MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1021124ad2a144ca265da5ab016a35ef68515a9509b4da1df284d27f3e8181a5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 1021124ad2a144ca265da5ab016a35ef68515a9509b4da1df284d27f3e8181a5
SHA3-384 hash: 4a9ab443022323e8c31a762375400c9318f88bf486bc8191576b5e8e5391b482661efc228de2b51f9a31fdc12a3a5a96
SHA1 hash: ec43efd5227b97b25c0f20c3171f6a7c203aa698
MD5 hash: 0b49cb897a47c8435029342c529d1bfc
humanhash: mountain-shade-mirror-equal
File name:1.sh
Download: download sample
Signature Mirai
File size:2'142 bytes
First seen:2025-08-22 19:52:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ITRQ2n7O9utiH3AqoJxZNIV6uWL7KGJguHF4:gZ0387/Jt+
TLSH T1B7418BFF5382E913847FCFDB3A66D59C9009C09FD6CE4FB9449A88394488E0C7456E5A
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.24/bins/morte.x868ed8684e37fed57d6a517549a3c33a47c965bd2c1b749477065300cd3befb8a8 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mips1bf649de3be52962fc4aae70aea0274646316556a3dd0bad8571ffa8bdf0d05a Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arc98833f42ea4e04673d56891cc2bc7af3e7f4def2c113bfeaefebd62dc9cbf4d1 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.i468n/an/aelf ua-wget
http://196.251.73.24/bins/morte.i6869f95429199df814af4b249582f306e331931a5b1589cc0253a3fe1cf00729a32 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.x86_64dc42dab20737c30846d8cd5245c92f7a2de2a99dee368e0e1b722171575f9b70 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mpslb05eb83d4502f8d974ff67d2e6e39eab2854f903990a30e216fee23eb96cf0f4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.armfd66075653adb6af129688520f493763553558fe461dde1e1e6b7f37cc9a7f67 Miraicensys elf mirai opendir ua-wget
http://196.251.73.24/bins/morte.arm5316f2dbc5ce4d44982adf97aa64de4669a0050862b5d42b31d23c32e5c22c743 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm6d8c6a66e47b848a317a4a40a216e1cb227d10276b7bd73bf89c1da8d35f24902 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm72a7e7542927ad5a3fbfa0700d1008e57a0581534f1b347b9f10ab1cf2b8d45d0 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.ppcdd6578f10f62f72e47533dfac771693a49d9f99f29a72b125455165c75254abc Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.spc1ff43a354faee418c12c47694f39b2e92e46aa4705a570be06d156128d9297b4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.m68kaefc54f8202f34d24d309cb7a2e6c9cfe70b07f5f8ed4ba0835ca3b531e4896e Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.sh45e69cd3c506f77714a43ba8b887d565eb16780549a54ef3626678bc5c22caab9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-22T17:51:00Z UTC
Last seen:
2025-08-22T17:51:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=edc811e5-1600-0000-4e42-21219c0d0000 pid=3484 /usr/bin/sudo guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485 /tmp/sample.bin guuid=edc811e5-1600-0000-4e42-21219c0d0000 pid=3484->guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485 execve guuid=d28a06e8-1600-0000-4e42-2121a10d0000 pid=3489 /usr/bin/cp guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=d28a06e8-1600-0000-4e42-2121a10d0000 pid=3489 execve guuid=d21c8beb-1600-0000-4e42-2121a80d0000 pid=3496 /usr/bin/rm guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=d21c8beb-1600-0000-4e42-2121a80d0000 pid=3496 execve guuid=d8f6d0eb-1600-0000-4e42-2121a90d0000 pid=3497 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=d8f6d0eb-1600-0000-4e42-2121a90d0000 pid=3497 execve guuid=7e21b2fb-1600-0000-4e42-2121c30d0000 pid=3523 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=7e21b2fb-1600-0000-4e42-2121c30d0000 pid=3523 execve guuid=6d74a40d-1700-0000-4e42-2121e30d0000 pid=3555 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=6d74a40d-1700-0000-4e42-2121e30d0000 pid=3555 execve guuid=206e0b0e-1700-0000-4e42-2121e50d0000 pid=3557 /tmp/morte.x86 net guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=206e0b0e-1700-0000-4e42-2121e50d0000 pid=3557 execve guuid=de2edc0e-1700-0000-4e42-2121eb0d0000 pid=3563 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=de2edc0e-1700-0000-4e42-2121eb0d0000 pid=3563 execve guuid=9ef92510-1700-0000-4e42-2121ee0d0000 pid=3566 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=9ef92510-1700-0000-4e42-2121ee0d0000 pid=3566 execve guuid=7c35d81d-1700-0000-4e42-21210c0e0000 pid=3596 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=7c35d81d-1700-0000-4e42-21210c0e0000 pid=3596 execve guuid=f00e682d-1700-0000-4e42-21214b0e0000 pid=3659 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f00e682d-1700-0000-4e42-21214b0e0000 pid=3659 execve guuid=20b3ab2d-1700-0000-4e42-21214f0e0000 pid=3663 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=20b3ab2d-1700-0000-4e42-21214f0e0000 pid=3663 clone guuid=632c2c2e-1700-0000-4e42-2121540e0000 pid=3668 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=632c2c2e-1700-0000-4e42-2121540e0000 pid=3668 execve guuid=b3c96a2e-1700-0000-4e42-2121550e0000 pid=3669 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=b3c96a2e-1700-0000-4e42-2121550e0000 pid=3669 execve guuid=f0854846-1700-0000-4e42-2121bf0e0000 pid=3775 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f0854846-1700-0000-4e42-2121bf0e0000 pid=3775 execve guuid=0944e55f-1700-0000-4e42-2121410f0000 pid=3905 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=0944e55f-1700-0000-4e42-2121410f0000 pid=3905 execve guuid=2bcd3d60-1700-0000-4e42-2121440f0000 pid=3908 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=2bcd3d60-1700-0000-4e42-2121440f0000 pid=3908 clone guuid=8accd960-1700-0000-4e42-2121490f0000 pid=3913 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8accd960-1700-0000-4e42-2121490f0000 pid=3913 execve guuid=4e662261-1700-0000-4e42-21214d0f0000 pid=3917 /usr/bin/wget net send-data guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=4e662261-1700-0000-4e42-21214d0f0000 pid=3917 execve guuid=43c12565-1700-0000-4e42-21215d0f0000 pid=3933 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=43c12565-1700-0000-4e42-21215d0f0000 pid=3933 execve guuid=9cb3cc69-1700-0000-4e42-21217a0f0000 pid=3962 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=9cb3cc69-1700-0000-4e42-21217a0f0000 pid=3962 execve guuid=1b2e0b6a-1700-0000-4e42-21217c0f0000 pid=3964 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=1b2e0b6a-1700-0000-4e42-21217c0f0000 pid=3964 clone guuid=b24d316a-1700-0000-4e42-21217d0f0000 pid=3965 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=b24d316a-1700-0000-4e42-21217d0f0000 pid=3965 execve guuid=818f706a-1700-0000-4e42-21217f0f0000 pid=3967 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=818f706a-1700-0000-4e42-21217f0f0000 pid=3967 execve guuid=aa3a8274-1700-0000-4e42-2121b30f0000 pid=4019 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=aa3a8274-1700-0000-4e42-2121b30f0000 pid=4019 execve guuid=7508a080-1700-0000-4e42-2121e70f0000 pid=4071 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=7508a080-1700-0000-4e42-2121e70f0000 pid=4071 execve guuid=36bef180-1700-0000-4e42-2121eb0f0000 pid=4075 /tmp/morte.i686 net guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=36bef180-1700-0000-4e42-2121eb0f0000 pid=4075 execve guuid=8dc19081-1700-0000-4e42-2121f10f0000 pid=4081 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8dc19081-1700-0000-4e42-2121f10f0000 pid=4081 execve guuid=1042c881-1700-0000-4e42-2121f20f0000 pid=4082 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=1042c881-1700-0000-4e42-2121f20f0000 pid=4082 execve guuid=0819878c-1700-0000-4e42-212120100000 pid=4128 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=0819878c-1700-0000-4e42-212120100000 pid=4128 execve