MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ac12224d300baa85a2ccb8becb3f9cc01c6165ea77a0f41cc17e14f6d7ea4185. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 2 File information Comments

SHA256 hash: ac12224d300baa85a2ccb8becb3f9cc01c6165ea77a0f41cc17e14f6d7ea4185
SHA3-384 hash: 99cc90104fabc5192debe9f6758216dba7bf530a1accff6c2644880a40ead52e8d7f07a56f6b9cd58d2db5c54da1312f
SHA1 hash: 747cb3c753e528c69a80fe2421aae8b5aa19fc86
MD5 hash: 242c5bd5126ac5b4d54ca6a97edf0678
humanhash: sierra-saturn-sodium-one
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'066 bytes
First seen:2026-03-31 12:29:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ZpdXdgUpdgndgwdpdoXdd7pdZd2updydL1pdDdsgpd7dUopd2dfppdvdo8pd2dfG:ZzNgUzgdgwdzoNd7zj2uzIL1zhsgzJU/
TLSH T1C751F4C445849E75ACB7EA52BAB6C21C7092A4C314DF7F9ADEC8B9E0858EE10F140793
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://176.65.139.59/hiddenbin/boatnet.aarch64f20991717b62d88a44b917df63021187bdee72b4c92a7773eb66531f86c3a43f Miraielf ua-wget
http://176.65.139.59/hiddenbin/boatnet.arccecaed0ffe519c83d77655e1c2f3409fa795fc97917fe9a258f2473b1f84788d Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.armv4l128396e00e8d7f3b3ae0ea8764c8d05448861a825e872d729013768537c0fdde Miraielf ua-wget
http://176.65.139.59/hiddenbin/boatnet.armv5l3f064c305e1210001e661ebc6154f3f4f71a1de02a495a70bb266cdb50997377 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.armv6l332e784b02746b3dd6054d71e22112fc4cede6384d4ef44ca447ccc34d84674f Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.armv7la7abb507c3fba818d313401ac9da83c6e7fc9a109f9dfc4e9c6b0d9d9703f6fa Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.i486d24964dbf3bdd5ad822bcd66f4207275c238cb940eff4628dad7c6559648bd22 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.m68kfb10cbce3b750290774de552141bdfee2b97f43c29b8a8e4be04fba0a2c0d5e7 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.mips5b6399acbc07e044107ef03c275b998306324f53f5442f4c243abdc8bcb27a07 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.mipsel72fc53134560249613c435b13044911019d1ea00b337f43fa539f21eb903b320 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.mipsroutere946662996cb04d86082d20460698495fc28cf36f9a876bb70185d986462d360 Miraielf ua-wget
http://176.65.139.59/hiddenbin/boatnet.powerpcab8e7ec76f4021ec7f0a2586d3a2d5bf27d1e78e531c07aa6c71afcb6b59a245 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.sh4c5fabb7238edaf7d1f9b477a492fc8bfa1bdb6137784dca152e6187ccc4b6cdb Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.sparc312c4ba029a605fae997860667eea6b46fdfacccd00c90b40f4b6dd392e6d304 Miraielf mirai ua-wget
http://176.65.139.59/hiddenbin/boatnet.x86_6436283e93299fb13567ff63d1ba6f1ae5a54a345473a6c30263ad45f61b2eb4b8 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Gathering data
Result
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-30T00:30:00Z UTC
Last seen:
2026-03-30T14:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c8f54d01-1e00-0000-9d77-cba2710c0000 pid=3185 /usr/bin/sudo guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193 /tmp/sample.bin guuid=c8f54d01-1e00-0000-9d77-cba2710c0000 pid=3185->guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193 execve guuid=bdf7fd05-1e00-0000-9d77-cba27a0c0000 pid=3194 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=bdf7fd05-1e00-0000-9d77-cba27a0c0000 pid=3194 execve guuid=df3e800e-1e00-0000-9d77-cba28b0c0000 pid=3211 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=df3e800e-1e00-0000-9d77-cba28b0c0000 pid=3211 execve guuid=ba7bd31a-1e00-0000-9d77-cba2960c0000 pid=3222 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=ba7bd31a-1e00-0000-9d77-cba2960c0000 pid=3222 execve guuid=9144d21b-1e00-0000-9d77-cba2970c0000 pid=3223 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=9144d21b-1e00-0000-9d77-cba2970c0000 pid=3223 execve guuid=a216a81c-1e00-0000-9d77-cba2980c0000 pid=3224 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=a216a81c-1e00-0000-9d77-cba2980c0000 