MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f4cd34574511fba95f796025862741c1ccd2375edd13e1a544ca0fd418098604. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: f4cd34574511fba95f796025862741c1ccd2375edd13e1a544ca0fd418098604
SHA3-384 hash: fee2556906005f061cd608c8d4942fb2ead792ba209467073e76677d9596e8fd6969afa4d321fbca51790cd2794a20e8
SHA1 hash: 27d564bd544628239a10eb0c6ae97ed8ed7e48d4
MD5 hash: 3b1cce8bc659280f11143c4a50a03c8c
humanhash: helium-fanta-yellow-single
File name:1.sh
Download: download sample
Signature Mirai
File size:3'344 bytes
First seen:2025-11-06 08:30:54 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Itf5RZsfKWbhfv3kf2KlffMwmsfo0TfiaiGgJfB56fw8nLfMaMNIpKksf6mMEfE9:iSHUr5Nqn16ZLyJvZsKrBgJsJk
TLSH T12E6183FB134246379CAAEED332B888047145419BA5CE5FB55BEC39F51C8CECA6C41A62
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.87.155/00101010101001/morte.x8670a64a2f61de16f7c53a206ccd45ffd05129d8e176cb69a1972923fbd720a3de Miraielf mirai
http://196.251.87.155/00101010101001/morte.mips4065b4d921d8cb95f14719930de61e4fbfbe57748c9a16979dbfb8b9e782ed6e Miraielf mirai
http://196.251.87.155/00101010101001/morte.arcb9a216ebff916091d3d22af2625b436d3e5e6998522a1685bb476191ef93e461 MiraiDEU elf geofenced mirai ua-wget
http://196.251.87.155/00101010101001/morte.i468n/an/aelf ua-wget
http://196.251.87.155/00101010101001/morte.i6864b24aaad6e9eb56539588110d4c50ae45c28b4647715796f090af6358e58afc7 MiraiDEU elf geofenced mirai
http://196.251.87.155/00101010101001/morte.x86_648c3f3518f247f415ea5c839524c51773ee552aa5ee25fdfea6a3968ebb40d241 MiraiDEU elf geofenced mirai
http://196.251.87.155/00101010101001/morte.mpsl3e5ef3d1a707f0f935ed55136b433b6328b4c6984d1c5c020359f586b3932a73 MiraiDEU elf geofenced mirai
http://196.251.87.155/00101010101001/morte.arm70bd62673da4b4863a79b91bc5ba9a5636257685dbb981e669af123313def828 Miraielf gafgyt mirai
http://196.251.87.155/00101010101001/morte.arm5df160fac5cfdece27ef21645ff664f2816187e034b0db7673f05af254a5f607e MiraiDEU elf geofenced mirai
http://196.251.87.155/00101010101001/morte.arm6e0bf86191882649a3b163925144da7b9cdc8fbf359e20924f96807cae1e4a5de Miraielf mirai
http://196.251.87.155/00101010101001/morte.arm7677dad5e79d975f86cb2cfdfc7b82434289e599b01bb26b4e861aad5f903ad70 Miraielf mirai
http://196.251.87.155/00101010101001/morte.ppc0d54c44eec3b371978542f5e81b0f377f1e2948cf081711fb2b798c1ccbf13dd Miraielf mirai
http://196.251.87.155/00101010101001/morte.spc581a67c0b870f72d922266e6110520db647d0bd0126f52265d4298be9d9177eb Miraielf mirai ua-wget
http://196.251.87.155/00101010101001/morte.m68k5a06b97b18f906092397e3531274f80d05bbba01a15e93ec47a6a504b0f34323 MiraiDEU elf geofenced mirai
http://196.251.87.155/00101010101001/morte.sh466399f695954db7bf91e7e52e7e8f1331b4e0fb091610c5b22a4c1172b942531 MiraiDEU elf geofenced mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-06T05:10:00Z UTC
Last seen:
2025-11-06T10:23:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5a762f92-1600-0000-5ea3-3de71a0d0000 pid=3354 /usr/bin/sudo guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359 /tmp/sample.bin guuid=5a762f92-1600-0000-5ea3-3de71a0d0000 pid=3354->guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359 execve guuid=7b492894-1600-0000-5ea3-3de7220d0000 pid=3362 /usr/bin/cp guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=7b492894-1600-0000-5ea3-3de7220d0000 pid=3362 execve guuid=dd6b5b99-1600-0000-5ea3-3de7320d0000 pid=3378 