MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4ea30e2466ac21c67873e946bc93b824d154a224ee8a2fe76f314f49e1b6446a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 4ea30e2466ac21c67873e946bc93b824d154a224ee8a2fe76f314f49e1b6446a
SHA3-384 hash: 0670690fbc861048790169bf2afb6e8a3e4af25d92a563a36e759b5845a9936f7885bf6f5d601aa2c5e0c5d2f2b0f98e
SHA1 hash: 620c141f62eb7141619441bf1ef5a55355f9af6e
MD5 hash: 21f76baf5a73eba37fdb9d6e5e7ef21f
humanhash: vegan-blossom-pip-carolina
File name:1.sh
Download: download sample
Signature Mirai
File size:2'969 bytes
First seen:2025-10-19 23:28:30 UTC
Last seen:2025-10-20 22:42:29 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItkT4sk8XkKOKsFkU1BkK+skSrkhTh5JkAAAaNka3LkvTvNI8kskIbkM/k6A6XXM:i+bJHsFPxxSFf2FLeJ/J7XHOju/i
TLSH T15F519FD520658B703E659D2AF7B9481C3C85A1DB50C71FA6AAEA3CA848CFD2875C07D2
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://144.172.109.62/Orbt/Orbt.x8668c85af1a2a9ef2f74cd53ed39cc9e00333b961e9f51b9c55ff679c0197a2ae0 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.mips74b0536ba2de49f1989592c085010eb3400aa33b4a4b85424e320fb74d143d82 Miraielf gafgyt mirai ua-wget
http://144.172.109.62/Orbt/Orbt.arc0d82c11a95b346a400b5a0e83c7f4a71fd0ccee56e66169cf6bfbc86d8d97e5f Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.i468n/an/aelf ua-wget
http://144.172.109.62/Orbt/Orbt.i6863355e0e1089c7f56e7d89ac87e9726ad9132d773c120342787eb2113e6956f32 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.x86_6468aa9d2e946a9cd7b886e7b1e3c0e30e3599260a76f8ccd45883748bdd4d43e0 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.mpsl784db215b440dbd938978437151c78733af63be748c51c04ea8a52e9ba560576 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.armdae6bf3bd0f3c3d79660d75ca611430d1f8b2c0857be97b5ed27372db2a2bfd6 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.arm5367d2f567b2b318282e3cd5a389b481205d4161bd2811f7cc5f728eaa154a3ba Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.arm656bc93c42245723780b706d193f7f1a3a2c46d4665c333f22bf9c58116b9cd18 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.arm74f7ea3e11393cbe8863cadbcbdeabde5a091dba32cdb22bd8ef3bdf3c2b615b2 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.ppc2541e7c6889f9f3322ac0a8eda7f15f46b8c4f8d742953235d8818a41245e62b Gafgytelf gafgyt mirai ua-wget
http://144.172.109.62/Orbt/Orbt.spc6eda1367bf822811a7d0e2b47903fa6983741685b017f17282638fbf9b889091 Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.m68ka4c662015b1a6698af83ffa3b2f90562d673299e8b7516c8aa4a0a145b6173ef Miraielf mirai ua-wget
http://144.172.109.62/Orbt/Orbt.sh40018c3a0ebe07eafddadceb7fef8fe50ce6a468fc22df79f7d586d0c96b82499 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-19T20:33:00Z UTC
Last seen:
2025-10-21T18:33:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=1b7519a5-1700-0000-9e3b-7852ab0b0000 pid=2987 /usr/bin/sudo guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995 /tmp/sample.bin guuid=1b7519a5-1700-0000-9e3b-7852ab0b0000 pid=2987->guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995 execve guuid=9c2777a7-1700-0000-9e3b-7852b50b0000 pid=2997 /usr/bin/cp guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=9c2777a7-1700-0000-9e3b-7852b50b0000 pid=2997 execve guuid=912ce5ac-1700-0000-9e3b-7852c10b0000 pid=3009 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=912ce5ac-1700-0000-9e3b-7852c10b0000 pid=3009 execve guuid=3e2fd4d2-1700-0000-9e3b-78521d0c0000 pid=3101 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=3e2fd4d2-1700-0000-9e3b-78521d0c0000 pid=3101 execve guuid=1f34aaf9-1700-0000-9e3b-7852600c0000 pid=3168 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=1f34aaf9-1700-0000-9e3b-7852600c0000 pid=3168 execve guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169 /tmp/Orbt.x86 net guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169 