MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81a917839ff4249951ecb0ae7e21d57b1d5218ae34007ed3e015672f3e54c306. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 81a917839ff4249951ecb0ae7e21d57b1d5218ae34007ed3e015672f3e54c306
SHA3-384 hash: 85b014dbef3d3393be9d9c8f3963bda5d4d64c7cb5b1a676eb5efac97ccf8834a69f0b47ea8907ba9da63d99bafcc1b8
SHA1 hash: f89c89f911dcff81430c4c6f8249e508b4199853
MD5 hash: d0dff99dc98d67b781581a2980886e32
humanhash: jig-gee-hydrogen-batman
File name:qkuys.sh
Download: download sample
Signature Mirai
File size:3'044 bytes
First seen:2025-11-21 06:39:47 UTC
Last seen:2025-11-22 05:48:15 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iFIAFPmFqMFXeF9CFRSF0a60aX3KLFEnAFBILFguJFPOFD6F28FmYF3bh:iFIAFPmFqMFXeF9CFRSF030E3KLFEnAc
TLSH T1485190ED11E04B7EAE5A9AA332A8CB95398970D7ACD39F0C9CDC24F5084DF043100BA3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.241.208.248/bin/Polar.x86n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.mipsn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.arcn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.i468n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.i686n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.x86_64n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.mpsln/an/aelf ua-wget
http://185.241.208.248/bin/Polar.armn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.arm5n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.arm6n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.arm7n/an/aelf ua-wget
http://185.241.208.248/bin/Polar.ppcn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.spcn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.m68kn/an/aelf ua-wget
http://185.241.208.248/bin/Polar.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai virus
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-19T14:40:00Z UTC
Last seen:
2025-11-22T10:18:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=8b3f429e-1600-0000-5456-eb06100d0000 pid=3344 /usr/bin/sudo guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351 /tmp/sample.bin guuid=8b3f429e-1600-0000-5456-eb06100d0000 pid=3344->guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351 execve guuid=8774b0a1-1600-0000-5456-eb06180d0000 pid=3352 /usr/bin/cp guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=8774b0a1-1600-0000-5456-eb06180d0000 pid=3352 execve guuid=6325c3a5-1600-0000-5456-eb06220d0000 pid=3362 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=6325c3a5-1600-0000-5456-eb06220d0000 pid=3362 execve guuid=a451ccae-1600-0000-5456-eb06360d0000 pid=3382 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=a451ccae-1600-0000-5456-eb06360d0000 pid=3382 execve guuid=c25ec1bf-1600-0000-5456-eb06540d0000 pid=3412 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=c25ec1bf-1600-0000-5456-eb06540d0000 pid=3412 execve guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415 /tmp/Polar.x86 net guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415 execve guuid=c1a43eee-1700-0000-5456-eb0644100000 pid=4164 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=c1a43eee-1700-0000-5456-eb0644100000 pid=4164 execve guuid=32f8b3ee-1700-0000-5456-eb0646100000 pid=4166 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=32f8b3ee-1700-0000-5456-eb0646100000 pid=4166 execve guuid=af8b6af7-1700-0000-5456-eb065d100000 pid=4189 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=af8b6af7-1700-0000-5456-eb065d100000 pid=4189 execve guuid=88a6ad01-1800-0000-5456-eb0678100000 pid=4216 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=88a6ad01-1800-0000-5456-eb0678100000 pid=4216 execve guuid=e7db2202-1800-0000-5456-eb067b100000 pid=4219 