MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ba2d7b26a77e78af1d1c8526ffd7b0959fd85e4d9f3efa70a7220130edd37e5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 1ba2d7b26a77e78af1d1c8526ffd7b0959fd85e4d9f3efa70a7220130edd37e5
SHA3-384 hash: 8a39b98c34008b32fd3c1849aa8932cd05f08ca8e3f8147f4b69c7d407396516f92ba00fb36520798869b5c5be637713
SHA1 hash: 6d59c3d7605585c31dec1f6d8bd7af3e3b4f8001
MD5 hash: 8b92a460868e7d6abd1b58be7e42a480
humanhash: paris-harry-oregon-florida
File name:bin.sh
Download: download sample
Signature Mirai
File size:1'763 bytes
First seen:2026-02-01 07:47:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vDUFpbiUPZ3zKWUf8AUQUhxbUS7s8UwU5UPUn:vDUFpmUP9zKWUf8AUQU/US7s8UwU5U8n
TLSH T139317BCA12D155B1BC7259D77AF40D4772C4905A9DE72B069DF839E88C9EF083D88682
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://82.165.181.201/bins/bin.x86n/an/aelf ua-wget
http://82.165.181.201/bins/bin.mipsn/an/aelf ua-wget
http://82.165.181.201/bins/bin.mpsln/an/aelf ua-wget
http://82.165.181.201/bins/bin.arm4n/an/aelf ua-wget
http://82.165.181.201/bins/bin.arm5n/an/aelf ua-wget
http://82.165.181.201/bins/bin.arm6n/an/aelf ua-wget
http://82.165.181.201/bins/bin.arm7n/an/aelf ua-wget
http://82.165.181.201/bins/bin.ppcn/an/aelf ua-wget
http://82.165.181.201/bins/bin.m68kn/an/aelf ua-wget
http://82.165.181.201/bins/bin.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai obfuscated
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-02-01T04:57:00Z UTC
Last seen:
2026-02-01T09:52:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=546108b4-1800-0000-0044-eb7e9f080000 pid=2207 /usr/bin/sudo guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216 /tmp/sample.bin guuid=546108b4-1800-0000-0044-eb7e9f080000 pid=2207->guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216 execve guuid=a5ad46b7-1800-0000-0044-eb7eaa080000 pid=2218 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=a5ad46b7-1800-0000-0044-eb7eaa080000 pid=2218 execve guuid=972a03c8-1800-0000-0044-eb7ed1080000 pid=2257 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=972a03c8-1800-0000-0044-eb7ed1080000 pid=2257 execve guuid=422bcfe8-1800-0000-0044-eb7ef7080000 pid=2295 /usr/bin/cat guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=422bcfe8-1800-0000-0044-eb7ef7080000 pid=2295 execve guuid=9e86b1e9-1800-0000-0044-eb7ef8080000 pid=2296 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=9e86b1e9-1800-0000-0044-eb7ef8080000 pid=2296 execve guuid=fba612ea-1800-0000-0044-eb7ef9080000 pid=2297 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=fba612ea-1800-0000-0044-eb7ef9080000 pid=2297 execve guuid=d0bfb6ea-1800-0000-0044-eb7efe080000 pid=2302 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=d0bfb6ea-1800-0000-0044-eb7efe080000 pid=2302 execve guuid=b88abaf7-1800-0000-0044-eb7e0a090000 pid=2314 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=b88abaf7-1800-0000-0044-eb7e0a090000 pid=2314 execve guuid=123f4805-1900-0000-0044-eb7e23090000 pid=2339 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=123f4805-1900-0000-0044-eb7e23090000 pid=2339 clone guuid=bbe36b05-1900-0000-0044-eb7e24090000 pid=2340 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=bbe36b05-1900-0000-0044-eb7e24090000 pid=2340 execve guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343 execve guuid=6344c930-1a00-0000-0044-eb7e720b0000 pid=2930 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=6344c930-1a00-0000-0044-eb7e720b0000 pid=2930 execve guuid=d037053d-1a00-0000-0044-eb7e800b0000 pid=2944 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=d037053d-1a00-0000-0044-eb7e800b0000 pid=2944 execve guuid=67d62a4b-1a00-0000-0044-eb7e990b0000 pid=2969 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=67d62a4b-1a00-0000-0044-eb7e990b0000 pid=2969 clone guuid=2ecd504b-1a00-0000-0044-eb7e9a0b0000 pid=2970 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=2ecd504b-1a00-0000-0044-eb7e9a0b0000 pid=2970 execve guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972 execve guuid=44f4d076-1b00-0000-0044-eb7eb90d0000 pid=3513 /usr/bin/wget net send-data guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=44f4d076-1b00-0000-0044-eb7eb90d0000 pid=3513 execve guuid=0065e67b-1b00-0000-0044-eb7ec70d0000 pid=3527 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=0065e67b-1b00-0000-0044-eb7ec70d0000 pid=3527 execve guuid=e5561783-1b00-0000-0044-eb7ed00d0000 pid=3536 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=e5561783-1b00-0000-0044-eb7ed00d0000 pid=3536 clone guuid=11324683-1b00-0000-0044-eb7ed10d0000 pid=3537 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=11324683-1b00-0000-0044-eb7ed10d0000 pid=3537 execve guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539 execve guuid=2b0b92af-1c00-0000-0044-eb7ea9110000 pid=4521 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=2b0b92af-1c00-0000-0044-eb7ea9110000 pid=4521 execve guuid=48800fbf-1c00-0000-0044-eb7ed2110000 pid=4562 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=48800fbf-1c00-0000-0044-eb7ed2110000 pid=4562 execve guuid=7f29a4cc-1c00-0000-0044-eb7e08120000 pid=4616 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=7f29a4cc-1c00-0000-0044-eb7e08120000 pid=4616 clone guuid=3119cdcc-1c00-0000-0044-eb7e09120000 pid=4617 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=3119cdcc-1c00-0000-0044-eb7e09120000 pid=4617 execve guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621 execve guuid=d9d52afa-1d00-0000-0044-eb7e92140000 pid=5266 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=d9d52afa-1d00-0000-0044-eb7e92140000 pid=5266 execve guuid=46222d06-1e00-0000-0044-eb7e94140000 pid=5268 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=46222d06-1e00-0000-0044-eb7e94140000 pid=5268 execve guuid=17634814-1e00-0000-0044-eb7e95140000 pid=5269 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=17634814-1e00-0000-0044-eb7e95140000 pid=5269 clone guuid=f5ee7d14-1e00-0000-0044-eb7e96140000 pid=5270 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=f5ee7d14-1e00-0000-0044-eb7e96140000 pid=5270 execve guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271 execve guuid=bcc08840-1f00-0000-0044-eb7ea1140000 pid=5281 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=bcc08840-1f00-0000-0044-eb7ea1140000 pid=5281 execve guuid=bf83a44d-1f00-0000-0044-eb7ea4140000 pid=5284 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=bf83a44d-1f00-0000-0044-eb7ea4140000 pid=5284 execve guuid=c4ead05a-1f00-0000-0044-eb7ea5140000 pid=5285 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=c4ead05a-1f00-0000-0044-eb7ea5140000 pid=5285 clone guuid=d7b8035b-1f00-0000-0044-eb7ea6140000 pid=5286 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=d7b8035b-1f00-0000-0044-eb7ea6140000 pid=5286 execve guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287 execve guuid=ee2aba88-2000-0000-0044-eb7ecc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=ee2aba88-2000-0000-0044-eb7ecc140000 pid=5324 execve guuid=3e0c4394-2000-0000-0044-eb7ecd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=3e0c4394-2000-0000-0044-eb7ecd140000 pid=5325 execve guuid=c645bba3-2000-0000-0044-eb7ece140000 pid=5326 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=c645bba3-2000-0000-0044-eb7ece140000 pid=5326 clone guuid=6cc5eaa3-2000-0000-0044-eb7ecf140000 pid=5327 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=6cc5eaa3-2000-0000-0044-eb7ecf140000 pid=5327 execve guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328 execve guuid=b7cdddd0-2100-0000-0044-eb7ed5140000 pid=5333 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=b7cdddd0-2100-0000-0044-eb7ed5140000 pid=5333 execve guuid=756baddd-2100-0000-0044-eb7ed6140000 pid=5334 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=756baddd-2100-0000-0044-eb7ed6140000 pid=5334 execve guuid=457718eb-2100-0000-0044-eb7ed7140000 pid=5335 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=457718eb-2100-0000-0044-eb7ed7140000 pid=5335 clone guuid=dfa650eb-2100-0000-0044-eb7ed8140000 pid=5336 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=dfa650eb-2100-0000-0044-eb7ed8140000 pid=5336 execve guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337 