MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8ed925e948b20635a5b6761edc4e4d522cb77d32a5403cbff28a9ebbf27721e2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 8ed925e948b20635a5b6761edc4e4d522cb77d32a5403cbff28a9ebbf27721e2
SHA3-384 hash: cc1e4e4deee5a95be0b2436dc00307118e37a3063a500532f6d71748cde60ef906230f166456438a64721d2a31940523
SHA1 hash: 397527956e202a49a4481585007cccaf462d6c92
MD5 hash: ee4cb934a3c8e6c215a57faa7e6b5606
humanhash: gee-winner-potato-bulldog
File name:dick.sh
Download: download sample
File size:1'994 bytes
First seen:2026-06-15 07:06:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vpCanp5pdpZpxpQKplp9pDlpQR9R4RFBrp9pppS:vkanT3TbGK/fTy/C/BrfTE
TLSH T15C413AD615A549346CEDD95B33B9980030D4D1969FCA6F9F68EC38E48DCDD84B8C4BC2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.24/m-i.p-s.dick42bc0e1e7309a256236ea5e46d0ddba04648f1ed6f930870d79f717c177dcae4 Miraielf mirai ua-wget
http://176.65.148.24/m-p.s-l.dickb6ee6eb7d33a8c2e4963c32e078d3a86e7d3a96a3eb78b699996136f3a4c297a Miraielf mirai ua-wget
http://176.65.148.24/s-h.4-.dick84dbbefd653fbfb4f0753ceaa757987098a87bf08f792425470d1e8a43bbe0bc Miraielf mirai ua-wget
http://176.65.148.24/x-8.6-.dick271c4e74701bceebf3afdadf3a9564d29debdc568b3696386637a6c3b1d8b405 Miraielf mirai ua-wget
http://176.65.148.24/a-r.m-6.dicke36505927dcdb61f95ed2b36c3d9620894f57065cd4546137bad6ecce975c3da Miraielf mirai ua-wget
http://176.65.148.24/x-3.2-.dickda808c541f3d5a295f96863e1b605b23cdb7f69a2e2bc5d017a1c4616c1298cf Miraielf mirai ua-wget
http://176.65.148.24/a-r.m-7.dick6ed82f4c8f41e9ee28bfeb6aa6e757e85d2d811c4b8ef97476622710c9acf53b Miraielf mirai ua-wget
http://176.65.148.24/p-p.c-.dickbf814c9f566f3f01e7bfbbd2c92e4b8cf94ff06d0eec2784009f6482301f9ce7 Miraielf mirai ua-wget
http://176.65.148.24/i-5.8-6.dick81bec5933e0561d3f6685358bb9e7362ed3c63c373e6592e3d387664a5081d93 Miraielf mirai ua-wget
http://176.65.148.24/m-6.8-k.dick23b61b7224532d7695a04057f8725e4b7758053d2057eec1a918a7d57080bf98 Miraielf mirai ua-wget
http://176.65.148.24/a-r.m-4.dickbf814c9f566f3f01e7bfbbd2c92e4b8cf94ff06d0eec2784009f6482301f9ce7 Miraielf mirai ua-wget
http://176.65.148.24/a-r.m-5.dick182dc5a1e6dbb9027d11e3d9c78b61a7ada2c85e1a282229b2428a869af2f79f Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-14T13:21:00Z UTC
Last seen:
2026-06-17T00:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f4b20b2e-1c00-0000-f1e6-562ef4090000 pid=2548 /usr/bin/sudo guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556 /tmp/sample.bin guuid=f4b20b2e-1c00-0000-f1e6-562ef4090000 pid=2548->guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556 execve guuid=56726531-1c00-0000-f1e6-562eff090000 pid=2559 /usr/bin/wget net send-data write-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=56726531-1c00-0000-f1e6-562eff090000 pid=2559 execve guuid=04ab6938-1c00-0000-f1e6-562e130a0000 pid=2579 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=04ab6938-1c00-0000-f1e6-562e130a0000 pid=2579 execve guuid=5bbcba38-1c00-0000-f1e6-562e150a0000 pid=2581 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=5bbcba38-1c00-0000-f1e6-562e150a0000 pid=2581 clone guuid=d2b76c39-1c00-0000-f1e6-562e1a0a0000 pid=2586 /usr/bin/rm delete-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d2b76c39-1c00-0000-f1e6-562e1a0a0000 pid=2586 execve guuid=53dfd539-1c00-0000-f1e6-562e1c0a0000 pid=2588 /usr/bin/wget net send-data