MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 757de8284ef3595bea3dbcecb1effca1a7593ba33b4f1fdfe7bdcf28b8e3a315. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 2 File information Comments

SHA256 hash: 757de8284ef3595bea3dbcecb1effca1a7593ba33b4f1fdfe7bdcf28b8e3a315
SHA3-384 hash: c1804ea2de8b7363579d459e4a0f10c361901743f69034c5f05ed622a0b3bfdee14057b98030104cdfa091e699354de4
SHA1 hash: 55ad948bdb23eb6826325e9e266ddfa13604cf5f
MD5 hash: 4a00c198153af6a22e57c09f488b9747
humanhash: lemon-mars-spring-friend
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2026-03-31 12:13:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp47047N7hp4v46Gp4gn4zPp4f4KWp414oUp47147o7Up4fO43bp4E49Rp4h4cgJ:vq7/7N7hqw6Gqg4zPqgKWqeoUq7e7o7U
TLSH T1925182C592856D326CB7FA23F6B6C128308190935CEA7F99DDD8BFE4868ED247240753
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.96/hiddenbin/boatnet.x866638c6aae5f21777821af608664aa93598dad45dd84510045f8aa20b7ea8f71d Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.mips45894380e529a897d0f9b04071efbec44d86940cef1923df015deedc350746e0 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.arcn/an/aelf ua-wget
http://176.65.139.96/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://176.65.139.96/hiddenbin/boatnet.i68681624654cd84695cb1c881a0c5eec8ec6d7e2df2d515f9ffb08c72e522a64a69 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.x86_64a55f39dc610ec4dd3918dbba2997644d710ae61c2c5bc1e987b5e64a6db82baa Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.mpslcf4a7efd5a9eef3fa50ba1463aa7ffef36548c11486c76b43b90a83ae304d29d Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.arm9779011a3f6b3fd45fc0fac60aad08cf3db37689ac3a5595c4d2a725b8d99e53 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.arm5114e5ec5f210360cc42fcad1595665a43a3af92e537d47ef902ade871b8ac200 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.arm6d04a50371f6a9b25d19475bc8455997d2a2ce339534373439ebe04220df3eecc Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.arm7d619e3024f32eddf2054b7198d8820d5d2dd5c12d27920150317d13f75ee3c4e Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.ppc782606738079703fc7ae546f5cd5904e530e318d19a48e4a64309a93c4c623d0 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.spc32ace463b3ef724a87ad97fa7dd17a6578981cf060595fc092bb089692c04ce7 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.m68k78471120e4d5bd409a59d2f12d1f7c5cea94c1f818fd92db8d3bf5647ebc5da2 Miraielf mirai ua-wget
http://176.65.139.96/hiddenbin/boatnet.sh40253355d66c4f314ddb4b5a15b7b1dc205f2c9fd7852319fe5b84b54f98ef93b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
49
Origin country :
GB GB
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-30T15:25:00Z UTC
Last seen:
2026-03-31T11:45:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=54ec9d7f-1b00-0000-5413-8bb5920c0000 pid=3218 /usr/bin/sudo guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219 /tmp/sample.bin guuid=54ec9d7f-1b00-0000-5413-8bb5920c0000 pid=3218->guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219 execve guuid=afcf3883-1b00-0000-5413-8bb5940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=afcf3883-1b00-0000-5413-8bb5940c0000 pid=3220 execve guuid=0a601489-1b00-0000-5413-8bb5950c0000 pid=3221 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=0a601489-1b00-0000-5413-8bb5950c0000 pid=3221 execve guuid=e57de394-1b00-0000-5413-8bb5a60c0000 pid=3238 /usr/bin/cat guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=e57de394-1b00-0000-5413-8bb5a60c0000 pid=3238 execve guuid=0eb74d95-1b00-0000-5413-8bb5a80c0000 pid=3240 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=0eb74d95-1b00-0000-5413-8bb5a80c0000 pid=3240 execve guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242 execve guuid=55aa1196-1b00-0000-5413-8bb5af0c0000 pid=3247 