MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 cb912d3295673bb37e533d3c8b61d347ef1ba344c3c33f51552dfdc9c2eb44aa. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 2 File information Comments

SHA256 hash: cb912d3295673bb37e533d3c8b61d347ef1ba344c3c33f51552dfdc9c2eb44aa
SHA3-384 hash: bb48f943a0f7891e5bcc1cce4d676499bcd672c1bd0b90b2a8d4bfd8d17c508ec13fc6c6a464944a427b22e98999ecc1
SHA1 hash: 6b555051ce4628879d2948c50595da2a4101361f
MD5 hash: 7919151e719f835eab006c5a1c910277
humanhash: enemy-gee-louisiana-minnesota
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2026-04-01 05:51:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vBA7gA7N7hBATA6GBAg7AzPBAjAKWBAdAoUBA7dA7o7UBAfWA3bBAQA9RBAJAcgR:vBA7gA7N7hBATA6GBAg7AzPBAjAKWBAI
TLSH T15D51DEC651880C349D636E53EA76C19C71CA917128FAEBE5DACCF5E4814EE983940753
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter adliwahid
Tags:mirai
URLMalware sample (SHA256 hash)SignatureTags
http://82.23.183.167/hiddenbin/boatnet.x86aed989d84071a05da9662f9b1de8d36973fdebcc641e9e9001c341dd899eebdf Miraimirai
http://82.23.183.167/hiddenbin/boatnet.mipsac914fe1b0ce527bb7f29f31bde365151a6fb65729e5980ff38b085b579bc457 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.arcbdd064c7894244e3b8b7465dbef00be1c64d588d8459d0d90884fd042c968ea1 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://82.23.183.167/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://82.23.183.167/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://82.23.183.167/hiddenbin/boatnet.mpslba4d2f103407816f75eb623830dd96d5bf1a368cfbdb47c604bb1f528c11e84d Miraimirai
http://82.23.183.167/hiddenbin/boatnet.arm8221d526fa678fec87590cb98767ca21cce09930dfae8701062db22083a4418f Miraimirai
http://82.23.183.167/hiddenbin/boatnet.arm572e34026135410e3c8a717bb3cb16fe624b7259d88fbdfb1bb20dcadaf3aa386 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.arm660497d4f2b60430f0ad48b50cdaa204b0d1f429cf3874aef811a0ce2ea35121f Miraimirai
http://82.23.183.167/hiddenbin/boatnet.arm753698d89b3cce77d5023d421e065ffd2170019f91c219862d5985278d082a1b9 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.ppc3b4659ca648c5e42edbb1db07d331f9f0561d6adadd6f7a3537c6ddfa3656346 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.spc61f919f38d1244ffaa6afd556fbac3550e4e27f50fd07a84f8908d3f19eb5978 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.m68k3edd11ac6dc90a27a991b2c3c5cd1bf5f8c6b66732e81fef3d02ff9e0a6dd212 Miraimirai
http://82.23.183.167/hiddenbin/boatnet.sh4985cb51febf70a96b96a977e2fb01d54d5b9f38a5930581e4e0fbdd1b1a35dd4 Miraimirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
NL NL
Vendor Threat Intelligence
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-03-31T23:26:00Z UTC
Last seen:
2026-04-01T14:21:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=5dd041b2-1d00-0000-819d-abb69a090000 pid=2458 /usr/bin/sudo guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465 /tmp/sample.bin guuid=5dd041b2-1d00-0000-819d-abb69a090000 pid=2458->guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465 execve guuid=0916e2b5-1d00-0000-819d-abb6a4090000 pid=2468 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=0916e2b5-1d00-0000-819d-abb6a4090000 pid=2468 execve guuid=ef1b2abc-1d00-0000-819d-abb6b0090000 pid=2480 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=ef1b2abc-1d00-0000-819d-abb6b0090000 