MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 37416a2cd23dcd8044f35b73a430acf96d59b7dec5b1a3b937da27bcfb6f5217. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 37416a2cd23dcd8044f35b73a430acf96d59b7dec5b1a3b937da27bcfb6f5217
SHA3-384 hash: 14db6cb40a804648d4519102ba1ad50c2e5f984869913deb1159495dbdf02e15773ca08a3a12b6a41dc8996a109a4d01
SHA1 hash: 5505e5f19147e5c9797f613de0d491bc97c94147
MD5 hash: d67dcbe15c591a144b1a606793134c51
humanhash: montana-hot-diet-oregon
File name:1.sh
Download: download sample
Signature Mirai
File size:3'509 bytes
First seen:2025-10-08 18:27:15 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It+D4s+U/+xXV+sjb+mF8s+CQY+7h7vJ+3uC+SwCL+O8hO8NIuHks+W7WK6wCs+/:iEpu9xRwYGlBcPLUJu+TmMrw
TLSH T1E6713A8D20952B73185DEE36E26BE59733C78096E7CA4E56F8DC64A8405CE1C2740FCE
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://62.72.44.49/executorloveyou/executor.x864c8d84766919970863d17dc584456be71e4e83bd7e9a49c757abc90f169382b7 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.mips4f926dbbcb5cde583b0219c0cc7c7b044b3d63d3706b7859b0761739e1206dbd Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.arc72da919821739d45c7063f59bd40acf8d81484a79ebfbcc4a1917dfb14e2a080 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.i468n/an/aelf ua-wget
http://62.72.44.49/executorloveyou/executor.i686ecb681fd70fa7206daae04969c4dd68d0f8628954d21c840a0d1420436a00d89 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.x86_6461ec8368f202ae376de9147b2d6d9db7080dd7542524f85ce854b83fa274e8dd Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.mpsl94bf729a461aaa5ea64a1eac62e389c3e448310ede53019d3bd2fcaf982be876 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.arm8f34929c4a1ec3c340f19e8dd84db21dee6447b8ed95b6962af51340a453330d Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.arm50a6db04000d3c1326926aa00b84a6b6bca65d4a5e12947ae529fc2d4ac40db54 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.arm69e4690ae50d03eb950b5701e67675fe55c04bf140efb2644aa8825564967732b Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.arm74f3ae18842e9d5c3ef3cce9e195ddb8264d408d70a71a30799c3496aa4d3308f Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.ppcb99b9ead168d33cad6378710c8822cacec9b9c875a2c6b8e76af1b6410688960 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.spca364aab19883159f71e56fdddf9db3c0e887c959cb3a737c208e590ac5bea250 Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.m68k472d9575f4e50b95112b5f63761df4099fbf3f2c816eea0077c4afe90db56dad Miraimirai opendir
http://62.72.44.49/executorloveyou/executor.sh41d0b927a8ea35d87f944850fa51e9786e766f4465c1b8116c8aea9aec4a02622 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=c841df60-1a00-0000-aa3b-b43e370b0000 pid=2871 /usr/bin/sudo guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880 /tmp/sample.bin guuid=c841df60-1a00-0000-aa3b-b43e370b0000 pid=2871->guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880 execve guuid=0713ba63-1a00-0000-aa3b-b43e410b0000 pid=2881 /usr/bin/cp guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=0713ba63-1a00-0000-aa3b-b43e410b0000 pid=2881 execve guuid=6444e065-1a00-0000-aa3b-b43e490b0000 pid=2889 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=6444e065-1a00-0000-aa3b-b43e490b0000 pid=2889 execve guuid=35f86284-1a00-0000-aa3b-b43e800b0000 pid=2944 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=35f86284-1a00-0000-aa3b-b43e800b0000 pid=2944 execve guuid=c9f949a7-1a00-0000-aa3b-b43ec30b0000 pid=3011 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=c9f949a7-1a00-0000-aa3b-b43ec30b0000 pid=3011 execve guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012 /tmp/executor.x86 net guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012 execve guuid=1a8163d5-1b00-0000-aa3b-b43eb60d0000 pid=3510 