MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 489ee0930ca21690c07c770b01b60d35b9eaa46f4e20da92b7f8b5d533b49867. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 489ee0930ca21690c07c770b01b60d35b9eaa46f4e20da92b7f8b5d533b49867
SHA3-384 hash: d6fc126d84b456d4b2f9d2f3e7bab86bd612c009c478160fadd2b06f248c87b971cecdb6f38c4c354fcb51b0916682e8
SHA1 hash: b849aedafcd530e8d80022fbea187e810e3708e2
MD5 hash: b59e0fd4e9db5c33e213fb98bb5e81a3
humanhash: mississippi-freddie-sad-grey
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'970 bytes
First seen:2025-10-03 05:35:25 UTC
Last seen:2025-10-03 11:40:10 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vc7f7N7hc66GcgSzPcqKWcooUc7o7o7UcfZ3bcv9RcUcgcjpVcSSOcG+CcpfTcB0:vc7f7N7hc66GcgSzPcqKWcooUc7o7o7Q
TLSH T1CD51C1894106CD382D67AF13E6B6C2287086A452ECE1BFD599E7BBF0074EC147650FA3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.80.225/hiddenbin/boatnet.x86804d3d54d13108819443e419c3d4cc652a2b1f4b5888c4dde5f268ef64de954f Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.mips6d2a1b330ef54ed53061e877759eadf1da2a61b756b9b7ac885e8e12ccb0e540 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.arc9fd8101e6ffd964f4fbfc443f50ca5415c5fe2b12a33c440214261c282a75478 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://196.251.80.225/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://196.251.80.225/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://196.251.80.225/hiddenbin/boatnet.mpsl89099c1e998108e7e02fec68014145098aeb3ebc59382e85d9bcad21f3590169 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.armce37b068e07472c43fa7fbb1d19fc4afcaa5f198f5f42634bc20686d82387d46 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.arm5b23c50d2b16ebfda7f97af2e735e00b4bf55791faa93d3d59745ad0f0c422a8d Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.arm6941e01321b9fbed42248436fbefa0509173b18bc00977b671de61ad06cafe1a0 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.arm79c73051dca715b07d730e72d2a7c9cf38d19f8b9facf159beea2d1d1acd1d2a9 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.ppc2687623f1b70a39cde38049d5703b404e4dc6748bb96644045181a2088a108d0 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://196.251.80.225/hiddenbin/boatnet.m68ka38627df22e61daeb371a761cd84ddf7f9574844934d3d8af658595daf1e6ef1 Miraielf mirai ua-wget
http://196.251.80.225/hiddenbin/boatnet.sh428d29bb92b443aee20f42edb6923d9e7f7d34f8af9d6099c5d50402b33b780c8 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
51
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-10-03T02:41:00Z UTC
Last seen:
2025-10-04T13:03:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=ab954d6a-2000-0000-02ba-7cee0c0c0000 pid=3084 /usr/bin/sudo guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091 /tmp/sample.bin guuid=ab954d6a-2000-0000-02ba-7cee0c0c0000 pid=3084->guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091 execve guuid=f6dc5c6e-2000-0000-02ba-7cee140c0000 pid=3092 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=f6dc5c6e-2000-0000-02ba-7cee140c0000 pid=3092 execve guuid=0de46274-2000-0000-02ba-7cee220c0000 pid=3106 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=0de46274-2000-0000-02ba-7cee220c0000 pid=3106 execve guuid=98a78e7f-2000-0000-02ba-7cee3e0c0000 pid=3134 /usr/bin/cat guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=98a78e7f-2000-0000-02ba-7cee3e0c0000 pid=3134 execve guuid=6bb70980-2000-0000-02ba-7cee410c0000 pid=3137 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=6bb70980-2000-0000-02ba-7cee410c0000 pid=3137 execve guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138 execve guuid=5f575d81-2000-0000-02ba-7cee4a0c0000 pid=3146 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=5f575d81-2000-0000-02ba-7cee4a0c0000 pid=3146 execve guuid=a16aab85-2000-0000-02ba-7cee510c0000 pid=3153 