MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a47760cc5ae692eb0cea3699d2756879322cd4bd2b172fb92ae57b7e83a3850. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 0a47760cc5ae692eb0cea3699d2756879322cd4bd2b172fb92ae57b7e83a3850
SHA3-384 hash: 154ca8ce896c634f6f4825cee75cd2b6c4d62228163b9e008a211599b158e0835e3e9c2f111957c2deff6593b39c49e8
SHA1 hash: 67a99eaa27a11122477b1618122fcd9655149da9
MD5 hash: 127108bd88335d24cd4308aa3620e7eb
humanhash: bulldog-three-texas-iowa
File name:EkSgbins.sh
Download: download sample
Signature Gafgyt
File size:1'516 bytes
First seen:2026-02-16 04:27:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:q0FmV0Fk0Flac43fX0FUOeekX0F2+k0FzoX0FcJ91FZ0FjEX0Fuh0F9gV8po0FRi:vm+tcc4kUOas1zoscJ9+jEsd/Jde
TLSH T1453153CB22A20A74ACB1E967326A980475D9F5D725CE6F9DBCDC3AF5418DE047001BE3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:gafgyt
URLMalware sample (SHA256 hash)SignatureTags
http://45.131.64.121/mips07a156c9004e3272f3e2c8120fc2718b5ea2d593c702124dcf1d6fb3d0648d65 Miraimirai
http://45.131.64.121/mipsel36c254c98d17a855694486f20bf4051d460ad1f4074e9640f794faf972e0eb91 Miraimirai
http://45.131.64.121/sh412b4d70d65c78aa9de125ad3be2e4f1bf6d7c334ecc852149850d6deffe258c4 Miraimirai
http://45.131.64.121/x86211ed980a5a75ce9313e8d8d516ee4971879b50a6784a062bb13811af238f947 Miraimirai
http://45.131.64.121/armv6l730c6e697e944c9672cb65dda33c805e5c328ebfe28da9e192b6ebba30446ed8 Miraimirai
http://45.131.64.121/i6861131e55f0bdbda12686176c4eda52a5dc6d1922aa583aa2425753f244c7b6c20 Miraimirai
http://45.131.64.121/powerpc0ed824177d7348c404f5986417c7e97ef8a141c487b4fbf60778d0934eb43e33 Miraimirai
http://45.131.64.121/i586c94101b076da0aa2d8336b24656c55bc4635c80a128ba2c256d006a3625e5b0c Miraimirai
http://45.131.64.121/m68k0ab90e49a9e1b2bae6235ba43eefc44adaf0a5a9c1df510793ea085ea65c2baf Miraimirai
http://45.131.64.121/sparc8eae216a61bf4193c65632d7ca79bd1fbda62bc80e57861d255b45ebc8811489 Miraimirai
http://45.131.64.121/armv4l94101c7ed73e72ae300a81c9dafc41ccabb613c9871ee05e5594ee09f8d82216 Miraigafgyt
http://45.131.64.121/armv5la1deea1b1897cf4b44520e87575db4b24bcbde8c112c0c789427a6aa8a4c6c60 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai virus
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=97b12d8a-1800-0000-2ae8-92e8ba0c0000 pid=3258 /usr/bin/sudo guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266 /tmp/sample.bin guuid=97b12d8a-1800-0000-2ae8-92e8ba0c0000 pid=3258->guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266 execve guuid=6385db8c-1800-0000-2ae8-92e8c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=6385db8c-1800-0000-2ae8-92e8c50c0000 pid=3269 execve guuid=bbb86f98-1800-0000-2ae8-92e8de0c0000 pid=3294 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=bbb86f98-1800-0000-2ae8-92e8de0c0000 pid=3294 execve guuid=01f5f298-1800-0000-2ae8-92e8e10c0000 pid=3297 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=01f5f298-1800-0000-2ae8-92e8e10c0000 pid=3297 clone guuid=762aa799-1800-0000-2ae8-92e8e40c0000 pid=3300 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=762aa799-1800-0000-2ae8-92e8e40c0000 pid=3300 execve guuid=dc73109a-1800-0000-2ae8-92e8e50c0000 pid=3301 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=dc73109a-1800-0000-2ae8-92e8e50c0000 pid=3301 execve guuid=15b9b7a2-1800-0000-2ae8-92e8f70c0000 pid=3319 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=15b9b7a2-1800-0000-2ae8-92e8f70c0000 