MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9450cdae39985a317a0c04828544aa0a6db9df22b7ba50339f1b8b8d459c1e36. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 9450cdae39985a317a0c04828544aa0a6db9df22b7ba50339f1b8b8d459c1e36
SHA3-384 hash: 9b686ae8bd6392d49baaa5a577547e4b33c602ad1f36dc6e7f5f9574e6d2d0e96177f847a37069d27c5b9fed5a22ab33
SHA1 hash: 4596bd845841a7e244fabc7a6b9fed8489751f55
MD5 hash: 7e533afbbeb6273d49d79d4d2e04890b
humanhash: july-monkey-five-kitten
File name:1.sh
Download: download sample
Signature Mirai
File size:3'314 bytes
First seen:2025-08-06 18:32:56 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItfZs3bhjkTlfjmsnTwbGgJP6fnLmdNIpKksPMEhhzsAvcGgJswopk:iK1QRrTwb1yfLSJJDIAvBgJs3k
TLSH T15D6150FE23410A37ADB6C9D276A8C408628840DB95CE3F765BDC78B58E8CEC93D41A51
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.84.111/00101010101001/morte.x86ff31263c5f431ce64726b938090561d49344c0dddd523a12d43615dafa6d10ef Miraimirai opendir
http://87.121.84.111/00101010101001/morte.mipsa29ac2abb460b0f0b489d4f0c1b5b604969edb59ebf3179402179ede261453b6 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.arcabf476a15447dfaa756bf9a81593ce45d34e2efa0986d2ffdc0dc7266c292100 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.i468n/an/amirai opendir
http://87.121.84.111/00101010101001/morte.i6866299b8d0b66b4ba01e7ab97a794180cd9390031c90bde586a71cb08346b3f1fa Miraimirai opendir
http://87.121.84.111/00101010101001/morte.x86_647136f5de0d01efb8522d5b530824833f675f2938b5fd51028b4614837ad9c93b Miraimirai opendir
http://87.121.84.111/00101010101001/morte.mpsl1fa1025a1c601432faa0a4e1dd8358d44652f7338d31f0fc9719a510cc879857 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.arm9543b2d80ee42747aa0be1686d8cbe076f65123c1e30781009ce78c4c7f33280 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.arm5c2e54e153f1ef1e3bfb617e0f54aff2611cc2342fa73f26ddfcaf242669f42f1 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.arm6ad5fa6caa61325d3b35f7db276d34b58504e82a37991bfeb9f5f4ea5e1571e0d Miraimirai opendir
http://87.121.84.111/00101010101001/morte.arm72cd0908c116423a9b3748f4dd01f238fe186eab227f5020fe4bc5a857165c02a Miraimirai opendir
http://87.121.84.111/00101010101001/morte.ppc8aa8dce39c5ac5fdadc044d6c22f68b35b64db0165e108234999a155b7dbb235 Miraimirai opendir
http://87.121.84.111/00101010101001/morte.spc3c0cddf94c82b3cb8cca81bf23c40c5074ad3c3fe77725745563291c62c23dca Miraimirai opendir
http://87.121.84.111/00101010101001/morte.m68k5a443f67e328a97bcf3c910708401937fb5724f9ab223766e04b913865bda38f Miraimirai opendir
http://87.121.84.111/00101010101001/morte.sh4bb80954cb850e3bd69a14a8f81f1835b2245e1617732b2189321fe417802c7e8 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=897f5789-1600-0000-0f85-07c2b60b0000 pid=2998 /usr/bin/sudo guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006 /tmp/sample.bin guuid=897f5789-1600-0000-0f85-07c2b60b0000 pid=2998->guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006 execve guuid=307b2e8c-1600-0000-0f85-07c2c10b0000 pid=3009 /usr/bin/cp guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=307b2e8c-1600-0000-0f85-07c2c10b0000 pid=3009 execve guuid=59261b90-1600-0000-0f85-07c2cc0b0000 pid=3020 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=59261b90-1600-0000-0f85-07c2cc0b0000 pid=3020 execve guuid=b1dbf096-1600-0000-0f85-07c2e60b0000 pid=3046 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b1dbf096-1600-0000-0f85-07c2e60b0000 pid=3046 execve guuid=056315a2-1600-0000-0f85-07c2070c0000 pid=3079 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=056315a2-1600-0000-0f85-07c2070c0000 pid=3079 execve guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081 /tmp/morte.x86 net guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081 execve guuid=ee84edce-1700-0000-0f85-07c2df0d0000 pid=3551 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=ee84edce-1700-0000-0f85-07c2df0d0000 pid=3551 execve guuid=710d76cf-1700-0000-0f85-07c2e10d0000 pid=3553 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=710d76cf-1700-0000-0f85-07c2e10d0000 pid=3553 execve guuid=b3ecced7-1700-0000-0f85-07c2f20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b3ecced7-1700-0000-0f85-07c2f20d0000 