execve guuid=c36b8728-1900-0000-9e3b-78524a0e0000 pid=3658 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=c36b8728-1900-0000-9e3b-78524a0e0000 pid=3658 execve guuid=48166529-1900-0000-9e3b-78524b0e0000 pid=3659 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=48166529-1900-0000-9e3b-78524b0e0000 pid=3659 execve guuid=93d7a44f-1900-0000-9e3b-7852950e0000 pid=3733 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=93d7a44f-1900-0000-9e3b-7852950e0000 pid=3733 execve guuid=19fa4d75-1900-0000-9e3b-7852070f0000 pid=3847 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=19fa4d75-1900-0000-9e3b-7852070f0000 pid=3847 execve guuid=37acf175-1900-0000-9e3b-78520a0f0000 pid=3850 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=37acf175-1900-0000-9e3b-78520a0f0000 pid=3850 clone guuid=d3750977-1900-0000-9e3b-78520c0f0000 pid=3852 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=d3750977-1900-0000-9e3b-78520c0f0000 pid=3852 execve guuid=f8908d77-1900-0000-9e3b-78520e0f0000 pid=3854 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f8908d77-1900-0000-9e3b-78520e0f0000 pid=3854 execve guuid=eb4e5fa4-1900-0000-9e3b-7852880f0000 pid=3976 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=eb4e5fa4-1900-0000-9e3b-7852880f0000 pid=3976 execve guuid=29f295d3-1900-0000-9e3b-785202100000 pid=4098 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=29f295d3-1900-0000-9e3b-785202100000 pid=4098 execve guuid=961d2ed4-1900-0000-9e3b-785206100000 pid=4102 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=961d2ed4-1900-0000-9e3b-785206100000 pid=4102 clone guuid=cdfdc4d4-1900-0000-9e3b-78520b100000 pid=4107 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=cdfdc4d4-1900-0000-9e3b-78520b100000 pid=4107 execve guuid=468c0dd5-1900-0000-9e3b-78520c100000 pid=4108 /usr/bin/wget net send-data guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=468c0dd5-1900-0000-9e3b-78520c100000 pid=4108 execve guuid=9884c2e8-1900-0000-9e3b-78523e100000 pid=4158 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=9884c2e8-1900-0000-9e3b-78523e100000 pid=4158 execve guuid=2d6f0600-1a00-0000-9e3b-78527d100000 pid=4221 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=2d6f0600-1a00-0000-9e3b-78527d100000 pid=4221 execve guuid=cc7e9200-1a00-0000-9e3b-78527f100000 pid=4223 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=cc7e9200-1a00-0000-9e3b-78527f100000 pid=4223 clone guuid=d985dc00-1a00-0000-9e3b-785280100000 pid=4224 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=d985dc00-1a00-0000-9e3b-785280100000 pid=4224 execve guuid=07166601-1a00-0000-9e3b-785283100000 pid=4227 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=07166601-1a00-0000-9e3b-785283100000 pid=4227 execve guuid=e34e4d26-1a00-0000-9e3b-7852f2100000 pid=4338 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=e34e4d26-1a00-0000-9e3b-7852f2100000 pid=4338 execve guuid=42f0e54b-1a00-0000-9e3b-785269110000 pid=4457 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=42f0e54b-1a00-0000-9e3b-785269110000 pid=4457 execve guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459 /tmp/Orbt.i686 net guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459 execve guuid=c990647a-1b00-0000-9e3b-78520c140000 pid=5132 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=c990647a-1b00-0000-9e3b-78520c140000 pid=5132 execve guuid=045a007b-1b00-0000-9e3b-78520e140000 pid=5134 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=045a007b-1b00-0000-9e3b-78520e140000 pid=5134 execve guuid=298565a0-1b00-0000-9e3b-785266140000 pid=5222 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=298565a0-1b00-0000-9e3b-785266140000 pid=5222 execve guuid=c035d0c7-1b00-0000-9e3b-785284140000 pid=5252 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=c035d0c7-1b00-0000-9e3b-785284140000 