MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 97b61cd74c3a63809607412e9b7b0d09d08b34cc2f60782bdc9e5bf6e78bb644. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 97b61cd74c3a63809607412e9b7b0d09d08b34cc2f60782bdc9e5bf6e78bb644
SHA3-384 hash: 3dc7768f77cccc8f7f2ef783c826b7de857801d8c1b94cda21404c8eca622788e8b642fff1b52b94431c59de24a2a452
SHA1 hash: 182e74a2088d9cfc9e3668fde921cfcd35585456
MD5 hash: 53856e70d7f69daf660bf221dd814ca0
humanhash: magazine-bravo-salami-kilo
File name:1.sh
Download: download sample
Signature Mirai
File size:3'014 bytes
First seen:2025-08-23 13:30:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItXZsTbhLkPlfXmsbTw3GgJH6DnLmZNIpKksLMEthLsA7cGgJswgpk:iCh41HPw31a7LKJt/AA7BgJs7k
TLSH T1E05185EB23828A336CB9CED776AAC4587145809FD5CE5F7954EEB8B9408CE086441E53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.24/bins/morte.x868ed8684e37fed57d6a517549a3c33a47c965bd2c1b749477065300cd3befb8a8 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mips1bf649de3be52962fc4aae70aea0274646316556a3dd0bad8571ffa8bdf0d05a Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arc98833f42ea4e04673d56891cc2bc7af3e7f4def2c113bfeaefebd62dc9cbf4d1 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.i468n/an/aelf ua-wget
http://196.251.73.24/bins/morte.i6869f95429199df814af4b249582f306e331931a5b1589cc0253a3fe1cf00729a32 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.x86_64dc42dab20737c30846d8cd5245c92f7a2de2a99dee368e0e1b722171575f9b70 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mpslb05eb83d4502f8d974ff67d2e6e39eab2854f903990a30e216fee23eb96cf0f4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.armfd66075653adb6af129688520f493763553558fe461dde1e1e6b7f37cc9a7f67 Miraicensys elf mirai opendir ua-wget
http://196.251.73.24/bins/morte.arm5316f2dbc5ce4d44982adf97aa64de4669a0050862b5d42b31d23c32e5c22c743 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm6d8c6a66e47b848a317a4a40a216e1cb227d10276b7bd73bf89c1da8d35f24902 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm72a7e7542927ad5a3fbfa0700d1008e57a0581534f1b347b9f10ab1cf2b8d45d0 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.ppcdd6578f10f62f72e47533dfac771693a49d9f99f29a72b125455165c75254abc Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.spc1ff43a354faee418c12c47694f39b2e92e46aa4705a570be06d156128d9297b4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.m68kaefc54f8202f34d24d309cb7a2e6c9cfe70b07f5f8ed4ba0835ca3b531e4896e Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.sh45e69cd3c506f77714a43ba8b887d565eb16780549a54ef3626678bc5c22caab9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=d13cc5b6-1700-0000-6eea-cf0b8e0b0000 pid=2958 /usr/bin/sudo guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963 /tmp/sample.bin guuid=d13cc5b6-1700-0000-6eea-cf0b8e0b0000 pid=2958->guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963 execve guuid=67cc6cb9-1700-0000-6eea-cf0b960b0000 pid=2966 /usr/bin/cp guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=67cc6cb9-1700-0000-6eea-cf0b960b0000 pid=2966 execve guuid=a936a8be-1700-0000-6eea-cf0ba20b0000 pid=2978 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=a936a8be-1700-0000-6eea-cf0ba20b0000 pid=2978 execve guuid=cbc73cc6-1700-0000-6eea-cf0baf0b0000 pid=2991 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=cbc73cc6-1700-0000-6eea-cf0baf0b0000 pid=2991 execve guuid=3c2332d5-1700-0000-6eea-cf0bd00b0000 pid=3024 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=3c2332d5-1700-0000-6eea-cf0bd00b0000 