MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 33f83dc5555afc3222686934a3d4fe0c227e592fb7a40c2b2155540dd2630746. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 33f83dc5555afc3222686934a3d4fe0c227e592fb7a40c2b2155540dd2630746
SHA3-384 hash: dd7eb964f814488aad9a7b8b5f83a7b811952093759aa1a3e1ca153e2046d28fe830af10ed25117cc84942433da1cee4
SHA1 hash: cf8cd22ccad5bad50a4d827b403e07349b190ff9
MD5 hash: 4f464a9b411790d7635520127d159d08
humanhash: west-montana-california-texas
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'064 bytes
First seen:2026-02-15 22:16:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipMvMQzLpMVM0zLpMSMwzLpMaMwzLpMMMszLpMuMEzLpMoOMzEzLpM9MEzLpM6MX:iO3g3d3N3b3R3VE3k3t3M3j3N3x3C3Iz
TLSH T11651B1A5E2814232AFB9A59379B681447182DAE25CC97D13F2FCBCB885CDE0475817C3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.148.189/HideChaotic/sora.arcea22176d9a339d8f053e388c62801457369e3042608f1cd78184cf56abc045d5 Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.x8658ef677ddfe8c476f236176231880ec76c00f019a5bf3c85e4c7a60eb457cadb Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.x86_64f71b9ccce705ae0f84546f6e8d9b66a5e98f96d4996f2c176fcea3773d256a7a Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.i6864a4793f97f1b492d648733fbab1e560b0cd4d4e664701733a7e97d0b6042556d Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.mipsdea7b3f9c4e806083414bb90b3d6a326ef46313b821963ac633479b784560e09 Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.mips64n/an/aelf ua-wget
http://176.65.148.189/HideChaotic/sora.mpsle74b52e34a8fff53883595b683a42b880e1cc425e6a6d259c0137cfb0bd472e7 Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.armc78f27b4208ad3049c1d0ecb502b3ea3ea6e215cafff856abc2214c3e867a4cd Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.arm5n/an/aelf ua-wget
http://176.65.148.189/HideChaotic/sora.arm6n/an/aelf ua-wget
http://176.65.148.189/HideChaotic/sora.arm7n/an/aelf ua-wget
http://176.65.148.189/HideChaotic/sora.ppc520e1e931a87fa4df3a7fa7698ac8d98725ccf17c9cc33fe1e1cfc3702faa39e Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.sparcn/an/aelf ua-wget
http://176.65.148.189/HideChaotic/sora.m68k9eb2ed94c54993784b23b9f654ecde936b7d5a844703e6361507fa4468f2cd2c Miraimirai opendir
http://176.65.148.189/HideChaotic/sora.sh4eee7c1c7bcc00f8ffbbc25eccebaaa6bf18de6afb30265327f9ce1d18e717e25 Miraimirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=e219b4ce-1f00-0000-2660-b05a790c0000 pid=3193 /usr/bin/sudo guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201 /tmp/sample.bin guuid=e219b4ce-1f00-0000-2660-b05a790c0000 pid=3193->guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201 execve guuid=576fe3d0-1f00-0000-2660-b05a820c0000 pid=3202 /usr/bin/cp guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=576fe3d0-1f00-0000-2660-b05a820c0000 pid=3202 execve guuid=014e7bd6-1f00-0000-2660-b05a8a0c0000 pid=3210 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=014e7bd6-1f00-0000-2660-b05a8a0c0000 pid=3210 execve guuid=8d1fbdde-1f00-0000-2660-b05a950c0000 pid=3221 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=8d1fbdde-1f00-0000-2660-b05a950c0000 pid=3221 execve guuid=797fe5ee-1f00-0000-2660-b05a960c0000 pid=3222 /usr/bin/cat guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=797fe5ee-1f00-0000-2660-b05a960c0000 pid=3222 execve guuid=422a66ef-1f00-0000-2660-b05a970c0000 pid=3223 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=422a66ef-1f00-0000-2660-b05a970c0000 pid=3223 execve guuid=92f5ccef-1f00-0000-2660-b05a980c0000 pid=3224 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=92f5ccef-1f00-0000-2660-b05a980c0000 pid=3224 clone guuid=414d09f1-1f00-0000-2660-b05a9a0c0000 pid=3226 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=414d09f1-1f00-0000-2660-b05a9a0c0000 pid=3226 execve guuid=68b7d33f-2000-0000-2660-b05a0e0d0000 pid=3342 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=68b7d33f-2000-0000-2660-b05a0e0d0000 