MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d58013ec3f55dd6b18d59a2eaee4b70f0dba608a7fc07ad8cd135bde54dfdc17. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: d58013ec3f55dd6b18d59a2eaee4b70f0dba608a7fc07ad8cd135bde54dfdc17
SHA3-384 hash: 81adcca95f5ca2b04a75d82021a51fae1b64701a69367f0ebcf389a22badeccb4434886cc5772535deb5258934163442
SHA1 hash: 6ed49b56dadb306b57324b591e77f0fe3fe9191b
MD5 hash: 499e2a79d4ebcf392331b9d9844d44b7
humanhash: lamp-minnesota-equal-bulldog
File name:1.sh
Download: download sample
Signature Mirai
File size:2'959 bytes
First seen:2025-08-07 08:19:13 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iXAhmlXqnElXPCXlXzePlXaeazvZlXasaFvjlX9NU9z4gelXujclX/SvlXjejzqE:iSmlKElqXlaPlKfzvZlKxFvjltoz4ZlV
TLSH T198516EC702514A312EA7BE23FEB98F7C358155D21CE1BF0465DD78A5528CE88F06AA4B
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.67.244.57/hiddenbin/Space.arcf5c26797b96f03c0fc22ca06f7630c4fdc2aa1c09721662c02ff7a9bf803fe07 Miraielf geofenced mirai opendir ua-wget USA
http://103.67.244.57/hiddenbin/Space.x86f00e344d0c4530bbcaabdc5b1d15cabe0572a550fd21302589724665a45128b4 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.x86_64d31f069ada96d16d05e7ad3f2996bf395c8f665d283bb57755f93c71078069dc Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.i68610e34ed179fdbfa963054766c49e534a77ddcb84abef5b17d5e83531013c0b36 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.mips6543ec98c16b9c1519e71dd3ffaab0076ec848ff3f785b822945da81dfbd1806 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.mips64n/an/aelf geofenced ua-wget USA
http://103.67.244.57/hiddenbin/Space.mpsl24da29d761fd956f8466907b9e8550d1a9a149947bae74b16d25a4021014a7f7 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.arm1d7f44d4b8d5625cc8231d44111847b5693e80c9ec2c76b37f5090d6d04e1b73 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.arm57ca7d501bc0a8eda40d8746b0ac21a2ba38c7062cb81fe6e1007ded8839565bf Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.arm69ee881504b8d2f0ae4ad14a8269436eec02b95d2e5260b432e1b122bc5879c7f Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.arm722df6da06dac3e8ecd9057cc266cddbfaf2741dd188a5a84e75b7da40afff733 Miraielf geofenced mirai opendir ua-wget USA
http://103.67.244.57/hiddenbin/Space.ppcfeb60454b038a8cb1918dd40e599d8163d3986194c17933ef56d27a3cb708544 Miraielf mirai ua-wget
http://103.67.244.57/hiddenbin/Space.sparcn/an/aelf geofenced ua-wget USA
http://103.67.244.57/hiddenbin/Space.m68kd4bbd809ebc42a56c1710da9cfffb8cf566ce90b9e7a294b2314e8c2f4a1196f Miraielf geofenced mirai opendir ua-wget USA
http://103.67.244.57/hiddenbin/Space.sh49a9a03da6c7d9e83ddf8d4fcc7a99a8a63622b37f94d6151bcdb79789c9a21d5 Miraielf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=b83b87cd-1a00-0000-25c7-c9faa00a0000 pid=2720 /usr/bin/sudo guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725 /tmp/sample.bin guuid=b83b87cd-1a00-0000-25c7-c9faa00a0000 pid=2720->guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725 execve guuid=cda2f8cf-1a00-0000-25c7-c9faa80a0000 pid=2728 /usr/bin/cp guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=cda2f8cf-1a00-0000-25c7-c9faa80a0000 pid=2728 execve guuid=f2d9d1d6-1a00-0000-25c7-c9fab70a0000 pid=2743 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=f2d9d1d6-1a00-0000-25c7-c9fab70a0000 pid=2743 execve guuid=b9c2cb10-1b00-0000-25c7-c9fa0e0b0000 pid=2830 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=b9c2cb10-1b00-0000-25c7-c9fa0e0b0000 pid=2830 execve guuid=c6e08d50-1b00-0000-25c7-c9fa800b0000 pid=2944 /usr/bin/cat guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=c6e08d50-1b00-0000-25c7-c9fa800b0000 pid=2944 execve