MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1fd6d68852a93148e8d04ac6089fda742ac5ffc4d326b3dba5e4884b3b0bd3a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 1fd6d68852a93148e8d04ac6089fda742ac5ffc4d326b3dba5e4884b3b0bd3a0
SHA3-384 hash: 78f4ad6441deb027f41947b4f2ba2fb6191e0abb00dc35e41e93d3c3c6e946446393745c4ff80651e4f29815465a7b68
SHA1 hash: 995526d5c67904545790d8469174b3e528cf1848
MD5 hash: f4d3e0911c841ab90c0bffe9ab664805
humanhash: beryllium-mississippi-floor-september
File name:zte
Download: download sample
Signature Mirai
File size:4'793 bytes
First seen:2026-03-27 23:13:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vpK8KMV4kUpKDK1V4ApKrOKrWV4bpKQKoV4ZpKE0KEEV4ENpKUKkV4tpKDK1V4A+:v3idFbGXqTGEpN7cFZjjf2jUtzrvjM/N
TLSH T1E4A1C5E974B4936B3DB0ED7375D6CA52F24021A7E0C91C0AE6D6F0E9498CF61F494B82
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
70
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=a45f2bb1-1600-0000-bf75-a827350e0000 pid=3637 /usr/bin/sudo guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645 /tmp/sample.bin guuid=a45f2bb1-1600-0000-bf75-a827350e0000 pid=3637->guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645 execve guuid=c7a2e1b3-1600-0000-bf75-a827410e0000 pid=3649 /usr/bin/wget net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=c7a2e1b3-1600-0000-bf75-a827410e0000 pid=3649 execve guuid=9d7856bb-1600-0000-bf75-a8274b0e0000 pid=3659 /usr/bin/curl net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=9d7856bb-1600-0000-bf75-a8274b0e0000 pid=3659 execve guuid=3f1f01c6-1600-0000-bf75-a827550e0000 pid=3669 /usr/bin/cat guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=3f1f01c6-1600-0000-bf75-a827550e0000 pid=3669 execve guuid=dada50c6-1600-0000-bf75-a827570e0000 pid=3671 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=dada50c6-1600-0000-bf75-a827570e0000 pid=3671 execve guuid=974e9ec6-1600-0000-bf75-a827590e0000 pid=3673 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=974e9ec6-1600-0000-bf75-a827590e0000 pid=3673 execve guuid=c7bce1c6-1600-0000-bf75-a8275f0e0000 pid=3679 /usr/bin/wget net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=c7bce1c6-1600-0000-bf75-a8275f0e0000 pid=3679 execve guuid=373b3cd3-1600-0000-bf75-a8277a0e0000 pid=3706 /usr/bin/curl net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=373b3cd3-1600-0000-bf75-a8277a0e0000 pid=3706 execve guuid=21cfe6dc-1600-0000-bf75-a827a50e0000 pid=3749 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=21cfe6dc-1600-0000-bf75-a827a50e0000 pid=3749 clone guuid=a1d6fcdc-1600-0000-bf75-a827a60e0000 pid=3750 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=a1d6fcdc-1600-0000-bf75-a827a60e0000 pid=3750 execve guuid=b2963fdd-1600-0000-bf75-a827a80e0000 pid=3752 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=b2963fdd-1600-0000-bf75-a827a80e0000 pid=3752 execve guuid=f39c730e-1800-0000-bf75-a82777120000 pid=4727 /usr/bin/wget net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=f39c730e-1800-0000-bf75-a82777120000 pid=4727 execve guuid=11be6e17-1800-0000-bf75-a82799120000 pid=4761 /usr/bin/curl net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=11be6e17-1800-0000-bf75-a82799120000 pid=4761 execve guuid=3c91201d-1800-0000-bf75-a827b1120000 pid=4785 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=3c91201d-1800-0000-bf75-a827b1120000 pid=4785 clone guuid=a705381d-1800-0000-bf75-a827b2120000 pid=4786 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=a705381d-1800-0000-bf75-a827b2120000 pid=4786 execve guuid=f5397c1d-1800-0000-bf75-a827b4120000 pid=4788 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=f5397c1d-1800-0000-bf75-a827b4120000 pid=4788 execve guuid=e75c7c50-1900-0000-bf75-a82781140000 pid=5249 /usr/bin/wget net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=e75c7c50-1900-0000-bf75-a82781140000 pid=5249 execve guuid=1a828e5a-1900-0000-bf75-a82786140000 pid=5254 /usr/bin/curl net send-data write-file guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=1a828e5a-1900-0000-bf75-a82786140000 pid=5254 execve guuid=fa89c761-1900-0000-bf75-a82787140000 pid=5255 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=fa89c761-1900-0000-bf75-a82787140000 pid=5255 clone guuid=37d2f061-1900-0000-bf75-a82788140000 pid=5256 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=37d2f061-1900-0000-bf75-a82788140000 pid=5256 execve guuid=278f7d62-1900-0000-bf75-a82789140000 pid=5257 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=278f7d62-1900-0000-bf75-a82789140000 pid=5257 execve guuid=8c4a4c95-1a00-0000-bf75-a82792140000 pid=5266 /usr/bin/wget net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=8c4a4c95-1a00-0000-bf75-a82792140000 pid=5266 execve guuid=34a21098-1a00-0000-bf75-a82797140000 pid=5271 /usr/bin/curl