MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bff314fbbc14981c43feaa5ddf2e48c926cf7902aa030de80a29ccbcd3556ce9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: bff314fbbc14981c43feaa5ddf2e48c926cf7902aa030de80a29ccbcd3556ce9
SHA3-384 hash: c81b13adb78eaeb3e5307a82d89a840cc8c140d2d5bf4ece57f72c65a16388346819844f08a85e2324b365e015151dd1
SHA1 hash: f80858e51076efaa8808340a7dd7960430432a00
MD5 hash: 7453c66820255cbdac7be036f86f7cb4
humanhash: mobile-edward-thirteen-friend
File name:1.sh
Download: download sample
Signature Mirai
File size:3'044 bytes
First seen:2025-08-27 06:14:55 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Itf+W+qZsf+L+Lbhf+0+4kf+b+7lff+l+Vmsf+d+NTf+Va+VGgJf+a+G6f+l+VnD:iCbcXVloJ1qBLmJ3tkoZBgJsVk
TLSH T1945166EF238246335CBAEEE77AA98458B35550EBE4CE5F7554ECBCF9404CE086440A63
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.166/bins/morte.x86224bb391451b00c3c44269f7d9d94caa59623c65e08e24de22420f4f21686440 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.mips898f7f84f9ad51ae37a565893e4f72b6ebce2691d529f8744d7d3fb32ed4c4ca Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.arc570791184ff5faa904839758cc51c3419e3802e8abe9d347e5928915e17d7ffe Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.i468n/an/aelf ua-wget
http://196.251.87.166/bins/morte.i68663021604b19c822d162cb1ff2e65a49e51c792fecfb2975f068ab5acb805a04f Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.x86_64f904c5dbb0f0346f55ca3667fbe2f97aaac07b320ae16e4fcf718c34f23de2cd Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.mpslc7121493e6e7e2c519dfaf688d1be09d07d06d46ac3984cc513d52d190169c9a Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.armabb79091e35cd813de2d50e02ec355d6fc309d704ab8bc6d4354bbda531ca615 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.arm5c8ae7fee6b607a59a8a76bdf0026a987c118b01d7843cc01c3e4cd7182e67fd5 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.arm6b5ff3d5b1158f4cb6bffa6e8a1a4c25af0ee8655c31b0b8084c50e2f913daa5c Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.arm754f3f6d1330b4c9667d1113ee3329c2a023cab9a71de20ba55dbed869a38a6b2 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.ppc8ba34509d086573760aa8f7677c3d828c0cf477bd4342a9f743c7ba9b81051f5 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.spc9d717775b3a0461cc62c5a8fbfd6027e62fb8f8ff47e5d1dc28a12db816cdcf3 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.m68k6ceddf85002197439346890d29eda288c11ab7e11c27deb86a953bd96dd03096 Miraielf mirai ua-wget
http://196.251.87.166/bins/morte.sh4e98333b12e1353d142e9b467839d4f21a7640294f4b7cd9bd9a6029d93b806b3 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-08-26T09:31:00Z UTC
Last seen:
2025-08-26T09:31:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=55026cb1-1900-0000-abe9-a31a920c0000 pid=3218 /usr/bin/sudo guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226 /tmp/sample.bin guuid=55026cb1-1900-0000-abe9-a31a920c0000 pid=3218->guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226 execve guuid=260917b5-1900-0000-abe9-a31a9c0c0000 pid=3228 /usr/bin/cp guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=260917b5-1900-0000-abe9-a31a9c0c0000 pid=3228 execve guuid=adf6abbb-1900-0000-abe9-a31aa20c0000 pid=3234 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=adf6abbb-1900-0000-abe9-a31aa20c0000 pid=3234 execve guuid=b799b4c3-1900-0000-abe9-a31aa40c0000 pid=3236 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=b799b4c3-1900-0000-abe9-a31aa40c0000 pid=3236 execve guuid=d60fa9ce-1900-0000-abe9-a31ab50c0000 pid=3253 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=d60fa9ce-1900-0000-abe9-a31ab50c0000 pid=3253 execve guuid=fd3612cf-1900-0000-abe9-a31ab70c0000 pid=3255 /tmp/morte.x86 net guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=fd3612cf-1900-0000-abe9-a31ab70c0000 pid=3255 execve guuid=ee9dd3cf-1900-0000-abe9-a31abb0c0000 pid=3259 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=ee9dd3cf-1900-0000-abe9-a31abb0c0000 pid=3259 execve guuid=ef7337d0-1900-0000-abe9-a31abe0c0000 pid=3262 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=ef7337d0-1900-0000-abe9-a31abe0c0000 pid=3262 execve guuid=87da7bd5-1900-0000-abe9-a31ac00c0000 pid=3264 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=87da7bd5-1900-0000-abe9-a31ac00c0000 pid=3264 execve guuid=5ce329db-1900-0000-abe9-a31acc0c0000 pid=3276 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=5ce329db-1900-0000-abe9-a31acc0c0000 pid=3276 execve guuid=8b7564db-1900-0000-abe9-a31ace0c0000 pid=3278 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=8b7564db-1900-0000-abe9-a31ace0c0000 pid=3278 clone guuid=2ae7ebdb-1900-0000-abe9-a31ad20c0000 pid=3282 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=2ae7ebdb-1900-0000-abe9-a31ad20c0000 pid=3282 execve guuid=0b632fdc-1900-0000-abe9-a31ad40c0000 pid=3284 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=0b632fdc-1900-0000-abe9-a31ad40c0000 pid=3284 execve guuid=3d6b6ee1-1900-0000-abe9-a31ae20c0000 pid=3298 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=3d6b6ee1-1900-0000-abe9-a31ae20c0000 pid=3298 execve guuid=117b77e9-1900-0000-abe9-a31af90c0000 pid=3321 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=117b77e9-1900-0000-abe9-a31af90c0000 pid=3321 execve guuid=d6e4cee9-1900-0000-abe9-a31afb0c0000 pid=3323 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=d6e4cee9-1900-0000-abe9-a31afb0c0000 pid=3323 clone guuid=bde09aea-1900-0000-abe9-a31aff0c0000 pid=3327 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=bde09aea-1900-0000-abe9-a31aff0c0000 pid=3327 execve guuid=07d0feea-1900-0000-abe9-a31a010d0000 pid=3329 /usr/bin/wget net send-data guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=07d0feea-1900-0000-abe9-a31a010d0000 pid=3329 execve guuid=33912fed-1900-0000-abe9-a31a080d0000 pid=3336 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=33912fed-1900-0000-abe9-a31a080d0000 pid=3336 execve guuid=8c7793f0-1900-0000-abe9-a31a110d0000 pid=3345 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=8c7793f0-1900-0000-abe9-a31a110d0000 pid=3345 execve guuid=4ef2d6f0-1900-0000-abe9-a31a130d0000 pid=3347 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4ef2d6f0-1900-0000-abe9-a31a130d0000 pid=3347 clone guuid=6d07f8f0-1900-0000-abe9-a31a140d0000 pid=3348 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=6d07f8f0-1900-0000-abe9-a31a140d0000 pid=3348 execve guuid=1eec3af1-1900-0000-abe9-a31a160d0000 pid=3350 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=1eec3af1-1900-0000-abe9-a31a160d0000 pid=3350 execve guuid=cac1a4f4-1900-0000-abe9-a31a1a0d0000 pid=3354 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=cac1a4f4-1900-0000-abe9-a31a1a0d0000 pid=3354 execve guuid=e798e1ff-1900-0000-abe9-a31a220d0000 pid=3362 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=e798e1ff-1900-0000-abe9-a31a220d0000 pid=3362 execve guuid=15b65700-1a00-0000-abe9-a31a240d0000 pid=3364 /tmp/morte.i686 net guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=15b65700-1a00-0000-abe9-a31a240d0000 pid=3364 execve guuid=1e6aef00-1a00-0000-abe9-a31a270d0000 pid=3367 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=1e6aef00-1a00-0000-abe9-a31a270d0000 pid=3367 execve guuid=49c42b01-1a00-0000-abe9-a31a290d0000 pid=3369 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=49c42b01-1a00-0000-abe9-a31a290d0000 pid=3369 execve guuid=c73f6b06-1a00-0000-abe9-a31a2e0d0000 pid=3374 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=c73f6b06-1a00-0000-abe9-a31a2e0d0000 pid=3374 