MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c95f9ef95bd0fabf48e025b98c9ce7a79e1c61aeb96b433e30d21d52082d5da7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: c95f9ef95bd0fabf48e025b98c9ce7a79e1c61aeb96b433e30d21d52082d5da7
SHA3-384 hash: b693cd1cd90edbf267e3ded50640b33b5eef0876429f30e115c7087ba28dad36d7c917a8a884901a3e69d563833da43f
SHA1 hash: d097c8c37fea792faef88f7accc46ac017809b36
MD5 hash: 8b98ff30b1b88b1b48b2bdea4f2f8590
humanhash: enemy-indigo-twelve-king
File name:yarn
Download: download sample
Signature Mirai
File size:2'745 bytes
First seen:2025-12-23 21:14:23 UTC
Last seen:2025-12-24 01:35:39 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vby7wIb0d0QwSHbDGwbbPqwLbF+twGbgWYw6bpkw9bKjwAbbuwjbvXvCwVJb4RwL:v6bYyQNHOIuC8DQzOQkNuK7fCsJUPOr
TLSH T1F4517A9D671300B6B8DEEA67BDA90804F54C94B25D8CDD90F5FE28FD368CE0864A174E
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.255.103.171/bins/sdxkzX_UXA229x.x869b2a851f233972d421481a79d7be7ac7ee45288b0599ecdb62a6a6f203f44d84 Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.spc67bcae85e624585fa0b682425eaeb84323b1a3222c27aa1fdb46b69e09bbcc3b Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.sh47501f714f4c5c7ec1efc47ba26305c02859416ad276d01090665117a2183065b Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.mipse530b4adb8b1ffa561ed18c4ad5886a1daf860aec402ecf679fb8559fa2b4cdc Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.mpsl96c43a2bbdd790cc4c8b2721b8364757c774c5c3b7d8617dca11eda425839089 Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.arm4n/an/aelf ua-wget
http://5.255.103.171/bins/sdxkzX_UXA229x.arm55879891986f59c8b383eceefa97ae332fb55c1ff1a7313f1f3b9d080a094c616 Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.arm65e1843ee80b0a0f47fe7c102882aecaf626b2c2c671f80f217b8fb5558cf4456 Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.arm74b00c9ff1eb55bd1ab7e067a274dc00a16fd07870f915cbc871e887f16d0277d Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.ppc1b1df35f15ce9734c51a5ee94460400efafd1523b4b3baea89ddb0cf86c970dc Miraimirai opendir
http://5.255.103.171/bins/sdxkzX_UXA229x.m68k2b84ee15e57c62eb1290ce93a70baa65f7bc397a5688db0eab69b93967c6de71 Miraimirai opendir

Intelligence


File Origin
# of uploads :
2
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-23T18:28:00Z UTC
Last seen:
2025-12-24T12:48:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=ca190d87-1800-0000-b808-ae2a51090000 pid=2385 /usr/bin/sudo guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389 /tmp/sample.bin guuid=ca190d87-1800-0000-b808-ae2a51090000 pid=2385->guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389 execve guuid=0b3f338a-1800-0000-b808-ae2a57090000 pid=2391 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=0b3f338a-1800-0000-b808-ae2a57090000 pid=2391 execve guuid=cfa8b192-1800-0000-b808-ae2a5f090000 pid=2399 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=cfa8b192-1800-0000-b808-ae2a5f090000 pid=2399 execve guuid=7dc72fa2-1800-0000-b808-ae2a74090000 pid=2420 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=7dc72fa2-1800-0000-b808-ae2a74090000 pid=2420 execve guuid=6527d1a2-1800-0000-b808-ae2a75090000 pid=2421 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=6527d1a2-1800-0000-b808-ae2a75090000 pid=2421 execve guuid=bd2940a3-1800-0000-b808-ae2a76090000 pid=2422 /tmp/femboyowo delete-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=bd2940a3-1800-0000-b808-ae2a76090000 pid=2422 execve guuid=000097a3-1800-0000-b808-ae2a7a090000 pid=2426 /usr/bin/wget net send-data guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=000097a3-1800-0000-b808-ae2a7a090000 pid=2426 execve guuid=2c54d4a6-1800-0000-b808-ae2a82090000 pid=2434 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=2c54d4a6-1800-0000-b808-ae2a82090000 pid=2434 execve guuid=2c5475b0-1800-0000-b808-ae2a96090000 pid=2454 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=2c5475b0-1800-0000-b808-ae2a96090000 pid=2454 execve