MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 11261321ec75bcde1aa101a0670998ee095a1c3927351ec047a2ae2c024c64a9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 11261321ec75bcde1aa101a0670998ee095a1c3927351ec047a2ae2c024c64a9
SHA3-384 hash: 1254ee43325b1c7936625ffd1cca81148f1256cd71a028a5dae5592a374240326618a993f91c5eeba394dd760e00300b
SHA1 hash: 84df2becbe18ec2fdaa0db28fe780e2c87b34c09
MD5 hash: 916a95bafbf319ef89c5d95128b77456
humanhash: zebra-alanine-robert-two
File name:dick.sh
Download: download sample
File size:1'968 bytes
First seen:2026-03-03 02:18:27 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vyGnDL/dLJLYWRL9LgoLRLlbLC0+MfnLAR9RG3RFBHLlbL1Lrchig:vyanpNJhgKVtTlAR9R4RFBrtZC
TLSH T12C415ED7189909742CDDD9AB33BB681034D4D09B2BC5AF0F68EE38E4098DD85B8C4BD2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://77.90.61.79/m-i.p-s.dick876577bcd50061d0ae066c6b6c328af673595233441df9c9197e440add1a09dd Miraielf mirai ua-wget
http://77.90.61.79/m-p.s-l.dick3c924ae8905ee297be06c3eb02fd6340d22b902e1f8e34a831996c71d3b6231a Miraielf mirai ua-wget
http://77.90.61.79/s-h.4-.dick58968266f92ea06e3f064e23e58d689cc9d6841082581e06876d36d4a14228ca Miraielf mirai ua-wget
http://77.90.61.79/x-8.6-.dickbc0b175fc6ca68475397d362b5c556c60ac2d1bac7b207fb016ba2fb9ace771e Miraielf mirai ua-wget
http://77.90.61.79/a-r.m-6.dick4bf771b4d750b3d3beb1aaa1311d7890f1b83a9242f5183fe72e7dfe2a02ea70 Miraielf mirai ua-wget
http://77.90.61.79/x-3.2-.dickef15218a93fd7274e3904f9e58831fea865d69020a91635b0bed69379b22ab41 Miraielf mirai ua-wget
http://77.90.61.79/a-r.m-7.dick3d5add2acceb6d8ffec49932f7bfa31e2c945dcf366e1317fe9c998dfb37fce3 Miraielf mirai ua-wget
http://77.90.61.79/p-p.c-.dick448452d8804f49777e0d8d1f31b1bfe9bf6e73965574dc30dce6e8a58f1ca5bc Gafgytelf gafgyt ua-wget
http://77.90.61.79/i-5.8-6.dick1ec4349dc3a07ecfc1d86980b30bd00f5fa978748d6fa8e2c5e1deb2c86adfc1 Miraielf mirai ua-wget
http://77.90.61.79/m-6.8-k.dick60d896fd063131c40e1036d648989147f787f46d17e33decff8a24c08651d35d Miraielf mirai ua-wget
http://77.90.61.79/a-r.m-4.dick448452d8804f49777e0d8d1f31b1bfe9bf6e73965574dc30dce6e8a58f1ca5bc Gafgytelf gafgyt ua-wget
http://77.90.61.79/a-r.m-5.dick0fd0434d337188f1ccc4babaa0889494948ebbf59545eb67e1767f2430e66e4b Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
79
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai obfuscated
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ff8130dc-1700-0000-13b8-00d77e0b0000 pid=2942 /usr/bin/sudo guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946 /tmp/sample.bin guuid=ff8130dc-1700-0000-13b8-00d77e0b0000 pid=2942->guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946 execve guuid=b5fb5ade-1700-0000-13b8-00d7840b0000 pid=2948 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=b5fb5ade-1700-0000-13b8-00d7840b0000 pid=2948 execve guuid=c58df7e5-1700-0000-13b8-00d7960b0000 pid=2966 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=c58df7e5-1700-0000-13b8-00d7960b0000 pid=2966 execve guuid=67c934e6-1700-0000-13b8-00d7980b0000 pid=2968 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=67c934e6-1700-0000-13b8-00d7980b0000 pid=2968 clone guuid=63b6b7e6-1700-0000-13b8-00d79c0b0000 pid=2972 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=63b6b7e6-1700-0000-13b8-00d79c0b0000 pid=2972 execve guuid=fc9f0de7-1700-0000-13b8-00d79e0b0000 pid=2974 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=fc9f0de7-1700-0000-13b8-00d79e0b0000 