guuid=e9921c51-1b00-0000-25c7-c9fa820b0000 pid=2946 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=e9921c51-1b00-0000-25c7-c9fa820b0000 pid=2946 execve guuid=3d117c51-1b00-0000-25c7-c9fa850b0000 pid=2949 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=3d117c51-1b00-0000-25c7-c9fa850b0000 pid=2949 clone guuid=200f6f53-1b00-0000-25c7-c9fa8a0b0000 pid=2954 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=200f6f53-1b00-0000-25c7-c9fa8a0b0000 pid=2954 execve guuid=530afb73-1b00-0000-25c7-c9fac60b0000 pid=3014 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=530afb73-1b00-0000-25c7-c9fac60b0000 pid=3014 execve guuid=8470ac98-1b00-0000-25c7-c9fa240c0000 pid=3108 /usr/bin/cat guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=8470ac98-1b00-0000-25c7-c9fa240c0000 pid=3108 execve guuid=ff3e0e99-1b00-0000-25c7-c9fa250c0000 pid=3109 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=ff3e0e99-1b00-0000-25c7-c9fa250c0000 pid=3109 execve guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111 execve guuid=7ac4ccc6-1c00-0000-25c7-c9fa350e0000 pid=3637 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=7ac4ccc6-1c00-0000-25c7-c9fa350e0000 pid=3637 execve guuid=e3e118e9-1c00-0000-25c7-c9fa640e0000 pid=3684 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=e3e118e9-1c00-0000-25c7-c9fa640e0000 pid=3684 execve guuid=20f54b0e-1d00-0000-25c7-c9fabf0e0000 pid=3775 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=20f54b0e-1d00-0000-25c7-c9fabf0e0000 pid=3775 clone guuid=3b126b0e-1d00-0000-25c7-c9fac10e0000 pid=3777 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=3b126b0e-1d00-0000-25c7-c9fac10e0000 pid=3777 execve guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778 execve guuid=4637273b-1e00-0000-25c7-c9fac3110000 pid=4547 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=4637273b-1e00-0000-25c7-c9fac3110000 pid=4547 execve guuid=151efd5f-1e00-0000-25c7-c9fa25120000 pid=4645 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=151efd5f-1e00-0000-25c7-c9fa25120000 pid=4645 execve guuid=a89c588a-1e00-0000-25c7-c9fa57120000 pid=4695 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=a89c588a-1e00-0000-25c7-c9fa57120000 pid=4695 clone guuid=46c5848a-1e00-0000-25c7-c9fa58120000 pid=4696 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=46c5848a-1e00-0000-25c7-c9fa58120000 pid=4696 execve guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699 execve guuid=7277c6b7-1f00-0000-25c7-c9fa94140000 pid=5268 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=7277c6b7-1f00-0000-25c7-c9fa94140000 pid=5268 execve guuid=6e33aede-1f00-0000-25c7-c9fa95140000 pid=5269 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=6e33aede-1f00-0000-25c7-c9fa95140000 pid=5269 execve guuid=1ea34205-2000-0000-25c7-c9fa96140000 pid=5270 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=1ea34205-2000-0000-25c7-c9fa96140000 pid=5270 clone guuid=868b7105-2000-0000-25c7-c9fa97140000 pid=5271 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=868b7105-2000-0000-25c7-c9fa97140000 pid=5271 execve guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272 execve guuid=9f433533-2100-0000-25c7-c9faa6140000 pid=5286 /usr/bin/wget net send-data guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=9f433533-2100-0000-25c7-c9faa6140000 pid=5286 execve guuid=13025a49-2100-0000-25c7-c9faac140000 pid=5292 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=13025a49-2100-0000-25c7-c9faac140000 pid=5292 execve guuid=9d3acc62-2100-0000-25c7-c9fab4140000 pid=5300 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=9d3acc62-2100-0000-25c7-c9fab4140000 pid=5300 clone guuid=b8870363-2100-0000-25c7-c9fab5140000 pid=5301 