pid=3319 execve guuid=778617a3-1800-0000-2ae8-92e8f90c0000 pid=3321 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=778617a3-1800-0000-2ae8-92e8f90c0000 pid=3321 clone guuid=0331d7a3-1800-0000-2ae8-92e8fd0c0000 pid=3325 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=0331d7a3-1800-0000-2ae8-92e8fd0c0000 pid=3325 execve guuid=5a5736a4-1800-0000-2ae8-92e8fe0c0000 pid=3326 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=5a5736a4-1800-0000-2ae8-92e8fe0c0000 pid=3326 execve guuid=7f81d0ac-1800-0000-2ae8-92e8050d0000 pid=3333 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=7f81d0ac-1800-0000-2ae8-92e8050d0000 pid=3333 execve guuid=13de27ad-1800-0000-2ae8-92e8060d0000 pid=3334 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=13de27ad-1800-0000-2ae8-92e8060d0000 pid=3334 clone guuid=b9d9eaad-1800-0000-2ae8-92e8080d0000 pid=3336 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=b9d9eaad-1800-0000-2ae8-92e8080d0000 pid=3336 execve guuid=976a89ae-1800-0000-2ae8-92e8090d0000 pid=3337 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=976a89ae-1800-0000-2ae8-92e8090d0000 pid=3337 execve guuid=52ebe9b7-1800-0000-2ae8-92e8150d0000 pid=3349 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=52ebe9b7-1800-0000-2ae8-92e8150d0000 pid=3349 execve guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350 /tmp/x86 net guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350 execve guuid=6df270b8-1800-0000-2ae8-92e81c0d0000 pid=3356 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=6df270b8-1800-0000-2ae8-92e81c0d0000 pid=3356 execve guuid=7e01bdb8-1800-0000-2ae8-92e81e0d0000 pid=3358 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=7e01bdb8-1800-0000-2ae8-92e81e0d0000 pid=3358 execve guuid=32bb41c2-1800-0000-2ae8-92e8330d0000 pid=3379 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=32bb41c2-1800-0000-2ae8-92e8330d0000 pid=3379 execve guuid=988d84c2-1800-0000-2ae8-92e8350d0000 pid=3381 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=988d84c2-1800-0000-2ae8-92e8350d0000 pid=3381 clone guuid=38431ac3-1800-0000-2ae8-92e8390d0000 pid=3385 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=38431ac3-1800-0000-2ae8-92e8390d0000 pid=3385 execve guuid=3b5985c3-1800-0000-2ae8-92e83b0d0000 pid=3387 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=3b5985c3-1800-0000-2ae8-92e83b0d0000 pid=3387 execve guuid=730727cc-1800-0000-2ae8-92e8530d0000 pid=3411 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=730727cc-1800-0000-2ae8-92e8530d0000 pid=3411 execve guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413 /tmp/i686 net guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413 execve guuid=fdfb0fce-1800-0000-2ae8-92e85d0d0000 pid=3421 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=fdfb0fce-1800-0000-2ae8-92e85d0d0000 pid=3421 execve guuid=0b1c81ce-1800-0000-2ae8-92e8600d0000 pid=3424 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=0b1c81ce-1800-0000-2ae8-92e8600d0000 pid=3424 execve guuid=d8c714d7-1800-0000-2ae8-92e87e0d0000 pid=3454 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=d8c714d7-1800-0000-2ae8-92e87e0d0000 pid=3454 execve guuid=c57e56d7-1800-0000-2ae8-92e8800d0000 pid=3456 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=c57e56d7-1800-0000-2ae8-92e8800d0000 pid=3456 clone guuid=d4a214d8-1800-0000-2ae8-92e8840d0000 pid=3460 