MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8555eff282e97266ce61c36f63a8c959f1ddbca46b45b4dc91cfe8733ba09e2a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 8555eff282e97266ce61c36f63a8c959f1ddbca46b45b4dc91cfe8733ba09e2a
SHA3-384 hash: 41c7b5ceb7ff1e66d6590e3ce9b4dde3279f86b5bfe343d9162cfa9d91980b7ef608a67c43cc0a24be3c354a7f706e17
SHA1 hash: a356b125f1fffa2cdcb2fe26fac195437d6c4d92
MD5 hash: a649d2baddfc4f64ddea083be5f06788
humanhash: potato-hamper-king-vegan
File name:1.sh
Download: download sample
Signature Mirai
File size:3'019 bytes
First seen:2025-09-12 10:15:25 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iXchmlXqnElXfCXlXjePlXaeazvZlXaYaFvjlX9NQ9z4gelXujclXPSvlXjejzqE:i2mlKElaXlKPlKfzvZlKlFvjltoz4ZlJ
TLSH T129514497233185756CEB7653FDF9DE1C3180A0911D9BBF08D6EC34A9A18CD8A3888E53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.229.191/hiddenbin/Space.arca6ec68635f2000d140eb6010d0133db3ec9170f1f73f752938f35fa165722dcd Miraielf mirai
http://160.187.229.191/hiddenbin/Space.x866619c1ca05935f567d8aa610a9a91ab297d09226ee196f6ca7f66288bbff3bb1 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.x86_643a60b1e61bf7498f19ec5151b203b526ed64cb0c666ddc1b5ccffb2ce20ff4c4 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.i6861d8804244fad816f6dac0d4538435467f210e2c5631c7f8fb5c48277b94afc45 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.mips987cc77bdb569bb8693e990d56a2d3a8f79e53ec580ef92ed5f71120c6122026 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.mips64n/an/aelf ua-wget
http://160.187.229.191/hiddenbin/Space.mpslc903653ebefa08080845123a3b2e1011d6318436de5012ac96491e727cea2f15 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.arm3d3c44ce46874dcf7147f04fc3f66477ad85aa0146e3880605a12630795eace0 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.arm5d9cb6aa3b5c9c952ee72dc75e946855079afcea380bf362ba13ec2e915aeac22 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.arm6767463d9d83c67006f32e92ba4f7332bb28568b7632867798041be58188fe9ed Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.arm7e8ec2a855b2b427d02e225cf7f2b5877dfd8beeb556bc5a590a137aa39968558 Miraielf mirai
http://160.187.229.191/hiddenbin/Space.ppc99969aef5a3338f8c9c25adb94e32679a89640d6c05e4ecd8321a7e78e9bf941 Miraielf mirai ua-wget
http://160.187.229.191/hiddenbin/Space.sparcn/an/aelf ua-wget
http://160.187.229.191/hiddenbin/Space.m68k48c5fa2872a9eb948bd41c836b3291de395afcf2ea9883bf0feb45b7ca05fd2d Miraielf mirai
http://160.187.229.191/hiddenbin/Space.sh40bc7b344a1c851ac386fcc2629daa6e48fdd67fafa061d2b7ecdb4d729bceb3c Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-12T08:00:00Z UTC
Last seen:
2025-09-12T08:00:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=88045f21-1e00-0000-731b-9ab7930b0000 pid=2963 /usr/bin/sudo guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970 /tmp/sample.bin guuid=88045f21-1e00-0000-731b-9ab7930b0000 pid=2963->guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970 execve guuid=5795c124-1e00-0000-731b-9ab79e0b0000 pid=2974 /usr/bin/cp guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=5795c124-1e00-0000-731b-9ab79e0b0000 pid=2974 execve guuid=9d7dc828-1e00-0000-731b-9ab7a20b0000 pid=2978 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=9d7dc828-1e00-0000-731b-9ab7a20b0000 pid=2978 execve guuid=01a65a6a-1e00-0000-731b-9ab73d0c0000 pid=3133 