pid=3224 clone guuid=8fb1581e-1e00-0000-9d77-cba29a0c0000 pid=3226 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=8fb1581e-1e00-0000-9d77-cba29a0c0000 pid=3226 execve guuid=e92ca624-1e00-0000-9d77-cba29b0c0000 pid=3227 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=e92ca624-1e00-0000-9d77-cba29b0c0000 pid=3227 execve guuid=9069ed2c-1e00-0000-9d77-cba29e0c0000 pid=3230 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=9069ed2c-1e00-0000-9d77-cba29e0c0000 pid=3230 execve guuid=2a86552d-1e00-0000-9d77-cba2a00c0000 pid=3232 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=2a86552d-1e00-0000-9d77-cba2a00c0000 pid=3232 execve guuid=1da6b02d-1e00-0000-9d77-cba2a20c0000 pid=3234 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1da6b02d-1e00-0000-9d77-cba2a20c0000 pid=3234 clone guuid=6c434e2e-1e00-0000-9d77-cba2a60c0000 pid=3238 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=6c434e2e-1e00-0000-9d77-cba2a60c0000 pid=3238 execve guuid=64e28d35-1e00-0000-9d77-cba2b00c0000 pid=3248 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=64e28d35-1e00-0000-9d77-cba2b00c0000 pid=3248 execve guuid=eb31723e-1e00-0000-9d77-cba2b70c0000 pid=3255 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=eb31723e-1e00-0000-9d77-cba2b70c0000 pid=3255 execve guuid=d120f13e-1e00-0000-9d77-cba2b80c0000 pid=3256 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=d120f13e-1e00-0000-9d77-cba2b80c0000 pid=3256 execve guuid=c38e653f-1e00-0000-9d77-cba2b90c0000 pid=3257 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=c38e653f-1e00-0000-9d77-cba2b90c0000 pid=3257 clone guuid=1a4cf341-1e00-0000-9d77-cba2bc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1a4cf341-1e00-0000-9d77-cba2bc0c0000 pid=3260 execve guuid=f7061c47-1e00-0000-9d77-cba2c50c0000 pid=3269 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=f7061c47-1e00-0000-9d77-cba2c50c0000 pid=3269 execve guuid=a4735550-1e00-0000-9d77-cba2d20c0000 pid=3282 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=a4735550-1e00-0000-9d77-cba2d20c0000 pid=3282 execve guuid=17a62251-1e00-0000-9d77-cba2d30c0000 pid=3283 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=17a62251-1e00-0000-9d77-cba2d30c0000 pid=3283 execve guuid=1ca6a451-1e00-0000-9d77-cba2d40c0000 pid=3284 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1ca6a451-1e00-0000-9d77-cba2d40c0000 pid=3284 clone guuid=a5627f52-1e00-0000-9d77-cba2d70c0000 pid=3287 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=a5627f52-1e00-0000-9d77-cba2d70c0000 pid=3287 execve guuid=9858e357-1e00-0000-9d77-cba2e20c0000 pid=3298 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=9858e357-1e00-0000-9d77-cba2e20c0000 pid=3298 execve guuid=be30a460-1e00-0000-9d77-cba2ef0c0000 pid=3311 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=be30a460-1e00-0000-9d77-cba2ef0c0000 pid=3311 execve guuid=25484861-1e00-0000-9d77-cba2f10c0000 pid=3313 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=25484861-1e00-0000-9d77-cba2f10c0000 pid=3313 execve guuid=2e7ee761-1e00-0000-9d77-cba2f30c0000 pid=3315 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=2e7ee761-1e00-0000-9d77-cba2f30c0000 pid=3315 clone guuid=2c8e7b63-1e00-0000-9d77-cba2f70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=2c8e7b63-1e00-0000-9d77-cba2f70c0000 pid=3319 execve guuid=49535d68-1e00-0000-9d77-cba2ff0c0000 pid=3327 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=49535d68-1e00-0000-9d77-cba2ff0c0000 pid=3327 execve guuid=1d63b46f-1e00-0000-9d77-cba20a0d0000 pid=3338 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1d63b46f-1e00-0000-9d77-cba20a0d0000 pid=3338 execve guuid=46175b70-1e00-0000-9d77-cba20c0d0000 pid=3340 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=46175b70-1e00-0000-9d77-cba20c0d0000 pid=3340 execve guuid=1fa5f070-1e00-0000-9d77-cba20e0d0000 pid=3342 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1fa5f070-1e00-0000-9d77-cba20e0d0000 pid=3342 clone