MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1bec14536fc435a53720be6dc8d5a75b39608b8a5876f772e83cf539bb5676f3. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 1bec14536fc435a53720be6dc8d5a75b39608b8a5876f772e83cf539bb5676f3
SHA3-384 hash: 10a5b8f5837f66e2a3802721ed96be3ce475c319001567316b65e27be4127056097c8fbbb1148f117f02865a93189674
SHA1 hash: 09fd8151642c280604ed442934f37a11b4956362
MD5 hash: d79768b83e2083d0803f5888a08af332
humanhash: minnesota-charlie-whiskey-kentucky
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'970 bytes
First seen:2025-08-11 23:58:50 UTC
Last seen:2025-08-12 00:04:07 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v/7s7N7h/F6G/gNzP/1KW/zoU/7z7o7U/fu3b/89R/Hcg/YpV/NSO/Z+C/+fT/GW:v/7s7N7h/F6G/gNzP/1KW/zoU/7z7o7k
TLSH T1E551678581044D702CA36A57E6B76168729E9467E8F9EF8AD9E4BFE8034FF307540723
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://185.213.240.31/hiddenbin/boatnet.x861be29695bd3bbeebc245067dcfc8adaf5ce6adc117be15573184ff4439383f1c Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.mipsfaabb1bc1a5cbfec613667b378649a01e439bcf319a4ddea8be71d653ed25224 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.arc9883f22757e4145e218c7daca70086001bc35824f84677e4b2cd6f2fb67223f0 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.i468n/an/an/a
http://185.213.240.31/hiddenbin/boatnet.i686n/an/an/a
http://185.213.240.31/hiddenbin/boatnet.x86_64n/an/an/a
http://185.213.240.31/hiddenbin/boatnet.mpsle1ca558673c529e8663bd7c25c7c08091bd95e84f241608aff6dec09af817b96 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.armbda14fe3c813b2974961bd8cfb81e4b60fdfe1e85f9efb563f929ae04fe7b59b Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.arm50af847c9e7745774946782b54488597eaa729a6115ba68cddc11e1cde7a26cd6 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.arm61e040e437db14c5f372f39f99dade184d42ac06f67767f13be8745f8679ddffd Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.arm7b9fda4c11126f5bec2b8453fd2ddcb01bcef6f6fd70cc75bee6b392759851351 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.ppc643629378be2250e8036b86592d6651233579a3e852f228c57e1c8c7f878890f Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.spc56ea1a0727f9f1a90407d7170c4e27d5a529d97d3b3117b6b34dc81773f764d5 Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.m68k4a73874fe4c0ef28b52029721c2996d0c99941cc82445cb96dd263f801a676ad Miraielf mirai ua-wget
http://185.213.240.31/hiddenbin/boatnet.sh4feac50be0d4473b8ad486ae19f4eb64c11f00de45eb620e269a2d3a776766c75 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=ab53ca25-1900-0000-bb78-2e8615120000 pid=4629 /usr/bin/sudo guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638 /tmp/sample.bin guuid=ab53ca25-1900-0000-bb78-2e8615120000 pid=4629->guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638 execve guuid=502fb427-1900-0000-bb78-2e8621120000 pid=4641 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=502fb427-1900-0000-bb78-2e8621120000 pid=4641 execve guuid=05f65d2d-1900-0000-bb78-2e8638120000 pid=4664 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=05f65d2d-1900-0000-bb78-2e8638120000 pid=4664 execve guuid=4eaa0a37-1900-0000-bb78-2e865f120000 pid=4703 /usr/bin/cat guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=4eaa0a37-1900-0000-bb78-2e865f120000 pid=4703 execve guuid=b36c7037-1900-0000-bb78-2e8661120000 pid=4705 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=b36c7037-1900-0000-bb78-2e8661120000 pid=4705 execve guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706 execve guuid=82581a38-1900-0000-bb78-2e8667120000 pid=4711 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=82581a38-1900-0000-bb78-2e8667120000 pid=4711 execve guuid=e80f083c-1900-0000-bb78-2e8676120000 pid=4726 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=e80f083c-1900-0000-bb78-2e8676120000 