MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9b25b603427438fe93e5a6851c94cf877f4279dd093882c8e02189aa195d9d31. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 9b25b603427438fe93e5a6851c94cf877f4279dd093882c8e02189aa195d9d31
SHA3-384 hash: 9fc4751d7e14f7724005b915190e512e76a33d8c0c2daa5f0346bc5d7c790b1f0a90b01c51a5ff8dffe5a0421b9a9e77
SHA1 hash: 5ed09f895d9b120dbdef0a5e0e1a75fb4ad76c8d
MD5 hash: d89bf59edef54535a4ba5efd1204f894
humanhash: xray-muppet-twelve-artist
File name:1.sh
Download: download sample
Signature Mirai
File size:2'834 bytes
First seen:2025-10-11 15:44:34 UTC
Last seen:2025-10-12 06:55:20 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipJi2pID9jpZDZETWTpydpIFpGpfpsOsxEpRKAJpuR7LpD8UBJpUf5pW5PpTMEpJ:i+2W9jjAOif6EuAJq7LCKi5wPyEmwAPY
TLSH T156519085188147396CFAD92A73F8A408B4F580C7B4DB6F16D8DC78E6808DD59BC40B8E
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.141.49/main_x86f31b2a135b8ddcb9722663b8ec4520b8924a2c38b8dd3c99e6bf6d19544aa91e Miraielf mirai ua-wget
http://176.65.141.49/main_mips0ebf90fd660237531739c37f1425f2d4e5f6ff31d1bae5b5a98c935bc21867ad Miraielf mirai ua-wget
http://176.65.141.49/vicious.arcn/an/aelf ua-wget
http://176.65.141.49/vicious.i468n/an/aelf ua-wget
http://176.65.141.49/vicious.i686n/an/aelf ua-wget
http://176.65.141.49/main_x86_64ee7c32f57efb86a285514da96e2598f7d81688c177ec3de92e4f828cd23b47f7 Miraielf mirai ua-wget
http://176.65.141.49/main_mpsl43eb865a957058c8def3999c593386106d5b29598233768cc051e88a1ab96508 Miraielf mirai ua-wget
http://176.65.141.49/main_armdd0d12712ab5d8e4b26dbd5a059bd53d7e064ec8db2f2cf2a42e043c8dea2b7f Miraielf mirai ua-wget
http://176.65.141.49/main_arm5b3ae8570a382da334ef90b15c0fa21202d5115d32e2c7031e15576d6824adf18 Miraielf mirai ua-wget
http://176.65.141.49/main_arm6e742ad42f67f70b3affdc31018fdea67666ab740b48adf4d0488c08fe21db994 Miraielf mirai ua-wget
http://176.65.141.49/main_arm79783c5a5f2e0a5e430ad7a84a5ef5572eec1ee2600e00c24b69f7140ca96bb6b Miraielf mirai ua-wget
http://176.65.141.49/main_ppc94f74449bbff8ee640fa827d4eca9a376df175ddad43dbcda1a2a2372e588cd8 Miraielf mirai ua-wget
http://176.65.141.49/main_spcn/an/aelf ua-wget
http://176.65.141.49/main_m68k042febd0f4564e3ee998b8e38962c58a73b41cf1caac748c3cd4f54122d6c281 Miraielf mirai ua-wget
http://176.65.141.49/main_sh49d89128c9ddd6b99a29bb271a8f5555dfd27dffde8a1bccff44661e9c84a4c3a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-11T12:59:00Z UTC
Last seen:
2025-10-11T13:24:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=68834a18-1900-0000-eaea-ab6d56130000 pid=4950 /usr/bin/sudo guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959 /tmp/sample.bin guuid=68834a18-1900-0000-eaea-ab6d56130000 pid=4950->guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959 execve guuid=e293311b-1900-0000-eaea-ab6d62130000 pid=4962 /usr/bin/cp guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=e293311b-1900-0000-eaea-ab6d62130000 pid=4962 execve guuid=cfb53e20-1900-0000-eaea-ab6d72130000 pid=4978 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=cfb53e20-1900-0000-eaea-ab6d72130000 pid=4978 execve guuid=3e27ce28-1900-0000-eaea-ab6d88130000 pid=5000 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=3e27ce28-1900-0000-eaea-ab6d88130000 pid=5000 execve guuid=6b547536-1900-0000-eaea-ab6dae130000 pid=5038 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=6b547536-1900-0000-eaea-ab6dae130000 pid=5038 execve guuid=9ef2bc36-1900-0000-eaea-ab6db1130000 