MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9fce1578d0305981889ee6a62e114fef925d263b2ed93500b532a6ecf50f0bdb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: 9fce1578d0305981889ee6a62e114fef925d263b2ed93500b532a6ecf50f0bdb
SHA3-384 hash: f8ec49b3c8084cc10e506363f7e6ecfc6d487749c8728ca677b7654a7651d41882499bbb9df73b9f22bb5fdb96f695e4
SHA1 hash: a2997f004ae488ba9cffadabeec984517f16020a
MD5 hash: bb81eca867f91d05929cff72d6694c48
humanhash: alpha-sixteen-bacon-uniform
File name:lg
Download: download sample
Signature Mirai
File size:2'793 bytes
First seen:2026-02-03 16:40:16 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vzyucz3Ucz58czHwczBwczdudzEczoCczR8czKuczLMczH+cz7x7UfczAuczjWf:vzyucz3Ucz58czHwczBwczM9EczoCczu
TLSH T172518CC832204BB5BFB15992B6F585167489E0D1AEC74EC9E2FC68FE014CF096C916A6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.106.177/bins/sora.x86e9e378387a21bdfc4c1f424ec79a209ceba05d1f0919d6dca05e5623e3f941fd Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.mips5e74a50c9255cda93e51e37903260477800d9aac1301e8447a8793a83529c07a Mirai32-bit elf mirai Mozi
http://94.26.106.177/bins/sora.x86_649494683239ff99d86db9145ddd361c5014eef8506c720ef34bae542b1f140c88 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.i468n/an/an/a
http://94.26.106.177/bins/sora.i68628d2d9759823d69e7fc46485b53a413b38ef2f8ff504dd397b6726c21c5dcd19 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.mpslc62afaff80ce42bd7e8f6f3b66e45da9a3b36d00fcd630936d28fbce2c9d8f26 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm4n/an/an/a
http://94.26.106.177/bins/sora.arm5681c788f1f1c6beb7f7ef7dce47c3971dbb506c5ce58a0caedbb7999efb9bd66 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm69633a560c9e528465418f37cb0111f6cbda015a4b46f4ab2efe27eaa0b75413b Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm7n/an/an/a
http://94.26.106.177/bins/sora.ppcf67c66b6e0cf80b0546171bc249b825601f1078f0df6fb18402441eba65ad610 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.ppc440fpn/an/an/a
http://94.26.106.177/bins/sora.m68k482fe1c5adf10b2feb46d79a6ba89ac5865e73fda816738642d61c03e2149e07 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.sh4be6d52de33de60fd6d03fc14a719eea4b605519b22370321e44acd102ba7447c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=b7c45e08-1e00-0000-bb6c-6ed8860b0000 pid=2950 /usr/bin/sudo guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952 /tmp/sample.bin guuid=b7c45e08-1e00-0000-bb6c-6ed8860b0000 pid=2950->guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952 execve guuid=87dcae0c-1e00-0000-bb6c-6ed8890b0000 pid=2953 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=87dcae0c-1e00-0000-bb6c-6ed8890b0000 pid=2953 execve guuid=e3245412-1e00-0000-bb6c-6ed8910b0000 pid=2961 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=e3245412-1e00-0000-bb6c-6ed8910b0000 pid=2961 execve guuid=2556801f-1e00-0000-bb6c-6ed8a50b0000 pid=2981 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=2556801f-1e00-0000-bb6c-6ed8a50b0000 pid=2981 execve guuid=a409ea1f-1e00-0000-bb6c-6ed8a70b0000 pid=2983 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a409ea1f-1e00-0000-bb6c-6ed8a70b0000 pid=2983 execve guuid=59fe3d20-1e00-0000-bb6c-6ed8a90b0000 pid=2985 /tmp/robben net guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=59fe3d20-1e00-0000-bb6c-6ed8a90b0000 pid=2985 execve guuid=57f1ca23-1e00-0000-bb6c-6ed8b40b0000 pid=2996 /usr/bin/wget net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=57f1ca23-1e00-0000-bb6c-6ed8b40b0000 