MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 84c60aae6337281f26785177548ae102fbb8d3ca1332062236e0100e404972cc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 84c60aae6337281f26785177548ae102fbb8d3ca1332062236e0100e404972cc
SHA3-384 hash: 91e208709689db1035b466a85d1ed1e2507d3db9006430ea7b37952158f35d9d05ceae48486ff353f52384dc943df6e1
SHA1 hash: 52ff1376b9a3bbcdfddcd3a58bb4c8418877ba0d
MD5 hash: 718a512a34fb4626992f511e06aa1cb2
humanhash: maryland-finch-hotel-magazine
File name:1.sh
Download: download sample
Signature Mirai
File size:3'019 bytes
First seen:2025-11-01 14:57:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:innenhmlnncnnElnnvnCXlnnrnePlnna4nazvZlnnaynaFvjlnn9Nqn9z4gelnnh:iumlOElaXlSPlazzvZlaVFvjl9kz4Zlh
TLSH T1FA519FC70225453D6CA7BA23FDBE9F2C35C056921AE9BF8697EC34B5528CDC8B044A43
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.163.118.111/hiddenbin/Space.arc901f0ebbc68d65b08f81fe050bb08e76c976596109a8304acbb41b680dd3c697 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.x86e8fa014196818d3551c0f9a495310d01f1a5d951a95d34f5e6fa8d3461d0b2bd Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.x86_640cb291cd58939d1be6f96da6feda04dff16623b5c29b331c1ad559ce79914d24 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.i686e94666504b15ec4bd5842a790012ba81e7fbed2bd07ff7afc4faf1f8d4579829 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.mips4fe401227d4d6a4b2c6e78405f1fda8ec500396e5a88dc1afe13fdc018d472dc Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.mips64n/an/aelf ua-wget
http://103.163.118.111/hiddenbin/Space.mpsl19e8d298828636c379fb28d72e9b2794f6277efabaa678b761da9f5abdf0e6f1 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.arm7a6cf4acad516547d3f63b79d99e1f0a9f3e00a9a71eb148b3ec0cd0e4a16cdd Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.arm555415eb373b09e347c6528214758673a8ed465d2365a0920a85d7d865c6de7d8 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.arm67493565de036353bff63e86f48e813f9ee727532e4eafc99ef8a18f8899b3e5a Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.arm720ddadb29d652186d2cc3b43e54ba6f6048f4fa988a7ef0b859ee606ede8d5e4 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.ppc121ba3d1548ef96ab2dc37624e6aa45e3459c3af8b756858b5e122343c8248e5 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.sparcn/an/aelf ua-wget
http://103.163.118.111/hiddenbin/Space.m68k56e1cee39ef126216bcf33e4a96d0814f48c84eb956e8916ad71402e18f00247 Miraielf mirai ua-wget
http://103.163.118.111/hiddenbin/Space.sh47604b2164d5dd1cf105fd5d9e72bab89ed8f56f21e578c314cbdc105631e20dd Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-01T12:05:00Z UTC
Last seen:
2025-11-02T13:28:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=8f2cca16-1900-0000-f617-793768120000 pid=4712 /usr/bin/sudo guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718 /tmp/sample.bin guuid=8f2cca16-1900-0000-f617-793768120000 pid=4712->guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718 execve guuid=32080119-1900-0000-f617-79376f120000 pid=4719 /usr/bin/cp guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=32080119-1900-0000-f617-79376f120000 pid=4719 execve guuid=3c907a1e-1900-0000-f617-793777120000 pid=4727 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=3c907a1e-1900-0000-f617-793777120000 pid=4727 execve guuid=1cda59b0-1900-0000-f617-7937d7130000 pid=5079 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=1cda59b0-1900-0000-f617-7937d7130000 pid=5079 execve guuid=05d83a10-1a00-0000-f617-793762140000 pid=5218 /usr/bin/cat guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=05d83a10-1a00-0000-f617-793762140000 pid=5218 execve guuid=41578910-1a00-0000-f617-793763140000 pid=5219 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=41578910-1a00-0000-f617-793763140000 