pid=5041 /tmp/main_x86 delete-file net guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9ef2bc36-1900-0000-eaea-ab6db1130000 pid=5041 execve guuid=b89de736-1900-0000-eaea-ab6db4130000 pid=5044 /usr/bin/rm guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=b89de736-1900-0000-eaea-ab6db4130000 pid=5044 execve guuid=ce202237-1900-0000-eaea-ab6db6130000 pid=5046 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=ce202237-1900-0000-eaea-ab6db6130000 pid=5046 execve guuid=16b57e3f-1900-0000-eaea-ab6dd9130000 pid=5081 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=16b57e3f-1900-0000-eaea-ab6dd9130000 pid=5081 execve guuid=0b4af86c-1900-0000-eaea-ab6d09140000 pid=5129 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=0b4af86c-1900-0000-eaea-ab6d09140000 pid=5129 execve guuid=2a4b806d-1900-0000-eaea-ab6d0b140000 pid=5131 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=2a4b806d-1900-0000-eaea-ab6d0b140000 pid=5131 clone guuid=85909770-1900-0000-eaea-ab6d10140000 pid=5136 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=85909770-1900-0000-eaea-ab6d10140000 pid=5136 execve guuid=f1bc0871-1900-0000-eaea-ab6d12140000 pid=5138 /usr/bin/wget net send-data guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=f1bc0871-1900-0000-eaea-ab6d12140000 pid=5138 execve guuid=a118ee74-1900-0000-eaea-ab6d17140000 pid=5143 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=a118ee74-1900-0000-eaea-ab6d17140000 pid=5143 execve guuid=8a75107b-1900-0000-eaea-ab6d27140000 pid=5159 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=8a75107b-1900-0000-eaea-ab6d27140000 pid=5159 execve guuid=a233707b-1900-0000-eaea-ab6d29140000 pid=5161 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=a233707b-1900-0000-eaea-ab6d29140000 pid=5161 clone guuid=ab93be7b-1900-0000-eaea-ab6d2b140000 pid=5163 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=ab93be7b-1900-0000-eaea-ab6d2b140000 pid=5163 execve guuid=4a270d7c-1900-0000-eaea-ab6d2d140000 pid=5165 /usr/bin/wget net send-data guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=4a270d7c-1900-0000-eaea-ab6d2d140000 pid=5165 execve guuid=a837a780-1900-0000-eaea-ab6d35140000 pid=5173 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=a837a780-1900-0000-eaea-ab6d35140000 pid=5173 execve guuid=9b048186-1900-0000-eaea-ab6d39140000 pid=5177 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9b048186-1900-0000-eaea-ab6d39140000 pid=5177 execve guuid=b96ac386-1900-0000-eaea-ab6d3a140000 pid=5178 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=b96ac386-1900-0000-eaea-ab6d3a140000 pid=5178 clone guuid=7b2d0187-1900-0000-eaea-ab6d3c140000 pid=5180 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=7b2d0187-1900-0000-eaea-ab6d3c140000 pid=5180 execve guuid=5a954187-1900-0000-eaea-ab6d3d140000 pid=5181 /usr/bin/wget net send-data guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=5a954187-1900-0000-eaea-ab6d3d140000 pid=5181 execve guuid=3ce7078c-1900-0000-eaea-ab6d51140000 pid=5201 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=3ce7078c-1900-0000-eaea-ab6d51140000 pid=5201 execve guuid=41ccb292-1900-0000-eaea-ab6d6f140000 pid=5231 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=41ccb292-1900-0000-eaea-ab6d6f140000 pid=5231 execve guuid=614cfe92-1900-0000-eaea-ab6d70140000 pid=5232 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=614cfe92-1900-0000-eaea-ab6d70140000 pid=5232 clone guuid=e2533f93-1900-0000-eaea-ab6d72140000 pid=5234 