MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bfb04c46cee4523982d19d0a47be747fb4988dfb41c8bf332895cb5c9e794a2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: bfb04c46cee4523982d19d0a47be747fb4988dfb41c8bf332895cb5c9e794a2b
SHA3-384 hash: 9302b0ef217b1859e34da58f5c0d7f886e9bfb7ddb5d2fd582405976033272150aec9c39e057528b6915b0b276f25a67
SHA1 hash: 663a801ff4b19efd263de8b49bda3b2b1ca90cbb
MD5 hash: e2fa1f0760ca599f002b852b5eaa06a6
humanhash: fillet-early-hotel-paris
File name:1.sh
Download: download sample
Signature Mirai
File size:3'347 bytes
First seen:2025-12-28 00:47:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:YNE3NpFNaE2NE2EGLesNzxNrBNlolxN43NTFLNshJNtlN020y56sNOzNirNFt0:YqBYZ/DcW3Lm5mly56sE8R0
TLSH T1486173CAB29603F39DF24BAB72764C4437E4A1E644C6AE15A5DCA4F1094DD3C740B5D3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.216.189.149/HOME/Mark90c80.x86e2bcf189c377f8a005f152bad20c89f66f74dfd40f6c5432b5a2e01831ba014e Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.mips271d6a0e041ad8a3fcb638d869b36abc1d358509f69a57817c561723973dd305 Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.arc64e28d40ae1b261c53dafe3ede379e4286e5cf16bec6839486df9cd96fe1cb0b Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.i468n/an/aelf ua-wget
http://41.216.189.149/HOME/Mark90c80.i6865c3143983ed8466d1dfad3b559c5e889431ca53c41b9ea8fb523e7f8ec17d781 Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.x86_6462cebcf7aabaff4f582c281f620811e45a16ac5e5fcfdd782f8748dc01c18a17 Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.mpsl88c5165e657f1257c2968e8d7653f72128db4128741ee59a421b5456279ef0f8 Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.armeb32c5d648cb6ac14419232cdb50f6babd4f1034b16b1bb0b7a9491b1c394a3a Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.arm56e04ebb5902187654c319021840c486cbc8e9202325d35fd668b5545956d6d7c Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.arm6n/an/aelf ua-wget
http://41.216.189.149/HOME/Mark90c80.arm7n/an/aelf ua-wget
http://41.216.189.149/HOME/Mark90c80.ppc87d5d6f02f582b4ce13433f4dad7f428ea812bfdc6b3fdc5983ec5c1ecb6bc1a Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.spcn/an/aelf ua-wget
http://41.216.189.149/HOME/Mark90c80.m68k3155e9279470b9498e8b9f70a9bf57a6351be5fb47ddc2e5dc3a57456771c271 Miraielf mirai ua-wget
http://41.216.189.149/HOME/Mark90c80.sh4ed7f373864180e1c167c8bc9d45725b7d7c3df7604d7834280b0f2003d52d948 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai virus
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-27T21:43:00Z UTC
Last seen:
2025-12-27T21:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=970e3a87-1700-0000-42f0-bfe9b30a0000 pid=2739 /usr/bin/sudo guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746 /tmp/sample.bin guuid=970e3a87-1700-0000-42f0-bfe9b30a0000 pid=2739->guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746 execve guuid=950edb89-1700-0000-42f0-bfe9bb0a0000 pid=2747 /usr/bin/cp guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=950edb89-1700-0000-42f0-bfe9bb0a0000 pid=2747 execve guuid=9833798f-1700-0000-42f0-bfe9bd0a0000 pid=2749 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=9833798f-1700-0000-42f0-bfe9bd0a0000 pid=2749 execve guuid=4426a494-1700-0000-42f0-bfe9c60a0000 pid=2758 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=4426a494-1700-0000-42f0-bfe9c60a0000 pid=2758 execve guuid=ca137ca2-1700-0000-42f0-bfe9df0a0000 pid=2783 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=ca137ca2-1700-0000-42f0-bfe9df0a0000 