pid=2996 execve guuid=6df5cf27-1e00-0000-bb6c-6ed8be0b0000 pid=3006 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=6df5cf27-1e00-0000-bb6c-6ed8be0b0000 pid=3006 execve guuid=f34a9c2e-1e00-0000-bb6c-6ed8c90b0000 pid=3017 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=f34a9c2e-1e00-0000-bb6c-6ed8c90b0000 pid=3017 execve guuid=1e31112f-1e00-0000-bb6c-6ed8cc0b0000 pid=3020 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=1e31112f-1e00-0000-bb6c-6ed8cc0b0000 pid=3020 execve guuid=598d8d2f-1e00-0000-bb6c-6ed8cf0b0000 pid=3023 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=598d8d2f-1e00-0000-bb6c-6ed8cf0b0000 pid=3023 clone guuid=ee5eb82f-1e00-0000-bb6c-6ed8d00b0000 pid=3024 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=ee5eb82f-1e00-0000-bb6c-6ed8d00b0000 pid=3024 execve guuid=14195535-1e00-0000-bb6c-6ed8e00b0000 pid=3040 /usr/bin/curl net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=14195535-1e00-0000-bb6c-6ed8e00b0000 pid=3040 execve guuid=5cec7738-1e00-0000-bb6c-6ed8e70b0000 pid=3047 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=5cec7738-1e00-0000-bb6c-6ed8e70b0000 pid=3047 execve guuid=1dcff438-1e00-0000-bb6c-6ed8e90b0000 pid=3049 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=1dcff438-1e00-0000-bb6c-6ed8e90b0000 pid=3049 execve guuid=662f3f39-1e00-0000-bb6c-6ed8eb0b0000 pid=3051 /tmp/robben mprotect-exec net guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=662f3f39-1e00-0000-bb6c-6ed8eb0b0000 pid=3051 execve guuid=52bd263d-1e00-0000-bb6c-6ed8f00b0000 pid=3056 /usr/bin/wget net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=52bd263d-1e00-0000-bb6c-6ed8f00b0000 pid=3056 execve guuid=5aa15141-1e00-0000-bb6c-6ed8f70b0000 pid=3063 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=5aa15141-1e00-0000-bb6c-6ed8f70b0000 pid=3063 execve guuid=c16cf746-1e00-0000-bb6c-6ed8040c0000 pid=3076 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=c16cf746-1e00-0000-bb6c-6ed8040c0000 pid=3076 execve guuid=db96ac47-1e00-0000-bb6c-6ed8060c0000 pid=3078 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=db96ac47-1e00-0000-bb6c-6ed8060c0000 pid=3078 execve guuid=7d006248-1e00-0000-bb6c-6ed8070c0000 pid=3079 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=7d006248-1e00-0000-bb6c-6ed8070c0000 pid=3079 clone guuid=2eb0ea48-1e00-0000-bb6c-6ed8090c0000 pid=3081 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=2eb0ea48-1e00-0000-bb6c-6ed8090c0000 pid=3081 execve guuid=a9666150-1e00-0000-bb6c-6ed8150c0000 pid=3093 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a9666150-1e00-0000-bb6c-6ed8150c0000 pid=3093 execve guuid=a42eb257-1e00-0000-bb6c-6ed8260c0000 pid=3110 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a42eb257-1e00-0000-bb6c-6ed8260c0000 pid=3110 execve guuid=bc19ff57-1e00-0000-bb6c-6ed8270c0000 pid=3111 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=bc19ff57-1e00-0000-bb6c-6ed8270c0000 pid=3111 execve guuid=dac07b58-1e00-0000-bb6c-6ed82a0c0000 pid=3114 /tmp/robben net guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=dac07b58-1e00-0000-bb6c-6ed82a0c0000 pid=3114 execve guuid=a14ce75c-1e00-0000-bb6c-6ed8380c0000 pid=3128 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a14ce75c-1e00-0000-bb6c-6ed8380c0000 pid=3128 execve guuid=c14ec662-1e00-0000-bb6c-6ed8420c0000 pid=3138 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=c14ec662-1e00-0000-bb6c-6ed8420c0000 pid=3138 execve