MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5c9f8b254cb85abdf05baf043034d47d1c32b4e2249ca1a25e4f21c617645f2f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5c9f8b254cb85abdf05baf043034d47d1c32b4e2249ca1a25e4f21c617645f2f
SHA3-384 hash: 787c91ebe8335a16b22fb37a033e1d7ce950dfdade994bfa5089e090c24333611101665f1705c4a8fca78056a9c5aeda
SHA1 hash: cc10c4442235daf11eebb53723976c73021ef27e
MD5 hash: 99b27bdfb5beb3ceed6715c915e60ee0
humanhash: low-pasta-seventeen-william
File name:1.sh
Download: download sample
Signature Mirai
File size:3'314 bytes
First seen:2025-07-08 23:11:13 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItNZsHbhFknlfDms3TBOGgJh6fnLP4NIpKks/ME3hRsHYcGgJsRRpk:iIFGdLjBO18fLyJ5RqHYBgJsxk
TLSH T1866180FA1346463FACAACEE332A884047149409B95CE5FB55BEE2CF51C8CEC96C4165A
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.69.95/00101010101001/morte.x8605310b8660041be2fc065b10f5e3552682a96328ea729cbef06ac2f4d9b90e83 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.mips51187e3313a6eb3d216971154920fffe3eb5934f45591253a77d1e7502b42028 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.arced67075b604a4e4ef9da5e3d8c5d65805c943c6912cd09ffaff7b9545c9df571 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.i468n/an/aelf opendir ua-wget
http://196.251.69.95/00101010101001/morte.i686e8fd96cd277a25f91d504f2498e9cd2ae43b5cfc8496967807d3d40fc4473fb8 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.x86_6485be94ab11a8e87c5645a30393b98307a4e784ff634402ec5aeb59d8644b558b Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.mpsl40184fbf50c0d0258d78b8f38a83b0e0cb1315b80fdff27887387f8304eb93ab Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.arm88844b8b2e3d2f04e5f65fc885186bd91027a968dadf7183287e7d1d7f6f291f Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.arm545d4741837c95127ad9887e696fafd69f6dd37ace0a891cbd62abfc24d040cb4 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.arm655bd81bc000ebd24dc7571b745420bb1faf9607112da3723482fe5f045cd67de Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.arm72d7ac5ba36cc73adcfc53e78fbe8e156a7bbbcaaec8e833d83f3e562d8030a94 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.ppcd9787c1edf201fbf158ab62554ea6369387e002551a07f97f50629ec6bd706e4 MiraiCoinMiner elf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.spc1f40f43a66f215886efa655b96a8f8dace7502940485c266bb141e67fd04d6f7 Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.m68k64167acd17aac2637cbb4dd84f0159a2395e0f1f9057f1f471bbe37646b9c20a Miraielf mirai opendir ua-wget
http://196.251.69.95/00101010101001/morte.sh423e3d7a1ea1eb6be1b0ed170f1c0fe7126fcbaf5da1e1358507b5553d9da5f07 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
25
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
downloader phishing trojan agent
Status:
terminated
Behavior Graph:
