MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9ee5066a1854ee15278b55e0a4cf9c58c2446f0f4599d1de85202c2341026bbb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 9ee5066a1854ee15278b55e0a4cf9c58c2446f0f4599d1de85202c2341026bbb
SHA3-384 hash: ec89fc2d7c7f87732215a491edb4822b38c037ac0fd6abb597cef068c91cd15ce156c45741904d289f0395dc81b1e2b7
SHA1 hash: ddc4ab7285b8610d282554fdcf229179e43dad64
MD5 hash: 55a2a6b6527bc9e6e6906aedc09c3058
humanhash: nuts-queen-double-echo
File name:1.sh
Download: download sample
Signature Mirai
File size:2'608 bytes
First seen:2025-10-14 08:31:35 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipJi2pID9jpe0e/a/qsp+hjpGpfpsOsxEpRKAJpuR7LpD8UBJpUf5pW5PpT5mEpJ:i+2W9jCIajif6EuAJq7LCKi5wP2EmwAQ
TLSH T128518E8918954B396CF6D82E73A9A408B0F990CB74DB6F16DCDC74E6808ED55BC00B8E
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.141.49/main_x86f31b2a135b8ddcb9722663b8ec4520b8924a2c38b8dd3c99e6bf6d19544aa91e Miraielf mirai ua-wget
http://176.65.141.49/main_mips0ebf90fd660237531739c37f1425f2d4e5f6ff31d1bae5b5a98c935bc21867ad Miraielf mirai ua-wget
http://176.65.141.49/main_arcn/an/aelf ua-wget
http://176.65.141.49/main_i686n/an/aelf ua-wget
http://176.65.141.49/main_x86_64ee7c32f57efb86a285514da96e2598f7d81688c177ec3de92e4f828cd23b47f7 Miraielf mirai ua-wget
http://176.65.141.49/main_mpsl43eb865a957058c8def3999c593386106d5b29598233768cc051e88a1ab96508 Miraielf mirai ua-wget
http://176.65.141.49/main_armdd0d12712ab5d8e4b26dbd5a059bd53d7e064ec8db2f2cf2a42e043c8dea2b7f Miraielf mirai ua-wget
http://176.65.141.49/main_arm5b3ae8570a382da334ef90b15c0fa21202d5115d32e2c7031e15576d6824adf18 Miraielf mirai ua-wget
http://176.65.141.49/main_arm6e742ad42f67f70b3affdc31018fdea67666ab740b48adf4d0488c08fe21db994 Miraielf mirai ua-wget
http://176.65.141.49/main_arm79783c5a5f2e0a5e430ad7a84a5ef5572eec1ee2600e00c24b69f7140ca96bb6b Miraielf mirai ua-wget
http://176.65.141.49/main_ppc94f74449bbff8ee640fa827d4eca9a376df175ddad43dbcda1a2a2372e588cd8 Miraielf mirai ua-wget
http://176.65.141.49/spmain_spccn/an/aelf ua-wget
http://176.65.141.49/main_m68k042febd0f4564e3ee998b8e38962c58a73b41cf1caac748c3cd4f54122d6c281 Miraielf mirai ua-wget
http://176.65.141.49/main_sh49d89128c9ddd6b99a29bb271a8f5555dfd27dffde8a1bccff44661e9c84a4c3a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-14T06:20:00Z UTC
Last seen:
2025-10-14T07:38:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=76fe71bf-1900-0000-ae84-506e3d080000 pid=2109 /usr/bin/sudo guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112 /tmp/sample.bin guuid=76fe71bf-1900-0000-ae84-506e3d080000 pid=2109->guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112 execve guuid=af0b65c2-1900-0000-ae84-506e42080000 pid=2114 /usr/bin/cp guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=af0b65c2-1900-0000-ae84-506e42080000 pid=2114 execve guuid=a44ebfc6-1900-0000-ae84-506e4e080000 pid=2126 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=a44ebfc6-1900-0000-ae84-506e4e080000 pid=2126 execve guuid=1712dacd-1900-0000-ae84-506e65080000 pid=2149 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=1712dacd-1900-0000-ae84-506e65080000 pid=2149 execve guuid=44f725e2-1900-0000-ae84-506e9a080000 pid=2202 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=44f725e2-1900-0000-ae84-506e9a080000 pid=2202 execve guuid=7b4b94e2-1900-0000-ae84-506e9c080000 pid=2204 /tmp/main_x86 delete-file net guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=7b4b94e2-1900-0000-ae84-506e9c080000 pid=2204 execve guuid=0267c8e2-1900-0000-ae84-506e9f080000 pid=2207 /usr/bin/rm guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=0267c8e2-1900-0000-ae84-506e9f080000 pid=2207 execve guuid=058114e3-1900-0000-ae84-506ea1080000 pid=2209 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=058114e3-1900-0000-ae84-506ea1080000 pid=2209 execve guuid=adf91fea-1900-0000-ae84-506eb8080000 