MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7b27434c69d07768debb963f2f9671ba28f7a43db8fb0b71f88f3c6a12f8e26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: b7b27434c69d07768debb963f2f9671ba28f7a43db8fb0b71f88f3c6a12f8e26
SHA3-384 hash: e73949d04729c2bb973c6df42f8bffde9f1a13860f7db623f10109e36f0993c414312873beff368fcc9c2f4d0d2d465b
SHA1 hash: aa7980dbc9a475236553a7e1404045b3e1f19adb
MD5 hash: c0225fb0fa26451ea78c20e1c189fa2f
humanhash: kansas-snake-five-mars
File name:1.sh
Download: download sample
Signature Mirai
File size:3'045 bytes
First seen:2025-08-22 13:30:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:IrsXZsTbhLkPlfXmsbTw3GgJH6DnLmZNIpKksLMEthLsA7cGgJswgpVP:csCh41HPw31a7LKJt/AA7BgJs7p
TLSH T1BE5185EB23828A336CB9CFD776AAC45C7145809FD5CE5F7954EEB8B9408CE086441E53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.73.24/bins/morte.x868ed8684e37fed57d6a517549a3c33a47c965bd2c1b749477065300cd3befb8a8 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mips1bf649de3be52962fc4aae70aea0274646316556a3dd0bad8571ffa8bdf0d05a Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arc98833f42ea4e04673d56891cc2bc7af3e7f4def2c113bfeaefebd62dc9cbf4d1 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.i468n/an/aelf ua-wget
http://196.251.73.24/bins/morte.i6869f95429199df814af4b249582f306e331931a5b1589cc0253a3fe1cf00729a32 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.x86_64dc42dab20737c30846d8cd5245c92f7a2de2a99dee368e0e1b722171575f9b70 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.mpslb05eb83d4502f8d974ff67d2e6e39eab2854f903990a30e216fee23eb96cf0f4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.armfd66075653adb6af129688520f493763553558fe461dde1e1e6b7f37cc9a7f67 Miraicensys elf mirai opendir ua-wget
http://196.251.73.24/bins/morte.arm5316f2dbc5ce4d44982adf97aa64de4669a0050862b5d42b31d23c32e5c22c743 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm6d8c6a66e47b848a317a4a40a216e1cb227d10276b7bd73bf89c1da8d35f24902 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.arm72a7e7542927ad5a3fbfa0700d1008e57a0581534f1b347b9f10ab1cf2b8d45d0 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.ppcdd6578f10f62f72e47533dfac771693a49d9f99f29a72b125455165c75254abc Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.spc1ff43a354faee418c12c47694f39b2e92e46aa4705a570be06d156128d9297b4 Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.m68kaefc54f8202f34d24d309cb7a2e6c9cfe70b07f5f8ed4ba0835ca3b531e4896e Miraielf mirai ua-wget
http://196.251.73.24/bins/morte.sh45e69cd3c506f77714a43ba8b887d565eb16780549a54ef3626678bc5c22caab9 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-22T10:39:00Z UTC
Last seen:
2025-08-22T10:39:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=57cce72c-1900-0000-82b5-ed84cd100000 pid=4301 /usr/bin/sudo guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310 /tmp/sample.bin guuid=57cce72c-1900-0000-82b5-ed84cd100000 pid=4301->guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310 execve guuid=4e5fc52e-1900-0000-82b5-ed84d8100000 pid=4312 /usr/bin/cp guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=4e5fc52e-1900-0000-82b5-ed84d8100000 pid=4312 execve guuid=ac856933-1900-0000-82b5-ed84e4100000 pid=4324 /usr/bin/rm guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=ac856933-1900-0000-82b5-ed84e4100000 pid=4324 execve guuid=0c9ab433-1900-0000-82b5-ed84e6100000 pid=4326 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0c9ab433-1900-0000-82b5-ed84e6100000 pid=4326 execve guuid=b3a5033a-1900-0000-82b5-ed8401110000 pid=4353 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=b3a5033a-1900-0000-82b5-ed8401110000 pid=4353 execve guuid=cc47e343-1900-0000-82b5-ed8421110000 pid=4385 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=cc47e343-1900-0000-82b5-ed8421110000 pid=4385 execve guuid=7c784544-1900-0000-82b5-ed8423110000 