MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d71825d1cc73dbcc582f0b75e00b9f3457217b421dd503ed7bfd4643d68cac58. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: d71825d1cc73dbcc582f0b75e00b9f3457217b421dd503ed7bfd4643d68cac58
SHA3-384 hash: 9e2f0d547c78572c9418b4d284e5a3712025b16114634adc4fda01e81d3b225e92908b37072cf6a50a719ed86e1cdd87
SHA1 hash: d9297bd20182a4a7bcf6f926388b6d4b0356ce36
MD5 hash: 6777da52673377a9b9762994e5132418
humanhash: moon-floor-jersey-crazy
File name:zyxel
Download: download sample
Signature Mirai
File size:2'835 bytes
First seen:2025-09-06 06:46:02 UTC
Last seen:2025-09-07 00:25:05 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v3X3Uo3GNUo3gtUo3ypUo34NUo3soszEUo3bvUo3IdUo31vUo3ihUo3QHUo3A5Ae:v3X3t3GNt3gtt3ypt34Nt37oEt3bvt3/
TLSH T1AB51D1C6F22983B03FF1895A35FA640474D0F1955BC20F55D9FC38BEA14DF0974916AA
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.162.114.77/bins/sora.x86c4fdffa36b13e3742a38317302b552e0142055d028e43ef4ccbbdbfa0b208342 Miraielf mirai
http://38.162.114.77/bins/sora.mips518bb7ecad7786975b925e68c15f70746e6ab02508deb8bbbc8b8cc5cc597355 Miraielf mirai
http://38.162.114.77/bins/sora.x86_64n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i468n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i686n/an/aelf ua-wget
http://38.162.114.77/bins/sora.mpslcb66f0b9bfb996b5e4fe142cd03b3061b9843899675d93690e5474e87ef1bef2 Miraielf mirai
http://38.162.114.77/bins/sora.arm4n/an/aelf ua-wget
http://38.162.114.77/bins/sora.arm512486e4b57bd5ee074988b64d0716aa9c631aeb5805d8fc7664063d5a98dfaac Miraielf mirai
http://38.162.114.77/bins/sora.arm6e7b1d9504e3f6186d5c26f39932d0327b4ba22e04bf6e32e78ae72ca6969bd8c Miraielf mirai
http://38.162.114.77/bins/sora.arm77a0d000d79bc1be7a41fa59d1892995ff61815d4dbeb49f6d7053da7034a1598 Miraielf mirai
http://38.162.114.77/bins/sora.ppcadfb9de9a74d82e9d980515498e5d02b527961d37375a76e784404d059676f85 Miraielf mirai
http://38.162.114.77/bins/sora.ppc440fpn/an/aelf ua-wget
http://38.162.114.77/bins/sora.m68k6d1d1df496a3ab3aa77e2536fc9fcb09ed3b6653b77c27e305aba647bc5f2193 Miraielf mirai
http://38.162.114.77/bins/sora.sh438e47119b088297ba98fe3db4022607ff33af93d40ebc4991de353a424d180cc Miraielf mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T04:06:00Z UTC
Last seen:
2025-09-06T04:06:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=cbe9b342-1900-0000-b38f-f77b0b080000 pid=2059 /usr/bin/sudo guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060 /tmp/sample.bin guuid=cbe9b342-1900-0000-b38f-f77b0b080000 pid=2059->guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060 execve guuid=4cd8b345-1900-0000-b38f-f77b0d080000 pid=2061 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=4cd8b345-1900-0000-b38f-f77b0d080000 pid=2061 execve guuid=89365d68-1900-0000-b38f-f77b49080000 pid=2121 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=89365d68-1900-0000-b38f-f77b49080000 pid=2121 execve guuid=11a9cd85-1900-0000-b38f-f77b9d080000 pid=2205 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=11a9cd85-1900-0000-b38f-f77b9d080000 pid=2205 execve guuid=bab14286-1900-0000-b38f-f77ba0080000 pid=2208 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=bab14286-1900-0000-b38f-f77ba0080000 pid=2208 execve guuid=3aabad86-1900-0000-b38f-f77ba2080000 pid=2210 /tmp/robben net guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3aabad86-1900-0000-b38f-f77ba2080000 pid=2210 execve guuid=65b5358a-1900-0000-b38f-f77bae080000 pid=2222 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=65b5358a-1900-0000-b38f-f77bae080000 pid=2222 execve guuid=901a63a5-1900-0000-b38f-f77be5080000 pid=2277 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=901a63a5-1900-0000-b38f-f77be5080000 pid=2277 execve guuid=9ea681c4-1900-0000-b38f-f77b1c090000 pid=2332 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=9ea681c4-1900-0000-b38f-f77b1c090000 pid=2332 execve guuid=e31531c5-1900-0000-b38f-f77b1e090000 pid=2334 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=e31531c5-1900-0000-b38f-f77b1e090000 pid=2334 execve guuid=16a07fc5-1900-0000-b38f-f77b1f090000 pid=2335 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=16a07fc5-1900-0000-b38f-f77b1f090000 pid=2335 clone guuid=b16218c7-1900-0000-b38f-f77b21090000 pid=2337 /usr/bin/wget net send-data guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=b16218c7-1900-0000-b38f-f77b21090000 pid=2337 execve guuid=53962ada-1900-0000-b38f-f77b51090000 pid=2385 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=53962ada-1900-0000-b38f-f77b51090000 pid=2385 execve guuid=fb848bed-1900-0000-b38f-f77b73090000 pid=2419 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=fb848bed-1900-0000-b38f-f77b73090000 pid=2419 execve guuid=ef9c0cee-1900-0000-b38f-f77b74090000 pid=2420 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=ef9c0cee-1900-0000-b38f-f77b74090000 pid=2420 execve guuid=d24bb6ee-1900-0000-b38f-f77b75090000 pid=2421 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=d24bb6ee-1900-0000-b38f-f77b75090000 pid=2421 clone guuid=0f302bef-1900-0000-b38f-f77b76090000 pid=2422 /usr/bin/wget net send-data guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=0f302bef-1900-0000-b38f-f77b76090000 pid=2422 execve guuid=f485ae02-1a00-0000-b38f-f77b9f090000 pid=2463 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=f485ae02-1a00-0000-b38f-f77b9f090000 pid=2463 execve guuid=4fabab18-1a00-0000-b38f-f77bd7090000 pid=2519 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=4fabab18-1a00-0000-b38f-f77bd7090000 pid=2519 execve guuid=ff760e19-1a00-0000-b38f-f77bd9090000 pid=2521 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=ff760e19-1a00-0000-b38f-f77bd9090000 pid=2521 execve guuid=5ad76e19-1a00-0000-b38f-f77bdb090000 pid=2523 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=5ad76e19-1a00-0000-b38f-f77bdb090000 pid=2523 clone guuid=5d5ba719-1a00-0000-b38f-f77bdc090000 pid=2524 /usr/bin/wget net send-data guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=5d5ba719-1a00-0000-b38f-f77bdc090000 pid=2524 execve guuid=6f6b322d-1a00-0000-b38f-f77b080a0000 pid=2568 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=6f6b322d-1a00-0000-b38f-f77b080a0000 pid=2568 execve guuid=08c6cf40-1a00-0000-b38f-f77b3a0a0000 pid=2618 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=08c6cf40-1a00-0000-b38f-f77b3a0a0000 pid=2618 execve guuid=2ea15741-1a00-0000-b38f-f77b3c0a0000 pid=2620 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=2ea15741-1a00-0000-b38f-f77b3c0a0000 pid=2620 execve guuid=3bddbf41-1a00-0000-b38f-f77b3e0a0000 pid=2622 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3bddbf41-1a00-0000-b38f-f77b3e0a0000 pid=2622 clone guuid=7dd5e541-1a00-0000-b38f-f77b400a0000 pid=2624 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=7dd5e541-1a00-0000-b38f-f77b400a0000 pid=2624 execve guuid=0461f45e-1a00-0000-b38f-f77b8c0a0000 pid=2700 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=0461f45e-1a00-0000-b38f-f77b8c0a0000 pid=2700 execve guuid=d14a267e-1a00-0000-b38f-f77bd50a0000 pid=2773 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=d14a267e-1a00-0000-b38f-f77bd50a0000 pid=2773 execve guuid=e9019a7e-1a00-0000-b38f-f77bd70a0000 pid=2775 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=e9019a7e-1a00-0000-b38f-f77bd70a0000 pid=2775 execve guuid=9552fd7e-1a00-0000-b38f-f77bd90a0000 pid=2777 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=9552fd7e-1a00-0000-b38f-f77bd90a0000 pid=2777 clone guuid=a80eb27f-1a00-0000-b38f-f77bdd0a0000 pid=2781 /usr/bin/wget net send-data guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=a80eb27f-1a00-0000-b38f-f77bdd0a0000 pid=2781 execve guuid=33d35f94-1a00-0000-b38f-f77beb0a0000 pid=2795 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=33d35f94-1a00-0000-b38f-f77beb0a0000 pid=2795 execve guuid=008986a8-1a00-0000-b38f-f77b0f0b0000 pid=2831 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=008986a8-1a00-0000-b38f-f77b0f0b0000 pid=2831 execve guuid=484fd0a8-1a00-0000-b38f-f77b100b0000 pid=2832 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=484fd0a8-1a00-0000-b38f-f77b100b0000 pid=2832 execve guuid=915a3da9-1a00-0000-b38f-f77b120b0000 pid=2834 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=915a3da9-1a00-0000-b38f-f77b120b0000 pid=2834 clone guuid=69356ca9-1a00-0000-b38f-f77b140b0000 pid=2836 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=69356ca9-1a00-0000-b38f-f77b140b0000 pid=2836 execve guuid=3d9d23c9-1a00-0000-b38f-f77b590b0000 pid=2905 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3d9d23c9-1a00-0000-b38f-f77b590b0000 pid=2905 execve guuid=dc1b62e7-1a00-0000-b38f-f77b930b0000 