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=e7db2202-1800-0000-5456-eb067b100000 pid=4219 clone guuid=e69f3104-1800-0000-5456-eb0682100000 pid=4226 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=e69f3104-1800-0000-5456-eb0682100000 pid=4226 execve guuid=3dfa8d04-1800-0000-5456-eb0686100000 pid=4230 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=3dfa8d04-1800-0000-5456-eb0686100000 pid=4230 execve guuid=23d8d90d-1800-0000-5456-eb06a7100000 pid=4263 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=23d8d90d-1800-0000-5456-eb06a7100000 pid=4263 execve guuid=7534e519-1800-0000-5456-eb06ce100000 pid=4302 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=7534e519-1800-0000-5456-eb06ce100000 pid=4302 execve guuid=bd442e1a-1800-0000-5456-eb06d0100000 pid=4304 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=bd442e1a-1800-0000-5456-eb06d0100000 pid=4304 clone guuid=3266ed1a-1800-0000-5456-eb06d4100000 pid=4308 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=3266ed1a-1800-0000-5456-eb06d4100000 pid=4308 execve guuid=0b09701b-1800-0000-5456-eb06d5100000 pid=4309 /usr/bin/wget net send-data guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=0b09701b-1800-0000-5456-eb06d5100000 pid=4309 execve guuid=c34b2c20-1800-0000-5456-eb06e1100000 pid=4321 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=c34b2c20-1800-0000-5456-eb06e1100000 pid=4321 execve guuid=e080cc27-1800-0000-5456-eb06f0100000 pid=4336 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=e080cc27-1800-0000-5456-eb06f0100000 pid=4336 execve guuid=56761028-1800-0000-5456-eb06f3100000 pid=4339 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=56761028-1800-0000-5456-eb06f3100000 pid=4339 clone guuid=d3336328-1800-0000-5456-eb06f7100000 pid=4343 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=d3336328-1800-0000-5456-eb06f7100000 pid=4343 execve guuid=96c9a128-1800-0000-5456-eb06f8100000 pid=4344 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=96c9a128-1800-0000-5456-eb06f8100000 pid=4344 execve guuid=4a400d30-1800-0000-5456-eb0611110000 pid=4369 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=4a400d30-1800-0000-5456-eb0611110000 pid=4369 execve guuid=0abfc138-1800-0000-5456-eb0632110000 pid=4402 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=0abfc138-1800-0000-5456-eb0632110000 pid=4402 execve guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404 /tmp/Polar.i686 net guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404 execve guuid=1f514c68-1900-0000-5456-eb06fb130000 pid=5115 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=1f514c68-1900-0000-5456-eb06fb130000 pid=5115 execve guuid=415a3969-1900-0000-5456-eb06fe130000 pid=5118 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=415a3969-1900-0000-5456-eb06fe130000 pid=5118 execve guuid=75644a71-1900-0000-5456-eb060a140000 pid=5130 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=75644a71-1900-0000-5456-eb060a140000 pid=5130 execve guuid=46e60b7c-1900-0000-5456-eb062b140000 pid=5163 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=46e60b7c-1900-0000-5456-eb062b140000 pid=5163 execve guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165 /tmp/Polar.x86_64 mprotect-exec net guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165 execve guuid=29b0c2a7-1a00-0000-5456-eb0694140000 pid=5268 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=29b0c2a7-1a00-0000-5456-eb0694140000 pid=5268 execve guuid=409b5ea8-1a00-0000-5456-eb0695140000 pid=5269 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=409b5ea8-1a00-0000-5456-eb0695140000 pid=5269 execve guuid=126f92b1-1a00-0000-5456-eb0696140000 pid=5270 