pid=2480 execve guuid=e3964ac9-1d00-0000-819d-abb6c7090000 pid=2503 /usr/bin/cat guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=e3964ac9-1d00-0000-819d-abb6c7090000 pid=2503 execve guuid=e906aec9-1d00-0000-819d-abb6c9090000 pid=2505 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=e906aec9-1d00-0000-819d-abb6c9090000 pid=2505 execve guuid=fffa07ca-1d00-0000-819d-abb6ca090000 pid=2506 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=fffa07ca-1d00-0000-819d-abb6ca090000 pid=2506 execve guuid=416160ca-1d00-0000-819d-abb6cd090000 pid=2509 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=416160ca-1d00-0000-819d-abb6cd090000 pid=2509 execve guuid=637a25cd-1d00-0000-819d-abb6d6090000 pid=2518 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=637a25cd-1d00-0000-819d-abb6d6090000 pid=2518 execve guuid=06a424d1-1d00-0000-819d-abb6de090000 pid=2526 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=06a424d1-1d00-0000-819d-abb6de090000 pid=2526 clone guuid=01cc56d1-1d00-0000-819d-abb6df090000 pid=2527 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=01cc56d1-1d00-0000-819d-abb6df090000 pid=2527 execve guuid=2390b5d1-1d00-0000-819d-abb6e1090000 pid=2529 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=2390b5d1-1d00-0000-819d-abb6e1090000 pid=2529 execve guuid=f4fc33d2-1d00-0000-819d-abb6e5090000 pid=2533 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=f4fc33d2-1d00-0000-819d-abb6e5090000 pid=2533 execve guuid=2c0a52d5-1d00-0000-819d-abb6ec090000 pid=2540 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=2c0a52d5-1d00-0000-819d-abb6ec090000 pid=2540 execve guuid=b5e678db-1d00-0000-819d-abb6fa090000 pid=2554 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=b5e678db-1d00-0000-819d-abb6fa090000 pid=2554 clone guuid=7e5ca0db-1d00-0000-819d-abb6fb090000 pid=2555 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=7e5ca0db-1d00-0000-819d-abb6fb090000 pid=2555 execve guuid=c76bfcdb-1d00-0000-819d-abb6fd090000 pid=2557 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=c76bfcdb-1d00-0000-819d-abb6fd090000 pid=2557 execve guuid=5d3653dc-1d00-0000-819d-abb6010a0000 pid=2561 /usr/bin/wget net send-data guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=5d3653dc-1d00-0000-819d-abb6010a0000 pid=2561 execve guuid=a0cf2ade-1d00-0000-819d-abb6070a0000 pid=2567 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=a0cf2ade-1d00-0000-819d-abb6070a0000 pid=2567 execve guuid=2136dbe1-1d00-0000-819d-abb6140a0000 pid=2580 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=2136dbe1-1d00-0000-819d-abb6140a0000 pid=2580 clone guuid=b60607e2-1d00-0000-819d-abb6150a0000 pid=2581 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=b60607e2-1d00-0000-819d-abb6150a0000 pid=2581 execve guuid=8a317be2-1d00-0000-819d-abb6180a0000 pid=2584 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=8a317be2-1d00-0000-819d-abb6180a0000 pid=2584 execve guuid=6a6cd7e2-1d00-0000-819d-abb61c0a0000 pid=2588 /usr/bin/wget net send-data guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=6a6cd7e2-1d00-0000-819d-abb61c0a0000 pid=2588 execve guuid=46a1b7e4-1d00-0000-819d-abb6230a0000 pid=2595 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=46a1b7e4-1d00-0000-819d-abb6230a0000 pid=2595 execve guuid=263362e7-1d00-0000-819d-abb62c0a0000 pid=2604 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=263362e7-1d00-0000-819d-abb62c0a0000 