MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5af6d3884a0e1197228a031050a4251ef7c5b547502c1bdc71fcb93c7ce5df9a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 5af6d3884a0e1197228a031050a4251ef7c5b547502c1bdc71fcb93c7ce5df9a
SHA3-384 hash: 12064c2f24425defda3e33dd2d83437b77fb17fe27a6cff948fea8998258b23546bca87354d20d04e9734d6e5bd2848b
SHA1 hash: 3cdf3420e94f24168b093bd8c476ca859b62b4bb
MD5 hash: 36007d92555fdda295272c64eca86668
humanhash: double-lactose-lithium-steak
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'754 bytes
First seen:2025-11-18 16:45:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:ij393cx3e3M38B3aE353u3l3k3e3S3b3Swz:Utsxu8MBrpeVUuCLiW
TLSH T1277162B6CA1211BC1C555B62ADBA21EBF085F3E234E7B70F758828F8618DF025885DD2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.arc4db7b2a2962f3bd34717d00af3cb9fd1992b71f637c36ae64cbf01badf1d6da1 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.x865c9263ff6894534d5daf19a0d03526b161121b46acadc9a32ad54326b633fa72 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.x86_6465d79a80749a44472b5c6a0a40e8e3b9bf43df31746163a1b1c4b7e4f69d5d08 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.i686fa8fe904c13604c733f5f75be1049a859adc1b002b59b960e5b83c990d80d7c9 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips70dc29c0909dcaf00bb882b3c06b474cf45a2c5a77a7b1bbd681c96dd1a18fea Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips64n/an/aelf ua-wget
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.mpsl5b355f440e303cc72f46896c4b0989c67e1571a112806c775d42acf5ada2bbef Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.armb53bab74037498c676a6e57bb21cb5c01c2563ba4be5fc8fbe5fa6f18a9fd7c8 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm550f43384eb6f7d1bdd2ce1ab3af60bfa074377b2f82a4334d08e31b1ca2ead70 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm6d18be78197adc4b19e20b6a3e7c782c6b2dd486e02c8a0fcccbed1723e2828c5 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm79b5bd88d60a84bbf17e1740cd3e09691200dfd8c2ce09bad9023630ccafcd0ad Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.ppce177db508ce5a9eaa9b8ab4bcc9aecb8566c1331a47cf120183722294fefdb54 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.sparcn/an/aelf ua-wget
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.m68kcfeca24f7253593c460581183712e266012dba2450dea0408e762bc57b6169e7 Miraimirai opendir
http://45.83.207.191/HideChaotic/ub8ehJSePAfc9FYqZIT6.sh46b35f6e4bfceb854b6b50e38f125a751b9f4102cb0ffb52a9d31c8a05d10174f Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-17T17:06:00Z UTC
Last seen:
2025-11-19T18:18:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4f8f3ddf-1800-0000-1f73-ac42ad080000 pid=2221 /usr/bin/sudo guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229 /tmp/sample.bin guuid=4f8f3ddf-1800-0000-1f73-ac42ad080000 pid=2221->guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229 execve guuid=aa7f38e3-1800-0000-1f73-ac42b9080000 pid=2233 /usr/bin/cp guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=aa7f38e3-1800-0000-1f73-ac42b9080000 pid=2233 execve guuid=ae8983ea-1800-0000-1f73-ac42c7080000 pid=2247 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=ae8983ea-1800-0000-1f73-ac42c7080000 pid=2247 execve guuid=0922a444-1900-0000-1f73-ac425e090000 pid=2398 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=0922a444-1900-0000-1f73-ac425e090000 pid=2398 execve guuid=144c689e-1900-0000-1f73-ac422d0a0000 pid=2605 /usr/bin/cat guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=144c689e-1900-0000-1f73-ac422d0a0000 