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=b8870363-2100-0000-25c7-c9fab5140000 pid=5301 execve guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302 execve guuid=6a671891-2200-0000-25c7-c9facf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=6a671891-2200-0000-25c7-c9facf140000 pid=5327 execve guuid=0aac08b6-2200-0000-25c7-c9fad0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=0aac08b6-2200-0000-25c7-c9fad0140000 pid=5328 execve guuid=c7023dda-2200-0000-25c7-c9fad1140000 pid=5329 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=c7023dda-2200-0000-25c7-c9fad1140000 pid=5329 clone guuid=14915dda-2200-0000-25c7-c9fad2140000 pid=5330 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=14915dda-2200-0000-25c7-c9fad2140000 pid=5330 execve guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331 execve guuid=846b5c07-2400-0000-25c7-c9fad9140000 pid=5337 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=846b5c07-2400-0000-25c7-c9fad9140000 pid=5337 execve guuid=fbde9a2a-2400-0000-25c7-c9fada140000 pid=5338 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=fbde9a2a-2400-0000-25c7-c9fada140000 pid=5338 execve guuid=8bd60d66-2400-0000-25c7-c9fadb140000 pid=5339 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=8bd60d66-2400-0000-25c7-c9fadb140000 pid=5339 clone guuid=165c5266-2400-0000-25c7-c9fadc140000 pid=5340 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=165c5266-2400-0000-25c7-c9fadc140000 pid=5340 execve guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341 execve guuid=590e6b95-2500-0000-25c7-c9fae3140000 pid=5347 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=590e6b95-2500-0000-25c7-c9fae3140000 pid=5347 execve guuid=b7a2b7c6-2500-0000-25c7-c9fae4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=b7a2b7c6-2500-0000-25c7-c9fae4140000 pid=5348 execve guuid=14b960ef-2500-0000-25c7-c9fae5140000 pid=5349 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=14b960ef-2500-0000-25c7-c9fae5140000 pid=5349 clone guuid=221ea3ef-2500-0000-25c7-c9fae6140000 pid=5350 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=221ea3ef-2500-0000-25c7-c9fae6140000 pid=5350 execve guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351 execve guuid=11015a1e-2700-0000-25c7-c9faed140000 pid=5357 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=11015a1e-2700-0000-25c7-c9faed140000 pid=5357 execve guuid=7d4b6b58-2700-0000-25c7-c9faee140000 pid=5358 /usr/bin/curl net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=7d4b6b58-2700-0000-25c7-c9faee140000 pid=5358 execve guuid=b841777f-2700-0000-25c7-c9faef140000 pid=5359 /usr/bin/bash guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=b841777f-2700-0000-25c7-c9faef140000 pid=5359 clone guuid=007ab37f-2700-0000-25c7-c9faf0140000 pid=5360 /usr/bin/chmod guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=007ab37f-2700-0000-25c7-c9faf0140000 pid=5360 execve guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361 /tmp/Space net guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361 execve guuid=950694ae-2800-0000-25c7-c9faf9140000 pid=5369 /usr/bin/wget net send-data write-file guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=950694ae-2800-0000-25c7-c9faf9140000 pid=5369 execve guuid=66aa35dc-2800-0000-25c7-c9fa02150000 pid=5378 /usr/bin/curl net send-data guuid=fd657bcf-1a00-0000-25c7-c9faa50a0000 pid=2725->guuid=66aa35dc-2800-0000-25c7-c9fa02150000 pid=5378 execve ff8aed58-b700-5c66-af35-d0e39f6be125 103.67.244.57:80 guuid=f2d9d1d6-1a00-0000-25c7-c9fab70a0000 pid=2743->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 147B guuid=b9c2cb10-1b00-0000-25c7-c9fa0e0b0000 