pid=3570 execve guuid=4ac785df-1700-0000-0f85-07c2060e0000 pid=3590 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=4ac785df-1700-0000-0f85-07c2060e0000 pid=3590 execve guuid=3f80e9df-1700-0000-0f85-07c2070e0000 pid=3591 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=3f80e9df-1700-0000-0f85-07c2070e0000 pid=3591 clone guuid=a491bee0-1700-0000-0f85-07c20b0e0000 pid=3595 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=a491bee0-1700-0000-0f85-07c20b0e0000 pid=3595 execve guuid=6e5e70e5-1700-0000-0f85-07c20c0e0000 pid=3596 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=6e5e70e5-1700-0000-0f85-07c20c0e0000 pid=3596 execve guuid=61bd83ed-1700-0000-0f85-07c2170e0000 pid=3607 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=61bd83ed-1700-0000-0f85-07c2170e0000 pid=3607 execve guuid=c563bef7-1700-0000-0f85-07c22c0e0000 pid=3628 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=c563bef7-1700-0000-0f85-07c22c0e0000 pid=3628 execve guuid=0e5c32f8-1700-0000-0f85-07c22d0e0000 pid=3629 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=0e5c32f8-1700-0000-0f85-07c22d0e0000 pid=3629 clone guuid=965e42fa-1700-0000-0f85-07c2360e0000 pid=3638 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=965e42fa-1700-0000-0f85-07c2360e0000 pid=3638 execve guuid=91fe98fa-1700-0000-0f85-07c2380e0000 pid=3640 /usr/bin/wget net send-data guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=91fe98fa-1700-0000-0f85-07c2380e0000 pid=3640 execve guuid=860201fe-1700-0000-0f85-07c23f0e0000 pid=3647 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=860201fe-1700-0000-0f85-07c23f0e0000 pid=3647 execve guuid=a8cdc703-1800-0000-0f85-07c2510e0000 pid=3665 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=a8cdc703-1800-0000-0f85-07c2510e0000 pid=3665 execve guuid=eee13504-1800-0000-0f85-07c2550e0000 pid=3669 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=eee13504-1800-0000-0f85-07c2550e0000 pid=3669 clone guuid=29448904-1800-0000-0f85-07c2560e0000 pid=3670 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=29448904-1800-0000-0f85-07c2560e0000 pid=3670 execve guuid=a3b8eb04-1800-0000-0f85-07c2580e0000 pid=3672 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=a3b8eb04-1800-0000-0f85-07c2580e0000 pid=3672 execve guuid=b098260a-1800-0000-0f85-07c25e0e0000 pid=3678 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b098260a-1800-0000-0f85-07c25e0e0000 pid=3678 execve guuid=dc5f4a11-1800-0000-0f85-07c2670e0000 pid=3687 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=dc5f4a11-1800-0000-0f85-07c2670e0000 pid=3687 execve guuid=275db511-1800-0000-0f85-07c2680e0000 pid=3688 /tmp/morte.i686 net guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=275db511-1800-0000-0f85-07c2680e0000 pid=3688 execve guuid=ce21c689-1800-0000-0f85-07c27d0f0000 pid=3965 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=ce21c689-1800-0000-0f85-07c27d0f0000 pid=3965 execve guuid=71e1868a-1800-0000-0f85-07c2810f0000 pid=3969 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=71e1868a-1800-0000-0f85-07c2810f0000 pid=3969 execve guuid=cc8f5491-1800-0000-0f85-07c2900f0000 pid=3984 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=cc8f5491-1800-0000-0f85-07c2900f0000 pid=3984 execve guuid=c91d9698-1800-0000-0f85-07c2a30f0000 pid=4003 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=c91d9698-1800-0000-0f85-07c2a30f0000 pid=4003 execve guuid=c1e1e898-1800-0000-0f85-07c2a50f0000 pid=4005 /tmp/morte.x86_64 mprotect-exec net guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=c1e1e898-1800-0000-0f85-07c2a50f0000 pid=4005 execve guuid=1774e210-1900-0000-0f85-07c2c7100000 pid=4295 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=1774e210-1900-0000-0f85-07c2c7100000 pid=4295 execve guuid=2d916f11-1900-0000-0f85-07c2c9100000 pid=4297 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=2d916f11-1900-0000-0f85-07c2c9100000 pid=4297 execve guuid=24ed5817-1900-0000-0f85-07c2d4100000 pid=4308 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=24ed5817-1900-0000-0f85-07c2d4100000 pid=4308 execve guuid=66b0cc1f-1900-0000-0f85-07c2ec100000 