MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7b4acd4f11779c0b1016957bad0cbc77b90e630177aeff6c60c09f86d7b744a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 7b4acd4f11779c0b1016957bad0cbc77b90e630177aeff6c60c09f86d7b744a2
SHA3-384 hash: b52745e4239f37a35ee788f957661a5f1b8a743f62c7adf9a7a759caa5e393e4147aaff5b49c72cd333294ade07145cd
SHA1 hash: 14ffdf9a4a5220cc9389cbd8b56d0f7bc6a1abb0
MD5 hash: 952a16d5625c23f01d6950778ccdc782
humanhash: fanta-mango-november-enemy
File name:test.sh
Download: download sample
Signature Mirai
File size:2'466 bytes
First seen:2025-08-19 01:55:21 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:UeGKG/se9yseGTGUjseh3Gsea5ser8sezSzZsepBpGseO7seC02seftKseZuse8v:UlR04qgyIcISsyiHmL4N
TLSH T1CE51C7DD27215E74ED57DA33F1AA44087190A4E374CA4F0658FD3CF8C89EF0431A5AA9
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://138.201.154.194/systemcl/arcn/an/aelf ua-wget
http://138.201.154.194/systemcl/arma2812bf91c1836b0749615f8c92f49b055ed1152a0cfcb03cffb4473388ae1f9 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/arm5467ca3ecdb388a31f9687f3f93134ae992fbfbe2936cfbd700c3d198b3b65ecb Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/arm67a4627901da5e02ceacaf688cc103b4944a3cf75b4f1f4316ee638893eaa4104 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/arm71745a1dc09e108e719186017f4d6f10e1835aa4ba3f74b50b8394e3268c66524 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/m68k19abfca0200531ee5ddc2dd7bc4454af84d9ffe0ef2e12cd2a54fc828ebdc659 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/mipsad42066092b60784e1579fb3742cf3a41450dacc13b254e9c3a0c5b84aaf0db4 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/mpsl7365564e3fc5bc60caa91eb8b6b87a6d8da423389be87134899fcd0caaeb3242 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/ppcabfd19ac36a02a8d3552a65a6e023b7499af427f7ea558cbc5064b8475bd955e Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/sh4b5d5a320320766751e9a1e31bc6ff850196e0c3f0b5baee15eee600b8a3cdae2 Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/spc2b4e44a8a37c63ce0a2c007bb22d903ae9d13b643b6b556f4d15199926cdd54c Miraielf geofenced mirai opendir ua-wget USA
http://138.201.154.194/systemcl/x862e9b4bb064c078485eab38389da45cfecd1f865d77cd5c199ae3c2fe195daf72 Mirai32-bit elf mirai Mozi
http://138.201.154.194/systemcl/x86_6447a0fa2b9aa3ebdb48324d5ad43903187a528176193716db81991191b3d3b230 Miraielf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=438503f5-1900-0000-c56e-9a4574130000 pid=4980 /usr/bin/sudo guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988 /tmp/sample.bin guuid=438503f5-1900-0000-c56e-9a4574130000 pid=4980->guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988 execve guuid=4b75fff6-1900-0000-c56e-9a457e130000 pid=4990 /usr/bin/wget net send-data guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=4b75fff6-1900-0000-c56e-9a457e130000 pid=4990 execve guuid=5603c5fc-1900-0000-c56e-9a4591130000 pid=5009 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=5603c5fc-1900-0000-c56e-9a4591130000 pid=5009 execve guuid=7914ae06-1a00-0000-c56e-9a45ae130000 pid=5038 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=7914ae06-1a00-0000-c56e-9a45ae130000 pid=5038 execve guuid=80550907-1a00-0000-c56e-9a45b0130000 pid=5040 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=80550907-1a00-0000-c56e-9a45b0130000 pid=5040 execve guuid=49b84507-1a00-0000-c56e-9a45b2130000 pid=5042 /tmp/arc guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=49b84507-1a00-0000-c56e-9a45b2130000 pid=5042 execve guuid=17c28807-1a00-0000-c56e-9a45b3130000 pid=5043 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=17c28807-1a00-0000-c56e-9a45b3130000 pid=5043 execve guuid=8f16f407-1a00-0000-c56e-9a45b4130000 pid=5044 