MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e3140cc9dc1348c3d4d7f0e76211d5411083cf649c9ffd88dc2969e55d9f7b6f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 2 File information Comments

SHA256 hash: e3140cc9dc1348c3d4d7f0e76211d5411083cf649c9ffd88dc2969e55d9f7b6f
SHA3-384 hash: 8360ce67e1fc848fc57aff700a8370d1a4356ffe29bec3384100a00e73618e0c564fa8f55422a403b319fb4b39e1f1d4
SHA1 hash: 347091a445038130c6a623852fc0cfc5139d5824
MD5 hash: ba5b00bad9a8bc5a20ca00f9567715ec
humanhash: lamp-whiskey-foxtrot-pip
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2026-02-25 07:04:31 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vt7u7N7htX6GtgfzPtHKWtZoUt7Z7o7Utf83bt+9Rt1cgtSpVtfSOtD+CtMfTtUm:vt7u7N7htX6GtgfzPtHKWtZoUt7Z7o74
TLSH T1F7512AC541D40FB41C636B77EAB6416C33C6B6678CE1ABD5D9E4BBE0824EE5039407A3
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://83.142.209.9/hiddenbin/boatnet.x8633704c6f682a5399f3a763bbef351afae4f64759a4d9eab086e3530fc4e13023 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.mips0e5ce8920fc81721e195d6567473daeee40023ae542c0e641a099b39441f20cf Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.arc3762a6a3b989850716155a080bf907ddde31d00903cf192dbd01fe3584bc3b1f Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://83.142.209.9/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://83.142.209.9/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://83.142.209.9/hiddenbin/boatnet.mpslbe4e5905ac734250ef02d18c3cad7c537ae7f6c2b4a35a77da99c1e2eb74abb8 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.armc3bf3b0be0e8a68eef4365fcae96aeef658b18e32fe52c86701e13ae464ecd70 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.arm50260f7c239b5741341c84b2334222c98a8bfa688fb058472c2ac390b039ea100 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.arm603eba2113e1ce14bec510ab7c3cb9536886d9cc46ec02936538a610104ff09ba Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.arm7ab277a4ed7e102b7ab4c204127cc5c38ba69cd8799d6042518457b0225abfde0 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.ppc1ab5099ca53a7ac2fdfc5455f52f9b67036eb3d89a44ca98099a11cff86056fe Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.spc6a8e701c2bccea14460cdf7bc8d92acf5ff1187554094565407cf91ce226cab2 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.m68kaadd6c06fab540b50b2f84fe852b970fd625defa427597e8a4c0f33ca1320c35 Miraielf mirai ua-wget
http://83.142.209.9/hiddenbin/boatnet.sh4f2d106119cf094bab39955c564eaa924ff7e0888d9e225c69fd0123cda5f43e7 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
81
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=32176abc-1b00-0000-e47d-bab9ff0a0000 pid=2815 /usr/bin/sudo guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819 /tmp/sample.bin guuid=32176abc-1b00-0000-e47d-bab9ff0a0000 pid=2815->guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819 execve guuid=a463b3be-1b00-0000-e47d-bab9040b0000 pid=2820 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=a463b3be-1b00-0000-e47d-bab9040b0000 pid=2820 execve guuid=4d5234ca-1b00-0000-e47d-bab9130b0000 pid=2835 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=4d5234ca-1b00-0000-e47d-bab9130b0000 pid=2835 execve guuid=1a9b79da-1b00-0000-e47d-bab9240b0000 pid=2852 /usr/bin/cat guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=1a9b79da-1b00-0000-e47d-bab9240b0000 pid=2852 execve guuid=f2c640db-1b00-0000-e47d-bab9260b0000 pid=2854 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=f2c640db-1b00-0000-e47d-bab9260b0000 pid=2854 execve guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857 execve guuid=523471dc-1b00-0000-e47d-bab92e0b0000 pid=2862 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=523471dc-1b00-0000-e47d-bab92e0b0000 pid=2862 execve guuid=9b6c30e2-1b00-0000-e47d-bab9370b0000 pid=2871 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9b6c30e2-1b00-0000-e47d-bab9370b0000 pid=2871 