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=01a65a6a-1e00-0000-731b-9ab73d0c0000 pid=3133 execve guuid=37544aad-1e00-0000-731b-9ab7b70c0000 pid=3255 /usr/bin/cat guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=37544aad-1e00-0000-731b-9ab7b70c0000 pid=3255 execve guuid=23a4a9ad-1e00-0000-731b-9ab7ba0c0000 pid=3258 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=23a4a9ad-1e00-0000-731b-9ab7ba0c0000 pid=3258 execve guuid=a759f9ad-1e00-0000-731b-9ab7bc0c0000 pid=3260 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=a759f9ad-1e00-0000-731b-9ab7bc0c0000 pid=3260 clone guuid=94e6f8af-1e00-0000-731b-9ab7bf0c0000 pid=3263 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=94e6f8af-1e00-0000-731b-9ab7bf0c0000 pid=3263 execve guuid=c7dcb9d7-1e00-0000-731b-9ab70d0d0000 pid=3341 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=c7dcb9d7-1e00-0000-731b-9ab70d0d0000 pid=3341 execve guuid=05529f00-1f00-0000-731b-9ab7730d0000 pid=3443 /usr/bin/cat guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=05529f00-1f00-0000-731b-9ab7730d0000 pid=3443 execve guuid=e2305401-1f00-0000-731b-9ab7760d0000 pid=3446 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=e2305401-1f00-0000-731b-9ab7760d0000 pid=3446 execve guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448 execve guuid=b6b59e2e-2000-0000-731b-9ab752100000 pid=4178 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=b6b59e2e-2000-0000-731b-9ab752100000 pid=4178 execve guuid=b2562559-2000-0000-731b-9ab7d2100000 pid=4306 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=b2562559-2000-0000-731b-9ab7d2100000 pid=4306 execve guuid=1cd20b82-2000-0000-731b-9ab748110000 pid=4424 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=1cd20b82-2000-0000-731b-9ab748110000 pid=4424 clone guuid=80ec3082-2000-0000-731b-9ab749110000 pid=4425 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=80ec3082-2000-0000-731b-9ab749110000 pid=4425 execve guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429 execve guuid=cf48b1af-2100-0000-731b-9ab783140000 pid=5251 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=cf48b1af-2100-0000-731b-9ab783140000 pid=5251 execve guuid=0bbb15fe-2100-0000-731b-9ab78c140000 pid=5260 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=0bbb15fe-2100-0000-731b-9ab78c140000 pid=5260 execve guuid=bab9ba29-2200-0000-731b-9ab78d140000 pid=5261 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=bab9ba29-2200-0000-731b-9ab78d140000 pid=5261 clone guuid=0fcadc29-2200-0000-731b-9ab78e140000 pid=5262 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=0fcadc29-2200-0000-731b-9ab78e140000 pid=5262 execve guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263 execve guuid=b9080c57-2300-0000-731b-9ab79c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=b9080c57-2300-0000-731b-9ab79c140000 pid=5276 execve guuid=b902c57d-2300-0000-731b-9ab79d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=b902c57d-2300-0000-731b-9ab79d140000 pid=5277 execve guuid=170e28a6-2300-0000-731b-9ab79f140000 pid=5279 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=170e28a6-2300-0000-731b-9ab79f140000 pid=5279 clone guuid=2cf146a6-2300-0000-731b-9ab7a0140000 pid=5280 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=2cf146a6-2300-0000-731b-9ab7a0140000 pid=5280 execve guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281 