MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92fc8f2ded05418117b46fe8701f3a414c7b1b8372ca26165f2b062c59a72f6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 92fc8f2ded05418117b46fe8701f3a414c7b1b8372ca26165f2b062c59a72f6d
SHA3-384 hash: 2ed094ba34850b41d639cdd484503e1e8af340afcfd3e36c877adf4ba1b3857045bff17cbc2702b53b687271777844c3
SHA1 hash: 8c2ab7de2490e18bcc4102d0bb26b93e8bf0bb94
MD5 hash: f3d7ec7bbe69bf82fb48c68236d09d20
humanhash: two-december-coffee-twelve
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'007 bytes
First seen:2025-10-24 12:14:06 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iCt79t7N7hCtot6GCtgQtzPCt4tKWCtmtoUCt7mt7o7UCtfnt3bCttt9RCtqtcgn:iA7n7N7hA66GAgCzPAqKWA0oUA707o7I
TLSH T1FC5183C541546E341CABEA2BA677822830C3B06298EB6F95DBD4AEE0475EE147780F53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://192.142.10.124/hiddenbin/boatnet.x8645cd3b09f34adf3d5cd1a10fb4716145f7e9f78324af5da3ff8267314fd5aacb Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.mips5471e26e2fac7d56e47fefd5d0ec4cc4df049b4d9668b893b842f0bb8cef69f5 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.arc0b3509bfea82c3c2b1032c315cbe2f08a21ab30df64d03b89d0909aa05a09348 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.i46824a2379d625b8269501babe0eac3dd5c5fe04b841c869cf13d0a8688d68f180b Miraielf mirai ua-wget
http://192.142.10.124/hiddenbin/boatnet.i6868159ebce3beea97a0df4d558a67077a123960f097e66806a883a58536e8a5415 Miraielf mirai ua-wget
http://192.142.10.124/hiddenbin/boatnet.x86_642173c740c4d6dec7d6e99d595253360f3fca6eeeb2f248ec4b6e1fb38c042bb6 Miraielf mirai ua-wget
http://192.142.10.124/hiddenbin/boatnet.mpsl61a1dbc1043be77a8167a7f76548aeccb8e8e89258ff59877289670a037552d6 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.armbc9b09ac7beebdee4f39ee8207fa0b57202d39c8e9fe158eb8006a2270e505b1 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.arm50e436461207c53c2bfb69bd684a439ddbb65dd44d15a6c5ecb7f092e60817433 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.arm66aefcb35569d5a6f03ca744b1a8197b85e38293f3506d5f520d734a72a075b38 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.arm70e436461207c53c2bfb69bd684a439ddbb65dd44d15a6c5ecb7f092e60817433 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.ppc051790796751e97ee60e75201bc1358b6b553042da965e26bd39d376e1a26b0b Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.spce1962626e0cdc9c3464920387f4e80039d6131b730098550131de534d135f586 Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.m68k7560349da3de161e8a2c8d488f24d5ea4f72e1c54b062207e6c74e2cb45ea42b Miraimirai opendir
http://192.142.10.124/hiddenbin/boatnet.sh4365a69936b75809e9ca965ccb4d8932f1568f4ec5db9349534079074e69a3ce4 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-24T11:08:00Z UTC
Last seen:
2025-10-24T12:05:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=fe008d2a-1800-0000-7d29-5624b80c0000 pid=3256 /usr/bin/sudo guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264 /tmp/sample.bin guuid=fe008d2a-1800-0000-7d29-5624b80c0000 pid=3256->guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264 execve guuid=75d6372d-1800-0000-7d29-5624c30c0000 pid=3267 /usr/bin/cp guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=75d6372d-1800-0000-7d29-5624c30c0000 pid=3267 execve guuid=0ac7fc32-1800-0000-7d29-5624ce0c0000 pid=3278 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=0ac7fc32-1800-0000-7d29-5624ce0c0000 pid=3278 execve guuid=6296dc76-1800-0000-7d29-5624740d0000 pid=3444 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=6296dc76-1800-0000-7d29-5624740d0000 pid=3444 execve guuid=b5bcf97e-1800-0000-7d29-56248f0d0000 pid=3471 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=b5bcf97e-1800-0000-7d29-56248f0d0000 