MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 dc35aa4c01c11cef05eb3ba05e52fac7de17350edcbfbe10e272f9d98d3ed3bc. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: dc35aa4c01c11cef05eb3ba05e52fac7de17350edcbfbe10e272f9d98d3ed3bc
SHA3-384 hash: 7d718e71e8b1e82b8fa4758fc583f0b9499239babed98f118963bb48be3149fa166366ae3676a868a9130a576d0a6244
SHA1 hash: f3dc639cb1aa0bc5ce1a90aef8b67bd4396a384f
MD5 hash: 20667aac4970dd04963e52d9f3e760f0
humanhash: eighteen-fillet-enemy-juliet
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:3'037 bytes
First seen:2025-09-16 06:52:12 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ic757N7hcm6GcguzPcWKWcooUc7o7o7Ucfn3bcJ9RckcgctpVcuSOcy+Cc3fTcfG:ic757N7hcm6GcguzPcWKWcooUc7o7o7w
TLSH T12251E58562044E7418A76E17F67651A83082A093ECFDEFDAD9E8FBE81B4ED10B940753
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://195.248.240.141/hiddenbin/boatnet.x86f01c4c644e3e1f5eda07b757f02a6ae773584a52fea94acd7c42f2ffb21cd855 Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.mips499643893e03001bfc362cb959d7adf18cb7bdbb49452284fb4fef2217700e78 Mirai32-bit elf mirai Mozi
http://195.248.240.141/hiddenbin/boatnet.arcf126f5c9e00d2410ea652a7ed9792744b4018d415156857e57594dab242732dd Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://195.248.240.141/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://195.248.240.141/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://195.248.240.141/hiddenbin/boatnet.mpsl176f4f628e68d4a8654f2accdc20767c7002e3586097fddc3115927bc8c30cbc Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.arm531abc5d50abad8da7ed5a8aa03c5a0ff93e0abc1a6902b0ad0749ae0b07922b Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.arm5fc1d102f8b271fcfdc812325e7a7a4f23dd2c10b78c3b799c4692f0f04414ade Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.arm6b71da3283b93f4514831f964bbfc6aff6919695ae64b89a5e568632be79bfd81 Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.arm7bb65e5a41a7a37642d24405127fd7539017ea2d4a0df36c0a6258d429b648713 Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.ppcd11155289af909cf6ced3d2374f1f92f6cf8365605b2fb793470b5f5859ccdd0 Miraielf geofenced mirai opendir ua-wget USA
http://195.248.240.141/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://195.248.240.141/hiddenbin/boatnet.m68kfac662e8ece923483c7baa3dba098467e1823e60ac63ab946e98f275c7bb62dd Mirai32-bit elf mirai Mozi
http://195.248.240.141/hiddenbin/boatnet.sh48aa1abbc2e72a49bb19df3904d081a6d05b2197ae904deb517880d9a9ac8a1ef Miraielf geofenced mirai opendir ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-16T04:48:00Z UTC
Last seen:
2025-09-16T04:48:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=0c80da79-1900-0000-496a-e7cd66140000 pid=5222 /usr/bin/sudo guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223 /tmp/sample.bin guuid=0c80da79-1900-0000-496a-e7cd66140000 pid=5222->guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223 execve guuid=949fe97b-1900-0000-496a-e7cd68140000 pid=5224 /usr/bin/cp guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=949fe97b-1900-0000-496a-e7cd68140000 pid=5224 execve guuid=90032d82-1900-0000-496a-e7cd69140000 pid=5225 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=90032d82-1900-0000-496a-e7cd69140000 pid=5225 execve guuid=5e049389-1900-0000-496a-e7cd6a140000 pid=5226 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=5e049389-1900-0000-496a-e7cd6a140000 pid=5226 execve guuid=795b3697-1900-0000-496a-e7cd6b140000 pid=5227 /usr/bin/cat guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=795b3697-1900-0000-496a-e7cd6b140000 pid=5227 execve guuid=cfae8c97-1900-0000-496a-e7cd6c140000 