MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f2a8379b2099f6250c90def328ad9e98e36c869bcad082e46e815f5d725e75a3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: f2a8379b2099f6250c90def328ad9e98e36c869bcad082e46e815f5d725e75a3
SHA3-384 hash: 2273841ae8a64da6449b7a7a7cb7ba6b8000e7e879a50172a344f6ed11ff877b6cbf01fb0f61ba9d4bbc1539fbc961d5
SHA1 hash: 05029118d878f8e9a05f07bb4edee9dca1a1a78b
MD5 hash: 76742d1c2a782a218a195642a590bda2
humanhash: nineteen-delta-video-blossom
File name:skid.sh
Download: download sample
Signature Mirai
File size:2'534 bytes
First seen:2026-01-11 05:34:52 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vd0DuIBtGP1OXmKLTDoo9ItM13BWhFnH9eDTN4XY:vmDuaEPEFDj+u10zHcDTSo
TLSH T1C85191942162C1F27E9EBF3362B90594B2D562F35CF05F29D8D939E94D9CE087085A83
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://195.24.237.39/bin/skid.x86cad75da344df34c316635c5fe362436f9e0b8435ff8b25777d1544445e007e2b Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.mips2df3377218da5c67f41f469adc2479b1849e0ac46a9fa2c8e1c0531fcaa771de Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.arc946c0a8ef9e19f416a340070ea4e95c6f5be76b722c8ff8d7029b9532673da22 Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.i586n/an/aelf ua-wget
http://195.24.237.39/bin/skid.x86_64n/an/aelf ua-wget
http://195.24.237.39/bin/skid.mpsl1eadf9761eee38479d93ad0049a1a7de4633965dc4b8d71e8dee33a4dbcd8a04 Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.arma652653dea5135bf54bf130e52cd65ca453099b1c20b8067c95817259c8e5d0f Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.arm5ef303a9c0d6f9b70402e23b1dde531f200d329432ad01939f844178f0dc78112 Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.arm6690564fbfb45c8bd2892f4fb0d80d0b8b69a3381fb9b7a0f3f19f7a0484323fd Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.arm7f5e51b440f89d13c0e0bc3fb2254ad2608903034dffdf038f97c6b86be765f1c Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.ppcc541df3e8f0b61b138b01279318384d86eaeb2ec21dc89095cb9097e357bf2c8 Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.spcdf0fb1a9b7c32e0edaac9fde2acd93616726d5635944e60b637fb05ac6e79c0f Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.m68k027dea1b05ae120f463c2b600c6ea114dfd75c7eb703acf97d3181464739b779 Miraielf mirai ua-wget
http://195.24.237.39/bin/skid.sh4830dd4a46a5ae29d0c6c6df144630971090b1e7e3ff732baad25c793263ae12d Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-10T22:23:00Z UTC
Last seen:
2026-01-12T12:48:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=9318535e-1900-0000-ad97-c99c51090000 pid=2385 /usr/bin/sudo guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388 /tmp/sample.bin guuid=9318535e-1900-0000-ad97-c99c51090000 pid=2385->guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388 execve guuid=ca570362-1900-0000-ad97-c99c57090000 pid=2391 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=ca570362-1900-0000-ad97-c99c57090000 pid=2391 execve guuid=30ebce68-1900-0000-ad97-c99c60090000 pid=2400 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=30ebce68-1900-0000-ad97-c99c60090000 pid=2400 execve guuid=197e6974-1900-0000-ad97-c99c73090000 pid=2419 /usr/bin/cat guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=197e6974-1900-0000-ad97-c99c73090000 pid=2419 execve guuid=8eb53275-1900-0000-ad97-c99c75090000 pid=2421 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=8eb53275-1900-0000-ad97-c99c75090000 pid=2421 execve guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423 execve guuid=295e0b76-1900-0000-ad97-c99c7b090000 pid=2427 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=295e0b76-1900-0000-ad97-c99c7b090000 