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=8f16f407-1a00-0000-c56e-9a45b4130000 pid=5044 execve guuid=aaf6c50d-1a00-0000-c56e-9a45cb130000 pid=5067 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=aaf6c50d-1a00-0000-c56e-9a45cb130000 pid=5067 execve guuid=7ebdd013-1a00-0000-c56e-9a45e2130000 pid=5090 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=7ebdd013-1a00-0000-c56e-9a45e2130000 pid=5090 execve guuid=69203014-1a00-0000-c56e-9a45e3130000 pid=5091 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=69203014-1a00-0000-c56e-9a45e3130000 pid=5091 execve guuid=1bff8514-1a00-0000-c56e-9a45e5130000 pid=5093 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=1bff8514-1a00-0000-c56e-9a45e5130000 pid=5093 clone guuid=cbafe915-1a00-0000-c56e-9a45ee130000 pid=5102 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=cbafe915-1a00-0000-c56e-9a45ee130000 pid=5102 execve guuid=ce12ba1f-1a00-0000-c56e-9a450b140000 pid=5131 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=ce12ba1f-1a00-0000-c56e-9a450b140000 pid=5131 execve guuid=45d75625-1a00-0000-c56e-9a4518140000 pid=5144 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=45d75625-1a00-0000-c56e-9a4518140000 pid=5144 execve guuid=c583a933-1a00-0000-c56e-9a4523140000 pid=5155 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=c583a933-1a00-0000-c56e-9a4523140000 pid=5155 execve guuid=65c33234-1a00-0000-c56e-9a4525140000 pid=5157 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=65c33234-1a00-0000-c56e-9a4525140000 pid=5157 execve guuid=7da3fa34-1a00-0000-c56e-9a4527140000 pid=5159 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=7da3fa34-1a00-0000-c56e-9a4527140000 pid=5159 clone guuid=37c9d337-1a00-0000-c56e-9a452e140000 pid=5166 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=37c9d337-1a00-0000-c56e-9a452e140000 pid=5166 execve guuid=eac23a38-1a00-0000-c56e-9a452f140000 pid=5167 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=eac23a38-1a00-0000-c56e-9a452f140000 pid=5167 execve guuid=2c10613f-1a00-0000-c56e-9a4537140000 pid=5175 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=2c10613f-1a00-0000-c56e-9a4537140000 pid=5175 execve guuid=a1d4d14a-1a00-0000-c56e-9a454c140000 pid=5196 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=a1d4d14a-1a00-0000-c56e-9a454c140000 pid=5196 execve guuid=7ac22e4b-1a00-0000-c56e-9a454d140000 pid=5197 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=7ac22e4b-1a00-0000-c56e-9a454d140000 pid=5197 execve guuid=c8f4af4b-1a00-0000-c56e-9a454e140000 pid=5198 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=c8f4af4b-1a00-0000-c56e-9a454e140000 pid=5198 clone guuid=04f7b14c-1a00-0000-c56e-9a4550140000 pid=5200 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=04f7b14c-1a00-0000-c56e-9a4550140000 pid=5200 execve guuid=46a0305e-1a00-0000-c56e-9a455b140000 pid=5211 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=46a0305e-1a00-0000-c56e-9a455b140000 pid=5211 execve guuid=ebcf1566-1a00-0000-c56e-9a4581140000 pid=5249 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=ebcf1566-1a00-0000-c56e-9a4581140000 pid=5249 execve guuid=25ae4870-1a00-0000-c56e-9a4583140000 pid=5251 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=25ae4870-1a00-0000-c56e-9a4583140000 pid=5251 execve guuid=143f9370-1a00-0000-c56e-9a4584140000 pid=5252 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=143f9370-1a00-0000-c56e-9a4584140000 pid=5252 execve guuid=8276da70-1a00-0000-c56e-9a4585140000 pid=5253 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=8276da70-1a00-0000-c56e-9a4585140000 pid=5253 clone guuid=d8f95972-1a00-0000-c56e-9a4587140000 pid=5255 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=d8f95972-1a00-0000-c56e-9a4587140000 pid=5255 execve guuid=29f2f273-1a00-0000-c56e-9a4588140000 