MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f41e6de59989e2c6ed117b87578e0af3aaa5aaad2ef47a6e054f591b0c166d6d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: f41e6de59989e2c6ed117b87578e0af3aaa5aaad2ef47a6e054f591b0c166d6d
SHA3-384 hash: b6bc4f24071043ba0c2813e8531f21b1dfd11fd61df7c6b149cd2108968b1e3d1e49998ac22986afddcf5950ad78bf24
SHA1 hash: ca6bd1110df1a696d8eddc5b05068e5fd9689b93
MD5 hash: a45649aa9691bd169c078330a0303cc8
humanhash: green-cardinal-single-batman
File name:ohshit.sh
Download: download sample
Signature Mirai
File size:2'940 bytes
First seen:2025-08-19 03:42:36 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vsX7pX7N7hsX+X6GsXgWXzPsXuXKWsXgXoUsX7gX7o7UsXf3X3bsX5X9RsXEXcgx:vsX7pX7N7hsX+X6GsXgWXzPsXuXKWsX2
TLSH T1C551FE8543040D7CA963EA67F6B68A6836C5949ACCE1FB99DDCCBEE0034EC607E40753
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://87.248.130.35/hiddenbin/boatnet.x868f0e238a567f9ca48b1c4b1a66632fc7b81677cc96cc4dc45bea2f911afede98 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.mips3afc9fbca40c7438888ac8cf76960cacc995fbd318f5da8ab9a2c19aa7eb43c5 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.arcef22eb1202da76a34463883d389b4ba38fec546f63448baa5ce23f14df37e3fb Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.i468n/an/aelf ua-wget
http://87.248.130.35/hiddenbin/boatnet.i686n/an/aelf ua-wget
http://87.248.130.35/hiddenbin/boatnet.x86_64n/an/aelf ua-wget
http://87.248.130.35/hiddenbin/boatnet.mpsl59133721df19c0f3a98427cb0488ae138aa57a72f5dd5bd93c0c04f8ce898f1c Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.armf5e000f5fbf47ca4af50578c9f7faa043cd26f387e265f76043a52e034a2648e Mirai32-bit elf mirai Mozi
http://87.248.130.35/hiddenbin/boatnet.arm52944417cc687828437b385ab784070a6ed78be9ff0351f0bb76252afd82f2d05 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.arm6dfa9c94cf8083b93dd6b1671798925677c4d2b8d57fca00ae51cb53a2869af28 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.arm7b50cb401830afeb0ababa44c7a4fd6ec8750e201390ab2552b1c94418d40af06 Mirai32-bit elf mirai Mozi
http://87.248.130.35/hiddenbin/boatnet.ppcfff1297728f6e5c4d08c640cabff2461d7af035b9e7d17c955fcba6582aff8c2 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.spcn/an/aelf ua-wget
http://87.248.130.35/hiddenbin/boatnet.m68k614da65bb9290e16302332692a6f7a0e722f1081ef2f8379d438addab8587fe5 Miraielf mirai ua-wget
http://87.248.130.35/hiddenbin/boatnet.sh41ff919c6528e2e4531ffe74ac4cd35c9fbbd513cc38fb69bedf7ebb16f961b9b Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=be843c61-1700-0000-a28d-80df7c0d0000 pid=3452 /usr/bin/sudo guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459 /tmp/sample.bin guuid=be843c61-1700-0000-a28d-80df7c0d0000 pid=3452->guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459 execve guuid=dc4f8369-1700-0000-a28d-80df860d0000 pid=3462 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=dc4f8369-1700-0000-a28d-80df860d0000 pid=3462 execve guuid=7ef6467f-1700-0000-a28d-80df990d0000 pid=3481 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=7ef6467f-1700-0000-a28d-80df990d0000 pid=3481 execve guuid=e7e84ca6-1700-0000-a28d-80dfaa0d0000 pid=3498 /usr/bin/cat guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e7e84ca6-1700-0000-a28d-80dfaa0d0000 pid=3498 execve guuid=3eeca0a7-1700-0000-a28d-80dfad0d0000 pid=3501 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=3eeca0a7-1700-0000-a28d-80dfad0d0000 pid=3501 execve guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504 execve guuid=c48dc3ac-1700-0000-a28d-80dfb50d0000 pid=3509 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=c48dc3ac-1700-0000-a28d-80dfb50d0000 pid=3509 execve guuid=4dc279c5-1700-0000-a28d-80dfbd0d0000 pid=3517 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=4dc279c5-1700-0000-a28d-80dfbd0d0000 pid=3517 execve guuid=25564933-1800-0000-a28d-80dffd0d0000 pid=3581 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=25564933-1800-0000-a28d-80dffd0d0000 pid=3581 clone guuid=67949533-1800-0000-a28d-80dffe0d0000 pid=3582 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=67949533-1800-0000-a28d-80dffe0d0000 