MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6bee097968d5468854f58ae86da97e0d87801dece2f9545dce00541e1e8c8744. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 6bee097968d5468854f58ae86da97e0d87801dece2f9545dce00541e1e8c8744
SHA3-384 hash: fdc49affdea5fca94444e948621689ce6a57633610ac70c21049eb9a5bbedcf8fba8e49e812e0b46033e1831937a2041
SHA1 hash: b1c45d524e5174dfacd88d01497e5d8f6eea8287
MD5 hash: f699d79490fb19659936bf2ee6a6e42f
humanhash: massachusetts-lactose-two-stream
File name:fentbins.sh
Download: download sample
Signature Mirai
File size:1'857 bytes
First seen:2026-01-13 06:18:00 UTC
Last seen:2026-01-13 18:38:58 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iqxdqCUqRheGqvCkqMcLqZtJq2MqS8qnRqOz:iqxdqCUqLeGqvdqMcLqZ7q2MqS8qnRqa
TLSH T14A312FC52341353169A1DD2B7ABBC984B2F47065BEC52A2966D83CE8C1DCF08FC51F92
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.112.124/bins/fent.x860d32236bfdd18985046bc80818bfa5b8baec2ca0a982d61bf4b62d898d94d08f Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.mips6668094256bac1ecf829e2686192d4de0322c65ad24b6bce0137dc1ca5ccb844 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.mpsl7b3f23580daa37bf9fc7811a111b25ad60eeb3b6ebed2fb531fd3b44fb2ee8a6 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm4n/an/aelf ua-wget
http://87.121.112.124/bins/fent.arm53b50fa8b73b431bf3c4ceafc12bbf57d7227d1f2586cb6cabe5fded45e511d55 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm67b9538d470db982bd0b900a517de9275c8a2a9427657a85358f1da8723a7814c Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm71bf10173feab7e57ff553a91fa313a213a025f5e295852db136707fe1173bb14 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.ppcae1a3bf5a75f9610aa20349f03c58bb144b7de874fd4800ec477934dd0ebfeb8 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.m68k0a147ad163eb46d153a692d285093dd08042cc9f377fe75cff63189e5c82eee8 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.sh405733b6df5ecb188fcece2cce03ee0cd4926facf754d10a2b6e8143c315ba18a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=78620175-1900-0000-3586-224e66140000 pid=5222 /usr/bin/sudo guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223 /tmp/sample.bin guuid=78620175-1900-0000-3586-224e66140000 pid=5222->guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223 execve guuid=8973127b-1900-0000-3586-224e68140000 pid=5224 /usr/bin/cp guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=8973127b-1900-0000-3586-224e68140000 pid=5224 execve guuid=cd498e81-1900-0000-3586-224e69140000 pid=5225 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=cd498e81-1900-0000-3586-224e69140000 pid=5225 execve guuid=c2a92c91-1900-0000-3586-224e6a140000 pid=5226 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=c2a92c91-1900-0000-3586-224e6a140000 pid=5226 execve guuid=b837bca9-1900-0000-3586-224e72140000 pid=5234 /usr/bin/cat guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=b837bca9-1900-0000-3586-224e72140000 pid=5234 execve guuid=312f2faa-1900-0000-3586-224e73140000 pid=5235 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=312f2faa-1900-0000-3586-224e73140000 pid=5235 execve guuid=604991aa-1900-0000-3586-224e74140000 pid=5236 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=604991aa-1900-0000-3586-224e74140000 pid=5236 execve guuid=2c3dd6aa-1900-0000-3586-224e77140000 pid=5239 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=2c3dd6aa-1900-0000-3586-224e77140000 pid=5239 execve guuid=6a2d9db8-1900-0000-3586-224e78140000 pid=5240 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=6a2d9db8-1900-0000-3586-224e78140000 pid=5240 execve guuid=c9f96dc8-1900-0000-3586-224e79140000 pid=5241 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=c9f96dc8-1900-0000-3586-224e79140000 pid=5241 clone guuid=02babcc8-1900-0000-3586-224e7a140000 pid=5242 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=02babcc8-1900-0000-3586-224e7a140000 pid=5242 execve guuid=962ed5c9-1900-0000-3586-224e7b140000 pid=5243 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=962ed5c9-1900-0000-3586-224e7b140000 