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=a16aab85-2000-0000-02ba-7cee510c0000 pid=3153 execve guuid=73046e8d-2000-0000-02ba-7cee630c0000 pid=3171 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=73046e8d-2000-0000-02ba-7cee630c0000 pid=3171 clone guuid=b0e88a8d-2000-0000-02ba-7cee640c0000 pid=3172 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=b0e88a8d-2000-0000-02ba-7cee640c0000 pid=3172 execve guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173 execve guuid=3e21fd8e-2000-0000-02ba-7cee690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=3e21fd8e-2000-0000-02ba-7cee690c0000 pid=3177 execve guuid=83d1b493-2000-0000-02ba-7cee6d0c0000 pid=3181 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=83d1b493-2000-0000-02ba-7cee6d0c0000 pid=3181 execve guuid=7eadde99-2000-0000-02ba-7cee790c0000 pid=3193 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=7eadde99-2000-0000-02ba-7cee790c0000 pid=3193 clone guuid=8042009a-2000-0000-02ba-7cee7a0c0000 pid=3194 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=8042009a-2000-0000-02ba-7cee7a0c0000 pid=3194 execve guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195 execve guuid=4a425d9b-2000-0000-02ba-7cee7f0c0000 pid=3199 /usr/bin/wget net send-data guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=4a425d9b-2000-0000-02ba-7cee7f0c0000 pid=3199 execve guuid=1435029e-2000-0000-02ba-7cee800c0000 pid=3200 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=1435029e-2000-0000-02ba-7cee800c0000 pid=3200 execve guuid=40d3afa2-2000-0000-02ba-7cee810c0000 pid=3201 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=40d3afa2-2000-0000-02ba-7cee810c0000 pid=3201 clone guuid=7d35e6a2-2000-0000-02ba-7cee820c0000 pid=3202 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=7d35e6a2-2000-0000-02ba-7cee820c0000 pid=3202 execve guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203 execve guuid=f7460ea6-2000-0000-02ba-7cee870c0000 pid=3207 /usr/bin/wget net send-data guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=f7460ea6-2000-0000-02ba-7cee870c0000 pid=3207 execve guuid=726eacaa-2000-0000-02ba-7cee880c0000 pid=3208 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=726eacaa-2000-0000-02ba-7cee880c0000 pid=3208 execve guuid=c80976b2-2000-0000-02ba-7cee8b0c0000 pid=3211 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=c80976b2-2000-0000-02ba-7cee8b0c0000 pid=3211 clone guuid=047796b2-2000-0000-02ba-7cee8c0c0000 pid=3212 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=047796b2-2000-0000-02ba-7cee8c0c0000 pid=3212 execve guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214 execve guuid=2ba5aeb3-2000-0000-02ba-7cee950c0000 pid=3221 /usr/bin/wget net send-data guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=2ba5aeb3-2000-0000-02ba-7cee950c0000 pid=3221 execve guuid=5f2faab6-2000-0000-02ba-7cee9a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=5f2faab6-2000-0000-02ba-7cee9a0c0000 pid=3226 execve guuid=177af3ba-2000-0000-02ba-7ceea50c0000 pid=3237 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=177af3ba-2000-0000-02ba-7ceea50c0000 pid=3237 clone guuid=0ef00dbb-2000-0000-02ba-7ceea70c0000 pid=3239 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=0ef00dbb-2000-0000-02ba-7ceea70c0000 pid=3239 execve guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241 execve guuid=4d0dffbb-2000-0000-02ba-7ceeaf0c0000 pid=3247 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=4d0dffbb-2000-0000-02ba-7ceeaf0c0000 pid=3247 execve guuid=cddaedbf-2000-0000-02ba-7ceeb70c0000 pid=3255 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=cddaedbf-2000-0000-02ba-7ceeb70c0000 pid=3255 execve guuid=8f502cc7-2000-0000-02ba-7ceebd0c0000 pid=3261 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=8f502cc7-2000-0000-02ba-7ceebd0c0000 pid=3261 clone guuid=da7058c7-2000-0000-02ba-7ceebe0c0000 