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=55aa1196-1b00-0000-5413-8bb5af0c0000 pid=3247 execve guuid=0b2f359a-1b00-0000-5413-8bb5b20c0000 pid=3250 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=0b2f359a-1b00-0000-5413-8bb5b20c0000 pid=3250 execve guuid=343fff9e-1b00-0000-5413-8bb5b30c0000 pid=3251 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=343fff9e-1b00-0000-5413-8bb5b30c0000 pid=3251 clone guuid=d385219f-1b00-0000-5413-8bb5b40c0000 pid=3252 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=d385219f-1b00-0000-5413-8bb5b40c0000 pid=3252 execve guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254 execve guuid=9789e89f-1b00-0000-5413-8bb5ba0c0000 pid=3258 /usr/bin/wget net send-data guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=9789e89f-1b00-0000-5413-8bb5ba0c0000 pid=3258 execve guuid=e7ac06a4-1b00-0000-5413-8bb5c20c0000 pid=3266 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=e7ac06a4-1b00-0000-5413-8bb5c20c0000 pid=3266 execve guuid=48aebda9-1b00-0000-5413-8bb5ca0c0000 pid=3274 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=48aebda9-1b00-0000-5413-8bb5ca0c0000 pid=3274 clone guuid=b109dba9-1b00-0000-5413-8bb5cb0c0000 pid=3275 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=b109dba9-1b00-0000-5413-8bb5cb0c0000 pid=3275 execve guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276 execve guuid=e08a8aaa-1b00-0000-5413-8bb5d00c0000 pid=3280 /usr/bin/wget net send-data guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=e08a8aaa-1b00-0000-5413-8bb5d00c0000 pid=3280 execve guuid=d56360ad-1b00-0000-5413-8bb5d70c0000 pid=3287 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=d56360ad-1b00-0000-5413-8bb5d70c0000 pid=3287 execve guuid=94cfe5b4-1b00-0000-5413-8bb5e10c0000 pid=3297 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=94cfe5b4-1b00-0000-5413-8bb5e10c0000 pid=3297 clone guuid=7d7c04b5-1b00-0000-5413-8bb5e20c0000 pid=3298 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=7d7c04b5-1b00-0000-5413-8bb5e20c0000 pid=3298 execve guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300 execve guuid=717f95b5-1b00-0000-5413-8bb5e90c0000 pid=3305 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=717f95b5-1b00-0000-5413-8bb5e90c0000 pid=3305 execve guuid=033a39b9-1b00-0000-5413-8bb5f20c0000 pid=3314 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=033a39b9-1b00-0000-5413-8bb5f20c0000 pid=3314 execve guuid=44dc24bf-1b00-0000-5413-8bb5fe0c0000 pid=3326 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=44dc24bf-1b00-0000-5413-8bb5fe0c0000 pid=3326 clone guuid=d81c4abf-1b00-0000-5413-8bb5ff0c0000 pid=3327 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=d81c4abf-1b00-0000-5413-8bb5ff0c0000 pid=3327 execve guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329 execve guuid=5b1809c0-1b00-0000-5413-8bb5060d0000 pid=3334 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=5b1809c0-1b00-0000-5413-8bb5060d0000 pid=3334 execve guuid=a3f7c4c3-1b00-0000-5413-8bb5110d0000 pid=3345 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=a3f7c4c3-1b00-0000-5413-8bb5110d0000 pid=3345 execve guuid=e6fa45cb-1b00-0000-5413-8bb5210d0000 pid=3361 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=e6fa45cb-1b00-0000-5413-8bb5210d0000 pid=3361 clone guuid=1eb26bcb-1b00-0000-5413-8bb5230d0000 pid=3363 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=1eb26bcb-1b00-0000-5413-8bb5230d0000 pid=3363 execve guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364 execve guuid=75e31dcc-1b00-0000-5413-8bb5290d0000 pid=3369 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=75e31dcc-1b00-0000-5413-8bb5290d0000 pid=3369 execve guuid=20f952d0-1b00-0000-5413-8bb5320d0000 pid=3378 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=20f952d0-1b00-0000-5413-8bb5320d0000 pid=3378 execve guuid=4e7010d7-1b00-0000-5413-8bb53b0d0000 