MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1359a2e0dc123a9669174407dbc0735853fa403d411bfa360bcf0f2c05cf9280. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 1359a2e0dc123a9669174407dbc0735853fa403d411bfa360bcf0f2c05cf9280
SHA3-384 hash: ca7b6b7a477ff26d36009dabacf5874b9356c0473654002494a420ff9f14467c26a946b9d3abb25b6f0973144b41de31
SHA1 hash: ad821a37eb139327ac9a7b534005bdf02ba90c0e
MD5 hash: cefb461a7adfc4c1c170d42b892e20ce
humanhash: jig-august-fanta-enemy
File name:zte
Download: download sample
Signature Mirai
File size:2'807 bytes
First seen:2025-10-14 20:15:13 UTC
Last seen:2025-11-19 00:50:05 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vTWYWqWEWOWNkzEWJWqWjWEWSWLRUfWZWGZ:vTWYWqWEWOWmEWJWqWjWEWSWLRUfWZW4
TLSH T1675152C4722203707FF25D727DB640ACB2C5E1D2B6C59E89D4ECA8BD818DF0814E06A3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.91.237.162/bins/sora.x869209da6b229bc24256cf26833723fc3a7c89272a5af754861c095d350b99de10 Miraimirai opendir
http://64.91.237.162/bins/sora.mips29c7491b527a0e18a776b8cc1831a8ba4b97d917fd76d047c96cc5ae21a79924 Miraimirai opendir
http://64.91.237.162/bins/sora.x86_647e8a271658bd0f9be6bf33a2ea92ce4fad4774aafac33c5b2caedf6417fd15ac Miraimirai opendir
http://64.91.237.162/bins/sora.i468n/an/aelf ua-wget
http://64.91.237.162/bins/sora.i68692575fbaacd79518241425e42a4cdacbf65def900864a48fc0b27504f78cbff4 Miraimirai opendir
http://64.91.237.162/bins/sora.mpsla3b52b958c8ea783c24f7a02fb57b5228fc1969791021519b42e14e58124e30d Miraimirai opendir
http://64.91.237.162/bins/sora.arm4n/an/aelf ua-wget
http://64.91.237.162/bins/sora.arm56357efa12b55a6c1f2d555f6dbbe40a0ed2d5c1e2dced815347fa98881eeefcb Miraimirai opendir
http://64.91.237.162/bins/sora.arm6579e9db35f7d3e276a6fd3b2bb98091a12c58d4cb0cd0ed3ae3cdbfd19304b0a Miraimirai opendir
http://64.91.237.162/bins/sora.arm7a2a3eda8d88cb807ffc26480a5a40cf79ac74b135b8aadaa225fed856da77cef Miraimirai opendir
http://64.91.237.162/bins/sora.ppc773298e6d3a314ffe9554eeea412ac65fbb16cf4030acf0e2553c42a1f159bb2 Miraimirai opendir
http://64.91.237.162/bins/sora.ppc440fpn/an/aelf ua-wget
http://64.91.237.162/bins/sora.m68ka25e8659220a59deaae914fc945fa6b31667bc0c7146a968bec1c4be9ffee9ed Miraimirai opendir
http://64.91.237.162/bins/sora.sh40dd50416937f0bbb202464b09fb982739b34bde7d11834b78a137fc4659502de Miraimirai opendir

Intelligence


File Origin
# of uploads :
2
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-14T17:38:00Z UTC
Last seen:
2025-10-14T19:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0d769d5d-1a00-0000-9172-f030c80a0000 pid=2760 /usr/bin/sudo guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768 /tmp/sample.bin guuid=0d769d5d-1a00-0000-9172-f030c80a0000 pid=2760->guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768 execve guuid=a9a08161-1a00-0000-9172-f030d10a0000 pid=2769 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a9a08161-1a00-0000-9172-f030d10a0000 pid=2769 execve guuid=4c29e178-1a00-0000-9172-f030f90a0000 pid=2809 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=4c29e178-1a00-0000-9172-f030f90a0000 pid=2809 execve guuid=ef520595-1a00-0000-9172-f030330b0000 pid=2867 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=ef520595-1a00-0000-9172-f030330b0000 pid=2867 execve guuid=2b865a95-1a00-0000-9172-f030340b0000 pid=2868 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=2b865a95-1a00-0000-9172-f030340b0000 pid=2868 execve guuid=4f4ac795-1a00-0000-9172-f030370b0000 pid=2871 /tmp/robben net guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=4f4ac795-1a00-0000-9172-f030370b0000 pid=2871 execve guuid=c9eff298-1a00-0000-9172-f030410b0000 pid=2881 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=c9eff298-1a00-0000-9172-f030410b0000 pid=2881 execve guuid=2213e4ad-1a00-0000-9172-f030720b0000 pid=2930 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=2213e4ad-1a00-0000-9172-f030720b0000 pid=2930 execve guuid=9f54aac5-1a00-0000-9172-f030a00b0000 pid=2976 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=9f54aac5-1a00-0000-9172-f030a00b0000 pid=2976 execve guuid=c1f46cc6-1a00-0000-9172-f030a30b0000 pid=2979 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=c1f46cc6-1a00-0000-9172-f030a30b0000 pid=2979 execve guuid=09aadec6-1a00-0000-9172-f030a60b0000 pid=2982 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=09aadec6-1a00-0000-9172-f030a60b0000 pid=2982 clone