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=d4a214d8-1800-0000-2ae8-92e8840d0000 pid=3460 execve guuid=c3b97cd8-1800-0000-2ae8-92e8870d0000 pid=3463 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=c3b97cd8-1800-0000-2ae8-92e8870d0000 pid=3463 execve guuid=7c931ce2-1800-0000-2ae8-92e8a80d0000 pid=3496 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=7c931ce2-1800-0000-2ae8-92e8a80d0000 pid=3496 execve guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499 /tmp/i586 net guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499 execve guuid=bdf0e5e3-1800-0000-2ae8-92e8b50d0000 pid=3509 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=bdf0e5e3-1800-0000-2ae8-92e8b50d0000 pid=3509 execve guuid=df765de4-1800-0000-2ae8-92e8b90d0000 pid=3513 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=df765de4-1800-0000-2ae8-92e8b90d0000 pid=3513 execve guuid=e31962ed-1800-0000-2ae8-92e8de0d0000 pid=3550 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=e31962ed-1800-0000-2ae8-92e8de0d0000 pid=3550 execve guuid=ee47a4ed-1800-0000-2ae8-92e8df0d0000 pid=3551 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=ee47a4ed-1800-0000-2ae8-92e8df0d0000 pid=3551 clone guuid=9ec92bee-1800-0000-2ae8-92e8e10d0000 pid=3553 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=9ec92bee-1800-0000-2ae8-92e8e10d0000 pid=3553 execve guuid=97d16fee-1800-0000-2ae8-92e8e20d0000 pid=3554 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=97d16fee-1800-0000-2ae8-92e8e20d0000 pid=3554 execve guuid=5dd2edf6-1800-0000-2ae8-92e8f10d0000 pid=3569 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=5dd2edf6-1800-0000-2ae8-92e8f10d0000 pid=3569 execve guuid=f83c44f7-1800-0000-2ae8-92e8f20d0000 pid=3570 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=f83c44f7-1800-0000-2ae8-92e8f20d0000 pid=3570 clone guuid=61e6eff7-1800-0000-2ae8-92e8f40d0000 pid=3572 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=61e6eff7-1800-0000-2ae8-92e8f40d0000 pid=3572 execve guuid=07274af8-1800-0000-2ae8-92e8f50d0000 pid=3573 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=07274af8-1800-0000-2ae8-92e8f50d0000 pid=3573 execve guuid=d3c19100-1900-0000-2ae8-92e80b0e0000 pid=3595 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=d3c19100-1900-0000-2ae8-92e80b0e0000 pid=3595 execve guuid=bd6dd000-1900-0000-2ae8-92e80d0e0000 pid=3597 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=bd6dd000-1900-0000-2ae8-92e80d0e0000 pid=3597 clone guuid=159b5b01-1900-0000-2ae8-92e8100e0000 pid=3600 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=159b5b01-1900-0000-2ae8-92e8100e0000 pid=3600 execve guuid=3065dc01-1900-0000-2ae8-92e8110e0000 pid=3601 /usr/bin/wget net send-data write-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=3065dc01-1900-0000-2ae8-92e8110e0000 pid=3601 execve guuid=e350040c-1900-0000-2ae8-92e8270e0000 pid=3623 /usr/bin/chmod guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=e350040c-1900-0000-2ae8-92e8270e0000 pid=3623 execve guuid=8169620c-1900-0000-2ae8-92e8290e0000 pid=3625 /usr/bin/bash guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=8169620c-1900-0000-2ae8-92e8290e0000 pid=3625 clone guuid=76091d0e-1900-0000-2ae8-92e82e0e0000 pid=3630 /usr/bin/rm delete-file guuid=8055228c-1800-0000-2ae8-92e8c20c0000 pid=3266->guuid=76091d0e-1900-0000-2ae8-92e82e0e0000 pid=3630 execve 78b40149-66ee-51ff-97dc-e61a4ad4d6d2 45.131.64.121:80 