MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 85c89e3e84e41da0c333f2e6bae7779445ec812edc3c351b1b9330485f694cae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 85c89e3e84e41da0c333f2e6bae7779445ec812edc3c351b1b9330485f694cae
SHA3-384 hash: a5afb7e0c302ae0fe7e3311ce99fcb4085775260f32bfba2f205ae027925d1050f8177a86fb9076feec3874655cf993c
SHA1 hash: 8127e2a77d7126291838746cecc35b946e1b5aac
MD5 hash: a2fd89da203852d4ae475aed6cb3d3de
humanhash: december-harry-six-ceiling
File name:23.sh
Download: download sample
Signature Mirai
File size:2'639 bytes
First seen:2026-01-15 17:09:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vZonlnKKt4vRtKFT4+CXlFc4lKVblKyySl4PZkTGB8FbmA:vZa/t4vRtKFT4+w9AtekTvj
TLSH T150515AC483711AB02E62ED7671B88264B0E5A5DFACF6FB0748FD3DE6508CD045F84646
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://5.59.248.100/djmario.x86ae88cc6dc61a559d7fa1d7271cc91572fbba361affaa0d93fe6a4c606c097860 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.mips1e54387d2545094dae5a55b49056d73f076028cffa530f2b060104af7709cba8 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.arcn/an/aelf ua-wget
http://5.59.248.100/djmario.i468n/an/aelf ua-wget
http://5.59.248.100/djmario.i686n/an/aelf ua-wget
http://5.59.248.100/djmario.x86_64216bc844451868628bedb68b6968b4627968bde0593e00de0853831f10dc635f Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.mpsl664cd78d438af62048a0a127f98bfcca55b264df109035fba90f1f325fcb9cd9 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.arm702dc79f56fcf920a798195707d7750726241fe54e10188de6dfb20202941568 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.arm50c205753701807954b21b125866030ac034b331dfc9618952385dce90ab1e00e Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.arm6698472487992cb604b774270b9c71b46e59653da63e04d3d97a3d849f63b47d9 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.arm73491f22a5814b3c83ac3e7e68af24c9b4ad2746e38aa196d3f153cf8557bff20 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.ppcb764a4697649ed6d93c94132bbb3e1b432d5242f3f395599c203e6fa772937df Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.spcn/an/aelf ua-wget
http://5.59.248.100/djmario.m68kcdcda4765bc21b10793948ac026ab1f8c9cb724ab3068f89199c515092b5eb99 Miraielf mirai opendir ua-wget
http://5.59.248.100/djmario.sh48cfae29ea39fde8dd28f8616cf32eb2a2b6ba0e1ef43ee93b2e2c3bcef5b133e Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
71
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
bash lolbin medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-15T14:17:00Z UTC
Last seen:
2026-01-16T12:48:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=7aeb2fe4-1600-0000-240d-74aecd0c0000 pid=3277 /usr/bin/sudo guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286 /tmp/sample.bin guuid=7aeb2fe4-1600-0000-240d-74aecd0c0000 pid=3277->guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286 execve guuid=8c1fb0e7-1600-0000-240d-74aed80c0000 pid=3288 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=8c1fb0e7-1600-0000-240d-74aed80c0000 pid=3288 execve guuid=f79d1bf2-1600-0000-240d-74aef20c0000 pid=3314 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=f79d1bf2-1600-0000-240d-74aef20c0000 pid=3314 execve guuid=2dccc9fe-1600-0000-240d-74aef60c0000 pid=3318 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=2dccc9fe-1600-0000-240d-74aef60c0000 pid=3318 execve guuid=01f913ff-1600-0000-240d-74aef80c0000 pid=3320 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=01f913ff-1600-0000-240d-74aef80c0000 pid=3320 execve guuid=4f4976ff-1600-0000-240d-74aefa0c0000 pid=3322 /tmp/main delete-file net guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=4f4976ff-1600-0000-240d-74aefa0c0000 pid=3322 execve guuid=0536c2ff-1600-0000-240d-74aefd0c0000 pid=3325 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=0536c2ff-1600-0000-240d-74aefd0c0000 pid=3325 execve guuid=ec9f5a0a-1700-0000-240d-74ae1b0d0000 pid=3355 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=ec9f5a0a-1700-0000-240d-74ae1b0d0000 