MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5316df86854e8f99b024a8039843b12275fc3a10c8680d3393e699d735bb4bef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 5316df86854e8f99b024a8039843b12275fc3a10c8680d3393e699d735bb4bef
SHA3-384 hash: c8ce18516ad553edb6d7ca5ca32fe38d948b42aa5f5135b2745c9a5baad942173955fcf4da76efcc4716ce7094ccc73e
SHA1 hash: e8236dd7cbaf78980868bcfb7735976eb3a94e00
MD5 hash: 717411451d46f3aa422d3097e9625fee
humanhash: september-lemon-eleven-bakerloo
File name:test.sh
Download: download sample
Signature Mirai
File size:2'531 bytes
First seen:2025-09-17 15:17:34 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:UITUTbsIidsI3r3U/sIUq0sI1usI+5sI2M2BsISlS0sIvCsIz+sIgaYsIKZ/sIjs:UITUTQIiGI7RIUAI1vI+yI2M2KISKIvU
TLSH T16D5196CD17321F712D529DB672AB4458B3A6A4CBB4890E0798DC38F5C08CE0577D1EE5
Magika csv
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.188.8.180/systemcl/arcn/an/aelf ua-wget
http://64.188.8.180/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Miraielf mirai
http://64.188.8.180/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf mirai
http://64.188.8.180/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf mirai
http://64.188.8.180/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf mirai
http://64.188.8.180/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf mirai
http://64.188.8.180/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Miraielf mirai
http://64.188.8.180/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf mirai
http://64.188.8.180/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf mirai
http://64.188.8.180/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf mirai
http://64.188.8.180/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf mirai
http://64.188.8.180/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Miraielf mirai
http://64.188.8.180/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-17T12:51:00Z UTC
Last seen:
2025-09-17T12:51:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=57555103-1a00-0000-715f-dbb8610d0000 pid=3425 /usr/bin/sudo guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432 /tmp/sample.bin guuid=57555103-1a00-0000-715f-dbb8610d0000 pid=3425->guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432 execve guuid=7a2a3a05-1a00-0000-715f-dbb8690d0000 pid=3433 /usr/bin/wget net send-data guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=7a2a3a05-1a00-0000-715f-dbb8690d0000 pid=3433 execve guuid=d04cf214-1a00-0000-715f-dbb89b0d0000 pid=3483 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=d04cf214-1a00-0000-715f-dbb89b0d0000 pid=3483 execve guuid=c4813a27-1a00-0000-715f-dbb8b60d0000 pid=3510 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=c4813a27-1a00-0000-715f-dbb8b60d0000 pid=3510 execve guuid=7ce49827-1a00-0000-715f-dbb8b70d0000 pid=3511 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=7ce49827-1a00-0000-715f-dbb8b70d0000 pid=3511 execve guuid=46e0ea27-1a00-0000-715f-dbb8b90d0000 pid=3513 /tmp/arc guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=46e0ea27-1a00-0000-715f-dbb8b90d0000 pid=3513 execve guuid=942f3428-1a00-0000-715f-dbb8bb0d0000 pid=3515 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=942f3428-1a00-0000-715f-dbb8bb0d0000 pid=3515 execve guuid=0318a328-1a00-0000-715f-dbb8bc0d0000 pid=3516 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=0318a328-1a00-0000-715f-dbb8bc0d0000 pid=3516 execve guuid=2eded63b-1a00-0000-715f-dbb8e70d0000 pid=3559 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=2eded63b-1a00-0000-715f-dbb8e70d0000 pid=3559 execve guuid=32776052-1a00-0000-715f-dbb8160e0000 pid=3606 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=32776052-1a00-0000-715f-dbb8160e0000 