MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 882a875428a2c1b7210d249d85705cd4e6789ec46d5d3f41e512981e662e9b6e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: 882a875428a2c1b7210d249d85705cd4e6789ec46d5d3f41e512981e662e9b6e
SHA3-384 hash: 64bd801057616520b44a5b554743c5fb7f307377bbb449b0ad501d2e738e291e0d79355de551e96097f37aba5c1848d3
SHA1 hash: 8c7b4ae83e06eb6dd4502dfd5f6ee419b1ab3561
MD5 hash: 7d3685608892d212c489a60fbcf3c156
humanhash: mississippi-uranus-mike-social
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2026-03-17 20:14:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vp27027N7hp2v26Gp2gn2zPp2f2KWp212oUp27127o7Up2fO23bp2E29Rp2h2cgJ:vI7R7N7hI+6GIg2zPIuKWIMoUI7M7o7Y
TLSH T10851D5C592846C326CB7EA23F7B6C12CB081909319EE7F99DDC8BBE4868ED247540753
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.43/hiddenbin/boatnet.x869ad270e9ffe43aa57d6590d4720d1844208133173f77e25754006869032bb284 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.mips037d4cd4887d7e75a29b6ec338cc0f82625e34b5bb7f8868a87a7f2964f70eaa Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.arcn/an/aelf ua-wget
http://176.65.139.43/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://176.65.139.43/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://176.65.139.43/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://176.65.139.43/hiddenbin/boatnet.mpsl50c08680a361540919fc4b51a3c9832e1fdc1c7f0bf3b26d5895d3371bf34712 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.armb96e78ad21ffe8f21f45539fa0b5f197959448377ca7ba23ce76bab6c097f350 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.arm51f1ab7b92a9c3e9d2bca87bc0636a366a10495c7e13bcf319f51a9bd6768d3c2 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.arm68b760b930d47039552b9472dd01effc5e14a5b316602208b219e126fc929501f Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.arm776f9f2ceca29648448664c901a5de2432ed044f2056aa32aeaa3791cb5f9c4b5 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.ppcd462edb1cdf9c42d77865d7c11efc729ff0b1c171416b88ed3a546fd0416c701 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.spcd808d185e6847d49a5322f70366bb2420b1eb3594173f3ad5f7225a06e18a0d2 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.m68k646ed823a06ae53ac9c9117f68520916e67468bfa0ef6412c35682743cab5819 Miraielf mirai ua-wget
http://176.65.139.43/hiddenbin/boatnet.sh431e99d70ba545d8b07a297e3a8eddd16f9619ca7f305c7b3b9500f941d2d9294 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=03e10dc0-1900-0000-816f-a35f4e0a0000 pid=2638 /usr/bin/sudo guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645 /tmp/sample.bin guuid=03e10dc0-1900-0000-816f-a35f4e0a0000 pid=2638->guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645 execve guuid=00f871c3-1900-0000-816f-a35f580a0000 pid=2648 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=00f871c3-1900-0000-816f-a35f580a0000 pid=2648 execve guuid=0a1623ca-1900-0000-816f-a35f690a0000 pid=2665 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0a1623ca-1900-0000-816f-a35f690a0000 pid=2665 execve guuid=c72fa5d0-1900-0000-816f-a35f790a0000 pid=2681 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=c72fa5d0-1900-0000-816f-a35f790a0000 pid=2681 execve guuid=0d9a2ed1-1900-0000-816f-a35f7b0a0000 pid=2683 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0d9a2ed1-1900-0000-816f-a35f7b0a0000 pid=2683 execve guuid=dc06a4d1-1900-0000-816f-a35f7c0a0000 pid=2684 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=dc06a4d1-1900-0000-816f-a35f7c0a0000 pid=2684 clone guuid=0fb8d8d1-1900-0000-816f-a35f7e0a0000 pid=2686 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0fb8d8d1-1900-0000-816f-a35f7e0a0000 pid=2686 execve