pid=2974 execve guuid=0d58fdec-1700-0000-13b8-00d7af0b0000 pid=2991 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=0d58fdec-1700-0000-13b8-00d7af0b0000 pid=2991 execve guuid=4c884bed-1700-0000-13b8-00d7b10b0000 pid=2993 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=4c884bed-1700-0000-13b8-00d7b10b0000 pid=2993 clone guuid=3449eded-1700-0000-13b8-00d7b40b0000 pid=2996 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=3449eded-1700-0000-13b8-00d7b40b0000 pid=2996 execve guuid=a07a35ee-1700-0000-13b8-00d7b60b0000 pid=2998 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=a07a35ee-1700-0000-13b8-00d7b60b0000 pid=2998 execve guuid=176a44f3-1700-0000-13b8-00d7c30b0000 pid=3011 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=176a44f3-1700-0000-13b8-00d7c30b0000 pid=3011 execve guuid=e5bf83f3-1700-0000-13b8-00d7c50b0000 pid=3013 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=e5bf83f3-1700-0000-13b8-00d7c50b0000 pid=3013 clone guuid=009306f4-1700-0000-13b8-00d7c90b0000 pid=3017 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=009306f4-1700-0000-13b8-00d7c90b0000 pid=3017 execve guuid=a7be6df4-1700-0000-13b8-00d7cb0b0000 pid=3019 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=a7be6df4-1700-0000-13b8-00d7cb0b0000 pid=3019 execve guuid=cb513cfa-1700-0000-13b8-00d7df0b0000 pid=3039 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=cb513cfa-1700-0000-13b8-00d7df0b0000 pid=3039 execve guuid=94a086fa-1700-0000-13b8-00d7e10b0000 pid=3041 /tmp/x-8.6-.dick guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=94a086fa-1700-0000-13b8-00d7e10b0000 pid=3041 execve guuid=bf5ba5fa-1700-0000-13b8-00d7e40b0000 pid=3044 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=bf5ba5fa-1700-0000-13b8-00d7e40b0000 pid=3044 execve guuid=3778fafa-1700-0000-13b8-00d7e60b0000 pid=3046 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=3778fafa-1700-0000-13b8-00d7e60b0000 pid=3046 execve guuid=93a5fc00-1800-0000-13b8-00d7fb0b0000 pid=3067 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=93a5fc00-1800-0000-13b8-00d7fb0b0000 pid=3067 execve guuid=bab05201-1800-0000-13b8-00d7fd0b0000 pid=3069 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=bab05201-1800-0000-13b8-00d7fd0b0000 pid=3069 clone guuid=3357e601-1800-0000-13b8-00d7010c0000 pid=3073 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=3357e601-1800-0000-13b8-00d7010c0000 pid=3073 execve guuid=c75c4202-1800-0000-13b8-00d7030c0000 pid=3075 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=c75c4202-1800-0000-13b8-00d7030c0000 pid=3075 execve guuid=40d98f07-1800-0000-13b8-00d7140c0000 pid=3092 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=40d98f07-1800-0000-13b8-00d7140c0000 pid=3092 execve guuid=47c3dd07-1800-0000-13b8-00d7160c0000 pid=3094 /tmp/x-3.2-.dick guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=47c3dd07-1800-0000-13b8-00d7160c0000 pid=3094 execve guuid=9abb1008-1800-0000-13b8-00d7180c0000 pid=3096 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=9abb1008-1800-0000-13b8-00d7180c0000 pid=3096 execve guuid=e6d46008-1800-0000-13b8-00d7190c0000 pid=3097 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=e6d46008-1800-0000-13b8-00d7190c0000 pid=3097 execve guuid=53007c0d-1800-0000-13b8-00d7280c0000 pid=3112 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=53007c0d-1800-0000-13b8-00d7280c0000 pid=3112 execve guuid=838cf40d-1800-0000-13b8-00d7290c0000 pid=3113 