MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fd8e86a5e62931b7279df7adf26c5f5457a548cf87ca315a7fdb3bb8862c0d04. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: fd8e86a5e62931b7279df7adf26c5f5457a548cf87ca315a7fdb3bb8862c0d04
SHA3-384 hash: 6918eae0bb1a89a9802412f1adf3bd6ccdd59dcef417da2bf01a1fee9e2190dfe122c2db2261a8fbd5c407c5da09bedc
SHA1 hash: f67cc417dbebd44ce37c6a4978a089c4de3fa240
MD5 hash: 3bc21980fb369ba29c9527f0b056dbcf
humanhash: bluebird-lake-georgia-mars
File name:newreaxe.sh
Download: download sample
Signature Mirai
File size:3'169 bytes
First seen:2026-01-30 17:31:42 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:i+/RgQiGC+ukrVYhpuwLyJCuUqVTc36VL:iqiGCiYuwLICIc3AL
TLSH T16051A5F6A3D247305EA95637A3789904BC45E1E3B1862E649CFB29FEF84CE047005E97
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=4b77822a-1600-0000-fb15-41e40b0d0000 pid=3339 /usr/bin/sudo guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345 /tmp/sample.bin guuid=4b77822a-1600-0000-fb15-41e40b0d0000 pid=3339->guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345 execve guuid=71bbae2c-1600-0000-fb15-41e4130d0000 pid=3347 /usr/bin/cp guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=71bbae2c-1600-0000-fb15-41e4130d0000 pid=3347 execve guuid=6a84d731-1600-0000-fb15-41e4200d0000 pid=3360 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=6a84d731-1600-0000-fb15-41e4200d0000 pid=3360 execve guuid=527c5146-1600-0000-fb15-41e4470d0000 pid=3399 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=527c5146-1600-0000-fb15-41e4470d0000 pid=3399 execve guuid=8812095e-1600-0000-fb15-41e4860d0000 pid=3462 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=8812095e-1600-0000-fb15-41e4860d0000 pid=3462 execve guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464 /tmp/m9x7k2v8b3.x86 net guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464 execve guuid=cee2188c-1700-0000-fb15-41e4fa0f0000 pid=4090 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=cee2188c-1700-0000-fb15-41e4fa0f0000 pid=4090 execve guuid=57589e8c-1700-0000-fb15-41e4fc0f0000 pid=4092 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=57589e8c-1700-0000-fb15-41e4fc0f0000 pid=4092 execve guuid=93cc99a5-1700-0000-fb15-41e441100000 pid=4161 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=93cc99a5-1700-0000-fb15-41e441100000 pid=4161 execve guuid=b3ad93c1-1700-0000-fb15-41e4a8100000 pid=4264 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=b3ad93c1-1700-0000-fb15-41e4a8100000 pid=4264 execve guuid=4ef016c2-1700-0000-fb15-41e4aa100000 pid=4266 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=4ef016c2-1700-0000-fb15-41e4aa100000 pid=4266 clone guuid=df9f25c3-1700-0000-fb15-41e4ae100000 pid=4270 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=df9f25c3-1700-0000-fb15-41e4ae100000 pid=4270 execve guuid=57510dc4-1700-0000-fb15-41e4b2100000 pid=4274 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=57510dc4-1700-0000-fb15-41e4b2100000 pid=4274 execve guuid=d3b9c1e2-1700-0000-fb15-41e404110000 pid=4356 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=d3b9c1e2-1700-0000-fb15-41e404110000 pid=4356 execve guuid=352ca904-1800-0000-fb15-41e460110000 pid=4448 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=352ca904-1800-0000-fb15-41e460110000 pid=4448 execve guuid=af784f05-1800-0000-fb15-41e461110000 pid=4449 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=af784f05-1800-0000-fb15-41e461110000 pid=4449 clone guuid=3372af06-1800-0000-fb15-41e465110000 pid=4453 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=3372af06-1800-0000-fb15-41e465110000 pid=4453 execve guuid=79fa5407-1800-0000-fb15-41e469110000 pid=4457 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=79fa5407-1800-0000-fb15-41e469110000 pid=4457 execve guuid=b24f2c1a-1800-0000-fb15-41e497110000 pid=4503 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=b24f2c1a-1800-0000-fb15-41e497110000 pid=4503 execve guuid=15811f30-1800-0000-fb15-41e4cf110000 pid=4559 