MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f233f77247bef987f907ba7fcd2e299ab754cd065a564fa7d86c8951eae17f24. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f233f77247bef987f907ba7fcd2e299ab754cd065a564fa7d86c8951eae17f24
SHA3-384 hash: f926e2a576ff4a1be1214fab42443ed6b7191c46cfba655b1734a833877ac6ddfbcb7d6065477ea20460d71bf1d4ba9c
SHA1 hash: 1572bb8b26bf3ffc1ec3dbfaa35d17fa8b8301dc
MD5 hash: 345f78e3251184507794e29f71d1624b
humanhash: seventeen-johnny-social-eighteen
File name:goahead
Download: download sample
Signature Mirai
File size:2'863 bytes
First seen:2025-09-06 06:45:50 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v3X3o3GNo3gto3ypo34No3soszEo3bvo3Ido31vo3iho3QHo3A5AUfo3Lvo30vL:v3X3o3GNo3gto3ypo34No37oEo3bvo3G
TLSH T19351C1C6B22943B02FF19D5B35FA60047490B1965FC24E16D5FC38BEA18DF09B4926AB
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://38.162.114.77/bins/sora.x86c4fdffa36b13e3742a38317302b552e0142055d028e43ef4ccbbdbfa0b208342 Miraielf mirai
http://38.162.114.77/bins/sora.mips518bb7ecad7786975b925e68c15f70746e6ab02508deb8bbbc8b8cc5cc597355 Miraielf mirai
http://38.162.114.77/bins/sora.x86_64n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i468n/an/aelf ua-wget
http://38.162.114.77/bins/sora.i686n/an/aelf ua-wget
http://38.162.114.77/bins/sora.mpslcb66f0b9bfb996b5e4fe142cd03b3061b9843899675d93690e5474e87ef1bef2 Miraielf mirai
http://38.162.114.77/bins/sora.arm4n/an/aelf ua-wget
http://38.162.114.77/bins/sora.arm512486e4b57bd5ee074988b64d0716aa9c631aeb5805d8fc7664063d5a98dfaac Miraielf mirai
http://38.162.114.77/bins/sora.arm6e7b1d9504e3f6186d5c26f39932d0327b4ba22e04bf6e32e78ae72ca6969bd8c Miraielf mirai
http://38.162.114.77/bins/sora.arm77a0d000d79bc1be7a41fa59d1892995ff61815d4dbeb49f6d7053da7034a1598 Miraielf mirai
http://38.162.114.77/bins/sora.ppcadfb9de9a74d82e9d980515498e5d02b527961d37375a76e784404d059676f85 Miraielf mirai
http://38.162.114.77/bins/sora.ppc440fpn/an/aelf ua-wget
http://38.162.114.77/bins/sora.m68k6d1d1df496a3ab3aa77e2536fc9fcb09ed3b6653b77c27e305aba647bc5f2193 Miraielf mirai
http://38.162.114.77/bins/sora.sh438e47119b088297ba98fe3db4022607ff33af93d40ebc4991de353a424d180cc Miraielf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
30
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T03:57:00Z UTC
Last seen:
2025-09-06T03:57:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.c HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=a81db613-1a00-0000-07bf-6b0ac30d0000 pid=3523 /usr/bin/sudo guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524 /tmp/sample.bin guuid=a81db613-1a00-0000-07bf-6b0ac30d0000 pid=3523->guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524 execve guuid=88385c18-1a00-0000-07bf-6b0ac50d0000 pid=3525 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=88385c18-1a00-0000-07bf-6b0ac50d0000 pid=3525 execve guuid=21d9fe34-1a00-0000-07bf-6b0a0b0e0000 pid=3595 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=21d9fe34-1a00-0000-07bf-6b0a0b0e0000 pid=3595 execve guuid=bb684056-1a00-0000-07bf-6b0a4d0e0000 pid=3661 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=bb684056-1a00-0000-07bf-6b0a4d0e0000 pid=3661 execve guuid=423dac56-1a00-0000-07bf-6b0a4e0e0000 pid=3662 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=423dac56-1a00-0000-07bf-6b0a4e0e0000 pid=3662 execve guuid=4c2e0d57-1a00-0000-07bf-6b0a4f0e0000 pid=3663 /tmp/robben net guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=4c2e0d57-1a00-0000-07bf-6b0a4f0e0000 