MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4a891f64f5f1f3e32a3a2479bcadb2852992aa0722f216c6b3919d51f15a4f09. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4a891f64f5f1f3e32a3a2479bcadb2852992aa0722f216c6b3919d51f15a4f09
SHA3-384 hash: 3a5306a59705c1efd5a39910c891247f69b91d1fbc74645c26bb45da3e1c3dc67934a2e0e9f61ae4cc278175acae2552
SHA1 hash: 4ca04684599120e527d5aa5b2636c66dfeb2ac8b
MD5 hash: d69fd65db07d927b6b6875d66084eb66
humanhash: paris-johnny-black-alaska
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'614 bytes
First seen:2025-07-31 11:08:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ivNENFadvEFnkvrKzv/Grvts9AkvX+PvDaPIvIx8v76Lvc9Wvd85vZQbvB4vv2P+:iQGMkmzWre9nWPCI48GL6WK5Cbyvi4K8
TLSH T10951BDDA115214382DF2DA2AB2FB801471FEA59B35E33F0598F978F740DDD942860BD6
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://212.11.64.25//main_arcn/an/an/a
http://212.11.64.25//main_x86n/an/an/a
http://212.11.64.25//main_x86_64n/an/an/a
http://212.11.64.25//main_i686n/an/an/a
http://212.11.64.25//main_mipsn/an/an/a
http://212.11.64.25//main_mips64n/an/an/a
http://212.11.64.25//main_mpsln/an/an/a
http://212.11.64.25//main_armn/an/an/a
http://212.11.64.25//main_arm5n/an/an/a
http://212.11.64.25//main_arm6n/an/an/a
http://212.11.64.25//main_arm7n/an/an/a
http://212.11.64.25//main_ppcn/an/an/a
http://212.11.64.25//main_sparcn/an/an/a
http://212.11.64.25//main_m68kn/an/an/a
http://212.11.64.25//main_sh4n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=030b5cb4-1600-0000-f2af-a1a28d0c0000 pid=3213 /usr/bin/sudo guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216 /tmp/sample.bin guuid=030b5cb4-1600-0000-f2af-a1a28d0c0000 pid=3213->guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216 execve guuid=5b44b0b6-1600-0000-f2af-a1a2920c0000 pid=3218 /usr/bin/cp guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=5b44b0b6-1600-0000-f2af-a1a2920c0000 pid=3218 execve guuid=8995dfbc-1600-0000-f2af-a1a2970c0000 pid=3223 /usr/bin/wget net send-data guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=8995dfbc-1600-0000-f2af-a1a2970c0000 pid=3223 execve guuid=e78704c3-1600-0000-f2af-a1a2a00c0000 pid=3232 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=e78704c3-1600-0000-f2af-a1a2a00c0000 pid=3232 execve guuid=96ff80cc-1600-0000-f2af-a1a2ad0c0000 pid=3245 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=96ff80cc-1600-0000-f2af-a1a2ad0c0000 pid=3245 execve guuid=f07ecccc-1600-0000-f2af-a1a2af0c0000 pid=3247 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=f07ecccc-1600-0000-f2af-a1a2af0c0000 pid=3247 execve guuid=301e53cd-1600-0000-f2af-a1a2b00c0000 pid=3248 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=301e53cd-1600-0000-f2af-a1a2b00c0000 pid=3248 clone guuid=63acd6cd-1600-0000-f2af-a1a2b20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=63acd6cd-1600-0000-f2af-a1a2b20c0000 pid=3250 execve guuid=0b0bffd4-1600-0000-f2af-a1a2bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=0b0bffd4-1600-0000-f2af-a1a2bd0c0000 pid=3261 execve guuid=8a5454dd-1600-0000-f2af-a1a2d40c0000 pid=3284 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=8a5454dd-1600-0000-f2af-a1a2d40c0000 pid=3284 execve guuid=caefc6dd-1600-0000-f2af-a1a2d60c0000 pid=3286 