MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cece11963249ce094941b57bff342db7a322bea4e74250c10503abdac6b82aef. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: cece11963249ce094941b57bff342db7a322bea4e74250c10503abdac6b82aef
SHA3-384 hash: e1c7f1c13337dad14da8b3781415a5a86790a980fe8eb9313d38684a159b0fc6c025b6bf52453687af9350c94e45c9a0
SHA1 hash: b58c47b75e4ef6eca63ad72a31b984b192fec56d
MD5 hash: 1bcfde7d0142459d9fdb1d71e3840db2
humanhash: eight-nebraska-pip-social
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'784 bytes
First seen:2025-10-18 15:58:37 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:iL393Mx3O3E3gB3EE313O3T3U3Y3w3Z3kwz:Ytcxe0wBtl+DEogJ0W
TLSH T1BE718495D80250B41D5E6772A9FB22AAF191B3C238E77E0F7A8C68F4618CF4154C9DE1
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.arc9bbbc7e6130003b0f5eec08a6ecec6d8930851b060df3b1c5f94c2f2f909df0d Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.x86a7d3ea598f8397518cf54946c3c3a287c9d2ab8cae8d8dcddeeb2e1ffe6707ce Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.x86_64e133b2bdca392330464db0c7bca9ef03128c68c7d474edd3d24680fda250f486 Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.i686ec942d84ec57cc59f0ec4eda261ba088df6db6594620d4670d46bb4ccf7f824d Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.mipsad9148150a90ec5114cc3f8cf5fc3414b16bbb4ba6f1091c250ccb4a7b0716fa Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips64n/an/aelf ua-wget
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.mpsl9be8ec509eccd01d5c7698e6a67b5d001f1c77bceb9cdcdf4b2cac43b1bc32cc Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.arma5bbbc56e90ad697bd49cc950f982ad90da48c56838b1ba30a9a5e930677fe76 Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm5f2feb0015b5cce34b0b77b38130b8847288a209a0b3c8d1345ba2be630f22faa Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm657a870191cfacd9e04d206e9a33c1f01262374532525f558add1cc4e4d73cee1 Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm7b45bdef80933435e9840ed965fe778113490cb1f9afc0baee06301c1ad06836e Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.ppcfc09d9d48b1fa771b39aa50bb1fe77e3dfb8213283e0a6a693946dad33edd393 Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.sparcn/an/aelf ua-wget
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.m68k871f02bcc6c869814b7ae9f7f708e5972d47609e72524854f79ebab573a43aaf Miraimirai opendir
http://160.238.13.201/HideChaotic/ub8ehJSePAfc9FYqZIT6.sh49a9a4946241391b309c797a9633041f4b75c7e7fa621fc4a7dd775ba80e39e06 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-18T13:15:00Z UTC
Last seen:
2025-10-19T10:15:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=51ac13d2-1d00-0000-6b3e-7edff20c0000 pid=3314 /usr/bin/sudo guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321 /tmp/sample.bin guuid=51ac13d2-1d00-0000-6b3e-7edff20c0000 pid=3314->guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321 execve guuid=a7118ad4-1d00-0000-6b3e-7edffa0c0000 pid=3322 /usr/bin/cp guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=a7118ad4-1d00-0000-6b3e-7edffa0c0000 pid=3322 execve guuid=74ea0fdc-1d00-0000-6b3e-7edffb0c0000 pid=3323 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=74ea0fdc-1d00-0000-6b3e-7edffb0c0000 pid=3323 execve guuid=ac95111a-1e00-0000-6b3e-7edf870d0000 pid=3463 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=ac95111a-1e00-0000-6b3e-7edf870d0000 pid=3463 execve guuid=43e8265c-1e00-0000-6b3e-7edf080e0000 pid=3592 /usr/bin/cat guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=43e8265c-1e00-0000-6b3e-7edf080e0000 