MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ba00792f880e3821207ce96396089fa0213bff59a549e44879315582cbdc60c2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: ba00792f880e3821207ce96396089fa0213bff59a549e44879315582cbdc60c2
SHA3-384 hash: 3a79705738ba9f97a39c09dfed14554b274321057d7f4e4d487996c57ee21c86f2752dac423e159b33dea2799a15e502
SHA1 hash: efcd9737ed3abece72e9fd00f12b9c98b8105265
MD5 hash: e30e0155f6b5e621a369525e03b0b070
humanhash: kitten-lemon-yankee-colorado
File name:1.sh
Download: download sample
Signature Mirai
File size:3'077 bytes
First seen:2025-07-22 05:48:27 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Y/ZsnbhTkzlfbmsvToLGgJv63nLONNIpKks/ME5hzsoncGgJsYApk:YqlAxT7oL1SXLCJ5bIonBgJsvk
TLSH T1925183E663814AB32CBA8DDB36A84884735D50DFE4AF9F3AD5D8F4E9028EF187440741
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.213.240.242/bins/morte.x866b89288f82c10313cc04d6801994f61ae0f454a8e49ae902416549475d22563e Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.mipsdb7c3f4a4d9955f60e2428d33081b7516d2b05a554549ef7435ad5f0da26aebc Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arcbc7ba0be21d0bd4d5f8ffba11fb517a6128ed67aaee485f4e9ad55ebb206dfd7 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.i468n/an/aelf opendir ua-wget
http://185.213.240.242/bins/morte.i686ec6877d780e5c08a52316ed53c1e24688df1bb77573a73552807b446682303e1 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.x86_640f3d5843dbea20320950015e6b16d397ead64d3a0cc0c0c9d236ab0c329e5c3c Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.mpsl6a381680badfe72a680a7ebbac5a87b69b92bef8cf495dea18c08768ae4a8104 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm1e084f768e6f712bd7a6550bfd1d6651475110be15afdaf20ea165035e41825b Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm5bb58685e750ea7ea86ef5e8e0272309259225751e891a8180edeb43f00e12237 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm6fc5cd925ce297000ca57784ead53c74be59b7f1947fe30fc596b8288b58e34ac Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.arm7f668ad9e7208fb93503504745e844534c2f1cd03bb8be6580ceb107b2f3e5c1f Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.ppc4c2307922752b1dda4168efb06f7f577df1e1a6b559b16e290533fa875bbfb67 Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.spc600fc077b364f1e19774afc961c350ca78168a7c89985b8d649d18a784bb54ca Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.m68kb34ab7b3235520d509129dbf8ce61fa4aaf07c689caf1086678d209c2bdfb15f Miraielf mirai opendir ua-wget
http://185.213.240.242/bins/morte.sh4aeaca0a823b1c1ba1fef65021e4435d355d8da6763b976bfecfe002a17023b80 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=4a4e04cd-1c00-0000-87ea-237cda030000 pid=986 /usr/bin/sudo guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993 /tmp/sample.bin guuid=4a4e04cd-1c00-0000-87ea-237cda030000 pid=986->guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993 execve guuid=5f651bcf-1c00-0000-87ea-237ce4030000 pid=996 /usr/bin/cp guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=5f651bcf-1c00-0000-87ea-237ce4030000 pid=996 execve guuid=41118cd1-1c00-0000-87ea-237cea030000 pid=1002 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=41118cd1-1c00-0000-87ea-237cea030000 pid=1002 execve guuid=0fef58d7-1c00-0000-87ea-237cf8030000 pid=1016 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=0fef58d7-1c00-0000-87ea-237cf8030000 pid=1016 execve guuid=7e6339e6-1c00-0000-87ea-237c13040000 pid=1043 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=7e6339e6-1c00-0000-87ea-237c13040000 pid=1043 execve guuid=5b73bde6-1c00-0000-87ea-237c14040000 pid=1044 /tmp/morte.x86 net guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=5b73bde6-1c00-0000-87ea-237c14040000 