MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f41a835cb6bc86899353a027422a36158febfc62eca6f521916431b42dbeef2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 2f41a835cb6bc86899353a027422a36158febfc62eca6f521916431b42dbeef2
SHA3-384 hash: ae734dec22d5222a205ee4270e2cf6a034d48bee156c7c1909a119cdc47e7d45f88f9dfe7dbe5adaf9eb2f228b97786a
SHA1 hash: 928e4ebb228053b175601d73d9cc5be1b9723cfb
MD5 hash: c5e0865de650b1d4089632dfb9894cfb
humanhash: whiskey-ack-apart-spring
File name:1.sh
Download: download sample
Signature Mirai
File size:3'254 bytes
First seen:2025-08-23 02:48:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:iPADPb5PC3PL5P5tPBVPGfP0bPZ5LPYfPvhP71PGPPjejBgJsP3hk:4kBgJJ
TLSH T1516171FA135146775CAA89D332AC440462C048AB64CE5F795BDC38F98CAEFDE2C46691
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://163.5.63.89/00101010101001/morte.x86134264c8865b586a194591967c2c1d9238fdd11bb7d507532183fade84cc3f4c Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.mips76e8938a58555924b03dfc826fcf6b3ed2d20ed7f1ec6f61e874ca3cec49fc43 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.arc6aaa42b794d3f8987f104542bb2ddb9cfe7c377e833dc2f9fbd24647bd2060f9 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.i468n/an/aelf ua-wget
http://163.5.63.89/00101010101001/morte.i68650e67f52b8353b134b6118899bee8413547cb38c3a915d5c3b3b1ec5431a4464 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.x86_64f13188e81cac3f55bd0a4c499a8b524cd7656b77130997a123c4516960e55e45 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.mpsld7b5d0f754163b8b27c8a649a38938c6efeed0f6b52cf938b76c3a9bbbd8bb2e Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.armcc87a411276a5960ddd7c751b5b7f6205db0f26e2db2180599520fb2d873c701 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.arm526d4b29a52ec7dfc59e6e66a0a9d8759e1cc3ed255aef690bed53485ea77d91b Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.arm6dfdd3fd2c40326aa104fe95c28a671f66dae57caffb2ea390ba8f2726d459a7f Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.arm7ca2a562bd8606f953e1249ad1f8811db47279736057cb66432ccd4a908593c51 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.ppc1f732524278e5b2af1e78751c40c1d0fe1db1188fe39db7d741e328bdf734e72 Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.spc68a55330c8b7eb8b6220475aeebd7cbd4c41f27d42889c375ff0a8e6fb0a113a Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.m68k3240804c076c7fabd619b1e7aaef80e263568ce358039cc52cf4e37554720fcf Miraielf mirai ua-wget
http://163.5.63.89/00101010101001/morte.sh4e80eef4929318ff24d31170fee00d2ff8f9fceb27b3f8ca96f1a07206345cc6f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-22T23:56:00Z UTC
Last seen:
2025-08-22T23:56:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f7c083b1-1600-0000-551a-569c940c0000 pid=3220 /usr/bin/sudo guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221 /tmp/sample.bin guuid=f7c083b1-1600-0000-551a-569c940c0000 pid=3220->guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221 execve guuid=2df602b5-1600-0000-551a-569c960c0000 pid=3222 /usr/bin/cp guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=2df602b5-1600-0000-551a-569c960c0000 pid=3222 execve guuid=e64283bb-1600-0000-551a-569c9b0c0000 pid=3227 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=e64283bb-1600-0000-551a-569c9b0c0000 pid=3227 execve guuid=ad761fc1-1600-0000-551a-569ca80c0000 pid=3240 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=ad761fc1-1600-0000-551a-569ca80c0000 pid=3240 execve guuid=fed72dd0-1600-0000-551a-569cc20c0000 pid=3266 