pid=3024 execve guuid=4e438ed5-1700-0000-6eea-cf0bd20b0000 pid=3026 /tmp/morte.x86 net guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=4e438ed5-1700-0000-6eea-cf0bd20b0000 pid=3026 execve guuid=919e47d6-1700-0000-6eea-cf0bd80b0000 pid=3032 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=919e47d6-1700-0000-6eea-cf0bd80b0000 pid=3032 execve guuid=3e4993d6-1700-0000-6eea-cf0bda0b0000 pid=3034 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=3e4993d6-1700-0000-6eea-cf0bda0b0000 pid=3034 execve guuid=12d5efdc-1700-0000-6eea-cf0bf80b0000 pid=3064 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=12d5efdc-1700-0000-6eea-cf0bf80b0000 pid=3064 execve guuid=31544eec-1700-0000-6eea-cf0b1d0c0000 pid=3101 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=31544eec-1700-0000-6eea-cf0b1d0c0000 pid=3101 execve guuid=5ce799ec-1700-0000-6eea-cf0b1e0c0000 pid=3102 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=5ce799ec-1700-0000-6eea-cf0b1e0c0000 pid=3102 clone guuid=a294b3ec-1700-0000-6eea-cf0b200c0000 pid=3104 /usr/bin/rm guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=a294b3ec-1700-0000-6eea-cf0b200c0000 pid=3104 execve guuid=a359f8ec-1700-0000-6eea-cf0b220c0000 pid=3106 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=a359f8ec-1700-0000-6eea-cf0b220c0000 pid=3106 execve guuid=195d32f4-1700-0000-6eea-cf0b380c0000 pid=3128 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=195d32f4-1700-0000-6eea-cf0b380c0000 pid=3128 execve guuid=089eddfc-1700-0000-6eea-cf0b520c0000 pid=3154 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=089eddfc-1700-0000-6eea-cf0b520c0000 pid=3154 execve guuid=d30558fd-1700-0000-6eea-cf0b530c0000 pid=3155 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=d30558fd-1700-0000-6eea-cf0b530c0000 pid=3155 clone guuid=594c37ff-1700-0000-6eea-cf0b550c0000 pid=3157 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=594c37ff-1700-0000-6eea-cf0b550c0000 pid=3157 execve guuid=95cba503-1800-0000-6eea-cf0b560c0000 pid=3158 /usr/bin/wget net send-data guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=95cba503-1800-0000-6eea-cf0b560c0000 pid=3158 execve guuid=f3994007-1800-0000-6eea-cf0b5c0c0000 pid=3164 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=f3994007-1800-0000-6eea-cf0b5c0c0000 pid=3164 execve guuid=3c01340c-1800-0000-6eea-cf0b630c0000 pid=3171 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=3c01340c-1800-0000-6eea-cf0b630c0000 pid=3171 execve guuid=9df8c10c-1800-0000-6eea-cf0b650c0000 pid=3173 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=9df8c10c-1800-0000-6eea-cf0b650c0000 pid=3173 clone guuid=10bafc0c-1800-0000-6eea-cf0b670c0000 pid=3175 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=10bafc0c-1800-0000-6eea-cf0b670c0000 pid=3175 execve guuid=d9de4b0d-1800-0000-6eea-cf0b690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=d9de4b0d-1800-0000-6eea-cf0b690c0000 pid=3177 execve guuid=515e8512-1800-0000-6eea-cf0b760c0000 pid=3190 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=515e8512-1800-0000-6eea-cf0b760c0000 pid=3190 execve guuid=d574de1a-1800-0000-6eea-cf0b7c0c0000 pid=3196 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=d574de1a-1800-0000-6eea-cf0b7c0c0000 pid=3196 execve guuid=03ae9e1b-1800-0000-6eea-cf0b7d0c0000 pid=3197 /tmp/morte.i686 net guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=03ae9e1b-1800-0000-6eea-cf0b7d0c0000 pid=3197 execve guuid=2650bc1c-1800-0000-6eea-cf0b7f0c0000 pid=3199 