MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 79dfad940aa718395f04c71d5eb99fe87f2072ca1ce4d534c0e1847631f1375e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 79dfad940aa718395f04c71d5eb99fe87f2072ca1ce4d534c0e1847631f1375e
SHA3-384 hash: 6df3c6f4c41924a0a38359cb30f95e7728b72ca366912dd616c122ff0b5c0705a4d0c39ca40c8b1d3e204c1f9301d98f
SHA1 hash: 50ce4f78161c4a670c0cbfbee6aa2c0b5c1bb5f8
MD5 hash: db72f5e0d507c0abfcf9d6ff046cdd14
humanhash: beer-bakerloo-zebra-lion
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'007 bytes
First seen:2026-06-01 05:38:02 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ipl70l7N7hplvl6GplgnlzPplflKWpl1loUpl71l7o7UplfOl3bplEl9RplhlcgN:iD7Y7N7hD96GDglzPDtKWDvoUD7v7o7U
TLSH T10C51B4C542866C3968B7EA13F6B68138308191D318FE7F9ADED8BAF0868ED347140753
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.116/hiddenbin/boatnet.x8609015d7cc063b6d89e97e2eb864c934d7bd42cce1041ad67fa3c725074565bc6 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.mips39256d0ebac42184c8c5c8d5bfc4999090e5a0f3bf8cbf3ed4c69465e34cc104 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.arccab04ea015a6260a1dede7f2df4162e43743890e45974bc38b79a3e3e0534037 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://176.65.139.116/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://176.65.139.116/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://176.65.139.116/hiddenbin/boatnet.mpsldd4199c2b8d94da33925badf03a25a5a896c71167a1afa6b8fe6119a4d28f213 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.arm35490e92117a13045b528fe05c3aa20c784657d1a674f3730ab23aae045516f7 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.arm568f13ab488e209bae93f7c03b8c14a2f51fdc1930a8412dc806c07a58beeae73 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.arm623ab870dbce151ea72e0966114dacd7d0b3e436314c73943bc8d2ddf679625d9 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.arm7d5f651b772c567a2997eebad10b8b062191270dba3d17c99f161686bf8b98adf Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.ppc2cc14c04ab566cb0d3a3778d76cc263e0b75c504f03af3b6b464a1366dbd5044 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.spcd05519da897fa942cd63f3b05257dc850deee869a188b2faf25c5f54d9a4effa Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.m68kc7395e64995437727f25a648fb0b8dc7dbca02cfc9a3bba463f8eb7f1f0068f8 Mirai176-65-139-116 elf mirai ua-wget
http://176.65.139.116/hiddenbin/boatnet.sh4c8010894730cbf62d420591cae5d92cf2bc91d36241826a86ba90c6a8ad58082 Mirai176-65-139-116 elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
RO RO
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
busybox
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-01T04:05:00Z UTC
Last seen:
2026-06-01T13:36:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=161b85a7-1c00-0000-6151-8fb7ef0b0000 pid=3055 /usr/bin/sudo guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064 /tmp/sample.bin guuid=161b85a7-1c00-0000-6151-8fb7ef0b0000 pid=3055->guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064 execve guuid=7d53baa9-1c00-0000-6151-8fb7fa0b0000 pid=3066 /usr/bin/cp guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=7d53baa9-1c00-0000-6151-8fb7fa0b0000 pid=3066 execve guuid=0f6e55af-1c00-0000-6151-8fb70c0c0000 pid=3084 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=0f6e55af-1c00-0000-6151-8fb70c0c0000 pid=3084 execve guuid=e92b04b7-1c00-0000-6151-8fb71a0c0000 pid=3098 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=e92b04b7-1c00-0000-6151-8fb71a0c0000 pid=3098 execve guuid=6d6608c1-1c00-0000-6151-8fb72e0c0000 pid=3118 /usr/bin/cat guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=6d6608c1-1c00-0000-6151-8fb72e0c0000 pid=3118 execve guuid=a85870c1-1c00-0000-6151-8fb72f0c0000 pid=3119 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=a85870c1-1c00-0000-6151-8fb72f0c0000 pid=3119 execve guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122 execve guuid=b8349ec2-1c00-0000-6151-8fb7380c0000 pid=3128 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=b8349ec2-1c00-0000-6151-8fb7380c0000 pid=3128 execve guuid=5b8372c8-1c00-0000-6151-8fb7440c0000 pid=3140 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=5b8372c8-1c00-0000-6151-8fb7440c0000 pid=3140 execve guuid=737937d0-1c00-0000-6151-8fb7580c0000 pid=3160 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=737937d0-1c00-0000-6151-8fb7580c0000 pid=3160 clone guuid=15ec56d0-1c00-0000-6151-8fb7590c0000 pid=3161 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=15ec56d0-1c00-0000-6151-8fb7590c0000 pid=3161 execve guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163 execve guuid=ce7477d1-1c00-0000-6151-8fb7600c0000 pid=3168 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=ce7477d1-1c00-0000-6151-8fb7600c0000 pid=3168 execve guuid=1b050dd7-1c00-0000-6151-8fb76f0c0000 pid=3183 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=1b050dd7-1c00-0000-6151-8fb76f0c0000 pid=3183 execve guuid=7e5054dd-1c00-0000-6151-8fb7790c0000 pid=3193 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=7e5054dd-1c00-0000-6151-8fb7790c0000 pid=3193 clone guuid=d56d67dd-1c00-0000-6151-8fb77b0c0000 pid=3195 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=d56d67dd-1c00-0000-6151-8fb77b0c0000 pid=3195 execve guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196 execve guuid=c32d55de-1c00-0000-6151-8fb7810c0000 pid=3201 /usr/bin/wget net send-data guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=c32d55de-1c00-0000-6151-8fb7810c0000 pid=3201 execve guuid=5097bbe1-1c00-0000-6151-8fb7880c0000 pid=3208 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=5097bbe1-1c00-0000-6151-8fb7880c0000 pid=3208 execve guuid=08eb03ea-1c00-0000-6151-8fb7930c0000 pid=3219 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=08eb03ea-1c00-0000-6151-8fb7930c0000 pid=3219 clone guuid=d40d3eea-1c00-0000-6151-8fb7940c0000 pid=3220 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=d40d3eea-1c00-0000-6151-8fb7940c0000 pid=3220 execve guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221 execve guuid=0af369eb-1c00-0000-6151-8fb7990c0000 pid=3225 /usr/bin/wget net send-data guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=0af369eb-1c00-0000-6151-8fb7990c0000 pid=3225 execve guuid=041788ee-1c00-0000-6151-8fb79a0c0000 pid=3226 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=041788ee-1c00-0000-6151-8fb79a0c0000 pid=3226 execve guuid=c607f9f3-1c00-0000-6151-8fb79b0c0000 pid=3227 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=c607f9f3-1c00-0000-6151-8fb79b0c0000 pid=3227 clone guuid=1e0421f4-1c00-0000-6151-8fb79c0c0000 pid=3228 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=1e0421f4-1c00-0000-6151-8fb79c0c0000 pid=3228 execve guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229 execve guuid=b3ff40f5-1c00-0000-6151-8fb7a10c0000 pid=3233 /usr/bin/wget net send-data guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=b3ff40f5-1c00-0000-6151-8fb7a10c0000 pid=3233 execve guuid=358bfef8-1c00-0000-6151-8fb7a30c0000 pid=3235 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=358bfef8-1c00-0000-6151-8fb7a30c0000 pid=3235 execve guuid=7e02edfc-1c00-0000-6151-8fb7ac0c0000 pid=3244 