MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f55eb9ac447608017451a30425c2a7ce85a51fa5cf436b16c215cbeec25d909. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 7f55eb9ac447608017451a30425c2a7ce85a51fa5cf436b16c215cbeec25d909
SHA3-384 hash: 764d5110bed841e73a46620e090ccb499ce7bb9fd3b03e4ba26093bb98c897f320c7b2c10f66d5f27dd3f84460c2003b
SHA1 hash: dfe2bc857a1b47853049d9c9f8e31f7a21696ee3
MD5 hash: a6dd49e8a65beaac72703a41f5696f98
humanhash: east-december-early-queen
File name:qkuys.sh
Download: download sample
Signature Mirai
File size:3'014 bytes
First seen:2025-11-18 17:23:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iJbgbAJbDbmJbKbMJbbbeJbRbCJbFbSJb0aab0aX3KLJbcbnAJb1bILJbobuJJbh:iViAV/mVsMV3eVdCVJSV0X0E3KLV2nAS
TLSH T188515A8A10D1877EAE56DB9373ADC708B9AAB4D694C79F0CDCDE25F9A04CF093110762
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.225/bin/Polar.x86c71b9710d13d3152d370b46d22afda921cbe0815bbfc49eb703c6a0c739dc91f Miraimirai opendir
http://143.20.185.225/bin/Polar.mips4a98d6bd63190c2aef2a7567e36f11fafbf12d64c161ec17bc01f60384ed30d0 Miraimirai opendir
http://143.20.185.225/bin/Polar.arc9ad3a1c947bef2d67ab1d659ee391b47b4655af952a214fc2d5ad8a6c16ad58f Miraimirai opendir
http://143.20.185.225/bin/Polar.i468n/an/aelf ua-wget
http://143.20.185.225/bin/Polar.i68670a46bf2111e393fda22863bd7449630867cab7023117e0672be2b829f6ff429 Miraimirai opendir
http://143.20.185.225/bin/Polar.x86_64b784633b94f332feb9cf753e478adb69f8cd2a80b90293f06ef4ce7bcb1eb690 Miraimirai opendir
http://143.20.185.225/bin/Polar.mpsl46d699e5fecb934da82228f81c8d2ede537e4ed84cdcf0c6816dba773073577c Miraimirai opendir
http://143.20.185.225/bin/Polar.arm094a10196a06c26e7d02316a2364cf2ee7a85266a0409b90f433fe77b8dacc9b Miraimirai opendir
http://143.20.185.225/bin/Polar.arm54476a4f8616cfe832f9740c6aadc02d72976b81f123ca2ff8ceb8b5110bba58d Miraimirai opendir
http://143.20.185.225/bin/Polar.arm6bd52db8e0392c1cd596862981f2c0951829d5c379f4b6e2f81e1f52d032c82ca Miraimirai opendir
http://143.20.185.225/bin/Polar.arm74429f00e0efabe0ce89644caba8979e00a2b064bde1e43a30b87e3c4a345988b Miraimirai opendir
http://143.20.185.225/bin/Polar.ppce3dade7ec1a0db7c080a50d555492ec6329457f2b10801bea3c942550acb62c8 Miraimirai opendir
http://143.20.185.225/bin/Polar.spcef728dc73fe11f9aac29ade59130c96215d151b6c1e74ced52c5a9673a2380a7 Miraimirai opendir
http://143.20.185.225/bin/Polar.m68k212b314cf46d30641138c55c90f537be908c0d889fe835c40cf6d779de90504e Miraimirai opendir
http://143.20.185.225/bin/Polar.sh41c72cb6c8c31e9c467706a0190f99717c165a8935b3a163778f172c2f6db6a99 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-18T14:45:00Z UTC
Last seen:
2025-11-20T10:18:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=d0c29b03-1c00-0000-b09a-dc7b870b0000 pid=2951 /usr/bin/sudo guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956 /tmp/sample.bin guuid=d0c29b03-1c00-0000-b09a-dc7b870b0000 pid=2951->guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956 execve guuid=f40e0a06-1c00-0000-b09a-dc7b8e0b0000 pid=2958 /usr/bin/cp guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=f40e0a06-1c00-0000-b09a-dc7b8e0b0000 pid=2958 execve guuid=46055a07-1c00-0000-b09a-dc7b930b0000 pid=2963 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=46055a07-1c00-0000-b09a-dc7b930b0000 pid=2963 execve guuid=be0cdd14-1c00-0000-b09a-dc7bb20b0000 pid=2994 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=be0cdd14-1c00-0000-b09a-dc7bb20b0000 pid=2994 execve guuid=db206029-1c00-0000-b09a-dc7be50b0000 pid=3045 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=db206029-1c00-0000-b09a-dc7be50b0000 pid=3045 execve guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047 /tmp/Polar.x86 net guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047 execve guuid=9235e656-1d00-0000-b09a-dc7bf80d0000 