MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3f69ba905c14f4c84e3008d252f0828d1283451e4b48d8065049bfca3d6b6a47. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: 3f69ba905c14f4c84e3008d252f0828d1283451e4b48d8065049bfca3d6b6a47
SHA3-384 hash: ee095b5fd9c361ac9091119b49a691e5d02da688b83c7d435768323208bb8d4739f13e6e5ba6131056d31236cf1e3f06
SHA1 hash: 6e03e3eebdcff86e00eb26118da68b6f3b51e85a
MD5 hash: 5a91877097ffa6fe11de60d1a3a853df
humanhash: arizona-arkansas-blossom-blossom
File name:1.sh
Download: download sample
Signature Mirai
File size:3'044 bytes
First seen:2025-07-21 12:42:18 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ip4R4qp4g48p4z4Kp484cp4W4Ep4O4Qp4UO4U1p4p4ap4W4eLp4r4YJp4c4Ip4eQ:iG+qG98GUKGZcGvEGXQGiGGGaGveLG8J
TLSH T1B1514FEA23C186736CFADAD776A98404728155EBEC8F2F3694DCE8E9808DE097040752
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.210/bins/morte.x86bd297ae9c45ffbfe444213d57dd4eb32d6212465d6c840f1a497cc20c533d4e9 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.mips568780e2ac25888e3151dd8e8cb76d1ebdfd2e986e0fed4931d15656fa5b9eb1 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.arc7321f337422bcdbac4f2a90af9d827e18fb1ead5acee542ecf05e4fe37e5822e Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.i468n/an/aelf opendir ua-wget
http://176.65.148.210/bins/morte.i68682444c55629dc38a74ad72ef9af7239b973f85aadd1c7d227205e529901e97fb Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.x86_64750684d31633710b2a8bd3ffe886405d3a7ed4e5ad57779c742fba4e7a592018 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.mpsl5d1b62d8c2acef405d9027ce927733d49d04464ed761421a74c9652bd0339709 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.armf83b76f66452fe975e2c15145bbcd4fb24b12192eddc87b1272a9413f11b4018 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.arm58b536240087f1627bf1417ee5529c42a17561a64b3f8628c907d1e023cc91893 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.arm6f6ceab5e38268a31528821a82a6ad66b27031c8ecffef6c7e718bcca359d03b5 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.arm700969384d60395745426767373265dcc7aca5888936df57b2deafaefe780b9e4 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.ppcce2a3ca361d668031c19ea9bf31a5c96e37d6dc7d10c6ed9d7b7919df009850c Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.spc196663d92cac163ac2730d386e4bc9261d29b8c6d811e8f5b5370c8633375f99 Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.m68kc9b7bbf730c616b2edbfc26eda34f7bff8d306bab45974e45083175778ebecce Miraielf mirai opendir ua-wget
http://176.65.148.210/bins/morte.sh49756731375c8aaa5e4deb59e70739d555fbee90ec01276d839ea965f3c1c58b6 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=05150473-1900-0000-4017-cd935a090000 pid=2394 /usr/bin/sudo guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396 /tmp/sample.bin guuid=05150473-1900-0000-4017-cd935a090000 pid=2394->guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396 execve guuid=3d747b75-1900-0000-4017-cd935d090000 pid=2397 /usr/bin/cp guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=3d747b75-1900-0000-4017-cd935d090000 pid=2397 execve guuid=3684717d-1900-0000-4017-cd9365090000 pid=2405 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=3684717d-1900-0000-4017-cd9365090000 pid=2405 execve guuid=af203d83-1900-0000-4017-cd936a090000 pid=2410 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=af203d83-1900-0000-4017-cd936a090000 pid=2410 execve guuid=e7e7b791-1900-0000-4017-cd938f090000 pid=2447 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e7e7b791-1900-0000-4017-cd938f090000 pid=2447 execve guuid=937d3392-1900-0000-4017-cd9391090000 pid=2449 /tmp/morte.x86 net guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=937d3392-1900-0000-4017-cd9391090000 