MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3913c5e5e2c0324d51da1c172928b0d32e8dbbecae4f180b4f0ab643afcbd389. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 3913c5e5e2c0324d51da1c172928b0d32e8dbbecae4f180b4f0ab643afcbd389
SHA3-384 hash: 4c68f6cc6a3bc8295153d86947e0b81cc5e457020ee98c229c202bf8cb276d3c53a608b888befbea56b44ef94e5465f1
SHA1 hash: 9e69956514d31537049846ef3ef493c5c3088cbe
MD5 hash: b63a273e684a33e15daea979ac367396
humanhash: grey-twelve-apart-missouri
File name:qkuys.sh
Download: download sample
Signature Mirai
File size:2'954 bytes
First seen:2025-11-22 16:36:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:i7gA7dm7KM7Ve7jC73S70aa0aX3KL7snA7nIL7IuJ7dO7R67G872Y71bh:i7gA7dm7KM7Ve7jC73S7010E3KL7snAi
TLSH T1B0516F8910D24A7EBE979A5372B9DF043981E0DA25C66F4EECDE34B5684CF153500FE2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://154.6.197.44/bin/Polar.x8693a1c252d10d76024a5d488f92658d0f9cd32dc0ad90ed9ed64b26bcb93194ca Miraielf geofenced mirai opendir ua-wget USA x86
http://154.6.197.44/bin/Polar.mips59c55501918e0f7c6c0fbdfb9582b3bd2cb851d56608bbe4cfd76eb5225bed7f Miraielf geofenced mips mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.arced92383ba83cf87045d54e5235418a73b279258abe9c1ad0c00c093ce42da7aa Miraiarc elf geofenced mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.i468n/an/aelf ua-wget
http://154.6.197.44/bin/Polar.i686e4887d3bd2122919343f1cd0d222deb98f1a652fceb4dc4746cef8a64ac84266 Miraielf geofenced mirai opendir ua-wget USA x86
http://154.6.197.44/bin/Polar.x86_64d5f6fe226289a3f9cb5d83db63a2fdbf0024f61ac7b893b670129813e9fa0a08 Miraielf geofenced mirai opendir ua-wget USA x86
http://154.6.197.44/bin/Polar.mpslacc9ea729fb577311870758f13e08f838e1e658d3fcf1046682667331426f223 Miraielf geofenced mips mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.arm583901d5241b61add64f1c5a4b0db6f208e1966b59f875c6b752c9ba1a97f2aa Miraiarm elf geofenced mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.arm5ee9753ac80e2def70e03baeab0451978552c4705ff035fa4e674bb40a3ccaa91 Miraiarm elf geofenced mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.arm6721fe15d7d32f9940823b6401dba7004634d31e5d0144e778e07fd24d266d0f1 Miraiarm elf geofenced mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.arm74fe7c8ec1c0bc38038cd295f0e86e4ee82a6acfacf078216dca3ec934b9a9419 Miraiarm elf geofenced mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.ppc5f4e153c8107eba841c35ec284550fef6f37149f5e340f8c93a51de95eeb368f Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://154.6.197.44/bin/Polar.spc31089c8a5283bb413a4d4baf0465cc0865bd741ec5243fa42c9e4a0b1e8b23a8 Miraielf geofenced mirai opendir sparc ua-wget USA
http://154.6.197.44/bin/Polar.m68k3bbb478c8b9d843bfac8b3e30c1a8995c8083c9bec566afb0a8cc83f0152a855 Miraielf geofenced m68k mirai opendir ua-wget USA
http://154.6.197.44/bin/Polar.sh43ab21df5266014a5d499a423818b1ecce0ed014d99cb2670e582b2449a1d9789 Miraielf geofenced mirai opendir SuperH ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-22T14:06:00Z UTC
Last seen:
2025-11-23T10:33:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=12731531-1700-0000-b765-4fc2610b0000 pid=2913 /usr/bin/sudo guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916 /tmp/sample.bin guuid=12731531-1700-0000-b765-4fc2610b0000 pid=2913->guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916 execve guuid=486d3a34-1700-0000-b765-4fc2650b0000 pid=2917 /usr/bin/cp guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=486d3a34-1700-0000-b765-4fc2650b0000 pid=2917 execve guuid=96139739-1700-0000-b765-4fc26f0b0000 pid=2927 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=96139739-1700-0000-b765-4fc26f0b0000 pid=2927 execve guuid=1352fa66-1700-0000-b765-4fc2a10b0000 pid=2977 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=1352fa66-1700-0000-b765-4fc2a10b0000 