pid=3582 execve guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583 execve guuid=9891d235-1800-0000-a28d-80df030e0000 pid=3587 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=9891d235-1800-0000-a28d-80df030e0000 pid=3587 execve guuid=44130253-1800-0000-a28d-80df2a0e0000 pid=3626 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=44130253-1800-0000-a28d-80df2a0e0000 pid=3626 execve guuid=25586c6d-1800-0000-a28d-80df5d0e0000 pid=3677 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=25586c6d-1800-0000-a28d-80df5d0e0000 pid=3677 clone guuid=7b01a26d-1800-0000-a28d-80df5e0e0000 pid=3678 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=7b01a26d-1800-0000-a28d-80df5e0e0000 pid=3678 execve guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679 execve guuid=e8f8f46f-1800-0000-a28d-80df630e0000 pid=3683 /usr/bin/wget net send-data guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e8f8f46f-1800-0000-a28d-80df630e0000 pid=3683 execve guuid=7a76667c-1800-0000-a28d-80df700e0000 pid=3696 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=7a76667c-1800-0000-a28d-80df700e0000 pid=3696 execve guuid=e18b0d8c-1800-0000-a28d-80df8e0e0000 pid=3726 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e18b0d8c-1800-0000-a28d-80df8e0e0000 pid=3726 clone guuid=3f1b458c-1800-0000-a28d-80df8f0e0000 pid=3727 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=3f1b458c-1800-0000-a28d-80df8f0e0000 pid=3727 execve guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731 execve guuid=72f9bb8d-1800-0000-a28d-80df9b0e0000 pid=3739 /usr/bin/wget net send-data guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=72f9bb8d-1800-0000-a28d-80df9b0e0000 pid=3739 execve guuid=004f0c9b-1800-0000-a28d-80dfbb0e0000 pid=3771 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=004f0c9b-1800-0000-a28d-80dfbb0e0000 pid=3771 execve guuid=c36648e9-1800-0000-a28d-80df5f0f0000 pid=3935 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=c36648e9-1800-0000-a28d-80df5f0f0000 pid=3935 clone guuid=2dfd70e9-1800-0000-a28d-80df610f0000 pid=3937 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=2dfd70e9-1800-0000-a28d-80df610f0000 pid=3937 execve guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939 execve guuid=47a21beb-1800-0000-a28d-80df670f0000 pid=3943 /usr/bin/wget net send-data guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=47a21beb-1800-0000-a28d-80df670f0000 pid=3943 execve guuid=de382634-1900-0000-a28d-80df0f100000 pid=4111 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=de382634-1900-0000-a28d-80df0f100000 pid=4111 execve guuid=81e0a840-1900-0000-a28d-80df3a100000 pid=4154 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=81e0a840-1900-0000-a28d-80df3a100000 pid=4154 clone guuid=2a8dc740-1900-0000-a28d-80df3b100000 pid=4155 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=2a8dc740-1900-0000-a28d-80df3b100000 pid=4155 execve guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159 execve guuid=8b17a742-1900-0000-a28d-80df46100000 pid=4166 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=8b17a742-1900-0000-a28d-80df46100000 pid=4166 execve guuid=b5723559-1900-0000-a28d-80df7f100000 pid=4223 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=b5723559-1900-0000-a28d-80df7f100000 pid=4223 execve guuid=f0f68e74-1900-0000-a28d-80dfc4100000 pid=4292 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=f0f68e74-1900-0000-a28d-80dfc4100000 pid=4292 clone guuid=137caa74-1900-0000-a28d-80dfc5100000 pid=4293 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=137caa74-1900-0000-a28d-80dfc5100000 pid=4293 execve guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295 execve guuid=70519875-1900-0000-a28d-80dfcf100000 pid=4303 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=70519875-1900-0000-a28d-80dfcf100000 pid=4303 execve guuid=d7a83192-1900-0000-a28d-80df27110000 pid=4391 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=d7a83192-1900-0000-a28d-80df27110000 pid=4391 execve guuid=c84d38a8-1900-0000-a28d-80df77110000 pid=4471 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=c84d38a8-1900-0000-a28d-80df77110000 