MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5e3f7ec55b3f15b049e594a50bc20e8b655d1b33fe74f120cff586f24e1970a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 5e3f7ec55b3f15b049e594a50bc20e8b655d1b33fe74f120cff586f24e1970a0
SHA3-384 hash: f91131a868b19c56f2d84b89fc68513cd4e79b900cdfeec412a1603430e40d796a3e79cf77c91a083280527ed4fe7faf
SHA1 hash: ceaa16f9073823811db0f4b27cbe3e15beed3d87
MD5 hash: 3c43534228b73697fe111a21e17ff0a5
humanhash: bulldog-speaker-football-sixteen
File name:i
Download: download sample
Signature Mirai
File size:4'856 bytes
First seen:2025-12-18 23:32:26 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 96:1xAPxH2lFcbpXH2dYHeE/ljaxBgHdXHGtCoXHssHK7H3THM:YR/XWdY+E/ljax2HdXmtXXMsq7XTs
TLSH T1E5A119D9787117B7CDE2AD28F615493F3046C2C49C76DFB4E45DB0BDB8ABD88A200945
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://158.94.208.162/z/89/mips1ef86f38b7e44a7511f09e4bec9a1da105e70db6d522467ac14b4ea42df632c9 Miraielf mirai ua-wget
http://158.94.208.162/z/89/mpslb3af651dbf2ffce881ed5539fcb7a3371f94f301eb4f7ac757d6aba63e5e1038 Miraielf mirai ua-wget
http://158.94.208.162/z/89/x86_649c033cf8304f0ed83cbba11c153b4fa29d766a90e57b1e8b715b9d25ef05ed76 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm4n/an/aelf ua-wget
http://158.94.208.162/z/89/arm571ecf29f0548ecb0051046067bf46b3966c596a554bde739db08900b38198918 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm628d8a15cfb38b9e56722fac60e7b53c84f53fcd678a62f67e82312be67b88bd7 Miraielf mirai ua-wget
http://158.94.208.162/z/89/arm78730e029d0f40e909494760198bd41b3a6aa44843a8968910cff20dea0fc35ca Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
53
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox medusa mirai virus
Verdict:
Malicious
File Type:
text
First seen:
2025-12-18T23:21:00Z UTC
Last seen:
2025-12-19T13:03:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=44b8897e-1900-0000-323b-e38a0a110000 pid=4362 /usr/bin/sudo guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374 /tmp/sample.bin guuid=44b8897e-1900-0000-323b-e38a0a110000 pid=4362->guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374 execve guuid=80f74081-1900-0000-323b-e38a19110000 pid=4377 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=80f74081-1900-0000-323b-e38a19110000 pid=4377 execve guuid=3d427582-1900-0000-323b-e38a1e110000 pid=4382 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=3d427582-1900-0000-323b-e38a1e110000 pid=4382 execve guuid=8d106883-1900-0000-323b-e38a23110000 pid=4387 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8d106883-1900-0000-323b-e38a23110000 pid=4387 execve guuid=07552591-1900-0000-323b-e38a53110000 pid=4435 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=07552591-1900-0000-323b-e38a53110000 pid=4435 execve guuid=76279f91-1900-0000-323b-e38a57110000 pid=4439 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=76279f91-1900-0000-323b-e38a57110000 pid=4439 clone guuid=85217292-1900-0000-323b-e38a5c110000 pid=4444 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=85217292-1900-0000-323b-e38a5c110000 pid=4444 execve guuid=f89f6294-1900-0000-323b-e38a65110000 pid=4453 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f89f6294-1900-0000-323b-e38a65110000 pid=4453 execve guuid=b84e7595-1900-0000-323b-e38a6b110000 pid=4459 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=b84e7595-1900-0000-323b-e38a6b110000 pid=4459 execve guuid=0f7bd7a2-1900-0000-323b-e38a9b110000 pid=4507 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0f7bd7a2-1900-0000-323b-e38a9b110000 pid=4507 execve guuid=4c0c0fa3-1900-0000-323b-e38a9c110000 pid=4508 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=4c0c0fa3-1900-0000-323b-e38a9c110000 pid=4508 clone guuid=b62a7fa3-1900-0000-323b-e38aa0110000 pid=4512 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=b62a7fa3-1900-0000-323b-e38aa0110000 pid=4512 execve guuid=b06619a4-1900-0000-323b-e38aa3110000 pid=4515 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=b06619a4-1900-0000-323b-e38aa3110000 pid=4515 execve guuid=7bd5b8a4-1900-0000-323b-e38aa6110000 pid=4518 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=7bd5b8a4-1900-0000-323b-e38aa6110000 