pid=3387 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=4e7010d7-1b00-0000-5413-8bb53b0d0000 pid=3387 clone guuid=ade335d7-1b00-0000-5413-8bb53d0d0000 pid=3389 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=ade335d7-1b00-0000-5413-8bb53d0d0000 pid=3389 execve guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390 execve guuid=d3fd2cd8-1b00-0000-5413-8bb5440d0000 pid=3396 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=d3fd2cd8-1b00-0000-5413-8bb5440d0000 pid=3396 execve guuid=ff5814dc-1b00-0000-5413-8bb54b0d0000 pid=3403 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=ff5814dc-1b00-0000-5413-8bb54b0d0000 pid=3403 execve guuid=2a57f9e3-1b00-0000-5413-8bb55a0d0000 pid=3418 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=2a57f9e3-1b00-0000-5413-8bb55a0d0000 pid=3418 clone guuid=6c5416e4-1b00-0000-5413-8bb55b0d0000 pid=3419 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=6c5416e4-1b00-0000-5413-8bb55b0d0000 pid=3419 execve guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421 execve guuid=00ed08e5-1b00-0000-5413-8bb5630d0000 pid=3427 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=00ed08e5-1b00-0000-5413-8bb5630d0000 pid=3427 execve guuid=7b6ca5e8-1b00-0000-5413-8bb56a0d0000 pid=3434 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=7b6ca5e8-1b00-0000-5413-8bb56a0d0000 pid=3434 execve guuid=27fa0aed-1b00-0000-5413-8bb56d0d0000 pid=3437 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=27fa0aed-1b00-0000-5413-8bb56d0d0000 pid=3437 clone guuid=40792aed-1b00-0000-5413-8bb56e0d0000 pid=3438 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=40792aed-1b00-0000-5413-8bb56e0d0000 pid=3438 execve guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439 execve guuid=f302d9ed-1b00-0000-5413-8bb5740d0000 pid=3444 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=f302d9ed-1b00-0000-5413-8bb5740d0000 pid=3444 execve guuid=3efea40f-1c00-0000-5413-8bb57f0d0000 pid=3455 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=3efea40f-1c00-0000-5413-8bb57f0d0000 pid=3455 execve guuid=f023e919-1c00-0000-5413-8bb58d0d0000 pid=3469 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=f023e919-1c00-0000-5413-8bb58d0d0000 pid=3469 clone guuid=88266c1a-1c00-0000-5413-8bb58e0d0000 pid=3470 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=88266c1a-1c00-0000-5413-8bb58e0d0000 pid=3470 execve guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480 execve guuid=30612a20-1c00-0000-5413-8bb5a40d0000 pid=3492 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=30612a20-1c00-0000-5413-8bb5a40d0000 pid=3492 execve guuid=e7f2c62e-1c00-0000-5413-8bb5c30d0000 pid=3523 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=e7f2c62e-1c00-0000-5413-8bb5c30d0000 pid=3523 execve guuid=784a1a4e-1c00-0000-5413-8bb5fc0d0000 pid=3580 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=784a1a4e-1c00-0000-5413-8bb5fc0d0000 pid=3580 clone guuid=3c3e5a4f-1c00-0000-5413-8bb5000e0000 pid=3584 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=3c3e5a4f-1c00-0000-5413-8bb5000e0000 pid=3584 execve guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589 execve guuid=6441da51-1c00-0000-5413-8bb50a0e0000 pid=3594 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=6441da51-1c00-0000-5413-8bb50a0e0000 pid=3594 execve guuid=419e105b-1c00-0000-5413-8bb50f0e0000 pid=3599 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=419e105b-1c00-0000-5413-8bb50f0e0000 pid=3599 execve guuid=ec4c4a73-1c00-0000-5413-8bb51d0e0000 pid=3613 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=ec4c4a73-1c00-0000-5413-8bb51d0e0000 pid=3613 clone guuid=f0ef6073-1c00-0000-5413-8bb51e0e0000 pid=3614 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=f0ef6073-1c00-0000-5413-8bb51e0e0000 pid=3614 execve guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615 