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=1a8163d5-1b00-0000-aa3b-b43eb60d0000 pid=3510 execve guuid=3a619dd6-1b00-0000-aa3b-b43eb80d0000 pid=3512 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=3a619dd6-1b00-0000-aa3b-b43eb80d0000 pid=3512 execve guuid=3a565afd-1b00-0000-aa3b-b43e0b0e0000 pid=3595 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=3a565afd-1b00-0000-aa3b-b43e0b0e0000 pid=3595 execve guuid=cb80a926-1c00-0000-aa3b-b43e630e0000 pid=3683 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=cb80a926-1c00-0000-aa3b-b43e630e0000 pid=3683 execve guuid=9d190a27-1c00-0000-aa3b-b43e670e0000 pid=3687 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=9d190a27-1c00-0000-aa3b-b43e670e0000 pid=3687 clone guuid=3955fa27-1c00-0000-aa3b-b43e6c0e0000 pid=3692 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=3955fa27-1c00-0000-aa3b-b43e6c0e0000 pid=3692 execve guuid=33c5642b-1c00-0000-aa3b-b43e750e0000 pid=3701 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=33c5642b-1c00-0000-aa3b-b43e750e0000 pid=3701 execve guuid=b7b1265e-1c00-0000-aa3b-b43ef80e0000 pid=3832 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=b7b1265e-1c00-0000-aa3b-b43ef80e0000 pid=3832 execve guuid=ff96168f-1c00-0000-aa3b-b43e900f0000 pid=3984 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=ff96168f-1c00-0000-aa3b-b43e900f0000 pid=3984 execve guuid=65d1718f-1c00-0000-aa3b-b43e910f0000 pid=3985 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=65d1718f-1c00-0000-aa3b-b43e910f0000 pid=3985 clone guuid=bf8ec390-1c00-0000-aa3b-b43e970f0000 pid=3991 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=bf8ec390-1c00-0000-aa3b-b43e970f0000 pid=3991 execve guuid=2a270a96-1c00-0000-aa3b-b43ea50f0000 pid=4005 /usr/bin/wget net send-data guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=2a270a96-1c00-0000-aa3b-b43ea50f0000 pid=4005 execve guuid=7a5fb5aa-1c00-0000-aa3b-b43ee30f0000 pid=4067 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=7a5fb5aa-1c00-0000-aa3b-b43ee30f0000 pid=4067 execve guuid=539289c1-1c00-0000-aa3b-b43e26100000 pid=4134 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=539289c1-1c00-0000-aa3b-b43e26100000 pid=4134 execve guuid=8388cdc1-1c00-0000-aa3b-b43e28100000 pid=4136 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=8388cdc1-1c00-0000-aa3b-b43e28100000 pid=4136 clone guuid=f20ffdc1-1c00-0000-aa3b-b43e2a100000 pid=4138 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=f20ffdc1-1c00-0000-aa3b-b43e2a100000 pid=4138 execve guuid=52464ec2-1c00-0000-aa3b-b43e2e100000 pid=4142 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=52464ec2-1c00-0000-aa3b-b43e2e100000 pid=4142 execve guuid=885ee4df-1c00-0000-aa3b-b43e77100000 pid=4215 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=885ee4df-1c00-0000-aa3b-b43e77100000 pid=4215 execve guuid=6a8462ff-1c00-0000-aa3b-b43edf100000 pid=4319 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=6a8462ff-1c00-0000-aa3b-b43edf100000 pid=4319 execve guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320 /tmp/executor.i686 net guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320 execve guuid=17bfdc2c-1e00-0000-aa3b-b43e2a140000 pid=5162 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=17bfdc2c-1e00-0000-aa3b-b43e2a140000 pid=5162 execve guuid=29585391-1e00-0000-aa3b-b43e2c140000 pid=5164 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=29585391-1e00-0000-aa3b-b43e2c140000 pid=5164 execve guuid=66e772ae-1e00-0000-aa3b-b43e83140000 pid=5251 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=66e772ae-1e00-0000-aa3b-b43e83140000 pid=5251 execve guuid=6b8d96cc-1e00-0000-aa3b-b43e8f140000 pid=5263 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=6b8d96cc-1e00-0000-aa3b-b43e8f140000 pid=5263 execve guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264 /tmp/executor.x86_64 