MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 75c235cb6d97f739c174240bd4030a98e1eef69ca60333608c88ede89b258eaf. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: 75c235cb6d97f739c174240bd4030a98e1eef69ca60333608c88ede89b258eaf
SHA3-384 hash: f1042e9d9f9df9494cb00e202bdd8a9760e55edde1b9af8671663214ed7d0c08206e7593576111abc23cdd449fc3deec
SHA1 hash: d0ab409d1b070df7273ee599389195397fd5ca5c
MD5 hash: 1ae676ef35dec3d1cdbb719021bb22f5
humanhash: louisiana-three-moon-north
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2026-01-22 09:17:21 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vI7L7N7hIS6GIg6zPICKWIEoUI7E7o7UIf53bIb9RIwcgIfpVI6SOI++CIJfTIRE:vI7L7N7hIS6GIg6zPICKWIEoUI7E7o7A
TLSH T11151B68A47462E7038A36E53FAB771383081D45298E1AB95EDE4BEF0336EF143184793
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.144.54.79/hiddenbin/boatnet.x868018baeb68c36b223cb6d9df66d158c50fe11a215aed02825177474c93b86939 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.mips0e5726a596c6d83994a14dd7d95a339f2d058e6cc6eecd127ac8e891ced08584 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.arcddc80619659aaceed7c9b01accef32dcf5fd2db3b5fff47f574cb1a9fc4f9858 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://45.144.54.79/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://45.144.54.79/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://45.144.54.79/hiddenbin/boatnet.mpsl0a9fb6f2877778839a6b8a36ce4e7b7973cf853ebfacbd4e35b1000bbf1867fd Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.armc16a6c5af10f561b281764aae289cf9e60a86aabf6c8b02b577b041be09f9f01 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.arm51c5c43711d001c4ee3af49cf4bdeafd97fccb6228e653a943008800910b86005 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.arm60f2c8ca60db776610b09f62221dc4f2dfbca6dee0c5fe19318e4b8759ee5a706 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.arm75e001b88f4d0c1a80c9feb1ec7a673d96202821f5e6f7c35a7c12d01909c9a63 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.ppcb9c637bfa42aebb25fe433cdd8b4867d21f63f71eb93e87d7a638a3e79f6d904 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.spcfd6035d46484c22f614268ccca884d9e02ae7ed9f7d05e87e1c07bf404d8c395 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.m68k362512cef9d62ebdc4a8fd1a29b4065b6270341058c6a3e714b1b14348eb25b8 Miraielf mirai ua-wget
http://45.144.54.79/hiddenbin/boatnet.sh43f113f972822757c5a113be92f886192d85408cbcb995632f2dc8f70cf99d5fb Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-22T06:21:00Z UTC
Last seen:
2026-01-22T12:54:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=cfdd49ea-1800-0000-044e-b5c205080000 pid=2053 /usr/bin/sudo guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061 /tmp/sample.bin guuid=cfdd49ea-1800-0000-044e-b5c205080000 pid=2053->guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061 execve guuid=933995ee-1800-0000-044e-b5c20f080000 pid=2063 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=933995ee-1800-0000-044e-b5c20f080000 pid=2063 execve guuid=f3c2e8f3-1800-0000-044e-b5c218080000 pid=2072 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=f3c2e8f3-1800-0000-044e-b5c218080000 pid=2072 execve guuid=9d3b1bfe-1800-0000-044e-b5c228080000 pid=2088 /usr/bin/cat guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9d3b1bfe-1800-0000-044e-b5c228080000 pid=2088 execve guuid=7e87adfe-1800-0000-044e-b5c22b080000 pid=2091 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7e87adfe-1800-0000-044e-b5c22b080000 pid=2091 execve guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093 execve guuid=e73894ff-1800-0000-044e-b5c233080000 pid=2099 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=e73894ff-1800-0000-044e-b5c233080000 pid=2099 execve guuid=06b87b03-1900-0000-044e-b5c238080000 pid=2104 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=06b87b03-1900-0000-044e-b5c238080000 pid=2104 execve guuid=9ccd4e08-1900-0000-044e-b5c242080000 pid=2114 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9ccd4e08-1900-0000-044e-b5c242080000 pid=2114 clone guuid=65657008-1900-0000-044e-b5c243080000 