pid=5243 execve guuid=45bc91f4-1a00-0000-3586-224e8e140000 pid=5262 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=45bc91f4-1a00-0000-3586-224e8e140000 pid=5262 execve guuid=83254903-1b00-0000-3586-224e98140000 pid=5272 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=83254903-1b00-0000-3586-224e98140000 pid=5272 execve guuid=edec0010-1b00-0000-3586-224ea0140000 pid=5280 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=edec0010-1b00-0000-3586-224ea0140000 pid=5280 clone guuid=12a22910-1b00-0000-3586-224ea1140000 pid=5281 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=12a22910-1b00-0000-3586-224ea1140000 pid=5281 execve guuid=ad977810-1b00-0000-3586-224ea2140000 pid=5282 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=ad977810-1b00-0000-3586-224ea2140000 pid=5282 execve guuid=752cd13a-1c00-0000-3586-224ea5140000 pid=5285 /usr/bin/wget net send-data guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=752cd13a-1c00-0000-3586-224ea5140000 pid=5285 execve guuid=4fce4241-1c00-0000-3586-224ea6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=4fce4241-1c00-0000-3586-224ea6140000 pid=5286 execve guuid=d62c5b48-1c00-0000-3586-224ea7140000 pid=5287 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=d62c5b48-1c00-0000-3586-224ea7140000 pid=5287 clone guuid=a9db7748-1c00-0000-3586-224ea8140000 pid=5288 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=a9db7748-1c00-0000-3586-224ea8140000 pid=5288 execve guuid=5154b948-1c00-0000-3586-224ea9140000 pid=5289 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=5154b948-1c00-0000-3586-224ea9140000 pid=5289 execve guuid=51ca3d73-1d00-0000-3586-224eac140000 pid=5292 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=51ca3d73-1d00-0000-3586-224eac140000 pid=5292 execve guuid=3c32527d-1d00-0000-3586-224ead140000 pid=5293 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=3c32527d-1d00-0000-3586-224ead140000 pid=5293 execve guuid=aeb95589-1d00-0000-3586-224eae140000 pid=5294 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=aeb95589-1d00-0000-3586-224eae140000 pid=5294 clone guuid=84e09889-1d00-0000-3586-224eaf140000 pid=5295 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=84e09889-1d00-0000-3586-224eaf140000 pid=5295 execve guuid=3106298a-1d00-0000-3586-224eb0140000 pid=5296 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=3106298a-1d00-0000-3586-224eb0140000 pid=5296 execve guuid=3f4ec3b4-1e00-0000-3586-224eb3140000 pid=5299 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=3f4ec3b4-1e00-0000-3586-224eb3140000 pid=5299 execve guuid=b0f70fc2-1e00-0000-3586-224eb4140000 pid=5300 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=b0f70fc2-1e00-0000-3586-224eb4140000 pid=5300 execve guuid=8d50f0d0-1e00-0000-3586-224eb5140000 pid=5301 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=8d50f0d0-1e00-0000-3586-224eb5140000 pid=5301 clone guuid=26d63cd1-1e00-0000-3586-224eb6140000 pid=5302 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=26d63cd1-1e00-0000-3586-224eb6140000 pid=5302 execve guuid=4eccd1d1-1e00-0000-3586-224eb7140000 pid=5303 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=4eccd1d1-1e00-0000-3586-224eb7140000 pid=5303 execve guuid=5bd093fc-1f00-0000-3586-224eb9140000 pid=5305 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=5bd093fc-1f00-0000-3586-224eb9140000 pid=5305 execve guuid=9c60ef0b-2000-0000-3586-224ebb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=9c60ef0b-2000-0000-3586-224ebb140000 pid=5307 execve guuid=c38de01c-2000-0000-3586-224ebc140000 pid=5308 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=c38de01c-2000-0000-3586-224ebc140000 pid=5308 clone guuid=ddab121d-2000-0000-3586-224ebd140000 pid=5309 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=ddab121d-2000-0000-3586-224ebd140000 pid=5309 execve guuid=85899d1d-2000-0000-3586-224ebe140000 pid=5310 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=85899d1d-2000-0000-3586-224ebe140000 pid=5310 execve guuid=1d9b4148-2100-0000-3586-224ec1140000 pid=5313 