MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f682cc9cc16ec1df8121c61faa266405ae67b377224ecbb295eee7d1b4fb2f2b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f682cc9cc16ec1df8121c61faa266405ae67b377224ecbb295eee7d1b4fb2f2b
SHA3-384 hash: 114cb9d88355ba4822c0a83a805a06d87117c674b6280d4c13534dafd9be9bc1d2d7dc639db93412191dc6a3551e500c
SHA1 hash: 86f37b247e4d1d454a0c418f45827d5215cde2b7
MD5 hash: b1137f24526842a8f378522eabab959c
humanhash: muppet-mountain-blue-apart
File name:1.sh
Download: download sample
Signature Mirai
File size:3'314 bytes
First seen:2025-10-03 05:35:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:ItwtEtbZswt3tsbhwt2t9kwtLtglfwtdtamswt1tyTwtQptQGgJwtMtj6wtNtqnn:iohuxXzvs18HLCJBpCNKBgJspk
TLSH T14B616EF703424F779CEB89D732A888446144A4AB68CE9F75DBDD24A81ECCECA7C45641
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://151.242.30.16/00101010101001/morte.x8692d69c7546249a3195233a2b73f4bb30ea88bd2827d4c110398b1e941e56dbb8 Miraielf geofenced mirai opendir ua-wget USA x86
http://151.242.30.16/00101010101001/morte.mips93f5237da0a31e68e9329282d64a46434b4248cb6b3012a1585c0f72a8bcfcd5 Miraielf geofenced mips mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.arc8ea12d1456993834e828c565cc19065d411401378a6c98b98c73d18680686017 Miraiarc elf geofenced mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.i468n/an/aelf ua-wget
http://151.242.30.16/00101010101001/morte.i686fc990589d1f85aaed8a231b1e7b48a121aa1c6a1eb19eb4843a6c13d376d992c Miraielf geofenced mirai opendir ua-wget USA x86
http://151.242.30.16/00101010101001/morte.x86_64c3e1d20599df336815a735e7b0dfb30c365393aa981875d8a607dc20b5a06be2 Miraielf geofenced mirai opendir ua-wget USA x86
http://151.242.30.16/00101010101001/morte.mpsln/an/aelf geofenced mips mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.arm1ea88b28b54a4454882dbe3565215e39dbea43229a630885e0432ee243f46324 Miraiarm elf geofenced mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.arm545d8bd8c375305921de509f4724914162b1dfb209617d24a6d87b8eecd6ffa0b Miraiarm elf geofenced mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.arm6d1da191ce2dabc7519c8eef07fb246354d23117c67430437506fe2062cee9e84 Miraiarm elf geofenced mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.arm70f3829f85ac77d1b9e15cbac4fc01afd3e5c5b114c247245029b1ad29c478f3a Miraiarm elf geofenced mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.ppcc758b10c61c61d14d4fc1fdeca89e71109db4352307b66a445941e6c2ea91008 Miraielf geofenced mirai opendir PowerPC ua-wget USA
http://151.242.30.16/00101010101001/morte.spc99b49622032cec0dc901aaaa7fe74bbe467cc4224b3cf3d1e6c2e667df27b7c2 Miraielf geofenced mirai opendir sparc ua-wget USA
http://151.242.30.16/00101010101001/morte.m68kbee9c25fe35b4a590540518d411e378026856c6e3af5c03cdc37e7b1d919b017 Miraielf geofenced m68k mirai opendir ua-wget USA
http://151.242.30.16/00101010101001/morte.sh47a3a20e1b1341eb8cb77856de47cc177e6ae61345a19359fa6173ab1f30444ba Miraielf geofenced mirai opendir SuperH ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-02T18:18:00Z UTC
Last seen:
2025-10-03T10:29:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=99e3c0ab-1a00-0000-0070-2bee140d0000 pid=3348 /usr/bin/sudo guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354 /tmp/sample.bin guuid=99e3c0ab-1a00-0000-0070-2bee140d0000 pid=3348->guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354 execve guuid=f305dcad-1a00-0000-0070-2bee1d0d0000 pid=3357 /usr/bin/cp guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=f305dcad-1a00-0000-0070-2bee1d0d0000 pid=3357 execve guuid=0479dfb2-1a00-0000-0070-2bee270d0000 pid=3367 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0479dfb2-1a00-0000-0070-2bee270d0000 pid=3367 execve guuid=b18dd2ba-1a00-0000-0070-2bee3c0d0000 pid=3388 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=b18dd2ba-1a00-0000-0070-2bee3c0d0000 pid=3388 execve guuid=3b09d2c9-1a00-0000-0070-2bee6e0d0000 pid=3438 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=3b09d2c9-1a00-0000-0070-2bee6e0d0000 pid=3438 execve guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440 /tmp/morte.x86 net guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440 execve