pid=2604 clone guuid=95db7ee7-1d00-0000-819d-abb62d0a0000 pid=2605 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=95db7ee7-1d00-0000-819d-abb62d0a0000 pid=2605 execve guuid=54f4f2e7-1d00-0000-819d-abb6300a0000 pid=2608 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=54f4f2e7-1d00-0000-819d-abb6300a0000 pid=2608 execve guuid=ba2a35e8-1d00-0000-819d-abb6340a0000 pid=2612 /usr/bin/wget net send-data guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=ba2a35e8-1d00-0000-819d-abb6340a0000 pid=2612 execve guuid=86ac71ea-1d00-0000-819d-abb63a0a0000 pid=2618 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=86ac71ea-1d00-0000-819d-abb63a0a0000 pid=2618 execve guuid=3f5584ee-1d00-0000-819d-abb6430a0000 pid=2627 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=3f5584ee-1d00-0000-819d-abb6430a0000 pid=2627 clone guuid=0284a4ee-1d00-0000-819d-abb6440a0000 pid=2628 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=0284a4ee-1d00-0000-819d-abb6440a0000 pid=2628 execve guuid=3a3a35ef-1d00-0000-819d-abb6460a0000 pid=2630 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=3a3a35ef-1d00-0000-819d-abb6460a0000 pid=2630 execve guuid=165b99ef-1d00-0000-819d-abb64b0a0000 pid=2635 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=165b99ef-1d00-0000-819d-abb64b0a0000 pid=2635 execve guuid=029393f2-1d00-0000-819d-abb6530a0000 pid=2643 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=029393f2-1d00-0000-819d-abb6530a0000 pid=2643 execve guuid=1492235e-1e00-0000-819d-abb63a0b0000 pid=2874 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=1492235e-1e00-0000-819d-abb63a0b0000 pid=2874 clone guuid=d8183e5e-1e00-0000-819d-abb63b0b0000 pid=2875 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=d8183e5e-1e00-0000-819d-abb63b0b0000 pid=2875 execve guuid=0bd9b55e-1e00-0000-819d-abb63d0b0000 pid=2877 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=0bd9b55e-1e00-0000-819d-abb63d0b0000 pid=2877 execve guuid=d7c45b5f-1e00-0000-819d-abb6410b0000 pid=2881 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=d7c45b5f-1e00-0000-819d-abb6410b0000 pid=2881 execve guuid=bf317162-1e00-0000-819d-abb6470b0000 pid=2887 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=bf317162-1e00-0000-819d-abb6470b0000 pid=2887 execve guuid=3da80966-1e00-0000-819d-abb64d0b0000 pid=2893 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=3da80966-1e00-0000-819d-abb64d0b0000 pid=2893 clone guuid=d96a2566-1e00-0000-819d-abb64e0b0000 pid=2894 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=d96a2566-1e00-0000-819d-abb64e0b0000 pid=2894 execve guuid=552cb266-1e00-0000-819d-abb6500b0000 pid=2896 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=552cb266-1e00-0000-819d-abb6500b0000 pid=2896 execve guuid=66992267-1e00-0000-819d-abb6540b0000 pid=2900 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=66992267-1e00-0000-819d-abb6540b0000 pid=2900 execve guuid=1e538769-1e00-0000-819d-abb65a0b0000 pid=2906 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=1e538769-1e00-0000-819d-abb65a0b0000 pid=2906 execve guuid=afbeae6c-1e00-0000-819d-abb6620b0000 pid=2914 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=afbeae6c-1e00-0000-819d-abb6620b0000 pid=2914 clone guuid=7d3dd26c-1e00-0000-819d-abb6630b0000 pid=2915 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=7d3dd26c-1e00-0000-819d-abb6630b0000 