MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 65dc6be4f2ff455fa54a298b1be92b12d5371e0173fecee46767762611df3b41. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 65dc6be4f2ff455fa54a298b1be92b12d5371e0173fecee46767762611df3b41
SHA3-384 hash: 88d5214c0d65c60bf97c7e25c7a0b02e2fe24522ce6ab00498ed1341f3a6e64d5c4bdf7a45d8728ad49b41b2bf2c3a2b
SHA1 hash: 0eea9cc39d163b5759c0a0727a1f7085fed1bcd0
MD5 hash: 7c4b34f275d95c0e8e17b063e37fe6fe
humanhash: carolina-massachusetts-harry-two
File name:jaws
Download: download sample
Signature Mirai
File size:2'821 bytes
First seen:2025-10-14 20:14:51 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vTSYSqSESOSNkzESJSqSjSESSSLRUfSZSGl:vTSYSqSESOSmESJSqSjSESSSLRUfSZSm
TLSH T1A45161C4726607707FE25DB27DF540ACB2C5E2D1B6C58E99D4ECA8BC818DF1814A06B3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://64.91.237.162/bins/sora.x869209da6b229bc24256cf26833723fc3a7c89272a5af754861c095d350b99de10 Miraimirai opendir
http://64.91.237.162/bins/sora.mips29c7491b527a0e18a776b8cc1831a8ba4b97d917fd76d047c96cc5ae21a79924 Miraimirai opendir
http://64.91.237.162/bins/sora.x86_647e8a271658bd0f9be6bf33a2ea92ce4fad4774aafac33c5b2caedf6417fd15ac Miraimirai opendir
http://64.91.237.162/bins/sora.i468n/an/aelf ua-wget
http://64.91.237.162/bins/sora.i68692575fbaacd79518241425e42a4cdacbf65def900864a48fc0b27504f78cbff4 Miraimirai opendir
http://64.91.237.162/bins/sora.mpsla3b52b958c8ea783c24f7a02fb57b5228fc1969791021519b42e14e58124e30d Miraimirai opendir
http://64.91.237.162/bins/sora.arm4n/an/aelf ua-wget
http://64.91.237.162/bins/sora.arm56357efa12b55a6c1f2d555f6dbbe40a0ed2d5c1e2dced815347fa98881eeefcb Miraimirai opendir
http://64.91.237.162/bins/sora.arm6579e9db35f7d3e276a6fd3b2bb98091a12c58d4cb0cd0ed3ae3cdbfd19304b0a Miraimirai opendir
http://64.91.237.162/bins/sora.arm7a2a3eda8d88cb807ffc26480a5a40cf79ac74b135b8aadaa225fed856da77cef Miraimirai opendir
http://64.91.237.162/bins/sora.ppc773298e6d3a314ffe9554eeea412ac65fbb16cf4030acf0e2553c42a1f159bb2 Miraimirai opendir
http://64.91.237.162/bins/sora.ppc440fpn/an/aelf ua-wget
http://64.91.237.162/bins/sora.m68ka25e8659220a59deaae914fc945fa6b31667bc0c7146a968bec1c4be9ffee9ed Miraimirai opendir
http://64.91.237.162/bins/sora.sh40dd50416937f0bbb202464b09fb982739b34bde7d11834b78a137fc4659502de Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-14T17:40:00Z UTC
Last seen:
2025-10-14T19:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=a5a99ed9-1900-0000-fb93-7ea770090000 pid=2416 /usr/bin/sudo guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424 /tmp/sample.bin guuid=a5a99ed9-1900-0000-fb93-7ea770090000 pid=2416->guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424 execve guuid=58e578dc-1900-0000-fb93-7ea779090000 pid=2425 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=58e578dc-1900-0000-fb93-7ea779090000 pid=2425 execve guuid=b3c99ff4-1900-0000-fb93-7ea7af090000 pid=2479 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=b3c99ff4-1900-0000-fb93-7ea7af090000 pid=2479 execve guuid=7117260e-1a00-0000-fb93-7ea7ea090000 pid=2538 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=7117260e-1a00-0000-fb93-7ea7ea090000 pid=2538 execve guuid=27438b0e-1a00-0000-fb93-7ea7eb090000 pid=2539 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=27438b0e-1a00-0000-fb93-7ea7eb090000 pid=2539 execve guuid=90ebf20e-1a00-0000-fb93-7ea7ec090000 pid=2540 /tmp/robben net guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=90ebf20e-1a00-0000-fb93-7ea7ec090000 pid=2540 execve