MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5037f465eb1f32ab65304d2b23c88d35f58fd841e9cdce734e27c596049a1669. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5037f465eb1f32ab65304d2b23c88d35f58fd841e9cdce734e27c596049a1669
SHA3-384 hash: 8da2ee83c13624cb174ebe9cbba8e4321a41a305c2f5829fd288a9a99e796989a8441103ae29afe4ebcbbd64573575fa
SHA1 hash: b40574e00235e08cddd6617c7b0616f6f2b69549
MD5 hash: 6436aacd565ef23e29268c39fb7ea0e7
humanhash: nine-hydrogen-lion-tennessee
File name:lg
Download: download sample
Signature Mirai
File size:2'793 bytes
First seen:2025-10-14 20:15:05 UTC
Last seen:2025-10-15 13:24:59 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vTcYcqcEcOcNkzEcJcqcjcEcScLRUfcZcGf:vTcYcqcEcOcmEcJcqcjcEcScLRUfcZcs
TLSH T1B15170C4B22203B17FE25D727DB5556CB6C9E1D1BAC58E89D4ECA8BC818DF0814E06A3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.91.237.162/bins/sora.x869209da6b229bc24256cf26833723fc3a7c89272a5af754861c095d350b99de10 Miraimirai opendir
http://64.91.237.162/bins/sora.mips29c7491b527a0e18a776b8cc1831a8ba4b97d917fd76d047c96cc5ae21a79924 Miraimirai opendir
http://64.91.237.162/bins/sora.x86_647e8a271658bd0f9be6bf33a2ea92ce4fad4774aafac33c5b2caedf6417fd15ac Miraimirai opendir
http://64.91.237.162/bins/sora.i468n/an/aelf ua-wget
http://64.91.237.162/bins/sora.i68692575fbaacd79518241425e42a4cdacbf65def900864a48fc0b27504f78cbff4 Miraimirai opendir
http://64.91.237.162/bins/sora.mpsla3b52b958c8ea783c24f7a02fb57b5228fc1969791021519b42e14e58124e30d Miraimirai opendir
http://64.91.237.162/bins/sora.arm4n/an/aelf ua-wget
http://64.91.237.162/bins/sora.arm56357efa12b55a6c1f2d555f6dbbe40a0ed2d5c1e2dced815347fa98881eeefcb Miraimirai opendir
http://64.91.237.162/bins/sora.arm6579e9db35f7d3e276a6fd3b2bb98091a12c58d4cb0cd0ed3ae3cdbfd19304b0a Miraimirai opendir
http://64.91.237.162/bins/sora.arm7a2a3eda8d88cb807ffc26480a5a40cf79ac74b135b8aadaa225fed856da77cef Miraimirai opendir
http://64.91.237.162/bins/sora.ppc773298e6d3a314ffe9554eeea412ac65fbb16cf4030acf0e2553c42a1f159bb2 Miraimirai opendir
http://64.91.237.162/bins/sora.ppc440fpn/an/aelf ua-wget
http://64.91.237.162/bins/sora.m68ka25e8659220a59deaae914fc945fa6b31667bc0c7146a968bec1c4be9ffee9ed Miraimirai opendir
http://64.91.237.162/bins/sora.sh40dd50416937f0bbb202464b09fb982739b34bde7d11834b78a137fc4659502de Miraimirai opendir

Intelligence


File Origin
# of uploads :
2
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-14T17:40:00Z UTC
Last seen:
2025-10-14T19:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cbae69a9-1a00-0000-0375-4237260b0000 pid=2854 /usr/bin/sudo guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861 /tmp/sample.bin guuid=cbae69a9-1a00-0000-0375-4237260b0000 pid=2854->guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861 execve guuid=e2960fac-1a00-0000-0375-4237310b0000 pid=2865 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=e2960fac-1a00-0000-0375-4237310b0000 pid=2865 execve guuid=9d15e9c4-1a00-0000-0375-4237650b0000 pid=2917 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=9d15e9c4-1a00-0000-0375-4237650b0000 pid=2917 execve guuid=404783e9-1a00-0000-0375-4237840b0000 pid=2948 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=404783e9-1a00-0000-0375-4237840b0000 pid=2948 execve guuid=d968eee9-1a00-0000-0375-4237850b0000 pid=2949 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=d968eee9-1a00-0000-0375-4237850b0000 pid=2949 execve guuid=35d35cea-1a00-0000-0375-4237860b0000 pid=2950 /tmp/robben net guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=35d35cea-1a00-0000-0375-4237860b0000 pid=2950 execve guuid=867670ed-1a00-0000-0375-42378c0b0000 pid=2956 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=867670ed-1a00-0000-0375-42378c0b0000 pid=2956 execve guuid=bf8d9b04-1b00-0000-0375-4237b80b0000 pid=3000 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=bf8d9b04-1b00-0000-0375-4237b80b0000 pid=3000 execve guuid=89f2fb1a-1b00-0000-0375-4237ed0b0000 pid=3053 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=89f2fb1a-1b00-0000-0375-4237ed0b0000 pid=3053 execve guuid=7bb0c91b-1b00-0000-0375-4237ef0b0000 pid=3055 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=7bb0c91b-1b00-0000-0375-4237ef0b0000 pid=3055 execve guuid=5684871c-1b00-0000-0375-4237f10b0000 pid=3057 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=5684871c-1b00-0000-0375-4237f10b0000 pid=3057 clone