pid=2427 execve guuid=0a51cf7d-1900-0000-ad97-c99c87090000 pid=2439 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=0a51cf7d-1900-0000-ad97-c99c87090000 pid=2439 execve guuid=299e6087-1900-0000-ad97-c99c9e090000 pid=2462 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=299e6087-1900-0000-ad97-c99c9e090000 pid=2462 clone guuid=6d0d8787-1900-0000-ad97-c99ca0090000 pid=2464 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=6d0d8787-1900-0000-ad97-c99ca0090000 pid=2464 execve guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466 execve guuid=1a678088-1900-0000-ad97-c99ca7090000 pid=2471 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1a678088-1900-0000-ad97-c99ca7090000 pid=2471 execve guuid=13500e8f-1900-0000-ad97-c99caf090000 pid=2479 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=13500e8f-1900-0000-ad97-c99caf090000 pid=2479 execve guuid=dc122f96-1900-0000-ad97-c99cc5090000 pid=2501 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=dc122f96-1900-0000-ad97-c99cc5090000 pid=2501 clone guuid=1e975396-1900-0000-ad97-c99cc6090000 pid=2502 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1e975396-1900-0000-ad97-c99cc6090000 pid=2502 execve guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504 execve guuid=1aed2797-1900-0000-ad97-c99ccd090000 pid=2509 /usr/bin/wget net send-data guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1aed2797-1900-0000-ad97-c99ccd090000 pid=2509 execve guuid=6b55ea99-1900-0000-ad97-c99cd5090000 pid=2517 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=6b55ea99-1900-0000-ad97-c99cd5090000 pid=2517 execve guuid=462d219e-1900-0000-ad97-c99cde090000 pid=2526 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=462d219e-1900-0000-ad97-c99cde090000 pid=2526 clone guuid=dc2c3b9e-1900-0000-ad97-c99cdf090000 pid=2527 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=dc2c3b9e-1900-0000-ad97-c99cdf090000 pid=2527 execve guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530 execve guuid=b863209f-1900-0000-ad97-c99ce7090000 pid=2535 /usr/bin/wget net send-data guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=b863209f-1900-0000-ad97-c99ce7090000 pid=2535 execve guuid=1d9ab1a2-1900-0000-ad97-c99cf0090000 pid=2544 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1d9ab1a2-1900-0000-ad97-c99cf0090000 pid=2544 execve guuid=2dc903a7-1900-0000-ad97-c99cfc090000 pid=2556 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=2dc903a7-1900-0000-ad97-c99cfc090000 pid=2556 clone guuid=32b721a7-1900-0000-ad97-c99cfd090000 pid=2557 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=32b721a7-1900-0000-ad97-c99cfd090000 pid=2557 execve guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559 execve guuid=8844e8a7-1900-0000-ad97-c99c040a0000 pid=2564 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=8844e8a7-1900-0000-ad97-c99c040a0000 pid=2564 execve guuid=2f2ab1ab-1900-0000-ad97-c99c0d0a0000 pid=2573 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=2f2ab1ab-1900-0000-ad97-c99c0d0a0000 pid=2573 execve guuid=a00053b0-1900-0000-ad97-c99c190a0000 pid=2585 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=a00053b0-1900-0000-ad97-c99c190a0000 pid=2585 clone guuid=00e96fb0-1900-0000-ad97-c99c1a0a0000 pid=2586 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=00e96fb0-1900-0000-ad97-c99c1a0a0000 pid=2586 execve guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589 execve guuid=e74b18b1-1900-0000-ad97-c99c210a0000 pid=2593 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=e74b18b1-1900-0000-ad97-c99c210a0000 pid=2593 execve guuid=cf3fddb4-1900-0000-ad97-c99c2b0a0000 