execve guuid=af5ae218-2300-0000-0044-eb7ede140000 pid=5342 /usr/bin/wget net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=af5ae218-2300-0000-0044-eb7ede140000 pid=5342 execve guuid=0764d125-2300-0000-0044-eb7edf140000 pid=5343 /usr/bin/curl net send-data write-file guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=0764d125-2300-0000-0044-eb7edf140000 pid=5343 execve guuid=1ee2d333-2300-0000-0044-eb7ee0140000 pid=5344 /usr/bin/bash guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=1ee2d333-2300-0000-0044-eb7ee0140000 pid=5344 clone guuid=14691034-2300-0000-0044-eb7ee1140000 pid=5345 /usr/bin/chmod guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=14691034-2300-0000-0044-eb7ee1140000 pid=5345 execve guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346 /tmp/SSH net guuid=81c799b6-1800-0000-0044-eb7ea8080000 pid=2216->guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346 execve 887ca154-e197-5b7b-ab60-4bc685c8a0bb 82.165.181.201:80 guuid=a5ad46b7-1800-0000-0044-eb7eaa080000 pid=2218->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 141B guuid=972a03c8-1800-0000-0044-eb7ed1080000 pid=2257->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fba612ea-1800-0000-0044-eb7ef9080000 pid=2297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dff295ea-1800-0000-0044-eb7efa080000 pid=2298 /tmp/SSH guuid=fba612ea-1800-0000-0044-eb7ef9080000 pid=2297->guuid=dff295ea-1800-0000-0044-eb7efa080000 pid=2298 clone guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299 /tmp/SSH dns net send-data zombie guuid=fba612ea-1800-0000-0044-eb7ef9080000 pid=2297->guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299 clone guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B 80668549-c89f-5883-8f50-79c9db044b08 217.32.184.17:23 guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299->80668549-c89f-5883-8f50-79c9db044b08 con guuid=b859b0ea-1800-0000-0044-eb7efc080000 pid=2300 /tmp/SSH guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299->guuid=b859b0ea-1800-0000-0044-eb7efc080000 pid=2300 clone guuid=6e1ab5ea-1800-0000-0044-eb7efd080000 pid=2301 /tmp/SSH guuid=725b9cea-1800-0000-0044-eb7efb080000 pid=2299->guuid=6e1ab5ea-1800-0000-0044-eb7efd080000 pid=2301 clone guuid=d0bfb6ea-1800-0000-0044-eb7efe080000 pid=2302->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=b88abaf7-1800-0000-0044-eb7e0a090000 pid=2314->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b2d8e54b-c731-5e9d-91ce-9be6b900c2bd 0.0.0.0:63841 guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=342fb030-1a00-0000-0044-eb7e700b0000 pid=2928 /tmp/SSH zombie guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343->guuid=342fb030-1a00-0000-0044-eb7e700b0000 pid=2928 clone guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929 /tmp/SSH dns net send-data zombie guuid=0d58cf05-1900-0000-0044-eb7e27090000 pid=2343->guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929 clone guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929->80668549-c89f-5883-8f50-79c9db044b08 con guuid=50b8d630-1a00-0000-0044-eb7e730b0000 pid=2931 /tmp/SSH guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929->guuid=50b8d630-1a00-0000-0044-eb7e730b0000 pid=2931 clone guuid=ea44d930-1a00-0000-0044-eb7e740b0000 pid=2932 /tmp/SSH guuid=0f8db230-1a00-0000-0044-eb7e710b0000 pid=2929->guuid=ea44d930-1a00-0000-0044-eb7e740b0000 pid=2932 clone guuid=6344c930-1a00-0000-0044-eb7e720b0000 pid=2930->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=d037053d-1a00-0000-0044-eb7e800b0000 pid=2944->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=f2aeb776-1b00-0000-0044-eb7eb50d0000 pid=3509 /tmp/SSH zombie guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972->guuid=f2aeb776-1b00-0000-0044-eb7eb50d0000 pid=3509 clone guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510 /tmp/SSH dns net send-data zombie guuid=a359a24b-1a00-0000-0044-eb7e9c0b0000 pid=2972->guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510 clone guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510->80668549-c89f-5883-8f50-79c9db044b08 con guuid=5e2eca76-1b00-0000-0044-eb7eb70d0000 