MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80
SHA3-384 hash: 74acd77c3c11018746912b81fa77462c3c1d21bddf55f09adbec33a8257de4ce553d8a1827224c8e7c174a25e33c9d88
SHA1 hash: eff46afe789c44e50be84cf405ea88adf7c9128d
MD5 hash: f86dab9f11ba4aa886550c7a141f6f3a
humanhash: angel-robert-berlin-don
File name:cat.sh
Download: download sample
Signature Mirai
File size:3'120 bytes
First seen:2026-04-05 01:54:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:fiLElAgybCbrnRnEL+V6fT2IJCCCrlClrpsgx/C/V1Tb2TI:yJ+P2I
TLSH T12451D28E125240F9BC45EE17F4669F9078A09FDA4EE38F4EDEDD2B5251CCC146834672
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.130.214.71:1212/mirai.apk908a90f59dfcead5fcc6a8ad7eaac7799dadf1ebc083306c0b4c5b5ae23c9e63 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm42bfa803d1e3de85337e3014217cd696395b2fcd43df64faf08d486ef430bf50c Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm5f99a34410fc5e5de197a0f7927188a653744860a7339eb18993dbe6c5de97c26 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm6a037866f92e33a4f8bf7083f211636ff053be45ff7d45fdca24388400323a486 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.arm7908a90f59dfcead5fcc6a8ad7eaac7799dadf1ebc083306c0b4c5b5ae23c9e63 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.dbga95e4e2c9aeb0410f8ea3e48888eb2e386056336625dea408dd568f5d4c7d58e Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.i486179a6adc0d6377ea4b8d76483574e69e973615a6476c46cd0276b604f2e89d92 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.i686a9549846f4fed8c2067218770280c61a3457d4b2341047ef0682b9b6f158c115 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.m68k082121edb46ad791d60420d235560eeeb5a71520066c9fb0a1065e4e1d1879bd Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.mips228b01b7cbb4acff60ccf8894fb333efe662a445fc33f1347756e4fa0dd11c58 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.mpsl2301c22590b771b4283c13b8acb9e786e53f9e7e7e20fb558b8f969eac2afba9 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.sh46bfebb9caeb383e28af35f4429ddd9410f087ce33cebdcaa4c894db9a13ad30c Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.spcf4814c2f30e6131789c31ba5219252de9c6fe92c373a62bf878599e9044c2477 Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.x64a8fba0d6211e9897ef7dcce3728199aa8fb1f1442586865e74ba9b8dfa55a9cc Miraielf mirai ua-wget
http://103.130.214.71:1212/mirai.x86409fad8fa5203e0eeb4cbde4e6354cb4242c020c0874238593375dc1fd842ae4 Miraielf mirai ua-wget x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
14
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Gathering data
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=74a9762d-1a00-0000-c621-d15b94090000 pid=2452 /usr/bin/sudo guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461 /tmp/sample.bin guuid=74a9762d-1a00-0000-c621-d15b94090000 pid=2452->guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461 execve guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463 clone guuid=91981d65-1a00-0000-c621-d15b030a0000 pid=2563 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=91981d65-1a00-0000-c621-d15b030a0000 pid=2563 execve guuid=e8dbcf65-1a00-0000-c621-d15b040a0000 pid=2564 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=e8dbcf65-1a00-0000-c621-d15b040a0000 pid=2564 clone guuid=34e6f766-1a00-0000-c621-d15b090a0000 pid=2569 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=34e6f766-1a00-0000-c621-d15b090a0000 pid=2569 execve guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572 clone guuid=19037299-1a00-0000-c621-d15b8b0a0000 pid=2699 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=19037299-1a00-0000-c621-d15b8b0a0000 pid=2699 execve guuid=d45adb99-1a00-0000-c621-d15b8d0a0000 pid=2701 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d45adb99-1a00-0000-c621-d15b8d0a0000 pid=2701 clone guuid=b694dc9a-1a00-0000-c621-d15b920a0000 pid=2706 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b694dc9a-1a00-0000-c621-d15b920a0000 