pid=1044 execve guuid=95e232e7-1c00-0000-87ea-237c16040000 pid=1046 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=95e232e7-1c00-0000-87ea-237c16040000 pid=1046 execve guuid=8e25a7e7-1c00-0000-87ea-237c19040000 pid=1049 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=8e25a7e7-1c00-0000-87ea-237c19040000 pid=1049 execve guuid=96ad5bec-1c00-0000-87ea-237c2a040000 pid=1066 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=96ad5bec-1c00-0000-87ea-237c2a040000 pid=1066 execve guuid=fb7e79f2-1c00-0000-87ea-237c39040000 pid=1081 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=fb7e79f2-1c00-0000-87ea-237c39040000 pid=1081 execve guuid=513bbcf2-1c00-0000-87ea-237c3b040000 pid=1083 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=513bbcf2-1c00-0000-87ea-237c3b040000 pid=1083 clone guuid=63b539f3-1c00-0000-87ea-237c40040000 pid=1088 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=63b539f3-1c00-0000-87ea-237c40040000 pid=1088 execve guuid=b367f7f7-1c00-0000-87ea-237c43040000 pid=1091 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=b367f7f7-1c00-0000-87ea-237c43040000 pid=1091 execve guuid=246977fd-1c00-0000-87ea-237c52040000 pid=1106 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=246977fd-1c00-0000-87ea-237c52040000 pid=1106 execve guuid=ca124305-1d00-0000-87ea-237c69040000 pid=1129 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=ca124305-1d00-0000-87ea-237c69040000 pid=1129 execve guuid=e6a77a05-1d00-0000-87ea-237c6b040000 pid=1131 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=e6a77a05-1d00-0000-87ea-237c6b040000 pid=1131 clone guuid=2090ef05-1d00-0000-87ea-237c6f040000 pid=1135 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2090ef05-1d00-0000-87ea-237c6f040000 pid=1135 execve guuid=3ddf1208-1d00-0000-87ea-237c74040000 pid=1140 /usr/bin/wget net send-data guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=3ddf1208-1d00-0000-87ea-237c74040000 pid=1140 execve guuid=2406e40a-1d00-0000-87ea-237c7d040000 pid=1149 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2406e40a-1d00-0000-87ea-237c7d040000 pid=1149 execve guuid=2e9f300f-1d00-0000-87ea-237c88040000 pid=1160 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2e9f300f-1d00-0000-87ea-237c88040000 pid=1160 execve guuid=4f38880f-1d00-0000-87ea-237c89040000 pid=1161 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=4f38880f-1d00-0000-87ea-237c89040000 pid=1161 clone guuid=8fdaab0f-1d00-0000-87ea-237c8a040000 pid=1162 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=8fdaab0f-1d00-0000-87ea-237c8a040000 pid=1162 execve guuid=ac5b1b10-1d00-0000-87ea-237c8c040000 pid=1164 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=ac5b1b10-1d00-0000-87ea-237c8c040000 pid=1164 execve guuid=b2a9f314-1d00-0000-87ea-237c99040000 pid=1177 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=b2a9f314-1d00-0000-87ea-237c99040000 pid=1177 execve guuid=2461251b-1d00-0000-87ea-237cab040000 pid=1195 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2461251b-1d00-0000-87ea-237cab040000 pid=1195 execve guuid=7e507c1b-1d00-0000-87ea-237cad040000 pid=1197 /tmp/morte.i686 net guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=7e507c1b-1d00-0000-87ea-237cad040000 pid=1197 execve guuid=89b9c01b-1d00-0000-87ea-237cb0040000 pid=1200 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=89b9c01b-1d00-0000-87ea-237cb0040000 pid=1200 execve guuid=04eb221c-1d00-0000-87ea-237cb3040000 pid=1203 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=04eb221c-1d00-0000-87ea-237cb3040000 pid=1203 execve guuid=88ee4222-1d00-0000-87ea-237cc2040000 pid=1218 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=88ee4222-1d00-0000-87ea-237cc2040000 pid=1218 