MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13779d2d17a962b7f2d9644c0fcbb1c2ac4a61baccfe6ff9a3cc1b66637c1521. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 13779d2d17a962b7f2d9644c0fcbb1c2ac4a61baccfe6ff9a3cc1b66637c1521
SHA3-384 hash: 6a352ec01a8d16ed0f627a54eff790d529eb174bd6a3464281e4df108d6fbbcc449105ab0b7a50eacc9f4a68b84da689
SHA1 hash: 1c4183fc2968732b0a13c7103579ecb5384559ee
MD5 hash: 025e6dc91cf49b9db71b98efa0f794c4
humanhash: salami-purple-network-echo
File name:1.sh
Download: download sample
Signature Mirai
File size:3'346 bytes
First seen:2025-07-28 16:47:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Gm/ZsvbhTkHlfrmsvTtAGgJr63nL72NIpKksnMEvhHs7KcGgJsNdpk:GmqdA9D7tA12XLAJhJM7KBgJsJk
TLSH T1136172FA13924633DDAA8EE332A88404718541DB94CE5FF55BFC34B50C8CED8BC42652
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.116.34/00101010101001/morte.x86bd297ae9c45ffbfe444213d57dd4eb32d6212465d6c840f1a497cc20c533d4e9 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.mips568780e2ac25888e3151dd8e8cb76d1ebdfd2e986e0fed4931d15656fa5b9eb1 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.arc7321f337422bcdbac4f2a90af9d827e18fb1ead5acee542ecf05e4fe37e5822e Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.i468n/an/aelf opendir ua-wget
http://196.251.116.34/00101010101001/morte.i68682444c55629dc38a74ad72ef9af7239b973f85aadd1c7d227205e529901e97fb Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.x86_64750684d31633710b2a8bd3ffe886405d3a7ed4e5ad57779c742fba4e7a592018 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.mpsl5d1b62d8c2acef405d9027ce927733d49d04464ed761421a74c9652bd0339709 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.armf83b76f66452fe975e2c15145bbcd4fb24b12192eddc87b1272a9413f11b4018 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.arm58b536240087f1627bf1417ee5529c42a17561a64b3f8628c907d1e023cc91893 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.arm6f6ceab5e38268a31528821a82a6ad66b27031c8ecffef6c7e718bcca359d03b5 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.arm700969384d60395745426767373265dcc7aca5888936df57b2deafaefe780b9e4 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.ppcce2a3ca361d668031c19ea9bf31a5c96e37d6dc7d10c6ed9d7b7919df009850c Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.spc196663d92cac163ac2730d386e4bc9261d29b8c6d811e8f5b5370c8633375f99 Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.m68kc9b7bbf730c616b2edbfc26eda34f7bff8d306bab45974e45083175778ebecce Miraielf mirai ua-wget
http://196.251.116.34/00101010101001/morte.sh49756731375c8aaa5e4deb59e70739d555fbee90ec01276d839ea965f3c1c58b6 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=fcc2c2f7-1900-0000-b769-a415b40c0000 pid=3252 /usr/bin/sudo guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253 /tmp/sample.bin guuid=fcc2c2f7-1900-0000-b769-a415b40c0000 pid=3252->guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253 execve guuid=839645fc-1900-0000-b769-a415b60c0000 pid=3254 /usr/bin/cp guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=839645fc-1900-0000-b769-a415b60c0000 pid=3254 execve guuid=520d4d03-1a00-0000-b769-a415bf0c0000 pid=3263 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=520d4d03-1a00-0000-b769-a415bf0c0000 pid=3263 execve guuid=969c3109-1a00-0000-b769-a415cc0c0000 pid=3276 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=969c3109-1a00-0000-b769-a415cc0c0000 pid=3276 execve guuid=3aa5f614-1a00-0000-b769-a415e60c0000 pid=3302 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=3aa5f614-1a00-0000-b769-a415e60c0000 pid=3302 execve guuid=49e05015-1a00-0000-b769-a415e70c0000 pid=3303 /tmp/morte.x86 net guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=49e05015-1a00-0000-b769-a415e70c0000 