mprotect-exec net guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264 execve guuid=b8cbe1f7-1f00-0000-aa3b-b43e9d140000 pid=5277 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=b8cbe1f7-1f00-0000-aa3b-b43e9d140000 pid=5277 execve guuid=2f418d12-2000-0000-aa3b-b43e9e140000 pid=5278 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=2f418d12-2000-0000-aa3b-b43e9e140000 pid=5278 execve guuid=37b0d840-2000-0000-aa3b-b43e9f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=37b0d840-2000-0000-aa3b-b43e9f140000 pid=5279 execve guuid=a1d6536a-2000-0000-aa3b-b43ea0140000 pid=5280 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a1d6536a-2000-0000-aa3b-b43ea0140000 pid=5280 execve guuid=a0ed9f6a-2000-0000-aa3b-b43ea1140000 pid=5281 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a0ed9f6a-2000-0000-aa3b-b43ea1140000 pid=5281 clone guuid=15e94d6b-2000-0000-aa3b-b43ea3140000 pid=5283 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=15e94d6b-2000-0000-aa3b-b43ea3140000 pid=5283 execve guuid=448c946b-2000-0000-aa3b-b43ea4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=448c946b-2000-0000-aa3b-b43ea4140000 pid=5284 execve guuid=00b84288-2000-0000-aa3b-b43ea6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=00b84288-2000-0000-aa3b-b43ea6140000 pid=5286 execve guuid=1d9f97a6-2000-0000-aa3b-b43eac140000 pid=5292 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=1d9f97a6-2000-0000-aa3b-b43eac140000 pid=5292 execve guuid=f8ca19a7-2000-0000-aa3b-b43ead140000 pid=5293 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=f8ca19a7-2000-0000-aa3b-b43ead140000 pid=5293 clone guuid=6d4f37a8-2000-0000-aa3b-b43eaf140000 pid=5295 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=6d4f37a8-2000-0000-aa3b-b43eaf140000 pid=5295 execve guuid=0ff2a9a8-2000-0000-aa3b-b43eb0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=0ff2a9a8-2000-0000-aa3b-b43eb0140000 pid=5296 execve guuid=ed43e4c5-2000-0000-aa3b-b43eb8140000 pid=5304 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=ed43e4c5-2000-0000-aa3b-b43eb8140000 pid=5304 execve guuid=f6519de5-2000-0000-aa3b-b43ebc140000 pid=5308 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=f6519de5-2000-0000-aa3b-b43ebc140000 pid=5308 execve guuid=1d0df3e5-2000-0000-aa3b-b43ebd140000 pid=5309 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=1d0df3e5-2000-0000-aa3b-b43ebd140000 pid=5309 clone guuid=c02092e6-2000-0000-aa3b-b43ebf140000 pid=5311 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=c02092e6-2000-0000-aa3b-b43ebf140000 pid=5311 execve guuid=898233e7-2000-0000-aa3b-b43ec1140000 pid=5313 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=898233e7-2000-0000-aa3b-b43ec1140000 pid=5313 execve guuid=d038870d-2100-0000-aa3b-b43ed1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=d038870d-2100-0000-aa3b-b43ed1140000 pid=5329 execve guuid=bd46ca35-2100-0000-aa3b-b43ed2140000 pid=5330 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=bd46ca35-2100-0000-aa3b-b43ed2140000 pid=5330 execve guuid=c5515d36-2100-0000-aa3b-b43ed3140000 pid=5331 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=c5515d36-2100-0000-aa3b-b43ed3140000 pid=5331 clone guuid=49dc8e37-2100-0000-aa3b-b43ed5140000 pid=5333 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=49dc8e37-2100-0000-aa3b-b43ed5140000 pid=5333 execve guuid=a453813e-2100-0000-aa3b-b43ed6140000 pid=5334 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a453813e-2100-0000-aa3b-b43ed6140000 pid=5334 execve guuid=b534ca64-2100-0000-aa3b-b43ed7140000 pid=5335 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=b534ca64-2100-0000-aa3b-b43ed7140000 pid=5335 execve guuid=69dc99f8-2100-0000-aa3b-b43ed8140000 pid=5336 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=69dc99f8-2100-0000-aa3b-b43ed8140000 pid=5336 execve