MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 46626ff6e0c9ca700c398f551d7ad5a3fea186abf400c37de81dbb13b0e1f3f2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 46626ff6e0c9ca700c398f551d7ad5a3fea186abf400c37de81dbb13b0e1f3f2
SHA3-384 hash: fa2d5baf3e4630b0c646a561e02334d82a81cec7d0c661eed54112c3f85d7f4f715e64b780c3bb00338ae551afbd816c
SHA1 hash: b198afaf3ca90a4e0bd01a6fdee7905fae796e04
MD5 hash: 27b24d7250b68302f663d8e7fa452431
humanhash: cup-zebra-east-august
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-07-11 06:59:15 UTC
Last seen:2025-07-15 23:28:00 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItHZsRbhfkdlfdmsNTsNGgJ369nLybNIpKks1ME7hPsUFcGgJs8Apk:iyzc3VlsN1KxLeJnV0UFBgJsVk
TLSH T15A61A3F60342457BDCAACAD7B1AC8405624944ABA4CF4FF1CBECA4F41E4CEC86C85656
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.69.179/00101010101001/morte.x86f4185560f61a2e65676dca39e34f3bf58df70e31bac15ff102a457d017bd03b9 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.mipsd3e2b7563f92982267e822718ac8c3283de40870e3de3d0f4617bb13e13e00b2 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.arcc378185b0f76947eb0183861f4d01ef7df4964a68640d7280ca312ee4280868e Miraimirai opendir
http://196.251.69.179/00101010101001/morte.i468n/an/aelf ua-wget
http://196.251.69.179/00101010101001/morte.i6867d6e0067be1beb10bc1c9976049964f5970a8ace8db721b41dd41865b577c5ed Miraimirai opendir
http://196.251.69.179/00101010101001/morte.x86_6485d0a0a8f6e490d799733d5cfa6aab5329b952ebb4cd59a719628e48de26e062 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.mpslcbacea9fabf5d49ccd0200a0aac24fa0bfd6d0decb1dfa3dcb486ac681c6b329 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.armbbfd89b8e5789aea24faabc0ad57cfc040c2380e8cc7bd2c37bf6f9fafbed785 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.arm533a6f20085ccee2f138076d19681c70bc51e85de8a9a9feff8244cb8e781a53b Miraimirai opendir
http://196.251.69.179/00101010101001/morte.arm6de5961922467e9b023a48e56fa3df60e136c84e01a1d73aa34c20015804ba173 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.arm7b40189b56d6e902a21d45b28a9a5aeef87f311628872922e510cbbfd19b6ead6 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.ppc03e95dd682d96c01e1c6e93ed45531c38b71e644b837a71044146d7abce4abaf MiraiCoinMiner mirai opendir
http://196.251.69.179/00101010101001/morte.spcf0acbd7cd2a32d3a5230a1760980619f9e1cb32a230d31ad452723c62c76576a Miraimirai opendir
http://196.251.69.179/00101010101001/morte.m68kdfb19a5c962ceedd185ebe83c688189f666e7e62f4a07c36242a44d8bb8f42c6 Miraimirai opendir
http://196.251.69.179/00101010101001/morte.sh497d65ac4d7ef56c46367a3b4bd6ca5fd3e22c3b45f86f8f377864ec77814c5e5 Miraimirai opendir

Intelligence


File Origin
# of uploads :
3
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader phishing trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=9588f9dd-1800-0000-f145-327b96080000 pid=2198 /usr/bin/sudo guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204 /tmp/sample.bin guuid=9588f9dd-1800-0000-f145-327b96080000 pid=2198->guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204 execve guuid=e5de11e1-1800-0000-f145-327b9f080000 pid=2207 /usr/bin/cp guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=e5de11e1-1800-0000-f145-327b9f080000 pid=2207 execve guuid=ea4fdee7-1800-0000-f145-327bad080000 pid=2221 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=ea4fdee7-1800-0000-f145-327bad080000 pid=2221 execve guuid=e460a5ee-1800-0000-f145-327bbf080000 pid=2239 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=e460a5ee-1800-0000-f145-327bbf080000 pid=2239 execve guuid=2df754f9-1800-0000-f145-327bd2080000 pid=2258 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=2df754f9-1800-0000-f145-327bd2080000 