guuid=0cddd4b0-1800-0000-b808-ae2a98090000 pid=2456 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=0cddd4b0-1800-0000-b808-ae2a98090000 pid=2456 execve guuid=d2f514b1-1800-0000-b808-ae2a99090000 pid=2457 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=d2f514b1-1800-0000-b808-ae2a99090000 pid=2457 clone guuid=ecaeecb2-1800-0000-b808-ae2a9b090000 pid=2459 /usr/bin/wget net send-data guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=ecaeecb2-1800-0000-b808-ae2a9b090000 pid=2459 execve guuid=5bba4eb5-1800-0000-b808-ae2aa2090000 pid=2466 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=5bba4eb5-1800-0000-b808-ae2aa2090000 pid=2466 execve guuid=62c521be-1800-0000-b808-ae2ab3090000 pid=2483 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=62c521be-1800-0000-b808-ae2ab3090000 pid=2483 execve guuid=bed3b2be-1800-0000-b808-ae2ab5090000 pid=2485 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=bed3b2be-1800-0000-b808-ae2ab5090000 pid=2485 execve guuid=0cba25bf-1800-0000-b808-ae2ab7090000 pid=2487 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=0cba25bf-1800-0000-b808-ae2ab7090000 pid=2487 clone guuid=0f0424c0-1800-0000-b808-ae2abd090000 pid=2493 /usr/bin/wget net send-data guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=0f0424c0-1800-0000-b808-ae2abd090000 pid=2493 execve guuid=47cf4cc3-1800-0000-b808-ae2ac3090000 pid=2499 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=47cf4cc3-1800-0000-b808-ae2ac3090000 pid=2499 execve guuid=e6d631c9-1800-0000-b808-ae2acd090000 pid=2509 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=e6d631c9-1800-0000-b808-ae2acd090000 pid=2509 execve guuid=e2afbdc9-1800-0000-b808-ae2acf090000 pid=2511 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=e2afbdc9-1800-0000-b808-ae2acf090000 pid=2511 execve guuid=820346ca-1800-0000-b808-ae2ad2090000 pid=2514 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=820346ca-1800-0000-b808-ae2ad2090000 pid=2514 clone guuid=750d40cb-1800-0000-b808-ae2ad5090000 pid=2517 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=750d40cb-1800-0000-b808-ae2ad5090000 pid=2517 execve guuid=a6d832d0-1800-0000-b808-ae2ade090000 pid=2526 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=a6d832d0-1800-0000-b808-ae2ade090000 pid=2526 execve guuid=58236cd6-1800-0000-b808-ae2aed090000 pid=2541 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=58236cd6-1800-0000-b808-ae2aed090000 pid=2541 execve guuid=5e9dd8d6-1800-0000-b808-ae2aef090000 pid=2543 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=5e9dd8d6-1800-0000-b808-ae2aef090000 pid=2543 execve guuid=cf89c4d7-1800-0000-b808-ae2af0090000 pid=2544 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=cf89c4d7-1800-0000-b808-ae2af0090000 pid=2544 clone guuid=8956dad8-1800-0000-b808-ae2af5090000 pid=2549 /usr/bin/wget net send-data guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=8956dad8-1800-0000-b808-ae2af5090000 pid=2549 execve guuid=d0e788db-1800-0000-b808-ae2afa090000 pid=2554 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=d0e788db-1800-0000-b808-ae2afa090000 pid=2554 execve guuid=eac77ce2-1800-0000-b808-ae2a0a0a0000 pid=2570 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=eac77ce2-1800-0000-b808-ae2a0a0a0000 pid=2570 execve guuid=237703e3-1800-0000-b808-ae2a0b0a0000 pid=2571 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=237703e3-1800-0000-b808-ae2a0b0a0000 pid=2571 execve guuid=22796ae3-1800-0000-b808-ae2a0c0a0000 pid=2572 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=22796ae3-1800-0000-b808-ae2a0c0a0000 pid=2572 clone guuid=9f1cabe3-1800-0000-b808-ae2a0d0a0000 pid=2573 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=9f1cabe3-1800-0000-b808-ae2a0d0a0000 pid=2573 execve guuid=5df02de7-1800-0000-b808-ae2a160a0000 pid=2582 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=5df02de7-1800-0000-b808-ae2a160a0000 pid=2582 execve guuid=5f04a5ed-1800-0000-b808-ae2a230a0000 pid=2595 