execve guuid=3786e2d2-2400-0000-731b-9ab7c6140000 pid=5318 /usr/bin/wget net send-data guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=3786e2d2-2400-0000-731b-9ab7c6140000 pid=5318 execve guuid=be8f5cee-2400-0000-731b-9ab7c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=be8f5cee-2400-0000-731b-9ab7c7140000 pid=5319 execve guuid=e0d7be09-2500-0000-731b-9ab7c8140000 pid=5320 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=e0d7be09-2500-0000-731b-9ab7c8140000 pid=5320 clone guuid=7ce2f109-2500-0000-731b-9ab7c9140000 pid=5321 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=7ce2f109-2500-0000-731b-9ab7c9140000 pid=5321 execve guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322 execve guuid=a3de5537-2600-0000-731b-9ab7d0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=a3de5537-2600-0000-731b-9ab7d0140000 pid=5328 execve guuid=04e5885e-2600-0000-731b-9ab7d1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=04e5885e-2600-0000-731b-9ab7d1140000 pid=5329 execve guuid=9b16f287-2600-0000-731b-9ab7d2140000 pid=5330 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=9b16f287-2600-0000-731b-9ab7d2140000 pid=5330 clone guuid=64a71188-2600-0000-731b-9ab7d3140000 pid=5331 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=64a71188-2600-0000-731b-9ab7d3140000 pid=5331 execve guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332 execve guuid=00688eb4-2700-0000-731b-9ab7da140000 pid=5338 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=00688eb4-2700-0000-731b-9ab7da140000 pid=5338 execve guuid=04a32adb-2700-0000-731b-9ab7db140000 pid=5339 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=04a32adb-2700-0000-731b-9ab7db140000 pid=5339 execve guuid=d27bb002-2800-0000-731b-9ab7dc140000 pid=5340 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=d27bb002-2800-0000-731b-9ab7dc140000 pid=5340 clone guuid=3df5d402-2800-0000-731b-9ab7dd140000 pid=5341 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=3df5d402-2800-0000-731b-9ab7dd140000 pid=5341 execve guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342 execve guuid=07b9512f-2900-0000-731b-9ab7e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=07b9512f-2900-0000-731b-9ab7e4140000 pid=5348 execve guuid=ef84d055-2900-0000-731b-9ab7e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=ef84d055-2900-0000-731b-9ab7e5140000 pid=5349 execve guuid=f8c20f7f-2900-0000-731b-9ab7e6140000 pid=5350 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=f8c20f7f-2900-0000-731b-9ab7e6140000 pid=5350 clone guuid=b6872d7f-2900-0000-731b-9ab7e7140000 pid=5351 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=b6872d7f-2900-0000-731b-9ab7e7140000 pid=5351 execve guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352 execve guuid=c600ceab-2a00-0000-731b-9ab7ee140000 pid=5358 /usr/bin/wget net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=c600ceab-2a00-0000-731b-9ab7ee140000 pid=5358 execve guuid=9c8485d2-2a00-0000-731b-9ab7ef140000 pid=5359 /usr/bin/curl net send-data write-file guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=9c8485d2-2a00-0000-731b-9ab7ef140000 pid=5359 execve guuid=fd20f8f9-2a00-0000-731b-9ab7f0140000 pid=5360 /usr/bin/bash guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=fd20f8f9-2a00-0000-731b-9ab7f0140000 pid=5360 clone