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=e2533f93-1900-0000-eaea-ab6d72140000 pid=5234 execve guuid=bd018793-1900-0000-eaea-ab6d73140000 pid=5235 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=bd018793-1900-0000-eaea-ab6d73140000 pid=5235 execve guuid=1e3feb99-1900-0000-eaea-ab6d74140000 pid=5236 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=1e3feb99-1900-0000-eaea-ab6d74140000 pid=5236 execve guuid=911a73a1-1900-0000-eaea-ab6d75140000 pid=5237 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=911a73a1-1900-0000-eaea-ab6d75140000 pid=5237 execve guuid=f344bea1-1900-0000-eaea-ab6d76140000 pid=5238 /tmp/main_x86_64 delete-file net guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=f344bea1-1900-0000-eaea-ab6d76140000 pid=5238 execve guuid=0cbee3a1-1900-0000-eaea-ab6d78140000 pid=5240 /usr/bin/rm guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=0cbee3a1-1900-0000-eaea-ab6d78140000 pid=5240 execve guuid=57892da2-1900-0000-eaea-ab6d7a140000 pid=5242 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=57892da2-1900-0000-eaea-ab6d7a140000 pid=5242 execve guuid=55c1daa8-1900-0000-eaea-ab6d7b140000 pid=5243 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=55c1daa8-1900-0000-eaea-ab6d7b140000 pid=5243 execve guuid=4d7f88b0-1900-0000-eaea-ab6d7f140000 pid=5247 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=4d7f88b0-1900-0000-eaea-ab6d7f140000 pid=5247 execve guuid=47f5fab0-1900-0000-eaea-ab6d80140000 pid=5248 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=47f5fab0-1900-0000-eaea-ab6d80140000 pid=5248 clone guuid=5142dbb1-1900-0000-eaea-ab6d82140000 pid=5250 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=5142dbb1-1900-0000-eaea-ab6d82140000 pid=5250 execve guuid=9b6d46b2-1900-0000-eaea-ab6d85140000 pid=5253 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9b6d46b2-1900-0000-eaea-ab6d85140000 pid=5253 execve guuid=0b8311b9-1900-0000-eaea-ab6d8c140000 pid=5260 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=0b8311b9-1900-0000-eaea-ab6d8c140000 pid=5260 execve guuid=a1e294c0-1900-0000-eaea-ab6d8d140000 pid=5261 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=a1e294c0-1900-0000-eaea-ab6d8d140000 pid=5261 execve guuid=9f14e8c0-1900-0000-eaea-ab6d8e140000 pid=5262 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9f14e8c0-1900-0000-eaea-ab6d8e140000 pid=5262 clone guuid=7b0194c2-1900-0000-eaea-ab6d90140000 pid=5264 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=7b0194c2-1900-0000-eaea-ab6d90140000 pid=5264 execve guuid=0f27dbc2-1900-0000-eaea-ab6d91140000 pid=5265 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=0f27dbc2-1900-0000-eaea-ab6d91140000 pid=5265 execve guuid=cf734ac9-1900-0000-eaea-ab6d92140000 pid=5266 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=cf734ac9-1900-0000-eaea-ab6d92140000 pid=5266 execve guuid=8872a3d3-1900-0000-eaea-ab6d93140000 pid=5267 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=8872a3d3-1900-0000-eaea-ab6d93140000 pid=5267 execve guuid=d04602d4-1900-0000-eaea-ab6d94140000 pid=5268 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=d04602d4-1900-0000-eaea-ab6d94140000 pid=5268 clone guuid=e0f0bbd4-1900-0000-eaea-ab6d96140000 pid=5270 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=e0f0bbd4-1900-0000-eaea-ab6d96140000 pid=5270 execve guuid=2e7b7ed5-1900-0000-eaea-ab6d97140000 pid=5271 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=2e7b7ed5-1900-0000-eaea-ab6d97140000 