MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 92ffa4a78aa9744345f724b2ef49f3048c20982b73dbcf26db73fa7c9bc5df27. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 92ffa4a78aa9744345f724b2ef49f3048c20982b73dbcf26db73fa7c9bc5df27
SHA3-384 hash: 895c46b875cc035ba9e8d4ac676157004330ddaa8dbc0a23bac12967551cf516757a761f46a75d8e898059c1fc6240bf
SHA1 hash: ea247d617b8d7bbe2e68923e3be9345ebfc81fbc
MD5 hash: 497e5d47b7eebc00fee83a4c3183269d
humanhash: lion-lake-hot-mexico
File name:huawei
Download: download sample
File size:2'438 bytes
First seen:2025-07-10 13:01:54 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSGrx0xX99rxuwxuj6rxZxa+rxyxlBrxbx08rx8xfjrxGxpxrxdxuKrxnxAR:vlTSGliX99lb66l7a+lQlBlV08lKfjlf
TLSH T1EC41A1F50145073DACF6996E31E789C8B6A196C620C39FD4D6FC38E5404DE483EA6E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
99.1%
Tags:
medusa agent virus
Status:
terminated
Behavior Graph:
%3 guuid=3f55979e-1900-0000-6e4a-42d9b10c0000 pid=3249 /usr/bin/sudo guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253 /tmp/sample.bin guuid=3f55979e-1900-0000-6e4a-42d9b10c0000 pid=3249->guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253 execve guuid=f2e906a1-1900-0000-6e4a-42d9b60c0000 pid=3254 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f2e906a1-1900-0000-6e4a-42d9b60c0000 pid=3254 execve guuid=6d982da5-1900-0000-6e4a-42d9b80c0000 pid=3256 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=6d982da5-1900-0000-6e4a-42d9b80c0000 pid=3256 execve guuid=2d8b72ae-1900-0000-6e4a-42d9cc0c0000 pid=3276 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=2d8b72ae-1900-0000-6e4a-42d9cc0c0000 pid=3276 execve guuid=c18dfbae-1900-0000-6e4a-42d9cf0c0000 pid=3279 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=c18dfbae-1900-0000-6e4a-42d9cf0c0000 pid=3279 execve guuid=309d6daf-1900-0000-6e4a-42d9d10c0000 pid=3281 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=309d6daf-1900-0000-6e4a-42d9d10c0000 pid=3281 clone guuid=0031b4af-1900-0000-6e4a-42d9d30c0000 pid=3283 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=0031b4af-1900-0000-6e4a-42d9d30c0000 pid=3283 execve guuid=43ab71b1-1900-0000-6e4a-42d9d90c0000 pid=3289 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=43ab71b1-1900-0000-6e4a-42d9d90c0000 pid=3289 execve guuid=71160bb5-1900-0000-6e4a-42d9e40c0000 pid=3300 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=71160bb5-1900-0000-6e4a-42d9e40c0000 pid=3300 execve guuid=04d454b5-1900-0000-6e4a-42d9e50c0000 pid=3301 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=04d454b5-1900-0000-6e4a-42d9e50c0000 pid=3301 execve guuid=04eb94b5-1900-0000-6e4a-42d9e70c0000 pid=3303 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=04eb94b5-1900-0000-6e4a-42d9e70c0000 pid=3303 clone guuid=fde6b7b5-1900-0000-6e4a-42d9e80c0000 pid=3304 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=fde6b7b5-1900-0000-6e4a-42d9e80c0000 pid=3304 execve guuid=5c0f51b7-1900-0000-6e4a-42d9ee0c0000 pid=3310 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=5c0f51b7-1900-0000-6e4a-42d9ee0c0000 pid=3310 execve guuid=dc6ef0b9-1900-0000-6e4a-42d9f50c0000 pid=3317 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=dc6ef0b9-1900-0000-6e4a-42d9f50c0000 pid=3317 execve guuid=f4c639ba-1900-0000-6e4a-42d9f70c0000 pid=3319 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f4c639ba-1900-0000-6e4a-42d9f70c0000 pid=3319 execve guuid=c6b39bba-1900-0000-6e4a-42d9f90c0000 pid=3321 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=c6b39bba-1900-0000-6e4a-42d9f90c0000 pid=3321 clone guuid=5377bbba-1900-0000-6e4a-42d9fb0c0000 pid=3323 