9d8-13e1610e0000 pid=3681 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=5308e5fd-1700-0000-b9d8-13e1610e0000 pid=3681 execve guuid=2b9449fe-1700-0000-b9d8-13e1620e0000 pid=3682 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=2b9449fe-1700-0000-b9d8-13e1620e0000 pid=3682 execve guuid=a2eaa5fe-1700-0000-b9d8-13e1630e0000 pid=3683 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a2eaa5fe-1700-0000-b9d8-13e1630e0000 pid=3683 clone guuid=9a5b5eff-1700-0000-b9d8-13e1650e0000 pid=3685 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=9a5b5eff-1700-0000-b9d8-13e1650e0000 pid=3685 execve guuid=e1858900-1800-0000-b9d8-13e16c0e0000 pid=3692 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=e1858900-1800-0000-b9d8-13e16c0e0000 pid=3692 execve guuid=21e51208-1800-0000-b9d8-13e1790e0000 pid=3705 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=21e51208-1800-0000-b9d8-13e1790e0000 pid=3705 execve guuid=b006ee10-1800-0000-b9d8-13e1990e0000 pid=3737 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b006ee10-1800-0000-b9d8-13e1990e0000 pid=3737 execve guuid=0d9e2b11-1800-0000-b9d8-13e19d0e0000 pid=3741 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=0d9e2b11-1800-0000-b9d8-13e19d0e0000 pid=3741 execve guuid=6d936911-1800-0000-b9d8-13e19e0e0000 pid=3742 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=6d936911-1800-0000-b9d8-13e19e0e0000 pid=3742 clone guuid=c05f2812-1800-0000-b9d8-13e1a30e0000 pid=3747 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=c05f2812-1800-0000-b9d8-13e1a30e0000 pid=3747 execve guuid=3bf60414-1800-0000-b9d8-13e1ad0e0000 pid=3757 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=3bf60414-1800-0000-b9d8-13e1ad0e0000 pid=3757 execve guuid=e77f721a-1800-0000-b9d8-13e1c70e0000 pid=3783 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=e77f721a-1800-0000-b9d8-13e1c70e0000 pid=3783 execve guuid=b8c6d221-1800-0000-b9d8-13e1dd0e0000 pid=3805 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b8c6d221-1800-0000-b9d8-13e1dd0e0000 pid=3805 execve guuid=1ca02822-1800-0000-b9d8-13e1de0e0000 pid=3806 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=1ca02822-1800-0000-b9d8-13e1de0e0000 pid=3806 execve guuid=560a7222-1800-0000-b9d8-13e1df0e0000 pid=3807 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=560a7222-1800-0000-b9d8-13e1df0e0000 pid=3807 clone guuid=64990d23-1800-0000-b9d8-13e1e10e0000 pid=3809 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=64990d23-1800-0000-b9d8-13e1e10e0000 pid=3809 execve guuid=7aa14030-1800-0000-b9d8-13e1e40e0000 pid=3812 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=7aa14030-1800-0000-b9d8-13e1e40e0000 pid=3812 execve guuid=0bc5b637-1800-0000-b9d8-13e1e50e0000 pid=3813 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=0bc5b637-1800-0000-b9d8-13e1e50e0000 pid=3813 execve guuid=a76f7868-1800-0000-b9d8-13e1ee0e0000 pid=3822 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a76f7868-1800-0000-b9d8-13e1ee0e0000 pid=3822 execve guuid=7efc0569-1800-0000-b9d8-13e1ef0e0000 pid=3823 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=7efc0569-1800-0000-b9d8-13e1ef0e0000 pid=3823 execve guuid=71239669-1800-0000-b9d8-13e1f10e0000 pid=3825 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=71239669-1800-0000-b9d8-13e1f10e0000 pid=3825 clone guuid=abcfa76a-1800-0000-b9d8-13e1f40e0000 pid=3828 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=abcfa76a-1800-0000-b9d8-13e1f40e0000 pid=3828 