guuid=73af1ffa-2a00-0000-731b-9ab7f1140000 pid=5361 /usr/bin/chmod guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=73af1ffa-2a00-0000-731b-9ab7f1140000 pid=5361 execve guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362 /tmp/Space net guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362 execve guuid=ae2b8427-2c00-0000-731b-9ab702150000 pid=5378 /usr/bin/wget net send-data guuid=91249923-1e00-0000-731b-9ab79a0b0000 pid=2970->guuid=ae2b8427-2c00-0000-731b-9ab702150000 pid=5378 execve 691f847f-96f1-5392-aa00-131c6583afa7 160.187.229.191:80 guuid=9d7dc828-1e00-0000-731b-9ab7a20b0000 pid=2978->691f847f-96f1-5392-aa00-131c6583afa7 send: 149B guuid=01a65a6a-1e00-0000-731b-9ab73d0c0000 pid=3133->691f847f-96f1-5392-aa00-131c6583afa7 send: 98B guuid=94e6f8af-1e00-0000-731b-9ab7bf0c0000 pid=3263->691f847f-96f1-5392-aa00-131c6583afa7 send: 149B guuid=c7dcb9d7-1e00-0000-731b-9ab70d0d0000 pid=3341->691f847f-96f1-5392-aa00-131c6583afa7 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=236c3602-1f00-0000-731b-9ab77b0d0000 pid=3451 /tmp/Space guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448->guuid=236c3602-1f00-0000-731b-9ab77b0d0000 pid=3451 clone guuid=44338a2e-2000-0000-731b-9ab750100000 pid=4176 /tmp/Space guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448->guuid=44338a2e-2000-0000-731b-9ab750100000 pid=4176 clone guuid=5b2a932e-2000-0000-731b-9ab751100000 pid=4177 /tmp/Space net zombie guuid=17afa301-1f00-0000-731b-9ab7780d0000 pid=3448->guuid=5b2a932e-2000-0000-731b-9ab751100000 pid=4177 clone guuid=728c4102-1f00-0000-731b-9ab77c0d0000 pid=3452 /tmp/Space guuid=236c3602-1f00-0000-731b-9ab77b0d0000 pid=3451->guuid=728c4102-1f00-0000-731b-9ab77c0d0000 pid=3452 clone guuid=fd354b02-1f00-0000-731b-9ab77d0d0000 pid=3453 /tmp/Space net zombie guuid=236c3602-1f00-0000-731b-9ab77b0d0000 pid=3451->guuid=fd354b02-1f00-0000-731b-9ab77d0d0000 pid=3453 clone 9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d 160.187.229.191:3778 guuid=fd354b02-1f00-0000-731b-9ab77d0d0000 pid=3453->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=5b2a932e-2000-0000-731b-9ab751100000 pid=4177->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=b6b59e2e-2000-0000-731b-9ab752100000 pid=4178->691f847f-96f1-5392-aa00-131c6583afa7 send: 152B guuid=b2562559-2000-0000-731b-9ab7d2100000 pid=4306->691f847f-96f1-5392-aa00-131c6583afa7 send: 101B guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6d5c5383-2000-0000-731b-9ab74e110000 pid=4430 /tmp/Space guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429->guuid=6d5c5383-2000-0000-731b-9ab74e110000 pid=4430 clone guuid=75d08faf-2100-0000-731b-9ab781140000 pid=5249 /tmp/Space guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429->guuid=75d08faf-2100-0000-731b-9ab781140000 pid=5249 clone guuid=809b9daf-2100-0000-731b-9ab782140000 pid=5250 /tmp/Space net zombie guuid=4ec19e82-2000-0000-731b-9ab74d110000 pid=4429->guuid=809b9daf-2100-0000-731b-9ab782140000 pid=5250 clone guuid=ad265e83-2000-0000-731b-9ab74f110000 pid=4431 /tmp/Space guuid=6d5c5383-2000-0000-731b-9ab74e110000 pid=4430->guuid=ad265e83-2000-0000-731b-9ab74f110000 pid=4431 clone guuid=9e4c6483-2000-0000-731b-9ab750110000 pid=4432 /tmp/Space net zombie guuid=6d5c5383-2000-0000-731b-9ab74e110000 pid=4430->guuid=9e4c6483-2000-0000-731b-9ab750110000 pid=4432 clone guuid=9e4c6483-2000-0000-731b-9ab750110000 