MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e8ee8ab1fdfc2e908493c8433ab4c67295e7a04c2fb98831bb56101d8ea73c26. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: e8ee8ab1fdfc2e908493c8433ab4c67295e7a04c2fb98831bb56101d8ea73c26
SHA3-384 hash: 4eeffc7417d843375d458e1f528bd2b1768278edd13f4da78b559ceeee3fdd619ceb923d68966e955799af98d8e51712
SHA1 hash: b8a50581aea9305240d77413268408d954a216b5
MD5 hash: 596fff9ffffffb50b14b6167131abdd7
humanhash: mango-oranges-pluto-stairway
File name:fentbins.sh
Download: download sample
Signature Mirai
File size:1'820 bytes
First seen:2026-01-11 05:43:58 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vqxdqCUqRheGqvCkqMcLqZtJq2MqS8qnRqOz:vqxdqCUqLeGqvdqMcLqZ7q2MqS8qnRqa
TLSH T1963110C53341353169A1DD2B7ABBC984B2F47059BEC52A2966D43CE8C1DCF08BC55F92
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.121.112.124/bins/fent.x860d32236bfdd18985046bc80818bfa5b8baec2ca0a982d61bf4b62d898d94d08f Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.mips6668094256bac1ecf829e2686192d4de0322c65ad24b6bce0137dc1ca5ccb844 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.mpsl7b3f23580daa37bf9fc7811a111b25ad60eeb3b6ebed2fb531fd3b44fb2ee8a6 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm4n/an/aelf ua-wget
http://87.121.112.124/bins/fent.arm53b50fa8b73b431bf3c4ceafc12bbf57d7227d1f2586cb6cabe5fded45e511d55 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm6803e8a0df8506cb0c52a095ae7c1512540964ccf6ef96887afd62ef9f5a18710 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.arm71bf10173feab7e57ff553a91fa313a213a025f5e295852db136707fe1173bb14 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.ppcc948fc6cc962dcdfd94b0351ab7df2f1fc4034ded3023e2e54bccd57417f805c Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.m68k0a147ad163eb46d153a692d285093dd08042cc9f377fe75cff63189e5c82eee8 Miraielf mirai ua-wget
http://87.121.112.124/bins/fent.sh405733b6df5ecb188fcece2cce03ee0cd4926facf754d10a2b6e8143c315ba18a Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=3e100bb1-1700-0000-ebf0-6d326b0d0000 pid=3435 /usr/bin/sudo guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442 /tmp/sample.bin guuid=3e100bb1-1700-0000-ebf0-6d326b0d0000 pid=3435->guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442 execve guuid=90b44fb3-1700-0000-ebf0-6d32750d0000 pid=3445 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=90b44fb3-1700-0000-ebf0-6d32750d0000 pid=3445 execve guuid=04ef83be-1700-0000-ebf0-6d32960d0000 pid=3478 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=04ef83be-1700-0000-ebf0-6d32960d0000 pid=3478 execve guuid=2e8034ce-1700-0000-ebf0-6d32b60d0000 pid=3510 /usr/bin/cat guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=2e8034ce-1700-0000-ebf0-6d32b60d0000 pid=3510 execve guuid=737f83ce-1700-0000-ebf0-6d32b70d0000 pid=3511 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=737f83ce-1700-0000-ebf0-6d32b70d0000 pid=3511 execve guuid=6f00c7ce-1700-0000-ebf0-6d32b80d0000 pid=3512 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=6f00c7ce-1700-0000-ebf0-6d32b80d0000 pid=3512 execve guuid=884a03cf-1700-0000-ebf0-6d32ba0d0000 pid=3514 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=884a03cf-1700-0000-ebf0-6d32ba0d0000 pid=3514 execve guuid=ad3301dc-1700-0000-ebf0-6d32cd0d0000 pid=3533 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=ad3301dc-1700-0000-ebf0-6d32cd0d0000 