MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 13a07121d74dafa9f2ba4bb2d64fe8a9be9dd1827b8eb4aaf154299958c62b2e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 13a07121d74dafa9f2ba4bb2d64fe8a9be9dd1827b8eb4aaf154299958c62b2e
SHA3-384 hash: 5082eda98dc1fbbb457f9290e54f3ef3dc66ae5bd340f9235a0ef9ec52b69ff5f5386572b3cfaf8228fddf6b85142897
SHA1 hash: 543cd009fb5bb7d49715552fce514f8aec6e4a48
MD5 hash: 571f92bcbccca4330e476cd999aaa1a7
humanhash: magazine-jersey-nine-missouri
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2025-09-08 14:22:43 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vpx70x7N7hpxvx6GpxgnxzPpxfxKWpx1xoUpx71x7o7UpxfOx3bpxEx9Rpxhxcg3:vT7q7N7hTZ6GTgxzPTJKWTnoUT7n7o7+
TLSH T1B751D6C582846D302DB7EB13F7B6C128308190979CEA7F99D9CCFAE8869ED147148B53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.149.23/hiddenbin/boatnet.x86ad6587e8cd903beda37a7ebbcdf5fce2931a8ac91b462fca04e042ae2d75d6b8 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.mipsc6387ca4478a96ab000530098b2ed43e8413853dddb5db6b238d1ad97145ea9f Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.arc48287062699959950e419d9d411c6b77676f590f1c1dc61b63196c900538c3b4 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://176.65.149.23/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://176.65.149.23/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://176.65.149.23/hiddenbin/boatnet.mpsl49295efe77ab2354c10389128a0e642a9b1105b76e5959a3a978c4fcf5d46432 Mirai32-bit elf mirai Mozi
http://176.65.149.23/hiddenbin/boatnet.armdc5277aba17d1ac2774b1e3e41cfc06610ae208518045f54c8cc552ac31b4227 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.arm5395dc40310b3f119b6e9f58134295f3846a97cae22afbebe83dc84ad2e1878fb Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.arm6248b51a4f77c442decae3c247009b9a31b7bc8af6a2203196e5f2d583dfceec2 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.arm7dc42fcb7587dbfcf39bd7e6ea9c731d0351f7e02c8a3eaffd74cc26297cd7944 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.ppcf3cb6f12228a5191515645660fc1dc6e00d87e2dfa97f54fa02f133e2a73f154 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://176.65.149.23/hiddenbin/boatnet.m68k5a350ad8524816744b8fd9bbc6e95157d7b347f91fc23afc9adb4876c20bd3e4 Miraielf mirai ua-wget
http://176.65.149.23/hiddenbin/boatnet.sh44f30c9c1e8679bfdf29ac44f315ee78543c56a82c69880d0af06cb44b648e698 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
31
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-07T15:21:00Z UTC
Last seen:
2025-09-07T15:21:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=05d43bf5-1900-0000-d3a7-a5afa0080000 pid=2208 /usr/bin/sudo guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214 /tmp/sample.bin guuid=05d43bf5-1900-0000-d3a7-a5afa0080000 pid=2208->guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214 execve guuid=393e91f7-1900-0000-d3a7-a5afa8080000 pid=2216 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=393e91f7-1900-0000-d3a7-a5afa8080000 pid=2216 execve guuid=c774b602-1a00-0000-d3a7-a5afc9080000 pid=2249 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=c774b602-1a00-0000-d3a7-a5afc9080000 pid=2249 execve guuid=c8a39114-1a00-0000-d3a7-a5afea080000 pid=2282 /usr/bin/cat guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=c8a39114-1a00-0000-d3a7-a5afea080000 pid=2282 execve guuid=fa580315-1a00-0000-d3a7-a5afec080000 pid=2284 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=fa580315-1a00-0000-d3a7-a5afec080000 pid=2284 execve guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286 execve guuid=da3f6016-1a00-0000-d3a7-a5aff6080000 pid=2294 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=da3f6016-1a00-0000-d3a7-a5aff6080000 pid=2294 execve guuid=fbe6fc21-1a00-0000-d3a7-a5af11090000 pid=2321 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=fbe6fc21-1a00-0000-d3a7-a5af11090000 pid=2321 execve guuid=54060235-1a00-0000-d3a7-a5af2b090000 pid=2347 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=54060235-1a00-0000-d3a7-a5af2b090000 pid=2347 clone guuid=bef35335-1a00-0000-d3a7-a5af2c090000 pid=2348 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=bef35335-1a00-0000-d3a7-a5af2c090000 pid=2348 execve guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349 execve guuid=becda336-1a00-0000-d3a7-a5af31090000 pid=2353 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=becda336-1a00-0000-d3a7-a5af31090000 pid=2353 execve guuid=7b217e43-1a00-0000-d3a7-a5af3f090000 