pid=4387 /tmp/morte.x86 net guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=7c784544-1900-0000-82b5-ed8423110000 pid=4387 execve guuid=d0f6fe44-1900-0000-82b5-ed8427110000 pid=4391 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=d0f6fe44-1900-0000-82b5-ed8427110000 pid=4391 execve guuid=590d4a45-1900-0000-82b5-ed842a110000 pid=4394 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=590d4a45-1900-0000-82b5-ed842a110000 pid=4394 execve guuid=e969804b-1900-0000-82b5-ed844a110000 pid=4426 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=e969804b-1900-0000-82b5-ed844a110000 pid=4426 execve guuid=81b3a756-1900-0000-82b5-ed847e110000 pid=4478 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=81b3a756-1900-0000-82b5-ed847e110000 pid=4478 execve guuid=6e5fff56-1900-0000-82b5-ed8480110000 pid=4480 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=6e5fff56-1900-0000-82b5-ed8480110000 pid=4480 clone guuid=82db1457-1900-0000-82b5-ed8482110000 pid=4482 /usr/bin/rm guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=82db1457-1900-0000-82b5-ed8482110000 pid=4482 execve guuid=17b16657-1900-0000-82b5-ed8484110000 pid=4484 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=17b16657-1900-0000-82b5-ed8484110000 pid=4484 execve guuid=7f668a5e-1900-0000-82b5-ed84a0110000 pid=4512 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=7f668a5e-1900-0000-82b5-ed84a0110000 pid=4512 execve guuid=7fef7067-1900-0000-82b5-ed84ba110000 pid=4538 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=7fef7067-1900-0000-82b5-ed84ba110000 pid=4538 execve guuid=dff5aa67-1900-0000-82b5-ed84bc110000 pid=4540 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=dff5aa67-1900-0000-82b5-ed84bc110000 pid=4540 clone guuid=dd582068-1900-0000-82b5-ed84c2110000 pid=4546 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=dd582068-1900-0000-82b5-ed84c2110000 pid=4546 execve guuid=8f8fef6d-1900-0000-82b5-ed84e6110000 pid=4582 /usr/bin/wget net send-data guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8f8fef6d-1900-0000-82b5-ed84e6110000 pid=4582 execve guuid=6e3c8772-1900-0000-82b5-ed84f7110000 pid=4599 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=6e3c8772-1900-0000-82b5-ed84f7110000 pid=4599 execve guuid=ba5bbc7b-1900-0000-82b5-ed8418120000 pid=4632 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=ba5bbc7b-1900-0000-82b5-ed8418120000 pid=4632 execve guuid=1ccf387c-1900-0000-82b5-ed841a120000 pid=4634 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=1ccf387c-1900-0000-82b5-ed841a120000 pid=4634 clone guuid=3ea09f7c-1900-0000-82b5-ed841b120000 pid=4635 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=3ea09f7c-1900-0000-82b5-ed841b120000 pid=4635 execve guuid=c82d297d-1900-0000-82b5-ed841d120000 pid=4637 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c82d297d-1900-0000-82b5-ed841d120000 pid=4637 execve guuid=72b49b83-1900-0000-82b5-ed842d120000 pid=4653 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=72b49b83-1900-0000-82b5-ed842d120000 pid=4653 execve guuid=1335468a-1900-0000-82b5-ed844b120000 pid=4683 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=1335468a-1900-0000-82b5-ed844b120000 pid=4683 execve guuid=2f1f868a-1900-0000-82b5-ed844d120000 pid=4685 /tmp/morte.i686 net guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=2f1f868a-1900-0000-82b5-ed844d120000 pid=4685 execve guuid=f9c8098b-1900-0000-82b5-ed8451120000 pid=4689 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=f9c8098b-1900-0000-82b5-ed8451120000 pid=4689 execve guuid=f81aa18b-1900-0000-82b5-ed8456120000 pid=4694 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=f81aa18b-1900-0000-82b5-ed8456120000 pid=4694 execve guuid=8d1fd490-1900-0000-82b5-ed8475120000 pid=4725 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8d1fd490-1900-0000-82b5-ed8475120000 