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=caefc6dd-1600-0000-f2af-a1a2d60c0000 pid=3286 execve guuid=09b32cde-1600-0000-f2af-a1a2d90c0000 pid=3289 /tmp/Astro delete-file net guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=09b32cde-1600-0000-f2af-a1a2d90c0000 pid=3289 execve guuid=95a57dde-1600-0000-f2af-a1a2dc0c0000 pid=3292 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=95a57dde-1600-0000-f2af-a1a2dc0c0000 pid=3292 execve guuid=6dc796e6-1600-0000-f2af-a1a2e90c0000 pid=3305 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=6dc796e6-1600-0000-f2af-a1a2e90c0000 pid=3305 execve guuid=055d65ef-1600-0000-f2af-a1a2fc0c0000 pid=3324 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=055d65ef-1600-0000-f2af-a1a2fc0c0000 pid=3324 execve guuid=7e03c2ef-1600-0000-f2af-a1a2fe0c0000 pid=3326 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=7e03c2ef-1600-0000-f2af-a1a2fe0c0000 pid=3326 execve guuid=538111f0-1600-0000-f2af-a1a2000d0000 pid=3328 /tmp/Astro delete-file net guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=538111f0-1600-0000-f2af-a1a2000d0000 pid=3328 execve guuid=3ccf3ff0-1600-0000-f2af-a1a2040d0000 pid=3332 /usr/bin/wget net send-data guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=3ccf3ff0-1600-0000-f2af-a1a2040d0000 pid=3332 execve guuid=d6a585f4-1600-0000-f2af-a1a2080d0000 pid=3336 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=d6a585f4-1600-0000-f2af-a1a2080d0000 pid=3336 execve guuid=d9536afb-1600-0000-f2af-a1a2110d0000 pid=3345 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=d9536afb-1600-0000-f2af-a1a2110d0000 pid=3345 execve guuid=3921aefb-1600-0000-f2af-a1a2120d0000 pid=3346 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=3921aefb-1600-0000-f2af-a1a2120d0000 pid=3346 execve guuid=5152f2fb-1600-0000-f2af-a1a2140d0000 pid=3348 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=5152f2fb-1600-0000-f2af-a1a2140d0000 pid=3348 clone guuid=fd9b2ffc-1600-0000-f2af-a1a2160d0000 pid=3350 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=fd9b2ffc-1600-0000-f2af-a1a2160d0000 pid=3350 execve guuid=b20a3705-1700-0000-f2af-a1a2270d0000 pid=3367 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=b20a3705-1700-0000-f2af-a1a2270d0000 pid=3367 execve guuid=3cebb10e-1700-0000-f2af-a1a23e0d0000 pid=3390 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=3cebb10e-1700-0000-f2af-a1a23e0d0000 pid=3390 execve guuid=f1c31e0f-1700-0000-f2af-a1a2400d0000 pid=3392 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=f1c31e0f-1700-0000-f2af-a1a2400d0000 pid=3392 execve guuid=8d0f7a0f-1700-0000-f2af-a1a2420d0000 pid=3394 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=8d0f7a0f-1700-0000-f2af-a1a2420d0000 pid=3394 clone guuid=05bd3110-1700-0000-f2af-a1a2460d0000 pid=3398 /usr/bin/wget net send-data guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=05bd3110-1700-0000-f2af-a1a2460d0000 pid=3398 execve guuid=da5fe115-1700-0000-f2af-a1a2560d0000 pid=3414 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=da5fe115-1700-0000-f2af-a1a2560d0000 pid=3414 execve guuid=02061d1b-1700-0000-f2af-a1a2670d0000 pid=3431 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=02061d1b-1700-0000-f2af-a1a2670d0000 pid=3431 execve guuid=395e661b-1700-0000-f2af-a1a2690d0000 pid=3433 