MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ae9adb1dcf005b2797708d4a3f26f808dd2afee141e794f45f89360a20d5e3d1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: ae9adb1dcf005b2797708d4a3f26f808dd2afee141e794f45f89360a20d5e3d1
SHA3-384 hash: cba0ff1f376a00dccc02407427b0212e0a27a66f62fb85dff0056294a68e4da84fd46797e426fe83d636d4f3f83fd7de
SHA1 hash: 55c48306da6c4e670fd167c66cf187029bb80fa8
MD5 hash: dfb7a89636093dba661252bb7edd62d4
humanhash: failed-sixteen-cup-crazy
File name:1.sh
Download: download sample
Signature Mirai
File size:3'314 bytes
First seen:2025-09-25 18:40:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItZZsvbhRkHlfjmsnTFuGgJF6PnLDYNIpKksHME/hFsDocGgJsV9pk:icdy9rTFu1IvL+JB5eDoBgJsZk
TLSH T1776184F6234286339CAACED332AE8504754580ABD4CF5FF55BFD24B98C4CEC9AC41652
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.72.82/00101010101001/morte.x8627ed1e4b1f179555a2c68978b5639802b211d8dae49b65d88a0313e924864d47 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.mips666767bd28d0fb24ca972246aa73932d71a30ddca5a0f4b6a730eef506305d10 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.arcfa75437e2e7019dd5e7543aca3dbcf58bf8a86efd50e1a8fb08b877e00dc661a Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.i468n/an/aelf ua-wget
http://196.251.72.82/00101010101001/morte.i686313f87e22b3cb8932e9aefbc8743c37e701daf40f5902986b0338ac090240409 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.x86_64bd7d31ddbc5878f9d635f1ca4aabab67490fbe075ee0d9aa00f0fbca4d3bb209 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.mpsl68c74f5b9af34b7862d3f2ac9ef6414cfcb58125c78d80d4e3374dacdbcd91da Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.armd9ab1253763b1af3f90a6345db9a1eacc9e5bce76d3cc21de177fe6e39b3df11 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.arm573bc5ac30bd6862a81ea07096697a459ff2f4e0f22ef5207ba1fa7e890de3f7f Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.arm684fa88f488dcac685b9dc425fa13411d9f9cc428fcac9f27f1c919718e1189b5 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.arm7f38a2852519f14d654ae30f22933bbf9dff308d63ba7d1bf6bb31efd06a08d4a Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.ppcaad1ec25bc56693cc40828a6f8d4fb5afae9196ed415e7606eaee465d7e5fd4e Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.spc93fe2714b44b7d85763ffd53134c78bada32da20ca0eebddb1fd6c2570d116b8 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.m68kd2c8df309b9e28bd66087c9f45b70f788dda3d4988f65642f79c83904394fa72 Miraielf mirai ua-wget
http://196.251.72.82/00101010101001/morte.sh429edec46b9370fc454f0e2b3b0280a0d49e6c85139b0a2edc46fc75e1829c1f8 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-25T15:48:00Z UTC
Last seen:
2025-09-25T15:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=438ef4cf-1a00-0000-3533-438b5e0a0000 pid=2654 /usr/bin/sudo guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661 /tmp/sample.bin guuid=438ef4cf-1a00-0000-3533-438b5e0a0000 pid=2654->guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661 execve guuid=57caf4d1-1a00-0000-3533-438b670a0000 pid=2663 /usr/bin/cp guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=57caf4d1-1a00-0000-3533-438b670a0000 pid=2663 execve guuid=f7b24cd7-1a00-0000-3533-438b750a0000 pid=2677 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=f7b24cd7-1a00-0000-3533-438b750a0000 pid=2677 execve guuid=d0a4f6de-1a00-0000-3533-438b8c0a0000 pid=2700 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=d0a4f6de-1a00-0000-3533-438b8c0a0000 pid=2700 execve guuid=822fe1f0-1a00-0000-3533-438ba60a0000 pid=2726 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=822fe1f0-1a00-0000-3533-438ba60a0000 pid=2726 execve guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730 /tmp/morte.x86 net guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730 execve guuid=abb31b20-1c00-0000-3533-438bf00c0000 pid=3312 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=abb31b20-1c00-0000-3533-438bf00c0000 pid=3312 execve guuid=222fad20-1c00-0000-3533-438bf30c0000 pid=3315 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=222fad20-1c00-0000-3533-438bf30c0000 pid=3315 execve