MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5f6d315261a928c32802d53c6ca693c57affda17939b3a7290ed5d8ea9138f4a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 5f6d315261a928c32802d53c6ca693c57affda17939b3a7290ed5d8ea9138f4a
SHA3-384 hash: 842c2415d4e915a9566a904cd8ded8cd9d5d4cbdcbcbf2f74c05491ee40e68d6c81dfc767ebaa13469bab44194821d72
SHA1 hash: 2837f44a08d92758db975b150726dd2aed11a4ed
MD5 hash: c46841de88d00810142be7753b8b81c0
humanhash: king-hotel-arizona-speaker
File name:ok
Download: download sample
Signature Mirai
File size:2'778 bytes
First seen:2025-11-21 22:40:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vJACyfJMO3GJ//JJllXnJOwjJhBEJRURWTJRRGJF7Frb0SolJ6sCsKe3JZeZgrBw:vJACyfJMO3GJ//JJllXnJOwjJhBEJyke
TLSH T1545142DD2AA05A215810D8BAF2AAC5CC7195A2F71CBAEF4098DF36F5C06CD447C7C762
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://83.150.218.225/SupplySrvarmbc8e56b086d6dff8c4bbc0024306f2f368dad282fb69e01f832facedd66f52c5 Miraiarm elf geofenced mirai ua-wget USA
http://83.150.218.225/SupplySrvarm63be70fc3e9f54f38da5acb854babcce2bea80d5a38987dabd9d60c9dde6d917c Miraiarm elf geofenced mirai ua-wget USA
http://83.150.218.225/SupplySrvarm5n/an/aelf ua-wget
http://83.150.218.225/SupplySrvarm7n/an/aelf ua-wget
http://83.150.218.225/SupplySrvm68k37444aaf2a15551e182f35b0501adb44ae52705c0b385d709e822ee18ae6b286 Miraielf geofenced m68k mirai ua-wget USA
http://83.150.218.225/SupplySrvmipsd4cd65f586307579b6eba2540779633ae3e7a68906b6ca3a772e99532fedd605 Miraielf geofenced mips mirai ua-wget USA
http://83.150.218.225/SupplySrvmpsle33743491df24ba92b79656fea6b398302042a6d07bbff9bbf254243317b1f7e Miraielf geofenced mips mirai ua-wget USA
http://83.150.218.225/SupplySrvppc964b22f03b8c29dd5a24b8b2bd5648eaec1a750ada4e0f1a4a001e9f2dc27bb7 Miraielf geofenced mirai PowerPC ua-wget USA
http://83.150.218.225/SupplySrvsh4abe2a6cf5eeb276ef68c627032aea68f769e049203fe29d3c5a565c7fb68475a Miraielf geofenced mirai SuperH ua-wget USA
http://83.150.218.225/SupplySrvspc24b8846706503e38321a71be85d68169326030a20a8efb64bedc8145103d22ee Miraielf geofenced mirai sparc ua-wget USA
http://83.150.218.225/SupplySrvx6416b870f6de57049a36b6a8b6c8ce5610efa69cb5b6d6495d82d549cb74bd38bb Miraielf geofenced mirai ua-wget USA x86
http://83.150.218.225/SupplySrvx86dddd16cb5c5e035211360a5458544611738fc8571ced8ba4138e5e13158c9cbe Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
42
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-21T20:55:00Z UTC
Last seen:
2025-11-21T23:42:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5b163574-1a00-0000-e3f5-e9aa2c0b0000 pid=2860 /usr/bin/sudo guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867 /tmp/sample.bin guuid=5b163574-1a00-0000-e3f5-e9aa2c0b0000 pid=2860->guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867 execve guuid=fe848778-1a00-0000-e3f5-e9aa350b0000 pid=2869 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=fe848778-1a00-0000-e3f5-e9aa350b0000 pid=2869 execve guuid=7623d87e-1a00-0000-e3f5-e9aa3e0b0000 pid=2878 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=7623d87e-1a00-0000-e3f5-e9aa3e0b0000 pid=2878 execve guuid=4c62aea5-1a00-0000-e3f5-e9aa4f0b0000 pid=2895 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=4c62aea5-1a00-0000-e3f5-e9aa4f0b0000 pid=2895 execve guuid=f4f218a6-1a00-0000-e3f5-e9aa510b0000 pid=2897 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=f4f218a6-1a00-0000-e3f5-e9aa510b0000 pid=2897 clone