execve guuid=0ac9aaf1-1b00-0000-e47d-bab9540b0000 pid=2900 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0ac9aaf1-1b00-0000-e47d-bab9540b0000 pid=2900 clone guuid=d6c9d8f1-1b00-0000-e47d-bab9550b0000 pid=2901 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=d6c9d8f1-1b00-0000-e47d-bab9550b0000 pid=2901 execve guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903 execve guuid=4cebd7f2-1b00-0000-e47d-bab95c0b0000 pid=2908 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=4cebd7f2-1b00-0000-e47d-bab95c0b0000 pid=2908 execve guuid=968dd6f9-1b00-0000-e47d-bab96c0b0000 pid=2924 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=968dd6f9-1b00-0000-e47d-bab96c0b0000 pid=2924 execve guuid=53452901-1c00-0000-e47d-bab97e0b0000 pid=2942 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=53452901-1c00-0000-e47d-bab97e0b0000 pid=2942 clone guuid=b4c24801-1c00-0000-e47d-bab97f0b0000 pid=2943 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=b4c24801-1c00-0000-e47d-bab97f0b0000 pid=2943 execve guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944 execve guuid=2970e001-1c00-0000-e47d-bab9840b0000 pid=2948 /usr/bin/wget net send-data guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=2970e001-1c00-0000-e47d-bab9840b0000 pid=2948 execve guuid=7237eb05-1c00-0000-e47d-bab98e0b0000 pid=2958 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=7237eb05-1c00-0000-e47d-bab98e0b0000 pid=2958 execve guuid=4774510a-1c00-0000-e47d-bab9970b0000 pid=2967 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=4774510a-1c00-0000-e47d-bab9970b0000 pid=2967 clone guuid=6f976c0a-1c00-0000-e47d-bab9980b0000 pid=2968 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=6f976c0a-1c00-0000-e47d-bab9980b0000 pid=2968 execve guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970 execve guuid=97d21b0b-1c00-0000-e47d-bab99e0b0000 pid=2974 /usr/bin/wget net send-data guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=97d21b0b-1c00-0000-e47d-bab99e0b0000 pid=2974 execve guuid=9284c10e-1c00-0000-e47d-bab9a60b0000 pid=2982 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9284c10e-1c00-0000-e47d-bab9a60b0000 pid=2982 execve guuid=d1521d13-1c00-0000-e47d-bab9af0b0000 pid=2991 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=d1521d13-1c00-0000-e47d-bab9af0b0000 pid=2991 clone guuid=8bc13913-1c00-0000-e47d-bab9b10b0000 pid=2993 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=8bc13913-1c00-0000-e47d-bab9b10b0000 pid=2993 execve guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995 execve guuid=0e14c113-1c00-0000-e47d-bab9b70b0000 pid=2999 /usr/bin/wget net send-data guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0e14c113-1c00-0000-e47d-bab9b70b0000 pid=2999 execve guuid=e6c71517-1c00-0000-e47d-bab9be0b0000 pid=3006 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=e6c71517-1c00-0000-e47d-bab9be0b0000 pid=3006 execve guuid=f436e01c-1c00-0000-e47d-bab9c90b0000 pid=3017 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=f436e01c-1c00-0000-e47d-bab9c90b0000 pid=3017 clone guuid=7b2aff1c-1c00-0000-e47d-bab9cb0b0000 pid=3019 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=7b2aff1c-1c00-0000-e47d-bab9cb0b0000 pid=3019 execve guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021 execve guuid=9a5cd51d-1c00-0000-e47d-bab9d20b0000 pid=3026 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9a5cd51d-1c00-0000-e47d-bab9d20b0000 pid=3026 execve guuid=ce55fc22-1c00-0000-e47d-bab9d80b0000 pid=3032 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=ce55fc22-1c00-0000-e47d-bab9d80b0000 pid=3032 execve guuid=93e4f72d-1c00-0000-e47d-bab9eb0b0000 pid=3051 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=93e4f72d-1c00-0000-e47d-bab9eb0b0000 pid=3051 clone guuid=83bd6c2e-1c00-0000-e47d-bab9ed0b0000 pid=3053 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=83bd6c2e-1c00-0000-e47d-bab9ed0b0000 