pid=3533 execve guuid=5e2ac7e9-1700-0000-ebf0-6d32df0d0000 pid=3551 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=5e2ac7e9-1700-0000-ebf0-6d32df0d0000 pid=3551 clone guuid=ca4608ea-1700-0000-ebf0-6d32e00d0000 pid=3552 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=ca4608ea-1700-0000-ebf0-6d32e00d0000 pid=3552 execve guuid=631cacea-1700-0000-ebf0-6d32e20d0000 pid=3554 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=631cacea-1700-0000-ebf0-6d32e20d0000 pid=3554 execve guuid=a1c13d15-1900-0000-ebf0-6d3289100000 pid=4233 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=a1c13d15-1900-0000-ebf0-6d3289100000 pid=4233 execve guuid=7d22c622-1900-0000-ebf0-6d32bd100000 pid=4285 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=7d22c622-1900-0000-ebf0-6d32bd100000 pid=4285 execve guuid=cf8fe230-1900-0000-ebf0-6d32ed100000 pid=4333 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=cf8fe230-1900-0000-ebf0-6d32ed100000 pid=4333 clone guuid=639d0731-1900-0000-ebf0-6d32ee100000 pid=4334 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=639d0731-1900-0000-ebf0-6d32ee100000 pid=4334 execve guuid=21576431-1900-0000-ebf0-6d32ef100000 pid=4335 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=21576431-1900-0000-ebf0-6d32ef100000 pid=4335 execve guuid=5f85b35b-1a00-0000-ebf0-6d3275140000 pid=5237 /usr/bin/wget net send-data guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=5f85b35b-1a00-0000-ebf0-6d3275140000 pid=5237 execve guuid=26a9da62-1a00-0000-ebf0-6d3276140000 pid=5238 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=26a9da62-1a00-0000-ebf0-6d3276140000 pid=5238 execve guuid=1c4c396a-1a00-0000-ebf0-6d3277140000 pid=5239 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=1c4c396a-1a00-0000-ebf0-6d3277140000 pid=5239 clone guuid=8b17616a-1a00-0000-ebf0-6d3278140000 pid=5240 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=8b17616a-1a00-0000-ebf0-6d3278140000 pid=5240 execve guuid=65cfb96a-1a00-0000-ebf0-6d3279140000 pid=5241 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=65cfb96a-1a00-0000-ebf0-6d3279140000 pid=5241 execve guuid=7e1b4595-1b00-0000-ebf0-6d328b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=7e1b4595-1b00-0000-ebf0-6d328b140000 pid=5259 execve guuid=198bb9a0-1b00-0000-ebf0-6d328c140000 pid=5260 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=198bb9a0-1b00-0000-ebf0-6d328c140000 pid=5260 execve guuid=3909b8be-1b00-0000-ebf0-6d328d140000 pid=5261 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=3909b8be-1b00-0000-ebf0-6d328d140000 pid=5261 clone guuid=8ad1e5be-1b00-0000-ebf0-6d328e140000 pid=5262 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=8ad1e5be-1b00-0000-ebf0-6d328e140000 pid=5262 execve guuid=b9f233bf-1b00-0000-ebf0-6d328f140000 pid=5263 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=b9f233bf-1b00-0000-ebf0-6d328f140000 pid=5263 execve guuid=3c1cd6e9-1c00-0000-ebf0-6d329e140000 pid=5278 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=3c1cd6e9-1c00-0000-ebf0-6d329e140000 pid=5278 execve guuid=05a7e017-1d00-0000-ebf0-6d32a0140000 pid=5280 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=05a7e017-1d00-0000-ebf0-6d32a0140000 pid=5280 execve guuid=f111fc24-1d00-0000-ebf0-6d32a1140000 pid=5281 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=f111fc24-1d00-0000-ebf0-6d32a1140000 pid=5281 clone guuid=90bd2925-1d00-0000-ebf0-6d32a2140000 