pid=4432->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=809b9daf-2100-0000-731b-9ab782140000 pid=5250->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=cf48b1af-2100-0000-731b-9ab783140000 pid=5251->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B guuid=0bbb15fe-2100-0000-731b-9ab78c140000 pid=5260->691f847f-96f1-5392-aa00-131c6583afa7 send: 99B guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c753c12a-2200-0000-731b-9ab790140000 pid=5264 /tmp/Space guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263->guuid=c753c12a-2200-0000-731b-9ab790140000 pid=5264 clone guuid=e91df956-2300-0000-731b-9ab79a140000 pid=5274 /tmp/Space guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263->guuid=e91df956-2300-0000-731b-9ab79a140000 pid=5274 clone guuid=236dfd56-2300-0000-731b-9ab79b140000 pid=5275 /tmp/Space net zombie guuid=865a382a-2200-0000-731b-9ab78f140000 pid=5263->guuid=236dfd56-2300-0000-731b-9ab79b140000 pid=5275 clone guuid=d8e9c62a-2200-0000-731b-9ab791140000 pid=5265 /tmp/Space guuid=c753c12a-2200-0000-731b-9ab790140000 pid=5264->guuid=d8e9c62a-2200-0000-731b-9ab791140000 pid=5265 clone guuid=799ecd2a-2200-0000-731b-9ab792140000 pid=5266 /tmp/Space net zombie guuid=c753c12a-2200-0000-731b-9ab790140000 pid=5264->guuid=799ecd2a-2200-0000-731b-9ab792140000 pid=5266 clone guuid=799ecd2a-2200-0000-731b-9ab792140000 pid=5266->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=236dfd56-2300-0000-731b-9ab79b140000 pid=5275->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=b9080c57-2300-0000-731b-9ab79c140000 pid=5276->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B guuid=b902c57d-2300-0000-731b-9ab79d140000 pid=5277->691f847f-96f1-5392-aa00-131c6583afa7 send: 99B guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=705a00a7-2300-0000-731b-9ab7a2140000 pid=5282 /tmp/Space guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281->guuid=705a00a7-2300-0000-731b-9ab7a2140000 pid=5282 clone guuid=4440ccd2-2400-0000-731b-9ab7c4140000 pid=5316 /tmp/Space guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281->guuid=4440ccd2-2400-0000-731b-9ab7c4140000 pid=5316 clone guuid=d455d2d2-2400-0000-731b-9ab7c5140000 pid=5317 /tmp/Space net zombie guuid=96cf8ba6-2300-0000-731b-9ab7a1140000 pid=5281->guuid=d455d2d2-2400-0000-731b-9ab7c5140000 pid=5317 clone guuid=2c2306a7-2300-0000-731b-9ab7a3140000 pid=5283 /tmp/Space guuid=705a00a7-2300-0000-731b-9ab7a2140000 pid=5282->guuid=2c2306a7-2300-0000-731b-9ab7a3140000 pid=5283 clone guuid=ded409a7-2300-0000-731b-9ab7a4140000 pid=5284 /tmp/Space net zombie guuid=705a00a7-2300-0000-731b-9ab7a2140000 pid=5282->guuid=ded409a7-2300-0000-731b-9ab7a4140000 pid=5284 clone guuid=ded409a7-2300-0000-731b-9ab7a4140000 pid=5284->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=d455d2d2-2400-0000-731b-9ab7c5140000 pid=5317->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=3786e2d2-2400-0000-731b-9ab7c6140000 pid=5318->691f847f-96f1-5392-aa00-131c6583afa7 send: 152B guuid=be8f5cee-2400-0000-731b-9ab7c7140000 pid=5319->691f847f-96f1-5392-aa00-131c6583afa7 send: 101B guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=86ad290b-2500-0000-731b-9ab7cb140000 pid=5323 /tmp/Space guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322->guuid=86ad290b-2500-0000-731b-9ab7cb140000 pid=5323 clone