execve guuid=2bf8e473-1c00-0000-5413-8bb5230e0000 pid=3619 /usr/bin/wget net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=2bf8e473-1c00-0000-5413-8bb5230e0000 pid=3619 execve guuid=28461c86-1c00-0000-5413-8bb5240e0000 pid=3620 /usr/bin/curl net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=28461c86-1c00-0000-5413-8bb5240e0000 pid=3620 execve guuid=5d5f7999-1c00-0000-5413-8bb5270e0000 pid=3623 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=5d5f7999-1c00-0000-5413-8bb5270e0000 pid=3623 clone guuid=7b12419a-1c00-0000-5413-8bb5280e0000 pid=3624 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=7b12419a-1c00-0000-5413-8bb5280e0000 pid=3624 execve guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625 execve guuid=022a0d9c-1c00-0000-5413-8bb52d0e0000 pid=3629 /usr/bin/wget net send-data guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=022a0d9c-1c00-0000-5413-8bb52d0e0000 pid=3629 execve guuid=b4c104aa-1c00-0000-5413-8bb5330e0000 pid=3635 /usr/bin/bash net send-data write-file guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=b4c104aa-1c00-0000-5413-8bb5330e0000 pid=3635 clone guuid=ea34cabe-1c00-0000-5413-8bb5450e0000 pid=3653 /usr/bin/bash guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=ea34cabe-1c00-0000-5413-8bb5450e0000 pid=3653 clone guuid=ba04e5be-1c00-0000-5413-8bb5460e0000 pid=3654 /usr/bin/chmod guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=ba04e5be-1c00-0000-5413-8bb5460e0000 pid=3654 execve guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655 /tmp/WTF net guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655 execve guuid=017374bf-1c00-0000-5413-8bb54b0e0000 pid=3659 /usr/bin/wget guuid=cfd22682-1b00-0000-5413-8bb5930c0000 pid=3219->guuid=017374bf-1c00-0000-5413-8bb54b0e0000 pid=3659 execve 33673a35-8f08-5aeb-b365-8b166da6f7f7 176.65.139.96:80 guuid=afcf3883-1b00-0000-5413-8bb5940c0000 pid=3220->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 149B guuid=0a601489-1b00-0000-5413-8bb5950c0000 pid=3221->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c085f395-1b00-0000-5413-8bb5ab0c0000 pid=3243 /tmp/WTF guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242->guuid=c085f395-1b00-0000-5413-8bb5ab0c0000 pid=3243 clone guuid=ddbafb95-1b00-0000-5413-8bb5ac0c0000 pid=3244 /tmp/WTF guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242->guuid=ddbafb95-1b00-0000-5413-8bb5ac0c0000 pid=3244 clone guuid=0d3a0296-1b00-0000-5413-8bb5ad0c0000 pid=3245 /tmp/WTF net send-data zombie guuid=0915a995-1b00-0000-5413-8bb5aa0c0000 pid=3242->guuid=0d3a0296-1b00-0000-5413-8bb5ad0c0000 pid=3245 clone guuid=0d3a0296-1b00-0000-5413-8bb5ad0c0000 pid=3245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 5ab2dab8-4725-502a-8ff3-47b656dd5b7d 176.65.139.96:3778 guuid=0d3a0296-1b00-0000-5413-8bb5ad0c0000 pid=3245->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=38a1d3ed-1b00-0000-5413-8bb5730d0000 pid=3443 /tmp/WTF net send-data guuid=0d3a0296-1b00-0000-5413-8bb5ad0c0000 pid=3245->guuid=38a1d3ed-1b00-0000-5413-8bb5730d0000 pid=3443 clone guuid=55aa1196-1b00-0000-5413-8bb5af0c0000 pid=3247->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=0b2f359a-1b00-0000-5413-8bb5b20c0000 pid=3250->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ecd1cc9f-1b00-0000-5413-8bb5b70c0000 pid=3255 /tmp/WTF guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254->guuid=ecd1cc9f-1b00-0000-5413-8bb5b70c0000 pid=3255 clone guuid=b75ad29f-1b00-0000-5413-8bb5b80c0000 pid=3256 /tmp/WTF guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254->guuid=b75ad29f-1b00-0000-5413-8bb5b80c0000 pid=3256 clone guuid=190ad89f-1b00-0000-5413-8bb5b90c0000 pid=3257 /tmp/WTF net send-data zombie guuid=86918b9f-1b00-0000-5413-8bb5b60c0000 pid=3254->guuid=190ad89f-1b00-0000-5413-8bb5b90c0000 pid=3257 clone