MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b63483689d2533e0583b7f7a93033143d2532f87482df48654fceb5b9af314ad. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: b63483689d2533e0583b7f7a93033143d2532f87482df48654fceb5b9af314ad
SHA3-384 hash: 900898c3d9281f6a6d1416e3613f56ee79961aa68e63e73e017ff3e1ba3a7051f2eac999170a5d4e6ab248c910cb0df7
SHA1 hash: 3a8eefdb7ef6835149b7ac03899d990c0c3e9f71
MD5 hash: 9a2a42a250f86964815c4e45cb50868a
humanhash: alanine-mars-emma-six
File name:thefuiodaas
Download: download sample
Signature Mirai
File size:3'333 bytes
First seen:2025-11-25 08:07:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:ibnWbgUbpKbGwbuYbjKbfOb2OLbZSbMMbmgbxs3bjGb6E2:enCgspWGouAjWfq24ZOM0mYxsrjy6z
TLSH T1A96184F6C2C282609EA1D532B3698A047C49F5F3F4C67E145DFA25AEF48DE443025E4B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.x86a6d331329e20d8b21c5dadfb92da75d046f1ac0d128dea8e58272e11043a83cc Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.mipse4fb13d2b1039326615b6ea97cc2418b73d3dc532aeaa2273a191d3433f9f3f6 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.arc49b987b7e71921dbeaa61d49dfd8f5f4b9e5fddd3c347925ae42763657960e75 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.i686c9a0db8b4b1a657625526fd09ffd9773c757a76d2fa465b10f751ca11abb36b7 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.x86_6483e12a989f190473be130ff7fa6f5ae86e2eabbe6aa789f643c2b80add1596f0 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.mpsl3d404058829b47f37e70e35e2835ef6033dc61254cca44318056ad755008ec41 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.arm77c95a977bc212cfc3c0c5e918a94b1925df9a086e291e7f84f315573f901577 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.arm52c435aa90ca3e34078572097627afd1610f64fcec5e8cc08dad41df8762ef2e3 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.arm6fce2a09a5e4f12d48fd9c2232cac167069ee072a9613a1462fe0c0893156b00c Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.arm7fe81c5cd324b6e4214cd4508a03a773e4a5f8a94bdc7fb8b124d48c818c738d1 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.ppcea59147e911f1056f8bae2e426054ad996f4b7ff053a8917fe02bb5c5eab74f9 Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.spc3cb48d24602d099c3d56eb628427e45e14d98d714e8640faadb04b2be719748a Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.m68ke8d3cf36f0a1d65447fad7d8da173f2f9f9767b9ed96443f86eae34e60c4be5b Miraielf mirai ua-wget
http://178.239.149.17/x7k2m9v8b/m9x7k2v8b3.sh45a4f236030744f7284ea200a1eb67ac8e041f7bb6bfa32513d8a3af3b44dc46a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai obfuscated
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-25T05:47:00Z UTC
Last seen:
2025-11-26T12:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=6b6d7a03-1800-0000-12e7-fd3c640c0000 pid=3172 /usr/bin/sudo guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173 /tmp/sample.bin guuid=6b6d7a03-1800-0000-12e7-fd3c640c0000 pid=3172->guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173 execve guuid=0a109906-1800-0000-12e7-fd3c660c0000 pid=3174 /usr/bin/cp guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=0a109906-1800-0000-12e7-fd3c660c0000 pid=3174 execve guuid=7ef4c80b-1800-0000-12e7-fd3c670c0000 pid=3175 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=7ef4c80b-1800-0000-12e7-fd3c670c0000 pid=3175 execve guuid=8d06021f-1800-0000-12e7-fd3c810c0000 pid=3201 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=8d06021f-1800-0000-12e7-fd3c810c0000 pid=3201 execve guuid=e28d5632-1800-0000-12e7-fd3c8d0c0000 pid=3213 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=e28d5632-1800-0000-12e7-fd3c8d0c0000 