MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e1a28893d0727ba239249f50f1ee5e3d517fda448bf574df01f8e06a5b84d9c8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: e1a28893d0727ba239249f50f1ee5e3d517fda448bf574df01f8e06a5b84d9c8
SHA3-384 hash: 526c2b8a8ddb5348e33dbf5a0fb667acf300a101a61e656de35497a869ea74f6c1f562e8436d0f606663fcb8ab98ddd6
SHA1 hash: 3b68af87f3a8fd4d8b87b9a918609ef3bba724c1
MD5 hash: 4b8f6394b6106f30d4b5d7a261f99cee
humanhash: cat-pennsylvania-ink-rugby
File name:bin
Download: download sample
File size:1'653 bytes
First seen:2025-10-20 20:07:22 UTC
Last seen:2025-10-21 04:59:56 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:q0FtwS3wgWX0FtwwI3wwdoX0FtwiONi3wiOusX0Ftwg3wC+LX0Ftwv3w3FX0Ftwu:vTnw9YqB5fa+pygvqkWo1Dk
TLSH T1033150E9228603366E629C37B5A9444872B255A7A8D5EE14A4DC78FC528FF1C3053A53
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.209.143.62/bins/x86n/an/aelf ua-wget
http://213.209.143.62/bins/mipsn/an/aelf ua-wget
http://213.209.143.62/bins/mpsln/an/aelf ua-wget
http://213.209.143.62/bins/arm4n/an/aelf ua-wget
http://213.209.143.62/bins/arm5n/an/aelf ua-wget
http://213.209.143.62/bins/arm6n/an/aelf ua-wget
http://213.209.143.62/bins/arm7n/an/aelf ua-wget
http://213.209.143.62/bins/ppcn/an/aelf ua-wget
http://213.209.143.62/bins/m68kn/an/aelf ua-wget
http://213.209.143.62/bins/sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
3
# of downloads :
45
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-20T17:47:00Z UTC
Last seen:
2025-10-21T10:18:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=4448f956-1900-0000-d626-dba17b130000 pid=4987 /usr/bin/sudo guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995 /tmp/sample.bin guuid=4448f956-1900-0000-d626-dba17b130000 pid=4987->guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995 execve guuid=428d2e59-1900-0000-d626-dba185130000 pid=4997 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=428d2e59-1900-0000-d626-dba185130000 pid=4997 execve guuid=fbea7d60-1900-0000-d626-dba19b130000 pid=5019 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=fbea7d60-1900-0000-d626-dba19b130000 pid=5019 execve guuid=f25bb269-1900-0000-d626-dba1b5130000 pid=5045 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=f25bb269-1900-0000-d626-dba1b5130000 pid=5045 execve guuid=a240186a-1900-0000-d626-dba1b9130000 pid=5049 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=a240186a-1900-0000-d626-dba1b9130000 pid=5049 execve guuid=423e706a-1900-0000-d626-dba1ba130000 pid=5050 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=423e706a-1900-0000-d626-dba1ba130000 pid=5050 clone guuid=f5dc9f6a-1900-0000-d626-dba1bb130000 pid=5051 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=f5dc9f6a-1900-0000-d626-dba1bb130000 pid=5051 execve guuid=795ca36d-1900-0000-d626-dba1c6130000 pid=5062 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=795ca36d-1900-0000-d626-dba1c6130000 pid=5062 execve guuid=c0adfd74-1900-0000-d626-dba1de130000 pid=5086 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=c0adfd74-1900-0000-d626-dba1de130000 pid=5086 execve guuid=0a137075-1900-0000-d626-dba1e0130000 pid=5088 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=0a137075-1900-0000-d626-dba1e0130000 pid=5088 execve guuid=96c8c775-1900-0000-d626-dba1e2130000 pid=5090 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=96c8c775-1900-0000-d626-dba1e2130000 pid=5090 clone guuid=e2970776-1900-0000-d626-dba1e6130000 pid=5094 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=e2970776-1900-0000-d626-dba1e6130000 pid=5094 execve guuid=c4e53779-1900-0000-d626-dba1ea130000 pid=5098 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=c4e53779-1900-0000-d626-dba1ea130000 pid=5098 execve guuid=7b4b157e-1900-0000-d626-dba1f4130000 pid=5108 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=7b4b157e-1900-0000-d626-dba1f4130000 pid=5108 execve guuid=cd707c7e-1900-0000-d626-dba1f7130000 pid=5111 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=cd707c7e-1900-0000-d626-dba1f7130000 pid=5111 execve guuid=90e4d57e-1900-0000-d626-dba1f9130000 pid=5113 