MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c88bab565e4897fa8d74594e05db8c1f856d70a5d42e5619d10415c6c6c071e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 8c88bab565e4897fa8d74594e05db8c1f856d70a5d42e5619d10415c6c6c071e
SHA3-384 hash: 3cfe13f928ce782e9585d6ed5056e87ffcf0794be06caf7205def023c84b3a1833d7a6eac5cab9432b8cc8708cb6e826
SHA1 hash: 795c0259371e9c46be4c7fd93a6f9e12925ac780
MD5 hash: 75632ec8dda0a4590f2cbb5ae6d725a2
humanhash: london-jig-uranus-michigan
File name:Sakura.sh
Download: download sample
Signature Mirai
File size:2'124 bytes
First seen:2025-12-25 07:54:29 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vod8jHttQdMGYdRb7QT6aCOIlL1f5NOI9xET:vod8jHttQdMGYdRb7QT6aCOIlBf5NOIQ
TLSH T194413CC7226147F26CA0DCB3326AD4C0B5E89195E4D66F4B69DC3CE448BFEEC64446C2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.221.199.206/m-i.p-s.Sakurabab1c65eb103979e523c51279d9b166ce7023667cabc7cee6f3356f6d4a496a5 Miraielf mirai ua-wget
http://185.221.199.206/m-p.s-l.Sakura9f00a765db5ce358ea849926921ffd9e6f34c8e84e8e6bc9b236fa614f9a5b98 Gafgytelf gafgyt ua-wget
http://185.221.199.206/s-h.4-.Sakura59118fb1d51e93b916f89dddde76b3f6f8e2760e49ba2b8f0f2a5e8308f1d892 Miraielf mirai ua-wget
http://185.221.199.206/x-8.6-.Sakuraebe6a23a1e288e1bd0aced70302a618d0a06afd1a62fb9ad62314aa6791cb7e0 Miraielf mirai ua-wget
http://185.221.199.206/a-r.m-6.Sakura900943f8067c381a00bf655c3e537389fe1f0b32d64d67c64023b7bfe9b74a5b Gafgytelf gafgyt ua-wget
http://185.221.199.206/x-3.2-.Sakurab7e3744783f2ab4901e2e0e62d8259115e54f2b6af934e8dd2df20c9c5db5432 Gafgytelf gafgyt ua-wget
http://185.221.199.206/a-r.m-7.Sakura27dabb9ad95bb8c9b25d7cfffa6fca500774a8e07a4a0d7d261a597875ff0391 Miraielf mirai ua-wget
http://185.221.199.206/p-p.c-.Sakura40cfc43aa48d5a4afdf57b549e0b586faf8fd39e9e153e6c8e1bc78d819866c5 Gafgytelf gafgyt ua-wget
http://185.221.199.206/i-5.8-6.Sakuraa2039c787503669586f07db8d5e61ba9984bc9bbf67ee391ca6bc3490e857819 Miraielf mirai ua-wget
http://185.221.199.206/m-6.8-k.Sakuraa8f159d165188e04d08649711833987d54ce17e0f541d0fa90633f58e23ca065 Gafgytelf gafgyt ua-wget
http://185.221.199.206/a-r.m-4.Sakura40cfc43aa48d5a4afdf57b549e0b586faf8fd39e9e153e6c8e1bc78d819866c5 Gafgytelf gafgyt ua-wget
http://185.221.199.206/a-r.m-5.Sakuradfc0c0820b4d7b5fba03d41d5a99e969fd4886dce51ec752b454669c3c4166e4 Gafgytelf gafgyt ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=b1205f46-1900-0000-518a-056ab10a0000 pid=2737 /usr/bin/sudo guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742 /tmp/sample.bin guuid=b1205f46-1900-0000-518a-056ab10a0000 pid=2737->guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742 execve guuid=9aa42849-1900-0000-518a-056ab80a0000 pid=2744 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=9aa42849-1900-0000-518a-056ab80a0000 pid=2744 execve guuid=29ede25a-1900-0000-518a-056ace0a0000 pid=2766 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=29ede25a-1900-0000-518a-056ace0a0000 pid=2766 execve guuid=2294835b-1900-0000-518a-056acf0a0000 pid=2767 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=2294835b-1900-0000-518a-056acf0a0000 pid=2767 clone guuid=2882795c-1900-0000-518a-056ad40a0000 pid=2772 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=2882795c-1900-0000-518a-056ad40a0000 pid=2772 execve guuid=fe47095d-1900-0000-518a-056ad70a0000 pid=2775 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=fe47095d-1900-0000-518a-056ad70a0000 pid=2775 execve guuid=5ef2576c-1900-0000-518a-056af20a0000 pid=2802 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=5ef2576c-1900-0000-518a-056af20a0000 