MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 adb92a99d9554859fa43ffe596a7571c9fd07e2f14693d8553c72d01bba226bf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: adb92a99d9554859fa43ffe596a7571c9fd07e2f14693d8553c72d01bba226bf
SHA3-384 hash: d9fda835ef292cf658cdb9239d265466b81f8572382127cb7f8552b201a6b1bcf296e23aeb67189130ad4b13468c0808
SHA1 hash: f176dff949a4a83d8a6efb8ab36658cf5c4dada5
MD5 hash: 00d01bfe9e41cfea6b53bbff59d8eb81
humanhash: edward-tango-tennessee-east
File name:vitek.sh
Download: download sample
Signature Mirai
File size:3'729 bytes
First seen:2026-02-16 09:59:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:ior5o5joXdoTBTO9AwEoTIT90loTIT9OTloSsos8oj9LoayoJPo7ZoNzNtopspSA:frG5cXSTBTO9AwdTIT90aTIT90aSFsVJ
TLSH T1897131F656E14B321C629DB7B7A950277042908A94C7BF05EBE968B931EDD0C3088B5F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.144.64.166:81/epshteyn_x86_64354b42ba644a621b2d7c63da4fc4b62b93bcfed1962a761826e5a4d6d02db84a Miraimirai
http://45.144.64.166:81/epshteyn_i4868c252a0623638c441aa90a97e7df42a95281028630c578b24dade116955b72f0 Miraimirai
http://45.144.64.166:81/epshteyn_aarch64fa74adf19d58fd9dc812cdbbf22a1951de69ab9dbe21aec87389d507ad1f3146 Miraimirai
http://45.144.64.166:81/epshteyn_mips8281588e04600cbf3cece7261b73873618d8bb2fc451d81fd4bb34ad4f9e639d Miraimirai
http://45.144.64.166:81/epshteyn_mpsld5a387b1fa9e3b03ae0a055aebb844e73c8e1ed1728ba775bb74d918a015c5ef Miraimirai
http://45.144.64.166:81/epshteyn_mips32232d1fbbbc8d0807bfc4c3d236468687adbc92635be4969508d78e029561a10e Miraimirai
http://45.144.64.166:81/epshteyn_arc9a372e6e294b69861d246f5f316047e8fa27e2e970ebb6de1004b105dd9ecfb6 Miraimirai
http://45.144.64.166:81/epshteyn_arm4800a02b006e274ae455ae5f231cfcacfc69cdab5a99870c9adeed76c2fa298b5 Miraimirai
http://45.144.64.166:81/epshteyn_arm59ee3f6e4412df6a836e74081fcc01b5046d5bf3d07f7a97ca108867429730c82 Miraimirai
http://45.144.64.166:81/epshteyn_arm6cb5c01163888125d43f063b02c1a19cdf0a7aecfe8b175f8fbefde50db11232c Miraimirai
http://45.144.64.166:81/epshteyn_arm7918ca73a9ad98ae6b7d9129e22d4e8eae6841d54abadc76925af111aacfe6d00 Miraimirai
http://45.144.64.166:81/epshteyn_ppc07f0056010295dd01ef7292975d3738fdaaa4cf66e909a48fa3eff96aee53d1b Miraimirai
http://45.144.64.166:81/epshteyn_ppc440fe44ed151419ee10d36cbd20f0a7b6fae542b03ecae99ec215279ea39f0c049f Miraimirai
http://45.144.64.166:81/epshteyn_spc876e0e1290b19d3f26a7fcd4ee7c36239902009de02135e6cfbfca8269d95d2f Miraimirai
http://45.144.64.166:81/epshteyn_m68k3ecda2a7a6d13bafea629c41b5b8a35d8e129d873db178d17e1c69adc48a7540 Miraimirai
http://45.144.64.166:81/epshteyn_sh4b7588bde89df4af3e0e90f7fa0e4ae44e6fd4b9efcd515d6f76f1cd5ae70dfb6 Miraimirai
http://45.144.64.166:81/epshteyn_riscv320eb96a804a6097bc1827094043f6388d05f0b1920ad558de7024aa0941967402 Miraimirai
http://45.144.64.166:81/epshteyn_riscv64e648ddd49dcb88cc435bfa0bcdf643d39ccc27c21f901cbd472dd831f4ed317a Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=525ff321-1a00-0000-188a-83fd78090000 pid=2424 /usr/bin/sudo guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430 /tmp/sample.bin guuid=525ff321-1a00-0000-188a-83fd78090000 pid=2424->guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430 execve guuid=25284625-1a00-0000-188a-83fd7f090000 pid=2431 /usr/bin/cp guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=25284625-1a00-0000-188a-83fd7f090000 pid=2431 execve guuid=f2f30e2b-1a00-0000-188a-83fd8d090000 pid=2445 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f2f30e2b-1a00-0000-188a-83fd8d090000 pid=2445 execve guuid=45f23056-1a00-0000-188a-83fdbe090000 pid=2494 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=45f23056-1a00-0000-188a-83fdbe090000 pid=2494 