MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822f
SHA3-384 hash: c810f58a8ee65e99810be1668cc796efbc3f2a1f0893f835d556d097c5949ac71fb12229b09d44d0017f57be8e22858e
SHA1 hash: cc688571a5cd955fce8cf47f2e3e2c129498dcf9
MD5 hash: bb6223f3ecf0b937268b4bda5ba6bc6a
humanhash: dakota-louisiana-utah-asparagus
File name:bin
Download: download sample
Signature Mirai
File size:3'751 bytes
First seen:2025-12-21 15:23:45 UTC
Last seen:2025-12-22 01:55:00 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:NB7+xh7oU8BI1ChwG7rsyj+HjKCbdUBAz82U7Xg5:NBQn1ChwGHaDKCbdUGz82UM
TLSH T12A71F0CD22B020367CA18ABEB2A786577BCFD376DCC51D8454EB34E864BDE4924D0B52
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://81.88.18.108/bins/shadow.x866e01176ce19a409441cadb631f5f0c9b51705a99ebeac50cfae65de383b2e4d4 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.mips7a84fe422301a21cbbb8dd3cdc0e643ee0b9c1aadffa8c57398fd62ea4b58c4b Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.mpsl7a1849017c0684337d85b2aa8a730c4fee62486f444c675e8414b97c50cfb5a8 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.armeb9e1cf68eb14e4adcdfa704496393a5650750460d44a27fc6810a8fb943c18d Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm54d5a9a2f2e81daf2490c91bbc8f8a9363cea14da81749fa0131ba80512542b30 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm601a6e4d8e80b7090e1287238fce08de7bf135d537438845cbb3283f0c17f2d95 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.arm7a9e36e6d5c7b89b86270b0ea4d1363cd83e1f8efdabd7331c76ce3e1c64a3539 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.ppc72f8dcac376fa2861c1a6591953d2c4ad3eed9c634938b3a04388603121ac424 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.m68k5442e5301eab8ab38d0957494067d4b1e5f0df7123945e9fc2a19ca0e82eb502 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.sh49db2cdc377de44600f2bd4ea70114ef56ca00c876e0577899288782fd8b11fbd Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.spcc9b7e82f11bbb447ffd558b840e98e8d4472371545b80b35432b0502447e81fe Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.x86_647c4d404b0e75f2e8a13e6d396544a04667a28b0d73f2baf2ee11d715d09c52e1 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.i686n/an/aelf ua-wget
http://81.88.18.108/bins/shadow.i5866e01176ce19a409441cadb631f5f0c9b51705a99ebeac50cfae65de383b2e4d4 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.i4860e96a2b051308669018d8a9270e18b63d79348e962a920e4dc25025baac3a753 Miraielf mirai opendir ua-wget
http://81.88.18.108/bins/shadow.armv5ln/an/aelf ua-wget
http://81.88.18.108/bins/shadow.armv7ln/an/aelf ua-wget
http://81.88.18.108/bins/shadow.powerpcn/an/aelf ua-wget
http://81.88.18.108/bins/shadow.mipseln/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
36
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T12:43:00Z UTC
Last seen:
2025-12-22T12:28:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4086d5f0-1600-0000-2ff3-aa479d070000 pid=1949 /usr/bin/sudo guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951 /tmp/sample.bin guuid=4086d5f0-1600-0000-2ff3-aa479d070000 pid=1949->guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951 execve guuid=b95dc6f4-1600-0000-2ff3-aa47a1070000 pid=1953 /usr/bin/cp guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b95dc6f4-1600-0000-2ff3-aa47a1070000 pid=1953 execve guuid=9bbf3dfa-1600-0000-2ff3-aa47aa070000 pid=1962 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9bbf3dfa-1600-0000-2ff3-aa47aa070000 pid=1962 execve guuid=8aea0204-1700-0000-2ff3-aa47bc070000 pid=1980 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=8aea0204-1700-0000-2ff3-aa47bc070000 pid=1980 execve guuid=bb270317-1700-0000-2ff3-aa47cc070000 pid=1996 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=bb270317-1700-0000-2ff3-aa47cc070000 pid=1996 execve guuid=d5f95317-1700-0000-2ff3-aa47cd070000 pid=1997 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=d5f95317-1700-0000-2ff3-aa47cd070000 