pid=5228 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=cfae8c97-1900-0000-496a-e7cd6c140000 pid=5228 execve guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229 execve guuid=3555b198-1900-0000-496a-e7cd71140000 pid=5233 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=3555b198-1900-0000-496a-e7cd71140000 pid=5233 execve guuid=94c03aa0-1900-0000-496a-e7cd72140000 pid=5234 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=94c03aa0-1900-0000-496a-e7cd72140000 pid=5234 execve guuid=4304f2a8-1900-0000-496a-e7cd73140000 pid=5235 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=4304f2a8-1900-0000-496a-e7cd73140000 pid=5235 clone guuid=056825a9-1900-0000-496a-e7cd74140000 pid=5236 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=056825a9-1900-0000-496a-e7cd74140000 pid=5236 execve guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237 execve guuid=28665daa-1900-0000-496a-e7cd79140000 pid=5241 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=28665daa-1900-0000-496a-e7cd79140000 pid=5241 execve guuid=6f906ab3-1900-0000-496a-e7cd7a140000 pid=5242 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=6f906ab3-1900-0000-496a-e7cd7a140000 pid=5242 execve guuid=19ef57bc-1900-0000-496a-e7cd7b140000 pid=5243 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=19ef57bc-1900-0000-496a-e7cd7b140000 pid=5243 clone guuid=31b47abc-1900-0000-496a-e7cd7c140000 pid=5244 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=31b47abc-1900-0000-496a-e7cd7c140000 pid=5244 execve guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245 execve guuid=b0efa9bd-1900-0000-496a-e7cd81140000 pid=5249 /usr/bin/wget net send-data guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=b0efa9bd-1900-0000-496a-e7cd81140000 pid=5249 execve guuid=ed735ac2-1900-0000-496a-e7cd82140000 pid=5250 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=ed735ac2-1900-0000-496a-e7cd82140000 pid=5250 execve guuid=1ac27fcb-1900-0000-496a-e7cd83140000 pid=5251 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=1ac27fcb-1900-0000-496a-e7cd83140000 pid=5251 clone guuid=419ab3cb-1900-0000-496a-e7cd84140000 pid=5252 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=419ab3cb-1900-0000-496a-e7cd84140000 pid=5252 execve guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253 execve guuid=6cac39ce-1900-0000-496a-e7cd89140000 pid=5257 /usr/bin/wget net send-data guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=6cac39ce-1900-0000-496a-e7cd89140000 pid=5257 execve guuid=6b768bd1-1900-0000-496a-e7cd8a140000 pid=5258 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=6b768bd1-1900-0000-496a-e7cd8a140000 pid=5258 execve guuid=6b55ffd7-1900-0000-496a-e7cd8b140000 pid=5259 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=6b55ffd7-1900-0000-496a-e7cd8b140000 pid=5259 clone guuid=69c33cd8-1900-0000-496a-e7cd8c140000 pid=5260 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=69c33cd8-1900-0000-496a-e7cd8c140000 pid=5260 execve guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261 execve guuid=10c6e4da-1900-0000-496a-e7cd91140000 pid=5265 /usr/bin/wget net send-data guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=10c6e4da-1900-0000-496a-e7cd91140000 pid=5265 execve guuid=87a150de-1900-0000-496a-e7cd92140000 pid=5266 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=87a150de-1900-0000-496a-e7cd92140000 pid=5266 execve guuid=01dcd5e2-1900-0000-496a-e7cd93140000 pid=5267 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=01dcd5e2-1900-0000-496a-e7cd93140000 pid=5267 clone guuid=907cf6e2-1900-0000-496a-e7cd94140000 pid=5268 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=907cf6e2-1900-0000-496a-e7cd94140000 