MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 66b59213ba9d602854fbd06c1c880ffc51a55c0f364998b8818035ac71a43d15. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 66b59213ba9d602854fbd06c1c880ffc51a55c0f364998b8818035ac71a43d15
SHA3-384 hash: aa8e2eaf7e33ff14578c44fd2a8979555aa34c21f383051679f163540e7e18cb5158775188fb8379a28361ad109f4043
SHA1 hash: d4377578513869a6301a9d5be13428d1dafaad74
MD5 hash: e744374396021cec1dbde77fc418c62e
humanhash: eleven-lactose-wisconsin-ink
File name:zyxel
Download: download sample
File size:2'425 bytes
First seen:2025-07-10 13:01:56 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSLrx0xX9+rxuwxujfrxZxaTrxyxlyrxbx0lrx8xfgrxGxpirxdxuvrxnxA5:vlTSLliX9+lb6fl7aTlQlylV0llKfglh
TLSH T14041A1F51144473CACF2996E71E78988B6E296C620C39FC4D5FC39E6404DE483DA2E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=7e1a046c-1a00-0000-5052-3f72030c0000 pid=3075 /usr/bin/sudo guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082 /tmp/sample.bin guuid=7e1a046c-1a00-0000-5052-3f72030c0000 pid=3075->guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082 execve guuid=bdebfe6e-1a00-0000-5052-3f720c0c0000 pid=3084 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=bdebfe6e-1a00-0000-5052-3f720c0c0000 pid=3084 execve guuid=d7bb7973-1a00-0000-5052-3f72160c0000 pid=3094 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=d7bb7973-1a00-0000-5052-3f72160c0000 pid=3094 execve guuid=a8f2747d-1a00-0000-5052-3f722c0c0000 pid=3116 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=a8f2747d-1a00-0000-5052-3f722c0c0000 pid=3116 execve guuid=2ec5e37d-1a00-0000-5052-3f722e0c0000 pid=3118 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=2ec5e37d-1a00-0000-5052-3f722e0c0000 pid=3118 execve guuid=e1f3647e-1a00-0000-5052-3f72300c0000 pid=3120 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=e1f3647e-1a00-0000-5052-3f72300c0000 pid=3120 clone guuid=a9149a7e-1a00-0000-5052-3f72310c0000 pid=3121 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=a9149a7e-1a00-0000-5052-3f72310c0000 pid=3121 execve guuid=863c9680-1a00-0000-5052-3f72380c0000 pid=3128 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=863c9680-1a00-0000-5052-3f72380c0000 pid=3128 execve guuid=abcae685-1a00-0000-5052-3f72460c0000 pid=3142 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=abcae685-1a00-0000-5052-3f72460c0000 pid=3142 execve guuid=3bff3386-1a00-0000-5052-3f72480c0000 pid=3144 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=3bff3386-1a00-0000-5052-3f72480c0000 pid=3144 execve guuid=71137586-1a00-0000-5052-3f724a0c0000 pid=3146 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=71137586-1a00-0000-5052-3f724a0c0000 pid=3146 clone guuid=df579986-1a00-0000-5052-3f724c0c0000 pid=3148 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=df579986-1a00-0000-5052-3f724c0c0000 pid=3148 execve guuid=a4f52e88-1a00-0000-5052-3f72540c0000 pid=3156 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=a4f52e88-1a00-0000-5052-3f72540c0000 pid=3156 execve guuid=25c8d28b-1a00-0000-5052-3f725b0c0000 pid=3163 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=25c8d28b-1a00-0000-5052-3f725b0c0000 pid=3163 execve guuid=1d21268c-1a00-0000-5052-3f725d0c0000 pid=3165 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=1d21268c-1a00-0000-5052-3f725d0c0000 pid=3165 execve guuid=768e768c-1a00-0000-5052-3f725f0c0000 pid=3167 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=768e768c-1a00-0000-5052-3f725f0c0000 pid=3167 clone guuid=310da88c-1a00-0000-5052-3f72600c0000 pid=3168 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=310da88c-1a00-0000-5052-3f72600c0000 pid=3168 execve guuid=adfd758e-1a00-0000-5052-3f72650c0000 pid=3173 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=adfd758e-1a00-0000-5052-3f72650c0000 pid=3173 execve guuid=9f402491-1a00-0000-5052-3f726c0c0000 pid=3180 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=9f402491-1a00-0000-5052-3f726c0c0000 pid=3180 execve guuid=93718091-1a00-0000-5052-3f726d0c0000 pid=3181 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=93718091-1a00-0000-5052-3f726d0c0000 pid=3181 execve guuid=4ba8e191-1a00-0000-5052-3f726e0c0000 pid=3182 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=4ba8e191-1a00-0000-5052-3f726e0c0000 pid=3182 clone guuid=eea50b92-1a00-0000-5052-3f726f0c0000 pid=3183 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=eea50b92-1a00-0000-5052-3f726f0c0000 pid=3183 execve guuid=2bb2e793-1a00-0000-5052-3f72760c0000 pid=3190 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=2bb2e793-1a00-0000-5052-3f72760c0000 pid=3190 execve guuid=e6e13397-1a00-0000-5052-3f727e0c0000 pid=3198 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=e6e13397-1a00-0000-5052-3f727e0c0000 pid=3198 execve guuid=51b68997-1a00-0000-5052-3f727f0c0000 