pid=2115 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=65657008-1900-0000-044e-b5c243080000 pid=2115 execve guuid=506de708-1900-0000-044e-b5c245080000 pid=2117 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=506de708-1900-0000-044e-b5c245080000 pid=2117 execve guuid=4cac4609-1900-0000-044e-b5c24a080000 pid=2122 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=4cac4609-1900-0000-044e-b5c24a080000 pid=2122 execve guuid=ae18120c-1900-0000-044e-b5c250080000 pid=2128 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ae18120c-1900-0000-044e-b5c250080000 pid=2128 execve guuid=d6db1f10-1900-0000-044e-b5c255080000 pid=2133 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=d6db1f10-1900-0000-044e-b5c255080000 pid=2133 clone guuid=6a6a4010-1900-0000-044e-b5c257080000 pid=2135 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=6a6a4010-1900-0000-044e-b5c257080000 pid=2135 execve guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136 execve guuid=ed63df10-1900-0000-044e-b5c25d080000 pid=2141 /usr/bin/wget net send-data guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ed63df10-1900-0000-044e-b5c25d080000 pid=2141 execve guuid=d3779213-1900-0000-044e-b5c264080000 pid=2148 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=d3779213-1900-0000-044e-b5c264080000 pid=2148 execve guuid=51ec5c16-1900-0000-044e-b5c26d080000 pid=2157 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=51ec5c16-1900-0000-044e-b5c26d080000 pid=2157 clone guuid=6eb48116-1900-0000-044e-b5c26e080000 pid=2158 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=6eb48116-1900-0000-044e-b5c26e080000 pid=2158 execve guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160 execve guuid=04892717-1900-0000-044e-b5c275080000 pid=2165 /usr/bin/wget net send-data guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=04892717-1900-0000-044e-b5c275080000 pid=2165 execve guuid=4fa28319-1900-0000-044e-b5c27c080000 pid=2172 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=4fa28319-1900-0000-044e-b5c27c080000 pid=2172 execve guuid=8d40cc1c-1900-0000-044e-b5c286080000 pid=2182 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=8d40cc1c-1900-0000-044e-b5c286080000 pid=2182 clone guuid=b60ceb1c-1900-0000-044e-b5c287080000 pid=2183 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=b60ceb1c-1900-0000-044e-b5c287080000 pid=2183 execve guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185 execve guuid=89f6c11d-1900-0000-044e-b5c28e080000 pid=2190 /usr/bin/wget net send-data guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=89f6c11d-1900-0000-044e-b5c28e080000 pid=2190 execve guuid=849d2b20-1900-0000-044e-b5c296080000 pid=2198 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=849d2b20-1900-0000-044e-b5c296080000 pid=2198 execve guuid=ffa65824-1900-0000-044e-b5c2a3080000 pid=2211 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ffa65824-1900-0000-044e-b5c2a3080000 pid=2211 clone guuid=bb027c24-1900-0000-044e-b5c2a4080000 pid=2212 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=bb027c24-1900-0000-044e-b5c2a4080000 pid=2212 execve guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214 execve guuid=62920b25-1900-0000-044e-b5c2ab080000 pid=2219 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=62920b25-1900-0000-044e-b5c2ab080000 pid=2219 execve guuid=06e64d27-1900-0000-044e-b5c2b2080000 pid=2226 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=06e64d27-1900-0000-044e-b5c2b2080000 pid=2226 execve guuid=7a4dd02b-1900-0000-044e-b5c2bf080000 pid=2239 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7a4dd02b-1900-0000-044e-b5c2bf080000 pid=2239 clone guuid=613de92b-1900-0000-044e-b5c2c0080000 pid=2240 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=613de92b-1900-0000-044e-b5c2c0080000 pid=2240 execve guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242 execve guuid=5a24a42c-1900-0000-044e-b5c2c7080000 pid=2247 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=5a24a42c-1900-0000-044e-b5c2c7080000 pid=2247 execve guuid=fb510e2f-1900-0000-044e-b5c2cf080000 pid=2255 