MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1c339842b9730fa557f03b8cf4dcc2277f31011bef16db8d9b3503f8c0ca0ffb. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1c339842b9730fa557f03b8cf4dcc2277f31011bef16db8d9b3503f8c0ca0ffb
SHA3-384 hash: d49d91f52f8cc902d5d0b51507b4f1aae1c439a9092a139e39e256ddab3b381ef4dbe045e5d70c30eafd8655cacbfc3f
SHA1 hash: bc4f50d6714264a13e06909ce59742460357644e
MD5 hash: 26e441d82159849776e508cfb2879c60
humanhash: muppet-texas-xray-papa
File name:yarn
Download: download sample
File size:2'412 bytes
First seen:2025-07-10 13:02:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSlrx0xX92rxuwxujZrxZxadrxyxlKrxbx0vrx8xfgrxGxp6rxdxuprxnxAT:vlTSlliX92lb6Zl7adlQlKlV0vlKfgl9
TLSH T17341A3F50144073C6CF2996E31E78988BAA196C720C3DF95D6FC39E5404DE483DA2E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
24
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=382384dc-1b00-0000-0b09-d68f1a0e0000 pid=3610 /usr/bin/sudo guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617 /tmp/sample.bin guuid=382384dc-1b00-0000-0b09-d68f1a0e0000 pid=3610->guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617 execve guuid=2269e4df-1b00-0000-0b09-d68f250e0000 pid=3621 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=2269e4df-1b00-0000-0b09-d68f250e0000 pid=3621 execve guuid=c083d3e3-1b00-0000-0b09-d68f2f0e0000 pid=3631 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=c083d3e3-1b00-0000-0b09-d68f2f0e0000 pid=3631 execve guuid=6f7927eb-1b00-0000-0b09-d68f3e0e0000 pid=3646 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=6f7927eb-1b00-0000-0b09-d68f3e0e0000 pid=3646 execve guuid=c18993eb-1b00-0000-0b09-d68f400e0000 pid=3648 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=c18993eb-1b00-0000-0b09-d68f400e0000 pid=3648 execve guuid=17e7f1eb-1b00-0000-0b09-d68f420e0000 pid=3650 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=17e7f1eb-1b00-0000-0b09-d68f420e0000 pid=3650 clone guuid=37993cec-1b00-0000-0b09-d68f440e0000 pid=3652 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=37993cec-1b00-0000-0b09-d68f440e0000 pid=3652 execve guuid=1efa6bee-1b00-0000-0b09-d68f490e0000 pid=3657 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=1efa6bee-1b00-0000-0b09-d68f490e0000 pid=3657 execve guuid=e791eaf2-1b00-0000-0b09-d68f550e0000 pid=3669 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=e791eaf2-1b00-0000-0b09-d68f550e0000 pid=3669 execve guuid=474f61f3-1b00-0000-0b09-d68f570e0000 pid=3671 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=474f61f3-1b00-0000-0b09-d68f570e0000 pid=3671 execve guuid=7ae0c5f3-1b00-0000-0b09-d68f580e0000 pid=3672 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=7ae0c5f3-1b00-0000-0b09-d68f580e0000 pid=3672 clone guuid=5af1f9f3-1b00-0000-0b09-d68f5a0e0000 pid=3674 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=5af1f9f3-1b00-0000-0b09-d68f5a0e0000 pid=3674 execve guuid=52eb14f6-1b00-0000-0b09-d68f5b0e0000 pid=3675 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=52eb14f6-1b00-0000-0b09-d68f5b0e0000 pid=3675 execve guuid=76bed3f9-1b00-0000-0b09-d68f680e0000 pid=3688 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=76bed3f9-1b00-0000-0b09-d68f680e0000 pid=3688 execve guuid=14d675fa-1b00-0000-0b09-d68f6a0e0000 pid=3690 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=14d675fa-1b00-0000-0b09-d68f6a0e0000 pid=3690 execve guuid=f5b6d8fa-1b00-0000-0b09-d68f6d0e0000 pid=3693 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=f5b6d8fa-1b00-0000-0b09-d68f6d0e0000 pid=3693 clone guuid=942c14fb-1b00-0000-0b09-d68f6e0e0000 pid=3694 