MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 284c708064162876e9f9a7dab75649fcf02c7b991bc296ee1f737428e940208f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 284c708064162876e9f9a7dab75649fcf02c7b991bc296ee1f737428e940208f
SHA3-384 hash: 9356f9e705c5d68c97e0c1f2ea2add2cb6ec3727c6ed09faeb14f80a719213db3b9173f76081fbff0573b543e649fd37
SHA1 hash: 8ce6c33fd5e8bed0858cce7dfde31f7980fcfd81
MD5 hash: 738c381fedc7b69e0d8e968e94705045
humanhash: red-echo-november-early
File name:hnap
Download: download sample
Signature Mirai
File size:4'816 bytes
First seen:2025-11-24 22:17:56 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vUhMV4kRWUq1V4NWUrHrWV44WUNoV4yWUEpEEV4E2WUJkV4WWUq1V4NWUOZV4JWR:vbCpjPmLKzOEprboZ3b1DWjA1FDRDYRK
TLSH T157A10AE674B4977A6DB0ED7375D6C652B14061AAE0D68C0BF2D1F0EC084EF61F494B82
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mipsn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.mpsln/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.armn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm5n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm6n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arm7n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.ppcn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.m68kn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.spcn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.i686n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.sh4n/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.arcn/an/an/a
http://158.94.210.88/596a96cc7bf9108cd896f33c44aedc8a/db0fa4b8db0333367e9bda3ab68b8042.x86_64n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
medusa mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=7d80bfba-1600-0000-48a4-47ec9c0c0000 pid=3228 /usr/bin/sudo guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235 /tmp/sample.bin guuid=7d80bfba-1600-0000-48a4-47ec9c0c0000 pid=3228->guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235 execve guuid=50ce30bd-1600-0000-48a4-47eca50c0000 pid=3237 /usr/bin/wget net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=50ce30bd-1600-0000-48a4-47eca50c0000 pid=3237 execve guuid=b547fcc7-1600-0000-48a4-47ecad0c0000 pid=3245 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=b547fcc7-1600-0000-48a4-47ecad0c0000 pid=3245 execve guuid=91574ed7-1600-0000-48a4-47eccc0c0000 pid=3276 /usr/bin/cat guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=91574ed7-1600-0000-48a4-47eccc0c0000 pid=3276 execve guuid=9a539fd7-1600-0000-48a4-47eccd0c0000 pid=3277 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=9a539fd7-1600-0000-48a4-47eccd0c0000 pid=3277 execve guuid=e85ae7d7-1600-0000-48a4-47eccf0c0000 pid=3279 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=e85ae7d7-1600-0000-48a4-47eccf0c0000 pid=3279 execve guuid=8d6f43d8-1600-0000-48a4-47ecd40c0000 pid=3284 /usr/bin/wget net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=8d6f43d8-1600-0000-48a4-47ecd40c0000 pid=3284 execve guuid=d507fbe4-1600-0000-48a4-47ece30c0000 pid=3299 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=d507fbe4-1600-0000-48a4-47ece30c0000 pid=3299 execve guuid=d50f4cf0-1600-0000-48a4-47ecf70c0000 pid=3319 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=d50f4cf0-1600-0000-48a4-47ecf70c0000 pid=3319 clone guuid=c8ec8af0-1600-0000-48a4-47ecf90c0000 pid=3321 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=c8ec8af0-1600-0000-48a4-47ecf90c0000 pid=3321 execve guuid=0d3d02f1-1600-0000-48a4-47ecfb0c0000 pid=3323 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=0d3d02f1-1600-0000-48a4-47ecfb0c0000 pid=3323 execve guuid=9075a521-1800-0000-48a4-47ec4e0f0000 pid=3918 /usr/bin/wget net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=9075a521-1800-0000-48a4-47ec4e0f0000 pid=3918 execve guuid=6597be2c-1800-0000-48a4-47ec7a0f0000 pid=3962 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=6597be2c-1800-0000-48a4-47ec7a0f0000 pid=3962 execve guuid=36c86739-1800-0000-48a4-47ecae0f0000 pid=4014 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=36c86739-1800-0000-48a4-47ecae0f0000 pid=4014 