MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d3ff060dabbfa251af5943a1389c7b8ffeb3e7e61e773d06d4ed3da1ca41f800. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: d3ff060dabbfa251af5943a1389c7b8ffeb3e7e61e773d06d4ed3da1ca41f800
SHA3-384 hash: 658eca808cc8c3d822835dba68b3a199952ff6e111c11d6058779a4efc524b29ea4908803b5f3f65ff8d5aae44dcc7f6
SHA1 hash: 034d3bf19131bf082348cb64793444e7697c11a8
MD5 hash: c49d50f590098bf96e4c96b62b71c0e8
humanhash: saturn-fillet-california-summer
File name:1.sh
Download: download sample
Signature Mirai
File size:3'007 bytes
First seen:2026-04-28 06:12:28 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vqRFRtRHReLRBoRTRERRRZRH9R+R7aRjRNRAc:v8nPxAAF+7DHf4gVvF
TLSH T17A51378651E24474ADF6DD12A2E6C4047580E05A3BC0FF8AD6F53CFAA98DF043C49B93
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://156.226.174.212/manji.x86ebf52bab6189b716479624b0bac008ce47c2982fdefade9d6a6905e8f587a0e8 Miraielf ua-wget
http://156.226.174.212/manji.mipsfd7acf8ea2be7bb148096057431248d7618b299d2cabe805f38256877c46b486 Miraielf mirai ua-wget
http://156.226.174.212/manji.i468n/an/aelf ua-wget
http://156.226.174.212/manji.i68601f341229086f721006cb4d03476f7991d6dfb93ac34f651d36011115b856edb Miraielf ua-wget
http://156.226.174.212/manji.mpsl3aceefe39982a5eb27e374338eb36ce001663f710b0cbd8d37da619e253c31bc Miraielf ua-wget
http://156.226.174.212/manji.arm4c1c4af6bbef4c3851231dfc513a58d13a06f031e84d03935b557199c77ac73b3 Miraielf mirai ua-wget
http://156.226.174.212/manji.arm56330ffa1c3268c3810c009b7478ab69acd5cd96028787ba910c4b8e3e4815407 Miraielf ua-wget
http://156.226.174.212/manji.arm6c16cb63fd128e507f7ddb58f33cc288942d60746a136d42f8e6b0759c32d36f6 Miraielf ua-wget
http://156.226.174.212/manji.arm740b7c4227235062b1b5d8a3976a8cfd2e7a2783776446a5adfbc35344945d240 Miraielf mirai ua-wget
http://156.226.174.212/manji.ppc7a554b95133b9d2be284dcf4d4e411b80e0cd92f3aeda094ca7006882d8f2747 Miraielf mirai ua-wget
http://156.226.174.212/manji.ppc4404bb88283016c6f096cf8adcef1b2bd25be3e716bcfaab2ea77eac46758059363 Miraielf ua-wget
http://156.226.174.212/manji.m68k496d0ea58eece2fdd1f18e5f34303623d2cf2d14f9831a8f09599cbb6008c16e Miraielf ua-wget
http://156.226.174.212/manji.apk40b7c4227235062b1b5d8a3976a8cfd2e7a2783776446a5adfbc35344945d240 Miraielf mirai ua-wget
http://156.226.174.212/manji.dbgd0d854e91f52b8cf8e852ac2accc50eae4d80a034c29152eac563f667f76a3fd Miraielf ua-wget
http://156.226.174.212/manji.sh4512114c8359ccdf13f9dc20c643e7ce43baa38902943a106f54245f1b595fa28 Miraielf ua-wget
http://156.226.174.212/manji.spc22753fee4f319addacd02755978a47336743a2a50e09fa651d2f5a19ca721816 Miraielf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai virus
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-27T11:29:00Z UTC
Last seen:
2026-04-28T01:21:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=99bb7a09-1900-0000-51ea-46579e0d0000 pid=3486 /usr/bin/sudo guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492 /tmp/sample.bin guuid=99bb7a09-1900-0000-51ea-46579e0d0000 pid=3486->guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492 execve guuid=f26cc40c-1900-0000-51ea-4657a70d0000 pid=3495 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=f26cc40c-1900-0000-51ea-4657a70d0000 pid=3495 execve guuid=f7d3bd10-1900-0000-51ea-4657ae0d0000 pid=3502 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=f7d3bd10-1900-0000-51ea-4657ae0d0000 pid=3502 execve guuid=766e1615-1900-0000-51ea-4657b60d0000 pid=3510 /usr/bin/cat guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=766e1615-1900-0000-51ea-4657b60d0000 pid=3510 execve guuid=42aa1516-1900-0000-51ea-4657b70d0000 pid=3511 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=42aa1516-1900-0000-51ea-4657b70d0000 pid=3511 execve guuid=0f505716-1900-0000-51ea-4657b90d0000 pid=3513 