pid=2915 execve guuid=e81d496d-1e00-0000-819d-abb6660b0000 pid=2918 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=e81d496d-1e00-0000-819d-abb6660b0000 pid=2918 execve guuid=8b2e976d-1e00-0000-819d-abb66a0b0000 pid=2922 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=8b2e976d-1e00-0000-819d-abb66a0b0000 pid=2922 execve guuid=7111dd6f-1e00-0000-819d-abb6710b0000 pid=2929 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=7111dd6f-1e00-0000-819d-abb6710b0000 pid=2929 execve guuid=5faac972-1e00-0000-819d-abb67b0b0000 pid=2939 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=5faac972-1e00-0000-819d-abb67b0b0000 pid=2939 clone guuid=fb6bef72-1e00-0000-819d-abb67c0b0000 pid=2940 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=fb6bef72-1e00-0000-819d-abb67c0b0000 pid=2940 execve guuid=20463f73-1e00-0000-819d-abb67e0b0000 pid=2942 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=20463f73-1e00-0000-819d-abb67e0b0000 pid=2942 execve guuid=a0377e73-1e00-0000-819d-abb6810b0000 pid=2945 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=a0377e73-1e00-0000-819d-abb6810b0000 pid=2945 execve guuid=859af075-1e00-0000-819d-abb68a0b0000 pid=2954 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=859af075-1e00-0000-819d-abb68a0b0000 pid=2954 execve guuid=7437ed79-1e00-0000-819d-abb6950b0000 pid=2965 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=7437ed79-1e00-0000-819d-abb6950b0000 pid=2965 clone guuid=51400e7a-1e00-0000-819d-abb6960b0000 pid=2966 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=51400e7a-1e00-0000-819d-abb6960b0000 pid=2966 execve guuid=9adb7a7a-1e00-0000-819d-abb6980b0000 pid=2968 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=9adb7a7a-1e00-0000-819d-abb6980b0000 pid=2968 execve guuid=0158d77a-1e00-0000-819d-abb69d0b0000 pid=2973 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=0158d77a-1e00-0000-819d-abb69d0b0000 pid=2973 execve guuid=b35a2a7d-1e00-0000-819d-abb6a40b0000 pid=2980 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=b35a2a7d-1e00-0000-819d-abb6a40b0000 pid=2980 execve guuid=f4b60e80-1e00-0000-819d-abb6ad0b0000 pid=2989 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=f4b60e80-1e00-0000-819d-abb6ad0b0000 pid=2989 clone guuid=c5512a80-1e00-0000-819d-abb6af0b0000 pid=2991 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=c5512a80-1e00-0000-819d-abb6af0b0000 pid=2991 execve guuid=5021a680-1e00-0000-819d-abb6b20b0000 pid=2994 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=5021a680-1e00-0000-819d-abb6b20b0000 pid=2994 execve guuid=699fdb80-1e00-0000-819d-abb6b50b0000 pid=2997 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=699fdb80-1e00-0000-819d-abb6b50b0000 pid=2997 execve guuid=07d15683-1e00-0000-819d-abb6b90b0000 pid=3001 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=07d15683-1e00-0000-819d-abb6b90b0000 pid=3001 execve guuid=7f895387-1e00-0000-819d-abb6c10b0000 pid=3009 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=7f895387-1e00-0000-819d-abb6c10b0000 pid=3009 clone guuid=c7007187-1e00-0000-819d-abb6c20b0000 pid=3010 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=c7007187-1e00-0000-819d-abb6c20b0000 pid=3010 execve guuid=befbb987-1e00-0000-819d-abb6c40b0000 pid=3012 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=befbb987-1e00-0000-819d-abb6c40b0000 