MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f0652634262fb2d081e4dbc35d45cfcc8cac0e061862fc7ceadf3ed6cb107c9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 7f0652634262fb2d081e4dbc35d45cfcc8cac0e061862fc7ceadf3ed6cb107c9
SHA3-384 hash: 3f23f3c375a26f57be1b92ae5c4eabc4387e888dba202d2ed026fea70212d270075b7194b22de49b50215cebdddcfa9c
SHA1 hash: faea454ddbddf434bd21b0b5216f9e0eb6cfcd1e
MD5 hash: a560ea05c656202a25e659a3a91d3bdb
humanhash: sad-oranges-crazy-jupiter
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-07-14 07:59:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItQVGVxZsQVhV2bhQVAVXkQVlVqlfQVnVQmsQVLVUTQVCRVCGgJQVOVZ6QVzVcnd:i+Js5/D/u1K3L8J5pYdMBgJshk
TLSH T1BB618EFA03654E3F6CAAC9D3B2E84504658164AB56CE1F759BDC2CB83E8CEC93D41642
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://104.164.104.15/00101010101001/morte.x867196fdb42f127478c84560a1687eede33e0eba72dc617cd0a5ea53555a265c54 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.mipsd2f7207f029f0f4af18b3794d44594087afef997a0522d0b08e0d4bbea71b54a Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.arca851a356311c345001caf70c79a51980d634dc59624d208ac5d2d00b38dcd1f0 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.i468n/an/aua-wget
http://104.164.104.15/00101010101001/morte.i686e55a4c994ea480147991ad39576dcbdbcc0f8d838f249d897ec58c5dbd498e39 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.x86_64c02160f8d032f14899c38d499121cfc735f88f944dc86f1c43625c2decf599e2 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.mpsl999e268bd1d7691875aaead94114dcec9d9fff165d63b28de4b094639383435b Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.arm90a19bc444173323f0ddefb8b2a521318168c27082f12c75e645e0dfbe4de37a Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.arm55d0b05171869c2ec854b2d7ed3673f759b42c8b0f42c027646e49ecf2938aee9 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.arm634bfdd2d6844472e5b697e212743926f8b40fd2b127bd4d513ef4f6226e11019 Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.arm76ff0097d9df2e1faffcb66f7600a8d5a8f409222eeddeaaba1a5361902b6a0bd Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.ppcd423ded7d989496e17fb1446c2f266240e8d2d3a19c55d2cf3fd3736d057be0d Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.spc09c03620ab0292edbf23443279bd2648d251083b4e3512ef6e5386e88eb7a07e Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.m68k12fce44ba88e9672d23df2758518408678ca730990b315de6d09d40c56c5945d Miraielf mirai ua-wget
http://104.164.104.15/00101010101001/morte.sh44fefc3f056ead1a64fe2c5132c19e05b700ce944f9319cc8c50ba094ff860a9e Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9fa3a93b-1a00-0000-2ecb-98c1f5080000 pid=2293 /usr/bin/sudo guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295 /tmp/sample.bin guuid=9fa3a93b-1a00-0000-2ecb-98c1f5080000 pid=2293->guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295 execve guuid=9793b63d-1a00-0000-2ecb-98c1f8080000 pid=2296 /usr/bin/cp guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=9793b63d-1a00-0000-2ecb-98c1f8080000 pid=2296 execve guuid=6dea4145-1a00-0000-2ecb-98c107090000 pid=2311 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=6dea4145-1a00-0000-2ecb-98c107090000 pid=2311 execve guuid=acefae58-1a00-0000-2ecb-98c130090000 pid=2352 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=acefae58-1a00-0000-2ecb-98c130090000 pid=2352 execve guuid=4df01f6f-1a00-0000-2ecb-98c162090000 pid=2402 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=4df01f6f-1a00-0000-2ecb-98c162090000 pid=2402 execve