MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c218a3067ba3d62259fdc61811a686d751fde495914a5ea662f6a08b7ff62018. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: c218a3067ba3d62259fdc61811a686d751fde495914a5ea662f6a08b7ff62018
SHA3-384 hash: 2eac0ea5ddcb69c48ad12cca52978d2755699a670736912cf60171ce88c8e3faaa9979470a15e781420f5bb0f5881e4f
SHA1 hash: 42a3654514acadb97a72ad301e94b002f4fc997c
MD5 hash: cb5077badc015a24beedbb7336b8fbba
humanhash: georgia-nineteen-zebra-autumn
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'970 bytes
First seen:2025-09-17 15:17:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:v57C7N7h5j6G5gbzP5TKW5loU57l7o7U5fA3b5S9R5xcg5GpV5bSO5f+C5QfT5Im:v57C7N7h5j6G5gbzP5TKW5loU57l7o7Q
TLSH T10951168563C44D782C636A53E6B6412872DAF4568CE2BFD5D9CCBFE0234EE10B941B53
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://89.213.174.225/hiddenbin/boatnet.x86dfeb7acda278f46310539560d46c1f4054ba255aaba0b75ea1c6f5634779b847 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.mipsce037db965e1b96149c34a219dd31a069b78db3b2892540540c99f2e95250e88 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.arce14148ef50afaf90475f6a13323b0a1547c747c45895b0d1c6ecbdfe773324f9 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://89.213.174.225/hiddenbin/boatnet.i6864b6e5cc2aa27d0338421feb62a952f652076f5436aa6580abfc3f7a018815232 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.x86_643450424b0f9a0f3b78d9a4701bb572a0476b27e1db1d041b41eb9aa8da2aa1f6 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.mpsl282786263a89c5ff2cdec8c2e021d670a6073d99f0e03b65f0e6f07024b4f81c Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.arm3d1c06ab7a63ea3ab6fe5f226e3e0c7faa7c6926000fb048fcd041fb1d5b14a7 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.arm5cf6613970a53f466364a6422761d28724f6ef50983bce95fe285dc7d72da3c21 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.arm66cb58686e4a5196264c6d7b8c3f3cd5c8b78388cb7dcb0b79f0ad56de2e8ec14 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.arm7080697ddd9ab71acfd9b736168a0ecabda7cb3a1c86f36a2660943b67249923c Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.ppc7f5e4a7f021e83738bb50c721651dc9b3a415014fdab6399ea6c465605028985 Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.spc6fa54a5ddce877dece40fcad3695ace427c43c1912422ecd895be284309c6eef Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.m68k4245b7a26616ea900e29beca8314057ffe821a0ff0910d4977c04d03e0a8836a Miraielf mirai ua-wget
http://89.213.174.225/hiddenbin/boatnet.sh49994f9cd9011844f69e34910db7219b75c47e36d730b27a5eb90cbbf8c8a4c79 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
39
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-17T09:52:00Z UTC
Last seen:
2025-09-17T09:52:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f2d0c26a-1900-0000-a786-f99eb50c0000 pid=3253 /usr/bin/sudo guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257 /tmp/sample.bin guuid=f2d0c26a-1900-0000-a786-f99eb50c0000 pid=3253->guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257 execve guuid=498a836d-1900-0000-a786-f99ebc0c0000 pid=3260 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=498a836d-1900-0000-a786-f99ebc0c0000 pid=3260 execve guuid=2484cc76-1900-0000-a786-f99ed40c0000 pid=3284 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=2484cc76-1900-0000-a786-f99ed40c0000 pid=3284 execve guuid=65954684-1900-0000-a786-f99ef40c0000 pid=3316 /usr/bin/cat guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=65954684-1900-0000-a786-f99ef40c0000 pid=3316 execve guuid=ce789484-1900-0000-a786-f99ef60c0000 