MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09e7aefe2c812b2488c500ac4154b8cd8774e9b5cbb1ba670974a1adb7836849. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 11 File information Comments

SHA256 hash: 09e7aefe2c812b2488c500ac4154b8cd8774e9b5cbb1ba670974a1adb7836849
SHA3-384 hash: 13ed05f378b9adc49251f351f7d4cd6284d61208493032a5aec635fa17a5fde77c1cdd27d1d10b842d8835d3f5bc1d3d
SHA1 hash: a8fdb42ad19f5d3f22abdea2994902b9af5566ca
MD5 hash: a4de5f2763874c48586a3142dc1e4a52
humanhash: burger-maine-arizona-indigo
File name:getty
Download: download sample
Signature Mirai
File size:105'759 bytes
First seen:2025-07-15 06:39:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:tk68NdUVKR5H3OWNWXZ0SznNgpEmpFithVnrlTxgT:tkdVLd0Z0S5FmpFithVnrlTxgT
TLSH T18FA31942A745D673D14305F212A79B250532FEBB1E2A9E06F3697CF49F36184B221FAC
telfhash t185316621953546142fb2d928acfc56b30532272323556f71af25c5cc49260e1e93de4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Collects information on the OS
Receives data from a server
Kills processes
Collects information on the CPU
Runs as daemon
Sends data to a server
Connection attempt
Launching a process
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc lolbin obfuscated remote
Status:
terminated
Behavior Graph:
%3 guuid=1ec8b442-1800-0000-e66d-7ed244090000 pid=2372 /usr/bin/sudo guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378 /tmp/sample.bin net guuid=1ec8b442-1800-0000-e66d-7ed244090000 pid=2372->guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381 /tmp/sample.bin zombie guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378->guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381 clone guuid=920c3846-1800-0000-e66d-7ed24e090000 pid=2382 /tmp/sample.bin guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378->guuid=920c3846-1800-0000-e66d-7ed24e090000 pid=2382 clone guuid=916e3e46-1800-0000-e66d-7ed24f090000 pid=2383 /tmp/sample.bin guuid=a4234f45-1800-0000-e66d-7ed24a090000 pid=2378->guuid=916e3e46-1800-0000-e66d-7ed24f090000 pid=2383 clone guuid=aa12ce78-1800-0000-e66d-7ed2bd090000 pid=2493 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=aa12ce78-1800-0000-e66d-7ed2bd090000 pid=2493 execve guuid=1b804e7c-1800-0000-e66d-7ed2c7090000 pid=2503 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1b804e7c-1800-0000-e66d-7ed2c7090000 pid=2503 execve guuid=8bcb707d-1800-0000-e66d-7ed2cd090000 pid=2509 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=8bcb707d-1800-0000-e66d-7ed2cd090000 pid=2509 execve guuid=a011547e-1800-0000-e66d-7ed2d1090000 pid=2513 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=a011547e-1800-0000-e66d-7ed2d1090000 pid=2513 execve guuid=e943397f-1800-0000-e66d-7ed2d5090000 pid=2517 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e943397f-1800-0000-e66d-7ed2d5090000 pid=2517 execve guuid=950c5680-1800-0000-e66d-7ed2da090000 pid=2522 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=950c5680-1800-0000-e66d-7ed2da090000 pid=2522 execve guuid=9c214d81-1800-0000-e66d-7ed2de090000 pid=2526 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=9c214d81-1800-0000-e66d-7ed2de090000 pid=2526 execve guuid=726b2982-1800-0000-e66d-7ed2e3090000 pid=2531 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=726b2982-1800-0000-e66d-7ed2e3090000 pid=2531 execve guuid=64912283-1800-0000-e66d-7ed2e8090000 pid=2536 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=64912283-1800-0000-e66d-7ed2e8090000 pid=2536 execve guuid=80129fb0-1900-0000-e66d-7ed2c10c0000 pid=3265 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=80129fb0-1900-0000-e66d-7ed2c10c0000 pid=3265 execve guuid=b9c1ceb4-1900-0000-e66d-7ed2cc0c0000 pid=3276 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b9c1ceb4-1900-0000-e66d-7ed2cc0c0000 pid=3276 execve