MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c0469c8400de5b76b99f26aa982023f483df42781813ebbbdaf4e4013d8fdabd. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA 2 File information Comments

SHA256 hash: c0469c8400de5b76b99f26aa982023f483df42781813ebbbdaf4e4013d8fdabd
SHA3-384 hash: 88dd505582b8d169e53519bb162debb01fff719eab5de391c7111acc16c8039ad60274a6475ec5c1eb7fac25a9b64704
SHA1 hash: a82b9f2b9ae10374b182fdd285b74c925daa4704
MD5 hash: 743ac21cf9245397dae9fbfcce1c6c20
humanhash: july-sierra-eleven-california
File name:goahead
Download: download sample
Signature Mirai
File size:2'863 bytes
First seen:2026-02-03 16:40:17 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vzyuoz3Uoz58ozHwozBwozdudzEozoCozR8ozKuozLMozH+oz7x7UfozAuozjWL:vzyuoz3Uoz58ozHwozBwozM9EozoCozE
TLSH T11D5193C532254BB8AFB15D97B6F540057485A0D2AEC74ECAE2FC64FE018CF096C926B7
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://94.26.106.177/bins/sora.x86e9e378387a21bdfc4c1f424ec79a209ceba05d1f0919d6dca05e5623e3f941fd Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.mips5e74a50c9255cda93e51e37903260477800d9aac1301e8447a8793a83529c07a Mirai32-bit elf mirai Mozi
http://94.26.106.177/bins/sora.x86_649494683239ff99d86db9145ddd361c5014eef8506c720ef34bae542b1f140c88 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.i468n/an/an/a
http://94.26.106.177/bins/sora.i68628d2d9759823d69e7fc46485b53a413b38ef2f8ff504dd397b6726c21c5dcd19 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.mpslc62afaff80ce42bd7e8f6f3b66e45da9a3b36d00fcd630936d28fbce2c9d8f26 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm4n/an/an/a
http://94.26.106.177/bins/sora.arm5681c788f1f1c6beb7f7ef7dce47c3971dbb506c5ce58a0caedbb7999efb9bd66 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm69633a560c9e528465418f37cb0111f6cbda015a4b46f4ab2efe27eaa0b75413b Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.arm7n/an/an/a
http://94.26.106.177/bins/sora.ppcf67c66b6e0cf80b0546171bc249b825601f1078f0df6fb18402441eba65ad610 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.ppc440fpn/an/an/a
http://94.26.106.177/bins/sora.m68k482fe1c5adf10b2feb46d79a6ba89ac5865e73fda816738642d61c03e2149e07 Miraielf mirai ua-wget
http://94.26.106.177/bins/sora.sh4be6d52de33de60fd6d03fc14a719eea4b605519b22370321e44acd102ba7447c Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=8701c469-1b00-0000-70af-7ea88f0c0000 pid=3215 /usr/bin/sudo guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216 /tmp/sample.bin guuid=8701c469-1b00-0000-70af-7ea88f0c0000 pid=3215->guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216 execve guuid=6c24c06c-1b00-0000-70af-7ea8910c0000 pid=3217 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=6c24c06c-1b00-0000-70af-7ea8910c0000 pid=3217 execve guuid=c49aa674-1b00-0000-70af-7ea89a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=c49aa674-1b00-0000-70af-7ea89a0c0000 pid=3226 execve guuid=3b171380-1b00-0000-70af-7ea8a80c0000 pid=3240 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=3b171380-1b00-0000-70af-7ea8a80c0000 pid=3240 execve guuid=1cfa7f80-1b00-0000-70af-7ea8a90c0000 pid=3241 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=1cfa7f80-1b00-0000-70af-7ea8a90c0000 pid=3241 execve guuid=2eb63181-1b00-0000-70af-7ea8aa0c0000 pid=3242 /tmp/robben net guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=2eb63181-1b00-0000-70af-7ea8aa0c0000 pid=3242 execve guuid=8533dc85-1b00-0000-70af-7ea8ac0c0000 pid=3244 /usr/bin/wget net send-data guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=8533dc85-1b00-0000-70af-7ea8ac0c0000 pid=3244 execve guuid=1336cb8a-1b00-0000-70af-7ea8b70c0000 pid=3255 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=1336cb8a-1b00-0000-70af-7ea8b70c0000 pid=3255 execve guuid=660d4591-1b00-0000-70af-7ea8c20c0000 pid=3266 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=660d4591-1b00-0000-70af-7ea8c20c0000 pid=3266 execve guuid=89cebd91-1b00-0000-70af-7ea8c30c0000 pid=3267 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=89cebd91-1b00-0000-70af-7ea8c30c0000 pid=3267 execve guuid=8ffa3692-1b00-0000-70af-7ea8c40c0000 pid=3268 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=8ffa3692-1b00-0000-70af-7ea8c40c0000 pid=3268 clone guuid=2e476e92-1b00-0000-70af-7ea8c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=2e476e92-1b00-0000-70af-7ea8c50c0000 pid=3269 execve guuid=74ac8299-1b00-0000-70af-7ea8cb0c0000 pid=3275 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=74ac8299-1b00-0000-70af-7ea8cb0c0000 pid=3275 execve guuid=eb3647a2-1b00-0000-70af-7ea8df0c0000 pid=3295 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=eb3647a2-1b00-0000-70af-7ea8df0c0000 pid=3295 execve guuid=4b4eb4a2-1b00-0000-70af-7ea8e10c0000 pid=3297 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=4b4eb4a2-1b00-0000-70af-7ea8e10c0000 pid=3297 execve guuid=1381ffa2-1b00-0000-70af-7ea8e30c0000 pid=3299 /tmp/robben mprotect-exec net guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=1381ffa2-1b00-0000-70af-7ea8e30c0000 pid=3299 execve guuid=1063b5a5-1b00-0000-70af-7ea8ec0c0000 pid=3308 /usr/bin/wget net send-data guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=1063b5a5-1b00-0000-70af-7ea8ec0c0000 pid=3308 execve guuid=83e61ba9-1b00-0000-70af-7ea8f10c0000 pid=3313 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=83e61ba9-1b00-0000-70af-7ea8f10c0000 pid=3313 execve guuid=286f2baf-1b00-0000-70af-7ea8fa0c0000 pid=3322 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=286f2baf-1b00-0000-70af-7ea8fa0c0000 pid=3322 execve guuid=498773af-1b00-0000-70af-7ea8fd0c0000 pid=3325 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=498773af-1b00-0000-70af-7ea8fd0c0000 pid=3325 execve guuid=a83badaf-1b00-0000-70af-7ea8fe0c0000 pid=3326 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=a83badaf-1b00-0000-70af-7ea8fe0c0000 pid=3326 clone guuid=453ce2af-1b00-0000-70af-7ea8000d0000 pid=3328 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=453ce2af-1b00-0000-70af-7ea8000d0000 pid=3328 execve guuid=1c6bf6b5-1b00-0000-70af-7ea8120d0000 pid=3346 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=1c6bf6b5-1b00-0000-70af-7ea8120d0000 pid=3346 execve guuid=655eefbc-1b00-0000-70af-7ea8180d0000 pid=3352 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=655eefbc-1b00-0000-70af-7ea8180d0000 pid=3352 execve guuid=98e377bd-1b00-0000-70af-7ea8190d0000 pid=3353 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=98e377bd-1b00-0000-70af-7ea8190d0000 pid=3353 execve guuid=99e01fbe-1b00-0000-70af-7ea81a0d0000 pid=3354 /tmp/robben net guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=99e01fbe-1b00-0000-70af-7ea81a0d0000 pid=3354 execve guuid=44c86ec2-1b00-0000-70af-7ea8210d0000 pid=3361 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=44c86ec2-1b00-0000-70af-7ea8210d0000 pid=3361 execve guuid=e33f52c8-1b00-0000-70af-7ea82e0d0000 pid=3374 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=e33f52c8-1b00-0000-70af-7ea82e0d0000 pid=3374 execve guuid=6f425fcf-1b00-0000-70af-7ea8370d0000 