MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7709d54a50df45500a97ca2818e8e85ffbac82f8289a1bfadf972bde5797a657. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7709d54a50df45500a97ca2818e8e85ffbac82f8289a1bfadf972bde5797a657
SHA3-384 hash: 873abbc2f10479c8097431404ca86012a18ec38c14f0909693def4e5f57e1d8e8520b8d8859e1d8e561f2df6b198782e
SHA1 hash: 8616d7c56e3f7d332cfe850551b15dd9f1fc8a32
MD5 hash: e281a1e329ac4f6171dec9e5f3204ed7
humanhash: lithium-east-low-mirror
File name:pay
Download: download sample
Signature Mirai
File size:1'793 bytes
First seen:2025-10-26 08:52:26 UTC
Last seen:2025-10-27 08:38:36 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:vYeanqWeatTceaPyeafea7YeaReanea+eaN/ZU:v/aIatfaPpaWaragaeaVaI
TLSH T10231A2E4725302752D939DF7B3AC440D32E255E7D8D0EE2164E8BCAD418FE187453E42
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.62/bins/bot.x86n/an/aelf ua-wget
http://213.209.143.62/bins/bot.mipsn/an/aelf ua-wget
http://213.209.143.62/bins/bot.mpsln/an/aelf ua-wget
http://213.209.143.62/bins/bot.arm4n/an/aelf ua-wget
http://213.209.143.62/bins/bot.arm5n/an/aelf ua-wget
http://213.209.143.62/bins/bot.arm6n/an/aelf ua-wget
http://213.209.143.62/bins/bot.arm7n/an/aelf ua-wget
http://213.209.143.62/bins/bot.ppcn/an/aelf ua-wget
http://213.209.143.62/bins/bot.m68kn/an/aelf ua-wget
http://213.209.143.62/bins/bot.sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
56
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-26T05:59:00Z UTC
Last seen:
2025-10-26T06:57:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=ab5a601b-1900-0000-e36c-bde8da120000 pid=4826 /usr/bin/sudo guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836 /tmp/sample.bin guuid=ab5a601b-1900-0000-e36c-bde8da120000 pid=4826->guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836 execve guuid=4c88571e-1900-0000-e36c-bde8e7120000 pid=4839 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=4c88571e-1900-0000-e36c-bde8e7120000 pid=4839 execve guuid=50b43023-1900-0000-e36c-bde8fc120000 pid=4860 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=50b43023-1900-0000-e36c-bde8fc120000 pid=4860 execve guuid=4096392a-1900-0000-e36c-bde814130000 pid=4884 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=4096392a-1900-0000-e36c-bde814130000 pid=4884 execve guuid=f4f9952a-1900-0000-e36c-bde817130000 pid=4887 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=f4f9952a-1900-0000-e36c-bde817130000 pid=4887 execve guuid=b36aec2a-1900-0000-e36c-bde819130000 pid=4889 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=b36aec2a-1900-0000-e36c-bde819130000 pid=4889 clone guuid=998d922b-1900-0000-e36c-bde81c130000 pid=4892 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=998d922b-1900-0000-e36c-bde81c130000 pid=4892 execve guuid=c6de062e-1900-0000-e36c-bde826130000 pid=4902 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=c6de062e-1900-0000-e36c-bde826130000 pid=4902 execve guuid=e4ff7031-1900-0000-e36c-bde835130000 pid=4917 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=e4ff7031-1900-0000-e36c-bde835130000 pid=4917 execve guuid=06e9b731-1900-0000-e36c-bde837130000 pid=4919 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=06e9b731-1900-0000-e36c-bde837130000 pid=4919 execve guuid=b2d6ef31-1900-0000-e36c-bde839130000 pid=4921 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=b2d6ef31-1900-0000-e36c-bde839130000 pid=4921 clone guuid=bf7b1832-1900-0000-e36c-bde83b130000 pid=4923 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=bf7b1832-1900-0000-e36c-bde83b130000 pid=4923 execve guuid=ab3fdc35-1900-0000-e36c-bde848130000 pid=4936 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=ab3fdc35-1900-0000-e36c-bde848130000 pid=4936 execve guuid=05ed0e39-1900-0000-e36c-bde851130000 pid=4945 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=05ed0e39-1900-0000-e36c-bde851130000 pid=4945 execve guuid=53cc6039-1900-0000-e36c-bde853130000 pid=4947 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=53cc6039-1900-0000-e36c-bde853130000 pid=4947 execve guuid=f88ba939-1900-0000-e36c-bde855130000 