MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c86247a6f0565194bcb0f2864ead389d543b10e23eaf2a59d8f652bb84414219. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: c86247a6f0565194bcb0f2864ead389d543b10e23eaf2a59d8f652bb84414219
SHA3-384 hash: 9b0e27e33b63e378c1608b5412d87fd5f147174b0fb54b2a7f5bef95176e7d72dfb5da102471c0ffa9f6888b6f28e0d6
SHA1 hash: d0c903f7e8d039e02e60203f7f59746b3c75aa49
MD5 hash: 0a3d64e0b51b62f2ed11ccde02463b96
humanhash: cola-emma-magazine-happy
File name:mass
Download: download sample
Signature Mirai
File size:1'953 bytes
First seen:2025-09-27 04:37:19 UTC
Last seen:2025-09-27 06:48:11 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:pXISnfgcB7MEgrS8bDgdq4NlgqT1Y1igBATaxgagUdLEsgAP9wYgrGDgbDgMf9c2:pXISnfgcB7MEgrS8bDgdq4NlgqT1aiga
TLSH T11C4100DA7C101913130DFE8CA3B2C469A05E84DDA78A21E8B6A55EAD9D4C70E7970F4C
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.35.154/powerpc.urbotnetisass09a18ca51af0504d1de3691d6a5c290d3e2c1a6c98043957b8518267a3bb12ed Miraielf geofenced mirai ua-wget USA
http://94.154.35.154/mips.urbotnetisassb18659cad3db34b8d2d82ad5786c5696454ce7dd79e4de554f3da84f8f9d2aa0 Miraielf geofenced mirai ua-wget USA
http://94.154.35.154/mipsel.urbotnetisass9b01970e468137eceb8f401e6f20a643826cb19b724a73de07c5d4abee718237 Miraielf geofenced mirai ua-wget USA
http://94.154.35.154/arm.urbotnetisassa28ba2c86793fdc59244babe507f419e4cfa658bd61a5dd178ae090a5e795984 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm5.urbotnetisass98b0356eb57747abf0f7aa3aac9c5ebee23164227fcbdf7a6e2984647b207334 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm6.urbotnetisass4080cdfcf00475b9709de913f4fadccb5e43164702fa9c8247cc4927982eb9b0 Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/arm7.urbotnetisass483994d47c07d3cc14da050b1c6db9167bb9eef388a33aad5b3910ece49a830c Miraiarm elf geofenced mirai ua-wget USA
http://94.154.35.154/sparc.urbotnetisassn/an/aelf ua-wget
http://94.154.35.154/m68k.urbotnetisassf4946b27267c603871ff2a00cfce51e49993eb1528240d4d028030f119bab328 Miraielf geofenced mirai ua-wget USA
http://94.154.35.154/sh4.urbotnetisass89936f49e50a14f7c17b9ed52f01677b1cba93ff5d631fff8675a5eb68c7ceb2 Miraielf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-27T01:46:00Z UTC
Last seen:
2025-09-27T01:46:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=809ee625-1600-0000-5c83-7396ba0b0000 pid=3002 /usr/bin/sudo guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011 /tmp/sample.bin guuid=809ee625-1600-0000-5c83-7396ba0b0000 pid=3002->guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011 execve guuid=dc7cbb28-1600-0000-5c83-7396c60b0000 pid=3014 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=dc7cbb28-1600-0000-5c83-7396c60b0000 pid=3014 execve guuid=4f56a757-1600-0000-5c83-73962e0c0000 pid=3118 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=4f56a757-1600-0000-5c83-73962e0c0000 pid=3118 execve guuid=546c0175-1600-0000-5c83-73965d0c0000 pid=3165 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=546c0175-1600-0000-5c83-73965d0c0000 pid=3165 execve guuid=3221c075-1600-0000-5c83-73965e0c0000 pid=3166 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=3221c075-1600-0000-5c83-73965e0c0000 pid=3166 clone guuid=f4ac4377-1600-0000-5c83-7396600c0000 pid=3168 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f4ac4377-1600-0000-5c83-7396600c0000 pid=3168 execve guuid=3c38dc77-1600-0000-5c83-7396610c0000 pid=3169 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=3c38dc77-1600-0000-5c83-7396610c0000 pid=3169 execve guuid=e70a7c93-1600-0000-5c83-7396750c0000 pid=3189 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=e70a7c93-1600-0000-5c83-7396750c0000 pid=3189 execve guuid=7781a9b1-1600-0000-5c83-7396870c0000 pid=3207 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=7781a9b1-1600-0000-5c83-7396870c0000 pid=3207 execve guuid=74861ab2-1600-0000-5c83-7396880c0000 pid=3208 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=74861ab2-1600-0000-5c83-7396880c0000 pid=3208 clone guuid=40e3edb2-1600-0000-5c83-73968a0c0000 pid=3210 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=40e3edb2-1600-0000-5c83-73968a0c0000 pid=3210 execve guuid=836f68b3-1600-0000-5c83-73968b0c0000 pid=3211 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=836f68b3-1600-0000-5c83-73968b0c0000 pid=3211 execve guuid=ca0745ce-1600-0000-5c83-7396aa0c0000 