MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3416131cbc8e604d87c962b7fb99c1ecdd075abf401a28e20711e13748de1cbc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 3416131cbc8e604d87c962b7fb99c1ecdd075abf401a28e20711e13748de1cbc
SHA3-384 hash: 24aed5bdc80ccc758b1eb807ad9ba1b03af6b64b094f8fe02b8b42431a83e4dafa58aedf11684ccee932a0d370b404f2
SHA1 hash: e2e4a413e5e0ae1ce434eebbe28f0f84a8cdae0c
MD5 hash: ef9ee2de77e562fd5b67b92f579a6f6c
humanhash: delta-steak-pip-winner
File name:pulse
Download: download sample
File size:2'425 bytes
First seen:2025-07-10 13:02:06 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSgrx0xX9Nrxuwxuj8rxZxa4rxyxl5rxbx0arx8xf/rxGxpprxdxuMrxnxAX:vlTSgliX9Nlb68l7a4lQl5lV0alKf/lZ
TLSH T1DA41A8F90244473EACF2955E31E78988B6B1A6C620C39F84D5FC38E5404DE483DA2E8E
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=bb2dfe3f-1a00-0000-3545-0bbc390a0000 pid=2617 /usr/bin/sudo guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622 /tmp/sample.bin guuid=bb2dfe3f-1a00-0000-3545-0bbc390a0000 pid=2617->guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622 execve guuid=6ce11642-1a00-0000-3545-0bbc3f0a0000 pid=2623 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=6ce11642-1a00-0000-3545-0bbc3f0a0000 pid=2623 execve guuid=7c7bde45-1a00-0000-3545-0bbc490a0000 pid=2633 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7c7bde45-1a00-0000-3545-0bbc490a0000 pid=2633 execve guuid=f283074f-1a00-0000-3545-0bbc5c0a0000 pid=2652 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=f283074f-1a00-0000-3545-0bbc5c0a0000 pid=2652 execve guuid=78aca14f-1a00-0000-3545-0bbc5e0a0000 pid=2654 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=78aca14f-1a00-0000-3545-0bbc5e0a0000 pid=2654 execve guuid=d4ca1350-1a00-0000-3545-0bbc600a0000 pid=2656 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=d4ca1350-1a00-0000-3545-0bbc600a0000 pid=2656 clone guuid=fd0c5d50-1a00-0000-3545-0bbc620a0000 pid=2658 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=fd0c5d50-1a00-0000-3545-0bbc620a0000 pid=2658 execve guuid=aa591b53-1a00-0000-3545-0bbc690a0000 pid=2665 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=aa591b53-1a00-0000-3545-0bbc690a0000 pid=2665 execve guuid=55f2a257-1a00-0000-3545-0bbc760a0000 pid=2678 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=55f2a257-1a00-0000-3545-0bbc760a0000 pid=2678 execve guuid=862b2158-1a00-0000-3545-0bbc790a0000 pid=2681 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=862b2158-1a00-0000-3545-0bbc790a0000 pid=2681 execve guuid=76ae9358-1a00-0000-3545-0bbc7b0a0000 pid=2683 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=76ae9358-1a00-0000-3545-0bbc7b0a0000 pid=2683 clone guuid=63e0bd58-1a00-0000-3545-0bbc7d0a0000 pid=2685 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=63e0bd58-1a00-0000-3545-0bbc7d0a0000 pid=2685 execve guuid=dc0e785a-1a00-0000-3545-0bbc820a0000 pid=2690 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=dc0e785a-1a00-0000-3545-0bbc820a0000 pid=2690 execve guuid=274b085e-1a00-0000-3545-0bbc8c0a0000 pid=2700 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=274b085e-1a00-0000-3545-0bbc8c0a0000 pid=2700 execve guuid=7bdc835e-1a00-0000-3545-0bbc8e0a0000 pid=2702 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7bdc835e-1a00-0000-3545-0bbc8e0a0000 pid=2702 execve guuid=ace2fa5e-1a00-0000-3545-0bbc900a0000 pid=2704 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=ace2fa5e-1a00-0000-3545-0bbc900a0000 pid=2704 clone guuid=a1403c5f-1a00-0000-3545-0bbc920a0000 pid=2706 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=a1403c5f-1a00-0000-3545-0bbc920a0000 