pid=3576 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=9235e656-1d00-0000-b09a-dc7bf80d0000 pid=3576 execve guuid=ee8d6657-1d00-0000-b09a-dc7bf90d0000 pid=3577 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=ee8d6657-1d00-0000-b09a-dc7bf90d0000 pid=3577 execve guuid=7eca0d65-1d00-0000-b09a-dc7bfb0d0000 pid=3579 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=7eca0d65-1d00-0000-b09a-dc7bfb0d0000 pid=3579 execve guuid=f24f8275-1d00-0000-b09a-dc7b1f0e0000 pid=3615 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=f24f8275-1d00-0000-b09a-dc7b1f0e0000 pid=3615 execve guuid=e79b2676-1d00-0000-b09a-dc7b210e0000 pid=3617 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=e79b2676-1d00-0000-b09a-dc7b210e0000 pid=3617 clone guuid=edc0fe76-1d00-0000-b09a-dc7b250e0000 pid=3621 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=edc0fe76-1d00-0000-b09a-dc7b250e0000 pid=3621 execve guuid=e7354f77-1d00-0000-b09a-dc7b260e0000 pid=3622 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=e7354f77-1d00-0000-b09a-dc7b260e0000 pid=3622 execve guuid=c5527985-1d00-0000-b09a-dc7b4a0e0000 pid=3658 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=c5527985-1d00-0000-b09a-dc7b4a0e0000 pid=3658 execve guuid=cf39fb9c-1d00-0000-b09a-dc7b700e0000 pid=3696 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=cf39fb9c-1d00-0000-b09a-dc7b700e0000 pid=3696 execve guuid=f407589d-1d00-0000-b09a-dc7b720e0000 pid=3698 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=f407589d-1d00-0000-b09a-dc7b720e0000 pid=3698 clone guuid=1b2622a0-1d00-0000-b09a-dc7b770e0000 pid=3703 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=1b2622a0-1d00-0000-b09a-dc7b770e0000 pid=3703 execve guuid=60e566a0-1d00-0000-b09a-dc7b780e0000 pid=3704 /usr/bin/wget net send-data guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=60e566a0-1d00-0000-b09a-dc7b780e0000 pid=3704 execve guuid=1d1528a7-1d00-0000-b09a-dc7b860e0000 pid=3718 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=1d1528a7-1d00-0000-b09a-dc7b860e0000 pid=3718 execve guuid=8e855db1-1d00-0000-b09a-dc7ba70e0000 pid=3751 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=8e855db1-1d00-0000-b09a-dc7ba70e0000 pid=3751 execve guuid=9bbcd2b1-1d00-0000-b09a-dc7bab0e0000 pid=3755 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=9bbcd2b1-1d00-0000-b09a-dc7bab0e0000 pid=3755 clone guuid=2c4d00b2-1d00-0000-b09a-dc7bac0e0000 pid=3756 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=2c4d00b2-1d00-0000-b09a-dc7bac0e0000 pid=3756 execve guuid=e1ce7db2-1d00-0000-b09a-dc7bae0e0000 pid=3758 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=e1ce7db2-1d00-0000-b09a-dc7bae0e0000 pid=3758 execve guuid=647aa5be-1d00-0000-b09a-dc7bd20e0000 pid=3794 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=647aa5be-1d00-0000-b09a-dc7bd20e0000 pid=3794 execve guuid=468bc6cc-1d00-0000-b09a-dc7b0c0f0000 pid=3852 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=468bc6cc-1d00-0000-b09a-dc7b0c0f0000 pid=3852 execve guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853 /tmp/Polar.i686 net guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853 execve guuid=af9d9ffa-1e00-0000-b09a-dc7ba7120000 pid=4775 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=af9d9ffa-1e00-0000-b09a-dc7ba7120000 pid=4775 execve guuid=f28deefa-1e00-0000-b09a-dc7ba8120000 pid=4776 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=f28deefa-1e00-0000-b09a-dc7ba8120000 pid=4776 execve guuid=ec930c07-1f00-0000-b09a-dc7bce120000 pid=4814 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=ec930c07-1f00-0000-b09a-dc7bce120000 pid=4814 execve guuid=71982816-1f00-0000-b09a-dc7b06130000 pid=4870 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=71982816-1f00-0000-b09a-dc7b06130000 pid=4870 execve guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872 /tmp/Polar.x86_64 mprotect-exec net guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872 execve guuid=375d4a42-2000-0000-b09a-dc7b9e140000 pid=5278 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=375d4a42-2000-0000-b09a-dc7b9e140000 pid=5278 execve guuid=6b9faf42-2000-0000-b09a-dc7b9f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=6b9faf42-2000-0000-b09a-dc7b9f140000 pid=5279 execve guuid=10e79753-2000-0000-b09a-dc7ba0140000 pid=5280 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=10e79753-2000-0000-b09a-dc7ba0140000 pid=5280 execve guuid=3d037b60-2000-0000-b09a-dc7ba1140000 pid=5281 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=3d037b60-2000-0000-b09a-dc7ba1140000 pid=5281 execve guuid=df8ad360-2000-0000-b09a-dc7ba2140000 pid=5282 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=df8ad360-2000-0000-b09a-dc7ba2140000 pid=5282 clone guuid=943e7f61-2000-0000-b09a-dc7ba4140000 pid=5284 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=943e7f61-2000-0000-b09a-dc7ba4140000 pid=5284 execve guuid=760dda61-2000-0000-b09a-dc7ba5140000 pid=5285 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=760dda61-2000-0000-b09a-dc7ba5140000 pid=5285 execve guuid=4370bf6e-2000-0000-b09a-dc7ba6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=4370bf6e-2000-0000-b09a-dc7ba6140000 pid=5286 execve guuid=be4b8d7c-2000-0000-b09a-dc7ba7140000 pid=5287 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=be4b8d7c-2000-0000-b09a-dc7ba7140000 pid=5287 execve guuid=714c237d-2000-0000-b09a-dc7ba8140000 pid=5288 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=714c237d-2000-0000-b09a-dc7ba8140000 pid=5288 clone guuid=623e037e-2000-0000-b09a-dc7baa140000 pid=5290 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=623e037e-2000-0000-b09a-dc7baa140000 pid=5290 execve guuid=988c9b7e-2000-0000-b09a-dc7bab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=988c9b7e-2000-0000-b09a-dc7bab140000 pid=5291 execve guuid=185a738e-2000-0000-b09a-dc7bac140000 pid=5292 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=185a738e-2000-0000-b09a-dc7bac140000 pid=5292 execve guuid=7116be9a-2000-0000-b09a-dc7bad140000 pid=5293 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=7116be9a-2000-0000-b09a-dc7bad140000 pid=5293 execve guuid=dca20e9b-2000-0000-b09a-dc7bae140000 pid=5294 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=dca20e9b-2000-0000-b09a-dc7bae140000 pid=5294 clone guuid=83cbdb9b-2000-0000-b09a-dc7bb0140000 pid=5296 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=83cbdb9b-2000-0000-b09a-dc7bb0140000 pid=5296 execve guuid=1acf299c-2000-0000-b09a-dc7bb1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=1acf299c-2000-0000-b09a-dc7bb1140000 pid=5297 execve guuid=401647aa-2000-0000-b09a-dc7bb9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=401647aa-2000-0000-b09a-dc7bb9140000 pid=5305 execve guuid=124be4bd-2000-0000-b09a-dc7bba140000 pid=5306 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=124be4bd-2000-0000-b09a-dc7bba140000 pid=5306 execve guuid=b89a79be-2000-0000-b09a-dc7bbb140000 pid=5307 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=b89a79be-2000-0000-b09a-dc7bbb140000 pid=5307 clone guuid=24826dc0-2000-0000-b09a-dc7bbd140000 pid=5309 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=24826dc0-2000-0000-b09a-dc7bbd140000 pid=5309 execve guuid=594ee1c0-2000-0000-b09a-dc7bbe140000 pid=5310 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=594ee1c0-2000-0000-b09a-dc7bbe140000 pid=5310 execve guuid=eb0fa2cd-2000-0000-b09a-dc7bbf140000 pid=5311 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=eb0fa2cd-2000-0000-b09a-dc7bbf140000 pid=5311 execve guuid=4667efdf-2000-0000-b09a-dc7bc0140000 pid=5312 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=4667efdf-2000-0000-b09a-dc7bc0140000 