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0f505716-1900-0000-51ea-4657b90d0000 pid=3513 execve guuid=a2857416-1900-0000-51ea-4657bb0d0000 pid=3515 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a2857416-1900-0000-51ea-4657bb0d0000 pid=3515 execve guuid=e6feda19-1900-0000-51ea-4657c60d0000 pid=3526 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=e6feda19-1900-0000-51ea-4657c60d0000 pid=3526 execve guuid=e007d720-1900-0000-51ea-4657ce0d0000 pid=3534 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=e007d720-1900-0000-51ea-4657ce0d0000 pid=3534 clone guuid=a4280021-1900-0000-51ea-4657cf0d0000 pid=3535 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a4280021-1900-0000-51ea-4657cf0d0000 pid=3535 execve guuid=576b5b21-1900-0000-51ea-4657d00d0000 pid=3536 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=576b5b21-1900-0000-51ea-4657d00d0000 pid=3536 execve guuid=89b58b21-1900-0000-51ea-4657d20d0000 pid=3538 /usr/bin/wget net send-data guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=89b58b21-1900-0000-51ea-4657d20d0000 pid=3538 execve guuid=46236923-1900-0000-51ea-4657d80d0000 pid=3544 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=46236923-1900-0000-51ea-4657d80d0000 pid=3544 execve guuid=64bf2326-1900-0000-51ea-4657e40d0000 pid=3556 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=64bf2326-1900-0000-51ea-4657e40d0000 pid=3556 clone guuid=91163f26-1900-0000-51ea-4657e50d0000 pid=3557 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=91163f26-1900-0000-51ea-4657e50d0000 pid=3557 execve guuid=18fe9026-1900-0000-51ea-4657e70d0000 pid=3559 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=18fe9026-1900-0000-51ea-4657e70d0000 pid=3559 execve guuid=5a94b226-1900-0000-51ea-4657ea0d0000 pid=3562 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=5a94b226-1900-0000-51ea-4657ea0d0000 pid=3562 execve guuid=10d3072a-1900-0000-51ea-4657f40d0000 pid=3572 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=10d3072a-1900-0000-51ea-4657f40d0000 pid=3572 execve guuid=7cf6f82f-1900-0000-51ea-4657080e0000 pid=3592 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=7cf6f82f-1900-0000-51ea-4657080e0000 pid=3592 clone guuid=bef40e30-1900-0000-51ea-46570a0e0000 pid=3594 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=bef40e30-1900-0000-51ea-46570a0e0000 pid=3594 execve guuid=f5525130-1900-0000-51ea-46570c0e0000 pid=3596 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=f5525130-1900-0000-51ea-46570c0e0000 pid=3596 execve guuid=9ee26930-1900-0000-51ea-46570e0e0000 pid=3598 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9ee26930-1900-0000-51ea-46570e0e0000 pid=3598 execve guuid=5f853e33-1900-0000-51ea-4657160e0000 pid=3606 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=5f853e33-1900-0000-51ea-4657160e0000 pid=3606 execve guuid=8941e536-1900-0000-51ea-4657220e0000 pid=3618 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=8941e536-1900-0000-51ea-4657220e0000 pid=3618 clone guuid=0ef80f37-1900-0000-51ea-4657230e0000 pid=3619 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0ef80f37-1900-0000-51ea-4657230e0000 pid=3619 execve guuid=94d97537-1900-0000-51ea-4657250e0000 pid=3621 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=94d97537-1900-0000-51ea-4657250e0000 pid=3621 execve guuid=357ac237-1900-0000-51ea-4657280e0000 pid=3624 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=357ac237-1900-0000-51ea-4657280e0000 pid=3624 execve guuid=c284993a-1900-0000-51ea-46572f0e0000 pid=3631 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=c284993a-1900-0000-51ea-46572f0e0000 pid=3631 execve guuid=d0cdf03e-1900-0000-51ea-46573a0e0000 pid=3642 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=d0cdf03e-1900-0000-51ea-46573a0e0000 pid=3642 clone