pid=3053 execve guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054 execve guuid=4c719c2f-1c00-0000-e47d-bab9f30b0000 pid=3059 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=4c719c2f-1c00-0000-e47d-bab9f30b0000 pid=3059 execve guuid=20b75f34-1c00-0000-e47d-bab9fe0b0000 pid=3070 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=20b75f34-1c00-0000-e47d-bab9fe0b0000 pid=3070 execve guuid=0439f539-1c00-0000-e47d-bab90a0c0000 pid=3082 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0439f539-1c00-0000-e47d-bab90a0c0000 pid=3082 clone guuid=90951a3a-1c00-0000-e47d-bab90c0c0000 pid=3084 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=90951a3a-1c00-0000-e47d-bab90c0c0000 pid=3084 execve guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086 execve guuid=0878f83a-1c00-0000-e47d-bab9120c0000 pid=3090 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0878f83a-1c00-0000-e47d-bab9120c0000 pid=3090 execve guuid=c8aa9f3f-1c00-0000-e47d-bab91f0c0000 pid=3103 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=c8aa9f3f-1c00-0000-e47d-bab91f0c0000 pid=3103 execve guuid=0c86cf45-1c00-0000-e47d-bab9300c0000 pid=3120 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0c86cf45-1c00-0000-e47d-bab9300c0000 pid=3120 clone guuid=033f0246-1c00-0000-e47d-bab9310c0000 pid=3121 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=033f0246-1c00-0000-e47d-bab9310c0000 pid=3121 execve guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123 execve guuid=2bc3c346-1c00-0000-e47d-bab9380c0000 pid=3128 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=2bc3c346-1c00-0000-e47d-bab9380c0000 pid=3128 execve guuid=c37ec64b-1c00-0000-e47d-bab9430c0000 pid=3139 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=c37ec64b-1c00-0000-e47d-bab9430c0000 pid=3139 execve guuid=edbbdb51-1c00-0000-e47d-bab9560c0000 pid=3158 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=edbbdb51-1c00-0000-e47d-bab9560c0000 pid=3158 clone guuid=7dc21e52-1c00-0000-e47d-bab9580c0000 pid=3160 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=7dc21e52-1c00-0000-e47d-bab9580c0000 pid=3160 execve guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162 execve guuid=ffb94b53-1c00-0000-e47d-bab95f0c0000 pid=3167 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=ffb94b53-1c00-0000-e47d-bab95f0c0000 pid=3167 execve guuid=b6922459-1c00-0000-e47d-bab96d0c0000 pid=3181 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=b6922459-1c00-0000-e47d-bab96d0c0000 pid=3181 execve guuid=398b8f61-1c00-0000-e47d-bab97c0c0000 pid=3196 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=398b8f61-1c00-0000-e47d-bab97c0c0000 pid=3196 clone guuid=9ae3bf61-1c00-0000-e47d-bab97e0c0000 pid=3198 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9ae3bf61-1c00-0000-e47d-bab97e0c0000 pid=3198 execve guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200 execve guuid=6c37b962-1c00-0000-e47d-bab9850c0000 pid=3205 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=6c37b962-1c00-0000-e47d-bab9850c0000 pid=3205 execve guuid=0f01ee68-1c00-0000-e47d-bab9890c0000 pid=3209 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=0f01ee68-1c00-0000-e47d-bab9890c0000 pid=3209 execve guuid=53e64f70-1c00-0000-e47d-bab98e0c0000 pid=3214 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=53e64f70-1c00-0000-e47d-bab98e0c0000 pid=3214 clone guuid=b87a7770-1c00-0000-e47d-bab98f0c0000 pid=3215 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=b87a7770-1c00-0000-e47d-bab98f0c0000 pid=3215 execve guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218 execve guuid=dc888471-1c00-0000-e47d-bab9970c0000 pid=3223 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=dc888471-1c00-0000-e47d-bab9970c0000 pid=3223 execve guuid=a57d7d77-1c00-0000-e47d-bab9a50c0000 pid=3237 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=a57d7d77-1c00-0000-e47d-bab9a50c0000 