guuid=af66561d-1b00-0000-0375-4237f50b0000 pid=3061 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=af66561d-1b00-0000-0375-4237f50b0000 pid=3061 execve guuid=3b7b8932-1b00-0000-0375-42372d0c0000 pid=3117 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=3b7b8932-1b00-0000-0375-42372d0c0000 pid=3117 execve guuid=9d019d48-1b00-0000-0375-42375d0c0000 pid=3165 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=9d019d48-1b00-0000-0375-42375d0c0000 pid=3165 execve guuid=464e0149-1b00-0000-0375-42375e0c0000 pid=3166 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=464e0149-1b00-0000-0375-42375e0c0000 pid=3166 execve guuid=b0b19149-1b00-0000-0375-42375f0c0000 pid=3167 /tmp/robben mprotect-exec net guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=b0b19149-1b00-0000-0375-42375f0c0000 pid=3167 execve guuid=bc5d574d-1b00-0000-0375-4237670c0000 pid=3175 /usr/bin/wget net send-data guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=bc5d574d-1b00-0000-0375-4237670c0000 pid=3175 execve guuid=8186d75c-1b00-0000-0375-4237750c0000 pid=3189 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=8186d75c-1b00-0000-0375-4237750c0000 pid=3189 execve guuid=98b6e46d-1b00-0000-0375-42378f0c0000 pid=3215 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=98b6e46d-1b00-0000-0375-42378f0c0000 pid=3215 execve guuid=c9b3426e-1b00-0000-0375-4237910c0000 pid=3217 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=c9b3426e-1b00-0000-0375-4237910c0000 pid=3217 execve guuid=fbaca76e-1b00-0000-0375-4237920c0000 pid=3218 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=fbaca76e-1b00-0000-0375-4237920c0000 pid=3218 clone guuid=4abee46e-1b00-0000-0375-4237940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=4abee46e-1b00-0000-0375-4237940c0000 pid=3220 execve guuid=fae58e85-1b00-0000-0375-4237a30c0000 pid=3235 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=fae58e85-1b00-0000-0375-4237a30c0000 pid=3235 execve guuid=12a3f3ee-1b00-0000-0375-42373a0d0000 pid=3386 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=12a3f3ee-1b00-0000-0375-42373a0d0000 pid=3386 execve guuid=9b7fc6ef-1b00-0000-0375-42373d0d0000 pid=3389 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=9b7fc6ef-1b00-0000-0375-42373d0d0000 pid=3389 execve guuid=d32234f0-1b00-0000-0375-42373f0d0000 pid=3391 /tmp/robben net guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=d32234f0-1b00-0000-0375-42373f0d0000 pid=3391 execve guuid=1f1603f4-1b00-0000-0375-4237490d0000 pid=3401 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=1f1603f4-1b00-0000-0375-4237490d0000 pid=3401 execve guuid=5e4f99a3-1c00-0000-0375-4237860e0000 pid=3718 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=5e4f99a3-1c00-0000-0375-4237860e0000 pid=3718 execve guuid=d96010bb-1c00-0000-0375-4237d50e0000 pid=3797 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=d96010bb-1c00-0000-0375-4237d50e0000 pid=3797 execve guuid=de0f83bb-1c00-0000-0375-4237d60e0000 pid=3798 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=de0f83bb-1c00-0000-0375-4237d60e0000 pid=3798 execve guuid=cebcddbb-1c00-0000-0375-4237d70e0000 pid=3799 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=cebcddbb-1c00-0000-0375-4237d70e0000 pid=3799 clone guuid=295ab4bc-1c00-0000-0375-4237d90e0000 pid=3801 /usr/bin/wget net send-data guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=295ab4bc-1c00-0000-0375-4237d90e0000 pid=3801 execve guuid=7e8c53cb-1c00-0000-0375-4237070f0000 pid=3847 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=7e8c53cb-1c00-0000-0375-4237070f0000 pid=3847 execve guuid=628356dd-1c00-0000-0375-4237450f0000 pid=3909 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=628356dd-1c00-0000-0375-4237450f0000 pid=3909 execve guuid=5ab4a3dd-1c00-0000-0375-4237470f0000 pid=3911 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=5ab4a3dd-1c00-0000-0375-4237470f0000 pid=3911 execve guuid=2fe2e1dd-1c00-0000-0375-4237490f0000 pid=3913 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=2fe2e1dd-1c00-0000-0375-4237490f0000 pid=3913 clone guuid=b50c00de-1c00-0000-0375-42374a0f0000 pid=3914 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=b50c00de-1c00-0000-0375-42374a0f0000 pid=3914 execve guuid=fa62d1f3-1c00-0000-0375-42378e0f0000 pid=3982 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=fa62d1f3-1c00-0000-0375-42378e0f0000 pid=3982 execve guuid=f127e60c-1d00-0000-0375-4237e80f0000 