guuid=19e20c3f-1900-0000-51ea-46573b0e0000 pid=3643 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=19e20c3f-1900-0000-51ea-46573b0e0000 pid=3643 execve guuid=d9435a3f-1900-0000-51ea-46573f0e0000 pid=3647 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=d9435a3f-1900-0000-51ea-46573f0e0000 pid=3647 execve guuid=4bb37c3f-1900-0000-51ea-4657410e0000 pid=3649 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=4bb37c3f-1900-0000-51ea-4657410e0000 pid=3649 execve guuid=0dd50642-1900-0000-51ea-46574c0e0000 pid=3660 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0dd50642-1900-0000-51ea-46574c0e0000 pid=3660 execve guuid=501fef45-1900-0000-51ea-46575d0e0000 pid=3677 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=501fef45-1900-0000-51ea-46575d0e0000 pid=3677 clone guuid=6c410c46-1900-0000-51ea-46575e0e0000 pid=3678 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=6c410c46-1900-0000-51ea-46575e0e0000 pid=3678 execve guuid=9aea7446-1900-0000-51ea-4657600e0000 pid=3680 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9aea7446-1900-0000-51ea-4657600e0000 pid=3680 execve guuid=7f0c8e46-1900-0000-51ea-4657630e0000 pid=3683 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=7f0c8e46-1900-0000-51ea-4657630e0000 pid=3683 execve guuid=6d08074a-1900-0000-51ea-4657700e0000 pid=3696 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=6d08074a-1900-0000-51ea-4657700e0000 pid=3696 execve guuid=e06fd94e-1900-0000-51ea-4657770e0000 pid=3703 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=e06fd94e-1900-0000-51ea-4657770e0000 pid=3703 clone guuid=60642f4f-1900-0000-51ea-4657780e0000 pid=3704 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=60642f4f-1900-0000-51ea-4657780e0000 pid=3704 execve guuid=d4e83e50-1900-0000-51ea-4657790e0000 pid=3705 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=d4e83e50-1900-0000-51ea-4657790e0000 pid=3705 execve guuid=a4c49b50-1900-0000-51ea-46577b0e0000 pid=3707 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a4c49b50-1900-0000-51ea-46577b0e0000 pid=3707 execve guuid=b61c4355-1900-0000-51ea-46577c0e0000 pid=3708 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=b61c4355-1900-0000-51ea-46577c0e0000 pid=3708 execve guuid=9532c95a-1900-0000-51ea-4657890e0000 pid=3721 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9532c95a-1900-0000-51ea-4657890e0000 pid=3721 clone guuid=fda2e85a-1900-0000-51ea-46578a0e0000 pid=3722 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=fda2e85a-1900-0000-51ea-46578a0e0000 pid=3722 execve guuid=b8204a5b-1900-0000-51ea-46578b0e0000 pid=3723 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=b8204a5b-1900-0000-51ea-46578b0e0000 pid=3723 execve guuid=a64c7a5b-1900-0000-51ea-46578d0e0000 pid=3725 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a64c7a5b-1900-0000-51ea-46578d0e0000 pid=3725 execve guuid=9227675e-1900-0000-51ea-4657950e0000 pid=3733 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9227675e-1900-0000-51ea-4657950e0000 pid=3733 execve guuid=a8350863-1900-0000-51ea-46579f0e0000 pid=3743 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a8350863-1900-0000-51ea-46579f0e0000 pid=3743 clone guuid=9b932263-1900-0000-51ea-4657a00e0000 pid=3744 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9b932263-1900-0000-51ea-4657a00e0000 pid=3744 execve guuid=d35ea963-1900-0000-51ea-4657a30e0000 pid=3747 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=d35ea963-1900-0000-51ea-4657a30e0000 pid=3747 execve guuid=0703d363-1900-0000-51ea-4657a60e0000 pid=3750 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0703d363-1900-0000-51ea-4657a60e0000 pid=3750 execve guuid=6779ab66-1900-0000-51ea-4657b10e0000 pid=3761 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=6779ab66-1900-0000-51ea-4657b10e0000 pid=3761 execve