pid=3262 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=da7058c7-2000-0000-02ba-7ceebe0c0000 pid=3262 execve guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263 execve guuid=f869a6c8-2000-0000-02ba-7ceec30c0000 pid=3267 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=f869a6c8-2000-0000-02ba-7ceec30c0000 pid=3267 execve guuid=175202ce-2000-0000-02ba-7ceec40c0000 pid=3268 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=175202ce-2000-0000-02ba-7ceec40c0000 pid=3268 execve guuid=758767d3-2000-0000-02ba-7ceec50c0000 pid=3269 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=758767d3-2000-0000-02ba-7ceec50c0000 pid=3269 clone guuid=ee9e90d3-2000-0000-02ba-7ceec60c0000 pid=3270 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=ee9e90d3-2000-0000-02ba-7ceec60c0000 pid=3270 execve guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271 execve guuid=a7ba30d5-2000-0000-02ba-7ceecb0c0000 pid=3275 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=a7ba30d5-2000-0000-02ba-7ceecb0c0000 pid=3275 execve guuid=c6b5c3d8-2000-0000-02ba-7ceecc0c0000 pid=3276 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=c6b5c3d8-2000-0000-02ba-7ceecc0c0000 pid=3276 execve guuid=e07150dd-2000-0000-02ba-7ceed40c0000 pid=3284 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=e07150dd-2000-0000-02ba-7ceed40c0000 pid=3284 clone guuid=6e5569dd-2000-0000-02ba-7ceed50c0000 pid=3285 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=6e5569dd-2000-0000-02ba-7ceed50c0000 pid=3285 execve guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286 execve guuid=49df78de-2000-0000-02ba-7ceeda0c0000 pid=3290 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=49df78de-2000-0000-02ba-7ceeda0c0000 pid=3290 execve guuid=05804de3-2000-0000-02ba-7ceedb0c0000 pid=3291 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=05804de3-2000-0000-02ba-7ceedb0c0000 pid=3291 execve guuid=d6a5b6ea-2000-0000-02ba-7ceee50c0000 pid=3301 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=d6a5b6ea-2000-0000-02ba-7ceee50c0000 pid=3301 clone guuid=ed03cfea-2000-0000-02ba-7ceee60c0000 pid=3302 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=ed03cfea-2000-0000-02ba-7ceee60c0000 pid=3302 execve guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304 execve guuid=63352fec-2000-0000-02ba-7ceeee0c0000 pid=3310 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=63352fec-2000-0000-02ba-7ceeee0c0000 pid=3310 execve guuid=7bb2e5f0-2000-0000-02ba-7ceef10c0000 pid=3313 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=7bb2e5f0-2000-0000-02ba-7ceef10c0000 pid=3313 execve guuid=4a9b66f7-2000-0000-02ba-7ceefc0c0000 pid=3324 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=4a9b66f7-2000-0000-02ba-7ceefc0c0000 pid=3324 clone guuid=0a3687f7-2000-0000-02ba-7ceefd0c0000 pid=3325 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=0a3687f7-2000-0000-02ba-7ceefd0c0000 pid=3325 execve guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327 execve guuid=0f31d4f8-2000-0000-02ba-7cee060d0000 pid=3334 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=0f31d4f8-2000-0000-02ba-7cee060d0000 pid=3334 execve guuid=384fd4fd-2000-0000-02ba-7cee0c0d0000 pid=3340 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=384fd4fd-2000-0000-02ba-7cee0c0d0000 pid=3340 execve guuid=d0503d05-2100-0000-02ba-7cee0f0d0000 pid=3343 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=d0503d05-2100-0000-02ba-7cee0f0d0000 pid=3343 clone guuid=2cdc5905-2100-0000-02ba-7cee100d0000 pid=3344 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=2cdc5905-2100-0000-02ba-7cee100d0000 pid=3344 execve guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346 execve guuid=26479906-2100-0000-02ba-7cee160d0000 pid=3350 /usr/bin/wget net send-data guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=26479906-2100-0000-02ba-7cee160d0000 