guuid=da134037-2600-0000-731b-9ab7ce140000 pid=5326 /tmp/Space guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322->guuid=da134037-2600-0000-731b-9ab7ce140000 pid=5326 clone guuid=3cea4837-2600-0000-731b-9ab7cf140000 pid=5327 /tmp/Space net zombie guuid=daca680a-2500-0000-731b-9ab7ca140000 pid=5322->guuid=3cea4837-2600-0000-731b-9ab7cf140000 pid=5327 clone guuid=7944310b-2500-0000-731b-9ab7cc140000 pid=5324 /tmp/Space guuid=86ad290b-2500-0000-731b-9ab7cb140000 pid=5323->guuid=7944310b-2500-0000-731b-9ab7cc140000 pid=5324 clone guuid=29b3360b-2500-0000-731b-9ab7cd140000 pid=5325 /tmp/Space net zombie guuid=86ad290b-2500-0000-731b-9ab7cb140000 pid=5323->guuid=29b3360b-2500-0000-731b-9ab7cd140000 pid=5325 clone guuid=29b3360b-2500-0000-731b-9ab7cd140000 pid=5325->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=3cea4837-2600-0000-731b-9ab7cf140000 pid=5327->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=a3de5537-2600-0000-731b-9ab7d0140000 pid=5328->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B guuid=04e5885e-2600-0000-731b-9ab7d1140000 pid=5329->691f847f-96f1-5392-aa00-131c6583afa7 send: 99B guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=22a3ca88-2600-0000-731b-9ab7d5140000 pid=5333 /tmp/Space guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332->guuid=22a3ca88-2600-0000-731b-9ab7d5140000 pid=5333 clone guuid=b2ff7ab4-2700-0000-731b-9ab7d8140000 pid=5336 /tmp/Space guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332->guuid=b2ff7ab4-2700-0000-731b-9ab7d8140000 pid=5336 clone guuid=22cc82b4-2700-0000-731b-9ab7d9140000 pid=5337 /tmp/Space net zombie guuid=f76c5988-2600-0000-731b-9ab7d4140000 pid=5332->guuid=22cc82b4-2700-0000-731b-9ab7d9140000 pid=5337 clone guuid=5078d588-2600-0000-731b-9ab7d6140000 pid=5334 /tmp/Space guuid=22a3ca88-2600-0000-731b-9ab7d5140000 pid=5333->guuid=5078d588-2600-0000-731b-9ab7d6140000 pid=5334 clone guuid=7827da88-2600-0000-731b-9ab7d7140000 pid=5335 /tmp/Space net zombie guuid=22a3ca88-2600-0000-731b-9ab7d5140000 pid=5333->guuid=7827da88-2600-0000-731b-9ab7d7140000 pid=5335 clone guuid=7827da88-2600-0000-731b-9ab7d7140000 pid=5335->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=22cc82b4-2700-0000-731b-9ab7d9140000 pid=5337->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=00688eb4-2700-0000-731b-9ab7da140000 pid=5338->691f847f-96f1-5392-aa00-131c6583afa7 send: 149B guuid=04a32adb-2700-0000-731b-9ab7db140000 pid=5339->691f847f-96f1-5392-aa00-131c6583afa7 send: 98B guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4ee19603-2800-0000-731b-9ab7df140000 pid=5343 /tmp/Space guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342->guuid=4ee19603-2800-0000-731b-9ab7df140000 pid=5343 clone guuid=05053e2f-2900-0000-731b-9ab7e2140000 pid=5346 /tmp/Space guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342->guuid=05053e2f-2900-0000-731b-9ab7e2140000 pid=5346 clone guuid=7f04432f-2900-0000-731b-9ab7e3140000 pid=5347 /tmp/Space net zombie guuid=86f02703-2800-0000-731b-9ab7de140000 pid=5342->guuid=7f04432f-2900-0000-731b-9ab7e3140000 pid=5347 clone guuid=18b29c03-2800-0000-731b-9ab7e0140000 pid=5344 /tmp/Space guuid=4ee19603-2800-0000-731b-9ab7df140000 pid=5343->guuid=18b29c03-2800-0000-731b-9ab7e0140000 pid=5344 clone guuid=ae7ba003-2800-0000-731b-9ab7e1140000 pid=5345 /tmp/Space net zombie guuid=4ee19603-2800-0000-731b-9ab7df140000 