MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 892a42f0b3c9e054b2679db53c44d5eeee5afe2b647e2fc3f7b6c05f1b18aae4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 892a42f0b3c9e054b2679db53c44d5eeee5afe2b647e2fc3f7b6c05f1b18aae4
SHA3-384 hash: 0c599ca56e9d5f4d0b79d01b9d29cd3f46bbb1a5fa22f3832508b391ece19c2f5933c1c98077479ec1745ffa0ca91696
SHA1 hash: 6c270f9844691f469fca139949b3061e2bc83e50
MD5 hash: f14a0539ee9f1d7425b3d21035642930
humanhash: three-sad-nebraska-moon
File name:1.sh
Download: download sample
Signature Mirai
File size:2'217 bytes
First seen:2025-10-04 22:40:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iR/E2R2B9jRoHfRCGCxERHcAJRQ/7LRFWUBJRGx5RcbPRbgwR43P4x:iC2Y9jofiEiAJo7LqKs5mPCw+P4x
TLSH T13841839531C207B96CF1A86FB2FD4808B2FAB08A64C79F9498DC2BE6514DE54BC0574B
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.213.174.225/condi/main_x86n/an/aelf ua-wget
http://89.213.174.225/condi/main_mipsn/an/aelf ua-wget
http://89.213.174.225/condi/main_x86_64n/an/aelf ua-wget
http://89.213.174.225/condi/main_mpsln/an/aelf ua-wget
http://89.213.174.225/condi/main_armn/an/aelf ua-wget
http://89.213.174.225/condi/main_arm5n/an/aelf ua-wget
http://89.213.174.225/condi/main_arm6n/an/aelf ua-wget
http://89.213.174.225/condi/main_arm7n/an/aelf ua-wget
http://89.213.174.225/condi/main_ppcn/an/aelf ua-wget
http://89.213.174.225/condi/main_m68kn/an/aelf ua-wget
http://89.213.174.225/condi/main_sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-04T20:10:00Z UTC
Last seen:
2025-10-04T20:26:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=15b6bdbe-1600-0000-79a1-e2af140d0000 pid=3348 /usr/bin/sudo guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356 /tmp/sample.bin guuid=15b6bdbe-1600-0000-79a1-e2af140d0000 pid=3348->guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356 execve guuid=597c5bc2-1600-0000-79a1-e2af1e0d0000 pid=3358 /usr/bin/cp guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=597c5bc2-1600-0000-79a1-e2af1e0d0000 pid=3358 execve guuid=c25f11c8-1600-0000-79a1-e2af270d0000 pid=3367 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=c25f11c8-1600-0000-79a1-e2af270d0000 pid=3367 execve guuid=12e3bad5-1600-0000-79a1-e2af470d0000 pid=3399 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=12e3bad5-1600-0000-79a1-e2af470d0000 pid=3399 execve guuid=e26bb9e3-1600-0000-79a1-e2af600d0000 pid=3424 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=e26bb9e3-1600-0000-79a1-e2af600d0000 pid=3424 execve guuid=da082ee4-1600-0000-79a1-e2af620d0000 pid=3426 /tmp/main_x86 delete-file net guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=da082ee4-1600-0000-79a1-e2af620d0000 pid=3426 execve guuid=1ff77fe4-1600-0000-79a1-e2af650d0000 pid=3429 /usr/bin/rm guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=1ff77fe4-1600-0000-79a1-e2af650d0000 pid=3429 execve guuid=a074dce4-1600-0000-79a1-e2af680d0000 pid=3432 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=a074dce4-1600-0000-79a1-e2af680d0000 pid=3432 execve guuid=c6f8a92e-1700-0000-79a1-e2aff90d0000 pid=3577 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=c6f8a92e-1700-0000-79a1-e2aff90d0000 pid=3577 execve guuid=82c9ab3b-1700-0000-79a1-e2af080e0000 pid=3592 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=82c9ab3b-1700-0000-79a1-e2af080e0000 pid=3592 execve guuid=ff4c333c-1700-0000-79a1-e2af0a0e0000 pid=3594 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=ff4c333c-1700-0000-79a1-e2af0a0e0000 pid=3594 clone guuid=cba54e3d-1700-0000-79a1-e2af0e0e0000 pid=3598 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=cba54e3d-1700-0000-79a1-e2af0e0e0000 pid=3598 execve guuid=409bdd3d-1700-0000-79a1-e2af100e0000 pid=3600 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=409bdd3d-1700-0000-79a1-e2af100e0000 pid=3600 execve