pid=3606 execve guuid=cc71c052-1a00-0000-715f-dbb8170e0000 pid=3607 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=cc71c052-1a00-0000-715f-dbb8170e0000 pid=3607 execve guuid=650d2853-1a00-0000-715f-dbb8180e0000 pid=3608 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=650d2853-1a00-0000-715f-dbb8180e0000 pid=3608 clone guuid=67c3e553-1a00-0000-715f-dbb81b0e0000 pid=3611 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=67c3e553-1a00-0000-715f-dbb81b0e0000 pid=3611 execve guuid=eb554254-1a00-0000-715f-dbb81d0e0000 pid=3613 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=eb554254-1a00-0000-715f-dbb81d0e0000 pid=3613 execve guuid=0d98f968-1a00-0000-715f-dbb8540e0000 pid=3668 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=0d98f968-1a00-0000-715f-dbb8540e0000 pid=3668 execve guuid=dd8d9f7f-1a00-0000-715f-dbb8650e0000 pid=3685 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=dd8d9f7f-1a00-0000-715f-dbb8650e0000 pid=3685 execve guuid=2e7eff7f-1a00-0000-715f-dbb8660e0000 pid=3686 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=2e7eff7f-1a00-0000-715f-dbb8660e0000 pid=3686 execve guuid=08c54780-1a00-0000-715f-dbb8670e0000 pid=3687 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=08c54780-1a00-0000-715f-dbb8670e0000 pid=3687 clone guuid=f3c9fb80-1a00-0000-715f-dbb8690e0000 pid=3689 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=f3c9fb80-1a00-0000-715f-dbb8690e0000 pid=3689 execve guuid=daa35681-1a00-0000-715f-dbb86a0e0000 pid=3690 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=daa35681-1a00-0000-715f-dbb86a0e0000 pid=3690 execve guuid=50ed4b9a-1a00-0000-715f-dbb8bd0e0000 pid=3773 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=50ed4b9a-1a00-0000-715f-dbb8bd0e0000 pid=3773 execve guuid=b8498fb6-1a00-0000-715f-dbb8180f0000 pid=3864 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=b8498fb6-1a00-0000-715f-dbb8180f0000 pid=3864 execve guuid=545a05b7-1a00-0000-715f-dbb81b0f0000 pid=3867 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=545a05b7-1a00-0000-715f-dbb81b0f0000 pid=3867 execve guuid=1c9c5db7-1a00-0000-715f-dbb81d0f0000 pid=3869 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=1c9c5db7-1a00-0000-715f-dbb81d0f0000 pid=3869 clone guuid=596a50b8-1a00-0000-715f-dbb8200f0000 pid=3872 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=596a50b8-1a00-0000-715f-dbb8200f0000 pid=3872 execve guuid=46b2bfba-1a00-0000-715f-dbb82a0f0000 pid=3882 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=46b2bfba-1a00-0000-715f-dbb82a0f0000 pid=3882 execve guuid=c10789d3-1a00-0000-715f-dbb8770f0000 pid=3959 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=c10789d3-1a00-0000-715f-dbb8770f0000 pid=3959 execve guuid=25d93ded-1a00-0000-715f-dbb8c40f0000 pid=4036 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=25d93ded-1a00-0000-715f-dbb8c40f0000 pid=4036 execve guuid=397dc2ed-1a00-0000-715f-dbb8c50f0000 pid=4037 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=397dc2ed-1a00-0000-715f-dbb8c50f0000 pid=4037 execve guuid=ac822cee-1a00-0000-715f-dbb8c70f0000 pid=4039 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=ac822cee-1a00-0000-715f-dbb8c70f0000 pid=4039 clone guuid=228be3ee-1a00-0000-715f-dbb8cb0f0000 pid=4043 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=228be3ee-1a00-0000-715f-dbb8cb0f0000 pid=4043 execve guuid=73a9a3f1-1a00-0000-715f-dbb8d40f0000 pid=4052 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=73a9a3f1-1a00-0000-715f-dbb8d40f0000 pid=4052 execve guuid=727ab00b-1b00-0000-715f-dbb81b100000 pid=4123 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=727ab00b-1b00-0000-715f-dbb81b100000 pid=4123 execve