MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0356f34fa8b7a5c81823a03d1b264a9c7dac9b117d1b504665a71527f12150c4. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 1 File information Comments

SHA256 hash: 0356f34fa8b7a5c81823a03d1b264a9c7dac9b117d1b504665a71527f12150c4
SHA3-384 hash: 5ec655cae6b27c223b7e3c43cbb60bc03d1b3901ac0fafe67fe474a7834f78f9b8188a0ec77cc97aafab5d8e64328f58
SHA1 hash: 72e653a3ad9c1efce29ae317e68bc900b6d3a445
MD5 hash: 2f6de899fa906903cbf5bcb17d929895
humanhash: nine-fourteen-comet-purple
File name:multi.sh
Download: download sample
Signature Mirai
File size:2'417 bytes
First seen:2025-09-24 17:29:24 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ScaYAnHk+n5kmTw0IkEpsIkKlPKe/ax4TqDn49qdcFMAjF6x4T9:ScaY+HkSkmTw0IkESIkYCe/ax4TqU9M4
TLSH T19141F7CF7922162A955F8E4BB3F194F87033C4D725918B24EECC38A9F3D8D5A7044A26
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/arm1c6ad7da3701f41af453d1701d5656e256a6dcf08023270b2926685b82a19d07 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget
http://45.125.66.56/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/x86001c9c983afed1489f2a681b2d4045ae6120ecca1640045068d68d443891168b Miraiddos DEU elf gafgyt geofenced mirai
http://45.125.66.56/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 MiraiDEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
43
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox evasive medusa mirai
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-24T15:42:00Z UTC
Last seen:
2025-09-24T15:42:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=78692c0e-1800-0000-786e-2b50d40c0000 pid=3284 /usr/bin/sudo guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291 /tmp/sample.bin guuid=78692c0e-1800-0000-786e-2b50d40c0000 pid=3284->guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291 execve guuid=f0114010-1800-0000-786e-2b50dc0c0000 pid=3292 /usr/bin/cp guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=f0114010-1800-0000-786e-2b50dc0c0000 pid=3292 execve guuid=bad2b615-1800-0000-786e-2b50e60c0000 pid=3302 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=bad2b615-1800-0000-786e-2b50e60c0000 pid=3302 execve guuid=48865522-1800-0000-786e-2b50ff0c0000 pid=3327 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=48865522-1800-0000-786e-2b50ff0c0000 pid=3327 execve guuid=ecb03e33-1800-0000-786e-2b501a0d0000 pid=3354 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ecb03e33-1800-0000-786e-2b501a0d0000 pid=3354 clone guuid=ef206233-1800-0000-786e-2b501b0d0000 pid=3355 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ef206233-1800-0000-786e-2b501b0d0000 pid=3355 execve guuid=ed5cf233-1800-0000-786e-2b501c0d0000 pid=3356 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ed5cf233-1800-0000-786e-2b501c0d0000 pid=3356 clone guuid=1d8f9a35-1800-0000-786e-2b50220d0000 pid=3362 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1d8f9a35-1800-0000-786e-2b50220d0000 pid=3362 execve guuid=4ff5db35-1800-0000-786e-2b50240d0000 pid=3364 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=4ff5db35-1800-0000-786e-2b50240d0000 pid=3364 execve guuid=1782b940-1800-0000-786e-2b50480d0000 pid=3400 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1782b940-1800-0000-786e-2b50480d0000 pid=3400 execve guuid=2713cc4d-1800-0000-786e-2b50750d0000 pid=3445 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=2713cc4d-1800-0000-786e-2b50750d0000 pid=3445 clone guuid=c8cddf4d-1800-0000-786e-2b50770d0000 pid=3447 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=c8cddf4d-1800-0000-786e-2b50770d0000 pid=3447 execve guuid=3d7d294e-1800-0000-786e-2b50790d0000 pid=3449 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=3d7d294e-1800-0000-786e-2b50790d0000 pid=3449 clone guuid=5687084f-1800-0000-786e-2b507e0d0000 pid=3454 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=5687084f-1800-0000-786e-2b507e0d0000 pid=3454 execve guuid=caaa5f4f-1800-0000-786e-2b50800d0000 pid=3456 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=caaa5f4f-1800-0000-786e-2b50800d0000 