MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 64a93c5b0e32cd73f1312dc3d10a9cc63ee26e139ca1f5c9c9d580c120d73980. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 64a93c5b0e32cd73f1312dc3d10a9cc63ee26e139ca1f5c9c9d580c120d73980
SHA3-384 hash: 86daf563f8951d34cd7cf40acd58592cdb4d3add7e6b6a62b46b9901f39f2fb2ae188fa3866340a1ce12162e4d3d78bf
SHA1 hash: 083c557078857e922f01c865d722ca1cd0aaf37d
MD5 hash: eaa26f164b5006ab9db083c5b2ab9c15
humanhash: cola-pip-nuts-beer
File name:1.sh
Download: download sample
Signature Mirai
File size:3'224 bytes
First seen:2026-01-12 11:18:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Iti0C05si0X0Ei0w0yi0j0+Ti0Z0Xsi0B04i0sp0snJi0q0+Li0J0i1Li0yp0yNe:iibcX1RubJyNLaJLV3kLCJY
TLSH T1286172A9218252B43CB9CF63226D46183283C4B6ADDF7F46F5EC79E8809CE56F042742
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.1.31.175/windyloveyou/windy.x86bcfd1c9b186666483509dba5d0377d67e440449b7699f4304509855346cb6564 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.mips0bbed3bade9eb683c8de2830666302183923641e7d83a7fa4c5bdcf2a7a53d1e Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.arcc90c08d68c7f3844b7055f345eccca551e589bbe98a23b36c64370c159fa6679 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.i468n/an/aelf ua-wget
http://202.1.31.175/windyloveyou/windy.i68601563d7779828af88279dac3d95cd3332434f5be7963254e75dc4756cdb6235a Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.x86_64a16884f22c23b1eaf3cf4592db352d6059a8a7cb755bd99f5843bcaa77950d8b Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.mpsle92795e5c1b34a77a7233a5d184e29fb7149c120a05c3d105c998e2be63a2b42 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.arma1bb22f212902bebe68dfd700ec35da759169060b9ff62bac552037dde65d728 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.arm5cb52ae19dce8f112409e790bdffae28ae8514edd23e17f38b48b8df4bce83dae Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.arm617eb2359948a9d523b3c15b97364c0658eb74080c042d319518c9f706accdc15 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.arm76d0329f2cdaf6670732328f9f9ffd0282af6aa99e284643e44bf9b33f70cd9e9 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.ppc3cf072e8e36a2a49b1bc3dcf6fc1564fb72792af672906010282a19d3e118af2 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.spc458a71e1d9feb07eeb09cb2cc4b8dcabd9aaa89774687ba9aad1e6f1bd518d8a Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.m68k15d22fe6d17b10f7dcd5e5336526743926031355bc9b396a6644d59890b3fa71 Miraielf mirai ua-wget
http://202.1.31.175/windyloveyou/windy.sh476b5daf6bc1527726048d5ee444b5e2d79f99f519a1b290bbada05892cf14d78 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-12T08:25:00Z UTC
Last seen:
2026-01-14T09:00:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=0becdfd0-1f00-0000-6251-8914820a0000 pid=2690 /usr/bin/sudo guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697 /tmp/sample.bin guuid=0becdfd0-1f00-0000-6251-8914820a0000 pid=2690->guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697 execve guuid=c6fe74d3-1f00-0000-6251-89148b0a0000 pid=2699 /usr/bin/cp guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=c6fe74d3-1f00-0000-6251-89148b0a0000 pid=2699 execve guuid=3f6000db-1f00-0000-6251-8914a30a0000 pid=2723 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=3f6000db-1f00-0000-6251-8914a30a0000 pid=2723 execve guuid=1f2406fc-1f00-0000-6251-8914e20a0000 pid=2786 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=1f2406fc-1f00-0000-6251-8914e20a0000 pid=2786 execve guuid=4621fc3c-2000-0000-6251-8914240b0000 pid=2852 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=4621fc3c-2000-0000-6251-8914240b0000 pid=2852 execve guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853 /tmp/windy.x86 net guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853 execve