pid=4726 execve guuid=45c7a941-1900-0000-bb78-2e8683120000 pid=4739 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=45c7a941-1900-0000-bb78-2e8683120000 pid=4739 clone guuid=0565ce41-1900-0000-bb78-2e8685120000 pid=4741 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=0565ce41-1900-0000-bb78-2e8685120000 pid=4741 execve guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743 execve guuid=b5a47942-1900-0000-bb78-2e868c120000 pid=4748 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=b5a47942-1900-0000-bb78-2e868c120000 pid=4748 execve guuid=e5979b48-1900-0000-bb78-2e86a0120000 pid=4768 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=e5979b48-1900-0000-bb78-2e86a0120000 pid=4768 execve guuid=29a99fba-1900-0000-bb78-2e8684130000 pid=4996 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=29a99fba-1900-0000-bb78-2e8684130000 pid=4996 clone guuid=f6d0dbba-1900-0000-bb78-2e8685130000 pid=4997 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=f6d0dbba-1900-0000-bb78-2e8685130000 pid=4997 execve guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000 execve guuid=41fe49bc-1900-0000-bb78-2e868d130000 pid=5005 /usr/bin/wget net send-data guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=41fe49bc-1900-0000-bb78-2e868d130000 pid=5005 execve guuid=65d9ddbf-1900-0000-bb78-2e8695130000 pid=5013 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=65d9ddbf-1900-0000-bb78-2e8695130000 pid=5013 execve guuid=5cda51c5-1900-0000-bb78-2e869e130000 pid=5022 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=5cda51c5-1900-0000-bb78-2e869e130000 pid=5022 clone guuid=52858ec5-1900-0000-bb78-2e869f130000 pid=5023 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=52858ec5-1900-0000-bb78-2e869f130000 pid=5023 execve guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024 execve guuid=7ee398c6-1900-0000-bb78-2e86a6130000 pid=5030 /usr/bin/wget net send-data guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=7ee398c6-1900-0000-bb78-2e86a6130000 pid=5030 execve guuid=1dbcbacb-1900-0000-bb78-2e86b1130000 pid=5041 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1dbcbacb-1900-0000-bb78-2e86b1130000 pid=5041 execve guuid=d23302d1-1900-0000-bb78-2e86c5130000 pid=5061 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=d23302d1-1900-0000-bb78-2e86c5130000 pid=5061 clone guuid=05f21cd1-1900-0000-bb78-2e86c6130000 pid=5062 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=05f21cd1-1900-0000-bb78-2e86c6130000 pid=5062 execve guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064 execve guuid=8a2ea1d1-1900-0000-bb78-2e86cf130000 pid=5071 /usr/bin/wget net send-data guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=8a2ea1d1-1900-0000-bb78-2e86cf130000 pid=5071 execve guuid=03be75d5-1900-0000-bb78-2e86e0130000 pid=5088 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=03be75d5-1900-0000-bb78-2e86e0130000 pid=5088 execve guuid=66095ed9-1900-0000-bb78-2e86f3130000 pid=5107 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=66095ed9-1900-0000-bb78-2e86f3130000 pid=5107 clone guuid=c0137ed9-1900-0000-bb78-2e86f4130000 pid=5108 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=c0137ed9-1900-0000-bb78-2e86f4130000 pid=5108 execve guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110 execve guuid=e7271ada-1900-0000-bb78-2e86fd130000 pid=5117 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=e7271ada-1900-0000-bb78-2e86fd130000 pid=5117 execve guuid=1d7530de-1900-0000-bb78-2e860a140000 pid=5130 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1d7530de-1900-0000-bb78-2e860a140000 pid=5130 execve guuid=4e4d97e3-1900-0000-bb78-2e8615140000 pid=5141 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=4e4d97e3-1900-0000-bb78-2e8615140000 pid=5141 clone guuid=1e7ebae3-1900-0000-bb78-2e8616140000 pid=5142 