%3 guuid=a1e1df46-1b00-0000-2e9f-ff99270b0000 pid=2855 /usr/bin/sudo guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862 /tmp/sample.bin guuid=a1e1df46-1b00-0000-2e9f-ff99270b0000 pid=2855->guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862 execve guuid=9d05184a-1b00-0000-2e9f-ff99300b0000 pid=2864 /usr/bin/cp guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=9d05184a-1b00-0000-2e9f-ff99300b0000 pid=2864 execve guuid=d9a30956-1b00-0000-2e9f-ff994f0b0000 pid=2895 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=d9a30956-1b00-0000-2e9f-ff994f0b0000 pid=2895 execve guuid=3891745c-1b00-0000-2e9f-ff99570b0000 pid=2903 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3891745c-1b00-0000-2e9f-ff99570b0000 pid=2903 execve guuid=5b6ab268-1b00-0000-2e9f-ff99680b0000 pid=2920 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=5b6ab268-1b00-0000-2e9f-ff99680b0000 pid=2920 execve guuid=f2644069-1b00-0000-2e9f-ff996a0b0000 pid=2922 /tmp/morte.x86 net guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=f2644069-1b00-0000-2e9f-ff996a0b0000 pid=2922 execve guuid=aaba5e6a-1b00-0000-2e9f-ff996d0b0000 pid=2925 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=aaba5e6a-1b00-0000-2e9f-ff996d0b0000 pid=2925 execve guuid=86beb06a-1b00-0000-2e9f-ff996f0b0000 pid=2927 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=86beb06a-1b00-0000-2e9f-ff996f0b0000 pid=2927 execve guuid=3e773b6f-1b00-0000-2e9f-ff997a0b0000 pid=2938 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3e773b6f-1b00-0000-2e9f-ff997a0b0000 pid=2938 execve guuid=f075a974-1b00-0000-2e9f-ff99890b0000 pid=2953 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=f075a974-1b00-0000-2e9f-ff99890b0000 pid=2953 execve guuid=b924f274-1b00-0000-2e9f-ff998a0b0000 pid=2954 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=b924f274-1b00-0000-2e9f-ff998a0b0000 pid=2954 clone guuid=06cd7c75-1b00-0000-2e9f-ff998c0b0000 pid=2956 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=06cd7c75-1b00-0000-2e9f-ff998c0b0000 pid=2956 execve guuid=51aebe76-1b00-0000-2e9f-ff998d0b0000 pid=2957 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=51aebe76-1b00-0000-2e9f-ff998d0b0000 pid=2957 execve guuid=120d9e7c-1b00-0000-2e9f-ff99990b0000 pid=2969 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=120d9e7c-1b00-0000-2e9f-ff99990b0000 pid=2969 execve guuid=6be55884-1b00-0000-2e9f-ff99ab0b0000 pid=2987 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=6be55884-1b00-0000-2e9f-ff99ab0b0000 pid=2987 execve guuid=9b2f9a84-1b00-0000-2e9f-ff99ac0b0000 pid=2988 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=9b2f9a84-1b00-0000-2e9f-ff99ac0b0000 pid=2988 clone guuid=90904b85-1b00-0000-2e9f-ff99ae0b0000 pid=2990 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=90904b85-1b00-0000-2e9f-ff99ae0b0000 pid=2990 execve guuid=3040ce85-1b00-0000-2e9f-ff99b00b0000 pid=2992 /usr/bin/wget net send-data guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3040ce85-1b00-0000-2e9f-ff99b00b0000 pid=2992 execve guuid=2743e788-1b00-0000-2e9f-ff99b90b0000 pid=3001 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=2743e788-1b00-0000-2e9f-ff99b90b0000 pid=3001 execve guuid=73d3e08d-1b00-0000-2e9f-ff99c40b0000 pid=3012 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=73d3e08d-1b00-0000-2e9f-ff99c40b0000 pid=3012 execve guuid=3fe63a8e-1b00-0000-2e9f-ff99c50b0000 pid=3013 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3fe63a8e-1b00-0000-2e9f-ff99c50b0000 pid=3013 clone guuid=78eb6a8e-1b00-0000-2e9f-ff99c70b0000 pid=3015 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=78eb6a8e-1b00-0000-2e9f-ff99c70b0000 pid=3015 execve guuid=fb8fc08e-1b00-0000-2e9f-ff99c90b0000 pid=3017 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=fb8fc08e-1b00-0000-2e9f-ff99c90b0000 pid=3017 