write-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=53dfd539-1c00-0000-f1e6-562e1c0a0000 pid=2588 execve guuid=0883f740-1c00-0000-f1e6-562e310a0000 pid=2609 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=0883f740-1c00-0000-f1e6-562e310a0000 pid=2609 execve guuid=f3516e41-1c00-0000-f1e6-562e330a0000 pid=2611 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=f3516e41-1c00-0000-f1e6-562e330a0000 pid=2611 clone guuid=5bd81442-1c00-0000-f1e6-562e370a0000 pid=2615 /usr/bin/rm delete-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=5bd81442-1c00-0000-f1e6-562e370a0000 pid=2615 execve guuid=68b66342-1c00-0000-f1e6-562e380a0000 pid=2616 /usr/bin/wget net send-data write-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=68b66342-1c00-0000-f1e6-562e380a0000 pid=2616 execve guuid=0b9eb247-1c00-0000-f1e6-562e480a0000 pid=2632 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=0b9eb247-1c00-0000-f1e6-562e480a0000 pid=2632 execve guuid=0ee2f947-1c00-0000-f1e6-562e4a0a0000 pid=2634 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=0ee2f947-1c00-0000-f1e6-562e4a0a0000 pid=2634 clone guuid=7fcc0f49-1c00-0000-f1e6-562e4f0a0000 pid=2639 /usr/bin/rm delete-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=7fcc0f49-1c00-0000-f1e6-562e4f0a0000 pid=2639 execve guuid=6a809249-1c00-0000-f1e6-562e520a0000 pid=2642 /usr/bin/wget net send-data write-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=6a809249-1c00-0000-f1e6-562e520a0000 pid=2642 execve guuid=c464924f-1c00-0000-f1e6-562e5f0a0000 pid=2655 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=c464924f-1c00-0000-f1e6-562e5f0a0000 pid=2655 execve guuid=1d480650-1c00-0000-f1e6-562e610a0000 pid=2657 /tmp/x-8.6-.dick guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=1d480650-1c00-0000-f1e6-562e610a0000 pid=2657 execve guuid=87384650-1c00-0000-f1e6-562e650a0000 pid=2661 /usr/bin/rm delete-file guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=87384650-1c00-0000-f1e6-562e650a0000 pid=2661 execve guuid=2510ce50-1c00-0000-f1e6-562e680a0000 pid=2664 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2510ce50-1c00-0000-f1e6-562e680a0000 pid=2664 clone guuid=d53cf050-1c00-0000-f1e6-562e690a0000 pid=2665 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d53cf050-1c00-0000-f1e6-562e690a0000 pid=2665 execve guuid=9fef5851-1c00-0000-f1e6-562e6c0a0000 pid=2668 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=9fef5851-1c00-0000-f1e6-562e6c0a0000 pid=2668 clone guuid=1a217451-1c00-0000-f1e6-562e6d0a0000 pid=2669 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=1a217451-1c00-0000-f1e6-562e6d0a0000 pid=2669 execve guuid=7020bf51-1c00-0000-f1e6-562e700a0000 pid=2672 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=7020bf51-1c00-0000-f1e6-562e700a0000 pid=2672 clone guuid=ad12dd51-1c00-0000-f1e6-562e730a0000 pid=2675 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=ad12dd51-1c00-0000-f1e6-562e730a0000 pid=2675 execve guuid=bd8a4952-1c00-0000-f1e6-562e750a0000 pid=2677 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=bd8a4952-1c00-0000-f1e6-562e750a0000 pid=2677 clone guuid=23ce6552-1c00-0000-f1e6-562e760a0000 pid=2678 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=23ce6552-1c00-0000-f1e6-562e760a0000 pid=2678 execve guuid=d745aa52-1c00-0000-f1e6-562e780a0000 pid=2680 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d745aa52-1c00-0000-f1e6-562e780a0000 pid=2680 clone