MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f46ad85e9a087360cff3bdf4eebfae0f7f0d86e1497115f4e8a97b3105eff338. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: f46ad85e9a087360cff3bdf4eebfae0f7f0d86e1497115f4e8a97b3105eff338
SHA3-384 hash: a296e9cdc9e1565805caf114cba9452c5c346ba55a1f68b2699e81d8c547c5f0306a059a2d00b808898a53dab1a0ccdf
SHA1 hash: b8f0ac5634dffd96d5312534fdc531d8d91a246e
MD5 hash: 7f67edbfe0532b2d205368d7eccbee8b
humanhash: network-maryland-social-colorado
File name:1.sh
Download: download sample
Signature Mirai
File size:3'019 bytes
First seen:2026-03-25 12:17:33 UTC
Last seen:2026-03-25 12:18:42 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:i5XwgXwhml5XwyXwnEl5XwhXwCXl5XwFXwePl5XwaWXwazvZl5XwacXwaFvjl5X1:i5Biml53cEl5WzXl5ynPl5NWNzvZl5No
TLSH T1335181D702114A312D6BBAE3FDBA8E4CB1C2609A58F17F2EA4DC74F5638CD883444A53
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://165.245.189.236/hiddenbin/Space.arca4ab0aa858512faa71448502a07f12aad49e3ce5e97e61ac4462530b5681bc84 Mirain/a
http://165.245.189.236/hiddenbin/Space.x86c6bf6c5b713b558cf76df57b26f9caca4580009b69720a837e124f3a14433bf6 Mirain/a
http://165.245.189.236/hiddenbin/Space.x86_64a6c4a730cc420bf8ea0c80bec14a7cfe3bdcf7f967903a20373a80fac617c1a6 Mirain/a
http://165.245.189.236/hiddenbin/Space.i6861c7fe134e87bd6ea1ada1fcb95c68a3194ec8ead34c1f39d46083cef46d243d8 Mirain/a
http://165.245.189.236/hiddenbin/Space.mips4dfe0982d38ad7f281052afffd415eeb90c1ca1ac2ba78698329f3b23322ff8b Miraimirai
http://165.245.189.236/hiddenbin/Space.mips64n/an/aelf ua-wget
http://165.245.189.236/hiddenbin/Space.mpslfbf7f5aab968803676df630810e109fdea761e4953b363c7239812ca49ffaaa1 Mirain/a
http://165.245.189.236/hiddenbin/Space.armcf1050719da0515eeb387fb709cc9fb5f76cb30ec42065159416fa98d40aad89 Miraimirai
http://165.245.189.236/hiddenbin/Space.arm529e458665e1eb899012544550c734452eb4fa022ce56c2fba280b70d6afccc2e Mirain/a
http://165.245.189.236/hiddenbin/Space.arm65d50743a6e9f4da6fad686fd940ae61021e20418b92e7af76d17d6c1763e6341 Mirain/a
http://165.245.189.236/hiddenbin/Space.arm79a97a45408ca47a7224afa840a956a0ec8a790cca0c887cf92c5f359151e2e79 Miraimirai
http://165.245.189.236/hiddenbin/Space.ppcd1b7d5ad4d54bd395372985d1e1cf1938f904db95880b72f703904e7c66b7219 Miraimirai
http://165.245.189.236/hiddenbin/Space.sparcn/an/aelf ua-wget
http://165.245.189.236/hiddenbin/Space.m68k8bfdbca6acf51d2308a45c21b61a3851759cad7318f1c6e552520d18dc061ef8 Miraimirai
http://165.245.189.236/hiddenbin/Space.sh402534d4332ca537018adf8c606d6534974c051ae69b0a2bfd6b4419f534d2d76 Mirain/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
49
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-23T16:22:00Z UTC
Last seen:
2026-03-25T11:52:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=511da19f-1e00-0000-941b-69715f140000 pid=5215 /usr/bin/sudo guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216 /tmp/sample.bin guuid=511da19f-1e00-0000-941b-69715f140000 pid=5215->guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216 execve guuid=980071a2-1e00-0000-941b-697161140000 pid=5217 /usr/bin/cp guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=980071a2-1e00-0000-941b-697161140000 pid=5217 execve guuid=b02c21a3-1e00-0000-941b-697162140000 pid=5218 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=b02c21a3-1e00-0000-941b-697162140000 pid=5218 execve guuid=2ae2fc07-1f00-0000-941b-697163140000 pid=5219 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=2ae2fc07-1f00-0000-941b-697163140000 pid=5219 execve guuid=f5c7b972-1f00-0000-941b-697164140000 pid=5220 /usr/bin/cat guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=f5c7b972-1f00-0000-941b-697164140000 pid=5220 execve guuid=dd8e0873-1f00-0000-941b-697165140000 pid=5221 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=dd8e0873-1f00-0000-941b-697165140000 pid=5221 execve guuid=cf56b973-1f00-0000-941b-697166140000 pid=5222 