guuid=5b5eb1f6-1b00-0000-0070-2beee5100000 pid=4325 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=5b5eb1f6-1b00-0000-0070-2beee5100000 pid=4325 execve guuid=1ede0ff7-1b00-0000-0070-2beee6100000 pid=4326 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=1ede0ff7-1b00-0000-0070-2beee6100000 pid=4326 execve guuid=7eb66800-1c00-0000-0070-2bee0b110000 pid=4363 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=7eb66800-1c00-0000-0070-2bee0b110000 pid=4363 execve guuid=dd70860a-1c00-0000-0070-2bee38110000 pid=4408 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=dd70860a-1c00-0000-0070-2bee38110000 pid=4408 execve guuid=a3e1010b-1c00-0000-0070-2bee3c110000 pid=4412 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=a3e1010b-1c00-0000-0070-2bee3c110000 pid=4412 clone guuid=ef36ec0b-1c00-0000-0070-2bee43110000 pid=4419 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=ef36ec0b-1c00-0000-0070-2bee43110000 pid=4419 execve guuid=5a8e5f0d-1c00-0000-0070-2bee4a110000 pid=4426 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=5a8e5f0d-1c00-0000-0070-2bee4a110000 pid=4426 execve guuid=3c062919-1c00-0000-0070-2bee83110000 pid=4483 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=3c062919-1c00-0000-0070-2bee83110000 pid=4483 execve guuid=3476e325-1c00-0000-0070-2beead110000 pid=4525 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=3476e325-1c00-0000-0070-2beead110000 pid=4525 execve guuid=49df7026-1c00-0000-0070-2beeb0110000 pid=4528 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=49df7026-1c00-0000-0070-2beeb0110000 pid=4528 clone guuid=887f5127-1c00-0000-0070-2beeb5110000 pid=4533 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=887f5127-1c00-0000-0070-2beeb5110000 pid=4533 execve guuid=da02c229-1c00-0000-0070-2beec1110000 pid=4545 /usr/bin/wget net send-data guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=da02c229-1c00-0000-0070-2beec1110000 pid=4545 execve guuid=4f8dec2e-1c00-0000-0070-2beeda110000 pid=4570 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=4f8dec2e-1c00-0000-0070-2beeda110000 pid=4570 execve guuid=2ba82d35-1c00-0000-0070-2beefb110000 pid=4603 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=2ba82d35-1c00-0000-0070-2beefb110000 pid=4603 execve guuid=db567135-1c00-0000-0070-2beeff110000 pid=4607 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=db567135-1c00-0000-0070-2beeff110000 pid=4607 clone guuid=cbc79035-1c00-0000-0070-2bee00120000 pid=4608 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=cbc79035-1c00-0000-0070-2bee00120000 pid=4608 execve guuid=3c1ed735-1c00-0000-0070-2bee02120000 pid=4610 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=3c1ed735-1c00-0000-0070-2bee02120000 pid=4610 execve guuid=d207be3c-1c00-0000-0070-2bee1f120000 pid=4639 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=d207be3c-1c00-0000-0070-2bee1f120000 pid=4639 execve guuid=3bd6b144-1c00-0000-0070-2bee41120000 pid=4673 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=3bd6b144-1c00-0000-0070-2bee41120000 pid=4673 execve guuid=4562fd44-1c00-0000-0070-2bee45120000 pid=4677 /tmp/morte.i686 net guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=4562fd44-1c00-0000-0070-2bee45120000 pid=4677 execve guuid=ed81debc-1c00-0000-0070-2beea5130000 pid=5029 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=ed81debc-1c00-0000-0070-2beea5130000 pid=5029 execve guuid=57c462bd-1c00-0000-0070-2beea7130000 pid=5031 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=57c462bd-1c00-0000-0070-2beea7130000 pid=5031 execve guuid=0383cdc6-1c00-0000-0070-2beebe130000 pid=5054 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0383cdc6-1c00-0000-0070-2beebe130000 pid=5054 execve guuid=851484d2-1c00-0000-0070-2beedd130000 pid=5085 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=851484d2-1c00-0000-0070-2beedd130000 pid=5085 execve guuid=b2390dd3-1c00-0000-0070-2beedf130000 pid=5087 /tmp/morte.x86_64 mprotect-exec net guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=b2390dd3-1c00-0000-0070-2beedf130000 pid=5087 execve guuid=e95e464b-1d00-0000-0070-2bee83140000 pid=5251 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=e95e464b-1d00-0000-0070-2bee83140000 