MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4aca098bdfcd3ff9dc1ba3d15f6f461321c58a3dbb1d688ca731d95eac8e1ffa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 4aca098bdfcd3ff9dc1ba3d15f6f461321c58a3dbb1d688ca731d95eac8e1ffa
SHA3-384 hash: 7522c9fff02fb2f24485c47237fc1f40450ba806bb6f2d51da32f3668dd36c2eec8d150e5d6c7dd0142a72533816e526
SHA1 hash: 45818386c2be4a1d93cfacd8a22f69586ce92c0a
MD5 hash: 1dbcbcbb64d81965ecaebbebcfb6a1df
humanhash: summer-spaghetti-bakerloo-summer
File name:kla.sh
Download: download sample
Signature Mirai
File size:1'560 bytes
First seen:2026-05-08 18:48:59 UTC
Last seen:2026-05-09 13:05:30 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It8uvuWCw8k4k3w8SBdoKOw8by8w8fP+w88BOBw8xOw8yHCw8qSCz:ihGWXcVwKjX+zNwrr
TLSH T1B631D4CA0B12A5306DA2D91F7EA4C809F3D5ADCFACC1294594D878E894DCF49EA42A43
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.16/bins/px86f51d6a9837ac5868175ba0c57e7d2ef4a98e0d6131bef755f404c313ca049652 Miraielf mirai opendir ua-wget x86
http://89.32.41.16/bins/pmipsc5b338d9e78bb2152913a5f9b3ad682f3f7fd41e51793843f6600c546c536d61 Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/pmpsl44a0840a1f12163824e3a61c849c785741c1cb3be194abc937648a8e4a8d4d44 Miraielf mips mirai opendir ua-wget
http://89.32.41.16/bins/parm5e30e4677b2b91eb0b57a646a14bd4fcbe8538967d44598347c7b157ee4f9115 Miraielf mirai ua-wget
http://89.32.41.16/bins/parm57e45e9769cb7f1db7b20cd3a06d61a2977e8f31e9774e0a4a70e048384041f58 Miraielf mirai ua-wget
http://89.32.41.16/bins/parm605445d58ae969fc9f98eeef8c2f7ba40ddbdbc6085934a05763e8c82584c26bf Miraiarm elf mirai opendir ua-wget
http://89.32.41.16/bins/parm7f23ad05baffc1e5f13a87c8f800001c0b4b72a1c239aa2f77c3fe8c545402ea4 Miraielf mirai ua-wget
http://89.32.41.16/bins/pm68kn/an/aelf ua-wget
http://89.32.41.16/bins/psh4c6486adf985db95d787e1e1b064465513aaa1fa582e24163b83324aab67a5725 Miraielf mirai opendir SuperH ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
64
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-08T15:55:00Z UTC
Last seen:
2026-05-09T02:40:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=151c8735-1e00-0000-4590-35f6920c0000 pid=3218 /usr/bin/sudo guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219 /tmp/sample.bin guuid=151c8735-1e00-0000-4590-35f6920c0000 pid=3218->guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219 execve guuid=389a213b-1e00-0000-4590-35f6940c0000 pid=3220 /usr/bin/cp guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=389a213b-1e00-0000-4590-35f6940c0000 pid=3220 execve guuid=d65c2e44-1e00-0000-4590-35f6950c0000 pid=3221 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=d65c2e44-1e00-0000-4590-35f6950c0000 pid=3221 execve guuid=d4a6d14f-1e00-0000-4590-35f69e0c0000 pid=3230 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=d4a6d14f-1e00-0000-4590-35f69e0c0000 pid=3230 execve guuid=b8f0045f-1e00-0000-4590-35f6bf0c0000 pid=3263 /usr/bin/cat guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=b8f0045f-1e00-0000-4590-35f6bf0c0000 pid=3263 execve guuid=b359575f-1e00-0000-4590-35f6c10c0000 pid=3265 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=b359575f-1e00-0000-4590-35f6c10c0000 pid=3265 execve guuid=c1ae9b5f-1e00-0000-4590-35f6c30c0000 pid=3267 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c1ae9b5f-1e00-0000-4590-35f6c30c0000 pid=3267 execve guuid=4d53b75f-1e00-0000-4590-35f6c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=4d53b75f-1e00-0000-4590-35f6c50c0000 