MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d58011db0b5bb21a50387d8f0d7e6a4da6fa0c9a896fb28709b23f4f47631007. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: d58011db0b5bb21a50387d8f0d7e6a4da6fa0c9a896fb28709b23f4f47631007
SHA3-384 hash: 68ca74c729598fd169096140381f69dcc7c43861e6c903c69b7f7d880cca13536afd31d971aebc5ee1dc2af131d9c93a
SHA1 hash: 042e719edecb03c16704028a90b099edd2f8a0e1
MD5 hash: 8ead438a4ce2a502f119e01584382a95
humanhash: island-solar-bluebird-wisconsin
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2025-09-06 18:32:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vx7Q7N7hxD6Gxg7zPxzKWxdoUx7d7o7Uxfu3bxg9RxJcgxkpVx7SOxv+Cx+fTx2G:vx7Q7N7hxD6Gxg7zPxzKWxdoUx7d7o7G
TLSH T18F51A38787768EB828636A17F7B681783081D0939CF9EB99EBC4BBE0834ED143154753
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.79.126.103/hiddenbin/boatnet.x86103c7baac2ecef90db8e4583e56cdb0e93c006552019339a6ea5e67282b57c7f Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.mips79f477ddebaddf16cf5965c31b2c480d82742fc7207d512071049e337b1a84a5 Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.arcn/an/aelf ua-wget
http://45.79.126.103/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://45.79.126.103/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://45.79.126.103/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://45.79.126.103/hiddenbin/boatnet.mpsl090c9dd8540ee3bcdd8fec6ecedb657439820b2a9a2c092260d5f288a1574515 Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.armf5fd00d981f5e3987816ac6c68e4eb91eed42e5775169b74984a48ff44f4cb78 Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.arm5ff4af9890c5d89f5eccf39ae5ee1ce0298bb48255069905599ac75f05a72e755 Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.arm6788d9e6ae51a80f3f5b6647db426f171c62a8d7026e777d0d52a393bb06ed9b9 Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.arm7afeeb691c7733d1c3ac33a8a88f4e496323ad5346f8925c8f057bd1d8e4459bc Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.ppc964f2f6e2bcf4bb33ee4ffe3db2e184722001b05ea499cf3892e0d43e2b1d96e Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://45.79.126.103/hiddenbin/boatnet.m68ke0e4fe62b7d6de7c7f84cc9f6a7082f20c0eed2967b0370f6b814a802476d17f Miraicensys elf mirai ua-wget
http://45.79.126.103/hiddenbin/boatnet.sh45e6e33f93d093c1f992e80f3d31758ff7ccb4ad97449022a75c6e2fc4566eaa8 Miraicensys elf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-06T16:04:00Z UTC
Last seen:
2025-09-06T16:04:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=ce42d226-1800-0000-16b9-01d5d20c0000 pid=3282 /usr/bin/sudo guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289 /tmp/sample.bin guuid=ce42d226-1800-0000-16b9-01d5d20c0000 pid=3282->guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289 execve guuid=13f97b2a-1800-0000-16b9-01d5db0c0000 pid=3291 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=13f97b2a-1800-0000-16b9-01d5db0c0000 pid=3291 execve guuid=30d4088a-1800-0000-16b9-01d56e0d0000 pid=3438 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=30d4088a-1800-0000-16b9-01d56e0d0000 pid=3438 execve guuid=30fc02ef-1800-0000-16b9-01d50a0e0000 pid=3594 /usr/bin/cat guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=30fc02ef-1800-0000-16b9-01d50a0e0000 pid=3594 execve guuid=d0e87cef-1800-0000-16b9-01d50b0e0000 pid=3595 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=d0e87cef-1800-0000-16b9-01d50b0e0000 pid=3595 execve guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596 execve guuid=d11d93f0-1800-0000-16b9-01d5100e0000 pid=3600 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=d11d93f0-1800-0000-16b9-01d5100e0000 pid=3600 execve guuid=70dc9a51-1900-0000-16b9-01d5ac0e0000 pid=3756 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=70dc9a51-1900-0000-16b9-01d5ac0e0000 pid=3756 execve guuid=f66eeeb5-1900-0000-16b9-01d5960f0000 