pid=3355 execve guuid=6deb4119-1700-0000-240d-74ae3e0d0000 pid=3390 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=6deb4119-1700-0000-240d-74ae3e0d0000 pid=3390 execve guuid=bf1aa419-1700-0000-240d-74ae400d0000 pid=3392 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=bf1aa419-1700-0000-240d-74ae400d0000 pid=3392 execve guuid=6f7c0a1a-1700-0000-240d-74ae420d0000 pid=3394 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=6f7c0a1a-1700-0000-240d-74ae420d0000 pid=3394 clone guuid=6a75ba1a-1700-0000-240d-74ae460d0000 pid=3398 /usr/bin/wget net send-data guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=6a75ba1a-1700-0000-240d-74ae460d0000 pid=3398 execve guuid=a2d5a71f-1700-0000-240d-74ae540d0000 pid=3412 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=a2d5a71f-1700-0000-240d-74ae540d0000 pid=3412 execve guuid=d0cc1326-1700-0000-240d-74ae650d0000 pid=3429 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=d0cc1326-1700-0000-240d-74ae650d0000 pid=3429 execve guuid=81d27826-1700-0000-240d-74ae670d0000 pid=3431 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=81d27826-1700-0000-240d-74ae670d0000 pid=3431 execve guuid=285bcb26-1700-0000-240d-74ae690d0000 pid=3433 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=285bcb26-1700-0000-240d-74ae690d0000 pid=3433 clone guuid=fb29f526-1700-0000-240d-74ae6b0d0000 pid=3435 /usr/bin/wget net send-data guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=fb29f526-1700-0000-240d-74ae6b0d0000 pid=3435 execve guuid=bde3f02b-1700-0000-240d-74ae7c0d0000 pid=3452 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=bde3f02b-1700-0000-240d-74ae7c0d0000 pid=3452 execve guuid=de4a0932-1700-0000-240d-74ae900d0000 pid=3472 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=de4a0932-1700-0000-240d-74ae900d0000 pid=3472 execve guuid=14f98232-1700-0000-240d-74ae930d0000 pid=3475 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=14f98232-1700-0000-240d-74ae930d0000 pid=3475 execve guuid=8555f632-1700-0000-240d-74ae950d0000 pid=3477 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=8555f632-1700-0000-240d-74ae950d0000 pid=3477 clone guuid=ceaa3533-1700-0000-240d-74ae970d0000 pid=3479 /usr/bin/wget net send-data guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=ceaa3533-1700-0000-240d-74ae970d0000 pid=3479 execve guuid=dc2a2238-1700-0000-240d-74aea30d0000 pid=3491 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=dc2a2238-1700-0000-240d-74aea30d0000 pid=3491 execve guuid=5132013e-1700-0000-240d-74aead0d0000 pid=3501 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=5132013e-1700-0000-240d-74aead0d0000 pid=3501 execve guuid=45e4623e-1700-0000-240d-74aeae0d0000 pid=3502 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=45e4623e-1700-0000-240d-74aeae0d0000 pid=3502 execve guuid=0cdabe3e-1700-0000-240d-74aeaf0d0000 pid=3503 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=0cdabe3e-1700-0000-240d-74aeaf0d0000 pid=3503 clone guuid=c116ed3e-1700-0000-240d-74aeb00d0000 pid=3504 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=c116ed3e-1700-0000-240d-74aeb00d0000 pid=3504 execve guuid=acf68549-1700-0000-240d-74aec60d0000 pid=3526 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=acf68549-1700-0000-240d-74aec60d0000 pid=3526 execve guuid=4a130e56-1700-0000-240d-74aee00d0000 pid=3552 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=4a130e56-1700-0000-240d-74aee00d0000 pid=3552 execve guuid=8b8fad56-1700-0000-240d-74aee20d0000 pid=3554 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=8b8fad56-1700-0000-240d-74aee20d0000 pid=3554 execve guuid=a5fa3157-1700-0000-240d-74aee40d0000 pid=3556 /tmp/main delete-file net guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=a5fa3157-1700-0000-240d-74aee40d0000 pid=3556 execve guuid=52907757-1700-0000-240d-74aee70d0000 pid=3559 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=52907757-1700-0000-240d-74aee70d0000 pid=3559 execve