pid=2603 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=cf3fddb4-1900-0000-ad97-c99c2b0a0000 pid=2603 execve guuid=673323ba-1900-0000-ad97-c99c390a0000 pid=2617 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=673323ba-1900-0000-ad97-c99c390a0000 pid=2617 clone guuid=e2213cba-1900-0000-ad97-c99c3a0a0000 pid=2618 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=e2213cba-1900-0000-ad97-c99c3a0a0000 pid=2618 execve guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620 execve guuid=b576e3ba-1900-0000-ad97-c99c410a0000 pid=2625 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=b576e3ba-1900-0000-ad97-c99c410a0000 pid=2625 execve guuid=0833aabe-1900-0000-ad97-c99c4c0a0000 pid=2636 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=0833aabe-1900-0000-ad97-c99c4c0a0000 pid=2636 execve guuid=13cb80c4-1900-0000-ad97-c99c5b0a0000 pid=2651 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=13cb80c4-1900-0000-ad97-c99c5b0a0000 pid=2651 clone guuid=b9fab8c4-1900-0000-ad97-c99c5d0a0000 pid=2653 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=b9fab8c4-1900-0000-ad97-c99c5d0a0000 pid=2653 execve guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655 execve guuid=67c77ac5-1900-0000-ad97-c99c640a0000 pid=2660 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=67c77ac5-1900-0000-ad97-c99c640a0000 pid=2660 execve guuid=bed8c0c9-1900-0000-ad97-c99c710a0000 pid=2673 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=bed8c0c9-1900-0000-ad97-c99c710a0000 pid=2673 execve guuid=6dde04cf-1900-0000-ad97-c99c810a0000 pid=2689 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=6dde04cf-1900-0000-ad97-c99c810a0000 pid=2689 clone guuid=a2042acf-1900-0000-ad97-c99c820a0000 pid=2690 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=a2042acf-1900-0000-ad97-c99c820a0000 pid=2690 execve guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692 execve guuid=d92ddacf-1900-0000-ad97-c99c890a0000 pid=2697 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=d92ddacf-1900-0000-ad97-c99c890a0000 pid=2697 execve guuid=a861f5d4-1900-0000-ad97-c99c980a0000 pid=2712 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=a861f5d4-1900-0000-ad97-c99c980a0000 pid=2712 execve guuid=a8b0a0db-1900-0000-ad97-c99ca90a0000 pid=2729 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=a8b0a0db-1900-0000-ad97-c99ca90a0000 pid=2729 clone guuid=1756bddb-1900-0000-ad97-c99caa0a0000 pid=2730 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1756bddb-1900-0000-ad97-c99caa0a0000 pid=2730 execve guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732 execve guuid=26be62dc-1900-0000-ad97-c99cb10a0000 pid=2737 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=26be62dc-1900-0000-ad97-c99cb10a0000 pid=2737 execve guuid=f6accbe0-1900-0000-ad97-c99cbf0a0000 pid=2751 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=f6accbe0-1900-0000-ad97-c99cbf0a0000 pid=2751 execve guuid=8ea83fe5-1900-0000-ad97-c99cce0a0000 pid=2766 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=8ea83fe5-1900-0000-ad97-c99cce0a0000 pid=2766 clone guuid=63115ae5-1900-0000-ad97-c99ccf0a0000 pid=2767 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=63115ae5-1900-0000-ad97-c99ccf0a0000 pid=2767 execve guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769 execve guuid=dcaee9e5-1900-0000-ad97-c99cd60a0000 pid=2774 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=dcaee9e5-1900-0000-ad97-c99cd60a0000 pid=2774 execve guuid=c77f95ea-1900-0000-ad97-c99ce30a0000 pid=2787 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=c77f95ea-1900-0000-ad97-c99ce30a0000 pid=2787 execve