MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ede0207a574383e05f70dcdde61fcba86bacbe95c2467075883a29b48ba4e551. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: ede0207a574383e05f70dcdde61fcba86bacbe95c2467075883a29b48ba4e551
SHA3-384 hash: fd64a1765507be2e36063d5dcfdce6ab046f74eb5e720e7c58adefef0d987cbb5c268c7318c48776ad2a97be42b0331c
SHA1 hash: a39c3a3dc0a30c1fafee9812738173e27b0cbb29
MD5 hash: be199c126258d6c3fffa56a2f5fc0ae9
humanhash: cardinal-purple-july-purple
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'910 bytes
First seen:2025-09-23 05:08:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vac7vc7N7hacMc6GacgkczPacccKWacucoUac7uc7o7Uacf1c3bacfc9RacSccg1:vac7vc7N7hacMc6GacgkczPacccKWacD
TLSH T19651C3C556878D302D63EE63F6B6432830C1B59A18F16FA7E9C8BEE4429EE247140753
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://37.114.37.19/hiddenbin/boatnet.x86acc077ee702812eaf6d68c96ddbf85133ad7ebf68c271de3fd83c20c26029df9 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.mips2f8befc5825cce8b5d0f84c7eb973b76a142c4e67136eac6302c1b03edb8dc10 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.arca6bcc5dcb2a9ae9daf9d612bf5ee4c7224b59b060e4298e1b827c9e66e547e28 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://37.114.37.19/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://37.114.37.19/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://37.114.37.19/hiddenbin/boatnet.mpsl997c7f26cc82fc2b2932a922acd49f8e279164aa2e5d99233e963ce771125731 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.arm0c48a6d53662e5a75fa10e1ade9724fbcd1822a9170e294dde07a7a6ce71a3eb Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.arm559ca3ca2437ceee173ac95007a6bb2d4b0d3339b2193a0742ae0bcb0a1385aa9 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.arm6d294782f32b1cbbd728426b659ab99889613f7e4daaab6d9cbd293ae28ab8c51 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.arm74652fbbb3c70ea236fca73bba89d3ad471f66294bdfefc5e01d36db91d6d6207 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.ppc0bcb76be8a2a32afbcd085a6c9e9815e4e8c63b64430f049d1573dd19337e17b Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://37.114.37.19/hiddenbin/boatnet.m68k86bb8875ea9e242bae2cf234828c6316100446e017ad160fd0a864c30c6e52b7 Mirai32-bit elf mirai Mozi
http://37.114.37.19/hiddenbin/boatnet.sh4ef0eaa8191e3c68c2b9fd9dd1d5da34f3b535a7c1b6dd33298f629e5ef5174a4 Mirai32-bit elf mirai Mozi

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-23T02:17:00Z UTC
Last seen:
2025-09-23T02:17:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=f212b70c-1900-0000-a10a-6476f4130000 pid=5108 /usr/bin/sudo guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115 /tmp/sample.bin guuid=f212b70c-1900-0000-a10a-6476f4130000 pid=5108->guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115 execve guuid=cfd11a0f-1900-0000-a10a-6476fe130000 pid=5118 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=cfd11a0f-1900-0000-a10a-6476fe130000 pid=5118 execve guuid=a95d2b14-1900-0000-a10a-64760b140000 pid=5131 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=a95d2b14-1900-0000-a10a-64760b140000 pid=5131 execve guuid=7512211f-1900-0000-a10a-647626140000 pid=5158 /usr/bin/cat guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=7512211f-1900-0000-a10a-647626140000 pid=5158 execve guuid=361d9a1f-1900-0000-a10a-647627140000 pid=5159 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=361d9a1f-1900-0000-a10a-647627140000 pid=5159 execve guuid=40283520-1900-0000-a10a-64762d140000 pid=5165 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=40283520-1900-0000-a10a-64762d140000 pid=5165 execve guuid=79d82822-1900-0000-a10a-647638140000 pid=5176 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=79d82822-1900-0000-a10a-647638140000 pid=5176 execve guuid=4ffa3c25-1900-0000-a10a-647647140000 pid=5191 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4ffa3c25-1900-0000-a10a-647647140000 pid=5191 execve guuid=088f0a2b-1900-0000-a10a-64765d140000 pid=5213 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=088f0a2b-1900-0000-a10a-64765d140000 pid=5213 clone guuid=1dfa242b-1900-0000-a10a-64765e140000 