net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=34a21098-1a00-0000-bf75-a82797140000 pid=5271 execve guuid=e8e4b29a-1a00-0000-bf75-a82798140000 pid=5272 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=e8e4b29a-1a00-0000-bf75-a82798140000 pid=5272 clone guuid=fdd5f09a-1a00-0000-bf75-a82799140000 pid=5273 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=fdd5f09a-1a00-0000-bf75-a82799140000 pid=5273 execve guuid=528bc29b-1a00-0000-bf75-a8279a140000 pid=5274 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=528bc29b-1a00-0000-bf75-a8279a140000 pid=5274 execve guuid=3b063c46-2000-0000-bf75-a827bd140000 pid=5309 /usr/bin/wget net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=3b063c46-2000-0000-bf75-a827bd140000 pid=5309 execve guuid=a338aa48-2000-0000-bf75-a827c1140000 pid=5313 /usr/bin/curl net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=a338aa48-2000-0000-bf75-a827c1140000 pid=5313 execve guuid=f79e734c-2000-0000-bf75-a827c2140000 pid=5314 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=f79e734c-2000-0000-bf75-a827c2140000 pid=5314 clone guuid=c75c924c-2000-0000-bf75-a827c3140000 pid=5315 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=c75c924c-2000-0000-bf75-a827c3140000 pid=5315 execve guuid=1ce5ec4c-2000-0000-bf75-a827c4140000 pid=5316 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=1ce5ec4c-2000-0000-bf75-a827c4140000 pid=5316 execve guuid=2c9c89f6-2500-0000-bf75-a827c7140000 pid=5319 /usr/bin/wget net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=2c9c89f6-2500-0000-bf75-a827c7140000 pid=5319 execve guuid=1c6109f8-2500-0000-bf75-a827cb140000 pid=5323 /usr/bin/curl net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=1c6109f8-2500-0000-bf75-a827cb140000 pid=5323 execve guuid=f0a719fb-2500-0000-bf75-a827cc140000 pid=5324 /usr/bin/bash guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=f0a719fb-2500-0000-bf75-a827cc140000 pid=5324 clone guuid=f0ea37fb-2500-0000-bf75-a827cd140000 pid=5325 /usr/bin/chmod guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=f0ea37fb-2500-0000-bf75-a827cd140000 pid=5325 execve guuid=6233a0fb-2500-0000-bf75-a827ce140000 pid=5326 /tmp/76d32be0 net guuid=bbf4edb2-1600-0000-bf75-a8273d0e0000 pid=3645->guuid=6233a0fb-2500-0000-bf75-a827ce140000 pid=5326 execve 36b1b8f9-982a-5d21-ae66-55c270ae0d99 176.65.139.80:80 guuid=c7a2e1b3-1600-0000-bf75-a827410e0000 pid=3649->36b1b8f9-982a-5d21-ae66-55c270ae0d99 send: 197B guuid=9d7856bb-1600-0000-bf75-a8274b0e0000 pid=3659->36b1b8f9-982a-5d21-ae66-55c270ae0d99 send: 146B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=974e9ec6-1600-0000-bf75-a827590e0000 pid=3673->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675 /tmp/76d32be0 dns net send-data zombie guuid=974e9ec6-1600-0000-bf75-a827590e0000 pid=3673->guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675 clone guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B 2ac2249c-25bc-5019-a88f-33a6c2731b07 cnc.504.su:56999 guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 16B guuid=7d33d2c6-1600-0000-bf75-a8275c0e0000 pid=3676 /tmp/76d32be0 guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->guuid=7d33d2c6-1600-0000-bf75-a8275c0e0000 pid=3676 clone guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677 /tmp/76d32be0 net net-scan send-data guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677 clone guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678 /tmp/76d32be0 net net-scan send-data guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678 clone guuid=85a7e2c6-1600-0000-bf75-a827600e0000 pid=3680 /tmp/76d32be0 guuid=2d0cc3c6-1600-0000-bf75-a8275b0e0000 pid=3675->guuid=85a7e2c6-1600-0000-bf75-a827600e0000 pid=3680 clone guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677|send-data send-data to 384 IP addresses review logs to see them all guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677->guuid=e970d7c6-1600-0000-bf75-a8275d0e0000 pid=3677|send-data send guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678|send-data send-data to 320 IP addresses review logs to see them all guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678->guuid=1276dbc6-1600-0000-bf75-a8275e0e0000 pid=3678|send-data send 4bcd05e0-7ebf-53bb-9cc8-c008d3256770 cnc.504.su:80 guuid=c7bce1c6-1600-0000-bf75-a8275f0e0000 pid=3679->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 198B guuid=373b3cd3-1600-0000-bf75-a8277a0e0000 pid=3706->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 147B guuid=b2963fdd-1600-0000-bf75-a827a80e0000 pid=3752->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5fbefa0b-74db-5ddb-909f-7c8f89ca1384 0.0.0.0:46157 guuid=b2963fdd-1600-0000-bf75-a827a80e0000 pid=3752->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726 /tmp/76d32be0 dns net send-data zombie