guuid=3e2841c9-1a00-0000-9172-f030ad0b0000 pid=2989 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=3e2841c9-1a00-0000-9172-f030ad0b0000 pid=2989 execve guuid=7f20adde-1a00-0000-9172-f030ba0b0000 pid=3002 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=7f20adde-1a00-0000-9172-f030ba0b0000 pid=3002 execve guuid=03fc46f4-1a00-0000-9172-f030e30b0000 pid=3043 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=03fc46f4-1a00-0000-9172-f030e30b0000 pid=3043 execve guuid=d66eb5f4-1a00-0000-9172-f030e40b0000 pid=3044 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=d66eb5f4-1a00-0000-9172-f030e40b0000 pid=3044 execve guuid=857520f5-1a00-0000-9172-f030e70b0000 pid=3047 /tmp/robben mprotect-exec net guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=857520f5-1a00-0000-9172-f030e70b0000 pid=3047 execve guuid=661da7f8-1a00-0000-9172-f030f00b0000 pid=3056 /usr/bin/wget net send-data guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=661da7f8-1a00-0000-9172-f030f00b0000 pid=3056 execve guuid=a3389f07-1b00-0000-9172-f030160c0000 pid=3094 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a3389f07-1b00-0000-9172-f030160c0000 pid=3094 execve guuid=a229a317-1b00-0000-9172-f0303c0c0000 pid=3132 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a229a317-1b00-0000-9172-f0303c0c0000 pid=3132 execve guuid=a76bfb17-1b00-0000-9172-f0303e0c0000 pid=3134 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a76bfb17-1b00-0000-9172-f0303e0c0000 pid=3134 execve guuid=9b137d18-1b00-0000-9172-f030400c0000 pid=3136 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=9b137d18-1b00-0000-9172-f030400c0000 pid=3136 clone guuid=4d93a518-1b00-0000-9172-f030420c0000 pid=3138 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=4d93a518-1b00-0000-9172-f030420c0000 pid=3138 execve guuid=fffc122e-1b00-0000-9172-f030720c0000 pid=3186 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=fffc122e-1b00-0000-9172-f030720c0000 pid=3186 execve guuid=1a039746-1b00-0000-9172-f030860c0000 pid=3206 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=1a039746-1b00-0000-9172-f030860c0000 pid=3206 execve guuid=f25a0547-1b00-0000-9172-f030870c0000 pid=3207 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=f25a0547-1b00-0000-9172-f030870c0000 pid=3207 execve guuid=abc86547-1b00-0000-9172-f030880c0000 pid=3208 /tmp/robben net guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=abc86547-1b00-0000-9172-f030880c0000 pid=3208 execve guuid=7fe8284b-1b00-0000-9172-f030910c0000 pid=3217 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=7fe8284b-1b00-0000-9172-f030910c0000 pid=3217 execve guuid=63d57460-1b00-0000-9172-f030a40c0000 pid=3236 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=63d57460-1b00-0000-9172-f030a40c0000 pid=3236 execve guuid=98692f79-1b00-0000-9172-f030bb0c0000 pid=3259 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=98692f79-1b00-0000-9172-f030bb0c0000 pid=3259 execve guuid=bf3dc179-1b00-0000-9172-f030bc0c0000 pid=3260 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=bf3dc179-1b00-0000-9172-f030bc0c0000 pid=3260 execve guuid=022e417a-1b00-0000-9172-f030bd0c0000 pid=3261 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=022e417a-1b00-0000-9172-f030bd0c0000 pid=3261 clone guuid=d7cc027b-1b00-0000-9172-f030c00c0000 pid=3264 /usr/bin/wget net send-data guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=d7cc027b-1b00-0000-9172-f030c00c0000 pid=3264 execve guuid=eae3ad89-1b00-0000-9172-f030d40c0000 pid=3284 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=eae3ad89-1b00-0000-9172-f030d40c0000 pid=3284 execve guuid=d85c089b-1b00-0000-9172-f030fb0c0000 pid=3323 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=d85c089b-1b00-0000-9172-f030fb0c0000 pid=3323 execve guuid=4f71889b-1b00-0000-9172-f030fc0c0000 pid=3324 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=4f71889b-1b00-0000-9172-f030fc0c0000 pid=3324 execve guuid=1eee3a9c-1b00-0000-9172-f030fe0c0000 pid=3326 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=1eee3a9c-1b00-0000-9172-f030fe0c0000 pid=3326 clone guuid=11b28e9c-1b00-0000-9172-f030000d0000 pid=3328 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=11b28e9c-1b00-0000-9172-f030000d0000 pid=3328 execve guuid=2a0becb1-1b00-0000-9172-f030210d0000 pid=3361 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=2a0becb1-1b00-0000-9172-f030210d0000 pid=3361 execve guuid=a2f64ecb-1b00-0000-9172-f030540d0000 