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1e7ebae3-1900-0000-bb78-2e8616140000 pid=5142 execve guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144 execve guuid=274d5ae4-1900-0000-bb78-2e861d140000 pid=5149 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=274d5ae4-1900-0000-bb78-2e861d140000 pid=5149 execve guuid=cf2230e8-1900-0000-bb78-2e8627140000 pid=5159 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=cf2230e8-1900-0000-bb78-2e8627140000 pid=5159 execve guuid=d367abed-1900-0000-bb78-2e8637140000 pid=5175 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=d367abed-1900-0000-bb78-2e8637140000 pid=5175 clone guuid=4cefd4ed-1900-0000-bb78-2e8639140000 pid=5177 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=4cefd4ed-1900-0000-bb78-2e8639140000 pid=5177 execve guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178 execve guuid=a2ccc3ee-1900-0000-bb78-2e863f140000 pid=5183 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=a2ccc3ee-1900-0000-bb78-2e863f140000 pid=5183 execve guuid=faca85f2-1900-0000-bb78-2e8647140000 pid=5191 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=faca85f2-1900-0000-bb78-2e8647140000 pid=5191 execve guuid=460c1bf8-1900-0000-bb78-2e8657140000 pid=5207 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=460c1bf8-1900-0000-bb78-2e8657140000 pid=5207 clone guuid=48213ff8-1900-0000-bb78-2e8659140000 pid=5209 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=48213ff8-1900-0000-bb78-2e8659140000 pid=5209 execve guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211 execve guuid=0f57daf8-1900-0000-bb78-2e8660140000 pid=5216 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=0f57daf8-1900-0000-bb78-2e8660140000 pid=5216 execve guuid=da63ecfc-1900-0000-bb78-2e866d140000 pid=5229 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=da63ecfc-1900-0000-bb78-2e866d140000 pid=5229 execve guuid=96730502-1a00-0000-bb78-2e866e140000 pid=5230 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=96730502-1a00-0000-bb78-2e866e140000 pid=5230 clone guuid=67b14502-1a00-0000-bb78-2e866f140000 pid=5231 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=67b14502-1a00-0000-bb78-2e866f140000 pid=5231 execve guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232 execve guuid=6e213c03-1a00-0000-bb78-2e8674140000 pid=5236 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=6e213c03-1a00-0000-bb78-2e8674140000 pid=5236 execve guuid=0daeab08-1a00-0000-bb78-2e8689140000 pid=5257 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=0daeab08-1a00-0000-bb78-2e8689140000 pid=5257 execve guuid=f573f70e-1a00-0000-bb78-2e86a6140000 pid=5286 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=f573f70e-1a00-0000-bb78-2e86a6140000 pid=5286 clone guuid=f188150f-1a00-0000-bb78-2e86a7140000 pid=5287 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=f188150f-1a00-0000-bb78-2e86a7140000 pid=5287 execve guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288 execve guuid=8c1ce40f-1a00-0000-bb78-2e86ac140000 pid=5292 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=8c1ce40f-1a00-0000-bb78-2e86ac140000 pid=5292 execve guuid=0797fe13-1a00-0000-bb78-2e86ad140000 pid=5293 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=0797fe13-1a00-0000-bb78-2e86ad140000 pid=5293 execve guuid=84cc9c1b-1a00-0000-bb78-2e86ae140000 pid=5294 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=84cc9c1b-1a00-0000-bb78-2e86ae140000 pid=5294 clone guuid=d685b91b-1a00-0000-bb78-2e86af140000 pid=5295 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=d685b91b-1a00-0000-bb78-2e86af140000 pid=5295 execve guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296 execve guuid=ba87411c-1a00-0000-bb78-2e86b4140000 pid=5300 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=ba87411c-1a00-0000-bb78-2e86b4140000 pid=5300 execve