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=942c14fb-1b00-0000-0b09-d68f6e0e0000 pid=3694 execve guuid=84d815fd-1b00-0000-0b09-d68f770e0000 pid=3703 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=84d815fd-1b00-0000-0b09-d68f770e0000 pid=3703 execve guuid=6ebe3d00-1c00-0000-0b09-d68f800e0000 pid=3712 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=6ebe3d00-1c00-0000-0b09-d68f800e0000 pid=3712 execve guuid=b59baf00-1c00-0000-0b09-d68f830e0000 pid=3715 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=b59baf00-1c00-0000-0b09-d68f830e0000 pid=3715 execve guuid=c0ee2101-1c00-0000-0b09-d68f860e0000 pid=3718 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=c0ee2101-1c00-0000-0b09-d68f860e0000 pid=3718 clone guuid=39eb5601-1c00-0000-0b09-d68f870e0000 pid=3719 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=39eb5601-1c00-0000-0b09-d68f870e0000 pid=3719 execve guuid=6fa95003-1c00-0000-0b09-d68f910e0000 pid=3729 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=6fa95003-1c00-0000-0b09-d68f910e0000 pid=3729 execve guuid=cd9f7206-1c00-0000-0b09-d68f9d0e0000 pid=3741 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=cd9f7206-1c00-0000-0b09-d68f9d0e0000 pid=3741 execve guuid=a7cddf06-1c00-0000-0b09-d68f9f0e0000 pid=3743 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=a7cddf06-1c00-0000-0b09-d68f9f0e0000 pid=3743 execve guuid=25e02a07-1c00-0000-0b09-d68fa10e0000 pid=3745 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=25e02a07-1c00-0000-0b09-d68fa10e0000 pid=3745 clone guuid=917a5707-1c00-0000-0b09-d68fa20e0000 pid=3746 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=917a5707-1c00-0000-0b09-d68fa20e0000 pid=3746 execve guuid=df0a4c09-1c00-0000-0b09-d68fac0e0000 pid=3756 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=df0a4c09-1c00-0000-0b09-d68fac0e0000 pid=3756 execve guuid=65818f0e-1c00-0000-0b09-d68fc00e0000 pid=3776 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=65818f0e-1c00-0000-0b09-d68fc00e0000 pid=3776 execve guuid=457cef0e-1c00-0000-0b09-d68fc20e0000 pid=3778 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=457cef0e-1c00-0000-0b09-d68fc20e0000 pid=3778 execve guuid=b46f3b0f-1c00-0000-0b09-d68fc40e0000 pid=3780 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=b46f3b0f-1c00-0000-0b09-d68fc40e0000 pid=3780 clone guuid=b9486a0f-1c00-0000-0b09-d68fc50e0000 pid=3781 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=b9486a0f-1c00-0000-0b09-d68fc50e0000 pid=3781 execve guuid=738ce211-1c00-0000-0b09-d68fcd0e0000 pid=3789 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=738ce211-1c00-0000-0b09-d68fcd0e0000 pid=3789 execve guuid=90e16315-1c00-0000-0b09-d68fd70e0000 pid=3799 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=90e16315-1c00-0000-0b09-d68fd70e0000 pid=3799 execve guuid=0a1dd215-1c00-0000-0b09-d68fd90e0000 pid=3801 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=0a1dd215-1c00-0000-0b09-d68fd90e0000 pid=3801 execve guuid=34924016-1c00-0000-0b09-d68fdb0e0000 pid=3803 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=34924016-1c00-0000-0b09-d68fdb0e0000 pid=3803 clone guuid=f5a97b16-1c00-0000-0b09-d68fdc0e0000 pid=3804 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=f5a97b16-1c00-0000-0b09-d68fdc0e0000 pid=3804 execve guuid=5bb09918-1c00-0000-0b09-d68fe90e0000 pid=3817 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=5bb09918-1c00-0000-0b09-d68fe90e0000 pid=3817 execve guuid=dae62c1e-1c00-0000-0b09-d68f030f0000 pid=3843 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=dae62c1e-1c00-0000-0b09-d68f030f0000 pid=3843 execve guuid=1493a71e-1c00-0000-0b09-d68f060f0000 