MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ecc9b6b2bfabae3e6a9025492815c4af334a9b7fd7547cf4a65a7953bf52f160. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: ecc9b6b2bfabae3e6a9025492815c4af334a9b7fd7547cf4a65a7953bf52f160
SHA3-384 hash: 8503af8a32b1a59ac052dbbc6b79722aa7c11aa779e48496db5e83d14683a37ec2f3d156e2b77da654f1204d0d2db53d
SHA1 hash: 39343cdc065ecdab2727396298244350fa78a6f0
MD5 hash: 288f142973e1b0ebeb048d966fac9de3
humanhash: orange-saturn-music-oxygen
File name:1.sh
Download: download sample
Signature Mirai
File size:2'149 bytes
First seen:2025-10-02 22:17:14 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:GB1LvR2M5pIiKMCmCQ3gSH4JU/fSWO6NX3Fe+:GsRQ3gSwa
TLSH T10641E5F7A34BCA03D27D87CA3EA50406B015C36BB49FC735DCEAEAC90494E9C7255A85
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://157.20.32.209/bins/morte.arc4704e07f48738bd7b4cd44cec97a7c5526a4419fa665fd425ba217425916024a Miraimirai opendir
http://157.20.32.209/bins/morte.armf6d0afe358d658d05afad447734fee5a590e953c6c0f98cbd217a867521f8754 Miraimirai opendir
http://157.20.32.209/bins/morte.arm517bb63761f5c8c1601c331cf193c55c09d4619053f9572b3648ef69e49fd1a89 Miraimirai opendir
http://157.20.32.209/bins/morte.arm6b3cd17f0afa885b377f8b04679e75f7f0827189f0b3f025a3814d156b4db1c38 Miraimirai opendir
http://157.20.32.209/bins/morte.arm709d4f358af13014b924279b5b4318a7da185db5a95b1175fac33a87e93f00b35 Miraimirai opendir
http://157.20.32.209/bins/morte.i686a1617a2f4c04b81e7d8fa32fd63a09ed977cd7607b24b76055b36fdea3112c89 Miraimirai opendir
http://157.20.32.209/bins/morte.m68kcdab74aed8c37c66f1370e839cd48ae264c4bda7f1aae193b516e1c9a52a93ea Miraimirai opendir
http://157.20.32.209/bins/morte.mips1cb41b9c1a9e8123336054934a6ade938b976b5dbb87e852c742ef3f1fa9cdbb Miraimirai opendir
http://157.20.32.209/bins/morte.mpsl9f142d179fbde485e13d3364d65180ee6d62449aff02e35d87447ca0f9417210 Miraimirai opendir
http://157.20.32.209/bins/morte.ppc1dc7e464cdaabeaa49a759a198d6a69d7cfc69014337f7fe1881dc9f3efdb8dd Miraimirai opendir
http://157.20.32.209/bins/morte.sh4bb8425e14a2cc5ce0d44da49e2b28d19e081b6352f48c376c7b0f9b0c92e3054 Miraimirai opendir
http://157.20.32.209/bins/morte.spce43b10988feae69a629b29ad0826d88d485372dabbed9421f2e1094147da7c01 Miraimirai opendir
http://157.20.32.209/bins/morte.x8620eec1f49d7ab9223b5d47b6f464aed12e418942570966eae401968088463f1a Miraimirai opendir
http://157.20.32.209/bins/morte.x86_6416ba16bf6f0d4de4341bf38820777755012f008554f5e482b88cd4a85e97eb8b Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-02T19:24:00Z UTC
Last seen:
2025-10-03T01:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=63592397-1700-0000-0961-b4b3260a0000 pid=2598 /usr/bin/sudo guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607 /tmp/sample.bin guuid=63592397-1700-0000-0961-b4b3260a0000 pid=2598->guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607 execve guuid=66e6e699-1700-0000-0961-b4b3320a0000 pid=2610 /usr/bin/cp guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=66e6e699-1700-0000-0961-b4b3320a0000 pid=2610 execve guuid=3b0a739d-1700-0000-0961-b4b33d0a0000 pid=2621 /usr/bin/mkdir guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=3b0a739d-1700-0000-0961-b4b33d0a0000 pid=2621 execve guuid=a2ccca9d-1700-0000-0961-b4b33f0a0000 pid=2623 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=a2ccca9d-1700-0000-0961-b4b33f0a0000 pid=2623 execve guuid=65c5e7d2-1700-0000-0961-b4b3d40a0000 pid=2772 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=65c5e7d2-1700-0000-0961-b4b3d40a0000 pid=2772 execve guuid=c0903a0a-1800-0000-0961-b4b3600b0000 pid=2912 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c0903a0a-1800-0000-0961-b4b3600b0000 