pid=5256 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=29f2f273-1a00-0000-c56e-9a4588140000 pid=5256 execve guuid=b5359a7a-1a00-0000-c56e-9a4589140000 pid=5257 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=b5359a7a-1a00-0000-c56e-9a4589140000 pid=5257 execve guuid=cb720f85-1a00-0000-c56e-9a458a140000 pid=5258 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=cb720f85-1a00-0000-c56e-9a458a140000 pid=5258 execve guuid=e43db885-1a00-0000-c56e-9a458b140000 pid=5259 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=e43db885-1a00-0000-c56e-9a458b140000 pid=5259 execve guuid=9cef3486-1a00-0000-c56e-9a458c140000 pid=5260 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=9cef3486-1a00-0000-c56e-9a458c140000 pid=5260 clone guuid=10683c87-1a00-0000-c56e-9a4590140000 pid=5264 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=10683c87-1a00-0000-c56e-9a4590140000 pid=5264 execve guuid=acf27d93-1a00-0000-c56e-9a4592140000 pid=5266 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=acf27d93-1a00-0000-c56e-9a4592140000 pid=5266 execve guuid=27eccc9b-1a00-0000-c56e-9a459b140000 pid=5275 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=27eccc9b-1a00-0000-c56e-9a459b140000 pid=5275 execve guuid=eedd3fa4-1a00-0000-c56e-9a459c140000 pid=5276 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=eedd3fa4-1a00-0000-c56e-9a459c140000 pid=5276 execve guuid=23cdd1a4-1a00-0000-c56e-9a459d140000 pid=5277 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=23cdd1a4-1a00-0000-c56e-9a459d140000 pid=5277 execve guuid=d7ce51a5-1a00-0000-c56e-9a459e140000 pid=5278 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=d7ce51a5-1a00-0000-c56e-9a459e140000 pid=5278 clone guuid=449339a6-1a00-0000-c56e-9a45a0140000 pid=5280 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=449339a6-1a00-0000-c56e-9a45a0140000 pid=5280 execve guuid=eaff9da6-1a00-0000-c56e-9a45a1140000 pid=5281 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=eaff9da6-1a00-0000-c56e-9a45a1140000 pid=5281 execve guuid=2a0a14ad-1a00-0000-c56e-9a45a2140000 pid=5282 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=2a0a14ad-1a00-0000-c56e-9a45a2140000 pid=5282 execve guuid=c13685b5-1a00-0000-c56e-9a45a3140000 pid=5283 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=c13685b5-1a00-0000-c56e-9a45a3140000 pid=5283 execve guuid=51eb34b6-1a00-0000-c56e-9a45a4140000 pid=5284 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=51eb34b6-1a00-0000-c56e-9a45a4140000 pid=5284 execve guuid=179cdcb6-1a00-0000-c56e-9a45a5140000 pid=5285 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=179cdcb6-1a00-0000-c56e-9a45a5140000 pid=5285 clone guuid=33f989b7-1a00-0000-c56e-9a45a7140000 pid=5287 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=33f989b7-1a00-0000-c56e-9a45a7140000 pid=5287 execve guuid=057b39b8-1a00-0000-c56e-9a45a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=057b39b8-1a00-0000-c56e-9a45a8140000 pid=5288 execve guuid=1ac362be-1a00-0000-c56e-9a45a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=1ac362be-1a00-0000-c56e-9a45a9140000 pid=5289 execve guuid=5c4079c6-1a00-0000-c56e-9a45aa140000 pid=5290 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=5c4079c6-1a00-0000-c56e-9a45aa140000 pid=5290 execve guuid=dbaee3c6-1a00-0000-c56e-9a45ab140000 pid=5291 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=dbaee3c6-1a00-0000-c56e-9a45ab140000 pid=5291 execve guuid=8a806ec7-1a00-0000-c56e-9a45ac140000 pid=5292 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=8a806ec7-1a00-0000-c56e-9a45ac140000 pid=5292 clone guuid=dea98bc9-1a00-0000-c56e-9a45ae140000 pid=5294 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=dea98bc9-1a00-0000-c56e-9a45ae140000 pid=5294 execve guuid=b25e19ca-1a00-0000-c56e-9a45af140000 