guuid=45dbff20-1a00-0000-bb78-2e86b5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=45dbff20-1a00-0000-bb78-2e86b5140000 pid=5301 execve guuid=51029327-1a00-0000-bb78-2e86b6140000 pid=5302 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=51029327-1a00-0000-bb78-2e86b6140000 pid=5302 clone guuid=3c4db127-1a00-0000-bb78-2e86b7140000 pid=5303 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=3c4db127-1a00-0000-bb78-2e86b7140000 pid=5303 execve guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304 execve guuid=1af95028-1a00-0000-bb78-2e86bc140000 pid=5308 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1af95028-1a00-0000-bb78-2e86bc140000 pid=5308 execve guuid=9272ef2e-1a00-0000-bb78-2e86c0140000 pid=5312 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=9272ef2e-1a00-0000-bb78-2e86c0140000 pid=5312 execve guuid=ff1c3f36-1a00-0000-bb78-2e86c9140000 pid=5321 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=ff1c3f36-1a00-0000-bb78-2e86c9140000 pid=5321 clone guuid=57656236-1a00-0000-bb78-2e86ca140000 pid=5322 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=57656236-1a00-0000-bb78-2e86ca140000 pid=5322 execve guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323 execve guuid=fbebfe36-1a00-0000-bb78-2e86cf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=fbebfe36-1a00-0000-bb78-2e86cf140000 pid=5327 execve guuid=e310613c-1a00-0000-bb78-2e86d0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=e310613c-1a00-0000-bb78-2e86d0140000 pid=5328 execve guuid=9167b043-1a00-0000-bb78-2e86d1140000 pid=5329 /usr/bin/bash guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=9167b043-1a00-0000-bb78-2e86d1140000 pid=5329 clone guuid=1c17de43-1a00-0000-bb78-2e86d2140000 pid=5330 /usr/bin/chmod guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1c17de43-1a00-0000-bb78-2e86d2140000 pid=5330 execve guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331 /tmp/WTF net guuid=edc26727-1900-0000-bb78-2e861e120000 pid=4638->guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331 execve 776be247-04a7-53c7-92eb-8e146d32bf0b 185.213.240.31:80 guuid=502fb427-1900-0000-bb78-2e8621120000 pid=4641->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=05f65d2d-1900-0000-bb78-2e8638120000 pid=4664->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d2010638-1900-0000-bb78-2e8664120000 pid=4708 /tmp/WTF guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706->guuid=d2010638-1900-0000-bb78-2e8664120000 pid=4708 clone guuid=b1b40a38-1900-0000-bb78-2e8665120000 pid=4709 /tmp/WTF guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706->guuid=b1b40a38-1900-0000-bb78-2e8665120000 pid=4709 clone guuid=499d1038-1900-0000-bb78-2e8666120000 pid=4710 /tmp/WTF net send-data zombie guuid=2cfcc837-1900-0000-bb78-2e8662120000 pid=4706->guuid=499d1038-1900-0000-bb78-2e8666120000 pid=4710 clone b231bcfe-25ce-5697-b396-1adc56fa265a 159.100.14.33:3778 guuid=499d1038-1900-0000-bb78-2e8666120000 pid=4710->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=82581a38-1900-0000-bb78-2e8667120000 pid=4711->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=e80f083c-1900-0000-bb78-2e8676120000 pid=4726->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62f26142-1900-0000-bb78-2e8689120000 pid=4745 /tmp/WTF guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743->guuid=62f26142-1900-0000-bb78-2e8689120000 pid=4745 clone guuid=70596842-1900-0000-bb78-2e868a120000 pid=4746 /tmp/WTF guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743->guuid=70596842-1900-0000-bb78-2e868a120000 pid=4746 clone guuid=67416b42-1900-0000-bb78-2e868b120000 pid=4747 /tmp/WTF net send-data zombie guuid=222b3442-1900-0000-bb78-2e8687120000 pid=4743->guuid=67416b42-1900-0000-bb78-2e868b120000 pid=4747 clone guuid=67416b42-1900-0000-bb78-2e868b120000 