MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 00deb6f187ddc703fe9b5af57088608b767fab46414e87c896ddbd3162562870. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 00deb6f187ddc703fe9b5af57088608b767fab46414e87c896ddbd3162562870
SHA3-384 hash: 1fbb3da41a55fadd36726c8c03d2de42a38ceb32f3cf5721d19496f3f789e214d9c745dc648bd36f33ae6e53a636be93
SHA1 hash: b20badbf36fdf0067e3f9019eb33943aa285e84c
MD5 hash: e9a95f447e8194b9f53daadbdef2153f
humanhash: april-tango-one-papa
File name:1.sh
Download: download sample
Signature Mirai
File size:2'789 bytes
First seen:2025-07-18 00:41:56 UTC
Last seen:2025-07-18 13:29:15 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ircw80rEyElZrOsrNR0rycyntdrEnE2UrJc1JMhrJXJ11krJIJeLrJ9JRvmr21i2:ircwRrEyElZrOsrNerlMdrEnE2UrJc1z
TLSH T1745164C84FC305B26C75AE3BB56A47842E99D8A379D4AE2794EC3CEA504DE053061D63
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.77.188/HBTs/top1miku.i58663d867a35531716d2e18314fbe4d2b0ffc3cc4bbb56d61a49ad1a42220746dac Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mips6dba5a43486ad2c883f236754e25806a860f5063fcf73e225f4f86c1c1741ead Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.arc380cdfff39fab66e0d2f0e3217f0e2573374ebbde28f6a96343e2cb72c0ca944 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.i686b80576044beece1b4d384a03a1cf722b0859177e554946eb0a6b0c96ae98d92d Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.x86_645c03e74290ffbc6332f3d357d54853000ea53f19ee0fa3fb36d466989c48826f Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mipseld1fab6b2f50e0ff23b55efacb28d56953902bd7bf276d1bbb0e8b8008cdbb7e6 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv4l861077a289df2f605a07e5054d37a41cc087751a1347d57c0c5977d91197e7b3 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv5le32f0af161e9dc5d213b9dc2d291da8dda9e836b9478d13a773a051a27075b89 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv6l6541c73c5c61b39d318d6e8e2c84a512824d846e03dce12a05ce5749315e10d7 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv7l21fde295094321e113cc7fe87fb3dc1230c4f602a21ea1919997e9289d683194 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.powerpcf9619daee99e761f7ef1df5c67a70f966af51d6f5c603bd3cf09a68f7f00b26f Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.powerpc-440fp050fb23f00a9e0583cc357a453959ec9f7d6e5268b285caec9476eef5b25c618 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.m68kaf5ef5773b4f244557be125fa269d59bfa897f6ad5ddbbd600a224a7fe38fdb8 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.sh4200f50c4e8e10d7cd12823b2ff9dcc4fd4643094ee0cb1bbd321a636af1acdc4 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox
Status:
terminated
Behavior Graph:
%3 guuid=b8d941fe-1900-0000-f8c6-78456d0d0000 pid=3437 /usr/bin/sudo guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444 /tmp/sample.bin guuid=b8d941fe-1900-0000-f8c6-78456d0d0000 pid=3437->guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444 execve guuid=f1966800-1a00-0000-f8c6-7845760d0000 pid=3446 /usr/bin/cp guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=f1966800-1a00-0000-f8c6-7845760d0000 pid=3446 execve guuid=f0c42b05-1a00-0000-f8c6-7845850d0000 pid=3461 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=f0c42b05-1a00-0000-f8c6-7845850d0000 pid=3461 execve guuid=43c2280f-1a00-0000-f8c6-7845a00d0000 pid=3488 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=43c2280f-1a00-0000-f8c6-7845a00d0000 pid=3488 execve guuid=cfa14621-1a00-0000-f8c6-7845ae0d0000 pid=3502 /usr/bin/cat guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=cfa14621-1a00-0000-f8c6-7845ae0d0000 pid=3502 execve guuid=675cb821-1a00-0000-f8c6-7845af0d0000 pid=3503 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=675cb821-1a00-0000-f8c6-7845af0d0000 pid=3503 execve guuid=78a31322-1a00-0000-f8c6-7845b00d0000 pid=3504 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=78a31322-1a00-0000-f8c6-7845b00d0000 pid=3504 execve guuid=7559cb22-1a00-0000-f8c6-7845b30d0000 pid=3507 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=7559cb22-1a00-0000-f8c6-7845b30d0000 pid=3507 execve guuid=feb9b626-1a00-0000-f8c6-7845bb0d0000 pid=3515 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=feb9b626-1a00-0000-f8c6-7845bb0d0000 pid=3515 execve guuid=fe853732-1a00-0000-f8c6-7845d10d0000 pid=3537 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=fe853732-1a00-0000-f8c6-7845d10d0000 pid=3537 clone guuid=05446832-1a00-0000-f8c6-7845d20d0000 pid=3538 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=05446832-1a00-0000-f8c6-7845d20d0000 pid=3538 execve guuid=e8aece32-1a00-0000-f8c6-7845d30d0000 pid=3539 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=e8aece32-1a00-0000-f8c6-7845d30d0000 pid=3539 execve guuid=47c30633-1a00-0000-f8c6-7845d60d0000 pid=3542 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=47c30633-1a00-0000-f8c6-7845d60d0000 pid=3542 execve guuid=530bd83b-1a00-0000-f8c6-7845f60d0000 pid=3574 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=530bd83b-1a00-0000-f8c6-7845f60d0000 pid=3574 execve guuid=5a410947-1a00-0000-f8c6-7845190e0000 pid=3609 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=5a410947-1a00-0000-f8c6-7845190e0000 pid=3609 clone guuid=04ed2e47-1a00-0000-f8c6-78451a0e0000 pid=3610 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=04ed2e47-1a00-0000-f8c6-78451a0e0000 pid=3610 execve guuid=a2448c47-1a00-0000-f8c6-78451c0e0000 pid=3612 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=a2448c47-1a00-0000-f8c6-78451c0e0000 pid=3612 execve guuid=1f77eb47-1a00-0000-f8c6-78451f0e0000 pid=3615 