clone guuid=21339239-1800-0000-48a4-47ecaf0f0000 pid=4015 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=21339239-1800-0000-48a4-47ecaf0f0000 pid=4015 execve guuid=b8a8e139-1800-0000-48a4-47ecb20f0000 pid=4018 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=b8a8e139-1800-0000-48a4-47ecb20f0000 pid=4018 execve guuid=bd007c6b-1900-0000-48a4-47ec7f120000 pid=4735 /usr/bin/wget net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=bd007c6b-1900-0000-48a4-47ec7f120000 pid=4735 execve guuid=fa76f777-1900-0000-48a4-47ec94120000 pid=4756 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=fa76f777-1900-0000-48a4-47ec94120000 pid=4756 execve guuid=ccd2db85-1900-0000-48a4-47ecc4120000 pid=4804 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=ccd2db85-1900-0000-48a4-47ecc4120000 pid=4804 clone guuid=ed6b2686-1900-0000-48a4-47ecc6120000 pid=4806 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=ed6b2686-1900-0000-48a4-47ecc6120000 pid=4806 execve guuid=64590c87-1900-0000-48a4-47ecca120000 pid=4810 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=64590c87-1900-0000-48a4-47ecca120000 pid=4810 execve guuid=a6f7abba-1a00-0000-48a4-47ec7e140000 pid=5246 /usr/bin/wget net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=a6f7abba-1a00-0000-48a4-47ec7e140000 pid=5246 execve guuid=ef1470bd-1a00-0000-48a4-47ec82140000 pid=5250 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=ef1470bd-1a00-0000-48a4-47ec82140000 pid=5250 execve guuid=8b6889ca-1a00-0000-48a4-47ec83140000 pid=5251 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=8b6889ca-1a00-0000-48a4-47ec83140000 pid=5251 clone guuid=2708bdca-1a00-0000-48a4-47ec84140000 pid=5252 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=2708bdca-1a00-0000-48a4-47ec84140000 pid=5252 execve guuid=88cd78cb-1a00-0000-48a4-47ec85140000 pid=5253 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=88cd78cb-1a00-0000-48a4-47ec85140000 pid=5253 execve guuid=daf67501-1c00-0000-48a4-47ec9b140000 pid=5275 /usr/bin/wget net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=daf67501-1c00-0000-48a4-47ec9b140000 pid=5275 execve guuid=44e4dc03-1c00-0000-48a4-47ec9f140000 pid=5279 /usr/bin/curl net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=44e4dc03-1c00-0000-48a4-47ec9f140000 pid=5279 execve guuid=8841dc05-1c00-0000-48a4-47eca0140000 pid=5280 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=8841dc05-1c00-0000-48a4-47eca0140000 pid=5280 clone guuid=5970f505-1c00-0000-48a4-47eca1140000 pid=5281 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=5970f505-1c00-0000-48a4-47eca1140000 pid=5281 execve guuid=a8108606-1c00-0000-48a4-47eca2140000 pid=5282 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=a8108606-1c00-0000-48a4-47eca2140000 pid=5282 execve guuid=91cd063d-1d00-0000-48a4-47ecb8140000 pid=5304 /usr/bin/wget net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=91cd063d-1d00-0000-48a4-47ecb8140000 pid=5304 execve guuid=7d4f953f-1d00-0000-48a4-47ecbb140000 pid=5307 /usr/bin/curl net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=7d4f953f-1d00-0000-48a4-47ecbb140000 pid=5307 execve guuid=b77f1b42-1d00-0000-48a4-47ecbc140000 pid=5308 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=b77f1b42-1d00-0000-48a4-47ecbc140000 pid=5308 clone guuid=74f13e42-1d00-0000-48a4-47ecbd140000 pid=5309 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=74f13e42-1d00-0000-48a4-47ecbd140000 pid=5309 execve guuid=5663f542-1d00-0000-48a4-47ecbe140000 pid=5310 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=5663f542-1d00-0000-48a4-47ecbe140000 pid=5310 execve guuid=f86a6487-2100-0000-48a4-47ecc1140000 pid=5313 /usr/bin/wget net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=f86a6487-2100-0000-48a4-47ecc1140000 pid=5313 execve guuid=92791f89-2100-0000-48a4-47ecc4140000 pid=5316 /usr/bin/curl net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=92791f89-2100-0000-48a4-47ecc4140000 pid=5316 execve guuid=945a6e8d-2100-0000-48a4-47ecc5140000 pid=5317 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=945a6e8d-2100-0000-48a4-47ecc5140000 pid=5317 