guuid=d873c652-1c00-0000-f1e6-562e790a0000 pid=2681 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d873c652-1c00-0000-f1e6-562e790a0000 pid=2681 execve guuid=c0671d53-1c00-0000-f1e6-562e7b0a0000 pid=2683 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=c0671d53-1c00-0000-f1e6-562e7b0a0000 pid=2683 clone guuid=7b383453-1c00-0000-f1e6-562e7d0a0000 pid=2685 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=7b383453-1c00-0000-f1e6-562e7d0a0000 pid=2685 execve guuid=f3619b53-1c00-0000-f1e6-562e7f0a0000 pid=2687 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=f3619b53-1c00-0000-f1e6-562e7f0a0000 pid=2687 clone guuid=d272b753-1c00-0000-f1e6-562e800a0000 pid=2688 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d272b753-1c00-0000-f1e6-562e800a0000 pid=2688 execve guuid=ca3e0e54-1c00-0000-f1e6-562e830a0000 pid=2691 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=ca3e0e54-1c00-0000-f1e6-562e830a0000 pid=2691 clone guuid=8f222454-1c00-0000-f1e6-562e840a0000 pid=2692 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=8f222454-1c00-0000-f1e6-562e840a0000 pid=2692 execve guuid=f2a09754-1c00-0000-f1e6-562e860a0000 pid=2694 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=f2a09754-1c00-0000-f1e6-562e860a0000 pid=2694 clone guuid=8c14b654-1c00-0000-f1e6-562e870a0000 pid=2695 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=8c14b654-1c00-0000-f1e6-562e870a0000 pid=2695 execve guuid=89d46155-1c00-0000-f1e6-562e8a0a0000 pid=2698 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=89d46155-1c00-0000-f1e6-562e8a0a0000 pid=2698 clone guuid=2dc67855-1c00-0000-f1e6-562e8b0a0000 pid=2699 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2dc67855-1c00-0000-f1e6-562e8b0a0000 pid=2699 execve guuid=05f5ef55-1c00-0000-f1e6-562e8d0a0000 pid=2701 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=05f5ef55-1c00-0000-f1e6-562e8d0a0000 pid=2701 clone guuid=d6bd1056-1c00-0000-f1e6-562e8e0a0000 pid=2702 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=d6bd1056-1c00-0000-f1e6-562e8e0a0000 pid=2702 execve guuid=850e6a56-1c00-0000-f1e6-562e900a0000 pid=2704 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=850e6a56-1c00-0000-f1e6-562e900a0000 pid=2704 clone guuid=2cf58e56-1c00-0000-f1e6-562e920a0000 pid=2706 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2cf58e56-1c00-0000-f1e6-562e920a0000 pid=2706 execve guuid=a04cfb56-1c00-0000-f1e6-562e940a0000 pid=2708 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=a04cfb56-1c00-0000-f1e6-562e940a0000 pid=2708 clone guuid=a1c81e57-1c00-0000-f1e6-562e960a0000 pid=2710 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=a1c81e57-1c00-0000-f1e6-562e960a0000 pid=2710 execve guuid=ab4a7557-1c00-0000-f1e6-562e980a0000 pid=2712 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=ab4a7557-1c00-0000-f1e6-562e980a0000 pid=2712 clone guuid=933d9957-1c00-0000-f1e6-562e990a0000 pid=2713 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=933d9957-1c00-0000-f1e6-562e990a0000 pid=2713 execve guuid=2bead657-1c00-0000-f1e6-562e9b0a0000 pid=2715 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2bead657-1c00-0000-f1e6-562e9b0a0000 pid=2715 clone guuid=9abaf057-1c00-0000-f1e6-562e9c0a0000 pid=2716 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=9abaf057-1c00-0000-f1e6-562e9c0a0000 pid=2716 execve guuid=2e883558-1c00-0000-f1e6-562e9e0a0000 pid=2718 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2e883558-1c00-0000-f1e6-562e9e0a0000 