pid=2232 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=adf91fea-1900-0000-ae84-506eb8080000 pid=2232 execve guuid=89a4f1f2-1900-0000-ae84-506ed0080000 pid=2256 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=89a4f1f2-1900-0000-ae84-506ed0080000 pid=2256 execve guuid=ffe137f3-1900-0000-ae84-506ed2080000 pid=2258 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=ffe137f3-1900-0000-ae84-506ed2080000 pid=2258 clone guuid=20c1cdf3-1900-0000-ae84-506ed6080000 pid=2262 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=20c1cdf3-1900-0000-ae84-506ed6080000 pid=2262 execve guuid=b0756bf4-1900-0000-ae84-506ed7080000 pid=2263 /usr/bin/wget net send-data guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=b0756bf4-1900-0000-ae84-506ed7080000 pid=2263 execve guuid=428249f9-1900-0000-ae84-506edc080000 pid=2268 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=428249f9-1900-0000-ae84-506edc080000 pid=2268 execve guuid=2c5d83fe-1900-0000-ae84-506ee7080000 pid=2279 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=2c5d83fe-1900-0000-ae84-506ee7080000 pid=2279 execve guuid=e3edc8fe-1900-0000-ae84-506ee9080000 pid=2281 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=e3edc8fe-1900-0000-ae84-506ee9080000 pid=2281 clone guuid=c05a10ff-1900-0000-ae84-506eeb080000 pid=2283 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=c05a10ff-1900-0000-ae84-506eeb080000 pid=2283 execve guuid=62e36aff-1900-0000-ae84-506eec080000 pid=2284 /usr/bin/wget net send-data guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=62e36aff-1900-0000-ae84-506eec080000 pid=2284 execve guuid=f7570303-1a00-0000-ae84-506ef7080000 pid=2295 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=f7570303-1a00-0000-ae84-506ef7080000 pid=2295 execve guuid=72ab7807-1a00-0000-ae84-506efe080000 pid=2302 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=72ab7807-1a00-0000-ae84-506efe080000 pid=2302 execve guuid=ea54dd07-1a00-0000-ae84-506e01090000 pid=2305 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=ea54dd07-1a00-0000-ae84-506e01090000 pid=2305 clone guuid=59c93908-1a00-0000-ae84-506e04090000 pid=2308 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=59c93908-1a00-0000-ae84-506e04090000 pid=2308 execve guuid=a6978908-1a00-0000-ae84-506e06090000 pid=2310 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=a6978908-1a00-0000-ae84-506e06090000 pid=2310 execve guuid=f1474a23-1a00-0000-ae84-506e42090000 pid=2370 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=f1474a23-1a00-0000-ae84-506e42090000 pid=2370 execve guuid=b707a92c-1a00-0000-ae84-506e50090000 pid=2384 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=b707a92c-1a00-0000-ae84-506e50090000 pid=2384 execve guuid=db5a032d-1a00-0000-ae84-506e51090000 pid=2385 /tmp/main_x86_64 delete-file net guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=db5a032d-1a00-0000-ae84-506e51090000 pid=2385 execve guuid=05eb262d-1a00-0000-ae84-506e53090000 pid=2387 /usr/bin/rm guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=05eb262d-1a00-0000-ae84-506e53090000 pid=2387 execve guuid=7a1e6a2d-1a00-0000-ae84-506e55090000 pid=2389 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=7a1e6a2d-1a00-0000-ae84-506e55090000 pid=2389 execve guuid=71e16d35-1a00-0000-ae84-506e6a090000 pid=2410 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=71e16d35-1a00-0000-ae84-506e6a090000 pid=2410 execve guuid=cedd603d-1a00-0000-ae84-506e7b090000 pid=2427 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=cedd603d-1a00-0000-ae84-506e7b090000 pid=2427 execve guuid=6c95bf3d-1a00-0000-ae84-506e7e090000 pid=2430 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=6c95bf3d-1a00-0000-ae84-506e7e090000 pid=2430 clone guuid=a9895f3f-1a00-0000-ae84-506e84090000 pid=2436 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=a9895f3f-1a00-0000-ae84-506e84090000 