MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bf524afed3a4c56766d617b3909089d3193c65f7a62ebd13af2a49be8270ccdc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: bf524afed3a4c56766d617b3909089d3193c65f7a62ebd13af2a49be8270ccdc
SHA3-384 hash: 521b5a09134e55411ce01b655228e318a494ce9b384b7ddc6ca07f160f320d4d681ab551070f66d62abe1ae8ca8baa2a
SHA1 hash: 3c3a89b1a5982523d1c64131bf4cd61301a7e558
MD5 hash: e79703d5f9e4238205753a99ca98f515
humanhash: mirror-foxtrot-monkey-mockingbird
File name:1.sh
Download: download sample
Signature Mirai
File size:2'738 bytes
First seen:2025-12-30 21:19:27 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iE269jOJra/qssrLA7sijSfcfE0AJS7L8UBJ+5MPAEcw8P45:iE269jQIoxijSfME0AJS7L8K+5MPAEcq
TLSH T1AD51CF8A20414F393CFA986E33F91448B4F084AB25D75F649CE834E7418EE547F88A6E
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://130.12.180.2/main_x860d7faa61a016d1ddbba591a09ce005623faced2ec2750b1f3148950f877a5b2a Miraielf mirai ua-wget
http://130.12.180.2/main_mipsb870b0c66e5cdbab21bc4d28c3e5e66a557f6d03ab30857312d445e6624d8894 Miraielf mirai ua-wget
http://130.12.180.2/main_arcn/an/aelf ua-wget
http://130.12.180.2/main_i468n/an/aelf ua-wget
http://130.12.180.2/main_i686n/an/aelf ua-wget
http://130.12.180.2/main_x86_6470653f2079ed5ad5982aa4fbff4ac49c79a54b5ad6a0240fed2848897c00b17c Miraielf mirai ua-wget
http://130.12.180.2/main_mpsl36a37ced893b0ab6400b785e14ee1c63e03f39cbb5bb18399b635ef59ffc3b14 Miraielf mirai ua-wget
http://130.12.180.2/main_armf0492645461def1452f4eb2d9ae14b218869b4dbc2093199042752b723a43bb7 Miraielf mirai ua-wget
http://130.12.180.2/main_arm5e4c4775ebf8858e632497092e578940b33228349fadef0207aed99a7fb14d37b Miraielf mirai ua-wget
http://130.12.180.2/main_arm6dabf196b20d87c5b615e6b4ba7b5a73caf04caed60f032d9454b61fd7d34fca6 Miraielf mirai ua-wget
http://130.12.180.2/main_arm78fa63cf16bd8b5f0c267c99c6d62004db560a66360695c949b498231836df8ff Miraielf mirai ua-wget
http://130.12.180.2/main_ppc0c84dd5e63104cb7ab0194b28f5c41adee4c460b54cfaa9f9dd855ebe589e18a Miraielf mirai ua-wget
http://130.12.180.2/main_spcn/an/aelf ua-wget
http://130.12.180.2/main_m68ke4c9bb581e89de0ccdc2d33b90c2c3833492f4b6d238b0428ba5dfae94a348a4 Miraielf mirai ua-wget
http://130.12.180.2/main_sh45c8b91b9f5f0bcd72fd1ad5a8229396bfba43ecf1ce1f2eb3a483347652a876a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash busybox evasive lolbin mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=5297b2cc-1900-0000-6ac6-abf6f3080000 pid=2291 /usr/bin/sudo guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298 /tmp/sample.bin guuid=5297b2cc-1900-0000-6ac6-abf6f3080000 pid=2291->guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298 execve guuid=41278ed0-1900-0000-6ac6-abf6fc080000 pid=2300 /usr/bin/cp guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=41278ed0-1900-0000-6ac6-abf6fc080000 pid=2300 execve guuid=dd94aad5-1900-0000-6ac6-abf605090000 pid=2309 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=dd94aad5-1900-0000-6ac6-abf605090000 pid=2309 execve guuid=b1995add-1900-0000-6ac6-abf611090000 pid=2321 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=b1995add-1900-0000-6ac6-abf611090000 pid=2321 execve guuid=24b990f0-1900-0000-6ac6-abf62b090000 pid=2347 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=24b990f0-1900-0000-6ac6-abf62b090000 pid=2347 execve guuid=8b28def0-1900-0000-6ac6-abf62c090000 pid=2348 /tmp/main_x86 delete-file net guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=8b28def0-1900-0000-6ac6-abf62c090000 pid=2348 execve guuid=995f19f1-1900-0000-6ac6-abf62e090000 pid=2350 /usr/bin/rm guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=995f19f1-1900-0000-6ac6-abf62e090000 pid=2350 execve guuid=2fd962f1-1900-0000-6ac6-abf630090000 pid=2352 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=2fd962f1-1900-0000-6ac6-abf630090000 pid=2352 execve guuid=3a4e2bf7-1900-0000-6ac6-abf63a090000 pid=2362 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=3a4e2bf7-1900-0000-6ac6-abf63a090000 pid=2362 execve guuid=4246dffd-1900-0000-6ac6-abf649090000 pid=2377 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=4246dffd-1900-0000-6ac6-abf649090000 pid=2377 execve guuid=cf2738fe-1900-0000-6ac6-abf64a090000 pid=2378 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=cf2738fe-1900-0000-6ac6-abf64a090000 pid=2378 clone guuid=1d04e5fe-1900-0000-6ac6-abf64e090000 pid=2382 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=1d04e5fe-1900-0000-6ac6-abf64e090000 pid=2382 execve guuid=2faa3bff-1900-0000-6ac6-abf650090000 pid=2384 /usr/bin/wget net send-data guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=2faa3bff-1900-0000-6ac6-abf650090000 pid=2384 execve guuid=98b36802-1a00-0000-6ac6-abf657090000 pid=2391 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=98b36802-1a00-0000-6ac6-abf657090000 pid=2391 execve guuid=d6664207-1a00-0000-6ac6-abf663090000 pid=2403 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=d6664207-1a00-0000-6ac6-abf663090000 pid=2403 execve guuid=5ab3c907-1a00-0000-6ac6-abf664090000 pid=2404 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=5ab3c907-1a00-0000-6ac6-abf664090000 pid=2404 clone guuid=15a23308-1a00-0000-6ac6-abf667090000 pid=2407 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=15a23308-1a00-0000-6ac6-abf667090000 pid=2407 execve guuid=16efa908-1a00-0000-6ac6-abf66a090000 pid=2410 /usr/bin/wget net send-data guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=16efa908-1a00-0000-6ac6-abf66a090000 pid=2410 execve guuid=db86b00b-1a00-0000-6ac6-abf672090000 pid=2418 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=db86b00b-1a00-0000-6ac6-abf672090000 pid=2418 execve guuid=cb4b6313-1a00-0000-6ac6-abf680090000 pid=2432 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=cb4b6313-1a00-0000-6ac6-abf680090000 pid=2432 execve guuid=8bf7c213-1a00-0000-6ac6-abf682090000 pid=2434 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=8bf7c213-1a00-0000-6ac6-abf682090000 pid=2434 clone guuid=707a0014-1a00-0000-6ac6-abf685090000 pid=2437 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=707a0014-1a00-0000-6ac6-abf685090000 pid=2437 execve guuid=3df85c14-1a00-0000-6ac6-abf687090000 pid=2439 /usr/bin/wget net send-data guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=3df85c14-1a00-0000-6ac6-abf687090000 pid=2439 execve guuid=8b925e18-1a00-0000-6ac6-abf692090000 pid=2450 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=8b925e18-1a00-0000-6ac6-abf692090000 pid=2450 execve guuid=eb564b1e-1a00-0000-6ac6-abf6a3090000 pid=2467 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=eb564b1e-1a00-0000-6ac6-abf6a3090000 pid=2467 execve guuid=c7ac911e-1a00-0000-6ac6-abf6a5090000 pid=2469 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=c7ac911e-1a00-0000-6ac6-abf6a5090000 pid=2469 clone guuid=224bd51e-1a00-0000-6ac6-abf6a8090000 pid=2472 