pid=2977 execve guuid=7a963c96-1700-0000-b765-4fc2f80b0000 pid=3064 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=7a963c96-1700-0000-b765-4fc2f80b0000 pid=3064 execve guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066 /tmp/Polar.x86 net guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066 execve guuid=ae1defc4-1800-0000-b765-4fc2b30d0000 pid=3507 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ae1defc4-1800-0000-b765-4fc2b30d0000 pid=3507 execve guuid=49df95c5-1800-0000-b765-4fc2b40d0000 pid=3508 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=49df95c5-1800-0000-b765-4fc2b40d0000 pid=3508 execve guuid=c1103a13-1900-0000-b765-4fc22e0e0000 pid=3630 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=c1103a13-1900-0000-b765-4fc22e0e0000 pid=3630 execve guuid=6888bb51-1900-0000-b765-4fc2a70e0000 pid=3751 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=6888bb51-1900-0000-b765-4fc2a70e0000 pid=3751 execve guuid=afe78252-1900-0000-b765-4fc2a90e0000 pid=3753 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=afe78252-1900-0000-b765-4fc2a90e0000 pid=3753 clone guuid=b5b6e954-1900-0000-b765-4fc2b00e0000 pid=3760 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b5b6e954-1900-0000-b765-4fc2b00e0000 pid=3760 execve guuid=5a755c58-1900-0000-b765-4fc2b70e0000 pid=3767 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=5a755c58-1900-0000-b765-4fc2b70e0000 pid=3767 execve guuid=93dfad95-1900-0000-b765-4fc2410f0000 pid=3905 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=93dfad95-1900-0000-b765-4fc2410f0000 pid=3905 execve guuid=8f53f7d1-1900-0000-b765-4fc2ed0f0000 pid=4077 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=8f53f7d1-1900-0000-b765-4fc2ed0f0000 pid=4077 execve guuid=32bba0d2-1900-0000-b765-4fc2ef0f0000 pid=4079 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=32bba0d2-1900-0000-b765-4fc2ef0f0000 pid=4079 clone guuid=799846d5-1900-0000-b765-4fc2f60f0000 pid=4086 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=799846d5-1900-0000-b765-4fc2f60f0000 pid=4086 execve guuid=30f7a2d5-1900-0000-b765-4fc2f80f0000 pid=4088 /usr/bin/wget net send-data guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=30f7a2d5-1900-0000-b765-4fc2f80f0000 pid=4088 execve guuid=b8c697e5-1900-0000-b765-4fc237100000 pid=4151 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b8c697e5-1900-0000-b765-4fc237100000 pid=4151 execve guuid=7f1c92f7-1900-0000-b765-4fc269100000 pid=4201 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=7f1c92f7-1900-0000-b765-4fc269100000 pid=4201 execve guuid=816e37f8-1900-0000-b765-4fc26b100000 pid=4203 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=816e37f8-1900-0000-b765-4fc26b100000 pid=4203 clone guuid=271073f8-1900-0000-b765-4fc26c100000 pid=4204 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=271073f8-1900-0000-b765-4fc26c100000 pid=4204 execve guuid=c9461df9-1900-0000-b765-4fc26e100000 pid=4206 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=c9461df9-1900-0000-b765-4fc26e100000 pid=4206 execve guuid=2813f426-1a00-0000-b765-4fc206110000 pid=4358 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=2813f426-1a00-0000-b765-4fc206110000 pid=4358 execve guuid=22497f85-1a00-0000-b765-4fc248120000 pid=4680 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=22497f85-1a00-0000-b765-4fc248120000 pid=4680 execve guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682 /tmp/Polar.i686 net guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682 execve guuid=d06420b3-1b00-0000-b765-4fc282140000 pid=5250 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=d06420b3-1b00-0000-b765-4fc282140000 pid=5250 execve guuid=b13c6fb3-1b00-0000-b765-4fc283140000 pid=5251 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b13c6fb3-1b00-0000-b765-4fc283140000 pid=5251 execve guuid=ab5a3ad9-1b00-0000-b765-4fc284140000 