pid=2449 execve guuid=770f3093-1900-0000-4017-cd9394090000 pid=2452 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=770f3093-1900-0000-4017-cd9394090000 pid=2452 execve guuid=58bec593-1900-0000-4017-cd9396090000 pid=2454 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=58bec593-1900-0000-4017-cd9396090000 pid=2454 execve guuid=4b0a2699-1900-0000-4017-cd93a3090000 pid=2467 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=4b0a2699-1900-0000-4017-cd93a3090000 pid=2467 execve guuid=89db8aa0-1900-0000-4017-cd93b7090000 pid=2487 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=89db8aa0-1900-0000-4017-cd93b7090000 pid=2487 execve guuid=eb13d3a0-1900-0000-4017-cd93b9090000 pid=2489 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=eb13d3a0-1900-0000-4017-cd93b9090000 pid=2489 clone guuid=506c5aa1-1900-0000-4017-cd93bc090000 pid=2492 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=506c5aa1-1900-0000-4017-cd93bc090000 pid=2492 execve guuid=069d95a6-1900-0000-4017-cd93c0090000 pid=2496 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=069d95a6-1900-0000-4017-cd93c0090000 pid=2496 execve guuid=e83e20ac-1900-0000-4017-cd93ce090000 pid=2510 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e83e20ac-1900-0000-4017-cd93ce090000 pid=2510 execve guuid=aec546b3-1900-0000-4017-cd93db090000 pid=2523 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=aec546b3-1900-0000-4017-cd93db090000 pid=2523 execve guuid=d7819db3-1900-0000-4017-cd93dc090000 pid=2524 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=d7819db3-1900-0000-4017-cd93dc090000 pid=2524 clone guuid=9f5835b4-1900-0000-4017-cd93df090000 pid=2527 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=9f5835b4-1900-0000-4017-cd93df090000 pid=2527 execve guuid=378459b6-1900-0000-4017-cd93e8090000 pid=2536 /usr/bin/wget net send-data guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=378459b6-1900-0000-4017-cd93e8090000 pid=2536 execve guuid=dd7205b9-1900-0000-4017-cd93ef090000 pid=2543 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=dd7205b9-1900-0000-4017-cd93ef090000 pid=2543 execve guuid=d6b160bd-1900-0000-4017-cd93fb090000 pid=2555 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=d6b160bd-1900-0000-4017-cd93fb090000 pid=2555 execve guuid=c9dda4bd-1900-0000-4017-cd93fd090000 pid=2557 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=c9dda4bd-1900-0000-4017-cd93fd090000 pid=2557 clone guuid=5dc2ccbd-1900-0000-4017-cd93ff090000 pid=2559 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=5dc2ccbd-1900-0000-4017-cd93ff090000 pid=2559 execve guuid=7a5a0dbe-1900-0000-4017-cd93010a0000 pid=2561 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=7a5a0dbe-1900-0000-4017-cd93010a0000 pid=2561 execve guuid=e157a9c1-1900-0000-4017-cd93080a0000 pid=2568 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e157a9c1-1900-0000-4017-cd93080a0000 pid=2568 execve guuid=21015fc6-1900-0000-4017-cd93160a0000 pid=2582 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=21015fc6-1900-0000-4017-cd93160a0000 pid=2582 execve guuid=ca47b6c6-1900-0000-4017-cd93180a0000 pid=2584 /tmp/morte.i686 net guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=ca47b6c6-1900-0000-4017-cd93180a0000 pid=2584 execve guuid=6ecef1c6-1900-0000-4017-cd931b0a0000 pid=2587 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=6ecef1c6-1900-0000-4017-cd931b0a0000 pid=2587 execve guuid=aeea54c7-1900-0000-4017-cd931e0a0000 pid=2590 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=aeea54c7-1900-0000-4017-cd931e0a0000 pid=2590 execve guuid=d916eecb-1900-0000-4017-cd932e0a0000 pid=2606 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=d916eecb-1900-0000-4017-cd932e0a0000 