pid=3990 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=f66eeeb5-1900-0000-16b9-01d5960f0000 pid=3990 clone guuid=472021b6-1900-0000-16b9-01d5970f0000 pid=3991 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=472021b6-1900-0000-16b9-01d5970f0000 pid=3991 execve guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995 execve guuid=8d0bd4b7-1900-0000-16b9-01d5a10f0000 pid=4001 /usr/bin/wget net send-data guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=8d0bd4b7-1900-0000-16b9-01d5a10f0000 pid=4001 execve guuid=cca3dff4-1900-0000-16b9-01d53e100000 pid=4158 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=cca3dff4-1900-0000-16b9-01d53e100000 pid=4158 execve guuid=244ece28-1a00-0000-16b9-01d5e8100000 pid=4328 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=244ece28-1a00-0000-16b9-01d5e8100000 pid=4328 clone guuid=a4a9ee28-1a00-0000-16b9-01d5e9100000 pid=4329 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=a4a9ee28-1a00-0000-16b9-01d5e9100000 pid=4329 execve guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331 execve guuid=353fb72a-1a00-0000-16b9-01d5f2100000 pid=4338 /usr/bin/wget net send-data guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=353fb72a-1a00-0000-16b9-01d5f2100000 pid=4338 execve guuid=16bc9f6f-1a00-0000-16b9-01d5ae110000 pid=4526 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=16bc9f6f-1a00-0000-16b9-01d5ae110000 pid=4526 execve guuid=6ebdc5a0-1a00-0000-16b9-01d52b120000 pid=4651 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=6ebdc5a0-1a00-0000-16b9-01d52b120000 pid=4651 clone guuid=5743efa0-1a00-0000-16b9-01d52c120000 pid=4652 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=5743efa0-1a00-0000-16b9-01d52c120000 pid=4652 execve guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653 execve guuid=b16604a2-1a00-0000-16b9-01d533120000 pid=4659 /usr/bin/wget net send-data guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b16604a2-1a00-0000-16b9-01d533120000 pid=4659 execve guuid=90d232e6-1a00-0000-16b9-01d51e130000 pid=4894 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=90d232e6-1a00-0000-16b9-01d51e130000 pid=4894 execve guuid=44fe1c5f-1b00-0000-16b9-01d57c140000 pid=5244 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=44fe1c5f-1b00-0000-16b9-01d57c140000 pid=5244 clone guuid=7c33455f-1b00-0000-16b9-01d57d140000 pid=5245 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=7c33455f-1b00-0000-16b9-01d57d140000 pid=5245 execve guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246 execve guuid=460e7a60-1b00-0000-16b9-01d582140000 pid=5250 /usr/bin/wget net send-data guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=460e7a60-1b00-0000-16b9-01d582140000 pid=5250 execve guuid=caed91a3-1b00-0000-16b9-01d58e140000 pid=5262 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=caed91a3-1b00-0000-16b9-01d58e140000 pid=5262 execve guuid=c3dad2d9-1b00-0000-16b9-01d58f140000 pid=5263 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=c3dad2d9-1b00-0000-16b9-01d58f140000 pid=5263 clone guuid=50a1fcd9-1b00-0000-16b9-01d590140000 pid=5264 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=50a1fcd9-1b00-0000-16b9-01d590140000 pid=5264 execve guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265 execve guuid=638501dc-1b00-0000-16b9-01d595140000 pid=5269 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=638501dc-1b00-0000-16b9-01d595140000 pid=5269 execve guuid=a6f11877-1c00-0000-16b9-01d59d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=a6f11877-1c00-0000-16b9-01d59d140000 pid=5277 execve guuid=1b4a62d9-1c00-0000-16b9-01d59e140000 pid=5278 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=1b4a62d9-1c00-0000-16b9-01d59e140000 pid=5278 clone guuid=22f1c4d9-1c00-0000-16b9-01d59f140000 pid=5279 