MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7a3af59ee5db48d17799334c31d2fa9e6c819ea0f5dcfea3e10f689808286d2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: b7a3af59ee5db48d17799334c31d2fa9e6c819ea0f5dcfea3e10f689808286d2
SHA3-384 hash: 1f02554de1163dadc99300759075244fd8ca76de2e6c89c051c3e6d1b7fd80b5c903f9d237414ece9d75bc55948ba2db
SHA1 hash: 7dedea74c3cc0c2241bbe7c8972cb43be9174f9e
MD5 hash: ea06167acd0193e549c213ff7813ca4b
humanhash: item-monkey-oxygen-april
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2026-01-31 11:33:12 UTC
Last seen:2026-02-01 04:37:30 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vK7J7N7hKM6GKg0zPK8KWKOoUK7O7o7UKff3bKZ9RKycgKFpVK0SOKg+CKvfTK3U:vK7J7N7hKM6GKg0zPK8KWKOoUK7O7o74
TLSH T13B5165C6534A1E302CA3AE13F6F6452831C2D2A26CE5AB99EDDCBEE4434ED343142753
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.137.98.97/hiddenbin/boatnet.x861630c0ac8b151b87303be177d5e88405bdfbb20c4e093e65a8c24183752889e0 Miraielf ua-wget
http://45.137.98.97/hiddenbin/boatnet.mips9e6ec64dc19e5ddf7637b525d3efabb389310135eb7804324759301cadda2e43 Miraielf ua-wget
http://45.137.98.97/hiddenbin/boatnet.arcadb2385fba3898d961f892bee173eccecbca0966f4af2d3122b4b88a13f27cc3 Miraielf ua-wget
http://45.137.98.97/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://45.137.98.97/hiddenbin/boatnet.i6869d35cdb7e64c5c2b6b6414bbdb0ed673462eaae0d33ca1a13982076da3c14920 Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.x86_64b49b61a50bae2e33237dae317d4c13b3930b820ef7413dba7aa03843d045925a Mirai64-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.mpsl1a36cc27aad9710d84cae270e45d1a3316e26abe26fdca923c5cd9fcfdc25f18 Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.arm4d51d0159555abeaf7fe47c02edefb953d1ee27bd9085f8307fc81cbf6ebda0c Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.arm5d9ba9fb873fa21e81758486c9b84d6b4a733844958b5c752151715d6ebb1b0fe Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.arm62601ed454c19e82b3fc9c10f1b8e9f1c83cee1108ae86e34ab998527bf73488d Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.arm7c617e1eec0d27007dfeea31c3bcc40b849f66e531ffeaef18ecdbd694538cae0 Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.ppca2ded513c4266461de5786f3304cd28b0e9622815e279080052146f96b59bf63 Miraielf ua-wget
http://45.137.98.97/hiddenbin/boatnet.spc53ae423125c6fd4f48f6c1330bcd056c3f038bb35ef6b0c6d539ab87c5f0e8e6 Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.m68k1ca4d27101849db0b20b2e17b4cb430ca7f895c83df304e54bce4aea025e6667 Mirai32-bit elf mirai Mozi
http://45.137.98.97/hiddenbin/boatnet.sh49f105da2ffe133a582958a7c5bcdfddc4454216cef71fe7aec5e67a4002f88f9 Mirai32-bit elf mirai Mozi

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-01-30T07:41:00Z UTC
Last seen:
2026-01-31T15:45:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=827b8076-1600-0000-3705-2fcb800c0000 pid=3200 /usr/bin/sudo guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201 /tmp/sample.bin guuid=827b8076-1600-0000-3705-2fcb800c0000 pid=3200->guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201 execve guuid=8d94a079-1600-0000-3705-2fcb820c0000 pid=3202 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=8d94a079-1600-0000-3705-2fcb820c0000 pid=3202 execve guuid=0704da88-1600-0000-3705-2fcb830c0000 pid=3203 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=0704da88-1600-0000-3705-2fcb830c0000 pid=3203 execve guuid=189d979c-1600-0000-3705-2fcba10c0000 pid=3233 /usr/bin/cat guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=189d979c-1600-0000-3705-2fcba10c0000 pid=3233 