guuid=3a21d311-1a00-0000-fb93-7ea7f3090000 pid=2547 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=3a21d311-1a00-0000-fb93-7ea7f3090000 pid=2547 execve guuid=4ecd5528-1a00-0000-fb93-7ea7320a0000 pid=2610 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=4ecd5528-1a00-0000-fb93-7ea7320a0000 pid=2610 execve guuid=33861041-1a00-0000-fb93-7ea7720a0000 pid=2674 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=33861041-1a00-0000-fb93-7ea7720a0000 pid=2674 execve guuid=3d185d41-1a00-0000-fb93-7ea7740a0000 pid=2676 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=3d185d41-1a00-0000-fb93-7ea7740a0000 pid=2676 execve guuid=127da841-1a00-0000-fb93-7ea7760a0000 pid=2678 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=127da841-1a00-0000-fb93-7ea7760a0000 pid=2678 clone guuid=4db15242-1a00-0000-fb93-7ea77a0a0000 pid=2682 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=4db15242-1a00-0000-fb93-7ea77a0a0000 pid=2682 execve guuid=5b5e9657-1a00-0000-fb93-7ea7ba0a0000 pid=2746 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=5b5e9657-1a00-0000-fb93-7ea7ba0a0000 pid=2746 execve guuid=ab0e7a6e-1a00-0000-fb93-7ea7e70a0000 pid=2791 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=ab0e7a6e-1a00-0000-fb93-7ea7e70a0000 pid=2791 execve guuid=a5fa036f-1a00-0000-fb93-7ea7e80a0000 pid=2792 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=a5fa036f-1a00-0000-fb93-7ea7e80a0000 pid=2792 execve guuid=05ac886f-1a00-0000-fb93-7ea7e90a0000 pid=2793 /tmp/robben mprotect-exec net guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=05ac886f-1a00-0000-fb93-7ea7e90a0000 pid=2793 execve guuid=93f4bb73-1a00-0000-fb93-7ea7f40a0000 pid=2804 /usr/bin/wget net send-data guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=93f4bb73-1a00-0000-fb93-7ea7f40a0000 pid=2804 execve guuid=b0cf7082-1a00-0000-fb93-7ea7060b0000 pid=2822 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=b0cf7082-1a00-0000-fb93-7ea7060b0000 pid=2822 execve guuid=8f73a392-1a00-0000-fb93-7ea72a0b0000 pid=2858 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=8f73a392-1a00-0000-fb93-7ea72a0b0000 pid=2858 execve guuid=1b3c1f93-1a00-0000-fb93-7ea72b0b0000 pid=2859 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=1b3c1f93-1a00-0000-fb93-7ea72b0b0000 pid=2859 execve guuid=60b48d93-1a00-0000-fb93-7ea72c0b0000 pid=2860 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=60b48d93-1a00-0000-fb93-7ea72c0b0000 pid=2860 clone guuid=2c5cc393-1a00-0000-fb93-7ea72e0b0000 pid=2862 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=2c5cc393-1a00-0000-fb93-7ea72e0b0000 pid=2862 execve guuid=921f6ca9-1a00-0000-fb93-7ea7660b0000 pid=2918 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=921f6ca9-1a00-0000-fb93-7ea7660b0000 pid=2918 execve guuid=0d55b6c5-1a00-0000-fb93-7ea7910b0000 pid=2961 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=0d55b6c5-1a00-0000-fb93-7ea7910b0000 pid=2961 execve guuid=f21125c6-1a00-0000-fb93-7ea7920b0000 pid=2962 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=f21125c6-1a00-0000-fb93-7ea7920b0000 pid=2962 execve guuid=716582c6-1a00-0000-fb93-7ea7930b0000 pid=2963 /tmp/robben net guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=716582c6-1a00-0000-fb93-7ea7930b0000 pid=2963 execve guuid=5c054dc9-1a00-0000-fb93-7ea79c0b0000 pid=2972 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=5c054dc9-1a00-0000-fb93-7ea79c0b0000 pid=2972 execve guuid=7948c2df-1a00-0000-fb93-7ea7c00b0000 pid=3008 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=7948c2df-1a00-0000-fb93-7ea7c00b0000 