pid=4332 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=66b0cc1f-1900-0000-0f85-07c2ec100000 pid=4332 execve guuid=89e93020-1900-0000-0f85-07c2ed100000 pid=4333 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=89e93020-1900-0000-0f85-07c2ed100000 pid=4333 clone guuid=cf582621-1900-0000-0f85-07c2f4100000 pid=4340 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=cf582621-1900-0000-0f85-07c2f4100000 pid=4340 execve guuid=06b79f26-1900-0000-0f85-07c2ff100000 pid=4351 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=06b79f26-1900-0000-0f85-07c2ff100000 pid=4351 execve guuid=34e79e2c-1900-0000-0f85-07c20f110000 pid=4367 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=34e79e2c-1900-0000-0f85-07c20f110000 pid=4367 execve guuid=8fdd3f34-1900-0000-0f85-07c22e110000 pid=4398 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=8fdd3f34-1900-0000-0f85-07c22e110000 pid=4398 execve guuid=15b99734-1900-0000-0f85-07c22f110000 pid=4399 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=15b99734-1900-0000-0f85-07c22f110000 pid=4399 clone guuid=f13ae436-1900-0000-0f85-07c239110000 pid=4409 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=f13ae436-1900-0000-0f85-07c239110000 pid=4409 execve guuid=b3265237-1900-0000-0f85-07c23b110000 pid=4411 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b3265237-1900-0000-0f85-07c23b110000 pid=4411 execve guuid=1a126a3b-1900-0000-0f85-07c24d110000 pid=4429 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=1a126a3b-1900-0000-0f85-07c24d110000 pid=4429 execve guuid=37130d42-1900-0000-0f85-07c266110000 pid=4454 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=37130d42-1900-0000-0f85-07c266110000 pid=4454 execve guuid=31d45442-1900-0000-0f85-07c268110000 pid=4456 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=31d45442-1900-0000-0f85-07c268110000 pid=4456 clone guuid=a569ed42-1900-0000-0f85-07c26c110000 pid=4460 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=a569ed42-1900-0000-0f85-07c26c110000 pid=4460 execve guuid=c6aa4c43-1900-0000-0f85-07c270110000 pid=4464 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=c6aa4c43-1900-0000-0f85-07c270110000 pid=4464 execve guuid=13de2648-1900-0000-0f85-07c282110000 pid=4482 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=13de2648-1900-0000-0f85-07c282110000 pid=4482 execve guuid=2b3ea74f-1900-0000-0f85-07c29b110000 pid=4507 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=2b3ea74f-1900-0000-0f85-07c29b110000 pid=4507 execve guuid=c9411350-1900-0000-0f85-07c29f110000 pid=4511 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=c9411350-1900-0000-0f85-07c29f110000 pid=4511 clone guuid=b1810151-1900-0000-0f85-07c2a2110000 pid=4514 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b1810151-1900-0000-0f85-07c2a2110000 pid=4514 execve guuid=cfd32853-1900-0000-0f85-07c2a8110000 pid=4520 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=cfd32853-1900-0000-0f85-07c2a8110000 pid=4520 execve guuid=d1d3115c-1900-0000-0f85-07c2be110000 pid=4542 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=d1d3115c-1900-0000-0f85-07c2be110000 pid=4542 execve guuid=f8266762-1900-0000-0f85-07c2d1110000 pid=4561 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=f8266762-1900-0000-0f85-07c2d1110000 pid=4561 execve guuid=afaaa662-1900-0000-0f85-07c2d2110000 pid=4562 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=afaaa662-1900-0000-0f85-07c2d2110000 pid=4562 clone guuid=ac728f63-1900-0000-0f85-07c2d7110000 pid=4567 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=ac728f63-1900-0000-0f85-07c2d7110000 pid=4567 execve guuid=3c434d69-1900-0000-0f85-07c2ee110000 pid=4590 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=3c434d69-1900-0000-0f85-07c2ee110000 pid=4590 execve guuid=e5584f6e-1900-0000-0f85-07c2ff110000 pid=4607 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=e5584f6e-1900-0000-0f85-07c2ff110000 pid=4607 execve guuid=f5be8874-1900-0000-0f85-07c215120000 pid=4629 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=f5be8874-1900-0000-0f85-07c215120000 pid=4629 execve guuid=5ef4c874-1900-0000-0f85-07c219120000 pid=4633 