pid=2830->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 96B guuid=200f6f53-1b00-0000-25c7-c9fa8a0b0000 pid=2954->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 147B guuid=530afb73-1b00-0000-25c7-c9fac60b0000 pid=3014->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 96B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b18e059a-1b00-0000-25c7-c9fa280c0000 pid=3112 /tmp/Space guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111->guuid=b18e059a-1b00-0000-25c7-c9fa280c0000 pid=3112 clone guuid=8a69bbc6-1c00-0000-25c7-c9fa330e0000 pid=3635 /tmp/Space guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111->guuid=8a69bbc6-1c00-0000-25c7-c9fa330e0000 pid=3635 clone guuid=ab8bc0c6-1c00-0000-25c7-c9fa340e0000 pid=3636 /tmp/Space net send-data zombie guuid=51046a99-1b00-0000-25c7-c9fa270c0000 pid=3111->guuid=ab8bc0c6-1c00-0000-25c7-c9fa340e0000 pid=3636 clone guuid=4d550c9a-1b00-0000-25c7-c9fa290c0000 pid=3113 /tmp/Space guuid=b18e059a-1b00-0000-25c7-c9fa280c0000 pid=3112->guuid=4d550c9a-1b00-0000-25c7-c9fa290c0000 pid=3113 clone guuid=3e76109a-1b00-0000-25c7-c9fa2a0c0000 pid=3114 /tmp/Space net send-data zombie guuid=b18e059a-1b00-0000-25c7-c9fa280c0000 pid=3112->guuid=3e76109a-1b00-0000-25c7-c9fa2a0c0000 pid=3114 clone guuid=3e76109a-1b00-0000-25c7-c9fa2a0c0000 pid=3114->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0b7fcb0e-329d-5230-a4b3-03ad05baa1cd 103.67.244.57:3778 guuid=3e76109a-1b00-0000-25c7-c9fa2a0c0000 pid=3114->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 17B guuid=ab8bc0c6-1c00-0000-25c7-c9fa340e0000 pid=3636->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ab8bc0c6-1c00-0000-25c7-c9fa340e0000 pid=3636->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=7ac4ccc6-1c00-0000-25c7-c9fa350e0000 pid=3637->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 150B guuid=e3e118e9-1c00-0000-25c7-c9fa640e0000 pid=3684->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 99B guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e318360f-1d00-0000-25c7-c9fac50e0000 pid=3781 /tmp/Space guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778->guuid=e318360f-1d00-0000-25c7-c9fac50e0000 pid=3781 clone guuid=1d5a0e3b-1e00-0000-25c7-c9fac1110000 pid=4545 /tmp/Space guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778->guuid=1d5a0e3b-1e00-0000-25c7-c9fac1110000 pid=4545 clone guuid=5d53183b-1e00-0000-25c7-c9fac2110000 pid=4546 /tmp/Space net send-data zombie guuid=fababd0e-1d00-0000-25c7-c9fac20e0000 pid=3778->guuid=5d53183b-1e00-0000-25c7-c9fac2110000 pid=4546 clone guuid=54303b0f-1d00-0000-25c7-c9fac60e0000 pid=3782 /tmp/Space guuid=e318360f-1d00-0000-25c7-c9fac50e0000 pid=3781->guuid=54303b0f-1d00-0000-25c7-c9fac60e0000 pid=3782 clone guuid=deb2420f-1d00-0000-25c7-c9fac70e0000 pid=3783 /tmp/Space net send-data zombie guuid=e318360f-1d00-0000-25c7-c9fac50e0000 pid=3781->guuid=deb2420f-1d00-0000-25c7-c9fac70e0000 pid=3783 clone guuid=deb2420f-1d00-0000-25c7-c9fac70e0000 pid=3783->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=deb2420f-1d00-0000-25c7-c9fac70e0000 pid=3783->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=5d53183b-1e00-0000-25c7-c9fac2110000 pid=4546->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5d53183b-1e00-0000-25c7-c9fac2110000 pid=4546->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=4637273b-1e00-0000-25c7-c9fac3110000 pid=4547->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=151efd5f-1e00-0000-25c7-c9fa25120000 pid=4645->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=78ca998b-1e00-0000-25c7-c9fa60120000 pid=4704 /tmp/Space guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699->guuid=78ca998b-1e00-0000-25c7-c9fa60120000 