MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 80a38307191ee64af780665afa1ea0ebfc7355d66ce420f8469cf63f0eaa17d3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 80a38307191ee64af780665afa1ea0ebfc7355d66ce420f8469cf63f0eaa17d3
SHA3-384 hash: 6832487a9ffdd73e4d77cd2cec7996900a905626aa5195eb64505b6ca5b7fa15e9e4a06f59c4e915b736834442874878
SHA1 hash: 9bbf49ea5705f1f574b37718d60c1c85a89f30c2
MD5 hash: 200975240313bfd610508d9225489780
humanhash: aspen-two-helium-kitten
File name:1.sh
Download: download sample
Signature Mirai
File size:3'074 bytes
First seen:2025-07-21 23:23:17 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It/ZsnbhTkzlfbmsvToLGgJv63nLONNIpKks/ME5hzsoncGgJsYApk:iqlAxT7oL1SXLCJ5bIonBgJsvk
TLSH T1905164E663814AB31CBA8DDB76A84884735D40DFE4AF9F3AD5D8E4E9428EF187440741
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.213.240.242/bins/morte.x866b89288f82c10313cc04d6801994f61ae0f454a8e49ae902416549475d22563e Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.mipsdb7c3f4a4d9955f60e2428d33081b7516d2b05a554549ef7435ad5f0da26aebc Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arcbc7ba0be21d0bd4d5f8ffba11fb517a6128ed67aaee485f4e9ad55ebb206dfd7 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.i468n/an/aelf opendir ua-wget
http://185.213.240.242/bins/morte.i686ec6877d780e5c08a52316ed53c1e24688df1bb77573a73552807b446682303e1 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.x86_640f3d5843dbea20320950015e6b16d397ead64d3a0cc0c0c9d236ab0c329e5c3c Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.mpsl6a381680badfe72a680a7ebbac5a87b69b92bef8cf495dea18c08768ae4a8104 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm1e084f768e6f712bd7a6550bfd1d6651475110be15afdaf20ea165035e41825b Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm5bb58685e750ea7ea86ef5e8e0272309259225751e891a8180edeb43f00e12237 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm6fc5cd925ce297000ca57784ead53c74be59b7f1947fe30fc596b8288b58e34ac Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm7f668ad9e7208fb93503504745e844534c2f1cd03bb8be6580ceb107b2f3e5c1f Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.ppc4c2307922752b1dda4168efb06f7f577df1e1a6b559b16e290533fa875bbfb67 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.spc600fc077b364f1e19774afc961c350ca78168a7c89985b8d649d18a784bb54ca Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.m68kb34ab7b3235520d509129dbf8ce61fa4aaf07c689caf1086678d209c2bdfb15f Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.sh4aeaca0a823b1c1ba1fef65021e4435d355d8da6763b976bfecfe002a17023b80 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=d9ff6778-1600-0000-6546-a20df00c0000 pid=3312 /usr/bin/sudo guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313 /tmp/sample.bin guuid=d9ff6778-1600-0000-6546-a20df00c0000 pid=3312->guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313 execve guuid=028c5f7c-1600-0000-6546-a20df30c0000 pid=3315 /usr/bin/cp guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=028c5f7c-1600-0000-6546-a20df30c0000 pid=3315 execve guuid=638c3081-1600-0000-6546-a20df90c0000 pid=3321 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=638c3081-1600-0000-6546-a20df90c0000 pid=3321 execve guuid=fb60b986-1600-0000-6546-a20d050d0000 pid=3333 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=fb60b986-1600-0000-6546-a20d050d0000 pid=3333 execve guuid=73bdb992-1600-0000-6546-a20d1f0d0000 pid=3359 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=73bdb992-1600-0000-6546-a20d1f0d0000 pid=3359 execve guuid=b5a43893-1600-0000-6546-a20d220d0000 pid=3362 /tmp/morte.x86 net guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=b5a43893-1600-0000-6546-a20d220d0000 pid=3362 execve