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=cf56b973-1f00-0000-941b-697166140000 pid=5222 clone guuid=828f4674-1f00-0000-941b-697168140000 pid=5224 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=828f4674-1f00-0000-941b-697168140000 pid=5224 execve guuid=89930bb0-1f00-0000-941b-697169140000 pid=5225 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=89930bb0-1f00-0000-941b-697169140000 pid=5225 execve guuid=395b81ee-1f00-0000-941b-69716a140000 pid=5226 /usr/bin/cat guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=395b81ee-1f00-0000-941b-69716a140000 pid=5226 execve guuid=6d03d1ee-1f00-0000-941b-69716b140000 pid=5227 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=6d03d1ee-1f00-0000-941b-69716b140000 pid=5227 execve guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228 execve guuid=dd93741b-2100-0000-941b-697172140000 pid=5234 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=dd93741b-2100-0000-941b-697172140000 pid=5234 execve guuid=160e7857-2100-0000-941b-697173140000 pid=5235 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=160e7857-2100-0000-941b-697173140000 pid=5235 execve guuid=42199a93-2100-0000-941b-697174140000 pid=5236 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=42199a93-2100-0000-941b-697174140000 pid=5236 clone guuid=dff2c493-2100-0000-941b-697175140000 pid=5237 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=dff2c493-2100-0000-941b-697175140000 pid=5237 execve guuid=a0701694-2100-0000-941b-697176140000 pid=5238 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=a0701694-2100-0000-941b-697176140000 pid=5238 execve guuid=a8345ac0-2200-0000-941b-69717c140000 pid=5244 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=a8345ac0-2200-0000-941b-69717c140000 pid=5244 execve guuid=843c54fe-2200-0000-941b-69717d140000 pid=5245 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=843c54fe-2200-0000-941b-69717d140000 pid=5245 execve guuid=bb9fe23a-2300-0000-941b-69717e140000 pid=5246 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=bb9fe23a-2300-0000-941b-69717e140000 pid=5246 clone guuid=d0e2fc3a-2300-0000-941b-69717f140000 pid=5247 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=d0e2fc3a-2300-0000-941b-69717f140000 pid=5247 execve guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248 execve guuid=f485b967-2400-0000-941b-697186140000 pid=5254 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=f485b967-2400-0000-941b-697186140000 pid=5254 execve guuid=425eb0a1-2400-0000-941b-697187140000 pid=5255 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=425eb0a1-2400-0000-941b-697187140000 pid=5255 execve guuid=5e912bde-2400-0000-941b-697188140000 pid=5256 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=5e912bde-2400-0000-941b-697188140000 pid=5256 clone guuid=30af56de-2400-0000-941b-697189140000 pid=5257 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=30af56de-2400-0000-941b-697189140000 pid=5257 execve guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258 execve guuid=dc32f00c-2600-0000-941b-697190140000 pid=5264 /usr/bin/wget net send-data guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=dc32f00c-2600-0000-941b-697190140000 pid=5264 execve guuid=2052f836-2600-0000-941b-697191140000 pid=5265 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=2052f836-2600-0000-941b-697191140000 pid=5265 execve guuid=6a64ef61-2600-0000-941b-697192140000 pid=5266 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=6a64ef61-2600-0000-941b-697192140000 pid=5266 clone guuid=8bcd2562-2600-0000-941b-697193140000 pid=5267 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=8bcd2562-2600-0000-941b-697193140000 pid=5267 execve guuid=34ecb762-2600-0000-941b-697194140000 pid=5268 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=34ecb762-2600-0000-941b-697194140000 pid=5268 execve guuid=28e33390-2700-0000-941b-69719a140000 pid=5274 