pid=4518 execve guuid=ec6cb4b1-1900-0000-323b-e38ae6110000 pid=4582 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=ec6cb4b1-1900-0000-323b-e38ae6110000 pid=4582 execve guuid=bfc5efb1-1900-0000-323b-e38ae7110000 pid=4583 /tmp/x86_64 net guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bfc5efb1-1900-0000-323b-e38ae7110000 pid=4583 execve guuid=322616b2-1900-0000-323b-e38ae9110000 pid=4585 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=322616b2-1900-0000-323b-e38ae9110000 pid=4585 execve guuid=665e4fb3-1900-0000-323b-e38af0110000 pid=4592 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=665e4fb3-1900-0000-323b-e38af0110000 pid=4592 execve guuid=88a210b4-1900-0000-323b-e38af4110000 pid=4596 /usr/bin/wget net send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=88a210b4-1900-0000-323b-e38af4110000 pid=4596 execve guuid=e5eb28bb-1900-0000-323b-e38a14120000 pid=4628 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=e5eb28bb-1900-0000-323b-e38a14120000 pid=4628 execve guuid=340164bb-1900-0000-323b-e38a16120000 pid=4630 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=340164bb-1900-0000-323b-e38a16120000 pid=4630 clone guuid=7ce571bb-1900-0000-323b-e38a17120000 pid=4631 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=7ce571bb-1900-0000-323b-e38a17120000 pid=4631 execve guuid=95772dbc-1900-0000-323b-e38a1a120000 pid=4634 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=95772dbc-1900-0000-323b-e38a1a120000 pid=4634 execve guuid=bd6cd4bc-1900-0000-323b-e38a1d120000 pid=4637 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bd6cd4bc-1900-0000-323b-e38a1d120000 pid=4637 execve guuid=f3c6fbc6-1900-0000-323b-e38a48120000 pid=4680 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f3c6fbc6-1900-0000-323b-e38a48120000 pid=4680 execve guuid=550f56c7-1900-0000-323b-e38a4b120000 pid=4683 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=550f56c7-1900-0000-323b-e38a4b120000 pid=4683 clone guuid=b8901ac8-1900-0000-323b-e38a50120000 pid=4688 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=b8901ac8-1900-0000-323b-e38a50120000 pid=4688 execve guuid=4ad70fc9-1900-0000-323b-e38a54120000 pid=4692 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=4ad70fc9-1900-0000-323b-e38a54120000 pid=4692 execve guuid=359fefc9-1900-0000-323b-e38a58120000 pid=4696 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=359fefc9-1900-0000-323b-e38a58120000 pid=4696 execve guuid=1567b9d6-1900-0000-323b-e38a90120000 pid=4752 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1567b9d6-1900-0000-323b-e38a90120000 pid=4752 execve guuid=637ff4d6-1900-0000-323b-e38a91120000 pid=4753 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=637ff4d6-1900-0000-323b-e38a91120000 pid=4753 clone guuid=16587ad7-1900-0000-323b-e38a95120000 pid=4757 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=16587ad7-1900-0000-323b-e38a95120000 pid=4757 execve guuid=31de3cd8-1900-0000-323b-e38a99120000 pid=4761 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=31de3cd8-1900-0000-323b-e38a99120000 pid=4761 execve guuid=2b7fe3d8-1900-0000-323b-e38a9c120000 pid=4764 /usr/bin/wget net send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2b7fe3d8-1900-0000-323b-e38a9c120000 pid=4764 execve guuid=6d2f5be0-1900-0000-323b-e38ab8120000 pid=4792 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=6d2f5be0-1900-0000-323b-e38ab8120000 pid=4792 execve guuid=0837afe0-1900-0000-323b-e38aba120000 pid=4794 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0837afe0-1900-0000-323b-e38aba120000 pid=4794 clone guuid=7a7ac6e0-1900-0000-323b-e38abc120000 pid=4796 /usr/bin/rm delete-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=7a7ac6e0-1900-0000-323b-e38abc120000 pid=4796 execve guuid=47895de1-1900-0000-323b-e38abe120000 pid=4798 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=47895de1-1900-0000-323b-e38abe120000 pid=4798 execve guuid=5a5397e1-1900-0000-323b-e38abf120000 pid=4799 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=5a5397e1-1900-0000-323b-e38abf120000 pid=4799 execve guuid=8e7dd8e1-1900-0000-323b-e38ac2120000 pid=4802 