guuid=472f956f-1a00-0000-2ecb-98c163090000 pid=2403 /tmp/morte.x86 net guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=472f956f-1a00-0000-2ecb-98c163090000 pid=2403 execve guuid=d2da8070-1a00-0000-2ecb-98c166090000 pid=2406 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=d2da8070-1a00-0000-2ecb-98c166090000 pid=2406 execve guuid=c9acfe70-1a00-0000-2ecb-98c167090000 pid=2407 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=c9acfe70-1a00-0000-2ecb-98c167090000 pid=2407 execve guuid=d7453f83-1a00-0000-2ecb-98c194090000 pid=2452 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=d7453f83-1a00-0000-2ecb-98c194090000 pid=2452 execve guuid=7faf8795-1a00-0000-2ecb-98c1ad090000 pid=2477 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=7faf8795-1a00-0000-2ecb-98c1ad090000 pid=2477 execve guuid=7fb1d395-1a00-0000-2ecb-98c1af090000 pid=2479 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=7fb1d395-1a00-0000-2ecb-98c1af090000 pid=2479 clone guuid=6f26c697-1a00-0000-2ecb-98c1b5090000 pid=2485 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=6f26c697-1a00-0000-2ecb-98c1b5090000 pid=2485 execve guuid=bea20498-1a00-0000-2ecb-98c1b6090000 pid=2486 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=bea20498-1a00-0000-2ecb-98c1b6090000 pid=2486 execve guuid=7a1361b3-1a00-0000-2ecb-98c1ff090000 pid=2559 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=7a1361b3-1a00-0000-2ecb-98c1ff090000 pid=2559 execve guuid=088617d0-1a00-0000-2ecb-98c14a0a0000 pid=2634 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=088617d0-1a00-0000-2ecb-98c14a0a0000 pid=2634 execve guuid=96f785d0-1a00-0000-2ecb-98c14c0a0000 pid=2636 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=96f785d0-1a00-0000-2ecb-98c14c0a0000 pid=2636 clone guuid=fee66ad1-1a00-0000-2ecb-98c14f0a0000 pid=2639 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=fee66ad1-1a00-0000-2ecb-98c14f0a0000 pid=2639 execve guuid=c036b9d1-1a00-0000-2ecb-98c1510a0000 pid=2641 /usr/bin/wget net send-data guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=c036b9d1-1a00-0000-2ecb-98c1510a0000 pid=2641 execve guuid=73fc72dd-1a00-0000-2ecb-98c1730a0000 pid=2675 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=73fc72dd-1a00-0000-2ecb-98c1730a0000 pid=2675 execve guuid=bffcbfeb-1a00-0000-2ecb-98c1a00a0000 pid=2720 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=bffcbfeb-1a00-0000-2ecb-98c1a00a0000 pid=2720 execve guuid=33343cec-1a00-0000-2ecb-98c1a30a0000 pid=2723 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=33343cec-1a00-0000-2ecb-98c1a30a0000 pid=2723 clone guuid=2e916fec-1a00-0000-2ecb-98c1a50a0000 pid=2725 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=2e916fec-1a00-0000-2ecb-98c1a50a0000 pid=2725 execve guuid=bf3dc4ec-1a00-0000-2ecb-98c1a70a0000 pid=2727 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=bf3dc4ec-1a00-0000-2ecb-98c1a70a0000 pid=2727 execve guuid=fef1f9fd-1a00-0000-2ecb-98c1d00a0000 pid=2768 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=fef1f9fd-1a00-0000-2ecb-98c1d00a0000 pid=2768 execve guuid=f8f87312-1b00-0000-2ecb-98c1ef0a0000 pid=2799 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=f8f87312-1b00-0000-2ecb-98c1ef0a0000 pid=2799 execve guuid=a881c912-1b00-0000-2ecb-98c1f10a0000 pid=2801 /tmp/morte.i686 net guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=a881c912-1b00-0000-2ecb-98c1f10a0000 pid=2801 execve guuid=e61fd713-1b00-0000-2ecb-98c1f60a0000 pid=2806 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=e61fd713-1b00-0000-2ecb-98c1f60a0000 pid=2806 