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=dd6b5b99-1600-0000-5ea3-3de7320d0000 pid=3378 execve guuid=0c857d9e-1600-0000-5ea3-3de7440d0000 pid=3396 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=0c857d9e-1600-0000-5ea3-3de7440d0000 pid=3396 execve guuid=29061fa6-1600-0000-5ea3-3de75e0d0000 pid=3422 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=29061fa6-1600-0000-5ea3-3de75e0d0000 pid=3422 execve guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424 /tmp/morte.x86 net guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424 execve guuid=c6c62fd3-1700-0000-5ea3-3de749100000 pid=4169 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=c6c62fd3-1700-0000-5ea3-3de749100000 pid=4169 execve guuid=720d95d3-1700-0000-5ea3-3de74b100000 pid=4171 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=720d95d3-1700-0000-5ea3-3de74b100000 pid=4171 execve guuid=1ac3c2d6-1700-0000-5ea3-3de758100000 pid=4184 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=1ac3c2d6-1700-0000-5ea3-3de758100000 pid=4184 execve guuid=538dc5db-1700-0000-5ea3-3de76e100000 pid=4206 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=538dc5db-1700-0000-5ea3-3de76e100000 pid=4206 execve guuid=15a910dc-1700-0000-5ea3-3de770100000 pid=4208 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=15a910dc-1700-0000-5ea3-3de770100000 pid=4208 clone guuid=2d226fdd-1700-0000-5ea3-3de776100000 pid=4214 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=2d226fdd-1700-0000-5ea3-3de776100000 pid=4214 execve guuid=197a27e0-1700-0000-5ea3-3de781100000 pid=4225 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=197a27e0-1700-0000-5ea3-3de781100000 pid=4225 execve guuid=4f4af8e4-1700-0000-5ea3-3de796100000 pid=4246 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=4f4af8e4-1700-0000-5ea3-3de796100000 pid=4246 execve guuid=3e5a4eec-1700-0000-5ea3-3de7b8100000 pid=4280 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=3e5a4eec-1700-0000-5ea3-3de7b8100000 pid=4280 execve guuid=ac3b94ec-1700-0000-5ea3-3de7bb100000 pid=4283 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=ac3b94ec-1700-0000-5ea3-3de7bb100000 pid=4283 clone guuid=8a839fed-1700-0000-5ea3-3de7c1100000 pid=4289 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=8a839fed-1700-0000-5ea3-3de7c1100000 pid=4289 execve guuid=940db8ee-1700-0000-5ea3-3de7c8100000 pid=4296 /usr/bin/wget net send-data guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=940db8ee-1700-0000-5ea3-3de7c8100000 pid=4296 execve guuid=f9308cf1-1700-0000-5ea3-3de7d5100000 pid=4309 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=f9308cf1-1700-0000-5ea3-3de7d5100000 pid=4309 execve guuid=2837c3f4-1700-0000-5ea3-3de7e5100000 pid=4325 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=2837c3f4-1700-0000-5ea3-3de7e5100000 pid=4325 execve guuid=61ba1df5-1700-0000-5ea3-3de7e7100000 pid=4327 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=61ba1df5-1700-0000-5ea3-3de7e7100000 pid=4327 clone guuid=ae644af5-1700-0000-5ea3-3de7e9100000 pid=4329 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=ae644af5-1700-0000-5ea3-3de7e9100000 pid=4329 execve guuid=d4e699f5-1700-0000-5ea3-3de7ea100000 pid=4330 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=d4e699f5-1700-0000-5ea3-3de7ea100000 pid=4330 execve guuid=1486bbf8-1700-0000-5ea3-3de7f8100000 pid=4344 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=1486bbf8-1700-0000-5ea3-3de7f8100000 pid=4344 execve