pid=3846 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=1493a71e-1c00-0000-0b09-d68f060f0000 pid=3846 execve guuid=240cfe1e-1c00-0000-0b09-d68f0a0f0000 pid=3850 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=240cfe1e-1c00-0000-0b09-d68f0a0f0000 pid=3850 clone guuid=5cc75c1f-1c00-0000-0b09-d68f0c0f0000 pid=3852 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=5cc75c1f-1c00-0000-0b09-d68f0c0f0000 pid=3852 execve guuid=546b5122-1c00-0000-0b09-d68f170f0000 pid=3863 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=546b5122-1c00-0000-0b09-d68f170f0000 pid=3863 execve guuid=8bad4826-1c00-0000-0b09-d68f220f0000 pid=3874 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=8bad4826-1c00-0000-0b09-d68f220f0000 pid=3874 execve guuid=3194c626-1c00-0000-0b09-d68f260f0000 pid=3878 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=3194c626-1c00-0000-0b09-d68f260f0000 pid=3878 execve guuid=34b00f27-1c00-0000-0b09-d68f280f0000 pid=3880 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=34b00f27-1c00-0000-0b09-d68f280f0000 pid=3880 clone guuid=33497427-1c00-0000-0b09-d68f2b0f0000 pid=3883 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=33497427-1c00-0000-0b09-d68f2b0f0000 pid=3883 execve guuid=ab10242a-1c00-0000-0b09-d68f350f0000 pid=3893 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=ab10242a-1c00-0000-0b09-d68f350f0000 pid=3893 execve guuid=159d9b2e-1c00-0000-0b09-d68f430f0000 pid=3907 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=159d9b2e-1c00-0000-0b09-d68f430f0000 pid=3907 execve guuid=3ee61664-1c00-0000-0b09-d68f7d0f0000 pid=3965 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=3ee61664-1c00-0000-0b09-d68f7d0f0000 pid=3965 execve guuid=4ef3b564-1c00-0000-0b09-d68f7e0f0000 pid=3966 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=4ef3b564-1c00-0000-0b09-d68f7e0f0000 pid=3966 clone guuid=4e2ef064-1c00-0000-0b09-d68f800f0000 pid=3968 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=4e2ef064-1c00-0000-0b09-d68f800f0000 pid=3968 execve guuid=080ed766-1c00-0000-0b09-d68f8c0f0000 pid=3980 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=080ed766-1c00-0000-0b09-d68f8c0f0000 pid=3980 execve guuid=2bf5396a-1c00-0000-0b09-d68f9a0f0000 pid=3994 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=2bf5396a-1c00-0000-0b09-d68f9a0f0000 pid=3994 execve guuid=57fbac6a-1c00-0000-0b09-d68f9c0f0000 pid=3996 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=57fbac6a-1c00-0000-0b09-d68f9c0f0000 pid=3996 execve guuid=f6b4076b-1c00-0000-0b09-d68f9e0f0000 pid=3998 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=f6b4076b-1c00-0000-0b09-d68f9e0f0000 pid=3998 clone guuid=1da82e6b-1c00-0000-0b09-d68fa00f0000 pid=4000 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=1da82e6b-1c00-0000-0b09-d68fa00f0000 pid=4000 execve guuid=2971e86c-1c00-0000-0b09-d68fa50f0000 pid=4005 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=2971e86c-1c00-0000-0b09-d68fa50f0000 pid=4005 execve guuid=a168c26f-1c00-0000-0b09-d68fb40f0000 pid=4020 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=a168c26f-1c00-0000-0b09-d68fb40f0000 pid=4020 execve guuid=b6d91770-1c00-0000-0b09-d68fb50f0000 pid=4021 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=b6d91770-1c00-0000-0b09-d68fb50f0000 pid=4021 execve guuid=97986370-1c00-0000-0b09-d68fb80f0000 pid=4024 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=97986370-1c00-0000-0b09-d68fb80f0000 pid=4024 clone guuid=b0768d70-1c00-0000-0b09-d68fb90f0000 pid=4025 /usr/bin/wget net send-data guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=b0768d70-1c00-0000-0b09-d68fb90f0000 