pid=3456 execve guuid=854c405c-1800-0000-786e-2b50a70d0000 pid=3495 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=854c405c-1800-0000-786e-2b50a70d0000 pid=3495 execve guuid=dda95468-1800-0000-786e-2b50c00d0000 pid=3520 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=dda95468-1800-0000-786e-2b50c00d0000 pid=3520 clone guuid=9fc5a768-1800-0000-786e-2b50c20d0000 pid=3522 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=9fc5a768-1800-0000-786e-2b50c20d0000 pid=3522 execve guuid=2b770169-1800-0000-786e-2b50c40d0000 pid=3524 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=2b770169-1800-0000-786e-2b50c40d0000 pid=3524 clone guuid=206ff76a-1800-0000-786e-2b50ca0d0000 pid=3530 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=206ff76a-1800-0000-786e-2b50ca0d0000 pid=3530 execve guuid=d6cb536b-1800-0000-786e-2b50cb0d0000 pid=3531 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d6cb536b-1800-0000-786e-2b50cb0d0000 pid=3531 execve guuid=f1fa9a74-1800-0000-786e-2b50db0d0000 pid=3547 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=f1fa9a74-1800-0000-786e-2b50db0d0000 pid=3547 execve guuid=1cbf6e81-1800-0000-786e-2b50f60d0000 pid=3574 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1cbf6e81-1800-0000-786e-2b50f60d0000 pid=3574 clone guuid=10858081-1800-0000-786e-2b50f70d0000 pid=3575 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=10858081-1800-0000-786e-2b50f70d0000 pid=3575 execve guuid=7f01bd81-1800-0000-786e-2b50f90d0000 pid=3577 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=7f01bd81-1800-0000-786e-2b50f90d0000 pid=3577 clone guuid=72374682-1800-0000-786e-2b50fd0d0000 pid=3581 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=72374682-1800-0000-786e-2b50fd0d0000 pid=3581 execve guuid=81acec89-1800-0000-786e-2b50040e0000 pid=3588 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=81acec89-1800-0000-786e-2b50040e0000 pid=3588 execve guuid=b5b72093-1800-0000-786e-2b50170e0000 pid=3607 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b5b72093-1800-0000-786e-2b50170e0000 pid=3607 execve guuid=49005aa0-1800-0000-786e-2b50320e0000 pid=3634 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=49005aa0-1800-0000-786e-2b50320e0000 pid=3634 clone guuid=974e75a0-1800-0000-786e-2b50330e0000 pid=3635 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=974e75a0-1800-0000-786e-2b50330e0000 pid=3635 execve guuid=44aedca0-1800-0000-786e-2b50350e0000 pid=3637 /tmp/i486 guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=44aedca0-1800-0000-786e-2b50350e0000 pid=3637 execve guuid=b2baf3a2-1800-0000-786e-2b503e0e0000 pid=3646 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b2baf3a2-1800-0000-786e-2b503e0e0000 pid=3646 execve guuid=f3534da3-1800-0000-786e-2b50410e0000 pid=3649 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=f3534da3-1800-0000-786e-2b50410e0000 pid=3649 execve guuid=9f128cac-1800-0000-786e-2b505d0e0000 pid=3677 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=9f128cac-1800-0000-786e-2b505d0e0000 pid=3677 execve guuid=c44702b7-1800-0000-786e-2b50780e0000 pid=3704 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=c44702b7-1800-0000-786e-2b50780e0000 pid=3704 clone guuid=ee0b18b7-1800-0000-786e-2b50790e0000 pid=3705 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ee0b18b7-1800-0000-786e-2b50790e0000 pid=3705 execve guuid=63507db7-1800-0000-786e-2b507b0e0000 pid=3707 /tmp/i686 guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=63507db7-1800-0000-786e-2b507b0e0000 pid=3707 execve guuid=edf115c4-1800-0000-786e-2b50b70e0000 pid=3767 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=edf115c4-1800-0000-786e-2b50b70e0000 pid=3767 execve guuid=0acb64c4-1800-0000-786e-2b50bc0e0000 pid=3772 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=0acb64c4-1800-0000-786e-2b50bc0e0000 pid=3772 execve guuid=c7c049cf-1800-0000-786e-2b50e60e0000 pid=3814 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=c7c049cf-1800-0000-786e-2b50e60e0000 pid=3814 execve