MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5d1eccb213d13bed8f4c0ed2adbcbff8e9a1ce8a6f6306a3cbc7dad21d905ef0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 5d1eccb213d13bed8f4c0ed2adbcbff8e9a1ce8a6f6306a3cbc7dad21d905ef0
SHA3-384 hash: 1caf691225eed4cfe9abea7e40c9420c385ba37c00974f871fc9342ce368dd289de9e3d1f760477b794262e47ebbe0ce
SHA1 hash: 1812efde155c5466b67101111d62fc7379258fb0
MD5 hash: d3f9f282a5a5e5e941875dca19a31b15
humanhash: cold-floor-orange-coffee
File name:x.sh
Download: download sample
Signature Mirai
File size:2'204 bytes
First seen:2026-04-18 04:24:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp2upZApKaOKaupiSpj+9pOYpNop5HQp8YpIypjcplopMp:vzQPrg9VgMjZyoO
TLSH T17B41ACD9109553306CF6DD7272E79468718190E399CEBE84D4DC78EDC8DEE44B082B86
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.173/x86025bfef806662c34ca8a3b17219854e4c277b0f1a27de0bf1f3e922d17fbb2b1 Miraielf mirai ua-wget
http://176.65.148.173/mipsb927020d009eade59e1b679162f57995aaf54b96e5a0cc631d81f404091cc3e6 Miraielf gafgyt mirai ua-wget
http://176.65.148.173/mpsl9794a9e6403b12f28526270712855bdbcf8caded5a465ca1e7df892f3817e961 Miraielf mirai ua-wget
http://176.65.148.173/armdbb234915f65bc22e2206bceefe4c7c0916cc1678ecc22cb17136c35232fe724 Gafgytelf gafgyt mirai ua-wget
http://176.65.148.173/arm5n/an/aua-wget
http://176.65.148.173/arm6ca8eb07779893526758e8004e3489207a825c094bf642d0cf8c4b31585f066bd Miraielf mirai ua-wget
http://176.65.148.173/arm71f2553a51260340b846fcef1afc358c2207cf69d22f85e166e36e8d8ac630b15 Miraielf mirai ua-wget
http://176.65.148.173/ppca329f1fed00ae7b5ca49e8e6a7c25b3f69e62eaafe75e10a42334f1379ddc7a7 Miraielf mirai ua-wget
http://176.65.148.173/m68kf96cf5df19e0e98426e2d7584a789a36474f715895677dc0e417ed3f82e84253 Miraielf mirai ua-wget
http://176.65.148.173/spc6d0ccf790ff27fb69bb64e8f0d0a3b9ea6b250efd79ee7cd6fb93fe9d12dc09a Miraielf mirai ua-wget
http://176.65.148.173/i686n/an/aua-wget
http://176.65.148.173/sh4bd275f5b00c77a9fe5e2ce262693e820b22ab5515ffdbff1ebf907c50116b439 Miraielf mirai ua-wget
http://176.65.148.173/arcb63290159d4975f21dcf3738f7593221b86a680116101d11e7679861ea582495 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-17T22:19:00Z UTC
Last seen:
2026-04-18T17:14:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=5350e9e1-1b00-0000-11fc-aab4fc0b0000 pid=3068 /usr/bin/sudo guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077 /tmp/sample.bin guuid=5350e9e1-1b00-0000-11fc-aab4fc0b0000 pid=3068->guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077 execve guuid=88dca8e7-1b00-0000-11fc-aab4070c0000 pid=3079 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=88dca8e7-1b00-0000-11fc-aab4070c0000 pid=3079 execve guuid=234d91f0-1b00-0000-11fc-aab4190c0000 pid=3097 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=234d91f0-1b00-0000-11fc-aab4190c0000 pid=3097 execve guuid=2a61a737-1c00-0000-11fc-aab4850c0000 pid=3205 /usr/bin/cat guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=2a61a737-1c00-0000-11fc-aab4850c0000 pid=3205 execve guuid=bc2f3838-1c00-0000-11fc-aab4870c0000 pid=3207 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=bc2f3838-1c00-0000-11fc-aab4870c0000 pid=3207 execve guuid=a1a0bd38-1c00-0000-11fc-aab4890c0000 pid=3209 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=a1a0bd38-1c00-0000-11fc-aab4890c0000 pid=3209 execve