MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6b662161f5760b5032e316cb28468c0a16a8f628df06418329f99c5da33f4dab. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 6b662161f5760b5032e316cb28468c0a16a8f628df06418329f99c5da33f4dab
SHA3-384 hash: 27fe76a5f0978ff172dd08a8bc2be556918b03d990d374a525155294a06943719b554925faefaf4172763329977977e0
SHA1 hash: 5b722011201acd64602c35da9e0d4d1c383a4bba
MD5 hash: fddb9173147eb441570e48d98d78a8e1
humanhash: muppet-two-lithium-johnny
File name:1.sh
Download: download sample
Signature Mirai
File size:3'047 bytes
First seen:2025-07-26 22:43:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:YjZs3bh7kHlfXmsLTx4GgJH6DnL/eNIpKksPMEHhns3mcGgJshlpk:Y21o9H/x41a7L0JJBs3mBgJsRk
TLSH T1765191EF23E24A33ADB98FE737A8C404718550DBD5CE5FB554E8B8B9088CE18B441A53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.116.34/bins/morte.x86e41cf98b55686fca887f880de8ebb0d6b05e6b26649b0d95a59729081ac709f5 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.mipsd17de3b065d524a85522d7ed5ab4b15575407c438be1ee5f892445b9148963bd Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.arcbe3824168a5d476bec60bb9f771a5228fa752a6078a05ff079bdca0a4166cdfd Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.i468n/an/aDEU elf geofenced ua-wget
http://196.251.116.34/bins/morte.i686157c027217ced4b50771bbc0e222dc4760f4a0f804763010d3a0a79d84cd0600 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.x86_64623a439ec19f826bdd9cd68d00e38279d60b5ccd8f6fab633b1c6e84207c75a1 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.mpsl815ba825cad23a8791a89ce794d1df9048133a152c2b37ed05066b2d8c6a68e9 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.arma1fa785a37fd03276effde035c81addd23415dfa8ab4ccce30e7deb806d3bb24 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.arm54dcdfc88ddee2531c6caee9c75192843af953b42845654a86937ae82df6072ee Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.arm62ce39c00011d45b712f7310b3d3738c592edcb581b981010f37ddb3853dfdbd9 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.arm7d91ec037d4a3bd3da8068121fd9d0447dd5eb7549051e7122b5d217cdb46af81 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.ppcaca86d90aef3a6b4ad4c0bab0bcac9b306e0f3db025b06735ece832013d40c11 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.spc8f7c1622b81de5ba394145552b33b51e86a009392f7884408ba0507ea148b841 Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.m68kbec7cd4fd3d3921bcb4b581fb9474610cd702b70f5f93d91bc0ee424cfc94dda Miraielf mirai opendir ua-wget
http://196.251.116.34/bins/morte.sh4921022e867133faf030885d2a04b10224417a897c499cd4ee2481ae9c9cd4cb6 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9e1845f6-1700-0000-e32a-8ce7620c0000 pid=3170 /usr/bin/sudo guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174 /tmp/sample.bin guuid=9e1845f6-1700-0000-e32a-8ce7620c0000 pid=3170->guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174 execve guuid=2211d7f9-1700-0000-e32a-8ce7670c0000 pid=3175 /usr/bin/cp guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=2211d7f9-1700-0000-e32a-8ce7670c0000 pid=3175 execve guuid=e8e7e3ff-1700-0000-e32a-8ce7680c0000 pid=3176 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=e8e7e3ff-1700-0000-e32a-8ce7680c0000 pid=3176 execve guuid=8813e205-1800-0000-e32a-8ce7690c0000 pid=3177 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=8813e205-1800-0000-e32a-8ce7690c0000 pid=3177 execve guuid=37868216-1800-0000-e32a-8ce77d0c0000 pid=3197 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=37868216-1800-0000-e32a-8ce77d0c0000 pid=3197 execve guuid=1e03d416-1800-0000-e32a-8ce77e0c0000 pid=3198 /tmp/morte.x86 net guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=1e03d416-1800-0000-e32a-8ce77e0c0000 