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=5f04a5ed-1800-0000-b808-ae2a230a0000 pid=2595 execve guuid=151b09ee-1800-0000-b808-ae2a250a0000 pid=2597 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=151b09ee-1800-0000-b808-ae2a250a0000 pid=2597 execve guuid=c22775ee-1800-0000-b808-ae2a270a0000 pid=2599 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=c22775ee-1800-0000-b808-ae2a270a0000 pid=2599 clone guuid=201a56ef-1800-0000-b808-ae2a2b0a0000 pid=2603 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=201a56ef-1800-0000-b808-ae2a2b0a0000 pid=2603 execve guuid=f65d12f4-1800-0000-b808-ae2a390a0000 pid=2617 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=f65d12f4-1800-0000-b808-ae2a390a0000 pid=2617 execve guuid=e2c264f9-1800-0000-b808-ae2a490a0000 pid=2633 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=e2c264f9-1800-0000-b808-ae2a490a0000 pid=2633 execve guuid=111eb7f9-1800-0000-b808-ae2a4b0a0000 pid=2635 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=111eb7f9-1800-0000-b808-ae2a4b0a0000 pid=2635 execve guuid=530af7f9-1800-0000-b808-ae2a4c0a0000 pid=2636 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=530af7f9-1800-0000-b808-ae2a4c0a0000 pid=2636 clone guuid=ed7882fa-1800-0000-b808-ae2a4f0a0000 pid=2639 /usr/bin/wget net guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=ed7882fa-1800-0000-b808-ae2a4f0a0000 pid=2639 execve guuid=0b220afc-1800-0000-b808-ae2a540a0000 pid=2644 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=0b220afc-1800-0000-b808-ae2a540a0000 pid=2644 execve guuid=15dcfc03-1900-0000-b808-ae2a6b0a0000 pid=2667 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=15dcfc03-1900-0000-b808-ae2a6b0a0000 pid=2667 execve guuid=ec4a7f04-1900-0000-b808-ae2a6d0a0000 pid=2669 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=ec4a7f04-1900-0000-b808-ae2a6d0a0000 pid=2669 execve guuid=1b32d004-1900-0000-b808-ae2a6f0a0000 pid=2671 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=1b32d004-1900-0000-b808-ae2a6f0a0000 pid=2671 clone guuid=58fc8405-1900-0000-b808-ae2a730a0000 pid=2675 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=58fc8405-1900-0000-b808-ae2a730a0000 pid=2675 execve guuid=09722e0a-1900-0000-b808-ae2a810a0000 pid=2689 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=09722e0a-1900-0000-b808-ae2a810a0000 pid=2689 execve guuid=7181de11-1900-0000-b808-ae2a980a0000 pid=2712 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=7181de11-1900-0000-b808-ae2a980a0000 pid=2712 execve guuid=4e7d5512-1900-0000-b808-ae2a9b0a0000 pid=2715 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=4e7d5512-1900-0000-b808-ae2a9b0a0000 pid=2715 execve guuid=8e52b112-1900-0000-b808-ae2a9d0a0000 pid=2717 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=8e52b112-1900-0000-b808-ae2a9d0a0000 pid=2717 clone guuid=20cd5413-1900-0000-b808-ae2aa10a0000 pid=2721 /usr/bin/wget net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=20cd5413-1900-0000-b808-ae2aa10a0000 pid=2721 execve guuid=a68aff17-1900-0000-b808-ae2aaf0a0000 pid=2735 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=a68aff17-1900-0000-b808-ae2aaf0a0000 pid=2735 execve guuid=ab9abf20-1900-0000-b808-ae2ac90a0000 pid=2761 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=ab9abf20-1900-0000-b808-ae2ac90a0000 pid=2761 execve guuid=7d521121-1900-0000-b808-ae2acb0a0000 pid=2763 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=7d521121-1900-0000-b808-ae2acb0a0000 pid=2763 execve guuid=64fc5c21-1900-0000-b808-ae2acc0a0000 pid=2764 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=64fc5c21-1900-0000-b808-ae2acc0a0000 pid=2764 clone guuid=b8d21922-1900-0000-b808-ae2ad10a0000 pid=2769 /usr/bin/wget net guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=b8d21922-1900-0000-b808-ae2ad10a0000 pid=2769 execve guuid=72e01725-1900-0000-b808-ae2adb0a0000 pid=2779 /usr/bin/curl net send-data write-file guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=72e01725-1900-0000-b808-ae2adb0a0000 pid=2779 execve