MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fbda1d301783e63db44bf57e3aa238f60c742d6c19d68d60ee224190236460c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: fbda1d301783e63db44bf57e3aa238f60c742d6c19d68d60ee224190236460c2
SHA3-384 hash: db8b5c3e1b01988410719368d0c9687606ac9c7937effaa88b8fadd209568f8510281bae80e8edb9c04cb97171d79840
SHA1 hash: 43886c0e47c7738a5c1ef6c0c3b2d888802ea41b
MD5 hash: a0326cefe12ada466e7738704eb282f0
humanhash: fifteen-carpet-bulldog-wisconsin
File name:nad.sh
Download: download sample
Signature Mirai
File size:1'649 bytes
First seen:2026-02-13 23:50:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 24:olstMHNWNNIuiqMGhGRaiGiZ8MrNgBN0NLi/CLWzN:olstMtqrw32r8OCLWzN
TLSH T16831B5C91001D309D6DAEBA4A3BED488E13AF9932DC8EF5BDDC44E79C88C954703DA45
Magika batch
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.59/amsx8661471eb021b09432e7ee034a8d826ebfd80bec4ea59752418ab1601162db8da3 Miraielf geofenced mirai ua-wget USA x86
http://143.20.185.59/amsx86_64n/an/aelf ua-wget
http://143.20.185.59/amsarm70c3ef2e2be3d68fae28e25f2ed7673cb30192f707f21fe9f4307769c06e3c6ac Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.59/amsarm66904fe055ecbc779432c226c2828bfe3d25cb77f08600a0a0304015bf20bbc8d Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.59/amsarm5c5ae1522bd4681f32b6640e6525212457b0a237d7167a4da32a8f7a7075334e1 Miraiarm elf geofenced mirai ua-wget USA
http://143.20.185.59/amsarm4n/an/aelf ua-wget
http://143.20.185.59/amsmips7a34277edccea9192113ec46e4ea7d1fd6029188ca56dae949c507ef9e87f42a Miraielf geofenced mips mirai ua-wget USA
http://143.20.185.59/amsmipseln/an/aelf ua-wget
http://143.20.185.59/amssh4e00581db1cde61344ba2869f4950e7fe6033e073f48c62196460dfddcfb19ed2 Miraielf geofenced mirai SuperH ua-wget USA
http://143.20.185.59/amsmpslee15042dec79e36d12cd57489a7ba7f09f752a39343a2c0b35ba877e7cc607d5 Miraielf geofenced mips mirai ua-wget USA
http://143.20.185.59/amsppce162749e3528890e32050b8288aeb5a6a79f1aeb8a29de37cee6113bc405706d Miraielf geofenced mirai PowerPC ua-wget USA
http://143.20.185.59/amsm68kf1096f20630e8882267d6348830e24f48ace2fcf79376c3ba8d8d5cea3642020 Miraielf geofenced m68k mirai ua-wget USA
http://143.20.185.59/amsi686n/an/aelf ua-wget
http://143.20.185.59/amsspc24f683925e0f90507855e4d4a141466eaff0b142488f406e7ad9e329588a266c Miraielf geofenced mirai sparc ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=17a663bd-1700-0000-6152-70902b0c0000 pid=3115 /usr/bin/sudo guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124 /tmp/sample.bin guuid=17a663bd-1700-0000-6152-70902b0c0000 pid=3115->guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124 execve guuid=ebccc7bf-1700-0000-6152-7090360c0000 pid=3126 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=ebccc7bf-1700-0000-6152-7090360c0000 pid=3126 execve guuid=6c98d2c9-1700-0000-6152-7090520c0000 pid=3154 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=6c98d2c9-1700-0000-6152-7090520c0000 pid=3154 execve guuid=e3ff41db-1700-0000-6152-7090680c0000 pid=3176 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=e3ff41db-1700-0000-6152-7090680c0000 pid=3176 execve guuid=686f98db-1700-0000-6152-7090690c0000 pid=3177 /tmp/amsx86 delete-file net guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=686f98db-1700-0000-6152-7090690c0000 pid=3177 execve guuid=d1eef6db-1700-0000-6152-70906b0c0000 pid=3179 /usr/bin/wget net send-data guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=d1eef6db-1700-0000-6152-70906b0c0000 pid=3179 execve guuid=84b6fde1-1700-0000-6152-70906e0c0000 pid=3182 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=84b6fde1-1700-0000-6152-70906e0c0000 pid=3182 execve guuid=879f43ee-1700-0000-6152-70906f0c0000 pid=3183 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=879f43ee-1700-0000-6152-70906f0c0000 pid=3183 execve guuid=f997c3ee-1700-0000-6152-7090700c0000 pid=3184 /tmp/amsx86_64 guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=f997c3ee-1700-0000-6152-7090700c0000 pid=3184 execve guuid=a0443def-1700-0000-6152-7090710c0000 pid=3185 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=a0443def-1700-0000-6152-7090710c0000 pid=3185 execve guuid=3714a900-1800-0000-6152-70908c0c0000 