MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2767e8ece559b00a39917ae961fb26116d0e85015ad796850166cf025670f3e9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 2767e8ece559b00a39917ae961fb26116d0e85015ad796850166cf025670f3e9
SHA3-384 hash: ffdbf21f07910aa19247d967f4723ea740761e1cb2afb517599af8acdcd02d913ee41bc59f0c12bc54b506f92bfd4c21
SHA1 hash: 60644ebc0207ff7178347a7e938236ca1b4eb9ad
MD5 hash: 703e98d86baafe1c39780bdfec5478ca
humanhash: fanta-music-lima-music
File name:jewn.sh
Download: download sample
Signature Mirai
File size:1'763 bytes
First seen:2025-11-10 18:25:54 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vnVonWqnOqYnNbknsEBn3Enu2nIsnpgnUH:viByCP0pVmG
TLSH T11D31BCC9096500BA6CA36B7BF2B41D1C35D8AE9556CAAFE6D3DC38B8408CEC5B071643
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.163.118.111/trc/TRC.x869197a85c5180866d5f4bdff9ce443e20976f814e88a57db498d694ed6130f1c1 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.mips58a0697ace786bada774996adec154a736fbcc23034c78de67c4188348fc3b17 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.mpsl4c5d3fc2facde344db1304361e6b51311f9f82c57e7ca7a2ce57c9e1819d8058 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.arm4n/an/aelf ua-wget
http://103.163.118.111/trc/TRC.arm501ad4495cbbb79b950027c5530d5b2464d89d64fcb6bd442056b9dbdba68da12 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.arm618072699656453a0d16873793d436a0671b4ca543370b0a537acbcce57630002 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.arm79368bfad1522138480ea08813c64c06ee392e0fb90c2dafcf5b20d8c61c349f7 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.ppce2d41fb6c3ceb3340dea8706e9d706d826af2c8952b04acbf1c261b617d130f1 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.m68k61ffa89b2eac0463377408ca3fbad67e1f05bb4dc34c47a701dae43eea5390f4 Miraielf mirai opendir
http://103.163.118.111/trc/TRC.sh43f1d9a9c9db6985f68fd172a3a1aee1ae15dac7d8d64cebc221386774b1ba86c Miraielf mirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
89
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-10T15:37:00Z UTC
Last seen:
2025-11-11T01:22:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=9cabaeed-1600-0000-aea8-2a69920e0000 pid=3730 /usr/bin/sudo guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739 /tmp/sample.bin guuid=9cabaeed-1600-0000-aea8-2a69920e0000 pid=3730->guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739 execve guuid=ab3769f0-1600-0000-aea8-2a699e0e0000 pid=3742 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=ab3769f0-1600-0000-aea8-2a699e0e0000 pid=3742 execve guuid=3ad62920-1700-0000-aea8-2a69380f0000 pid=3896 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=3ad62920-1700-0000-aea8-2a69380f0000 pid=3896 execve guuid=b8bcb45f-1700-0000-aea8-2a69d90f0000 pid=4057 /usr/bin/cat guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=b8bcb45f-1700-0000-aea8-2a69d90f0000 pid=4057 execve guuid=d5113c60-1700-0000-aea8-2a69dc0f0000 pid=4060 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=d5113c60-1700-0000-aea8-2a69dc0f0000 pid=4060 execve guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063 execve guuid=194d2761-1700-0000-aea8-2a69e30f0000 pid=4067 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=194d2761-1700-0000-aea8-2a69e30f0000 pid=4067 execve guuid=4283149b-1700-0000-aea8-2a6977100000 pid=4215 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=4283149b-1700-0000-aea8-2a6977100000 pid=4215 execve guuid=ed174cea-1700-0000-aea8-2a6948110000 pid=4424 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=ed174cea-1700-0000-aea8-2a6948110000 pid=4424 clone guuid=6a8278ea-1700-0000-aea8-2a694c110000 pid=4428 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=6a8278ea-1700-0000-aea8-2a694c110000 pid=4428 execve guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429 execve guuid=ecab55eb-1700-0000-aea8-2a6954110000 pid=4436 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=ecab55eb-1700-0000-aea8-2a6954110000 pid=4436 execve guuid=d6520e25-1800-0000-aea8-2a69f1110000 pid=4593 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=d6520e25-1800-0000-aea8-2a69f1110000 pid=4593 execve guuid=a6819c6e-1800-0000-aea8-2a6965120000 pid=4709 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=a6819c6e-1800-0000-aea8-2a6965120000 pid=4709 clone guuid=3404de6e-1800-0000-aea8-2a6966120000 pid=4710 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=3404de6e-1800-0000-aea8-2a6966120000 