MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5fc52953f79ce69bf8df96552fb4ac7e59f9f1ca1d90d1efb16d0cbad479eca7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 5fc52953f79ce69bf8df96552fb4ac7e59f9f1ca1d90d1efb16d0cbad479eca7
SHA3-384 hash: 9f9f7c44747b0a00e25b0c9c4ef85481b89c4a85bbcc0dd356a6c116777682f63e0a9bc45e79fd1f69a742f7004ec707
SHA1 hash: 28ad7741a5cbba452709daf88bb99375cb6c743d
MD5 hash: 9efea1004081b9f04274eafa7247b587
humanhash: winner-pasta-cola-mirror
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'749 bytes
First seen:2026-05-06 00:12:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipunTpyvp3xpvhpdNp/FpFOLp+npPhpqvppRp9nplhxpYbpxk:i4TInLdfOUvkpLHaE
TLSH T1DD51B3C822D14072ADF6D9B373BAC518B99050D778C97F599CE838F4C08CE46B2C1BA2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.64/bin/bot.arcn/an/aelf ua-wget
http://176.65.139.64/bin/bot.x86n/an/a32-bit elf mirai x86-32
http://176.65.139.64/bin/bot.x86_64n/an/aelf ua-wget
http://176.65.139.64/bin/bot.i686n/an/aelf ua-wget
http://176.65.139.64/bin/bot.mipsn/an/aelf ua-wget
http://176.65.139.64/bin/bot.mips64n/an/aelf ua-wget
http://176.65.139.64/bin/bot.mpsln/an/aelf ua-wget
http://176.65.139.64/bin/bot.armn/an/aelf ua-wget
http://176.65.139.64/bin/bot.arm5n/an/aelf ua-wget
http://176.65.139.64/bin/bot.arm6n/an/aelf ua-wget
http://176.65.139.64/bin/bot.arm7n/an/aelf ua-wget
http://176.65.139.64/bin/bot.ppcn/an/aelf ua-wget
http://176.65.139.64/bin/bot.sparcn/an/aelf ua-wget
http://176.65.139.64/bin/bot.m68kn/an/aelf ua-wget
http://176.65.139.64/bin/bot.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
67
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-05T21:15:00Z UTC
Last seen:
2026-05-06T11:30:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=55744845-1700-0000-6905-faebba0d0000 pid=3514 /usr/bin/sudo guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521 /tmp/sample.bin guuid=55744845-1700-0000-6905-faebba0d0000 pid=3514->guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521 execve guuid=cb875347-1700-0000-6905-faebc20d0000 pid=3522 /usr/bin/cp guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=cb875347-1700-0000-6905-faebc20d0000 pid=3522 execve guuid=b97dc148-1700-0000-6905-faebc40d0000 pid=3524 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=b97dc148-1700-0000-6905-faebc40d0000 pid=3524 execve guuid=a7e6ba4c-1700-0000-6905-faebd20d0000 pid=3538 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=a7e6ba4c-1700-0000-6905-faebd20d0000 pid=3538 execve guuid=23a20951-1700-0000-6905-faebe60d0000 pid=3558 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=23a20951-1700-0000-6905-faebe60d0000 pid=3558 execve guuid=d88b4851-1700-0000-6905-faebe80d0000 pid=3560 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=d88b4851-1700-0000-6905-faebe80d0000 pid=3560 execve guuid=1e408451-1700-0000-6905-faebe90d0000 pid=3561 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=1e408451-1700-0000-6905-faebe90d0000 pid=3561 clone guuid=8f1cb651-1700-0000-6905-faebea0d0000 pid=3562 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=8f1cb651-1700-0000-6905-faebea0d0000 pid=3562 execve guuid=43253055-1700-0000-6905-faebf40d0000 pid=3572 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=43253055-1700-0000-6905-faebf40d0000 pid=3572 execve guuid=f4d4145a-1700-0000-6905-faeb050e0000 pid=3589 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f4d4145a-1700-0000-6905-faeb050e0000 pid=3589 execve guuid=6db6705a-1700-0000-6905-faeb060e0000 pid=3590 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=6db6705a-1700-0000-6905-faeb060e0000 pid=3590 execve guuid=31cbb45a-1700-0000-6905-faeb070e0000 pid=3591 /tmp/FuckYou delete-file net guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=31cbb45a-1700-0000-6905-faeb070e0000 pid=3591 execve