pid=5214 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=1dfa242b-1900-0000-a10a-64765e140000 pid=5214 execve guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215 execve guuid=0902312c-1900-0000-a10a-647663140000 pid=5219 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=0902312c-1900-0000-a10a-647663140000 pid=5219 execve guuid=52d7272f-1900-0000-a10a-647664140000 pid=5220 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=52d7272f-1900-0000-a10a-647664140000 pid=5220 execve guuid=71a3cc33-1900-0000-a10a-647665140000 pid=5221 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=71a3cc33-1900-0000-a10a-647665140000 pid=5221 clone guuid=7e8e2d34-1900-0000-a10a-647666140000 pid=5222 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=7e8e2d34-1900-0000-a10a-647666140000 pid=5222 execve guuid=919aac34-1900-0000-a10a-647667140000 pid=5223 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=919aac34-1900-0000-a10a-647667140000 pid=5223 execve guuid=812fd435-1900-0000-a10a-64766b140000 pid=5227 /usr/bin/wget net send-data guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=812fd435-1900-0000-a10a-64766b140000 pid=5227 execve guuid=9ab37737-1900-0000-a10a-64766c140000 pid=5228 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=9ab37737-1900-0000-a10a-64766c140000 pid=5228 execve guuid=0105973a-1900-0000-a10a-64766d140000 pid=5229 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=0105973a-1900-0000-a10a-64766d140000 pid=5229 clone guuid=4ee1b53a-1900-0000-a10a-64766e140000 pid=5230 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4ee1b53a-1900-0000-a10a-64766e140000 pid=5230 execve guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231 execve guuid=17a7f93b-1900-0000-a10a-647673140000 pid=5235 /usr/bin/wget net send-data guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=17a7f93b-1900-0000-a10a-647673140000 pid=5235 execve guuid=53ddcc3d-1900-0000-a10a-647674140000 pid=5236 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=53ddcc3d-1900-0000-a10a-647674140000 pid=5236 execve guuid=a054c341-1900-0000-a10a-647675140000 pid=5237 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=a054c341-1900-0000-a10a-647675140000 pid=5237 clone guuid=361a0642-1900-0000-a10a-647676140000 pid=5238 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=361a0642-1900-0000-a10a-647676140000 pid=5238 execve guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239 execve guuid=9c6f3a43-1900-0000-a10a-64767b140000 pid=5243 /usr/bin/wget net send-data guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=9c6f3a43-1900-0000-a10a-64767b140000 pid=5243 execve guuid=52ff2145-1900-0000-a10a-64767d140000 pid=5245 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=52ff2145-1900-0000-a10a-64767d140000 pid=5245 execve guuid=17819847-1900-0000-a10a-647680140000 pid=5248 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=17819847-1900-0000-a10a-647680140000 pid=5248 clone guuid=0f22b447-1900-0000-a10a-647681140000 pid=5249 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=0f22b447-1900-0000-a10a-647681140000 pid=5249 execve guuid=331ef147-1900-0000-a10a-647682140000 pid=5250 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=331ef147-1900-0000-a10a-647682140000 pid=5250 execve guuid=4beb9e48-1900-0000-a10a-647686140000 pid=5254 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4beb9e48-1900-0000-a10a-647686140000 pid=5254 execve guuid=beae114b-1900-0000-a10a-647687140000 pid=5255 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=beae114b-1900-0000-a10a-647687140000 pid=5255 execve guuid=55741f4f-1900-0000-a10a-647688140000 pid=5256 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=55741f4f-1900-0000-a10a-647688140000 pid=5256 clone guuid=272c514f-1900-0000-a10a-647689140000 pid=5257 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=272c514f-1900-0000-a10a-647689140000 pid=5257 execve guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258 execve guuid=d181ba50-1900-0000-a10a-64768e140000 pid=5262 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=d181ba50-1900-0000-a10a-64768e140000 pid=5262 execve guuid=da458253-1900-0000-a10a-64768f140000 