guuid=b8002ef5-1800-0000-786e-2b50f30e0000 pid=3827 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b8002ef5-1800-0000-786e-2b50f30e0000 pid=3827 clone guuid=848945f5-1800-0000-786e-2b50f50e0000 pid=3829 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=848945f5-1800-0000-786e-2b50f50e0000 pid=3829 execve guuid=b19696f5-1800-0000-786e-2b50f70e0000 pid=3831 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b19696f5-1800-0000-786e-2b50f70e0000 pid=3831 clone guuid=b647cdf5-1800-0000-786e-2b50fb0e0000 pid=3835 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b647cdf5-1800-0000-786e-2b50fb0e0000 pid=3835 execve guuid=362812f6-1800-0000-786e-2b50fc0e0000 pid=3836 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=362812f6-1800-0000-786e-2b50fc0e0000 pid=3836 execve guuid=15fc1403-1900-0000-786e-2b502a0f0000 pid=3882 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=15fc1403-1900-0000-786e-2b502a0f0000 pid=3882 execve guuid=96151911-1900-0000-786e-2b50490f0000 pid=3913 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=96151911-1900-0000-786e-2b50490f0000 pid=3913 clone guuid=58033511-1900-0000-786e-2b504a0f0000 pid=3914 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=58033511-1900-0000-786e-2b504a0f0000 pid=3914 execve guuid=3b979411-1900-0000-786e-2b504e0f0000 pid=3918 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=3b979411-1900-0000-786e-2b504e0f0000 pid=3918 clone guuid=e431ef11-1900-0000-786e-2b50510f0000 pid=3921 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=e431ef11-1900-0000-786e-2b50510f0000 pid=3921 execve guuid=cdad4212-1900-0000-786e-2b50550f0000 pid=3925 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=cdad4212-1900-0000-786e-2b50550f0000 pid=3925 execve guuid=b959bb1f-1900-0000-786e-2b507d0f0000 pid=3965 /usr/bin/curl send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b959bb1f-1900-0000-786e-2b507d0f0000 pid=3965 execve guuid=d947d32d-1900-0000-786e-2b50840f0000 pid=3972 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d947d32d-1900-0000-786e-2b50840f0000 pid=3972 clone guuid=7632092e-1900-0000-786e-2b50850f0000 pid=3973 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=7632092e-1900-0000-786e-2b50850f0000 pid=3973 execve guuid=ca387f2e-1900-0000-786e-2b50860f0000 pid=3974 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ca387f2e-1900-0000-786e-2b50860f0000 pid=3974 clone guuid=29b5ef2e-1900-0000-786e-2b508c0f0000 pid=3980 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=29b5ef2e-1900-0000-786e-2b508c0f0000 pid=3980 execve guuid=8ce3822f-1900-0000-786e-2b508d0f0000 pid=3981 /usr/bin/wget send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=8ce3822f-1900-0000-786e-2b508d0f0000 pid=3981 execve guuid=4c20da3a-1900-0000-786e-2b50af0f0000 pid=4015 /usr/bin/curl send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=4c20da3a-1900-0000-786e-2b50af0f0000 pid=4015 execve guuid=ba633047-1900-0000-786e-2b50d40f0000 pid=4052 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=ba633047-1900-0000-786e-2b50d40f0000 pid=4052 clone guuid=1a347047-1900-0000-786e-2b50d60f0000 pid=4054 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1a347047-1900-0000-786e-2b50d60f0000 pid=4054 execve guuid=d4900a48-1900-0000-786e-2b50d80f0000 pid=4056 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d4900a48-1900-0000-786e-2b50d80f0000 pid=4056 clone guuid=846d4e48-1900-0000-786e-2b50dc0f0000 pid=4060 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=846d4e48-1900-0000-786e-2b50dc0f0000 pid=4060 execve guuid=3c1cad48-1900-0000-786e-2b50dd0f0000 pid=4061 /usr/bin/wget send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=3c1cad48-1900-0000-786e-2b50dd0f0000 pid=4061 execve guuid=9c4fbe53-1900-0000-786e-2b50fe0f0000 pid=4094 /usr/bin/curl send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=9c4fbe53-1900-0000-786e-2b50fe0f0000 pid=4094 execve guuid=5932df5f-1900-0000-786e-2b501f100000 pid=4127 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=5932df5f-1900-0000-786e-2b501f100000 pid=4127 