MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 12f4fa99abe2864ae54e4ca36fff875b70b048d834dda99d4db3e57101b3f16f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 12f4fa99abe2864ae54e4ca36fff875b70b048d834dda99d4db3e57101b3f16f
SHA3-384 hash: 336392010e6157a20e9d3329348e7295808d68949d957e2685d53add878f1b07a69c44c55a0ae2ec74d5d75da0f7d3ba
SHA1 hash: 000eb832b603f4608d3879e4d97705809b747c48
MD5 hash: 69635ecb8f49de95f7f174a1aa04cc40
humanhash: ack-arizona-mississippi-fish
File name:cache
Download: download sample
File size:3'180 bytes
First seen:2025-12-26 12:27:15 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp7/76p7K7Wp7GO7GVp7n7ap7I7ifNp7x76p7S7Op7c7Yp7e07eDbp7A7Qp7d7GP:vI18wVNqpRMNDblGOT/O
TLSH T1676142CD21B1A3357DB5D72732E586C4F0C1929FD4C92E63ACDEB8A9C48CE187990693
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.41/Mddos/Mddos.x86n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.mipsn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.mpsln/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.armn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.arm5n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.arm6n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.arm7n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.ppcn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.m68kn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.sh4n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.spcn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.arcn/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.x86_64n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.i686n/an/aelf ua-wget
http://176.65.148.41/Mddos/Mddos.i486n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-26T09:47:00Z UTC
Last seen:
2025-12-27T02:00:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=696d79ff-1900-0000-1011-7c6ca0090000 pid=2464 /usr/bin/sudo guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471 /tmp/sample.bin guuid=696d79ff-1900-0000-1011-7c6ca0090000 pid=2464->guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471 execve guuid=2bc0cd01-1a00-0000-1011-7c6ca9090000 pid=2473 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=2bc0cd01-1a00-0000-1011-7c6ca9090000 pid=2473 execve guuid=197fc606-1a00-0000-1011-7c6cb1090000 pid=2481 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=197fc606-1a00-0000-1011-7c6cb1090000 pid=2481 execve guuid=e643c14c-1a00-0000-1011-7c6c480a0000 pid=2632 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e643c14c-1a00-0000-1011-7c6c480a0000 pid=2632 execve guuid=ca621c4d-1a00-0000-1011-7c6c4a0a0000 pid=2634 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=ca621c4d-1a00-0000-1011-7c6c4a0a0000 pid=2634 execve guuid=cfc28c4d-1a00-0000-1011-7c6c4c0a0000 pid=2636 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=cfc28c4d-1a00-0000-1011-7c6c4c0a0000 pid=2636 clone guuid=d3fbb54d-1a00-0000-1011-7c6c4d0a0000 pid=2637 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=d3fbb54d-1a00-0000-1011-7c6c4d0a0000 pid=2637 execve guuid=40527251-1a00-0000-1011-7c6c560a0000 pid=2646 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=40527251-1a00-0000-1011-7c6c560a0000 pid=2646 execve guuid=c4fbf757-1a00-0000-1011-7c6c680a0000 pid=2664 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=c4fbf757-1a00-0000-1011-7c6c680a0000 pid=2664 execve guuid=ec8d5458-1a00-0000-1011-7c6c6b0a0000 pid=2667 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=ec8d5458-1a00-0000-1011-7c6c6b0a0000 pid=2667 execve guuid=8f31a858-1a00-0000-1011-7c6c6c0a0000 pid=2668 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=8f31a858-1a00-0000-1011-7c6c6c0a0000 pid=2668 clone guuid=9992d658-1a00-0000-1011-7c6c6e0a0000 pid=2670 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=9992d658-1a00-0000-1011-7c6c6e0a0000 pid=2670 execve guuid=0702465c-1a00-0000-1011-7c6c790a0000 pid=2681 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=0702465c-1a00-0000-1011-7c6c790a0000 pid=2681 execve guuid=565f9463-1a00-0000-1011-7c6c8f0a0000 pid=2703 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=565f9463-1a00-0000-1011-7c6c8f0a0000 pid=2703 execve guuid=618ee263-1a00-0000-1011-7c6c910a0000 pid=2705 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=618ee263-1a00-0000-1011-7c6c910a0000 pid=2705 execve guuid=a3ce2564-1a00-0000-1011-7c6c930a0000 pid=2707 