MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63556748e8e14e485cbd2ee62c7eb01afd7fec0da2a4bec563014959e1404788. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 63556748e8e14e485cbd2ee62c7eb01afd7fec0da2a4bec563014959e1404788
SHA3-384 hash: b35378abf72e7f9375e8f2400a80685f6c013dd12537d03b7cc9851d7c377ff41b56ad11f8f1aef7fd33b1d6f313d7bd
SHA1 hash: 5c07f28cae4bf77b4eb33f55694a3ea136737ed9
MD5 hash: c3675f85c50d2db30c24d3806218aea6
humanhash: black-speaker-california-burger
File name:1.sh
Download: download sample
Signature Mirai
File size:3'164 bytes
First seen:2025-11-20 17:32:18 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iBsdGVsXQfdB9UPFyR16JhL2hLcJD3UY81uN6:iBsdGVsXQfdB9UPFyRM2hLmD3UYF6
TLSH T14851C4B6214447386CE2ABDB63BE804D709196A704F67F62A7DC38A00D8DFDCBC41663
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.216.189.47/00101010101001/S3o.x86n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.mipsn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.arcn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.i468n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.i686n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.x86_64n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.mpsln/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.armn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.arm5n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.arm6n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.arm7n/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.ppcn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.spcn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.m68kn/an/aelf ua-wget
http://41.216.189.47/00101010101001/S3o.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-19T00:17:00Z UTC
Last seen:
2025-11-22T10:20:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=adb4736c-1a00-0000-bbab-6237d50a0000 pid=2773 /usr/bin/sudo guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777 /tmp/sample.bin guuid=adb4736c-1a00-0000-bbab-6237d50a0000 pid=2773->guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777 execve guuid=1e92ff6e-1a00-0000-bbab-6237db0a0000 pid=2779 /usr/bin/cp guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=1e92ff6e-1a00-0000-bbab-6237db0a0000 pid=2779 execve guuid=50246674-1a00-0000-bbab-6237e90a0000 pid=2793 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=50246674-1a00-0000-bbab-6237e90a0000 pid=2793 execve guuid=d62de67b-1a00-0000-bbab-6237f60a0000 pid=2806 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=d62de67b-1a00-0000-bbab-6237f60a0000 pid=2806 execve guuid=ab62d287-1a00-0000-bbab-62370b0b0000 pid=2827 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=ab62d287-1a00-0000-bbab-62370b0b0000 pid=2827 execve guuid=81072a88-1a00-0000-bbab-62370d0b0000 pid=2829 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=81072a88-1a00-0000-bbab-62370d0b0000 pid=2829 clone guuid=78745188-1a00-0000-bbab-62370e0b0000 pid=2830 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=78745188-1a00-0000-bbab-62370e0b0000 pid=2830 execve guuid=b25ba188-1a00-0000-bbab-6237100b0000 pid=2832 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=b25ba188-1a00-0000-bbab-6237100b0000 pid=2832 execve guuid=6fac748c-1a00-0000-bbab-6237170b0000 pid=2839 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=6fac748c-1a00-0000-bbab-6237170b0000 pid=2839 execve guuid=0923a593-1a00-0000-bbab-6237250b0000 pid=2853 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=0923a593-1a00-0000-bbab-6237250b0000 pid=2853 execve guuid=c666ee93-1a00-0000-bbab-6237270b0000 pid=2855 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=c666ee93-1a00-0000-bbab-6237270b0000 pid=2855 clone guuid=7a162694-1a00-0000-bbab-6237290b0000 pid=2857 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=7a162694-1a00-0000-bbab-6237290b0000 pid=2857 execve guuid=d50f8294-1a00-0000-bbab-62372a0b0000 pid=2858 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=d50f8294-1a00-0000-bbab-62372a0b0000 pid=2858 execve guuid=e7a1d897-1a00-0000-bbab-6237340b0000 pid=2868 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e7a1d897-1a00-0000-bbab-6237340b0000 pid=2868 execve guuid=e16ae79b-1a00-0000-bbab-6237420b0000 pid=2882 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e16ae79b-1a00-0000-bbab-6237420b0000 pid=2882 execve guuid=f9df2f9c-1a00-0000-bbab-6237440b0000 pid=2884 