pid=3303 execve guuid=6092f915-1a00-0000-b769-a415ea0c0000 pid=3306 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=6092f915-1a00-0000-b769-a415ea0c0000 pid=3306 execve guuid=087a5716-1a00-0000-b769-a415ec0c0000 pid=3308 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=087a5716-1a00-0000-b769-a415ec0c0000 pid=3308 execve guuid=d37ec619-1a00-0000-b769-a415f60c0000 pid=3318 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d37ec619-1a00-0000-b769-a415f60c0000 pid=3318 execve guuid=c2c8be20-1a00-0000-b769-a4150a0d0000 pid=3338 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=c2c8be20-1a00-0000-b769-a4150a0d0000 pid=3338 execve guuid=d9d36921-1a00-0000-b769-a4150b0d0000 pid=3339 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d9d36921-1a00-0000-b769-a4150b0d0000 pid=3339 clone guuid=9ef70822-1a00-0000-b769-a4150d0d0000 pid=3341 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=9ef70822-1a00-0000-b769-a4150d0d0000 pid=3341 execve guuid=b4511924-1a00-0000-b769-a4150e0d0000 pid=3342 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=b4511924-1a00-0000-b769-a4150e0d0000 pid=3342 execve guuid=15a31f2a-1a00-0000-b769-a4150f0d0000 pid=3343 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=15a31f2a-1a00-0000-b769-a4150f0d0000 pid=3343 execve guuid=3ade4d33-1a00-0000-b769-a4151c0d0000 pid=3356 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=3ade4d33-1a00-0000-b769-a4151c0d0000 pid=3356 execve guuid=72f79c33-1a00-0000-b769-a4151d0d0000 pid=3357 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=72f79c33-1a00-0000-b769-a4151d0d0000 pid=3357 clone guuid=16562534-1a00-0000-b769-a415210d0000 pid=3361 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=16562534-1a00-0000-b769-a415210d0000 pid=3361 execve guuid=a41b1437-1a00-0000-b769-a415260d0000 pid=3366 /usr/bin/wget net send-data guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=a41b1437-1a00-0000-b769-a415260d0000 pid=3366 execve guuid=089ec339-1a00-0000-b769-a4152e0d0000 pid=3374 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=089ec339-1a00-0000-b769-a4152e0d0000 pid=3374 execve guuid=c5d6a73f-1a00-0000-b769-a4153f0d0000 pid=3391 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=c5d6a73f-1a00-0000-b769-a4153f0d0000 pid=3391 execve guuid=d3e7e53f-1a00-0000-b769-a415410d0000 pid=3393 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d3e7e53f-1a00-0000-b769-a415410d0000 pid=3393 clone guuid=5d670140-1a00-0000-b769-a415420d0000 pid=3394 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=5d670140-1a00-0000-b769-a415420d0000 pid=3394 execve guuid=b2023e40-1a00-0000-b769-a415440d0000 pid=3396 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=b2023e40-1a00-0000-b769-a415440d0000 pid=3396 execve guuid=e87de443-1a00-0000-b769-a415510d0000 pid=3409 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=e87de443-1a00-0000-b769-a415510d0000 pid=3409 execve guuid=b8a98848-1a00-0000-b769-a4155d0d0000 pid=3421 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=b8a98848-1a00-0000-b769-a4155d0d0000 pid=3421 execve guuid=52bac748-1a00-0000-b769-a4155f0d0000 pid=3423 /tmp/morte.i686 net guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=52bac748-1a00-0000-b769-a4155f0d0000 pid=3423 execve guuid=24afff48-1a00-0000-b769-a415610d0000 pid=3425 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=24afff48-1a00-0000-b769-a415610d0000 pid=3425 execve guuid=f4e44449-1a00-0000-b769-a415630d0000 pid=3427 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=f4e44449-1a00-0000-b769-a415630d0000 pid=3427 execve guuid=d36fb94c-1a00-0000-b769-a415720d0000 pid=3442 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d36fb94c-1a00-0000-b769-a415720d0000 