pid=3471 execve guuid=a4e9497f-1800-0000-7d29-5624910d0000 pid=3473 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=a4e9497f-1800-0000-7d29-5624910d0000 pid=3473 execve guuid=2dea877f-1800-0000-7d29-5624930d0000 pid=3475 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=2dea877f-1800-0000-7d29-5624930d0000 pid=3475 clone guuid=f2b6b17f-1800-0000-7d29-5624950d0000 pid=3477 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=f2b6b17f-1800-0000-7d29-5624950d0000 pid=3477 execve guuid=0a865883-1800-0000-7d29-5624a20d0000 pid=3490 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=0a865883-1800-0000-7d29-5624a20d0000 pid=3490 execve guuid=9b20ae87-1800-0000-7d29-5624a80d0000 pid=3496 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=9b20ae87-1800-0000-7d29-5624a80d0000 pid=3496 execve guuid=044ffa87-1800-0000-7d29-5624a90d0000 pid=3497 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=044ffa87-1800-0000-7d29-5624a90d0000 pid=3497 execve guuid=91ac3988-1800-0000-7d29-5624aa0d0000 pid=3498 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=91ac3988-1800-0000-7d29-5624aa0d0000 pid=3498 clone guuid=e5b45c88-1800-0000-7d29-5624ab0d0000 pid=3499 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=e5b45c88-1800-0000-7d29-5624ab0d0000 pid=3499 execve guuid=3f81168c-1800-0000-7d29-5624b60d0000 pid=3510 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=3f81168c-1800-0000-7d29-5624b60d0000 pid=3510 execve guuid=9c4e9791-1800-0000-7d29-5624be0d0000 pid=3518 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=9c4e9791-1800-0000-7d29-5624be0d0000 pid=3518 execve guuid=e02d1592-1800-0000-7d29-5624c10d0000 pid=3521 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=e02d1592-1800-0000-7d29-5624c10d0000 pid=3521 execve guuid=9d425292-1800-0000-7d29-5624c30d0000 pid=3523 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=9d425292-1800-0000-7d29-5624c30d0000 pid=3523 clone guuid=cadb7d92-1800-0000-7d29-5624c40d0000 pid=3524 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=cadb7d92-1800-0000-7d29-5624c40d0000 pid=3524 execve guuid=b14c2e96-1800-0000-7d29-5624ce0d0000 pid=3534 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=b14c2e96-1800-0000-7d29-5624ce0d0000 pid=3534 execve guuid=bfcd789a-1800-0000-7d29-5624d80d0000 pid=3544 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=bfcd789a-1800-0000-7d29-5624d80d0000 pid=3544 execve guuid=34a9d09a-1800-0000-7d29-5624d90d0000 pid=3545 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=34a9d09a-1800-0000-7d29-5624d90d0000 pid=3545 execve guuid=4bd7259b-1800-0000-7d29-5624da0d0000 pid=3546 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=4bd7259b-1800-0000-7d29-5624da0d0000 pid=3546 clone guuid=dbae4c9b-1800-0000-7d29-5624db0d0000 pid=3547 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=dbae4c9b-1800-0000-7d29-5624db0d0000 pid=3547 execve guuid=c8aa9e9f-1800-0000-7d29-5624e90d0000 pid=3561 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=c8aa9e9f-1800-0000-7d29-5624e90d0000 pid=3561 execve guuid=8f5a43a5-1800-0000-7d29-5624fd0d0000 pid=3581 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=8f5a43a5-1800-0000-7d29-5624fd0d0000 pid=3581 execve guuid=df409fa5-1800-0000-7d29-5624ff0d0000 pid=3583 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=df409fa5-1800-0000-7d29-5624ff0d0000 pid=3583 execve guuid=f99fe6a5-1800-0000-7d29-5624000e0000 pid=3584 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=f99fe6a5-1800-0000-7d29-5624000e0000 pid=3584 clone guuid=1b080fa6-1800-0000-7d29-5624010e0000 pid=3585 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=1b080fa6-1800-0000-7d29-5624010e0000 pid=3585 execve guuid=7d2d2ba9-1800-0000-7d29-56240a0e0000 pid=3594 