pid=2783 execve guuid=ca4bdaa2-1700-0000-42f0-bfe9e10a0000 pid=2785 /tmp/Mark90c80.x86 net guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=ca4bdaa2-1700-0000-42f0-bfe9e10a0000 pid=2785 execve guuid=c9c27ca3-1700-0000-42f0-bfe9e60a0000 pid=2790 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=c9c27ca3-1700-0000-42f0-bfe9e60a0000 pid=2790 execve guuid=6e568ba4-1700-0000-42f0-bfe9ea0a0000 pid=2794 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=6e568ba4-1700-0000-42f0-bfe9ea0a0000 pid=2794 execve guuid=d32a3fa8-1700-0000-42f0-bfe9ec0a0000 pid=2796 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=d32a3fa8-1700-0000-42f0-bfe9ec0a0000 pid=2796 execve guuid=5faf2aaf-1700-0000-42f0-bfe9fd0a0000 pid=2813 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=5faf2aaf-1700-0000-42f0-bfe9fd0a0000 pid=2813 execve guuid=4b476faf-1700-0000-42f0-bfe9fe0a0000 pid=2814 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=4b476faf-1700-0000-42f0-bfe9fe0a0000 pid=2814 clone guuid=a3f03bb0-1700-0000-42f0-bfe9000b0000 pid=2816 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=a3f03bb0-1700-0000-42f0-bfe9000b0000 pid=2816 execve guuid=aa232eb1-1700-0000-42f0-bfe9030b0000 pid=2819 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=aa232eb1-1700-0000-42f0-bfe9030b0000 pid=2819 execve guuid=887b12b6-1700-0000-42f0-bfe9110b0000 pid=2833 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=887b12b6-1700-0000-42f0-bfe9110b0000 pid=2833 execve guuid=f946febc-1700-0000-42f0-bfe9280b0000 pid=2856 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=f946febc-1700-0000-42f0-bfe9280b0000 pid=2856 execve guuid=3b9143bd-1700-0000-42f0-bfe92a0b0000 pid=2858 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=3b9143bd-1700-0000-42f0-bfe92a0b0000 pid=2858 clone guuid=b23ecfbd-1700-0000-42f0-bfe92e0b0000 pid=2862 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=b23ecfbd-1700-0000-42f0-bfe92e0b0000 pid=2862 execve guuid=fec720c2-1700-0000-42f0-bfe9400b0000 pid=2880 /usr/bin/wget net send-data guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=fec720c2-1700-0000-42f0-bfe9400b0000 pid=2880 execve guuid=c67265c4-1700-0000-42f0-bfe9490b0000 pid=2889 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=c67265c4-1700-0000-42f0-bfe9490b0000 pid=2889 execve guuid=5838e8c8-1700-0000-42f0-bfe95a0b0000 pid=2906 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=5838e8c8-1700-0000-42f0-bfe95a0b0000 pid=2906 execve guuid=d9ec39c9-1700-0000-42f0-bfe95b0b0000 pid=2907 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=d9ec39c9-1700-0000-42f0-bfe95b0b0000 pid=2907 clone guuid=f10373c9-1700-0000-42f0-bfe95c0b0000 pid=2908 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=f10373c9-1700-0000-42f0-bfe95c0b0000 pid=2908 execve guuid=cf2db8c9-1700-0000-42f0-bfe95e0b0000 pid=2910 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=cf2db8c9-1700-0000-42f0-bfe95e0b0000 pid=2910 execve guuid=ae9d6acd-1700-0000-42f0-bfe96c0b0000 pid=2924 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=ae9d6acd-1700-0000-42f0-bfe96c0b0000 pid=2924 execve guuid=392306d2-1700-0000-42f0-bfe9770b0000 pid=2935 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=392306d2-1700-0000-42f0-bfe9770b0000 pid=2935 execve guuid=fc3559d2-1700-0000-42f0-bfe9780b0000 pid=2936 /tmp/Mark90c80.i686 net guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=fc3559d2-1700-0000-42f0-bfe9780b0000 pid=2936 execve guuid=8d6e22d3-1700-0000-42f0-bfe97a0b0000 pid=2938 