pid=3442 execve guuid=53c08158-1a00-0000-b769-a415a40d0000 pid=3492 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=53c08158-1a00-0000-b769-a415a40d0000 pid=3492 execve guuid=1b71d858-1a00-0000-b769-a415a60d0000 pid=3494 /tmp/morte.x86_64 mprotect-exec net guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=1b71d858-1a00-0000-b769-a415a60d0000 pid=3494 execve guuid=72378759-1a00-0000-b769-a415ab0d0000 pid=3499 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=72378759-1a00-0000-b769-a415ab0d0000 pid=3499 execve guuid=7266125a-1a00-0000-b769-a415b00d0000 pid=3504 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=7266125a-1a00-0000-b769-a415b00d0000 pid=3504 execve guuid=4e5b485f-1a00-0000-b769-a415c70d0000 pid=3527 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=4e5b485f-1a00-0000-b769-a415c70d0000 pid=3527 execve guuid=fcb14364-1a00-0000-b769-a415d20d0000 pid=3538 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=fcb14364-1a00-0000-b769-a415d20d0000 pid=3538 execve guuid=28d4ba64-1a00-0000-b769-a415d30d0000 pid=3539 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=28d4ba64-1a00-0000-b769-a415d30d0000 pid=3539 clone guuid=93315a66-1a00-0000-b769-a415d50d0000 pid=3541 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=93315a66-1a00-0000-b769-a415d50d0000 pid=3541 execve guuid=5f7ccf66-1a00-0000-b769-a415d60d0000 pid=3542 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=5f7ccf66-1a00-0000-b769-a415d60d0000 pid=3542 execve guuid=226faf6a-1a00-0000-b769-a415de0d0000 pid=3550 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=226faf6a-1a00-0000-b769-a415de0d0000 pid=3550 execve guuid=bb41ce6f-1a00-0000-b769-a415ec0d0000 pid=3564 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=bb41ce6f-1a00-0000-b769-a415ec0d0000 pid=3564 execve guuid=26904870-1a00-0000-b769-a415ed0d0000 pid=3565 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=26904870-1a00-0000-b769-a415ed0d0000 pid=3565 clone guuid=cedc7271-1a00-0000-b769-a415f00d0000 pid=3568 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=cedc7271-1a00-0000-b769-a415f00d0000 pid=3568 execve guuid=303cb179-1a00-0000-b769-a415fc0d0000 pid=3580 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=303cb179-1a00-0000-b769-a415fc0d0000 pid=3580 execve guuid=3caa387e-1a00-0000-b769-a415020e0000 pid=3586 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=3caa387e-1a00-0000-b769-a415020e0000 pid=3586 execve guuid=86251b84-1a00-0000-b769-a415070e0000 pid=3591 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=86251b84-1a00-0000-b769-a415070e0000 pid=3591 execve guuid=99506a84-1a00-0000-b769-a415090e0000 pid=3593 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=99506a84-1a00-0000-b769-a415090e0000 pid=3593 clone guuid=a6008e85-1a00-0000-b769-a4150e0e0000 pid=3598 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=a6008e85-1a00-0000-b769-a4150e0e0000 pid=3598 execve guuid=154c2c86-1a00-0000-b769-a415110e0000 pid=3601 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=154c2c86-1a00-0000-b769-a415110e0000 pid=3601 execve guuid=b4ee1c8b-1a00-0000-b769-a4151e0e0000 pid=3614 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=b4ee1c8b-1a00-0000-b769-a4151e0e0000 pid=3614 execve guuid=feee8e91-1a00-0000-b769-a415300e0000 pid=3632 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=feee8e91-1a00-0000-b769-a415300e0000 pid=3632 execve guuid=4145cc91-1a00-0000-b769-a415320e0000 pid=3634 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=4145cc91-1a00-0000-b769-a415320e0000 pid=3634 clone guuid=7e463b93-1a00-0000-b769-a415340e0000 pid=3636 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=7e463b93-1a00-0000-b769-a415340e0000 