guuid=17734d62-1700-0000-240d-74ae030e0000 pid=3587 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=17734d62-1700-0000-240d-74ae030e0000 pid=3587 execve guuid=4076066e-1700-0000-240d-74ae1c0e0000 pid=3612 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=4076066e-1700-0000-240d-74ae1c0e0000 pid=3612 execve guuid=c34f666e-1700-0000-240d-74ae1e0e0000 pid=3614 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=c34f666e-1700-0000-240d-74ae1e0e0000 pid=3614 execve guuid=1e77ca6e-1700-0000-240d-74ae200e0000 pid=3616 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=1e77ca6e-1700-0000-240d-74ae200e0000 pid=3616 clone guuid=88209f6f-1700-0000-240d-74ae240e0000 pid=3620 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=88209f6f-1700-0000-240d-74ae240e0000 pid=3620 execve guuid=d49d787a-1700-0000-240d-74ae380e0000 pid=3640 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=d49d787a-1700-0000-240d-74ae380e0000 pid=3640 execve guuid=39145f86-1700-0000-240d-74ae5c0e0000 pid=3676 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=39145f86-1700-0000-240d-74ae5c0e0000 pid=3676 execve guuid=e5f7cb86-1700-0000-240d-74ae5e0e0000 pid=3678 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=e5f7cb86-1700-0000-240d-74ae5e0e0000 pid=3678 execve guuid=0b652b87-1700-0000-240d-74ae5f0e0000 pid=3679 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=0b652b87-1700-0000-240d-74ae5f0e0000 pid=3679 clone guuid=acbef487-1700-0000-240d-74ae650e0000 pid=3685 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=acbef487-1700-0000-240d-74ae650e0000 pid=3685 execve guuid=18b47792-1700-0000-240d-74ae7e0e0000 pid=3710 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=18b47792-1700-0000-240d-74ae7e0e0000 pid=3710 execve guuid=cfe5189f-1700-0000-240d-74aeb00e0000 pid=3760 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=cfe5189f-1700-0000-240d-74aeb00e0000 pid=3760 execve guuid=4e14679f-1700-0000-240d-74aeb20e0000 pid=3762 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=4e14679f-1700-0000-240d-74aeb20e0000 pid=3762 execve guuid=97ccb49f-1700-0000-240d-74aeb60e0000 pid=3766 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=97ccb49f-1700-0000-240d-74aeb60e0000 pid=3766 clone guuid=c4396fa0-1700-0000-240d-74aeb80e0000 pid=3768 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=c4396fa0-1700-0000-240d-74aeb80e0000 pid=3768 execve guuid=696194aa-1700-0000-240d-74aed90e0000 pid=3801 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=696194aa-1700-0000-240d-74aed90e0000 pid=3801 execve guuid=7bb6e0b5-1700-0000-240d-74ae120f0000 pid=3858 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=7bb6e0b5-1700-0000-240d-74ae120f0000 pid=3858 execve guuid=0ff86ab6-1700-0000-240d-74ae130f0000 pid=3859 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=0ff86ab6-1700-0000-240d-74ae130f0000 pid=3859 execve guuid=e233b9b6-1700-0000-240d-74ae150f0000 pid=3861 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=e233b9b6-1700-0000-240d-74ae150f0000 pid=3861 clone guuid=62968bb7-1700-0000-240d-74ae190f0000 pid=3865 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=62968bb7-1700-0000-240d-74ae190f0000 pid=3865 execve guuid=c7efcfc2-1700-0000-240d-74ae3d0f0000 pid=3901 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=c7efcfc2-1700-0000-240d-74ae3d0f0000 pid=3901 execve guuid=0f81dbce-1700-0000-240d-74ae6e0f0000 pid=3950 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=0f81dbce-1700-0000-240d-74ae6e0f0000 pid=3950 execve guuid=2f1f4bcf-1700-0000-240d-74ae700f0000 pid=3952 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=2f1f4bcf-1700-0000-240d-74ae700f0000 pid=3952 execve guuid=5465a2cf-1700-0000-240d-74ae720f0000 pid=3954 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=5465a2cf-1700-0000-240d-74ae720f0000 pid=3954 clone guuid=e45d72d0-1700-0000-240d-74ae740f0000 pid=3956 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=e45d72d0-1700-0000-240d-74ae740f0000 pid=3956 execve guuid=8236f2da-1700-0000-240d-74ae970f0000 