pid=2718 clone guuid=0bc94e58-1c00-0000-f1e6-562e9f0a0000 pid=2719 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=0bc94e58-1c00-0000-f1e6-562e9f0a0000 pid=2719 execve guuid=45aea858-1c00-0000-f1e6-562ea10a0000 pid=2721 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=45aea858-1c00-0000-f1e6-562ea10a0000 pid=2721 clone guuid=5d9ac258-1c00-0000-f1e6-562ea30a0000 pid=2723 /usr/bin/chmod guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=5d9ac258-1c00-0000-f1e6-562ea30a0000 pid=2723 execve guuid=49cb2259-1c00-0000-f1e6-562ea50a0000 pid=2725 /usr/bin/bash guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=49cb2259-1c00-0000-f1e6-562ea50a0000 pid=2725 clone guuid=2f2d5659-1c00-0000-f1e6-562ea70a0000 pid=2727 /usr/bin/rm guuid=806ed030-1c00-0000-f1e6-562efc090000 pid=2556->guuid=2f2d5659-1c00-0000-f1e6-562ea70a0000 pid=2727 execve 00d64a87-ce76-56e8-b87c-0dd1888f8452 176.65.148.24:80 guuid=56726531-1c00-0000-f1e6-562eff090000 pid=2559->00d64a87-ce76-56e8-b87c-0dd1888f8452 send: 140B guuid=53dfd539-1c00-0000-f1e6-562e1c0a0000 pid=2588->00d64a87-ce76-56e8-b87c-0dd1888f8452 send: 140B guuid=68b66342-1c00-0000-f1e6-562e380a0000 pid=2616->00d64a87-ce76-56e8-b87c-0dd1888f8452 send: 139B guuid=6a809249-1c00-0000-f1e6-562e520a0000 pid=2642->00d64a87-ce76-56e8-b87c-0dd1888f8452 send: 139B guuid=f0f93250-1c00-0000-f1e6-562e620a0000 pid=2658 /tmp/x-8.6-.dick guuid=1d480650-1c00-0000-f1e6-562e610a0000 pid=2657->guuid=f0f93250-1c00-0000-f1e6-562e620a0000 pid=2658 clone guuid=3df13850-1c00-0000-f1e6-562e630a0000 pid=2659 /tmp/x-8.6-.dick zombie guuid=1d480650-1c00-0000-f1e6-562e610a0000 pid=2657->guuid=3df13850-1c00-0000-f1e6-562e630a0000 pid=2659 clone guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660 /tmp/x-8.6-.dick delete-file write-config zombie guuid=3df13850-1c00-0000-f1e6-562e630a0000 pid=2659->guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660 clone guuid=a3bab350-1c00-0000-f1e6-562e670a0000 pid=2663 /usr/bin/dash guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660->guuid=a3bab350-1c00-0000-f1e6-562e670a0000 pid=2663 execve guuid=009a7d51-1c00-0000-f1e6-562e6f0a0000 pid=2671 /usr/bin/dash guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660->guuid=009a7d51-1c00-0000-f1e6-562e6f0a0000 pid=2671 execve guuid=003fbf51-1c00-0000-f1e6-562e710a0000 pid=2673 /tmp/x-8.6-.dick guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660->guuid=003fbf51-1c00-0000-f1e6-562e710a0000 pid=2673 clone guuid=9a1ac751-1c00-0000-f1e6-562e720a0000 pid=2674 /tmp/x-8.6-.dick dns net send-data guuid=33324550-1c00-0000-f1e6-562e640a0000 pid=2660->guuid=9a1ac751-1c00-0000-f1e6-562e720a0000 pid=2674 clone guuid=0fbaf750-1c00-0000-f1e6-562e6b0a0000 pid=2667 /usr/bin/cp guuid=a3bab350-1c00-0000-f1e6-562e670a0000 pid=2663->guuid=0fbaf750-1c00-0000-f1e6-562e6b0a0000 pid=2667 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9a1ac751-1c00-0000-f1e6-562e720a0000 pid=2674->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 36B 40570245-e1d5-575f-adf1-34212482cbed definitely-not.gay:9118 guuid=9a1ac751-1c00-0000-f1e6-562e720a0000 pid=2674->40570245-e1d5-575f-adf1-34212482cbed con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-06-14 16:31:21 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8ed925e948b20635a5b6761edc4e4d522cb77d32a5403cbff28a9ebbf27721e2

(this sample)

  
Delivery method
Distributed via web download

Comments