pid=5219 execve guuid=90b5ca10-1a00-0000-f617-793764140000 pid=5220 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=90b5ca10-1a00-0000-f617-793764140000 pid=5220 clone guuid=ed955b11-1a00-0000-f617-793766140000 pid=5222 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=ed955b11-1a00-0000-f617-793766140000 pid=5222 execve guuid=0491203d-1a00-0000-f617-793767140000 pid=5223 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=0491203d-1a00-0000-f617-793767140000 pid=5223 execve guuid=947fd879-1a00-0000-f617-793768140000 pid=5224 /usr/bin/cat guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=947fd879-1a00-0000-f617-793768140000 pid=5224 execve guuid=1586b27a-1a00-0000-f617-793769140000 pid=5225 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=1586b27a-1a00-0000-f617-793769140000 pid=5225 execve guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226 execve guuid=cdb8f9a8-1b00-0000-f617-793777140000 pid=5239 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=cdb8f9a8-1b00-0000-f617-793777140000 pid=5239 execve guuid=4b57c3eb-1b00-0000-f617-793786140000 pid=5254 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=4b57c3eb-1b00-0000-f617-793786140000 pid=5254 execve guuid=9321f71f-1c00-0000-f617-793799140000 pid=5273 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=9321f71f-1c00-0000-f617-793799140000 pid=5273 clone guuid=d2142e20-1c00-0000-f617-79379a140000 pid=5274 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=d2142e20-1c00-0000-f617-79379a140000 pid=5274 execve guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275 execve guuid=52001c4e-1d00-0000-f617-7937a1140000 pid=5281 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=52001c4e-1d00-0000-f617-7937a1140000 pid=5281 execve guuid=e138fe89-1d00-0000-f617-7937a2140000 pid=5282 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=e138fe89-1d00-0000-f617-7937a2140000 pid=5282 execve guuid=ee8634be-1d00-0000-f617-7937a3140000 pid=5283 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=ee8634be-1d00-0000-f617-7937a3140000 pid=5283 clone guuid=03a973be-1d00-0000-f617-7937a4140000 pid=5284 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=03a973be-1d00-0000-f617-7937a4140000 pid=5284 execve guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285 execve guuid=39d312ed-1e00-0000-f617-7937ab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=39d312ed-1e00-0000-f617-7937ab140000 pid=5291 execve guuid=8319166d-1f00-0000-f617-7937ac140000 pid=5292 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=8319166d-1f00-0000-f617-7937ac140000 pid=5292 execve guuid=ee1f5bd0-1f00-0000-f617-7937ad140000 pid=5293 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=ee1f5bd0-1f00-0000-f617-7937ad140000 pid=5293 clone guuid=4a87a9d0-1f00-0000-f617-7937ae140000 pid=5294 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=4a87a9d0-1f00-0000-f617-7937ae140000 pid=5294 execve guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295 execve guuid=d14193ff-2000-0000-f617-7937b5140000 pid=5301 /usr/bin/wget net send-data guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=d14193ff-2000-0000-f617-7937b5140000 pid=5301 execve guuid=8d64502f-2100-0000-f617-7937b6140000 pid=5302 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=8d64502f-2100-0000-f617-7937b6140000 pid=5302 execve guuid=4b53d750-2100-0000-f617-7937b7140000 pid=5303 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=4b53d750-2100-0000-f617-7937b7140000 pid=5303 clone guuid=ac5d1751-2100-0000-f617-7937b8140000 pid=5304 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=ac5d1751-2100-0000-f617-7937b8140000 pid=5304 execve guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305 execve