MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e0c6f352df1831f85dd76a3fe2777fa0b1ef5b6efec4f52114e24660d8fb4bd5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e0c6f352df1831f85dd76a3fe2777fa0b1ef5b6efec4f52114e24660d8fb4bd5
SHA3-384 hash: 789bd3e2aca7820008fcfaf0c4e84e125de2cf9183903dcb07b6bb0c8c87f97e3a57d1d18d287e50590a43fb377e99a5
SHA1 hash: 754bba53295085dee70798ea4de3715cf7f85d75
MD5 hash: 86bace9a1a1efa81132d83348420344c
humanhash: michigan-muppet-maryland-july
File name:kla.sh
Download: download sample
File size:1'783 bytes
First seen:2025-07-05 13:21:38 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vl7jRly3RlGWxRljTpRlgbRl9IGRlK3RlUvRlHRRlIfe:vl7VlyhlTbljnlgNl9HlKhlUZlH7lIG
TLSH T1DC31C3C912E144B17DD29DA6B2F98904B080B1576CC39F8A9DEC39FD884DF183CC9A53
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://93.123.109.218/bins/x86n/an/aelf ua-wget
http://93.123.109.218/bins/mipsn/an/aelf ua-wget
http://93.123.109.218/bins/mpsln/an/aelf ua-wget
http://93.123.109.218/bins/arm4n/an/aelf ua-wget
http://93.123.109.218/bins/arm5n/an/aelf ua-wget
http://93.123.109.218/bins/arm6n/an/aelf ua-wget
http://93.123.109.218/bins/arm7n/an/aelf ua-wget
http://93.123.109.218/bins/ppcn/an/aelf ua-wget
http://93.123.109.218/bins/m68kn/an/aelf ua-wget
http://93.123.109.218/bins/sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
19
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
trojandownloader trojware mirai agent
Status:
terminated
Behavior Graph:
%3 guuid=a0009207-2000-0000-4de3-1e00450b0000 pid=2885 /usr/bin/sudo guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891 /tmp/sample.bin guuid=a0009207-2000-0000-4de3-1e00450b0000 pid=2885->guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891 execve guuid=6fb1f30d-2000-0000-4de3-1e004c0b0000 pid=2892 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=6fb1f30d-2000-0000-4de3-1e004c0b0000 pid=2892 execve guuid=214a0392-2000-0000-4de3-1e005f0c0000 pid=3167 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=214a0392-2000-0000-4de3-1e005f0c0000 pid=3167 execve guuid=51401d9a-2000-0000-4de3-1e006a0c0000 pid=3178 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=51401d9a-2000-0000-4de3-1e006a0c0000 pid=3178 execve guuid=48066c9a-2000-0000-4de3-1e006b0c0000 pid=3179 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=48066c9a-2000-0000-4de3-1e006b0c0000 pid=3179 execve guuid=ef23ac9a-2000-0000-4de3-1e006c0c0000 pid=3180 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ef23ac9a-2000-0000-4de3-1e006c0c0000 pid=3180 clone guuid=f3e5d09a-2000-0000-4de3-1e006d0c0000 pid=3181 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=f3e5d09a-2000-0000-4de3-1e006d0c0000 pid=3181 execve guuid=e350379d-2000-0000-4de3-1e00720c0000 pid=3186 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=e350379d-2000-0000-4de3-1e00720c0000 pid=3186 execve guuid=37618fa3-2000-0000-4de3-1e00820c0000 pid=3202 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=37618fa3-2000-0000-4de3-1e00820c0000 pid=3202 execve guuid=f6e80fa4-2000-0000-4de3-1e00830c0000 pid=3203 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=f6e80fa4-2000-0000-4de3-1e00830c0000 pid=3203 execve guuid=5d78a9a4-2000-0000-4de3-1e00840c0000 pid=3204 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=5d78a9a4-2000-0000-4de3-1e00840c0000 pid=3204 clone guuid=ee09d6a4-2000-0000-4de3-1e00850c0000 pid=3205 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ee09d6a4-2000-0000-4de3-1e00850c0000 pid=3205 execve guuid=ffc696a7-2000-0000-4de3-1e008c0c0000 pid=3212 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ffc696a7-2000-0000-4de3-1e008c0c0000 pid=3212 execve guuid=2c9ddeac-2000-0000-4de3-1e00930c0000 pid=3219 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=2c9ddeac-2000-0000-4de3-1e00930c0000 pid=3219 execve guuid=befd30ad-2000-0000-4de3-1e00950c0000 pid=3221 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=befd30ad-2000-0000-4de3-1e00950c0000 pid=3221 execve guuid=96f3a4ad-2000-0000-4de3-1e00970c0000 pid=3223 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=96f3a4ad-2000-0000-4de3-1e00970c0000 