MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a43f6a8613ef0b1d6123aada7ad34566d2e27c73bccccdb8e7bf68dbcc18677f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a43f6a8613ef0b1d6123aada7ad34566d2e27c73bccccdb8e7bf68dbcc18677f
SHA3-384 hash: 4d3fe02ec3d35ab958eb0aae61533c99572bdde05ac4a5c065857c4f218b600911313db0b4f76dffb8461363573e43d6
SHA1 hash: e35a1e0e1b45153e6808251c87146ecfd3ca26ad
MD5 hash: 732176a2ea3527b00b30cce08192a744
humanhash: nitrogen-red-edward-coffee
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'150 bytes
First seen:2025-10-12 09:21:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:vBDsBBmxyBtmrBqNqBsHIBo70Bb0vB7UVBgDEBxCpBe5iBsHOBlOfB282XZhBo7N:5DmmMtaqgsMosbG7WgUxmeIsala282pg
TLSH T11A5139843211FA783DBB5923A275450CB1406CF2ACDFFD848DEC28A5619DE00395A7E6
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://91.231.222.182/hiddenbin/vdataupdate.x86b7e2904a9fdb74cc2e8c04e7ceaa8b7d2a3a5a752243b69ed150b8491e17abcf Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.mips98014a1a30a3083ce8411d2ba2528e0ee90d480e614b43e857de6a4e74f8621d Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.arc6f1b64500e506c245d19785998a752ae36e6754e68c69091cfc39cd9d2a3b647 MiraiDEU elf geofenced mirai
http://91.231.222.182/hiddenbin/vdataupdate.i468n/an/aelf ua-wget
http://91.231.222.182/hiddenbin/vdataupdate.i686n/an/aelf ua-wget
http://91.231.222.182/hiddenbin/vdataupdate.x86_64n/an/aelf ua-wget
http://91.231.222.182/hiddenbin/vdataupdate.mpslf5b4f88a4c70399d89eb83083565fe01b942170cffc4ada739aefea648906ec8 MiraiDEU elf geofenced mirai
http://91.231.222.182/hiddenbin/vdataupdate.arm32ba56f7801b5581ee2f66eb3e21d80b5206681108037ac89e4bdafc8e4be290 Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.arm50ebc1ece17e20bc2e3152d15454bac3e2cffaac5a9c80402c42116fb6f88d869 Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.arm6a05ab194d7576fcba5653d583739bdc7e35e0a6191f0cd13b4ff75c4e1a81390 Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.arm73e017f7319cbf6940240abbd4926fbb5f08955caa986b99cec4baaa7eb78e1e9 Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.ppc533335400df9bfba7b527089f51bc084e66d9639e5c4545bda2c9357049785fe Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.spc083843febd5c0ea084e07b0199ae8a9a4a32a5983121fe6947143ba6a77a1a6f Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.m68k6429714379b972207fa45a94646773186684173a129cbfe1e5aa55b679afd023 Miraielf mirai
http://91.231.222.182/hiddenbin/vdataupdate.sh4599e5b086932a4c7a35874a5b185caea8405c0679bcfd031886c028aa13173d7 Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-12T04:12:00Z UTC
Last seen:
2025-10-12T10:09:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a5d02b56-1900-0000-5135-c2413c0f0000 pid=3900 /usr/bin/sudo guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903 /tmp/sample.bin guuid=a5d02b56-1900-0000-5135-c2413c0f0000 pid=3900->guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903 execve guuid=41faba58-1900-0000-5135-c241420f0000 pid=3906 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=41faba58-1900-0000-5135-c241420f0000 pid=3906 execve guuid=e263ac64-1900-0000-5135-c2416d0f0000 pid=3949 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=e263ac64-1900-0000-5135-c2416d0f0000 pid=3949 execve guuid=fb57d575-1900-0000-5135-c241a90f0000 pid=4009 /usr/bin/cat guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=fb57d575-1900-0000-5135-c241a90f0000 pid=4009 execve guuid=7e092a76-1900-0000-5135-c241ab0f0000 pid=4011 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7e092a76-1900-0000-5135-c241ab0f0000 pid=4011 execve guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013 execve guuid=a1ccbd76-1900-0000-5135-c241b20f0000 pid=4018 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=a1ccbd76-1900-0000-5135-c241b20f0000 pid=4018 execve guuid=79861a80-1900-0000-5135-c241db0f0000 pid=4059 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=79861a80-1900-0000-5135-c241db0f0000 pid=4059 execve guuid=8d30b18a-1900-0000-5135-c241fb0f0000 pid=4091 