pid=2367 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=7b217e43-1a00-0000-d3a7-a5af3f090000 pid=2367 execve guuid=151b5852-1a00-0000-d3a7-a5af5e090000 pid=2398 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=151b5852-1a00-0000-d3a7-a5af5e090000 pid=2398 clone guuid=0bc78052-1a00-0000-d3a7-a5af5f090000 pid=2399 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=0bc78052-1a00-0000-d3a7-a5af5f090000 pid=2399 execve guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400 execve guuid=832a2254-1a00-0000-d3a7-a5af65090000 pid=2405 /usr/bin/wget net send-data guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=832a2254-1a00-0000-d3a7-a5af65090000 pid=2405 execve guuid=4c20a259-1a00-0000-d3a7-a5af71090000 pid=2417 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=4c20a259-1a00-0000-d3a7-a5af71090000 pid=2417 execve guuid=0b8b0162-1a00-0000-d3a7-a5af7e090000 pid=2430 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=0b8b0162-1a00-0000-d3a7-a5af7e090000 pid=2430 clone guuid=4f391d62-1a00-0000-d3a7-a5af80090000 pid=2432 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=4f391d62-1a00-0000-d3a7-a5af80090000 pid=2432 execve guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433 execve guuid=73a92d63-1a00-0000-d3a7-a5af87090000 pid=2439 /usr/bin/wget net send-data guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=73a92d63-1a00-0000-d3a7-a5af87090000 pid=2439 execve guuid=91b63a6a-1a00-0000-d3a7-a5af91090000 pid=2449 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=91b63a6a-1a00-0000-d3a7-a5af91090000 pid=2449 execve guuid=1c2a9d70-1a00-0000-d3a7-a5afa0090000 pid=2464 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=1c2a9d70-1a00-0000-d3a7-a5afa0090000 pid=2464 clone guuid=868fc470-1a00-0000-d3a7-a5afa1090000 pid=2465 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=868fc470-1a00-0000-d3a7-a5afa1090000 pid=2465 execve guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467 execve guuid=d7b6e871-1a00-0000-d3a7-a5afa9090000 pid=2473 /usr/bin/wget net send-data guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=d7b6e871-1a00-0000-d3a7-a5afa9090000 pid=2473 execve guuid=7fb4eb76-1a00-0000-d3a7-a5afb5090000 pid=2485 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=7fb4eb76-1a00-0000-d3a7-a5afb5090000 pid=2485 execve guuid=9bc1067d-1a00-0000-d3a7-a5afca090000 pid=2506 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=9bc1067d-1a00-0000-d3a7-a5afca090000 pid=2506 clone guuid=cd7c2a7d-1a00-0000-d3a7-a5afcb090000 pid=2507 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=cd7c2a7d-1a00-0000-d3a7-a5afcb090000 pid=2507 execve guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509 execve guuid=e3ff227e-1a00-0000-d3a7-a5afd3090000 pid=2515 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=e3ff227e-1a00-0000-d3a7-a5afd3090000 pid=2515 execve guuid=11f68a87-1a00-0000-d3a7-a5afe8090000 pid=2536 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=11f68a87-1a00-0000-d3a7-a5afe8090000 pid=2536 execve guuid=b8d73e93-1a00-0000-d3a7-a5af020a0000 pid=2562 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=b8d73e93-1a00-0000-d3a7-a5af020a0000 pid=2562 clone guuid=d1dd7993-1a00-0000-d3a7-a5af040a0000 pid=2564 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=d1dd7993-1a00-0000-d3a7-a5af040a0000 pid=2564 execve guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567 execve guuid=1fcfcb94-1a00-0000-d3a7-a5af0e0a0000 pid=2574 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=1fcfcb94-1a00-0000-d3a7-a5af0e0a0000 pid=2574 execve guuid=66d55d9e-1a00-0000-d3a7-a5af160a0000 pid=2582 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=66d55d9e-1a00-0000-d3a7-a5af160a0000 pid=2582 execve guuid=b7fa73ac-1a00-0000-d3a7-a5af3e0a0000 pid=2622 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=b7fa73ac-1a00-0000-d3a7-a5af3e0a0000 pid=2622 clone guuid=6da291ac-1a00-0000-d3a7-a5af3f0a0000 pid=2623 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=6da291ac-1a00-0000-d3a7-a5af3f0a0000 pid=2623 execve guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626 execve guuid=02dcc6ad-1a00-0000-d3a7-a5af490a0000 pid=2633 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=02dcc6ad-1a00-0000-d3a7-a5af490a0000 pid=2633 execve guuid=9e11d9b4-1a00-0000-d3a7-a5af5f0a0000 pid=2655 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=9e11d9b4-1a00-0000-d3a7-a5af5f0a0000 pid=2655 execve guuid=609489bd-1a00-0000-d3a7-a5af7d0a0000 