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=1f77eb47-1a00-0000-f8c6-78451f0e0000 pid=3615 execve guuid=775af850-1a00-0000-f8c6-78452e0e0000 pid=3630 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=775af850-1a00-0000-f8c6-78452e0e0000 pid=3630 execve guuid=a85d0356-1a00-0000-f8c6-78453c0e0000 pid=3644 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=a85d0356-1a00-0000-f8c6-78453c0e0000 pid=3644 clone guuid=c3673a56-1a00-0000-f8c6-78453d0e0000 pid=3645 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=c3673a56-1a00-0000-f8c6-78453d0e0000 pid=3645 execve guuid=d23b8556-1a00-0000-f8c6-78453e0e0000 pid=3646 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=d23b8556-1a00-0000-f8c6-78453e0e0000 pid=3646 execve guuid=a278ae56-1a00-0000-f8c6-7845410e0000 pid=3649 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=a278ae56-1a00-0000-f8c6-7845410e0000 pid=3649 execve guuid=472df75a-1a00-0000-f8c6-7845440e0000 pid=3652 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=472df75a-1a00-0000-f8c6-7845440e0000 pid=3652 execve guuid=b592da61-1a00-0000-f8c6-78455a0e0000 pid=3674 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=b592da61-1a00-0000-f8c6-78455a0e0000 pid=3674 clone guuid=4ea80462-1a00-0000-f8c6-78455b0e0000 pid=3675 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=4ea80462-1a00-0000-f8c6-78455b0e0000 pid=3675 execve guuid=d82e5f62-1a00-0000-f8c6-78455f0e0000 pid=3679 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=d82e5f62-1a00-0000-f8c6-78455f0e0000 pid=3679 execve guuid=60969e62-1a00-0000-f8c6-7845610e0000 pid=3681 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=60969e62-1a00-0000-f8c6-7845610e0000 pid=3681 execve guuid=5c2c7966-1a00-0000-f8c6-7845710e0000 pid=3697 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=5c2c7966-1a00-0000-f8c6-7845710e0000 pid=3697 execve guuid=233f576f-1a00-0000-f8c6-78457d0e0000 pid=3709 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=233f576f-1a00-0000-f8c6-78457d0e0000 pid=3709 clone guuid=04e8a36f-1a00-0000-f8c6-78457e0e0000 pid=3710 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=04e8a36f-1a00-0000-f8c6-78457e0e0000 pid=3710 execve guuid=018ad770-1a00-0000-f8c6-78457f0e0000 pid=3711 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=018ad770-1a00-0000-f8c6-78457f0e0000 pid=3711 execve guuid=ca1fa471-1a00-0000-f8c6-7845810e0000 pid=3713 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=ca1fa471-1a00-0000-f8c6-7845810e0000 pid=3713 execve guuid=2e9a2277-1a00-0000-f8c6-7845980e0000 pid=3736 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=2e9a2277-1a00-0000-f8c6-7845980e0000 pid=3736 execve guuid=3d5f3f85-1a00-0000-f8c6-7845ab0e0000 pid=3755 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=3d5f3f85-1a00-0000-f8c6-7845ab0e0000 pid=3755 clone guuid=bd036185-1a00-0000-f8c6-7845ac0e0000 pid=3756 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=bd036185-1a00-0000-f8c6-7845ac0e0000 pid=3756 execve guuid=bcdca585-1a00-0000-f8c6-7845ad0e0000 pid=3757 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=bcdca585-1a00-0000-f8c6-7845ad0e0000 pid=3757 execve guuid=080fcc85-1a00-0000-f8c6-7845af0e0000 pid=3759 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=080fcc85-1a00-0000-f8c6-7845af0e0000 pid=3759 execve guuid=696dab89-1a00-0000-f8c6-7845c20e0000 pid=3778 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=696dab89-1a00-0000-f8c6-7845c20e0000 pid=3778 execve guuid=857eb795-1a00-0000-f8c6-7845f50e0000 pid=3829 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=857eb795-1a00-0000-f8c6-7845f50e0000 pid=3829 clone guuid=4af7cf95-1a00-0000-f8c6-7845f60e0000 pid=3830 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=4af7cf95-1a00-0000-f8c6-7845f60e0000 pid=3830 execve guuid=06d64296-1a00-0000-f8c6-7845f90e0000 pid=3833 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=06d64296-1a00-0000-f8c6-7845f90e0000 pid=3833 execve guuid=91506c96-1a00-0000-f8c6-7845fb0e0000 pid=3835 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=91506c96-1a00-0000-f8c6-7845fb0e0000 pid=3835 execve guuid=6ef8119a-1a00-0000-f8c6-78450d0f0000 pid=3853 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=6ef8119a-1a00-0000-f8c6-78450d0f0000 pid=3853 execve guuid=d331fa9f-1a00-0000-f8c6-78452b0f0000 pid=3883 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=d331fa9f-1a00-0000-f8c6-78452b0f0000 pid=3883 clone guuid=08d119a0-1a00-0000-f8c6-78452d0f0000 pid=3885 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=08d119a0-1a00-0000-f8c6-78452d0f0000 pid=3885 execve guuid=e8a283a0-1a00-0000-f8c6-7845300f0000 pid=3888 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=e8a283a0-1a00-0000-f8c6-7845300f0000 pid=3888 execve guuid=c05fb9a0-1a00-0000-f8c6-7845330f0000 pid=3891 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=c05fb9a0-1a00-0000-f8c6-7845330f0000 pid=3891 execve guuid=0b0dbea9-1a00-0000-f8c6-78454c0f0000 pid=3916 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=0b0dbea9-1a00-0000-f8c6-78454c0f0000 pid=3916 execve guuid=76b7f3b1-1a00-0000-f8c6-7845620f0000 pid=3938 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=76b7f3b1-1a00-0000-f8c6-7845620f0000 pid=3938 clone guuid=ed6a25b2-1a00-0000-f8c6-7845660f0000 pid=3942 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=ed6a25b2-1a00-0000-f8c6-7845660f0000 pid=3942 execve guuid=21533bb3-1a00-0000-f8c6-78456b0f0000 pid=3947 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=21533bb3-1a00-0000-f8c6-78456b0f0000 pid=3947 execve guuid=c2ac1ab4-1a00-0000-f8c6-7845700f0000 pid=3952 