guuid=8fc2ac7f-2200-0000-f617-7937bf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=8fc2ac7f-2200-0000-f617-7937bf140000 pid=5311 execve guuid=5b1edbb6-2200-0000-f617-7937c0140000 pid=5312 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=5b1edbb6-2200-0000-f617-7937c0140000 pid=5312 execve guuid=80fe88e3-2200-0000-f617-7937c1140000 pid=5313 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=80fe88e3-2200-0000-f617-7937c1140000 pid=5313 clone guuid=16a6c8e3-2200-0000-f617-7937c2140000 pid=5314 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=16a6c8e3-2200-0000-f617-7937c2140000 pid=5314 execve guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315 execve guuid=de151312-2400-0000-f617-7937c9140000 pid=5321 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=de151312-2400-0000-f617-7937c9140000 pid=5321 execve guuid=9edd79af-2400-0000-f617-7937ca140000 pid=5322 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=9edd79af-2400-0000-f617-7937ca140000 pid=5322 execve guuid=5bd3baf2-2400-0000-f617-7937cb140000 pid=5323 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=5bd3baf2-2400-0000-f617-7937cb140000 pid=5323 clone guuid=ff93f6f2-2400-0000-f617-7937cc140000 pid=5324 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=ff93f6f2-2400-0000-f617-7937cc140000 pid=5324 execve guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325 execve guuid=495d6321-2600-0000-f617-7937d3140000 pid=5331 /usr/bin/wget net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=495d6321-2600-0000-f617-7937d3140000 pid=5331 execve guuid=8506f64d-2600-0000-f617-7937d4140000 pid=5332 /usr/bin/curl net send-data write-file guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=8506f64d-2600-0000-f617-7937d4140000 pid=5332 execve guuid=5be3cd84-2600-0000-f617-7937d5140000 pid=5333 /usr/bin/bash guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=5be3cd84-2600-0000-f617-7937d5140000 pid=5333 clone guuid=f8fbfc84-2600-0000-f617-7937d6140000 pid=5334 /usr/bin/chmod guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=f8fbfc84-2600-0000-f617-7937d6140000 pid=5334 execve guuid=7bd69385-2600-0000-f617-7937d7140000 pid=5335 /tmp/Space net guuid=9bc47618-1900-0000-f617-79376e120000 pid=4718->guuid=7bd69385-2600-0000-f617-7937d7140000 pid=5335 execve 4dc8f021-65f9-592d-ba70-ad0bb944acca 103.163.118.111:80 guuid=3c907a1e-1900-0000-f617-793777120000 pid=4727->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 149B guuid=1cda59b0-1900-0000-f617-7937d7130000 pid=5079->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 98B guuid=ed955b11-1a00-0000-f617-793766140000 pid=5222->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 149B guuid=0491203d-1a00-0000-f617-793767140000 pid=5223->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18ddb07c-1a00-0000-f617-79376b140000 pid=5227 /tmp/Space guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226->guuid=18ddb07c-1a00-0000-f617-79376b140000 pid=5227 clone guuid=df9fe7a8-1b00-0000-f617-793775140000 pid=5237 /tmp/Space guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226->guuid=df9fe7a8-1b00-0000-f617-793775140000 pid=5237 clone guuid=4a21eda8-1b00-0000-f617-793776140000 pid=5238 /tmp/Space net send-data zombie guuid=3818777b-1a00-0000-f617-79376a140000 pid=5226->guuid=4a21eda8-1b00-0000-f617-793776140000 pid=5238 clone guuid=eb55e57c-1a00-0000-f617-79376c140000 pid=5228 /tmp/Space guuid=18ddb07c-1a00-0000-f617-79376b140000 pid=5227->guuid=eb55e57c-1a00-0000-f617-79376c140000 pid=5228 clone guuid=03c6f17c-1a00-0000-f617-79376d140000 pid=5229 /tmp/Space net send-data zombie guuid=18ddb07c-1a00-0000-f617-79376b140000 pid=5227->guuid=03c6f17c-1a00-0000-f617-79376d140000 pid=5229 clone guuid=03c6f17c-1a00-0000-f617-79376d140000 pid=5229->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 