MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 185e86a756475c65731c8eba1023d9c7e4abef6375b44986a238dd98756a749f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 185e86a756475c65731c8eba1023d9c7e4abef6375b44986a238dd98756a749f
SHA3-384 hash: 77bb2971fcd270d339efb53e0ab0810da26f56391a67a1c2f0220351bab812e1f432901482319a9345385bf2a2d49a9f
SHA1 hash: 3d679553ebe9c3594954b50878a5762db9dc0c67
MD5 hash: b304f3f3e43a6e98804d2c7d12916580
humanhash: freddie-lamp-sodium-comet
File name:1.sh
Download: download sample
Signature Mirai
File size:3'239 bytes
First seen:2025-09-26 03:28:46 UTC
Last seen:2025-09-26 04:20:32 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:IttsPkNJQuZQsmSHGdJiZrLpgNIsks7nwc3JMAK:iWPkP11HGriZrLwJ7nwc5nK
TLSH T1906161E930529232AE67CB5363AA95983C45D0A7D0CB9F9557FD78B98C8CFC8AC00553
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.72.82/00101010101001/Ares.x86ae23915ce8258283349323c0cf0465a9f86b8f74a29cb2ac16099434bd3e4d76 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.mipsf39606655f94a3f5ba998faba6b36253eaa6ff55db958d0c01f129e3a4eeb4f7 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.arcn/an/aelf ua-wget
http://196.251.72.82/00101010101001/Ares.i468n/an/aelf ua-wget
http://196.251.72.82/00101010101001/Ares.i686n/an/aelf ua-wget
http://196.251.72.82/00101010101001/Ares.x86_64n/an/aelf ua-wget
http://196.251.72.82/00101010101001/Ares.mpsl4f954038b1560cd751be3494c79a46faf7996de397a5090f86b0105364339d7c Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.arm36e058db9537942b6297092ef2f2cc9cc0867ca07ade0ab506cfe88c70fda41f Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.arm56c15ea97428d16afdaee722b87fb4e4a080f1bb23f2cecab851566051ae1870e Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.arm6fdb51b5dc14923aef8064ef76baa3b8e6bb80bff7cd2d4e9dd59a2335bb903f3 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.arm77aaf766531c34cd54b3900d8d2577ac231de38f7f4ef8dc715d6241d2eb69d22 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.ppc1af2a2992cd501b8c41e5cd2f519dc74844cd2035287420ab251336ef07ca4bf Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.spc873dc94fe82e7853c4932e5141319a3d4e805ab0e464839a34146629682ad498 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.m68k2eac628086fbd7ef141240e3b3e54935a1dbca0a699c2ed3859654fc27817067 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/Ares.sh474ff2914135ad80d3eaa968dfa9ffee882baa2306b51ad96b526c25787a48865 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-26T00:36:00Z UTC
Last seen:
2025-09-26T00:36:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=4d6f2b35-1a00-0000-0441-a573f50b0000 pid=3061 /usr/bin/sudo guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062 /tmp/sample.bin guuid=4d6f2b35-1a00-0000-0441-a573f50b0000 pid=3061->guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062 execve guuid=38382538-1a00-0000-0441-a573f70b0000 pid=3063 /usr/bin/cp guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=38382538-1a00-0000-0441-a573f70b0000 pid=3063 execve guuid=ea57183f-1a00-0000-0441-a573f80b0000 pid=3064 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=ea57183f-1a00-0000-0441-a573f80b0000 pid=3064 execve guuid=04c8784d-1a00-0000-0441-a5730d0c0000 pid=3085 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=04c8784d-1a00-0000-0441-a5730d0c0000 pid=3085 execve guuid=72461869-1a00-0000-0441-a573240c0000 pid=3108 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=72461869-1a00-0000-0441-a573240c0000 pid=3108 execve guuid=e59c9c69-1a00-0000-0441-a573250c0000 pid=3109 /tmp/Ares.x86 net guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=e59c9c69-1a00-0000-0441-a573250c0000 pid=3109 execve guuid=1218f269-1a00-0000-0441-a573280c0000 pid=3112 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=1218f269-1a00-0000-0441-a573280c0000 pid=3112 execve guuid=2b205e6a-1a00-0000-0441-a5732b0c0000 pid=3115 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=2b205e6a-1a00-0000-0441-a5732b0c0000 pid=3115 execve guuid=0a1f8878-1a00-0000-0441-a573520c0000 pid=3154 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=0a1f8878-1a00-0000-0441-a573520c0000 