execve guuid=e616a692-1b00-0000-2e9f-ff99d30b0000 pid=3027 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=e616a692-1b00-0000-2e9f-ff99d30b0000 pid=3027 execve guuid=ffd81197-1b00-0000-2e9f-ff99df0b0000 pid=3039 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=ffd81197-1b00-0000-2e9f-ff99df0b0000 pid=3039 execve guuid=fd769a97-1b00-0000-2e9f-ff99e10b0000 pid=3041 /tmp/morte.i686 net guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=fd769a97-1b00-0000-2e9f-ff99e10b0000 pid=3041 execve guuid=3bee5798-1b00-0000-2e9f-ff99e70b0000 pid=3047 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3bee5798-1b00-0000-2e9f-ff99e70b0000 pid=3047 execve guuid=a4b0b498-1b00-0000-2e9f-ff99ea0b0000 pid=3050 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=a4b0b498-1b00-0000-2e9f-ff99ea0b0000 pid=3050 execve guuid=0c931f9e-1b00-0000-2e9f-ff99fc0b0000 pid=3068 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=0c931f9e-1b00-0000-2e9f-ff99fc0b0000 pid=3068 execve guuid=3b31a4a2-1b00-0000-2e9f-ff990d0c0000 pid=3085 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3b31a4a2-1b00-0000-2e9f-ff990d0c0000 pid=3085 execve guuid=3194fda2-1b00-0000-2e9f-ff99100c0000 pid=3088 /tmp/morte.x86_64 mprotect-exec net guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3194fda2-1b00-0000-2e9f-ff99100c0000 pid=3088 execve guuid=9a1db0a3-1b00-0000-2e9f-ff99160c0000 pid=3094 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=9a1db0a3-1b00-0000-2e9f-ff99160c0000 pid=3094 execve guuid=388b63a4-1b00-0000-2e9f-ff991c0c0000 pid=3100 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=388b63a4-1b00-0000-2e9f-ff991c0c0000 pid=3100 execve guuid=db76ffa8-1b00-0000-2e9f-ff99300c0000 pid=3120 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=db76ffa8-1b00-0000-2e9f-ff99300c0000 pid=3120 execve guuid=e60ec7af-1b00-0000-2e9f-ff993e0c0000 pid=3134 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=e60ec7af-1b00-0000-2e9f-ff993e0c0000 pid=3134 execve guuid=92d161b0-1b00-0000-2e9f-ff99400c0000 pid=3136 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=92d161b0-1b00-0000-2e9f-ff99400c0000 pid=3136 clone guuid=32ce1bb1-1b00-0000-2e9f-ff99440c0000 pid=3140 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=32ce1bb1-1b00-0000-2e9f-ff99440c0000 pid=3140 execve guuid=a378a2b1-1b00-0000-2e9f-ff99460c0000 pid=3142 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=a378a2b1-1b00-0000-2e9f-ff99460c0000 pid=3142 execve guuid=aaa9c1b5-1b00-0000-2e9f-ff99510c0000 pid=3153 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=aaa9c1b5-1b00-0000-2e9f-ff99510c0000 pid=3153 execve guuid=be3fd4bb-1b00-0000-2e9f-ff995e0c0000 pid=3166 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=be3fd4bb-1b00-0000-2e9f-ff995e0c0000 pid=3166 execve guuid=8c3f3dbc-1b00-0000-2e9f-ff995f0c0000 pid=3167 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=8c3f3dbc-1b00-0000-2e9f-ff995f0c0000 pid=3167 clone guuid=b92639bd-1b00-0000-2e9f-ff99620c0000 pid=3170 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=b92639bd-1b00-0000-2e9f-ff99620c0000 pid=3170 execve guuid=228587bd-1b00-0000-2e9f-ff99640c0000 pid=3172 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=228587bd-1b00-0000-2e9f-ff99640c0000 pid=3172 execve guuid=601178c1-1b00-0000-2e9f-ff99700c0000 pid=3184 