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=1d9b4148-2100-0000-3586-224ec1140000 pid=5313 execve guuid=ea724855-2100-0000-3586-224ec2140000 pid=5314 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=ea724855-2100-0000-3586-224ec2140000 pid=5314 execve guuid=60d80064-2100-0000-3586-224ec3140000 pid=5315 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=60d80064-2100-0000-3586-224ec3140000 pid=5315 clone guuid=45d63b64-2100-0000-3586-224ec4140000 pid=5316 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=45d63b64-2100-0000-3586-224ec4140000 pid=5316 execve guuid=9066d864-2100-0000-3586-224ec5140000 pid=5317 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=9066d864-2100-0000-3586-224ec5140000 pid=5317 execve guuid=0e10798f-2200-0000-3586-224ec7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=0e10798f-2200-0000-3586-224ec7140000 pid=5319 execve guuid=470c119c-2200-0000-3586-224ec9140000 pid=5321 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=470c119c-2200-0000-3586-224ec9140000 pid=5321 execve guuid=815cc5aa-2200-0000-3586-224eca140000 pid=5322 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=815cc5aa-2200-0000-3586-224eca140000 pid=5322 clone guuid=3f0ffcaa-2200-0000-3586-224ecb140000 pid=5323 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=3f0ffcaa-2200-0000-3586-224ecb140000 pid=5323 execve guuid=cf9195ab-2200-0000-3586-224ecc140000 pid=5324 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=cf9195ab-2200-0000-3586-224ecc140000 pid=5324 execve guuid=5d7e31d6-2300-0000-3586-224ece140000 pid=5326 /usr/bin/wget net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=5d7e31d6-2300-0000-3586-224ece140000 pid=5326 execve guuid=256ef1e2-2300-0000-3586-224ed0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=256ef1e2-2300-0000-3586-224ed0140000 pid=5328 execve guuid=6a9dfff0-2300-0000-3586-224ed1140000 pid=5329 /usr/bin/bash guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=6a9dfff0-2300-0000-3586-224ed1140000 pid=5329 clone guuid=26ca3af1-2300-0000-3586-224ed2140000 pid=5330 /usr/bin/chmod guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=26ca3af1-2300-0000-3586-224ed2140000 pid=5330 execve guuid=6ea4c9f1-2300-0000-3586-224ed3140000 pid=5331 /tmp/cp net guuid=b9ec9279-1900-0000-3586-224e67140000 pid=5223->guuid=6ea4c9f1-2300-0000-3586-224ed3140000 pid=5331 execve efef254e-80b3-5bfb-b0bf-2e8b7a7434cf 87.121.112.124:80 guuid=cd498e81-1900-0000-3586-224e69140000 pid=5225->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=c2a92c91-1900-0000-3586-224e6a140000 pid=5226->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=604991aa-1900-0000-3586-224e74140000 pid=5236->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8fdabfaa-1900-0000-3586-224e75140000 pid=5237 /tmp/cp net send-data zombie guuid=604991aa-1900-0000-3586-224e74140000 pid=5236->guuid=8fdabfaa-1900-0000-3586-224e75140000 pid=5237 clone guuid=8fdabfaa-1900-0000-3586-224e75140000 pid=5237->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con df7c0f9f-a1b8-565b-9132-7cd03da85718 87.121.112.124:911 guuid=8fdabfaa-1900-0000-3586-224e75140000 pid=5237->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 8B guuid=427acdaa-1900-0000-3586-224e76140000 pid=5238 /tmp/cp guuid=8fdabfaa-1900-0000-3586-224e75140000 pid=5237->guuid=427acdaa-1900-0000-3586-224e76140000 pid=5238 clone guuid=2c3dd6aa-1900-0000-3586-224e77140000 pid=5239->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=6a2d9db8-1900-0000-3586-224e78140000 pid=5240->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=962ed5c9-1900-0000-3586-224e7b140000 pid=5243->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b9502367-5dd5-56e5-a2d2-9be7d9d70400 0.0.0.0:39148 guuid=962ed5c9-1900-0000-3586-224e7b140000 pid=5243->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=8b837bf4-1a00-0000-3586-224e8c140000 pid=5260 /tmp/cp net send-data zombie guuid=962ed5c9-1900-0000-3586-224e7b140000 pid=5243->guuid=8b837bf4-1a00-0000-3586-224e8c140000 pid=5260 clone guuid=8b837bf4-1a00-0000-3586-224e8c140000 pid=5260->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8b837bf4-1a00-0000-3586-224e8c140000 