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=fb510e2f-1900-0000-044e-b5c2cf080000 pid=2255 execve guuid=fae74c32-1900-0000-044e-b5c2da080000 pid=2266 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=fae74c32-1900-0000-044e-b5c2da080000 pid=2266 clone guuid=9d317432-1900-0000-044e-b5c2db080000 pid=2267 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9d317432-1900-0000-044e-b5c2db080000 pid=2267 execve guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269 execve guuid=e34a5a33-1900-0000-044e-b5c2e3080000 pid=2275 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=e34a5a33-1900-0000-044e-b5c2e3080000 pid=2275 execve guuid=ae198e35-1900-0000-044e-b5c2ea080000 pid=2282 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ae198e35-1900-0000-044e-b5c2ea080000 pid=2282 execve guuid=1643e738-1900-0000-044e-b5c2f5080000 pid=2293 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=1643e738-1900-0000-044e-b5c2f5080000 pid=2293 clone guuid=90fc0539-1900-0000-044e-b5c2f6080000 pid=2294 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=90fc0539-1900-0000-044e-b5c2f6080000 pid=2294 execve guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296 execve guuid=d87b9039-1900-0000-044e-b5c2fc080000 pid=2300 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=d87b9039-1900-0000-044e-b5c2fc080000 pid=2300 execve guuid=9dbbb93b-1900-0000-044e-b5c202090000 pid=2306 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9dbbb93b-1900-0000-044e-b5c202090000 pid=2306 execve guuid=fccbae3e-1900-0000-044e-b5c20b090000 pid=2315 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=fccbae3e-1900-0000-044e-b5c20b090000 pid=2315 clone guuid=ca80c63e-1900-0000-044e-b5c20c090000 pid=2316 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ca80c63e-1900-0000-044e-b5c20c090000 pid=2316 execve guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318 execve guuid=e79d903f-1900-0000-044e-b5c213090000 pid=2323 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=e79d903f-1900-0000-044e-b5c213090000 pid=2323 execve guuid=f2b01442-1900-0000-044e-b5c21a090000 pid=2330 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=f2b01442-1900-0000-044e-b5c21a090000 pid=2330 execve guuid=3c644749-1900-0000-044e-b5c226090000 pid=2342 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=3c644749-1900-0000-044e-b5c226090000 pid=2342 clone guuid=20709b49-1900-0000-044e-b5c227090000 pid=2343 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=20709b49-1900-0000-044e-b5c227090000 pid=2343 execve guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344 execve guuid=9606594a-1900-0000-044e-b5c22c090000 pid=2348 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=9606594a-1900-0000-044e-b5c22c090000 pid=2348 execve guuid=6693ef4c-1900-0000-044e-b5c22d090000 pid=2349 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=6693ef4c-1900-0000-044e-b5c22d090000 pid=2349 execve guuid=a143c753-1900-0000-044e-b5c233090000 pid=2355 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=a143c753-1900-0000-044e-b5c233090000 pid=2355 clone guuid=6e54e753-1900-0000-044e-b5c234090000 pid=2356 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=6e54e753-1900-0000-044e-b5c234090000 pid=2356 execve guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358 execve guuid=c78d7d54-1900-0000-044e-b5c23b090000 pid=2363 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=c78d7d54-1900-0000-044e-b5c23b090000 pid=2363 execve guuid=a6641857-1900-0000-044e-b5c240090000 pid=2368 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=a6641857-1900-0000-044e-b5c240090000 pid=2368 execve guuid=7724c75c-1900-0000-044e-b5c250090000 pid=2384 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7724c75c-1900-0000-044e-b5c250090000 pid=2384 clone guuid=12d6e15c-1900-0000-044e-b5c251090000 pid=2385 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=12d6e15c-1900-0000-044e-b5c251090000 pid=2385 execve guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388 execve guuid=bf96625d-1900-0000-044e-b5c258090000 pid=2392 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=bf96625d-1900-0000-044e-b5c258090000 