MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5b5d30ce0854edba215c967e9845f034e1f35be2b1c72552e27eea2509590bb7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 5b5d30ce0854edba215c967e9845f034e1f35be2b1c72552e27eea2509590bb7
SHA3-384 hash: a3be8955e8e22703f485bd6c876d0293b7d411535b12312c88401098ba8720ad0efb088b6b59982946ff3ff21d1ed867
SHA1 hash: b121fbddbcdb30ed1aeb854e43f091a011459683
MD5 hash: 1efaae5c5b9c761f38fe3028fd5a107e
humanhash: whiskey-mirror-oxygen-salami
File name:1.sh
Download: download sample
Signature Mirai
File size:2'142 bytes
First seen:2025-11-08 18:39:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:N5sX5lnh55R5jzJ52L50b5875Th5t554Qv:NEBBPKk8n1Dv
TLSH T1C541AFCA016A5134EC99D4AA22B7481C678A58EB4ACB1F7EEDD874F7804CC147DC3642
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.35.130.116/huhu/titanjr.x86_644ba70027fdfa176f4ce98a9b46e31070ac40738b0a9ef7f12fcbc126b806d47b Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.x86_32a1dab206a740808694a3a99b6f98f531b4b5df2eb9b5832efe87a3d928a45e50 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.arm9b9dbb95ba9e39c1706de99639adffa83a9cd25d33932218fc728f2578848950 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.arm64c7da7f93f8645b3ec037c6cc501a382bbeecfd74a7b2444d0ec5cbebaa0cef6 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.mipsc5f329b6c92027aa18f2055d5893c483f26ec6ece96a3ca65c5e24d55324e2cf Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.mipsl99c8064702b0727a422f9a8b38b7964472d41846acfed5aa2b933f05ba3fce26 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.ppcaecb17419e4a5aab5829745c9aef9ee2cc3f06926b151883589a89bc0dbde733 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.spc818d53bf873aaaa9be3683e53602a3c961c8faee11ef0b7ba92b778ccb0ed53b Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.m68k0dc1f23f1aa04089e0d5144ab48af826d4f3aad564f7b2e9ca465fb53ca467d6 Miraielf mirai ua-wget
http://89.35.130.116/huhu/titanjr.sh40feda0f2f68bfa767dc9430253144c5160a2b022362fa1319409c5e3aaa98045 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-08T15:59:00Z UTC
Last seen:
2025-11-08T17:04:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ad3cc818-1b00-0000-ef26-89fee40a0000 pid=2788 /usr/bin/sudo guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792 /tmp/sample.bin zombie guuid=ad3cc818-1b00-0000-ef26-89fee40a0000 pid=2788->guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792 execve guuid=b884cf1a-1b00-0000-ef26-89fee90a0000 pid=2793 /usr/bin/cp guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=b884cf1a-1b00-0000-ef26-89fee90a0000 pid=2793 execve guuid=0706601f-1b00-0000-ef26-89feed0a0000 pid=2797 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=0706601f-1b00-0000-ef26-89feed0a0000 pid=2797 execve guuid=9e20fe3a-1b00-0000-ef26-89fe0e0b0000 pid=2830 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=9e20fe3a-1b00-0000-ef26-89fe0e0b0000 pid=2830 execve guuid=24985f58-1b00-0000-ef26-89fe510b0000 pid=2897 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=24985f58-1b00-0000-ef26-89fe510b0000 pid=2897 execve guuid=7539c558-1b00-0000-ef26-89fe520b0000 pid=2898 /tmp/titanjr.x86_64 net guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=7539c558-1b00-0000-ef26-89fe520b0000 pid=2898 execve guuid=64a45459-1b00-0000-ef26-89fe580b0000 