pid=5252 execve guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253 /tmp/Orbt.x86_64 mprotect-exec net guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253 execve guuid=81f615f8-1c00-0000-9e3b-785293140000 pid=5267 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=81f615f8-1c00-0000-9e3b-785293140000 pid=5267 execve guuid=0e6ca3fc-1c00-0000-9e3b-785294140000 pid=5268 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=0e6ca3fc-1c00-0000-9e3b-785294140000 pid=5268 execve guuid=1bc58f20-1d00-0000-9e3b-785295140000 pid=5269 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=1bc58f20-1d00-0000-9e3b-785295140000 pid=5269 execve guuid=4f0b0146-1d00-0000-9e3b-785296140000 pid=5270 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=4f0b0146-1d00-0000-9e3b-785296140000 pid=5270 execve guuid=5c2b4446-1d00-0000-9e3b-785297140000 pid=5271 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=5c2b4446-1d00-0000-9e3b-785297140000 pid=5271 clone guuid=ca6fcc46-1d00-0000-9e3b-785299140000 pid=5273 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=ca6fcc46-1d00-0000-9e3b-785299140000 pid=5273 execve guuid=579b0b47-1d00-0000-9e3b-78529a140000 pid=5274 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=579b0b47-1d00-0000-9e3b-78529a140000 pid=5274 execve guuid=9f9d526a-1d00-0000-9e3b-78529c140000 pid=5276 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=9f9d526a-1d00-0000-9e3b-78529c140000 pid=5276 execve guuid=ba8e268e-1d00-0000-9e3b-7852a9140000 pid=5289 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=ba8e268e-1d00-0000-9e3b-7852a9140000 pid=5289 execve guuid=fec2708e-1d00-0000-9e3b-7852aa140000 pid=5290 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=fec2708e-1d00-0000-9e3b-7852aa140000 pid=5290 clone guuid=243e028f-1d00-0000-9e3b-7852ac140000 pid=5292 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=243e028f-1d00-0000-9e3b-7852ac140000 pid=5292 execve guuid=f1eb8f8f-1d00-0000-9e3b-7852ad140000 pid=5293 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f1eb8f8f-1d00-0000-9e3b-7852ad140000 pid=5293 execve guuid=9a6f18aa-1d00-0000-9e3b-7852b2140000 pid=5298 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=9a6f18aa-1d00-0000-9e3b-7852b2140000 pid=5298 execve guuid=c64096c5-1d00-0000-9e3b-7852c2140000 pid=5314 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=c64096c5-1d00-0000-9e3b-7852c2140000 pid=5314 execve guuid=db86d7c5-1d00-0000-9e3b-7852c3140000 pid=5315 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=db86d7c5-1d00-0000-9e3b-7852c3140000 pid=5315 clone guuid=974a6cc6-1d00-0000-9e3b-7852c5140000 pid=5317 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=974a6cc6-1d00-0000-9e3b-7852c5140000 pid=5317 execve guuid=e1adc2c6-1d00-0000-9e3b-7852c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=e1adc2c6-1d00-0000-9e3b-7852c6140000 pid=5318 execve guuid=9e58fbe9-1d00-0000-9e3b-7852c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=9e58fbe9-1d00-0000-9e3b-7852c7140000 pid=5319 execve guuid=ab9c190f-1e00-0000-9e3b-7852c8140000 pid=5320 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=ab9c190f-1e00-0000-9e3b-7852c8140000 pid=5320 execve guuid=7b9b6c0f-1e00-0000-9e3b-7852c9140000 pid=5321 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=7b9b6c0f-1e00-0000-9e3b-7852c9140000 pid=5321 clone guuid=267f1910-1e00-0000-9e3b-7852cb140000 pid=5323 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=267f1910-1e00-0000-9e3b-7852cb140000 pid=5323 execve guuid=de0f6f10-1e00-0000-9e3b-7852cc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=de0f6f10-1e00-0000-9e3b-7852cc140000 pid=5324 execve guuid=eb64a433-1e00-0000-9e3b-7852cd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=eb64a433-1e00-0000-9e3b-7852cd140000 pid=5325 execve guuid=11c83a5a-1e00-0000-9e3b-7852ce140000 pid=5326 