MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a700a9bfb68fe0eaae7b36b7961dd597fc898a97309a5ad5737d11d804cee7a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: a700a9bfb68fe0eaae7b36b7961dd597fc898a97309a5ad5737d11d804cee7a0
SHA3-384 hash: 3a5c88bd76f7ce0b819b75180c00e679d412a8d2a2be71afdb3cee5bd229dbb7eecd195f73700d189203b733625c9dfc
SHA1 hash: cfeaa0373b9e372a31c69c5b67c51cbf1b15d38d
MD5 hash: 9ff74c34d4d0abef9e1dfddb6746748d
humanhash: mango-nitrogen-fourteen-florida
File name:goahead
Download: download sample
File size:2'451 bytes
First seen:2025-07-10 13:02:05 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxS+rx0xX9PrxuwxujyrxZxamrxyxlzrxbx0Urx8xf9rxGxpDrxdxuirxnxAH:vlTS+liX9Plb6yl7amlQlzlV0UlKf9lN
TLSH T1CB51A2F61145073D6CF2996E31F689C8B6A196C720C2DF8595FC38F6409DE483DA2E8A
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=a6d8288b-1b00-0000-8dbd-1512710c0000 pid=3185 /usr/bin/sudo guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191 /tmp/sample.bin guuid=a6d8288b-1b00-0000-8dbd-1512710c0000 pid=3185->guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191 execve guuid=2538738d-1b00-0000-8dbd-1512790c0000 pid=3193 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=2538738d-1b00-0000-8dbd-1512790c0000 pid=3193 execve guuid=a784f491-1b00-0000-8dbd-1512800c0000 pid=3200 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=a784f491-1b00-0000-8dbd-1512800c0000 pid=3200 execve guuid=5b60eb98-1b00-0000-8dbd-15128c0c0000 pid=3212 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=5b60eb98-1b00-0000-8dbd-15128c0c0000 pid=3212 execve guuid=38e29b99-1b00-0000-8dbd-15128d0c0000 pid=3213 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=38e29b99-1b00-0000-8dbd-15128d0c0000 pid=3213 execve guuid=f9eb2a9a-1b00-0000-8dbd-15128e0c0000 pid=3214 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=f9eb2a9a-1b00-0000-8dbd-15128e0c0000 pid=3214 clone guuid=b91a899a-1b00-0000-8dbd-15128f0c0000 pid=3215 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=b91a899a-1b00-0000-8dbd-15128f0c0000 pid=3215 execve guuid=f5cc189d-1b00-0000-8dbd-1512900c0000 pid=3216 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=f5cc189d-1b00-0000-8dbd-1512900c0000 pid=3216 execve guuid=78551ca1-1b00-0000-8dbd-1512910c0000 pid=3217 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=78551ca1-1b00-0000-8dbd-1512910c0000 pid=3217 execve guuid=3573a7a1-1b00-0000-8dbd-1512920c0000 pid=3218 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=3573a7a1-1b00-0000-8dbd-1512920c0000 pid=3218 execve guuid=e8fb0ea2-1b00-0000-8dbd-1512930c0000 pid=3219 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=e8fb0ea2-1b00-0000-8dbd-1512930c0000 pid=3219 clone guuid=529b4ca2-1b00-0000-8dbd-1512940c0000 pid=3220 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=529b4ca2-1b00-0000-8dbd-1512940c0000 pid=3220 execve guuid=05bbafa4-1b00-0000-8dbd-1512950c0000 pid=3221 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=05bbafa4-1b00-0000-8dbd-1512950c0000 pid=3221 execve guuid=b74d54a8-1b00-0000-8dbd-1512960c0000 pid=3222 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=b74d54a8-1b00-0000-8dbd-1512960c0000 pid=3222 execve guuid=9220b9b6-1b00-0000-8dbd-1512970c0000 pid=3223 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=9220b9b6-1b00-0000-8dbd-1512970c0000 pid=3223 execve guuid=408f69b7-1b00-0000-8dbd-1512980c0000 pid=3224 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=408f69b7-1b00-0000-8dbd-1512980c0000 pid=3224 clone guuid=a172b1b7-1b00-0000-8dbd-1512990c0000 pid=3225 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=a172b1b7-1b00-0000-8dbd-1512990c0000 