pid=3663 execve guuid=5aa98c5b-1a00-0000-07bf-6b0a560e0000 pid=3670 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=5aa98c5b-1a00-0000-07bf-6b0a560e0000 pid=3670 execve guuid=9135bf77-1a00-0000-07bf-6b0aa00e0000 pid=3744 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=9135bf77-1a00-0000-07bf-6b0aa00e0000 pid=3744 execve guuid=e2695e9a-1a00-0000-07bf-6b0a140f0000 pid=3860 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=e2695e9a-1a00-0000-07bf-6b0a140f0000 pid=3860 execve guuid=19c6d09a-1a00-0000-07bf-6b0a160f0000 pid=3862 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=19c6d09a-1a00-0000-07bf-6b0a160f0000 pid=3862 execve guuid=7313409b-1a00-0000-07bf-6b0a180f0000 pid=3864 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=7313409b-1a00-0000-07bf-6b0a180f0000 pid=3864 clone guuid=b242299d-1a00-0000-07bf-6b0a1e0f0000 pid=3870 /usr/bin/wget net send-data guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=b242299d-1a00-0000-07bf-6b0a1e0f0000 pid=3870 execve guuid=f8d328b0-1a00-0000-07bf-6b0a540f0000 pid=3924 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=f8d328b0-1a00-0000-07bf-6b0a540f0000 pid=3924 execve guuid=6bf139c4-1a00-0000-07bf-6b0a900f0000 pid=3984 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=6bf139c4-1a00-0000-07bf-6b0a900f0000 pid=3984 execve guuid=fb569cc4-1a00-0000-07bf-6b0a920f0000 pid=3986 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=fb569cc4-1a00-0000-07bf-6b0a920f0000 pid=3986 execve guuid=2ee5e2c4-1a00-0000-07bf-6b0a940f0000 pid=3988 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=2ee5e2c4-1a00-0000-07bf-6b0a940f0000 pid=3988 clone guuid=fb6102c5-1a00-0000-07bf-6b0a950f0000 pid=3989 /usr/bin/wget net send-data guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=fb6102c5-1a00-0000-07bf-6b0a950f0000 pid=3989 execve guuid=b6f653d8-1a00-0000-07bf-6b0ad30f0000 pid=4051 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=b6f653d8-1a00-0000-07bf-6b0ad30f0000 pid=4051 execve guuid=2dc879ed-1a00-0000-07bf-6b0a0f100000 pid=4111 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=2dc879ed-1a00-0000-07bf-6b0a0f100000 pid=4111 execve guuid=5c6df6ed-1a00-0000-07bf-6b0a13100000 pid=4115 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=5c6df6ed-1a00-0000-07bf-6b0a13100000 pid=4115 execve guuid=93a065ee-1a00-0000-07bf-6b0a15100000 pid=4117 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=93a065ee-1a00-0000-07bf-6b0a15100000 pid=4117 clone guuid=7ae29bee-1a00-0000-07bf-6b0a16100000 pid=4118 /usr/bin/wget net send-data guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=7ae29bee-1a00-0000-07bf-6b0a16100000 pid=4118 execve guuid=b11a3602-1b00-0000-07bf-6b0a4b100000 pid=4171 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=b11a3602-1b00-0000-07bf-6b0a4b100000 pid=4171 execve guuid=399da216-1b00-0000-07bf-6b0a88100000 pid=4232 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=399da216-1b00-0000-07bf-6b0a88100000 pid=4232 execve guuid=e3f9ee16-1b00-0000-07bf-6b0a89100000 pid=4233 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=e3f9ee16-1b00-0000-07bf-6b0a89100000 pid=4233 execve guuid=2eb94317-1b00-0000-07bf-6b0a8b100000 pid=4235 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=2eb94317-1b00-0000-07bf-6b0a8b100000 pid=4235 clone guuid=bf277517-1b00-0000-07bf-6b0a8d100000 pid=4237 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=bf277517-1b00-0000-07bf-6b0a8d100000 pid=4237 execve guuid=5eb67934-1b00-0000-07bf-6b0af4100000 