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8e7dd8e1-1900-0000-323b-e38ac2120000 pid=4802 clone guuid=bf47f0e1-1900-0000-323b-e38ac3120000 pid=4803 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bf47f0e1-1900-0000-323b-e38ac3120000 pid=4803 execve guuid=d64e1ae2-1900-0000-323b-e38ac5120000 pid=4805 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d64e1ae2-1900-0000-323b-e38ac5120000 pid=4805 execve guuid=985c66e2-1900-0000-323b-e38ac7120000 pid=4807 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=985c66e2-1900-0000-323b-e38ac7120000 pid=4807 clone guuid=e80b75e2-1900-0000-323b-e38ac8120000 pid=4808 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=e80b75e2-1900-0000-323b-e38ac8120000 pid=4808 execve guuid=408a98e2-1900-0000-323b-e38ac9120000 pid=4809 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=408a98e2-1900-0000-323b-e38ac9120000 pid=4809 execve guuid=2cefd2e2-1900-0000-323b-e38acb120000 pid=4811 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2cefd2e2-1900-0000-323b-e38acb120000 pid=4811 clone guuid=77b9dce2-1900-0000-323b-e38acc120000 pid=4812 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=77b9dce2-1900-0000-323b-e38acc120000 pid=4812 execve guuid=ab54fbe2-1900-0000-323b-e38acd120000 pid=4813 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=ab54fbe2-1900-0000-323b-e38acd120000 pid=4813 execve guuid=844930e3-1900-0000-323b-e38acf120000 pid=4815 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=844930e3-1900-0000-323b-e38acf120000 pid=4815 clone guuid=a77e39e3-1900-0000-323b-e38ad0120000 pid=4816 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=a77e39e3-1900-0000-323b-e38ad0120000 pid=4816 execve guuid=ca6d5de3-1900-0000-323b-e38ad1120000 pid=4817 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=ca6d5de3-1900-0000-323b-e38ad1120000 pid=4817 execve guuid=f29c97e3-1900-0000-323b-e38ad3120000 pid=4819 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f29c97e3-1900-0000-323b-e38ad3120000 pid=4819 clone guuid=8954a2e3-1900-0000-323b-e38ad4120000 pid=4820 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8954a2e3-1900-0000-323b-e38ad4120000 pid=4820 execve guuid=df16c4e3-1900-0000-323b-e38ad5120000 pid=4821 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=df16c4e3-1900-0000-323b-e38ad5120000 pid=4821 execve guuid=1d60fae3-1900-0000-323b-e38ad7120000 pid=4823 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1d60fae3-1900-0000-323b-e38ad7120000 pid=4823 clone guuid=57e200e4-1900-0000-323b-e38ad8120000 pid=4824 /usr/bin/busybox guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=57e200e4-1900-0000-323b-e38ad8120000 pid=4824 execve guuid=a56521e4-1900-0000-323b-e38ada120000 pid=4826 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=a56521e4-1900-0000-323b-e38ada120000 pid=4826 execve guuid=d2ea57e4-1900-0000-323b-e38adc120000 pid=4828 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d2ea57e4-1900-0000-323b-e38adc120000 pid=4828 clone guuid=2b765fe4-1900-0000-323b-e38add120000 pid=4829 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2b765fe4-1900-0000-323b-e38add120000 pid=4829 execve guuid=d24c06e5-1900-0000-323b-e38ae1120000 pid=4833 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d24c06e5-1900-0000-323b-e38ae1120000 pid=4833 execve guuid=603fa7e5-1900-0000-323b-e38ae5120000 pid=4837 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=603fa7e5-1900-0000-323b-e38ae5120000 pid=4837 execve guuid=2a620af3-1900-0000-323b-e38a14130000 pid=4884 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2a620af3-1900-0000-323b-e38a14130000 pid=4884 execve guuid=7dc445f3-1900-0000-323b-e38a16130000 pid=4886 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=7dc445f3-1900-0000-323b-e38a16130000 pid=4886 clone guuid=a7e0cef3-1900-0000-323b-e38a1a130000 pid=4890 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=a7e0cef3-1900-0000-323b-e38a1a130000 pid=4890 execve guuid=e7de14f5-1900-0000-323b-e38a20130000 pid=4896 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=e7de14f5-1900-0000-323b-e38a20130000 pid=4896 execve guuid=144edef5-1900-0000-323b-e38a24130000 pid=4900 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=144edef5-1900-0000-323b-e38a24130000 