execve guuid=4a38dc0d-1a00-0000-abe9-a31a320d0000 pid=3378 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4a38dc0d-1a00-0000-abe9-a31a320d0000 pid=3378 execve guuid=247c250e-1a00-0000-abe9-a31a330d0000 pid=3379 /tmp/morte.x86_64 mprotect-exec net guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=247c250e-1a00-0000-abe9-a31a330d0000 pid=3379 execve guuid=0cc3d00e-1a00-0000-abe9-a31a360d0000 pid=3382 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=0cc3d00e-1a00-0000-abe9-a31a360d0000 pid=3382 execve guuid=44783d10-1a00-0000-abe9-a31a3e0d0000 pid=3390 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=44783d10-1a00-0000-abe9-a31a3e0d0000 pid=3390 execve guuid=e9174f14-1a00-0000-abe9-a31a480d0000 pid=3400 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=e9174f14-1a00-0000-abe9-a31a480d0000 pid=3400 execve guuid=48d2d018-1a00-0000-abe9-a31a540d0000 pid=3412 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=48d2d018-1a00-0000-abe9-a31a540d0000 pid=3412 execve guuid=13a61c19-1a00-0000-abe9-a31a560d0000 pid=3414 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=13a61c19-1a00-0000-abe9-a31a560d0000 pid=3414 clone guuid=b6dea319-1a00-0000-abe9-a31a5a0d0000 pid=3418 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=b6dea319-1a00-0000-abe9-a31a5a0d0000 pid=3418 execve guuid=4c69eb1a-1a00-0000-abe9-a31a5f0d0000 pid=3423 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4c69eb1a-1a00-0000-abe9-a31a5f0d0000 pid=3423 execve guuid=7a36151e-1a00-0000-abe9-a31a680d0000 pid=3432 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=7a36151e-1a00-0000-abe9-a31a680d0000 pid=3432 execve guuid=2f51e822-1a00-0000-abe9-a31a740d0000 pid=3444 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=2f51e822-1a00-0000-abe9-a31a740d0000 pid=3444 execve guuid=25943223-1a00-0000-abe9-a31a770d0000 pid=3447 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=25943223-1a00-0000-abe9-a31a770d0000 pid=3447 clone guuid=c1544b25-1a00-0000-abe9-a31a7f0d0000 pid=3455 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=c1544b25-1a00-0000-abe9-a31a7f0d0000 pid=3455 execve guuid=a676b325-1a00-0000-abe9-a31a810d0000 pid=3457 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=a676b325-1a00-0000-abe9-a31a810d0000 pid=3457 execve guuid=2ad0cf28-1a00-0000-abe9-a31a8b0d0000 pid=3467 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=2ad0cf28-1a00-0000-abe9-a31a8b0d0000 pid=3467 execve guuid=7c839b2d-1a00-0000-abe9-a31a9a0d0000 pid=3482 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=7c839b2d-1a00-0000-abe9-a31a9a0d0000 pid=3482 execve guuid=9690fd2d-1a00-0000-abe9-a31a9c0d0000 pid=3484 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=9690fd2d-1a00-0000-abe9-a31a9c0d0000 pid=3484 clone guuid=261a042f-1a00-0000-abe9-a31aa10d0000 pid=3489 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=261a042f-1a00-0000-abe9-a31aa10d0000 pid=3489 execve guuid=f0a8662f-1a00-0000-abe9-a31aa30d0000 pid=3491 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=f0a8662f-1a00-0000-abe9-a31aa30d0000 pid=3491 execve guuid=e2d93e33-1a00-0000-abe9-a31aae0d0000 pid=3502 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=e2d93e33-1a00-0000-abe9-a31aae0d0000 pid=3502 execve guuid=72baae37-1a00-0000-abe9-a31abc0d0000 pid=3516 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=72baae37-1a00-0000-abe9-a31abc0d0000 pid=3516 execve guuid=ee682638-1a00-0000-abe9-a31abe0d0000 pid=3518 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=ee682638-1a00-0000-abe9-a31abe0d0000 pid=3518 clone guuid=01cc1e39-1a00-0000-abe9-a31ac20d0000 pid=3522 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=01cc1e39-1a00-0000-abe9-a31ac20d0000 pid=3522 execve guuid=b9a4c252-1a00-0000-abe9-a31af50d0000 pid=3573 