MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a0c8570dde73fc647c8a7d6cb0b1ac0585ec065b01c91223402e91844a1fea5c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: a0c8570dde73fc647c8a7d6cb0b1ac0585ec065b01c91223402e91844a1fea5c
SHA3-384 hash: 430acee7f735584dc4a89fa14823577b852a5d08bcdef55b8291dd1a46f9644815d09457452d1cfb1e2913220461eaac
SHA1 hash: db0177b17b6557f805fde7d0bc92a54f8ad9ad24
MD5 hash: f4fc465c51df332218cbb99851fed510
humanhash: april-freddie-sodium-neptune
File name:yarn
Download: download sample
Signature Mirai
File size:2'695 bytes
First seen:2025-09-06 06:45:46 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v3XOR3GmR3gSR3yCR34yR3soiR3btoR3ISR31KR3iqR3QUR3A5aR3LGR30Ue:v3XI3Gg3gk3yU34E3703bE3Ik31c3i8N
TLSH T1FE5192C6F32446B06FF29E5A71B9B404B090B1665FD11A11D8FC3CBAE44EF087492A5B
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.162.114.77/bins/sora.x86c4fdffa36b13e3742a38317302b552e0142055d028e43ef4ccbbdbfa0b208342 Miraielf mirai
http://38.162.114.77/bins/sora.mips518bb7ecad7786975b925e68c15f70746e6ab02508deb8bbbc8b8cc5cc597355 Miraielf mirai
http://38.162.114.77/bins/sora.x86_64n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i468n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i686n/an/aelf ua-wget
http://38.162.114.77/bins/sora.mpslcb66f0b9bfb996b5e4fe142cd03b3061b9843899675d93690e5474e87ef1bef2 Miraielf mirai
http://38.162.114.77/bins/sora.arm4n/an/aelf ua-wget
http://38.162.114.77/bins/sora.arm512486e4b57bd5ee074988b64d0716aa9c631aeb5805d8fc7664063d5a98dfaac Miraielf mirai
http://38.162.114.77/bins/sora.arm6e7b1d9504e3f6186d5c26f39932d0327b4ba22e04bf6e32e78ae72ca6969bd8c Miraielf mirai
http://38.162.114.77/bins/sora.arm77a0d000d79bc1be7a41fa59d1892995ff61815d4dbeb49f6d7053da7034a1598 Miraielf mirai
http://38.162.114.77/bins/sora.ppcadfb9de9a74d82e9d980515498e5d02b527961d37375a76e784404d059676f85 Miraielf mirai
http://38.162.114.77/bins/sora.ppc440fpn/an/aelf ua-wget
http://38.162.114.77/bins/sora.m68k6d1d1df496a3ab3aa77e2536fc9fcb09ed3b6653b77c27e305aba647bc5f2193 Miraielf mirai
http://38.162.114.77/bins/sora.sh438e47119b088297ba98fe3db4022607ff33af93d40ebc4991de353a424d180cc Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T03:53:00Z UTC
Last seen:
2025-09-06T03:53:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.c HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=2785440c-1a00-0000-ac05-a7bc1d0c0000 pid=3101 /usr/bin/sudo guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105 /tmp/sample.bin guuid=2785440c-1a00-0000-ac05-a7bc1d0c0000 pid=3101->guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105 execve guuid=60e1620f-1a00-0000-ac05-a7bc230c0000 pid=3107 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=60e1620f-1a00-0000-ac05-a7bc230c0000 pid=3107 execve guuid=76edcf2b-1a00-0000-ac05-a7bc670c0000 pid=3175 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=76edcf2b-1a00-0000-ac05-a7bc670c0000 pid=3175 execve guuid=43e7414f-1a00-0000-ac05-a7bc8e0c0000 pid=3214 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=43e7414f-1a00-0000-ac05-a7bc8e0c0000 pid=3214 execve guuid=1f31b34f-1a00-0000-ac05-a7bc8f0c0000 pid=3215 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=1f31b34f-1a00-0000-ac05-a7bc8f0c0000 pid=3215 execve guuid=b8451050-1a00-0000-ac05-a7bc900c0000 pid=3216 /tmp/robben net guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=b8451050-1a00-0000-ac05-a7bc900c0000 pid=3216 execve