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=7d2d2ba9-1800-0000-7d29-56240a0e0000 pid=3594 execve guuid=a16e0cad-1800-0000-7d29-5624170e0000 pid=3607 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=a16e0cad-1800-0000-7d29-5624170e0000 pid=3607 execve guuid=cab29aad-1800-0000-7d29-5624190e0000 pid=3609 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=cab29aad-1800-0000-7d29-5624190e0000 pid=3609 execve guuid=a256f9ad-1800-0000-7d29-56241b0e0000 pid=3611 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=a256f9ad-1800-0000-7d29-56241b0e0000 pid=3611 clone guuid=56454fae-1800-0000-7d29-56241d0e0000 pid=3613 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=56454fae-1800-0000-7d29-56241d0e0000 pid=3613 execve guuid=b1196ab2-1800-0000-7d29-5624290e0000 pid=3625 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=b1196ab2-1800-0000-7d29-5624290e0000 pid=3625 execve guuid=d24457b6-1800-0000-7d29-5624350e0000 pid=3637 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=d24457b6-1800-0000-7d29-5624350e0000 pid=3637 execve guuid=bc69aab6-1800-0000-7d29-5624370e0000 pid=3639 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=bc69aab6-1800-0000-7d29-5624370e0000 pid=3639 execve guuid=272e04b7-1800-0000-7d29-5624380e0000 pid=3640 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=272e04b7-1800-0000-7d29-5624380e0000 pid=3640 clone guuid=db752fb7-1800-0000-7d29-56243a0e0000 pid=3642 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=db752fb7-1800-0000-7d29-56243a0e0000 pid=3642 execve guuid=47bf36ba-1800-0000-7d29-5624420e0000 pid=3650 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=47bf36ba-1800-0000-7d29-5624420e0000 pid=3650 execve guuid=78b282be-1800-0000-7d29-5624430e0000 pid=3651 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=78b282be-1800-0000-7d29-5624430e0000 pid=3651 execve guuid=e73cb0dc-1800-0000-7d29-5624720e0000 pid=3698 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=e73cb0dc-1800-0000-7d29-5624720e0000 pid=3698 execve guuid=80c51cdd-1800-0000-7d29-5624730e0000 pid=3699 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=80c51cdd-1800-0000-7d29-5624730e0000 pid=3699 clone guuid=79674add-1800-0000-7d29-5624740e0000 pid=3700 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=79674add-1800-0000-7d29-5624740e0000 pid=3700 execve guuid=2205fbe1-1800-0000-7d29-56247d0e0000 pid=3709 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=2205fbe1-1800-0000-7d29-56247d0e0000 pid=3709 execve guuid=73e10ce8-1800-0000-7d29-5624850e0000 pid=3717 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=73e10ce8-1800-0000-7d29-5624850e0000 pid=3717 execve guuid=32aad6f0-1800-0000-7d29-5624890e0000 pid=3721 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=32aad6f0-1800-0000-7d29-5624890e0000 pid=3721 execve guuid=417e7ff1-1800-0000-7d29-56248a0e0000 pid=3722 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=417e7ff1-1800-0000-7d29-56248a0e0000 pid=3722 clone guuid=0733b5f1-1800-0000-7d29-56248b0e0000 pid=3723 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=0733b5f1-1800-0000-7d29-56248b0e0000 pid=3723 execve guuid=5d8e40f6-1800-0000-7d29-5624940e0000 pid=3732 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=5d8e40f6-1800-0000-7d29-5624940e0000 pid=3732 execve guuid=db76c8fa-1800-0000-7d29-56249f0e0000 pid=3743 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=db76c8fa-1800-0000-7d29-56249f0e0000 pid=3743 execve guuid=df861efb-1800-0000-7d29-5624a10e0000 pid=3745 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=df861efb-1800-0000-7d29-5624a10e0000 pid=3745 execve guuid=c90573fb-1800-0000-7d29-5624a40e0000 pid=3748 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=c90573fb-1800-0000-7d29-5624a40e0000 pid=3748 clone guuid=862893fb-1800-0000-7d29-5624a70e0000 