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=fed72dd0-1600-0000-551a-569cc20c0000 pid=3266 execve guuid=ec5392d0-1600-0000-551a-569cc30c0000 pid=3267 /tmp/morte.x86 net guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=ec5392d0-1600-0000-551a-569cc30c0000 pid=3267 execve guuid=b80273d1-1600-0000-551a-569cc80c0000 pid=3272 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=b80273d1-1600-0000-551a-569cc80c0000 pid=3272 execve guuid=97c1ffd1-1600-0000-551a-569cca0c0000 pid=3274 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=97c1ffd1-1600-0000-551a-569cca0c0000 pid=3274 execve guuid=76af9ad7-1600-0000-551a-569cdc0c0000 pid=3292 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=76af9ad7-1600-0000-551a-569cdc0c0000 pid=3292 execve guuid=c8d997dd-1600-0000-551a-569cef0c0000 pid=3311 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=c8d997dd-1600-0000-551a-569cef0c0000 pid=3311 execve guuid=4011d3dd-1600-0000-551a-569cf10c0000 pid=3313 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=4011d3dd-1600-0000-551a-569cf10c0000 pid=3313 clone guuid=578d50de-1600-0000-551a-569cf50c0000 pid=3317 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=578d50de-1600-0000-551a-569cf50c0000 pid=3317 execve guuid=92b191de-1600-0000-551a-569cf70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=92b191de-1600-0000-551a-569cf70c0000 pid=3319 execve guuid=e8007ce4-1600-0000-551a-569c020d0000 pid=3330 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=e8007ce4-1600-0000-551a-569c020d0000 pid=3330 execve guuid=296db1ec-1600-0000-551a-569c070d0000 pid=3335 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=296db1ec-1600-0000-551a-569c070d0000 pid=3335 execve guuid=dc2e09ed-1600-0000-551a-569c0a0d0000 pid=3338 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=dc2e09ed-1600-0000-551a-569c0a0d0000 pid=3338 clone guuid=fc779ded-1600-0000-551a-569c0e0d0000 pid=3342 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=fc779ded-1600-0000-551a-569c0e0d0000 pid=3342 execve guuid=08bb96ef-1600-0000-551a-569c120d0000 pid=3346 /usr/bin/wget net send-data guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=08bb96ef-1600-0000-551a-569c120d0000 pid=3346 execve guuid=48fbc2f2-1600-0000-551a-569c190d0000 pid=3353 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=48fbc2f2-1600-0000-551a-569c190d0000 pid=3353 execve guuid=740afef8-1600-0000-551a-569c250d0000 pid=3365 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=740afef8-1600-0000-551a-569c250d0000 pid=3365 execve guuid=bec33df9-1600-0000-551a-569c270d0000 pid=3367 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=bec33df9-1600-0000-551a-569c270d0000 pid=3367 clone guuid=bb6e6bf9-1600-0000-551a-569c290d0000 pid=3369 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=bb6e6bf9-1600-0000-551a-569c290d0000 pid=3369 execve guuid=8c47abf9-1600-0000-551a-569c2b0d0000 pid=3371 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=8c47abf9-1600-0000-551a-569c2b0d0000 pid=3371 execve guuid=79e662fd-1600-0000-551a-569c380d0000 pid=3384 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=79e662fd-1600-0000-551a-569c380d0000 pid=3384 execve guuid=2375b206-1700-0000-551a-569c4f0d0000 pid=3407 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=2375b206-1700-0000-551a-569c4f0d0000 pid=3407 execve guuid=d0a41a07-1700-0000-551a-569c510d0000 pid=3409 /tmp/morte.i686 net guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=d0a41a07-1700-0000-551a-569c510d0000 pid=3409 execve guuid=289dd707-1700-0000-551a-569c560d0000 