MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3d2acd9571f1e62e42aaf6d34a320d96eb07a1d4b16cce9dc74885aeb0b03f4f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 3d2acd9571f1e62e42aaf6d34a320d96eb07a1d4b16cce9dc74885aeb0b03f4f
SHA3-384 hash: e18f8da7a9b9a795eabab870ad83e62e59a84a9bda3c4634a378e6815204d158333ca0349cfad5f514da678bcfd859dd
SHA1 hash: 8f095ba8a86dfaa659454697e3dbfa30a35d2c41
MD5 hash: 95f205501f8ec39971ff13e2ba4db664
humanhash: april-cup-blossom-steak
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-08-22 01:51:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It3ZsxbhTkFlf5msJTgNGgJX6JnLWbNIpKksNME3hDswZcGgJsAopk:iiTAPZZgN1qVLCJfR4wZBgJsZk
TLSH T1386185F61342493F9CAACED335A8C408B545C09B94CE5FBA5FEE24F60C4CEC96C41A52
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.215/00101010101001/morte.x86e8099bae8e84278b060f8651d0f601d2e3de08797024a0a13dba0138b3095b43 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.mipsdd1b6595a3a898630f14f8a55a695c2e501cbeb3c909bff9ceb29537c2127ab4 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.arc08516780febe4d87e6104cd34e313ec0542dfd6ab0e51022f0d4e00e2a533c20 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.i468n/an/aelf ua-wget
http://196.251.73.215/00101010101001/morte.i686f036a7842232a000fd0a07d87feddd0d7b8b54b3d32f7d92a2addcca2d563548 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.x86_6462a70e26cea6c21fcaf3750479ba6222e1a655b26f05978bdd04ea221722f0e7 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.mpsl1a62aabc26ace9ee3e99e2dff5a2237f8a1f1e36dfbfcbc2c9bf5f6beb8d00f1 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.arm537bf941eb034d76632909f39a03d5e018f433c09be32d7bd6c4b9d89d1fe764 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.arm54b8a0d8113d0f2d71abc0fef204c1a05d3144c59e727666e519283489693f116 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.arm609b59c56685eec32cb847b6596ffd452c2ecc580212d2ef58bbba09f78b67003 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.arm77530228f8f2c854bd6b3a5b1c6eba9f554bc37f69d195fb0355eabdbfa790f26 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.ppce656926beee61ada6d06880d8b23a47941231d04c90683fe9ea2edb12980b71f Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.spc6622164c76b52290e0fedd1eea0ce0940188f8ac40db272eb0627ace7628b3fe Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.m68k7de8085dd54c5ea46dda7f42c2c4da30088dc43e27e46f40defa96f23f5a2a52 Miraielf mirai ua-wget
http://196.251.73.215/00101010101001/morte.sh4c2bc223a2d9c0716ae88f1f3c197342982753679782d2bf685eb0b0098fb3191 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=38e1397b-1600-0000-34ad-986cc70c0000 pid=3271 /usr/bin/sudo guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278 /tmp/sample.bin guuid=38e1397b-1600-0000-34ad-986cc70c0000 pid=3271->guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278 execve guuid=2ce7437e-1600-0000-34ad-986cd10c0000 pid=3281 /usr/bin/cp guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=2ce7437e-1600-0000-34ad-986cd10c0000 pid=3281 execve guuid=44bae883-1600-0000-34ad-986cdb0c0000 pid=3291 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=44bae883-1600-0000-34ad-986cdb0c0000 pid=3291 execve