pid=1997 execve guuid=abdcbc17-1700-0000-2ff3-aa47cf070000 pid=1999 /tmp/shadow delete-file net guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=abdcbc17-1700-0000-2ff3-aa47cf070000 pid=1999 execve guuid=774fef17-1700-0000-2ff3-aa47d1070000 pid=2001 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=774fef17-1700-0000-2ff3-aa47d1070000 pid=2001 execve guuid=f0dc961c-1700-0000-2ff3-aa47df070000 pid=2015 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=f0dc961c-1700-0000-2ff3-aa47df070000 pid=2015 execve guuid=bf192c22-1700-0000-2ff3-aa47ec070000 pid=2028 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=bf192c22-1700-0000-2ff3-aa47ec070000 pid=2028 execve guuid=efa27d22-1700-0000-2ff3-aa47ed070000 pid=2029 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=efa27d22-1700-0000-2ff3-aa47ed070000 pid=2029 execve guuid=17dbca22-1700-0000-2ff3-aa47ee070000 pid=2030 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=17dbca22-1700-0000-2ff3-aa47ee070000 pid=2030 clone guuid=186b8523-1700-0000-2ff3-aa47f0070000 pid=2032 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=186b8523-1700-0000-2ff3-aa47f0070000 pid=2032 execve guuid=2f6fc327-1700-0000-2ff3-aa47f1070000 pid=2033 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=2f6fc327-1700-0000-2ff3-aa47f1070000 pid=2033 execve guuid=19a0582d-1700-0000-2ff3-aa47fd070000 pid=2045 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=19a0582d-1700-0000-2ff3-aa47fd070000 pid=2045 execve guuid=6857a82d-1700-0000-2ff3-aa47ff070000 pid=2047 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=6857a82d-1700-0000-2ff3-aa47ff070000 pid=2047 execve guuid=aa08ef2d-1700-0000-2ff3-aa4701080000 pid=2049 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=aa08ef2d-1700-0000-2ff3-aa4701080000 pid=2049 clone guuid=909f7c2e-1700-0000-2ff3-aa4704080000 pid=2052 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=909f7c2e-1700-0000-2ff3-aa4704080000 pid=2052 execve guuid=d0edd932-1700-0000-2ff3-aa470f080000 pid=2063 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=d0edd932-1700-0000-2ff3-aa470f080000 pid=2063 execve guuid=57d85438-1700-0000-2ff3-aa4721080000 pid=2081 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=57d85438-1700-0000-2ff3-aa4721080000 pid=2081 execve guuid=fadab938-1700-0000-2ff3-aa4723080000 pid=2083 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=fadab938-1700-0000-2ff3-aa4723080000 pid=2083 execve guuid=af5af138-1700-0000-2ff3-aa4725080000 pid=2085 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=af5af138-1700-0000-2ff3-aa4725080000 pid=2085 clone guuid=caf76839-1700-0000-2ff3-aa4728080000 pid=2088 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=caf76839-1700-0000-2ff3-aa4728080000 pid=2088 execve guuid=0af19e3d-1700-0000-2ff3-aa4733080000 pid=2099 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=0af19e3d-1700-0000-2ff3-aa4733080000 pid=2099 execve guuid=c5b2a842-1700-0000-2ff3-aa4743080000 pid=2115 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c5b2a842-1700-0000-2ff3-aa4743080000 pid=2115 execve guuid=81d8e442-1700-0000-2ff3-aa4745080000 pid=2117 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=81d8e442-1700-0000-2ff3-aa4745080000 pid=2117 execve guuid=ac8b1d43-1700-0000-2ff3-aa4747080000 pid=2119 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=ac8b1d43-1700-0000-2ff3-aa4747080000 pid=2119 clone guuid=a9c89c43-1700-0000-2ff3-aa474b080000 pid=2123 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=a9c89c43-1700-0000-2ff3-aa474b080000 pid=2123 execve guuid=c160e947-1700-0000-2ff3-aa4759080000 pid=2137 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c160e947-1700-0000-2ff3-aa4759080000 pid=2137 execve guuid=cbbe3f4d-1700-0000-2ff3-aa476a080000 pid=2154 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=cbbe3f4d-1700-0000-2ff3-aa476a080000 pid=2154 execve guuid=b420854d-1700-0000-2ff3-aa476c080000 pid=2156 