clone guuid=21d20f60-1900-0000-786e-2b5021100000 pid=4129 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=21d20f60-1900-0000-786e-2b5021100000 pid=4129 execve guuid=f6eb6460-1900-0000-786e-2b5022100000 pid=4130 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=f6eb6460-1900-0000-786e-2b5022100000 pid=4130 clone guuid=274ade60-1900-0000-786e-2b5026100000 pid=4134 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=274ade60-1900-0000-786e-2b5026100000 pid=4134 execve guuid=01f4e363-1900-0000-786e-2b5032100000 pid=4146 /usr/bin/wget send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=01f4e363-1900-0000-786e-2b5032100000 pid=4146 execve guuid=6fc3336f-1900-0000-786e-2b505d100000 pid=4189 /usr/bin/curl send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=6fc3336f-1900-0000-786e-2b505d100000 pid=4189 execve guuid=143ee07a-1900-0000-786e-2b507d100000 pid=4221 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=143ee07a-1900-0000-786e-2b507d100000 pid=4221 clone guuid=d7d5fc7a-1900-0000-786e-2b507e100000 pid=4222 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d7d5fc7a-1900-0000-786e-2b507e100000 pid=4222 execve guuid=2f004e7b-1900-0000-786e-2b5080100000 pid=4224 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=2f004e7b-1900-0000-786e-2b5080100000 pid=4224 clone guuid=60ab817b-1900-0000-786e-2b5083100000 pid=4227 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=60ab817b-1900-0000-786e-2b5083100000 pid=4227 execve guuid=7494d57b-1900-0000-786e-2b5085100000 pid=4229 /usr/bin/wget send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=7494d57b-1900-0000-786e-2b5085100000 pid=4229 execve guuid=6a93f684-1900-0000-786e-2b509d100000 pid=4253 /usr/bin/curl send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=6a93f684-1900-0000-786e-2b509d100000 pid=4253 execve guuid=f19d3d8f-1900-0000-786e-2b50b1100000 pid=4273 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=f19d3d8f-1900-0000-786e-2b50b1100000 pid=4273 clone guuid=5c97628f-1900-0000-786e-2b50b3100000 pid=4275 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=5c97628f-1900-0000-786e-2b50b3100000 pid=4275 execve guuid=b666c18f-1900-0000-786e-2b50b4100000 pid=4276 /tmp/x86 guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=b666c18f-1900-0000-786e-2b50b4100000 pid=4276 execve guuid=1e0ae89c-1900-0000-786e-2b50f0100000 pid=4336 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1e0ae89c-1900-0000-786e-2b50f0100000 pid=4336 execve guuid=4e40319d-1900-0000-786e-2b50f1100000 pid=4337 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=4e40319d-1900-0000-786e-2b50f1100000 pid=4337 execve guuid=68391ea8-1900-0000-786e-2b50f6100000 pid=4342 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=68391ea8-1900-0000-786e-2b50f6100000 pid=4342 execve guuid=4580eeb4-1900-0000-786e-2b50ff100000 pid=4351 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=4580eeb4-1900-0000-786e-2b50ff100000 pid=4351 clone guuid=1f1517b5-1900-0000-786e-2b5000110000 pid=4352 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=1f1517b5-1900-0000-786e-2b5000110000 pid=4352 execve guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353 /tmp/x86_64 guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353 execve guuid=d81e2db7-1900-0000-786e-2b5008110000 pid=4360 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d81e2db7-1900-0000-786e-2b5008110000 pid=4360 execve guuid=c5dd71b8-1900-0000-786e-2b500b110000 pid=4363 /usr/bin/wget net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=c5dd71b8-1900-0000-786e-2b500b110000 pid=4363 execve guuid=8b3d3fc4-1900-0000-786e-2b500c110000 pid=4364 /usr/bin/curl net send-data write-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=8b3d3fc4-1900-0000-786e-2b500c110000 pid=4364 execve guuid=2c8d7fd2-1900-0000-786e-2b500d110000 pid=4365 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=2c8d7fd2-1900-0000-786e-2b500d110000 pid=4365 clone guuid=c83194d2-1900-0000-786e-2b500e110000 pid=4366 /usr/bin/chmod guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=c83194d2-1900-0000-786e-2b500e110000 pid=4366 execve guuid=d998dad2-1900-0000-786e-2b500f110000 pid=4367 /usr/bin/bash guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d998dad2-1900-0000-786e-2b500f110000 pid=4367 clone guuid=d0dc0bd3-1900-0000-786e-2b5012110000 pid=4370 /usr/bin/rm delete-file guuid=8054f00f-1800-0000-786e-2b50db0c0000 pid=3291->guuid=d0dc0bd3-1900-0000-786e-2b5012110000 pid=4370 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=bad2b615-1800-0000-786e-2b50e60c0000 pid=3302->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=48865522-1800-0000-786e-2b50ff0c0000 pid=3327->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=4ff5db35-1800-0000-786e-2b50240d0000 pid=3364->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=1782b940-1800-0000-786e-2b50480d0000 pid=3400->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=caaa5f4f-1800-0000-786e-2b50800d0000 pid=3456->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=854c405c-1800-0000-786e-2b50a70d0000 pid=3495->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=d6cb536b-1800-0000-786e-2b50cb0d0000 pid=3531->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=f1fa9a74-1800-0000-786e-2b50db0d0000 pid=3547->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=81acec89-1800-0000-786e-2b50040e0000 pid=3588->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=b5b72093-1800-0000-786e-2b50170e0000 pid=3607->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=6e29c2a1-1800-0000-786e-2b50380e0000 pid=3640 /tmp/i486 net zombie guuid=44aedca0-1800-0000-786e-2b50350e0000 pid=3637->guuid=6e29c2a1-1800-0000-786e-2b50380e0000 pid=3640 clone guuid=5d74cca1-1800-0000-786e-2b50390e0000 pid=3641 /tmp/i486 net zombie guuid=44aedca0-1800-0000-786e-2b50350e0000 pid=3637->guuid=5d74cca1-1800-0000-786e-2b50390e0000 pid=3641 clone guuid=bd3edea2-1800-0000-786e-2b503c0e0000 pid=3644 /tmp/i486 guuid=44aedca0-1800-0000-786e-2b50350e0000 pid=3637->guuid=bd3edea2-1800-0000-786e-2b503c0e0000 pid=3644 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=6e29c2a1-1800-0000-786e-2b50380e0000 pid=3640->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=5d74cca1-1800-0000-786e-2b50390e0000 pid=3641->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=0c0feea2-1800-0000-786e-2b503d0e0000 pid=3645 /tmp/i486 net send-data zombie guuid=bd3edea2-1800-0000-786e-2b503c0e0000 pid=3644->guuid=0c0feea2-1800-0000-786e-2b503d0e0000 pid=3645 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=0c0feea2-1800-0000-786e-2b503d0e0000 pid=3645->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b2c2ad8f-4321-5ca8-994b-072c20344629 31.59.120.38:1025 guuid=0c0feea2-1800-0000-786e-2b503d0e0000 pid=3645->b2c2ad8f-4321-5ca8-994b-072c20344629 send: 20B guuid=e2cec0a3-1800-0000-786e-2b50420e0000 pid=3650 /tmp/i486 guuid=0c0feea2-1800-0000-786e-2b503d0e0000 pid=3645->guuid=e2cec0a3-1800-0000-786e-2b50420e0000 pid=3650 clone guuid=f3534da3-1800-0000-786e-2b50410e0000 pid=3649->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=9f128cac-1800-0000-786e-2b505d0e0000 pid=3677->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=74e0f2bd-1800-0000-786e-2b50940e0000 pid=3732 /tmp/i686 net zombie guuid=63507db7-1800-0000-786e-2b507b0e0000 pid=3707->guuid=74e0f2bd-1800-0000-786e-2b50940e0000 pid=3732 clone guuid=8baef7bd-1800-0000-786e-2b50950e0000 pid=3733 /tmp/i686 net zombie guuid=63507db7-1800-0000-786e-2b507b0e0000 pid=3707->guuid=8baef7bd-1800-0000-786e-2b50950e0000 pid=3733 clone guuid=56b90ac4-1800-0000-786e-2b50b60e0000 pid=3766 /tmp/i686 guuid=63507db7-1800-0000-786e-2b507b0e0000 pid=3707->guuid=56b90ac4-1800-0000-786e-2b50b60e0000 pid=3766 clone guuid=74e0f2bd-1800-0000-786e-2b50940e0000 pid=3732->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=8baef7bd-1800-0000-786e-2b50950e0000 pid=3733->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=2a7924c4-1800-0000-786e-2b50b80e0000 pid=3768 /tmp/i686 net send-data write-file zombie guuid=56b90ac4-1800-0000-786e-2b50b60e0000 