MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4380db13717e531fa7dd7ecdd4dce7833d5cbf1ff1a0a1dc75ae8ef755a1228f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 4380db13717e531fa7dd7ecdd4dce7833d5cbf1ff1a0a1dc75ae8ef755a1228f
SHA3-384 hash: 0020969682d709fa4a9ab19b94fa270f7a215674759e654fa6b4940c5a274cda5aa1176008c76411b04e4e4e00ccbd77
SHA1 hash: d96bdf0814382de7af47903f3cb4db1e821f90fb
MD5 hash: 1567db413307908e7f6910eb3d76cfaa
humanhash: fix-orange-victor-xray
File name:aws
Download: download sample
Signature Mirai
File size:2'807 bytes
First seen:2025-09-06 06:46:04 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v3X3a3GNa3gta3ypa34Na3soszEa3bva3Ida31va3iha3QHa3A5AUfa3Lva30vd:v3X3a3GNa3gta3ypa34Na37oEa3bva3M
TLSH T1F151B1C6F22847B07FF1999A35FA600470D0F1955BC24E11D9FC78BEA14DF0974916AA
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.162.114.77/bins/sora.x86c4fdffa36b13e3742a38317302b552e0142055d028e43ef4ccbbdbfa0b208342 Miraielf mirai
http://38.162.114.77/bins/sora.mips518bb7ecad7786975b925e68c15f70746e6ab02508deb8bbbc8b8cc5cc597355 Miraielf mirai
http://38.162.114.77/bins/sora.x86_64n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i468n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i686n/an/aelf ua-wget
http://38.162.114.77/bins/sora.mpslcb66f0b9bfb996b5e4fe142cd03b3061b9843899675d93690e5474e87ef1bef2 Miraielf mirai
http://38.162.114.77/bins/sora.arm4n/an/aelf ua-wget
http://38.162.114.77/bins/sora.arm512486e4b57bd5ee074988b64d0716aa9c631aeb5805d8fc7664063d5a98dfaac Miraielf mirai
http://38.162.114.77/bins/sora.arm6e7b1d9504e3f6186d5c26f39932d0327b4ba22e04bf6e32e78ae72ca6969bd8c Miraielf mirai
http://38.162.114.77/bins/sora.arm77a0d000d79bc1be7a41fa59d1892995ff61815d4dbeb49f6d7053da7034a1598 Miraielf mirai
http://38.162.114.77/bins/sora.ppcadfb9de9a74d82e9d980515498e5d02b527961d37375a76e784404d059676f85 Miraielf mirai
http://38.162.114.77/bins/sora.ppc440fpn/an/aelf ua-wget
http://38.162.114.77/bins/sora.m68k6d1d1df496a3ab3aa77e2536fc9fcb09ed3b6653b77c27e305aba647bc5f2193 Miraielf mirai
http://38.162.114.77/bins/sora.sh438e47119b088297ba98fe3db4022607ff33af93d40ebc4991de353a424d180cc Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T04:02:00Z UTC
Last seen:
2025-09-06T04:02:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=132e9cad-1a00-0000-7eb4-f6ba620c0000 pid=3170 /usr/bin/sudo guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175 /tmp/sample.bin guuid=132e9cad-1a00-0000-7eb4-f6ba620c0000 pid=3170->guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175 execve guuid=571819b1-1a00-0000-7eb4-f6ba690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=571819b1-1a00-0000-7eb4-f6ba690c0000 pid=3177 execve guuid=5ea373f3-1a00-0000-7eb4-f6ba970c0000 pid=3223 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=5ea373f3-1a00-0000-7eb4-f6ba970c0000 pid=3223 execve guuid=7c9519aa-1b00-0000-7eb4-f6bab20d0000 pid=3506 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=7c9519aa-1b00-0000-7eb4-f6bab20d0000 pid=3506 execve guuid=357572aa-1b00-0000-7eb4-f6bab40d0000 pid=3508 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=357572aa-1b00-0000-7eb4-f6bab40d0000 pid=3508 execve guuid=4adafbaa-1b00-0000-7eb4-f6bab70d0000 pid=3511 /tmp/robben net guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=4adafbaa-1b00-0000-7eb4-f6bab70d0000 pid=3511 execve guuid=d9d4bbae-1b00-0000-7eb4-f6babd0d0000 pid=3517 