pid=5282 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=90bd2925-1d00-0000-ebf0-6d32a2140000 pid=5282 execve guuid=e36d9125-1d00-0000-ebf0-6d32a3140000 pid=5283 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=e36d9125-1d00-0000-ebf0-6d32a3140000 pid=5283 execve guuid=c008ef4f-1e00-0000-ebf0-6d32a5140000 pid=5285 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=c008ef4f-1e00-0000-ebf0-6d32a5140000 pid=5285 execve guuid=2f57f65e-1e00-0000-ebf0-6d32a7140000 pid=5287 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=2f57f65e-1e00-0000-ebf0-6d32a7140000 pid=5287 execve guuid=7e5a816e-1e00-0000-ebf0-6d32a8140000 pid=5288 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=7e5a816e-1e00-0000-ebf0-6d32a8140000 pid=5288 clone guuid=5c98a56e-1e00-0000-ebf0-6d32a9140000 pid=5289 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=5c98a56e-1e00-0000-ebf0-6d32a9140000 pid=5289 execve guuid=afede96e-1e00-0000-ebf0-6d32aa140000 pid=5290 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=afede96e-1e00-0000-ebf0-6d32aa140000 pid=5290 execve guuid=abd85e99-1f00-0000-ebf0-6d32b8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=abd85e99-1f00-0000-ebf0-6d32b8140000 pid=5304 execve guuid=ede52ba5-1f00-0000-ebf0-6d32c1140000 pid=5313 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=ede52ba5-1f00-0000-ebf0-6d32c1140000 pid=5313 execve guuid=ef3f48b2-1f00-0000-ebf0-6d32c2140000 pid=5314 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=ef3f48b2-1f00-0000-ebf0-6d32c2140000 pid=5314 clone guuid=4c9768b2-1f00-0000-ebf0-6d32c3140000 pid=5315 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=4c9768b2-1f00-0000-ebf0-6d32c3140000 pid=5315 execve guuid=ca00adb2-1f00-0000-ebf0-6d32c4140000 pid=5316 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=ca00adb2-1f00-0000-ebf0-6d32c4140000 pid=5316 execve guuid=69e7fddc-2000-0000-ebf0-6d32c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=69e7fddc-2000-0000-ebf0-6d32c6140000 pid=5318 execve guuid=4f7ddfe8-2000-0000-ebf0-6d32c8140000 pid=5320 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=4f7ddfe8-2000-0000-ebf0-6d32c8140000 pid=5320 execve guuid=16abadf5-2000-0000-ebf0-6d32c9140000 pid=5321 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=16abadf5-2000-0000-ebf0-6d32c9140000 pid=5321 clone guuid=3f16e3f5-2000-0000-ebf0-6d32ca140000 pid=5322 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=3f16e3f5-2000-0000-ebf0-6d32ca140000 pid=5322 execve guuid=36602df6-2000-0000-ebf0-6d32cb140000 pid=5323 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=36602df6-2000-0000-ebf0-6d32cb140000 pid=5323 execve guuid=bbe2cb20-2200-0000-ebf0-6d32cd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=bbe2cb20-2200-0000-ebf0-6d32cd140000 pid=5325 execve guuid=bee727bc-2200-0000-ebf0-6d32cf140000 pid=5327 /usr/bin/curl net send-data write-file guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=bee727bc-2200-0000-ebf0-6d32cf140000 pid=5327 execve guuid=76646ec6-2200-0000-ebf0-6d32d0140000 pid=5328 /usr/bin/bash guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=76646ec6-2200-0000-ebf0-6d32d0140000 pid=5328 clone guuid=538193c6-2200-0000-ebf0-6d32d1140000 pid=5329 /usr/bin/chmod guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=538193c6-2200-0000-ebf0-6d32d1140000 pid=5329 execve guuid=13bee0c6-2200-0000-ebf0-6d32d2140000 pid=5330 /tmp/cp