pid=3766->guuid=2a7924c4-1800-0000-786e-2b50b80e0000 pid=3768 clone guuid=2a7924c4-1800-0000-786e-2b50b80e0000 pid=3768->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ec24d88-10a2-533e-9815-5add425c4ddb 109.248.162.59:1025 guuid=2a7924c4-1800-0000-786e-2b50b80e0000 pid=3768->8ec24d88-10a2-533e-9815-5add425c4ddb send: 20B guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802 /tmp/i686 zombie guuid=2a7924c4-1800-0000-786e-2b50b80e0000 pid=3768->guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802 clone guuid=0acb64c4-1800-0000-786e-2b50bc0e0000 pid=3772->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=2dbbacf5-1800-0000-786e-2b50fa0e0000 pid=3834 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=2dbbacf5-1800-0000-786e-2b50fa0e0000 pid=3834 clone guuid=fa508401-1900-0000-786e-2b50250f0000 pid=3877 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=fa508401-1900-0000-786e-2b50250f0000 pid=3877 clone guuid=f3cc0305-1900-0000-786e-2b50330f0000 pid=3891 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=f3cc0305-1900-0000-786e-2b50330f0000 pid=3891 clone guuid=5b07ae0d-1900-0000-786e-2b503f0f0000 pid=3903 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=5b07ae0d-1900-0000-786e-2b503f0f0000 pid=3903 clone guuid=a6abb511-1900-0000-786e-2b50500f0000 pid=3920 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=a6abb511-1900-0000-786e-2b50500f0000 pid=3920 clone guuid=6c253112-1900-0000-786e-2b50540f0000 pid=3924 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=6c253112-1900-0000-786e-2b50540f0000 pid=3924 clone guuid=9a4d6b17-1900-0000-786e-2b50620f0000 pid=3938 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=9a4d6b17-1900-0000-786e-2b50620f0000 pid=3938 clone guuid=bfeeba1a-1900-0000-786e-2b506d0f0000 pid=3949 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=bfeeba1a-1900-0000-786e-2b506d0f0000 pid=3949 clone guuid=f914f81a-1900-0000-786e-2b506f0f0000 pid=3951 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=f914f81a-1900-0000-786e-2b506f0f0000 pid=3951 clone guuid=697d4d1f-1900-0000-786e-2b507b0f0000 pid=3963 /tmp/i686 net zombie guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=697d4d1f-1900-0000-786e-2b507b0f0000 pid=3963 clone guuid=c48ab02e-1900-0000-786e-2b50890f0000 pid=3977 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=c48ab02e-1900-0000-786e-2b50890f0000 pid=3977 clone guuid=92b3ee2f-1900-0000-786e-2b50900f0000 pid=3984 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=92b3ee2f-1900-0000-786e-2b50900f0000 pid=3984 clone guuid=5b1cff33-1900-0000-786e-2b509b0f0000 pid=3995 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=5b1cff33-1900-0000-786e-2b509b0f0000 pid=3995 clone guuid=71cfc537-1900-0000-786e-2b50a60f0000 pid=4006 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=71cfc537-1900-0000-786e-2b50a60f0000 pid=4006 clone guuid=60ccd33b-1900-0000-786e-2b50b20f0000 pid=4018 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=60ccd33b-1900-0000-786e-2b50b20f0000 pid=4018 clone guuid=7dd2743f-1900-0000-786e-2b50bd0f0000 pid=4029 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=7dd2743f-1900-0000-786e-2b50bd0f0000 pid=4029 clone guuid=df582f48-1900-0000-786e-2b50da0f0000 pid=4058 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=df582f48-1900-0000-786e-2b50da0f0000 pid=4058 clone guuid=a2c0d64f-1900-0000-786e-2b50f20f0000 pid=4082 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=a2c0d64f-1900-0000-786e-2b50f20f0000 pid=4082 clone guuid=897cc75a-1900-0000-786e-2b5011100000 pid=4113 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=897cc75a-1900-0000-786e-2b5011100000 pid=4113 clone guuid=44b8e55e-1900-0000-786e-2b501d100000 pid=4125 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=44b8e55e-1900-0000-786e-2b501d100000 pid=4125 clone guuid=0707bc60-1900-0000-786e-2b5025100000 pid=4133 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=0707bc60-1900-0000-786e-2b5025100000 pid=4133 clone guuid=e392f662-1900-0000-786e-2b502f100000 pid=4143 