guuid=07acdeef-1900-0000-ad97-c99cf20a0000 pid=2802 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=07acdeef-1900-0000-ad97-c99cf20a0000 pid=2802 clone guuid=bb2409f0-1900-0000-ad97-c99cf30a0000 pid=2803 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=bb2409f0-1900-0000-ad97-c99cf30a0000 pid=2803 execve guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805 execve guuid=1e09f0f0-1900-0000-ad97-c99cfa0a0000 pid=2810 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=1e09f0f0-1900-0000-ad97-c99cfa0a0000 pid=2810 execve guuid=d1b9a8f5-1900-0000-ad97-c99c080b0000 pid=2824 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=d1b9a8f5-1900-0000-ad97-c99c080b0000 pid=2824 execve guuid=e51f2ffb-1900-0000-ad97-c99c150b0000 pid=2837 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=e51f2ffb-1900-0000-ad97-c99c150b0000 pid=2837 clone guuid=2b9b48fb-1900-0000-ad97-c99c160b0000 pid=2838 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=2b9b48fb-1900-0000-ad97-c99c160b0000 pid=2838 execve guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840 execve guuid=dcbad7fb-1900-0000-ad97-c99c1d0b0000 pid=2845 /usr/bin/wget net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=dcbad7fb-1900-0000-ad97-c99c1d0b0000 pid=2845 execve guuid=15f77a00-1a00-0000-ad97-c99c260b0000 pid=2854 /usr/bin/curl net send-data write-file guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=15f77a00-1a00-0000-ad97-c99c260b0000 pid=2854 execve guuid=e9516806-1a00-0000-ad97-c99c340b0000 pid=2868 /usr/bin/bash guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=e9516806-1a00-0000-ad97-c99c340b0000 pid=2868 clone guuid=5a228f06-1a00-0000-ad97-c99c350b0000 pid=2869 /usr/bin/chmod guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=5a228f06-1a00-0000-ad97-c99c350b0000 pid=2869 execve guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871 /tmp/init-d net guuid=64dc0861-1900-0000-ad97-c99c54090000 pid=2388->guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871 execve 183dcefe-2155-56a8-8af7-7d1a53c55d62 195.24.237.39:80 guuid=ca570362-1900-0000-ad97-c99c57090000 pid=2391->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=30ebce68-1900-0000-ad97-c99c60090000 pid=2400->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c41ef075-1900-0000-ad97-c99c78090000 pid=2424 /tmp/init-d guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423->guuid=c41ef075-1900-0000-ad97-c99c78090000 pid=2424 clone guuid=6bd9f675-1900-0000-ad97-c99c79090000 pid=2425 /tmp/init-d guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423->guuid=6bd9f675-1900-0000-ad97-c99c79090000 pid=2425 clone guuid=af34fe75-1900-0000-ad97-c99c7a090000 pid=2426 /tmp/init-d net zombie guuid=e8bda375-1900-0000-ad97-c99c77090000 pid=2423->guuid=af34fe75-1900-0000-ad97-c99c7a090000 pid=2426 clone 526b7c46-4508-52a3-a9d1-fd9e86e95f5e 195.24.237.39:3778 guuid=af34fe75-1900-0000-ad97-c99c7a090000 pid=2426->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=295e0b76-1900-0000-ad97-c99c7b090000 pid=2427->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=0a51cf7d-1900-0000-ad97-c99c87090000 pid=2439->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=06db5988-1900-0000-ad97-c99ca4090000 pid=2468 /tmp/init-d guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466->guuid=06db5988-1900-0000-ad97-c99ca4090000 pid=2468 clone guuid=d7d56088-1900-0000-ad97-c99ca5090000 pid=2469 /tmp/init-d guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466->guuid=d7d56088-1900-0000-ad97-c99ca5090000 pid=2469 clone guuid=54e86988-1900-0000-ad97-c99ca6090000 pid=2470 /tmp/init-d net zombie guuid=b56c0f88-1900-0000-ad97-c99ca2090000 