guuid=190ad89f-1b00-0000-5413-8bb5b90c0000 pid=3257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=190ad89f-1b00-0000-5413-8bb5b90c0000 pid=3257->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=c40ee1ef-1b00-0000-5413-8bb5770d0000 pid=3447 /tmp/WTF net send-data guuid=190ad89f-1b00-0000-5413-8bb5b90c0000 pid=3257->guuid=c40ee1ef-1b00-0000-5413-8bb5770d0000 pid=3447 clone guuid=9789e89f-1b00-0000-5413-8bb5ba0c0000 pid=3258->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 149B guuid=e7ac06a4-1b00-0000-5413-8bb5c20c0000 pid=3266->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 98B guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=88266aaa-1b00-0000-5413-8bb5cd0c0000 pid=3277 /tmp/WTF guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276->guuid=88266aaa-1b00-0000-5413-8bb5cd0c0000 pid=3277 clone guuid=205a73aa-1b00-0000-5413-8bb5ce0c0000 pid=3278 /tmp/WTF guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276->guuid=205a73aa-1b00-0000-5413-8bb5ce0c0000 pid=3278 clone guuid=ad247caa-1b00-0000-5413-8bb5cf0c0000 pid=3279 /tmp/WTF net send-data zombie guuid=5c912baa-1b00-0000-5413-8bb5cc0c0000 pid=3276->guuid=ad247caa-1b00-0000-5413-8bb5cf0c0000 pid=3279 clone guuid=ad247caa-1b00-0000-5413-8bb5cf0c0000 pid=3279->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ad247caa-1b00-0000-5413-8bb5cf0c0000 pid=3279->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 7B guuid=186b4c03-1c00-0000-5413-8bb57c0d0000 pid=3452 /tmp/WTF net send-data guuid=ad247caa-1b00-0000-5413-8bb5cf0c0000 pid=3279->guuid=186b4c03-1c00-0000-5413-8bb57c0d0000 pid=3452 clone guuid=e08a8aaa-1b00-0000-5413-8bb5d00c0000 pid=3280->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=d56360ad-1b00-0000-5413-8bb5d70c0000 pid=3287->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f15b80b5-1b00-0000-5413-8bb5e50c0000 pid=3301 /tmp/WTF guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300->guuid=f15b80b5-1b00-0000-5413-8bb5e50c0000 pid=3301 clone guuid=b21785b5-1b00-0000-5413-8bb5e60c0000 pid=3302 /tmp/WTF guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300->guuid=b21785b5-1b00-0000-5413-8bb5e60c0000 pid=3302 clone guuid=cc9888b5-1b00-0000-5413-8bb5e70c0000 pid=3303 /tmp/WTF net send-data zombie guuid=59044bb5-1b00-0000-5413-8bb5e40c0000 pid=3300->guuid=cc9888b5-1b00-0000-5413-8bb5e70c0000 pid=3303 clone guuid=cc9888b5-1b00-0000-5413-8bb5e70c0000 pid=3303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cc9888b5-1b00-0000-5413-8bb5e70c0000 pid=3303->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=0d0f77eb-1b00-0000-5413-8bb56b0d0000 pid=3435 /tmp/WTF net send-data guuid=cc9888b5-1b00-0000-5413-8bb5e70c0000 pid=3303->guuid=0d0f77eb-1b00-0000-5413-8bb56b0d0000 pid=3435 clone guuid=717f95b5-1b00-0000-5413-8bb5e90c0000 pid=3305->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=033a39b9-1b00-0000-5413-8bb5f20c0000 pid=3314->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=710bdfbf-1b00-0000-5413-8bb5030d0000 pid=3331 /tmp/WTF guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329->guuid=710bdfbf-1b00-0000-5413-8bb5030d0000 pid=3331 clone guuid=4136e4bf-1b00-0000-5413-8bb5040d0000 pid=3332 /tmp/WTF guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329->guuid=4136e4bf-1b00-0000-5413-8bb5040d0000 pid=3332 clone guuid=478deabf-1b00-0000-5413-8bb5050d0000 pid=3333 /tmp/WTF net send-data zombie guuid=1c3b9cbf-1b00-0000-5413-8bb5010d0000 pid=3329->guuid=478deabf-1b00-0000-5413-8bb5050d0000 pid=3333 clone guuid=478deabf-1b00-0000-5413-8bb5050d0000 pid=3333->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=478deabf-1b00-0000-5413-8bb5050d0000 pid=3333->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=905dd4ef-1b00-0000-5413-8bb5760d0000 pid=3446 /tmp/WTF net send-data guuid=478deabf-1b00-0000-5413-8bb5050d0000 