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=8d30b18a-1900-0000-5135-c241fb0f0000 pid=4091 clone guuid=6b3de98a-1900-0000-5135-c241fc0f0000 pid=4092 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=6b3de98a-1900-0000-5135-c241fc0f0000 pid=4092 execve guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094 execve guuid=c7faea90-1900-0000-5135-c24107100000 pid=4103 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=c7faea90-1900-0000-5135-c24107100000 pid=4103 execve guuid=691ca6a0-1900-0000-5135-c24126100000 pid=4134 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=691ca6a0-1900-0000-5135-c24126100000 pid=4134 execve guuid=7c1436b3-1900-0000-5135-c2414d100000 pid=4173 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7c1436b3-1900-0000-5135-c2414d100000 pid=4173 clone guuid=d52d62b3-1900-0000-5135-c2414e100000 pid=4174 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=d52d62b3-1900-0000-5135-c2414e100000 pid=4174 execve guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176 execve guuid=cbb1afb4-1900-0000-5135-c24156100000 pid=4182 /usr/bin/wget net send-data guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=cbb1afb4-1900-0000-5135-c24156100000 pid=4182 execve guuid=2b6a41bb-1900-0000-5135-c24172100000 pid=4210 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=2b6a41bb-1900-0000-5135-c24172100000 pid=4210 execve guuid=7c934ac3-1900-0000-5135-c24190100000 pid=4240 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7c934ac3-1900-0000-5135-c24190100000 pid=4240 clone guuid=12da67c3-1900-0000-5135-c24191100000 pid=4241 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=12da67c3-1900-0000-5135-c24191100000 pid=4241 execve guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245 execve guuid=dfc30dc4-1900-0000-5135-c24199100000 pid=4249 /usr/bin/wget net send-data guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=dfc30dc4-1900-0000-5135-c24199100000 pid=4249 execve guuid=4fddaeca-1900-0000-5135-c241b3100000 pid=4275 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=4fddaeca-1900-0000-5135-c241b3100000 pid=4275 execve guuid=319ad7d3-1900-0000-5135-c241d2100000 pid=4306 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=319ad7d3-1900-0000-5135-c241d2100000 pid=4306 clone guuid=db9605d4-1900-0000-5135-c241d4100000 pid=4308 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=db9605d4-1900-0000-5135-c241d4100000 pid=4308 execve guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310 execve guuid=b6580bd5-1900-0000-5135-c241da100000 pid=4314 /usr/bin/wget net send-data guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=b6580bd5-1900-0000-5135-c241da100000 pid=4314 execve guuid=b7db4fdc-1900-0000-5135-c241f0100000 pid=4336 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=b7db4fdc-1900-0000-5135-c241f0100000 pid=4336 execve guuid=506e13e6-1900-0000-5135-c2410b110000 pid=4363 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=506e13e6-1900-0000-5135-c2410b110000 pid=4363 clone guuid=dc223fe6-1900-0000-5135-c2410d110000 pid=4365 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=dc223fe6-1900-0000-5135-c2410d110000 pid=4365 execve guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369 execve guuid=105b07e7-1900-0000-5135-c24116110000 pid=4374 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=105b07e7-1900-0000-5135-c24116110000 pid=4374 execve guuid=aa2cf1ef-1900-0000-5135-c2413f110000 pid=4415 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=aa2cf1ef-1900-0000-5135-c2413f110000 pid=4415 execve guuid=b96ccbfb-1900-0000-5135-c2416d110000 pid=4461 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=b96ccbfb-1900-0000-5135-c2416d110000 pid=4461 clone guuid=59c3f1fb-1900-0000-5135-c2416e110000 pid=4462 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=59c3f1fb-1900-0000-5135-c2416e110000 pid=4462 execve guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464 execve guuid=9a4ba8fc-1900-0000-5135-c24175110000 pid=4469 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=9a4ba8fc-1900-0000-5135-c24175110000 