MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 99795158f1ac499a76e82b8c5278d21af53d78eec83c19f30fd365d20fa8a621. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 99795158f1ac499a76e82b8c5278d21af53d78eec83c19f30fd365d20fa8a621
SHA3-384 hash: ee53b199d2b7c56cfc45646e90902d4de15fb6fb0d68d8f416efc1c2f779bc831e3866d9ddbd8f263020d08139bc633e
SHA1 hash: e4e022884f2e721892898f2b0d5f3a8c26d5ba7b
MD5 hash: 89c7344fbe37f859b71b07d8a911ccca
humanhash: island-tennessee-equal-football
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-09-26 06:19:51 UTC
Last seen:2025-09-27 06:54:11 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It3ZsVbhTkhlftms9T0FGgJH69nLKDNIpKksJMELhzsspcGgJs0spk:iinAjFV0F1axLKJjFIspBgJsdk
TLSH T10B6172F623C106779CA289D232A84504B2D9E09B54CF5FF55BDC2AE52E4CFC9BC42B41
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.213.174.225/00101010101001/morte.x86cd2c99ab859d6dd28255d69e9e7f549695f87f339a0dc91766807e789d827a04 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.mipsf7e8bdd3c471eb15a664c8b38e2a068be130cd568b78c40a56bfa852604abf1a Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.arc6bac36a9da6baf62b802eb49e4be1b916ef48359ea88afa524ce06932a663137 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.i468n/an/aelf ua-wget
http://89.213.174.225/00101010101001/morte.i6866910d0fd17d05762ddaa59499e6c598d5cf384738798e2631ceaeda1e10a476d Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.x86_6480e0b3e1815760e8d6200118fcd7ebd67f3ff943551f0105a5ade4e52ec87961 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.mpsl782f17e0bf0ab1220f126b70d30c6b0bd1201de8c1ae65f0c088cb2dc3f22004 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.armf4cf19e5c13a745e6a73b89bf7ed820d461f3dc9bb2c4380da369427785a6bf5 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.arm589b07e9752c1c269364c64abf35a23949fdd1bff15431cc99ea351134337490f Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.arm651a95c7fa8678e36792e75114dcb9a8a340b51c2a0c34e2061bf3eeaa2f2e2dd Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.arm7b4618e7cdbfc97c1502c84aa95db42545803c26f8101865c11737aa9f7e109d9 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.ppc4f733b6403ab10c8c6784d88db610b80a3d891a6c50c034d60a61f91b3617625 Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.spc3ae19d7041ed54a585eb8199f47aa79a5194d54c35551dce95bf0d4734df8caa Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.m68k883e61d4155f62b361a56a8e9dfe09d627967b72373ad3be703710b415e081ad Miraielf mirai ua-wget
http://89.213.174.225/00101010101001/morte.sh460b91391b0914e8a56249cc3edf24c577aeebcf02c2d74b5fa9b1a602e759c35 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-25T15:41:00Z UTC
Last seen:
2025-09-25T15:41:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=bb7a390e-1d00-0000-dfa7-15b9e50b0000 pid=3045 /usr/bin/sudo guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052 /tmp/sample.bin guuid=bb7a390e-1d00-0000-dfa7-15b9e50b0000 pid=3045->guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052 execve guuid=cbb8f410-1d00-0000-dfa7-15b9ee0b0000 pid=3054 /usr/bin/cp guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=cbb8f410-1d00-0000-dfa7-15b9ee0b0000 pid=3054 execve guuid=86073517-1d00-0000-dfa7-15b9fb0b0000 pid=3067 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=86073517-1d00-0000-dfa7-15b9fb0b0000 pid=3067 execve guuid=57e1a729-1d00-0000-dfa7-15b9220c0000 pid=3106 /usr/bin/curl net send-data guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=57e1a729-1d00-0000-dfa7-15b9220c0000 pid=3106 execve guuid=70708133-1d00-0000-dfa7-15b93f0c0000 pid=3135 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=70708133-1d00-0000-dfa7-15b93f0c0000 pid=3135 execve guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137 /tmp/morte.x86 net guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137 execve guuid=d3b25b61-1e00-0000-dfa7-15b9770e0000 pid=3703 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=d3b25b61-1e00-0000-dfa7-15b9770e0000 pid=3703 execve guuid=f1fc0662-1e00-0000-dfa7-15b97a0e0000 pid=3706 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=f1fc0662-1e00-0000-dfa7-15b97a0e0000 