pid=2466->guuid=54e86988-1900-0000-ad97-c99ca6090000 pid=2470 clone guuid=54e86988-1900-0000-ad97-c99ca6090000 pid=2470->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=1a678088-1900-0000-ad97-c99ca7090000 pid=2471->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=13500e8f-1900-0000-ad97-c99caf090000 pid=2479->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=55920597-1900-0000-ad97-c99cca090000 pid=2506 /tmp/init-d guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504->guuid=55920597-1900-0000-ad97-c99cca090000 pid=2506 clone guuid=ef201097-1900-0000-ad97-c99ccb090000 pid=2507 /tmp/init-d guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504->guuid=ef201097-1900-0000-ad97-c99ccb090000 pid=2507 clone guuid=fd571597-1900-0000-ad97-c99ccc090000 pid=2508 /tmp/init-d net zombie guuid=b29db596-1900-0000-ad97-c99cc8090000 pid=2504->guuid=fd571597-1900-0000-ad97-c99ccc090000 pid=2508 clone guuid=fd571597-1900-0000-ad97-c99ccc090000 pid=2508->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=1aed2797-1900-0000-ad97-c99ccd090000 pid=2509->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=6b55ea99-1900-0000-ad97-c99cd5090000 pid=2517->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e6f30b9f-1900-0000-ad97-c99ce4090000 pid=2532 /tmp/init-d guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530->guuid=e6f30b9f-1900-0000-ad97-c99ce4090000 pid=2532 clone guuid=6360109f-1900-0000-ad97-c99ce5090000 pid=2533 /tmp/init-d guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530->guuid=6360109f-1900-0000-ad97-c99ce5090000 pid=2533 clone guuid=586a169f-1900-0000-ad97-c99ce6090000 pid=2534 /tmp/init-d net zombie guuid=39bcd19e-1900-0000-ad97-c99ce2090000 pid=2530->guuid=586a169f-1900-0000-ad97-c99ce6090000 pid=2534 clone guuid=586a169f-1900-0000-ad97-c99ce6090000 pid=2534->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=b863209f-1900-0000-ad97-c99ce7090000 pid=2535->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 143B guuid=1d9ab1a2-1900-0000-ad97-c99cf0090000 pid=2544->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 92B guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2c33cca7-1900-0000-ad97-c99c010a0000 pid=2561 /tmp/init-d guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559->guuid=2c33cca7-1900-0000-ad97-c99c010a0000 pid=2561 clone guuid=13a3cfa7-1900-0000-ad97-c99c020a0000 pid=2562 /tmp/init-d guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559->guuid=13a3cfa7-1900-0000-ad97-c99c020a0000 pid=2562 clone guuid=b3b3d6a7-1900-0000-ad97-c99c030a0000 pid=2563 /tmp/init-d net zombie guuid=cc5691a7-1900-0000-ad97-c99cff090000 pid=2559->guuid=b3b3d6a7-1900-0000-ad97-c99c030a0000 pid=2563 clone guuid=b3b3d6a7-1900-0000-ad97-c99c030a0000 pid=2563->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=8844e8a7-1900-0000-ad97-c99c040a0000 pid=2564->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=2f2ab1ab-1900-0000-ad97-c99c0d0a0000 pid=2573->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d58107b1-1900-0000-ad97-c99c1e0a0000 pid=2590 /tmp/init-d guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589->guuid=d58107b1-1900-0000-ad97-c99c1e0a0000 pid=2590 clone guuid=00750ab1-1900-0000-ad97-c99c1f0a0000 pid=2591 /tmp/init-d guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589->guuid=00750ab1-1900-0000-ad97-c99c1f0a0000 pid=2591 clone guuid=5ab40db1-1900-0000-ad97-c99c200a0000 pid=2592 /tmp/init-d net zombie guuid=ed17dab0-1900-0000-ad97-c99c1d0a0000 pid=2589->guuid=5ab40db1-1900-0000-ad97-c99c200a0000 pid=2592 clone guuid=5ab40db1-1900-0000-ad97-c99c200a0000 pid=2592->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=e74b18b1-1900-0000-ad97-c99c210a0000 