pid=3342 execve guuid=3895cb47-2000-0000-2660-b05a1c0d0000 pid=3356 /usr/bin/cat guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=3895cb47-2000-0000-2660-b05a1c0d0000 pid=3356 execve guuid=69274c48-2000-0000-2660-b05a1f0d0000 pid=3359 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=69274c48-2000-0000-2660-b05a1f0d0000 pid=3359 execve guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361 /tmp/Chaotic delete-file net guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361 execve guuid=e799f7d0-2000-0000-2660-b05ac40d0000 pid=3524 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e799f7d0-2000-0000-2660-b05ac40d0000 pid=3524 execve guuid=109a51d6-2000-0000-2660-b05acc0d0000 pid=3532 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=109a51d6-2000-0000-2660-b05acc0d0000 pid=3532 execve guuid=ea2f0adc-2000-0000-2660-b05ad70d0000 pid=3543 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=ea2f0adc-2000-0000-2660-b05ad70d0000 pid=3543 clone guuid=d97428dc-2000-0000-2660-b05ad80d0000 pid=3544 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=d97428dc-2000-0000-2660-b05ad80d0000 pid=3544 execve guuid=5b97b0dc-2000-0000-2660-b05ada0d0000 pid=3546 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=5b97b0dc-2000-0000-2660-b05ada0d0000 pid=3546 execve guuid=6de347dd-2000-0000-2660-b05adb0d0000 pid=3547 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=6de347dd-2000-0000-2660-b05adb0d0000 pid=3547 execve guuid=e48b47e1-2000-0000-2660-b05ae40d0000 pid=3556 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e48b47e1-2000-0000-2660-b05ae40d0000 pid=3556 execve guuid=4c7b1925-2100-0000-2660-b05a880e0000 pid=3720 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=4c7b1925-2100-0000-2660-b05a880e0000 pid=3720 clone guuid=b2323c25-2100-0000-2660-b05a890e0000 pid=3721 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b2323c25-2100-0000-2660-b05a890e0000 pid=3721 execve guuid=b5aec525-2100-0000-2660-b05a8b0e0000 pid=3723 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b5aec525-2100-0000-2660-b05a8b0e0000 pid=3723 execve guuid=3fb48026-2100-0000-2660-b05a900e0000 pid=3728 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=3fb48026-2100-0000-2660-b05a900e0000 pid=3728 execve guuid=47595d2d-2100-0000-2660-b05aa90e0000 pid=3753 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=47595d2d-2100-0000-2660-b05aa90e0000 pid=3753 execve guuid=a0d6ea33-2100-0000-2660-b05ac00e0000 pid=3776 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=a0d6ea33-2100-0000-2660-b05ac00e0000 pid=3776 clone guuid=0c070f34-2100-0000-2660-b05ac10e0000 pid=3777 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=0c070f34-2100-0000-2660-b05ac10e0000 pid=3777 execve guuid=1e736434-2100-0000-2660-b05ac30e0000 pid=3779 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=1e736434-2100-0000-2660-b05ac30e0000 pid=3779 execve guuid=12aeed34-2100-0000-2660-b05ac50e0000 pid=3781 /usr/bin/wget net send-data guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=12aeed34-2100-0000-2660-b05ac50e0000 pid=3781 execve guuid=18704d38-2100-0000-2660-b05acf0e0000 pid=3791 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=18704d38-2100-0000-2660-b05acf0e0000 pid=3791 execve guuid=fc0a193f-2100-0000-2660-b05ae70e0000 pid=3815 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=fc0a193f-2100-0000-2660-b05ae70e0000 pid=3815 clone guuid=c213383f-2100-0000-2660-b05ae90e0000 pid=3817 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=c213383f-2100-0000-2660-b05ae90e0000 pid=3817 execve guuid=ba09c13f-2100-0000-2660-b05aec0e0000 pid=3820 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=ba09c13f-2100-0000-2660-b05aec0e0000 pid=3820 execve guuid=54d14f40-2100-0000-2660-b05af00e0000 pid=3824 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=54d14f40-2100-0000-2660-b05af00e0000 pid=3824 execve guuid=6fd4cf47-2100-0000-2660-b05a130f0000 pid=3859 