pid=3706 execve guuid=1a898d6c-1e00-0000-dfa7-15b9a50e0000 pid=3749 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=1a898d6c-1e00-0000-dfa7-15b9a50e0000 pid=3749 execve guuid=8dd8bc77-1e00-0000-dfa7-15b9ce0e0000 pid=3790 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=8dd8bc77-1e00-0000-dfa7-15b9ce0e0000 pid=3790 execve guuid=5ecf0778-1e00-0000-dfa7-15b9cf0e0000 pid=3791 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=5ecf0778-1e00-0000-dfa7-15b9cf0e0000 pid=3791 clone guuid=0a3aae78-1e00-0000-dfa7-15b9d10e0000 pid=3793 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=0a3aae78-1e00-0000-dfa7-15b9d10e0000 pid=3793 execve guuid=62f1037e-1e00-0000-dfa7-15b9d20e0000 pid=3794 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=62f1037e-1e00-0000-dfa7-15b9d20e0000 pid=3794 execve guuid=27284189-1e00-0000-dfa7-15b9000f0000 pid=3840 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=27284189-1e00-0000-dfa7-15b9000f0000 pid=3840 execve guuid=8abeb596-1e00-0000-dfa7-15b9290f0000 pid=3881 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=8abeb596-1e00-0000-dfa7-15b9290f0000 pid=3881 execve guuid=88ae0d97-1e00-0000-dfa7-15b92d0f0000 pid=3885 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=88ae0d97-1e00-0000-dfa7-15b92d0f0000 pid=3885 clone guuid=7c20bb97-1e00-0000-dfa7-15b9310f0000 pid=3889 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=7c20bb97-1e00-0000-dfa7-15b9310f0000 pid=3889 execve guuid=b64f399b-1e00-0000-dfa7-15b93d0f0000 pid=3901 /usr/bin/wget net send-data guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=b64f399b-1e00-0000-dfa7-15b93d0f0000 pid=3901 execve guuid=496ccda0-1e00-0000-dfa7-15b9500f0000 pid=3920 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=496ccda0-1e00-0000-dfa7-15b9500f0000 pid=3920 execve guuid=eaf1ada6-1e00-0000-dfa7-15b95f0f0000 pid=3935 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=eaf1ada6-1e00-0000-dfa7-15b95f0f0000 pid=3935 execve guuid=9ff4f5a6-1e00-0000-dfa7-15b9620f0000 pid=3938 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=9ff4f5a6-1e00-0000-dfa7-15b9620f0000 pid=3938 clone guuid=dba915a7-1e00-0000-dfa7-15b9630f0000 pid=3939 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=dba915a7-1e00-0000-dfa7-15b9630f0000 pid=3939 execve guuid=b1925ca7-1e00-0000-dfa7-15b9650f0000 pid=3941 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=b1925ca7-1e00-0000-dfa7-15b9650f0000 pid=3941 execve guuid=778481b0-1e00-0000-dfa7-15b9910f0000 pid=3985 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=778481b0-1e00-0000-dfa7-15b9910f0000 pid=3985 execve guuid=327df7ba-1e00-0000-dfa7-15b9af0f0000 pid=4015 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=327df7ba-1e00-0000-dfa7-15b9af0f0000 pid=4015 execve guuid=4df84cbb-1e00-0000-dfa7-15b9b10f0000 pid=4017 /tmp/morte.i686 net guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=4df84cbb-1e00-0000-dfa7-15b9b10f0000 pid=4017 execve guuid=fd6e7b33-1f00-0000-dfa7-15b959110000 pid=4441 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=fd6e7b33-1f00-0000-dfa7-15b959110000 pid=4441 execve guuid=5b86d633-1f00-0000-dfa7-15b95b110000 pid=4443 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=5b86d633-1f00-0000-dfa7-15b95b110000 pid=4443 execve guuid=fbe5ac41-1f00-0000-dfa7-15b995110000 pid=4501 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=fbe5ac41-1f00-0000-dfa7-15b995110000 pid=4501 execve guuid=d4f8524d-1f00-0000-dfa7-15b9b5110000 pid=4533 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=d4f8524d-1f00-0000-dfa7-15b9b5110000 pid=4533 execve guuid=38479b4d-1f00-0000-dfa7-15b9b7110000 pid=4535 /tmp/morte.x86_64 mprotect-exec net guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=38479b4d-1f00-0000-dfa7-15b9b7110000 pid=4535 execve guuid=a2fa64c5-1f00-0000-dfa7-15b93f130000 pid=4927 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=a2fa64c5-1f00-0000-dfa7-15b93f130000 pid=4927 execve guuid=185fbec5-1f00-0000-dfa7-15b941130000 pid=4929 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=185fbec5-1f00-0000-dfa7-15b941130000 pid=4929 execve