guuid=63dc6a53-1a00-0000-ac05-a7bc910c0000 pid=3217 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=63dc6a53-1a00-0000-ac05-a7bc910c0000 pid=3217 execve guuid=daa9766f-1a00-0000-ac05-a7bca80c0000 pid=3240 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=daa9766f-1a00-0000-ac05-a7bca80c0000 pid=3240 execve guuid=ff771b8f-1a00-0000-ac05-a7bceb0c0000 pid=3307 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=ff771b8f-1a00-0000-ac05-a7bceb0c0000 pid=3307 execve guuid=775f998f-1a00-0000-ac05-a7bcec0c0000 pid=3308 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=775f998f-1a00-0000-ac05-a7bcec0c0000 pid=3308 execve guuid=4b36e28f-1a00-0000-ac05-a7bcee0c0000 pid=3310 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=4b36e28f-1a00-0000-ac05-a7bcee0c0000 pid=3310 clone guuid=7b829992-1a00-0000-ac05-a7bcf70c0000 pid=3319 /usr/bin/wget net send-data guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7b829992-1a00-0000-ac05-a7bcf70c0000 pid=3319 execve guuid=033d6ca5-1a00-0000-ac05-a7bc090d0000 pid=3337 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=033d6ca5-1a00-0000-ac05-a7bc090d0000 pid=3337 execve guuid=cb709db9-1a00-0000-ac05-a7bc380d0000 pid=3384 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=cb709db9-1a00-0000-ac05-a7bc380d0000 pid=3384 execve guuid=9898f0b9-1a00-0000-ac05-a7bc390d0000 pid=3385 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=9898f0b9-1a00-0000-ac05-a7bc390d0000 pid=3385 execve guuid=216d3aba-1a00-0000-ac05-a7bc3b0d0000 pid=3387 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=216d3aba-1a00-0000-ac05-a7bc3b0d0000 pid=3387 clone guuid=d0fe5eba-1a00-0000-ac05-a7bc3c0d0000 pid=3388 /usr/bin/wget net send-data guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=d0fe5eba-1a00-0000-ac05-a7bc3c0d0000 pid=3388 execve guuid=0341e6cc-1a00-0000-ac05-a7bc700d0000 pid=3440 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=0341e6cc-1a00-0000-ac05-a7bc700d0000 pid=3440 execve guuid=baa8e7e1-1a00-0000-ac05-a7bcb20d0000 pid=3506 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=baa8e7e1-1a00-0000-ac05-a7bcb20d0000 pid=3506 execve guuid=9c0f3be2-1a00-0000-ac05-a7bcb30d0000 pid=3507 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=9c0f3be2-1a00-0000-ac05-a7bcb30d0000 pid=3507 execve guuid=617781e2-1a00-0000-ac05-a7bcb40d0000 pid=3508 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=617781e2-1a00-0000-ac05-a7bcb40d0000 pid=3508 clone guuid=7296a6e2-1a00-0000-ac05-a7bcb50d0000 pid=3509 /usr/bin/wget net send-data guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7296a6e2-1a00-0000-ac05-a7bcb50d0000 pid=3509 execve guuid=ccf9f0f4-1a00-0000-ac05-a7bcdb0d0000 pid=3547 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=ccf9f0f4-1a00-0000-ac05-a7bcdb0d0000 pid=3547 execve guuid=fac94409-1b00-0000-ac05-a7bc0b0e0000 pid=3595 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=fac94409-1b00-0000-ac05-a7bc0b0e0000 pid=3595 execve guuid=1a2ec209-1b00-0000-ac05-a7bc0e0e0000 pid=3598 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=1a2ec209-1b00-0000-ac05-a7bc0e0e0000 pid=3598 execve guuid=1c21290a-1b00-0000-ac05-a7bc0f0e0000 pid=3599 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=1c21290a-1b00-0000-ac05-a7bc0f0e0000 pid=3599 clone guuid=7a2a600a-1b00-0000-ac05-a7bc110e0000 pid=3601 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7a2a600a-1b00-0000-ac05-a7bc110e0000 pid=3601 execve guuid=2a5ba526-1b00-0000-ac05-a7bc630e0000 