guuid=17709f93-1600-0000-6546-a20d250d0000 pid=3365 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=17709f93-1600-0000-6546-a20d250d0000 pid=3365 execve guuid=f335ef93-1600-0000-6546-a20d280d0000 pid=3368 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=f335ef93-1600-0000-6546-a20d280d0000 pid=3368 execve guuid=eb3c9099-1600-0000-6546-a20d3c0d0000 pid=3388 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=eb3c9099-1600-0000-6546-a20d3c0d0000 pid=3388 execve guuid=6403c2a0-1600-0000-6546-a20d530d0000 pid=3411 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=6403c2a0-1600-0000-6546-a20d530d0000 pid=3411 execve guuid=4ae7fca0-1600-0000-6546-a20d550d0000 pid=3413 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=4ae7fca0-1600-0000-6546-a20d550d0000 pid=3413 clone guuid=0a9d72a1-1600-0000-6546-a20d590d0000 pid=3417 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=0a9d72a1-1600-0000-6546-a20d590d0000 pid=3417 execve guuid=2c9fb0a1-1600-0000-6546-a20d5c0d0000 pid=3420 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=2c9fb0a1-1600-0000-6546-a20d5c0d0000 pid=3420 execve guuid=ab6d16a7-1600-0000-6546-a20d720d0000 pid=3442 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=ab6d16a7-1600-0000-6546-a20d720d0000 pid=3442 execve guuid=50f797ad-1600-0000-6546-a20d8b0d0000 pid=3467 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=50f797ad-1600-0000-6546-a20d8b0d0000 pid=3467 execve guuid=06bad4ad-1600-0000-6546-a20d8d0d0000 pid=3469 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=06bad4ad-1600-0000-6546-a20d8d0d0000 pid=3469 clone guuid=e98e23af-1600-0000-6546-a20d930d0000 pid=3475 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=e98e23af-1600-0000-6546-a20d930d0000 pid=3475 execve guuid=4d1663af-1600-0000-6546-a20d950d0000 pid=3477 /usr/bin/wget net send-data guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=4d1663af-1600-0000-6546-a20d950d0000 pid=3477 execve guuid=fe2f19b2-1600-0000-6546-a20da10d0000 pid=3489 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=fe2f19b2-1600-0000-6546-a20da10d0000 pid=3489 execve guuid=72bd8db5-1600-0000-6546-a20dae0d0000 pid=3502 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=72bd8db5-1600-0000-6546-a20dae0d0000 pid=3502 execve guuid=8fa8c7b5-1600-0000-6546-a20daf0d0000 pid=3503 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=8fa8c7b5-1600-0000-6546-a20daf0d0000 pid=3503 clone guuid=8477ecb5-1600-0000-6546-a20db00d0000 pid=3504 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=8477ecb5-1600-0000-6546-a20db00d0000 pid=3504 execve guuid=d3af2ab6-1600-0000-6546-a20db10d0000 pid=3505 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=d3af2ab6-1600-0000-6546-a20db10d0000 pid=3505 execve guuid=fcc28fba-1600-0000-6546-a20dba0d0000 pid=3514 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=fcc28fba-1600-0000-6546-a20dba0d0000 pid=3514 execve guuid=7fd4ddc1-1600-0000-6546-a20dca0d0000 pid=3530 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=7fd4ddc1-1600-0000-6546-a20dca0d0000 pid=3530 execve guuid=02f0a1c2-1600-0000-6546-a20dcd0d0000 pid=3533 /tmp/morte.i686 net guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=02f0a1c2-1600-0000-6546-a20dcd0d0000 pid=3533 execve guuid=caeee0c2-1600-0000-6546-a20dd10d0000 pid=3537 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=caeee0c2-1600-0000-6546-a20dd10d0000 pid=3537 execve guuid=7fea2dc3-1600-0000-6546-a20dd40d0000 pid=3540 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=7fea2dc3-1600-0000-6546-a20dd40d0000 pid=3540 execve guuid=805c96c8-1600-0000-6546-a20ddc0d0000 pid=3548 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=805c96c8-1600-0000-6546-a20ddc0d0000 pid=3548 execve guuid=e2f9b1d1-1600-0000-6546-a20df20d0000 