MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c7d699759cce2042dc3933c898cfbff866a0872657de44de4efa1b5c96d63b66. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: c7d699759cce2042dc3933c898cfbff866a0872657de44de4efa1b5c96d63b66
SHA3-384 hash: acd7088d63e064a105c437093c64eee70084b9cb402df7c42be4cbb68c4abc0bda8f315db269a54a0cabf944a752a47d
SHA1 hash: 05e9f8af98fdc2a2cf1b18554c57d528a92cb687
MD5 hash: c28214b9e962906bd44533eeadb2df33
humanhash: sodium-autumn-lactose-video
File name:matrix.sh
Download: download sample
Signature Mirai
File size:3'884 bytes
First seen:2026-02-16 09:59:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:iorXo5roXLoTBTO9TDEoTIT9RloTIT9ploSNosZojLLoaRoJTo7joNzN9opsp3ol:frY5kXETBTO9ndTIT9RaTIT9paSCsmj5
TLSH T19B8152B652F20B325C629DF7B7A950277042808994C7BF06EBD968F961FDD4C304865F
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter juroots
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.144.64.166:81/epshteyn_x86_64354b42ba644a621b2d7c63da4fc4b62b93bcfed1962a761826e5a4d6d02db84a Miraimirai
http://45.144.64.166:81/epshteyn_i4868c252a0623638c441aa90a97e7df42a95281028630c578b24dade116955b72f0 Miraimirai
http://45.144.64.166:81/epshteyn_aarch64fa74adf19d58fd9dc812cdbbf22a1951de69ab9dbe21aec87389d507ad1f3146 Miraimirai
http://45.144.64.166:81/epshteyn_mips8281588e04600cbf3cece7261b73873618d8bb2fc451d81fd4bb34ad4f9e639d Miraimirai
http://45.144.64.166:81/epshteyn_mpsld5a387b1fa9e3b03ae0a055aebb844e73c8e1ed1728ba775bb74d918a015c5ef Miraimirai
http://45.144.64.166:81/epshteyn_mips32232d1fbbbc8d0807bfc4c3d236468687adbc92635be4969508d78e029561a10e Miraimirai
http://45.144.64.166:81/epshteyn_arc9a372e6e294b69861d246f5f316047e8fa27e2e970ebb6de1004b105dd9ecfb6 Miraimirai
http://45.144.64.166:81/epshteyn_arm4800a02b006e274ae455ae5f231cfcacfc69cdab5a99870c9adeed76c2fa298b5 Miraimirai
http://45.144.64.166:81/epshteyn_arm59ee3f6e4412df6a836e74081fcc01b5046d5bf3d07f7a97ca108867429730c82 Miraimirai
http://45.144.64.166:81/epshteyn_arm6cb5c01163888125d43f063b02c1a19cdf0a7aecfe8b175f8fbefde50db11232c Miraimirai
http://45.144.64.166:81/epshteyn_arm7918ca73a9ad98ae6b7d9129e22d4e8eae6841d54abadc76925af111aacfe6d00 Miraimirai
http://45.144.64.166:81/epshteyn_ppc07f0056010295dd01ef7292975d3738fdaaa4cf66e909a48fa3eff96aee53d1b Miraimirai
http://45.144.64.166:81/epshteyn_ppc440fe44ed151419ee10d36cbd20f0a7b6fae542b03ecae99ec215279ea39f0c049f Miraimirai
http://45.144.64.166:81/epshteyn_spc876e0e1290b19d3f26a7fcd4ee7c36239902009de02135e6cfbfca8269d95d2f Miraimirai
http://45.144.64.166:81/epshteyn_m68k3ecda2a7a6d13bafea629c41b5b8a35d8e129d873db178d17e1c69adc48a7540 Miraimirai
http://45.144.64.166:81/epshteyn_sh4b7588bde89df4af3e0e90f7fa0e4ae44e6fd4b9efcd515d6f76f1cd5ae70dfb6 Miraimirai
http://45.144.64.166:81/epshteyn_riscv320eb96a804a6097bc1827094043f6388d05f0b1920ad558de7024aa0941967402 Miraimirai
http://45.144.64.166:81/epshteyn_riscv64e648ddd49dcb88cc435bfa0bcdf643d39ccc27c21f901cbd472dd831f4ed317a Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
CH CH
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=382d101a-1b00-0000-dcfe-8d2e170c0000 pid=3095 /usr/bin/sudo guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099 /tmp/sample.bin guuid=382d101a-1b00-0000-dcfe-8d2e170c0000 pid=3095->guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099 execve guuid=c7d4e01c-1b00-0000-dcfe-8d2e1f0c0000 pid=3103 /usr/bin/cp guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=c7d4e01c-1b00-0000-dcfe-8d2e1f0c0000 pid=3103 execve guuid=3dfcd322-1b00-0000-dcfe-8d2e270c0000 pid=3111 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3dfcd322-1b00-0000-dcfe-8d2e270c0000 pid=3111 execve guuid=6d86d433-1b00-0000-dcfe-8d2e550c0000 pid=3157 