guuid=acf2c03a-1c00-0000-11fc-aab4900c0000 pid=3216 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=acf2c03a-1c00-0000-11fc-aab4900c0000 pid=3216 execve guuid=aad5fc41-1c00-0000-11fc-aab49b0c0000 pid=3227 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=aad5fc41-1c00-0000-11fc-aab49b0c0000 pid=3227 execve guuid=aa25aa4c-1c00-0000-11fc-aab4a60c0000 pid=3238 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=aa25aa4c-1c00-0000-11fc-aab4a60c0000 pid=3238 clone guuid=b32ce94c-1c00-0000-11fc-aab4a70c0000 pid=3239 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=b32ce94c-1c00-0000-11fc-aab4a70c0000 pid=3239 execve guuid=8938844d-1c00-0000-11fc-aab4a80c0000 pid=3240 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=8938844d-1c00-0000-11fc-aab4a80c0000 pid=3240 execve guuid=c0290150-1c00-0000-11fc-aab4ab0c0000 pid=3243 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=c0290150-1c00-0000-11fc-aab4ab0c0000 pid=3243 execve guuid=3b9a2b58-1c00-0000-11fc-aab4ac0c0000 pid=3244 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=3b9a2b58-1c00-0000-11fc-aab4ac0c0000 pid=3244 execve guuid=743a8263-1c00-0000-11fc-aab4b70c0000 pid=3255 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=743a8263-1c00-0000-11fc-aab4b70c0000 pid=3255 clone guuid=0a0ab463-1c00-0000-11fc-aab4b80c0000 pid=3256 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=0a0ab463-1c00-0000-11fc-aab4b80c0000 pid=3256 execve guuid=b6411064-1c00-0000-11fc-aab4ba0c0000 pid=3258 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=b6411064-1c00-0000-11fc-aab4ba0c0000 pid=3258 execve guuid=6e136666-1c00-0000-11fc-aab4c00c0000 pid=3264 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=6e136666-1c00-0000-11fc-aab4c00c0000 pid=3264 execve guuid=d028a372-1c00-0000-11fc-aab4c80c0000 pid=3272 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=d028a372-1c00-0000-11fc-aab4c80c0000 pid=3272 execve guuid=ce69117c-1c00-0000-11fc-aab4ca0c0000 pid=3274 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=ce69117c-1c00-0000-11fc-aab4ca0c0000 pid=3274 clone guuid=448f597c-1c00-0000-11fc-aab4cb0c0000 pid=3275 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=448f597c-1c00-0000-11fc-aab4cb0c0000 pid=3275 execve guuid=c7d5207d-1c00-0000-11fc-aab4cc0c0000 pid=3276 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=c7d5207d-1c00-0000-11fc-aab4cc0c0000 pid=3276 execve guuid=f49f157f-1c00-0000-11fc-aab4d50c0000 pid=3285 /usr/bin/wget net send-data guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=f49f157f-1c00-0000-11fc-aab4d50c0000 pid=3285 execve guuid=5af2e282-1c00-0000-11fc-aab4d60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=5af2e282-1c00-0000-11fc-aab4d60c0000 pid=3286 execve guuid=ff207988-1c00-0000-11fc-aab4d70c0000 pid=3287 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=ff207988-1c00-0000-11fc-aab4d70c0000 pid=3287 clone guuid=78a59688-1c00-0000-11fc-aab4d80c0000 pid=3288 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=78a59688-1c00-0000-11fc-aab4d80c0000 pid=3288 execve guuid=778ae488-1c00-0000-11fc-aab4d90c0000 pid=3289 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=778ae488-1c00-0000-11fc-aab4d90c0000 pid=3289 execve guuid=f7538e8a-1c00-0000-11fc-aab4dc0c0000 pid=3292 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=f7538e8a-1c00-0000-11fc-aab4dc0c0000 pid=3292 execve guuid=79079093-1c00-0000-11fc-aab4eb0c0000 