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=28e33390-2700-0000-941b-69719a140000 pid=5274 execve guuid=3cd4f8cb-2700-0000-941b-69719b140000 pid=5275 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=3cd4f8cb-2700-0000-941b-69719b140000 pid=5275 execve guuid=7b5d450c-2800-0000-941b-69719c140000 pid=5276 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=7b5d450c-2800-0000-941b-69719c140000 pid=5276 clone guuid=ff7e600c-2800-0000-941b-69719d140000 pid=5277 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=ff7e600c-2800-0000-941b-69719d140000 pid=5277 execve guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278 execve guuid=8b25f438-2900-0000-941b-6971a4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=8b25f438-2900-0000-941b-6971a4140000 pid=5284 execve guuid=4d82f673-2900-0000-941b-6971a5140000 pid=5285 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=4d82f673-2900-0000-941b-6971a5140000 pid=5285 execve guuid=bbc4b4b3-2900-0000-941b-6971a6140000 pid=5286 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=bbc4b4b3-2900-0000-941b-6971a6140000 pid=5286 clone guuid=7530d7b3-2900-0000-941b-6971a7140000 pid=5287 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=7530d7b3-2900-0000-941b-6971a7140000 pid=5287 execve guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288 execve guuid=5c9506e1-2a00-0000-941b-6971ae140000 pid=5294 /usr/bin/wget net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=5c9506e1-2a00-0000-941b-6971ae140000 pid=5294 execve guuid=7656631d-2b00-0000-941b-6971af140000 pid=5295 /usr/bin/curl net send-data write-file guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=7656631d-2b00-0000-941b-6971af140000 pid=5295 execve guuid=f9eab658-2b00-0000-941b-6971b0140000 pid=5296 /usr/bin/bash guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=f9eab658-2b00-0000-941b-6971b0140000 pid=5296 clone guuid=06aeef58-2b00-0000-941b-6971b1140000 pid=5297 /usr/bin/chmod guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=06aeef58-2b00-0000-941b-6971b1140000 pid=5297 execve guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298 /tmp/Space net guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298 execve guuid=2014a687-2c00-0000-941b-6971ba140000 pid=5306 /usr/bin/wget guuid=f47015a2-1e00-0000-941b-697160140000 pid=5216->guuid=2014a687-2c00-0000-941b-6971ba140000 pid=5306 execve 564f20fa-3207-58e2-934a-15dd5a6774f6 165.245.189.236:80 guuid=b02c21a3-1e00-0000-941b-697162140000 pid=5218->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 149B guuid=2ae2fc07-1f00-0000-941b-697163140000 pid=5219->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 98B guuid=828f4674-1f00-0000-941b-697168140000 pid=5224->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 149B guuid=89930bb0-1f00-0000-941b-697169140000 pid=5225->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70e687ef-1f00-0000-941b-69716d140000 pid=5229 /tmp/Space guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228->guuid=70e687ef-1f00-0000-941b-69716d140000 pid=5229 clone guuid=7c6b551b-2100-0000-941b-697170140000 pid=5232 /tmp/Space guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228->guuid=7c6b551b-2100-0000-941b-697170140000 pid=5232 clone guuid=d0405b1b-2100-0000-941b-697171140000 pid=5233 /tmp/Space net send-data zombie guuid=333e12ef-1f00-0000-941b-69716c140000 pid=5228->guuid=d0405b1b-2100-0000-941b-697171140000 pid=5233 clone guuid=66ab8eef-1f00-0000-941b-69716e140000 pid=5230 /tmp/Space guuid=70e687ef-1f00-0000-941b-69716d140000 pid=5229->guuid=66ab8eef-1f00-0000-941b-69716e140000 pid=5230 clone guuid=7afc92ef-1f00-0000-941b-69716f140000 pid=5231 /tmp/Space net send-data zombie guuid=70e687ef-1f00-0000-941b-69716d140000 pid=5229->guuid=7afc92ef-1f00-0000-941b-69716f140000 pid=5231 clone guuid=7afc92ef-1f00-0000-941b-69716f140000 pid=5231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 413a7120-767c-5584-b6d6-f7447bf54005 165.245.189.236:3778 