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=6d86d433-1b00-0000-dcfe-8d2e550c0000 pid=3157 execve guuid=fcbdbb46-1b00-0000-dcfe-8d2e6f0c0000 pid=3183 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=fcbdbb46-1b00-0000-dcfe-8d2e6f0c0000 pid=3183 execve guuid=242c3947-1b00-0000-dcfe-8d2e700c0000 pid=3184 /tmp/epshteyn_x86_64 delete-file net guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=242c3947-1b00-0000-dcfe-8d2e700c0000 pid=3184 execve guuid=59d86a47-1b00-0000-dcfe-8d2e710c0000 pid=3185 /usr/bin/rm guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=59d86a47-1b00-0000-dcfe-8d2e710c0000 pid=3185 execve guuid=eaa4d547-1b00-0000-dcfe-8d2e720c0000 pid=3186 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=eaa4d547-1b00-0000-dcfe-8d2e720c0000 pid=3186 execve guuid=91b17254-1b00-0000-dcfe-8d2e740c0000 pid=3188 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=91b17254-1b00-0000-dcfe-8d2e740c0000 pid=3188 execve guuid=81146062-1b00-0000-dcfe-8d2e900c0000 pid=3216 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=81146062-1b00-0000-dcfe-8d2e900c0000 pid=3216 execve guuid=7df7dc62-1b00-0000-dcfe-8d2e920c0000 pid=3218 /tmp/epshteyn_i486 delete-file net guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=7df7dc62-1b00-0000-dcfe-8d2e920c0000 pid=3218 execve guuid=adc85363-1b00-0000-dcfe-8d2e940c0000 pid=3220 /usr/bin/rm guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=adc85363-1b00-0000-dcfe-8d2e940c0000 pid=3220 execve guuid=1510f563-1b00-0000-dcfe-8d2e950c0000 pid=3221 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=1510f563-1b00-0000-dcfe-8d2e950c0000 pid=3221 execve guuid=47d5967a-1b00-0000-dcfe-8d2e9c0c0000 pid=3228 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=47d5967a-1b00-0000-dcfe-8d2e9c0c0000 pid=3228 execve guuid=297d1c93-1b00-0000-dcfe-8d2eb20c0000 pid=3250 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=297d1c93-1b00-0000-dcfe-8d2eb20c0000 pid=3250 execve guuid=291bb293-1b00-0000-dcfe-8d2eb30c0000 pid=3251 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=291bb293-1b00-0000-dcfe-8d2eb30c0000 pid=3251 clone guuid=48daab94-1b00-0000-dcfe-8d2eb60c0000 pid=3254 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=48daab94-1b00-0000-dcfe-8d2eb60c0000 pid=3254 execve guuid=612a2795-1b00-0000-dcfe-8d2eb70c0000 pid=3255 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=612a2795-1b00-0000-dcfe-8d2eb70c0000 pid=3255 execve guuid=ce9e93a4-1b00-0000-dcfe-8d2ecc0c0000 pid=3276 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=ce9e93a4-1b00-0000-dcfe-8d2ecc0c0000 pid=3276 execve guuid=3bdcb103-1c00-0000-dcfe-8d2e010d0000 pid=3329 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3bdcb103-1c00-0000-dcfe-8d2e010d0000 pid=3329 execve guuid=7973f703-1c00-0000-dcfe-8d2e020d0000 pid=3330 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=7973f703-1c00-0000-dcfe-8d2e020d0000 pid=3330 clone guuid=3ca89804-1c00-0000-dcfe-8d2e060d0000 pid=3334 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3ca89804-1c00-0000-dcfe-8d2e060d0000 pid=3334 execve guuid=35028507-1c00-0000-dcfe-8d2e0d0d0000 pid=3341 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=35028507-1c00-0000-dcfe-8d2e0d0d0000 pid=3341 execve guuid=10b6cb17-1c00-0000-dcfe-8d2e2f0d0000 pid=3375 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=10b6cb17-1c00-0000-dcfe-8d2e2f0d0000 pid=3375 execve guuid=569ebb27-1c00-0000-dcfe-8d2e520d0000 pid=3410 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=569ebb27-1c00-0000-dcfe-8d2e520d0000 pid=3410 execve guuid=3daf1728-1c00-0000-dcfe-8d2e550d0000 pid=3413 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3daf1728-1c00-0000-dcfe-8d2e550d0000 pid=3413 clone