pid=3636 execve guuid=ef854b96-1a00-0000-b769-a415360e0000 pid=3638 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=ef854b96-1a00-0000-b769-a415360e0000 pid=3638 execve guuid=d09be69a-1a00-0000-b769-a415420e0000 pid=3650 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d09be69a-1a00-0000-b769-a415420e0000 pid=3650 execve guuid=d5adf79f-1a00-0000-b769-a4154f0e0000 pid=3663 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d5adf79f-1a00-0000-b769-a4154f0e0000 pid=3663 execve guuid=91bc7fa0-1a00-0000-b769-a415500e0000 pid=3664 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=91bc7fa0-1a00-0000-b769-a415500e0000 pid=3664 clone guuid=827e7ba1-1a00-0000-b769-a415520e0000 pid=3666 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=827e7ba1-1a00-0000-b769-a415520e0000 pid=3666 execve guuid=cfc1e4a1-1a00-0000-b769-a415540e0000 pid=3668 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=cfc1e4a1-1a00-0000-b769-a415540e0000 pid=3668 execve guuid=24cc59a5-1a00-0000-b769-a4155d0e0000 pid=3677 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=24cc59a5-1a00-0000-b769-a4155d0e0000 pid=3677 execve guuid=2d0a5daa-1a00-0000-b769-a415670e0000 pid=3687 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=2d0a5daa-1a00-0000-b769-a415670e0000 pid=3687 execve guuid=9ac19faa-1a00-0000-b769-a415690e0000 pid=3689 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=9ac19faa-1a00-0000-b769-a415690e0000 pid=3689 clone guuid=aedc31ab-1a00-0000-b769-a4156d0e0000 pid=3693 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=aedc31ab-1a00-0000-b769-a4156d0e0000 pid=3693 execve guuid=f7b1e0ab-1a00-0000-b769-a415710e0000 pid=3697 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=f7b1e0ab-1a00-0000-b769-a415710e0000 pid=3697 execve guuid=6edc18b0-1a00-0000-b769-a415820e0000 pid=3714 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=6edc18b0-1a00-0000-b769-a415820e0000 pid=3714 execve guuid=f248a4b5-1a00-0000-b769-a415920e0000 pid=3730 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=f248a4b5-1a00-0000-b769-a415920e0000 pid=3730 execve guuid=9d1c06b6-1a00-0000-b769-a415940e0000 pid=3732 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=9d1c06b6-1a00-0000-b769-a415940e0000 pid=3732 clone guuid=d77465b7-1a00-0000-b769-a4159a0e0000 pid=3738 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=d77465b7-1a00-0000-b769-a4159a0e0000 pid=3738 execve guuid=4d38bab7-1a00-0000-b769-a4159c0e0000 pid=3740 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=4d38bab7-1a00-0000-b769-a4159c0e0000 pid=3740 execve guuid=fb9f5ebc-1a00-0000-b769-a415a60e0000 pid=3750 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=fb9f5ebc-1a00-0000-b769-a415a60e0000 pid=3750 execve guuid=69fc55c3-1a00-0000-b769-a415a70e0000 pid=3751 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=69fc55c3-1a00-0000-b769-a415a70e0000 pid=3751 execve guuid=3d61ecc3-1a00-0000-b769-a415a80e0000 pid=3752 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=3d61ecc3-1a00-0000-b769-a415a80e0000 pid=3752 clone guuid=2460e7c4-1a00-0000-b769-a415ad0e0000 pid=3757 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=2460e7c4-1a00-0000-b769-a415ad0e0000 pid=3757 execve guuid=485d4ec5-1a00-0000-b769-a415ae0e0000 pid=3758 /usr/bin/wget net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=485d4ec5-1a00-0000-b769-a415ae0e0000 pid=3758 execve guuid=48fed7c9-1a00-0000-b769-a415b80e0000 pid=3768 /usr/bin/curl net send-data write-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=48fed7c9-1a00-0000-b769-a415b80e0000 pid=3768 execve guuid=eaefdecf-1a00-0000-b769-a415c70e0000 pid=3783 /usr/bin/chmod guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=eaefdecf-1a00-0000-b769-a415c70e0000 