guuid=a42cc3d4-1900-0000-816f-a35f860a0000 pid=2694 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=a42cc3d4-1900-0000-816f-a35f860a0000 pid=2694 execve guuid=56bfd8d9-1900-0000-816f-a35f930a0000 pid=2707 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=56bfd8d9-1900-0000-816f-a35f930a0000 pid=2707 execve guuid=59742bda-1900-0000-816f-a35f940a0000 pid=2708 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=59742bda-1900-0000-816f-a35f940a0000 pid=2708 execve guuid=f9636eda-1900-0000-816f-a35f960a0000 pid=2710 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=f9636eda-1900-0000-816f-a35f960a0000 pid=2710 clone guuid=38ea94da-1900-0000-816f-a35f980a0000 pid=2712 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=38ea94da-1900-0000-816f-a35f980a0000 pid=2712 execve guuid=ec7558dd-1900-0000-816f-a35fa00a0000 pid=2720 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=ec7558dd-1900-0000-816f-a35fa00a0000 pid=2720 execve guuid=8a8335e1-1900-0000-816f-a35fac0a0000 pid=2732 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=8a8335e1-1900-0000-816f-a35fac0a0000 pid=2732 execve guuid=9b3f88e1-1900-0000-816f-a35fae0a0000 pid=2734 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=9b3f88e1-1900-0000-816f-a35fae0a0000 pid=2734 execve guuid=6dcd03e2-1900-0000-816f-a35fb10a0000 pid=2737 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6dcd03e2-1900-0000-816f-a35fb10a0000 pid=2737 clone guuid=785236e2-1900-0000-816f-a35fb20a0000 pid=2738 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=785236e2-1900-0000-816f-a35fb20a0000 pid=2738 execve guuid=933d1ae6-1900-0000-816f-a35fbb0a0000 pid=2747 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=933d1ae6-1900-0000-816f-a35fbb0a0000 pid=2747 execve guuid=92cac9ea-1900-0000-816f-a35fc60a0000 pid=2758 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=92cac9ea-1900-0000-816f-a35fc60a0000 pid=2758 execve guuid=68d843eb-1900-0000-816f-a35fc90a0000 pid=2761 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=68d843eb-1900-0000-816f-a35fc90a0000 pid=2761 execve guuid=1c2ab5eb-1900-0000-816f-a35fcb0a0000 pid=2763 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=1c2ab5eb-1900-0000-816f-a35fcb0a0000 pid=2763 clone guuid=6e27e5eb-1900-0000-816f-a35fcc0a0000 pid=2764 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6e27e5eb-1900-0000-816f-a35fcc0a0000 pid=2764 execve guuid=410b5aef-1900-0000-816f-a35fd50a0000 pid=2773 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=410b5aef-1900-0000-816f-a35fd50a0000 pid=2773 execve guuid=6c2145f4-1900-0000-816f-a35fdc0a0000 pid=2780 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6c2145f4-1900-0000-816f-a35fdc0a0000 pid=2780 execve guuid=ef21d0f4-1900-0000-816f-a35fdd0a0000 pid=2781 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=ef21d0f4-1900-0000-816f-a35fdd0a0000 pid=2781 execve guuid=4f0640f5-1900-0000-816f-a35fde0a0000 pid=2782 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=4f0640f5-1900-0000-816f-a35fde0a0000 pid=2782 clone guuid=0a8b90f5-1900-0000-816f-a35fdf0a0000 pid=2783 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0a8b90f5-1900-0000-816f-a35fdf0a0000 pid=2783 execve guuid=ff8a6cf9-1900-0000-816f-a35fe90a0000 pid=2793 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=ff8a6cf9-1900-0000-816f-a35fe90a0000 pid=2793 execve guuid=5dbc30fe-1900-0000-816f-a35ff10a0000 pid=2801 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=5dbc30fe-1900-0000-816f-a35ff10a0000 pid=2801 execve guuid=0654cdfe-1900-0000-816f-a35ff30a0000 pid=2803 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0654cdfe-1900-0000-816f-a35ff30a0000 pid=2803 execve guuid=5c9c2cff-1900-0000-816f-a35ff50a0000 