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a3ce2564-1a00-0000-1011-7c6c930a0000 pid=2707 clone guuid=17d55764-1a00-0000-1011-7c6c940a0000 pid=2708 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=17d55764-1a00-0000-1011-7c6c940a0000 pid=2708 execve guuid=51bd0767-1a00-0000-1011-7c6c9d0a0000 pid=2717 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=51bd0767-1a00-0000-1011-7c6c9d0a0000 pid=2717 execve guuid=2755646b-1a00-0000-1011-7c6cab0a0000 pid=2731 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=2755646b-1a00-0000-1011-7c6cab0a0000 pid=2731 execve guuid=5cdde66b-1a00-0000-1011-7c6cae0a0000 pid=2734 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=5cdde66b-1a00-0000-1011-7c6cae0a0000 pid=2734 execve guuid=aa95466c-1a00-0000-1011-7c6cb00a0000 pid=2736 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=aa95466c-1a00-0000-1011-7c6cb00a0000 pid=2736 clone guuid=715f686c-1a00-0000-1011-7c6cb10a0000 pid=2737 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=715f686c-1a00-0000-1011-7c6cb10a0000 pid=2737 execve guuid=c922bd6f-1a00-0000-1011-7c6cbb0a0000 pid=2747 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=c922bd6f-1a00-0000-1011-7c6cbb0a0000 pid=2747 execve guuid=23d66e73-1a00-0000-1011-7c6cc60a0000 pid=2758 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=23d66e73-1a00-0000-1011-7c6cc60a0000 pid=2758 execve guuid=e89bcc73-1a00-0000-1011-7c6cc70a0000 pid=2759 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e89bcc73-1a00-0000-1011-7c6cc70a0000 pid=2759 execve guuid=a5b91074-1a00-0000-1011-7c6cc90a0000 pid=2761 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a5b91074-1a00-0000-1011-7c6cc90a0000 pid=2761 clone guuid=fe573574-1a00-0000-1011-7c6cca0a0000 pid=2762 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=fe573574-1a00-0000-1011-7c6cca0a0000 pid=2762 execve guuid=a1e0da76-1a00-0000-1011-7c6cd00a0000 pid=2768 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a1e0da76-1a00-0000-1011-7c6cd00a0000 pid=2768 execve guuid=c50c2d7f-1a00-0000-1011-7c6ce00a0000 pid=2784 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=c50c2d7f-1a00-0000-1011-7c6ce00a0000 pid=2784 execve guuid=d11b867f-1a00-0000-1011-7c6ce20a0000 pid=2786 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=d11b867f-1a00-0000-1011-7c6ce20a0000 pid=2786 execve guuid=b229df7f-1a00-0000-1011-7c6ce30a0000 pid=2787 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=b229df7f-1a00-0000-1011-7c6ce30a0000 pid=2787 clone guuid=be512680-1a00-0000-1011-7c6ce40a0000 pid=2788 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=be512680-1a00-0000-1011-7c6ce40a0000 pid=2788 execve guuid=09f4ff8f-1a00-0000-1011-7c6c070b0000 pid=2823 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=09f4ff8f-1a00-0000-1011-7c6c070b0000 pid=2823 execve guuid=0b5e7795-1a00-0000-1011-7c6c0c0b0000 pid=2828 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=0b5e7795-1a00-0000-1011-7c6c0c0b0000 pid=2828 execve guuid=a6a4fe95-1a00-0000-1011-7c6c0e0b0000 pid=2830 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a6a4fe95-1a00-0000-1011-7c6c0e0b0000 pid=2830 execve guuid=c6106f96-1a00-0000-1011-7c6c0f0b0000 pid=2831 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=c6106f96-1a00-0000-1011-7c6c0f0b0000 pid=2831 clone guuid=ef28a996-1a00-0000-1011-7c6c100b0000 pid=2832 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=ef28a996-1a00-0000-1011-7c6c100b0000 pid=2832 execve guuid=f5f39299-1a00-0000-1011-7c6c160b0000 pid=2838 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=f5f39299-1a00-0000-1011-7c6c160b0000 pid=2838 execve guuid=df05569e-1a00-0000-1011-7c6c1d0b0000 pid=2845 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=df05569e-1a00-0000-1011-7c6c1d0b0000 pid=2845 execve guuid=7e4daa9e-1a00-0000-1011-7c6c1f0b0000 pid=2847 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=7e4daa9e-1a00-0000-1011-7c6c1f0b0000 pid=2847 execve guuid=27dd0b9f-1a00-0000-1011-7c6c210b0000 pid=2849 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=27dd0b9f-1a00-0000-1011-7c6c210b0000 pid=2849 clone guuid=e181309f-1a00-0000-1011-7c6c230b0000 pid=2851 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e181309f-1a00-0000-1011-7c6c230b0000 pid=2851 execve guuid=ebcc45a2-1a00-0000-1011-7c6c270b0000 pid=2855 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=ebcc45a2-1a00-0000-1011-7c6c270b0000 pid=2855 execve