guuid=f1dd0527-1c00-0000-3533-438b060d0000 pid=3334 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=f1dd0527-1c00-0000-3533-438b060d0000 pid=3334 execve guuid=4a11bb30-1c00-0000-3533-438b0b0d0000 pid=3339 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=4a11bb30-1c00-0000-3533-438b0b0d0000 pid=3339 execve guuid=36c32631-1c00-0000-3533-438b0d0d0000 pid=3341 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=36c32631-1c00-0000-3533-438b0d0d0000 pid=3341 clone guuid=5ea9ec31-1c00-0000-3533-438b120d0000 pid=3346 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=5ea9ec31-1c00-0000-3533-438b120d0000 pid=3346 execve guuid=16829532-1c00-0000-3533-438b140d0000 pid=3348 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=16829532-1c00-0000-3533-438b140d0000 pid=3348 execve guuid=38a9fe3a-1c00-0000-3533-438b270d0000 pid=3367 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=38a9fe3a-1c00-0000-3533-438b270d0000 pid=3367 execve guuid=efa2f645-1c00-0000-3533-438b3a0d0000 pid=3386 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=efa2f645-1c00-0000-3533-438b3a0d0000 pid=3386 execve guuid=4a518146-1c00-0000-3533-438b3c0d0000 pid=3388 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=4a518146-1c00-0000-3533-438b3c0d0000 pid=3388 clone guuid=3d972447-1c00-0000-3533-438b3f0d0000 pid=3391 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=3d972447-1c00-0000-3533-438b3f0d0000 pid=3391 execve guuid=b66ec249-1c00-0000-3533-438b400d0000 pid=3392 /usr/bin/wget net send-data guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=b66ec249-1c00-0000-3533-438b400d0000 pid=3392 execve guuid=b10df54e-1c00-0000-3533-438b4a0d0000 pid=3402 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=b10df54e-1c00-0000-3533-438b4a0d0000 pid=3402 execve guuid=4a74bf55-1c00-0000-3533-438b5a0d0000 pid=3418 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=4a74bf55-1c00-0000-3533-438b5a0d0000 pid=3418 execve guuid=1ee40456-1c00-0000-3533-438b5c0d0000 pid=3420 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=1ee40456-1c00-0000-3533-438b5c0d0000 pid=3420 clone guuid=9aea2a56-1c00-0000-3533-438b5e0d0000 pid=3422 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=9aea2a56-1c00-0000-3533-438b5e0d0000 pid=3422 execve guuid=57227956-1c00-0000-3533-438b600d0000 pid=3424 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=57227956-1c00-0000-3533-438b600d0000 pid=3424 execve guuid=64d1805b-1c00-0000-3533-438b6f0d0000 pid=3439 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=64d1805b-1c00-0000-3533-438b6f0d0000 pid=3439 execve guuid=0381fd62-1c00-0000-3533-438b850d0000 pid=3461 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=0381fd62-1c00-0000-3533-438b850d0000 pid=3461 execve guuid=5c705263-1c00-0000-3533-438b870d0000 pid=3463 /tmp/morte.i686 net guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=5c705263-1c00-0000-3533-438b870d0000 pid=3463 execve guuid=844e63db-1c00-0000-3533-438bb30e0000 pid=3763 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=844e63db-1c00-0000-3533-438bb30e0000 pid=3763 execve guuid=38deb3db-1c00-0000-3533-438bb60e0000 pid=3766 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=38deb3db-1c00-0000-3533-438bb60e0000 pid=3766 execve guuid=04c638e2-1c00-0000-3533-438bc90e0000 pid=3785 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=04c638e2-1c00-0000-3533-438bc90e0000 pid=3785 execve guuid=58e65ceb-1c00-0000-3533-438bea0e0000 pid=3818 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=58e65ceb-1c00-0000-3533-438bea0e0000 pid=3818 execve guuid=f4fbbceb-1c00-0000-3533-438bed0e0000 pid=3821 /tmp/morte.x86_64 mprotect-exec net guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=f4fbbceb-1c00-0000-3533-438bed0e0000 pid=3821 execve guuid=57937963-1d00-0000-3533-438b66100000 pid=4198 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=57937963-1d00-0000-3533-438b66100000 pid=4198 execve guuid=d451c663-1d00-0000-3533-438b67100000 pid=4199 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=d451c663-1d00-0000-3533-438b67100000 pid=4199 execve guuid=561d4c6a-1d00-0000-3533-438b7c100000 pid=4220 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=561d4c6a-1d00-0000-3533-438b7c100000 