MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 54f074f9741c2480533ce774637dae79d011ba9bc616e1215ad9ddf488e162f6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 54f074f9741c2480533ce774637dae79d011ba9bc616e1215ad9ddf488e162f6
SHA3-384 hash: 2322b6a02ed0f6c8aada55177ef506d96df5c02779d5354026043aa1deb318ccd7387007027115dc31f41467658ef308
SHA1 hash: a874100187ea57278aae5e504c4a38536e94c134
MD5 hash: 04dbcaf16b0c7e7bf92a85d6916241aa
humanhash: uncle-double-virginia-grey
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-10-12 23:02:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItTZs3bhvkvlfrms/T10GgJH6HnLzKNIpKksHMEXh7szmcGgJslVpk:im1sVDL101aHLkJBxQzmBgJs5k
TLSH T1F6615DFA134146379CAA8AD332A88508F164B49B94CE9F75DFDD28F99C8CEC93C41A41
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://143.20.185.225/00101010101001/morte.x863d241827f1484f1b5f563efc3d6f116f9346380a920ba93349d8d4dbceae9b4f Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.mipsff9c2d0dcb7c4a5b58574473bcc5fae143b4360365b4692e6d4fa59fb2bac44a Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.arcfc2f69664dd6fdef2e2863488657f4119b857758613de17704c4bea0edb3d705 Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.i468n/an/aelf ua-wget
http://143.20.185.225/00101010101001/morte.i686518faa4fee85b372113e37daa020f4e9484048e50e42941368cc26056c7680ef Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.x86_64002b721da2bc498543d53ab4bcc641e976a15c696684a65d1366110df21e047a Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.mpsl914b57aae4cf6c5531aeab24f6a3938ba5dcd2c28135d7c335b268c40c85d3fd Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.arm0d8c79a42954c491d90b49dc10af15238c1074393e38ba89f7608e41fc7c17e2 Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.arm541be03d1af06f01382a1a71a5e2601b19fa3e99a108fde20d8047045f80f61e9 Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.arm6a2ee8855a507124bd599a0255ee2f7d30b5087fe272df9430da1c5e01b813f82 Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.arm7332b0e4952931f17911218e567821cb8cb7e412bef0728056d830e36c4ead9ac Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.ppc8e4a8babc19265eb83b123f623aa20e48d2655af0e7939e234af11eb50acb8db Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.spca552e30759dc66cbc35dc894d48071f4397366cc1658b79efd16d91a81d54b5f Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.m68k932c003508cb926db5a6fb1db1cf9bc107f2ca0c3a97344f4723316115f297ee Miraielf mirai ua-wget
http://143.20.185.225/00101010101001/morte.sh407b1adb027946202303d522c62c3efb2254bb498f343f49957aacf51e55a6d8b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
55
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-12T21:10:00Z UTC
Last seen:
2025-10-14T10:39:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5e226c2a-1900-0000-4e23-0f2e70100000 pid=4208 /usr/bin/sudo guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216 /tmp/sample.bin guuid=5e226c2a-1900-0000-4e23-0f2e70100000 pid=4208->guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216 execve guuid=f7d56a2c-1900-0000-4e23-0f2e7a100000 pid=4218 /usr/bin/cp guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=f7d56a2c-1900-0000-4e23-0f2e7a100000 pid=4218 execve guuid=a383a331-1900-0000-4e23-0f2e8f100000 pid=4239 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=a383a331-1900-0000-4e23-0f2e8f100000 pid=4239 execve guuid=439c604b-1900-0000-4e23-0f2efa100000 pid=4346 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=439c604b-1900-0000-4e23-0f2efa100000 pid=4346 execve guuid=fa489e6a-1900-0000-4e23-0f2e7f110000 pid=4479 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=fa489e6a-1900-0000-4e23-0f2e7f110000 pid=4479 execve guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481 /tmp/morte.x86 net guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481 execve guuid=c25a9a97-1a00-0000-4e23-0f2ea2130000 pid=5026 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=c25a9a97-1a00-0000-4e23-0f2ea2130000 pid=5026 execve guuid=19861d98-1a00-0000-4e23-0f2ea4130000 pid=5028 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=19861d98-1a00-0000-4e23-0f2ea4130000 