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=395e661b-1700-0000-f2af-a1a2690d0000 pid=3433 execve guuid=0e85a81b-1700-0000-f2af-a1a26b0d0000 pid=3435 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=0e85a81b-1700-0000-f2af-a1a26b0d0000 pid=3435 clone guuid=ec75e61b-1700-0000-f2af-a1a26e0d0000 pid=3438 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=ec75e61b-1700-0000-f2af-a1a26e0d0000 pid=3438 execve guuid=34431025-1700-0000-f2af-a1a2880d0000 pid=3464 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=34431025-1700-0000-f2af-a1a2880d0000 pid=3464 execve guuid=d0b2842e-1700-0000-f2af-a1a29e0d0000 pid=3486 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=d0b2842e-1700-0000-f2af-a1a29e0d0000 pid=3486 execve guuid=a1252c2f-1700-0000-f2af-a1a2a00d0000 pid=3488 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=a1252c2f-1700-0000-f2af-a1a2a00d0000 pid=3488 execve guuid=dce29f2f-1700-0000-f2af-a1a2a20d0000 pid=3490 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=dce29f2f-1700-0000-f2af-a1a2a20d0000 pid=3490 clone guuid=6d419230-1700-0000-f2af-a1a2a60d0000 pid=3494 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=6d419230-1700-0000-f2af-a1a2a60d0000 pid=3494 execve guuid=56493939-1700-0000-f2af-a1a2b70d0000 pid=3511 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=56493939-1700-0000-f2af-a1a2b70d0000 pid=3511 execve guuid=2ae9b947-1700-0000-f2af-a1a2d00d0000 pid=3536 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=2ae9b947-1700-0000-f2af-a1a2d00d0000 pid=3536 execve guuid=97020e48-1700-0000-f2af-a1a2d20d0000 pid=3538 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=97020e48-1700-0000-f2af-a1a2d20d0000 pid=3538 execve guuid=70da5248-1700-0000-f2af-a1a2d30d0000 pid=3539 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=70da5248-1700-0000-f2af-a1a2d30d0000 pid=3539 clone guuid=de9be348-1700-0000-f2af-a1a2d50d0000 pid=3541 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=de9be348-1700-0000-f2af-a1a2d50d0000 pid=3541 execve guuid=55fc9f52-1700-0000-f2af-a1a2e60d0000 pid=3558 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=55fc9f52-1700-0000-f2af-a1a2e60d0000 pid=3558 execve guuid=70623b5c-1700-0000-f2af-a1a2fa0d0000 pid=3578 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=70623b5c-1700-0000-f2af-a1a2fa0d0000 pid=3578 execve guuid=f701d75c-1700-0000-f2af-a1a2fc0d0000 pid=3580 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=f701d75c-1700-0000-f2af-a1a2fc0d0000 pid=3580 execve guuid=49b3555d-1700-0000-f2af-a1a2fe0d0000 pid=3582 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=49b3555d-1700-0000-f2af-a1a2fe0d0000 pid=3582 clone guuid=217d4b5e-1700-0000-f2af-a1a2020e0000 pid=3586 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=217d4b5e-1700-0000-f2af-a1a2020e0000 pid=3586 execve guuid=66f4e666-1700-0000-f2af-a1a2160e0000 pid=3606 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=66f4e666-1700-0000-f2af-a1a2160e0000 pid=3606 execve guuid=d7f68370-1700-0000-f2af-a1a2260e0000 pid=3622 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=d7f68370-1700-0000-f2af-a1a2260e0000 pid=3622 execve guuid=9addfb70-1700-0000-f2af-a1a2270e0000 pid=3623 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=9addfb70-1700-0000-f2af-a1a2270e0000 pid=3623 execve