MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4adc49e6a8128f659d6642f7addb22b8eb109553cea022c2df2465098f50b5ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 4adc49e6a8128f659d6642f7addb22b8eb109553cea022c2df2465098f50b5ba
SHA3-384 hash: ff58086ba6cca2a0489f7bec67fcb1985f4038d2ed3eb5ca15d36485b02ecf720dde19f428c623cd0c70aa7c2ef38378
SHA1 hash: 2a69ba6bacb717110150a4e8cd15670eb0789eff
MD5 hash: 00f476ed09ae7d45d678e4b7e1d0872b
humanhash: jersey-ohio-princess-five
File name:goahead
Download: download sample
Signature Mirai
File size:2'863 bytes
First seen:2025-10-14 20:15:01 UTC
Last seen:2025-11-19 08:34:25 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vToYoqoEoOoNkzEoJoqojoEoSoLRUfoZoGL:vToYoqoEoOomEoJoqojoEoSoLRUfoZoC
TLSH T1735160C5722603747FE25D777DB5406CB6C5E1D2BAC58E8AD4ECA8B881CDF0814A06B3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.91.237.162/bins/sora.x869209da6b229bc24256cf26833723fc3a7c89272a5af754861c095d350b99de10 Miraimirai opendir
http://64.91.237.162/bins/sora.mips29c7491b527a0e18a776b8cc1831a8ba4b97d917fd76d047c96cc5ae21a79924 Miraimirai opendir
http://64.91.237.162/bins/sora.x86_647e8a271658bd0f9be6bf33a2ea92ce4fad4774aafac33c5b2caedf6417fd15ac Miraimirai opendir
http://64.91.237.162/bins/sora.i468n/an/aelf ua-wget
http://64.91.237.162/bins/sora.i68692575fbaacd79518241425e42a4cdacbf65def900864a48fc0b27504f78cbff4 Miraimirai opendir
http://64.91.237.162/bins/sora.mpsla3b52b958c8ea783c24f7a02fb57b5228fc1969791021519b42e14e58124e30d Miraimirai opendir
http://64.91.237.162/bins/sora.arm4n/an/aelf ua-wget
http://64.91.237.162/bins/sora.arm56357efa12b55a6c1f2d555f6dbbe40a0ed2d5c1e2dced815347fa98881eeefcb Miraimirai opendir
http://64.91.237.162/bins/sora.arm6579e9db35f7d3e276a6fd3b2bb98091a12c58d4cb0cd0ed3ae3cdbfd19304b0a Miraimirai opendir
http://64.91.237.162/bins/sora.arm7a2a3eda8d88cb807ffc26480a5a40cf79ac74b135b8aadaa225fed856da77cef Miraimirai opendir
http://64.91.237.162/bins/sora.ppc773298e6d3a314ffe9554eeea412ac65fbb16cf4030acf0e2553c42a1f159bb2 Miraimirai opendir
http://64.91.237.162/bins/sora.ppc440fpn/an/aelf ua-wget
http://64.91.237.162/bins/sora.m68ka25e8659220a59deaae914fc945fa6b31667bc0c7146a968bec1c4be9ffee9ed Miraimirai opendir
http://64.91.237.162/bins/sora.sh40dd50416937f0bbb202464b09fb982739b34bde7d11834b78a137fc4659502de Miraimirai opendir

Intelligence


File Origin
# of uploads :
2
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-14T17:40:00Z UTC
Last seen:
2025-10-14T19:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0ed8164b-1a00-0000-5ba1-1c50c40a0000 pid=2756 /usr/bin/sudo guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760 /tmp/sample.bin guuid=0ed8164b-1a00-0000-5ba1-1c50c40a0000 pid=2756->guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760 execve guuid=1786854d-1a00-0000-5ba1-1c50ca0a0000 pid=2762 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=1786854d-1a00-0000-5ba1-1c50ca0a0000 pid=2762 execve guuid=e8837864-1a00-0000-5ba1-1c50ed0a0000 pid=2797 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=e8837864-1a00-0000-5ba1-1c50ed0a0000 pid=2797 execve guuid=edebf480-1a00-0000-5ba1-1c50220b0000 pid=2850 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=edebf480-1a00-0000-5ba1-1c50220b0000 pid=2850 execve guuid=de8d5881-1a00-0000-5ba1-1c50230b0000 pid=2851 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=de8d5881-1a00-0000-5ba1-1c50230b0000 pid=2851 execve guuid=2ddcaf81-1a00-0000-5ba1-1c50240b0000 pid=2852 /tmp/robben net guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=2ddcaf81-1a00-0000-5ba1-1c50240b0000 pid=2852 execve guuid=222d9684-1a00-0000-5ba1-1c50300b0000 pid=2864 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=222d9684-1a00-0000-5ba1-1c50300b0000 pid=2864 execve guuid=ca4f299c-1a00-0000-5ba1-1c506c0b0000 pid=2924 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ca4f299c-1a00-0000-5ba1-1c506c0b0000 pid=2924 execve guuid=80ecd7b3-1a00-0000-5ba1-1c50930b0000 pid=2963 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=80ecd7b3-1a00-0000-5ba1-1c50930b0000 pid=2963 execve guuid=5db84fb4-1a00-0000-5ba1-1c50950b0000 pid=2965 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=5db84fb4-1a00-0000-5ba1-1c50950b0000 pid=2965 execve guuid=069c96b4-1a00-0000-5ba1-1c50960b0000 pid=2966 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=069c96b4-1a00-0000-5ba1-1c50960b0000 pid=2966 clone guuid=b85777b6-1a00-0000-5ba1-1c50980b0000 pid=2968 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=b85777b6-1a00-0000-5ba1-1c50980b0000 pid=2968 execve guuid=ac14aed0-1a00-0000-5ba1-1c50b50b0000 pid=2997 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ac14aed0-1a00-0000-5ba1-1c50b50b0000 pid=2997 execve guuid=4c9671e9-1a00-0000-5ba1-1c50e30b0000 pid=3043 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=4c9671e9-1a00-0000-5ba1-1c50e30b0000 pid=3043 execve guuid=02f8e8e9-1a00-0000-5ba1-1c50e40b0000 pid=3044 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=02f8e8e9-1a00-0000-5ba1-1c50e40b0000 pid=3044 execve guuid=a8db3dea-1a00-0000-5ba1-1c50e60b0000 pid=3046 /tmp/robben mprotect-exec net guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=a8db3dea-1a00-0000-5ba1-1c50e60b0000 pid=3046 execve guuid=7f0107ed-1a00-0000-5ba1-1c50ee0b0000 pid=3054 /usr/bin/wget net send-data guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=7f0107ed-1a00-0000-5ba1-1c50ee0b0000 pid=3054 execve guuid=b6a0fbfb-1a00-0000-5ba1-1c50140c0000 pid=3092 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=b6a0fbfb-1a00-0000-5ba1-1c50140c0000 pid=3092 execve guuid=858d020c-1b00-0000-5ba1-1c50350c0000 pid=3125 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=858d020c-1b00-0000-5ba1-1c50350c0000 pid=3125 execve guuid=bd1d5e0c-1b00-0000-5ba1-1c50370c0000 pid=3127 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=bd1d5e0c-1b00-0000-5ba1-1c50370c0000 pid=3127 execve guuid=9cf8c40c-1b00-0000-5ba1-1c50390c0000 pid=3129 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=9cf8c40c-1b00-0000-5ba1-1c50390c0000 pid=3129 clone guuid=150bf80c-1b00-0000-5ba1-1c503a0c0000 pid=3130 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=150bf80c-1b00-0000-5ba1-1c503a0c0000 pid=3130 execve guuid=6d9d9a22-1b00-0000-5ba1-1c506b0c0000 pid=3179 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=6d9d9a22-1b00-0000-5ba1-1c506b0c0000 pid=3179 execve guuid=5c4d4c3a-1b00-0000-5ba1-1c507f0c0000 pid=3199 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=5c4d4c3a-1b00-0000-5ba1-1c507f0c0000 pid=3199 execve guuid=b6c6d93a-1b00-0000-5ba1-1c50800c0000 pid=3200 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=b6c6d93a-1b00-0000-5ba1-1c50800c0000 pid=3200 execve guuid=e7ea4b3b-1b00-0000-5ba1-1c50810c0000 pid=3201 /tmp/robben net guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=e7ea4b3b-1b00-0000-5ba1-1c50810c0000 pid=3201 execve guuid=3000e13e-1b00-0000-5ba1-1c50880c0000 pid=3208 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=3000e13e-1b00-0000-5ba1-1c50880c0000 pid=3208 execve guuid=18148755-1b00-0000-5ba1-1c50a60c0000 