pid=2605 execve guuid=3764ca9e-1900-0000-1f73-ac422f0a0000 pid=2607 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=3764ca9e-1900-0000-1f73-ac422f0a0000 pid=2607 execve guuid=fc45699f-1900-0000-1f73-ac42310a0000 pid=2609 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=fc45699f-1900-0000-1f73-ac42310a0000 pid=2609 clone guuid=53754ca0-1900-0000-1f73-ac42360a0000 pid=2614 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=53754ca0-1900-0000-1f73-ac42360a0000 pid=2614 execve guuid=c7c84fcd-1900-0000-1f73-ac42b80a0000 pid=2744 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=c7c84fcd-1900-0000-1f73-ac42b80a0000 pid=2744 execve guuid=125deef1-1900-0000-1f73-ac42f50a0000 pid=2805 /usr/bin/cat guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=125deef1-1900-0000-1f73-ac42f50a0000 pid=2805 execve guuid=3c6762f2-1900-0000-1f73-ac42f60a0000 pid=2806 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=3c6762f2-1900-0000-1f73-ac42f60a0000 pid=2806 execve guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807 execve guuid=9cd6ef1f-1b00-0000-1f73-ac42060d0000 pid=3334 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=9cd6ef1f-1b00-0000-1f73-ac42060d0000 pid=3334 execve guuid=f7368459-1b00-0000-1f73-ac426a0d0000 pid=3434 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=f7368459-1b00-0000-1f73-ac426a0d0000 pid=3434 execve guuid=0d56f67d-1b00-0000-1f73-ac42b40d0000 pid=3508 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=0d56f67d-1b00-0000-1f73-ac42b40d0000 pid=3508 clone guuid=bbda287e-1b00-0000-1f73-ac42b50d0000 pid=3509 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=bbda287e-1b00-0000-1f73-ac42b50d0000 pid=3509 execve guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510 execve guuid=004239ac-1c00-0000-1f73-ac42d5100000 pid=4309 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=004239ac-1c00-0000-1f73-ac42d5100000 pid=4309 execve guuid=50ad5bd5-1c00-0000-1f73-ac4224110000 pid=4388 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=50ad5bd5-1c00-0000-1f73-ac4224110000 pid=4388 execve guuid=fd327009-1d00-0000-1f73-ac42bc110000 pid=4540 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=fd327009-1d00-0000-1f73-ac42bc110000 pid=4540 clone guuid=5e368c09-1d00-0000-1f73-ac42bd110000 pid=4541 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=5e368c09-1d00-0000-1f73-ac42bd110000 pid=4541 execve guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545 execve guuid=a8b5be36-1e00-0000-1f73-ac428b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=a8b5be36-1e00-0000-1f73-ac428b140000 pid=5259 execve guuid=17322c69-1e00-0000-1f73-ac428c140000 pid=5260 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=17322c69-1e00-0000-1f73-ac428c140000 pid=5260 execve guuid=08d9abc0-1e00-0000-1f73-ac428d140000 pid=5261 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=08d9abc0-1e00-0000-1f73-ac428d140000 pid=5261 clone guuid=ef49d4c0-1e00-0000-1f73-ac428e140000 pid=5262 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=ef49d4c0-1e00-0000-1f73-ac428e140000 pid=5262 execve guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263 execve guuid=09386eef-1f00-0000-1f73-ac429c140000 pid=5276 /usr/bin/wget net send-data guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=09386eef-1f00-0000-1f73-ac429c140000 pid=5276 execve guuid=6238c10f-2000-0000-1f73-ac429d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=6238c10f-2000-0000-1f73-ac429d140000 pid=5277 execve guuid=77b17637-2000-0000-1f73-ac42a4140000 