pid=3683 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=2a5ba526-1b00-0000-ac05-a7bc630e0000 pid=3683 execve guuid=b7386b46-1b00-0000-ac05-a7bca70e0000 pid=3751 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=b7386b46-1b00-0000-ac05-a7bca70e0000 pid=3751 execve guuid=f60fe846-1b00-0000-ac05-a7bcac0e0000 pid=3756 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=f60fe846-1b00-0000-ac05-a7bcac0e0000 pid=3756 execve guuid=d9df3247-1b00-0000-ac05-a7bcad0e0000 pid=3757 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=d9df3247-1b00-0000-ac05-a7bcad0e0000 pid=3757 clone guuid=26487749-1b00-0000-ac05-a7bcba0e0000 pid=3770 /usr/bin/wget net send-data guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=26487749-1b00-0000-ac05-a7bcba0e0000 pid=3770 execve guuid=3a41dc5d-1b00-0000-ac05-a7bcda0e0000 pid=3802 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=3a41dc5d-1b00-0000-ac05-a7bcda0e0000 pid=3802 execve guuid=75ce9471-1b00-0000-ac05-a7bcdb0e0000 pid=3803 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=75ce9471-1b00-0000-ac05-a7bcdb0e0000 pid=3803 execve guuid=85ea0b7c-1b00-0000-ac05-a7bcde0e0000 pid=3806 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=85ea0b7c-1b00-0000-ac05-a7bcde0e0000 pid=3806 execve guuid=11fe687c-1b00-0000-ac05-a7bce10e0000 pid=3809 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=11fe687c-1b00-0000-ac05-a7bce10e0000 pid=3809 clone guuid=1a85cb7c-1b00-0000-ac05-a7bce40e0000 pid=3812 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=1a85cb7c-1b00-0000-ac05-a7bce40e0000 pid=3812 execve guuid=4e878a97-1b00-0000-ac05-a7bc360f0000 pid=3894 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=4e878a97-1b00-0000-ac05-a7bc360f0000 pid=3894 execve guuid=a3b5c3b4-1b00-0000-ac05-a7bc8c0f0000 pid=3980 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=a3b5c3b4-1b00-0000-ac05-a7bc8c0f0000 pid=3980 execve guuid=e71a45b5-1b00-0000-ac05-a7bc8e0f0000 pid=3982 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=e71a45b5-1b00-0000-ac05-a7bc8e0f0000 pid=3982 execve guuid=9f99c5b5-1b00-0000-ac05-a7bc900f0000 pid=3984 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=9f99c5b5-1b00-0000-ac05-a7bc900f0000 pid=3984 clone guuid=a981dab7-1b00-0000-ac05-a7bc960f0000 pid=3990 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=a981dab7-1b00-0000-ac05-a7bc960f0000 pid=3990 execve guuid=34429ad3-1b00-0000-ac05-a7bced0f0000 pid=4077 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=34429ad3-1b00-0000-ac05-a7bced0f0000 pid=4077 execve guuid=aad098f1-1b00-0000-ac05-a7bc54100000 pid=4180 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=aad098f1-1b00-0000-ac05-a7bc54100000 pid=4180 execve guuid=2d756df2-1b00-0000-ac05-a7bc58100000 pid=4184 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=2d756df2-1b00-0000-ac05-a7bc58100000 pid=4184 execve guuid=3bf309f3-1b00-0000-ac05-a7bc5b100000 pid=4187 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=3bf309f3-1b00-0000-ac05-a7bc5b100000 pid=4187 clone guuid=227ab2f3-1b00-0000-ac05-a7bc60100000 pid=4192 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=227ab2f3-1b00-0000-ac05-a7bc60100000 pid=4192 execve guuid=0058fd17-1c00-0000-ac05-a7bce2100000 pid=4322 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=0058fd17-1c00-0000-ac05-a7bce2100000 pid=4322 execve guuid=97f60f3d-1c00-0000-ac05-a7bc6e110000 pid=4462 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=97f60f3d-1c00-0000-ac05-a7bc6e110000 