pid=4340 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=5eb67934-1b00-0000-07bf-6b0af4100000 pid=4340 execve guuid=90feed52-1b00-0000-07bf-6b0a51110000 pid=4433 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=90feed52-1b00-0000-07bf-6b0a51110000 pid=4433 execve guuid=fa269c53-1b00-0000-07bf-6b0a55110000 pid=4437 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=fa269c53-1b00-0000-07bf-6b0a55110000 pid=4437 execve guuid=981c3a54-1b00-0000-07bf-6b0a57110000 pid=4439 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=981c3a54-1b00-0000-07bf-6b0a57110000 pid=4439 clone guuid=e9525755-1b00-0000-07bf-6b0a5d110000 pid=4445 /usr/bin/wget net send-data guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=e9525755-1b00-0000-07bf-6b0a5d110000 pid=4445 execve guuid=62da9269-1b00-0000-07bf-6b0a9b110000 pid=4507 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=62da9269-1b00-0000-07bf-6b0a9b110000 pid=4507 execve guuid=ccadfa80-1b00-0000-07bf-6b0ad1110000 pid=4561 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=ccadfa80-1b00-0000-07bf-6b0ad1110000 pid=4561 execve guuid=e8b67e81-1b00-0000-07bf-6b0ad3110000 pid=4563 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=e8b67e81-1b00-0000-07bf-6b0ad3110000 pid=4563 execve guuid=a2a2e981-1b00-0000-07bf-6b0ad5110000 pid=4565 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=a2a2e981-1b00-0000-07bf-6b0ad5110000 pid=4565 clone guuid=0ad52f82-1b00-0000-07bf-6b0ad9110000 pid=4569 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=0ad52f82-1b00-0000-07bf-6b0ad9110000 pid=4569 execve guuid=1e589a9e-1b00-0000-07bf-6b0a3a120000 pid=4666 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=1e589a9e-1b00-0000-07bf-6b0a3a120000 pid=4666 execve guuid=afc08cbd-1b00-0000-07bf-6b0a9f120000 pid=4767 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=afc08cbd-1b00-0000-07bf-6b0a9f120000 pid=4767 execve guuid=cf1df3bd-1b00-0000-07bf-6b0aa0120000 pid=4768 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=cf1df3bd-1b00-0000-07bf-6b0aa0120000 pid=4768 execve guuid=a65854be-1b00-0000-07bf-6b0aa1120000 pid=4769 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=a65854be-1b00-0000-07bf-6b0aa1120000 pid=4769 clone guuid=5dd805bf-1b00-0000-07bf-6b0aa3120000 pid=4771 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=5dd805bf-1b00-0000-07bf-6b0aa3120000 pid=4771 execve guuid=a7e379df-1b00-0000-07bf-6b0af2120000 pid=4850 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=a7e379df-1b00-0000-07bf-6b0af2120000 pid=4850 execve guuid=fdcfc0fd-1b00-0000-07bf-6b0a40130000 pid=4928 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=fdcfc0fd-1b00-0000-07bf-6b0a40130000 pid=4928 execve guuid=333545fe-1b00-0000-07bf-6b0a42130000 pid=4930 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=333545fe-1b00-0000-07bf-6b0a42130000 pid=4930 execve guuid=454da5fe-1b00-0000-07bf-6b0a44130000 pid=4932 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=454da5fe-1b00-0000-07bf-6b0a44130000 pid=4932 clone guuid=f8ed46ff-1b00-0000-07bf-6b0a48130000 pid=4936 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=f8ed46ff-1b00-0000-07bf-6b0a48130000 pid=4936 execve guuid=38108b23-1c00-0000-07bf-6b0ac5130000 pid=5061 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=38108b23-1c00-0000-07bf-6b0ac5130000 pid=5061 execve guuid=0af2e147-1c00-0000-07bf-6b0a4d140000 pid=5197 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=0af2e147-1c00-0000-07bf-6b0a4d140000 pid=5197 execve