pid=4704 clone guuid=720dafb7-1f00-0000-25c7-c9fa92140000 pid=5266 /tmp/Space guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699->guuid=720dafb7-1f00-0000-25c7-c9fa92140000 pid=5266 clone guuid=1832b5b7-1f00-0000-25c7-c9fa93140000 pid=5267 /tmp/Space net send-data zombie guuid=14f1fa8a-1e00-0000-25c7-c9fa5b120000 pid=4699->guuid=1832b5b7-1f00-0000-25c7-c9fa93140000 pid=5267 clone guuid=790baf8b-1e00-0000-25c7-c9fa61120000 pid=4705 /tmp/Space guuid=78ca998b-1e00-0000-25c7-c9fa60120000 pid=4704->guuid=790baf8b-1e00-0000-25c7-c9fa61120000 pid=4705 clone guuid=ed1fb28b-1e00-0000-25c7-c9fa62120000 pid=4706 /tmp/Space net send-data zombie guuid=78ca998b-1e00-0000-25c7-c9fa60120000 pid=4704->guuid=ed1fb28b-1e00-0000-25c7-c9fa62120000 pid=4706 clone guuid=ed1fb28b-1e00-0000-25c7-c9fa62120000 pid=4706->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ed1fb28b-1e00-0000-25c7-c9fa62120000 pid=4706->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=1832b5b7-1f00-0000-25c7-c9fa93140000 pid=5267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1832b5b7-1f00-0000-25c7-c9fa93140000 pid=5267->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=7277c6b7-1f00-0000-25c7-c9fa94140000 pid=5268->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=6e33aede-1f00-0000-25c7-c9fa95140000 pid=5269->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fe0b9106-2000-0000-25c7-c9fa99140000 pid=5273 /tmp/Space guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272->guuid=fe0b9106-2000-0000-25c7-c9fa99140000 pid=5273 clone guuid=98590d33-2100-0000-25c7-c9faa4140000 pid=5284 /tmp/Space guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272->guuid=98590d33-2100-0000-25c7-c9faa4140000 pid=5284 clone guuid=37941233-2100-0000-25c7-c9faa5140000 pid=5285 /tmp/Space net send-data zombie guuid=12f7db05-2000-0000-25c7-c9fa98140000 pid=5272->guuid=37941233-2100-0000-25c7-c9faa5140000 pid=5285 clone guuid=5c2d3e07-2000-0000-25c7-c9fa9a140000 pid=5274 /tmp/Space guuid=fe0b9106-2000-0000-25c7-c9fa99140000 pid=5273->guuid=5c2d3e07-2000-0000-25c7-c9fa9a140000 pid=5274 clone guuid=91fc4507-2000-0000-25c7-c9fa9b140000 pid=5275 /tmp/Space net send-data zombie guuid=fe0b9106-2000-0000-25c7-c9fa99140000 pid=5273->guuid=91fc4507-2000-0000-25c7-c9fa9b140000 pid=5275 clone guuid=91fc4507-2000-0000-25c7-c9fa9b140000 pid=5275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=91fc4507-2000-0000-25c7-c9fa9b140000 pid=5275->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=37941233-2100-0000-25c7-c9faa5140000 pid=5285->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=37941233-2100-0000-25c7-c9faa5140000 pid=5285->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 22B guuid=9f433533-2100-0000-25c7-c9faa6140000 pid=5286->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 150B guuid=13025a49-2100-0000-25c7-c9faac140000 pid=5292->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 99B guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a8a4e464-2100-0000-25c7-c9fab7140000 pid=5303 /tmp/Space guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302->guuid=a8a4e464-2100-0000-25c7-c9fab7140000 pid=5303 clone guuid=bfceef90-2200-0000-25c7-c9facd140000 pid=5325 /tmp/Space guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302->guuid=bfceef90-2200-0000-25c7-c9facd140000 pid=5325 clone guuid=7d84f790-2200-0000-25c7-c9face140000 pid=5326 /tmp/Space net send-data zombie guuid=d2259a63-2100-0000-25c7-c9fab6140000 pid=5302->guuid=7d84f790-2200-0000-25c7-c9face140000 pid=5326 clone guuid=8c6dea64-2100-0000-25c7-c9fab8140000 pid=5304 /tmp/Space guuid=a8a4e464-2100-0000-25c7-c9fab7140000 pid=5303->guuid=8c6dea64-2100-0000-25c7-c9fab8140000 