execve guuid=ce00ce29-1d00-0000-87ea-237cd6040000 pid=1238 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=ce00ce29-1d00-0000-87ea-237cd6040000 pid=1238 execve guuid=4760032a-1d00-0000-87ea-237cd8040000 pid=1240 /tmp/morte.x86_64 mprotect-exec net guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=4760032a-1d00-0000-87ea-237cd8040000 pid=1240 execve guuid=dc17672a-1d00-0000-87ea-237cdc040000 pid=1244 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=dc17672a-1d00-0000-87ea-237cdc040000 pid=1244 execve guuid=52e3a72a-1d00-0000-87ea-237cde040000 pid=1246 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=52e3a72a-1d00-0000-87ea-237cde040000 pid=1246 execve guuid=f662682f-1d00-0000-87ea-237ce7040000 pid=1255 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f662682f-1d00-0000-87ea-237ce7040000 pid=1255 execve guuid=1eaf5e36-1d00-0000-87ea-237cf9040000 pid=1273 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=1eaf5e36-1d00-0000-87ea-237cf9040000 pid=1273 execve guuid=f4c3c036-1d00-0000-87ea-237cfb040000 pid=1275 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f4c3c036-1d00-0000-87ea-237cfb040000 pid=1275 clone guuid=f107c337-1d00-0000-87ea-237cff040000 pid=1279 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f107c337-1d00-0000-87ea-237cff040000 pid=1279 execve guuid=43c72038-1d00-0000-87ea-237c00050000 pid=1280 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=43c72038-1d00-0000-87ea-237c00050000 pid=1280 execve guuid=2dc8403c-1d00-0000-87ea-237c0a050000 pid=1290 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2dc8403c-1d00-0000-87ea-237c0a050000 pid=1290 execve guuid=2fd0f040-1d00-0000-87ea-237c15050000 pid=1301 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=2fd0f040-1d00-0000-87ea-237c15050000 pid=1301 execve guuid=26ef4141-1d00-0000-87ea-237c17050000 pid=1303 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=26ef4141-1d00-0000-87ea-237c17050000 pid=1303 clone guuid=35b3f341-1d00-0000-87ea-237c1c050000 pid=1308 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=35b3f341-1d00-0000-87ea-237c1c050000 pid=1308 execve guuid=4bffa648-1d00-0000-87ea-237c20050000 pid=1312 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=4bffa648-1d00-0000-87ea-237c20050000 pid=1312 execve guuid=32e7c34d-1d00-0000-87ea-237c27050000 pid=1319 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=32e7c34d-1d00-0000-87ea-237c27050000 pid=1319 execve guuid=9711d953-1d00-0000-87ea-237c31050000 pid=1329 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=9711d953-1d00-0000-87ea-237c31050000 pid=1329 execve guuid=ce3c3a54-1d00-0000-87ea-237c32050000 pid=1330 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=ce3c3a54-1d00-0000-87ea-237c32050000 pid=1330 clone guuid=02884555-1d00-0000-87ea-237c36050000 pid=1334 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=02884555-1d00-0000-87ea-237c36050000 pid=1334 execve guuid=e1e9d255-1d00-0000-87ea-237c38050000 pid=1336 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=e1e9d255-1d00-0000-87ea-237c38050000 pid=1336 execve guuid=a23a5d5b-1d00-0000-87ea-237c41050000 pid=1345 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=a23a5d5b-1d00-0000-87ea-237c41050000 pid=1345 execve guuid=f75cb261-1d00-0000-87ea-237c4c050000 pid=1356 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f75cb261-1d00-0000-87ea-237c4c050000 pid=1356 execve guuid=05612b62-1d00-0000-87ea-237c4d050000 pid=1357 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=05612b62-1d00-0000-87ea-237c4d050000 pid=1357 clone guuid=efbe1e63-1d00-0000-87ea-237c4f050000 pid=1359 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=efbe1e63-1d00-0000-87ea-237c4f050000 pid=1359 execve guuid=e3ed2c6d-1d00-0000-87ea-237c50050000 