execve guuid=eeb4179d-1600-0000-3705-2fcba30c0000 pid=3235 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=eeb4179d-1600-0000-3705-2fcba30c0000 pid=3235 execve guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238 execve guuid=6296069e-1600-0000-3705-2fcbab0c0000 pid=3243 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=6296069e-1600-0000-3705-2fcbab0c0000 pid=3243 execve guuid=fe916deb-1600-0000-3705-2fcb2b0d0000 pid=3371 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=fe916deb-1600-0000-3705-2fcb2b0d0000 pid=3371 execve guuid=a1ca75f9-1600-0000-3705-2fcb520d0000 pid=3410 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=a1ca75f9-1600-0000-3705-2fcb520d0000 pid=3410 clone guuid=c66c9ff9-1600-0000-3705-2fcb530d0000 pid=3411 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=c66c9ff9-1600-0000-3705-2fcb530d0000 pid=3411 execve guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413 execve guuid=95ff5dfa-1600-0000-3705-2fcb5a0d0000 pid=3418 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=95ff5dfa-1600-0000-3705-2fcb5a0d0000 pid=3418 execve guuid=6e3e1d2e-1700-0000-3705-2fcbcc0d0000 pid=3532 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=6e3e1d2e-1700-0000-3705-2fcbcc0d0000 pid=3532 execve guuid=560d0b55-1700-0000-3705-2fcb400e0000 pid=3648 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=560d0b55-1700-0000-3705-2fcb400e0000 pid=3648 clone guuid=fee62455-1700-0000-3705-2fcb420e0000 pid=3650 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=fee62455-1700-0000-3705-2fcb420e0000 pid=3650 execve guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652 execve guuid=66ee9f55-1700-0000-3705-2fcb490e0000 pid=3657 /usr/bin/wget net send-data guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=66ee9f55-1700-0000-3705-2fcb490e0000 pid=3657 execve guuid=d24d5d9a-1700-0000-3705-2fcb6b0f0000 pid=3947 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=d24d5d9a-1700-0000-3705-2fcb6b0f0000 pid=3947 execve guuid=8f8d40a1-1700-0000-3705-2fcb880f0000 pid=3976 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=8f8d40a1-1700-0000-3705-2fcb880f0000 pid=3976 clone guuid=481258a1-1700-0000-3705-2fcb890f0000 pid=3977 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=481258a1-1700-0000-3705-2fcb890f0000 pid=3977 execve guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979 execve guuid=ecaad7a1-1700-0000-3705-2fcb900f0000 pid=3984 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=ecaad7a1-1700-0000-3705-2fcb900f0000 pid=3984 execve guuid=478202b3-1700-0000-3705-2fcbca0f0000 pid=4042 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=478202b3-1700-0000-3705-2fcbca0f0000 pid=4042 execve guuid=180487c3-1700-0000-3705-2fcbef0f0000 pid=4079 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=180487c3-1700-0000-3705-2fcbef0f0000 pid=4079 clone guuid=8141aac3-1700-0000-3705-2fcbf00f0000 pid=4080 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=8141aac3-1700-0000-3705-2fcbf00f0000 pid=4080 execve guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082 execve guuid=9197a1c4-1700-0000-3705-2fcbf70f0000 pid=4087 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=9197a1c4-1700-0000-3705-2fcbf70f0000 pid=4087 execve guuid=db61ed17-1800-0000-3705-2fcbbe100000 pid=4286 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=db61ed17-1800-0000-3705-2fcbbe100000 pid=4286 execve guuid=c35d6c2a-1800-0000-3705-2fcbee100000 pid=4334 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=c35d6c2a-1800-0000-3705-2fcbee100000 pid=4334 clone guuid=3cd48c2a-1800-0000-3705-2fcbef100000 