pid=2706 execve guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708 clone guuid=ced495c1-1a00-0000-c621-d15bce0a0000 pid=2766 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=ced495c1-1a00-0000-c621-d15bce0a0000 pid=2766 execve guuid=b493f4c1-1a00-0000-c621-d15bcf0a0000 pid=2767 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b493f4c1-1a00-0000-c621-d15bcf0a0000 pid=2767 clone guuid=0abde1c2-1a00-0000-c621-d15bd10a0000 pid=2769 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0abde1c2-1a00-0000-c621-d15bd10a0000 pid=2769 execve guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770 clone guuid=bc9ed2f5-1a00-0000-c621-d15b0a0b0000 pid=2826 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bc9ed2f5-1a00-0000-c621-d15b0a0b0000 pid=2826 execve guuid=6cd041f6-1a00-0000-c621-d15b0b0b0000 pid=2827 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=6cd041f6-1a00-0000-c621-d15b0b0b0000 pid=2827 clone guuid=67d01ff8-1a00-0000-c621-d15b0f0b0000 pid=2831 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=67d01ff8-1a00-0000-c621-d15b0f0b0000 pid=2831 execve guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833 clone guuid=bf7c932a-1b00-0000-c621-d15b7e0b0000 pid=2942 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bf7c932a-1b00-0000-c621-d15b7e0b0000 pid=2942 execve guuid=285fd82a-1b00-0000-c621-d15b7f0b0000 pid=2943 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=285fd82a-1b00-0000-c621-d15b7f0b0000 pid=2943 clone guuid=0a09ac2b-1b00-0000-c621-d15b820b0000 pid=2946 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0a09ac2b-1b00-0000-c621-d15b820b0000 pid=2946 execve guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948 clone guuid=c699b168-1b00-0000-c621-d15beb0b0000 pid=3051 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=c699b168-1b00-0000-c621-d15beb0b0000 pid=3051 execve guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053 execve guuid=966d1569-1b00-0000-c621-d15bef0b0000 pid=3055 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=966d1569-1b00-0000-c621-d15bef0b0000 pid=3055 execve guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057 clone guuid=e18bd99a-1b00-0000-c621-d15b770c0000 pid=3191 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=e18bd99a-1b00-0000-c621-d15b770c0000 pid=3191 execve guuid=bc1d209b-1b00-0000-c621-d15b780c0000 pid=3192 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bc1d209b-1b00-0000-c621-d15b780c0000 pid=3192 execve guuid=723f379b-1b00-0000-c621-d15b7a0c0000 pid=3194 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=723f379b-1b00-0000-c621-d15b7a0c0000 pid=3194 execve guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195 clone guuid=8c9c8cce-1b00-0000-c621-d15bb50c0000 pid=3253 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8c9c8cce-1b00-0000-c621-d15bb50c0000 pid=3253 execve guuid=533a24cf-1b00-0000-c621-d15bb70c0000 pid=3255 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=533a24cf-1b00-0000-c621-d15bb70c0000 pid=3255 execve guuid=539d5ccf-1b00-0000-c621-d15bb90c0000 pid=3257 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=539d5ccf-1b00-0000-c621-d15bb90c0000 pid=3257 execve guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259 clone guuid=3492b201-1c00-0000-c621-d15b110d0000 pid=3345 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=3492b201-1c00-0000-c621-d15b110d0000 pid=3345 execve guuid=7f980502-1c00-0000-c621-d15b130d0000 pid=3347 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7f980502-1c00-0000-c621-d15b130d0000 pid=3347 clone guuid=1b0cc802-1c00-0000-c621-d15b170d0000 pid=3351 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=1b0cc802-1c00-0000-c621-d15b170d0000 pid=3351 execve guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353 clone guuid=8dc9d936-1c00-0000-c621-d15b720d0000 pid=3442 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8dc9d936-1c00-0000-c621-d15b720d0000 pid=3442 execve guuid=78103437-1c00-0000-c621-d15b740d0000 