guuid=0629a68a-1600-0000-34ad-986cf20c0000 pid=3314 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=0629a68a-1600-0000-34ad-986cf20c0000 pid=3314 execve guuid=fa169c98-1600-0000-34ad-986cf60c0000 pid=3318 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=fa169c98-1600-0000-34ad-986cf60c0000 pid=3318 execve guuid=a272fb98-1600-0000-34ad-986cf80c0000 pid=3320 /tmp/morte.x86 net guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=a272fb98-1600-0000-34ad-986cf80c0000 pid=3320 execve guuid=dcd07199-1600-0000-34ad-986cfc0c0000 pid=3324 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=dcd07199-1600-0000-34ad-986cfc0c0000 pid=3324 execve guuid=4a96aa99-1600-0000-34ad-986cfe0c0000 pid=3326 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=4a96aa99-1600-0000-34ad-986cfe0c0000 pid=3326 execve guuid=db1e799f-1600-0000-34ad-986c0f0d0000 pid=3343 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=db1e799f-1600-0000-34ad-986c0f0d0000 pid=3343 execve guuid=aa7861a6-1600-0000-34ad-986c230d0000 pid=3363 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=aa7861a6-1600-0000-34ad-986c230d0000 pid=3363 execve guuid=7dcea4a6-1600-0000-34ad-986c240d0000 pid=3364 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=7dcea4a6-1600-0000-34ad-986c240d0000 pid=3364 clone guuid=0f202fa7-1600-0000-34ad-986c260d0000 pid=3366 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=0f202fa7-1600-0000-34ad-986c260d0000 pid=3366 execve guuid=32d288ab-1600-0000-34ad-986c280d0000 pid=3368 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=32d288ab-1600-0000-34ad-986c280d0000 pid=3368 execve guuid=83ad38b4-1600-0000-34ad-986c420d0000 pid=3394 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=83ad38b4-1600-0000-34ad-986c420d0000 pid=3394 execve guuid=129fb1bd-1600-0000-34ad-986c630d0000 pid=3427 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=129fb1bd-1600-0000-34ad-986c630d0000 pid=3427 execve guuid=57edf0bd-1600-0000-34ad-986c650d0000 pid=3429 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=57edf0bd-1600-0000-34ad-986c650d0000 pid=3429 clone guuid=7e66b1bf-1600-0000-34ad-986c6d0d0000 pid=3437 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=7e66b1bf-1600-0000-34ad-986c6d0d0000 pid=3437 execve guuid=acf23ac1-1600-0000-34ad-986c740d0000 pid=3444 /usr/bin/wget net send-data guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=acf23ac1-1600-0000-34ad-986c740d0000 pid=3444 execve guuid=16c15dc5-1600-0000-34ad-986c860d0000 pid=3462 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=16c15dc5-1600-0000-34ad-986c860d0000 pid=3462 execve guuid=278f16cc-1600-0000-34ad-986c9a0d0000 pid=3482 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=278f16cc-1600-0000-34ad-986c9a0d0000 pid=3482 execve guuid=979550cc-1600-0000-34ad-986c9b0d0000 pid=3483 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=979550cc-1600-0000-34ad-986c9b0d0000 pid=3483 clone guuid=cf6c6ecc-1600-0000-34ad-986c9d0d0000 pid=3485 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=cf6c6ecc-1600-0000-34ad-986c9d0d0000 pid=3485 execve guuid=f69aafcc-1600-0000-34ad-986c9f0d0000 pid=3487 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f69aafcc-1600-0000-34ad-986c9f0d0000 pid=3487 execve guuid=7d9ca8d1-1600-0000-34ad-986cae0d0000 