pid=5251 execve guuid=4f65e14b-1d00-0000-0070-2bee84140000 pid=5252 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=4f65e14b-1d00-0000-0070-2bee84140000 pid=5252 execve guuid=e738085d-1d00-0000-0070-2bee85140000 pid=5253 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=e738085d-1d00-0000-0070-2bee85140000 pid=5253 execve guuid=36967e68-1d00-0000-0070-2bee88140000 pid=5256 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=36967e68-1d00-0000-0070-2bee88140000 pid=5256 execve guuid=d4929169-1d00-0000-0070-2bee8f140000 pid=5263 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=d4929169-1d00-0000-0070-2bee8f140000 pid=5263 clone guuid=dc57736a-1d00-0000-0070-2bee91140000 pid=5265 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=dc57736a-1d00-0000-0070-2bee91140000 pid=5265 execve guuid=04f95a6b-1d00-0000-0070-2bee92140000 pid=5266 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=04f95a6b-1d00-0000-0070-2bee92140000 pid=5266 execve guuid=65594375-1d00-0000-0070-2bee93140000 pid=5267 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=65594375-1d00-0000-0070-2bee93140000 pid=5267 execve guuid=1398e07e-1d00-0000-0070-2bee94140000 pid=5268 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=1398e07e-1d00-0000-0070-2bee94140000 pid=5268 execve guuid=27e83d7f-1d00-0000-0070-2bee95140000 pid=5269 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=27e83d7f-1d00-0000-0070-2bee95140000 pid=5269 clone guuid=d3a8f17f-1d00-0000-0070-2bee97140000 pid=5271 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=d3a8f17f-1d00-0000-0070-2bee97140000 pid=5271 execve guuid=0107fa84-1d00-0000-0070-2bee98140000 pid=5272 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0107fa84-1d00-0000-0070-2bee98140000 pid=5272 execve guuid=73cf578d-1d00-0000-0070-2bee99140000 pid=5273 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=73cf578d-1d00-0000-0070-2bee99140000 pid=5273 execve guuid=c67df097-1d00-0000-0070-2bee9a140000 pid=5274 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=c67df097-1d00-0000-0070-2bee9a140000 pid=5274 execve guuid=c96bc298-1d00-0000-0070-2bee9b140000 pid=5275 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=c96bc298-1d00-0000-0070-2bee9b140000 pid=5275 clone guuid=8cbcd899-1d00-0000-0070-2bee9d140000 pid=5277 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=8cbcd899-1d00-0000-0070-2bee9d140000 pid=5277 execve guuid=9228669a-1d00-0000-0070-2bee9e140000 pid=5278 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=9228669a-1d00-0000-0070-2bee9e140000 pid=5278 execve guuid=a564bda4-1d00-0000-0070-2bee9f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=a564bda4-1d00-0000-0070-2bee9f140000 pid=5279 execve guuid=6bd36bb2-1d00-0000-0070-2beea0140000 pid=5280 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=6bd36bb2-1d00-0000-0070-2beea0140000 pid=5280 execve guuid=992fdfb2-1d00-0000-0070-2beea1140000 pid=5281 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=992fdfb2-1d00-0000-0070-2beea1140000 pid=5281 clone guuid=0205e8b3-1d00-0000-0070-2beea3140000 pid=5283 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0205e8b3-1d00-0000-0070-2beea3140000 pid=5283 execve guuid=02c682b4-1d00-0000-0070-2beea4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=02c682b4-1d00-0000-0070-2beea4140000 pid=5284 execve guuid=a74e18be-1d00-0000-0070-2beea5140000 pid=5285 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=a74e18be-1d00-0000-0070-2beea5140000 pid=5285 execve guuid=c1f016ca-1d00-0000-0070-2beea6140000 pid=5286 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=c1f016ca-1d00-0000-0070-2beea6140000 pid=5286 execve guuid=537b71ca-1d00-0000-0070-2beea7140000 pid=5287 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=537b71ca-1d00-0000-0070-2beea7140000 pid=5287 clone guuid=6aad73cb-1d00-0000-0070-2beea9140000 pid=5289 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=6aad73cb-1d00-0000-0070-2beea9140000 pid=5289 execve guuid=687af5cb-1d00-0000-0070-2beeaa140000 pid=5290 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=687af5cb-1d00-0000-0070-2beeaa140000 pid=5290 execve guuid=33901bd5-1d00-0000-0070-2beeab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=33901bd5-1d00-0000-0070-2beeab140000 