pid=3269 execve guuid=6758b46a-1e00-0000-4590-35f6dc0c0000 pid=3292 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=6758b46a-1e00-0000-4590-35f6dc0c0000 pid=3292 execve guuid=ed9edd77-1e00-0000-4590-35f6fa0c0000 pid=3322 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=ed9edd77-1e00-0000-4590-35f6fa0c0000 pid=3322 clone guuid=ce470178-1e00-0000-4590-35f6fc0c0000 pid=3324 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=ce470178-1e00-0000-4590-35f6fc0c0000 pid=3324 execve guuid=c5ea4478-1e00-0000-4590-35f6fd0c0000 pid=3325 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c5ea4478-1e00-0000-4590-35f6fd0c0000 pid=3325 execve guuid=fc0c6778-1e00-0000-4590-35f6000d0000 pid=3328 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=fc0c6778-1e00-0000-4590-35f6000d0000 pid=3328 execve guuid=1b03b584-1e00-0000-4590-35f6170d0000 pid=3351 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=1b03b584-1e00-0000-4590-35f6170d0000 pid=3351 execve guuid=1d99fb92-1e00-0000-4590-35f62a0d0000 pid=3370 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=1d99fb92-1e00-0000-4590-35f62a0d0000 pid=3370 clone guuid=385b1b93-1e00-0000-4590-35f62c0d0000 pid=3372 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=385b1b93-1e00-0000-4590-35f62c0d0000 pid=3372 execve guuid=14738a93-1e00-0000-4590-35f62d0d0000 pid=3373 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=14738a93-1e00-0000-4590-35f62d0d0000 pid=3373 execve guuid=c650a893-1e00-0000-4590-35f6300d0000 pid=3376 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c650a893-1e00-0000-4590-35f6300d0000 pid=3376 execve guuid=a6ba119e-1e00-0000-4590-35f6480d0000 pid=3400 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=a6ba119e-1e00-0000-4590-35f6480d0000 pid=3400 execve guuid=9c3061a9-1e00-0000-4590-35f65f0d0000 pid=3423 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=9c3061a9-1e00-0000-4590-35f65f0d0000 pid=3423 clone guuid=c4d585a9-1e00-0000-4590-35f6600d0000 pid=3424 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c4d585a9-1e00-0000-4590-35f6600d0000 pid=3424 execve guuid=029cf2a9-1e00-0000-4590-35f6620d0000 pid=3426 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=029cf2a9-1e00-0000-4590-35f6620d0000 pid=3426 execve guuid=bd7716aa-1e00-0000-4590-35f6640d0000 pid=3428 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=bd7716aa-1e00-0000-4590-35f6640d0000 pid=3428 execve guuid=faac4eb4-1e00-0000-4590-35f6800d0000 pid=3456 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=faac4eb4-1e00-0000-4590-35f6800d0000 pid=3456 execve guuid=318505bf-1e00-0000-4590-35f69d0d0000 pid=3485 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=318505bf-1e00-0000-4590-35f69d0d0000 pid=3485 clone guuid=368f26bf-1e00-0000-4590-35f69f0d0000 pid=3487 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=368f26bf-1e00-0000-4590-35f69f0d0000 pid=3487 execve guuid=2aa485bf-1e00-0000-4590-35f6a10d0000 pid=3489 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=2aa485bf-1e00-0000-4590-35f6a10d0000 pid=3489 execve guuid=4027afbf-1e00-0000-4590-35f6a30d0000 pid=3491 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=4027afbf-1e00-0000-4590-35f6a30d0000 pid=3491 execve guuid=6a04dacd-1e00-0000-4590-35f6c80d0000 pid=3528 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=6a04dacd-1e00-0000-4590-35f6c80d0000 pid=3528 execve