103.163.118.111:3778 guuid=03c6f17c-1a00-0000-f617-79376d140000 pid=5229->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 112B guuid=4a21eda8-1b00-0000-f617-793776140000 pid=5238->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4a21eda8-1b00-0000-f617-793776140000 pid=5238->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 77B guuid=cdb8f9a8-1b00-0000-f617-793777140000 pid=5239->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 152B guuid=4b57c3eb-1b00-0000-f617-793786140000 pid=5254->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 101B guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1acb121-1c00-0000-f617-79379c140000 pid=5276 /tmp/Space guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275->guuid=f1acb121-1c00-0000-f617-79379c140000 pid=5276 clone guuid=f275034e-1d00-0000-f617-79379f140000 pid=5279 /tmp/Space guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275->guuid=f275034e-1d00-0000-f617-79379f140000 pid=5279 clone guuid=5bab0a4e-1d00-0000-f617-7937a0140000 pid=5280 /tmp/Space net send-data zombie guuid=8292bd20-1c00-0000-f617-79379b140000 pid=5275->guuid=5bab0a4e-1d00-0000-f617-7937a0140000 pid=5280 clone guuid=8ea6be21-1c00-0000-f617-79379d140000 pid=5277 /tmp/Space guuid=f1acb121-1c00-0000-f617-79379c140000 pid=5276->guuid=8ea6be21-1c00-0000-f617-79379d140000 pid=5277 clone guuid=2b11c921-1c00-0000-f617-79379e140000 pid=5278 /tmp/Space net send-data zombie guuid=f1acb121-1c00-0000-f617-79379c140000 pid=5276->guuid=2b11c921-1c00-0000-f617-79379e140000 pid=5278 clone guuid=2b11c921-1c00-0000-f617-79379e140000 pid=5278->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2b11c921-1c00-0000-f617-79379e140000 pid=5278->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 87B guuid=5bab0a4e-1d00-0000-f617-7937a0140000 pid=5280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5bab0a4e-1d00-0000-f617-7937a0140000 pid=5280->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 27B guuid=52001c4e-1d00-0000-f617-7937a1140000 pid=5281->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 150B guuid=e138fe89-1d00-0000-f617-7937a2140000 pid=5282->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 99B guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=23a1fcbf-1d00-0000-f617-7937a6140000 pid=5286 /tmp/Space guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285->guuid=23a1fcbf-1d00-0000-f617-7937a6140000 pid=5286 clone guuid=8364eaec-1e00-0000-f617-7937a9140000 pid=5289 /tmp/Space guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285->guuid=8364eaec-1e00-0000-f617-7937a9140000 pid=5289 clone guuid=7dbcf8ec-1e00-0000-f617-7937aa140000 pid=5290 /tmp/Space net send-data zombie guuid=1f9907bf-1d00-0000-f617-7937a5140000 pid=5285->guuid=7dbcf8ec-1e00-0000-f617-7937aa140000 pid=5290 clone guuid=0bd509c0-1d00-0000-f617-7937a7140000 pid=5287 /tmp/Space guuid=23a1fcbf-1d00-0000-f617-7937a6140000 pid=5286->guuid=0bd509c0-1d00-0000-f617-7937a7140000 pid=5287 clone guuid=186016c0-1d00-0000-f617-7937a8140000 pid=5288 /tmp/Space net send-data zombie guuid=23a1fcbf-1d00-0000-f617-7937a6140000 pid=5286->guuid=186016c0-1d00-0000-f617-7937a8140000 pid=5288 clone guuid=186016c0-1d00-0000-f617-7937a8140000 pid=5288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=186016c0-1d00-0000-f617-7937a8140000 pid=5288->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 77B guuid=7dbcf8ec-1e00-0000-f617-7937aa140000 pid=5290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7dbcf8ec-1e00-0000-f617-7937aa140000 pid=5290->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 42B guuid=39d312ed-1e00-0000-f617-7937ab140000 pid=5291->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 150B guuid=8319166d-1f00-0000-f617-7937ac140000 pid=5292->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 