pid=2912 execve guuid=72a09d0a-1800-0000-0961-b4b3610b0000 pid=2913 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=72a09d0a-1800-0000-0961-b4b3610b0000 pid=2913 clone guuid=0d933c0b-1800-0000-0961-b4b3640b0000 pid=2916 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=0d933c0b-1800-0000-0961-b4b3640b0000 pid=2916 execve guuid=e3dfc50b-1800-0000-0961-b4b3650b0000 pid=2917 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=e3dfc50b-1800-0000-0961-b4b3650b0000 pid=2917 execve guuid=14abb62b-1800-0000-0961-b4b3b40b0000 pid=2996 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=14abb62b-1800-0000-0961-b4b3b40b0000 pid=2996 execve guuid=fa99434d-1800-0000-0961-b4b3070c0000 pid=3079 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=fa99434d-1800-0000-0961-b4b3070c0000 pid=3079 execve guuid=0e7ecb4d-1800-0000-0961-b4b3080c0000 pid=3080 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=0e7ecb4d-1800-0000-0961-b4b3080c0000 pid=3080 clone guuid=85fee44e-1800-0000-0961-b4b30c0c0000 pid=3084 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=85fee44e-1800-0000-0961-b4b30c0c0000 pid=3084 execve guuid=64315f4f-1800-0000-0961-b4b30e0c0000 pid=3086 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=64315f4f-1800-0000-0961-b4b30e0c0000 pid=3086 execve guuid=80134877-1800-0000-0961-b4b34d0c0000 pid=3149 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=80134877-1800-0000-0961-b4b34d0c0000 pid=3149 execve guuid=172bd099-1800-0000-0961-b4b36d0c0000 pid=3181 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=172bd099-1800-0000-0961-b4b36d0c0000 pid=3181 execve guuid=62ca3d9a-1800-0000-0961-b4b36e0c0000 pid=3182 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=62ca3d9a-1800-0000-0961-b4b36e0c0000 pid=3182 clone guuid=c5e80b9b-1800-0000-0961-b4b3700c0000 pid=3184 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c5e80b9b-1800-0000-0961-b4b3700c0000 pid=3184 execve guuid=51c1659b-1800-0000-0961-b4b3710c0000 pid=3185 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=51c1659b-1800-0000-0961-b4b3710c0000 pid=3185 execve guuid=f262b5d7-1800-0000-0961-b4b3ab0c0000 pid=3243 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=f262b5d7-1800-0000-0961-b4b3ab0c0000 pid=3243 execve guuid=4603a803-1900-0000-0961-b4b3e10c0000 pid=3297 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=4603a803-1900-0000-0961-b4b3e10c0000 pid=3297 execve guuid=92613a04-1900-0000-0961-b4b3e30c0000 pid=3299 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=92613a04-1900-0000-0961-b4b3e30c0000 pid=3299 clone guuid=e1216305-1900-0000-0961-b4b3e70c0000 pid=3303 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=e1216305-1900-0000-0961-b4b3e70c0000 pid=3303 execve guuid=088af705-1900-0000-0961-b4b3ea0c0000 pid=3306 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=088af705-1900-0000-0961-b4b3ea0c0000 pid=3306 execve guuid=9a432c2f-1900-0000-0961-b4b3200d0000 pid=3360 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=9a432c2f-1900-0000-0961-b4b3200d0000 pid=3360 execve guuid=1790415b-1900-0000-0961-b4b3830d0000 pid=3459 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=1790415b-1900-0000-0961-b4b3830d0000 pid=3459 execve guuid=d0279a5b-1900-0000-0961-b4b3850d0000 pid=3461 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=d0279a5b-1900-0000-0961-b4b3850d0000 pid=3461 clone guuid=49245d5c-1900-0000-0961-b4b3890d0000 pid=3465 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=49245d5c-1900-0000-0961-b4b3890d0000 pid=3465 execve guuid=ccf1bf5c-1900-0000-0961-b4b38b0d0000 pid=3467 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=ccf1bf5c-1900-0000-0961-b4b38b0d0000 