pid=2258 execve guuid=cddcb3f9-1800-0000-f145-327bd3080000 pid=2259 /tmp/morte.x86 net guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=cddcb3f9-1800-0000-f145-327bd3080000 pid=2259 execve guuid=ad5347fa-1800-0000-f145-327bd7080000 pid=2263 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=ad5347fa-1800-0000-f145-327bd7080000 pid=2263 execve guuid=fd6587fa-1800-0000-f145-327bda080000 pid=2266 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=fd6587fa-1800-0000-f145-327bda080000 pid=2266 execve guuid=2aa2b9fe-1800-0000-f145-327bdf080000 pid=2271 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=2aa2b9fe-1800-0000-f145-327bdf080000 pid=2271 execve guuid=932e0005-1900-0000-f145-327bf1080000 pid=2289 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=932e0005-1900-0000-f145-327bf1080000 pid=2289 execve guuid=af6b5305-1900-0000-f145-327bf3080000 pid=2291 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=af6b5305-1900-0000-f145-327bf3080000 pid=2291 clone guuid=c29cc107-1900-0000-f145-327bfa080000 pid=2298 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=c29cc107-1900-0000-f145-327bfa080000 pid=2298 execve guuid=f2358208-1900-0000-f145-327bfc080000 pid=2300 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=f2358208-1900-0000-f145-327bfc080000 pid=2300 execve guuid=1b7b6e0e-1900-0000-f145-327b08090000 pid=2312 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=1b7b6e0e-1900-0000-f145-327b08090000 pid=2312 execve guuid=c136d516-1900-0000-f145-327b11090000 pid=2321 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=c136d516-1900-0000-f145-327b11090000 pid=2321 execve guuid=811b4a17-1900-0000-f145-327b13090000 pid=2323 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=811b4a17-1900-0000-f145-327b13090000 pid=2323 clone guuid=2097e917-1900-0000-f145-327b16090000 pid=2326 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=2097e917-1900-0000-f145-327b16090000 pid=2326 execve guuid=85ae8e19-1900-0000-f145-327b1b090000 pid=2331 /usr/bin/wget net send-data guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=85ae8e19-1900-0000-f145-327b1b090000 pid=2331 execve guuid=0d88131d-1900-0000-f145-327b26090000 pid=2342 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=0d88131d-1900-0000-f145-327b26090000 pid=2342 execve guuid=1c9e5521-1900-0000-f145-327b2f090000 pid=2351 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=1c9e5521-1900-0000-f145-327b2f090000 pid=2351 execve guuid=8a27a521-1900-0000-f145-327b30090000 pid=2352 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=8a27a521-1900-0000-f145-327b30090000 pid=2352 clone guuid=356cd821-1900-0000-f145-327b31090000 pid=2353 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=356cd821-1900-0000-f145-327b31090000 pid=2353 execve guuid=29242722-1900-0000-f145-327b32090000 pid=2354 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=29242722-1900-0000-f145-327b32090000 pid=2354 execve guuid=4775de25-1900-0000-f145-327b38090000 pid=2360 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4775de25-1900-0000-f145-327b38090000 pid=2360 execve guuid=1767e02a-1900-0000-f145-327b46090000 pid=2374 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=1767e02a-1900-0000-f145-327b46090000 pid=2374 execve guuid=d7341c2b-1900-0000-f145-327b48090000 pid=2376 /tmp/morte.i686 net guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=d7341c2b-1900-0000-f145-327b48090000 pid=2376 execve guuid=d53e552b-1900-0000-f145-327b4a090000 pid=2378 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=d53e552b-1900-0000-f145-327b4a090000 pid=2378 execve guuid=7bbba12b-1900-0000-f145-327b4b090000 pid=2379 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=7bbba12b-1900-0000-f145-327b4b090000 