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=f9df2f9c-1a00-0000-bbab-6237440b0000 pid=2884 clone guuid=1f13629c-1a00-0000-bbab-6237450b0000 pid=2885 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=1f13629c-1a00-0000-bbab-6237450b0000 pid=2885 execve guuid=2f7cad9c-1a00-0000-bbab-6237470b0000 pid=2887 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=2f7cad9c-1a00-0000-bbab-6237470b0000 pid=2887 execve guuid=de10aba1-1a00-0000-bbab-6237550b0000 pid=2901 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=de10aba1-1a00-0000-bbab-6237550b0000 pid=2901 execve guuid=b82db3a5-1a00-0000-bbab-6237630b0000 pid=2915 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=b82db3a5-1a00-0000-bbab-6237630b0000 pid=2915 execve guuid=e6c2fda5-1a00-0000-bbab-6237650b0000 pid=2917 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e6c2fda5-1a00-0000-bbab-6237650b0000 pid=2917 clone guuid=c87b28a6-1a00-0000-bbab-6237670b0000 pid=2919 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=c87b28a6-1a00-0000-bbab-6237670b0000 pid=2919 execve guuid=f34e6ea6-1a00-0000-bbab-6237680b0000 pid=2920 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=f34e6ea6-1a00-0000-bbab-6237680b0000 pid=2920 execve guuid=459fdbaa-1a00-0000-bbab-6237730b0000 pid=2931 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=459fdbaa-1a00-0000-bbab-6237730b0000 pid=2931 execve guuid=61f90db1-1a00-0000-bbab-62377d0b0000 pid=2941 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=61f90db1-1a00-0000-bbab-62377d0b0000 pid=2941 execve guuid=75d67bb1-1a00-0000-bbab-62377e0b0000 pid=2942 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=75d67bb1-1a00-0000-bbab-62377e0b0000 pid=2942 clone guuid=1632b4b1-1a00-0000-bbab-62377f0b0000 pid=2943 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=1632b4b1-1a00-0000-bbab-62377f0b0000 pid=2943 execve guuid=663821b2-1a00-0000-bbab-6237800b0000 pid=2944 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=663821b2-1a00-0000-bbab-6237800b0000 pid=2944 execve guuid=0e1480b6-1a00-0000-bbab-6237890b0000 pid=2953 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=0e1480b6-1a00-0000-bbab-6237890b0000 pid=2953 execve guuid=11295fbc-1a00-0000-bbab-6237960b0000 pid=2966 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=11295fbc-1a00-0000-bbab-6237960b0000 pid=2966 execve guuid=43b8a5bc-1a00-0000-bbab-6237980b0000 pid=2968 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=43b8a5bc-1a00-0000-bbab-6237980b0000 pid=2968 clone guuid=5386cbbc-1a00-0000-bbab-6237990b0000 pid=2969 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=5386cbbc-1a00-0000-bbab-6237990b0000 pid=2969 execve guuid=e7d625bd-1a00-0000-bbab-62379a0b0000 pid=2970 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e7d625bd-1a00-0000-bbab-62379a0b0000 pid=2970 execve guuid=f6cb17c2-1a00-0000-bbab-6237a50b0000 pid=2981 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=f6cb17c2-1a00-0000-bbab-6237a50b0000 pid=2981 execve guuid=69059cc7-1a00-0000-bbab-6237b40b0000 pid=2996 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=69059cc7-1a00-0000-bbab-6237b40b0000 pid=2996 execve guuid=ecc3efc7-1a00-0000-bbab-6237b60b0000 pid=2998 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=ecc3efc7-1a00-0000-bbab-6237b60b0000 pid=2998 clone guuid=eb2f11c8-1a00-0000-bbab-6237b80b0000 pid=3000 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=eb2f11c8-1a00-0000-bbab-6237b80b0000 pid=3000 execve guuid=22cd5bc8-1a00-0000-bbab-6237ba0b0000 pid=3002 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=22cd5bc8-1a00-0000-bbab-6237ba0b0000 pid=3002 execve guuid=ffad68cd-1a00-0000-bbab-6237c40b0000 pid=3012 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=ffad68cd-1a00-0000-bbab-6237c40b0000 pid=3012 execve guuid=c5370ed4-1a00-0000-bbab-6237d40b0000 pid=3028 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=c5370ed4-1a00-0000-bbab-6237d40b0000 pid=3028 execve guuid=35866dd4-1a00-0000-bbab-6237d60b0000 pid=3030 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=35866dd4-1a00-0000-bbab-6237d60b0000 pid=3030 clone guuid=2cd394d4-1a00-0000-bbab-6237d80b0000 pid=3032 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=2cd394d4-1a00-0000-bbab-6237d80b0000 pid=3032 execve guuid=08b5e0d4-1a00-0000-bbab-6237d90b0000 pid=3033 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=08b5e0d4-1a00-0000-bbab-6237d90b0000 pid=3033 execve guuid=09af4cd9-1a00-0000-bbab-6237e50b0000 pid=3045 