pid=5263 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=da458253-1900-0000-a10a-64768f140000 pid=5263 execve guuid=af75ab6b-1900-0000-a10a-647690140000 pid=5264 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=af75ab6b-1900-0000-a10a-647690140000 pid=5264 clone guuid=3792e96b-1900-0000-a10a-647691140000 pid=5265 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=3792e96b-1900-0000-a10a-647691140000 pid=5265 execve guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266 execve guuid=74dee86d-1900-0000-a10a-647698140000 pid=5272 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=74dee86d-1900-0000-a10a-647698140000 pid=5272 execve guuid=6964eb70-1900-0000-a10a-64769f140000 pid=5279 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=6964eb70-1900-0000-a10a-64769f140000 pid=5279 execve guuid=d8d36474-1900-0000-a10a-6476a0140000 pid=5280 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=d8d36474-1900-0000-a10a-6476a0140000 pid=5280 clone guuid=bc208874-1900-0000-a10a-6476a1140000 pid=5281 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=bc208874-1900-0000-a10a-6476a1140000 pid=5281 execve guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282 execve guuid=36f37d75-1900-0000-a10a-6476a6140000 pid=5286 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=36f37d75-1900-0000-a10a-6476a6140000 pid=5286 execve guuid=20262c78-1900-0000-a10a-6476a7140000 pid=5287 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=20262c78-1900-0000-a10a-6476a7140000 pid=5287 execve guuid=3173727b-1900-0000-a10a-6476a8140000 pid=5288 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=3173727b-1900-0000-a10a-6476a8140000 pid=5288 clone guuid=36c5937b-1900-0000-a10a-6476a9140000 pid=5289 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=36c5937b-1900-0000-a10a-6476a9140000 pid=5289 execve guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290 execve guuid=e133957c-1900-0000-a10a-6476ae140000 pid=5294 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=e133957c-1900-0000-a10a-6476ae140000 pid=5294 execve guuid=4b76d07f-1900-0000-a10a-6476af140000 pid=5295 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4b76d07f-1900-0000-a10a-6476af140000 pid=5295 execve guuid=4ac61785-1900-0000-a10a-6476b0140000 pid=5296 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4ac61785-1900-0000-a10a-6476b0140000 pid=5296 clone guuid=63183c85-1900-0000-a10a-6476b1140000 pid=5297 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=63183c85-1900-0000-a10a-6476b1140000 pid=5297 execve guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298 execve guuid=6a80c786-1900-0000-a10a-6476b6140000 pid=5302 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=6a80c786-1900-0000-a10a-6476b6140000 pid=5302 execve guuid=81d4f589-1900-0000-a10a-6476b7140000 pid=5303 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=81d4f589-1900-0000-a10a-6476b7140000 pid=5303 execve guuid=35159b8e-1900-0000-a10a-6476b8140000 pid=5304 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=35159b8e-1900-0000-a10a-6476b8140000 pid=5304 clone guuid=cdc0d08e-1900-0000-a10a-6476b9140000 pid=5305 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=cdc0d08e-1900-0000-a10a-6476b9140000 pid=5305 execve guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306 execve guuid=10a57190-1900-0000-a10a-6476be140000 pid=5310 /usr/bin/wget net send-data guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=10a57190-1900-0000-a10a-6476be140000 pid=5310 execve guuid=d5c85593-1900-0000-a10a-6476bf140000 pid=5311 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=d5c85593-1900-0000-a10a-6476bf140000 pid=5311 execve guuid=2e6ac396-1900-0000-a10a-6476c0140000 pid=5312 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=2e6ac396-1900-0000-a10a-6476c0140000 pid=5312 clone guuid=9b85e596-1900-0000-a10a-6476c1140000 pid=5313 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=9b85e596-1900-0000-a10a-6476c1140000 pid=5313 execve guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314 execve guuid=a4756098-1900-0000-a10a-6476c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=a4756098-1900-0000-a10a-6476c6140000 