MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f194289631fe35021f88dd3daaee28e4b1e04f03a9697084c472e20330f51db8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f194289631fe35021f88dd3daaee28e4b1e04f03a9697084c472e20330f51db8
SHA3-384 hash: 9492cf1c9fdb8322bf33efaae0292eff892f781d4e16b2e1d8d69603ddae63ea0f1c16a6b93dfe86dc3cf264627a852b
SHA1 hash: 8663c2d221a76f192252f5678cfd8789a809da44
MD5 hash: 3ddf6daad2ed3546ad44b2ff2fbf295a
humanhash: cat-zulu-cold-earth
File name:1.sh
Download: download sample
Signature Mirai
File size:3'253 bytes
First seen:2025-09-21 03:28:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:It3ZsvbhHkblfnmsXTyBGgJn6vnLcPNIpKksDMEVhXsCtcGgJsKOpa:iidEp3DyB16PLiJlH8CtBgJs7a
TLSH T1A16170FB1341073BEDA68DE372A84404B284409BD4CEEF765BFC78A54EADEC92D41642
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://84.201.5.31/00101010101001/morte.x8657c45b6b28433f72a53e439cd32cb99077386dcd497c5a6d7ff9ca9135e9be4c Miraimirai opendir
http://84.201.5.31/00101010101001/morte.mipsea84573d28ba0d96bb3456e6dabbb4fe71368a7e34cf013e89071d3b7f5cbca3 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.arcee39075e53eb9454ea4e3fa1f1e13ceb1d79512e031068f637c0f51e7db7baa0 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.i468n/an/aelf ua-wget
http://84.201.5.31/00101010101001/morte.i6869857a7f28670ebb79ecacebb9182264f7950db124033b4e0aed2b9c8e3819e28 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.x86_64a20c81fff3c937e0c96bc4f00a847490c6fa5bf5f360fc208213e05dc5f2bfc1 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.mpslada6c6994010559d659cff358dc24675164165c3918429d3f25348f2110d7401 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.armaf6fb0c1a129cf01e1944423f9e03ee2db7baf59511b72752297790124dd32c6 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.arm5913ee4326edeb5752b661023046c9bdd479450a744fa94fb8b702389369fa0fc Miraimirai opendir
http://84.201.5.31/00101010101001/morte.arm68b98da24cffb4a4409b3b2ba001a5b93d78d6bbe8df2878d71d24774ac6ceb53 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.arm7a911945a1aa7d0113378f66d90d94b34f5561a19498188dfe5e045101a79aa4f Miraimirai opendir
http://84.201.5.31/00101010101001/morte.ppc0061e7300d9c568ebd211a8af1583ba797abdcf89175553044660b4222401c88 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.spc67a6972acf50ac27b5f7e1190edfc7cfb2946eb0185979a841960e446ab0b726 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.m68k240d245f60e896a4aa332816226b0d23defcb95b0f99bd6ed1ad302465539582 Miraimirai opendir
http://84.201.5.31/00101010101001/morte.sh4fd10c7fd9ea0f7fe3c8e91e31f009b079ff5f58556e83cd6f087d63e76bff751 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-21T00:42:00Z UTC
Last seen:
2025-09-21T00:42:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=eeaa4165-1900-0000-b47a-9bdb900c0000 pid=3216 /usr/bin/sudo guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222 /tmp/sample.bin guuid=eeaa4165-1900-0000-b47a-9bdb900c0000 pid=3216->guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222 execve guuid=2d1a5e69-1900-0000-b47a-9bdb980c0000 pid=3224 /usr/bin/cp guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=2d1a5e69-1900-0000-b47a-9bdb980c0000 pid=3224 execve guuid=e022446f-1900-0000-b47a-9bdba00c0000 pid=3232 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=e022446f-1900-0000-b47a-9bdba00c0000 pid=3232 execve guuid=9f5f3776-1900-0000-b47a-9bdba20c0000 pid=3234 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=9f5f3776-1900-0000-b47a-9bdba20c0000 pid=3234 execve guuid=98a19983-1900-0000-b47a-9bdbb70c0000 pid=3255 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=98a19983-1900-0000-b47a-9bdbb70c0000 pid=3255 execve guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256 /tmp/morte.x86 net guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256 execve guuid=4c2755b2-1a00-0000-b47a-9bdb860f0000 pid=3974 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=4c2755b2-1a00-0000-b47a-9bdb860f0000 pid=3974 execve guuid=ccb89eb2-1a00-0000-b47a-9bdb870f0000 pid=3975 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=ccb89eb2-1a00-0000-b47a-9bdb870f0000 pid=3975 execve