pid=4471 clone guuid=f0407ea8-1900-0000-a28d-80df78110000 pid=4472 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=f0407ea8-1900-0000-a28d-80df78110000 pid=4472 execve guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474 execve guuid=1fcf54aa-1900-0000-a28d-80df82110000 pid=4482 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=1fcf54aa-1900-0000-a28d-80df82110000 pid=4482 execve guuid=a5dc0bb9-1900-0000-a28d-80dfb5110000 pid=4533 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=a5dc0bb9-1900-0000-a28d-80dfb5110000 pid=4533 execve guuid=ba9b38da-1900-0000-a28d-80dfd0110000 pid=4560 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=ba9b38da-1900-0000-a28d-80dfd0110000 pid=4560 clone guuid=25a875da-1900-0000-a28d-80dfd1110000 pid=4561 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=25a875da-1900-0000-a28d-80dfd1110000 pid=4561 execve guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562 execve guuid=beb975dc-1900-0000-a28d-80dfd8110000 pid=4568 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=beb975dc-1900-0000-a28d-80dfd8110000 pid=4568 execve guuid=fb4456f3-1900-0000-a28d-80df11120000 pid=4625 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=fb4456f3-1900-0000-a28d-80df11120000 pid=4625 execve guuid=b2e2850e-1a00-0000-a28d-80df51120000 pid=4689 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=b2e2850e-1a00-0000-a28d-80df51120000 pid=4689 clone guuid=6f66ae0e-1a00-0000-a28d-80df52120000 pid=4690 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=6f66ae0e-1a00-0000-a28d-80df52120000 pid=4690 execve guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692 execve guuid=4e4b3f10-1a00-0000-a28d-80df5a120000 pid=4698 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=4e4b3f10-1a00-0000-a28d-80df5a120000 pid=4698 execve guuid=4af42227-1a00-0000-a28d-80dfa3120000 pid=4771 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=4af42227-1a00-0000-a28d-80dfa3120000 pid=4771 execve guuid=dcc6e93b-1a00-0000-a28d-80dfd8120000 pid=4824 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=dcc6e93b-1a00-0000-a28d-80dfd8120000 pid=4824 clone guuid=a3b20f3c-1a00-0000-a28d-80dfda120000 pid=4826 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=a3b20f3c-1a00-0000-a28d-80dfda120000 pid=4826 execve guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828 execve guuid=a91f583d-1a00-0000-a28d-80dfe3120000 pid=4835 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=a91f583d-1a00-0000-a28d-80dfe3120000 pid=4835 execve guuid=58695753-1a00-0000-a28d-80df18130000 pid=4888 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=58695753-1a00-0000-a28d-80df18130000 pid=4888 execve guuid=b0126f6b-1a00-0000-a28d-80df4f130000 pid=4943 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=b0126f6b-1a00-0000-a28d-80df4f130000 pid=4943 clone guuid=ee8b9f6b-1a00-0000-a28d-80df50130000 pid=4944 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=ee8b9f6b-1a00-0000-a28d-80df50130000 pid=4944 execve guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946 execve guuid=cbb05b6d-1a00-0000-a28d-80df59130000 pid=4953 /usr/bin/wget net send-data guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=cbb05b6d-1a00-0000-a28d-80df59130000 pid=4953 execve guuid=d625a17d-1a00-0000-a28d-80df7e130000 pid=4990 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=d625a17d-1a00-0000-a28d-80df7e130000 pid=4990 execve guuid=708f2a8a-1a00-0000-a28d-80df9f130000 pid=5023 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=708f2a8a-1a00-0000-a28d-80df9f130000 pid=5023 clone guuid=979e4c8a-1a00-0000-a28d-80dfa0130000 pid=5024 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=979e4c8a-1a00-0000-a28d-80dfa0130000 pid=5024 execve guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026 execve guuid=540a838b-1a00-0000-a28d-80dfa8130000 pid=5032 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=540a838b-1a00-0000-a28d-80dfa8130000 pid=5032 execve guuid=e817cda4-1a00-0000-a28d-80dfde130000 pid=5086 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e817cda4-1a00-0000-a28d-80dfde130000 pid=5086 execve