pid=5291 execve guuid=549757df-1d00-0000-0070-2beeac140000 pid=5292 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=549757df-1d00-0000-0070-2beeac140000 pid=5292 execve guuid=aaa725e0-1d00-0000-0070-2beead140000 pid=5293 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=aaa725e0-1d00-0000-0070-2beead140000 pid=5293 clone guuid=86fc46e3-1d00-0000-0070-2beeaf140000 pid=5295 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=86fc46e3-1d00-0000-0070-2beeaf140000 pid=5295 execve guuid=71a1e2e3-1d00-0000-0070-2beeb0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=71a1e2e3-1d00-0000-0070-2beeb0140000 pid=5296 execve guuid=206d80f0-1d00-0000-0070-2beeb1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=206d80f0-1d00-0000-0070-2beeb1140000 pid=5297 execve guuid=d2f55dfe-1d00-0000-0070-2beeb2140000 pid=5298 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=d2f55dfe-1d00-0000-0070-2beeb2140000 pid=5298 execve guuid=72d421ff-1d00-0000-0070-2beeb3140000 pid=5299 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=72d421ff-1d00-0000-0070-2beeb3140000 pid=5299 clone guuid=dac4e400-1e00-0000-0070-2beeb5140000 pid=5301 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=dac4e400-1e00-0000-0070-2beeb5140000 pid=5301 execve guuid=2d768801-1e00-0000-0070-2beeb6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=2d768801-1e00-0000-0070-2beeb6140000 pid=5302 execve guuid=f9f61c0e-1e00-0000-0070-2beeb7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=f9f61c0e-1e00-0000-0070-2beeb7140000 pid=5303 execve guuid=7ecc101b-1e00-0000-0070-2beeb8140000 pid=5304 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=7ecc101b-1e00-0000-0070-2beeb8140000 pid=5304 execve guuid=8111661b-1e00-0000-0070-2beeb9140000 pid=5305 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=8111661b-1e00-0000-0070-2beeb9140000 pid=5305 clone guuid=0551161c-1e00-0000-0070-2beebb140000 pid=5307 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0551161c-1e00-0000-0070-2beebb140000 pid=5307 execve guuid=5569c31d-1e00-0000-0070-2beebc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=5569c31d-1e00-0000-0070-2beebc140000 pid=5308 execve guuid=546ad428-1e00-0000-0070-2beebd140000 pid=5309 /usr/bin/curl net send-data write-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=546ad428-1e00-0000-0070-2beebd140000 pid=5309 execve guuid=0f6e0d33-1e00-0000-0070-2beebe140000 pid=5310 /usr/bin/chmod guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=0f6e0d33-1e00-0000-0070-2beebe140000 pid=5310 execve guuid=b8466b33-1e00-0000-0070-2beebf140000 pid=5311 /usr/bin/bash guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=b8466b33-1e00-0000-0070-2beebf140000 pid=5311 clone guuid=74276334-1e00-0000-0070-2beec1140000 pid=5313 /usr/bin/rm delete-file guuid=770157ad-1a00-0000-0070-2bee1a0d0000 pid=3354->guuid=74276334-1e00-0000-0070-2beec1140000 pid=5313 execve e3b8f47c-c845-5324-9849-6a90101af0c9 151.242.30.16:80 guuid=0479dfb2-1a00-0000-0070-2bee270d0000 pid=3367->e3b8f47c-c845-5324-9849-6a90101af0c9 send: 152B guuid=b18dd2ba-1a00-0000-0070-2bee3c0d0000 pid=3388->e3b8f47c-c845-5324-9849-6a90101af0c9 send: 101B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ec7595ca-1a00-0000-0070-2bee720d0000 pid=3442 /tmp/morte.x86 guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440->guuid=ec7595ca-1a00-0000-0070-2bee720d0000 pid=3442 clone guuid=e31c98f6-1b00-0000-0070-2beee3100000 pid=4323 /tmp/morte.x86 guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440->guuid=e31c98f6-1b00-0000-0070-2beee3100000 pid=4323 clone guuid=56cf9df6-1b00-0000-0070-2beee4100000 pid=4324 /tmp/morte.x86 net send-data zombie guuid=39471aca-1a00-0000-0070-2bee700d0000 pid=3440->guuid=56cf9df6-1b00-0000-0070-2beee4100000 pid=4324 clone guuid=f85f9cca-1a00-0000-0070-2bee730d0000 pid=3443 /tmp/morte.x86 guuid=ec7595ca-1a00-0000-0070-2bee720d0000 pid=3442->guuid=f85f9cca-1a00-0000-0070-2bee730d0000 pid=3443 clone guuid=dda59fca-1a00-0000-0070-2bee740d0000 pid=3444 /tmp/morte.x86 dns net send-data zombie guuid=ec7595ca-1a00-0000-0070-2bee720d0000 pid=3442->guuid=dda59fca-1a00-0000-0070-2bee740d0000 pid=3444 clone guuid=dda59fca-1a00-0000-0070-2bee740d0000 