pid=3467 execve guuid=a6e0d87b-1900-0000-0961-b4b3ca0d0000 pid=3530 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=a6e0d87b-1900-0000-0961-b4b3ca0d0000 pid=3530 execve guuid=704bc6bf-1900-0000-0961-b4b3ff0d0000 pid=3583 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=704bc6bf-1900-0000-0961-b4b3ff0d0000 pid=3583 execve guuid=f23656c0-1900-0000-0961-b4b3000e0000 pid=3584 /bins/morte.i686 net guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=f23656c0-1900-0000-0961-b4b3000e0000 pid=3584 execve guuid=07a470c1-1900-0000-0961-b4b3030e0000 pid=3587 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=07a470c1-1900-0000-0961-b4b3030e0000 pid=3587 execve guuid=5a3b37c2-1900-0000-0961-b4b3040e0000 pid=3588 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=5a3b37c2-1900-0000-0961-b4b3040e0000 pid=3588 execve guuid=b09755f5-1900-0000-0961-b4b3770e0000 pid=3703 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=b09755f5-1900-0000-0961-b4b3770e0000 pid=3703 execve guuid=016f8a20-1a00-0000-0961-b4b3190f0000 pid=3865 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=016f8a20-1a00-0000-0961-b4b3190f0000 pid=3865 execve guuid=d506fe20-1a00-0000-0961-b4b31b0f0000 pid=3867 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=d506fe20-1a00-0000-0961-b4b31b0f0000 pid=3867 clone guuid=ee55be21-1a00-0000-0961-b4b3200f0000 pid=3872 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=ee55be21-1a00-0000-0961-b4b3200f0000 pid=3872 execve guuid=dd782222-1a00-0000-0961-b4b3240f0000 pid=3876 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=dd782222-1a00-0000-0961-b4b3240f0000 pid=3876 execve guuid=8c95ef4a-1a00-0000-0961-b4b38d0f0000 pid=3981 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=8c95ef4a-1a00-0000-0961-b4b38d0f0000 pid=3981 execve guuid=2110a175-1a00-0000-0961-b4b3f70f0000 pid=4087 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=2110a175-1a00-0000-0961-b4b3f70f0000 pid=4087 execve guuid=8bce2776-1a00-0000-0961-b4b3f80f0000 pid=4088 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=8bce2776-1a00-0000-0961-b4b3f80f0000 pid=4088 clone guuid=c5010077-1a00-0000-0961-b4b3fd0f0000 pid=4093 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c5010077-1a00-0000-0961-b4b3fd0f0000 pid=4093 execve guuid=3bb86877-1a00-0000-0961-b4b301100000 pid=4097 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=3bb86877-1a00-0000-0961-b4b301100000 pid=4097 execve guuid=4f631da0-1a00-0000-0961-b4b364100000 pid=4196 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=4f631da0-1a00-0000-0961-b4b364100000 pid=4196 execve guuid=6165c2d9-1a00-0000-0961-b4b3da100000 pid=4314 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=6165c2d9-1a00-0000-0961-b4b3da100000 pid=4314 execve guuid=761f63da-1a00-0000-0961-b4b3dc100000 pid=4316 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=761f63da-1a00-0000-0961-b4b3dc100000 pid=4316 clone guuid=944240dd-1a00-0000-0961-b4b3e2100000 pid=4322 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=944240dd-1a00-0000-0961-b4b3e2100000 pid=4322 execve guuid=0bbe94dd-1a00-0000-0961-b4b3e4100000 pid=4324 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=0bbe94dd-1a00-0000-0961-b4b3e4100000 pid=4324 execve guuid=b6f465fd-1a00-0000-0961-b4b33c110000 pid=4412 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=b6f465fd-1a00-0000-0961-b4b33c110000 pid=4412 execve guuid=e3545e1f-1b00-0000-0961-b4b3a0110000 pid=4512 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=e3545e1f-1b00-0000-0961-b4b3a0110000 pid=4512 execve guuid=742eeb1f-1b00-0000-0961-b4b3a2110000 pid=4514 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=742eeb1f-1b00-0000-0961-b4b3a2110000 