pid=5312 execve guuid=eae6b7e0-2000-0000-b09a-dc7bc1140000 pid=5313 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=eae6b7e0-2000-0000-b09a-dc7bc1140000 pid=5313 clone guuid=964b07e2-2000-0000-b09a-dc7bc3140000 pid=5315 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=964b07e2-2000-0000-b09a-dc7bc3140000 pid=5315 execve guuid=d2507ce2-2000-0000-b09a-dc7bc4140000 pid=5316 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=d2507ce2-2000-0000-b09a-dc7bc4140000 pid=5316 execve guuid=4542d2f4-2000-0000-b09a-dc7bc5140000 pid=5317 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=4542d2f4-2000-0000-b09a-dc7bc5140000 pid=5317 execve guuid=89112320-2100-0000-b09a-dc7bc6140000 pid=5318 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=89112320-2100-0000-b09a-dc7bc6140000 pid=5318 execve guuid=20f7c022-2100-0000-b09a-dc7bc7140000 pid=5319 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=20f7c022-2100-0000-b09a-dc7bc7140000 pid=5319 clone guuid=5ff61128-2100-0000-b09a-dc7bc9140000 pid=5321 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=5ff61128-2100-0000-b09a-dc7bc9140000 pid=5321 execve guuid=54c68128-2100-0000-b09a-dc7bca140000 pid=5322 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=54c68128-2100-0000-b09a-dc7bca140000 pid=5322 execve guuid=bbe71e37-2100-0000-b09a-dc7bcb140000 pid=5323 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=bbe71e37-2100-0000-b09a-dc7bcb140000 pid=5323 execve guuid=755f7346-2100-0000-b09a-dc7bcc140000 pid=5324 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=755f7346-2100-0000-b09a-dc7bcc140000 pid=5324 execve guuid=8fcaf846-2100-0000-b09a-dc7bcd140000 pid=5325 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=8fcaf846-2100-0000-b09a-dc7bcd140000 pid=5325 clone guuid=4cdd6548-2100-0000-b09a-dc7bcf140000 pid=5327 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=4cdd6548-2100-0000-b09a-dc7bcf140000 pid=5327 execve guuid=dad0e548-2100-0000-b09a-dc7bd0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=dad0e548-2100-0000-b09a-dc7bd0140000 pid=5328 execve guuid=1e5aac5b-2100-0000-b09a-dc7bd1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=1e5aac5b-2100-0000-b09a-dc7bd1140000 pid=5329 execve guuid=5e574e6f-2100-0000-b09a-dc7bd2140000 pid=5330 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=5e574e6f-2100-0000-b09a-dc7bd2140000 pid=5330 execve guuid=4d4e976f-2100-0000-b09a-dc7bd3140000 pid=5331 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=4d4e976f-2100-0000-b09a-dc7bd3140000 pid=5331 clone guuid=0cba6970-2100-0000-b09a-dc7bd5140000 pid=5333 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=0cba6970-2100-0000-b09a-dc7bd5140000 pid=5333 execve guuid=aed8b470-2100-0000-b09a-dc7bd6140000 pid=5334 /usr/bin/wget net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=aed8b470-2100-0000-b09a-dc7bd6140000 pid=5334 execve guuid=70d1ed7e-2100-0000-b09a-dc7bd7140000 pid=5335 /usr/bin/curl net send-data write-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=70d1ed7e-2100-0000-b09a-dc7bd7140000 pid=5335 execve guuid=b2901491-2100-0000-b09a-dc7bd8140000 pid=5336 /usr/bin/chmod guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=b2901491-2100-0000-b09a-dc7bd8140000 pid=5336 execve guuid=aa7ab291-2100-0000-b09a-dc7bd9140000 pid=5337 /usr/bin/bash guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=aa7ab291-2100-0000-b09a-dc7bd9140000 pid=5337 clone guuid=ede0c293-2100-0000-b09a-dc7bdb140000 pid=5339 /usr/bin/rm delete-file guuid=2e159805-1c00-0000-b09a-dc7b8c0b0000 pid=2956->guuid=ede0c293-2100-0000-b09a-dc7bdb140000 pid=5339 execve d5466fdd-d2e6-50d9-9f3d-61d919bad8ae 143.20.185.225:80 guuid=46055a07-1c00-0000-b09a-dc7b930b0000 pid=2963->d5466fdd-d2e6-50d9-9f3d-61d919bad8ae send: 142B guuid=be0cdd14-1c00-0000-b09a-dc7bb20b0000 