pid=3502 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=7d9ca8d1-1600-0000-34ad-986cae0d0000 pid=3502 execve guuid=b00c8bda-1600-0000-34ad-986cc00d0000 pid=3520 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=b00c8bda-1600-0000-34ad-986cc00d0000 pid=3520 execve guuid=3845d7da-1600-0000-34ad-986cc10d0000 pid=3521 /tmp/morte.i686 net guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=3845d7da-1600-0000-34ad-986cc10d0000 pid=3521 execve guuid=f0e420db-1600-0000-34ad-986cc30d0000 pid=3523 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f0e420db-1600-0000-34ad-986cc30d0000 pid=3523 execve guuid=83ed87db-1600-0000-34ad-986cc60d0000 pid=3526 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=83ed87db-1600-0000-34ad-986cc60d0000 pid=3526 execve guuid=0324a6e2-1600-0000-34ad-986cd70d0000 pid=3543 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=0324a6e2-1600-0000-34ad-986cd70d0000 pid=3543 execve guuid=59b44de9-1600-0000-34ad-986ce30d0000 pid=3555 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=59b44de9-1600-0000-34ad-986ce30d0000 pid=3555 execve guuid=6080a7e9-1600-0000-34ad-986ce40d0000 pid=3556 /tmp/morte.x86_64 mprotect-exec net guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=6080a7e9-1600-0000-34ad-986ce40d0000 pid=3556 execve guuid=61993eea-1600-0000-34ad-986ce80d0000 pid=3560 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=61993eea-1600-0000-34ad-986ce80d0000 pid=3560 execve guuid=db4ea2ea-1600-0000-34ad-986ced0d0000 pid=3565 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=db4ea2ea-1600-0000-34ad-986ced0d0000 pid=3565 execve guuid=78a55cf1-1600-0000-34ad-986c080e0000 pid=3592 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=78a55cf1-1600-0000-34ad-986c080e0000 pid=3592 execve guuid=f55dcdf8-1600-0000-34ad-986c1f0e0000 pid=3615 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f55dcdf8-1600-0000-34ad-986c1f0e0000 pid=3615 execve guuid=975625f9-1600-0000-34ad-986c210e0000 pid=3617 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=975625f9-1600-0000-34ad-986c210e0000 pid=3617 clone guuid=a639bff9-1600-0000-34ad-986c250e0000 pid=3621 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=a639bff9-1600-0000-34ad-986c250e0000 pid=3621 execve guuid=17064afa-1600-0000-34ad-986c270e0000 pid=3623 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=17064afa-1600-0000-34ad-986c270e0000 pid=3623 execve guuid=57c7e5ff-1600-0000-34ad-986c340e0000 pid=3636 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=57c7e5ff-1600-0000-34ad-986c340e0000 pid=3636 execve guuid=d518f409-1700-0000-34ad-986c500e0000 pid=3664 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=d518f409-1700-0000-34ad-986c500e0000 pid=3664 execve guuid=f076610a-1700-0000-34ad-986c510e0000 pid=3665 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f076610a-1700-0000-34ad-986c510e0000 pid=3665 clone guuid=a86a490b-1700-0000-34ad-986c580e0000 pid=3672 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=a86a490b-1700-0000-34ad-986c580e0000 pid=3672 execve guuid=45bab40b-1700-0000-34ad-986c5a0e0000 pid=3674 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=45bab40b-1700-0000-34ad-986c5a0e0000 pid=3674 execve guuid=1dbfa711-1700-0000-34ad-986c6a0e0000 