pid=5284 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=77b17637-2000-0000-1f73-ac42a4140000 pid=5284 clone guuid=13a79237-2000-0000-1f73-ac42a5140000 pid=5285 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=13a79237-2000-0000-1f73-ac42a5140000 pid=5285 execve guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286 execve guuid=41143164-2100-0000-1f73-ac42c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=41143164-2100-0000-1f73-ac42c6140000 pid=5318 execve guuid=aa84ab88-2100-0000-1f73-ac42c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=aa84ab88-2100-0000-1f73-ac42c7140000 pid=5319 execve guuid=724a3cbd-2100-0000-1f73-ac42c8140000 pid=5320 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=724a3cbd-2100-0000-1f73-ac42c8140000 pid=5320 clone guuid=22b87ebd-2100-0000-1f73-ac42c9140000 pid=5321 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=22b87ebd-2100-0000-1f73-ac42c9140000 pid=5321 execve guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322 execve guuid=f37c9cec-2200-0000-1f73-ac42d0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=f37c9cec-2200-0000-1f73-ac42d0140000 pid=5328 execve guuid=0142f41e-2300-0000-1f73-ac42d1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=0142f41e-2300-0000-1f73-ac42d1140000 pid=5329 execve guuid=9c4b4353-2300-0000-1f73-ac42d2140000 pid=5330 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=9c4b4353-2300-0000-1f73-ac42d2140000 pid=5330 clone guuid=42cc8653-2300-0000-1f73-ac42d3140000 pid=5331 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=42cc8653-2300-0000-1f73-ac42d3140000 pid=5331 execve guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332 execve guuid=43278582-2400-0000-1f73-ac42da140000 pid=5338 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=43278582-2400-0000-1f73-ac42da140000 pid=5338 execve guuid=e49dedd5-2400-0000-1f73-ac42db140000 pid=5339 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=e49dedd5-2400-0000-1f73-ac42db140000 pid=5339 execve guuid=df527d06-2500-0000-1f73-ac42dc140000 pid=5340 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=df527d06-2500-0000-1f73-ac42dc140000 pid=5340 clone guuid=321ebf06-2500-0000-1f73-ac42dd140000 pid=5341 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=321ebf06-2500-0000-1f73-ac42dd140000 pid=5341 execve guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342 execve guuid=a460d435-2600-0000-1f73-ac42e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=a460d435-2600-0000-1f73-ac42e4140000 pid=5348 execve guuid=d3c89f8c-2600-0000-1f73-ac42e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=d3c89f8c-2600-0000-1f73-ac42e5140000 pid=5349 execve guuid=262687bf-2600-0000-1f73-ac42e7140000 pid=5351 /usr/bin/bash guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=262687bf-2600-0000-1f73-ac42e7140000 pid=5351 clone guuid=5385b5bf-2600-0000-1f73-ac42e8140000 pid=5352 /usr/bin/chmod guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=5385b5bf-2600-0000-1f73-ac42e8140000 pid=5352 execve guuid=0cb042c0-2600-0000-1f73-ac42ea140000 pid=5354 /tmp/Chaotic net guuid=bafc06e2-1800-0000-1f73-ac42b5080000 pid=2229->guuid=0cb042c0-2600-0000-1f73-ac42ea140000 pid=5354 execve 4b145f03-a0d5-5492-815a-c3ca0d11fe3c 45.83.207.191:80 guuid=ae8983ea-1800-0000-1f73-ac42c7080000 pid=2247->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 164B guuid=0922a444-1900-0000-1f73-ac425e090000 pid=2398->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 113B guuid=53754ca0-1900-0000-1f73-ac42360a0000 