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=2650bc1c-1800-0000-6eea-cf0b7f0c0000 pid=3199 execve guuid=9051111d-1800-0000-6eea-cf0b800c0000 pid=3200 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=9051111d-1800-0000-6eea-cf0b800c0000 pid=3200 execve guuid=c1084224-1800-0000-6eea-cf0b8a0c0000 pid=3210 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=c1084224-1800-0000-6eea-cf0b8a0c0000 pid=3210 execve guuid=257dc630-1800-0000-6eea-cf0b9f0c0000 pid=3231 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=257dc630-1800-0000-6eea-cf0b9f0c0000 pid=3231 execve guuid=b79d4731-1800-0000-6eea-cf0ba10c0000 pid=3233 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=b79d4731-1800-0000-6eea-cf0ba10c0000 pid=3233 clone guuid=16536d31-1800-0000-6eea-cf0ba20c0000 pid=3234 /usr/bin/rm guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=16536d31-1800-0000-6eea-cf0ba20c0000 pid=3234 execve guuid=36edfc31-1800-0000-6eea-cf0ba30c0000 pid=3235 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=36edfc31-1800-0000-6eea-cf0ba30c0000 pid=3235 execve guuid=e170ed38-1800-0000-6eea-cf0bae0c0000 pid=3246 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=e170ed38-1800-0000-6eea-cf0bae0c0000 pid=3246 execve guuid=f445bc41-1800-0000-6eea-cf0baf0c0000 pid=3247 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=f445bc41-1800-0000-6eea-cf0baf0c0000 pid=3247 execve guuid=4fc81642-1800-0000-6eea-cf0bb00c0000 pid=3248 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=4fc81642-1800-0000-6eea-cf0bb00c0000 pid=3248 clone guuid=51fdc642-1800-0000-6eea-cf0bb20c0000 pid=3250 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=51fdc642-1800-0000-6eea-cf0bb20c0000 pid=3250 execve guuid=61969646-1800-0000-6eea-cf0bb30c0000 pid=3251 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=61969646-1800-0000-6eea-cf0bb30c0000 pid=3251 execve guuid=530d964d-1800-0000-6eea-cf0bb40c0000 pid=3252 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=530d964d-1800-0000-6eea-cf0bb40c0000 pid=3252 execve guuid=55f84d56-1800-0000-6eea-cf0bc60c0000 pid=3270 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=55f84d56-1800-0000-6eea-cf0bc60c0000 pid=3270 execve guuid=23349156-1800-0000-6eea-cf0bc80c0000 pid=3272 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=23349156-1800-0000-6eea-cf0bc80c0000 pid=3272 clone guuid=553a3d57-1800-0000-6eea-cf0bcc0c0000 pid=3276 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=553a3d57-1800-0000-6eea-cf0bcc0c0000 pid=3276 execve guuid=011b3258-1800-0000-6eea-cf0bce0c0000 pid=3278 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=011b3258-1800-0000-6eea-cf0bce0c0000 pid=3278 execve guuid=d8698a5d-1800-0000-6eea-cf0bcf0c0000 pid=3279 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=d8698a5d-1800-0000-6eea-cf0bcf0c0000 pid=3279 execve guuid=ff2b7165-1800-0000-6eea-cf0be50c0000 pid=3301 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=ff2b7165-1800-0000-6eea-cf0be50c0000 pid=3301 execve guuid=abdfca65-1800-0000-6eea-cf0be60c0000 pid=3302 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=abdfca65-1800-0000-6eea-cf0be60c0000 pid=3302 clone guuid=45339066-1800-0000-6eea-cf0be80c0000 pid=3304 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=45339066-1800-0000-6eea-cf0be80c0000 pid=3304 execve guuid=265eef66-1800-0000-6eea-cf0be90c0000 pid=3305 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=265eef66-1800-0000-6eea-cf0be90c0000 pid=3305 execve guuid=af8bde6c-1800-0000-6eea-cf0bee0c0000 pid=3310 