net guuid=2744f3b2-1700-0000-ebf0-6d32720d0000 pid=3442->guuid=13bee0c6-2200-0000-ebf0-6d32d2140000 pid=5330 execve efef254e-80b3-5bfb-b0bf-2e8b7a7434cf 87.121.112.124:80 guuid=90b44fb3-1700-0000-ebf0-6d32750d0000 pid=3445->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=04ef83be-1700-0000-ebf0-6d32960d0000 pid=3478->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=6f00c7ce-1700-0000-ebf0-6d32b80d0000 pid=3512->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2e7af4ce-1700-0000-ebf0-6d32b90d0000 pid=3513 /tmp/cp net send-data zombie guuid=6f00c7ce-1700-0000-ebf0-6d32b80d0000 pid=3512->guuid=2e7af4ce-1700-0000-ebf0-6d32b90d0000 pid=3513 clone guuid=2e7af4ce-1700-0000-ebf0-6d32b90d0000 pid=3513->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con df7c0f9f-a1b8-565b-9132-7cd03da85718 87.121.112.124:911 guuid=2e7af4ce-1700-0000-ebf0-6d32b90d0000 pid=3513->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 8B guuid=64eb0ecf-1700-0000-ebf0-6d32bb0d0000 pid=3515 /tmp/cp guuid=2e7af4ce-1700-0000-ebf0-6d32b90d0000 pid=3513->guuid=64eb0ecf-1700-0000-ebf0-6d32bb0d0000 pid=3515 clone guuid=884a03cf-1700-0000-ebf0-6d32ba0d0000 pid=3514->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=ad3301dc-1700-0000-ebf0-6d32cd0d0000 pid=3533->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=631cacea-1700-0000-ebf0-6d32e20d0000 pid=3554->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b9502367-5dd5-56e5-a2d2-9be7d9d70400 0.0.0.0:39148 guuid=631cacea-1700-0000-ebf0-6d32e20d0000 pid=3554->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=f5412a15-1900-0000-ebf0-6d3287100000 pid=4231 /tmp/cp net send-data zombie guuid=631cacea-1700-0000-ebf0-6d32e20d0000 pid=3554->guuid=f5412a15-1900-0000-ebf0-6d3287100000 pid=4231 clone guuid=f5412a15-1900-0000-ebf0-6d3287100000 pid=4231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f5412a15-1900-0000-ebf0-6d3287100000 pid=4231->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=9e6e3515-1900-0000-ebf0-6d3288100000 pid=4232 /tmp/cp guuid=f5412a15-1900-0000-ebf0-6d3287100000 pid=4231->guuid=9e6e3515-1900-0000-ebf0-6d3288100000 pid=4232 clone guuid=a1c13d15-1900-0000-ebf0-6d3289100000 pid=4233->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=7d22c622-1900-0000-ebf0-6d32bd100000 pid=4285->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=21576431-1900-0000-ebf0-6d32ef100000 pid=4335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=21576431-1900-0000-ebf0-6d32ef100000 pid=4335->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=2278a65b-1a00-0000-ebf0-6d3273140000 pid=5235 /tmp/cp net send-data zombie guuid=21576431-1900-0000-ebf0-6d32ef100000 pid=4335->guuid=2278a65b-1a00-0000-ebf0-6d3273140000 pid=5235 clone guuid=2278a65b-1a00-0000-ebf0-6d3273140000 pid=5235->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2278a65b-1a00-0000-ebf0-6d3273140000 pid=5235->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 18B guuid=9926b25b-1a00-0000-ebf0-6d3274140000 pid=5236 /tmp/cp guuid=2278a65b-1a00-0000-ebf0-6d3273140000 pid=5235->guuid=9926b25b-1a00-0000-ebf0-6d3274140000 pid=5236 clone guuid=5f85b35b-1a00-0000-ebf0-6d3275140000 pid=5237->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=26a9da62-1a00-0000-ebf0-6d3276140000 pid=5238->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=65cfb96a-1a00-0000-ebf0-6d3279140000 