MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5861c4bb71a595cbc7d2f8b1b6d964b949859845e1895fd213f5e5d0968688c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 5861c4bb71a595cbc7d2f8b1b6d964b949859845e1895fd213f5e5d0968688c6
SHA3-384 hash: 503d56d678ac300604dfec9aacd68cc72d44afb9db51cf2209057cee54b62d93d60d3154f28e9348d29ccd6efcad4fca
SHA1 hash: 8e273dc0f238f6e55120242a41a250e474252904
MD5 hash: 8ad316dc0fe1404cd89c41de67684676
humanhash: social-video-white-mississippi
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-06-29 04:16:22 UTC
Last seen:2025-06-29 23:07:15 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Itf+7+bZsf+A+sbhf+t+9kf+c+glff+m+amsf+++yTf+Qa+QGgJf+D+j6f+W+qnF:i2l0ljblU1qHLkJBBIjeBgJspk
TLSH T1686186FB13424533DCAADEE335A884447185419BA8CE5FB56BED38F50D4CECAAC41E92
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.244/00101010101001/morte.x864fef063a9f02ba436aa8231ae6e68833cc7007d4acd4c911b0742fc6edb7f3e0 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.mipsb4d52619e506d97e60184c38b62b2b88461afd363d0744ccbebf3e26cdcb6bc3 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arc475367b6e70877052c1d83cb21a6542e9e023667e8a669b3983a9f7c70febacb Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.i468n/an/an/a
http://196.251.87.244/00101010101001/morte.i686502887af7e3bae97358328e359486004ac2e72a31500b26fb98b6a672d75fef9 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.x86_645f40e73a84e77e83a454da3ee487429836e3bdec4ceffc19d0d26c4901a911dd Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.mpslf4d2edf5cb22fd836842fb0c277395557f3a1329cc90c280cc12839c3e6fd72c Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm0e1c862fb7b3927bbf3f71b5c83949151be2dfedd584eb482c173ce2e851dd3f Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm5a67885abc3a05d82c9083e3df77c227e91f38aa242bc9988caf35b3a447ca596 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm661dfc5c73839259cb55254701e29c43307b89acaecf4c14b51be5d209ce80d5b Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.arm795d5407a92ac4b36ed3d0f10b3fb494fed6ae21491b9f5fce152b85b78fb2e12 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.ppc437732d5bde3a06c54a001342f0ad3735088bc10d3aaeb69d038520c3a00a9db Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.spcb98844c282ecfff203dabee396106d9726de54c4821bd35208239f7621d774b9 Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.m68k7c5e6035418ce9f52bdb00eaff5e23d3d7a41f7a75554249c6cf6e44ce34ae3f Miraielf mirai ua-wget
http://196.251.87.244/00101010101001/morte.sh4e0fadfca7d4f0704722720c739c817d05fa639fdbb6edbd961d0083f73342c80 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
92.5%
Tags:
medusa virus shell
Status:
terminated
Behavior Graph:
%3 guuid=cd7fd6e8-1700-0000-9f78-58b4960c0000 pid=3222 /usr/bin/sudo guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223 /tmp/sample.bin guuid=cd7fd6e8-1700-0000-9f78-58b4960c0000 pid=3222->guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223 execve guuid=7378b30b-1800-0000-9f78-58b4980c0000 pid=3224 /usr/bin/cp guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=7378b30b-1800-0000-9f78-58b4980c0000 pid=3224 execve guuid=6bc9f611-1800-0000-9f78-58b4990c0000 pid=3225 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=6bc9f611-1800-0000-9f78-58b4990c0000 pid=3225 execve guuid=72c98917-1800-0000-9f78-58b49e0c0000 pid=3230 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=72c98917-1800-0000-9f78-58b49e0c0000 pid=3230 execve guuid=1c101e23-1800-0000-9f78-58b4b00c0000 pid=3248 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=1c101e23-1800-0000-9f78-58b4b00c0000 pid=3248 execve guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249 /tmp/morte.x86 net guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249 execve guuid=9d8c1951-1900-0000-9f78-58b4670e0000 pid=3687 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=9d8c1951-1900-0000-9f78-58b4670e0000 pid=3687 execve guuid=ae3c8351-1900-0000-9f78-58b4690e0000 pid=3689 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=ae3c8351-1900-0000-9f78-58b4690e0000 pid=3689 execve guuid=50bed456-1900-0000-9f78-58b47a0e0000 