pid=4514 clone guuid=3414b320-1b00-0000-0961-b4b3a7110000 pid=4519 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=3414b320-1b00-0000-0961-b4b3a7110000 pid=4519 execve guuid=c0330921-1b00-0000-0961-b4b3a9110000 pid=4521 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c0330921-1b00-0000-0961-b4b3a9110000 pid=4521 execve guuid=edb61d4a-1b00-0000-0961-b4b314120000 pid=4628 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=edb61d4a-1b00-0000-0961-b4b314120000 pid=4628 execve guuid=f15d4478-1b00-0000-0961-b4b38e120000 pid=4750 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=f15d4478-1b00-0000-0961-b4b38e120000 pid=4750 execve guuid=3c79b678-1b00-0000-0961-b4b391120000 pid=4753 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=3c79b678-1b00-0000-0961-b4b391120000 pid=4753 clone guuid=2d13b079-1b00-0000-0961-b4b394120000 pid=4756 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=2d13b079-1b00-0000-0961-b4b394120000 pid=4756 execve guuid=c31e077a-1b00-0000-0961-b4b396120000 pid=4758 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c31e077a-1b00-0000-0961-b4b396120000 pid=4758 execve guuid=a6646da4-1b00-0000-0961-b4b308130000 pid=4872 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=a6646da4-1b00-0000-0961-b4b308130000 pid=4872 execve guuid=cd3570d1-1b00-0000-0961-b4b35f130000 pid=4959 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=cd3570d1-1b00-0000-0961-b4b35f130000 pid=4959 execve guuid=81c912d2-1b00-0000-0961-b4b361130000 pid=4961 /usr/bin/bash guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=81c912d2-1b00-0000-0961-b4b361130000 pid=4961 clone guuid=452735d3-1b00-0000-0961-b4b365130000 pid=4965 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=452735d3-1b00-0000-0961-b4b365130000 pid=4965 execve guuid=0d50a9d4-1b00-0000-0961-b4b369130000 pid=4969 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=0d50a9d4-1b00-0000-0961-b4b369130000 pid=4969 execve guuid=335984f4-1b00-0000-0961-b4b3ca130000 pid=5066 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=335984f4-1b00-0000-0961-b4b3ca130000 pid=5066 execve guuid=77eb2415-1c00-0000-0961-b4b32a140000 pid=5162 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=77eb2415-1c00-0000-0961-b4b32a140000 pid=5162 execve guuid=f7de7915-1c00-0000-0961-b4b32b140000 pid=5163 /bins/morte.x86 net guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=f7de7915-1c00-0000-0961-b4b32b140000 pid=5163 execve guuid=55fb1a16-1c00-0000-0961-b4b32f140000 pid=5167 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=55fb1a16-1c00-0000-0961-b4b32f140000 pid=5167 execve guuid=188e9116-1c00-0000-0961-b4b333140000 pid=5171 /usr/bin/wget net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=188e9116-1c00-0000-0961-b4b333140000 pid=5171 execve guuid=20408c35-1c00-0000-0961-b4b395140000 pid=5269 /usr/bin/curl net send-data write-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=20408c35-1c00-0000-0961-b4b395140000 pid=5269 execve guuid=c2c82756-1c00-0000-0961-b4b3af140000 pid=5295 /usr/bin/chmod guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=c2c82756-1c00-0000-0961-b4b3af140000 pid=5295 execve guuid=e440a256-1c00-0000-0961-b4b3b0140000 pid=5296 /bins/morte.x86_64 mprotect-exec net guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=e440a256-1c00-0000-0961-b4b3b0140000 pid=5296 execve guuid=b2e99f57-1c00-0000-0961-b4b3b3140000 pid=5299 /usr/bin/rm delete-file guuid=fd8c4899-1700-0000-0961-b4b32f0a0000 pid=2607->guuid=b2e99f57-1c00-0000-0961-b4b3b3140000 pid=5299 execve 3ec9d820-2553-5143-b726-8f9a2d649b55 157.20.32.209:80 guuid=a2ccca9d-1700-0000-0961-b4b33f0a0000 