MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8dee740521e955f36594a3a5fc3f5e8f61bc4335698dcb226321719038eca687. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 8dee740521e955f36594a3a5fc3f5e8f61bc4335698dcb226321719038eca687
SHA3-384 hash: c5189d372bead535b2eec826f7fff8c3997d87da758a30b82231600856128f06780853eb0b160e89a0ba336571be7b7d
SHA1 hash: 24a11ecac03d45d3b4c002da1f7ff03ebd8810a7
MD5 hash: 3c791ab3a71b481873489cfb5fb9d09e
humanhash: london-uncle-oranges-green
File name:1.sh
Download: download sample
Signature Mirai
File size:3'374 bytes
First seen:2025-06-25 21:58:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:iwFpwOHwHNwevwUbwYbwvzv1wRhwIfLwNTJw2vwiTwzFwNxNBgJsweTk:iydE5/nS6zLkxfMUzBgJsTk
TLSH T1516187F6134246739DE68EE335A88404739580D798CE5FB59BEC34B60D8CEC9BC46692
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.117.166/00101010101001/morte.x86n/an/an/a
http://196.251.117.166/00101010101001/morte.mipsn/an/an/a
http://196.251.117.166/00101010101001/morte.arcn/an/an/a
http://196.251.117.166/00101010101001/morte.i468n/an/an/a
http://196.251.117.166/00101010101001/morte.i686n/an/an/a
http://196.251.117.166/00101010101001/morte.x86_64n/an/an/a
http://196.251.117.166/00101010101001/morte.mpsln/an/an/a
http://196.251.117.166/00101010101001/morte.armn/an/an/a
http://196.251.117.166/00101010101001/morte.arm5n/an/an/a
http://196.251.117.166/00101010101001/morte.arm6n/an/an/a
http://196.251.117.166/00101010101001/morte.arm7n/an/an/a
http://196.251.117.166/00101010101001/morte.ppcn/an/an/a
http://196.251.117.166/00101010101001/morte.spcn/an/an/a
http://196.251.117.166/00101010101001/morte.m68kn/an/an/a
http://196.251.117.166/00101010101001/morte.sh4n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
125
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.9%
Tags:
downloader ransomware agent
Status:
terminated
Behavior Graph:
%3 guuid=090c4c81-1900-0000-7559-547dad090000 pid=2477 /usr/bin/sudo guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483 /tmp/sample.bin guuid=090c4c81-1900-0000-7559-547dad090000 pid=2477->guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483 execve guuid=1bd47184-1900-0000-7559-547db5090000 pid=2485 /usr/bin/cp guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1bd47184-1900-0000-7559-547db5090000 pid=2485 execve guuid=ff8c6086-1900-0000-7559-547dba090000 pid=2490 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=ff8c6086-1900-0000-7559-547dba090000 pid=2490 execve guuid=87cd068d-1900-0000-7559-547dc3090000 pid=2499 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=87cd068d-1900-0000-7559-547dc3090000 pid=2499 execve guuid=05ce6898-1900-0000-7559-547dde090000 pid=2526 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=05ce6898-1900-0000-7559-547dde090000 pid=2526 execve guuid=85f0e098-1900-0000-7559-547de1090000 pid=2529 /tmp/morte.x86 net guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=85f0e098-1900-0000-7559-547de1090000 pid=2529 execve guuid=1f9c0c11-1a00-0000-7559-547df90a0000 pid=2809 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1f9c0c11-1a00-0000-7559-547df90a0000 pid=2809 execve guuid=5c626d11-1a00-0000-7559-547dfa0a0000 pid=2810 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=5c626d11-1a00-0000-7559-547dfa0a0000 pid=2810 execve guuid=e394f81c-1a00-0000-7559-547d100b0000 pid=2832 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=e394f81c-1a00-0000-7559-547d100b0000 pid=2832 execve guuid=2144c125-1a00-0000-7559-547d210b0000 pid=2849 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=2144c125-1a00-0000-7559-547d210b0000 pid=2849 execve guuid=b59c4126-1a00-0000-7559-547d220b0000 pid=2850 