pid=3751 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=862893fb-1800-0000-7d29-5624a70e0000 pid=3751 execve guuid=e04f03ff-1800-0000-7d29-5624b40e0000 pid=3764 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=e04f03ff-1800-0000-7d29-5624b40e0000 pid=3764 execve guuid=a5495204-1900-0000-7d29-5624c90e0000 pid=3785 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=a5495204-1900-0000-7d29-5624c90e0000 pid=3785 execve guuid=c87fb304-1900-0000-7d29-5624cd0e0000 pid=3789 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=c87fb304-1900-0000-7d29-5624cd0e0000 pid=3789 execve guuid=d1291205-1900-0000-7d29-5624ce0e0000 pid=3790 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=d1291205-1900-0000-7d29-5624ce0e0000 pid=3790 clone guuid=c8764905-1900-0000-7d29-5624d20e0000 pid=3794 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=c8764905-1900-0000-7d29-5624d20e0000 pid=3794 execve guuid=32079408-1900-0000-7d29-5624dd0e0000 pid=3805 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=32079408-1900-0000-7d29-5624dd0e0000 pid=3805 execve guuid=2c36c30d-1900-0000-7d29-5624ed0e0000 pid=3821 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=2c36c30d-1900-0000-7d29-5624ed0e0000 pid=3821 execve guuid=b73f170e-1900-0000-7d29-5624ef0e0000 pid=3823 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=b73f170e-1900-0000-7d29-5624ef0e0000 pid=3823 execve guuid=2311620e-1900-0000-7d29-5624f40e0000 pid=3828 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=2311620e-1900-0000-7d29-5624f40e0000 pid=3828 clone guuid=828d980e-1900-0000-7d29-5624f60e0000 pid=3830 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=828d980e-1900-0000-7d29-5624f60e0000 pid=3830 execve guuid=3fc23813-1900-0000-7d29-56240b0f0000 pid=3851 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=3fc23813-1900-0000-7d29-56240b0f0000 pid=3851 execve guuid=e2ab4b18-1900-0000-7d29-5624280f0000 pid=3880 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=e2ab4b18-1900-0000-7d29-5624280f0000 pid=3880 execve guuid=8436c318-1900-0000-7d29-5624290f0000 pid=3881 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=8436c318-1900-0000-7d29-5624290f0000 pid=3881 execve guuid=f0d21619-1900-0000-7d29-56242b0f0000 pid=3883 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=f0d21619-1900-0000-7d29-56242b0f0000 pid=3883 clone guuid=77a74719-1900-0000-7d29-56242d0f0000 pid=3885 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=77a74719-1900-0000-7d29-56242d0f0000 pid=3885 execve guuid=8735881c-1900-0000-7d29-56243c0f0000 pid=3900 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=8735881c-1900-0000-7d29-56243c0f0000 pid=3900 execve guuid=b371d025-1900-0000-7d29-56244b0f0000 pid=3915 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=b371d025-1900-0000-7d29-56244b0f0000 pid=3915 execve guuid=3dc73726-1900-0000-7d29-56244f0f0000 pid=3919 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=3dc73726-1900-0000-7d29-56244f0f0000 pid=3919 execve guuid=48d69626-1900-0000-7d29-5624500f0000 pid=3920 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=48d69626-1900-0000-7d29-5624500f0000 pid=3920 clone guuid=4256f826-1900-0000-7d29-5624510f0000 pid=3921 /usr/bin/wget net send-data guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=4256f826-1900-0000-7d29-5624510f0000 pid=3921 execve guuid=71ee752a-1900-0000-7d29-56245d0f0000 pid=3933 /usr/bin/curl net send-data write-file guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=71ee752a-1900-0000-7d29-56245d0f0000 pid=3933 execve guuid=a195902e-1900-0000-7d29-5624700f0000 pid=3952 /usr/bin/cat guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=a195902e-1900-0000-7d29-5624700f0000 pid=3952 execve guuid=364ce72e-1900-0000-7d29-5624720f0000 