pid=5271 execve guuid=cf5b92dd-1900-0000-eaea-ab6d98140000 pid=5272 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=cf5b92dd-1900-0000-eaea-ab6d98140000 pid=5272 execve guuid=c12b0de5-1900-0000-eaea-ab6d99140000 pid=5273 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=c12b0de5-1900-0000-eaea-ab6d99140000 pid=5273 execve guuid=2d1a57e5-1900-0000-eaea-ab6d9a140000 pid=5274 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=2d1a57e5-1900-0000-eaea-ab6d9a140000 pid=5274 clone guuid=4d7aece5-1900-0000-eaea-ab6d9c140000 pid=5276 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=4d7aece5-1900-0000-eaea-ab6d9c140000 pid=5276 execve guuid=ace146e6-1900-0000-eaea-ab6d9d140000 pid=5277 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=ace146e6-1900-0000-eaea-ab6d9d140000 pid=5277 execve guuid=327cf8ed-1900-0000-eaea-ab6d9e140000 pid=5278 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=327cf8ed-1900-0000-eaea-ab6d9e140000 pid=5278 execve guuid=15a2a1f8-1900-0000-eaea-ab6d9f140000 pid=5279 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=15a2a1f8-1900-0000-eaea-ab6d9f140000 pid=5279 execve guuid=5beae8f8-1900-0000-eaea-ab6da0140000 pid=5280 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=5beae8f8-1900-0000-eaea-ab6da0140000 pid=5280 clone guuid=f5fa85f9-1900-0000-eaea-ab6da2140000 pid=5282 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=f5fa85f9-1900-0000-eaea-ab6da2140000 pid=5282 execve guuid=9b1bd4f9-1900-0000-eaea-ab6da3140000 pid=5283 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9b1bd4f9-1900-0000-eaea-ab6da3140000 pid=5283 execve guuid=395a5b00-1a00-0000-eaea-ab6da4140000 pid=5284 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=395a5b00-1a00-0000-eaea-ab6da4140000 pid=5284 execve guuid=a1ff1608-1a00-0000-eaea-ab6da5140000 pid=5285 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=a1ff1608-1a00-0000-eaea-ab6da5140000 pid=5285 execve guuid=1dc95d08-1a00-0000-eaea-ab6da6140000 pid=5286 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=1dc95d08-1a00-0000-eaea-ab6da6140000 pid=5286 clone guuid=be0ff708-1a00-0000-eaea-ab6da8140000 pid=5288 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=be0ff708-1a00-0000-eaea-ab6da8140000 pid=5288 execve guuid=bc804409-1a00-0000-eaea-ab6da9140000 pid=5289 /usr/bin/wget net send-data guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=bc804409-1a00-0000-eaea-ab6da9140000 pid=5289 execve guuid=5ac75b0c-1a00-0000-eaea-ab6daa140000 pid=5290 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=5ac75b0c-1a00-0000-eaea-ab6daa140000 pid=5290 execve guuid=32cc7a10-1a00-0000-eaea-ab6dab140000 pid=5291 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=32cc7a10-1a00-0000-eaea-ab6dab140000 pid=5291 execve guuid=1be0c310-1a00-0000-eaea-ab6dac140000 pid=5292 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=1be0c310-1a00-0000-eaea-ab6dac140000 pid=5292 clone guuid=477e0b11-1a00-0000-eaea-ab6dae140000 pid=5294 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=477e0b11-1a00-0000-eaea-ab6dae140000 pid=5294 execve guuid=89325911-1a00-0000-eaea-ab6daf140000 pid=5295 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=89325911-1a00-0000-eaea-ab6daf140000 pid=5295 execve guuid=9a79ef17-1a00-0000-eaea-ab6db0140000 pid=5296 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=9a79ef17-1a00-0000-eaea-ab6db0140000 pid=5296 execve guuid=04fc1120-1a00-0000-eaea-ab6db1140000 pid=5297 