pid=4710 execve guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711 execve guuid=3fe33470-1800-0000-aea8-2a696b120000 pid=4715 /usr/bin/wget net send-data guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=3fe33470-1800-0000-aea8-2a696b120000 pid=4715 execve guuid=d810258d-1800-0000-aea8-2a69ba120000 pid=4794 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=d810258d-1800-0000-aea8-2a69ba120000 pid=4794 execve guuid=659718bd-1800-0000-aea8-2a69a2130000 pid=5026 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=659718bd-1800-0000-aea8-2a69a2130000 pid=5026 clone guuid=502041bd-1800-0000-aea8-2a69a4130000 pid=5028 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=502041bd-1800-0000-aea8-2a69a4130000 pid=5028 execve guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030 execve guuid=16f40ebe-1800-0000-aea8-2a69ac130000 pid=5036 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=16f40ebe-1800-0000-aea8-2a69ac130000 pid=5036 execve guuid=51f99ce8-1800-0000-aea8-2a6982140000 pid=5250 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=51f99ce8-1800-0000-aea8-2a6982140000 pid=5250 execve guuid=ee08db19-1900-0000-aea8-2a698f140000 pid=5263 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=ee08db19-1900-0000-aea8-2a698f140000 pid=5263 clone guuid=9e3a761a-1900-0000-aea8-2a6990140000 pid=5264 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=9e3a761a-1900-0000-aea8-2a6990140000 pid=5264 execve guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265 execve guuid=be98bc1b-1900-0000-aea8-2a6995140000 pid=5269 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=be98bc1b-1900-0000-aea8-2a6995140000 pid=5269 execve guuid=e0c1b76c-1900-0000-aea8-2a6998140000 pid=5272 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=e0c1b76c-1900-0000-aea8-2a6998140000 pid=5272 execve guuid=46e42aaa-1900-0000-aea8-2a6999140000 pid=5273 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=46e42aaa-1900-0000-aea8-2a6999140000 pid=5273 clone guuid=6127d9aa-1900-0000-aea8-2a699a140000 pid=5274 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=6127d9aa-1900-0000-aea8-2a699a140000 pid=5274 execve guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275 execve guuid=96afefac-1900-0000-aea8-2a699f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=96afefac-1900-0000-aea8-2a699f140000 pid=5279 execve guuid=5ee8ccf9-1900-0000-aea8-2a69ad140000 pid=5293 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=5ee8ccf9-1900-0000-aea8-2a69ad140000 pid=5293 execve guuid=161db669-1a00-0000-aea8-2a69ae140000 pid=5294 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=161db669-1a00-0000-aea8-2a69ae140000 pid=5294 clone guuid=3ddb096b-1a00-0000-aea8-2a69af140000 pid=5295 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=3ddb096b-1a00-0000-aea8-2a69af140000 pid=5295 execve guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296 execve guuid=d8551f6d-1a00-0000-aea8-2a69b4140000 pid=5300 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=d8551f6d-1a00-0000-aea8-2a69b4140000 pid=5300 execve guuid=4b7e64aa-1a00-0000-aea8-2a69b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=4b7e64aa-1a00-0000-aea8-2a69b7140000 pid=5303 execve guuid=891eb5f8-1a00-0000-aea8-2a69b8140000 pid=5304 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=891eb5f8-1a00-0000-aea8-2a69b8140000 pid=5304 clone guuid=199af0f8-1a00-0000-aea8-2a69b9140000 pid=5305 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=199af0f8-1a00-0000-aea8-2a69b9140000 pid=5305 execve guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306 execve guuid=e1230efd-1a00-0000-aea8-2a69be140000 pid=5310 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=e1230efd-1a00-0000-aea8-2a69be140000 pid=5310 execve guuid=b7e4053a-1b00-0000-aea8-2a69cf140000 pid=5327 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=b7e4053a-1b00-0000-aea8-2a69cf140000 pid=5327 execve guuid=8a06ee79-1b00-0000-aea8-2a69e2140000 pid=5346 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=8a06ee79-1b00-0000-aea8-2a69e2140000 pid=5346 clone guuid=190ae07a-1b00-0000-aea8-2a69e3140000 pid=5347 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=190ae07a-1b00-0000-aea8-2a69e3140000 pid=5347 execve guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348 execve guuid=ccd9a67d-1b00-0000-aea8-2a69e8140000 pid=5352 /usr/bin/wget