guuid=35cc8c4a-1700-0000-79a1-e2af2c0e0000 pid=3628 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=35cc8c4a-1700-0000-79a1-e2af2c0e0000 pid=3628 execve guuid=93888757-1700-0000-79a1-e2af4d0e0000 pid=3661 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=93888757-1700-0000-79a1-e2af4d0e0000 pid=3661 execve guuid=69ca0458-1700-0000-79a1-e2af4f0e0000 pid=3663 /tmp/main_x86_64 delete-file net guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=69ca0458-1700-0000-79a1-e2af4f0e0000 pid=3663 execve guuid=20524358-1700-0000-79a1-e2af510e0000 pid=3665 /usr/bin/rm guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=20524358-1700-0000-79a1-e2af510e0000 pid=3665 execve guuid=613cbc58-1700-0000-79a1-e2af530e0000 pid=3667 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=613cbc58-1700-0000-79a1-e2af530e0000 pid=3667 execve guuid=d2ac6b66-1700-0000-79a1-e2af710e0000 pid=3697 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=d2ac6b66-1700-0000-79a1-e2af710e0000 pid=3697 execve guuid=85081e75-1700-0000-79a1-e2af9c0e0000 pid=3740 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=85081e75-1700-0000-79a1-e2af9c0e0000 pid=3740 execve guuid=34d38e75-1700-0000-79a1-e2af9e0e0000 pid=3742 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=34d38e75-1700-0000-79a1-e2af9e0e0000 pid=3742 clone guuid=25637176-1700-0000-79a1-e2afa40e0000 pid=3748 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=25637176-1700-0000-79a1-e2afa40e0000 pid=3748 execve guuid=1c9ed976-1700-0000-79a1-e2afa80e0000 pid=3752 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=1c9ed976-1700-0000-79a1-e2afa80e0000 pid=3752 execve guuid=e823f282-1700-0000-79a1-e2afc00e0000 pid=3776 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=e823f282-1700-0000-79a1-e2afc00e0000 pid=3776 execve guuid=9aab778f-1700-0000-79a1-e2afeb0e0000 pid=3819 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=9aab778f-1700-0000-79a1-e2afeb0e0000 pid=3819 execve guuid=bcd6f98f-1700-0000-79a1-e2afee0e0000 pid=3822 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=bcd6f98f-1700-0000-79a1-e2afee0e0000 pid=3822 clone guuid=9417fd90-1700-0000-79a1-e2aff30e0000 pid=3827 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=9417fd90-1700-0000-79a1-e2aff30e0000 pid=3827 execve guuid=f98f7791-1700-0000-79a1-e2aff60e0000 pid=3830 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=f98f7791-1700-0000-79a1-e2aff60e0000 pid=3830 execve guuid=af8b6c9d-1700-0000-79a1-e2af160f0000 pid=3862 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=af8b6c9d-1700-0000-79a1-e2af160f0000 pid=3862 execve guuid=1beba8aa-1700-0000-79a1-e2af3a0f0000 pid=3898 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=1beba8aa-1700-0000-79a1-e2af3a0f0000 pid=3898 execve guuid=2bae38ab-1700-0000-79a1-e2af3c0f0000 pid=3900 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=2bae38ab-1700-0000-79a1-e2af3c0f0000 pid=3900 clone guuid=b53318ac-1700-0000-79a1-e2af3f0f0000 pid=3903 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=b53318ac-1700-0000-79a1-e2af3f0f0000 pid=3903 execve guuid=5117a8ac-1700-0000-79a1-e2af410f0000 pid=3905 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=5117a8ac-1700-0000-79a1-e2af410f0000 pid=3905 execve guuid=9cdf6ab8-1700-0000-79a1-e2af5e0f0000 pid=3934 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=9cdf6ab8-1700-0000-79a1-e2af5e0f0000 pid=3934 execve guuid=6cb23ec5-1700-0000-79a1-e2af860f0000 pid=3974 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=6cb23ec5-1700-0000-79a1-e2af860f0000 pid=3974 execve guuid=d8d6d5c5-1700-0000-79a1-e2af870f0000 pid=3975 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=d8d6d5c5-1700-0000-79a1-e2af870f0000 pid=3975 clone guuid=969684c8-1700-0000-79a1-e2af950f0000 pid=3989 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=969684c8-1700-0000-79a1-e2af950f0000 