pid=3213 execve guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214 /tmp/m9x7k2v8b3.x86 net guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214 execve guuid=0fc50460-1900-0000-12e7-fd3c500e0000 pid=3664 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=0fc50460-1900-0000-12e7-fd3c500e0000 pid=3664 execve guuid=987a5d66-1900-0000-12e7-fd3c540e0000 pid=3668 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=987a5d66-1900-0000-12e7-fd3c540e0000 pid=3668 execve guuid=066de975-1900-0000-12e7-fd3c670e0000 pid=3687 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=066de975-1900-0000-12e7-fd3c670e0000 pid=3687 execve guuid=87ee8488-1900-0000-12e7-fd3c8e0e0000 pid=3726 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=87ee8488-1900-0000-12e7-fd3c8e0e0000 pid=3726 execve guuid=35000489-1900-0000-12e7-fd3c900e0000 pid=3728 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=35000489-1900-0000-12e7-fd3c900e0000 pid=3728 clone guuid=6bfff88a-1900-0000-12e7-fd3c980e0000 pid=3736 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=6bfff88a-1900-0000-12e7-fd3c980e0000 pid=3736 execve guuid=41f6698b-1900-0000-12e7-fd3c990e0000 pid=3737 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=41f6698b-1900-0000-12e7-fd3c990e0000 pid=3737 execve guuid=87a887a7-1900-0000-12e7-fd3cd70e0000 pid=3799 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=87a887a7-1900-0000-12e7-fd3cd70e0000 pid=3799 execve guuid=3ef6b8c1-1900-0000-12e7-fd3c290f0000 pid=3881 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=3ef6b8c1-1900-0000-12e7-fd3c290f0000 pid=3881 execve guuid=07b23ec2-1900-0000-12e7-fd3c2d0f0000 pid=3885 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=07b23ec2-1900-0000-12e7-fd3c2d0f0000 pid=3885 clone guuid=796c74c4-1900-0000-12e7-fd3c340f0000 pid=3892 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=796c74c4-1900-0000-12e7-fd3c340f0000 pid=3892 execve guuid=4061e9c4-1900-0000-12e7-fd3c360f0000 pid=3894 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=4061e9c4-1900-0000-12e7-fd3c360f0000 pid=3894 execve guuid=9f2cb8d3-1900-0000-12e7-fd3c5e0f0000 pid=3934 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=9f2cb8d3-1900-0000-12e7-fd3c5e0f0000 pid=3934 execve guuid=292a14e6-1900-0000-12e7-fd3c9b0f0000 pid=3995 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=292a14e6-1900-0000-12e7-fd3c9b0f0000 pid=3995 execve guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997 /tmp/m9x7k2v8b3.i686 net guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997 execve guuid=ddc1a113-1b00-0000-12e7-fd3c8c120000 pid=4748 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=ddc1a113-1b00-0000-12e7-fd3c8c120000 pid=4748 execve guuid=c3c13414-1b00-0000-12e7-fd3c8d120000 pid=4749 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c3c13414-1b00-0000-12e7-fd3c8d120000 pid=4749 execve guuid=7d0b7424-1b00-0000-12e7-fd3ca3120000 pid=4771 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=7d0b7424-1b00-0000-12e7-fd3ca3120000 pid=4771 execve guuid=6f31003d-1b00-0000-12e7-fd3ce6120000 pid=4838 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=6f31003d-1b00-0000-12e7-fd3ce6120000 pid=4838 execve guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840 /tmp/m9x7k2v8b3.x86_64 mprotect-exec net guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840 execve guuid=9cc13469-1c00-0000-12e7-fd3c90140000 pid=5264 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=9cc13469-1c00-0000-12e7-fd3c90140000 pid=5264 execve guuid=668d8d69-1c00-0000-12e7-fd3c91140000 pid=5265 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=668d8d69-1c00-0000-12e7-fd3c91140000 