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=224bd51e-1a00-0000-6ac6-abf6a8090000 pid=2472 execve guuid=3032461f-1a00-0000-6ac6-abf6a9090000 pid=2473 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=3032461f-1a00-0000-6ac6-abf6a9090000 pid=2473 execve guuid=f036f124-1a00-0000-6ac6-abf6b2090000 pid=2482 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=f036f124-1a00-0000-6ac6-abf6b2090000 pid=2482 execve guuid=7f82c92b-1a00-0000-6ac6-abf6c5090000 pid=2501 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=7f82c92b-1a00-0000-6ac6-abf6c5090000 pid=2501 execve guuid=44152e2c-1a00-0000-6ac6-abf6c7090000 pid=2503 /tmp/main_x86_64 delete-file net guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=44152e2c-1a00-0000-6ac6-abf6c7090000 pid=2503 execve guuid=c3f1592c-1a00-0000-6ac6-abf6ca090000 pid=2506 /usr/bin/rm guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=c3f1592c-1a00-0000-6ac6-abf6ca090000 pid=2506 execve guuid=0833cb2c-1a00-0000-6ac6-abf6cd090000 pid=2509 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=0833cb2c-1a00-0000-6ac6-abf6cd090000 pid=2509 execve guuid=bfbee232-1a00-0000-6ac6-abf6d8090000 pid=2520 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=bfbee232-1a00-0000-6ac6-abf6d8090000 pid=2520 execve guuid=7deb4e3a-1a00-0000-6ac6-abf6ea090000 pid=2538 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=7deb4e3a-1a00-0000-6ac6-abf6ea090000 pid=2538 execve guuid=54eb943a-1a00-0000-6ac6-abf6eb090000 pid=2539 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=54eb943a-1a00-0000-6ac6-abf6eb090000 pid=2539 clone guuid=738b4a3c-1a00-0000-6ac6-abf6f1090000 pid=2545 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=738b4a3c-1a00-0000-6ac6-abf6f1090000 pid=2545 execve guuid=ff3ee83c-1a00-0000-6ac6-abf6f3090000 pid=2547 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=ff3ee83c-1a00-0000-6ac6-abf6f3090000 pid=2547 execve guuid=a1648b44-1a00-0000-6ac6-abf6030a0000 pid=2563 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=a1648b44-1a00-0000-6ac6-abf6030a0000 pid=2563 execve guuid=534c0d4d-1a00-0000-6ac6-abf6180a0000 pid=2584 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=534c0d4d-1a00-0000-6ac6-abf6180a0000 pid=2584 execve guuid=91e9934d-1a00-0000-6ac6-abf6190a0000 pid=2585 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=91e9934d-1a00-0000-6ac6-abf6190a0000 pid=2585 clone guuid=2f967a4e-1a00-0000-6ac6-abf61d0a0000 pid=2589 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=2f967a4e-1a00-0000-6ac6-abf61d0a0000 pid=2589 execve guuid=a36eca4e-1a00-0000-6ac6-abf61f0a0000 pid=2591 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=a36eca4e-1a00-0000-6ac6-abf61f0a0000 pid=2591 execve guuid=2dbfdb54-1a00-0000-6ac6-abf62f0a0000 pid=2607 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=2dbfdb54-1a00-0000-6ac6-abf62f0a0000 pid=2607 execve guuid=f100f75d-1a00-0000-6ac6-abf6480a0000 pid=2632 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=f100f75d-1a00-0000-6ac6-abf6480a0000 pid=2632 execve guuid=efb5535e-1a00-0000-6ac6-abf64a0a0000 pid=2634 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=efb5535e-1a00-0000-6ac6-abf64a0a0000 pid=2634 clone guuid=9243195f-1a00-0000-6ac6-abf64e0a0000 pid=2638 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=9243195f-1a00-0000-6ac6-abf64e0a0000 pid=2638 execve guuid=9ccdad5f-1a00-0000-6ac6-abf6500a0000 pid=2640 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=9ccdad5f-1a00-0000-6ac6-abf6500a0000 pid=2640 