MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f61a79f3386597ce686202aa195659930893b1fdd186c8ef70a9f429752533fe. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA File information Comments

SHA256 hash: f61a79f3386597ce686202aa195659930893b1fdd186c8ef70a9f429752533fe
SHA3-384 hash: 70e5e9f5c2eafe768de3d646bcdd8d6bab157571958b5be632e926a47be00ae3a4c614ddf42743a7a380acec3ceb3e28
SHA1 hash: e88347960169e0c67354e2d4be117bd26452eab4
MD5 hash: 66eb997d60688635d76dc64861feaf60
humanhash: illinois-coffee-oregon-network
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'505 bytes
First seen:2025-12-22 07:05:27 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vVsJ0V/o9bVJAJFahV6A6FLhVR6fVtOHVv+D4VglsV9+/VEhWVXA9VLsPV+r+V2O:v40W9bMGm92fiHW4MsK/WWW92PY+ioWw
TLSH T14C51D5C7230284386CF3992F32BAF014B2EE989E20DC9F8844D879EB455ED045E41A47
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.32.41.193//main_x86n/an/aelf ua-wget
http://89.32.41.193//main_mipsn/an/aelf ua-wget
http://89.32.41.193//main_arcn/an/aelf ua-wget
http://89.32.41.193//main_i468n/an/aelf ua-wget
http://89.32.41.193//main_i686n/an/aelf ua-wget
http://89.32.41.193//main_x86_64n/an/aelf ua-wget
http://89.32.41.193//main_mpsln/an/aelf ua-wget
http://89.32.41.193//main_armn/an/aelf ua-wget
http://89.32.41.193//main_arm5n/an/aelf ua-wget
http://89.32.41.193//main_arm6n/an/aelf ua-wget
http://89.32.41.193//main_arm72794c486f5b0e4d425491b85f24311210c3d821f797ae8c74b1f65ae8ac2cf2b Miraielf mirai ua-wget
http://89.32.41.193//main_ppcn/an/aelf ua-wget
http://89.32.41.193//main_spcn/an/aelf ua-wget
http://89.32.41.193//main_m68kn/an/aelf ua-wget
http://89.32.41.193//main_sh4n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-12-21T17:18:00Z UTC
Last seen:
2025-12-22T12:48:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=cf7462d2-1700-0000-2754-0579960c0000 pid=3222 /usr/bin/sudo guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224 /tmp/sample.bin guuid=cf7462d2-1700-0000-2754-0579960c0000 pid=3222->guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224 execve guuid=1a72d7d5-1700-0000-2754-0579990c0000 pid=3225 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=1a72d7d5-1700-0000-2754-0579990c0000 pid=3225 execve guuid=8f1ccfdf-1700-0000-2754-0579a70c0000 pid=3239 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8f1ccfdf-1700-0000-2754-0579a70c0000 pid=3239 execve guuid=f18611ec-1700-0000-2754-0579b10c0000 pid=3249 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=f18611ec-1700-0000-2754-0579b10c0000 pid=3249 execve guuid=575484ec-1700-0000-2754-0579b40c0000 pid=3252 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=575484ec-1700-0000-2754-0579b40c0000 pid=3252 execve guuid=8e68d2ec-1700-0000-2754-0579b60c0000 pid=3254 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8e68d2ec-1700-0000-2754-0579b60c0000 pid=3254 execve guuid=7721c1f2-1700-0000-2754-0579c70c0000 pid=3271 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=7721c1f2-1700-0000-2754-0579c70c0000 pid=3271 execve guuid=fa8152f8-1700-0000-2754-0579d80c0000 pid=3288 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=fa8152f8-1700-0000-2754-0579d80c0000 pid=3288 execve guuid=c4b12bff-1700-0000-2754-0579e90c0000 pid=3305 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=c4b12bff-1700-0000-2754-0579e90c0000 pid=3305 execve guuid=aa7275ff-1700-0000-2754-0579eb0c0000 pid=3307 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=aa7275ff-1700-0000-2754-0579eb0c0000 pid=3307 execve guuid=fdb9b6ff-1700-0000-2754-0579ec0c0000 pid=3308 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=fdb9b6ff-1700-0000-2754-0579ec0c0000 pid=3308 execve guuid=ed8a3d05-1800-0000-2754-0579000d0000 pid=3328 /usr/bin/wget net send-data guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=ed8a3d05-1800-0000-2754-0579000d0000 pid=3328 execve guuid=939d1b0b-1800-0000-2754-0579020d0000 pid=3330 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=939d1b0b-1800-0000-2754-0579020d0000 pid=3330 execve guuid=0bedab13-1800-0000-2754-0579140d0000 pid=3348 