MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b61c91545ce49c9751531e8a8043f4aa113550679d5ddc7bb29b451bc4a452d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 3 File information Comments

SHA256 hash: b61c91545ce49c9751531e8a8043f4aa113550679d5ddc7bb29b451bc4a452d2
SHA3-384 hash: e91e0ef78853bff4a05df6565fa680803e913bb8e37bfedb7843609f9025e6461f3d8c537898184b2e0520d001f1826c
SHA1 hash: 8d62c5e10ff1ba8bf514929939cf239eaa13848b
MD5 hash: 610012cb3283f6f6a65cb79cbc568f2c
humanhash: tennis-asparagus-lactose-nebraska
File name:Ciabins.sh
Download: download sample
Signature Mirai
File size:1'954 bytes
First seen:2026-06-09 13:50:37 UTC
Last seen:2026-06-10 00:09:15 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vtwtkt1atItchtPLsft7Atkttjg11JtMttU3CGttdUvpLttmhEqJttn76Zc:vmqvaWGh9LsfRA66qjU3CGjdUvpLjmhh
TLSH T120412FCB61924975BEA0ED6B31AE484D33C0A5EB90DFEF645CDC34E4809FE987404697
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.183.232.247/CRY.mips3a56ce727e772c89bd75eb6c5fbb029f19b89d73bd22865b0d4dfdf32448532b Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.mipseln/an/aelf opendir ua-wget
http://94.183.232.247/CRY.sh487218d3a50595e89c351f16eea6b4e3c5dbb6f1251fe2ca0369493baa46f7556 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.x86f997453517af9a39f3fb2264c1742bc710307305787ab4cdc2e7d470d58c71ba Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.i686n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.ppc42c982251c083492949a37c78bad1af1370c79ea4c842a212d1d51d2015fa821 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.i586n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.m68kn/an/aelf mirai opendir ua-wget
http://94.183.232.247/CRY.sparcn/an/aelf opendir ua-wget
http://94.183.232.247/CRY.arcddddae35387b65d0fc7757550aab9bd967f9601042982c06647590617c28b97a Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm4n/an/aelf opendir ua-wget
http://94.183.232.247/CRY.arm57f07a1fb09ec75adf79dc878f15485e03aadcbe8d8b0717135c769b7d41ae7ef Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm66cebdb60882f724b6b3666897054603fbacd69f3369599ad40ae43e4a1bea880 Miraielf mirai opendir ua-wget
http://94.183.232.247/CRY.arm766b11ec69ec5f5e72b5377820cd8cc3ff7d68918daad4c247ccf8dd556ba2b9b Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-09T11:01:00Z UTC
Last seen:
2026-06-09T11:15:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5a353602-1700-0000-7481-13a3470c0000 pid=3143 /usr/bin/sudo guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148 /tmp/sample.bin guuid=5a353602-1700-0000-7481-13a3470c0000 pid=3143->guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148 execve guuid=55bf1b05-1700-0000-7481-13a34f0c0000 pid=3151 /usr/bin/wget net send-data write-file guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=55bf1b05-1700-0000-7481-13a34f0c0000 pid=3151 execve guuid=2b31382e-1700-0000-7481-13a38c0c0000 pid=3212 /usr/bin/chmod guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=2b31382e-1700-0000-7481-13a38c0c0000 pid=3212 execve guuid=9c7d792e-1700-0000-7481-13a38f0c0000 pid=3215 /usr/bin/bash guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=9c7d792e-1700-0000-7481-13a38f0c0000 pid=3215 clone guuid=892c142f-1700-0000-7481-13a3930c0000 pid=3219 /usr/bin/rm delete-file guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=892c142f-1700-0000-7481-13a3930c0000 pid=3219 execve guuid=78465e2f-1700-0000-7481-13a3950c0000 pid=3221 /usr/bin/wget net send-data guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=78465e2f-1700-0000-7481-13a3950c0000 pid=3221 execve guuid=a7c4e23e-1700-0000-7481-13a3a50c0000 pid=3237 /usr/bin/chmod guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=a7c4e23e-1700-0000-7481-13a3a50c0000 pid=3237 execve guuid=8a90953f-1700-0000-7481-13a3a60c0000 pid=3238 /usr/bin/bash guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=8a90953f-1700-0000-7481-13a3a60c0000 pid=3238 clone guuid=2742cf3f-1700-0000-7481-13a3a70c0000 pid=3239 /usr/bin/rm guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=2742cf3f-1700-0000-7481-13a3a70c0000 pid=3239 execve guuid=60e02540-1700-0000-7481-13a3a90c0000 pid=3241 /usr/bin/wget net send-data write-file guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=60e02540-1700-0000-7481-13a3a90c0000 pid=3241 execve guuid=ba967f64-1700-0000-7481-13a3dd0c0000 pid=3293 /usr/bin/chmod guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=ba967f64-1700-0000-7481-13a3dd0c0000 pid=3293 execve guuid=701f2865-1700-0000-7481-13a3de0c0000 pid=3294 /usr/bin/bash guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=701f2865-1700-0000-7481-13a3de0c0000 pid=3294 clone guuid=71925066-1700-0000-7481-13a3e10c0000 pid=3297 /usr/bin/rm delete-file guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=71925066-1700-0000-7481-13a3e10c0000 pid=3297 execve guuid=add0c366-1700-0000-7481-13a3e30c0000 pid=3299 /usr/bin/wget net send-data write-file guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=add0c366-1700-0000-7481-13a3e30c0000 pid=3299 execve guuid=ecd2cc8c-1700-0000-7481-13a3110d0000 pid=3345 /usr/bin/chmod guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=ecd2cc8c-1700-0000-7481-13a3110d0000 pid=3345 execve guuid=661b1d8d-1700-0000-7481-13a3120d0000 pid=3346 /tmp/CRY.x86 net send-data guuid=5979a304-1700-0000-7481-13a34c0c0000 pid=3148->guuid=661b1d8d-1700-0000-7481-13a3120d0000 pid=3346 execve 3c08363b-4c05-5247-9298-7388a6812181 94.183.232.247:80 guuid=55bf1b05-1700-0000-7481-13a34f0c0000 pid=3151->3c08363b-4c05-5247-9298-7388a6812181 send: 137B guuid=78465e2f-1700-0000-7481-13a3950c0000 pid=3221->3c08363b-4c05-5247-9298-7388a6812181 send: 139B guuid=60e02540-1700-0000-7481-13a3a90c0000 pid=3241->3c08363b-4c05-5247-9298-7388a6812181 send: 136B guuid=add0c366-1700-0000-7481-13a3e30c0000 pid=3299->3c08363b-4c05-5247-9298-7388a6812181 send: 136B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=661b1d8d-1700-0000-7481-13a3120d0000 pid=3346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 2e545346-5d00-5451-a084-ebe2099cc359 185.31.200.8:2139 guuid=661b1d8d-1700-0000-7481-13a3120d0000 pid=3346->2e545346-5d00-5451-a084-ebe2099cc359 send: 34B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-06-09 13:51:49 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
discovery linux
Behaviour
System Network Configuration Discovery
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b61c91545ce49c9751531e8a8043f4aa113550679d5ddc7bb29b451bc4a452d2

(this sample)

  
Delivery method
Distributed via web download

Comments