guuid=5949e4b5-1900-0000-e66d-7ed2d00c0000 pid=3280 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=5949e4b5-1900-0000-e66d-7ed2d00c0000 pid=3280 execve guuid=b9cccab6-1900-0000-e66d-7ed2d50c0000 pid=3285 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b9cccab6-1900-0000-e66d-7ed2d50c0000 pid=3285 execve guuid=fe37a5b7-1900-0000-e66d-7ed2da0c0000 pid=3290 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=fe37a5b7-1900-0000-e66d-7ed2da0c0000 pid=3290 execve guuid=333d95b8-1900-0000-e66d-7ed2dc0c0000 pid=3292 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=333d95b8-1900-0000-e66d-7ed2dc0c0000 pid=3292 execve guuid=d5efb2b9-1900-0000-e66d-7ed2e10c0000 pid=3297 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d5efb2b9-1900-0000-e66d-7ed2e10c0000 pid=3297 execve guuid=61f935bb-1900-0000-e66d-7ed2e90c0000 pid=3305 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=61f935bb-1900-0000-e66d-7ed2e90c0000 pid=3305 execve guuid=c07b21bc-1900-0000-e66d-7ed2ee0c0000 pid=3310 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=c07b21bc-1900-0000-e66d-7ed2ee0c0000 pid=3310 execve guuid=b6c655ea-1a00-0000-e66d-7ed2f30e0000 pid=3827 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b6c655ea-1a00-0000-e66d-7ed2f30e0000 pid=3827 execve guuid=78cc8fef-1a00-0000-e66d-7ed20a0f0000 pid=3850 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=78cc8fef-1a00-0000-e66d-7ed20a0f0000 pid=3850 execve guuid=98fb5df1-1a00-0000-e66d-7ed2130f0000 pid=3859 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=98fb5df1-1a00-0000-e66d-7ed2130f0000 pid=3859 execve guuid=db8768f3-1a00-0000-e66d-7ed21b0f0000 pid=3867 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=db8768f3-1a00-0000-e66d-7ed21b0f0000 pid=3867 execve guuid=e8c5cff4-1a00-0000-e66d-7ed2200f0000 pid=3872 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e8c5cff4-1a00-0000-e66d-7ed2200f0000 pid=3872 execve guuid=a2f4daf5-1a00-0000-e66d-7ed2250f0000 pid=3877 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=a2f4daf5-1a00-0000-e66d-7ed2250f0000 pid=3877 execve guuid=fa0e1df7-1a00-0000-e66d-7ed22a0f0000 pid=3882 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=fa0e1df7-1a00-0000-e66d-7ed22a0f0000 pid=3882 execve guuid=980d31f8-1a00-0000-e66d-7ed2310f0000 pid=3889 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=980d31f8-1a00-0000-e66d-7ed2310f0000 pid=3889 execve guuid=0e8b2af9-1a00-0000-e66d-7ed23a0f0000 pid=3898 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=0e8b2af9-1a00-0000-e66d-7ed23a0f0000 pid=3898 execve guuid=1e962a27-1c00-0000-e66d-7ed2bf120000 pid=4799 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1e962a27-1c00-0000-e66d-7ed2bf120000 pid=4799 execve guuid=d188962a-1c00-0000-e66d-7ed2d0120000 pid=4816 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d188962a-1c00-0000-e66d-7ed2d0120000 pid=4816 execve guuid=c46e6f2b-1c00-0000-e66d-7ed2d6120000 pid=4822 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=c46e6f2b-1c00-0000-e66d-7ed2d6120000 pid=4822 execve guuid=9f0b452c-1c00-0000-e66d-7ed2dc120000 pid=4828 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=9f0b452c-1c00-0000-e66d-7ed2dc120000 pid=4828 execve guuid=63ae222d-1c00-0000-e66d-7ed2e1120000 pid=4833 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=63ae222d-1c00-0000-e66d-7ed2e1120000 pid=4833 execve guuid=1836f72d-1c00-0000-e66d-7ed2e7120000 pid=4839 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1836f72d-1c00-0000-e66d-7ed2e7120000 pid=4839 execve guuid=816ad12e-1c00-0000-e66d-7ed2ed120000 pid=4845 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=816ad12e-1c00-0000-e66d-7ed2ed120000 pid=4845 execve guuid=fb31ab2f-1c00-0000-e66d-7ed2f2120000 pid=4850 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=fb31ab2f-1c00-0000-e66d-7ed2f2120000 