net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=ccd9a67d-1b00-0000-aea8-2a69e8140000 pid=5352 execve guuid=a103f1b9-1b00-0000-aea8-2a69eb140000 pid=5355 /usr/bin/curl net send-data write-file guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=a103f1b9-1b00-0000-aea8-2a69eb140000 pid=5355 execve guuid=dcc4cbe8-1b00-0000-aea8-2a69ec140000 pid=5356 /usr/bin/bash guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=dcc4cbe8-1b00-0000-aea8-2a69ec140000 pid=5356 clone guuid=b80ebbe9-1b00-0000-aea8-2a69ed140000 pid=5357 /usr/bin/chmod guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=b80ebbe9-1b00-0000-aea8-2a69ed140000 pid=5357 execve guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358 /tmp/igz net guuid=3fa4f3ef-1600-0000-aea8-2a699b0e0000 pid=3739->guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358 execve 4dc8f021-65f9-592d-ba70-ad0bb944acca 103.163.118.111:80 guuid=ab3769f0-1600-0000-aea8-2a699e0e0000 pid=3742->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 141B guuid=3ad62920-1700-0000-aea8-2a69380f0000 pid=3896->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e37ffb60-1700-0000-aea8-2a69e00f0000 pid=4064 /tmp/igz zombie guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063->guuid=e37ffb60-1700-0000-aea8-2a69e00f0000 pid=4064 clone guuid=99ed0361-1700-0000-aea8-2a69e10f0000 pid=4065 /tmp/igz guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063->guuid=99ed0361-1700-0000-aea8-2a69e10f0000 pid=4065 clone guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066 /tmp/igz net send-data zombie guuid=f061c560-1700-0000-aea8-2a69df0f0000 pid=4063->guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066 clone guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 40846cfc-4e67-58bb-a7b6-ae1da521127d 103.163.118.111:13 guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=02812e61-1700-0000-aea8-2a69e40f0000 pid=4068 /tmp/igz guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066->guuid=02812e61-1700-0000-aea8-2a69e40f0000 pid=4068 clone guuid=f2d25861-1700-0000-aea8-2a69e50f0000 pid=4069 /tmp/igz guuid=bc4a1461-1700-0000-aea8-2a69e20f0000 pid=4066->guuid=f2d25861-1700-0000-aea8-2a69e50f0000 pid=4069 clone guuid=194d2761-1700-0000-aea8-2a69e30f0000 pid=4067->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=4283149b-1700-0000-aea8-2a6977100000 pid=4215->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dc9d1eeb-1700-0000-aea8-2a694e110000 pid=4430 /tmp/igz zombie guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429->guuid=dc9d1eeb-1700-0000-aea8-2a694e110000 pid=4430 clone guuid=3a9b24eb-1700-0000-aea8-2a694f110000 pid=4431 /tmp/igz guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429->guuid=3a9b24eb-1700-0000-aea8-2a694f110000 pid=4431 clone guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432 /tmp/igz net send-data zombie guuid=b607e0ea-1700-0000-aea8-2a694d110000 pid=4429->guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432 clone guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=ee6a45eb-1700-0000-aea8-2a6951110000 pid=4433 /tmp/igz guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432->guuid=ee6a45eb-1700-0000-aea8-2a6951110000 pid=4433 clone guuid=b0e44ceb-1700-0000-aea8-2a6953110000 pid=4435 /tmp/igz guuid=af1434eb-1700-0000-aea8-2a6950110000 pid=4432->guuid=b0e44ceb-1700-0000-aea8-2a6953110000 pid=4435 clone guuid=ecab55eb-1700-0000-aea8-2a6954110000 pid=4436->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=d6520e25-1800-0000-aea8-2a69f1110000 pid=4593->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cb4bff6f-1800-0000-aea8-2a6968120000 pid=4712 /tmp/igz guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711->guuid=cb4bff6f-1800-0000-aea8-2a6968120000 pid=4712 clone guuid=83ce0870-1800-0000-aea8-2a6969120000 pid=4713 /tmp/igz guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711->guuid=83ce0870-1800-0000-aea8-2a6969120000 pid=4713 clone guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714 /tmp/igz net send-data zombie guuid=2811c66f-1800-0000-aea8-2a6967120000 pid=4711->guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714 clone guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=5d6c4070-1800-0000-aea8-2a696c120000 pid=4716 /tmp/igz guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714->guuid=5d6c4070-1800-0000-aea8-2a696c120000 pid=4716 clone guuid=00ec4770-1800-0000-aea8-2a696d120000 pid=4717 /tmp/igz