pid=2805 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=5c9c2cff-1900-0000-816f-a35ff50a0000 pid=2805 clone guuid=1f3567ff-1900-0000-816f-a35ff60a0000 pid=2806 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=1f3567ff-1900-0000-816f-a35ff60a0000 pid=2806 execve guuid=dd539804-1a00-0000-816f-a35ffc0a0000 pid=2812 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=dd539804-1a00-0000-816f-a35ffc0a0000 pid=2812 execve guuid=207ce809-1a00-0000-816f-a35f070b0000 pid=2823 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=207ce809-1a00-0000-816f-a35f070b0000 pid=2823 execve guuid=5eea730a-1a00-0000-816f-a35f080b0000 pid=2824 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=5eea730a-1a00-0000-816f-a35f080b0000 pid=2824 execve guuid=423bf60a-1a00-0000-816f-a35f090b0000 pid=2825 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=423bf60a-1a00-0000-816f-a35f090b0000 pid=2825 clone guuid=2b17270b-1a00-0000-816f-a35f0a0b0000 pid=2826 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=2b17270b-1a00-0000-816f-a35f0a0b0000 pid=2826 execve guuid=6476730e-1a00-0000-816f-a35f110b0000 pid=2833 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6476730e-1a00-0000-816f-a35f110b0000 pid=2833 execve guuid=21513715-1a00-0000-816f-a35f1d0b0000 pid=2845 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=21513715-1a00-0000-816f-a35f1d0b0000 pid=2845 execve guuid=cbe78515-1a00-0000-816f-a35f1f0b0000 pid=2847 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=cbe78515-1a00-0000-816f-a35f1f0b0000 pid=2847 execve guuid=0232cf15-1a00-0000-816f-a35f210b0000 pid=2849 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0232cf15-1a00-0000-816f-a35f210b0000 pid=2849 clone guuid=fb80f415-1a00-0000-816f-a35f220b0000 pid=2850 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=fb80f415-1a00-0000-816f-a35f220b0000 pid=2850 execve guuid=22cccf19-1a00-0000-816f-a35f270b0000 pid=2855 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=22cccf19-1a00-0000-816f-a35f270b0000 pid=2855 execve guuid=e5c3811f-1a00-0000-816f-a35f310b0000 pid=2865 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=e5c3811f-1a00-0000-816f-a35f310b0000 pid=2865 execve guuid=b51ae11f-1a00-0000-816f-a35f330b0000 pid=2867 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=b51ae11f-1a00-0000-816f-a35f330b0000 pid=2867 execve guuid=bb684d20-1a00-0000-816f-a35f350b0000 pid=2869 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=bb684d20-1a00-0000-816f-a35f350b0000 pid=2869 clone guuid=a18b7320-1a00-0000-816f-a35f360b0000 pid=2870 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=a18b7320-1a00-0000-816f-a35f360b0000 pid=2870 execve guuid=82128024-1a00-0000-816f-a35f3d0b0000 pid=2877 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=82128024-1a00-0000-816f-a35f3d0b0000 pid=2877 execve guuid=05abde28-1a00-0000-816f-a35f420b0000 pid=2882 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=05abde28-1a00-0000-816f-a35f420b0000 pid=2882 execve guuid=a75e4d29-1a00-0000-816f-a35f430b0000 pid=2883 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=a75e4d29-1a00-0000-816f-a35f430b0000 pid=2883 execve guuid=2c56c329-1a00-0000-816f-a35f450b0000 pid=2885 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=2c56c329-1a00-0000-816f-a35f450b0000 pid=2885 clone guuid=30e9022a-1a00-0000-816f-a35f470b0000 pid=2887 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=30e9022a-1a00-0000-816f-a35f470b0000 pid=2887 execve guuid=ebba1e2d-1a00-0000-816f-a35f4d0b0000 pid=2893 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=ebba1e2d-1a00-0000-816f-a35f4d0b0000 pid=2893 execve guuid=78801632-1a00-0000-816f-a35f550b0000 pid=2901 