pid=4900 execve guuid=1f52fa02-1a00-0000-323b-e38a4e130000 pid=4942 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1f52fa02-1a00-0000-323b-e38a4e130000 pid=4942 execve guuid=3ceb3d03-1a00-0000-323b-e38a50130000 pid=4944 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=3ceb3d03-1a00-0000-323b-e38a50130000 pid=4944 clone guuid=9e47d503-1a00-0000-323b-e38a54130000 pid=4948 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9e47d503-1a00-0000-323b-e38a54130000 pid=4948 execve guuid=9b5cbc04-1a00-0000-323b-e38a58130000 pid=4952 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9b5cbc04-1a00-0000-323b-e38a58130000 pid=4952 execve guuid=9e428d05-1a00-0000-323b-e38a5c130000 pid=4956 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9e428d05-1a00-0000-323b-e38a5c130000 pid=4956 execve guuid=27e34c13-1a00-0000-323b-e38a80130000 pid=4992 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=27e34c13-1a00-0000-323b-e38a80130000 pid=4992 execve guuid=cf31e313-1a00-0000-323b-e38a82130000 pid=4994 /tmp/x86_64 net guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=cf31e313-1a00-0000-323b-e38a82130000 pid=4994 execve guuid=31a84140-1b00-0000-323b-e38ab8140000 pid=5304 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=31a84140-1b00-0000-323b-e38ab8140000 pid=5304 execve guuid=2f78a342-1b00-0000-323b-e38ab9140000 pid=5305 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2f78a342-1b00-0000-323b-e38ab9140000 pid=5305 execve guuid=6c234d45-1b00-0000-323b-e38aba140000 pid=5306 /usr/bin/wget net send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=6c234d45-1b00-0000-323b-e38aba140000 pid=5306 execve guuid=bade9d4d-1b00-0000-323b-e38abb140000 pid=5307 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bade9d4d-1b00-0000-323b-e38abb140000 pid=5307 execve guuid=6b4d494e-1b00-0000-323b-e38abc140000 pid=5308 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=6b4d494e-1b00-0000-323b-e38abc140000 pid=5308 clone guuid=9b286b4e-1b00-0000-323b-e38abd140000 pid=5309 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9b286b4e-1b00-0000-323b-e38abd140000 pid=5309 execve guuid=edd67950-1b00-0000-323b-e38abe140000 pid=5310 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=edd67950-1b00-0000-323b-e38abe140000 pid=5310 execve guuid=bef98752-1b00-0000-323b-e38abf140000 pid=5311 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bef98752-1b00-0000-323b-e38abf140000 pid=5311 execve guuid=ceaa5e5e-1b00-0000-323b-e38ac0140000 pid=5312 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=ceaa5e5e-1b00-0000-323b-e38ac0140000 pid=5312 execve guuid=2773025f-1b00-0000-323b-e38ac1140000 pid=5313 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2773025f-1b00-0000-323b-e38ac1140000 pid=5313 clone guuid=1eff5060-1b00-0000-323b-e38ac3140000 pid=5315 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1eff5060-1b00-0000-323b-e38ac3140000 pid=5315 execve guuid=0de53c62-1b00-0000-323b-e38ac4140000 pid=5316 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0de53c62-1b00-0000-323b-e38ac4140000 pid=5316 execve guuid=f925ac63-1b00-0000-323b-e38ac5140000 pid=5317 /usr/bin/wget net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f925ac63-1b00-0000-323b-e38ac5140000 pid=5317 execve guuid=85ec5772-1b00-0000-323b-e38ac6140000 pid=5318 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=85ec5772-1b00-0000-323b-e38ac6140000 pid=5318 execve guuid=c85e0473-1b00-0000-323b-e38ac7140000 pid=5319 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=c85e0473-1b00-0000-323b-e38ac7140000 pid=5319 clone guuid=40255374-1b00-0000-323b-e38ac9140000 pid=5321 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=40255374-1b00-0000-323b-e38ac9140000 pid=5321 execve guuid=2c8a4476-1b00-0000-323b-e38aca140000 pid=5322 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2c8a4476-1b00-0000-323b-e38aca140000 pid=5322 execve guuid=3deeb977-1b00-0000-323b-e38acb140000 pid=5323 /usr/bin/wget net send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=3deeb977-1b00-0000-323b-e38acb140000 pid=5323 execve guuid=4a35a07f-1b00-0000-323b-e38acc140000 pid=5324 