pid=5295 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=b25e19ca-1a00-0000-c56e-9a45af140000 pid=5295 execve guuid=e9842bd1-1a00-0000-c56e-9a45b0140000 pid=5296 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=e9842bd1-1a00-0000-c56e-9a45b0140000 pid=5296 execve guuid=774e39db-1a00-0000-c56e-9a45b1140000 pid=5297 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=774e39db-1a00-0000-c56e-9a45b1140000 pid=5297 execve guuid=cae1d9db-1a00-0000-c56e-9a45b2140000 pid=5298 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=cae1d9db-1a00-0000-c56e-9a45b2140000 pid=5298 execve guuid=cb8076dc-1a00-0000-c56e-9a45b3140000 pid=5299 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=cb8076dc-1a00-0000-c56e-9a45b3140000 pid=5299 clone guuid=e2dc0add-1a00-0000-c56e-9a45b5140000 pid=5301 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=e2dc0add-1a00-0000-c56e-9a45b5140000 pid=5301 execve guuid=393049dd-1a00-0000-c56e-9a45b6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=393049dd-1a00-0000-c56e-9a45b6140000 pid=5302 execve guuid=c5e0f3e3-1a00-0000-c56e-9a45b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=c5e0f3e3-1a00-0000-c56e-9a45b7140000 pid=5303 execve guuid=6a19adee-1a00-0000-c56e-9a45b8140000 pid=5304 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=6a19adee-1a00-0000-c56e-9a45b8140000 pid=5304 execve guuid=52ac57ef-1a00-0000-c56e-9a45b9140000 pid=5305 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=52ac57ef-1a00-0000-c56e-9a45b9140000 pid=5305 execve guuid=1942faef-1a00-0000-c56e-9a45ba140000 pid=5306 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=1942faef-1a00-0000-c56e-9a45ba140000 pid=5306 clone guuid=ab9651f1-1a00-0000-c56e-9a45bc140000 pid=5308 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=ab9651f1-1a00-0000-c56e-9a45bc140000 pid=5308 execve guuid=850bdbf1-1a00-0000-c56e-9a45bd140000 pid=5309 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=850bdbf1-1a00-0000-c56e-9a45bd140000 pid=5309 execve guuid=2a9907f8-1a00-0000-c56e-9a45be140000 pid=5310 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=2a9907f8-1a00-0000-c56e-9a45be140000 pid=5310 execve guuid=98e92a00-1b00-0000-c56e-9a45bf140000 pid=5311 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=98e92a00-1b00-0000-c56e-9a45bf140000 pid=5311 execve guuid=4b928000-1b00-0000-c56e-9a45c0140000 pid=5312 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=4b928000-1b00-0000-c56e-9a45c0140000 pid=5312 execve guuid=db53ce00-1b00-0000-c56e-9a45c1140000 pid=5313 /tmp/x86 net guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=db53ce00-1b00-0000-c56e-9a45c1140000 pid=5313 execve guuid=eb85a611-1b00-0000-c56e-9a45c4140000 pid=5316 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=eb85a611-1b00-0000-c56e-9a45c4140000 pid=5316 execve guuid=9640f411-1b00-0000-c56e-9a45c5140000 pid=5317 /usr/bin/wget net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=9640f411-1b00-0000-c56e-9a45c5140000 pid=5317 execve guuid=155e0f1a-1b00-0000-c56e-9a45c6140000 pid=5318 /usr/bin/curl net send-data write-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=155e0f1a-1b00-0000-c56e-9a45c6140000 pid=5318 execve guuid=2d1de023-1b00-0000-c56e-9a45c7140000 pid=5319 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=2d1de023-1b00-0000-c56e-9a45c7140000 pid=5319 execve guuid=00248b24-1b00-0000-c56e-9a45c8140000 pid=5320 /usr/bin/chmod guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=00248b24-1b00-0000-c56e-9a45c8140000 pid=5320 execve guuid=b2e32625-1b00-0000-c56e-9a45c9140000 pid=5321 /usr/bin/dash guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=b2e32625-1b00-0000-c56e-9a45c9140000 pid=5321 clone guuid=53447d26-1b00-0000-c56e-9a45cb140000 pid=5323 /usr/bin/rm delete-file