pid=3783 execve guuid=0e942ad0-1a00-0000-b769-a415c80e0000 pid=3784 /usr/bin/bash guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=0e942ad0-1a00-0000-b769-a415c80e0000 pid=3784 clone guuid=4815d2d0-1a00-0000-b769-a415cc0e0000 pid=3788 /usr/bin/rm delete-file guuid=7644e8fa-1900-0000-b769-a415b50c0000 pid=3253->guuid=4815d2d0-1a00-0000-b769-a415cc0e0000 pid=3788 execve f2b0adff-3c28-5b5a-8344-605c6057838c 196.251.116.34:80 guuid=520d4d03-1a00-0000-b769-a415bf0c0000 pid=3263->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=969c3109-1a00-0000-b769-a415cc0c0000 pid=3276->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=49e05015-1a00-0000-b769-a415e70c0000 pid=3303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=970bee15-1a00-0000-b769-a415e90c0000 pid=3305 /tmp/morte.x86 guuid=49e05015-1a00-0000-b769-a415e70c0000 pid=3303->guuid=970bee15-1a00-0000-b769-a415e90c0000 pid=3305 clone guuid=df420016-1a00-0000-b769-a415eb0c0000 pid=3307 /tmp/morte.x86 write-config zombie guuid=970bee15-1a00-0000-b769-a415e90c0000 pid=3305->guuid=df420016-1a00-0000-b769-a415eb0c0000 pid=3307 clone guuid=1feed319-1a00-0000-b769-a415f80c0000 pid=3320 /usr/bin/dash guuid=df420016-1a00-0000-b769-a415eb0c0000 pid=3307->guuid=1feed319-1a00-0000-b769-a415f80c0000 pid=3320 execve guuid=716d241c-1a00-0000-b769-a415010d0000 pid=3329 /tmp/morte.x86 delete-file guuid=df420016-1a00-0000-b769-a415eb0c0000 pid=3307->guuid=716d241c-1a00-0000-b769-a415010d0000 pid=3329 clone guuid=087a5716-1a00-0000-b769-a415ec0c0000 pid=3308->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=d37ec619-1a00-0000-b769-a415f60c0000 pid=3318->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=8b5bff19-1a00-0000-b769-a415f90c0000 pid=3321 /usr/bin/cp guuid=1feed319-1a00-0000-b769-a415f80c0000 pid=3320->guuid=8b5bff19-1a00-0000-b769-a415f90c0000 pid=3321 execve guuid=b4511924-1a00-0000-b769-a4150e0d0000 pid=3342->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=15a31f2a-1a00-0000-b769-a4150f0d0000 pid=3343->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B guuid=a41b1437-1a00-0000-b769-a415260d0000 pid=3366->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=089ec339-1a00-0000-b769-a4152e0d0000 pid=3374->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=b2023e40-1a00-0000-b769-a415440d0000 pid=3396->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=e87de443-1a00-0000-b769-a415510d0000 pid=3409->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=52bac748-1a00-0000-b769-a4155f0d0000 pid=3423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=52c8f948-1a00-0000-b769-a415600d0000 pid=3424 /tmp/morte.i686 guuid=52bac748-1a00-0000-b769-a4155f0d0000 pid=3423->guuid=52c8f948-1a00-0000-b769-a415600d0000 pid=3424 clone guuid=62d84a49-1a00-0000-b769-a415640d0000 pid=3428 /tmp/morte.i686 write-config zombie guuid=52c8f948-1a00-0000-b769-a415600d0000 pid=3424->guuid=62d84a49-1a00-0000-b769-a415640d0000 pid=3428 clone guuid=f4e44449-1a00-0000-b769-a415630d0000 pid=3427->f2b0adff-3c28-5b5a-8344-605c6057838c send: 156B guuid=d3dc444e-1a00-0000-b769-a415790d0000 pid=3449 /usr/bin/dash guuid=62d84a49-1a00-0000-b769-a415640d0000 pid=3428->guuid=d3dc444e-1a00-0000-b769-a415790d0000 pid=3449 execve guuid=bc30d350-1a00-0000-b769-a415840d0000 pid=3460 /tmp/morte.i686 guuid=62d84a49-1a00-0000-b769-a415640d0000 pid=3428->guuid=bc30d350-1a00-0000-b769-a415840d0000 pid=3460 clone guuid=df70c255-1e00-0000-b769-a415d5140000 pid=5333 /tmp/morte.i686 dns net send-data guuid=62d84a49-1a00-0000-b769-a415640d0000 pid=3428->guuid=df70c255-1e00-0000-b769-a415d5140000 pid=5333 clone guuid=d36fb94c-1a00-0000-b769-a415720d0000 pid=3442->f2b0adff-3c28-5b5a-8344-605c6057838c