guuid=c2d9d3c0-1a00-0000-a28d-80df48140000 pid=5192 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=c2d9d3c0-1a00-0000-a28d-80df48140000 pid=5192 clone guuid=361c08c1-1a00-0000-a28d-80df4a140000 pid=5194 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=361c08c1-1a00-0000-a28d-80df4a140000 pid=5194 execve guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196 execve guuid=9b3140c2-1a00-0000-a28d-80df52140000 pid=5202 /usr/bin/wget net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=9b3140c2-1a00-0000-a28d-80df52140000 pid=5202 execve guuid=82f893d9-1a00-0000-a28d-80df8a140000 pid=5258 /usr/bin/curl net send-data write-file guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=82f893d9-1a00-0000-a28d-80df8a140000 pid=5258 execve guuid=b66602f5-1a00-0000-a28d-80dfcf140000 pid=5327 /usr/bin/bash guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=b66602f5-1a00-0000-a28d-80dfcf140000 pid=5327 clone guuid=94183ff5-1a00-0000-a28d-80dfd0140000 pid=5328 /usr/bin/chmod guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=94183ff5-1a00-0000-a28d-80dfd0140000 pid=5328 execve guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329 /tmp/WTF net guuid=074fcc67-1700-0000-a28d-80df830d0000 pid=3459->guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329 execve 41abd0c0-c36d-5d43-9c6a-01ff76e22160 87.248.130.35:80 guuid=dc4f8369-1700-0000-a28d-80df860d0000 pid=3462->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=7ef6467f-1700-0000-a28d-80df990d0000 pid=3481->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=72660cac-1700-0000-a28d-80dfb20d0000 pid=3506 /tmp/WTF guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504->guuid=72660cac-1700-0000-a28d-80dfb20d0000 pid=3506 clone guuid=62451bac-1700-0000-a28d-80dfb30d0000 pid=3507 /tmp/WTF guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504->guuid=62451bac-1700-0000-a28d-80dfb30d0000 pid=3507 clone guuid=23cc48ac-1700-0000-a28d-80dfb40d0000 pid=3508 /tmp/WTF net send-data zombie guuid=f5e445aa-1700-0000-a28d-80dfb00d0000 pid=3504->guuid=23cc48ac-1700-0000-a28d-80dfb40d0000 pid=3508 clone guuid=23cc48ac-1700-0000-a28d-80dfb40d0000 pid=3508->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 3689577d-053d-55fe-8eb3-83de1ecc9462 87.248.130.35:3778 guuid=23cc48ac-1700-0000-a28d-80dfb40d0000 pid=3508->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=c48dc3ac-1700-0000-a28d-80dfb50d0000 pid=3509->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=4dc279c5-1700-0000-a28d-80dfbd0d0000 pid=3517->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=30656f35-1800-0000-a28d-80df000e0000 pid=3584 /tmp/WTF guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583->guuid=30656f35-1800-0000-a28d-80df000e0000 pid=3584 clone guuid=99c69035-1800-0000-a28d-80df010e0000 pid=3585 /tmp/WTF guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583->guuid=99c69035-1800-0000-a28d-80df010e0000 pid=3585 clone guuid=cf04a035-1800-0000-a28d-80df020e0000 pid=3586 /tmp/WTF net send-data zombie guuid=015f2834-1800-0000-a28d-80dfff0d0000 pid=3583->guuid=cf04a035-1800-0000-a28d-80df020e0000 pid=3586 clone guuid=cf04a035-1800-0000-a28d-80df020e0000 pid=3586->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf04a035-1800-0000-a28d-80df020e0000 pid=3586->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=9891d235-1800-0000-a28d-80df030e0000 pid=3587->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=44130253-1800-0000-a28d-80df2a0e0000 pid=3626->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ca10cd6f-1800-0000-a28d-80df600e0000 pid=3680 /tmp/WTF guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679->guuid=ca10cd6f-1800-0000-a28d-80df600e0000 pid=3680 clone guuid=7facd66f-1800-0000-a28d-80df610e0000 pid=3681 /tmp/WTF guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679->guuid=7facd66f-1800-0000-a28d-80df610e0000 pid=3681 clone guuid=4bdce16f-1800-0000-a28d-80df620e0000 pid=3682 /tmp/WTF net send-data zombie guuid=e6b6736e-1800-0000-a28d-80df5f0e0000 pid=3679->guuid=4bdce16f-1800-0000-a28d-80df620e0000 pid=3682 clone guuid=4bdce16f-1800-0000-a28d-80df620e0000 