pid=3706 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=50bed456-1900-0000-9f78-58b47a0e0000 pid=3706 execve guuid=5be1855d-1900-0000-9f78-58b4900e0000 pid=3728 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=5be1855d-1900-0000-9f78-58b4900e0000 pid=3728 execve guuid=21e4da5d-1900-0000-9f78-58b4940e0000 pid=3732 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=21e4da5d-1900-0000-9f78-58b4940e0000 pid=3732 clone guuid=2512925e-1900-0000-9f78-58b4990e0000 pid=3737 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=2512925e-1900-0000-9f78-58b4990e0000 pid=3737 execve guuid=1e5ce760-1900-0000-9f78-58b4a40e0000 pid=3748 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=1e5ce760-1900-0000-9f78-58b4a40e0000 pid=3748 execve guuid=6c2e0565-1900-0000-9f78-58b4b00e0000 pid=3760 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=6c2e0565-1900-0000-9f78-58b4b00e0000 pid=3760 execve guuid=f86bcc6a-1900-0000-9f78-58b4c70e0000 pid=3783 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=f86bcc6a-1900-0000-9f78-58b4c70e0000 pid=3783 execve guuid=86714b6b-1900-0000-9f78-58b4c80e0000 pid=3784 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=86714b6b-1900-0000-9f78-58b4c80e0000 pid=3784 clone guuid=30619a6c-1900-0000-9f78-58b4cc0e0000 pid=3788 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=30619a6c-1900-0000-9f78-58b4cc0e0000 pid=3788 execve guuid=60d6ec6c-1900-0000-9f78-58b4cf0e0000 pid=3791 /usr/bin/wget net send-data guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=60d6ec6c-1900-0000-9f78-58b4cf0e0000 pid=3791 execve guuid=ed6fd46f-1900-0000-9f78-58b4dc0e0000 pid=3804 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=ed6fd46f-1900-0000-9f78-58b4dc0e0000 pid=3804 execve guuid=db6f0175-1900-0000-9f78-58b4f50e0000 pid=3829 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=db6f0175-1900-0000-9f78-58b4f50e0000 pid=3829 execve guuid=0e6a5575-1900-0000-9f78-58b4f80e0000 pid=3832 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=0e6a5575-1900-0000-9f78-58b4f80e0000 pid=3832 clone guuid=8ecb8b75-1900-0000-9f78-58b4f90e0000 pid=3833 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=8ecb8b75-1900-0000-9f78-58b4f90e0000 pid=3833 execve guuid=98151e76-1900-0000-9f78-58b4fa0e0000 pid=3834 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=98151e76-1900-0000-9f78-58b4fa0e0000 pid=3834 execve guuid=ced70279-1900-0000-9f78-58b4020f0000 pid=3842 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=ced70279-1900-0000-9f78-58b4020f0000 pid=3842 execve guuid=a943f77c-1900-0000-9f78-58b4140f0000 pid=3860 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=a943f77c-1900-0000-9f78-58b4140f0000 pid=3860 execve guuid=82be347d-1900-0000-9f78-58b4160f0000 pid=3862 /tmp/morte.i686 net guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=82be347d-1900-0000-9f78-58b4160f0000 pid=3862 execve guuid=04f11ff5-1900-0000-9f78-58b441100000 pid=4161 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=04f11ff5-1900-0000-9f78-58b441100000 pid=4161 execve guuid=fe18aef5-1900-0000-9f78-58b443100000 pid=4163 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=fe18aef5-1900-0000-9f78-58b443100000 pid=4163 execve guuid=abc10efa-1900-0000-9f78-58b44e100000 pid=4174 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=abc10efa-1900-0000-9f78-58b44e100000 pid=4174 execve guuid=77cecdfe-1900-0000-9f78-58b45c100000 pid=4188 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=77cecdfe-1900-0000-9f78-58b45c100000 pid=4188 execve guuid=643513ff-1900-0000-9f78-58b45d100000 pid=4189 /tmp/morte.x86_64 mprotect-exec net guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=643513ff-1900-0000-9f78-58b45d100000 pid=4189 execve guuid=df23e276-1a00-0000-9f78-58b489110000 pid=4489 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=df23e276-1a00-0000-9f78-58b489110000 pid=4489 execve guuid=39456877-1a00-0000-9f78-58b48b110000 pid=4491 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=39456877-1a00-0000-9f78-58b48b110000 pid=4491 execve guuid=749bc590-1a00-0000-9f78-58b4bf110000 pid=4543 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=749bc590-1a00-0000-9f78-58b4bf110000 