pid=2614->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 164B guuid=c7c84fcd-1900-0000-1f73-ac42b80a0000 pid=2744->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 113B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e53663f3-1900-0000-1f73-ac42fa0a0000 pid=2810 /tmp/Chaotic guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807->guuid=e53663f3-1900-0000-1f73-ac42fa0a0000 pid=2810 clone guuid=74f6c61f-1b00-0000-1f73-ac42030d0000 pid=3331 /tmp/Chaotic guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807->guuid=74f6c61f-1b00-0000-1f73-ac42030d0000 pid=3331 clone guuid=c3fad31f-1b00-0000-1f73-ac42040d0000 pid=3332 /tmp/Chaotic net send-data zombie guuid=4ebcbbf2-1900-0000-1f73-ac42f70a0000 pid=2807->guuid=c3fad31f-1b00-0000-1f73-ac42040d0000 pid=3332 clone guuid=905b85f3-1900-0000-1f73-ac42fb0a0000 pid=2811 /tmp/Chaotic guuid=e53663f3-1900-0000-1f73-ac42fa0a0000 pid=2810->guuid=905b85f3-1900-0000-1f73-ac42fb0a0000 pid=2811 clone guuid=447c88f3-1900-0000-1f73-ac42fc0a0000 pid=2812 /tmp/Chaotic net send-data zombie guuid=e53663f3-1900-0000-1f73-ac42fa0a0000 pid=2810->guuid=447c88f3-1900-0000-1f73-ac42fc0a0000 pid=2812 clone guuid=447c88f3-1900-0000-1f73-ac42fc0a0000 pid=2812->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 45.83.207.191:3778 guuid=447c88f3-1900-0000-1f73-ac42fc0a0000 pid=2812->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=c3fad31f-1b00-0000-1f73-ac42040d0000 pid=3332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c3fad31f-1b00-0000-1f73-ac42040d0000 pid=3332->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=9cd6ef1f-1b00-0000-1f73-ac42060d0000 pid=3334->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 167B guuid=f7368459-1b00-0000-1f73-ac426a0d0000 pid=3434->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 116B guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8c8b617f-1b00-0000-1f73-ac42b70d0000 pid=3511 /tmp/Chaotic guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510->guuid=8c8b617f-1b00-0000-1f73-ac42b70d0000 pid=3511 clone guuid=26e417ac-1c00-0000-1f73-ac42d3100000 pid=4307 /tmp/Chaotic guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510->guuid=26e417ac-1c00-0000-1f73-ac42d3100000 pid=4307 clone guuid=06e32aac-1c00-0000-1f73-ac42d4100000 pid=4308 /tmp/Chaotic net send-data zombie guuid=e67a9b7e-1b00-0000-1f73-ac42b60d0000 pid=3510->guuid=06e32aac-1c00-0000-1f73-ac42d4100000 pid=4308 clone guuid=f1ab697f-1b00-0000-1f73-ac42b80d0000 pid=3512 /tmp/Chaotic guuid=8c8b617f-1b00-0000-1f73-ac42b70d0000 pid=3511->guuid=f1ab697f-1b00-0000-1f73-ac42b80d0000 pid=3512 clone guuid=5603707f-1b00-0000-1f73-ac42b90d0000 pid=3513 /tmp/Chaotic net send-data zombie guuid=8c8b617f-1b00-0000-1f73-ac42b70d0000 pid=3511->guuid=5603707f-1b00-0000-1f73-ac42b90d0000 pid=3513 clone guuid=5603707f-1b00-0000-1f73-ac42b90d0000 pid=3513->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5603707f-1b00-0000-1f73-ac42b90d0000 pid=3513->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=06e32aac-1c00-0000-1f73-ac42d4100000 pid=4308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06e32aac-1c00-0000-1f73-ac42d4100000 pid=4308->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=004239ac-1c00-0000-1f73-ac42d5100000 pid=4309->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 165B guuid=50ad5bd5-1c00-0000-1f73-ac4224110000 pid=4388->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 114B guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06d0790a-1d00-0000-1f73-ac42c5110000 pid=4549 /tmp/Chaotic guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545->guuid=06d0790a-1d00-0000-1f73-ac42c5110000 pid=4549 clone guuid=1e28a736-1e00-0000-1f73-ac4289140000 pid=5257 /tmp/Chaotic guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545->guuid=1e28a736-1e00-0000-1f73-ac4289140000 pid=5257 clone guuid=9c18af36-1e00-0000-1f73-ac428a140000 pid=5258 /tmp/Chaotic net send-data zombie guuid=63c4e209-1d00-0000-1f73-ac42c1110000 pid=4545->guuid=9c18af36-1e00-0000-1f73-ac428a140000 pid=5258 clone guuid=3ff3800a-1d00-0000-1f73-ac42c6110000 pid=4550 /tmp/Chaotic guuid=06d0790a-1d00-0000-1f73-ac42c5110000 pid=4549->guuid=3ff3800a-1d00-0000-1f73-ac42c6110000 pid=4550 clone guuid=512a870a-1d00-0000-1f73-ac42c7110000 pid=4551 /tmp/Chaotic net send-data zombie guuid=06d0790a-1d00-0000-1f73-ac42c5110000 pid=4549->guuid=512a870a-1d00-0000-1f73-ac42c7110000 pid=4551 clone guuid=512a870a-1d00-0000-1f73-ac42c7110000 pid=4551->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=512a870a-1d00-0000-1f73-ac42c7110000 pid=4551->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=9c18af36-1e00-0000-1f73-ac428a140000 pid=5258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9c18af36-1e00-0000-1f73-ac428a140000 pid=5258->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=a8b5be36-1e00-0000-1f73-ac428b140000 pid=5259->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 165B guuid=17322c69-1e00-0000-1f73-ac428c140000 pid=5260->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 114B guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=788b43c2-1e00-0000-1f73-ac4290140000 pid=5264 /tmp/Chaotic guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263->guuid=788b43c2-1e00-0000-1f73-ac4290140000 pid=5264 clone guuid=058704ef-1f00-0000-1f73-ac429a140000 pid=5274 /tmp/Chaotic guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263->guuid=058704ef-1f00-0000-1f73-ac429a140000 pid=5274 clone guuid=d9870eef-1f00-0000-1f73-ac429b140000 pid=5275 /tmp/Chaotic net send-data zombie guuid=fc646ac1-1e00-0000-1f73-ac428f140000 pid=5263->guuid=d9870eef-1f00-0000-1f73-ac429b140000 pid=5275 clone guuid=64034dc2-1e00-0000-1f73-ac4291140000 pid=5265 /tmp/Chaotic guuid=788b43c2-1e00-0000-1f73-ac4290140000 pid=5264->guuid=64034dc2-1e00-0000-1f73-ac4291140000 pid=5265 clone guuid=3b5155c2-1e00-0000-1f73-ac4292140000 pid=5266 /tmp/Chaotic net send-data zombie guuid=788b43c2-1e00-0000-1f73-ac4290140000 pid=5264->guuid=3b5155c2-1e00-0000-1f73-ac4292140000 pid=5266 clone guuid=3b5155c2-1e00-0000-1f73-ac4292140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3b5155c2-1e00-0000-1f73-ac4292140000 pid=5266->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=d9870eef-1f00-0000-1f73-ac429b140000 pid=5275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d9870eef-1f00-0000-1f73-ac429b140000 pid=5275->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=09386eef-1f00-0000-1f73-ac429c140000 pid=5276->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 167B guuid=6238c10f-2000-0000-1f73-ac429d140000 pid=5277->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 116B guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aa264338-2000-0000-1f73-ac42a7140000 pid=5287 /tmp/Chaotic guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286->guuid=aa264338-2000-0000-1f73-ac42a7140000 pid=5287 clone guuid=1fa61a64-2100-0000-1f73-ac42c4140000 pid=5316 /tmp/Chaotic guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286->guuid=1fa61a64-2100-0000-1f73-ac42c4140000 pid=5316 clone guuid=ce2a2264-2100-0000-1f73-ac42c5140000 