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b420854d-1700-0000-2ff3-aa476c080000 pid=2156 execve guuid=b8d9bf4d-1700-0000-2ff3-aa476e080000 pid=2158 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b8d9bf4d-1700-0000-2ff3-aa476e080000 pid=2158 clone guuid=c28b3e4e-1700-0000-2ff3-aa4772080000 pid=2162 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c28b3e4e-1700-0000-2ff3-aa4772080000 pid=2162 execve guuid=0ec64453-1700-0000-2ff3-aa4782080000 pid=2178 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=0ec64453-1700-0000-2ff3-aa4782080000 pid=2178 execve guuid=c7822d59-1700-0000-2ff3-aa4793080000 pid=2195 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c7822d59-1700-0000-2ff3-aa4793080000 pid=2195 execve guuid=959b7659-1700-0000-2ff3-aa4795080000 pid=2197 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=959b7659-1700-0000-2ff3-aa4795080000 pid=2197 execve guuid=47eab059-1700-0000-2ff3-aa4797080000 pid=2199 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=47eab059-1700-0000-2ff3-aa4797080000 pid=2199 clone guuid=aa4b305a-1700-0000-2ff3-aa479b080000 pid=2203 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=aa4b305a-1700-0000-2ff3-aa479b080000 pid=2203 execve guuid=2dbe555e-1700-0000-2ff3-aa47a8080000 pid=2216 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=2dbe555e-1700-0000-2ff3-aa47a8080000 pid=2216 execve guuid=917eac63-1700-0000-2ff3-aa47bc080000 pid=2236 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=917eac63-1700-0000-2ff3-aa47bc080000 pid=2236 execve guuid=9f9def63-1700-0000-2ff3-aa47be080000 pid=2238 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9f9def63-1700-0000-2ff3-aa47be080000 pid=2238 execve guuid=c9762e64-1700-0000-2ff3-aa47c0080000 pid=2240 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c9762e64-1700-0000-2ff3-aa47c0080000 pid=2240 clone guuid=89cbc764-1700-0000-2ff3-aa47c4080000 pid=2244 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=89cbc764-1700-0000-2ff3-aa47c4080000 pid=2244 execve guuid=25e4dc68-1700-0000-2ff3-aa47d1080000 pid=2257 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=25e4dc68-1700-0000-2ff3-aa47d1080000 pid=2257 execve guuid=3f45296e-1700-0000-2ff3-aa47e4080000 pid=2276 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=3f45296e-1700-0000-2ff3-aa47e4080000 pid=2276 execve guuid=f37a736e-1700-0000-2ff3-aa47e5080000 pid=2277 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=f37a736e-1700-0000-2ff3-aa47e5080000 pid=2277 execve guuid=d597b56e-1700-0000-2ff3-aa47e7080000 pid=2279 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=d597b56e-1700-0000-2ff3-aa47e7080000 pid=2279 clone guuid=ac32416f-1700-0000-2ff3-aa47ea080000 pid=2282 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=ac32416f-1700-0000-2ff3-aa47ea080000 pid=2282 execve guuid=96ed7873-1700-0000-2ff3-aa47f4080000 pid=2292 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=96ed7873-1700-0000-2ff3-aa47f4080000 pid=2292 execve guuid=c1933979-1700-0000-2ff3-aa4701090000 pid=2305 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=c1933979-1700-0000-2ff3-aa4701090000 pid=2305 execve guuid=6a339d79-1700-0000-2ff3-aa4703090000 pid=2307 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=6a339d79-1700-0000-2ff3-aa4703090000 pid=2307 execve guuid=048efb79-1700-0000-2ff3-aa4705090000 pid=2309 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=048efb79-1700-0000-2ff3-aa4705090000 pid=2309 clone guuid=37dfb87a-1700-0000-2ff3-aa4709090000 pid=2313 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=37dfb87a-1700-0000-2ff3-aa4709090000 pid=2313 execve guuid=d8e7d17e-1700-0000-2ff3-aa470b090000 pid=2315 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=d8e7d17e-1700-0000-2ff3-aa470b090000 pid=2315 execve guuid=2e0e9e8c-1700-0000-2ff3-aa470c090000 pid=2316 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=2e0e9e8c-1700-0000-2ff3-aa470c090000 pid=2316 execve guuid=b3ede68c-1700-0000-2ff3-aa470d090000 