pid=4025 execve guuid=4987a072-1c00-0000-0b09-d68fc00f0000 pid=4032 /usr/bin/curl net send-data write-file guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=4987a072-1c00-0000-0b09-d68fc00f0000 pid=4032 execve guuid=95b55877-1c00-0000-0b09-d68fcf0f0000 pid=4047 /usr/bin/cat guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=95b55877-1c00-0000-0b09-d68fcf0f0000 pid=4047 execve guuid=e66ba177-1c00-0000-0b09-d68fd30f0000 pid=4051 /usr/bin/chmod guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=e66ba177-1c00-0000-0b09-d68fd30f0000 pid=4051 execve guuid=eb84e377-1c00-0000-0b09-d68fd40f0000 pid=4052 /usr/bin/bash guuid=1bfa57df-1b00-0000-0b09-d68f210e0000 pid=3617->guuid=eb84e377-1c00-0000-0b09-d68fd40f0000 pid=4052 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=2269e4df-1b00-0000-0b09-d68f250e0000 pid=3621->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=c083d3e3-1b00-0000-0b09-d68f2f0e0000 pid=3631->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=37993cec-1b00-0000-0b09-d68f440e0000 pid=3652->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=1efa6bee-1b00-0000-0b09-d68f490e0000 pid=3657->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=5af1f9f3-1b00-0000-0b09-d68f5a0e0000 pid=3674->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=52eb14f6-1b00-0000-0b09-d68f5b0e0000 pid=3675->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=942c14fb-1b00-0000-0b09-d68f6e0e0000 pid=3694->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=84d815fd-1b00-0000-0b09-d68f770e0000 pid=3703->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=39eb5601-1c00-0000-0b09-d68f870e0000 pid=3719->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=6fa95003-1c00-0000-0b09-d68f910e0000 pid=3729->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=917a5707-1c00-0000-0b09-d68fa20e0000 pid=3746->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=df0a4c09-1c00-0000-0b09-d68fac0e0000 pid=3756->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=b9486a0f-1c00-0000-0b09-d68fc50e0000 pid=3781->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=738ce211-1c00-0000-0b09-d68fcd0e0000 pid=3789->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=f5a97b16-1c00-0000-0b09-d68fdc0e0000 pid=3804->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=5bb09918-1c00-0000-0b09-d68fe90e0000 pid=3817->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=5cc75c1f-1c00-0000-0b09-d68f0c0f0000 pid=3852->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=546b5122-1c00-0000-0b09-d68f170f0000 pid=3863->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=33497427-1c00-0000-0b09-d68f2b0f0000 pid=3883->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=ab10242a-1c00-0000-0b09-d68f350f0000 pid=3893->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=4e2ef064-1c00-0000-0b09-d68f800f0000 pid=3968->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=080ed766-1c00-0000-0b09-d68f8c0f0000 pid=3980->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=1da82e6b-1c00-0000-0b09-d68fa00f0000 pid=4000->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=2971e86c-1c00-0000-0b09-d68fa50f0000 pid=4005->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=b0768d70-1c00-0000-0b09-d68fb90f0000 pid=4025->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=4987a072-1c00-0000-0b09-d68fc00f0000 pid=4032->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:02:22 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1c339842b9730fa557f03b8cf4dcc2277f31011bef16db8d9b3503f8c0ca0ffb

(this sample)

  
Delivery method
Distributed via web download

Comments