guuid=72949799-1700-0000-4e42-21215b100000 pid=4187 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=72949799-1700-0000-4e42-21215b100000 pid=4187 execve guuid=5f10d799-1700-0000-4e42-21215d100000 pid=4189 /tmp/morte.x86_64 mprotect-exec net guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=5f10d799-1700-0000-4e42-21215d100000 pid=4189 execve guuid=b852459a-1700-0000-4e42-212160100000 pid=4192 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=b852459a-1700-0000-4e42-212160100000 pid=4192 execve guuid=4ea67a9a-1700-0000-4e42-212162100000 pid=4194 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=4ea67a9a-1700-0000-4e42-212162100000 pid=4194 execve guuid=83cf64ae-1700-0000-4e42-2121ab100000 pid=4267 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=83cf64ae-1700-0000-4e42-2121ab100000 pid=4267 execve guuid=10f936c3-1700-0000-4e42-2121e7100000 pid=4327 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=10f936c3-1700-0000-4e42-2121e7100000 pid=4327 execve guuid=5f2cd3c3-1700-0000-4e42-2121e8100000 pid=4328 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=5f2cd3c3-1700-0000-4e42-2121e8100000 pid=4328 clone guuid=cdf7e1c6-1700-0000-4e42-2121f0100000 pid=4336 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=cdf7e1c6-1700-0000-4e42-2121f0100000 pid=4336 execve guuid=0b2542c7-1700-0000-4e42-2121f4100000 pid=4340 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=0b2542c7-1700-0000-4e42-2121f4100000 pid=4340 execve guuid=f471f3d2-1700-0000-4e42-212110110000 pid=4368 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f471f3d2-1700-0000-4e42-212110110000 pid=4368 execve guuid=a6d40fe2-1700-0000-4e42-21213b110000 pid=4411 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=a6d40fe2-1700-0000-4e42-21213b110000 pid=4411 execve guuid=e35f99e2-1700-0000-4e42-21213f110000 pid=4415 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=e35f99e2-1700-0000-4e42-21213f110000 pid=4415 clone guuid=3f384ae3-1700-0000-4e42-212144110000 pid=4420 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=3f384ae3-1700-0000-4e42-212144110000 pid=4420 execve guuid=4799a1e3-1700-0000-4e42-212146110000 pid=4422 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=4799a1e3-1700-0000-4e42-212146110000 pid=4422 execve guuid=57233dec-1700-0000-4e42-212160110000 pid=4448 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=57233dec-1700-0000-4e42-212160110000 pid=4448 execve guuid=1c5c38f8-1700-0000-4e42-212188110000 pid=4488 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=1c5c38f8-1700-0000-4e42-212188110000 pid=4488 execve guuid=61739af8-1700-0000-4e42-21218c110000 pid=4492 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=61739af8-1700-0000-4e42-21218c110000 pid=4492 clone guuid=c5a490f9-1700-0000-4e42-212190110000 pid=4496 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=c5a490f9-1700-0000-4e42-212190110000 pid=4496 execve guuid=8fe3f4f9-1700-0000-4e42-212194110000 pid=4500 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8fe3f4f9-1700-0000-4e42-212194110000 pid=4500 execve guuid=1ec3d308-1800-0000-4e42-2121ba110000 pid=4538 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=1ec3d308-1800-0000-4e42-2121ba110000 pid=4538 execve guuid=8e19f719-1800-0000-4e42-2121e7110000 pid=4583 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8e19f719-1800-0000-4e42-2121e7110000 pid=4583 execve guuid=65aa3f1a-1800-0000-4e42-2121ea110000 pid=4586 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=65aa3f1a-1800-0000-4e42-2121ea110000 pid=4586 clone guuid=f446581a-1800-0000-4e42-2121ec110000 pid=4588 /usr/bin/rm guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f446581a-1800-0000-4e42-2121ec110000 pid=4588 execve guuid=98bda71a-1800-0000-4e42-2121ee110000 pid=4590 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=98bda71a-1800-0000-4e42-2121ee110000 pid=4590 