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=4a35a07f-1b00-0000-323b-e38acc140000 pid=5324 execve guuid=0a437c80-1b00-0000-323b-e38acd140000 pid=5325 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0a437c80-1b00-0000-323b-e38acd140000 pid=5325 clone guuid=76f6ac80-1b00-0000-323b-e38ace140000 pid=5326 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=76f6ac80-1b00-0000-323b-e38ace140000 pid=5326 execve guuid=4467b882-1b00-0000-323b-e38acf140000 pid=5327 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=4467b882-1b00-0000-323b-e38acf140000 pid=5327 execve guuid=bff88683-1b00-0000-323b-e38ad0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bff88683-1b00-0000-323b-e38ad0140000 pid=5328 execve guuid=acd7d497-1b00-0000-323b-e38ad1140000 pid=5329 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=acd7d497-1b00-0000-323b-e38ad1140000 pid=5329 execve guuid=eed95e98-1b00-0000-323b-e38ad2140000 pid=5330 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=eed95e98-1b00-0000-323b-e38ad2140000 pid=5330 clone guuid=7c07b499-1b00-0000-323b-e38ad4140000 pid=5332 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=7c07b499-1b00-0000-323b-e38ad4140000 pid=5332 execve guuid=c14bac9b-1b00-0000-323b-e38ad5140000 pid=5333 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=c14bac9b-1b00-0000-323b-e38ad5140000 pid=5333 execve guuid=178bd49e-1b00-0000-323b-e38ad6140000 pid=5334 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=178bd49e-1b00-0000-323b-e38ad6140000 pid=5334 execve guuid=8f2d76af-1b00-0000-323b-e38ad7140000 pid=5335 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8f2d76af-1b00-0000-323b-e38ad7140000 pid=5335 execve guuid=75f6beaf-1b00-0000-323b-e38ad8140000 pid=5336 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=75f6beaf-1b00-0000-323b-e38ad8140000 pid=5336 clone guuid=ef315eb0-1b00-0000-323b-e38ada140000 pid=5338 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=ef315eb0-1b00-0000-323b-e38ada140000 pid=5338 execve guuid=368d33b1-1b00-0000-323b-e38adb140000 pid=5339 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=368d33b1-1b00-0000-323b-e38adb140000 pid=5339 execve guuid=f1e2f9b1-1b00-0000-323b-e38adc140000 pid=5340 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f1e2f9b1-1b00-0000-323b-e38adc140000 pid=5340 execve guuid=22594cc0-1b00-0000-323b-e38add140000 pid=5341 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=22594cc0-1b00-0000-323b-e38add140000 pid=5341 execve guuid=0bba95c0-1b00-0000-323b-e38ade140000 pid=5342 /tmp/x86_64 net guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0bba95c0-1b00-0000-323b-e38ade140000 pid=5342 execve guuid=9678eeec-1c00-0000-323b-e38aed140000 pid=5357 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9678eeec-1c00-0000-323b-e38aed140000 pid=5357 execve guuid=1ce443ee-1c00-0000-323b-e38aee140000 pid=5358 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1ce443ee-1c00-0000-323b-e38aee140000 pid=5358 execve guuid=454fa1ef-1c00-0000-323b-e38aef140000 pid=5359 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=454fa1ef-1c00-0000-323b-e38aef140000 pid=5359 execve guuid=9db131f9-1c00-0000-323b-e38af7140000 pid=5367 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=9db131f9-1c00-0000-323b-e38af7140000 pid=5367 execve guuid=1aecc0f9-1c00-0000-323b-e38af8140000 pid=5368 /tmp/arm4 guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1aecc0f9-1c00-0000-323b-e38af8140000 pid=5368 execve guuid=39a03ffa-1c00-0000-323b-e38af9140000 pid=5369 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=39a03ffa-1c00-0000-323b-e38af9140000 pid=5369 execve guuid=353087fb-1c00-0000-323b-e38afa140000 pid=5370 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=353087fb-1c00-0000-323b-e38afa140000 pid=5370 execve guuid=0e0acefc-1c00-0000-323b-e38afb140000 pid=5371 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0e0acefc-1c00-0000-323b-e38afb140000 pid=5371 execve guuid=5887f808-1d00-0000-323b-e38afc140000 pid=5372 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=5887f808-1d00-0000-323b-e38afc140000 pid=5372 execve guuid=65657009-1d00-0000-323b-e38afd140000 pid=5373 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=65657009-1d00-0000-323b-e38afd140000 