pid=2706 execve guuid=1c255a61-1a00-0000-3545-0bbc970a0000 pid=2711 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=1c255a61-1a00-0000-3545-0bbc970a0000 pid=2711 execve guuid=7ccf5e66-1a00-0000-3545-0bbca70a0000 pid=2727 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7ccf5e66-1a00-0000-3545-0bbca70a0000 pid=2727 execve guuid=7bcedc66-1a00-0000-3545-0bbcaa0a0000 pid=2730 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7bcedc66-1a00-0000-3545-0bbcaa0a0000 pid=2730 execve guuid=9a556367-1a00-0000-3545-0bbcac0a0000 pid=2732 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=9a556367-1a00-0000-3545-0bbcac0a0000 pid=2732 clone guuid=6b5faf67-1a00-0000-3545-0bbcae0a0000 pid=2734 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=6b5faf67-1a00-0000-3545-0bbcae0a0000 pid=2734 execve guuid=2f9b7b69-1a00-0000-3545-0bbcb40a0000 pid=2740 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=2f9b7b69-1a00-0000-3545-0bbcb40a0000 pid=2740 execve guuid=cf96df6c-1a00-0000-3545-0bbcbd0a0000 pid=2749 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=cf96df6c-1a00-0000-3545-0bbcbd0a0000 pid=2749 execve guuid=9634306d-1a00-0000-3545-0bbcbf0a0000 pid=2751 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=9634306d-1a00-0000-3545-0bbcbf0a0000 pid=2751 execve guuid=36fd7c6d-1a00-0000-3545-0bbcc10a0000 pid=2753 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=36fd7c6d-1a00-0000-3545-0bbcc10a0000 pid=2753 clone guuid=db18a96d-1a00-0000-3545-0bbcc20a0000 pid=2754 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=db18a96d-1a00-0000-3545-0bbcc20a0000 pid=2754 execve guuid=2ea89f6f-1a00-0000-3545-0bbcc90a0000 pid=2761 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=2ea89f6f-1a00-0000-3545-0bbcc90a0000 pid=2761 execve guuid=a7253173-1a00-0000-3545-0bbcd20a0000 pid=2770 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=a7253173-1a00-0000-3545-0bbcd20a0000 pid=2770 execve guuid=eb67a373-1a00-0000-3545-0bbcd30a0000 pid=2771 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=eb67a373-1a00-0000-3545-0bbcd30a0000 pid=2771 execve guuid=7c3a2b74-1a00-0000-3545-0bbcd40a0000 pid=2772 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7c3a2b74-1a00-0000-3545-0bbcd40a0000 pid=2772 clone guuid=0ca16374-1a00-0000-3545-0bbcd50a0000 pid=2773 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=0ca16374-1a00-0000-3545-0bbcd50a0000 pid=2773 execve guuid=d37f2d76-1a00-0000-3545-0bbcda0a0000 pid=2778 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=d37f2d76-1a00-0000-3545-0bbcda0a0000 pid=2778 execve guuid=c9136079-1a00-0000-3545-0bbce30a0000 pid=2787 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=c9136079-1a00-0000-3545-0bbce30a0000 pid=2787 execve guuid=7d09b479-1a00-0000-3545-0bbce40a0000 pid=2788 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7d09b479-1a00-0000-3545-0bbce40a0000 pid=2788 execve guuid=46ccff79-1a00-0000-3545-0bbce60a0000 pid=2790 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=46ccff79-1a00-0000-3545-0bbce60a0000 pid=2790 clone guuid=d7b0307a-1a00-0000-3545-0bbce70a0000 pid=2791 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=d7b0307a-1a00-0000-3545-0bbce70a0000 pid=2791 execve guuid=a0edd97c-1a00-0000-3545-0bbce90a0000 pid=2793 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=a0edd97c-1a00-0000-3545-0bbce90a0000 pid=2793 execve guuid=abe09181-1a00-0000-3545-0bbcf10a0000 pid=2801 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=abe09181-1a00-0000-3545-0bbcf10a0000 pid=2801 execve guuid=5f242582-1a00-0000-3545-0bbcf20a0000 pid=2802 