pid=3690 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=1dbfa711-1700-0000-34ad-986c6a0e0000 pid=3690 execve guuid=fd3cc319-1700-0000-34ad-986c7e0e0000 pid=3710 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=fd3cc319-1700-0000-34ad-986c7e0e0000 pid=3710 execve guuid=407b2c1a-1700-0000-34ad-986c7f0e0000 pid=3711 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=407b2c1a-1700-0000-34ad-986c7f0e0000 pid=3711 clone guuid=339e0c1b-1700-0000-34ad-986c810e0000 pid=3713 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=339e0c1b-1700-0000-34ad-986c810e0000 pid=3713 execve guuid=667ddd1b-1700-0000-34ad-986c850e0000 pid=3717 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=667ddd1b-1700-0000-34ad-986c850e0000 pid=3717 execve guuid=aa50ae21-1700-0000-34ad-986c970e0000 pid=3735 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=aa50ae21-1700-0000-34ad-986c970e0000 pid=3735 execve guuid=a183092b-1700-0000-34ad-986ca70e0000 pid=3751 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=a183092b-1700-0000-34ad-986ca70e0000 pid=3751 execve guuid=2d71742b-1700-0000-34ad-986ca80e0000 pid=3752 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=2d71742b-1700-0000-34ad-986ca80e0000 pid=3752 clone guuid=0912592c-1700-0000-34ad-986caa0e0000 pid=3754 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=0912592c-1700-0000-34ad-986caa0e0000 pid=3754 execve guuid=ffc9bb2c-1700-0000-34ad-986cad0e0000 pid=3757 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=ffc9bb2c-1700-0000-34ad-986cad0e0000 pid=3757 execve guuid=78418e33-1700-0000-34ad-986cd10e0000 pid=3793 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=78418e33-1700-0000-34ad-986cd10e0000 pid=3793 execve guuid=678fbc3b-1700-0000-34ad-986ce90e0000 pid=3817 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=678fbc3b-1700-0000-34ad-986ce90e0000 pid=3817 execve guuid=5b19263c-1700-0000-34ad-986ceb0e0000 pid=3819 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=5b19263c-1700-0000-34ad-986ceb0e0000 pid=3819 clone guuid=e544ea3c-1700-0000-34ad-986cf00e0000 pid=3824 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=e544ea3c-1700-0000-34ad-986cf00e0000 pid=3824 execve guuid=f8c8373d-1700-0000-34ad-986cf10e0000 pid=3825 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f8c8373d-1700-0000-34ad-986cf10e0000 pid=3825 execve guuid=f8c64543-1700-0000-34ad-986c090f0000 pid=3849 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f8c64543-1700-0000-34ad-986c090f0000 pid=3849 execve guuid=cdd6f649-1700-0000-34ad-986c220f0000 pid=3874 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=cdd6f649-1700-0000-34ad-986c220f0000 pid=3874 execve guuid=3ede714a-1700-0000-34ad-986c250f0000 pid=3877 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=3ede714a-1700-0000-34ad-986c250f0000 pid=3877 clone guuid=886a7f4b-1700-0000-34ad-986c280f0000 pid=3880 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=886a7f4b-1700-0000-34ad-986c280f0000 pid=3880 execve guuid=8245ea4b-1700-0000-34ad-986c2e0f0000 pid=3886 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=8245ea4b-1700-0000-34ad-986c2e0f0000 pid=3886 execve guuid=f7799a53-1700-0000-34ad-986c3b0f0000 pid=3899 