pid=2593->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=cf3fddb4-1900-0000-ad97-c99c2b0a0000 pid=2603->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6afeccba-1900-0000-ad97-c99c3e0a0000 pid=2622 /tmp/init-d guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620->guuid=6afeccba-1900-0000-ad97-c99c3e0a0000 pid=2622 clone guuid=eba4d1ba-1900-0000-ad97-c99c3f0a0000 pid=2623 /tmp/init-d guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620->guuid=eba4d1ba-1900-0000-ad97-c99c3f0a0000 pid=2623 clone guuid=f588d6ba-1900-0000-ad97-c99c400a0000 pid=2624 /tmp/init-d net zombie guuid=ed829eba-1900-0000-ad97-c99c3c0a0000 pid=2620->guuid=f588d6ba-1900-0000-ad97-c99c400a0000 pid=2624 clone guuid=f588d6ba-1900-0000-ad97-c99c400a0000 pid=2624->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=b576e3ba-1900-0000-ad97-c99c410a0000 pid=2625->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=0833aabe-1900-0000-ad97-c99c4c0a0000 pid=2636->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=230e65c5-1900-0000-ad97-c99c610a0000 pid=2657 /tmp/init-d guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655->guuid=230e65c5-1900-0000-ad97-c99c610a0000 pid=2657 clone guuid=f30168c5-1900-0000-ad97-c99c620a0000 pid=2658 /tmp/init-d guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655->guuid=f30168c5-1900-0000-ad97-c99c620a0000 pid=2658 clone guuid=58206bc5-1900-0000-ad97-c99c630a0000 pid=2659 /tmp/init-d net zombie guuid=78c128c5-1900-0000-ad97-c99c5f0a0000 pid=2655->guuid=58206bc5-1900-0000-ad97-c99c630a0000 pid=2659 clone guuid=58206bc5-1900-0000-ad97-c99c630a0000 pid=2659->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=67c77ac5-1900-0000-ad97-c99c640a0000 pid=2660->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=bed8c0c9-1900-0000-ad97-c99c710a0000 pid=2673->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c15abbcf-1900-0000-ad97-c99c860a0000 pid=2694 /tmp/init-d guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692->guuid=c15abbcf-1900-0000-ad97-c99c860a0000 pid=2694 clone guuid=ed27c0cf-1900-0000-ad97-c99c870a0000 pid=2695 /tmp/init-d guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692->guuid=ed27c0cf-1900-0000-ad97-c99c870a0000 pid=2695 clone guuid=9645c9cf-1900-0000-ad97-c99c880a0000 pid=2696 /tmp/init-d net zombie guuid=8c2c82cf-1900-0000-ad97-c99c840a0000 pid=2692->guuid=9645c9cf-1900-0000-ad97-c99c880a0000 pid=2696 clone guuid=9645c9cf-1900-0000-ad97-c99c880a0000 pid=2696->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=d92ddacf-1900-0000-ad97-c99c890a0000 pid=2697->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=a861f5d4-1900-0000-ad97-c99c980a0000 pid=2712->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce634cdc-1900-0000-ad97-c99cae0a0000 pid=2734 /tmp/init-d guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732->guuid=ce634cdc-1900-0000-ad97-c99cae0a0000 pid=2734 clone guuid=1d9a4fdc-1900-0000-ad97-c99caf0a0000 pid=2735 /tmp/init-d guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732->guuid=1d9a4fdc-1900-0000-ad97-c99caf0a0000 pid=2735 clone guuid=7ffa54dc-1900-0000-ad97-c99cb00a0000 pid=2736 /tmp/init-d net zombie guuid=daae20dc-1900-0000-ad97-c99cac0a0000 pid=2732->guuid=7ffa54dc-1900-0000-ad97-c99cb00a0000 pid=2736 clone guuid=7ffa54dc-1900-0000-ad97-c99cb00a0000 pid=2736->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=26be62dc-1900-0000-ad97-c99cb10a0000 pid=2737->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=f6accbe0-1900-0000-ad97-c99cbf0a0000 pid=2751->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=17cfd2e5-1900-0000-ad97-c99cd20a0000 