pid=3444 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=78103437-1c00-0000-c621-d15b740d0000 pid=3444 clone guuid=86467f38-1c00-0000-c621-d15b7a0d0000 pid=3450 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=86467f38-1c00-0000-c621-d15b7a0d0000 pid=3450 execve guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452 clone guuid=d955726c-1c00-0000-c621-d15bf20d0000 pid=3570 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d955726c-1c00-0000-c621-d15bf20d0000 pid=3570 execve guuid=d974d06c-1c00-0000-c621-d15bf30d0000 pid=3571 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d974d06c-1c00-0000-c621-d15bf30d0000 pid=3571 clone guuid=d318ee6d-1c00-0000-c621-d15bf50d0000 pid=3573 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d318ee6d-1c00-0000-c621-d15bf50d0000 pid=3573 execve guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574 clone guuid=b966d99f-1c00-0000-c621-d15b630e0000 pid=3683 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=b966d99f-1c00-0000-c621-d15b630e0000 pid=3683 execve guuid=1c7c4ea0-1c00-0000-c621-d15b650e0000 pid=3685 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=1c7c4ea0-1c00-0000-c621-d15b650e0000 pid=3685 clone guuid=f5d4f0a1-1c00-0000-c621-d15b6b0e0000 pid=3691 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=f5d4f0a1-1c00-0000-c621-d15b6b0e0000 pid=3691 execve guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693 clone guuid=9674d6d4-1c00-0000-c621-d15bdb0e0000 pid=3803 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=9674d6d4-1c00-0000-c621-d15bdb0e0000 pid=3803 execve guuid=d92b24d5-1c00-0000-c621-d15bdd0e0000 pid=3805 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d92b24d5-1c00-0000-c621-d15bdd0e0000 pid=3805 clone guuid=50fcf1d5-1c00-0000-c621-d15be20e0000 pid=3810 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=50fcf1d5-1c00-0000-c621-d15be20e0000 pid=3810 execve guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814 clone guuid=fd659a08-1d00-0000-c621-d15b7f0f0000 pid=3967 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=fd659a08-1d00-0000-c621-d15b7f0f0000 pid=3967 execve guuid=4b03f308-1d00-0000-c621-d15b830f0000 pid=3971 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=4b03f308-1d00-0000-c621-d15b830f0000 pid=3971 execve guuid=5dc70f09-1d00-0000-c621-d15b840f0000 pid=3972 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=5dc70f09-1d00-0000-c621-d15b840f0000 pid=3972 execve guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973 /usr/bin/bash guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973 clone guuid=d999103d-1d00-0000-c621-d15b22100000 pid=4130 /usr/bin/chmod guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=d999103d-1d00-0000-c621-d15b22100000 pid=4130 execve guuid=f6888c3d-1d00-0000-c621-d15b26100000 pid=4134 /tmp/target guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=f6888c3d-1d00-0000-c621-d15b26100000 pid=4134 execve guuid=7f01bc3d-1d00-0000-c621-d15b27100000 pid=4135 /usr/bin/rm delete-file guuid=16532031-1a00-0000-c621-d15b9d090000 pid=2461->guuid=7f01bc3d-1d00-0000-c621-d15b27100000 pid=4135 execve guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464 /usr/bin/wget net send-data write-file guuid=728c9f31-1a00-0000-c621-d15b9f090000 pid=2463->guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464 execve 9d944b7b-5602-507b-b9b6-87b651bc0ff5 103.130.214.71:1212 guuid=19c6d331-1a00-0000-c621-d15ba0090000 pid=2464->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574 /usr/bin/wget net send-data write-file guuid=8c1a9467-1a00-0000-c621-d15b0c0a0000 pid=2572->guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574 execve guuid=d86eb367-1a00-0000-c621-d15b0e0a0000 pid=2574->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709 /usr/bin/wget net send-data write-file guuid=de256d9b-1a00-0000-c621-d15b940a0000 pid=2708->guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709 execve