pid=3350 execve guuid=142f6309-2100-0000-02ba-7cee1d0d0000 pid=3357 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=142f6309-2100-0000-02ba-7cee1d0d0000 pid=3357 execve guuid=3ad6650d-2100-0000-02ba-7cee2a0d0000 pid=3370 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=3ad6650d-2100-0000-02ba-7cee2a0d0000 pid=3370 clone guuid=fbb29c0d-2100-0000-02ba-7cee2b0d0000 pid=3371 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=fbb29c0d-2100-0000-02ba-7cee2b0d0000 pid=3371 execve guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373 execve guuid=9809f10e-2100-0000-02ba-7cee310d0000 pid=3377 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=9809f10e-2100-0000-02ba-7cee310d0000 pid=3377 execve guuid=74893c14-2100-0000-02ba-7cee3d0d0000 pid=3389 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=74893c14-2100-0000-02ba-7cee3d0d0000 pid=3389 execve guuid=bbb6d01a-2100-0000-02ba-7cee4d0d0000 pid=3405 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=bbb6d01a-2100-0000-02ba-7cee4d0d0000 pid=3405 clone guuid=4d18f11a-2100-0000-02ba-7cee4e0d0000 pid=3406 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=4d18f11a-2100-0000-02ba-7cee4e0d0000 pid=3406 execve guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407 execve guuid=849e271c-2100-0000-02ba-7cee530d0000 pid=3411 /usr/bin/wget net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=849e271c-2100-0000-02ba-7cee530d0000 pid=3411 execve guuid=8b0d5721-2100-0000-02ba-7cee600d0000 pid=3424 /usr/bin/curl net send-data write-file guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=8b0d5721-2100-0000-02ba-7cee600d0000 pid=3424 execve guuid=a17f0828-2100-0000-02ba-7cee6e0d0000 pid=3438 /usr/bin/bash guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=a17f0828-2100-0000-02ba-7cee6e0d0000 pid=3438 clone guuid=b9793c28-2100-0000-02ba-7cee6f0d0000 pid=3439 /usr/bin/chmod guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=b9793c28-2100-0000-02ba-7cee6f0d0000 pid=3439 execve guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440 /tmp/WTF net guuid=b3f9d66d-2000-0000-02ba-7cee130c0000 pid=3091->guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440 execve 1a2786df-91d9-5c63-a7db-fd7bd90e4df7 196.251.80.225:80 guuid=f6dc5c6e-2000-0000-02ba-7cee140c0000 pid=3092->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=0de46274-2000-0000-02ba-7cee220c0000 pid=3106->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=68a83581-2000-0000-02ba-7cee470c0000 pid=3143 /tmp/WTF guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138->guuid=68a83581-2000-0000-02ba-7cee470c0000 pid=3143 clone guuid=17b63f81-2000-0000-02ba-7cee480c0000 pid=3144 /tmp/WTF guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138->guuid=17b63f81-2000-0000-02ba-7cee480c0000 pid=3144 clone guuid=f52f4781-2000-0000-02ba-7cee490c0000 pid=3145 /tmp/WTF net zombie guuid=f16f6780-2000-0000-02ba-7cee420c0000 pid=3138->guuid=f52f4781-2000-0000-02ba-7cee490c0000 pid=3145 clone 4f8cff72-eb04-5a2e-a483-afec4b16493f 196.251.80.225:3778 guuid=f52f4781-2000-0000-02ba-7cee490c0000 pid=3145->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=5f575d81-2000-0000-02ba-7cee4a0c0000 pid=3146->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=a16aab85-2000-0000-02ba-7cee510c0000 pid=3153->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=25dbdd8e-2000-0000-02ba-7cee660c0000 pid=3174 /tmp/WTF guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173->guuid=25dbdd8e-2000-0000-02ba-7cee660c0000 pid=3174 clone guuid=0675e78e-2000-0000-02ba-7cee670c0000 pid=3175 /tmp/WTF guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173->guuid=0675e78e-2000-0000-02ba-7cee670c0000 pid=3175 clone guuid=7f31ed8e-2000-0000-02ba-7cee680c0000 pid=3176 /tmp/WTF net zombie guuid=0d91108e-2000-0000-02ba-7cee650c0000 pid=3173->guuid=7f31ed8e-2000-0000-02ba-7cee680c0000 