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=11c83a5a-1e00-0000-9e3b-7852ce140000 pid=5326 execve guuid=ccb2c45a-1e00-0000-9e3b-7852cf140000 pid=5327 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=ccb2c45a-1e00-0000-9e3b-7852cf140000 pid=5327 clone guuid=3d94e55b-1e00-0000-9e3b-7852d1140000 pid=5329 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=3d94e55b-1e00-0000-9e3b-7852d1140000 pid=5329 execve guuid=10b7775c-1e00-0000-9e3b-7852d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=10b7775c-1e00-0000-9e3b-7852d2140000 pid=5330 execve guuid=ce9b4880-1e00-0000-9e3b-7852d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=ce9b4880-1e00-0000-9e3b-7852d3140000 pid=5331 execve guuid=91dccfa5-1e00-0000-9e3b-7852d4140000 pid=5332 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=91dccfa5-1e00-0000-9e3b-7852d4140000 pid=5332 execve guuid=898468a6-1e00-0000-9e3b-7852d5140000 pid=5333 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=898468a6-1e00-0000-9e3b-7852d5140000 pid=5333 clone guuid=51f681a7-1e00-0000-9e3b-7852d7140000 pid=5335 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=51f681a7-1e00-0000-9e3b-7852d7140000 pid=5335 execve guuid=f4b007a9-1e00-0000-9e3b-7852d8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f4b007a9-1e00-0000-9e3b-7852d8140000 pid=5336 execve guuid=4c1d17cf-1e00-0000-9e3b-7852d9140000 pid=5337 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=4c1d17cf-1e00-0000-9e3b-7852d9140000 pid=5337 execve guuid=b98786f4-1e00-0000-9e3b-7852da140000 pid=5338 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=b98786f4-1e00-0000-9e3b-7852da140000 pid=5338 execve guuid=161e16f5-1e00-0000-9e3b-7852db140000 pid=5339 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=161e16f5-1e00-0000-9e3b-7852db140000 pid=5339 clone guuid=211f43f6-1e00-0000-9e3b-7852dd140000 pid=5341 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=211f43f6-1e00-0000-9e3b-7852dd140000 pid=5341 execve guuid=4b54d6f6-1e00-0000-9e3b-7852de140000 pid=5342 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=4b54d6f6-1e00-0000-9e3b-7852de140000 pid=5342 execve guuid=35212324-1f00-0000-9e3b-7852df140000 pid=5343 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=35212324-1f00-0000-9e3b-7852df140000 pid=5343 execve guuid=15804f52-1f00-0000-9e3b-7852e0140000 pid=5344 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=15804f52-1f00-0000-9e3b-7852e0140000 pid=5344 execve guuid=d22ed752-1f00-0000-9e3b-7852e1140000 pid=5345 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=d22ed752-1f00-0000-9e3b-7852e1140000 pid=5345 clone guuid=bd4d3654-1f00-0000-9e3b-7852e3140000 pid=5347 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=bd4d3654-1f00-0000-9e3b-7852e3140000 pid=5347 execve guuid=e606cd54-1f00-0000-9e3b-7852e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=e606cd54-1f00-0000-9e3b-7852e4140000 pid=5348 execve guuid=f7687d81-1f00-0000-9e3b-7852e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f7687d81-1f00-0000-9e3b-7852e5140000 pid=5349 execve guuid=f74bc7af-1f00-0000-9e3b-7852e6140000 pid=5350 /usr/bin/chmod guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=f74bc7af-1f00-0000-9e3b-7852e6140000 pid=5350 execve guuid=6a971eb0-1f00-0000-9e3b-7852e7140000 pid=5351 /usr/bin/bash guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=6a971eb0-1f00-0000-9e3b-7852e7140000 pid=5351 clone guuid=7e67bab0-1f00-0000-9e3b-7852e9140000 pid=5353 /usr/bin/rm delete-file guuid=38c319a7-1700-0000-9e3b-7852b30b0000 pid=2995->guuid=7e67bab0-1f00-0000-9e3b-7852e9140000 pid=5353 execve 83b0964e-e5bb-55d5-a8e6-b9eaf25e09c1 144.172.109.62:80 guuid=912ce5ac-1700-0000-9e3b-7852c10b0000 pid=3009->83b0964e-e5bb-55d5-a8e6-b9eaf25e09c1 send: 142B guuid=3e2fd4d2-1700-0000-9e3b-78521d0c0000 pid=3101->83b0964e-e5bb-55d5-a8e6-b9eaf25e09c1 