pid=3225 execve guuid=ca97c2ba-1b00-0000-8dbd-15129a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=ca97c2ba-1b00-0000-8dbd-15129a0c0000 pid=3226 execve guuid=fc8b7ebd-1b00-0000-8dbd-15129c0c0000 pid=3228 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=fc8b7ebd-1b00-0000-8dbd-15129c0c0000 pid=3228 execve guuid=61cf26c4-1b00-0000-8dbd-1512a30c0000 pid=3235 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=61cf26c4-1b00-0000-8dbd-1512a30c0000 pid=3235 execve guuid=ed86c1c4-1b00-0000-8dbd-1512a50c0000 pid=3237 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=ed86c1c4-1b00-0000-8dbd-1512a50c0000 pid=3237 clone guuid=f78a1ec5-1b00-0000-8dbd-1512a60c0000 pid=3238 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=f78a1ec5-1b00-0000-8dbd-1512a60c0000 pid=3238 execve guuid=0fcccbc7-1b00-0000-8dbd-1512ad0c0000 pid=3245 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=0fcccbc7-1b00-0000-8dbd-1512ad0c0000 pid=3245 execve guuid=da48e6ca-1b00-0000-8dbd-1512b30c0000 pid=3251 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=da48e6ca-1b00-0000-8dbd-1512b30c0000 pid=3251 execve guuid=8b9d40cb-1b00-0000-8dbd-1512b50c0000 pid=3253 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=8b9d40cb-1b00-0000-8dbd-1512b50c0000 pid=3253 execve guuid=7a4d85cb-1b00-0000-8dbd-1512b70c0000 pid=3255 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=7a4d85cb-1b00-0000-8dbd-1512b70c0000 pid=3255 clone guuid=0f11b5cb-1b00-0000-8dbd-1512b80c0000 pid=3256 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=0f11b5cb-1b00-0000-8dbd-1512b80c0000 pid=3256 execve guuid=8d9dddcd-1b00-0000-8dbd-1512b90c0000 pid=3257 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=8d9dddcd-1b00-0000-8dbd-1512b90c0000 pid=3257 execve guuid=396016d4-1b00-0000-8dbd-1512bb0c0000 pid=3259 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=396016d4-1b00-0000-8dbd-1512bb0c0000 pid=3259 execve guuid=fd32b3d4-1b00-0000-8dbd-1512bc0c0000 pid=3260 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=fd32b3d4-1b00-0000-8dbd-1512bc0c0000 pid=3260 execve guuid=9e0555d5-1b00-0000-8dbd-1512bd0c0000 pid=3261 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=9e0555d5-1b00-0000-8dbd-1512bd0c0000 pid=3261 clone guuid=d5b892d5-1b00-0000-8dbd-1512be0c0000 pid=3262 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=d5b892d5-1b00-0000-8dbd-1512be0c0000 pid=3262 execve guuid=8fbc81d8-1b00-0000-8dbd-1512c40c0000 pid=3268 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=8fbc81d8-1b00-0000-8dbd-1512c40c0000 pid=3268 execve guuid=a5b026dd-1b00-0000-8dbd-1512cd0c0000 pid=3277 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=a5b026dd-1b00-0000-8dbd-1512cd0c0000 pid=3277 execve guuid=7578dcdd-1b00-0000-8dbd-1512cf0c0000 pid=3279 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=7578dcdd-1b00-0000-8dbd-1512cf0c0000 pid=3279 execve guuid=295a81de-1b00-0000-8dbd-1512d00c0000 pid=3280 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=295a81de-1b00-0000-8dbd-1512d00c0000 pid=3280 clone guuid=92bdeede-1b00-0000-8dbd-1512d10c0000 pid=3281 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=92bdeede-1b00-0000-8dbd-1512d10c0000 pid=3281 execve guuid=9f2da2e1-1b00-0000-8dbd-1512d60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=9f2da2e1-1b00-0000-8dbd-1512d60c0000 pid=3286 execve guuid=beb3dae5-1b00-0000-8dbd-1512dd0c0000 pid=3293 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=beb3dae5-1b00-0000-8dbd-1512dd0c0000 pid=3293 execve guuid=6b8050e6-1b00-0000-8dbd-1512df0c0000 pid=3295 