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=838cf40d-1800-0000-13b8-00d7290c0000 pid=3113 clone guuid=5fc6760f-1800-0000-13b8-00d72c0c0000 pid=3116 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=5fc6760f-1800-0000-13b8-00d72c0c0000 pid=3116 execve guuid=c4f7c70f-1800-0000-13b8-00d72e0c0000 pid=3118 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=c4f7c70f-1800-0000-13b8-00d72e0c0000 pid=3118 execve guuid=99533a15-1800-0000-13b8-00d73c0c0000 pid=3132 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=99533a15-1800-0000-13b8-00d73c0c0000 pid=3132 execve guuid=e102bd15-1800-0000-13b8-00d73f0c0000 pid=3135 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=e102bd15-1800-0000-13b8-00d73f0c0000 pid=3135 clone guuid=7bf76d16-1800-0000-13b8-00d7430c0000 pid=3139 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=7bf76d16-1800-0000-13b8-00d7430c0000 pid=3139 execve guuid=709ef316-1800-0000-13b8-00d7460c0000 pid=3142 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=709ef316-1800-0000-13b8-00d7460c0000 pid=3142 execve guuid=11c4241d-1800-0000-13b8-00d75c0c0000 pid=3164 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=11c4241d-1800-0000-13b8-00d75c0c0000 pid=3164 execve guuid=cf8f6d1d-1800-0000-13b8-00d75e0c0000 pid=3166 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=cf8f6d1d-1800-0000-13b8-00d75e0c0000 pid=3166 clone guuid=907f361e-1800-0000-13b8-00d7630c0000 pid=3171 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=907f361e-1800-0000-13b8-00d7630c0000 pid=3171 execve guuid=fcd54a23-1800-0000-13b8-00d76a0c0000 pid=3178 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=fcd54a23-1800-0000-13b8-00d76a0c0000 pid=3178 execve guuid=64bb5528-1800-0000-13b8-00d7740c0000 pid=3188 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=64bb5528-1800-0000-13b8-00d7740c0000 pid=3188 execve guuid=190d9b28-1800-0000-13b8-00d7760c0000 pid=3190 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=190d9b28-1800-0000-13b8-00d7760c0000 pid=3190 clone guuid=0c914629-1800-0000-13b8-00d7790c0000 pid=3193 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=0c914629-1800-0000-13b8-00d7790c0000 pid=3193 execve guuid=2ca9a829-1800-0000-13b8-00d77a0c0000 pid=3194 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=2ca9a829-1800-0000-13b8-00d77a0c0000 pid=3194 execve guuid=2fb52b2f-1800-0000-13b8-00d7880c0000 pid=3208 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=2fb52b2f-1800-0000-13b8-00d7880c0000 pid=3208 execve guuid=c6876e2f-1800-0000-13b8-00d78a0c0000 pid=3210 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=c6876e2f-1800-0000-13b8-00d78a0c0000 pid=3210 clone guuid=e5de1f30-1800-0000-13b8-00d78c0c0000 pid=3212 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=e5de1f30-1800-0000-13b8-00d78c0c0000 pid=3212 execve guuid=75256a30-1800-0000-13b8-00d78e0c0000 pid=3214 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=75256a30-1800-0000-13b8-00d78e0c0000 pid=3214 execve guuid=77d61a36-1800-0000-13b8-00d7940c0000 pid=3220 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=77d61a36-1800-0000-13b8-00d7940c0000 pid=3220 execve guuid=ba9ed736-1800-0000-13b8-00d7950c0000 pid=3221 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=ba9ed736-1800-0000-13b8-00d7950c0000 pid=3221 clone guuid=458f9537-1800-0000-13b8-00d7970c0000 pid=3223 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=458f9537-1800-0000-13b8-00d7970c0000 pid=3223 execve