pid=2606 execve guuid=524c26d3-1900-0000-4017-cd93450a0000 pid=2629 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=524c26d3-1900-0000-4017-cd93450a0000 pid=2629 execve guuid=007854d4-1900-0000-4017-cd93490a0000 pid=2633 /tmp/morte.x86_64 mprotect-exec net guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=007854d4-1900-0000-4017-cd93490a0000 pid=2633 execve guuid=e0d41ed5-1900-0000-4017-cd934c0a0000 pid=2636 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e0d41ed5-1900-0000-4017-cd934c0a0000 pid=2636 execve guuid=a8138ed5-1900-0000-4017-cd934f0a0000 pid=2639 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=a8138ed5-1900-0000-4017-cd934f0a0000 pid=2639 execve guuid=6ff0bed9-1900-0000-4017-cd935e0a0000 pid=2654 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=6ff0bed9-1900-0000-4017-cd935e0a0000 pid=2654 execve guuid=7bfe32df-1900-0000-4017-cd93700a0000 pid=2672 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=7bfe32df-1900-0000-4017-cd93700a0000 pid=2672 execve guuid=152a71df-1900-0000-4017-cd93720a0000 pid=2674 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=152a71df-1900-0000-4017-cd93720a0000 pid=2674 clone guuid=023901e0-1900-0000-4017-cd93760a0000 pid=2678 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=023901e0-1900-0000-4017-cd93760a0000 pid=2678 execve guuid=cd464ce3-1900-0000-4017-cd93820a0000 pid=2690 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=cd464ce3-1900-0000-4017-cd93820a0000 pid=2690 execve guuid=93cff7e7-1900-0000-4017-cd938e0a0000 pid=2702 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=93cff7e7-1900-0000-4017-cd938e0a0000 pid=2702 execve guuid=e43c6bec-1900-0000-4017-cd939c0a0000 pid=2716 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e43c6bec-1900-0000-4017-cd939c0a0000 pid=2716 execve guuid=80b2c9ec-1900-0000-4017-cd939e0a0000 pid=2718 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=80b2c9ec-1900-0000-4017-cd939e0a0000 pid=2718 clone guuid=dfadeded-1900-0000-4017-cd93a40a0000 pid=2724 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=dfadeded-1900-0000-4017-cd93a40a0000 pid=2724 execve guuid=f63fdcee-1900-0000-4017-cd93a80a0000 pid=2728 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=f63fdcee-1900-0000-4017-cd93a80a0000 pid=2728 execve guuid=4a8a25f2-1900-0000-4017-cd93b10a0000 pid=2737 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=4a8a25f2-1900-0000-4017-cd93b10a0000 pid=2737 execve guuid=208cd8f6-1900-0000-4017-cd93bf0a0000 pid=2751 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=208cd8f6-1900-0000-4017-cd93bf0a0000 pid=2751 execve guuid=b48522f7-1900-0000-4017-cd93c10a0000 pid=2753 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=b48522f7-1900-0000-4017-cd93c10a0000 pid=2753 clone guuid=f16eacf7-1900-0000-4017-cd93c40a0000 pid=2756 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=f16eacf7-1900-0000-4017-cd93c40a0000 pid=2756 execve guuid=589909f8-1900-0000-4017-cd93c60a0000 pid=2758 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=589909f8-1900-0000-4017-cd93c60a0000 pid=2758 execve guuid=3f7c07fc-1900-0000-4017-cd93d30a0000 pid=2771 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=3f7c07fc-1900-0000-4017-cd93d30a0000 pid=2771 execve guuid=9e0caf00-1a00-0000-4017-cd93e10a0000 pid=2785 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=9e0caf00-1a00-0000-4017-cd93e10a0000 pid=2785 execve guuid=454c1201-1a00-0000-4017-cd93e30a0000 pid=2787 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=454c1201-1a00-0000-4017-cd93e30a0000 pid=2787 clone guuid=eaaff101-1a00-0000-4017-cd93e80a0000 pid=2792 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=eaaff101-1a00-0000-4017-cd93e80a0000 pid=2792 