pid=3318 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=ce789484-1900-0000-a786-f99ef60c0000 pid=3318 execve guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319 execve guuid=b3ad2d85-1900-0000-a786-f99efc0c0000 pid=3324 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=b3ad2d85-1900-0000-a786-f99efc0c0000 pid=3324 execve guuid=646e5d8d-1900-0000-a786-f99e060d0000 pid=3334 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=646e5d8d-1900-0000-a786-f99e060d0000 pid=3334 execve guuid=a622d196-1900-0000-a786-f99e0d0d0000 pid=3341 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=a622d196-1900-0000-a786-f99e0d0d0000 pid=3341 clone guuid=669bf296-1900-0000-a786-f99e0e0d0000 pid=3342 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=669bf296-1900-0000-a786-f99e0e0d0000 pid=3342 execve guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345 execve guuid=dcd5a997-1900-0000-a786-f99e150d0000 pid=3349 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=dcd5a997-1900-0000-a786-f99e150d0000 pid=3349 execve guuid=f42a32a4-1900-0000-a786-f99e330d0000 pid=3379 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=f42a32a4-1900-0000-a786-f99e330d0000 pid=3379 execve guuid=32b31cb0-1900-0000-a786-f99e4e0d0000 pid=3406 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=32b31cb0-1900-0000-a786-f99e4e0d0000 pid=3406 clone guuid=5e4d3cb0-1900-0000-a786-f99e4f0d0000 pid=3407 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=5e4d3cb0-1900-0000-a786-f99e4f0d0000 pid=3407 execve guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409 execve guuid=1107d3b0-1900-0000-a786-f99e560d0000 pid=3414 /usr/bin/wget net send-data guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=1107d3b0-1900-0000-a786-f99e560d0000 pid=3414 execve guuid=4c9fe5b6-1900-0000-a786-f99e6c0d0000 pid=3436 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=4c9fe5b6-1900-0000-a786-f99e6c0d0000 pid=3436 execve guuid=124f3fbd-1900-0000-a786-f99e810d0000 pid=3457 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=124f3fbd-1900-0000-a786-f99e810d0000 pid=3457 clone guuid=72825cbd-1900-0000-a786-f99e830d0000 pid=3459 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=72825cbd-1900-0000-a786-f99e830d0000 pid=3459 execve guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460 execve guuid=3bc501be-1900-0000-a786-f99e8a0d0000 pid=3466 /usr/bin/wget net send-data guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=3bc501be-1900-0000-a786-f99e8a0d0000 pid=3466 execve guuid=a7f7a3c3-1900-0000-a786-f99e9d0d0000 pid=3485 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=a7f7a3c3-1900-0000-a786-f99e9d0d0000 pid=3485 execve guuid=1bf78eca-1900-0000-a786-f99eb50d0000 pid=3509 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=1bf78eca-1900-0000-a786-f99eb50d0000 pid=3509 clone guuid=0239b4ca-1900-0000-a786-f99eb60d0000 pid=3510 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=0239b4ca-1900-0000-a786-f99eb60d0000 pid=3510 execve guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512 execve guuid=c2ea35cb-1900-0000-a786-f99ebd0d0000 pid=3517 /usr/bin/wget net send-data guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=c2ea35cb-1900-0000-a786-f99ebd0d0000 pid=3517 execve guuid=5b2d3fd0-1900-0000-a786-f99ec90d0000 pid=3529 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=5b2d3fd0-1900-0000-a786-f99ec90d0000 pid=3529 execve guuid=998463d8-1900-0000-a786-f99ed80d0000 pid=3544 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=998463d8-1900-0000-a786-f99ed80d0000 pid=3544 clone guuid=3b9782d8-1900-0000-a786-f99ed90d0000 