pid=2904 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=64a45459-1b00-0000-ef26-89fe580b0000 pid=2904 execve guuid=717a8a59-1b00-0000-ef26-89fe5b0b0000 pid=2907 /usr/bin/wget net send-data guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=717a8a59-1b00-0000-ef26-89fe5b0b0000 pid=2907 execve guuid=4f7abb5c-1b00-0000-ef26-89fe630b0000 pid=2915 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=4f7abb5c-1b00-0000-ef26-89fe630b0000 pid=2915 execve guuid=85bdfe65-1b00-0000-ef26-89fe750b0000 pid=2933 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=85bdfe65-1b00-0000-ef26-89fe750b0000 pid=2933 execve guuid=51658a66-1b00-0000-ef26-89fe760b0000 pid=2934 /tmp/titanjr.x86_32 net guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=51658a66-1b00-0000-ef26-89fe760b0000 pid=2934 execve guuid=a727b466-1b00-0000-ef26-89fe780b0000 pid=2936 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=a727b466-1b00-0000-ef26-89fe780b0000 pid=2936 execve guuid=25583667-1b00-0000-ef26-89fe7a0b0000 pid=2938 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=25583667-1b00-0000-ef26-89fe7a0b0000 pid=2938 execve guuid=6a675f6e-1b00-0000-ef26-89fe890b0000 pid=2953 /usr/bin/curl net guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=6a675f6e-1b00-0000-ef26-89fe890b0000 pid=2953 execve guuid=1afcc173-1b00-0000-ef26-89fe960b0000 pid=2966 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=1afcc173-1b00-0000-ef26-89fe960b0000 pid=2966 execve guuid=47440574-1b00-0000-ef26-89fe970b0000 pid=2967 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=47440574-1b00-0000-ef26-89fe970b0000 pid=2967 clone guuid=1ad99f74-1b00-0000-ef26-89fe990b0000 pid=2969 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=1ad99f74-1b00-0000-ef26-89fe990b0000 pid=2969 execve guuid=0707d774-1b00-0000-ef26-89fe9b0b0000 pid=2971 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=0707d774-1b00-0000-ef26-89fe9b0b0000 pid=2971 execve guuid=400ece7d-1b00-0000-ef26-89feb00b0000 pid=2992 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=400ece7d-1b00-0000-ef26-89feb00b0000 pid=2992 execve guuid=0ac70f88-1b00-0000-ef26-89feca0b0000 pid=3018 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=0ac70f88-1b00-0000-ef26-89feca0b0000 pid=3018 execve guuid=3a025388-1b00-0000-ef26-89fecb0b0000 pid=3019 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=3a025388-1b00-0000-ef26-89fecb0b0000 pid=3019 clone guuid=1a602e89-1b00-0000-ef26-89fece0b0000 pid=3022 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=1a602e89-1b00-0000-ef26-89fece0b0000 pid=3022 execve guuid=80619389-1b00-0000-ef26-89fecf0b0000 pid=3023 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=80619389-1b00-0000-ef26-89fecf0b0000 pid=3023 execve guuid=4cddff90-1b00-0000-ef26-89fedb0b0000 pid=3035 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=4cddff90-1b00-0000-ef26-89fedb0b0000 pid=3035 execve guuid=2042959e-1b00-0000-ef26-89fefc0b0000 pid=3068 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=2042959e-1b00-0000-ef26-89fefc0b0000 pid=3068 execve guuid=f4b4f29e-1b00-0000-ef26-89fefe0b0000 pid=3070 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=f4b4f29e-1b00-0000-ef26-89fefe0b0000 pid=3070 clone guuid=7489d4a0-1b00-0000-ef26-89fe030c0000 pid=3075 