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=09af4cd9-1a00-0000-bbab-6237e50b0000 pid=3045 execve guuid=68d683de-1a00-0000-bbab-6237f10b0000 pid=3057 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=68d683de-1a00-0000-bbab-6237f10b0000 pid=3057 execve guuid=edf1e8de-1a00-0000-bbab-6237f40b0000 pid=3060 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=edf1e8de-1a00-0000-bbab-6237f40b0000 pid=3060 clone guuid=b1a50adf-1a00-0000-bbab-6237f50b0000 pid=3061 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=b1a50adf-1a00-0000-bbab-6237f50b0000 pid=3061 execve guuid=763a71df-1a00-0000-bbab-6237f70b0000 pid=3063 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=763a71df-1a00-0000-bbab-6237f70b0000 pid=3063 execve guuid=2b6910e4-1a00-0000-bbab-6237060c0000 pid=3078 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=2b6910e4-1a00-0000-bbab-6237060c0000 pid=3078 execve guuid=3994c6f2-1a00-0000-bbab-62372a0c0000 pid=3114 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=3994c6f2-1a00-0000-bbab-62372a0c0000 pid=3114 execve guuid=5df12cf3-1a00-0000-bbab-62372b0c0000 pid=3115 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=5df12cf3-1a00-0000-bbab-62372b0c0000 pid=3115 clone guuid=fe4c53f3-1a00-0000-bbab-62372c0c0000 pid=3116 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=fe4c53f3-1a00-0000-bbab-62372c0c0000 pid=3116 execve guuid=39c1c7f3-1a00-0000-bbab-62372e0c0000 pid=3118 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=39c1c7f3-1a00-0000-bbab-62372e0c0000 pid=3118 execve guuid=c9fe5ef7-1a00-0000-bbab-62373a0c0000 pid=3130 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=c9fe5ef7-1a00-0000-bbab-62373a0c0000 pid=3130 execve guuid=4a6596fd-1a00-0000-bbab-62374d0c0000 pid=3149 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=4a6596fd-1a00-0000-bbab-62374d0c0000 pid=3149 execve guuid=70f5e0fd-1a00-0000-bbab-62374f0c0000 pid=3151 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=70f5e0fd-1a00-0000-bbab-62374f0c0000 pid=3151 clone guuid=0510fffd-1a00-0000-bbab-6237500c0000 pid=3152 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=0510fffd-1a00-0000-bbab-6237500c0000 pid=3152 execve guuid=8e0444fe-1a00-0000-bbab-6237530c0000 pid=3155 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=8e0444fe-1a00-0000-bbab-6237530c0000 pid=3155 execve guuid=1cb88e02-1b00-0000-bbab-62375e0c0000 pid=3166 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=1cb88e02-1b00-0000-bbab-62375e0c0000 pid=3166 execve guuid=8ee64f08-1b00-0000-bbab-6237720c0000 pid=3186 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=8ee64f08-1b00-0000-bbab-6237720c0000 pid=3186 execve guuid=52d1c508-1b00-0000-bbab-6237750c0000 pid=3189 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=52d1c508-1b00-0000-bbab-6237750c0000 pid=3189 clone guuid=296f3709-1b00-0000-bbab-6237760c0000 pid=3190 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=296f3709-1b00-0000-bbab-6237760c0000 pid=3190 execve guuid=0976a709-1b00-0000-bbab-6237790c0000 pid=3193 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=0976a709-1b00-0000-bbab-6237790c0000 pid=3193 execve guuid=b940cc0e-1b00-0000-bbab-6237860c0000 pid=3206 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=b940cc0e-1b00-0000-bbab-6237860c0000 pid=3206 execve guuid=81111914-1b00-0000-bbab-6237920c0000 pid=3218 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=81111914-1b00-0000-bbab-6237920c0000 pid=3218 execve guuid=5f967514-1b00-0000-bbab-6237930c0000 pid=3219 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=5f967514-1b00-0000-bbab-6237930c0000 pid=3219 clone guuid=45c1a714-1b00-0000-bbab-6237940c0000 pid=3220 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=45c1a714-1b00-0000-bbab-6237940c0000 pid=3220 execve guuid=356b0915-1b00-0000-bbab-6237950c0000 pid=3221 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=356b0915-1b00-0000-bbab-6237950c0000 pid=3221 execve guuid=127da219-1b00-0000-bbab-6237a00c0000 pid=3232 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=127da219-1b00-0000-bbab-6237a00c0000 pid=3232 execve guuid=28d56421-1b00-0000-bbab-6237ab0c0000 pid=3243 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=28d56421-1b00-0000-bbab-6237ab0c0000 pid=3243 execve guuid=83c9f621-1b00-0000-bbab-6237ac0c0000 pid=3244 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=83c9f621-1b00-0000-bbab-6237ac0c0000 pid=3244 clone guuid=b14d3a22-1b00-0000-bbab-6237ad0c0000 