pid=3199 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=51b68997-1a00-0000-5052-3f727f0c0000 pid=3199 execve guuid=f47bf497-1a00-0000-5052-3f72800c0000 pid=3200 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=f47bf497-1a00-0000-5052-3f72800c0000 pid=3200 clone guuid=1fcc3598-1a00-0000-5052-3f72810c0000 pid=3201 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=1fcc3598-1a00-0000-5052-3f72810c0000 pid=3201 execve guuid=2082729a-1a00-0000-5052-3f72820c0000 pid=3202 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=2082729a-1a00-0000-5052-3f72820c0000 pid=3202 execve guuid=0e38b39e-1a00-0000-5052-3f72830c0000 pid=3203 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=0e38b39e-1a00-0000-5052-3f72830c0000 pid=3203 execve guuid=38a5789f-1a00-0000-5052-3f72840c0000 pid=3204 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=38a5789f-1a00-0000-5052-3f72840c0000 pid=3204 execve guuid=991b34a0-1a00-0000-5052-3f72850c0000 pid=3205 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=991b34a0-1a00-0000-5052-3f72850c0000 pid=3205 clone guuid=d6588ea0-1a00-0000-5052-3f72860c0000 pid=3206 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=d6588ea0-1a00-0000-5052-3f72860c0000 pid=3206 execve guuid=426f68a3-1a00-0000-5052-3f72870c0000 pid=3207 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=426f68a3-1a00-0000-5052-3f72870c0000 pid=3207 execve guuid=f27795a6-1a00-0000-5052-3f72880c0000 pid=3208 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=f27795a6-1a00-0000-5052-3f72880c0000 pid=3208 execve guuid=dc4e18a7-1a00-0000-5052-3f72890c0000 pid=3209 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=dc4e18a7-1a00-0000-5052-3f72890c0000 pid=3209 execve guuid=281a7ba7-1a00-0000-5052-3f728a0c0000 pid=3210 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=281a7ba7-1a00-0000-5052-3f728a0c0000 pid=3210 clone guuid=ba8cc2a7-1a00-0000-5052-3f728b0c0000 pid=3211 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=ba8cc2a7-1a00-0000-5052-3f728b0c0000 pid=3211 execve guuid=29e590a9-1a00-0000-5052-3f728d0c0000 pid=3213 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=29e590a9-1a00-0000-5052-3f728d0c0000 pid=3213 execve guuid=59ad6eac-1a00-0000-5052-3f72980c0000 pid=3224 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=59ad6eac-1a00-0000-5052-3f72980c0000 pid=3224 execve guuid=6febc1ac-1a00-0000-5052-3f729a0c0000 pid=3226 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=6febc1ac-1a00-0000-5052-3f729a0c0000 pid=3226 execve guuid=862422ad-1a00-0000-5052-3f729c0c0000 pid=3228 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=862422ad-1a00-0000-5052-3f729c0c0000 pid=3228 clone guuid=729aadad-1a00-0000-5052-3f729e0c0000 pid=3230 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=729aadad-1a00-0000-5052-3f729e0c0000 pid=3230 execve guuid=6047d0af-1a00-0000-5052-3f72a30c0000 pid=3235 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=6047d0af-1a00-0000-5052-3f72a30c0000 pid=3235 execve guuid=da3c66b2-1a00-0000-5052-3f72ab0c0000 pid=3243 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=da3c66b2-1a00-0000-5052-3f72ab0c0000 pid=3243 execve guuid=0bcfb5b2-1a00-0000-5052-3f72ac0c0000 pid=3244 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=0bcfb5b2-1a00-0000-5052-3f72ac0c0000 pid=3244 execve guuid=cceb23b3-1a00-0000-5052-3f72ae0c0000 pid=3246 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=cceb23b3-1a00-0000-5052-3f72ae0c0000 pid=3246 clone guuid=f5a359b3-1a00-0000-5052-3f72af0c0000 pid=3247 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=f5a359b3-1a00-0000-5052-3f72af0c0000 pid=3247 execve guuid=593c3db5-1a00-0000-5052-3f72b30c0000 pid=3251 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=593c3db5-1a00-0000-5052-3f72b30c0000 pid=3251 execve guuid=d2e9afb8-1a00-0000-5052-3f72bb0c0000 pid=3259 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=d2e9afb8-1a00-0000-5052-3f72bb0c0000 pid=3259 execve guuid=63f921b9-1a00-0000-5052-3f72bc0c0000 pid=3260 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=63f921b9-1a00-0000-5052-3f72bc0c0000 pid=3260 execve guuid=a91391b9-1a00-0000-5052-3f72bd0c0000 pid=3261 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=a91391b9-1a00-0000-5052-3f72bd0c0000 pid=3261 clone guuid=c737d3b9-1a00-0000-5052-3f72be0c0000 pid=3262 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=c737d3b9-1a00-0000-5052-3f72be0c0000 pid=3262 execve guuid=fba67cbc-1a00-0000-5052-3f72bf0c0000 pid=3263 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=fba67cbc-1a00-0000-5052-3f72bf0c0000 pid=3263 execve guuid=1e37f1c0-1a00-0000-5052-3f72c00c0000 pid=3264 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=1e37f1c0-1a00-0000-5052-3f72c00c0000 pid=3264 execve guuid=017d66c1-1a00-0000-5052-3f72c10c0000 pid=3265 