guuid=b2963fdd-1600-0000-bf75-a827a80e0000 pid=3752->guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726 clone guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 16B guuid=a197760e-1800-0000-bf75-a82778120000 pid=4728 /tmp/76d32be0 guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->guuid=a197760e-1800-0000-bf75-a82778120000 pid=4728 clone guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729 /tmp/76d32be0 net net-scan send-data guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729 clone guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730 /tmp/76d32be0 net net-scan send-data guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730 clone guuid=af4f810e-1800-0000-bf75-a8277b120000 pid=4731 /tmp/76d32be0 guuid=a5716a0e-1800-0000-bf75-a82776120000 pid=4726->guuid=af4f810e-1800-0000-bf75-a8277b120000 pid=4731 clone guuid=f39c730e-1800-0000-bf75-a82777120000 pid=4727->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 198B guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729|send-data send-data to 384 IP addresses review logs to see them all guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729->guuid=98af790e-1800-0000-bf75-a82779120000 pid=4729|send-data send guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730|send-data send-data to 320 IP addresses review logs to see them all guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730->guuid=ab657d0e-1800-0000-bf75-a8277a120000 pid=4730|send-data send guuid=11be6e17-1800-0000-bf75-a82799120000 pid=4761->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 147B guuid=f5397c1d-1800-0000-bf75-a827b4120000 pid=4788->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f5397c1d-1800-0000-bf75-a827b4120000 pid=4788->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248 /tmp/76d32be0 dns net send-data zombie guuid=f5397c1d-1800-0000-bf75-a827b4120000 pid=4788->guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248 clone guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 16B guuid=cfc99250-1900-0000-bf75-a82782140000 pid=5250 /tmp/76d32be0 guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->guuid=cfc99250-1900-0000-bf75-a82782140000 pid=5250 clone guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251 /tmp/76d32be0 net net-scan send-data guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251 clone guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252 /tmp/76d32be0 net net-scan send-data guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252 clone guuid=2804a250-1900-0000-bf75-a82785140000 pid=5253 /tmp/76d32be0 guuid=d98d6250-1900-0000-bf75-a82780140000 pid=5248->guuid=2804a250-1900-0000-bf75-a82785140000 pid=5253 clone guuid=e75c7c50-1900-0000-bf75-a82781140000 pid=5249->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 197B guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251|send-data send-data to 384 IP addresses review logs to see them all guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251->guuid=38d09950-1900-0000-bf75-a82783140000 pid=5251|send-data send guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252|send-data send-data to 320 IP addresses review logs to see them all guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252->guuid=e3e69d50-1900-0000-bf75-a82784140000 pid=5252|send-data send guuid=1a828e5a-1900-0000-bf75-a82786140000 pid=5254->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 146B guuid=278f7d62-1900-0000-bf75-a82789140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=278f7d62-1900-0000-bf75-a82789140000 pid=5257->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265 /tmp/76d32be0 dns net send-data zombie guuid=278f7d62-1900-0000-bf75-a82789140000 pid=5257->guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265 clone guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->2ac2249c-25bc-5019-a88f-33a6c2731b07 con guuid=b6665095-1a00-0000-bf75-a82793140000 pid=5267 /tmp/76d32be0 guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->guuid=b6665095-1a00-0000-bf75-a82793140000 pid=5267 clone guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268 /tmp/76d32be0 net net-scan send-data zombie guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268 clone guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269 /tmp/76d32be0 net net-scan send-data zombie guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269 clone guuid=97665e95-1a00-0000-bf75-a82796140000 pid=5270 /tmp/76d32be0 guuid=5a344095-1a00-0000-bf75-a82791140000 pid=5265->guuid=97665e95-1a00-0000-bf75-a82796140000 pid=5270 clone guuid=8c4a4c95-1a00-0000-bf75-a82792140000 pid=5266->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268|send-data send-data to 4097 IP addresses review logs to see them all guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268->guuid=15965495-1a00-0000-bf75-a82794140000 