pid=2317 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b3ede68c-1700-0000-2ff3-aa470d090000 pid=2317 execve guuid=4b14218d-1700-0000-2ff3-aa470e090000 pid=2318 /usr/bin/dash guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=4b14218d-1700-0000-2ff3-aa470e090000 pid=2318 clone guuid=e6cfa98d-1700-0000-2ff3-aa4710090000 pid=2320 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=e6cfa98d-1700-0000-2ff3-aa4710090000 pid=2320 execve guuid=5c2efa91-1700-0000-2ff3-aa4718090000 pid=2328 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=5c2efa91-1700-0000-2ff3-aa4718090000 pid=2328 execve guuid=63421f99-1700-0000-2ff3-aa4730090000 pid=2352 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=63421f99-1700-0000-2ff3-aa4730090000 pid=2352 execve guuid=184b5d99-1700-0000-2ff3-aa4732090000 pid=2354 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=184b5d99-1700-0000-2ff3-aa4732090000 pid=2354 execve guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356 /tmp/shadow delete-file net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356 execve guuid=80def0c4-1800-0000-2ff3-aa477c0c0000 pid=3196 /usr/bin/wget net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=80def0c4-1800-0000-2ff3-aa477c0c0000 pid=3196 execve guuid=a12b97c7-1800-0000-2ff3-aa47860c0000 pid=3206 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=a12b97c7-1800-0000-2ff3-aa47860c0000 pid=3206 execve guuid=0ccc5dcc-1800-0000-2ff3-aa47910c0000 pid=3217 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=0ccc5dcc-1800-0000-2ff3-aa47910c0000 pid=3217 execve guuid=6fefafcc-1800-0000-2ff3-aa47920c0000 pid=3218 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=6fefafcc-1800-0000-2ff3-aa47920c0000 pid=3218 execve guuid=f93934cd-1800-0000-2ff3-aa47950c0000 pid=3221 /tmp/shadow guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=f93934cd-1800-0000-2ff3-aa47950c0000 pid=3221 execve guuid=68bc70cd-1800-0000-2ff3-aa47960c0000 pid=3222 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=68bc70cd-1800-0000-2ff3-aa47960c0000 pid=3222 execve guuid=fa64ccd1-1800-0000-2ff3-aa479d0c0000 pid=3229 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=fa64ccd1-1800-0000-2ff3-aa479d0c0000 pid=3229 execve guuid=b8db93d7-1800-0000-2ff3-aa47a50c0000 pid=3237 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b8db93d7-1800-0000-2ff3-aa47a50c0000 pid=3237 execve guuid=6ec2e3d7-1800-0000-2ff3-aa47a60c0000 pid=3238 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=6ec2e3d7-1800-0000-2ff3-aa47a60c0000 pid=3238 execve guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239 /tmp/shadow delete-file net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239 execve guuid=657aa014-1a00-0000-2ff3-aa479a0f0000 pid=3994 /usr/bin/wget net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=657aa014-1a00-0000-2ff3-aa479a0f0000 pid=3994 execve guuid=b77fe519-1a00-0000-2ff3-aa47af0f0000 pid=4015 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b77fe519-1a00-0000-2ff3-aa47af0f0000 pid=4015 execve guuid=e3b94f20-1a00-0000-2ff3-aa47c60f0000 pid=4038 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=e3b94f20-1a00-0000-2ff3-aa47c60f0000 pid=4038 execve guuid=b180593e-1a00-0000-2ff3-aa47d00f0000 pid=4048 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b180593e-1a00-0000-2ff3-aa47d00f0000 pid=4048 execve guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051 /tmp/shadow delete-file net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051 execve guuid=ac3ee07c-1b00-0000-2ff3-aa47bd130000 pid=5053 /usr/bin/wget net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=ac3ee07c-1b00-0000-2ff3-aa47bd130000 pid=5053 execve guuid=18354280-1b00-0000-2ff3-aa47c9130000 pid=5065 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=18354280-1b00-0000-2ff3-aa47c9130000 pid=5065 execve guuid=7c969288-1b00-0000-2ff3-aa47db130000 pid=5083 