pid=3176 clone guuid=7f31ed8e-2000-0000-02ba-7cee680c0000 pid=3176->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=3e21fd8e-2000-0000-02ba-7cee690c0000 pid=3177->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=83d1b493-2000-0000-02ba-7cee6d0c0000 pid=3181->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7882449b-2000-0000-02ba-7cee7c0c0000 pid=3196 /tmp/WTF guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195->guuid=7882449b-2000-0000-02ba-7cee7c0c0000 pid=3196 clone guuid=cd1b4b9b-2000-0000-02ba-7cee7d0c0000 pid=3197 /tmp/WTF guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195->guuid=cd1b4b9b-2000-0000-02ba-7cee7d0c0000 pid=3197 clone guuid=7f544e9b-2000-0000-02ba-7cee7e0c0000 pid=3198 /tmp/WTF net zombie guuid=97549b9a-2000-0000-02ba-7cee7b0c0000 pid=3195->guuid=7f544e9b-2000-0000-02ba-7cee7e0c0000 pid=3198 clone guuid=7f544e9b-2000-0000-02ba-7cee7e0c0000 pid=3198->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=4a425d9b-2000-0000-02ba-7cee7f0c0000 pid=3199->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=1435029e-2000-0000-02ba-7cee800c0000 pid=3200->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6beec2a5-2000-0000-02ba-7cee840c0000 pid=3204 /tmp/WTF guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203->guuid=6beec2a5-2000-0000-02ba-7cee840c0000 pid=3204 clone guuid=0f8edda5-2000-0000-02ba-7cee850c0000 pid=3205 /tmp/WTF guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203->guuid=0f8edda5-2000-0000-02ba-7cee850c0000 pid=3205 clone guuid=f5f4eba5-2000-0000-02ba-7cee860c0000 pid=3206 /tmp/WTF net zombie guuid=3ca013a4-2000-0000-02ba-7cee830c0000 pid=3203->guuid=f5f4eba5-2000-0000-02ba-7cee860c0000 pid=3206 clone guuid=f5f4eba5-2000-0000-02ba-7cee860c0000 pid=3206->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=f7460ea6-2000-0000-02ba-7cee870c0000 pid=3207->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=726eacaa-2000-0000-02ba-7cee880c0000 pid=3208->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=120b94b3-2000-0000-02ba-7cee920c0000 pid=3218 /tmp/WTF guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214->guuid=120b94b3-2000-0000-02ba-7cee920c0000 pid=3218 clone guuid=fb6497b3-2000-0000-02ba-7cee930c0000 pid=3219 /tmp/WTF guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214->guuid=fb6497b3-2000-0000-02ba-7cee930c0000 pid=3219 clone guuid=dc599eb3-2000-0000-02ba-7cee940c0000 pid=3220 /tmp/WTF net zombie guuid=46a5f9b2-2000-0000-02ba-7cee8e0c0000 pid=3214->guuid=dc599eb3-2000-0000-02ba-7cee940c0000 pid=3220 clone guuid=dc599eb3-2000-0000-02ba-7cee940c0000 pid=3220->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=2ba5aeb3-2000-0000-02ba-7cee950c0000 pid=3221->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 153B guuid=5f2faab6-2000-0000-02ba-7cee9a0c0000 pid=3226->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 102B guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e791e8bb-2000-0000-02ba-7ceeac0c0000 pid=3244 /tmp/WTF guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241->guuid=e791e8bb-2000-0000-02ba-7ceeac0c0000 pid=3244 clone guuid=3cd4ecbb-2000-0000-02ba-7ceead0c0000 pid=3245 /tmp/WTF guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241->guuid=3cd4ecbb-2000-0000-02ba-7ceead0c0000 pid=3245 clone guuid=937df6bb-2000-0000-02ba-7ceeae0c0000 pid=3246 /tmp/WTF net zombie guuid=46a84fbb-2000-0000-02ba-7ceea90c0000 pid=3241->guuid=937df6bb-2000-0000-02ba-7ceeae0c0000 pid=3246 clone guuid=937df6bb-2000-0000-02ba-7ceeae0c0000 pid=3246->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=4d0dffbb-2000-0000-02ba-7ceeaf0c0000 pid=3247->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=cddaedbf-2000-0000-02ba-7ceeb70c0000 pid=3255->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=17708ac8-2000-0000-02ba-7ceec00c0000 pid=3264 /tmp/WTF guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263->guuid=17708ac8-2000-0000-02ba-7ceec00c0000 pid=3264 clone guuid=4aba8ec8-2000-0000-02ba-7ceec10c0000 pid=3265 /tmp/WTF guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263->guuid=4aba8ec8-2000-0000-02ba-7ceec10c0000 pid=3265 clone guuid=4cf195c8-2000-0000-02ba-7ceec20c0000 pid=3266 /tmp/WTF net zombie guuid=7ea0bec7-2000-0000-02ba-7ceebf0c0000 pid=3263->guuid=4cf195c8-2000-0000-02ba-7ceec20c0000 pid=3266 clone guuid=4cf195c8-2000-0000-02ba-7ceec20c0000 pid=3266->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=f869a6c8-2000-0000-02ba-7ceec30c0000 pid=3267->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=175202ce-2000-0000-02ba-7ceec40c0000 pid=3268->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1bd40ad5-2000-0000-02ba-7ceec80c0000 pid=3272 /tmp/WTF guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271->guuid=1bd40ad5-2000-0000-02ba-7ceec80c0000 pid=3272 clone guuid=e56612d5-2000-0000-02ba-7ceec90c0000 pid=3273 /tmp/WTF guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271->guuid=e56612d5-2000-0000-02ba-7ceec90c0000 pid=3273 clone guuid=5b021ad5-2000-0000-02ba-7ceeca0c0000 pid=3274 /tmp/WTF net zombie guuid=849216d4-2000-0000-02ba-7ceec70c0000 pid=3271->guuid=5b021ad5-2000-0000-02ba-7ceeca0c0000 pid=3274 clone guuid=5b021ad5-2000-0000-02ba-7ceeca0c0000 pid=3274->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=a7ba30d5-2000-0000-02ba-7ceecb0c0000 pid=3275->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=c6b5c3d8-2000-0000-02ba-7ceecc0c0000 pid=3276->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5af964de-2000-0000-02ba-7ceed70c0000 pid=3287 /tmp/WTF guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286->guuid=5af964de-2000-0000-02ba-7ceed70c0000 pid=3287 clone guuid=119b69de-2000-0000-02ba-7ceed80c0000 pid=3288 /tmp/WTF guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286->guuid=119b69de-2000-0000-02ba-7ceed80c0000 pid=3288 clone guuid=e2e56cde-2000-0000-02ba-7ceed90c0000 pid=3289 /tmp/WTF net zombie guuid=a02bbddd-2000-0000-02ba-7ceed60c0000 pid=3286->guuid=e2e56cde-2000-0000-02ba-7ceed90c0000 pid=3289 clone guuid=e2e56cde-2000-0000-02ba-7ceed90c0000 pid=3289->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=49df78de-2000-0000-02ba-7ceeda0c0000 pid=3290->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=05804de3-2000-0000-02ba-7ceedb0c0000 pid=3291->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=598312ec-2000-0000-02ba-7ceeeb0c0000 pid=3307 /tmp/WTF guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304->guuid=598312ec-2000-0000-02ba-7ceeeb0c0000 pid=3307 clone guuid=700f18ec-2000-0000-02ba-7ceeec0c0000 pid=3308 /tmp/WTF guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304->guuid=700f18ec-2000-0000-02ba-7ceeec0c0000 pid=3308 clone guuid=d82b21ec-2000-0000-02ba-7ceeed0c0000 pid=3309 /tmp/WTF net zombie guuid=f40f39eb-2000-0000-02ba-7ceee80c0000 pid=3304->guuid=d82b21ec-2000-0000-02ba-7ceeed0c0000 pid=3309 clone guuid=d82b21ec-2000-0000-02ba-7ceeed0c0000 pid=3309->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=63352fec-2000-0000-02ba-7ceeee0c0000 pid=3310->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=7bb2e5f0-2000-0000-02ba-7ceef10c0000 pid=3313->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf95bbf8-2000-0000-02ba-7cee020d0000 pid=3330 /tmp/WTF guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327->guuid=cf95bbf8-2000-0000-02ba-7cee020d0000 pid=3330 clone guuid=3ed1c2f8-2000-0000-02ba-7cee030d0000 pid=3331 /tmp/WTF guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327->guuid=3ed1c2f8-2000-0000-02ba-7cee030d0000 pid=3331 clone guuid=f623c8f8-2000-0000-02ba-7cee040d0000 pid=3332 /tmp/WTF net zombie guuid=e050e1f7-2000-0000-02ba-7ceeff0c0000 pid=3327->guuid=f623c8f8-2000-0000-02ba-7cee040d0000 pid=3332 clone