guuid=6385db8c-1800-0000-2ae8-92e8c50c0000 pid=3269->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 132B guuid=dc73109a-1800-0000-2ae8-92e8e50c0000 pid=3301->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 134B guuid=5a5736a4-1800-0000-2ae8-92e8fe0c0000 pid=3326->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 131B guuid=976a89ae-1800-0000-2ae8-92e8090d0000 pid=3337->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 131B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352 /usr/bin/dash zombie guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350->guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352 execve guuid=95795eb8-1800-0000-2ae8-92e8190d0000 pid=3353 /tmp/x86 zombie guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350->guuid=95795eb8-1800-0000-2ae8-92e8190d0000 pid=3353 clone guuid=3bf860b8-1800-0000-2ae8-92e81a0d0000 pid=3354 /tmp/x86 guuid=35fe30b8-1800-0000-2ae8-92e8160d0000 pid=3350->guuid=3bf860b8-1800-0000-2ae8-92e81a0d0000 pid=3354 clone guuid=a01e9fb8-1800-0000-2ae8-92e81d0d0000 pid=3357 /usr/bin/wget dns net send-data guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352->guuid=a01e9fb8-1800-0000-2ae8-92e81d0d0000 pid=3357 execve guuid=587924be-1800-0000-2ae8-92e8260d0000 pid=3366 /usr/bin/chmod guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352->guuid=587924be-1800-0000-2ae8-92e8260d0000 pid=3366 execve guuid=130575be-1800-0000-2ae8-92e8270d0000 pid=3367 /tmp/..... guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352->guuid=130575be-1800-0000-2ae8-92e8270d0000 pid=3367 execve guuid=bfb56dbf-1800-0000-2ae8-92e82c0d0000 pid=3372 /usr/bin/rm delete-file guuid=758b5bb8-1800-0000-2ae8-92e8180d0000 pid=3352->guuid=bfb56dbf-1800-0000-2ae8-92e82c0d0000 pid=3372 execve guuid=d2ef66b8-1800-0000-2ae8-92e81b0d0000 pid=3355 /tmp/x86 net send-data zombie guuid=3bf860b8-1800-0000-2ae8-92e81a0d0000 pid=3354->guuid=d2ef66b8-1800-0000-2ae8-92e81b0d0000 pid=3355 clone ce759d12-4dec-536a-a55c-6ed7795ab03c 45.131.64.121:323 guuid=d2ef66b8-1800-0000-2ae8-92e81b0d0000 pid=3355->ce759d12-4dec-536a-a55c-6ed7795ab03c send: 9B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a01e9fb8-1800-0000-2ae8-92e81d0d0000 pid=3357->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=7e01bdb8-1800-0000-2ae8-92e81e0d0000 pid=3358->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 134B guuid=3b5985c3-1800-0000-2ae8-92e83b0d0000 pid=3387->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 132B guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417 /usr/bin/dash zombie guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413->guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417 execve guuid=9824e5cd-1800-0000-2ae8-92e85a0d0000 pid=3418 /tmp/i686 guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413->guuid=9824e5cd-1800-0000-2ae8-92e85a0d0000 pid=3418 clone guuid=292aebcd-1800-0000-2ae8-92e85b0d0000 pid=3419 /tmp/i686 guuid=dce086cc-1800-0000-2ae8-92e8550d0000 pid=3413->guuid=292aebcd-1800-0000-2ae8-92e85b0d0000 pid=3419 clone guuid=908d24ce-1800-0000-2ae8-92e85e0d0000 pid=3422 /usr/bin/wget dns net send-data guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417->guuid=908d24ce-1800-0000-2ae8-92e85e0d0000 pid=3422 execve guuid=215abad2-1800-0000-2ae8-92e86d0d0000 pid=3437 /usr/bin/chmod guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417->guuid=215abad2-1800-0000-2ae8-92e86d0d0000 