MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1532042b11c1469ea5b9e421f85a9e0f046e1c3eeae9d002b9a566c7d980a4a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1532042b11c1469ea5b9e421f85a9e0f046e1c3eeae9d002b9a566c7d980a4a0
SHA3-384 hash: 43a937c6f6a475dcf7bcc51a2aa3e5e3c9e74a69649d0257d1e879f862a8b34b84f4c2109107d99851162f6061420654
SHA1 hash: 5c2157fe9640634f4b2e9f5c5bf17225eb2d9a9a
MD5 hash: db5b338bedb284e0669258e193da0571
humanhash: ack-vegan-network-timing
File name:jaws
Download: download sample
File size:2'412 bytes
First seen:2025-07-10 12:29:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSorx0xX9Trxuwxuj8rxZxawrxyxlnrxbx02rx8xfBrxGxpXrxdxuMrxnxAh:vlTSoliX9Tlb68l7awlQlnlV02lKfBl3
TLSH T13D4191F51145073CACF2A96E71E789C8B6E296C620C39FD4D5FC38E5404DE583DA2E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
26
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=9753b1da-2100-0000-c66e-32d5c2070000 pid=1986 /usr/bin/sudo guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987 /tmp/sample.bin guuid=9753b1da-2100-0000-c66e-32d5c2070000 pid=1986->guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987 execve guuid=79918fdf-2100-0000-c66e-32d5c4070000 pid=1988 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=79918fdf-2100-0000-c66e-32d5c4070000 pid=1988 execve guuid=382237e4-2100-0000-c66e-32d5c6070000 pid=1990 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=382237e4-2100-0000-c66e-32d5c6070000 pid=1990 execve guuid=e17d12ed-2100-0000-c66e-32d5d5070000 pid=2005 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=e17d12ed-2100-0000-c66e-32d5d5070000 pid=2005 execve guuid=c32d93ed-2100-0000-c66e-32d5d6070000 pid=2006 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=c32d93ed-2100-0000-c66e-32d5d6070000 pid=2006 execve guuid=9d9c28ee-2100-0000-c66e-32d5d7070000 pid=2007 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=9d9c28ee-2100-0000-c66e-32d5d7070000 pid=2007 clone guuid=fbc175ee-2100-0000-c66e-32d5d8070000 pid=2008 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=fbc175ee-2100-0000-c66e-32d5d8070000 pid=2008 execve guuid=aa4a67f0-2100-0000-c66e-32d5df070000 pid=2015 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=aa4a67f0-2100-0000-c66e-32d5df070000 pid=2015 execve guuid=c22fbcf6-2100-0000-c66e-32d5ea070000 pid=2026 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=c22fbcf6-2100-0000-c66e-32d5ea070000 pid=2026 execve guuid=ac5412f7-2100-0000-c66e-32d5ec070000 pid=2028 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=ac5412f7-2100-0000-c66e-32d5ec070000 pid=2028 execve guuid=f0bd58f7-2100-0000-c66e-32d5ee070000 pid=2030 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=f0bd58f7-2100-0000-c66e-32d5ee070000 pid=2030 clone guuid=aa168bf7-2100-0000-c66e-32d5f0070000 pid=2032 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=aa168bf7-2100-0000-c66e-32d5f0070000 pid=2032 execve guuid=dcb027f9-2100-0000-c66e-32d5f6070000 pid=2038 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=dcb027f9-2100-0000-c66e-32d5f6070000 pid=2038 execve guuid=2f897dfd-2100-0000-c66e-32d5fe070000 pid=2046 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=2f897dfd-2100-0000-c66e-32d5fe070000 pid=2046 execve guuid=9189e9fd-2100-0000-c66e-32d500080000 pid=2048 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=9189e9fd-2100-0000-c66e-32d500080000 pid=2048 execve guuid=1ea251fe-2100-0000-c66e-32d501080000 pid=2049 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=1ea251fe-2100-0000-c66e-32d501080000 pid=2049 clone guuid=abb982fe-2100-0000-c66e-32d502080000 pid=2050 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=abb982fe-2100-0000-c66e-32d502080000 pid=2050 execve guuid=f9f52900-2200-0000-c66e-32d508080000 pid=2056 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=f9f52900-2200-0000-c66e-32d508080000 pid=2056 execve guuid=4f3b5304-2200-0000-c66e-32d510080000 pid=2064 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=4f3b5304-2200-0000-c66e-32d510080000 pid=2064 execve guuid=703ca404-2200-0000-c66e-32d512080000 pid=2066 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=703ca404-2200-0000-c66e-32d512080000 pid=2066 execve guuid=9d6d1005-2200-0000-c66e-32d513080000 pid=2067 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=9d6d1005-2200-0000-c66e-32d513080000 pid=2067 clone guuid=28a64005-2200-0000-c66e-32d514080000 pid=2068 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=28a64005-2200-0000-c66e-32d514080000 pid=2068 execve guuid=97062407-2200-0000-c66e-32d51a080000 pid=2074 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=97062407-2200-0000-c66e-32d51a080000 pid=2074 execve guuid=0475df0a-2200-0000-c66e-32d524080000 pid=2084 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=0475df0a-2200-0000-c66e-32d524080000 pid=2084 execve