guuid=44477f71-1700-0000-f2af-a1a2290e0000 pid=3625 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=44477f71-1700-0000-f2af-a1a2290e0000 pid=3625 clone guuid=b8f96772-1700-0000-f2af-a1a22e0e0000 pid=3630 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=b8f96772-1700-0000-f2af-a1a22e0e0000 pid=3630 execve guuid=7acd017b-1700-0000-f2af-a1a23f0e0000 pid=3647 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=7acd017b-1700-0000-f2af-a1a23f0e0000 pid=3647 execve guuid=805df984-1700-0000-f2af-a1a2530e0000 pid=3667 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=805df984-1700-0000-f2af-a1a2530e0000 pid=3667 execve guuid=670c9d85-1700-0000-f2af-a1a2540e0000 pid=3668 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=670c9d85-1700-0000-f2af-a1a2540e0000 pid=3668 execve guuid=606e2486-1700-0000-f2af-a1a2560e0000 pid=3670 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=606e2486-1700-0000-f2af-a1a2560e0000 pid=3670 clone guuid=5f671787-1700-0000-f2af-a1a25d0e0000 pid=3677 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=5f671787-1700-0000-f2af-a1a25d0e0000 pid=3677 execve guuid=a690428f-1700-0000-f2af-a1a2740e0000 pid=3700 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=a690428f-1700-0000-f2af-a1a2740e0000 pid=3700 execve guuid=9d97eb98-1700-0000-f2af-a1a28d0e0000 pid=3725 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=9d97eb98-1700-0000-f2af-a1a28d0e0000 pid=3725 execve guuid=c3589299-1700-0000-f2af-a1a28f0e0000 pid=3727 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=c3589299-1700-0000-f2af-a1a28f0e0000 pid=3727 execve guuid=03ade499-1700-0000-f2af-a1a2910e0000 pid=3729 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=03ade499-1700-0000-f2af-a1a2910e0000 pid=3729 clone guuid=34ab8b9a-1700-0000-f2af-a1a2940e0000 pid=3732 /usr/bin/wget net send-data guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=34ab8b9a-1700-0000-f2af-a1a2940e0000 pid=3732 execve guuid=be55989e-1700-0000-f2af-a1a29f0e0000 pid=3743 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=be55989e-1700-0000-f2af-a1a29f0e0000 pid=3743 execve guuid=c7e214a4-1700-0000-f2af-a1a2aa0e0000 pid=3754 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=c7e214a4-1700-0000-f2af-a1a2aa0e0000 pid=3754 execve guuid=21f16ba4-1700-0000-f2af-a1a2ac0e0000 pid=3756 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=21f16ba4-1700-0000-f2af-a1a2ac0e0000 pid=3756 execve guuid=b83bc6a4-1700-0000-f2af-a1a2ae0e0000 pid=3758 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=b83bc6a4-1700-0000-f2af-a1a2ae0e0000 pid=3758 clone guuid=264218a5-1700-0000-f2af-a1a2b00e0000 pid=3760 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=264218a5-1700-0000-f2af-a1a2b00e0000 pid=3760 execve guuid=a41640ad-1700-0000-f2af-a1a2cc0e0000 pid=3788 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=a41640ad-1700-0000-f2af-a1a2cc0e0000 pid=3788 execve guuid=aef1d5b6-1700-0000-f2af-a1a2ef0e0000 pid=3823 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=aef1d5b6-1700-0000-f2af-a1a2ef0e0000 pid=3823 execve guuid=542447b7-1700-0000-f2af-a1a2f10e0000 pid=3825 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=542447b7-1700-0000-f2af-a1a2f10e0000 pid=3825 execve guuid=f440b1b7-1700-0000-f2af-a1a2f30e0000 pid=3827 