send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5fae53fb-1700-0000-9e3b-7852620c0000 pid=3170 /tmp/Orbt.x86 guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169->guuid=5fae53fb-1700-0000-9e3b-7852620c0000 pid=3170 clone guuid=a1f34f28-1900-0000-9e3b-7852480e0000 pid=3656 /tmp/Orbt.x86 guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169->guuid=a1f34f28-1900-0000-9e3b-7852480e0000 pid=3656 clone guuid=d6865f28-1900-0000-9e3b-7852490e0000 pid=3657 /tmp/Orbt.x86 net send-data zombie guuid=b9fd51fa-1700-0000-9e3b-7852610c0000 pid=3169->guuid=d6865f28-1900-0000-9e3b-7852490e0000 pid=3657 clone guuid=2dd05dfb-1700-0000-9e3b-7852630c0000 pid=3171 /tmp/Orbt.x86 guuid=5fae53fb-1700-0000-9e3b-7852620c0000 pid=3170->guuid=2dd05dfb-1700-0000-9e3b-7852630c0000 pid=3171 clone guuid=e2fb62fb-1700-0000-9e3b-7852640c0000 pid=3172 /tmp/Orbt.x86 dns net send-data zombie guuid=5fae53fb-1700-0000-9e3b-7852620c0000 pid=3170->guuid=e2fb62fb-1700-0000-9e3b-7852640c0000 pid=3172 clone guuid=e2fb62fb-1700-0000-9e3b-7852640c0000 pid=3172->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 90B 0ecf02bb-0e2c-5ebd-8166-f09908e50581 mirailoversddos.duckdns.org:69 guuid=e2fb62fb-1700-0000-9e3b-7852640c0000 pid=3172->0ecf02bb-0e2c-5ebd-8166-f09908e50581 send: 32B guuid=d6865f28-1900-0000-9e3b-7852490e0000 pid=3657->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1150B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=d6865f28-1900-0000-9e3b-7852490e0000 pid=3657->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B 50f4a7af-3780-5248-b2cc-de15b6c8e346 mirailoversddos.duckdns.org:80 guuid=48166529-1900-0000-9e3b-78524b0e0000 pid=3659->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=93d7a44f-1900-0000-9e3b-7852950e0000 pid=3733->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=f8908d77-1900-0000-9e3b-78520e0f0000 pid=3854->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 142B guuid=eb4e5fa4-1900-0000-9e3b-7852880f0000 pid=3976->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 91B guuid=468c0dd5-1900-0000-9e3b-78520c100000 pid=4108->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=9884c2e8-1900-0000-9e3b-78523e100000 pid=4158->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=07166601-1a00-0000-9e3b-785283100000 pid=4227->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=e34e4d26-1a00-0000-9e3b-7852f2100000 pid=4338->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1821c44d-1a00-0000-9e3b-785271110000 pid=4465 /tmp/Orbt.i686 guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459->guuid=1821c44d-1a00-0000-9e3b-785271110000 pid=4465 clone guuid=535b357a-1b00-0000-9e3b-78520a140000 pid=5130 /tmp/Orbt.i686 guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459->guuid=535b357a-1b00-0000-9e3b-78520a140000 pid=5130 clone guuid=68163e7a-1b00-0000-9e3b-78520b140000 pid=5131 /tmp/Orbt.i686 net send-data zombie guuid=f3826a4c-1a00-0000-9e3b-78526b110000 pid=4459->guuid=68163e7a-1b00-0000-9e3b-78520b140000 pid=5131 clone guuid=ca13d14d-1a00-0000-9e3b-785274110000 pid=4468 /tmp/Orbt.i686 guuid=1821c44d-1a00-0000-9e3b-785271110000 pid=4465->guuid=ca13d14d-1a00-0000-9e3b-785274110000 pid=4468 clone guuid=3f85d94d-1a00-0000-9e3b-785275110000 pid=4469 /tmp/Orbt.i686 dns net send-data zombie guuid=1821c44d-1a00-0000-9e3b-785271110000 pid=4465->guuid=3f85d94d-1a00-0000-9e3b-785275110000 pid=4469 clone guuid=3f85d94d-1a00-0000-9e3b-785275110000 pid=4469->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 45B guuid=3f85d94d-1a00-0000-9e3b-785275110000 pid=4469->0ecf02bb-0e2c-5ebd-8166-f09908e50581 send: 17B guuid=68163e7a-1b00-0000-9e3b-78520b140000 pid=5131->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1058B guuid=68163e7a-1b00-0000-9e3b-78520b140000 pid=5131->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=045a007b-1b00-0000-9e3b-78520e140000 