pid=2770 /tmp/init-d guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769->guuid=17cfd2e5-1900-0000-ad97-c99cd20a0000 pid=2770 clone guuid=afbfd7e5-1900-0000-ad97-c99cd40a0000 pid=2772 /tmp/init-d guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769->guuid=afbfd7e5-1900-0000-ad97-c99cd40a0000 pid=2772 clone guuid=83cadce5-1900-0000-ad97-c99cd50a0000 pid=2773 /tmp/init-d net zombie guuid=6f2999e5-1900-0000-ad97-c99cd10a0000 pid=2769->guuid=83cadce5-1900-0000-ad97-c99cd50a0000 pid=2773 clone guuid=83cadce5-1900-0000-ad97-c99cd50a0000 pid=2773->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=dcaee9e5-1900-0000-ad97-c99cd60a0000 pid=2774->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=c77f95ea-1900-0000-ad97-c99ce30a0000 pid=2787->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d96bc5f0-1900-0000-ad97-c99cf70a0000 pid=2807 /tmp/init-d guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805->guuid=d96bc5f0-1900-0000-ad97-c99cf70a0000 pid=2807 clone guuid=91afd0f0-1900-0000-ad97-c99cf80a0000 pid=2808 /tmp/init-d guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805->guuid=91afd0f0-1900-0000-ad97-c99cf80a0000 pid=2808 clone guuid=1aa0daf0-1900-0000-ad97-c99cf90a0000 pid=2809 /tmp/init-d net zombie guuid=ef4d76f0-1900-0000-ad97-c99cf50a0000 pid=2805->guuid=1aa0daf0-1900-0000-ad97-c99cf90a0000 pid=2809 clone guuid=1aa0daf0-1900-0000-ad97-c99cf90a0000 pid=2809->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=1e09f0f0-1900-0000-ad97-c99cfa0a0000 pid=2810->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 141B guuid=d1b9a8f5-1900-0000-ad97-c99c080b0000 pid=2824->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 90B guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4b53c0fb-1900-0000-ad97-c99c1a0b0000 pid=2842 /tmp/init-d guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840->guuid=4b53c0fb-1900-0000-ad97-c99c1a0b0000 pid=2842 clone guuid=a053c3fb-1900-0000-ad97-c99c1b0b0000 pid=2843 /tmp/init-d guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840->guuid=a053c3fb-1900-0000-ad97-c99c1b0b0000 pid=2843 clone guuid=cc3fc6fb-1900-0000-ad97-c99c1c0b0000 pid=2844 /tmp/init-d net zombie guuid=f4b593fb-1900-0000-ad97-c99c180b0000 pid=2840->guuid=cc3fc6fb-1900-0000-ad97-c99c1c0b0000 pid=2844 clone guuid=cc3fc6fb-1900-0000-ad97-c99c1c0b0000 pid=2844->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con guuid=dcbad7fb-1900-0000-ad97-c99c1d0b0000 pid=2845->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 140B guuid=15f77a00-1a00-0000-ad97-c99c260b0000 pid=2854->183dcefe-2155-56a8-8af7-7d1a53c55d62 send: 89B guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0ea11207-1a00-0000-ad97-c99c390b0000 pid=2873 /tmp/init-d guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871->guuid=0ea11207-1a00-0000-ad97-c99c390b0000 pid=2873 clone guuid=5e2b1907-1a00-0000-ad97-c99c3a0b0000 pid=2874 /tmp/init-d guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871->guuid=5e2b1907-1a00-0000-ad97-c99c3a0b0000 pid=2874 clone guuid=ce8f2107-1a00-0000-ad97-c99c3b0b0000 pid=2875 /tmp/init-d net zombie guuid=cf5cd606-1a00-0000-ad97-c99c370b0000 pid=2871->guuid=ce8f2107-1a00-0000-ad97-c99c3b0b0000 pid=2875 clone guuid=ce8f2107-1a00-0000-ad97-c99c3b0b0000 pid=2875->526b7c46-4508-52a3-a9d1-fd9e86e95f5e con
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-01-11 01:48:50 UTC
File Type:
Text (Shell)
AV detection:
16 of 24 (66.67%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f2a8379b2099f6250c90def328ad9e98e36c869bcad082e46e815f5d725e75a3

(this sample)

  
Delivery method
Distributed via web download

Comments