pid=4469 execve guuid=294f4f07-1a00-0000-5135-c241a0110000 pid=4512 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=294f4f07-1a00-0000-5135-c241a0110000 pid=4512 execve guuid=a5a17013-1a00-0000-5135-c241c2110000 pid=4546 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=a5a17013-1a00-0000-5135-c241c2110000 pid=4546 clone guuid=5a699a13-1a00-0000-5135-c241c3110000 pid=4547 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=5a699a13-1a00-0000-5135-c241c3110000 pid=4547 execve guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548 execve guuid=55cd6914-1a00-0000-5135-c241c9110000 pid=4553 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=55cd6914-1a00-0000-5135-c241c9110000 pid=4553 execve guuid=f01b3e1d-1a00-0000-5135-c241d8110000 pid=4568 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=f01b3e1d-1a00-0000-5135-c241d8110000 pid=4568 execve guuid=74a34c29-1a00-0000-5135-c24101120000 pid=4609 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=74a34c29-1a00-0000-5135-c24101120000 pid=4609 clone guuid=9c797d29-1a00-0000-5135-c24103120000 pid=4611 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=9c797d29-1a00-0000-5135-c24103120000 pid=4611 execve guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615 execve guuid=bc79762a-1a00-0000-5135-c2410e120000 pid=4622 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=bc79762a-1a00-0000-5135-c2410e120000 pid=4622 execve guuid=b831ee33-1a00-0000-5135-c2412c120000 pid=4652 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=b831ee33-1a00-0000-5135-c2412c120000 pid=4652 execve guuid=9824d161-1a00-0000-5135-c2419b120000 pid=4763 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=9824d161-1a00-0000-5135-c2419b120000 pid=4763 clone guuid=7c04f861-1a00-0000-5135-c2419c120000 pid=4764 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7c04f861-1a00-0000-5135-c2419c120000 pid=4764 execve guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765 execve guuid=79d30663-1a00-0000-5135-c241a3120000 pid=4771 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=79d30663-1a00-0000-5135-c241a3120000 pid=4771 execve guuid=3af3ac6f-1a00-0000-5135-c241c8120000 pid=4808 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=3af3ac6f-1a00-0000-5135-c241c8120000 pid=4808 execve guuid=0c72907e-1a00-0000-5135-c241f2120000 pid=4850 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=0c72907e-1a00-0000-5135-c241f2120000 pid=4850 clone guuid=0308b67e-1a00-0000-5135-c241f3120000 pid=4851 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=0308b67e-1a00-0000-5135-c241f3120000 pid=4851 execve guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853 execve guuid=7c247a7f-1a00-0000-5135-c241fa120000 pid=4858 /usr/bin/wget net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=7c247a7f-1a00-0000-5135-c241fa120000 pid=4858 execve guuid=fdfd9e88-1a00-0000-5135-c24114130000 pid=4884 /usr/bin/curl net send-data write-file guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=fdfd9e88-1a00-0000-5135-c24114130000 pid=4884 execve guuid=9b582495-1a00-0000-5135-c2413a130000 pid=4922 /usr/bin/bash guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=9b582495-1a00-0000-5135-c2413a130000 pid=4922 clone guuid=5b1a5695-1a00-0000-5135-c2413c130000 pid=4924 /usr/bin/chmod guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=5b1a5695-1a00-0000-5135-c2413c130000 pid=4924 execve guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926 /tmp/WTF net guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926 execve guuid=a2047096-1a00-0000-5135-c24143130000 pid=4931 /usr/bin/wget net send-data write-file zombie guuid=0f2c5658-1900-0000-5135-c2413f0f0000 pid=3903->guuid=a2047096-1a00-0000-5135-c24143130000 pid=4931 execve 2278db12-a125-5e5c-94fb-c572a683d1c5 91.231.222.182:80 guuid=41faba58-1900-0000-5135-c241420f0000 pid=3906->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 154B guuid=e263ac64-1900-0000-5135-c2416d0f0000 pid=3949->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 