MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7
SHA3-384 hash: d6c6bae4f03e812aa70576471b685a6f962f0ea6b66dab782f437777aa670ca40d61925e26a80798189197593609b099
SHA1 hash: d894d941a1e8228d275b66885899689aba1fefbd
MD5 hash: 1378eec9d6e112bb72a4dced1ecd4915
humanhash: whiskey-hot-freddie-fish
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'754 bytes
First seen:2026-01-20 19:14:00 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 96:i2sF32i532Hxx32vH32Bb32TVB32WyE32KN32PX328X32lv32fX32z/32GD32b9W:avkxag8BXHOVEIAH0W
TLSH T1907172A6CA0211781C595B62EDBB11FAF085F3E234E7BB0F75882CF8619DF025485DD2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arc6c1eb958d98d7ed84163cb9ebbd01f6951d1a08cab6447c803e3774d0ce15f29 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.x8644416a0e03e3023fbbe9fe9902b88fb7e91e220ba51d66e84f6e8b36b00cbe31 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.x86_6443f061b3363390f9a18c45ebfa7e1ecf5b816b8c89c3bab854c1949e66308f59 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.i6867e9f6d938f9a646812f5689172c76d7268fa6408b4014dc5f0c3039dd5dcb43c Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips38f5e2dcbc7636ea968e7765c2ec2b8e9ace6faae5f3c067a32cbd7e151c2e21 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mips64n/an/acensys elf ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.mpslc2f74d83d6ea88ea9275391cff7d6abebc1689e562aa00a0f083aae191bbae86 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.armc22b631e109685d77cef7c70e083ed02aefed9e50aed1d37a440a36e989c2b76 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm578b30c10048387bf7255a785339d1f6001b8e67d2a63ce8781a45ae6fc784c82 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm64409752a9a014c5699614f0f834392292cb14f889d55bd63b332a50af4c04220 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.arm7f0c00c47ab00f051efa5776deaac34d0ccd2ebb8a9fff90db83cb877c50732b1 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.ppc1b006631bebae3f724055e4d835abea40399bfcc2a517d235731527db9904a5f Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.sparcn/an/acensys elf ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.m68k702c5ff22698a3df5ba6e08e8325fb311726df2408e85e9bfbf07058a23fcfb4 Miraicensys elf mirai ua-wget
http://45.83.207.194/HideChaotic/ub8ehJSePAfc9FYqZIT6.sh40a0565a2216f09fa039902f24f4e1c7ef05fadd5f338109d518e7007135bd09a Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-19T15:18:00Z UTC
Last seen:
2026-01-21T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=6e95cebb-1a00-0000-dbcd-6040640b0000 pid=2916 /usr/bin/sudo guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922 /tmp/sample.bin guuid=6e95cebb-1a00-0000-dbcd-6040640b0000 pid=2916->guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922 execve guuid=374761bf-1a00-0000-dbcd-60406b0b0000 pid=2923 /usr/bin/cp guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=374761bf-1a00-0000-dbcd-60406b0b0000 pid=2923 execve guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937 execve guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069 execve guuid=38eeab3d-1b00-0000-dbcd-6040670c0000 pid=3175 /usr/bin/cat guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=38eeab3d-1b00-0000-dbcd-6040670c0000 pid=3175 execve guuid=8742183e-1b00-0000-dbcd-6040680c0000 pid=3176 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=8742183e-1b00-0000-dbcd-6040680c0000 pid=3176 execve guuid=e998683e-1b00-0000-dbcd-6040690c0000 pid=3177 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e998683e-1b00-0000-dbcd-6040690c0000 pid=3177 clone guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180 execve guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217 execve guuid=c15ead89-1b00-0000-dbcd-6040cb0c0000 pid=3275 /usr/bin/cat guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c15ead89-1b00-0000-dbcd-6040cb0c0000 pid=3275 execve guuid=e6f2178a-1b00-0000-dbcd-6040ce0c0000 pid=3278 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e6f2178a-1b00-0000-dbcd-6040ce0c0000 pid=3278 execve guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280 /tmp/Chaotic delete-file net guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280 execve guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537 execve guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621 execve guuid=b59dbe5e-1c00-0000-dbcd-6040980e0000 pid=3736 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b59dbe5e-1c00-0000-dbcd-6040980e0000 pid=3736 clone guuid=d4ece35e-1c00-0000-dbcd-60409a0e0000 pid=3738 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=d4ece35e-1c00-0000-dbcd-60409a0e0000 pid=3738 execve guuid=ab91625f-1c00-0000-dbcd-60409c0e0000 pid=3740 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=ab91625f-1c00-0000-dbcd-60409c0e0000 pid=3740 execve guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744 execve guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857 execve guuid=29d7aca9-1c00-0000-dbcd-60408b0f0000 pid=3979 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=29d7aca9-1c00-0000-dbcd-60408b0f0000 pid=3979 clone guuid=739ec1a9-1c00-0000-dbcd-60408d0f0000 pid=3981 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=739ec1a9-1c00-0000-dbcd-60408d0f0000 pid=3981 execve guuid=207902aa-1c00-0000-dbcd-60408f0f0000 pid=3983 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=207902aa-1c00-0000-dbcd-60408f0f0000 pid=3983 execve guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986 execve guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170 execve guuid=cf973d0b-1d00-0000-dbcd-6040f5100000 pid=4341 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=cf973d0b-1d00-0000-dbcd-6040f5100000 pid=4341 clone guuid=83a1560b-1d00-0000-dbcd-6040f6100000 pid=4342 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=83a1560b-1d00-0000-dbcd-6040f6100000 pid=4342 execve guuid=320ebb0b-1d00-0000-dbcd-6040f7100000 pid=4343 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=320ebb0b-1d00-0000-dbcd-6040f7100000 pid=4343 execve guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344 /usr/bin/wget net send-data guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344 execve guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430 execve guuid=6f841c3f-1d00-0000-dbcd-6040ad110000 pid=4525 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=6f841c3f-1d00-0000-dbcd-6040ad110000 pid=4525 clone guuid=7a53343f-1d00-0000-dbcd-6040ae110000 pid=4526 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=7a53343f-1d00-0000-dbcd-6040ae110000 pid=4526 execve guuid=22ab923f-1d00-0000-dbcd-6040b0110000 pid=4528 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=22ab923f-1d00-0000-dbcd-6040b0110000 pid=4528 execve guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530 execve guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725 execve guuid=f84dd49f-1d00-0000-dbcd-60402b130000 pid=4907 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=f84dd49f-1d00-0000-dbcd-60402b130000 pid=4907 clone guuid=5b2e02a0-1d00-0000-dbcd-60402c130000 pid=4908 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=5b2e02a0-1d00-0000-dbcd-60402c130000 pid=4908 execve guuid=4dc358a0-1d00-0000-dbcd-60402e130000 pid=4910 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=4dc358a0-1d00-0000-dbcd-60402e130000 pid=4910 execve guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913 execve guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103 execve guuid=ef418203-1e00-0000-dbcd-604084140000 pid=5252 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=ef418203-1e00-0000-dbcd-604084140000 pid=5252 clone guuid=96f9a203-1e00-0000-dbcd-604085140000 pid=5253 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=96f9a203-1e00-0000-dbcd-604085140000 pid=5253 execve guuid=22c22604-1e00-0000-dbcd-604086140000 pid=5254 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=22c22604-1e00-0000-dbcd-604086140000 pid=5254 execve guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255 execve guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267 execve guuid=0d055a4c-1e00-0000-dbcd-604094140000 pid=5268 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=0d055a4c-1e00-0000-dbcd-604094140000 pid=5268 clone guuid=b9a08e4c-1e00-0000-dbcd-604095140000 pid=5269 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=b9a08e4c-1e00-0000-dbcd-604095140000 pid=5269 execve guuid=11c9264d-1e00-0000-dbcd-604096140000 