pid=4072 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=f127e60c-1d00-0000-0375-4237e80f0000 pid=4072 execve guuid=83ef420d-1d00-0000-0375-4237ea0f0000 pid=4074 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=83ef420d-1d00-0000-0375-4237ea0f0000 pid=4074 execve guuid=9d178d0d-1d00-0000-0375-4237ec0f0000 pid=4076 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=9d178d0d-1d00-0000-0375-4237ec0f0000 pid=4076 clone guuid=f42e290e-1d00-0000-0375-4237ee0f0000 pid=4078 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=f42e290e-1d00-0000-0375-4237ee0f0000 pid=4078 execve guuid=daef8323-1d00-0000-0375-423737100000 pid=4151 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=daef8323-1d00-0000-0375-423737100000 pid=4151 execve guuid=d9e17d3a-1d00-0000-0375-423761100000 pid=4193 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=d9e17d3a-1d00-0000-0375-423761100000 pid=4193 execve guuid=72a9053b-1d00-0000-0375-423763100000 pid=4195 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=72a9053b-1d00-0000-0375-423763100000 pid=4195 execve guuid=0cf0783b-1d00-0000-0375-423764100000 pid=4196 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=0cf0783b-1d00-0000-0375-423764100000 pid=4196 clone guuid=2d402e3c-1d00-0000-0375-423766100000 pid=4198 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=2d402e3c-1d00-0000-0375-423766100000 pid=4198 execve guuid=deb7dd58-1d00-0000-0375-4237c2100000 pid=4290 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=deb7dd58-1d00-0000-0375-4237c2100000 pid=4290 execve guuid=399bf576-1d00-0000-0375-42370c110000 pid=4364 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=399bf576-1d00-0000-0375-42370c110000 pid=4364 execve guuid=a9f26577-1d00-0000-0375-42370d110000 pid=4365 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=a9f26577-1d00-0000-0375-42370d110000 pid=4365 execve guuid=968bef77-1d00-0000-0375-42370e110000 pid=4366 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=968bef77-1d00-0000-0375-42370e110000 pid=4366 clone guuid=f92fe579-1d00-0000-0375-423710110000 pid=4368 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=f92fe579-1d00-0000-0375-423710110000 pid=4368 execve guuid=3461c290-1d00-0000-0375-423748110000 pid=4424 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=3461c290-1d00-0000-0375-423748110000 pid=4424 execve guuid=f88235a7-1d00-0000-0375-4237a5110000 pid=4517 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=f88235a7-1d00-0000-0375-4237a5110000 pid=4517 execve guuid=45f3aea7-1d00-0000-0375-4237a7110000 pid=4519 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=45f3aea7-1d00-0000-0375-4237a7110000 pid=4519 execve guuid=d40520a8-1d00-0000-0375-4237aa110000 pid=4522 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=d40520a8-1d00-0000-0375-4237aa110000 pid=4522 clone guuid=c3f2bda8-1d00-0000-0375-4237ae110000 pid=4526 /usr/bin/wget net send-data guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=c3f2bda8-1d00-0000-0375-4237ae110000 pid=4526 execve guuid=defe29b7-1d00-0000-0375-4237d2110000 pid=4562 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=defe29b7-1d00-0000-0375-4237d2110000 pid=4562 execve guuid=c1f6e0c7-1d00-0000-0375-42371b120000 pid=4635 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=c1f6e0c7-1d00-0000-0375-42371b120000 pid=4635 execve guuid=cec941c8-1d00-0000-0375-42371d120000 pid=4637 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=cec941c8-1d00-0000-0375-42371d120000 pid=4637 execve guuid=b39194c8-1d00-0000-0375-423720120000 pid=4640 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=b39194c8-1d00-0000-0375-423720120000 pid=4640 clone guuid=2329c4c8-1d00-0000-0375-423722120000 pid=4642 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=2329c4c8-1d00-0000-0375-423722120000 pid=4642 execve guuid=69b875e4-1d00-0000-0375-423775120000 pid=4725 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=69b875e4-1d00-0000-0375-423775120000 pid=4725 execve guuid=03e78903-1e00-0000-0375-4237c8120000 pid=4808 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=03e78903-1e00-0000-0375-4237c8120000 pid=4808 execve guuid=18a2e703-1e00-0000-0375-4237ca120000 pid=4810 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=18a2e703-1e00-0000-0375-4237ca120000 pid=4810 execve guuid=c7bd2d04-1e00-0000-0375-4237cc120000 pid=4812 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=c7bd2d04-1e00-0000-0375-4237cc120000 