guuid=4b3f57b6-1a00-0000-b47a-9bdb950f0000 pid=3989 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=4b3f57b6-1a00-0000-b47a-9bdb950f0000 pid=3989 execve guuid=fe4217bc-1a00-0000-b47a-9bdbaa0f0000 pid=4010 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=fe4217bc-1a00-0000-b47a-9bdbaa0f0000 pid=4010 execve guuid=cf5968bc-1a00-0000-b47a-9bdbab0f0000 pid=4011 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=cf5968bc-1a00-0000-b47a-9bdbab0f0000 pid=4011 clone guuid=684f78be-1a00-0000-b47a-9bdbb60f0000 pid=4022 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=684f78be-1a00-0000-b47a-9bdbb60f0000 pid=4022 execve guuid=316ec8be-1a00-0000-b47a-9bdbb70f0000 pid=4023 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=316ec8be-1a00-0000-b47a-9bdbb70f0000 pid=4023 execve guuid=a09ff2c3-1a00-0000-b47a-9bdbc70f0000 pid=4039 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=a09ff2c3-1a00-0000-b47a-9bdbc70f0000 pid=4039 execve guuid=456410cb-1a00-0000-b47a-9bdbe70f0000 pid=4071 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=456410cb-1a00-0000-b47a-9bdbe70f0000 pid=4071 execve guuid=9c8b59cb-1a00-0000-b47a-9bdbe90f0000 pid=4073 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=9c8b59cb-1a00-0000-b47a-9bdbe90f0000 pid=4073 clone guuid=630f69cc-1a00-0000-b47a-9bdbee0f0000 pid=4078 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=630f69cc-1a00-0000-b47a-9bdbee0f0000 pid=4078 execve guuid=1fc48bcd-1a00-0000-b47a-9bdbf30f0000 pid=4083 /usr/bin/wget net send-data guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=1fc48bcd-1a00-0000-b47a-9bdbf30f0000 pid=4083 execve guuid=fc82b3d1-1a00-0000-b47a-9bdb02100000 pid=4098 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=fc82b3d1-1a00-0000-b47a-9bdb02100000 pid=4098 execve guuid=2a8bb7d6-1a00-0000-b47a-9bdb10100000 pid=4112 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=2a8bb7d6-1a00-0000-b47a-9bdb10100000 pid=4112 execve guuid=6d6927d7-1a00-0000-b47a-9bdb12100000 pid=4114 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=6d6927d7-1a00-0000-b47a-9bdb12100000 pid=4114 clone guuid=67c45bd7-1a00-0000-b47a-9bdb13100000 pid=4115 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=67c45bd7-1a00-0000-b47a-9bdb13100000 pid=4115 execve guuid=54b6e2d7-1a00-0000-b47a-9bdb14100000 pid=4116 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=54b6e2d7-1a00-0000-b47a-9bdb14100000 pid=4116 execve guuid=7c9332dc-1a00-0000-b47a-9bdb22100000 pid=4130 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=7c9332dc-1a00-0000-b47a-9bdb22100000 pid=4130 execve guuid=126af101-1b00-0000-b47a-9bdb98100000 pid=4248 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=126af101-1b00-0000-b47a-9bdb98100000 pid=4248 execve guuid=371a4702-1b00-0000-b47a-9bdb9c100000 pid=4252 /tmp/morte.i686 net guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=371a4702-1b00-0000-b47a-9bdb9c100000 pid=4252 execve guuid=064f497a-1b00-0000-b47a-9bdb3b120000 pid=4667 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=064f497a-1b00-0000-b47a-9bdb3b120000 pid=4667 execve guuid=8c50a894-1b00-0000-b47a-9bdb4f120000 pid=4687 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=8c50a894-1b00-0000-b47a-9bdb4f120000 pid=4687 execve guuid=05b6359a-1b00-0000-b47a-9bdb5f120000 pid=4703 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=05b6359a-1b00-0000-b47a-9bdb5f120000 pid=4703 execve guuid=5dd842a0-1b00-0000-b47a-9bdb75120000 pid=4725 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=5dd842a0-1b00-0000-b47a-9bdb75120000 pid=4725 execve guuid=5dc2a4a0-1b00-0000-b47a-9bdb78120000 pid=4728 /tmp/morte.x86_64 mprotect-exec net guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=5dc2a4a0-1b00-0000-b47a-9bdb78120000 pid=4728 execve guuid=a5636518-1c00-0000-b47a-9bdb11140000 pid=5137 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=a5636518-1c00-0000-b47a-9bdb11140000 pid=5137 execve guuid=45e5d118-1c00-0000-b47a-9bdb13140000 pid=5139 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=45e5d118-1c00-0000-b47a-9bdb13140000 pid=5139 execve guuid=58d8db1c-1c00-0000-b47a-9bdb20140000 pid=5152 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=58d8db1c-1c00-0000-b47a-9bdb20140000 