pid=4335 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=3cd48c2a-1800-0000-3705-2fcbef100000 pid=4335 execve guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337 execve guuid=9af8182b-1800-0000-3705-2fcbf6100000 pid=4342 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=9af8182b-1800-0000-3705-2fcbf6100000 pid=4342 execve guuid=1ea7b43e-1800-0000-3705-2fcb55110000 pid=4437 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=1ea7b43e-1800-0000-3705-2fcb55110000 pid=4437 execve guuid=4b44ad8c-1800-0000-3705-2fcb55120000 pid=4693 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=4b44ad8c-1800-0000-3705-2fcb55120000 pid=4693 clone guuid=710cdc8c-1800-0000-3705-2fcb56120000 pid=4694 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=710cdc8c-1800-0000-3705-2fcb56120000 pid=4694 execve guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696 execve guuid=1341058e-1800-0000-3705-2fcb5d120000 pid=4701 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=1341058e-1800-0000-3705-2fcb5d120000 pid=4701 execve guuid=790334a1-1800-0000-3705-2fcba7120000 pid=4775 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=790334a1-1800-0000-3705-2fcba7120000 pid=4775 execve guuid=fc125bb5-1800-0000-3705-2fcbf9120000 pid=4857 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=fc125bb5-1800-0000-3705-2fcbf9120000 pid=4857 clone guuid=271a79b5-1800-0000-3705-2fcbfb120000 pid=4859 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=271a79b5-1800-0000-3705-2fcbfb120000 pid=4859 execve guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861 execve guuid=289c0db6-1800-0000-3705-2fcb02130000 pid=4866 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=289c0db6-1800-0000-3705-2fcb02130000 pid=4866 execve guuid=3dc555c1-1800-0000-3705-2fcb28130000 pid=4904 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=3dc555c1-1800-0000-3705-2fcb28130000 pid=4904 execve guuid=1e0f42d0-1800-0000-3705-2fcb5e130000 pid=4958 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=1e0f42d0-1800-0000-3705-2fcb5e130000 pid=4958 clone guuid=29af5cd0-1800-0000-3705-2fcb5f130000 pid=4959 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=29af5cd0-1800-0000-3705-2fcb5f130000 pid=4959 execve guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961 execve guuid=ce0ce1d0-1800-0000-3705-2fcb67130000 pid=4967 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=ce0ce1d0-1800-0000-3705-2fcb67130000 pid=4967 execve guuid=be5cc2e0-1800-0000-3705-2fcb98130000 pid=5016 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=be5cc2e0-1800-0000-3705-2fcb98130000 pid=5016 execve guuid=7965c1f6-1800-0000-3705-2fcbc9130000 pid=5065 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=7965c1f6-1800-0000-3705-2fcbc9130000 pid=5065 clone guuid=c968f7f6-1800-0000-3705-2fcbcb130000 pid=5067 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=c968f7f6-1800-0000-3705-2fcbcb130000 pid=5067 execve guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068 execve guuid=e4b314f8-1800-0000-3705-2fcbd1130000 pid=5073 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=e4b314f8-1800-0000-3705-2fcbd1130000 pid=5073 execve guuid=1591910e-1900-0000-3705-2fcb0d140000 pid=5133 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=1591910e-1900-0000-3705-2fcb0d140000 pid=5133 execve guuid=0c7bfd23-1900-0000-3705-2fcb41140000 pid=5185 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=0c7bfd23-1900-0000-3705-2fcb41140000 pid=5185 clone guuid=ffce2924-1900-0000-3705-2fcb42140000 pid=5186 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=ffce2924-1900-0000-3705-2fcb42140000 