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=601178c1-1b00-0000-2e9f-ff99700c0000 pid=3184 execve guuid=900befc9-1b00-0000-2e9f-ff99800c0000 pid=3200 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=900befc9-1b00-0000-2e9f-ff99800c0000 pid=3200 execve guuid=efc456ca-1b00-0000-2e9f-ff99810c0000 pid=3201 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=efc456ca-1b00-0000-2e9f-ff99810c0000 pid=3201 clone guuid=c91c46cb-1b00-0000-2e9f-ff99840c0000 pid=3204 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=c91c46cb-1b00-0000-2e9f-ff99840c0000 pid=3204 execve guuid=4b81eccd-1b00-0000-2e9f-ff998b0c0000 pid=3211 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=4b81eccd-1b00-0000-2e9f-ff998b0c0000 pid=3211 execve guuid=94874cd3-1b00-0000-2e9f-ff99970c0000 pid=3223 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=94874cd3-1b00-0000-2e9f-ff99970c0000 pid=3223 execve guuid=3a1ea2db-1b00-0000-2e9f-ff99a40c0000 pid=3236 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=3a1ea2db-1b00-0000-2e9f-ff99a40c0000 pid=3236 execve guuid=7a91f5db-1b00-0000-2e9f-ff99a60c0000 pid=3238 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=7a91f5db-1b00-0000-2e9f-ff99a60c0000 pid=3238 clone guuid=f0dba9dc-1b00-0000-2e9f-ff99ab0c0000 pid=3243 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=f0dba9dc-1b00-0000-2e9f-ff99ab0c0000 pid=3243 execve guuid=c7af0adf-1b00-0000-2e9f-ff99ae0c0000 pid=3246 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=c7af0adf-1b00-0000-2e9f-ff99ae0c0000 pid=3246 execve guuid=ee08a7e3-1b00-0000-2e9f-ff99b50c0000 pid=3253 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=ee08a7e3-1b00-0000-2e9f-ff99b50c0000 pid=3253 execve guuid=94f3b5e9-1b00-0000-2e9f-ff99c00c0000 pid=3264 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=94f3b5e9-1b00-0000-2e9f-ff99c00c0000 pid=3264 execve guuid=4dbd0eea-1b00-0000-2e9f-ff99c20c0000 pid=3266 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=4dbd0eea-1b00-0000-2e9f-ff99c20c0000 pid=3266 clone guuid=2540bfea-1b00-0000-2e9f-ff99c60c0000 pid=3270 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=2540bfea-1b00-0000-2e9f-ff99c60c0000 pid=3270 execve guuid=6c3833eb-1b00-0000-2e9f-ff99c80c0000 pid=3272 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=6c3833eb-1b00-0000-2e9f-ff99c80c0000 pid=3272 execve guuid=601cc2ee-1b00-0000-2e9f-ff99d10c0000 pid=3281 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=601cc2ee-1b00-0000-2e9f-ff99d10c0000 pid=3281 execve guuid=be5685f3-1b00-0000-2e9f-ff99dc0c0000 pid=3292 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=be5685f3-1b00-0000-2e9f-ff99dc0c0000 pid=3292 execve guuid=6c39d2f3-1b00-0000-2e9f-ff99de0c0000 pid=3294 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=6c39d2f3-1b00-0000-2e9f-ff99de0c0000 pid=3294 clone guuid=c5c45ef4-1b00-0000-2e9f-ff99e10c0000 pid=3297 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=c5c45ef4-1b00-0000-2e9f-ff99e10c0000 pid=3297 execve guuid=250af0f5-1b00-0000-2e9f-ff99e40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=250af0f5-1b00-0000-2e9f-ff99e40c0000 pid=3300 execve guuid=9381dcfb-1b00-0000-2e9f-ff99e50c0000 pid=3301 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=9381dcfb-1b00-0000-2e9f-ff99e50c0000 pid=3301 execve guuid=da00ea02-1c00-0000-2e9f-ff99e60c0000 pid=3302 