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=c2ac1ab4-1a00-0000-f8c6-7845700f0000 pid=3952 execve guuid=34a4d0b7-1a00-0000-f8c6-7845850f0000 pid=3973 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=34a4d0b7-1a00-0000-f8c6-7845850f0000 pid=3973 execve guuid=fdac76bd-1a00-0000-f8c6-7845a10f0000 pid=4001 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=fdac76bd-1a00-0000-f8c6-7845a10f0000 pid=4001 clone guuid=745797bd-1a00-0000-f8c6-7845a20f0000 pid=4002 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=745797bd-1a00-0000-f8c6-7845a20f0000 pid=4002 execve guuid=2f85f1bd-1a00-0000-f8c6-7845a40f0000 pid=4004 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=2f85f1bd-1a00-0000-f8c6-7845a40f0000 pid=4004 execve guuid=697e46be-1a00-0000-f8c6-7845a80f0000 pid=4008 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=697e46be-1a00-0000-f8c6-7845a80f0000 pid=4008 execve guuid=0e51c3cc-1a00-0000-f8c6-7845de0f0000 pid=4062 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=0e51c3cc-1a00-0000-f8c6-7845de0f0000 pid=4062 execve guuid=6e9104da-1a00-0000-f8c6-7845f00f0000 pid=4080 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=6e9104da-1a00-0000-f8c6-7845f00f0000 pid=4080 clone guuid=d78b35da-1a00-0000-f8c6-7845f40f0000 pid=4084 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=d78b35da-1a00-0000-f8c6-7845f40f0000 pid=4084 execve guuid=11bf8ada-1a00-0000-f8c6-7845f50f0000 pid=4085 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=11bf8ada-1a00-0000-f8c6-7845f50f0000 pid=4085 execve guuid=2eb2cbda-1a00-0000-f8c6-7845f80f0000 pid=4088 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=2eb2cbda-1a00-0000-f8c6-7845f80f0000 pid=4088 execve guuid=9c9431df-1a00-0000-f8c6-784504100000 pid=4100 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=9c9431df-1a00-0000-f8c6-784504100000 pid=4100 execve guuid=a8567ae6-1a00-0000-f8c6-784524100000 pid=4132 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=a8567ae6-1a00-0000-f8c6-784524100000 pid=4132 clone guuid=2f66c1e6-1a00-0000-f8c6-784526100000 pid=4134 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=2f66c1e6-1a00-0000-f8c6-784526100000 pid=4134 execve guuid=04d702e7-1a00-0000-f8c6-784528100000 pid=4136 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=04d702e7-1a00-0000-f8c6-784528100000 pid=4136 execve guuid=e85727e7-1a00-0000-f8c6-78452a100000 pid=4138 /usr/bin/wget net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=e85727e7-1a00-0000-f8c6-78452a100000 pid=4138 execve guuid=eddf66f0-1a00-0000-f8c6-784555100000 pid=4181 /usr/bin/curl net send-data write-file guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=eddf66f0-1a00-0000-f8c6-784555100000 pid=4181 execve guuid=2d2769f6-1a00-0000-f8c6-78456e100000 pid=4206 /usr/bin/bash guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=2d2769f6-1a00-0000-f8c6-78456e100000 pid=4206 clone guuid=1e7c37f7-1a00-0000-f8c6-784573100000 pid=4211 /usr/bin/chmod guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=1e7c37f7-1a00-0000-f8c6-784573100000 pid=4211 execve guuid=6b2e17f9-1a00-0000-f8c6-78457b100000 pid=4219 /tmp/HBTs net guuid=683ff1ff-1900-0000-f8c6-7845740d0000 pid=3444->guuid=6b2e17f9-1a00-0000-f8c6-78457b100000 pid=4219 execve 7a155949-225c-5534-9d46-ce85bc851092 161.97.77.188:80 guuid=f0c42b05-1a00-0000-f8c6-7845850d0000 pid=3461->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=43c2280f-1a00-0000-f8c6-7845a00d0000 pid=3488->7a155949-225c-5534-9d46-ce85bc851092 send: 95B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=78a31322-1a00-0000-f8c6-7845b00d0000 pid=3504->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8a9db922-1a00-0000-f8c6-7845b20d0000 pid=3506 /tmp/HBTs guuid=78a31322-1a00-0000-f8c6-7845b00d0000 pid=3504->guuid=8a9db922-1a00-0000-f8c6-7845b20d0000 pid=3506 clone guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508 /tmp/HBTs write-config zombie guuid=8a9db922-1a00-0000-f8c6-7845b20d0000 pid=3506->guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508 clone guuid=7559cb22-1a00-0000-f8c6-7845b30d0000 pid=3507->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=cabec126-1a00-0000-f8c6-7845bc0d0000 pid=3516 /usr/bin/dash guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508->guuid=cabec126-1a00-0000-f8c6-7845bc0d0000 pid=3516 execve guuid=6cbeb229-1a00-0000-f8c6-7845bf0d0000 pid=3519 /tmp/HBTs delete-file guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508->guuid=6cbeb229-1a00-0000-f8c6-7845bf0d0000 pid=3519 clone guuid=2a228acb-1d00-0000-f8c6-7845fa140000 pid=5370 /tmp/HBTs dns net send-data guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508->guuid=2a228acb-1d00-0000-f8c6-7845fa140000 pid=5370 clone guuid=5e71ad74-2200-0000-f8c6-78452d150000 pid=5421 /tmp/HBTs dns net send-data guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508->guuid=5e71ad74-2200-0000-f8c6-78452d150000 pid=5421 clone guuid=746a233a-2600-0000-f8c6-784539150000 pid=5433 /tmp/HBTs dns net send-data guuid=5f33d522-1a00-0000-f8c6-7845b40d0000 pid=3508->guuid=746a233a-2600-0000-f8c6-784539150000 pid=5433 clone guuid=feb9b626-1a00-0000-f8c6-7845bb0d0000 pid=3515->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=522a0227-1a00-0000-f8c6-7845bd0d0000 pid=3517 /usr/bin/cp guuid=cabec126-1a00-0000-f8c6-7845bc0d0000 pid=3516->guuid=522a0227-1a00-0000-f8c6-7845bd0d0000 pid=3517 execve guuid=e8aece32-1a00-0000-f8c6-7845d30d0000 pid=3539->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=79effa32-1a00-0000-f8c6-7845d40d0000 pid=3540 /tmp/HBTs guuid=e8aece32-1a00-0000-f8c6-7845d30d0000 pid=3539->guuid=79effa32-1a00-0000-f8c6-7845d40d0000 