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=7489d4a0-1b00-0000-ef26-89fe030c0000 pid=3075 execve guuid=b31b17a1-1b00-0000-ef26-89fe040c0000 pid=3076 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=b31b17a1-1b00-0000-ef26-89fe040c0000 pid=3076 execve guuid=23ea63a9-1b00-0000-ef26-89fe1a0c0000 pid=3098 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=23ea63a9-1b00-0000-ef26-89fe1a0c0000 pid=3098 execve guuid=9c16fcb1-1b00-0000-ef26-89fe330c0000 pid=3123 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=9c16fcb1-1b00-0000-ef26-89fe330c0000 pid=3123 execve guuid=876f74b2-1b00-0000-ef26-89fe340c0000 pid=3124 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=876f74b2-1b00-0000-ef26-89fe340c0000 pid=3124 clone guuid=df076db3-1b00-0000-ef26-89fe370c0000 pid=3127 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=df076db3-1b00-0000-ef26-89fe370c0000 pid=3127 execve guuid=e897fbb3-1b00-0000-ef26-89fe380c0000 pid=3128 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=e897fbb3-1b00-0000-ef26-89fe380c0000 pid=3128 execve guuid=9ac351ba-1b00-0000-ef26-89fe460c0000 pid=3142 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=9ac351ba-1b00-0000-ef26-89fe460c0000 pid=3142 execve guuid=cdfa80c6-1b00-0000-ef26-89fe5e0c0000 pid=3166 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=cdfa80c6-1b00-0000-ef26-89fe5e0c0000 pid=3166 execve guuid=73c0e5c6-1b00-0000-ef26-89fe5f0c0000 pid=3167 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=73c0e5c6-1b00-0000-ef26-89fe5f0c0000 pid=3167 clone guuid=5774a7c7-1b00-0000-ef26-89fe630c0000 pid=3171 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=5774a7c7-1b00-0000-ef26-89fe630c0000 pid=3171 execve guuid=d080f4c7-1b00-0000-ef26-89fe640c0000 pid=3172 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=d080f4c7-1b00-0000-ef26-89fe640c0000 pid=3172 execve guuid=707cd0ce-1b00-0000-ef26-89fe750c0000 pid=3189 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=707cd0ce-1b00-0000-ef26-89fe750c0000 pid=3189 execve guuid=921f2fd7-1b00-0000-ef26-89fe850c0000 pid=3205 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=921f2fd7-1b00-0000-ef26-89fe850c0000 pid=3205 execve guuid=e09975d7-1b00-0000-ef26-89fe870c0000 pid=3207 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=e09975d7-1b00-0000-ef26-89fe870c0000 pid=3207 clone guuid=74660cd8-1b00-0000-ef26-89fe8a0c0000 pid=3210 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=74660cd8-1b00-0000-ef26-89fe8a0c0000 pid=3210 execve guuid=0b8e56d8-1b00-0000-ef26-89fe8b0c0000 pid=3211 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=0b8e56d8-1b00-0000-ef26-89fe8b0c0000 pid=3211 execve guuid=f7c15de1-1b00-0000-ef26-89fe980c0000 pid=3224 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=f7c15de1-1b00-0000-ef26-89fe980c0000 pid=3224 execve guuid=d4c011ed-1b00-0000-ef26-89feaa0c0000 pid=3242 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=d4c011ed-1b00-0000-ef26-89feaa0c0000 pid=3242 execve guuid=d90d73ed-1b00-0000-ef26-89feac0c0000 pid=3244 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=d90d73ed-1b00-0000-ef26-89feac0c0000 pid=3244 clone guuid=d7fa3aee-1b00-0000-ef26-89feb00c0000 pid=3248 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=d7fa3aee-1b00-0000-ef26-89feb00c0000 pid=3248 execve guuid=bc19a9ee-1b00-0000-ef26-89feb20c0000 