pid=5028 execve guuid=cba65dbb-1a00-0000-4e23-0f2eec130000 pid=5100 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=cba65dbb-1a00-0000-4e23-0f2eec130000 pid=5100 execve guuid=542ff4da-1a00-0000-4e23-0f2e27140000 pid=5159 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=542ff4da-1a00-0000-4e23-0f2e27140000 pid=5159 execve guuid=8bda56db-1a00-0000-4e23-0f2e29140000 pid=5161 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=8bda56db-1a00-0000-4e23-0f2e29140000 pid=5161 clone guuid=ac5528dc-1a00-0000-4e23-0f2e2c140000 pid=5164 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=ac5528dc-1a00-0000-4e23-0f2e2c140000 pid=5164 execve guuid=37b485dc-1a00-0000-4e23-0f2e2e140000 pid=5166 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=37b485dc-1a00-0000-4e23-0f2e2e140000 pid=5166 execve guuid=733b9afe-1a00-0000-4e23-0f2e66140000 pid=5222 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=733b9afe-1a00-0000-4e23-0f2e66140000 pid=5222 execve guuid=4f64fd22-1b00-0000-4e23-0f2e72140000 pid=5234 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=4f64fd22-1b00-0000-4e23-0f2e72140000 pid=5234 execve guuid=7f6e5a23-1b00-0000-4e23-0f2e73140000 pid=5235 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=7f6e5a23-1b00-0000-4e23-0f2e73140000 pid=5235 clone guuid=fa970524-1b00-0000-4e23-0f2e75140000 pid=5237 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=fa970524-1b00-0000-4e23-0f2e75140000 pid=5237 execve guuid=f7a86124-1b00-0000-4e23-0f2e76140000 pid=5238 /usr/bin/wget net send-data guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=f7a86124-1b00-0000-4e23-0f2e76140000 pid=5238 execve guuid=9fb09329-1b00-0000-4e23-0f2e77140000 pid=5239 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=9fb09329-1b00-0000-4e23-0f2e77140000 pid=5239 execve guuid=284d9d31-1b00-0000-4e23-0f2e78140000 pid=5240 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=284d9d31-1b00-0000-4e23-0f2e78140000 pid=5240 execve guuid=ab891a32-1b00-0000-4e23-0f2e79140000 pid=5241 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=ab891a32-1b00-0000-4e23-0f2e79140000 pid=5241 clone guuid=f1aa6232-1b00-0000-4e23-0f2e7a140000 pid=5242 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=f1aa6232-1b00-0000-4e23-0f2e7a140000 pid=5242 execve guuid=6c2cd632-1b00-0000-4e23-0f2e7b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=6c2cd632-1b00-0000-4e23-0f2e7b140000 pid=5243 execve guuid=ce982555-1b00-0000-4e23-0f2e7c140000 pid=5244 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=ce982555-1b00-0000-4e23-0f2e7c140000 pid=5244 execve guuid=0795f47c-1b00-0000-4e23-0f2e7d140000 pid=5245 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=0795f47c-1b00-0000-4e23-0f2e7d140000 pid=5245 execve guuid=951b747d-1b00-0000-4e23-0f2e7e140000 pid=5246 /tmp/morte.i686 net guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=951b747d-1b00-0000-4e23-0f2e7e140000 pid=5246 execve guuid=f7341af5-1b00-0000-4e23-0f2e86140000 pid=5254 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=f7341af5-1b00-0000-4e23-0f2e86140000 pid=5254 execve guuid=8ceda8f5-1b00-0000-4e23-0f2e87140000 pid=5255 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=8ceda8f5-1b00-0000-4e23-0f2e87140000 pid=5255 execve guuid=cfe19c12-1c00-0000-4e23-0f2e88140000 pid=5256 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=cfe19c12-1c00-0000-4e23-0f2e88140000 pid=5256 execve guuid=61bbc42d-1c00-0000-4e23-0f2e89140000 pid=5257 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=61bbc42d-1c00-0000-4e23-0f2e89140000 pid=5257 execve guuid=0f732f2e-1c00-0000-4e23-0f2e8a140000 pid=5258 /tmp/morte.x86_64 net guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=0f732f2e-1c00-0000-4e23-0f2e8a140000 pid=5258 execve guuid=7934a8a5-1c00-0000-4e23-0f2e8b140000 pid=5259 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=7934a8a5-1c00-0000-4e23-0f2e8b140000 pid=5259 execve guuid=6100eda5-1c00-0000-4e23-0f2e8c140000 pid=5260 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=6100eda5-1c00-0000-4e23-0f2e8c140000 pid=5260 execve