pid=3414 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=289dd707-1700-0000-551a-569c560d0000 pid=3414 execve guuid=3e1d4908-1700-0000-551a-569c590d0000 pid=3417 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=3e1d4908-1700-0000-551a-569c590d0000 pid=3417 execve guuid=a7b2c60d-1700-0000-551a-569c6b0d0000 pid=3435 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=a7b2c60d-1700-0000-551a-569c6b0d0000 pid=3435 execve guuid=c1bbe217-1700-0000-551a-569c8e0d0000 pid=3470 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=c1bbe217-1700-0000-551a-569c8e0d0000 pid=3470 execve guuid=708d2818-1700-0000-551a-569c900d0000 pid=3472 /tmp/morte.x86_64 mprotect-exec net guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=708d2818-1700-0000-551a-569c900d0000 pid=3472 execve guuid=f2559c18-1700-0000-551a-569c950d0000 pid=3477 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=f2559c18-1700-0000-551a-569c950d0000 pid=3477 execve guuid=dae9e118-1700-0000-551a-569c980d0000 pid=3480 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=dae9e118-1700-0000-551a-569c980d0000 pid=3480 execve guuid=5f52b91d-1700-0000-551a-569cad0d0000 pid=3501 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=5f52b91d-1700-0000-551a-569cad0d0000 pid=3501 execve guuid=124e0323-1700-0000-551a-569cc10d0000 pid=3521 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=124e0323-1700-0000-551a-569cc10d0000 pid=3521 execve guuid=a98c5b23-1700-0000-551a-569cc20d0000 pid=3522 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=a98c5b23-1700-0000-551a-569cc20d0000 pid=3522 clone guuid=20190924-1700-0000-551a-569cc40d0000 pid=3524 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=20190924-1700-0000-551a-569cc40d0000 pid=3524 execve guuid=2afbdb24-1700-0000-551a-569cc50d0000 pid=3525 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=2afbdb24-1700-0000-551a-569cc50d0000 pid=3525 execve guuid=22089d29-1700-0000-551a-569cce0d0000 pid=3534 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=22089d29-1700-0000-551a-569cce0d0000 pid=3534 execve guuid=02110730-1700-0000-551a-569cd90d0000 pid=3545 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=02110730-1700-0000-551a-569cd90d0000 pid=3545 execve guuid=7dfd5f30-1700-0000-551a-569cdb0d0000 pid=3547 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=7dfd5f30-1700-0000-551a-569cdb0d0000 pid=3547 clone guuid=41240b31-1700-0000-551a-569cde0d0000 pid=3550 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=41240b31-1700-0000-551a-569cde0d0000 pid=3550 execve guuid=701a8331-1700-0000-551a-569cdf0d0000 pid=3551 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=701a8331-1700-0000-551a-569cdf0d0000 pid=3551 execve guuid=27c5aa35-1700-0000-551a-569ce80d0000 pid=3560 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=27c5aa35-1700-0000-551a-569ce80d0000 pid=3560 execve guuid=60ad3c3b-1700-0000-551a-569cf30d0000 pid=3571 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=60ad3c3b-1700-0000-551a-569cf30d0000 pid=3571 execve guuid=d714b83b-1700-0000-551a-569cf60d0000 pid=3574 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=d714b83b-1700-0000-551a-569cf60d0000 pid=3574 clone guuid=e79b873c-1700-0000-551a-569cfb0d0000 pid=3579 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=e79b873c-1700-0000-551a-569cfb0d0000 pid=3579 execve guuid=9485ee3c-1700-0000-551a-569cfe0d0000 pid=3582 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=9485ee3c-1700-0000-551a-569cfe0d0000 pid=3582 execve guuid=ad64b941-1700-0000-551a-569c0e0e0000 pid=3598 