pid=3012 execve guuid=9a9bfb87-1e00-0000-819d-abb6c70b0000 pid=3015 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=9a9bfb87-1e00-0000-819d-abb6c70b0000 pid=3015 execve guuid=1a929d8a-1e00-0000-819d-abb6cf0b0000 pid=3023 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=1a929d8a-1e00-0000-819d-abb6cf0b0000 pid=3023 execve guuid=cb63508e-1e00-0000-819d-abb6d90b0000 pid=3033 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=cb63508e-1e00-0000-819d-abb6d90b0000 pid=3033 clone guuid=1f50748e-1e00-0000-819d-abb6db0b0000 pid=3035 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=1f50748e-1e00-0000-819d-abb6db0b0000 pid=3035 execve guuid=6e5ec58e-1e00-0000-819d-abb6dc0b0000 pid=3036 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=6e5ec58e-1e00-0000-819d-abb6dc0b0000 pid=3036 execve guuid=530a048f-1e00-0000-819d-abb6e00b0000 pid=3040 /usr/bin/wget net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=530a048f-1e00-0000-819d-abb6e00b0000 pid=3040 execve guuid=fd4c7191-1e00-0000-819d-abb6e50b0000 pid=3045 /usr/bin/curl net send-data write-file guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=fd4c7191-1e00-0000-819d-abb6e50b0000 pid=3045 execve guuid=99a9a894-1e00-0000-819d-abb6ec0b0000 pid=3052 /usr/bin/bash guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=99a9a894-1e00-0000-819d-abb6ec0b0000 pid=3052 clone guuid=a977d794-1e00-0000-819d-abb6ee0b0000 pid=3054 /usr/bin/chmod guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=a977d794-1e00-0000-819d-abb6ee0b0000 pid=3054 execve guuid=590c5c95-1e00-0000-819d-abb6f00b0000 pid=3056 /tmp/WTF net guuid=9efafdb4-1d00-0000-819d-abb6a1090000 pid=2465->guuid=590c5c95-1e00-0000-819d-abb6f00b0000 pid=3056 execve d65d9914-4729-548c-af00-708f45624fbf 82.23.183.167:80 guuid=0916e2b5-1d00-0000-819d-abb6a4090000 pid=2468->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=ef1b2abc-1d00-0000-819d-abb6b0090000 pid=2480->d65d9914-4729-548c-af00-708f45624fbf send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fffa07ca-1d00-0000-819d-abb6ca090000 pid=2506->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bb5a3bca-1d00-0000-819d-abb6cb090000 pid=2507 /tmp/WTF guuid=fffa07ca-1d00-0000-819d-abb6ca090000 pid=2506->guuid=bb5a3bca-1d00-0000-819d-abb6cb090000 pid=2507 clone guuid=0cbe3fca-1d00-0000-819d-abb6cc090000 pid=2508 /tmp/WTF net zombie guuid=fffa07ca-1d00-0000-819d-abb6ca090000 pid=2506->guuid=0cbe3fca-1d00-0000-819d-abb6cc090000 pid=2508 clone 21052afb-603e-5e1a-9b71-92fcfbf936f1 82.23.183.167:3778 guuid=0cbe3fca-1d00-0000-819d-abb6cc090000 pid=2508->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=416160ca-1d00-0000-819d-abb6cd090000 pid=2509->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=637a25cd-1d00-0000-819d-abb6d6090000 pid=2518->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=2390b5d1-1d00-0000-819d-abb6e1090000 pid=2529->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d91dfcd1-1d00-0000-819d-abb6e3090000 pid=2531 /tmp/WTF guuid=2390b5d1-1d00-0000-819d-abb6e1090000 pid=2529->guuid=d91dfcd1-1d00-0000-819d-abb6e3090000 pid=2531 clone guuid=815301d2-1d00-0000-819d-abb6e4090000 pid=2532 /tmp/WTF net zombie guuid=2390b5d1-1d00-0000-819d-abb6e1090000 pid=2529->guuid=815301d2-1d00-0000-819d-abb6e4090000 pid=2532 clone guuid=815301d2-1d00-0000-819d-abb6e4090000 