MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7dca536f80d61bfb182eebc0d9e17e3723194b2a472cb60c8cc2c0a119d4a2c5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 3 File information Comments

SHA256 hash: 7dca536f80d61bfb182eebc0d9e17e3723194b2a472cb60c8cc2c0a119d4a2c5
SHA3-384 hash: 527e1bae879d40760ebc182156aef2138740fc5e5f13403be3c41f8fdb6d2bd6fe03693180b9ddc9e629ef81757fbe4b
SHA1 hash: 1eacb4d51287ff8f33acf6cf820dcb8f938fd441
MD5 hash: 999ce814bdbde48e252ef3979d91508e
humanhash: eleven-juliet-mike-maryland
File name:Ciabins.sh
Download: download sample
Signature Mirai
File size:1'970 bytes
First seen:2026-06-07 14:55:27 UTC
Last seen:2026-06-08 12:51:12 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vtwtkt1atItcht+apfUxt7Atkttjg11JtMttU3CGttdUvpLttmhEqJttn76Zc:vmqvaWGhEalUxRA66qjU3CGjdUvpLjmb
TLSH T1FD413ECB61924975BEA0ED6B31AE884D33C4E5E780DFEF6468DC34E4809FE987410697
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.183.232.247/CRY.mipsf188a78202626243c40841543b2f280cf1f183371bfca353eb99f3423a23c18d Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.mipseln/an/aelf opendir ua-wget
http://94.183.232.247/CRY.sh438679f84b82e188affb462c17e50e5b352ca53f469b7424473bfdd0da8afcb6a Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.x86644933ccf018523580c4b45682ae4f58a46ac8b9bebbdf138b908f0eae37bb59 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.i686n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.powerpcn/an/aelf opendir ua-wget
http://94.183.232.247/CRY.i586n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.m68k634ef1d7252b8636cf06f1ae4a800a560a68b0372a40f993764b9cdf62840aa0 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.sparcn/an/aelf opendir ua-wget
http://94.183.232.247/CRY.arc13237d9b0ea5aa0addc244351ce66b7491e2855bd286093571151b3f8d09d789 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm4n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.arm51bf3503333a2fbb50bd4081c2eb468d60682385563190e2fdb4df8adb3e22f21 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm624598637bc80b2454b3a3f6675c495a94772ce8b3280d01aec91de01f783b9bc Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm7872bc0cf636a7d71b04ee7c298f76eac90cf99f86bc62a51f56d1c3c64ed1b0b Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
6
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=f776384a-1700-0000-65c4-e5809e0d0000 pid=3486 /usr/bin/sudo guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487 /tmp/sample.bin guuid=f776384a-1700-0000-65c4-e5809e0d0000 pid=3486->guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487 execve guuid=af9dad4c-1700-0000-65c4-e580a00d0000 pid=3488 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=af9dad4c-1700-0000-65c4-e580a00d0000 pid=3488 execve guuid=17684e76-1700-0000-65c4-e5800e0e0000 pid=3598 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=17684e76-1700-0000-65c4-e5800e0e0000 pid=3598 execve guuid=38269676-1700-0000-65c4-e580100e0000 pid=3600 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=38269676-1700-0000-65c4-e580100e0000 pid=3600 clone guuid=246d267a-1700-0000-65c4-e580130e0000 pid=3603 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=246d267a-1700-0000-65c4-e580130e0000 pid=3603 execve guuid=308b7a7a-1700-0000-65c4-e580140e0000 pid=3604 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=308b7a7a-1700-0000-65c4-e580140e0000 pid=3604 execve guuid=e8ae2789-1700-0000-65c4-e5804b0e0000 pid=3659 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=e8ae2789-1700-0000-65c4-e5804b0e0000 pid=3659 execve guuid=d9976e89-1700-0000-65c4-e5804d0e0000 pid=3661 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d9976e89-1700-0000-65c4-e5804d0e0000 pid=3661 clone guuid=eb748789-1700-0000-65c4-e5804e0e0000 pid=3662 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=eb748789-1700-0000-65c4-e5804e0e0000 pid=3662 execve guuid=0a52d089-1700-0000-65c4-e580500e0000 pid=3664 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=0a52d089-1700-0000-65c4-e580500e0000 pid=3664 execve guuid=8f76adae-1700-0000-65c4-e580890e0000 pid=3721 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=8f76adae-1700-0000-65c4-e580890e0000 pid=3721 execve guuid=5f0f1caf-1700-0000-65c4-e5808c0e0000 pid=3724 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=5f0f1caf-1700-0000-65c4-e5808c0e0000 pid=3724 clone guuid=d79501b0-1700-0000-65c4-e580900e0000 pid=3728 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d79501b0-1700-0000-65c4-e580900e0000 pid=3728 execve guuid=7b4d7bb0-1700-0000-65c4-e580920e0000 pid=3730 