pid=3540 clone guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541 /tmp/HBTs write-config zombie guuid=79effa32-1a00-0000-f8c6-7845d40d0000 pid=3540->guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541 clone guuid=297c8636-1a00-0000-f8c6-7845e00d0000 pid=3552 /usr/bin/dash guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541->guuid=297c8636-1a00-0000-f8c6-7845e00d0000 pid=3552 execve guuid=3c05f338-1a00-0000-f8c6-7845ea0d0000 pid=3562 /tmp/HBTs dns net send-data guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541->guuid=3c05f338-1a00-0000-f8c6-7845ea0d0000 pid=3562 clone guuid=ca7d3f55-1f00-0000-f8c6-784524150000 pid=5412 /tmp/HBTs dns net send-data guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541->guuid=ca7d3f55-1f00-0000-f8c6-784524150000 pid=5412 clone guuid=c7691b0f-2400-0000-f8c6-784533150000 pid=5427 /tmp/HBTs guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541->guuid=c7691b0f-2400-0000-f8c6-784533150000 pid=5427 clone guuid=9cc2fa9b-2700-0000-f8c6-78453f150000 pid=5439 /tmp/HBTs guuid=daa00533-1a00-0000-f8c6-7845d50d0000 pid=3541->guuid=9cc2fa9b-2700-0000-f8c6-78453f150000 pid=5439 clone guuid=47c30633-1a00-0000-f8c6-7845d60d0000 pid=3542->7a155949-225c-5534-9d46-ce85bc851092 send: 145B guuid=326db736-1a00-0000-f8c6-7845e20d0000 pid=3554 /usr/bin/cp guuid=297c8636-1a00-0000-f8c6-7845e00d0000 pid=3552->guuid=326db736-1a00-0000-f8c6-7845e20d0000 pid=3554 execve guuid=3c05f338-1a00-0000-f8c6-7845ea0d0000 pid=3562->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=3c05f338-1a00-0000-f8c6-7845ea0d0000 pid=3562->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=530bd83b-1a00-0000-f8c6-7845f60d0000 pid=3574->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=a2448c47-1a00-0000-f8c6-78451c0e0000 pid=3612->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3debd747-1a00-0000-f8c6-78451d0e0000 pid=3613 /tmp/HBTs guuid=a2448c47-1a00-0000-f8c6-78451c0e0000 pid=3612->guuid=3debd747-1a00-0000-f8c6-78451d0e0000 pid=3613 clone guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614 /tmp/HBTs write-config zombie guuid=3debd747-1a00-0000-f8c6-78451d0e0000 pid=3613->guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614 clone guuid=1d099b4b-1a00-0000-f8c6-7845200e0000 pid=3616 /usr/bin/dash guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614->guuid=1d099b4b-1a00-0000-f8c6-7845200e0000 pid=3616 execve guuid=ae0eee4d-1a00-0000-f8c6-7845260e0000 pid=3622 /tmp/HBTs delete-file guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614->guuid=ae0eee4d-1a00-0000-f8c6-7845260e0000 pid=3622 clone guuid=5522f4f2-1d00-0000-f8c6-7845fb140000 pid=5371 /tmp/HBTs guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614->guuid=5522f4f2-1d00-0000-f8c6-7845fb140000 pid=5371 clone guuid=078a2fa2-2100-0000-f8c6-784528150000 pid=5416 /tmp/HBTs dns net send-data guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614->guuid=078a2fa2-2100-0000-f8c6-784528150000 pid=5416 clone guuid=16d2b870-2500-0000-f8c6-784535150000 pid=5429 /tmp/HBTs guuid=ca2de247-1a00-0000-f8c6-78451e0e0000 pid=3614->guuid=16d2b870-2500-0000-f8c6-784535150000 pid=5429 clone guuid=1f77eb47-1a00-0000-f8c6-78451f0e0000 pid=3615->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=9dafcb4b-1a00-0000-f8c6-7845210e0000 pid=3617 /usr/bin/cp guuid=1d099b4b-1a00-0000-f8c6-7845200e0000 pid=3616->guuid=9dafcb4b-1a00-0000-f8c6-7845210e0000 pid=3617 execve guuid=775af850-1a00-0000-f8c6-78452e0e0000 pid=3630->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=d23b8556-1a00-0000-f8c6-78453e0e0000 pid=3646->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=247ba356-1a00-0000-f8c6-78453f0e0000 pid=3647 /tmp/HBTs guuid=d23b8556-1a00-0000-f8c6-78453e0e0000 pid=3646->guuid=247ba356-1a00-0000-f8c6-78453f0e0000 pid=3647 clone guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648 /tmp/HBTs write-config zombie guuid=247ba356-1a00-0000-f8c6-78453f0e0000 pid=3647->guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648 clone guuid=1ba1ed59-1a00-0000-f8c6-7845420e0000 pid=3650 /usr/bin/dash guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648->guuid=1ba1ed59-1a00-0000-f8c6-7845420e0000 pid=3650 execve guuid=fbc60f5d-1a00-0000-f8c6-7845450e0000 pid=3653 /tmp/HBTs delete-file dns net send-data guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648->guuid=fbc60f5d-1a00-0000-f8c6-7845450e0000 pid=3653 clone guuid=b48bc9f9-1f00-0000-f8c6-784526150000 pid=5414 /tmp/HBTs dns net send-data guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648->guuid=b48bc9f9-1f00-0000-f8c6-784526150000 pid=5414 clone guuid=830f62ea-2400-0000-f8c6-784534150000 pid=5428 /tmp/HBTs net send-data guuid=f276ad56-1a00-0000-f8c6-7845400e0000 pid=3648->guuid=830f62ea-2400-0000-f8c6-784534150000 pid=5428 clone guuid=a278ae56-1a00-0000-f8c6-7845410e0000 pid=3649->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=89ad465a-1a00-0000-f8c6-7845430e0000 pid=3651 /usr/bin/cp guuid=1ba1ed59-1a00-0000-f8c6-7845420e0000 pid=3650->guuid=89ad465a-1a00-0000-f8c6-7845430e0000 pid=3651 execve guuid=472df75a-1a00-0000-f8c6-7845440e0000 pid=3652->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=fbc60f5d-1a00-0000-f8c6-7845450e0000 pid=3653->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=fbc60f5d-1a00-0000-f8c6-7845450e0000 pid=3653->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=d82e5f62-1a00-0000-f8c6-78455f0e0000 pid=3679->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cb059262-1a00-0000-f8c6-7845600e0000 pid=3680 /tmp/HBTs guuid=d82e5f62-1a00-0000-f8c6-78455f0e0000 