guuid=63142b48-1c00-0000-07bf-6b0a4f140000 pid=5199 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=63142b48-1c00-0000-07bf-6b0a4f140000 pid=5199 execve guuid=b5686a48-1c00-0000-07bf-6b0a50140000 pid=5200 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=b5686a48-1c00-0000-07bf-6b0a50140000 pid=5200 clone guuid=38f00549-1c00-0000-07bf-6b0a54140000 pid=5204 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=38f00549-1c00-0000-07bf-6b0a54140000 pid=5204 execve guuid=aaf3dd63-1c00-0000-07bf-6b0a98140000 pid=5272 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=aaf3dd63-1c00-0000-07bf-6b0a98140000 pid=5272 execve guuid=ab80b57f-1c00-0000-07bf-6b0aa1140000 pid=5281 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=ab80b57f-1c00-0000-07bf-6b0aa1140000 pid=5281 execve guuid=805c1c80-1c00-0000-07bf-6b0aa2140000 pid=5282 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=805c1c80-1c00-0000-07bf-6b0aa2140000 pid=5282 execve guuid=cbbb7c80-1c00-0000-07bf-6b0aa3140000 pid=5283 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=cbbb7c80-1c00-0000-07bf-6b0aa3140000 pid=5283 clone guuid=edc17382-1c00-0000-07bf-6b0aa5140000 pid=5285 /usr/bin/wget net send-data guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=edc17382-1c00-0000-07bf-6b0aa5140000 pid=5285 execve guuid=e5b88695-1c00-0000-07bf-6b0aa6140000 pid=5286 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=e5b88695-1c00-0000-07bf-6b0aa6140000 pid=5286 execve guuid=cb83d6a9-1c00-0000-07bf-6b0aa7140000 pid=5287 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=cb83d6a9-1c00-0000-07bf-6b0aa7140000 pid=5287 execve guuid=aadb2caa-1c00-0000-07bf-6b0aa8140000 pid=5288 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=aadb2caa-1c00-0000-07bf-6b0aa8140000 pid=5288 execve guuid=ab307baa-1c00-0000-07bf-6b0aa9140000 pid=5289 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=ab307baa-1c00-0000-07bf-6b0aa9140000 pid=5289 clone guuid=d849a8aa-1c00-0000-07bf-6b0aaa140000 pid=5290 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=d849a8aa-1c00-0000-07bf-6b0aaa140000 pid=5290 execve guuid=169d39d0-1c00-0000-07bf-6b0aab140000 pid=5291 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=169d39d0-1c00-0000-07bf-6b0aab140000 pid=5291 execve guuid=2e9dadf8-1c00-0000-07bf-6b0aac140000 pid=5292 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=2e9dadf8-1c00-0000-07bf-6b0aac140000 pid=5292 execve guuid=f4b10ff9-1c00-0000-07bf-6b0aad140000 pid=5293 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=f4b10ff9-1c00-0000-07bf-6b0aad140000 pid=5293 execve guuid=8993b4f9-1c00-0000-07bf-6b0aae140000 pid=5294 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=8993b4f9-1c00-0000-07bf-6b0aae140000 pid=5294 clone guuid=c04761fa-1c00-0000-07bf-6b0ab0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=c04761fa-1c00-0000-07bf-6b0ab0140000 pid=5296 execve guuid=3c00bc20-1d00-0000-07bf-6b0ab1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=3c00bc20-1d00-0000-07bf-6b0ab1140000 pid=5297 execve guuid=818a1a47-1d00-0000-07bf-6b0ab9140000 pid=5305 /usr/bin/cat guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=818a1a47-1d00-0000-07bf-6b0ab9140000 pid=5305 execve guuid=a8cf9947-1d00-0000-07bf-6b0aba140000 pid=5306 /usr/bin/chmod guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=a8cf9947-1d00-0000-07bf-6b0aba140000 pid=5306 execve guuid=be3f0d48-1d00-0000-07bf-6b0abb140000 pid=5307 /usr/bin/bash guuid=75aea217-1a00-0000-07bf-6b0ac40d0000 