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=7b4d7bb0-1700-0000-65c4-e580920e0000 pid=3730 execve guuid=2206acd6-1700-0000-65c4-e580ef0e0000 pid=3823 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=2206acd6-1700-0000-65c4-e580ef0e0000 pid=3823 execve guuid=c5b56bd7-1700-0000-65c4-e580f40e0000 pid=3828 /tmp/CRY.x86 net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=c5b56bd7-1700-0000-65c4-e580f40e0000 pid=3828 execve guuid=d9c18813-1800-0000-65c4-e580730f0000 pid=3955 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d9c18813-1800-0000-65c4-e580730f0000 pid=3955 execve guuid=c0812c14-1800-0000-65c4-e580750f0000 pid=3957 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=c0812c14-1800-0000-65c4-e580750f0000 pid=3957 execve guuid=14f4fe23-1800-0000-65c4-e580980f0000 pid=3992 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=14f4fe23-1800-0000-65c4-e580980f0000 pid=3992 execve guuid=248b8124-1800-0000-65c4-e5809a0f0000 pid=3994 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=248b8124-1800-0000-65c4-e5809a0f0000 pid=3994 clone guuid=f5d4a824-1800-0000-65c4-e5809b0f0000 pid=3995 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=f5d4a824-1800-0000-65c4-e5809b0f0000 pid=3995 execve guuid=a96a2925-1800-0000-65c4-e5809d0f0000 pid=3997 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=a96a2925-1800-0000-65c4-e5809d0f0000 pid=3997 execve guuid=656b7a34-1800-0000-65c4-e580c40f0000 pid=4036 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=656b7a34-1800-0000-65c4-e580c40f0000 pid=4036 execve guuid=c67c1835-1800-0000-65c4-e580c60f0000 pid=4038 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=c67c1835-1800-0000-65c4-e580c60f0000 pid=4038 clone guuid=d6465435-1800-0000-65c4-e580c80f0000 pid=4040 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d6465435-1800-0000-65c4-e580c80f0000 pid=4040 execve guuid=4b6e1a36-1800-0000-65c4-e580ca0f0000 pid=4042 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=4b6e1a36-1800-0000-65c4-e580ca0f0000 pid=4042 execve guuid=cfe9da45-1800-0000-65c4-e580f10f0000 pid=4081 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=cfe9da45-1800-0000-65c4-e580f10f0000 pid=4081 execve guuid=96e66046-1800-0000-65c4-e580f30f0000 pid=4083 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=96e66046-1800-0000-65c4-e580f30f0000 pid=4083 clone guuid=af7a8346-1800-0000-65c4-e580f40f0000 pid=4084 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=af7a8346-1800-0000-65c4-e580f40f0000 pid=4084 execve guuid=edf6c846-1800-0000-65c4-e580f60f0000 pid=4086 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=edf6c846-1800-0000-65c4-e580f60f0000 pid=4086 execve guuid=233c986d-1800-0000-65c4-e5804c100000 pid=4172 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=233c986d-1800-0000-65c4-e5804c100000 pid=4172 execve guuid=f5d80d6e-1800-0000-65c4-e58050100000 pid=4176 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=f5d80d6e-1800-0000-65c4-e58050100000 pid=4176 clone guuid=4c744a70-1800-0000-65c4-e58055100000 pid=4181 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=4c744a70-1800-0000-65c4-e58055100000 pid=4181 execve guuid=dff7ae70-1800-0000-65c4-e58057100000 pid=4183 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=dff7ae70-1800-0000-65c4-e58057100000 pid=4183 execve guuid=01e21c80-1800-0000-65c4-e58074100000 pid=4212 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=01e21c80-1800-0000-65c4-e58074100000 pid=4212 execve guuid=4e7ea180-1800-0000-65c4-e58078100000 pid=4216 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=4e7ea180-1800-0000-65c4-e58078100000 pid=4216 clone guuid=c218c780-1800-0000-65c4-e58079100000 pid=4217 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=c218c780-1800-0000-65c4-e58079100000 pid=4217 execve guuid=3f2e4181-1800-0000-65c4-e5807d100000 pid=4221 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=3f2e4181-1800-0000-65c4-e5807d100000 pid=4221 execve guuid=af1b75a6-1800-0000-65c4-e580d3100000 pid=4307 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=af1b75a6-1800-0000-65c4-e580d3100000 pid=4307 execve guuid=35e3fea6-1800-0000-65c4-e580d5100000 pid=4309 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=35e3fea6-1800-0000-65c4-e580d5100000 pid=4309 clone guuid=3ee71fa8-1800-0000-65c4-e580d9100000 pid=4313 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=3ee71fa8-1800-0000-65c4-e580d9100000 pid=4313 execve guuid=dea7bba8-1800-0000-65c4-e580db100000 pid=4315 /usr/bin/wget net send-data guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=dea7bba8-1800-0000-65c4-e580db100000 