pid=2436 execve guuid=3ea4f03f-1a00-0000-ae84-506e85090000 pid=2437 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=3ea4f03f-1a00-0000-ae84-506e85090000 pid=2437 execve guuid=c3c80c47-1a00-0000-ae84-506e95090000 pid=2453 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=c3c80c47-1a00-0000-ae84-506e95090000 pid=2453 execve guuid=f370e450-1a00-0000-ae84-506eaf090000 pid=2479 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=f370e450-1a00-0000-ae84-506eaf090000 pid=2479 execve guuid=d8f52351-1a00-0000-ae84-506eb1090000 pid=2481 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=d8f52351-1a00-0000-ae84-506eb1090000 pid=2481 clone guuid=ded1ad51-1a00-0000-ae84-506eb5090000 pid=2485 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=ded1ad51-1a00-0000-ae84-506eb5090000 pid=2485 execve guuid=e6831c52-1a00-0000-ae84-506eb6090000 pid=2486 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=e6831c52-1a00-0000-ae84-506eb6090000 pid=2486 execve guuid=df885059-1a00-0000-ae84-506ecd090000 pid=2509 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=df885059-1a00-0000-ae84-506ecd090000 pid=2509 execve guuid=68dbd961-1a00-0000-ae84-506ee3090000 pid=2531 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=68dbd961-1a00-0000-ae84-506ee3090000 pid=2531 execve guuid=36bc2e62-1a00-0000-ae84-506ee4090000 pid=2532 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=36bc2e62-1a00-0000-ae84-506ee4090000 pid=2532 clone guuid=6e990a63-1a00-0000-ae84-506ee6090000 pid=2534 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=6e990a63-1a00-0000-ae84-506ee6090000 pid=2534 execve guuid=5a2f8d63-1a00-0000-ae84-506ee8090000 pid=2536 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=5a2f8d63-1a00-0000-ae84-506ee8090000 pid=2536 execve guuid=be61346b-1a00-0000-ae84-506efe090000 pid=2558 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=be61346b-1a00-0000-ae84-506efe090000 pid=2558 execve guuid=5fcc2a75-1a00-0000-ae84-506e160a0000 pid=2582 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=5fcc2a75-1a00-0000-ae84-506e160a0000 pid=2582 execve guuid=999c7675-1a00-0000-ae84-506e170a0000 pid=2583 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=999c7675-1a00-0000-ae84-506e170a0000 pid=2583 clone guuid=917e3f77-1a00-0000-ae84-506e1c0a0000 pid=2588 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=917e3f77-1a00-0000-ae84-506e1c0a0000 pid=2588 execve guuid=f9bfa877-1a00-0000-ae84-506e1e0a0000 pid=2590 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=f9bfa877-1a00-0000-ae84-506e1e0a0000 pid=2590 execve guuid=9b82f27f-1a00-0000-ae84-506e350a0000 pid=2613 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=9b82f27f-1a00-0000-ae84-506e350a0000 pid=2613 execve guuid=66c30189-1a00-0000-ae84-506e540a0000 pid=2644 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=66c30189-1a00-0000-ae84-506e540a0000 pid=2644 execve guuid=38b47689-1a00-0000-ae84-506e560a0000 pid=2646 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=38b47689-1a00-0000-ae84-506e560a0000 pid=2646 clone guuid=5c99588a-1a00-0000-ae84-506e5a0a0000 pid=2650 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=5c99588a-1a00-0000-ae84-506e5a0a0000 pid=2650 execve guuid=cab3db8a-1a00-0000-ae84-506e5c0a0000 pid=2652 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=cab3db8a-1a00-0000-ae84-506e5c0a0000 pid=2652 execve guuid=fb2cb792-1a00-0000-ae84-506e730a0000 pid=2675 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=fb2cb792-1a00-0000-ae84-506e730a0000 pid=2675 execve guuid=5667919c-1a00-0000-ae84-506e900a0000 pid=2704 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=5667919c-1a00-0000-ae84-506e900a0000 pid=2704 execve guuid=e026d89c-1a00-0000-ae84-506e920a0000 pid=2706 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=e026d89c-1a00-0000-ae84-506e920a0000 pid=2706 clone guuid=a817729d-1a00-0000-ae84-506e960a0000 pid=2710 