pid=3679->guuid=cb059262-1a00-0000-f8c6-7845600e0000 pid=3680 clone guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685 /tmp/HBTs write-config zombie guuid=cb059262-1a00-0000-f8c6-7845600e0000 pid=3680->guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685 clone guuid=60969e62-1a00-0000-f8c6-7845610e0000 pid=3681->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=39e6c668-1a00-0000-f8c6-7845760e0000 pid=3702 /usr/bin/dash guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685->guuid=39e6c668-1a00-0000-f8c6-7845760e0000 pid=3702 execve guuid=9077d475-1a00-0000-f8c6-78458f0e0000 pid=3727 /tmp/HBTs delete-file guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685->guuid=9077d475-1a00-0000-f8c6-78458f0e0000 pid=3727 clone guuid=9fc39d11-1e00-0000-f8c6-7845fc140000 pid=5372 /tmp/HBTs dns net send-data guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685->guuid=9fc39d11-1e00-0000-f8c6-7845fc140000 pid=5372 clone guuid=1c23e2e4-2200-0000-f8c6-78452f150000 pid=5423 /tmp/HBTs dns net send-data guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685->guuid=1c23e2e4-2200-0000-f8c6-78452f150000 pid=5423 clone guuid=e10b4681-2700-0000-f8c6-78453e150000 pid=5438 /tmp/HBTs guuid=46575f63-1a00-0000-f8c6-7845650e0000 pid=3685->guuid=e10b4681-2700-0000-f8c6-78453e150000 pid=5438 clone guuid=5c2c7966-1a00-0000-f8c6-7845710e0000 pid=3697->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=219b6d6a-1a00-0000-f8c6-78457c0e0000 pid=3708 /usr/bin/cp guuid=39e6c668-1a00-0000-f8c6-7845760e0000 pid=3702->guuid=219b6d6a-1a00-0000-f8c6-78457c0e0000 pid=3708 execve guuid=018ad770-1a00-0000-f8c6-78457f0e0000 pid=3711->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=162f9571-1a00-0000-f8c6-7845800e0000 pid=3712 /tmp/HBTs guuid=018ad770-1a00-0000-f8c6-78457f0e0000 pid=3711->guuid=162f9571-1a00-0000-f8c6-7845800e0000 pid=3712 clone guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715 /tmp/HBTs write-config zombie guuid=162f9571-1a00-0000-f8c6-7845800e0000 pid=3712->guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715 clone guuid=ca1fa471-1a00-0000-f8c6-7845810e0000 pid=3713->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=5339ee75-1a00-0000-f8c6-7845900e0000 pid=3728 /usr/bin/dash guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715->guuid=5339ee75-1a00-0000-f8c6-7845900e0000 pid=3728 execve guuid=82272c7f-1a00-0000-f8c6-7845990e0000 pid=3737 /tmp/HBTs delete-file dns net send-data guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715->guuid=82272c7f-1a00-0000-f8c6-7845990e0000 pid=3737 clone guuid=1b68eb5c-2100-0000-f8c6-784527150000 pid=5415 /tmp/HBTs dns net send-data guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715->guuid=1b68eb5c-2100-0000-f8c6-784527150000 pid=5415 clone guuid=47906200-2600-0000-f8c6-784538150000 pid=5432 /tmp/HBTs dns net send-data guuid=3e9ff971-1a00-0000-f8c6-7845830e0000 pid=3715->guuid=47906200-2600-0000-f8c6-784538150000 pid=5432 clone guuid=69772476-1a00-0000-f8c6-7845910e0000 pid=3729 /usr/bin/cp guuid=5339ee75-1a00-0000-f8c6-7845900e0000 pid=3728->guuid=69772476-1a00-0000-f8c6-7845910e0000 pid=3729 execve guuid=2e9a2277-1a00-0000-f8c6-7845980e0000 pid=3736->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=82272c7f-1a00-0000-f8c6-7845990e0000 pid=3737->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=82272c7f-1a00-0000-f8c6-7845990e0000 pid=3737->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=bcdca585-1a00-0000-f8c6-7845ad0e0000 pid=3757->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1d5cc485-1a00-0000-f8c6-7845ae0e0000 pid=3758 /tmp/HBTs guuid=bcdca585-1a00-0000-f8c6-7845ad0e0000 pid=3757->guuid=1d5cc485-1a00-0000-f8c6-7845ae0e0000 pid=3758 clone guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762 /tmp/HBTs write-config zombie guuid=1d5cc485-1a00-0000-f8c6-7845ae0e0000 pid=3758->guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762 clone guuid=080fcc85-1a00-0000-f8c6-7845af0e0000 pid=3759->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=89b33f8d-1a00-0000-f8c6-7845d70e0000 pid=3799 /usr/bin/dash guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762->guuid=89b33f8d-1a00-0000-f8c6-7845d70e0000 pid=3799 execve guuid=04eaff92-1a00-0000-f8c6-7845ec0e0000 pid=3820 /tmp/HBTs delete-file guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762->guuid=04eaff92-1a00-0000-f8c6-7845ec0e0000 pid=3820 clone guuid=a7ac0236-1e00-0000-f8c6-784503150000 pid=5379 /tmp/HBTs guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762->guuid=a7ac0236-1e00-0000-f8c6-784503150000 pid=5379 clone guuid=29b132e5-2100-0000-f8c6-784529150000 pid=5417 /tmp/HBTs dns net send-data guuid=77d33b86-1a00-0000-f8c6-7845b20e0000 pid=3762->guuid=29b132e5-2100-0000-f8c6-784529150000 pid=5417 clone guuid=696dab89-1a00-0000-f8c6-7845c20e0000 pid=3778->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=c097ce8d-1a00-0000-f8c6-7845dc0e0000 pid=3804 /usr/bin/cp guuid=89b33f8d-1a00-0000-f8c6-7845d70e0000 pid=3799->guuid=c097ce8d-1a00-0000-f8c6-7845dc0e0000 pid=3804 execve guuid=06d64296-1a00-0000-f8c6-7845f90e0000 pid=3833->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=df456396-1a00-0000-f8c6-7845fa0e0000 pid=3834 /tmp/HBTs guuid=06d64296-1a00-0000-f8c6-7845f90e0000 pid=3833->guuid=df456396-1a00-0000-f8c6-7845fa0e0000 pid=3834 clone guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837 /tmp/HBTs write-config zombie guuid=df456396-1a00-0000-f8c6-7845fa0e0000 pid=3834->guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837 clone guuid=91506c96-1a00-0000-f8c6-7845fb0e0000 