guuid=54158e71-1e00-0000-9d77-cba2110d0000 pid=3345 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=54158e71-1e00-0000-9d77-cba2110d0000 pid=3345 execve guuid=37731176-1e00-0000-9d77-cba21e0d0000 pid=3358 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=37731176-1e00-0000-9d77-cba21e0d0000 pid=3358 execve guuid=4f25a47b-1e00-0000-9d77-cba22b0d0000 pid=3371 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=4f25a47b-1e00-0000-9d77-cba22b0d0000 pid=3371 execve guuid=e0d6007c-1e00-0000-9d77-cba22d0d0000 pid=3373 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=e0d6007c-1e00-0000-9d77-cba22d0d0000 pid=3373 execve guuid=4c3a617c-1e00-0000-9d77-cba22e0d0000 pid=3374 /tmp/WTF guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=4c3a617c-1e00-0000-9d77-cba22e0d0000 pid=3374 execve guuid=087c227d-1e00-0000-9d77-cba2320d0000 pid=3378 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=087c227d-1e00-0000-9d77-cba2320d0000 pid=3378 execve guuid=bfc46883-1e00-0000-9d77-cba23c0d0000 pid=3388 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=bfc46883-1e00-0000-9d77-cba23c0d0000 pid=3388 execve guuid=1bc4e68a-1e00-0000-9d77-cba24c0d0000 pid=3404 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1bc4e68a-1e00-0000-9d77-cba24c0d0000 pid=3404 execve guuid=a2bc5e8b-1e00-0000-9d77-cba24d0d0000 pid=3405 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=a2bc5e8b-1e00-0000-9d77-cba24d0d0000 pid=3405 execve guuid=d750a78b-1e00-0000-9d77-cba24f0d0000 pid=3407 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=d750a78b-1e00-0000-9d77-cba24f0d0000 pid=3407 clone guuid=4152338c-1e00-0000-9d77-cba2530d0000 pid=3411 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=4152338c-1e00-0000-9d77-cba2530d0000 pid=3411 execve guuid=19f88f91-1e00-0000-9d77-cba2610d0000 pid=3425 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=19f88f91-1e00-0000-9d77-cba2610d0000 pid=3425 execve guuid=d5677497-1e00-0000-9d77-cba2710d0000 pid=3441 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=d5677497-1e00-0000-9d77-cba2710d0000 pid=3441 execve guuid=5e0aec97-1e00-0000-9d77-cba2740d0000 pid=3444 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=5e0aec97-1e00-0000-9d77-cba2740d0000 pid=3444 execve guuid=0c3c4198-1e00-0000-9d77-cba2760d0000 pid=3446 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=0c3c4198-1e00-0000-9d77-cba2760d0000 pid=3446 clone guuid=dc04f198-1e00-0000-9d77-cba27a0d0000 pid=3450 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=dc04f198-1e00-0000-9d77-cba27a0d0000 pid=3450 execve guuid=2c83569e-1e00-0000-9d77-cba28a0d0000 pid=3466 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=2c83569e-1e00-0000-9d77-cba28a0d0000 pid=3466 execve guuid=b986afa4-1e00-0000-9d77-cba29e0d0000 pid=3486 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=b986afa4-1e00-0000-9d77-cba29e0d0000 pid=3486 execve guuid=3ff008a5-1e00-0000-9d77-cba2a00d0000 pid=3488 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=3ff008a5-1e00-0000-9d77-cba2a00d0000 pid=3488 execve guuid=236951a5-1e00-0000-9d77-cba2a20d0000 pid=3490 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=236951a5-1e00-0000-9d77-cba2a20d0000 pid=3490 clone guuid=771e30a6-1e00-0000-9d77-cba2a60d0000 pid=3494 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=771e30a6-1e00-0000-9d77-cba2a60d0000 pid=3494 execve guuid=00ae96ab-1e00-0000-9d77-cba2b70d0000 pid=3511 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=00ae96ab-1e00-0000-9d77-cba2b70d0000 pid=3511 execve guuid=675225b2-1e00-0000-9d77-cba2c80d0000 pid=3528 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=675225b2-1e00-0000-9d77-cba2c80d0000 pid=3528 execve guuid=f8c69fb2-1e00-0000-9d77-cba2cb0d0000 pid=3531 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=f8c69fb2-1e00-0000-9d77-cba2cb0d0000 pid=3531 execve guuid=7808e5b2-1e00-0000-9d77-cba2cd0d0000 pid=3533 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=7808e5b2-1e00-0000-9d77-cba2cd0d0000 pid=3533 clone