pid=5186 execve guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188 execve guuid=83a72425-1900-0000-3705-2fcb49140000 pid=5193 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=83a72425-1900-0000-3705-2fcb49140000 pid=5193 execve guuid=09ef1332-1900-0000-3705-2fcb4b140000 pid=5195 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=09ef1332-1900-0000-3705-2fcb4b140000 pid=5195 execve guuid=f6fffd43-1900-0000-3705-2fcb68140000 pid=5224 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=f6fffd43-1900-0000-3705-2fcb68140000 pid=5224 clone guuid=86782b44-1900-0000-3705-2fcb69140000 pid=5225 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=86782b44-1900-0000-3705-2fcb69140000 pid=5225 execve guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227 execve guuid=70755645-1900-0000-3705-2fcb71140000 pid=5233 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=70755645-1900-0000-3705-2fcb71140000 pid=5233 execve guuid=0e522c5f-1900-0000-3705-2fcbb4140000 pid=5300 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=0e522c5f-1900-0000-3705-2fcbb4140000 pid=5300 execve guuid=82c6ae7d-1900-0000-3705-2fcbc0140000 pid=5312 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=82c6ae7d-1900-0000-3705-2fcbc0140000 pid=5312 clone guuid=bff0cc7d-1900-0000-3705-2fcbc1140000 pid=5313 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=bff0cc7d-1900-0000-3705-2fcbc1140000 pid=5313 execve guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314 execve guuid=f5ff807e-1900-0000-3705-2fcbc6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=f5ff807e-1900-0000-3705-2fcbc6140000 pid=5318 execve guuid=b3f3a292-1900-0000-3705-2fcbc7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=b3f3a292-1900-0000-3705-2fcbc7140000 pid=5319 execve guuid=edb32fa6-1900-0000-3705-2fcbc8140000 pid=5320 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=edb32fa6-1900-0000-3705-2fcbc8140000 pid=5320 clone guuid=1b644da6-1900-0000-3705-2fcbc9140000 pid=5321 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=1b644da6-1900-0000-3705-2fcbc9140000 pid=5321 execve guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322 execve guuid=c9c7e5a6-1900-0000-3705-2fcbce140000 pid=5326 /usr/bin/wget net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=c9c7e5a6-1900-0000-3705-2fcbce140000 pid=5326 execve guuid=b5f390bb-1900-0000-3705-2fcbcf140000 pid=5327 /usr/bin/curl net send-data write-file guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=b5f390bb-1900-0000-3705-2fcbcf140000 pid=5327 execve guuid=b24ba9ce-1900-0000-3705-2fcbd0140000 pid=5328 /usr/bin/bash guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=b24ba9ce-1900-0000-3705-2fcbd0140000 pid=5328 clone guuid=07bbcece-1900-0000-3705-2fcbd1140000 pid=5329 /usr/bin/chmod guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=07bbcece-1900-0000-3705-2fcbd1140000 pid=5329 execve guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330 /tmp/WTF net guuid=47819b78-1600-0000-3705-2fcb810c0000 pid=3201->guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330 execve 99f6939d-f237-5896-9717-09e3a5f03882 45.137.98.97:80 guuid=8d94a079-1600-0000-3705-2fcb820c0000 pid=3202->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=0704da88-1600-0000-3705-2fcb830c0000 pid=3203->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5821e69d-1600-0000-3705-2fcba70c0000 pid=3239 /tmp/WTF guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238->guuid=5821e69d-1600-0000-3705-2fcba70c0000 pid=3239 clone guuid=2c09ec9d-1600-0000-3705-2fcba90c0000 