pid=3242 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=ca0745ce-1600-0000-5c83-7396aa0c0000 pid=3242 execve guuid=ecfefae9-1600-0000-5c83-7396d90c0000 pid=3289 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=ecfefae9-1600-0000-5c83-7396d90c0000 pid=3289 execve guuid=20556aea-1600-0000-5c83-7396da0c0000 pid=3290 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=20556aea-1600-0000-5c83-7396da0c0000 pid=3290 clone guuid=a1db1aeb-1600-0000-5c83-7396de0c0000 pid=3294 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=a1db1aeb-1600-0000-5c83-7396de0c0000 pid=3294 execve guuid=bbc968eb-1600-0000-5c83-7396e10c0000 pid=3297 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=bbc968eb-1600-0000-5c83-7396e10c0000 pid=3297 execve guuid=923b8005-1700-0000-5c83-7396030d0000 pid=3331 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=923b8005-1700-0000-5c83-7396030d0000 pid=3331 execve guuid=772e0d21-1700-0000-5c83-73963d0d0000 pid=3389 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=772e0d21-1700-0000-5c83-73963d0d0000 pid=3389 execve guuid=353c6e21-1700-0000-5c83-73963f0d0000 pid=3391 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=353c6e21-1700-0000-5c83-73963f0d0000 pid=3391 clone guuid=be732022-1700-0000-5c83-7396430d0000 pid=3395 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=be732022-1700-0000-5c83-7396430d0000 pid=3395 execve guuid=9cdc7f22-1700-0000-5c83-7396450d0000 pid=3397 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=9cdc7f22-1700-0000-5c83-7396450d0000 pid=3397 execve guuid=0482063c-1700-0000-5c83-7396840d0000 pid=3460 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=0482063c-1700-0000-5c83-7396840d0000 pid=3460 execve guuid=31376056-1700-0000-5c83-7396b30d0000 pid=3507 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=31376056-1700-0000-5c83-7396b30d0000 pid=3507 execve guuid=8dd3ca56-1700-0000-5c83-7396b50d0000 pid=3509 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=8dd3ca56-1700-0000-5c83-7396b50d0000 pid=3509 clone guuid=30dda457-1700-0000-5c83-7396b90d0000 pid=3513 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=30dda457-1700-0000-5c83-7396b90d0000 pid=3513 execve guuid=f23e0858-1700-0000-5c83-7396bb0d0000 pid=3515 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f23e0858-1700-0000-5c83-7396bb0d0000 pid=3515 execve guuid=4b29e171-1700-0000-5c83-7396e50d0000 pid=3557 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=4b29e171-1700-0000-5c83-7396e50d0000 pid=3557 execve guuid=4f61a58c-1700-0000-5c83-73961b0e0000 pid=3611 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=4f61a58c-1700-0000-5c83-73961b0e0000 pid=3611 execve guuid=d95e018d-1700-0000-5c83-73961c0e0000 pid=3612 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=d95e018d-1700-0000-5c83-73961c0e0000 pid=3612 clone guuid=afe4128e-1700-0000-5c83-73961e0e0000 pid=3614 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=afe4128e-1700-0000-5c83-73961e0e0000 pid=3614 execve guuid=f9c22c90-1700-0000-5c83-73961f0e0000 pid=3615 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f9c22c90-1700-0000-5c83-73961f0e0000 pid=3615 execve guuid=e6eafaa9-1700-0000-5c83-7396550e0000 pid=3669 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=e6eafaa9-1700-0000-5c83-7396550e0000 pid=3669 execve guuid=cfa722ce-1700-0000-5c83-7396b70e0000 pid=3767 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=cfa722ce-1700-0000-5c83-7396b70e0000 pid=3767 execve guuid=5d83a3ce-1700-0000-5c83-7396b90e0000 pid=3769 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=5d83a3ce-1700-0000-5c83-7396b90e0000 pid=3769 clone guuid=e4e5c7cf-1700-0000-5c83-7396bd0e0000 pid=3773 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=e4e5c7cf-1700-0000-5c83-7396bd0e0000 pid=3773 execve guuid=584850d0-1700-0000-5c83-7396bf0e0000 pid=3775 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=584850d0-1700-0000-5c83-7396bf0e0000 pid=3775 execve guuid=f124e2e5-1700-0000-5c83-7396f50e0000 pid=3829 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f124e2e5-1700-0000-5c83-7396f50e0000 pid=3829 execve guuid=2a7f06f5-1700-0000-5c83-73961e0f0000 pid=3870 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=2a7f06f5-1700-0000-5c83-73961e0f0000 pid=3870 execve guuid=815685f5-1700-0000-5c83-7396200f0000 pid=3872 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=815685f5-1700-0000-5c83-7396200f0000 