guuid=8ac4fa69-2100-0000-6251-89145a0d0000 pid=3418 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=8ac4fa69-2100-0000-6251-89145a0d0000 pid=3418 execve guuid=29975e6a-2100-0000-6251-89145c0d0000 pid=3420 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=29975e6a-2100-0000-6251-89145c0d0000 pid=3420 execve guuid=e885fa91-2100-0000-6251-8914c00d0000 pid=3520 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=e885fa91-2100-0000-6251-8914c00d0000 pid=3520 execve guuid=f76ecab4-2100-0000-6251-8914090e0000 pid=3593 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=f76ecab4-2100-0000-6251-8914090e0000 pid=3593 execve guuid=d16415b5-2100-0000-6251-89140a0e0000 pid=3594 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=d16415b5-2100-0000-6251-89140a0e0000 pid=3594 clone guuid=726dfdb6-2100-0000-6251-8914100e0000 pid=3600 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=726dfdb6-2100-0000-6251-8914100e0000 pid=3600 execve guuid=db3f63bf-2100-0000-6251-8914110e0000 pid=3601 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=db3f63bf-2100-0000-6251-8914110e0000 pid=3601 execve guuid=65d774f1-2100-0000-6251-8914690e0000 pid=3689 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=65d774f1-2100-0000-6251-8914690e0000 pid=3689 execve guuid=b6455c26-2200-0000-6251-8914130f0000 pid=3859 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b6455c26-2200-0000-6251-8914130f0000 pid=3859 execve guuid=495d9e26-2200-0000-6251-8914150f0000 pid=3861 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=495d9e26-2200-0000-6251-8914150f0000 pid=3861 clone guuid=63853327-2200-0000-6251-8914190f0000 pid=3865 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=63853327-2200-0000-6251-8914190f0000 pid=3865 execve guuid=95678427-2200-0000-6251-89141c0f0000 pid=3868 /usr/bin/wget net send-data guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=95678427-2200-0000-6251-89141c0f0000 pid=3868 execve guuid=c573fa3b-2200-0000-6251-8914710f0000 pid=3953 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=c573fa3b-2200-0000-6251-8914710f0000 pid=3953 execve guuid=b629f651-2200-0000-6251-8914bb0f0000 pid=4027 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b629f651-2200-0000-6251-8914bb0f0000 pid=4027 execve guuid=a5b85c52-2200-0000-6251-8914bf0f0000 pid=4031 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=a5b85c52-2200-0000-6251-8914bf0f0000 pid=4031 clone guuid=29739652-2200-0000-6251-8914c00f0000 pid=4032 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=29739652-2200-0000-6251-8914c00f0000 pid=4032 execve guuid=16c4e352-2200-0000-6251-8914c40f0000 pid=4036 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=16c4e352-2200-0000-6251-8914c40f0000 pid=4036 execve guuid=28163a71-2200-0000-6251-89142d100000 pid=4141 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=28163a71-2200-0000-6251-89142d100000 pid=4141 execve guuid=8feeb292-2200-0000-6251-891499100000 pid=4249 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=8feeb292-2200-0000-6251-891499100000 pid=4249 execve guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251 /tmp/windy.i686 net guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251 execve guuid=17564cc0-2300-0000-6251-8914e7130000 pid=5095 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=17564cc0-2300-0000-6251-8914e7130000 pid=5095 execve guuid=5d76c0c0-2300-0000-6251-8914e9130000 pid=5097 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=5d76c0c0-2300-0000-6251-8914e9130000 pid=5097 execve guuid=abb011df-2300-0000-6251-891439140000 pid=5177 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=abb011df-2300-0000-6251-891439140000 pid=5177 execve guuid=bf42acfe-2300-0000-6251-891485140000 pid=5253 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=bf42acfe-2300-0000-6251-891485140000 