pid=3545 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=3b9782d8-1900-0000-a786-f99ed90d0000 pid=3545 execve guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546 execve guuid=bcd237d9-1900-0000-a786-f99edf0d0000 pid=3551 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=bcd237d9-1900-0000-a786-f99edf0d0000 pid=3551 execve guuid=08806fe0-1900-0000-a786-f99ee90d0000 pid=3561 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=08806fe0-1900-0000-a786-f99ee90d0000 pid=3561 execve guuid=2f9e5cea-1900-0000-a786-f99efb0d0000 pid=3579 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=2f9e5cea-1900-0000-a786-f99efb0d0000 pid=3579 clone guuid=f1c97cea-1900-0000-a786-f99efc0d0000 pid=3580 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=f1c97cea-1900-0000-a786-f99efc0d0000 pid=3580 execve guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583 execve guuid=c64c1ceb-1900-0000-a786-f99e030e0000 pid=3587 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=c64c1ceb-1900-0000-a786-f99e030e0000 pid=3587 execve guuid=2e1c6ef2-1900-0000-a786-f99e1f0e0000 pid=3615 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=2e1c6ef2-1900-0000-a786-f99e1f0e0000 pid=3615 execve guuid=244375fb-1900-0000-a786-f99e350e0000 pid=3637 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=244375fb-1900-0000-a786-f99e350e0000 pid=3637 clone guuid=db13a1fb-1900-0000-a786-f99e360e0000 pid=3638 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=db13a1fb-1900-0000-a786-f99e360e0000 pid=3638 execve guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639 execve guuid=e24745fc-1900-0000-a786-f99e3b0e0000 pid=3643 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=e24745fc-1900-0000-a786-f99e3b0e0000 pid=3643 execve guuid=5d5a2d03-1a00-0000-a786-f99e3c0e0000 pid=3644 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=5d5a2d03-1a00-0000-a786-f99e3c0e0000 pid=3644 execve guuid=9b0dac26-1a00-0000-a786-f99e4e0e0000 pid=3662 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=9b0dac26-1a00-0000-a786-f99e4e0e0000 pid=3662 clone guuid=7e63c926-1a00-0000-a786-f99e4f0e0000 pid=3663 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=7e63c926-1a00-0000-a786-f99e4f0e0000 pid=3663 execve guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666 execve guuid=c781a627-1a00-0000-a786-f99e560e0000 pid=3670 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=c781a627-1a00-0000-a786-f99e560e0000 pid=3670 execve guuid=56ccf12e-1a00-0000-a786-f99e660e0000 pid=3686 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=56ccf12e-1a00-0000-a786-f99e660e0000 pid=3686 execve guuid=4218d337-1a00-0000-a786-f99e7b0e0000 pid=3707 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=4218d337-1a00-0000-a786-f99e7b0e0000 pid=3707 clone guuid=4517f237-1a00-0000-a786-f99e7d0e0000 pid=3709 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=4517f237-1a00-0000-a786-f99e7d0e0000 pid=3709 execve guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712 execve guuid=987eb838-1a00-0000-a786-f99e870e0000 pid=3719 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=987eb838-1a00-0000-a786-f99e870e0000 pid=3719 execve guuid=80af3c43-1a00-0000-a786-f99e9c0e0000 pid=3740 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=80af3c43-1a00-0000-a786-f99e9c0e0000 pid=3740 execve guuid=a6663f51-1a00-0000-a786-f99eb50e0000 pid=3765 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=a6663f51-1a00-0000-a786-f99eb50e0000 pid=3765 clone guuid=fcfb6251-1a00-0000-a786-f99eb70e0000 pid=3767 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=fcfb6251-1a00-0000-a786-f99eb70e0000 