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=7e02edfc-1c00-0000-6151-8fb7ac0c0000 pid=3244 clone guuid=bf3813fd-1c00-0000-6151-8fb7ad0c0000 pid=3245 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=bf3813fd-1c00-0000-6151-8fb7ad0c0000 pid=3245 execve guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247 execve guuid=8e628bfe-1c00-0000-6151-8fb7b30c0000 pid=3251 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=8e628bfe-1c00-0000-6151-8fb7b30c0000 pid=3251 execve guuid=2adedc02-1d00-0000-6151-8fb7be0c0000 pid=3262 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=2adedc02-1d00-0000-6151-8fb7be0c0000 pid=3262 execve guuid=881d4f07-1d00-0000-6151-8fb7c50c0000 pid=3269 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=881d4f07-1d00-0000-6151-8fb7c50c0000 pid=3269 clone guuid=7c3e7907-1d00-0000-6151-8fb7c60c0000 pid=3270 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=7c3e7907-1d00-0000-6151-8fb7c60c0000 pid=3270 execve guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271 execve guuid=6233b008-1d00-0000-6151-8fb7ce0c0000 pid=3278 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=6233b008-1d00-0000-6151-8fb7ce0c0000 pid=3278 execve guuid=a379a80c-1d00-0000-6151-8fb7d60c0000 pid=3286 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=a379a80c-1d00-0000-6151-8fb7d60c0000 pid=3286 execve guuid=0942fb15-1d00-0000-6151-8fb7d70c0000 pid=3287 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=0942fb15-1d00-0000-6151-8fb7d70c0000 pid=3287 clone guuid=15af2e16-1d00-0000-6151-8fb7d80c0000 pid=3288 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=15af2e16-1d00-0000-6151-8fb7d80c0000 pid=3288 execve guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289 execve guuid=49d46717-1d00-0000-6151-8fb7dd0c0000 pid=3293 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=49d46717-1d00-0000-6151-8fb7dd0c0000 pid=3293 execve guuid=64d65c1b-1d00-0000-6151-8fb7de0c0000 pid=3294 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=64d65c1b-1d00-0000-6151-8fb7de0c0000 pid=3294 execve guuid=eee7af20-1d00-0000-6151-8fb7df0c0000 pid=3295 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=eee7af20-1d00-0000-6151-8fb7df0c0000 pid=3295 clone guuid=85b0d020-1d00-0000-6151-8fb7e00c0000 pid=3296 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=85b0d020-1d00-0000-6151-8fb7e00c0000 pid=3296 execve guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297 execve guuid=6a680c22-1d00-0000-6151-8fb7e50c0000 pid=3301 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=6a680c22-1d00-0000-6151-8fb7e50c0000 pid=3301 execve guuid=72a82f28-1d00-0000-6151-8fb7ed0c0000 pid=3309 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=72a82f28-1d00-0000-6151-8fb7ed0c0000 pid=3309 execve guuid=fcd9092d-1d00-0000-6151-8fb7f50c0000 pid=3317 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=fcd9092d-1d00-0000-6151-8fb7f50c0000 pid=3317 clone guuid=6925292d-1d00-0000-6151-8fb7f60c0000 pid=3318 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=6925292d-1d00-0000-6151-8fb7f60c0000 pid=3318 execve guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319 execve guuid=ca09442e-1d00-0000-6151-8fb7fb0c0000 pid=3323 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=ca09442e-1d00-0000-6151-8fb7fb0c0000 pid=3323 execve guuid=4d74c933-1d00-0000-6151-8fb7020d0000 pid=3330 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=4d74c933-1d00-0000-6151-8fb7020d0000 pid=3330 execve guuid=7976d739-1d00-0000-6151-8fb7050d0000 pid=3333 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=7976d739-1d00-0000-6151-8fb7050d0000 pid=3333 clone guuid=3a85f839-1d00-0000-6151-8fb7060d0000 pid=3334 