pid=2685 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=609489bd-1a00-0000-d3a7-a5af7d0a0000 pid=2685 clone guuid=5bc7a7bd-1a00-0000-d3a7-a5af7e0a0000 pid=2686 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=5bc7a7bd-1a00-0000-d3a7-a5af7e0a0000 pid=2686 execve guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688 execve guuid=cc81dfbe-1a00-0000-d3a7-a5af870a0000 pid=2695 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=cc81dfbe-1a00-0000-d3a7-a5af870a0000 pid=2695 execve guuid=f5bef3c9-1a00-0000-d3a7-a5afa50a0000 pid=2725 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=f5bef3c9-1a00-0000-d3a7-a5afa50a0000 pid=2725 execve guuid=4ab7dbd4-1a00-0000-d3a7-a5afc50a0000 pid=2757 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=4ab7dbd4-1a00-0000-d3a7-a5afc50a0000 pid=2757 clone guuid=3fb907d5-1a00-0000-d3a7-a5afc60a0000 pid=2758 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=3fb907d5-1a00-0000-d3a7-a5afc60a0000 pid=2758 execve guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760 execve guuid=3b0628d6-1a00-0000-d3a7-a5afcf0a0000 pid=2767 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=3b0628d6-1a00-0000-d3a7-a5afcf0a0000 pid=2767 execve guuid=d51b21e0-1a00-0000-d3a7-a5afea0a0000 pid=2794 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=d51b21e0-1a00-0000-d3a7-a5afea0a0000 pid=2794 execve guuid=3fbf95ea-1a00-0000-d3a7-a5af030b0000 pid=2819 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=3fbf95ea-1a00-0000-d3a7-a5af030b0000 pid=2819 clone guuid=0ab9b4ea-1a00-0000-d3a7-a5af040b0000 pid=2820 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=0ab9b4ea-1a00-0000-d3a7-a5af040b0000 pid=2820 execve guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821 execve guuid=f35838ec-1a00-0000-d3a7-a5af0d0b0000 pid=2829 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=f35838ec-1a00-0000-d3a7-a5af0d0b0000 pid=2829 execve guuid=fe6dcdf6-1a00-0000-d3a7-a5af170b0000 pid=2839 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=fe6dcdf6-1a00-0000-d3a7-a5af170b0000 pid=2839 execve guuid=87e72703-1b00-0000-d3a7-a5af2d0b0000 pid=2861 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=87e72703-1b00-0000-d3a7-a5af2d0b0000 pid=2861 clone guuid=0e764703-1b00-0000-d3a7-a5af2e0b0000 pid=2862 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=0e764703-1b00-0000-d3a7-a5af2e0b0000 pid=2862 execve guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863 execve guuid=52f45e04-1b00-0000-d3a7-a5af330b0000 pid=2867 /usr/bin/wget net send-data guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=52f45e04-1b00-0000-d3a7-a5af330b0000 pid=2867 execve guuid=8405e109-1b00-0000-d3a7-a5af420b0000 pid=2882 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=8405e109-1b00-0000-d3a7-a5af420b0000 pid=2882 execve guuid=80a90e10-1b00-0000-d3a7-a5af480b0000 pid=2888 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=80a90e10-1b00-0000-d3a7-a5af480b0000 pid=2888 clone guuid=53ad3410-1b00-0000-d3a7-a5af490b0000 pid=2889 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=53ad3410-1b00-0000-d3a7-a5af490b0000 pid=2889 execve guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890 execve guuid=e5737c11-1b00-0000-d3a7-a5af510b0000 pid=2897 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=e5737c11-1b00-0000-d3a7-a5af510b0000 pid=2897 execve guuid=84067d1d-1b00-0000-d3a7-a5af660b0000 pid=2918 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=84067d1d-1b00-0000-d3a7-a5af660b0000 pid=2918 execve guuid=961bf12a-1b00-0000-d3a7-a5af810b0000 pid=2945 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=961bf12a-1b00-0000-d3a7-a5af810b0000 pid=2945 clone guuid=c96d0d2b-1b00-0000-d3a7-a5af830b0000 pid=2947 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=c96d0d2b-1b00-0000-d3a7-a5af830b0000 pid=2947 execve guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948 execve guuid=1be41e2c-1b00-0000-d3a7-a5af890b0000 pid=2953 /usr/bin/wget net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=1be41e2c-1b00-0000-d3a7-a5af890b0000 pid=2953 execve guuid=2c9fa039-1b00-0000-d3a7-a5afac0b0000 pid=2988 /usr/bin/curl net send-data write-file guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=2c9fa039-1b00-0000-d3a7-a5afac0b0000 pid=2988 execve guuid=4633cf4a-1b00-0000-d3a7-a5afd30b0000 pid=3027 /usr/bin/bash guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=4633cf4a-1b00-0000-d3a7-a5afd30b0000 pid=3027 clone