pid=3008 execve guuid=97b88ef6-1a00-0000-fb93-7ea7f60b0000 pid=3062 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=97b88ef6-1a00-0000-fb93-7ea7f60b0000 pid=3062 execve guuid=02de12f7-1a00-0000-fb93-7ea7f90b0000 pid=3065 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=02de12f7-1a00-0000-fb93-7ea7f90b0000 pid=3065 execve guuid=dfcb86f7-1a00-0000-fb93-7ea7fb0b0000 pid=3067 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=dfcb86f7-1a00-0000-fb93-7ea7fb0b0000 pid=3067 clone guuid=b11572f8-1a00-0000-fb93-7ea7000c0000 pid=3072 /usr/bin/wget net send-data guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=b11572f8-1a00-0000-fb93-7ea7000c0000 pid=3072 execve guuid=72597f07-1b00-0000-fb93-7ea72f0c0000 pid=3119 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=72597f07-1b00-0000-fb93-7ea72f0c0000 pid=3119 execve guuid=73a0b217-1b00-0000-fb93-7ea75b0c0000 pid=3163 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=73a0b217-1b00-0000-fb93-7ea75b0c0000 pid=3163 execve guuid=9af91a18-1b00-0000-fb93-7ea75d0c0000 pid=3165 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=9af91a18-1b00-0000-fb93-7ea75d0c0000 pid=3165 execve guuid=8ca26618-1b00-0000-fb93-7ea75f0c0000 pid=3167 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=8ca26618-1b00-0000-fb93-7ea75f0c0000 pid=3167 clone guuid=865a9318-1b00-0000-fb93-7ea7600c0000 pid=3168 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=865a9318-1b00-0000-fb93-7ea7600c0000 pid=3168 execve guuid=4378242e-1b00-0000-fb93-7ea78c0c0000 pid=3212 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=4378242e-1b00-0000-fb93-7ea78c0c0000 pid=3212 execve guuid=fada6848-1b00-0000-fb93-7ea7a30c0000 pid=3235 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=fada6848-1b00-0000-fb93-7ea7a30c0000 pid=3235 execve guuid=edeeeb48-1b00-0000-fb93-7ea7a50c0000 pid=3237 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=edeeeb48-1b00-0000-fb93-7ea7a50c0000 pid=3237 execve guuid=0a4a5449-1b00-0000-fb93-7ea7a70c0000 pid=3239 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=0a4a5449-1b00-0000-fb93-7ea7a70c0000 pid=3239 clone guuid=3d76f349-1b00-0000-fb93-7ea7aa0c0000 pid=3242 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=3d76f349-1b00-0000-fb93-7ea7aa0c0000 pid=3242 execve guuid=2ac6cb5e-1b00-0000-fb93-7ea7bd0c0000 pid=3261 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=2ac6cb5e-1b00-0000-fb93-7ea7bd0c0000 pid=3261 execve guuid=9e434a75-1b00-0000-fb93-7ea7d50c0000 pid=3285 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=9e434a75-1b00-0000-fb93-7ea7d50c0000 pid=3285 execve guuid=99c6be78-1b00-0000-fb93-7ea7db0c0000 pid=3291 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=99c6be78-1b00-0000-fb93-7ea7db0c0000 pid=3291 execve guuid=2cb93379-1b00-0000-fb93-7ea7dc0c0000 pid=3292 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=2cb93379-1b00-0000-fb93-7ea7dc0c0000 pid=3292 clone guuid=2d731a7a-1b00-0000-fb93-7ea7de0c0000 pid=3294 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=2d731a7a-1b00-0000-fb93-7ea7de0c0000 pid=3294 execve guuid=9d572e96-1b00-0000-fb93-7ea7080d0000 pid=3336 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=9d572e96-1b00-0000-fb93-7ea7080d0000 pid=3336 execve guuid=a1794fb4-1b00-0000-fb93-7ea73a0d0000 pid=3386 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=a1794fb4-1b00-0000-fb93-7ea73a0d0000 pid=3386 execve guuid=9074adb4-1b00-0000-fb93-7ea73b0d0000 pid=3387 