pid=5373 clone guuid=1eb7480a-1d00-0000-323b-e38aff140000 pid=5375 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=1eb7480a-1d00-0000-323b-e38aff140000 pid=5375 execve guuid=beb9820b-1d00-0000-323b-e38a00150000 pid=5376 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=beb9820b-1d00-0000-323b-e38a00150000 pid=5376 execve guuid=abbaf40c-1d00-0000-323b-e38a01150000 pid=5377 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=abbaf40c-1d00-0000-323b-e38a01150000 pid=5377 execve guuid=11d2b11c-1d00-0000-323b-e38a03150000 pid=5379 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=11d2b11c-1d00-0000-323b-e38a03150000 pid=5379 execve guuid=cab21b1d-1d00-0000-323b-e38a04150000 pid=5380 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=cab21b1d-1d00-0000-323b-e38a04150000 pid=5380 clone guuid=4a23001e-1d00-0000-323b-e38a06150000 pid=5382 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=4a23001e-1d00-0000-323b-e38a06150000 pid=5382 execve guuid=46f8851f-1d00-0000-323b-e38a07150000 pid=5383 /usr/bin/killall guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=46f8851f-1d00-0000-323b-e38a07150000 pid=5383 execve guuid=34263820-1d00-0000-323b-e38a09150000 pid=5385 /usr/bin/curl net send-data write-file guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=34263820-1d00-0000-323b-e38a09150000 pid=5385 execve guuid=3a157c28-1d00-0000-323b-e38a0b150000 pid=5387 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=3a157c28-1d00-0000-323b-e38a0b150000 pid=5387 execve guuid=0691bb28-1d00-0000-323b-e38a0c150000 pid=5388 /tmp/arm7 guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=0691bb28-1d00-0000-323b-e38a0c150000 pid=5388 execve guuid=84a8f328-1d00-0000-323b-e38a0d150000 pid=5389 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=84a8f328-1d00-0000-323b-e38a0d150000 pid=5389 clone guuid=bbbe0329-1d00-0000-323b-e38a0e150000 pid=5390 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bbbe0329-1d00-0000-323b-e38a0e150000 pid=5390 execve guuid=5da23f29-1d00-0000-323b-e38a0f150000 pid=5391 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=5da23f29-1d00-0000-323b-e38a0f150000 pid=5391 clone guuid=2d0dc129-1d00-0000-323b-e38a11150000 pid=5393 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=2d0dc129-1d00-0000-323b-e38a11150000 pid=5393 clone guuid=81afd229-1d00-0000-323b-e38a12150000 pid=5394 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=81afd229-1d00-0000-323b-e38a12150000 pid=5394 execve guuid=8870082a-1d00-0000-323b-e38a13150000 pid=5395 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8870082a-1d00-0000-323b-e38a13150000 pid=5395 clone guuid=d8189b2a-1d00-0000-323b-e38a15150000 pid=5397 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d8189b2a-1d00-0000-323b-e38a15150000 pid=5397 clone guuid=050da02a-1d00-0000-323b-e38a16150000 pid=5398 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=050da02a-1d00-0000-323b-e38a16150000 pid=5398 execve guuid=25c8d02a-1d00-0000-323b-e38a17150000 pid=5399 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=25c8d02a-1d00-0000-323b-e38a17150000 pid=5399 clone guuid=fc81d52a-1d00-0000-323b-e38a18150000 pid=5400 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=fc81d52a-1d00-0000-323b-e38a18150000 pid=5400 clone guuid=d6acda2a-1d00-0000-323b-e38a19150000 pid=5401 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d6acda2a-1d00-0000-323b-e38a19150000 pid=5401 execve guuid=380b1a2b-1d00-0000-323b-e38a1a150000 pid=5402 /tmp/arm4 guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=380b1a2b-1d00-0000-323b-e38a1a150000 pid=5402 execve guuid=367a572b-1d00-0000-323b-e38a1b150000 pid=5403 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=367a572b-1d00-0000-323b-e38a1b150000 pid=5403 clone guuid=e4dd5c2b-1d00-0000-323b-e38a1c150000 pid=5404 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=e4dd5c2b-1d00-0000-323b-e38a1c150000 pid=5404 execve guuid=099c982b-1d00-0000-323b-e38a1d150000 pid=5405 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=099c982b-1d00-0000-323b-e38a1d150000 pid=5405 clone guuid=23f3382c-1d00-0000-323b-e38a1f150000 pid=5407 