pid=3154 execve guuid=b8d66081-1a00-0000-0441-a5735d0c0000 pid=3165 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=b8d66081-1a00-0000-0441-a5735d0c0000 pid=3165 execve guuid=18abb181-1a00-0000-0441-a5735f0c0000 pid=3167 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=18abb181-1a00-0000-0441-a5735f0c0000 pid=3167 clone guuid=c723eb82-1a00-0000-0441-a573610c0000 pid=3169 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=c723eb82-1a00-0000-0441-a573610c0000 pid=3169 execve guuid=07e06087-1a00-0000-0441-a573680c0000 pid=3176 /usr/bin/wget net send-data guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=07e06087-1a00-0000-0441-a573680c0000 pid=3176 execve guuid=ad1a028c-1a00-0000-0441-a573730c0000 pid=3187 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=ad1a028c-1a00-0000-0441-a573730c0000 pid=3187 execve guuid=2f831091-1a00-0000-0441-a573780c0000 pid=3192 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=2f831091-1a00-0000-0441-a573780c0000 pid=3192 execve guuid=10a0aa91-1a00-0000-0441-a573790c0000 pid=3193 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=10a0aa91-1a00-0000-0441-a573790c0000 pid=3193 clone guuid=88efd791-1a00-0000-0441-a5737a0c0000 pid=3194 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=88efd791-1a00-0000-0441-a5737a0c0000 pid=3194 execve guuid=2dd24092-1a00-0000-0441-a5737b0c0000 pid=3195 /usr/bin/wget net send-data guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=2dd24092-1a00-0000-0441-a5737b0c0000 pid=3195 execve guuid=7fc0c496-1a00-0000-0441-a5737c0c0000 pid=3196 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=7fc0c496-1a00-0000-0441-a5737c0c0000 pid=3196 execve guuid=52fd829c-1a00-0000-0441-a5737d0c0000 pid=3197 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=52fd829c-1a00-0000-0441-a5737d0c0000 pid=3197 execve guuid=255a369d-1a00-0000-0441-a5737e0c0000 pid=3198 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=255a369d-1a00-0000-0441-a5737e0c0000 pid=3198 clone guuid=3d69989d-1a00-0000-0441-a5737f0c0000 pid=3199 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=3d69989d-1a00-0000-0441-a5737f0c0000 pid=3199 execve guuid=50f0599e-1a00-0000-0441-a573800c0000 pid=3200 /usr/bin/wget net send-data guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=50f0599e-1a00-0000-0441-a573800c0000 pid=3200 execve guuid=245fb1a2-1a00-0000-0441-a573820c0000 pid=3202 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=245fb1a2-1a00-0000-0441-a573820c0000 pid=3202 execve guuid=7754b1aa-1a00-0000-0441-a573960c0000 pid=3222 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=7754b1aa-1a00-0000-0441-a573960c0000 pid=3222 execve guuid=458b49ab-1a00-0000-0441-a573990c0000 pid=3225 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=458b49ab-1a00-0000-0441-a573990c0000 pid=3225 clone guuid=4b77d8ab-1a00-0000-0441-a5739a0c0000 pid=3226 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=4b77d8ab-1a00-0000-0441-a5739a0c0000 pid=3226 execve guuid=eb0533ac-1a00-0000-0441-a5739c0c0000 pid=3228 /usr/bin/wget net send-data guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=eb0533ac-1a00-0000-0441-a5739c0c0000 pid=3228 execve guuid=c0c33cb5-1a00-0000-0441-a573a40c0000 pid=3236 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=c0c33cb5-1a00-0000-0441-a573a40c0000 pid=3236 execve guuid=df53b7bc-1a00-0000-0441-a573ab0c0000 pid=3243 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=df53b7bc-1a00-0000-0441-a573ab0c0000 pid=3243 execve guuid=765069bd-1a00-0000-0441-a573ac0c0000 pid=3244 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=765069bd-1a00-0000-0441-a573ac0c0000 pid=3244 clone guuid=9cbaacbd-1a00-0000-0441-a573ad0c0000 pid=3245 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=9cbaacbd-1a00-0000-0441-a573ad0c0000 pid=3245 execve guuid=039648be-1a00-0000-0441-a573ae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=039648be-1a00-0000-0441-a573ae0c0000 pid=3246 execve guuid=d3bf1bc6-1a00-0000-0441-a573af0c0000 pid=3247 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=d3bf1bc6-1a00-0000-0441-a573af0c0000 