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=9074adb4-1b00-0000-fb93-7ea73b0d0000 pid=3387 execve guuid=aa5921b5-1b00-0000-fb93-7ea73d0d0000 pid=3389 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=aa5921b5-1b00-0000-fb93-7ea73d0d0000 pid=3389 clone guuid=9560e3b5-1b00-0000-fb93-7ea7410d0000 pid=3393 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=9560e3b5-1b00-0000-fb93-7ea7410d0000 pid=3393 execve guuid=0bd330cb-1b00-0000-fb93-7ea7700d0000 pid=3440 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=0bd330cb-1b00-0000-fb93-7ea7700d0000 pid=3440 execve guuid=fb03b8e5-1b00-0000-fb93-7ea7a40d0000 pid=3492 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=fb03b8e5-1b00-0000-fb93-7ea7a40d0000 pid=3492 execve guuid=23c926e6-1b00-0000-fb93-7ea7a70d0000 pid=3495 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=23c926e6-1b00-0000-fb93-7ea7a70d0000 pid=3495 execve guuid=4b377de6-1b00-0000-fb93-7ea7a90d0000 pid=3497 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=4b377de6-1b00-0000-fb93-7ea7a90d0000 pid=3497 clone guuid=6f25d2e7-1b00-0000-fb93-7ea7ae0d0000 pid=3502 /usr/bin/wget net send-data guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=6f25d2e7-1b00-0000-fb93-7ea7ae0d0000 pid=3502 execve guuid=8f65aef6-1b00-0000-fb93-7ea7d00d0000 pid=3536 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=8f65aef6-1b00-0000-fb93-7ea7d00d0000 pid=3536 execve guuid=c0b86406-1c00-0000-fb93-7ea7ec0d0000 pid=3564 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=c0b86406-1c00-0000-fb93-7ea7ec0d0000 pid=3564 execve guuid=7faab706-1c00-0000-fb93-7ea7ee0d0000 pid=3566 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=7faab706-1c00-0000-fb93-7ea7ee0d0000 pid=3566 execve guuid=c07d0907-1c00-0000-fb93-7ea7f00d0000 pid=3568 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=c07d0907-1c00-0000-fb93-7ea7f00d0000 pid=3568 clone guuid=54843a07-1c00-0000-fb93-7ea7f20d0000 pid=3570 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=54843a07-1c00-0000-fb93-7ea7f20d0000 pid=3570 execve guuid=94198623-1c00-0000-fb93-7ea7370e0000 pid=3639 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=94198623-1c00-0000-fb93-7ea7370e0000 pid=3639 execve guuid=f27b5040-1c00-0000-fb93-7ea77d0e0000 pid=3709 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=f27b5040-1c00-0000-fb93-7ea77d0e0000 pid=3709 execve guuid=a247d940-1c00-0000-fb93-7ea77f0e0000 pid=3711 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=a247d940-1c00-0000-fb93-7ea77f0e0000 pid=3711 execve guuid=7f7f4e41-1c00-0000-fb93-7ea7810e0000 pid=3713 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=7f7f4e41-1c00-0000-fb93-7ea7810e0000 pid=3713 clone guuid=c06c1142-1c00-0000-fb93-7ea7840e0000 pid=3716 /usr/bin/wget net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=c06c1142-1c00-0000-fb93-7ea7840e0000 pid=3716 execve guuid=e9f9405e-1c00-0000-fb93-7ea7d90e0000 pid=3801 /usr/bin/curl net send-data write-file guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=e9f9405e-1c00-0000-fb93-7ea7d90e0000 pid=3801 execve guuid=056ef47e-1c00-0000-fb93-7ea7400f0000 pid=3904 /usr/bin/cat guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=056ef47e-1c00-0000-fb93-7ea7400f0000 pid=3904 execve guuid=f108597f-1c00-0000-fb93-7ea7420f0000 pid=3906 /usr/bin/chmod guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=f108597f-1c00-0000-fb93-7ea7420f0000 pid=3906 execve guuid=d9b7dd7f-1c00-0000-fb93-7ea7430f0000 pid=3907 /usr/bin/bash guuid=69c0d5db-1900-0000-fb93-7ea778090000 pid=2424->guuid=d9b7dd7f-1c00-0000-fb93-7ea7430f0000 