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=0bedab13-1800-0000-2754-0579140d0000 pid=3348 execve guuid=d8a90c14-1800-0000-2754-0579160d0000 pid=3350 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d8a90c14-1800-0000-2754-0579160d0000 pid=3350 execve guuid=058b7114-1800-0000-2754-0579170d0000 pid=3351 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=058b7114-1800-0000-2754-0579170d0000 pid=3351 clone guuid=02f39714-1800-0000-2754-0579190d0000 pid=3353 /usr/bin/wget net send-data guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=02f39714-1800-0000-2754-0579190d0000 pid=3353 execve guuid=199ced1b-1800-0000-2754-05792b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=199ced1b-1800-0000-2754-05792b0d0000 pid=3371 execve guuid=b263ba24-1800-0000-2754-0579390d0000 pid=3385 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=b263ba24-1800-0000-2754-0579390d0000 pid=3385 execve guuid=614f2f25-1800-0000-2754-05793b0d0000 pid=3387 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=614f2f25-1800-0000-2754-05793b0d0000 pid=3387 execve guuid=eadd7725-1800-0000-2754-05793d0d0000 pid=3389 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=eadd7725-1800-0000-2754-05793d0d0000 pid=3389 clone guuid=d9e49c25-1800-0000-2754-05793f0d0000 pid=3391 /usr/bin/wget net send-data guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d9e49c25-1800-0000-2754-05793f0d0000 pid=3391 execve guuid=44a6db2b-1800-0000-2754-05794f0d0000 pid=3407 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=44a6db2b-1800-0000-2754-05794f0d0000 pid=3407 execve guuid=42b5d933-1800-0000-2754-0579680d0000 pid=3432 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=42b5d933-1800-0000-2754-0579680d0000 pid=3432 execve guuid=fc7d5034-1800-0000-2754-05796a0d0000 pid=3434 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=fc7d5034-1800-0000-2754-05796a0d0000 pid=3434 execve guuid=d418ce34-1800-0000-2754-05796c0d0000 pid=3436 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d418ce34-1800-0000-2754-05796c0d0000 pid=3436 clone guuid=ccc80435-1800-0000-2754-05796e0d0000 pid=3438 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=ccc80435-1800-0000-2754-05796e0d0000 pid=3438 execve guuid=798be63b-1800-0000-2754-0579800d0000 pid=3456 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=798be63b-1800-0000-2754-0579800d0000 pid=3456 execve guuid=7d98be43-1800-0000-2754-0579920d0000 pid=3474 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=7d98be43-1800-0000-2754-0579920d0000 pid=3474 execve guuid=20be1e44-1800-0000-2754-0579950d0000 pid=3477 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=20be1e44-1800-0000-2754-0579950d0000 pid=3477 execve guuid=ccaa7744-1800-0000-2754-0579970d0000 pid=3479 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=ccaa7744-1800-0000-2754-0579970d0000 pid=3479 execve guuid=93c5994b-1800-0000-2754-0579ac0d0000 pid=3500 /usr/bin/wget net send-data guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=93c5994b-1800-0000-2754-0579ac0d0000 pid=3500 execve guuid=a0c1a050-1800-0000-2754-0579b90d0000 pid=3513 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=a0c1a050-1800-0000-2754-0579b90d0000 pid=3513 execve guuid=0d3e4459-1800-0000-2754-0579c80d0000 pid=3528 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=0d3e4459-1800-0000-2754-0579c80d0000 pid=3528 execve guuid=c5279159-1800-0000-2754-0579c90d0000 pid=3529 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=c5279159-1800-0000-2754-0579c90d0000 pid=3529 execve guuid=8045f359-1800-0000-2754-0579cb0d0000 pid=3531 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8045f359-1800-0000-2754-0579cb0d0000 pid=3531 clone guuid=8c8d1d5a-1800-0000-2754-0579cc0d0000 pid=3532 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8c8d1d5a-1800-0000-2754-0579cc0d0000 pid=3532 execve guuid=bda4a55f-1800-0000-2754-0579d40d0000 pid=3540 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=bda4a55f-1800-0000-2754-0579d40d0000 pid=3540 execve guuid=d67b9c68-1800-0000-2754-0579e90d0000 pid=3561 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d67b9c68-1800-0000-2754-0579e90d0000 