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=3a85f839-1d00-0000-6151-8fb7060d0000 pid=3334 execve guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335 execve guuid=83e60a3b-1d00-0000-6151-8fb70b0d0000 pid=3339 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=83e60a3b-1d00-0000-6151-8fb70b0d0000 pid=3339 execve guuid=cdd9cb3e-1d00-0000-6151-8fb7120d0000 pid=3346 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=cdd9cb3e-1d00-0000-6151-8fb7120d0000 pid=3346 execve guuid=3f3ca845-1d00-0000-6151-8fb71a0d0000 pid=3354 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=3f3ca845-1d00-0000-6151-8fb71a0d0000 pid=3354 clone guuid=2043c645-1d00-0000-6151-8fb71b0d0000 pid=3355 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=2043c645-1d00-0000-6151-8fb71b0d0000 pid=3355 execve guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356 execve guuid=e374a946-1d00-0000-6151-8fb7210d0000 pid=3361 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=e374a946-1d00-0000-6151-8fb7210d0000 pid=3361 execve guuid=ab4ad14b-1d00-0000-6151-8fb7290d0000 pid=3369 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=ab4ad14b-1d00-0000-6151-8fb7290d0000 pid=3369 execve guuid=3e74ae56-1d00-0000-6151-8fb73f0d0000 pid=3391 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=3e74ae56-1d00-0000-6151-8fb73f0d0000 pid=3391 clone guuid=884fc356-1d00-0000-6151-8fb7400d0000 pid=3392 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=884fc356-1d00-0000-6151-8fb7400d0000 pid=3392 execve guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395 execve guuid=88bbd057-1d00-0000-6151-8fb7490d0000 pid=3401 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=88bbd057-1d00-0000-6151-8fb7490d0000 pid=3401 execve guuid=17581d5d-1d00-0000-6151-8fb7570d0000 pid=3415 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=17581d5d-1d00-0000-6151-8fb7570d0000 pid=3415 execve guuid=f4aee564-1d00-0000-6151-8fb7690d0000 pid=3433 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=f4aee564-1d00-0000-6151-8fb7690d0000 pid=3433 clone guuid=4a43fe64-1d00-0000-6151-8fb76a0d0000 pid=3434 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=4a43fe64-1d00-0000-6151-8fb76a0d0000 pid=3434 execve guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437 execve guuid=819cfd65-1d00-0000-6151-8fb7730d0000 pid=3443 /usr/bin/wget net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=819cfd65-1d00-0000-6151-8fb7730d0000 pid=3443 execve guuid=b42bff6a-1d00-0000-6151-8fb77e0d0000 pid=3454 /usr/bin/curl net send-data write-file guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=b42bff6a-1d00-0000-6151-8fb77e0d0000 pid=3454 execve guuid=b0402b72-1d00-0000-6151-8fb7800d0000 pid=3456 /usr/bin/bash guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=b0402b72-1d00-0000-6151-8fb7800d0000 pid=3456 clone guuid=d28e5f72-1d00-0000-6151-8fb7810d0000 pid=3457 /usr/bin/chmod guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=d28e5f72-1d00-0000-6151-8fb7810d0000 pid=3457 execve guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458 /tmp/WTF net guuid=0c5353a9-1c00-0000-6151-8fb7f80b0000 pid=3064->guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458 execve 716e1aec-1753-5783-abc9-55dd603a7708 176.65.139.116:80 guuid=0f6e55af-1c00-0000-6151-8fb70c0c0000 pid=3084->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=e92b04b7-1c00-0000-6151-8fb71a0c0000 pid=3098->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc2e7ec2-1c00-0000-6151-8fb7340c0000 pid=3124 /tmp/WTF guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122->guuid=bc2e7ec2-1c00-0000-6151-8fb7340c0000 