pid=3250 /usr/bin/wget net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=bc19a9ee-1b00-0000-ef26-89feb20c0000 pid=3250 execve guuid=1ef43af6-1b00-0000-ef26-89fec30c0000 pid=3267 /usr/bin/curl net send-data write-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=1ef43af6-1b00-0000-ef26-89fec30c0000 pid=3267 execve guuid=6b29cefd-1b00-0000-ef26-89fed00c0000 pid=3280 /usr/bin/chmod guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=6b29cefd-1b00-0000-ef26-89fed00c0000 pid=3280 execve guuid=558c36fe-1b00-0000-ef26-89fed10c0000 pid=3281 /usr/bin/dash guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=558c36fe-1b00-0000-ef26-89fed10c0000 pid=3281 clone guuid=62b354ff-1b00-0000-ef26-89fed30c0000 pid=3283 /usr/bin/rm delete-file guuid=1eab8c1a-1b00-0000-ef26-89fee80a0000 pid=2792->guuid=62b354ff-1b00-0000-ef26-89fed30c0000 pid=3283 execve 05ff2587-c2ca-5da8-8e92-7f32a1c4f34b 89.35.130.116:80 guuid=0706601f-1b00-0000-ef26-89feed0a0000 pid=2797->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 147B guuid=9e20fe3a-1b00-0000-ef26-89fe0e0b0000 pid=2830->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7539c558-1b00-0000-ef26-89fe520b0000 pid=2898->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7198f358-1b00-0000-ef26-89fe540b0000 pid=2900 /tmp/titanjr.x86_64 zombie guuid=7539c558-1b00-0000-ef26-89fe520b0000 pid=2898->guuid=7198f358-1b00-0000-ef26-89fe540b0000 pid=2900 clone guuid=d42cfc58-1b00-0000-ef26-89fe550b0000 pid=2901 /tmp/titanjr.x86_64 write-config zombie guuid=7198f358-1b00-0000-ef26-89fe540b0000 pid=2900->guuid=d42cfc58-1b00-0000-ef26-89fe550b0000 pid=2901 clone guuid=899d4459-1b00-0000-ef26-89fe570b0000 pid=2903 /usr/bin/dash guuid=d42cfc58-1b00-0000-ef26-89fe550b0000 pid=2901->guuid=899d4459-1b00-0000-ef26-89fe570b0000 pid=2903 execve guuid=3980795a-1b00-0000-ef26-89fe5f0b0000 pid=2911 /tmp/titanjr.x86_64 net send-data guuid=d42cfc58-1b00-0000-ef26-89fe550b0000 pid=2901->guuid=3980795a-1b00-0000-ef26-89fe5f0b0000 pid=2911 clone guuid=6aa48059-1b00-0000-ef26-89fe5a0b0000 pid=2906 /usr/bin/cp guuid=899d4459-1b00-0000-ef26-89fe570b0000 pid=2903->guuid=6aa48059-1b00-0000-ef26-89fe5a0b0000 pid=2906 execve guuid=717a8a59-1b00-0000-ef26-89fe5b0b0000 pid=2907->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 147B guuid=3980795a-1b00-0000-ef26-89fe5f0b0000 pid=2911->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=5dc1905a-1b00-0000-ef26-89fe600b0000 pid=2912 /tmp/titanjr.x86_64 guuid=3980795a-1b00-0000-ef26-89fe5f0b0000 pid=2911->guuid=5dc1905a-1b00-0000-ef26-89fe600b0000 pid=2912 clone guuid=5c72965a-1b00-0000-ef26-89fe610b0000 pid=2913 /tmp/titanjr.x86_64 guuid=3980795a-1b00-0000-ef26-89fe5f0b0000 pid=2911->guuid=5c72965a-1b00-0000-ef26-89fe610b0000 pid=2913 clone guuid=4f7abb5c-1b00-0000-ef26-89fe630b0000 pid=2915->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 96B guuid=51658a66-1b00-0000-ef26-89fe760b0000 pid=2934->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4e1aac66-1b00-0000-ef26-89fe770b0000 pid=2935 /tmp/titanjr.x86_32 guuid=51658a66-1b00-0000-ef26-89fe760b0000 pid=2934->guuid=4e1aac66-1b00-0000-ef26-89fe770b0000 pid=2935 clone guuid=21aeb866-1b00-0000-ef26-89fe790b0000 pid=2937 /tmp/titanjr.x86_32 write-config zombie guuid=4e1aac66-1b00-0000-ef26-89fe770b0000 