MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f0de4ca46293b5d0d5edfd37e69f866cfd506d5cc04dd3e39f330a6ccd93ead3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: f0de4ca46293b5d0d5edfd37e69f866cfd506d5cc04dd3e39f330a6ccd93ead3
SHA3-384 hash: bb36769705f132ccb293675710a7446773ff3310805efac08f9f40a34af53c4b8b14df12aa69bfcb52b509e1ed69b1fe
SHA1 hash: 517b24ab83fe7649772e866650c6d9a1f8ca52aa
MD5 hash: 3c0000cc11b578270e94f8cc9b81574d
humanhash: gee-idaho-carolina-pasta
File name:1.sh
Download: download sample
Signature Mirai
File size:2'969 bytes
First seen:2025-10-31 22:04:48 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItZs/N3sFhB0sJGt5J9xaN9Lg7NI8ksbJnjXXOjCeUi:iS/N3sFLZJGtfK9L2JbJnjHOjCni
TLSH T11651D6E538D103347D69E93AB3A4794C3A91B4D790E61FA768D838E4A0CFD05B5E0F82
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://209.141.49.229/Orbt/Orbt.x86dd258a9497fc4af04f0420e4f98e852a6b544f5a253cea4f4109bf066a4b53e9 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.mips6b654482488f83c862d46ab264c19be24ce7ca2c72534066db084473f31a94d7 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.arc17dd5e8f0fbad1dff33178ae8378d2e6472cd421b08397ada166c6675f05d742 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.i468n/an/aelf ua-wget
http://209.141.49.229/Orbt/Orbt.i68662e00dd7bfb4743a202f1fba715eee4f9c8b1b5c86481b5126bd28e01fcea5fb Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.x86_64a3690d48dd05229e06a8de1d9ecac923919f395cc776bef22c15037f8b8e6c60 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.mpsl1f138f89f62439f1cfba40065d45abbf2ecb3c2b3c8467beb5d297f99f8b90dc Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.armfd4edf1203ccea7414ea15042b577b4c4532e60cc29a291224457db5f5281b90 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.arm5f9be88e2e0fefa32f2654c37b8a04e15dac0ddf1bb323f82179e48a90c00476a Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.arm676ed669c5c695512cdfc229798185cd98e72908945454f1ad21625c2f73386d5 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.arm7b153642b892fb063f5e9290a0b01e0bf2f0774567f85d38653ac04ce287653a5 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.ppc3334bfa7ebd9db0de552e059d47231d342cd77a035cd111087fc4aa7e5285974 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.spc30d6e4fcbc22b9f14d8dcce2db53b9a75d95c1029ec426ccb6f1a9e8d4083bf6 Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.m68k482f2363c886e7c3ca46cd69869c60723a8df6332f07b45105bb56fed7239b8d Miraimirai opendir
http://209.141.49.229/Orbt/Orbt.sh417bb39d2ca685bcfc9ba83713d0bd4198ce9f1ed7e2fad308da09ee343d3c1d1 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
40
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-31T19:27:00Z UTC
Last seen:
2025-11-01T16:00:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=d847e213-1800-0000-e0f4-fd225b0c0000 pid=3163 /usr/bin/sudo guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164 /tmp/sample.bin guuid=d847e213-1800-0000-e0f4-fd225b0c0000 pid=3163->guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164 execve guuid=e09c401c-1800-0000-e0f4-fd225d0c0000 pid=3165 /usr/bin/cp guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=e09c401c-1800-0000-e0f4-fd225d0c0000 pid=3165 execve guuid=b9367824-1800-0000-e0f4-fd226d0c0000 pid=3181 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=b9367824-1800-0000-e0f4-fd226d0c0000 pid=3181 execve guuid=e5520950-1800-0000-e0f4-fd22930c0000 pid=3219 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=e5520950-1800-0000-e0f4-fd22930c0000 pid=3219 execve guuid=b260577a-1800-0000-e0f4-fd22c90c0000 pid=3273 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=b260577a-1800-0000-e0f4-fd22c90c0000 pid=3273 execve guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275 /tmp/Orbt.x86 net guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275 execve guuid=022d9fa8-1900-0000-e0f4-fd22fb0e0000 pid=3835 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=022d9fa8-1900-0000-e0f4-fd22fb0e0000 pid=3835 execve guuid=01c437a9-1900-0000-e0f4-fd22fc0e0000 pid=3836 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=01c437a9-1900-0000-e0f4-fd22fc0e0000 pid=3836 execve guuid=64ddced3-1900-0000-e0f4-fd22680f0000 pid=3944 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=64ddced3-1900-0000-e0f4-fd22680f0000 pid=3944 execve guuid=d3abdffe-1900-0000-e0f4-fd22cc0f0000 pid=4044 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d3abdffe-1900-0000-e0f4-fd22cc0f0000 pid=4044 execve guuid=008986ff-1900-0000-e0f4-fd22cd0f0000 pid=4045 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=008986ff-1900-0000-e0f4-fd22cd0f0000 pid=4045 clone guuid=e5349600-1a00-0000-e0f4-fd22d20f0000 pid=4050 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=e5349600-1a00-0000-e0f4-fd22d20f0000 pid=4050 execve guuid=e7d44303-1a00-0000-e0f4-fd22da0f0000 pid=4058 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=e7d44303-1a00-0000-e0f4-fd22da0f0000 pid=4058 execve guuid=168aef2e-1a00-0000-e0f4-fd2240100000 pid=4160 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=168aef2e-1a00-0000-e0f4-fd2240100000 pid=4160 execve guuid=c64a595c-1a00-0000-e0f4-fd22b9100000 pid=4281 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=c64a595c-1a00-0000-e0f4-fd22b9100000 pid=4281 execve guuid=2da0bf5c-1a00-0000-e0f4-fd22ba100000 pid=4282 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=2da0bf5c-1a00-0000-e0f4-fd22ba100000 pid=4282 clone guuid=f2577b5d-1a00-0000-e0f4-fd22be100000 pid=4286 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=f2577b5d-1a00-0000-e0f4-fd22be100000 pid=4286 execve guuid=cc3cd95e-1a00-0000-e0f4-fd22c2100000 pid=4290 /usr/bin/wget net send-data guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=cc3cd95e-1a00-0000-e0f4-fd22c2100000 pid=4290 execve guuid=6bc17a71-1a00-0000-e0f4-fd22f6100000 pid=4342 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=6bc17a71-1a00-0000-e0f4-fd22f6100000 pid=4342 execve guuid=fcf62889-1a00-0000-e0f4-fd223d110000 pid=4413 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=fcf62889-1a00-0000-e0f4-fd223d110000 pid=4413 execve guuid=cb8c9889-1a00-0000-e0f4-fd223f110000 pid=4415 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=cb8c9889-1a00-0000-e0f4-fd223f110000 pid=4415 clone guuid=5b2aba89-1a00-0000-e0f4-fd2241110000 pid=4417 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=5b2aba89-1a00-0000-e0f4-fd2241110000 pid=4417 execve guuid=369b8f8a-1a00-0000-e0f4-fd2246110000 pid=4422 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=369b8f8a-1a00-0000-e0f4-fd2246110000 pid=4422 execve guuid=96e512ae-1a00-0000-e0f4-fd22a0110000 pid=4512 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=96e512ae-1a00-0000-e0f4-fd22a0110000 pid=4512 execve guuid=269e34d6-1a00-0000-e0f4-fd220b120000 pid=4619 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=269e34d6-1a00-0000-e0f4-fd220b120000 pid=4619 execve guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621 /tmp/Orbt.i686 net guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621 execve guuid=0a7cb005-1c00-0000-e0f4-fd227a140000 pid=5242 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=0a7cb005-1c00-0000-e0f4-fd227a140000 pid=5242 execve guuid=50d06807-1c00-0000-e0f4-fd227b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=50d06807-1c00-0000-e0f4-fd227b140000 pid=5243 execve guuid=0e09fd31-1c00-0000-e0f4-fd2284140000 pid=5252 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=0e09fd31-1c00-0000-e0f4-fd2284140000 pid=5252 execve guuid=87189956-1c00-0000-e0f4-fd2285140000 pid=5253 