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=22f1c4d9-1c00-0000-16b9-01d59f140000 pid=5279 execve guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280 execve guuid=93df65db-1c00-0000-16b9-01d5a4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=93df65db-1c00-0000-16b9-01d5a4140000 pid=5284 execve guuid=2d5338b7-1d00-0000-16b9-01d5c5140000 pid=5317 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=2d5338b7-1d00-0000-16b9-01d5c5140000 pid=5317 execve guuid=51cae418-1e00-0000-16b9-01d5c6140000 pid=5318 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=51cae418-1e00-0000-16b9-01d5c6140000 pid=5318 clone guuid=e9942519-1e00-0000-16b9-01d5c7140000 pid=5319 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=e9942519-1e00-0000-16b9-01d5c7140000 pid=5319 execve guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320 execve guuid=b8451c1b-1e00-0000-16b9-01d5cc140000 pid=5324 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b8451c1b-1e00-0000-16b9-01d5cc140000 pid=5324 execve guuid=ba892a76-1e00-0000-16b9-01d5cd140000 pid=5325 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=ba892a76-1e00-0000-16b9-01d5cd140000 pid=5325 execve guuid=b8bb81d9-1e00-0000-16b9-01d5ce140000 pid=5326 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b8bb81d9-1e00-0000-16b9-01d5ce140000 pid=5326 clone guuid=6c0fbdd9-1e00-0000-16b9-01d5cf140000 pid=5327 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=6c0fbdd9-1e00-0000-16b9-01d5cf140000 pid=5327 execve guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328 execve guuid=8eeaabdb-1e00-0000-16b9-01d5d4140000 pid=5332 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=8eeaabdb-1e00-0000-16b9-01d5d4140000 pid=5332 execve guuid=1f89e76b-1f00-0000-16b9-01d5d5140000 pid=5333 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=1f89e76b-1f00-0000-16b9-01d5d5140000 pid=5333 execve guuid=2a7f99e4-1f00-0000-16b9-01d5d6140000 pid=5334 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=2a7f99e4-1f00-0000-16b9-01d5d6140000 pid=5334 clone guuid=598db9e4-1f00-0000-16b9-01d5d7140000 pid=5335 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=598db9e4-1f00-0000-16b9-01d5d7140000 pid=5335 execve guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336 execve guuid=d051b1e5-1f00-0000-16b9-01d5dc140000 pid=5340 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=d051b1e5-1f00-0000-16b9-01d5dc140000 pid=5340 execve guuid=74a1f740-2000-0000-16b9-01d5dd140000 pid=5341 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=74a1f740-2000-0000-16b9-01d5dd140000 pid=5341 execve guuid=7ee7899f-2000-0000-16b9-01d5de140000 pid=5342 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=7ee7899f-2000-0000-16b9-01d5de140000 pid=5342 clone guuid=d43cbf9f-2000-0000-16b9-01d5df140000 pid=5343 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=d43cbf9f-2000-0000-16b9-01d5df140000 pid=5343 execve guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344 execve guuid=2475c5a1-2000-0000-16b9-01d5e4140000 pid=5348 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=2475c5a1-2000-0000-16b9-01d5e4140000 pid=5348 execve guuid=20163573-2100-0000-16b9-01d5e5140000 pid=5349 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=20163573-2100-0000-16b9-01d5e5140000 pid=5349 execve guuid=e62bc3d5-2100-0000-16b9-01d5e6140000 pid=5350 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=e62bc3d5-2100-0000-16b9-01d5e6140000 pid=5350 clone guuid=732eeed5-2100-0000-16b9-01d5e7140000 pid=5351 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=732eeed5-2100-0000-16b9-01d5e7140000 pid=5351 execve guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352 execve guuid=7c4ebfd7-2100-0000-16b9-01d5ec140000 pid=5356 /usr/bin/wget net send-data guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=7c4ebfd7-2100-0000-16b9-01d5ec140000 pid=5356 execve guuid=6ade0908-2200-0000-16b9-01d5ed140000 