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=15811f30-1800-0000-fb15-41e4cf110000 pid=4559 execve guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560 /tmp/m9x7k2v8b3.i686 net guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560 execve guuid=a93c425e-1900-0000-fb15-41e469140000 pid=5225 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=a93c425e-1900-0000-fb15-41e469140000 pid=5225 execve guuid=792ecf5e-1900-0000-fb15-41e46f140000 pid=5231 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=792ecf5e-1900-0000-fb15-41e46f140000 pid=5231 execve guuid=0659f071-1900-0000-fb15-41e476140000 pid=5238 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0659f071-1900-0000-fb15-41e476140000 pid=5238 execve guuid=1009d988-1900-0000-fb15-41e47c140000 pid=5244 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=1009d988-1900-0000-fb15-41e47c140000 pid=5244 execve guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245 /tmp/m9x7k2v8b3.x86_64 mprotect-exec net guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245 execve guuid=1fa1afb4-1a00-0000-fb15-41e490140000 pid=5264 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=1fa1afb4-1a00-0000-fb15-41e490140000 pid=5264 execve guuid=14c29acb-1a00-0000-fb15-41e491140000 pid=5265 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=14c29acb-1a00-0000-fb15-41e491140000 pid=5265 execve guuid=f9ead8e3-1a00-0000-fb15-41e492140000 pid=5266 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=f9ead8e3-1a00-0000-fb15-41e492140000 pid=5266 execve guuid=b3cbf100-1b00-0000-fb15-41e493140000 pid=5267 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=b3cbf100-1b00-0000-fb15-41e493140000 pid=5267 execve guuid=98413801-1b00-0000-fb15-41e494140000 pid=5268 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=98413801-1b00-0000-fb15-41e494140000 pid=5268 clone guuid=ccf4e401-1b00-0000-fb15-41e496140000 pid=5270 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=ccf4e401-1b00-0000-fb15-41e496140000 pid=5270 execve guuid=fccf2e03-1b00-0000-fb15-41e497140000 pid=5271 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=fccf2e03-1b00-0000-fb15-41e497140000 pid=5271 execve guuid=2274f315-1b00-0000-fb15-41e498140000 pid=5272 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=2274f315-1b00-0000-fb15-41e498140000 pid=5272 execve guuid=d7e4b229-1b00-0000-fb15-41e49a140000 pid=5274 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=d7e4b229-1b00-0000-fb15-41e49a140000 pid=5274 execve guuid=f66dfb29-1b00-0000-fb15-41e49b140000 pid=5275 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=f66dfb29-1b00-0000-fb15-41e49b140000 pid=5275 clone guuid=e888862a-1b00-0000-fb15-41e49d140000 pid=5277 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=e888862a-1b00-0000-fb15-41e49d140000 pid=5277 execve guuid=18c99330-1b00-0000-fb15-41e4a3140000 pid=5283 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=18c99330-1b00-0000-fb15-41e4a3140000 pid=5283 execve guuid=0e7a3143-1b00-0000-fb15-41e4ab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0e7a3143-1b00-0000-fb15-41e4ab140000 pid=5291 execve guuid=81180157-1b00-0000-fb15-41e4ad140000 pid=5293 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=81180157-1b00-0000-fb15-41e4ad140000 pid=5293 execve guuid=0e858757-1b00-0000-fb15-41e4ae140000 pid=5294 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0e858757-1b00-0000-fb15-41e4ae140000 pid=5294 clone guuid=dcbf7459-1b00-0000-fb15-41e4b0140000 pid=5296 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=dcbf7459-1b00-0000-fb15-41e4b0140000 pid=5296 execve guuid=3547075a-1b00-0000-fb15-41e4b1140000 pid=5297 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=3547075a-1b00-0000-fb15-41e4b1140000 pid=5297 execve guuid=59ef6c73-1b00-0000-fb15-41e4b4140000 pid=5300 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=59ef6c73-1b00-0000-fb15-41e4b4140000 pid=5300 execve guuid=bbc7be8c-1b00-0000-fb15-41e4c5140000 pid=5317 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=bbc7be8c-1b00-0000-fb15-41e4c5140000 