pid=3198 execve guuid=ea049517-1800-0000-e32a-8ce7800c0000 pid=3200 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=ea049517-1800-0000-e32a-8ce7800c0000 pid=3200 execve guuid=38630e18-1800-0000-e32a-8ce7830c0000 pid=3203 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=38630e18-1800-0000-e32a-8ce7830c0000 pid=3203 execve guuid=3348c11b-1800-0000-e32a-8ce78a0c0000 pid=3210 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=3348c11b-1800-0000-e32a-8ce78a0c0000 pid=3210 execve guuid=c5115620-1800-0000-e32a-8ce7980c0000 pid=3224 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c5115620-1800-0000-e32a-8ce7980c0000 pid=3224 execve guuid=4e85f720-1800-0000-e32a-8ce7990c0000 pid=3225 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=4e85f720-1800-0000-e32a-8ce7990c0000 pid=3225 clone guuid=75b0f921-1800-0000-e32a-8ce79b0c0000 pid=3227 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=75b0f921-1800-0000-e32a-8ce79b0c0000 pid=3227 execve guuid=120d6e26-1800-0000-e32a-8ce79c0c0000 pid=3228 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=120d6e26-1800-0000-e32a-8ce79c0c0000 pid=3228 execve guuid=3ef7bf2d-1800-0000-e32a-8ce79d0c0000 pid=3229 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=3ef7bf2d-1800-0000-e32a-8ce79d0c0000 pid=3229 execve guuid=1fd31137-1800-0000-e32a-8ce79f0c0000 pid=3231 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=1fd31137-1800-0000-e32a-8ce79f0c0000 pid=3231 execve guuid=2e5b6b37-1800-0000-e32a-8ce7a00c0000 pid=3232 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=2e5b6b37-1800-0000-e32a-8ce7a00c0000 pid=3232 clone guuid=c7c30538-1800-0000-e32a-8ce7a20c0000 pid=3234 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c7c30538-1800-0000-e32a-8ce7a20c0000 pid=3234 execve guuid=d38dcb39-1800-0000-e32a-8ce7a90c0000 pid=3241 /usr/bin/wget net send-data guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=d38dcb39-1800-0000-e32a-8ce7a90c0000 pid=3241 execve guuid=6c518b3c-1800-0000-e32a-8ce7b10c0000 pid=3249 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=6c518b3c-1800-0000-e32a-8ce7b10c0000 pid=3249 execve guuid=c425d440-1800-0000-e32a-8ce7b90c0000 pid=3257 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c425d440-1800-0000-e32a-8ce7b90c0000 pid=3257 execve guuid=d7104441-1800-0000-e32a-8ce7ba0c0000 pid=3258 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=d7104441-1800-0000-e32a-8ce7ba0c0000 pid=3258 clone guuid=e2cd8c41-1800-0000-e32a-8ce7bb0c0000 pid=3259 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=e2cd8c41-1800-0000-e32a-8ce7bb0c0000 pid=3259 execve guuid=5dc1fc41-1800-0000-e32a-8ce7bc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=5dc1fc41-1800-0000-e32a-8ce7bc0c0000 pid=3260 execve guuid=8ba4e545-1800-0000-e32a-8ce7be0c0000 pid=3262 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=8ba4e545-1800-0000-e32a-8ce7be0c0000 pid=3262 execve guuid=c7b4434b-1800-0000-e32a-8ce7cc0c0000 pid=3276 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c7b4434b-1800-0000-e32a-8ce7cc0c0000 pid=3276 execve guuid=7c2caf4b-1800-0000-e32a-8ce7ce0c0000 pid=3278 /tmp/morte.i686 net guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=7c2caf4b-1800-0000-e32a-8ce7ce0c0000 pid=3278 execve guuid=26ad384c-1800-0000-e32a-8ce7d10c0000 pid=3281 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=26ad384c-1800-0000-e32a-8ce7d10c0000 pid=3281 execve guuid=fa56724d-1800-0000-e32a-8ce7d30c0000 pid=3283 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=fa56724d-1800-0000-e32a-8ce7d30c0000 pid=3283 execve guuid=70b77b51-1800-0000-e32a-8ce7db0c0000 pid=3291 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=70b77b51-1800-0000-e32a-8ce7db0c0000 