pid=3570 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=e2f9b1d1-1600-0000-6546-a20df20d0000 pid=3570 execve guuid=c0f9f3d1-1600-0000-6546-a20df40d0000 pid=3572 /tmp/morte.x86_64 mprotect-exec net guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=c0f9f3d1-1600-0000-6546-a20df40d0000 pid=3572 execve guuid=d6865bd2-1600-0000-6546-a20df80d0000 pid=3576 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=d6865bd2-1600-0000-6546-a20df80d0000 pid=3576 execve guuid=7e3a99d2-1600-0000-6546-a20dfa0d0000 pid=3578 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=7e3a99d2-1600-0000-6546-a20dfa0d0000 pid=3578 execve guuid=541e5bd7-1600-0000-6546-a20d100e0000 pid=3600 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=541e5bd7-1600-0000-6546-a20d100e0000 pid=3600 execve guuid=14d2e2de-1600-0000-6546-a20d270e0000 pid=3623 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=14d2e2de-1600-0000-6546-a20d270e0000 pid=3623 execve guuid=35cf2cdf-1600-0000-6546-a20d280e0000 pid=3624 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=35cf2cdf-1600-0000-6546-a20d280e0000 pid=3624 clone guuid=819ee3df-1600-0000-6546-a20d2a0e0000 pid=3626 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=819ee3df-1600-0000-6546-a20d2a0e0000 pid=3626 execve guuid=b85d8ee1-1600-0000-6546-a20d2c0e0000 pid=3628 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=b85d8ee1-1600-0000-6546-a20d2c0e0000 pid=3628 execve guuid=72a926e5-1600-0000-6546-a20d380e0000 pid=3640 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=72a926e5-1600-0000-6546-a20d380e0000 pid=3640 execve guuid=f692f6e9-1600-0000-6546-a20d470e0000 pid=3655 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=f692f6e9-1600-0000-6546-a20d470e0000 pid=3655 execve guuid=be4641ea-1600-0000-6546-a20d490e0000 pid=3657 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=be4641ea-1600-0000-6546-a20d490e0000 pid=3657 clone guuid=1cfcf0ea-1600-0000-6546-a20d4d0e0000 pid=3661 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=1cfcf0ea-1600-0000-6546-a20d4d0e0000 pid=3661 execve guuid=369a14ec-1600-0000-6546-a20d4e0e0000 pid=3662 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=369a14ec-1600-0000-6546-a20d4e0e0000 pid=3662 execve guuid=bab721f0-1600-0000-6546-a20d5e0e0000 pid=3678 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=bab721f0-1600-0000-6546-a20d5e0e0000 pid=3678 execve guuid=5613d8f4-1600-0000-6546-a20d710e0000 pid=3697 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=5613d8f4-1600-0000-6546-a20d710e0000 pid=3697 execve guuid=03d018f5-1600-0000-6546-a20d730e0000 pid=3699 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=03d018f5-1600-0000-6546-a20d730e0000 pid=3699 clone guuid=0b86dbf5-1600-0000-6546-a20d7b0e0000 pid=3707 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=0b86dbf5-1600-0000-6546-a20d7b0e0000 pid=3707 execve guuid=926522f6-1600-0000-6546-a20d7c0e0000 pid=3708 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=926522f6-1600-0000-6546-a20d7c0e0000 pid=3708 execve guuid=0285adfa-1600-0000-6546-a20d830e0000 pid=3715 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=0285adfa-1600-0000-6546-a20d830e0000 pid=3715 execve guuid=1e54c500-1700-0000-6546-a20d840e0000 pid=3716 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=1e54c500-1700-0000-6546-a20d840e0000 pid=3716 execve guuid=c4f21801-1700-0000-6546-a20d880e0000 pid=3720 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=c4f21801-1700-0000-6546-a20d880e0000 pid=3720 clone guuid=db3bac02-1700-0000-6546-a20d8c0e0000 pid=3724 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=db3bac02-1700-0000-6546-a20d8c0e0000 pid=3724 execve guuid=91454504-1700-0000-6546-a20d910e0000 pid=3729 