pid=5317 execve guuid=8e04488d-1b00-0000-fb15-41e4c6140000 pid=5318 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=8e04488d-1b00-0000-fb15-41e4c6140000 pid=5318 clone guuid=54deed8d-1b00-0000-fb15-41e4c8140000 pid=5320 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=54deed8d-1b00-0000-fb15-41e4c8140000 pid=5320 execve guuid=4158778e-1b00-0000-fb15-41e4c9140000 pid=5321 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=4158778e-1b00-0000-fb15-41e4c9140000 pid=5321 execve guuid=f18f87a7-1b00-0000-fb15-41e4ca140000 pid=5322 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=f18f87a7-1b00-0000-fb15-41e4ca140000 pid=5322 execve guuid=53fad2c4-1b00-0000-fb15-41e4cb140000 pid=5323 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=53fad2c4-1b00-0000-fb15-41e4cb140000 pid=5323 execve guuid=9f995dc5-1b00-0000-fb15-41e4cc140000 pid=5324 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=9f995dc5-1b00-0000-fb15-41e4cc140000 pid=5324 clone guuid=c72f86c6-1b00-0000-fb15-41e4ce140000 pid=5326 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=c72f86c6-1b00-0000-fb15-41e4ce140000 pid=5326 execve guuid=a52112c7-1b00-0000-fb15-41e4cf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=a52112c7-1b00-0000-fb15-41e4cf140000 pid=5327 execve guuid=6cae2cdc-1b00-0000-fb15-41e4d0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=6cae2cdc-1b00-0000-fb15-41e4d0140000 pid=5328 execve guuid=46bcd4ee-1b00-0000-fb15-41e4d1140000 pid=5329 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=46bcd4ee-1b00-0000-fb15-41e4d1140000 pid=5329 execve guuid=54cf6bef-1b00-0000-fb15-41e4d2140000 pid=5330 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=54cf6bef-1b00-0000-fb15-41e4d2140000 pid=5330 clone guuid=e6a285f0-1b00-0000-fb15-41e4d4140000 pid=5332 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=e6a285f0-1b00-0000-fb15-41e4d4140000 pid=5332 execve guuid=0bf264f4-1b00-0000-fb15-41e4d5140000 pid=5333 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0bf264f4-1b00-0000-fb15-41e4d5140000 pid=5333 execve guuid=8608ea0d-1c00-0000-fb15-41e4d6140000 pid=5334 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=8608ea0d-1c00-0000-fb15-41e4d6140000 pid=5334 execve guuid=a85ac527-1c00-0000-fb15-41e4d7140000 pid=5335 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=a85ac527-1c00-0000-fb15-41e4d7140000 pid=5335 execve guuid=3a4e5328-1c00-0000-fb15-41e4d8140000 pid=5336 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=3a4e5328-1c00-0000-fb15-41e4d8140000 pid=5336 clone guuid=58968229-1c00-0000-fb15-41e4da140000 pid=5338 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=58968229-1c00-0000-fb15-41e4da140000 pid=5338 execve guuid=e4b5132a-1c00-0000-fb15-41e4db140000 pid=5339 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=e4b5132a-1c00-0000-fb15-41e4db140000 pid=5339 execve guuid=0cc83846-1c00-0000-fb15-41e4dc140000 pid=5340 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0cc83846-1c00-0000-fb15-41e4dc140000 pid=5340 execve guuid=51970761-1c00-0000-fb15-41e4dd140000 pid=5341 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=51970761-1c00-0000-fb15-41e4dd140000 pid=5341 execve guuid=18e99e61-1c00-0000-fb15-41e4de140000 pid=5342 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=18e99e61-1c00-0000-fb15-41e4de140000 pid=5342 clone guuid=0abbbb62-1c00-0000-fb15-41e4e0140000 pid=5344 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=0abbbb62-1c00-0000-fb15-41e4e0140000 pid=5344 execve guuid=e3615863-1c00-0000-fb15-41e4e1140000 pid=5345 /usr/bin/wget net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=e3615863-1c00-0000-fb15-41e4e1140000 pid=5345 execve guuid=2a6e0e7d-1c00-0000-fb15-41e4e2140000 pid=5346 /usr/bin/curl net send-data write-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=2a6e0e7d-1c00-0000-fb15-41e4e2140000 pid=5346 execve guuid=8174a297-1c00-0000-fb15-41e4e3140000 pid=5347 /usr/bin/chmod guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=8174a297-1c00-0000-fb15-41e4e3140000 