pid=3307 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=79079093-1c00-0000-11fc-aab4eb0c0000 pid=3307 execve guuid=299ddeb0-1c00-0000-11fc-aab4120d0000 pid=3346 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=299ddeb0-1c00-0000-11fc-aab4120d0000 pid=3346 clone guuid=2c6d1cb1-1c00-0000-11fc-aab4130d0000 pid=3347 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=2c6d1cb1-1c00-0000-11fc-aab4130d0000 pid=3347 execve guuid=a651c6b1-1c00-0000-11fc-aab4140d0000 pid=3348 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=a651c6b1-1c00-0000-11fc-aab4140d0000 pid=3348 execve guuid=1d1bb6b3-1c00-0000-11fc-aab4170d0000 pid=3351 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=1d1bb6b3-1c00-0000-11fc-aab4170d0000 pid=3351 execve guuid=2dec3cf9-1c00-0000-11fc-aab4820d0000 pid=3458 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=2dec3cf9-1c00-0000-11fc-aab4820d0000 pid=3458 execve guuid=83920e1b-1d00-0000-11fc-aab4d10d0000 pid=3537 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=83920e1b-1d00-0000-11fc-aab4d10d0000 pid=3537 clone guuid=63f32d1b-1d00-0000-11fc-aab4d20d0000 pid=3538 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=63f32d1b-1d00-0000-11fc-aab4d20d0000 pid=3538 execve guuid=db14aa1b-1d00-0000-11fc-aab4d40d0000 pid=3540 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=db14aa1b-1d00-0000-11fc-aab4d40d0000 pid=3540 execve guuid=1f38b41d-1d00-0000-11fc-aab4dc0d0000 pid=3548 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=1f38b41d-1d00-0000-11fc-aab4dc0d0000 pid=3548 execve guuid=6fc6352a-1d00-0000-11fc-aab4e60d0000 pid=3558 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=6fc6352a-1d00-0000-11fc-aab4e60d0000 pid=3558 execve guuid=ab3a01b9-1d00-0000-11fc-aab4f60e0000 pid=3830 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=ab3a01b9-1d00-0000-11fc-aab4f60e0000 pid=3830 clone guuid=203f40b9-1d00-0000-11fc-aab4f70e0000 pid=3831 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=203f40b9-1d00-0000-11fc-aab4f70e0000 pid=3831 execve guuid=6bd5cfb9-1d00-0000-11fc-aab4f90e0000 pid=3833 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=6bd5cfb9-1d00-0000-11fc-aab4f90e0000 pid=3833 execve guuid=3d7aa2bd-1d00-0000-11fc-aab4060f0000 pid=3846 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=3d7aa2bd-1d00-0000-11fc-aab4060f0000 pid=3846 execve guuid=ea248a27-1e00-0000-11fc-aab436100000 pid=4150 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=ea248a27-1e00-0000-11fc-aab436100000 pid=4150 execve guuid=6685a11d-1f00-0000-11fc-aab4f7120000 pid=4855 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=6685a11d-1f00-0000-11fc-aab4f7120000 pid=4855 clone guuid=44a7c51d-1f00-0000-11fc-aab4f9120000 pid=4857 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=44a7c51d-1f00-0000-11fc-aab4f9120000 pid=4857 execve guuid=4a6c151e-1f00-0000-11fc-aab4fa120000 pid=4858 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=4a6c151e-1f00-0000-11fc-aab4fa120000 pid=4858 execve guuid=84950120-1f00-0000-11fc-aab404130000 pid=4868 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=84950120-1f00-0000-11fc-aab404130000 pid=4868 execve guuid=7fbda14f-1f00-0000-11fc-aab490130000 pid=5008 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=7fbda14f-1f00-0000-11fc-aab490130000 pid=5008 execve guuid=7bbf11ee-1f00-0000-11fc-aab4ba140000 pid=5306 