pid=2935->guuid=21aeb866-1b00-0000-ef26-89fe790b0000 pid=2937 clone guuid=28e0a66a-1b00-0000-ef26-89fe7c0b0000 pid=2940 /usr/bin/dash guuid=21aeb866-1b00-0000-ef26-89fe790b0000 pid=2937->guuid=28e0a66a-1b00-0000-ef26-89fe7c0b0000 pid=2940 execve guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949 /tmp/titanjr.x86_32 net send-data zombie guuid=21aeb866-1b00-0000-ef26-89fe790b0000 pid=2937->guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949 clone guuid=25583667-1b00-0000-ef26-89fe7a0b0000 pid=2938->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 144B guuid=e85bd96a-1b00-0000-ef26-89fe7e0b0000 pid=2942 /usr/bin/cp guuid=28e0a66a-1b00-0000-ef26-89fe7c0b0000 pid=2940->guuid=e85bd96a-1b00-0000-ef26-89fe7e0b0000 pid=2942 execve guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 930B a1d9265a-5bb5-511b-bdf4-66841f0191f5 89.35.130.116:12121 guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949->a1d9265a-5bb5-511b-bdf4-66841f0191f5 send: 34B guuid=f5099c6d-1b00-0000-ef26-89fe860b0000 pid=2950 /tmp/titanjr.x86_32 guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949->guuid=f5099c6d-1b00-0000-ef26-89fe860b0000 pid=2950 clone guuid=d107a36d-1b00-0000-ef26-89fe870b0000 pid=2951 /tmp/titanjr.x86_32 guuid=af1b926d-1b00-0000-ef26-89fe850b0000 pid=2949->guuid=d107a36d-1b00-0000-ef26-89fe870b0000 pid=2951 clone guuid=6a675f6e-1b00-0000-ef26-89fe890b0000 pid=2953->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b con guuid=0707d774-1b00-0000-ef26-89fe9b0b0000 pid=2971->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 145B guuid=400ece7d-1b00-0000-ef26-89feb00b0000 pid=2992->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 94B guuid=80619389-1b00-0000-ef26-89fecf0b0000 pid=3023->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 145B guuid=4cddff90-1b00-0000-ef26-89fedb0b0000 pid=3035->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 94B guuid=b31b17a1-1b00-0000-ef26-89fe040c0000 pid=3076->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 146B guuid=23ea63a9-1b00-0000-ef26-89fe1a0c0000 pid=3098->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 95B guuid=e897fbb3-1b00-0000-ef26-89fe380c0000 pid=3128->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 144B guuid=9ac351ba-1b00-0000-ef26-89fe460c0000 pid=3142->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 93B guuid=d080f4c7-1b00-0000-ef26-89fe640c0000 pid=3172->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 144B guuid=707cd0ce-1b00-0000-ef26-89fe750c0000 pid=3189->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 93B guuid=0b8e56d8-1b00-0000-ef26-89fe8b0c0000 pid=3211->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 145B guuid=f7c15de1-1b00-0000-ef26-89fe980c0000 pid=3224->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 94B guuid=bc19a9ee-1b00-0000-ef26-89feb20c0000 pid=3250->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 144B guuid=1ef43af6-1b00-0000-ef26-89fec30c0000 pid=3267->05ff2587-c2ca-5da8-8e92-7f32a1c4f34b send: 93B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-08 18:39:17 UTC
File Type:
Text (Shell)
AV detection:
21 of 38 (55.26%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5b5d30ce0854edba215c967e9845f034e1f35be2b1c72552e27eea2509590bb7

(this sample)

  
Delivery method
Distributed via web download

Comments