execve guuid=8c39266a-1a00-0000-188a-83fde3090000 pid=2531 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=8c39266a-1a00-0000-188a-83fde3090000 pid=2531 execve guuid=660f6a6a-1a00-0000-188a-83fde5090000 pid=2533 /tmp/epshteyn_x86_64 delete-file net guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=660f6a6a-1a00-0000-188a-83fde5090000 pid=2533 execve guuid=69818a6a-1a00-0000-188a-83fde7090000 pid=2535 /usr/bin/rm guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=69818a6a-1a00-0000-188a-83fde7090000 pid=2535 execve guuid=40f7d26a-1a00-0000-188a-83fde9090000 pid=2537 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=40f7d26a-1a00-0000-188a-83fde9090000 pid=2537 execve guuid=f4f5b377-1a00-0000-188a-83fd020a0000 pid=2562 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f4f5b377-1a00-0000-188a-83fd020a0000 pid=2562 execve guuid=0626b486-1a00-0000-188a-83fd310a0000 pid=2609 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0626b486-1a00-0000-188a-83fd310a0000 pid=2609 execve guuid=635fff86-1a00-0000-188a-83fd320a0000 pid=2610 /tmp/epshteyn_i486 delete-file net guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=635fff86-1a00-0000-188a-83fd320a0000 pid=2610 execve guuid=13fb3687-1a00-0000-188a-83fd340a0000 pid=2612 /usr/bin/rm guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=13fb3687-1a00-0000-188a-83fd340a0000 pid=2612 execve guuid=9a76a587-1a00-0000-188a-83fd360a0000 pid=2614 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=9a76a587-1a00-0000-188a-83fd360a0000 pid=2614 execve guuid=aede209d-1a00-0000-188a-83fd7a0a0000 pid=2682 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=aede209d-1a00-0000-188a-83fd7a0a0000 pid=2682 execve guuid=8229d0b5-1a00-0000-188a-83fdbb0a0000 pid=2747 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=8229d0b5-1a00-0000-188a-83fdbb0a0000 pid=2747 execve guuid=4acb3db6-1a00-0000-188a-83fdbd0a0000 pid=2749 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=4acb3db6-1a00-0000-188a-83fdbd0a0000 pid=2749 clone guuid=1c4c1db7-1a00-0000-188a-83fdc10a0000 pid=2753 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=1c4c1db7-1a00-0000-188a-83fdc10a0000 pid=2753 execve guuid=d8668eb7-1a00-0000-188a-83fdc20a0000 pid=2754 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=d8668eb7-1a00-0000-188a-83fdc20a0000 pid=2754 execve guuid=b40b72c7-1a00-0000-188a-83fdde0a0000 pid=2782 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=b40b72c7-1a00-0000-188a-83fdde0a0000 pid=2782 execve guuid=dae043d8-1a00-0000-188a-83fdff0a0000 pid=2815 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=dae043d8-1a00-0000-188a-83fdff0a0000 pid=2815 execve guuid=5cea8dd8-1a00-0000-188a-83fd000b0000 pid=2816 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=5cea8dd8-1a00-0000-188a-83fd000b0000 pid=2816 clone guuid=616c67d9-1a00-0000-188a-83fd020b0000 pid=2818 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=616c67d9-1a00-0000-188a-83fd020b0000 pid=2818 execve guuid=0cd5c9d9-1a00-0000-188a-83fd030b0000 pid=2819 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0cd5c9d9-1a00-0000-188a-83fd030b0000 pid=2819 execve guuid=e38d71eb-1a00-0000-188a-83fd220b0000 pid=2850 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=e38d71eb-1a00-0000-188a-83fd220b0000 pid=2850 execve guuid=53b626fe-1a00-0000-188a-83fd500b0000 pid=2896 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=53b626fe-1a00-0000-188a-83fd500b0000 pid=2896 execve guuid=aefd76fe-1a00-0000-188a-83fd520b0000 pid=2898 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=aefd76fe-1a00-0000-188a-83fd520b0000 pid=2898 clone guuid=0af910ff-1a00-0000-188a-83fd560b0000 pid=2902 