pid=5357 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=6ade0908-2200-0000-16b9-01d5ed140000 pid=5357 execve guuid=c9780738-2200-0000-16b9-01d5ee140000 pid=5358 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=c9780738-2200-0000-16b9-01d5ee140000 pid=5358 clone guuid=f01d3638-2200-0000-16b9-01d5ef140000 pid=5359 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=f01d3638-2200-0000-16b9-01d5ef140000 pid=5359 execve guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360 execve guuid=b1e2393a-2200-0000-16b9-01d5f4140000 pid=5364 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b1e2393a-2200-0000-16b9-01d5f4140000 pid=5364 execve guuid=b7a360ae-2200-0000-16b9-01d5f5140000 pid=5365 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b7a360ae-2200-0000-16b9-01d5f5140000 pid=5365 execve guuid=2b2b0928-2300-0000-16b9-01d5f6140000 pid=5366 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=2b2b0928-2300-0000-16b9-01d5f6140000 pid=5366 clone guuid=bea04328-2300-0000-16b9-01d5f7140000 pid=5367 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=bea04328-2300-0000-16b9-01d5f7140000 pid=5367 execve guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368 execve guuid=73f22f2a-2300-0000-16b9-01d5fc140000 pid=5372 /usr/bin/wget net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=73f22f2a-2300-0000-16b9-01d5fc140000 pid=5372 execve guuid=b4c92ba1-2300-0000-16b9-01d5fd140000 pid=5373 /usr/bin/curl net send-data write-file guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b4c92ba1-2300-0000-16b9-01d5fd140000 pid=5373 execve guuid=7336c3b0-2400-0000-16b9-01d5fe140000 pid=5374 /usr/bin/bash guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=7336c3b0-2400-0000-16b9-01d5fe140000 pid=5374 clone guuid=5364f3b0-2400-0000-16b9-01d5ff140000 pid=5375 /usr/bin/chmod guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=5364f3b0-2400-0000-16b9-01d5ff140000 pid=5375 execve guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376 /tmp/WTF net guuid=fd890c2a-1800-0000-16b9-01d5d90c0000 pid=3289->guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376 execve a24300b2-8dd9-5540-9888-69e144f4a35e 45.79.126.103:80 guuid=13f97b2a-1800-0000-16b9-01d5db0c0000 pid=3291->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=30d4088a-1800-0000-16b9-01d56e0d0000 pid=3438->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5da273f0-1800-0000-16b9-01d50d0e0000 pid=3597 /tmp/WTF guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596->guuid=5da273f0-1800-0000-16b9-01d50d0e0000 pid=3597 clone guuid=40fa79f0-1800-0000-16b9-01d50e0e0000 pid=3598 /tmp/WTF guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596->guuid=40fa79f0-1800-0000-16b9-01d50e0e0000 pid=3598 clone guuid=720181f0-1800-0000-16b9-01d50f0e0000 pid=3599 /tmp/WTF net zombie guuid=dbd3ccef-1800-0000-16b9-01d50c0e0000 pid=3596->guuid=720181f0-1800-0000-16b9-01d50f0e0000 pid=3599 clone cfb37fde-b45a-5bb4-bc73-6c2959dc401e 45.79.126.103:3778 guuid=720181f0-1800-0000-16b9-01d50f0e0000 pid=3599->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=d11d93f0-1800-0000-16b9-01d5100e0000 pid=3600->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=70dc9a51-1900-0000-16b9-01d5ac0e0000 pid=3756->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=91168eb7-1900-0000-16b9-01d59d0f0000 pid=3997 /tmp/WTF guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995->guuid=91168eb7-1900-0000-16b9-01d59d0f0000 pid=3997 clone guuid=8861a2b7-1900-0000-16b9-01d59e0f0000 pid=3998 /tmp/WTF guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995->guuid=8861a2b7-1900-0000-16b9-01d59e0f0000 pid=3998 clone guuid=2038aeb7-1900-0000-16b9-01d59f0f0000 pid=3999 /tmp/WTF net zombie guuid=49caaeb6-1900-0000-16b9-01d59b0f0000 pid=3995->guuid=2038aeb7-1900-0000-16b9-01d59f0f0000 pid=3999 clone