MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b5a94259016263d3b72b80dbbbdf5f2df0d358c53d34b01874c8efc7c66dd37b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: b5a94259016263d3b72b80dbbbdf5f2df0d358c53d34b01874c8efc7c66dd37b
SHA3-384 hash: 0de834a5e5777d5f5152e75a45d73c32e6d5e45f79e27663b8ee4a7cb2dee5c3a2953d64945cb1cf5da4ff172a097737
SHA1 hash: 81018d3c4f4c9d90499ca54d51a4dfead72ee5d5
MD5 hash: d48959d4f84c7fb8a961e8a69c3140b2
humanhash: steak-speaker-carbon-nebraska
File name:gpon443
Download: download sample
File size:2'451 bytes
First seen:2025-07-10 13:02:04 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vrxxxSmrx0xX9HrxuwxujCrxZxaurxyxlDrxbx0srx8xfVrxGxpTrxdxuyrxnxA/:vlTSmliX9Hlb6Cl7aulQlDlV0slKfVl1
TLSH T1FA518CF50155073DACF2996E31FB89C8F6A1968A30C29F8495FC38E5404DE583DB2E8E
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://206.123.128.90/main_x86n/an/an/a
http://206.123.128.90/main_mipsn/an/an/a
http://206.123.128.90/main_mpsln/an/an/a
http://206.123.128.90/main_armn/an/an/a
http://206.123.128.90/main_arm5n/an/an/a
http://206.123.128.90/main_arm6n/an/an/a
http://206.123.128.90/main_arm7n/an/an/a
http://206.123.128.90/main_ppcn/an/an/a
http://206.123.128.90/main_m68kn/an/an/a
http://206.123.128.90/main_spcn/an/an/a
http://206.123.128.90/main_i686n/an/an/a
http://206.123.128.90/main_sh4n/an/an/a
http://206.123.128.90/main_arcn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
21
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=c02c133f-2000-0000-b48d-e1401d0b0000 pid=2845 /usr/bin/sudo guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850 /tmp/sample.bin guuid=c02c133f-2000-0000-b48d-e1401d0b0000 pid=2845->guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850 execve guuid=eec06142-2000-0000-b48d-e140240b0000 pid=2852 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=eec06142-2000-0000-b48d-e140240b0000 pid=2852 execve guuid=40847a46-2000-0000-b48d-e1402f0b0000 pid=2863 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=40847a46-2000-0000-b48d-e1402f0b0000 pid=2863 execve guuid=04f06b52-2000-0000-b48d-e140480b0000 pid=2888 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=04f06b52-2000-0000-b48d-e140480b0000 pid=2888 execve guuid=44e7c252-2000-0000-b48d-e1404a0b0000 pid=2890 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=44e7c252-2000-0000-b48d-e1404a0b0000 pid=2890 execve guuid=111c1553-2000-0000-b48d-e1404b0b0000 pid=2891 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=111c1553-2000-0000-b48d-e1404b0b0000 pid=2891 clone guuid=9de93c53-2000-0000-b48d-e1404d0b0000 pid=2893 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=9de93c53-2000-0000-b48d-e1404d0b0000 pid=2893 execve guuid=82bd1655-2000-0000-b48d-e140510b0000 pid=2897 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=82bd1655-2000-0000-b48d-e140510b0000 pid=2897 execve guuid=164a5d62-2000-0000-b48d-e1405b0b0000 pid=2907 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=164a5d62-2000-0000-b48d-e1405b0b0000 pid=2907 execve guuid=4d66b862-2000-0000-b48d-e1405c0b0000 pid=2908 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=4d66b862-2000-0000-b48d-e1405c0b0000 pid=2908 execve guuid=8d27fc62-2000-0000-b48d-e1405d0b0000 pid=2909 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=8d27fc62-2000-0000-b48d-e1405d0b0000 pid=2909 clone guuid=4cec2963-2000-0000-b48d-e1405e0b0000 pid=2910 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=4cec2963-2000-0000-b48d-e1405e0b0000 pid=2910 execve guuid=cb7baa65-2000-0000-b48d-e140600b0000 pid=2912 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=cb7baa65-2000-0000-b48d-e140600b0000 pid=2912 execve guuid=6477e968-2000-0000-b48d-e140680b0000 pid=2920 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=6477e968-2000-0000-b48d-e140680b0000 