pid=2392 execve guuid=df70b261-1900-0000-044e-b5c265090000 pid=2405 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=df70b261-1900-0000-044e-b5c265090000 pid=2405 execve guuid=94552065-1900-0000-044e-b5c26e090000 pid=2414 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=94552065-1900-0000-044e-b5c26e090000 pid=2414 clone guuid=f8553b65-1900-0000-044e-b5c26f090000 pid=2415 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=f8553b65-1900-0000-044e-b5c26f090000 pid=2415 execve guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416 execve guuid=7c6ddb65-1900-0000-044e-b5c275090000 pid=2421 /usr/bin/wget net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=7c6ddb65-1900-0000-044e-b5c275090000 pid=2421 execve guuid=425d6068-1900-0000-044e-b5c27d090000 pid=2429 /usr/bin/curl net send-data write-file guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=425d6068-1900-0000-044e-b5c27d090000 pid=2429 execve guuid=0d88116c-1900-0000-044e-b5c284090000 pid=2436 /usr/bin/bash guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=0d88116c-1900-0000-044e-b5c284090000 pid=2436 clone guuid=bf3c306c-1900-0000-044e-b5c285090000 pid=2437 /usr/bin/chmod guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=bf3c306c-1900-0000-044e-b5c285090000 pid=2437 execve guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439 /tmp/WTF net guuid=c26baded-1800-0000-044e-b5c20d080000 pid=2061->guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439 execve bda9c966-c1a4-5198-902e-d018491d1a73 45.144.54.79:80 guuid=933995ee-1800-0000-044e-b5c20f080000 pid=2063->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=f3c2e8f3-1800-0000-044e-b5c218080000 pid=2072->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bd726eff-1800-0000-044e-b5c230080000 pid=2096 /tmp/WTF guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093->guuid=bd726eff-1800-0000-044e-b5c230080000 pid=2096 clone guuid=2f1073ff-1800-0000-044e-b5c231080000 pid=2097 /tmp/WTF guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093->guuid=2f1073ff-1800-0000-044e-b5c231080000 pid=2097 clone guuid=d48779ff-1800-0000-044e-b5c232080000 pid=2098 /tmp/WTF net send-data zombie guuid=ae8610ff-1800-0000-044e-b5c22d080000 pid=2093->guuid=d48779ff-1800-0000-044e-b5c232080000 pid=2098 clone guuid=d48779ff-1800-0000-044e-b5c232080000 pid=2098->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 7ab2820e-ed61-543c-abec-1dd2c4971d26 45.144.54.79:3778 guuid=d48779ff-1800-0000-044e-b5c232080000 pid=2098->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=e73894ff-1800-0000-044e-b5c233080000 pid=2099->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=06b87b03-1900-0000-044e-b5c238080000 pid=2104->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=506de708-1900-0000-044e-b5c245080000 pid=2117->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=84302809-1900-0000-044e-b5c247080000 pid=2119 /tmp/WTF guuid=506de708-1900-0000-044e-b5c245080000 pid=2117->guuid=84302809-1900-0000-044e-b5c247080000 pid=2119 clone guuid=5fd23209-1900-0000-044e-b5c248080000 pid=2120 /tmp/WTF guuid=506de708-1900-0000-044e-b5c245080000 pid=2117->guuid=5fd23209-1900-0000-044e-b5c248080000 pid=2120 clone guuid=fb553909-1900-0000-044e-b5c249080000 pid=2121 /tmp/WTF net send-data zombie guuid=506de708-1900-0000-044e-b5c245080000 pid=2117->guuid=fb553909-1900-0000-044e-b5c249080000 pid=2121 clone guuid=fb553909-1900-0000-044e-b5c249080000 pid=2121->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fb553909-1900-0000-044e-b5c249080000 pid=2121->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=4cac4609-1900-0000-044e-b5c24a080000 pid=2122->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=ae18120c-1900-0000-044e-b5c250080000 pid=2128->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=de71c210-1900-0000-044e-b5c25a080000 pid=2138 /tmp/WTF guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136->guuid=de71c210-1900-0000-044e-b5c25a080000 pid=2138 clone guuid=c579c610-1900-0000-044e-b5c25b080000 pid=2139 /tmp/WTF guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136->guuid=c579c610-1900-0000-044e-b5c25b080000 