clone guuid=f12b8e8d-2100-0000-48a4-47ecc6140000 pid=5318 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=f12b8e8d-2100-0000-48a4-47ecc6140000 pid=5318 execve guuid=44e2ef8d-2100-0000-48a4-47ecc7140000 pid=5319 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=44e2ef8d-2100-0000-48a4-47ecc7140000 pid=5319 execve guuid=51a23dd0-2500-0000-48a4-47ecca140000 pid=5322 /usr/bin/wget net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=51a23dd0-2500-0000-48a4-47ecca140000 pid=5322 execve guuid=50341ed2-2500-0000-48a4-47eccd140000 pid=5325 /usr/bin/curl net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=50341ed2-2500-0000-48a4-47eccd140000 pid=5325 execve guuid=f5c3d9d4-2500-0000-48a4-47ecce140000 pid=5326 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=f5c3d9d4-2500-0000-48a4-47ecce140000 pid=5326 clone guuid=1006f6d4-2500-0000-48a4-47eccf140000 pid=5327 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=1006f6d4-2500-0000-48a4-47eccf140000 pid=5327 execve guuid=09b03cd5-2500-0000-48a4-47ecd0140000 pid=5328 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=09b03cd5-2500-0000-48a4-47ecd0140000 pid=5328 execve guuid=020b4f12-2a00-0000-48a4-47ecd4140000 pid=5332 /usr/bin/wget net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=020b4f12-2a00-0000-48a4-47ecd4140000 pid=5332 execve guuid=03162d22-2a00-0000-48a4-47ecd8140000 pid=5336 /usr/bin/curl net send-data write-file guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=03162d22-2a00-0000-48a4-47ecd8140000 pid=5336 execve guuid=9daf0e34-2a00-0000-48a4-47ece1140000 pid=5345 /usr/bin/bash guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=9daf0e34-2a00-0000-48a4-47ece1140000 pid=5345 clone guuid=a2622c34-2a00-0000-48a4-47ece2140000 pid=5346 /usr/bin/chmod guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=a2622c34-2a00-0000-48a4-47ece2140000 pid=5346 execve guuid=dcb27d34-2a00-0000-48a4-47ece3140000 pid=5347 /tmp/76d32be0 net guuid=02e9d7bc-1600-0000-48a4-47eca30c0000 pid=3235->guuid=dcb27d34-2a00-0000-48a4-47ece3140000 pid=5347 execve 28ee2c59-94a6-5756-a2b6-fa7fcfec6d46 158.94.210.88:80 guuid=50ce30bd-1600-0000-48a4-47eca50c0000 pid=3237->28ee2c59-94a6-5756-a2b6-fa7fcfec6d46 send: 197B guuid=b547fcc7-1600-0000-48a4-47ecad0c0000 pid=3245->28ee2c59-94a6-5756-a2b6-fa7fcfec6d46 send: 146B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e85ae7d7-1600-0000-48a4-47eccf0c0000 pid=3279->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280 /tmp/76d32be0 dns net send-data zombie guuid=e85ae7d7-1600-0000-48a4-47eccf0c0000 pid=3279->guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280 clone guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B 2ac2249c-25bc-5019-a88f-33a6c2731b07 cnc.504.su:56999 guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 34B guuid=11d42fd8-1600-0000-48a4-47ecd10c0000 pid=3281 /tmp/76d32be0 guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280->guuid=11d42fd8-1600-0000-48a4-47ecd10c0000 pid=3281 clone guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282 /tmp/76d32be0 net net-scan send-data guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280->guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282 clone guuid=d86836d8-1600-0000-48a4-47ecd30c0000 pid=3283 /tmp/76d32be0 guuid=f15324d8-1600-0000-48a4-47ecd00c0000 pid=3280->guuid=d86836d8-1600-0000-48a4-47ecd30c0000 pid=3283 clone guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282|send-data send-data to 384 IP addresses review logs to see them all guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282->guuid=5b9d32d8-1600-0000-48a4-47ecd20c0000 pid=3282|send-data send 4bcd05e0-7ebf-53bb-9cc8-c008d3256770 cnc.504.su:80 guuid=8d6f43d8-1600-0000-48a4-47ecd40c0000 pid=3284->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 198B guuid=d507fbe4-1600-0000-48a4-47ece30c0000 pid=3299->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 147B guuid=0d3d02f1-1600-0000-48a4-47ecfb0c0000 pid=3323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5fbefa0b-74db-5ddb-909f-7c8f89ca1384 0.0.0.0:46157 guuid=0d3d02f1-1600-0000-48a4-47ecfb0c0000 