pid=3592 execve guuid=48c8b35c-1e00-0000-6b3e-7edf090e0000 pid=3593 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=48c8b35c-1e00-0000-6b3e-7edf090e0000 pid=3593 execve guuid=27070d5d-1e00-0000-6b3e-7edf0b0e0000 pid=3595 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=27070d5d-1e00-0000-6b3e-7edf0b0e0000 pid=3595 clone guuid=0875ee5d-1e00-0000-6b3e-7edf0f0e0000 pid=3599 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=0875ee5d-1e00-0000-6b3e-7edf0f0e0000 pid=3599 execve guuid=6f7e8980-1e00-0000-6b3e-7edf4f0e0000 pid=3663 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=6f7e8980-1e00-0000-6b3e-7edf4f0e0000 pid=3663 execve guuid=d93ba4be-1e00-0000-6b3e-7edfc30e0000 pid=3779 /usr/bin/cat guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=d93ba4be-1e00-0000-6b3e-7edfc30e0000 pid=3779 execve guuid=978590c5-1e00-0000-6b3e-7edfc80e0000 pid=3784 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=978590c5-1e00-0000-6b3e-7edfc80e0000 pid=3784 execve guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787 execve guuid=f8f584f2-1f00-0000-6b3e-7edfd8120000 pid=4824 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=f8f584f2-1f00-0000-6b3e-7edfd8120000 pid=4824 execve guuid=8302f917-2000-0000-6b3e-7edf4b130000 pid=4939 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=8302f917-2000-0000-6b3e-7edf4b130000 pid=4939 execve guuid=c7321940-2000-0000-6b3e-7edfcc130000 pid=5068 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=c7321940-2000-0000-6b3e-7edfcc130000 pid=5068 clone guuid=5dde3940-2000-0000-6b3e-7edfcd130000 pid=5069 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=5dde3940-2000-0000-6b3e-7edfcd130000 pid=5069 execve guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071 execve guuid=f0aa356e-2100-0000-6b3e-7edf80140000 pid=5248 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=f0aa356e-2100-0000-6b3e-7edf80140000 pid=5248 execve guuid=1fd8f192-2100-0000-6b3e-7edf88140000 pid=5256 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=1fd8f192-2100-0000-6b3e-7edf88140000 pid=5256 execve guuid=b0230dba-2100-0000-6b3e-7edf89140000 pid=5257 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=b0230dba-2100-0000-6b3e-7edf89140000 pid=5257 clone guuid=29c9d8ba-2100-0000-6b3e-7edf8a140000 pid=5258 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=29c9d8ba-2100-0000-6b3e-7edf8a140000 pid=5258 execve guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259 execve guuid=06f4e1e8-2200-0000-6b3e-7edfa0140000 pid=5280 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=06f4e1e8-2200-0000-6b3e-7edfa0140000 pid=5280 execve guuid=3d012b16-2300-0000-6b3e-7edfb2140000 pid=5298 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=3d012b16-2300-0000-6b3e-7edfb2140000 pid=5298 execve guuid=bb18a03a-2300-0000-6b3e-7edfb3140000 pid=5299 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=bb18a03a-2300-0000-6b3e-7edfb3140000 pid=5299 clone guuid=8f8cc13a-2300-0000-6b3e-7edfb4140000 pid=5300 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=8f8cc13a-2300-0000-6b3e-7edfb4140000 pid=5300 execve guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301 execve guuid=bbe34567-2400-0000-6b3e-7edfbb140000 pid=5307 /usr/bin/wget net send-data guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=bbe34567-2400-0000-6b3e-7edfbb140000 pid=5307 execve guuid=dc748f80-2400-0000-6b3e-7edfbc140000 pid=5308 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=dc748f80-2400-0000-6b3e-7edfbc140000 pid=5308 execve guuid=fa8f5e9a-2400-0000-6b3e-7edfbd140000 