pid=2994->d5466fdd-d2e6-50d9-9f3d-61d919bad8ae send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9a4a852a-1c00-0000-b09a-dc7bea0b0000 pid=3050 /tmp/Polar.x86 guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047->guuid=9a4a852a-1c00-0000-b09a-dc7bea0b0000 pid=3050 clone guuid=b94cd356-1d00-0000-b09a-dc7bf60d0000 pid=3574 /tmp/Polar.x86 guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047->guuid=b94cd356-1d00-0000-b09a-dc7bf60d0000 pid=3574 clone guuid=a6b8d956-1d00-0000-b09a-dc7bf70d0000 pid=3575 /tmp/Polar.x86 net send-data zombie guuid=bfbfbe29-1c00-0000-b09a-dc7be70b0000 pid=3047->guuid=a6b8d956-1d00-0000-b09a-dc7bf70d0000 pid=3575 clone guuid=6cb88f2a-1c00-0000-b09a-dc7beb0b0000 pid=3051 /tmp/Polar.x86 guuid=9a4a852a-1c00-0000-b09a-dc7bea0b0000 pid=3050->guuid=6cb88f2a-1c00-0000-b09a-dc7beb0b0000 pid=3051 clone guuid=0c97942a-1c00-0000-b09a-dc7bec0b0000 pid=3052 /tmp/Polar.x86 dns net send-data zombie guuid=9a4a852a-1c00-0000-b09a-dc7bea0b0000 pid=3050->guuid=0c97942a-1c00-0000-b09a-dc7bec0b0000 pid=3052 clone guuid=0c97942a-1c00-0000-b09a-dc7bec0b0000 pid=3052->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B 4b0e4b24-021f-5743-8b5a-ce89b76b814b uraniumc2.ddns.net:69 guuid=0c97942a-1c00-0000-b09a-dc7bec0b0000 pid=3052->4b0e4b24-021f-5743-8b5a-ce89b76b814b send: 19B guuid=a6b8d956-1d00-0000-b09a-dc7bf70d0000 pid=3575->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1080B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=a6b8d956-1d00-0000-b09a-dc7bf70d0000 pid=3575->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 uraniumc2.ddns.net:80 guuid=ee8d6657-1d00-0000-b09a-dc7bf90d0000 pid=3577->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=7eca0d65-1d00-0000-b09a-dc7bfb0d0000 pid=3579->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=e7354f77-1d00-0000-b09a-dc7b260e0000 pid=3622->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 142B guuid=c5527985-1d00-0000-b09a-dc7b4a0e0000 pid=3658->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 91B guuid=60e566a0-1d00-0000-b09a-dc7b780e0000 pid=3704->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=1d1528a7-1d00-0000-b09a-dc7b860e0000 pid=3718->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=e1ce7db2-1d00-0000-b09a-dc7bae0e0000 pid=3758->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=647aa5be-1d00-0000-b09a-dc7bd20e0000 pid=3794->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1a0f2cce-1d00-0000-b09a-dc7b100f0000 pid=3856 /tmp/Polar.i686 guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853->guuid=1a0f2cce-1d00-0000-b09a-dc7b100f0000 pid=3856 clone guuid=11f68ffa-1e00-0000-b09a-dc7ba5120000 pid=4773 /tmp/Polar.i686 guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853->guuid=11f68ffa-1e00-0000-b09a-dc7ba5120000 pid=4773 clone guuid=2c0594fa-1e00-0000-b09a-dc7ba6120000 pid=4774 /tmp/Polar.i686 net send-data zombie guuid=56d940cd-1d00-0000-b09a-dc7b0d0f0000 pid=3853->guuid=2c0594fa-1e00-0000-b09a-dc7ba6120000 pid=4774 clone guuid=f96334ce-1d00-0000-b09a-dc7b110f0000 pid=3857 /tmp/Polar.i686 guuid=1a0f2cce-1d00-0000-b09a-dc7b100f0000 pid=3856->guuid=f96334ce-1d00-0000-b09a-dc7b110f0000 pid=3857 clone guuid=1a5739ce-1d00-0000-b09a-dc7b120f0000 pid=3858 /tmp/Polar.i686 dns net send-data zombie guuid=1a0f2cce-1d00-0000-b09a-dc7b100f0000 pid=3856->guuid=1a5739ce-1d00-0000-b09a-dc7b120f0000 pid=3858 clone guuid=1a5739ce-1d00-0000-b09a-dc7b120f0000 pid=3858->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=1a5739ce-1d00-0000-b09a-dc7b120f0000 pid=3858->4b0e4b24-021f-5743-8b5a-ce89b76b814b send: 20B guuid=2c0594fa-1e00-0000-b09a-dc7ba6120000 pid=4774->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 900B guuid=2c0594fa-1e00-0000-b09a-dc7ba6120000 pid=4774->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=f28deefa-1e00-0000-b09a-dc7ba8120000 