guuid=18f2370b-2200-0000-c66e-32d526080000 pid=2086 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=18f2370b-2200-0000-c66e-32d526080000 pid=2086 execve guuid=a814810b-2200-0000-c66e-32d527080000 pid=2087 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=a814810b-2200-0000-c66e-32d527080000 pid=2087 clone guuid=a2dfa90b-2200-0000-c66e-32d528080000 pid=2088 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=a2dfa90b-2200-0000-c66e-32d528080000 pid=2088 execve guuid=22919a0d-2200-0000-c66e-32d52f080000 pid=2095 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=22919a0d-2200-0000-c66e-32d52f080000 pid=2095 execve guuid=09821511-2200-0000-c66e-32d538080000 pid=2104 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=09821511-2200-0000-c66e-32d538080000 pid=2104 execve guuid=84368611-2200-0000-c66e-32d53a080000 pid=2106 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=84368611-2200-0000-c66e-32d53a080000 pid=2106 execve guuid=2289e311-2200-0000-c66e-32d53b080000 pid=2107 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=2289e311-2200-0000-c66e-32d53b080000 pid=2107 clone guuid=72b01e12-2200-0000-c66e-32d53c080000 pid=2108 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=72b01e12-2200-0000-c66e-32d53c080000 pid=2108 execve guuid=4942e714-2200-0000-c66e-32d53d080000 pid=2109 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=4942e714-2200-0000-c66e-32d53d080000 pid=2109 execve guuid=9d3ab323-2200-0000-c66e-32d53f080000 pid=2111 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=9d3ab323-2200-0000-c66e-32d53f080000 pid=2111 execve guuid=d7fa9424-2200-0000-c66e-32d541080000 pid=2113 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=d7fa9424-2200-0000-c66e-32d541080000 pid=2113 execve guuid=0ec3f824-2200-0000-c66e-32d543080000 pid=2115 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=0ec3f824-2200-0000-c66e-32d543080000 pid=2115 clone guuid=b61d2425-2200-0000-c66e-32d544080000 pid=2116 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=b61d2425-2200-0000-c66e-32d544080000 pid=2116 execve guuid=76adf826-2200-0000-c66e-32d549080000 pid=2121 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=76adf826-2200-0000-c66e-32d549080000 pid=2121 execve guuid=bfb7d82b-2200-0000-c66e-32d54a080000 pid=2122 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=bfb7d82b-2200-0000-c66e-32d54a080000 pid=2122 execve guuid=b40a4a2c-2200-0000-c66e-32d54c080000 pid=2124 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=b40a4a2c-2200-0000-c66e-32d54c080000 pid=2124 execve guuid=e74ba52c-2200-0000-c66e-32d54d080000 pid=2125 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=e74ba52c-2200-0000-c66e-32d54d080000 pid=2125 clone guuid=6b96df2c-2200-0000-c66e-32d54f080000 pid=2127 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=6b96df2c-2200-0000-c66e-32d54f080000 pid=2127 execve guuid=a9f47930-2200-0000-c66e-32d557080000 pid=2135 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=a9f47930-2200-0000-c66e-32d557080000 pid=2135 execve guuid=b256e934-2200-0000-c66e-32d562080000 pid=2146 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=b256e934-2200-0000-c66e-32d562080000 pid=2146 execve guuid=c6543835-2200-0000-c66e-32d563080000 pid=2147 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=c6543835-2200-0000-c66e-32d563080000 pid=2147 execve guuid=98ea7935-2200-0000-c66e-32d565080000 pid=2149 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=98ea7935-2200-0000-c66e-32d565080000 pid=2149 clone guuid=cb8ba035-2200-0000-c66e-32d566080000 pid=2150 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=cb8ba035-2200-0000-c66e-32d566080000 pid=2150 execve guuid=fb98ae37-2200-0000-c66e-32d56e080000 pid=2158 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=fb98ae37-2200-0000-c66e-32d56e080000 pid=2158 execve guuid=3d78083b-2200-0000-c66e-32d577080000 pid=2167 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=3d78083b-2200-0000-c66e-32d577080000 pid=2167 execve guuid=204b6d3b-2200-0000-c66e-32d578080000 pid=2168 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=204b6d3b-2200-0000-c66e-32d578080000 pid=2168 execve guuid=3ed1e03b-2200-0000-c66e-32d57b080000 pid=2171 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=3ed1e03b-2200-0000-c66e-32d57b080000 pid=2171 clone guuid=b59d033c-2200-0000-c66e-32d57c080000 pid=2172 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=b59d033c-2200-0000-c66e-32d57c080000 pid=2172 execve guuid=f29a233e-2200-0000-c66e-32d583080000 pid=2179 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=f29a233e-2200-0000-c66e-32d583080000 pid=2179 execve guuid=d122b440-2200-0000-c66e-32d58a080000 pid=2186 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=d122b440-2200-0000-c66e-32d58a080000 pid=2186 execve guuid=31fffb40-2200-0000-c66e-32d58c080000 pid=2188 