guuid=c4840a29-1c00-0000-dcfe-8d2e590d0000 pid=3417 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=c4840a29-1c00-0000-dcfe-8d2e590d0000 pid=3417 execve guuid=1f119029-1c00-0000-dcfe-8d2e5c0d0000 pid=3420 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=1f119029-1c00-0000-dcfe-8d2e5c0d0000 pid=3420 execve guuid=14387f40-1c00-0000-dcfe-8d2e930d0000 pid=3475 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=14387f40-1c00-0000-dcfe-8d2e930d0000 pid=3475 execve guuid=cb638356-1c00-0000-dcfe-8d2ec30d0000 pid=3523 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=cb638356-1c00-0000-dcfe-8d2ec30d0000 pid=3523 execve guuid=1776cd56-1c00-0000-dcfe-8d2ec40d0000 pid=3524 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=1776cd56-1c00-0000-dcfe-8d2ec40d0000 pid=3524 clone guuid=06905057-1c00-0000-dcfe-8d2ec60d0000 pid=3526 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=06905057-1c00-0000-dcfe-8d2ec60d0000 pid=3526 execve guuid=b8dda557-1c00-0000-dcfe-8d2ec70d0000 pid=3527 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=b8dda557-1c00-0000-dcfe-8d2ec70d0000 pid=3527 execve guuid=302ce067-1c00-0000-dcfe-8d2eed0d0000 pid=3565 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=302ce067-1c00-0000-dcfe-8d2eed0d0000 pid=3565 execve guuid=8c75ce77-1c00-0000-dcfe-8d2e140e0000 pid=3604 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=8c75ce77-1c00-0000-dcfe-8d2e140e0000 pid=3604 execve guuid=70782078-1c00-0000-dcfe-8d2e160e0000 pid=3606 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=70782078-1c00-0000-dcfe-8d2e160e0000 pid=3606 clone guuid=2ba4ed78-1c00-0000-dcfe-8d2e190e0000 pid=3609 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=2ba4ed78-1c00-0000-dcfe-8d2e190e0000 pid=3609 execve guuid=e07f5b79-1c00-0000-dcfe-8d2e1b0e0000 pid=3611 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=e07f5b79-1c00-0000-dcfe-8d2e1b0e0000 pid=3611 execve guuid=3c5d9d89-1c00-0000-dcfe-8d2e3d0e0000 pid=3645 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3c5d9d89-1c00-0000-dcfe-8d2e3d0e0000 pid=3645 execve guuid=7b9ac099-1c00-0000-dcfe-8d2e740e0000 pid=3700 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=7b9ac099-1c00-0000-dcfe-8d2e740e0000 pid=3700 execve guuid=b8f70b9a-1c00-0000-dcfe-8d2e750e0000 pid=3701 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=b8f70b9a-1c00-0000-dcfe-8d2e750e0000 pid=3701 clone guuid=21f5299b-1c00-0000-dcfe-8d2e7a0e0000 pid=3706 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=21f5299b-1c00-0000-dcfe-8d2e7a0e0000 pid=3706 execve guuid=661aa99b-1c00-0000-dcfe-8d2e7c0e0000 pid=3708 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=661aa99b-1c00-0000-dcfe-8d2e7c0e0000 pid=3708 execve guuid=2175beaa-1c00-0000-dcfe-8d2e930e0000 pid=3731 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=2175beaa-1c00-0000-dcfe-8d2e930e0000 pid=3731 execve guuid=7617aebc-1c00-0000-dcfe-8d2ed50e0000 pid=3797 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=7617aebc-1c00-0000-dcfe-8d2ed50e0000 pid=3797 execve guuid=f880f5bc-1c00-0000-dcfe-8d2ed70e0000 pid=3799 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=f880f5bc-1c00-0000-dcfe-8d2ed70e0000 pid=3799 clone guuid=a01d83bd-1c00-0000-dcfe-8d2edb0e0000 pid=3803 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=a01d83bd-1c00-0000-dcfe-8d2edb0e0000 pid=3803 execve guuid=55b6d2bd-1c00-0000-dcfe-8d2edd0e0000 pid=3805 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=55b6d2bd-1c00-0000-dcfe-8d2edd0e0000 pid=3805 execve guuid=9dea1ccd-1c00-0000-dcfe-8d2e180f0000 pid=3864 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=9dea1ccd-1c00-0000-dcfe-8d2e180f0000 pid=3864 execve guuid=9b80b1e0-1c00-0000-dcfe-8d2e4c0f0000 pid=3916 