pid=4776->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 145B guuid=ec930c07-1f00-0000-b09a-dc7bce120000 pid=4814->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 94B guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f12c6517-1f00-0000-b09a-dc7b0c130000 pid=4876 /tmp/Polar.x86_64 guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872->guuid=f12c6517-1f00-0000-b09a-dc7b0c130000 pid=4876 clone guuid=7a892942-2000-0000-b09a-dc7b9c140000 pid=5276 /tmp/Polar.x86_64 guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872->guuid=7a892942-2000-0000-b09a-dc7b9c140000 pid=5276 clone guuid=241a3342-2000-0000-b09a-dc7b9d140000 pid=5277 /tmp/Polar.x86_64 net send-data zombie guuid=bd5c7616-1f00-0000-b09a-dc7b08130000 pid=4872->guuid=241a3342-2000-0000-b09a-dc7b9d140000 pid=5277 clone guuid=7da06b17-1f00-0000-b09a-dc7b0d130000 pid=4877 /tmp/Polar.x86_64 guuid=f12c6517-1f00-0000-b09a-dc7b0c130000 pid=4876->guuid=7da06b17-1f00-0000-b09a-dc7b0d130000 pid=4877 clone guuid=8e6d6f17-1f00-0000-b09a-dc7b0f130000 pid=4879 /tmp/Polar.x86_64 net send-data zombie guuid=f12c6517-1f00-0000-b09a-dc7b0c130000 pid=4876->guuid=8e6d6f17-1f00-0000-b09a-dc7b0f130000 pid=4879 clone guuid=8e6d6f17-1f00-0000-b09a-dc7b0f130000 pid=4879->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 740B guuid=8e6d6f17-1f00-0000-b09a-dc7b0f130000 pid=4879->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=241a3342-2000-0000-b09a-dc7b9d140000 pid=5277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 740B guuid=241a3342-2000-0000-b09a-dc7b9d140000 pid=5277->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=6b9faf42-2000-0000-b09a-dc7b9f140000 pid=5279->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=10e79753-2000-0000-b09a-dc7ba0140000 pid=5280->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=760dda61-2000-0000-b09a-dc7ba5140000 pid=5285->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 142B guuid=4370bf6e-2000-0000-b09a-dc7ba6140000 pid=5286->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 91B guuid=988c9b7e-2000-0000-b09a-dc7bab140000 pid=5291->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=185a738e-2000-0000-b09a-dc7bac140000 pid=5292->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=1acf299c-2000-0000-b09a-dc7bb1140000 pid=5297->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=401647aa-2000-0000-b09a-dc7bb9140000 pid=5305->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=594ee1c0-2000-0000-b09a-dc7bbe140000 pid=5310->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=eb0fa2cd-2000-0000-b09a-dc7bbf140000 pid=5311->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=d2507ce2-2000-0000-b09a-dc7bc4140000 pid=5316->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 142B guuid=4542d2f4-2000-0000-b09a-dc7bc5140000 pid=5317->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 91B guuid=54c68128-2100-0000-b09a-dc7bca140000 pid=5322->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 142B guuid=bbe71e37-2100-0000-b09a-dc7bcb140000 pid=5323->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 91B guuid=dad0e548-2100-0000-b09a-dc7bd0140000 pid=5328->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=1e5aac5b-2100-0000-b09a-dc7bd1140000 pid=5329->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=aed8b470-2100-0000-b09a-dc7bd6140000 pid=5334->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 142B guuid=70d1ed7e-2100-0000-b09a-dc7bd7140000 pid=5335->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-18 16:53:28 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
uraniumc2.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7f55eb9ac447608017451a30425c2a7ce85a51fa5cf436b16c215cbeec25d909

(this sample)

  
Delivery method
Distributed via web download

Comments