pid=3212 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=3714a900-1800-0000-6152-70908c0c0000 pid=3212 execve guuid=d862930f-1800-0000-6152-7090980c0000 pid=3224 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=d862930f-1800-0000-6152-7090980c0000 pid=3224 execve guuid=3d15e90f-1800-0000-6152-7090990c0000 pid=3225 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=3d15e90f-1800-0000-6152-7090990c0000 pid=3225 clone guuid=67460311-1800-0000-6152-70909b0c0000 pid=3227 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=67460311-1800-0000-6152-70909b0c0000 pid=3227 execve guuid=6a4db31b-1800-0000-6152-70909d0c0000 pid=3229 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=6a4db31b-1800-0000-6152-70909d0c0000 pid=3229 execve guuid=52ee2637-1800-0000-6152-7090b60c0000 pid=3254 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=52ee2637-1800-0000-6152-7090b60c0000 pid=3254 execve guuid=b5668f37-1800-0000-6152-7090b90c0000 pid=3257 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=b5668f37-1800-0000-6152-7090b90c0000 pid=3257 clone guuid=f59f2738-1800-0000-6152-7090bc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=f59f2738-1800-0000-6152-7090bc0c0000 pid=3260 execve guuid=c452c840-1800-0000-6152-7090cb0c0000 pid=3275 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=c452c840-1800-0000-6152-7090cb0c0000 pid=3275 execve guuid=1dd6e94d-1800-0000-6152-7090ed0c0000 pid=3309 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=1dd6e94d-1800-0000-6152-7090ed0c0000 pid=3309 execve guuid=2075274e-1800-0000-6152-7090ee0c0000 pid=3310 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=2075274e-1800-0000-6152-7090ee0c0000 pid=3310 clone guuid=d6d2b54e-1800-0000-6152-7090f20c0000 pid=3314 /usr/bin/wget net send-data guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=d6d2b54e-1800-0000-6152-7090f20c0000 pid=3314 execve guuid=e0ec7f55-1800-0000-6152-7090030d0000 pid=3331 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=e0ec7f55-1800-0000-6152-7090030d0000 pid=3331 execve guuid=483c235f-1800-0000-6152-7090180d0000 pid=3352 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=483c235f-1800-0000-6152-7090180d0000 pid=3352 execve guuid=038d6e5f-1800-0000-6152-7090190d0000 pid=3353 /tmp/amsarm4 guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=038d6e5f-1800-0000-6152-7090190d0000 pid=3353 execve guuid=001ab65f-1800-0000-6152-70901a0d0000 pid=3354 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=001ab65f-1800-0000-6152-70901a0d0000 pid=3354 execve guuid=35734c6b-1800-0000-6152-7090250d0000 pid=3365 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=35734c6b-1800-0000-6152-7090250d0000 pid=3365 execve guuid=709eae79-1800-0000-6152-70904a0d0000 pid=3402 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=709eae79-1800-0000-6152-70904a0d0000 pid=3402 execve guuid=f9d5177a-1800-0000-6152-70904c0d0000 pid=3404 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=f9d5177a-1800-0000-6152-70904c0d0000 pid=3404 clone guuid=9299e47a-1800-0000-6152-7090500d0000 pid=3408 /usr/bin/wget net send-data guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=9299e47a-1800-0000-6152-7090500d0000 pid=3408 execve guuid=ce25d681-1800-0000-6152-70905e0d0000 pid=3422 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=ce25d681-1800-0000-6152-70905e0d0000 pid=3422 execve guuid=a4d6ee88-1800-0000-6152-7090720d0000 pid=3442 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=a4d6ee88-1800-0000-6152-7090720d0000 pid=3442 execve guuid=9a812c89-1800-0000-6152-7090730d0000 pid=3443 /tmp/amsmipsel guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=9a812c89-1800-0000-6152-7090730d0000 pid=3443 execve guuid=c6445c89-1800-0000-6152-7090750d0000 pid=3445 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=c6445c89-1800-0000-6152-7090750d0000 pid=3445 execve guuid=fb5ab994-1800-0000-6152-7090970d0000 pid=3479 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=fb5ab994-1800-0000-6152-7090970d0000 pid=3479 execve guuid=99b72ea1-1800-0000-6152-7090c10d0000 pid=3521 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=99b72ea1-1800-0000-6152-7090c10d0000 pid=3521 execve guuid=6bf386a1-1800-0000-6152-7090c30d0000 pid=3523 