pid=5252 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ab5a3ad9-1b00-0000-b765-4fc284140000 pid=5252 execve guuid=773c195d-1c00-0000-b765-4fc28c140000 pid=5260 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=773c195d-1c00-0000-b765-4fc28c140000 pid=5260 execve guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261 /tmp/Polar.x86_64 mprotect-exec net guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261 execve guuid=b1b74589-1d00-0000-b765-4fc2b3140000 pid=5299 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b1b74589-1d00-0000-b765-4fc2b3140000 pid=5299 execve guuid=04eee089-1d00-0000-b765-4fc2b4140000 pid=5300 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=04eee089-1d00-0000-b765-4fc2b4140000 pid=5300 execve guuid=ee444fac-1d00-0000-b765-4fc2b5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ee444fac-1d00-0000-b765-4fc2b5140000 pid=5301 execve guuid=dea190d5-1d00-0000-b765-4fc2b6140000 pid=5302 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=dea190d5-1d00-0000-b765-4fc2b6140000 pid=5302 execve guuid=f2c024d6-1d00-0000-b765-4fc2b7140000 pid=5303 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=f2c024d6-1d00-0000-b765-4fc2b7140000 pid=5303 clone guuid=ea4746d7-1d00-0000-b765-4fc2b9140000 pid=5305 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ea4746d7-1d00-0000-b765-4fc2b9140000 pid=5305 execve guuid=7f3dd6d7-1d00-0000-b765-4fc2ba140000 pid=5306 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=7f3dd6d7-1d00-0000-b765-4fc2ba140000 pid=5306 execve guuid=ef379020-1e00-0000-b765-4fc2bb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ef379020-1e00-0000-b765-4fc2bb140000 pid=5307 execve guuid=39862e98-1e00-0000-b765-4fc2bc140000 pid=5308 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=39862e98-1e00-0000-b765-4fc2bc140000 pid=5308 execve guuid=acb6ce98-1e00-0000-b765-4fc2bd140000 pid=5309 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=acb6ce98-1e00-0000-b765-4fc2bd140000 pid=5309 clone guuid=0b00149a-1e00-0000-b765-4fc2bf140000 pid=5311 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=0b00149a-1e00-0000-b765-4fc2bf140000 pid=5311 execve guuid=be93b49a-1e00-0000-b765-4fc2c0140000 pid=5312 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=be93b49a-1e00-0000-b765-4fc2c0140000 pid=5312 execve guuid=da824bb4-1e00-0000-b765-4fc2c1140000 pid=5313 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=da824bb4-1e00-0000-b765-4fc2c1140000 pid=5313 execve guuid=e030c5ce-1e00-0000-b765-4fc2c2140000 pid=5314 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=e030c5ce-1e00-0000-b765-4fc2c2140000 pid=5314 execve guuid=40db59cf-1e00-0000-b765-4fc2c3140000 pid=5315 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=40db59cf-1e00-0000-b765-4fc2c3140000 pid=5315 clone guuid=39bc9dd0-1e00-0000-b765-4fc2c5140000 pid=5317 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=39bc9dd0-1e00-0000-b765-4fc2c5140000 pid=5317 execve guuid=045431d1-1e00-0000-b765-4fc2c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=045431d1-1e00-0000-b765-4fc2c6140000 pid=5318 execve guuid=8dbb3102-1f00-0000-b765-4fc2c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=8dbb3102-1f00-0000-b765-4fc2c7140000 pid=5319 execve guuid=e9462048-1f00-0000-b765-4fc2c8140000 pid=5320 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=e9462048-1f00-0000-b765-4fc2c8140000 pid=5320 execve guuid=4c51e448-1f00-0000-b765-4fc2c9140000 pid=5321 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=4c51e448-1f00-0000-b765-4fc2c9140000 pid=5321 clone guuid=2d4d0b4a-1f00-0000-b765-4fc2cb140000 pid=5323 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=2d4d0b4a-1f00-0000-b765-4fc2cb140000 pid=5323 execve guuid=b6ad9d4a-1f00-0000-b765-4fc2cc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b6ad9d4a-1f00-0000-b765-4fc2cc140000 pid=5324 execve