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=f7799a53-1700-0000-34ad-986c3b0f0000 pid=3899 execve guuid=9afbfd5e-1700-0000-34ad-986c500f0000 pid=3920 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=9afbfd5e-1700-0000-34ad-986c500f0000 pid=3920 execve guuid=93e3df5f-1700-0000-34ad-986c520f0000 pid=3922 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=93e3df5f-1700-0000-34ad-986c520f0000 pid=3922 clone guuid=ec696862-1700-0000-34ad-986c580f0000 pid=3928 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=ec696862-1700-0000-34ad-986c580f0000 pid=3928 execve guuid=80f5c563-1700-0000-34ad-986c590f0000 pid=3929 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=80f5c563-1700-0000-34ad-986c590f0000 pid=3929 execve guuid=1459cc6f-1700-0000-34ad-986c6c0f0000 pid=3948 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=1459cc6f-1700-0000-34ad-986c6c0f0000 pid=3948 execve guuid=a3c0557f-1700-0000-34ad-986c800f0000 pid=3968 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=a3c0557f-1700-0000-34ad-986c800f0000 pid=3968 execve guuid=4b418380-1700-0000-34ad-986c820f0000 pid=3970 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=4b418380-1700-0000-34ad-986c820f0000 pid=3970 clone guuid=3f88ba83-1700-0000-34ad-986c880f0000 pid=3976 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=3f88ba83-1700-0000-34ad-986c880f0000 pid=3976 execve guuid=045a5a85-1700-0000-34ad-986c890f0000 pid=3977 /usr/bin/wget net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=045a5a85-1700-0000-34ad-986c890f0000 pid=3977 execve guuid=bd045890-1700-0000-34ad-986c940f0000 pid=3988 /usr/bin/curl net send-data write-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=bd045890-1700-0000-34ad-986c940f0000 pid=3988 execve guuid=21c3239f-1700-0000-34ad-986ca50f0000 pid=4005 /usr/bin/chmod guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=21c3239f-1700-0000-34ad-986ca50f0000 pid=4005 execve guuid=72453ba1-1700-0000-34ad-986ca90f0000 pid=4009 /usr/bin/bash guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=72453ba1-1700-0000-34ad-986ca90f0000 pid=4009 clone guuid=7ecb95a3-1700-0000-34ad-986caf0f0000 pid=4015 /usr/bin/rm delete-file guuid=7c6f857d-1600-0000-34ad-986cce0c0000 pid=3278->guuid=7ecb95a3-1700-0000-34ad-986caf0f0000 pid=4015 execve 8b3161c8-3f69-5fae-b290-1b21c3202a39 196.251.73.215:80 guuid=44bae883-1600-0000-34ad-986cdb0c0000 pid=3291->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 153B guuid=0629a68a-1600-0000-34ad-986cf20c0000 pid=3314->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a272fb98-1600-0000-34ad-986cf80c0000 pid=3320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=560b6b99-1600-0000-34ad-986cfb0c0000 pid=3323 /tmp/morte.x86 guuid=a272fb98-1600-0000-34ad-986cf80c0000 pid=3320->guuid=560b6b99-1600-0000-34ad-986cfb0c0000 pid=3323 clone guuid=716f7399-1600-0000-34ad-986cfd0c0000 pid=3325 /tmp/morte.x86 write-config zombie guuid=560b6b99-1600-0000-34ad-986cfb0c0000 pid=3323->guuid=716f7399-1600-0000-34ad-986cfd0c0000 pid=3325 clone guuid=26f6cc9d-1600-0000-34ad-986c070d0000 pid=3335 /usr/bin/dash guuid=716f7399-1600-0000-34ad-986cfd0c0000 pid=3325->guuid=26f6cc9d-1600-0000-34ad-986c070d0000 pid=3335 execve guuid=94d6fa9f-1600-0000-34ad-986c110d0000 pid=3345 /tmp/morte.x86 