pid=3561 execve guuid=1f011969-1800-0000-2754-0579eb0d0000 pid=3563 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=1f011969-1800-0000-2754-0579eb0d0000 pid=3563 execve guuid=ef167e69-1800-0000-2754-0579ed0d0000 pid=3565 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=ef167e69-1800-0000-2754-0579ed0d0000 pid=3565 execve guuid=02b3ff6e-1800-0000-2754-0579000e0000 pid=3584 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=02b3ff6e-1800-0000-2754-0579000e0000 pid=3584 execve guuid=80d7fb75-1800-0000-2754-0579120e0000 pid=3602 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=80d7fb75-1800-0000-2754-0579120e0000 pid=3602 execve guuid=a7016e7d-1800-0000-2754-0579250e0000 pid=3621 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=a7016e7d-1800-0000-2754-0579250e0000 pid=3621 execve guuid=759dc27d-1800-0000-2754-0579260e0000 pid=3622 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=759dc27d-1800-0000-2754-0579260e0000 pid=3622 execve guuid=678f0c7e-1800-0000-2754-0579270e0000 pid=3623 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=678f0c7e-1800-0000-2754-0579270e0000 pid=3623 execve guuid=c4b96883-1800-0000-2754-0579370e0000 pid=3639 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=c4b96883-1800-0000-2754-0579370e0000 pid=3639 execve guuid=7a77a288-1800-0000-2754-0579400e0000 pid=3648 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=7a77a288-1800-0000-2754-0579400e0000 pid=3648 execve guuid=3176a590-1800-0000-2754-0579580e0000 pid=3672 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=3176a590-1800-0000-2754-0579580e0000 pid=3672 execve guuid=3e5a1e91-1800-0000-2754-05795a0e0000 pid=3674 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=3e5a1e91-1800-0000-2754-05795a0e0000 pid=3674 execve guuid=469e9e91-1800-0000-2754-05795d0e0000 pid=3677 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=469e9e91-1800-0000-2754-05795d0e0000 pid=3677 execve guuid=eb5fd197-1800-0000-2754-0579740e0000 pid=3700 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=eb5fd197-1800-0000-2754-0579740e0000 pid=3700 execve guuid=562549a4-1800-0000-2754-0579870e0000 pid=3719 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=562549a4-1800-0000-2754-0579870e0000 pid=3719 execve guuid=e6127bb6-1800-0000-2754-0579b40e0000 pid=3764 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=e6127bb6-1800-0000-2754-0579b40e0000 pid=3764 execve guuid=09ed23b7-1800-0000-2754-0579b60e0000 pid=3766 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=09ed23b7-1800-0000-2754-0579b60e0000 pid=3766 execve guuid=2ec0a9b7-1800-0000-2754-0579ba0e0000 pid=3770 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=2ec0a9b7-1800-0000-2754-0579ba0e0000 pid=3770 clone guuid=81e4f6b8-1800-0000-2754-0579c10e0000 pid=3777 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=81e4f6b8-1800-0000-2754-0579c10e0000 pid=3777 execve guuid=30fe04bf-1800-0000-2754-0579d70e0000 pid=3799 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=30fe04bf-1800-0000-2754-0579d70e0000 pid=3799 execve guuid=f84b00c5-1800-0000-2754-0579e70e0000 pid=3815 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=f84b00c5-1800-0000-2754-0579e70e0000 pid=3815 execve guuid=8e3474c5-1800-0000-2754-0579ea0e0000 pid=3818 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8e3474c5-1800-0000-2754-0579ea0e0000 pid=3818 execve guuid=8b65d2c5-1800-0000-2754-0579ec0e0000 pid=3820 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=8b65d2c5-1800-0000-2754-0579ec0e0000 pid=3820 execve guuid=a84d76cc-1800-0000-2754-05790b0f0000 pid=3851 /usr/bin/wget net send-data guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=a84d76cc-1800-0000-2754-05790b0f0000 pid=3851 execve guuid=f332c6d1-1800-0000-2754-0579230f0000 pid=3875 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=f332c6d1-1800-0000-2754-0579230f0000 pid=3875 execve guuid=5348b9da-1800-0000-2754-05793e0f0000 pid=3902 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=5348b9da-1800-0000-2754-05793e0f0000 pid=3902 execve guuid=940614db-1800-0000-2754-0579400f0000 pid=3904 