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=7bbf11ee-1f00-0000-11fc-aab4ba140000 pid=5306 clone guuid=8d4532ee-1f00-0000-11fc-aab4bb140000 pid=5307 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=8d4532ee-1f00-0000-11fc-aab4bb140000 pid=5307 execve guuid=e66089ee-1f00-0000-11fc-aab4bc140000 pid=5308 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=e66089ee-1f00-0000-11fc-aab4bc140000 pid=5308 execve guuid=4a4f66f0-1f00-0000-11fc-aab4bf140000 pid=5311 /usr/bin/wget net send-data guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=4a4f66f0-1f00-0000-11fc-aab4bf140000 pid=5311 execve guuid=6a2675f4-1f00-0000-11fc-aab4c0140000 pid=5312 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=6a2675f4-1f00-0000-11fc-aab4c0140000 pid=5312 execve guuid=4e4ddcfc-1f00-0000-11fc-aab4c1140000 pid=5313 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=4e4ddcfc-1f00-0000-11fc-aab4c1140000 pid=5313 clone guuid=549909fd-1f00-0000-11fc-aab4c2140000 pid=5314 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=549909fd-1f00-0000-11fc-aab4c2140000 pid=5314 execve guuid=a67f61fd-1f00-0000-11fc-aab4c3140000 pid=5315 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=a67f61fd-1f00-0000-11fc-aab4c3140000 pid=5315 execve guuid=14138aff-1f00-0000-11fc-aab4c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=14138aff-1f00-0000-11fc-aab4c6140000 pid=5318 execve guuid=9c0a7724-2000-0000-11fc-aab4c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=9c0a7724-2000-0000-11fc-aab4c7140000 pid=5319 execve guuid=79deedd9-2000-0000-11fc-aab4c8140000 pid=5320 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=79deedd9-2000-0000-11fc-aab4c8140000 pid=5320 clone guuid=0d120fda-2000-0000-11fc-aab4c9140000 pid=5321 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=0d120fda-2000-0000-11fc-aab4c9140000 pid=5321 execve guuid=42b55fda-2000-0000-11fc-aab4ca140000 pid=5322 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=42b55fda-2000-0000-11fc-aab4ca140000 pid=5322 execve guuid=9a0112dc-2000-0000-11fc-aab4cd140000 pid=5325 /usr/bin/wget net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=9a0112dc-2000-0000-11fc-aab4cd140000 pid=5325 execve guuid=edb94266-2100-0000-11fc-aab4d5140000 pid=5333 /usr/bin/curl net send-data write-file guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=edb94266-2100-0000-11fc-aab4d5140000 pid=5333 execve guuid=61960e9d-2100-0000-11fc-aab4d6140000 pid=5334 /usr/bin/bash guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=61960e9d-2100-0000-11fc-aab4d6140000 pid=5334 clone guuid=b783929d-2100-0000-11fc-aab4d7140000 pid=5335 /usr/bin/chmod guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=b783929d-2100-0000-11fc-aab4d7140000 pid=5335 execve guuid=8812bf9e-2100-0000-11fc-aab4d8140000 pid=5336 /tmp/Love net guuid=e544a0e6-1b00-0000-11fc-aab4050c0000 pid=3077->guuid=8812bf9e-2100-0000-11fc-aab4d8140000 pid=5336 execve 9014b735-fee2-536a-a424-791876b94e33 176.65.148.173:80 guuid=88dca8e7-1b00-0000-11fc-aab4070c0000 pid=3079->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=234d91f0-1b00-0000-11fc-aab4190c0000 pid=3097->9014b735-fee2-536a-a424-791876b94e33 send: 81B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a1a0bd38-1c00-0000-11fc-aab4890c0000 pid=3209->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=50409c3a-1c00-0000-11fc-aab48e0c0000 pid=3214 /tmp/Love guuid=a1a0bd38-1c00-0000-11fc-aab4890c0000 