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=9b80b1e0-1c00-0000-dcfe-8d2e4c0f0000 pid=3916 execve guuid=5310f3e0-1c00-0000-dcfe-8d2e4d0f0000 pid=3917 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=5310f3e0-1c00-0000-dcfe-8d2e4d0f0000 pid=3917 clone guuid=0d03aae1-1c00-0000-dcfe-8d2e520f0000 pid=3922 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=0d03aae1-1c00-0000-dcfe-8d2e520f0000 pid=3922 execve guuid=d185f5e1-1c00-0000-dcfe-8d2e530f0000 pid=3923 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=d185f5e1-1c00-0000-dcfe-8d2e530f0000 pid=3923 execve guuid=db1cc9f2-1c00-0000-dcfe-8d2e800f0000 pid=3968 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=db1cc9f2-1c00-0000-dcfe-8d2e800f0000 pid=3968 execve guuid=82c7f703-1d00-0000-dcfe-8d2ec50f0000 pid=4037 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=82c7f703-1d00-0000-dcfe-8d2ec50f0000 pid=4037 execve guuid=399e4c04-1d00-0000-dcfe-8d2ec60f0000 pid=4038 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=399e4c04-1d00-0000-dcfe-8d2ec60f0000 pid=4038 clone guuid=89413306-1d00-0000-dcfe-8d2ecb0f0000 pid=4043 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=89413306-1d00-0000-dcfe-8d2ecb0f0000 pid=4043 execve guuid=050f7d06-1d00-0000-dcfe-8d2ecd0f0000 pid=4045 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=050f7d06-1d00-0000-dcfe-8d2ecd0f0000 pid=4045 execve guuid=3cebf914-1d00-0000-dcfe-8d2efe0f0000 pid=4094 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3cebf914-1d00-0000-dcfe-8d2efe0f0000 pid=4094 execve guuid=88c4fd3e-1d00-0000-dcfe-8d2e32100000 pid=4146 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=88c4fd3e-1d00-0000-dcfe-8d2e32100000 pid=4146 execve guuid=5496513f-1d00-0000-dcfe-8d2e34100000 pid=4148 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=5496513f-1d00-0000-dcfe-8d2e34100000 pid=4148 clone guuid=c3e1e53f-1d00-0000-dcfe-8d2e39100000 pid=4153 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=c3e1e53f-1d00-0000-dcfe-8d2e39100000 pid=4153 execve guuid=f3c44f40-1d00-0000-dcfe-8d2e3b100000 pid=4155 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=f3c44f40-1d00-0000-dcfe-8d2e3b100000 pid=4155 execve guuid=1fbff24e-1d00-0000-dcfe-8d2e66100000 pid=4198 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=1fbff24e-1d00-0000-dcfe-8d2e66100000 pid=4198 execve guuid=6e2b115f-1d00-0000-dcfe-8d2e86100000 pid=4230 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=6e2b115f-1d00-0000-dcfe-8d2e86100000 pid=4230 execve guuid=be03a75f-1d00-0000-dcfe-8d2e87100000 pid=4231 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=be03a75f-1d00-0000-dcfe-8d2e87100000 pid=4231 clone guuid=25a30662-1d00-0000-dcfe-8d2e8e100000 pid=4238 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=25a30662-1d00-0000-dcfe-8d2e8e100000 pid=4238 execve guuid=90725762-1d00-0000-dcfe-8d2e92100000 pid=4242 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=90725762-1d00-0000-dcfe-8d2e92100000 pid=4242 execve guuid=3b94616c-1d00-0000-dcfe-8d2eb7100000 pid=4279 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=3b94616c-1d00-0000-dcfe-8d2eb7100000 pid=4279 execve guuid=0beafd76-1d00-0000-dcfe-8d2eda100000 pid=4314 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=0beafd76-1d00-0000-dcfe-8d2eda100000 pid=4314 execve guuid=789f9b77-1d00-0000-dcfe-8d2edb100000 pid=4315 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=789f9b77-1d00-0000-dcfe-8d2edb100000 pid=4315 clone guuid=32ed5b79-1d00-0000-dcfe-8d2ee1100000 pid=4321 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=32ed5b79-1d00-0000-dcfe-8d2ee1100000 pid=4321 execve guuid=50d2c879-1d00-0000-dcfe-8d2ee3100000 pid=4323 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=50d2c879-1d00-0000-dcfe-8d2ee3100000 pid=4323 