pid=5241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=65cfb96a-1a00-0000-ebf0-6d3279140000 pid=5241->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=1ed00c95-1b00-0000-ebf0-6d3289140000 pid=5257 /tmp/cp net send-data zombie guuid=65cfb96a-1a00-0000-ebf0-6d3279140000 pid=5241->guuid=1ed00c95-1b00-0000-ebf0-6d3289140000 pid=5257 clone guuid=1ed00c95-1b00-0000-ebf0-6d3289140000 pid=5257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1ed00c95-1b00-0000-ebf0-6d3289140000 pid=5257->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=a9c11f95-1b00-0000-ebf0-6d328a140000 pid=5258 /tmp/cp guuid=1ed00c95-1b00-0000-ebf0-6d3289140000 pid=5257->guuid=a9c11f95-1b00-0000-ebf0-6d328a140000 pid=5258 clone guuid=7e1b4595-1b00-0000-ebf0-6d328b140000 pid=5259->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=198bb9a0-1b00-0000-ebf0-6d328c140000 pid=5260->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=b9f233bf-1b00-0000-ebf0-6d328f140000 pid=5263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b9f233bf-1b00-0000-ebf0-6d328f140000 pid=5263->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=3421b4e9-1c00-0000-ebf0-6d329d140000 pid=5277 /tmp/cp net send-data zombie guuid=b9f233bf-1b00-0000-ebf0-6d328f140000 pid=5263->guuid=3421b4e9-1c00-0000-ebf0-6d329d140000 pid=5277 clone guuid=3421b4e9-1c00-0000-ebf0-6d329d140000 pid=5277->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3421b4e9-1c00-0000-ebf0-6d329d140000 pid=5277->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=b1b4dbe9-1c00-0000-ebf0-6d329f140000 pid=5279 /tmp/cp guuid=3421b4e9-1c00-0000-ebf0-6d329d140000 pid=5277->guuid=b1b4dbe9-1c00-0000-ebf0-6d329f140000 pid=5279 clone guuid=3c1cd6e9-1c00-0000-ebf0-6d329e140000 pid=5278->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=05a7e017-1d00-0000-ebf0-6d32a0140000 pid=5280->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=e36d9125-1d00-0000-ebf0-6d32a3140000 pid=5283->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e36d9125-1d00-0000-ebf0-6d32a3140000 pid=5283->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=2b02db4f-1e00-0000-ebf0-6d32a4140000 pid=5284 /tmp/cp net send-data zombie guuid=e36d9125-1d00-0000-ebf0-6d32a3140000 pid=5283->guuid=2b02db4f-1e00-0000-ebf0-6d32a4140000 pid=5284 clone guuid=2b02db4f-1e00-0000-ebf0-6d32a4140000 pid=5284->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2b02db4f-1e00-0000-ebf0-6d32a4140000 pid=5284->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=f624f04f-1e00-0000-ebf0-6d32a6140000 pid=5286 /tmp/cp guuid=2b02db4f-1e00-0000-ebf0-6d32a4140000 pid=5284->guuid=f624f04f-1e00-0000-ebf0-6d32a6140000 pid=5286 clone guuid=c008ef4f-1e00-0000-ebf0-6d32a5140000 pid=5285->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=2f57f65e-1e00-0000-ebf0-6d32a7140000 pid=5287->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=afede96e-1e00-0000-ebf0-6d32aa140000 pid=5290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=afede96e-1e00-0000-ebf0-6d32aa140000 pid=5290->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=3f6d4599-1f00-0000-ebf0-6d32b6140000 pid=5302 /tmp/cp net send-data zombie guuid=afede96e-1e00-0000-ebf0-6d32aa140000 pid=5290->guuid=3f6d4599-1f00-0000-ebf0-6d32b6140000 pid=5302 clone guuid=3f6d4599-1f00-0000-ebf0-6d32b6140000 pid=5302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3f6d4599-1f00-0000-ebf0-6d32b6140000 pid=5302->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 