pid=4949 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=f88ba939-1900-0000-e36c-bde855130000 pid=4949 clone guuid=3d80dd39-1900-0000-e36c-bde856130000 pid=4950 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=3d80dd39-1900-0000-e36c-bde856130000 pid=4950 execve guuid=5aa6f43d-1900-0000-e36c-bde861130000 pid=4961 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=5aa6f43d-1900-0000-e36c-bde861130000 pid=4961 execve guuid=fe650344-1900-0000-e36c-bde877130000 pid=4983 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=fe650344-1900-0000-e36c-bde877130000 pid=4983 execve guuid=41b84744-1900-0000-e36c-bde87b130000 pid=4987 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=41b84744-1900-0000-e36c-bde87b130000 pid=4987 execve guuid=cfe08b44-1900-0000-e36c-bde87d130000 pid=4989 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=cfe08b44-1900-0000-e36c-bde87d130000 pid=4989 clone guuid=023bb144-1900-0000-e36c-bde87e130000 pid=4990 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=023bb144-1900-0000-e36c-bde87e130000 pid=4990 execve guuid=7c064847-1900-0000-e36c-bde88e130000 pid=5006 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=7c064847-1900-0000-e36c-bde88e130000 pid=5006 execve guuid=603e5b4a-1900-0000-e36c-bde89e130000 pid=5022 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=603e5b4a-1900-0000-e36c-bde89e130000 pid=5022 execve guuid=05fca84a-1900-0000-e36c-bde8a0130000 pid=5024 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=05fca84a-1900-0000-e36c-bde8a0130000 pid=5024 execve guuid=f363e94a-1900-0000-e36c-bde8a4130000 pid=5028 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=f363e94a-1900-0000-e36c-bde8a4130000 pid=5028 clone guuid=2f63134b-1900-0000-e36c-bde8a5130000 pid=5029 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=2f63134b-1900-0000-e36c-bde8a5130000 pid=5029 execve guuid=6f90914d-1900-0000-e36c-bde8b1130000 pid=5041 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=6f90914d-1900-0000-e36c-bde8b1130000 pid=5041 execve guuid=09bb5851-1900-0000-e36c-bde8bd130000 pid=5053 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=09bb5851-1900-0000-e36c-bde8bd130000 pid=5053 execve guuid=8873a051-1900-0000-e36c-bde8bf130000 pid=5055 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=8873a051-1900-0000-e36c-bde8bf130000 pid=5055 execve guuid=95d5de51-1900-0000-e36c-bde8c0130000 pid=5056 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=95d5de51-1900-0000-e36c-bde8c0130000 pid=5056 clone guuid=7bd5ff51-1900-0000-e36c-bde8c1130000 pid=5057 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=7bd5ff51-1900-0000-e36c-bde8c1130000 pid=5057 execve guuid=274f6354-1900-0000-e36c-bde8cb130000 pid=5067 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=274f6354-1900-0000-e36c-bde8cb130000 pid=5067 execve guuid=7631655a-1900-0000-e36c-bde8db130000 pid=5083 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=7631655a-1900-0000-e36c-bde8db130000 pid=5083 execve guuid=d588025b-1900-0000-e36c-bde8de130000 pid=5086 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=d588025b-1900-0000-e36c-bde8de130000 pid=5086 execve guuid=82f9855b-1900-0000-e36c-bde8e1130000 pid=5089 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=82f9855b-1900-0000-e36c-bde8e1130000 pid=5089 clone guuid=996bc45b-1900-0000-e36c-bde8e3130000 pid=5091 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=996bc45b-1900-0000-e36c-bde8e3130000 pid=5091 execve guuid=3fd3b95e-1900-0000-e36c-bde8ed130000 pid=5101 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=3fd3b95e-1900-0000-e36c-bde8ed130000 pid=5101 execve guuid=393aba62-1900-0000-e36c-bde8f8130000 pid=5112 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=393aba62-1900-0000-e36c-bde8f8130000 pid=5112 execve guuid=54ad0663-1900-0000-e36c-bde8fa130000 pid=5114 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=54ad0663-1900-0000-e36c-bde8fa130000 pid=5114 execve guuid=6c7c4a63-1900-0000-e36c-bde8fc130000 pid=5116 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=6c7c4a63-1900-0000-e36c-bde8fc130000 