guuid=fc2dc0e7-1c00-0000-4e23-0f2e93140000 pid=5267 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=fc2dc0e7-1c00-0000-4e23-0f2e93140000 pid=5267 execve guuid=d38a3905-1d00-0000-4e23-0f2e9b140000 pid=5275 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=d38a3905-1d00-0000-4e23-0f2e9b140000 pid=5275 execve guuid=cdb48305-1d00-0000-4e23-0f2e9c140000 pid=5276 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=cdb48305-1d00-0000-4e23-0f2e9c140000 pid=5276 clone guuid=a5492a06-1d00-0000-4e23-0f2e9e140000 pid=5278 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=a5492a06-1d00-0000-4e23-0f2e9e140000 pid=5278 execve guuid=70619406-1d00-0000-4e23-0f2e9f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=70619406-1d00-0000-4e23-0f2e9f140000 pid=5279 execve guuid=bc84dc21-1d00-0000-4e23-0f2ea4140000 pid=5284 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=bc84dc21-1d00-0000-4e23-0f2ea4140000 pid=5284 execve guuid=a44c453d-1d00-0000-4e23-0f2eb4140000 pid=5300 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=a44c453d-1d00-0000-4e23-0f2eb4140000 pid=5300 execve guuid=e5fba53d-1d00-0000-4e23-0f2eb5140000 pid=5301 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=e5fba53d-1d00-0000-4e23-0f2eb5140000 pid=5301 clone guuid=4cf3453e-1d00-0000-4e23-0f2eb7140000 pid=5303 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=4cf3453e-1d00-0000-4e23-0f2eb7140000 pid=5303 execve guuid=741d913e-1d00-0000-4e23-0f2eb8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=741d913e-1d00-0000-4e23-0f2eb8140000 pid=5304 execve guuid=bf76a855-1d00-0000-4e23-0f2eb9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=bf76a855-1d00-0000-4e23-0f2eb9140000 pid=5305 execve guuid=8d3a156c-1d00-0000-4e23-0f2eba140000 pid=5306 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=8d3a156c-1d00-0000-4e23-0f2eba140000 pid=5306 execve guuid=7634b36c-1d00-0000-4e23-0f2ebb140000 pid=5307 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=7634b36c-1d00-0000-4e23-0f2ebb140000 pid=5307 clone guuid=9b8bee6d-1d00-0000-4e23-0f2ebd140000 pid=5309 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=9b8bee6d-1d00-0000-4e23-0f2ebd140000 pid=5309 execve guuid=2768aa6e-1d00-0000-4e23-0f2ebe140000 pid=5310 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=2768aa6e-1d00-0000-4e23-0f2ebe140000 pid=5310 execve guuid=2784b18d-1d00-0000-4e23-0f2ebf140000 pid=5311 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=2784b18d-1d00-0000-4e23-0f2ebf140000 pid=5311 execve guuid=a49bd6ac-1d00-0000-4e23-0f2ec0140000 pid=5312 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=a49bd6ac-1d00-0000-4e23-0f2ec0140000 pid=5312 execve guuid=1f4f65ad-1d00-0000-4e23-0f2ec1140000 pid=5313 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=1f4f65ad-1d00-0000-4e23-0f2ec1140000 pid=5313 clone guuid=0a2ba0ae-1d00-0000-4e23-0f2ec3140000 pid=5315 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=0a2ba0ae-1d00-0000-4e23-0f2ec3140000 pid=5315 execve guuid=325054af-1d00-0000-4e23-0f2ec4140000 pid=5316 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=325054af-1d00-0000-4e23-0f2ec4140000 pid=5316 execve guuid=0f904dce-1d00-0000-4e23-0f2ec5140000 pid=5317 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=0f904dce-1d00-0000-4e23-0f2ec5140000 pid=5317 execve guuid=d33755ef-1d00-0000-4e23-0f2ec6140000 pid=5318 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=d33755ef-1d00-0000-4e23-0f2ec6140000 pid=5318 execve guuid=bf48e0ef-1d00-0000-4e23-0f2ec7140000 pid=5319 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=bf48e0ef-1d00-0000-4e23-0f2ec7140000 pid=5319 clone guuid=9b2707f1-1d00-0000-4e23-0f2ec9140000 pid=5321 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=9b2707f1-1d00-0000-4e23-0f2ec9140000 pid=5321 execve guuid=b3dd9bf3-1d00-0000-4e23-0f2eca140000 pid=5322 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=b3dd9bf3-1d00-0000-4e23-0f2eca140000 pid=5322 execve guuid=fe31fb14-1e00-0000-4e23-0f2ecb140000 pid=5323 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=fe31fb14-1e00-0000-4e23-0f2ecb140000 pid=5323 execve guuid=809a4130-1e00-0000-4e23-0f2ecc140000 