MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 16f7bd0f48bcdfbf0206735e81c7ee5c5ab2b8fa92b120fa2eeb684d16af40e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 16f7bd0f48bcdfbf0206735e81c7ee5c5ab2b8fa92b120fa2eeb684d16af40e2
SHA3-384 hash: 861ad943e08c04bfb56b1c4e3c087d7363c6687053f0da6e3652f5a13ce213187d61bdb042bf2f4e6d81d21a47e95e18
SHA1 hash: c8571dc072221defffbc9b4e12bb5bd35b0ee4a1
MD5 hash: 07e6132799f7f0cce910b46de3a4478d
humanhash: sink-texas-georgia-xray
File name:1.sh
Download: download sample
Signature Mirai
File size:3'314 bytes
First seen:2025-07-30 22:23:07 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:i2Zh2wf2/l2AH2iT22z2zl2FZ2G3L2hF2on2Ur2bd2l9lBgJs2gbk:nZQwO/0AWiC2iz0FIGKhUo2U6bsl9lBi
TLSH T1086171FA13414A3B9CEA8AE332BC4424614345EB64CF1F759BDC38E61CADECDAC45642
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.15.36.159/00101010101001/morte.x86n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.mipsn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.arcn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.i468n/an/an/a
http://194.15.36.159/00101010101001/morte.i686n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.x86_64n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.mpsln/an/amirai opendir
http://194.15.36.159/00101010101001/morte.armn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.arm5n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.arm6n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.arm7n/an/amirai opendir
http://194.15.36.159/00101010101001/morte.ppcn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.spcn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.m68kn/an/amirai opendir
http://194.15.36.159/00101010101001/morte.sh4n/an/amirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=ed5e744d-1900-0000-604b-451041090000 pid=2369 /usr/bin/sudo guuid=231f1750-1900-0000-604b-451047090000 pid=2375 /tmp/sample.bin guuid=ed5e744d-1900-0000-604b-451041090000 pid=2369->guuid=231f1750-1900-0000-604b-451047090000 pid=2375 execve guuid=32939550-1900-0000-604b-451049090000 pid=2377 /usr/bin/cp guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=32939550-1900-0000-604b-451049090000 pid=2377 execve guuid=f9d21d57-1900-0000-604b-451054090000 pid=2388 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f9d21d57-1900-0000-604b-451054090000 pid=2388 execve guuid=f07b095a-1900-0000-604b-45105c090000 pid=2396 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f07b095a-1900-0000-604b-45105c090000 pid=2396 execve guuid=14f2ff62-1900-0000-604b-45106a090000 pid=2410 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=14f2ff62-1900-0000-604b-45106a090000 pid=2410 execve guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411 /tmp/morte.x86 net guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411 execve guuid=bf899890-1a00-0000-604b-4510bf0b0000 pid=3007 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=bf899890-1a00-0000-604b-4510bf0b0000 pid=3007 execve guuid=8f9b0c91-1a00-0000-604b-4510c00b0000 pid=3008 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=8f9b0c91-1a00-0000-604b-4510c00b0000 pid=3008 execve guuid=30bb2394-1a00-0000-604b-4510c80b0000 pid=3016 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=30bb2394-1a00-0000-604b-4510c80b0000 pid=3016 execve guuid=e1b1489b-1a00-0000-604b-4510d40b0000 pid=3028 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=e1b1489b-1a00-0000-604b-4510d40b0000 pid=3028 execve guuid=b4c8899b-1a00-0000-604b-4510d50b0000 pid=3029 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=b4c8899b-1a00-0000-604b-4510d50b0000 pid=3029 clone guuid=5fc11d9c-1a00-0000-604b-4510d90b0000 pid=3033 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=5fc11d9c-1a00-0000-604b-4510d90b0000 pid=3033 execve guuid=47f5639c-1a00-0000-604b-4510da0b0000 pid=3034 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=47f5639c-1a00-0000-604b-4510da0b0000 pid=3034 execve