guuid=ec067dda-1e00-0000-4590-35f6db0d0000 pid=3547 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=ec067dda-1e00-0000-4590-35f6db0d0000 pid=3547 clone guuid=ef20aada-1e00-0000-4590-35f6dc0d0000 pid=3548 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=ef20aada-1e00-0000-4590-35f6dc0d0000 pid=3548 execve guuid=c90bfeda-1e00-0000-4590-35f6de0d0000 pid=3550 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c90bfeda-1e00-0000-4590-35f6de0d0000 pid=3550 execve guuid=a67927db-1e00-0000-4590-35f6e10d0000 pid=3553 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=a67927db-1e00-0000-4590-35f6e10d0000 pid=3553 execve guuid=2ebe8de6-1e00-0000-4590-35f6f00d0000 pid=3568 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=2ebe8de6-1e00-0000-4590-35f6f00d0000 pid=3568 execve guuid=170012f5-1e00-0000-4590-35f6020e0000 pid=3586 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=170012f5-1e00-0000-4590-35f6020e0000 pid=3586 clone guuid=1f4538f5-1e00-0000-4590-35f6040e0000 pid=3588 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=1f4538f5-1e00-0000-4590-35f6040e0000 pid=3588 execve guuid=3d58bbf5-1e00-0000-4590-35f6060e0000 pid=3590 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=3d58bbf5-1e00-0000-4590-35f6060e0000 pid=3590 execve guuid=1b76eff5-1e00-0000-4590-35f6090e0000 pid=3593 /usr/bin/wget net send-data guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=1b76eff5-1e00-0000-4590-35f6090e0000 pid=3593 execve guuid=db1816fe-1e00-0000-4590-35f61d0e0000 pid=3613 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=db1816fe-1e00-0000-4590-35f61d0e0000 pid=3613 execve guuid=06b0f105-1f00-0000-4590-35f6300e0000 pid=3632 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=06b0f105-1f00-0000-4590-35f6300e0000 pid=3632 clone guuid=c0542006-1f00-0000-4590-35f6310e0000 pid=3633 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=c0542006-1f00-0000-4590-35f6310e0000 pid=3633 execve guuid=f8769006-1f00-0000-4590-35f6330e0000 pid=3635 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=f8769006-1f00-0000-4590-35f6330e0000 pid=3635 execve guuid=af4aba06-1f00-0000-4590-35f6350e0000 pid=3637 /usr/bin/wget net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=af4aba06-1f00-0000-4590-35f6350e0000 pid=3637 execve guuid=133b2211-1f00-0000-4590-35f64b0e0000 pid=3659 /usr/bin/curl net send-data write-file guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=133b2211-1f00-0000-4590-35f64b0e0000 pid=3659 execve guuid=7171011c-1f00-0000-4590-35f65b0e0000 pid=3675 /usr/bin/bash guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=7171011c-1f00-0000-4590-35f65b0e0000 pid=3675 clone guuid=f814211c-1f00-0000-4590-35f65c0e0000 pid=3676 /usr/bin/chmod guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=f814211c-1f00-0000-4590-35f65c0e0000 pid=3676 execve guuid=9c45921c-1f00-0000-4590-35f65e0e0000 pid=3678 /tmp/SSH guuid=42a73f3a-1e00-0000-4590-35f6930c0000 pid=3219->guuid=9c45921c-1f00-0000-4590-35f65e0e0000 pid=3678 execve ed1ae445-8403-522d-9c55-b54488c1ab36 89.32.41.16:80 guuid=d65c2e44-1e00-0000-4590-35f6950c0000 pid=3221->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 135B guuid=d4a6d14f-1e00-0000-4590-35f69e0c0000 pid=3230->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 84B guuid=3e28ac5f-1e00-0000-4590-35f6c40c0000 pid=3268 /tmp/SSH write-file zombie guuid=c1ae9b5f-1e00-0000-4590-35f6c30c0000 pid=3267->guuid=3e28ac5f-1e00-0000-4590-35f6c40c0000 