pid=3247 execve guuid=d4f14ccf-1a00-0000-0441-a573b00c0000 pid=3248 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=d4f14ccf-1a00-0000-0441-a573b00c0000 pid=3248 execve guuid=c1bfc2cf-1a00-0000-0441-a573b10c0000 pid=3249 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=c1bfc2cf-1a00-0000-0441-a573b10c0000 pid=3249 clone guuid=a7e7bdd0-1a00-0000-0441-a573b30c0000 pid=3251 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=a7e7bdd0-1a00-0000-0441-a573b30c0000 pid=3251 execve guuid=11e88dd1-1a00-0000-0441-a573b40c0000 pid=3252 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=11e88dd1-1a00-0000-0441-a573b40c0000 pid=3252 execve guuid=4210dad8-1a00-0000-0441-a573bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=4210dad8-1a00-0000-0441-a573bd0c0000 pid=3261 execve guuid=7f7ff3e2-1a00-0000-0441-a573cb0c0000 pid=3275 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=7f7ff3e2-1a00-0000-0441-a573cb0c0000 pid=3275 execve guuid=a25089e3-1a00-0000-0441-a573cc0c0000 pid=3276 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=a25089e3-1a00-0000-0441-a573cc0c0000 pid=3276 clone guuid=6e56b6e5-1a00-0000-0441-a573ce0c0000 pid=3278 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=6e56b6e5-1a00-0000-0441-a573ce0c0000 pid=3278 execve guuid=45562ae6-1a00-0000-0441-a573cf0c0000 pid=3279 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=45562ae6-1a00-0000-0441-a573cf0c0000 pid=3279 execve guuid=c28ff0eb-1a00-0000-0441-a573d70c0000 pid=3287 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=c28ff0eb-1a00-0000-0441-a573d70c0000 pid=3287 execve guuid=f92c2df4-1a00-0000-0441-a573e30c0000 pid=3299 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=f92c2df4-1a00-0000-0441-a573e30c0000 pid=3299 execve guuid=99687af4-1a00-0000-0441-a573e50c0000 pid=3301 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=99687af4-1a00-0000-0441-a573e50c0000 pid=3301 clone guuid=e02912f5-1a00-0000-0441-a573e90c0000 pid=3305 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=e02912f5-1a00-0000-0441-a573e90c0000 pid=3305 execve guuid=089e89fe-1a00-0000-0441-a573ea0c0000 pid=3306 /usr/bin/wget net guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=089e89fe-1a00-0000-0441-a573ea0c0000 pid=3306 execve guuid=93a84300-1b00-0000-0441-a573eb0c0000 pid=3307 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=93a84300-1b00-0000-0441-a573eb0c0000 pid=3307 execve guuid=490cd30a-1b00-0000-0441-a573ff0c0000 pid=3327 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=490cd30a-1b00-0000-0441-a573ff0c0000 pid=3327 execve guuid=2110170b-1b00-0000-0441-a573010d0000 pid=3329 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=2110170b-1b00-0000-0441-a573010d0000 pid=3329 clone guuid=7155bb0b-1b00-0000-0441-a573030d0000 pid=3331 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=7155bb0b-1b00-0000-0441-a573030d0000 pid=3331 execve guuid=1085240c-1b00-0000-0441-a573040d0000 pid=3332 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=1085240c-1b00-0000-0441-a573040d0000 pid=3332 execve guuid=88869d14-1b00-0000-0441-a5731a0d0000 pid=3354 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=88869d14-1b00-0000-0441-a5731a0d0000 pid=3354 execve guuid=cf9e7b1e-1b00-0000-0441-a573340d0000 pid=3380 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=cf9e7b1e-1b00-0000-0441-a573340d0000 pid=3380 execve guuid=6c47ce1e-1b00-0000-0441-a573360d0000 pid=3382 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=6c47ce1e-1b00-0000-0441-a573360d0000 pid=3382 clone guuid=82cd791f-1b00-0000-0441-a573390d0000 pid=3385 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=82cd791f-1b00-0000-0441-a573390d0000 pid=3385 execve guuid=e3c4b622-1b00-0000-0441-a5733d0d0000 pid=3389 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=e3c4b622-1b00-0000-0441-a5733d0d0000 pid=3389 execve guuid=36769a2a-1b00-0000-0441-a5733e0d0000 pid=3390 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=36769a2a-1b00-0000-0441-a5733e0d0000 pid=3390 execve guuid=0737c233-1b00-0000-0441-a5734a0d0000 pid=3402 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=0737c233-1b00-0000-0441-a5734a0d0000 