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=5f242582-1a00-0000-3545-0bbcf20a0000 pid=2802 execve guuid=c7bd9f82-1a00-0000-3545-0bbcf30a0000 pid=2803 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=c7bd9f82-1a00-0000-3545-0bbcf30a0000 pid=2803 clone guuid=9ae1d282-1a00-0000-3545-0bbcf50a0000 pid=2805 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=9ae1d282-1a00-0000-3545-0bbcf50a0000 pid=2805 execve guuid=6d42f684-1a00-0000-3545-0bbcfc0a0000 pid=2812 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=6d42f684-1a00-0000-3545-0bbcfc0a0000 pid=2812 execve guuid=2030318a-1a00-0000-3545-0bbc040b0000 pid=2820 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=2030318a-1a00-0000-3545-0bbc040b0000 pid=2820 execve guuid=fe37a18a-1a00-0000-3545-0bbc050b0000 pid=2821 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=fe37a18a-1a00-0000-3545-0bbc050b0000 pid=2821 execve guuid=e180178b-1a00-0000-3545-0bbc070b0000 pid=2823 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=e180178b-1a00-0000-3545-0bbc070b0000 pid=2823 clone guuid=27f5568b-1a00-0000-3545-0bbc090b0000 pid=2825 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=27f5568b-1a00-0000-3545-0bbc090b0000 pid=2825 execve guuid=dd8d7d8d-1a00-0000-3545-0bbc0f0b0000 pid=2831 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=dd8d7d8d-1a00-0000-3545-0bbc0f0b0000 pid=2831 execve guuid=ba9bf090-1a00-0000-3545-0bbc170b0000 pid=2839 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=ba9bf090-1a00-0000-3545-0bbc170b0000 pid=2839 execve guuid=ea377e91-1a00-0000-3545-0bbc190b0000 pid=2841 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=ea377e91-1a00-0000-3545-0bbc190b0000 pid=2841 execve guuid=e9b42192-1a00-0000-3545-0bbc1b0b0000 pid=2843 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=e9b42192-1a00-0000-3545-0bbc1b0b0000 pid=2843 clone guuid=b7a86e92-1a00-0000-3545-0bbc1d0b0000 pid=2845 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=b7a86e92-1a00-0000-3545-0bbc1d0b0000 pid=2845 execve guuid=f73c7594-1a00-0000-3545-0bbc1e0b0000 pid=2846 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=f73c7594-1a00-0000-3545-0bbc1e0b0000 pid=2846 execve guuid=d7616997-1a00-0000-3545-0bbc1f0b0000 pid=2847 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=d7616997-1a00-0000-3545-0bbc1f0b0000 pid=2847 execve guuid=cab39e9c-1a00-0000-3545-0bbc210b0000 pid=2849 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=cab39e9c-1a00-0000-3545-0bbc210b0000 pid=2849 execve guuid=7c81eb9c-1a00-0000-3545-0bbc220b0000 pid=2850 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=7c81eb9c-1a00-0000-3545-0bbc220b0000 pid=2850 clone guuid=36f41b9d-1a00-0000-3545-0bbc230b0000 pid=2851 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=36f41b9d-1a00-0000-3545-0bbc230b0000 pid=2851 execve guuid=de47fe9e-1a00-0000-3545-0bbc280b0000 pid=2856 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=de47fe9e-1a00-0000-3545-0bbc280b0000 pid=2856 execve guuid=38a60fa5-1a00-0000-3545-0bbc350b0000 pid=2869 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=38a60fa5-1a00-0000-3545-0bbc350b0000 pid=2869 execve guuid=de48faa5-1a00-0000-3545-0bbc360b0000 pid=2870 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=de48faa5-1a00-0000-3545-0bbc360b0000 pid=2870 execve guuid=29fe7da6-1a00-0000-3545-0bbc370b0000 pid=2871 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=29fe7da6-1a00-0000-3545-0bbc370b0000 pid=2871 clone guuid=6914bda6-1a00-0000-3545-0bbc380b0000 pid=2872 /usr/bin/wget net send-data guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=6914bda6-1a00-0000-3545-0bbc380b0000 pid=2872 