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=23f3382c-1d00-0000-323b-e38a1f150000 pid=5407 clone guuid=cde44b2c-1d00-0000-323b-e38a20150000 pid=5408 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=cde44b2c-1d00-0000-323b-e38a20150000 pid=5408 execve guuid=f974c72c-1d00-0000-323b-e38a21150000 pid=5409 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f974c72c-1d00-0000-323b-e38a21150000 pid=5409 clone guuid=8341592d-1d00-0000-323b-e38a23150000 pid=5411 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=8341592d-1d00-0000-323b-e38a23150000 pid=5411 clone guuid=d99a772d-1d00-0000-323b-e38a24150000 pid=5412 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=d99a772d-1d00-0000-323b-e38a24150000 pid=5412 execve guuid=aa9bec2d-1d00-0000-323b-e38a25150000 pid=5413 /tmp/arm7 guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=aa9bec2d-1d00-0000-323b-e38a25150000 pid=5413 execve guuid=3daa1d2e-1d00-0000-323b-e38a26150000 pid=5414 /usr/bin/busybox send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=3daa1d2e-1d00-0000-323b-e38a26150000 pid=5414 execve guuid=bd66c836-2000-0000-323b-e38a37150000 pid=5431 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=bd66c836-2000-0000-323b-e38a37150000 pid=5431 execve guuid=866c5c37-2000-0000-323b-e38a38150000 pid=5432 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=866c5c37-2000-0000-323b-e38a38150000 pid=5432 clone guuid=61797c38-2000-0000-323b-e38a3a150000 pid=5434 /usr/bin/busybox send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=61797c38-2000-0000-323b-e38a3a150000 pid=5434 execve guuid=a5f7093c-2300-0000-323b-e38a3b150000 pid=5435 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=a5f7093c-2300-0000-323b-e38a3b150000 pid=5435 execve guuid=f82a9d3c-2300-0000-323b-e38a3c150000 pid=5436 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=f82a9d3c-2300-0000-323b-e38a3c150000 pid=5436 clone guuid=fba6b33d-2300-0000-323b-e38a3e150000 pid=5438 /usr/bin/busybox send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=fba6b33d-2300-0000-323b-e38a3e150000 pid=5438 execve guuid=56382741-2600-0000-323b-e38a3f150000 pid=5439 /usr/bin/chmod guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=56382741-2600-0000-323b-e38a3f150000 pid=5439 execve guuid=e814b141-2600-0000-323b-e38a40150000 pid=5440 /usr/bin/dash guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=e814b141-2600-0000-323b-e38a40150000 pid=5440 clone guuid=48c3ce41-2600-0000-323b-e38a41150000 pid=5441 /usr/bin/busybox send-data guuid=74ef0081-1900-0000-323b-e38a16110000 pid=4374->guuid=48c3ce41-2600-0000-323b-e38a41150000 pid=5441 execve dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 158.94.208.162:80 guuid=8d106883-1900-0000-323b-e38a23110000 pid=4387->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=b84e7595-1900-0000-323b-e38a6b110000 pid=4459->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=7bd5b8a4-1900-0000-323b-e38aa6110000 pid=4518->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 140B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=bfc5efb1-1900-0000-323b-e38ae7110000 pid=4583->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584 /tmp/ dns net send-data zombie guuid=bfc5efb1-1900-0000-323b-e38ae7110000 pid=4583->guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584 clone guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 997a677b-e2e3-587d-b712-9bb3900e9b02 51.158.108.203:53 guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584->997a677b-e2e3-587d-b712-9bb3900e9b02 send: 29B 84a380bc-aa57-5600-87c1-ca531ceab881 80.152.203.134:53 guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584->84a380bc-aa57-5600-87c1-ca531ceab881 send: 30B b7f22dff-36ca-56fe-b940-e18740a057c3 bunnybots.ru:38241 guuid=b1630db2-1900-0000-323b-e38ae8110000 pid=4584->b7f22dff-36ca-56fe-b940-e18740a057c3 send: 10B guuid=88a210b4-1900-0000-323b-e38af4110000 pid=4596->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=bd6cd4bc-1900-0000-323b-e38a1d120000 pid=4637->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=359fefc9-1900-0000-323b-e38a58120000 pid=4696->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=2b7fe3d8-1900-0000-323b-e38a9c120000 