guuid=fd11f6cf-1f00-0000-dfa7-15b95a130000 pid=4954 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=fd11f6cf-1f00-0000-dfa7-15b95a130000 pid=4954 execve guuid=bd0f64dd-1f00-0000-dfa7-15b986130000 pid=4998 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=bd0f64dd-1f00-0000-dfa7-15b986130000 pid=4998 execve guuid=2c81b1dd-1f00-0000-dfa7-15b988130000 pid=5000 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=2c81b1dd-1f00-0000-dfa7-15b988130000 pid=5000 clone guuid=55e455de-1f00-0000-dfa7-15b98c130000 pid=5004 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=55e455de-1f00-0000-dfa7-15b98c130000 pid=5004 execve guuid=7c64c5e1-1f00-0000-dfa7-15b999130000 pid=5017 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=7c64c5e1-1f00-0000-dfa7-15b999130000 pid=5017 execve guuid=837bbded-1f00-0000-dfa7-15b9ba130000 pid=5050 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=837bbded-1f00-0000-dfa7-15b9ba130000 pid=5050 execve guuid=614433fb-1f00-0000-dfa7-15b9d8130000 pid=5080 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=614433fb-1f00-0000-dfa7-15b9d8130000 pid=5080 execve guuid=d6d075fb-1f00-0000-dfa7-15b9da130000 pid=5082 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=d6d075fb-1f00-0000-dfa7-15b9da130000 pid=5082 clone guuid=f87624fc-1f00-0000-dfa7-15b9e2130000 pid=5090 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=f87624fc-1f00-0000-dfa7-15b9e2130000 pid=5090 execve guuid=38fe2e02-2000-0000-dfa7-15b9f9130000 pid=5113 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=38fe2e02-2000-0000-dfa7-15b9f9130000 pid=5113 execve guuid=b929cd09-2000-0000-dfa7-15b913140000 pid=5139 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=b929cd09-2000-0000-dfa7-15b913140000 pid=5139 execve guuid=fe36e515-2000-0000-dfa7-15b92c140000 pid=5164 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=fe36e515-2000-0000-dfa7-15b92c140000 pid=5164 execve guuid=035d6416-2000-0000-dfa7-15b92e140000 pid=5166 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=035d6416-2000-0000-dfa7-15b92e140000 pid=5166 clone guuid=e48b2d18-2000-0000-dfa7-15b931140000 pid=5169 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=e48b2d18-2000-0000-dfa7-15b931140000 pid=5169 execve guuid=7d706f21-2000-0000-dfa7-15b932140000 pid=5170 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=7d706f21-2000-0000-dfa7-15b932140000 pid=5170 execve guuid=474e1d2c-2000-0000-dfa7-15b943140000 pid=5187 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=474e1d2c-2000-0000-dfa7-15b943140000 pid=5187 execve guuid=c288d83b-2000-0000-dfa7-15b966140000 pid=5222 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=c288d83b-2000-0000-dfa7-15b966140000 pid=5222 execve guuid=c9ba3c3c-2000-0000-dfa7-15b967140000 pid=5223 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=c9ba3c3c-2000-0000-dfa7-15b967140000 pid=5223 clone guuid=7111803e-2000-0000-dfa7-15b977140000 pid=5239 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=7111803e-2000-0000-dfa7-15b977140000 pid=5239 execve guuid=265f3754-2000-0000-dfa7-15b999140000 pid=5273 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=265f3754-2000-0000-dfa7-15b999140000 pid=5273 execve guuid=f5d3f75e-2000-0000-dfa7-15b99a140000 pid=5274 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=f5d3f75e-2000-0000-dfa7-15b99a140000 pid=5274 execve guuid=fcc5126d-2000-0000-dfa7-15b99b140000 pid=5275 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=fcc5126d-2000-0000-dfa7-15b99b140000 pid=5275 execve guuid=c18f696d-2000-0000-dfa7-15b99d140000 pid=5277 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=c18f696d-2000-0000-dfa7-15b99d140000 pid=5277 clone guuid=528c096e-2000-0000-dfa7-15b9a0140000 pid=5280 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=528c096e-2000-0000-dfa7-15b9a0140000 pid=5280 execve guuid=ea824673-2000-0000-dfa7-15b9a2140000 pid=5282 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=ea824673-2000-0000-dfa7-15b9a2140000 pid=5282 execve guuid=461db77c-2000-0000-dfa7-15b9ab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=461db77c-2000-0000-dfa7-15b9ab140000 pid=5291 execve