pid=5304 clone guuid=542ff064-2100-0000-25c7-c9fab9140000 pid=5305 /tmp/Space net send-data zombie guuid=a8a4e464-2100-0000-25c7-c9fab7140000 pid=5303->guuid=542ff064-2100-0000-25c7-c9fab9140000 pid=5305 clone guuid=542ff064-2100-0000-25c7-c9fab9140000 pid=5305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=542ff064-2100-0000-25c7-c9fab9140000 pid=5305->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=7d84f790-2200-0000-25c7-c9face140000 pid=5326->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7d84f790-2200-0000-25c7-c9face140000 pid=5326->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=6a671891-2200-0000-25c7-c9facf140000 pid=5327->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=0aac08b6-2200-0000-25c7-c9fad0140000 pid=5328->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=112715db-2200-0000-25c7-c9fad4140000 pid=5332 /tmp/Space guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331->guuid=112715db-2200-0000-25c7-c9fad4140000 pid=5332 clone guuid=86503407-2400-0000-25c7-c9fad7140000 pid=5335 /tmp/Space guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331->guuid=86503407-2400-0000-25c7-c9fad7140000 pid=5335 clone guuid=85694407-2400-0000-25c7-c9fad8140000 pid=5336 /tmp/Space net send-data zombie guuid=10b99fda-2200-0000-25c7-c9fad3140000 pid=5331->guuid=85694407-2400-0000-25c7-c9fad8140000 pid=5336 clone guuid=cc9d1bdb-2200-0000-25c7-c9fad5140000 pid=5333 /tmp/Space guuid=112715db-2200-0000-25c7-c9fad4140000 pid=5332->guuid=cc9d1bdb-2200-0000-25c7-c9fad5140000 pid=5333 clone guuid=f14025db-2200-0000-25c7-c9fad6140000 pid=5334 /tmp/Space net send-data zombie guuid=112715db-2200-0000-25c7-c9fad4140000 pid=5332->guuid=f14025db-2200-0000-25c7-c9fad6140000 pid=5334 clone guuid=f14025db-2200-0000-25c7-c9fad6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f14025db-2200-0000-25c7-c9fad6140000 pid=5334->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=85694407-2400-0000-25c7-c9fad8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=85694407-2400-0000-25c7-c9fad8140000 pid=5336->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 7B guuid=846b5c07-2400-0000-25c7-c9fad9140000 pid=5337->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 147B guuid=fbde9a2a-2400-0000-25c7-c9fada140000 pid=5338->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 96B guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1f26f667-2400-0000-25c7-c9fade140000 pid=5342 /tmp/Space guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341->guuid=1f26f667-2400-0000-25c7-c9fade140000 pid=5342 clone guuid=f9dc3695-2500-0000-25c7-c9fae1140000 pid=5345 /tmp/Space guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341->guuid=f9dc3695-2500-0000-25c7-c9fae1140000 pid=5345 clone guuid=e01f4095-2500-0000-25c7-c9fae2140000 pid=5346 /tmp/Space net send-data zombie guuid=49c0ea66-2400-0000-25c7-c9fadd140000 pid=5341->guuid=e01f4095-2500-0000-25c7-c9fae2140000 pid=5346 clone guuid=56a10468-2400-0000-25c7-c9fadf140000 pid=5343 /tmp/Space guuid=1f26f667-2400-0000-25c7-c9fade140000 pid=5342->guuid=56a10468-2400-0000-25c7-c9fadf140000 pid=5343 clone guuid=4e311568-2400-0000-25c7-c9fae0140000 pid=5344 /tmp/Space net send-data zombie guuid=1f26f667-2400-0000-25c7-c9fade140000 pid=5342->guuid=4e311568-2400-0000-25c7-c9fae0140000 pid=5344 clone guuid=4e311568-2400-0000-25c7-c9fae0140000 pid=5344->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4e311568-2400-0000-25c7-c9fae0140000 pid=5344->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=e01f4095-2500-0000-25c7-c9fae2140000 pid=5346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e01f4095-2500-0000-25c7-c9fae2140000 