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0af910ff-1a00-0000-188a-83fd560b0000 pid=2902 execve guuid=ebff9cff-1a00-0000-188a-83fd590b0000 pid=2905 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=ebff9cff-1a00-0000-188a-83fd590b0000 pid=2905 execve guuid=7244e315-1b00-0000-188a-83fd7a0b0000 pid=2938 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=7244e315-1b00-0000-188a-83fd7a0b0000 pid=2938 execve guuid=51a4532f-1b00-0000-188a-83fd9a0b0000 pid=2970 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=51a4532f-1b00-0000-188a-83fd9a0b0000 pid=2970 execve guuid=f146d22f-1b00-0000-188a-83fd9b0b0000 pid=2971 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f146d22f-1b00-0000-188a-83fd9b0b0000 pid=2971 clone guuid=9cebf831-1b00-0000-188a-83fd9d0b0000 pid=2973 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=9cebf831-1b00-0000-188a-83fd9d0b0000 pid=2973 execve guuid=d1b45c32-1b00-0000-188a-83fd9f0b0000 pid=2975 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=d1b45c32-1b00-0000-188a-83fd9f0b0000 pid=2975 execve guuid=4cb8fe41-1b00-0000-188a-83fdc30b0000 pid=3011 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=4cb8fe41-1b00-0000-188a-83fdc30b0000 pid=3011 execve guuid=ed031452-1b00-0000-188a-83fdeb0b0000 pid=3051 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=ed031452-1b00-0000-188a-83fdeb0b0000 pid=3051 execve guuid=05d16852-1b00-0000-188a-83fded0b0000 pid=3053 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=05d16852-1b00-0000-188a-83fded0b0000 pid=3053 clone guuid=3ad7b553-1b00-0000-188a-83fdf20b0000 pid=3058 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=3ad7b553-1b00-0000-188a-83fdf20b0000 pid=3058 execve guuid=1dab0154-1b00-0000-188a-83fdf40b0000 pid=3060 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=1dab0154-1b00-0000-188a-83fdf40b0000 pid=3060 execve guuid=410be262-1b00-0000-188a-83fd1d0c0000 pid=3101 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=410be262-1b00-0000-188a-83fd1d0c0000 pid=3101 execve guuid=77042075-1b00-0000-188a-83fd460c0000 pid=3142 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=77042075-1b00-0000-188a-83fd460c0000 pid=3142 execve guuid=47b78775-1b00-0000-188a-83fd480c0000 pid=3144 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=47b78775-1b00-0000-188a-83fd480c0000 pid=3144 clone guuid=61196376-1b00-0000-188a-83fd4c0c0000 pid=3148 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=61196376-1b00-0000-188a-83fd4c0c0000 pid=3148 execve guuid=0cd0ca76-1b00-0000-188a-83fd4e0c0000 pid=3150 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0cd0ca76-1b00-0000-188a-83fd4e0c0000 pid=3150 execve guuid=23a77b85-1b00-0000-188a-83fd7a0c0000 pid=3194 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=23a77b85-1b00-0000-188a-83fd7a0c0000 pid=3194 execve guuid=5a604696-1b00-0000-188a-83fd980c0000 pid=3224 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=5a604696-1b00-0000-188a-83fd980c0000 pid=3224 execve guuid=4cb6af96-1b00-0000-188a-83fd990c0000 pid=3225 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=4cb6af96-1b00-0000-188a-83fd990c0000 pid=3225 clone guuid=d1ada999-1b00-0000-188a-83fd9b0c0000 pid=3227 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=d1ada999-1b00-0000-188a-83fd9b0c0000 pid=3227 execve guuid=4d9e0d9a-1b00-0000-188a-83fd9c0c0000 pid=3228 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=4d9e0d9a-1b00-0000-188a-83fd9c0c0000 pid=3228 execve guuid=b129c6a9-1b00-0000-188a-83fdb00c0000 pid=3248 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=b129c6a9-1b00-0000-188a-83fdb00c0000 pid=3248 execve guuid=5ad147bb-1b00-0000-188a-83fdc20c0000 pid=3266 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=5ad147bb-1b00-0000-188a-83fdc20c0000 