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=5ef4c874-1900-0000-0f85-07c219120000 pid=4633 clone guuid=f8594a75-1900-0000-0f85-07c21e120000 pid=4638 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=f8594a75-1900-0000-0f85-07c21e120000 pid=4638 execve guuid=2dec8678-1900-0000-0f85-07c22d120000 pid=4653 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=2dec8678-1900-0000-0f85-07c22d120000 pid=4653 execve guuid=e2dea57d-1900-0000-0f85-07c240120000 pid=4672 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=e2dea57d-1900-0000-0f85-07c240120000 pid=4672 execve guuid=2c41e3a1-1900-0000-0f85-07c283120000 pid=4739 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=2c41e3a1-1900-0000-0f85-07c283120000 pid=4739 execve guuid=811142a2-1900-0000-0f85-07c287120000 pid=4743 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=811142a2-1900-0000-0f85-07c287120000 pid=4743 clone guuid=893e0ba3-1900-0000-0f85-07c28c120000 pid=4748 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=893e0ba3-1900-0000-0f85-07c28c120000 pid=4748 execve guuid=460767a3-1900-0000-0f85-07c28e120000 pid=4750 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=460767a3-1900-0000-0f85-07c28e120000 pid=4750 execve guuid=4490caaa-1900-0000-0f85-07c2a7120000 pid=4775 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=4490caaa-1900-0000-0f85-07c2a7120000 pid=4775 execve guuid=b402d0b1-1900-0000-0f85-07c2bd120000 pid=4797 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=b402d0b1-1900-0000-0f85-07c2bd120000 pid=4797 execve guuid=265755b2-1900-0000-0f85-07c2bf120000 pid=4799 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=265755b2-1900-0000-0f85-07c2bf120000 pid=4799 clone guuid=8eeb7cb3-1900-0000-0f85-07c2c3120000 pid=4803 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=8eeb7cb3-1900-0000-0f85-07c2c3120000 pid=4803 execve guuid=3eececb3-1900-0000-0f85-07c2c4120000 pid=4804 /usr/bin/wget net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=3eececb3-1900-0000-0f85-07c2c4120000 pid=4804 execve guuid=a80659b9-1900-0000-0f85-07c2d5120000 pid=4821 /usr/bin/curl net send-data write-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=a80659b9-1900-0000-0f85-07c2d5120000 pid=4821 execve guuid=d2be4ec0-1900-0000-0f85-07c2ea120000 pid=4842 /usr/bin/chmod guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=d2be4ec0-1900-0000-0f85-07c2ea120000 pid=4842 execve guuid=cf28b4c0-1900-0000-0f85-07c2ec120000 pid=4844 /usr/bin/bash guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=cf28b4c0-1900-0000-0f85-07c2ec120000 pid=4844 clone guuid=f0b888c1-1900-0000-0f85-07c2f0120000 pid=4848 /usr/bin/rm delete-file guuid=faac448b-1600-0000-0f85-07c2be0b0000 pid=3006->guuid=f0b888c1-1900-0000-0f85-07c2f0120000 pid=4848 execve 3c9cf1b4-e372-55da-9b98-da9ce4abcb12 87.121.84.111:80 guuid=59261b90-1600-0000-0f85-07c2cc0b0000 pid=3020->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 152B guuid=b1dbf096-1600-0000-0f85-07c2e60b0000 pid=3046->3c9cf1b4-e372-55da-9b98-da9ce4abcb12 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e274d2a2-1600-0000-0f85-07c20c0c0000 pid=3084 /tmp/morte.x86 guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081->guuid=e274d2a2-1600-0000-0f85-07c20c0c0000 pid=3084 clone guuid=2762d0ce-1700-0000-0f85-07c2dc0d0000 pid=3548 /tmp/morte.x86 guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081->guuid=2762d0ce-1700-0000-0f85-07c2dc0d0000 pid=3548 clone guuid=545bdbce-1700-0000-0f85-07c2de0d0000 pid=3550 /tmp/morte.x86 net send-data zombie guuid=7d7652a2-1600-0000-0f85-07c2090c0000 pid=3081->guuid=545bdbce-1700-0000-0f85-07c2de0d0000 pid=3550 clone guuid=61fed8a2-1600-0000-0f85-07c20d0c0000 pid=3085 /tmp/morte.x86 guuid=e274d2a2-1600-0000-0f85-07c20c0c0000 pid=3084->guuid=61fed8a2-1600-0000-0f85-07c20d0c0000 pid=3085 clone guuid=740cdca2-1600-0000-0f85-07c20e0c0000 pid=3086 /tmp/morte.x86 dns net send-data zombie guuid=e274d2a2-1600-0000-0f85-07c20c0c0000 pid=3084->guuid=740cdca2-1600-0000-0f85-07c20e0c0000 pid=3086 clone guuid=740cdca2-1600-0000-0f85-07c20e0c0000 pid=3086->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B dac1a50c-9030-58bd-8b04-b0ceda4107fe boatn1941.ddns.net:12121 