pid=2379 execve guuid=0f7c5230-1900-0000-f145-327b52090000 pid=2386 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=0f7c5230-1900-0000-f145-327b52090000 pid=2386 execve guuid=8ccab838-1900-0000-f145-327b66090000 pid=2406 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=8ccab838-1900-0000-f145-327b66090000 pid=2406 execve guuid=c0e21939-1900-0000-f145-327b67090000 pid=2407 /tmp/morte.x86_64 mprotect-exec net guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=c0e21939-1900-0000-f145-327b67090000 pid=2407 execve guuid=b538b039-1900-0000-f145-327b69090000 pid=2409 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=b538b039-1900-0000-f145-327b69090000 pid=2409 execve guuid=c5b6aa3b-1900-0000-f145-327b71090000 pid=2417 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=c5b6aa3b-1900-0000-f145-327b71090000 pid=2417 execve guuid=4d4ca740-1900-0000-f145-327b82090000 pid=2434 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4d4ca740-1900-0000-f145-327b82090000 pid=2434 execve guuid=640b0546-1900-0000-f145-327b90090000 pid=2448 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=640b0546-1900-0000-f145-327b90090000 pid=2448 execve guuid=4b2d6646-1900-0000-f145-327b91090000 pid=2449 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4b2d6646-1900-0000-f145-327b91090000 pid=2449 clone guuid=235d1447-1900-0000-f145-327b93090000 pid=2451 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=235d1447-1900-0000-f145-327b93090000 pid=2451 execve guuid=ea50404d-1900-0000-f145-327b94090000 pid=2452 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=ea50404d-1900-0000-f145-327b94090000 pid=2452 execve guuid=ecac8552-1900-0000-f145-327b9b090000 pid=2459 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=ecac8552-1900-0000-f145-327b9b090000 pid=2459 execve guuid=3b440658-1900-0000-f145-327ba7090000 pid=2471 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=3b440658-1900-0000-f145-327ba7090000 pid=2471 execve guuid=4edda058-1900-0000-f145-327baa090000 pid=2474 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4edda058-1900-0000-f145-327baa090000 pid=2474 clone guuid=90205e5a-1900-0000-f145-327baf090000 pid=2479 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=90205e5a-1900-0000-f145-327baf090000 pid=2479 execve guuid=9adcae5a-1900-0000-f145-327bb1090000 pid=2481 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=9adcae5a-1900-0000-f145-327bb1090000 pid=2481 execve guuid=8785e05e-1900-0000-f145-327bb9090000 pid=2489 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=8785e05e-1900-0000-f145-327bb9090000 pid=2489 execve guuid=e527c965-1900-0000-f145-327bcb090000 pid=2507 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=e527c965-1900-0000-f145-327bcb090000 pid=2507 execve guuid=a3cc6666-1900-0000-f145-327bcd090000 pid=2509 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=a3cc6666-1900-0000-f145-327bcd090000 pid=2509 clone guuid=69fa2f68-1900-0000-f145-327bcf090000 pid=2511 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=69fa2f68-1900-0000-f145-327bcf090000 pid=2511 execve guuid=662fa76c-1900-0000-f145-327bd0090000 pid=2512 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=662fa76c-1900-0000-f145-327bd0090000 pid=2512 execve guuid=4929a070-1900-0000-f145-327bda090000 pid=2522 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4929a070-1900-0000-f145-327bda090000 pid=2522 execve guuid=d58c2b76-1900-0000-f145-327bea090000 pid=2538 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=d58c2b76-1900-0000-f145-327bea090000 pid=2538 execve guuid=1ebe7d76-1900-0000-f145-327bec090000 pid=2540 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=1ebe7d76-1900-0000-f145-327bec090000 pid=2540 clone guuid=47ec4677-1900-0000-f145-327bf0090000 