guuid=198f2af9-2100-0000-aa3b-b43ed9140000 pid=5337 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=198f2af9-2100-0000-aa3b-b43ed9140000 pid=5337 clone guuid=431477fa-2100-0000-aa3b-b43edb140000 pid=5339 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=431477fa-2100-0000-aa3b-b43edb140000 pid=5339 execve guuid=a22e10fb-2100-0000-aa3b-b43edc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a22e10fb-2100-0000-aa3b-b43edc140000 pid=5340 execve guuid=7b2b0c19-2200-0000-aa3b-b43edd140000 pid=5341 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=7b2b0c19-2200-0000-aa3b-b43edd140000 pid=5341 execve guuid=324de538-2200-0000-aa3b-b43ede140000 pid=5342 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=324de538-2200-0000-aa3b-b43ede140000 pid=5342 execve guuid=e0317439-2200-0000-aa3b-b43edf140000 pid=5343 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=e0317439-2200-0000-aa3b-b43edf140000 pid=5343 clone guuid=e68ba23a-2200-0000-aa3b-b43ee1140000 pid=5345 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=e68ba23a-2200-0000-aa3b-b43ee1140000 pid=5345 execve guuid=55193a3b-2200-0000-aa3b-b43ee2140000 pid=5346 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=55193a3b-2200-0000-aa3b-b43ee2140000 pid=5346 execve guuid=a7f8c261-2200-0000-aa3b-b43ee3140000 pid=5347 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a7f8c261-2200-0000-aa3b-b43ee3140000 pid=5347 execve guuid=a09ae78a-2200-0000-aa3b-b43ee4140000 pid=5348 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=a09ae78a-2200-0000-aa3b-b43ee4140000 pid=5348 execve guuid=74f8788b-2200-0000-aa3b-b43ee5140000 pid=5349 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=74f8788b-2200-0000-aa3b-b43ee5140000 pid=5349 clone guuid=372aa68c-2200-0000-aa3b-b43ee7140000 pid=5351 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=372aa68c-2200-0000-aa3b-b43ee7140000 pid=5351 execve guuid=64d8ce93-2200-0000-aa3b-b43ee8140000 pid=5352 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=64d8ce93-2200-0000-aa3b-b43ee8140000 pid=5352 execve guuid=e979afba-2200-0000-aa3b-b43ee9140000 pid=5353 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=e979afba-2200-0000-aa3b-b43ee9140000 pid=5353 execve guuid=3a0c96e2-2200-0000-aa3b-b43eea140000 pid=5354 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=3a0c96e2-2200-0000-aa3b-b43eea140000 pid=5354 execve guuid=9dda1fe3-2200-0000-aa3b-b43eeb140000 pid=5355 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=9dda1fe3-2200-0000-aa3b-b43eeb140000 pid=5355 clone guuid=d06655e4-2200-0000-aa3b-b43eed140000 pid=5357 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=d06655e4-2200-0000-aa3b-b43eed140000 pid=5357 execve guuid=d0e2e4e4-2200-0000-aa3b-b43eee140000 pid=5358 /usr/bin/wget net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=d0e2e4e4-2200-0000-aa3b-b43eee140000 pid=5358 execve guuid=7f11cf0b-2300-0000-aa3b-b43eef140000 pid=5359 /usr/bin/curl net send-data write-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=7f11cf0b-2300-0000-aa3b-b43eef140000 pid=5359 execve guuid=c6b53534-2300-0000-aa3b-b43ef0140000 pid=5360 /usr/bin/chmod guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=c6b53534-2300-0000-aa3b-b43ef0140000 pid=5360 execve guuid=0b8dca34-2300-0000-aa3b-b43ef1140000 pid=5361 /usr/bin/bash guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=0b8dca34-2300-0000-aa3b-b43ef1140000 pid=5361 clone guuid=fd0cf035-2300-0000-aa3b-b43ef3140000 pid=5363 /usr/bin/rm delete-file guuid=bf116663-1a00-0000-aa3b-b43e400b0000 pid=2880->guuid=fd0cf035-2300-0000-aa3b-b43ef3140000 pid=5363 execve 38b5e784-dc3c-5ac0-8d3b-f603e3aaca6d 62.72.44.49:80 guuid=6444e065-1a00-0000-aa3b-b43e490b0000 pid=2889->38b5e784-dc3c-5ac0-8d3b-f603e3aaca6d send: 154B guuid=35f86284-1a00-0000-aa3b-b43e800b0000 pid=2944->38b5e784-dc3c-5ac0-8d3b-f603e3aaca6d