pid=3767 execve guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769 execve guuid=fa314152-1a00-0000-a786-f99ebd0e0000 pid=3773 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=fa314152-1a00-0000-a786-f99ebd0e0000 pid=3773 execve guuid=d083ae59-1a00-0000-a786-f99ed90e0000 pid=3801 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=d083ae59-1a00-0000-a786-f99ed90e0000 pid=3801 execve guuid=8b18a262-1a00-0000-a786-f99efe0e0000 pid=3838 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=8b18a262-1a00-0000-a786-f99efe0e0000 pid=3838 clone guuid=57acc362-1a00-0000-a786-f99eff0e0000 pid=3839 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=57acc362-1a00-0000-a786-f99eff0e0000 pid=3839 execve guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841 execve guuid=35b46663-1a00-0000-a786-f99e050f0000 pid=3845 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=35b46663-1a00-0000-a786-f99e050f0000 pid=3845 execve guuid=4f14fb6c-1a00-0000-a786-f99e1d0f0000 pid=3869 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=4f14fb6c-1a00-0000-a786-f99e1d0f0000 pid=3869 execve guuid=e2595779-1a00-0000-a786-f99e490f0000 pid=3913 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=e2595779-1a00-0000-a786-f99e490f0000 pid=3913 clone guuid=ade68c79-1a00-0000-a786-f99e4a0f0000 pid=3914 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=ade68c79-1a00-0000-a786-f99e4a0f0000 pid=3914 execve guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915 execve guuid=a5e4357a-1a00-0000-a786-f99e510f0000 pid=3921 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=a5e4357a-1a00-0000-a786-f99e510f0000 pid=3921 execve guuid=25da5084-1a00-0000-a786-f99e540f0000 pid=3924 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=25da5084-1a00-0000-a786-f99e540f0000 pid=3924 execve guuid=889dd28f-1a00-0000-a786-f99e710f0000 pid=3953 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=889dd28f-1a00-0000-a786-f99e710f0000 pid=3953 clone guuid=ed2afa8f-1a00-0000-a786-f99e720f0000 pid=3954 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=ed2afa8f-1a00-0000-a786-f99e720f0000 pid=3954 execve guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957 execve guuid=abfecc90-1a00-0000-a786-f99e7a0f0000 pid=3962 /usr/bin/wget net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=abfecc90-1a00-0000-a786-f99e7a0f0000 pid=3962 execve guuid=6702b59a-1a00-0000-a786-f99e940f0000 pid=3988 /usr/bin/curl net send-data write-file guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=6702b59a-1a00-0000-a786-f99e940f0000 pid=3988 execve guuid=8b67aea5-1a00-0000-a786-f99eb40f0000 pid=4020 /usr/bin/bash guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=8b67aea5-1a00-0000-a786-f99eb40f0000 pid=4020 clone guuid=710cd2a5-1a00-0000-a786-f99eb50f0000 pid=4021 /usr/bin/chmod guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=710cd2a5-1a00-0000-a786-f99eb50f0000 pid=4021 execve guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023 /tmp/WTF net guuid=a751dc6c-1900-0000-a786-f99eb90c0000 pid=3257->guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023 execve 1abdd55f-79cd-53ae-abf5-622946afe271 89.213.174.225:80 guuid=498a836d-1900-0000-a786-f99ebc0c0000 pid=3260->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=2484cc76-1900-0000-a786-f99ed40c0000 pid=3284->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e3b61385-1900-0000-a786-f99ef80c0000 pid=3320 /tmp/WTF guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319->guuid=e3b61385-1900-0000-a786-f99ef80c0000 pid=3320 clone guuid=c5301785-1900-0000-a786-f99ef90c0000 pid=3321 /tmp/WTF guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319->guuid=c5301785-1900-0000-a786-f99ef90c0000 pid=3321 clone guuid=2a5d1a85-1900-0000-a786-f99efa0c0000 pid=3322 /tmp/WTF net send-data zombie guuid=de3ce384-1900-0000-a786-f99ef70c0000 pid=3319->guuid=2a5d1a85-1900-0000-a786-f99efa0c0000 pid=3322 clone guuid=2a5d1a85-1900-0000-a786-f99efa0c0000 pid=3322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 56a397e1-01ee-52ae-86ff-e29a19f15864 89.213.174.225:3778 guuid=2a5d1a85-1900-0000-a786-f99efa0c0000 pid=3322->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=b3ad2d85-1900-0000-a786-f99efc0c0000 pid=3324->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=646e5d8d-1900-0000-a786-f99e060d0000 pid=3334->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bcfd9997-1900-0000-a786-f99e120d0000 pid=3346 /tmp/WTF guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345->guuid=bcfd9997-1900-0000-a786-f99e120d0000 pid=3346 clone guuid=817d9e97-1900-0000-a786-f99e130d0000 pid=3347 /tmp/WTF guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345->guuid=817d9e97-1900-0000-a786-f99e130d0000 pid=3347 clone guuid=1886a197-1900-0000-a786-f99e140d0000 pid=3348 /tmp/WTF net send-data zombie guuid=3dc25a97-1900-0000-a786-f99e110d0000 pid=3345->guuid=1886a197-1900-0000-a786-f99e140d0000 pid=3348 clone guuid=1886a197-1900-0000-a786-f99e140d0000 pid=3348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1886a197-1900-0000-a786-f99e140d0000 pid=3348->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 12B guuid=dcd5a997-1900-0000-a786-f99e150d0000 pid=3349->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=f42a32a4-1900-0000-a786-f99e330d0000 pid=3379->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=96e3b8b0-1900-0000-a786-f99e530d0000 pid=3411 /tmp/WTF guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409->guuid=96e3b8b0-1900-0000-a786-f99e530d0000 pid=3411 clone guuid=c51cbdb0-1900-0000-a786-f99e540d0000 pid=3412 /tmp/WTF guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409->guuid=c51cbdb0-1900-0000-a786-f99e540d0000 pid=3412 clone guuid=a56ec1b0-1900-0000-a786-f99e550d0000 pid=3413 /tmp/WTF net send-data zombie guuid=abc987b0-1900-0000-a786-f99e510d0000 pid=3409->guuid=a56ec1b0-1900-0000-a786-f99e550d0000 pid=3413 clone guuid=a56ec1b0-1900-0000-a786-f99e550d0000 pid=3413->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a56ec1b0-1900-0000-a786-f99e550d0000 pid=3413->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=1107d3b0-1900-0000-a786-f99e560d0000 pid=3414->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=4c9fe5b6-1900-0000-a786-f99e6c0d0000 pid=3436->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7078e7bd-1900-0000-a786-f99e860d0000 pid=3462 /tmp/WTF guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460->guuid=7078e7bd-1900-0000-a786-f99e860d0000 pid=3462 clone guuid=a80deebd-1900-0000-a786-f99e880d0000 pid=3464 /tmp/WTF guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460->guuid=a80deebd-1900-0000-a786-f99e880d0000 pid=3464 clone guuid=7ff9f4bd-1900-0000-a786-f99e890d0000 pid=3465 /tmp/WTF net send-data zombie guuid=b2edaabd-1900-0000-a786-f99e840d0000 pid=3460->guuid=7ff9f4bd-1900-0000-a786-f99e890d0000 pid=3465 clone guuid=7ff9f4bd-1900-0000-a786-f99e890d0000 pid=3465->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7ff9f4bd-1900-0000-a786-f99e890d0000 pid=3465->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=3bc501be-1900-0000-a786-f99e8a0d0000 pid=3466->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=a7f7a3c3-1900-0000-a786-f99e9d0d0000 