MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bbdfa157a11857424d0b0adb3a66e863b0ea8441e2a0c92cb739e5d8ebc81516. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: bbdfa157a11857424d0b0adb3a66e863b0ea8441e2a0c92cb739e5d8ebc81516
SHA3-384 hash: fca6212d110b8b86975a90c1a7fc30448fba426e2e4c888a860f61d671925eefa19a157177af39c13ee8cdb2c1da460f
SHA1 hash: 004d677bce7e4cbea662eb5db930bd1d0be21309
MD5 hash: 48d064120fdd364bc7abaf9dae4fce41
humanhash: emma-equal-east-moon
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-07-27 17:46:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItduYZsdv1bhdsSkd/llfd5zmsd1PTdvgvGgJdi86dlfnLdBgBNIpKksdHdMEd7s:iSVk9Hfx81WbL4JpBY3iBgJsRk
TLSH T16161B0FA03A0A6336DEA8DD7B2AC0505754069BB15FE8F724FDC28E40C8DED86C85642
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.212.227.29/00101010101001/morte.x86bb8411d88ccf2db0b973f2b5ae42b296e00db8663086bc1ad571ec63290630a2 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.mipsde44217ea506f4a91125400520dca46e97606f1ce7c7ed81f8a1a3e561cb6ef3 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.arc3a9882d40e0fbe51fc065949f2a77d07bd26fb9cd7cceec5f805b6c48e4ac41c Miraimirai opendir
http://103.212.227.29/00101010101001/morte.i468n/an/an/a
http://103.212.227.29/00101010101001/morte.i686bce821858a5bac9383451287522111603041d22adef3c62ec826f59646fab712 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.x86_6415f675f733bf02b6202275a5085b1359fb614dc32dca5e0df6cefbc0c98b6cf3 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.mpsl9bcc387304f55d5c2592245d1aeb30e57349a14f33d77cc4d47f083e6fb35895 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.arm9c94452fe22fcb3462dc53acd40e31b019dd22ac2db55d314e0f526f9e3e5865 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.arm5f604378df57c92885d6ffddd225b35e8d640fcd4c7e4cb1821655cf0fa053018 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.arm6308bde152ec169241339f441958eca0760af29a79c0462dd8721a787e50b38b9 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.arm7d83bbd67e42d4ed4de290cb93e5b7b4ccd47b25955e063fc8068d37bfdc9526f Miraimirai opendir
http://103.212.227.29/00101010101001/morte.ppcfab8e909ac5bcbad2fd909a0c2554d8000574d4745c5b9415e9a4189681e3e01 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.spcff94f9812c5d5b49ced4a1f488d8fe738921ef699b301321e1161feb448e8f24 Miraimirai opendir
http://103.212.227.29/00101010101001/morte.m68k0edff82ad6363057e418ebd4be09fb0ab2bc881356c7f7bda9fd0f04493fb74f Miraimirai opendir
http://103.212.227.29/00101010101001/morte.sh4ecc6005560c69e83d965683f2d1deb800a801bfca69a45067e7b3fd307393e1b Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9cb5f72d-1f00-0000-af7b-952dc40a0000 pid=2756 /usr/bin/sudo guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762 /tmp/sample.bin guuid=9cb5f72d-1f00-0000-af7b-952dc40a0000 pid=2756->guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762 execve guuid=9247b832-1f00-0000-af7b-952dcd0a0000 pid=2765 /usr/bin/cp guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=9247b832-1f00-0000-af7b-952dcd0a0000 pid=2765 execve guuid=d5fae138-1f00-0000-af7b-952dd60a0000 pid=2774 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d5fae138-1f00-0000-af7b-952dd60a0000 pid=2774 execve guuid=6d413b69-1f00-0000-af7b-952d330b0000 pid=2867 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=6d413b69-1f00-0000-af7b-952d330b0000 pid=2867 execve guuid=0f3bb59b-1f00-0000-af7b-952d870b0000 pid=2951 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=0f3bb59b-1f00-0000-af7b-952d870b0000 pid=2951 execve guuid=b8a0079c-1f00-0000-af7b-952d890b0000 pid=2953 /tmp/morte.x86 net guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=b8a0079c-1f00-0000-af7b-952d890b0000 pid=2953 execve guuid=6ccf969c-1f00-0000-af7b-952d8c0b0000 pid=2956 