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=91454504-1700-0000-6546-a20d910e0000 pid=3729 execve guuid=a0ec7909-1700-0000-6546-a20d9b0e0000 pid=3739 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=a0ec7909-1700-0000-6546-a20d9b0e0000 pid=3739 execve guuid=9e54f516-1700-0000-6546-a20dba0e0000 pid=3770 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=9e54f516-1700-0000-6546-a20dba0e0000 pid=3770 execve guuid=910acc17-1700-0000-6546-a20dbe0e0000 pid=3774 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=910acc17-1700-0000-6546-a20dbe0e0000 pid=3774 clone guuid=94228f18-1700-0000-6546-a20dc10e0000 pid=3777 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=94228f18-1700-0000-6546-a20dc10e0000 pid=3777 execve guuid=a9fb1319-1700-0000-6546-a20dc50e0000 pid=3781 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=a9fb1319-1700-0000-6546-a20dc50e0000 pid=3781 execve guuid=7202271d-1700-0000-6546-a20dd40e0000 pid=3796 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=7202271d-1700-0000-6546-a20dd40e0000 pid=3796 execve guuid=1e17dd22-1700-0000-6546-a20de90e0000 pid=3817 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=1e17dd22-1700-0000-6546-a20de90e0000 pid=3817 execve guuid=61b34023-1700-0000-6546-a20deb0e0000 pid=3819 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=61b34023-1700-0000-6546-a20deb0e0000 pid=3819 clone guuid=edd21024-1700-0000-6546-a20def0e0000 pid=3823 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=edd21024-1700-0000-6546-a20def0e0000 pid=3823 execve guuid=d3736724-1700-0000-6546-a20df10e0000 pid=3825 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=d3736724-1700-0000-6546-a20df10e0000 pid=3825 execve guuid=6f324d29-1700-0000-6546-a20d040f0000 pid=3844 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=6f324d29-1700-0000-6546-a20d040f0000 pid=3844 execve guuid=afce8930-1700-0000-6546-a20d140f0000 pid=3860 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=afce8930-1700-0000-6546-a20d140f0000 pid=3860 execve guuid=6a0a0031-1700-0000-6546-a20d170f0000 pid=3863 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=6a0a0031-1700-0000-6546-a20d170f0000 pid=3863 clone guuid=8b99ee31-1700-0000-6546-a20d1d0f0000 pid=3869 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=8b99ee31-1700-0000-6546-a20d1d0f0000 pid=3869 execve guuid=1fd86632-1700-0000-6546-a20d200f0000 pid=3872 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=1fd86632-1700-0000-6546-a20d200f0000 pid=3872 execve guuid=7b472d38-1700-0000-6546-a20d390f0000 pid=3897 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=7b472d38-1700-0000-6546-a20d390f0000 pid=3897 execve guuid=2d09e43e-1700-0000-6546-a20d520f0000 pid=3922 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=2d09e43e-1700-0000-6546-a20d520f0000 pid=3922 execve guuid=2a4c4f3f-1700-0000-6546-a20d540f0000 pid=3924 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=2a4c4f3f-1700-0000-6546-a20d540f0000 pid=3924 clone guuid=e8392640-1700-0000-6546-a20d590f0000 pid=3929 /usr/bin/rm delete-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=e8392640-1700-0000-6546-a20d590f0000 pid=3929 execve guuid=a5dd8540-1700-0000-6546-a20d5b0f0000 pid=3931 /usr/bin/wget net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=a5dd8540-1700-0000-6546-a20d5b0f0000 pid=3931 execve guuid=d7d43545-1700-0000-6546-a20d6e0f0000 pid=3950 /usr/bin/curl net send-data write-file guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=d7d43545-1700-0000-6546-a20d6e0f0000 pid=3950 execve guuid=36da104b-1700-0000-6546-a20d850f0000 pid=3973 /usr/bin/chmod guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=36da104b-1700-0000-6546-a20d850f0000 pid=3973 execve guuid=96c94a4b-1700-0000-6546-a20d870f0000 pid=3975 /usr/bin/bash guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=96c94a4b-1700-0000-6546-a20d870f0000 pid=3975 clone guuid=6901644b-1700-0000-6546-a20d880f0000 pid=3976 /usr/bin/rm guuid=87a7847b-1600-0000-6546-a20df10c0000 pid=3313->guuid=6901644b-1700-0000-6546-a20d880f0000 pid=3976 execve 6257db47-794e-52cb-98db-8da39c87047c 185.213.240.242:80 guuid=638c3081-1600-0000-6546-a20df90c0000 pid=3321->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=fb60b986-1600-0000-6546-a20d050d0000 pid=3333->6257db47-794e-52cb-98db-8da39c87047c send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b5a43893-1600-0000-6546-a20d220d0000 pid=3362->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=88a18c93-1600-0000-6546-a20d240d0000 pid=3364 /tmp/morte.x86 guuid=b5a43893-1600-0000-6546-a20d220d0000 pid=3362->guuid=88a18c93-1600-0000-6546-a20d240d0000 pid=3364 clone guuid=0c70ae93-1600-0000-6546-a20d260d0000 pid=3366 /tmp/morte.x86 write-config zombie guuid=88a18c93-1600-0000-6546-a20d240d0000 pid=3364->guuid=0c70ae93-1600-0000-6546-a20d260d0000 pid=3366 clone guuid=a35fa097-1600-0000-6546-a20d350d0000 pid=3381 /usr/bin/dash guuid=0c70ae93-1600-0000-6546-a20d260d0000 pid=3366->guuid=a35fa097-1600-0000-6546-a20d350d0000 pid=3381 execve guuid=f8c3519a-1600-0000-6546-a20d3d0d0000 pid=3389 /tmp/morte.x86 delete-file guuid=0c70ae93-1600-0000-6546-a20d260d0000 pid=3366->guuid=f8c3519a-1600-0000-6546-a20d3d0d0000 pid=3389 clone guuid=f335ef93-1600-0000-6546-a20d280d0000 pid=3368->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=73f8db97-1600-0000-6546-a20d360d0000 pid=3382 /usr/bin/cp guuid=a35fa097-1600-0000-6546-a20d350d0000 pid=3381->guuid=73f8db97-1600-0000-6546-a20d360d0000 pid=3382 execve guuid=eb3c9099-1600-0000-6546-a20d3c0d0000 pid=3388->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=2c9fb0a1-1600-0000-6546-a20d5c0d0000 pid=3420->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=ab6d16a7-1600-0000-6546-a20d720d0000 pid=3442->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=4d1663af-1600-0000-6546-a20d950d0000 pid=3477->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=fe2f19b2-1600-0000-6546-a20da10d0000 pid=3489->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=d3af2ab6-1600-0000-6546-a20db10d0000 pid=3505->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=fcc28fba-1600-0000-6546-a20dba0d0000 pid=3514->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=02f0a1c2-1600-0000-6546-a20dcd0d0000 pid=3533->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=75b6dac2-1600-0000-6546-a20dd00d0000 pid=3536 /tmp/morte.i686 guuid=02f0a1c2-1600-0000-6546-a20dcd0d0000 pid=3533->guuid=75b6dac2-1600-0000-6546-a20dd00d0000 pid=3536 clone guuid=ad3ffac2-1600-0000-6546-a20dd20d0000 pid=3538 /tmp/morte.i686 write-config zombie guuid=75b6dac2-1600-0000-6546-a20dd00d0000 pid=3536->guuid=ad3ffac2-1600-0000-6546-a20dd20d0000 pid=3538 clone guuid=6bea51c6-1600-0000-6546-a20dd80d0000 pid=3544 /usr/bin/dash guuid=ad3ffac2-1600-0000-6546-a20dd20d0000 pid=3538->guuid=6bea51c6-1600-0000-6546-a20dd80d0000 pid=3544 execve guuid=5a0db7c8-1600-0000-6546-a20dde0d0000 pid=3550 /tmp/morte.i686 delete-file guuid=ad3ffac2-1600-0000-6546-a20dd20d0000 pid=3538->guuid=5a0db7c8-1600-0000-6546-a20dde0d0000 pid=3550 clone guuid=3a9adece-1a00-0000-6546-a20dd8140000 pid=5336 /tmp/morte.i686 dns net send-data guuid=ad3ffac2-1600-0000-6546-a20dd20d0000 pid=3538->guuid=3a9adece-1a00-0000-6546-a20dd8140000 pid=5336 clone guuid=7fea2dc3-1600-0000-6546-a20dd40d0000 pid=3540->6257db47-794e-52cb-98db-8da39c87047c send: 147B guuid=cdf680c6-1600-0000-6546-a20dd90d0000 pid=3545 /usr/bin/cp guuid=6bea51c6-1600-0000-6546-a20dd80d0000 pid=3544->guuid=cdf680c6-1600-0000-6546-a20dd90d0000 pid=3545 