guuid=2038aeb7-1900-0000-16b9-01d59f0f0000 pid=3999->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=8d0bd4b7-1900-0000-16b9-01d5a10f0000 pid=4001->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=cca3dff4-1900-0000-16b9-01d53e100000 pid=4158->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a029972a-1a00-0000-16b9-01d5ee100000 pid=4334 /tmp/WTF guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331->guuid=a029972a-1a00-0000-16b9-01d5ee100000 pid=4334 clone guuid=19e79f2a-1a00-0000-16b9-01d5ef100000 pid=4335 /tmp/WTF guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331->guuid=19e79f2a-1a00-0000-16b9-01d5ef100000 pid=4335 clone guuid=4a0da72a-1a00-0000-16b9-01d5f1100000 pid=4337 /tmp/WTF net zombie guuid=d4056529-1a00-0000-16b9-01d5eb100000 pid=4331->guuid=4a0da72a-1a00-0000-16b9-01d5f1100000 pid=4337 clone guuid=4a0da72a-1a00-0000-16b9-01d5f1100000 pid=4337->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=353fb72a-1a00-0000-16b9-01d5f2100000 pid=4338->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=16bc9f6f-1a00-0000-16b9-01d5ae110000 pid=4526->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=baa3c9a1-1a00-0000-16b9-01d530120000 pid=4656 /tmp/WTF guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653->guuid=baa3c9a1-1a00-0000-16b9-01d530120000 pid=4656 clone guuid=a5cfcca1-1a00-0000-16b9-01d531120000 pid=4657 /tmp/WTF guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653->guuid=a5cfcca1-1a00-0000-16b9-01d531120000 pid=4657 clone guuid=dd23d4a1-1a00-0000-16b9-01d532120000 pid=4658 /tmp/WTF net zombie guuid=bf6031a1-1a00-0000-16b9-01d52d120000 pid=4653->guuid=dd23d4a1-1a00-0000-16b9-01d532120000 pid=4658 clone guuid=dd23d4a1-1a00-0000-16b9-01d532120000 pid=4658->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=b16604a2-1a00-0000-16b9-01d533120000 pid=4659->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=90d232e6-1a00-0000-16b9-01d51e130000 pid=4894->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e1955c60-1b00-0000-16b9-01d57f140000 pid=5247 /tmp/WTF guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246->guuid=e1955c60-1b00-0000-16b9-01d57f140000 pid=5247 clone guuid=feb46160-1b00-0000-16b9-01d580140000 pid=5248 /tmp/WTF guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246->guuid=feb46160-1b00-0000-16b9-01d580140000 pid=5248 clone guuid=fcdf6560-1b00-0000-16b9-01d581140000 pid=5249 /tmp/WTF net zombie guuid=e31da75f-1b00-0000-16b9-01d57e140000 pid=5246->guuid=fcdf6560-1b00-0000-16b9-01d581140000 pid=5249 clone guuid=fcdf6560-1b00-0000-16b9-01d581140000 pid=5249->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=460e7a60-1b00-0000-16b9-01d582140000 pid=5250->a24300b2-8dd9-5540-9888-69e144f4a35e send: 152B guuid=caed91a3-1b00-0000-16b9-01d58e140000 pid=5262->a24300b2-8dd9-5540-9888-69e144f4a35e send: 101B guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a46ba0db-1b00-0000-16b9-01d592140000 pid=5266 /tmp/WTF guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265->guuid=a46ba0db-1b00-0000-16b9-01d592140000 pid=5266 clone guuid=e092a5db-1b00-0000-16b9-01d593140000 pid=5267 /tmp/WTF guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265->guuid=e092a5db-1b00-0000-16b9-01d593140000 pid=5267 clone guuid=dc56a9db-1b00-0000-16b9-01d594140000 pid=5268 /tmp/WTF net zombie guuid=0743bada-1b00-0000-16b9-01d591140000 pid=5265->guuid=dc56a9db-1b00-0000-16b9-01d594140000 pid=5268 clone guuid=dc56a9db-1b00-0000-16b9-01d594140000 pid=5268->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=638501dc-1b00-0000-16b9-01d595140000 pid=5269->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=a6f11877-1c00-0000-16b9-01d59d140000 pid=5277->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=74854cdb-1c00-0000-16b9-01d5a1140000 pid=5281 /tmp/WTF guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280->guuid=74854cdb-1c00-0000-16b9-01d5a1140000 