🤲🏼 NEW | abuse.ch Community Hub! Earn recognition 🏅 for the malware intelligence you share, climb the leaderboards 📈, and connect with like-minded contributors who share your hunting focus 🤝. Ready to unlock your profile? Go to the Community Hub →

MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a01ff2bc22326ab8d47d2d7119a0051097537ff6f8032ea6d60ee678f52dbdfa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: a01ff2bc22326ab8d47d2d7119a0051097537ff6f8032ea6d60ee678f52dbdfa
SHA3-384 hash: c5258515bc18a5494067ced07bf3829f333ebf6f0b3943a277140073408e32278129790c86b857e4505288d87bfb454f
SHA1 hash: b0345110464e6fe52976079645ce085ec3248cb1
MD5 hash: 7c904c925055359b3ee8599f907aa0d2
humanhash: diet-happy-emma-tango
File name:all.sh
Download: download sample
Signature Mirai
File size:2'542 bytes
First seen:2026-09-04 08:20:21 UTC
Last seen:2026-09-04 08:43:41 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:OYBzOqaaYBnOO9BAOfMBHKAOwEBDO6NBkOjCBFOwCBtOorBiO11lSBZOks3BdOYw:OcS5hOA9oktCk5ak7s0PBuAXR8LJ3LFr
TLSH T1385144F62726673381AF8AE697E2574AA04540537CD80BF0FBEC65103F56FD9BC8A501
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://180.93.111.142/00101010101001/morte.x86_64be1446c301864eec216c8c8743beba0f256e69b3777d641a43d155146ce3507d Miraiua-wget
http://180.93.111.142/00101010101001/morte.i686579f6321bc4b7db08932c8e3b84f8ec54cf898d35c3dda976b062a923d377190 Miraiua-wget
http://180.93.111.142/00101010101001/morte.x86n/an/aua-wget
http://180.93.111.142/00101010101001/morte.arm75196899532a56e73454398678e30c3f4d1091f084a861d36b6213b0a529e4c4f Miraiua-wget
http://180.93.111.142/00101010101001/morte.arm57f2877c0400dcaf354e7de2848461abd959ad5d56f86d0e69fa7644ffa1287da Miraiua-wget
http://180.93.111.142/00101010101001/morte.armn/an/aua-wget
http://180.93.111.142/00101010101001/morte.aarch64n/an/aua-wget
http://180.93.111.142/00101010101001/morte.mipsf348ecd809cf4663af8eec9373b57efcb807ec949134de96bfa3f055f6486b44 Miraiua-wget
http://180.93.111.142/00101010101001/morte.mpsl969dddce3ec20d51407ed27ed133622f8b650539d46d44b685e8b33e42335fae Miraiua-wget
http://180.93.111.142/00101010101001/morte.ppcf4eecad1c42f85b730e07959ade99e821d4b827cc77d0be9d76d0e34fd9fc7d8 Miraiua-wget
http://180.93.111.142/00101010101001/morte.sh4n/an/aua-wget
http://180.93.111.142/00101010101001/morte.spcn/an/aua-wget
http://180.93.111.142/00101010101001/morte.m68k1db8123fc4841223d6a5fb9b08368ad7d67ab5d6d6c9f89e234bcb08b4706f2b Miraiua-wget
http://180.93.111.142/00101010101001/morte.arc8f7791b74e0b504e7c62fc6a8211eb222957d33a1f264189e421269bbe0004cb Miraiua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
75
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=02893bcc-1900-0000-8a06-d957d40d0000 pid=3540 /usr/bin/sudo guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553 /tmp/sample.bin guuid=02893bcc-1900-0000-8a06-d957d40d0000 pid=3540->guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553 execve guuid=dbae46d1-1900-0000-8a06-d957e20d0000 pid=3554 /usr/bin/uname guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=dbae46d1-1900-0000-8a06-d957e20d0000 pid=3554 execve guuid=5564e2d1-1900-0000-8a06-d957e30d0000 pid=3555 /usr/bin/wget net send-data write-file guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=5564e2d1-1900-0000-8a06-d957e30d0000 pid=3555 execve guuid=481a8a0b-1a00-0000-8a06-d9577b0e0000 pid=3707 /usr/bin/chmod guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=481a8a0b-1a00-0000-8a06-d9577b0e0000 pid=3707 execve guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709 /tmp/morte net guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709 execve guuid=ffb64237-1b00-0000-8a06-d957f2110000 pid=4594 /usr/bin/bash guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=ffb64237-1b00-0000-8a06-d957f2110000 pid=4594 clone guuid=610f6937-1b00-0000-8a06-d957f3110000 pid=4595 /usr/bin/chmod guuid=eb57eccf-1900-0000-8a06-d957e10d0000 pid=3553->guuid=610f6937-1b00-0000-8a06-d957f3110000 pid=4595 execve 5533afd5-20a9-51f0-b7e0-6dba5cb42610 180.93.111.142:80 guuid=5564e2d1-1900-0000-8a06-d957e30d0000 pid=3555->5533afd5-20a9-51f0-b7e0-6dba5cb42610 send: 156B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5f93410c-1a00-0000-8a06-d9577f0e0000 pid=3711 /tmp/morte guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709->guuid=5f93410c-1a00-0000-8a06-d9577f0e0000 pid=3711 clone guuid=c9d63237-1b00-0000-8a06-d957f0110000 pid=4592 /tmp/morte guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709->guuid=c9d63237-1b00-0000-8a06-d957f0110000 pid=4592 clone guuid=f8bc3737-1b00-0000-8a06-d957f1110000 pid=4593 /tmp/morte dns net send-data zombie guuid=b866290c-1a00-0000-8a06-d9577d0e0000 pid=3709->guuid=f8bc3737-1b00-0000-8a06-d957f1110000 pid=4593 clone guuid=1b12490c-1a00-0000-8a06-d957800e0000 pid=3712 /tmp/morte guuid=5f93410c-1a00-0000-8a06-d9577f0e0000 pid=3711->guuid=1b12490c-1a00-0000-8a06-d957800e0000 pid=3712 clone guuid=9ffe560c-1a00-0000-8a06-d957810e0000 pid=3713 /tmp/morte dns net send-data zombie guuid=5f93410c-1a00-0000-8a06-d9577f0e0000 pid=3711->guuid=9ffe560c-1a00-0000-8a06-d957810e0000 pid=3713 clone guuid=9ffe560c-1a00-0000-8a06-d957810e0000 pid=3713->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 960B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=9ffe560c-1a00-0000-8a06-d957810e0000 pid=3713->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 4B guuid=f8bc3737-1b00-0000-8a06-d957f1110000 pid=4593->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 800B guuid=f8bc3737-1b00-0000-8a06-d957f1110000 pid=4593->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B
Threat name:
Script-BAT.Downloader.Heuristic
Status:
Malicious
First seen:
2026-09-04 08:21:21 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a01ff2bc22326ab8d47d2d7119a0051097537ff6f8032ea6d60ee678f52dbdfa

(this sample)

  
Delivery method
Distributed via web download

Comments