guuid=d2899669-1e00-0000-bb6c-6ed8500c0000 pid=3152 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=d2899669-1e00-0000-bb6c-6ed8500c0000 pid=3152 execve guuid=d5991e6a-1e00-0000-bb6c-6ed8510c0000 pid=3153 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=d5991e6a-1e00-0000-bb6c-6ed8510c0000 pid=3153 execve guuid=0425696a-1e00-0000-bb6c-6ed8520c0000 pid=3154 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=0425696a-1e00-0000-bb6c-6ed8520c0000 pid=3154 clone guuid=2d9b1f6b-1e00-0000-bb6c-6ed8540c0000 pid=3156 /usr/bin/wget net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=2d9b1f6b-1e00-0000-bb6c-6ed8540c0000 pid=3156 execve guuid=7056f46e-1e00-0000-bb6c-6ed8560c0000 pid=3158 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=7056f46e-1e00-0000-bb6c-6ed8560c0000 pid=3158 execve guuid=9b304475-1e00-0000-bb6c-6ed8640c0000 pid=3172 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=9b304475-1e00-0000-bb6c-6ed8640c0000 pid=3172 execve guuid=2822b075-1e00-0000-bb6c-6ed8660c0000 pid=3174 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=2822b075-1e00-0000-bb6c-6ed8660c0000 pid=3174 execve guuid=b6f11276-1e00-0000-bb6c-6ed8680c0000 pid=3176 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=b6f11276-1e00-0000-bb6c-6ed8680c0000 pid=3176 clone guuid=40c83d76-1e00-0000-bb6c-6ed8690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=40c83d76-1e00-0000-bb6c-6ed8690c0000 pid=3177 execve guuid=190ff47c-1e00-0000-bb6c-6ed87c0c0000 pid=3196 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=190ff47c-1e00-0000-bb6c-6ed87c0c0000 pid=3196 execve guuid=44fe6d86-1e00-0000-bb6c-6ed8940c0000 pid=3220 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=44fe6d86-1e00-0000-bb6c-6ed8940c0000 pid=3220 execve guuid=ac93f086-1e00-0000-bb6c-6ed8960c0000 pid=3222 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=ac93f086-1e00-0000-bb6c-6ed8960c0000 pid=3222 execve guuid=a0546787-1e00-0000-bb6c-6ed8980c0000 pid=3224 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a0546787-1e00-0000-bb6c-6ed8980c0000 pid=3224 clone guuid=73217c88-1e00-0000-bb6c-6ed89d0c0000 pid=3229 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=73217c88-1e00-0000-bb6c-6ed89d0c0000 pid=3229 execve guuid=00962b8e-1e00-0000-bb6c-6ed8a70c0000 pid=3239 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=00962b8e-1e00-0000-bb6c-6ed8a70c0000 pid=3239 execve guuid=67673a94-1e00-0000-bb6c-6ed8b50c0000 pid=3253 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=67673a94-1e00-0000-bb6c-6ed8b50c0000 pid=3253 execve guuid=0d4eb094-1e00-0000-bb6c-6ed8b60c0000 pid=3254 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=0d4eb094-1e00-0000-bb6c-6ed8b60c0000 pid=3254 execve guuid=a8dc1595-1e00-0000-bb6c-6ed8b70c0000 pid=3255 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a8dc1595-1e00-0000-bb6c-6ed8b70c0000 pid=3255 clone guuid=0f68d395-1e00-0000-bb6c-6ed8b90c0000 pid=3257 /usr/bin/wget net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=0f68d395-1e00-0000-bb6c-6ed8b90c0000 pid=3257 execve guuid=daabd598-1e00-0000-bb6c-6ed8ba0c0000 pid=3258 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=daabd598-1e00-0000-bb6c-6ed8ba0c0000 pid=3258 execve guuid=7f290d9f-1e00-0000-bb6c-6ed8bb0c0000 pid=3259 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=7f290d9f-1e00-0000-bb6c-6ed8bb0c0000 pid=3259 execve guuid=9419679f-1e00-0000-bb6c-6ed8bc0c0000 pid=3260 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=9419679f-1e00-0000-bb6c-6ed8bc0c0000 