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=6ccf969c-1f00-0000-af7b-952d8c0b0000 pid=2956 execve guuid=0158f89c-1f00-0000-af7b-952d8d0b0000 pid=2957 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=0158f89c-1f00-0000-af7b-952d8d0b0000 pid=2957 execve guuid=475598cb-1f00-0000-af7b-952d0b0c0000 pid=3083 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=475598cb-1f00-0000-af7b-952d0b0c0000 pid=3083 execve guuid=aec9d3fb-1f00-0000-af7b-952d750c0000 pid=3189 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=aec9d3fb-1f00-0000-af7b-952d750c0000 pid=3189 execve guuid=044636fc-1f00-0000-af7b-952d760c0000 pid=3190 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=044636fc-1f00-0000-af7b-952d760c0000 pid=3190 clone guuid=6e291bff-1f00-0000-af7b-952d780c0000 pid=3192 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=6e291bff-1f00-0000-af7b-952d780c0000 pid=3192 execve guuid=2cd090ff-1f00-0000-af7b-952d790c0000 pid=3193 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=2cd090ff-1f00-0000-af7b-952d790c0000 pid=3193 execve guuid=33e5e84c-2000-0000-af7b-952dc80c0000 pid=3272 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=33e5e84c-2000-0000-af7b-952dc80c0000 pid=3272 execve guuid=626d669d-2000-0000-af7b-952d680d0000 pid=3432 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=626d669d-2000-0000-af7b-952d680d0000 pid=3432 execve guuid=8f71b59d-2000-0000-af7b-952d6a0d0000 pid=3434 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=8f71b59d-2000-0000-af7b-952d6a0d0000 pid=3434 clone guuid=9e2b439e-2000-0000-af7b-952d6d0d0000 pid=3437 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=9e2b439e-2000-0000-af7b-952d6d0d0000 pid=3437 execve guuid=5f042b9f-2000-0000-af7b-952d700d0000 pid=3440 /usr/bin/wget net send-data guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=5f042b9f-2000-0000-af7b-952d700d0000 pid=3440 execve guuid=301871be-2000-0000-af7b-952dc10d0000 pid=3521 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=301871be-2000-0000-af7b-952dc10d0000 pid=3521 execve guuid=20e120df-2000-0000-af7b-952d120e0000 pid=3602 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=20e120df-2000-0000-af7b-952d120e0000 pid=3602 execve guuid=a1076adf-2000-0000-af7b-952d140e0000 pid=3604 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=a1076adf-2000-0000-af7b-952d140e0000 pid=3604 clone guuid=bb1d8edf-2000-0000-af7b-952d160e0000 pid=3606 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=bb1d8edf-2000-0000-af7b-952d160e0000 pid=3606 execve guuid=56f3cddf-2000-0000-af7b-952d170e0000 pid=3607 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=56f3cddf-2000-0000-af7b-952d170e0000 pid=3607 execve guuid=b0f92c0e-2100-0000-af7b-952d7b0e0000 pid=3707 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=b0f92c0e-2100-0000-af7b-952d7b0e0000 pid=3707 execve guuid=04420040-2100-0000-af7b-952d390f0000 pid=3897 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=04420040-2100-0000-af7b-952d390f0000 pid=3897 execve guuid=8b5b4940-2100-0000-af7b-952d3b0f0000 pid=3899 /tmp/morte.i686 net guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=8b5b4940-2100-0000-af7b-952d3b0f0000 pid=3899 execve guuid=59148840-2100-0000-af7b-952d3e0f0000 pid=3902 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=59148840-2100-0000-af7b-952d3e0f0000 pid=3902 execve guuid=784ecf40-2100-0000-af7b-952d410f0000 pid=3905 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=784ecf40-2100-0000-af7b-952d410f0000 pid=3905 execve guuid=32b41d6f-2100-0000-af7b-952dec0f0000 pid=4076 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=32b41d6f-2100-0000-af7b-952dec0f0000 pid=4076 execve guuid=39745b9f-2100-0000-af7b-952d89100000 pid=4233 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=39745b9f-2100-0000-af7b-952d89100000 pid=4233 execve guuid=218aa39f-2100-0000-af7b-952d8a100000 pid=4234 /tmp/morte.x86_64 