pid=3333->guuid=905dd4ef-1b00-0000-5413-8bb5760d0000 pid=3446 clone guuid=5b1809c0-1b00-0000-5413-8bb5060d0000 pid=3334->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 152B guuid=a3f7c4c3-1b00-0000-5413-8bb5110d0000 pid=3345->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 101B guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0b6706cc-1b00-0000-5413-8bb5260d0000 pid=3366 /tmp/WTF guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364->guuid=0b6706cc-1b00-0000-5413-8bb5260d0000 pid=3366 clone guuid=f3920ccc-1b00-0000-5413-8bb5270d0000 pid=3367 /tmp/WTF guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364->guuid=f3920ccc-1b00-0000-5413-8bb5270d0000 pid=3367 clone guuid=89c60fcc-1b00-0000-5413-8bb5280d0000 pid=3368 /tmp/WTF net send-data zombie guuid=1192bdcb-1b00-0000-5413-8bb5240d0000 pid=3364->guuid=89c60fcc-1b00-0000-5413-8bb5280d0000 pid=3368 clone guuid=89c60fcc-1b00-0000-5413-8bb5280d0000 pid=3368->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=89c60fcc-1b00-0000-5413-8bb5280d0000 pid=3368->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 7B guuid=36115efc-1b00-0000-5413-8bb57a0d0000 pid=3450 /tmp/WTF net send-data guuid=89c60fcc-1b00-0000-5413-8bb5280d0000 pid=3368->guuid=36115efc-1b00-0000-5413-8bb57a0d0000 pid=3450 clone guuid=75e31dcc-1b00-0000-5413-8bb5290d0000 pid=3369->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=20f952d0-1b00-0000-5413-8bb5320d0000 pid=3378->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c2770ed8-1b00-0000-5413-8bb5410d0000 pid=3393 /tmp/WTF guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390->guuid=c2770ed8-1b00-0000-5413-8bb5410d0000 pid=3393 clone guuid=9e1d15d8-1b00-0000-5413-8bb5420d0000 pid=3394 /tmp/WTF guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390->guuid=9e1d15d8-1b00-0000-5413-8bb5420d0000 pid=3394 clone guuid=34a81ed8-1b00-0000-5413-8bb5430d0000 pid=3395 /tmp/WTF net send-data zombie guuid=822390d7-1b00-0000-5413-8bb53e0d0000 pid=3390->guuid=34a81ed8-1b00-0000-5413-8bb5430d0000 pid=3395 clone guuid=34a81ed8-1b00-0000-5413-8bb5430d0000 pid=3395->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=34a81ed8-1b00-0000-5413-8bb5430d0000 pid=3395->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=9795c634-1c00-0000-5413-8bb5d60d0000 pid=3542 /tmp/WTF net send-data guuid=34a81ed8-1b00-0000-5413-8bb5430d0000 pid=3395->guuid=9795c634-1c00-0000-5413-8bb5d60d0000 pid=3542 clone guuid=d3fd2cd8-1b00-0000-5413-8bb5440d0000 pid=3396->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 149B guuid=ff5814dc-1b00-0000-5413-8bb54b0d0000 pid=3403->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 98B guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc4cabe4-1b00-0000-5413-8bb55f0d0000 pid=3423 /tmp/WTF guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421->guuid=bc4cabe4-1b00-0000-5413-8bb55f0d0000 pid=3423 clone guuid=6300b0e4-1b00-0000-5413-8bb5600d0000 pid=3424 /tmp/WTF guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421->guuid=6300b0e4-1b00-0000-5413-8bb5600d0000 pid=3424 clone guuid=e1a4d3e4-1b00-0000-5413-8bb5610d0000 pid=3425 /tmp/WTF net send-data zombie guuid=bdd96ae4-1b00-0000-5413-8bb55d0d0000 pid=3421->guuid=e1a4d3e4-1b00-0000-5413-8bb5610d0000 pid=3425 clone guuid=e1a4d3e4-1b00-0000-5413-8bb5610d0000 pid=3425->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e1a4d3e4-1b00-0000-5413-8bb5610d0000 pid=3425->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 42B guuid=00ed08e5-1b00-0000-5413-8bb5630d0000 pid=3427->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=7b6ca5e8-1b00-0000-5413-8bb56a0d0000 pid=3434->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B 12948888-988a-54de-8359-92deeb92f2c0 200.40.36.1:80 guuid=0d0f77eb-1b00-0000-5413-8bb56b0d0000 pid=3435->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=08ed7deb-1b00-0000-5413-8bb56c0d0000 