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=6fd4cf47-2100-0000-2660-b05a130f0000 pid=3859 execve guuid=a4927853-2100-0000-2660-b05a2e0f0000 pid=3886 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=a4927853-2100-0000-2660-b05a2e0f0000 pid=3886 clone guuid=e0ae9153-2100-0000-2660-b05a2f0f0000 pid=3887 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e0ae9153-2100-0000-2660-b05a2f0f0000 pid=3887 execve guuid=481bf453-2100-0000-2660-b05a310f0000 pid=3889 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=481bf453-2100-0000-2660-b05a310f0000 pid=3889 execve guuid=d6668f54-2100-0000-2660-b05a340f0000 pid=3892 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=d6668f54-2100-0000-2660-b05a340f0000 pid=3892 execve guuid=ee5a6e59-2100-0000-2660-b05a420f0000 pid=3906 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=ee5a6e59-2100-0000-2660-b05a420f0000 pid=3906 execve guuid=d603c15f-2100-0000-2660-b05a590f0000 pid=3929 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=d603c15f-2100-0000-2660-b05a590f0000 pid=3929 clone guuid=06e7f35f-2100-0000-2660-b05a5b0f0000 pid=3931 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=06e7f35f-2100-0000-2660-b05a5b0f0000 pid=3931 execve guuid=53776960-2100-0000-2660-b05a5d0f0000 pid=3933 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=53776960-2100-0000-2660-b05a5d0f0000 pid=3933 execve guuid=bfc02361-2100-0000-2660-b05a610f0000 pid=3937 /usr/bin/wget net send-data guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=bfc02361-2100-0000-2660-b05a610f0000 pid=3937 execve guuid=3338ee64-2100-0000-2660-b05a710f0000 pid=3953 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=3338ee64-2100-0000-2660-b05a710f0000 pid=3953 execve guuid=f839a4a5-2100-0000-2660-b05a53100000 pid=4179 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=f839a4a5-2100-0000-2660-b05a53100000 pid=4179 clone guuid=b021bea5-2100-0000-2660-b05a56100000 pid=4182 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b021bea5-2100-0000-2660-b05a56100000 pid=4182 execve guuid=57fd05a6-2100-0000-2660-b05a57100000 pid=4183 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=57fd05a6-2100-0000-2660-b05a57100000 pid=4183 execve guuid=b35393a6-2100-0000-2660-b05a5a100000 pid=4186 /usr/bin/wget net send-data guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b35393a6-2100-0000-2660-b05a5a100000 pid=4186 execve guuid=99fb98a9-2100-0000-2660-b05a68100000 pid=4200 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=99fb98a9-2100-0000-2660-b05a68100000 pid=4200 execve guuid=2ec7bbaf-2100-0000-2660-b05a75100000 pid=4213 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=2ec7bbaf-2100-0000-2660-b05a75100000 pid=4213 clone guuid=b654deaf-2100-0000-2660-b05a76100000 pid=4214 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=b654deaf-2100-0000-2660-b05a76100000 pid=4214 execve guuid=655029b0-2100-0000-2660-b05a7a100000 pid=4218 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=655029b0-2100-0000-2660-b05a7a100000 pid=4218 execve guuid=bd49bfb0-2100-0000-2660-b05a7b100000 pid=4219 /usr/bin/wget net send-data guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=bd49bfb0-2100-0000-2660-b05a7b100000 pid=4219 execve guuid=aff3f8b3-2100-0000-2660-b05a8b100000 pid=4235 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=aff3f8b3-2100-0000-2660-b05a8b100000 pid=4235 execve guuid=ffbf18b9-2100-0000-2660-b05a9b100000 pid=4251 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=ffbf18b9-2100-0000-2660-b05a9b100000 pid=4251 clone guuid=61b431b9-2100-0000-2660-b05a9d100000 pid=4253 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=61b431b9-2100-0000-2660-b05a9d100000 pid=4253 execve guuid=f28274b9-2100-0000-2660-b05a9f100000 pid=4255 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=f28274b9-2100-0000-2660-b05a9f100000 pid=4255 execve guuid=a498f0b9-2100-0000-2660-b05aa1100000 pid=4257 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=a498f0b9-2100-0000-2660-b05aa1100000 