pid=3260 execve guuid=615316a0-1e00-0000-bb6c-6ed8be0c0000 pid=3262 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=615316a0-1e00-0000-bb6c-6ed8be0c0000 pid=3262 clone guuid=62815ba0-1e00-0000-bb6c-6ed8bf0c0000 pid=3263 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=62815ba0-1e00-0000-bb6c-6ed8bf0c0000 pid=3263 execve guuid=cc28c8a5-1e00-0000-bb6c-6ed8c90c0000 pid=3273 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=cc28c8a5-1e00-0000-bb6c-6ed8c90c0000 pid=3273 execve guuid=4c9006ae-1e00-0000-bb6c-6ed8da0c0000 pid=3290 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=4c9006ae-1e00-0000-bb6c-6ed8da0c0000 pid=3290 execve guuid=a19098ae-1e00-0000-bb6c-6ed8dc0c0000 pid=3292 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=a19098ae-1e00-0000-bb6c-6ed8dc0c0000 pid=3292 execve guuid=77c8dfae-1e00-0000-bb6c-6ed8dd0c0000 pid=3293 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=77c8dfae-1e00-0000-bb6c-6ed8dd0c0000 pid=3293 clone guuid=f13084af-1e00-0000-bb6c-6ed8e10c0000 pid=3297 /usr/bin/wget net send-data guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=f13084af-1e00-0000-bb6c-6ed8e10c0000 pid=3297 execve guuid=db35edb2-1e00-0000-bb6c-6ed8e90c0000 pid=3305 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=db35edb2-1e00-0000-bb6c-6ed8e90c0000 pid=3305 execve guuid=1a4be7bb-1e00-0000-bb6c-6ed8ea0c0000 pid=3306 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=1a4be7bb-1e00-0000-bb6c-6ed8ea0c0000 pid=3306 execve guuid=7a73a7bc-1e00-0000-bb6c-6ed8eb0c0000 pid=3307 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=7a73a7bc-1e00-0000-bb6c-6ed8eb0c0000 pid=3307 execve guuid=2ec835bd-1e00-0000-bb6c-6ed8ec0c0000 pid=3308 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=2ec835bd-1e00-0000-bb6c-6ed8ec0c0000 pid=3308 clone guuid=bdf484bd-1e00-0000-bb6c-6ed8ed0c0000 pid=3309 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=bdf484bd-1e00-0000-bb6c-6ed8ed0c0000 pid=3309 execve guuid=e3921fc9-1e00-0000-bb6c-6ed8ee0c0000 pid=3310 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=e3921fc9-1e00-0000-bb6c-6ed8ee0c0000 pid=3310 execve guuid=20a5c8d5-1e00-0000-bb6c-6ed8f60c0000 pid=3318 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=20a5c8d5-1e00-0000-bb6c-6ed8f60c0000 pid=3318 execve guuid=c01f5cd6-1e00-0000-bb6c-6ed8f80c0000 pid=3320 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=c01f5cd6-1e00-0000-bb6c-6ed8f80c0000 pid=3320 execve guuid=4755ebd6-1e00-0000-bb6c-6ed8f90c0000 pid=3321 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=4755ebd6-1e00-0000-bb6c-6ed8f90c0000 pid=3321 clone guuid=d15b1dd8-1e00-0000-bb6c-6ed8fb0c0000 pid=3323 /usr/bin/wget net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=d15b1dd8-1e00-0000-bb6c-6ed8fb0c0000 pid=3323 execve guuid=7d8099dd-1e00-0000-bb6c-6ed8030d0000 pid=3331 /usr/bin/curl net send-data write-file guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=7d8099dd-1e00-0000-bb6c-6ed8030d0000 pid=3331 execve guuid=035013e6-1e00-0000-bb6c-6ed80a0d0000 pid=3338 /usr/bin/cat guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=035013e6-1e00-0000-bb6c-6ed80a0d0000 pid=3338 execve guuid=76fdb5e6-1e00-0000-bb6c-6ed80b0d0000 pid=3339 /usr/bin/chmod guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=76fdb5e6-1e00-0000-bb6c-6ed80b0d0000 pid=3339 execve guuid=fe2b1de7-1e00-0000-bb6c-6ed80c0d0000 pid=3340 /usr/bin/bash guuid=96f4f80b-1e00-0000-bb6c-6ed8880b0000 pid=2952->guuid=fe2b1de7-1e00-0000-bb6c-6ed80c0d0000 