pid=5260->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=362b90f4-1a00-0000-3586-224e8d140000 pid=5261 /tmp/cp guuid=8b837bf4-1a00-0000-3586-224e8c140000 pid=5260->guuid=362b90f4-1a00-0000-3586-224e8d140000 pid=5261 clone guuid=45bc91f4-1a00-0000-3586-224e8e140000 pid=5262->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=83254903-1b00-0000-3586-224e98140000 pid=5272->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=ad977810-1b00-0000-3586-224ea2140000 pid=5282->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ad977810-1b00-0000-3586-224ea2140000 pid=5282->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=52a6bf3a-1c00-0000-3586-224ea3140000 pid=5283 /tmp/cp net send-data zombie guuid=ad977810-1b00-0000-3586-224ea2140000 pid=5282->guuid=52a6bf3a-1c00-0000-3586-224ea3140000 pid=5283 clone guuid=52a6bf3a-1c00-0000-3586-224ea3140000 pid=5283->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=52a6bf3a-1c00-0000-3586-224ea3140000 pid=5283->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=13d4d03a-1c00-0000-3586-224ea4140000 pid=5284 /tmp/cp guuid=52a6bf3a-1c00-0000-3586-224ea3140000 pid=5283->guuid=13d4d03a-1c00-0000-3586-224ea4140000 pid=5284 clone guuid=752cd13a-1c00-0000-3586-224ea5140000 pid=5285->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=4fce4241-1c00-0000-3586-224ea6140000 pid=5286->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=5154b948-1c00-0000-3586-224ea9140000 pid=5289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5154b948-1c00-0000-3586-224ea9140000 pid=5289->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=9cde1a73-1d00-0000-3586-224eaa140000 pid=5290 /tmp/cp net send-data zombie guuid=5154b948-1c00-0000-3586-224ea9140000 pid=5289->guuid=9cde1a73-1d00-0000-3586-224eaa140000 pid=5290 clone guuid=9cde1a73-1d00-0000-3586-224eaa140000 pid=5290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9cde1a73-1d00-0000-3586-224eaa140000 pid=5290->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=1dca3273-1d00-0000-3586-224eab140000 pid=5291 /tmp/cp guuid=9cde1a73-1d00-0000-3586-224eaa140000 pid=5290->guuid=1dca3273-1d00-0000-3586-224eab140000 pid=5291 clone guuid=51ca3d73-1d00-0000-3586-224eac140000 pid=5292->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=3c32527d-1d00-0000-3586-224ead140000 pid=5293->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=3106298a-1d00-0000-3586-224eb0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3106298a-1d00-0000-3586-224eb0140000 pid=5296->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=a3a7a6b4-1e00-0000-3586-224eb1140000 pid=5297 /tmp/cp net send-data zombie guuid=3106298a-1d00-0000-3586-224eb0140000 pid=5296->guuid=a3a7a6b4-1e00-0000-3586-224eb1140000 pid=5297 clone guuid=a3a7a6b4-1e00-0000-3586-224eb1140000 pid=5297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a3a7a6b4-1e00-0000-3586-224eb1140000 pid=5297->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=b08ec2b4-1e00-0000-3586-224eb2140000 pid=5298 /tmp/cp guuid=a3a7a6b4-1e00-0000-3586-224eb1140000 pid=5297->guuid=b08ec2b4-1e00-0000-3586-224eb2140000 pid=5298 clone guuid=3f4ec3b4-1e00-0000-3586-224eb3140000 pid=5299->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=b0f70fc2-1e00-0000-3586-224eb4140000 pid=5300->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=4eccd1d1-1e00-0000-3586-224eb7140000 pid=5303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4eccd1d1-1e00-0000-3586-224eb7140000 pid=5303->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=d23878fc-1f00-0000-3586-224eb8140000 pid=5304 /tmp/cp net send-data zombie guuid=4eccd1d1-1e00-0000-3586-224eb7140000 pid=5303->guuid=d23878fc-1f00-0000-3586-224eb8140000 pid=5304 clone guuid=d23878fc-1f00-0000-3586-224eb8140000 pid=5304->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d23878fc-1f00-0000-3586-224eb8140000 pid=5304->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=a42e9cfc-1f00-0000-3586-224eba140000 pid=5306 /tmp/cp guuid=d23878fc-1f00-0000-3586-224eb8140000 