pid=4257 execve guuid=4087eefa-2100-0000-2660-b05a9b110000 pid=4507 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=4087eefa-2100-0000-2660-b05a9b110000 pid=4507 execve guuid=928dd501-2200-0000-2660-b05ab7110000 pid=4535 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=928dd501-2200-0000-2660-b05ab7110000 pid=4535 clone guuid=854efe01-2200-0000-2660-b05ab9110000 pid=4537 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=854efe01-2200-0000-2660-b05ab9110000 pid=4537 execve guuid=c30c7002-2200-0000-2660-b05abb110000 pid=4539 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=c30c7002-2200-0000-2660-b05abb110000 pid=4539 execve guuid=e8fd2e03-2200-0000-2660-b05abe110000 pid=4542 /usr/bin/wget net send-data guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e8fd2e03-2200-0000-2660-b05abe110000 pid=4542 execve guuid=2af2dc05-2200-0000-2660-b05ac9110000 pid=4553 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=2af2dc05-2200-0000-2660-b05ac9110000 pid=4553 execve guuid=ff614d0a-2200-0000-2660-b05ad5110000 pid=4565 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=ff614d0a-2200-0000-2660-b05ad5110000 pid=4565 clone guuid=f066690a-2200-0000-2660-b05ad6110000 pid=4566 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=f066690a-2200-0000-2660-b05ad6110000 pid=4566 execve guuid=119aaf0a-2200-0000-2660-b05ad8110000 pid=4568 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=119aaf0a-2200-0000-2660-b05ad8110000 pid=4568 execve guuid=7b19850b-2200-0000-2660-b05adc110000 pid=4572 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=7b19850b-2200-0000-2660-b05adc110000 pid=4572 execve guuid=e9ac241f-2200-0000-2660-b05a28120000 pid=4648 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e9ac241f-2200-0000-2660-b05a28120000 pid=4648 execve guuid=a6d71928-2200-0000-2660-b05a4d120000 pid=4685 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=a6d71928-2200-0000-2660-b05a4d120000 pid=4685 clone guuid=758d3328-2200-0000-2660-b05a4e120000 pid=4686 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=758d3328-2200-0000-2660-b05a4e120000 pid=4686 execve guuid=f46c7928-2200-0000-2660-b05a4f120000 pid=4687 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=f46c7928-2200-0000-2660-b05a4f120000 pid=4687 execve guuid=251c0529-2200-0000-2660-b05a52120000 pid=4690 /usr/bin/wget net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=251c0529-2200-0000-2660-b05a52120000 pid=4690 execve guuid=e2959b2e-2200-0000-2660-b05a61120000 pid=4705 /usr/bin/curl net send-data write-file guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=e2959b2e-2200-0000-2660-b05a61120000 pid=4705 execve guuid=d19d8e38-2200-0000-2660-b05a85120000 pid=4741 /usr/bin/bash guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=d19d8e38-2200-0000-2660-b05a85120000 pid=4741 clone guuid=8745a838-2200-0000-2660-b05a86120000 pid=4742 /usr/bin/chmod guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=8745a838-2200-0000-2660-b05a86120000 pid=4742 execve guuid=2686fb38-2200-0000-2660-b05a8a120000 pid=4746 /tmp/Chaotic guuid=b3308ed0-1f00-0000-2660-b05a810c0000 pid=3201->guuid=2686fb38-2200-0000-2660-b05a8a120000 pid=4746 execve ef5976db-57ef-5c0b-b69d-e426e72a9af3 176.65.148.189:80 guuid=014e7bd6-1f00-0000-2660-b05a8a0c0000 pid=3210->ef5976db-57ef-5c0b-b69d-e426e72a9af3 send: 149B guuid=8d1fbdde-1f00-0000-2660-b05a950c0000 pid=3221->ef5976db-57ef-5c0b-b69d-e426e72a9af3 send: 98B guuid=414d09f1-1f00-0000-2660-b05a9a0c0000 pid=3226->ef5976db-57ef-5c0b-b69d-e426e72a9af3 send: 149B guuid=68b7d33f-2000-0000-2660-b05a0e0d0000 pid=3342->ef5976db-57ef-5c0b-b69d-e426e72a9af3 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=628fa649-2000-0000-2660-b05a220d0000 pid=3362 /tmp/Chaotic guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361->guuid=628fa649-2000-0000-2660-b05a220d0000 pid=3362 clone guuid=a9a45085-2000-0000-2660-b05aae0d0000 pid=3502 /tmp/Chaotic guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361->guuid=a9a45085-2000-0000-2660-b05aae0d0000 pid=3502 clone guuid=1a1dfcc0-2000-0000-2660-b05ac20d0000 pid=3522 /tmp/Chaotic guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361->guuid=1a1dfcc0-2000-0000-2660-b05ac20d0000 pid=3522 clone guuid=203402c1-2000-0000-2660-b05ac30d0000 pid=3523 /tmp/Chaotic dns net send-data zombie guuid=b72ac548-2000-0000-2660-b05a210d0000 pid=3361->guuid=203402c1-2000-0000-2660-b05ac30d0000 pid=3523 clone guuid=203402c1-2000-0000-2660-b05ac30d0000 pid=3523->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=203402c1-2000-0000-2660-b05ac30d0000 pid=3523->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 4585B de5351a1-2161-595d-a53b-7b036346f95c cnc.frtewq.online:3778 guuid=203402c1-2000-0000-2660-b05ac30d0000 pid=3523->de5351a1-2161-595d-a53b-7b036346f95c send: 650B 63c910a8-5039-5653-8f25-fc5b431bdf53 cnc.frtewq.online:80 guuid=e799f7d0-2000-0000-2660-b05ac40d0000 pid=3524->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 152B guuid=109a51d6-2000-0000-2660-b05acc0d0000 pid=3532->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 101B guuid=6de347dd-2000-0000-2660-b05adb0d0000 pid=3547->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=e48b47e1-2000-0000-2660-b05ae40d0000 pid=3556->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=3fb48026-2100-0000-2660-b05a900e0000 pid=3728->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=47595d2d-2100-0000-2660-b05aa90e0000 pid=3753->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=12aeed34-2100-0000-2660-b05ac50e0000 pid=3781->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 152B guuid=18704d38-2100-0000-2660-b05acf0e0000 pid=3791->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 101B guuid=54d14f40-2100-0000-2660-b05af00e0000 pid=3824->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=6fd4cf47-2100-0000-2660-b05a130f0000 pid=3859->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=d6668f54-2100-0000-2660-b05a340f0000 pid=3892->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 149B guuid=ee5a6e59-2100-0000-2660-b05a420f0000 pid=3906->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 98B guuid=bfc02361-2100-0000-2660-b05a610f0000 pid=3937->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=3338ee64-2100-0000-2660-b05a710f0000 pid=3953->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=b35393a6-2100-0000-2660-b05a5a100000 pid=4186->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=99fb98a9-2100-0000-2660-b05a68100000 pid=4200->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=bd49bfb0-2100-0000-2660-b05a7b100000 pid=4219->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=aff3f8b3-2100-0000-2660-b05a8b100000 pid=4235->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=a498f0b9-2100-0000-2660-b05aa1100000 pid=4257->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 149B guuid=4087eefa-2100-0000-2660-b05a9b110000 pid=4507->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 98B guuid=e8fd2e03-2200-0000-2660-b05abe110000 pid=4542->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 151B guuid=2af2dc05-2200-0000-2660-b05ac9110000 pid=4553->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 100B guuid=7b19850b-2200-0000-2660-b05adc110000 pid=4572->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 150B guuid=e9ac241f-2200-0000-2660-b05a28120000 pid=4648->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 99B guuid=251c0529-2200-0000-2660-b05a52120000 pid=4690->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 149B guuid=e2959b2e-2200-0000-2660-b05a61120000 pid=4705->63c910a8-5039-5653-8f25-fc5b431bdf53 send: 98B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-15 23:21:06 UTC
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 33f83dc5555afc3222686934a3d4fe0c227e592fb7a40c2b2155540dd2630746

(this sample)

  
Delivery method
Distributed via web download

Comments