execve guuid=9c049366-1a00-0000-6ac6-abf6620a0000 pid=2658 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=9c049366-1a00-0000-6ac6-abf6620a0000 pid=2658 execve guuid=2e7ef96c-1a00-0000-6ac6-abf6760a0000 pid=2678 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=2e7ef96c-1a00-0000-6ac6-abf6760a0000 pid=2678 execve guuid=528e456d-1a00-0000-6ac6-abf6770a0000 pid=2679 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=528e456d-1a00-0000-6ac6-abf6770a0000 pid=2679 clone guuid=6d11c66d-1a00-0000-6ac6-abf67b0a0000 pid=2683 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=6d11c66d-1a00-0000-6ac6-abf67b0a0000 pid=2683 execve guuid=7e2a0b6e-1a00-0000-6ac6-abf67d0a0000 pid=2685 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=7e2a0b6e-1a00-0000-6ac6-abf67d0a0000 pid=2685 execve guuid=ac380074-1a00-0000-6ac6-abf68f0a0000 pid=2703 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=ac380074-1a00-0000-6ac6-abf68f0a0000 pid=2703 execve guuid=4f59447c-1a00-0000-6ac6-abf6a90a0000 pid=2729 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=4f59447c-1a00-0000-6ac6-abf6a90a0000 pid=2729 execve guuid=f8d5917c-1a00-0000-6ac6-abf6aa0a0000 pid=2730 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=f8d5917c-1a00-0000-6ac6-abf6aa0a0000 pid=2730 clone guuid=f723327d-1a00-0000-6ac6-abf6ae0a0000 pid=2734 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=f723327d-1a00-0000-6ac6-abf6ae0a0000 pid=2734 execve guuid=037fa97d-1a00-0000-6ac6-abf6b10a0000 pid=2737 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=037fa97d-1a00-0000-6ac6-abf6b10a0000 pid=2737 execve guuid=85bdae83-1a00-0000-6ac6-abf6c40a0000 pid=2756 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=85bdae83-1a00-0000-6ac6-abf6c40a0000 pid=2756 execve guuid=49a4e98a-1a00-0000-6ac6-abf6d80a0000 pid=2776 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=49a4e98a-1a00-0000-6ac6-abf6d80a0000 pid=2776 execve guuid=9967328b-1a00-0000-6ac6-abf6da0a0000 pid=2778 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=9967328b-1a00-0000-6ac6-abf6da0a0000 pid=2778 clone guuid=d3802d8c-1a00-0000-6ac6-abf6de0a0000 pid=2782 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=d3802d8c-1a00-0000-6ac6-abf6de0a0000 pid=2782 execve guuid=cf987e8c-1a00-0000-6ac6-abf6e00a0000 pid=2784 /usr/bin/wget net send-data guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=cf987e8c-1a00-0000-6ac6-abf6e00a0000 pid=2784 execve guuid=bf347e8f-1a00-0000-6ac6-abf6eb0a0000 pid=2795 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=bf347e8f-1a00-0000-6ac6-abf6eb0a0000 pid=2795 execve guuid=ee05aa94-1a00-0000-6ac6-abf6f90a0000 pid=2809 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=ee05aa94-1a00-0000-6ac6-abf6f90a0000 pid=2809 execve guuid=e66cef94-1a00-0000-6ac6-abf6fb0a0000 pid=2811 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=e66cef94-1a00-0000-6ac6-abf6fb0a0000 pid=2811 clone guuid=7c484595-1a00-0000-6ac6-abf6fe0a0000 pid=2814 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=7c484595-1a00-0000-6ac6-abf6fe0a0000 pid=2814 execve guuid=8fe08f95-1a00-0000-6ac6-abf6000b0000 pid=2816 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=8fe08f95-1a00-0000-6ac6-abf6000b0000 pid=2816 execve guuid=58d94e9b-1a00-0000-6ac6-abf60f0b0000 pid=2831 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=58d94e9b-1a00-0000-6ac6-abf60f0b0000 pid=2831 execve guuid=99360da2-1a00-0000-6ac6-abf6180b0000 pid=2840 