pid=5268 execve guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269 execve guuid=e4141de4-1900-0000-496a-e7cd99140000 pid=5273 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=e4141de4-1900-0000-496a-e7cd99140000 pid=5273 execve guuid=bd247fea-1900-0000-496a-e7cd9d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=bd247fea-1900-0000-496a-e7cd9d140000 pid=5277 execve guuid=922b12f4-1900-0000-496a-e7cda2140000 pid=5282 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=922b12f4-1900-0000-496a-e7cda2140000 pid=5282 clone guuid=f29c34f4-1900-0000-496a-e7cda3140000 pid=5283 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=f29c34f4-1900-0000-496a-e7cda3140000 pid=5283 execve guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284 execve guuid=d6dab1f6-1900-0000-496a-e7cda8140000 pid=5288 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=d6dab1f6-1900-0000-496a-e7cda8140000 pid=5288 execve guuid=c7f57ffd-1900-0000-496a-e7cda9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=c7f57ffd-1900-0000-496a-e7cda9140000 pid=5289 execve guuid=da57d406-1a00-0000-496a-e7cdaa140000 pid=5290 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=da57d406-1a00-0000-496a-e7cdaa140000 pid=5290 clone guuid=344e0307-1a00-0000-496a-e7cdab140000 pid=5291 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=344e0307-1a00-0000-496a-e7cdab140000 pid=5291 execve guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292 execve guuid=f4886e08-1a00-0000-496a-e7cdb0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=f4886e08-1a00-0000-496a-e7cdb0140000 pid=5296 execve guuid=3f1e580f-1a00-0000-496a-e7cdb1140000 pid=5297 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=3f1e580f-1a00-0000-496a-e7cdb1140000 pid=5297 execve guuid=39a1171c-1a00-0000-496a-e7cdb2140000 pid=5298 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=39a1171c-1a00-0000-496a-e7cdb2140000 pid=5298 clone guuid=62ca391c-1a00-0000-496a-e7cdb3140000 pid=5299 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=62ca391c-1a00-0000-496a-e7cdb3140000 pid=5299 execve guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300 execve guuid=3d46a51d-1a00-0000-496a-e7cdb8140000 pid=5304 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=3d46a51d-1a00-0000-496a-e7cdb8140000 pid=5304 execve guuid=d3023226-1a00-0000-496a-e7cdb9140000 pid=5305 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=d3023226-1a00-0000-496a-e7cdb9140000 pid=5305 execve guuid=9f3d772e-1a00-0000-496a-e7cdba140000 pid=5306 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=9f3d772e-1a00-0000-496a-e7cdba140000 pid=5306 clone guuid=a0c0262f-1a00-0000-496a-e7cdbb140000 pid=5307 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=a0c0262f-1a00-0000-496a-e7cdbb140000 pid=5307 execve guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308 execve guuid=c1042231-1a00-0000-496a-e7cdc0140000 pid=5312 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=c1042231-1a00-0000-496a-e7cdc0140000 pid=5312 execve guuid=cfe2a54c-1a00-0000-496a-e7cdc1140000 pid=5313 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=cfe2a54c-1a00-0000-496a-e7cdc1140000 pid=5313 execve guuid=ffb9995d-1a00-0000-496a-e7cdc2140000 pid=5314 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=ffb9995d-1a00-0000-496a-e7cdc2140000 pid=5314 clone guuid=3eb4ca5d-1a00-0000-496a-e7cdc3140000 pid=5315 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=3eb4ca5d-1a00-0000-496a-e7cdc3140000 pid=5315 execve guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316 execve guuid=4d2da563-1a00-0000-496a-e7cdc8140000 pid=5320 