pid=3238 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=18148755-1b00-0000-5ba1-1c50a60c0000 pid=3238 execve guuid=1e0e6570-1b00-0000-5ba1-1c50bc0c0000 pid=3260 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=1e0e6570-1b00-0000-5ba1-1c50bc0c0000 pid=3260 execve guuid=3134e570-1b00-0000-5ba1-1c50bd0c0000 pid=3261 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=3134e570-1b00-0000-5ba1-1c50bd0c0000 pid=3261 execve guuid=abdd7671-1b00-0000-5ba1-1c50be0c0000 pid=3262 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=abdd7671-1b00-0000-5ba1-1c50be0c0000 pid=3262 clone guuid=6ca1bc72-1b00-0000-5ba1-1c50c00c0000 pid=3264 /usr/bin/wget net send-data guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=6ca1bc72-1b00-0000-5ba1-1c50c00c0000 pid=3264 execve guuid=33a27c81-1b00-0000-5ba1-1c50d60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=33a27c81-1b00-0000-5ba1-1c50d60c0000 pid=3286 execve guuid=42be7491-1b00-0000-5ba1-1c50f00c0000 pid=3312 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=42be7491-1b00-0000-5ba1-1c50f00c0000 pid=3312 execve guuid=4a4eef91-1b00-0000-5ba1-1c50f20c0000 pid=3314 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=4a4eef91-1b00-0000-5ba1-1c50f20c0000 pid=3314 execve guuid=32ac5992-1b00-0000-5ba1-1c50f40c0000 pid=3316 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=32ac5992-1b00-0000-5ba1-1c50f40c0000 pid=3316 clone guuid=1b6b9292-1b00-0000-5ba1-1c50f50c0000 pid=3317 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=1b6b9292-1b00-0000-5ba1-1c50f50c0000 pid=3317 execve guuid=f0142264-1c00-0000-5ba1-1c50950e0000 pid=3733 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=f0142264-1c00-0000-5ba1-1c50950e0000 pid=3733 execve guuid=ce8943a5-1c00-0000-5ba1-1c506a0f0000 pid=3946 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ce8943a5-1c00-0000-5ba1-1c506a0f0000 pid=3946 execve guuid=01d193a5-1c00-0000-5ba1-1c506c0f0000 pid=3948 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=01d193a5-1c00-0000-5ba1-1c506c0f0000 pid=3948 execve guuid=6692fca5-1c00-0000-5ba1-1c50700f0000 pid=3952 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=6692fca5-1c00-0000-5ba1-1c50700f0000 pid=3952 clone guuid=ba55fba7-1c00-0000-5ba1-1c50760f0000 pid=3958 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ba55fba7-1c00-0000-5ba1-1c50760f0000 pid=3958 execve guuid=58b247bd-1c00-0000-5ba1-1c50b70f0000 pid=4023 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=58b247bd-1c00-0000-5ba1-1c50b70f0000 pid=4023 execve guuid=148ac4d4-1c00-0000-5ba1-1c500a100000 pid=4106 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=148ac4d4-1c00-0000-5ba1-1c500a100000 pid=4106 execve guuid=322e30d5-1c00-0000-5ba1-1c500b100000 pid=4107 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=322e30d5-1c00-0000-5ba1-1c500b100000 pid=4107 execve guuid=ed97d0d5-1c00-0000-5ba1-1c500c100000 pid=4108 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ed97d0d5-1c00-0000-5ba1-1c500c100000 pid=4108 clone guuid=af8fc1d6-1c00-0000-5ba1-1c5014100000 pid=4116 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=af8fc1d6-1c00-0000-5ba1-1c5014100000 pid=4116 execve guuid=49eceff3-1c00-0000-5ba1-1c506a100000 pid=4202 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=49eceff3-1c00-0000-5ba1-1c506a100000 pid=4202 execve guuid=e738d812-1d00-0000-5ba1-1c50ce100000 pid=4302 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=e738d812-1d00-0000-5ba1-1c50ce100000 pid=4302 execve guuid=1a853813-1d00-0000-5ba1-1c50d2100000 