pid=5318 execve guuid=8151bf9b-1900-0000-a10a-6476c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=8151bf9b-1900-0000-a10a-6476c7140000 pid=5319 execve guuid=5710b9a0-1900-0000-a10a-6476c8140000 pid=5320 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=5710b9a0-1900-0000-a10a-6476c8140000 pid=5320 clone guuid=2b77e6a0-1900-0000-a10a-6476c9140000 pid=5321 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=2b77e6a0-1900-0000-a10a-6476c9140000 pid=5321 execve guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322 execve guuid=014e9fa2-1900-0000-a10a-6476ce140000 pid=5326 /usr/bin/wget net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=014e9fa2-1900-0000-a10a-6476ce140000 pid=5326 execve guuid=6f7f08a7-1900-0000-a10a-6476cf140000 pid=5327 /usr/bin/curl net send-data write-file guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=6f7f08a7-1900-0000-a10a-6476cf140000 pid=5327 execve guuid=ac694eac-1900-0000-a10a-6476d0140000 pid=5328 /usr/bin/bash guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=ac694eac-1900-0000-a10a-6476d0140000 pid=5328 clone guuid=96286aac-1900-0000-a10a-6476d1140000 pid=5329 /usr/bin/chmod guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=96286aac-1900-0000-a10a-6476d1140000 pid=5329 execve guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330 /tmp/WTF net guuid=7733400e-1900-0000-a10a-6476fb130000 pid=5115->guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330 execve 9544e5e7-d937-5c56-ab35-4e6432a1d794 37.114.37.19:80 guuid=cfd11a0f-1900-0000-a10a-6476fe130000 pid=5118->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=a95d2b14-1900-0000-a10a-64760b140000 pid=5131->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=40283520-1900-0000-a10a-64762d140000 pid=5165->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=da62c221-1900-0000-a10a-647633140000 pid=5171 /tmp/WTF guuid=40283520-1900-0000-a10a-64762d140000 pid=5165->guuid=da62c221-1900-0000-a10a-647633140000 pid=5171 clone guuid=ba7dca21-1900-0000-a10a-647635140000 pid=5173 /tmp/WTF guuid=40283520-1900-0000-a10a-64762d140000 pid=5165->guuid=ba7dca21-1900-0000-a10a-647635140000 pid=5173 clone guuid=c83bd021-1900-0000-a10a-647636140000 pid=5174 /tmp/WTF net send-data zombie guuid=40283520-1900-0000-a10a-64762d140000 pid=5165->guuid=c83bd021-1900-0000-a10a-647636140000 pid=5174 clone guuid=c83bd021-1900-0000-a10a-647636140000 pid=5174->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 06142b72-d45b-5741-86ab-8db9d6808404 37.114.37.19:3778 guuid=c83bd021-1900-0000-a10a-647636140000 pid=5174->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=79d82822-1900-0000-a10a-647638140000 pid=5176->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=4ffa3c25-1900-0000-a10a-647647140000 pid=5191->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7e291b2c-1900-0000-a10a-647660140000 pid=5216 /tmp/WTF guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215->guuid=7e291b2c-1900-0000-a10a-647660140000 pid=5216 clone guuid=b95e1e2c-1900-0000-a10a-647661140000 pid=5217 /tmp/WTF guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215->guuid=b95e1e2c-1900-0000-a10a-647661140000 pid=5217 clone guuid=9696232c-1900-0000-a10a-647662140000 pid=5218 /tmp/WTF net send-data zombie guuid=01516d2b-1900-0000-a10a-64765f140000 pid=5215->guuid=9696232c-1900-0000-a10a-647662140000 pid=5218 clone guuid=9696232c-1900-0000-a10a-647662140000 pid=5218->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9696232c-1900-0000-a10a-647662140000 pid=5218->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=0902312c-1900-0000-a10a-647663140000 pid=5219->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=52d7272f-1900-0000-a10a-647664140000 pid=5220->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B guuid=919aac34-1900-0000-a10a-647667140000 pid=5223->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e96b9e35-1900-0000-a10a-647668140000 pid=5224 /tmp/WTF guuid=919aac34-1900-0000-a10a-647667140000 pid=5223->guuid=e96b9e35-1900-0000-a10a-647668140000 pid=5224 clone guuid=32e4ad35-1900-0000-a10a-647669140000 pid=5225 /tmp/WTF guuid=919aac34-1900-0000-a10a-647667140000 