MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b49beeafa4ec1ccee3b24ef539a7183dda6561fbaf17abccfe4ce9f401c6a58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 8b49beeafa4ec1ccee3b24ef539a7183dda6561fbaf17abccfe4ce9f401c6a58
SHA3-384 hash: a42e77479aace8a587d527786a2fd045df754c9b237c7a1c424f5145c5699140df7606ffa9b3b324e540d21cba290284
SHA1 hash: 2a890a96e17b411b20db21d6e056d0ba9bced8a7
MD5 hash: 65a3baa28a93d7824da147ca52f42f88
humanhash: dakota-charlie-salami-berlin
File name:gg.sh
Download: download sample
Signature Mirai
File size:749 bytes
First seen:2026-08-26 15:45:34 UTC
Last seen:2026-08-27 03:27:08 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:40FI2K83daRnX0FIFKd3qza6CO0FIhiKhI3LaqkX0FI7Kr32ac:ZIp83dasIQd3qz2LIh9hI3L7ksImr32R
TLSH T144016CDD23512F321F654D12B1BF001431A1B0D169C35F9998DB38F494DEE48A5B7E53
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
URLMalware sample (SHA256 hash)SignatureTags
http://94.154.43.60/system_arm4fccee3f7a390ede947f9ded646933ab48d5a12e4bfbdc0dca5c1c4b41d54b2c1 Mirai94-154-43-60 elf mirai ua-wget
http://94.154.43.60/system_arm5cc906f595988068a8e6e2bc485b8d514e15666c751c909c0b1a631be45b9aa51 Mirai94-154-43-60 elf mirai ua-wget
http://94.154.43.60/system_arm69c28c7e77e78ce8573557fa6b069907f7a16c953f20ae2662e920d74091b75e9 Mirai94-154-43-60 elf mirai ua-wget
http://94.154.43.60/system_arm755bc4f5d8d2867652859a0c0f84c7ad5bc03cba3b7d1a431a49af8353b0cbaeb Mirai94-154-43-60 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
73
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-08-26T11:28:00Z UTC
Last seen:
2026-08-26T20:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f240bacc-1a00-0000-785f-7c78f1080000 pid=2289 /usr/bin/sudo guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295 /tmp/sample.bin guuid=f240bacc-1a00-0000-785f-7c78f1080000 pid=2289->guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295 execve guuid=9bf83ad1-1a00-0000-785f-7c78fa080000 pid=2298 /usr/bin/wget net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=9bf83ad1-1a00-0000-785f-7c78fa080000 pid=2298 execve guuid=c895b1d9-1a00-0000-785f-7c7806090000 pid=2310 /usr/bin/curl net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=c895b1d9-1a00-0000-785f-7c7806090000 pid=2310 execve guuid=0962dee3-1a00-0000-785f-7c781d090000 pid=2333 /usr/bin/cat guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=0962dee3-1a00-0000-785f-7c781d090000 pid=2333 execve guuid=a1cfd4e4-1a00-0000-785f-7c7820090000 pid=2336 /usr/bin/chmod guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=a1cfd4e4-1a00-0000-785f-7c7820090000 pid=2336 execve guuid=466a4ee5-1a00-0000-785f-7c7822090000 pid=2338 /usr/bin/bash guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=466a4ee5-1a00-0000-785f-7c7822090000 pid=2338 clone guuid=dc8419e6-1a00-0000-785f-7c7826090000 pid=2342 /usr/bin/wget net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=dc8419e6-1a00-0000-785f-7c7826090000 pid=2342 execve guuid=093d41ea-1a00-0000-785f-7c782d090000 pid=2349 /usr/bin/curl net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=093d41ea-1a00-0000-785f-7c782d090000 pid=2349 execve guuid=9f8dd4f1-1a00-0000-785f-7c7841090000 pid=2369 /usr/bin/cat guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=9f8dd4f1-1a00-0000-785f-7c7841090000 pid=2369 execve guuid=a6c821f2-1a00-0000-785f-7c7842090000 pid=2370 /usr/bin/chmod guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=a6c821f2-1a00-0000-785f-7c7842090000 pid=2370 execve guuid=131e6bf2-1a00-0000-785f-7c7843090000 pid=2371 /usr/bin/bash guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=131e6bf2-1a00-0000-785f-7c7843090000 pid=2371 clone guuid=05060af3-1a00-0000-785f-7c7845090000 pid=2373 /usr/bin/wget net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=05060af3-1a00-0000-785f-7c7845090000 pid=2373 execve guuid=08f7bef9-1a00-0000-785f-7c7852090000 pid=2386 /usr/bin/curl net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=08f7bef9-1a00-0000-785f-7c7852090000 pid=2386 execve guuid=40edff00-1b00-0000-785f-7c785f090000 pid=2399 /usr/bin/cat guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=40edff00-1b00-0000-785f-7c785f090000 pid=2399 execve guuid=5f916801-1b00-0000-785f-7c7860090000 pid=2400 /usr/bin/chmod guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=5f916801-1b00-0000-785f-7c7860090000 pid=2400 execve guuid=1e74b701-1b00-0000-785f-7c7861090000 pid=2401 /usr/bin/bash guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=1e74b701-1b00-0000-785f-7c7861090000 pid=2401 clone guuid=11b8c904-1b00-0000-785f-7c7869090000 pid=2409 /usr/bin/wget net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=11b8c904-1b00-0000-785f-7c7869090000 pid=2409 execve guuid=12a37e0c-1b00-0000-785f-7c787b090000 pid=2427 /usr/bin/curl net send-data write-file guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=12a37e0c-1b00-0000-785f-7c787b090000 pid=2427 execve guuid=60efc812-1b00-0000-785f-7c7880090000 pid=2432 /usr/bin/cat guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=60efc812-1b00-0000-785f-7c7880090000 pid=2432 execve guuid=7c534613-1b00-0000-785f-7c7881090000 pid=2433 /usr/bin/chmod guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=7c534613-1b00-0000-785f-7c7881090000 pid=2433 execve guuid=6147bc13-1b00-0000-785f-7c7883090000 pid=2435 /usr/bin/bash guuid=3e600ad0-1a00-0000-785f-7c78f7080000 pid=2295->guuid=6147bc13-1b00-0000-785f-7c7883090000 pid=2435 clone 079589fc-ef9b-528e-b132-247c095d948c 94.154.43.60:80 guuid=9bf83ad1-1a00-0000-785f-7c78fa080000 pid=2298->079589fc-ef9b-528e-b132-247c095d948c send: 138B guuid=c895b1d9-1a00-0000-785f-7c7806090000 pid=2310->079589fc-ef9b-528e-b132-247c095d948c send: 87B guuid=dc8419e6-1a00-0000-785f-7c7826090000 pid=2342->079589fc-ef9b-528e-b132-247c095d948c send: 138B guuid=093d41ea-1a00-0000-785f-7c782d090000 pid=2349->079589fc-ef9b-528e-b132-247c095d948c send: 87B guuid=05060af3-1a00-0000-785f-7c7845090000 pid=2373->079589fc-ef9b-528e-b132-247c095d948c send: 138B guuid=08f7bef9-1a00-0000-785f-7c7852090000 pid=2386->079589fc-ef9b-528e-b132-247c095d948c send: 87B guuid=11b8c904-1b00-0000-785f-7c7869090000 pid=2409->079589fc-ef9b-528e-b132-247c095d948c send: 138B guuid=12a37e0c-1b00-0000-785f-7c787b090000 pid=2427->079589fc-ef9b-528e-b132-247c095d948c send: 87B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-08-26 15:44:12 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm defense_evasion discovery linux upx
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (210932) amount of remote hosts
Creates a large amount of network flows
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8b49beeafa4ec1ccee3b24ef539a7183dda6561fbaf17abccfe4ce9f401c6a58

(this sample)

  
Delivery method
Distributed via web download

Comments