pid=3485->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=46f721cb-1900-0000-a786-f99eba0d0000 pid=3514 /tmp/WTF guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512->guuid=46f721cb-1900-0000-a786-f99eba0d0000 pid=3514 clone guuid=a45d25cb-1900-0000-a786-f99ebb0d0000 pid=3515 /tmp/WTF guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512->guuid=a45d25cb-1900-0000-a786-f99ebb0d0000 pid=3515 clone guuid=eee028cb-1900-0000-a786-f99ebc0d0000 pid=3516 /tmp/WTF net send-data zombie guuid=3564f5ca-1900-0000-a786-f99eb80d0000 pid=3512->guuid=eee028cb-1900-0000-a786-f99ebc0d0000 pid=3516 clone guuid=eee028cb-1900-0000-a786-f99ebc0d0000 pid=3516->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eee028cb-1900-0000-a786-f99ebc0d0000 pid=3516->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=c2ea35cb-1900-0000-a786-f99ebd0d0000 pid=3517->1abdd55f-79cd-53ae-abf5-622946afe271 send: 153B guuid=5b2d3fd0-1900-0000-a786-f99ec90d0000 pid=3529->1abdd55f-79cd-53ae-abf5-622946afe271 send: 102B guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2e2421d9-1900-0000-a786-f99edc0d0000 pid=3548 /tmp/WTF guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546->guuid=2e2421d9-1900-0000-a786-f99edc0d0000 pid=3548 clone guuid=2a7626d9-1900-0000-a786-f99edd0d0000 pid=3549 /tmp/WTF guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546->guuid=2a7626d9-1900-0000-a786-f99edd0d0000 pid=3549 clone guuid=e95b2bd9-1900-0000-a786-f99ede0d0000 pid=3550 /tmp/WTF net send-data zombie guuid=be3ae4d8-1900-0000-a786-f99eda0d0000 pid=3546->guuid=e95b2bd9-1900-0000-a786-f99ede0d0000 pid=3550 clone guuid=e95b2bd9-1900-0000-a786-f99ede0d0000 pid=3550->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e95b2bd9-1900-0000-a786-f99ede0d0000 pid=3550->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=bcd237d9-1900-0000-a786-f99edf0d0000 pid=3551->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=08806fe0-1900-0000-a786-f99ee90d0000 pid=3561->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a7e707eb-1900-0000-a786-f99e000e0000 pid=3584 /tmp/WTF guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583->guuid=a7e707eb-1900-0000-a786-f99e000e0000 pid=3584 clone guuid=eaaa0beb-1900-0000-a786-f99e010e0000 pid=3585 /tmp/WTF guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583->guuid=eaaa0beb-1900-0000-a786-f99e010e0000 pid=3585 clone guuid=931811eb-1900-0000-a786-f99e020e0000 pid=3586 /tmp/WTF net send-data zombie guuid=c92bdaea-1900-0000-a786-f99eff0d0000 pid=3583->guuid=931811eb-1900-0000-a786-f99e020e0000 pid=3586 clone guuid=931811eb-1900-0000-a786-f99e020e0000 pid=3586->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=931811eb-1900-0000-a786-f99e020e0000 pid=3586->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=c64c1ceb-1900-0000-a786-f99e030e0000 pid=3587->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=2e1c6ef2-1900-0000-a786-f99e1f0e0000 pid=3615->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f80525fc-1900-0000-a786-f99e380e0000 pid=3640 /tmp/WTF guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639->guuid=f80525fc-1900-0000-a786-f99e380e0000 pid=3640 clone guuid=ac422cfc-1900-0000-a786-f99e390e0000 pid=3641 /tmp/WTF guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639->guuid=ac422cfc-1900-0000-a786-f99e390e0000 pid=3641 clone guuid=3a2934fc-1900-0000-a786-f99e3a0e0000 pid=3642 /tmp/WTF net send-data zombie guuid=fa69f1fb-1900-0000-a786-f99e370e0000 pid=3639->guuid=3a2934fc-1900-0000-a786-f99e3a0e0000 pid=3642 clone guuid=3a2934fc-1900-0000-a786-f99e3a0e0000 