pid=2532->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=f4fc33d2-1d00-0000-819d-abb6e5090000 pid=2533->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=2c0a52d5-1d00-0000-819d-abb6ec090000 pid=2540->d65d9914-4729-548c-af00-708f45624fbf send: 98B guuid=c76bfcdb-1d00-0000-819d-abb6fd090000 pid=2557->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=456f3fdc-1d00-0000-819d-abb6ff090000 pid=2559 /tmp/WTF guuid=c76bfcdb-1d00-0000-819d-abb6fd090000 pid=2557->guuid=456f3fdc-1d00-0000-819d-abb6ff090000 pid=2559 clone guuid=700d45dc-1d00-0000-819d-abb6000a0000 pid=2560 /tmp/WTF net zombie guuid=c76bfcdb-1d00-0000-819d-abb6fd090000 pid=2557->guuid=700d45dc-1d00-0000-819d-abb6000a0000 pid=2560 clone guuid=700d45dc-1d00-0000-819d-abb6000a0000 pid=2560->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=5d3653dc-1d00-0000-819d-abb6010a0000 pid=2561->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=a0cf2ade-1d00-0000-819d-abb6070a0000 pid=2567->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=8a317be2-1d00-0000-819d-abb6180a0000 pid=2584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=00e9c1e2-1d00-0000-819d-abb6190a0000 pid=2585 /tmp/WTF guuid=8a317be2-1d00-0000-819d-abb6180a0000 pid=2584->guuid=00e9c1e2-1d00-0000-819d-abb6190a0000 pid=2585 clone guuid=3713c8e2-1d00-0000-819d-abb61b0a0000 pid=2587 /tmp/WTF net zombie guuid=8a317be2-1d00-0000-819d-abb6180a0000 pid=2584->guuid=3713c8e2-1d00-0000-819d-abb61b0a0000 pid=2587 clone guuid=3713c8e2-1d00-0000-819d-abb61b0a0000 pid=2587->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=6a6cd7e2-1d00-0000-819d-abb61c0a0000 pid=2588->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=46a1b7e4-1d00-0000-819d-abb6230a0000 pid=2595->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=54f4f2e7-1d00-0000-819d-abb6300a0000 pid=2608->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=592225e8-1d00-0000-819d-abb6320a0000 pid=2610 /tmp/WTF guuid=54f4f2e7-1d00-0000-819d-abb6300a0000 pid=2608->guuid=592225e8-1d00-0000-819d-abb6320a0000 pid=2610 clone guuid=c13c28e8-1d00-0000-819d-abb6330a0000 pid=2611 /tmp/WTF net zombie guuid=54f4f2e7-1d00-0000-819d-abb6300a0000 pid=2608->guuid=c13c28e8-1d00-0000-819d-abb6330a0000 pid=2611 clone guuid=c13c28e8-1d00-0000-819d-abb6330a0000 pid=2611->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=ba2a35e8-1d00-0000-819d-abb6340a0000 pid=2612->d65d9914-4729-548c-af00-708f45624fbf send: 152B guuid=86ac71ea-1d00-0000-819d-abb63a0a0000 pid=2618->d65d9914-4729-548c-af00-708f45624fbf send: 101B guuid=3a3a35ef-1d00-0000-819d-abb6460a0000 pid=2630->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7d2f82ef-1d00-0000-819d-abb6480a0000 pid=2632 /tmp/WTF guuid=3a3a35ef-1d00-0000-819d-abb6460a0000 pid=2630->guuid=7d2f82ef-1d00-0000-819d-abb6480a0000 pid=2632 clone guuid=ae1688ef-1d00-0000-819d-abb6490a0000 pid=2633 /tmp/WTF net zombie guuid=3a3a35ef-1d00-0000-819d-abb6460a0000 pid=2630->guuid=ae1688ef-1d00-0000-819d-abb6490a0000 pid=2633 clone guuid=ae1688ef-1d00-0000-819d-abb6490a0000 pid=2633->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=165b99ef-1d00-0000-819d-abb64b0a0000 pid=2635->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=029393f2-1d00-0000-819d-abb6530a0000 pid=2643->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=0bd9b55e-1e00-0000-819d-abb63d0b0000 pid=2877->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9e2beb5e-1e00-0000-819d-abb63e0b0000 