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=b9a4c252-1a00-0000-abe9-a31af50d0000 pid=3573 execve guuid=1308c857-1a00-0000-abe9-a31af60d0000 pid=3574 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=1308c857-1a00-0000-abe9-a31af60d0000 pid=3574 execve guuid=0d89a06a-1a00-0000-abe9-a31af80d0000 pid=3576 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=0d89a06a-1a00-0000-abe9-a31af80d0000 pid=3576 execve guuid=5359f46a-1a00-0000-abe9-a31af90d0000 pid=3577 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=5359f46a-1a00-0000-abe9-a31af90d0000 pid=3577 clone guuid=041df46b-1a00-0000-abe9-a31afb0d0000 pid=3579 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=041df46b-1a00-0000-abe9-a31afb0d0000 pid=3579 execve guuid=3efe5b6c-1a00-0000-abe9-a31afc0d0000 pid=3580 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=3efe5b6c-1a00-0000-abe9-a31afc0d0000 pid=3580 execve guuid=68a9c36f-1a00-0000-abe9-a31a030e0000 pid=3587 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=68a9c36f-1a00-0000-abe9-a31a030e0000 pid=3587 execve guuid=39e5af74-1a00-0000-abe9-a31a090e0000 pid=3593 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=39e5af74-1a00-0000-abe9-a31a090e0000 pid=3593 execve guuid=608d1975-1a00-0000-abe9-a31a0b0e0000 pid=3595 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=608d1975-1a00-0000-abe9-a31a0b0e0000 pid=3595 clone guuid=54e6c475-1a00-0000-abe9-a31a0f0e0000 pid=3599 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=54e6c475-1a00-0000-abe9-a31a0f0e0000 pid=3599 execve guuid=e1e52476-1a00-0000-abe9-a31a100e0000 pid=3600 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=e1e52476-1a00-0000-abe9-a31a100e0000 pid=3600 execve guuid=b12afb7b-1a00-0000-abe9-a31a1a0e0000 pid=3610 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=b12afb7b-1a00-0000-abe9-a31a1a0e0000 pid=3610 execve guuid=eade5f86-1a00-0000-abe9-a31a300e0000 pid=3632 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=eade5f86-1a00-0000-abe9-a31a300e0000 pid=3632 execve guuid=cbe6b786-1a00-0000-abe9-a31a320e0000 pid=3634 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=cbe6b786-1a00-0000-abe9-a31a320e0000 pid=3634 clone guuid=ccd04c87-1a00-0000-abe9-a31a360e0000 pid=3638 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=ccd04c87-1a00-0000-abe9-a31a360e0000 pid=3638 execve guuid=dab6a387-1a00-0000-abe9-a31a380e0000 pid=3640 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=dab6a387-1a00-0000-abe9-a31a380e0000 pid=3640 execve guuid=fdb5868c-1a00-0000-abe9-a31a440e0000 pid=3652 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=fdb5868c-1a00-0000-abe9-a31a440e0000 pid=3652 execve guuid=4d660291-1a00-0000-abe9-a31a530e0000 pid=3667 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4d660291-1a00-0000-abe9-a31a530e0000 pid=3667 execve guuid=75b14f91-1a00-0000-abe9-a31a550e0000 pid=3669 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=75b14f91-1a00-0000-abe9-a31a550e0000 pid=3669 clone guuid=f550ed91-1a00-0000-abe9-a31a590e0000 pid=3673 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=f550ed91-1a00-0000-abe9-a31a590e0000 pid=3673 execve guuid=9b1c4092-1a00-0000-abe9-a31a5b0e0000 pid=3675 /usr/bin/wget net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=9b1c4092-1a00-0000-abe9-a31a5b0e0000 pid=3675 execve guuid=6fe53296-1a00-0000-abe9-a31a680e0000 pid=3688 /usr/bin/curl net send-data write-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=6fe53296-1a00-0000-abe9-a31a680e0000 pid=3688 execve guuid=4cdb139b-1a00-0000-abe9-a31a740e0000 pid=3700 /usr/bin/chmod guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4cdb139b-1a00-0000-abe9-a31a740e0000 pid=3700 execve guuid=3cd4819b-1a00-0000-abe9-a31a770e0000 pid=3703 /usr/bin/bash guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=3cd4819b-1a00-0000-abe9-a31a770e0000 