pid=3266 execve guuid=02344bbc-1b00-0000-188a-83fdc30c0000 pid=3267 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=02344bbc-1b00-0000-188a-83fdc30c0000 pid=3267 clone guuid=6882e8bd-1b00-0000-188a-83fdc50c0000 pid=3269 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=6882e8bd-1b00-0000-188a-83fdc50c0000 pid=3269 execve guuid=72e65fbe-1b00-0000-188a-83fdc60c0000 pid=3270 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=72e65fbe-1b00-0000-188a-83fdc60c0000 pid=3270 execve guuid=7ad6bacf-1b00-0000-188a-83fdd60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=7ad6bacf-1b00-0000-188a-83fdd60c0000 pid=3286 execve guuid=f256e1e0-1b00-0000-188a-83fdf60c0000 pid=3318 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f256e1e0-1b00-0000-188a-83fdf60c0000 pid=3318 execve guuid=2e0739e1-1b00-0000-188a-83fdf70c0000 pid=3319 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=2e0739e1-1b00-0000-188a-83fdf70c0000 pid=3319 clone guuid=fe27f5e1-1b00-0000-188a-83fdfb0c0000 pid=3323 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=fe27f5e1-1b00-0000-188a-83fdfb0c0000 pid=3323 execve guuid=c27878e2-1b00-0000-188a-83fdfe0c0000 pid=3326 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=c27878e2-1b00-0000-188a-83fdfe0c0000 pid=3326 execve guuid=7afb45f2-1b00-0000-188a-83fd250d0000 pid=3365 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=7afb45f2-1b00-0000-188a-83fd250d0000 pid=3365 execve guuid=45af0304-1c00-0000-188a-83fd4c0d0000 pid=3404 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=45af0304-1c00-0000-188a-83fd4c0d0000 pid=3404 execve guuid=fd186804-1c00-0000-188a-83fd4e0d0000 pid=3406 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=fd186804-1c00-0000-188a-83fd4e0d0000 pid=3406 clone guuid=d157fc04-1c00-0000-188a-83fd520d0000 pid=3410 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=d157fc04-1c00-0000-188a-83fd520d0000 pid=3410 execve guuid=2ab57505-1c00-0000-188a-83fd540d0000 pid=3412 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=2ab57505-1c00-0000-188a-83fd540d0000 pid=3412 execve guuid=d12b1a15-1c00-0000-188a-83fd7a0d0000 pid=3450 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=d12b1a15-1c00-0000-188a-83fd7a0d0000 pid=3450 execve guuid=5c743c25-1c00-0000-188a-83fdb10d0000 pid=3505 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=5c743c25-1c00-0000-188a-83fdb10d0000 pid=3505 execve guuid=48858d25-1c00-0000-188a-83fdb30d0000 pid=3507 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=48858d25-1c00-0000-188a-83fdb30d0000 pid=3507 clone guuid=44156326-1c00-0000-188a-83fdb70d0000 pid=3511 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=44156326-1c00-0000-188a-83fdb70d0000 pid=3511 execve guuid=cf9bb526-1c00-0000-188a-83fdb90d0000 pid=3513 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=cf9bb526-1c00-0000-188a-83fdb90d0000 pid=3513 execve guuid=36268c3b-1c00-0000-188a-83fded0d0000 pid=3565 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=36268c3b-1c00-0000-188a-83fded0d0000 pid=3565 execve guuid=58cad446-1c00-0000-188a-83fd000e0000 pid=3584 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=58cad446-1c00-0000-188a-83fd000e0000 pid=3584 execve guuid=f9db2247-1c00-0000-188a-83fd020e0000 pid=3586 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f9db2247-1c00-0000-188a-83fd020e0000 pid=3586 clone guuid=7f4ab447-1c00-0000-188a-83fd050e0000 pid=3589 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=7f4ab447-1c00-0000-188a-83fd050e0000 pid=3589 execve guuid=0da98148-1c00-0000-188a-83fd060e0000 pid=3590 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0da98148-1c00-0000-188a-83fd060e0000 pid=3590 execve guuid=f7196f57-1c00-0000-188a-83fd220e0000 