9B guuid=bb5f5999-1f00-0000-ebf0-6d32b7140000 pid=5303 /tmp/cp guuid=3f6d4599-1f00-0000-ebf0-6d32b6140000 pid=5302->guuid=bb5f5999-1f00-0000-ebf0-6d32b7140000 pid=5303 clone guuid=abd85e99-1f00-0000-ebf0-6d32b8140000 pid=5304->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=ede52ba5-1f00-0000-ebf0-6d32c1140000 pid=5313->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B guuid=ca00adb2-1f00-0000-ebf0-6d32c4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ca00adb2-1f00-0000-ebf0-6d32c4140000 pid=5316->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=0630f1dc-2000-0000-ebf0-6d32c5140000 pid=5317 /tmp/cp net send-data zombie guuid=ca00adb2-1f00-0000-ebf0-6d32c4140000 pid=5316->guuid=0630f1dc-2000-0000-ebf0-6d32c5140000 pid=5317 clone guuid=0630f1dc-2000-0000-ebf0-6d32c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0630f1dc-2000-0000-ebf0-6d32c5140000 pid=5317->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 8B guuid=270902dd-2000-0000-ebf0-6d32c7140000 pid=5319 /tmp/cp guuid=0630f1dc-2000-0000-ebf0-6d32c5140000 pid=5317->guuid=270902dd-2000-0000-ebf0-6d32c7140000 pid=5319 clone guuid=69e7fddc-2000-0000-ebf0-6d32c6140000 pid=5318->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 143B guuid=4f7ddfe8-2000-0000-ebf0-6d32c8140000 pid=5320->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 92B guuid=36602df6-2000-0000-ebf0-6d32cb140000 pid=5323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=36602df6-2000-0000-ebf0-6d32cb140000 pid=5323->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=6c11b020-2200-0000-ebf0-6d32cc140000 pid=5324 /tmp/cp net send-data zombie guuid=36602df6-2000-0000-ebf0-6d32cb140000 pid=5323->guuid=6c11b020-2200-0000-ebf0-6d32cc140000 pid=5324 clone guuid=6c11b020-2200-0000-ebf0-6d32cc140000 pid=5324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6c11b020-2200-0000-ebf0-6d32cc140000 pid=5324->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 18B guuid=eb9ecc20-2200-0000-ebf0-6d32ce140000 pid=5326 /tmp/cp guuid=6c11b020-2200-0000-ebf0-6d32cc140000 pid=5324->guuid=eb9ecc20-2200-0000-ebf0-6d32ce140000 pid=5326 clone guuid=bbe2cb20-2200-0000-ebf0-6d32cd140000 pid=5325->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 142B guuid=bee727bc-2200-0000-ebf0-6d32cf140000 pid=5327->efef254e-80b3-5bfb-b0bf-2e8b7a7434cf send: 91B guuid=13bee0c6-2200-0000-ebf0-6d32d2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=13bee0c6-2200-0000-ebf0-6d32d2140000 pid=5330->b9502367-5dd5-56e5-a2d2-9be7d9d70400 con guuid=237f43f1-2300-0000-ebf0-6d32d3140000 pid=5331 /tmp/cp net send-data zombie guuid=13bee0c6-2200-0000-ebf0-6d32d2140000 pid=5330->guuid=237f43f1-2300-0000-ebf0-6d32d3140000 pid=5331 clone guuid=237f43f1-2300-0000-ebf0-6d32d3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=237f43f1-2300-0000-ebf0-6d32d3140000 pid=5331->df7c0f9f-a1b8-565b-9132-7cd03da85718 send: 10B guuid=e34b5df1-2300-0000-ebf0-6d32d4140000 pid=5332 /tmp/cp guuid=237f43f1-2300-0000-ebf0-6d32d3140000 pid=5331->guuid=e34b5df1-2300-0000-ebf0-6d32d4140000 pid=5332 clone
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-11 05:33:43 UTC
File Type:
Text (Shell)
AV detection:
22 of 36 (61.11%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e8ee8ab1fdfc2e908493c8433ab4c67295e7a04c2fb98831bb56101d8ea73c26

(this sample)

  
Delivery method
Distributed via web download

Comments