pid=3268 clone guuid=eff9c35f-1e00-0000-4590-35f6c60c0000 pid=3270 /tmp/SSH write-file guuid=3e28ac5f-1e00-0000-4590-35f6c40c0000 pid=3268->guuid=eff9c35f-1e00-0000-4590-35f6c60c0000 pid=3270 clone guuid=48e6c75f-1e00-0000-4590-35f6c70c0000 pid=3271 /tmp/SSH write-file zombie guuid=3e28ac5f-1e00-0000-4590-35f6c40c0000 pid=3268->guuid=48e6c75f-1e00-0000-4590-35f6c70c0000 pid=3271 clone guuid=4d53b75f-1e00-0000-4590-35f6c50c0000 pid=3269->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=6758b46a-1e00-0000-4590-35f6dc0c0000 pid=3292->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=55a95678-1e00-0000-4590-35f6fe0c0000 pid=3326 /tmp/SSH write-file zombie guuid=c5ea4478-1e00-0000-4590-35f6fd0c0000 pid=3325->guuid=55a95678-1e00-0000-4590-35f6fe0c0000 pid=3326 clone guuid=57aa6b78-1e00-0000-4590-35f6010d0000 pid=3329 /tmp/SSH write-file guuid=55a95678-1e00-0000-4590-35f6fe0c0000 pid=3326->guuid=57aa6b78-1e00-0000-4590-35f6010d0000 pid=3329 clone guuid=b9586f78-1e00-0000-4590-35f6020d0000 pid=3330 /tmp/SSH write-file zombie guuid=55a95678-1e00-0000-4590-35f6fe0c0000 pid=3326->guuid=b9586f78-1e00-0000-4590-35f6020d0000 pid=3330 clone guuid=fc0c6778-1e00-0000-4590-35f6000d0000 pid=3328->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=1b03b584-1e00-0000-4590-35f6170d0000 pid=3351->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=9acd9c93-1e00-0000-4590-35f62e0d0000 pid=3374 /tmp/SSH write-file zombie guuid=14738a93-1e00-0000-4590-35f62d0d0000 pid=3373->guuid=9acd9c93-1e00-0000-4590-35f62e0d0000 pid=3374 clone guuid=80d7ac93-1e00-0000-4590-35f6310d0000 pid=3377 /tmp/SSH write-file guuid=9acd9c93-1e00-0000-4590-35f62e0d0000 pid=3374->guuid=80d7ac93-1e00-0000-4590-35f6310d0000 pid=3377 clone guuid=e188af93-1e00-0000-4590-35f6320d0000 pid=3378 /tmp/SSH write-file zombie guuid=9acd9c93-1e00-0000-4590-35f62e0d0000 pid=3374->guuid=e188af93-1e00-0000-4590-35f6320d0000 pid=3378 clone guuid=c650a893-1e00-0000-4590-35f6300d0000 pid=3376->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 135B guuid=a6ba119e-1e00-0000-4590-35f6480d0000 pid=3400->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 84B guuid=5e040baa-1e00-0000-4590-35f6630d0000 pid=3427 /tmp/SSH write-file zombie guuid=029cf2a9-1e00-0000-4590-35f6620d0000 pid=3426->guuid=5e040baa-1e00-0000-4590-35f6630d0000 pid=3427 clone guuid=59a61faa-1e00-0000-4590-35f6650d0000 pid=3429 /tmp/SSH write-file guuid=5e040baa-1e00-0000-4590-35f6630d0000 pid=3427->guuid=59a61faa-1e00-0000-4590-35f6650d0000 pid=3429 clone guuid=d30227aa-1e00-0000-4590-35f6660d0000 pid=3430 /tmp/SSH write-file zombie guuid=5e040baa-1e00-0000-4590-35f6630d0000 pid=3427->guuid=d30227aa-1e00-0000-4590-35f6660d0000 pid=3430 clone guuid=bd7716aa-1e00-0000-4590-35f6640d0000 pid=3428->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=faac4eb4-1e00-0000-4590-35f6800d0000 pid=3456->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=e0099abf-1e00-0000-4590-35f6a20d0000 pid=3490 /tmp/SSH write-file zombie guuid=2aa485bf-1e00-0000-4590-35f6a10d0000 pid=3489->guuid=e0099abf-1e00-0000-4590-35f6a20d0000 pid=3490 clone guuid=bdc5b0bf-1e00-0000-4590-35f6a40d0000 pid=3492 /tmp/SSH write-file guuid=e0099abf-1e00-0000-4590-35f6a20d0000 pid=3490->guuid=bdc5b0bf-1e00-0000-4590-35f6a40d0000 pid=3492 clone guuid=fe7cb3bf-1e00-0000-4590-35f6a50d0000 pid=3493 /tmp/SSH write-file zombie guuid=e0099abf-1e00-0000-4590-35f6a20d0000 