pid=4220 execve guuid=3db2b071-1d00-0000-3533-438b94100000 pid=4244 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=3db2b071-1d00-0000-3533-438b94100000 pid=4244 execve guuid=fb650f72-1d00-0000-3533-438b97100000 pid=4247 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=fb650f72-1d00-0000-3533-438b97100000 pid=4247 clone guuid=02fb3074-1d00-0000-3533-438b9e100000 pid=4254 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=02fb3074-1d00-0000-3533-438b9e100000 pid=4254 execve guuid=52a9dd74-1d00-0000-3533-438ba2100000 pid=4258 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=52a9dd74-1d00-0000-3533-438ba2100000 pid=4258 execve guuid=dfbb5d7c-1d00-0000-3533-438bbe100000 pid=4286 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=dfbb5d7c-1d00-0000-3533-438bbe100000 pid=4286 execve guuid=1ef16283-1d00-0000-3533-438bda100000 pid=4314 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=1ef16283-1d00-0000-3533-438bda100000 pid=4314 execve guuid=e633c783-1d00-0000-3533-438bdc100000 pid=4316 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=e633c783-1d00-0000-3533-438bdc100000 pid=4316 clone guuid=61b18484-1d00-0000-3533-438be0100000 pid=4320 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=61b18484-1d00-0000-3533-438be0100000 pid=4320 execve guuid=6db64085-1d00-0000-3533-438be3100000 pid=4323 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=6db64085-1d00-0000-3533-438be3100000 pid=4323 execve guuid=f3ce5d8a-1d00-0000-3533-438bf7100000 pid=4343 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=f3ce5d8a-1d00-0000-3533-438bf7100000 pid=4343 execve guuid=799c2192-1d00-0000-3533-438b0f110000 pid=4367 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=799c2192-1d00-0000-3533-438b0f110000 pid=4367 execve guuid=fbcd8892-1d00-0000-3533-438b11110000 pid=4369 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=fbcd8892-1d00-0000-3533-438b11110000 pid=4369 clone guuid=a5461194-1d00-0000-3533-438b19110000 pid=4377 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=a5461194-1d00-0000-3533-438b19110000 pid=4377 execve guuid=94c4609b-1d00-0000-3533-438b32110000 pid=4402 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=94c4609b-1d00-0000-3533-438b32110000 pid=4402 execve guuid=c0ea82a1-1d00-0000-3533-438b4a110000 pid=4426 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=c0ea82a1-1d00-0000-3533-438b4a110000 pid=4426 execve guuid=180011a9-1d00-0000-3533-438b63110000 pid=4451 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=180011a9-1d00-0000-3533-438b63110000 pid=4451 execve guuid=fb7667a9-1d00-0000-3533-438b65110000 pid=4453 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=fb7667a9-1d00-0000-3533-438b65110000 pid=4453 clone guuid=81b4f6a9-1d00-0000-3533-438b6a110000 pid=4458 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=81b4f6a9-1d00-0000-3533-438b6a110000 pid=4458 execve guuid=cba77dac-1d00-0000-3533-438b76110000 pid=4470 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=cba77dac-1d00-0000-3533-438b76110000 pid=4470 execve guuid=337f04b3-1d00-0000-3533-438b8d110000 pid=4493 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=337f04b3-1d00-0000-3533-438b8d110000 pid=4493 execve guuid=4db803bc-1d00-0000-3533-438bb3110000 pid=4531 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=4db803bc-1d00-0000-3533-438bb3110000 pid=4531 execve guuid=3e1c6fbc-1d00-0000-3533-438bb5110000 pid=4533 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=3e1c6fbc-1d00-0000-3533-438bb5110000 pid=4533 clone guuid=bf9813bd-1d00-0000-3533-438bba110000 pid=4538 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=bf9813bd-1d00-0000-3533-438bba110000 pid=4538 execve guuid=d08e65c0-1d00-0000-3533-438bc6110000 pid=4550 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=d08e65c0-1d00-0000-3533-438bc6110000 pid=4550 execve guuid=12fce0c5-1d00-0000-3533-438bd2110000 pid=4562 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=12fce0c5-1d00-0000-3533-438bd2110000 pid=4562 execve guuid=494192cc-1d00-0000-3533-438bdd110000 pid=4573 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=494192cc-1d00-0000-3533-438bdd110000 