execve guuid=595e6f14-1b00-0000-2ecb-98c1f80a0000 pid=2808 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=595e6f14-1b00-0000-2ecb-98c1f80a0000 pid=2808 execve guuid=6b5aa025-1b00-0000-2ecb-98c1150b0000 pid=2837 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=6b5aa025-1b00-0000-2ecb-98c1150b0000 pid=2837 execve guuid=867a4138-1b00-0000-2ecb-98c1350b0000 pid=2869 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=867a4138-1b00-0000-2ecb-98c1350b0000 pid=2869 execve guuid=8c5fa138-1b00-0000-2ecb-98c1360b0000 pid=2870 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=8c5fa138-1b00-0000-2ecb-98c1360b0000 pid=2870 clone guuid=3eecda38-1b00-0000-2ecb-98c1370b0000 pid=2871 /usr/bin/rm guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=3eecda38-1b00-0000-2ecb-98c1370b0000 pid=2871 execve guuid=a5d03139-1b00-0000-2ecb-98c1380b0000 pid=2872 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=a5d03139-1b00-0000-2ecb-98c1380b0000 pid=2872 execve guuid=d2c0a54a-1b00-0000-2ecb-98c1640b0000 pid=2916 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=d2c0a54a-1b00-0000-2ecb-98c1640b0000 pid=2916 execve guuid=73bee961-1b00-0000-2ecb-98c1950b0000 pid=2965 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=73bee961-1b00-0000-2ecb-98c1950b0000 pid=2965 execve guuid=17f9f962-1b00-0000-2ecb-98c1960b0000 pid=2966 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=17f9f962-1b00-0000-2ecb-98c1960b0000 pid=2966 clone guuid=8b93b363-1b00-0000-2ecb-98c1990b0000 pid=2969 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=8b93b363-1b00-0000-2ecb-98c1990b0000 pid=2969 execve guuid=2c6b6c64-1b00-0000-2ecb-98c19a0b0000 pid=2970 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=2c6b6c64-1b00-0000-2ecb-98c19a0b0000 pid=2970 execve guuid=e9ff1c76-1b00-0000-2ecb-98c1c20b0000 pid=3010 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=e9ff1c76-1b00-0000-2ecb-98c1c20b0000 pid=3010 execve guuid=8927e18a-1b00-0000-2ecb-98c1df0b0000 pid=3039 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=8927e18a-1b00-0000-2ecb-98c1df0b0000 pid=3039 execve guuid=78285f8b-1b00-0000-2ecb-98c1e20b0000 pid=3042 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=78285f8b-1b00-0000-2ecb-98c1e20b0000 pid=3042 clone guuid=3562958c-1b00-0000-2ecb-98c1e60b0000 pid=3046 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=3562958c-1b00-0000-2ecb-98c1e60b0000 pid=3046 execve guuid=2669ef96-1b00-0000-2ecb-98c1ee0b0000 pid=3054 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=2669ef96-1b00-0000-2ecb-98c1ee0b0000 pid=3054 execve guuid=89c508a8-1b00-0000-2ecb-98c11f0c0000 pid=3103 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=89c508a8-1b00-0000-2ecb-98c11f0c0000 pid=3103 execve guuid=6e26c9bc-1b00-0000-2ecb-98c14e0c0000 pid=3150 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=6e26c9bc-1b00-0000-2ecb-98c14e0c0000 pid=3150 execve guuid=4ac53bbd-1b00-0000-2ecb-98c14f0c0000 pid=3151 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=4ac53bbd-1b00-0000-2ecb-98c14f0c0000 pid=3151 clone guuid=3fcbe0bd-1b00-0000-2ecb-98c1510c0000 pid=3153 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=3fcbe0bd-1b00-0000-2ecb-98c1510c0000 pid=3153 execve guuid=1dd3d9c1-1b00-0000-2ecb-98c1530c0000 pid=3155 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=1dd3d9c1-1b00-0000-2ecb-98c1530c0000 pid=3155 execve guuid=772bb1d3-1b00-0000-2ecb-98c1770c0000 pid=3191 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=772bb1d3-1b00-0000-2ecb-98c1770c0000 pid=3191 execve guuid=aea830e6-1b00-0000-2ecb-98c1a20c0000 