guuid=81d9dea6-1a00-0000-e3f5-e9aa550b0000 pid=2901 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=81d9dea6-1a00-0000-e3f5-e9aa550b0000 pid=2901 execve guuid=1d3c42a7-1a00-0000-e3f5-e9aa580b0000 pid=2904 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=1d3c42a7-1a00-0000-e3f5-e9aa580b0000 pid=2904 execve guuid=bf29d0a7-1a00-0000-e3f5-e9aa5a0b0000 pid=2906 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=bf29d0a7-1a00-0000-e3f5-e9aa5a0b0000 pid=2906 execve guuid=4cb025ac-1a00-0000-e3f5-e9aa630b0000 pid=2915 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=4cb025ac-1a00-0000-e3f5-e9aa630b0000 pid=2915 execve guuid=079e89b1-1a00-0000-e3f5-e9aa6b0b0000 pid=2923 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=079e89b1-1a00-0000-e3f5-e9aa6b0b0000 pid=2923 execve guuid=7f25e6b1-1a00-0000-e3f5-e9aa6d0b0000 pid=2925 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=7f25e6b1-1a00-0000-e3f5-e9aa6d0b0000 pid=2925 clone guuid=d40ba1b3-1a00-0000-e3f5-e9aa720b0000 pid=2930 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=d40ba1b3-1a00-0000-e3f5-e9aa720b0000 pid=2930 execve guuid=36ab1ac6-1a00-0000-e3f5-e9aa7e0b0000 pid=2942 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=36ab1ac6-1a00-0000-e3f5-e9aa7e0b0000 pid=2942 execve guuid=f5f895c6-1a00-0000-e3f5-e9aa800b0000 pid=2944 /usr/bin/wget net send-data guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=f5f895c6-1a00-0000-e3f5-e9aa800b0000 pid=2944 execve guuid=d66759c9-1a00-0000-e3f5-e9aa830b0000 pid=2947 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=d66759c9-1a00-0000-e3f5-e9aa830b0000 pid=2947 execve guuid=f2a70ad0-1a00-0000-e3f5-e9aa8f0b0000 pid=2959 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=f2a70ad0-1a00-0000-e3f5-e9aa8f0b0000 pid=2959 execve guuid=a21c77d0-1a00-0000-e3f5-e9aa910b0000 pid=2961 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=a21c77d0-1a00-0000-e3f5-e9aa910b0000 pid=2961 clone guuid=9e9dc2d0-1a00-0000-e3f5-e9aa940b0000 pid=2964 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=9e9dc2d0-1a00-0000-e3f5-e9aa940b0000 pid=2964 execve guuid=bab721d1-1a00-0000-e3f5-e9aa960b0000 pid=2966 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=bab721d1-1a00-0000-e3f5-e9aa960b0000 pid=2966 execve guuid=00ab8ad1-1a00-0000-e3f5-e9aa980b0000 pid=2968 /usr/bin/wget net send-data guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=00ab8ad1-1a00-0000-e3f5-e9aa980b0000 pid=2968 execve guuid=e2884ed4-1a00-0000-e3f5-e9aa9e0b0000 pid=2974 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=e2884ed4-1a00-0000-e3f5-e9aa9e0b0000 pid=2974 execve guuid=c84bc0d8-1a00-0000-e3f5-e9aaa90b0000 pid=2985 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=c84bc0d8-1a00-0000-e3f5-e9aaa90b0000 pid=2985 execve guuid=a2750cd9-1a00-0000-e3f5-e9aaaa0b0000 pid=2986 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=a2750cd9-1a00-0000-e3f5-e9aaaa0b0000 pid=2986 clone guuid=d0ec9fd9-1a00-0000-e3f5-e9aaae0b0000 pid=2990 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=d0ec9fd9-1a00-0000-e3f5-e9aaae0b0000 pid=2990 execve guuid=c124e1d9-1a00-0000-e3f5-e9aab00b0000 pid=2992 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=c124e1d9-1a00-0000-e3f5-e9aab00b0000 pid=2992 execve guuid=e4d920da-1a00-0000-e3f5-e9aab20b0000 pid=2994 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=e4d920da-1a00-0000-e3f5-e9aab20b0000 pid=2994 execve guuid=12ca0bde-1a00-0000-e3f5-e9aac20b0000 pid=3010 