guuid=9ee0b0b3-1e00-0000-9d77-cba2d10d0000 pid=3537 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=9ee0b0b3-1e00-0000-9d77-cba2d10d0000 pid=3537 execve guuid=eec908b9-1e00-0000-9d77-cba2df0d0000 pid=3551 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=eec908b9-1e00-0000-9d77-cba2df0d0000 pid=3551 execve guuid=85f95cbf-1e00-0000-9d77-cba2ed0d0000 pid=3565 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=85f95cbf-1e00-0000-9d77-cba2ed0d0000 pid=3565 execve guuid=80b9ebbf-1e00-0000-9d77-cba2ee0d0000 pid=3566 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=80b9ebbf-1e00-0000-9d77-cba2ee0d0000 pid=3566 execve guuid=931440c0-1e00-0000-9d77-cba2ef0d0000 pid=3567 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=931440c0-1e00-0000-9d77-cba2ef0d0000 pid=3567 clone guuid=fc4bd5c0-1e00-0000-9d77-cba2f10d0000 pid=3569 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=fc4bd5c0-1e00-0000-9d77-cba2f10d0000 pid=3569 execve guuid=150bd4c5-1e00-0000-9d77-cba2f50d0000 pid=3573 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=150bd4c5-1e00-0000-9d77-cba2f50d0000 pid=3573 execve guuid=1bb1c6cc-1e00-0000-9d77-cba2080e0000 pid=3592 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=1bb1c6cc-1e00-0000-9d77-cba2080e0000 pid=3592 execve guuid=89ac45cd-1e00-0000-9d77-cba2090e0000 pid=3593 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=89ac45cd-1e00-0000-9d77-cba2090e0000 pid=3593 execve guuid=f0a08fcd-1e00-0000-9d77-cba20c0e0000 pid=3596 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=f0a08fcd-1e00-0000-9d77-cba20c0e0000 pid=3596 clone guuid=aca117ce-1e00-0000-9d77-cba20f0e0000 pid=3599 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=aca117ce-1e00-0000-9d77-cba20f0e0000 pid=3599 execve guuid=3d5b4bd1-1e00-0000-9d77-cba2190e0000 pid=3609 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=3d5b4bd1-1e00-0000-9d77-cba2190e0000 pid=3609 execve guuid=78447ed6-1e00-0000-9d77-cba21f0e0000 pid=3615 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=78447ed6-1e00-0000-9d77-cba21f0e0000 pid=3615 execve guuid=ffdc0cd7-1e00-0000-9d77-cba2210e0000 pid=3617 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=ffdc0cd7-1e00-0000-9d77-cba2210e0000 pid=3617 execve guuid=59348ad7-1e00-0000-9d77-cba2230e0000 pid=3619 /usr/bin/bash guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=59348ad7-1e00-0000-9d77-cba2230e0000 pid=3619 clone guuid=692b8bd8-1e00-0000-9d77-cba2270e0000 pid=3623 /usr/bin/wget net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=692b8bd8-1e00-0000-9d77-cba2270e0000 pid=3623 execve guuid=76a2ebdc-1e00-0000-9d77-cba2340e0000 pid=3636 /usr/bin/curl net send-data write-file guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=76a2ebdc-1e00-0000-9d77-cba2340e0000 pid=3636 execve guuid=cf4092e2-1e00-0000-9d77-cba2450e0000 pid=3653 /usr/bin/cat guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=cf4092e2-1e00-0000-9d77-cba2450e0000 pid=3653 execve guuid=ddcde9e2-1e00-0000-9d77-cba2460e0000 pid=3654 /usr/bin/chmod guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=ddcde9e2-1e00-0000-9d77-cba2460e0000 pid=3654 execve guuid=c1cd31e3-1e00-0000-9d77-cba2480e0000 pid=3656 /tmp/WTF mprotect-exec guuid=73a0c604-1e00-0000-9d77-cba2790c0000 pid=3193->guuid=c1cd31e3-1e00-0000-9d77-cba2480e0000 pid=3656 execve 2518ac35-7c39-5ae3-902e-6b81291bcee9 176.65.139.59:80 guuid=bdf7fd05-1e00-0000-9d77-cba27a0c0000 pid=3194->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 153B guuid=df3e800e-1e00-0000-9d77-cba28b0c0000 pid=3211->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 102B guuid=8fb1581e-1e00-0000-9d77-cba29a0c0000 pid=3226->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 149B guuid=e92ca624-1e00-0000-9d77-cba29b0c0000 pid=3227->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 98B guuid=6c434e2e-1e00-0000-9d77-cba2a60c0000 pid=3238->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=64e28d35-1e00-0000-9d77-cba2b00c0000 pid=3248->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=1a4cf341-1e00-0000-9d77-cba2bc0c0000 