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=5377bbba-1900-0000-6e4a-42d9fb0c0000 pid=3323 execve guuid=1b2cd9bc-1900-0000-6e4a-42d9030d0000 pid=3331 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=1b2cd9bc-1900-0000-6e4a-42d9030d0000 pid=3331 execve guuid=e172b4bf-1900-0000-6e4a-42d90c0d0000 pid=3340 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=e172b4bf-1900-0000-6e4a-42d90c0d0000 pid=3340 execve guuid=dc0503c0-1900-0000-6e4a-42d90f0d0000 pid=3343 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=dc0503c0-1900-0000-6e4a-42d90f0d0000 pid=3343 execve guuid=2bb244c0-1900-0000-6e4a-42d9100d0000 pid=3344 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=2bb244c0-1900-0000-6e4a-42d9100d0000 pid=3344 clone guuid=3ce76ac0-1900-0000-6e4a-42d9110d0000 pid=3345 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=3ce76ac0-1900-0000-6e4a-42d9110d0000 pid=3345 execve guuid=2ee48cc2-1900-0000-6e4a-42d9120d0000 pid=3346 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=2ee48cc2-1900-0000-6e4a-42d9120d0000 pid=3346 execve guuid=2734f9c7-1900-0000-6e4a-42d9140d0000 pid=3348 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=2734f9c7-1900-0000-6e4a-42d9140d0000 pid=3348 execve guuid=f03f4cc8-1900-0000-6e4a-42d9150d0000 pid=3349 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f03f4cc8-1900-0000-6e4a-42d9150d0000 pid=3349 execve guuid=4c7fb8c8-1900-0000-6e4a-42d9170d0000 pid=3351 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=4c7fb8c8-1900-0000-6e4a-42d9170d0000 pid=3351 clone guuid=2a73e1c8-1900-0000-6e4a-42d9180d0000 pid=3352 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=2a73e1c8-1900-0000-6e4a-42d9180d0000 pid=3352 execve guuid=f12e2ecb-1900-0000-6e4a-42d9210d0000 pid=3361 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f12e2ecb-1900-0000-6e4a-42d9210d0000 pid=3361 execve guuid=98d879cf-1900-0000-6e4a-42d92c0d0000 pid=3372 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=98d879cf-1900-0000-6e4a-42d92c0d0000 pid=3372 execve guuid=65ecdecf-1900-0000-6e4a-42d92f0d0000 pid=3375 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=65ecdecf-1900-0000-6e4a-42d92f0d0000 pid=3375 execve guuid=d2a322d0-1900-0000-6e4a-42d9300d0000 pid=3376 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=d2a322d0-1900-0000-6e4a-42d9300d0000 pid=3376 clone guuid=341051d0-1900-0000-6e4a-42d9320d0000 pid=3378 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=341051d0-1900-0000-6e4a-42d9320d0000 pid=3378 execve guuid=aa2cded1-1900-0000-6e4a-42d9370d0000 pid=3383 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=aa2cded1-1900-0000-6e4a-42d9370d0000 pid=3383 execve guuid=1b0860d4-1900-0000-6e4a-42d9410d0000 pid=3393 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=1b0860d4-1900-0000-6e4a-42d9410d0000 pid=3393 execve guuid=8a78afd4-1900-0000-6e4a-42d9430d0000 pid=3395 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=8a78afd4-1900-0000-6e4a-42d9430d0000 pid=3395 execve guuid=ddd5f1d4-1900-0000-6e4a-42d9440d0000 pid=3396 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=ddd5f1d4-1900-0000-6e4a-42d9440d0000 pid=3396 clone guuid=11e41dd5-1900-0000-6e4a-42d9450d0000 pid=3397 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=11e41dd5-1900-0000-6e4a-42d9450d0000 pid=3397 execve guuid=6df6cfd6-1900-0000-6e4a-42d94c0d0000 pid=3404 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=6df6cfd6-1900-0000-6e4a-42d94c0d0000 pid=3404 execve guuid=54806fdc-1900-0000-6e4a-42d95b0d0000 pid=3419 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=54806fdc-1900-0000-6e4a-42d95b0d0000 pid=3419 execve guuid=9586dedc-1900-0000-6e4a-42d95e0d0000 