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=a817729d-1a00-0000-ae84-506e960a0000 pid=2710 execve guuid=8f8fbb9d-1a00-0000-ae84-506e970a0000 pid=2711 /usr/bin/wget net send-data guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=8f8fbb9d-1a00-0000-ae84-506e970a0000 pid=2711 execve guuid=2a548ba1-1a00-0000-ae84-506ea20a0000 pid=2722 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=2a548ba1-1a00-0000-ae84-506ea20a0000 pid=2722 execve guuid=740c19a7-1a00-0000-ae84-506eb30a0000 pid=2739 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=740c19a7-1a00-0000-ae84-506eb30a0000 pid=2739 execve guuid=f82c5ea7-1a00-0000-ae84-506eb50a0000 pid=2741 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=f82c5ea7-1a00-0000-ae84-506eb50a0000 pid=2741 clone guuid=17367da7-1a00-0000-ae84-506eb70a0000 pid=2743 /usr/bin/rm guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=17367da7-1a00-0000-ae84-506eb70a0000 pid=2743 execve guuid=cb91c4a7-1a00-0000-ae84-506eb80a0000 pid=2744 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=cb91c4a7-1a00-0000-ae84-506eb80a0000 pid=2744 execve guuid=7efca0ae-1a00-0000-ae84-506ecc0a0000 pid=2764 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=7efca0ae-1a00-0000-ae84-506ecc0a0000 pid=2764 execve guuid=47af50b6-1a00-0000-ae84-506ee20a0000 pid=2786 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=47af50b6-1a00-0000-ae84-506ee20a0000 pid=2786 execve guuid=285d9bb6-1a00-0000-ae84-506ee40a0000 pid=2788 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=285d9bb6-1a00-0000-ae84-506ee40a0000 pid=2788 clone guuid=9d5416b8-1a00-0000-ae84-506eea0a0000 pid=2794 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=9d5416b8-1a00-0000-ae84-506eea0a0000 pid=2794 execve guuid=93af58b8-1a00-0000-ae84-506eeb0a0000 pid=2795 /usr/bin/wget net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=93af58b8-1a00-0000-ae84-506eeb0a0000 pid=2795 execve guuid=8b5413c0-1a00-0000-ae84-506efd0a0000 pid=2813 /usr/bin/curl net send-data write-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=8b5413c0-1a00-0000-ae84-506efd0a0000 pid=2813 execve guuid=2cd8bdc7-1a00-0000-ae84-506e0e0b0000 pid=2830 /usr/bin/chmod guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=2cd8bdc7-1a00-0000-ae84-506e0e0b0000 pid=2830 execve guuid=24c512c8-1a00-0000-ae84-506e100b0000 pid=2832 /usr/bin/bash guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=24c512c8-1a00-0000-ae84-506e100b0000 pid=2832 clone guuid=e0f5dcc8-1a00-0000-ae84-506e120b0000 pid=2834 /usr/bin/rm delete-file guuid=dc4d04c2-1900-0000-ae84-506e40080000 pid=2112->guuid=e0f5dcc8-1a00-0000-ae84-506e120b0000 pid=2834 execve 16d48607-c65f-508c-8e44-171edd592193 176.65.141.49:80 guuid=a44ebfc6-1900-0000-ae84-506e4e080000 pid=2126->16d48607-c65f-508c-8e44-171edd592193 send: 136B guuid=1712dacd-1900-0000-ae84-506e65080000 pid=2149->16d48607-c65f-508c-8e44-171edd592193 send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7b4b94e2-1900-0000-ae84-506e9c080000 pid=2204->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0160bde2-1900-0000-ae84-506e9d080000 pid=2205 /tmp/main_x86 dns net send-data zombie guuid=7b4b94e2-1900-0000-ae84-506e9c080000 pid=2204->guuid=0160bde2-1900-0000-ae84-506e9d080000 pid=2205 clone guuid=0160bde2-1900-0000-ae84-506e9d080000 pid=2205->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B 25f3365d-095a-517f-9fd3-6b7167ac5b5d vicious-net.duckdns.org:1995 guuid=0160bde2-1900-0000-ae84-506e9d080000 pid=2205->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 15B guuid=38cacee2-1900-0000-ae84-506ea0080000 pid=2208 /tmp/main_x86 guuid=0160bde2-1900-0000-ae84-506e9d080000 pid=2205->guuid=38cacee2-1900-0000-ae84-506ea0080000 pid=2208 clone guuid=058114e3-1900-0000-ae84-506ea1080000 pid=2209->16d48607-c65f-508c-8e44-171edd592193 send: 137B guuid=adf91fea-1900-0000-ae84-506eb8080000 pid=2232->16d48607-c65f-508c-8e44-171edd592193 