pid=3323->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917 /tmp/76d32be0 dns net send-data zombie guuid=0d3d02f1-1600-0000-48a4-47ecfb0c0000 pid=3323->guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917 clone guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 17B guuid=1f71a821-1800-0000-48a4-47ec4f0f0000 pid=3919 /tmp/76d32be0 guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917->guuid=1f71a821-1800-0000-48a4-47ec4f0f0000 pid=3919 clone guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920 /tmp/76d32be0 net net-scan send-data guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917->guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920 clone guuid=fa66b321-1800-0000-48a4-47ec520f0000 pid=3922 /tmp/76d32be0 guuid=7a799d21-1800-0000-48a4-47ec4d0f0000 pid=3917->guuid=fa66b321-1800-0000-48a4-47ec520f0000 pid=3922 clone guuid=9075a521-1800-0000-48a4-47ec4e0f0000 pid=3918->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 198B guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920|send-data send-data to 384 IP addresses review logs to see them all guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920->guuid=55c6ad21-1800-0000-48a4-47ec500f0000 pid=3920|send-data send guuid=6597be2c-1800-0000-48a4-47ec7a0f0000 pid=3962->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 147B guuid=b8a8e139-1800-0000-48a4-47ecb20f0000 pid=4018->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b8a8e139-1800-0000-48a4-47ecb20f0000 pid=4018->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732 /tmp/76d32be0 dns net send-data zombie guuid=b8a8e139-1800-0000-48a4-47ecb20f0000 pid=4018->guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732 clone guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 17B guuid=553a7a6b-1900-0000-48a4-47ec7d120000 pid=4733 /tmp/76d32be0 guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732->guuid=553a7a6b-1900-0000-48a4-47ec7d120000 pid=4733 clone guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736 /tmp/76d32be0 net net-scan send-data guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732->guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736 clone guuid=b10e826b-1900-0000-48a4-47ec81120000 pid=4737 /tmp/76d32be0 guuid=99b16c6b-1900-0000-48a4-47ec7c120000 pid=4732->guuid=b10e826b-1900-0000-48a4-47ec81120000 pid=4737 clone guuid=bd007c6b-1900-0000-48a4-47ec7f120000 pid=4735->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 197B guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736|send-data send-data to 384 IP addresses review logs to see them all guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736->guuid=f8d57d6b-1900-0000-48a4-47ec80120000 pid=4736|send-data send guuid=fa76f777-1900-0000-48a4-47ec94120000 pid=4756->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 146B guuid=64590c87-1900-0000-48a4-47ecca120000 pid=4810->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=64590c87-1900-0000-48a4-47ecca120000 pid=4810->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245 /tmp/76d32be0 dns net send-data zombie guuid=64590c87-1900-0000-48a4-47ecca120000 pid=4810->guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245 clone guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 34B guuid=1b42adba-1a00-0000-48a4-47ec7f140000 pid=5247 /tmp/76d32be0 guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245->guuid=1b42adba-1a00-0000-48a4-47ec7f140000 pid=5247 clone guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248 /tmp/76d32be0 net net-scan send-data guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245->guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248 clone guuid=9aa7b6ba-1a00-0000-48a4-47ec81140000 pid=5249 /tmp/76d32be0 guuid=cc09a1ba-1a00-0000-48a4-47ec7d140000 pid=5245->guuid=9aa7b6ba-1a00-0000-48a4-47ec81140000 pid=5249 clone guuid=a6f7abba-1a00-0000-48a4-47ec7e140000 pid=5246->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248|send-data send-data to 384 IP addresses review logs to see them all guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248->guuid=a2fab0ba-1a00-0000-48a4-47ec80140000 