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=da00ea02-1c00-0000-2e9f-ff99e60c0000 pid=3302 execve guuid=be7e7f03-1c00-0000-2e9f-ff99e70c0000 pid=3303 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=be7e7f03-1c00-0000-2e9f-ff99e70c0000 pid=3303 clone guuid=7559c104-1c00-0000-2e9f-ff99e90c0000 pid=3305 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=7559c104-1c00-0000-2e9f-ff99e90c0000 pid=3305 execve guuid=80374005-1c00-0000-2e9f-ff99ea0c0000 pid=3306 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=80374005-1c00-0000-2e9f-ff99ea0c0000 pid=3306 execve guuid=b0612d0a-1c00-0000-2e9f-ff99f30c0000 pid=3315 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=b0612d0a-1c00-0000-2e9f-ff99f30c0000 pid=3315 execve guuid=36b5e012-1c00-0000-2e9f-ff99010d0000 pid=3329 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=36b5e012-1c00-0000-2e9f-ff99010d0000 pid=3329 execve guuid=bf0c6f13-1c00-0000-2e9f-ff99020d0000 pid=3330 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=bf0c6f13-1c00-0000-2e9f-ff99020d0000 pid=3330 clone guuid=4089bd14-1c00-0000-2e9f-ff99040d0000 pid=3332 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=4089bd14-1c00-0000-2e9f-ff99040d0000 pid=3332 execve guuid=ca757015-1c00-0000-2e9f-ff99050d0000 pid=3333 /usr/bin/wget net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=ca757015-1c00-0000-2e9f-ff99050d0000 pid=3333 execve guuid=7071e51a-1c00-0000-2e9f-ff990a0d0000 pid=3338 /usr/bin/curl net send-data write-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=7071e51a-1c00-0000-2e9f-ff990a0d0000 pid=3338 execve guuid=4d809f22-1c00-0000-2e9f-ff991c0d0000 pid=3356 /usr/bin/chmod guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=4d809f22-1c00-0000-2e9f-ff991c0d0000 pid=3356 execve guuid=721cfa22-1c00-0000-2e9f-ff991d0d0000 pid=3357 /usr/bin/bash guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=721cfa22-1c00-0000-2e9f-ff991d0d0000 pid=3357 clone guuid=0c2daf23-1c00-0000-2e9f-ff991f0d0000 pid=3359 /usr/bin/rm delete-file guuid=98598b49-1b00-0000-2e9f-ff992e0b0000 pid=2862->guuid=0c2daf23-1c00-0000-2e9f-ff991f0d0000 pid=3359 execve 98abb22e-03b6-509f-a439-809602e811c5 196.251.69.95:80 guuid=d9a30956-1b00-0000-2e9f-ff994f0b0000 pid=2895->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=3891745c-1b00-0000-2e9f-ff99570b0000 pid=2903->98abb22e-03b6-509f-a439-809602e811c5 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f2644069-1b00-0000-2e9f-ff996a0b0000 pid=2922->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=acfd426a-1b00-0000-2e9f-ff996b0b0000 pid=2923 /tmp/morte.x86 guuid=f2644069-1b00-0000-2e9f-ff996a0b0000 pid=2922->guuid=acfd426a-1b00-0000-2e9f-ff996b0b0000 pid=2923 clone guuid=d9c44b6a-1b00-0000-2e9f-ff996c0b0000 pid=2924 /tmp/morte.x86 guuid=f2644069-1b00-0000-2e9f-ff996a0b0000 pid=2922->guuid=d9c44b6a-1b00-0000-2e9f-ff996c0b0000 pid=2924 clone guuid=9e9f606a-1b00-0000-2e9f-ff996e0b0000 pid=2926 /tmp/morte.x86 write-config zombie guuid=d9c44b6a-1b00-0000-2e9f-ff996c0b0000 pid=2924->guuid=9e9f606a-1b00-0000-2e9f-ff996e0b0000 pid=2926 clone guuid=8403376e-1b00-0000-2e9f-ff99760b0000 pid=2934 /usr/bin/dash guuid=9e9f606a-1b00-0000-2e9f-ff996e0b0000 pid=2926->guuid=8403376e-1b00-0000-2e9f-ff99760b0000 pid=2934 execve guuid=f9780372-1b00-0000-2e9f-ff99810b0000 pid=2945 /tmp/morte.x86 delete-file zombie