pid=3209->guuid=50409c3a-1c00-0000-11fc-aab48e0c0000 pid=3214 clone guuid=a174a73a-1c00-0000-11fc-aab48f0c0000 pid=3215 /tmp/Love net send-data zombie guuid=50409c3a-1c00-0000-11fc-aab48e0c0000 pid=3214->guuid=a174a73a-1c00-0000-11fc-aab48f0c0000 pid=3215 clone 54d02837-d66c-5abe-9bf4-0667442f2c39 176.65.148.173:19286 guuid=a174a73a-1c00-0000-11fc-aab48f0c0000 pid=3215->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 25752B guuid=acf2c03a-1c00-0000-11fc-aab4900c0000 pid=3216->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=aad5fc41-1c00-0000-11fc-aab49b0c0000 pid=3227->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=8938844d-1c00-0000-11fc-aab4a80c0000 pid=3240->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4effce4f-1c00-0000-11fc-aab4a90c0000 pid=3241 /tmp/Love guuid=8938844d-1c00-0000-11fc-aab4a80c0000 pid=3240->guuid=4effce4f-1c00-0000-11fc-aab4a90c0000 pid=3241 clone guuid=d7c2dd4f-1c00-0000-11fc-aab4aa0c0000 pid=3242 /tmp/Love net send-data zombie guuid=4effce4f-1c00-0000-11fc-aab4a90c0000 pid=3241->guuid=d7c2dd4f-1c00-0000-11fc-aab4aa0c0000 pid=3242 clone guuid=d7c2dd4f-1c00-0000-11fc-aab4aa0c0000 pid=3242->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 111B guuid=c0290150-1c00-0000-11fc-aab4ab0c0000 pid=3243->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=3b9a2b58-1c00-0000-11fc-aab4ac0c0000 pid=3244->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=b6411064-1c00-0000-11fc-aab4ba0c0000 pid=3258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=73c53366-1c00-0000-11fc-aab4be0c0000 pid=3262 /tmp/Love guuid=b6411064-1c00-0000-11fc-aab4ba0c0000 pid=3258->guuid=73c53366-1c00-0000-11fc-aab4be0c0000 pid=3262 clone guuid=3de74166-1c00-0000-11fc-aab4bf0c0000 pid=3263 /tmp/Love net send-data zombie guuid=73c53366-1c00-0000-11fc-aab4be0c0000 pid=3262->guuid=3de74166-1c00-0000-11fc-aab4bf0c0000 pid=3263 clone guuid=3de74166-1c00-0000-11fc-aab4bf0c0000 pid=3263->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 22977B guuid=6e136666-1c00-0000-11fc-aab4c00c0000 pid=3264->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=d028a372-1c00-0000-11fc-aab4c80c0000 pid=3272->9014b735-fee2-536a-a424-791876b94e33 send: 81B guuid=c7d5207d-1c00-0000-11fc-aab4cc0c0000 pid=3276->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4196f97e-1c00-0000-11fc-aab4d30c0000 pid=3283 /tmp/Love guuid=c7d5207d-1c00-0000-11fc-aab4cc0c0000 pid=3276->guuid=4196f97e-1c00-0000-11fc-aab4d30c0000 pid=3283 clone guuid=c8c9ff7e-1c00-0000-11fc-aab4d40c0000 pid=3284 /tmp/Love net send-data zombie guuid=4196f97e-1c00-0000-11fc-aab4d30c0000 pid=3283->guuid=c8c9ff7e-1c00-0000-11fc-aab4d40c0000 pid=3284 clone guuid=c8c9ff7e-1c00-0000-11fc-aab4d40c0000 pid=3284->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 19980B guuid=f49f157f-1c00-0000-11fc-aab4d50c0000 pid=3285->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=5af2e282-1c00-0000-11fc-aab4d60c0000 pid=3286->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=778ae488-1c00-0000-11fc-aab4d90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a65e6e8a-1c00-0000-11fc-aab4da0c0000 pid=3290 /tmp/Love guuid=778ae488-1c00-0000-11fc-aab4d90c0000 pid=3289->guuid=a65e6e8a-1c00-0000-11fc-aab4da0c0000 pid=3290 clone guuid=2372768a-1c00-0000-11fc-aab4db0c0000 pid=3291 /tmp/Love net send-data zombie guuid=a65e6e8a-1c00-0000-11fc-aab4da0c0000 