pid=5253 execve guuid=68c60cff-2300-0000-6251-891486140000 pid=5254 /tmp/windy.x86_64 mprotect-exec net guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=68c60cff-2300-0000-6251-891486140000 pid=5254 execve guuid=719f362a-2500-0000-6251-89149e140000 pid=5278 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=719f362a-2500-0000-6251-89149e140000 pid=5278 execve guuid=5eb5162b-2500-0000-6251-89149f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=5eb5162b-2500-0000-6251-89149f140000 pid=5279 execve guuid=b7a15e55-2500-0000-6251-8914a0140000 pid=5280 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b7a15e55-2500-0000-6251-8914a0140000 pid=5280 execve guuid=fbbc2f83-2500-0000-6251-8914a1140000 pid=5281 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=fbbc2f83-2500-0000-6251-8914a1140000 pid=5281 execve guuid=b9499e83-2500-0000-6251-8914a2140000 pid=5282 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b9499e83-2500-0000-6251-8914a2140000 pid=5282 clone guuid=de089d84-2500-0000-6251-8914a4140000 pid=5284 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=de089d84-2500-0000-6251-8914a4140000 pid=5284 execve guuid=183d1485-2500-0000-6251-8914a5140000 pid=5285 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=183d1485-2500-0000-6251-8914a5140000 pid=5285 execve guuid=d9782aaa-2500-0000-6251-8914a6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=d9782aaa-2500-0000-6251-8914a6140000 pid=5286 execve guuid=3ac7ddc9-2500-0000-6251-8914a7140000 pid=5287 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=3ac7ddc9-2500-0000-6251-8914a7140000 pid=5287 execve guuid=cd5d56ca-2500-0000-6251-8914a8140000 pid=5288 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=cd5d56ca-2500-0000-6251-8914a8140000 pid=5288 clone guuid=c9c05bcb-2500-0000-6251-8914aa140000 pid=5290 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=c9c05bcb-2500-0000-6251-8914aa140000 pid=5290 execve guuid=bd27aacb-2500-0000-6251-8914ab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=bd27aacb-2500-0000-6251-8914ab140000 pid=5291 execve guuid=3df8efe9-2500-0000-6251-8914ac140000 pid=5292 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=3df8efe9-2500-0000-6251-8914ac140000 pid=5292 execve guuid=bb05d90a-2600-0000-6251-8914b1140000 pid=5297 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=bb05d90a-2600-0000-6251-8914b1140000 pid=5297 execve guuid=c373770b-2600-0000-6251-8914b3140000 pid=5299 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=c373770b-2600-0000-6251-8914b3140000 pid=5299 clone guuid=7e07c80c-2600-0000-6251-8914b6140000 pid=5302 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=7e07c80c-2600-0000-6251-8914b6140000 pid=5302 execve guuid=5a3b0b17-2600-0000-6251-8914b7140000 pid=5303 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=5a3b0b17-2600-0000-6251-8914b7140000 pid=5303 execve guuid=5fe09a3f-2600-0000-6251-8914bf140000 pid=5311 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=5fe09a3f-2600-0000-6251-8914bf140000 pid=5311 execve guuid=4f80aa69-2600-0000-6251-8914c5140000 pid=5317 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=4f80aa69-2600-0000-6251-8914c5140000 pid=5317 execve guuid=47c91c6a-2600-0000-6251-8914c6140000 pid=5318 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=47c91c6a-2600-0000-6251-8914c6140000 pid=5318 clone guuid=08a3046b-2600-0000-6251-8914ca140000 pid=5322 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=08a3046b-2600-0000-6251-8914ca140000 pid=5322 execve guuid=ec5a4d6b-2600-0000-6251-8914cb140000 pid=5323 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=ec5a4d6b-2600-0000-6251-8914cb140000 pid=5323 execve guuid=33abb893-2600-0000-6251-8914d8140000 pid=5336 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=33abb893-2600-0000-6251-8914d8140000 pid=5336 