pid=3437 execve guuid=178201d3-1800-0000-2ae8-92e86f0d0000 pid=3439 /tmp/..... guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417->guuid=178201d3-1800-0000-2ae8-92e86f0d0000 pid=3439 execve guuid=3ad5e8d3-1800-0000-2ae8-92e8740d0000 pid=3444 /usr/bin/rm delete-file guuid=6bcadbcd-1800-0000-2ae8-92e8590d0000 pid=3417->guuid=3ad5e8d3-1800-0000-2ae8-92e8740d0000 pid=3444 execve guuid=d5e9f4cd-1800-0000-2ae8-92e85c0d0000 pid=3420 /tmp/i686 net send-data zombie guuid=292aebcd-1800-0000-2ae8-92e85b0d0000 pid=3419->guuid=d5e9f4cd-1800-0000-2ae8-92e85c0d0000 pid=3420 clone guuid=d5e9f4cd-1800-0000-2ae8-92e85c0d0000 pid=3420->ce759d12-4dec-536a-a55c-6ed7795ab03c send: 52B guuid=908d24ce-1800-0000-2ae8-92e85e0d0000 pid=3422->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=0b1c81ce-1800-0000-2ae8-92e8600d0000 pid=3424->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 135B guuid=c3b97cd8-1800-0000-2ae8-92e8870d0000 pid=3463->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 132B guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505 /usr/bin/dash zombie guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499->guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505 execve guuid=2be5b7e3-1800-0000-2ae8-92e8b20d0000 pid=3506 /tmp/i586 guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499->guuid=2be5b7e3-1800-0000-2ae8-92e8b20d0000 pid=3506 clone guuid=1674c3e3-1800-0000-2ae8-92e8b30d0000 pid=3507 /tmp/i586 guuid=99387ce2-1800-0000-2ae8-92e8ab0d0000 pid=3499->guuid=1674c3e3-1800-0000-2ae8-92e8b30d0000 pid=3507 clone guuid=347ff5e3-1800-0000-2ae8-92e8b70d0000 pid=3511 /usr/bin/wget dns net send-data guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505->guuid=347ff5e3-1800-0000-2ae8-92e8b70d0000 pid=3511 execve guuid=457f1be9-1800-0000-2ae8-92e8ca0d0000 pid=3530 /usr/bin/chmod guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505->guuid=457f1be9-1800-0000-2ae8-92e8ca0d0000 pid=3530 execve guuid=259f54e9-1800-0000-2ae8-92e8cc0d0000 pid=3532 /tmp/..... guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505->guuid=259f54e9-1800-0000-2ae8-92e8cc0d0000 pid=3532 execve guuid=1c44ffe9-1800-0000-2ae8-92e8d00d0000 pid=3536 /usr/bin/rm delete-file guuid=82daaee3-1800-0000-2ae8-92e8b10d0000 pid=3505->guuid=1c44ffe9-1800-0000-2ae8-92e8d00d0000 pid=3536 execve guuid=6c09cce3-1800-0000-2ae8-92e8b40d0000 pid=3508 /tmp/i586 net send-data zombie guuid=1674c3e3-1800-0000-2ae8-92e8b30d0000 pid=3507->guuid=6c09cce3-1800-0000-2ae8-92e8b40d0000 pid=3508 clone guuid=6c09cce3-1800-0000-2ae8-92e8b40d0000 pid=3508->ce759d12-4dec-536a-a55c-6ed7795ab03c send: 52B guuid=347ff5e3-1800-0000-2ae8-92e8b70d0000 pid=3511->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=df765de4-1800-0000-2ae8-92e8b90d0000 pid=3513->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 132B guuid=97d16fee-1800-0000-2ae8-92e8e20d0000 pid=3554->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 133B guuid=07274af8-1800-0000-2ae8-92e8f50d0000 pid=3573->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 134B guuid=3065dc01-1900-0000-2ae8-92e8110e0000 pid=3601->78b40149-66ee-51ff-97dc-e61a4ad4d6d2 send: 134B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-02-16 02:53:25 UTC
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Gafgyt

sh 0a47760cc5ae692eb0cea3699d2756879322cd4bd2b172fb92ae57b7e83a3850

(this sample)

Comments