MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5cea6237f2e47265f9bd38c0c907adeab2a5e4000e4770f6ad1c757955a95059. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 4


Intelligence 4 IOCs YARA 2 File information Comments

SHA256 hash: 5cea6237f2e47265f9bd38c0c907adeab2a5e4000e4770f6ad1c757955a95059
SHA3-384 hash: 9fc7ec4e9dffc8b85208768047e01b8c64a754f269c85dc94f0ec2330be0b0174ccc8e5321bb6330015a8a6dd0272557
SHA1 hash: a25eb873bdc6304b0cf44e03d8a581c305b5a160
MD5 hash: 84fd6b6633d1becafe28dedd80ef1b1a
humanhash: twelve-double-eighteen-fix
File name:test.sh
Download: download sample
Signature Mirai
File size:2'531 bytes
First seen:2025-08-21 07:52:26 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:UWabsfsWvU/sE0sNs5sD3Bs5w0sXsHsGYsD/s5f:UWaQUua2yD3KGcMGtop
TLSH T10E5165CD17B376312D96D97272AE4488B6B2A0A630C91F4B98DD38F5C49CF053271EB6
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.74.69/systemcl/arcn/an/aelf ua-wget
http://161.97.74.69/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf mirai ua-wget
http://161.97.74.69/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf mirai ua-wget
http://161.97.74.69/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf mirai ua-wget
http://161.97.74.69/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf mirai ua-wget
http://161.97.74.69/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Mirai32-bit elf mirai Mozi
http://161.97.74.69/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=1e14ed4f-1a00-0000-3a3d-f301140a0000 pid=2580 /usr/bin/sudo guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585 /tmp/sample.bin guuid=1e14ed4f-1a00-0000-3a3d-f301140a0000 pid=2580->guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585 execve guuid=684e2652-1a00-0000-3a3d-f3011b0a0000 pid=2587 /usr/bin/wget net send-data guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=684e2652-1a00-0000-3a3d-f3011b0a0000 pid=2587 execve guuid=6f9fb358-1a00-0000-3a3d-f3012f0a0000 pid=2607 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=6f9fb358-1a00-0000-3a3d-f3012f0a0000 pid=2607 execve guuid=5bd04d63-1a00-0000-3a3d-f3014d0a0000 pid=2637 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=5bd04d63-1a00-0000-3a3d-f3014d0a0000 pid=2637 execve guuid=0cfa9563-1a00-0000-3a3d-f3014e0a0000 pid=2638 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=0cfa9563-1a00-0000-3a3d-f3014e0a0000 pid=2638 execve guuid=1b880d64-1a00-0000-3a3d-f301510a0000 pid=2641 /tmp/arc guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=1b880d64-1a00-0000-3a3d-f301510a0000 pid=2641 execve guuid=0f466064-1a00-0000-3a3d-f301520a0000 pid=2642 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=0f466064-1a00-0000-3a3d-f301520a0000 pid=2642 execve guuid=64edd664-1a00-0000-3a3d-f301550a0000 pid=2645 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=64edd664-1a00-0000-3a3d-f301550a0000 pid=2645 execve guuid=40aaa96b-1a00-0000-3a3d-f301680a0000 pid=2664 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=40aaa96b-1a00-0000-3a3d-f301680a0000 pid=2664 execve guuid=a07b0f75-1a00-0000-3a3d-f301860a0000 pid=2694 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=a07b0f75-1a00-0000-3a3d-f301860a0000 pid=2694 execve guuid=1df04a75-1a00-0000-3a3d-f301870a0000 pid=2695 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=1df04a75-1a00-0000-3a3d-f301870a0000 pid=2695 execve guuid=104f8775-1a00-0000-3a3d-f301890a0000 pid=2697 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=104f8775-1a00-0000-3a3d-f301890a0000 pid=2697 clone guuid=60b01376-1a00-0000-3a3d-f3018d0a0000 pid=2701 