pid=5347 execve guuid=6a8b3c98-1c00-0000-fb15-41e4e4140000 pid=5348 /usr/bin/bash guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=6a8b3c98-1c00-0000-fb15-41e4e4140000 pid=5348 clone guuid=1a256e99-1c00-0000-fb15-41e4e6140000 pid=5350 /usr/bin/rm delete-file guuid=9c05552c-1600-0000-fb15-41e4110d0000 pid=3345->guuid=1a256e99-1c00-0000-fb15-41e4e6140000 pid=5350 execve 1a25d009-e9f5-535b-9794-133757a79f2f 192.3.154.52:80 guuid=6a84d731-1600-0000-fb15-41e4200d0000 pid=3360->1a25d009-e9f5-535b-9794-133757a79f2f send: 151B guuid=527c5146-1600-0000-fb15-41e4470d0000 pid=3399->1a25d009-e9f5-535b-9794-133757a79f2f send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eadc845f-1600-0000-fb15-41e48b0d0000 pid=3467 /tmp/m9x7k2v8b3.x86 guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464->guuid=eadc845f-1600-0000-fb15-41e48b0d0000 pid=3467 clone guuid=24c5018c-1700-0000-fb15-41e4f80f0000 pid=4088 /tmp/m9x7k2v8b3.x86 guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464->guuid=24c5018c-1700-0000-fb15-41e4f80f0000 pid=4088 clone guuid=13df098c-1700-0000-fb15-41e4f90f0000 pid=4089 /tmp/m9x7k2v8b3.x86 net send-data zombie guuid=8424875e-1600-0000-fb15-41e4880d0000 pid=3464->guuid=13df098c-1700-0000-fb15-41e4f90f0000 pid=4089 clone guuid=b248925f-1600-0000-fb15-41e48c0d0000 pid=3468 /tmp/m9x7k2v8b3.x86 guuid=eadc845f-1600-0000-fb15-41e48b0d0000 pid=3467->guuid=b248925f-1600-0000-fb15-41e48c0d0000 pid=3468 clone guuid=5414975f-1600-0000-fb15-41e48d0d0000 pid=3469 /tmp/m9x7k2v8b3.x86 dns net send-data zombie guuid=eadc845f-1600-0000-fb15-41e48b0d0000 pid=3467->guuid=5414975f-1600-0000-fb15-41e48d0d0000 pid=3469 clone guuid=5414975f-1600-0000-fb15-41e48d0d0000 pid=3469->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B 852eada3-51ac-5275-909a-778490b5e6b0 play.mclighthouse.ir:6742 guuid=5414975f-1600-0000-fb15-41e48d0d0000 pid=3469->852eada3-51ac-5275-909a-778490b5e6b0 send: 17B guuid=13df098c-1700-0000-fb15-41e4f90f0000 pid=4089->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=13df098c-1700-0000-fb15-41e4f90f0000 pid=4089->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B ad785374-9e7c-5217-acbe-83a9cb2f51b9 play.mclighthouse.ir:80 guuid=57589e8c-1700-0000-fb15-41e4fc0f0000 pid=4092->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=93cc99a5-1700-0000-fb15-41e441100000 pid=4161->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=57510dc4-1700-0000-fb15-41e4b2100000 pid=4274->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=d3b9c1e2-1700-0000-fb15-41e404110000 pid=4356->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=79fa5407-1800-0000-fb15-41e469110000 pid=4457->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=b24f2c1a-1800-0000-fb15-41e497110000 pid=4503->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fd7f9831-1800-0000-fb15-41e4d3110000 pid=4563 /tmp/m9x7k2v8b3.i686 guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560->guuid=fd7f9831-1800-0000-fb15-41e4d3110000 pid=4563 clone guuid=628e135e-1900-0000-fb15-41e467140000 pid=5223 /tmp/m9x7k2v8b3.i686 guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560->guuid=628e135e-1900-0000-fb15-41e467140000 pid=5223 clone guuid=d8601b5e-1900-0000-fb15-41e468140000 pid=5224 /tmp/m9x7k2v8b3.i686 net send-data zombie guuid=67c7a330-1800-0000-fb15-41e4d0110000 pid=4560->guuid=d8601b5e-1900-0000-fb15-41e468140000 pid=5224 clone guuid=74aaa331-1800-0000-fb15-41e4d4110000 pid=4564 /tmp/m9x7k2v8b3.i686 guuid=fd7f9831-1800-0000-fb15-41e4d3110000 pid=4563->guuid=74aaa331-1800-0000-fb15-41e4d4110000 pid=4564 clone guuid=c166ac31-1800-0000-fb15-41e4d5110000 pid=4565 /tmp/m9x7k2v8b3.i686 dns net send-data zombie guuid=fd7f9831-1800-0000-fb15-41e4d3110000 pid=4563->guuid=c166ac31-1800-0000-fb15-41e4d5110000 pid=4565 clone guuid=c166ac31-1800-0000-fb15-41e4d5110000 pid=4565->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=c166ac31-1800-0000-fb15-41e4d5110000 pid=4565->852eada3-51ac-5275-909a-778490b5e6b0 send: 17B guuid=d8601b5e-1900-0000-fb15-41e468140000 