delete-file dns net send-data zombie guuid=716f7399-1600-0000-34ad-986cfd0c0000 pid=3325->guuid=94d6fa9f-1600-0000-34ad-986c110d0000 pid=3345 clone guuid=4a96aa99-1600-0000-34ad-986cfe0c0000 pid=3326->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 154B guuid=c764199e-1600-0000-34ad-986c090d0000 pid=3337 /usr/bin/cp guuid=26f6cc9d-1600-0000-34ad-986c070d0000 pid=3335->guuid=c764199e-1600-0000-34ad-986c090d0000 pid=3337 execve guuid=db1e799f-1600-0000-34ad-986c0f0d0000 pid=3343->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 103B guuid=94d6fa9f-1600-0000-34ad-986c110d0000 pid=3345->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B bd521c90-acbc-5fbf-8f56-b34657f8083c codingvix.win:12121 guuid=94d6fa9f-1600-0000-34ad-986c110d0000 pid=3345->bd521c90-acbc-5fbf-8f56-b34657f8083c send: 22B guuid=32d288ab-1600-0000-34ad-986c280d0000 pid=3368->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 153B guuid=83ad38b4-1600-0000-34ad-986c420d0000 pid=3394->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 102B guuid=acf23ac1-1600-0000-34ad-986c740d0000 pid=3444->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 154B guuid=16c15dc5-1600-0000-34ad-986c860d0000 pid=3462->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 103B guuid=f69aafcc-1600-0000-34ad-986c9f0d0000 pid=3487->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 154B guuid=7d9ca8d1-1600-0000-34ad-986cae0d0000 pid=3502->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 103B guuid=3845d7da-1600-0000-34ad-986cc10d0000 pid=3521->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7a7519db-1600-0000-34ad-986cc20d0000 pid=3522 /tmp/morte.i686 guuid=3845d7da-1600-0000-34ad-986cc10d0000 pid=3521->guuid=7a7519db-1600-0000-34ad-986cc20d0000 pid=3522 clone guuid=b44d30db-1600-0000-34ad-986cc40d0000 pid=3524 /tmp/morte.i686 write-config zombie guuid=7a7519db-1600-0000-34ad-986cc20d0000 pid=3522->guuid=b44d30db-1600-0000-34ad-986cc40d0000 pid=3524 clone guuid=9e528bde-1600-0000-34ad-986ccd0d0000 pid=3533 /usr/bin/dash guuid=b44d30db-1600-0000-34ad-986cc40d0000 pid=3524->guuid=9e528bde-1600-0000-34ad-986ccd0d0000 pid=3533 execve guuid=069b20e1-1600-0000-34ad-986cd00d0000 pid=3536 /tmp/morte.i686 guuid=b44d30db-1600-0000-34ad-986cc40d0000 pid=3524->guuid=069b20e1-1600-0000-34ad-986cd00d0000 pid=3536 clone guuid=df673af2-1a00-0000-34ad-986cca140000 pid=5322 /tmp/morte.i686 dns net send-data guuid=b44d30db-1600-0000-34ad-986cc40d0000 pid=3524->guuid=df673af2-1a00-0000-34ad-986cca140000 pid=5322 clone guuid=83ed87db-1600-0000-34ad-986cc60d0000 pid=3526->8b3161c8-3f69-5fae-b290-1b21c3202a39 send: 156B guuid=7681c6de-1600-0000-34ad-986cce0d0000 pid=3534 /usr/bin/cp guuid=9e528bde-1600-0000-34ad-986ccd0d0000 pid=3533->guuid=7681c6de-1600-0000-34ad-986cce0d0000 pid=3534 execve 77225478-3486-52b9-b7ea-bb3961ba83fc codingvix.win:80 guuid=0324a6e2-1600-0000-34ad-986cd70d0000 pid=3543->77225478-3486-52b9-b7ea-bb3961ba83fc send: 105B guuid=6080a7e9-1600-0000-34ad-986ce40d0000 pid=3556->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b9b621ea-1600-0000-34ad-986ce70d0000 pid=3559 /tmp/morte.x86_64 zombie guuid=6080a7e9-1600-0000-34ad-986ce40d0000 pid=3556->guuid=b9b621ea-1600-0000-34ad-986ce70d0000 pid=3559 clone