pid=3291 execve guuid=bd39f359-1800-0000-e32a-8ce7ec0c0000 pid=3308 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=bd39f359-1800-0000-e32a-8ce7ec0c0000 pid=3308 execve guuid=e3c63e5a-1800-0000-e32a-8ce7ee0c0000 pid=3310 /tmp/morte.x86_64 mprotect-exec net guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=e3c63e5a-1800-0000-e32a-8ce7ee0c0000 pid=3310 execve guuid=16bcc55a-1800-0000-e32a-8ce7f20c0000 pid=3314 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=16bcc55a-1800-0000-e32a-8ce7f20c0000 pid=3314 execve guuid=62063d5b-1800-0000-e32a-8ce7f50c0000 pid=3317 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=62063d5b-1800-0000-e32a-8ce7f50c0000 pid=3317 execve guuid=fce5eb5f-1800-0000-e32a-8ce7050d0000 pid=3333 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=fce5eb5f-1800-0000-e32a-8ce7050d0000 pid=3333 execve guuid=f65a5d64-1800-0000-e32a-8ce7140d0000 pid=3348 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=f65a5d64-1800-0000-e32a-8ce7140d0000 pid=3348 execve guuid=bea4b664-1800-0000-e32a-8ce7160d0000 pid=3350 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=bea4b664-1800-0000-e32a-8ce7160d0000 pid=3350 clone guuid=2e465e65-1800-0000-e32a-8ce7190d0000 pid=3353 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=2e465e65-1800-0000-e32a-8ce7190d0000 pid=3353 execve guuid=5351b365-1800-0000-e32a-8ce71c0d0000 pid=3356 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=5351b365-1800-0000-e32a-8ce71c0d0000 pid=3356 execve guuid=e5b5476e-1800-0000-e32a-8ce72a0d0000 pid=3370 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=e5b5476e-1800-0000-e32a-8ce72a0d0000 pid=3370 execve guuid=19f38c75-1800-0000-e32a-8ce7340d0000 pid=3380 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=19f38c75-1800-0000-e32a-8ce7340d0000 pid=3380 execve guuid=53ce1b76-1800-0000-e32a-8ce7350d0000 pid=3381 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=53ce1b76-1800-0000-e32a-8ce7350d0000 pid=3381 clone guuid=226d2477-1800-0000-e32a-8ce7370d0000 pid=3383 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=226d2477-1800-0000-e32a-8ce7370d0000 pid=3383 execve guuid=e54ee17d-1800-0000-e32a-8ce7380d0000 pid=3384 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=e54ee17d-1800-0000-e32a-8ce7380d0000 pid=3384 execve guuid=ff5e2984-1800-0000-e32a-8ce7390d0000 pid=3385 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=ff5e2984-1800-0000-e32a-8ce7390d0000 pid=3385 execve guuid=6683578a-1800-0000-e32a-8ce7400d0000 pid=3392 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=6683578a-1800-0000-e32a-8ce7400d0000 pid=3392 execve guuid=1c589e8a-1800-0000-e32a-8ce7420d0000 pid=3394 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=1c589e8a-1800-0000-e32a-8ce7420d0000 pid=3394 clone guuid=a75e2b8b-1800-0000-e32a-8ce7450d0000 pid=3397 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=a75e2b8b-1800-0000-e32a-8ce7450d0000 pid=3397 execve guuid=5bc9918b-1800-0000-e32a-8ce7470d0000 pid=3399 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=5bc9918b-1800-0000-e32a-8ce7470d0000 pid=3399 execve guuid=360d548f-1800-0000-e32a-8ce7510d0000 pid=3409 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=360d548f-1800-0000-e32a-8ce7510d0000 pid=3409 execve guuid=a1abdd94-1800-0000-e32a-8ce75e0d0000 pid=3422 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=a1abdd94-1800-0000-e32a-8ce75e0d0000 pid=3422 execve guuid=86943495-1800-0000-e32a-8ce7600d0000 pid=3424 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=86943495-1800-0000-e32a-8ce7600d0000 pid=3424 clone guuid=1bfaf895-1800-0000-e32a-8ce7640d0000 pid=3428 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=1bfaf895-1800-0000-e32a-8ce7640d0000 pid=3428 execve