execve guuid=cfec4802-1a00-0000-4017-cd93ea0a0000 pid=2794 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=cfec4802-1a00-0000-4017-cd93ea0a0000 pid=2794 execve guuid=667fb006-1a00-0000-4017-cd93f40a0000 pid=2804 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=667fb006-1a00-0000-4017-cd93f40a0000 pid=2804 execve guuid=739a0810-1a00-0000-4017-cd93070b0000 pid=2823 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=739a0810-1a00-0000-4017-cd93070b0000 pid=2823 execve guuid=23c44e10-1a00-0000-4017-cd93090b0000 pid=2825 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=23c44e10-1a00-0000-4017-cd93090b0000 pid=2825 clone guuid=55431611-1a00-0000-4017-cd930b0b0000 pid=2827 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=55431611-1a00-0000-4017-cd930b0b0000 pid=2827 execve guuid=dfc1f817-1a00-0000-4017-cd930c0b0000 pid=2828 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=dfc1f817-1a00-0000-4017-cd930c0b0000 pid=2828 execve guuid=e875371c-1a00-0000-4017-cd93140b0000 pid=2836 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=e875371c-1a00-0000-4017-cd93140b0000 pid=2836 execve guuid=7f469e22-1a00-0000-4017-cd93160b0000 pid=2838 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=7f469e22-1a00-0000-4017-cd93160b0000 pid=2838 execve guuid=1cf0ff22-1a00-0000-4017-cd93170b0000 pid=2839 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=1cf0ff22-1a00-0000-4017-cd93170b0000 pid=2839 clone guuid=cb06ce23-1a00-0000-4017-cd931a0b0000 pid=2842 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=cb06ce23-1a00-0000-4017-cd931a0b0000 pid=2842 execve guuid=d1f83527-1a00-0000-4017-cd93200b0000 pid=2848 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=d1f83527-1a00-0000-4017-cd93200b0000 pid=2848 execve guuid=9036002c-1a00-0000-4017-cd93270b0000 pid=2855 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=9036002c-1a00-0000-4017-cd93270b0000 pid=2855 execve guuid=fb031032-1a00-0000-4017-cd93350b0000 pid=2869 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=fb031032-1a00-0000-4017-cd93350b0000 pid=2869 execve guuid=f29e6632-1a00-0000-4017-cd93370b0000 pid=2871 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=f29e6632-1a00-0000-4017-cd93370b0000 pid=2871 clone guuid=73065233-1a00-0000-4017-cd933c0b0000 pid=2876 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=73065233-1a00-0000-4017-cd933c0b0000 pid=2876 execve guuid=c0f12a35-1a00-0000-4017-cd933f0b0000 pid=2879 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=c0f12a35-1a00-0000-4017-cd933f0b0000 pid=2879 execve guuid=86e7e739-1a00-0000-4017-cd93480b0000 pid=2888 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=86e7e739-1a00-0000-4017-cd93480b0000 pid=2888 execve guuid=52499640-1a00-0000-4017-cd93520b0000 pid=2898 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=52499640-1a00-0000-4017-cd93520b0000 pid=2898 execve guuid=af4a1e41-1a00-0000-4017-cd93550b0000 pid=2901 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=af4a1e41-1a00-0000-4017-cd93550b0000 pid=2901 clone guuid=8222e141-1a00-0000-4017-cd93580b0000 pid=2904 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=8222e141-1a00-0000-4017-cd93580b0000 pid=2904 execve guuid=3d215042-1a00-0000-4017-cd935a0b0000 pid=2906 /usr/bin/wget net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=3d215042-1a00-0000-4017-cd935a0b0000 pid=2906 execve guuid=39e7f646-1a00-0000-4017-cd93600b0000 pid=2912 /usr/bin/curl net send-data write-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=39e7f646-1a00-0000-4017-cd93600b0000 pid=2912 execve guuid=8c73b54e-1a00-0000-4017-cd93730b0000 pid=2931 /usr/bin/chmod guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=8c73b54e-1a00-0000-4017-cd93730b0000 