guuid=7afc92ef-1f00-0000-941b-69716f140000 pid=5231->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=d0405b1b-2100-0000-941b-697171140000 pid=5233->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d0405b1b-2100-0000-941b-697171140000 pid=5233->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=dd93741b-2100-0000-941b-697172140000 pid=5234->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 152B guuid=160e7857-2100-0000-941b-697173140000 pid=5235->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 101B guuid=a0701694-2100-0000-941b-697176140000 pid=5238->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=df389094-2100-0000-941b-697177140000 pid=5239 /tmp/Space guuid=a0701694-2100-0000-941b-697176140000 pid=5238->guuid=df389094-2100-0000-941b-697177140000 pid=5239 clone guuid=3f7541c0-2200-0000-941b-69717a140000 pid=5242 /tmp/Space guuid=a0701694-2100-0000-941b-697176140000 pid=5238->guuid=3f7541c0-2200-0000-941b-69717a140000 pid=5242 clone guuid=18cc45c0-2200-0000-941b-69717b140000 pid=5243 /tmp/Space net send-data zombie guuid=a0701694-2100-0000-941b-697176140000 pid=5238->guuid=18cc45c0-2200-0000-941b-69717b140000 pid=5243 clone guuid=4c3c9c94-2100-0000-941b-697178140000 pid=5240 /tmp/Space guuid=df389094-2100-0000-941b-697177140000 pid=5239->guuid=4c3c9c94-2100-0000-941b-697178140000 pid=5240 clone guuid=bc47a594-2100-0000-941b-697179140000 pid=5241 /tmp/Space net send-data zombie guuid=df389094-2100-0000-941b-697177140000 pid=5239->guuid=bc47a594-2100-0000-941b-697179140000 pid=5241 clone guuid=bc47a594-2100-0000-941b-697179140000 pid=5241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc47a594-2100-0000-941b-697179140000 pid=5241->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=18cc45c0-2200-0000-941b-69717b140000 pid=5243->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18cc45c0-2200-0000-941b-69717b140000 pid=5243->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=a8345ac0-2200-0000-941b-69717c140000 pid=5244->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 150B guuid=843c54fe-2200-0000-941b-69717d140000 pid=5245->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 99B guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=854cca3b-2300-0000-941b-697181140000 pid=5249 /tmp/Space guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248->guuid=854cca3b-2300-0000-941b-697181140000 pid=5249 clone guuid=37ce9767-2400-0000-941b-697184140000 pid=5252 /tmp/Space guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248->guuid=37ce9767-2400-0000-941b-697184140000 pid=5252 clone guuid=7edda267-2400-0000-941b-697185140000 pid=5253 /tmp/Space net send-data zombie guuid=a2d9443b-2300-0000-941b-697180140000 pid=5248->guuid=7edda267-2400-0000-941b-697185140000 pid=5253 clone guuid=b3e8d63b-2300-0000-941b-697182140000 pid=5250 /tmp/Space guuid=854cca3b-2300-0000-941b-697181140000 pid=5249->guuid=b3e8d63b-2300-0000-941b-697182140000 pid=5250 clone guuid=804be03b-2300-0000-941b-697183140000 pid=5251 /tmp/Space net send-data zombie guuid=854cca3b-2300-0000-941b-697181140000 pid=5249->guuid=804be03b-2300-0000-941b-697183140000 pid=5251 clone guuid=804be03b-2300-0000-941b-697183140000 pid=5251->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=804be03b-2300-0000-941b-697183140000 pid=5251->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=7edda267-2400-0000-941b-697185140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7edda267-2400-0000-941b-697185140000 pid=5253->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=f485b967-2400-0000-941b-697186140000 pid=5254->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 150B guuid=425eb0a1-2400-0000-941b-697187140000 pid=5255->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 99B guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c34d9bdf-2400-0000-941b-69718b140000 pid=5259 /tmp/Space guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258->guuid=c34d9bdf-2400-0000-941b-69718b140000 