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=60b01376-1a00-0000-3a3d-f3018d0a0000 pid=2701 execve guuid=6508077e-1a00-0000-3a3d-f301a40a0000 pid=2724 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=6508077e-1a00-0000-3a3d-f301a40a0000 pid=2724 execve guuid=e0ec2b81-1a00-0000-3a3d-f301ad0a0000 pid=2733 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=e0ec2b81-1a00-0000-3a3d-f301ad0a0000 pid=2733 execve guuid=e9df1585-1a00-0000-3a3d-f301b70a0000 pid=2743 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=e9df1585-1a00-0000-3a3d-f301b70a0000 pid=2743 execve guuid=6ef55985-1a00-0000-3a3d-f301b90a0000 pid=2745 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=6ef55985-1a00-0000-3a3d-f301b90a0000 pid=2745 execve guuid=ba6fc985-1a00-0000-3a3d-f301bb0a0000 pid=2747 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ba6fc985-1a00-0000-3a3d-f301bb0a0000 pid=2747 clone guuid=0c558e87-1a00-0000-3a3d-f301c10a0000 pid=2753 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=0c558e87-1a00-0000-3a3d-f301c10a0000 pid=2753 execve guuid=deb5e087-1a00-0000-3a3d-f301c20a0000 pid=2754 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=deb5e087-1a00-0000-3a3d-f301c20a0000 pid=2754 execve guuid=20d8058e-1a00-0000-3a3d-f301ce0a0000 pid=2766 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=20d8058e-1a00-0000-3a3d-f301ce0a0000 pid=2766 execve guuid=b575d098-1a00-0000-3a3d-f301e00a0000 pid=2784 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=b575d098-1a00-0000-3a3d-f301e00a0000 pid=2784 execve guuid=59572999-1a00-0000-3a3d-f301e10a0000 pid=2785 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=59572999-1a00-0000-3a3d-f301e10a0000 pid=2785 execve guuid=dd656699-1a00-0000-3a3d-f301e30a0000 pid=2787 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=dd656699-1a00-0000-3a3d-f301e30a0000 pid=2787 clone guuid=018e419a-1a00-0000-3a3d-f301e70a0000 pid=2791 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=018e419a-1a00-0000-3a3d-f301e70a0000 pid=2791 execve guuid=b152b19a-1a00-0000-3a3d-f301e80a0000 pid=2792 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=b152b19a-1a00-0000-3a3d-f301e80a0000 pid=2792 execve guuid=05c5b9b0-1a00-0000-3a3d-f3010a0b0000 pid=2826 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=05c5b9b0-1a00-0000-3a3d-f3010a0b0000 pid=2826 execve guuid=ce9a9dbb-1a00-0000-3a3d-f301180b0000 pid=2840 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ce9a9dbb-1a00-0000-3a3d-f301180b0000 pid=2840 execve guuid=afd0d4bb-1a00-0000-3a3d-f301190b0000 pid=2841 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=afd0d4bb-1a00-0000-3a3d-f301190b0000 pid=2841 execve guuid=e1f30ebc-1a00-0000-3a3d-f3011a0b0000 pid=2842 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=e1f30ebc-1a00-0000-3a3d-f3011a0b0000 pid=2842 clone guuid=94bf0cbd-1a00-0000-3a3d-f3011e0b0000 pid=2846 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=94bf0cbd-1a00-0000-3a3d-f3011e0b0000 pid=2846 execve guuid=035d48bd-1a00-0000-3a3d-f3011f0b0000 pid=2847 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=035d48bd-1a00-0000-3a3d-f3011f0b0000 pid=2847 execve guuid=002738c1-1a00-0000-3a3d-f3012b0b0000 pid=2859 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=002738c1-1a00-0000-3a3d-f3012b0b0000 pid=2859 execve guuid=cf8d76cc-1a00-0000-3a3d-f301420b0000 pid=2882 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=cf8d76cc-1a00-0000-3a3d-f301420b0000 pid=2882 execve guuid=1d88e5cc-1a00-0000-3a3d-f301440b0000 pid=2884 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=1d88e5cc-1a00-0000-3a3d-f301440b0000 pid=2884 execve