pid=3422 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=9586dedc-1900-0000-6e4a-42d95e0d0000 pid=3422 execve guuid=587e36dd-1900-0000-6e4a-42d9600d0000 pid=3424 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=587e36dd-1900-0000-6e4a-42d9600d0000 pid=3424 clone guuid=f4315bdd-1900-0000-6e4a-42d9620d0000 pid=3426 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f4315bdd-1900-0000-6e4a-42d9620d0000 pid=3426 execve guuid=490808e0-1900-0000-6e4a-42d96b0d0000 pid=3435 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=490808e0-1900-0000-6e4a-42d96b0d0000 pid=3435 execve guuid=08a886e4-1900-0000-6e4a-42d97a0d0000 pid=3450 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=08a886e4-1900-0000-6e4a-42d97a0d0000 pid=3450 execve guuid=a1cbcce4-1900-0000-6e4a-42d97c0d0000 pid=3452 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=a1cbcce4-1900-0000-6e4a-42d97c0d0000 pid=3452 execve guuid=219f14e5-1900-0000-6e4a-42d97e0d0000 pid=3454 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=219f14e5-1900-0000-6e4a-42d97e0d0000 pid=3454 clone guuid=b7d134e5-1900-0000-6e4a-42d97f0d0000 pid=3455 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=b7d134e5-1900-0000-6e4a-42d97f0d0000 pid=3455 execve guuid=036f1fe8-1900-0000-6e4a-42d98a0d0000 pid=3466 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=036f1fe8-1900-0000-6e4a-42d98a0d0000 pid=3466 execve guuid=0524a8ea-1900-0000-6e4a-42d9930d0000 pid=3475 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=0524a8ea-1900-0000-6e4a-42d9930d0000 pid=3475 execve guuid=cf8002eb-1900-0000-6e4a-42d9950d0000 pid=3477 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=cf8002eb-1900-0000-6e4a-42d9950d0000 pid=3477 execve guuid=a0074eeb-1900-0000-6e4a-42d9970d0000 pid=3479 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=a0074eeb-1900-0000-6e4a-42d9970d0000 pid=3479 clone guuid=3eb995eb-1900-0000-6e4a-42d9990d0000 pid=3481 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=3eb995eb-1900-0000-6e4a-42d9990d0000 pid=3481 execve guuid=148aaded-1900-0000-6e4a-42d99f0d0000 pid=3487 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=148aaded-1900-0000-6e4a-42d99f0d0000 pid=3487 execve guuid=9a4989f0-1900-0000-6e4a-42d9aa0d0000 pid=3498 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=9a4989f0-1900-0000-6e4a-42d9aa0d0000 pid=3498 execve guuid=c69a6dff-1900-0000-6e4a-42d9d50d0000 pid=3541 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=c69a6dff-1900-0000-6e4a-42d9d50d0000 pid=3541 execve guuid=136ee1ff-1900-0000-6e4a-42d9d60d0000 pid=3542 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=136ee1ff-1900-0000-6e4a-42d9d60d0000 pid=3542 clone guuid=aec11600-1a00-0000-6e4a-42d9d70d0000 pid=3543 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=aec11600-1a00-0000-6e4a-42d9d70d0000 pid=3543 execve guuid=d790f501-1a00-0000-6e4a-42d9d80d0000 pid=3544 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=d790f501-1a00-0000-6e4a-42d9d80d0000 pid=3544 execve guuid=62bd0606-1a00-0000-6e4a-42d9dd0d0000 pid=3549 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=62bd0606-1a00-0000-6e4a-42d9dd0d0000 pid=3549 execve guuid=d9d44c06-1a00-0000-6e4a-42d9df0d0000 pid=3551 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=d9d44c06-1a00-0000-6e4a-42d9df0d0000 pid=3551 execve guuid=c467a906-1a00-0000-6e4a-42d9e10d0000 pid=3553 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=c467a906-1a00-0000-6e4a-42d9e10d0000 pid=3553 clone guuid=f592d106-1a00-0000-6e4a-42d9e30d0000 pid=3555 /usr/bin/wget net send-data guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=f592d106-1a00-0000-6e4a-42d9e30d0000 