pid=5259 clone guuid=3a00b90c-2600-0000-941b-69718e140000 pid=5262 /tmp/Space guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258->guuid=3a00b90c-2600-0000-941b-69718e140000 pid=5262 clone guuid=231ac30c-2600-0000-941b-69718f140000 pid=5263 /tmp/Space net send-data zombie guuid=7bbaa3de-2400-0000-941b-69718a140000 pid=5258->guuid=231ac30c-2600-0000-941b-69718f140000 pid=5263 clone guuid=cfd1a8df-2400-0000-941b-69718c140000 pid=5260 /tmp/Space guuid=c34d9bdf-2400-0000-941b-69718b140000 pid=5259->guuid=cfd1a8df-2400-0000-941b-69718c140000 pid=5260 clone guuid=0ebdbddf-2400-0000-941b-69718d140000 pid=5261 /tmp/Space net send-data zombie guuid=c34d9bdf-2400-0000-941b-69718b140000 pid=5259->guuid=0ebdbddf-2400-0000-941b-69718d140000 pid=5261 clone guuid=0ebdbddf-2400-0000-941b-69718d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0ebdbddf-2400-0000-941b-69718d140000 pid=5261->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=231ac30c-2600-0000-941b-69718f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=231ac30c-2600-0000-941b-69718f140000 pid=5263->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=dc32f00c-2600-0000-941b-697190140000 pid=5264->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 152B guuid=2052f836-2600-0000-941b-697191140000 pid=5265->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 101B guuid=34ecb762-2600-0000-941b-697194140000 pid=5268->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=57aba963-2600-0000-941b-697195140000 pid=5269 /tmp/Space guuid=34ecb762-2600-0000-941b-697194140000 pid=5268->guuid=57aba963-2600-0000-941b-697195140000 pid=5269 clone guuid=92c01c90-2700-0000-941b-697198140000 pid=5272 /tmp/Space guuid=34ecb762-2600-0000-941b-697194140000 pid=5268->guuid=92c01c90-2700-0000-941b-697198140000 pid=5272 clone guuid=63762390-2700-0000-941b-697199140000 pid=5273 /tmp/Space net send-data zombie guuid=34ecb762-2600-0000-941b-697194140000 pid=5268->guuid=63762390-2700-0000-941b-697199140000 pid=5273 clone guuid=e1f0b463-2600-0000-941b-697196140000 pid=5270 /tmp/Space guuid=57aba963-2600-0000-941b-697195140000 pid=5269->guuid=e1f0b463-2600-0000-941b-697196140000 pid=5270 clone guuid=c73dba63-2600-0000-941b-697197140000 pid=5271 /tmp/Space net send-data zombie guuid=57aba963-2600-0000-941b-697195140000 pid=5269->guuid=c73dba63-2600-0000-941b-697197140000 pid=5271 clone guuid=c73dba63-2600-0000-941b-697197140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c73dba63-2600-0000-941b-697197140000 pid=5271->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=63762390-2700-0000-941b-697199140000 pid=5273->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=63762390-2700-0000-941b-697199140000 pid=5273->413a7120-767c-5584-b6d6-f7447bf54005 send: 17B guuid=28e33390-2700-0000-941b-69719a140000 pid=5274->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 150B guuid=3cd4f8cb-2700-0000-941b-69719b140000 pid=5275->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 99B guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7d2f1a0d-2800-0000-941b-69719f140000 pid=5279 /tmp/Space guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278->guuid=7d2f1a0d-2800-0000-941b-69719f140000 pid=5279 clone guuid=e57cda38-2900-0000-941b-6971a2140000 pid=5282 /tmp/Space guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278->guuid=e57cda38-2900-0000-941b-6971a2140000 pid=5282 clone guuid=2f91e038-2900-0000-941b-6971a3140000 pid=5283 /tmp/Space net send-data zombie guuid=5e17a90c-2800-0000-941b-69719e140000 pid=5278->guuid=2f91e038-2900-0000-941b-6971a3140000 pid=5283 clone guuid=017e220d-2800-0000-941b-6971a0140000 pid=5280 /tmp/Space guuid=7d2f1a0d-2800-0000-941b-69719f140000 pid=5279->guuid=017e220d-2800-0000-941b-6971a0140000 pid=5280 clone guuid=2d49270d-2800-0000-941b-6971a1140000 pid=5281 /tmp/Space net send-data zombie guuid=7d2f1a0d-2800-0000-941b-69719f140000 