mprotect-exec net guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=218aa39f-2100-0000-af7b-952d8a100000 pid=4234 execve guuid=532a3aa0-2100-0000-af7b-952d90100000 pid=4240 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=532a3aa0-2100-0000-af7b-952d90100000 pid=4240 execve guuid=c6cea0a0-2100-0000-af7b-952d92100000 pid=4242 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=c6cea0a0-2100-0000-af7b-952d92100000 pid=4242 execve guuid=ac832acf-2100-0000-af7b-952d35110000 pid=4405 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=ac832acf-2100-0000-af7b-952d35110000 pid=4405 execve guuid=9af3d2ff-2100-0000-af7b-952de2110000 pid=4578 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=9af3d2ff-2100-0000-af7b-952de2110000 pid=4578 execve guuid=3dfa4400-2200-0000-af7b-952de4110000 pid=4580 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=3dfa4400-2200-0000-af7b-952de4110000 pid=4580 clone guuid=9e49d301-2200-0000-af7b-952dec110000 pid=4588 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=9e49d301-2200-0000-af7b-952dec110000 pid=4588 execve guuid=e2744302-2200-0000-af7b-952dee110000 pid=4590 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=e2744302-2200-0000-af7b-952dee110000 pid=4590 execve guuid=5d79e430-2200-0000-af7b-952da6120000 pid=4774 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=5d79e430-2200-0000-af7b-952da6120000 pid=4774 execve guuid=8b3be161-2200-0000-af7b-952d2e130000 pid=4910 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=8b3be161-2200-0000-af7b-952d2e130000 pid=4910 execve guuid=c79e6e62-2200-0000-af7b-952d30130000 pid=4912 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=c79e6e62-2200-0000-af7b-952d30130000 pid=4912 clone guuid=da4fa063-2200-0000-af7b-952d35130000 pid=4917 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=da4fa063-2200-0000-af7b-952d35130000 pid=4917 execve guuid=7fe14284-2200-0000-af7b-952d78130000 pid=4984 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=7fe14284-2200-0000-af7b-952d78130000 pid=4984 execve guuid=e12640b3-2200-0000-af7b-952ded130000 pid=5101 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=e12640b3-2200-0000-af7b-952ded130000 pid=5101 execve guuid=a068e3e4-2200-0000-af7b-952d50140000 pid=5200 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=a068e3e4-2200-0000-af7b-952d50140000 pid=5200 execve guuid=61d06ee5-2200-0000-af7b-952d51140000 pid=5201 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=61d06ee5-2200-0000-af7b-952d51140000 pid=5201 clone guuid=578be9e6-2200-0000-af7b-952d55140000 pid=5205 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=578be9e6-2200-0000-af7b-952d55140000 pid=5205 execve guuid=cdfed8e7-2200-0000-af7b-952d58140000 pid=5208 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=cdfed8e7-2200-0000-af7b-952d58140000 pid=5208 execve guuid=d9df3b19-2300-0000-af7b-952da3140000 pid=5283 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d9df3b19-2300-0000-af7b-952da3140000 pid=5283 execve guuid=5e35b348-2300-0000-af7b-952dac140000 pid=5292 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=5e35b348-2300-0000-af7b-952dac140000 pid=5292 execve guuid=0a096b49-2300-0000-af7b-952dad140000 pid=5293 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=0a096b49-2300-0000-af7b-952dad140000 pid=5293 clone guuid=35f6804a-2300-0000-af7b-952daf140000 pid=5295 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=35f6804a-2300-0000-af7b-952daf140000 pid=5295 execve guuid=1421024b-2300-0000-af7b-952db0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=1421024b-2300-0000-af7b-952db0140000 pid=5296 execve guuid=52342b89-2300-0000-af7b-952db1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=52342b89-2300-0000-af7b-952db1140000 pid=5297 execve guuid=6ee19bc8-2300-0000-af7b-952db2140000 pid=5298 