pid=5304->guuid=a42e9cfc-1f00-0000-3586-224eba140000 pid=5306 clone guuid=5bd093fc-1f00-0000-3586-224eb9140000 pid=5305->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=9c60ef0b-2000-0000-3586-224ebb140000 pid=5307->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=85899d1d-2000-0000-3586-224ebe140000 pid=5310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=85899d1d-2000-0000-3586-224ebe140000 pid=5310->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=b1ca2048-2100-0000-3586-224ebf140000 pid=5311 /tmp/cp net send-data zombie guuid=85899d1d-2000-0000-3586-224ebe140000 pid=5310->guuid=b1ca2048-2100-0000-3586-224ebf140000 pid=5311 clone guuid=b1ca2048-2100-0000-3586-224ebf140000 pid=5311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b1ca2048-2100-0000-3586-224ebf140000 pid=5311->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=dff73b48-2100-0000-3586-224ec0140000 pid=5312 /tmp/cp guuid=b1ca2048-2100-0000-3586-224ebf140000 pid=5311->guuid=dff73b48-2100-0000-3586-224ec0140000 pid=5312 clone guuid=1d9b4148-2100-0000-3586-224ec1140000 pid=5313->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=ea724855-2100-0000-3586-224ec2140000 pid=5314->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B guuid=9066d864-2100-0000-3586-224ec5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9066d864-2100-0000-3586-224ec5140000 pid=5317->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=80055c8f-2200-0000-3586-224ec6140000 pid=5318 /tmp/cp net send-data zombie guuid=9066d864-2100-0000-3586-224ec5140000 pid=5317->guuid=80055c8f-2200-0000-3586-224ec6140000 pid=5318 clone guuid=80055c8f-2200-0000-3586-224ec6140000 pid=5318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=80055c8f-2200-0000-3586-224ec6140000 pid=5318->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 8B guuid=552c7b8f-2200-0000-3586-224ec8140000 pid=5320 /tmp/cp guuid=80055c8f-2200-0000-3586-224ec6140000 pid=5318->guuid=552c7b8f-2200-0000-3586-224ec8140000 pid=5320 clone guuid=0e10798f-2200-0000-3586-224ec7140000 pid=5319->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=470c119c-2200-0000-3586-224ec9140000 pid=5321->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=cf9195ab-2200-0000-3586-224ecc140000 pid=5324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf9195ab-2200-0000-3586-224ecc140000 pid=5324->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=f49818d6-2300-0000-3586-224ecd140000 pid=5325 /tmp/cp net send-data zombie guuid=cf9195ab-2200-0000-3586-224ecc140000 pid=5324->guuid=f49818d6-2300-0000-3586-224ecd140000 pid=5325 clone guuid=f49818d6-2300-0000-3586-224ecd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f49818d6-2300-0000-3586-224ecd140000 pid=5325->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=f61732d6-2300-0000-3586-224ecf140000 pid=5327 /tmp/cp guuid=f49818d6-2300-0000-3586-224ecd140000 pid=5325->guuid=f61732d6-2300-0000-3586-224ecf140000 pid=5327 clone guuid=5d7e31d6-2300-0000-3586-224ece140000 pid=5326->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=256ef1e2-2300-0000-3586-224ed0140000 pid=5328->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B guuid=6ea4c9f1-2300-0000-3586-224ed3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6ea4c9f1-2300-0000-3586-224ed3140000 pid=5331->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=91574e1c-2500-0000-3586-224ed4140000 pid=5332 /tmp/cp net send-data zombie guuid=6ea4c9f1-2300-0000-3586-224ed3140000 pid=5331->guuid=91574e1c-2500-0000-3586-224ed4140000 pid=5332 clone guuid=91574e1c-2500-0000-3586-224ed4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=91574e1c-2500-0000-3586-224ed4140000 pid=5332->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 10B guuid=6b3a6f1c-2500-0000-3586-224ed5140000 pid=5333 /tmp/cp guuid=91574e1c-2500-0000-3586-224ed4140000 pid=5332->guuid=6b3a6f1c-2500-0000-3586-224ed5140000 pid=5333 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-13 05:22:50 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6bee097968d5468854f58ae86da97e0d87801dece2f9545dce00541e1e8c8744

(this sample)

Comments