guuid=342ef037-1800-0000-13b8-00d7980c0000 pid=3224 /usr/bin/wget net send-data write-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=342ef037-1800-0000-13b8-00d7980c0000 pid=3224 execve guuid=89e47f3d-1800-0000-13b8-00d7990c0000 pid=3225 /usr/bin/chmod guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=89e47f3d-1800-0000-13b8-00d7990c0000 pid=3225 execve guuid=ed43de3d-1800-0000-13b8-00d79a0c0000 pid=3226 /usr/bin/bash guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=ed43de3d-1800-0000-13b8-00d79a0c0000 pid=3226 clone guuid=f4f6903e-1800-0000-13b8-00d79c0c0000 pid=3228 /usr/bin/rm delete-file guuid=a398f7dd-1700-0000-13b8-00d7820b0000 pid=2946->guuid=f4f6903e-1800-0000-13b8-00d79c0c0000 pid=3228 execve 840d7f1d-2953-5e40-8ed3-576dbf41850c 77.90.61.79:80 guuid=b5fb5ade-1700-0000-13b8-00d7840b0000 pid=2948->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=fc9f0de7-1700-0000-13b8-00d79e0b0000 pid=2974->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=a07a35ee-1700-0000-13b8-00d7b60b0000 pid=2998->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 137B guuid=a7be6df4-1700-0000-13b8-00d7cb0b0000 pid=3019->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 137B guuid=6e9599fa-1700-0000-13b8-00d7e30b0000 pid=3043 /tmp/x-8.6-.dick net send-data zombie guuid=94a086fa-1700-0000-13b8-00d7e10b0000 pid=3041->guuid=6e9599fa-1700-0000-13b8-00d7e30b0000 pid=3043 clone b719cd81-0cf7-5f23-87ea-c6d5d4b1cd16 77.90.61.79:4912 guuid=6e9599fa-1700-0000-13b8-00d7e30b0000 pid=3043->b719cd81-0cf7-5f23-87ea-c6d5d4b1cd16 send: 6B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6e9599fa-1700-0000-13b8-00d7e30b0000 pid=3043->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 36B guuid=3778fafa-1700-0000-13b8-00d7e60b0000 pid=3046->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=c75c4202-1800-0000-13b8-00d7030c0000 pid=3075->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 137B guuid=aab80208-1800-0000-13b8-00d7170c0000 pid=3095 /tmp/x-3.2-.dick net send-data zombie guuid=47c3dd07-1800-0000-13b8-00d7160c0000 pid=3094->guuid=aab80208-1800-0000-13b8-00d7170c0000 pid=3095 clone guuid=aab80208-1800-0000-13b8-00d7170c0000 pid=3095->b719cd81-0cf7-5f23-87ea-c6d5d4b1cd16 send: 330B guuid=aab80208-1800-0000-13b8-00d7170c0000 pid=3095->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1980B guuid=e6d46008-1800-0000-13b8-00d7190c0000 pid=3097->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=c4f7c70f-1800-0000-13b8-00d72e0c0000 pid=3118->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 137B guuid=709ef316-1800-0000-13b8-00d7460c0000 pid=3142->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=fcd54a23-1800-0000-13b8-00d76a0c0000 pid=3178->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=2ca9a829-1800-0000-13b8-00d77a0c0000 pid=3194->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 137B guuid=75256a30-1800-0000-13b8-00d78e0c0000 pid=3214->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B guuid=342ef037-1800-0000-13b8-00d7980c0000 pid=3224->840d7f1d-2953-5e40-8ed3-576dbf41850c send: 138B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-03-03 02:19:27 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion linux
Behaviour
Writes file to tmp directory
Changes its process name
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 11261321ec75bcde1aa101a0670998ee095a1c3927351ec047a2ae2c024c64a9

(this sample)

  
Delivery method
Distributed via web download

Comments