execve guuid=7413b32b-1800-0000-4e42-212133120000 pid=4659 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=7413b32b-1800-0000-4e42-212133120000 pid=4659 execve guuid=f6f23853-1800-0000-4e42-212178120000 pid=4728 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f6f23853-1800-0000-4e42-212178120000 pid=4728 execve guuid=51e5e653-1800-0000-4e42-212179120000 pid=4729 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=51e5e653-1800-0000-4e42-212179120000 pid=4729 clone guuid=862cf554-1800-0000-4e42-21217e120000 pid=4734 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=862cf554-1800-0000-4e42-21217e120000 pid=4734 execve guuid=69518355-1800-0000-4e42-21217f120000 pid=4735 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=69518355-1800-0000-4e42-21217f120000 pid=4735 execve guuid=e198d761-1800-0000-4e42-21219f120000 pid=4767 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=e198d761-1800-0000-4e42-21219f120000 pid=4767 execve guuid=c67e2f76-1800-0000-4e42-2121d7120000 pid=4823 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=c67e2f76-1800-0000-4e42-2121d7120000 pid=4823 execve guuid=ed986d76-1800-0000-4e42-2121d9120000 pid=4825 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=ed986d76-1800-0000-4e42-2121d9120000 pid=4825 clone guuid=e469e476-1800-0000-4e42-2121dd120000 pid=4829 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=e469e476-1800-0000-4e42-2121dd120000 pid=4829 execve guuid=60e14a77-1800-0000-4e42-2121df120000 pid=4831 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=60e14a77-1800-0000-4e42-2121df120000 pid=4831 execve guuid=f3406b8c-1800-0000-4e42-212111130000 pid=4881 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=f3406b8c-1800-0000-4e42-212111130000 pid=4881 execve guuid=1174e19c-1800-0000-4e42-212152130000 pid=4946 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=1174e19c-1800-0000-4e42-212152130000 pid=4946 execve guuid=dae3309d-1800-0000-4e42-212154130000 pid=4948 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=dae3309d-1800-0000-4e42-212154130000 pid=4948 clone guuid=5c90c39d-1800-0000-4e42-212158130000 pid=4952 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=5c90c39d-1800-0000-4e42-212158130000 pid=4952 execve guuid=8e72039e-1800-0000-4e42-21215b130000 pid=4955 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8e72039e-1800-0000-4e42-21215b130000 pid=4955 execve guuid=2412c9ac-1800-0000-4e42-21218b130000 pid=5003 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=2412c9ac-1800-0000-4e42-21218b130000 pid=5003 execve guuid=bb3d8dc4-1800-0000-4e42-2121c4130000 pid=5060 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=bb3d8dc4-1800-0000-4e42-2121c4130000 pid=5060 execve guuid=61a806c5-1800-0000-4e42-2121c6130000 pid=5062 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=61a806c5-1800-0000-4e42-2121c6130000 pid=5062 clone guuid=205820c6-1800-0000-4e42-2121ca130000 pid=5066 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=205820c6-1800-0000-4e42-2121ca130000 pid=5066 execve guuid=af10aac6-1800-0000-4e42-2121cc130000 pid=5068 /usr/bin/wget net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=af10aac6-1800-0000-4e42-2121cc130000 pid=5068 execve guuid=8c5432db-1800-0000-4e42-2121f8130000 pid=5112 /usr/bin/curl net send-data write-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=8c5432db-1800-0000-4e42-2121f8130000 pid=5112 execve guuid=b76981f9-1800-0000-4e42-212144140000 pid=5188 /usr/bin/chmod guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=b76981f9-1800-0000-4e42-212144140000 pid=5188 execve guuid=3d9ceef9-1800-0000-4e42-212146140000 pid=5190 /usr/bin/bash guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=3d9ceef9-1800-0000-4e42-212146140000 pid=5190 clone guuid=864e15fb-1800-0000-4e42-212148140000 pid=5192 /usr/bin/rm delete-file guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=864e15fb-1800-0000-4e42-212148140000 pid=5192 execve guuid=51f4b9fb-1800-0000-4e42-212149140000 pid=5193 /usr/bin/rm guuid=91bb7be7-1600-0000-4e42-21219d0d0000 pid=3485->guuid=51f4b9fb-1800-0000-4e42-212149140000 pid=5193 execve 6beadc35-efc4-5e26-84e6-0089cd490f0e 196.251.73.24:80 guuid=d8f6d0eb-1600-0000-4e42-2121a90d0000 pid=3497->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=7e21b2fb-1600-0000-4e42-2121c30d0000 pid=3523->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=206e0b0e-1700-0000-4e42-2121e50d0000 pid=3557->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d76dd40e-1700-0000-4e42-2121ea0d0000 pid=3562 /tmp/morte.x86 guuid=206e0b0e-1700-0000-4e42-2121e50d0000 pid=3557->guuid=d76dd40e-1700-0000-4e42-2121ea0d0000 pid=3562 clone guuid=f2c8dd0e-1700-0000-4e42-2121ec0d0000 pid=3564 /tmp/morte.x86 write-config zombie guuid=d76dd40e-1700-0000-4e42-2121ea0d0000 pid=3562->guuid=f2c8dd0e-1700-0000-4e42-2121ec0d0000 pid=3564 clone guuid=e772e014-1700-0000-4e42-2121f80d0000 pid=3576 /usr/bin/dash guuid=f2c8dd0e-1700-0000-4e42-2121ec0d0000 pid=3564->guuid=e772e014-1700-0000-4e42-2121f80d0000 pid=3576 execve guuid=0279a017-1700-0000-4e42-2121fd0d0000 pid=3581 /tmp/morte.x86 delete-file dns net send-data guuid=f2c8dd0e-1700-0000-4e42-2121ec0d0000 pid=3564->guuid=0279a017-1700-0000-4e42-2121fd0d0000 pid=3581 clone guuid=9ef92510-1700-0000-4e42-2121ee0d0000 pid=3566->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=febd1915-1700-0000-4e42-2121f90d0000 pid=3577 /usr/bin/cp guuid=e772e014-1700-0000-4e42-2121f80d0000 pid=3576->guuid=febd1915-1700-0000-4e42-2121f90d0000 pid=3577 execve guuid=0279a017-1700-0000-4e42-2121fd0d0000 pid=3581->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B debdf84d-299e-545d-934e-259ecac9681a riseonid.com:12121 guuid=0279a017-1700-0000-4e42-2121fd0d0000 pid=3581->debdf84d-299e-545d-934e-259ecac9681a send: 14B guuid=7c35d81d-1700-0000-4e42-21210c0e0000 pid=3596->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=b3c96a2e-1700-0000-4e42-2121550e0000 pid=3669->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=f0854846-1700-0000-4e42-2121bf0e0000 pid=3775->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B dcd0c388-ab1e-53dc-878c-c7efac1522a9 riseonid.com:80 guuid=4e662261-1700-0000-4e42-21214d0f0000 pid=3917->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=43c12565-1700-0000-4e42-21215d0f0000 pid=3933->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=818f706a-1700-0000-4e42-21217f0f0000 pid=3967->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=aa3a8274-1700-0000-4e42-2121b30f0000 pid=4019->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=36bef180-1700-0000-4e42-2121eb0f0000 pid=4075->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d58c6e81-1700-0000-4e42-2121ef0f0000 pid=4079 /tmp/morte.i686 guuid=36bef180-1700-0000-4e42-2121eb0f0000 pid=4075->guuid=d58c6e81-1700-0000-4e42-2121ef0f0000 pid=4079 clone guuid=a0cb7881-1700-0000-4e42-2121f00f0000 pid=4080 /tmp/morte.i686 write-config zombie guuid=d58c6e81-1700-0000-4e42-2121ef0f0000 pid=4079->guuid=a0cb7881-1700-0000-4e42-2121f00f0000 pid=4080 clone guuid=61cdd784-1700-0000-4e42-212101100000 pid=4097 /usr/bin/dash guuid=a0cb7881-1700-0000-4e42-2121f00f0000 pid=4080->guuid=61cdd784-1700-0000-4e42-212101100000 pid=4097 execve guuid=fdca0d87-1700-0000-4e42-21210a100000 pid=4106 /tmp/morte.i686 delete-file guuid=a0cb7881-1700-0000-4e42-2121f00f0000 pid=4080->guuid=fdca0d87-1700-0000-4e42-21210a100000 pid=4106 clone guuid=4399b043-1900-0000-4e42-2121c5140000 pid=5317 /tmp/morte.i686 dns net send-data guuid=a0cb7881-1700-0000-4e42-2121f00f0000 pid=4080->guuid=4399b043-1900-0000-4e42-2121c5140000 pid=5317 clone guuid=1042c881-1700-0000-4e42-2121f20f0000 pid=4082->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 145B