guuid=183056cd-1a00-0000-3a3d-f301460b0000 pid=2886 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=183056cd-1a00-0000-3a3d-f301460b0000 pid=2886 clone guuid=959e31ce-1a00-0000-3a3d-f301490b0000 pid=2889 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=959e31ce-1a00-0000-3a3d-f301490b0000 pid=2889 execve guuid=fdc97ace-1a00-0000-3a3d-f3014a0b0000 pid=2890 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=fdc97ace-1a00-0000-3a3d-f3014a0b0000 pid=2890 execve guuid=d2580ed5-1a00-0000-3a3d-f301580b0000 pid=2904 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=d2580ed5-1a00-0000-3a3d-f301580b0000 pid=2904 execve guuid=8bb517d9-1a00-0000-3a3d-f301630b0000 pid=2915 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=8bb517d9-1a00-0000-3a3d-f301630b0000 pid=2915 execve guuid=97ac68d9-1a00-0000-3a3d-f301640b0000 pid=2916 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=97ac68d9-1a00-0000-3a3d-f301640b0000 pid=2916 execve guuid=ac6db4d9-1a00-0000-3a3d-f301650b0000 pid=2917 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ac6db4d9-1a00-0000-3a3d-f301650b0000 pid=2917 clone guuid=fc223bda-1a00-0000-3a3d-f301690b0000 pid=2921 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=fc223bda-1a00-0000-3a3d-f301690b0000 pid=2921 execve guuid=49b679db-1a00-0000-3a3d-f3016e0b0000 pid=2926 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=49b679db-1a00-0000-3a3d-f3016e0b0000 pid=2926 execve guuid=8771b3e3-1a00-0000-3a3d-f301860b0000 pid=2950 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=8771b3e3-1a00-0000-3a3d-f301860b0000 pid=2950 execve guuid=c4a774eb-1a00-0000-3a3d-f301950b0000 pid=2965 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=c4a774eb-1a00-0000-3a3d-f301950b0000 pid=2965 execve guuid=e7f7c4eb-1a00-0000-3a3d-f301960b0000 pid=2966 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=e7f7c4eb-1a00-0000-3a3d-f301960b0000 pid=2966 execve guuid=816109ec-1a00-0000-3a3d-f301970b0000 pid=2967 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=816109ec-1a00-0000-3a3d-f301970b0000 pid=2967 clone guuid=77dbc9ec-1a00-0000-3a3d-f3019a0b0000 pid=2970 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=77dbc9ec-1a00-0000-3a3d-f3019a0b0000 pid=2970 execve guuid=d6d734ef-1a00-0000-3a3d-f301a20b0000 pid=2978 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=d6d734ef-1a00-0000-3a3d-f301a20b0000 pid=2978 execve guuid=17722af4-1a00-0000-3a3d-f301a60b0000 pid=2982 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=17722af4-1a00-0000-3a3d-f301a60b0000 pid=2982 execve guuid=9c8e4ef9-1a00-0000-3a3d-f301af0b0000 pid=2991 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=9c8e4ef9-1a00-0000-3a3d-f301af0b0000 pid=2991 execve guuid=fe3ab2f9-1a00-0000-3a3d-f301b00b0000 pid=2992 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=fe3ab2f9-1a00-0000-3a3d-f301b00b0000 pid=2992 execve guuid=cb2904fa-1a00-0000-3a3d-f301b20b0000 pid=2994 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=cb2904fa-1a00-0000-3a3d-f301b20b0000 pid=2994 clone guuid=ab0609fc-1a00-0000-3a3d-f301b90b0000 pid=3001 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ab0609fc-1a00-0000-3a3d-f301b90b0000 pid=3001 execve guuid=39475afe-1a00-0000-3a3d-f301ba0b0000 pid=3002 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=39475afe-1a00-0000-3a3d-f301ba0b0000 pid=3002 execve guuid=2aa7ca03-1b00-0000-3a3d-f301c20b0000 pid=3010 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=2aa7ca03-1b00-0000-3a3d-f301c20b0000 pid=3010 execve guuid=0fbce908-1b00-0000-3a3d-f301cd0b0000 pid=3021 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=0fbce908-1b00-0000-3a3d-f301cd0b0000 