pid=3835->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=8fafac9a-1a00-0000-f8c6-78450f0f0000 pid=3855 /usr/bin/dash guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837->guuid=8fafac9a-1a00-0000-f8c6-78450f0f0000 pid=3855 execve guuid=c017399e-1a00-0000-f8c6-78451f0f0000 pid=3871 /tmp/HBTs delete-file dns net send-data guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837->guuid=c017399e-1a00-0000-f8c6-78451f0f0000 pid=3871 clone guuid=bd3febe5-1e00-0000-f8c6-784523150000 pid=5411 /tmp/HBTs dns net send-data guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837->guuid=bd3febe5-1e00-0000-f8c6-784523150000 pid=5411 clone guuid=3af02388-2300-0000-f8c6-784532150000 pid=5426 /tmp/HBTs dns net send-data guuid=a6f67896-1a00-0000-f8c6-7845fd0e0000 pid=3837->guuid=3af02388-2300-0000-f8c6-784532150000 pid=5426 clone guuid=6ef8119a-1a00-0000-f8c6-78450d0f0000 pid=3853->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=a0232b9b-1a00-0000-f8c6-7845120f0000 pid=3858 /usr/bin/cp guuid=8fafac9a-1a00-0000-f8c6-78450f0f0000 pid=3855->guuid=a0232b9b-1a00-0000-f8c6-7845120f0000 pid=3858 execve guuid=c017399e-1a00-0000-f8c6-78451f0f0000 pid=3871->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=c017399e-1a00-0000-f8c6-78451f0f0000 pid=3871->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=e8a283a0-1a00-0000-f8c6-7845300f0000 pid=3888->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1697ada0-1a00-0000-f8c6-7845310f0000 pid=3889 /tmp/HBTs guuid=e8a283a0-1a00-0000-f8c6-7845300f0000 pid=3888->guuid=1697ada0-1a00-0000-f8c6-7845310f0000 pid=3889 clone guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893 /tmp/HBTs write-config zombie guuid=1697ada0-1a00-0000-f8c6-7845310f0000 pid=3889->guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893 clone guuid=c05fb9a0-1a00-0000-f8c6-7845330f0000 pid=3891->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=1ca236a7-1a00-0000-f8c6-7845410f0000 pid=3905 /usr/bin/dash guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893->guuid=1ca236a7-1a00-0000-f8c6-7845410f0000 pid=3905 execve guuid=1c524aab-1a00-0000-f8c6-78454d0f0000 pid=3917 /tmp/HBTs delete-file guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893->guuid=1c524aab-1a00-0000-f8c6-78454d0f0000 pid=3917 clone guuid=925bca5a-1e00-0000-f8c6-78450d150000 pid=5389 /tmp/HBTs guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893->guuid=925bca5a-1e00-0000-f8c6-78450d150000 pid=5389 clone guuid=808790f3-2100-0000-f8c6-78452a150000 pid=5418 /tmp/HBTs guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893->guuid=808790f3-2100-0000-f8c6-78452a150000 pid=5418 clone guuid=5ee64c81-2500-0000-f8c6-784536150000 pid=5430 /tmp/HBTs dns net send-data guuid=de70cca0-1a00-0000-f8c6-7845350f0000 pid=3893->guuid=5ee64c81-2500-0000-f8c6-784536150000 pid=5430 clone guuid=47aea6a7-1a00-0000-f8c6-7845430f0000 pid=3907 /usr/bin/cp guuid=1ca236a7-1a00-0000-f8c6-7845410f0000 pid=3905->guuid=47aea6a7-1a00-0000-f8c6-7845430f0000 pid=3907 execve guuid=0b0dbea9-1a00-0000-f8c6-78454c0f0000 pid=3916->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=21533bb3-1a00-0000-f8c6-78456b0f0000 pid=3947->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3dc410b4-1a00-0000-f8c6-78456f0f0000 pid=3951 /tmp/HBTs guuid=21533bb3-1a00-0000-f8c6-78456b0f0000 pid=3947->guuid=3dc410b4-1a00-0000-f8c6-78456f0f0000 pid=3951 clone guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954 /tmp/HBTs write-config zombie guuid=3dc410b4-1a00-0000-f8c6-78456f0f0000 pid=3951->guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954 clone guuid=c2ac1ab4-1a00-0000-f8c6-7845700f0000 pid=3952->7a155949-225c-5534-9d46-ce85bc851092 send: 149B guuid=d742f8b8-1a00-0000-f8c6-78458a0f0000 pid=3978 /usr/bin/dash guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954->guuid=d742f8b8-1a00-0000-f8c6-78458a0f0000 pid=3978 execve guuid=0d8e2abc-1a00-0000-f8c6-78459c0f0000 pid=3996 /tmp/HBTs delete-file dns net send-data guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954->guuid=0d8e2abc-1a00-0000-f8c6-78459c0f0000 pid=3996 clone guuid=b40a626f-1f00-0000-f8c6-784525150000 pid=5413 /tmp/HBTs guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954->guuid=b40a626f-1f00-0000-f8c6-784525150000 pid=5413 clone guuid=398585fd-2200-0000-f8c6-784530150000 pid=5424 /tmp/HBTs guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954->guuid=398585fd-2200-0000-f8c6-784530150000 pid=5424 clone guuid=d1de318e-2600-0000-f8c6-78453b150000 pid=5435 /tmp/HBTs guuid=77e540b4-1a00-0000-f8c6-7845720f0000 pid=3954->guuid=d1de318e-2600-0000-f8c6-78453b150000 pid=5435 clone guuid=34a4d0b7-1a00-0000-f8c6-7845850f0000 pid=3973->7a155949-225c-5534-9d46-ce85bc851092 send: 98B guuid=18bc25b9-1a00-0000-f8c6-78458b0f0000 pid=3979 /usr/bin/cp guuid=d742f8b8-1a00-0000-f8c6-78458a0f0000 pid=3978->guuid=18bc25b9-1a00-0000-f8c6-78458b0f0000 pid=3979 execve guuid=0d8e2abc-1a00-0000-f8c6-78459c0f0000 pid=3996->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=0d8e2abc-1a00-0000-f8c6-78459c0f0000 pid=3996->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=2f85f1bd-1a00-0000-f8c6-7845a40f0000 pid=4004->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d4d30be-1a00-0000-f8c6-7845a60f0000 pid=4006 /tmp/HBTs guuid=2f85f1bd-1a00-0000-f8c6-7845a40f0000 pid=4004->guuid=4d4d30be-1a00-0000-f8c6-7845a60f0000 pid=4006 clone guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013 /tmp/HBTs write-config zombie guuid=4d4d30be-1a00-0000-f8c6-7845a60f0000 pid=4006->guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013 clone