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=940614db-1800-0000-2754-0579400f0000 pid=3904 execve guuid=7e8593db-1800-0000-2754-0579420f0000 pid=3906 /usr/bin/bash guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=7e8593db-1800-0000-2754-0579420f0000 pid=3906 clone guuid=f472c6db-1800-0000-2754-0579430f0000 pid=3907 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=f472c6db-1800-0000-2754-0579430f0000 pid=3907 execve guuid=d37b07e1-1800-0000-2754-0579530f0000 pid=3923 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d37b07e1-1800-0000-2754-0579530f0000 pid=3923 execve guuid=4da8f4e6-1800-0000-2754-0579690f0000 pid=3945 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=4da8f4e6-1800-0000-2754-0579690f0000 pid=3945 execve guuid=671374e7-1800-0000-2754-05796c0f0000 pid=3948 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=671374e7-1800-0000-2754-05796c0f0000 pid=3948 execve guuid=bd9edee7-1800-0000-2754-05796d0f0000 pid=3949 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=bd9edee7-1800-0000-2754-05796d0f0000 pid=3949 execve guuid=70c64fed-1800-0000-2754-0579850f0000 pid=3973 /usr/bin/wget net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=70c64fed-1800-0000-2754-0579850f0000 pid=3973 execve guuid=d55f62f2-1800-0000-2754-0579910f0000 pid=3985 /usr/bin/curl net send-data write-file guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=d55f62f2-1800-0000-2754-0579910f0000 pid=3985 execve guuid=96d149f9-1800-0000-2754-0579ad0f0000 pid=4013 /usr/bin/cat guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=96d149f9-1800-0000-2754-0579ad0f0000 pid=4013 execve guuid=816d8ef9-1800-0000-2754-0579af0f0000 pid=4015 /usr/bin/chmod guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=816d8ef9-1800-0000-2754-0579af0f0000 pid=4015 execve guuid=0f73d1f9-1800-0000-2754-0579b10f0000 pid=4017 /tmp/WTF guuid=389624d5-1700-0000-2754-0579980c0000 pid=3224->guuid=0f73d1f9-1800-0000-2754-0579b10f0000 pid=4017 execve ef835abf-9ad8-5e99-94a0-f7c24f035fa6 89.32.41.193:80 guuid=1a72d7d5-1700-0000-2754-0579990c0000 pid=3225->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=8f1ccfdf-1700-0000-2754-0579a70c0000 pid=3239->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=fc1305ed-1700-0000-2754-0579b70c0000 pid=3255 /usr/bin/wget net send-data guuid=8e68d2ec-1700-0000-2754-0579b60c0000 pid=3254->guuid=fc1305ed-1700-0000-2754-0579b70c0000 pid=3255 execve guuid=fc1305ed-1700-0000-2754-0579b70c0000 pid=3255->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=7721c1f2-1700-0000-2754-0579c70c0000 pid=3271->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=fa8152f8-1700-0000-2754-0579d80c0000 pid=3288->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=04dde3ff-1700-0000-2754-0579ee0c0000 pid=3310 /usr/bin/wget net send-data guuid=fdb9b6ff-1700-0000-2754-0579ec0c0000 pid=3308->guuid=04dde3ff-1700-0000-2754-0579ee0c0000 pid=3310 execve guuid=04dde3ff-1700-0000-2754-0579ee0c0000 pid=3310->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=ed8a3d05-1800-0000-2754-0579000d0000 pid=3328->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=939d1b0b-1800-0000-2754-0579020d0000 pid=3330->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=02f39714-1800-0000-2754-0579190d0000 pid=3353->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=199ced1b-1800-0000-2754-05792b0d0000 pid=3371->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=d9e49c25-1800-0000-2754-05793f0d0000 pid=3391->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=44a6db2b-1800-0000-2754-05794f0d0000 pid=3407->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=ccc80435-1800-0000-2754-05796e0d0000 pid=3438->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 139B guuid=798be63b-1800-0000-2754-0579800d0000 pid=3456->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 88B guuid=8c30b644-1800-0000-2754-0579980d0000 pid=3480 /usr/bin/wget net send-data guuid=ccaa7744-1800-0000-2754-0579970d0000 pid=3479->guuid=8c30b644-1800-0000-2754-0579980d0000 pid=3480 execve guuid=8c30b644-1800-0000-2754-0579980d0000 