MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7
SHA3-384 hash: d6c6bae4f03e812aa70576471b685a6f962f0ea6b66dab782f437777aa670ca40d61925e26a80798189197593609b099
SHA1 hash: d894d941a1e8228d275b66885899689aba1fefbd
MD5 hash: 1378eec9d6e112bb72a4dced1ecd4915
humanhash: whiskey-hot-freddie-fish
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'754 bytes
First seen:2026-01-20 19:14:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:i2sF32i532Hxx32vH32Bb32TVB32WyE32KN32PX328X32lv32fX32z/32GD32b9W:avkxag8BXHOVEIAH0W
TLSH T1907172A6CA0211781C595B62EDBB11FAF085F3E234E7BB0F75882CF8619DF025485DD2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arcb6713999794c074afb20cd0fddd1a2b84c3a9bbc4118cbfc7485b250ece0c5d4 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.x869e20ba6171389eb317538e9c6e06ad1a8e62f361eff798d12dd7bccf2282f2dd Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.x86_641a530aad31e8082d833355356aa3b68df3fd4043aa08a07217ccb614da59bbb9 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.i68647660b0021d466c1ad2061f2ea45f36b5ec1a036a332588290ed740f11c2dae9 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mipscc65128ca415ce856ec533b877c95a4f3fdcf0b24d08a15fdf1b9a289fb37c40 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips64n/an/acensys elf ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mpslf9771621dbeae85c50574ed370278e679b1b09b857b90823a28708cbdfb53a00 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm0b9f8a80f72c5900d1c7f5d6bc8b162c32dbce682412073521c9f9d12226cc39 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm5e7dc1aeefd378db04cfcbdc88a7822ff03d868fda8d4dc34e804ee6e5af4b4f5 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm6262b55fe2b19f552c29edca64d09341f92a93a3f8007c67a5e31cda4679c0739 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm73573118eddae37e80b4e199500a1296a9b72fbb86ec93ca1aa12b70c7269cdd0 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.ppcccd150b016e80c8ddc967b068792cbec07cbec7bb9b4d75e71209b7b733715f6 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.sparcn/an/acensys elf ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.m68kcdcb1ddec2f6ad49cb8aea86c5a54f73eacf08b0f52363f86fcb4199b1baee19 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.sh49f295bdd995f144619a52708d3539f5c7e8fb2e25d8268b5744470bf7e381648 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-19T15:18:00Z UTC
Last seen:
2026-01-21T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=6e95cebb-1a00-0000-dbcd-6040640b0000 pid=2916 /usr/bin/sudo guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922 /tmp/sample.bin guuid=6e95cebb-1a00-0000-dbcd-6040640b0000 pid=2916->guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922 execve guuid=374761bf-1a00-0000-dbcd-60406b0b0000 pid=2923 /usr/bin/cp guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=374761bf-1a00-0000-dbcd-60406b0b0000 pid=2923 execve guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937 execve guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069 execve guuid=38eeab3d-1b00-0000-dbcd-6040670c0000 pid=3175 /usr/bin/cat guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=38eeab3d-1b00-0000-dbcd-6040670c0000 pid=3175 execve guuid=8742183e-1b00-0000-dbcd-6040680c0000 pid=3176 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=8742183e-1b00-0000-dbcd-6040680c0000 pid=3176 execve guuid=e998683e-1b00-0000-dbcd-6040690c0000 pid=3177 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e998683e-1b00-0000-dbcd-6040690c0000 pid=3177 clone guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180 execve guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217 execve guuid=c15ead89-1b00-0000-dbcd-6040cb0c0000 pid=3275 /usr/bin/cat guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c15ead89-1b00-0000-dbcd-6040cb0c0000 pid=3275 execve guuid=e6f2178a-1b00-0000-dbcd-6040ce0c0000 pid=3278 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e6f2178a-1b00-0000-dbcd-6040ce0c0000 pid=3278 execve guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280 /tmp/Chaotic delete-file net guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280 execve guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537 execve guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621 execve guuid=b59dbe5e-1c00-0000-dbcd-6040980e0000 pid=3736 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b59dbe5e-1c00-0000-dbcd-6040980e0000 pid=3736 clone guuid=d4ece35e-1c00-0000-dbcd-60409a0e0000 pid=3738 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=d4ece35e-1c00-0000-dbcd-60409a0e0000 pid=3738 execve guuid=ab91625f-1c00-0000-dbcd-60409c0e0000 pid=3740 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=ab91625f-1c00-0000-dbcd-60409c0e0000 pid=3740 execve guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744 execve guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857 execve guuid=29d7aca9-1c00-0000-dbcd-60408b0f0000 pid=3979 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=29d7aca9-1c00-0000-dbcd-60408b0f0000 pid=3979 clone guuid=739ec1a9-1c00-0000-dbcd-60408d0f0000 pid=3981 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=739ec1a9-1c00-0000-dbcd-60408d0f0000 pid=3981 execve guuid=207902aa-1c00-0000-dbcd-60408f0f0000 pid=3983 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=207902aa-1c00-0000-dbcd-60408f0f0000 pid=3983 execve guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986 execve guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170 execve guuid=cf973d0b-1d00-0000-dbcd-6040f5100000 pid=4341 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=cf973d0b-1d00-0000-dbcd-6040f5100000 pid=4341 clone guuid=83a1560b-1d00-0000-dbcd-6040f6100000 pid=4342 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=83a1560b-1d00-0000-dbcd-6040f6100000 pid=4342 execve guuid=320ebb0b-1d00-0000-dbcd-6040f7100000 pid=4343 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=320ebb0b-1d00-0000-dbcd-6040f7100000 pid=4343 execve guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344 /usr/bin/wget net send-data guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344 execve guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430 execve guuid=6f841c3f-1d00-0000-dbcd-6040ad110000 pid=4525 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=6f841c3f-1d00-0000-dbcd-6040ad110000 pid=4525 clone guuid=7a53343f-1d00-0000-dbcd-6040ae110000 pid=4526 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=7a53343f-1d00-0000-dbcd-6040ae110000 pid=4526 execve guuid=22ab923f-1d00-0000-dbcd-6040b0110000 pid=4528 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=22ab923f-1d00-0000-dbcd-6040b0110000 pid=4528 execve guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530 execve guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725 execve guuid=f84dd49f-1d00-0000-dbcd-60402b130000 pid=4907 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=f84dd49f-1d00-0000-dbcd-60402b130000 pid=4907 clone guuid=5b2e02a0-1d00-0000-dbcd-60402c130000 pid=4908 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5b2e02a0-1d00-0000-dbcd-60402c130000 pid=4908 execve guuid=4dc358a0-1d00-0000-dbcd-60402e130000 pid=4910 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=4dc358a0-1d00-0000-dbcd-60402e130000 pid=4910 execve guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913 execve guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103 execve guuid=ef418203-1e00-0000-dbcd-604084140000 pid=5252 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=ef418203-1e00-0000-dbcd-604084140000 pid=5252 clone guuid=96f9a203-1e00-0000-dbcd-604085140000 pid=5253 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=96f9a203-1e00-0000-dbcd-604085140000 pid=5253 execve guuid=22c22604-1e00-0000-dbcd-604086140000 pid=5254 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=22c22604-1e00-0000-dbcd-604086140000 pid=5254 execve guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255 execve guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267 execve guuid=0d055a4c-1e00-0000-dbcd-604094140000 pid=5268 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=0d055a4c-1e00-0000-dbcd-604094140000 pid=5268 clone guuid=b9a08e4c-1e00-0000-dbcd-604095140000 pid=5269 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b9a08e4c-1e00-0000-dbcd-604095140000 pid=5269 execve guuid=11c9264d-1e00-0000-dbcd-604096140000 pid=5270 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=11c9264d-1e00-0000-dbcd-604096140000 pid=5270 execve guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271 execve guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272 execve guuid=132058ae-1e00-0000-dbcd-604099140000 pid=5273 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=132058ae-1e00-0000-dbcd-604099140000 pid=5273 clone guuid=32aaa5ae-1e00-0000-dbcd-60409a140000 pid=5274 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=32aaa5ae-1e00-0000-dbcd-60409a140000 pid=5274 execve guuid=e52332af-1e00-0000-dbcd-60409b140000 pid=5275 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e52332af-1e00-0000-dbcd-60409b140000 pid=5275 execve guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276 execve guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277 execve guuid=248c3b10-1f00-0000-dbcd-6040a5140000 pid=5285 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=248c3b10-1f00-0000-dbcd-6040a5140000 pid=5285 clone guuid=92616a10-1f00-0000-dbcd-6040a6140000 pid=5286 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=92616a10-1f00-0000-dbcd-6040a6140000 pid=5286 execve guuid=c226d110-1f00-0000-dbcd-6040a7140000 pid=5287 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c226d110-1f00-0000-dbcd-6040a7140000 