pid=4543 execve guuid=159057ac-1a00-0000-9f78-58b41a120000 pid=4634 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=159057ac-1a00-0000-9f78-58b41a120000 pid=4634 execve guuid=f43cbaac-1a00-0000-9f78-58b41c120000 pid=4636 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=f43cbaac-1a00-0000-9f78-58b41c120000 pid=4636 clone guuid=891295ad-1a00-0000-9f78-58b41f120000 pid=4639 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=891295ad-1a00-0000-9f78-58b41f120000 pid=4639 execve guuid=b41f3dae-1a00-0000-9f78-58b422120000 pid=4642 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=b41f3dae-1a00-0000-9f78-58b422120000 pid=4642 execve guuid=25d363b2-1a00-0000-9f78-58b42b120000 pid=4651 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=25d363b2-1a00-0000-9f78-58b42b120000 pid=4651 execve guuid=9c94fdb7-1a00-0000-9f78-58b43c120000 pid=4668 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=9c94fdb7-1a00-0000-9f78-58b43c120000 pid=4668 execve guuid=817f4fb8-1a00-0000-9f78-58b43f120000 pid=4671 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=817f4fb8-1a00-0000-9f78-58b43f120000 pid=4671 clone guuid=8b151fb9-1a00-0000-9f78-58b442120000 pid=4674 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=8b151fb9-1a00-0000-9f78-58b442120000 pid=4674 execve guuid=c46a67b9-1a00-0000-9f78-58b446120000 pid=4678 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=c46a67b9-1a00-0000-9f78-58b446120000 pid=4678 execve guuid=cef54dbc-1a00-0000-9f78-58b454120000 pid=4692 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=cef54dbc-1a00-0000-9f78-58b454120000 pid=4692 execve guuid=748e33c2-1a00-0000-9f78-58b46b120000 pid=4715 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=748e33c2-1a00-0000-9f78-58b46b120000 pid=4715 execve guuid=42d683c2-1a00-0000-9f78-58b46d120000 pid=4717 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=42d683c2-1a00-0000-9f78-58b46d120000 pid=4717 clone guuid=feb829c3-1a00-0000-9f78-58b472120000 pid=4722 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=feb829c3-1a00-0000-9f78-58b472120000 pid=4722 execve guuid=bb9d75c3-1a00-0000-9f78-58b476120000 pid=4726 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=bb9d75c3-1a00-0000-9f78-58b476120000 pid=4726 execve guuid=3aff94c6-1a00-0000-9f78-58b482120000 pid=4738 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=3aff94c6-1a00-0000-9f78-58b482120000 pid=4738 execve guuid=291befe6-1a00-0000-9f78-58b4cf120000 pid=4815 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=291befe6-1a00-0000-9f78-58b4cf120000 pid=4815 execve guuid=fef784e7-1a00-0000-9f78-58b4d1120000 pid=4817 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=fef784e7-1a00-0000-9f78-58b4d1120000 pid=4817 clone guuid=0c9550e9-1a00-0000-9f78-58b4d7120000 pid=4823 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=0c9550e9-1a00-0000-9f78-58b4d7120000 pid=4823 execve guuid=23363cef-1a00-0000-9f78-58b4e6120000 pid=4838 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=23363cef-1a00-0000-9f78-58b4e6120000 pid=4838 execve guuid=767753f3-1a00-0000-9f78-58b4ee120000 pid=4846 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=767753f3-1a00-0000-9f78-58b4ee120000 pid=4846 execve guuid=96935af8-1a00-0000-9f78-58b4fe120000 pid=4862 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=96935af8-1a00-0000-9f78-58b4fe120000 pid=4862 execve guuid=4fbdbbf8-1a00-0000-9f78-58b401130000 pid=4865 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=4fbdbbf8-1a00-0000-9f78-58b401130000 pid=4865 clone guuid=3775f1f9-1a00-0000-9f78-58b406130000 pid=4870 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=3775f1f9-1a00-0000-9f78-58b406130000 pid=4870 execve guuid=270569fa-1a00-0000-9f78-58b408130000 pid=4872 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=270569fa-1a00-0000-9f78-58b408130000 pid=4872 execve guuid=24f1b6fe-1a00-0000-9f78-58b415130000 pid=4885 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=24f1b6fe-1a00-0000-9f78-58b415130000 pid=4885 execve guuid=78ac0e03-1b00-0000-9f78-58b426130000 pid=4902 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=78ac0e03-1b00-0000-9f78-58b426130000 