pid=5152 execve guuid=45efb821-1c00-0000-b47a-9bdb2e140000 pid=5166 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=45efb821-1c00-0000-b47a-9bdb2e140000 pid=5166 execve guuid=c627ff21-1c00-0000-b47a-9bdb2f140000 pid=5167 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=c627ff21-1c00-0000-b47a-9bdb2f140000 pid=5167 clone guuid=c5348e22-1c00-0000-b47a-9bdb33140000 pid=5171 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=c5348e22-1c00-0000-b47a-9bdb33140000 pid=5171 execve guuid=30fad222-1c00-0000-b47a-9bdb35140000 pid=5173 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=30fad222-1c00-0000-b47a-9bdb35140000 pid=5173 execve guuid=75e65026-1c00-0000-b47a-9bdb3f140000 pid=5183 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=75e65026-1c00-0000-b47a-9bdb3f140000 pid=5183 execve guuid=f82acf2a-1c00-0000-b47a-9bdb4f140000 pid=5199 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=f82acf2a-1c00-0000-b47a-9bdb4f140000 pid=5199 execve guuid=78f3122b-1c00-0000-b47a-9bdb51140000 pid=5201 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=78f3122b-1c00-0000-b47a-9bdb51140000 pid=5201 clone guuid=978faa2b-1c00-0000-b47a-9bdb55140000 pid=5205 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=978faa2b-1c00-0000-b47a-9bdb55140000 pid=5205 execve guuid=3de5f12b-1c00-0000-b47a-9bdb56140000 pid=5206 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=3de5f12b-1c00-0000-b47a-9bdb56140000 pid=5206 execve guuid=e611932f-1c00-0000-b47a-9bdb69140000 pid=5225 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=e611932f-1c00-0000-b47a-9bdb69140000 pid=5225 execve guuid=52d3ca34-1c00-0000-b47a-9bdb8c140000 pid=5260 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=52d3ca34-1c00-0000-b47a-9bdb8c140000 pid=5260 execve guuid=0a030f35-1c00-0000-b47a-9bdb8f140000 pid=5263 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=0a030f35-1c00-0000-b47a-9bdb8f140000 pid=5263 clone guuid=9e61c135-1c00-0000-b47a-9bdb92140000 pid=5266 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=9e61c135-1c00-0000-b47a-9bdb92140000 pid=5266 execve guuid=81ff3036-1c00-0000-b47a-9bdb93140000 pid=5267 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=81ff3036-1c00-0000-b47a-9bdb93140000 pid=5267 execve guuid=072a373a-1c00-0000-b47a-9bdb94140000 pid=5268 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=072a373a-1c00-0000-b47a-9bdb94140000 pid=5268 execve guuid=695d0d3f-1c00-0000-b47a-9bdb95140000 pid=5269 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=695d0d3f-1c00-0000-b47a-9bdb95140000 pid=5269 execve guuid=5197553f-1c00-0000-b47a-9bdb96140000 pid=5270 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=5197553f-1c00-0000-b47a-9bdb96140000 pid=5270 clone guuid=4d1ff13f-1c00-0000-b47a-9bdb98140000 pid=5272 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=4d1ff13f-1c00-0000-b47a-9bdb98140000 pid=5272 execve guuid=15f77d48-1c00-0000-b47a-9bdb9c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=15f77d48-1c00-0000-b47a-9bdb9c140000 pid=5276 execve guuid=50d0934d-1c00-0000-b47a-9bdb9d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=50d0934d-1c00-0000-b47a-9bdb9d140000 pid=5277 execve guuid=5e06e753-1c00-0000-b47a-9bdba6140000 pid=5286 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=5e06e753-1c00-0000-b47a-9bdba6140000 pid=5286 execve guuid=e5993754-1c00-0000-b47a-9bdba7140000 pid=5287 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=e5993754-1c00-0000-b47a-9bdba7140000 pid=5287 clone guuid=8d91d254-1c00-0000-b47a-9bdba9140000 pid=5289 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=8d91d254-1c00-0000-b47a-9bdba9140000 pid=5289 execve guuid=2b212055-1c00-0000-b47a-9bdbaa140000 pid=5290 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=2b212055-1c00-0000-b47a-9bdbaa140000 pid=5290 execve guuid=4f91c758-1c00-0000-b47a-9bdbab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=4f91c758-1c00-0000-b47a-9bdbab140000 pid=5291 execve guuid=7d444c5d-1c00-0000-b47a-9bdbac140000 pid=5292 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=7d444c5d-1c00-0000-b47a-9bdbac140000 pid=5292 execve