pid=4306 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=1a853813-1d00-0000-5ba1-1c50d2100000 pid=4306 execve guuid=cf7b8113-1d00-0000-5ba1-1c50d6100000 pid=4310 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=cf7b8113-1d00-0000-5ba1-1c50d6100000 pid=4310 clone guuid=fbd61314-1d00-0000-5ba1-1c50d9100000 pid=4313 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=fbd61314-1d00-0000-5ba1-1c50d9100000 pid=4313 execve guuid=d07e9f2a-1d00-0000-5ba1-1c500a110000 pid=4362 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=d07e9f2a-1d00-0000-5ba1-1c500a110000 pid=4362 execve guuid=ef604358-1d00-0000-5ba1-1c505c110000 pid=4444 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ef604358-1d00-0000-5ba1-1c505c110000 pid=4444 execve guuid=5bd0a858-1d00-0000-5ba1-1c505e110000 pid=4446 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=5bd0a858-1d00-0000-5ba1-1c505e110000 pid=4446 execve guuid=9a181e59-1d00-0000-5ba1-1c5061110000 pid=4449 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=9a181e59-1d00-0000-5ba1-1c5061110000 pid=4449 clone guuid=df99d15a-1d00-0000-5ba1-1c5069110000 pid=4457 /usr/bin/wget net send-data guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=df99d15a-1d00-0000-5ba1-1c5069110000 pid=4457 execve guuid=39c70b6a-1d00-0000-5ba1-1c50a5110000 pid=4517 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=39c70b6a-1d00-0000-5ba1-1c50a5110000 pid=4517 execve guuid=ee7f157b-1d00-0000-5ba1-1c50d9110000 pid=4569 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=ee7f157b-1d00-0000-5ba1-1c50d9110000 pid=4569 execve guuid=98656a7b-1d00-0000-5ba1-1c50da110000 pid=4570 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=98656a7b-1d00-0000-5ba1-1c50da110000 pid=4570 execve guuid=4ad0dd7b-1d00-0000-5ba1-1c50db110000 pid=4571 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=4ad0dd7b-1d00-0000-5ba1-1c50db110000 pid=4571 clone guuid=443f0a7c-1d00-0000-5ba1-1c50dd110000 pid=4573 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=443f0a7c-1d00-0000-5ba1-1c50dd110000 pid=4573 execve guuid=cffe8697-1d00-0000-5ba1-1c5044120000 pid=4676 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=cffe8697-1d00-0000-5ba1-1c5044120000 pid=4676 execve guuid=901cd1b5-1d00-0000-5ba1-1c50a9120000 pid=4777 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=901cd1b5-1d00-0000-5ba1-1c50a9120000 pid=4777 execve guuid=b27b21b6-1d00-0000-5ba1-1c50ab120000 pid=4779 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=b27b21b6-1d00-0000-5ba1-1c50ab120000 pid=4779 execve guuid=848366b6-1d00-0000-5ba1-1c50ac120000 pid=4780 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=848366b6-1d00-0000-5ba1-1c50ac120000 pid=4780 clone guuid=bf0d31b7-1d00-0000-5ba1-1c50b2120000 pid=4786 /usr/bin/wget net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=bf0d31b7-1d00-0000-5ba1-1c50b2120000 pid=4786 execve guuid=3d8a13d3-1d00-0000-5ba1-1c50fd120000 pid=4861 /usr/bin/curl net send-data write-file guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=3d8a13d3-1d00-0000-5ba1-1c50fd120000 pid=4861 execve guuid=f8dcf8f1-1d00-0000-5ba1-1c504f130000 pid=4943 /usr/bin/cat guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=f8dcf8f1-1d00-0000-5ba1-1c504f130000 pid=4943 execve guuid=d91b6ef2-1d00-0000-5ba1-1c5051130000 pid=4945 /usr/bin/chmod guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=d91b6ef2-1d00-0000-5ba1-1c5051130000 pid=4945 execve guuid=5817d2f2-1d00-0000-5ba1-1c5053130000 pid=4947 /usr/bin/bash guuid=d7eb284d-1a00-0000-5ba1-1c50c80a0000 