pid=5265 execve guuid=e410287d-1c00-0000-12e7-fd3c92140000 pid=5266 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=e410287d-1c00-0000-12e7-fd3c92140000 pid=5266 execve guuid=e164fb98-1c00-0000-12e7-fd3c93140000 pid=5267 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=e164fb98-1c00-0000-12e7-fd3c93140000 pid=5267 execve guuid=e957b899-1c00-0000-12e7-fd3c94140000 pid=5268 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=e957b899-1c00-0000-12e7-fd3c94140000 pid=5268 clone guuid=c57d849a-1c00-0000-12e7-fd3c96140000 pid=5270 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c57d849a-1c00-0000-12e7-fd3c96140000 pid=5270 execve guuid=f0ce0aa1-1c00-0000-12e7-fd3c97140000 pid=5271 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=f0ce0aa1-1c00-0000-12e7-fd3c97140000 pid=5271 execve guuid=d38cc4b1-1c00-0000-12e7-fd3c9f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=d38cc4b1-1c00-0000-12e7-fd3c9f140000 pid=5279 execve guuid=ed8d87ca-1c00-0000-12e7-fd3ca0140000 pid=5280 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=ed8d87ca-1c00-0000-12e7-fd3ca0140000 pid=5280 execve guuid=614436cb-1c00-0000-12e7-fd3ca1140000 pid=5281 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=614436cb-1c00-0000-12e7-fd3ca1140000 pid=5281 clone guuid=499419cc-1c00-0000-12e7-fd3ca3140000 pid=5283 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=499419cc-1c00-0000-12e7-fd3ca3140000 pid=5283 execve guuid=08e87ecc-1c00-0000-12e7-fd3ca4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=08e87ecc-1c00-0000-12e7-fd3ca4140000 pid=5284 execve guuid=b3694bde-1c00-0000-12e7-fd3ca5140000 pid=5285 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=b3694bde-1c00-0000-12e7-fd3ca5140000 pid=5285 execve guuid=03adf8ee-1c00-0000-12e7-fd3ca6140000 pid=5286 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=03adf8ee-1c00-0000-12e7-fd3ca6140000 pid=5286 execve guuid=606187ef-1c00-0000-12e7-fd3ca7140000 pid=5287 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=606187ef-1c00-0000-12e7-fd3ca7140000 pid=5287 clone guuid=b949bff1-1c00-0000-12e7-fd3ca9140000 pid=5289 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=b949bff1-1c00-0000-12e7-fd3ca9140000 pid=5289 execve guuid=c7fd632c-1d00-0000-12e7-fd3cab140000 pid=5291 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c7fd632c-1d00-0000-12e7-fd3cab140000 pid=5291 execve guuid=67ce0f40-1d00-0000-12e7-fd3cae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=67ce0f40-1d00-0000-12e7-fd3cae140000 pid=5294 execve guuid=f28ab958-1d00-0000-12e7-fd3cb7140000 pid=5303 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=f28ab958-1d00-0000-12e7-fd3cb7140000 pid=5303 execve guuid=4099a75c-1d00-0000-12e7-fd3cbb140000 pid=5307 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=4099a75c-1d00-0000-12e7-fd3cbb140000 pid=5307 clone guuid=884f7b5d-1d00-0000-12e7-fd3cbe140000 pid=5310 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=884f7b5d-1d00-0000-12e7-fd3cbe140000 pid=5310 execve guuid=bec0da5d-1d00-0000-12e7-fd3cbf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=bec0da5d-1d00-0000-12e7-fd3cbf140000 pid=5311 execve guuid=2619f870-1d00-0000-12e7-fd3ccb140000 pid=5323 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=2619f870-1d00-0000-12e7-fd3ccb140000 pid=5323 execve guuid=febaaf8f-1d00-0000-12e7-fd3ccc140000 pid=5324 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=febaaf8f-1d00-0000-12e7-fd3ccc140000 pid=5324 execve guuid=6e4e4490-1d00-0000-12e7-fd3ccd140000 pid=5325 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=6e4e4490-1d00-0000-12e7-fd3ccd140000 