MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33b554e0ba3a5c402fe0442d2f98e72d18f5cb9e2c4ead4bfa6d1a0fe9bfb482. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: 33b554e0ba3a5c402fe0442d2f98e72d18f5cb9e2c4ead4bfa6d1a0fe9bfb482
SHA3-384 hash: 15579dedf0a199b913cfe2716f891d09c2b9da84fae0a1d15e19cacbe900dfb4ffe4a747b030b53522284818c2c17b16
SHA1 hash: 74c798eece8ac8486b418db8b57f265fa47236ed
MD5 hash: 127d91b5a6b945bf7f4111745d786e1a
humanhash: pennsylvania-tennessee-eighteen-twelve
File name:Ciabins.sh
Download: download sample
File size:1'730 bytes
First seen:2026-06-21 09:31:48 UTC
Last seen:2026-06-21 16:17:23 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vtgtEtc4ktcbtm9t4tEt0tSJtct0t3WLtOJtVh:vm6y4kabeu66uq6MLinh
TLSH T1593184CA72A309F12DE4ED6B367A884531D1F5CB91D7EFA82CEC34E9419DE44B440A93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.183.232.247/mipsn/an/aelf mips opendir ua-wget
http://94.183.232.247/mipseln/an/aelf mips opendir ua-wget
http://94.183.232.247/sh4ec318ad071cb53d8d91f1bd10ca8f10834b2b9e7e4d5e60979b664eed7ba0711 Gafgytelf gafgyt mirai opendir SuperH ua-wget
http://94.183.232.247/x86c81f71c9987070d131647f840c5c449a7167573f1fb3a02743e304b682a887f2 Miraielf mirai ua-wget
http://94.183.232.247/i686cdf16fe0e568c5307463a4553c5e8e1ec5fce43b9c08841b2821476cbd6cb268 Gafgytelf gafgyt opendir ua-wget x86
http://94.183.232.247/ppcn/an/aelf ua-wget
http://94.183.232.247/i5860b979a71b7eee9cfb5506d00c4031a7a9acda8493b37116eacdbfa7cfc1b9227 Gafgytelf gafgyt opendir ua-wget x86
http://94.183.232.247/m68k4393bd7bad0b4d1283d0db65d2bed45f6a7fa27b8c607cf73bcf8d57079701fc Miraielf m68k mirai opendir ua-wget
http://94.183.232.247/sparcf22272984edd823d419a439912c2bb82b0ff3ae67604430da5d80219095d0173 Gafgytelf gafgyt mirai opendir sparc ua-wget
http://94.183.232.247/arm47e8b4ec162aa621799c1d9d96783dba6a8c91966a167e209061a267a2ac7667 Miraielf ua-wget
http://94.183.232.247/arm4n/an/aelf ua-wget
http://94.183.232.247/arm58d09251c40eaeddfcaf637ff7ab2781bbd37734eeee6a45ceea6ecb0490bdcc8 Miraielf ua-wget
http://94.183.232.247/arm624911afd5f8561c5e7af01bf8ef9fd3d0b81e40029d748a348c1e5d296264fa9 Miraielf ua-wget
http://94.183.232.247/arm73887673e2132c610c6d8c9aa00abf5dc05a123752f58785efe16226d3f8b607a Miraielf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
89
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-21T06:36:00Z UTC
Last seen:
2026-06-21T06:36:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=5c10d079-1900-0000-116c-18892d140000 pid=5165 /usr/bin/sudo guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166 /tmp/sample.bin guuid=5c10d079-1900-0000-116c-18892d140000 pid=5165->guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166 execve guuid=53931d7d-1900-0000-116c-18892f140000 pid=5167 /usr/bin/wget net send-data write-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=53931d7d-1900-0000-116c-18892f140000 pid=5167 execve guuid=c19404db-1900-0000-116c-188937140000 pid=5175 /usr/bin/chmod guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=c19404db-1900-0000-116c-188937140000 pid=5175 execve guuid=099ea0db-1900-0000-116c-188938140000 pid=5176 /usr/bin/bash guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=099ea0db-1900-0000-116c-188938140000 pid=5176 clone guuid=50b401dd-1900-0000-116c-18893a140000 pid=5178 /usr/bin/rm delete-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=50b401dd-1900-0000-116c-18893a140000 pid=5178 execve guuid=18c57cdd-1900-0000-116c-18893b140000 pid=5179 /usr/bin/wget net send-data guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=18c57cdd-1900-0000-116c-18893b140000 pid=5179 execve guuid=b7a3bded-1900-0000-116c-18893c140000 pid=5180 /usr/bin/chmod guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=b7a3bded-1900-0000-116c-18893c140000 pid=5180 execve guuid=f924c0ee-1900-0000-116c-18893d140000 pid=5181 /usr/bin/bash guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=f924c0ee-1900-0000-116c-18893d140000 pid=5181 clone guuid=d39a24ef-1900-0000-116c-18893e140000 pid=5182 /usr/bin/rm guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=d39a24ef-1900-0000-116c-18893e140000 