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=af8bde6c-1800-0000-6eea-cf0bee0c0000 pid=3310 execve guuid=a240c973-1800-0000-6eea-cf0bfe0c0000 pid=3326 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=a240c973-1800-0000-6eea-cf0bfe0c0000 pid=3326 execve guuid=d89c4274-1800-0000-6eea-cf0bff0c0000 pid=3327 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=d89c4274-1800-0000-6eea-cf0bff0c0000 pid=3327 clone guuid=57484775-1800-0000-6eea-cf0b010d0000 pid=3329 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=57484775-1800-0000-6eea-cf0b010d0000 pid=3329 execve guuid=47110076-1800-0000-6eea-cf0b030d0000 pid=3331 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=47110076-1800-0000-6eea-cf0b030d0000 pid=3331 execve guuid=b685cc7c-1800-0000-6eea-cf0b110d0000 pid=3345 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=b685cc7c-1800-0000-6eea-cf0b110d0000 pid=3345 execve guuid=49fc4586-1800-0000-6eea-cf0b280d0000 pid=3368 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=49fc4586-1800-0000-6eea-cf0b280d0000 pid=3368 execve guuid=3d84cf86-1800-0000-6eea-cf0b2a0d0000 pid=3370 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=3d84cf86-1800-0000-6eea-cf0b2a0d0000 pid=3370 clone guuid=ae4dcc87-1800-0000-6eea-cf0b2e0d0000 pid=3374 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=ae4dcc87-1800-0000-6eea-cf0b2e0d0000 pid=3374 execve guuid=01ab3f88-1800-0000-6eea-cf0b300d0000 pid=3376 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=01ab3f88-1800-0000-6eea-cf0b300d0000 pid=3376 execve guuid=bc582f8e-1800-0000-6eea-cf0b3c0d0000 pid=3388 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=bc582f8e-1800-0000-6eea-cf0b3c0d0000 pid=3388 execve guuid=865f1197-1800-0000-6eea-cf0b400d0000 pid=3392 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=865f1197-1800-0000-6eea-cf0b400d0000 pid=3392 execve guuid=30647497-1800-0000-6eea-cf0b420d0000 pid=3394 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=30647497-1800-0000-6eea-cf0b420d0000 pid=3394 clone guuid=c4751898-1800-0000-6eea-cf0b460d0000 pid=3398 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=c4751898-1800-0000-6eea-cf0b460d0000 pid=3398 execve guuid=abba17a0-1800-0000-6eea-cf0b4d0d0000 pid=3405 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=abba17a0-1800-0000-6eea-cf0b4d0d0000 pid=3405 execve guuid=06cf37a7-1800-0000-6eea-cf0b560d0000 pid=3414 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=06cf37a7-1800-0000-6eea-cf0b560d0000 pid=3414 execve guuid=6c262caf-1800-0000-6eea-cf0b6a0d0000 pid=3434 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=6c262caf-1800-0000-6eea-cf0b6a0d0000 pid=3434 execve guuid=c97c7aaf-1800-0000-6eea-cf0b6b0d0000 pid=3435 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=c97c7aaf-1800-0000-6eea-cf0b6b0d0000 pid=3435 clone guuid=54b140b0-1800-0000-6eea-cf0b6f0d0000 pid=3439 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=54b140b0-1800-0000-6eea-cf0b6f0d0000 pid=3439 execve guuid=f434b5b0-1800-0000-6eea-cf0b710d0000 pid=3441 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=f434b5b0-1800-0000-6eea-cf0b710d0000 pid=3441 execve guuid=72e86cb7-1800-0000-6eea-cf0b7d0d0000 pid=3453 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=72e86cb7-1800-0000-6eea-cf0b7d0d0000 pid=3453 execve guuid=cdb036c1-1800-0000-6eea-cf0b910d0000 pid=3473 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=cdb036c1-1800-0000-6eea-cf0b910d0000 pid=3473 execve guuid=fbffc4c1-1800-0000-6eea-cf0b940d0000 pid=3476 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=fbffc4c1-1800-0000-6eea-cf0b940d0000 