pid=5287 execve guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288 execve guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289 execve guuid=0a463770-1f00-0000-dbcd-6040aa140000 pid=5290 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=0a463770-1f00-0000-dbcd-6040aa140000 pid=5290 clone guuid=da786770-1f00-0000-dbcd-6040ab140000 pid=5291 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=da786770-1f00-0000-dbcd-6040ab140000 pid=5291 execve guuid=00e5f270-1f00-0000-dbcd-6040ac140000 pid=5292 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=00e5f270-1f00-0000-dbcd-6040ac140000 pid=5292 execve guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293 /usr/bin/wget net send-data guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293 execve guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294 execve guuid=2c1b51a9-1f00-0000-dbcd-6040af140000 pid=5295 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=2c1b51a9-1f00-0000-dbcd-6040af140000 pid=5295 clone guuid=a7266eac-1f00-0000-dbcd-6040b0140000 pid=5296 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=a7266eac-1f00-0000-dbcd-6040b0140000 pid=5296 execve guuid=c5d509ad-1f00-0000-dbcd-6040b1140000 pid=5297 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c5d509ad-1f00-0000-dbcd-6040b1140000 pid=5297 execve guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298 execve guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299 execve guuid=465bc52b-2000-0000-dbcd-6040c3140000 pid=5315 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=465bc52b-2000-0000-dbcd-6040c3140000 pid=5315 clone guuid=13aadf2b-2000-0000-dbcd-6040c4140000 pid=5316 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=13aadf2b-2000-0000-dbcd-6040c4140000 pid=5316 execve guuid=688e2e2c-2000-0000-dbcd-6040c5140000 pid=5317 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=688e2e2c-2000-0000-dbcd-6040c5140000 pid=5317 execve guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319 execve guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336 execve guuid=746d8e9f-2000-0000-dbcd-6040d9140000 pid=5337 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=746d8e9f-2000-0000-dbcd-6040d9140000 pid=5337 clone guuid=8f4cb99f-2000-0000-dbcd-6040da140000 pid=5338 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=8f4cb99f-2000-0000-dbcd-6040da140000 pid=5338 execve guuid=e69407a0-2000-0000-dbcd-6040db140000 pid=5339 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e69407a0-2000-0000-dbcd-6040db140000 pid=5339 execve 15315276-1abc-5418-9f15-f39b3f0d7152 45.83.207.194:80 guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937->15315276-1abc-5418-9f15-f39b3f0d7152 send: 164B guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069->15315276-1abc-5418-9f15-f39b3f0d7152 send: 113B guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180->15315276-1abc-5418-9f15-f39b3f0d7152 send: 164B guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217->15315276-1abc-5418-9f15-f39b3f0d7152 send: 113B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=867d068b-1b00-0000-dbcd-6040d10c0000 pid=3281 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=867d068b-1b00-0000-dbcd-6040d10c0000 pid=3281 clone guuid=3fbcafc6-1b00-0000-dbcd-6040320d0000 pid=3378 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=3fbcafc6-1b00-0000-dbcd-6040320d0000 pid=3378 clone guuid=79a55702-1c00-0000-dbcd-6040cf0d0000 pid=3535 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=79a55702-1c00-0000-dbcd-6040cf0d0000 pid=3535 clone guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536 /tmp/Chaotic dns net send-data zombie guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536 clone guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 1638B bb4fe9eb-6da4-5bc7-bf8c-de96d6b4783d dongfeng.serveftp.com:3778 guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->bb4fe9eb-6da4-5bc7-bf8c-de96d6b4783d send: 210B 685f26a2-1253-56c3-81ac-19327d8ce227 dongfeng.serveftp.com:80 guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537->685f26a2-1253-56c3-81ac-19327d8ce227 send: 167B guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621->685f26a2-1253-56c3-81ac-19327d8ce227 send: 116B guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344->685f26a2-1253-56c3-81ac-19327d8ce227 send: 167B guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430->685f26a2-1253-56c3-81ac-19327d8ce227 send: 116B guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293->685f26a2-1253-56c3-81ac-19327d8ce227 send: 166B guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294->685f26a2-1253-56c3-81ac-19327d8ce227 send: 115B guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-20 19:14:40 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7

(this sample)

Comments