guuid=644cd2a8-1a00-0000-1011-7c6c2d0b0000 pid=2861 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=644cd2a8-1a00-0000-1011-7c6c2d0b0000 pid=2861 execve guuid=fde925aa-1a00-0000-1011-7c6c2e0b0000 pid=2862 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=fde925aa-1a00-0000-1011-7c6c2e0b0000 pid=2862 execve guuid=532a74aa-1a00-0000-1011-7c6c300b0000 pid=2864 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=532a74aa-1a00-0000-1011-7c6c300b0000 pid=2864 clone guuid=283b9daa-1a00-0000-1011-7c6c310b0000 pid=2865 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=283b9daa-1a00-0000-1011-7c6c310b0000 pid=2865 execve guuid=369c5baf-1a00-0000-1011-7c6c3f0b0000 pid=2879 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=369c5baf-1a00-0000-1011-7c6c3f0b0000 pid=2879 execve guuid=02c115b6-1a00-0000-1011-7c6c4e0b0000 pid=2894 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=02c115b6-1a00-0000-1011-7c6c4e0b0000 pid=2894 execve guuid=a395b7b6-1a00-0000-1011-7c6c500b0000 pid=2896 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a395b7b6-1a00-0000-1011-7c6c500b0000 pid=2896 execve guuid=1d25fcb6-1a00-0000-1011-7c6c510b0000 pid=2897 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=1d25fcb6-1a00-0000-1011-7c6c510b0000 pid=2897 clone guuid=93e122b7-1a00-0000-1011-7c6c520b0000 pid=2898 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=93e122b7-1a00-0000-1011-7c6c520b0000 pid=2898 execve guuid=b7b1ddf7-1a00-0000-1011-7c6cd90b0000 pid=3033 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=b7b1ddf7-1a00-0000-1011-7c6cd90b0000 pid=3033 execve guuid=38d81efd-1a00-0000-1011-7c6ce80b0000 pid=3048 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=38d81efd-1a00-0000-1011-7c6ce80b0000 pid=3048 execve guuid=8cafa5fd-1a00-0000-1011-7c6cea0b0000 pid=3050 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=8cafa5fd-1a00-0000-1011-7c6cea0b0000 pid=3050 execve guuid=b4532ffe-1a00-0000-1011-7c6ceb0b0000 pid=3051 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=b4532ffe-1a00-0000-1011-7c6ceb0b0000 pid=3051 clone guuid=e07257fe-1a00-0000-1011-7c6cec0b0000 pid=3052 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e07257fe-1a00-0000-1011-7c6cec0b0000 pid=3052 execve guuid=2cd78602-1b00-0000-1011-7c6cf70b0000 pid=3063 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=2cd78602-1b00-0000-1011-7c6cf70b0000 pid=3063 execve guuid=cc005008-1b00-0000-1011-7c6c050c0000 pid=3077 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=cc005008-1b00-0000-1011-7c6c050c0000 pid=3077 execve guuid=65d1bc08-1b00-0000-1011-7c6c070c0000 pid=3079 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=65d1bc08-1b00-0000-1011-7c6c070c0000 pid=3079 execve guuid=38853b09-1b00-0000-1011-7c6c090c0000 pid=3081 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=38853b09-1b00-0000-1011-7c6c090c0000 pid=3081 clone guuid=58018409-1b00-0000-1011-7c6c0b0c0000 pid=3083 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=58018409-1b00-0000-1011-7c6c0b0c0000 pid=3083 execve guuid=05d47a19-1b00-0000-1011-7c6c400c0000 pid=3136 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=05d47a19-1b00-0000-1011-7c6c400c0000 pid=3136 execve guuid=d01d641d-1b00-0000-1011-7c6c4b0c0000 pid=3147 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=d01d641d-1b00-0000-1011-7c6c4b0c0000 pid=3147 execve guuid=d0cbbb1d-1b00-0000-1011-7c6c4d0c0000 pid=3149 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=d0cbbb1d-1b00-0000-1011-7c6c4d0c0000 pid=3149 execve guuid=35ae191e-1b00-0000-1011-7c6c4f0c0000 pid=3151 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=35ae191e-1b00-0000-1011-7c6c4f0c0000 pid=3151 clone guuid=e4bd451e-1b00-0000-1011-7c6c500c0000 pid=3152 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e4bd451e-1b00-0000-1011-7c6c500c0000 pid=3152 execve guuid=23620621-1b00-0000-1011-7c6c580c0000 pid=3160 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=23620621-1b00-0000-1011-7c6c580c0000 pid=3160 execve guuid=48efd624-1b00-0000-1011-7c6c640c0000 pid=3172 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=48efd624-1b00-0000-1011-7c6c640c0000 pid=3172 execve guuid=b8134d25-1b00-0000-1011-7c6c660c0000 pid=3174 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=b8134d25-1b00-0000-1011-7c6c660c0000 pid=3174 execve guuid=2a008f25-1b00-0000-1011-7c6c680c0000 pid=3176 