execve guuid=cd3c58bc-2600-0000-6251-8914d9140000 pid=5337 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=cd3c58bc-2600-0000-6251-8914d9140000 pid=5337 execve guuid=23c6a7bc-2600-0000-6251-8914da140000 pid=5338 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=23c6a7bc-2600-0000-6251-8914da140000 pid=5338 clone guuid=9ff34dbd-2600-0000-6251-8914dc140000 pid=5340 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=9ff34dbd-2600-0000-6251-8914dc140000 pid=5340 execve guuid=b34ac2bd-2600-0000-6251-8914dd140000 pid=5341 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b34ac2bd-2600-0000-6251-8914dd140000 pid=5341 execve guuid=d2698adc-2600-0000-6251-8914de140000 pid=5342 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=d2698adc-2600-0000-6251-8914de140000 pid=5342 execve guuid=160e16fd-2600-0000-6251-8914df140000 pid=5343 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=160e16fd-2600-0000-6251-8914df140000 pid=5343 execve guuid=812385fd-2600-0000-6251-8914e0140000 pid=5344 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=812385fd-2600-0000-6251-8914e0140000 pid=5344 clone guuid=e9d070fe-2600-0000-6251-8914e2140000 pid=5346 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=e9d070fe-2600-0000-6251-8914e2140000 pid=5346 execve guuid=96eedcfe-2600-0000-6251-8914e3140000 pid=5347 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=96eedcfe-2600-0000-6251-8914e3140000 pid=5347 execve guuid=1b830927-2700-0000-6251-8914e4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=1b830927-2700-0000-6251-8914e4140000 pid=5348 execve guuid=2b8fc053-2700-0000-6251-8914e5140000 pid=5349 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=2b8fc053-2700-0000-6251-8914e5140000 pid=5349 execve guuid=cee90754-2700-0000-6251-8914e6140000 pid=5350 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=cee90754-2700-0000-6251-8914e6140000 pid=5350 clone guuid=6835b854-2700-0000-6251-8914e8140000 pid=5352 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=6835b854-2700-0000-6251-8914e8140000 pid=5352 execve guuid=1cd40b55-2700-0000-6251-8914e9140000 pid=5353 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=1cd40b55-2700-0000-6251-8914e9140000 pid=5353 execve guuid=b971487f-2700-0000-6251-8914ea140000 pid=5354 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=b971487f-2700-0000-6251-8914ea140000 pid=5354 execve guuid=497b43a8-2700-0000-6251-8914eb140000 pid=5355 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=497b43a8-2700-0000-6251-8914eb140000 pid=5355 execve guuid=368f88a8-2700-0000-6251-8914ec140000 pid=5356 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=368f88a8-2700-0000-6251-8914ec140000 pid=5356 clone guuid=7dc32ea9-2700-0000-6251-8914ee140000 pid=5358 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=7dc32ea9-2700-0000-6251-8914ee140000 pid=5358 execve guuid=504c81a9-2700-0000-6251-8914ef140000 pid=5359 /usr/bin/wget net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=504c81a9-2700-0000-6251-8914ef140000 pid=5359 execve guuid=43eed8d1-2700-0000-6251-8914f0140000 pid=5360 /usr/bin/curl net send-data write-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=43eed8d1-2700-0000-6251-8914f0140000 pid=5360 execve guuid=7e7681fb-2700-0000-6251-8914f1140000 pid=5361 /usr/bin/chmod guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=7e7681fb-2700-0000-6251-8914f1140000 pid=5361 execve guuid=091cc7fb-2700-0000-6251-8914f2140000 pid=5362 /usr/bin/bash guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=091cc7fb-2700-0000-6251-8914f2140000 pid=5362 clone guuid=87ef50fc-2700-0000-6251-8914f4140000 pid=5364 /usr/bin/rm delete-file guuid=83fb1ed3-1f00-0000-6251-8914890a0000 pid=2697->guuid=87ef50fc-2700-0000-6251-8914f4140000 pid=5364 execve a3e10e98-30b9-575a-ae66-9e9cefd70a4c 202.1.31.175:80 