guuid=ad8813b6-1f00-0000-b765-4fc2cd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ad8813b6-1f00-0000-b765-4fc2cd140000 pid=5325 execve guuid=262d63e4-1f00-0000-b765-4fc2ce140000 pid=5326 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=262d63e4-1f00-0000-b765-4fc2ce140000 pid=5326 execve guuid=50f4efe4-1f00-0000-b765-4fc2cf140000 pid=5327 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=50f4efe4-1f00-0000-b765-4fc2cf140000 pid=5327 clone guuid=8b1f03e6-1f00-0000-b765-4fc2d1140000 pid=5329 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=8b1f03e6-1f00-0000-b765-4fc2d1140000 pid=5329 execve guuid=f7829ae6-1f00-0000-b765-4fc2d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=f7829ae6-1f00-0000-b765-4fc2d2140000 pid=5330 execve guuid=f105cc0f-2000-0000-b765-4fc2d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=f105cc0f-2000-0000-b765-4fc2d3140000 pid=5331 execve guuid=9b8e7cdb-2000-0000-b765-4fc2d4140000 pid=5332 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=9b8e7cdb-2000-0000-b765-4fc2d4140000 pid=5332 execve guuid=b31d14dc-2000-0000-b765-4fc2d5140000 pid=5333 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=b31d14dc-2000-0000-b765-4fc2d5140000 pid=5333 clone guuid=2fea5cdd-2000-0000-b765-4fc2d7140000 pid=5335 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=2fea5cdd-2000-0000-b765-4fc2d7140000 pid=5335 execve guuid=5e67eddd-2000-0000-b765-4fc2d8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=5e67eddd-2000-0000-b765-4fc2d8140000 pid=5336 execve guuid=7a946411-2100-0000-b765-4fc2d9140000 pid=5337 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=7a946411-2100-0000-b765-4fc2d9140000 pid=5337 execve guuid=a2b03735-2100-0000-b765-4fc2da140000 pid=5338 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=a2b03735-2100-0000-b765-4fc2da140000 pid=5338 execve guuid=e5b19535-2100-0000-b765-4fc2db140000 pid=5339 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=e5b19535-2100-0000-b765-4fc2db140000 pid=5339 clone guuid=dab34736-2100-0000-b765-4fc2dd140000 pid=5341 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=dab34736-2100-0000-b765-4fc2dd140000 pid=5341 execve guuid=fddc9336-2100-0000-b765-4fc2de140000 pid=5342 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=fddc9336-2100-0000-b765-4fc2de140000 pid=5342 execve guuid=2b5c5c26-2300-0000-b765-4fc2df140000 pid=5343 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=2b5c5c26-2300-0000-b765-4fc2df140000 pid=5343 execve guuid=4091a25a-2300-0000-b765-4fc2e0140000 pid=5344 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=4091a25a-2300-0000-b765-4fc2e0140000 pid=5344 execve guuid=bf37275b-2300-0000-b765-4fc2e1140000 pid=5345 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=bf37275b-2300-0000-b765-4fc2e1140000 pid=5345 clone guuid=ad8c5f5c-2300-0000-b765-4fc2e3140000 pid=5347 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=ad8c5f5c-2300-0000-b765-4fc2e3140000 pid=5347 execve guuid=e6a5fc5c-2300-0000-b765-4fc2e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=e6a5fc5c-2300-0000-b765-4fc2e4140000 pid=5348 execve guuid=4013018c-2300-0000-b765-4fc2e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=4013018c-2300-0000-b765-4fc2e5140000 pid=5349 execve guuid=cd5afd1e-2400-0000-b765-4fc2e6140000 pid=5350 /usr/bin/chmod guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=cd5afd1e-2400-0000-b765-4fc2e6140000 pid=5350 execve guuid=00f1981f-2400-0000-b765-4fc2e7140000 pid=5351 /usr/bin/bash guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=00f1981f-2400-0000-b765-4fc2e7140000 pid=5351 clone guuid=be23c520-2400-0000-b765-4fc2e9140000 pid=5353 /usr/bin/rm delete-file guuid=20a6cd33-1700-0000-b765-4fc2640b0000 pid=2916->guuid=be23c520-2400-0000-b765-4fc2e9140000 pid=5353 execve 5a963a3b-e46c-556d-9861-12c629ba8f3d 154.6.197.44:80 guuid=96139739-1700-0000-b765-4fc26f0b0000 