guuid=f8df36fe-1700-0000-5ea3-3de70f110000 pid=4367 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=f8df36fe-1700-0000-5ea3-3de70f110000 pid=4367 execve guuid=822276fe-1700-0000-5ea3-3de712110000 pid=4370 /tmp/morte.i686 net guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=822276fe-1700-0000-5ea3-3de712110000 pid=4370 execve guuid=e95a6e76-1800-0000-5ea3-3de7c9110000 pid=4553 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=e95a6e76-1800-0000-5ea3-3de7c9110000 pid=4553 execve guuid=cdcdf876-1800-0000-5ea3-3de7ca110000 pid=4554 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=cdcdf876-1800-0000-5ea3-3de7ca110000 pid=4554 execve guuid=b104b87a-1800-0000-5ea3-3de7d6110000 pid=4566 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=b104b87a-1800-0000-5ea3-3de7d6110000 pid=4566 execve guuid=05bc6d81-1800-0000-5ea3-3de7e9110000 pid=4585 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=05bc6d81-1800-0000-5ea3-3de7e9110000 pid=4585 execve guuid=ba51e681-1800-0000-5ea3-3de7ed110000 pid=4589 /tmp/morte.x86_64 mprotect-exec net guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=ba51e681-1800-0000-5ea3-3de7ed110000 pid=4589 execve guuid=caea76fa-1800-0000-5ea3-3de7f9120000 pid=4857 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=caea76fa-1800-0000-5ea3-3de7f9120000 pid=4857 execve guuid=4dcc05fb-1800-0000-5ea3-3de7fc120000 pid=4860 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=4dcc05fb-1800-0000-5ea3-3de7fc120000 pid=4860 execve guuid=e074a700-1900-0000-5ea3-3de70b130000 pid=4875 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=e074a700-1900-0000-5ea3-3de70b130000 pid=4875 execve guuid=603ef005-1900-0000-5ea3-3de71d130000 pid=4893 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=603ef005-1900-0000-5ea3-3de71d130000 pid=4893 execve guuid=70485306-1900-0000-5ea3-3de71f130000 pid=4895 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=70485306-1900-0000-5ea3-3de71f130000 pid=4895 clone guuid=8a300107-1900-0000-5ea3-3de723130000 pid=4899 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=8a300107-1900-0000-5ea3-3de723130000 pid=4899 execve guuid=ae335c0c-1900-0000-5ea3-3de733130000 pid=4915 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=ae335c0c-1900-0000-5ea3-3de733130000 pid=4915 execve guuid=6eaf2111-1900-0000-5ea3-3de743130000 pid=4931 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=6eaf2111-1900-0000-5ea3-3de743130000 pid=4931 execve guuid=dddeb516-1900-0000-5ea3-3de75a130000 pid=4954 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=dddeb516-1900-0000-5ea3-3de75a130000 pid=4954 execve guuid=b882f616-1900-0000-5ea3-3de75c130000 pid=4956 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=b882f616-1900-0000-5ea3-3de75c130000 pid=4956 clone guuid=9f978217-1900-0000-5ea3-3de760130000 pid=4960 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=9f978217-1900-0000-5ea3-3de760130000 pid=4960 execve guuid=4208211a-1900-0000-5ea3-3de76a130000 pid=4970 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=4208211a-1900-0000-5ea3-3de76a130000 pid=4970 execve guuid=dcd11f1d-1900-0000-5ea3-3de778130000 pid=4984 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=dcd11f1d-1900-0000-5ea3-3de778130000 pid=4984 execve guuid=36fec823-1900-0000-5ea3-3de794130000 pid=5012 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=36fec823-1900-0000-5ea3-3de794130000 pid=5012 execve guuid=1b690724-1900-0000-5ea3-3de796130000 pid=5014 