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=6b8050e6-1b00-0000-8dbd-1512df0c0000 pid=3295 execve guuid=ab15d8e6-1b00-0000-8dbd-1512e20c0000 pid=3298 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=ab15d8e6-1b00-0000-8dbd-1512e20c0000 pid=3298 clone guuid=695034e7-1b00-0000-8dbd-1512e30c0000 pid=3299 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=695034e7-1b00-0000-8dbd-1512e30c0000 pid=3299 execve guuid=9bb29de9-1b00-0000-8dbd-1512e80c0000 pid=3304 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=9bb29de9-1b00-0000-8dbd-1512e80c0000 pid=3304 execve guuid=931d53ed-1b00-0000-8dbd-1512f00c0000 pid=3312 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=931d53ed-1b00-0000-8dbd-1512f00c0000 pid=3312 execve guuid=a1a8fced-1b00-0000-8dbd-1512f20c0000 pid=3314 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=a1a8fced-1b00-0000-8dbd-1512f20c0000 pid=3314 execve guuid=b1796eee-1b00-0000-8dbd-1512f40c0000 pid=3316 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=b1796eee-1b00-0000-8dbd-1512f40c0000 pid=3316 clone guuid=7e8ab5ee-1b00-0000-8dbd-1512f60c0000 pid=3318 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=7e8ab5ee-1b00-0000-8dbd-1512f60c0000 pid=3318 execve guuid=21907bf0-1b00-0000-8dbd-1512fd0c0000 pid=3325 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=21907bf0-1b00-0000-8dbd-1512fd0c0000 pid=3325 execve guuid=c1ad12f3-1b00-0000-8dbd-1512050d0000 pid=3333 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=c1ad12f3-1b00-0000-8dbd-1512050d0000 pid=3333 execve guuid=2af05ff3-1b00-0000-8dbd-1512070d0000 pid=3335 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=2af05ff3-1b00-0000-8dbd-1512070d0000 pid=3335 execve guuid=fe5d9ff3-1b00-0000-8dbd-1512090d0000 pid=3337 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=fe5d9ff3-1b00-0000-8dbd-1512090d0000 pid=3337 clone guuid=746fc0f3-1b00-0000-8dbd-15120a0d0000 pid=3338 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=746fc0f3-1b00-0000-8dbd-15120a0d0000 pid=3338 execve guuid=9efd7bf5-1b00-0000-8dbd-15120f0d0000 pid=3343 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=9efd7bf5-1b00-0000-8dbd-15120f0d0000 pid=3343 execve guuid=55f2f9f7-1b00-0000-8dbd-1512160d0000 pid=3350 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=55f2f9f7-1b00-0000-8dbd-1512160d0000 pid=3350 execve guuid=f13f74f8-1b00-0000-8dbd-1512180d0000 pid=3352 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=f13f74f8-1b00-0000-8dbd-1512180d0000 pid=3352 execve guuid=2b5cd5f8-1b00-0000-8dbd-15121a0d0000 pid=3354 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=2b5cd5f8-1b00-0000-8dbd-15121a0d0000 pid=3354 clone guuid=64ba05f9-1b00-0000-8dbd-15121b0d0000 pid=3355 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=64ba05f9-1b00-0000-8dbd-15121b0d0000 pid=3355 execve guuid=f5d8effa-1b00-0000-8dbd-1512230d0000 pid=3363 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=f5d8effa-1b00-0000-8dbd-1512230d0000 pid=3363 execve guuid=4db790fd-1b00-0000-8dbd-15122d0d0000 pid=3373 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=4db790fd-1b00-0000-8dbd-15122d0d0000 pid=3373 execve guuid=078bfffd-1b00-0000-8dbd-15122f0d0000 pid=3375 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=078bfffd-1b00-0000-8dbd-15122f0d0000 pid=3375 execve guuid=50215bfe-1b00-0000-8dbd-1512300d0000 pid=3376 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=50215bfe-1b00-0000-8dbd-1512300d0000 pid=3376 clone guuid=e0708afe-1b00-0000-8dbd-1512320d0000 pid=3378 /usr/bin/wget net send-data guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=e0708afe-1b00-0000-8dbd-1512320d0000 pid=3378 execve