execve guuid=0e2f4e6b-1800-0000-b9d8-13e1f50e0000 pid=3829 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=0e2f4e6b-1800-0000-b9d8-13e1f50e0000 pid=3829 execve guuid=be44066f-1800-0000-b9d8-13e1000f0000 pid=3840 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=be44066f-1800-0000-b9d8-13e1000f0000 pid=3840 execve guuid=7ad23c74-1800-0000-b9d8-13e1120f0000 pid=3858 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=7ad23c74-1800-0000-b9d8-13e1120f0000 pid=3858 execve guuid=41ebad74-1800-0000-b9d8-13e1130f0000 pid=3859 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=41ebad74-1800-0000-b9d8-13e1130f0000 pid=3859 execve guuid=0ca82375-1800-0000-b9d8-13e11b0f0000 pid=3867 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=0ca82375-1800-0000-b9d8-13e11b0f0000 pid=3867 clone guuid=eb81e775-1800-0000-b9d8-13e11d0f0000 pid=3869 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=eb81e775-1800-0000-b9d8-13e11d0f0000 pid=3869 execve guuid=3ae54076-1800-0000-b9d8-13e11e0f0000 pid=3870 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=3ae54076-1800-0000-b9d8-13e11e0f0000 pid=3870 execve guuid=f9265179-1800-0000-b9d8-13e1260f0000 pid=3878 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=f9265179-1800-0000-b9d8-13e1260f0000 pid=3878 execve guuid=3aa8a686-1800-0000-b9d8-13e1540f0000 pid=3924 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=3aa8a686-1800-0000-b9d8-13e1540f0000 pid=3924 execve guuid=e5d7e686-1800-0000-b9d8-13e1550f0000 pid=3925 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=e5d7e686-1800-0000-b9d8-13e1550f0000 pid=3925 execve guuid=5c1b3287-1800-0000-b9d8-13e1560f0000 pid=3926 /usr/bin/dash guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=5c1b3287-1800-0000-b9d8-13e1560f0000 pid=3926 clone guuid=0c17d088-1800-0000-b9d8-13e1600f0000 pid=3936 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=0c17d088-1800-0000-b9d8-13e1600f0000 pid=3936 execve guuid=c2083d89-1800-0000-b9d8-13e1620f0000 pid=3938 /usr/bin/wget net send-data guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=c2083d89-1800-0000-b9d8-13e1620f0000 pid=3938 execve guuid=d9eb3c8c-1800-0000-b9d8-13e16e0f0000 pid=3950 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=d9eb3c8c-1800-0000-b9d8-13e16e0f0000 pid=3950 execve guuid=b8be2a8f-1800-0000-b9d8-13e1790f0000 pid=3961 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b8be2a8f-1800-0000-b9d8-13e1790f0000 pid=3961 execve guuid=352d678f-1800-0000-b9d8-13e17a0f0000 pid=3962 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=352d678f-1800-0000-b9d8-13e17a0f0000 pid=3962 execve guuid=ea11ab8f-1800-0000-b9d8-13e17c0f0000 pid=3964 /tmp/sh4 guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=ea11ab8f-1800-0000-b9d8-13e17c0f0000 pid=3964 execve guuid=a59de28f-1800-0000-b9d8-13e17e0f0000 pid=3966 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a59de28f-1800-0000-b9d8-13e17e0f0000 pid=3966 execve guuid=17a88590-1800-0000-b9d8-13e1820f0000 pid=3970 /usr/bin/wget net send-data guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=17a88590-1800-0000-b9d8-13e1820f0000 pid=3970 execve guuid=806bdc95-1800-0000-b9d8-13e1900f0000 pid=3984 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=806bdc95-1800-0000-b9d8-13e1900f0000 pid=3984 execve guuid=b32b789a-1800-0000-b9d8-13e1a70f0000 pid=4007 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b32b789a-1800-0000-b9d8-13e1a70f0000 pid=4007 execve guuid=a333b59a-1800-0000-b9d8-13e1a90f0000 