guuid=262dfa5a-1700-0000-6905-faeb0a0e0000 pid=3594 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=262dfa5a-1700-0000-6905-faeb0a0e0000 pid=3594 execve guuid=bd88f163-1700-0000-6905-faeb110e0000 pid=3601 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=bd88f163-1700-0000-6905-faeb110e0000 pid=3601 execve guuid=cc831a6a-1700-0000-6905-faeb1f0e0000 pid=3615 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=cc831a6a-1700-0000-6905-faeb1f0e0000 pid=3615 execve guuid=7d006b6a-1700-0000-6905-faeb210e0000 pid=3617 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=7d006b6a-1700-0000-6905-faeb210e0000 pid=3617 execve guuid=0fa9b66a-1700-0000-6905-faeb230e0000 pid=3619 /tmp/FuckYou delete-file net guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=0fa9b66a-1700-0000-6905-faeb230e0000 pid=3619 execve guuid=12ebc5a7-1700-0000-6905-faebda0e0000 pid=3802 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=12ebc5a7-1700-0000-6905-faebda0e0000 pid=3802 execve guuid=0dad33ab-1700-0000-6905-faebdb0e0000 pid=3803 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=0dad33ab-1700-0000-6905-faebdb0e0000 pid=3803 execve guuid=47b468b0-1700-0000-6905-faebdc0e0000 pid=3804 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=47b468b0-1700-0000-6905-faebdc0e0000 pid=3804 execve guuid=27c7bcb0-1700-0000-6905-faebdd0e0000 pid=3805 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=27c7bcb0-1700-0000-6905-faebdd0e0000 pid=3805 execve guuid=e1b251b1-1700-0000-6905-faebe20e0000 pid=3810 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=e1b251b1-1700-0000-6905-faebe20e0000 pid=3810 clone guuid=c8d6a0b1-1700-0000-6905-faebe50e0000 pid=3813 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=c8d6a0b1-1700-0000-6905-faebe50e0000 pid=3813 execve guuid=b42b65b6-1700-0000-6905-faebfc0e0000 pid=3836 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=b42b65b6-1700-0000-6905-faebfc0e0000 pid=3836 execve guuid=38b59dbe-1700-0000-6905-faeb0b0f0000 pid=3851 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=38b59dbe-1700-0000-6905-faeb0b0f0000 pid=3851 execve guuid=3f3e0dbf-1700-0000-6905-faeb0e0f0000 pid=3854 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=3f3e0dbf-1700-0000-6905-faeb0e0f0000 pid=3854 execve guuid=3c0c85bf-1700-0000-6905-faeb120f0000 pid=3858 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=3c0c85bf-1700-0000-6905-faeb120f0000 pid=3858 clone guuid=8ae139c0-1700-0000-6905-faeb150f0000 pid=3861 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=8ae139c0-1700-0000-6905-faeb150f0000 pid=3861 execve guuid=401cfdc3-1700-0000-6905-faeb220f0000 pid=3874 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=401cfdc3-1700-0000-6905-faeb220f0000 pid=3874 execve guuid=fe82e6ca-1700-0000-6905-faeb360f0000 pid=3894 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=fe82e6ca-1700-0000-6905-faeb360f0000 pid=3894 execve guuid=6c1968cb-1700-0000-6905-faeb370f0000 pid=3895 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=6c1968cb-1700-0000-6905-faeb370f0000 pid=3895 execve guuid=27ceaccb-1700-0000-6905-faeb3b0f0000 pid=3899 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=27ceaccb-1700-0000-6905-faeb3b0f0000 pid=3899 clone guuid=274be9cb-1700-0000-6905-faeb3c0f0000 pid=3900 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=274be9cb-1700-0000-6905-faeb3c0f0000 pid=3900 execve guuid=ddf64ecf-1700-0000-6905-faeb4a0f0000 pid=3914 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=ddf64ecf-1700-0000-6905-faeb4a0f0000 pid=3914 execve guuid=303a5cd5-1700-0000-6905-faeb5e0f0000 pid=3934 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=303a5cd5-1700-0000-6905-faeb5e0f0000 pid=3934 execve guuid=fbecb2d5-1700-0000-6905-faeb600f0000 pid=3936 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=fbecb2d5-1700-0000-6905-faeb600f0000 pid=3936 execve