pid=5224->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B guuid=d8601b5e-1900-0000-fb15-41e468140000 pid=5224->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=792ecf5e-1900-0000-fb15-41e46f140000 pid=5231->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 154B guuid=0659f071-1900-0000-fb15-41e476140000 pid=5238->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 103B guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=109b048a-1900-0000-fb15-41e47e140000 pid=5246 /tmp/m9x7k2v8b3.x86_64 guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245->guuid=109b048a-1900-0000-fb15-41e47e140000 pid=5246 clone guuid=6e6e93b4-1a00-0000-fb15-41e48e140000 pid=5262 /tmp/m9x7k2v8b3.x86_64 guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245->guuid=6e6e93b4-1a00-0000-fb15-41e48e140000 pid=5262 clone guuid=f3009eb4-1a00-0000-fb15-41e48f140000 pid=5263 /tmp/m9x7k2v8b3.x86_64 net send-data zombie guuid=87296589-1900-0000-fb15-41e47d140000 pid=5245->guuid=f3009eb4-1a00-0000-fb15-41e48f140000 pid=5263 clone guuid=3b260b8a-1900-0000-fb15-41e480140000 pid=5248 /tmp/m9x7k2v8b3.x86_64 guuid=109b048a-1900-0000-fb15-41e47e140000 pid=5246->guuid=3b260b8a-1900-0000-fb15-41e480140000 pid=5248 clone guuid=afd40e8a-1900-0000-fb15-41e481140000 pid=5249 /tmp/m9x7k2v8b3.x86_64 net send-data zombie guuid=109b048a-1900-0000-fb15-41e47e140000 pid=5246->guuid=afd40e8a-1900-0000-fb15-41e481140000 pid=5249 clone guuid=afd40e8a-1900-0000-fb15-41e481140000 pid=5249->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 975B guuid=afd40e8a-1900-0000-fb15-41e481140000 pid=5249->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=f3009eb4-1a00-0000-fb15-41e48f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 780B guuid=f3009eb4-1a00-0000-fb15-41e48f140000 pid=5263->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=14c29acb-1a00-0000-fb15-41e491140000 pid=5265->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=f9ead8e3-1a00-0000-fb15-41e492140000 pid=5266->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=fccf2e03-1b00-0000-fb15-41e497140000 pid=5271->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=2274f315-1b00-0000-fb15-41e498140000 pid=5272->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=18c99330-1b00-0000-fb15-41e4a3140000 pid=5283->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=0e7a3143-1b00-0000-fb15-41e4ab140000 pid=5291->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=3547075a-1b00-0000-fb15-41e4b1140000 pid=5297->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=59ef6c73-1b00-0000-fb15-41e4b4140000 pid=5300->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=4158778e-1b00-0000-fb15-41e4c9140000 pid=5321->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=f18f87a7-1b00-0000-fb15-41e4ca140000 pid=5322->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=a52112c7-1b00-0000-fb15-41e4cf140000 pid=5327->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=6cae2cdc-1b00-0000-fb15-41e4d0140000 pid=5328->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=0bf264f4-1b00-0000-fb15-41e4d5140000 pid=5333->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=8608ea0d-1c00-0000-fb15-41e4d6140000 pid=5334->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B guuid=e4b5132a-1c00-0000-fb15-41e4db140000 pid=5339->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 152B guuid=0cc83846-1c00-0000-fb15-41e4dc140000 pid=5340->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 101B guuid=e3615863-1c00-0000-fb15-41e4e1140000 pid=5345->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 151B guuid=2a6e0e7d-1c00-0000-fb15-41e4e2140000 pid=5346->ad785374-9e7c-5217-acbe-83a9cb2f51b9 send: 100B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-30 17:32:37 UTC
File Type:
Text (Shell)
AV detection:
20 of 36 (55.56%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh fd8e86a5e62931b7279df7adf26c5f5457a548cf87ca315a7fdb3bb8862c0d04

(this sample)

  
Delivery method
Distributed via web download

Comments