pid=5325 clone guuid=7fa68191-1d00-0000-12e7-fd3ccf140000 pid=5327 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=7fa68191-1d00-0000-12e7-fd3ccf140000 pid=5327 execve guuid=21913e92-1d00-0000-12e7-fd3cd0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=21913e92-1d00-0000-12e7-fd3cd0140000 pid=5328 execve guuid=2e378da2-1d00-0000-12e7-fd3cd1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=2e378da2-1d00-0000-12e7-fd3cd1140000 pid=5329 execve guuid=52d6aab7-1d00-0000-12e7-fd3cd8140000 pid=5336 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=52d6aab7-1d00-0000-12e7-fd3cd8140000 pid=5336 execve guuid=275f0eb8-1d00-0000-12e7-fd3cd9140000 pid=5337 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=275f0eb8-1d00-0000-12e7-fd3cd9140000 pid=5337 clone guuid=e6ae62b9-1d00-0000-12e7-fd3cdb140000 pid=5339 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=e6ae62b9-1d00-0000-12e7-fd3cdb140000 pid=5339 execve guuid=1ac83eba-1d00-0000-12e7-fd3cdc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=1ac83eba-1d00-0000-12e7-fd3cdc140000 pid=5340 execve guuid=79ba6bd0-1d00-0000-12e7-fd3ce4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=79ba6bd0-1d00-0000-12e7-fd3ce4140000 pid=5348 execve guuid=6c31e7ec-1d00-0000-12e7-fd3ce8140000 pid=5352 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=6c31e7ec-1d00-0000-12e7-fd3ce8140000 pid=5352 execve guuid=7ba941ed-1d00-0000-12e7-fd3ce9140000 pid=5353 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=7ba941ed-1d00-0000-12e7-fd3ce9140000 pid=5353 clone guuid=c2580eee-1d00-0000-12e7-fd3ceb140000 pid=5355 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c2580eee-1d00-0000-12e7-fd3ceb140000 pid=5355 execve guuid=832968ee-1d00-0000-12e7-fd3cec140000 pid=5356 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=832968ee-1d00-0000-12e7-fd3cec140000 pid=5356 execve guuid=ecc02405-1e00-0000-12e7-fd3cfd140000 pid=5373 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=ecc02405-1e00-0000-12e7-fd3cfd140000 pid=5373 execve guuid=c892c71a-1e00-0000-12e7-fd3cfe140000 pid=5374 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c892c71a-1e00-0000-12e7-fd3cfe140000 pid=5374 execve guuid=c2650d1b-1e00-0000-12e7-fd3cff140000 pid=5375 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=c2650d1b-1e00-0000-12e7-fd3cff140000 pid=5375 clone guuid=b2b0ac1c-1e00-0000-12e7-fd3c01150000 pid=5377 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=b2b0ac1c-1e00-0000-12e7-fd3c01150000 pid=5377 execve guuid=76072d1d-1e00-0000-12e7-fd3c02150000 pid=5378 /usr/bin/wget net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=76072d1d-1e00-0000-12e7-fd3c02150000 pid=5378 execve guuid=9d16d549-1e00-0000-12e7-fd3c03150000 pid=5379 /usr/bin/curl net send-data write-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=9d16d549-1e00-0000-12e7-fd3c03150000 pid=5379 execve guuid=49308661-1e00-0000-12e7-fd3c04150000 pid=5380 /usr/bin/chmod guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=49308661-1e00-0000-12e7-fd3c04150000 pid=5380 execve guuid=23381262-1e00-0000-12e7-fd3c05150000 pid=5381 /usr/bin/bash guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=23381262-1e00-0000-12e7-fd3c05150000 pid=5381 clone guuid=03c56863-1e00-0000-12e7-fd3c07150000 pid=5383 /usr/bin/rm delete-file guuid=ff50b305-1800-0000-12e7-fd3c650c0000 pid=3173->guuid=03c56863-1e00-0000-12e7-fd3c07150000 pid=5383 execve 0d978787-977c-56f2-9ffb-c253cca25f19 178.239.149.17:80 guuid=7ef4c80b-1800-0000-12e7-fd3c670c0000 pid=3175->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=8d06021f-1800-0000-12e7-fd3c810c0000 