guuid=26ad9c9f-1a00-0000-604b-4510e40b0000 pid=3044 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=26ad9c9f-1a00-0000-604b-4510e40b0000 pid=3044 execve guuid=09674ca5-1a00-0000-604b-4510f40b0000 pid=3060 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=09674ca5-1a00-0000-604b-4510f40b0000 pid=3060 execve guuid=a2eebba5-1a00-0000-604b-4510f70b0000 pid=3063 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a2eebba5-1a00-0000-604b-4510f70b0000 pid=3063 clone guuid=a684b6a6-1a00-0000-604b-4510fc0b0000 pid=3068 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a684b6a6-1a00-0000-604b-4510fc0b0000 pid=3068 execve guuid=766548a8-1a00-0000-604b-4510020c0000 pid=3074 /usr/bin/wget net send-data guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=766548a8-1a00-0000-604b-4510020c0000 pid=3074 execve guuid=37f443aa-1a00-0000-604b-4510080c0000 pid=3080 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=37f443aa-1a00-0000-604b-4510080c0000 pid=3080 execve guuid=8fc30caf-1a00-0000-604b-4510130c0000 pid=3091 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=8fc30caf-1a00-0000-604b-4510130c0000 pid=3091 execve guuid=73da49af-1a00-0000-604b-4510150c0000 pid=3093 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=73da49af-1a00-0000-604b-4510150c0000 pid=3093 clone guuid=36aa71af-1a00-0000-604b-4510160c0000 pid=3094 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=36aa71af-1a00-0000-604b-4510160c0000 pid=3094 execve guuid=7399b2af-1a00-0000-604b-4510180c0000 pid=3096 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=7399b2af-1a00-0000-604b-4510180c0000 pid=3096 execve guuid=2bb899b2-1a00-0000-604b-4510200c0000 pid=3104 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=2bb899b2-1a00-0000-604b-4510200c0000 pid=3104 execve guuid=240ce6b5-1a00-0000-604b-4510290c0000 pid=3113 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=240ce6b5-1a00-0000-604b-4510290c0000 pid=3113 execve guuid=f6092cb6-1a00-0000-604b-45102b0c0000 pid=3115 /tmp/morte.i686 net guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f6092cb6-1a00-0000-604b-45102b0c0000 pid=3115 execve guuid=9d19012e-1b00-0000-604b-4510c50c0000 pid=3269 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=9d19012e-1b00-0000-604b-4510c50c0000 pid=3269 execve guuid=94a04d2e-1b00-0000-604b-4510c70c0000 pid=3271 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=94a04d2e-1b00-0000-604b-4510c70c0000 pid=3271 execve guuid=cbd08a30-1b00-0000-604b-4510cb0c0000 pid=3275 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=cbd08a30-1b00-0000-604b-4510cb0c0000 pid=3275 execve guuid=72f78835-1b00-0000-604b-4510d30c0000 pid=3283 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=72f78835-1b00-0000-604b-4510d30c0000 pid=3283 execve guuid=be2fd635-1b00-0000-604b-4510d60c0000 pid=3286 /tmp/morte.x86_64 mprotect-exec net guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=be2fd635-1b00-0000-604b-4510d60c0000 pid=3286 execve guuid=f2e196ad-1b00-0000-604b-4510e30d0000 pid=3555 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f2e196ad-1b00-0000-604b-4510e30d0000 pid=3555 execve guuid=e08c03ae-1b00-0000-604b-4510e50d0000 pid=3557 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=e08c03ae-1b00-0000-604b-4510e50d0000 pid=3557 execve guuid=57b6edb0-1b00-0000-604b-4510eb0d0000 pid=3563 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=57b6edb0-1b00-0000-604b-4510eb0d0000 pid=3563 execve guuid=f308c7b7-1b00-0000-604b-4510ed0d0000 pid=3565 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f308c7b7-1b00-0000-604b-4510ed0d0000 pid=3565 execve guuid=b78534b8-1b00-0000-604b-4510ee0d0000 pid=3566 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=b78534b8-1b00-0000-604b-4510ee0d0000 pid=3566 clone guuid=9872b7ba-1b00-0000-604b-4510f60d0000 pid=3574 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=9872b7ba-1b00-0000-604b-4510f60d0000 pid=3574 execve guuid=09d702bb-1b00-0000-604b-4510f80d0000 pid=3576 