pid=5248|send-data send guuid=ef1470bd-1a00-0000-48a4-47ec82140000 pid=5250->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 147B guuid=88cd78cb-1a00-0000-48a4-47ec85140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=88cd78cb-1a00-0000-48a4-47ec85140000 pid=5253->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274 /tmp/76d32be0 dns net send-data zombie guuid=88cd78cb-1a00-0000-48a4-47ec85140000 pid=5253->guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274 clone guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274->2ac2249c-25bc-5019-a88f-33a6c2731b07 con guuid=94b67601-1c00-0000-48a4-47ec9c140000 pid=5276 /tmp/76d32be0 guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274->guuid=94b67601-1c00-0000-48a4-47ec9c140000 pid=5276 clone guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277 /tmp/76d32be0 net net-scan send-data guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274->guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277 clone guuid=40d78001-1c00-0000-48a4-47ec9e140000 pid=5278 /tmp/76d32be0 guuid=d6cd6b01-1c00-0000-48a4-47ec9a140000 pid=5274->guuid=40d78001-1c00-0000-48a4-47ec9e140000 pid=5278 clone guuid=daf67501-1c00-0000-48a4-47ec9b140000 pid=5275->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277|send-data send-data to 384 IP addresses review logs to see them all guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277->guuid=259c7901-1c00-0000-48a4-47ec9d140000 pid=5277|send-data send guuid=44e4dc03-1c00-0000-48a4-47ec9f140000 pid=5279->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=a8108606-1c00-0000-48a4-47eca2140000 pid=5282->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a8108606-1c00-0000-48a4-47eca2140000 pid=5282->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302 /tmp/76d32be0 dns net send-data zombie guuid=a8108606-1c00-0000-48a4-47eca2140000 pid=5282->guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302 clone guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302->2ac2249c-25bc-5019-a88f-33a6c2731b07 con guuid=09b9053d-1d00-0000-48a4-47ecb7140000 pid=5303 /tmp/76d32be0 guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302->guuid=09b9053d-1d00-0000-48a4-47ecb7140000 pid=5303 clone guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305 /tmp/76d32be0 net net-scan send-data zombie guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302->guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305 clone guuid=e2ae0e3d-1d00-0000-48a4-47ecba140000 pid=5306 /tmp/76d32be0 guuid=fc12f83c-1d00-0000-48a4-47ecb6140000 pid=5302->guuid=e2ae0e3d-1d00-0000-48a4-47ecba140000 pid=5306 clone guuid=91cd063d-1d00-0000-48a4-47ecb8140000 pid=5304->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305|send-data send-data to 4097 IP addresses review logs to see them all guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305->guuid=32470a3d-1d00-0000-48a4-47ecb9140000 pid=5305|send-data send guuid=7d4f953f-1d00-0000-48a4-47ecbb140000 pid=5307->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=5663f542-1d00-0000-48a4-47ecbe140000 pid=5310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5663f542-1d00-0000-48a4-47ecbe140000 pid=5310->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311 /tmp/76d32be0 dns net send-data zombie guuid=5663f542-1d00-0000-48a4-47ecbe140000 pid=5310->guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311 clone guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 28B guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311->2ac2249c-25bc-5019-a88f-33a6c2731b07 con guuid=94da5e87-2100-0000-48a4-47ecc0140000 pid=5312 /tmp/76d32be0 guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311->guuid=94da5e87-2100-0000-48a4-47ecc0140000 pid=5312 clone guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314 /tmp/76d32be0 net net-scan send-data zombie guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311->guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314 clone guuid=3cbd7587-2100-0000-48a4-47ecc3140000 pid=5315 /tmp/76d32be0 guuid=5a8b4587-2100-0000-48a4-47ecbf140000 