pid=3682->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4bdce16f-1800-0000-a28d-80df620e0000 pid=3682->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=e8f8f46f-1800-0000-a28d-80df630e0000 pid=3683->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=7a76667c-1800-0000-a28d-80df700e0000 pid=3696->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=412c9d8d-1800-0000-a28d-80df980e0000 pid=3736 /tmp/WTF guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731->guuid=412c9d8d-1800-0000-a28d-80df980e0000 pid=3736 clone guuid=fff4a28d-1800-0000-a28d-80df990e0000 pid=3737 /tmp/WTF guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731->guuid=fff4a28d-1800-0000-a28d-80df990e0000 pid=3737 clone guuid=6023ab8d-1800-0000-a28d-80df9a0e0000 pid=3738 /tmp/WTF net send-data zombie guuid=db7db48c-1800-0000-a28d-80df930e0000 pid=3731->guuid=6023ab8d-1800-0000-a28d-80df9a0e0000 pid=3738 clone guuid=6023ab8d-1800-0000-a28d-80df9a0e0000 pid=3738->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6023ab8d-1800-0000-a28d-80df9a0e0000 pid=3738->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=72f9bb8d-1800-0000-a28d-80df9b0e0000 pid=3739->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=004f0c9b-1800-0000-a28d-80dfbb0e0000 pid=3771->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6468f4ea-1800-0000-a28d-80df640f0000 pid=3940 /tmp/WTF guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939->guuid=6468f4ea-1800-0000-a28d-80df640f0000 pid=3940 clone guuid=fd56feea-1800-0000-a28d-80df650f0000 pid=3941 /tmp/WTF guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939->guuid=fd56feea-1800-0000-a28d-80df650f0000 pid=3941 clone guuid=980507eb-1800-0000-a28d-80df660f0000 pid=3942 /tmp/WTF net send-data zombie guuid=fd0fe7e9-1800-0000-a28d-80df630f0000 pid=3939->guuid=980507eb-1800-0000-a28d-80df660f0000 pid=3942 clone guuid=980507eb-1800-0000-a28d-80df660f0000 pid=3942->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=980507eb-1800-0000-a28d-80df660f0000 pid=3942->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=47a21beb-1800-0000-a28d-80df670f0000 pid=3943->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 152B guuid=de382634-1900-0000-a28d-80df0f100000 pid=4111->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 101B guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3ee68542-1900-0000-a28d-80df43100000 pid=4163 /tmp/WTF guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159->guuid=3ee68542-1900-0000-a28d-80df43100000 pid=4163 clone guuid=77708b42-1900-0000-a28d-80df44100000 pid=4164 /tmp/WTF guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159->guuid=77708b42-1900-0000-a28d-80df44100000 pid=4164 clone guuid=d1b29242-1900-0000-a28d-80df45100000 pid=4165 /tmp/WTF net send-data zombie guuid=c0e56741-1900-0000-a28d-80df3f100000 pid=4159->guuid=d1b29242-1900-0000-a28d-80df45100000 pid=4165 clone guuid=d1b29242-1900-0000-a28d-80df45100000 pid=4165->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d1b29242-1900-0000-a28d-80df45100000 pid=4165->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 12B guuid=8b17a742-1900-0000-a28d-80df46100000 pid=4166->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=b5723559-1900-0000-a28d-80df7f100000 pid=4223->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=44488775-1900-0000-a28d-80dfcc100000 pid=4300 /tmp/WTF guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295->guuid=44488775-1900-0000-a28d-80dfcc100000 pid=4300 clone guuid=2c4c8b75-1900-0000-a28d-80dfcd100000 pid=4301 /tmp/WTF guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295->guuid=2c4c8b75-1900-0000-a28d-80dfcd100000 pid=4301 clone guuid=82808f75-1900-0000-a28d-80dfce100000 pid=4302 /tmp/WTF net send-data zombie guuid=8c80ed74-1900-0000-a28d-80dfc7100000 pid=4295->guuid=82808f75-1900-0000-a28d-80dfce100000 pid=4302 clone guuid=82808f75-1900-0000-a28d-80dfce100000 pid=4302->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=82808f75-1900-0000-a28d-80dfce100000 pid=4302->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=70519875-1900-0000-a28d-80dfcf100000 