pid=3480->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=93c5994b-1800-0000-2754-0579ac0d0000 pid=3500->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=a0c1a050-1800-0000-2754-0579b90d0000 pid=3513->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=8c8d1d5a-1800-0000-2754-0579cc0d0000 pid=3532->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=bda4a55f-1800-0000-2754-0579d40d0000 pid=3540->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=1a1dc769-1800-0000-2754-0579ef0d0000 pid=3567 /usr/bin/wget net send-data guuid=ef167e69-1800-0000-2754-0579ed0d0000 pid=3565->guuid=1a1dc769-1800-0000-2754-0579ef0d0000 pid=3567 execve guuid=1a1dc769-1800-0000-2754-0579ef0d0000 pid=3567->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=02b3ff6e-1800-0000-2754-0579000e0000 pid=3584->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=80d7fb75-1800-0000-2754-0579120e0000 pid=3602->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=2723417e-1800-0000-2754-0579290e0000 pid=3625 /usr/bin/wget net send-data guuid=678f0c7e-1800-0000-2754-0579270e0000 pid=3623->guuid=2723417e-1800-0000-2754-0579290e0000 pid=3625 execve guuid=2723417e-1800-0000-2754-0579290e0000 pid=3625->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=c4b96883-1800-0000-2754-0579370e0000 pid=3639->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=7a77a288-1800-0000-2754-0579400e0000 pid=3648->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=9497e391-1800-0000-2754-05795e0e0000 pid=3678 /usr/bin/wget net send-data guuid=469e9e91-1800-0000-2754-05795d0e0000 pid=3677->guuid=9497e391-1800-0000-2754-05795e0e0000 pid=3678 execve guuid=9497e391-1800-0000-2754-05795e0e0000 pid=3678->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=eb5fd197-1800-0000-2754-0579740e0000 pid=3700->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=562549a4-1800-0000-2754-0579870e0000 pid=3719->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=81e4f6b8-1800-0000-2754-0579c10e0000 pid=3777->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=30fe04bf-1800-0000-2754-0579d70e0000 pid=3799->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=c4b81fc6-1800-0000-2754-0579ee0e0000 pid=3822 /usr/bin/wget net send-data guuid=8b65d2c5-1800-0000-2754-0579ec0e0000 pid=3820->guuid=c4b81fc6-1800-0000-2754-0579ee0e0000 pid=3822 execve guuid=c4b81fc6-1800-0000-2754-0579ee0e0000 pid=3822->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=a84d76cc-1800-0000-2754-05790b0f0000 pid=3851->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=f332c6d1-1800-0000-2754-0579230f0000 pid=3875->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=f472c6db-1800-0000-2754-0579430f0000 pid=3907->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 137B guuid=d37b07e1-1800-0000-2754-0579530f0000 pid=3923->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 86B guuid=7edb25e8-1800-0000-2754-0579710f0000 pid=3953 /usr/bin/wget net send-data guuid=bd9edee7-1800-0000-2754-05796d0f0000 pid=3949->guuid=7edb25e8-1800-0000-2754-0579710f0000 pid=3953 execve guuid=7edb25e8-1800-0000-2754-0579710f0000 pid=3953->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B guuid=70c64fed-1800-0000-2754-0579850f0000 pid=3973->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 136B guuid=d55f62f2-1800-0000-2754-0579910f0000 pid=3985->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 85B guuid=7aaefef9-1800-0000-2754-0579b20f0000 pid=4018 /usr/bin/wget net send-data guuid=0f73d1f9-1800-0000-2754-0579b10f0000 pid=4017->guuid=7aaefef9-1800-0000-2754-0579b20f0000 pid=4018 execve guuid=7aaefef9-1800-0000-2754-0579b20f0000 pid=4018->ef835abf-9ad8-5e99-94a0-f7c24f035fa6 send: 133B
Threat name:
Linux.Downloader.Morila
Status:
Malicious
First seen:
2025-12-22 02:04:00 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Traces itself
Mirai
Mirai family
Malware Config
C2 Extraction:
lited.myftp.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f61a79f3386597ce686202aa195659930893b1fdd186c8ef70a9f429752533fe

(this sample)

  
Delivery method
Distributed via web download

Comments