pid=4462 execve guuid=e526873d-1c00-0000-ac05-a7bc70110000 pid=4464 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=e526873d-1c00-0000-ac05-a7bc70110000 pid=4464 execve guuid=5a45f73d-1c00-0000-ac05-a7bc72110000 pid=4466 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=5a45f73d-1c00-0000-ac05-a7bc72110000 pid=4466 clone guuid=6ebfdb3e-1c00-0000-ac05-a7bc76110000 pid=4470 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=6ebfdb3e-1c00-0000-ac05-a7bc76110000 pid=4470 execve guuid=7f3c6159-1c00-0000-ac05-a7bcd9110000 pid=4569 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7f3c6159-1c00-0000-ac05-a7bcd9110000 pid=4569 execve guuid=62449688-1c00-0000-ac05-a7bc36120000 pid=4662 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=62449688-1c00-0000-ac05-a7bc36120000 pid=4662 execve guuid=c6390089-1c00-0000-ac05-a7bc37120000 pid=4663 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=c6390089-1c00-0000-ac05-a7bc37120000 pid=4663 execve guuid=52b15a89-1c00-0000-ac05-a7bc39120000 pid=4665 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=52b15a89-1c00-0000-ac05-a7bc39120000 pid=4665 clone guuid=bb6bf789-1c00-0000-ac05-a7bc3c120000 pid=4668 /usr/bin/wget net send-data guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=bb6bf789-1c00-0000-ac05-a7bc3c120000 pid=4668 execve guuid=7a43339c-1c00-0000-ac05-a7bc6e120000 pid=4718 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7a43339c-1c00-0000-ac05-a7bc6e120000 pid=4718 execve guuid=75a11eb0-1c00-0000-ac05-a7bc9f120000 pid=4767 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=75a11eb0-1c00-0000-ac05-a7bc9f120000 pid=4767 execve guuid=89a89bb0-1c00-0000-ac05-a7bca3120000 pid=4771 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=89a89bb0-1c00-0000-ac05-a7bca3120000 pid=4771 execve guuid=db190cb1-1c00-0000-ac05-a7bca5120000 pid=4773 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=db190cb1-1c00-0000-ac05-a7bca5120000 pid=4773 clone guuid=db5b49b1-1c00-0000-ac05-a7bca8120000 pid=4776 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=db5b49b1-1c00-0000-ac05-a7bca8120000 pid=4776 execve guuid=e85207d6-1c00-0000-ac05-a7bcfc120000 pid=4860 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=e85207d6-1c00-0000-ac05-a7bcfc120000 pid=4860 execve guuid=15bfebfe-1c00-0000-ac05-a7bc71130000 pid=4977 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=15bfebfe-1c00-0000-ac05-a7bc71130000 pid=4977 execve guuid=7e314aff-1c00-0000-ac05-a7bc73130000 pid=4979 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=7e314aff-1c00-0000-ac05-a7bc73130000 pid=4979 execve guuid=5fbdaaff-1c00-0000-ac05-a7bc76130000 pid=4982 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=5fbdaaff-1c00-0000-ac05-a7bc76130000 pid=4982 clone guuid=26b90402-1d00-0000-ac05-a7bc7d130000 pid=4989 /usr/bin/wget net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=26b90402-1d00-0000-ac05-a7bc7d130000 pid=4989 execve guuid=cce4be27-1d00-0000-ac05-a7bcd9130000 pid=5081 /usr/bin/curl net send-data write-file guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=cce4be27-1d00-0000-ac05-a7bcd9130000 pid=5081 execve guuid=bf0e1c50-1d00-0000-ac05-a7bc59140000 pid=5209 /usr/bin/cat guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=bf0e1c50-1d00-0000-ac05-a7bc59140000 pid=5209 execve guuid=31718350-1d00-0000-ac05-a7bc5b140000 pid=5211 /usr/bin/chmod guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=31718350-1d00-0000-ac05-a7bc5b140000 