pid=3201->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06da8233-1800-0000-12e7-fd3c8f0c0000 pid=3215 /tmp/m9x7k2v8b3.x86 guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214->guuid=06da8233-1800-0000-12e7-fd3c8f0c0000 pid=3215 clone guuid=7a23d85f-1900-0000-12e7-fd3c4e0e0000 pid=3662 /tmp/m9x7k2v8b3.x86 guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214->guuid=7a23d85f-1900-0000-12e7-fd3c4e0e0000 pid=3662 clone guuid=52e3e35f-1900-0000-12e7-fd3c4f0e0000 pid=3663 /tmp/m9x7k2v8b3.x86 net send-data zombie guuid=5c19d832-1800-0000-12e7-fd3c8e0c0000 pid=3214->guuid=52e3e35f-1900-0000-12e7-fd3c4f0e0000 pid=3663 clone guuid=43238a33-1800-0000-12e7-fd3c900c0000 pid=3216 /tmp/m9x7k2v8b3.x86 guuid=06da8233-1800-0000-12e7-fd3c8f0c0000 pid=3215->guuid=43238a33-1800-0000-12e7-fd3c900c0000 pid=3216 clone guuid=bea59133-1800-0000-12e7-fd3c910c0000 pid=3217 /tmp/m9x7k2v8b3.x86 dns net send-data zombie guuid=06da8233-1800-0000-12e7-fd3c8f0c0000 pid=3215->guuid=bea59133-1800-0000-12e7-fd3c910c0000 pid=3217 clone guuid=bea59133-1800-0000-12e7-fd3c910c0000 pid=3217->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B 852eada3-51ac-5275-909a-778490b5e6b0 play.mclighthouse.ir:6742 guuid=bea59133-1800-0000-12e7-fd3c910c0000 pid=3217->852eada3-51ac-5275-909a-778490b5e6b0 send: 44B guuid=52e3e35f-1900-0000-12e7-fd3c4f0e0000 pid=3663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=52e3e35f-1900-0000-12e7-fd3c4f0e0000 pid=3663->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B guuid=987a5d66-1900-0000-12e7-fd3c540e0000 pid=3668->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=066de975-1900-0000-12e7-fd3c670e0000 pid=3687->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=41f6698b-1900-0000-12e7-fd3c990e0000 pid=3737->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=87a887a7-1900-0000-12e7-fd3cd70e0000 pid=3799->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B guuid=4061e9c4-1900-0000-12e7-fd3c360f0000 pid=3894->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=9f2cb8d3-1900-0000-12e7-fd3c5e0f0000 pid=3934->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ede805e7-1900-0000-12e7-fd3ca00f0000 pid=4000 /tmp/m9x7k2v8b3.i686 guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997->guuid=ede805e7-1900-0000-12e7-fd3ca00f0000 pid=4000 clone guuid=8fd98613-1b00-0000-12e7-fd3c88120000 pid=4744 /tmp/m9x7k2v8b3.i686 guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997->guuid=8fd98613-1b00-0000-12e7-fd3c88120000 pid=4744 clone guuid=a0939313-1b00-0000-12e7-fd3c89120000 pid=4745 /tmp/m9x7k2v8b3.i686 net send-data zombie guuid=40ff54e6-1900-0000-12e7-fd3c9d0f0000 pid=3997->guuid=a0939313-1b00-0000-12e7-fd3c89120000 pid=4745 clone guuid=373e0ee7-1900-0000-12e7-fd3ca10f0000 pid=4001 /tmp/m9x7k2v8b3.i686 guuid=ede805e7-1900-0000-12e7-fd3ca00f0000 pid=4000->guuid=373e0ee7-1900-0000-12e7-fd3ca10f0000 pid=4001 clone guuid=a9ba16e7-1900-0000-12e7-fd3ca20f0000 pid=4002 /tmp/m9x7k2v8b3.i686 dns net send-data zombie guuid=ede805e7-1900-0000-12e7-fd3ca00f0000 pid=4000->guuid=a9ba16e7-1900-0000-12e7-fd3ca20f0000 pid=4002 clone guuid=a9ba16e7-1900-0000-12e7-fd3ca20f0000 pid=4002->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 152B guuid=a9ba16e7-1900-0000-12e7-fd3ca20f0000 pid=4002->852eada3-51ac-5275-909a-778490b5e6b0 send: 88B guuid=a0939313-1b00-0000-12e7-fd3c89120000 pid=4745->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B guuid=a0939313-1b00-0000-12e7-fd3c89120000 pid=4745->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=c3c13414-1b00-0000-12e7-fd3c8d120000 pid=4749->0d978787-977c-56f2-9ffb-c253cca25f19 send: 156B