guuid=740cdca2-1600-0000-0f85-07c20e0c0000 pid=3086->dac1a50c-9030-58bd-8b04-b0ceda4107fe send: 15B guuid=545bdbce-1700-0000-0f85-07c2de0d0000 pid=3550->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 180B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=545bdbce-1700-0000-0f85-07c2de0d0000 pid=3550->310a0ed0-c544-54ca-bf3f-fca55e459297 con 0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 boatn1941.ddns.net:80 guuid=710d76cf-1700-0000-0f85-07c2e10d0000 pid=3553->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=b3ecced7-1700-0000-0f85-07c2f20d0000 pid=3570->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=6e5e70e5-1700-0000-0f85-07c20c0e0000 pid=3596->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 152B guuid=61bd83ed-1700-0000-0f85-07c2170e0000 pid=3607->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 101B guuid=91fe98fa-1700-0000-0f85-07c2380e0000 pid=3640->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=860201fe-1700-0000-0f85-07c23f0e0000 pid=3647->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=a3b8eb04-1800-0000-0f85-07c2580e0000 pid=3672->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=b098260a-1800-0000-0f85-07c25e0e0000 pid=3678->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=275db511-1800-0000-0f85-07c2680e0000 pid=3688->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=275db511-1800-0000-0f85-07c2680e0000 pid=3688->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=71e1868a-1800-0000-0f85-07c2810f0000 pid=3969->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 155B guuid=cc8f5491-1800-0000-0f85-07c2900f0000 pid=3984->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 104B guuid=c1e1e898-1800-0000-0f85-07c2a50f0000 pid=4005->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c1e1e898-1800-0000-0f85-07c2a50f0000 pid=4005->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=2d916f11-1900-0000-0f85-07c2c9100000 pid=4297->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=24ed5817-1900-0000-0f85-07c2d4100000 pid=4308->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=06b79f26-1900-0000-0f85-07c2ff100000 pid=4351->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 152B guuid=34e79e2c-1900-0000-0f85-07c20f110000 pid=4367->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 101B guuid=b3265237-1900-0000-0f85-07c23b110000 pid=4411->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=1a126a3b-1900-0000-0f85-07c24d110000 pid=4429->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=c6aa4c43-1900-0000-0f85-07c270110000 pid=4464->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=13de2648-1900-0000-0f85-07c282110000 pid=4482->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=cfd32853-1900-0000-0f85-07c2a8110000 pid=4520->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=d1d3115c-1900-0000-0f85-07c2be110000 pid=4542->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=3c434d69-1900-0000-0f85-07c2ee110000 pid=4590->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 152B guuid=e5584f6e-1900-0000-0f85-07c2ff110000 pid=4607->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 101B guuid=2dec8678-1900-0000-0f85-07c22d120000 pid=4653->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 152B guuid=e2dea57d-1900-0000-0f85-07c240120000 pid=4672->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 101B guuid=460767a3-1900-0000-0f85-07c28e120000 pid=4750->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 153B guuid=4490caaa-1900-0000-0f85-07c2a7120000 pid=4775->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 102B guuid=3eececb3-1900-0000-0f85-07c2c4120000 pid=4804->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 152B guuid=a80659b9-1900-0000-0f85-07c2d5120000 pid=4821->0dc4f6e2-32d4-55b8-bbab-9e225ce06eb0 send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-06 18:33:26 UTC
File Type:
Text (Shell)
AV detection:
15 of 23 (65.22%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
boatn1941.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9450cdae39985a317a0c04828544aa0a6db9df22b7ba50339f1b8b8d459c1e36

(this sample)

  
Delivery method
Distributed via web download

Comments