pid=4764->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=603fa7e5-1900-0000-323b-e38ae5120000 pid=4837->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=144edef5-1900-0000-323b-e38a24130000 pid=4900->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=9e428d05-1a00-0000-323b-e38a5c130000 pid=4956->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 140B guuid=cf31e313-1a00-0000-323b-e38a82130000 pid=4994->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 92cfe373-e651-503a-911e-5935bcf3745c 0.0.0.0:2353 guuid=cf31e313-1a00-0000-323b-e38a82130000 pid=4994->92cfe373-e651-503a-911e-5935bcf3745c con guuid=cd561940-1b00-0000-323b-e38ab7140000 pid=5303 /tmp/ dns net send-data zombie guuid=cf31e313-1a00-0000-323b-e38a82130000 pid=4994->guuid=cd561940-1b00-0000-323b-e38ab7140000 pid=5303 clone guuid=cd561940-1b00-0000-323b-e38ab7140000 pid=5303->b7f22dff-36ca-56fe-b940-e18740a057c3 con 8dc3cbf0-e657-54a9-b6da-3abe058dcf2a 5.161.109.23:53 guuid=cd561940-1b00-0000-323b-e38ab7140000 pid=5303->8dc3cbf0-e657-54a9-b6da-3abe058dcf2a send: 30B e7e3f3be-4c6e-5491-b4cf-189f3e7a0301 65.21.1.106:53 guuid=cd561940-1b00-0000-323b-e38ab7140000 pid=5303->e7e3f3be-4c6e-5491-b4cf-189f3e7a0301 send: 30B guuid=6c234d45-1b00-0000-323b-e38aba140000 pid=5306->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=bef98752-1b00-0000-323b-e38abf140000 pid=5311->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=f925ac63-1b00-0000-323b-e38ac5140000 pid=5317->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=3deeb977-1b00-0000-323b-e38acb140000 pid=5323->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 138B guuid=bff88683-1b00-0000-323b-e38ad0140000 pid=5328->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B guuid=178bd49e-1b00-0000-323b-e38ad6140000 pid=5334->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B guuid=f1e2f9b1-1b00-0000-323b-e38adc140000 pid=5340->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 89B guuid=0bba95c0-1b00-0000-323b-e38ade140000 pid=5342->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0bba95c0-1b00-0000-323b-e38ade140000 pid=5342->92cfe373-e651-503a-911e-5935bcf3745c con guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356 /tmp/ dns net send-data zombie guuid=0bba95c0-1b00-0000-323b-e38ade140000 pid=5342->guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356 clone guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356->b7f22dff-36ca-56fe-b940-e18740a057c3 send: 12B 290f2f6d-9b03-5a51-9b59-33627a07e20d 137.220.52.23:53 guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356->290f2f6d-9b03-5a51-9b59-33627a07e20d send: 30B c0b60401-2787-5e57-85f9-7652823a4a8e 70.34.254.19:53 guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356->c0b60401-2787-5e57-85f9-7652823a4a8e send: 30B 69e3eade-acae-5a5a-b527-3b224017b69e 168.235.111.72:53 guuid=99c9deec-1c00-0000-323b-e38aec140000 pid=5356->69e3eade-acae-5a5a-b527-3b224017b69e send: 30B guuid=454fa1ef-1c00-0000-323b-e38aef140000 pid=5359->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B guuid=0e0acefc-1c00-0000-323b-e38afb140000 pid=5371->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B guuid=abbaf40c-1d00-0000-323b-e38a01150000 pid=5377->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B guuid=34263820-1d00-0000-323b-e38a09150000 pid=5385->dc5c0a7c-6cb2-5901-a16c-cfb107bab3b5 send: 87B 6d6ff507-7a25-59af-a0f6-df3bb6fc076a 0.0.0.69:69 guuid=3daa1d2e-1d00-0000-323b-e38a26150000 pid=5414->6d6ff507-7a25-59af-a0f6-df3bb6fc076a send: 492B guuid=61797c38-2000-0000-323b-e38a3a150000 pid=5434->6d6ff507-7a25-59af-a0f6-df3bb6fc076a send: 492B guuid=fba6b33d-2300-0000-323b-e38a3e150000 pid=5438->6d6ff507-7a25-59af-a0f6-df3bb6fc076a send: 516B guuid=48c3ce41-2600-0000-323b-e38a41150000 pid=5441->6d6ff507-7a25-59af-a0f6-df3bb6fc076a send: 369B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-12-19 00:10:55 UTC
File Type:
Text (Shell)
AV detection:
12 of 24 (50.00%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 5e3f7ec55b3f15b049e594a50bc20e8b655d1b33fe74f120cff586f24e1970a0

(this sample)

  
Delivery method
Distributed via web download

Comments