pid=3402 execve guuid=85e30934-1b00-0000-0441-a5734b0d0000 pid=3403 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=85e30934-1b00-0000-0441-a5734b0d0000 pid=3403 clone guuid=c97ee735-1b00-0000-0441-a573510d0000 pid=3409 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=c97ee735-1b00-0000-0441-a573510d0000 pid=3409 execve guuid=4f24f037-1b00-0000-0441-a573550d0000 pid=3413 /usr/bin/wget net guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=4f24f037-1b00-0000-0441-a573550d0000 pid=3413 execve guuid=43882139-1b00-0000-0441-a573560d0000 pid=3414 /usr/bin/curl net guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=43882139-1b00-0000-0441-a573560d0000 pid=3414 execve guuid=f36e713d-1b00-0000-0441-a5735d0d0000 pid=3421 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=f36e713d-1b00-0000-0441-a5735d0d0000 pid=3421 execve guuid=1ba2de3d-1b00-0000-0441-a5735f0d0000 pid=3423 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=1ba2de3d-1b00-0000-0441-a5735f0d0000 pid=3423 clone guuid=39b9f93d-1b00-0000-0441-a573600d0000 pid=3424 /usr/bin/rm guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=39b9f93d-1b00-0000-0441-a573600d0000 pid=3424 execve guuid=bd1a653e-1b00-0000-0441-a573620d0000 pid=3426 /usr/bin/wget net guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=bd1a653e-1b00-0000-0441-a573620d0000 pid=3426 execve guuid=803ac13f-1b00-0000-0441-a573650d0000 pid=3429 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=803ac13f-1b00-0000-0441-a573650d0000 pid=3429 execve guuid=9991b148-1b00-0000-0441-a573780d0000 pid=3448 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=9991b148-1b00-0000-0441-a573780d0000 pid=3448 execve guuid=4e794249-1b00-0000-0441-a573790d0000 pid=3449 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=4e794249-1b00-0000-0441-a573790d0000 pid=3449 clone guuid=d32a164a-1b00-0000-0441-a5737c0d0000 pid=3452 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=d32a164a-1b00-0000-0441-a5737c0d0000 pid=3452 execve guuid=22da6d4a-1b00-0000-0441-a5737e0d0000 pid=3454 /usr/bin/wget net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=22da6d4a-1b00-0000-0441-a5737e0d0000 pid=3454 execve guuid=f3de7650-1b00-0000-0441-a5738e0d0000 pid=3470 /usr/bin/curl net send-data write-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=f3de7650-1b00-0000-0441-a5738e0d0000 pid=3470 execve guuid=be4b0857-1b00-0000-0441-a573a70d0000 pid=3495 /usr/bin/chmod guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=be4b0857-1b00-0000-0441-a573a70d0000 pid=3495 execve guuid=de145857-1b00-0000-0441-a573a90d0000 pid=3497 /usr/bin/bash guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=de145857-1b00-0000-0441-a573a90d0000 pid=3497 clone guuid=ac943458-1b00-0000-0441-a573ae0d0000 pid=3502 /usr/bin/rm delete-file guuid=6c292c37-1a00-0000-0441-a573f60b0000 pid=3062->guuid=ac943458-1b00-0000-0441-a573ae0d0000 pid=3502 execve ce94efdc-f6e6-538c-917c-a4373dec06e1 196.251.72.82:80 guuid=ea57183f-1a00-0000-0441-a573f80b0000 pid=3064->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 151B guuid=04c8784d-1a00-0000-0441-a5730d0c0000 pid=3085->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e59c9c69-1a00-0000-0441-a573250c0000 pid=3109->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=35eade69-1a00-0000-0441-a573260c0000 pid=3110 /tmp/Ares.x86 net zombie guuid=e59c9c69-1a00-0000-0441-a573250c0000 pid=3109->guuid=35eade69-1a00-0000-0441-a573260c0000 pid=3110 clone 05858422-5da4-5b91-b8c2-c3ec07f417a8 196.251.72.82:37212 guuid=35eade69-1a00-0000-0441-a573260c0000 pid=3110->05858422-5da4-5b91-b8c2-c3ec07f417a8 con guuid=926cee69-1a00-0000-0441-a573270c0000 pid=3111 /tmp/Ares.x86 guuid=35eade69-1a00-0000-0441-a573260c0000 pid=3110->guuid=926cee69-1a00-0000-0441-a573270c0000 pid=3111 clone guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113 /tmp/Ares.x86 net net-scan send-data guuid=35eade69-1a00-0000-0441-a573260c0000 pid=3110->guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113 clone guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 