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=6bf386a1-1800-0000-6152-7090c30d0000 pid=3523 clone guuid=eb1c53a2-1800-0000-6152-7090ca0d0000 pid=3530 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=eb1c53a2-1800-0000-6152-7090ca0d0000 pid=3530 execve guuid=8c2137ac-1800-0000-6152-7090da0d0000 pid=3546 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=8c2137ac-1800-0000-6152-7090da0d0000 pid=3546 execve guuid=ffe129b7-1800-0000-6152-7090f20d0000 pid=3570 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=ffe129b7-1800-0000-6152-7090f20d0000 pid=3570 execve guuid=ad676bb7-1800-0000-6152-7090f40d0000 pid=3572 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=ad676bb7-1800-0000-6152-7090f40d0000 pid=3572 clone guuid=f7bd33b9-1800-0000-6152-7090f60d0000 pid=3574 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=f7bd33b9-1800-0000-6152-7090f60d0000 pid=3574 execve guuid=1e9441c3-1800-0000-6152-7090180e0000 pid=3608 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=1e9441c3-1800-0000-6152-7090180e0000 pid=3608 execve guuid=ab1c7fcf-1800-0000-6152-70903a0e0000 pid=3642 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=ab1c7fcf-1800-0000-6152-70903a0e0000 pid=3642 execve guuid=088bc1cf-1800-0000-6152-70903c0e0000 pid=3644 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=088bc1cf-1800-0000-6152-70903c0e0000 pid=3644 clone guuid=493039d0-1800-0000-6152-70903f0e0000 pid=3647 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=493039d0-1800-0000-6152-70903f0e0000 pid=3647 execve guuid=f73459db-1800-0000-6152-7090670e0000 pid=3687 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=f73459db-1800-0000-6152-7090670e0000 pid=3687 execve guuid=499be2eb-1800-0000-6152-7090820e0000 pid=3714 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=499be2eb-1800-0000-6152-7090820e0000 pid=3714 execve guuid=43b035ec-1800-0000-6152-7090830e0000 pid=3715 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=43b035ec-1800-0000-6152-7090830e0000 pid=3715 clone guuid=5ec3e4ec-1800-0000-6152-7090850e0000 pid=3717 /usr/bin/wget net send-data guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=5ec3e4ec-1800-0000-6152-7090850e0000 pid=3717 execve guuid=bf2007f3-1800-0000-6152-7090920e0000 pid=3730 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=bf2007f3-1800-0000-6152-7090920e0000 pid=3730 execve guuid=871c15fd-1800-0000-6152-7090b00e0000 pid=3760 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=871c15fd-1800-0000-6152-7090b00e0000 pid=3760 execve guuid=9faf5cfd-1800-0000-6152-7090b20e0000 pid=3762 /tmp/amsi686 guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=9faf5cfd-1800-0000-6152-7090b20e0000 pid=3762 execve guuid=e0888bfd-1800-0000-6152-7090b50e0000 pid=3765 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=e0888bfd-1800-0000-6152-7090b50e0000 pid=3765 execve guuid=143ebc08-1900-0000-6152-7090e70e0000 pid=3815 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=143ebc08-1900-0000-6152-7090e70e0000 pid=3815 execve guuid=611b171b-1900-0000-6152-7090270f0000 pid=3879 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=611b171b-1900-0000-6152-7090270f0000 pid=3879 execve guuid=e2a1711b-1900-0000-6152-7090280f0000 pid=3880 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=e2a1711b-1900-0000-6152-7090280f0000 pid=3880 clone guuid=595e521c-1900-0000-6152-70902a0f0000 pid=3882 /usr/bin/wget net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=595e521c-1900-0000-6152-70902a0f0000 pid=3882 execve guuid=cdb3b324-1900-0000-6152-7090440f0000 pid=3908 /usr/bin/curl net send-data write-file guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=cdb3b324-1900-0000-6152-7090440f0000 pid=3908 execve guuid=5f58942e-1900-0000-6152-70906b0f0000 pid=3947 /usr/bin/chmod guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=5f58942e-1900-0000-6152-70906b0f0000 pid=3947 execve guuid=8d870e2f-1900-0000-6152-70906e0f0000 pid=3950 /usr/bin/dash guuid=5e7996bf-1700-0000-6152-7090340c0000 pid=3124->guuid=8d870e2f-1900-0000-6152-70906e0f0000 pid=3950 clone ac1c563b-d6e8-5834-ba74-c2dfdc889f96 143.20.185.59:80 guuid=ebccc7bf-1700-0000-6152-7090360c0000 pid=3126->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 