execve guuid=ca825189-1d00-0000-dcfe-8d2e1f110000 pid=4383 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=ca825189-1d00-0000-dcfe-8d2e1f110000 pid=4383 execve guuid=c9023a9a-1d00-0000-dcfe-8d2e54110000 pid=4436 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=c9023a9a-1d00-0000-dcfe-8d2e54110000 pid=4436 execve guuid=c973059b-1d00-0000-dcfe-8d2e58110000 pid=4440 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=c973059b-1d00-0000-dcfe-8d2e58110000 pid=4440 clone guuid=6aabb59b-1d00-0000-dcfe-8d2e5c110000 pid=4444 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=6aabb59b-1d00-0000-dcfe-8d2e5c110000 pid=4444 execve guuid=b2c4059c-1d00-0000-dcfe-8d2e5e110000 pid=4446 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=b2c4059c-1d00-0000-dcfe-8d2e5e110000 pid=4446 execve guuid=a2408dab-1d00-0000-dcfe-8d2e9c110000 pid=4508 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=a2408dab-1d00-0000-dcfe-8d2e9c110000 pid=4508 execve guuid=bb4a62bc-1d00-0000-dcfe-8d2ee1110000 pid=4577 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=bb4a62bc-1d00-0000-dcfe-8d2ee1110000 pid=4577 execve guuid=a513a3bc-1d00-0000-dcfe-8d2ee3110000 pid=4579 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=a513a3bc-1d00-0000-dcfe-8d2ee3110000 pid=4579 clone guuid=56cf60bd-1d00-0000-dcfe-8d2ee7110000 pid=4583 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=56cf60bd-1d00-0000-dcfe-8d2ee7110000 pid=4583 execve guuid=9a41b0bd-1d00-0000-dcfe-8d2ee9110000 pid=4585 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=9a41b0bd-1d00-0000-dcfe-8d2ee9110000 pid=4585 execve guuid=f192a1d3-1d00-0000-dcfe-8d2e38120000 pid=4664 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=f192a1d3-1d00-0000-dcfe-8d2e38120000 pid=4664 execve guuid=747303f7-1d00-0000-dcfe-8d2ec8120000 pid=4808 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=747303f7-1d00-0000-dcfe-8d2ec8120000 pid=4808 execve guuid=e61640f7-1d00-0000-dcfe-8d2ecc120000 pid=4812 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=e61640f7-1d00-0000-dcfe-8d2ecc120000 pid=4812 clone guuid=48c6c2f7-1d00-0000-dcfe-8d2ed0120000 pid=4816 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=48c6c2f7-1d00-0000-dcfe-8d2ed0120000 pid=4816 execve guuid=e57132f8-1d00-0000-dcfe-8d2ed4120000 pid=4820 /usr/bin/wget net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=e57132f8-1d00-0000-dcfe-8d2ed4120000 pid=4820 execve guuid=b1e42f0d-1e00-0000-dcfe-8d2e13130000 pid=4883 /usr/bin/curl net send-data write-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=b1e42f0d-1e00-0000-dcfe-8d2e13130000 pid=4883 execve guuid=b9a67a24-1e00-0000-dcfe-8d2e64130000 pid=4964 /usr/bin/chmod guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=b9a67a24-1e00-0000-dcfe-8d2e64130000 pid=4964 execve guuid=55e5c024-1e00-0000-dcfe-8d2e67130000 pid=4967 /usr/bin/bash guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=55e5c024-1e00-0000-dcfe-8d2e67130000 pid=4967 clone guuid=e5441026-1e00-0000-dcfe-8d2e6d130000 pid=4973 /usr/bin/rm delete-file guuid=06e10a1c-1b00-0000-dcfe-8d2e1b0c0000 pid=3099->guuid=e5441026-1e00-0000-dcfe-8d2e6d130000 pid=4973 execve 77639cd7-c402-5514-8f87-f0d3cc8fa2c2 45.144.64.166:81 guuid=3dfcd322-1b00-0000-dcfe-8d2e270c0000 pid=3111->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=6d86d433-1b00-0000-dcfe-8d2e550c0000 pid=3157->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=242c3947-1b00-0000-dcfe-8d2e700c0000 pid=3184->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eaa4d547-1b00-0000-dcfe-8d2e720c0000 pid=3186->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=91b17254-1b00-0000-dcfe-8d2e740c0000 pid=3188->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=7df7dc62-1b00-0000-dcfe-8d2e920c0000 