pid=2139 clone guuid=b46acf10-1900-0000-044e-b5c25c080000 pid=2140 /tmp/WTF net send-data zombie guuid=8f8b8d10-1900-0000-044e-b5c258080000 pid=2136->guuid=b46acf10-1900-0000-044e-b5c25c080000 pid=2140 clone guuid=b46acf10-1900-0000-044e-b5c25c080000 pid=2140->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b46acf10-1900-0000-044e-b5c25c080000 pid=2140->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=ed63df10-1900-0000-044e-b5c25d080000 pid=2141->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=d3779213-1900-0000-044e-b5c264080000 pid=2148->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=67341517-1900-0000-044e-b5c272080000 pid=2162 /tmp/WTF guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160->guuid=67341517-1900-0000-044e-b5c272080000 pid=2162 clone guuid=004a1a17-1900-0000-044e-b5c273080000 pid=2163 /tmp/WTF guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160->guuid=004a1a17-1900-0000-044e-b5c273080000 pid=2163 clone guuid=c3e91e17-1900-0000-044e-b5c274080000 pid=2164 /tmp/WTF net send-data zombie guuid=b074e616-1900-0000-044e-b5c270080000 pid=2160->guuid=c3e91e17-1900-0000-044e-b5c274080000 pid=2164 clone guuid=c3e91e17-1900-0000-044e-b5c274080000 pid=2164->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c3e91e17-1900-0000-044e-b5c274080000 pid=2164->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=04892717-1900-0000-044e-b5c275080000 pid=2165->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=4fa28319-1900-0000-044e-b5c27c080000 pid=2172->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7b38a31d-1900-0000-044e-b5c28b080000 pid=2187 /tmp/WTF guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185->guuid=7b38a31d-1900-0000-044e-b5c28b080000 pid=2187 clone guuid=521ca81d-1900-0000-044e-b5c28c080000 pid=2188 /tmp/WTF guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185->guuid=521ca81d-1900-0000-044e-b5c28c080000 pid=2188 clone guuid=917ab01d-1900-0000-044e-b5c28d080000 pid=2189 /tmp/WTF net send-data zombie guuid=3b89611d-1900-0000-044e-b5c289080000 pid=2185->guuid=917ab01d-1900-0000-044e-b5c28d080000 pid=2189 clone guuid=917ab01d-1900-0000-044e-b5c28d080000 pid=2189->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=917ab01d-1900-0000-044e-b5c28d080000 pid=2189->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=89f6c11d-1900-0000-044e-b5c28e080000 pid=2190->bda9c966-c1a4-5198-902e-d018491d1a73 send: 151B guuid=849d2b20-1900-0000-044e-b5c296080000 pid=2198->bda9c966-c1a4-5198-902e-d018491d1a73 send: 100B guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c75ef924-1900-0000-044e-b5c2a8080000 pid=2216 /tmp/WTF guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214->guuid=c75ef924-1900-0000-044e-b5c2a8080000 pid=2216 clone guuid=ce46fc24-1900-0000-044e-b5c2a9080000 pid=2217 /tmp/WTF guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214->guuid=ce46fc24-1900-0000-044e-b5c2a9080000 pid=2217 clone guuid=48380025-1900-0000-044e-b5c2aa080000 pid=2218 /tmp/WTF net send-data zombie guuid=f228c524-1900-0000-044e-b5c2a6080000 pid=2214->guuid=48380025-1900-0000-044e-b5c2aa080000 pid=2218 clone guuid=48380025-1900-0000-044e-b5c2aa080000 pid=2218->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=48380025-1900-0000-044e-b5c2aa080000 pid=2218->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=62920b25-1900-0000-044e-b5c2ab080000 pid=2219->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=06e64d27-1900-0000-044e-b5c2b2080000 pid=2226->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f8ab8a2c-1900-0000-044e-b5c2c4080000 pid=2244 /tmp/WTF guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242->guuid=f8ab8a2c-1900-0000-044e-b5c2c4080000 pid=2244 clone guuid=f088902c-1900-0000-044e-b5c2c5080000 pid=2245 /tmp/WTF guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242->guuid=f088902c-1900-0000-044e-b5c2c5080000 pid=2245 clone guuid=05d4962c-1900-0000-044e-b5c2c6080000 pid=2246 /tmp/WTF net send-data zombie guuid=9e19442c-1900-0000-044e-b5c2c2080000 pid=2242->guuid=05d4962c-1900-0000-044e-b5c2c6080000 