pid=3021 execve guuid=8c377609-1b00-0000-3a3d-f301ce0b0000 pid=3022 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=8c377609-1b00-0000-3a3d-f301ce0b0000 pid=3022 execve guuid=a0e6e509-1b00-0000-3a3d-f301cf0b0000 pid=3023 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=a0e6e509-1b00-0000-3a3d-f301cf0b0000 pid=3023 clone guuid=d6f1df0a-1b00-0000-3a3d-f301d20b0000 pid=3026 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=d6f1df0a-1b00-0000-3a3d-f301d20b0000 pid=3026 execve guuid=9af15a0b-1b00-0000-3a3d-f301d50b0000 pid=3029 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=9af15a0b-1b00-0000-3a3d-f301d50b0000 pid=3029 execve guuid=28257c0f-1b00-0000-3a3d-f301e10b0000 pid=3041 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=28257c0f-1b00-0000-3a3d-f301e10b0000 pid=3041 execve guuid=94c3a613-1b00-0000-3a3d-f301ea0b0000 pid=3050 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=94c3a613-1b00-0000-3a3d-f301ea0b0000 pid=3050 execve guuid=169fe613-1b00-0000-3a3d-f301ec0b0000 pid=3052 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=169fe613-1b00-0000-3a3d-f301ec0b0000 pid=3052 execve guuid=ea082514-1b00-0000-3a3d-f301ed0b0000 pid=3053 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ea082514-1b00-0000-3a3d-f301ed0b0000 pid=3053 clone guuid=7b5d5715-1b00-0000-3a3d-f301f20b0000 pid=3058 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=7b5d5715-1b00-0000-3a3d-f301f20b0000 pid=3058 execve guuid=21a69d15-1b00-0000-3a3d-f301f40b0000 pid=3060 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=21a69d15-1b00-0000-3a3d-f301f40b0000 pid=3060 execve guuid=7a2cd518-1b00-0000-3a3d-f301fc0b0000 pid=3068 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=7a2cd518-1b00-0000-3a3d-f301fc0b0000 pid=3068 execve guuid=ef24811c-1b00-0000-3a3d-f301070c0000 pid=3079 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=ef24811c-1b00-0000-3a3d-f301070c0000 pid=3079 execve guuid=2f22b91c-1b00-0000-3a3d-f301090c0000 pid=3081 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=2f22b91c-1b00-0000-3a3d-f301090c0000 pid=3081 execve guuid=2217101d-1b00-0000-3a3d-f3010a0c0000 pid=3082 /tmp/x86 net write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=2217101d-1b00-0000-3a3d-f3010a0c0000 pid=3082 execve guuid=1a563c2d-1b00-0000-3a3d-f301390c0000 pid=3129 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=1a563c2d-1b00-0000-3a3d-f301390c0000 pid=3129 execve guuid=a74b942d-1b00-0000-3a3d-f3013b0c0000 pid=3131 /usr/bin/wget net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=a74b942d-1b00-0000-3a3d-f3013b0c0000 pid=3131 execve guuid=deb55036-1b00-0000-3a3d-f301530c0000 pid=3155 /usr/bin/curl net send-data write-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=deb55036-1b00-0000-3a3d-f301530c0000 pid=3155 execve guuid=85b3c840-1b00-0000-3a3d-f3016c0c0000 pid=3180 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=85b3c840-1b00-0000-3a3d-f3016c0c0000 pid=3180 execve guuid=23f42541-1b00-0000-3a3d-f3016e0c0000 pid=3182 /usr/bin/chmod guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=23f42541-1b00-0000-3a3d-f3016e0c0000 pid=3182 execve guuid=de1a8541-1b00-0000-3a3d-f301700c0000 pid=3184 /usr/bin/dash guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=de1a8541-1b00-0000-3a3d-f301700c0000 pid=3184 clone guuid=a7d12642-1b00-0000-3a3d-f301740c0000 pid=3188 /usr/bin/rm delete-file guuid=ade4d751-1a00-0000-3a3d-f301190a0000 pid=2585->guuid=a7d12642-1b00-0000-3a3d-f301740c0000 pid=3188 execve 1859fa66-700c-573f-a69b-967c040da2df 161.97.74.69:80 guuid=684e2652-1a00-0000-3a3d-f3011b0a0000 