99B guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=615b60d2-1f00-0000-f617-7937b0140000 pid=5296 /tmp/Space guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295->guuid=615b60d2-1f00-0000-f617-7937b0140000 pid=5296 clone guuid=8fda65ff-2000-0000-f617-7937b3140000 pid=5299 /tmp/Space guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295->guuid=8fda65ff-2000-0000-f617-7937b3140000 pid=5299 clone guuid=2d3a79ff-2000-0000-f617-7937b4140000 pid=5300 /tmp/Space net send-data zombie guuid=efb833d1-1f00-0000-f617-7937af140000 pid=5295->guuid=2d3a79ff-2000-0000-f617-7937b4140000 pid=5300 clone guuid=6e1f6dd2-1f00-0000-f617-7937b1140000 pid=5297 /tmp/Space guuid=615b60d2-1f00-0000-f617-7937b0140000 pid=5296->guuid=6e1f6dd2-1f00-0000-f617-7937b1140000 pid=5297 clone guuid=7bdc75d2-1f00-0000-f617-7937b2140000 pid=5298 /tmp/Space net send-data zombie guuid=615b60d2-1f00-0000-f617-7937b0140000 pid=5296->guuid=7bdc75d2-1f00-0000-f617-7937b2140000 pid=5298 clone guuid=7bdc75d2-1f00-0000-f617-7937b2140000 pid=5298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7bdc75d2-1f00-0000-f617-7937b2140000 pid=5298->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 12B guuid=2d3a79ff-2000-0000-f617-7937b4140000 pid=5300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d3a79ff-2000-0000-f617-7937b4140000 pid=5300->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 57B guuid=d14193ff-2000-0000-f617-7937b5140000 pid=5301->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 152B guuid=8d64502f-2100-0000-f617-7937b6140000 pid=5302->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 101B guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c78da752-2100-0000-f617-7937ba140000 pid=5306 /tmp/Space guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305->guuid=c78da752-2100-0000-f617-7937ba140000 pid=5306 clone guuid=5686867f-2200-0000-f617-7937bd140000 pid=5309 /tmp/Space guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305->guuid=5686867f-2200-0000-f617-7937bd140000 pid=5309 clone guuid=8068917f-2200-0000-f617-7937be140000 pid=5310 /tmp/Space net send-data zombie guuid=28daaf51-2100-0000-f617-7937b9140000 pid=5305->guuid=8068917f-2200-0000-f617-7937be140000 pid=5310 clone guuid=4905bd52-2100-0000-f617-7937bb140000 pid=5307 /tmp/Space guuid=c78da752-2100-0000-f617-7937ba140000 pid=5306->guuid=4905bd52-2100-0000-f617-7937bb140000 pid=5307 clone guuid=db8dc552-2100-0000-f617-7937bc140000 pid=5308 /tmp/Space net send-data zombie guuid=c78da752-2100-0000-f617-7937ba140000 pid=5306->guuid=db8dc552-2100-0000-f617-7937bc140000 pid=5308 clone guuid=db8dc552-2100-0000-f617-7937bc140000 pid=5308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=db8dc552-2100-0000-f617-7937bc140000 pid=5308->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 7B guuid=8068917f-2200-0000-f617-7937be140000 pid=5310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8068917f-2200-0000-f617-7937be140000 pid=5310->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 120B guuid=8fc2ac7f-2200-0000-f617-7937bf140000 pid=5311->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 150B guuid=5b1edbb6-2200-0000-f617-7937c0140000 pid=5312->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 99B guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62b364e5-2200-0000-f617-7937c4140000 pid=5316 /tmp/Space guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315->guuid=62b364e5-2200-0000-f617-7937c4140000 pid=5316 clone guuid=9848e811-2400-0000-f617-7937c7140000 pid=5319 /tmp/Space guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315->guuid=9848e811-2400-0000-f617-7937c7140000 pid=5319 clone guuid=b6eff311-2400-0000-f617-7937c8140000 pid=5320 /tmp/Space net send-data zombie