pid=5324 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=809a4130-1e00-0000-4e23-0f2ecc140000 pid=5324 execve guuid=ab94cb30-1e00-0000-4e23-0f2ecd140000 pid=5325 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=ab94cb30-1e00-0000-4e23-0f2ecd140000 pid=5325 clone guuid=e1d4ef31-1e00-0000-4e23-0f2ecf140000 pid=5327 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=e1d4ef31-1e00-0000-4e23-0f2ecf140000 pid=5327 execve guuid=c27f8a32-1e00-0000-4e23-0f2ed0140000 pid=5328 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=c27f8a32-1e00-0000-4e23-0f2ed0140000 pid=5328 execve guuid=bef1d94a-1e00-0000-4e23-0f2ed1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=bef1d94a-1e00-0000-4e23-0f2ed1140000 pid=5329 execve guuid=b692aa63-1e00-0000-4e23-0f2ed2140000 pid=5330 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=b692aa63-1e00-0000-4e23-0f2ed2140000 pid=5330 execve guuid=dc813664-1e00-0000-4e23-0f2ed3140000 pid=5331 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=dc813664-1e00-0000-4e23-0f2ed3140000 pid=5331 clone guuid=2f9d5b65-1e00-0000-4e23-0f2ed5140000 pid=5333 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=2f9d5b65-1e00-0000-4e23-0f2ed5140000 pid=5333 execve guuid=c682e165-1e00-0000-4e23-0f2ed6140000 pid=5334 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=c682e165-1e00-0000-4e23-0f2ed6140000 pid=5334 execve guuid=f070a27f-1e00-0000-4e23-0f2ed7140000 pid=5335 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=f070a27f-1e00-0000-4e23-0f2ed7140000 pid=5335 execve guuid=761db399-1e00-0000-4e23-0f2ed8140000 pid=5336 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=761db399-1e00-0000-4e23-0f2ed8140000 pid=5336 execve guuid=ed03479a-1e00-0000-4e23-0f2ed9140000 pid=5337 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=ed03479a-1e00-0000-4e23-0f2ed9140000 pid=5337 clone guuid=07b2729b-1e00-0000-4e23-0f2edb140000 pid=5339 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=07b2729b-1e00-0000-4e23-0f2edb140000 pid=5339 execve guuid=9f19029c-1e00-0000-4e23-0f2edc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=9f19029c-1e00-0000-4e23-0f2edc140000 pid=5340 execve guuid=5b1b36b2-1e00-0000-4e23-0f2edd140000 pid=5341 /usr/bin/curl net send-data write-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=5b1b36b2-1e00-0000-4e23-0f2edd140000 pid=5341 execve guuid=9afc70c8-1e00-0000-4e23-0f2ede140000 pid=5342 /usr/bin/chmod guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=9afc70c8-1e00-0000-4e23-0f2ede140000 pid=5342 execve guuid=d7fafdc8-1e00-0000-4e23-0f2edf140000 pid=5343 /usr/bin/bash guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=d7fafdc8-1e00-0000-4e23-0f2edf140000 pid=5343 clone guuid=3da945ca-1e00-0000-4e23-0f2ee1140000 pid=5345 /usr/bin/rm delete-file guuid=34f5162c-1900-0000-4e23-0f2e78100000 pid=4216->guuid=3da945ca-1e00-0000-4e23-0f2ee1140000 pid=5345 execve d5466fdd-d2e6-50d9-9f3d-61d919bad8ae 143.20.185.225:80 guuid=a383a331-1900-0000-4e23-0f2e8f100000 pid=4239->d5466fdd-d2e6-50d9-9f3d-61d919bad8ae send: 153B guuid=439c604b-1900-0000-4e23-0f2efa100000 pid=4346->d5466fdd-d2e6-50d9-9f3d-61d919bad8ae send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c2574c6b-1900-0000-4e23-0f2e83110000 pid=4483 /tmp/morte.x86 guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481->guuid=c2574c6b-1900-0000-4e23-0f2e83110000 pid=4483 clone guuid=ec356997-1a00-0000-4e23-0f2ea0130000 pid=5024 /tmp/morte.x86 guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481->guuid=ec356997-1a00-0000-4e23-0f2ea0130000 pid=5024 clone guuid=5ed87c97-1a00-0000-4e23-0f2ea1130000 pid=5025 /tmp/morte.x86 net send-data zombie guuid=768b146b-1900-0000-4e23-0f2e81110000 pid=4481->guuid=5ed87c97-1a00-0000-4e23-0f2ea1130000 pid=5025 clone guuid=a9317f6b-1900-0000-4e23-0f2e85110000 pid=4485 /tmp/morte.x86 guuid=c2574c6b-1900-0000-4e23-0f2e83110000 pid=4483->guuid=a9317f6b-1900-0000-4e23-0f2e85110000 pid=4485 clone guuid=3f79826b-1900-0000-4e23-0f2e86110000 pid=4486 /tmp/morte.x86 dns net send-data zombie guuid=c2574c6b-1900-0000-4e23-0f2e83110000 pid=4483->guuid=3f79826b-1900-0000-4e23-0f2e86110000 