pid=2802 execve guuid=8552b26c-1900-0000-518a-056af30a0000 pid=2803 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=8552b26c-1900-0000-518a-056af30a0000 pid=2803 clone guuid=3f46a16d-1900-0000-518a-056af50a0000 pid=2805 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=3f46a16d-1900-0000-518a-056af50a0000 pid=2805 execve guuid=cb05226e-1900-0000-518a-056af60a0000 pid=2806 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=cb05226e-1900-0000-518a-056af60a0000 pid=2806 execve guuid=36de827a-1900-0000-518a-056a0b0b0000 pid=2827 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=36de827a-1900-0000-518a-056a0b0b0000 pid=2827 execve guuid=b8714d7b-1900-0000-518a-056a0e0b0000 pid=2830 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=b8714d7b-1900-0000-518a-056a0e0b0000 pid=2830 clone guuid=b77a3b7c-1900-0000-518a-056a120b0000 pid=2834 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=b77a3b7c-1900-0000-518a-056a120b0000 pid=2834 execve guuid=00629d7c-1900-0000-518a-056a130b0000 pid=2835 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=00629d7c-1900-0000-518a-056a130b0000 pid=2835 execve guuid=aab6de88-1900-0000-518a-056a290b0000 pid=2857 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=aab6de88-1900-0000-518a-056a290b0000 pid=2857 execve guuid=11334089-1900-0000-518a-056a2b0b0000 pid=2859 /tmp/x-8.6-.Sakura net guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=11334089-1900-0000-518a-056a2b0b0000 pid=2859 execve guuid=44a98889-1900-0000-518a-056a2f0b0000 pid=2863 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=44a98889-1900-0000-518a-056a2f0b0000 pid=2863 execve guuid=b1b3dd89-1900-0000-518a-056a310b0000 pid=2865 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=b1b3dd89-1900-0000-518a-056a310b0000 pid=2865 execve guuid=3f434499-1900-0000-518a-056a500b0000 pid=2896 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=3f434499-1900-0000-518a-056a500b0000 pid=2896 execve guuid=07688599-1900-0000-518a-056a520b0000 pid=2898 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=07688599-1900-0000-518a-056a520b0000 pid=2898 clone guuid=5665149a-1900-0000-518a-056a570b0000 pid=2903 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=5665149a-1900-0000-518a-056a570b0000 pid=2903 execve guuid=895f5c9a-1900-0000-518a-056a590b0000 pid=2905 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=895f5c9a-1900-0000-518a-056a590b0000 pid=2905 execve guuid=94e3dfa7-1900-0000-518a-056a760b0000 pid=2934 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=94e3dfa7-1900-0000-518a-056a760b0000 pid=2934 execve guuid=fc7831a8-1900-0000-518a-056a770b0000 pid=2935 /tmp/x-3.2-.Sakura net guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=fc7831a8-1900-0000-518a-056a770b0000 pid=2935 execve guuid=a3757fa9-1900-0000-518a-056a7b0b0000 pid=2939 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=a3757fa9-1900-0000-518a-056a7b0b0000 pid=2939 execve guuid=171efca9-1900-0000-518a-056a7c0b0000 pid=2940 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=171efca9-1900-0000-518a-056a7c0b0000 pid=2940 execve guuid=c3136fb6-1900-0000-518a-056a8e0b0000 pid=2958 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=c3136fb6-1900-0000-518a-056a8e0b0000 pid=2958 execve guuid=0f4ec5b6-1900-0000-518a-056a900b0000 pid=2960 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=0f4ec5b6-1900-0000-518a-056a900b0000 pid=2960 clone guuid=538863b8-1900-0000-518a-056a950b0000 pid=2965 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=538863b8-1900-0000-518a-056a950b0000 pid=2965 execve