guuid=57c49587-2000-0000-dfa7-15b9ac140000 pid=5292 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=57c49587-2000-0000-dfa7-15b9ac140000 pid=5292 execve guuid=10dd3088-2000-0000-dfa7-15b9ad140000 pid=5293 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=10dd3088-2000-0000-dfa7-15b9ad140000 pid=5293 clone guuid=30a97989-2000-0000-dfa7-15b9af140000 pid=5295 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=30a97989-2000-0000-dfa7-15b9af140000 pid=5295 execve guuid=cc7bfc89-2000-0000-dfa7-15b9b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=cc7bfc89-2000-0000-dfa7-15b9b0140000 pid=5296 execve guuid=db26aa96-2000-0000-dfa7-15b9b1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=db26aa96-2000-0000-dfa7-15b9b1140000 pid=5297 execve guuid=7f4b36a4-2000-0000-dfa7-15b9b2140000 pid=5298 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=7f4b36a4-2000-0000-dfa7-15b9b2140000 pid=5298 execve guuid=52d2bea4-2000-0000-dfa7-15b9b3140000 pid=5299 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=52d2bea4-2000-0000-dfa7-15b9b3140000 pid=5299 clone guuid=ff65d7a5-2000-0000-dfa7-15b9b5140000 pid=5301 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=ff65d7a5-2000-0000-dfa7-15b9b5140000 pid=5301 execve guuid=3b5452a6-2000-0000-dfa7-15b9b6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=3b5452a6-2000-0000-dfa7-15b9b6140000 pid=5302 execve guuid=38c60cb3-2000-0000-dfa7-15b9b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=38c60cb3-2000-0000-dfa7-15b9b7140000 pid=5303 execve guuid=5f06a0c2-2000-0000-dfa7-15b9b8140000 pid=5304 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=5f06a0c2-2000-0000-dfa7-15b9b8140000 pid=5304 execve guuid=9582efc2-2000-0000-dfa7-15b9b9140000 pid=5305 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=9582efc2-2000-0000-dfa7-15b9b9140000 pid=5305 clone guuid=ef1498c3-2000-0000-dfa7-15b9bb140000 pid=5307 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=ef1498c3-2000-0000-dfa7-15b9bb140000 pid=5307 execve guuid=535640c6-2000-0000-dfa7-15b9bc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=535640c6-2000-0000-dfa7-15b9bc140000 pid=5308 execve guuid=ce12d5d1-2000-0000-dfa7-15b9bd140000 pid=5309 /usr/bin/curl net send-data write-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=ce12d5d1-2000-0000-dfa7-15b9bd140000 pid=5309 execve guuid=2b4452de-2000-0000-dfa7-15b9be140000 pid=5310 /usr/bin/chmod guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=2b4452de-2000-0000-dfa7-15b9be140000 pid=5310 execve guuid=ab27c6de-2000-0000-dfa7-15b9bf140000 pid=5311 /usr/bin/bash guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=ab27c6de-2000-0000-dfa7-15b9bf140000 pid=5311 clone guuid=8baa80df-2000-0000-dfa7-15b9c1140000 pid=5313 /usr/bin/rm delete-file guuid=84c19910-1d00-0000-dfa7-15b9ec0b0000 pid=3052->guuid=8baa80df-2000-0000-dfa7-15b9c1140000 pid=5313 execve 1abdd55f-79cd-53ae-abf5-622946afe271 89.213.174.225:80 guuid=86073517-1d00-0000-dfa7-15b9fb0b0000 pid=3067->1abdd55f-79cd-53ae-abf5-622946afe271 send: 153B guuid=57e1a729-1d00-0000-dfa7-15b9220c0000 pid=3106->1abdd55f-79cd-53ae-abf5-622946afe271 send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f7c49d34-1d00-0000-dfa7-15b9440c0000 pid=3140 /tmp/morte.x86 guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137->guuid=f7c49d34-1d00-0000-dfa7-15b9440c0000 pid=3140 clone guuid=a57d4161-1e00-0000-dfa7-15b9740e0000 pid=3700 /tmp/morte.x86 guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137->guuid=a57d4161-1e00-0000-dfa7-15b9740e0000 pid=3700 clone guuid=6c274a61-1e00-0000-dfa7-15b9750e0000 pid=3701 /tmp/morte.x86 net send-data zombie guuid=98cfec33-1d00-0000-dfa7-15b9410c0000 pid=3137->guuid=6c274a61-1e00-0000-dfa7-15b9750e0000 pid=3701 clone guuid=53e1a634-1d00-0000-dfa7-15b9460c0000 pid=3142 /tmp/morte.x86 guuid=f7c49d34-1d00-0000-dfa7-15b9440c0000 pid=3140->guuid=53e1a634-1d00-0000-dfa7-15b9460c0000 pid=3142 clone guuid=a98eab34-1d00-0000-dfa7-15b9470c0000 pid=3143 /tmp/morte.x86 dns net send-data zombie guuid=f7c49d34-1d00-0000-dfa7-15b9440c0000 pid=3140->guuid=a98eab34-1d00-0000-dfa7-15b9470c0000 pid=3143 clone