pid=3642->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3a2934fc-1900-0000-a786-f99e3a0e0000 pid=3642->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=e24745fc-1900-0000-a786-f99e3b0e0000 pid=3643->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=5d5a2d03-1a00-0000-a786-f99e3c0e0000 pid=3644->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b8048927-1a00-0000-a786-f99e530e0000 pid=3667 /tmp/WTF guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666->guuid=b8048927-1a00-0000-a786-f99e530e0000 pid=3667 clone guuid=ca718e27-1a00-0000-a786-f99e540e0000 pid=3668 /tmp/WTF guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666->guuid=ca718e27-1a00-0000-a786-f99e540e0000 pid=3668 clone guuid=4d0c9427-1a00-0000-a786-f99e550e0000 pid=3669 /tmp/WTF net send-data zombie guuid=5f444a27-1a00-0000-a786-f99e520e0000 pid=3666->guuid=4d0c9427-1a00-0000-a786-f99e550e0000 pid=3669 clone guuid=4d0c9427-1a00-0000-a786-f99e550e0000 pid=3669->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d0c9427-1a00-0000-a786-f99e550e0000 pid=3669->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=c781a627-1a00-0000-a786-f99e560e0000 pid=3670->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=56ccf12e-1a00-0000-a786-f99e660e0000 pid=3686->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=222c9a38-1a00-0000-a786-f99e840e0000 pid=3716 /tmp/WTF guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712->guuid=222c9a38-1a00-0000-a786-f99e840e0000 pid=3716 clone guuid=a346a038-1a00-0000-a786-f99e850e0000 pid=3717 /tmp/WTF guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712->guuid=a346a038-1a00-0000-a786-f99e850e0000 pid=3717 clone guuid=7501a538-1a00-0000-a786-f99e860e0000 pid=3718 /tmp/WTF net send-data zombie guuid=8ffe5e38-1a00-0000-a786-f99e800e0000 pid=3712->guuid=7501a538-1a00-0000-a786-f99e860e0000 pid=3718 clone guuid=7501a538-1a00-0000-a786-f99e860e0000 pid=3718->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7501a538-1a00-0000-a786-f99e860e0000 pid=3718->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=987eb838-1a00-0000-a786-f99e870e0000 pid=3719->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=80af3c43-1a00-0000-a786-f99e9c0e0000 pid=3740->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7ff81b52-1a00-0000-a786-f99eba0e0000 pid=3770 /tmp/WTF guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769->guuid=7ff81b52-1a00-0000-a786-f99eba0e0000 pid=3770 clone guuid=faeb2152-1a00-0000-a786-f99ebb0e0000 pid=3771 /tmp/WTF guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769->guuid=faeb2152-1a00-0000-a786-f99ebb0e0000 pid=3771 clone guuid=bbdc2c52-1a00-0000-a786-f99ebc0e0000 pid=3772 /tmp/WTF net send-data zombie guuid=362edb51-1a00-0000-a786-f99eb90e0000 pid=3769->guuid=bbdc2c52-1a00-0000-a786-f99ebc0e0000 pid=3772 clone guuid=bbdc2c52-1a00-0000-a786-f99ebc0e0000 pid=3772->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bbdc2c52-1a00-0000-a786-f99ebc0e0000 pid=3772->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=fa314152-1a00-0000-a786-f99ebd0e0000 pid=3773->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=d083ae59-1a00-0000-a786-f99ed90e0000 pid=3801->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b5864d63-1a00-0000-a786-f99e020f0000 pid=3842 /tmp/WTF guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841->guuid=b5864d63-1a00-0000-a786-f99e020f0000 pid=3842 clone guuid=3d4d5163-1a00-0000-a786-f99e030f0000 pid=3843 /tmp/WTF guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841->guuid=3d4d5163-1a00-0000-a786-f99e030f0000 pid=3843 clone guuid=024f5763-1a00-0000-a786-f99e040f0000 pid=3844 /tmp/WTF net