pid=4747->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=b5a47942-1900-0000-bb78-2e868c120000 pid=4748->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=e5979b48-1900-0000-bb78-2e86a0120000 pid=4768->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=701d1cbc-1900-0000-bb78-2e868a130000 pid=5002 /tmp/WTF guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000->guuid=701d1cbc-1900-0000-bb78-2e868a130000 pid=5002 clone guuid=4a2226bc-1900-0000-bb78-2e868b130000 pid=5003 /tmp/WTF guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000->guuid=4a2226bc-1900-0000-bb78-2e868b130000 pid=5003 clone guuid=77b72ebc-1900-0000-bb78-2e868c130000 pid=5004 /tmp/WTF net send-data zombie guuid=fa9fa4bb-1900-0000-bb78-2e8688130000 pid=5000->guuid=77b72ebc-1900-0000-bb78-2e868c130000 pid=5004 clone guuid=77b72ebc-1900-0000-bb78-2e868c130000 pid=5004->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=41fe49bc-1900-0000-bb78-2e868d130000 pid=5005->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=65d9ddbf-1900-0000-bb78-2e8695130000 pid=5013->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e53265c6-1900-0000-bb78-2e86a2130000 pid=5026 /tmp/WTF guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024->guuid=e53265c6-1900-0000-bb78-2e86a2130000 pid=5026 clone guuid=56856dc6-1900-0000-bb78-2e86a3130000 pid=5027 /tmp/WTF guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024->guuid=56856dc6-1900-0000-bb78-2e86a3130000 pid=5027 clone guuid=b36d76c6-1900-0000-bb78-2e86a4130000 pid=5028 /tmp/WTF net send-data zombie guuid=c75313c6-1900-0000-bb78-2e86a0130000 pid=5024->guuid=b36d76c6-1900-0000-bb78-2e86a4130000 pid=5028 clone guuid=b36d76c6-1900-0000-bb78-2e86a4130000 pid=5028->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=7ee398c6-1900-0000-bb78-2e86a6130000 pid=5030->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=1dbcbacb-1900-0000-bb78-2e86b1130000 pid=5041->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=af3791d1-1900-0000-bb78-2e86cc130000 pid=5068 /tmp/WTF guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064->guuid=af3791d1-1900-0000-bb78-2e86cc130000 pid=5068 clone guuid=2c7f94d1-1900-0000-bb78-2e86cd130000 pid=5069 /tmp/WTF guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064->guuid=2c7f94d1-1900-0000-bb78-2e86cd130000 pid=5069 clone guuid=f3c797d1-1900-0000-bb78-2e86ce130000 pid=5070 /tmp/WTF net send-data zombie guuid=a59c65d1-1900-0000-bb78-2e86c8130000 pid=5064->guuid=f3c797d1-1900-0000-bb78-2e86ce130000 pid=5070 clone guuid=f3c797d1-1900-0000-bb78-2e86ce130000 pid=5070->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=8a2ea1d1-1900-0000-bb78-2e86cf130000 pid=5071->776be247-04a7-53c7-92eb-8e146d32bf0b send: 153B guuid=03be75d5-1900-0000-bb78-2e86e0130000 pid=5088->776be247-04a7-53c7-92eb-8e146d32bf0b send: 102B guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5f58fed9-1900-0000-bb78-2e86fa130000 pid=5114 /tmp/WTF guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110->guuid=5f58fed9-1900-0000-bb78-2e86fa130000 pid=5114 clone guuid=b02c06da-1900-0000-bb78-2e86fb130000 pid=5115 /tmp/WTF guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110->guuid=b02c06da-1900-0000-bb78-2e86fb130000 pid=5115 clone guuid=70380eda-1900-0000-bb78-2e86fc130000 pid=5116 /tmp/WTF net send-data zombie guuid=a7ccc2d9-1900-0000-bb78-2e86f6130000 pid=5110->guuid=70380eda-1900-0000-bb78-2e86fc130000 pid=5116 clone guuid=70380eda-1900-0000-bb78-2e86fc130000 pid=5116->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=e7271ada-1900-0000-bb78-2e86fd130000 pid=5117->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=1d7530de-1900-0000-bb78-2e860a140000 pid=5130->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=37e040e4-1900-0000-bb78-2e861a140000 pid=5146 /tmp/WTF guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144->guuid=37e040e4-1900-0000-bb78-2e861a140000 