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=4d2da563-1a00-0000-496a-e7cdc8140000 pid=5320 execve guuid=fd60636b-1a00-0000-496a-e7cdc9140000 pid=5321 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=fd60636b-1a00-0000-496a-e7cdc9140000 pid=5321 execve guuid=27a0c976-1a00-0000-496a-e7cdca140000 pid=5322 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=27a0c976-1a00-0000-496a-e7cdca140000 pid=5322 clone guuid=13c52b77-1a00-0000-496a-e7cdcb140000 pid=5323 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=13c52b77-1a00-0000-496a-e7cdcb140000 pid=5323 execve guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324 execve guuid=6e0d9379-1a00-0000-496a-e7cdd0140000 pid=5328 /usr/bin/wget net send-data guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=6e0d9379-1a00-0000-496a-e7cdd0140000 pid=5328 execve guuid=052d927d-1a00-0000-496a-e7cdd1140000 pid=5329 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=052d927d-1a00-0000-496a-e7cdd1140000 pid=5329 execve guuid=bb09b182-1a00-0000-496a-e7cdd2140000 pid=5330 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=bb09b182-1a00-0000-496a-e7cdd2140000 pid=5330 clone guuid=15b91783-1a00-0000-496a-e7cdd3140000 pid=5331 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=15b91783-1a00-0000-496a-e7cdd3140000 pid=5331 execve guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332 execve guuid=ec5d3886-1a00-0000-496a-e7cdd8140000 pid=5336 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=ec5d3886-1a00-0000-496a-e7cdd8140000 pid=5336 execve guuid=80b1a58f-1a00-0000-496a-e7cdd9140000 pid=5337 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=80b1a58f-1a00-0000-496a-e7cdd9140000 pid=5337 execve guuid=b37d8399-1a00-0000-496a-e7cdda140000 pid=5338 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=b37d8399-1a00-0000-496a-e7cdda140000 pid=5338 clone guuid=9b179e99-1a00-0000-496a-e7cddb140000 pid=5339 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=9b179e99-1a00-0000-496a-e7cddb140000 pid=5339 execve guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340 execve guuid=d0bfbf9a-1a00-0000-496a-e7cde0140000 pid=5344 /usr/bin/wget net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=d0bfbf9a-1a00-0000-496a-e7cde0140000 pid=5344 execve guuid=81f507a3-1a00-0000-496a-e7cde1140000 pid=5345 /usr/bin/curl net send-data write-file guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=81f507a3-1a00-0000-496a-e7cde1140000 pid=5345 execve guuid=f56d77ae-1a00-0000-496a-e7cde2140000 pid=5346 /usr/bin/bash guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=f56d77ae-1a00-0000-496a-e7cde2140000 pid=5346 clone guuid=bf6093ae-1a00-0000-496a-e7cde3140000 pid=5347 /usr/bin/chmod guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=bf6093ae-1a00-0000-496a-e7cde3140000 pid=5347 execve guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348 /tmp/WTF net guuid=684d997b-1900-0000-496a-e7cd67140000 pid=5223->guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348 execve 474ce109-b259-5332-893b-60440a3f2c99 195.248.240.141:80 guuid=90032d82-1900-0000-496a-e7cd69140000 pid=5225->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=5e049389-1900-0000-496a-e7cd6a140000 pid=5226->474ce109-b259-5332-893b-60440a3f2c99 send: 100B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=859a9b98-1900-0000-496a-e7cd6e140000 pid=5230 /tmp/WTF zombie guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229->guuid=859a9b98-1900-0000-496a-e7cd6e140000 pid=5230 clone guuid=fc73a198-1900-0000-496a-e7cd6f140000 pid=5231 /tmp/WTF guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229->guuid=fc73a198-1900-0000-496a-e7cd6f140000 pid=5231 clone