pid=3124 clone guuid=402483c2-1c00-0000-6151-8fb7350c0000 pid=3125 /tmp/WTF guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122->guuid=402483c2-1c00-0000-6151-8fb7350c0000 pid=3125 clone guuid=ab908cc2-1c00-0000-6151-8fb7370c0000 pid=3127 /tmp/WTF net send-data zombie guuid=ffbbddc1-1c00-0000-6151-8fb7320c0000 pid=3122->guuid=ab908cc2-1c00-0000-6151-8fb7370c0000 pid=3127 clone guuid=ab908cc2-1c00-0000-6151-8fb7370c0000 pid=3127->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con cb36c0d4-3a93-5be1-b5a6-766520e9e66f 176.65.139.116:3778 guuid=ab908cc2-1c00-0000-6151-8fb7370c0000 pid=3127->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=b8349ec2-1c00-0000-6151-8fb7380c0000 pid=3128->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=5b8372c8-1c00-0000-6151-8fb7440c0000 pid=3140->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=03ef58d1-1c00-0000-6151-8fb75d0c0000 pid=3165 /tmp/WTF guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163->guuid=03ef58d1-1c00-0000-6151-8fb75d0c0000 pid=3165 clone guuid=cac35dd1-1c00-0000-6151-8fb75e0c0000 pid=3166 /tmp/WTF guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163->guuid=cac35dd1-1c00-0000-6151-8fb75e0c0000 pid=3166 clone guuid=607868d1-1c00-0000-6151-8fb75f0c0000 pid=3167 /tmp/WTF net send-data zombie guuid=fedecbd0-1c00-0000-6151-8fb75b0c0000 pid=3163->guuid=607868d1-1c00-0000-6151-8fb75f0c0000 pid=3167 clone guuid=607868d1-1c00-0000-6151-8fb75f0c0000 pid=3167->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=607868d1-1c00-0000-6151-8fb75f0c0000 pid=3167->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=ce7477d1-1c00-0000-6151-8fb7600c0000 pid=3168->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=1b050dd7-1c00-0000-6151-8fb76f0c0000 pid=3183->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=94fe30de-1c00-0000-6151-8fb77e0c0000 pid=3198 /tmp/WTF guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196->guuid=94fe30de-1c00-0000-6151-8fb77e0c0000 pid=3198 clone guuid=241f37de-1c00-0000-6151-8fb77f0c0000 pid=3199 /tmp/WTF guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196->guuid=241f37de-1c00-0000-6151-8fb77f0c0000 pid=3199 clone guuid=43ae3ade-1c00-0000-6151-8fb7800c0000 pid=3200 /tmp/WTF net send-data zombie guuid=a997aedd-1c00-0000-6151-8fb77c0c0000 pid=3196->guuid=43ae3ade-1c00-0000-6151-8fb7800c0000 pid=3200 clone guuid=43ae3ade-1c00-0000-6151-8fb7800c0000 pid=3200->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=43ae3ade-1c00-0000-6151-8fb7800c0000 pid=3200->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=c32d55de-1c00-0000-6151-8fb7810c0000 pid=3201->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=5097bbe1-1c00-0000-6151-8fb7880c0000 pid=3208->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cce149eb-1c00-0000-6151-8fb7960c0000 pid=3222 /tmp/WTF guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221->guuid=cce149eb-1c00-0000-6151-8fb7960c0000 pid=3222 clone guuid=e8a850eb-1c00-0000-6151-8fb7970c0000 pid=3223 /tmp/WTF guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221->guuid=e8a850eb-1c00-0000-6151-8fb7970c0000 pid=3223 clone guuid=5d9555eb-1c00-0000-6151-8fb7980c0000 pid=3224 /tmp/WTF net send-data zombie guuid=bfb0a3ea-1c00-0000-6151-8fb7950c0000 pid=3221->guuid=5d9555eb-1c00-0000-6151-8fb7980c0000 pid=3224 clone guuid=5d9555eb-1c00-0000-6151-8fb7980c0000 pid=3224->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5d9555eb-1c00-0000-6151-8fb7980c0000 pid=3224->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=0af369eb-1c00-0000-6151-8fb7990c0000 pid=3225->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=041788ee-1c00-0000-6151-8fb79a0c0000 pid=3226->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=40b621f5-1c00-0000-6151-8fb79e0c0000 pid=3230 /tmp/WTF guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229->guuid=40b621f5-1c00-0000-6151-8fb79e0c0000 pid=3230 clone guuid=82aa29f5-1c00-0000-6151-8fb79f0c0000 pid=3231 /tmp/WTF guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229->guuid=82aa29f5-1c00-0000-6151-8fb79f0c0000 pid=3231 clone guuid=62e22ef5-1c00-0000-6151-8fb7a00c0000 pid=3232 /tmp/WTF net send-data zombie guuid=f4e086f4-1c00-0000-6151-8fb79d0c0000 pid=3229->guuid=62e22ef5-1c00-0000-6151-8fb7a00c0000 pid=3232 clone guuid=62e22ef5-1c00-0000-6151-8fb7a00c0000 pid=3232->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62e22ef5-1c00-0000-6151-8fb7a00c0000 pid=3232->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=b3ff40f5-1c00-0000-6151-8fb7a10c0000 pid=3233->716e1aec-1753-5783-abc9-55dd603a7708 send: 153B guuid=358bfef8-1c00-0000-6151-8fb7a30c0000 pid=3235->716e1aec-1753-5783-abc9-55dd603a7708 send: 102B guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6c9954fe-1c00-0000-6151-8fb7b00c0000 pid=3248 /tmp/WTF guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247->guuid=6c9954fe-1c00-0000-6151-8fb7b00c0000 pid=3248 clone guuid=f75d5ffe-1c00-0000-6151-8fb7b10c0000 pid=3249 /tmp/WTF guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247->guuid=f75d5ffe-1c00-0000-6151-8fb7b10c0000 pid=3249 clone guuid=ce4c67fe-1c00-0000-6151-8fb7b20c0000 pid=3250 /tmp/WTF net send-data zombie guuid=72565efd-1c00-0000-6151-8fb7af0c0000 pid=3247->guuid=ce4c67fe-1c00-0000-6151-8fb7b20c0000 pid=3250 clone guuid=ce4c67fe-1c00-0000-6151-8fb7b20c0000 pid=3250->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ce4c67fe-1c00-0000-6151-8fb7b20c0000 pid=3250->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=8e628bfe-1c00-0000-6151-8fb7b30c0000 pid=3251->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=2adedc02-1d00-0000-6151-8fb7be0c0000 pid=3262->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e5929108-1d00-0000-6151-8fb7ca0c0000 pid=3274 /tmp/WTF guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271->guuid=e5929108-1d00-0000-6151-8fb7ca0c0000 pid=3274 clone guuid=ee1e9808-1d00-0000-6151-8fb7cb0c0000 pid=3275 /tmp/WTF guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271->guuid=ee1e9808-1d00-0000-6151-8fb7cb0c0000 pid=3275 clone guuid=a8ec9e08-1d00-0000-6151-8fb7cc0c0000 pid=3276 /tmp/WTF net send-data zombie guuid=603ae707-1d00-0000-6151-8fb7c70c0000 pid=3271->guuid=a8ec9e08-1d00-0000-6151-8fb7cc0c0000 pid=3276 clone guuid=a8ec9e08-1d00-0000-6151-8fb7cc0c0000 pid=3276->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a8ec9e08-1d00-0000-6151-8fb7cc0c0000 pid=3276->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=6233b008-1d00-0000-6151-8fb7ce0c0000 pid=3278->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=a379a80c-1d00-0000-6151-8fb7d60c0000 pid=3286->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=09024717-1d00-0000-6151-8fb7da0c0000 pid=3290 /tmp/WTF guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289->guuid=09024717-1d00-0000-6151-8fb7da0c0000 pid=3290 clone guuid=26b34e17-1d00-0000-6151-8fb7db0c0000 pid=3291 /tmp/WTF guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289->guuid=26b34e17-1d00-0000-6151-8fb7db0c0000 pid=3291 clone guuid=e93f5517-1d00-0000-6151-8fb7dc0c0000 pid=3292 /tmp/WTF net send-data zombie guuid=3c68ab16-1d00-0000-6151-8fb7d90c0000 pid=3289->guuid=e93f5517-1d00-0000-6151-8fb7dc0c0000 pid=3292 clone guuid=e93f5517-1d00-0000-6151-8fb7dc0c0000 