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=6ee19bc8-2300-0000-af7b-952db2140000 pid=5298 execve guuid=91949cc9-2300-0000-af7b-952db3140000 pid=5299 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=91949cc9-2300-0000-af7b-952db3140000 pid=5299 clone guuid=d9a0dcca-2300-0000-af7b-952db5140000 pid=5301 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d9a0dcca-2300-0000-af7b-952db5140000 pid=5301 execve guuid=d61062ce-2300-0000-af7b-952db6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d61062ce-2300-0000-af7b-952db6140000 pid=5302 execve guuid=dbecef0c-2400-0000-af7b-952dbe140000 pid=5310 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=dbecef0c-2400-0000-af7b-952dbe140000 pid=5310 execve guuid=46644956-2400-0000-af7b-952dbf140000 pid=5311 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=46644956-2400-0000-af7b-952dbf140000 pid=5311 execve guuid=ecf5ab56-2400-0000-af7b-952dc0140000 pid=5312 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=ecf5ab56-2400-0000-af7b-952dc0140000 pid=5312 clone guuid=7f400258-2400-0000-af7b-952dc2140000 pid=5314 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=7f400258-2400-0000-af7b-952dc2140000 pid=5314 execve guuid=06af4359-2400-0000-af7b-952dc3140000 pid=5315 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=06af4359-2400-0000-af7b-952dc3140000 pid=5315 execve guuid=842f599a-2400-0000-af7b-952dc4140000 pid=5316 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=842f599a-2400-0000-af7b-952dc4140000 pid=5316 execve guuid=689e69db-2400-0000-af7b-952dc5140000 pid=5317 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=689e69db-2400-0000-af7b-952dc5140000 pid=5317 execve guuid=a09bbedb-2400-0000-af7b-952dc6140000 pid=5318 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=a09bbedb-2400-0000-af7b-952dc6140000 pid=5318 clone guuid=050978dc-2400-0000-af7b-952dc8140000 pid=5320 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=050978dc-2400-0000-af7b-952dc8140000 pid=5320 execve guuid=8c44c5dc-2400-0000-af7b-952dc9140000 pid=5321 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=8c44c5dc-2400-0000-af7b-952dc9140000 pid=5321 execve guuid=2877911a-2500-0000-af7b-952dd0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=2877911a-2500-0000-af7b-952dd0140000 pid=5328 execve guuid=5fd4845a-2500-0000-af7b-952ddb140000 pid=5339 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=5fd4845a-2500-0000-af7b-952ddb140000 pid=5339 execve guuid=309ddb5a-2500-0000-af7b-952ddc140000 pid=5340 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=309ddb5a-2500-0000-af7b-952ddc140000 pid=5340 clone guuid=d3d1835b-2500-0000-af7b-952dde140000 pid=5342 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d3d1835b-2500-0000-af7b-952dde140000 pid=5342 execve guuid=f185da5b-2500-0000-af7b-952ddf140000 pid=5343 /usr/bin/wget net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=f185da5b-2500-0000-af7b-952ddf140000 pid=5343 execve guuid=ca4f4899-2500-0000-af7b-952df0140000 pid=5360 /usr/bin/curl net send-data write-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=ca4f4899-2500-0000-af7b-952df0140000 pid=5360 execve guuid=4eac5ed9-2500-0000-af7b-952df2140000 pid=5362 /usr/bin/chmod guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=4eac5ed9-2500-0000-af7b-952df2140000 pid=5362 execve guuid=c13be8d9-2500-0000-af7b-952df3140000 pid=5363 /usr/bin/bash guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=c13be8d9-2500-0000-af7b-952df3140000 pid=5363 clone guuid=d2369fda-2500-0000-af7b-952df5140000 pid=5365 /usr/bin/rm delete-file guuid=04cfed31-1f00-0000-af7b-952dca0a0000 pid=2762->guuid=d2369fda-2500-0000-af7b-952df5140000 pid=5365 execve 39612d49-ad68-5695-a4b6-56f584df0253 103.212.227.29:80 guuid=d5fae138-1f00-0000-af7b-952dd60a0000 pid=2774->39612d49-ad68-5695-a4b6-56f584df0253 send: 153B guuid=6d413b69-1f00-0000-af7b-952d330b0000 