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=04fc1120-1a00-0000-eaea-ab6db1140000 pid=5297 execve guuid=90167120-1a00-0000-eaea-ab6db2140000 pid=5298 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=90167120-1a00-0000-eaea-ab6db2140000 pid=5298 clone guuid=82c21721-1a00-0000-eaea-ab6db4140000 pid=5300 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=82c21721-1a00-0000-eaea-ab6db4140000 pid=5300 execve guuid=c9747421-1a00-0000-eaea-ab6db5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=c9747421-1a00-0000-eaea-ab6db5140000 pid=5301 execve guuid=c20a122b-1a00-0000-eaea-ab6db6140000 pid=5302 /usr/bin/curl net send-data write-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=c20a122b-1a00-0000-eaea-ab6db6140000 pid=5302 execve guuid=1effa133-1a00-0000-eaea-ab6db7140000 pid=5303 /usr/bin/chmod guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=1effa133-1a00-0000-eaea-ab6db7140000 pid=5303 execve guuid=00befa33-1a00-0000-eaea-ab6db8140000 pid=5304 /usr/bin/bash guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=00befa33-1a00-0000-eaea-ab6db8140000 pid=5304 clone guuid=d5dacf34-1a00-0000-eaea-ab6dba140000 pid=5306 /usr/bin/rm delete-file guuid=e4258d1a-1900-0000-eaea-ab6d5f130000 pid=4959->guuid=d5dacf34-1a00-0000-eaea-ab6dba140000 pid=5306 execve 16d48607-c65f-508c-8e44-171edd592193 176.65.141.49:80 guuid=cfb53e20-1900-0000-eaea-ab6d72130000 pid=4978->16d48607-c65f-508c-8e44-171edd592193 send: 136B guuid=3e27ce28-1900-0000-eaea-ab6d88130000 pid=5000->16d48607-c65f-508c-8e44-171edd592193 send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9ef2bc36-1900-0000-eaea-ab6db1130000 pid=5041->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=319bdf36-1900-0000-eaea-ab6db3130000 pid=5043 /tmp/main_x86 dns net send-data zombie guuid=9ef2bc36-1900-0000-eaea-ab6db1130000 pid=5041->guuid=319bdf36-1900-0000-eaea-ab6db3130000 pid=5043 clone guuid=319bdf36-1900-0000-eaea-ab6db3130000 pid=5043->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B 25f3365d-095a-517f-9fd3-6b7167ac5b5d vicious-net.duckdns.org:1995 guuid=319bdf36-1900-0000-eaea-ab6db3130000 pid=5043->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 15B guuid=2327f536-1900-0000-eaea-ab6db5130000 pid=5045 /tmp/main_x86 guuid=319bdf36-1900-0000-eaea-ab6db3130000 pid=5043->guuid=2327f536-1900-0000-eaea-ab6db5130000 pid=5045 clone guuid=ce202237-1900-0000-eaea-ab6db6130000 pid=5046->16d48607-c65f-508c-8e44-171edd592193 send: 137B ecd4a88d-d012-5f15-bffb-623c66bb0b83 vicious-net.duckdns.org:80 guuid=16b57e3f-1900-0000-eaea-ab6dd9130000 pid=5081->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=f1bc0871-1900-0000-eaea-ab6d12140000 pid=5138->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 139B guuid=a118ee74-1900-0000-eaea-ab6d17140000 pid=5143->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 88B guuid=a7b08b7b-1900-0000-eaea-ab6d2a140000 pid=5162 /usr/bin/bash guuid=a233707b-1900-0000-eaea-ab6d29140000 pid=5161->guuid=a7b08b7b-1900-0000-eaea-ab6d2a140000 pid=5162 clone guuid=4a270d7c-1900-0000-eaea-ab6d2d140000 pid=5165->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 140B guuid=a837a780-1900-0000-eaea-ab6d35140000 pid=5173->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 89B guuid=589cda86-1900-0000-eaea-ab6d3b140000 pid=5179 /usr/bin/bash guuid=b96ac386-1900-0000-eaea-ab6d3a140000 pid=5178->guuid=589cda86-1900-0000-eaea-ab6d3b140000 pid=5179 clone guuid=5a954187-1900-0000-eaea-ab6d3d140000 