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=b59c4126-1a00-0000-7559-547d220b0000 pid=2850 clone guuid=6fea7527-1a00-0000-7559-547d270b0000 pid=2855 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=6fea7527-1a00-0000-7559-547d270b0000 pid=2855 execve guuid=af08c72f-1a00-0000-7559-547d400b0000 pid=2880 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=af08c72f-1a00-0000-7559-547d400b0000 pid=2880 execve guuid=b4faea3b-1a00-0000-7559-547d600b0000 pid=2912 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=b4faea3b-1a00-0000-7559-547d600b0000 pid=2912 execve guuid=0c004e47-1a00-0000-7559-547d750b0000 pid=2933 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=0c004e47-1a00-0000-7559-547d750b0000 pid=2933 execve guuid=413daf47-1a00-0000-7559-547d760b0000 pid=2934 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=413daf47-1a00-0000-7559-547d760b0000 pid=2934 clone guuid=6e5ad348-1a00-0000-7559-547d780b0000 pid=2936 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=6e5ad348-1a00-0000-7559-547d780b0000 pid=2936 execve guuid=6e825349-1a00-0000-7559-547d790b0000 pid=2937 /usr/bin/wget net send-data guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=6e825349-1a00-0000-7559-547d790b0000 pid=2937 execve guuid=10c05a4f-1a00-0000-7559-547d870b0000 pid=2951 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=10c05a4f-1a00-0000-7559-547d870b0000 pid=2951 execve guuid=c0502256-1a00-0000-7559-547d8f0b0000 pid=2959 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=c0502256-1a00-0000-7559-547d8f0b0000 pid=2959 execve guuid=f4d08456-1a00-0000-7559-547d900b0000 pid=2960 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=f4d08456-1a00-0000-7559-547d900b0000 pid=2960 clone guuid=3c5fd256-1a00-0000-7559-547d910b0000 pid=2961 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=3c5fd256-1a00-0000-7559-547d910b0000 pid=2961 execve guuid=a4782057-1a00-0000-7559-547d920b0000 pid=2962 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=a4782057-1a00-0000-7559-547d920b0000 pid=2962 execve guuid=8f66315c-1a00-0000-7559-547d930b0000 pid=2963 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=8f66315c-1a00-0000-7559-547d930b0000 pid=2963 execve guuid=1ec33269-1a00-0000-7559-547d940b0000 pid=2964 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1ec33269-1a00-0000-7559-547d940b0000 pid=2964 execve guuid=2a54b369-1a00-0000-7559-547d960b0000 pid=2966 /tmp/morte.i686 net guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=2a54b369-1a00-0000-7559-547d960b0000 pid=2966 execve guuid=8b0e0be2-1a00-0000-7559-547d6d0c0000 pid=3181 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=8b0e0be2-1a00-0000-7559-547d6d0c0000 pid=3181 execve guuid=33869fe2-1a00-0000-7559-547d6e0c0000 pid=3182 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=33869fe2-1a00-0000-7559-547d6e0c0000 pid=3182 execve guuid=b3f118e8-1a00-0000-7559-547d740c0000 pid=3188 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=b3f118e8-1a00-0000-7559-547d740c0000 pid=3188 execve guuid=b03c55f3-1a00-0000-7559-547d850c0000 pid=3205 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=b03c55f3-1a00-0000-7559-547d850c0000 pid=3205 execve guuid=ce09cef3-1a00-0000-7559-547d860c0000 pid=3206 /tmp/morte.x86_64 mprotect-exec net guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=ce09cef3-1a00-0000-7559-547d860c0000 pid=3206 execve guuid=8123ca6b-1b00-0000-7559-547d0a0d0000 pid=3338 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=8123ca6b-1b00-0000-7559-547d0a0d0000 pid=3338 execve guuid=57bb686c-1b00-0000-7559-547d0c0d0000 pid=3340 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=57bb686c-1b00-0000-7559-547d0c0d0000 pid=3340 execve