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=1b690724-1900-0000-5ea3-3de796130000 pid=5014 clone guuid=971e8824-1900-0000-5ea3-3de79a130000 pid=5018 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=971e8824-1900-0000-5ea3-3de79a130000 pid=5018 execve guuid=f31ee324-1900-0000-5ea3-3de79c130000 pid=5020 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=f31ee324-1900-0000-5ea3-3de79c130000 pid=5020 execve guuid=f97a1f28-1900-0000-5ea3-3de7aa130000 pid=5034 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=f97a1f28-1900-0000-5ea3-3de7aa130000 pid=5034 execve guuid=ee12122c-1900-0000-5ea3-3de7b9130000 pid=5049 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=ee12122c-1900-0000-5ea3-3de7b9130000 pid=5049 execve guuid=d24e512c-1900-0000-5ea3-3de7ba130000 pid=5050 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=d24e512c-1900-0000-5ea3-3de7ba130000 pid=5050 clone guuid=915d152d-1900-0000-5ea3-3de7bf130000 pid=5055 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=915d152d-1900-0000-5ea3-3de7bf130000 pid=5055 execve guuid=3996542d-1900-0000-5ea3-3de7c1130000 pid=5057 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=3996542d-1900-0000-5ea3-3de7c1130000 pid=5057 execve guuid=2f58bc30-1900-0000-5ea3-3de7d1130000 pid=5073 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=2f58bc30-1900-0000-5ea3-3de7d1130000 pid=5073 execve guuid=8c962d36-1900-0000-5ea3-3de7ed130000 pid=5101 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=8c962d36-1900-0000-5ea3-3de7ed130000 pid=5101 execve guuid=f6007536-1900-0000-5ea3-3de7f1130000 pid=5105 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=f6007536-1900-0000-5ea3-3de7f1130000 pid=5105 clone guuid=07943337-1900-0000-5ea3-3de7f4130000 pid=5108 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=07943337-1900-0000-5ea3-3de7f4130000 pid=5108 execve guuid=cbff5d38-1900-0000-5ea3-3de7f9130000 pid=5113 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=cbff5d38-1900-0000-5ea3-3de7f9130000 pid=5113 execve guuid=10b4ab3b-1900-0000-5ea3-3de708140000 pid=5128 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=10b4ab3b-1900-0000-5ea3-3de708140000 pid=5128 execve guuid=fffcc03f-1900-0000-5ea3-3de719140000 pid=5145 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=fffcc03f-1900-0000-5ea3-3de719140000 pid=5145 execve guuid=28a20a40-1900-0000-5ea3-3de71b140000 pid=5147 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=28a20a40-1900-0000-5ea3-3de71b140000 pid=5147 clone guuid=eb67c440-1900-0000-5ea3-3de71f140000 pid=5151 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=eb67c440-1900-0000-5ea3-3de71f140000 pid=5151 execve guuid=01420e41-1900-0000-5ea3-3de721140000 pid=5153 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=01420e41-1900-0000-5ea3-3de721140000 pid=5153 execve guuid=85118744-1900-0000-5ea3-3de72a140000 pid=5162 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=85118744-1900-0000-5ea3-3de72a140000 pid=5162 execve guuid=23d83b4a-1900-0000-5ea3-3de73d140000 pid=5181 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=23d83b4a-1900-0000-5ea3-3de73d140000 pid=5181 execve guuid=7c627b4a-1900-0000-5ea3-3de73f140000 pid=5183 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=7c627b4a-1900-0000-5ea3-3de73f140000 pid=5183 clone guuid=02250a4b-1900-0000-5ea3-3de743140000 pid=5187 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=02250a4b-1900-0000-5ea3-3de743140000 pid=5187 execve guuid=a0904e4b-1900-0000-5ea3-3de745140000 