pid=2587->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=6f9fb358-1a00-0000-3a3d-f3012f0a0000 pid=2607->1859fa66-700c-573f-a69b-967c040da2df send: 88B guuid=64edd664-1a00-0000-3a3d-f301550a0000 pid=2645->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=40aaa96b-1a00-0000-3a3d-f301680a0000 pid=2664->1859fa66-700c-573f-a69b-967c040da2df send: 88B guuid=6508077e-1a00-0000-3a3d-f301a40a0000 pid=2724->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=e0ec2b81-1a00-0000-3a3d-f301ad0a0000 pid=2733->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=deb5e087-1a00-0000-3a3d-f301c20a0000 pid=2754->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=20d8058e-1a00-0000-3a3d-f301ce0a0000 pid=2766->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=b152b19a-1a00-0000-3a3d-f301e80a0000 pid=2792->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=05c5b9b0-1a00-0000-3a3d-f3010a0b0000 pid=2826->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=035d48bd-1a00-0000-3a3d-f3011f0b0000 pid=2847->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=002738c1-1a00-0000-3a3d-f3012b0b0000 pid=2859->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=fdc97ace-1a00-0000-3a3d-f3014a0b0000 pid=2890->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=d2580ed5-1a00-0000-3a3d-f301580b0000 pid=2904->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=49b679db-1a00-0000-3a3d-f3016e0b0000 pid=2926->1859fa66-700c-573f-a69b-967c040da2df send: 140B guuid=8771b3e3-1a00-0000-3a3d-f301860b0000 pid=2950->1859fa66-700c-573f-a69b-967c040da2df send: 89B guuid=d6d734ef-1a00-0000-3a3d-f301a20b0000 pid=2978->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=17722af4-1a00-0000-3a3d-f301a60b0000 pid=2982->1859fa66-700c-573f-a69b-967c040da2df send: 88B guuid=39475afe-1a00-0000-3a3d-f301ba0b0000 pid=3002->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=2aa7ca03-1b00-0000-3a3d-f301c20b0000 pid=3010->1859fa66-700c-573f-a69b-967c040da2df send: 88B guuid=9af15a0b-1b00-0000-3a3d-f301d50b0000 pid=3029->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=28257c0f-1b00-0000-3a3d-f301e10b0000 pid=3041->1859fa66-700c-573f-a69b-967c040da2df send: 88B guuid=21a69d15-1b00-0000-3a3d-f301f40b0000 pid=3060->1859fa66-700c-573f-a69b-967c040da2df send: 139B guuid=7a2cd518-1b00-0000-3a3d-f301fc0b0000 pid=3068->1859fa66-700c-573f-a69b-967c040da2df send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2217101d-1b00-0000-3a3d-f3010a0c0000 pid=3082->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8c3c302d-1b00-0000-3a3d-f301370c0000 pid=3127 /tmp/x86 guuid=2217101d-1b00-0000-3a3d-f3010a0c0000 pid=3082->guuid=8c3c302d-1b00-0000-3a3d-f301370c0000 pid=3127 clone guuid=3cb9352d-1b00-0000-3a3d-f301380c0000 pid=3128 /tmp/x86 net send-data zombie guuid=2217101d-1b00-0000-3a3d-f3010a0c0000 pid=3082->guuid=3cb9352d-1b00-0000-3a3d-f301380c0000 pid=3128 clone guuid=3cb9352d-1b00-0000-3a3d-f301380c0000 pid=3128->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b 87.121.84.220:61459 guuid=3cb9352d-1b00-0000-3a3d-f301380c0000 pid=3128->dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b send: 43B guuid=a74b942d-1b00-0000-3a3d-f3013b0c0000 pid=3131->1859fa66-700c-573f-a69b-967c040da2df send: 142B guuid=deb55036-1b00-0000-3a3d-f301530c0000 pid=3155->1859fa66-700c-573f-a69b-967c040da2df send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-21 06:35:29 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5cea6237f2e47265f9bd38c0c907adeab2a5e4000e4770f6ad1c757955a95059

(this sample)

  
Delivery method
Distributed via web download

Comments