pid=3618 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f7196f57-1c00-0000-188a-83fd220e0000 pid=3618 execve guuid=911dee66-1c00-0000-188a-83fd4c0e0000 pid=3660 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=911dee66-1c00-0000-188a-83fd4c0e0000 pid=3660 execve guuid=147b2e67-1c00-0000-188a-83fd4e0e0000 pid=3662 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=147b2e67-1c00-0000-188a-83fd4e0e0000 pid=3662 clone guuid=37acb467-1c00-0000-188a-83fd520e0000 pid=3666 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=37acb467-1c00-0000-188a-83fd520e0000 pid=3666 execve guuid=786e1868-1c00-0000-188a-83fd530e0000 pid=3667 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=786e1868-1c00-0000-188a-83fd530e0000 pid=3667 execve guuid=49fd4277-1c00-0000-188a-83fd7c0e0000 pid=3708 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=49fd4277-1c00-0000-188a-83fd7c0e0000 pid=3708 execve guuid=cde72c88-1c00-0000-188a-83fda50e0000 pid=3749 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=cde72c88-1c00-0000-188a-83fda50e0000 pid=3749 execve guuid=acb5b288-1c00-0000-188a-83fda60e0000 pid=3750 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=acb5b288-1c00-0000-188a-83fda60e0000 pid=3750 clone guuid=0833ad89-1c00-0000-188a-83fda80e0000 pid=3752 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=0833ad89-1c00-0000-188a-83fda80e0000 pid=3752 execve guuid=2128148a-1c00-0000-188a-83fda90e0000 pid=3753 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=2128148a-1c00-0000-188a-83fda90e0000 pid=3753 execve guuid=ba8dc79f-1c00-0000-188a-83fdcf0e0000 pid=3791 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=ba8dc79f-1c00-0000-188a-83fdcf0e0000 pid=3791 execve guuid=589784b6-1c00-0000-188a-83fd160f0000 pid=3862 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=589784b6-1c00-0000-188a-83fd160f0000 pid=3862 execve guuid=5b44e7b6-1c00-0000-188a-83fd1a0f0000 pid=3866 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=5b44e7b6-1c00-0000-188a-83fd1a0f0000 pid=3866 clone guuid=ddfeb3b7-1c00-0000-188a-83fd1c0f0000 pid=3868 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=ddfeb3b7-1c00-0000-188a-83fd1c0f0000 pid=3868 execve guuid=83f604b8-1c00-0000-188a-83fd1d0f0000 pid=3869 /usr/bin/wget net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=83f604b8-1c00-0000-188a-83fd1d0f0000 pid=3869 execve guuid=7d512ecc-1c00-0000-188a-83fd1e0f0000 pid=3870 /usr/bin/curl net send-data write-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=7d512ecc-1c00-0000-188a-83fd1e0f0000 pid=3870 execve guuid=639e9fe7-1c00-0000-188a-83fd260f0000 pid=3878 /usr/bin/chmod guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=639e9fe7-1c00-0000-188a-83fd260f0000 pid=3878 execve guuid=f5474ee8-1c00-0000-188a-83fd2a0f0000 pid=3882 /usr/bin/bash guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=f5474ee8-1c00-0000-188a-83fd2a0f0000 pid=3882 clone guuid=86422ae9-1c00-0000-188a-83fd2f0f0000 pid=3887 /usr/bin/rm delete-file guuid=f045e824-1a00-0000-188a-83fd7e090000 pid=2430->guuid=86422ae9-1c00-0000-188a-83fd2f0f0000 pid=3887 execve 77639cd7-c402-5514-8f87-f0d3cc8fa2c2 45.144.64.166:81 guuid=f2f30e2b-1a00-0000-188a-83fd8d090000 pid=2445->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=45f23056-1a00-0000-188a-83fdbe090000 pid=2494->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=660f6a6a-1a00-0000-188a-83fde5090000 pid=2533->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=40f7d26a-1a00-0000-188a-83fde9090000 pid=2537->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=f4f5b377-1a00-0000-188a-83fd020a0000 pid=2562->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=635fff86-1a00-0000-188a-83fd320a0000 