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=d9d4bbae-1b00-0000-7eb4-f6babd0d0000 pid=3517 execve guuid=005545e3-1b00-0000-7eb4-f6ba0b0e0000 pid=3595 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=005545e3-1b00-0000-7eb4-f6ba0b0e0000 pid=3595 execve guuid=3ca32108-1c00-0000-7eb4-f6ba790e0000 pid=3705 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=3ca32108-1c00-0000-7eb4-f6ba790e0000 pid=3705 execve guuid=7b4c8208-1c00-0000-7eb4-f6ba7b0e0000 pid=3707 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=7b4c8208-1c00-0000-7eb4-f6ba7b0e0000 pid=3707 execve guuid=d992dc08-1c00-0000-7eb4-f6ba7d0e0000 pid=3709 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=d992dc08-1c00-0000-7eb4-f6ba7d0e0000 pid=3709 clone guuid=7da1a009-1c00-0000-7eb4-f6ba830e0000 pid=3715 /usr/bin/wget net send-data guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=7da1a009-1c00-0000-7eb4-f6ba830e0000 pid=3715 execve guuid=c3d7851c-1c00-0000-7eb4-f6bac30e0000 pid=3779 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=c3d7851c-1c00-0000-7eb4-f6bac30e0000 pid=3779 execve guuid=4e425531-1c00-0000-7eb4-f6ba1a0f0000 pid=3866 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=4e425531-1c00-0000-7eb4-f6ba1a0f0000 pid=3866 execve guuid=a45bbf31-1c00-0000-7eb4-f6ba1c0f0000 pid=3868 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=a45bbf31-1c00-0000-7eb4-f6ba1c0f0000 pid=3868 execve guuid=52d60532-1c00-0000-7eb4-f6ba1f0f0000 pid=3871 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=52d60532-1c00-0000-7eb4-f6ba1f0f0000 pid=3871 clone guuid=61623632-1c00-0000-7eb4-f6ba200f0000 pid=3872 /usr/bin/wget net send-data guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=61623632-1c00-0000-7eb4-f6ba200f0000 pid=3872 execve guuid=88e8e144-1c00-0000-7eb4-f6ba670f0000 pid=3943 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=88e8e144-1c00-0000-7eb4-f6ba670f0000 pid=3943 execve guuid=9be05559-1c00-0000-7eb4-f6baa50f0000 pid=4005 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=9be05559-1c00-0000-7eb4-f6baa50f0000 pid=4005 execve guuid=899eb659-1c00-0000-7eb4-f6baa70f0000 pid=4007 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=899eb659-1c00-0000-7eb4-f6baa70f0000 pid=4007 execve guuid=ab660e5a-1c00-0000-7eb4-f6baa90f0000 pid=4009 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=ab660e5a-1c00-0000-7eb4-f6baa90f0000 pid=4009 clone guuid=5e8f3a5a-1c00-0000-7eb4-f6baaa0f0000 pid=4010 /usr/bin/wget net send-data guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=5e8f3a5a-1c00-0000-7eb4-f6baaa0f0000 pid=4010 execve guuid=47b49e6c-1c00-0000-7eb4-f6bae70f0000 pid=4071 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=47b49e6c-1c00-0000-7eb4-f6bae70f0000 pid=4071 execve guuid=1a7b5c80-1c00-0000-7eb4-f6ba27100000 pid=4135 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=1a7b5c80-1c00-0000-7eb4-f6ba27100000 pid=4135 execve guuid=5520b480-1c00-0000-7eb4-f6ba29100000 pid=4137 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=5520b480-1c00-0000-7eb4-f6ba29100000 pid=4137 execve guuid=f9180181-1c00-0000-7eb4-f6ba2b100000 pid=4139 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=f9180181-1c00-0000-7eb4-f6ba2b100000 pid=4139 clone guuid=7a1f2b81-1c00-0000-7eb4-f6ba2c100000 pid=4140 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=7a1f2b81-1c00-0000-7eb4-f6ba2c100000 pid=4140 execve guuid=5226ed9d-1c00-0000-7eb4-f6ba80100000 pid=4224 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=5226ed9d-1c00-0000-7eb4-f6ba80100000 