pid=3234 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=aea830e6-1b00-0000-2ecb-98c1a20c0000 pid=3234 execve guuid=bc147fe6-1b00-0000-2ecb-98c1a30c0000 pid=3235 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=bc147fe6-1b00-0000-2ecb-98c1a30c0000 pid=3235 clone guuid=fc9607e7-1b00-0000-2ecb-98c1a60c0000 pid=3238 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=fc9607e7-1b00-0000-2ecb-98c1a60c0000 pid=3238 execve guuid=b7f252e7-1b00-0000-2ecb-98c1a80c0000 pid=3240 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=b7f252e7-1b00-0000-2ecb-98c1a80c0000 pid=3240 execve guuid=9abbd5fd-1b00-0000-2ecb-98c1d10c0000 pid=3281 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=9abbd5fd-1b00-0000-2ecb-98c1d10c0000 pid=3281 execve guuid=0704b917-1c00-0000-2ecb-98c1e70c0000 pid=3303 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=0704b917-1c00-0000-2ecb-98c1e70c0000 pid=3303 execve guuid=a6061618-1c00-0000-2ecb-98c1e80c0000 pid=3304 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=a6061618-1c00-0000-2ecb-98c1e80c0000 pid=3304 clone guuid=5c213a18-1c00-0000-2ecb-98c1e90c0000 pid=3305 /usr/bin/rm guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=5c213a18-1c00-0000-2ecb-98c1e90c0000 pid=3305 execve guuid=7efd9218-1c00-0000-2ecb-98c1ea0c0000 pid=3306 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=7efd9218-1c00-0000-2ecb-98c1ea0c0000 pid=3306 execve guuid=d8bdc629-1c00-0000-2ecb-98c1000d0000 pid=3328 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=d8bdc629-1c00-0000-2ecb-98c1000d0000 pid=3328 execve guuid=80d5c33d-1c00-0000-2ecb-98c1330d0000 pid=3379 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=80d5c33d-1c00-0000-2ecb-98c1330d0000 pid=3379 execve guuid=39800a3e-1c00-0000-2ecb-98c1350d0000 pid=3381 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=39800a3e-1c00-0000-2ecb-98c1350d0000 pid=3381 clone guuid=6f1b6840-1c00-0000-2ecb-98c13e0d0000 pid=3390 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=6f1b6840-1c00-0000-2ecb-98c13e0d0000 pid=3390 execve guuid=58a69e42-1c00-0000-2ecb-98c1450d0000 pid=3397 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=58a69e42-1c00-0000-2ecb-98c1450d0000 pid=3397 execve guuid=dc7fe258-1c00-0000-2ecb-98c1600d0000 pid=3424 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=dc7fe258-1c00-0000-2ecb-98c1600d0000 pid=3424 execve guuid=757a2d74-1c00-0000-2ecb-98c19b0d0000 pid=3483 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=757a2d74-1c00-0000-2ecb-98c19b0d0000 pid=3483 execve guuid=5d1a8774-1c00-0000-2ecb-98c19d0d0000 pid=3485 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=5d1a8774-1c00-0000-2ecb-98c19d0d0000 pid=3485 clone guuid=4f273175-1c00-0000-2ecb-98c1a10d0000 pid=3489 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=4f273175-1c00-0000-2ecb-98c1a10d0000 pid=3489 execve guuid=2baeaa77-1c00-0000-2ecb-98c1a70d0000 pid=3495 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=2baeaa77-1c00-0000-2ecb-98c1a70d0000 pid=3495 execve guuid=04a5f38e-1c00-0000-2ecb-98c1de0d0000 pid=3550 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=04a5f38e-1c00-0000-2ecb-98c1de0d0000 pid=3550 execve guuid=edade8a6-1c00-0000-2ecb-98c10b0e0000 pid=3595 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=edade8a6-1c00-0000-2ecb-98c10b0e0000 pid=3595 execve guuid=a2e359a7-1c00-0000-2ecb-98c10c0e0000 pid=3596 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=a2e359a7-1c00-0000-2ecb-98c10c0e0000 pid=3596 clone guuid=721a0fa8-1c00-0000-2ecb-98c10e0e0000 pid=3598 /usr/bin/rm