pid=3412 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a2f64ecb-1b00-0000-9172-f030540d0000 pid=3412 execve guuid=5c8ccfcb-1b00-0000-9172-f030560d0000 pid=3414 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=5c8ccfcb-1b00-0000-9172-f030560d0000 pid=3414 execve guuid=7cde39cc-1b00-0000-9172-f030580d0000 pid=3416 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=7cde39cc-1b00-0000-9172-f030580d0000 pid=3416 clone guuid=b7001fcd-1b00-0000-9172-f0305c0d0000 pid=3420 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=b7001fcd-1b00-0000-9172-f0305c0d0000 pid=3420 execve guuid=b50c4ae2-1b00-0000-9172-f0308a0d0000 pid=3466 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=b50c4ae2-1b00-0000-9172-f0308a0d0000 pid=3466 execve guuid=1a7404f9-1b00-0000-9172-f030ca0d0000 pid=3530 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=1a7404f9-1b00-0000-9172-f030ca0d0000 pid=3530 execve guuid=e6e36ef9-1b00-0000-9172-f030cb0d0000 pid=3531 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=e6e36ef9-1b00-0000-9172-f030cb0d0000 pid=3531 execve guuid=f531bff9-1b00-0000-9172-f030cc0d0000 pid=3532 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=f531bff9-1b00-0000-9172-f030cc0d0000 pid=3532 clone guuid=a4a55afa-1b00-0000-9172-f030ce0d0000 pid=3534 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a4a55afa-1b00-0000-9172-f030ce0d0000 pid=3534 execve guuid=9614c616-1c00-0000-9172-f030f20d0000 pid=3570 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=9614c616-1c00-0000-9172-f030f20d0000 pid=3570 execve guuid=cdc50e34-1c00-0000-9172-f030290e0000 pid=3625 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=cdc50e34-1c00-0000-9172-f030290e0000 pid=3625 execve guuid=96c09f34-1c00-0000-9172-f0302c0e0000 pid=3628 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=96c09f34-1c00-0000-9172-f0302c0e0000 pid=3628 execve guuid=a829f734-1c00-0000-9172-f0302d0e0000 pid=3629 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=a829f734-1c00-0000-9172-f0302d0e0000 pid=3629 clone guuid=3daae435-1c00-0000-9172-f030300e0000 pid=3632 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=3daae435-1c00-0000-9172-f030300e0000 pid=3632 execve guuid=0e10d44b-1c00-0000-9172-f030620e0000 pid=3682 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=0e10d44b-1c00-0000-9172-f030620e0000 pid=3682 execve guuid=6476c063-1c00-0000-9172-f0308d0e0000 pid=3725 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=6476c063-1c00-0000-9172-f0308d0e0000 pid=3725 execve guuid=ddb84564-1c00-0000-9172-f0308e0e0000 pid=3726 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=ddb84564-1c00-0000-9172-f0308e0e0000 pid=3726 execve guuid=8b00ca64-1c00-0000-9172-f0308f0e0000 pid=3727 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=8b00ca64-1c00-0000-9172-f0308f0e0000 pid=3727 clone guuid=5f24f366-1c00-0000-9172-f030970e0000 pid=3735 /usr/bin/wget net send-data guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=5f24f366-1c00-0000-9172-f030970e0000 pid=3735 execve guuid=3eb86e76-1c00-0000-9172-f030d20e0000 pid=3794 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=3eb86e76-1c00-0000-9172-f030d20e0000 pid=3794 execve guuid=f00e1986-1c00-0000-9172-f0300f0f0000 pid=3855 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=f00e1986-1c00-0000-9172-f0300f0f0000 pid=3855 execve guuid=52a06786-1c00-0000-9172-f030120f0000 pid=3858 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=52a06786-1c00-0000-9172-f030120f0000 pid=3858 execve guuid=4459b586-1c00-0000-9172-f030130f0000 pid=3859 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=4459b586-1c00-0000-9172-f030130f0000 pid=3859 clone guuid=b4bfda86-1c00-0000-9172-f030140f0000 pid=3860 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=b4bfda86-1c00-0000-9172-f030140f0000 pid=3860 execve guuid=eb2c8ca2-1c00-0000-9172-f0306f0f0000 pid=3951 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=eb2c8ca2-1c00-0000-9172-f0306f0f0000 pid=3951 execve guuid=e24bc2c2-1c00-0000-9172-f030d30f0000 pid=4051 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=e24bc2c2-1c00-0000-9172-f030d30f0000 pid=4051 execve guuid=c04e14c3-1c00-0000-9172-f030d50f0000 pid=4053 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=c04e14c3-1c00-0000-9172-f030d50f0000 pid=4053 execve guuid=76f477c3-1c00-0000-9172-f030d70f0000 pid=4055 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=76f477c3-1c00-0000-9172-f030d70f0000 