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=09d702bb-1b00-0000-604b-4510f80d0000 pid=3576 execve guuid=832727bd-1b00-0000-604b-4510ff0d0000 pid=3583 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=832727bd-1b00-0000-604b-4510ff0d0000 pid=3583 execve guuid=e1ec23c0-1b00-0000-604b-4510090e0000 pid=3593 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=e1ec23c0-1b00-0000-604b-4510090e0000 pid=3593 execve guuid=b96573c0-1b00-0000-604b-45100a0e0000 pid=3594 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=b96573c0-1b00-0000-604b-45100a0e0000 pid=3594 clone guuid=4f9c09c2-1b00-0000-604b-4510110e0000 pid=3601 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=4f9c09c2-1b00-0000-604b-4510110e0000 pid=3601 execve guuid=57b5b0c5-1b00-0000-604b-4510180e0000 pid=3608 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=57b5b0c5-1b00-0000-604b-4510180e0000 pid=3608 execve guuid=55322bc8-1b00-0000-604b-45101f0e0000 pid=3615 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=55322bc8-1b00-0000-604b-45101f0e0000 pid=3615 execve guuid=6c848bce-1b00-0000-604b-45102f0e0000 pid=3631 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=6c848bce-1b00-0000-604b-45102f0e0000 pid=3631 execve guuid=8330fdce-1b00-0000-604b-4510310e0000 pid=3633 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=8330fdce-1b00-0000-604b-4510310e0000 pid=3633 clone guuid=608794cf-1b00-0000-604b-4510340e0000 pid=3636 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=608794cf-1b00-0000-604b-4510340e0000 pid=3636 execve guuid=a816f4cf-1b00-0000-604b-4510360e0000 pid=3638 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a816f4cf-1b00-0000-604b-4510360e0000 pid=3638 execve guuid=b74fb8d2-1b00-0000-604b-45103d0e0000 pid=3645 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=b74fb8d2-1b00-0000-604b-45103d0e0000 pid=3645 execve guuid=a54035d8-1b00-0000-604b-4510480e0000 pid=3656 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a54035d8-1b00-0000-604b-4510480e0000 pid=3656 execve guuid=54959dd8-1b00-0000-604b-4510490e0000 pid=3657 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=54959dd8-1b00-0000-604b-4510490e0000 pid=3657 clone guuid=a6705cd9-1b00-0000-604b-45104b0e0000 pid=3659 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a6705cd9-1b00-0000-604b-45104b0e0000 pid=3659 execve guuid=d20649da-1b00-0000-604b-45104c0e0000 pid=3660 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=d20649da-1b00-0000-604b-45104c0e0000 pid=3660 execve guuid=dca31add-1b00-0000-604b-4510540e0000 pid=3668 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=dca31add-1b00-0000-604b-4510540e0000 pid=3668 execve guuid=499239e1-1b00-0000-604b-4510620e0000 pid=3682 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=499239e1-1b00-0000-604b-4510620e0000 pid=3682 execve guuid=06c890e1-1b00-0000-604b-4510630e0000 pid=3683 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=06c890e1-1b00-0000-604b-4510630e0000 pid=3683 clone guuid=5f6266e2-1b00-0000-604b-4510680e0000 pid=3688 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=5f6266e2-1b00-0000-604b-4510680e0000 pid=3688 execve guuid=d965cae4-1b00-0000-604b-4510710e0000 pid=3697 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=d965cae4-1b00-0000-604b-4510710e0000 pid=3697 execve guuid=c27838e7-1b00-0000-604b-4510780e0000 pid=3704 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=c27838e7-1b00-0000-604b-4510780e0000 pid=3704 execve guuid=521080eb-1b00-0000-604b-4510820e0000 pid=3714 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=521080eb-1b00-0000-604b-4510820e0000 pid=3714 execve guuid=d04111ec-1b00-0000-604b-4510840e0000 pid=3716 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=d04111ec-1b00-0000-604b-4510840e0000 pid=3716 clone guuid=2d36f1ec-1b00-0000-604b-45108a0e0000 pid=3722 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=2d36f1ec-1b00-0000-604b-45108a0e0000 pid=3722 execve guuid=b5c672ed-1b00-0000-604b-45108b0e0000 pid=3723 