pid=4224 execve guuid=79ce83be-1c00-0000-7eb4-f6baee100000 pid=4334 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=79ce83be-1c00-0000-7eb4-f6baee100000 pid=4334 execve guuid=96e710bf-1c00-0000-7eb4-f6baf0100000 pid=4336 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=96e710bf-1c00-0000-7eb4-f6baf0100000 pid=4336 execve guuid=e2ea6dbf-1c00-0000-7eb4-f6baf3100000 pid=4339 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=e2ea6dbf-1c00-0000-7eb4-f6baf3100000 pid=4339 clone guuid=345da1c0-1c00-0000-7eb4-f6baf9100000 pid=4345 /usr/bin/wget net send-data guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=345da1c0-1c00-0000-7eb4-f6baf9100000 pid=4345 execve guuid=54facad3-1c00-0000-7eb4-f6ba08110000 pid=4360 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=54facad3-1c00-0000-7eb4-f6ba08110000 pid=4360 execve guuid=df11f2ea-1c00-0000-7eb4-f6ba1d110000 pid=4381 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=df11f2ea-1c00-0000-7eb4-f6ba1d110000 pid=4381 execve guuid=95da90eb-1c00-0000-7eb4-f6ba21110000 pid=4385 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=95da90eb-1c00-0000-7eb4-f6ba21110000 pid=4385 execve guuid=071a15ec-1c00-0000-7eb4-f6ba24110000 pid=4388 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=071a15ec-1c00-0000-7eb4-f6ba24110000 pid=4388 clone guuid=4a8147ec-1c00-0000-7eb4-f6ba25110000 pid=4389 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=4a8147ec-1c00-0000-7eb4-f6ba25110000 pid=4389 execve guuid=0e925409-1d00-0000-7eb4-f6ba7b110000 pid=4475 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=0e925409-1d00-0000-7eb4-f6ba7b110000 pid=4475 execve guuid=85a83a26-1d00-0000-7eb4-f6bad5110000 pid=4565 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=85a83a26-1d00-0000-7eb4-f6bad5110000 pid=4565 execve guuid=359fb126-1d00-0000-7eb4-f6bad6110000 pid=4566 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=359fb126-1d00-0000-7eb4-f6bad6110000 pid=4566 execve guuid=a3fd1227-1d00-0000-7eb4-f6bada110000 pid=4570 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=a3fd1227-1d00-0000-7eb4-f6bada110000 pid=4570 clone guuid=cb7e3028-1d00-0000-7eb4-f6bae1110000 pid=4577 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=cb7e3028-1d00-0000-7eb4-f6bae1110000 pid=4577 execve guuid=aaf8fc43-1d00-0000-7eb4-f6ba42120000 pid=4674 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=aaf8fc43-1d00-0000-7eb4-f6ba42120000 pid=4674 execve guuid=b701d760-1d00-0000-7eb4-f6baaf120000 pid=4783 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=b701d760-1d00-0000-7eb4-f6baaf120000 pid=4783 execve guuid=4f8d8061-1d00-0000-7eb4-f6bab0120000 pid=4784 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=4f8d8061-1d00-0000-7eb4-f6bab0120000 pid=4784 execve guuid=77bfed61-1d00-0000-7eb4-f6bab1120000 pid=4785 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=77bfed61-1d00-0000-7eb4-f6bab1120000 pid=4785 clone guuid=d75b1563-1d00-0000-7eb4-f6bab6120000 pid=4790 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=d75b1563-1d00-0000-7eb4-f6bab6120000 pid=4790 execve guuid=19159d87-1d00-0000-7eb4-f6ba28130000 pid=4904 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=19159d87-1d00-0000-7eb4-f6ba28130000 pid=4904 execve guuid=4a9103ae-1d00-0000-7eb4-f6baab130000 pid=5035 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=4a9103ae-1d00-0000-7eb4-f6baab130000 pid=5035 execve guuid=c64261ae-1d00-0000-7eb4-f6baad130000 