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=ad64b941-1700-0000-551a-569c0e0e0000 pid=3598 execve guuid=2dcf9b49-1700-0000-551a-569c230e0000 pid=3619 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=2dcf9b49-1700-0000-551a-569c230e0000 pid=3619 execve guuid=9f5d2e4a-1700-0000-551a-569c240e0000 pid=3620 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=9f5d2e4a-1700-0000-551a-569c240e0000 pid=3620 clone guuid=f6b66f4b-1700-0000-551a-569c260e0000 pid=3622 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=f6b66f4b-1700-0000-551a-569c260e0000 pid=3622 execve guuid=2de95a4e-1700-0000-551a-569c280e0000 pid=3624 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=2de95a4e-1700-0000-551a-569c280e0000 pid=3624 execve guuid=542c2554-1700-0000-551a-569c320e0000 pid=3634 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=542c2554-1700-0000-551a-569c320e0000 pid=3634 execve guuid=9ad7e15a-1700-0000-551a-569c3e0e0000 pid=3646 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=9ad7e15a-1700-0000-551a-569c3e0e0000 pid=3646 execve guuid=b46d5b5b-1700-0000-551a-569c3f0e0000 pid=3647 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=b46d5b5b-1700-0000-551a-569c3f0e0000 pid=3647 clone guuid=7cb95d5c-1700-0000-551a-569c410e0000 pid=3649 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=7cb95d5c-1700-0000-551a-569c410e0000 pid=3649 execve guuid=caab5763-1700-0000-551a-569c430e0000 pid=3651 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=caab5763-1700-0000-551a-569c430e0000 pid=3651 execve guuid=1a39c168-1700-0000-551a-569c4c0e0000 pid=3660 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=1a39c168-1700-0000-551a-569c4c0e0000 pid=3660 execve guuid=3973656e-1700-0000-551a-569c560e0000 pid=3670 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=3973656e-1700-0000-551a-569c560e0000 pid=3670 execve guuid=408bd46e-1700-0000-551a-569c580e0000 pid=3672 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=408bd46e-1700-0000-551a-569c580e0000 pid=3672 clone guuid=b6401d70-1700-0000-551a-569c5f0e0000 pid=3679 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=b6401d70-1700-0000-551a-569c5f0e0000 pid=3679 execve guuid=6aee8370-1700-0000-551a-569c600e0000 pid=3680 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=6aee8370-1700-0000-551a-569c600e0000 pid=3680 execve guuid=4b05df75-1700-0000-551a-569c710e0000 pid=3697 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=4b05df75-1700-0000-551a-569c710e0000 pid=3697 execve guuid=29edf97c-1700-0000-551a-569c830e0000 pid=3715 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=29edf97c-1700-0000-551a-569c830e0000 pid=3715 execve guuid=de5e867d-1700-0000-551a-569c850e0000 pid=3717 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=de5e867d-1700-0000-551a-569c850e0000 pid=3717 clone guuid=a049967e-1700-0000-551a-569c8a0e0000 pid=3722 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=a049967e-1700-0000-551a-569c8a0e0000 pid=3722 execve guuid=6069fe7e-1700-0000-551a-569c8b0e0000 pid=3723 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=6069fe7e-1700-0000-551a-569c8b0e0000 pid=3723 execve guuid=5f8c2185-1700-0000-551a-569c9c0e0000 pid=3740 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=5f8c2185-1700-0000-551a-569c9c0e0000 pid=3740 execve guuid=5e2cd08c-1700-0000-551a-569cb10e0000 pid=3761 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=5e2cd08c-1700-0000-551a-569cb10e0000 pid=3761 execve guuid=fe1c418d-1700-0000-551a-569cb30e0000 pid=3763 