pid=3989 execve guuid=6dfac8c8-1700-0000-79a1-e2af960f0000 pid=3990 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=6dfac8c8-1700-0000-79a1-e2af960f0000 pid=3990 execve guuid=554bbed4-1700-0000-79a1-e2afbe0f0000 pid=4030 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=554bbed4-1700-0000-79a1-e2afbe0f0000 pid=4030 execve guuid=708d49e4-1700-0000-79a1-e2afe90f0000 pid=4073 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=708d49e4-1700-0000-79a1-e2afe90f0000 pid=4073 execve guuid=e0a6cbe4-1700-0000-79a1-e2afed0f0000 pid=4077 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=e0a6cbe4-1700-0000-79a1-e2afed0f0000 pid=4077 clone guuid=d53993e6-1700-0000-79a1-e2aff20f0000 pid=4082 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=d53993e6-1700-0000-79a1-e2aff20f0000 pid=4082 execve guuid=188501e7-1700-0000-79a1-e2aff50f0000 pid=4085 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=188501e7-1700-0000-79a1-e2aff50f0000 pid=4085 execve guuid=214926f2-1700-0000-79a1-e2af13100000 pid=4115 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=214926f2-1700-0000-79a1-e2af13100000 pid=4115 execve guuid=3aec4e01-1800-0000-79a1-e2af46100000 pid=4166 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=3aec4e01-1800-0000-79a1-e2af46100000 pid=4166 execve guuid=90d0c401-1800-0000-79a1-e2af47100000 pid=4167 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=90d0c401-1800-0000-79a1-e2af47100000 pid=4167 clone guuid=39c7b002-1800-0000-79a1-e2af4b100000 pid=4171 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=39c7b002-1800-0000-79a1-e2af4b100000 pid=4171 execve guuid=3a9a4703-1800-0000-79a1-e2af4f100000 pid=4175 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=3a9a4703-1800-0000-79a1-e2af4f100000 pid=4175 execve guuid=abdef50e-1800-0000-79a1-e2af69100000 pid=4201 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=abdef50e-1800-0000-79a1-e2af69100000 pid=4201 execve guuid=b6d4031d-1800-0000-79a1-e2af9d100000 pid=4253 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=b6d4031d-1800-0000-79a1-e2af9d100000 pid=4253 execve guuid=03a17f1d-1800-0000-79a1-e2af9f100000 pid=4255 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=03a17f1d-1800-0000-79a1-e2af9f100000 pid=4255 clone guuid=bedecd1e-1800-0000-79a1-e2afa4100000 pid=4260 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=bedecd1e-1800-0000-79a1-e2afa4100000 pid=4260 execve guuid=8223361f-1800-0000-79a1-e2afa6100000 pid=4262 /usr/bin/wget net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=8223361f-1800-0000-79a1-e2afa6100000 pid=4262 execve guuid=70ba362a-1800-0000-79a1-e2afcd100000 pid=4301 /usr/bin/curl net send-data write-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=70ba362a-1800-0000-79a1-e2afcd100000 pid=4301 execve guuid=1a734f37-1800-0000-79a1-e2aff7100000 pid=4343 /usr/bin/chmod guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=1a734f37-1800-0000-79a1-e2aff7100000 pid=4343 execve guuid=8bc9b137-1800-0000-79a1-e2aff9100000 pid=4345 /usr/bin/bash guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=8bc9b137-1800-0000-79a1-e2aff9100000 pid=4345 clone guuid=e7421c39-1800-0000-79a1-e2affe100000 pid=4350 /usr/bin/rm delete-file guuid=f0ef9cc1-1600-0000-79a1-e2af1c0d0000 pid=3356->guuid=e7421c39-1800-0000-79a1-e2affe100000 pid=4350 execve 1abdd55f-79cd-53ae-abf5-622946afe271 89.213.174.225:80 guuid=c25f11c8-1600-0000-79a1-e2af270d0000 pid=3367->1abdd55f-79cd-53ae-abf5-622946afe271 send: 143B guuid=12e3bad5-1600-0000-79a1-e2af470d0000 pid=3399->1abdd55f-79cd-53ae-abf5-622946afe271 send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=da082ee4-1600-0000-79a1-e2af620d0000 pid=3426->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=89566ae4-1600-0000-79a1-e2af630d0000 pid=3427 /tmp/main_x86 dns net send-data zombie