guuid=ab976996-1800-0000-e32a-8ce7660d0000 pid=3430 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=ab976996-1800-0000-e32a-8ce7660d0000 pid=3430 execve guuid=d830289b-1800-0000-e32a-8ce7720d0000 pid=3442 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=d830289b-1800-0000-e32a-8ce7720d0000 pid=3442 execve guuid=95f9fc9f-1800-0000-e32a-8ce7810d0000 pid=3457 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=95f9fc9f-1800-0000-e32a-8ce7810d0000 pid=3457 execve guuid=060a54a0-1800-0000-e32a-8ce7830d0000 pid=3459 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=060a54a0-1800-0000-e32a-8ce7830d0000 pid=3459 clone guuid=f3990da1-1800-0000-e32a-8ce7870d0000 pid=3463 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=f3990da1-1800-0000-e32a-8ce7870d0000 pid=3463 execve guuid=472362a1-1800-0000-e32a-8ce7890d0000 pid=3465 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=472362a1-1800-0000-e32a-8ce7890d0000 pid=3465 execve guuid=70dca8a4-1800-0000-e32a-8ce7940d0000 pid=3476 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=70dca8a4-1800-0000-e32a-8ce7940d0000 pid=3476 execve guuid=73bc04a9-1800-0000-e32a-8ce7a20d0000 pid=3490 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=73bc04a9-1800-0000-e32a-8ce7a20d0000 pid=3490 execve guuid=c9b565a9-1800-0000-e32a-8ce7a40d0000 pid=3492 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c9b565a9-1800-0000-e32a-8ce7a40d0000 pid=3492 clone guuid=172f16aa-1800-0000-e32a-8ce7a80d0000 pid=3496 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=172f16aa-1800-0000-e32a-8ce7a80d0000 pid=3496 execve guuid=c3786caa-1800-0000-e32a-8ce7aa0d0000 pid=3498 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=c3786caa-1800-0000-e32a-8ce7aa0d0000 pid=3498 execve guuid=0a3cddae-1800-0000-e32a-8ce7b70d0000 pid=3511 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=0a3cddae-1800-0000-e32a-8ce7b70d0000 pid=3511 execve guuid=664b8cb4-1800-0000-e32a-8ce7ca0d0000 pid=3530 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=664b8cb4-1800-0000-e32a-8ce7ca0d0000 pid=3530 execve guuid=6d8ee1b4-1800-0000-e32a-8ce7cc0d0000 pid=3532 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=6d8ee1b4-1800-0000-e32a-8ce7cc0d0000 pid=3532 clone guuid=4277a8b6-1800-0000-e32a-8ce7d30d0000 pid=3539 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=4277a8b6-1800-0000-e32a-8ce7d30d0000 pid=3539 execve guuid=27c6f8b6-1800-0000-e32a-8ce7d50d0000 pid=3541 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=27c6f8b6-1800-0000-e32a-8ce7d50d0000 pid=3541 execve guuid=d2eb8bbb-1800-0000-e32a-8ce7e50d0000 pid=3557 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=d2eb8bbb-1800-0000-e32a-8ce7e50d0000 pid=3557 execve guuid=13c9c7c0-1800-0000-e32a-8ce7f30d0000 pid=3571 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=13c9c7c0-1800-0000-e32a-8ce7f30d0000 pid=3571 execve guuid=dd970dc1-1800-0000-e32a-8ce7f40d0000 pid=3572 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=dd970dc1-1800-0000-e32a-8ce7f40d0000 pid=3572 clone guuid=fb2b97c1-1800-0000-e32a-8ce7f70d0000 pid=3575 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=fb2b97c1-1800-0000-e32a-8ce7f70d0000 pid=3575 execve guuid=71efd9c1-1800-0000-e32a-8ce7f90d0000 pid=3577 /usr/bin/wget net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=71efd9c1-1800-0000-e32a-8ce7f90d0000 pid=3577 execve guuid=4496c4c5-1800-0000-e32a-8ce7000e0000 pid=3584 /usr/bin/curl net send-data write-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=4496c4c5-1800-0000-e32a-8ce7000e0000 pid=3584 execve guuid=fe2e84cc-1800-0000-e32a-8ce70b0e0000 pid=3595 /usr/bin/chmod guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=fe2e84cc-1800-0000-e32a-8ce70b0e0000 pid=3595 