guuid=d22602d6-1700-0000-6905-faeb620f0000 pid=3938 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=d22602d6-1700-0000-6905-faeb620f0000 pid=3938 clone guuid=95192fd6-1700-0000-6905-faeb640f0000 pid=3940 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=95192fd6-1700-0000-6905-faeb640f0000 pid=3940 execve guuid=3afe67d9-1700-0000-6905-faeb6f0f0000 pid=3951 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=3afe67d9-1700-0000-6905-faeb6f0f0000 pid=3951 execve guuid=ff83e2de-1700-0000-6905-faeb850f0000 pid=3973 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=ff83e2de-1700-0000-6905-faeb850f0000 pid=3973 execve guuid=f5b62edf-1700-0000-6905-faeb870f0000 pid=3975 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f5b62edf-1700-0000-6905-faeb870f0000 pid=3975 execve guuid=24f075df-1700-0000-6905-faeb8a0f0000 pid=3978 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=24f075df-1700-0000-6905-faeb8a0f0000 pid=3978 clone guuid=5b4b9ddf-1700-0000-6905-faeb8b0f0000 pid=3979 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=5b4b9ddf-1700-0000-6905-faeb8b0f0000 pid=3979 execve guuid=20982ce4-1700-0000-6905-faeb9f0f0000 pid=3999 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=20982ce4-1700-0000-6905-faeb9f0f0000 pid=3999 execve guuid=00edbae9-1700-0000-6905-faebb30f0000 pid=4019 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=00edbae9-1700-0000-6905-faebb30f0000 pid=4019 execve guuid=500938ea-1700-0000-6905-faebb50f0000 pid=4021 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=500938ea-1700-0000-6905-faebb50f0000 pid=4021 execve guuid=7b62adea-1700-0000-6905-faebb70f0000 pid=4023 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=7b62adea-1700-0000-6905-faebb70f0000 pid=4023 clone guuid=c1209feb-1700-0000-6905-faebbb0f0000 pid=4027 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=c1209feb-1700-0000-6905-faebbb0f0000 pid=4027 execve guuid=777221f0-1700-0000-6905-faebcc0f0000 pid=4044 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=777221f0-1700-0000-6905-faebcc0f0000 pid=4044 execve guuid=b465def5-1700-0000-6905-faebdc0f0000 pid=4060 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=b465def5-1700-0000-6905-faebdc0f0000 pid=4060 execve guuid=4ff53cf6-1700-0000-6905-faebde0f0000 pid=4062 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=4ff53cf6-1700-0000-6905-faebde0f0000 pid=4062 execve guuid=eefd9bf6-1700-0000-6905-faebe00f0000 pid=4064 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=eefd9bf6-1700-0000-6905-faebe00f0000 pid=4064 clone guuid=894c58f7-1700-0000-6905-faebe30f0000 pid=4067 /usr/bin/wget net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=894c58f7-1700-0000-6905-faebe30f0000 pid=4067 execve guuid=b35a19fd-1700-0000-6905-faebf60f0000 pid=4086 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=b35a19fd-1700-0000-6905-faebf60f0000 pid=4086 execve guuid=30390b03-1800-0000-6905-faeb06100000 pid=4102 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=30390b03-1800-0000-6905-faeb06100000 pid=4102 execve guuid=838e6b03-1800-0000-6905-faeb09100000 pid=4105 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=838e6b03-1800-0000-6905-faeb09100000 pid=4105 execve guuid=aec4af03-1800-0000-6905-faeb0b100000 pid=4107 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=aec4af03-1800-0000-6905-faeb0b100000 pid=4107 clone guuid=f2cc9d05-1800-0000-6905-faeb14100000 pid=4116 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f2cc9d05-1800-0000-6905-faeb14100000 pid=4116 execve guuid=0e4d0e08-1800-0000-6905-faeb1f100000 pid=4127 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=0e4d0e08-1800-0000-6905-faeb1f100000 pid=4127 execve guuid=4844900b-1800-0000-6905-faeb2c100000 pid=4140 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=4844900b-1800-0000-6905-faeb2c100000 pid=4140 execve