pid=2760->guuid=5817d2f2-1d00-0000-5ba1-1c5053130000 pid=4947 clone 10651e68-131f-5e6d-a670-1d19a7120e88 64.91.237.162:80 guuid=1786854d-1a00-0000-5ba1-1c50ca0a0000 pid=2762->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=e8837864-1a00-0000-5ba1-1c50ed0a0000 pid=2797->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2ddcaf81-1a00-0000-5ba1-1c50240b0000 pid=2852->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=222d9684-1a00-0000-5ba1-1c50300b0000 pid=2864->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=ca4f299c-1a00-0000-5ba1-1c506c0b0000 pid=2924->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=b85777b6-1a00-0000-5ba1-1c50980b0000 pid=2968->10651e68-131f-5e6d-a670-1d19a7120e88 send: 144B guuid=ac14aed0-1a00-0000-5ba1-1c50b50b0000 pid=2997->10651e68-131f-5e6d-a670-1d19a7120e88 send: 93B guuid=a8db3dea-1a00-0000-5ba1-1c50e60b0000 pid=3046->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7f0107ed-1a00-0000-5ba1-1c50ee0b0000 pid=3054->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=b6a0fbfb-1a00-0000-5ba1-1c50140c0000 pid=3092->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=150bf80c-1b00-0000-5ba1-1c503a0c0000 pid=3130->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=6d9d9a22-1b00-0000-5ba1-1c506b0c0000 pid=3179->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=e7ea4b3b-1b00-0000-5ba1-1c50810c0000 pid=3201->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3000e13e-1b00-0000-5ba1-1c50880c0000 pid=3208->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=18148755-1b00-0000-5ba1-1c50a60c0000 pid=3238->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=6ca1bc72-1b00-0000-5ba1-1c50c00c0000 pid=3264->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=33a27c81-1b00-0000-5ba1-1c50d60c0000 pid=3286->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=1b6b9292-1b00-0000-5ba1-1c50f50c0000 pid=3317->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=f0142264-1c00-0000-5ba1-1c50950e0000 pid=3733->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=ba55fba7-1c00-0000-5ba1-1c50760f0000 pid=3958->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=58b247bd-1c00-0000-5ba1-1c50b70f0000 pid=4023->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=af8fc1d6-1c00-0000-5ba1-1c5014100000 pid=4116->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=49eceff3-1c00-0000-5ba1-1c506a100000 pid=4202->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=fbd61314-1d00-0000-5ba1-1c50d9100000 pid=4313->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=d07e9f2a-1d00-0000-5ba1-1c500a110000 pid=4362->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B guuid=df99d15a-1d00-0000-5ba1-1c5069110000 pid=4457->10651e68-131f-5e6d-a670-1d19a7120e88 send: 146B guuid=39c70b6a-1d00-0000-5ba1-1c50a5110000 pid=4517->10651e68-131f-5e6d-a670-1d19a7120e88 send: 95B guuid=443f0a7c-1d00-0000-5ba1-1c50dd110000 pid=4573->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=cffe8697-1d00-0000-5ba1-1c5044120000 pid=4676->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=bf0d31b7-1d00-0000-5ba1-1c50b2120000 pid=4786->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=3d8a13d3-1d00-0000-5ba1-1c50fd120000 pid=4861->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-14 20:22:28 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (47425) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 4adc49e6a8128f659d6642f7addb22b8eb109553cea022c2df2465098f50b5ba

(this sample)

  
Delivery method
Distributed via web download

Comments