pid=4725 execve guuid=2b9a3597-1900-0000-82b5-ed849c120000 pid=4764 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=2b9a3597-1900-0000-82b5-ed849c120000 pid=4764 execve guuid=80f67997-1900-0000-82b5-ed849e120000 pid=4766 /tmp/morte.x86_64 mprotect-exec net guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=80f67997-1900-0000-82b5-ed849e120000 pid=4766 execve guuid=52c5e397-1900-0000-82b5-ed84a1120000 pid=4769 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=52c5e397-1900-0000-82b5-ed84a1120000 pid=4769 execve guuid=a0a75698-1900-0000-82b5-ed84a4120000 pid=4772 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=a0a75698-1900-0000-82b5-ed84a4120000 pid=4772 execve guuid=20548a9e-1900-0000-82b5-ed84be120000 pid=4798 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=20548a9e-1900-0000-82b5-ed84be120000 pid=4798 execve guuid=ca43a0d3-1900-0000-82b5-ed8440130000 pid=4928 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=ca43a0d3-1900-0000-82b5-ed8440130000 pid=4928 execve guuid=1c8422d4-1900-0000-82b5-ed8442130000 pid=4930 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=1c8422d4-1900-0000-82b5-ed8442130000 pid=4930 clone guuid=add72dd5-1900-0000-82b5-ed8446130000 pid=4934 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=add72dd5-1900-0000-82b5-ed8446130000 pid=4934 execve guuid=bad491d6-1900-0000-82b5-ed844b130000 pid=4939 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=bad491d6-1900-0000-82b5-ed844b130000 pid=4939 execve guuid=0fca8bdb-1900-0000-82b5-ed8459130000 pid=4953 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0fca8bdb-1900-0000-82b5-ed8459130000 pid=4953 execve guuid=8b901de2-1900-0000-82b5-ed846c130000 pid=4972 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8b901de2-1900-0000-82b5-ed846c130000 pid=4972 execve guuid=cc8e86e2-1900-0000-82b5-ed846e130000 pid=4974 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=cc8e86e2-1900-0000-82b5-ed846e130000 pid=4974 clone guuid=bc0373e3-1900-0000-82b5-ed8473130000 pid=4979 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=bc0373e3-1900-0000-82b5-ed8473130000 pid=4979 execve guuid=8cfe73e5-1900-0000-82b5-ed847a130000 pid=4986 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8cfe73e5-1900-0000-82b5-ed847a130000 pid=4986 execve guuid=4a2fcfea-1900-0000-82b5-ed8487130000 pid=4999 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=4a2fcfea-1900-0000-82b5-ed8487130000 pid=4999 execve guuid=c528f3f0-1900-0000-82b5-ed8498130000 pid=5016 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c528f3f0-1900-0000-82b5-ed8498130000 pid=5016 execve guuid=c05067f1-1900-0000-82b5-ed849a130000 pid=5018 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c05067f1-1900-0000-82b5-ed849a130000 pid=5018 clone guuid=093057f2-1900-0000-82b5-ed849f130000 pid=5023 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=093057f2-1900-0000-82b5-ed849f130000 pid=5023 execve guuid=0942d9f2-1900-0000-82b5-ed84a1130000 pid=5025 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0942d9f2-1900-0000-82b5-ed84a1130000 pid=5025 execve guuid=97c4f3f8-1900-0000-82b5-ed84b3130000 pid=5043 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=97c4f3f8-1900-0000-82b5-ed84b3130000 pid=5043 execve guuid=0ea10601-1a00-0000-82b5-ed84cb130000 pid=5067 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0ea10601-1a00-0000-82b5-ed84cb130000 pid=5067 execve guuid=dd845301-1a00-0000-82b5-ed84cc130000 pid=5068 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=dd845301-1a00-0000-82b5-ed84cc130000 pid=5068 clone guuid=3b60e801-1a00-0000-82b5-ed84d0130000 pid=5072 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=3b60e801-1a00-0000-82b5-ed84d0130000 pid=5072 execve guuid=d9f2040b-1a00-0000-82b5-ed84d8130000 pid=5080 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=d9f2040b-1a00-0000-82b5-ed84d8130000 pid=5080 