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=e392f662-1900-0000-786e-2b502f100000 pid=4143 clone guuid=dfca2d67-1900-0000-786e-2b503e100000 pid=4158 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=dfca2d67-1900-0000-786e-2b503e100000 pid=4158 clone guuid=b85b8367-1900-0000-786e-2b5040100000 pid=4160 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=b85b8367-1900-0000-786e-2b5040100000 pid=4160 clone guuid=a3201b6d-1900-0000-786e-2b5053100000 pid=4179 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=a3201b6d-1900-0000-786e-2b5053100000 pid=4179 clone guuid=15d15f6d-1900-0000-786e-2b5055100000 pid=4181 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=15d15f6d-1900-0000-786e-2b5055100000 pid=4181 clone guuid=15a1687b-1900-0000-786e-2b5082100000 pid=4226 /tmp/i686 guuid=c623e4ca-1800-0000-786e-2b50da0e0000 pid=3802->guuid=15a1687b-1900-0000-786e-2b5082100000 pid=4226 clone guuid=c7c049cf-1800-0000-786e-2b50e60e0000 pid=3814->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=2dbbacf5-1800-0000-786e-2b50fa0e0000 pid=3834->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=362812f6-1800-0000-786e-2b50fc0e0000 pid=3836->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=fa508401-1900-0000-786e-2b50250f0000 pid=3877->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=15fc1403-1900-0000-786e-2b502a0f0000 pid=3882->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=f3cc0305-1900-0000-786e-2b50330f0000 pid=3891->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=5b07ae0d-1900-0000-786e-2b503f0f0000 pid=3903->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=a6abb511-1900-0000-786e-2b50500f0000 pid=3920->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=6c253112-1900-0000-786e-2b50540f0000 pid=3924->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=cdad4212-1900-0000-786e-2b50550f0000 pid=3925->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=9a4d6b17-1900-0000-786e-2b50620f0000 pid=3938->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=bfeeba1a-1900-0000-786e-2b506d0f0000 pid=3949->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=f914f81a-1900-0000-786e-2b506f0f0000 pid=3951->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=697d4d1f-1900-0000-786e-2b507b0f0000 pid=3963->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=b959bb1f-1900-0000-786e-2b507d0f0000 pid=3965->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=8ce3822f-1900-0000-786e-2b508d0f0000 pid=3981->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=4c20da3a-1900-0000-786e-2b50af0f0000 pid=4015->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=3c1cad48-1900-0000-786e-2b50dd0f0000 pid=4061->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=9c4fbe53-1900-0000-786e-2b50fe0f0000 pid=4094->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=01f4e363-1900-0000-786e-2b5032100000 pid=4146->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=6fc3336f-1900-0000-786e-2b505d100000 pid=4189->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=7494d57b-1900-0000-786e-2b5085100000 pid=4229->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=6a93f684-1900-0000-786e-2b509d100000 pid=4253->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=2b14a996-1900-0000-786e-2b50de100000 pid=4318 /tmp/x86 guuid=b666c18f-1900-0000-786e-2b50b4100000 pid=4276->guuid=2b14a996-1900-0000-786e-2b50de100000 pid=4318 clone guuid=8a83ae96-1900-0000-786e-2b50df100000 pid=4319 /tmp/x86 guuid=b666c18f-1900-0000-786e-2b50b4100000 pid=4276->guuid=8a83ae96-1900-0000-786e-2b50df100000 pid=4319 clone guuid=b04fc49c-1900-0000-786e-2b50ee100000 pid=4334 /tmp/x86 guuid=b666c18f-1900-0000-786e-2b50b4100000 pid=4276->guuid=b04fc49c-1900-0000-786e-2b50ee100000 pid=4334 clone guuid=e863d29c-1900-0000-786e-2b50ef100000 pid=4335 /tmp/x86 net send-data write-file zombie guuid=b04fc49c-1900-0000-786e-2b50ee100000 pid=4334->guuid=e863d29c-1900-0000-786e-2b50ef100000 pid=4335 clone guuid=e863d29c-1900-0000-786e-2b50ef100000 pid=4335->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 