pid=1360 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=e3ed2c6d-1d00-0000-87ea-237c50050000 pid=1360 execve guuid=1b737073-1d00-0000-87ea-237c5a050000 pid=1370 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=1b737073-1d00-0000-87ea-237c5a050000 pid=1370 execve guuid=b5b08b7a-1d00-0000-87ea-237c64050000 pid=1380 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=b5b08b7a-1d00-0000-87ea-237c64050000 pid=1380 execve guuid=d7461a7b-1d00-0000-87ea-237c65050000 pid=1381 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=d7461a7b-1d00-0000-87ea-237c65050000 pid=1381 clone guuid=be52737c-1d00-0000-87ea-237c67050000 pid=1383 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=be52737c-1d00-0000-87ea-237c67050000 pid=1383 execve guuid=8a124880-1d00-0000-87ea-237c69050000 pid=1385 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=8a124880-1d00-0000-87ea-237c69050000 pid=1385 execve guuid=7abad385-1d00-0000-87ea-237c73050000 pid=1395 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=7abad385-1d00-0000-87ea-237c73050000 pid=1395 execve guuid=c38b498c-1d00-0000-87ea-237c80050000 pid=1408 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=c38b498c-1d00-0000-87ea-237c80050000 pid=1408 execve guuid=3816ab8c-1d00-0000-87ea-237c82050000 pid=1410 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=3816ab8c-1d00-0000-87ea-237c82050000 pid=1410 clone guuid=9717688d-1d00-0000-87ea-237c85050000 pid=1413 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=9717688d-1d00-0000-87ea-237c85050000 pid=1413 execve guuid=f471d48d-1d00-0000-87ea-237c87050000 pid=1415 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f471d48d-1d00-0000-87ea-237c87050000 pid=1415 execve guuid=93b11b94-1d00-0000-87ea-237c93050000 pid=1427 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=93b11b94-1d00-0000-87ea-237c93050000 pid=1427 execve guuid=1270b99b-1d00-0000-87ea-237ca0050000 pid=1440 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=1270b99b-1d00-0000-87ea-237ca0050000 pid=1440 execve guuid=8951399c-1d00-0000-87ea-237ca2050000 pid=1442 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=8951399c-1d00-0000-87ea-237ca2050000 pid=1442 clone guuid=c56cde9c-1d00-0000-87ea-237ca6050000 pid=1446 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=c56cde9c-1d00-0000-87ea-237ca6050000 pid=1446 execve guuid=f4102c9d-1d00-0000-87ea-237ca8050000 pid=1448 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=f4102c9d-1d00-0000-87ea-237ca8050000 pid=1448 execve guuid=442afca2-1d00-0000-87ea-237cb4050000 pid=1460 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=442afca2-1d00-0000-87ea-237cb4050000 pid=1460 execve guuid=79fbb0aa-1d00-0000-87ea-237cc1050000 pid=1473 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=79fbb0aa-1d00-0000-87ea-237cc1050000 pid=1473 execve guuid=a66c07ab-1d00-0000-87ea-237cc2050000 pid=1474 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=a66c07ab-1d00-0000-87ea-237cc2050000 pid=1474 clone guuid=c27bc2ab-1d00-0000-87ea-237cc6050000 pid=1478 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=c27bc2ab-1d00-0000-87ea-237cc6050000 pid=1478 execve guuid=76c70aac-1d00-0000-87ea-237cc8050000 pid=1480 /usr/bin/wget net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=76c70aac-1d00-0000-87ea-237cc8050000 pid=1480 execve guuid=9a538ab1-1d00-0000-87ea-237cd0050000 pid=1488 /usr/bin/curl net send-data write-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=9a538ab1-1d00-0000-87ea-237cd0050000 pid=1488 execve guuid=8a16cab7-1d00-0000-87ea-237cda050000 pid=1498 /usr/bin/chmod guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=8a16cab7-1d00-0000-87ea-237cda050000 pid=1498 execve