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=99360da2-1a00-0000-6ac6-abf6180b0000 pid=2840 execve guuid=ffd86fa2-1a00-0000-6ac6-abf61a0b0000 pid=2842 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=ffd86fa2-1a00-0000-6ac6-abf61a0b0000 pid=2842 clone guuid=1c6f5fa3-1a00-0000-6ac6-abf61c0b0000 pid=2844 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=1c6f5fa3-1a00-0000-6ac6-abf61c0b0000 pid=2844 execve guuid=34dedba3-1a00-0000-6ac6-abf61d0b0000 pid=2845 /usr/bin/wget net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=34dedba3-1a00-0000-6ac6-abf61d0b0000 pid=2845 execve guuid=8dc03eaa-1a00-0000-6ac6-abf62c0b0000 pid=2860 /usr/bin/curl net send-data write-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=8dc03eaa-1a00-0000-6ac6-abf62c0b0000 pid=2860 execve guuid=432548b1-1a00-0000-6ac6-abf63a0b0000 pid=2874 /usr/bin/chmod guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=432548b1-1a00-0000-6ac6-abf63a0b0000 pid=2874 execve guuid=20a2b0b1-1a00-0000-6ac6-abf63c0b0000 pid=2876 /usr/bin/bash guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=20a2b0b1-1a00-0000-6ac6-abf63c0b0000 pid=2876 clone guuid=f8f47fb2-1a00-0000-6ac6-abf6400b0000 pid=2880 /usr/bin/rm delete-file guuid=12d0abcf-1900-0000-6ac6-abf6fa080000 pid=2298->guuid=f8f47fb2-1a00-0000-6ac6-abf6400b0000 pid=2880 execve d22a5e33-d698-503d-a0f3-540a55a09d91 130.12.180.2:80 guuid=dd94aad5-1900-0000-6ac6-abf605090000 pid=2309->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=b1995add-1900-0000-6ac6-abf611090000 pid=2321->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8b28def0-1900-0000-6ac6-abf62c090000 pid=2348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3afa09f1-1900-0000-6ac6-abf62d090000 pid=2349 /tmp/main_x86 dns net send-data zombie guuid=8b28def0-1900-0000-6ac6-abf62c090000 pid=2348->guuid=3afa09f1-1900-0000-6ac6-abf62d090000 pid=2349 clone guuid=3afa09f1-1900-0000-6ac6-abf62d090000 pid=2349->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 82B 25f3365d-095a-517f-9fd3-6b7167ac5b5d vicious-net.duckdns.org:1995 guuid=3afa09f1-1900-0000-6ac6-abf62d090000 pid=2349->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 15B guuid=bee42af1-1900-0000-6ac6-abf62f090000 pid=2351 /tmp/main_x86 guuid=3afa09f1-1900-0000-6ac6-abf62d090000 pid=2349->guuid=bee42af1-1900-0000-6ac6-abf62f090000 pid=2351 clone guuid=2fd962f1-1900-0000-6ac6-abf630090000 pid=2352->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=3a4e2bf7-1900-0000-6ac6-abf63a090000 pid=2362->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=2faa3bff-1900-0000-6ac6-abf650090000 pid=2384->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=98b36802-1a00-0000-6ac6-abf657090000 pid=2391->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B guuid=1783f707-1a00-0000-6ac6-abf665090000 pid=2405 /usr/bin/bash guuid=5ab3c907-1a00-0000-6ac6-abf664090000 pid=2404->guuid=1783f707-1a00-0000-6ac6-abf665090000 pid=2405 clone guuid=16efa908-1a00-0000-6ac6-abf66a090000 pid=2410->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 131B guuid=db86b00b-1a00-0000-6ac6-abf672090000 pid=2418->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=1161de13-1a00-0000-6ac6-abf684090000 pid=2436 /usr/bin/bash guuid=8bf7c213-1a00-0000-6ac6-abf682090000 pid=2434->guuid=1161de13-1a00-0000-6ac6-abf684090000 pid=2436 clone guuid=3df85c14-1a00-0000-6ac6-abf687090000 pid=2439->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=8b925e18-1a00-0000-6ac6-abf692090000 