pid=3436 /tmp/WTF guuid=0d0f77eb-1b00-0000-5413-8bb56b0d0000 pid=3435->guuid=08ed7deb-1b00-0000-5413-8bb56c0d0000 pid=3436 clone guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ea07aeed-1b00-0000-5413-8bb5700d0000 pid=3440 /tmp/WTF guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439->guuid=ea07aeed-1b00-0000-5413-8bb5700d0000 pid=3440 clone guuid=4803b7ed-1b00-0000-5413-8bb5710d0000 pid=3441 /tmp/WTF guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439->guuid=4803b7ed-1b00-0000-5413-8bb5710d0000 pid=3441 clone guuid=d61bbced-1b00-0000-5413-8bb5720d0000 pid=3442 /tmp/WTF net send-data zombie guuid=55f17ced-1b00-0000-5413-8bb56f0d0000 pid=3439->guuid=d61bbced-1b00-0000-5413-8bb5720d0000 pid=3442 clone guuid=d61bbced-1b00-0000-5413-8bb5720d0000 pid=3442->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d61bbced-1b00-0000-5413-8bb5720d0000 pid=3442->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 32B guuid=38a1d3ed-1b00-0000-5413-8bb5730d0000 pid=3443->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=211be2ed-1b00-0000-5413-8bb5750d0000 pid=3445 /tmp/WTF guuid=38a1d3ed-1b00-0000-5413-8bb5730d0000 pid=3443->guuid=211be2ed-1b00-0000-5413-8bb5750d0000 pid=3445 clone guuid=f302d9ed-1b00-0000-5413-8bb5740d0000 pid=3444->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=905dd4ef-1b00-0000-5413-8bb5760d0000 pid=3446->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=70dee7ef-1b00-0000-5413-8bb5790d0000 pid=3449 /tmp/WTF guuid=905dd4ef-1b00-0000-5413-8bb5760d0000 pid=3446->guuid=70dee7ef-1b00-0000-5413-8bb5790d0000 pid=3449 clone guuid=c40ee1ef-1b00-0000-5413-8bb5770d0000 pid=3447->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=81e3e6ef-1b00-0000-5413-8bb5780d0000 pid=3448 /tmp/WTF guuid=c40ee1ef-1b00-0000-5413-8bb5770d0000 pid=3447->guuid=81e3e6ef-1b00-0000-5413-8bb5780d0000 pid=3448 clone guuid=36115efc-1b00-0000-5413-8bb57a0d0000 pid=3450->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=a67dc9fc-1b00-0000-5413-8bb57b0d0000 pid=3451 /tmp/WTF guuid=36115efc-1b00-0000-5413-8bb57a0d0000 pid=3450->guuid=a67dc9fc-1b00-0000-5413-8bb57b0d0000 pid=3451 clone guuid=186b4c03-1c00-0000-5413-8bb57c0d0000 pid=3452->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=f96bad03-1c00-0000-5413-8bb57d0d0000 pid=3453 /tmp/WTF guuid=186b4c03-1c00-0000-5413-8bb57c0d0000 pid=3452->guuid=f96bad03-1c00-0000-5413-8bb57d0d0000 pid=3453 clone guuid=3efea40f-1c00-0000-5413-8bb57f0d0000 pid=3455->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5f66bd1f-1c00-0000-5413-8bb5a10d0000 pid=3489 /tmp/WTF guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480->guuid=5f66bd1f-1c00-0000-5413-8bb5a10d0000 pid=3489 clone guuid=30820f20-1c00-0000-5413-8bb5a20d0000 pid=3490 /tmp/WTF guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480->guuid=30820f20-1c00-0000-5413-8bb5a20d0000 pid=3490 clone guuid=d4831720-1c00-0000-5413-8bb5a30d0000 pid=3491 /tmp/WTF net send-data zombie guuid=2fbdf41c-1c00-0000-5413-8bb5980d0000 pid=3480->guuid=d4831720-1c00-0000-5413-8bb5a30d0000 pid=3491 clone guuid=d4831720-1c00-0000-5413-8bb5a30d0000 pid=3491->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d4831720-1c00-0000-5413-8bb5a30d0000 pid=3491->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 35B guuid=30612a20-1c00-0000-5413-8bb5a40d0000 pid=3492->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=e7f2c62e-1c00-0000-5413-8bb5c30d0000 pid=3523->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=9795c634-1c00-0000-5413-8bb5d60d0000 pid=3542->12948888-988a-54de-8359-92deeb92f2c0 send: 2097664B guuid=611b4435-1c00-0000-5413-8bb5d80d0000 pid=3544 /tmp/WTF guuid=9795c634-1c00-0000-5413-8bb5d60d0000 pid=3542->guuid=611b4435-1c00-0000-5413-8bb5d80d0000 pid=3544 clone guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ee1ab951-1c00-0000-5413-8bb5070e0000 