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=78801632-1a00-0000-816f-a35f550b0000 pid=2901 execve guuid=5ac27d32-1a00-0000-816f-a35f570b0000 pid=2903 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=5ac27d32-1a00-0000-816f-a35f570b0000 pid=2903 execve guuid=bf87fe32-1a00-0000-816f-a35f590b0000 pid=2905 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=bf87fe32-1a00-0000-816f-a35f590b0000 pid=2905 clone guuid=45d33033-1a00-0000-816f-a35f5b0b0000 pid=2907 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=45d33033-1a00-0000-816f-a35f5b0b0000 pid=2907 execve guuid=fa59d535-1a00-0000-816f-a35f630b0000 pid=2915 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=fa59d535-1a00-0000-816f-a35f630b0000 pid=2915 execve guuid=306fdf3f-1a00-0000-816f-a35f7f0b0000 pid=2943 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=306fdf3f-1a00-0000-816f-a35f7f0b0000 pid=2943 execve guuid=3f3e5640-1a00-0000-816f-a35f810b0000 pid=2945 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=3f3e5640-1a00-0000-816f-a35f810b0000 pid=2945 execve guuid=3e9cb340-1a00-0000-816f-a35f840b0000 pid=2948 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=3e9cb340-1a00-0000-816f-a35f840b0000 pid=2948 clone guuid=8e57ec40-1a00-0000-816f-a35f850b0000 pid=2949 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=8e57ec40-1a00-0000-816f-a35f850b0000 pid=2949 execve guuid=8a237643-1a00-0000-816f-a35f8f0b0000 pid=2959 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=8a237643-1a00-0000-816f-a35f8f0b0000 pid=2959 execve guuid=1a3c4247-1a00-0000-816f-a35f9b0b0000 pid=2971 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=1a3c4247-1a00-0000-816f-a35f9b0b0000 pid=2971 execve guuid=0e67a747-1a00-0000-816f-a35f9d0b0000 pid=2973 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=0e67a747-1a00-0000-816f-a35f9d0b0000 pid=2973 execve guuid=6c81f847-1a00-0000-816f-a35f9e0b0000 pid=2974 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6c81f847-1a00-0000-816f-a35f9e0b0000 pid=2974 clone guuid=a52a1848-1a00-0000-816f-a35fa00b0000 pid=2976 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=a52a1848-1a00-0000-816f-a35fa00b0000 pid=2976 execve guuid=8752ea4a-1a00-0000-816f-a35fa90b0000 pid=2985 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=8752ea4a-1a00-0000-816f-a35fa90b0000 pid=2985 execve guuid=fe28ef4f-1a00-0000-816f-a35faa0b0000 pid=2986 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=fe28ef4f-1a00-0000-816f-a35faa0b0000 pid=2986 execve guuid=a757e751-1a00-0000-816f-a35fab0b0000 pid=2987 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=a757e751-1a00-0000-816f-a35fab0b0000 pid=2987 execve guuid=1a3da652-1a00-0000-816f-a35fac0b0000 pid=2988 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=1a3da652-1a00-0000-816f-a35fac0b0000 pid=2988 clone guuid=6c43e752-1a00-0000-816f-a35fad0b0000 pid=2989 /usr/bin/wget net send-data guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=6c43e752-1a00-0000-816f-a35fad0b0000 pid=2989 execve guuid=20c4ed55-1a00-0000-816f-a35fb00b0000 pid=2992 /usr/bin/curl net send-data write-file guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=20c4ed55-1a00-0000-816f-a35fb00b0000 pid=2992 execve guuid=f38e185a-1a00-0000-816f-a35fbd0b0000 pid=3005 /usr/bin/cat guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=f38e185a-1a00-0000-816f-a35fbd0b0000 pid=3005 execve guuid=ec3d795a-1a00-0000-816f-a35fbf0b0000 pid=3007 /usr/bin/chmod guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=ec3d795a-1a00-0000-816f-a35fbf0b0000 pid=3007 execve guuid=209bd65a-1a00-0000-816f-a35fc00b0000 pid=3008 /usr/bin/bash guuid=e7f757c2-1900-0000-816f-a35f550a0000 pid=2645->guuid=209bd65a-1a00-0000-816f-a35fc00b0000 pid=3008 clone