guuid=9600c6b8-1900-0000-518a-056a970b0000 pid=2967 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=9600c6b8-1900-0000-518a-056a970b0000 pid=2967 execve guuid=a7026ec8-1900-0000-518a-056ab40b0000 pid=2996 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=a7026ec8-1900-0000-518a-056ab40b0000 pid=2996 execve guuid=b356c2c8-1900-0000-518a-056ab50b0000 pid=2997 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=b356c2c8-1900-0000-518a-056ab50b0000 pid=2997 clone guuid=f7680fd1-1900-0000-518a-056abd0b0000 pid=3005 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=f7680fd1-1900-0000-518a-056abd0b0000 pid=3005 execve guuid=f43598d1-1900-0000-518a-056abf0b0000 pid=3007 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=f43598d1-1900-0000-518a-056abf0b0000 pid=3007 execve guuid=a90822de-1900-0000-518a-056ad60b0000 pid=3030 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=a90822de-1900-0000-518a-056ad60b0000 pid=3030 execve guuid=f22569de-1900-0000-518a-056ad80b0000 pid=3032 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=f22569de-1900-0000-518a-056ad80b0000 pid=3032 clone guuid=954e0bdf-1900-0000-518a-056adc0b0000 pid=3036 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=954e0bdf-1900-0000-518a-056adc0b0000 pid=3036 execve guuid=206b59df-1900-0000-518a-056ade0b0000 pid=3038 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=206b59df-1900-0000-518a-056ade0b0000 pid=3038 execve guuid=a0936aee-1900-0000-518a-056a060c0000 pid=3078 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=a0936aee-1900-0000-518a-056a060c0000 pid=3078 execve guuid=3305d3ee-1900-0000-518a-056a080c0000 pid=3080 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=3305d3ee-1900-0000-518a-056a080c0000 pid=3080 clone guuid=232976ef-1900-0000-518a-056a0c0c0000 pid=3084 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=232976ef-1900-0000-518a-056a0c0c0000 pid=3084 execve guuid=3a49d6ef-1900-0000-518a-056a0e0c0000 pid=3086 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=3a49d6ef-1900-0000-518a-056a0e0c0000 pid=3086 execve guuid=f431a7fe-1900-0000-518a-056a330c0000 pid=3123 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=f431a7fe-1900-0000-518a-056a330c0000 pid=3123 execve guuid=bc9404ff-1900-0000-518a-056a350c0000 pid=3125 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=bc9404ff-1900-0000-518a-056a350c0000 pid=3125 clone guuid=c954d000-1a00-0000-518a-056a3b0c0000 pid=3131 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=c954d000-1a00-0000-518a-056a3b0c0000 pid=3131 execve guuid=9e1f4801-1a00-0000-518a-056a3e0c0000 pid=3134 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=9e1f4801-1a00-0000-518a-056a3e0c0000 pid=3134 execve guuid=24b7c30f-1a00-0000-518a-056a650c0000 pid=3173 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=24b7c30f-1a00-0000-518a-056a650c0000 pid=3173 execve guuid=35d45710-1a00-0000-518a-056a670c0000 pid=3175 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=35d45710-1a00-0000-518a-056a670c0000 pid=3175 clone guuid=9ae07711-1a00-0000-518a-056a6c0c0000 pid=3180 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=9ae07711-1a00-0000-518a-056a6c0c0000 pid=3180 execve guuid=1d36cc11-1a00-0000-518a-056a6e0c0000 pid=3182 /usr/bin/wget net send-data write-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=1d36cc11-1a00-0000-518a-056a6e0c0000 pid=3182 execve guuid=2713061e-1a00-0000-518a-056a8d0c0000 pid=3213 /usr/bin/chmod guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=2713061e-1a00-0000-518a-056a8d0c0000 pid=3213 execve guuid=6068541e-1a00-0000-518a-056a8e0c0000 