send: 103B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6a4766a8-1a00-0000-aa3b-b43ec50b0000 pid=3013 /tmp/executor.x86 guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012->guuid=6a4766a8-1a00-0000-aa3b-b43ec50b0000 pid=3013 clone guuid=e8ad4ad5-1b00-0000-aa3b-b43eb40d0000 pid=3508 /tmp/executor.x86 guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012->guuid=e8ad4ad5-1b00-0000-aa3b-b43eb40d0000 pid=3508 clone guuid=f07b51d5-1b00-0000-aa3b-b43eb50d0000 pid=3509 /tmp/executor.x86 net send-data zombie guuid=1727b8a7-1a00-0000-aa3b-b43ec40b0000 pid=3012->guuid=f07b51d5-1b00-0000-aa3b-b43eb50d0000 pid=3509 clone guuid=95aa70a8-1a00-0000-aa3b-b43ec60b0000 pid=3014 /tmp/executor.x86 guuid=6a4766a8-1a00-0000-aa3b-b43ec50b0000 pid=3013->guuid=95aa70a8-1a00-0000-aa3b-b43ec60b0000 pid=3014 clone guuid=478875a8-1a00-0000-aa3b-b43ec70b0000 pid=3015 /tmp/executor.x86 dns net send-data zombie guuid=6a4766a8-1a00-0000-aa3b-b43ec50b0000 pid=3013->guuid=478875a8-1a00-0000-aa3b-b43ec70b0000 pid=3015 clone guuid=478875a8-1a00-0000-aa3b-b43ec70b0000 pid=3015->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 141B 3b0e2bdf-914d-513d-bae2-b7313c839528 eagle1997.executorstresser.ru:69 guuid=478875a8-1a00-0000-aa3b-b43ec70b0000 pid=3015->3b0e2bdf-914d-513d-bae2-b7313c839528 send: 58B guuid=f07b51d5-1b00-0000-aa3b-b43eb50d0000 pid=3509->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1200B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=f07b51d5-1b00-0000-aa3b-b43eb50d0000 pid=3509->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B 95af1084-bb50-5e21-b268-bef6227a3a19 eagle1997.executorstresser.ru:80 guuid=3a619dd6-1b00-0000-aa3b-b43eb80d0000 pid=3512->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=3a565afd-1b00-0000-aa3b-b43e0b0e0000 pid=3595->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=33c5642b-1c00-0000-aa3b-b43e750e0000 pid=3701->95af1084-bb50-5e21-b268-bef6227a3a19 send: 154B guuid=b7b1265e-1c00-0000-aa3b-b43ef80e0000 pid=3832->95af1084-bb50-5e21-b268-bef6227a3a19 send: 103B guuid=2a270a96-1c00-0000-aa3b-b43ea50f0000 pid=4005->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=7a5fb5aa-1c00-0000-aa3b-b43ee30f0000 pid=4067->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=52464ec2-1c00-0000-aa3b-b43e2e100000 pid=4142->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=885ee4df-1c00-0000-aa3b-b43e77100000 pid=4215->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=66ec8100-1d00-0000-aa3b-b43ee3100000 pid=4323 /tmp/executor.i686 guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320->guuid=66ec8100-1d00-0000-aa3b-b43ee3100000 pid=4323 clone guuid=1b51c72c-1e00-0000-aa3b-b43e28140000 pid=5160 /tmp/executor.i686 guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320->guuid=1b51c72c-1e00-0000-aa3b-b43e28140000 pid=5160 clone guuid=478fcc2c-1e00-0000-aa3b-b43e29140000 pid=5161 /tmp/executor.i686 net send-data zombie guuid=edf7c2ff-1c00-0000-aa3b-b43ee0100000 pid=4320->guuid=478fcc2c-1e00-0000-aa3b-b43e29140000 pid=5161 clone guuid=24bf8700-1d00-0000-aa3b-b43ee5100000 pid=4325 /tmp/executor.i686 guuid=66ec8100-1d00-0000-aa3b-b43ee3100000 pid=4323->guuid=24bf8700-1d00-0000-aa3b-b43ee5100000 pid=4325 clone guuid=9f2f8d00-1d00-0000-aa3b-b43ee6100000 pid=4326 /tmp/executor.i686 dns net send-data zombie guuid=66ec8100-1d00-0000-aa3b-b43ee3100000 pid=4323->guuid=9f2f8d00-1d00-0000-aa3b-b43ee6100000 pid=4326 clone guuid=9f2f8d00-1d00-0000-aa3b-b43ee6100000 pid=4326->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 94B guuid=9f2f8d00-1d00-0000-aa3b-b43ee6100000 pid=4326->3b0e2bdf-914d-513d-bae2-b7313c839528 send: 40B guuid=478fcc2c-1e00-0000-aa3b-b43e29140000 pid=5161->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 960B guuid=478fcc2c-1e00-0000-aa3b-b43e29140000 