guuid=a98eab34-1d00-0000-dfa7-15b9470c0000 pid=3143->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 72B a1a7e44c-f53d-520b-b2c8-ccb9907e473c uraniumc2.ddns.net:12121 guuid=a98eab34-1d00-0000-dfa7-15b9470c0000 pid=3143->a1a7e44c-f53d-520b-b2c8-ccb9907e473c send: 30B guuid=6c274a61-1e00-0000-dfa7-15b9750e0000 pid=3701->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 180B a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 uraniumc2.ddns.net:80 guuid=6c274a61-1e00-0000-dfa7-15b9750e0000 pid=3701->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 15B guuid=f1fc0662-1e00-0000-dfa7-15b97a0e0000 pid=3706->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=1a898d6c-1e00-0000-dfa7-15b9a50e0000 pid=3749->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=62f1037e-1e00-0000-dfa7-15b9d20e0000 pid=3794->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=27284189-1e00-0000-dfa7-15b9000f0000 pid=3840->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=b64f399b-1e00-0000-dfa7-15b93d0f0000 pid=3901->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=496ccda0-1e00-0000-dfa7-15b9500f0000 pid=3920->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=b1925ca7-1e00-0000-dfa7-15b9650f0000 pid=3941->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=778481b0-1e00-0000-dfa7-15b9910f0000 pid=3985->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=4df84cbb-1e00-0000-dfa7-15b9b10f0000 pid=4017->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=4df84cbb-1e00-0000-dfa7-15b9b10f0000 pid=4017->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=5b86d633-1f00-0000-dfa7-15b95b110000 pid=4443->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 156B guuid=fbe5ac41-1f00-0000-dfa7-15b995110000 pid=4501->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 105B guuid=38479b4d-1f00-0000-dfa7-15b9b7110000 pid=4535->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=38479b4d-1f00-0000-dfa7-15b9b7110000 pid=4535->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=185fbec5-1f00-0000-dfa7-15b941130000 pid=4929->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=fd11f6cf-1f00-0000-dfa7-15b95a130000 pid=4954->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=7c64c5e1-1f00-0000-dfa7-15b999130000 pid=5017->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=837bbded-1f00-0000-dfa7-15b9ba130000 pid=5050->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=38fe2e02-2000-0000-dfa7-15b9f9130000 pid=5113->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=b929cd09-2000-0000-dfa7-15b913140000 pid=5139->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=7d706f21-2000-0000-dfa7-15b932140000 pid=5170->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=474e1d2c-2000-0000-dfa7-15b943140000 pid=5187->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=265f3754-2000-0000-dfa7-15b999140000 pid=5273->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=f5d3f75e-2000-0000-dfa7-15b99a140000 pid=5274->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=ea824673-2000-0000-dfa7-15b9a2140000 pid=5282->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=461db77c-2000-0000-dfa7-15b9ab140000 pid=5291->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=cc7bfc89-2000-0000-dfa7-15b9b0140000 pid=5296->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=db26aa96-2000-0000-dfa7-15b9b1140000 pid=5297->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=3b5452a6-2000-0000-dfa7-15b9b6140000 pid=5302->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 154B guuid=38c60cb3-2000-0000-dfa7-15b9b7140000 pid=5303->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 103B guuid=535640c6-2000-0000-dfa7-15b9bc140000 pid=5308->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=ce12d5d1-2000-0000-dfa7-15b9bd140000 pid=5309->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-26 02:30:50 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
uraniumc2.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 99795158f1ac499a76e82b8c5278d21af53d78eec83c19f30fd365d20fa8a621

(this sample)

  
Delivery method
Distributed via web download

Comments