guuid=4e7af34a-1b00-0000-d3a7-a5afd50b0000 pid=3029 /usr/bin/chmod guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=4e7af34a-1b00-0000-d3a7-a5afd50b0000 pid=3029 execve guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031 /tmp/WTF net guuid=154a00f7-1900-0000-d3a7-a5afa6080000 pid=2214->guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031 execve 33c43df8-4f2f-5748-96ff-21010ff25a74 176.65.149.23:80 guuid=393e91f7-1900-0000-d3a7-a5afa8080000 pid=2216->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=c774b602-1a00-0000-d3a7-a5afc9080000 pid=2249->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=77eb4316-1a00-0000-d3a7-a5aff3080000 pid=2291 /tmp/WTF guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286->guuid=77eb4316-1a00-0000-d3a7-a5aff3080000 pid=2291 clone guuid=81474916-1a00-0000-d3a7-a5aff4080000 pid=2292 /tmp/WTF guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286->guuid=81474916-1a00-0000-d3a7-a5aff4080000 pid=2292 clone guuid=49525016-1a00-0000-d3a7-a5aff5080000 pid=2293 /tmp/WTF net send-data zombie guuid=72ea5f15-1a00-0000-d3a7-a5afee080000 pid=2286->guuid=49525016-1a00-0000-d3a7-a5aff5080000 pid=2293 clone guuid=49525016-1a00-0000-d3a7-a5aff5080000 pid=2293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b6227d2c-1ffc-578a-a536-5d08c4440c1f 176.65.149.23:3778 guuid=49525016-1a00-0000-d3a7-a5aff5080000 pid=2293->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=76c2a4c4-2000-0000-d3a7-a5afe6140000 pid=5350 /tmp/WTF net send-data guuid=49525016-1a00-0000-d3a7-a5aff5080000 pid=2293->guuid=76c2a4c4-2000-0000-d3a7-a5afe6140000 pid=5350 clone guuid=da3f6016-1a00-0000-d3a7-a5aff6080000 pid=2294->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=fbe6fc21-1a00-0000-d3a7-a5af11090000 pid=2321->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=aabc6e36-1a00-0000-d3a7-a5af2e090000 pid=2350 /tmp/WTF guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349->guuid=aabc6e36-1a00-0000-d3a7-a5af2e090000 pid=2350 clone guuid=d51e7736-1a00-0000-d3a7-a5af2f090000 pid=2351 /tmp/WTF guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349->guuid=d51e7736-1a00-0000-d3a7-a5af2f090000 pid=2351 clone guuid=b2758236-1a00-0000-d3a7-a5af30090000 pid=2352 /tmp/WTF net send-data zombie guuid=c079d735-1a00-0000-d3a7-a5af2d090000 pid=2349->guuid=b2758236-1a00-0000-d3a7-a5af30090000 pid=2352 clone guuid=b2758236-1a00-0000-d3a7-a5af30090000 pid=2352->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b2758236-1a00-0000-d3a7-a5af30090000 pid=2352->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=d8d737c9-2000-0000-d3a7-a5aff6140000 pid=5366 /tmp/WTF net send-data guuid=b2758236-1a00-0000-d3a7-a5af30090000 pid=2352->guuid=d8d737c9-2000-0000-d3a7-a5aff6140000 pid=5366 clone guuid=becda336-1a00-0000-d3a7-a5af31090000 pid=2353->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=7b217e43-1a00-0000-d3a7-a5af3f090000 pid=2367->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0a130654-1a00-0000-d3a7-a5af62090000 pid=2402 /tmp/WTF guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400->guuid=0a130654-1a00-0000-d3a7-a5af62090000 pid=2402 clone guuid=22860d54-1a00-0000-d3a7-a5af63090000 pid=2403 /tmp/WTF guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400->guuid=22860d54-1a00-0000-d3a7-a5af63090000 pid=2403 clone guuid=70421254-1a00-0000-d3a7-a5af64090000 pid=2404 /tmp/WTF net send-data zombie guuid=835c0c53-1a00-0000-d3a7-a5af60090000 pid=2400->guuid=70421254-1a00-0000-d3a7-a5af64090000 pid=2404 clone guuid=70421254-1a00-0000-d3a7-a5af64090000 pid=2404->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70421254-1a00-0000-d3a7-a5af64090000 pid=2404->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=109d7cc4-2000-0000-d3a7-a5afe1140000 pid=5345 /tmp/WTF net send-data guuid=70421254-1a00-0000-d3a7-a5af64090000 pid=2404->guuid=109d7cc4-2000-0000-d3a7-a5afe1140000 pid=5345 clone guuid=832a2254-1a00-0000-d3a7-a5af65090000 pid=2405->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=4c20a259-1a00-0000-d3a7-a5af71090000 pid=2417->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9bb70f63-1a00-0000-d3a7-a5af84090000 pid=2436 /tmp/WTF guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433->guuid=9bb70f63-1a00-0000-d3a7-a5af84090000 pid=2436 clone guuid=c7901463-1a00-0000-d3a7-a5af85090000 pid=2437 /tmp/WTF guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433->guuid=c7901463-1a00-0000-d3a7-a5af85090000 pid=2437 clone