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=017d66c1-1a00-0000-5052-3f72c10c0000 pid=3265 execve guuid=6b1dcdc1-1a00-0000-5052-3f72c20c0000 pid=3266 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=6b1dcdc1-1a00-0000-5052-3f72c20c0000 pid=3266 clone guuid=cd7a03c2-1a00-0000-5052-3f72c30c0000 pid=3267 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=cd7a03c2-1a00-0000-5052-3f72c30c0000 pid=3267 execve guuid=d52c24c4-1a00-0000-5052-3f72c40c0000 pid=3268 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=d52c24c4-1a00-0000-5052-3f72c40c0000 pid=3268 execve guuid=f6d256cb-1a00-0000-5052-3f72c50c0000 pid=3269 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=f6d256cb-1a00-0000-5052-3f72c50c0000 pid=3269 execve guuid=d085f2cb-1a00-0000-5052-3f72c70c0000 pid=3271 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=d085f2cb-1a00-0000-5052-3f72c70c0000 pid=3271 execve guuid=15a15acc-1a00-0000-5052-3f72c80c0000 pid=3272 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=15a15acc-1a00-0000-5052-3f72c80c0000 pid=3272 clone guuid=f74b81cc-1a00-0000-5052-3f72ca0c0000 pid=3274 /usr/bin/wget net send-data guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=f74b81cc-1a00-0000-5052-3f72ca0c0000 pid=3274 execve guuid=88964cce-1a00-0000-5052-3f72d10c0000 pid=3281 /usr/bin/curl net send-data write-file guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=88964cce-1a00-0000-5052-3f72d10c0000 pid=3281 execve guuid=19eca8d1-1a00-0000-5052-3f72d90c0000 pid=3289 /usr/bin/cat guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=19eca8d1-1a00-0000-5052-3f72d90c0000 pid=3289 execve guuid=640105d2-1a00-0000-5052-3f72da0c0000 pid=3290 /usr/bin/chmod guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=640105d2-1a00-0000-5052-3f72da0c0000 pid=3290 execve guuid=2b5757d2-1a00-0000-5052-3f72db0c0000 pid=3291 /usr/bin/bash guuid=8173816e-1a00-0000-5052-3f720a0c0000 pid=3082->guuid=2b5757d2-1a00-0000-5052-3f72db0c0000 pid=3291 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=bdebfe6e-1a00-0000-5052-3f720c0c0000 pid=3084->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=d7bb7973-1a00-0000-5052-3f72160c0000 pid=3094->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=a9149a7e-1a00-0000-5052-3f72310c0000 pid=3121->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=863c9680-1a00-0000-5052-3f72380c0000 pid=3128->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=df579986-1a00-0000-5052-3f724c0c0000 pid=3148->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=a4f52e88-1a00-0000-5052-3f72540c0000 pid=3156->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=310da88c-1a00-0000-5052-3f72600c0000 pid=3168->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=adfd758e-1a00-0000-5052-3f72650c0000 pid=3173->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=eea50b92-1a00-0000-5052-3f726f0c0000 pid=3183->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=2bb2e793-1a00-0000-5052-3f72760c0000 pid=3190->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=1fcc3598-1a00-0000-5052-3f72810c0000 pid=3201->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=2082729a-1a00-0000-5052-3f72820c0000 pid=3202->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=d6588ea0-1a00-0000-5052-3f72860c0000 pid=3206->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=426f68a3-1a00-0000-5052-3f72870c0000 pid=3207->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=ba8cc2a7-1a00-0000-5052-3f728b0c0000 pid=3211->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=29e590a9-1a00-0000-5052-3f728d0c0000 pid=3213->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=729aadad-1a00-0000-5052-3f729e0c0000 pid=3230->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=6047d0af-1a00-0000-5052-3f72a30c0000 pid=3235->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=f5a359b3-1a00-0000-5052-3f72af0c0000 pid=3247->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=593c3db5-1a00-0000-5052-3f72b30c0000 pid=3251->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=c737d3b9-1a00-0000-5052-3f72be0c0000 pid=3262->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=fba67cbc-1a00-0000-5052-3f72bf0c0000 pid=3263->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=cd7a03c2-1a00-0000-5052-3f72c30c0000 pid=3267->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=d52c24c4-1a00-0000-5052-3f72c40c0000 pid=3268->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=f74b81cc-1a00-0000-5052-3f72ca0c0000 pid=3274->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=88964cce-1a00-0000-5052-3f72d10c0000 pid=3281->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:02:18 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 66b59213ba9d602854fbd06c1c880ffc51a55c0f364998b8818035ac71a43d15

(this sample)

  
Delivery method
Distributed via web download

Comments