pid=2878 /tmp/WTF guuid=0bd9b55e-1e00-0000-819d-abb63d0b0000 pid=2877->guuid=9e2beb5e-1e00-0000-819d-abb63e0b0000 pid=2878 clone guuid=57beef5e-1e00-0000-819d-abb63f0b0000 pid=2879 /tmp/WTF net zombie guuid=0bd9b55e-1e00-0000-819d-abb63d0b0000 pid=2877->guuid=57beef5e-1e00-0000-819d-abb63f0b0000 pid=2879 clone guuid=57beef5e-1e00-0000-819d-abb63f0b0000 pid=2879->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=d7c45b5f-1e00-0000-819d-abb6410b0000 pid=2881->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=bf317162-1e00-0000-819d-abb6470b0000 pid=2887->d65d9914-4729-548c-af00-708f45624fbf send: 98B guuid=552cb266-1e00-0000-819d-abb6500b0000 pid=2896->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=77e41167-1e00-0000-819d-abb6520b0000 pid=2898 /tmp/WTF guuid=552cb266-1e00-0000-819d-abb6500b0000 pid=2896->guuid=77e41167-1e00-0000-819d-abb6520b0000 pid=2898 clone guuid=ceac1767-1e00-0000-819d-abb6530b0000 pid=2899 /tmp/WTF net zombie guuid=552cb266-1e00-0000-819d-abb6500b0000 pid=2896->guuid=ceac1767-1e00-0000-819d-abb6530b0000 pid=2899 clone guuid=ceac1767-1e00-0000-819d-abb6530b0000 pid=2899->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=66992267-1e00-0000-819d-abb6540b0000 pid=2900->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=1e538769-1e00-0000-819d-abb65a0b0000 pid=2906->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=e81d496d-1e00-0000-819d-abb6660b0000 pid=2918->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=901c7d6d-1e00-0000-819d-abb6670b0000 pid=2919 /tmp/WTF guuid=e81d496d-1e00-0000-819d-abb6660b0000 pid=2918->guuid=901c7d6d-1e00-0000-819d-abb6670b0000 pid=2919 clone guuid=ef01816d-1e00-0000-819d-abb6680b0000 pid=2920 /tmp/WTF net zombie guuid=e81d496d-1e00-0000-819d-abb6660b0000 pid=2918->guuid=ef01816d-1e00-0000-819d-abb6680b0000 pid=2920 clone guuid=ef01816d-1e00-0000-819d-abb6680b0000 pid=2920->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=8b2e976d-1e00-0000-819d-abb66a0b0000 pid=2922->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=7111dd6f-1e00-0000-819d-abb6710b0000 pid=2929->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=20463f73-1e00-0000-819d-abb67e0b0000 pid=2942->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62f56e73-1e00-0000-819d-abb67f0b0000 pid=2943 /tmp/WTF guuid=20463f73-1e00-0000-819d-abb67e0b0000 pid=2942->guuid=62f56e73-1e00-0000-819d-abb67f0b0000 pid=2943 clone guuid=cbfc7173-1e00-0000-819d-abb6800b0000 pid=2944 /tmp/WTF net zombie guuid=20463f73-1e00-0000-819d-abb67e0b0000 pid=2942->guuid=cbfc7173-1e00-0000-819d-abb6800b0000 pid=2944 clone guuid=cbfc7173-1e00-0000-819d-abb6800b0000 pid=2944->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=a0377e73-1e00-0000-819d-abb6810b0000 pid=2945->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=859af075-1e00-0000-819d-abb68a0b0000 pid=2954->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=9adb7a7a-1e00-0000-819d-abb6980b0000 pid=2968->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e01c47a-1e00-0000-819d-abb69a0b0000 pid=2970 /tmp/WTF guuid=9adb7a7a-1e00-0000-819d-abb6980b0000 pid=2968->guuid=1e01c47a-1e00-0000-819d-abb69a0b0000 pid=2970 clone guuid=ead1c87a-1e00-0000-819d-abb69c0b0000 pid=2972 /tmp/WTF net zombie guuid=9adb7a7a-1e00-0000-819d-abb6980b0000 pid=2968->guuid=ead1c87a-1e00-0000-819d-abb69c0b0000 pid=2972 clone