guuid=a66a7772-1b00-0000-7559-547d190d0000 pid=3353 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=a66a7772-1b00-0000-7559-547d190d0000 pid=3353 execve guuid=90d5357e-1b00-0000-7559-547d200d0000 pid=3360 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=90d5357e-1b00-0000-7559-547d200d0000 pid=3360 execve guuid=7219b57e-1b00-0000-7559-547d210d0000 pid=3361 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=7219b57e-1b00-0000-7559-547d210d0000 pid=3361 clone guuid=b7a09a7f-1b00-0000-7559-547d230d0000 pid=3363 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=b7a09a7f-1b00-0000-7559-547d230d0000 pid=3363 execve guuid=33401a8a-1b00-0000-7559-547d2e0d0000 pid=3374 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=33401a8a-1b00-0000-7559-547d2e0d0000 pid=3374 execve guuid=cdc4c28e-1b00-0000-7559-547d370d0000 pid=3383 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=cdc4c28e-1b00-0000-7559-547d370d0000 pid=3383 execve guuid=9fd8f993-1b00-0000-7559-547d400d0000 pid=3392 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=9fd8f993-1b00-0000-7559-547d400d0000 pid=3392 execve guuid=73565e94-1b00-0000-7559-547d420d0000 pid=3394 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=73565e94-1b00-0000-7559-547d420d0000 pid=3394 clone guuid=4668bd95-1b00-0000-7559-547d470d0000 pid=3399 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=4668bd95-1b00-0000-7559-547d470d0000 pid=3399 execve guuid=07249596-1b00-0000-7559-547d4b0d0000 pid=3403 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=07249596-1b00-0000-7559-547d4b0d0000 pid=3403 execve guuid=9e04d19a-1b00-0000-7559-547d540d0000 pid=3412 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=9e04d19a-1b00-0000-7559-547d540d0000 pid=3412 execve guuid=d483bfa2-1b00-0000-7559-547d680d0000 pid=3432 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=d483bfa2-1b00-0000-7559-547d680d0000 pid=3432 execve guuid=bb6139a3-1b00-0000-7559-547d6a0d0000 pid=3434 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=bb6139a3-1b00-0000-7559-547d6a0d0000 pid=3434 clone guuid=1efe6ea4-1b00-0000-7559-547d6d0d0000 pid=3437 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1efe6ea4-1b00-0000-7559-547d6d0d0000 pid=3437 execve guuid=7b83fda4-1b00-0000-7559-547d6e0d0000 pid=3438 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=7b83fda4-1b00-0000-7559-547d6e0d0000 pid=3438 execve guuid=9c0b2aa9-1b00-0000-7559-547d7c0d0000 pid=3452 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=9c0b2aa9-1b00-0000-7559-547d7c0d0000 pid=3452 execve guuid=1f64a1b0-1b00-0000-7559-547d910d0000 pid=3473 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1f64a1b0-1b00-0000-7559-547d910d0000 pid=3473 execve guuid=573318b1-1b00-0000-7559-547d930d0000 pid=3475 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=573318b1-1b00-0000-7559-547d930d0000 pid=3475 clone guuid=82506eb2-1b00-0000-7559-547d970d0000 pid=3479 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=82506eb2-1b00-0000-7559-547d970d0000 pid=3479 execve guuid=e185b8b2-1b00-0000-7559-547d990d0000 pid=3481 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=e185b8b2-1b00-0000-7559-547d990d0000 pid=3481 execve guuid=08f743b9-1b00-0000-7559-547dac0d0000 pid=3500 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=08f743b9-1b00-0000-7559-547dac0d0000 pid=3500 execve guuid=f5f714c2-1b00-0000-7559-547dc40d0000 pid=3524 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=f5f714c2-1b00-0000-7559-547dc40d0000 pid=3524 execve guuid=2032f1c2-1b00-0000-7559-547dc70d0000 pid=3527 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=2032f1c2-1b00-0000-7559-547dc70d0000 pid=3527 clone guuid=37822fc6-1b00-0000-7559-547dd10d0000 pid=3537 