guuid=7d0b7424-1b00-0000-12e7-fd3ca3120000 pid=4771->0d978787-977c-56f2-9ffb-c253cca25f19 send: 105B guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=167f613e-1b00-0000-12e7-fd3cea120000 pid=4842 /tmp/m9x7k2v8b3.x86_64 guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840->guuid=167f613e-1b00-0000-12e7-fd3cea120000 pid=4842 clone guuid=0dfb2269-1c00-0000-12e7-fd3c8e140000 pid=5262 /tmp/m9x7k2v8b3.x86_64 guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840->guuid=0dfb2269-1c00-0000-12e7-fd3c8e140000 pid=5262 clone guuid=3bde2769-1c00-0000-12e7-fd3c8f140000 pid=5263 /tmp/m9x7k2v8b3.x86_64 net send-data zombie guuid=eb64803d-1b00-0000-12e7-fd3ce8120000 pid=4840->guuid=3bde2769-1c00-0000-12e7-fd3c8f140000 pid=5263 clone guuid=83266a3e-1b00-0000-12e7-fd3ceb120000 pid=4843 /tmp/m9x7k2v8b3.x86_64 guuid=167f613e-1b00-0000-12e7-fd3cea120000 pid=4842->guuid=83266a3e-1b00-0000-12e7-fd3ceb120000 pid=4843 clone guuid=2cfb793e-1b00-0000-12e7-fd3cec120000 pid=4844 /tmp/m9x7k2v8b3.x86_64 net send-data zombie guuid=167f613e-1b00-0000-12e7-fd3cea120000 pid=4842->guuid=2cfb793e-1b00-0000-12e7-fd3cec120000 pid=4844 clone guuid=2cfb793e-1b00-0000-12e7-fd3cec120000 pid=4844->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B guuid=2cfb793e-1b00-0000-12e7-fd3cec120000 pid=4844->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=3bde2769-1c00-0000-12e7-fd3c8f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 780B guuid=3bde2769-1c00-0000-12e7-fd3c8f140000 pid=5263->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=668d8d69-1c00-0000-12e7-fd3c91140000 pid=5265->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=e410287d-1c00-0000-12e7-fd3c92140000 pid=5266->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=f0ce0aa1-1c00-0000-12e7-fd3c97140000 pid=5271->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=d38cc4b1-1c00-0000-12e7-fd3c9f140000 pid=5279->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B guuid=08e87ecc-1c00-0000-12e7-fd3ca4140000 pid=5284->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=b3694bde-1c00-0000-12e7-fd3ca5140000 pid=5285->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=c7fd632c-1d00-0000-12e7-fd3cab140000 pid=5291->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=67ce0f40-1d00-0000-12e7-fd3cae140000 pid=5294->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=bec0da5d-1d00-0000-12e7-fd3cbf140000 pid=5311->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=2619f870-1d00-0000-12e7-fd3ccb140000 pid=5323->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=21913e92-1d00-0000-12e7-fd3cd0140000 pid=5328->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=2e378da2-1d00-0000-12e7-fd3cd1140000 pid=5329->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B guuid=1ac83eba-1d00-0000-12e7-fd3cdc140000 pid=5340->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=79ba6bd0-1d00-0000-12e7-fd3ce4140000 pid=5348->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B guuid=832968ee-1d00-0000-12e7-fd3cec140000 pid=5356->0d978787-977c-56f2-9ffb-c253cca25f19 send: 154B guuid=ecc02405-1e00-0000-12e7-fd3cfd140000 pid=5373->0d978787-977c-56f2-9ffb-c253cca25f19 send: 103B guuid=76072d1d-1e00-0000-12e7-fd3c02150000 pid=5378->0d978787-977c-56f2-9ffb-c253cca25f19 send: 153B guuid=9d16d549-1e00-0000-12e7-fd3c03150000 pid=5379->0d978787-977c-56f2-9ffb-c253cca25f19 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-25 08:08:25 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b63483689d2533e0583b7f7a93033143d2532f87482df48654fceb5b9af314ad

(this sample)

  
Delivery method
Distributed via web download

Comments