92dd5de4-6fb3-50dc-a795-50f61c7cc226 103.45.173.36:23 guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->92dd5de4-6fb3-50dc-a795-50f61c7cc226 send: 40B ff1b0036-8841-59c3-b84b-4b3cb4e2dff2 1.49.246.58:23 guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->ff1b0036-8841-59c3-b84b-4b3cb4e2dff2 send: 40B be85a9bf-e00b-52c7-8938-59e54a833a87 212.3.216.191:2323 guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->be85a9bf-e00b-52c7-8938-59e54a833a87 con eccd2260-e924-51a1-925f-b445418922ba 132.183.247.84:23 guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->eccd2260-e924-51a1-925f-b445418922ba con guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113|send-data send-data to 4097 IP addresses review logs to see them all guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113->guuid=3cfef669-1a00-0000-0441-a573290c0000 pid=3113|send-data send guuid=2b205e6a-1a00-0000-0441-a5732b0c0000 pid=3115->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=0a1f8878-1a00-0000-0441-a573520c0000 pid=3154->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=07e06087-1a00-0000-0441-a573680c0000 pid=3176->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 151B guuid=ad1a028c-1a00-0000-0441-a573730c0000 pid=3187->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 100B guuid=2dd24092-1a00-0000-0441-a5737b0c0000 pid=3195->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=7fc0c496-1a00-0000-0441-a5737c0c0000 pid=3196->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=50f0599e-1a00-0000-0441-a573800c0000 pid=3200->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=245fb1a2-1a00-0000-0441-a573820c0000 pid=3202->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=eb0533ac-1a00-0000-0441-a5739c0c0000 pid=3228->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 154B guuid=c0c33cb5-1a00-0000-0441-a573a40c0000 pid=3236->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 103B guuid=039648be-1a00-0000-0441-a573ae0c0000 pid=3246->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=d3bf1bc6-1a00-0000-0441-a573af0c0000 pid=3247->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=11e88dd1-1a00-0000-0441-a573b40c0000 pid=3252->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 151B guuid=4210dad8-1a00-0000-0441-a573bd0c0000 pid=3261->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 100B guuid=45562ae6-1a00-0000-0441-a573cf0c0000 pid=3279->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=c28ff0eb-1a00-0000-0441-a573d70c0000 pid=3287->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=089e89fe-1a00-0000-0441-a573ea0c0000 pid=3306->ce94efdc-f6e6-538c-917c-a4373dec06e1 con guuid=93a84300-1b00-0000-0441-a573eb0c0000 pid=3307->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=1085240c-1b00-0000-0441-a573040d0000 pid=3332->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=88869d14-1b00-0000-0441-a5731a0d0000 pid=3354->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=e3c4b622-1b00-0000-0441-a5733d0d0000 pid=3389->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 151B guuid=36769a2a-1b00-0000-0441-a5733e0d0000 pid=3390->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 100B guuid=4f24f037-1b00-0000-0441-a573550d0000 pid=3413->ce94efdc-f6e6-538c-917c-a4373dec06e1 con guuid=43882139-1b00-0000-0441-a573560d0000 pid=3414->ce94efdc-f6e6-538c-917c-a4373dec06e1 con guuid=bd1a653e-1b00-0000-0441-a573620d0000 pid=3426->ce94efdc-f6e6-538c-917c-a4373dec06e1 con guuid=803ac13f-1b00-0000-0441-a573650d0000 pid=3429->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B guuid=22da6d4a-1b00-0000-0441-a5737e0d0000 pid=3454->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 151B guuid=f3de7650-1b00-0000-0441-a5738e0d0000 pid=3470->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 100B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-26 03:29:30 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (116618) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 185e86a756475c65731c8eba1023d9c7e4abef6375b44986a238dd98756a749f

(this sample)

  
Delivery method
Distributed via web download

Comments