pid=5037 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=c64261ae-1d00-0000-7eb4-f6baad130000 pid=5037 execve guuid=9495c1ae-1d00-0000-7eb4-f6baaf130000 pid=5039 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=9495c1ae-1d00-0000-7eb4-f6baaf130000 pid=5039 clone guuid=967bb5af-1d00-0000-7eb4-f6bab2130000 pid=5042 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=967bb5af-1d00-0000-7eb4-f6bab2130000 pid=5042 execve guuid=43af73cb-1d00-0000-7eb4-f6ba1b140000 pid=5147 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=43af73cb-1d00-0000-7eb4-f6ba1b140000 pid=5147 execve guuid=029fdfea-1d00-0000-7eb4-f6ba7a140000 pid=5242 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=029fdfea-1d00-0000-7eb4-f6ba7a140000 pid=5242 execve guuid=429c55eb-1d00-0000-7eb4-f6ba7e140000 pid=5246 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=429c55eb-1d00-0000-7eb4-f6ba7e140000 pid=5246 execve guuid=532ea9eb-1d00-0000-7eb4-f6ba81140000 pid=5249 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=532ea9eb-1d00-0000-7eb4-f6ba81140000 pid=5249 clone guuid=f3a93ded-1d00-0000-7eb4-f6ba89140000 pid=5257 /usr/bin/wget net send-data guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=f3a93ded-1d00-0000-7eb4-f6ba89140000 pid=5257 execve guuid=cb9a1300-1e00-0000-7eb4-f6baa5140000 pid=5285 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=cb9a1300-1e00-0000-7eb4-f6baa5140000 pid=5285 execve guuid=2ebbdc15-1e00-0000-7eb4-f6baa9140000 pid=5289 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=2ebbdc15-1e00-0000-7eb4-f6baa9140000 pid=5289 execve guuid=07fd2c16-1e00-0000-7eb4-f6baaa140000 pid=5290 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=07fd2c16-1e00-0000-7eb4-f6baaa140000 pid=5290 execve guuid=b2c87b16-1e00-0000-7eb4-f6baab140000 pid=5291 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=b2c87b16-1e00-0000-7eb4-f6baab140000 pid=5291 clone guuid=3a66a216-1e00-0000-7eb4-f6baac140000 pid=5292 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=3a66a216-1e00-0000-7eb4-f6baac140000 pid=5292 execve guuid=0d9ef53a-1e00-0000-7eb4-f6bab5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=0d9ef53a-1e00-0000-7eb4-f6bab5140000 pid=5301 execve guuid=36685463-1e00-0000-7eb4-f6bab6140000 pid=5302 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=36685463-1e00-0000-7eb4-f6bab6140000 pid=5302 execve guuid=a51d1b64-1e00-0000-7eb4-f6bab7140000 pid=5303 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=a51d1b64-1e00-0000-7eb4-f6bab7140000 pid=5303 execve guuid=5344c364-1e00-0000-7eb4-f6bab8140000 pid=5304 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=5344c364-1e00-0000-7eb4-f6bab8140000 pid=5304 clone guuid=d6704066-1e00-0000-7eb4-f6baba140000 pid=5306 /usr/bin/wget net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=d6704066-1e00-0000-7eb4-f6baba140000 pid=5306 execve guuid=0bd1c08b-1e00-0000-7eb4-f6babb140000 pid=5307 /usr/bin/curl net send-data write-file guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=0bd1c08b-1e00-0000-7eb4-f6babb140000 pid=5307 execve guuid=6a87f7af-1e00-0000-7eb4-f6babc140000 pid=5308 /usr/bin/cat guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=6a87f7af-1e00-0000-7eb4-f6babc140000 pid=5308 execve guuid=c78457b0-1e00-0000-7eb4-f6babd140000 pid=5309 /usr/bin/chmod guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=c78457b0-1e00-0000-7eb4-f6babd140000 pid=5309 execve guuid=91afacb0-1e00-0000-7eb4-f6babe140000 