pid=5270 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=11c9264d-1e00-0000-dbcd-604096140000 pid=5270 execve guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271 execve guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272 execve guuid=132058ae-1e00-0000-dbcd-604099140000 pid=5273 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=132058ae-1e00-0000-dbcd-604099140000 pid=5273 clone guuid=32aaa5ae-1e00-0000-dbcd-60409a140000 pid=5274 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=32aaa5ae-1e00-0000-dbcd-60409a140000 pid=5274 execve guuid=e52332af-1e00-0000-dbcd-60409b140000 pid=5275 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e52332af-1e00-0000-dbcd-60409b140000 pid=5275 execve guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276 execve guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277 execve guuid=248c3b10-1f00-0000-dbcd-6040a5140000 pid=5285 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=248c3b10-1f00-0000-dbcd-6040a5140000 pid=5285 clone guuid=92616a10-1f00-0000-dbcd-6040a6140000 pid=5286 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=92616a10-1f00-0000-dbcd-6040a6140000 pid=5286 execve guuid=c226d110-1f00-0000-dbcd-6040a7140000 pid=5287 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c226d110-1f00-0000-dbcd-6040a7140000 pid=5287 execve guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288 execve guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289 execve guuid=0a463770-1f00-0000-dbcd-6040aa140000 pid=5290 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=0a463770-1f00-0000-dbcd-6040aa140000 pid=5290 clone guuid=da786770-1f00-0000-dbcd-6040ab140000 pid=5291 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=da786770-1f00-0000-dbcd-6040ab140000 pid=5291 execve guuid=00e5f270-1f00-0000-dbcd-6040ac140000 pid=5292 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=00e5f270-1f00-0000-dbcd-6040ac140000 pid=5292 execve guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293 /usr/bin/wget net send-data guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293 execve guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294 execve guuid=2c1b51a9-1f00-0000-dbcd-6040af140000 pid=5295 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=2c1b51a9-1f00-0000-dbcd-6040af140000 pid=5295 clone guuid=a7266eac-1f00-0000-dbcd-6040b0140000 pid=5296 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=a7266eac-1f00-0000-dbcd-6040b0140000 pid=5296 execve guuid=c5d509ad-1f00-0000-dbcd-6040b1140000 pid=5297 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c5d509ad-1f00-0000-dbcd-6040b1140000 pid=5297 execve guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298 execve guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299 execve guuid=465bc52b-2000-0000-dbcd-6040c3140000 pid=5315 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=465bc52b-2000-0000-dbcd-6040c3140000 pid=5315 clone guuid=13aadf2b-2000-0000-dbcd-6040c4140000 pid=5316 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=13aadf2b-2000-0000-dbcd-6040c4140000 pid=5316 execve guuid=688e2e2c-2000-0000-dbcd-6040c5140000 pid=5317 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=688e2e2c-2000-0000-dbcd-6040c5140000 pid=5317 execve guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319 /usr/bin/wget net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319 execve guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336 /usr/bin/curl net send-data write-file guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336 execve guuid=746d8e9f-2000-0000-dbcd-6040d9140000 pid=5337 /usr/bin/bash guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=746d8e9f-2000-0000-dbcd-6040d9140000 pid=5337 clone guuid=8f4cb99f-2000-0000-dbcd-6040da140000 pid=5338 /usr/bin/chmod guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=8f4cb99f-2000-0000-dbcd-6040da140000 pid=5338 execve guuid=e69407a0-2000-0000-dbcd-6040db140000 pid=5339 /tmp/Chaotic guuid=ded27ebe-1a00-0000-dbcd-60406a0b0000 pid=2922->guuid=e69407a0-2000-0000-dbcd-6040db140000 pid=5339 execve 15315276-1abc-5418-9f15-f39b3f0d7152 45.83.207.194:80 guuid=5ec525c5-1a00-0000-dbcd-6040790b0000 pid=2937->15315276-1abc-5418-9f15-f39b3f0d7152 