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=b5c672ed-1b00-0000-604b-45108b0e0000 pid=3723 execve guuid=cafac8f0-1b00-0000-604b-4510940e0000 pid=3732 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=cafac8f0-1b00-0000-604b-4510940e0000 pid=3732 execve guuid=634376f5-1b00-0000-604b-45109f0e0000 pid=3743 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=634376f5-1b00-0000-604b-45109f0e0000 pid=3743 execve guuid=d906b6f5-1b00-0000-604b-4510a10e0000 pid=3745 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=d906b6f5-1b00-0000-604b-4510a10e0000 pid=3745 clone guuid=769b35f6-1b00-0000-604b-4510a50e0000 pid=3749 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=769b35f6-1b00-0000-604b-4510a50e0000 pid=3749 execve guuid=5acd7ff6-1b00-0000-604b-4510a60e0000 pid=3750 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=5acd7ff6-1b00-0000-604b-4510a60e0000 pid=3750 execve guuid=986b2df9-1b00-0000-604b-4510b30e0000 pid=3763 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=986b2df9-1b00-0000-604b-4510b30e0000 pid=3763 execve guuid=eb57dcfc-1b00-0000-604b-4510c50e0000 pid=3781 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=eb57dcfc-1b00-0000-604b-4510c50e0000 pid=3781 execve guuid=40521afd-1b00-0000-604b-4510c60e0000 pid=3782 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=40521afd-1b00-0000-604b-4510c60e0000 pid=3782 clone guuid=f4aeb3fd-1b00-0000-604b-4510cb0e0000 pid=3787 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=f4aeb3fd-1b00-0000-604b-4510cb0e0000 pid=3787 execve guuid=e1a5a8ff-1b00-0000-604b-4510d70e0000 pid=3799 /usr/bin/wget net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=e1a5a8ff-1b00-0000-604b-4510d70e0000 pid=3799 execve guuid=655e0202-1c00-0000-604b-4510e20e0000 pid=3810 /usr/bin/curl net send-data write-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=655e0202-1c00-0000-604b-4510e20e0000 pid=3810 execve guuid=a36a9b05-1c00-0000-604b-4510f30e0000 pid=3827 /usr/bin/chmod guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=a36a9b05-1c00-0000-604b-4510f30e0000 pid=3827 execve guuid=05f2ec05-1c00-0000-604b-4510f50e0000 pid=3829 /usr/bin/bash guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=05f2ec05-1c00-0000-604b-4510f50e0000 pid=3829 clone guuid=1e9da506-1c00-0000-604b-4510f80e0000 pid=3832 /usr/bin/rm delete-file guuid=231f1750-1900-0000-604b-451047090000 pid=2375->guuid=1e9da506-1c00-0000-604b-4510f80e0000 pid=3832 execve 0cd9ff9a-a531-56f6-b156-923d9a234b66 194.15.36.159:80 guuid=f9d21d57-1900-0000-604b-451054090000 pid=2388->0cd9ff9a-a531-56f6-b156-923d9a234b66 send: 152B guuid=f07b095a-1900-0000-604b-45105c090000 pid=2396->0cd9ff9a-a531-56f6-b156-923d9a234b66 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=05d5fb63-1900-0000-604b-45106d090000 pid=2413 /tmp/morte.x86 guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411->guuid=05d5fb63-1900-0000-604b-45106d090000 pid=2413 clone guuid=bf838590-1a00-0000-604b-4510bd0b0000 pid=3005 /tmp/morte.x86 guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411->guuid=bf838590-1a00-0000-604b-4510bd0b0000 pid=3005 clone guuid=2f178b90-1a00-0000-604b-4510be0b0000 pid=3006 /tmp/morte.x86 net send-data zombie guuid=3b8c4f63-1900-0000-604b-45106b090000 pid=2411->guuid=2f178b90-1a00-0000-604b-4510be0b0000 pid=3006 clone guuid=fb280464-1900-0000-604b-45106e090000 pid=2414 /tmp/morte.x86 guuid=05d5fb63-1900-0000-604b-45106d090000 pid=2413->guuid=fb280464-1900-0000-604b-45106e090000 pid=2414 clone guuid=b7960b64-1900-0000-604b-45106f090000 pid=2415 /tmp/morte.x86 dns net send-data zombie guuid=05d5fb63-1900-0000-604b-45106d090000 pid=2413->guuid=b7960b64-1900-0000-604b-45106f090000 pid=2415 clone guuid=b7960b64-1900-0000-604b-45106f090000 pid=2415->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B 00cb50cf-cfea-501b-b2ea-c0cab3b44dca meow2137.duckdns.org:12121 guuid=b7960b64-1900-0000-604b-45106f090000 pid=2415->00cb50cf-cfea-501b-b2ea-c0cab3b44dca send: 15B guuid=2f178b90-1a00-0000-604b-4510be0b0000 