pid=2867->39612d49-ad68-5695-a4b6-56f584df0253 send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b8a0079c-1f00-0000-af7b-952d890b0000 pid=2953->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=afc0879c-1f00-0000-af7b-952d8a0b0000 pid=2954 /tmp/morte.x86 guuid=b8a0079c-1f00-0000-af7b-952d890b0000 pid=2953->guuid=afc0879c-1f00-0000-af7b-952d8a0b0000 pid=2954 clone guuid=fb9f969c-1f00-0000-af7b-952d8b0b0000 pid=2955 /tmp/morte.x86 write-config zombie guuid=afc0879c-1f00-0000-af7b-952d8a0b0000 pid=2954->guuid=fb9f969c-1f00-0000-af7b-952d8b0b0000 pid=2955 clone guuid=b351dba0-1f00-0000-af7b-952d930b0000 pid=2963 /usr/bin/dash guuid=fb9f969c-1f00-0000-af7b-952d8b0b0000 pid=2955->guuid=b351dba0-1f00-0000-af7b-952d930b0000 pid=2963 execve guuid=278bcba3-1f00-0000-af7b-952d9a0b0000 pid=2970 /tmp/morte.x86 delete-file dns net send-data guuid=fb9f969c-1f00-0000-af7b-952d8b0b0000 pid=2955->guuid=278bcba3-1f00-0000-af7b-952d9a0b0000 pid=2970 clone guuid=0158f89c-1f00-0000-af7b-952d8d0b0000 pid=2957->39612d49-ad68-5695-a4b6-56f584df0253 send: 154B guuid=d1b608a1-1f00-0000-af7b-952d950b0000 pid=2965 /usr/bin/cp guuid=b351dba0-1f00-0000-af7b-952d930b0000 pid=2963->guuid=d1b608a1-1f00-0000-af7b-952d950b0000 pid=2965 execve guuid=278bcba3-1f00-0000-af7b-952d9a0b0000 pid=2970->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B 5935e425-895b-58ea-a784-fec9a6290d6c as.ddos678.com:12121 guuid=278bcba3-1f00-0000-af7b-952d9a0b0000 pid=2970->5935e425-895b-58ea-a784-fec9a6290d6c send: 22B guuid=475598cb-1f00-0000-af7b-952d0b0c0000 pid=3083->39612d49-ad68-5695-a4b6-56f584df0253 send: 103B eca966e9-0fd6-5873-8ab1-dc2e308ed22d as.ddos678.com:80 guuid=2cd090ff-1f00-0000-af7b-952d790c0000 pid=3193->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 153B guuid=33e5e84c-2000-0000-af7b-952dc80c0000 pid=3272->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 102B guuid=5f042b9f-2000-0000-af7b-952d700d0000 pid=3440->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=301871be-2000-0000-af7b-952dc10d0000 pid=3521->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=56f3cddf-2000-0000-af7b-952d170e0000 pid=3607->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=b0f92c0e-2100-0000-af7b-952d7b0e0000 pid=3707->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=8b5b4940-2100-0000-af7b-952d3b0f0000 pid=3899->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06347d40-2100-0000-af7b-952d3d0f0000 pid=3901 /tmp/morte.i686 guuid=8b5b4940-2100-0000-af7b-952d3b0f0000 pid=3899->guuid=06347d40-2100-0000-af7b-952d3d0f0000 pid=3901 clone guuid=ff308d40-2100-0000-af7b-952d3f0f0000 pid=3903 /tmp/morte.i686 write-config zombie guuid=06347d40-2100-0000-af7b-952d3d0f0000 pid=3901->guuid=ff308d40-2100-0000-af7b-952d3f0f0000 pid=3903 clone guuid=9dcfac44-2100-0000-af7b-952d530f0000 pid=3923 /usr/bin/dash guuid=ff308d40-2100-0000-af7b-952d3f0f0000 pid=3903->guuid=9dcfac44-2100-0000-af7b-952d530f0000 pid=3923 execve guuid=71644b47-2100-0000-af7b-952d5d0f0000 pid=3933 /tmp/morte.i686 dns net send-data guuid=ff308d40-2100-0000-af7b-952d3f0f0000 pid=3903->guuid=71644b47-2100-0000-af7b-952d5d0f0000 pid=3933 clone guuid=2160f99b-2500-0000-af7b-952df1140000 pid=5361 /tmp/morte.i686 dns net send-data guuid=ff308d40-2100-0000-af7b-952d3f0f0000 pid=3903->guuid=2160f99b-2500-0000-af7b-952df1140000 pid=5361 clone guuid=784ecf40-2100-0000-af7b-952d410f0000 pid=3905->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 156B guuid=21d20545-2100-0000-af7b-952d550f0000 pid=3925 /usr/bin/cp guuid=9dcfac44-2100-0000-af7b-952d530f0000 pid=3923->guuid=21d20545-2100-0000-af7b-952d550f0000 pid=3925 execve guuid=71644b47-2100-0000-af7b-952d5d0f0000 pid=3933->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B guuid=71644b47-2100-0000-af7b-952d5d0f0000 pid=3933->5935e425-895b-58ea-a784-fec9a6290d6c