pid=3245 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=b14d3a22-1b00-0000-bbab-6237ad0c0000 pid=3245 execve guuid=e7aad322-1b00-0000-bbab-6237ae0c0000 pid=3246 /usr/bin/wget net send-data guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e7aad322-1b00-0000-bbab-6237ae0c0000 pid=3246 execve guuid=d288c426-1b00-0000-bbab-6237af0c0000 pid=3247 /usr/bin/curl net send-data write-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=d288c426-1b00-0000-bbab-6237af0c0000 pid=3247 execve guuid=c721ed2d-1b00-0000-bbab-6237b00c0000 pid=3248 /usr/bin/chmod guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=c721ed2d-1b00-0000-bbab-6237b00c0000 pid=3248 execve guuid=f501892e-1b00-0000-bbab-6237b10c0000 pid=3249 /usr/bin/bash guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=f501892e-1b00-0000-bbab-6237b10c0000 pid=3249 clone guuid=e1c9ce2e-1b00-0000-bbab-6237b20c0000 pid=3250 /usr/bin/rm delete-file guuid=4ed9766e-1a00-0000-bbab-6237d90a0000 pid=2777->guuid=e1c9ce2e-1b00-0000-bbab-6237b20c0000 pid=3250 execve 287a12f2-4a83-595d-96f2-f071a3f506da 41.216.189.47:80 guuid=50246674-1a00-0000-bbab-6237e90a0000 pid=2793->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=d62de67b-1a00-0000-bbab-6237f60a0000 pid=2806->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B guuid=b25ba188-1a00-0000-bbab-6237100b0000 pid=2832->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=6fac748c-1a00-0000-bbab-6237170b0000 pid=2839->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=d50f8294-1a00-0000-bbab-62372a0b0000 pid=2858->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=e7a1d897-1a00-0000-bbab-6237340b0000 pid=2868->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B guuid=2f7cad9c-1a00-0000-bbab-6237470b0000 pid=2887->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=de10aba1-1a00-0000-bbab-6237550b0000 pid=2901->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=f34e6ea6-1a00-0000-bbab-6237680b0000 pid=2920->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=459fdbaa-1a00-0000-bbab-6237730b0000 pid=2931->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=663821b2-1a00-0000-bbab-6237800b0000 pid=2944->287a12f2-4a83-595d-96f2-f071a3f506da send: 153B guuid=0e1480b6-1a00-0000-bbab-6237890b0000 pid=2953->287a12f2-4a83-595d-96f2-f071a3f506da send: 102B guuid=e7d625bd-1a00-0000-bbab-62379a0b0000 pid=2970->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=f6cb17c2-1a00-0000-bbab-6237a50b0000 pid=2981->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=22cd5bc8-1a00-0000-bbab-6237ba0b0000 pid=3002->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=ffad68cd-1a00-0000-bbab-6237c40b0000 pid=3012->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B guuid=08b5e0d4-1a00-0000-bbab-6237d90b0000 pid=3033->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=09af4cd9-1a00-0000-bbab-6237e50b0000 pid=3045->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=763a71df-1a00-0000-bbab-6237f70b0000 pid=3063->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=2b6910e4-1a00-0000-bbab-6237060c0000 pid=3078->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=39c1c7f3-1a00-0000-bbab-62372e0c0000 pid=3118->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=c9fe5ef7-1a00-0000-bbab-62373a0c0000 pid=3130->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=8e0444fe-1a00-0000-bbab-6237530c0000 pid=3155->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=1cb88e02-1b00-0000-bbab-62375e0c0000 pid=3166->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B guuid=0976a709-1b00-0000-bbab-6237790c0000 pid=3193->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=b940cc0e-1b00-0000-bbab-6237860c0000 pid=3206->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B guuid=356b0915-1b00-0000-bbab-6237950c0000 pid=3221->287a12f2-4a83-595d-96f2-f071a3f506da send: 151B guuid=127da219-1b00-0000-bbab-6237a00c0000 pid=3232->287a12f2-4a83-595d-96f2-f071a3f506da send: 100B guuid=e7aad322-1b00-0000-bbab-6237ae0c0000 pid=3246->287a12f2-4a83-595d-96f2-f071a3f506da send: 150B guuid=d288c426-1b00-0000-bbab-6237af0c0000 pid=3247->287a12f2-4a83-595d-96f2-f071a3f506da send: 99B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-19 02:08:01 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 63556748e8e14e485cbd2ee62c7eb01afd7fec0da2a4bec563014959e1404788

(this sample)

  
Delivery method
Distributed via web download

Comments