guuid=3f6000db-1f00-0000-6251-8914a30a0000 pid=2723->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=1f2406fc-1f00-0000-6251-8914e20a0000 pid=2786->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1b91ca3d-2000-0000-6251-8914270b0000 pid=2855 /tmp/windy.x86 guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853->guuid=1b91ca3d-2000-0000-6251-8914270b0000 pid=2855 clone guuid=2053ed69-2100-0000-6251-8914580d0000 pid=3416 /tmp/windy.x86 guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853->guuid=2053ed69-2100-0000-6251-8914580d0000 pid=3416 clone guuid=4f12f269-2100-0000-6251-8914590d0000 pid=3417 /tmp/windy.x86 net send-data zombie guuid=e3b7423d-2000-0000-6251-8914250b0000 pid=2853->guuid=4f12f269-2100-0000-6251-8914590d0000 pid=3417 clone guuid=aef7d93d-2000-0000-6251-8914280b0000 pid=2856 /tmp/windy.x86 guuid=1b91ca3d-2000-0000-6251-8914270b0000 pid=2855->guuid=aef7d93d-2000-0000-6251-8914280b0000 pid=2856 clone guuid=85f0df3d-2000-0000-6251-8914290b0000 pid=2857 /tmp/windy.x86 dns net send-data zombie guuid=1b91ca3d-2000-0000-6251-8914270b0000 pid=2855->guuid=85f0df3d-2000-0000-6251-8914290b0000 pid=2857 clone guuid=85f0df3d-2000-0000-6251-8914290b0000 pid=2857->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=85f0df3d-2000-0000-6251-8914290b0000 pid=2857->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=4f12f269-2100-0000-6251-8914590d0000 pid=3417->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 775B guuid=4f12f269-2100-0000-6251-8914590d0000 pid=3417->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=29975e6a-2100-0000-6251-89145c0d0000 pid=3420->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=e885fa91-2100-0000-6251-8914c00d0000 pid=3520->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=db3f63bf-2100-0000-6251-8914110e0000 pid=3601->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=65d774f1-2100-0000-6251-8914690e0000 pid=3689->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B guuid=95678427-2200-0000-6251-89141c0f0000 pid=3868->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=c573fa3b-2200-0000-6251-8914710f0000 pid=3953->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=16c4e352-2200-0000-6251-8914c40f0000 pid=4036->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=28163a71-2200-0000-6251-89142d100000 pid=4141->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6357c093-2200-0000-6251-89149f100000 pid=4255 /tmp/windy.i686 guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251->guuid=6357c093-2200-0000-6251-89149f100000 pid=4255 clone guuid=0a4c35c0-2300-0000-6251-8914e5130000 pid=5093 /tmp/windy.i686 guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251->guuid=0a4c35c0-2300-0000-6251-8914e5130000 pid=5093 clone guuid=dd593dc0-2300-0000-6251-8914e6130000 pid=5094 /tmp/windy.i686 net send-data zombie guuid=1fcf0793-2200-0000-6251-89149b100000 pid=4251->guuid=dd593dc0-2300-0000-6251-8914e6130000 pid=5094 clone guuid=f0a2d393-2200-0000-6251-8914a0100000 pid=4256 /tmp/windy.i686 guuid=6357c093-2200-0000-6251-89149f100000 pid=4255->guuid=f0a2d393-2200-0000-6251-8914a0100000 pid=4256 clone guuid=6013dd93-2200-0000-6251-8914a2100000 pid=4258 /tmp/windy.i686 dns net send-data zombie guuid=6357c093-2200-0000-6251-89149f100000 pid=4255->guuid=6013dd93-2200-0000-6251-8914a2100000 pid=4258 clone guuid=6013dd93-2200-0000-6251-8914a2100000 pid=4258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B guuid=6013dd93-2200-0000-6251-8914a2100000 pid=4258->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=dd593dc0-2300-0000-6251-8914e6130000 pid=5094->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 620B guuid=dd593dc0-2300-0000-6251-8914e6130000 pid=5094->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=5d76c0c0-2300-0000-6251-8914e9130000 