pid=3290->guuid=2372768a-1c00-0000-11fc-aab4db0c0000 pid=3291 clone guuid=2372768a-1c00-0000-11fc-aab4db0c0000 pid=3291->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 18981B guuid=f7538e8a-1c00-0000-11fc-aab4dc0c0000 pid=3292->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=79079093-1c00-0000-11fc-aab4eb0c0000 pid=3307->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=a651c6b1-1c00-0000-11fc-aab4140d0000 pid=3348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3a1588b3-1c00-0000-11fc-aab4150d0000 pid=3349 /tmp/Love guuid=a651c6b1-1c00-0000-11fc-aab4140d0000 pid=3348->guuid=3a1588b3-1c00-0000-11fc-aab4150d0000 pid=3349 clone guuid=4fe998b3-1c00-0000-11fc-aab4160d0000 pid=3350 /tmp/Love net send-data zombie guuid=3a1588b3-1c00-0000-11fc-aab4150d0000 pid=3349->guuid=4fe998b3-1c00-0000-11fc-aab4160d0000 pid=3350 clone guuid=4fe998b3-1c00-0000-11fc-aab4160d0000 pid=3350->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 23310B guuid=1d1bb6b3-1c00-0000-11fc-aab4170d0000 pid=3351->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=2dec3cf9-1c00-0000-11fc-aab4820d0000 pid=3458->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=db14aa1b-1d00-0000-11fc-aab4d40d0000 pid=3540->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4c0b821d-1d00-0000-11fc-aab4da0d0000 pid=3546 /tmp/Love guuid=db14aa1b-1d00-0000-11fc-aab4d40d0000 pid=3540->guuid=4c0b821d-1d00-0000-11fc-aab4da0d0000 pid=3546 clone guuid=37c5901d-1d00-0000-11fc-aab4db0d0000 pid=3547 /tmp/Love net send-data zombie guuid=4c0b821d-1d00-0000-11fc-aab4da0d0000 pid=3546->guuid=37c5901d-1d00-0000-11fc-aab4db0d0000 pid=3547 clone guuid=37c5901d-1d00-0000-11fc-aab4db0d0000 pid=3547->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 22311B guuid=1f38b41d-1d00-0000-11fc-aab4dc0d0000 pid=3548->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=6fc6352a-1d00-0000-11fc-aab4e60d0000 pid=3558->9014b735-fee2-536a-a424-791876b94e33 send: 81B guuid=6bd5cfb9-1d00-0000-11fc-aab4f90e0000 pid=3833->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=007374bd-1d00-0000-11fc-aab4030f0000 pid=3843 /tmp/Love guuid=6bd5cfb9-1d00-0000-11fc-aab4f90e0000 pid=3833->guuid=007374bd-1d00-0000-11fc-aab4030f0000 pid=3843 clone guuid=74977cbd-1d00-0000-11fc-aab4040f0000 pid=3844 /tmp/Love net send-data zombie guuid=007374bd-1d00-0000-11fc-aab4030f0000 pid=3843->guuid=74977cbd-1d00-0000-11fc-aab4040f0000 pid=3844 clone guuid=74977cbd-1d00-0000-11fc-aab4040f0000 pid=3844->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 19758B guuid=3d7aa2bd-1d00-0000-11fc-aab4060f0000 pid=3846->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=ea248a27-1e00-0000-11fc-aab436100000 pid=4150->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=4a6c151e-1f00-0000-11fc-aab4fa120000 pid=4858->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b0c7e81f-1f00-0000-11fc-aab402130000 pid=4866 /tmp/Love guuid=4a6c151e-1f00-0000-11fc-aab4fa120000 pid=4858->guuid=b0c7e81f-1f00-0000-11fc-aab402130000 pid=4866 clone guuid=49b2f01f-1f00-0000-11fc-aab403130000 pid=4867 /tmp/Love net send-data zombie guuid=b0c7e81f-1f00-0000-11fc-aab402130000 pid=4866->guuid=49b2f01f-1f00-0000-11fc-aab403130000 pid=4867 clone guuid=49b2f01f-1f00-0000-11fc-aab403130000 pid=4867->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 20535B guuid=84950120-1f00-0000-11fc-aab404130000 