pid=3511 /tmp/SSH guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510->guuid=5e2eca76-1b00-0000-0044-eb7eb70d0000 pid=3511 clone guuid=9124cd76-1b00-0000-0044-eb7eb80d0000 pid=3512 /tmp/SSH guuid=b745be76-1b00-0000-0044-eb7eb60d0000 pid=3510->guuid=9124cd76-1b00-0000-0044-eb7eb80d0000 pid=3512 clone guuid=44f4d076-1b00-0000-0044-eb7eb90d0000 pid=3513->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=0065e67b-1b00-0000-0044-eb7ec70d0000 pid=3527->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=8ea980af-1c00-0000-0044-eb7ea5110000 pid=4517 /tmp/SSH guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539->guuid=8ea980af-1c00-0000-0044-eb7ea5110000 pid=4517 clone guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518 /tmp/SSH dns net send-data zombie guuid=61d0ad83-1b00-0000-0044-eb7ed30d0000 pid=3539->guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518 clone guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518->80668549-c89f-5883-8f50-79c9db044b08 con guuid=c34c8faf-1c00-0000-0044-eb7ea7110000 pid=4519 /tmp/SSH guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518->guuid=c34c8faf-1c00-0000-0044-eb7ea7110000 pid=4519 clone guuid=c6fc91af-1c00-0000-0044-eb7ea8110000 pid=4520 /tmp/SSH guuid=4b5583af-1c00-0000-0044-eb7ea6110000 pid=4518->guuid=c6fc91af-1c00-0000-0044-eb7ea8110000 pid=4520 clone guuid=2b0b92af-1c00-0000-0044-eb7ea9110000 pid=4521->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=48800fbf-1c00-0000-0044-eb7ed2110000 pid=4562->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=ea9c05fa-1d00-0000-0044-eb7e8f140000 pid=5263 /tmp/SSH zombie guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621->guuid=ea9c05fa-1d00-0000-0044-eb7e8f140000 pid=5263 clone guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264 /tmp/SSH dns net send-data zombie guuid=642d13cd-1c00-0000-0044-eb7e0d120000 pid=4621->guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264 clone guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264->80668549-c89f-5883-8f50-79c9db044b08 con guuid=6d5326fa-1d00-0000-0044-eb7e91140000 pid=5265 /tmp/SSH guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264->guuid=6d5326fa-1d00-0000-0044-eb7e91140000 pid=5265 clone guuid=ad0f3ffa-1d00-0000-0044-eb7e93140000 pid=5267 /tmp/SSH guuid=6f5b0dfa-1d00-0000-0044-eb7e90140000 pid=5264->guuid=ad0f3ffa-1d00-0000-0044-eb7e93140000 pid=5267 clone guuid=d9d52afa-1d00-0000-0044-eb7e92140000 pid=5266->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=46222d06-1e00-0000-0044-eb7e94140000 pid=5268->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=1bc47240-1f00-0000-0044-eb7e9f140000 pid=5279 /tmp/SSH guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271->guuid=1bc47240-1f00-0000-0044-eb7e9f140000 pid=5279 clone guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280 /tmp/SSH dns net send-data zombie guuid=67c40d15-1e00-0000-0044-eb7e97140000 pid=5271->guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280 clone guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280->80668549-c89f-5883-8f50-79c9db044b08 con guuid=1b699240-1f00-0000-0044-eb7ea2140000 pid=5282 /tmp/SSH guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280->guuid=1b699240-1f00-0000-0044-eb7ea2140000 pid=5282 clone guuid=88f39540-1f00-0000-0044-eb7ea3140000 pid=5283 /tmp/SSH guuid=2b397740-1f00-0000-0044-eb7ea0140000 pid=5280->guuid=88f39540-1f00-0000-0044-eb7ea3140000 pid=5283 clone guuid=bcc08840-1f00-0000-0044-eb7ea1140000 pid=5281->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=bf83a44d-1f00-0000-0044-eb7ea4140000 pid=5284->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=a70e9f88-2000-0000-0044-eb7ec8140000 pid=5320 /tmp/SSH zombie guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287->guuid=a70e9f88-2000-0000-0044-eb7ec8140000 pid=5320 clone guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321 /tmp/SSH dns net send-data zombie guuid=2064815b-1f00-0000-0044-eb7ea7140000 pid=5287->guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321 clone guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321->80668549-c89f-5883-8f50-79c9db044b08 