guuid=9421a598-1900-0000-496a-e7cd70140000 pid=5232 /tmp/WTF net send-data zombie guuid=0a18d497-1900-0000-496a-e7cd6d140000 pid=5229->guuid=9421a598-1900-0000-496a-e7cd70140000 pid=5232 clone guuid=9421a598-1900-0000-496a-e7cd70140000 pid=5232->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b24e3793-0d82-5dd0-85ae-a89182159724 195.248.240.141:3778 guuid=9421a598-1900-0000-496a-e7cd70140000 pid=5232->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=3555b198-1900-0000-496a-e7cd71140000 pid=5233->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=94c03aa0-1900-0000-496a-e7cd72140000 pid=5234->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=40723baa-1900-0000-496a-e7cd76140000 pid=5238 /tmp/WTF zombie guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237->guuid=40723baa-1900-0000-496a-e7cd76140000 pid=5238 clone guuid=bced3eaa-1900-0000-496a-e7cd77140000 pid=5239 /tmp/WTF guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237->guuid=bced3eaa-1900-0000-496a-e7cd77140000 pid=5239 clone guuid=d17142aa-1900-0000-496a-e7cd78140000 pid=5240 /tmp/WTF net send-data zombie guuid=151578a9-1900-0000-496a-e7cd75140000 pid=5237->guuid=d17142aa-1900-0000-496a-e7cd78140000 pid=5240 clone guuid=d17142aa-1900-0000-496a-e7cd78140000 pid=5240->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d17142aa-1900-0000-496a-e7cd78140000 pid=5240->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=28665daa-1900-0000-496a-e7cd79140000 pid=5241->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=6f906ab3-1900-0000-496a-e7cd7a140000 pid=5242->474ce109-b259-5332-893b-60440a3f2c99 send: 100B guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=148993bd-1900-0000-496a-e7cd7e140000 pid=5246 /tmp/WTF zombie guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245->guuid=148993bd-1900-0000-496a-e7cd7e140000 pid=5246 clone guuid=aad197bd-1900-0000-496a-e7cd7f140000 pid=5247 /tmp/WTF guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245->guuid=aad197bd-1900-0000-496a-e7cd7f140000 pid=5247 clone guuid=c0d39bbd-1900-0000-496a-e7cd80140000 pid=5248 /tmp/WTF net send-data zombie guuid=efeac9bc-1900-0000-496a-e7cd7d140000 pid=5245->guuid=c0d39bbd-1900-0000-496a-e7cd80140000 pid=5248 clone guuid=c0d39bbd-1900-0000-496a-e7cd80140000 pid=5248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c0d39bbd-1900-0000-496a-e7cd80140000 pid=5248->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=b0efa9bd-1900-0000-496a-e7cd81140000 pid=5249->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=ed735ac2-1900-0000-496a-e7cd82140000 pid=5250->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2c9f0ece-1900-0000-496a-e7cd86140000 pid=5254 /tmp/WTF zombie guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253->guuid=2c9f0ece-1900-0000-496a-e7cd86140000 pid=5254 clone guuid=d79d19ce-1900-0000-496a-e7cd87140000 pid=5255 /tmp/WTF guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253->guuid=d79d19ce-1900-0000-496a-e7cd87140000 pid=5255 clone guuid=591f26ce-1900-0000-496a-e7cd88140000 pid=5256 /tmp/WTF net send-data zombie guuid=f27d68cc-1900-0000-496a-e7cd85140000 pid=5253->guuid=591f26ce-1900-0000-496a-e7cd88140000 pid=5256 clone guuid=591f26ce-1900-0000-496a-e7cd88140000 pid=5256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=591f26ce-1900-0000-496a-e7cd88140000 pid=5256->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=6cac39ce-1900-0000-496a-e7cd89140000 pid=5257->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=6b768bd1-1900-0000-496a-e7cd8a140000 pid=5258->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1e48b9da-1900-0000-496a-e7cd8e140000 pid=5262 /tmp/WTF zombie guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261->guuid=1e48b9da-1900-0000-496a-e7cd8e140000 pid=5262 clone guuid=44cec6da-1900-0000-496a-e7cd8f140000 pid=5263 /tmp/WTF guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261->guuid=44cec6da-1900-0000-496a-e7cd8f140000 pid=5263 clone guuid=269eceda-1900-0000-496a-e7cd90140000 pid=5264 /tmp/WTF net send-data zombie guuid=ce67fad8-1900-0000-496a-e7cd8d140000 pid=5261->guuid=269eceda-1900-0000-496a-e7cd90140000 pid=5264 clone guuid=269eceda-1900-0000-496a-e7cd90140000 pid=5264->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=269eceda-1900-0000-496a-e7cd90140000 pid=5264->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=10c6e4da-1900-0000-496a-e7cd91140000 pid=5265->474ce109-b259-5332-893b-60440a3f2c99 send: 154B guuid=87a150de-1900-0000-496a-e7cd92140000 pid=5266->474ce109-b259-5332-893b-60440a3f2c99 send: 103B guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=42d403e4-1900-0000-496a-e7cd96140000 pid=5270 /tmp/WTF zombie guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269->guuid=42d403e4-1900-0000-496a-e7cd96140000 pid=5270 clone guuid=9fb208e4-1900-0000-496a-e7cd97140000 pid=5271 /tmp/WTF guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269->guuid=9fb208e4-1900-0000-496a-e7cd97140000 pid=5271 clone guuid=548610e4-1900-0000-496a-e7cd98140000 pid=5272 /tmp/WTF net send-data zombie guuid=bf3143e3-1900-0000-496a-e7cd95140000 pid=5269->guuid=548610e4-1900-0000-496a-e7cd98140000 pid=5272 clone guuid=548610e4-1900-0000-496a-e7cd98140000 pid=5272->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=548610e4-1900-0000-496a-e7cd98140000 pid=5272->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=e4141de4-1900-0000-496a-e7cd99140000 pid=5273->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=bd247fea-1900-0000-496a-e7cd9d140000 pid=5277->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f8948ef6-1900-0000-496a-e7cda5140000 pid=5285 /tmp/WTF zombie guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284->guuid=f8948ef6-1900-0000-496a-e7cda5140000 pid=5285 clone guuid=b45596f6-1900-0000-496a-e7cda6140000 pid=5286 /tmp/WTF guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284->guuid=b45596f6-1900-0000-496a-e7cda6140000 pid=5286 clone guuid=bbff9bf6-1900-0000-496a-e7cda7140000 pid=5287 /tmp/WTF net send-data zombie guuid=fa2602f5-1900-0000-496a-e7cda4140000 pid=5284->guuid=bbff9bf6-1900-0000-496a-e7cda7140000 pid=5287 clone guuid=bbff9bf6-1900-0000-496a-e7cda7140000 pid=5287->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bbff9bf6-1900-0000-496a-e7cda7140000 pid=5287->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=d6dab1f6-1900-0000-496a-e7cda8140000 pid=5288->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=c7f57ffd-1900-0000-496a-e7cda9140000 pid=5289->474ce109-b259-5332-893b-60440a3f2c99 send: 100B guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e1664c08-1a00-0000-496a-e7cdad140000 pid=5293 /tmp/WTF zombie guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292->guuid=e1664c08-1a00-0000-496a-e7cdad140000 pid=5293 clone guuid=dc8e4f08-1a00-0000-496a-e7cdae140000 pid=5294 /tmp/WTF guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292->guuid=dc8e4f08-1a00-0000-496a-e7cdae140000 pid=5294 clone guuid=09035b08-1a00-0000-496a-e7cdaf140000 pid=5295 /tmp/WTF net send-data zombie guuid=b5886507-1a00-0000-496a-e7cdac140000 pid=5292->guuid=09035b08-1a00-0000-496a-e7cdaf140000 pid=5295 clone guuid=09035b08-1a00-0000-496a-e7cdaf140000 pid=5295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=09035b08-1a00-0000-496a-e7cdaf140000 