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=12ca0bde-1a00-0000-e3f5-e9aac20b0000 pid=3010 execve guuid=243be6e2-1a00-0000-e3f5-e9aad20b0000 pid=3026 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=243be6e2-1a00-0000-e3f5-e9aad20b0000 pid=3026 execve guuid=01d728e3-1a00-0000-e3f5-e9aad30b0000 pid=3027 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=01d728e3-1a00-0000-e3f5-e9aad30b0000 pid=3027 clone guuid=d9f5c4e3-1a00-0000-e3f5-e9aad80b0000 pid=3032 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=d9f5c4e3-1a00-0000-e3f5-e9aad80b0000 pid=3032 execve guuid=393ff9e5-1a00-0000-e3f5-e9aae00b0000 pid=3040 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=393ff9e5-1a00-0000-e3f5-e9aae00b0000 pid=3040 execve guuid=b33c67e6-1a00-0000-e3f5-e9aae20b0000 pid=3042 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=b33c67e6-1a00-0000-e3f5-e9aae20b0000 pid=3042 execve guuid=e5b418ea-1a00-0000-e3f5-e9aaec0b0000 pid=3052 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=e5b418ea-1a00-0000-e3f5-e9aaec0b0000 pid=3052 execve guuid=939a32f0-1a00-0000-e3f5-e9aaf90b0000 pid=3065 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=939a32f0-1a00-0000-e3f5-e9aaf90b0000 pid=3065 execve guuid=6f5c8cf0-1a00-0000-e3f5-e9aafb0b0000 pid=3067 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=6f5c8cf0-1a00-0000-e3f5-e9aafb0b0000 pid=3067 clone guuid=757460f1-1a00-0000-e3f5-e9aafe0b0000 pid=3070 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=757460f1-1a00-0000-e3f5-e9aafe0b0000 pid=3070 execve guuid=deac31f4-1a00-0000-e3f5-e9aa040c0000 pid=3076 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=deac31f4-1a00-0000-e3f5-e9aa040c0000 pid=3076 execve guuid=95947af4-1a00-0000-e3f5-e9aa060c0000 pid=3078 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=95947af4-1a00-0000-e3f5-e9aa060c0000 pid=3078 execve guuid=e8aa76f9-1a00-0000-e3f5-e9aa140c0000 pid=3092 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=e8aa76f9-1a00-0000-e3f5-e9aa140c0000 pid=3092 execve guuid=2f7d3b00-1b00-0000-e3f5-e9aa240c0000 pid=3108 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=2f7d3b00-1b00-0000-e3f5-e9aa240c0000 pid=3108 execve guuid=9c8fa100-1b00-0000-e3f5-e9aa260c0000 pid=3110 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=9c8fa100-1b00-0000-e3f5-e9aa260c0000 pid=3110 clone guuid=3cbc3b01-1b00-0000-e3f5-e9aa2a0c0000 pid=3114 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=3cbc3b01-1b00-0000-e3f5-e9aa2a0c0000 pid=3114 execve guuid=8a800002-1b00-0000-e3f5-e9aa2d0c0000 pid=3117 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=8a800002-1b00-0000-e3f5-e9aa2d0c0000 pid=3117 execve guuid=8e2b5b02-1b00-0000-e3f5-e9aa2f0c0000 pid=3119 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=8e2b5b02-1b00-0000-e3f5-e9aa2f0c0000 pid=3119 execve guuid=ec432206-1b00-0000-e3f5-e9aa3d0c0000 pid=3133 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=ec432206-1b00-0000-e3f5-e9aa3d0c0000 pid=3133 execve guuid=e7c52b0b-1b00-0000-e3f5-e9aa4c0c0000 pid=3148 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=e7c52b0b-1b00-0000-e3f5-e9aa4c0c0000 pid=3148 execve guuid=b369740b-1b00-0000-e3f5-e9aa4e0c0000 pid=3150 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=b369740b-1b00-0000-e3f5-e9aa4e0c0000 pid=3150 clone guuid=a1e5060c-1b00-0000-e3f5-e9aa500c0000 pid=3152 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=a1e5060c-1b00-0000-e3f5-e9aa500c0000 pid=3152 execve guuid=a158600c-1b00-0000-e3f5-e9aa510c0000 pid=3153 