pid=2920 execve guuid=3d046c69-2000-0000-b48d-e1406a0b0000 pid=2922 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=3d046c69-2000-0000-b48d-e1406a0b0000 pid=2922 execve guuid=9ca3d469-2000-0000-b48d-e1406c0b0000 pid=2924 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=9ca3d469-2000-0000-b48d-e1406c0b0000 pid=2924 clone guuid=83d6046a-2000-0000-b48d-e1406e0b0000 pid=2926 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=83d6046a-2000-0000-b48d-e1406e0b0000 pid=2926 execve guuid=abb0b56b-2000-0000-b48d-e140750b0000 pid=2933 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=abb0b56b-2000-0000-b48d-e140750b0000 pid=2933 execve guuid=3da0e570-2000-0000-b48d-e140780b0000 pid=2936 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=3da0e570-2000-0000-b48d-e140780b0000 pid=2936 execve guuid=12845271-2000-0000-b48d-e140790b0000 pid=2937 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=12845271-2000-0000-b48d-e140790b0000 pid=2937 execve guuid=f602a071-2000-0000-b48d-e1407a0b0000 pid=2938 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=f602a071-2000-0000-b48d-e1407a0b0000 pid=2938 clone guuid=67abc171-2000-0000-b48d-e1407b0b0000 pid=2939 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=67abc171-2000-0000-b48d-e1407b0b0000 pid=2939 execve guuid=79a7c673-2000-0000-b48d-e140820b0000 pid=2946 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=79a7c673-2000-0000-b48d-e140820b0000 pid=2946 execve guuid=9f0da076-2000-0000-b48d-e140890b0000 pid=2953 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=9f0da076-2000-0000-b48d-e140890b0000 pid=2953 execve guuid=3d3fff76-2000-0000-b48d-e1408b0b0000 pid=2955 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=3d3fff76-2000-0000-b48d-e1408b0b0000 pid=2955 execve guuid=51714b77-2000-0000-b48d-e1408c0b0000 pid=2956 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=51714b77-2000-0000-b48d-e1408c0b0000 pid=2956 clone guuid=eea47477-2000-0000-b48d-e1408d0b0000 pid=2957 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=eea47477-2000-0000-b48d-e1408d0b0000 pid=2957 execve guuid=7e79aa79-2000-0000-b48d-e140920b0000 pid=2962 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=7e79aa79-2000-0000-b48d-e140920b0000 pid=2962 execve guuid=f42b727c-2000-0000-b48d-e140980b0000 pid=2968 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=f42b727c-2000-0000-b48d-e140980b0000 pid=2968 execve guuid=1a99c47c-2000-0000-b48d-e1409a0b0000 pid=2970 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=1a99c47c-2000-0000-b48d-e1409a0b0000 pid=2970 execve guuid=99d51a7d-2000-0000-b48d-e1409c0b0000 pid=2972 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=99d51a7d-2000-0000-b48d-e1409c0b0000 pid=2972 clone guuid=ff4f487d-2000-0000-b48d-e1409d0b0000 pid=2973 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=ff4f487d-2000-0000-b48d-e1409d0b0000 pid=2973 execve guuid=ce854b7f-2000-0000-b48d-e140a30b0000 pid=2979 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=ce854b7f-2000-0000-b48d-e140a30b0000 pid=2979 execve guuid=2d3a4482-2000-0000-b48d-e140a90b0000 pid=2985 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=2d3a4482-2000-0000-b48d-e140a90b0000 pid=2985 execve guuid=28d3ba82-2000-0000-b48d-e140ab0b0000 pid=2987 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=28d3ba82-2000-0000-b48d-e140ab0b0000 pid=2987 execve guuid=b12e1983-2000-0000-b48d-e140ad0b0000 pid=2989 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=b12e1983-2000-0000-b48d-e140ad0b0000 pid=2989 clone guuid=dc364f83-2000-0000-b48d-e140af0b0000 pid=2991 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=dc364f83-2000-0000-b48d-e140af0b0000 pid=2991 execve guuid=a7a92e85-2000-0000-b48d-e140b40b0000 pid=2996 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=a7a92e85-2000-0000-b48d-e140b40b0000 