pid=2931 execve guuid=297e074f-1a00-0000-4017-cd93740b0000 pid=2932 /usr/bin/bash guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=297e074f-1a00-0000-4017-cd93740b0000 pid=2932 clone guuid=13edda4f-1a00-0000-4017-cd93770b0000 pid=2935 /usr/bin/rm delete-file guuid=25b20a75-1900-0000-4017-cd935c090000 pid=2396->guuid=13edda4f-1a00-0000-4017-cd93770b0000 pid=2935 execve 2776bfab-ddb2-5f1f-8a0b-4c3d169449bd 176.65.148.210:80 guuid=3684717d-1900-0000-4017-cd9365090000 pid=2405->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=af203d83-1900-0000-4017-cd936a090000 pid=2410->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=937d3392-1900-0000-4017-cd9391090000 pid=2449->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=05a81f93-1900-0000-4017-cd9393090000 pid=2451 /tmp/morte.x86 guuid=937d3392-1900-0000-4017-cd9391090000 pid=2449->guuid=05a81f93-1900-0000-4017-cd9393090000 pid=2451 clone guuid=1a423f93-1900-0000-4017-cd9395090000 pid=2453 /tmp/morte.x86 write-config zombie guuid=05a81f93-1900-0000-4017-cd9393090000 pid=2451->guuid=1a423f93-1900-0000-4017-cd9395090000 pid=2453 clone guuid=d9115398-1900-0000-4017-cd939e090000 pid=2462 /usr/bin/dash guuid=1a423f93-1900-0000-4017-cd9395090000 pid=2453->guuid=d9115398-1900-0000-4017-cd939e090000 pid=2462 execve guuid=69d9cb9a-1900-0000-4017-cd93a5090000 pid=2469 /tmp/morte.x86 delete-file guuid=1a423f93-1900-0000-4017-cd9395090000 pid=2453->guuid=69d9cb9a-1900-0000-4017-cd93a5090000 pid=2469 clone guuid=58bec593-1900-0000-4017-cd9396090000 pid=2454->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=08eb7e98-1900-0000-4017-cd93a0090000 pid=2464 /usr/bin/cp guuid=d9115398-1900-0000-4017-cd939e090000 pid=2462->guuid=08eb7e98-1900-0000-4017-cd93a0090000 pid=2464 execve guuid=4b0a2699-1900-0000-4017-cd93a3090000 pid=2467->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=069d95a6-1900-0000-4017-cd93c0090000 pid=2496->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=e83e20ac-1900-0000-4017-cd93ce090000 pid=2510->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B guuid=378459b6-1900-0000-4017-cd93e8090000 pid=2536->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=dd7205b9-1900-0000-4017-cd93ef090000 pid=2543->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=7a5a0dbe-1900-0000-4017-cd93010a0000 pid=2561->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=e157a9c1-1900-0000-4017-cd93080a0000 pid=2568->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=ca47b6c6-1900-0000-4017-cd93180a0000 pid=2584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5d28ecc6-1900-0000-4017-cd931a0a0000 pid=2586 /tmp/morte.i686 guuid=ca47b6c6-1900-0000-4017-cd93180a0000 pid=2584->guuid=5d28ecc6-1900-0000-4017-cd931a0a0000 pid=2586 clone guuid=e91dfbc6-1900-0000-4017-cd931c0a0000 pid=2588 /tmp/morte.i686 write-config zombie guuid=5d28ecc6-1900-0000-4017-cd931a0a0000 pid=2586->guuid=e91dfbc6-1900-0000-4017-cd931c0a0000 pid=2588 clone guuid=7f8d5dcb-1900-0000-4017-cd932c0a0000 pid=2604 /usr/bin/dash guuid=e91dfbc6-1900-0000-4017-cd931c0a0000 pid=2588->guuid=7f8d5dcb-1900-0000-4017-cd932c0a0000 pid=2604 execve guuid=04e662d1-1900-0000-4017-cd933e0a0000 pid=2622 /tmp/morte.i686 dns net send-data guuid=e91dfbc6-1900-0000-4017-cd931c0a0000 pid=2588->guuid=04e662d1-1900-0000-4017-cd933e0a0000 pid=2622 clone guuid=aeea54c7-1900-0000-4017-cd931e0a0000 pid=2590->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 146B guuid=0f4b5ecc-1900-0000-4017-cd93300a0000 pid=2608 /usr/bin/cp guuid=7f8d5dcb-1900-0000-4017-cd932c0a0000 pid=2604->guuid=0f4b5ecc-1900-0000-4017-cd93300a0000 pid=2608 execve guuid=d916eecb-1900-0000-4017-cd932e0a0000 pid=2606->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 95B