pid=3241 /tmp/WTF guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238->guuid=2c09ec9d-1600-0000-3705-2fcba90c0000 pid=3241 clone guuid=3baff19d-1600-0000-3705-2fcbaa0c0000 pid=3242 /tmp/WTF net send-data zombie guuid=cdab829d-1600-0000-3705-2fcba60c0000 pid=3238->guuid=3baff19d-1600-0000-3705-2fcbaa0c0000 pid=3242 clone guuid=3baff19d-1600-0000-3705-2fcbaa0c0000 pid=3242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 713032c8-f7c4-5455-b885-e4dbd87df246 45.137.98.97:3778 guuid=3baff19d-1600-0000-3705-2fcbaa0c0000 pid=3242->713032c8-f7c4-5455-b885-e4dbd87df246 send: 82B guuid=6296069e-1600-0000-3705-2fcbab0c0000 pid=3243->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=fe916deb-1600-0000-3705-2fcb2b0d0000 pid=3371->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=03bc49fa-1600-0000-3705-2fcb570d0000 pid=3415 /tmp/WTF guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413->guuid=03bc49fa-1600-0000-3705-2fcb570d0000 pid=3415 clone guuid=11644dfa-1600-0000-3705-2fcb580d0000 pid=3416 /tmp/WTF guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413->guuid=11644dfa-1600-0000-3705-2fcb580d0000 pid=3416 clone guuid=4b1c51fa-1600-0000-3705-2fcb590d0000 pid=3417 /tmp/WTF net send-data zombie guuid=8af302fa-1600-0000-3705-2fcb550d0000 pid=3413->guuid=4b1c51fa-1600-0000-3705-2fcb590d0000 pid=3417 clone guuid=4b1c51fa-1600-0000-3705-2fcb590d0000 pid=3417->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4b1c51fa-1600-0000-3705-2fcb590d0000 pid=3417->713032c8-f7c4-5455-b885-e4dbd87df246 send: 67B guuid=95ff5dfa-1600-0000-3705-2fcb5a0d0000 pid=3418->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=6e3e1d2e-1700-0000-3705-2fcbcc0d0000 pid=3532->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fa058b55-1700-0000-3705-2fcb450e0000 pid=3653 /tmp/WTF guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652->guuid=fa058b55-1700-0000-3705-2fcb450e0000 pid=3653 clone guuid=f1848e55-1700-0000-3705-2fcb460e0000 pid=3654 /tmp/WTF guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652->guuid=f1848e55-1700-0000-3705-2fcb460e0000 pid=3654 clone guuid=75af9355-1700-0000-3705-2fcb470e0000 pid=3655 /tmp/WTF net send-data zombie guuid=704a6255-1700-0000-3705-2fcb440e0000 pid=3652->guuid=75af9355-1700-0000-3705-2fcb470e0000 pid=3655 clone guuid=75af9355-1700-0000-3705-2fcb470e0000 pid=3655->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=75af9355-1700-0000-3705-2fcb470e0000 pid=3655->713032c8-f7c4-5455-b885-e4dbd87df246 send: 12B guuid=66ee9f55-1700-0000-3705-2fcb490e0000 pid=3657->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=d24d5d9a-1700-0000-3705-2fcb6b0f0000 pid=3947->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=532bc2a1-1700-0000-3705-2fcb8d0f0000 pid=3981 /tmp/WTF guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979->guuid=532bc2a1-1700-0000-3705-2fcb8d0f0000 pid=3981 clone guuid=9c47c5a1-1700-0000-3705-2fcb8e0f0000 pid=3982 /tmp/WTF guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979->guuid=9c47c5a1-1700-0000-3705-2fcb8e0f0000 pid=3982 clone guuid=4710cca1-1700-0000-3705-2fcb8f0f0000 pid=3983 /tmp/WTF net send-data zombie guuid=763c95a1-1700-0000-3705-2fcb8b0f0000 pid=3979->guuid=4710cca1-1700-0000-3705-2fcb8f0f0000 pid=3983 clone guuid=4710cca1-1700-0000-3705-2fcb8f0f0000 pid=3983->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4710cca1-1700-0000-3705-2fcb8f0f0000 pid=3983->713032c8-f7c4-5455-b885-e4dbd87df246 send: 122B guuid=ecaad7a1-1700-0000-3705-2fcb900f0000 pid=3984->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=478202b3-1700-0000-3705-2fcbca0f0000 