pid=5309 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=fa8f5e9a-2400-0000-6b3e-7edfbd140000 pid=5309 clone guuid=60f49c9a-2400-0000-6b3e-7edfbe140000 pid=5310 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=60f49c9a-2400-0000-6b3e-7edfbe140000 pid=5310 execve guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311 execve guuid=a84034ca-2500-0000-6b3e-7edfc5140000 pid=5317 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=a84034ca-2500-0000-6b3e-7edfc5140000 pid=5317 execve guuid=4a7dd3f8-2500-0000-6b3e-7edfc6140000 pid=5318 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=4a7dd3f8-2500-0000-6b3e-7edfc6140000 pid=5318 execve guuid=af9c2e2a-2600-0000-6b3e-7edfc7140000 pid=5319 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=af9c2e2a-2600-0000-6b3e-7edfc7140000 pid=5319 clone guuid=ba80732a-2600-0000-6b3e-7edfc8140000 pid=5320 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=ba80732a-2600-0000-6b3e-7edfc8140000 pid=5320 execve guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321 execve guuid=682f4d59-2700-0000-6b3e-7edfcf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=682f4d59-2700-0000-6b3e-7edfcf140000 pid=5327 execve guuid=c694857c-2700-0000-6b3e-7edfd0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=c694857c-2700-0000-6b3e-7edfd0140000 pid=5328 execve guuid=2190aea2-2700-0000-6b3e-7edfd1140000 pid=5329 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=2190aea2-2700-0000-6b3e-7edfd1140000 pid=5329 clone guuid=d259e4a2-2700-0000-6b3e-7edfd2140000 pid=5330 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=d259e4a2-2700-0000-6b3e-7edfd2140000 pid=5330 execve guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331 execve guuid=1ab9bdd1-2800-0000-6b3e-7edfd9140000 pid=5337 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=1ab9bdd1-2800-0000-6b3e-7edfd9140000 pid=5337 execve guuid=f7000ef7-2800-0000-6b3e-7edfda140000 pid=5338 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=f7000ef7-2800-0000-6b3e-7edfda140000 pid=5338 execve guuid=14fab119-2900-0000-6b3e-7edfdb140000 pid=5339 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=14fab119-2900-0000-6b3e-7edfdb140000 pid=5339 clone guuid=2cfcd119-2900-0000-6b3e-7edfdc140000 pid=5340 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=2cfcd119-2900-0000-6b3e-7edfdc140000 pid=5340 execve guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341 execve guuid=5fb57046-2a00-0000-6b3e-7edfe3140000 pid=5347 /usr/bin/wget net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=5fb57046-2a00-0000-6b3e-7edfe3140000 pid=5347 execve guuid=0b10f976-2a00-0000-6b3e-7edfe4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=0b10f976-2a00-0000-6b3e-7edfe4140000 pid=5348 execve guuid=e30f014f-2b00-0000-6b3e-7edfe5140000 pid=5349 /usr/bin/bash guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=e30f014f-2b00-0000-6b3e-7edfe5140000 pid=5349 clone guuid=683a414f-2b00-0000-6b3e-7edfe6140000 pid=5350 /usr/bin/chmod guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=683a414f-2b00-0000-6b3e-7edfe6140000 pid=5350 execve guuid=c939da4f-2b00-0000-6b3e-7edfe7140000 pid=5351 /tmp/Chaotic net guuid=0bc0c0d3-1d00-0000-6b3e-7edff90c0000 pid=3321->guuid=c939da4f-2b00-0000-6b3e-7edfe7140000 pid=5351 execve 7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 160.238.13.201:80 guuid=74ea0fdc-1d00-0000-6b3e-7edffb0c0000 pid=3323->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 165B guuid=ac95111a-1e00-0000-6b3e-7edf870d0000 pid=3463->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 