guuid=ec50fe0b-1800-0000-6905-faeb30100000 pid=4144 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=ec50fe0b-1800-0000-6905-faeb30100000 pid=4144 execve guuid=f34e3c0c-1800-0000-6905-faeb33100000 pid=4147 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f34e3c0c-1800-0000-6905-faeb33100000 pid=4147 clone guuid=4031720c-1800-0000-6905-faeb35100000 pid=4149 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=4031720c-1800-0000-6905-faeb35100000 pid=4149 execve guuid=30bb0a0f-1800-0000-6905-faeb3d100000 pid=4157 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=30bb0a0f-1800-0000-6905-faeb3d100000 pid=4157 execve guuid=88809b12-1800-0000-6905-faeb4a100000 pid=4170 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=88809b12-1800-0000-6905-faeb4a100000 pid=4170 execve guuid=98eced12-1800-0000-6905-faeb4c100000 pid=4172 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=98eced12-1800-0000-6905-faeb4c100000 pid=4172 execve guuid=a8874013-1800-0000-6905-faeb4e100000 pid=4174 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=a8874013-1800-0000-6905-faeb4e100000 pid=4174 clone guuid=0b497013-1800-0000-6905-faeb4f100000 pid=4175 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=0b497013-1800-0000-6905-faeb4f100000 pid=4175 execve guuid=a8d11416-1800-0000-6905-faeb5b100000 pid=4187 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=a8d11416-1800-0000-6905-faeb5b100000 pid=4187 execve guuid=63867c19-1800-0000-6905-faeb6c100000 pid=4204 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=63867c19-1800-0000-6905-faeb6c100000 pid=4204 execve guuid=0d43d519-1800-0000-6905-faeb70100000 pid=4208 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=0d43d519-1800-0000-6905-faeb70100000 pid=4208 execve guuid=79644c1a-1800-0000-6905-faeb71100000 pid=4209 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=79644c1a-1800-0000-6905-faeb71100000 pid=4209 clone guuid=f452711a-1800-0000-6905-faeb73100000 pid=4211 /usr/bin/wget net send-data guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f452711a-1800-0000-6905-faeb73100000 pid=4211 execve guuid=c6d9381d-1800-0000-6905-faeb7a100000 pid=4218 /usr/bin/curl net send-data write-file guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=c6d9381d-1800-0000-6905-faeb7a100000 pid=4218 execve guuid=13b97c22-1800-0000-6905-faeb87100000 pid=4231 /usr/bin/cat guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=13b97c22-1800-0000-6905-faeb87100000 pid=4231 execve guuid=f258ff22-1800-0000-6905-faeb88100000 pid=4232 /usr/bin/chmod guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=f258ff22-1800-0000-6905-faeb88100000 pid=4232 execve guuid=e3507923-1800-0000-6905-faeb89100000 pid=4233 /usr/bin/bash guuid=6c7fff46-1700-0000-6905-faebc10d0000 pid=3521->guuid=e3507923-1800-0000-6905-faeb89100000 pid=4233 clone d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f 176.65.139.64:80 guuid=b97dc148-1700-0000-6905-faebc40d0000 pid=3524->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 139B guuid=a7e6ba4c-1700-0000-6905-faebd20d0000 pid=3538->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 88B guuid=8f1cb651-1700-0000-6905-faebea0d0000 pid=3562->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 139B guuid=43253055-1700-0000-6905-faebf40d0000 pid=3572->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=31cbb45a-1700-0000-6905-faeb070e0000 pid=3591->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b31be65a-1700-0000-6905-faeb080e0000 pid=3592 /tmp/FuckYou net zombie guuid=31cbb45a-1700-0000-6905-faeb070e0000 pid=3591->guuid=b31be65a-1700-0000-6905-faeb080e0000 pid=3592 clone b1ea6f51-2974-580f-9fad-2a41cd4cadee 176.65.139.64:61802 guuid=b31be65a-1700-0000-6905-faeb080e0000 pid=3592->b1ea6f51-2974-580f-9fad-2a41cd4cadee con guuid=5990f65a-1700-0000-6905-faeb090e0000 pid=3593 /tmp/FuckYou