pid=5134->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 145B guuid=298565a0-1b00-0000-9e3b-785266140000 pid=5222->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 94B guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c91323c9-1b00-0000-9e3b-785287140000 pid=5255 /tmp/Orbt.x86_64 guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253->guuid=c91323c9-1b00-0000-9e3b-785287140000 pid=5255 clone guuid=9f9ff1f7-1c00-0000-9e3b-785291140000 pid=5265 /tmp/Orbt.x86_64 guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253->guuid=9f9ff1f7-1c00-0000-9e3b-785291140000 pid=5265 clone guuid=69d200f8-1c00-0000-9e3b-785292140000 pid=5266 /tmp/Orbt.x86_64 net send-data zombie guuid=56d521c8-1b00-0000-9e3b-785285140000 pid=5253->guuid=69d200f8-1c00-0000-9e3b-785292140000 pid=5266 clone guuid=177c2ac9-1b00-0000-9e3b-785288140000 pid=5256 /tmp/Orbt.x86_64 guuid=c91323c9-1b00-0000-9e3b-785287140000 pid=5255->guuid=177c2ac9-1b00-0000-9e3b-785288140000 pid=5256 clone guuid=82cc2fc9-1b00-0000-9e3b-785289140000 pid=5257 /tmp/Orbt.x86_64 net send-data zombie guuid=c91323c9-1b00-0000-9e3b-785287140000 pid=5255->guuid=82cc2fc9-1b00-0000-9e3b-785289140000 pid=5257 clone guuid=82cc2fc9-1b00-0000-9e3b-785289140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 900B guuid=82cc2fc9-1b00-0000-9e3b-785289140000 pid=5257->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=69d200f8-1c00-0000-9e3b-785292140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 920B guuid=69d200f8-1c00-0000-9e3b-785292140000 pid=5266->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=0e6ca3fc-1c00-0000-9e3b-785294140000 pid=5268->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=1bc58f20-1d00-0000-9e3b-785295140000 pid=5269->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=579b0b47-1d00-0000-9e3b-78529a140000 pid=5274->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 142B guuid=9f9d526a-1d00-0000-9e3b-78529c140000 pid=5276->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 91B guuid=f1eb8f8f-1d00-0000-9e3b-7852ad140000 pid=5293->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=9a6f18aa-1d00-0000-9e3b-7852b2140000 pid=5298->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=e1adc2c6-1d00-0000-9e3b-7852c6140000 pid=5318->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=9e58fbe9-1d00-0000-9e3b-7852c7140000 pid=5319->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=de0f6f10-1e00-0000-9e3b-7852cc140000 pid=5324->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=eb64a433-1e00-0000-9e3b-7852cd140000 pid=5325->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=10b7775c-1e00-0000-9e3b-7852d2140000 pid=5330->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 142B guuid=ce9b4880-1e00-0000-9e3b-7852d3140000 pid=5331->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 91B guuid=f4b007a9-1e00-0000-9e3b-7852d8140000 pid=5336->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 142B guuid=4c1d17cf-1e00-0000-9e3b-7852d9140000 pid=5337->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 91B guuid=4b54d6f6-1e00-0000-9e3b-7852de140000 pid=5342->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 143B guuid=35212324-1f00-0000-9e3b-7852df140000 pid=5343->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 92B guuid=e606cd54-1f00-0000-9e3b-7852e4140000 pid=5348->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 142B guuid=f7687d81-1f00-0000-9e3b-7852e5140000 pid=5349->50f4a7af-3780-5248-b2cc-de15b6c8e346 send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-19 23:29:32 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
mirailoversddos.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4ea30e2466ac21c67873e946bc93b824d154a224ee8a2fe76f314f49e1b6446a

(this sample)

  
Delivery method
Distributed via web download

Comments