pid=3223 clone guuid=0978d4ad-2000-0000-4de3-1e00980c0000 pid=3224 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=0978d4ad-2000-0000-4de3-1e00980c0000 pid=3224 execve guuid=be19feb0-2000-0000-4de3-1e009c0c0000 pid=3228 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=be19feb0-2000-0000-4de3-1e009c0c0000 pid=3228 execve guuid=40254cb6-2000-0000-4de3-1e009d0c0000 pid=3229 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=40254cb6-2000-0000-4de3-1e009d0c0000 pid=3229 execve guuid=4812b9b6-2000-0000-4de3-1e009e0c0000 pid=3230 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=4812b9b6-2000-0000-4de3-1e009e0c0000 pid=3230 execve guuid=d9cf32b7-2000-0000-4de3-1e009f0c0000 pid=3231 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=d9cf32b7-2000-0000-4de3-1e009f0c0000 pid=3231 clone guuid=8bc56cb7-2000-0000-4de3-1e00a00c0000 pid=3232 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=8bc56cb7-2000-0000-4de3-1e00a00c0000 pid=3232 execve guuid=aa3343ba-2000-0000-4de3-1e00a10c0000 pid=3233 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=aa3343ba-2000-0000-4de3-1e00a10c0000 pid=3233 execve guuid=f7d1a8bf-2000-0000-4de3-1e00a20c0000 pid=3234 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=f7d1a8bf-2000-0000-4de3-1e00a20c0000 pid=3234 execve guuid=e83419c0-2000-0000-4de3-1e00a30c0000 pid=3235 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=e83419c0-2000-0000-4de3-1e00a30c0000 pid=3235 execve guuid=c6ac7bc0-2000-0000-4de3-1e00a40c0000 pid=3236 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=c6ac7bc0-2000-0000-4de3-1e00a40c0000 pid=3236 clone guuid=edf2afc0-2000-0000-4de3-1e00a50c0000 pid=3237 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=edf2afc0-2000-0000-4de3-1e00a50c0000 pid=3237 execve guuid=cc83a4c3-2000-0000-4de3-1e00a70c0000 pid=3239 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=cc83a4c3-2000-0000-4de3-1e00a70c0000 pid=3239 execve guuid=8d2bccc7-2000-0000-4de3-1e00ae0c0000 pid=3246 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=8d2bccc7-2000-0000-4de3-1e00ae0c0000 pid=3246 execve guuid=4cf738c8-2000-0000-4de3-1e00af0c0000 pid=3247 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=4cf738c8-2000-0000-4de3-1e00af0c0000 pid=3247 execve guuid=223d9ac8-2000-0000-4de3-1e00b10c0000 pid=3249 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=223d9ac8-2000-0000-4de3-1e00b10c0000 pid=3249 clone guuid=ae0ed9c8-2000-0000-4de3-1e00b20c0000 pid=3250 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ae0ed9c8-2000-0000-4de3-1e00b20c0000 pid=3250 execve guuid=c87dbacb-2000-0000-4de3-1e00b90c0000 pid=3257 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=c87dbacb-2000-0000-4de3-1e00b90c0000 pid=3257 execve guuid=ef31e0cf-2000-0000-4de3-1e00c10c0000 pid=3265 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ef31e0cf-2000-0000-4de3-1e00c10c0000 pid=3265 execve guuid=3112bad0-2000-0000-4de3-1e00c20c0000 pid=3266 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=3112bad0-2000-0000-4de3-1e00c20c0000 pid=3266 execve guuid=da8a25d1-2000-0000-4de3-1e00c30c0000 pid=3267 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=da8a25d1-2000-0000-4de3-1e00c30c0000 pid=3267 clone guuid=ff3575d1-2000-0000-4de3-1e00c40c0000 pid=3268 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=ff3575d1-2000-0000-4de3-1e00c40c0000 pid=3268 execve guuid=35f083d6-2000-0000-4de3-1e00ca0c0000 pid=3274 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=35f083d6-2000-0000-4de3-1e00ca0c0000 pid=3274 execve guuid=1044fadc-2000-0000-4de3-1e00d50c0000 pid=3285 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=1044fadc-2000-0000-4de3-1e00d50c0000 pid=3285 execve guuid=900e96dd-2000-0000-4de3-1e00d80c0000 pid=3288 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=900e96dd-2000-0000-4de3-1e00d80c0000 pid=3288 execve guuid=488726de-2000-0000-4de3-1e00da0c0000 pid=3290 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=488726de-2000-0000-4de3-1e00da0c0000 pid=3290 clone guuid=54e84cde-2000-0000-4de3-1e00dc0c0000 pid=3292 