guuid=9be15e6d-1900-0000-51ea-4657cd0e0000 pid=3789 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=9be15e6d-1900-0000-51ea-4657cd0e0000 pid=3789 clone guuid=0213836d-1900-0000-51ea-4657ce0e0000 pid=3790 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0213836d-1900-0000-51ea-4657ce0e0000 pid=3790 execve guuid=8e2ac66d-1900-0000-51ea-4657d20e0000 pid=3794 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=8e2ac66d-1900-0000-51ea-4657d20e0000 pid=3794 execve guuid=7d61f06d-1900-0000-51ea-4657d40e0000 pid=3796 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=7d61f06d-1900-0000-51ea-4657d40e0000 pid=3796 execve guuid=0d26c670-1900-0000-51ea-4657df0e0000 pid=3807 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0d26c670-1900-0000-51ea-4657df0e0000 pid=3807 execve guuid=6f645c76-1900-0000-51ea-4657f10e0000 pid=3825 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=6f645c76-1900-0000-51ea-4657f10e0000 pid=3825 clone guuid=900e7b76-1900-0000-51ea-4657f30e0000 pid=3827 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=900e7b76-1900-0000-51ea-4657f30e0000 pid=3827 execve guuid=5f18cb76-1900-0000-51ea-4657f40e0000 pid=3828 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=5f18cb76-1900-0000-51ea-4657f40e0000 pid=3828 execve guuid=a2c4e976-1900-0000-51ea-4657f70e0000 pid=3831 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a2c4e976-1900-0000-51ea-4657f70e0000 pid=3831 execve guuid=2e5a927a-1900-0000-51ea-4657080f0000 pid=3848 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=2e5a927a-1900-0000-51ea-4657080f0000 pid=3848 execve guuid=51bf0580-1900-0000-51ea-4657270f0000 pid=3879 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=51bf0580-1900-0000-51ea-4657270f0000 pid=3879 clone guuid=cd392080-1900-0000-51ea-4657280f0000 pid=3880 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=cd392080-1900-0000-51ea-4657280f0000 pid=3880 execve guuid=aa937080-1900-0000-51ea-46572b0f0000 pid=3883 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=aa937080-1900-0000-51ea-46572b0f0000 pid=3883 execve guuid=2d038f80-1900-0000-51ea-46572d0f0000 pid=3885 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=2d038f80-1900-0000-51ea-46572d0f0000 pid=3885 execve guuid=b33ea983-1900-0000-51ea-4657380f0000 pid=3896 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=b33ea983-1900-0000-51ea-4657380f0000 pid=3896 execve guuid=10737c87-1900-0000-51ea-4657390f0000 pid=3897 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=10737c87-1900-0000-51ea-4657390f0000 pid=3897 clone guuid=1f09b387-1900-0000-51ea-46573a0f0000 pid=3898 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=1f09b387-1900-0000-51ea-46573a0f0000 pid=3898 execve guuid=415c5088-1900-0000-51ea-46573b0f0000 pid=3899 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=415c5088-1900-0000-51ea-46573b0f0000 pid=3899 execve guuid=355c8888-1900-0000-51ea-46573d0f0000 pid=3901 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=355c8888-1900-0000-51ea-46573d0f0000 pid=3901 execve guuid=a8931c8c-1900-0000-51ea-4657420f0000 pid=3906 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=a8931c8c-1900-0000-51ea-4657420f0000 pid=3906 execve guuid=ee730e92-1900-0000-51ea-4657580f0000 pid=3928 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=ee730e92-1900-0000-51ea-4657580f0000 pid=3928 clone guuid=b04c3292-1900-0000-51ea-4657590f0000 pid=3929 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=b04c3292-1900-0000-51ea-4657590f0000 pid=3929 execve guuid=c714ac92-1900-0000-51ea-46575c0f0000 pid=3932 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=c714ac92-1900-0000-51ea-46575c0f0000 pid=3932 execve guuid=2ff7c992-1900-0000-51ea-46575e0f0000 pid=3934 /usr/bin/wget net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=2ff7c992-1900-0000-51ea-46575e0f0000 pid=3934 