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=90e4d57e-1900-0000-d626-dba1f9130000 pid=5113 clone guuid=675dfe7e-1900-0000-d626-dba1fa130000 pid=5114 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=675dfe7e-1900-0000-d626-dba1fa130000 pid=5114 execve guuid=39fc4984-1900-0000-d626-dba108140000 pid=5128 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=39fc4984-1900-0000-d626-dba108140000 pid=5128 execve guuid=71fa7188-1900-0000-d626-dba110140000 pid=5136 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=71fa7188-1900-0000-d626-dba110140000 pid=5136 execve guuid=dbb4f588-1900-0000-d626-dba113140000 pid=5139 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=dbb4f588-1900-0000-d626-dba113140000 pid=5139 execve guuid=d7166389-1900-0000-d626-dba115140000 pid=5141 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=d7166389-1900-0000-d626-dba115140000 pid=5141 clone guuid=6c4fa089-1900-0000-d626-dba117140000 pid=5143 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=6c4fa089-1900-0000-d626-dba117140000 pid=5143 execve guuid=303b3b8d-1900-0000-d626-dba122140000 pid=5154 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=303b3b8d-1900-0000-d626-dba122140000 pid=5154 execve guuid=62df8392-1900-0000-d626-dba132140000 pid=5170 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=62df8392-1900-0000-d626-dba132140000 pid=5170 execve guuid=046fc592-1900-0000-d626-dba134140000 pid=5172 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=046fc592-1900-0000-d626-dba134140000 pid=5172 execve guuid=1b880b93-1900-0000-d626-dba136140000 pid=5174 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=1b880b93-1900-0000-d626-dba136140000 pid=5174 clone guuid=6e023393-1900-0000-d626-dba138140000 pid=5176 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=6e023393-1900-0000-d626-dba138140000 pid=5176 execve guuid=bb9c2b98-1900-0000-d626-dba152140000 pid=5202 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=bb9c2b98-1900-0000-d626-dba152140000 pid=5202 execve guuid=856db79b-1900-0000-d626-dba16f140000 pid=5231 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=856db79b-1900-0000-d626-dba16f140000 pid=5231 execve guuid=82bef79b-1900-0000-d626-dba172140000 pid=5234 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=82bef79b-1900-0000-d626-dba172140000 pid=5234 execve guuid=8553359c-1900-0000-d626-dba174140000 pid=5236 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=8553359c-1900-0000-d626-dba174140000 pid=5236 clone guuid=1833559c-1900-0000-d626-dba176140000 pid=5238 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=1833559c-1900-0000-d626-dba176140000 pid=5238 execve guuid=13fd2d9f-1900-0000-d626-dba17a140000 pid=5242 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=13fd2d9f-1900-0000-d626-dba17a140000 pid=5242 execve guuid=56f101a5-1900-0000-d626-dba17b140000 pid=5243 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=56f101a5-1900-0000-d626-dba17b140000 pid=5243 execve guuid=f84382a5-1900-0000-d626-dba17c140000 pid=5244 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=f84382a5-1900-0000-d626-dba17c140000 pid=5244 execve guuid=efb2efa5-1900-0000-d626-dba17d140000 pid=5245 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=efb2efa5-1900-0000-d626-dba17d140000 pid=5245 clone guuid=198527a6-1900-0000-d626-dba17f140000 pid=5247 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=198527a6-1900-0000-d626-dba17f140000 pid=5247 execve guuid=460c9eab-1900-0000-d626-dba182140000 pid=5250 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=460c9eab-1900-0000-d626-dba182140000 pid=5250 execve guuid=c1a415b2-1900-0000-d626-dba183140000 pid=5251 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=c1a415b2-1900-0000-d626-dba183140000 pid=5251 execve guuid=acbb62b2-1900-0000-d626-dba184140000 pid=5252 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=acbb62b2-1900-0000-d626-dba184140000 pid=5252 execve guuid=df46d8b2-1900-0000-d626-dba185140000 pid=5253 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=df46d8b2-1900-0000-d626-dba185140000 pid=5253 clone guuid=ec0205b3-1900-0000-d626-dba186140000 pid=5254 