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=f440b1b7-1700-0000-f2af-a1a2f30e0000 pid=3827 clone guuid=ae796fb8-1700-0000-f2af-a1a2f70e0000 pid=3831 /usr/bin/wget net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=ae796fb8-1700-0000-f2af-a1a2f70e0000 pid=3831 execve guuid=6b4583c1-1700-0000-f2af-a1a2140f0000 pid=3860 /usr/bin/curl net send-data write-file guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=6b4583c1-1700-0000-f2af-a1a2140f0000 pid=3860 execve guuid=063f1fcd-1700-0000-f2af-a1a2350f0000 pid=3893 /usr/bin/cat guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=063f1fcd-1700-0000-f2af-a1a2350f0000 pid=3893 execve guuid=131780cd-1700-0000-f2af-a1a2360f0000 pid=3894 /usr/bin/chmod guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=131780cd-1700-0000-f2af-a1a2360f0000 pid=3894 execve guuid=792fd8cd-1700-0000-f2af-a1a2370f0000 pid=3895 /usr/bin/bash guuid=147f4bb6-1600-0000-f2af-a1a2900c0000 pid=3216->guuid=792fd8cd-1700-0000-f2af-a1a2370f0000 pid=3895 clone eeaafefa-f084-5c46-b648-925974ebfae5 212.11.64.25:80 guuid=8995dfbc-1600-0000-f2af-a1a2970c0000 pid=3223->eeaafefa-f084-5c46-b648-925974ebfae5 send: 136B guuid=e78704c3-1600-0000-f2af-a1a2a00c0000 pid=3232->eeaafefa-f084-5c46-b648-925974ebfae5 send: 85B guuid=524f91cd-1600-0000-f2af-a1a2b10c0000 pid=3249 /usr/bin/bash guuid=301e53cd-1600-0000-f2af-a1a2b00c0000 pid=3248->guuid=524f91cd-1600-0000-f2af-a1a2b10c0000 pid=3249 clone guuid=63acd6cd-1600-0000-f2af-a1a2b20c0000 pid=3250->eeaafefa-f084-5c46-b648-925974ebfae5 send: 136B guuid=0b0bffd4-1600-0000-f2af-a1a2bd0c0000 pid=3261->eeaafefa-f084-5c46-b648-925974ebfae5 send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=09b32cde-1600-0000-f2af-a1a2d90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9fa86ede-1600-0000-f2af-a1a2da0c0000 pid=3290 /tmp/Astro dns net send-data zombie guuid=09b32cde-1600-0000-f2af-a1a2d90c0000 pid=3289->guuid=9fa86ede-1600-0000-f2af-a1a2da0c0000 pid=3290 clone guuid=9fa86ede-1600-0000-f2af-a1a2da0c0000 pid=3290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 180B 32d458a0-a40f-565e-b5ae-91358dd4506a 115.11.111.11:22 guuid=9fa86ede-1600-0000-f2af-a1a2da0c0000 pid=3290->32d458a0-a40f-565e-b5ae-91358dd4506a con guuid=0d0486de-1600-0000-f2af-a1a2dd0c0000 pid=3293 /tmp/Astro guuid=9fa86ede-1600-0000-f2af-a1a2da0c0000 pid=3290->guuid=0d0486de-1600-0000-f2af-a1a2dd0c0000 pid=3293 clone guuid=95a57dde-1600-0000-f2af-a1a2dc0c0000 pid=3292->eeaafefa-f084-5c46-b648-925974ebfae5 send: 139B guuid=6dc796e6-1600-0000-f2af-a1a2e90c0000 pid=3305->eeaafefa-f084-5c46-b648-925974ebfae5 send: 88B guuid=538111f0-1600-0000-f2af-a1a2000d0000 pid=3328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6d282ff0-1600-0000-f2af-a1a2010d0000 pid=3329 /tmp/Astro delete-file dns net send-data zombie guuid=538111f0-1600-0000-f2af-a1a2000d0000 pid=3328->guuid=6d282ff0-1600-0000-f2af-a1a2010d0000 pid=3329 clone guuid=6d282ff0-1600-0000-f2af-a1a2010d0000 pid=3329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1080B guuid=6d282ff0-1600-0000-f2af-a1a2010d0000 pid=3329->32d458a0-a40f-565e-b5ae-91358dd4506a send: 2B guuid=90983bf0-1600-0000-f2af-a1a2030d0000 pid=3331 /tmp/Astro guuid=6d282ff0-1600-0000-f2af-a1a2010d0000 pid=3329->guuid=90983bf0-1600-0000-f2af-a1a2030d0000 pid=3331 clone