pid=4315 execve guuid=41a7f7b7-1800-0000-65c4-e580fb100000 pid=4347 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=41a7f7b7-1800-0000-65c4-e580fb100000 pid=4347 execve guuid=d5ef77b8-1800-0000-65c4-e580fd100000 pid=4349 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d5ef77b8-1800-0000-65c4-e580fd100000 pid=4349 clone guuid=646da4b8-1800-0000-65c4-e580fe100000 pid=4350 /usr/bin/rm guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=646da4b8-1800-0000-65c4-e580fe100000 pid=4350 execve guuid=972d23b9-1800-0000-65c4-e58000110000 pid=4352 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=972d23b9-1800-0000-65c4-e58000110000 pid=4352 execve guuid=3440c0de-1800-0000-65c4-e58052110000 pid=4434 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=3440c0de-1800-0000-65c4-e58052110000 pid=4434 execve guuid=d0823edf-1800-0000-65c4-e58055110000 pid=4437 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=d0823edf-1800-0000-65c4-e58055110000 pid=4437 clone guuid=ec3643e0-1800-0000-65c4-e58058110000 pid=4440 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=ec3643e0-1800-0000-65c4-e58058110000 pid=4440 execve guuid=31ecaae0-1800-0000-65c4-e5805c110000 pid=4444 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=31ecaae0-1800-0000-65c4-e5805c110000 pid=4444 execve guuid=54cd9807-1900-0000-65c4-e580bf110000 pid=4543 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=54cd9807-1900-0000-65c4-e580bf110000 pid=4543 execve guuid=f861f407-1900-0000-65c4-e580c1110000 pid=4545 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=f861f407-1900-0000-65c4-e580c1110000 pid=4545 clone guuid=c248c508-1900-0000-65c4-e580c4110000 pid=4548 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=c248c508-1900-0000-65c4-e580c4110000 pid=4548 execve guuid=f0cb2009-1900-0000-65c4-e580c8110000 pid=4552 /usr/bin/wget net send-data write-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=f0cb2009-1900-0000-65c4-e580c8110000 pid=4552 execve guuid=dcb37a2f-1900-0000-65c4-e58022120000 pid=4642 /usr/bin/chmod guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=dcb37a2f-1900-0000-65c4-e58022120000 pid=4642 execve guuid=9ba7d82f-1900-0000-65c4-e58024120000 pid=4644 /usr/bin/bash guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=9ba7d82f-1900-0000-65c4-e58024120000 pid=4644 clone guuid=58b6e131-1900-0000-65c4-e5802d120000 pid=4653 /usr/bin/rm delete-file guuid=16fe3a4c-1700-0000-65c4-e5809f0d0000 pid=3487->guuid=58b6e131-1900-0000-65c4-e5802d120000 pid=4653 execve 3c08363b-4c05-5247-9298-7388a6812181 94.183.232.247:80 guuid=af9dad4c-1700-0000-65c4-e580a00d0000 pid=3488->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=308b7a7a-1700-0000-65c4-e580140e0000 pid=3604->3c08363b-4c05-5247-9298-7388a6812181 send: 139B guuid=0a52d089-1700-0000-65c4-e580500e0000 pid=3664->3c08363b-4c05-5247-9298-7388a6812181 send: 136B guuid=7b4d7bb0-1700-0000-65c4-e580920e0000 pid=3730->3c08363b-4c05-5247-9298-7388a6812181 send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c5b56bd7-1700-0000-65c4-e580f40e0000 pid=3828->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 55a35792-d7c1-5c0f-aabd-6e221273c95f 91.92.254.173:2139 guuid=c5b56bd7-1700-0000-65c4-e580f40e0000 pid=3828->55a35792-d7c1-5c0f-aabd-6e221273c95f send: 2B guuid=c0812c14-1800-0000-65c4-e580750f0000 pid=3957->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=a96a2925-1800-0000-65c4-e5809d0f0000 pid=3997->3c08363b-4c05-5247-9298-7388a6812181 send: 140B guuid=4b6e1a36-1800-0000-65c4-e580ca0f0000 pid=4042->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=edf6c846-1800-0000-65c4-e580f60f0000 pid=4086->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=dff7ae70-1800-0000-65c4-e58057100000 pid=4183->3c08363b-4c05-5247-9298-7388a6812181 send: 138B guuid=3f2e4181-1800-0000-65c4-e5807d100000 pid=4221->3c08363b-4c05-5247-9298-7388a6812181 send: 136B guuid=dea7bba8-1800-0000-65c4-e580db100000 pid=4315->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=972d23b9-1800-0000-65c4-e58000110000 pid=4352->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=31ecaae0-1800-0000-65c4-e5805c110000 pid=4444->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=f0cb2009-1900-0000-65c4-e580c8110000 pid=4552->3c08363b-4c05-5247-9298-7388a6812181 send: 137B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-06-07 14:56:26 UTC
File Type:
Text (Shell)
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7dca536f80d61bfb182eebc0d9e17e3723194b2a472cb60c8cc2c0a119d4a2c5

(this sample)

  
Delivery method
Distributed via web download

Comments