pid=2963 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=dc1b62e7-1a00-0000-b38f-f77b930b0000 pid=2963 execve guuid=8bffdbe7-1a00-0000-b38f-f77b950b0000 pid=2965 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=8bffdbe7-1a00-0000-b38f-f77b950b0000 pid=2965 execve guuid=799c20e8-1a00-0000-b38f-f77b960b0000 pid=2966 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=799c20e8-1a00-0000-b38f-f77b960b0000 pid=2966 clone guuid=57b216e9-1a00-0000-b38f-f77b980b0000 pid=2968 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=57b216e9-1a00-0000-b38f-f77b980b0000 pid=2968 execve guuid=40871906-1b00-0000-b38f-f77bcb0b0000 pid=3019 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=40871906-1b00-0000-b38f-f77bcb0b0000 pid=3019 execve guuid=ae9f4424-1b00-0000-b38f-f77b060c0000 pid=3078 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=ae9f4424-1b00-0000-b38f-f77b060c0000 pid=3078 execve guuid=021cc624-1b00-0000-b38f-f77b080c0000 pid=3080 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=021cc624-1b00-0000-b38f-f77b080c0000 pid=3080 execve guuid=97cb4425-1b00-0000-b38f-f77b0a0c0000 pid=3082 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=97cb4425-1b00-0000-b38f-f77b0a0c0000 pid=3082 clone guuid=c94afd27-1b00-0000-b38f-f77b120c0000 pid=3090 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=c94afd27-1b00-0000-b38f-f77b120c0000 pid=3090 execve guuid=3380934d-1b00-0000-b38f-f77b770c0000 pid=3191 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3380934d-1b00-0000-b38f-f77b770c0000 pid=3191 execve guuid=084e8c74-1b00-0000-b38f-f77ba10c0000 pid=3233 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=084e8c74-1b00-0000-b38f-f77ba10c0000 pid=3233 execve guuid=de920375-1b00-0000-b38f-f77ba40c0000 pid=3236 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=de920375-1b00-0000-b38f-f77ba40c0000 pid=3236 execve guuid=990b5175-1b00-0000-b38f-f77ba50c0000 pid=3237 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=990b5175-1b00-0000-b38f-f77ba50c0000 pid=3237 clone guuid=abf81476-1b00-0000-b38f-f77ba80c0000 pid=3240 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=abf81476-1b00-0000-b38f-f77ba80c0000 pid=3240 execve guuid=12ee4f92-1b00-0000-b38f-f77bc30c0000 pid=3267 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=12ee4f92-1b00-0000-b38f-f77bc30c0000 pid=3267 execve guuid=8c4244b0-1b00-0000-b38f-f77be00c0000 pid=3296 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=8c4244b0-1b00-0000-b38f-f77be00c0000 pid=3296 execve guuid=2d16b8b0-1b00-0000-b38f-f77be20c0000 pid=3298 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=2d16b8b0-1b00-0000-b38f-f77be20c0000 pid=3298 execve guuid=ef625bb1-1b00-0000-b38f-f77be30c0000 pid=3299 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=ef625bb1-1b00-0000-b38f-f77be30c0000 pid=3299 clone guuid=4aeb5bb3-1b00-0000-b38f-f77be80c0000 pid=3304 /usr/bin/wget net send-data guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=4aeb5bb3-1b00-0000-b38f-f77be80c0000 pid=3304 execve guuid=d4956ec6-1b00-0000-b38f-f77b020d0000 pid=3330 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=d4956ec6-1b00-0000-b38f-f77b020d0000 pid=3330 execve guuid=c5df7edc-1b00-0000-b38f-f77b330d0000 pid=3379 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=c5df7edc-1b00-0000-b38f-f77b330d0000 pid=3379 execve guuid=a3b4dedc-1b00-0000-b38f-f77b350d0000 pid=3381 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=a3b4dedc-1b00-0000-b38f-f77b350d0000 pid=3381 execve guuid=7ee17edd-1b00-0000-b38f-f77b370d0000 pid=3383 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=7ee17edd-1b00-0000-b38f-f77b370d0000 pid=3383 clone guuid=9e94a4dd-1b00-0000-b38f-f77b380d0000 pid=3384 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=9e94a4dd-1b00-0000-b38f-f77b380d0000 pid=3384 execve guuid=2dc52b02-1c00-0000-b38f-f77b970d0000 pid=3479 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=2dc52b02-1c00-0000-b38f-f77b970d0000 pid=3479 execve guuid=94452a28-1c00-0000-b38f-f77bf10d0000 pid=3569 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=94452a28-1c00-0000-b38f-f77bf10d0000 pid=3569 execve guuid=cf618a28-1c00-0000-b38f-f77bf20d0000 pid=3570 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=cf618a28-1c00-0000-b38f-f77bf20d0000 pid=3570 execve guuid=3014e728-1c00-0000-b38f-f77bf50d0000 