pid=3237 execve guuid=5122ab7d-1c00-0000-e47d-bab9b50c0000 pid=3253 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=5122ab7d-1c00-0000-e47d-bab9b50c0000 pid=3253 clone guuid=bf95ec7d-1c00-0000-e47d-bab9b70c0000 pid=3255 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=bf95ec7d-1c00-0000-e47d-bab9b70c0000 pid=3255 execve guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257 execve guuid=6d73937e-1c00-0000-e47d-bab9c00c0000 pid=3264 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=6d73937e-1c00-0000-e47d-bab9c00c0000 pid=3264 execve guuid=a4b01184-1c00-0000-e47d-bab9c20c0000 pid=3266 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=a4b01184-1c00-0000-e47d-bab9c20c0000 pid=3266 execve guuid=c4764e8c-1c00-0000-e47d-bab9d00c0000 pid=3280 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=c4764e8c-1c00-0000-e47d-bab9d00c0000 pid=3280 clone guuid=060e778c-1c00-0000-e47d-bab9d10c0000 pid=3281 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=060e778c-1c00-0000-e47d-bab9d10c0000 pid=3281 execve guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283 execve guuid=b5c82f8d-1c00-0000-e47d-bab9d80c0000 pid=3288 /usr/bin/wget net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=b5c82f8d-1c00-0000-e47d-bab9d80c0000 pid=3288 execve guuid=aade1294-1c00-0000-e47d-bab9e10c0000 pid=3297 /usr/bin/curl net send-data write-file guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=aade1294-1c00-0000-e47d-bab9e10c0000 pid=3297 execve guuid=7be93d9c-1c00-0000-e47d-bab9e90c0000 pid=3305 /usr/bin/bash guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=7be93d9c-1c00-0000-e47d-bab9e90c0000 pid=3305 clone guuid=abef6a9c-1c00-0000-e47d-bab9ea0c0000 pid=3306 /usr/bin/chmod guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=abef6a9c-1c00-0000-e47d-bab9ea0c0000 pid=3306 execve guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307 /tmp/WTF net guuid=e2634cbe-1b00-0000-e47d-bab9030b0000 pid=2819->guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307 execve 09167120-9840-5a5a-925d-e4061c49b03e 83.142.209.9:80 guuid=a463b3be-1b00-0000-e47d-bab9040b0000 pid=2820->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=4d5234ca-1b00-0000-e47d-bab9130b0000 pid=2835->09167120-9840-5a5a-925d-e4061c49b03e send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=be4b4edc-1b00-0000-e47d-bab92b0b0000 pid=2859 /tmp/WTF guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857->guuid=be4b4edc-1b00-0000-e47d-bab92b0b0000 pid=2859 clone guuid=960554dc-1b00-0000-e47d-bab92c0b0000 pid=2860 /tmp/WTF guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857->guuid=960554dc-1b00-0000-e47d-bab92c0b0000 pid=2860 clone guuid=97115cdc-1b00-0000-e47d-bab92d0b0000 pid=2861 /tmp/WTF net zombie guuid=3dd8d6db-1b00-0000-e47d-bab9290b0000 pid=2857->guuid=97115cdc-1b00-0000-e47d-bab92d0b0000 pid=2861 clone 1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 83.142.209.9:3778 guuid=97115cdc-1b00-0000-e47d-bab92d0b0000 pid=2861->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=523471dc-1b00-0000-e47d-bab92e0b0000 pid=2862->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=9b6c30e2-1b00-0000-e47d-bab9370b0000 pid=2871->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7e16aef2-1b00-0000-e47d-bab9590b0000 pid=2905 /tmp/WTF guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903->guuid=7e16aef2-1b00-0000-e47d-bab9590b0000 pid=2905 clone guuid=3ffdb9f2-1b00-0000-e47d-bab95a0b0000 pid=2906 /tmp/WTF guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903->guuid=3ffdb9f2-1b00-0000-e47d-bab95a0b0000 pid=2906 clone guuid=5643c3f2-1b00-0000-e47d-bab95b0b0000 pid=2907 /tmp/WTF net zombie guuid=f9e761f2-1b00-0000-e47d-bab9570b0000 pid=2903->guuid=5643c3f2-1b00-0000-e47d-bab95b0b0000 pid=2907 clone guuid=5643c3f2-1b00-0000-e47d-bab95b0b0000 pid=2907->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=4cebd7f2-1b00-0000-e47d-bab95c0b0000 