pid=5317 /tmp/Chaotic net send-data zombie guuid=d104d437-2000-0000-1f73-ac42a6140000 pid=5286->guuid=ce2a2264-2100-0000-1f73-ac42c5140000 pid=5317 clone guuid=1ea54b38-2000-0000-1f73-ac42a8140000 pid=5288 /tmp/Chaotic guuid=aa264338-2000-0000-1f73-ac42a7140000 pid=5287->guuid=1ea54b38-2000-0000-1f73-ac42a8140000 pid=5288 clone guuid=cc815338-2000-0000-1f73-ac42a9140000 pid=5289 /tmp/Chaotic net send-data zombie guuid=aa264338-2000-0000-1f73-ac42a7140000 pid=5287->guuid=cc815338-2000-0000-1f73-ac42a9140000 pid=5289 clone guuid=cc815338-2000-0000-1f73-ac42a9140000 pid=5289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cc815338-2000-0000-1f73-ac42a9140000 pid=5289->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=ce2a2264-2100-0000-1f73-ac42c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce2a2264-2100-0000-1f73-ac42c5140000 pid=5317->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=41143164-2100-0000-1f73-ac42c6140000 pid=5318->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 165B guuid=aa84ab88-2100-0000-1f73-ac42c7140000 pid=5319->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 114B guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf2603bf-2100-0000-1f73-ac42cb140000 pid=5323 /tmp/Chaotic guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322->guuid=cf2603bf-2100-0000-1f73-ac42cb140000 pid=5323 clone guuid=1e9583ec-2200-0000-1f73-ac42ce140000 pid=5326 /tmp/Chaotic guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322->guuid=1e9583ec-2200-0000-1f73-ac42ce140000 pid=5326 clone guuid=61bd88ec-2200-0000-1f73-ac42cf140000 pid=5327 /tmp/Chaotic net send-data zombie guuid=81fb0cbe-2100-0000-1f73-ac42ca140000 pid=5322->guuid=61bd88ec-2200-0000-1f73-ac42cf140000 pid=5327 clone guuid=48e70ebf-2100-0000-1f73-ac42cc140000 pid=5324 /tmp/Chaotic guuid=cf2603bf-2100-0000-1f73-ac42cb140000 pid=5323->guuid=48e70ebf-2100-0000-1f73-ac42cc140000 pid=5324 clone guuid=a28a1ebf-2100-0000-1f73-ac42cd140000 pid=5325 /tmp/Chaotic net send-data zombie guuid=cf2603bf-2100-0000-1f73-ac42cb140000 pid=5323->guuid=a28a1ebf-2100-0000-1f73-ac42cd140000 pid=5325 clone guuid=a28a1ebf-2100-0000-1f73-ac42cd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a28a1ebf-2100-0000-1f73-ac42cd140000 pid=5325->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=61bd88ec-2200-0000-1f73-ac42cf140000 pid=5327->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=61bd88ec-2200-0000-1f73-ac42cf140000 pid=5327->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=f37c9cec-2200-0000-1f73-ac42d0140000 pid=5328->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 164B guuid=0142f41e-2300-0000-1f73-ac42d1140000 pid=5329->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 113B guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9f1e3155-2300-0000-1f73-ac42d5140000 pid=5333 /tmp/Chaotic guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332->guuid=9f1e3155-2300-0000-1f73-ac42d5140000 pid=5333 clone guuid=fabb5d82-2400-0000-1f73-ac42d8140000 pid=5336 /tmp/Chaotic guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332->guuid=fabb5d82-2400-0000-1f73-ac42d8140000 pid=5336 clone guuid=b0c66782-2400-0000-1f73-ac42d9140000 pid=5337 /tmp/Chaotic net send-data zombie guuid=3c614154-2300-0000-1f73-ac42d4140000 pid=5332->guuid=b0c66782-2400-0000-1f73-ac42d9140000 pid=5337 clone guuid=b61f3f55-2300-0000-1f73-ac42d6140000 pid=5334 /tmp/Chaotic guuid=9f1e3155-2300-0000-1f73-ac42d5140000 pid=5333->guuid=b61f3f55-2300-0000-1f73-ac42d6140000 pid=5334 clone