pid=2623->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=65c5e7d2-1700-0000-0961-b4b3d40a0000 pid=2772->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=e3dfc50b-1800-0000-0961-b4b3650b0000 pid=2917->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=14abb62b-1800-0000-0961-b4b3b40b0000 pid=2996->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=64315f4f-1800-0000-0961-b4b30e0c0000 pid=3086->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=80134877-1800-0000-0961-b4b34d0c0000 pid=3149->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=51c1659b-1800-0000-0961-b4b3710c0000 pid=3185->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=f262b5d7-1800-0000-0961-b4b3ab0c0000 pid=3243->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=088af705-1900-0000-0961-b4b3ea0c0000 pid=3306->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=9a432c2f-1900-0000-0961-b4b3200d0000 pid=3360->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=ccf1bf5c-1900-0000-0961-b4b38b0d0000 pid=3467->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=a6e0d87b-1900-0000-0961-b4b3ca0d0000 pid=3530->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f23656c0-1900-0000-0961-b4b3000e0000 pid=3584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d2965cc1-1900-0000-0961-b4b3010e0000 pid=3585 /bins/morte.i686 guuid=f23656c0-1900-0000-0961-b4b3000e0000 pid=3584->guuid=d2965cc1-1900-0000-0961-b4b3010e0000 pid=3585 clone guuid=a3a06fc1-1900-0000-0961-b4b3020e0000 pid=3586 /bins/morte.i686 write-config zombie guuid=d2965cc1-1900-0000-0961-b4b3010e0000 pid=3585->guuid=a3a06fc1-1900-0000-0961-b4b3020e0000 pid=3586 clone guuid=c19c28c6-1900-0000-0961-b4b30d0e0000 pid=3597 /usr/bin/dash guuid=a3a06fc1-1900-0000-0961-b4b3020e0000 pid=3586->guuid=c19c28c6-1900-0000-0961-b4b30d0e0000 pid=3597 execve guuid=98d43dc9-1900-0000-0961-b4b3190e0000 pid=3609 /bins/morte.i686 delete-file dns net send-data guuid=a3a06fc1-1900-0000-0961-b4b3020e0000 pid=3586->guuid=98d43dc9-1900-0000-0961-b4b3190e0000 pid=3609 clone guuid=05827959-1d00-0000-0961-b4b3c5140000 pid=5317 /bins/morte.i686 dns net send-data guuid=a3a06fc1-1900-0000-0961-b4b3020e0000 pid=3586->guuid=05827959-1d00-0000-0961-b4b3c5140000 pid=5317 clone guuid=5a3b37c2-1900-0000-0961-b4b3040e0000 pid=3588->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=be3d8cc6-1900-0000-0961-b4b30f0e0000 pid=3599 /usr/bin/cp guuid=c19c28c6-1900-0000-0961-b4b30d0e0000 pid=3597->guuid=be3d8cc6-1900-0000-0961-b4b30f0e0000 pid=3599 execve guuid=98d43dc9-1900-0000-0961-b4b3190e0000 pid=3609->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 775B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=98d43dc9-1900-0000-0961-b4b3190e0000 pid=3609->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=b09755f5-1900-0000-0961-b4b3770e0000 pid=3703->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=dd782222-1a00-0000-0961-b4b3240f0000 pid=3876->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=8c95ef4a-1a00-0000-0961-b4b38d0f0000 pid=3981->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=3bb86877-1a00-0000-0961-b4b301100000 pid=4097->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 143B guuid=4f631da0-1a00-0000-0961-b4b364100000 pid=4196->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 92B guuid=0bbe94dd-1a00-0000-0961-b4b3e4100000 pid=4324->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=b6f465fd-1a00-0000-0961-b4b33c110000 pid=4412->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=c0330921-1b00-0000-0961-b4b3a9110000 pid=4521->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=edb61d4a-1b00-0000-0961-b4b314120000 pid=4628->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=c31e077a-1b00-0000-0961-b4b396120000 