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=a158600c-1b00-0000-e3f5-e9aa510c0000 pid=3153 execve guuid=99efc30c-1b00-0000-e3f5-e9aa530c0000 pid=3155 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=99efc30c-1b00-0000-e3f5-e9aa530c0000 pid=3155 execve guuid=b053c811-1b00-0000-e3f5-e9aa5c0c0000 pid=3164 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=b053c811-1b00-0000-e3f5-e9aa5c0c0000 pid=3164 execve guuid=c6eb7e15-1b00-0000-e3f5-e9aa640c0000 pid=3172 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=c6eb7e15-1b00-0000-e3f5-e9aa640c0000 pid=3172 execve guuid=f22ec415-1b00-0000-e3f5-e9aa670c0000 pid=3175 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=f22ec415-1b00-0000-e3f5-e9aa670c0000 pid=3175 clone guuid=2adb5c16-1b00-0000-e3f5-e9aa6b0c0000 pid=3179 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=2adb5c16-1b00-0000-e3f5-e9aa6b0c0000 pid=3179 execve guuid=45c1dc19-1b00-0000-e3f5-e9aa6d0c0000 pid=3181 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=45c1dc19-1b00-0000-e3f5-e9aa6d0c0000 pid=3181 execve guuid=93a2361a-1b00-0000-e3f5-e9aa6e0c0000 pid=3182 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=93a2361a-1b00-0000-e3f5-e9aa6e0c0000 pid=3182 execve guuid=d7c92c1e-1b00-0000-e3f5-e9aa6f0c0000 pid=3183 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=d7c92c1e-1b00-0000-e3f5-e9aa6f0c0000 pid=3183 execve guuid=56b12024-1b00-0000-e3f5-e9aa700c0000 pid=3184 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=56b12024-1b00-0000-e3f5-e9aa700c0000 pid=3184 execve guuid=3b28a224-1b00-0000-e3f5-e9aa710c0000 pid=3185 /usr/bin/bash guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=3b28a224-1b00-0000-e3f5-e9aa710c0000 pid=3185 clone guuid=47212127-1b00-0000-e3f5-e9aa730c0000 pid=3187 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=47212127-1b00-0000-e3f5-e9aa730c0000 pid=3187 execve guuid=72c88c27-1b00-0000-e3f5-e9aa740c0000 pid=3188 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=72c88c27-1b00-0000-e3f5-e9aa740c0000 pid=3188 execve guuid=45c23528-1b00-0000-e3f5-e9aa750c0000 pid=3189 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=45c23528-1b00-0000-e3f5-e9aa750c0000 pid=3189 execve guuid=0103202c-1b00-0000-e3f5-e9aa7b0c0000 pid=3195 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=0103202c-1b00-0000-e3f5-e9aa7b0c0000 pid=3195 execve guuid=acd35735-1b00-0000-e3f5-e9aa8e0c0000 pid=3214 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=acd35735-1b00-0000-e3f5-e9aa8e0c0000 pid=3214 execve guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215 /tmp/SupplySrvx64 net guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215 execve guuid=51e8ea35-1b00-0000-e3f5-e9aa940c0000 pid=3220 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=51e8ea35-1b00-0000-e3f5-e9aa940c0000 pid=3220 execve guuid=351b5436-1b00-0000-e3f5-e9aa980c0000 pid=3224 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=351b5436-1b00-0000-e3f5-e9aa980c0000 pid=3224 execve guuid=4df2ba36-1b00-0000-e3f5-e9aa990c0000 pid=3225 /usr/bin/wget net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=4df2ba36-1b00-0000-e3f5-e9aa990c0000 pid=3225 execve guuid=60ce1b3a-1b00-0000-e3f5-e9aa9b0c0000 pid=3227 /usr/bin/curl net send-data write-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=60ce1b3a-1b00-0000-e3f5-e9aa9b0c0000 pid=3227 execve guuid=708cf73d-1b00-0000-e3f5-e9aaa50c0000 pid=3237 /usr/bin/chmod guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=708cf73d-1b00-0000-e3f5-e9aaa50c0000 