pid=3292->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e93f5517-1d00-0000-6151-8fb7dc0c0000 pid=3292->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=49d46717-1d00-0000-6151-8fb7dd0c0000 pid=3293->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=64d65c1b-1d00-0000-6151-8fb7de0c0000 pid=3294->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=19b3e321-1d00-0000-6151-8fb7e20c0000 pid=3298 /tmp/WTF guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297->guuid=19b3e321-1d00-0000-6151-8fb7e20c0000 pid=3298 clone guuid=5019e921-1d00-0000-6151-8fb7e30c0000 pid=3299 /tmp/WTF guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297->guuid=5019e921-1d00-0000-6151-8fb7e30c0000 pid=3299 clone guuid=64baee21-1d00-0000-6151-8fb7e40c0000 pid=3300 /tmp/WTF net send-data zombie guuid=c5324821-1d00-0000-6151-8fb7e10c0000 pid=3297->guuid=64baee21-1d00-0000-6151-8fb7e40c0000 pid=3300 clone guuid=64baee21-1d00-0000-6151-8fb7e40c0000 pid=3300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=64baee21-1d00-0000-6151-8fb7e40c0000 pid=3300->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=6a680c22-1d00-0000-6151-8fb7e50c0000 pid=3301->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=72a82f28-1d00-0000-6151-8fb7ed0c0000 pid=3309->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7875272e-1d00-0000-6151-8fb7f80c0000 pid=3320 /tmp/WTF guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319->guuid=7875272e-1d00-0000-6151-8fb7f80c0000 pid=3320 clone guuid=0b102b2e-1d00-0000-6151-8fb7f90c0000 pid=3321 /tmp/WTF guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319->guuid=0b102b2e-1d00-0000-6151-8fb7f90c0000 pid=3321 clone guuid=56462f2e-1d00-0000-6151-8fb7fa0c0000 pid=3322 /tmp/WTF net send-data zombie guuid=8909812d-1d00-0000-6151-8fb7f70c0000 pid=3319->guuid=56462f2e-1d00-0000-6151-8fb7fa0c0000 pid=3322 clone guuid=56462f2e-1d00-0000-6151-8fb7fa0c0000 pid=3322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=56462f2e-1d00-0000-6151-8fb7fa0c0000 pid=3322->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=ca09442e-1d00-0000-6151-8fb7fb0c0000 pid=3323->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=4d74c933-1d00-0000-6151-8fb7020d0000 pid=3330->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cb51ef3a-1d00-0000-6151-8fb7080d0000 pid=3336 /tmp/WTF guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335->guuid=cb51ef3a-1d00-0000-6151-8fb7080d0000 pid=3336 clone guuid=a919f43a-1d00-0000-6151-8fb7090d0000 pid=3337 /tmp/WTF guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335->guuid=a919f43a-1d00-0000-6151-8fb7090d0000 pid=3337 clone guuid=28bcfb3a-1d00-0000-6151-8fb70a0d0000 pid=3338 /tmp/WTF net send-data zombie guuid=1c8c593a-1d00-0000-6151-8fb7070d0000 pid=3335->guuid=28bcfb3a-1d00-0000-6151-8fb70a0d0000 pid=3338 clone guuid=28bcfb3a-1d00-0000-6151-8fb70a0d0000 pid=3338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=28bcfb3a-1d00-0000-6151-8fb70a0d0000 pid=3338->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=83e60a3b-1d00-0000-6151-8fb70b0d0000 pid=3339->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=cdd9cb3e-1d00-0000-6151-8fb7120d0000 pid=3346->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=585b9546-1d00-0000-6151-8fb71e0d0000 pid=3358 /tmp/WTF guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356->guuid=585b9546-1d00-0000-6151-8fb71e0d0000 pid=3358 clone guuid=5c0c9946-1d00-0000-6151-8fb71f0d0000 pid=3359 /tmp/WTF guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356->guuid=5c0c9946-1d00-0000-6151-8fb71f0d0000 pid=3359 clone guuid=f6afa046-1d00-0000-6151-8fb7200d0000 pid=3360 /tmp/WTF net