guuid=fb776300-1c00-0000-8dbd-1512380d0000 pid=3384 /usr/bin/curl net send-data write-file guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=fb776300-1c00-0000-8dbd-1512380d0000 pid=3384 execve guuid=93ff2303-1c00-0000-8dbd-15123d0d0000 pid=3389 /usr/bin/cat guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=93ff2303-1c00-0000-8dbd-15123d0d0000 pid=3389 execve guuid=b5868203-1c00-0000-8dbd-15123f0d0000 pid=3391 /usr/bin/chmod guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=b5868203-1c00-0000-8dbd-15123f0d0000 pid=3391 execve guuid=4be7eb03-1c00-0000-8dbd-1512410d0000 pid=3393 /usr/bin/bash guuid=4fcaff8c-1b00-0000-8dbd-1512770c0000 pid=3191->guuid=4be7eb03-1c00-0000-8dbd-1512410d0000 pid=3393 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=2538738d-1b00-0000-8dbd-1512790c0000 pid=3193->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=a784f491-1b00-0000-8dbd-1512800c0000 pid=3200->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=b91a899a-1b00-0000-8dbd-15128f0c0000 pid=3215->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=f5cc189d-1b00-0000-8dbd-1512900c0000 pid=3216->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=529b4ca2-1b00-0000-8dbd-1512940c0000 pid=3220->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=05bbafa4-1b00-0000-8dbd-1512950c0000 pid=3221->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=a172b1b7-1b00-0000-8dbd-1512990c0000 pid=3225->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=ca97c2ba-1b00-0000-8dbd-15129a0c0000 pid=3226->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=f78a1ec5-1b00-0000-8dbd-1512a60c0000 pid=3238->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=0fcccbc7-1b00-0000-8dbd-1512ad0c0000 pid=3245->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=0f11b5cb-1b00-0000-8dbd-1512b80c0000 pid=3256->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=8d9dddcd-1b00-0000-8dbd-1512b90c0000 pid=3257->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=d5b892d5-1b00-0000-8dbd-1512be0c0000 pid=3262->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=8fbc81d8-1b00-0000-8dbd-1512c40c0000 pid=3268->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=92bdeede-1b00-0000-8dbd-1512d10c0000 pid=3281->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=9f2da2e1-1b00-0000-8dbd-1512d60c0000 pid=3286->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=695034e7-1b00-0000-8dbd-1512e30c0000 pid=3299->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=9bb29de9-1b00-0000-8dbd-1512e80c0000 pid=3304->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=7e8ab5ee-1b00-0000-8dbd-1512f60c0000 pid=3318->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=21907bf0-1b00-0000-8dbd-1512fd0c0000 pid=3325->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=746fc0f3-1b00-0000-8dbd-15120a0d0000 pid=3338->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=9efd7bf5-1b00-0000-8dbd-15120f0d0000 pid=3343->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=64ba05f9-1b00-0000-8dbd-15121b0d0000 pid=3355->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=f5d8effa-1b00-0000-8dbd-1512230d0000 pid=3363->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=e0708afe-1b00-0000-8dbd-1512320d0000 pid=3378->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=fb776300-1c00-0000-8dbd-1512380d0000 pid=3384->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:03:19 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a700a9bfb68fe0eaae7b36b7961dd597fc898a97309a5ad5737d11d804cee7a0

(this sample)

  
Delivery method
Distributed via web download

Comments