pid=3476 clone guuid=2fd6b7c2-1800-0000-6eea-cf0b990d0000 pid=3481 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=2fd6b7c2-1800-0000-6eea-cf0b990d0000 pid=3481 execve guuid=46f417c3-1800-0000-6eea-cf0b9a0d0000 pid=3482 /usr/bin/wget net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=46f417c3-1800-0000-6eea-cf0b9a0d0000 pid=3482 execve guuid=6af170ca-1800-0000-6eea-cf0bad0d0000 pid=3501 /usr/bin/curl net send-data write-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=6af170ca-1800-0000-6eea-cf0bad0d0000 pid=3501 execve guuid=3c53cad2-1800-0000-6eea-cf0bc40d0000 pid=3524 /usr/bin/chmod guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=3c53cad2-1800-0000-6eea-cf0bc40d0000 pid=3524 execve guuid=f74420d3-1800-0000-6eea-cf0bc60d0000 pid=3526 /usr/bin/bash guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=f74420d3-1800-0000-6eea-cf0bc60d0000 pid=3526 clone guuid=955bd6d3-1800-0000-6eea-cf0bca0d0000 pid=3530 /usr/bin/rm delete-file guuid=e2c0adb8-1700-0000-6eea-cf0b930b0000 pid=2963->guuid=955bd6d3-1800-0000-6eea-cf0bca0d0000 pid=3530 execve 6beadc35-efc4-5e26-84e6-0089cd490f0e 196.251.73.24:80 guuid=a936a8be-1700-0000-6eea-cf0ba20b0000 pid=2978->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=cbc73cc6-1700-0000-6eea-cf0baf0b0000 pid=2991->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4e438ed5-1700-0000-6eea-cf0bd20b0000 pid=3026->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=86473ed6-1700-0000-6eea-cf0bd60b0000 pid=3030 /tmp/morte.x86 guuid=4e438ed5-1700-0000-6eea-cf0bd20b0000 pid=3026->guuid=86473ed6-1700-0000-6eea-cf0bd60b0000 pid=3030 clone guuid=9f3447d6-1700-0000-6eea-cf0bd70b0000 pid=3031 /tmp/morte.x86 write-config zombie guuid=86473ed6-1700-0000-6eea-cf0bd60b0000 pid=3030->guuid=9f3447d6-1700-0000-6eea-cf0bd70b0000 pid=3031 clone guuid=4f6da6d9-1700-0000-6eea-cf0be70b0000 pid=3047 /usr/bin/dash guuid=9f3447d6-1700-0000-6eea-cf0bd70b0000 pid=3031->guuid=4f6da6d9-1700-0000-6eea-cf0be70b0000 pid=3047 execve guuid=a3a9addb-1700-0000-6eea-cf0bf10b0000 pid=3057 /tmp/morte.x86 delete-file dns net send-data zombie guuid=9f3447d6-1700-0000-6eea-cf0bd70b0000 pid=3031->guuid=a3a9addb-1700-0000-6eea-cf0bf10b0000 pid=3057 clone guuid=3e4993d6-1700-0000-6eea-cf0bda0b0000 pid=3034->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=d024d1d9-1700-0000-6eea-cf0be90b0000 pid=3049 /usr/bin/cp guuid=4f6da6d9-1700-0000-6eea-cf0be70b0000 pid=3047->guuid=d024d1d9-1700-0000-6eea-cf0be90b0000 pid=3049 execve guuid=a3a9addb-1700-0000-6eea-cf0bf10b0000 pid=3057->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B debdf84d-299e-545d-934e-259ecac9681a riseonid.com:12121 guuid=a3a9addb-1700-0000-6eea-cf0bf10b0000 pid=3057->debdf84d-299e-545d-934e-259ecac9681a send: 23B guuid=12d5efdc-1700-0000-6eea-cf0bf80b0000 pid=3064->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=a359f8ec-1700-0000-6eea-cf0b220c0000 pid=3106->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=195d32f4-1700-0000-6eea-cf0b380c0000 pid=3128->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B guuid=95cba503-1800-0000-6eea-cf0b560c0000 pid=3158->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=f3994007-1800-0000-6eea-cf0b5c0c0000 pid=3164->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=d9de4b0d-1800-0000-6eea-cf0b690c0000 pid=3177->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=515e8512-1800-0000-6eea-cf0b760c0000 pid=3190->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=03ae9e1b-1800-0000-6eea-cf0b7d0c0000 