execve guuid=805c96c8-1600-0000-6546-a20ddc0d0000 pid=3548->6257db47-794e-52cb-98db-8da39c87047c send: 96B guuid=c0f9f3d1-1600-0000-6546-a20df40d0000 pid=3572->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c74a54d2-1600-0000-6546-a20df70d0000 pid=3575 /tmp/morte.x86_64 zombie guuid=c0f9f3d1-1600-0000-6546-a20df40d0000 pid=3572->guuid=c74a54d2-1600-0000-6546-a20df70d0000 pid=3575 clone guuid=dcee9dd2-1600-0000-6546-a20dfb0d0000 pid=3579 /tmp/morte.x86_64 write-config zombie guuid=c74a54d2-1600-0000-6546-a20df70d0000 pid=3575->guuid=dcee9dd2-1600-0000-6546-a20dfb0d0000 pid=3579 clone guuid=7e3a99d2-1600-0000-6546-a20dfa0d0000 pid=3578->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=59d275d3-1600-0000-6546-a20d000e0000 pid=3584 /usr/bin/dash guuid=dcee9dd2-1600-0000-6546-a20dfb0d0000 pid=3579->guuid=59d275d3-1600-0000-6546-a20d000e0000 pid=3584 execve guuid=395c34d4-1600-0000-6546-a20d050e0000 pid=3589 /tmp/morte.x86_64 dns net send-data guuid=dcee9dd2-1600-0000-6546-a20dfb0d0000 pid=3579->guuid=395c34d4-1600-0000-6546-a20d050e0000 pid=3589 clone guuid=9a6098d3-1600-0000-6546-a20d020e0000 pid=3586 /usr/bin/cp guuid=59d275d3-1600-0000-6546-a20d000e0000 pid=3584->guuid=9a6098d3-1600-0000-6546-a20d020e0000 pid=3586 execve guuid=395c34d4-1600-0000-6546-a20d050e0000 pid=3589->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 1bbb4005-5fa7-5147-8924-030d465cc44a vipcncnetwork.com:12121 guuid=395c34d4-1600-0000-6546-a20d050e0000 pid=3589->1bbb4005-5fa7-5147-8924-030d465cc44a send: 27B guuid=541e5bd7-1600-0000-6546-a20d100e0000 pid=3600->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=b85d8ee1-1600-0000-6546-a20d2c0e0000 pid=3628->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=72a926e5-1600-0000-6546-a20d380e0000 pid=3640->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=369a14ec-1600-0000-6546-a20d4e0e0000 pid=3662->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=bab721f0-1600-0000-6546-a20d5e0e0000 pid=3678->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=926522f6-1600-0000-6546-a20d7c0e0000 pid=3708->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=0285adfa-1600-0000-6546-a20d830e0000 pid=3715->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=91454504-1700-0000-6546-a20d910e0000 pid=3729->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=a0ec7909-1700-0000-6546-a20d9b0e0000 pid=3739->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=a9fb1319-1700-0000-6546-a20dc50e0000 pid=3781->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=7202271d-1700-0000-6546-a20dd40e0000 pid=3796->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=d3736724-1700-0000-6546-a20df10e0000 pid=3825->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=6f324d29-1700-0000-6546-a20d040f0000 pid=3844->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=1fd86632-1700-0000-6546-a20d200f0000 pid=3872->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=7b472d38-1700-0000-6546-a20d390f0000 pid=3897->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=a5dd8540-1700-0000-6546-a20d5b0f0000 pid=3931->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=d7d43545-1700-0000-6546-a20d6e0f0000 pid=3950->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=3a9adece-1a00-0000-6546-a20dd8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=3a9adece-1a00-0000-6546-a20dd8140000 pid=5336->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-22 01:52:00 UTC
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Unexpected DNS network traffic destination
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 80a38307191ee64af780665afa1ea0ebfc7355d66ce420f8469cf63f0eaa17d3

(this sample)

  
Delivery method
Distributed via web download

Comments