pid=2927->5a963a3b-e46c-556d-9861-12c629ba8f3d send: 140B guuid=1352fa66-1700-0000-b765-4fc2a10b0000 pid=2977->5a963a3b-e46c-556d-9861-12c629ba8f3d send: 89B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c8765b98-1700-0000-b765-4fc2ff0b0000 pid=3071 /tmp/Polar.x86 guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066->guuid=c8765b98-1700-0000-b765-4fc2ff0b0000 pid=3071 clone guuid=354dc6c4-1800-0000-b765-4fc2b10d0000 pid=3505 /tmp/Polar.x86 guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066->guuid=354dc6c4-1800-0000-b765-4fc2b10d0000 pid=3505 clone guuid=7606cfc4-1800-0000-b765-4fc2b20d0000 pid=3506 /tmp/Polar.x86 net send-data zombie guuid=4c9dc096-1700-0000-b765-4fc2fa0b0000 pid=3066->guuid=7606cfc4-1800-0000-b765-4fc2b20d0000 pid=3506 clone guuid=e2e06998-1700-0000-b765-4fc2000c0000 pid=3072 /tmp/Polar.x86 guuid=c8765b98-1700-0000-b765-4fc2ff0b0000 pid=3071->guuid=e2e06998-1700-0000-b765-4fc2000c0000 pid=3072 clone guuid=86dc7698-1700-0000-b765-4fc2010c0000 pid=3073 /tmp/Polar.x86 dns net send-data zombie guuid=c8765b98-1700-0000-b765-4fc2ff0b0000 pid=3071->guuid=86dc7698-1700-0000-b765-4fc2010c0000 pid=3073 clone guuid=86dc7698-1700-0000-b765-4fc2010c0000 pid=3073->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B 835e2637-8ea8-5733-9bcd-e417a3d56db3 lolzzmortex.duckdns.org:69 guuid=86dc7698-1700-0000-b765-4fc2010c0000 pid=3073->835e2637-8ea8-5733-9bcd-e417a3d56db3 send: 19B guuid=7606cfc4-1800-0000-b765-4fc2b20d0000 pid=3506->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1025B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=7606cfc4-1800-0000-b765-4fc2b20d0000 pid=3506->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B 476a0c93-2191-583b-9b9c-60decf74ba9d lolzzmortex.duckdns.org:80 guuid=49df95c5-1800-0000-b765-4fc2b40d0000 pid=3508->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=c1103a13-1900-0000-b765-4fc22e0e0000 pid=3630->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=5a755c58-1900-0000-b765-4fc2b70e0000 pid=3767->476a0c93-2191-583b-9b9c-60decf74ba9d send: 140B guuid=93dfad95-1900-0000-b765-4fc2410f0000 pid=3905->476a0c93-2191-583b-9b9c-60decf74ba9d send: 89B guuid=30f7a2d5-1900-0000-b765-4fc2f80f0000 pid=4088->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=b8c697e5-1900-0000-b765-4fc237100000 pid=4151->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=c9461df9-1900-0000-b765-4fc26e100000 pid=4206->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=2813f426-1a00-0000-b765-4fc206110000 pid=4358->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f19f8786-1a00-0000-b765-4fc24e120000 pid=4686 /tmp/Polar.i686 guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682->guuid=f19f8786-1a00-0000-b765-4fc24e120000 pid=4686 clone guuid=251cf9b2-1b00-0000-b765-4fc280140000 pid=5248 /tmp/Polar.i686 guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682->guuid=251cf9b2-1b00-0000-b765-4fc280140000 pid=5248 clone guuid=bdf504b3-1b00-0000-b765-4fc281140000 pid=5249 /tmp/Polar.i686 net send-data zombie guuid=8784d185-1a00-0000-b765-4fc24a120000 pid=4682->guuid=bdf504b3-1b00-0000-b765-4fc281140000 pid=5249 clone guuid=60b09086-1a00-0000-b765-4fc24f120000 pid=4687 /tmp/Polar.i686 guuid=f19f8786-1a00-0000-b765-4fc24e120000 pid=4686->guuid=60b09086-1a00-0000-b765-4fc24f120000 pid=4687 clone guuid=4e729686-1a00-0000-b765-4fc250120000 pid=4688 /tmp/Polar.i686 dns net send-data zombie guuid=f19f8786-1a00-0000-b765-4fc24e120000 pid=4686->guuid=4e729686-1a00-0000-b765-4fc250120000 pid=4688 clone guuid=4e729686-1a00-0000-b765-4fc250120000 pid=4688->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B guuid=4e729686-1a00-0000-b765-4fc250120000 pid=4688->835e2637-8ea8-5733-9bcd-e417a3d56db3 send: 18B guuid=bdf504b3-1b00-0000-b765-4fc281140000 pid=5249->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=bdf504b3-1b00-0000-b765-4fc281140000 