pid=4009 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a333b59a-1800-0000-b9d8-13e1a90f0000 pid=4009 execve guuid=5fd2ef9a-1800-0000-b9d8-13e1aa0f0000 pid=4010 /tmp/spc guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=5fd2ef9a-1800-0000-b9d8-13e1aa0f0000 pid=4010 execve guuid=2caf229b-1800-0000-b9d8-13e1ac0f0000 pid=4012 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=2caf229b-1800-0000-b9d8-13e1ac0f0000 pid=4012 execve guuid=bc6b759b-1800-0000-b9d8-13e1ae0f0000 pid=4014 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=bc6b759b-1800-0000-b9d8-13e1ae0f0000 pid=4014 execve guuid=b1f23f9e-1800-0000-b9d8-13e1b80f0000 pid=4024 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b1f23f9e-1800-0000-b9d8-13e1b80f0000 pid=4024 execve guuid=b317bba2-1800-0000-b9d8-13e1cd0f0000 pid=4045 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=b317bba2-1800-0000-b9d8-13e1cd0f0000 pid=4045 execve guuid=ae5903a3-1800-0000-b9d8-13e1ce0f0000 pid=4046 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=ae5903a3-1800-0000-b9d8-13e1ce0f0000 pid=4046 execve guuid=ccc441a3-1800-0000-b9d8-13e1d20f0000 pid=4050 /tmp/x86 net write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=ccc441a3-1800-0000-b9d8-13e1d20f0000 pid=4050 execve guuid=1b6b77b1-1800-0000-b9d8-13e114100000 pid=4116 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=1b6b77b1-1800-0000-b9d8-13e114100000 pid=4116 execve guuid=dcdcbcb1-1800-0000-b9d8-13e116100000 pid=4118 /usr/bin/wget net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=dcdcbcb1-1800-0000-b9d8-13e116100000 pid=4118 execve guuid=7043b6b5-1800-0000-b9d8-13e126100000 pid=4134 /usr/bin/curl net send-data write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=7043b6b5-1800-0000-b9d8-13e126100000 pid=4134 execve guuid=4a2b5fbb-1800-0000-b9d8-13e139100000 pid=4153 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=4a2b5fbb-1800-0000-b9d8-13e139100000 pid=4153 execve guuid=156ca2bb-1800-0000-b9d8-13e13a100000 pid=4154 /usr/bin/chmod guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=156ca2bb-1800-0000-b9d8-13e13a100000 pid=4154 execve guuid=a3abe2bb-1800-0000-b9d8-13e13c100000 pid=4156 /tmp/x86_64 net write-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=a3abe2bb-1800-0000-b9d8-13e13c100000 pid=4156 execve guuid=5cbd10ca-1800-0000-b9d8-13e177100000 pid=4215 /usr/bin/rm delete-file guuid=34a11ebd-1700-0000-b9d8-13e1d80d0000 pid=3544->guuid=5cbd10ca-1800-0000-b9d8-13e177100000 pid=4215 execve fc577216-6857-5e80-aeaf-7ca7103e91b9 161.97.149.138:80 guuid=eb7f54bd-1700-0000-b9d8-13e1da0d0000 pid=3546->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=ccf322c1-1700-0000-b9d8-13e1e70d0000 pid=3559->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B guuid=27a78add-1700-0000-b9d8-13e1050e0000 pid=3589->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=64a9f9df-1700-0000-b9d8-13e10a0e0000 pid=3594->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B guuid=3f4ea4e8-1700-0000-b9d8-13e1250e0000 pid=3621->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=a40056ed-1700-0000-b9d8-13e1340e0000 pid=3636->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=dd510bf5-1700-0000-b9d8-13e1590e0000 pid=3673->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=97ddd5f7-1700-0000-b9d8-13e1600e0000 pid=3680->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=e1858900-1800-0000-b9d8-13e16c0e0000 