delete-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=721a0fa8-1c00-0000-2ecb-98c10e0e0000 pid=3598 execve guuid=9e4164a8-1c00-0000-2ecb-98c10f0e0000 pid=3599 /usr/bin/wget net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=9e4164a8-1c00-0000-2ecb-98c10f0e0000 pid=3599 execve guuid=855285bf-1c00-0000-2ecb-98c12a0e0000 pid=3626 /usr/bin/curl net send-data write-file guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=855285bf-1c00-0000-2ecb-98c12a0e0000 pid=3626 execve guuid=3c2c26d8-1c00-0000-2ecb-98c16c0e0000 pid=3692 /usr/bin/chmod guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=3c2c26d8-1c00-0000-2ecb-98c16c0e0000 pid=3692 execve guuid=413ba2d8-1c00-0000-2ecb-98c16d0e0000 pid=3693 /usr/bin/bash guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=413ba2d8-1c00-0000-2ecb-98c16d0e0000 pid=3693 clone guuid=c423d4d8-1c00-0000-2ecb-98c16f0e0000 pid=3695 /usr/bin/rm guuid=1bbf593d-1a00-0000-2ecb-98c1f7080000 pid=2295->guuid=c423d4d8-1c00-0000-2ecb-98c16f0e0000 pid=3695 execve 8597c678-19f5-53fc-90aa-87e81ecf04ca 104.164.104.15:80 guuid=6dea4145-1a00-0000-2ecb-98c107090000 pid=2311->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 153B guuid=acefae58-1a00-0000-2ecb-98c130090000 pid=2352->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=472f956f-1a00-0000-2ecb-98c163090000 pid=2403->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=82e27070-1a00-0000-2ecb-98c164090000 pid=2404 /tmp/morte.x86 guuid=472f956f-1a00-0000-2ecb-98c163090000 pid=2403->guuid=82e27070-1a00-0000-2ecb-98c164090000 pid=2404 clone guuid=66417e70-1a00-0000-2ecb-98c165090000 pid=2405 /tmp/morte.x86 write-config zombie guuid=82e27070-1a00-0000-2ecb-98c164090000 pid=2404->guuid=66417e70-1a00-0000-2ecb-98c165090000 pid=2405 clone guuid=3ba56275-1a00-0000-2ecb-98c170090000 pid=2416 /usr/bin/dash guuid=66417e70-1a00-0000-2ecb-98c165090000 pid=2405->guuid=3ba56275-1a00-0000-2ecb-98c170090000 pid=2416 execve guuid=40e18778-1a00-0000-2ecb-98c179090000 pid=2425 /tmp/morte.x86 delete-file dns net send-data zombie guuid=66417e70-1a00-0000-2ecb-98c165090000 pid=2405->guuid=40e18778-1a00-0000-2ecb-98c179090000 pid=2425 clone guuid=c9acfe70-1a00-0000-2ecb-98c167090000 pid=2407->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 154B guuid=384b0176-1a00-0000-2ecb-98c172090000 pid=2418 /usr/bin/cp guuid=3ba56275-1a00-0000-2ecb-98c170090000 pid=2416->guuid=384b0176-1a00-0000-2ecb-98c172090000 pid=2418 execve guuid=40e18778-1a00-0000-2ecb-98c179090000 pid=2425->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 60B 96fddf7d-a0d8-5efa-9fe5-4b09baec8f67 cnnetwork.uk:12121 guuid=40e18778-1a00-0000-2ecb-98c179090000 pid=2425->96fddf7d-a0d8-5efa-9fe5-4b09baec8f67 send: 44B guuid=d7453f83-1a00-0000-2ecb-98c194090000 pid=2452->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 103B guuid=bea20498-1a00-0000-2ecb-98c1b6090000 pid=2486->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 153B guuid=7a1361b3-1a00-0000-2ecb-98c1ff090000 pid=2559->8597c678-19f5-53fc-90aa-87e81ecf04ca send: 102B b9cfaa70-272f-5865-bf7e-eba900bc34b5 cnnetwork.uk:80 guuid=c036b9d1-1a00-0000-2ecb-98c1510a0000 pid=2641->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=73fc72dd-1a00-0000-2ecb-98c1730a0000 pid=2675->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=bf3dc4ec-1a00-0000-2ecb-98c1a70a0000 pid=2727->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=fef1f9fd-1a00-0000-2ecb-98c1d00a0000 pid=2768->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=a881c912-1b00-0000-2ecb-98c1f10a0000 