pid=5249->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=b13c6fb3-1b00-0000-b765-4fc283140000 pid=5251->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=ab5a3ad9-1b00-0000-b765-4fc284140000 pid=5252->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=269c615e-1c00-0000-b765-4fc28e140000 pid=5262 /tmp/Polar.x86_64 guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261->guuid=269c615e-1c00-0000-b765-4fc28e140000 pid=5262 clone guuid=b6011d89-1d00-0000-b765-4fc2b1140000 pid=5297 /tmp/Polar.x86_64 guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261->guuid=b6011d89-1d00-0000-b765-4fc2b1140000 pid=5297 clone guuid=3bc22889-1d00-0000-b765-4fc2b2140000 pid=5298 /tmp/Polar.x86_64 net send-data zombie guuid=6bd47c5d-1c00-0000-b765-4fc28d140000 pid=5261->guuid=3bc22889-1d00-0000-b765-4fc2b2140000 pid=5298 clone guuid=7fa76b5e-1c00-0000-b765-4fc28f140000 pid=5263 /tmp/Polar.x86_64 guuid=269c615e-1c00-0000-b765-4fc28e140000 pid=5262->guuid=7fa76b5e-1c00-0000-b765-4fc28f140000 pid=5263 clone guuid=fd90725e-1c00-0000-b765-4fc290140000 pid=5264 /tmp/Polar.x86_64 net send-data zombie guuid=269c615e-1c00-0000-b765-4fc28e140000 pid=5262->guuid=fd90725e-1c00-0000-b765-4fc290140000 pid=5264 clone guuid=fd90725e-1c00-0000-b765-4fc290140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=fd90725e-1c00-0000-b765-4fc290140000 pid=5264->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=3bc22889-1d00-0000-b765-4fc2b2140000 pid=5298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=3bc22889-1d00-0000-b765-4fc2b2140000 pid=5298->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=04eee089-1d00-0000-b765-4fc2b4140000 pid=5300->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=ee444fac-1d00-0000-b765-4fc2b5140000 pid=5301->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=7f3dd6d7-1d00-0000-b765-4fc2ba140000 pid=5306->476a0c93-2191-583b-9b9c-60decf74ba9d send: 140B guuid=ef379020-1e00-0000-b765-4fc2bb140000 pid=5307->476a0c93-2191-583b-9b9c-60decf74ba9d send: 89B guuid=be93b49a-1e00-0000-b765-4fc2c0140000 pid=5312->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=da824bb4-1e00-0000-b765-4fc2c1140000 pid=5313->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=045431d1-1e00-0000-b765-4fc2c6140000 pid=5318->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=8dbb3102-1f00-0000-b765-4fc2c7140000 pid=5319->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=b6ad9d4a-1f00-0000-b765-4fc2cc140000 pid=5324->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=ad8813b6-1f00-0000-b765-4fc2cd140000 pid=5325->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=f7829ae6-1f00-0000-b765-4fc2d2140000 pid=5330->476a0c93-2191-583b-9b9c-60decf74ba9d send: 140B guuid=f105cc0f-2000-0000-b765-4fc2d3140000 pid=5331->476a0c93-2191-583b-9b9c-60decf74ba9d send: 89B guuid=5e67eddd-2000-0000-b765-4fc2d8140000 pid=5336->476a0c93-2191-583b-9b9c-60decf74ba9d send: 140B guuid=7a946411-2100-0000-b765-4fc2d9140000 pid=5337->476a0c93-2191-583b-9b9c-60decf74ba9d send: 89B guuid=fddc9336-2100-0000-b765-4fc2de140000 pid=5342->476a0c93-2191-583b-9b9c-60decf74ba9d send: 141B guuid=2b5c5c26-2300-0000-b765-4fc2df140000 pid=5343->476a0c93-2191-583b-9b9c-60decf74ba9d send: 90B guuid=e6a5fc5c-2300-0000-b765-4fc2e4140000 pid=5348->476a0c93-2191-583b-9b9c-60decf74ba9d send: 140B guuid=4013018c-2300-0000-b765-4fc2e5140000 pid=5349->476a0c93-2191-583b-9b9c-60decf74ba9d send: 89B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-22 16:37:40 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Creates a large amount of network flows
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
lolzzmortex.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3913c5e5e2c0324d51da1c172928b0d32e8dbbecae4f180b4f0ab643afcbd389

(this sample)

  
Delivery method
Distributed via web download

Comments