guuid=6c73c4f6-1900-0000-c56e-9a457c130000 pid=4988->guuid=53447d26-1b00-0000-c56e-9a45cb140000 pid=5323 execve 0d8bcf72-e418-554e-aa94-b31d69d8ccca 138.201.154.194:80 guuid=4b75fff6-1900-0000-c56e-9a457e130000 pid=4990->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=5603c5fc-1900-0000-c56e-9a4591130000 pid=5009->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=8f16f407-1a00-0000-c56e-9a45b4130000 pid=5044->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=aaf6c50d-1a00-0000-c56e-9a45cb130000 pid=5067->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=ce12ba1f-1a00-0000-c56e-9a450b140000 pid=5131->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=45d75625-1a00-0000-c56e-9a4518140000 pid=5144->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=eac23a38-1a00-0000-c56e-9a452f140000 pid=5167->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=2c10613f-1a00-0000-c56e-9a4537140000 pid=5175->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=46a0305e-1a00-0000-c56e-9a455b140000 pid=5211->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=ebcf1566-1a00-0000-c56e-9a4581140000 pid=5249->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=29f2f273-1a00-0000-c56e-9a4588140000 pid=5256->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=b5359a7a-1a00-0000-c56e-9a4589140000 pid=5257->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=acf27d93-1a00-0000-c56e-9a4592140000 pid=5266->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=27eccc9b-1a00-0000-c56e-9a459b140000 pid=5275->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=eaff9da6-1a00-0000-c56e-9a45a1140000 pid=5281->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 143B guuid=2a0a14ad-1a00-0000-c56e-9a45a2140000 pid=5282->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 92B guuid=057b39b8-1a00-0000-c56e-9a45a8140000 pid=5288->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=1ac362be-1a00-0000-c56e-9a45a9140000 pid=5289->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=b25e19ca-1a00-0000-c56e-9a45af140000 pid=5295->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=e9842bd1-1a00-0000-c56e-9a45b0140000 pid=5296->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=393049dd-1a00-0000-c56e-9a45b6140000 pid=5302->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=c5e0f3e3-1a00-0000-c56e-9a45b7140000 pid=5303->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B guuid=850bdbf1-1a00-0000-c56e-9a45bd140000 pid=5309->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 142B guuid=2a9907f8-1a00-0000-c56e-9a45be140000 pid=5310->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=db53ce00-1b00-0000-c56e-9a45c1140000 pid=5313->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9f849011-1b00-0000-c56e-9a45c2140000 pid=5314 /tmp/x86 guuid=db53ce00-1b00-0000-c56e-9a45c1140000 pid=5313->guuid=9f849011-1b00-0000-c56e-9a45c2140000 pid=5314 clone guuid=cbc39811-1b00-0000-c56e-9a45c3140000 pid=5315 /tmp/x86 net send-data zombie guuid=db53ce00-1b00-0000-c56e-9a45c1140000 pid=5313->guuid=cbc39811-1b00-0000-c56e-9a45c3140000 pid=5315 clone guuid=cbc39811-1b00-0000-c56e-9a45c3140000 pid=5315->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b 87.121.84.220:61459 guuid=cbc39811-1b00-0000-c56e-9a45c3140000 pid=5315->dfbb6132-9b3a-5fcc-ae73-0a5bea22ee6b send: 43B guuid=9640f411-1b00-0000-c56e-9a45c5140000 pid=5317->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 145B guuid=155e0f1a-1b00-0000-c56e-9a45c6140000 pid=5318->0d8bcf72-e418-554e-aa94-b31d69d8ccca send: 94B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-19 01:55:34 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7b4acd4f11779c0b1016957bad0cbc77b90e630177aeff6c60c09f86d7b744a2

(this sample)

  
Delivery method
Distributed via web download

Comments