send: 86B guuid=b0756bf4-1900-0000-ae84-506ed7080000 pid=2263->16d48607-c65f-508c-8e44-171edd592193 send: 136B guuid=428249f9-1900-0000-ae84-506edc080000 pid=2268->16d48607-c65f-508c-8e44-171edd592193 send: 85B guuid=f265defe-1900-0000-ae84-506eea080000 pid=2282 /usr/bin/bash guuid=e3edc8fe-1900-0000-ae84-506ee9080000 pid=2281->guuid=f265defe-1900-0000-ae84-506eea080000 pid=2282 clone guuid=62e36aff-1900-0000-ae84-506eec080000 pid=2284->16d48607-c65f-508c-8e44-171edd592193 send: 137B guuid=f7570303-1a00-0000-ae84-506ef7080000 pid=2295->16d48607-c65f-508c-8e44-171edd592193 send: 86B guuid=6903fc07-1a00-0000-ae84-506e02090000 pid=2306 /usr/bin/bash guuid=ea54dd07-1a00-0000-ae84-506e01090000 pid=2305->guuid=6903fc07-1a00-0000-ae84-506e02090000 pid=2306 clone guuid=a6978908-1a00-0000-ae84-506e06090000 pid=2310->16d48607-c65f-508c-8e44-171edd592193 send: 139B ecd4a88d-d012-5f15-bffb-623c66bb0b83 vicious-net.duckdns.org:80 guuid=f1474a23-1a00-0000-ae84-506e42090000 pid=2370->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 88B guuid=db5a032d-1a00-0000-ae84-506e51090000 pid=2385->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=938c1c2d-1a00-0000-ae84-506e52090000 pid=2386 /tmp/main_x86_64 dns net send-data zombie guuid=db5a032d-1a00-0000-ae84-506e51090000 pid=2385->guuid=938c1c2d-1a00-0000-ae84-506e52090000 pid=2386 clone guuid=938c1c2d-1a00-0000-ae84-506e52090000 pid=2386->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=938c1c2d-1a00-0000-ae84-506e52090000 pid=2386->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 18B guuid=edf7282d-1a00-0000-ae84-506e54090000 pid=2388 /tmp/main_x86_64 guuid=938c1c2d-1a00-0000-ae84-506e52090000 pid=2386->guuid=edf7282d-1a00-0000-ae84-506e54090000 pid=2388 clone guuid=7a1e6a2d-1a00-0000-ae84-506e55090000 pid=2389->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=71e16d35-1a00-0000-ae84-506e6a090000 pid=2410->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=3ea4f03f-1a00-0000-ae84-506e85090000 pid=2437->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=c3c80c47-1a00-0000-ae84-506e95090000 pid=2453->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B guuid=e6831c52-1a00-0000-ae84-506eb6090000 pid=2486->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=df885059-1a00-0000-ae84-506ecd090000 pid=2509->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=5a2f8d63-1a00-0000-ae84-506ee8090000 pid=2536->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=be61346b-1a00-0000-ae84-506efe090000 pid=2558->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=f9bfa877-1a00-0000-ae84-506e1e0a0000 pid=2590->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=9b82f27f-1a00-0000-ae84-506e350a0000 pid=2613->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=cab3db8a-1a00-0000-ae84-506e5c0a0000 pid=2652->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=fb2cb792-1a00-0000-ae84-506e730a0000 pid=2675->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B guuid=8f8fbb9d-1a00-0000-ae84-506e970a0000 pid=2711->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=2a548ba1-1a00-0000-ae84-506ea20a0000 pid=2722->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 88B guuid=cb91c4a7-1a00-0000-ae84-506eb80a0000 pid=2744->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 137B guuid=7efca0ae-1a00-0000-ae84-506ecc0a0000 pid=2764->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 86B guuid=93af58b8-1a00-0000-ae84-506eeb0a0000 pid=2795->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 136B guuid=8b5413c0-1a00-0000-ae84-506efd0a0000 pid=2813->ecd4a88d-d012-5f15-bffb-623c66bb0b83 send: 85B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-14 08:32:35 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9ee5066a1854ee15278b55e0a4cf9c58c2446f0f4599d1de85202c2341026bbb

(this sample)

  
Delivery method
Distributed via web download

Comments