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=37822fc6-1b00-0000-7559-547dd10d0000 pid=3537 execve guuid=a38c06c7-1b00-0000-7559-547dd40d0000 pid=3540 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=a38c06c7-1b00-0000-7559-547dd40d0000 pid=3540 execve guuid=7b0e45cf-1b00-0000-7559-547ddf0d0000 pid=3551 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=7b0e45cf-1b00-0000-7559-547ddf0d0000 pid=3551 execve guuid=4740c0d9-1b00-0000-7559-547de60d0000 pid=3558 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=4740c0d9-1b00-0000-7559-547de60d0000 pid=3558 execve guuid=9ae742da-1b00-0000-7559-547de80d0000 pid=3560 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=9ae742da-1b00-0000-7559-547de80d0000 pid=3560 clone guuid=64f1b1db-1b00-0000-7559-547ded0d0000 pid=3565 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=64f1b1db-1b00-0000-7559-547ded0d0000 pid=3565 execve guuid=45bcdedc-1b00-0000-7559-547df00d0000 pid=3568 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=45bcdedc-1b00-0000-7559-547df00d0000 pid=3568 execve guuid=8acae3e6-1b00-0000-7559-547d080e0000 pid=3592 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=8acae3e6-1b00-0000-7559-547d080e0000 pid=3592 execve guuid=e6fcd5ed-1b00-0000-7559-547d170e0000 pid=3607 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=e6fcd5ed-1b00-0000-7559-547d170e0000 pid=3607 execve guuid=d95137ee-1b00-0000-7559-547d190e0000 pid=3609 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=d95137ee-1b00-0000-7559-547d190e0000 pid=3609 clone guuid=d5bd53ef-1b00-0000-7559-547d1d0e0000 pid=3613 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=d5bd53ef-1b00-0000-7559-547d1d0e0000 pid=3613 execve guuid=a5f2b4ef-1b00-0000-7559-547d1f0e0000 pid=3615 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=a5f2b4ef-1b00-0000-7559-547d1f0e0000 pid=3615 execve guuid=1e778bf4-1b00-0000-7559-547d2a0e0000 pid=3626 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=1e778bf4-1b00-0000-7559-547d2a0e0000 pid=3626 execve guuid=8232a8fd-1b00-0000-7559-547d410e0000 pid=3649 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=8232a8fd-1b00-0000-7559-547d410e0000 pid=3649 execve guuid=93a0e8fd-1b00-0000-7559-547d430e0000 pid=3651 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=93a0e8fd-1b00-0000-7559-547d430e0000 pid=3651 clone guuid=3ac686fe-1b00-0000-7559-547d450e0000 pid=3653 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=3ac686fe-1b00-0000-7559-547d450e0000 pid=3653 execve guuid=2291fd01-1c00-0000-7559-547d460e0000 pid=3654 /usr/bin/wget net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=2291fd01-1c00-0000-7559-547d460e0000 pid=3654 execve guuid=beeade08-1c00-0000-7559-547d540e0000 pid=3668 /usr/bin/curl net send-data write-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=beeade08-1c00-0000-7559-547d540e0000 pid=3668 execve guuid=97af0413-1c00-0000-7559-547d6f0e0000 pid=3695 /usr/bin/chmod guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=97af0413-1c00-0000-7559-547d6f0e0000 pid=3695 execve guuid=731c6613-1c00-0000-7559-547d710e0000 pid=3697 /usr/bin/bash guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=731c6613-1c00-0000-7559-547d710e0000 pid=3697 clone guuid=ec733814-1c00-0000-7559-547d780e0000 pid=3704 /usr/bin/rm delete-file guuid=a44ce083-1900-0000-7559-547db3090000 pid=2483->guuid=ec733814-1c00-0000-7559-547d780e0000 pid=3704 execve 63d8cde0-004c-50d3-81b4-71effda9a30f 196.251.117.166:80 guuid=ff8c6086-1900-0000-7559-547dba090000 pid=2490->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=87cd068d-1900-0000-7559-547dc3090000 pid=2499->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=85f0e098-1900-0000-7559-547de1090000 