pid=2908->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=968dd6f9-1b00-0000-e47d-bab96c0b0000 pid=2924->09167120-9840-5a5a-925d-e4061c49b03e send: 97B guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5164c901-1c00-0000-e47d-bab9810b0000 pid=2945 /tmp/WTF guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944->guuid=5164c901-1c00-0000-e47d-bab9810b0000 pid=2945 clone guuid=db08ce01-1c00-0000-e47d-bab9820b0000 pid=2946 /tmp/WTF guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944->guuid=db08ce01-1c00-0000-e47d-bab9820b0000 pid=2946 clone guuid=272cd101-1c00-0000-e47d-bab9830b0000 pid=2947 /tmp/WTF net zombie guuid=2bc69c01-1c00-0000-e47d-bab9800b0000 pid=2944->guuid=272cd101-1c00-0000-e47d-bab9830b0000 pid=2947 clone guuid=272cd101-1c00-0000-e47d-bab9830b0000 pid=2947->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=2970e001-1c00-0000-e47d-bab9840b0000 pid=2948->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=7237eb05-1c00-0000-e47d-bab98e0b0000 pid=2958->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4ee0f80a-1c00-0000-e47d-bab99b0b0000 pid=2971 /tmp/WTF guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970->guuid=4ee0f80a-1c00-0000-e47d-bab99b0b0000 pid=2971 clone guuid=b2adfd0a-1c00-0000-e47d-bab99c0b0000 pid=2972 /tmp/WTF guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970->guuid=b2adfd0a-1c00-0000-e47d-bab99c0b0000 pid=2972 clone guuid=8114030b-1c00-0000-e47d-bab99d0b0000 pid=2973 /tmp/WTF net zombie guuid=5072b40a-1c00-0000-e47d-bab99a0b0000 pid=2970->guuid=8114030b-1c00-0000-e47d-bab99d0b0000 pid=2973 clone guuid=8114030b-1c00-0000-e47d-bab99d0b0000 pid=2973->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=97d21b0b-1c00-0000-e47d-bab99e0b0000 pid=2974->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=9284c10e-1c00-0000-e47d-bab9a60b0000 pid=2982->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=756eb113-1c00-0000-e47d-bab9b40b0000 pid=2996 /tmp/WTF guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995->guuid=756eb113-1c00-0000-e47d-bab9b40b0000 pid=2996 clone guuid=5168b413-1c00-0000-e47d-bab9b50b0000 pid=2997 /tmp/WTF guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995->guuid=5168b413-1c00-0000-e47d-bab9b50b0000 pid=2997 clone guuid=31d9b713-1c00-0000-e47d-bab9b60b0000 pid=2998 /tmp/WTF net zombie guuid=44688413-1c00-0000-e47d-bab9b30b0000 pid=2995->guuid=31d9b713-1c00-0000-e47d-bab9b60b0000 pid=2998 clone guuid=31d9b713-1c00-0000-e47d-bab9b60b0000 pid=2998->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=0e14c113-1c00-0000-e47d-bab9b70b0000 pid=2999->09167120-9840-5a5a-925d-e4061c49b03e send: 151B guuid=e6c71517-1c00-0000-e47d-bab9be0b0000 pid=3006->09167120-9840-5a5a-925d-e4061c49b03e send: 100B guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=855ab51d-1c00-0000-e47d-bab9cf0b0000 pid=3023 /tmp/WTF guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021->guuid=855ab51d-1c00-0000-e47d-bab9cf0b0000 pid=3023 clone guuid=d616bb1d-1c00-0000-e47d-bab9d00b0000 pid=3024 /tmp/WTF guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021->guuid=d616bb1d-1c00-0000-e47d-bab9d00b0000 pid=3024 clone guuid=958fc51d-1c00-0000-e47d-bab9d10b0000 pid=3025 /tmp/WTF net zombie guuid=6caa6c1d-1c00-0000-e47d-bab9cd0b0000 pid=3021->guuid=958fc51d-1c00-0000-e47d-bab9d10b0000 pid=3025 clone guuid=958fc51d-1c00-0000-e47d-bab9d10b0000 pid=3025->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=9a5cd51d-1c00-0000-e47d-bab9d20b0000 pid=3026->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=ce55fc22-1c00-0000-e47d-bab9d80b0000 pid=3032->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6075562f-1c00-0000-e47d-bab9ef0b0000 pid=3055 /tmp/WTF guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054->guuid=6075562f-1c00-0000-e47d-bab9ef0b0000 pid=3055 clone guuid=0e7f5b2f-1c00-0000-e47d-bab9f00b0000 pid=3056 /tmp/WTF guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054->guuid=0e7f5b2f-1c00-0000-e47d-bab9f00b0000 pid=3056 clone guuid=02f8612f-1c00-0000-e47d-bab9f10b0000 pid=3057 /tmp/WTF net zombie guuid=9ef3ff2e-1c00-0000-e47d-bab9ee0b0000 pid=3054->guuid=02f8612f-1c00-0000-e47d-bab9f10b0000 pid=3057 clone guuid=02f8612f-1c00-0000-e47d-bab9f10b0000 pid=3057->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=4c719c2f-1c00-0000-e47d-bab9f30b0000 pid=3059->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=20b75f34-1c00-0000-e47d-bab9fe0b0000 pid=3070->09167120-9840-5a5a-925d-e4061c49b03e send: 97B guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a52bdb3a-1c00-0000-e47d-bab90f0c0000 pid=3087 /tmp/WTF guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086->guuid=a52bdb3a-1c00-0000-e47d-bab90f0c0000 pid=3087 clone guuid=ed00e03a-1c00-0000-e47d-bab9100c0000 pid=3088 /tmp/WTF guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086->guuid=ed00e03a-1c00-0000-e47d-bab9100c0000 pid=3088 clone guuid=36cee43a-1c00-0000-e47d-bab9110c0000 pid=3089 /tmp/WTF net zombie guuid=3d0b983a-1c00-0000-e47d-bab90e0c0000 pid=3086->guuid=36cee43a-1c00-0000-e47d-bab9110c0000 pid=3089 clone guuid=36cee43a-1c00-0000-e47d-bab9110c0000 pid=3089->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=0878f83a-1c00-0000-e47d-bab9120c0000 pid=3090->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=c8aa9f3f-1c00-0000-e47d-bab91f0c0000 pid=3103->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7952ab46-1c00-0000-e47d-bab9350c0000 pid=3125 /tmp/WTF guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123->guuid=7952ab46-1c00-0000-e47d-bab9350c0000 pid=3125 clone guuid=0124b046-1c00-0000-e47d-bab9360c0000 pid=3126 /tmp/WTF guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123->guuid=0124b046-1c00-0000-e47d-bab9360c0000 pid=3126 clone guuid=0002b646-1c00-0000-e47d-bab9370c0000 pid=3127 /tmp/WTF net zombie guuid=9f406346-1c00-0000-e47d-bab9330c0000 pid=3123->guuid=0002b646-1c00-0000-e47d-bab9370c0000 pid=3127 clone guuid=0002b646-1c00-0000-e47d-bab9370c0000 pid=3127->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=2bc3c346-1c00-0000-e47d-bab9380c0000 pid=3128->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=c37ec64b-1c00-0000-e47d-bab9430c0000 pid=3139->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4ad82c53-1c00-0000-e47d-bab95c0c0000 pid=3164 /tmp/WTF guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162->guuid=4ad82c53-1c00-0000-e47d-bab95c0c0000 pid=3164 clone guuid=e5403253-1c00-0000-e47d-bab95d0c0000 pid=3165 /tmp/WTF guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162->guuid=e5403253-1c00-0000-e47d-bab95d0c0000 pid=3165 clone guuid=4f913953-1c00-0000-e47d-bab95e0c0000 pid=3166 /tmp/WTF net zombie guuid=2d37d852-1c00-0000-e47d-bab95a0c0000 pid=3162->guuid=4f913953-1c00-0000-e47d-bab95e0c0000 pid=3166 clone guuid=4f913953-1c00-0000-e47d-bab95e0c0000 pid=3166->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=ffb94b53-1c00-0000-e47d-bab95f0c0000 pid=3167->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=b6922459-1c00-0000-e47d-bab96d0c0000 pid=3181->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=08b27762-1c00-0000-e47d-bab9810c0000 pid=3201 /tmp/WTF guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200->guuid=08b27762-1c00-0000-e47d-bab9810c0000 pid=3201 clone guuid=f4e89d62-1c00-0000-e47d-bab9830c0000 pid=3203 /tmp/WTF guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200->guuid=f4e89d62-1c00-0000-e47d-bab9830c0000 pid=3203 clone guuid=bd33a762-1c00-0000-e47d-bab9840c0000 pid=3204 /tmp/WTF net zombie guuid=4de23c62-1c00-0000-e47d-bab9800c0000 pid=3200->guuid=bd33a762-1c00-0000-e47d-bab9840c0000 pid=3204 clone guuid=bd33a762-1c00-0000-e47d-bab9840c0000 pid=3204->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=6c37b962-1c00-0000-e47d-bab9850c0000 