guuid=697e46be-1a00-0000-f8c6-7845a80f0000 pid=4008->7a155949-225c-5534-9d46-ce85bc851092 send: 155B guuid=3342c2c4-1a00-0000-f8c6-7845bf0f0000 pid=4031 /usr/bin/dash guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013->guuid=3342c2c4-1a00-0000-f8c6-7845bf0f0000 pid=4031 execve guuid=1379b9cb-1a00-0000-f8c6-7845d90f0000 pid=4057 /tmp/HBTs delete-file guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013->guuid=1379b9cb-1a00-0000-f8c6-7845d90f0000 pid=4057 clone guuid=60278861-1e00-0000-f8c6-78450f150000 pid=5391 /tmp/HBTs dns net send-data guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013->guuid=60278861-1e00-0000-f8c6-78450f150000 pid=5391 clone guuid=9d1b8cac-2200-0000-f8c6-78452e150000 pid=5422 /tmp/HBTs dns net send-data guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013->guuid=9d1b8cac-2200-0000-f8c6-78452e150000 pid=5422 clone guuid=559003f9-2600-0000-f8c6-78453c150000 pid=5436 /tmp/HBTs guuid=b779e0bf-1a00-0000-f8c6-7845ad0f0000 pid=4013->guuid=559003f9-2600-0000-f8c6-78453c150000 pid=5436 clone guuid=e20959c6-1a00-0000-f8c6-7845c80f0000 pid=4040 /usr/bin/cp guuid=3342c2c4-1a00-0000-f8c6-7845bf0f0000 pid=4031->guuid=e20959c6-1a00-0000-f8c6-7845c80f0000 pid=4040 execve guuid=0e51c3cc-1a00-0000-f8c6-7845de0f0000 pid=4062->7a155949-225c-5534-9d46-ce85bc851092 send: 104B guuid=11bf8ada-1a00-0000-f8c6-7845f50f0000 pid=4085->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=192cc3da-1a00-0000-f8c6-7845f70f0000 pid=4087 /tmp/HBTs guuid=11bf8ada-1a00-0000-f8c6-7845f50f0000 pid=4085->guuid=192cc3da-1a00-0000-f8c6-7845f70f0000 pid=4087 clone guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089 /tmp/HBTs write-config zombie guuid=192cc3da-1a00-0000-f8c6-7845f70f0000 pid=4087->guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089 clone guuid=2eb2cbda-1a00-0000-f8c6-7845f80f0000 pid=4088->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=f1af50df-1a00-0000-f8c6-784505100000 pid=4101 /usr/bin/dash guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089->guuid=f1af50df-1a00-0000-f8c6-784505100000 pid=4101 execve guuid=831512e3-1a00-0000-f8c6-784517100000 pid=4119 /tmp/HBTs delete-file guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089->guuid=831512e3-1a00-0000-f8c6-784517100000 pid=4119 clone guuid=94af4087-1e00-0000-f8c6-784520150000 pid=5408 /tmp/HBTs guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089->guuid=94af4087-1e00-0000-f8c6-784520150000 pid=5408 clone guuid=b5cbd724-2200-0000-f8c6-78452b150000 pid=5419 /tmp/HBTs guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089->guuid=b5cbd724-2200-0000-f8c6-78452b150000 pid=5419 clone guuid=a8cb6cc4-2500-0000-f8c6-784537150000 pid=5431 /tmp/HBTs dns net send-data guuid=ae7bd8da-1a00-0000-f8c6-7845f90f0000 pid=4089->guuid=a8cb6cc4-2500-0000-f8c6-784537150000 pid=5431 clone guuid=9c9431df-1a00-0000-f8c6-784504100000 pid=4100->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=b9f037e0-1a00-0000-f8c6-784509100000 pid=4105 /usr/bin/cp guuid=f1af50df-1a00-0000-f8c6-784505100000 pid=4101->guuid=b9f037e0-1a00-0000-f8c6-784509100000 pid=4105 execve guuid=04d702e7-1a00-0000-f8c6-784528100000 pid=4136->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7dbd1fe7-1a00-0000-f8c6-784529100000 pid=4137 /tmp/HBTs guuid=04d702e7-1a00-0000-f8c6-784528100000 pid=4136->guuid=7dbd1fe7-1a00-0000-f8c6-784529100000 pid=4137 clone guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142 /tmp/HBTs write-config zombie guuid=7dbd1fe7-1a00-0000-f8c6-784529100000 pid=4137->guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142 clone guuid=e85727e7-1a00-0000-f8c6-78452a100000 pid=4138->7a155949-225c-5534-9d46-ce85bc851092 send: 145B guuid=9a9697ec-1a00-0000-f8c6-784544100000 pid=4164 /usr/bin/dash guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142->guuid=9a9697ec-1a00-0000-f8c6-784544100000 pid=4164 execve guuid=5077fbef-1a00-0000-f8c6-784551100000 pid=4177 /tmp/HBTs delete-file guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142->guuid=5077fbef-1a00-0000-f8c6-784551100000 pid=4177 clone guuid=fe7d8395-1e00-0000-f8c6-784521150000 pid=5409 /tmp/HBTs dns net send-data guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142->guuid=fe7d8395-1e00-0000-f8c6-784521150000 pid=5409 clone guuid=8fabb66b-2300-0000-f8c6-784531150000 pid=5425 /tmp/HBTs dns net send-data guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142->guuid=8fabb66b-2300-0000-f8c6-784531150000 pid=5425 clone guuid=df177416-2700-0000-f8c6-78453d150000 pid=5437 /tmp/HBTs guuid=fecbeee7-1a00-0000-f8c6-78452e100000 pid=4142->guuid=df177416-2700-0000-f8c6-78453d150000 pid=5437 clone guuid=c7edcaec-1a00-0000-f8c6-784545100000 pid=4165 /usr/bin/cp guuid=9a9697ec-1a00-0000-f8c6-784544100000 pid=4164->guuid=c7edcaec-1a00-0000-f8c6-784545100000 pid=4165 execve guuid=eddf66f0-1a00-0000-f8c6-784555100000 pid=4181->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=6b2e17f9-1a00-0000-f8c6-78457b100000 pid=4219->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=79a7eff9-1a00-0000-f8c6-78457f100000 pid=4223 /tmp/HBTs guuid=6b2e17f9-1a00-0000-f8c6-78457b100000 pid=4219->guuid=79a7eff9-1a00-0000-f8c6-78457f100000 pid=4223 clone guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225 /tmp/HBTs write-config zombie guuid=79a7eff9-1a00-0000-f8c6-78457f100000 pid=4223->guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225 clone guuid=603a9efd-1a00-0000-f8c6-78458b100000 pid=4235 /usr/bin/dash guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225->guuid=603a9efd-1a00-0000-f8c6-78458b100000 pid=4235 execve