guuid=a41d2d28-1b00-0000-715f-dbb864100000 pid=4196 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=a41d2d28-1b00-0000-715f-dbb864100000 pid=4196 execve guuid=6a099d28-1b00-0000-715f-dbb866100000 pid=4198 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=6a099d28-1b00-0000-715f-dbb866100000 pid=4198 execve guuid=ac133629-1b00-0000-715f-dbb867100000 pid=4199 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=ac133629-1b00-0000-715f-dbb867100000 pid=4199 clone guuid=0dc0e829-1b00-0000-715f-dbb86c100000 pid=4204 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=0dc0e829-1b00-0000-715f-dbb86c100000 pid=4204 execve guuid=4884422a-1b00-0000-715f-dbb870100000 pid=4208 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=4884422a-1b00-0000-715f-dbb870100000 pid=4208 execve guuid=e334d345-1b00-0000-715f-dbb8cb100000 pid=4299 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=e334d345-1b00-0000-715f-dbb8cb100000 pid=4299 execve guuid=797f307d-1b00-0000-715f-dbb811110000 pid=4369 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=797f307d-1b00-0000-715f-dbb811110000 pid=4369 execve guuid=c38fae7d-1b00-0000-715f-dbb814110000 pid=4372 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=c38fae7d-1b00-0000-715f-dbb814110000 pid=4372 execve guuid=9e5a137e-1b00-0000-715f-dbb815110000 pid=4373 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=9e5a137e-1b00-0000-715f-dbb815110000 pid=4373 clone guuid=14ddbe7e-1b00-0000-715f-dbb81b110000 pid=4379 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=14ddbe7e-1b00-0000-715f-dbb81b110000 pid=4379 execve guuid=ebb9007f-1b00-0000-715f-dbb81d110000 pid=4381 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=ebb9007f-1b00-0000-715f-dbb81d110000 pid=4381 execve guuid=6e9dc597-1b00-0000-715f-dbb87e110000 pid=4478 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=6e9dc597-1b00-0000-715f-dbb87e110000 pid=4478 execve guuid=d164b6b2-1b00-0000-715f-dbb8d2110000 pid=4562 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=d164b6b2-1b00-0000-715f-dbb8d2110000 pid=4562 execve guuid=1e06eeb2-1b00-0000-715f-dbb8d3110000 pid=4563 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=1e06eeb2-1b00-0000-715f-dbb8d3110000 pid=4563 execve guuid=185f6eb3-1b00-0000-715f-dbb8d7110000 pid=4567 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=185f6eb3-1b00-0000-715f-dbb8d7110000 pid=4567 clone guuid=5595f7b3-1b00-0000-715f-dbb8dc110000 pid=4572 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=5595f7b3-1b00-0000-715f-dbb8dc110000 pid=4572 execve guuid=f5ab36b4-1b00-0000-715f-dbb8de110000 pid=4574 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=f5ab36b4-1b00-0000-715f-dbb8de110000 pid=4574 execve guuid=ea3df8c7-1b00-0000-715f-dbb83e120000 pid=4670 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=ea3df8c7-1b00-0000-715f-dbb83e120000 pid=4670 execve guuid=2b5b05dd-1b00-0000-715f-dbb884120000 pid=4740 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=2b5b05dd-1b00-0000-715f-dbb884120000 pid=4740 execve guuid=738855dd-1b00-0000-715f-dbb886120000 pid=4742 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=738855dd-1b00-0000-715f-dbb886120000 pid=4742 execve guuid=e9d5b5dd-1b00-0000-715f-dbb888120000 pid=4744 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=e9d5b5dd-1b00-0000-715f-dbb888120000 pid=4744 clone guuid=7c5483de-1b00-0000-715f-dbb88e120000 pid=4750 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=7c5483de-1b00-0000-715f-dbb88e120000 pid=4750 execve guuid=faf3c1e3-1b00-0000-715f-dbb8a0120000 pid=4768 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=faf3c1e3-1b00-0000-715f-dbb8a0120000 pid=4768 execve guuid=a86110fe-1b00-0000-715f-dbb8f1120000 pid=4849 