guuid=f825de2c-1900-0000-b808-ae2af30a0000 pid=2803 /usr/bin/cat guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=f825de2c-1900-0000-b808-ae2af30a0000 pid=2803 execve guuid=f69e622d-1900-0000-b808-ae2af50a0000 pid=2805 /usr/bin/chmod guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=f69e622d-1900-0000-b808-ae2af50a0000 pid=2805 execve guuid=541ec82d-1900-0000-b808-ae2af60a0000 pid=2806 /usr/bin/bash guuid=ea70d389-1800-0000-b808-ae2a55090000 pid=2389->guuid=541ec82d-1900-0000-b808-ae2af60a0000 pid=2806 clone 499968a9-0fa4-5adb-abbe-22bd4b86dc4d 5.255.103.171:80 guuid=0b3f338a-1800-0000-b808-ae2a57090000 pid=2391->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 151B guuid=cfa8b192-1800-0000-b808-ae2a5f090000 pid=2399->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 100B guuid=6de473a3-1800-0000-b808-ae2a77090000 pid=2423 /tmp/femboyowo net send-data zombie guuid=bd2940a3-1800-0000-b808-ae2a76090000 pid=2422->guuid=6de473a3-1800-0000-b808-ae2a77090000 pid=2423 clone 0c565469-e118-5e64-b250-02bc365c63ad 146.103.41.220:6669 guuid=6de473a3-1800-0000-b808-ae2a77090000 pid=2423->0c565469-e118-5e64-b250-02bc365c63ad send: 14B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6de473a3-1800-0000-b808-ae2a77090000 pid=2423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=52da81a3-1800-0000-b808-ae2a78090000 pid=2424 /tmp/femboyowo guuid=6de473a3-1800-0000-b808-ae2a77090000 pid=2423->guuid=52da81a3-1800-0000-b808-ae2a78090000 pid=2424 clone guuid=000097a3-1800-0000-b808-ae2a7a090000 pid=2426->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 151B guuid=2c54d4a6-1800-0000-b808-ae2a82090000 pid=2434->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 100B guuid=ecaeecb2-1800-0000-b808-ae2a9b090000 pid=2459->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 151B guuid=5bba4eb5-1800-0000-b808-ae2aa2090000 pid=2466->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 100B guuid=0f0424c0-1800-0000-b808-ae2abd090000 pid=2493->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=47cf4cc3-1800-0000-b808-ae2ac3090000 pid=2499->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=750d40cb-1800-0000-b808-ae2ad5090000 pid=2517->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=a6d832d0-1800-0000-b808-ae2ade090000 pid=2526->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=8956dad8-1800-0000-b808-ae2af5090000 pid=2549->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=d0e788db-1800-0000-b808-ae2afa090000 pid=2554->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=9f1cabe3-1800-0000-b808-ae2a0d0a0000 pid=2573->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=5df02de7-1800-0000-b808-ae2a160a0000 pid=2582->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=201a56ef-1800-0000-b808-ae2a2b0a0000 pid=2603->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=f65d12f4-1800-0000-b808-ae2a390a0000 pid=2617->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=ed7882fa-1800-0000-b808-ae2a4f0a0000 pid=2639->499968a9-0fa4-5adb-abbe-22bd4b86dc4d con guuid=0b220afc-1800-0000-b808-ae2a540a0000 pid=2644->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=58fc8405-1900-0000-b808-ae2a730a0000 pid=2675->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 151B guuid=09722e0a-1900-0000-b808-ae2a810a0000 pid=2689->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 100B guuid=20cd5413-1900-0000-b808-ae2aa10a0000 pid=2721->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 152B guuid=a68aff17-1900-0000-b808-ae2aaf0a0000 pid=2735->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 101B guuid=b8d21922-1900-0000-b808-ae2ad10a0000 pid=2769->499968a9-0fa4-5adb-abbe-22bd4b86dc4d con guuid=72e01725-1900-0000-b808-ae2adb0a0000 pid=2779->499968a9-0fa4-5adb-abbe-22bd4b86dc4d send: 100B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-23 21:15:22 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c95f9ef95bd0fabf48e025b98c9ce7a79e1c61aeb96b433e30d21d52082d5da7

(this sample)

Comments