pid=3237 execve guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239 /tmp/SupplySrvx86 net guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239 execve guuid=c13b6f3e-1b00-0000-e3f5-e9aaab0c0000 pid=3243 /usr/bin/rm delete-file guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=c13b6f3e-1b00-0000-e3f5-e9aaab0c0000 pid=3243 execve guuid=1139c23e-1b00-0000-e3f5-e9aaae0c0000 pid=3246 /usr/bin/rm guuid=7bf3ea77-1a00-0000-e3f5-e9aa330b0000 pid=2867->guuid=1139c23e-1b00-0000-e3f5-e9aaae0c0000 pid=3246 execve 64887c32-c940-58cb-a82e-68c4f755e3f4 83.150.218.225:80 guuid=fe848778-1a00-0000-e3f5-e9aa350b0000 pid=2869->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=7623d87e-1a00-0000-e3f5-e9aa3e0b0000 pid=2878->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B guuid=bf29d0a7-1a00-0000-e3f5-e9aa5a0b0000 pid=2906->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=4cb025ac-1a00-0000-e3f5-e9aa630b0000 pid=2915->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=f5f895c6-1a00-0000-e3f5-e9aa800b0000 pid=2944->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=d66759c9-1a00-0000-e3f5-e9aa830b0000 pid=2947->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=a3249ad0-1a00-0000-e3f5-e9aa920b0000 pid=2962 /usr/bin/bash guuid=a21c77d0-1a00-0000-e3f5-e9aa910b0000 pid=2961->guuid=a3249ad0-1a00-0000-e3f5-e9aa920b0000 pid=2962 clone guuid=00ab8ad1-1a00-0000-e3f5-e9aa980b0000 pid=2968->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=e2884ed4-1a00-0000-e3f5-e9aa9e0b0000 pid=2974->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=e6a765d9-1a00-0000-e3f5-e9aaad0b0000 pid=2989 /usr/bin/bash guuid=a2750cd9-1a00-0000-e3f5-e9aaaa0b0000 pid=2986->guuid=e6a765d9-1a00-0000-e3f5-e9aaad0b0000 pid=2989 clone guuid=e4d920da-1a00-0000-e3f5-e9aab20b0000 pid=2994->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=12ca0bde-1a00-0000-e3f5-e9aac20b0000 pid=3010->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=b33c67e6-1a00-0000-e3f5-e9aae20b0000 pid=3042->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=e5b418ea-1a00-0000-e3f5-e9aaec0b0000 pid=3052->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=95947af4-1a00-0000-e3f5-e9aa060c0000 pid=3078->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 142B guuid=e8aa76f9-1a00-0000-e3f5-e9aa140c0000 pid=3092->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 91B guuid=8e2b5b02-1b00-0000-e3f5-e9aa2f0c0000 pid=3119->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=ec432206-1b00-0000-e3f5-e9aa3d0c0000 pid=3133->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B guuid=99efc30c-1b00-0000-e3f5-e9aa530c0000 pid=3155->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=b053c811-1b00-0000-e3f5-e9aa5c0c0000 pid=3164->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B guuid=93a2361a-1b00-0000-e3f5-e9aa6e0c0000 pid=3182->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=d7c92c1e-1b00-0000-e3f5-e9aa6f0c0000 pid=3183->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B guuid=45c23528-1b00-0000-e3f5-e9aa750c0000 pid=3189->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=0103202c-1b00-0000-e3f5-e9aa7b0c0000 pid=3195->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=14e5d635-1b00-0000-e3f5-e9aa910c0000 pid=3217 /tmp/SupplySrvx64 zombie guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215->guuid=14e5d635-1b00-0000-e3f5-e9aa910c0000 pid=3217 clone guuid=8422da35-1b00-0000-e3f5-e9aa920c0000 