pid=3218->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1510f563-1b00-0000-dcfe-8d2e950c0000 pid=3221->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=47d5967a-1b00-0000-dcfe-8d2e9c0c0000 pid=3228->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B guuid=612a2795-1b00-0000-dcfe-8d2eb70c0000 pid=3255->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=ce9e93a4-1b00-0000-dcfe-8d2ecc0c0000 pid=3276->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=35028507-1c00-0000-dcfe-8d2e0d0d0000 pid=3341->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=10b6cb17-1c00-0000-dcfe-8d2e2f0d0000 pid=3375->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=1f119029-1c00-0000-dcfe-8d2e5c0d0000 pid=3420->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=14387f40-1c00-0000-dcfe-8d2e930d0000 pid=3475->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B guuid=b8dda557-1c00-0000-dcfe-8d2ec70d0000 pid=3527->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=302ce067-1c00-0000-dcfe-8d2eed0d0000 pid=3565->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=e07f5b79-1c00-0000-dcfe-8d2e1b0e0000 pid=3611->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=3c5d9d89-1c00-0000-dcfe-8d2e3d0e0000 pid=3645->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=661aa99b-1c00-0000-dcfe-8d2e7c0e0000 pid=3708->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=2175beaa-1c00-0000-dcfe-8d2e930e0000 pid=3731->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=55b6d2bd-1c00-0000-dcfe-8d2edd0e0000 pid=3805->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=9dea1ccd-1c00-0000-dcfe-8d2e180f0000 pid=3864->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=d185f5e1-1c00-0000-dcfe-8d2e530f0000 pid=3923->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=db1cc9f2-1c00-0000-dcfe-8d2e800f0000 pid=3968->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=050f7d06-1d00-0000-dcfe-8d2ecd0f0000 pid=4045->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=3cebf914-1d00-0000-dcfe-8d2efe0f0000 pid=4094->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=f3c44f40-1d00-0000-dcfe-8d2e3b100000 pid=4155->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 146B guuid=1fbff24e-1d00-0000-dcfe-8d2e66100000 pid=4198->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 95B guuid=90725762-1d00-0000-dcfe-8d2e92100000 pid=4242->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=3b94616c-1d00-0000-dcfe-8d2eb7100000 pid=4279->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=50d2c879-1d00-0000-dcfe-8d2ee3100000 pid=4323->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 144B guuid=ca825189-1d00-0000-dcfe-8d2e1f110000 pid=4383->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 93B guuid=b2c4059c-1d00-0000-dcfe-8d2e5e110000 pid=4446->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 143B guuid=a2408dab-1d00-0000-dcfe-8d2e9c110000 pid=4508->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 92B guuid=9a41b0bd-1d00-0000-dcfe-8d2ee9110000 pid=4585->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=f192a1d3-1d00-0000-dcfe-8d2e38120000 pid=4664->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B guuid=e57132f8-1d00-0000-dcfe-8d2ed4120000 pid=4820->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 147B guuid=b1e42f0d-1e00-0000-dcfe-8d2e13130000 pid=4883->77639cd7-c402-5514-8f87-f0d3cc8fa2c2 send: 96B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-16 10:00:37 UTC
File Type:
Text (Shell)
AV detection:
19 of 35 (54.29%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c7d699759cce2042dc3933c898cfbff866a0872657de44de4efa1b5c96d63b66

(this sample)

  
Delivery method
Distributed via web download

Comments