103B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=75eca976-1900-0000-5135-c241af0f0000 pid=4015 /tmp/WTF zombie guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013->guuid=75eca976-1900-0000-5135-c241af0f0000 pid=4015 clone guuid=ebc8ad76-1900-0000-5135-c241b00f0000 pid=4016 /tmp/WTF guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013->guuid=ebc8ad76-1900-0000-5135-c241b00f0000 pid=4016 clone guuid=3adcb276-1900-0000-5135-c241b10f0000 pid=4017 /tmp/WTF net send-data zombie guuid=21377c76-1900-0000-5135-c241ad0f0000 pid=4013->guuid=3adcb276-1900-0000-5135-c241b10f0000 pid=4017 clone guuid=3adcb276-1900-0000-5135-c241b10f0000 pid=4017->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 547236c1-d19e-57d5-b5d6-251785f8d0c8 91.231.222.182:3778 guuid=3adcb276-1900-0000-5135-c241b10f0000 pid=4017->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 255B guuid=a1ccbd76-1900-0000-5135-c241b20f0000 pid=4018->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=79861a80-1900-0000-5135-c241db0f0000 pid=4059->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f3a0b58b-1900-0000-5135-c24100100000 pid=4096 /tmp/WTF guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094->guuid=f3a0b58b-1900-0000-5135-c24100100000 pid=4096 clone guuid=f3f7ba8b-1900-0000-5135-c24101100000 pid=4097 /tmp/WTF guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094->guuid=f3f7ba8b-1900-0000-5135-c24101100000 pid=4097 clone guuid=0ffabf8b-1900-0000-5135-c24102100000 pid=4098 /tmp/WTF net send-data zombie guuid=71866a8b-1900-0000-5135-c241fe0f0000 pid=4094->guuid=0ffabf8b-1900-0000-5135-c24102100000 pid=4098 clone guuid=0ffabf8b-1900-0000-5135-c24102100000 pid=4098->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0ffabf8b-1900-0000-5135-c24102100000 pid=4098->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 245B guuid=c7faea90-1900-0000-5135-c24107100000 pid=4103->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 154B guuid=691ca6a0-1900-0000-5135-c24126100000 pid=4134->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 103B guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6fa07eb4-1900-0000-5135-c24152100000 pid=4178 /tmp/WTF guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176->guuid=6fa07eb4-1900-0000-5135-c24152100000 pid=4178 clone guuid=178f88b4-1900-0000-5135-c24153100000 pid=4179 /tmp/WTF guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176->guuid=178f88b4-1900-0000-5135-c24153100000 pid=4179 clone guuid=65b391b4-1900-0000-5135-c24154100000 pid=4180 /tmp/WTF net send-data zombie guuid=8a1714b4-1900-0000-5135-c24150100000 pid=4176->guuid=65b391b4-1900-0000-5135-c24154100000 pid=4180 clone guuid=65b391b4-1900-0000-5135-c24154100000 pid=4180->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=65b391b4-1900-0000-5135-c24154100000 pid=4180->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 245B guuid=cbb1afb4-1900-0000-5135-c24156100000 pid=4182->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=2b6a41bb-1900-0000-5135-c24172100000 pid=4210->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a3eff5c3-1900-0000-5135-c24196100000 pid=4246 /tmp/WTF guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245->guuid=a3eff5c3-1900-0000-5135-c24196100000 pid=4246 clone guuid=4e2dfac3-1900-0000-5135-c24197100000 pid=4247 /tmp/WTF guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245->guuid=4e2dfac3-1900-0000-5135-c24197100000 pid=4247 clone guuid=5afafdc3-1900-0000-5135-c24198100000 pid=4248 /tmp/WTF net send-data zombie guuid=e0e9bfc3-1900-0000-5135-c24195100000 pid=4245->guuid=5afafdc3-1900-0000-5135-c24198100000 pid=4248 clone guuid=5afafdc3-1900-0000-5135-c24198100000 pid=4248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5afafdc3-1900-0000-5135-c24198100000 pid=4248->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 250B guuid=dfc30dc4-1900-0000-5135-c24199100000 pid=4249->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=4fddaeca-1900-0000-5135-c241b3100000 pid=4275->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba5fddd4-1900-0000-5135-c241d7100000 