2b659683-be59-5022-8f04-927e151f5c7e 217.60.248.199:1025 guuid=e863d29c-1900-0000-786e-2b50ef100000 pid=4335->2b659683-be59-5022-8f04-927e151f5c7e send: 19B guuid=d0c661a3-1900-0000-786e-2b50f5100000 pid=4341 /tmp/x86 guuid=e863d29c-1900-0000-786e-2b50ef100000 pid=4335->guuid=d0c661a3-1900-0000-786e-2b50f5100000 pid=4341 clone guuid=4e40319d-1900-0000-786e-2b50f1100000 pid=4337->28318de2-8d63-5b31-be23-c532c58983b9 send: 133B guuid=68391ea8-1900-0000-786e-2b50f6100000 pid=4342->28318de2-8d63-5b31-be23-c532c58983b9 send: 82B guuid=708cedb5-1900-0000-786e-2b5002110000 pid=4354 /tmp/x86_64 net zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=708cedb5-1900-0000-786e-2b5002110000 pid=4354 clone guuid=63e2f3b5-1900-0000-786e-2b5003110000 pid=4355 /tmp/x86_64 net zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=63e2f3b5-1900-0000-786e-2b5003110000 pid=4355 clone guuid=148f09b6-1900-0000-786e-2b5004110000 pid=4356 /tmp/x86_64 net zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=148f09b6-1900-0000-786e-2b5004110000 pid=4356 clone guuid=263a10b6-1900-0000-786e-2b5005110000 pid=4357 /tmp/x86_64 net zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=263a10b6-1900-0000-786e-2b5005110000 pid=4357 clone guuid=e7b241b6-1900-0000-786e-2b5006110000 pid=4358 /tmp/x86_64 net zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=e7b241b6-1900-0000-786e-2b5006110000 pid=4358 clone guuid=894422b7-1900-0000-786e-2b5007110000 pid=4359 /tmp/x86_64 zombie guuid=80465bb5-1900-0000-786e-2b5001110000 pid=4353->guuid=894422b7-1900-0000-786e-2b5007110000 pid=4359 clone guuid=708cedb5-1900-0000-786e-2b5002110000 pid=4354->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=63e2f3b5-1900-0000-786e-2b5003110000 pid=4355->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=148f09b6-1900-0000-786e-2b5004110000 pid=4356->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=263a10b6-1900-0000-786e-2b5005110000 pid=4357->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=e7b241b6-1900-0000-786e-2b5006110000 pid=4358->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361 /tmp/x86_64 net send-data zombie guuid=894422b7-1900-0000-786e-2b5007110000 pid=4359->guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361 clone guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->b2c2ad8f-4321-5ca8-994b-072c20344629 send: 44B e9010b07-def5-5d53-bd9f-ed886898ca33 103.136.69.242:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->e9010b07-def5-5d53-bd9f-ed886898ca33 con c6203332-51f0-5ada-b496-18efd14e4d3d 217.60.249.53:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->c6203332-51f0-5ada-b496-18efd14e4d3d send: 22B db96774e-46a5-59dd-83b1-9c87ef6aad62 104.252.127.190:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->db96774e-46a5-59dd-83b1-9c87ef6aad62 send: 22B b3f9ddf4-8780-52e1-b41d-9c4a140190dd 196.251.83.20:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->b3f9ddf4-8780-52e1-b41d-9c4a140190dd con ea494a48-4f87-555b-a374-5bcf7d498d0d 51.83.147.130:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->ea494a48-4f87-555b-a374-5bcf7d498d0d send: 24B 7a699bac-7ed8-550c-a36b-104362f36479 31.58.51.213:1025 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->7a699bac-7ed8-550c-a36b-104362f36479 send: 22B guuid=132adbb7-1900-0000-786e-2b500a110000 pid=4362 /tmp/x86_64 guuid=6dbe41b7-1900-0000-786e-2b5009110000 pid=4361->guuid=132adbb7-1900-0000-786e-2b500a110000 pid=4362 clone guuid=5508f0d2-1900-0000-786e-2b5011110000 pid=4369 /tmp/x86_64 guuid=132adbb7-1900-0000-786e-2b500a110000 pid=4362->guuid=5508f0d2-1900-0000-786e-2b5011110000 pid=4369 clone guuid=c5dd71b8-1900-0000-786e-2b500b110000 pid=4363->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=8b3d3fc4-1900-0000-786e-2b500c110000 pid=4364->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-24 17:11:53 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 0356f34fa8b7a5c81823a03d1b264a9c7dac9b117d1b504665a71527f12150c4

(this sample)

  
Delivery method
Distributed via web download

Comments