114B guuid=0875ee5d-1e00-0000-6b3e-7edf0f0e0000 pid=3599->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 165B guuid=6f7e8980-1e00-0000-6b3e-7edf4f0e0000 pid=3663->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 114B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aa9e6ec6-1e00-0000-6b3e-7edfcf0e0000 pid=3791 /tmp/Chaotic guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787->guuid=aa9e6ec6-1e00-0000-6b3e-7edfcf0e0000 pid=3791 clone guuid=63e36ff2-1f00-0000-6b3e-7edfd6120000 pid=4822 /tmp/Chaotic guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787->guuid=63e36ff2-1f00-0000-6b3e-7edfd6120000 pid=4822 clone guuid=57d374f2-1f00-0000-6b3e-7edfd7120000 pid=4823 /tmp/Chaotic net send-data zombie guuid=6884e8c5-1e00-0000-6b3e-7edfcb0e0000 pid=3787->guuid=57d374f2-1f00-0000-6b3e-7edfd7120000 pid=4823 clone guuid=0ea473c6-1e00-0000-6b3e-7edfd00e0000 pid=3792 /tmp/Chaotic guuid=aa9e6ec6-1e00-0000-6b3e-7edfcf0e0000 pid=3791->guuid=0ea473c6-1e00-0000-6b3e-7edfd00e0000 pid=3792 clone guuid=84d276c6-1e00-0000-6b3e-7edfd10e0000 pid=3793 /tmp/Chaotic net send-data zombie guuid=aa9e6ec6-1e00-0000-6b3e-7edfcf0e0000 pid=3791->guuid=84d276c6-1e00-0000-6b3e-7edfd10e0000 pid=3793 clone guuid=84d276c6-1e00-0000-6b3e-7edfd10e0000 pid=3793->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 17a84415-af46-5723-a1d0-4815e1a0a157 160.238.13.201:3778 guuid=84d276c6-1e00-0000-6b3e-7edfd10e0000 pid=3793->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=57d374f2-1f00-0000-6b3e-7edfd7120000 pid=4823->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=57d374f2-1f00-0000-6b3e-7edfd7120000 pid=4823->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=f8f584f2-1f00-0000-6b3e-7edfd8120000 pid=4824->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 168B guuid=8302f917-2000-0000-6b3e-7edf4b130000 pid=4939->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 117B guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d099141-2000-0000-6b3e-7edfd2130000 pid=5074 /tmp/Chaotic guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071->guuid=4d099141-2000-0000-6b3e-7edfd2130000 pid=5074 clone guuid=6443156e-2100-0000-6b3e-7edf7e140000 pid=5246 /tmp/Chaotic guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071->guuid=6443156e-2100-0000-6b3e-7edf7e140000 pid=5246 clone guuid=e2c61c6e-2100-0000-6b3e-7edf7f140000 pid=5247 /tmp/Chaotic net send-data zombie guuid=77bfb240-2000-0000-6b3e-7edfcf130000 pid=5071->guuid=e2c61c6e-2100-0000-6b3e-7edf7f140000 pid=5247 clone guuid=ded39941-2000-0000-6b3e-7edfd4130000 pid=5076 /tmp/Chaotic guuid=4d099141-2000-0000-6b3e-7edfd2130000 pid=5074->guuid=ded39941-2000-0000-6b3e-7edfd4130000 pid=5076 clone guuid=0c77a041-2000-0000-6b3e-7edfd5130000 pid=5077 /tmp/Chaotic net send-data zombie guuid=4d099141-2000-0000-6b3e-7edfd2130000 pid=5074->guuid=0c77a041-2000-0000-6b3e-7edfd5130000 pid=5077 clone guuid=0c77a041-2000-0000-6b3e-7edfd5130000 pid=5077->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0c77a041-2000-0000-6b3e-7edfd5130000 pid=5077->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=e2c61c6e-2100-0000-6b3e-7edf7f140000 pid=5247->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e2c61c6e-2100-0000-6b3e-7edf7f140000 pid=5247->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=f0aa356e-2100-0000-6b3e-7edf80140000 pid=5248->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 166B guuid=1fd8f192-2100-0000-6b3e-7edf88140000 pid=5256->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 115B guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=347024bc-2100-0000-6b3e-7edf8c140000 pid=5260 /tmp/Chaotic guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259->guuid=347024bc-2100-0000-6b3e-7edf8c140000 pid=5260 clone guuid=9c10cce8-2200-0000-6b3e-7edf9e140000 pid=5278 /tmp/Chaotic guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259->guuid=9c10cce8-2200-0000-6b3e-7edf9e140000 pid=5278 clone guuid=7281d0e8-2200-0000-6b3e-7edf9f140000 pid=5279 /tmp/Chaotic net send-data zombie guuid=874867bb-2100-0000-6b3e-7edf8b140000 pid=5259->guuid=7281d0e8-2200-0000-6b3e-7edf9f140000 pid=5279 clone guuid=1e27fcbc-2100-0000-6b3e-7edf8d140000 pid=5261 /tmp/Chaotic guuid=347024bc-2100-0000-6b3e-7edf8c140000 pid=5260->guuid=1e27fcbc-2100-0000-6b3e-7edf8d140000 pid=5261 clone guuid=fa7902bd-2100-0000-6b3e-7edf8e140000 pid=5262 /tmp/Chaotic net send-data zombie guuid=347024bc-2100-0000-6b3e-7edf8c140000 pid=5260->guuid=fa7902bd-2100-0000-6b3e-7edf8e140000 pid=5262 clone guuid=fa7902bd-2100-0000-6b3e-7edf8e140000 pid=5262->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fa7902bd-2100-0000-6b3e-7edf8e140000 pid=5262->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=7281d0e8-2200-0000-6b3e-7edf9f140000 pid=5279->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7281d0e8-2200-0000-6b3e-7edf9f140000 pid=5279->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=06f4e1e8-2200-0000-6b3e-7edfa0140000 pid=5280->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 166B guuid=3d012b16-2300-0000-6b3e-7edfb2140000 pid=5298->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 115B guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9c62793b-2300-0000-6b3e-7edfb6140000 pid=5302 /tmp/Chaotic guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301->guuid=9c62793b-2300-0000-6b3e-7edfb6140000 pid=5302 clone guuid=1a9e1d67-2400-0000-6b3e-7edfb9140000 pid=5305 /tmp/Chaotic guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301->guuid=1a9e1d67-2400-0000-6b3e-7edfb9140000 pid=5305 clone guuid=4a6d2867-2400-0000-6b3e-7edfba140000 pid=5306 /tmp/Chaotic net send-data zombie guuid=694b073b-2300-0000-6b3e-7edfb5140000 pid=5301->guuid=4a6d2867-2400-0000-6b3e-7edfba140000 pid=5306 clone guuid=b3b57f3b-2300-0000-6b3e-7edfb7140000 pid=5303 /tmp/Chaotic guuid=9c62793b-2300-0000-6b3e-7edfb6140000 pid=5302->guuid=b3b57f3b-2300-0000-6b3e-7edfb7140000 pid=5303 clone guuid=f39f853b-2300-0000-6b3e-7edfb8140000 pid=5304 /tmp/Chaotic net send-data zombie guuid=9c62793b-2300-0000-6b3e-7edfb6140000 pid=5302->guuid=f39f853b-2300-0000-6b3e-7edfb8140000 pid=5304 clone guuid=f39f853b-2300-0000-6b3e-7edfb8140000 pid=5304->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f39f853b-2300-0000-6b3e-7edfb8140000 pid=5304->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=4a6d2867-2400-0000-6b3e-7edfba140000 pid=5306->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4a6d2867-2400-0000-6b3e-7edfba140000 pid=5306->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=bbe34567-2400-0000-6b3e-7edfbb140000 pid=5307->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 168B guuid=dc748f80-2400-0000-6b3e-7edfbc140000 pid=5308->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 117B guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b8442a9c-2400-0000-6b3e-7edfc0140000 pid=5312 /tmp/Chaotic guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311->guuid=b8442a9c-2400-0000-6b3e-7edfc0140000 pid=5312 clone guuid=f9ecfcc9-2500-0000-6b3e-7edfc3140000 pid=5315 /tmp/Chaotic guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311->guuid=f9ecfcc9-2500-0000-6b3e-7edfc3140000 