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=126f92b1-1a00-0000-5456-eb0696140000 pid=5270 execve guuid=58434bc0-1a00-0000-5456-eb0697140000 pid=5271 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=58434bc0-1a00-0000-5456-eb0697140000 pid=5271 execve guuid=3199c3c0-1a00-0000-5456-eb0698140000 pid=5272 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=3199c3c0-1a00-0000-5456-eb0698140000 pid=5272 clone guuid=4f01bcc1-1a00-0000-5456-eb069a140000 pid=5274 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=4f01bcc1-1a00-0000-5456-eb069a140000 pid=5274 execve guuid=f89e20c2-1a00-0000-5456-eb069b140000 pid=5275 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=f89e20c2-1a00-0000-5456-eb069b140000 pid=5275 execve guuid=3dfb22cb-1a00-0000-5456-eb069c140000 pid=5276 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=3dfb22cb-1a00-0000-5456-eb069c140000 pid=5276 execve guuid=69a856e8-1a00-0000-5456-eb069d140000 pid=5277 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=69a856e8-1a00-0000-5456-eb069d140000 pid=5277 execve guuid=1029e5e8-1a00-0000-5456-eb069e140000 pid=5278 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=1029e5e8-1a00-0000-5456-eb069e140000 pid=5278 clone guuid=cffdd4e9-1a00-0000-5456-eb06a0140000 pid=5280 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=cffdd4e9-1a00-0000-5456-eb06a0140000 pid=5280 execve guuid=80fd5dec-1a00-0000-5456-eb06a1140000 pid=5281 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=80fd5dec-1a00-0000-5456-eb06a1140000 pid=5281 execve guuid=909dbaf2-1a00-0000-5456-eb06a2140000 pid=5282 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=909dbaf2-1a00-0000-5456-eb06a2140000 pid=5282 execve guuid=3c9128fc-1a00-0000-5456-eb06a3140000 pid=5283 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=3c9128fc-1a00-0000-5456-eb06a3140000 pid=5283 execve guuid=f0f172fc-1a00-0000-5456-eb06a4140000 pid=5284 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=f0f172fc-1a00-0000-5456-eb06a4140000 pid=5284 clone guuid=6c461bfe-1a00-0000-5456-eb06a6140000 pid=5286 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=6c461bfe-1a00-0000-5456-eb06a6140000 pid=5286 execve guuid=d9645efe-1a00-0000-5456-eb06a7140000 pid=5287 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=d9645efe-1a00-0000-5456-eb06a7140000 pid=5287 execve guuid=ae8b9b06-1b00-0000-5456-eb06a8140000 pid=5288 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=ae8b9b06-1b00-0000-5456-eb06a8140000 pid=5288 execve guuid=b6cc2014-1b00-0000-5456-eb06a9140000 pid=5289 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=b6cc2014-1b00-0000-5456-eb06a9140000 pid=5289 execve guuid=5f5ddd14-1b00-0000-5456-eb06aa140000 pid=5290 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=5f5ddd14-1b00-0000-5456-eb06aa140000 pid=5290 clone guuid=7b7f8d17-1b00-0000-5456-eb06ac140000 pid=5292 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=7b7f8d17-1b00-0000-5456-eb06ac140000 pid=5292 execve guuid=edc3df17-1b00-0000-5456-eb06ad140000 pid=5293 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=edc3df17-1b00-0000-5456-eb06ad140000 pid=5293 execve guuid=11cfb920-1b00-0000-5456-eb06ae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=11cfb920-1b00-0000-5456-eb06ae140000 pid=5294 execve guuid=ddbc4629-1b00-0000-5456-eb06af140000 pid=5295 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=ddbc4629-1b00-0000-5456-eb06af140000 pid=5295 execve guuid=df0b8b29-1b00-0000-5456-eb06b0140000 pid=5296 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=df0b8b29-1b00-0000-5456-eb06b0140000 pid=5296 clone guuid=6eb9372a-1b00-0000-5456-eb06b2140000 pid=5298 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=6eb9372a-1b00-0000-5456-eb06b2140000 pid=5298 execve