pid=3006->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 195B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=2f178b90-1a00-0000-604b-4510be0b0000 pid=3006->310a0ed0-c544-54ca-bf3f-fca55e459297 con c06dfe17-71f7-54d7-8c0e-64afa255417c meow2137.duckdns.org:80 guuid=8f9b0c91-1a00-0000-604b-4510c00b0000 pid=3008->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=30bb2394-1a00-0000-604b-4510c80b0000 pid=3016->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=47f5639c-1a00-0000-604b-4510da0b0000 pid=3034->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 152B guuid=26ad9c9f-1a00-0000-604b-4510e40b0000 pid=3044->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 101B guuid=766548a8-1a00-0000-604b-4510020c0000 pid=3074->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=37f443aa-1a00-0000-604b-4510080c0000 pid=3080->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=7399b2af-1a00-0000-604b-4510180c0000 pid=3096->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=2bb899b2-1a00-0000-604b-4510200c0000 pid=3104->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=f6092cb6-1a00-0000-604b-45102b0c0000 pid=3115->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=f6092cb6-1a00-0000-604b-45102b0c0000 pid=3115->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=94a04d2e-1b00-0000-604b-4510c70c0000 pid=3271->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 155B guuid=cbd08a30-1b00-0000-604b-4510cb0c0000 pid=3275->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 104B guuid=be2fd635-1b00-0000-604b-4510d60c0000 pid=3286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be2fd635-1b00-0000-604b-4510d60c0000 pid=3286->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=e08c03ae-1b00-0000-604b-4510e50d0000 pid=3557->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=57b6edb0-1b00-0000-604b-4510eb0d0000 pid=3563->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=09d702bb-1b00-0000-604b-4510f80d0000 pid=3576->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 152B guuid=832727bd-1b00-0000-604b-4510ff0d0000 pid=3583->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 101B guuid=57b5b0c5-1b00-0000-604b-4510180e0000 pid=3608->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=55322bc8-1b00-0000-604b-45101f0e0000 pid=3615->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=a816f4cf-1b00-0000-604b-4510360e0000 pid=3638->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=b74fb8d2-1b00-0000-604b-45103d0e0000 pid=3645->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=d20649da-1b00-0000-604b-45104c0e0000 pid=3660->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=dca31add-1b00-0000-604b-4510540e0000 pid=3668->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=d965cae4-1b00-0000-604b-4510710e0000 pid=3697->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 152B guuid=c27838e7-1b00-0000-604b-4510780e0000 pid=3704->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 101B guuid=b5c672ed-1b00-0000-604b-45108b0e0000 pid=3723->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 152B guuid=cafac8f0-1b00-0000-604b-4510940e0000 pid=3732->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 101B guuid=5acd7ff6-1b00-0000-604b-4510a60e0000 pid=3750->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 153B guuid=986b2df9-1b00-0000-604b-4510b30e0000 pid=3763->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 102B guuid=e1a5a8ff-1b00-0000-604b-4510d70e0000 pid=3799->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 152B guuid=655e0202-1c00-0000-604b-4510e20e0000 pid=3810->c06dfe17-71f7-54d7-8c0e-64afa255417c send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-30 22:23:20 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
meow2137.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 16f7bd0f48bcdfbf0206735e81c7ee5c5ab2b8fa92b120fa2eeb684d16af40e2

(this sample)

  
Delivery method
Distributed via web download

Comments