pid=5223->guuid=32e4ad35-1900-0000-a10a-647669140000 pid=5225 clone guuid=d3ceb535-1900-0000-a10a-64766a140000 pid=5226 /tmp/WTF net send-data zombie guuid=919aac34-1900-0000-a10a-647667140000 pid=5223->guuid=d3ceb535-1900-0000-a10a-64766a140000 pid=5226 clone guuid=d3ceb535-1900-0000-a10a-64766a140000 pid=5226->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d3ceb535-1900-0000-a10a-64766a140000 pid=5226->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=812fd435-1900-0000-a10a-64766b140000 pid=5227->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=9ab37737-1900-0000-a10a-64766c140000 pid=5228->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1248d93b-1900-0000-a10a-647670140000 pid=5232 /tmp/WTF guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231->guuid=1248d93b-1900-0000-a10a-647670140000 pid=5232 clone guuid=7b14de3b-1900-0000-a10a-647671140000 pid=5233 /tmp/WTF guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231->guuid=7b14de3b-1900-0000-a10a-647671140000 pid=5233 clone guuid=cfa7e43b-1900-0000-a10a-647672140000 pid=5234 /tmp/WTF net send-data zombie guuid=fc5b293b-1900-0000-a10a-64766f140000 pid=5231->guuid=cfa7e43b-1900-0000-a10a-647672140000 pid=5234 clone guuid=cfa7e43b-1900-0000-a10a-647672140000 pid=5234->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cfa7e43b-1900-0000-a10a-647672140000 pid=5234->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=17a7f93b-1900-0000-a10a-647673140000 pid=5235->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=53ddcc3d-1900-0000-a10a-647674140000 pid=5236->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d8470f43-1900-0000-a10a-647678140000 pid=5240 /tmp/WTF guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239->guuid=d8470f43-1900-0000-a10a-647678140000 pid=5240 clone guuid=b7cb1843-1900-0000-a10a-647679140000 pid=5241 /tmp/WTF guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239->guuid=b7cb1843-1900-0000-a10a-647679140000 pid=5241 clone guuid=2d7e2743-1900-0000-a10a-64767a140000 pid=5242 /tmp/WTF net send-data zombie guuid=ec085a42-1900-0000-a10a-647677140000 pid=5239->guuid=2d7e2743-1900-0000-a10a-64767a140000 pid=5242 clone guuid=2d7e2743-1900-0000-a10a-64767a140000 pid=5242->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2d7e2743-1900-0000-a10a-64767a140000 pid=5242->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=9c6f3a43-1900-0000-a10a-64767b140000 pid=5243->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 151B guuid=52ff2145-1900-0000-a10a-64767d140000 pid=5245->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 100B guuid=331ef147-1900-0000-a10a-647682140000 pid=5250->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=973b8848-1900-0000-a10a-647683140000 pid=5251 /tmp/WTF guuid=331ef147-1900-0000-a10a-647682140000 pid=5250->guuid=973b8848-1900-0000-a10a-647683140000 pid=5251 clone guuid=eed68c48-1900-0000-a10a-647684140000 pid=5252 /tmp/WTF guuid=331ef147-1900-0000-a10a-647682140000 pid=5250->guuid=eed68c48-1900-0000-a10a-647684140000 pid=5252 clone guuid=8b4d9248-1900-0000-a10a-647685140000 pid=5253 /tmp/WTF net send-data zombie guuid=331ef147-1900-0000-a10a-647682140000 pid=5250->guuid=8b4d9248-1900-0000-a10a-647685140000 pid=5253 clone guuid=8b4d9248-1900-0000-a10a-647685140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8b4d9248-1900-0000-a10a-647685140000 pid=5253->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=4beb9e48-1900-0000-a10a-647686140000 pid=5254->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=beae114b-1900-0000-a10a-647687140000 pid=5255->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=45749b50-1900-0000-a10a-64768b140000 pid=5259 /tmp/WTF guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258->guuid=45749b50-1900-0000-a10a-64768b140000 pid=5259 clone guuid=52eca150-1900-0000-a10a-64768c140000 pid=5260 /tmp/WTF guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258->guuid=52eca150-1900-0000-a10a-64768c140000 pid=5260 clone guuid=97eda750-1900-0000-a10a-64768d140000 pid=5261 /tmp/WTF net send-data zombie guuid=f82ed54f-1900-0000-a10a-64768a140000 pid=5258->guuid=97eda750-1900-0000-a10a-64768d140000 