pid=5311->guuid=3cbd7587-2100-0000-48a4-47ecc3140000 pid=5315 clone guuid=f86a6487-2100-0000-48a4-47ecc1140000 pid=5313->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314|send-data send-data to 4097 IP addresses review logs to see them all guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314->guuid=4bf06b87-2100-0000-48a4-47ecc2140000 pid=5314|send-data send guuid=92791f89-2100-0000-48a4-47ecc4140000 pid=5316->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=44e2ef8d-2100-0000-48a4-47ecc7140000 pid=5319->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=44e2ef8d-2100-0000-48a4-47ecc7140000 pid=5319->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320 /tmp/76d32be0 net send-data zombie guuid=44e2ef8d-2100-0000-48a4-47ecc7140000 pid=5319->guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320 clone guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B guuid=1d7c3cd0-2500-0000-48a4-47ecc9140000 pid=5321 /tmp/76d32be0 guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320->guuid=1d7c3cd0-2500-0000-48a4-47ecc9140000 pid=5321 clone guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323 /tmp/76d32be0 net net-scan send-data zombie guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320->guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323 clone guuid=430745d0-2500-0000-48a4-47eccc140000 pid=5324 /tmp/76d32be0 guuid=312729d0-2500-0000-48a4-47ecc8140000 pid=5320->guuid=430745d0-2500-0000-48a4-47eccc140000 pid=5324 clone guuid=51a23dd0-2500-0000-48a4-47ecca140000 pid=5322->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323|send-data send-data to 4097 IP addresses review logs to see them all guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323->guuid=b29d40d0-2500-0000-48a4-47eccb140000 pid=5323|send-data send guuid=50341ed2-2500-0000-48a4-47eccd140000 pid=5325->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 con guuid=09b03cd5-2500-0000-48a4-47ecd0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=09b03cd5-2500-0000-48a4-47ecd0140000 pid=5328->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331 /tmp/76d32be0 dns net send-data zombie guuid=09b03cd5-2500-0000-48a4-47ecd0140000 pid=5328->guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331 clone guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 56B guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331->2ac2249c-25bc-5019-a88f-33a6c2731b07 send: 34B guuid=fd3c5012-2a00-0000-48a4-47ecd5140000 pid=5333 /tmp/76d32be0 guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331->guuid=fd3c5012-2a00-0000-48a4-47ecd5140000 pid=5333 clone guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334 /tmp/76d32be0 net net-scan send-data guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331->guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334 clone guuid=8a856212-2a00-0000-48a4-47ecd7140000 pid=5335 /tmp/76d32be0 guuid=49d23912-2a00-0000-48a4-47ecd3140000 pid=5331->guuid=8a856212-2a00-0000-48a4-47ecd7140000 pid=5335 clone guuid=020b4f12-2a00-0000-48a4-47ecd4140000 pid=5332->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 197B guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334|send-data send-data to 384 IP addresses review logs to see them all guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334->guuid=2c685a12-2a00-0000-48a4-47ecd6140000 pid=5334|send-data send guuid=03162d22-2a00-0000-48a4-47ecd8140000 pid=5336->4bcd05e0-7ebf-53bb-9cc8-c008d3256770 send: 146B guuid=dcb27d34-2a00-0000-48a4-47ece3140000 pid=5347->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dcb27d34-2a00-0000-48a4-47ece3140000 pid=5347->5fbefa0b-74db-5ddb-909f-7c8f89ca1384 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-24 22:18:25 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:unstable antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (55301) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
cnc.504.su
scan.504.su
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 284c708064162876e9f9a7dab75649fcf02c7b991bc296ee1f737428e940208f

(this sample)

  
Delivery method
Distributed via web download

Comments