pid=2529->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=85f0e098-1900-0000-7559-547de1090000 pid=2529->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=5c626d11-1a00-0000-7559-547dfa0a0000 pid=2810->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=e394f81c-1a00-0000-7559-547d100b0000 pid=2832->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=af08c72f-1a00-0000-7559-547d400b0000 pid=2880->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=b4faea3b-1a00-0000-7559-547d600b0000 pid=2912->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B guuid=6e825349-1a00-0000-7559-547d790b0000 pid=2937->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=10c05a4f-1a00-0000-7559-547d870b0000 pid=2951->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=a4782057-1a00-0000-7559-547d920b0000 pid=2962->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=8f66315c-1a00-0000-7559-547d930b0000 pid=2963->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=2a54b369-1a00-0000-7559-547d960b0000 pid=2966->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2a54b369-1a00-0000-7559-547d960b0000 pid=2966->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=33869fe2-1a00-0000-7559-547d6e0c0000 pid=3182->63d8cde0-004c-50d3-81b4-71effda9a30f send: 157B guuid=b3f118e8-1a00-0000-7559-547d740c0000 pid=3188->63d8cde0-004c-50d3-81b4-71effda9a30f send: 106B guuid=ce09cef3-1a00-0000-7559-547d860c0000 pid=3206->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce09cef3-1a00-0000-7559-547d860c0000 pid=3206->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=57bb686c-1b00-0000-7559-547d0c0d0000 pid=3340->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=a66a7772-1b00-0000-7559-547d190d0000 pid=3353->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=33401a8a-1b00-0000-7559-547d2e0d0000 pid=3374->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=cdc4c28e-1b00-0000-7559-547d370d0000 pid=3383->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B guuid=07249596-1b00-0000-7559-547d4b0d0000 pid=3403->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=9e04d19a-1b00-0000-7559-547d540d0000 pid=3412->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=7b83fda4-1b00-0000-7559-547d6e0d0000 pid=3438->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=9c0b2aa9-1b00-0000-7559-547d7c0d0000 pid=3452->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=e185b8b2-1b00-0000-7559-547d990d0000 pid=3481->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=08f743b9-1b00-0000-7559-547dac0d0000 pid=3500->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=a38c06c7-1b00-0000-7559-547dd40d0000 pid=3540->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=7b0e45cf-1b00-0000-7559-547ddf0d0000 pid=3551->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B guuid=45bcdedc-1b00-0000-7559-547df00d0000 pid=3568->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=8acae3e6-1b00-0000-7559-547d080e0000 pid=3592->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B guuid=a5f2b4ef-1b00-0000-7559-547d1f0e0000 pid=3615->63d8cde0-004c-50d3-81b4-71effda9a30f send: 155B guuid=1e778bf4-1b00-0000-7559-547d2a0e0000 pid=3626->63d8cde0-004c-50d3-81b4-71effda9a30f send: 104B guuid=2291fd01-1c00-0000-7559-547d460e0000 pid=3654->63d8cde0-004c-50d3-81b4-71effda9a30f send: 154B guuid=beeade08-1c00-0000-7559-547d540e0000 pid=3668->63d8cde0-004c-50d3-81b4-71effda9a30f send: 103B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-06-25 21:59:44 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8dee740521e955f36594a3a5fc3f5e8f61bc4335698dcb226321719038eca687

(this sample)

  
Delivery method
Distributed via web download

Comments