pid=3954 /usr/bin/chmod guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=364ce72e-1900-0000-7d29-5624720f0000 pid=3954 execve guuid=be13392f-1900-0000-7d29-5624740f0000 pid=3956 /usr/bin/bash guuid=5760a12c-1800-0000-7d29-5624c00c0000 pid=3264->guuid=be13392f-1900-0000-7d29-5624740f0000 pid=3956 clone d37d31e3-8687-57e3-9408-05f4b40c0fb1 192.142.10.124:80 guuid=0ac7fc32-1800-0000-7d29-5624ce0c0000 pid=3278->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=6296dc76-1800-0000-7d29-5624740d0000 pid=3444->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B guuid=f2b6b17f-1800-0000-7d29-5624950d0000 pid=3477->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=0a865883-1800-0000-7d29-5624a20d0000 pid=3490->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=e5b45c88-1800-0000-7d29-5624ab0d0000 pid=3499->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=3f81168c-1800-0000-7d29-5624b60d0000 pid=3510->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B guuid=cadb7d92-1800-0000-7d29-5624c40d0000 pid=3524->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=b14c2e96-1800-0000-7d29-5624ce0d0000 pid=3534->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=dbae4c9b-1800-0000-7d29-5624db0d0000 pid=3547->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=c8aa9e9f-1800-0000-7d29-5624e90d0000 pid=3561->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=1b080fa6-1800-0000-7d29-5624010e0000 pid=3585->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 153B guuid=7d2d2ba9-1800-0000-7d29-56240a0e0000 pid=3594->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 102B guuid=56454fae-1800-0000-7d29-56241d0e0000 pid=3613->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=b1196ab2-1800-0000-7d29-5624290e0000 pid=3625->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=db752fb7-1800-0000-7d29-56243a0e0000 pid=3642->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=47bf36ba-1800-0000-7d29-5624420e0000 pid=3650->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B guuid=79674add-1800-0000-7d29-5624740e0000 pid=3700->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=2205fbe1-1800-0000-7d29-56247d0e0000 pid=3709->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=0733b5f1-1800-0000-7d29-56248b0e0000 pid=3723->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=5d8e40f6-1800-0000-7d29-5624940e0000 pid=3732->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=862893fb-1800-0000-7d29-5624a70e0000 pid=3751->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=e04f03ff-1800-0000-7d29-5624b40e0000 pid=3764->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=c8764905-1900-0000-7d29-5624d20e0000 pid=3794->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=32079408-1900-0000-7d29-5624dd0e0000 pid=3805->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B guuid=828d980e-1900-0000-7d29-5624f60e0000 pid=3830->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=3fc23813-1900-0000-7d29-56240b0f0000 pid=3851->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B guuid=77a74719-1900-0000-7d29-56242d0f0000 pid=3885->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 151B guuid=8735881c-1900-0000-7d29-56243c0f0000 pid=3900->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 100B guuid=4256f826-1900-0000-7d29-5624510f0000 pid=3921->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 150B guuid=71ee752a-1900-0000-7d29-56245d0f0000 pid=3933->d37d31e3-8687-57e3-9408-05f4b40c0fb1 send: 99B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-24 12:14:40 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 92fc8f2ded05418117b46fe8701f3a414c7b1b8372ca26165f2b062c59a72f6d

(this sample)

  
Delivery method
Distributed via web download

Comments