guuid=9e9f606a-1b00-0000-2e9f-ff996e0b0000 pid=2926->guuid=f9780372-1b00-0000-2e9f-ff99810b0000 pid=2945 clone guuid=86beb06a-1b00-0000-2e9f-ff996f0b0000 pid=2927->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=2c15736e-1b00-0000-2e9f-ff99770b0000 pid=2935 /usr/bin/cp guuid=8403376e-1b00-0000-2e9f-ff99760b0000 pid=2934->guuid=2c15736e-1b00-0000-2e9f-ff99770b0000 pid=2935 execve guuid=3e773b6f-1b00-0000-2e9f-ff997a0b0000 pid=2938->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=95f30b72-1b00-0000-2e9f-ff99820b0000 pid=2946 /tmp/morte.x86 guuid=f9780372-1b00-0000-2e9f-ff99810b0000 pid=2945->guuid=95f30b72-1b00-0000-2e9f-ff99820b0000 pid=2946 clone guuid=51aebe76-1b00-0000-2e9f-ff998d0b0000 pid=2957->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=120d9e7c-1b00-0000-2e9f-ff99990b0000 pid=2969->98abb22e-03b6-509f-a439-809602e811c5 send: 101B guuid=3040ce85-1b00-0000-2e9f-ff99b00b0000 pid=2992->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=2743e788-1b00-0000-2e9f-ff99b90b0000 pid=3001->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=fb8fc08e-1b00-0000-2e9f-ff99c90b0000 pid=3017->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=e616a692-1b00-0000-2e9f-ff99d30b0000 pid=3027->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=fd769a97-1b00-0000-2e9f-ff99e10b0000 pid=3041->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be644b98-1b00-0000-2e9f-ff99e50b0000 pid=3045 /tmp/morte.i686 guuid=fd769a97-1b00-0000-2e9f-ff99e10b0000 pid=3041->guuid=be644b98-1b00-0000-2e9f-ff99e50b0000 pid=3045 clone guuid=ec7a4f98-1b00-0000-2e9f-ff99e60b0000 pid=3046 /tmp/morte.i686 guuid=fd769a97-1b00-0000-2e9f-ff99e10b0000 pid=3041->guuid=ec7a4f98-1b00-0000-2e9f-ff99e60b0000 pid=3046 clone guuid=b65c5c98-1b00-0000-2e9f-ff99e80b0000 pid=3048 /tmp/morte.i686 write-config zombie guuid=ec7a4f98-1b00-0000-2e9f-ff99e60b0000 pid=3046->guuid=b65c5c98-1b00-0000-2e9f-ff99e80b0000 pid=3048 clone guuid=64e5ce9c-1b00-0000-2e9f-ff99f70b0000 pid=3063 /usr/bin/dash guuid=b65c5c98-1b00-0000-2e9f-ff99e80b0000 pid=3048->guuid=64e5ce9c-1b00-0000-2e9f-ff99f70b0000 pid=3063 execve guuid=6b8063a0-1b00-0000-2e9f-ff99030c0000 pid=3075 /tmp/morte.i686 dns net send-data guuid=b65c5c98-1b00-0000-2e9f-ff99e80b0000 pid=3048->guuid=6b8063a0-1b00-0000-2e9f-ff99030c0000 pid=3075 clone guuid=a4b0b498-1b00-0000-2e9f-ff99ea0b0000 pid=3050->98abb22e-03b6-509f-a439-809602e811c5 send: 155B guuid=b30c129d-1b00-0000-2e9f-ff99f90b0000 pid=3065 /usr/bin/cp guuid=64e5ce9c-1b00-0000-2e9f-ff99f70b0000 pid=3063->guuid=b30c129d-1b00-0000-2e9f-ff99f90b0000 pid=3065 execve guuid=0c931f9e-1b00-0000-2e9f-ff99fc0b0000 pid=3068->98abb22e-03b6-509f-a439-809602e811c5 send: 104B guuid=6b8063a0-1b00-0000-2e9f-ff99030c0000 pid=3075->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 33B 128bad62-53f0-5c82-890a-d4a6ddbfdf3c abc.galaxias.cc:12121 guuid=6b8063a0-1b00-0000-2e9f-ff99030c0000 pid=3075->128bad62-53f0-5c82-890a-d4a6ddbfdf3c send: 17B guuid=940d6ba0-1b00-0000-2e9f-ff99040c0000 pid=3076 /tmp/morte.i686 guuid=6b8063a0-1b00-0000-2e9f-ff99030c0000 pid=3075->guuid=940d6ba0-1b00-0000-2e9f-ff99040c0000 pid=3076 clone guuid=3194fda2-1b00-0000-2e9f-ff99100c0000 pid=3088->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e849fa3-1b00-0000-2e9f-ff99130c0000 pid=3091 /tmp/morte.x86_64 guuid=3194fda2-1b00-0000-2e9f-ff99100c0000 