pid=5343->guuid=ae7ba003-2800-0000-731b-9ab7e1140000 pid=5345 clone guuid=ae7ba003-2800-0000-731b-9ab7e1140000 pid=5345->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=7f04432f-2900-0000-731b-9ab7e3140000 pid=5347->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=07b9512f-2900-0000-731b-9ab7e4140000 pid=5348->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B guuid=ef84d055-2900-0000-731b-9ab7e5140000 pid=5349->691f847f-96f1-5392-aa00-131c6583afa7 send: 99B guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1bdde67f-2900-0000-731b-9ab7e9140000 pid=5353 /tmp/Space guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352->guuid=1bdde67f-2900-0000-731b-9ab7e9140000 pid=5353 clone guuid=69c5bbab-2a00-0000-731b-9ab7ec140000 pid=5356 /tmp/Space guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352->guuid=69c5bbab-2a00-0000-731b-9ab7ec140000 pid=5356 clone guuid=611dc2ab-2a00-0000-731b-9ab7ed140000 pid=5357 /tmp/Space net zombie guuid=4e52727f-2900-0000-731b-9ab7e8140000 pid=5352->guuid=611dc2ab-2a00-0000-731b-9ab7ed140000 pid=5357 clone guuid=9c0aef7f-2900-0000-731b-9ab7ea140000 pid=5354 /tmp/Space guuid=1bdde67f-2900-0000-731b-9ab7e9140000 pid=5353->guuid=9c0aef7f-2900-0000-731b-9ab7ea140000 pid=5354 clone guuid=3443f57f-2900-0000-731b-9ab7eb140000 pid=5355 /tmp/Space net zombie guuid=1bdde67f-2900-0000-731b-9ab7e9140000 pid=5353->guuid=3443f57f-2900-0000-731b-9ab7eb140000 pid=5355 clone guuid=3443f57f-2900-0000-731b-9ab7eb140000 pid=5355->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=611dc2ab-2a00-0000-731b-9ab7ed140000 pid=5357->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=c600ceab-2a00-0000-731b-9ab7ee140000 pid=5358->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B guuid=9c8485d2-2a00-0000-731b-9ab7ef140000 pid=5359->691f847f-96f1-5392-aa00-131c6583afa7 send: 99B guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e2b01afb-2a00-0000-731b-9ab7f3140000 pid=5363 /tmp/Space guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362->guuid=e2b01afb-2a00-0000-731b-9ab7f3140000 pid=5363 clone guuid=5b947327-2c00-0000-731b-9ab700150000 pid=5376 /tmp/Space guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362->guuid=5b947327-2c00-0000-731b-9ab700150000 pid=5376 clone guuid=c39a7827-2c00-0000-731b-9ab701150000 pid=5377 /tmp/Space net zombie guuid=548680fa-2a00-0000-731b-9ab7f2140000 pid=5362->guuid=c39a7827-2c00-0000-731b-9ab701150000 pid=5377 clone guuid=44eb21fb-2a00-0000-731b-9ab7f4140000 pid=5364 /tmp/Space guuid=e2b01afb-2a00-0000-731b-9ab7f3140000 pid=5363->guuid=44eb21fb-2a00-0000-731b-9ab7f4140000 pid=5364 clone guuid=0f9229fb-2a00-0000-731b-9ab7f5140000 pid=5365 /tmp/Space net zombie guuid=e2b01afb-2a00-0000-731b-9ab7f3140000 pid=5363->guuid=0f9229fb-2a00-0000-731b-9ab7f5140000 pid=5365 clone guuid=0f9229fb-2a00-0000-731b-9ab7f5140000 pid=5365->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=c39a7827-2c00-0000-731b-9ab701150000 pid=5377->9d6d6a3c-5574-5ede-8f63-cbdd9e72c47d con guuid=ae2b8427-2c00-0000-731b-9ab702150000 pid=5378->691f847f-96f1-5392-aa00-131c6583afa7 send: 150B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-12 08:40:27 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8555eff282e97266ce61c36f63a8c959f1ddbca46b45b4dc91cfe8733ba09e2a

(this sample)

  
Delivery method
Distributed via web download

Comments