pid=5281 clone guuid=0f6552db-1c00-0000-16b9-01d5a2140000 pid=5282 /tmp/WTF guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280->guuid=0f6552db-1c00-0000-16b9-01d5a2140000 pid=5282 clone guuid=0fa557db-1c00-0000-16b9-01d5a3140000 pid=5283 /tmp/WTF net zombie guuid=92d927da-1c00-0000-16b9-01d5a0140000 pid=5280->guuid=0fa557db-1c00-0000-16b9-01d5a3140000 pid=5283 clone guuid=0fa557db-1c00-0000-16b9-01d5a3140000 pid=5283->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=93df65db-1c00-0000-16b9-01d5a4140000 pid=5284->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=2d5338b7-1d00-0000-16b9-01d5c5140000 pid=5317->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b62bea1a-1e00-0000-16b9-01d5c9140000 pid=5321 /tmp/WTF guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320->guuid=b62bea1a-1e00-0000-16b9-01d5c9140000 pid=5321 clone guuid=0e91f41a-1e00-0000-16b9-01d5ca140000 pid=5322 /tmp/WTF guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320->guuid=0e91f41a-1e00-0000-16b9-01d5ca140000 pid=5322 clone guuid=3c0f041b-1e00-0000-16b9-01d5cb140000 pid=5323 /tmp/WTF net zombie guuid=e1fcb719-1e00-0000-16b9-01d5c8140000 pid=5320->guuid=3c0f041b-1e00-0000-16b9-01d5cb140000 pid=5323 clone guuid=3c0f041b-1e00-0000-16b9-01d5cb140000 pid=5323->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=b8451c1b-1e00-0000-16b9-01d5cc140000 pid=5324->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=ba892a76-1e00-0000-16b9-01d5cd140000 pid=5325->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ac497edb-1e00-0000-16b9-01d5d1140000 pid=5329 /tmp/WTF guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328->guuid=ac497edb-1e00-0000-16b9-01d5d1140000 pid=5329 clone guuid=bb168cdb-1e00-0000-16b9-01d5d2140000 pid=5330 /tmp/WTF guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328->guuid=bb168cdb-1e00-0000-16b9-01d5d2140000 pid=5330 clone guuid=d7af95db-1e00-0000-16b9-01d5d3140000 pid=5331 /tmp/WTF net zombie guuid=886752da-1e00-0000-16b9-01d5d0140000 pid=5328->guuid=d7af95db-1e00-0000-16b9-01d5d3140000 pid=5331 clone guuid=d7af95db-1e00-0000-16b9-01d5d3140000 pid=5331->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=8eeaabdb-1e00-0000-16b9-01d5d4140000 pid=5332->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=1f89e76b-1f00-0000-16b9-01d5d5140000 pid=5333->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=515d92e5-1f00-0000-16b9-01d5d9140000 pid=5337 /tmp/WTF guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336->guuid=515d92e5-1f00-0000-16b9-01d5d9140000 pid=5337 clone guuid=a9eb96e5-1f00-0000-16b9-01d5da140000 pid=5338 /tmp/WTF guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336->guuid=a9eb96e5-1f00-0000-16b9-01d5da140000 pid=5338 clone guuid=2f5e9de5-1f00-0000-16b9-01d5db140000 pid=5339 /tmp/WTF net zombie guuid=e95803e5-1f00-0000-16b9-01d5d8140000 pid=5336->guuid=2f5e9de5-1f00-0000-16b9-01d5db140000 pid=5339 clone guuid=2f5e9de5-1f00-0000-16b9-01d5db140000 pid=5339->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=d051b1e5-1f00-0000-16b9-01d5dc140000 pid=5340->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=74a1f740-2000-0000-16b9-01d5dd140000 pid=5341->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0e5096a1-2000-0000-16b9-01d5e1140000 pid=5345 /tmp/WTF guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344->guuid=0e5096a1-2000-0000-16b9-01d5e1140000 pid=5345 clone guuid=043ea1a1-2000-0000-16b9-01d5e2140000 pid=5346 /tmp/WTF guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344->guuid=043ea1a1-2000-0000-16b9-01d5e2140000 pid=5346 clone guuid=50b2a9a1-2000-0000-16b9-01d5e3140000 pid=5347 /tmp/WTF net zombie guuid=307458a0-2000-0000-16b9-01d5e0140000 pid=5344->guuid=50b2a9a1-2000-0000-16b9-01d5e3140000 pid=5347 clone guuid=50b2a9a1-2000-0000-16b9-01d5e3140000 