pid=3555 execve guuid=4de65e08-1a00-0000-6e4a-42d9ea0d0000 pid=3562 /usr/bin/curl net send-data write-file guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=4de65e08-1a00-0000-6e4a-42d9ea0d0000 pid=3562 execve guuid=5c83df0a-1a00-0000-6e4a-42d9ec0d0000 pid=3564 /usr/bin/cat guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=5c83df0a-1a00-0000-6e4a-42d9ec0d0000 pid=3564 execve guuid=e0ad570b-1a00-0000-6e4a-42d9ed0d0000 pid=3565 /usr/bin/chmod guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=e0ad570b-1a00-0000-6e4a-42d9ed0d0000 pid=3565 execve guuid=9986e70b-1a00-0000-6e4a-42d9ee0d0000 pid=3566 /usr/bin/bash guuid=d1cb87a0-1900-0000-6e4a-42d9b50c0000 pid=3253->guuid=9986e70b-1a00-0000-6e4a-42d9ee0d0000 pid=3566 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=f2e906a1-1900-0000-6e4a-42d9b60c0000 pid=3254->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=6d982da5-1900-0000-6e4a-42d9b80c0000 pid=3256->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=0031b4af-1900-0000-6e4a-42d9d30c0000 pid=3283->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=43ab71b1-1900-0000-6e4a-42d9d90c0000 pid=3289->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=fde6b7b5-1900-0000-6e4a-42d9e80c0000 pid=3304->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=5c0f51b7-1900-0000-6e4a-42d9ee0c0000 pid=3310->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=5377bbba-1900-0000-6e4a-42d9fb0c0000 pid=3323->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=1b2cd9bc-1900-0000-6e4a-42d9030d0000 pid=3331->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=3ce76ac0-1900-0000-6e4a-42d9110d0000 pid=3345->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=2ee48cc2-1900-0000-6e4a-42d9120d0000 pid=3346->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=2a73e1c8-1900-0000-6e4a-42d9180d0000 pid=3352->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=f12e2ecb-1900-0000-6e4a-42d9210d0000 pid=3361->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=341051d0-1900-0000-6e4a-42d9320d0000 pid=3378->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=aa2cded1-1900-0000-6e4a-42d9370d0000 pid=3383->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=11e41dd5-1900-0000-6e4a-42d9450d0000 pid=3397->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=6df6cfd6-1900-0000-6e4a-42d94c0d0000 pid=3404->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=f4315bdd-1900-0000-6e4a-42d9620d0000 pid=3426->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=490808e0-1900-0000-6e4a-42d96b0d0000 pid=3435->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=b7d134e5-1900-0000-6e4a-42d97f0d0000 pid=3455->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=036f1fe8-1900-0000-6e4a-42d98a0d0000 pid=3466->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=3eb995eb-1900-0000-6e4a-42d9990d0000 pid=3481->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=148aaded-1900-0000-6e4a-42d99f0d0000 pid=3487->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=aec11600-1a00-0000-6e4a-42d9d70d0000 pid=3543->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=d790f501-1a00-0000-6e4a-42d9d80d0000 pid=3544->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=f592d106-1a00-0000-6e4a-42d9e30d0000 pid=3555->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=4de65e08-1a00-0000-6e4a-42d9ea0d0000 pid=3562->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:02:18 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 92ffa4a78aa9744345f724b2ef49f3048c20982b73dbcf26db73fa7c9bc5df27

(this sample)

  
Delivery method
Distributed via web download

Comments