MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7fd3aa653ece26c81e94f042ee6b85cfcd04a4bcfc2f4b097ee673b8635fc2ae. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 7fd3aa653ece26c81e94f042ee6b85cfcd04a4bcfc2f4b097ee673b8635fc2ae
SHA3-384 hash: 15484e865bb40d4773c29121164349e2464cee543c426a01ef2b1ee0fc36a707fe0cc92e3ea26d50811dac733603eb58
SHA1 hash: 1daa28d93508352d9aca212b9f2b4d4ced9f0d82
MD5 hash: b2fcc000f58f0e43fdaf5d3513fd83cf
humanhash: louisiana-winter-equal-alaska
File name:hnap
Download: download sample
Signature Mirai
File size:2'821 bytes
First seen:2025-09-06 06:45:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v3X3HW3GNHW3gtHW3ypHW34NHW3soszEHW3bvHW3IdHW31vHW3ihHW3QHHW3A5AV:v3X323GN23gt23yp234N237oE23bv23e
TLSH T19F51E3C6F22843703FF59A5A39FB612434D0B2995BC20E51C5FC38BEA54DF0A749169A
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.162.114.77/bins/sora.x86c4fdffa36b13e3742a38317302b552e0142055d028e43ef4ccbbdbfa0b208342 Miraielf mirai
http://38.162.114.77/bins/sora.mips518bb7ecad7786975b925e68c15f70746e6ab02508deb8bbbc8b8cc5cc597355 Miraielf mirai
http://38.162.114.77/bins/sora.x86_64n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i468n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i686n/an/aelf ua-wget
http://38.162.114.77/bins/sora.mpslcb66f0b9bfb996b5e4fe142cd03b3061b9843899675d93690e5474e87ef1bef2 Miraielf mirai
http://38.162.114.77/bins/sora.arm4n/an/aelf ua-wget
http://38.162.114.77/bins/sora.arm512486e4b57bd5ee074988b64d0716aa9c631aeb5805d8fc7664063d5a98dfaac Miraielf mirai
http://38.162.114.77/bins/sora.arm6e7b1d9504e3f6186d5c26f39932d0327b4ba22e04bf6e32e78ae72ca6969bd8c Miraielf mirai
http://38.162.114.77/bins/sora.arm77a0d000d79bc1be7a41fa59d1892995ff61815d4dbeb49f6d7053da7034a1598 Miraielf mirai
http://38.162.114.77/bins/sora.ppcadfb9de9a74d82e9d980515498e5d02b527961d37375a76e784404d059676f85 Miraielf mirai
http://38.162.114.77/bins/sora.ppc440fpn/an/aelf ua-wget
http://38.162.114.77/bins/sora.m68k6d1d1df496a3ab3aa77e2536fc9fcb09ed3b6653b77c27e305aba647bc5f2193 Miraielf mirai
http://38.162.114.77/bins/sora.sh438e47119b088297ba98fe3db4022607ff33af93d40ebc4991de353a424d180cc Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T03:57:00Z UTC
Last seen:
2025-09-06T03:57:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.c
Status:
terminated
Behavior Graph:
%3 guuid=5e3cb6d7-1700-0000-73e4-b521fd0c0000 pid=3325 /usr/bin/sudo guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328 /tmp/sample.bin guuid=5e3cb6d7-1700-0000-73e4-b521fd0c0000 pid=3325->guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328 execve guuid=3dfef5da-1700-0000-73e4-b521040d0000 pid=3332 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=3dfef5da-1700-0000-73e4-b521040d0000 pid=3332 execve guuid=93de2ff9-1700-0000-73e4-b521520d0000 pid=3410 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=93de2ff9-1700-0000-73e4-b521520d0000 pid=3410 execve guuid=178b7117-1800-0000-73e4-b521990d0000 pid=3481 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=178b7117-1800-0000-73e4-b521990d0000 pid=3481 execve guuid=b7ccbf17-1800-0000-73e4-b5219a0d0000 pid=3482 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b7ccbf17-1800-0000-73e4-b5219a0d0000 pid=3482 execve guuid=5a7e0d18-1800-0000-73e4-b5219b0d0000 pid=3483 /tmp/robben net guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=5a7e0d18-1800-0000-73e4-b5219b0d0000 pid=3483 execve guuid=141e0f1b-1800-0000-73e4-b521a10d0000 pid=3489 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=141e0f1b-1800-0000-73e4-b521a10d0000 pid=3489 execve guuid=a5f65a37-1800-0000-73e4-b521d80d0000 pid=3544 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=a5f65a37-1800-0000-73e4-b521d80d0000 pid=3544 execve guuid=5de6f154-1800-0000-73e4-b521230e0000 pid=3619 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=5de6f154-1800-0000-73e4-b521230e0000 pid=3619 execve guuid=54104655-1800-0000-73e4-b521250e0000 pid=3621 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=54104655-1800-0000-73e4-b521250e0000 pid=3621 execve guuid=d3fa8055-1800-0000-73e4-b521290e0000 pid=3625 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=d3fa8055-1800-0000-73e4-b521290e0000 pid=3625 clone guuid=b0b45956-1800-0000-73e4-b5212c0e0000 pid=3628 /usr/bin/wget net send-data guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b0b45956-1800-0000-73e4-b5212c0e0000 pid=3628 execve guuid=99b22369-1800-0000-73e4-b5214e0e0000 pid=3662 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=99b22369-1800-0000-73e4-b5214e0e0000 pid=3662 execve guuid=7566e67f-1800-0000-73e4-b521740e0000 pid=3700 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7566e67f-1800-0000-73e4-b521740e0000 pid=3700 execve guuid=6e1e9580-1800-0000-73e4-b521780e0000 pid=3704 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=6e1e9580-1800-0000-73e4-b521780e0000 pid=3704 execve guuid=e9853e81-1800-0000-73e4-b5217a0e0000 pid=3706 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e9853e81-1800-0000-73e4-b5217a0e0000 pid=3706 clone guuid=89330382-1800-0000-73e4-b5217b0e0000 pid=3707 /usr/bin/wget net send-data guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=89330382-1800-0000-73e4-b5217b0e0000 pid=3707 execve guuid=7f8ecb94-1800-0000-73e4-b521ae0e0000 pid=3758 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7f8ecb94-1800-0000-73e4-b521ae0e0000 pid=3758 execve guuid=b09f8da9-1800-0000-73e4-b521f20e0000 pid=3826 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b09f8da9-1800-0000-73e4-b521f20e0000 pid=3826 execve guuid=9c23e9a9-1800-0000-73e4-b521f40e0000 pid=3828 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=9c23e9a9-1800-0000-73e4-b521f40e0000 pid=3828 execve guuid=16922daa-1800-0000-73e4-b521f60e0000 pid=3830 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=16922daa-1800-0000-73e4-b521f60e0000 pid=3830 clone guuid=b37c5caa-1800-0000-73e4-b521f80e0000 pid=3832 /usr/bin/wget net send-data guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b37c5caa-1800-0000-73e4-b521f80e0000 pid=3832 execve guuid=b579c8bc-1800-0000-73e4-b521220f0000 pid=3874 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b579c8bc-1800-0000-73e4-b521220f0000 pid=3874 execve guuid=3982d3d0-1800-0000-73e4-b521520f0000 pid=3922 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=3982d3d0-1800-0000-73e4-b521520f0000 pid=3922 execve guuid=fe2f50d1-1800-0000-73e4-b521540f0000 pid=3924 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=fe2f50d1-1800-0000-73e4-b521540f0000 pid=3924 execve guuid=8e18f9d1-1800-0000-73e4-b521570f0000 pid=3927 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=8e18f9d1-1800-0000-73e4-b521570f0000 pid=3927 clone guuid=2e9625d2-1800-0000-73e4-b521590f0000 pid=3929 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=2e9625d2-1800-0000-73e4-b521590f0000 pid=3929 execve guuid=ae5af6ee-1800-0000-73e4-b521b20f0000 pid=4018 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=ae5af6ee-1800-0000-73e4-b521b20f0000 pid=4018 execve guuid=cdda6852-1900-0000-73e4-b521a9100000 pid=4265 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=cdda6852-1900-0000-73e4-b521a9100000 pid=4265 execve guuid=e4ef0f53-1900-0000-73e4-b521ab100000 pid=4267 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e4ef0f53-1900-0000-73e4-b521ab100000 pid=4267 execve guuid=e06b9853-1900-0000-73e4-b521af100000 pid=4271 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e06b9853-1900-0000-73e4-b521af100000 pid=4271 clone guuid=f7c98755-1900-0000-73e4-b521b6100000 pid=4278 /usr/bin/wget net send-data guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=f7c98755-1900-0000-73e4-b521b6100000 pid=4278 execve guuid=42a52869-1900-0000-73e4-b521ee100000 pid=4334 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=42a52869-1900-0000-73e4-b521ee100000 pid=4334 execve guuid=675c6f7e-1900-0000-73e4-b52123110000 pid=4387 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=675c6f7e-1900-0000-73e4-b52123110000 pid=4387 execve guuid=e735d37e-1900-0000-73e4-b52125110000 pid=4389 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e735d37e-1900-0000-73e4-b52125110000 pid=4389 execve guuid=a71d287f-1900-0000-73e4-b52127110000 pid=4391 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=a71d287f-1900-0000-73e4-b52127110000 pid=4391 clone guuid=7a90687f-1900-0000-73e4-b52128110000 pid=4392 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7a90687f-1900-0000-73e4-b52128110000 pid=4392 execve guuid=0f2e399a-1900-0000-73e4-b52180110000 pid=4480 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=0f2e399a-1900-0000-73e4-b52180110000 pid=4480 execve