134B guuid=6c98d2c9-1700-0000-6152-7090520c0000 pid=3154->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 83B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=686f98db-1700-0000-6152-7090690c0000 pid=3177->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178 /tmp/amsx86 net send-data zombie guuid=686f98db-1700-0000-6152-7090690c0000 pid=3177->guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178 clone guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 79cb4005-295a-567e-8cbb-dea3f41775e0 143.20.185.59:15154 guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178->79cb4005-295a-567e-8cbb-dea3f41775e0 send: 11B guuid=ec0605dc-1700-0000-6152-70906c0c0000 pid=3180 /tmp/amsx86 guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178->guuid=ec0605dc-1700-0000-6152-70906c0c0000 pid=3180 clone guuid=289508dc-1700-0000-6152-70906d0c0000 pid=3181 /tmp/amsx86 guuid=2f67eedb-1700-0000-6152-70906a0c0000 pid=3178->guuid=289508dc-1700-0000-6152-70906d0c0000 pid=3181 clone guuid=d1eef6db-1700-0000-6152-70906b0c0000 pid=3179->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 137B guuid=84b6fde1-1700-0000-6152-70906e0c0000 pid=3182->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 86B guuid=a0443def-1700-0000-6152-7090710c0000 pid=3185->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=3714a900-1800-0000-6152-70908c0c0000 pid=3212->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=67460311-1800-0000-6152-70909b0c0000 pid=3227->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=6a4db31b-1800-0000-6152-70909d0c0000 pid=3229->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=f59f2738-1800-0000-6152-7090bc0c0000 pid=3260->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=c452c840-1800-0000-6152-7090cb0c0000 pid=3275->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=d6d2b54e-1800-0000-6152-7090f20c0000 pid=3314->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=e0ec7f55-1800-0000-6152-7090030d0000 pid=3331->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=001ab65f-1800-0000-6152-70901a0d0000 pid=3354->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=35734c6b-1800-0000-6152-7090250d0000 pid=3365->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=9299e47a-1800-0000-6152-7090500d0000 pid=3408->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 137B guuid=ce25d681-1800-0000-6152-70905e0d0000 pid=3422->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 86B guuid=c6445c89-1800-0000-6152-7090750d0000 pid=3445->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 134B guuid=fb5ab994-1800-0000-6152-7090970d0000 pid=3479->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 83B guuid=eb1c53a2-1800-0000-6152-7090ca0d0000 pid=3530->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=8c2137ac-1800-0000-6152-7090da0d0000 pid=3546->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=f7bd33b9-1800-0000-6152-7090f60d0000 pid=3574->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 134B guuid=1e9441c3-1800-0000-6152-7090180e0000 pid=3608->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 83B guuid=493039d0-1800-0000-6152-70903f0e0000 pid=3647->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=f73459db-1800-0000-6152-7090670e0000 pid=3687->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=5ec3e4ec-1800-0000-6152-7090850e0000 pid=3717->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=bf2007f3-1800-0000-6152-7090920e0000 pid=3730->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B guuid=e0888bfd-1800-0000-6152-7090b50e0000 pid=3765->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 134B guuid=143ebc08-1900-0000-6152-7090e70e0000 pid=3815->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 83B guuid=595e521c-1900-0000-6152-70902a0f0000 pid=3882->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 135B guuid=cdb3b324-1900-0000-6152-7090440f0000 pid=3908->ac1c563b-d6e8-5834-ba74-c2dfdc889f96 send: 84B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-13 23:51:22 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fbda1d301783e63db44bf57e3aa238f60c742d6c19d68d60ee224190236460c2

(this sample)

  
Delivery method
Distributed via web download

Comments