guuid=40cf1b63-1a00-0000-d3a7-a5af86090000 pid=2438 /tmp/WTF net send-data zombie guuid=6fbe6a62-1a00-0000-d3a7-a5af81090000 pid=2433->guuid=40cf1b63-1a00-0000-d3a7-a5af86090000 pid=2438 clone guuid=40cf1b63-1a00-0000-d3a7-a5af86090000 pid=2438->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=40cf1b63-1a00-0000-d3a7-a5af86090000 pid=2438->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=1696a3c4-2000-0000-d3a7-a5afe5140000 pid=5349 /tmp/WTF net send-data guuid=40cf1b63-1a00-0000-d3a7-a5af86090000 pid=2438->guuid=1696a3c4-2000-0000-d3a7-a5afe5140000 pid=5349 clone guuid=73a92d63-1a00-0000-d3a7-a5af87090000 pid=2439->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=91b63a6a-1a00-0000-d3a7-a5af91090000 pid=2449->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2ab0d071-1a00-0000-d3a7-a5afa6090000 pid=2470 /tmp/WTF guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467->guuid=2ab0d071-1a00-0000-d3a7-a5afa6090000 pid=2470 clone guuid=1467d571-1a00-0000-d3a7-a5afa7090000 pid=2471 /tmp/WTF guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467->guuid=1467d571-1a00-0000-d3a7-a5afa7090000 pid=2471 clone guuid=415ada71-1a00-0000-d3a7-a5afa8090000 pid=2472 /tmp/WTF net send-data zombie guuid=c3042871-1a00-0000-d3a7-a5afa3090000 pid=2467->guuid=415ada71-1a00-0000-d3a7-a5afa8090000 pid=2472 clone guuid=415ada71-1a00-0000-d3a7-a5afa8090000 pid=2472->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=415ada71-1a00-0000-d3a7-a5afa8090000 pid=2472->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=076ddbc5-2000-0000-d3a7-a5afee140000 pid=5358 /tmp/WTF net send-data guuid=415ada71-1a00-0000-d3a7-a5afa8090000 pid=2472->guuid=076ddbc5-2000-0000-d3a7-a5afee140000 pid=5358 clone guuid=d7b6e871-1a00-0000-d3a7-a5afa9090000 pid=2473->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 152B guuid=7fb4eb76-1a00-0000-d3a7-a5afb5090000 pid=2485->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 101B guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0791077e-1a00-0000-d3a7-a5afd0090000 pid=2512 /tmp/WTF guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509->guuid=0791077e-1a00-0000-d3a7-a5afd0090000 pid=2512 clone guuid=9e080b7e-1a00-0000-d3a7-a5afd1090000 pid=2513 /tmp/WTF guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509->guuid=9e080b7e-1a00-0000-d3a7-a5afd1090000 pid=2513 clone guuid=7632117e-1a00-0000-d3a7-a5afd2090000 pid=2514 /tmp/WTF net send-data zombie guuid=a5bb767d-1a00-0000-d3a7-a5afcd090000 pid=2509->guuid=7632117e-1a00-0000-d3a7-a5afd2090000 pid=2514 clone guuid=7632117e-1a00-0000-d3a7-a5afd2090000 pid=2514->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7632117e-1a00-0000-d3a7-a5afd2090000 pid=2514->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=13df4ec5-2000-0000-d3a7-a5afeb140000 pid=5355 /tmp/WTF net send-data guuid=7632117e-1a00-0000-d3a7-a5afd2090000 pid=2514->guuid=13df4ec5-2000-0000-d3a7-a5afeb140000 pid=5355 clone guuid=e3ff227e-1a00-0000-d3a7-a5afd3090000 pid=2515->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=11f68a87-1a00-0000-d3a7-a5afe8090000 pid=2536->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1b3eb394-1a00-0000-d3a7-a5af0b0a0000 pid=2571 /tmp/WTF guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567->guuid=1b3eb394-1a00-0000-d3a7-a5af0b0a0000 pid=2571 clone guuid=d827b994-1a00-0000-d3a7-a5af0c0a0000 pid=2572 /tmp/WTF guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567->guuid=d827b994-1a00-0000-d3a7-a5af0c0a0000 pid=2572 clone guuid=235abc94-1a00-0000-d3a7-a5af0d0a0000 pid=2573 /tmp/WTF net send-data zombie guuid=3609f393-1a00-0000-d3a7-a5af070a0000 pid=2567->guuid=235abc94-1a00-0000-d3a7-a5af0d0a0000 pid=2573 clone guuid=235abc94-1a00-0000-d3a7-a5af0d0a0000 pid=2573->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=235abc94-1a00-0000-d3a7-a5af0d0a0000 pid=2573->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=ccd888c4-2000-0000-d3a7-a5afe2140000 pid=5346 /tmp/WTF net send-data guuid=235abc94-1a00-0000-d3a7-a5af0d0a0000 pid=2573->guuid=ccd888c4-2000-0000-d3a7-a5afe2140000 pid=5346 clone guuid=1fcfcb94-1a00-0000-d3a7-a5af0e0a0000 pid=2574->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=66d55d9e-1a00-0000-d3a7-a5af160a0000 pid=2582->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3630acad-1a00-0000-d3a7-a5af450a0000 pid=2629 /tmp/WTF guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626->guuid=3630acad-1a00-0000-d3a7-a5af450a0000 pid=2629 clone