pid=3490->guuid=fe7cb3bf-1e00-0000-4590-35f6a50d0000 pid=3493 clone guuid=4027afbf-1e00-0000-4590-35f6a30d0000 pid=3491->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=6a04dacd-1e00-0000-4590-35f6c80d0000 pid=3528->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=bbfd17db-1e00-0000-4590-35f6df0d0000 pid=3551 /tmp/SSH write-file zombie guuid=c90bfeda-1e00-0000-4590-35f6de0d0000 pid=3550->guuid=bbfd17db-1e00-0000-4590-35f6df0d0000 pid=3551 clone guuid=5e9631db-1e00-0000-4590-35f6e20d0000 pid=3554 /tmp/SSH write-file guuid=bbfd17db-1e00-0000-4590-35f6df0d0000 pid=3551->guuid=5e9631db-1e00-0000-4590-35f6e20d0000 pid=3554 clone guuid=dbcb36db-1e00-0000-4590-35f6e30d0000 pid=3555 /tmp/SSH write-file zombie guuid=bbfd17db-1e00-0000-4590-35f6df0d0000 pid=3551->guuid=dbcb36db-1e00-0000-4590-35f6e30d0000 pid=3555 clone guuid=a67927db-1e00-0000-4590-35f6e10d0000 pid=3553->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=2ebe8de6-1e00-0000-4590-35f6f00d0000 pid=3568->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=a7fcddf5-1e00-0000-4590-35f6080e0000 pid=3592 /tmp/SSH write-file zombie guuid=3d58bbf5-1e00-0000-4590-35f6060e0000 pid=3590->guuid=a7fcddf5-1e00-0000-4590-35f6080e0000 pid=3592 clone guuid=5cdaf7f5-1e00-0000-4590-35f60a0e0000 pid=3594 /tmp/SSH write-file guuid=a7fcddf5-1e00-0000-4590-35f6080e0000 pid=3592->guuid=5cdaf7f5-1e00-0000-4590-35f60a0e0000 pid=3594 clone guuid=5113fcf5-1e00-0000-4590-35f60b0e0000 pid=3595 /tmp/SSH write-file zombie guuid=a7fcddf5-1e00-0000-4590-35f6080e0000 pid=3592->guuid=5113fcf5-1e00-0000-4590-35f60b0e0000 pid=3595 clone guuid=1b76eff5-1e00-0000-4590-35f6090e0000 pid=3593->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 136B guuid=db1816fe-1e00-0000-4590-35f61d0e0000 pid=3613->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 85B guuid=e7f9a506-1f00-0000-4590-35f6340e0000 pid=3636 /tmp/SSH write-file zombie guuid=f8769006-1f00-0000-4590-35f6330e0000 pid=3635->guuid=e7f9a506-1f00-0000-4590-35f6340e0000 pid=3636 clone guuid=df7fcb06-1f00-0000-4590-35f6370e0000 pid=3639 /tmp/SSH write-file guuid=e7f9a506-1f00-0000-4590-35f6340e0000 pid=3636->guuid=df7fcb06-1f00-0000-4590-35f6370e0000 pid=3639 clone guuid=5573ce06-1f00-0000-4590-35f6380e0000 pid=3640 /tmp/SSH write-file zombie guuid=e7f9a506-1f00-0000-4590-35f6340e0000 pid=3636->guuid=5573ce06-1f00-0000-4590-35f6380e0000 pid=3640 clone guuid=af4aba06-1f00-0000-4590-35f6350e0000 pid=3637->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 135B guuid=133b2211-1f00-0000-4590-35f64b0e0000 pid=3659->ed1ae445-8403-522d-9c55-b54488c1ab36 send: 84B guuid=1898af1c-1f00-0000-4590-35f6600e0000 pid=3680 /tmp/SSH write-file zombie guuid=9c45921c-1f00-0000-4590-35f65e0e0000 pid=3678->guuid=1898af1c-1f00-0000-4590-35f6600e0000 pid=3680 clone guuid=a637bf1c-1f00-0000-4590-35f6610e0000 pid=3681 /tmp/SSH write-file guuid=1898af1c-1f00-0000-4590-35f6600e0000 pid=3680->guuid=a637bf1c-1f00-0000-4590-35f6610e0000 pid=3681 clone guuid=cdd2c31c-1f00-0000-4590-35f6620e0000 pid=3682 /tmp/SSH write-file zombie guuid=1898af1c-1f00-0000-4590-35f6600e0000 pid=3680->guuid=cdd2c31c-1f00-0000-4590-35f6620e0000 pid=3682 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-05-08 18:49:30 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4aca098bdfcd3ff9dc1ba3d15f6f461321c58a3dbb1d688ca731d95eac8e1ffa

(this sample)

  
Delivery method
Distributed via web download

Comments