execve guuid=7062cc11-1a00-0000-82b5-ed84ee130000 pid=5102 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=7062cc11-1a00-0000-82b5-ed84ee130000 pid=5102 execve guuid=8a41f019-1a00-0000-82b5-ed8418140000 pid=5144 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8a41f019-1a00-0000-82b5-ed8418140000 pid=5144 execve guuid=bf12331a-1a00-0000-82b5-ed8419140000 pid=5145 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=bf12331a-1a00-0000-82b5-ed8419140000 pid=5145 clone guuid=c785b71a-1a00-0000-82b5-ed841f140000 pid=5151 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c785b71a-1a00-0000-82b5-ed841f140000 pid=5151 execve guuid=ba8cfd1a-1a00-0000-82b5-ed8421140000 pid=5153 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=ba8cfd1a-1a00-0000-82b5-ed8421140000 pid=5153 execve guuid=67dde61f-1a00-0000-82b5-ed8436140000 pid=5174 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=67dde61f-1a00-0000-82b5-ed8436140000 pid=5174 execve guuid=b2a08225-1a00-0000-82b5-ed8446140000 pid=5190 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=b2a08225-1a00-0000-82b5-ed8446140000 pid=5190 execve guuid=a57dc025-1a00-0000-82b5-ed8448140000 pid=5192 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=a57dc025-1a00-0000-82b5-ed8448140000 pid=5192 clone guuid=8cf03626-1a00-0000-82b5-ed844b140000 pid=5195 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=8cf03626-1a00-0000-82b5-ed844b140000 pid=5195 execve guuid=20588d26-1a00-0000-82b5-ed844e140000 pid=5198 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=20588d26-1a00-0000-82b5-ed844e140000 pid=5198 execve guuid=a5cde92c-1a00-0000-82b5-ed845f140000 pid=5215 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=a5cde92c-1a00-0000-82b5-ed845f140000 pid=5215 execve guuid=c707ec33-1a00-0000-82b5-ed8476140000 pid=5238 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c707ec33-1a00-0000-82b5-ed8476140000 pid=5238 execve guuid=0a393c34-1a00-0000-82b5-ed8479140000 pid=5241 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0a393c34-1a00-0000-82b5-ed8479140000 pid=5241 clone guuid=3b38ed34-1a00-0000-82b5-ed847d140000 pid=5245 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=3b38ed34-1a00-0000-82b5-ed847d140000 pid=5245 execve guuid=2f034335-1a00-0000-82b5-ed847f140000 pid=5247 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=2f034335-1a00-0000-82b5-ed847f140000 pid=5247 execve guuid=a139b93b-1a00-0000-82b5-ed84aa140000 pid=5290 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=a139b93b-1a00-0000-82b5-ed84aa140000 pid=5290 execve guuid=84ce1043-1a00-0000-82b5-ed84b9140000 pid=5305 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=84ce1043-1a00-0000-82b5-ed84b9140000 pid=5305 execve guuid=64f25843-1a00-0000-82b5-ed84ba140000 pid=5306 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=64f25843-1a00-0000-82b5-ed84ba140000 pid=5306 clone guuid=89ed0644-1a00-0000-82b5-ed84bc140000 pid=5308 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=89ed0644-1a00-0000-82b5-ed84bc140000 pid=5308 execve guuid=67c85d44-1a00-0000-82b5-ed84bd140000 pid=5309 /usr/bin/wget net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=67c85d44-1a00-0000-82b5-ed84bd140000 pid=5309 execve guuid=0d32384a-1a00-0000-82b5-ed84be140000 pid=5310 /usr/bin/curl net send-data write-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=0d32384a-1a00-0000-82b5-ed84be140000 pid=5310 execve guuid=64ff4b51-1a00-0000-82b5-ed84bf140000 pid=5311 /usr/bin/chmod guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=64ff4b51-1a00-0000-82b5-ed84bf140000 pid=5311 execve guuid=d786a551-1a00-0000-82b5-ed84c0140000 pid=5312 /usr/bin/bash guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=d786a551-1a00-0000-82b5-ed84c0140000 pid=5312 clone guuid=88a26352-1a00-0000-82b5-ed84c2140000 pid=5314 /usr/bin/rm delete-file guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=88a26352-1a00-0000-82b5-ed84c2140000 pid=5314 execve guuid=c424c552-1a00-0000-82b5-ed84c3140000 pid=5315 /usr/bin/rm guuid=0c187b2e-1900-0000-82b5-ed84d6100000 pid=4310->guuid=c424c552-1a00-0000-82b5-ed84c3140000 pid=5315 execve 6beadc35-efc4-5e26-84e6-0089cd490f0e 196.251.73.24:80 guuid=0c9ab433-1900-0000-82b5-ed84e6100000 pid=4326->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=b3a5033a-1900-0000-82b5-ed8401110000 pid=4353->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=7c784544-1900-0000-82b5-ed8423110000 pid=4387->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9e33f444-1900-0000-82b5-ed8426110000 pid=4390 /tmp/morte.x86 guuid=7c784544-1900-0000-82b5-ed8423110000 pid=4387->guuid=9e33f444-1900-0000-82b5-ed8426110000 pid=4390 clone guuid=338c1045-1900-0000-82b5-ed8428110000 pid=4392 /tmp/morte.x86 write-config zombie guuid=9e33f444-1900-0000-82b5-ed8426110000 pid=4390->guuid=338c1045-1900-0000-82b5-ed8428110000 pid=4392 clone guuid=2ea2ce48-1900-0000-82b5-ed843b110000 pid=4411 /usr/bin/dash guuid=338c1045-1900-0000-82b5-ed8428110000 pid=4392->guuid=2ea2ce48-1900-0000-82b5-ed843b110000 pid=4411 execve guuid=9e89124b-1900-0000-82b5-ed8448110000 pid=4424 /tmp/morte.x86 delete-file dns net send-data zombie guuid=338c1045-1900-0000-82b5-ed8428110000 pid=4392->guuid=9e89124b-1900-0000-82b5-ed8448110000 pid=4424 clone guuid=590d4a45-1900-0000-82b5-ed842a110000 pid=4394->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=bf412249-1900-0000-82b5-ed843c110000 pid=4412 /usr/bin/cp guuid=2ea2ce48-1900-0000-82b5-ed843b110000 pid=4411->guuid=bf412249-1900-0000-82b5-ed843c110000 pid=4412 execve guuid=9e89124b-1900-0000-82b5-ed8448110000 pid=4424->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B debdf84d-299e-545d-934e-259ecac9681a riseonid.com:12121 guuid=9e89124b-1900-0000-82b5-ed8448110000 pid=4424->debdf84d-299e-545d-934e-259ecac9681a send: 23B guuid=e969804b-1900-0000-82b5-ed844a110000 pid=4426->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=17b16657-1900-0000-82b5-ed8484110000 pid=4484->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 142B guuid=7f668a5e-1900-0000-82b5-ed84a0110000 pid=4512->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 91B guuid=8f8fef6d-1900-0000-82b5-ed84e6110000 pid=4582->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=6e3c8772-1900-0000-82b5-ed84f7110000 pid=4599->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=c82d297d-1900-0000-82b5-ed841d120000 pid=4637->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 143B guuid=72b49b83-1900-0000-82b5-ed842d120000 pid=4653->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 92B guuid=2f1f868a-1900-0000-82b5-ed844d120000 pid=4685->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=651b038b-1900-0000-82b5-ed8450120000 pid=4688 /tmp/morte.i686 guuid=2f1f868a-1900-0000-82b5-ed844d120000 pid=4685->guuid=651b038b-1900-0000-82b5-ed8450120000 pid=4688 clone guuid=14dd168b-1900-0000-82b5-ed8452120000 pid=4690 /tmp/morte.i686 write-config zombie guuid=651b038b-1900-0000-82b5-ed8450120000 pid=4688->guuid=14dd168b-1900-0000-82b5-ed8452120000 pid=4690 clone guuid=13afd08e-1900-0000-82b5-ed846b120000 pid=4715 /usr/bin/dash guuid=14dd168b-1900-0000-82b5-ed8452120000 pid=4690->guuid=13afd08e-1900-0000-82b5-ed846b120000 pid=4715 execve guuid=4e1afe90-1900-0000-82b5-ed8478120000 pid=4728 /tmp/morte.i686 delete-file guuid=14dd168b-1900-0000-82b5-ed8452120000 pid=4690->guuid=4e1afe90-1900-0000-82b5-ed8478120000 pid=4728 clone guuid=e7694f41-1b00-0000-82b5-ed84d6140000 pid=5334 /tmp/morte.i686 dns net send-data guuid=14dd168b-1900-0000-82b5-ed8452120000 pid=4690->guuid=e7694f41-1b00-0000-82b5-ed84d6140000 pid=5334 clone guuid=f81aa18b-1900-0000-82b5-ed8456120000 pid=4694->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 145B guuid=5de4fa8e-1900-0000-82b5-ed846c120000 