pid=5182 execve guuid=e6b9b0ef-1900-0000-116c-18893f140000 pid=5183 /usr/bin/wget net send-data write-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=e6b9b0ef-1900-0000-116c-18893f140000 pid=5183 execve guuid=b1c8930d-1a00-0000-116c-188940140000 pid=5184 /usr/bin/chmod guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=b1c8930d-1a00-0000-116c-188940140000 pid=5184 execve guuid=2e83e70f-1a00-0000-116c-188941140000 pid=5185 /usr/bin/bash guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=2e83e70f-1a00-0000-116c-188941140000 pid=5185 clone guuid=c5e60414-1a00-0000-116c-188943140000 pid=5187 /usr/bin/rm delete-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=c5e60414-1a00-0000-116c-188943140000 pid=5187 execve guuid=d6ed7914-1a00-0000-116c-188944140000 pid=5188 /usr/bin/wget net send-data write-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=d6ed7914-1a00-0000-116c-188944140000 pid=5188 execve guuid=91951d2f-1a00-0000-116c-188945140000 pid=5189 /usr/bin/chmod guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=91951d2f-1a00-0000-116c-188945140000 pid=5189 execve guuid=32079b2f-1a00-0000-116c-188946140000 pid=5190 /tmp/x86 delete-file guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=32079b2f-1a00-0000-116c-188946140000 pid=5190 execve guuid=7904e42f-1a00-0000-116c-188948140000 pid=5192 /usr/bin/rm guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=7904e42f-1a00-0000-116c-188948140000 pid=5192 execve guuid=ab6b1931-1a00-0000-116c-18894b140000 pid=5195 /usr/bin/wget guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=ab6b1931-1a00-0000-116c-18894b140000 pid=5195 execve guuid=c3c50e38-1a00-0000-116c-18894d140000 pid=5197 /usr/bin/chmod guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=c3c50e38-1a00-0000-116c-18894d140000 pid=5197 execve guuid=476f2b39-1a00-0000-116c-18894e140000 pid=5198 /usr/bin/bash guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=476f2b39-1a00-0000-116c-18894e140000 pid=5198 clone guuid=97766239-1a00-0000-116c-18894f140000 pid=5199 /usr/bin/rm guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=97766239-1a00-0000-116c-18894f140000 pid=5199 execve guuid=a204e439-1a00-0000-116c-188950140000 pid=5200 /usr/bin/wget net send-data guuid=3d65aa7c-1900-0000-116c-18892e140000 pid=5166->guuid=a204e439-1a00-0000-116c-188950140000 pid=5200 execve 3c08363b-4c05-5247-9298-7388a6812181 94.183.232.247:80 guuid=53931d7d-1900-0000-116c-18892f140000 pid=5167->3c08363b-4c05-5247-9298-7388a6812181 send: 133B guuid=18c57cdd-1900-0000-116c-18893b140000 pid=5179->3c08363b-4c05-5247-9298-7388a6812181 send: 135B guuid=e6b9b0ef-1900-0000-116c-18893f140000 pid=5183->3c08363b-4c05-5247-9298-7388a6812181 send: 132B guuid=d6ed7914-1a00-0000-116c-188944140000 pid=5188->3c08363b-4c05-5247-9298-7388a6812181 send: 132B guuid=7a9acd2f-1a00-0000-116c-188947140000 pid=5191 /tmp/x86 net send-data zombie guuid=32079b2f-1a00-0000-116c-188946140000 pid=5190->guuid=7a9acd2f-1a00-0000-116c-188947140000 pid=5191 clone e1c887fd-1961-535f-9110-bd7ab05216ae 185.31.200.8:50289 guuid=7a9acd2f-1a00-0000-116c-188947140000 pid=5191->e1c887fd-1961-535f-9110-bd7ab05216ae send: 124B guuid=c3f0e230-1a00-0000-116c-188949140000 pid=5193 /tmp/x86 guuid=7a9acd2f-1a00-0000-116c-188947140000 pid=5191->guuid=c3f0e230-1a00-0000-116c-188949140000 pid=5193 clone guuid=1588eb30-1a00-0000-116c-18894a140000 pid=5194 /tmp/x86 guuid=7a9acd2f-1a00-0000-116c-188947140000 pid=5191->guuid=1588eb30-1a00-0000-116c-18894a140000 pid=5194 clone guuid=2a328f37-1a00-0000-116c-18894c140000 pid=5196 /tmp/x86 guuid=1588eb30-1a00-0000-116c-18894a140000 pid=5194->guuid=2a328f37-1a00-0000-116c-18894c140000 pid=5196 clone guuid=a204e439-1a00-0000-116c-188950140000 pid=5200->3c08363b-4c05-5247-9298-7388a6812181 send: 132B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-06-21 09:32:56 UTC
File Type:
Text (Shell)
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 33b554e0ba3a5c402fe0442d2f98e72d18f5cb9e2c4ead4bfa6d1a0fe9bfb482

(this sample)

  
Delivery method
Distributed via web download

Comments