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=a86110fe-1b00-0000-715f-dbb8f1120000 pid=4849 execve guuid=f64a0e19-1c00-0000-715f-dbb842130000 pid=4930 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=f64a0e19-1c00-0000-715f-dbb842130000 pid=4930 execve guuid=096c4b19-1c00-0000-715f-dbb843130000 pid=4931 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=096c4b19-1c00-0000-715f-dbb843130000 pid=4931 execve guuid=d1589019-1c00-0000-715f-dbb845130000 pid=4933 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=d1589019-1c00-0000-715f-dbb845130000 pid=4933 clone guuid=5085391a-1c00-0000-715f-dbb849130000 pid=4937 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=5085391a-1c00-0000-715f-dbb849130000 pid=4937 execve guuid=ac58941a-1c00-0000-715f-dbb84b130000 pid=4939 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=ac58941a-1c00-0000-715f-dbb84b130000 pid=4939 execve guuid=c956e434-1c00-0000-715f-dbb894130000 pid=5012 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=c956e434-1c00-0000-715f-dbb894130000 pid=5012 execve guuid=96c4de50-1c00-0000-715f-dbb8ee130000 pid=5102 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=96c4de50-1c00-0000-715f-dbb8ee130000 pid=5102 execve guuid=fe024b51-1c00-0000-715f-dbb8f2130000 pid=5106 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=fe024b51-1c00-0000-715f-dbb8f2130000 pid=5106 execve guuid=240c8c51-1c00-0000-715f-dbb8f3130000 pid=5107 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=240c8c51-1c00-0000-715f-dbb8f3130000 pid=5107 clone guuid=8ca51152-1c00-0000-715f-dbb8f6130000 pid=5110 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=8ca51152-1c00-0000-715f-dbb8f6130000 pid=5110 execve guuid=f1fa5352-1c00-0000-715f-dbb8f8130000 pid=5112 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=f1fa5352-1c00-0000-715f-dbb8f8130000 pid=5112 execve guuid=da5a5666-1c00-0000-715f-dbb83f140000 pid=5183 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=da5a5666-1c00-0000-715f-dbb83f140000 pid=5183 execve guuid=76ebf67c-1c00-0000-715f-dbb86b140000 pid=5227 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=76ebf67c-1c00-0000-715f-dbb86b140000 pid=5227 execve guuid=f747537d-1c00-0000-715f-dbb86d140000 pid=5229 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=f747537d-1c00-0000-715f-dbb86d140000 pid=5229 execve guuid=e3e3b07d-1c00-0000-715f-dbb86f140000 pid=5231 /tmp/x86 net write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=e3e3b07d-1c00-0000-715f-dbb86f140000 pid=5231 execve guuid=960baf8c-1c00-0000-715f-dbb8af140000 pid=5295 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=960baf8c-1c00-0000-715f-dbb8af140000 pid=5295 execve guuid=3f20ed8c-1c00-0000-715f-dbb8b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=3f20ed8c-1c00-0000-715f-dbb8b0140000 pid=5296 execve guuid=bebe3bad-1c00-0000-715f-dbb8bc140000 pid=5308 /usr/bin/curl net send-data write-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=bebe3bad-1c00-0000-715f-dbb8bc140000 pid=5308 execve guuid=57c8d9cd-1c00-0000-715f-dbb8bd140000 pid=5309 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=57c8d9cd-1c00-0000-715f-dbb8bd140000 pid=5309 execve guuid=af1a26ce-1c00-0000-715f-dbb8be140000 pid=5310 /usr/bin/chmod guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=af1a26ce-1c00-0000-715f-dbb8be140000 pid=5310 execve guuid=e9026dce-1c00-0000-715f-dbb8bf140000 pid=5311 /usr/bin/dash guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=e9026dce-1c00-0000-715f-dbb8bf140000 pid=5311 clone guuid=b3e10acf-1c00-0000-715f-dbb8c1140000 pid=5313 /usr/bin/rm delete-file guuid=b6ff0505-1a00-0000-715f-dbb8680d0000 pid=3432->guuid=b3e10acf-1c00-0000-715f-dbb8c1140000 pid=5313 execve 