send: 105B guuid=7f21804e-1a00-0000-b769-a4157b0d0000 pid=3451 /usr/bin/cp guuid=d3dc444e-1a00-0000-b769-a415790d0000 pid=3449->guuid=7f21804e-1a00-0000-b769-a4157b0d0000 pid=3451 execve guuid=1b71d858-1a00-0000-b769-a415a60d0000 pid=3494->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=90478059-1a00-0000-b769-a415aa0d0000 pid=3498 /tmp/morte.x86_64 zombie guuid=1b71d858-1a00-0000-b769-a415a60d0000 pid=3494->guuid=90478059-1a00-0000-b769-a415aa0d0000 pid=3498 clone guuid=b6b68d59-1a00-0000-b769-a415ac0d0000 pid=3500 /tmp/morte.x86_64 write-config zombie guuid=90478059-1a00-0000-b769-a415aa0d0000 pid=3498->guuid=b6b68d59-1a00-0000-b769-a415ac0d0000 pid=3500 clone guuid=da78f559-1a00-0000-b769-a415af0d0000 pid=3503 /usr/bin/dash guuid=b6b68d59-1a00-0000-b769-a415ac0d0000 pid=3500->guuid=da78f559-1a00-0000-b769-a415af0d0000 pid=3503 execve guuid=298dbe5a-1a00-0000-b769-a415b50d0000 pid=3509 /tmp/morte.x86_64 dns net send-data guuid=b6b68d59-1a00-0000-b769-a415ac0d0000 pid=3500->guuid=298dbe5a-1a00-0000-b769-a415b50d0000 pid=3509 clone guuid=01152a5a-1a00-0000-b769-a415b10d0000 pid=3505 /usr/bin/cp guuid=da78f559-1a00-0000-b769-a415af0d0000 pid=3503->guuid=01152a5a-1a00-0000-b769-a415b10d0000 pid=3505 execve guuid=7266125a-1a00-0000-b769-a415b00d0000 pid=3504->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=298dbe5a-1a00-0000-b769-a415b50d0000 pid=3509->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 1bbb4005-5fa7-5147-8924-030d465cc44a vipcncnetwork.com:12121 guuid=298dbe5a-1a00-0000-b769-a415b50d0000 pid=3509->1bbb4005-5fa7-5147-8924-030d465cc44a send: 27B guuid=4e5b485f-1a00-0000-b769-a415c70d0000 pid=3527->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=5f7ccf66-1a00-0000-b769-a415d60d0000 pid=3542->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=226faf6a-1a00-0000-b769-a415de0d0000 pid=3550->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B guuid=303cb179-1a00-0000-b769-a415fc0d0000 pid=3580->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=3caa387e-1a00-0000-b769-a415020e0000 pid=3586->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=154c2c86-1a00-0000-b769-a415110e0000 pid=3601->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=b4ee1c8b-1a00-0000-b769-a4151e0e0000 pid=3614->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=ef854b96-1a00-0000-b769-a415360e0000 pid=3638->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=d09be69a-1a00-0000-b769-a415420e0000 pid=3650->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=cfc1e4a1-1a00-0000-b769-a415540e0000 pid=3668->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=24cc59a5-1a00-0000-b769-a4155d0e0000 pid=3677->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B guuid=f7b1e0ab-1a00-0000-b769-a415710e0000 pid=3697->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=6edc18b0-1a00-0000-b769-a415820e0000 pid=3714->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B guuid=4d38bab7-1a00-0000-b769-a4159c0e0000 pid=3740->f2b0adff-3c28-5b5a-8344-605c6057838c send: 154B guuid=fb9f5ebc-1a00-0000-b769-a415a60e0000 pid=3750->f2b0adff-3c28-5b5a-8344-605c6057838c send: 103B guuid=485d4ec5-1a00-0000-b769-a415ae0e0000 pid=3758->f2b0adff-3c28-5b5a-8344-605c6057838c send: 153B guuid=48fed7c9-1a00-0000-b769-a415b80e0000 pid=3768->f2b0adff-3c28-5b5a-8344-605c6057838c send: 102B guuid=df70c255-1e00-0000-b769-a415d5140000 pid=5333->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=df70c255-1e00-0000-b769-a415d5140000 pid=5333->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-28 16:48:29 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 13779d2d17a962b7f2d9644c0fcbb1c2ac4a61baccfe6ff9a3cc1b66637c1521

(this sample)

Comments