pid=3088->guuid=1e849fa3-1b00-0000-2e9f-ff99130c0000 pid=3091 clone guuid=6eeaa3a3-1b00-0000-2e9f-ff99150c0000 pid=3093 /tmp/morte.x86_64 zombie guuid=3194fda2-1b00-0000-2e9f-ff99100c0000 pid=3088->guuid=6eeaa3a3-1b00-0000-2e9f-ff99150c0000 pid=3093 clone guuid=3d6ac1a3-1b00-0000-2e9f-ff99170c0000 pid=3095 /tmp/morte.x86_64 write-config zombie guuid=6eeaa3a3-1b00-0000-2e9f-ff99150c0000 pid=3093->guuid=3d6ac1a3-1b00-0000-2e9f-ff99170c0000 pid=3095 clone guuid=acf00ea4-1b00-0000-2e9f-ff99190c0000 pid=3097 /usr/bin/dash guuid=3d6ac1a3-1b00-0000-2e9f-ff99170c0000 pid=3095->guuid=acf00ea4-1b00-0000-2e9f-ff99190c0000 pid=3097 execve guuid=f235efa4-1b00-0000-2e9f-ff991f0c0000 pid=3103 /tmp/morte.x86_64 guuid=3d6ac1a3-1b00-0000-2e9f-ff99170c0000 pid=3095->guuid=f235efa4-1b00-0000-2e9f-ff991f0c0000 pid=3103 clone guuid=bf3d33a4-1b00-0000-2e9f-ff991a0c0000 pid=3098 /usr/bin/cp guuid=acf00ea4-1b00-0000-2e9f-ff99190c0000 pid=3097->guuid=bf3d33a4-1b00-0000-2e9f-ff991a0c0000 pid=3098 execve guuid=388b63a4-1b00-0000-2e9f-ff991c0c0000 pid=3100->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=3995f4a4-1b00-0000-2e9f-ff99200c0000 pid=3104 /tmp/morte.x86_64 guuid=f235efa4-1b00-0000-2e9f-ff991f0c0000 pid=3103->guuid=3995f4a4-1b00-0000-2e9f-ff99200c0000 pid=3104 clone guuid=db76ffa8-1b00-0000-2e9f-ff99300c0000 pid=3120->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=a378a2b1-1b00-0000-2e9f-ff99460c0000 pid=3142->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=aaa9c1b5-1b00-0000-2e9f-ff99510c0000 pid=3153->98abb22e-03b6-509f-a439-809602e811c5 send: 101B guuid=228587bd-1b00-0000-2e9f-ff99640c0000 pid=3172->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=601178c1-1b00-0000-2e9f-ff99700c0000 pid=3184->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=4b81eccd-1b00-0000-2e9f-ff998b0c0000 pid=3211->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=94874cd3-1b00-0000-2e9f-ff99970c0000 pid=3223->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=c7af0adf-1b00-0000-2e9f-ff99ae0c0000 pid=3246->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=ee08a7e3-1b00-0000-2e9f-ff99b50c0000 pid=3253->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=6c3833eb-1b00-0000-2e9f-ff99c80c0000 pid=3272->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=601cc2ee-1b00-0000-2e9f-ff99d10c0000 pid=3281->98abb22e-03b6-509f-a439-809602e811c5 send: 101B guuid=250af0f5-1b00-0000-2e9f-ff99e40c0000 pid=3300->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=9381dcfb-1b00-0000-2e9f-ff99e50c0000 pid=3301->98abb22e-03b6-509f-a439-809602e811c5 send: 101B guuid=80374005-1c00-0000-2e9f-ff99ea0c0000 pid=3306->98abb22e-03b6-509f-a439-809602e811c5 send: 153B guuid=b0612d0a-1c00-0000-2e9f-ff99f30c0000 pid=3315->98abb22e-03b6-509f-a439-809602e811c5 send: 102B guuid=ca757015-1c00-0000-2e9f-ff99050d0000 pid=3333->98abb22e-03b6-509f-a439-809602e811c5 send: 152B guuid=7071e51a-1c00-0000-2e9f-ff990a0d0000 pid=3338->98abb22e-03b6-509f-a439-809602e811c5 send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-08 23:11:21 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
abc.galaxias.cc
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5c9f8b254cb85abdf05baf043034d47d1c32b4e2249ca1a25e4f21c617645f2f

(this sample)

  
Delivery method
Distributed via web download

Comments