pid=2450->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=70d9a61e-1a00-0000-6ac6-abf6a6090000 pid=2470 /usr/bin/bash guuid=c7ac911e-1a00-0000-6ac6-abf6a5090000 pid=2469->guuid=70d9a61e-1a00-0000-6ac6-abf6a6090000 pid=2470 clone guuid=3032461f-1a00-0000-6ac6-abf6a9090000 pid=2473->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 138B guuid=f036f124-1a00-0000-6ac6-abf6b2090000 pid=2482->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 87B guuid=44152e2c-1a00-0000-6ac6-abf6c7090000 pid=2503->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba964c2c-1a00-0000-6ac6-abf6c9090000 pid=2505 /tmp/main_x86_64 dns net send-data zombie guuid=44152e2c-1a00-0000-6ac6-abf6c7090000 pid=2503->guuid=ba964c2c-1a00-0000-6ac6-abf6c9090000 pid=2505 clone guuid=ba964c2c-1a00-0000-6ac6-abf6c9090000 pid=2505->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 41B guuid=ba964c2c-1a00-0000-6ac6-abf6c9090000 pid=2505->25f3365d-095a-517f-9fd3-6b7167ac5b5d send: 18B guuid=37635c2c-1a00-0000-6ac6-abf6cb090000 pid=2507 /tmp/main_x86_64 guuid=ba964c2c-1a00-0000-6ac6-abf6c9090000 pid=2505->guuid=37635c2c-1a00-0000-6ac6-abf6cb090000 pid=2507 clone guuid=0833cb2c-1a00-0000-6ac6-abf6cd090000 pid=2509->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=bfbee232-1a00-0000-6ac6-abf6d8090000 pid=2520->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=ff3ee83c-1a00-0000-6ac6-abf6f3090000 pid=2547->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=a1648b44-1a00-0000-6ac6-abf6030a0000 pid=2563->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B guuid=a36eca4e-1a00-0000-6ac6-abf61f0a0000 pid=2591->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=2dbfdb54-1a00-0000-6ac6-abf62f0a0000 pid=2607->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=9ccdad5f-1a00-0000-6ac6-abf6500a0000 pid=2640->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=9c049366-1a00-0000-6ac6-abf6620a0000 pid=2658->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=7e2a0b6e-1a00-0000-6ac6-abf67d0a0000 pid=2685->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=ac380074-1a00-0000-6ac6-abf68f0a0000 pid=2703->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=037fa97d-1a00-0000-6ac6-abf6b10a0000 pid=2737->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=85bdae83-1a00-0000-6ac6-abf6c40a0000 pid=2756->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B guuid=cf987e8c-1a00-0000-6ac6-abf6e00a0000 pid=2784->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=bf347e8f-1a00-0000-6ac6-abf6eb0a0000 pid=2795->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B guuid=50af0c95-1a00-0000-6ac6-abf6fc0a0000 pid=2812 /usr/bin/bash guuid=e66cef94-1a00-0000-6ac6-abf6fb0a0000 pid=2811->guuid=50af0c95-1a00-0000-6ac6-abf6fc0a0000 pid=2812 clone guuid=8fe08f95-1a00-0000-6ac6-abf6000b0000 pid=2816->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 136B guuid=58d94e9b-1a00-0000-6ac6-abf60f0b0000 pid=2831->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 85B guuid=34dedba3-1a00-0000-6ac6-abf61d0b0000 pid=2845->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 135B guuid=8dc03eaa-1a00-0000-6ac6-abf62c0b0000 pid=2860->d22a5e33-d698-503d-a0f3-540a55a09d91 send: 84B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-30 21:20:19 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bf524afed3a4c56766d617b3909089d3193c65f7a62ebd13af2a49be8270ccdc

(this sample)

  
Delivery method
Distributed via web download

Comments