pid=3703 clone guuid=4f88339c-1a00-0000-abe9-a31a7a0e0000 pid=3706 /usr/bin/rm delete-file guuid=ab261cb4-1900-0000-abe9-a31a9a0c0000 pid=3226->guuid=4f88339c-1a00-0000-abe9-a31a7a0e0000 pid=3706 execve e0e21a48-ffad-5b01-84ef-2ee6b5294738 196.251.87.166:80 guuid=adf6abbb-1900-0000-abe9-a31aa20c0000 pid=3234->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=b799b4c3-1900-0000-abe9-a31aa40c0000 pid=3236->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fd3612cf-1900-0000-abe9-a31ab70c0000 pid=3255->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=495abecf-1900-0000-abe9-a31aba0c0000 pid=3258 /tmp/morte.x86 guuid=fd3612cf-1900-0000-abe9-a31ab70c0000 pid=3255->guuid=495abecf-1900-0000-abe9-a31aba0c0000 pid=3258 clone guuid=fd73dfcf-1900-0000-abe9-a31abc0c0000 pid=3260 /tmp/morte.x86 write-config zombie guuid=495abecf-1900-0000-abe9-a31aba0c0000 pid=3258->guuid=fd73dfcf-1900-0000-abe9-a31abc0c0000 pid=3260 clone guuid=fb88c3d4-1900-0000-abe9-a31abf0c0000 pid=3263 /usr/bin/dash guuid=fd73dfcf-1900-0000-abe9-a31abc0c0000 pid=3260->guuid=fb88c3d4-1900-0000-abe9-a31abf0c0000 pid=3263 execve guuid=9a0c40d9-1900-0000-abe9-a31ac50c0000 pid=3269 /tmp/morte.x86 delete-file guuid=fd73dfcf-1900-0000-abe9-a31abc0c0000 pid=3260->guuid=9a0c40d9-1900-0000-abe9-a31ac50c0000 pid=3269 clone guuid=ef7337d0-1900-0000-abe9-a31abe0c0000 pid=3262->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=766fa9d5-1900-0000-abe9-a31ac10c0000 pid=3265 /usr/bin/cp guuid=fb88c3d4-1900-0000-abe9-a31abf0c0000 pid=3263->guuid=766fa9d5-1900-0000-abe9-a31ac10c0000 pid=3265 execve guuid=87da7bd5-1900-0000-abe9-a31ac00c0000 pid=3264->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=0b632fdc-1900-0000-abe9-a31ad40c0000 pid=3284->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=3d6b6ee1-1900-0000-abe9-a31ae20c0000 pid=3298->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B guuid=07d0feea-1900-0000-abe9-a31a010d0000 pid=3329->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=33912fed-1900-0000-abe9-a31a080d0000 pid=3336->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=1eec3af1-1900-0000-abe9-a31a160d0000 pid=3350->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=cac1a4f4-1900-0000-abe9-a31a1a0d0000 pid=3354->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=15b65700-1a00-0000-abe9-a31a240d0000 pid=3364->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d27de700-1a00-0000-abe9-a31a260d0000 pid=3366 /tmp/morte.i686 guuid=15b65700-1a00-0000-abe9-a31a240d0000 pid=3364->guuid=d27de700-1a00-0000-abe9-a31a260d0000 pid=3366 clone guuid=4ba43101-1a00-0000-abe9-a31a2a0d0000 pid=3370 /tmp/morte.i686 write-config zombie guuid=d27de700-1a00-0000-abe9-a31a260d0000 pid=3366->guuid=4ba43101-1a00-0000-abe9-a31a2a0d0000 pid=3370 clone guuid=49c42b01-1a00-0000-abe9-a31a290d0000 pid=3369->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 146B guuid=b4fd9a04-1a00-0000-abe9-a31a2c0d0000 pid=3372 /usr/bin/dash guuid=4ba43101-1a00-0000-abe9-a31a2a0d0000 pid=3370->guuid=b4fd9a04-1a00-0000-abe9-a31a2c0d0000 pid=3372 execve guuid=63914907-1a00-0000-abe9-a31a2f0d0000 pid=3375 /tmp/morte.i686 guuid=4ba43101-1a00-0000-abe9-a31a2a0d0000 pid=3370->guuid=63914907-1a00-0000-abe9-a31a2f0d0000 pid=3375 clone guuid=8a811bb8-1b00-0000-abe9-a31aff110000 pid=4607 /tmp/morte.i686 dns net send-data guuid=4ba43101-1a00-0000-abe9-a31a2a0d0000 pid=3370->guuid=8a811bb8-1b00-0000-abe9-a31aff110000 pid=4607 clone guuid=86441f05-1a00-0000-abe9-a31a2d0d0000 pid=3373 /usr/bin/cp guuid=b4fd9a04-1a00-0000-abe9-a31a2c0d0000 pid=3372->guuid=86441f05-1a00-0000-abe9-a31a2d0d0000 pid=3373 execve guuid=c73f6b06-1a00-0000-abe9-a31a2e0d0000 pid=3374->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 95B