guuid=da082ee4-1600-0000-79a1-e2af620d0000 pid=3426->guuid=89566ae4-1600-0000-79a1-e2af630d0000 pid=3427 clone guuid=89566ae4-1600-0000-79a1-e2af630d0000 pid=3427->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B d10c12a5-d848-547f-9d6b-7d0784427188 uraniumc2.ddns.net:1995 guuid=89566ae4-1600-0000-79a1-e2af630d0000 pid=3427->d10c12a5-d848-547f-9d6b-7d0784427188 send: 15B guuid=ea928ce4-1600-0000-79a1-e2af660d0000 pid=3430 /tmp/main_x86 guuid=89566ae4-1600-0000-79a1-e2af630d0000 pid=3427->guuid=ea928ce4-1600-0000-79a1-e2af660d0000 pid=3430 clone a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 uraniumc2.ddns.net:80 guuid=a074dce4-1600-0000-79a1-e2af680d0000 pid=3432->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 288B guuid=c6f8a92e-1700-0000-79a1-e2aff90d0000 pid=3577->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=409bdd3d-1700-0000-79a1-e2af100e0000 pid=3600->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 146B guuid=35cc8c4a-1700-0000-79a1-e2af2c0e0000 pid=3628->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 95B guuid=69ca0458-1700-0000-79a1-e2af4f0e0000 pid=3663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=791c3058-1700-0000-79a1-e2af500e0000 pid=3664 /tmp/main_x86_64 dns net send-data zombie guuid=69ca0458-1700-0000-79a1-e2af4f0e0000 pid=3663->guuid=791c3058-1700-0000-79a1-e2af500e0000 pid=3664 clone guuid=791c3058-1700-0000-79a1-e2af500e0000 pid=3664->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=791c3058-1700-0000-79a1-e2af500e0000 pid=3664->d10c12a5-d848-547f-9d6b-7d0784427188 send: 18B guuid=a6cc4958-1700-0000-79a1-e2af520e0000 pid=3666 /tmp/main_x86_64 guuid=791c3058-1700-0000-79a1-e2af500e0000 pid=3664->guuid=a6cc4958-1700-0000-79a1-e2af520e0000 pid=3666 clone guuid=613cbc58-1700-0000-79a1-e2af530e0000 pid=3667->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 144B guuid=d2ac6b66-1700-0000-79a1-e2af710e0000 pid=3697->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=1c9ed976-1700-0000-79a1-e2afa80e0000 pid=3752->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=e823f282-1700-0000-79a1-e2afc00e0000 pid=3776->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=f98f7791-1700-0000-79a1-e2aff60e0000 pid=3830->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 144B guuid=af8b6c9d-1700-0000-79a1-e2af160f0000 pid=3862->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=5117a8ac-1700-0000-79a1-e2af410f0000 pid=3905->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 144B guuid=9cdf6ab8-1700-0000-79a1-e2af5e0f0000 pid=3934->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=6dfac8c8-1700-0000-79a1-e2af960f0000 pid=3990->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 144B guuid=554bbed4-1700-0000-79a1-e2afbe0f0000 pid=4030->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=188501e7-1700-0000-79a1-e2aff50f0000 pid=4085->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=214926f2-1700-0000-79a1-e2af13100000 pid=4115->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B guuid=3a9a4703-1800-0000-79a1-e2af4f100000 pid=4175->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 144B guuid=abdef50e-1800-0000-79a1-e2af69100000 pid=4201->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 93B guuid=8223361f-1800-0000-79a1-e2afa6100000 pid=4262->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 143B guuid=70ba362a-1800-0000-79a1-e2afcd100000 pid=4301->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 92B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-04 22:41:35 UTC
File Type:
Text (Shell)
AV detection:
22 of 37 (59.46%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
uraniumc2.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 892a42f0b3c9e054b2679db53c44d5eeee5afe2b647e2fc3f7b6c05f1b18aae4

(this sample)

  
Delivery method
Distributed via web download

Comments