pid=4055 clone guuid=8b89ffc4-1c00-0000-9172-f030df0f0000 pid=4063 /usr/bin/wget net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=8b89ffc4-1c00-0000-9172-f030df0f0000 pid=4063 execve guuid=bacd04e1-1c00-0000-9172-f03030100000 pid=4144 /usr/bin/curl net send-data write-file guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=bacd04e1-1c00-0000-9172-f03030100000 pid=4144 execve guuid=e84dec00-1d00-0000-9172-f03083100000 pid=4227 /usr/bin/cat guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=e84dec00-1d00-0000-9172-f03083100000 pid=4227 execve guuid=70cd5701-1d00-0000-9172-f03084100000 pid=4228 /usr/bin/chmod guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=70cd5701-1d00-0000-9172-f03084100000 pid=4228 execve guuid=9737c301-1d00-0000-9172-f03085100000 pid=4229 /usr/bin/bash guuid=7f461161-1a00-0000-9172-f030d00a0000 pid=2768->guuid=9737c301-1d00-0000-9172-f03085100000 pid=4229 clone 10651e68-131f-5e6d-a670-1d19a7120e88 64.91.237.162:80 guuid=a9a08161-1a00-0000-9172-f030d10a0000 pid=2769->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=4c29e178-1a00-0000-9172-f030f90a0000 pid=2809->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4f4ac795-1a00-0000-9172-f030370b0000 pid=2871->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c9eff298-1a00-0000-9172-f030410b0000 pid=2881->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=2213e4ad-1a00-0000-9172-f030720b0000 pid=2930->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=3e2841c9-1a00-0000-9172-f030ad0b0000 pid=2989->10651e68-131f-5e6d-a670-1d19a7120e88 send: 144B guuid=7f20adde-1a00-0000-9172-f030ba0b0000 pid=3002->10651e68-131f-5e6d-a670-1d19a7120e88 send: 93B guuid=857520f5-1a00-0000-9172-f030e70b0000 pid=3047->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=661da7f8-1a00-0000-9172-f030f00b0000 pid=3056->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=a3389f07-1b00-0000-9172-f030160c0000 pid=3094->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=4d93a518-1b00-0000-9172-f030420c0000 pid=3138->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=fffc122e-1b00-0000-9172-f030720c0000 pid=3186->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=abc86547-1b00-0000-9172-f030880c0000 pid=3208->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7fe8284b-1b00-0000-9172-f030910c0000 pid=3217->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=63d57460-1b00-0000-9172-f030a40c0000 pid=3236->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=d7cc027b-1b00-0000-9172-f030c00c0000 pid=3264->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=eae3ad89-1b00-0000-9172-f030d40c0000 pid=3284->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=11b28e9c-1b00-0000-9172-f030000d0000 pid=3328->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=2a0becb1-1b00-0000-9172-f030210d0000 pid=3361->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=b7001fcd-1b00-0000-9172-f0305c0d0000 pid=3420->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=b50c4ae2-1b00-0000-9172-f0308a0d0000 pid=3466->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=a4a55afa-1b00-0000-9172-f030ce0d0000 pid=3534->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=9614c616-1c00-0000-9172-f030f20d0000 pid=3570->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=3daae435-1c00-0000-9172-f030300e0000 pid=3632->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=0e10d44b-1c00-0000-9172-f030620e0000 pid=3682->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B guuid=5f24f366-1c00-0000-9172-f030970e0000 pid=3735->10651e68-131f-5e6d-a670-1d19a7120e88 send: 146B guuid=3eb86e76-1c00-0000-9172-f030d20e0000 pid=3794->10651e68-131f-5e6d-a670-1d19a7120e88 send: 95B guuid=b4bfda86-1c00-0000-9172-f030140f0000 pid=3860->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=eb2c8ca2-1c00-0000-9172-f0306f0f0000 pid=3951->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=8b89ffc4-1c00-0000-9172-f030df0f0000 pid=4063->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=bacd04e1-1c00-0000-9172-f03030100000 pid=4144->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-14 20:20:37 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (37632) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1359a2e0dc123a9669174407dbc0735853fa403d411bfa360bcf0f2c05cf9280

(this sample)

  
Delivery method
Distributed via web download

Comments