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=87189956-1c00-0000-e0f4-fd2285140000 pid=5253 execve guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254 /tmp/Orbt.x86_64 mprotect-exec net guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254 execve guuid=a0413982-1d00-0000-e0f4-fd2293140000 pid=5267 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=a0413982-1d00-0000-e0f4-fd2293140000 pid=5267 execve guuid=cb34c282-1d00-0000-e0f4-fd2294140000 pid=5268 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=cb34c282-1d00-0000-e0f4-fd2294140000 pid=5268 execve guuid=7ed7cca6-1d00-0000-e0f4-fd2295140000 pid=5269 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=7ed7cca6-1d00-0000-e0f4-fd2295140000 pid=5269 execve guuid=c80a4dcd-1d00-0000-e0f4-fd229c140000 pid=5276 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=c80a4dcd-1d00-0000-e0f4-fd229c140000 pid=5276 execve guuid=380ddecd-1d00-0000-e0f4-fd229d140000 pid=5277 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=380ddecd-1d00-0000-e0f4-fd229d140000 pid=5277 clone guuid=83f805cf-1d00-0000-e0f4-fd229f140000 pid=5279 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=83f805cf-1d00-0000-e0f4-fd229f140000 pid=5279 execve guuid=ef6794cf-1d00-0000-e0f4-fd22a1140000 pid=5281 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=ef6794cf-1d00-0000-e0f4-fd22a1140000 pid=5281 execve guuid=79d911f7-1d00-0000-e0f4-fd22ab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=79d911f7-1d00-0000-e0f4-fd22ab140000 pid=5291 execve guuid=377ecc1a-1e00-0000-e0f4-fd22bc140000 pid=5308 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=377ecc1a-1e00-0000-e0f4-fd22bc140000 pid=5308 execve guuid=f6bd531b-1e00-0000-e0f4-fd22bd140000 pid=5309 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=f6bd531b-1e00-0000-e0f4-fd22bd140000 pid=5309 clone guuid=88fa631c-1e00-0000-e0f4-fd22bf140000 pid=5311 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=88fa631c-1e00-0000-e0f4-fd22bf140000 pid=5311 execve guuid=850bec1c-1e00-0000-e0f4-fd22c0140000 pid=5312 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=850bec1c-1e00-0000-e0f4-fd22c0140000 pid=5312 execve guuid=2655d238-1e00-0000-e0f4-fd22c1140000 pid=5313 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=2655d238-1e00-0000-e0f4-fd22c1140000 pid=5313 execve guuid=d5c68059-1e00-0000-e0f4-fd22c2140000 pid=5314 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d5c68059-1e00-0000-e0f4-fd22c2140000 pid=5314 execve guuid=1b38285a-1e00-0000-e0f4-fd22c3140000 pid=5315 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=1b38285a-1e00-0000-e0f4-fd22c3140000 pid=5315 clone guuid=36f9635b-1e00-0000-e0f4-fd22c5140000 pid=5317 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=36f9635b-1e00-0000-e0f4-fd22c5140000 pid=5317 execve guuid=89cb415c-1e00-0000-e0f4-fd22c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=89cb415c-1e00-0000-e0f4-fd22c6140000 pid=5318 execve guuid=99969c80-1e00-0000-e0f4-fd22c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=99969c80-1e00-0000-e0f4-fd22c7140000 pid=5319 execve guuid=81dedda7-1e00-0000-e0f4-fd22c8140000 pid=5320 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=81dedda7-1e00-0000-e0f4-fd22c8140000 pid=5320 execve guuid=69b26ba8-1e00-0000-e0f4-fd22c9140000 pid=5321 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=69b26ba8-1e00-0000-e0f4-fd22c9140000 pid=5321 clone guuid=d91103aa-1e00-0000-e0f4-fd22cb140000 pid=5323 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d91103aa-1e00-0000-e0f4-fd22cb140000 pid=5323 execve guuid=c41197aa-1e00-0000-e0f4-fd22cc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=c41197aa-1e00-0000-e0f4-fd22cc140000 pid=5324 execve guuid=49dd1fd7-1e00-0000-e0f4-fd22cd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=49dd1fd7-1e00-0000-e0f4-fd22cd140000 pid=5325 