pid=5346->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 12B guuid=590e6b95-2500-0000-25c7-c9fae3140000 pid=5347->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=b7a2b7c6-2500-0000-25c7-c9fae4140000 pid=5348->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f3aa30f1-2500-0000-25c7-c9fae8140000 pid=5352 /tmp/Space guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351->guuid=f3aa30f1-2500-0000-25c7-c9fae8140000 pid=5352 clone guuid=8cc61f1e-2700-0000-25c7-c9faeb140000 pid=5355 /tmp/Space guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351->guuid=8cc61f1e-2700-0000-25c7-c9faeb140000 pid=5355 clone guuid=95b82a1e-2700-0000-25c7-c9faec140000 pid=5356 /tmp/Space net send-data zombie guuid=112833f0-2500-0000-25c7-c9fae7140000 pid=5351->guuid=95b82a1e-2700-0000-25c7-c9faec140000 pid=5356 clone guuid=4ec33af1-2500-0000-25c7-c9fae9140000 pid=5353 /tmp/Space guuid=f3aa30f1-2500-0000-25c7-c9fae8140000 pid=5352->guuid=4ec33af1-2500-0000-25c7-c9fae9140000 pid=5353 clone guuid=a02146f1-2500-0000-25c7-c9faea140000 pid=5354 /tmp/Space net send-data zombie guuid=f3aa30f1-2500-0000-25c7-c9fae8140000 pid=5352->guuid=a02146f1-2500-0000-25c7-c9faea140000 pid=5354 clone guuid=a02146f1-2500-0000-25c7-c9faea140000 pid=5354->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a02146f1-2500-0000-25c7-c9faea140000 pid=5354->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 17B guuid=95b82a1e-2700-0000-25c7-c9faec140000 pid=5356->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=95b82a1e-2700-0000-25c7-c9faec140000 pid=5356->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 5B guuid=11015a1e-2700-0000-25c7-c9faed140000 pid=5357->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=7d4b6b58-2700-0000-25c7-c9faee140000 pid=5358->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=45914a81-2700-0000-25c7-c9faf2140000 pid=5362 /tmp/Space guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361->guuid=45914a81-2700-0000-25c7-c9faf2140000 pid=5362 clone guuid=433a7bae-2800-0000-25c7-c9faf7140000 pid=5367 /tmp/Space guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361->guuid=433a7bae-2800-0000-25c7-c9faf7140000 pid=5367 clone guuid=c61682ae-2800-0000-25c7-c9faf8140000 pid=5368 /tmp/Space net send-data zombie guuid=af2d5080-2700-0000-25c7-c9faf1140000 pid=5361->guuid=c61682ae-2800-0000-25c7-c9faf8140000 pid=5368 clone guuid=31075781-2700-0000-25c7-c9faf3140000 pid=5363 /tmp/Space guuid=45914a81-2700-0000-25c7-c9faf2140000 pid=5362->guuid=31075781-2700-0000-25c7-c9faf3140000 pid=5363 clone guuid=23525f81-2700-0000-25c7-c9faf4140000 pid=5364 /tmp/Space net send-data zombie guuid=45914a81-2700-0000-25c7-c9faf2140000 pid=5362->guuid=23525f81-2700-0000-25c7-c9faf4140000 pid=5364 clone guuid=23525f81-2700-0000-25c7-c9faf4140000 pid=5364->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=23525f81-2700-0000-25c7-c9faf4140000 pid=5364->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 5B guuid=c61682ae-2800-0000-25c7-c9faf8140000 pid=5368->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c61682ae-2800-0000-25c7-c9faf8140000 pid=5368->0b7fcb0e-329d-5230-a4b3-03ad05baa1cd send: 5B guuid=950694ae-2800-0000-25c7-c9faf9140000 pid=5369->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 148B guuid=66aa35dc-2800-0000-25c7-c9fa02150000 pid=5378->ff8aed58-b700-5c66-af35-d0e39f6be125 send: 97B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-07 08:20:59 UTC
File Type:
Text (Shell)
AV detection:
23 of 37 (62.16%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d58013ec3f55dd6b18d59a2eaee4b70f0dba608a7fc07ad8cd135bde54dfdc17

(this sample)

  
Delivery method
Distributed via web download

Comments