guuid=b31be65a-1700-0000-6905-faeb080e0000 pid=3592->guuid=5990f65a-1700-0000-6905-faeb090e0000 pid=3593 clone guuid=262dfa5a-1700-0000-6905-faeb0a0e0000 pid=3594->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 142B guuid=bd88f163-1700-0000-6905-faeb110e0000 pid=3601->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 91B guuid=0fa9b66a-1700-0000-6905-faeb230e0000 pid=3619->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con afa91783-4de5-5704-817a-d50eb48832ce 127.0.0.1:8888 guuid=0fa9b66a-1700-0000-6905-faeb230e0000 pid=3619->afa91783-4de5-5704-817a-d50eb48832ce con guuid=b6f9aea7-1700-0000-6905-faebd80e0000 pid=3800 /tmp/FuckYou net zombie guuid=0fa9b66a-1700-0000-6905-faeb230e0000 pid=3619->guuid=b6f9aea7-1700-0000-6905-faebd80e0000 pid=3800 clone guuid=b6f9aea7-1700-0000-6905-faebd80e0000 pid=3800->b1ea6f51-2974-580f-9fad-2a41cd4cadee con guuid=bed5bea7-1700-0000-6905-faebd90e0000 pid=3801 /tmp/FuckYou guuid=b6f9aea7-1700-0000-6905-faebd80e0000 pid=3800->guuid=bed5bea7-1700-0000-6905-faebd90e0000 pid=3801 clone guuid=12ebc5a7-1700-0000-6905-faebda0e0000 pid=3802->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=0dad33ab-1700-0000-6905-faebdb0e0000 pid=3803->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=c8d6a0b1-1700-0000-6905-faebe50e0000 pid=3813->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=b42b65b6-1700-0000-6905-faebfc0e0000 pid=3836->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=8ae139c0-1700-0000-6905-faeb150f0000 pid=3861->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 142B guuid=401cfdc3-1700-0000-6905-faeb220f0000 pid=3874->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 91B guuid=274be9cb-1700-0000-6905-faeb3c0f0000 pid=3900->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=ddf64ecf-1700-0000-6905-faeb4a0f0000 pid=3914->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=95192fd6-1700-0000-6905-faeb640f0000 pid=3940->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 139B guuid=3afe67d9-1700-0000-6905-faeb6f0f0000 pid=3951->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 88B guuid=5b4b9ddf-1700-0000-6905-faeb8b0f0000 pid=3979->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=20982ce4-1700-0000-6905-faeb9f0f0000 pid=3999->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=c1209feb-1700-0000-6905-faebbb0f0000 pid=4027->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=777221f0-1700-0000-6905-faebcc0f0000 pid=4044->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=894c58f7-1700-0000-6905-faebe30f0000 pid=4067->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=b35a19fd-1700-0000-6905-faebf60f0000 pid=4086->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=f2cc9d05-1800-0000-6905-faeb14100000 pid=4116->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 139B guuid=0e4d0e08-1800-0000-6905-faeb1f100000 pid=4127->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 88B guuid=4031720c-1800-0000-6905-faeb35100000 pid=4149->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 141B guuid=30bb0a0f-1800-0000-6905-faeb3d100000 pid=4157->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 90B guuid=0b497013-1800-0000-6905-faeb4f100000 pid=4175->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 140B guuid=a8d11416-1800-0000-6905-faeb5b100000 pid=4187->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 89B guuid=f452711a-1800-0000-6905-faeb73100000 pid=4211->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 139B guuid=c6d9381d-1800-0000-6905-faeb7a100000 pid=4218->d7090cb0-ea11-5dae-b9ab-7fa7aa2d404f send: 88B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-05-06 00:12:35 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5fc52953f79ce69bf8df96552fb4ac7e59f9f1ca1d90d1efb16d0cbad479eca7

(this sample)

  
Delivery method
Distributed via web download

Comments