pid=4850 execve guuid=1eb27930-1c00-0000-e66d-7ed2f8120000 pid=4856 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1eb27930-1c00-0000-e66d-7ed2f8120000 pid=4856 execve guuid=86d5866f-1d00-0000-e66d-7ed2ba140000 pid=5306 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=86d5866f-1d00-0000-e66d-7ed2ba140000 pid=5306 execve guuid=56f52174-1d00-0000-e66d-7ed2bd140000 pid=5309 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=56f52174-1d00-0000-e66d-7ed2bd140000 pid=5309 execve guuid=d9e98075-1d00-0000-e66d-7ed2bf140000 pid=5311 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d9e98075-1d00-0000-e66d-7ed2bf140000 pid=5311 execve guuid=12305176-1d00-0000-e66d-7ed2c1140000 pid=5313 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=12305176-1d00-0000-e66d-7ed2c1140000 pid=5313 execve guuid=5ae92177-1d00-0000-e66d-7ed2c3140000 pid=5315 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=5ae92177-1d00-0000-e66d-7ed2c3140000 pid=5315 execve guuid=a29cf277-1d00-0000-e66d-7ed2c5140000 pid=5317 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=a29cf277-1d00-0000-e66d-7ed2c5140000 pid=5317 execve guuid=118ec578-1d00-0000-e66d-7ed2c7140000 pid=5319 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=118ec578-1d00-0000-e66d-7ed2c7140000 pid=5319 execve guuid=99bd9379-1d00-0000-e66d-7ed2c9140000 pid=5321 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=99bd9379-1d00-0000-e66d-7ed2c9140000 pid=5321 execve guuid=3d37657a-1d00-0000-e66d-7ed2cb140000 pid=5323 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=3d37657a-1d00-0000-e66d-7ed2cb140000 pid=5323 execve guuid=4e560fa9-1e00-0000-e66d-7ed2d2140000 pid=5330 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=4e560fa9-1e00-0000-e66d-7ed2d2140000 pid=5330 execve guuid=389ba1ad-1e00-0000-e66d-7ed2d4140000 pid=5332 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=389ba1ad-1e00-0000-e66d-7ed2d4140000 pid=5332 execve guuid=ff553baf-1e00-0000-e66d-7ed2d6140000 pid=5334 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=ff553baf-1e00-0000-e66d-7ed2d6140000 pid=5334 execve guuid=68e5b7b0-1e00-0000-e66d-7ed2d8140000 pid=5336 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=68e5b7b0-1e00-0000-e66d-7ed2d8140000 pid=5336 execve guuid=e09e45b2-1e00-0000-e66d-7ed2da140000 pid=5338 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e09e45b2-1e00-0000-e66d-7ed2da140000 pid=5338 execve guuid=f2ffd8b3-1e00-0000-e66d-7ed2dc140000 pid=5340 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=f2ffd8b3-1e00-0000-e66d-7ed2dc140000 pid=5340 execve guuid=611f5db5-1e00-0000-e66d-7ed2de140000 pid=5342 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=611f5db5-1e00-0000-e66d-7ed2de140000 pid=5342 execve guuid=e99ec4b6-1e00-0000-e66d-7ed2e0140000 pid=5344 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e99ec4b6-1e00-0000-e66d-7ed2e0140000 pid=5344 execve guuid=3221abb7-1e00-0000-e66d-7ed2e2140000 pid=5346 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=3221abb7-1e00-0000-e66d-7ed2e2140000 pid=5346 execve guuid=ca8170e6-1f00-0000-e66d-7ed2e4140000 pid=5348 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=ca8170e6-1f00-0000-e66d-7ed2e4140000 pid=5348 execve guuid=902dd2ea-1f00-0000-e66d-7ed2e6140000 pid=5350 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=902dd2ea-1f00-0000-e66d-7ed2e6140000 pid=5350 execve guuid=d39c3bec-1f00-0000-e66d-7ed2e8140000 pid=5352 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d39c3bec-1f00-0000-e66d-7ed2e8140000 pid=5352 execve guuid=0c44a2ed-1f00-0000-e66d-7ed2ea140000 pid=5354 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=0c44a2ed-1f00-0000-e66d-7ed2ea140000 pid=5354 execve guuid=fdab03ef-1f00-0000-e66d-7ed2ec140000 pid=5356 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=fdab03ef-1f00-0000-e66d-7ed2ec140000 