guuid=ffdd37b8-1d00-0000-87ea-237cdc050000 pid=1500 /usr/bin/bash guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=ffdd37b8-1d00-0000-87ea-237cdc050000 pid=1500 clone guuid=bd67f1b8-1d00-0000-87ea-237ce1050000 pid=1505 /usr/bin/rm delete-file guuid=a581abce-1c00-0000-87ea-237ce1030000 pid=993->guuid=bd67f1b8-1d00-0000-87ea-237ce1050000 pid=1505 execve 6257db47-794e-52cb-98db-8da39c87047c 185.213.240.242:80 guuid=41118cd1-1c00-0000-87ea-237cea030000 pid=1002->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=0fef58d7-1c00-0000-87ea-237cf8030000 pid=1016->6257db47-794e-52cb-98db-8da39c87047c send: 93B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5b73bde6-1c00-0000-87ea-237c14040000 pid=1044->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a09620e7-1c00-0000-87ea-237c15040000 pid=1045 /tmp/morte.x86 guuid=5b73bde6-1c00-0000-87ea-237c14040000 pid=1044->guuid=a09620e7-1c00-0000-87ea-237c15040000 pid=1045 clone guuid=f8ee3fe7-1c00-0000-87ea-237c17040000 pid=1047 /tmp/morte.x86 write-config zombie guuid=a09620e7-1c00-0000-87ea-237c15040000 pid=1045->guuid=f8ee3fe7-1c00-0000-87ea-237c17040000 pid=1047 clone guuid=fd15a0eb-1c00-0000-87ea-237c26040000 pid=1062 /usr/bin/dash guuid=f8ee3fe7-1c00-0000-87ea-237c17040000 pid=1047->guuid=fd15a0eb-1c00-0000-87ea-237c26040000 pid=1062 execve guuid=d50631ee-1c00-0000-87ea-237c2e040000 pid=1070 /tmp/morte.x86 delete-file guuid=f8ee3fe7-1c00-0000-87ea-237c17040000 pid=1047->guuid=d50631ee-1c00-0000-87ea-237c2e040000 pid=1070 clone guuid=8e25a7e7-1c00-0000-87ea-237c19040000 pid=1049->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=557bcfeb-1c00-0000-87ea-237c27040000 pid=1063 /usr/bin/cp guuid=fd15a0eb-1c00-0000-87ea-237c26040000 pid=1062->guuid=557bcfeb-1c00-0000-87ea-237c27040000 pid=1063 execve guuid=96ad5bec-1c00-0000-87ea-237c2a040000 pid=1066->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=b367f7f7-1c00-0000-87ea-237c43040000 pid=1091->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=246977fd-1c00-0000-87ea-237c52040000 pid=1106->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=3ddf1208-1d00-0000-87ea-237c74040000 pid=1140->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=2406e40a-1d00-0000-87ea-237c7d040000 pid=1149->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=ac5b1b10-1d00-0000-87ea-237c8c040000 pid=1164->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=b2a9f314-1d00-0000-87ea-237c99040000 pid=1177->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=7e507c1b-1d00-0000-87ea-237cad040000 pid=1197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06d9b81b-1d00-0000-87ea-237caf040000 pid=1199 /tmp/morte.i686 guuid=7e507c1b-1d00-0000-87ea-237cad040000 pid=1197->guuid=06d9b81b-1d00-0000-87ea-237caf040000 pid=1199 clone guuid=43922c1c-1d00-0000-87ea-237cb4040000 pid=1204 /tmp/morte.i686 write-config zombie guuid=06d9b81b-1d00-0000-87ea-237caf040000 pid=1199->guuid=43922c1c-1d00-0000-87ea-237cb4040000 pid=1204 clone guuid=04eb221c-1d00-0000-87ea-237cb3040000 pid=1203->6257db47-794e-52cb-98db-8da39c87047c send: 147B guuid=321f2420-1d00-0000-87ea-237cbc040000 pid=1212 /usr/bin/dash guuid=43922c1c-1d00-0000-87ea-237cb4040000 pid=1204->guuid=321f2420-1d00-0000-87ea-237cbc040000 pid=1212 execve guuid=431b1b23-1d00-0000-87ea-237cc6040000 pid=1222 /tmp/morte.i686 dns net send-data guuid=43922c1c-1d00-0000-87ea-237cb4040000 pid=1204->guuid=431b1b23-1d00-0000-87ea-237cc6040000 pid=1222 clone guuid=27285b20-1d00-0000-87ea-237cbd040000 pid=1213 /usr/bin/cp guuid=321f2420-1d00-0000-87ea-237cbc040000 pid=1212->guuid=27285b20-1d00-0000-87ea-237cbd040000 pid=1213 execve guuid=88ee4222-1d00-0000-87ea-237cc2040000 pid=1218->6257db47-794e-52cb-98db-8da39c87047c send: 96B