pid=3197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b025b51c-1800-0000-6eea-cf0b7e0c0000 pid=3198 /tmp/morte.i686 guuid=03ae9e1b-1800-0000-6eea-cf0b7d0c0000 pid=3197->guuid=b025b51c-1800-0000-6eea-cf0b7e0c0000 pid=3198 clone guuid=6147171d-1800-0000-6eea-cf0b810c0000 pid=3201 /tmp/morte.i686 write-config zombie guuid=b025b51c-1800-0000-6eea-cf0b7e0c0000 pid=3198->guuid=6147171d-1800-0000-6eea-cf0b810c0000 pid=3201 clone guuid=9051111d-1800-0000-6eea-cf0b800c0000 pid=3200->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 145B guuid=18ac0b22-1800-0000-6eea-cf0b820c0000 pid=3202 /usr/bin/dash guuid=6147171d-1800-0000-6eea-cf0b810c0000 pid=3201->guuid=18ac0b22-1800-0000-6eea-cf0b820c0000 pid=3202 execve guuid=87e08e24-1800-0000-6eea-cf0b8c0c0000 pid=3212 /tmp/morte.i686 dns net send-data guuid=6147171d-1800-0000-6eea-cf0b810c0000 pid=3201->guuid=87e08e24-1800-0000-6eea-cf0b8c0c0000 pid=3212 clone guuid=4beb4922-1800-0000-6eea-cf0b830c0000 pid=3203 /usr/bin/cp guuid=18ac0b22-1800-0000-6eea-cf0b820c0000 pid=3202->guuid=4beb4922-1800-0000-6eea-cf0b830c0000 pid=3203 execve dcd0c388-ab1e-53dc-878c-c7efac1522a9 riseonid.com:80 guuid=c1084224-1800-0000-6eea-cf0b8a0c0000 pid=3210->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 94B guuid=87e08e24-1800-0000-6eea-cf0b8c0c0000 pid=3212->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B guuid=87e08e24-1800-0000-6eea-cf0b8c0c0000 pid=3212->debdf84d-299e-545d-934e-259ecac9681a send: 27B guuid=36edfc31-1800-0000-6eea-cf0ba30c0000 pid=3235->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=e170ed38-1800-0000-6eea-cf0bae0c0000 pid=3246->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=61969646-1800-0000-6eea-cf0bb30c0000 pid=3251->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=530d964d-1800-0000-6eea-cf0bb40c0000 pid=3252->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=011b3258-1800-0000-6eea-cf0bce0c0000 pid=3278->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=d8698a5d-1800-0000-6eea-cf0bcf0c0000 pid=3279->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=265eef66-1800-0000-6eea-cf0be90c0000 pid=3305->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=af8bde6c-1800-0000-6eea-cf0bee0c0000 pid=3310->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=47110076-1800-0000-6eea-cf0b030d0000 pid=3331->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=b685cc7c-1800-0000-6eea-cf0b110d0000 pid=3345->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=01ab3f88-1800-0000-6eea-cf0b300d0000 pid=3376->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=bc582f8e-1800-0000-6eea-cf0b3c0d0000 pid=3388->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=abba17a0-1800-0000-6eea-cf0b4d0d0000 pid=3405->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=06cf37a7-1800-0000-6eea-cf0b560d0000 pid=3414->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=f434b5b0-1800-0000-6eea-cf0b710d0000 pid=3441->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=72e86cb7-1800-0000-6eea-cf0b7d0d0000 pid=3453->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=46f417c3-1800-0000-6eea-cf0b9a0d0000 pid=3482->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=6af170ca-1800-0000-6eea-cf0bad0d0000 pid=3501->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-23 13:31:54 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 97b61cd74c3a63809607412e9b7b0d09d08b34cc2f60782bdc9e5bf6e78bb644

(this sample)

  
Delivery method
Distributed via web download

Comments