pid=5116 clone guuid=6cb57363-1900-0000-e36c-bde8fe130000 pid=5118 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=6cb57363-1900-0000-e36c-bde8fe130000 pid=5118 execve guuid=d0104f66-1900-0000-e36c-bde807140000 pid=5127 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=d0104f66-1900-0000-e36c-bde807140000 pid=5127 execve guuid=5dedfe69-1900-0000-e36c-bde815140000 pid=5141 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=5dedfe69-1900-0000-e36c-bde815140000 pid=5141 execve guuid=00f7666a-1900-0000-e36c-bde817140000 pid=5143 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=00f7666a-1900-0000-e36c-bde817140000 pid=5143 execve guuid=3827b46a-1900-0000-e36c-bde819140000 pid=5145 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=3827b46a-1900-0000-e36c-bde819140000 pid=5145 clone guuid=a6f1f36a-1900-0000-e36c-bde81f140000 pid=5151 /usr/bin/wget net send-data guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=a6f1f36a-1900-0000-e36c-bde81f140000 pid=5151 execve guuid=009e6f6d-1900-0000-e36c-bde82d140000 pid=5165 /usr/bin/curl net send-data write-file guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=009e6f6d-1900-0000-e36c-bde82d140000 pid=5165 execve guuid=b5992671-1900-0000-e36c-bde849140000 pid=5193 /usr/bin/cat guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=b5992671-1900-0000-e36c-bde849140000 pid=5193 execve guuid=0f307e71-1900-0000-e36c-bde84a140000 pid=5194 /usr/bin/chmod guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=0f307e71-1900-0000-e36c-bde84a140000 pid=5194 execve guuid=3253d271-1900-0000-e36c-bde84c140000 pid=5196 /usr/bin/bash guuid=659fa61d-1900-0000-e36c-bde8e4120000 pid=4836->guuid=3253d271-1900-0000-e36c-bde84c140000 pid=5196 clone eaaaaddb-f5f1-5090-9f4d-096f63c93adc 213.209.143.62:80 guuid=4c88571e-1900-0000-e36c-bde8e7120000 pid=4839->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=50b43023-1900-0000-e36c-bde8fc120000 pid=4860->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=998d922b-1900-0000-e36c-bde81c130000 pid=4892->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=c6de062e-1900-0000-e36c-bde826130000 pid=4902->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=bf7b1832-1900-0000-e36c-bde83b130000 pid=4923->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=ab3fdc35-1900-0000-e36c-bde848130000 pid=4936->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=3d80dd39-1900-0000-e36c-bde856130000 pid=4950->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=5aa6f43d-1900-0000-e36c-bde861130000 pid=4961->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=023bb144-1900-0000-e36c-bde87e130000 pid=4990->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=7c064847-1900-0000-e36c-bde88e130000 pid=5006->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=2f63134b-1900-0000-e36c-bde8a5130000 pid=5029->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=6f90914d-1900-0000-e36c-bde8b1130000 pid=5041->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=7bd5ff51-1900-0000-e36c-bde8c1130000 pid=5057->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=274f6354-1900-0000-e36c-bde8cb130000 pid=5067->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=996bc45b-1900-0000-e36c-bde8e3130000 pid=5091->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=3fd3b95e-1900-0000-e36c-bde8ed130000 pid=5101->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B guuid=6cb57363-1900-0000-e36c-bde8fe130000 pid=5118->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 142B guuid=d0104f66-1900-0000-e36c-bde807140000 pid=5127->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 91B guuid=a6f1f36a-1900-0000-e36c-bde81f140000 pid=5151->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 141B guuid=009e6f6d-1900-0000-e36c-bde82d140000 pid=5165->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-26 08:53:41 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7709d54a50df45500a97ca2818e8e85ffbac82f8289a1bfadf972bde5797a657

(this sample)

  
Delivery method
Distributed via web download

Comments