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=7c969288-1b00-0000-2ff3-aa47db130000 pid=5083 execve guuid=b179f888-1b00-0000-2ff3-aa47de130000 pid=5086 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b179f888-1b00-0000-2ff3-aa47de130000 pid=5086 execve guuid=77b74d89-1b00-0000-2ff3-aa47e0130000 pid=5088 /tmp/shadow guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=77b74d89-1b00-0000-2ff3-aa47e0130000 pid=5088 execve guuid=cdd09e89-1b00-0000-2ff3-aa47e2130000 pid=5090 /usr/bin/wget net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=cdd09e89-1b00-0000-2ff3-aa47e2130000 pid=5090 execve guuid=26e64c8c-1b00-0000-2ff3-aa47e7130000 pid=5095 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=26e64c8c-1b00-0000-2ff3-aa47e7130000 pid=5095 execve guuid=79c52492-1b00-0000-2ff3-aa47f0130000 pid=5104 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=79c52492-1b00-0000-2ff3-aa47f0130000 pid=5104 execve guuid=2fdd8b92-1b00-0000-2ff3-aa47f1130000 pid=5105 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=2fdd8b92-1b00-0000-2ff3-aa47f1130000 pid=5105 execve guuid=2bfcdb92-1b00-0000-2ff3-aa47f2130000 pid=5106 /tmp/shadow guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=2bfcdb92-1b00-0000-2ff3-aa47f2130000 pid=5106 execve guuid=7c491493-1b00-0000-2ff3-aa47f3130000 pid=5107 /usr/bin/wget net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=7c491493-1b00-0000-2ff3-aa47f3130000 pid=5107 execve guuid=eeb7db95-1b00-0000-2ff3-aa47fd130000 pid=5117 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=eeb7db95-1b00-0000-2ff3-aa47fd130000 pid=5117 execve guuid=9750cd99-1b00-0000-2ff3-aa4710140000 pid=5136 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9750cd99-1b00-0000-2ff3-aa4710140000 pid=5136 execve guuid=949c189a-1b00-0000-2ff3-aa4711140000 pid=5137 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=949c189a-1b00-0000-2ff3-aa4711140000 pid=5137 execve guuid=9a1e879a-1b00-0000-2ff3-aa4713140000 pid=5139 /tmp/shadow guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9a1e879a-1b00-0000-2ff3-aa4713140000 pid=5139 execve guuid=b7bed69a-1b00-0000-2ff3-aa4715140000 pid=5141 /usr/bin/wget net send-data guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b7bed69a-1b00-0000-2ff3-aa4715140000 pid=5141 execve guuid=9eb86a9d-1b00-0000-2ff3-aa4721140000 pid=5153 /usr/bin/curl net send-data write-file guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9eb86a9d-1b00-0000-2ff3-aa4721140000 pid=5153 execve guuid=9746e6a3-1b00-0000-2ff3-aa4738140000 pid=5176 /usr/bin/cat guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=9746e6a3-1b00-0000-2ff3-aa4738140000 pid=5176 execve guuid=b76136a4-1b00-0000-2ff3-aa4739140000 pid=5177 /usr/bin/chmod guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=b76136a4-1b00-0000-2ff3-aa4739140000 pid=5177 execve guuid=64499ca4-1b00-0000-2ff3-aa473d140000 pid=5181 /tmp/shadow guuid=10f281f4-1600-0000-2ff3-aa479f070000 pid=1951->guuid=64499ca4-1b00-0000-2ff3-aa473d140000 pid=5181 execve eeec4aa2-e72a-5b27-bcb1-92cd6476f418 81.88.18.108:80 guuid=9bbf3dfa-1600-0000-2ff3-aa47aa070000 pid=1962->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=8aea0204-1700-0000-2ff3-aa47bc070000 pid=1980->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=abdcbc17-1700-0000-2ff3-aa47cf070000 pid=1999->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=617ce917-1700-0000-2ff3-aa47d0070000 pid=2000 /tmp/shadow write-file zombie guuid=abdcbc17-1700-0000-2ff3-aa47cf070000 pid=1999->guuid=617ce917-1700-0000-2ff3-aa47d0070000 pid=2000 clone guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006 /tmp/shadow dns net send-data guuid=617ce917-1700-0000-2ff3-aa47d0070000 pid=2000->guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006 clone guuid=774fef17-1700-0000-2ff3-aa47d1070000 pid=2001->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 6a6ce952-23cd-5c51-b461-6ca6a8c64225 1.0.0.1:53 guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006->6a6ce952-23cd-5c51-b461-6ca6a8c64225 