8edd4ccf-0a06-5311-990b-64f0702ebcd6 64.188.8.180:80 guuid=7a2a3a05-1a00-0000-715f-dbb8690d0000 pid=3433->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=d04cf214-1a00-0000-715f-dbb89b0d0000 pid=3483->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B guuid=0318a328-1a00-0000-715f-dbb8bc0d0000 pid=3516->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=2eded63b-1a00-0000-715f-dbb8e70d0000 pid=3559->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B guuid=eb554254-1a00-0000-715f-dbb81d0e0000 pid=3613->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=0d98f968-1a00-0000-715f-dbb8540e0000 pid=3668->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=daa35681-1a00-0000-715f-dbb86a0e0000 pid=3690->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=50ed4b9a-1a00-0000-715f-dbb8bd0e0000 pid=3773->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=46b2bfba-1a00-0000-715f-dbb82a0f0000 pid=3882->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=c10789d3-1a00-0000-715f-dbb8770f0000 pid=3959->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=73a9a3f1-1a00-0000-715f-dbb8d40f0000 pid=4052->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=727ab00b-1b00-0000-715f-dbb81b100000 pid=4123->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=4884422a-1b00-0000-715f-dbb870100000 pid=4208->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=e334d345-1b00-0000-715f-dbb8cb100000 pid=4299->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=ebb9007f-1b00-0000-715f-dbb81d110000 pid=4381->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 140B guuid=6e9dc597-1b00-0000-715f-dbb87e110000 pid=4478->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 89B guuid=f5ab36b4-1b00-0000-715f-dbb8de110000 pid=4574->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=ea3df8c7-1b00-0000-715f-dbb83e120000 pid=4670->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B guuid=faf3c1e3-1b00-0000-715f-dbb8a0120000 pid=4768->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=a86110fe-1b00-0000-715f-dbb8f1120000 pid=4849->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B guuid=ac58941a-1c00-0000-715f-dbb84b130000 pid=4939->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=c956e434-1c00-0000-715f-dbb894130000 pid=5012->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B guuid=f1fa5352-1c00-0000-715f-dbb8f8130000 pid=5112->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 139B guuid=da5a5666-1c00-0000-715f-dbb83f140000 pid=5183->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e3e3b07d-1c00-0000-715f-dbb86f140000 pid=5231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1400a08c-1c00-0000-715f-dbb8ad140000 pid=5293 /tmp/x86 guuid=e3e3b07d-1c00-0000-715f-dbb86f140000 pid=5231->guuid=1400a08c-1c00-0000-715f-dbb8ad140000 pid=5293 clone guuid=f336a48c-1c00-0000-715f-dbb8ae140000 pid=5294 /tmp/x86 net send-data zombie guuid=e3e3b07d-1c00-0000-715f-dbb86f140000 pid=5231->guuid=f336a48c-1c00-0000-715f-dbb8ae140000 pid=5294 clone guuid=f336a48c-1c00-0000-715f-dbb8ae140000 pid=5294->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b 87.121.84.220:61459 guuid=f336a48c-1c00-0000-715f-dbb8ae140000 pid=5294->dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b send: 43B guuid=3f20ed8c-1c00-0000-715f-dbb8b0140000 pid=5296->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 142B guuid=bebe3bad-1c00-0000-715f-dbb8bc140000 pid=5308->8edd4ccf-0a06-5311-990b-64f0702ebcd6 send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-17 14:57:23 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5316df86854e8f99b024a8039843b12275fc3a10c8680d3393e699d735bb4bef

(this sample)

  
Delivery method
Distributed via web download

Comments