pid=4868->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=7fbda14f-1f00-0000-11fc-aab490130000 pid=5008->9014b735-fee2-536a-a424-791876b94e33 send: 81B guuid=e66089ee-1f00-0000-11fc-aab4bc140000 pid=5308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b34843f0-1f00-0000-11fc-aab4bd140000 pid=5309 /tmp/Love guuid=e66089ee-1f00-0000-11fc-aab4bc140000 pid=5308->guuid=b34843f0-1f00-0000-11fc-aab4bd140000 pid=5309 clone guuid=c7fd51f0-1f00-0000-11fc-aab4be140000 pid=5310 /tmp/Love net send-data zombie guuid=b34843f0-1f00-0000-11fc-aab4bd140000 pid=5309->guuid=c7fd51f0-1f00-0000-11fc-aab4be140000 pid=5310 clone guuid=c7fd51f0-1f00-0000-11fc-aab4be140000 pid=5310->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 16761B guuid=4a4f66f0-1f00-0000-11fc-aab4bf140000 pid=5311->9014b735-fee2-536a-a424-791876b94e33 send: 133B guuid=6a2675f4-1f00-0000-11fc-aab4c0140000 pid=5312->9014b735-fee2-536a-a424-791876b94e33 send: 82B guuid=a67f61fd-1f00-0000-11fc-aab4c3140000 pid=5315->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d88e4dff-1f00-0000-11fc-aab4c4140000 pid=5316 /tmp/Love guuid=a67f61fd-1f00-0000-11fc-aab4c3140000 pid=5315->guuid=d88e4dff-1f00-0000-11fc-aab4c4140000 pid=5316 clone guuid=2b1462ff-1f00-0000-11fc-aab4c5140000 pid=5317 /tmp/Love net send-data zombie guuid=d88e4dff-1f00-0000-11fc-aab4c4140000 pid=5316->guuid=2b1462ff-1f00-0000-11fc-aab4c5140000 pid=5317 clone guuid=2b1462ff-1f00-0000-11fc-aab4c5140000 pid=5317->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 13431B guuid=14138aff-1f00-0000-11fc-aab4c6140000 pid=5318->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=9c0a7724-2000-0000-11fc-aab4c7140000 pid=5319->9014b735-fee2-536a-a424-791876b94e33 send: 81B guuid=42b55fda-2000-0000-11fc-aab4ca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=77d7ebdb-2000-0000-11fc-aab4cb140000 pid=5323 /tmp/Love guuid=42b55fda-2000-0000-11fc-aab4ca140000 pid=5322->guuid=77d7ebdb-2000-0000-11fc-aab4cb140000 pid=5323 clone guuid=c804f7db-2000-0000-11fc-aab4cc140000 pid=5324 /tmp/Love net send-data zombie guuid=77d7ebdb-2000-0000-11fc-aab4cb140000 pid=5323->guuid=c804f7db-2000-0000-11fc-aab4cc140000 pid=5324 clone guuid=c804f7db-2000-0000-11fc-aab4cc140000 pid=5324->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 16539B guuid=9a0112dc-2000-0000-11fc-aab4cd140000 pid=5325->9014b735-fee2-536a-a424-791876b94e33 send: 132B guuid=edb94266-2100-0000-11fc-aab4d5140000 pid=5333->9014b735-fee2-536a-a424-791876b94e33 send: 81B guuid=8812bf9e-2100-0000-11fc-aab4d8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5b51f4a2-2100-0000-11fc-aab4d9140000 pid=5337 /tmp/Love guuid=8812bf9e-2100-0000-11fc-aab4d8140000 pid=5336->guuid=5b51f4a2-2100-0000-11fc-aab4d9140000 pid=5337 clone guuid=c4023da3-2100-0000-11fc-aab4da140000 pid=5338 /tmp/Love net send-data zombie guuid=5b51f4a2-2100-0000-11fc-aab4d9140000 pid=5337->guuid=c4023da3-2100-0000-11fc-aab4da140000 pid=5338 clone guuid=c4023da3-2100-0000-11fc-aab4da140000 pid=5338->54d02837-d66c-5abe-9bf4-0667442f2c39 send: 18204B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2026-04-18 01:37:10 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads system network configuration
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5d1eccb213d13bed8f4c0ed2adbcbff8e9a1ce8a6f6306a3cbc7dad21d905ef0

(this sample)

  
Delivery method
Distributed via web download

Comments