pid=3383 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=6f425fcf-1b00-0000-70af-7ea8370d0000 pid=3383 execve guuid=8d455ad0-1b00-0000-70af-7ea83a0d0000 pid=3386 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=8d455ad0-1b00-0000-70af-7ea83a0d0000 pid=3386 execve guuid=959cb9d0-1b00-0000-70af-7ea83c0d0000 pid=3388 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=959cb9d0-1b00-0000-70af-7ea83c0d0000 pid=3388 clone guuid=37b57dd1-1b00-0000-70af-7ea83f0d0000 pid=3391 /usr/bin/wget net send-data guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=37b57dd1-1b00-0000-70af-7ea83f0d0000 pid=3391 execve guuid=8b6c7ad4-1b00-0000-70af-7ea8460d0000 pid=3398 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=8b6c7ad4-1b00-0000-70af-7ea8460d0000 pid=3398 execve guuid=3027fbd8-1b00-0000-70af-7ea8470d0000 pid=3399 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=3027fbd8-1b00-0000-70af-7ea8470d0000 pid=3399 execve guuid=7cb91cde-1b00-0000-70af-7ea8490d0000 pid=3401 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=7cb91cde-1b00-0000-70af-7ea8490d0000 pid=3401 execve guuid=53ea86de-1b00-0000-70af-7ea84a0d0000 pid=3402 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=53ea86de-1b00-0000-70af-7ea84a0d0000 pid=3402 clone guuid=0e79bdde-1b00-0000-70af-7ea84b0d0000 pid=3403 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=0e79bdde-1b00-0000-70af-7ea84b0d0000 pid=3403 execve guuid=8341fbe5-1b00-0000-70af-7ea85b0d0000 pid=3419 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=8341fbe5-1b00-0000-70af-7ea85b0d0000 pid=3419 execve guuid=e7de8ef9-1b00-0000-70af-7ea8660d0000 pid=3430 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=e7de8ef9-1b00-0000-70af-7ea8660d0000 pid=3430 execve guuid=794e07fa-1b00-0000-70af-7ea8670d0000 pid=3431 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=794e07fa-1b00-0000-70af-7ea8670d0000 pid=3431 execve guuid=513d51fa-1b00-0000-70af-7ea8680d0000 pid=3432 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=513d51fa-1b00-0000-70af-7ea8680d0000 pid=3432 clone guuid=ab8e14fb-1b00-0000-70af-7ea86a0d0000 pid=3434 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=ab8e14fb-1b00-0000-70af-7ea86a0d0000 pid=3434 execve guuid=71138301-1c00-0000-70af-7ea87a0d0000 pid=3450 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=71138301-1c00-0000-70af-7ea87a0d0000 pid=3450 execve guuid=e703f608-1c00-0000-70af-7ea8900d0000 pid=3472 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=e703f608-1c00-0000-70af-7ea8900d0000 pid=3472 execve guuid=a3d45809-1c00-0000-70af-7ea8920d0000 pid=3474 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=a3d45809-1c00-0000-70af-7ea8920d0000 pid=3474 execve guuid=788eb609-1c00-0000-70af-7ea8940d0000 pid=3476 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=788eb609-1c00-0000-70af-7ea8940d0000 pid=3476 clone guuid=00be6b0a-1c00-0000-70af-7ea8980d0000 pid=3480 /usr/bin/wget net send-data guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=00be6b0a-1c00-0000-70af-7ea8980d0000 pid=3480 execve guuid=cc3a2d0e-1c00-0000-70af-7ea8a20d0000 pid=3490 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=cc3a2d0e-1c00-0000-70af-7ea8a20d0000 pid=3490 execve guuid=11dc2515-1c00-0000-70af-7ea8b30d0000 pid=3507 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=11dc2515-1c00-0000-70af-7ea8b30d0000 pid=3507 execve guuid=594fcf15-1c00-0000-70af-7ea8b50d0000 pid=3509 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=594fcf15-1c00-0000-70af-7ea8b50d0000 