pid=2246 clone guuid=05d4962c-1900-0000-044e-b5c2c6080000 pid=2246->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=05d4962c-1900-0000-044e-b5c2c6080000 pid=2246->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=5a24a42c-1900-0000-044e-b5c2c7080000 pid=2247->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=fb510e2f-1900-0000-044e-b5c2cf080000 pid=2255->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a7333c33-1900-0000-044e-b5c2df080000 pid=2271 /tmp/WTF guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269->guuid=a7333c33-1900-0000-044e-b5c2df080000 pid=2271 clone guuid=cabc4333-1900-0000-044e-b5c2e0080000 pid=2272 /tmp/WTF guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269->guuid=cabc4333-1900-0000-044e-b5c2e0080000 pid=2272 clone guuid=31b34933-1900-0000-044e-b5c2e1080000 pid=2273 /tmp/WTF net send-data zombie guuid=7537f132-1900-0000-044e-b5c2dd080000 pid=2269->guuid=31b34933-1900-0000-044e-b5c2e1080000 pid=2273 clone guuid=31b34933-1900-0000-044e-b5c2e1080000 pid=2273->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=31b34933-1900-0000-044e-b5c2e1080000 pid=2273->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=e34a5a33-1900-0000-044e-b5c2e3080000 pid=2275->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=ae198e35-1900-0000-044e-b5c2ea080000 pid=2282->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a0937939-1900-0000-044e-b5c2f9080000 pid=2297 /tmp/WTF guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296->guuid=a0937939-1900-0000-044e-b5c2f9080000 pid=2297 clone guuid=9bb97c39-1900-0000-044e-b5c2fa080000 pid=2298 /tmp/WTF guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296->guuid=9bb97c39-1900-0000-044e-b5c2fa080000 pid=2298 clone guuid=3d448039-1900-0000-044e-b5c2fb080000 pid=2299 /tmp/WTF net send-data zombie guuid=b5104d39-1900-0000-044e-b5c2f8080000 pid=2296->guuid=3d448039-1900-0000-044e-b5c2fb080000 pid=2299 clone guuid=3d448039-1900-0000-044e-b5c2fb080000 pid=2299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3d448039-1900-0000-044e-b5c2fb080000 pid=2299->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=d87b9039-1900-0000-044e-b5c2fc080000 pid=2300->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=9dbbb93b-1900-0000-044e-b5c202090000 pid=2306->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1255763f-1900-0000-044e-b5c210090000 pid=2320 /tmp/WTF guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318->guuid=1255763f-1900-0000-044e-b5c210090000 pid=2320 clone guuid=3f357b3f-1900-0000-044e-b5c211090000 pid=2321 /tmp/WTF guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318->guuid=3f357b3f-1900-0000-044e-b5c211090000 pid=2321 clone guuid=7a9a813f-1900-0000-044e-b5c212090000 pid=2322 /tmp/WTF net send-data zombie guuid=798a383f-1900-0000-044e-b5c20e090000 pid=2318->guuid=7a9a813f-1900-0000-044e-b5c212090000 pid=2322 clone guuid=7a9a813f-1900-0000-044e-b5c212090000 pid=2322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7a9a813f-1900-0000-044e-b5c212090000 pid=2322->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=e79d903f-1900-0000-044e-b5c213090000 pid=2323->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=f2b01442-1900-0000-044e-b5c21a090000 pid=2330->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=84f0344a-1900-0000-044e-b5c229090000 pid=2345 /tmp/WTF guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344->guuid=84f0344a-1900-0000-044e-b5c229090000 pid=2345 clone guuid=12133b4a-1900-0000-044e-b5c22a090000 pid=2346 /tmp/WTF guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344->guuid=12133b4a-1900-0000-044e-b5c22a090000 pid=2346 clone guuid=6cf6444a-1900-0000-044e-b5c22b090000 pid=2347 /tmp/WTF net send-data zombie guuid=7702ea49-1900-0000-044e-b5c228090000 pid=2344->guuid=6cf6444a-1900-0000-044e-b5c22b090000 pid=2347 clone guuid=6cf6444a-1900-0000-044e-b5c22b090000 pid=2347->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6cf6444a-1900-0000-044e-b5c22b090000 pid=2347->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=9606594a-1900-0000-044e-b5c22c090000 