con guuid=15e4b188-2000-0000-0044-eb7eca140000 pid=5322 /tmp/SSH guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321->guuid=15e4b188-2000-0000-0044-eb7eca140000 pid=5322 clone guuid=c005b588-2000-0000-0044-eb7ecb140000 pid=5323 /tmp/SSH guuid=a48fa288-2000-0000-0044-eb7ec9140000 pid=5321->guuid=c005b588-2000-0000-0044-eb7ecb140000 pid=5323 clone guuid=ee2aba88-2000-0000-0044-eb7ecc140000 pid=5324->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 141B guuid=3e0c4394-2000-0000-0044-eb7ecd140000 pid=5325->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 90B guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=b57ab3d0-2100-0000-0044-eb7ed1140000 pid=5329 /tmp/SSH guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328->guuid=b57ab3d0-2100-0000-0044-eb7ed1140000 pid=5329 clone guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330 /tmp/SSH dns net send-data zombie guuid=8e493fa4-2000-0000-0044-eb7ed0140000 pid=5328->guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330 clone guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330->80668549-c89f-5883-8f50-79c9db044b08 con guuid=8de4d2d0-2100-0000-0044-eb7ed3140000 pid=5331 /tmp/SSH guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330->guuid=8de4d2d0-2100-0000-0044-eb7ed3140000 pid=5331 clone guuid=91ecdbd0-2100-0000-0044-eb7ed4140000 pid=5332 /tmp/SSH guuid=1279bdd0-2100-0000-0044-eb7ed2140000 pid=5330->guuid=91ecdbd0-2100-0000-0044-eb7ed4140000 pid=5332 clone guuid=b7cdddd0-2100-0000-0044-eb7ed5140000 pid=5333->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 142B guuid=756baddd-2100-0000-0044-eb7ed6140000 pid=5334->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 91B guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=75f7b418-2300-0000-0044-eb7eda140000 pid=5338 /tmp/SSH guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337->guuid=75f7b418-2300-0000-0044-eb7eda140000 pid=5338 clone guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339 /tmp/SSH dns net send-data zombie guuid=92e6dceb-2100-0000-0044-eb7ed9140000 pid=5337->guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339 clone guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339->80668549-c89f-5883-8f50-79c9db044b08 con guuid=a7b4da18-2300-0000-0044-eb7edc140000 pid=5340 /tmp/SSH guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339->guuid=a7b4da18-2300-0000-0044-eb7edc140000 pid=5340 clone guuid=789ddf18-2300-0000-0044-eb7edd140000 pid=5341 /tmp/SSH guuid=f383c118-2300-0000-0044-eb7edb140000 pid=5339->guuid=789ddf18-2300-0000-0044-eb7edd140000 pid=5341 clone guuid=af5ae218-2300-0000-0044-eb7ede140000 pid=5342->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 141B guuid=0764d125-2300-0000-0044-eb7edf140000 pid=5343->887ca154-e197-5b7b-ab60-4bc685c8a0bb send: 90B guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346->b2d8e54b-c731-5e9d-91ce-9be6b900c2bd con guuid=7d60ac61-2400-0000-0044-eb7ee3140000 pid=5347 /tmp/SSH zombie guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346->guuid=7d60ac61-2400-0000-0044-eb7ee3140000 pid=5347 clone guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348 /tmp/SSH dns net send-data zombie guuid=63959e34-2300-0000-0044-eb7ee2140000 pid=5346->guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348 clone guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 160B guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348->80668549-c89f-5883-8f50-79c9db044b08 send: 2B guuid=076ac661-2400-0000-0044-eb7ee5140000 pid=5349 /tmp/SSH guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348->guuid=076ac661-2400-0000-0044-eb7ee5140000 pid=5349 clone guuid=272bcc61-2400-0000-0044-eb7ee6140000 pid=5350 /tmp/SSH guuid=8a13b461-2400-0000-0044-eb7ee4140000 pid=5348->guuid=272bcc61-2400-0000-0044-eb7ee6140000 pid=5350 clone
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-02-01 07:35:50 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1ba2d7b26a77e78af1d1c8526ffd7b0959fd85e4d9f3efa70a7220130edd37e5

(this sample)

  
Delivery method
Distributed via web download

Comments