pid=3872 clone guuid=f85aeff5-1700-0000-5c83-7396220f0000 pid=3874 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f85aeff5-1700-0000-5c83-7396220f0000 pid=3874 execve guuid=1b296ff6-1700-0000-5c83-7396250f0000 pid=3877 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=1b296ff6-1700-0000-5c83-7396250f0000 pid=3877 execve guuid=f9389310-1800-0000-5c83-73965f0f0000 pid=3935 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f9389310-1800-0000-5c83-73965f0f0000 pid=3935 execve guuid=2f28c92b-1800-0000-5c83-7396a30f0000 pid=4003 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=2f28c92b-1800-0000-5c83-7396a30f0000 pid=4003 execve guuid=f006552c-1800-0000-5c83-7396a40f0000 pid=4004 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=f006552c-1800-0000-5c83-7396a40f0000 pid=4004 clone guuid=1c88502d-1800-0000-5c83-7396a90f0000 pid=4009 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=1c88502d-1800-0000-5c83-7396a90f0000 pid=4009 execve guuid=b350df2d-1800-0000-5c83-7396ad0f0000 pid=4013 /usr/bin/wget net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=b350df2d-1800-0000-5c83-7396ad0f0000 pid=4013 execve guuid=dd6a0848-1800-0000-5c83-7396ec0f0000 pid=4076 /usr/bin/curl net send-data write-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=dd6a0848-1800-0000-5c83-7396ec0f0000 pid=4076 execve guuid=03665963-1800-0000-5c83-73962d100000 pid=4141 /usr/bin/chmod guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=03665963-1800-0000-5c83-73962d100000 pid=4141 execve guuid=e932c963-1800-0000-5c83-73962f100000 pid=4143 /usr/bin/bash guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=e932c963-1800-0000-5c83-73962f100000 pid=4143 clone guuid=825dae66-1800-0000-5c83-739635100000 pid=4149 /usr/bin/rm delete-file guuid=4ed60a28-1600-0000-5c83-7396c30b0000 pid=3011->guuid=825dae66-1800-0000-5c83-739635100000 pid=4149 execve 64a07662-ebdf-52ea-9140-fd99af91f8af 94.154.35.154:80 guuid=dc7cbb28-1600-0000-5c83-7396c60b0000 pid=3014->64a07662-ebdf-52ea-9140-fd99af91f8af send: 149B guuid=4f56a757-1600-0000-5c83-73962e0c0000 pid=3118->64a07662-ebdf-52ea-9140-fd99af91f8af send: 98B guuid=3c38dc77-1600-0000-5c83-7396610c0000 pid=3169->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=e70a7c93-1600-0000-5c83-7396750c0000 pid=3189->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=836f68b3-1600-0000-5c83-73968b0c0000 pid=3211->64a07662-ebdf-52ea-9140-fd99af91f8af send: 148B guuid=ca0745ce-1600-0000-5c83-7396aa0c0000 pid=3242->64a07662-ebdf-52ea-9140-fd99af91f8af send: 97B guuid=bbc968eb-1600-0000-5c83-7396e10c0000 pid=3297->64a07662-ebdf-52ea-9140-fd99af91f8af send: 145B guuid=923b8005-1700-0000-5c83-7396030d0000 pid=3331->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B guuid=9cdc7f22-1700-0000-5c83-7396450d0000 pid=3397->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=0482063c-1700-0000-5c83-7396840d0000 pid=3460->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=f23e0858-1700-0000-5c83-7396bb0d0000 pid=3515->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=4b29e171-1700-0000-5c83-7396e50d0000 pid=3557->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=f9c22c90-1700-0000-5c83-73961f0e0000 pid=3615->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=e6eafaa9-1700-0000-5c83-7396550e0000 pid=3669->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=584850d0-1700-0000-5c83-7396bf0e0000 pid=3775->64a07662-ebdf-52ea-9140-fd99af91f8af send: 282B guuid=f124e2e5-1700-0000-5c83-7396f50e0000 pid=3829->64a07662-ebdf-52ea-9140-fd99af91f8af send: 96B guuid=b734abf5-1700-0000-5c83-7396210f0000 pid=3873 /usr/bin/bash guuid=815685f5-1700-0000-5c83-7396200f0000 pid=3872->guuid=b734abf5-1700-0000-5c83-7396210f0000 pid=3873 clone guuid=1b296ff6-1700-0000-5c83-7396250f0000 pid=3877->64a07662-ebdf-52ea-9140-fd99af91f8af send: 146B guuid=f9389310-1800-0000-5c83-73965f0f0000 pid=3935->64a07662-ebdf-52ea-9140-fd99af91f8af send: 95B guuid=b350df2d-1800-0000-5c83-7396ad0f0000 pid=4013->64a07662-ebdf-52ea-9140-fd99af91f8af send: 145B guuid=dd6a0848-1800-0000-5c83-7396ec0f0000 pid=4076->64a07662-ebdf-52ea-9140-fd99af91f8af send: 94B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-27 04:38:35 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c86247a6f0565194bcb0f2864ead389d543b10e23eaf2a59d8f652bb84414219

(this sample)

  
Delivery method
Distributed via web download

Comments