pid=3509 execve guuid=439c6616-1c00-0000-70af-7ea8b70d0000 pid=3511 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=439c6616-1c00-0000-70af-7ea8b70d0000 pid=3511 clone guuid=655aa616-1c00-0000-70af-7ea8b80d0000 pid=3512 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=655aa616-1c00-0000-70af-7ea8b80d0000 pid=3512 execve guuid=2c71001c-1c00-0000-70af-7ea8c70d0000 pid=3527 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=2c71001c-1c00-0000-70af-7ea8c70d0000 pid=3527 execve guuid=fd344822-1c00-0000-70af-7ea8dc0d0000 pid=3548 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=fd344822-1c00-0000-70af-7ea8dc0d0000 pid=3548 execve guuid=ba50bb22-1c00-0000-70af-7ea8dd0d0000 pid=3549 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=ba50bb22-1c00-0000-70af-7ea8dd0d0000 pid=3549 execve guuid=cba20923-1c00-0000-70af-7ea8de0d0000 pid=3550 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=cba20923-1c00-0000-70af-7ea8de0d0000 pid=3550 clone guuid=0362d123-1c00-0000-70af-7ea8e00d0000 pid=3552 /usr/bin/wget net send-data guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=0362d123-1c00-0000-70af-7ea8e00d0000 pid=3552 execve guuid=23319226-1c00-0000-70af-7ea8e10d0000 pid=3553 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=23319226-1c00-0000-70af-7ea8e10d0000 pid=3553 execve guuid=f396a62b-1c00-0000-70af-7ea8e50d0000 pid=3557 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=f396a62b-1c00-0000-70af-7ea8e50d0000 pid=3557 execve guuid=b7720d2c-1c00-0000-70af-7ea8e70d0000 pid=3559 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=b7720d2c-1c00-0000-70af-7ea8e70d0000 pid=3559 execve guuid=931a5d2c-1c00-0000-70af-7ea8e90d0000 pid=3561 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=931a5d2c-1c00-0000-70af-7ea8e90d0000 pid=3561 clone guuid=9efc872c-1c00-0000-70af-7ea8eb0d0000 pid=3563 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=9efc872c-1c00-0000-70af-7ea8eb0d0000 pid=3563 execve guuid=52524433-1c00-0000-70af-7ea8fb0d0000 pid=3579 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=52524433-1c00-0000-70af-7ea8fb0d0000 pid=3579 execve guuid=7a7dfa3a-1c00-0000-70af-7ea80d0e0000 pid=3597 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=7a7dfa3a-1c00-0000-70af-7ea80d0e0000 pid=3597 execve guuid=fd8e743b-1c00-0000-70af-7ea80e0e0000 pid=3598 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=fd8e743b-1c00-0000-70af-7ea80e0e0000 pid=3598 execve guuid=a6afe23b-1c00-0000-70af-7ea8110e0000 pid=3601 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=a6afe23b-1c00-0000-70af-7ea8110e0000 pid=3601 clone guuid=ae77813c-1c00-0000-70af-7ea8140e0000 pid=3604 /usr/bin/wget net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=ae77813c-1c00-0000-70af-7ea8140e0000 pid=3604 execve guuid=93d73a44-1c00-0000-70af-7ea8290e0000 pid=3625 /usr/bin/curl net send-data write-file guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=93d73a44-1c00-0000-70af-7ea8290e0000 pid=3625 execve guuid=53b5594c-1c00-0000-70af-7ea83f0e0000 pid=3647 /usr/bin/cat guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=53b5594c-1c00-0000-70af-7ea83f0e0000 pid=3647 execve guuid=74b1c54c-1c00-0000-70af-7ea8410e0000 pid=3649 /usr/bin/chmod guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=74b1c54c-1c00-0000-70af-7ea8410e0000 pid=3649 execve guuid=010e194d-1c00-0000-70af-7ea8420e0000 pid=3650 /usr/bin/bash guuid=19a8376c-1b00-0000-70af-7ea8900c0000 pid=3216->guuid=010e194d-1c00-0000-70af-7ea8420e0000 pid=3650 clone c0a32311-821d-5a61-9890-a16269c49685 