guuid=532b7502-1b00-0000-f8c6-78459d100000 pid=4253 /tmp/HBTs guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225->guuid=532b7502-1b00-0000-f8c6-78459d100000 pid=4253 clone guuid=ea2acd9d-1e00-0000-f8c6-784522150000 pid=5410 /tmp/HBTs guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225->guuid=ea2acd9d-1e00-0000-f8c6-784522150000 pid=5410 clone guuid=e7a26936-2200-0000-f8c6-78452c150000 pid=5420 /tmp/HBTs dns net send-data guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225->guuid=e7a26936-2200-0000-f8c6-78452c150000 pid=5420 clone guuid=f2ff7972-2600-0000-f8c6-78453a150000 pid=5434 /tmp/HBTs dns net send-data guuid=c7e41ffa-1a00-0000-f8c6-784581100000 pid=4225->guuid=f2ff7972-2600-0000-f8c6-78453a150000 pid=5434 clone guuid=7d10a4fe-1a00-0000-f8c6-784590100000 pid=4240 /usr/bin/cp guuid=603a9efd-1a00-0000-f8c6-78458b100000 pid=4235->guuid=7d10a4fe-1a00-0000-f8c6-784590100000 pid=4240 execve guuid=2a228acb-1d00-0000-f8c6-7845fa140000 pid=5370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=2a228acb-1d00-0000-f8c6-7845fa140000 pid=5370->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=9fc39d11-1e00-0000-f8c6-7845fc140000 pid=5372->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=9fc39d11-1e00-0000-f8c6-7845fc140000 pid=5372->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=60278861-1e00-0000-f8c6-78450f150000 pid=5391->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=60278861-1e00-0000-f8c6-78450f150000 pid=5391->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=fe7d8395-1e00-0000-f8c6-784521150000 pid=5409->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=fe7d8395-1e00-0000-f8c6-784521150000 pid=5409->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=bd3febe5-1e00-0000-f8c6-784523150000 pid=5411->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=bd3febe5-1e00-0000-f8c6-784523150000 pid=5411->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=ca7d3f55-1f00-0000-f8c6-784524150000 pid=5412->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=ca7d3f55-1f00-0000-f8c6-784524150000 pid=5412->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=b48bc9f9-1f00-0000-f8c6-784526150000 pid=5414->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=b48bc9f9-1f00-0000-f8c6-784526150000 pid=5414->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=1b68eb5c-2100-0000-f8c6-784527150000 pid=5415->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=1b68eb5c-2100-0000-f8c6-784527150000 pid=5415->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=078a2fa2-2100-0000-f8c6-784528150000 pid=5416->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=078a2fa2-2100-0000-f8c6-784528150000 pid=5416->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=29b132e5-2100-0000-f8c6-784529150000 pid=5417->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=29b132e5-2100-0000-f8c6-784529150000 pid=5417->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=e7a26936-2200-0000-f8c6-78452c150000 pid=5420->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=e7a26936-2200-0000-f8c6-78452c150000 pid=5420->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=5e71ad74-2200-0000-f8c6-78452d150000 pid=5421->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=5e71ad74-2200-0000-f8c6-78452d150000 pid=5421->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=9d1b8cac-2200-0000-f8c6-78452e150000 pid=5422->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=9d1b8cac-2200-0000-f8c6-78452e150000 pid=5422->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=1c23e2e4-2200-0000-f8c6-78452f150000 pid=5423->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=1c23e2e4-2200-0000-f8c6-78452f150000 pid=5423->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=8fabb66b-2300-0000-f8c6-784531150000 pid=5425->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=8fabb66b-2300-0000-f8c6-784531150000 pid=5425->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=3af02388-2300-0000-f8c6-784532150000 pid=5426->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=3af02388-2300-0000-f8c6-784532150000 pid=5426->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=830f62ea-2400-0000-f8c6-784534150000 pid=5428->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=5ee64c81-2500-0000-f8c6-784536150000 pid=5430->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=5ee64c81-2500-0000-f8c6-784536150000 pid=5430->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=a8cb6cc4-2500-0000-f8c6-784537150000 pid=5431->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=a8cb6cc4-2500-0000-f8c6-784537150000 pid=5431->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=47906200-2600-0000-f8c6-784538150000 pid=5432->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=47906200-2600-0000-f8c6-784538150000 pid=5432->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=746a233a-2600-0000-f8c6-784539150000 pid=5433->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=746a233a-2600-0000-f8c6-784539150000 pid=5433->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=f2ff7972-2600-0000-f8c6-78453a150000 pid=5434->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=f2ff7972-2600-0000-f8c6-78453a150000 pid=5434->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-18 00:42:18 UTC
File Type:
Text (Shell)
AV detection:
17 of 24 (70.83%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
top1miku.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 00deb6f187ddc703fe9b5af57088608b767fab46414e87c896ddbd3162562870

(this sample)

  
Delivery method
Distributed via web download

Comments