pid=4303->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=d7a83192-1900-0000-a28d-80df27110000 pid=4391->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a4a514aa-1900-0000-a28d-80df7f110000 pid=4479 /tmp/WTF guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474->guuid=a4a514aa-1900-0000-a28d-80df7f110000 pid=4479 clone guuid=1b741eaa-1900-0000-a28d-80df80110000 pid=4480 /tmp/WTF guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474->guuid=1b741eaa-1900-0000-a28d-80df80110000 pid=4480 clone guuid=41fb23aa-1900-0000-a28d-80df81110000 pid=4481 /tmp/WTF net send-data zombie guuid=437318a9-1900-0000-a28d-80df7a110000 pid=4474->guuid=41fb23aa-1900-0000-a28d-80df81110000 pid=4481 clone guuid=41fb23aa-1900-0000-a28d-80df81110000 pid=4481->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=41fb23aa-1900-0000-a28d-80df81110000 pid=4481->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=1fcf54aa-1900-0000-a28d-80df82110000 pid=4482->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=a5dc0bb9-1900-0000-a28d-80dfb5110000 pid=4533->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=98ed46dc-1900-0000-a28d-80dfd4110000 pid=4564 /tmp/WTF guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562->guuid=98ed46dc-1900-0000-a28d-80dfd4110000 pid=4564 clone guuid=a90b52dc-1900-0000-a28d-80dfd5110000 pid=4565 /tmp/WTF guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562->guuid=a90b52dc-1900-0000-a28d-80dfd5110000 pid=4565 clone guuid=f1475adc-1900-0000-a28d-80dfd6110000 pid=4566 /tmp/WTF net send-data zombie guuid=4f2d24db-1900-0000-a28d-80dfd2110000 pid=4562->guuid=f1475adc-1900-0000-a28d-80dfd6110000 pid=4566 clone guuid=f1475adc-1900-0000-a28d-80dfd6110000 pid=4566->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1475adc-1900-0000-a28d-80dfd6110000 pid=4566->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=beb975dc-1900-0000-a28d-80dfd8110000 pid=4568->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=fb4456f3-1900-0000-a28d-80df11120000 pid=4625->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7a7d0610-1a00-0000-a28d-80df57120000 pid=4695 /tmp/WTF guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692->guuid=7a7d0610-1a00-0000-a28d-80df57120000 pid=4695 clone guuid=36d50e10-1a00-0000-a28d-80df58120000 pid=4696 /tmp/WTF guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692->guuid=36d50e10-1a00-0000-a28d-80df58120000 pid=4696 clone guuid=35c51510-1a00-0000-a28d-80df59120000 pid=4697 /tmp/WTF net send-data zombie guuid=dead1e0f-1a00-0000-a28d-80df54120000 pid=4692->guuid=35c51510-1a00-0000-a28d-80df59120000 pid=4697 clone guuid=35c51510-1a00-0000-a28d-80df59120000 pid=4697->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=35c51510-1a00-0000-a28d-80df59120000 pid=4697->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=4e4b3f10-1a00-0000-a28d-80df5a120000 pid=4698->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=4af42227-1a00-0000-a28d-80dfa3120000 pid=4771->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62a03d3d-1a00-0000-a28d-80dfdf120000 pid=4831 /tmp/WTF guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828->guuid=62a03d3d-1a00-0000-a28d-80dfdf120000 pid=4831 clone guuid=063b483d-1a00-0000-a28d-80dfe1120000 pid=4833 /tmp/WTF guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828->guuid=063b483d-1a00-0000-a28d-80dfe1120000 pid=4833 clone guuid=01a04c3d-1a00-0000-a28d-80dfe2120000 pid=4834 /tmp/WTF net send-data zombie guuid=f4d7793c-1a00-0000-a28d-80dfdc120000 pid=4828->guuid=01a04c3d-1a00-0000-a28d-80dfe2120000 pid=4834 clone guuid=01a04c3d-1a00-0000-a28d-80dfe2120000 pid=4834->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=01a04c3d-1a00-0000-a28d-80dfe2120000 pid=4834->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 12B guuid=a91f583d-1a00-0000-a28d-80dfe3120000 pid=4835->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=58695753-1a00-0000-a28d-80df18130000 pid=4888->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=29053e6d-1a00-0000-a28d-80df56130000 pid=4950 /tmp/WTF guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946->guuid=29053e6d-1a00-0000-a28d-80df56130000 pid=4950 clone