pid=3991 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=8236f2da-1700-0000-240d-74ae970f0000 pid=3991 execve guuid=d9f054e6-1700-0000-240d-74aebf0f0000 pid=4031 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=d9f054e6-1700-0000-240d-74aebf0f0000 pid=4031 execve guuid=4470bae6-1700-0000-240d-74aec10f0000 pid=4033 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=4470bae6-1700-0000-240d-74aec10f0000 pid=4033 execve guuid=befd10e7-1700-0000-240d-74aec30f0000 pid=4035 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=befd10e7-1700-0000-240d-74aec30f0000 pid=4035 clone guuid=5820a8e7-1700-0000-240d-74aec70f0000 pid=4039 /usr/bin/wget net send-data guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=5820a8e7-1700-0000-240d-74aec70f0000 pid=4039 execve guuid=054118ed-1700-0000-240d-74aedd0f0000 pid=4061 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=054118ed-1700-0000-240d-74aedd0f0000 pid=4061 execve guuid=6dbf68f3-1700-0000-240d-74aef80f0000 pid=4088 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=6dbf68f3-1700-0000-240d-74aef80f0000 pid=4088 execve guuid=e779b7f3-1700-0000-240d-74aef90f0000 pid=4089 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=e779b7f3-1700-0000-240d-74aef90f0000 pid=4089 execve guuid=14b2f3f3-1700-0000-240d-74aefd0f0000 pid=4093 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=14b2f3f3-1700-0000-240d-74aefd0f0000 pid=4093 clone guuid=ecc310f4-1700-0000-240d-74aefe0f0000 pid=4094 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=ecc310f4-1700-0000-240d-74aefe0f0000 pid=4094 execve guuid=f8b14efe-1700-0000-240d-74ae28100000 pid=4136 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=f8b14efe-1700-0000-240d-74ae28100000 pid=4136 execve guuid=3c6d930a-1800-0000-240d-74ae50100000 pid=4176 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=3c6d930a-1800-0000-240d-74ae50100000 pid=4176 execve guuid=a567100b-1800-0000-240d-74ae52100000 pid=4178 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=a567100b-1800-0000-240d-74ae52100000 pid=4178 execve guuid=99298c0b-1800-0000-240d-74ae54100000 pid=4180 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=99298c0b-1800-0000-240d-74ae54100000 pid=4180 clone guuid=3924550c-1800-0000-240d-74ae5c100000 pid=4188 /usr/bin/wget net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=3924550c-1800-0000-240d-74ae5c100000 pid=4188 execve guuid=d9810117-1800-0000-240d-74ae80100000 pid=4224 /usr/bin/curl net send-data write-file guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=d9810117-1800-0000-240d-74ae80100000 pid=4224 execve guuid=ef0bda22-1800-0000-240d-74aea7100000 pid=4263 /usr/bin/cat guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=ef0bda22-1800-0000-240d-74aea7100000 pid=4263 execve guuid=492d5023-1800-0000-240d-74aead100000 pid=4269 /usr/bin/chmod guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=492d5023-1800-0000-240d-74aead100000 pid=4269 execve guuid=a7c89c23-1800-0000-240d-74aeae100000 pid=4270 /usr/bin/bash guuid=be880be7-1600-0000-240d-74aed60c0000 pid=3286->guuid=a7c89c23-1800-0000-240d-74aeae100000 pid=4270 clone 8ad66d97-7b47-57d4-b9f0-28b3a134bd36 5.59.248.100:80 guuid=8c1fb0e7-1600-0000-240d-74aed80c0000 pid=3288->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=f79d1bf2-1600-0000-240d-74aef20c0000 pid=3314->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4f4976ff-1600-0000-240d-74aefa0c0000 pid=3322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a0dcb0ff-1600-0000-240d-74aefc0c0000 pid=3324 /tmp/main dns net send-data zombie guuid=4f4976ff-1600-0000-240d-74aefa0c0000 pid=3322->guuid=a0dcb0ff-1600-0000-240d-74aefc0c0000 pid=3324 clone guuid=a0dcb0ff-1600-0000-240d-74aefc0c0000 pid=3324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 215B 32d458a0-a40f-565e-b5ae-91358dd4506a 115.11.111.11:22 guuid=a0dcb0ff-1600-0000-240d-74aefc0c0000 pid=3324->32d458a0-a40f-565e-b5ae-91358dd4506a con guuid=c9dddfff-1600-0000-240d-74aeff0c0000 