pid=2610->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9a76a587-1a00-0000-188a-83fd360a0000 pid=2614->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=aede209d-1a00-0000-188a-83fd7a0a0000 pid=2682->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B guuid=d8668eb7-1a00-0000-188a-83fdc20a0000 pid=2754->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=b40b72c7-1a00-0000-188a-83fdde0a0000 pid=2782->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=0cd5c9d9-1a00-0000-188a-83fd030b0000 pid=2819->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=e38d71eb-1a00-0000-188a-83fd220b0000 pid=2850->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=ebff9cff-1a00-0000-188a-83fd590b0000 pid=2905->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=7244e315-1b00-0000-188a-83fd7a0b0000 pid=2938->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B guuid=d1b45c32-1b00-0000-188a-83fd9f0b0000 pid=2975->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=4cb8fe41-1b00-0000-188a-83fdc30b0000 pid=3011->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=1dab0154-1b00-0000-188a-83fdf40b0000 pid=3060->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=410be262-1b00-0000-188a-83fd1d0c0000 pid=3101->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=0cd0ca76-1b00-0000-188a-83fd4e0c0000 pid=3150->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=23a77b85-1b00-0000-188a-83fd7a0c0000 pid=3194->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=4d9e0d9a-1b00-0000-188a-83fd9c0c0000 pid=3228->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=b129c6a9-1b00-0000-188a-83fdb00c0000 pid=3248->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=72e65fbe-1b00-0000-188a-83fdc60c0000 pid=3270->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=7ad6bacf-1b00-0000-188a-83fdd60c0000 pid=3286->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=c27878e2-1b00-0000-188a-83fdfe0c0000 pid=3326->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=7afb45f2-1b00-0000-188a-83fd250d0000 pid=3365->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=2ab57505-1c00-0000-188a-83fd540d0000 pid=3412->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=d12b1a15-1c00-0000-188a-83fd7a0d0000 pid=3450->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B guuid=cf9bb526-1c00-0000-188a-83fdb90d0000 pid=3513->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=36268c3b-1c00-0000-188a-83fded0d0000 pid=3565->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=0da98148-1c00-0000-188a-83fd060e0000 pid=3590->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=f7196f57-1c00-0000-188a-83fd220e0000 pid=3618->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=786e1868-1c00-0000-188a-83fd530e0000 pid=3667->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=49fd4277-1c00-0000-188a-83fd7c0e0000 pid=3708->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=2128148a-1c00-0000-188a-83fda90e0000 pid=3753->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=ba8dc79f-1c00-0000-188a-83fdcf0e0000 pid=3791->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B guuid=83f604b8-1c00-0000-188a-83fd1d0f0000 pid=3869->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=7d512ecc-1c00-0000-188a-83fd1e0f0000 pid=3870->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-16 10:00:44 UTC
File Type:
Text (Shell)
AV detection:
20 of 35 (57.14%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks SCSI settings
Checks hardware identifiers (DMI)
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh adb92a99d9554859fa43ffe596a7571c9fd07e2f14693d8553c72d01bba226bf

(this sample)

  
Delivery method
Distributed via web download

Comments