guuid=0c7d446d-1a00-0000-a28d-80df57130000 pid=4951 /tmp/WTF guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946->guuid=0c7d446d-1a00-0000-a28d-80df57130000 pid=4951 clone guuid=d7aa496d-1a00-0000-a28d-80df58130000 pid=4952 /tmp/WTF net send-data zombie guuid=dff8296c-1a00-0000-a28d-80df52130000 pid=4946->guuid=d7aa496d-1a00-0000-a28d-80df58130000 pid=4952 clone guuid=d7aa496d-1a00-0000-a28d-80df58130000 pid=4952->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d7aa496d-1a00-0000-a28d-80df58130000 pid=4952->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=cbb05b6d-1a00-0000-a28d-80df59130000 pid=4953->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=d625a17d-1a00-0000-a28d-80df7e130000 pid=4990->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2eac6b8b-1a00-0000-a28d-80dfa5130000 pid=5029 /tmp/WTF guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026->guuid=2eac6b8b-1a00-0000-a28d-80dfa5130000 pid=5029 clone guuid=0f8e718b-1a00-0000-a28d-80dfa6130000 pid=5030 /tmp/WTF guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026->guuid=0f8e718b-1a00-0000-a28d-80dfa6130000 pid=5030 clone guuid=4d7f778b-1a00-0000-a28d-80dfa7130000 pid=5031 /tmp/WTF net send-data zombie guuid=d79cab8a-1a00-0000-a28d-80dfa2130000 pid=5026->guuid=4d7f778b-1a00-0000-a28d-80dfa7130000 pid=5031 clone guuid=4d7f778b-1a00-0000-a28d-80dfa7130000 pid=5031->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d7f778b-1a00-0000-a28d-80dfa7130000 pid=5031->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=540a838b-1a00-0000-a28d-80dfa8130000 pid=5032->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 150B guuid=e817cda4-1a00-0000-a28d-80dfde130000 pid=5086->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 99B guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f5af07c2-1a00-0000-a28d-80df4f140000 pid=5199 /tmp/WTF guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196->guuid=f5af07c2-1a00-0000-a28d-80df4f140000 pid=5199 clone guuid=753f0bc2-1a00-0000-a28d-80df50140000 pid=5200 /tmp/WTF guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196->guuid=753f0bc2-1a00-0000-a28d-80df50140000 pid=5200 clone guuid=70f810c2-1a00-0000-a28d-80df51140000 pid=5201 /tmp/WTF net send-data zombie guuid=e97b55c1-1a00-0000-a28d-80df4c140000 pid=5196->guuid=70f810c2-1a00-0000-a28d-80df51140000 pid=5201 clone guuid=70f810c2-1a00-0000-a28d-80df51140000 pid=5201->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70f810c2-1a00-0000-a28d-80df51140000 pid=5201->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B guuid=9b3140c2-1a00-0000-a28d-80df52140000 pid=5202->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 149B guuid=82f893d9-1a00-0000-a28d-80df8a140000 pid=5258->41abd0c0-c36d-5d43-9c6a-01ff76e22160 send: 98B guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dd22d0f6-1a00-0000-a28d-80dfd2140000 pid=5330 /tmp/WTF guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329->guuid=dd22d0f6-1a00-0000-a28d-80dfd2140000 pid=5330 clone guuid=8600d7f6-1a00-0000-a28d-80dfd3140000 pid=5331 /tmp/WTF guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329->guuid=8600d7f6-1a00-0000-a28d-80dfd3140000 pid=5331 clone guuid=42d3def6-1a00-0000-a28d-80dfd4140000 pid=5332 /tmp/WTF net send-data zombie guuid=ae14d3f5-1a00-0000-a28d-80dfd1140000 pid=5329->guuid=42d3def6-1a00-0000-a28d-80dfd4140000 pid=5332 clone guuid=42d3def6-1a00-0000-a28d-80dfd4140000 pid=5332->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=42d3def6-1a00-0000-a28d-80dfd4140000 pid=5332->3689577d-053d-55fe-8eb3-83de1ecc9462 send: 7B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-17 17:38:00 UTC
File Type:
Text (Shell)
AV detection:
18 of 24 (75.00%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:lzrd antivm botnet defense_evasion discovery linux upx
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
UPX packed file
Enumerates running processes
Writes file to system bin folder
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh f41e6de59989e2c6ed117b87578e0af3aaa5aaad2ef47a6e054f591b0c166d6d

(this sample)

  
Delivery method
Distributed via web download

Comments