pid=4311 /tmp/WTF guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310->guuid=ba5fddd4-1900-0000-5135-c241d7100000 pid=4311 clone guuid=f58ae3d4-1900-0000-5135-c241d8100000 pid=4312 /tmp/WTF guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310->guuid=f58ae3d4-1900-0000-5135-c241d8100000 pid=4312 clone guuid=6b99ecd4-1900-0000-5135-c241d9100000 pid=4313 /tmp/WTF net send-data zombie guuid=21596fd4-1900-0000-5135-c241d6100000 pid=4310->guuid=6b99ecd4-1900-0000-5135-c241d9100000 pid=4313 clone guuid=6b99ecd4-1900-0000-5135-c241d9100000 pid=4313->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6b99ecd4-1900-0000-5135-c241d9100000 pid=4313->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 250B guuid=b6580bd5-1900-0000-5135-c241da100000 pid=4314->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 157B guuid=b7db4fdc-1900-0000-5135-c241f0100000 pid=4336->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 106B guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc01f2e6-1900-0000-5135-c24112110000 pid=4370 /tmp/WTF guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369->guuid=bc01f2e6-1900-0000-5135-c24112110000 pid=4370 clone guuid=0db8f6e6-1900-0000-5135-c24113110000 pid=4371 /tmp/WTF guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369->guuid=0db8f6e6-1900-0000-5135-c24113110000 pid=4371 clone guuid=1f3cfbe6-1900-0000-5135-c24114110000 pid=4372 /tmp/WTF net send-data zombie guuid=7954bce6-1900-0000-5135-c24111110000 pid=4369->guuid=1f3cfbe6-1900-0000-5135-c24114110000 pid=4372 clone guuid=1f3cfbe6-1900-0000-5135-c24114110000 pid=4372->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1f3cfbe6-1900-0000-5135-c24114110000 pid=4372->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 245B guuid=105b07e7-1900-0000-5135-c24116110000 pid=4374->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=aa2cf1ef-1900-0000-5135-c2413f110000 pid=4415->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6bc78cfc-1900-0000-5135-c24172110000 pid=4466 /tmp/WTF guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464->guuid=6bc78cfc-1900-0000-5135-c24172110000 pid=4466 clone guuid=45b091fc-1900-0000-5135-c24173110000 pid=4467 /tmp/WTF guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464->guuid=45b091fc-1900-0000-5135-c24173110000 pid=4467 clone guuid=8e1e97fc-1900-0000-5135-c24174110000 pid=4468 /tmp/WTF net send-data zombie guuid=82f244fc-1900-0000-5135-c24170110000 pid=4464->guuid=8e1e97fc-1900-0000-5135-c24174110000 pid=4468 clone guuid=8e1e97fc-1900-0000-5135-c24174110000 pid=4468->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8e1e97fc-1900-0000-5135-c24174110000 pid=4468->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 245B guuid=9a4ba8fc-1900-0000-5135-c24175110000 pid=4469->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 154B guuid=294f4f07-1a00-0000-5135-c241a0110000 pid=4512->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 103B guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=75454514-1a00-0000-5135-c241c5110000 pid=4549 /tmp/WTF guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548->guuid=75454514-1a00-0000-5135-c241c5110000 pid=4549 clone guuid=ad7f4914-1a00-0000-5135-c241c6110000 pid=4550 /tmp/WTF guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548->guuid=ad7f4914-1a00-0000-5135-c241c6110000 pid=4550 clone guuid=895a4f14-1a00-0000-5135-c241c7110000 pid=4551 /tmp/WTF net send-data zombie guuid=61e60414-1a00-0000-5135-c241c4110000 pid=4548->guuid=895a4f14-1a00-0000-5135-c241c7110000 pid=4551 clone guuid=895a4f14-1a00-0000-5135-c241c7110000 pid=4551->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=895a4f14-1a00-0000-5135-c241c7110000 pid=4551->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 240B guuid=55cd6914-1a00-0000-5135-c241c9110000 pid=4553->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=f01b3e1d-1a00-0000-5135-c241d8110000 pid=4568->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1089552a-1a00-0000-5135-c24108120000 pid=4616 /tmp/WTF guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615->guuid=1089552a-1a00-0000-5135-c24108120000 pid=4616 clone guuid=e3f15a2a-1a00-0000-5135-c24109120000 pid=4617 /tmp/WTF guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615->guuid=e3f15a2a-1a00-0000-5135-c24109120000 pid=4617 clone guuid=d651672a-1a00-0000-5135-c2410b120000 pid=4619 /tmp/WTF net send-data zombie guuid=c390042a-1a00-0000-5135-c24107120000 pid=4615->guuid=d651672a-1a00-0000-5135-c2410b120000 pid=4619 clone guuid=d651672a-1a00-0000-5135-c2410b120000 pid=4619->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d651672a-1a00-0000-5135-c2410b120000 pid=4619->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 250B guuid=bc79762a-1a00-0000-5135-c2410e120000 pid=4622->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=b831ee33-1a00-0000-5135-c2412c120000 pid=4652->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d02ce062-1a00-0000-5135-c241a0120000 pid=4768 /tmp/WTF guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765->guuid=d02ce062-1a00-0000-5135-c241a0120000 pid=4768 clone guuid=da9fea62-1a00-0000-5135-c241a1120000 pid=4769 /tmp/WTF guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765->guuid=da9fea62-1a00-0000-5135-c241a1120000 pid=4769 clone guuid=f698f362-1a00-0000-5135-c241a2120000 pid=4770 /tmp/WTF net send-data zombie guuid=67486062-1a00-0000-5135-c2419d120000 pid=4765->guuid=f698f362-1a00-0000-5135-c241a2120000 pid=4770 clone guuid=f698f362-1a00-0000-5135-c241a2120000 pid=4770->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f698f362-1a00-0000-5135-c241a2120000 pid=4770->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 235B guuid=79d30663-1a00-0000-5135-c241a3120000 pid=4771->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 155B guuid=3af3ac6f-1a00-0000-5135-c241c8120000 pid=4808->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 104B guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0b605f7f-1a00-0000-5135-c241f7120000 pid=4855 /tmp/WTF guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853->guuid=0b605f7f-1a00-0000-5135-c241f7120000 pid=4855 clone guuid=7a1f647f-1a00-0000-5135-c241f8120000 pid=4856 /tmp/WTF guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853->guuid=7a1f647f-1a00-0000-5135-c241f8120000 pid=4856 clone guuid=b49f6b7f-1a00-0000-5135-c241f9120000 pid=4857 /tmp/WTF net send-data zombie guuid=383b1f7f-1a00-0000-5135-c241f5120000 pid=4853->guuid=b49f6b7f-1a00-0000-5135-c241f9120000 pid=4857 clone guuid=b49f6b7f-1a00-0000-5135-c241f9120000 pid=4857->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b49f6b7f-1a00-0000-5135-c241f9120000 pid=4857->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 240B guuid=7c247a7f-1a00-0000-5135-c241fa120000 pid=4858->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 154B guuid=fdfd9e88-1a00-0000-5135-c24114130000 pid=4884->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 103B guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bb934f96-1a00-0000-5135-c2413f130000 pid=4927 /tmp/WTF guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926->guuid=bb934f96-1a00-0000-5135-c2413f130000 pid=4927 clone guuid=cffa5696-1a00-0000-5135-c24141130000 pid=4929 /tmp/WTF guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926->guuid=cffa5696-1a00-0000-5135-c24141130000 pid=4929 clone guuid=89f25d96-1a00-0000-5135-c24142130000 pid=4930 /tmp/WTF net send-data zombie guuid=4bcaf395-1a00-0000-5135-c2413e130000 pid=4926->guuid=89f25d96-1a00-0000-5135-c24142130000 pid=4930 clone guuid=89f25d96-1a00-0000-5135-c24142130000 pid=4930->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=89f25d96-1a00-0000-5135-c24142130000 pid=4930->547236c1-d19e-57d5-b5d6-251785f8d0c8 send: 240B guuid=a2047096-1a00-0000-5135-c24143130000 pid=4931->2278db12-a125-5e5c-94fb-c572a683d1c5 send: 154B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-12 07:44:05 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a43f6a8613ef0b1d6123aada7ad34566d2e27c73bccccdb8e7bf68dbcc18677f

(this sample)

  
Delivery method
Distributed via web download

Comments