pid=5097->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 152B guuid=abb011df-2300-0000-6251-891439140000 pid=5177->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 101B guuid=68c60cff-2300-0000-6251-891486140000 pid=5254->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=29e88eff-2300-0000-6251-891487140000 pid=5255 /tmp/windy.x86_64 guuid=68c60cff-2300-0000-6251-891486140000 pid=5254->guuid=29e88eff-2300-0000-6251-891487140000 pid=5255 clone guuid=45a1122a-2500-0000-6251-89149c140000 pid=5276 /tmp/windy.x86_64 guuid=68c60cff-2300-0000-6251-891486140000 pid=5254->guuid=45a1122a-2500-0000-6251-89149c140000 pid=5276 clone guuid=efb91e2a-2500-0000-6251-89149d140000 pid=5277 /tmp/windy.x86_64 net send-data zombie guuid=68c60cff-2300-0000-6251-891486140000 pid=5254->guuid=efb91e2a-2500-0000-6251-89149d140000 pid=5277 clone guuid=e7e09bff-2300-0000-6251-891488140000 pid=5256 /tmp/windy.x86_64 guuid=29e88eff-2300-0000-6251-891487140000 pid=5255->guuid=e7e09bff-2300-0000-6251-891488140000 pid=5256 clone guuid=79fd9eff-2300-0000-6251-891489140000 pid=5257 /tmp/windy.x86_64 net send-data zombie guuid=29e88eff-2300-0000-6251-891487140000 pid=5255->guuid=79fd9eff-2300-0000-6251-891489140000 pid=5257 clone guuid=79fd9eff-2300-0000-6251-891489140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 620B guuid=79fd9eff-2300-0000-6251-891489140000 pid=5257->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=efb91e2a-2500-0000-6251-89149d140000 pid=5277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 620B guuid=efb91e2a-2500-0000-6251-89149d140000 pid=5277->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=5eb5162b-2500-0000-6251-89149f140000 pid=5279->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=b7a15e55-2500-0000-6251-8914a0140000 pid=5280->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=183d1485-2500-0000-6251-8914a5140000 pid=5285->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=d9782aaa-2500-0000-6251-8914a6140000 pid=5286->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B guuid=bd27aacb-2500-0000-6251-8914ab140000 pid=5291->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=3df8efe9-2500-0000-6251-8914ac140000 pid=5292->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=5a3b0b17-2600-0000-6251-8914b7140000 pid=5303->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=5fe09a3f-2600-0000-6251-8914bf140000 pid=5311->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=ec5a4d6b-2600-0000-6251-8914cb140000 pid=5323->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=33abb893-2600-0000-6251-8914d8140000 pid=5336->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=b34ac2bd-2600-0000-6251-8914dd140000 pid=5341->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=d2698adc-2600-0000-6251-8914de140000 pid=5342->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B guuid=96eedcfe-2600-0000-6251-8914e3140000 pid=5347->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=1b830927-2700-0000-6251-8914e4140000 pid=5348->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B guuid=1cd40b55-2700-0000-6251-8914e9140000 pid=5353->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 150B guuid=b971487f-2700-0000-6251-8914ea140000 pid=5354->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 99B guuid=504c81a9-2700-0000-6251-8914ef140000 pid=5359->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 149B guuid=43eed8d1-2700-0000-6251-8914f0140000 pid=5360->a3e10e98-30b9-575a-ae66-9e9cefd70a4c send: 98B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-12 11:08:04 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
202.1.31.175
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 64a93c5b0e32cd73f1312dc3d10a9cc63ee26e139ca1f5c9c9d580c120d73980

(this sample)

  
Delivery method
Distributed via web download

Comments