pid=4716 /usr/bin/cp guuid=13afd08e-1900-0000-82b5-ed846b120000 pid=4715->guuid=5de4fa8e-1900-0000-82b5-ed846c120000 pid=4716 execve guuid=8d1fd490-1900-0000-82b5-ed8475120000 pid=4725->6beadc35-efc4-5e26-84e6-0089cd490f0e send: 94B guuid=80f67997-1900-0000-82b5-ed849e120000 pid=4766->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c3d7dd97-1900-0000-82b5-ed84a0120000 pid=4768 /tmp/morte.x86_64 zombie guuid=80f67997-1900-0000-82b5-ed849e120000 pid=4766->guuid=c3d7dd97-1900-0000-82b5-ed84a0120000 pid=4768 clone guuid=d65a7b98-1900-0000-82b5-ed84a5120000 pid=4773 /tmp/morte.x86_64 write-config zombie guuid=c3d7dd97-1900-0000-82b5-ed84a0120000 pid=4768->guuid=d65a7b98-1900-0000-82b5-ed84a5120000 pid=4773 clone dcd0c388-ab1e-53dc-878c-c7efac1522a9 riseonid.com:80 guuid=a0a75698-1900-0000-82b5-ed84a4120000 pid=4772->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=f6c78099-1900-0000-82b5-ed84a9120000 pid=4777 /usr/bin/dash guuid=d65a7b98-1900-0000-82b5-ed84a5120000 pid=4773->guuid=f6c78099-1900-0000-82b5-ed84a9120000 pid=4777 execve guuid=989e399a-1900-0000-82b5-ed84ae120000 pid=4782 /tmp/morte.x86_64 dns net send-data guuid=d65a7b98-1900-0000-82b5-ed84a5120000 pid=4773->guuid=989e399a-1900-0000-82b5-ed84ae120000 pid=4782 clone guuid=d440ac99-1900-0000-82b5-ed84aa120000 pid=4778 /usr/bin/cp guuid=f6c78099-1900-0000-82b5-ed84a9120000 pid=4777->guuid=d440ac99-1900-0000-82b5-ed84aa120000 pid=4778 execve guuid=989e399a-1900-0000-82b5-ed84ae120000 pid=4782->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B guuid=989e399a-1900-0000-82b5-ed84ae120000 pid=4782->debdf84d-299e-545d-934e-259ecac9681a send: 29B guuid=20548a9e-1900-0000-82b5-ed84be120000 pid=4798->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=bad491d6-1900-0000-82b5-ed844b130000 pid=4939->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=0fca8bdb-1900-0000-82b5-ed8459130000 pid=4953->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=8cfe73e5-1900-0000-82b5-ed847a130000 pid=4986->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=4a2fcfea-1900-0000-82b5-ed8487130000 pid=4999->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=0942d9f2-1900-0000-82b5-ed84a1130000 pid=5025->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=97c4f3f8-1900-0000-82b5-ed84b3130000 pid=5043->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=d9f2040b-1a00-0000-82b5-ed84d8130000 pid=5080->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=7062cc11-1a00-0000-82b5-ed84ee130000 pid=5102->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=ba8cfd1a-1a00-0000-82b5-ed8421140000 pid=5153->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=67dde61f-1a00-0000-82b5-ed8436140000 pid=5174->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=20588d26-1a00-0000-82b5-ed844e140000 pid=5198->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=a5cde92c-1a00-0000-82b5-ed845f140000 pid=5215->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=2f034335-1a00-0000-82b5-ed847f140000 pid=5247->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 143B guuid=a139b93b-1a00-0000-82b5-ed84aa140000 pid=5290->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 92B guuid=67c85d44-1a00-0000-82b5-ed84bd140000 pid=5309->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 142B guuid=0d32384a-1a00-0000-82b5-ed84be140000 pid=5310->dcd0c388-ab1e-53dc-878c-c7efac1522a9 send: 91B guuid=e7694f41-1b00-0000-82b5-ed84d6140000 pid=5334->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 30B guuid=e7694f41-1b00-0000-82b5-ed84d6140000 pid=5334->debdf84d-299e-545d-934e-259ecac9681a send: 27B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-22 13:31:45 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b7b27434c69d07768debb963f2f9671ba28f7a43db8fb0b71f88f3c6a12f8e26

(this sample)

  
Delivery method
Distributed via web download

Comments