pid=5347->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=2475c5a1-2000-0000-16b9-01d5e4140000 pid=5348->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=20163573-2100-0000-16b9-01d5e5140000 pid=5349->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a9ad97d7-2100-0000-16b9-01d5e9140000 pid=5353 /tmp/WTF guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352->guuid=a9ad97d7-2100-0000-16b9-01d5e9140000 pid=5353 clone guuid=907ba0d7-2100-0000-16b9-01d5ea140000 pid=5354 /tmp/WTF guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352->guuid=907ba0d7-2100-0000-16b9-01d5ea140000 pid=5354 clone guuid=03fdacd7-2100-0000-16b9-01d5eb140000 pid=5355 /tmp/WTF net zombie guuid=8a7742d6-2100-0000-16b9-01d5e8140000 pid=5352->guuid=03fdacd7-2100-0000-16b9-01d5eb140000 pid=5355 clone guuid=03fdacd7-2100-0000-16b9-01d5eb140000 pid=5355->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=7c4ebfd7-2100-0000-16b9-01d5ec140000 pid=5356->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=6ade0908-2200-0000-16b9-01d5ed140000 pid=5357->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f735053a-2200-0000-16b9-01d5f1140000 pid=5361 /tmp/WTF guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360->guuid=f735053a-2200-0000-16b9-01d5f1140000 pid=5361 clone guuid=a19c0e3a-2200-0000-16b9-01d5f2140000 pid=5362 /tmp/WTF guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360->guuid=a19c0e3a-2200-0000-16b9-01d5f2140000 pid=5362 clone guuid=73111a3a-2200-0000-16b9-01d5f3140000 pid=5363 /tmp/WTF net zombie guuid=5b5eca38-2200-0000-16b9-01d5f0140000 pid=5360->guuid=73111a3a-2200-0000-16b9-01d5f3140000 pid=5363 clone guuid=73111a3a-2200-0000-16b9-01d5f3140000 pid=5363->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=b1e2393a-2200-0000-16b9-01d5f4140000 pid=5364->a24300b2-8dd9-5540-9888-69e144f4a35e send: 150B guuid=b7a360ae-2200-0000-16b9-01d5f5140000 pid=5365->a24300b2-8dd9-5540-9888-69e144f4a35e send: 99B guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d633082a-2300-0000-16b9-01d5f9140000 pid=5369 /tmp/WTF guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368->guuid=d633082a-2300-0000-16b9-01d5f9140000 pid=5369 clone guuid=35c1112a-2300-0000-16b9-01d5fa140000 pid=5370 /tmp/WTF guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368->guuid=35c1112a-2300-0000-16b9-01d5fa140000 pid=5370 clone guuid=e3d6182a-2300-0000-16b9-01d5fb140000 pid=5371 /tmp/WTF net zombie guuid=4c7dd528-2300-0000-16b9-01d5f8140000 pid=5368->guuid=e3d6182a-2300-0000-16b9-01d5fb140000 pid=5371 clone guuid=e3d6182a-2300-0000-16b9-01d5fb140000 pid=5371->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con guuid=73f22f2a-2300-0000-16b9-01d5fc140000 pid=5372->a24300b2-8dd9-5540-9888-69e144f4a35e send: 149B guuid=b4c92ba1-2300-0000-16b9-01d5fd140000 pid=5373->a24300b2-8dd9-5540-9888-69e144f4a35e send: 98B guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e2e271b2-2400-0000-16b9-01d501150000 pid=5377 /tmp/WTF guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376->guuid=e2e271b2-2400-0000-16b9-01d501150000 pid=5377 clone guuid=703779b2-2400-0000-16b9-01d502150000 pid=5378 /tmp/WTF guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376->guuid=703779b2-2400-0000-16b9-01d502150000 pid=5378 clone guuid=373982b2-2400-0000-16b9-01d503150000 pid=5379 /tmp/WTF net zombie guuid=b91a49b1-2400-0000-16b9-01d500150000 pid=5376->guuid=373982b2-2400-0000-16b9-01d503150000 pid=5379 clone guuid=373982b2-2400-0000-16b9-01d503150000 pid=5379->cfb37fde-b45a-5bb4-bc73-6c2959dc401e con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-06 18:38:26 UTC
File Type:
Text (Shell)
AV detection:
24 of 37 (64.86%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d58011db0b5bb21a50387d8f0d7e6a4da6fa0c9a896fb28709b23f4f47631007

(this sample)

  
Delivery method
Distributed via web download

Comments