pid=4902 execve guuid=2e365903-1b00-0000-9f78-58b428130000 pid=4904 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=2e365903-1b00-0000-9f78-58b428130000 pid=4904 clone guuid=08ae9c05-1b00-0000-9f78-58b432130000 pid=4914 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=08ae9c05-1b00-0000-9f78-58b432130000 pid=4914 execve guuid=2caced05-1b00-0000-9f78-58b434130000 pid=4916 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=2caced05-1b00-0000-9f78-58b434130000 pid=4916 execve guuid=487bd109-1b00-0000-9f78-58b443130000 pid=4931 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=487bd109-1b00-0000-9f78-58b443130000 pid=4931 execve guuid=e2b93c11-1b00-0000-9f78-58b45e130000 pid=4958 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=e2b93c11-1b00-0000-9f78-58b45e130000 pid=4958 execve guuid=18de8c11-1b00-0000-9f78-58b460130000 pid=4960 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=18de8c11-1b00-0000-9f78-58b460130000 pid=4960 clone guuid=5bbdbb12-1b00-0000-9f78-58b464130000 pid=4964 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=5bbdbb12-1b00-0000-9f78-58b464130000 pid=4964 execve guuid=cc8f3a13-1b00-0000-9f78-58b466130000 pid=4966 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=cc8f3a13-1b00-0000-9f78-58b466130000 pid=4966 execve guuid=9f5f8517-1b00-0000-9f78-58b472130000 pid=4978 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=9f5f8517-1b00-0000-9f78-58b472130000 pid=4978 execve guuid=af39651e-1b00-0000-9f78-58b488130000 pid=5000 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=af39651e-1b00-0000-9f78-58b488130000 pid=5000 execve guuid=c815b11e-1b00-0000-9f78-58b48a130000 pid=5002 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=c815b11e-1b00-0000-9f78-58b48a130000 pid=5002 clone guuid=53c44b1f-1b00-0000-9f78-58b48e130000 pid=5006 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=53c44b1f-1b00-0000-9f78-58b48e130000 pid=5006 execve guuid=5317a11f-1b00-0000-9f78-58b490130000 pid=5008 /usr/bin/wget net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=5317a11f-1b00-0000-9f78-58b490130000 pid=5008 execve guuid=e9347323-1b00-0000-9f78-58b49a130000 pid=5018 /usr/bin/curl net send-data write-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=e9347323-1b00-0000-9f78-58b49a130000 pid=5018 execve guuid=b1e1a727-1b00-0000-9f78-58b4aa130000 pid=5034 /usr/bin/chmod guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=b1e1a727-1b00-0000-9f78-58b4aa130000 pid=5034 execve guuid=163e2f28-1b00-0000-9f78-58b4ac130000 pid=5036 /usr/bin/bash guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=163e2f28-1b00-0000-9f78-58b4ac130000 pid=5036 clone guuid=2a38d628-1b00-0000-9f78-58b4b1130000 pid=5041 /usr/bin/rm delete-file guuid=010cb3ea-1700-0000-9f78-58b4970c0000 pid=3223->guuid=2a38d628-1b00-0000-9f78-58b4b1130000 pid=5041 execve ad49dc11-8491-5478-bc0d-f4c61eb1e83c 196.251.87.244:80 guuid=6bc9f611-1800-0000-9f78-58b4990c0000 pid=3225->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 153B guuid=72c98917-1800-0000-9f78-58b49e0c0000 pid=3230->ad49dc11-8491-5478-bc0d-f4c61eb1e83c send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=693e2f24-1800-0000-9f78-58b4b20c0000 pid=3250 /tmp/morte.x86 guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249->guuid=693e2f24-1800-0000-9f78-58b4b20c0000 pid=3250 clone guuid=21370451-1900-0000-9f78-58b4650e0000 pid=3685 /tmp/morte.x86 guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249->guuid=21370451-1900-0000-9f78-58b4650e0000 pid=3685 clone guuid=1f070c51-1900-0000-9f78-58b4660e0000 pid=3686 /tmp/morte.x86 net send-data zombie guuid=1a548723-1800-0000-9f78-58b4b10c0000 pid=3249->guuid=1f070c51-1900-0000-9f78-58b4660e0000 pid=3686 clone guuid=eba23624-1800-0000-9f78-58b4b30c0000 pid=3251 /tmp/morte.x86 guuid=693e2f24-1800-0000-9f78-58b4b20c0000 pid=3250->guuid=eba23624-1800-0000-9f78-58b4b30c0000 pid=3251 clone guuid=92f93c24-1800-0000-9f78-58b4b40c0000 pid=3252 /tmp/morte.x86 dns net send-data zombie guuid=693e2f24-1800-0000-9f78-58b4b20c0000 pid=3250->guuid=92f93c24-1800-0000-9f78-58b4b40c0000 pid=3252 clone