pid=5189 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=a0904e4b-1900-0000-5ea3-3de745140000 pid=5189 execve guuid=2b1fac4e-1900-0000-5ea3-3de752140000 pid=5202 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=2b1fac4e-1900-0000-5ea3-3de752140000 pid=5202 execve guuid=a6a4ea55-1900-0000-5ea3-3de76a140000 pid=5226 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=a6a4ea55-1900-0000-5ea3-3de76a140000 pid=5226 execve guuid=529a2756-1900-0000-5ea3-3de76c140000 pid=5228 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=529a2756-1900-0000-5ea3-3de76c140000 pid=5228 clone guuid=a1bead56-1900-0000-5ea3-3de770140000 pid=5232 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=a1bead56-1900-0000-5ea3-3de770140000 pid=5232 execve guuid=73451357-1900-0000-5ea3-3de772140000 pid=5234 /usr/bin/wget net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=73451357-1900-0000-5ea3-3de772140000 pid=5234 execve guuid=879d0c5b-1900-0000-5ea3-3de78b140000 pid=5259 /usr/bin/curl net send-data write-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=879d0c5b-1900-0000-5ea3-3de78b140000 pid=5259 execve guuid=23e18560-1900-0000-5ea3-3de7aa140000 pid=5290 /usr/bin/chmod guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=23e18560-1900-0000-5ea3-3de7aa140000 pid=5290 execve guuid=249dcb60-1900-0000-5ea3-3de7ab140000 pid=5291 /usr/bin/bash guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=249dcb60-1900-0000-5ea3-3de7ab140000 pid=5291 clone guuid=1f0e5c61-1900-0000-5ea3-3de7ad140000 pid=5293 /usr/bin/rm delete-file guuid=a9aad593-1600-0000-5ea3-3de71f0d0000 pid=3359->guuid=1f0e5c61-1900-0000-5ea3-3de7ad140000 pid=5293 execve 696479e8-a1be-5993-b3e1-5d7c959a8b0a 196.251.87.155:80 guuid=dd6b5b99-1600-0000-5ea3-3de7320d0000 pid=3378->696479e8-a1be-5993-b3e1-5d7c959a8b0a send: 153B guuid=0c857d9e-1600-0000-5ea3-3de7440d0000 pid=3396->696479e8-a1be-5993-b3e1-5d7c959a8b0a send: 102B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c6602ea7-1600-0000-5ea3-3de7630d0000 pid=3427 /tmp/morte.x86 guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424->guuid=c6602ea7-1600-0000-5ea3-3de7630d0000 pid=3427 clone guuid=bc6823d3-1700-0000-5ea3-3de746100000 pid=4166 /tmp/morte.x86 guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424->guuid=bc6823d3-1700-0000-5ea3-3de746100000 pid=4166 clone guuid=661b28d3-1700-0000-5ea3-3de748100000 pid=4168 /tmp/morte.x86 net send-data zombie guuid=76ed7aa6-1600-0000-5ea3-3de7600d0000 pid=3424->guuid=661b28d3-1700-0000-5ea3-3de748100000 pid=4168 clone guuid=ce2a33a7-1600-0000-5ea3-3de7640d0000 pid=3428 /tmp/morte.x86 guuid=c6602ea7-1600-0000-5ea3-3de7630d0000 pid=3427->guuid=ce2a33a7-1600-0000-5ea3-3de7640d0000 pid=3428 clone guuid=d29337a7-1600-0000-5ea3-3de7650d0000 pid=3429 /tmp/morte.x86 dns net send-data zombie guuid=c6602ea7-1600-0000-5ea3-3de7630d0000 pid=3427->guuid=d29337a7-1600-0000-5ea3-3de7650d0000 pid=3429 clone guuid=d29337a7-1600-0000-5ea3-3de7650d0000 pid=3429->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B 55e75a70-5f0f-5401-b0ef-995451b8fb69 teamc2.duckdns.org:12121 guuid=d29337a7-1600-0000-5ea3-3de7650d0000 pid=3429->55e75a70-5f0f-5401-b0ef-995451b8fb69 send: 15B guuid=661b28d3-1700-0000-5ea3-3de748100000 pid=4168->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 180B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=661b28d3-1700-0000-5ea3-3de748100000 pid=4168->310a0ed0-c544-54ca-bf3f-fca55e459297 con 