pid=4758->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=a6646da4-1b00-0000-0961-b4b308130000 pid=4872->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=0d50a9d4-1b00-0000-0961-b4b369130000 pid=4969->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 142B guuid=335984f4-1b00-0000-0961-b4b3ca130000 pid=5066->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 91B guuid=f7de7915-1c00-0000-0961-b4b32b140000 pid=5163->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1700e16-1c00-0000-0961-b4b32e140000 pid=5166 /bins/morte.x86 guuid=f7de7915-1c00-0000-0961-b4b32b140000 pid=5163->guuid=f1700e16-1c00-0000-0961-b4b32e140000 pid=5166 clone guuid=25aa1d16-1c00-0000-0961-b4b330140000 pid=5168 /bins/morte.x86 write-config zombie guuid=f1700e16-1c00-0000-0961-b4b32e140000 pid=5166->guuid=25aa1d16-1c00-0000-0961-b4b330140000 pid=5168 clone guuid=a12dd919-1c00-0000-0961-b4b33e140000 pid=5182 /usr/bin/dash guuid=25aa1d16-1c00-0000-0961-b4b330140000 pid=5168->guuid=a12dd919-1c00-0000-0961-b4b33e140000 pid=5182 execve guuid=658e1f1c-1c00-0000-0961-b4b348140000 pid=5192 /bins/morte.x86 dns net send-data zombie guuid=25aa1d16-1c00-0000-0961-b4b330140000 pid=5168->guuid=658e1f1c-1c00-0000-0961-b4b348140000 pid=5192 clone guuid=188e9116-1c00-0000-0961-b4b333140000 pid=5171->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 145B guuid=ca9d011a-1c00-0000-0961-b4b33f140000 pid=5183 /usr/bin/cp guuid=a12dd919-1c00-0000-0961-b4b33e140000 pid=5182->guuid=ca9d011a-1c00-0000-0961-b4b33f140000 pid=5183 execve guuid=658e1f1c-1c00-0000-0961-b4b348140000 pid=5192->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 775B guuid=658e1f1c-1c00-0000-0961-b4b348140000 pid=5192->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=20408c35-1c00-0000-0961-b4b395140000 pid=5269->3ec9d820-2553-5143-b726-8f9a2d649b55 send: 94B guuid=e440a256-1c00-0000-0961-b4b3b0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3afa8457-1c00-0000-0961-b4b3b1140000 pid=5297 /bins/morte.x86_64 zombie guuid=e440a256-1c00-0000-0961-b4b3b0140000 pid=5296->guuid=3afa8457-1c00-0000-0961-b4b3b1140000 pid=5297 clone guuid=4d649657-1c00-0000-0961-b4b3b2140000 pid=5298 /bins/morte.x86_64 write-config zombie guuid=3afa8457-1c00-0000-0961-b4b3b1140000 pid=5297->guuid=4d649657-1c00-0000-0961-b4b3b2140000 pid=5298 clone guuid=d774f457-1c00-0000-0961-b4b3b4140000 pid=5300 /usr/bin/dash guuid=4d649657-1c00-0000-0961-b4b3b2140000 pid=5298->guuid=d774f457-1c00-0000-0961-b4b3b4140000 pid=5300 execve guuid=29dcf558-1c00-0000-0961-b4b3b6140000 pid=5302 /bins/morte.x86_64 dns net send-data guuid=4d649657-1c00-0000-0961-b4b3b2140000 pid=5298->guuid=29dcf558-1c00-0000-0961-b4b3b6140000 pid=5302 clone guuid=dc292e58-1c00-0000-0961-b4b3b5140000 pid=5301 /usr/bin/cp guuid=d774f457-1c00-0000-0961-b4b3b4140000 pid=5300->guuid=dc292e58-1c00-0000-0961-b4b3b5140000 pid=5301 execve guuid=29dcf558-1c00-0000-0961-b4b3b6140000 pid=5302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 775B guuid=29dcf558-1c00-0000-0961-b4b3b6140000 pid=5302->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=05827959-1d00-0000-0961-b4b3c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2325B guuid=05827959-1d00-0000-0961-b4b3c5140000 pid=5317->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-10-02 22:18:42 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery execution linux persistence
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
157.20.32.209
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ecc9b6b2bfabae3e6a9025492815c4af334a9b7fd7547cf4a65a7953bf52f160

(this sample)

  
Delivery method
Distributed via web download

Comments