execve guuid=1b832706-1f00-0000-e0f4-fd22ce140000 pid=5326 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=1b832706-1f00-0000-e0f4-fd22ce140000 pid=5326 execve guuid=fee2c406-1f00-0000-e0f4-fd22cf140000 pid=5327 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=fee2c406-1f00-0000-e0f4-fd22cf140000 pid=5327 clone guuid=a4de0408-1f00-0000-e0f4-fd22d1140000 pid=5329 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=a4de0408-1f00-0000-e0f4-fd22d1140000 pid=5329 execve guuid=d9b89e08-1f00-0000-e0f4-fd22d2140000 pid=5330 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d9b89e08-1f00-0000-e0f4-fd22d2140000 pid=5330 execve guuid=5534c234-1f00-0000-e0f4-fd22d3140000 pid=5331 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=5534c234-1f00-0000-e0f4-fd22d3140000 pid=5331 execve guuid=d8e8f359-1f00-0000-e0f4-fd22d4140000 pid=5332 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d8e8f359-1f00-0000-e0f4-fd22d4140000 pid=5332 execve guuid=0d37825a-1f00-0000-e0f4-fd22d5140000 pid=5333 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=0d37825a-1f00-0000-e0f4-fd22d5140000 pid=5333 clone guuid=d9ea005c-1f00-0000-e0f4-fd22d7140000 pid=5335 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d9ea005c-1f00-0000-e0f4-fd22d7140000 pid=5335 execve guuid=b53db55c-1f00-0000-e0f4-fd22d8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=b53db55c-1f00-0000-e0f4-fd22d8140000 pid=5336 execve guuid=9e643987-1f00-0000-e0f4-fd22d9140000 pid=5337 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=9e643987-1f00-0000-e0f4-fd22d9140000 pid=5337 execve guuid=1ba139b1-1f00-0000-e0f4-fd22da140000 pid=5338 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=1ba139b1-1f00-0000-e0f4-fd22da140000 pid=5338 execve guuid=d065c8b1-1f00-0000-e0f4-fd22db140000 pid=5339 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=d065c8b1-1f00-0000-e0f4-fd22db140000 pid=5339 clone guuid=990cf6b2-1f00-0000-e0f4-fd22dd140000 pid=5341 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=990cf6b2-1f00-0000-e0f4-fd22dd140000 pid=5341 execve guuid=f4048db3-1f00-0000-e0f4-fd22de140000 pid=5342 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=f4048db3-1f00-0000-e0f4-fd22de140000 pid=5342 execve guuid=10636fe8-1f00-0000-e0f4-fd22df140000 pid=5343 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=10636fe8-1f00-0000-e0f4-fd22df140000 pid=5343 execve guuid=e73d1eba-2000-0000-e0f4-fd22e0140000 pid=5344 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=e73d1eba-2000-0000-e0f4-fd22e0140000 pid=5344 execve guuid=4ac8b0ba-2000-0000-e0f4-fd22e1140000 pid=5345 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=4ac8b0ba-2000-0000-e0f4-fd22e1140000 pid=5345 clone guuid=378ad6bb-2000-0000-e0f4-fd22e3140000 pid=5347 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=378ad6bb-2000-0000-e0f4-fd22e3140000 pid=5347 execve guuid=b9016abc-2000-0000-e0f4-fd22e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=b9016abc-2000-0000-e0f4-fd22e4140000 pid=5348 execve guuid=1da18ee9-2000-0000-e0f4-fd22e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=1da18ee9-2000-0000-e0f4-fd22e5140000 pid=5349 execve guuid=6f2ded1d-2100-0000-e0f4-fd22e6140000 pid=5350 /usr/bin/chmod guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=6f2ded1d-2100-0000-e0f4-fd22e6140000 pid=5350 execve guuid=97327b1e-2100-0000-e0f4-fd22e7140000 pid=5351 /usr/bin/bash guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=97327b1e-2100-0000-e0f4-fd22e7140000 pid=5351 clone guuid=fb2fb91f-2100-0000-e0f4-fd22e9140000 pid=5353 /usr/bin/rm delete-file guuid=d79b0416-1800-0000-e0f4-fd225c0c0000 pid=3164->guuid=fb2fb91f-2100-0000-e0f4-fd22e9140000 pid=5353 execve 1b90f26c-e3c4-5957-98ef-9f59b69901dd 209.141.49.229:80 guuid=b9367824-1800-0000-e0f4-fd226d0c0000 