guuid=e394a72d-1b00-0000-5456-eb06b3140000 pid=5299 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=e394a72d-1b00-0000-5456-eb06b3140000 pid=5299 execve guuid=1045f534-1b00-0000-5456-eb06b4140000 pid=5300 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=1045f534-1b00-0000-5456-eb06b4140000 pid=5300 execve guuid=91e3673d-1b00-0000-5456-eb06b5140000 pid=5301 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=91e3673d-1b00-0000-5456-eb06b5140000 pid=5301 execve guuid=bdb2053e-1b00-0000-5456-eb06b6140000 pid=5302 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=bdb2053e-1b00-0000-5456-eb06b6140000 pid=5302 clone guuid=bbea1b3f-1b00-0000-5456-eb06b8140000 pid=5304 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=bbea1b3f-1b00-0000-5456-eb06b8140000 pid=5304 execve guuid=d255ab3f-1b00-0000-5456-eb06b9140000 pid=5305 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=d255ab3f-1b00-0000-5456-eb06b9140000 pid=5305 execve guuid=38f6e547-1b00-0000-5456-eb06bb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=38f6e547-1b00-0000-5456-eb06bb140000 pid=5307 execve guuid=94063350-1b00-0000-5456-eb06c1140000 pid=5313 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=94063350-1b00-0000-5456-eb06c1140000 pid=5313 execve guuid=ed8f8a50-1b00-0000-5456-eb06c2140000 pid=5314 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=ed8f8a50-1b00-0000-5456-eb06c2140000 pid=5314 clone guuid=d2223362-1b00-0000-5456-eb06c4140000 pid=5316 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=d2223362-1b00-0000-5456-eb06c4140000 pid=5316 execve guuid=0480c262-1b00-0000-5456-eb06c5140000 pid=5317 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=0480c262-1b00-0000-5456-eb06c5140000 pid=5317 execve guuid=5831e26c-1b00-0000-5456-eb06c6140000 pid=5318 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=5831e26c-1b00-0000-5456-eb06c6140000 pid=5318 execve guuid=4f3c0978-1b00-0000-5456-eb06ce140000 pid=5326 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=4f3c0978-1b00-0000-5456-eb06ce140000 pid=5326 execve guuid=8d628b78-1b00-0000-5456-eb06cf140000 pid=5327 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=8d628b78-1b00-0000-5456-eb06cf140000 pid=5327 clone guuid=c7adb679-1b00-0000-5456-eb06d1140000 pid=5329 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=c7adb679-1b00-0000-5456-eb06d1140000 pid=5329 execve guuid=d85e577a-1b00-0000-5456-eb06d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=d85e577a-1b00-0000-5456-eb06d2140000 pid=5330 execve guuid=a4476485-1b00-0000-5456-eb06d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=a4476485-1b00-0000-5456-eb06d3140000 pid=5331 execve guuid=576ef390-1b00-0000-5456-eb06d6140000 pid=5334 /usr/bin/chmod guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=576ef390-1b00-0000-5456-eb06d6140000 pid=5334 execve guuid=7db87e91-1b00-0000-5456-eb06d7140000 pid=5335 /usr/bin/bash guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=7db87e91-1b00-0000-5456-eb06d7140000 pid=5335 clone guuid=a5809792-1b00-0000-5456-eb06d9140000 pid=5337 /usr/bin/rm delete-file guuid=27f5aaa0-1600-0000-5456-eb06170d0000 pid=3351->guuid=a5809792-1b00-0000-5456-eb06d9140000 pid=5337 execve 6b32a7fe-f32b-50ba-b2d3-58003a915178 185.241.208.248:80 guuid=6325c3a5-1600-0000-5456-eb06220d0000 pid=3362->6b32a7fe-f32b-50ba-b2d3-58003a915178 send: 143B guuid=a451ccae-1600-0000-5456-eb06360d0000 pid=3382->6b32a7fe-f32b-50ba-b2d3-58003a915178 send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7447eac1-1600-0000-5456-eb06590d0000 pid=3417 /tmp/Polar.x86 guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415->guuid=7447eac1-1600-0000-5456-eb06590d0000 pid=3417 clone guuid=3c2622ee-1700-0000-5456-eb0640100000 