guuid=ce964955-2300-0000-1f73-ac42d7140000 pid=5335 /tmp/Chaotic net send-data zombie guuid=9f1e3155-2300-0000-1f73-ac42d5140000 pid=5333->guuid=ce964955-2300-0000-1f73-ac42d7140000 pid=5335 clone guuid=ce964955-2300-0000-1f73-ac42d7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce964955-2300-0000-1f73-ac42d7140000 pid=5335->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=b0c66782-2400-0000-1f73-ac42d9140000 pid=5337->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b0c66782-2400-0000-1f73-ac42d9140000 pid=5337->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 7B guuid=43278582-2400-0000-1f73-ac42da140000 pid=5338->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 165B guuid=e49dedd5-2400-0000-1f73-ac42db140000 pid=5339->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 114B guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=64da5208-2500-0000-1f73-ac42df140000 pid=5343 /tmp/Chaotic guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342->guuid=64da5208-2500-0000-1f73-ac42df140000 pid=5343 clone guuid=24f0a935-2600-0000-1f73-ac42e2140000 pid=5346 /tmp/Chaotic guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342->guuid=24f0a935-2600-0000-1f73-ac42e2140000 pid=5346 clone guuid=2839b335-2600-0000-1f73-ac42e3140000 pid=5347 /tmp/Chaotic net send-data zombie guuid=4bce5707-2500-0000-1f73-ac42de140000 pid=5342->guuid=2839b335-2600-0000-1f73-ac42e3140000 pid=5347 clone guuid=c9c36108-2500-0000-1f73-ac42e0140000 pid=5344 /tmp/Chaotic guuid=64da5208-2500-0000-1f73-ac42df140000 pid=5343->guuid=c9c36108-2500-0000-1f73-ac42e0140000 pid=5344 clone guuid=407f6a08-2500-0000-1f73-ac42e1140000 pid=5345 /tmp/Chaotic net send-data zombie guuid=64da5208-2500-0000-1f73-ac42df140000 pid=5343->guuid=407f6a08-2500-0000-1f73-ac42e1140000 pid=5345 clone guuid=407f6a08-2500-0000-1f73-ac42e1140000 pid=5345->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=407f6a08-2500-0000-1f73-ac42e1140000 pid=5345->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 5B guuid=2839b335-2600-0000-1f73-ac42e3140000 pid=5347->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2839b335-2600-0000-1f73-ac42e3140000 pid=5347->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 5B guuid=a460d435-2600-0000-1f73-ac42e4140000 pid=5348->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 165B guuid=d3c89f8c-2600-0000-1f73-ac42e5140000 pid=5349->4b145f03-a0d5-5492-815a-c3ca0d11fe3c send: 114B guuid=0cb042c0-2600-0000-1f73-ac42ea140000 pid=5354->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d4dc34c1-2600-0000-1f73-ac42eb140000 pid=5355 /tmp/Chaotic guuid=0cb042c0-2600-0000-1f73-ac42ea140000 pid=5354->guuid=d4dc34c1-2600-0000-1f73-ac42eb140000 pid=5355 clone guuid=21ba3fc1-2600-0000-1f73-ac42ec140000 pid=5356 /tmp/Chaotic guuid=d4dc34c1-2600-0000-1f73-ac42eb140000 pid=5355->guuid=21ba3fc1-2600-0000-1f73-ac42ec140000 pid=5356 clone guuid=db114ac1-2600-0000-1f73-ac42ed140000 pid=5357 /tmp/Chaotic net send-data zombie guuid=d4dc34c1-2600-0000-1f73-ac42eb140000 pid=5355->guuid=db114ac1-2600-0000-1f73-ac42ed140000 pid=5357 clone guuid=db114ac1-2600-0000-1f73-ac42ed140000 pid=5357->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=db114ac1-2600-0000-1f73-ac42ed140000 pid=5357->5b5a8b2e-dc68-5ce2-a507-cd6c73c3b816 send: 5B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-18 16:46:06 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5af6d3884a0e1197228a031050a4251ef7c5b547502c1bdc71fcb93c7ce5df9a

(this sample)

  
Delivery method
Distributed via web download

Comments