pid=2996 execve guuid=8ffbff90-2000-0000-b48d-e140ca0b0000 pid=3018 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=8ffbff90-2000-0000-b48d-e140ca0b0000 pid=3018 execve guuid=4ff55891-2000-0000-b48d-e140cb0b0000 pid=3019 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=4ff55891-2000-0000-b48d-e140cb0b0000 pid=3019 execve guuid=011db391-2000-0000-b48d-e140cd0b0000 pid=3021 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=011db391-2000-0000-b48d-e140cd0b0000 pid=3021 clone guuid=bec18592-2000-0000-b48d-e140cf0b0000 pid=3023 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=bec18592-2000-0000-b48d-e140cf0b0000 pid=3023 execve guuid=a898af95-2000-0000-b48d-e140d20b0000 pid=3026 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=a898af95-2000-0000-b48d-e140d20b0000 pid=3026 execve guuid=8700539c-2000-0000-b48d-e140d30b0000 pid=3027 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=8700539c-2000-0000-b48d-e140d30b0000 pid=3027 execve guuid=872f42a9-2000-0000-b48d-e140d50b0000 pid=3029 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=872f42a9-2000-0000-b48d-e140d50b0000 pid=3029 execve guuid=b0c885a9-2000-0000-b48d-e140d60b0000 pid=3030 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=b0c885a9-2000-0000-b48d-e140d60b0000 pid=3030 clone guuid=9640a8a9-2000-0000-b48d-e140d70b0000 pid=3031 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=9640a8a9-2000-0000-b48d-e140d70b0000 pid=3031 execve guuid=39e794ab-2000-0000-b48d-e140dd0b0000 pid=3037 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=39e794ab-2000-0000-b48d-e140dd0b0000 pid=3037 execve guuid=85174bae-2000-0000-b48d-e140e40b0000 pid=3044 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=85174bae-2000-0000-b48d-e140e40b0000 pid=3044 execve guuid=e7c8c3ae-2000-0000-b48d-e140e60b0000 pid=3046 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=e7c8c3ae-2000-0000-b48d-e140e60b0000 pid=3046 execve guuid=2dc618af-2000-0000-b48d-e140e90b0000 pid=3049 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=2dc618af-2000-0000-b48d-e140e90b0000 pid=3049 clone guuid=02784baf-2000-0000-b48d-e140ea0b0000 pid=3050 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=02784baf-2000-0000-b48d-e140ea0b0000 pid=3050 execve guuid=4b1800b1-2000-0000-b48d-e140f00b0000 pid=3056 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=4b1800b1-2000-0000-b48d-e140f00b0000 pid=3056 execve guuid=5d03c5b3-2000-0000-b48d-e140f90b0000 pid=3065 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=5d03c5b3-2000-0000-b48d-e140f90b0000 pid=3065 execve guuid=cb1111b4-2000-0000-b48d-e140fb0b0000 pid=3067 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=cb1111b4-2000-0000-b48d-e140fb0b0000 pid=3067 execve guuid=21e162b4-2000-0000-b48d-e140fd0b0000 pid=3069 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=21e162b4-2000-0000-b48d-e140fd0b0000 pid=3069 clone guuid=8b428bb4-2000-0000-b48d-e140fe0b0000 pid=3070 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=8b428bb4-2000-0000-b48d-e140fe0b0000 pid=3070 execve guuid=a2f949b6-2000-0000-b48d-e140040c0000 pid=3076 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=a2f949b6-2000-0000-b48d-e140040c0000 pid=3076 execve guuid=edb608b9-2000-0000-b48d-e1400b0c0000 pid=3083 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=edb608b9-2000-0000-b48d-e1400b0c0000 pid=3083 execve guuid=84405eb9-2000-0000-b48d-e1400d0c0000 pid=3085 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=84405eb9-2000-0000-b48d-e1400d0c0000 pid=3085 execve guuid=4311d0b9-2000-0000-b48d-e140100c0000 pid=3088 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=4311d0b9-2000-0000-b48d-e140100c0000 pid=3088 clone guuid=bffdf5b9-2000-0000-b48d-e140110c0000 pid=3089 /usr/bin/wget net send-data guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=bffdf5b9-2000-0000-b48d-e140110c0000 pid=3089 execve guuid=d449a8bb-2000-0000-b48d-e140160c0000 pid=3094 /usr/bin/curl net send-data write-file guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=d449a8bb-2000-0000-b48d-e140160c0000 pid=3094 execve guuid=a9462abe-2000-0000-b48d-e1401e0c0000 pid=3102 /usr/bin/cat guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=a9462abe-2000-0000-b48d-e1401e0c0000 pid=3102 execve guuid=b5b58ebe-2000-0000-b48d-e140200c0000 pid=3104 /usr/bin/chmod guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=b5b58ebe-2000-0000-b48d-e140200c0000 pid=3104 execve guuid=0596eebe-2000-0000-b48d-e140220c0000 pid=3106 /usr/bin/bash guuid=fca5b741-2000-0000-b48d-e140220b0000 pid=2850->guuid=0596eebe-2000-0000-b48d-e140220c0000 pid=3106 clone a55e00cd-00f2-5efd-a3e6-b858c51f60f8 206.123.128.90:80 guuid=eec06142-2000-0000-b48d-e140240b0000 pid=2852->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=40847a46-2000-0000-b48d-e1402f0b0000 pid=2863->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=9de93c53-2000-0000-b48d-e1404d0b0000 pid=2893->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=82bd1655-2000-0000-b48d-e140510b0000 pid=2897->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=4cec2963-2000-0000-b48d-e1405e0b0000 pid=2910->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=cb7baa65-2000-0000-b48d-e140600b0000 pid=2912->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=83d6046a-2000-0000-b48d-e1406e0b0000 pid=2926->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=abb0b56b-2000-0000-b48d-e140750b0000 pid=2933->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=67abc171-2000-0000-b48d-e1407b0b0000 pid=2939->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=79a7c673-2000-0000-b48d-e140820b0000 pid=2946->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=eea47477-2000-0000-b48d-e1408d0b0000 pid=2957->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=7e79aa79-2000-0000-b48d-e140920b0000 pid=2962->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=ff4f487d-2000-0000-b48d-e1409d0b0000 pid=2973->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=ce854b7f-2000-0000-b48d-e140a30b0000 pid=2979->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=dc364f83-2000-0000-b48d-e140af0b0000 pid=2991->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=a7a92e85-2000-0000-b48d-e140b40b0000 pid=2996->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=bec18592-2000-0000-b48d-e140cf0b0000 pid=3023->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=a898af95-2000-0000-b48d-e140d20b0000 pid=3026->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=9640a8a9-2000-0000-b48d-e140d70b0000 pid=3031->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=39e794ab-2000-0000-b48d-e140dd0b0000 pid=3037->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=02784baf-2000-0000-b48d-e140ea0b0000 pid=3050->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 138B guuid=4b1800b1-2000-0000-b48d-e140f00b0000 pid=3056->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 87B guuid=8b428bb4-2000-0000-b48d-e140fe0b0000 pid=3070->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=a2f949b6-2000-0000-b48d-e140040c0000 pid=3076->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B guuid=bffdf5b9-2000-0000-b48d-e140110c0000 pid=3089->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 137B guuid=d449a8bb-2000-0000-b48d-e140160c0000 pid=3094->a55e00cd-00f2-5efd-a3e6-b858c51f60f8 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-10 13:03:19 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b5a94259016263d3b72b80dbbbdf5f2df0d358c53d34b01874c8efc7c66dd37b

(this sample)

  
Delivery method
Distributed via web download

Comments