94.26.106.177:80 guuid=6c24c06c-1b00-0000-70af-7ea8910c0000 pid=3217->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=c49aa674-1b00-0000-70af-7ea89a0c0000 pid=3226->c0a32311-821d-5a61-9890-a16269c49685 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2eb63181-1b00-0000-70af-7ea8aa0c0000 pid=3242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8533dc85-1b00-0000-70af-7ea8ac0c0000 pid=3244->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=1336cb8a-1b00-0000-70af-7ea8b70c0000 pid=3255->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=2e476e92-1b00-0000-70af-7ea8c50c0000 pid=3269->c0a32311-821d-5a61-9890-a16269c49685 send: 144B guuid=74ac8299-1b00-0000-70af-7ea8cb0c0000 pid=3275->c0a32311-821d-5a61-9890-a16269c49685 send: 93B guuid=1381ffa2-1b00-0000-70af-7ea8e30c0000 pid=3299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1063b5a5-1b00-0000-70af-7ea8ec0c0000 pid=3308->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=83e61ba9-1b00-0000-70af-7ea8f10c0000 pid=3313->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=453ce2af-1b00-0000-70af-7ea8000d0000 pid=3328->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=1c6bf6b5-1b00-0000-70af-7ea8120d0000 pid=3346->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=99e01fbe-1b00-0000-70af-7ea81a0d0000 pid=3354->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=44c86ec2-1b00-0000-70af-7ea8210d0000 pid=3361->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=e33f52c8-1b00-0000-70af-7ea82e0d0000 pid=3374->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=37b57dd1-1b00-0000-70af-7ea83f0d0000 pid=3391->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=8b6c7ad4-1b00-0000-70af-7ea8460d0000 pid=3398->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=0e79bdde-1b00-0000-70af-7ea84b0d0000 pid=3403->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=8341fbe5-1b00-0000-70af-7ea85b0d0000 pid=3419->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=ab8e14fb-1b00-0000-70af-7ea86a0d0000 pid=3434->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=71138301-1c00-0000-70af-7ea87a0d0000 pid=3450->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=00be6b0a-1c00-0000-70af-7ea8980d0000 pid=3480->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=cc3a2d0e-1c00-0000-70af-7ea8a20d0000 pid=3490->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=655aa616-1c00-0000-70af-7ea8b80d0000 pid=3512->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=2c71001c-1c00-0000-70af-7ea8c70d0000 pid=3527->c0a32311-821d-5a61-9890-a16269c49685 send: 90B guuid=0362d123-1c00-0000-70af-7ea8e00d0000 pid=3552->c0a32311-821d-5a61-9890-a16269c49685 send: 146B guuid=23319226-1c00-0000-70af-7ea8e10d0000 pid=3553->c0a32311-821d-5a61-9890-a16269c49685 send: 95B guuid=9efc872c-1c00-0000-70af-7ea8eb0d0000 pid=3563->c0a32311-821d-5a61-9890-a16269c49685 send: 142B guuid=52524433-1c00-0000-70af-7ea8fb0d0000 pid=3579->c0a32311-821d-5a61-9890-a16269c49685 send: 91B guuid=ae77813c-1c00-0000-70af-7ea8140e0000 pid=3604->c0a32311-821d-5a61-9890-a16269c49685 send: 141B guuid=93d73a44-1c00-0000-70af-7ea8290e0000 pid=3625->c0a32311-821d-5a61-9890-a16269c49685 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-02-03 16:33:26 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  1/10
Tags:
linux
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c0469c8400de5b76b99f26aa982023f483df42781813ebbbdaf4e4013d8fdabd

(this sample)

  
Delivery method
Distributed via web download

Comments