pid=5315 clone guuid=5f930dca-2500-0000-6b3e-7edfc4140000 pid=5316 /tmp/Chaotic net send-data zombie guuid=bcb12d9b-2400-0000-6b3e-7edfbf140000 pid=5311->guuid=5f930dca-2500-0000-6b3e-7edfc4140000 pid=5316 clone guuid=e16b349c-2400-0000-6b3e-7edfc1140000 pid=5313 /tmp/Chaotic guuid=b8442a9c-2400-0000-6b3e-7edfc0140000 pid=5312->guuid=e16b349c-2400-0000-6b3e-7edfc1140000 pid=5313 clone guuid=2b63449c-2400-0000-6b3e-7edfc2140000 pid=5314 /tmp/Chaotic net send-data zombie guuid=b8442a9c-2400-0000-6b3e-7edfc0140000 pid=5312->guuid=2b63449c-2400-0000-6b3e-7edfc2140000 pid=5314 clone guuid=2b63449c-2400-0000-6b3e-7edfc2140000 pid=5314->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2b63449c-2400-0000-6b3e-7edfc2140000 pid=5314->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=5f930dca-2500-0000-6b3e-7edfc4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5f930dca-2500-0000-6b3e-7edfc4140000 pid=5316->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=a84034ca-2500-0000-6b3e-7edfc5140000 pid=5317->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 166B guuid=4a7dd3f8-2500-0000-6b3e-7edfc6140000 pid=5318->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 115B guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=01fa032c-2600-0000-6b3e-7edfca140000 pid=5322 /tmp/Chaotic guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321->guuid=01fa032c-2600-0000-6b3e-7edfca140000 pid=5322 clone guuid=15b62159-2700-0000-6b3e-7edfcd140000 pid=5325 /tmp/Chaotic guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321->guuid=15b62159-2700-0000-6b3e-7edfcd140000 pid=5325 clone guuid=50632c59-2700-0000-6b3e-7edfce140000 pid=5326 /tmp/Chaotic net send-data zombie guuid=2c690e2b-2600-0000-6b3e-7edfc9140000 pid=5321->guuid=50632c59-2700-0000-6b3e-7edfce140000 pid=5326 clone guuid=771d192c-2600-0000-6b3e-7edfcb140000 pid=5323 /tmp/Chaotic guuid=01fa032c-2600-0000-6b3e-7edfca140000 pid=5322->guuid=771d192c-2600-0000-6b3e-7edfcb140000 pid=5323 clone guuid=18e9222c-2600-0000-6b3e-7edfcc140000 pid=5324 /tmp/Chaotic net send-data zombie guuid=01fa032c-2600-0000-6b3e-7edfca140000 pid=5322->guuid=18e9222c-2600-0000-6b3e-7edfcc140000 pid=5324 clone guuid=18e9222c-2600-0000-6b3e-7edfcc140000 pid=5324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18e9222c-2600-0000-6b3e-7edfcc140000 pid=5324->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=50632c59-2700-0000-6b3e-7edfce140000 pid=5326->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=50632c59-2700-0000-6b3e-7edfce140000 pid=5326->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=682f4d59-2700-0000-6b3e-7edfcf140000 pid=5327->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 165B guuid=c694857c-2700-0000-6b3e-7edfd0140000 pid=5328->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 114B guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7a3066a4-2700-0000-6b3e-7edfd4140000 pid=5332 /tmp/Chaotic guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331->guuid=7a3066a4-2700-0000-6b3e-7edfd4140000 pid=5332 clone guuid=2e7085d1-2800-0000-6b3e-7edfd7140000 pid=5335 /tmp/Chaotic guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331->guuid=2e7085d1-2800-0000-6b3e-7edfd7140000 pid=5335 clone guuid=2f0092d1-2800-0000-6b3e-7edfd8140000 pid=5336 /tmp/Chaotic net send-data zombie guuid=e96871a3-2700-0000-6b3e-7edfd3140000 pid=5331->guuid=2f0092d1-2800-0000-6b3e-7edfd8140000 pid=5336 clone guuid=c9fc71a4-2700-0000-6b3e-7edfd5140000 pid=5333 /tmp/Chaotic guuid=7a3066a4-2700-0000-6b3e-7edfd4140000 