pid=3181->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=e5520950-1800-0000-e0f4-fd22930c0000 pid=3219->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3852407c-1800-0000-e0f4-fd22ce0c0000 pid=3278 /tmp/Orbt.x86 guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275->guuid=3852407c-1800-0000-e0f4-fd22ce0c0000 pid=3278 clone guuid=06da8ba8-1900-0000-e0f4-fd22f90e0000 pid=3833 /tmp/Orbt.x86 guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275->guuid=06da8ba8-1900-0000-e0f4-fd22f90e0000 pid=3833 clone guuid=e43092a8-1900-0000-e0f4-fd22fa0e0000 pid=3834 /tmp/Orbt.x86 net send-data zombie guuid=5e96e57a-1800-0000-e0f4-fd22cb0c0000 pid=3275->guuid=e43092a8-1900-0000-e0f4-fd22fa0e0000 pid=3834 clone guuid=92994f7c-1800-0000-e0f4-fd22cf0c0000 pid=3279 /tmp/Orbt.x86 guuid=3852407c-1800-0000-e0f4-fd22ce0c0000 pid=3278->guuid=92994f7c-1800-0000-e0f4-fd22cf0c0000 pid=3279 clone guuid=b47c577c-1800-0000-e0f4-fd22d00c0000 pid=3280 /tmp/Orbt.x86 dns net send-data zombie guuid=3852407c-1800-0000-e0f4-fd22ce0c0000 pid=3278->guuid=b47c577c-1800-0000-e0f4-fd22d00c0000 pid=3280 clone guuid=b47c577c-1800-0000-e0f4-fd22d00c0000 pid=3280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 123B 835e2637-8ea8-5733-9bcd-e417a3d56db3 lolzzmortex.duckdns.org:69 guuid=b47c577c-1800-0000-e0f4-fd22d00c0000 pid=3280->835e2637-8ea8-5733-9bcd-e417a3d56db3 con guuid=e43092a8-1900-0000-e0f4-fd22fa0e0000 pid=3834->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1025B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=e43092a8-1900-0000-e0f4-fd22fa0e0000 pid=3834->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=01c437a9-1900-0000-e0f4-fd22fc0e0000 pid=3836->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=64ddced3-1900-0000-e0f4-fd22680f0000 pid=3944->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=e7d44303-1a00-0000-e0f4-fd22da0f0000 pid=4058->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=168aef2e-1a00-0000-e0f4-fd2240100000 pid=4160->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B guuid=cc3cd95e-1a00-0000-e0f4-fd22c2100000 pid=4290->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=6bc17a71-1a00-0000-e0f4-fd22f6100000 pid=4342->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=369b8f8a-1a00-0000-e0f4-fd2246110000 pid=4422->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=96e512ae-1a00-0000-e0f4-fd22a0110000 pid=4512->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=86b35ed8-1a00-0000-e0f4-fd2211120000 pid=4625 /tmp/Orbt.i686 guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621->guuid=86b35ed8-1a00-0000-e0f4-fd2211120000 pid=4625 clone guuid=39269d05-1c00-0000-e0f4-fd2278140000 pid=5240 /tmp/Orbt.i686 guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621->guuid=39269d05-1c00-0000-e0f4-fd2278140000 pid=5240 clone guuid=4ca5a205-1c00-0000-e0f4-fd2279140000 pid=5241 /tmp/Orbt.i686 net send-data zombie guuid=0d08bed6-1a00-0000-e0f4-fd220d120000 pid=4621->guuid=4ca5a205-1c00-0000-e0f4-fd2279140000 pid=5241 clone guuid=df1f74d8-1a00-0000-e0f4-fd2213120000 pid=4627 /tmp/Orbt.i686 guuid=86b35ed8-1a00-0000-e0f4-fd2211120000 pid=4625->guuid=df1f74d8-1a00-0000-e0f4-fd2213120000 pid=4627 clone guuid=6aaf7bd8-1a00-0000-e0f4-fd2214120000 pid=4628 /tmp/Orbt.i686 dns net send-data zombie guuid=86b35ed8-1a00-0000-e0f4-fd2211120000 pid=4625->guuid=6aaf7bd8-1a00-0000-e0f4-fd2214120000 pid=4628 clone guuid=6aaf7bd8-1a00-0000-e0f4-fd2214120000 pid=4628->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 164B guuid=6aaf7bd8-1a00-0000-e0f4-fd2214120000 pid=4628->835e2637-8ea8-5733-9bcd-e417a3d56db3 con guuid=4ca5a205-1c00-0000-e0f4-fd2279140000 pid=5241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=4ca5a205-1c00-0000-e0f4-fd2279140000 pid=5241->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=50d06807-1c00-0000-e0f4-fd227b140000 