guuid=04e662d1-1900-0000-4017-cd933e0a0000 pid=2622->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 1bbb4005-5fa7-5147-8924-030d465cc44a vipcncnetwork.com:12121 guuid=04e662d1-1900-0000-4017-cd933e0a0000 pid=2622->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B guuid=007854d4-1900-0000-4017-cd93490a0000 pid=2633->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=839811d5-1900-0000-4017-cd934b0a0000 pid=2635 /tmp/morte.x86_64 zombie guuid=007854d4-1900-0000-4017-cd93490a0000 pid=2633->guuid=839811d5-1900-0000-4017-cd934b0a0000 pid=2635 clone guuid=8c8922d5-1900-0000-4017-cd934d0a0000 pid=2637 /tmp/morte.x86_64 write-config zombie guuid=839811d5-1900-0000-4017-cd934b0a0000 pid=2635->guuid=8c8922d5-1900-0000-4017-cd934d0a0000 pid=2637 clone guuid=ed273ad6-1900-0000-4017-cd93520a0000 pid=2642 /usr/bin/dash guuid=8c8922d5-1900-0000-4017-cd934d0a0000 pid=2637->guuid=ed273ad6-1900-0000-4017-cd93520a0000 pid=2642 execve guuid=6c077ed9-1900-0000-4017-cd935d0a0000 pid=2653 /tmp/morte.x86_64 dns net send-data zombie guuid=8c8922d5-1900-0000-4017-cd934d0a0000 pid=2637->guuid=6c077ed9-1900-0000-4017-cd935d0a0000 pid=2653 clone guuid=a8138ed5-1900-0000-4017-cd934f0a0000 pid=2639->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=5ea570d7-1900-0000-4017-cd93570a0000 pid=2647 /usr/bin/cp guuid=ed273ad6-1900-0000-4017-cd93520a0000 pid=2642->guuid=5ea570d7-1900-0000-4017-cd93570a0000 pid=2647 execve guuid=6c077ed9-1900-0000-4017-cd935d0a0000 pid=2653->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=6c077ed9-1900-0000-4017-cd935d0a0000 pid=2653->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B guuid=6ff0bed9-1900-0000-4017-cd935e0a0000 pid=2654->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=cd464ce3-1900-0000-4017-cd93820a0000 pid=2690->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=93cff7e7-1900-0000-4017-cd938e0a0000 pid=2702->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B guuid=f63fdcee-1900-0000-4017-cd93a80a0000 pid=2728->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=4a8a25f2-1900-0000-4017-cd93b10a0000 pid=2737->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=589909f8-1900-0000-4017-cd93c60a0000 pid=2758->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=3f7c07fc-1900-0000-4017-cd93d30a0000 pid=2771->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=cfec4802-1a00-0000-4017-cd93ea0a0000 pid=2794->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=667fb006-1a00-0000-4017-cd93f40a0000 pid=2804->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=dfc1f817-1a00-0000-4017-cd930c0b0000 pid=2828->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=e875371c-1a00-0000-4017-cd93140b0000 pid=2836->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B guuid=d1f83527-1a00-0000-4017-cd93200b0000 pid=2848->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=9036002c-1a00-0000-4017-cd93270b0000 pid=2855->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B guuid=c0f12a35-1a00-0000-4017-cd933f0b0000 pid=2879->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 144B guuid=86e7e739-1a00-0000-4017-cd93480b0000 pid=2888->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 93B guuid=3d215042-1a00-0000-4017-cd935a0b0000 pid=2906->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 143B guuid=39e7f646-1a00-0000-4017-cd93600b0000 pid=2912->2776bfab-ddb2-5f1f-8a0b-4c3d169449bd send: 92B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-21 12:43:20 UTC
File Type:
Text (Shell)
AV detection:
15 of 23 (65.22%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3f69ba905c14f4c84e3008d252f0828d1283451e4b48d8065049bfca3d6b6a47

(this sample)

  
Delivery method
Distributed via web download

Comments