pid=5332->guuid=c9fc71a4-2700-0000-6b3e-7edfd5140000 pid=5333 clone guuid=b36d80a4-2700-0000-6b3e-7edfd6140000 pid=5334 /tmp/Chaotic net send-data zombie guuid=7a3066a4-2700-0000-6b3e-7edfd4140000 pid=5332->guuid=b36d80a4-2700-0000-6b3e-7edfd6140000 pid=5334 clone guuid=b36d80a4-2700-0000-6b3e-7edfd6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b36d80a4-2700-0000-6b3e-7edfd6140000 pid=5334->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=2f0092d1-2800-0000-6b3e-7edfd8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f0092d1-2800-0000-6b3e-7edfd8140000 pid=5336->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=1ab9bdd1-2800-0000-6b3e-7edfd9140000 pid=5337->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 166B guuid=f7000ef7-2800-0000-6b3e-7edfda140000 pid=5338->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 115B guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b864911a-2900-0000-6b3e-7edfde140000 pid=5342 /tmp/Chaotic guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341->guuid=b864911a-2900-0000-6b3e-7edfde140000 pid=5342 clone guuid=a1fa4a46-2a00-0000-6b3e-7edfe1140000 pid=5345 /tmp/Chaotic guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341->guuid=a1fa4a46-2a00-0000-6b3e-7edfe1140000 pid=5345 clone guuid=d4c85b46-2a00-0000-6b3e-7edfe2140000 pid=5346 /tmp/Chaotic net send-data zombie guuid=eb3a1b1a-2900-0000-6b3e-7edfdd140000 pid=5341->guuid=d4c85b46-2a00-0000-6b3e-7edfe2140000 pid=5346 clone guuid=bdf5981a-2900-0000-6b3e-7edfdf140000 pid=5343 /tmp/Chaotic guuid=b864911a-2900-0000-6b3e-7edfde140000 pid=5342->guuid=bdf5981a-2900-0000-6b3e-7edfdf140000 pid=5343 clone guuid=c8cba11a-2900-0000-6b3e-7edfe0140000 pid=5344 /tmp/Chaotic net send-data zombie guuid=b864911a-2900-0000-6b3e-7edfde140000 pid=5342->guuid=c8cba11a-2900-0000-6b3e-7edfe0140000 pid=5344 clone guuid=c8cba11a-2900-0000-6b3e-7edfe0140000 pid=5344->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c8cba11a-2900-0000-6b3e-7edfe0140000 pid=5344->17a84415-af46-5723-a1d0-4815e1a0a157 send: 7B guuid=d4c85b46-2a00-0000-6b3e-7edfe2140000 pid=5346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d4c85b46-2a00-0000-6b3e-7edfe2140000 pid=5346->17a84415-af46-5723-a1d0-4815e1a0a157 send: 5B guuid=5fb57046-2a00-0000-6b3e-7edfe3140000 pid=5347->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 166B guuid=0b10f976-2a00-0000-6b3e-7edfe4140000 pid=5348->7f3e8daa-6a94-57d1-b642-8d6fa0c38ac6 send: 115B guuid=c939da4f-2b00-0000-6b3e-7edfe7140000 pid=5351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3d59d150-2b00-0000-6b3e-7edfe8140000 pid=5352 /tmp/Chaotic guuid=c939da4f-2b00-0000-6b3e-7edfe7140000 pid=5351->guuid=3d59d150-2b00-0000-6b3e-7edfe8140000 pid=5352 clone guuid=5605e950-2b00-0000-6b3e-7edfe9140000 pid=5353 /tmp/Chaotic guuid=3d59d150-2b00-0000-6b3e-7edfe8140000 pid=5352->guuid=5605e950-2b00-0000-6b3e-7edfe9140000 pid=5353 clone guuid=53b8f250-2b00-0000-6b3e-7edfea140000 pid=5354 /tmp/Chaotic net send-data zombie guuid=3d59d150-2b00-0000-6b3e-7edfe8140000 pid=5352->guuid=53b8f250-2b00-0000-6b3e-7edfea140000 pid=5354 clone guuid=53b8f250-2b00-0000-6b3e-7edfea140000 pid=5354->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=53b8f250-2b00-0000-6b3e-7edfea140000 pid=5354->17a84415-af46-5723-a1d0-4815e1a0a157 send: 5B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-18 15:59:34 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cece11963249ce094941b57bff342db7a322bea4e74250c10503abdac6b82aef

(this sample)

  
Delivery method
Distributed via web download

Comments