pid=5243->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 145B guuid=0e09fd31-1c00-0000-e0f4-fd2284140000 pid=5252->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 94B guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d2f9a357-1c00-0000-e0f4-fd2287140000 pid=5255 /tmp/Orbt.x86_64 guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254->guuid=d2f9a357-1c00-0000-e0f4-fd2287140000 pid=5255 clone guuid=cf0a2682-1d00-0000-e0f4-fd2291140000 pid=5265 /tmp/Orbt.x86_64 guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254->guuid=cf0a2682-1d00-0000-e0f4-fd2291140000 pid=5265 clone guuid=026d2b82-1d00-0000-e0f4-fd2292140000 pid=5266 /tmp/Orbt.x86_64 net send-data zombie guuid=d4bfeb56-1c00-0000-e0f4-fd2286140000 pid=5254->guuid=026d2b82-1d00-0000-e0f4-fd2292140000 pid=5266 clone guuid=8bd6aa57-1c00-0000-e0f4-fd2288140000 pid=5256 /tmp/Orbt.x86_64 guuid=d2f9a357-1c00-0000-e0f4-fd2287140000 pid=5255->guuid=8bd6aa57-1c00-0000-e0f4-fd2288140000 pid=5256 clone guuid=d62aae57-1c00-0000-e0f4-fd2289140000 pid=5257 /tmp/Orbt.x86_64 net send-data zombie guuid=d2f9a357-1c00-0000-e0f4-fd2287140000 pid=5255->guuid=d62aae57-1c00-0000-e0f4-fd2289140000 pid=5257 clone guuid=d62aae57-1c00-0000-e0f4-fd2289140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=d62aae57-1c00-0000-e0f4-fd2289140000 pid=5257->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=026d2b82-1d00-0000-e0f4-fd2292140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 820B guuid=026d2b82-1d00-0000-e0f4-fd2292140000 pid=5266->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=cb34c282-1d00-0000-e0f4-fd2294140000 pid=5268->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=7ed7cca6-1d00-0000-e0f4-fd2295140000 pid=5269->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=ef6794cf-1d00-0000-e0f4-fd22a1140000 pid=5281->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=79d911f7-1d00-0000-e0f4-fd22ab140000 pid=5291->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B guuid=850bec1c-1e00-0000-e0f4-fd22c0140000 pid=5312->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=2655d238-1e00-0000-e0f4-fd22c1140000 pid=5313->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=89cb415c-1e00-0000-e0f4-fd22c6140000 pid=5318->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=99969c80-1e00-0000-e0f4-fd22c7140000 pid=5319->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=c41197aa-1e00-0000-e0f4-fd22cc140000 pid=5324->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=49dd1fd7-1e00-0000-e0f4-fd22cd140000 pid=5325->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=d9b89e08-1f00-0000-e0f4-fd22d2140000 pid=5330->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=5534c234-1f00-0000-e0f4-fd22d3140000 pid=5331->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B guuid=b53db55c-1f00-0000-e0f4-fd22d8140000 pid=5336->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=9e643987-1f00-0000-e0f4-fd22d9140000 pid=5337->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B guuid=f4048db3-1f00-0000-e0f4-fd22de140000 pid=5342->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 143B guuid=10636fe8-1f00-0000-e0f4-fd22df140000 pid=5343->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 92B guuid=b9016abc-2000-0000-e0f4-fd22e4140000 pid=5348->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 142B guuid=1da18ee9-2000-0000-e0f4-fd22e5140000 pid=5349->1b90f26c-e3c4-5957-98ef-9f59b69901dd send: 91B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-31 22:18:11 UTC
File Type:
Text (Shell)
AV detection:
22 of 38 (57.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
lolzzmortex.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f0de4ca46293b5d0d5edfd37e69f866cfd506d5cc04dd3e39f330a6ccd93ead3

(this sample)

Comments