pid=3327 /tmp/main guuid=a0dcb0ff-1600-0000-240d-74aefc0c0000 pid=3324->guuid=c9dddfff-1600-0000-240d-74aeff0c0000 pid=3327 clone guuid=0536c2ff-1600-0000-240d-74aefd0c0000 pid=3325->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=ec9f5a0a-1700-0000-240d-74ae1b0d0000 pid=3355->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=6a75ba1a-1700-0000-240d-74ae460d0000 pid=3398->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=a2d5a71f-1700-0000-240d-74ae540d0000 pid=3412->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B guuid=fb29f526-1700-0000-240d-74ae6b0d0000 pid=3435->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=bde3f02b-1700-0000-240d-74ae7c0d0000 pid=3452->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=ceaa3533-1700-0000-240d-74ae970d0000 pid=3479->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=dc2a2238-1700-0000-240d-74aea30d0000 pid=3491->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=c116ed3e-1700-0000-240d-74aeb00d0000 pid=3504->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 141B guuid=acf68549-1700-0000-240d-74aec60d0000 pid=3526->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 90B guuid=a5fa3157-1700-0000-240d-74aee40d0000 pid=3556->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2a6f5f57-1700-0000-240d-74aee50d0000 pid=3557 /tmp/main delete-file dns net send-data zombie guuid=a5fa3157-1700-0000-240d-74aee40d0000 pid=3556->guuid=2a6f5f57-1700-0000-240d-74aee50d0000 pid=3557 clone guuid=2a6f5f57-1700-0000-240d-74aee50d0000 pid=3557->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1290B guuid=2a6f5f57-1700-0000-240d-74aee50d0000 pid=3557->32d458a0-a40f-565e-b5ae-91358dd4506a send: 2B guuid=b58d7a57-1700-0000-240d-74aee80d0000 pid=3560 /tmp/main guuid=2a6f5f57-1700-0000-240d-74aee50d0000 pid=3557->guuid=b58d7a57-1700-0000-240d-74aee80d0000 pid=3560 clone guuid=52907757-1700-0000-240d-74aee70d0000 pid=3559->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=17734d62-1700-0000-240d-74ae030e0000 pid=3587->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=88209f6f-1700-0000-240d-74ae240e0000 pid=3620->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=d49d787a-1700-0000-240d-74ae380e0000 pid=3640->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B guuid=acbef487-1700-0000-240d-74ae650e0000 pid=3685->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=18b47792-1700-0000-240d-74ae7e0e0000 pid=3710->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=c4396fa0-1700-0000-240d-74aeb80e0000 pid=3768->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=696194aa-1700-0000-240d-74aed90e0000 pid=3801->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=62968bb7-1700-0000-240d-74ae190f0000 pid=3865->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=c7efcfc2-1700-0000-240d-74ae3d0f0000 pid=3901->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=e45d72d0-1700-0000-240d-74ae740f0000 pid=3956->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=8236f2da-1700-0000-240d-74ae970f0000 pid=3991->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B guuid=5820a8e7-1700-0000-240d-74aec70f0000 pid=4039->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=054118ed-1700-0000-240d-74aedd0f0000 pid=4061->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B guuid=ecc310f4-1700-0000-240d-74aefe0f0000 pid=4094->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 139B guuid=f8b14efe-1700-0000-240d-74ae28100000 pid=4136->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 88B guuid=3924550c-1800-0000-240d-74ae5c100000 pid=4188->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 138B guuid=d9810117-1800-0000-240d-74ae80100000 pid=4224->8ad66d97-7b47-57d4-b9f0-28b3a134bd36 send: 87B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-15 16:42:16 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 85c89e3e84e41da0c333f2e6bae7779445ec812edc3c351b1b9330485f694cae

(this sample)

  
Delivery method
Distributed via web download

Comments