pid=3907 clone 10651e68-131f-5e6d-a670-1d19a7120e88 64.91.237.162:80 guuid=58e578dc-1900-0000-fb93-7ea779090000 pid=2425->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=b3c99ff4-1900-0000-fb93-7ea7af090000 pid=2479->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=90ebf20e-1a00-0000-fb93-7ea7ec090000 pid=2540->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3a21d311-1a00-0000-fb93-7ea7f3090000 pid=2547->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=4ecd5528-1a00-0000-fb93-7ea7320a0000 pid=2610->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=4db15242-1a00-0000-fb93-7ea77a0a0000 pid=2682->10651e68-131f-5e6d-a670-1d19a7120e88 send: 144B guuid=5b5e9657-1a00-0000-fb93-7ea7ba0a0000 pid=2746->10651e68-131f-5e6d-a670-1d19a7120e88 send: 93B guuid=05ac886f-1a00-0000-fb93-7ea7e90a0000 pid=2793->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=93f4bb73-1a00-0000-fb93-7ea7f40a0000 pid=2804->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=b0cf7082-1a00-0000-fb93-7ea7060b0000 pid=2822->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=2c5cc393-1a00-0000-fb93-7ea72e0b0000 pid=2862->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=921f6ca9-1a00-0000-fb93-7ea7660b0000 pid=2918->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=716582c6-1a00-0000-fb93-7ea7930b0000 pid=2963->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5c054dc9-1a00-0000-fb93-7ea79c0b0000 pid=2972->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=7948c2df-1a00-0000-fb93-7ea7c00b0000 pid=3008->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=b11572f8-1a00-0000-fb93-7ea7000c0000 pid=3072->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=72597f07-1b00-0000-fb93-7ea72f0c0000 pid=3119->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=865a9318-1b00-0000-fb93-7ea7600c0000 pid=3168->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=4378242e-1b00-0000-fb93-7ea78c0c0000 pid=3212->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=3d76f349-1b00-0000-fb93-7ea7aa0c0000 pid=3242->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=2ac6cb5e-1b00-0000-fb93-7ea7bd0c0000 pid=3261->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=2d731a7a-1b00-0000-fb93-7ea7de0c0000 pid=3294->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=9d572e96-1b00-0000-fb93-7ea7080d0000 pid=3336->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=9560e3b5-1b00-0000-fb93-7ea7410d0000 pid=3393->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=0bd330cb-1b00-0000-fb93-7ea7700d0000 pid=3440->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B guuid=6f25d2e7-1b00-0000-fb93-7ea7ae0d0000 pid=3502->10651e68-131f-5e6d-a670-1d19a7120e88 send: 146B guuid=8f65aef6-1b00-0000-fb93-7ea7d00d0000 pid=3536->10651e68-131f-5e6d-a670-1d19a7120e88 send: 95B guuid=54843a07-1c00-0000-fb93-7ea7f20d0000 pid=3570->10651e68-131f-5e6d-a670-1d19a7120e88 send: 142B guuid=94198623-1c00-0000-fb93-7ea7370e0000 pid=3639->10651e68-131f-5e6d-a670-1d19a7120e88 send: 91B guuid=c06c1142-1c00-0000-fb93-7ea7840e0000 pid=3716->10651e68-131f-5e6d-a670-1d19a7120e88 send: 141B guuid=e9f9405e-1c00-0000-fb93-7ea7d90e0000 pid=3801->10651e68-131f-5e6d-a670-1d19a7120e88 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-14 20:16:45 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (45956) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 65dc6be4f2ff455fa54a298b1be92b12d5371e0173fecee46767762611df3b41

(this sample)

  
Delivery method
Distributed via web download

Comments