send: 26B c610bf36-1f00-5bc3-ae18-24f0473b35c2 81.88.18.108:6767 guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 11B guuid=b83a2619-1700-0000-2ff3-aa47d7070000 pid=2007 /tmp/shadow guuid=5eae0c19-1700-0000-2ff3-aa47d6070000 pid=2006->guuid=b83a2619-1700-0000-2ff3-aa47d7070000 pid=2007 clone guuid=f0dc961c-1700-0000-2ff3-aa47df070000 pid=2015->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=186b8523-1700-0000-2ff3-aa47f0070000 pid=2032->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=2f6fc327-1700-0000-2ff3-aa47f1070000 pid=2033->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=909f7c2e-1700-0000-2ff3-aa4704080000 pid=2052->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=d0edd932-1700-0000-2ff3-aa470f080000 pid=2063->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 91B guuid=caf76839-1700-0000-2ff3-aa4728080000 pid=2088->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=0af19e3d-1700-0000-2ff3-aa4733080000 pid=2099->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=a9c89c43-1700-0000-2ff3-aa474b080000 pid=2123->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=c160e947-1700-0000-2ff3-aa4759080000 pid=2137->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=c28b3e4e-1700-0000-2ff3-aa4772080000 pid=2162->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=0ec64453-1700-0000-2ff3-aa4782080000 pid=2178->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=aa4b305a-1700-0000-2ff3-aa479b080000 pid=2203->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=2dbe555e-1700-0000-2ff3-aa47a8080000 pid=2216->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 91B guuid=89cbc764-1700-0000-2ff3-aa47c4080000 pid=2244->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=25e4dc68-1700-0000-2ff3-aa47d1080000 pid=2257->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=ac32416f-1700-0000-2ff3-aa47ea080000 pid=2282->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=96ed7873-1700-0000-2ff3-aa47f4080000 pid=2292->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 91B guuid=37dfb87a-1700-0000-2ff3-aa4709090000 pid=2313->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 142B guuid=d8e7d17e-1700-0000-2ff3-aa470b090000 pid=2315->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 91B guuid=e6cfa98d-1700-0000-2ff3-aa4710090000 pid=2320->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 145B guuid=5c2efa91-1700-0000-2ff3-aa4718090000 pid=2328->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 94B guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ff25191-b423-5251-a735-2378c22ab12a 0.0.0.0:48101 guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356->8ff25191-b423-5251-a735-2378c22ab12a con 230551d6-3124-51d2-b63c-f814e1d0d1f9 127.0.0.1:48101 guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356->230551d6-3124-51d2-b63c-f814e1d0d1f9 send: 4B guuid=0cbdeac4-1800-0000-2ff3-aa477b0c0000 pid=3195 /tmp/shadow write-file zombie guuid=727d9899-1700-0000-2ff3-aa4734090000 pid=2356->guuid=0cbdeac4-1800-0000-2ff3-aa477b0c0000 pid=3195 clone guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197 /tmp/shadow dns net send-data guuid=0cbdeac4-1800-0000-2ff3-aa477b0c0000 pid=3195->guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197 clone guuid=80def0c4-1800-0000-2ff3-aa477c0c0000 pid=3196->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 11B b4bf20d4-f7c8-5c24-8830-c23364537aa4 8.8.4.4:53 guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197->b4bf20d4-f7c8-5c24-8830-c23364537aa4 send: 26B guuid=984202c5-1800-0000-2ff3-aa477e0c0000 pid=3198 /tmp/shadow guuid=9ee9f7c4-1800-0000-2ff3-aa477d0c0000 pid=3197->guuid=984202c5-1800-0000-2ff3-aa477e0c0000 pid=3198 clone guuid=a12b97c7-1800-0000-2ff3-aa47860c0000 pid=3206->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=68bc70cd-1800-0000-2ff3-aa47960c0000 