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=31fffb40-2200-0000-c66e-32d58c080000 pid=2188 execve guuid=ae5f7041-2200-0000-c66e-32d58f080000 pid=2191 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=ae5f7041-2200-0000-c66e-32d58f080000 pid=2191 clone guuid=f1bb9241-2200-0000-c66e-32d590080000 pid=2192 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=f1bb9241-2200-0000-c66e-32d590080000 pid=2192 execve guuid=74668b43-2200-0000-c66e-32d597080000 pid=2199 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=74668b43-2200-0000-c66e-32d597080000 pid=2199 execve guuid=4da55847-2200-0000-c66e-32d5a1080000 pid=2209 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=4da55847-2200-0000-c66e-32d5a1080000 pid=2209 execve guuid=c707a147-2200-0000-c66e-32d5a3080000 pid=2211 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=c707a147-2200-0000-c66e-32d5a3080000 pid=2211 execve guuid=017ee147-2200-0000-c66e-32d5a5080000 pid=2213 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=017ee147-2200-0000-c66e-32d5a5080000 pid=2213 clone guuid=88bb0b48-2200-0000-c66e-32d5a6080000 pid=2214 /usr/bin/wget net send-data guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=88bb0b48-2200-0000-c66e-32d5a6080000 pid=2214 execve guuid=8b21134a-2200-0000-c66e-32d5ae080000 pid=2222 /usr/bin/curl net send-data write-file guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=8b21134a-2200-0000-c66e-32d5ae080000 pid=2222 execve guuid=0394534e-2200-0000-c66e-32d5b9080000 pid=2233 /usr/bin/cat guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=0394534e-2200-0000-c66e-32d5b9080000 pid=2233 execve guuid=2c94aa4e-2200-0000-c66e-32d5bb080000 pid=2235 /usr/bin/chmod guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=2c94aa4e-2200-0000-c66e-32d5bb080000 pid=2235 execve guuid=2d6e0c4f-2200-0000-c66e-32d5bd080000 pid=2237 /usr/bin/bash guuid=17b55bde-2100-0000-c66e-32d5c3070000 pid=1987->guuid=2d6e0c4f-2200-0000-c66e-32d5bd080000 pid=2237 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=79918fdf-2100-0000-c66e-32d5c4070000 pid=1988->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=382237e4-2100-0000-c66e-32d5c6070000 pid=1990->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=fbc175ee-2100-0000-c66e-32d5d8070000 pid=2008->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=aa4a67f0-2100-0000-c66e-32d5df070000 pid=2015->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=aa168bf7-2100-0000-c66e-32d5f0070000 pid=2032->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=dcb027f9-2100-0000-c66e-32d5f6070000 pid=2038->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=abb982fe-2100-0000-c66e-32d502080000 pid=2050->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=f9f52900-2200-0000-c66e-32d508080000 pid=2056->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=28a64005-2200-0000-c66e-32d514080000 pid=2068->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=97062407-2200-0000-c66e-32d51a080000 pid=2074->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=a2dfa90b-2200-0000-c66e-32d528080000 pid=2088->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=22919a0d-2200-0000-c66e-32d52f080000 pid=2095->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=72b01e12-2200-0000-c66e-32d53c080000 pid=2108->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=4942e714-2200-0000-c66e-32d53d080000 pid=2109->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=b61d2425-2200-0000-c66e-32d544080000 pid=2116->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=76adf826-2200-0000-c66e-32d549080000 pid=2121->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=6b96df2c-2200-0000-c66e-32d54f080000 pid=2127->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=a9f47930-2200-0000-c66e-32d557080000 pid=2135->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=cb8ba035-2200-0000-c66e-32d566080000 pid=2150->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=fb98ae37-2200-0000-c66e-32d56e080000 pid=2158->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=b59d033c-2200-0000-c66e-32d57c080000 pid=2172->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=f29a233e-2200-0000-c66e-32d583080000 pid=2179->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=f1bb9241-2200-0000-c66e-32d590080000 pid=2192->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=74668b43-2200-0000-c66e-32d597080000 pid=2199->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=88bb0b48-2200-0000-c66e-32d5a6080000 pid=2214->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=8b21134a-2200-0000-c66e-32d5ae080000 pid=2222->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 12:30:35 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1532042b11c1469ea5b9e421f85a9e0f046e1c3eeae9d002b9a566c7d980a4a0

(this sample)

  
Delivery method
Distributed via web download

Comments