b10a62f5-be2b-57f9-8b7e-5f0b78c526bb 176.65.139.43:80 guuid=00f871c3-1900-0000-816f-a35f580a0000 pid=2648->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=0a1623ca-1900-0000-816f-a35f690a0000 pid=2665->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B guuid=0fb8d8d1-1900-0000-816f-a35f7e0a0000 pid=2686->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=a42cc3d4-1900-0000-816f-a35f860a0000 pid=2694->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=38ea94da-1900-0000-816f-a35f980a0000 pid=2712->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=ec7558dd-1900-0000-816f-a35fa00a0000 pid=2720->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B guuid=785236e2-1900-0000-816f-a35fb20a0000 pid=2738->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=933d1ae6-1900-0000-816f-a35fbb0a0000 pid=2747->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=6e27e5eb-1900-0000-816f-a35fcc0a0000 pid=2764->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=410b5aef-1900-0000-816f-a35fd50a0000 pid=2773->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=0a8b90f5-1900-0000-816f-a35fdf0a0000 pid=2783->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 152B guuid=ff8a6cf9-1900-0000-816f-a35fe90a0000 pid=2793->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 101B guuid=1f3567ff-1900-0000-816f-a35ff60a0000 pid=2806->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=dd539804-1a00-0000-816f-a35ffc0a0000 pid=2812->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=2b17270b-1a00-0000-816f-a35f0a0b0000 pid=2826->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=6476730e-1a00-0000-816f-a35f110b0000 pid=2833->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B guuid=fb80f415-1a00-0000-816f-a35f220b0000 pid=2850->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=22cccf19-1a00-0000-816f-a35f270b0000 pid=2855->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=a18b7320-1a00-0000-816f-a35f360b0000 pid=2870->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=82128024-1a00-0000-816f-a35f3d0b0000 pid=2877->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=30e9022a-1a00-0000-816f-a35f470b0000 pid=2887->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=ebba1e2d-1a00-0000-816f-a35f4d0b0000 pid=2893->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=45d33033-1a00-0000-816f-a35f5b0b0000 pid=2907->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=fa59d535-1a00-0000-816f-a35f630b0000 pid=2915->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B guuid=8e57ec40-1a00-0000-816f-a35f850b0000 pid=2949->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=8a237643-1a00-0000-816f-a35f8f0b0000 pid=2959->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B guuid=a52a1848-1a00-0000-816f-a35fa00b0000 pid=2976->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 150B guuid=8752ea4a-1a00-0000-816f-a35fa90b0000 pid=2985->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 99B guuid=6c43e752-1a00-0000-816f-a35fad0b0000 pid=2989->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 149B guuid=20c4ed55-1a00-0000-816f-a35fb00b0000 pid=2992->b10a62f5-be2b-57f9-8b7e-5f0b78c526bb send: 98B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-17 20:02:54 UTC
File Type:
Text (Shell)
AV detection:
18 of 24 (75.00%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Contacts a large (26718) amount of remote hosts
Creates a large amount of network flows
Mirai
Mirai family
Malware Config
C2 Extraction:
loxoxo.snoowy.top
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 882a875428a2c1b7210d249d85705cd4e6789ec46d5d3f41e512981e662e9b6e

(this sample)

  
Delivery method
Distributed via web download

Comments