pid=3573 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3014e728-1c00-0000-b38f-f77bf50d0000 pid=3573 clone guuid=0f65b529-1c00-0000-b38f-f77bf80d0000 pid=3576 /usr/bin/wget net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=0f65b529-1c00-0000-b38f-f77bf80d0000 pid=3576 execve guuid=46de724d-1c00-0000-b38f-f77b490e0000 pid=3657 /usr/bin/curl net send-data write-file guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=46de724d-1c00-0000-b38f-f77b490e0000 pid=3657 execve guuid=a419c473-1c00-0000-b38f-f77b940e0000 pid=3732 /usr/bin/cat guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=a419c473-1c00-0000-b38f-f77b940e0000 pid=3732 execve guuid=3533ab74-1c00-0000-b38f-f77b950e0000 pid=3733 /usr/bin/chmod guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=3533ab74-1c00-0000-b38f-f77b950e0000 pid=3733 execve guuid=44ba7175-1c00-0000-b38f-f77b960e0000 pid=3734 /usr/bin/bash guuid=674f0b45-1900-0000-b38f-f77b0c080000 pid=2060->guuid=44ba7175-1c00-0000-b38f-f77b960e0000 pid=3734 clone e10eb183-c74b-539a-bc26-e43bbf2bbb51 38.162.114.77:80 guuid=4cd8b345-1900-0000-b38f-f77b0d080000 pid=2061->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=89365d68-1900-0000-b38f-f77b49080000 pid=2121->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3aabad86-1900-0000-b38f-f77ba2080000 pid=2210->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=65b5358a-1900-0000-b38f-f77bae080000 pid=2222->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=901a63a5-1900-0000-b38f-f77be5080000 pid=2277->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=b16218c7-1900-0000-b38f-f77b21090000 pid=2337->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 144B guuid=53962ada-1900-0000-b38f-f77b51090000 pid=2385->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 93B guuid=0f302bef-1900-0000-b38f-f77b76090000 pid=2422->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=f485ae02-1a00-0000-b38f-f77b9f090000 pid=2463->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=5d5ba719-1a00-0000-b38f-f77bdc090000 pid=2524->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=6f6b322d-1a00-0000-b38f-f77b080a0000 pid=2568->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7dd5e541-1a00-0000-b38f-f77b400a0000 pid=2624->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=0461f45e-1a00-0000-b38f-f77b8c0a0000 pid=2700->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=a80eb27f-1a00-0000-b38f-f77bdd0a0000 pid=2781->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=33d35f94-1a00-0000-b38f-f77beb0a0000 pid=2795->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=69356ca9-1a00-0000-b38f-f77b140b0000 pid=2836->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=3d9d23c9-1a00-0000-b38f-f77b590b0000 pid=2905->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=57b216e9-1a00-0000-b38f-f77b980b0000 pid=2968->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=40871906-1b00-0000-b38f-f77bcb0b0000 pid=3019->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=c94afd27-1b00-0000-b38f-f77b120c0000 pid=3090->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=3380934d-1b00-0000-b38f-f77b770c0000 pid=3191->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=abf81476-1b00-0000-b38f-f77ba80c0000 pid=3240->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=12ee4f92-1b00-0000-b38f-f77bc30c0000 pid=3267->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B guuid=4aeb5bb3-1b00-0000-b38f-f77be80c0000 pid=3304->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 146B guuid=d4956ec6-1b00-0000-b38f-f77b020d0000 pid=3330->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 95B guuid=9e94a4dd-1b00-0000-b38f-f77b380d0000 pid=3384->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=2dc52b02-1c00-0000-b38f-f77b970d0000 pid=3479->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=0f65b529-1c00-0000-b38f-f77bf80d0000 pid=3576->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=46de724d-1c00-0000-b38f-f77b490e0000 pid=3657->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 06:31:33 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (46596) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d71825d1cc73dbcc582f0b75e00b9f3457217b421dd503ed7bfd4643d68cac58

(this sample)

  
Delivery method
Distributed via web download

Comments