guuid=d8b244ea-1600-0000-34ad-986ce90d0000 pid=3561 /tmp/morte.x86_64 write-config zombie guuid=b9b621ea-1600-0000-34ad-986ce70d0000 pid=3559->guuid=d8b244ea-1600-0000-34ad-986ce90d0000 pid=3561 clone guuid=fc469fea-1600-0000-34ad-986cec0d0000 pid=3564 /usr/bin/dash guuid=d8b244ea-1600-0000-34ad-986ce90d0000 pid=3561->guuid=fc469fea-1600-0000-34ad-986cec0d0000 pid=3564 execve guuid=2408b4ec-1600-0000-34ad-986cf60d0000 pid=3574 /tmp/morte.x86_64 dns net send-data zombie guuid=d8b244ea-1600-0000-34ad-986ce90d0000 pid=3561->guuid=2408b4ec-1600-0000-34ad-986cf60d0000 pid=3574 clone guuid=f52bdfea-1600-0000-34ad-986cef0d0000 pid=3567 /usr/bin/cp guuid=fc469fea-1600-0000-34ad-986cec0d0000 pid=3564->guuid=f52bdfea-1600-0000-34ad-986cef0d0000 pid=3567 execve guuid=db4ea2ea-1600-0000-34ad-986ced0d0000 pid=3565->77225478-3486-52b9-b7ea-bb3961ba83fc send: 154B guuid=2408b4ec-1600-0000-34ad-986cf60d0000 pid=3574->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 31B guuid=2408b4ec-1600-0000-34ad-986cf60d0000 pid=3574->bd521c90-acbc-5fbf-8f56-b34657f8083c send: 27B guuid=78a55cf1-1600-0000-34ad-986c080e0000 pid=3592->77225478-3486-52b9-b7ea-bb3961ba83fc send: 103B guuid=17064afa-1600-0000-34ad-986c270e0000 pid=3623->77225478-3486-52b9-b7ea-bb3961ba83fc send: 153B guuid=57c7e5ff-1600-0000-34ad-986c340e0000 pid=3636->77225478-3486-52b9-b7ea-bb3961ba83fc send: 102B guuid=45bab40b-1700-0000-34ad-986c5a0e0000 pid=3674->77225478-3486-52b9-b7ea-bb3961ba83fc send: 154B guuid=1dbfa711-1700-0000-34ad-986c6a0e0000 pid=3690->77225478-3486-52b9-b7ea-bb3961ba83fc send: 103B guuid=667ddd1b-1700-0000-34ad-986c850e0000 pid=3717->77225478-3486-52b9-b7ea-bb3961ba83fc send: 154B guuid=aa50ae21-1700-0000-34ad-986c970e0000 pid=3735->77225478-3486-52b9-b7ea-bb3961ba83fc send: 103B guuid=ffc9bb2c-1700-0000-34ad-986cad0e0000 pid=3757->77225478-3486-52b9-b7ea-bb3961ba83fc send: 154B guuid=78418e33-1700-0000-34ad-986cd10e0000 pid=3793->77225478-3486-52b9-b7ea-bb3961ba83fc send: 103B guuid=f8c8373d-1700-0000-34ad-986cf10e0000 pid=3825->77225478-3486-52b9-b7ea-bb3961ba83fc send: 153B guuid=f8c64543-1700-0000-34ad-986c090f0000 pid=3849->77225478-3486-52b9-b7ea-bb3961ba83fc send: 102B guuid=8245ea4b-1700-0000-34ad-986c2e0f0000 pid=3886->77225478-3486-52b9-b7ea-bb3961ba83fc send: 153B guuid=f7799a53-1700-0000-34ad-986c3b0f0000 pid=3899->77225478-3486-52b9-b7ea-bb3961ba83fc send: 102B guuid=80f5c563-1700-0000-34ad-986c590f0000 pid=3929->77225478-3486-52b9-b7ea-bb3961ba83fc send: 154B guuid=1459cc6f-1700-0000-34ad-986c6c0f0000 pid=3948->77225478-3486-52b9-b7ea-bb3961ba83fc send: 103B guuid=045a5a85-1700-0000-34ad-986c890f0000 pid=3977->77225478-3486-52b9-b7ea-bb3961ba83fc send: 153B guuid=bd045890-1700-0000-34ad-986c940f0000 pid=3988->77225478-3486-52b9-b7ea-bb3961ba83fc send: 102B guuid=df673af2-1a00-0000-34ad-986cca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 62B guuid=df673af2-1a00-0000-34ad-986cca140000 pid=5322->bd521c90-acbc-5fbf-8f56-b34657f8083c send: 48B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-22 01:52:38 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3d2acd9571f1e62e42aaf6d34a320d96eb07a1d4b16cce9dc74885aeb0b03f4f

(this sample)

  
Delivery method
Distributed via web download

Comments