pid=4160 /tmp/Polar.x86 guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415->guuid=3c2622ee-1700-0000-5456-eb0640100000 pid=4160 clone guuid=cf5b30ee-1700-0000-5456-eb0642100000 pid=4162 /tmp/Polar.x86 net send-data zombie guuid=08a063c0-1600-0000-5456-eb06570d0000 pid=3415->guuid=cf5b30ee-1700-0000-5456-eb0642100000 pid=4162 clone guuid=6275fdc1-1600-0000-5456-eb065a0d0000 pid=3418 /tmp/Polar.x86 guuid=7447eac1-1600-0000-5456-eb06590d0000 pid=3417->guuid=6275fdc1-1600-0000-5456-eb065a0d0000 pid=3418 clone guuid=33d805c2-1600-0000-5456-eb065c0d0000 pid=3420 /tmp/Polar.x86 dns net send-data zombie guuid=7447eac1-1600-0000-5456-eb06590d0000 pid=3417->guuid=33d805c2-1600-0000-5456-eb065c0d0000 pid=3420 clone guuid=33d805c2-1600-0000-5456-eb065c0d0000 pid=3420->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B 835e2637-8ea8-5733-9bcd-e417a3d56db3 lolzzmortex.duckdns.org:69 guuid=33d805c2-1600-0000-5456-eb065c0d0000 pid=3420->835e2637-8ea8-5733-9bcd-e417a3d56db3 send: 19B guuid=cf5b30ee-1700-0000-5456-eb0642100000 pid=4162->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1025B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=cf5b30ee-1700-0000-5456-eb0642100000 pid=4162->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B 476a0c93-2191-583b-9b9c-60decf74ba9d lolzzmortex.duckdns.org:80 guuid=32f8b3ee-1700-0000-5456-eb0646100000 pid=4166->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=af8b6af7-1700-0000-5456-eb065d100000 pid=4189->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=3dfa8d04-1800-0000-5456-eb0686100000 pid=4230->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=23d8d90d-1800-0000-5456-eb06a7100000 pid=4263->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B guuid=0b09701b-1800-0000-5456-eb06d5100000 pid=4309->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=c34b2c20-1800-0000-5456-eb06e1100000 pid=4321->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=96c9a128-1800-0000-5456-eb06f8100000 pid=4344->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=4a400d30-1800-0000-5456-eb0611110000 pid=4369->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6e3b973a-1800-0000-5456-eb063a110000 pid=4410 /tmp/Polar.i686 guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404->guuid=6e3b973a-1800-0000-5456-eb063a110000 pid=4410 clone guuid=f1672b68-1900-0000-5456-eb06f9130000 pid=5113 /tmp/Polar.i686 guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404->guuid=f1672b68-1900-0000-5456-eb06f9130000 pid=5113 clone guuid=7ece3868-1900-0000-5456-eb06fa130000 pid=5114 /tmp/Polar.i686 net send-data zombie guuid=794c2439-1800-0000-5456-eb0634110000 pid=4404->guuid=7ece3868-1900-0000-5456-eb06fa130000 pid=5114 clone guuid=bc94a23a-1800-0000-5456-eb063b110000 pid=4411 /tmp/Polar.i686 guuid=6e3b973a-1800-0000-5456-eb063a110000 pid=4410->guuid=bc94a23a-1800-0000-5456-eb063b110000 pid=4411 clone guuid=982ca83a-1800-0000-5456-eb063c110000 pid=4412 /tmp/Polar.i686 dns net send-data zombie guuid=6e3b973a-1800-0000-5456-eb063a110000 pid=4410->guuid=982ca83a-1800-0000-5456-eb063c110000 pid=4412 clone guuid=982ca83a-1800-0000-5456-eb063c110000 pid=4412->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=982ca83a-1800-0000-5456-eb063c110000 pid=4412->835e2637-8ea8-5733-9bcd-e417a3d56db3 send: 20B guuid=7ece3868-1900-0000-5456-eb06fa130000 pid=5114->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1025B guuid=7ece3868-1900-0000-5456-eb06fa130000 pid=5114->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=415a3969-1900-0000-5456-eb06fe130000 pid=5118->476a0c93-2191-583b-9b9c-60decf74ba9d send: 146B guuid=75644a71-1900-0000-5456-eb060a140000 pid=5130->476a0c93-2191-583b-9b9c-60decf74ba9d