pid=4042->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1ded76c4-1700-0000-3705-2fcbf40f0000 pid=4084 /tmp/WTF guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082->guuid=1ded76c4-1700-0000-3705-2fcbf40f0000 pid=4084 clone guuid=831d86c4-1700-0000-3705-2fcbf50f0000 pid=4085 /tmp/WTF guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082->guuid=831d86c4-1700-0000-3705-2fcbf50f0000 pid=4085 clone guuid=63e48cc4-1700-0000-3705-2fcbf60f0000 pid=4086 /tmp/WTF net send-data zombie guuid=4b9321c4-1700-0000-3705-2fcbf20f0000 pid=4082->guuid=63e48cc4-1700-0000-3705-2fcbf60f0000 pid=4086 clone guuid=63e48cc4-1700-0000-3705-2fcbf60f0000 pid=4086->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=63e48cc4-1700-0000-3705-2fcbf60f0000 pid=4086->713032c8-f7c4-5455-b885-e4dbd87df246 send: 17B guuid=9197a1c4-1700-0000-3705-2fcbf70f0000 pid=4087->99f6939d-f237-5896-9717-09e3a5f03882 send: 151B guuid=db61ed17-1800-0000-3705-2fcbbe100000 pid=4286->99f6939d-f237-5896-9717-09e3a5f03882 send: 100B guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0ce7072b-1800-0000-3705-2fcbf3100000 pid=4339 /tmp/WTF guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337->guuid=0ce7072b-1800-0000-3705-2fcbf3100000 pid=4339 clone guuid=353a0b2b-1800-0000-3705-2fcbf4100000 pid=4340 /tmp/WTF guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337->guuid=353a0b2b-1800-0000-3705-2fcbf4100000 pid=4340 clone guuid=f65c0e2b-1800-0000-3705-2fcbf5100000 pid=4341 /tmp/WTF net send-data zombie guuid=086dd72a-1800-0000-3705-2fcbf1100000 pid=4337->guuid=f65c0e2b-1800-0000-3705-2fcbf5100000 pid=4341 clone guuid=f65c0e2b-1800-0000-3705-2fcbf5100000 pid=4341->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f65c0e2b-1800-0000-3705-2fcbf5100000 pid=4341->713032c8-f7c4-5455-b885-e4dbd87df246 send: 122B guuid=9af8182b-1800-0000-3705-2fcbf6100000 pid=4342->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=1ea7b43e-1800-0000-3705-2fcb55110000 pid=4437->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=48dbdc8d-1800-0000-3705-2fcb5a120000 pid=4698 /tmp/WTF guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696->guuid=48dbdc8d-1800-0000-3705-2fcb5a120000 pid=4698 clone guuid=a708e38d-1800-0000-3705-2fcb5b120000 pid=4699 /tmp/WTF guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696->guuid=a708e38d-1800-0000-3705-2fcb5b120000 pid=4699 clone guuid=4e64ee8d-1800-0000-3705-2fcb5c120000 pid=4700 /tmp/WTF net send-data zombie guuid=bc357d8d-1800-0000-3705-2fcb58120000 pid=4696->guuid=4e64ee8d-1800-0000-3705-2fcb5c120000 pid=4700 clone guuid=4e64ee8d-1800-0000-3705-2fcb5c120000 pid=4700->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4e64ee8d-1800-0000-3705-2fcb5c120000 pid=4700->713032c8-f7c4-5455-b885-e4dbd87df246 send: 87B guuid=1341058e-1800-0000-3705-2fcb5d120000 pid=4701->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=790334a1-1800-0000-3705-2fcba7120000 pid=4775->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5326fdb5-1800-0000-3705-2fcbff120000 pid=4863 /tmp/WTF guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861->guuid=5326fdb5-1800-0000-3705-2fcbff120000 pid=4863 clone guuid=ce1e00b6-1800-0000-3705-2fcb00130000 pid=4864 /tmp/WTF guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861->guuid=ce1e00b6-1800-0000-3705-2fcb00130000 pid=4864 clone guuid=d44905b6-1800-0000-3705-2fcb01130000 pid=4865 /tmp/WTF net send-data zombie guuid=dcbcc0b5-1800-0000-3705-2fcbfd120000 pid=4861->guuid=d44905b6-1800-0000-3705-2fcb01130000 pid=4865 clone guuid=d44905b6-1800-0000-3705-2fcb01130000 pid=4865->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d44905b6-1800-0000-3705-2fcb01130000 pid=4865->713032c8-f7c4-5455-b885-e4dbd87df246 send: 27B guuid=289c0db6-1800-0000-3705-2fcb02130000 pid=4866->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=3dc555c1-1800-0000-3705-2fcb28130000 pid=4904->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0d5ecfd0-1800-0000-3705-2fcb63130000 pid=4963 /tmp/WTF guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961->guuid=0d5ecfd0-1800-0000-3705-2fcb63130000 pid=4963 clone guuid=42bbd3d0-1800-0000-3705-2fcb64130000 pid=4964 /tmp/WTF guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961->guuid=42bbd3d0-1800-0000-3705-2fcb64130000 pid=4964 clone guuid=e9efd6d0-1800-0000-3705-2fcb65130000 pid=4965 /tmp/WTF net send-data zombie guuid=d15aa2d0-1800-0000-3705-2fcb61130000 pid=4961->guuid=e9efd6d0-1800-0000-3705-2fcb65130000 pid=4965 clone guuid=e9efd6d0-1800-0000-3705-2fcb65130000 pid=4965->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e9efd6d0-1800-0000-3705-2fcb65130000 pid=4965->713032c8-f7c4-5455-b885-e4dbd87df246 send: 32B guuid=ce0ce1d0-1800-0000-3705-2fcb67130000 pid=4967->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=be5cc2e0-1800-0000-3705-2fcb98130000 pid=5016->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=993ef0f7-1800-0000-3705-2fcbce130000 pid=5070 /tmp/WTF guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068->guuid=993ef0f7-1800-0000-3705-2fcbce130000 pid=5070 clone guuid=ef61f6f7-1800-0000-3705-2fcbcf130000 pid=5071 /tmp/WTF guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068->guuid=ef61f6f7-1800-0000-3705-2fcbcf130000 pid=5071 clone guuid=27b7fdf7-1800-0000-3705-2fcbd0130000 pid=5072 /tmp/WTF net send-data zombie guuid=849f92f7-1800-0000-3705-2fcbcc130000 pid=5068->guuid=27b7fdf7-1800-0000-3705-2fcbd0130000 pid=5072 clone guuid=27b7fdf7-1800-0000-3705-2fcbd0130000 pid=5072->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=27b7fdf7-1800-0000-3705-2fcbd0130000 pid=5072->713032c8-f7c4-5455-b885-e4dbd87df246 send: 72B guuid=e4b314f8-1800-0000-3705-2fcbd1130000 pid=5073->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=1591910e-1900-0000-3705-2fcb0d140000 pid=5133->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a7960525-1900-0000-3705-2fcb46140000 pid=5190 /tmp/WTF guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188->guuid=a7960525-1900-0000-3705-2fcb46140000 pid=5190 clone guuid=f5120c25-1900-0000-3705-2fcb47140000 pid=5191 /tmp/WTF guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188->guuid=f5120c25-1900-0000-3705-2fcb47140000 pid=5191 clone guuid=13dc1425-1900-0000-3705-2fcb48140000 pid=5192 /tmp/WTF net send-data zombie guuid=94c7a624-1900-0000-3705-2fcb44140000 pid=5188->guuid=13dc1425-1900-0000-3705-2fcb48140000 pid=5192 clone guuid=13dc1425-1900-0000-3705-2fcb48140000 pid=5192->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=13dc1425-1900-0000-3705-2fcb48140000 pid=5192->713032c8-f7c4-5455-b885-e4dbd87df246 send: 12B guuid=83a72425-1900-0000-3705-2fcb49140000 pid=5193->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=09ef1332-1900-0000-3705-2fcb4b140000 pid=5195->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=183f3445-1900-0000-3705-2fcb6d140000 pid=5229 /tmp/WTF guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227->guuid=183f3445-1900-0000-3705-2fcb6d140000 pid=5229 clone guuid=ed9b3c45-1900-0000-3705-2fcb6e140000 pid=5230 /tmp/WTF guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227->guuid=ed9b3c45-1900-0000-3705-2fcb6e140000 pid=5230 