execve guuid=f323c7cc-1800-0000-e32a-8ce70d0e0000 pid=3597 /usr/bin/bash guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=f323c7cc-1800-0000-e32a-8ce70d0e0000 pid=3597 clone guuid=7850d4cd-1800-0000-e32a-8ce7110e0000 pid=3601 /usr/bin/rm delete-file guuid=34943ff9-1700-0000-e32a-8ce7660c0000 pid=3174->guuid=7850d4cd-1800-0000-e32a-8ce7110e0000 pid=3601 execve f2b0adff-3c28-5b5a-8344-605c6057838c 196.251.116.34:80 guuid=e8e7e3ff-1700-0000-e32a-8ce7680c0000 pid=3176->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=8813e205-1800-0000-e32a-8ce7690c0000 pid=3177->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=1e03d416-1800-0000-e32a-8ce77e0c0000 pid=3198->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c1548317-1800-0000-e32a-8ce77f0c0000 pid=3199 /tmp/morte.x86 guuid=1e03d416-1800-0000-e32a-8ce77e0c0000 pid=3198->guuid=c1548317-1800-0000-e32a-8ce77f0c0000 pid=3199 clone guuid=8654a317-1800-0000-e32a-8ce7810c0000 pid=3201 /tmp/morte.x86 write-config zombie guuid=c1548317-1800-0000-e32a-8ce77f0c0000 pid=3199->guuid=8654a317-1800-0000-e32a-8ce7810c0000 pid=3201 clone guuid=0dc6b81c-1800-0000-e32a-8ce78b0c0000 pid=3211 /usr/bin/dash guuid=8654a317-1800-0000-e32a-8ce7810c0000 pid=3201->guuid=0dc6b81c-1800-0000-e32a-8ce78b0c0000 pid=3211 execve guuid=b530f61e-1800-0000-e32a-8ce7940c0000 pid=3220 /tmp/morte.x86 delete-file guuid=8654a317-1800-0000-e32a-8ce7810c0000 pid=3201->guuid=b530f61e-1800-0000-e32a-8ce7940c0000 pid=3220 clone guuid=38630e18-1800-0000-e32a-8ce7830c0000 pid=3203->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=3348c11b-1800-0000-e32a-8ce78a0c0000 pid=3210->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=68bbfc1c-1800-0000-e32a-8ce78d0c0000 pid=3213 /usr/bin/cp guuid=0dc6b81c-1800-0000-e32a-8ce78b0c0000 pid=3211->guuid=68bbfc1c-1800-0000-e32a-8ce78d0c0000 pid=3213 execve guuid=120d6e26-1800-0000-e32a-8ce79c0c0000 pid=3228->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=3ef7bf2d-1800-0000-e32a-8ce79d0c0000 pid=3229->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B guuid=d38dcb39-1800-0000-e32a-8ce7a90c0000 pid=3241->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=6c518b3c-1800-0000-e32a-8ce7b10c0000 pid=3249->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=5dc1fc41-1800-0000-e32a-8ce7bc0c0000 pid=3260->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=8ba4e545-1800-0000-e32a-8ce7be0c0000 pid=3262->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=7c2caf4b-1800-0000-e32a-8ce7ce0c0000 pid=3278->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5b4a064c-1800-0000-e32a-8ce7cf0c0000 pid=3279 /tmp/morte.i686 guuid=7c2caf4b-1800-0000-e32a-8ce7ce0c0000 pid=3278->guuid=5b4a064c-1800-0000-e32a-8ce7cf0c0000 pid=3279 clone guuid=d1a5134c-1800-0000-e32a-8ce7d00c0000 pid=3280 /tmp/morte.i686 write-config zombie guuid=5b4a064c-1800-0000-e32a-8ce7cf0c0000 pid=3279->guuid=d1a5134c-1800-0000-e32a-8ce7d00c0000 pid=3280 clone guuid=130b954f-1800-0000-e32a-8ce7d90c0000 pid=3289 /usr/bin/dash guuid=d1a5134c-1800-0000-e32a-8ce7d00c0000 pid=3280->guuid=130b954f-1800-0000-e32a-8ce7d90c0000 pid=3289 execve guuid=c3085552-1800-0000-e32a-8ce7dc0c0000 pid=3292 /tmp/morte.i686 guuid=d1a5134c-1800-0000-e32a-8ce7d00c0000 pid=3280->guuid=c3085552-1800-0000-e32a-8ce7dc0c0000 pid=3292 clone guuid=bb6a9257-1c00-0000-e32a-8ce7cd140000 pid=5325 /tmp/morte.i686 dns net send-data guuid=d1a5134c-1800-0000-e32a-8ce7d00c0000 pid=3280->guuid=bb6a9257-1c00-0000-e32a-8ce7cd140000 pid=5325 clone guuid=fa56724d-1800-0000-e32a-8ce7d30c0000 pid=3283->f2b0adff-3c28-5b5a-8344-605c6057838c send: 146B guuid=460acb4f-1800-0000-e32a-8ce7da0c0000 pid=3290 /usr/bin/cp guuid=130b954f-1800-0000-e32a-8ce7d90c0000 