guuid=247c250e-1a00-0000-abe9-a31a330d0000 pid=3379->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=265cc80e-1a00-0000-abe9-a31a350d0000 pid=3381 /tmp/morte.x86_64 zombie guuid=247c250e-1a00-0000-abe9-a31a330d0000 pid=3379->guuid=265cc80e-1a00-0000-abe9-a31a350d0000 pid=3381 clone guuid=9bc0d70e-1a00-0000-abe9-a31a370d0000 pid=3383 /tmp/morte.x86_64 write-config zombie guuid=265cc80e-1a00-0000-abe9-a31a350d0000 pid=3381->guuid=9bc0d70e-1a00-0000-abe9-a31a370d0000 pid=3383 clone guuid=8bf2170f-1a00-0000-abe9-a31a390d0000 pid=3385 /usr/bin/dash guuid=9bc0d70e-1a00-0000-abe9-a31a370d0000 pid=3383->guuid=8bf2170f-1a00-0000-abe9-a31a390d0000 pid=3385 execve guuid=b2eb0010-1a00-0000-abe9-a31a3d0d0000 pid=3389 /tmp/morte.x86_64 dns net send-data guuid=9bc0d70e-1a00-0000-abe9-a31a370d0000 pid=3383->guuid=b2eb0010-1a00-0000-abe9-a31a3d0d0000 pid=3389 clone guuid=8dc94a0f-1a00-0000-abe9-a31a3a0d0000 pid=3386 /usr/bin/cp guuid=8bf2170f-1a00-0000-abe9-a31a390d0000 pid=3385->guuid=8dc94a0f-1a00-0000-abe9-a31a3a0d0000 pid=3386 execve guuid=b2eb0010-1a00-0000-abe9-a31a3d0d0000 pid=3389->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B ba409a05-ee4b-5515-b303-c26a7537bae8 rinksog.com:12121 guuid=b2eb0010-1a00-0000-abe9-a31a3d0d0000 pid=3389->ba409a05-ee4b-5515-b303-c26a7537bae8 send: 29B guuid=44783d10-1a00-0000-abe9-a31a3e0d0000 pid=3390->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=e9174f14-1a00-0000-abe9-a31a480d0000 pid=3400->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=4c69eb1a-1a00-0000-abe9-a31a5f0d0000 pid=3423->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=7a36151e-1a00-0000-abe9-a31a680d0000 pid=3432->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B guuid=a676b325-1a00-0000-abe9-a31a810d0000 pid=3457->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=2ad0cf28-1a00-0000-abe9-a31a8b0d0000 pid=3467->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=f0a8662f-1a00-0000-abe9-a31aa30d0000 pid=3491->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=e2d93e33-1a00-0000-abe9-a31aae0d0000 pid=3502->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=b9a4c252-1a00-0000-abe9-a31af50d0000 pid=3573->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=1308c857-1a00-0000-abe9-a31af60d0000 pid=3574->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=3efe5b6c-1a00-0000-abe9-a31afc0d0000 pid=3580->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=68a9c36f-1a00-0000-abe9-a31a030e0000 pid=3587->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B guuid=e1e52476-1a00-0000-abe9-a31a100e0000 pid=3600->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=b12afb7b-1a00-0000-abe9-a31a1a0e0000 pid=3610->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B guuid=dab6a387-1a00-0000-abe9-a31a380e0000 pid=3640->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 144B guuid=fdb5868c-1a00-0000-abe9-a31a440e0000 pid=3652->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 93B guuid=9b1c4092-1a00-0000-abe9-a31a5b0e0000 pid=3675->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 143B guuid=6fe53296-1a00-0000-abe9-a31a680e0000 pid=3688->e0e21a48-ffad-5b01-84ef-2ee6b5294738 send: 92B guuid=8a811bb8-1b00-0000-abe9-a31aff110000 pid=4607->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 29B guuid=8a811bb8-1b00-0000-abe9-a31aff110000 pid=4607->ba409a05-ee4b-5515-b303-c26a7537bae8 send: 27B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-26 21:01:42 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence upx
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
UPX packed file
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh bff314fbbc14981c43feaa5ddf2e48c926cf7902aa030de80a29ccbcd3556ce9

(this sample)

  
Delivery method
Distributed via web download

Comments