pid=5261 clone guuid=97eda750-1900-0000-a10a-64768d140000 pid=5261->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=97eda750-1900-0000-a10a-64768d140000 pid=5261->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=d181ba50-1900-0000-a10a-64768e140000 pid=5262->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=da458253-1900-0000-a10a-64768f140000 pid=5263->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=29b3c36d-1900-0000-a10a-647695140000 pid=5269 /tmp/WTF guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266->guuid=29b3c36d-1900-0000-a10a-647695140000 pid=5269 clone guuid=a787ce6d-1900-0000-a10a-647696140000 pid=5270 /tmp/WTF guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266->guuid=a787ce6d-1900-0000-a10a-647696140000 pid=5270 clone guuid=fd9bd66d-1900-0000-a10a-647697140000 pid=5271 /tmp/WTF net send-data zombie guuid=9e038c6c-1900-0000-a10a-647692140000 pid=5266->guuid=fd9bd66d-1900-0000-a10a-647697140000 pid=5271 clone guuid=fd9bd66d-1900-0000-a10a-647697140000 pid=5271->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fd9bd66d-1900-0000-a10a-647697140000 pid=5271->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=74dee86d-1900-0000-a10a-647698140000 pid=5272->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=6964eb70-1900-0000-a10a-64769f140000 pid=5279->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fb426775-1900-0000-a10a-6476a3140000 pid=5283 /tmp/WTF guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282->guuid=fb426775-1900-0000-a10a-6476a3140000 pid=5283 clone guuid=810f6c75-1900-0000-a10a-6476a4140000 pid=5284 /tmp/WTF guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282->guuid=810f6c75-1900-0000-a10a-6476a4140000 pid=5284 clone guuid=53346f75-1900-0000-a10a-6476a5140000 pid=5285 /tmp/WTF net send-data zombie guuid=62d8d674-1900-0000-a10a-6476a2140000 pid=5282->guuid=53346f75-1900-0000-a10a-6476a5140000 pid=5285 clone guuid=53346f75-1900-0000-a10a-6476a5140000 pid=5285->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=53346f75-1900-0000-a10a-6476a5140000 pid=5285->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=36f37d75-1900-0000-a10a-6476a6140000 pid=5286->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=20262c78-1900-0000-a10a-6476a7140000 pid=5287->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c84b747c-1900-0000-a10a-6476ab140000 pid=5291 /tmp/WTF guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290->guuid=c84b747c-1900-0000-a10a-6476ab140000 pid=5291 clone guuid=9d30787c-1900-0000-a10a-6476ac140000 pid=5292 /tmp/WTF guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290->guuid=9d30787c-1900-0000-a10a-6476ac140000 pid=5292 clone guuid=6a9b7b7c-1900-0000-a10a-6476ad140000 pid=5293 /tmp/WTF net send-data zombie guuid=8807ea7b-1900-0000-a10a-6476aa140000 pid=5290->guuid=6a9b7b7c-1900-0000-a10a-6476ad140000 pid=5293 clone guuid=6a9b7b7c-1900-0000-a10a-6476ad140000 pid=5293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6a9b7b7c-1900-0000-a10a-6476ad140000 pid=5293->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=e133957c-1900-0000-a10a-6476ae140000 pid=5294->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=4b76d07f-1900-0000-a10a-6476af140000 pid=5295->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=543d9386-1900-0000-a10a-6476b3140000 pid=5299 /tmp/WTF guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298->guuid=543d9386-1900-0000-a10a-6476b3140000 pid=5299 clone guuid=d4dda386-1900-0000-a10a-6476b4140000 pid=5300 /tmp/WTF guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298->guuid=d4dda386-1900-0000-a10a-6476b4140000 pid=5300 clone guuid=f221b086-1900-0000-a10a-6476b5140000 pid=5301 /tmp/WTF net send-data zombie guuid=906a9f85-1900-0000-a10a-6476b2140000 pid=5298->guuid=f221b086-1900-0000-a10a-6476b5140000 pid=5301 clone guuid=f221b086-1900-0000-a10a-6476b5140000 pid=5301->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f221b086-1900-0000-a10a-6476b5140000 pid=5301->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=6a80c786-1900-0000-a10a-6476b6140000 pid=5302->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=81d4f589-1900-0000-a10a-6476b7140000 