con guuid=32b41d6f-2100-0000-af7b-952dec0f0000 pid=4076->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 105B guuid=218aa39f-2100-0000-af7b-952d8a100000 pid=4234->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=47ae2da0-2100-0000-af7b-952d8e100000 pid=4238 /tmp/morte.x86_64 zombie guuid=218aa39f-2100-0000-af7b-952d8a100000 pid=4234->guuid=47ae2da0-2100-0000-af7b-952d8e100000 pid=4238 clone guuid=b5c736a0-2100-0000-af7b-952d8f100000 pid=4239 /tmp/morte.x86_64 write-config zombie guuid=47ae2da0-2100-0000-af7b-952d8e100000 pid=4238->guuid=b5c736a0-2100-0000-af7b-952d8f100000 pid=4239 clone guuid=39e17aa0-2100-0000-af7b-952d91100000 pid=4241 /usr/bin/dash guuid=b5c736a0-2100-0000-af7b-952d8f100000 pid=4239->guuid=39e17aa0-2100-0000-af7b-952d91100000 pid=4241 execve guuid=af665da1-2100-0000-af7b-952d96100000 pid=4246 /tmp/morte.x86_64 delete-file dns net send-data guuid=b5c736a0-2100-0000-af7b-952d8f100000 pid=4239->guuid=af665da1-2100-0000-af7b-952d96100000 pid=4246 clone guuid=f777b7a0-2100-0000-af7b-952d93100000 pid=4243 /usr/bin/cp guuid=39e17aa0-2100-0000-af7b-952d91100000 pid=4241->guuid=f777b7a0-2100-0000-af7b-952d93100000 pid=4243 execve guuid=c6cea0a0-2100-0000-af7b-952d92100000 pid=4242->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=af665da1-2100-0000-af7b-952d96100000 pid=4246->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B guuid=af665da1-2100-0000-af7b-952d96100000 pid=4246->5935e425-895b-58ea-a784-fec9a6290d6c send: 27B guuid=ac832acf-2100-0000-af7b-952d35110000 pid=4405->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=e2744302-2200-0000-af7b-952dee110000 pid=4590->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 153B guuid=5d79e430-2200-0000-af7b-952da6120000 pid=4774->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 102B guuid=7fe14284-2200-0000-af7b-952d78130000 pid=4984->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=e12640b3-2200-0000-af7b-952ded130000 pid=5101->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=cdfed8e7-2200-0000-af7b-952d58140000 pid=5208->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=d9df3b19-2300-0000-af7b-952da3140000 pid=5283->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=1421024b-2300-0000-af7b-952db0140000 pid=5296->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=52342b89-2300-0000-af7b-952db1140000 pid=5297->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=d61062ce-2300-0000-af7b-952db6140000 pid=5302->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 153B guuid=dbecef0c-2400-0000-af7b-952dbe140000 pid=5310->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 102B guuid=06af4359-2400-0000-af7b-952dc3140000 pid=5315->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 153B guuid=842f599a-2400-0000-af7b-952dc4140000 pid=5316->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 102B guuid=8c44c5dc-2400-0000-af7b-952dc9140000 pid=5321->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 154B guuid=2877911a-2500-0000-af7b-952dd0140000 pid=5328->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 103B guuid=f185da5b-2500-0000-af7b-952ddf140000 pid=5343->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 153B guuid=ca4f4899-2500-0000-af7b-952df0140000 pid=5360->eca966e9-0fd6-5873-8ab1-dc2e308ed22d send: 102B guuid=2160f99b-2500-0000-af7b-952df1140000 pid=5361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 32B guuid=2160f99b-2500-0000-af7b-952df1140000 pid=5361->5935e425-895b-58ea-a784-fec9a6290d6c send: 25B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-27 17:46:38 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
as.ddos678.com
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bbdfa157a11857424d0b0adb3a66e863b0ea8441e2a0c92cb739e5d8ebc81516

(this sample)

  
Delivery method
Distributed via web download

Comments