34838265-02e6-553b-9f0b-6281956faf10 teamc2.duckdns.org:80 guuid=720d95d3-1700-0000-5ea3-3de74b100000 pid=4171->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=1ac3c2d6-1700-0000-5ea3-3de758100000 pid=4184->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=197a27e0-1700-0000-5ea3-3de781100000 pid=4225->34838265-02e6-553b-9f0b-6281956faf10 send: 153B guuid=4f4af8e4-1700-0000-5ea3-3de796100000 pid=4246->34838265-02e6-553b-9f0b-6281956faf10 send: 102B guuid=940db8ee-1700-0000-5ea3-3de7c8100000 pid=4296->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=f9308cf1-1700-0000-5ea3-3de7d5100000 pid=4309->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=d4e699f5-1700-0000-5ea3-3de7ea100000 pid=4330->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=1486bbf8-1700-0000-5ea3-3de7f8100000 pid=4344->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=822276fe-1700-0000-5ea3-3de712110000 pid=4370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=822276fe-1700-0000-5ea3-3de712110000 pid=4370->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=cdcdf876-1800-0000-5ea3-3de7ca110000 pid=4554->34838265-02e6-553b-9f0b-6281956faf10 send: 156B guuid=b104b87a-1800-0000-5ea3-3de7d6110000 pid=4566->34838265-02e6-553b-9f0b-6281956faf10 send: 105B guuid=ba51e681-1800-0000-5ea3-3de7ed110000 pid=4589->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba51e681-1800-0000-5ea3-3de7ed110000 pid=4589->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=4dcc05fb-1800-0000-5ea3-3de7fc120000 pid=4860->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=e074a700-1900-0000-5ea3-3de70b130000 pid=4875->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=ae335c0c-1900-0000-5ea3-3de733130000 pid=4915->34838265-02e6-553b-9f0b-6281956faf10 send: 153B guuid=6eaf2111-1900-0000-5ea3-3de743130000 pid=4931->34838265-02e6-553b-9f0b-6281956faf10 send: 102B guuid=4208211a-1900-0000-5ea3-3de76a130000 pid=4970->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=dcd11f1d-1900-0000-5ea3-3de778130000 pid=4984->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=f31ee324-1900-0000-5ea3-3de79c130000 pid=5020->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=f97a1f28-1900-0000-5ea3-3de7aa130000 pid=5034->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=3996542d-1900-0000-5ea3-3de7c1130000 pid=5057->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=2f58bc30-1900-0000-5ea3-3de7d1130000 pid=5073->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=cbff5d38-1900-0000-5ea3-3de7f9130000 pid=5113->34838265-02e6-553b-9f0b-6281956faf10 send: 153B guuid=10b4ab3b-1900-0000-5ea3-3de708140000 pid=5128->34838265-02e6-553b-9f0b-6281956faf10 send: 102B guuid=01420e41-1900-0000-5ea3-3de721140000 pid=5153->34838265-02e6-553b-9f0b-6281956faf10 send: 153B guuid=85118744-1900-0000-5ea3-3de72a140000 pid=5162->34838265-02e6-553b-9f0b-6281956faf10 send: 102B guuid=a0904e4b-1900-0000-5ea3-3de745140000 pid=5189->34838265-02e6-553b-9f0b-6281956faf10 send: 154B guuid=2b1fac4e-1900-0000-5ea3-3de752140000 pid=5202->34838265-02e6-553b-9f0b-6281956faf10 send: 103B guuid=73451357-1900-0000-5ea3-3de772140000 pid=5234->34838265-02e6-553b-9f0b-6281956faf10 send: 153B guuid=879d0c5b-1900-0000-5ea3-3de78b140000 pid=5259->34838265-02e6-553b-9f0b-6281956faf10 send: 102B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-11-06 08:31:20 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
teamc2.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments