MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c1d8d718cc73faf4786acee4d6d7dd01424fd4505ab0a9f50a6f50377c894f7d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: c1d8d718cc73faf4786acee4d6d7dd01424fd4505ab0a9f50a6f50377c894f7d
SHA3-384 hash: 6eada2d211183c83288ae83925dd4c8c27f70610488fbe64c51d77ef096debbf9f50b6d07a42e289e635429c4a179470
SHA1 hash: bf06c564b661e00cbd8d1b09c5805deede39ad4f
MD5 hash: 7ff92515fcde21fb0ea3607f0bcb7ace
humanhash: island-uncle-enemy-sierra
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2025-06-26 05:31:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vo7P7N7hoK6GogSzPo6KWoEoUo7E7o7Uof93bof9RowcgojpVoSSOoG+CoNfTo1A:vo7P7N7hoK6GogSzPo6KWoEoUo7E7o7A
TLSH T15B51E9C543440D302D636A97EAB7C12C72C7A4679CE16BE5E9C4BAE1038FE147B407A3
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.42.88.239/hiddenbin/boatnet.x861d908ba4fbc4c7ac68fff944b4723fada55ab89569e248036e40b18ef829e4db Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.mipsa8df7a6f8fa6146d30c20e0ca7f8ac849e0ba8596a5b01e3a3c6cb720c736420 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.arc9088213382505b5e9cd3e1b2b0ae7f4469695aa417cac460994b1b7c5575800c Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.i468n/an/an/a
http://89.42.88.239/hiddenbin/boatnet.i686n/an/an/a
http://89.42.88.239/hiddenbin/boatnet.x86_64n/an/an/a
http://89.42.88.239/hiddenbin/boatnet.mpsl6f83e5c36f8454491c6ce4621f5482ccc3c671b216b7e3ebba85715ab3dd4380 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.arm8d9291e86708b3266790077c9d37034f2e09d8439eae364898cdbca7eb99efa7 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.arm5ec25a66677f57719fe0061e622218e878542a3abccd48500892343ff9b619e09 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.arm6755667347b4245f965a4f4eb228bc82777ead558e68400227e8344386fabc64a Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.arm7d8aa947123f7edf93e6fdc1f828b5c4f783058a04fb7c807393d5a41783e053a Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.ppc9907fad0916c4e4596ada58f90433d751505c01f57a52f8ea7651acfe6589ddb Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.spcea136bcdfeb1a8381d88b0546c5ddbb0cb99d22c3b97176b19179a227c455e17 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.m68kc8f22977ad3af77f171902919a0344fc210bdefcc08ee2e24d266cb608dbd0d6 Miraielf mirai ua-wget
http://89.42.88.239/hiddenbin/boatnet.sh4e7641095f4d479eb201878c9e67cf1624bb47ad97306aab4f6dad9dbf06c3db8 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
85
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Score:
94.9%
Tags:
trojandownloader downloader agent
Status:
terminated
Behavior Graph:
%3 guuid=8e0cc7b3-1600-0000-8a52-f66d320c0000 pid=3122 /usr/bin/sudo guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129 /tmp/sample.bin guuid=8e0cc7b3-1600-0000-8a52-f66d320c0000 pid=3122->guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129 execve guuid=1ff9c3b6-1600-0000-8a52-f66d3c0c0000 pid=3132 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=1ff9c3b6-1600-0000-8a52-f66d3c0c0000 pid=3132 execve guuid=3ebda9bb-1600-0000-8a52-f66d460c0000 pid=3142 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=3ebda9bb-1600-0000-8a52-f66d460c0000 pid=3142 execve guuid=5429a6c4-1600-0000-8a52-f66d550c0000 pid=3157 /usr/bin/cat guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=5429a6c4-1600-0000-8a52-f66d550c0000 pid=3157 execve guuid=381100c5-1600-0000-8a52-f66d570c0000 pid=3159 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=381100c5-1600-0000-8a52-f66d570c0000 pid=3159 execve guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160 execve guuid=f7b389c5-1600-0000-8a52-f66d5d0c0000 pid=3165 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=f7b389c5-1600-0000-8a52-f66d5d0c0000 pid=3165 execve guuid=23c946c9-1600-0000-8a52-f66d620c0000 pid=3170 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=23c946c9-1600-0000-8a52-f66d620c0000 pid=3170 execve guuid=41e847ce-1600-0000-8a52-f66d690c0000 pid=3177 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=41e847ce-1600-0000-8a52-f66d690c0000 pid=3177 clone guuid=2fde68ce-1600-0000-8a52-f66d6a0c0000 pid=3178 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=2fde68ce-1600-0000-8a52-f66d6a0c0000 pid=3178 execve guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179 execve guuid=78e505cf-1600-0000-8a52-f66d6f0c0000 pid=3183 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=78e505cf-1600-0000-8a52-f66d6f0c0000 pid=3183 execve guuid=efcd23d6-1600-0000-8a52-f66d700c0000 pid=3184 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=efcd23d6-1600-0000-8a52-f66d700c0000 pid=3184 execve guuid=1d7194dd-1600-0000-8a52-f66d7a0c0000 pid=3194 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=1d7194dd-1600-0000-8a52-f66d7a0c0000 pid=3194 clone guuid=c0ecacdd-1600-0000-8a52-f66d7b0c0000 pid=3195 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=c0ecacdd-1600-0000-8a52-f66d7b0c0000 pid=3195 execve guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197 execve guuid=d73445de-1600-0000-8a52-f66d820c0000 pid=3202 /usr/bin/wget net send-data guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=d73445de-1600-0000-8a52-f66d820c0000 pid=3202 execve guuid=16d1f7e1-1600-0000-8a52-f66d8b0c0000 pid=3211 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=16d1f7e1-1600-0000-8a52-f66d8b0c0000 pid=3211 execve guuid=214bf7e6-1600-0000-8a52-f66d930c0000 pid=3219 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=214bf7e6-1600-0000-8a52-f66d930c0000 pid=3219 clone guuid=b68614e7-1600-0000-8a52-f66d940c0000 pid=3220 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=b68614e7-1600-0000-8a52-f66d940c0000 pid=3220 execve guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221 execve guuid=467fcbe7-1600-0000-8a52-f66d990c0000 pid=3225 /usr/bin/wget net send-data guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=467fcbe7-1600-0000-8a52-f66d990c0000 pid=3225 execve guuid=553c10eb-1600-0000-8a52-f66da30c0000 pid=3235 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=553c10eb-1600-0000-8a52-f66da30c0000 pid=3235 execve guuid=66d457ef-1600-0000-8a52-f66da50c0000 pid=3237 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=66d457ef-1600-0000-8a52-f66da50c0000 pid=3237 clone guuid=edc685ef-1600-0000-8a52-f66da60c0000 pid=3238 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=edc685ef-1600-0000-8a52-f66da60c0000 pid=3238 execve guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239 execve guuid=513146f0-1600-0000-8a52-f66dab0c0000 pid=3243 /usr/bin/wget net send-data guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=513146f0-1600-0000-8a52-f66dab0c0000 pid=3243 execve guuid=dc24a5f3-1600-0000-8a52-f66dac0c0000 pid=3244 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=dc24a5f3-1600-0000-8a52-f66dac0c0000 pid=3244 execve guuid=b69186f9-1600-0000-8a52-f66dad0c0000 pid=3245 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=b69186f9-1600-0000-8a52-f66dad0c0000 pid=3245 clone guuid=79fad3f9-1600-0000-8a52-f66dae0c0000 pid=3246 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=79fad3f9-1600-0000-8a52-f66dae0c0000 pid=3246 execve guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248 execve guuid=2d1d23fb-1600-0000-8a52-f66db40c0000 pid=3252 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=2d1d23fb-1600-0000-8a52-f66db40c0000 pid=3252 execve guuid=994f01ff-1600-0000-8a52-f66dbe0c0000 pid=3262 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=994f01ff-1600-0000-8a52-f66dbe0c0000 pid=3262 execve guuid=8426a404-1700-0000-8a52-f66dc80c0000 pid=3272 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=8426a404-1700-0000-8a52-f66dc80c0000 pid=3272 clone guuid=47a5d404-1700-0000-8a52-f66dca0c0000 pid=3274 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=47a5d404-1700-0000-8a52-f66dca0c0000 pid=3274 execve guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276 execve guuid=2586ad05-1700-0000-8a52-f66dd00c0000 pid=3280 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=2586ad05-1700-0000-8a52-f66dd00c0000 pid=3280 execve guuid=02f3600a-1700-0000-8a52-f66dd10c0000 pid=3281 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=02f3600a-1700-0000-8a52-f66dd10c0000 pid=3281 execve guuid=f7e53e12-1700-0000-8a52-f66de00c0000 pid=3296 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=f7e53e12-1700-0000-8a52-f66de00c0000 pid=3296 clone guuid=5d816112-1700-0000-8a52-f66de10c0000 pid=3297 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=5d816112-1700-0000-8a52-f66de10c0000 pid=3297 execve guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299 execve guuid=ed453813-1700-0000-8a52-f66de70c0000 pid=3303 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=ed453813-1700-0000-8a52-f66de70c0000 pid=3303 execve guuid=ed045417-1700-0000-8a52-f66dee0c0000 pid=3310 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=ed045417-1700-0000-8a52-f66dee0c0000 pid=3310 execve guuid=6ff37d1d-1700-0000-8a52-f66dff0c0000 pid=3327 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=6ff37d1d-1700-0000-8a52-f66dff0c0000 pid=3327 clone guuid=953dad1d-1700-0000-8a52-f66d000d0000 pid=3328 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=953dad1d-1700-0000-8a52-f66d000d0000 pid=3328 execve guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330 execve guuid=c285681e-1700-0000-8a52-f66d070d0000 pid=3335 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=c285681e-1700-0000-8a52-f66d070d0000 pid=3335 execve guuid=4a486b22-1700-0000-8a52-f66d0e0d0000 pid=3342 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=4a486b22-1700-0000-8a52-f66d0e0d0000 pid=3342 execve guuid=1a09ed27-1700-0000-8a52-f66d1d0d0000 pid=3357 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=1a09ed27-1700-0000-8a52-f66d1d0d0000 pid=3357 clone guuid=a68c2928-1700-0000-8a52-f66d1e0d0000 pid=3358 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=a68c2928-1700-0000-8a52-f66d1e0d0000 pid=3358 execve guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359 execve guuid=8465d528-1700-0000-8a52-f66d230d0000 pid=3363 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=8465d528-1700-0000-8a52-f66d230d0000 pid=3363 execve guuid=6b707d2d-1700-0000-8a52-f66d290d0000 pid=3369 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=6b707d2d-1700-0000-8a52-f66d290d0000 pid=3369 execve guuid=5c59256f-1700-0000-8a52-f66d970d0000 pid=3479 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=5c59256f-1700-0000-8a52-f66d970d0000 pid=3479 clone guuid=94ce536f-1700-0000-8a52-f66d980d0000 pid=3480 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=94ce536f-1700-0000-8a52-f66d980d0000 pid=3480 execve guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482 execve guuid=bf768370-1700-0000-8a52-f66d9f0d0000 pid=3487 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=bf768370-1700-0000-8a52-f66d9f0d0000 pid=3487 execve guuid=c411b474-1700-0000-8a52-f66da90d0000 pid=3497 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=c411b474-1700-0000-8a52-f66da90d0000 pid=3497 execve guuid=de81f47e-1700-0000-8a52-f66dc00d0000 pid=3520 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=de81f47e-1700-0000-8a52-f66dc00d0000 pid=3520 clone guuid=14261e7f-1700-0000-8a52-f66dc10d0000 pid=3521 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=14261e7f-1700-0000-8a52-f66dc10d0000 pid=3521 execve guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523 execve guuid=11e2ef7f-1700-0000-8a52-f66dc80d0000 pid=3528 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=11e2ef7f-1700-0000-8a52-f66dc80d0000 pid=3528 execve guuid=958b8ec3-1700-0000-8a52-f66d3a0e0000 pid=3642 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=958b8ec3-1700-0000-8a52-f66d3a0e0000 pid=3642 execve guuid=5c11bd07-1800-0000-8a52-f66db00e0000 pid=3760 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=5c11bd07-1800-0000-8a52-f66db00e0000 pid=3760 clone guuid=1c17ff07-1800-0000-8a52-f66db10e0000 pid=3761 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=1c17ff07-1800-0000-8a52-f66db10e0000 pid=3761 execve guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762 execve guuid=be298209-1800-0000-8a52-f66db60e0000 pid=3766 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=be298209-1800-0000-8a52-f66db60e0000 pid=3766 execve guuid=e03ed00f-1800-0000-8a52-f66dc50e0000 pid=3781 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=e03ed00f-1800-0000-8a52-f66dc50e0000 pid=3781 execve guuid=6a9f8016-1800-0000-8a52-f66dd80e0000 pid=3800 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=6a9f8016-1800-0000-8a52-f66dd80e0000 pid=3800 clone guuid=e93fa116-1800-0000-8a52-f66ddc0e0000 pid=3804 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=e93fa116-1800-0000-8a52-f66ddc0e0000 pid=3804 execve guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805 execve guuid=4f573017-1800-0000-8a52-f66de20e0000 pid=3810 /usr/bin/wget net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=4f573017-1800-0000-8a52-f66de20e0000 pid=3810 execve guuid=922f8357-1800-0000-8a52-f66d940f0000 pid=3988 /usr/bin/curl net send-data write-file guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=922f8357-1800-0000-8a52-f66d940f0000 pid=3988 execve guuid=dee36185-1800-0000-8a52-f66db70f0000 pid=4023 /usr/bin/bash guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=dee36185-1800-0000-8a52-f66db70f0000 pid=4023 clone guuid=a36e9985-1800-0000-8a52-f66dbb0f0000 pid=4027 /usr/bin/chmod guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=a36e9985-1800-0000-8a52-f66dbb0f0000 pid=4027 execve guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028 /tmp/WTF net guuid=0c1723b6-1600-0000-8a52-f66d390c0000 pid=3129->guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028 execve cecc9e35-201a-59b6-bc10-fb2b8662c26e 89.42.88.239:80 guuid=1ff9c3b6-1600-0000-8a52-f66d3c0c0000 pid=3132->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=3ebda9bb-1600-0000-8a52-f66d460c0000 pid=3142->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf8478c5-1600-0000-8a52-f66d5a0c0000 pid=3162 /tmp/WTF guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160->guuid=cf8478c5-1600-0000-8a52-f66d5a0c0000 pid=3162 clone guuid=30c67bc5-1600-0000-8a52-f66d5b0c0000 pid=3163 /tmp/WTF guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160->guuid=30c67bc5-1600-0000-8a52-f66d5b0c0000 pid=3163 clone guuid=39a47fc5-1600-0000-8a52-f66d5c0c0000 pid=3164 /tmp/WTF net zombie guuid=531c44c5-1600-0000-8a52-f66d580c0000 pid=3160->guuid=39a47fc5-1600-0000-8a52-f66d5c0c0000 pid=3164 clone 78d799b3-7819-5942-9c8e-7246718de85d 89.42.88.239:3778 guuid=39a47fc5-1600-0000-8a52-f66d5c0c0000 pid=3164->78d799b3-7819-5942-9c8e-7246718de85d con guuid=f7b389c5-1600-0000-8a52-f66d5d0c0000 pid=3165->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=23c946c9-1600-0000-8a52-f66d620c0000 pid=3170->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ea23f1ce-1600-0000-8a52-f66d6c0c0000 pid=3180 /tmp/WTF guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179->guuid=ea23f1ce-1600-0000-8a52-f66d6c0c0000 pid=3180 clone guuid=3ba3f5ce-1600-0000-8a52-f66d6d0c0000 pid=3181 /tmp/WTF guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179->guuid=3ba3f5ce-1600-0000-8a52-f66d6d0c0000 pid=3181 clone guuid=ae15face-1600-0000-8a52-f66d6e0c0000 pid=3182 /tmp/WTF net zombie guuid=bf08bece-1600-0000-8a52-f66d6b0c0000 pid=3179->guuid=ae15face-1600-0000-8a52-f66d6e0c0000 pid=3182 clone guuid=ae15face-1600-0000-8a52-f66d6e0c0000 pid=3182->78d799b3-7819-5942-9c8e-7246718de85d con guuid=78e505cf-1600-0000-8a52-f66d6f0c0000 pid=3183->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=efcd23d6-1600-0000-8a52-f66d700c0000 pid=3184->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=923531de-1600-0000-8a52-f66d7e0c0000 pid=3198 /tmp/WTF guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197->guuid=923531de-1600-0000-8a52-f66d7e0c0000 pid=3198 clone guuid=937334de-1600-0000-8a52-f66d800c0000 pid=3200 /tmp/WTF guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197->guuid=937334de-1600-0000-8a52-f66d800c0000 pid=3200 clone guuid=ada939de-1600-0000-8a52-f66d810c0000 pid=3201 /tmp/WTF net zombie guuid=709efddd-1600-0000-8a52-f66d7d0c0000 pid=3197->guuid=ada939de-1600-0000-8a52-f66d810c0000 pid=3201 clone guuid=ada939de-1600-0000-8a52-f66d810c0000 pid=3201->78d799b3-7819-5942-9c8e-7246718de85d con guuid=d73445de-1600-0000-8a52-f66d820c0000 pid=3202->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=16d1f7e1-1600-0000-8a52-f66d8b0c0000 pid=3211->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f4b3b3e7-1600-0000-8a52-f66d960c0000 pid=3222 /tmp/WTF guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221->guuid=f4b3b3e7-1600-0000-8a52-f66d960c0000 pid=3222 clone guuid=1ca9b6e7-1600-0000-8a52-f66d970c0000 pid=3223 /tmp/WTF guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221->guuid=1ca9b6e7-1600-0000-8a52-f66d970c0000 pid=3223 clone guuid=59cabde7-1600-0000-8a52-f66d980c0000 pid=3224 /tmp/WTF net zombie guuid=b24a78e7-1600-0000-8a52-f66d950c0000 pid=3221->guuid=59cabde7-1600-0000-8a52-f66d980c0000 pid=3224 clone guuid=59cabde7-1600-0000-8a52-f66d980c0000 pid=3224->78d799b3-7819-5942-9c8e-7246718de85d con guuid=467fcbe7-1600-0000-8a52-f66d990c0000 pid=3225->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=553c10eb-1600-0000-8a52-f66da30c0000 pid=3235->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=296c20f0-1600-0000-8a52-f66da80c0000 pid=3240 /tmp/WTF guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239->guuid=296c20f0-1600-0000-8a52-f66da80c0000 pid=3240 clone guuid=a05625f0-1600-0000-8a52-f66da90c0000 pid=3241 /tmp/WTF guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239->guuid=a05625f0-1600-0000-8a52-f66da90c0000 pid=3241 clone guuid=fd0a2af0-1600-0000-8a52-f66daa0c0000 pid=3242 /tmp/WTF net zombie guuid=f951e8ef-1600-0000-8a52-f66da70c0000 pid=3239->guuid=fd0a2af0-1600-0000-8a52-f66daa0c0000 pid=3242 clone guuid=fd0a2af0-1600-0000-8a52-f66daa0c0000 pid=3242->78d799b3-7819-5942-9c8e-7246718de85d con guuid=513146f0-1600-0000-8a52-f66dab0c0000 pid=3243->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 151B guuid=dc24a5f3-1600-0000-8a52-f66dac0c0000 pid=3244->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 100B guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=737f0cfb-1600-0000-8a52-f66db10c0000 pid=3249 /tmp/WTF guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248->guuid=737f0cfb-1600-0000-8a52-f66db10c0000 pid=3249 clone guuid=d4e911fb-1600-0000-8a52-f66db20c0000 pid=3250 /tmp/WTF guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248->guuid=d4e911fb-1600-0000-8a52-f66db20c0000 pid=3250 clone guuid=58e418fb-1600-0000-8a52-f66db30c0000 pid=3251 /tmp/WTF net zombie guuid=b822a1fa-1600-0000-8a52-f66db00c0000 pid=3248->guuid=58e418fb-1600-0000-8a52-f66db30c0000 pid=3251 clone guuid=58e418fb-1600-0000-8a52-f66db30c0000 pid=3251->78d799b3-7819-5942-9c8e-7246718de85d con guuid=2d1d23fb-1600-0000-8a52-f66db40c0000 pid=3252->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=994f01ff-1600-0000-8a52-f66dbe0c0000 pid=3262->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fd179705-1700-0000-8a52-f66dcd0c0000 pid=3277 /tmp/WTF guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276->guuid=fd179705-1700-0000-8a52-f66dcd0c0000 pid=3277 clone guuid=96b79b05-1700-0000-8a52-f66dce0c0000 pid=3278 /tmp/WTF guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276->guuid=96b79b05-1700-0000-8a52-f66dce0c0000 pid=3278 clone guuid=5567a105-1700-0000-8a52-f66dcf0c0000 pid=3279 /tmp/WTF net zombie guuid=bb334d05-1700-0000-8a52-f66dcc0c0000 pid=3276->guuid=5567a105-1700-0000-8a52-f66dcf0c0000 pid=3279 clone guuid=5567a105-1700-0000-8a52-f66dcf0c0000 pid=3279->78d799b3-7819-5942-9c8e-7246718de85d con guuid=2586ad05-1700-0000-8a52-f66dd00c0000 pid=3280->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=02f3600a-1700-0000-8a52-f66dd10c0000 pid=3281->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4a9b2313-1700-0000-8a52-f66de40c0000 pid=3300 /tmp/WTF guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299->guuid=4a9b2313-1700-0000-8a52-f66de40c0000 pid=3300 clone guuid=2e822713-1700-0000-8a52-f66de50c0000 pid=3301 /tmp/WTF guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299->guuid=2e822713-1700-0000-8a52-f66de50c0000 pid=3301 clone guuid=5bb62c13-1700-0000-8a52-f66de60c0000 pid=3302 /tmp/WTF net zombie guuid=e7c7d612-1700-0000-8a52-f66de30c0000 pid=3299->guuid=5bb62c13-1700-0000-8a52-f66de60c0000 pid=3302 clone guuid=5bb62c13-1700-0000-8a52-f66de60c0000 pid=3302->78d799b3-7819-5942-9c8e-7246718de85d con guuid=ed453813-1700-0000-8a52-f66de70c0000 pid=3303->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=ed045417-1700-0000-8a52-f66dee0c0000 pid=3310->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d5a7551e-1700-0000-8a52-f66d040d0000 pid=3332 /tmp/WTF guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330->guuid=d5a7551e-1700-0000-8a52-f66d040d0000 pid=3332 clone guuid=8bfd591e-1700-0000-8a52-f66d050d0000 pid=3333 /tmp/WTF guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330->guuid=8bfd591e-1700-0000-8a52-f66d050d0000 pid=3333 clone guuid=c1865d1e-1700-0000-8a52-f66d060d0000 pid=3334 /tmp/WTF net zombie guuid=c09f0f1e-1700-0000-8a52-f66d020d0000 pid=3330->guuid=c1865d1e-1700-0000-8a52-f66d060d0000 pid=3334 clone guuid=c1865d1e-1700-0000-8a52-f66d060d0000 pid=3334->78d799b3-7819-5942-9c8e-7246718de85d con guuid=c285681e-1700-0000-8a52-f66d070d0000 pid=3335->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=4a486b22-1700-0000-8a52-f66d0e0d0000 pid=3342->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c484b928-1700-0000-8a52-f66d200d0000 pid=3360 /tmp/WTF guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359->guuid=c484b928-1700-0000-8a52-f66d200d0000 pid=3360 clone guuid=d908bd28-1700-0000-8a52-f66d210d0000 pid=3361 /tmp/WTF guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359->guuid=d908bd28-1700-0000-8a52-f66d210d0000 pid=3361 clone guuid=5bdfc028-1700-0000-8a52-f66d220d0000 pid=3362 /tmp/WTF net zombie guuid=27d48928-1700-0000-8a52-f66d1f0d0000 pid=3359->guuid=5bdfc028-1700-0000-8a52-f66d220d0000 pid=3362 clone guuid=5bdfc028-1700-0000-8a52-f66d220d0000 pid=3362->78d799b3-7819-5942-9c8e-7246718de85d con guuid=8465d528-1700-0000-8a52-f66d230d0000 pid=3363->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=6b707d2d-1700-0000-8a52-f66d290d0000 pid=3369->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b2bb3a70-1700-0000-8a52-f66d9c0d0000 pid=3484 /tmp/WTF guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482->guuid=b2bb3a70-1700-0000-8a52-f66d9c0d0000 pid=3484 clone guuid=f6c14170-1700-0000-8a52-f66d9d0d0000 pid=3485 /tmp/WTF guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482->guuid=f6c14170-1700-0000-8a52-f66d9d0d0000 pid=3485 clone guuid=3eac5570-1700-0000-8a52-f66d9e0d0000 pid=3486 /tmp/WTF net zombie guuid=ec4ee06f-1700-0000-8a52-f66d9a0d0000 pid=3482->guuid=3eac5570-1700-0000-8a52-f66d9e0d0000 pid=3486 clone guuid=3eac5570-1700-0000-8a52-f66d9e0d0000 pid=3486->78d799b3-7819-5942-9c8e-7246718de85d con guuid=bf768370-1700-0000-8a52-f66d9f0d0000 pid=3487->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=c411b474-1700-0000-8a52-f66da90d0000 pid=3497->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=358ad37f-1700-0000-8a52-f66dc50d0000 pid=3525 /tmp/WTF guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523->guuid=358ad37f-1700-0000-8a52-f66dc50d0000 pid=3525 clone guuid=af46d87f-1700-0000-8a52-f66dc60d0000 pid=3526 /tmp/WTF guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523->guuid=af46d87f-1700-0000-8a52-f66dc60d0000 pid=3526 clone guuid=9ed2dd7f-1700-0000-8a52-f66dc70d0000 pid=3527 /tmp/WTF net zombie guuid=be0b8a7f-1700-0000-8a52-f66dc30d0000 pid=3523->guuid=9ed2dd7f-1700-0000-8a52-f66dc70d0000 pid=3527 clone guuid=9ed2dd7f-1700-0000-8a52-f66dc70d0000 pid=3527->78d799b3-7819-5942-9c8e-7246718de85d con guuid=11e2ef7f-1700-0000-8a52-f66dc80d0000 pid=3528->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=958b8ec3-1700-0000-8a52-f66d3a0e0000 pid=3642->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c7315e09-1800-0000-8a52-f66db30e0000 pid=3763 /tmp/WTF guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762->guuid=c7315e09-1800-0000-8a52-f66db30e0000 pid=3763 clone guuid=a1f06509-1800-0000-8a52-f66db40e0000 pid=3764 /tmp/WTF guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762->guuid=a1f06509-1800-0000-8a52-f66db40e0000 pid=3764 clone guuid=a7776f09-1800-0000-8a52-f66db50e0000 pid=3765 /tmp/WTF net zombie guuid=edfcce08-1800-0000-8a52-f66db20e0000 pid=3762->guuid=a7776f09-1800-0000-8a52-f66db50e0000 pid=3765 clone guuid=a7776f09-1800-0000-8a52-f66db50e0000 pid=3765->78d799b3-7819-5942-9c8e-7246718de85d con guuid=be298209-1800-0000-8a52-f66db60e0000 pid=3766->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 149B guuid=e03ed00f-1800-0000-8a52-f66dc50e0000 pid=3781->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 98B guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70ab1c17-1800-0000-8a52-f66ddf0e0000 pid=3807 /tmp/WTF guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805->guuid=70ab1c17-1800-0000-8a52-f66ddf0e0000 pid=3807 clone guuid=631f2017-1800-0000-8a52-f66de00e0000 pid=3808 /tmp/WTF guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805->guuid=631f2017-1800-0000-8a52-f66de00e0000 pid=3808 clone guuid=92492417-1800-0000-8a52-f66de10e0000 pid=3809 /tmp/WTF net zombie guuid=80dfeb16-1800-0000-8a52-f66ddd0e0000 pid=3805->guuid=92492417-1800-0000-8a52-f66de10e0000 pid=3809 clone guuid=92492417-1800-0000-8a52-f66de10e0000 pid=3809->78d799b3-7819-5942-9c8e-7246718de85d con guuid=4f573017-1800-0000-8a52-f66de20e0000 pid=3810->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 148B guuid=922f8357-1800-0000-8a52-f66d940f0000 pid=3988->cecc9e35-201a-59b6-bc10-fb2b8662c26e send: 97B guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3e45a486-1800-0000-8a52-f66dc00f0000 pid=4032 /tmp/WTF guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028->guuid=3e45a486-1800-0000-8a52-f66dc00f0000 pid=4032 clone guuid=7195aa86-1800-0000-8a52-f66dc10f0000 pid=4033 /tmp/WTF guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028->guuid=7195aa86-1800-0000-8a52-f66dc10f0000 pid=4033 clone guuid=3726af86-1800-0000-8a52-f66dc20f0000 pid=4034 /tmp/WTF net zombie guuid=c2cf1d86-1800-0000-8a52-f66dbc0f0000 pid=4028->guuid=3726af86-1800-0000-8a52-f66dc20f0000 pid=4034 clone guuid=3726af86-1800-0000-8a52-f66dc20f0000 pid=4034->78d799b3-7819-5942-9c8e-7246718de85d con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-06-26 05:22:22 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c1d8d718cc73faf4786acee4d6d7dd01424fd4505ab0a9f50a6f50377c894f7d

(this sample)

  
Delivery method
Distributed via web download

Comments