guuid=431b1b23-1d00-0000-87ea-237cc6040000 pid=1222->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B 1bbb4005-5fa7-5147-8924-030d465cc44a vipcncnetwork.com:12121 guuid=431b1b23-1d00-0000-87ea-237cc6040000 pid=1222->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B guuid=4760032a-1d00-0000-87ea-237cd8040000 pid=1240->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6c035f2a-1d00-0000-87ea-237cda040000 pid=1242 /tmp/morte.x86_64 zombie guuid=4760032a-1d00-0000-87ea-237cd8040000 pid=1240->guuid=6c035f2a-1d00-0000-87ea-237cda040000 pid=1242 clone guuid=8429ad2a-1d00-0000-87ea-237cdf040000 pid=1247 /tmp/morte.x86_64 write-config zombie guuid=6c035f2a-1d00-0000-87ea-237cda040000 pid=1242->guuid=8429ad2a-1d00-0000-87ea-237cdf040000 pid=1247 clone guuid=52e3a72a-1d00-0000-87ea-237cde040000 pid=1246->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=e89c6c2b-1d00-0000-87ea-237ce3040000 pid=1251 /usr/bin/dash guuid=8429ad2a-1d00-0000-87ea-237cdf040000 pid=1247->guuid=e89c6c2b-1d00-0000-87ea-237ce3040000 pid=1251 execve guuid=17b8372c-1d00-0000-87ea-237ce5040000 pid=1253 /tmp/morte.x86_64 delete-file dns net send-data zombie guuid=8429ad2a-1d00-0000-87ea-237cdf040000 pid=1247->guuid=17b8372c-1d00-0000-87ea-237ce5040000 pid=1253 clone guuid=6600912b-1d00-0000-87ea-237ce4040000 pid=1252 /usr/bin/cp guuid=e89c6c2b-1d00-0000-87ea-237ce3040000 pid=1251->guuid=6600912b-1d00-0000-87ea-237ce4040000 pid=1252 execve guuid=17b8372c-1d00-0000-87ea-237ce5040000 pid=1253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 35B guuid=17b8372c-1d00-0000-87ea-237ce5040000 pid=1253->1bbb4005-5fa7-5147-8924-030d465cc44a send: 25B guuid=f662682f-1d00-0000-87ea-237ce7040000 pid=1255->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=43c72038-1d00-0000-87ea-237c00050000 pid=1280->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=2dc8403c-1d00-0000-87ea-237c0a050000 pid=1290->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=4bffa648-1d00-0000-87ea-237c20050000 pid=1312->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=32e7c34d-1d00-0000-87ea-237c27050000 pid=1319->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=e1e9d255-1d00-0000-87ea-237c38050000 pid=1336->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=a23a5d5b-1d00-0000-87ea-237c41050000 pid=1345->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=e3ed2c6d-1d00-0000-87ea-237c50050000 pid=1360->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=1b737073-1d00-0000-87ea-237c5a050000 pid=1370->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=8a124880-1d00-0000-87ea-237c69050000 pid=1385->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=7abad385-1d00-0000-87ea-237c73050000 pid=1395->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=f471d48d-1d00-0000-87ea-237c87050000 pid=1415->6257db47-794e-52cb-98db-8da39c87047c send: 144B guuid=93b11b94-1d00-0000-87ea-237c93050000 pid=1427->6257db47-794e-52cb-98db-8da39c87047c send: 93B guuid=f4102c9d-1d00-0000-87ea-237ca8050000 pid=1448->6257db47-794e-52cb-98db-8da39c87047c send: 145B guuid=442afca2-1d00-0000-87ea-237cb4050000 pid=1460->6257db47-794e-52cb-98db-8da39c87047c send: 94B guuid=76c70aac-1d00-0000-87ea-237cc8050000 pid=1480->6257db47-794e-52cb-98db-8da39c87047c send: 144B 8ce41a07-531a-529b-8311-50f96849e8fa vipcncnetwork.com:80 guuid=9a538ab1-1d00-0000-87ea-237cd0050000 pid=1488->8ce41a07-531a-529b-8311-50f96849e8fa send: 93B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-22 05:49:20 UTC
File Type:
Text (Shell)
AV detection:
20 of 36 (55.56%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ba00792f880e3821207ce96396089fa0213bff59a549e44879315582cbdc60c2

(this sample)

  
Delivery method
Distributed via web download

Comments