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=ec0205b3-1900-0000-d626-dba186140000 pid=5254 execve guuid=be9655b8-1900-0000-d626-dba18f140000 pid=5263 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=be9655b8-1900-0000-d626-dba18f140000 pid=5263 execve guuid=526d99bc-1900-0000-d626-dba190140000 pid=5264 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=526d99bc-1900-0000-d626-dba190140000 pid=5264 execve guuid=4f2922bd-1900-0000-d626-dba191140000 pid=5265 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=4f2922bd-1900-0000-d626-dba191140000 pid=5265 execve guuid=0ab89ebd-1900-0000-d626-dba192140000 pid=5266 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=0ab89ebd-1900-0000-d626-dba192140000 pid=5266 clone guuid=1cb8cabd-1900-0000-d626-dba193140000 pid=5267 /usr/bin/wget net send-data guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=1cb8cabd-1900-0000-d626-dba193140000 pid=5267 execve guuid=5148a2c0-1900-0000-d626-dba194140000 pid=5268 /usr/bin/curl net send-data write-file guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=5148a2c0-1900-0000-d626-dba194140000 pid=5268 execve guuid=89b187c6-1900-0000-d626-dba195140000 pid=5269 /usr/bin/cat guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=89b187c6-1900-0000-d626-dba195140000 pid=5269 execve guuid=2763d0c6-1900-0000-d626-dba196140000 pid=5270 /usr/bin/chmod guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=2763d0c6-1900-0000-d626-dba196140000 pid=5270 execve guuid=a78b11c7-1900-0000-d626-dba197140000 pid=5271 /usr/bin/bash guuid=78d1c958-1900-0000-d626-dba183130000 pid=4995->guuid=a78b11c7-1900-0000-d626-dba197140000 pid=5271 clone eaaaaddb-f5f1-5090-9f4d-096f63c93adc 213.209.143.62:80 guuid=428d2e59-1900-0000-d626-dba185130000 pid=4997->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 137B guuid=fbea7d60-1900-0000-d626-dba19b130000 pid=5019->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 86B guuid=f5dc9f6a-1900-0000-d626-dba1bb130000 pid=5051->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=795ca36d-1900-0000-d626-dba1c6130000 pid=5062->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=e2970776-1900-0000-d626-dba1e6130000 pid=5094->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=c4e53779-1900-0000-d626-dba1ea130000 pid=5098->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=675dfe7e-1900-0000-d626-dba1fa130000 pid=5114->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=39fc4984-1900-0000-d626-dba108140000 pid=5128->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=6c4fa089-1900-0000-d626-dba117140000 pid=5143->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=303b3b8d-1900-0000-d626-dba122140000 pid=5154->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=6e023393-1900-0000-d626-dba138140000 pid=5176->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=bb9c2b98-1900-0000-d626-dba152140000 pid=5202->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=1833559c-1900-0000-d626-dba176140000 pid=5238->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=13fd2d9f-1900-0000-d626-dba17a140000 pid=5242->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=198527a6-1900-0000-d626-dba17f140000 pid=5247->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 137B guuid=460c9eab-1900-0000-d626-dba182140000 pid=5250->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 86B guuid=ec0205b3-1900-0000-d626-dba186140000 pid=5254->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 138B guuid=be9655b8-1900-0000-d626-dba18f140000 pid=5263->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 87B guuid=1cb8cabd-1900-0000-d626-dba193140000 pid=5267->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 137B guuid=5148a2c0-1900-0000-d626-dba194140000 pid=5268->eaaaaddb-f5f1-5090-9f4d-096f63c93adc send: 86B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-10-20 20:08:29 UTC
File Type:
Text (Shell)
AV detection:
23 of 37 (62.16%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh e1a28893d0727ba239249f50f1ee5e3d517fda448bf574df01f8e06a5b84d9c8

(this sample)

  
Delivery method
Distributed via web download

Comments