send: 95B guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=df80e77c-1900-0000-5456-eb0630140000 pid=5168 /tmp/Polar.x86_64 guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165->guuid=df80e77c-1900-0000-5456-eb0630140000 pid=5168 clone guuid=bd5e68a7-1a00-0000-5456-eb0692140000 pid=5266 /tmp/Polar.x86_64 guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165->guuid=bd5e68a7-1a00-0000-5456-eb0692140000 pid=5266 clone guuid=2b1e7fa7-1a00-0000-5456-eb0693140000 pid=5267 /tmp/Polar.x86_64 net send-data zombie guuid=94e44c7c-1900-0000-5456-eb062d140000 pid=5165->guuid=2b1e7fa7-1a00-0000-5456-eb0693140000 pid=5267 clone guuid=9dfced7c-1900-0000-5456-eb0631140000 pid=5169 /tmp/Polar.x86_64 guuid=df80e77c-1900-0000-5456-eb0630140000 pid=5168->guuid=9dfced7c-1900-0000-5456-eb0631140000 pid=5169 clone guuid=077ff17c-1900-0000-5456-eb0632140000 pid=5170 /tmp/Polar.x86_64 net send-data zombie guuid=df80e77c-1900-0000-5456-eb0630140000 pid=5168->guuid=077ff17c-1900-0000-5456-eb0632140000 pid=5170 clone guuid=077ff17c-1900-0000-5456-eb0632140000 pid=5170->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1025B guuid=077ff17c-1900-0000-5456-eb0632140000 pid=5170->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2b1e7fa7-1a00-0000-5456-eb0693140000 pid=5267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=2b1e7fa7-1a00-0000-5456-eb0693140000 pid=5267->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=409b5ea8-1a00-0000-5456-eb0695140000 pid=5269->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=126f92b1-1a00-0000-5456-eb0696140000 pid=5270->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=f89e20c2-1a00-0000-5456-eb069b140000 pid=5275->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=3dfb22cb-1a00-0000-5456-eb069c140000 pid=5276->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B guuid=80fd5dec-1a00-0000-5456-eb06a1140000 pid=5281->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=909dbaf2-1a00-0000-5456-eb06a2140000 pid=5282->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=d9645efe-1a00-0000-5456-eb06a7140000 pid=5287->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=ae8b9b06-1b00-0000-5456-eb06a8140000 pid=5288->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=edc3df17-1b00-0000-5456-eb06ad140000 pid=5293->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=11cfb920-1b00-0000-5456-eb06ae140000 pid=5294->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=e394a72d-1b00-0000-5456-eb06b3140000 pid=5299->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=1045f534-1b00-0000-5456-eb06b4140000 pid=5300->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B guuid=d255ab3f-1b00-0000-5456-eb06b9140000 pid=5305->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=38f6e547-1b00-0000-5456-eb06bb140000 pid=5307->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B guuid=0480c262-1b00-0000-5456-eb06c5140000 pid=5317->476a0c93-2191-583b-9b9c-60decf74ba9d send: 144B guuid=5831e26c-1b00-0000-5456-eb06c6140000 pid=5318->476a0c93-2191-583b-9b9c-60decf74ba9d send: 93B guuid=d85e577a-1b00-0000-5456-eb06d2140000 pid=5330->476a0c93-2191-583b-9b9c-60decf74ba9d send: 143B guuid=a4476485-1b00-0000-5456-eb06d3140000 pid=5331->476a0c93-2191-583b-9b9c-60decf74ba9d send: 92B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-20 04:16:48 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Creates a large amount of network flows
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
lolzzmortex.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 81a917839ff4249951ecb0ae7e21d57b1d5218ae34007ed3e015672f3e54c306

(this sample)

  
Delivery method
Distributed via web download

Comments