guuid=c4dd50e4-2200-0000-f617-7937c3140000 pid=5315->guuid=b6eff311-2400-0000-f617-7937c8140000 pid=5320 clone guuid=b9e16fe5-2200-0000-f617-7937c5140000 pid=5317 /tmp/Space guuid=62b364e5-2200-0000-f617-7937c4140000 pid=5316->guuid=b9e16fe5-2200-0000-f617-7937c5140000 pid=5317 clone guuid=d6497be5-2200-0000-f617-7937c6140000 pid=5318 /tmp/Space net send-data zombie guuid=62b364e5-2200-0000-f617-7937c4140000 pid=5316->guuid=d6497be5-2200-0000-f617-7937c6140000 pid=5318 clone guuid=d6497be5-2200-0000-f617-7937c6140000 pid=5318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d6497be5-2200-0000-f617-7937c6140000 pid=5318->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 40B guuid=b6eff311-2400-0000-f617-7937c8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b6eff311-2400-0000-f617-7937c8140000 pid=5320->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 25B guuid=de151312-2400-0000-f617-7937c9140000 pid=5321->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 149B guuid=9edd79af-2400-0000-f617-7937ca140000 pid=5322->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 98B guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d65681f4-2400-0000-f617-7937ce140000 pid=5326 /tmp/Space guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325->guuid=d65681f4-2400-0000-f617-7937ce140000 pid=5326 clone guuid=f9723f21-2600-0000-f617-7937d1140000 pid=5329 /tmp/Space guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325->guuid=f9723f21-2600-0000-f617-7937d1140000 pid=5329 clone guuid=37734821-2600-0000-f617-7937d2140000 pid=5330 /tmp/Space net send-data zombie guuid=d5cd89f3-2400-0000-f617-7937cd140000 pid=5325->guuid=37734821-2600-0000-f617-7937d2140000 pid=5330 clone guuid=20af8df4-2400-0000-f617-7937cf140000 pid=5327 /tmp/Space guuid=d65681f4-2400-0000-f617-7937ce140000 pid=5326->guuid=20af8df4-2400-0000-f617-7937cf140000 pid=5327 clone guuid=861e96f4-2400-0000-f617-7937d0140000 pid=5328 /tmp/Space net send-data zombie guuid=d65681f4-2400-0000-f617-7937ce140000 pid=5326->guuid=861e96f4-2400-0000-f617-7937d0140000 pid=5328 clone guuid=861e96f4-2400-0000-f617-7937d0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=861e96f4-2400-0000-f617-7937d0140000 pid=5328->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 45B guuid=37734821-2600-0000-f617-7937d2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=37734821-2600-0000-f617-7937d2140000 pid=5330->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 25B guuid=495d6321-2600-0000-f617-7937d3140000 pid=5331->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 150B guuid=8506f64d-2600-0000-f617-7937d4140000 pid=5332->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 99B guuid=7bd69385-2600-0000-f617-7937d7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8f9b8786-2600-0000-f617-7937d8140000 pid=5336 /tmp/Space guuid=7bd69385-2600-0000-f617-7937d7140000 pid=5335->guuid=8f9b8786-2600-0000-f617-7937d8140000 pid=5336 clone guuid=b5599386-2600-0000-f617-7937d9140000 pid=5337 /tmp/Space guuid=8f9b8786-2600-0000-f617-7937d8140000 pid=5336->guuid=b5599386-2600-0000-f617-7937d9140000 pid=5337 clone guuid=38029c86-2600-0000-f617-7937da140000 pid=5338 /tmp/Space net send-data zombie guuid=8f9b8786-2600-0000-f617-7937d8140000 pid=5336->guuid=38029c86-2600-0000-f617-7937da140000 pid=5338 clone guuid=38029c86-2600-0000-f617-7937da140000 pid=5338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=38029c86-2600-0000-f617-7937da140000 pid=5338->9d60ca2a-dbc0-5444-aaa2-510e538c2ee4 send: 15B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-01 14:58:29 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 84c60aae6337281f26785177548ae102fbb8d3ca1332062236e0100e404972cc

(this sample)

  
Delivery method
Distributed via web download

Comments