pid=3524->guuid=be3f0d48-1d00-0000-07bf-6b0abb140000 pid=5307 clone e10eb183-c74b-539a-bc26-e43bbf2bbb51 38.162.114.77:80 guuid=88385c18-1a00-0000-07bf-6b0ac50d0000 pid=3525->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=21d9fe34-1a00-0000-07bf-6b0a0b0e0000 pid=3595->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=4c2e0d57-1a00-0000-07bf-6b0a4f0e0000 pid=3663->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5aa98c5b-1a00-0000-07bf-6b0a560e0000 pid=3670->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=9135bf77-1a00-0000-07bf-6b0aa00e0000 pid=3744->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=b242299d-1a00-0000-07bf-6b0a1e0f0000 pid=3870->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 144B guuid=f8d328b0-1a00-0000-07bf-6b0a540f0000 pid=3924->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 93B guuid=fb6102c5-1a00-0000-07bf-6b0a950f0000 pid=3989->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=b6f653d8-1a00-0000-07bf-6b0ad30f0000 pid=4051->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=7ae29bee-1a00-0000-07bf-6b0a16100000 pid=4118->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=b11a3602-1b00-0000-07bf-6b0a4b100000 pid=4171->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=bf277517-1b00-0000-07bf-6b0a8d100000 pid=4237->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=5eb67934-1b00-0000-07bf-6b0af4100000 pid=4340->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=e9525755-1b00-0000-07bf-6b0a5d110000 pid=4445->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=62da9269-1b00-0000-07bf-6b0a9b110000 pid=4507->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=0ad52f82-1b00-0000-07bf-6b0ad9110000 pid=4569->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=1e589a9e-1b00-0000-07bf-6b0a3a120000 pid=4666->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=5dd805bf-1b00-0000-07bf-6b0aa3120000 pid=4771->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=a7e379df-1b00-0000-07bf-6b0af2120000 pid=4850->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=f8ed46ff-1b00-0000-07bf-6b0a48130000 pid=4936->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=38108b23-1c00-0000-07bf-6b0ac5130000 pid=5061->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=38f00549-1c00-0000-07bf-6b0a54140000 pid=5204->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=aaf3dd63-1c00-0000-07bf-6b0a98140000 pid=5272->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B guuid=edc17382-1c00-0000-07bf-6b0aa5140000 pid=5285->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 146B guuid=e5b88695-1c00-0000-07bf-6b0aa6140000 pid=5286->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 95B guuid=d849a8aa-1c00-0000-07bf-6b0aaa140000 pid=5290->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 142B guuid=169d39d0-1c00-0000-07bf-6b0aab140000 pid=5291->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 91B guuid=c04761fa-1c00-0000-07bf-6b0ab0140000 pid=5296->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 141B guuid=3c00bc20-1d00-0000-07bf-6b0ab1140000 pid=5297->e10eb183-c74b-539a-bc26-e43bbf2bbb51 send: 90B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-09-06 06:30:51 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:sora antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (46494) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f233f77247bef987f907ba7fcd2e299ab754cd065a564fa7d86c8951eae17f24

(this sample)

  
Delivery method
Distributed via web download

Comments