guuid=256bb0ad-1a00-0000-d3a7-a5af460a0000 pid=2630 /tmp/WTF guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626->guuid=256bb0ad-1a00-0000-d3a7-a5af460a0000 pid=2630 clone guuid=1346b5ad-1a00-0000-d3a7-a5af480a0000 pid=2632 /tmp/WTF net send-data zombie guuid=0f8d03ad-1a00-0000-d3a7-a5af420a0000 pid=2626->guuid=1346b5ad-1a00-0000-d3a7-a5af480a0000 pid=2632 clone guuid=1346b5ad-1a00-0000-d3a7-a5af480a0000 pid=2632->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1346b5ad-1a00-0000-d3a7-a5af480a0000 pid=2632->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=de9719c9-2000-0000-d3a7-a5aff5140000 pid=5365 /tmp/WTF net send-data guuid=1346b5ad-1a00-0000-d3a7-a5af480a0000 pid=2632->guuid=de9719c9-2000-0000-d3a7-a5aff5140000 pid=5365 clone guuid=02dcc6ad-1a00-0000-d3a7-a5af490a0000 pid=2633->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=9e11d9b4-1a00-0000-d3a7-a5af5f0a0000 pid=2655->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1b5bccbe-1a00-0000-d3a7-a5af840a0000 pid=2692 /tmp/WTF guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688->guuid=1b5bccbe-1a00-0000-d3a7-a5af840a0000 pid=2692 clone guuid=26a3cfbe-1a00-0000-d3a7-a5af850a0000 pid=2693 /tmp/WTF guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688->guuid=26a3cfbe-1a00-0000-d3a7-a5af850a0000 pid=2693 clone guuid=7ddfd2be-1a00-0000-d3a7-a5af860a0000 pid=2694 /tmp/WTF net send-data zombie guuid=2f0613be-1a00-0000-d3a7-a5af800a0000 pid=2688->guuid=7ddfd2be-1a00-0000-d3a7-a5af860a0000 pid=2694 clone guuid=7ddfd2be-1a00-0000-d3a7-a5af860a0000 pid=2694->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7ddfd2be-1a00-0000-d3a7-a5af860a0000 pid=2694->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=f8fd3ec1-2000-0000-d3a7-a5afdf140000 pid=5343 /tmp/WTF net send-data guuid=7ddfd2be-1a00-0000-d3a7-a5af860a0000 pid=2694->guuid=f8fd3ec1-2000-0000-d3a7-a5afdf140000 pid=5343 clone guuid=cc81dfbe-1a00-0000-d3a7-a5af870a0000 pid=2695->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=f5bef3c9-1a00-0000-d3a7-a5afa50a0000 pid=2725->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9fa712d6-1a00-0000-d3a7-a5afcb0a0000 pid=2763 /tmp/WTF guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760->guuid=9fa712d6-1a00-0000-d3a7-a5afcb0a0000 pid=2763 clone guuid=518417d6-1a00-0000-d3a7-a5afcd0a0000 pid=2765 /tmp/WTF guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760->guuid=518417d6-1a00-0000-d3a7-a5afcd0a0000 pid=2765 clone guuid=22fe1ad6-1a00-0000-d3a7-a5afce0a0000 pid=2766 /tmp/WTF net send-data zombie guuid=149b68d5-1a00-0000-d3a7-a5afc80a0000 pid=2760->guuid=22fe1ad6-1a00-0000-d3a7-a5afce0a0000 pid=2766 clone guuid=22fe1ad6-1a00-0000-d3a7-a5afce0a0000 pid=2766->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=22fe1ad6-1a00-0000-d3a7-a5afce0a0000 pid=2766->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=26c4b1c4-2000-0000-d3a7-a5afe7140000 pid=5351 /tmp/WTF net send-data guuid=22fe1ad6-1a00-0000-d3a7-a5afce0a0000 pid=2766->guuid=26c4b1c4-2000-0000-d3a7-a5afe7140000 pid=5351 clone guuid=3b0628d6-1a00-0000-d3a7-a5afcf0a0000 pid=2767->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=d51b21e0-1a00-0000-d3a7-a5afea0a0000 pid=2794->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=12ef17ec-1a00-0000-d3a7-a5af090b0000 pid=2825 /tmp/WTF guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821->guuid=12ef17ec-1a00-0000-d3a7-a5af090b0000 pid=2825 clone guuid=fc9a1dec-1a00-0000-d3a7-a5af0b0b0000 pid=2827 /tmp/WTF guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821->guuid=fc9a1dec-1a00-0000-d3a7-a5af0b0b0000 pid=2827 clone guuid=e30625ec-1a00-0000-d3a7-a5af0c0b0000 pid=2828 /tmp/WTF net send-data zombie guuid=51a648eb-1a00-0000-d3a7-a5af050b0000 pid=2821->guuid=e30625ec-1a00-0000-d3a7-a5af0c0b0000 pid=2828 clone guuid=e30625ec-1a00-0000-d3a7-a5af0c0b0000 pid=2828->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e30625ec-1a00-0000-d3a7-a5af0c0b0000 pid=2828->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=bf2cbcc4-2000-0000-d3a7-a5afe8140000 pid=5352 /tmp/WTF net send-data guuid=e30625ec-1a00-0000-d3a7-a5af0c0b0000 pid=2828->guuid=bf2cbcc4-2000-0000-d3a7-a5afe8140000 pid=5352 clone guuid=f35838ec-1a00-0000-d3a7-a5af0d0b0000 pid=2829->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=fe6dcdf6-1a00-0000-d3a7-a5af170b0000 pid=2839->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98fc4104-1b00-0000-d3a7-a5af300b0000 pid=2864 /tmp/WTF guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863->guuid=98fc4104-1b00-0000-d3a7-a5af300b0000 pid=2864 clone guuid=f4274604-1b00-0000-d3a7-a5af310b0000 pid=2865 /tmp/WTF guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863->guuid=f4274604-1b00-0000-d3a7-a5af310b0000 pid=2865 clone guuid=f0455004-1b00-0000-d3a7-a5af320b0000 pid=2866 /tmp/WTF net send-data zombie guuid=48cc9803-1b00-0000-d3a7-a5af2f0b0000 pid=2863->guuid=f0455004-1b00-0000-d3a7-a5af320b0000 pid=2866 clone guuid=f0455004-1b00-0000-d3a7-a5af320b0000 pid=2866->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f0455004-1b00-0000-d3a7-a5af320b0000 pid=2866->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=932c14c5-2000-0000-d3a7-a5afea140000 pid=5354 /tmp/WTF net send-data guuid=f0455004-1b00-0000-d3a7-a5af320b0000 pid=2866->guuid=932c14c5-2000-0000-d3a7-a5afea140000 pid=5354 clone guuid=52f45e04-1b00-0000-d3a7-a5af330b0000 pid=2867->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=8405e109-1b00-0000-d3a7-a5af420b0000 pid=2882->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=938f5e11-1b00-0000-d3a7-a5af4e0b0000 pid=2894 /tmp/WTF guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890->guuid=938f5e11-1b00-0000-d3a7-a5af4e0b0000 pid=2894 clone guuid=52f76411-1b00-0000-d3a7-a5af4f0b0000 pid=2895 /tmp/WTF guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890->guuid=52f76411-1b00-0000-d3a7-a5af4f0b0000 pid=2895 clone guuid=77d66e11-1b00-0000-d3a7-a5af500b0000 pid=2896 /tmp/WTF net send-data zombie guuid=fe3da610-1b00-0000-d3a7-a5af4a0b0000 pid=2890->guuid=77d66e11-1b00-0000-d3a7-a5af500b0000 pid=2896 clone guuid=77d66e11-1b00-0000-d3a7-a5af500b0000 pid=2896->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=77d66e11-1b00-0000-d3a7-a5af500b0000 pid=2896->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=801098c4-2000-0000-d3a7-a5afe4140000 pid=5348 /tmp/WTF net send-data guuid=77d66e11-1b00-0000-d3a7-a5af500b0000 pid=2896->guuid=801098c4-2000-0000-d3a7-a5afe4140000 pid=5348 clone guuid=e5737c11-1b00-0000-d3a7-a5af510b0000 pid=2897->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 150B guuid=84067d1d-1b00-0000-d3a7-a5af660b0000 pid=2918->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 99B guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=48a0ef2b-1b00-0000-d3a7-a5af860b0000 pid=2950 /tmp/WTF guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948->guuid=48a0ef2b-1b00-0000-d3a7-a5af860b0000 pid=2950 clone guuid=b125f52b-1b00-0000-d3a7-a5af870b0000 pid=2951 /tmp/WTF guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948->guuid=b125f52b-1b00-0000-d3a7-a5af870b0000 pid=2951 clone guuid=afb0fc2b-1b00-0000-d3a7-a5af880b0000 pid=2952 /tmp/WTF net send-data zombie guuid=3b14502b-1b00-0000-d3a7-a5af840b0000 pid=2948->guuid=afb0fc2b-1b00-0000-d3a7-a5af880b0000 pid=2952 clone guuid=afb0fc2b-1b00-0000-d3a7-a5af880b0000 pid=2952->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=afb0fc2b-1b00-0000-d3a7-a5af880b0000 pid=2952->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=81b6cac5-2000-0000-d3a7-a5afed140000 pid=5357 /tmp/WTF net send-data guuid=afb0fc2b-1b00-0000-d3a7-a5af880b0000 pid=2952->guuid=81b6cac5-2000-0000-d3a7-a5afed140000 pid=5357 clone guuid=1be41e2c-1b00-0000-d3a7-a5af890b0000 pid=2953->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 149B guuid=2c9fa039-1b00-0000-d3a7-a5afac0b0000 pid=2988->33c43df8-4f2f-5748-96ff-21010ff25a74 send: 98B guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=59aeef4b-1b00-0000-d3a7-a5afda0b0000 pid=3034 /tmp/WTF guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031->guuid=59aeef4b-1b00-0000-d3a7-a5afda0b0000 pid=3034 clone guuid=9a52f34b-1b00-0000-d3a7-a5afdb0b0000 pid=3035 /tmp/WTF guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031->guuid=9a52f34b-1b00-0000-d3a7-a5afdb0b0000 pid=3035 clone guuid=a1b9f64b-1b00-0000-d3a7-a5afdc0b0000 pid=3036 /tmp/WTF net send-data zombie guuid=bcd0434b-1b00-0000-d3a7-a5afd70b0000 pid=3031->guuid=a1b9f64b-1b00-0000-d3a7-a5afdc0b0000 pid=3036 clone guuid=a1b9f64b-1b00-0000-d3a7-a5afdc0b0000 pid=3036->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a1b9f64b-1b00-0000-d3a7-a5afdc0b0000 pid=3036->b6227d2c-1ffc-578a-a536-5d08c4440c1f send: 7B guuid=e0728bc4-2000-0000-d3a7-a5afe3140000 pid=5347 /tmp/WTF net send-data guuid=a1b9f64b-1b00-0000-d3a7-a5afdc0b0000 pid=3036->guuid=e0728bc4-2000-0000-d3a7-a5afe3140000 pid=5347 clone eca0c948-314f-5a49-a2fe-b9c22a5fa3ed 