guuid=f623c8f8-2000-0000-02ba-7cee040d0000 pid=3332->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=0f31d4f8-2000-0000-02ba-7cee060d0000 pid=3334->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=384fd4fd-2000-0000-02ba-7cee0c0d0000 pid=3340->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=97d27006-2100-0000-02ba-7cee130d0000 pid=3347 /tmp/WTF guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346->guuid=97d27006-2100-0000-02ba-7cee130d0000 pid=3347 clone guuid=68fb7506-2100-0000-02ba-7cee140d0000 pid=3348 /tmp/WTF guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346->guuid=68fb7506-2100-0000-02ba-7cee140d0000 pid=3348 clone guuid=a5267a06-2100-0000-02ba-7cee150d0000 pid=3349 /tmp/WTF net zombie guuid=9812aa05-2100-0000-02ba-7cee120d0000 pid=3346->guuid=a5267a06-2100-0000-02ba-7cee150d0000 pid=3349 clone guuid=a5267a06-2100-0000-02ba-7cee150d0000 pid=3349->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=26479906-2100-0000-02ba-7cee160d0000 pid=3350->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=142f6309-2100-0000-02ba-7cee1d0d0000 pid=3357->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=69aec60e-2100-0000-02ba-7cee2e0d0000 pid=3374 /tmp/WTF guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373->guuid=69aec60e-2100-0000-02ba-7cee2e0d0000 pid=3374 clone guuid=7553ce0e-2100-0000-02ba-7cee2f0d0000 pid=3375 /tmp/WTF guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373->guuid=7553ce0e-2100-0000-02ba-7cee2f0d0000 pid=3375 clone guuid=bd30d40e-2100-0000-02ba-7cee300d0000 pid=3376 /tmp/WTF net zombie guuid=61b7fd0d-2100-0000-02ba-7cee2d0d0000 pid=3373->guuid=bd30d40e-2100-0000-02ba-7cee300d0000 pid=3376 clone guuid=bd30d40e-2100-0000-02ba-7cee300d0000 pid=3376->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=9809f10e-2100-0000-02ba-7cee310d0000 pid=3377->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 151B guuid=74893c14-2100-0000-02ba-7cee3d0d0000 pid=3389->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 100B guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c7a3081c-2100-0000-02ba-7cee500d0000 pid=3408 /tmp/WTF guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407->guuid=c7a3081c-2100-0000-02ba-7cee500d0000 pid=3408 clone guuid=81d70c1c-2100-0000-02ba-7cee510d0000 pid=3409 /tmp/WTF guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407->guuid=81d70c1c-2100-0000-02ba-7cee510d0000 pid=3409 clone guuid=634e111c-2100-0000-02ba-7cee520d0000 pid=3410 /tmp/WTF net zombie guuid=cd80481b-2100-0000-02ba-7cee4f0d0000 pid=3407->guuid=634e111c-2100-0000-02ba-7cee520d0000 pid=3410 clone guuid=634e111c-2100-0000-02ba-7cee520d0000 pid=3410->4f8cff72-eb04-5a2e-a483-afec4b16493f con guuid=849e271c-2100-0000-02ba-7cee530d0000 pid=3411->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 150B guuid=8b0d5721-2100-0000-02ba-7cee600d0000 pid=3424->1a2786df-91d9-5c63-a7db-fd7bd90e4df7 send: 99B guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=446bc129-2100-0000-02ba-7cee710d0000 pid=3441 /tmp/WTF guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440->guuid=446bc129-2100-0000-02ba-7cee710d0000 pid=3441 clone guuid=e2e9cb29-2100-0000-02ba-7cee720d0000 pid=3442 /tmp/WTF guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440->guuid=e2e9cb29-2100-0000-02ba-7cee720d0000 pid=3442 clone guuid=a27cd029-2100-0000-02ba-7cee730d0000 pid=3443 /tmp/WTF net zombie guuid=ca34b628-2100-0000-02ba-7cee700d0000 pid=3440->guuid=a27cd029-2100-0000-02ba-7cee730d0000 pid=3443 clone guuid=a27cd029-2100-0000-02ba-7cee730d0000 pid=3443->4f8cff72-eb04-5a2e-a483-afec4b16493f con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-10-02 12:10:56 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 489ee0930ca21690c07c770b01b60d35b9eaa46f4e20da92b7f8b5d533b49867

(this sample)

  
Delivery method
Distributed via web download

Comments