pid=3591 /tmp/WTF guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589->guuid=ee1ab951-1c00-0000-5413-8bb5070e0000 pid=3591 clone guuid=f6debf51-1c00-0000-5413-8bb5080e0000 pid=3592 /tmp/WTF guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589->guuid=f6debf51-1c00-0000-5413-8bb5080e0000 pid=3592 clone guuid=acd5c451-1c00-0000-5413-8bb5090e0000 pid=3593 /tmp/WTF net send-data zombie guuid=c54c6b51-1c00-0000-5413-8bb5050e0000 pid=3589->guuid=acd5c451-1c00-0000-5413-8bb5090e0000 pid=3593 clone guuid=acd5c451-1c00-0000-5413-8bb5090e0000 pid=3593->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=acd5c451-1c00-0000-5413-8bb5090e0000 pid=3593->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 5B guuid=6441da51-1c00-0000-5413-8bb50a0e0000 pid=3594->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 149B guuid=419e105b-1c00-0000-5413-8bb50f0e0000 pid=3599->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 98B guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=58a6d373-1c00-0000-5413-8bb5200e0000 pid=3616 /tmp/WTF guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615->guuid=58a6d373-1c00-0000-5413-8bb5200e0000 pid=3616 clone guuid=f5c0d773-1c00-0000-5413-8bb5210e0000 pid=3617 /tmp/WTF guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615->guuid=f5c0d773-1c00-0000-5413-8bb5210e0000 pid=3617 clone guuid=144edc73-1c00-0000-5413-8bb5220e0000 pid=3618 /tmp/WTF net send-data zombie guuid=73c09f73-1c00-0000-5413-8bb51f0e0000 pid=3615->guuid=144edc73-1c00-0000-5413-8bb5220e0000 pid=3618 clone guuid=144edc73-1c00-0000-5413-8bb5220e0000 pid=3618->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=144edc73-1c00-0000-5413-8bb5220e0000 pid=3618->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 7B guuid=2bf8e473-1c00-0000-5413-8bb5230e0000 pid=3619->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 149B guuid=28461c86-1c00-0000-5413-8bb5240e0000 pid=3620->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 98B guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6869e89b-1c00-0000-5413-8bb52a0e0000 pid=3626 /tmp/WTF guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625->guuid=6869e89b-1c00-0000-5413-8bb52a0e0000 pid=3626 clone guuid=bac8ee9b-1c00-0000-5413-8bb52b0e0000 pid=3627 /tmp/WTF guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625->guuid=bac8ee9b-1c00-0000-5413-8bb52b0e0000 pid=3627 clone guuid=6dfbf49b-1c00-0000-5413-8bb52c0e0000 pid=3628 /tmp/WTF net send-data zombie guuid=c3cf809b-1c00-0000-5413-8bb5290e0000 pid=3625->guuid=6dfbf49b-1c00-0000-5413-8bb52c0e0000 pid=3628 clone guuid=6dfbf49b-1c00-0000-5413-8bb52c0e0000 pid=3628->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6dfbf49b-1c00-0000-5413-8bb52c0e0000 pid=3628->5ab2dab8-4725-502a-8ff3-47b656dd5b7d send: 7B guuid=022a0d9c-1c00-0000-5413-8bb52d0e0000 pid=3629->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 150B guuid=b4c104aa-1c00-0000-5413-8bb5330e0000 pid=3635->33673a35-8f08-5aeb-b365-8b166da6f7f7 send: 99B guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4c0162bf-1c00-0000-5413-8bb5480e0000 pid=3656 /tmp/WTF guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655->guuid=4c0162bf-1c00-0000-5413-8bb5480e0000 pid=3656 clone guuid=ec2966bf-1c00-0000-5413-8bb5490e0000 pid=3657 /tmp/WTF guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655->guuid=ec2966bf-1c00-0000-5413-8bb5490e0000 pid=3657 clone guuid=f86b6abf-1c00-0000-5413-8bb54a0e0000 pid=3658 /tmp/WTF guuid=8a5a29bf-1c00-0000-5413-8bb5470e0000 pid=3655->guuid=f86b6abf-1c00-0000-5413-8bb54a0e0000 pid=3658 clone
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-30 22:00:00 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 757de8284ef3595bea3dbcecb1effca1a7593ba33b4f1fdfe7bdcf28b8e3a315

(this sample)

  
Delivery method
Distributed via web download

Comments