pid=3214 /usr/bin/bash guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=6068541e-1a00-0000-518a-056a8e0c0000 pid=3214 clone guuid=77ce021f-1a00-0000-518a-056a910c0000 pid=3217 /usr/bin/rm delete-file guuid=16079e48-1900-0000-518a-056ab60a0000 pid=2742->guuid=77ce021f-1a00-0000-518a-056a910c0000 pid=3217 execve a63ee108-3729-5d55-9003-768af2eba4a7 185.221.199.206:80 guuid=9aa42849-1900-0000-518a-056ab80a0000 pid=2744->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=fe47095d-1900-0000-518a-056ad70a0000 pid=2775->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=cb05226e-1900-0000-518a-056af60a0000 pid=2806->a63ee108-3729-5d55-9003-768af2eba4a7 send: 143B guuid=00629d7c-1900-0000-518a-056a130b0000 pid=2835->a63ee108-3729-5d55-9003-768af2eba4a7 send: 143B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=11334089-1900-0000-518a-056a2b0b0000 pid=2859->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9c847389-1900-0000-518a-056a2d0b0000 pid=2861 /tmp/x-8.6-.Sakura guuid=11334089-1900-0000-518a-056a2b0b0000 pid=2859->guuid=9c847389-1900-0000-518a-056a2d0b0000 pid=2861 clone guuid=9d647c89-1900-0000-518a-056a2e0b0000 pid=2862 /tmp/x-8.6-.Sakura net send-data zombie guuid=9c847389-1900-0000-518a-056a2d0b0000 pid=2861->guuid=9d647c89-1900-0000-518a-056a2e0b0000 pid=2862 clone 657f306e-7d4f-599c-8c1d-3ba203d52932 185.221.199.206:12345 guuid=9d647c89-1900-0000-518a-056a2e0b0000 pid=2862->657f306e-7d4f-599c-8c1d-3ba203d52932 send: 65B guuid=b1b3dd89-1900-0000-518a-056a310b0000 pid=2865->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=895f5c9a-1900-0000-518a-056a590b0000 pid=2905->a63ee108-3729-5d55-9003-768af2eba4a7 send: 143B guuid=fc7831a8-1900-0000-518a-056a770b0000 pid=2935->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=098a5da9-1900-0000-518a-056a790b0000 pid=2937 /tmp/x-3.2-.Sakura guuid=fc7831a8-1900-0000-518a-056a770b0000 pid=2935->guuid=098a5da9-1900-0000-518a-056a790b0000 pid=2937 clone guuid=f87a6ba9-1900-0000-518a-056a7a0b0000 pid=2938 /tmp/x-3.2-.Sakura net send-data zombie guuid=098a5da9-1900-0000-518a-056a790b0000 pid=2937->guuid=f87a6ba9-1900-0000-518a-056a7a0b0000 pid=2938 clone guuid=f87a6ba9-1900-0000-518a-056a7a0b0000 pid=2938->657f306e-7d4f-599c-8c1d-3ba203d52932 send: 38805B guuid=171efca9-1900-0000-518a-056a7c0b0000 pid=2940->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=9600c6b8-1900-0000-518a-056a970b0000 pid=2967->a63ee108-3729-5d55-9003-768af2eba4a7 send: 143B guuid=f43598d1-1900-0000-518a-056abf0b0000 pid=3007->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=206b59df-1900-0000-518a-056ade0b0000 pid=3038->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=3a49d6ef-1900-0000-518a-056a0e0c0000 pid=3086->a63ee108-3729-5d55-9003-768af2eba4a7 send: 143B guuid=9e1f4801-1a00-0000-518a-056a3e0c0000 pid=3134->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B guuid=1d36cc11-1a00-0000-518a-056a6e0c0000 pid=3182->a63ee108-3729-5d55-9003-768af2eba4a7 send: 144B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-12-25 07:43:04 UTC
AV detection:
24 of 36 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt botnet defense_evasion discovery linux
Behaviour
Writes file to tmp directory
Reads system network configuration
Creates a large amount of network flows
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Malware Config
C2 Extraction:
185.221.199.206:12345
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 8c88bab565e4897fa8d74594e05db8c1f856d70a5d42e5619d10415c6c6c071e

(this sample)

  
Delivery method
Distributed via web download

Comments