guuid=b935adb6-1900-0000-73e4-b521ea110000 pid=4586 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b935adb6-1900-0000-73e4-b521ea110000 pid=4586 execve guuid=d4471db7-1900-0000-73e4-b521eb110000 pid=4587 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=d4471db7-1900-0000-73e4-b521eb110000 pid=4587 execve guuid=97ce68b7-1900-0000-73e4-b521ef110000 pid=4591 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=97ce68b7-1900-0000-73e4-b521ef110000 pid=4591 clone guuid=65ee20b8-1900-0000-73e4-b521f3110000 pid=4595 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=65ee20b8-1900-0000-73e4-b521f3110000 pid=4595 execve guuid=02e5e3d3-1900-0000-73e4-b52144120000 pid=4676 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=02e5e3d3-1900-0000-73e4-b52144120000 pid=4676 execve guuid=9758ddf0-1900-0000-73e4-b52196120000 pid=4758 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=9758ddf0-1900-0000-73e4-b52196120000 pid=4758 execve guuid=7fa774f1-1900-0000-73e4-b52199120000 pid=4761 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7fa774f1-1900-0000-73e4-b52199120000 pid=4761 execve guuid=b173eaf1-1900-0000-73e4-b5219a120000 pid=4762 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=b173eaf1-1900-0000-73e4-b5219a120000 pid=4762 clone guuid=4223bff2-1900-0000-73e4-b5219e120000 pid=4766 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=4223bff2-1900-0000-73e4-b5219e120000 pid=4766 execve guuid=126f6a17-1a00-0000-73e4-b521fd120000 pid=4861 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=126f6a17-1a00-0000-73e4-b521fd120000 pid=4861 execve guuid=6776ab3c-1a00-0000-73e4-b52161130000 pid=4961 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=6776ab3c-1a00-0000-73e4-b52161130000 pid=4961 execve guuid=64b9213d-1a00-0000-73e4-b52163130000 pid=4963 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=64b9213d-1a00-0000-73e4-b52163130000 pid=4963 execve guuid=f24a8a3d-1a00-0000-73e4-b52165130000 pid=4965 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=f24a8a3d-1a00-0000-73e4-b52165130000 pid=4965 clone guuid=eab8c73e-1a00-0000-73e4-b5216a130000 pid=4970 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=eab8c73e-1a00-0000-73e4-b5216a130000 pid=4970 execve guuid=7e0edc5a-1a00-0000-73e4-b521a6130000 pid=5030 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7e0edc5a-1a00-0000-73e4-b521a6130000 pid=5030 execve guuid=5f85c877-1a00-0000-73e4-b52101140000 pid=5121 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=5f85c877-1a00-0000-73e4-b52101140000 pid=5121 execve guuid=e7223078-1a00-0000-73e4-b52103140000 pid=5123 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e7223078-1a00-0000-73e4-b52103140000 pid=5123 execve guuid=e5478a78-1a00-0000-73e4-b52105140000 pid=5125 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e5478a78-1a00-0000-73e4-b52105140000 pid=5125 clone guuid=7fba3079-1a00-0000-73e4-b5210a140000 pid=5130 /usr/bin/wget net send-data guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=7fba3079-1a00-0000-73e4-b5210a140000 pid=5130 execve guuid=adfdcd8c-1a00-0000-73e4-b52134140000 pid=5172 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=adfdcd8c-1a00-0000-73e4-b52134140000 pid=5172 execve guuid=ab3886a0-1a00-0000-73e4-b52163140000 pid=5219 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=ab3886a0-1a00-0000-73e4-b52163140000 pid=5219 execve guuid=cdf719a1-1a00-0000-73e4-b52165140000 pid=5221 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=cdf719a1-1a00-0000-73e4-b52165140000 pid=5221 execve guuid=f7448fa1-1a00-0000-73e4-b52166140000 pid=5222 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=f7448fa1-1a00-0000-73e4-b52166140000 pid=5222 clone guuid=81f3eda1-1a00-0000-73e4-b5216c140000 pid=5228 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=81f3eda1-1a00-0000-73e4-b5216c140000 pid=5228 execve guuid=c77ecdc5-1a00-0000-73e4-b5219d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=c77ecdc5-1a00-0000-73e4-b5219d140000 pid=5277 execve guuid=4ee862ec-1a00-0000-73e4-b521a3140000 pid=5283 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=4ee862ec-1a00-0000-73e4-b521a3140000 pid=5283 execve guuid=90afd3ec-1a00-0000-73e4-b521a4140000 pid=5284 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=90afd3ec-1a00-0000-73e4-b521a4140000 pid=5284 execve guuid=5bdb55ed-1a00-0000-73e4-b521a5140000 