pid=4486 clone guuid=3f79826b-1900-0000-4e23-0f2e86110000 pid=4486->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 504B a1a7e44c-f53d-520b-b2c8-ccb9907e473c uraniumc2.ddns.net:12121 guuid=3f79826b-1900-0000-4e23-0f2e86110000 pid=4486->a1a7e44c-f53d-520b-b2c8-ccb9907e473c send: 195B guuid=5ed87c97-1a00-0000-4e23-0f2ea1130000 pid=5025->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 540B guuid=5ed87c97-1a00-0000-4e23-0f2ea1130000 pid=5025->a1a7e44c-f53d-520b-b2c8-ccb9907e473c send: 45B a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 uraniumc2.ddns.net:80 guuid=19861d98-1a00-0000-4e23-0f2ea4130000 pid=5028->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=cba65dbb-1a00-0000-4e23-0f2eec130000 pid=5100->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=37b485dc-1a00-0000-4e23-0f2e2e140000 pid=5166->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=733b9afe-1a00-0000-4e23-0f2e66140000 pid=5222->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=f7a86124-1b00-0000-4e23-0f2e76140000 pid=5238->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=9fb09329-1b00-0000-4e23-0f2e77140000 pid=5239->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=6c2cd632-1b00-0000-4e23-0f2e7b140000 pid=5243->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=ce982555-1b00-0000-4e23-0f2e7c140000 pid=5244->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=951b747d-1b00-0000-4e23-0f2e7e140000 pid=5246->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=951b747d-1b00-0000-4e23-0f2e7e140000 pid=5246->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=8ceda8f5-1b00-0000-4e23-0f2e87140000 pid=5255->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 156B guuid=cfe19c12-1c00-0000-4e23-0f2e88140000 pid=5256->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 105B guuid=0f732f2e-1c00-0000-4e23-0f2e8a140000 pid=5258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0f732f2e-1c00-0000-4e23-0f2e8a140000 pid=5258->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=6100eda5-1c00-0000-4e23-0f2e8c140000 pid=5260->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=fc2dc0e7-1c00-0000-4e23-0f2e93140000 pid=5267->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=70619406-1d00-0000-4e23-0f2e9f140000 pid=5279->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=bc84dc21-1d00-0000-4e23-0f2ea4140000 pid=5284->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=741d913e-1d00-0000-4e23-0f2eb8140000 pid=5304->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=bf76a855-1d00-0000-4e23-0f2eb9140000 pid=5305->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=2768aa6e-1d00-0000-4e23-0f2ebe140000 pid=5310->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=2784b18d-1d00-0000-4e23-0f2ebf140000 pid=5311->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=325054af-1d00-0000-4e23-0f2ec4140000 pid=5316->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=0f904dce-1d00-0000-4e23-0f2ec5140000 pid=5317->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=b3dd9bf3-1d00-0000-4e23-0f2eca140000 pid=5322->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=fe31fb14-1e00-0000-4e23-0f2ecb140000 pid=5323->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=c27f8a32-1e00-0000-4e23-0f2ed0140000 pid=5328->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=bef1d94a-1e00-0000-4e23-0f2ed1140000 pid=5329->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=c682e165-1e00-0000-4e23-0f2ed6140000 pid=5334->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=f070a27f-1e00-0000-4e23-0f2ed7140000 pid=5335->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=9f19029c-1e00-0000-4e23-0f2edc140000 pid=5340->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=5b1b36b2-1e00-0000-4e23-0f2edd140000 pid=5341->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-12 23:03:36 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
uraniumc2.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 54f074f9741c2480533ce774637dae79d011ba9bc616e1215ad9ddf488e162f6

(this sample)

  
Delivery method
Distributed via web download

Comments