141.94.131.184:22 guuid=f8fd3ec1-2000-0000-d3a7-a5afdf140000 pid=5343->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=067d53c1-2000-0000-d3a7-a5afe0140000 pid=5344 /tmp/WTF guuid=f8fd3ec1-2000-0000-d3a7-a5afdf140000 pid=5343->guuid=067d53c1-2000-0000-d3a7-a5afe0140000 pid=5344 clone guuid=109d7cc4-2000-0000-d3a7-a5afe1140000 pid=5345->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=9aefeec5-2000-0000-d3a7-a5afef140000 pid=5359 /tmp/WTF guuid=109d7cc4-2000-0000-d3a7-a5afe1140000 pid=5345->guuid=9aefeec5-2000-0000-d3a7-a5afef140000 pid=5359 clone guuid=ccd888c4-2000-0000-d3a7-a5afe2140000 pid=5346->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=c24341c6-2000-0000-d3a7-a5aff0140000 pid=5360 /tmp/WTF guuid=ccd888c4-2000-0000-d3a7-a5afe2140000 pid=5346->guuid=c24341c6-2000-0000-d3a7-a5aff0140000 pid=5360 clone guuid=e0728bc4-2000-0000-d3a7-a5afe3140000 pid=5347->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=7df2c9c9-2000-0000-d3a7-a5aff8140000 pid=5368 /tmp/WTF guuid=e0728bc4-2000-0000-d3a7-a5afe3140000 pid=5347->guuid=7df2c9c9-2000-0000-d3a7-a5aff8140000 pid=5368 clone guuid=801098c4-2000-0000-d3a7-a5afe4140000 pid=5348->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=23a58fca-2000-0000-d3a7-a5aff9140000 pid=5369 /tmp/WTF guuid=801098c4-2000-0000-d3a7-a5afe4140000 pid=5348->guuid=23a58fca-2000-0000-d3a7-a5aff9140000 pid=5369 clone guuid=1696a3c4-2000-0000-d3a7-a5afe5140000 pid=5349->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5934900B guuid=eec1c0ca-2000-0000-d3a7-a5affa140000 pid=5370 /tmp/WTF guuid=1696a3c4-2000-0000-d3a7-a5afe5140000 pid=5349->guuid=eec1c0ca-2000-0000-d3a7-a5affa140000 pid=5370 clone guuid=76c2a4c4-2000-0000-d3a7-a5afe6140000 pid=5350->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=5c4bd8cb-2000-0000-d3a7-a5affb140000 pid=5371 /tmp/WTF guuid=76c2a4c4-2000-0000-d3a7-a5afe6140000 pid=5350->guuid=5c4bd8cb-2000-0000-d3a7-a5affb140000 pid=5371 clone guuid=26c4b1c4-2000-0000-d3a7-a5afe7140000 pid=5351->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=93306bc5-2000-0000-d3a7-a5afec140000 pid=5356 /tmp/WTF guuid=26c4b1c4-2000-0000-d3a7-a5afe7140000 pid=5351->guuid=93306bc5-2000-0000-d3a7-a5afec140000 pid=5356 clone guuid=bf2cbcc4-2000-0000-d3a7-a5afe8140000 pid=5352->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=5a94ccc4-2000-0000-d3a7-a5afe9140000 pid=5353 /tmp/WTF guuid=bf2cbcc4-2000-0000-d3a7-a5afe8140000 pid=5352->guuid=5a94ccc4-2000-0000-d3a7-a5afe9140000 pid=5353 clone guuid=932c14c5-2000-0000-d3a7-a5afea140000 pid=5354->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=2929f7c6-2000-0000-d3a7-a5aff1140000 pid=5361 /tmp/WTF guuid=932c14c5-2000-0000-d3a7-a5afea140000 pid=5354->guuid=2929f7c6-2000-0000-d3a7-a5aff1140000 pid=5361 clone guuid=13df4ec5-2000-0000-d3a7-a5afeb140000 pid=5355->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=8b5f2fc7-2000-0000-d3a7-a5aff2140000 pid=5362 /tmp/WTF guuid=13df4ec5-2000-0000-d3a7-a5afeb140000 pid=5355->guuid=8b5f2fc7-2000-0000-d3a7-a5aff2140000 pid=5362 clone guuid=81b6cac5-2000-0000-d3a7-a5afed140000 pid=5357->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=32f0e2c7-2000-0000-d3a7-a5aff3140000 pid=5363 /tmp/WTF guuid=81b6cac5-2000-0000-d3a7-a5afed140000 pid=5357->guuid=32f0e2c7-2000-0000-d3a7-a5aff3140000 pid=5363 clone guuid=076ddbc5-2000-0000-d3a7-a5afee140000 pid=5358->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5748020B guuid=ab4c21c8-2000-0000-d3a7-a5aff4140000 pid=5364 /tmp/WTF guuid=076ddbc5-2000-0000-d3a7-a5afee140000 pid=5358->guuid=ab4c21c8-2000-0000-d3a7-a5aff4140000 pid=5364 clone guuid=de9719c9-2000-0000-d3a7-a5aff5140000 pid=5365->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=b21b50c9-2000-0000-d3a7-a5aff7140000 pid=5367 /tmp/WTF guuid=de9719c9-2000-0000-d3a7-a5aff5140000 pid=5365->guuid=b21b50c9-2000-0000-d3a7-a5aff7140000 pid=5367 clone guuid=d8d737c9-2000-0000-d3a7-a5aff6140000 pid=5366->eca0c948-314f-5a49-a2fe-b9c22a5fa3ed send: 5981620B guuid=77dca6cc-2000-0000-d3a7-a5affc140000 pid=5372 /tmp/WTF guuid=d8d737c9-2000-0000-d3a7-a5aff6140000 pid=5366->guuid=77dca6cc-2000-0000-d3a7-a5affc140000 pid=5372 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-07 21:01:55 UTC
File Type:
Text (Shell)
AV detection:
24 of 37 (64.86%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 13a07121d74dafa9f2ba4bb2d64fe8a9be9dd1827b8eb4aaf154299958c62b2e

(this sample)

  
Delivery method
Distributed via web download

Comments