guuid=e5150285-1700-0000-4e42-212102100000 pid=4098 /usr/bin/cp guuid=61cdd784-1700-0000-4e42-212101100000 pid=4097->guuid=e5150285-1700-0000-4e42-212102100000 pid=4098 execve guuid=0819878c-1700-0000-4e42-212120100000 pid=4128->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 94B guuid=5f10d799-1700-0000-4e42-21215d100000 pid=4189->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=edcf3a9a-1700-0000-4e42-21215f100000 pid=4191 /tmp/morte.x86_64 zombie guuid=5f10d799-1700-0000-4e42-21215d100000 pid=4189->guuid=edcf3a9a-1700-0000-4e42-21215f100000 pid=4191 clone guuid=57d1069b-1700-0000-4e42-212165100000 pid=4197 /tmp/morte.x86_64 write-config zombie guuid=edcf3a9a-1700-0000-4e42-21215f100000 pid=4191->guuid=57d1069b-1700-0000-4e42-212165100000 pid=4197 clone guuid=4ea67a9a-1700-0000-4e42-212162100000 pid=4194->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=7a44489b-1700-0000-4e42-212166100000 pid=4198 /usr/bin/dash guuid=57d1069b-1700-0000-4e42-212165100000 pid=4197->guuid=7a44489b-1700-0000-4e42-212166100000 pid=4198 execve guuid=b024559c-1700-0000-4e42-21216b100000 pid=4203 /tmp/morte.x86_64 delete-file dns net send-data guuid=57d1069b-1700-0000-4e42-212165100000 pid=4197->guuid=b024559c-1700-0000-4e42-21216b100000 pid=4203 clone guuid=9103d69b-1700-0000-4e42-212167100000 pid=4199 /usr/bin/cp guuid=7a44489b-1700-0000-4e42-212166100000 pid=4198->guuid=9103d69b-1700-0000-4e42-212167100000 pid=4199 execve guuid=b024559c-1700-0000-4e42-21216b100000 pid=4203->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B guuid=b024559c-1700-0000-4e42-21216b100000 pid=4203->debdf84d-299e-545d-934e-259ecac9681a send: 17B guuid=83cf64ae-1700-0000-4e42-2121ab100000 pid=4267->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=0b2542c7-1700-0000-4e42-2121f4100000 pid=4340->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=f471f3d2-1700-0000-4e42-212110110000 pid=4368->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=4799a1e3-1700-0000-4e42-212146110000 pid=4422->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=57233dec-1700-0000-4e42-212160110000 pid=4448->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=8fe3f4f9-1700-0000-4e42-212194110000 pid=4500->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=1ec3d308-1800-0000-4e42-2121ba110000 pid=4538->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=98bda71a-1800-0000-4e42-2121ee110000 pid=4590->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=7413b32b-1800-0000-4e42-212133120000 pid=4659->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=69518355-1800-0000-4e42-21217f120000 pid=4735->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=e198d761-1800-0000-4e42-21219f120000 pid=4767->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=60e14a77-1800-0000-4e42-2121df120000 pid=4831->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=f3406b8c-1800-0000-4e42-212111130000 pid=4881->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=8e72039e-1800-0000-4e42-21215b130000 pid=4955->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=2412c9ac-1800-0000-4e42-21218b130000 pid=5003->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=af10aac6-1800-0000-4e42-2121cc130000 pid=5068->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=8c5432db-1800-0000-4e42-2121f8130000 pid=5112->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=4399b043-1900-0000-4e42-2121c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B guuid=4399b043-1900-0000-4e42-2121c5140000 pid=5317->debdf84d-299e-545d-934e-259ecac9681a send: 17B
Threat name:
Script-Shell.Trojan.Vigorf
Status:
Malicious
First seen:
2025-08-22 19:53:32 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1021124ad2a144ca265da5ab016a35ef68515a9509b4da1df284d27f3e8181a5

(this sample)

  
Delivery method
Distributed via web download

Comments