pid=5161->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=29585391-1e00-0000-aa3b-b43e2c140000 pid=5164->95af1084-bb50-5e21-b268-bef6227a3a19 send: 157B guuid=66e772ae-1e00-0000-aa3b-b43e83140000 pid=5251->95af1084-bb50-5e21-b268-bef6227a3a19 send: 106B guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c7a154cd-1e00-0000-aa3b-b43e91140000 pid=5265 /tmp/executor.x86_64 guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264->guuid=c7a154cd-1e00-0000-aa3b-b43e91140000 pid=5265 clone guuid=5242bff7-1f00-0000-aa3b-b43e9b140000 pid=5275 /tmp/executor.x86_64 guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264->guuid=5242bff7-1f00-0000-aa3b-b43e9b140000 pid=5275 clone guuid=1a76ccf7-1f00-0000-aa3b-b43e9c140000 pid=5276 /tmp/executor.x86_64 net send-data zombie guuid=9b90e6cc-1e00-0000-aa3b-b43e90140000 pid=5264->guuid=1a76ccf7-1f00-0000-aa3b-b43e9c140000 pid=5276 clone guuid=9b445acd-1e00-0000-aa3b-b43e92140000 pid=5266 /tmp/executor.x86_64 guuid=c7a154cd-1e00-0000-aa3b-b43e91140000 pid=5265->guuid=9b445acd-1e00-0000-aa3b-b43e92140000 pid=5266 clone guuid=7e255ecd-1e00-0000-aa3b-b43e93140000 pid=5267 /tmp/executor.x86_64 net send-data zombie guuid=c7a154cd-1e00-0000-aa3b-b43e91140000 pid=5265->guuid=7e255ecd-1e00-0000-aa3b-b43e93140000 pid=5267 clone guuid=7e255ecd-1e00-0000-aa3b-b43e93140000 pid=5267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 940B guuid=7e255ecd-1e00-0000-aa3b-b43e93140000 pid=5267->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=1a76ccf7-1f00-0000-aa3b-b43e9c140000 pid=5276->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 960B guuid=1a76ccf7-1f00-0000-aa3b-b43e9c140000 pid=5276->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2f418d12-2000-0000-aa3b-b43e9e140000 pid=5278->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=37b0d840-2000-0000-aa3b-b43e9f140000 pid=5279->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=448c946b-2000-0000-aa3b-b43ea4140000 pid=5284->95af1084-bb50-5e21-b268-bef6227a3a19 send: 154B guuid=00b84288-2000-0000-aa3b-b43ea6140000 pid=5286->95af1084-bb50-5e21-b268-bef6227a3a19 send: 103B guuid=0ff2a9a8-2000-0000-aa3b-b43eb0140000 pid=5296->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=ed43e4c5-2000-0000-aa3b-b43eb8140000 pid=5304->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=898233e7-2000-0000-aa3b-b43ec1140000 pid=5313->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=d038870d-2100-0000-aa3b-b43ed1140000 pid=5329->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=a453813e-2100-0000-aa3b-b43ed6140000 pid=5334->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=b534ca64-2100-0000-aa3b-b43ed7140000 pid=5335->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=a22e10fb-2100-0000-aa3b-b43edc140000 pid=5340->95af1084-bb50-5e21-b268-bef6227a3a19 send: 154B guuid=7b2b0c19-2200-0000-aa3b-b43edd140000 pid=5341->95af1084-bb50-5e21-b268-bef6227a3a19 send: 103B guuid=55193a3b-2200-0000-aa3b-b43ee2140000 pid=5346->95af1084-bb50-5e21-b268-bef6227a3a19 send: 154B guuid=a7f8c261-2200-0000-aa3b-b43ee3140000 pid=5347->95af1084-bb50-5e21-b268-bef6227a3a19 send: 103B guuid=64d8ce93-2200-0000-aa3b-b43ee8140000 pid=5352->95af1084-bb50-5e21-b268-bef6227a3a19 send: 155B guuid=e979afba-2200-0000-aa3b-b43ee9140000 pid=5353->95af1084-bb50-5e21-b268-bef6227a3a19 send: 104B guuid=d0e2e4e4-2200-0000-aa3b-b43eee140000 pid=5358->95af1084-bb50-5e21-b268-bef6227a3a19 send: 154B guuid=7f11cf0b-2300-0000-aa3b-b43eef140000 pid=5359->95af1084-bb50-5e21-b268-bef6227a3a19 send: 103B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-08 18:34:31 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
eagle1997.executorstresser.ru
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 37416a2cd23dcd8044f35b73a430acf96d59b7dec5b1a3b937da27bcfb6f5217

(this sample)

  
Delivery method
Distributed via web download

Comments