pid=3260->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=f7061c47-1e00-0000-9d77-cba2c50c0000 pid=3269->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=a5627f52-1e00-0000-9d77-cba2d70c0000 pid=3287->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=9858e357-1e00-0000-9d77-cba2e20c0000 pid=3298->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=2c8e7b63-1e00-0000-9d77-cba2f70c0000 pid=3319->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=49535d68-1e00-0000-9d77-cba2ff0c0000 pid=3327->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=54158e71-1e00-0000-9d77-cba2110d0000 pid=3345->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 150B guuid=37731176-1e00-0000-9d77-cba21e0d0000 pid=3358->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 99B guuid=de0c0e7d-1e00-0000-9d77-cba2300d0000 pid=3376 /tmp/WTF guuid=4c3a617c-1e00-0000-9d77-cba22e0d0000 pid=3374->guuid=de0c0e7d-1e00-0000-9d77-cba2300d0000 pid=3376 clone guuid=4a7c187d-1e00-0000-9d77-cba2310d0000 pid=3377 /tmp/WTF delete-file net zombie guuid=de0c0e7d-1e00-0000-9d77-cba2300d0000 pid=3376->guuid=4a7c187d-1e00-0000-9d77-cba2310d0000 pid=3377 clone 6cdce850-6721-50ff-8214-b4bd2153b5f4 176.65.139.59:7080 guuid=4a7c187d-1e00-0000-9d77-cba2310d0000 pid=3377->6cdce850-6721-50ff-8214-b4bd2153b5f4 con guuid=087c227d-1e00-0000-9d77-cba2320d0000 pid=3378->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 150B guuid=bfc46883-1e00-0000-9d77-cba23c0d0000 pid=3388->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 99B guuid=4152338c-1e00-0000-9d77-cba2530d0000 pid=3411->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 150B guuid=19f88f91-1e00-0000-9d77-cba2610d0000 pid=3425->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 99B guuid=dc04f198-1e00-0000-9d77-cba27a0d0000 pid=3450->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=2c83569e-1e00-0000-9d77-cba28a0d0000 pid=3466->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=771e30a6-1e00-0000-9d77-cba2a60d0000 pid=3494->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 156B guuid=00ae96ab-1e00-0000-9d77-cba2b70d0000 pid=3511->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 105B guuid=9ee0b0b3-1e00-0000-9d77-cba2d10d0000 pid=3537->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 153B guuid=eec908b9-1e00-0000-9d77-cba2df0d0000 pid=3551->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 102B guuid=fc4bd5c0-1e00-0000-9d77-cba2f10d0000 pid=3569->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 149B guuid=150bd4c5-1e00-0000-9d77-cba2f50d0000 pid=3573->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 98B guuid=aca117ce-1e00-0000-9d77-cba20f0e0000 pid=3599->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 151B guuid=3d5b4bd1-1e00-0000-9d77-cba2190e0000 pid=3609->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 100B guuid=692b8bd8-1e00-0000-9d77-cba2270e0000 pid=3623->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 152B guuid=76a2ebdc-1e00-0000-9d77-cba2340e0000 pid=3636->2518ac35-7c39-5ae3-902e-6b81291bcee9 send: 101B guuid=c5ebe3e3-1e00-0000-9d77-cba2490e0000 pid=3657 /tmp/WTF zombie guuid=c1cd31e3-1e00-0000-9d77-cba2480e0000 pid=3656->guuid=c5ebe3e3-1e00-0000-9d77-cba2490e0000 pid=3657 clone guuid=42e2e9e3-1e00-0000-9d77-cba24a0e0000 pid=3658 /tmp/WTF delete-file net zombie guuid=c5ebe3e3-1e00-0000-9d77-cba2490e0000 pid=3657->guuid=42e2e9e3-1e00-0000-9d77-cba24a0e0000 pid=3658 clone guuid=42e2e9e3-1e00-0000-9d77-cba24a0e0000 pid=3658->6cdce850-6721-50ff-8214-b4bd2153b5f4 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-03-30 05:26:32 UTC
File Type:
Text (Shell)
AV detection:
21 of 36 (58.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
UPX packed file
Enumerates running processes
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ac12224d300baa85a2ccb8becb3f9cc01c6165ea77a0f41cc17e14f6d7ea4185

(this sample)

  
Delivery method
Distributed via web download

Comments