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=fe1c418d-1700-0000-551a-569cb30e0000 pid=3763 clone guuid=db680c8e-1700-0000-551a-569cb70e0000 pid=3767 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=db680c8e-1700-0000-551a-569cb70e0000 pid=3767 execve guuid=0728678e-1700-0000-551a-569cb80e0000 pid=3768 /usr/bin/wget net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=0728678e-1700-0000-551a-569cb80e0000 pid=3768 execve guuid=74c07e93-1700-0000-551a-569cca0e0000 pid=3786 /usr/bin/curl net send-data write-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=74c07e93-1700-0000-551a-569cca0e0000 pid=3786 execve guuid=77d8ff9a-1700-0000-551a-569ce30e0000 pid=3811 /usr/bin/chmod guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=77d8ff9a-1700-0000-551a-569ce30e0000 pid=3811 execve guuid=ee41619b-1700-0000-551a-569ce50e0000 pid=3813 /usr/bin/bash guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=ee41619b-1700-0000-551a-569ce50e0000 pid=3813 clone guuid=956eab9d-1700-0000-551a-569cee0e0000 pid=3822 /usr/bin/rm delete-file guuid=406f5fb4-1600-0000-551a-569c950c0000 pid=3221->guuid=956eab9d-1700-0000-551a-569cee0e0000 pid=3822 execve e5539266-383f-59da-8a17-abadeb01262d 163.5.63.89:80 guuid=e64283bb-1600-0000-551a-569c9b0c0000 pid=3227->e5539266-383f-59da-8a17-abadeb01262d send: 150B guuid=ad761fc1-1600-0000-551a-569ca80c0000 pid=3240->e5539266-383f-59da-8a17-abadeb01262d send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ec5392d0-1600-0000-551a-569cc30c0000 pid=3267->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7b7e63d1-1600-0000-551a-569cc50c0000 pid=3269 /tmp/morte.x86 guuid=ec5392d0-1600-0000-551a-569cc30c0000 pid=3267->guuid=7b7e63d1-1600-0000-551a-569cc50c0000 pid=3269 clone guuid=db9468d1-1600-0000-551a-569cc60c0000 pid=3270 /tmp/morte.x86 delete-file dns net send-data zombie guuid=ec5392d0-1600-0000-551a-569cc30c0000 pid=3267->guuid=db9468d1-1600-0000-551a-569cc60c0000 pid=3270 clone guuid=db9468d1-1600-0000-551a-569cc60c0000 pid=3270->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B e318023d-5577-5419-a5ff-2b20750ab986 bbos.p-e.kr:12121 guuid=db9468d1-1600-0000-551a-569cc60c0000 pid=3270->e318023d-5577-5419-a5ff-2b20750ab986 send: 15B guuid=17e972d1-1600-0000-551a-569cc70c0000 pid=3271 /tmp/morte.x86 guuid=db9468d1-1600-0000-551a-569cc60c0000 pid=3270->guuid=17e972d1-1600-0000-551a-569cc70c0000 pid=3271 clone guuid=97c1ffd1-1600-0000-551a-569cca0c0000 pid=3274->e5539266-383f-59da-8a17-abadeb01262d send: 151B guuid=76af9ad7-1600-0000-551a-569cdc0c0000 pid=3292->e5539266-383f-59da-8a17-abadeb01262d send: 100B guuid=92b191de-1600-0000-551a-569cf70c0000 pid=3319->e5539266-383f-59da-8a17-abadeb01262d send: 150B guuid=e8007ce4-1600-0000-551a-569c020d0000 pid=3330->e5539266-383f-59da-8a17-abadeb01262d send: 99B guuid=08bb96ef-1600-0000-551a-569c120d0000 pid=3346->e5539266-383f-59da-8a17-abadeb01262d send: 151B guuid=48fbc2f2-1600-0000-551a-569c190d0000 pid=3353->e5539266-383f-59da-8a17-abadeb01262d send: 100B guuid=8c47abf9-1600-0000-551a-569c2b0d0000 pid=3371->e5539266-383f-59da-8a17-abadeb01262d send: 151B guuid=79e662fd-1600-0000-551a-569c380d0000 pid=3384->e5539266-383f-59da-8a17-abadeb01262d send: 100B guuid=d0a41a07-1700-0000-551a-569c510d0000 pid=3409->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5145c907-1700-0000-551a-569c530d0000 pid=3411 /tmp/morte.i686 guuid=d0a41a07-1700-0000-551a-569c510d0000 pid=3409->guuid=5145c907-1700-0000-551a-569c530d0000 pid=3411 clone guuid=e38fce07-1700-0000-551a-569c540d0000 pid=3412 /tmp/morte.i686 delete-file zombie