pid=2544 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=47ec4677-1900-0000-f145-327bf0090000 pid=2544 execve guuid=b569967a-1900-0000-f145-327bf8090000 pid=2552 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=b569967a-1900-0000-f145-327bf8090000 pid=2552 execve guuid=be374d7f-1900-0000-f145-327b040a0000 pid=2564 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=be374d7f-1900-0000-f145-327b040a0000 pid=2564 execve guuid=9274fa84-1900-0000-f145-327b100a0000 pid=2576 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=9274fa84-1900-0000-f145-327b100a0000 pid=2576 execve guuid=adf84485-1900-0000-f145-327b120a0000 pid=2578 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=adf84485-1900-0000-f145-327b120a0000 pid=2578 clone guuid=4353e985-1900-0000-f145-327b150a0000 pid=2581 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=4353e985-1900-0000-f145-327b150a0000 pid=2581 execve guuid=164d3c86-1900-0000-f145-327b170a0000 pid=2583 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=164d3c86-1900-0000-f145-327b170a0000 pid=2583 execve guuid=19a8338a-1900-0000-f145-327b220a0000 pid=2594 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=19a8338a-1900-0000-f145-327b220a0000 pid=2594 execve guuid=79074b8f-1900-0000-f145-327b2e0a0000 pid=2606 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=79074b8f-1900-0000-f145-327b2e0a0000 pid=2606 execve guuid=b9f9af8f-1900-0000-f145-327b300a0000 pid=2608 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=b9f9af8f-1900-0000-f145-327b300a0000 pid=2608 clone guuid=01e4b691-1900-0000-f145-327b350a0000 pid=2613 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=01e4b691-1900-0000-f145-327b350a0000 pid=2613 execve guuid=94643c96-1900-0000-f145-327b3d0a0000 pid=2621 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=94643c96-1900-0000-f145-327b3d0a0000 pid=2621 execve guuid=a0e67e9b-1900-0000-f145-327b4d0a0000 pid=2637 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=a0e67e9b-1900-0000-f145-327b4d0a0000 pid=2637 execve guuid=511667a1-1900-0000-f145-327b5b0a0000 pid=2651 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=511667a1-1900-0000-f145-327b5b0a0000 pid=2651 execve guuid=5ea2aaa1-1900-0000-f145-327b5d0a0000 pid=2653 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=5ea2aaa1-1900-0000-f145-327b5d0a0000 pid=2653 clone guuid=67b934a2-1900-0000-f145-327b610a0000 pid=2657 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=67b934a2-1900-0000-f145-327b610a0000 pid=2657 execve guuid=6e4e3da3-1900-0000-f145-327b650a0000 pid=2661 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=6e4e3da3-1900-0000-f145-327b650a0000 pid=2661 execve guuid=80645ca8-1900-0000-f145-327b700a0000 pid=2672 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=80645ca8-1900-0000-f145-327b700a0000 pid=2672 execve guuid=783817b0-1900-0000-f145-327b830a0000 pid=2691 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=783817b0-1900-0000-f145-327b830a0000 pid=2691 execve guuid=80287db0-1900-0000-f145-327b860a0000 pid=2694 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=80287db0-1900-0000-f145-327b860a0000 pid=2694 clone guuid=3a6e5cb1-1900-0000-f145-327b8b0a0000 pid=2699 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=3a6e5cb1-1900-0000-f145-327b8b0a0000 pid=2699 execve guuid=e2b4bab1-1900-0000-f145-327b8d0a0000 pid=2701 /usr/bin/wget net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=e2b4bab1-1900-0000-f145-327b8d0a0000 pid=2701 execve guuid=a6a02eb6-1900-0000-f145-327b990a0000 pid=2713 /usr/bin/curl net send-data write-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=a6a02eb6-1900-0000-f145-327b990a0000 pid=2713 execve guuid=953c7cbb-1900-0000-f145-327ba80a0000 pid=2728 /usr/bin/chmod guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=953c7cbb-1900-0000-f145-327ba80a0000 pid=2728 execve guuid=859fbebb-1900-0000-f145-327baa0a0000 pid=2730 /usr/bin/bash guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=859fbebb-1900-0000-f145-327baa0a0000 pid=2730 clone guuid=2a2750bc-1900-0000-f145-327bad0a0000 pid=2733 /usr/bin/rm delete-file guuid=086df7df-1800-0000-f145-327b9c080000 pid=2204->guuid=2a2750bc-1900-0000-f145-327bad0a0000 pid=2733 execve e61310d3-8a78-57b3-879d-da359d378fb5 196.251.69.179:80 guuid=ea4fdee7-1800-0000-f145-327bad080000 pid=2221->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=e460a5ee-1800-0000-f145-327bbf080000 pid=2239->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cddcb3f9-1800-0000-f145-327bd3080000 pid=2259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f3a438fa-1800-0000-f145-327bd6080000 pid=2262 /tmp/morte.x86 guuid=cddcb3f9-1800-0000-f145-327bd3080000 pid=2259->guuid=f3a438fa-1800-0000-f145-327bd6080000 pid=2262 clone guuid=c88e53fa-1800-0000-f145-327bd8080000 pid=2264 /tmp/morte.x86 write-config zombie guuid=f3a438fa-1800-0000-f145-327bd6080000 pid=2262->guuid=c88e53fa-1800-0000-f145-327bd8080000 pid=2264 clone guuid=09c3f8ff-1800-0000-f145-327be4080000 pid=2276 /usr/bin/dash guuid=c88e53fa-1800-0000-f145-327bd8080000 pid=2264->guuid=09c3f8ff-1800-0000-f145-327be4080000 pid=2276 execve guuid=2ade3902-1900-0000-f145-327bed080000 pid=2285 /tmp/morte.x86 delete-file guuid=c88e53fa-1800-0000-f145-327bd8080000 pid=2264->guuid=2ade3902-1900-0000-f145-327bed080000 pid=2285 clone guuid=fd6587fa-1800-0000-f145-327bda080000 pid=2266->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=2aa2b9fe-1800-0000-f145-327bdf080000 pid=2271->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=6f392700-1900-0000-f145-327be6080000 pid=2278 /usr/bin/cp guuid=09c3f8ff-1800-0000-f145-327be4080000 pid=2276->guuid=6f392700-1900-0000-f145-327be6080000 pid=2278 execve guuid=f2358208-1900-0000-f145-327bfc080000 pid=2300->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=1b7b6e0e-1900-0000-f145-327b08090000 pid=2312->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B guuid=85ae8e19-1900-0000-f145-327b1b090000 pid=2331->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=0d88131d-1900-0000-f145-327b26090000 pid=2342->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=29242722-1900-0000-f145-327b32090000 pid=2354->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=4775de25-1900-0000-f145-327b38090000 pid=2360->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=d7341c2b-1900-0000-f145-327b48090000 pid=2376->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=947a4e2b-1900-0000-f145-327b49090000 pid=2377 /tmp/morte.i686 guuid=d7341c2b-1900-0000-f145-327b48090000 pid=2376->guuid=947a4e2b-1900-0000-f145-327b49090000 pid=2377 clone guuid=ca69a72b-1900-0000-f145-327b4c090000 pid=2380 /tmp/morte.i686 write-config zombie guuid=947a4e2b-1900-0000-f145-327b49090000 pid=2377->guuid=ca69a72b-1900-0000-f145-327b4c090000 pid=2380 clone guuid=7bbba12b-1900-0000-f145-327b4b090000 pid=2379->e61310d3-8a78-57b3-879d-da359d378fb5 send: 156B guuid=4580e12f-1900-0000-f145-327b4f090000 pid=2383 /usr/bin/dash guuid=ca69a72b-1900-0000-f145-327b4c090000 pid=2380->guuid=4580e12f-1900-0000-f145-327b4f090000 pid=2383 execve guuid=67d23332-1900-0000-f145-327b58090000 pid=2392 /tmp/morte.i686 dns net send-data guuid=ca69a72b-1900-0000-f145-327b4c090000 pid=2380->guuid=67d23332-1900-0000-f145-327b58090000 pid=2392 clone guuid=62220c30-1900-0000-f145-327b50090000 pid=2384 /usr/bin/cp guuid=4580e12f-1900-0000-f145-327b4f090000 pid=2383->guuid=62220c30-1900-0000-f145-327b50090000 pid=2384 execve