clone guuid=597d4645-1900-0000-3705-2fcb6f140000 pid=5231 /tmp/WTF net send-data zombie guuid=99d0b644-1900-0000-3705-2fcb6b140000 pid=5227->guuid=597d4645-1900-0000-3705-2fcb6f140000 pid=5231 clone guuid=597d4645-1900-0000-3705-2fcb6f140000 pid=5231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=597d4645-1900-0000-3705-2fcb6f140000 pid=5231->713032c8-f7c4-5455-b885-e4dbd87df246 send: 147B guuid=70755645-1900-0000-3705-2fcb71140000 pid=5233->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=0e522c5f-1900-0000-3705-2fcbb4140000 pid=5300->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cb99507e-1900-0000-3705-2fcbc3140000 pid=5315 /tmp/WTF guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314->guuid=cb99507e-1900-0000-3705-2fcbc3140000 pid=5315 clone guuid=0810567e-1900-0000-3705-2fcbc4140000 pid=5316 /tmp/WTF guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314->guuid=0810567e-1900-0000-3705-2fcbc4140000 pid=5316 clone guuid=fd9b5d7e-1900-0000-3705-2fcbc5140000 pid=5317 /tmp/WTF net send-data zombie guuid=d0b4197e-1900-0000-3705-2fcbc2140000 pid=5314->guuid=fd9b5d7e-1900-0000-3705-2fcbc5140000 pid=5317 clone guuid=fd9b5d7e-1900-0000-3705-2fcbc5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fd9b5d7e-1900-0000-3705-2fcbc5140000 pid=5317->713032c8-f7c4-5455-b885-e4dbd87df246 send: 62B guuid=f5ff807e-1900-0000-3705-2fcbc6140000 pid=5318->99f6939d-f237-5896-9717-09e3a5f03882 send: 149B guuid=b3f3a292-1900-0000-3705-2fcbc7140000 pid=5319->99f6939d-f237-5896-9717-09e3a5f03882 send: 98B guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5dfec9a6-1900-0000-3705-2fcbcb140000 pid=5323 /tmp/WTF guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322->guuid=5dfec9a6-1900-0000-3705-2fcbcb140000 pid=5323 clone guuid=cd2acea6-1900-0000-3705-2fcbcc140000 pid=5324 /tmp/WTF guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322->guuid=cd2acea6-1900-0000-3705-2fcbcc140000 pid=5324 clone guuid=5e68d3a6-1900-0000-3705-2fcbcd140000 pid=5325 /tmp/WTF net send-data zombie guuid=7b2697a6-1900-0000-3705-2fcbca140000 pid=5322->guuid=5e68d3a6-1900-0000-3705-2fcbcd140000 pid=5325 clone guuid=5e68d3a6-1900-0000-3705-2fcbcd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5e68d3a6-1900-0000-3705-2fcbcd140000 pid=5325->713032c8-f7c4-5455-b885-e4dbd87df246 send: 72B guuid=c9c7e5a6-1900-0000-3705-2fcbce140000 pid=5326->99f6939d-f237-5896-9717-09e3a5f03882 send: 148B guuid=b5f390bb-1900-0000-3705-2fcbcf140000 pid=5327->99f6939d-f237-5896-9717-09e3a5f03882 send: 97B guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a9d972cf-1900-0000-3705-2fcbd3140000 pid=5331 /tmp/WTF guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330->guuid=a9d972cf-1900-0000-3705-2fcbd3140000 pid=5331 clone guuid=5b9277cf-1900-0000-3705-2fcbd4140000 pid=5332 /tmp/WTF guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330->guuid=5b9277cf-1900-0000-3705-2fcbd4140000 pid=5332 clone guuid=d91480cf-1900-0000-3705-2fcbd5140000 pid=5333 /tmp/WTF net send-data zombie guuid=a4832acf-1900-0000-3705-2fcbd2140000 pid=5330->guuid=d91480cf-1900-0000-3705-2fcbd5140000 pid=5333 clone guuid=d91480cf-1900-0000-3705-2fcbd5140000 pid=5333->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d91480cf-1900-0000-3705-2fcbd5140000 pid=5333->713032c8-f7c4-5455-b885-e4dbd87df246 send: 27B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-01-30 14:57:24 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b7a3af59ee5db48d17799334c31d2fa9e6c819ea0f5dcfea3e10f689808286d2

(this sample)

  
Delivery method
Distributed via web download

Comments