guuid=724b985d-1c00-0000-b47a-9bdbad140000 pid=5293 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=724b985d-1c00-0000-b47a-9bdbad140000 pid=5293 clone guuid=71f72a5e-1c00-0000-b47a-9bdbaf140000 pid=5295 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=71f72a5e-1c00-0000-b47a-9bdbaf140000 pid=5295 execve guuid=b7c57b5e-1c00-0000-b47a-9bdbb0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=b7c57b5e-1c00-0000-b47a-9bdbb0140000 pid=5296 execve guuid=06394e63-1c00-0000-b47a-9bdbb1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=06394e63-1c00-0000-b47a-9bdbb1140000 pid=5297 execve guuid=e5cc9e6b-1c00-0000-b47a-9bdbb2140000 pid=5298 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=e5cc9e6b-1c00-0000-b47a-9bdbb2140000 pid=5298 execve guuid=da67ec6b-1c00-0000-b47a-9bdbb3140000 pid=5299 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=da67ec6b-1c00-0000-b47a-9bdbb3140000 pid=5299 clone guuid=579ba16c-1c00-0000-b47a-9bdbb5140000 pid=5301 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=579ba16c-1c00-0000-b47a-9bdbb5140000 pid=5301 execve guuid=64f0d373-1c00-0000-b47a-9bdbb6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=64f0d373-1c00-0000-b47a-9bdbb6140000 pid=5302 execve guuid=b6e94d79-1c00-0000-b47a-9bdbb7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=b6e94d79-1c00-0000-b47a-9bdbb7140000 pid=5303 execve guuid=6b5ade80-1c00-0000-b47a-9bdbb8140000 pid=5304 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=6b5ade80-1c00-0000-b47a-9bdbb8140000 pid=5304 execve guuid=6d013481-1c00-0000-b47a-9bdbb9140000 pid=5305 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=6d013481-1c00-0000-b47a-9bdbb9140000 pid=5305 clone guuid=87374682-1c00-0000-b47a-9bdbbb140000 pid=5307 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=87374682-1c00-0000-b47a-9bdbbb140000 pid=5307 execve guuid=d0afcd82-1c00-0000-b47a-9bdbbc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=d0afcd82-1c00-0000-b47a-9bdbbc140000 pid=5308 execve guuid=d4e55187-1c00-0000-b47a-9bdbbd140000 pid=5309 /usr/bin/curl net send-data write-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=d4e55187-1c00-0000-b47a-9bdbbd140000 pid=5309 execve guuid=fbadd38c-1c00-0000-b47a-9bdbbe140000 pid=5310 /usr/bin/chmod guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=fbadd38c-1c00-0000-b47a-9bdbbe140000 pid=5310 execve guuid=894c268d-1c00-0000-b47a-9bdbbf140000 pid=5311 /usr/bin/bash guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=894c268d-1c00-0000-b47a-9bdbbf140000 pid=5311 clone guuid=8297c78d-1c00-0000-b47a-9bdbc1140000 pid=5313 /usr/bin/rm delete-file guuid=e2a6b868-1900-0000-b47a-9bdb960c0000 pid=3222->guuid=8297c78d-1c00-0000-b47a-9bdbc1140000 pid=5313 execve 20a72524-ca42-5f6d-97a4-44237a105111 84.201.5.31:80 guuid=e022446f-1900-0000-b47a-9bdba00c0000 pid=3232->20a72524-ca42-5f6d-97a4-44237a105111 send: 150B guuid=9f5f3776-1900-0000-b47a-9bdba20c0000 pid=3234->20a72524-ca42-5f6d-97a4-44237a105111 send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=976de084-1900-0000-b47a-9bdbb90c0000 pid=3257 /tmp/morte.x86 guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256->guuid=976de084-1900-0000-b47a-9bdbb90c0000 pid=3257 clone guuid=abb749b2-1a00-0000-b47a-9bdb840f0000 pid=3972 /tmp/morte.x86 guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256->guuid=abb749b2-1a00-0000-b47a-9bdb840f0000 pid=3972 clone guuid=4cc94cb2-1a00-0000-b47a-9bdb850f0000 pid=3973 /tmp/morte.x86 net send-data zombie guuid=349a3684-1900-0000-b47a-9bdbb80c0000 pid=3256->guuid=4cc94cb2-1a00-0000-b47a-9bdb850f0000 pid=3973 clone guuid=58cceb84-1900-0000-b47a-9bdbba0c0000 pid=3258 /tmp/morte.x86 guuid=976de084-1900-0000-b47a-9bdbb90c0000 pid=3257->guuid=58cceb84-1900-0000-b47a-9bdbba0c0000 pid=3258 clone guuid=939af384-1900-0000-b47a-9bdbbb0c0000 pid=3259 /tmp/morte.x86 dns net send-data zombie guuid=976de084-1900-0000-b47a-9bdbb90c0000 pid=3257->guuid=939af384-1900-0000-b47a-9bdbbb0c0000 pid=3259 clone guuid=939af384-1900-0000-b47a-9bdbbb0c0000 pid=3259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B a1a7e44c-f53d-520b-b2c8-ccb9907e473c uraniumc2.ddns.net:12121 guuid=939af384-1900-0000-b47a-9bdbbb0c0000 