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=8d6e22d3-1700-0000-42f0-bfe97a0b0000 pid=2938 execve guuid=3a3ab0d3-1700-0000-42f0-bfe97b0b0000 pid=2939 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=3a3ab0d3-1700-0000-42f0-bfe97b0b0000 pid=2939 execve guuid=c69cd6d9-1700-0000-42f0-bfe9890b0000 pid=2953 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=c69cd6d9-1700-0000-42f0-bfe9890b0000 pid=2953 execve guuid=07f7cbe1-1700-0000-42f0-bfe99b0b0000 pid=2971 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=07f7cbe1-1700-0000-42f0-bfe99b0b0000 pid=2971 execve guuid=f4d107e2-1700-0000-42f0-bfe99d0b0000 pid=2973 /tmp/Mark90c80.x86_64 mprotect-exec net guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=f4d107e2-1700-0000-42f0-bfe99d0b0000 pid=2973 execve guuid=db23a9e2-1700-0000-42f0-bfe99f0b0000 pid=2975 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=db23a9e2-1700-0000-42f0-bfe99f0b0000 pid=2975 execve guuid=1602efe2-1700-0000-42f0-bfe9a10b0000 pid=2977 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=1602efe2-1700-0000-42f0-bfe9a10b0000 pid=2977 execve guuid=a12599e6-1700-0000-42f0-bfe9a30b0000 pid=2979 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=a12599e6-1700-0000-42f0-bfe9a30b0000 pid=2979 execve guuid=e1db43ed-1700-0000-42f0-bfe9b00b0000 pid=2992 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=e1db43ed-1700-0000-42f0-bfe9b00b0000 pid=2992 execve guuid=5ebaa1ed-1700-0000-42f0-bfe9b20b0000 pid=2994 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=5ebaa1ed-1700-0000-42f0-bfe9b20b0000 pid=2994 clone guuid=6659ecef-1700-0000-42f0-bfe9b90b0000 pid=3001 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=6659ecef-1700-0000-42f0-bfe9b90b0000 pid=3001 execve guuid=0bafdbf0-1700-0000-42f0-bfe9bb0b0000 pid=3003 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=0bafdbf0-1700-0000-42f0-bfe9bb0b0000 pid=3003 execve guuid=a58129f9-1700-0000-42f0-bfe9ce0b0000 pid=3022 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=a58129f9-1700-0000-42f0-bfe9ce0b0000 pid=3022 execve guuid=9f540700-1800-0000-42f0-bfe9e20b0000 pid=3042 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=9f540700-1800-0000-42f0-bfe9e20b0000 pid=3042 execve guuid=bcefc800-1800-0000-42f0-bfe9e50b0000 pid=3045 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=bcefc800-1800-0000-42f0-bfe9e50b0000 pid=3045 clone guuid=349d6202-1800-0000-42f0-bfe9e70b0000 pid=3047 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=349d6202-1800-0000-42f0-bfe9e70b0000 pid=3047 execve guuid=25161204-1800-0000-42f0-bfe9ea0b0000 pid=3050 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=25161204-1800-0000-42f0-bfe9ea0b0000 pid=3050 execve guuid=3af3a10a-1800-0000-42f0-bfe9ff0b0000 pid=3071 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=3af3a10a-1800-0000-42f0-bfe9ff0b0000 pid=3071 execve guuid=ff089616-1800-0000-42f0-bfe9280c0000 pid=3112 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=ff089616-1800-0000-42f0-bfe9280c0000 pid=3112 execve guuid=f93d6917-1800-0000-42f0-bfe92b0c0000 pid=3115 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=f93d6917-1800-0000-42f0-bfe92b0c0000 pid=3115 clone guuid=aadbab19-1800-0000-42f0-bfe9300c0000 pid=3120 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=aadbab19-1800-0000-42f0-bfe9300c0000 pid=3120 execve guuid=13a4fa1c-1800-0000-42f0-bfe9360c0000 pid=3126 /usr/bin/wget net send-data guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=13a4fa1c-1800-0000-42f0-bfe9360c0000 pid=3126 execve guuid=b0e59321-1800-0000-42f0-bfe93f0c0000 