guuid=3ccf3ff0-1600-0000-f2af-a1a2040d0000 pid=3332->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=d6a585f4-1600-0000-f2af-a1a2080d0000 pid=3336->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=b4800cfc-1600-0000-f2af-a1a2150d0000 pid=3349 /usr/bin/bash guuid=5152f2fb-1600-0000-f2af-a1a2140d0000 pid=3348->guuid=b4800cfc-1600-0000-f2af-a1a2150d0000 pid=3349 clone guuid=fd9b2ffc-1600-0000-f2af-a1a2160d0000 pid=3350->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=b20a3705-1700-0000-f2af-a1a2270d0000 pid=3367->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=05bd3110-1700-0000-f2af-a1a2460d0000 pid=3398->eeaafefa-f084-5c46-b648-925974ebfae5 send: 139B guuid=da5fe115-1700-0000-f2af-a1a2560d0000 pid=3414->eeaafefa-f084-5c46-b648-925974ebfae5 send: 88B guuid=f08fbe1b-1700-0000-f2af-a1a26c0d0000 pid=3436 /usr/bin/bash guuid=0e85a81b-1700-0000-f2af-a1a26b0d0000 pid=3435->guuid=f08fbe1b-1700-0000-f2af-a1a26c0d0000 pid=3436 clone guuid=ec75e61b-1700-0000-f2af-a1a26e0d0000 pid=3438->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=34431025-1700-0000-f2af-a1a2880d0000 pid=3464->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=6d419230-1700-0000-f2af-a1a2a60d0000 pid=3494->eeaafefa-f084-5c46-b648-925974ebfae5 send: 136B guuid=56493939-1700-0000-f2af-a1a2b70d0000 pid=3511->eeaafefa-f084-5c46-b648-925974ebfae5 send: 85B guuid=de9be348-1700-0000-f2af-a1a2d50d0000 pid=3541->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=55fc9f52-1700-0000-f2af-a1a2e60d0000 pid=3558->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=217d4b5e-1700-0000-f2af-a1a2020e0000 pid=3586->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=66f4e666-1700-0000-f2af-a1a2160e0000 pid=3606->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=b8f96772-1700-0000-f2af-a1a22e0e0000 pid=3630->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=7acd017b-1700-0000-f2af-a1a23f0e0000 pid=3647->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=5f671787-1700-0000-f2af-a1a25d0e0000 pid=3677->eeaafefa-f084-5c46-b648-925974ebfae5 send: 136B guuid=a690428f-1700-0000-f2af-a1a2740e0000 pid=3700->eeaafefa-f084-5c46-b648-925974ebfae5 send: 85B guuid=34ab8b9a-1700-0000-f2af-a1a2940e0000 pid=3732->eeaafefa-f084-5c46-b648-925974ebfae5 send: 138B guuid=be55989e-1700-0000-f2af-a1a29f0e0000 pid=3743->eeaafefa-f084-5c46-b648-925974ebfae5 send: 87B guuid=6ba5dca4-1700-0000-f2af-a1a2af0e0000 pid=3759 /usr/bin/bash guuid=b83bc6a4-1700-0000-f2af-a1a2ae0e0000 pid=3758->guuid=6ba5dca4-1700-0000-f2af-a1a2af0e0000 pid=3759 clone guuid=264218a5-1700-0000-f2af-a1a2b00e0000 pid=3760->eeaafefa-f084-5c46-b648-925974ebfae5 send: 137B guuid=a41640ad-1700-0000-f2af-a1a2cc0e0000 pid=3788->eeaafefa-f084-5c46-b648-925974ebfae5 send: 86B guuid=ae796fb8-1700-0000-f2af-a1a2f70e0000 pid=3831->eeaafefa-f084-5c46-b648-925974ebfae5 send: 136B guuid=6b4583c1-1700-0000-f2af-a1a2140f0000 pid=3860->eeaafefa-f084-5c46-b648-925974ebfae5 send: 85B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-31 14:04:44 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
botnet.m85test.xyz
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4a891f64f5f1f3e32a3a2479bcadb2852992aa0722f216c6b3919d51f15a4f09

(this sample)

  
Delivery method
Distributed via web download

Comments