pid=4812 clone guuid=df222205-1e00-0000-0375-4237d2120000 pid=4818 /usr/bin/wget net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=df222205-1e00-0000-0375-4237d2120000 pid=4818 execve guuid=09607a21-1e00-0000-0375-423729130000 pid=4905 /usr/bin/curl net send-data write-file guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=09607a21-1e00-0000-0375-423729130000 pid=4905 execve guuid=51b90040-1e00-0000-0375-42377d130000 pid=4989 /usr/bin/cat guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=51b90040-1e00-0000-0375-42377d130000 pid=4989 execve guuid=0c204d40-1e00-0000-0375-42377f130000 pid=4991 /usr/bin/chmod guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=0c204d40-1e00-0000-0375-42377f130000 pid=4991 execve guuid=ed108d40-1e00-0000-0375-423780130000 pid=4992 /usr/bin/bash guuid=2f9822ab-1a00-0000-0375-42372d0b0000 pid=2861->guuid=ed108d40-1e00-0000-0375-423780130000 pid=4992 clone 10651e68-131f-5e6d-a670-1d19a7120e88 64.91.237.162:80 guuid=e2960fac-1a00-0000-0375-4237310b0000 pid=2865->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=9d15e9c4-1a00-0000-0375-4237650b0000 pid=2917->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=35d35cea-1a00-0000-0375-4237860b0000 pid=2950->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=867670ed-1a00-0000-0375-42378c0b0000 pid=2956->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=bf8d9b04-1b00-0000-0375-4237b80b0000 pid=3000->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=af66561d-1b00-0000-0375-4237f50b0000 pid=3061->10651e68-131f-5e6d-a670-1d19a7120e88 send: 144B guuid=3b7b8932-1b00-0000-0375-42372d0c0000 pid=3117->10651e68-131f-5e6d-a670-1d19a7120e88 send: 93B guuid=b0b19149-1b00-0000-0375-42375f0c0000 pid=3167->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc5d574d-1b00-0000-0375-4237670c0000 pid=3175->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=8186d75c-1b00-0000-0375-4237750c0000 pid=3189->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=4abee46e-1b00-0000-0375-4237940c0000 pid=3220->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=fae58e85-1b00-0000-0375-4237a30c0000 pid=3235->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=d32234f0-1b00-0000-0375-42373f0d0000 pid=3391->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1f1603f4-1b00-0000-0375-4237490d0000 pid=3401->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=5e4f99a3-1c00-0000-0375-4237860e0000 pid=3718->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=295ab4bc-1c00-0000-0375-4237d90e0000 pid=3801->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=7e8c53cb-1c00-0000-0375-4237070f0000 pid=3847->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=b50c00de-1c00-0000-0375-42374a0f0000 pid=3914->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=fa62d1f3-1c00-0000-0375-42378e0f0000 pid=3982->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=f42e290e-1d00-0000-0375-4237ee0f0000 pid=4078->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=daef8323-1d00-0000-0375-423737100000 pid=4151->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=2d402e3c-1d00-0000-0375-423766100000 pid=4198->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=deb7dd58-1d00-0000-0375-4237c2100000 pid=4290->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=f92fe579-1d00-0000-0375-423710110000 pid=4368->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=3461c290-1d00-0000-0375-423748110000 pid=4424->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B guuid=c3f2bda8-1d00-0000-0375-4237ae110000 pid=4526->10651e68-131f-5e6d-a670-1d19a7120e88 send: 146B guuid=defe29b7-1d00-0000-0375-4237d2110000 pid=4562->10651e68-131f-5e6d-a670-1d19a7120e88 send: 95B guuid=2329c4c8-1d00-0000-0375-423722120000 pid=4642->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=69b875e4-1d00-0000-0375-423775120000 pid=4725->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=df222205-1e00-0000-0375-4237d2120000 pid=4818->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=09607a21-1e00-0000-0375-423729130000 pid=4905->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-14 20:23:27 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (46113) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5037f465eb1f32ab65304d2b23c88d35f58fd841e9cdce734e27c596049a1669

(this sample)

  
Delivery method
Distributed via web download

Comments