pid=5279->guuid=2d49270d-2800-0000-941b-6971a1140000 pid=5281 clone guuid=2d49270d-2800-0000-941b-6971a1140000 pid=5281->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d49270d-2800-0000-941b-6971a1140000 pid=5281->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=2f91e038-2900-0000-941b-6971a3140000 pid=5283->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f91e038-2900-0000-941b-6971a3140000 pid=5283->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=8b25f438-2900-0000-941b-6971a4140000 pid=5284->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 149B guuid=4d82f673-2900-0000-941b-6971a5140000 pid=5285->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 98B guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3c28cbb4-2900-0000-941b-6971a9140000 pid=5289 /tmp/Space guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288->guuid=3c28cbb4-2900-0000-941b-6971a9140000 pid=5289 clone guuid=d927ebe0-2a00-0000-941b-6971ac140000 pid=5292 /tmp/Space guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288->guuid=d927ebe0-2a00-0000-941b-6971ac140000 pid=5292 clone guuid=06a2f3e0-2a00-0000-941b-6971ad140000 pid=5293 /tmp/Space net send-data zombie guuid=33ac28b4-2900-0000-941b-6971a8140000 pid=5288->guuid=06a2f3e0-2a00-0000-941b-6971ad140000 pid=5293 clone guuid=039bd2b4-2900-0000-941b-6971aa140000 pid=5290 /tmp/Space guuid=3c28cbb4-2900-0000-941b-6971a9140000 pid=5289->guuid=039bd2b4-2900-0000-941b-6971aa140000 pid=5290 clone guuid=5981d8b4-2900-0000-941b-6971ab140000 pid=5291 /tmp/Space net send-data zombie guuid=3c28cbb4-2900-0000-941b-6971a9140000 pid=5289->guuid=5981d8b4-2900-0000-941b-6971ab140000 pid=5291 clone guuid=5981d8b4-2900-0000-941b-6971ab140000 pid=5291->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5981d8b4-2900-0000-941b-6971ab140000 pid=5291->413a7120-767c-5584-b6d6-f7447bf54005 send: 7B guuid=06a2f3e0-2a00-0000-941b-6971ad140000 pid=5293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06a2f3e0-2a00-0000-941b-6971ad140000 pid=5293->413a7120-767c-5584-b6d6-f7447bf54005 send: 5B guuid=5c9506e1-2a00-0000-941b-6971ae140000 pid=5294->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 150B guuid=7656631d-2b00-0000-941b-6971af140000 pid=5295->564f20fa-3207-58e2-934a-15dd5a6774f6 send: 99B guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=66d6ae5a-2b00-0000-941b-6971b3140000 pid=5299 /tmp/Space guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298->guuid=66d6ae5a-2b00-0000-941b-6971b3140000 pid=5299 clone guuid=829c5d87-2c00-0000-941b-6971b8140000 pid=5304 /tmp/Space guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298->guuid=829c5d87-2c00-0000-941b-6971b8140000 pid=5304 clone guuid=566a6587-2c00-0000-941b-6971b9140000 pid=5305 /tmp/Space net send-data zombie guuid=5429b359-2b00-0000-941b-6971b2140000 pid=5298->guuid=566a6587-2c00-0000-941b-6971b9140000 pid=5305 clone guuid=55f0b95a-2b00-0000-941b-6971b4140000 pid=5300 /tmp/Space guuid=66d6ae5a-2b00-0000-941b-6971b3140000 pid=5299->guuid=55f0b95a-2b00-0000-941b-6971b4140000 pid=5300 clone guuid=da53be5a-2b00-0000-941b-6971b5140000 pid=5301 /tmp/Space net send-data zombie guuid=66d6ae5a-2b00-0000-941b-6971b3140000 pid=5299->guuid=da53be5a-2b00-0000-941b-6971b5140000 pid=5301 clone guuid=da53be5a-2b00-0000-941b-6971b5140000 pid=5301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=da53be5a-2b00-0000-941b-6971b5140000 pid=5301->413a7120-767c-5584-b6d6-f7447bf54005 send: 5B guuid=566a6587-2c00-0000-941b-6971b9140000 pid=5305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=566a6587-2c00-0000-941b-6971b9140000 pid=5305->413a7120-767c-5584-b6d6-f7447bf54005 send: 5B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-24 02:52:46 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f46ad85e9a087360cff3bdf4eebfae0f7f0d86e1497115f4e8a97b3105eff338

(this sample)

  
Delivery method
Distributed via web download

Comments