pid=5146 clone guuid=a0e745e4-1900-0000-bb78-2e861b140000 pid=5147 /tmp/WTF guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144->guuid=a0e745e4-1900-0000-bb78-2e861b140000 pid=5147 clone guuid=753250e4-1900-0000-bb78-2e861c140000 pid=5148 /tmp/WTF net send-data zombie guuid=7b7e10e4-1900-0000-bb78-2e8618140000 pid=5144->guuid=753250e4-1900-0000-bb78-2e861c140000 pid=5148 clone guuid=753250e4-1900-0000-bb78-2e861c140000 pid=5148->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=274d5ae4-1900-0000-bb78-2e861d140000 pid=5149->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=cf2230e8-1900-0000-bb78-2e8627140000 pid=5159->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=419099ee-1900-0000-bb78-2e863c140000 pid=5180 /tmp/WTF guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178->guuid=419099ee-1900-0000-bb78-2e863c140000 pid=5180 clone guuid=d390a2ee-1900-0000-bb78-2e863d140000 pid=5181 /tmp/WTF guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178->guuid=d390a2ee-1900-0000-bb78-2e863d140000 pid=5181 clone guuid=e7b6a9ee-1900-0000-bb78-2e863e140000 pid=5182 /tmp/WTF net send-data zombie guuid=b94f1dee-1900-0000-bb78-2e863a140000 pid=5178->guuid=e7b6a9ee-1900-0000-bb78-2e863e140000 pid=5182 clone guuid=e7b6a9ee-1900-0000-bb78-2e863e140000 pid=5182->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=a2ccc3ee-1900-0000-bb78-2e863f140000 pid=5183->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=faca85f2-1900-0000-bb78-2e8647140000 pid=5191->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=54b7c2f8-1900-0000-bb78-2e865c140000 pid=5212 /tmp/WTF guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211->guuid=54b7c2f8-1900-0000-bb78-2e865c140000 pid=5212 clone guuid=3389ccf8-1900-0000-bb78-2e865d140000 pid=5213 /tmp/WTF guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211->guuid=3389ccf8-1900-0000-bb78-2e865d140000 pid=5213 clone guuid=7cb0cff8-1900-0000-bb78-2e865f140000 pid=5215 /tmp/WTF net send-data zombie guuid=3fdf92f8-1900-0000-bb78-2e865b140000 pid=5211->guuid=7cb0cff8-1900-0000-bb78-2e865f140000 pid=5215 clone guuid=7cb0cff8-1900-0000-bb78-2e865f140000 pid=5215->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=0f57daf8-1900-0000-bb78-2e8660140000 pid=5216->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=da63ecfc-1900-0000-bb78-2e866d140000 pid=5229->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fea22603-1a00-0000-bb78-2e8671140000 pid=5233 /tmp/WTF guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232->guuid=fea22603-1a00-0000-bb78-2e8671140000 pid=5233 clone guuid=273f2c03-1a00-0000-bb78-2e8672140000 pid=5234 /tmp/WTF guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232->guuid=273f2c03-1a00-0000-bb78-2e8672140000 pid=5234 clone guuid=85ca3003-1a00-0000-bb78-2e8673140000 pid=5235 /tmp/WTF net send-data zombie guuid=9b98e102-1a00-0000-bb78-2e8670140000 pid=5232->guuid=85ca3003-1a00-0000-bb78-2e8673140000 pid=5235 clone guuid=85ca3003-1a00-0000-bb78-2e8673140000 pid=5235->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=6e213c03-1a00-0000-bb78-2e8674140000 pid=5236->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=0daeab08-1a00-0000-bb78-2e8689140000 pid=5257->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6499ce0f-1a00-0000-bb78-2e86a9140000 pid=5289 /tmp/WTF guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288->guuid=6499ce0f-1a00-0000-bb78-2e86a9140000 pid=5289 clone guuid=2e8dd20f-1a00-0000-bb78-2e86aa140000 pid=5290 /tmp/WTF guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288->guuid=2e8dd20f-1a00-0000-bb78-2e86aa140000 pid=5290 clone guuid=914cd60f-1a00-0000-bb78-2e86ab140000 pid=5291 /tmp/WTF net send-data zombie guuid=d73d910f-1a00-0000-bb78-2e86a8140000 pid=5288->guuid=914cd60f-1a00-0000-bb78-2e86ab140000 pid=5291 clone guuid=914cd60f-1a00-0000-bb78-2e86ab140000 