pid=3222->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=fa64ccd1-1800-0000-2ff3-aa479d0c0000 pid=3229->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239->8ff25191-b423-5251-a735-2378c22ab12a con guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239->230551d6-3124-51d2-b63c-f814e1d0d1f9 send: 4B guuid=f93d9314-1a00-0000-2ff3-aa47980f0000 pid=3992 /tmp/shadow write-file zombie guuid=f82128d8-1800-0000-2ff3-aa47a70c0000 pid=3239->guuid=f93d9314-1a00-0000-2ff3-aa47980f0000 pid=3992 clone guuid=a085b014-1a00-0000-2ff3-aa479b0f0000 pid=3995 /tmp/shadow dns net send-data guuid=f93d9314-1a00-0000-2ff3-aa47980f0000 pid=3992->guuid=a085b014-1a00-0000-2ff3-aa479b0f0000 pid=3995 clone guuid=657aa014-1a00-0000-2ff3-aa479a0f0000 pid=3994->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 143B guuid=a085b014-1a00-0000-2ff3-aa479b0f0000 pid=3995->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 26B guuid=a085b014-1a00-0000-2ff3-aa479b0f0000 pid=3995->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 11B guuid=98f0bb14-1a00-0000-2ff3-aa479c0f0000 pid=3996 /tmp/shadow guuid=a085b014-1a00-0000-2ff3-aa479b0f0000 pid=3995->guuid=98f0bb14-1a00-0000-2ff3-aa479c0f0000 pid=3996 clone guuid=b77fe519-1a00-0000-2ff3-aa47af0f0000 pid=4015->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 92B guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051->8ff25191-b423-5251-a735-2378c22ab12a con guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051->230551d6-3124-51d2-b63c-f814e1d0d1f9 send: 4B guuid=0c1eda7c-1b00-0000-2ff3-aa47bc130000 pid=5052 /tmp/shadow write-file zombie guuid=dcf6ce3e-1a00-0000-2ff3-aa47d30f0000 pid=4051->guuid=0c1eda7c-1b00-0000-2ff3-aa47bc130000 pid=5052 clone guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054 /tmp/shadow dns net send-data guuid=0c1eda7c-1b00-0000-2ff3-aa47bc130000 pid=5052->guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054 clone guuid=ac3ee07c-1b00-0000-2ff3-aa47bd130000 pid=5053->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 145B guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054->6a6ce952-23cd-5c51-b461-6ca6a8c64225 send: 26B guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054->c610bf36-1f00-5bc3-ae18-24f0473b35c2 send: 13B guuid=7b54f97c-1b00-0000-2ff3-aa47bf130000 pid=5055 /tmp/shadow guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054->guuid=7b54f97c-1b00-0000-2ff3-aa47bf130000 pid=5055 clone guuid=02e0b887-1e00-0000-2ff3-aa47ed140000 pid=5357 /tmp/shadow net send-data guuid=1e23f07c-1b00-0000-2ff3-aa47be130000 pid=5054->guuid=02e0b887-1e00-0000-2ff3-aa47ed140000 pid=5357 clone guuid=18354280-1b00-0000-2ff3-aa47c9130000 pid=5065->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 94B guuid=cdd09e89-1b00-0000-2ff3-aa47e2130000 pid=5090->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 145B guuid=26e64c8c-1b00-0000-2ff3-aa47e7130000 pid=5095->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 94B guuid=7c491493-1b00-0000-2ff3-aa47f3130000 pid=5107->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 146B guuid=eeb7db95-1b00-0000-2ff3-aa47fd130000 pid=5117->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 95B guuid=b7bed69a-1b00-0000-2ff3-aa4715140000 pid=5141->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 145B guuid=9eb86a9d-1b00-0000-2ff3-aa4721140000 pid=5153->eeec4aa2-e72a-5b27-bcb1-92cd6476f418 send: 94B 736f118b-7a4f-5e11-8137-a0f9d54d3930 147.75.87.133:53 guuid=02e0b887-1e00-0000-2ff3-aa47ed140000 pid=5357->736f118b-7a4f-5e11-8137-a0f9d54d3930 send: 4097B guuid=7742c187-1e00-0000-2ff3-aa47ee140000 pid=5358 /tmp/shadow guuid=02e0b887-1e00-0000-2ff3-aa47ed140000 pid=5357->guuid=7742c187-1e00-0000-2ff3-aa47ee140000 pid=5358 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-21 15:36:13 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b80c304c154e78c442f468a2d986124c4e14222c343aff4cdd3d332c9ac3822f

(this sample)

  
Delivery method
Distributed via web download

Comments