pid=5285 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=5bdb55ed-1a00-0000-73e4-b521a5140000 pid=5285 clone guuid=5ba31fee-1a00-0000-73e4-b521a7140000 pid=5287 /usr/bin/wget net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=5ba31fee-1a00-0000-73e4-b521a7140000 pid=5287 execve guuid=99e41214-1b00-0000-73e4-b521a8140000 pid=5288 /usr/bin/curl net send-data write-file guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=99e41214-1b00-0000-73e4-b521a8140000 pid=5288 execve guuid=fde5d339-1b00-0000-73e4-b521a9140000 pid=5289 /usr/bin/cat guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=fde5d339-1b00-0000-73e4-b521a9140000 pid=5289 execve guuid=05d0453a-1b00-0000-73e4-b521aa140000 pid=5290 /usr/bin/chmod guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=05d0453a-1b00-0000-73e4-b521aa140000 pid=5290 execve guuid=e533963a-1b00-0000-73e4-b521ab140000 pid=5291 /usr/bin/bash guuid=fb9dded9-1700-0000-73e4-b521000d0000 pid=3328->guuid=e533963a-1b00-0000-73e4-b521ab140000 pid=5291 clone e10eb183-c74b-539a-bc26-e43bbf2bbb51 38.162.114.77:80 guuid=3dfef5da-1700-0000-73e4-b521040d0000 pid=3332->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=93de2ff9-1700-0000-73e4-b521520d0000 pid=3410->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5a7e0d18-1800-0000-73e4-b5219b0d0000 pid=3483->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=141e0f1b-1800-0000-73e4-b521a10d0000 pid=3489->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=a5f65a37-1800-0000-73e4-b521d80d0000 pid=3544->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=b0b45956-1800-0000-73e4-b5212c0e0000 pid=3628->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 144B guuid=99b22369-1800-0000-73e4-b5214e0e0000 pid=3662->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 93B guuid=89330382-1800-0000-73e4-b5217b0e0000 pid=3707->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=7f8ecb94-1800-0000-73e4-b521ae0e0000 pid=3758->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=b37c5caa-1800-0000-73e4-b521f80e0000 pid=3832->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=b579c8bc-1800-0000-73e4-b521220f0000 pid=3874->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=2e9625d2-1800-0000-73e4-b521590f0000 pid=3929->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=ae5af6ee-1800-0000-73e4-b521b20f0000 pid=4018->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=f7c98755-1900-0000-73e4-b521b6100000 pid=4278->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=42a52869-1900-0000-73e4-b521ee100000 pid=4334->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7a90687f-1900-0000-73e4-b52128110000 pid=4392->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0f2e399a-1900-0000-73e4-b52180110000 pid=4480->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=65ee20b8-1900-0000-73e4-b521f3110000 pid=4595->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=02e5e3d3-1900-0000-73e4-b52144120000 pid=4676->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=4223bff2-1900-0000-73e4-b5219e120000 pid=4766->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=126f6a17-1a00-0000-73e4-b521fd120000 pid=4861->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=eab8c73e-1a00-0000-73e4-b5216a130000 pid=4970->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=7e0edc5a-1a00-0000-73e4-b521a6130000 pid=5030->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B guuid=7fba3079-1a00-0000-73e4-b5210a140000 pid=5130->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 146B guuid=adfdcd8c-1a00-0000-73e4-b52134140000 pid=5172->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 95B guuid=81f3eda1-1a00-0000-73e4-b5216c140000 pid=5228->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=c77ecdc5-1a00-0000-73e4-b5219d140000 pid=5277->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=5ba31fee-1a00-0000-73e4-b521a7140000 pid=5287->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=99e41214-1b00-0000-73e4-b521a8140000 pid=5288->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 06:31:06 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (47316) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 7fd3aa653ece26c81e94f042ee6b85cfcd04a4bcfc2f4b097ee673b8635fc2ae

(this sample)

  
Delivery method
Distributed via web download

Comments