pid=2348->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=6693ef4c-1900-0000-044e-b5c22d090000 pid=2349->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d567054-1900-0000-044e-b5c238090000 pid=2360 /tmp/WTF guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358->guuid=2d567054-1900-0000-044e-b5c238090000 pid=2360 clone guuid=70e27354-1900-0000-044e-b5c239090000 pid=2361 /tmp/WTF guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358->guuid=70e27354-1900-0000-044e-b5c239090000 pid=2361 clone guuid=9db07654-1900-0000-044e-b5c23a090000 pid=2362 /tmp/WTF net send-data zombie guuid=20574b54-1900-0000-044e-b5c236090000 pid=2358->guuid=9db07654-1900-0000-044e-b5c23a090000 pid=2362 clone guuid=9db07654-1900-0000-044e-b5c23a090000 pid=2362->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9db07654-1900-0000-044e-b5c23a090000 pid=2362->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=c78d7d54-1900-0000-044e-b5c23b090000 pid=2363->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=a6641857-1900-0000-044e-b5c240090000 pid=2368->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7e9f505d-1900-0000-044e-b5c255090000 pid=2389 /tmp/WTF guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388->guuid=7e9f505d-1900-0000-044e-b5c255090000 pid=2389 clone guuid=848a545d-1900-0000-044e-b5c256090000 pid=2390 /tmp/WTF guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388->guuid=848a545d-1900-0000-044e-b5c256090000 pid=2390 clone guuid=8646595d-1900-0000-044e-b5c257090000 pid=2391 /tmp/WTF net send-data zombie guuid=fe3f2a5d-1900-0000-044e-b5c254090000 pid=2388->guuid=8646595d-1900-0000-044e-b5c257090000 pid=2391 clone guuid=8646595d-1900-0000-044e-b5c257090000 pid=2391->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8646595d-1900-0000-044e-b5c257090000 pid=2391->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=bf96625d-1900-0000-044e-b5c258090000 pid=2392->bda9c966-c1a4-5198-902e-d018491d1a73 send: 149B guuid=df70b261-1900-0000-044e-b5c265090000 pid=2405->bda9c966-c1a4-5198-902e-d018491d1a73 send: 98B guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9abccb65-1900-0000-044e-b5c272090000 pid=2418 /tmp/WTF guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416->guuid=9abccb65-1900-0000-044e-b5c272090000 pid=2418 clone guuid=0cc5ce65-1900-0000-044e-b5c273090000 pid=2419 /tmp/WTF guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416->guuid=0cc5ce65-1900-0000-044e-b5c273090000 pid=2419 clone guuid=85e2d165-1900-0000-044e-b5c274090000 pid=2420 /tmp/WTF net send-data zombie guuid=3c2d9865-1900-0000-044e-b5c270090000 pid=2416->guuid=85e2d165-1900-0000-044e-b5c274090000 pid=2420 clone guuid=85e2d165-1900-0000-044e-b5c274090000 pid=2420->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=85e2d165-1900-0000-044e-b5c274090000 pid=2420->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B guuid=7c6ddb65-1900-0000-044e-b5c275090000 pid=2421->bda9c966-c1a4-5198-902e-d018491d1a73 send: 148B guuid=425d6068-1900-0000-044e-b5c27d090000 pid=2429->bda9c966-c1a4-5198-902e-d018491d1a73 send: 97B guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bbb7ee6c-1900-0000-044e-b5c288090000 pid=2440 /tmp/WTF guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439->guuid=bbb7ee6c-1900-0000-044e-b5c288090000 pid=2440 clone guuid=dab3f26c-1900-0000-044e-b5c289090000 pid=2441 /tmp/WTF guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439->guuid=dab3f26c-1900-0000-044e-b5c289090000 pid=2441 clone guuid=4edbf66c-1900-0000-044e-b5c28a090000 pid=2442 /tmp/WTF net send-data zombie guuid=ed28b16c-1900-0000-044e-b5c287090000 pid=2439->guuid=4edbf66c-1900-0000-044e-b5c28a090000 pid=2442 clone guuid=4edbf66c-1900-0000-044e-b5c28a090000 pid=2442->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4edbf66c-1900-0000-044e-b5c28a090000 pid=2442->7ab2820e-ed61-543c-abec-1dd2c4971d26 send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-22 09:00:55 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 75c235cb6d97f739c174240bd4030a98e1eef69ca60333608c88ede89b258eaf

(this sample)

  
Delivery method
Distributed via web download

Comments