guuid=92f93c24-1800-0000-9f78-58b4b40c0000 pid=3252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B 42990ff2-8d05-5781-a3b1-955a2b52eab7 jbvpshosti.com:12121 guuid=92f93c24-1800-0000-9f78-58b4b40c0000 pid=3252->42990ff2-8d05-5781-a3b1-955a2b52eab7 send: 15B guuid=1f070c51-1900-0000-9f78-58b4660e0000 pid=3686->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=1f070c51-1900-0000-9f78-58b4660e0000 pid=3686->310a0ed0-c544-54ca-bf3f-fca55e459297 con 56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 jbvpshosti.com:80 guuid=ae3c8351-1900-0000-9f78-58b4690e0000 pid=3689->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=50bed456-1900-0000-9f78-58b47a0e0000 pid=3706->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=1e5ce760-1900-0000-9f78-58b4a40e0000 pid=3748->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 153B guuid=6c2e0565-1900-0000-9f78-58b4b00e0000 pid=3760->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 102B guuid=60d6ec6c-1900-0000-9f78-58b4cf0e0000 pid=3791->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=ed6fd46f-1900-0000-9f78-58b4dc0e0000 pid=3804->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=98151e76-1900-0000-9f78-58b4fa0e0000 pid=3834->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=ced70279-1900-0000-9f78-58b4020f0000 pid=3842->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=82be347d-1900-0000-9f78-58b4160f0000 pid=3862->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=82be347d-1900-0000-9f78-58b4160f0000 pid=3862->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=fe18aef5-1900-0000-9f78-58b443100000 pid=4163->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 156B guuid=abc10efa-1900-0000-9f78-58b44e100000 pid=4174->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 105B guuid=643513ff-1900-0000-9f78-58b45d100000 pid=4189->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=643513ff-1900-0000-9f78-58b45d100000 pid=4189->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=39456877-1a00-0000-9f78-58b48b110000 pid=4491->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=749bc590-1a00-0000-9f78-58b4bf110000 pid=4543->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=b41f3dae-1a00-0000-9f78-58b422120000 pid=4642->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 153B guuid=25d363b2-1a00-0000-9f78-58b42b120000 pid=4651->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 102B guuid=c46a67b9-1a00-0000-9f78-58b446120000 pid=4678->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=cef54dbc-1a00-0000-9f78-58b454120000 pid=4692->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=bb9d75c3-1a00-0000-9f78-58b476120000 pid=4726->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=3aff94c6-1a00-0000-9f78-58b482120000 pid=4738->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=23363cef-1a00-0000-9f78-58b4e6120000 pid=4838->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=767753f3-1a00-0000-9f78-58b4ee120000 pid=4846->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=270569fa-1a00-0000-9f78-58b408130000 pid=4872->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 153B guuid=24f1b6fe-1a00-0000-9f78-58b415130000 pid=4885->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 102B guuid=2caced05-1b00-0000-9f78-58b434130000 pid=4916->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 153B guuid=487bd109-1b00-0000-9f78-58b443130000 pid=4931->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 102B guuid=cc8f3a13-1b00-0000-9f78-58b466130000 pid=4966->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 154B guuid=9f5f8517-1b00-0000-9f78-58b472130000 pid=4978->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 103B guuid=5317a11f-1b00-0000-9f78-58b490130000 pid=5008->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 153B guuid=e9347323-1b00-0000-9f78-58b49a130000 pid=5018->56d2c9c1-1a90-5e50-a3f5-d00590bd5ef1 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-06-26 19:29:00 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5861c4bb71a595cbc7d2f8b1b6d964b949859845e1895fd213f5e5d0968688c6

(this sample)

  
Delivery method
Distributed via web download

Comments