guuid=d0a41a07-1700-0000-551a-569c510d0000 pid=3409->guuid=e38fce07-1700-0000-551a-569c540d0000 pid=3412 clone guuid=81cfe707-1700-0000-551a-569c570d0000 pid=3415 /tmp/morte.i686 guuid=e38fce07-1700-0000-551a-569c540d0000 pid=3412->guuid=81cfe707-1700-0000-551a-569c570d0000 pid=3415 clone 5a30e090-3266-568a-b031-c36ff662af24 bbos.p-e.kr:80 guuid=3e1d4908-1700-0000-551a-569c590d0000 pid=3417->5a30e090-3266-568a-b031-c36ff662af24 send: 153B guuid=a7b2c60d-1700-0000-551a-569c6b0d0000 pid=3435->5a30e090-3266-568a-b031-c36ff662af24 send: 102B guuid=708d2818-1700-0000-551a-569c900d0000 pid=3472->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=caac9218-1700-0000-551a-569c930d0000 pid=3475 /tmp/morte.x86_64 guuid=708d2818-1700-0000-551a-569c900d0000 pid=3472->guuid=caac9218-1700-0000-551a-569c930d0000 pid=3475 clone guuid=90b49518-1700-0000-551a-569c940d0000 pid=3476 /tmp/morte.x86_64 dns net send-data zombie guuid=708d2818-1700-0000-551a-569c900d0000 pid=3472->guuid=90b49518-1700-0000-551a-569c940d0000 pid=3476 clone guuid=90b49518-1700-0000-551a-569c940d0000 pid=3476->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B guuid=90b49518-1700-0000-551a-569c940d0000 pid=3476->e318023d-5577-5419-a5ff-2b20750ab986 send: 22B guuid=eccea618-1700-0000-551a-569c960d0000 pid=3478 /tmp/morte.x86_64 guuid=90b49518-1700-0000-551a-569c940d0000 pid=3476->guuid=eccea618-1700-0000-551a-569c960d0000 pid=3478 clone guuid=dae9e118-1700-0000-551a-569c980d0000 pid=3480->5a30e090-3266-568a-b031-c36ff662af24 send: 151B guuid=5f52b91d-1700-0000-551a-569cad0d0000 pid=3501->5a30e090-3266-568a-b031-c36ff662af24 send: 100B guuid=2afbdb24-1700-0000-551a-569cc50d0000 pid=3525->5a30e090-3266-568a-b031-c36ff662af24 send: 150B guuid=22089d29-1700-0000-551a-569cce0d0000 pid=3534->5a30e090-3266-568a-b031-c36ff662af24 send: 99B guuid=701a8331-1700-0000-551a-569cdf0d0000 pid=3551->5a30e090-3266-568a-b031-c36ff662af24 send: 151B guuid=27c5aa35-1700-0000-551a-569ce80d0000 pid=3560->5a30e090-3266-568a-b031-c36ff662af24 send: 100B guuid=9485ee3c-1700-0000-551a-569cfe0d0000 pid=3582->5a30e090-3266-568a-b031-c36ff662af24 send: 151B guuid=ad64b941-1700-0000-551a-569c0e0e0000 pid=3598->5a30e090-3266-568a-b031-c36ff662af24 send: 100B guuid=2de95a4e-1700-0000-551a-569c280e0000 pid=3624->5a30e090-3266-568a-b031-c36ff662af24 send: 151B guuid=542c2554-1700-0000-551a-569c320e0000 pid=3634->5a30e090-3266-568a-b031-c36ff662af24 send: 100B guuid=caab5763-1700-0000-551a-569c430e0000 pid=3651->5a30e090-3266-568a-b031-c36ff662af24 send: 150B guuid=1a39c168-1700-0000-551a-569c4c0e0000 pid=3660->5a30e090-3266-568a-b031-c36ff662af24 send: 99B guuid=6aee8370-1700-0000-551a-569c600e0000 pid=3680->5a30e090-3266-568a-b031-c36ff662af24 send: 150B guuid=4b05df75-1700-0000-551a-569c710e0000 pid=3697->5a30e090-3266-568a-b031-c36ff662af24 send: 99B guuid=6069fe7e-1700-0000-551a-569c8b0e0000 pid=3723->5a30e090-3266-568a-b031-c36ff662af24 send: 151B guuid=5f8c2185-1700-0000-551a-569c9c0e0000 pid=3740->5a30e090-3266-568a-b031-c36ff662af24 send: 100B guuid=0728678e-1700-0000-551a-569cb80e0000 pid=3768->5a30e090-3266-568a-b031-c36ff662af24 send: 150B guuid=74c07e93-1700-0000-551a-569cca0e0000 pid=3786->5a30e090-3266-568a-b031-c36ff662af24 send: 99B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-23 02:49:33 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
bbos.p-e.kr
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2f41a835cb6bc86899353a027422a36158febfc62eca6f521916431b42dbeef2

(this sample)

  
Delivery method
Distributed via web download

Comments