guuid=ead1c87a-1e00-0000-819d-abb69c0b0000 pid=2972->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=0158d77a-1e00-0000-819d-abb69d0b0000 pid=2973->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=b35a2a7d-1e00-0000-819d-abb6a40b0000 pid=2980->d65d9914-4729-548c-af00-708f45624fbf send: 98B guuid=5021a680-1e00-0000-819d-abb6b20b0000 pid=2994->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2bfed080-1e00-0000-819d-abb6b30b0000 pid=2995 /tmp/WTF guuid=5021a680-1e00-0000-819d-abb6b20b0000 pid=2994->guuid=2bfed080-1e00-0000-819d-abb6b30b0000 pid=2995 clone guuid=128cd480-1e00-0000-819d-abb6b40b0000 pid=2996 /tmp/WTF net zombie guuid=5021a680-1e00-0000-819d-abb6b20b0000 pid=2994->guuid=128cd480-1e00-0000-819d-abb6b40b0000 pid=2996 clone guuid=128cd480-1e00-0000-819d-abb6b40b0000 pid=2996->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=699fdb80-1e00-0000-819d-abb6b50b0000 pid=2997->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=07d15683-1e00-0000-819d-abb6b90b0000 pid=3001->d65d9914-4729-548c-af00-708f45624fbf send: 98B guuid=befbb987-1e00-0000-819d-abb6c40b0000 pid=3012->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f051e987-1e00-0000-819d-abb6c50b0000 pid=3013 /tmp/WTF guuid=befbb987-1e00-0000-819d-abb6c40b0000 pid=3012->guuid=f051e987-1e00-0000-819d-abb6c50b0000 pid=3013 clone guuid=1aadec87-1e00-0000-819d-abb6c60b0000 pid=3014 /tmp/WTF net zombie guuid=befbb987-1e00-0000-819d-abb6c40b0000 pid=3012->guuid=1aadec87-1e00-0000-819d-abb6c60b0000 pid=3014 clone guuid=1aadec87-1e00-0000-819d-abb6c60b0000 pid=3014->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=9a9bfb87-1e00-0000-819d-abb6c70b0000 pid=3015->d65d9914-4729-548c-af00-708f45624fbf send: 150B guuid=1a929d8a-1e00-0000-819d-abb6cf0b0000 pid=3023->d65d9914-4729-548c-af00-708f45624fbf send: 99B guuid=6e5ec58e-1e00-0000-819d-abb6dc0b0000 pid=3036->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bd81f48e-1e00-0000-819d-abb6de0b0000 pid=3038 /tmp/WTF guuid=6e5ec58e-1e00-0000-819d-abb6dc0b0000 pid=3036->guuid=bd81f48e-1e00-0000-819d-abb6de0b0000 pid=3038 clone guuid=bca7f78e-1e00-0000-819d-abb6df0b0000 pid=3039 /tmp/WTF net zombie guuid=6e5ec58e-1e00-0000-819d-abb6dc0b0000 pid=3036->guuid=bca7f78e-1e00-0000-819d-abb6df0b0000 pid=3039 clone guuid=bca7f78e-1e00-0000-819d-abb6df0b0000 pid=3039->21052afb-603e-5e1a-9b71-92fcfbf936f1 con guuid=530a048f-1e00-0000-819d-abb6e00b0000 pid=3040->d65d9914-4729-548c-af00-708f45624fbf send: 149B guuid=fd4c7191-1e00-0000-819d-abb6e50b0000 pid=3045->d65d9914-4729-548c-af00-708f45624fbf send: 98B guuid=590c5c95-1e00-0000-819d-abb6f00b0000 pid=3056->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba439595-1e00-0000-819d-abb6f20b0000 pid=3058 /tmp/WTF guuid=590c5c95-1e00-0000-819d-abb6f00b0000 pid=3056->guuid=ba439595-1e00-0000-819d-abb6f20b0000 pid=3058 clone guuid=de469a95-1e00-0000-819d-abb6f30b0000 pid=3059 /tmp/WTF net zombie guuid=590c5c95-1e00-0000-819d-abb6f00b0000 pid=3056->guuid=de469a95-1e00-0000-819d-abb6f30b0000 pid=3059 clone guuid=de469a95-1e00-0000-819d-abb6f30b0000 pid=3059->21052afb-603e-5e1a-9b71-92fcfbf936f1 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-04-01 05:52:47 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh cb912d3295673bb37e533d3c8b61d347ef1ba344c3c33f51552dfdc9c2eb44aa

(this sample)

  
Delivery method
Distributed via web download

Comments