pid=3135 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=b0e59321-1800-0000-42f0-bfe93f0c0000 pid=3135 execve guuid=cc0b1c29-1800-0000-42f0-bfe9510c0000 pid=3153 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=cc0b1c29-1800-0000-42f0-bfe9510c0000 pid=3153 execve guuid=b1fad129-1800-0000-42f0-bfe9540c0000 pid=3156 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=b1fad129-1800-0000-42f0-bfe9540c0000 pid=3156 clone guuid=0781fa29-1800-0000-42f0-bfe9560c0000 pid=3158 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=0781fa29-1800-0000-42f0-bfe9560c0000 pid=3158 execve guuid=7ba1f02b-1800-0000-42f0-bfe95e0c0000 pid=3166 /usr/bin/wget net send-data guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=7ba1f02b-1800-0000-42f0-bfe95e0c0000 pid=3166 execve guuid=fb5d0c31-1800-0000-42f0-bfe9710c0000 pid=3185 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=fb5d0c31-1800-0000-42f0-bfe9710c0000 pid=3185 execve guuid=4cde5737-1800-0000-42f0-bfe9840c0000 pid=3204 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=4cde5737-1800-0000-42f0-bfe9840c0000 pid=3204 execve guuid=37d09c37-1800-0000-42f0-bfe9860c0000 pid=3206 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=37d09c37-1800-0000-42f0-bfe9860c0000 pid=3206 clone guuid=5409c237-1800-0000-42f0-bfe9870c0000 pid=3207 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=5409c237-1800-0000-42f0-bfe9870c0000 pid=3207 execve guuid=044f4238-1800-0000-42f0-bfe98a0c0000 pid=3210 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=044f4238-1800-0000-42f0-bfe98a0c0000 pid=3210 execve guuid=02eecc41-1800-0000-42f0-bfe99a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=02eecc41-1800-0000-42f0-bfe99a0c0000 pid=3226 execve guuid=efc5ed48-1800-0000-42f0-bfe9a60c0000 pid=3238 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=efc5ed48-1800-0000-42f0-bfe9a60c0000 pid=3238 execve guuid=9f11494b-1800-0000-42f0-bfe9a70c0000 pid=3239 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=9f11494b-1800-0000-42f0-bfe9a70c0000 pid=3239 clone guuid=2fa5624b-1800-0000-42f0-bfe9a80c0000 pid=3240 /usr/bin/rm guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=2fa5624b-1800-0000-42f0-bfe9a80c0000 pid=3240 execve guuid=1d86a64b-1800-0000-42f0-bfe9aa0c0000 pid=3242 /usr/bin/wget net send-data guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=1d86a64b-1800-0000-42f0-bfe9aa0c0000 pid=3242 execve guuid=2cac0a4e-1800-0000-42f0-bfe9ac0c0000 pid=3244 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=2cac0a4e-1800-0000-42f0-bfe9ac0c0000 pid=3244 execve guuid=31332257-1800-0000-42f0-bfe9b20c0000 pid=3250 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=31332257-1800-0000-42f0-bfe9b20c0000 pid=3250 execve guuid=405f6057-1800-0000-42f0-bfe9b30c0000 pid=3251 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=405f6057-1800-0000-42f0-bfe9b30c0000 pid=3251 clone guuid=65ec8357-1800-0000-42f0-bfe9b40c0000 pid=3252 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=65ec8357-1800-0000-42f0-bfe9b40c0000 pid=3252 execve guuid=0db3c057-1800-0000-42f0-bfe9b60c0000 pid=3254 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=0db3c057-1800-0000-42f0-bfe9b60c0000 pid=3254 execve guuid=a677ef5b-1800-0000-42f0-bfe9b70c0000 pid=3255 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=a677ef5b-1800-0000-42f0-bfe9b70c0000 pid=3255 execve guuid=c6dda562-1800-0000-42f0-bfe9b80c0000 pid=3256 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=c6dda562-1800-0000-42f0-bfe9b80c0000 pid=3256 execve