guuid=9afc7a9b-1a00-0000-c621-d15b950a0000 pid=2709->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771 /usr/bin/wget net send-data write-file guuid=288d31c3-1a00-0000-c621-d15bd20a0000 pid=2770->guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771 execve guuid=18e646c3-1a00-0000-c621-d15bd30a0000 pid=2771->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834 /usr/bin/wget net send-data write-file guuid=a34395f8-1a00-0000-c621-d15b110b0000 pid=2833->guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834 execve guuid=cdafa7f8-1a00-0000-c621-d15b120b0000 pid=2834->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950 /usr/bin/wget net send-data write-file guuid=5d4e332c-1b00-0000-c621-d15b840b0000 pid=2948->guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950 execve guuid=2504412c-1b00-0000-c621-d15b860b0000 pid=2950->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054 /tmp/target net send-data zombie guuid=4ac4fb68-1b00-0000-c621-d15bed0b0000 pid=3053->guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e1dfe4ad-bd09-520e-b47b-5f4160545e50 103.130.214.71:9506 guuid=98fc0a69-1b00-0000-c621-d15bee0b0000 pid=3054->e1dfe4ad-bd09-520e-b47b-5f4160545e50 send: 121B guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058 /usr/bin/wget net send-data write-file guuid=220f6669-1b00-0000-c621-d15bf10b0000 pid=3057->guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058 execve guuid=d87f7569-1b00-0000-c621-d15bf20b0000 pid=3058->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196 /usr/bin/wget net send-data write-file guuid=de3d809b-1b00-0000-c621-d15b7b0c0000 pid=3195->guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196 execve guuid=1a0a8e9b-1b00-0000-c621-d15b7c0c0000 pid=3196->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=7e8a10d0-1b00-0000-c621-d15bbb0c0000 pid=3259->guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260 execve guuid=89f92cd0-1b00-0000-c621-d15bbc0c0000 pid=3260->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354 /usr/bin/wget net send-data write-file guuid=41c54703-1c00-0000-c621-d15b190d0000 pid=3353->guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354 execve guuid=73857503-1c00-0000-c621-d15b1a0d0000 pid=3354->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453 /usr/bin/wget net send-data write-file guuid=0043d738-1c00-0000-c621-d15b7c0d0000 pid=3452->guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453 execve guuid=a9fbe238-1c00-0000-c621-d15b7d0d0000 pid=3453->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 144B guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575 /usr/bin/wget net send-data write-file guuid=eba6536e-1c00-0000-c621-d15bf60d0000 pid=3574->guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575 execve guuid=ce1f626e-1c00-0000-c621-d15bf70d0000 pid=3575->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695 /usr/bin/wget net send-data write-file guuid=bd1256a2-1c00-0000-c621-d15b6d0e0000 pid=3693->guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695 execve guuid=5b8763a2-1c00-0000-c621-d15b6f0e0000 pid=3695->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815 /usr/bin/wget net send-data write-file guuid=be3e40d6-1c00-0000-c621-d15be60e0000 pid=3814->guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815 execve guuid=16f14ed6-1c00-0000-c621-d15be70e0000 pid=3815->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974 /usr/bin/wget net send-data write-file guuid=8fdc7109-1d00-0000-c621-d15b850f0000 pid=3973->guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974 execve guuid=e8bc7f09-1d00-0000-c621-d15b860f0000 pid=3974->9d944b7b-5602-507b-b9b6-87b651bc0ff5 send: 143B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-05 01:55:31 UTC
AV detection:
15 of 36 (41.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ec2913b36b2febcf01a9f097cf4bcb3a35553bdcf331c697f5acc54d59e0dc80

(this sample)

  
Delivery method
Distributed via web download

Comments