pid=2801->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a87e0113-1b00-0000-2ecb-98c1f20a0000 pid=2802 /tmp/morte.i686 guuid=a881c912-1b00-0000-2ecb-98c1f10a0000 pid=2801->guuid=a87e0113-1b00-0000-2ecb-98c1f20a0000 pid=2802 clone guuid=e5220a13-1b00-0000-2ecb-98c1f40a0000 pid=2804 /tmp/morte.i686 write-config zombie guuid=a87e0113-1b00-0000-2ecb-98c1f20a0000 pid=2802->guuid=e5220a13-1b00-0000-2ecb-98c1f40a0000 pid=2804 clone guuid=ee4b1117-1b00-0000-2ecb-98c1f90a0000 pid=2809 /usr/bin/dash guuid=e5220a13-1b00-0000-2ecb-98c1f40a0000 pid=2804->guuid=ee4b1117-1b00-0000-2ecb-98c1f90a0000 pid=2809 execve guuid=2928941a-1b00-0000-2ecb-98c1fd0a0000 pid=2813 /tmp/morte.i686 delete-file dns net send-data guuid=e5220a13-1b00-0000-2ecb-98c1f40a0000 pid=2804->guuid=2928941a-1b00-0000-2ecb-98c1fd0a0000 pid=2813 clone guuid=595e6f14-1b00-0000-2ecb-98c1f80a0000 pid=2808->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 156B guuid=6629a717-1b00-0000-2ecb-98c1fa0a0000 pid=2810 /usr/bin/cp guuid=ee4b1117-1b00-0000-2ecb-98c1f90a0000 pid=2809->guuid=6629a717-1b00-0000-2ecb-98c1fa0a0000 pid=2810 execve guuid=2928941a-1b00-0000-2ecb-98c1fd0a0000 pid=2813->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 750B guuid=2928941a-1b00-0000-2ecb-98c1fd0a0000 pid=2813->96fddf7d-a0d8-5efa-9fe5-4b09baec8f67 send: 575B guuid=6b5aa025-1b00-0000-2ecb-98c1150b0000 pid=2837->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 105B guuid=a5d03139-1b00-0000-2ecb-98c1380b0000 pid=2872->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=d2c0a54a-1b00-0000-2ecb-98c1640b0000 pid=2916->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=2c6b6c64-1b00-0000-2ecb-98c19a0b0000 pid=2970->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 153B guuid=e9ff1c76-1b00-0000-2ecb-98c1c20b0000 pid=3010->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 102B guuid=2669ef96-1b00-0000-2ecb-98c1ee0b0000 pid=3054->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=89c508a8-1b00-0000-2ecb-98c11f0c0000 pid=3103->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=1dd3d9c1-1b00-0000-2ecb-98c1530c0000 pid=3155->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=772bb1d3-1b00-0000-2ecb-98c1770c0000 pid=3191->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=b7f252e7-1b00-0000-2ecb-98c1a80c0000 pid=3240->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=9abbd5fd-1b00-0000-2ecb-98c1d10c0000 pid=3281->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=7efd9218-1c00-0000-2ecb-98c1ea0c0000 pid=3306->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 153B guuid=d8bdc629-1c00-0000-2ecb-98c1000d0000 pid=3328->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 102B guuid=58a69e42-1c00-0000-2ecb-98c1450d0000 pid=3397->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 153B guuid=dc7fe258-1c00-0000-2ecb-98c1600d0000 pid=3424->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 102B guuid=2baeaa77-1c00-0000-2ecb-98c1a70d0000 pid=3495->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 154B guuid=04a5f38e-1c00-0000-2ecb-98c1de0d0000 pid=3550->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 103B guuid=9e4164a8-1c00-0000-2ecb-98c10f0e0000 pid=3599->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 153B guuid=855285bf-1c00-0000-2ecb-98c12a0e0000 pid=3626->b9cfaa70-272f-5865-bf7e-eba900bc34b5 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-14 07:51:17 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7f0652634262fb2d081e4dbc35d45cfcc8cac0e061862fc7ceadf3ed6cb107c9

(this sample)

  
Delivery method
Distributed via web download

Comments