pid=4573 execve guuid=cab4e1cc-1d00-0000-3533-438be0110000 pid=4576 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=cab4e1cc-1d00-0000-3533-438be0110000 pid=4576 clone guuid=6938a9cd-1d00-0000-3533-438be5110000 pid=4581 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=6938a9cd-1d00-0000-3533-438be5110000 pid=4581 execve guuid=5e93f8cd-1d00-0000-3533-438be7110000 pid=4583 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=5e93f8cd-1d00-0000-3533-438be7110000 pid=4583 execve guuid=e90848d4-1d00-0000-3533-438b06120000 pid=4614 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=e90848d4-1d00-0000-3533-438b06120000 pid=4614 execve guuid=d58b0bdc-1d00-0000-3533-438b25120000 pid=4645 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=d58b0bdc-1d00-0000-3533-438b25120000 pid=4645 execve guuid=67cf5cdc-1d00-0000-3533-438b28120000 pid=4648 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=67cf5cdc-1d00-0000-3533-438b28120000 pid=4648 clone guuid=879740de-1d00-0000-3533-438b32120000 pid=4658 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=879740de-1d00-0000-3533-438b32120000 pid=4658 execve guuid=8c87bbde-1d00-0000-3533-438b36120000 pid=4662 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=8c87bbde-1d00-0000-3533-438b36120000 pid=4662 execve guuid=f13e6de5-1d00-0000-3533-438b4d120000 pid=4685 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=f13e6de5-1d00-0000-3533-438b4d120000 pid=4685 execve guuid=65d0e0ee-1d00-0000-3533-438b5b120000 pid=4699 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=65d0e0ee-1d00-0000-3533-438b5b120000 pid=4699 execve guuid=bdb344ef-1d00-0000-3533-438b5c120000 pid=4700 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=bdb344ef-1d00-0000-3533-438b5c120000 pid=4700 clone guuid=8ea9dbef-1d00-0000-3533-438b60120000 pid=4704 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=8ea9dbef-1d00-0000-3533-438b60120000 pid=4704 execve guuid=e97e37f2-1d00-0000-3533-438b69120000 pid=4713 /usr/bin/wget net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=e97e37f2-1d00-0000-3533-438b69120000 pid=4713 execve guuid=9f4492f9-1d00-0000-3533-438b82120000 pid=4738 /usr/bin/curl net send-data write-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=9f4492f9-1d00-0000-3533-438b82120000 pid=4738 execve guuid=93992602-1e00-0000-3533-438b9f120000 pid=4767 /usr/bin/chmod guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=93992602-1e00-0000-3533-438b9f120000 pid=4767 execve guuid=467fa602-1e00-0000-3533-438ba1120000 pid=4769 /usr/bin/bash guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=467fa602-1e00-0000-3533-438ba1120000 pid=4769 clone guuid=3b03be04-1e00-0000-3533-438ba9120000 pid=4777 /usr/bin/rm delete-file guuid=dc3ba3d1-1a00-0000-3533-438b650a0000 pid=2661->guuid=3b03be04-1e00-0000-3533-438ba9120000 pid=4777 execve ce94efdc-f6e6-538c-917c-a4373dec06e1 196.251.72.82:80 guuid=f7b24cd7-1a00-0000-3533-438b750a0000 pid=2677->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 152B guuid=d0a4f6de-1a00-0000-3533-438b8c0a0000 pid=2700->ce94efdc-f6e6-538c-917c-a4373dec06e1 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18e8f8f2-1a00-0000-3533-438bad0a0000 pid=2733 /tmp/morte.x86 guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730->guuid=18e8f8f2-1a00-0000-3533-438bad0a0000 pid=2733 clone guuid=21940420-1c00-0000-3533-438bee0c0000 pid=3310 /tmp/morte.x86 guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730->guuid=21940420-1c00-0000-3533-438bee0c0000 pid=3310 clone guuid=5f3b0d20-1c00-0000-3533-438bef0c0000 pid=3311 /tmp/morte.x86 net send-data zombie guuid=c49cc3f1-1a00-0000-3533-438baa0a0000 pid=2730->guuid=5f3b0d20-1c00-0000-3533-438bef0c0000 pid=3311 clone guuid=043300f3-1a00-0000-3533-438bae0a0000 pid=2734 /tmp/morte.x86 guuid=18e8f8f2-1a00-0000-3533-438bad0a0000 pid=2733->guuid=043300f3-1a00-0000-3533-438bae0a0000 pid=2734 clone guuid=638103f3-1a00-0000-3533-438baf0a0000 pid=2735 /tmp/morte.x86 dns net send-data zombie guuid=18e8f8f2-1a00-0000-3533-438bad0a0000 pid=2733->guuid=638103f3-1a00-0000-3533-438baf0a0000 pid=2735 clone guuid=638103f3-1a00-0000-3533-438baf0a0000 