pid=5211 execve guuid=f4d4d350-1d00-0000-ac05-a7bc5c140000 pid=5212 /usr/bin/bash guuid=23de070f-1a00-0000-ac05-a7bc210c0000 pid=3105->guuid=f4d4d350-1d00-0000-ac05-a7bc5c140000 pid=5212 clone e10eb183-c74b-539a-bc26-e43bbf2bbb51 38.162.114.77:80 guuid=60e1620f-1a00-0000-ac05-a7bc230c0000 pid=3107->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=76edcf2b-1a00-0000-ac05-a7bc670c0000 pid=3175->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b8451050-1a00-0000-ac05-a7bc900c0000 pid=3216->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=63dc6a53-1a00-0000-ac05-a7bc910c0000 pid=3217->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=daa9766f-1a00-0000-ac05-a7bca80c0000 pid=3240->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7b829992-1a00-0000-ac05-a7bcf70c0000 pid=3319->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 144B guuid=033d6ca5-1a00-0000-ac05-a7bc090d0000 pid=3337->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 93B guuid=d0fe5eba-1a00-0000-ac05-a7bc3c0d0000 pid=3388->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0341e6cc-1a00-0000-ac05-a7bc700d0000 pid=3440->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7296a6e2-1a00-0000-ac05-a7bcb50d0000 pid=3509->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=ccf9f0f4-1a00-0000-ac05-a7bcdb0d0000 pid=3547->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7a2a600a-1b00-0000-ac05-a7bc110e0000 pid=3601->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=2a5ba526-1b00-0000-ac05-a7bc630e0000 pid=3683->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=26487749-1b00-0000-ac05-a7bcba0e0000 pid=3770->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=3a41dc5d-1b00-0000-ac05-a7bcda0e0000 pid=3802->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=1a85cb7c-1b00-0000-ac05-a7bce40e0000 pid=3812->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=4e878a97-1b00-0000-ac05-a7bc360f0000 pid=3894->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=a981dab7-1b00-0000-ac05-a7bc960f0000 pid=3990->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=34429ad3-1b00-0000-ac05-a7bced0f0000 pid=4077->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=227ab2f3-1b00-0000-ac05-a7bc60100000 pid=4192->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0058fd17-1c00-0000-ac05-a7bce2100000 pid=4322->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=6ebfdb3e-1c00-0000-ac05-a7bc76110000 pid=4470->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=7f3c6159-1c00-0000-ac05-a7bcd9110000 pid=4569->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B guuid=bb6bf789-1c00-0000-ac05-a7bc3c120000 pid=4668->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 146B guuid=7a43339c-1c00-0000-ac05-a7bc6e120000 pid=4718->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 95B guuid=db5b49b1-1c00-0000-ac05-a7bca8120000 pid=4776->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=e85207d6-1c00-0000-ac05-a7bcfc120000 pid=4860->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=26b90402-1d00-0000-ac05-a7bc7d130000 pid=4989->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=cce4be27-1d00-0000-ac05-a7bcd9130000 pid=5081->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 06:31:18 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (38097) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh a0c8570dde73fc647c8a7d6cb0b1ac0585ec065b01c91223402e91844a1fea5c

(this sample)

Comments