pid=3289->guuid=460acb4f-1800-0000-e32a-8ce7da0c0000 pid=3290 execve guuid=70b77b51-1800-0000-e32a-8ce7db0c0000 pid=3291->f2b0adff-3c28-5b5a-8344-605c6057838c send: 95B guuid=e3c63e5a-1800-0000-e32a-8ce7ee0c0000 pid=3310->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=58e4b55a-1800-0000-e32a-8ce7f10c0000 pid=3313 /tmp/morte.x86_64 zombie guuid=e3c63e5a-1800-0000-e32a-8ce7ee0c0000 pid=3310->guuid=58e4b55a-1800-0000-e32a-8ce7f10c0000 pid=3313 clone guuid=2225de5a-1800-0000-e32a-8ce7f40c0000 pid=3316 /tmp/morte.x86_64 write-config zombie guuid=58e4b55a-1800-0000-e32a-8ce7f10c0000 pid=3313->guuid=2225de5a-1800-0000-e32a-8ce7f40c0000 pid=3316 clone guuid=7448535b-1800-0000-e32a-8ce7f60c0000 pid=3318 /usr/bin/dash guuid=2225de5a-1800-0000-e32a-8ce7f40c0000 pid=3316->guuid=7448535b-1800-0000-e32a-8ce7f60c0000 pid=3318 execve guuid=a3ed415c-1800-0000-e32a-8ce7f90c0000 pid=3321 /tmp/morte.x86_64 dns net send-data guuid=2225de5a-1800-0000-e32a-8ce7f40c0000 pid=3316->guuid=a3ed415c-1800-0000-e32a-8ce7f90c0000 pid=3321 clone guuid=62063d5b-1800-0000-e32a-8ce7f50c0000 pid=3317->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=89788b5b-1800-0000-e32a-8ce7f70c0000 pid=3319 /usr/bin/cp guuid=7448535b-1800-0000-e32a-8ce7f60c0000 pid=3318->guuid=89788b5b-1800-0000-e32a-8ce7f70c0000 pid=3319 execve guuid=a3ed415c-1800-0000-e32a-8ce7f90c0000 pid=3321->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 1bbb4005-5fa7-5147-8924-030d465cc44a vipcncnetwork.com:12121 guuid=a3ed415c-1800-0000-e32a-8ce7f90c0000 pid=3321->1bbb4005-5fa7-5147-8924-030d465cc44a send: 27B guuid=fce5eb5f-1800-0000-e32a-8ce7050d0000 pid=3333->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=5351b365-1800-0000-e32a-8ce71c0d0000 pid=3356->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=e5b5476e-1800-0000-e32a-8ce72a0d0000 pid=3370->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B guuid=e54ee17d-1800-0000-e32a-8ce7380d0000 pid=3384->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=ff5e2984-1800-0000-e32a-8ce7390d0000 pid=3385->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=5bc9918b-1800-0000-e32a-8ce7470d0000 pid=3399->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=360d548f-1800-0000-e32a-8ce7510d0000 pid=3409->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=ab976996-1800-0000-e32a-8ce7660d0000 pid=3430->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=d830289b-1800-0000-e32a-8ce7720d0000 pid=3442->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=472362a1-1800-0000-e32a-8ce7890d0000 pid=3465->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=70dca8a4-1800-0000-e32a-8ce7940d0000 pid=3476->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B guuid=c3786caa-1800-0000-e32a-8ce7aa0d0000 pid=3498->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=0a3cddae-1800-0000-e32a-8ce7b70d0000 pid=3511->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B guuid=27c6f8b6-1800-0000-e32a-8ce7d50d0000 pid=3541->f2b0adff-3c28-5b5a-8344-605c6057838c send: 144B guuid=d2eb8bbb-1800-0000-e32a-8ce7e50d0000 pid=3557->f2b0adff-3c28-5b5a-8344-605c6057838c send: 93B guuid=71efd9c1-1800-0000-e32a-8ce7f90d0000 pid=3577->f2b0adff-3c28-5b5a-8344-605c6057838c send: 143B guuid=4496c4c5-1800-0000-e32a-8ce7000e0000 pid=3584->f2b0adff-3c28-5b5a-8344-605c6057838c send: 92B guuid=bb6a9257-1c00-0000-e32a-8ce7cd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=bb6a9257-1c00-0000-e32a-8ce7cd140000 pid=5325->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-26 22:44:22 UTC
File Type:
Text (Shell)
AV detection:
20 of 35 (57.14%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6b662161f5760b5032e316cb28468c0a16a8f628df06418329f99c5da33f4dab

(this sample)

Comments