pid=3444->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 86B e3bbf482-b030-53db-81fc-cf3025bcc1da mangotruff.redirectme.net:12121 guuid=dda59fca-1a00-0000-0070-2bee740d0000 pid=3444->e3bbf482-b030-53db-81fc-cf3025bcc1da con guuid=56cf9df6-1b00-0000-0070-2beee4100000 pid=4324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 215B c45e9fdd-bbda-5cdd-961f-90d3713660d8 mangotruff.redirectme.net:80 guuid=56cf9df6-1b00-0000-0070-2beee4100000 pid=4324->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 15B guuid=1ede0ff7-1b00-0000-0070-2beee6100000 pid=4326->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=7eb66800-1c00-0000-0070-2bee0b110000 pid=4363->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=5a8e5f0d-1c00-0000-0070-2bee4a110000 pid=4426->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 152B guuid=3c062919-1c00-0000-0070-2bee83110000 pid=4483->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 101B guuid=da02c229-1c00-0000-0070-2beec1110000 pid=4545->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=4f8dec2e-1c00-0000-0070-2beeda110000 pid=4570->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=3c1ed735-1c00-0000-0070-2bee02120000 pid=4610->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=d207be3c-1c00-0000-0070-2bee1f120000 pid=4639->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=4562fd44-1c00-0000-0070-2bee45120000 pid=4677->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f77ebf5e-2af7-5b09-86f4-388588a8b445 0.0.0.0:12121 guuid=4562fd44-1c00-0000-0070-2bee45120000 pid=4677->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=57c462bd-1c00-0000-0070-2beea7130000 pid=5031->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 155B guuid=0383cdc6-1c00-0000-0070-2beebe130000 pid=5054->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 104B guuid=b2390dd3-1c00-0000-0070-2beedf130000 pid=5087->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b2390dd3-1c00-0000-0070-2beedf130000 pid=5087->f77ebf5e-2af7-5b09-86f4-388588a8b445 con guuid=4f65e14b-1d00-0000-0070-2bee84140000 pid=5252->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=e738085d-1d00-0000-0070-2bee85140000 pid=5253->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=04f95a6b-1d00-0000-0070-2bee92140000 pid=5266->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 152B guuid=65594375-1d00-0000-0070-2bee93140000 pid=5267->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 101B guuid=0107fa84-1d00-0000-0070-2bee98140000 pid=5272->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=73cf578d-1d00-0000-0070-2bee99140000 pid=5273->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=9228669a-1d00-0000-0070-2bee9e140000 pid=5278->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=a564bda4-1d00-0000-0070-2bee9f140000 pid=5279->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=02c682b4-1d00-0000-0070-2beea4140000 pid=5284->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=a74e18be-1d00-0000-0070-2beea5140000 pid=5285->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=687af5cb-1d00-0000-0070-2beeaa140000 pid=5290->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 152B guuid=33901bd5-1d00-0000-0070-2beeab140000 pid=5291->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 101B guuid=71a1e2e3-1d00-0000-0070-2beeb0140000 pid=5296->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 152B guuid=206d80f0-1d00-0000-0070-2beeb1140000 pid=5297->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 101B guuid=2d768801-1e00-0000-0070-2beeb6140000 pid=5302->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 153B guuid=f9f61c0e-1e00-0000-0070-2beeb7140000 pid=5303->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 102B guuid=5569c31d-1e00-0000-0070-2beebc140000 pid=5308->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 152B guuid=546ad428-1e00-0000-0070-2beebd140000 pid=5309->c45e9fdd-bbda-5cdd-961f-90d3713660d8 send: 101B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-03 00:28:05 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f682cc9cc16ec1df8121c61faa266405ae67b377224ecbb295eee7d1b4fb2f2b

(this sample)

  
Delivery method
Distributed via web download

Comments