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=2a008f25-1b00-0000-1011-7c6c680c0000 pid=3176 clone guuid=f050d825-1b00-0000-1011-7c6c690c0000 pid=3177 /usr/bin/wget net send-data guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=f050d825-1b00-0000-1011-7c6c690c0000 pid=3177 execve guuid=3d677529-1b00-0000-1011-7c6c720c0000 pid=3186 /usr/bin/curl net send-data write-file guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=3d677529-1b00-0000-1011-7c6c720c0000 pid=3186 execve guuid=a136a22e-1b00-0000-1011-7c6c850c0000 pid=3205 /usr/bin/cat guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=a136a22e-1b00-0000-1011-7c6c850c0000 pid=3205 execve guuid=562bf02e-1b00-0000-1011-7c6c860c0000 pid=3206 /usr/bin/chmod guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=562bf02e-1b00-0000-1011-7c6c860c0000 pid=3206 execve guuid=e9b54d2f-1b00-0000-1011-7c6c890c0000 pid=3209 /usr/bin/bash guuid=d4ee6301-1a00-0000-1011-7c6ca7090000 pid=2471->guuid=e9b54d2f-1b00-0000-1011-7c6c890c0000 pid=3209 clone d9db81a5-4229-5ecf-8d47-59af2d1108c6 176.65.148.41:80 guuid=2bc0cd01-1a00-0000-1011-7c6ca9090000 pid=2473->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=197fc606-1a00-0000-1011-7c6cb1090000 pid=2481->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=d3fbb54d-1a00-0000-1011-7c6c4d0a0000 pid=2637->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=40527251-1a00-0000-1011-7c6c560a0000 pid=2646->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=9992d658-1a00-0000-1011-7c6c6e0a0000 pid=2670->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=0702465c-1a00-0000-1011-7c6c790a0000 pid=2681->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=17d55764-1a00-0000-1011-7c6c940a0000 pid=2708->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=51bd0767-1a00-0000-1011-7c6c9d0a0000 pid=2717->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=715f686c-1a00-0000-1011-7c6cb10a0000 pid=2737->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=c922bd6f-1a00-0000-1011-7c6cbb0a0000 pid=2747->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=fe573574-1a00-0000-1011-7c6cca0a0000 pid=2762->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=a1e0da76-1a00-0000-1011-7c6cd00a0000 pid=2768->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=be512680-1a00-0000-1011-7c6ce40a0000 pid=2788->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=09f4ff8f-1a00-0000-1011-7c6c070b0000 pid=2823->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=ef28a996-1a00-0000-1011-7c6c100b0000 pid=2832->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=f5f39299-1a00-0000-1011-7c6c160b0000 pid=2838->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=e181309f-1a00-0000-1011-7c6c230b0000 pid=2851->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=ebcc45a2-1a00-0000-1011-7c6c270b0000 pid=2855->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=283b9daa-1a00-0000-1011-7c6c310b0000 pid=2865->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=369c5baf-1a00-0000-1011-7c6c3f0b0000 pid=2879->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=93e122b7-1a00-0000-1011-7c6c520b0000 pid=2898->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=b7b1ddf7-1a00-0000-1011-7c6cd90b0000 pid=3033->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=e07257fe-1a00-0000-1011-7c6cec0b0000 pid=3052->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 143B guuid=2cd78602-1b00-0000-1011-7c6cf70b0000 pid=3063->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 92B guuid=58018409-1b00-0000-1011-7c6c0b0c0000 pid=3083->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 146B guuid=05d47a19-1b00-0000-1011-7c6c400c0000 pid=3136->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 95B guuid=e4bd451e-1b00-0000-1011-7c6c500c0000 pid=3152->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=23620621-1b00-0000-1011-7c6c580c0000 pid=3160->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B guuid=f050d825-1b00-0000-1011-7c6c690c0000 pid=3177->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 144B guuid=3d677529-1b00-0000-1011-7c6c720c0000 pid=3186->d9db81a5-4229-5ecf-8d47-59af2d1108c6 send: 93B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-12-26 12:32:39 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 12f4fa99abe2864ae54e4ca36fff875b70b048d834dda99d4db3e57101b3f16f

(this sample)

  
Delivery method
Distributed via web download

Comments