guuid=5e0f1063-1800-0000-42f0-bfe9b90c0000 pid=3257 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=5e0f1063-1800-0000-42f0-bfe9b90c0000 pid=3257 clone guuid=2b7eaa63-1800-0000-42f0-bfe9bb0c0000 pid=3259 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=2b7eaa63-1800-0000-42f0-bfe9bb0c0000 pid=3259 execve guuid=1c05f263-1800-0000-42f0-bfe9bc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=1c05f263-1800-0000-42f0-bfe9bc0c0000 pid=3260 execve guuid=38a74568-1800-0000-42f0-bfe9bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=38a74568-1800-0000-42f0-bfe9bd0c0000 pid=3261 execve guuid=d0b6306d-1800-0000-42f0-bfe9bf0c0000 pid=3263 /usr/bin/chmod guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=d0b6306d-1800-0000-42f0-bfe9bf0c0000 pid=3263 execve guuid=cf0b6e6d-1800-0000-42f0-bfe9c00c0000 pid=3264 /usr/bin/bash guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=cf0b6e6d-1800-0000-42f0-bfe9c00c0000 pid=3264 clone guuid=b03bf16d-1800-0000-42f0-bfe9c20c0000 pid=3266 /usr/bin/rm delete-file guuid=1c6b6e89-1700-0000-42f0-bfe9ba0a0000 pid=2746->guuid=b03bf16d-1800-0000-42f0-bfe9c20c0000 pid=3266 execve 6af55d18-ce3e-52a6-afd4-3a102b893152 41.216.189.149:80 guuid=9833798f-1700-0000-42f0-bfe9bd0a0000 pid=2749->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=4426a494-1700-0000-42f0-bfe9c60a0000 pid=2758->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ca4bdaa2-1700-0000-42f0-bfe9e10a0000 pid=2785->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b4b374a3-1700-0000-42f0-bfe9e40a0000 pid=2788 /tmp/Mark90c80.x86 guuid=ca4bdaa2-1700-0000-42f0-bfe9e10a0000 pid=2785->guuid=b4b374a3-1700-0000-42f0-bfe9e40a0000 pid=2788 clone guuid=fd897da3-1700-0000-42f0-bfe9e70a0000 pid=2791 /tmp/Mark90c80.x86 guuid=b4b374a3-1700-0000-42f0-bfe9e40a0000 pid=2788->guuid=fd897da3-1700-0000-42f0-bfe9e70a0000 pid=2791 clone guuid=6e568ba4-1700-0000-42f0-bfe9ea0a0000 pid=2794->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=d32a3fa8-1700-0000-42f0-bfe9ec0a0000 pid=2796->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=aa232eb1-1700-0000-42f0-bfe9030b0000 pid=2819->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=887b12b6-1700-0000-42f0-bfe9110b0000 pid=2833->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B guuid=fec720c2-1700-0000-42f0-bfe9400b0000 pid=2880->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=c67265c4-1700-0000-42f0-bfe9490b0000 pid=2889->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=cf2db8c9-1700-0000-42f0-bfe95e0b0000 pid=2910->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=ae9d6acd-1700-0000-42f0-bfe96c0b0000 pid=2924->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=fc3559d2-1700-0000-42f0-bfe9780b0000 pid=2936->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=362a17d3-1700-0000-42f0-bfe9790b0000 pid=2937 /tmp/Mark90c80.i686 guuid=fc3559d2-1700-0000-42f0-bfe9780b0000 pid=2936->guuid=362a17d3-1700-0000-42f0-bfe9790b0000 pid=2937 clone guuid=ec6cb6d3-1700-0000-42f0-bfe97c0b0000 pid=2940 /tmp/Mark90c80.i686 guuid=362a17d3-1700-0000-42f0-bfe9790b0000 pid=2937->guuid=ec6cb6d3-1700-0000-42f0-bfe97c0b0000 pid=2940 clone guuid=3a3ab0d3-1700-0000-42f0-bfe97b0b0000 pid=2939->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 150B guuid=c69cd6d9-1700-0000-42f0-bfe9890b0000 pid=2953->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 99B guuid=f4d107e2-1700-0000-42f0-bfe99d0b0000 pid=2973->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6203a1e2-1700-0000-42f0-bfe99e0b0000 pid=2974 /tmp/Mark90c80.x86_64 zombie guuid=f4d107e2-1700-0000-42f0-bfe99d0b0000 pid=2973->guuid=6203a1e2-1700-0000-42f0-bfe99e0b0000 pid=2974 clone guuid=0876b5e2-1700-0000-42f0-bfe9a00b0000 pid=2976 /tmp/Mark90c80.x86_64 zombie guuid=6203a1e2-1700-0000-42f0-bfe99e0b0000 pid=2974->guuid=0876b5e2-1700-0000-42f0-bfe9a00b0000 pid=2976 clone guuid=fd713542-1800-0000-42f0-bfe99b0c0000 pid=3227 /tmp/Mark90c80.x86_64 net send-data zombie guuid=0876b5e2-1700-0000-42f0-bfe9a00b0000 pid=2976->guuid=fd713542-1800-0000-42f0-bfe99b0c0000 pid=3227 clone guuid=1602efe2-1700-0000-42f0-bfe9a10b0000 pid=2977->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=a12599e6-1700-0000-42f0-bfe9a30b0000 pid=2979->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=0bafdbf0-1700-0000-42f0-bfe9bb0b0000 pid=3003->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=a58129f9-1700-0000-42f0-bfe9ce0b0000 pid=3022->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B guuid=25161204-1800-0000-42f0-bfe9ea0b0000 pid=3050->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=3af3a10a-1800-0000-42f0-bfe9ff0b0000 pid=3071->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=13a4fa1c-1800-0000-42f0-bfe9360c0000 pid=3126->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=b0e59321-1800-0000-42f0-bfe93f0c0000 pid=3135->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=7ba1f02b-1800-0000-42f0-bfe95e0c0000 pid=3166->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=fb5d0c31-1800-0000-42f0-bfe9710c0000 pid=3185->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=044f4238-1800-0000-42f0-bfe98a0c0000 pid=3210->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=02eecc41-1800-0000-42f0-bfe99a0c0000 pid=3226->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B guuid=fd713542-1800-0000-42f0-bfe99b0c0000 pid=3227->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 627B guuid=7ca14a42-1800-0000-42f0-bfe99c0c0000 pid=3228 /tmp/Mark90c80.x86_64 guuid=fd713542-1800-0000-42f0-bfe99b0c0000 pid=3227->guuid=7ca14a42-1800-0000-42f0-bfe99c0c0000 pid=3228 clone guuid=b02a4e42-1800-0000-42f0-bfe99d0c0000 pid=3229 /tmp/Mark90c80.x86_64 delete-file guuid=7ca14a42-1800-0000-42f0-bfe99c0c0000 pid=3228->guuid=b02a4e42-1800-0000-42f0-bfe99d0c0000 pid=3229 clone guuid=10645342-1800-0000-42f0-bfe99e0c0000 pid=3230 /tmp/Mark90c80.x86_64 zombie guuid=7ca14a42-1800-0000-42f0-bfe99c0c0000 pid=3228->guuid=10645342-1800-0000-42f0-bfe99e0c0000 pid=3230 clone guuid=1d86a64b-1800-0000-42f0-bfe9aa0c0000 pid=3242->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=2cac0a4e-1800-0000-42f0-bfe9ac0c0000 pid=3244->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B guuid=0db3c057-1800-0000-42f0-bfe9b60c0000 pid=3254->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 148B guuid=a677ef5b-1800-0000-42f0-bfe9b70c0000 pid=3255->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 97B guuid=1c05f263-1800-0000-42f0-bfe9bc0c0000 pid=3260->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 147B guuid=38a74568-1800-0000-42f0-bfe9bd0c0000 pid=3261->6af55d18-ce3e-52a6-afd4-3a102b893152 send: 96B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-28 00:48:13 UTC
File Type:
Text (Shell)
AV detection:
20 of 36 (55.56%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Deletes log files
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Deletes Audit logs
Deletes system logs
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bfb04c46cee4523982d19d0a47be747fb4988dfb41c8bf332895cb5c9e794a2b

(this sample)

Comments