pid=3340 clone c0a32311-821d-5a61-9890-a16269c49685 94.26.106.177:80 guuid=87dcae0c-1e00-0000-bb6c-6ed8890b0000 pid=2953->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=e3245412-1e00-0000-bb6c-6ed8910b0000 pid=2961->c0a32311-821d-5a61-9890-a16269c49685 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=59fe3d20-1e00-0000-bb6c-6ed8a90b0000 pid=2985->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=57f1ca23-1e00-0000-bb6c-6ed8b40b0000 pid=2996->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=6df5cf27-1e00-0000-bb6c-6ed8be0b0000 pid=3006->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=ee5eb82f-1e00-0000-bb6c-6ed8d00b0000 pid=3024->c0a32311-821d-5a61-9890-a16269c49685 send: 144B guuid=14195535-1e00-0000-bb6c-6ed8e00b0000 pid=3040->c0a32311-821d-5a61-9890-a16269c49685 send: 93B guuid=662f3f39-1e00-0000-bb6c-6ed8eb0b0000 pid=3051->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=52bd263d-1e00-0000-bb6c-6ed8f00b0000 pid=3056->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=5aa15141-1e00-0000-bb6c-6ed8f70b0000 pid=3063->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=2eb0ea48-1e00-0000-bb6c-6ed8090c0000 pid=3081->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=a9666150-1e00-0000-bb6c-6ed8150c0000 pid=3093->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=dac07b58-1e00-0000-bb6c-6ed82a0c0000 pid=3114->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a14ce75c-1e00-0000-bb6c-6ed8380c0000 pid=3128->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=c14ec662-1e00-0000-bb6c-6ed8420c0000 pid=3138->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=2d9b1f6b-1e00-0000-bb6c-6ed8540c0000 pid=3156->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=7056f46e-1e00-0000-bb6c-6ed8560c0000 pid=3158->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=40c83d76-1e00-0000-bb6c-6ed8690c0000 pid=3177->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=190ff47c-1e00-0000-bb6c-6ed87c0c0000 pid=3196->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=73217c88-1e00-0000-bb6c-6ed89d0c0000 pid=3229->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=00962b8e-1e00-0000-bb6c-6ed8a70c0000 pid=3239->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=0f68d395-1e00-0000-bb6c-6ed8b90c0000 pid=3257->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=daabd598-1e00-0000-bb6c-6ed8ba0c0000 pid=3258->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=62815ba0-1e00-0000-bb6c-6ed8bf0c0000 pid=3263->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=cc28c8a5-1e00-0000-bb6c-6ed8c90c0000 pid=3273->c0a32311-821d-5a61-9890-a16269c49685 send: 90B guuid=f13084af-1e00-0000-bb6c-6ed8e10c0000 pid=3297->c0a32311-821d-5a61-9890-a16269c49685 send: 146B guuid=db35edb2-1e00-0000-bb6c-6ed8e90c0000 pid=3305->c0a32311-821d-5a61-9890-a16269c49685 send: 95B guuid=bdf484bd-1e00-0000-bb6c-6ed8ed0c0000 pid=3309->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=e3921fc9-1e00-0000-bb6c-6ed8ee0c0000 pid=3310->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=d15b1dd8-1e00-0000-bb6c-6ed8fb0c0000 pid=3323->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=7d8099dd-1e00-0000-bb6c-6ed8030d0000 pid=3331->c0a32311-821d-5a61-9890-a16269c49685 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-02-03 16:34:21 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9fce1578d0305981889ee6a62e114fef925d263b2ed93500b532a6ecf50f0bdb

(this sample)

  
Delivery method
Distributed via web download

Comments