pid=5295->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=f4886e08-1a00-0000-496a-e7cdb0140000 pid=5296->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=3f1e580f-1a00-0000-496a-e7cdb1140000 pid=5297->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ed828c1d-1a00-0000-496a-e7cdb5140000 pid=5301 /tmp/WTF zombie guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300->guuid=ed828c1d-1a00-0000-496a-e7cdb5140000 pid=5301 clone guuid=080b911d-1a00-0000-496a-e7cdb6140000 pid=5302 /tmp/WTF guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300->guuid=080b911d-1a00-0000-496a-e7cdb6140000 pid=5302 clone guuid=109b961d-1a00-0000-496a-e7cdb7140000 pid=5303 /tmp/WTF net send-data zombie guuid=e450931c-1a00-0000-496a-e7cdb4140000 pid=5300->guuid=109b961d-1a00-0000-496a-e7cdb7140000 pid=5303 clone guuid=109b961d-1a00-0000-496a-e7cdb7140000 pid=5303->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=109b961d-1a00-0000-496a-e7cdb7140000 pid=5303->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=3d46a51d-1a00-0000-496a-e7cdb8140000 pid=5304->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=d3023226-1a00-0000-496a-e7cdb9140000 pid=5305->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ae590031-1a00-0000-496a-e7cdbd140000 pid=5309 /tmp/WTF zombie guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308->guuid=ae590031-1a00-0000-496a-e7cdbd140000 pid=5309 clone guuid=6b100731-1a00-0000-496a-e7cdbe140000 pid=5310 /tmp/WTF guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308->guuid=6b100731-1a00-0000-496a-e7cdbe140000 pid=5310 clone guuid=44320f31-1a00-0000-496a-e7cdbf140000 pid=5311 /tmp/WTF net send-data zombie guuid=4cfcba2f-1a00-0000-496a-e7cdbc140000 pid=5308->guuid=44320f31-1a00-0000-496a-e7cdbf140000 pid=5311 clone guuid=44320f31-1a00-0000-496a-e7cdbf140000 pid=5311->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=44320f31-1a00-0000-496a-e7cdbf140000 pid=5311->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=c1042231-1a00-0000-496a-e7cdc0140000 pid=5312->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=cfe2a54c-1a00-0000-496a-e7cdc1140000 pid=5313->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=19b48463-1a00-0000-496a-e7cdc5140000 pid=5317 /tmp/WTF zombie guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316->guuid=19b48463-1a00-0000-496a-e7cdc5140000 pid=5317 clone guuid=53658a63-1a00-0000-496a-e7cdc6140000 pid=5318 /tmp/WTF guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316->guuid=53658a63-1a00-0000-496a-e7cdc6140000 pid=5318 clone guuid=888f8e63-1a00-0000-496a-e7cdc7140000 pid=5319 /tmp/WTF net send-data zombie guuid=c0aa935f-1a00-0000-496a-e7cdc4140000 pid=5316->guuid=888f8e63-1a00-0000-496a-e7cdc7140000 pid=5319 clone guuid=888f8e63-1a00-0000-496a-e7cdc7140000 pid=5319->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=888f8e63-1a00-0000-496a-e7cdc7140000 pid=5319->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=4d2da563-1a00-0000-496a-e7cdc8140000 pid=5320->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=fd60636b-1a00-0000-496a-e7cdc9140000 pid=5321->474ce109-b259-5332-893b-60440a3f2c99 send: 100B guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=317d0379-1a00-0000-496a-e7cdcd140000 pid=5325 /tmp/WTF zombie guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324->guuid=317d0379-1a00-0000-496a-e7cdcd140000 pid=5325 clone guuid=2c1a0979-1a00-0000-496a-e7cdce140000 pid=5326 /tmp/WTF guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324->guuid=2c1a0979-1a00-0000-496a-e7cdce140000 pid=5326 clone guuid=595b0c79-1a00-0000-496a-e7cdcf140000 pid=5327 /tmp/WTF net send-data zombie guuid=a57ddf77-1a00-0000-496a-e7cdcc140000 