execve guuid=d519f097-1900-0000-51ea-4657620f0000 pid=3938 /usr/bin/curl net send-data write-file guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=d519f097-1900-0000-51ea-4657620f0000 pid=3938 execve guuid=b8795e9c-1900-0000-51ea-4657700f0000 pid=3952 /usr/bin/bash guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=b8795e9c-1900-0000-51ea-4657700f0000 pid=3952 clone guuid=0d3d769c-1900-0000-51ea-4657710f0000 pid=3953 /usr/bin/chmod guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=0d3d769c-1900-0000-51ea-4657710f0000 pid=3953 execve guuid=05aee79c-1900-0000-51ea-4657730f0000 pid=3955 /tmp/robben guuid=3da0e60b-1900-0000-51ea-4657a40d0000 pid=3492->guuid=05aee79c-1900-0000-51ea-4657730f0000 pid=3955 execve dfc47e25-92ff-5564-add8-d07b7eeb210c 156.226.174.212:80 guuid=f26cc40c-1900-0000-51ea-4657a70d0000 pid=3495->dfc47e25-92ff-5564-add8-d07b7eeb210c send: 139B guuid=f7d3bd10-1900-0000-51ea-4657ae0d0000 pid=3502->dfc47e25-92ff-5564-add8-d07b7eeb210c send: 88B guuid=56516816-1900-0000-51ea-4657ba0d0000 pid=3514 /tmp/robben dns net send-data write-file zombie guuid=0f505716-1900-0000-51ea-4657b90d0000 pid=3513->guuid=56516816-1900-0000-51ea-4657ba0d0000 pid=3514 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=56516816-1900-0000-51ea-4657ba0d0000 pid=3514->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 496B 43701de0-3cf5-5e04-89d5-86946c0a8329 202604157.xyz:6621 guuid=56516816-1900-0000-51ea-4657ba0d0000 pid=3514->43701de0-3cf5-5e04-89d5-86946c0a8329 send: 25B 4a808cca-efd6-528b-8215-1abdd6a9284d 202604157.xyz:80 guuid=a2857416-1900-0000-51ea-4657bb0d0000 pid=3515->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=e6feda19-1900-0000-51ea-4657c60d0000 pid=3526->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=5bab7521-1900-0000-51ea-4657d10d0000 pid=3537 /tmp/robben guuid=576b5b21-1900-0000-51ea-4657d00d0000 pid=3536->guuid=5bab7521-1900-0000-51ea-4657d10d0000 pid=3537 clone guuid=89b58b21-1900-0000-51ea-4657d20d0000 pid=3538->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=46236923-1900-0000-51ea-4657d80d0000 pid=3544->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=e8fca126-1900-0000-51ea-4657e80d0000 pid=3560 /tmp/robben guuid=18fe9026-1900-0000-51ea-4657e70d0000 pid=3559->guuid=e8fca126-1900-0000-51ea-4657e80d0000 pid=3560 clone guuid=5a94b226-1900-0000-51ea-4657ea0d0000 pid=3562->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=10d3072a-1900-0000-51ea-4657f40d0000 pid=3572->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=a9c46030-1900-0000-51ea-46570d0e0000 pid=3597 /tmp/robben guuid=f5525130-1900-0000-51ea-46570c0e0000 pid=3596->guuid=a9c46030-1900-0000-51ea-46570d0e0000 pid=3597 clone guuid=9ee26930-1900-0000-51ea-46570e0e0000 pid=3598->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=5f853e33-1900-0000-51ea-4657160e0000 pid=3606->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=97628d37-1900-0000-51ea-4657260e0000 pid=3622 /tmp/robben guuid=94d97537-1900-0000-51ea-4657250e0000 pid=3621->guuid=97628d37-1900-0000-51ea-4657260e0000 pid=3622 clone guuid=357ac237-1900-0000-51ea-4657280e0000 pid=3624->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=c284993a-1900-0000-51ea-46572f0e0000 pid=3631->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=3213703f-1900-0000-51ea-4657400e0000 pid=3648 /tmp/robben guuid=d9435a3f-1900-0000-51ea-46573f0e0000 pid=3647->guuid=3213703f-1900-0000-51ea-4657400e0000 pid=3648 clone guuid=4bb37c3f-1900-0000-51ea-4657410e0000 pid=3649->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=0dd50642-1900-0000-51ea-46574c0e0000 pid=3660->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=9d1d8446-1900-0000-51ea-4657620e0000 pid=3682 /tmp/robben guuid=9aea7446-1900-0000-51ea-4657600e0000 pid=3680->guuid=9d1d8446-1900-0000-51ea-4657620e0000 