pid=5268|send-data send guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269|send-data send-data to 4097 IP addresses review logs to see them all guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269->guuid=25535995-1a00-0000-bf75-a82795140000 pid=5269|send-data send guuid=34a21098-1a00-0000-bf75-a82797140000 pid=5271->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=528bc29b-1a00-0000-bf75-a8279a140000 pid=5274->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=528bc29b-1a00-0000-bf75-a8279a140000 pid=5274->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307 /tmp/76d32be0 net send-data zombie guuid=528bc29b-1a00-0000-bf75-a8279a140000 pid=5274->guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307 clone guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B guuid=c6b43a46-2000-0000-bf75-a827bc140000 pid=5308 /tmp/76d32be0 guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307->guuid=c6b43a46-2000-0000-bf75-a827bc140000 pid=5308 clone guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310 /tmp/76d32be0 net net-scan send-data zombie guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307->guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310 clone guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311 /tmp/76d32be0 net net-scan send-data zombie guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307->guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311 clone guuid=8c0b4c46-2000-0000-bf75-a827c0140000 pid=5312 /tmp/76d32be0 guuid=8af32c46-2000-0000-bf75-a827bb140000 pid=5307->guuid=8c0b4c46-2000-0000-bf75-a827c0140000 pid=5312 clone guuid=3b063c46-2000-0000-bf75-a827bd140000 pid=5309->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310|send-data send-data to 4097 IP addresses review logs to see them all guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310->guuid=c7534346-2000-0000-bf75-a827be140000 pid=5310|send-data send guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311|send-data send-data to 4095 IP addresses review logs to see them all guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311->guuid=d5084846-2000-0000-bf75-a827bf140000 pid=5311|send-data send guuid=a338aa48-2000-0000-bf75-a827c1140000 pid=5313->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=1ce5ec4c-2000-0000-bf75-a827c4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1ce5ec4c-2000-0000-bf75-a827c4140000 pid=5316->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317 /tmp/76d32be0 net send-data zombie guuid=1ce5ec4c-2000-0000-bf75-a827c4140000 pid=5316->guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317 clone guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=d7d384f6-2500-0000-bf75-a827c6140000 pid=5318 /tmp/76d32be0 guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317->guuid=d7d384f6-2500-0000-bf75-a827c6140000 pid=5318 clone guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320 /tmp/76d32be0 net net-scan send-data guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317->guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320 clone guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321 /tmp/76d32be0 net net-scan send-data guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317->guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321 clone guuid=eb1491f6-2500-0000-bf75-a827ca140000 pid=5322 /tmp/76d32be0 guuid=741f78f6-2500-0000-bf75-a827c5140000 pid=5317->guuid=eb1491f6-2500-0000-bf75-a827ca140000 pid=5322 clone guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320|send-data send-data to 1920 IP addresses review logs to see them all guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320->guuid=669989f6-2500-0000-bf75-a827c8140000 pid=5320|send-data send guuid=2c9c89f6-2500-0000-bf75-a827c7140000 pid=5319->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321|send-data send-data to 1600 IP addresses review logs to see them all guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321->guuid=98098df6-2500-0000-bf75-a827c9140000 pid=5321|send-data send guuid=1c6109f8-2500-0000-bf75-a827cb140000 pid=5323->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=6233a0fb-2500-0000-bf75-a827ce140000 pid=5326->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6233a0fb-2500-0000-bf75-a827ce140000 pid=5326->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-27 23:14:17 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:unstable antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (64130) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
cnc.504.su
scan.504.su
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1fd6d68852a93148e8d04ac6089fda742ac5ffc4d326b3dba5e4884b3b0bd3a0

(this sample)

  
Delivery method
Distributed via web download

Comments