pid=5324->guuid=595b0c79-1a00-0000-496a-e7cdcf140000 pid=5327 clone guuid=595b0c79-1a00-0000-496a-e7cdcf140000 pid=5327->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=595b0c79-1a00-0000-496a-e7cdcf140000 pid=5327->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=6e0d9379-1a00-0000-496a-e7cdd0140000 pid=5328->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=052d927d-1a00-0000-496a-e7cdd1140000 pid=5329->474ce109-b259-5332-893b-60440a3f2c99 send: 100B guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d1b6685-1a00-0000-496a-e7cdd5140000 pid=5333 /tmp/WTF zombie guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332->guuid=2d1b6685-1a00-0000-496a-e7cdd5140000 pid=5333 clone guuid=aedc6c85-1a00-0000-496a-e7cdd6140000 pid=5334 /tmp/WTF guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332->guuid=aedc6c85-1a00-0000-496a-e7cdd6140000 pid=5334 clone guuid=267ff785-1a00-0000-496a-e7cdd7140000 pid=5335 /tmp/WTF net send-data zombie guuid=5fa7d083-1a00-0000-496a-e7cdd4140000 pid=5332->guuid=267ff785-1a00-0000-496a-e7cdd7140000 pid=5335 clone guuid=267ff785-1a00-0000-496a-e7cdd7140000 pid=5335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=267ff785-1a00-0000-496a-e7cdd7140000 pid=5335->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=ec5d3886-1a00-0000-496a-e7cdd8140000 pid=5336->474ce109-b259-5332-893b-60440a3f2c99 send: 152B guuid=80b1a58f-1a00-0000-496a-e7cdd9140000 pid=5337->474ce109-b259-5332-893b-60440a3f2c99 send: 101B guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4314af9a-1a00-0000-496a-e7cddd140000 pid=5341 /tmp/WTF zombie guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340->guuid=4314af9a-1a00-0000-496a-e7cddd140000 pid=5341 clone guuid=dea1b39a-1a00-0000-496a-e7cdde140000 pid=5342 /tmp/WTF guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340->guuid=dea1b39a-1a00-0000-496a-e7cdde140000 pid=5342 clone guuid=7d14b79a-1a00-0000-496a-e7cddf140000 pid=5343 /tmp/WTF net send-data zombie guuid=cc85e199-1a00-0000-496a-e7cddc140000 pid=5340->guuid=7d14b79a-1a00-0000-496a-e7cddf140000 pid=5343 clone guuid=7d14b79a-1a00-0000-496a-e7cddf140000 pid=5343->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7d14b79a-1a00-0000-496a-e7cddf140000 pid=5343->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B guuid=d0bfbf9a-1a00-0000-496a-e7cde0140000 pid=5344->474ce109-b259-5332-893b-60440a3f2c99 send: 151B guuid=81f507a3-1a00-0000-496a-e7cde1140000 pid=5345->474ce109-b259-5332-893b-60440a3f2c99 send: 100B guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=409caaaf-1a00-0000-496a-e7cde5140000 pid=5349 /tmp/WTF zombie guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348->guuid=409caaaf-1a00-0000-496a-e7cde5140000 pid=5349 clone guuid=3aaeb1af-1a00-0000-496a-e7cde6140000 pid=5350 /tmp/WTF guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348->guuid=3aaeb1af-1a00-0000-496a-e7cde6140000 pid=5350 clone guuid=9066b6af-1a00-0000-496a-e7cde7140000 pid=5351 /tmp/WTF net send-data zombie guuid=5fd4d5ae-1a00-0000-496a-e7cde4140000 pid=5348->guuid=9066b6af-1a00-0000-496a-e7cde7140000 pid=5351 clone guuid=9066b6af-1a00-0000-496a-e7cde7140000 pid=5351->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9066b6af-1a00-0000-496a-e7cde7140000 pid=5351->b24e3793-0d82-5dd0-85ae-a89182159724 send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-16 06:52:36 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Malware Config
C2 Extraction:
103.191.63.195
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh dc35aa4c01c11cef05eb3ba05e52fac7de17350edcbfbe10e272f9d98d3ed3bc

(this sample)

  
Delivery method
Distributed via web download

Comments