pid=3205->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=0f01ee68-1c00-0000-e47d-bab9890c0000 pid=3209->09167120-9840-5a5a-925d-e4061c49b03e send: 97B guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3c0b6771-1c00-0000-e47d-bab9940c0000 pid=3220 /tmp/WTF guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218->guuid=3c0b6771-1c00-0000-e47d-bab9940c0000 pid=3220 clone guuid=e1226c71-1c00-0000-e47d-bab9950c0000 pid=3221 /tmp/WTF guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218->guuid=e1226c71-1c00-0000-e47d-bab9950c0000 pid=3221 clone guuid=82827271-1c00-0000-e47d-bab9960c0000 pid=3222 /tmp/WTF net zombie guuid=3d191671-1c00-0000-e47d-bab9920c0000 pid=3218->guuid=82827271-1c00-0000-e47d-bab9960c0000 pid=3222 clone guuid=82827271-1c00-0000-e47d-bab9960c0000 pid=3222->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=dc888471-1c00-0000-e47d-bab9970c0000 pid=3223->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=a57d7d77-1c00-0000-e47d-bab9a50c0000 pid=3237->09167120-9840-5a5a-925d-e4061c49b03e send: 97B guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fc537e7e-1c00-0000-e47d-bab9bd0c0000 pid=3261 /tmp/WTF guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257->guuid=fc537e7e-1c00-0000-e47d-bab9bd0c0000 pid=3261 clone guuid=5c18837e-1c00-0000-e47d-bab9be0c0000 pid=3262 /tmp/WTF guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257->guuid=5c18837e-1c00-0000-e47d-bab9be0c0000 pid=3262 clone guuid=a9cb877e-1c00-0000-e47d-bab9bf0c0000 pid=3263 /tmp/WTF net zombie guuid=59d44f7e-1c00-0000-e47d-bab9b90c0000 pid=3257->guuid=a9cb877e-1c00-0000-e47d-bab9bf0c0000 pid=3263 clone guuid=a9cb877e-1c00-0000-e47d-bab9bf0c0000 pid=3263->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=6d73937e-1c00-0000-e47d-bab9c00c0000 pid=3264->09167120-9840-5a5a-925d-e4061c49b03e send: 149B guuid=a4b01184-1c00-0000-e47d-bab9c20c0000 pid=3266->09167120-9840-5a5a-925d-e4061c49b03e send: 98B guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1c62158d-1c00-0000-e47d-bab9d50c0000 pid=3285 /tmp/WTF guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283->guuid=1c62158d-1c00-0000-e47d-bab9d50c0000 pid=3285 clone guuid=a9c71a8d-1c00-0000-e47d-bab9d60c0000 pid=3286 /tmp/WTF guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283->guuid=a9c71a8d-1c00-0000-e47d-bab9d60c0000 pid=3286 clone guuid=93a0218d-1c00-0000-e47d-bab9d70c0000 pid=3287 /tmp/WTF net zombie guuid=5891d28c-1c00-0000-e47d-bab9d30c0000 pid=3283->guuid=93a0218d-1c00-0000-e47d-bab9d70c0000 pid=3287 clone guuid=93a0218d-1c00-0000-e47d-bab9d70c0000 pid=3287->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con guuid=b5c82f8d-1c00-0000-e47d-bab9d80c0000 pid=3288->09167120-9840-5a5a-925d-e4061c49b03e send: 148B guuid=aade1294-1c00-0000-e47d-bab9e10c0000 pid=3297->09167120-9840-5a5a-925d-e4061c49b03e send: 97B guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=843c4f9d-1c00-0000-e47d-bab9ec0c0000 pid=3308 /tmp/WTF guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307->guuid=843c4f9d-1c00-0000-e47d-bab9ec0c0000 pid=3308 clone guuid=a59b589d-1c00-0000-e47d-bab9ed0c0000 pid=3309 /tmp/WTF guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307->guuid=a59b589d-1c00-0000-e47d-bab9ed0c0000 pid=3309 clone guuid=b84d659d-1c00-0000-e47d-bab9ee0c0000 pid=3310 /tmp/WTF net zombie guuid=9f79fe9c-1c00-0000-e47d-bab9eb0c0000 pid=3307->guuid=b84d659d-1c00-0000-e47d-bab9ee0c0000 pid=3310 clone guuid=b84d659d-1c00-0000-e47d-bab9ee0c0000 pid=3310->1c81fa00-b3ce-56aa-b0a0-ca27c03f7d88 con
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2026-02-25 05:46:32 UTC
File Type:
Text (Shell)
AV detection:
23 of 36 (63.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders
Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e3140cc9dc1348c3d4d7f0e76211d5411083cf649c9ffd88dc2969e55d9f7b6f

(this sample)

  
Delivery method
Distributed via web download

Comments