send-data zombie guuid=c12f1c63-1a00-0000-a786-f99e010f0000 pid=3841->guuid=024f5763-1a00-0000-a786-f99e040f0000 pid=3844 clone guuid=024f5763-1a00-0000-a786-f99e040f0000 pid=3844->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=024f5763-1a00-0000-a786-f99e040f0000 pid=3844->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=35b46663-1a00-0000-a786-f99e050f0000 pid=3845->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=4f14fb6c-1a00-0000-a786-f99e1d0f0000 pid=3869->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9438147a-1a00-0000-a786-f99e4e0f0000 pid=3918 /tmp/WTF guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915->guuid=9438147a-1a00-0000-a786-f99e4e0f0000 pid=3918 clone guuid=6835187a-1a00-0000-a786-f99e4f0f0000 pid=3919 /tmp/WTF guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915->guuid=6835187a-1a00-0000-a786-f99e4f0f0000 pid=3919 clone guuid=f1941f7a-1a00-0000-a786-f99e500f0000 pid=3920 /tmp/WTF net send-data zombie guuid=df36da79-1a00-0000-a786-f99e4b0f0000 pid=3915->guuid=f1941f7a-1a00-0000-a786-f99e500f0000 pid=3920 clone guuid=f1941f7a-1a00-0000-a786-f99e500f0000 pid=3920->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1941f7a-1a00-0000-a786-f99e500f0000 pid=3920->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=a5e4357a-1a00-0000-a786-f99e510f0000 pid=3921->1abdd55f-79cd-53ae-abf5-622946afe271 send: 151B guuid=25da5084-1a00-0000-a786-f99e540f0000 pid=3924->1abdd55f-79cd-53ae-abf5-622946afe271 send: 100B guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d1f3b290-1a00-0000-a786-f99e770f0000 pid=3959 /tmp/WTF guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957->guuid=d1f3b290-1a00-0000-a786-f99e770f0000 pid=3959 clone guuid=b90cb890-1a00-0000-a786-f99e780f0000 pid=3960 /tmp/WTF guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957->guuid=b90cb890-1a00-0000-a786-f99e780f0000 pid=3960 clone guuid=4391bd90-1a00-0000-a786-f99e790f0000 pid=3961 /tmp/WTF net send-data zombie guuid=a1b77790-1a00-0000-a786-f99e750f0000 pid=3957->guuid=4391bd90-1a00-0000-a786-f99e790f0000 pid=3961 clone guuid=4391bd90-1a00-0000-a786-f99e790f0000 pid=3961->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4391bd90-1a00-0000-a786-f99e790f0000 pid=3961->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B guuid=abfecc90-1a00-0000-a786-f99e7a0f0000 pid=3962->1abdd55f-79cd-53ae-abf5-622946afe271 send: 150B guuid=6702b59a-1a00-0000-a786-f99e940f0000 pid=3988->1abdd55f-79cd-53ae-abf5-622946afe271 send: 99B guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4cc56fa6-1a00-0000-a786-f99eb80f0000 pid=4024 /tmp/WTF guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023->guuid=4cc56fa6-1a00-0000-a786-f99eb80f0000 pid=4024 clone guuid=269074a6-1a00-0000-a786-f99eb90f0000 pid=4025 /tmp/WTF guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023->guuid=269074a6-1a00-0000-a786-f99eb90f0000 pid=4025 clone guuid=538278a6-1a00-0000-a786-f99eba0f0000 pid=4026 /tmp/WTF net send-data zombie guuid=7cba2aa6-1a00-0000-a786-f99eb70f0000 pid=4023->guuid=538278a6-1a00-0000-a786-f99eba0f0000 pid=4026 clone guuid=538278a6-1a00-0000-a786-f99eba0f0000 pid=4026->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=538278a6-1a00-0000-a786-f99eba0f0000 pid=4026->56a397e1-01ee-52ae-86ff-e29a19f15864 send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-17 15:07:49 UTC
File Type:
Text (Shell)
AV detection:
24 of 38 (63.16%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c218a3067ba3d62259fdc61811a686d751fde495914a5ea662f6a08b7ff62018

(this sample)

  
Delivery method
Distributed via web download

Comments