pid=5310 /usr/bin/bash guuid=05d79cb0-1a00-0000-7eb4-f6ba670c0000 pid=3175->guuid=91afacb0-1e00-0000-7eb4-f6babe140000 pid=5310 clone e10eb183-c74b-539a-bc26-e43bbf2bbb51 38.162.114.77:80 guuid=571819b1-1a00-0000-7eb4-f6ba690c0000 pid=3177->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=5ea373f3-1a00-0000-7eb4-f6ba970c0000 pid=3223->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4adafbaa-1b00-0000-7eb4-f6bab70d0000 pid=3511->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d9d4bbae-1b00-0000-7eb4-f6babd0d0000 pid=3517->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=005545e3-1b00-0000-7eb4-f6ba0b0e0000 pid=3595->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7da1a009-1c00-0000-7eb4-f6ba830e0000 pid=3715->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 144B guuid=c3d7851c-1c00-0000-7eb4-f6bac30e0000 pid=3779->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 93B guuid=61623632-1c00-0000-7eb4-f6ba200f0000 pid=3872->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=88e8e144-1c00-0000-7eb4-f6ba670f0000 pid=3943->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=5e8f3a5a-1c00-0000-7eb4-f6baaa0f0000 pid=4010->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=47b49e6c-1c00-0000-7eb4-f6bae70f0000 pid=4071->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7a1f2b81-1c00-0000-7eb4-f6ba2c100000 pid=4140->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=5226ed9d-1c00-0000-7eb4-f6ba80100000 pid=4224->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=345da1c0-1c00-0000-7eb4-f6baf9100000 pid=4345->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=54facad3-1c00-0000-7eb4-f6ba08110000 pid=4360->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=4a8147ec-1c00-0000-7eb4-f6ba25110000 pid=4389->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0e925409-1d00-0000-7eb4-f6ba7b110000 pid=4475->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=cb7e3028-1d00-0000-7eb4-f6bae1110000 pid=4577->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=aaf8fc43-1d00-0000-7eb4-f6ba42120000 pid=4674->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=d75b1563-1d00-0000-7eb4-f6bab6120000 pid=4790->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=19159d87-1d00-0000-7eb4-f6ba28130000 pid=4904->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=967bb5af-1d00-0000-7eb4-f6bab2130000 pid=5042->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=43af73cb-1d00-0000-7eb4-f6ba1b140000 pid=5147->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B guuid=f3a93ded-1d00-0000-7eb4-f6ba89140000 pid=5257->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 146B guuid=cb9a1300-1e00-0000-7eb4-f6baa5140000 pid=5285->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 95B guuid=3a66a216-1e00-0000-7eb4-f6baac140000 pid=5292->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0d9ef53a-1e00-0000-7eb4-f6bab5140000 pid=5301->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=d6704066-1e00-0000-7eb4-f6baba140000 pid=5306->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=0bd1c08b-1e00-0000-7eb4-f6babb140000 pid=5307->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 06:31:36 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (47393) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4380db13717e531fa7dd7ecdd4dce7833d5cbf1ff1a0a1dc75ae8ef755a1228f

(this sample)

  
Delivery method
Distributed via web download

Comments