guuid=0f7c5230-1900-0000-f145-327b52090000 pid=2386->e61310d3-8a78-57b3-879d-da359d378fb5 send: 105B guuid=67d23332-1900-0000-f145-327b58090000 pid=2392->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 660B db1a8809-6dda-51f4-9007-a18c1a012ced abc.izumisv1.cc:12121 guuid=67d23332-1900-0000-f145-327b58090000 pid=2392->db1a8809-6dda-51f4-9007-a18c1a012ced send: 400B guuid=c0e21939-1900-0000-f145-327b67090000 pid=2407->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4381a339-1900-0000-f145-327b68090000 pid=2408 /tmp/morte.x86_64 zombie guuid=c0e21939-1900-0000-f145-327b67090000 pid=2407->guuid=4381a339-1900-0000-f145-327b68090000 pid=2408 clone guuid=732cd939-1900-0000-f145-327b6a090000 pid=2410 /tmp/morte.x86_64 write-config zombie guuid=4381a339-1900-0000-f145-327b68090000 pid=2408->guuid=732cd939-1900-0000-f145-327b6a090000 pid=2410 clone guuid=ff7fef3a-1900-0000-f145-327b6e090000 pid=2414 /usr/bin/dash guuid=732cd939-1900-0000-f145-327b6a090000 pid=2410->guuid=ff7fef3a-1900-0000-f145-327b6e090000 pid=2414 execve guuid=a9b7c53d-1900-0000-f145-327b78090000 pid=2424 /tmp/morte.x86_64 delete-file dns net send-data zombie guuid=732cd939-1900-0000-f145-327b6a090000 pid=2410->guuid=a9b7c53d-1900-0000-f145-327b78090000 pid=2424 clone guuid=1b1cdd3b-1900-0000-f145-327b73090000 pid=2419 /usr/bin/cp guuid=ff7fef3a-1900-0000-f145-327b6e090000 pid=2414->guuid=1b1cdd3b-1900-0000-f145-327b73090000 pid=2419 execve guuid=c5b6aa3b-1900-0000-f145-327b71090000 pid=2417->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=a9b7c53d-1900-0000-f145-327b78090000 pid=2424->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 66B guuid=a9b7c53d-1900-0000-f145-327b78090000 pid=2424->db1a8809-6dda-51f4-9007-a18c1a012ced send: 44B guuid=4d4ca740-1900-0000-f145-327b82090000 pid=2434->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=ea50404d-1900-0000-f145-327b94090000 pid=2452->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=ecac8552-1900-0000-f145-327b9b090000 pid=2459->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B guuid=9adcae5a-1900-0000-f145-327bb1090000 pid=2481->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=8785e05e-1900-0000-f145-327bb9090000 pid=2489->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=662fa76c-1900-0000-f145-327bd0090000 pid=2512->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=4929a070-1900-0000-f145-327bda090000 pid=2522->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=b569967a-1900-0000-f145-327bf8090000 pid=2552->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=be374d7f-1900-0000-f145-327b040a0000 pid=2564->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=164d3c86-1900-0000-f145-327b170a0000 pid=2583->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=19a8338a-1900-0000-f145-327b220a0000 pid=2594->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B guuid=94643c96-1900-0000-f145-327b3d0a0000 pid=2621->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=a0e67e9b-1900-0000-f145-327b4d0a0000 pid=2637->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B guuid=6e4e3da3-1900-0000-f145-327b650a0000 pid=2661->e61310d3-8a78-57b3-879d-da359d378fb5 send: 154B guuid=80645ca8-1900-0000-f145-327b700a0000 pid=2672->e61310d3-8a78-57b3-879d-da359d378fb5 send: 103B guuid=e2b4bab1-1900-0000-f145-327b8d0a0000 pid=2701->e61310d3-8a78-57b3-879d-da359d378fb5 send: 153B guuid=a6a02eb6-1900-0000-f145-327b990a0000 pid=2713->e61310d3-8a78-57b3-879d-da359d378fb5 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-11 07:00:30 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
abc.izumisv1.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 46626ff6e0c9ca700c398f551d7ad5a3fea186abf400c37de81dbb13b0e1f3f2

(this sample)

Comments