send: 164B guuid=b1ce6901-1b00-0000-dbcd-6040fd0b0000 pid=3069->15315276-1abc-5418-9f15-f39b3f0d7152 send: 113B guuid=1693f23f-1b00-0000-dbcd-60406c0c0000 pid=3180->15315276-1abc-5418-9f15-f39b3f0d7152 send: 164B guuid=75517864-1b00-0000-dbcd-6040910c0000 pid=3217->15315276-1abc-5418-9f15-f39b3f0d7152 send: 113B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=867d068b-1b00-0000-dbcd-6040d10c0000 pid=3281 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=867d068b-1b00-0000-dbcd-6040d10c0000 pid=3281 clone guuid=3fbcafc6-1b00-0000-dbcd-6040320d0000 pid=3378 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=3fbcafc6-1b00-0000-dbcd-6040320d0000 pid=3378 clone guuid=79a55702-1c00-0000-dbcd-6040cf0d0000 pid=3535 /tmp/Chaotic guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=79a55702-1c00-0000-dbcd-6040cf0d0000 pid=3535 clone guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536 /tmp/Chaotic dns net send-data zombie guuid=3625658a-1b00-0000-dbcd-6040d00c0000 pid=3280->guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536 clone guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 1638B bb4fe9eb-6da4-5bc7-bf8c-de96d6b4783d dongfeng.serveftp.com:3778 guuid=f30c5f02-1c00-0000-dbcd-6040d00d0000 pid=3536->bb4fe9eb-6da4-5bc7-bf8c-de96d6b4783d send: 210B 685f26a2-1253-56c3-81ac-19327d8ce227 dongfeng.serveftp.com:80 guuid=74ab7e02-1c00-0000-dbcd-6040d10d0000 pid=3537->685f26a2-1253-56c3-81ac-19327d8ce227 send: 167B guuid=daa6e72f-1c00-0000-dbcd-6040250e0000 pid=3621->685f26a2-1253-56c3-81ac-19327d8ce227 send: 116B guuid=5ba51760-1c00-0000-dbcd-6040a00e0000 pid=3744->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=b77c4884-1c00-0000-dbcd-6040110f0000 pid=3857->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=33ecadaa-1c00-0000-dbcd-6040920f0000 pid=3986->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=f1ad3edb-1c00-0000-dbcd-60404a100000 pid=4170->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=5642900c-1d00-0000-dbcd-6040f8100000 pid=4344->685f26a2-1253-56c3-81ac-19327d8ce227 send: 167B guuid=9407b324-1d00-0000-dbcd-60404e110000 pid=4430->685f26a2-1253-56c3-81ac-19327d8ce227 send: 116B guuid=a4241c40-1d00-0000-dbcd-6040b2110000 pid=4530->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=3f5cd46f-1d00-0000-dbcd-604075120000 pid=4725->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=e65ae5a0-1d00-0000-dbcd-604031130000 pid=4913->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=05d4afcf-1d00-0000-dbcd-6040ef130000 pid=5103->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B guuid=e56f3705-1e00-0000-dbcd-604087140000 pid=5255->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=89a3dd28-1e00-0000-dbcd-604093140000 pid=5267->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=4db93f4e-1e00-0000-dbcd-604097140000 pid=5271->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=bcf60b7d-1e00-0000-dbcd-604098140000 pid=5272->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=e7a42bb0-1e00-0000-dbcd-60409c140000 pid=5276->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=20fe87e0-1e00-0000-dbcd-60409d140000 pid=5277->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=dc33d311-1f00-0000-dbcd-6040a8140000 pid=5288->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=48d2e93f-1f00-0000-dbcd-6040a9140000 pid=5289->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B guuid=516bd371-1f00-0000-dbcd-6040ad140000 pid=5293->685f26a2-1253-56c3-81ac-19327d8ce227 send: 166B guuid=6d42108c-1f00-0000-dbcd-6040ae140000 pid=5294->685f26a2-1253-56c3-81ac-19327d8ce227 send: 115B guuid=c50674af-1f00-0000-dbcd-6040b2140000 pid=5298->685f26a2-1253-56c3-81ac-19327d8ce227 send: 165B guuid=2b7f07f3-1f00-0000-dbcd-6040b3140000 pid=5299->685f26a2-1253-56c3-81ac-19327d8ce227 send: 114B guuid=7fccbf2c-2000-0000-dbcd-6040c7140000 pid=5319->685f26a2-1253-56c3-81ac-19327d8ce227 send: 164B guuid=aaf01566-2000-0000-dbcd-6040d8140000 pid=5336->685f26a2-1253-56c3-81ac-19327d8ce227 send: 113B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-20 19:14:40 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 3b27f77945f61dcff3e1150d21e86ef317d58f59832cb84cfaed485a7a34cac7

(this sample)

Comments