pid=5291->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=8c1ce40f-1a00-0000-bb78-2e86ac140000 pid=5292->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=0797fe13-1a00-0000-bb78-2e86ad140000 pid=5293->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1c29301c-1a00-0000-bb78-2e86b1140000 pid=5297 /tmp/WTF guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296->guuid=1c29301c-1a00-0000-bb78-2e86b1140000 pid=5297 clone guuid=aaac331c-1a00-0000-bb78-2e86b2140000 pid=5298 /tmp/WTF guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296->guuid=aaac331c-1a00-0000-bb78-2e86b2140000 pid=5298 clone guuid=3b2f381c-1a00-0000-bb78-2e86b3140000 pid=5299 /tmp/WTF net send-data zombie guuid=756e041c-1a00-0000-bb78-2e86b0140000 pid=5296->guuid=3b2f381c-1a00-0000-bb78-2e86b3140000 pid=5299 clone guuid=3b2f381c-1a00-0000-bb78-2e86b3140000 pid=5299->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=ba87411c-1a00-0000-bb78-2e86b4140000 pid=5300->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=45dbff20-1a00-0000-bb78-2e86b5140000 pid=5301->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=24e23b28-1a00-0000-bb78-2e86b9140000 pid=5305 /tmp/WTF guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304->guuid=24e23b28-1a00-0000-bb78-2e86b9140000 pid=5305 clone guuid=8d054128-1a00-0000-bb78-2e86ba140000 pid=5306 /tmp/WTF guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304->guuid=8d054128-1a00-0000-bb78-2e86ba140000 pid=5306 clone guuid=707d4428-1a00-0000-bb78-2e86bb140000 pid=5307 /tmp/WTF net send-data zombie guuid=8d4f0728-1a00-0000-bb78-2e86b8140000 pid=5304->guuid=707d4428-1a00-0000-bb78-2e86bb140000 pid=5307 clone guuid=707d4428-1a00-0000-bb78-2e86bb140000 pid=5307->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=1af95028-1a00-0000-bb78-2e86bc140000 pid=5308->776be247-04a7-53c7-92eb-8e146d32bf0b send: 151B guuid=9272ef2e-1a00-0000-bb78-2e86c0140000 pid=5312->776be247-04a7-53c7-92eb-8e146d32bf0b send: 100B guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=adfce936-1a00-0000-bb78-2e86cc140000 pid=5324 /tmp/WTF guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323->guuid=adfce936-1a00-0000-bb78-2e86cc140000 pid=5324 clone guuid=a2f4ee36-1a00-0000-bb78-2e86cd140000 pid=5325 /tmp/WTF guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323->guuid=a2f4ee36-1a00-0000-bb78-2e86cd140000 pid=5325 clone guuid=5c9bf436-1a00-0000-bb78-2e86ce140000 pid=5326 /tmp/WTF net send-data zombie guuid=5111b636-1a00-0000-bb78-2e86cb140000 pid=5323->guuid=5c9bf436-1a00-0000-bb78-2e86ce140000 pid=5326 clone guuid=5c9bf436-1a00-0000-bb78-2e86ce140000 pid=5326->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B guuid=fbebfe36-1a00-0000-bb78-2e86cf140000 pid=5327->776be247-04a7-53c7-92eb-8e146d32bf0b send: 150B guuid=e310613c-1a00-0000-bb78-2e86d0140000 pid=5328->776be247-04a7-53c7-92eb-8e146d32bf0b send: 99B guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=410bc944-1a00-0000-bb78-2e86d4140000 pid=5332 /tmp/WTF guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331->guuid=410bc944-1a00-0000-bb78-2e86d4140000 pid=5332 clone guuid=520dd044-1a00-0000-bb78-2e86d5140000 pid=5333 /tmp/WTF guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331->guuid=520dd044-1a00-0000-bb78-2e86d5140000 pid=5333 clone guuid=f52ddc44-1a00-0000-bb78-2e86d6140000 pid=5334 /tmp/WTF net send-data zombie guuid=1cdb6c44-1a00-0000-bb78-2e86d3140000 pid=5331->guuid=f52ddc44-1a00-0000-bb78-2e86d6140000 pid=5334 clone guuid=f52ddc44-1a00-0000-bb78-2e86d6140000 pid=5334->b231bcfe-25ce-5697-b396-1adc56fa265a send: 2B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-11 13:47:58 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 1bec14536fc435a53720be6dc8d5a75b39608b8a5876f772e83cf539bb5676f3

(this sample)

  
Delivery method
Distributed via web download

Comments