pid=3682 clone guuid=7f0c8e46-1900-0000-51ea-4657630e0000 pid=3683->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=6d08074a-1900-0000-51ea-4657700e0000 pid=3696->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=707e8150-1900-0000-51ea-46577a0e0000 pid=3706 /tmp/robben guuid=d4e83e50-1900-0000-51ea-4657790e0000 pid=3705->guuid=707e8150-1900-0000-51ea-46577a0e0000 pid=3706 clone guuid=a4c49b50-1900-0000-51ea-46577b0e0000 pid=3707->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=b61c4355-1900-0000-51ea-46577c0e0000 pid=3708->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=028b645b-1900-0000-51ea-46578c0e0000 pid=3724 /tmp/robben guuid=b8204a5b-1900-0000-51ea-46578b0e0000 pid=3723->guuid=028b645b-1900-0000-51ea-46578c0e0000 pid=3724 clone guuid=a64c7a5b-1900-0000-51ea-46578d0e0000 pid=3725->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=9227675e-1900-0000-51ea-4657950e0000 pid=3733->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=6f57c163-1900-0000-51ea-4657a50e0000 pid=3749 /tmp/robben guuid=d35ea963-1900-0000-51ea-4657a30e0000 pid=3747->guuid=6f57c163-1900-0000-51ea-4657a50e0000 pid=3749 clone guuid=0703d363-1900-0000-51ea-4657a60e0000 pid=3750->4a808cca-efd6-528b-8215-1abdd6a9284d send: 142B guuid=6779ab66-1900-0000-51ea-4657b10e0000 pid=3761->4a808cca-efd6-528b-8215-1abdd6a9284d send: 91B guuid=a8a0e06d-1900-0000-51ea-4657d30e0000 pid=3795 /tmp/robben guuid=8e2ac66d-1900-0000-51ea-4657d20e0000 pid=3794->guuid=a8a0e06d-1900-0000-51ea-4657d30e0000 pid=3795 clone guuid=7d61f06d-1900-0000-51ea-4657d40e0000 pid=3796->4a808cca-efd6-528b-8215-1abdd6a9284d send: 140B guuid=0d26c670-1900-0000-51ea-4657df0e0000 pid=3807->4a808cca-efd6-528b-8215-1abdd6a9284d send: 89B guuid=f061df76-1900-0000-51ea-4657f60e0000 pid=3830 /tmp/robben guuid=5f18cb76-1900-0000-51ea-4657f40e0000 pid=3828->guuid=f061df76-1900-0000-51ea-4657f60e0000 pid=3830 clone guuid=a2c4e976-1900-0000-51ea-4657f70e0000 pid=3831->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=2e5a927a-1900-0000-51ea-4657080f0000 pid=3848->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=60ca8580-1900-0000-51ea-46572c0f0000 pid=3884 /tmp/robben guuid=aa937080-1900-0000-51ea-46572b0f0000 pid=3883->guuid=60ca8580-1900-0000-51ea-46572c0f0000 pid=3884 clone guuid=2d038f80-1900-0000-51ea-46572d0f0000 pid=3885->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=b33ea983-1900-0000-51ea-4657380f0000 pid=3896->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=ced06e88-1900-0000-51ea-46573c0f0000 pid=3900 /tmp/robben guuid=415c5088-1900-0000-51ea-46573b0f0000 pid=3899->guuid=ced06e88-1900-0000-51ea-46573c0f0000 pid=3900 clone guuid=355c8888-1900-0000-51ea-46573d0f0000 pid=3901->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=a8931c8c-1900-0000-51ea-4657420f0000 pid=3906->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=0911bf92-1900-0000-51ea-46575d0f0000 pid=3933 /tmp/robben guuid=c714ac92-1900-0000-51ea-46575c0f0000 pid=3932->guuid=0911bf92-1900-0000-51ea-46575d0f0000 pid=3933 clone guuid=2ff7c992-1900-0000-51ea-46575e0f0000 pid=3934->4a808cca-efd6-528b-8215-1abdd6a9284d send: 139B guuid=d519f097-1900-0000-51ea-4657620f0000 pid=3938->4a808cca-efd6-528b-8215-1abdd6a9284d send: 88B guuid=5995f99c-1900-0000-51ea-4657740f0000 pid=3956 /tmp/robben guuid=05aee79c-1900-0000-51ea-4657730f0000 pid=3955->guuid=5995f99c-1900-0000-51ea-4657740f0000 pid=3956 clone
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-04-28 06:13:43 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Traces itself
Family: Mirai
Malware Config
C2 Extraction:
89.190.156.145
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d3ff060dabbfa251af5943a1389c7b8ffeb3e7e61e773d06d4ed3da1ca41f800

(this sample)

  
Delivery method
Distributed via web download

Comments