pid=5181->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 140B guuid=3ce7078c-1900-0000-eaea-ab6d51140000 pid=5201->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 89B guuid=3c671493-1900-0000-eaea-ab6d71140000 pid=5233 /usr/bin/bash guuid=614cfe92-1900-0000-eaea-ab6d70140000 pid=5232->guuid=3c671493-1900-0000-eaea-ab6d71140000 pid=5233 clone guuid=bd018793-1900-0000-eaea-ab6d73140000 pid=5235->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 139B guuid=1e3feb99-1900-0000-eaea-ab6d74140000 pid=5236->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 88B guuid=f344bea1-1900-0000-eaea-ab6d76140000 pid=5238->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c2c7d5a1-1900-0000-eaea-ab6d77140000 pid=5239 /tmp/main_x86_64 dns net send-data zombie guuid=f344bea1-1900-0000-eaea-ab6d76140000 pid=5238->guuid=c2c7d5a1-1900-0000-eaea-ab6d77140000 pid=5239 clone guuid=c2c7d5a1-1900-0000-eaea-ab6d77140000 pid=5239->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=c2c7d5a1-1900-0000-eaea-ab6d77140000 pid=5239->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 18B guuid=5458eda1-1900-0000-eaea-ab6d79140000 pid=5241 /tmp/main_x86_64 guuid=c2c7d5a1-1900-0000-eaea-ab6d77140000 pid=5239->guuid=5458eda1-1900-0000-eaea-ab6d79140000 pid=5241 clone guuid=57892da2-1900-0000-eaea-ab6d7a140000 pid=5242->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=55c1daa8-1900-0000-eaea-ab6d7b140000 pid=5243->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=9b6d46b2-1900-0000-eaea-ab6d85140000 pid=5253->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=0b8311b9-1900-0000-eaea-ab6d8c140000 pid=5260->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B guuid=0f27dbc2-1900-0000-eaea-ab6d91140000 pid=5265->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=cf734ac9-1900-0000-eaea-ab6d92140000 pid=5266->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=2e7b7ed5-1900-0000-eaea-ab6d97140000 pid=5271->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=cf5b92dd-1900-0000-eaea-ab6d98140000 pid=5272->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=ace146e6-1900-0000-eaea-ab6d9d140000 pid=5277->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=327cf8ed-1900-0000-eaea-ab6d9e140000 pid=5278->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=9b1bd4f9-1900-0000-eaea-ab6da3140000 pid=5283->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=395a5b00-1a00-0000-eaea-ab6da4140000 pid=5284->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B guuid=bc804409-1a00-0000-eaea-ab6da9140000 pid=5289->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=5ac75b0c-1a00-0000-eaea-ab6daa140000 pid=5290->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B guuid=4b56df10-1a00-0000-eaea-ab6dad140000 pid=5293 /usr/bin/bash guuid=1be0c310-1a00-0000-eaea-ab6dac140000 pid=5292->guuid=4b56df10-1a00-0000-eaea-ab6dad140000 pid=5293 clone guuid=89325911-1a00-0000-eaea-ab6daf140000 pid=5295->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=9a79ef17-1a00-0000-eaea-ab6db0140000 pid=5296->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=c9747421-1a00-0000-eaea-ab6db5140000 pid=5301->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=c20a122b-1a00-0000-eaea-ab6db6140000 pid=5302->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-11 15:45:43 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9b25b603427438fe93e5a6851c94cf877f4279dd093882c8e02189aa195d9d31

(this sample)

  
Delivery method
Distributed via web download

Comments