pid=3218 /tmp/SupplySrvx64 zombie guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215->guuid=8422da35-1b00-0000-e3f5-e9aa920c0000 pid=3218 clone guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219 /tmp/SupplySrvx64 dns net send-data zombie guuid=52b3bc35-1b00-0000-e3f5-e9aa8f0c0000 pid=3215->guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219 clone guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 39B c866238d-8c90-58a8-b672-c5945d484a39 sophos1997.camdvr.org:13471 guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219->c866238d-8c90-58a8-b672-c5945d484a39 send: 10B guuid=7f24ec35-1b00-0000-e3f5-e9aa950c0000 pid=3221 /tmp/SupplySrvx64 dns net send-data guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219->guuid=7f24ec35-1b00-0000-e3f5-e9aa950c0000 pid=3221 clone guuid=2d7bf035-1b00-0000-e3f5-e9aa960c0000 pid=3222 /tmp/SupplySrvx64 guuid=d929de35-1b00-0000-e3f5-e9aa930c0000 pid=3219->guuid=2d7bf035-1b00-0000-e3f5-e9aa960c0000 pid=3222 clone guuid=7f24ec35-1b00-0000-e3f5-e9aa950c0000 pid=3221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 39B guuid=7f24ec35-1b00-0000-e3f5-e9aa950c0000 pid=3221->c866238d-8c90-58a8-b672-c5945d484a39 send: 8B guuid=e619bac6-2600-0000-e3f5-e9aab0140000 pid=5296 /tmp/SupplySrvx64 guuid=7f24ec35-1b00-0000-e3f5-e9aa950c0000 pid=3221->guuid=e619bac6-2600-0000-e3f5-e9aab0140000 pid=5296 clone guuid=4df2ba36-1b00-0000-e3f5-e9aa990c0000 pid=3225->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 141B guuid=60ce1b3a-1b00-0000-e3f5-e9aa9b0c0000 pid=3227->64887c32-c940-58cb-a82e-68c4f755e3f4 send: 90B guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=abe35a3e-1b00-0000-e3f5-e9aaa80c0000 pid=3240 /tmp/SupplySrvx86 zombie guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239->guuid=abe35a3e-1b00-0000-e3f5-e9aaa80c0000 pid=3240 clone guuid=efbd5f3e-1b00-0000-e3f5-e9aaa90c0000 pid=3241 /tmp/SupplySrvx86 guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239->guuid=efbd5f3e-1b00-0000-e3f5-e9aaa90c0000 pid=3241 clone guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242 /tmp/SupplySrvx86 dns net send-data zombie guuid=c6223f3e-1b00-0000-e3f5-e9aaa70c0000 pid=3239->guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242 clone guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 78B guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242->c866238d-8c90-58a8-b672-c5945d484a39 send: 18B guuid=b125863e-1b00-0000-e3f5-e9aaac0c0000 pid=3244 /tmp/SupplySrvx86 guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242->guuid=b125863e-1b00-0000-e3f5-e9aaac0c0000 pid=3244 clone guuid=03e48c3e-1b00-0000-e3f5-e9aaad0c0000 pid=3245 /tmp/SupplySrvx86 guuid=47fc623e-1b00-0000-e3f5-e9aaaa0c0000 pid=3242->guuid=03e48c3e-1b00-0000-e3f5-e9aaad0c0000 pid=3245 clone
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-11-21 22:41:23 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:owari antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
Modifies Watchdog functionality
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
sophos1997.camdvr.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts
Rule name:UNK_install_script
Author:evilcel3ri
Description:Detects a suspicious behaviour in an bash installation script

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5f6d315261a928c32802d53c6ca693c57affda17939b3a7290ed5d8ea9138f4a

(this sample)

  
Delivery method
Distributed via web download

Comments