pid=3692->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=21e51208-1800-0000-b9d8-13e1790e0000 pid=3705->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=3bf60414-1800-0000-b9d8-13e1ad0e0000 pid=3757->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=e77f721a-1800-0000-b9d8-13e1c70e0000 pid=3783->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=7aa14030-1800-0000-b9d8-13e1e40e0000 pid=3812->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=0bc5b637-1800-0000-b9d8-13e1e50e0000 pid=3813->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=0e2f4e6b-1800-0000-b9d8-13e1f50e0000 pid=3829->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 142B guuid=be44066f-1800-0000-b9d8-13e1000f0000 pid=3840->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 91B guuid=3ae54076-1800-0000-b9d8-13e11e0f0000 pid=3870->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=f9265179-1800-0000-b9d8-13e1260f0000 pid=3878->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B guuid=c2083d89-1800-0000-b9d8-13e1620f0000 pid=3938->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=d9eb3c8c-1800-0000-b9d8-13e16e0f0000 pid=3950->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B guuid=17a88590-1800-0000-b9d8-13e1820f0000 pid=3970->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=806bdc95-1800-0000-b9d8-13e1900f0000 pid=3984->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B guuid=bc6b759b-1800-0000-b9d8-13e1ae0f0000 pid=4014->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 141B guuid=b1f23f9e-1800-0000-b9d8-13e1b80f0000 pid=4024->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ccc441a3-1800-0000-b9d8-13e1d20f0000 pid=4050->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=094769b1-1800-0000-b9d8-13e112100000 pid=4114 /tmp/x86 guuid=ccc441a3-1800-0000-b9d8-13e1d20f0000 pid=4050->guuid=094769b1-1800-0000-b9d8-13e112100000 pid=4114 clone guuid=8bbf6db1-1800-0000-b9d8-13e113100000 pid=4115 /tmp/x86 net send-data zombie guuid=ccc441a3-1800-0000-b9d8-13e1d20f0000 pid=4050->guuid=8bbf6db1-1800-0000-b9d8-13e113100000 pid=4115 clone guuid=8bbf6db1-1800-0000-b9d8-13e113100000 pid=4115->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 741d4b50-67cd-5c90-a3da-6fb4b3d62b18 87.121.84.117:61459 guuid=8bbf6db1-1800-0000-b9d8-13e113100000 pid=4115->741d4b50-67cd-5c90-a3da-6fb4b3d62b18 send: 41B guuid=dcdcbcb1-1800-0000-b9d8-13e116100000 pid=4118->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 144B guuid=7043b6b5-1800-0000-b9d8-13e126100000 pid=4134->fc577216-6857-5e80-aeaf-7ca7103e91b9 send: 93B guuid=a3abe2bb-1800-0000-b9d8-13e13c100000 pid=4156->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f54f05ca-1800-0000-b9d8-13e174100000 pid=4212 /tmp/x86_64 guuid=a3abe2bb-1800-0000-b9d8-13e13c100000 pid=4156->guuid=f54f05ca-1800-0000-b9d8-13e174100000 pid=4212 clone guuid=c37a09ca-1800-0000-b9d8-13e176100000 pid=4214 /tmp/x86_64 net send-data zombie guuid=a3abe2bb-1800-0000-b9d8-13e13c100000 pid=4156->guuid=c37a09ca-1800-0000-b9d8-13e176100000 pid=4214 clone guuid=c37a09ca-1800-0000-b9d8-13e176100000 pid=4214->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c37a09ca-1800-0000-b9d8-13e176100000 pid=4214->741d4b50-67cd-5c90-a3da-6fb4b3d62b18 send: 46B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-29 18:00:26 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1551d33d26531767211244f0e646501a707170399859c9866ac1e704888d1939

(this sample)

  
Delivery method
Distributed via web download

Comments