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=54e84cde-2000-0000-4de3-1e00dc0c0000 pid=3292 execve guuid=a0bb32e1-2000-0000-4de3-1e00df0c0000 pid=3295 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=a0bb32e1-2000-0000-4de3-1e00df0c0000 pid=3295 execve guuid=a645a4e7-2000-0000-4de3-1e00e30c0000 pid=3299 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=a645a4e7-2000-0000-4de3-1e00e30c0000 pid=3299 execve guuid=d6e9f4e7-2000-0000-4de3-1e00e50c0000 pid=3301 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=d6e9f4e7-2000-0000-4de3-1e00e50c0000 pid=3301 execve guuid=6c3d3ce8-2000-0000-4de3-1e00e70c0000 pid=3303 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=6c3d3ce8-2000-0000-4de3-1e00e70c0000 pid=3303 clone guuid=d6f676e8-2000-0000-4de3-1e00e90c0000 pid=3305 /usr/bin/wget net send-data guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=d6f676e8-2000-0000-4de3-1e00e90c0000 pid=3305 execve guuid=dd1943eb-2000-0000-4de3-1e00f40c0000 pid=3316 /usr/bin/curl net send-data write-file guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=dd1943eb-2000-0000-4de3-1e00f40c0000 pid=3316 execve guuid=690979f1-2000-0000-4de3-1e00040d0000 pid=3332 /usr/bin/cat guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=690979f1-2000-0000-4de3-1e00040d0000 pid=3332 execve guuid=9060e7f1-2000-0000-4de3-1e00060d0000 pid=3334 /usr/bin/chmod guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=9060e7f1-2000-0000-4de3-1e00060d0000 pid=3334 execve guuid=9e2933f2-2000-0000-4de3-1e00070d0000 pid=3335 /usr/bin/bash guuid=d6a5be09-2000-0000-4de3-1e004b0b0000 pid=2891->guuid=9e2933f2-2000-0000-4de3-1e00070d0000 pid=3335 clone e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 93.123.109.218:80 guuid=6fb1f30d-2000-0000-4de3-1e004c0b0000 pid=2892->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 137B guuid=214a0392-2000-0000-4de3-1e005f0c0000 pid=3167->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 86B guuid=f3e5d09a-2000-0000-4de3-1e006d0c0000 pid=3181->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=e350379d-2000-0000-4de3-1e00720c0000 pid=3186->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=ee09d6a4-2000-0000-4de3-1e00850c0000 pid=3205->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=ffc696a7-2000-0000-4de3-1e008c0c0000 pid=3212->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=0978d4ad-2000-0000-4de3-1e00980c0000 pid=3224->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=be19feb0-2000-0000-4de3-1e009c0c0000 pid=3228->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=8bc56cb7-2000-0000-4de3-1e00a00c0000 pid=3232->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=aa3343ba-2000-0000-4de3-1e00a10c0000 pid=3233->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=edf2afc0-2000-0000-4de3-1e00a50c0000 pid=3237->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=cc83a4c3-2000-0000-4de3-1e00a70c0000 pid=3239->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=ae0ed9c8-2000-0000-4de3-1e00b20c0000 pid=3250->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=c87dbacb-2000-0000-4de3-1e00b90c0000 pid=3257->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=ff3575d1-2000-0000-4de3-1e00c40c0000 pid=3268->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 137B guuid=35f083d6-2000-0000-4de3-1e00ca0c0000 pid=3274->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 86B guuid=54e84cde-2000-0000-4de3-1e00dc0c0000 pid=3292->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 138B guuid=a0bb32e1-2000-0000-4de3-1e00df0c0000 pid=3295->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 87B guuid=d6f676e8-2000-0000-4de3-1e00e90c0000 pid=3305->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 137B guuid=dd1943eb-2000-0000-4de3-1e00f40c0000 pid=3316->e2ef2ac6-39dc-592c-8ad7-ce17fe31e3a6 send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-07-05 05:53:00 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e0c6f352df1831f85dd76a3fe2777fa0b1ef5b6efec4f52114e24660d8fb4bd5

(this sample)

  
Delivery method
Distributed via web download

Comments