pid=5303->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bc0b5990-1900-0000-a10a-6476bb140000 pid=5307 /tmp/WTF guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306->guuid=bc0b5990-1900-0000-a10a-6476bb140000 pid=5307 clone guuid=4a396090-1900-0000-a10a-6476bc140000 pid=5308 /tmp/WTF guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306->guuid=4a396090-1900-0000-a10a-6476bc140000 pid=5308 clone guuid=ea186690-1900-0000-a10a-6476bd140000 pid=5309 /tmp/WTF net send-data zombie guuid=b757658f-1900-0000-a10a-6476ba140000 pid=5306->guuid=ea186690-1900-0000-a10a-6476bd140000 pid=5309 clone guuid=ea186690-1900-0000-a10a-6476bd140000 pid=5309->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ea186690-1900-0000-a10a-6476bd140000 pid=5309->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=10a57190-1900-0000-a10a-6476be140000 pid=5310->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=d5c85593-1900-0000-a10a-6476bf140000 pid=5311->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9d114798-1900-0000-a10a-6476c3140000 pid=5315 /tmp/WTF guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314->guuid=9d114798-1900-0000-a10a-6476c3140000 pid=5315 clone guuid=51414d98-1900-0000-a10a-6476c4140000 pid=5316 /tmp/WTF guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314->guuid=51414d98-1900-0000-a10a-6476c4140000 pid=5316 clone guuid=fb0f5398-1900-0000-a10a-6476c5140000 pid=5317 /tmp/WTF net send-data zombie guuid=85f75497-1900-0000-a10a-6476c2140000 pid=5314->guuid=fb0f5398-1900-0000-a10a-6476c5140000 pid=5317 clone guuid=fb0f5398-1900-0000-a10a-6476c5140000 pid=5317->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fb0f5398-1900-0000-a10a-6476c5140000 pid=5317->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=a4756098-1900-0000-a10a-6476c6140000 pid=5318->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 149B guuid=8151bf9b-1900-0000-a10a-6476c7140000 pid=5319->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 98B guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6b4884a2-1900-0000-a10a-6476cb140000 pid=5323 /tmp/WTF guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322->guuid=6b4884a2-1900-0000-a10a-6476cb140000 pid=5323 clone guuid=c02889a2-1900-0000-a10a-6476cc140000 pid=5324 /tmp/WTF guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322->guuid=c02889a2-1900-0000-a10a-6476cc140000 pid=5324 clone guuid=5e3c90a2-1900-0000-a10a-6476cd140000 pid=5325 /tmp/WTF net send-data zombie guuid=4a1581a1-1900-0000-a10a-6476ca140000 pid=5322->guuid=5e3c90a2-1900-0000-a10a-6476cd140000 pid=5325 clone guuid=5e3c90a2-1900-0000-a10a-6476cd140000 pid=5325->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5e3c90a2-1900-0000-a10a-6476cd140000 pid=5325->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B guuid=014e9fa2-1900-0000-a10a-6476ce140000 pid=5326->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 148B guuid=6f7f08a7-1900-0000-a10a-6476cf140000 pid=5327->9544e5e7-d937-5c56-ab35-4e6432a1d794 send: 97B guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e9e451ad-1900-0000-a10a-6476d3140000 pid=5331 /tmp/WTF guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330->guuid=e9e451ad-1900-0000-a10a-6476d3140000 pid=5331 clone guuid=568f56ad-1900-0000-a10a-6476d4140000 pid=5332 /tmp/WTF guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330->guuid=568f56ad-1900-0000-a10a-6476d4140000 pid=5332 clone guuid=f9615bad-1900-0000-a10a-6476d5140000 pid=5333 /tmp/WTF net send-data zombie guuid=c0b4b3ac-1900-0000-a10a-6476d2140000 pid=5330->guuid=f9615bad-1900-0000-a10a-6476d5140000 pid=5333 clone guuid=f9615bad-1900-0000-a10a-6476d5140000 pid=5333->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f9615bad-1900-0000-a10a-6476d5140000 pid=5333->06142b72-d45b-5741-86ab-8db9d6808404 send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-09-23 04:54:32 UTC
File Type:
Text (Shell)
AV detection:
24 of 38 (63.16%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh ede0207a574383e05f70dcdde61fcba86bacbe95c2467075883a29b48ba4e551

(this sample)

  
Delivery method
Distributed via web download

Comments