guuid=d3f31170-1800-0000-aea8-2a696a120000 pid=4714->guuid=00ec4770-1800-0000-aea8-2a696d120000 pid=4717 clone guuid=3fe33470-1800-0000-aea8-2a696b120000 pid=4715->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=d810258d-1800-0000-aea8-2a69ba120000 pid=4794->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=527dd0bd-1800-0000-aea8-2a69a8130000 pid=5032 /tmp/igz guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030->guuid=527dd0bd-1800-0000-aea8-2a69a8130000 pid=5032 clone guuid=4b6bdebd-1800-0000-aea8-2a69a9130000 pid=5033 /tmp/igz guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030->guuid=4b6bdebd-1800-0000-aea8-2a69a9130000 pid=5033 clone guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034 /tmp/igz net send-data zombie guuid=bc649abd-1800-0000-aea8-2a69a6130000 pid=5030->guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034 clone guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=fa010cbf-1800-0000-aea8-2a69b0130000 pid=5040 /tmp/igz guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034->guuid=fa010cbf-1800-0000-aea8-2a69b0130000 pid=5040 clone guuid=cbb00fbf-1800-0000-aea8-2a69b1130000 pid=5041 /tmp/igz guuid=f1b0e6bd-1800-0000-aea8-2a69aa130000 pid=5034->guuid=cbb00fbf-1800-0000-aea8-2a69b1130000 pid=5041 clone guuid=16f40ebe-1800-0000-aea8-2a69ac130000 pid=5036->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=51f99ce8-1800-0000-aea8-2a6982140000 pid=5250->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6f65aa1b-1900-0000-aea8-2a6992140000 pid=5266 /tmp/igz zombie guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265->guuid=6f65aa1b-1900-0000-aea8-2a6992140000 pid=5266 clone guuid=6089af1b-1900-0000-aea8-2a6993140000 pid=5267 /tmp/igz guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265->guuid=6089af1b-1900-0000-aea8-2a6993140000 pid=5267 clone guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268 /tmp/igz net send-data zombie guuid=75e31a1b-1900-0000-aea8-2a6991140000 pid=5265->guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268 clone guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=e95b6e1c-1900-0000-aea8-2a6996140000 pid=5270 /tmp/igz guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268->guuid=e95b6e1c-1900-0000-aea8-2a6996140000 pid=5270 clone guuid=e4b1711c-1900-0000-aea8-2a6997140000 pid=5271 /tmp/igz guuid=975ab31b-1900-0000-aea8-2a6994140000 pid=5268->guuid=e4b1711c-1900-0000-aea8-2a6997140000 pid=5271 clone guuid=be98bc1b-1900-0000-aea8-2a6995140000 pid=5269->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=e0c1b76c-1900-0000-aea8-2a6998140000 pid=5272->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=91afd9ac-1900-0000-aea8-2a699c140000 pid=5276 /tmp/igz zombie guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275->guuid=91afd9ac-1900-0000-aea8-2a699c140000 pid=5276 clone guuid=301adfac-1900-0000-aea8-2a699d140000 pid=5277 /tmp/igz guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275->guuid=301adfac-1900-0000-aea8-2a699d140000 pid=5277 clone guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278 /tmp/igz net send-data zombie guuid=c92920ac-1900-0000-aea8-2a699b140000 pid=5275->guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278 clone guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=a834f2ad-1900-0000-aea8-2a69a0140000 pid=5280 /tmp/igz guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278->guuid=a834f2ad-1900-0000-aea8-2a69a0140000 pid=5280 clone guuid=ac09f8ad-1900-0000-aea8-2a69a1140000 pid=5281 /tmp/igz guuid=a72ee3ac-1900-0000-aea8-2a699e140000 pid=5278->guuid=ac09f8ad-1900-0000-aea8-2a69a1140000 pid=5281 clone guuid=96afefac-1900-0000-aea8-2a699f140000 pid=5279->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=5ee8ccf9-1900-0000-aea8-2a69ad140000 pid=5293->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=838f096d-1a00-0000-aea8-2a69b1140000 pid=5297 /tmp/igz zombie guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296->guuid=838f096d-1a00-0000-aea8-2a69b1140000 pid=5297 clone guuid=d6030f6d-1a00-0000-aea8-2a69b2140000 pid=5298 /tmp/igz guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296->guuid=d6030f6d-1a00-0000-aea8-2a69b2140000 pid=5298 clone guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299 /tmp/igz net send-data zombie guuid=aff70a6c-1a00-0000-aea8-2a69b0140000 pid=5296->guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299 clone guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=438d396f-1a00-0000-aea8-2a69b5140000 pid=5301 /tmp/igz guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299->guuid=438d396f-1a00-0000-aea8-2a69b5140000 pid=5301 clone guuid=4b6f3f6f-1a00-0000-aea8-2a69b6140000 pid=5302 /tmp/igz guuid=e7c2126d-1a00-0000-aea8-2a69b3140000 pid=5299->guuid=4b6f3f6f-1a00-0000-aea8-2a69b6140000 pid=5302 clone guuid=d8551f6d-1a00-0000-aea8-2a69b4140000 pid=5300->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 141B guuid=4b7e64aa-1a00-0000-aea8-2a69b7140000 pid=5303->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 90B guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3933fffc-1a00-0000-aea8-2a69bb140000 pid=5307 /tmp/igz zombie guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306->guuid=3933fffc-1a00-0000-aea8-2a69bb140000 pid=5307 clone guuid=4d1c02fd-1a00-0000-aea8-2a69bc140000 pid=5308 /tmp/igz guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306->guuid=4d1c02fd-1a00-0000-aea8-2a69bc140000 pid=5308 clone guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309 /tmp/igz net send-data zombie guuid=400d4cfa-1a00-0000-aea8-2a69ba140000 pid=5306->guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309 clone guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=02b9dffd-1a00-0000-aea8-2a69bf140000 pid=5311 /tmp/igz guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309->guuid=02b9dffd-1a00-0000-aea8-2a69bf140000 pid=5311 clone guuid=f019e5fd-1a00-0000-aea8-2a69c0140000 pid=5312 /tmp/igz guuid=033d05fd-1a00-0000-aea8-2a69bd140000 pid=5309->guuid=f019e5fd-1a00-0000-aea8-2a69c0140000 pid=5312 clone guuid=e1230efd-1a00-0000-aea8-2a69be140000 pid=5310->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 142B guuid=b7e4053a-1b00-0000-aea8-2a69cf140000 pid=5327->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 91B guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9b24957d-1b00-0000-aea8-2a69e5140000 pid=5349 /tmp/igz zombie guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348->guuid=9b24957d-1b00-0000-aea8-2a69e5140000 pid=5349 clone guuid=3595997d-1b00-0000-aea8-2a69e6140000 pid=5350 /tmp/igz guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348->guuid=3595997d-1b00-0000-aea8-2a69e6140000 pid=5350 clone guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351 /tmp/igz net send-data zombie guuid=a825397c-1b00-0000-aea8-2a69e4140000 pid=5348->guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351 clone guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 12B guuid=55f9db7e-1b00-0000-aea8-2a69e9140000 pid=5353 /tmp/igz guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351->guuid=55f9db7e-1b00-0000-aea8-2a69e9140000 pid=5353 clone guuid=f518e07e-1b00-0000-aea8-2a69ea140000 pid=5354 /tmp/igz guuid=70379d7d-1b00-0000-aea8-2a69e7140000 pid=5351->guuid=f518e07e-1b00-0000-aea8-2a69ea140000 pid=5354 clone guuid=ccd9a67d-1b00-0000-aea8-2a69e8140000 pid=5352->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 141B guuid=a103f1b9-1b00-0000-aea8-2a69eb140000 pid=5355->4dc8f021-65f9-592d-ba70-ad0bb944acca send: 90B guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e126cec-1b00-0000-aea8-2a69ef140000 pid=5359 /tmp/igz zombie guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358->guuid=1e126cec-1b00-0000-aea8-2a69ef140000 pid=5359 clone guuid=d4e170ec-1b00-0000-aea8-2a69f0140000 pid=5360 /tmp/igz guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358->guuid=d4e170ec-1b00-0000-aea8-2a69f0140000 pid=5360 clone guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361 /tmp/igz net send-data zombie guuid=9e114aeb-1b00-0000-aea8-2a69ee140000 pid=5358->guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361 clone guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361->40846cfc-4e67-58bb-a7b6-ae1da521127d send: 7B guuid=788abaed-1b00-0000-aea8-2a69f2140000 pid=5362 /tmp/igz guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361->guuid=788abaed-1b00-0000-aea8-2a69f2140000 pid=5362 clone guuid=4df6bded-1b00-0000-aea8-2a69f3140000 pid=5363 /tmp/igz guuid=bfad75ec-1b00-0000-aea8-2a69f1140000 pid=5361->guuid=4df6bded-1b00-0000-aea8-2a69f3140000 pid=5363 clone
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-11-10 16:17:55 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2767e8ece559b00a39917ae961fb26116d0e85015ad796850166cf025670f3e9

(this sample)

  
Delivery method
Distributed via web download

Comments