pid=3259->a1a7e44c-f53d-520b-b2c8-ccb9907e473c send: 15B guuid=4cc94cb2-1a00-0000-b47a-9bdb850f0000 pid=3973->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 180B a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 uraniumc2.ddns.net:80 guuid=4cc94cb2-1a00-0000-b47a-9bdb850f0000 pid=3973->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 15B guuid=ccb89eb2-1a00-0000-b47a-9bdb870f0000 pid=3975->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=4b3f57b6-1a00-0000-b47a-9bdb950f0000 pid=3989->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=316ec8be-1a00-0000-b47a-9bdbb70f0000 pid=4023->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 150B guuid=a09ff2c3-1a00-0000-b47a-9bdbc70f0000 pid=4039->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 99B guuid=1fc48bcd-1a00-0000-b47a-9bdbf30f0000 pid=4083->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=fc82b3d1-1a00-0000-b47a-9bdb02100000 pid=4098->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=54b6e2d7-1a00-0000-b47a-9bdb14100000 pid=4116->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=7c9332dc-1a00-0000-b47a-9bdb22100000 pid=4130->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=371a4702-1b00-0000-b47a-9bdb9c100000 pid=4252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=371a4702-1b00-0000-b47a-9bdb9c100000 pid=4252->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=8c50a894-1b00-0000-b47a-9bdb4f120000 pid=4687->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 153B guuid=05b6359a-1b00-0000-b47a-9bdb5f120000 pid=4703->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 102B guuid=5dc2a4a0-1b00-0000-b47a-9bdb78120000 pid=4728->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5dc2a4a0-1b00-0000-b47a-9bdb78120000 pid=4728->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=45e5d118-1c00-0000-b47a-9bdb13140000 pid=5139->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=58d8db1c-1c00-0000-b47a-9bdb20140000 pid=5152->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=30fad222-1c00-0000-b47a-9bdb35140000 pid=5173->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 150B guuid=75e65026-1c00-0000-b47a-9bdb3f140000 pid=5183->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 99B guuid=3de5f12b-1c00-0000-b47a-9bdb56140000 pid=5206->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=e611932f-1c00-0000-b47a-9bdb69140000 pid=5225->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=81ff3036-1c00-0000-b47a-9bdb93140000 pid=5267->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=072a373a-1c00-0000-b47a-9bdb94140000 pid=5268->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=15f77d48-1c00-0000-b47a-9bdb9c140000 pid=5276->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=50d0934d-1c00-0000-b47a-9bdb9d140000 pid=5277->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=2b212055-1c00-0000-b47a-9bdbaa140000 pid=5290->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 150B guuid=4f91c758-1c00-0000-b47a-9bdbab140000 pid=5291->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 99B guuid=b7c57b5e-1c00-0000-b47a-9bdbb0140000 pid=5296->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 150B guuid=06394e63-1c00-0000-b47a-9bdbb1140000 pid=5297->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 99B guuid=64f0d373-1c00-0000-b47a-9bdbb6140000 pid=5302->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 151B guuid=b6e94d79-1c00-0000-b47a-9bdbb7140000 pid=5303->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 100B guuid=d0afcd82-1c00-0000-b47a-9bdbbc140000 pid=5308->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 150B guuid=d4e55187-1c00-0000-b47a-9bdbbd140000 pid=5309->a9a6a646-bb5e-5819-9341-c8bf2a21b1b0 send: 99B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-21 04:24:10 UTC
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Unexpected DNS network traffic destination
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
uraniumc2.ddns.net
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f194289631fe35021f88dd3daaee28e4b1e04f03a9697084c472e20330f51db8

(this sample)

  
Delivery method
Distributed via web download

Comments