execve guuid=4b41ada9-1a00-0000-3545-0bbc3f0b0000 pid=2879 /usr/bin/curl net send-data write-file guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=4b41ada9-1a00-0000-3545-0bbc3f0b0000 pid=2879 execve guuid=282cb0ae-1a00-0000-3545-0bbc4b0b0000 pid=2891 /usr/bin/cat guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=282cb0ae-1a00-0000-3545-0bbc4b0b0000 pid=2891 execve guuid=00011baf-1a00-0000-3545-0bbc4d0b0000 pid=2893 /usr/bin/chmod guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=00011baf-1a00-0000-3545-0bbc4d0b0000 pid=2893 execve guuid=5eb08baf-1a00-0000-3545-0bbc500b0000 pid=2896 /usr/bin/bash guuid=3a66b941-1a00-0000-3545-0bbc3e0a0000 pid=2622->guuid=5eb08baf-1a00-0000-3545-0bbc500b0000 pid=2896 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=6ce11642-1a00-0000-3545-0bbc3f0a0000 pid=2623->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=7c7bde45-1a00-0000-3545-0bbc490a0000 pid=2633->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=fd0c5d50-1a00-0000-3545-0bbc620a0000 pid=2658->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=aa591b53-1a00-0000-3545-0bbc690a0000 pid=2665->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=63e0bd58-1a00-0000-3545-0bbc7d0a0000 pid=2685->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=dc0e785a-1a00-0000-3545-0bbc820a0000 pid=2690->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=a1403c5f-1a00-0000-3545-0bbc920a0000 pid=2706->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=1c255a61-1a00-0000-3545-0bbc970a0000 pid=2711->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=6b5faf67-1a00-0000-3545-0bbcae0a0000 pid=2734->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=2f9b7b69-1a00-0000-3545-0bbcb40a0000 pid=2740->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=db18a96d-1a00-0000-3545-0bbcc20a0000 pid=2754->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=2ea89f6f-1a00-0000-3545-0bbcc90a0000 pid=2761->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=0ca16374-1a00-0000-3545-0bbcd50a0000 pid=2773->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=d37f2d76-1a00-0000-3545-0bbcda0a0000 pid=2778->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=d7b0307a-1a00-0000-3545-0bbce70a0000 pid=2791->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=a0edd97c-1a00-0000-3545-0bbce90a0000 pid=2793->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=9ae1d282-1a00-0000-3545-0bbcf50a0000 pid=2805->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=6d42f684-1a00-0000-3545-0bbcfc0a0000 pid=2812->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=27f5568b-1a00-0000-3545-0bbc090b0000 pid=2825->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=dd8d7d8d-1a00-0000-3545-0bbc0f0b0000 pid=2831->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=b7a86e92-1a00-0000-3545-0bbc1d0b0000 pid=2845->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=f73c7594-1a00-0000-3545-0bbc1e0b0000 pid=2846->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=36f41b9d-1a00-0000-3545-0bbc230b0000 pid=2851->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=de47fe9e-1a00-0000-3545-0bbc280b0000 pid=2856->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=6914bda6-1a00-0000-3545-0bbc380b0000 pid=2872->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=4b41ada9-1a00-0000-3545-0bbc3f0b0000 pid=2879->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:02:24 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 3416131cbc8e604d87c962b7fb99c1ecdd075abf401a28e20711e13748de1cbc

(this sample)

  
Delivery method
Distributed via web download

Comments