send-data zombie guuid=84df0f46-1d00-0000-6151-8fb71c0d0000 pid=3356->guuid=f6afa046-1d00-0000-6151-8fb7200d0000 pid=3360 clone guuid=f6afa046-1d00-0000-6151-8fb7200d0000 pid=3360->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f6afa046-1d00-0000-6151-8fb7200d0000 pid=3360->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=e374a946-1d00-0000-6151-8fb7210d0000 pid=3361->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=ab4ad14b-1d00-0000-6151-8fb7290d0000 pid=3369->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=de15bd57-1d00-0000-6151-8fb7460d0000 pid=3398 /tmp/WTF guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395->guuid=de15bd57-1d00-0000-6151-8fb7460d0000 pid=3398 clone guuid=5beec057-1d00-0000-6151-8fb7470d0000 pid=3399 /tmp/WTF guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395->guuid=5beec057-1d00-0000-6151-8fb7470d0000 pid=3399 clone guuid=46a8c657-1d00-0000-6151-8fb7480d0000 pid=3400 /tmp/WTF net send-data zombie guuid=37c83557-1d00-0000-6151-8fb7430d0000 pid=3395->guuid=46a8c657-1d00-0000-6151-8fb7480d0000 pid=3400 clone guuid=46a8c657-1d00-0000-6151-8fb7480d0000 pid=3400->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=46a8c657-1d00-0000-6151-8fb7480d0000 pid=3400->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=88bbd057-1d00-0000-6151-8fb7490d0000 pid=3401->716e1aec-1753-5783-abc9-55dd603a7708 send: 151B guuid=17581d5d-1d00-0000-6151-8fb7570d0000 pid=3415->716e1aec-1753-5783-abc9-55dd603a7708 send: 100B guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a810dd65-1d00-0000-6151-8fb76f0d0000 pid=3439 /tmp/WTF guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437->guuid=a810dd65-1d00-0000-6151-8fb76f0d0000 pid=3439 clone guuid=6749e165-1d00-0000-6151-8fb7700d0000 pid=3440 /tmp/WTF guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437->guuid=6749e165-1d00-0000-6151-8fb7700d0000 pid=3440 clone guuid=28b3e465-1d00-0000-6151-8fb7710d0000 pid=3441 /tmp/WTF net send-data zombie guuid=71424e65-1d00-0000-6151-8fb76d0d0000 pid=3437->guuid=28b3e465-1d00-0000-6151-8fb7710d0000 pid=3441 clone guuid=28b3e465-1d00-0000-6151-8fb7710d0000 pid=3441->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=28b3e465-1d00-0000-6151-8fb7710d0000 pid=3441->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B guuid=819cfd65-1d00-0000-6151-8fb7730d0000 pid=3443->716e1aec-1753-5783-abc9-55dd603a7708 send: 150B guuid=b42bff6a-1d00-0000-6151-8fb77e0d0000 pid=3454->716e1aec-1753-5783-abc9-55dd603a7708 send: 99B guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=14149473-1d00-0000-6151-8fb7830d0000 pid=3459 /tmp/WTF guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458->guuid=14149473-1d00-0000-6151-8fb7830d0000 pid=3459 clone guuid=df709873-1d00-0000-6151-8fb7840d0000 pid=3460 /tmp/WTF guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458->guuid=df709873-1d00-0000-6151-8fb7840d0000 pid=3460 clone guuid=866c9d73-1d00-0000-6151-8fb7850d0000 pid=3461 /tmp/WTF net send-data zombie guuid=1a80e572-1d00-0000-6151-8fb7820d0000 pid=3458->guuid=866c9d73-1d00-0000-6151-8fb7850d0000 pid=3461 clone guuid=866c9d73-1d00-0000-6151-8fb7850d0000 pid=3461->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=866c9d73-1d00-0000-6151-8fb7850d0000 pid=3461->cb36c0d4-3a93-5be1-b5a6-766520e9e66f send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-06-01 05:37:49 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Family: Mirai
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 79dfad940aa718395f04c71d5eb99fe87f2072ca1ce4d534c0e1847631f1375e

(this sample)

  
Delivery method
Distributed via web download

Comments