pid=2735->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B c1d898e2-6d70-50b0-9695-286b857a1b6e hikylover.st:12121 guuid=638103f3-1a00-0000-3533-438baf0a0000 pid=2735->c1d898e2-6d70-50b0-9695-286b857a1b6e send: 15B guuid=5f3b0d20-1c00-0000-3533-438bef0c0000 pid=3311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 155B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=5f3b0d20-1c00-0000-3533-438bef0c0000 pid=3311->310a0ed0-c544-54ca-bf3f-fca55e459297 con 810338e8-948f-5546-b2ad-d7d7b3d6db72 hikylover.st:80 guuid=222fad20-1c00-0000-3533-438bf30c0000 pid=3315->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=f1dd0527-1c00-0000-3533-438b060d0000 pid=3334->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=16829532-1c00-0000-3533-438b140d0000 pid=3348->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 152B guuid=38a9fe3a-1c00-0000-3533-438b270d0000 pid=3367->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 101B guuid=b66ec249-1c00-0000-3533-438b400d0000 pid=3392->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=b10df54e-1c00-0000-3533-438b4a0d0000 pid=3402->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=57227956-1c00-0000-3533-438b600d0000 pid=3424->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=64d1805b-1c00-0000-3533-438b6f0d0000 pid=3439->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=5c705263-1c00-0000-3533-438b870d0000 pid=3463->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=5c705263-1c00-0000-3533-438b870d0000 pid=3463->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=38deb3db-1c00-0000-3533-438bb60e0000 pid=3766->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 155B guuid=04c638e2-1c00-0000-3533-438bc90e0000 pid=3785->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 104B guuid=f4fbbceb-1c00-0000-3533-438bed0e0000 pid=3821->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f4fbbceb-1c00-0000-3533-438bed0e0000 pid=3821->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=d451c663-1d00-0000-3533-438b67100000 pid=4199->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=561d4c6a-1d00-0000-3533-438b7c100000 pid=4220->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=52a9dd74-1d00-0000-3533-438ba2100000 pid=4258->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 152B guuid=dfbb5d7c-1d00-0000-3533-438bbe100000 pid=4286->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 101B guuid=6db64085-1d00-0000-3533-438be3100000 pid=4323->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=f3ce5d8a-1d00-0000-3533-438bf7100000 pid=4343->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=94c4609b-1d00-0000-3533-438b32110000 pid=4402->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=c0ea82a1-1d00-0000-3533-438b4a110000 pid=4426->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=cba77dac-1d00-0000-3533-438b76110000 pid=4470->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=337f04b3-1d00-0000-3533-438b8d110000 pid=4493->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=d08e65c0-1d00-0000-3533-438bc6110000 pid=4550->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 152B guuid=12fce0c5-1d00-0000-3533-438bd2110000 pid=4562->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 101B guuid=5e93f8cd-1d00-0000-3533-438be7110000 pid=4583->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 152B guuid=e90848d4-1d00-0000-3533-438b06120000 pid=4614->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 101B guuid=8c87bbde-1d00-0000-3533-438b36120000 pid=4662->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 153B guuid=f13e6de5-1d00-0000-3533-438b4d120000 pid=4685->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 102B guuid=e97e37f2-1d00-0000-3533-438b69120000 pid=4713->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 152B guuid=9f4492f9-1d00-0000-3533-438b82120000 pid=4738->810338e8-948f-5546-b2ad-d7d7b3d6db72 send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-25 18:41:42 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ae9adb1dcf005b2797708d4a3f26f808dd2afee141e794f45f89360a20d5e3d1

(this sample)

  
Delivery method
Distributed via web download

Comments