pid=5356 execve guuid=8a639cf0-1f00-0000-e66d-7ed2ee140000 pid=5358 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=8a639cf0-1f00-0000-e66d-7ed2ee140000 pid=5358 execve guuid=e4b139f2-1f00-0000-e66d-7ed2f0140000 pid=5360 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e4b139f2-1f00-0000-e66d-7ed2f0140000 pid=5360 execve guuid=985ad2f3-1f00-0000-e66d-7ed2f2140000 pid=5362 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=985ad2f3-1f00-0000-e66d-7ed2f2140000 pid=5362 execve guuid=0b0f42f5-1f00-0000-e66d-7ed2f4140000 pid=5364 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=0b0f42f5-1f00-0000-e66d-7ed2f4140000 pid=5364 execve guuid=cc8af724-2100-0000-e66d-7ed2f6140000 pid=5366 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=cc8af724-2100-0000-e66d-7ed2f6140000 pid=5366 execve guuid=acea3b28-2100-0000-e66d-7ed2f8140000 pid=5368 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=acea3b28-2100-0000-e66d-7ed2f8140000 pid=5368 execve guuid=01b06f29-2100-0000-e66d-7ed2fa140000 pid=5370 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=01b06f29-2100-0000-e66d-7ed2fa140000 pid=5370 execve guuid=1f10c32a-2100-0000-e66d-7ed2fc140000 pid=5372 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1f10c32a-2100-0000-e66d-7ed2fc140000 pid=5372 execve guuid=69e9f52b-2100-0000-e66d-7ed2fe140000 pid=5374 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=69e9f52b-2100-0000-e66d-7ed2fe140000 pid=5374 execve guuid=e6e4c12d-2100-0000-e66d-7ed200150000 pid=5376 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e6e4c12d-2100-0000-e66d-7ed200150000 pid=5376 execve guuid=d6708b2f-2100-0000-e66d-7ed202150000 pid=5378 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d6708b2f-2100-0000-e66d-7ed202150000 pid=5378 execve guuid=b3e64e31-2100-0000-e66d-7ed204150000 pid=5380 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b3e64e31-2100-0000-e66d-7ed204150000 pid=5380 execve guuid=42900733-2100-0000-e66d-7ed206150000 pid=5382 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=42900733-2100-0000-e66d-7ed206150000 pid=5382 execve guuid=9e1c2463-2200-0000-e66d-7ed208150000 pid=5384 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=9e1c2463-2200-0000-e66d-7ed208150000 pid=5384 execve guuid=b0ef4667-2200-0000-e66d-7ed20a150000 pid=5386 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b0ef4667-2200-0000-e66d-7ed20a150000 pid=5386 execve guuid=24bac868-2200-0000-e66d-7ed20c150000 pid=5388 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=24bac868-2200-0000-e66d-7ed20c150000 pid=5388 execve guuid=3e3d726a-2200-0000-e66d-7ed20e150000 pid=5390 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=3e3d726a-2200-0000-e66d-7ed20e150000 pid=5390 execve guuid=0542376c-2200-0000-e66d-7ed210150000 pid=5392 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=0542376c-2200-0000-e66d-7ed210150000 pid=5392 execve guuid=171dfe6d-2200-0000-e66d-7ed212150000 pid=5394 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=171dfe6d-2200-0000-e66d-7ed212150000 pid=5394 execve guuid=d33d656f-2200-0000-e66d-7ed214150000 pid=5396 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=d33d656f-2200-0000-e66d-7ed214150000 pid=5396 execve guuid=3ed41e71-2200-0000-e66d-7ed216150000 pid=5398 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=3ed41e71-2200-0000-e66d-7ed216150000 pid=5398 execve guuid=951bf972-2200-0000-e66d-7ed218150000 pid=5400 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=951bf972-2200-0000-e66d-7ed218150000 pid=5400 execve guuid=833d82a2-2300-0000-e66d-7ed21a150000 pid=5402 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=833d82a2-2300-0000-e66d-7ed21a150000 pid=5402 execve guuid=18fc72a6-2300-0000-e66d-7ed21c150000 pid=5404 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=18fc72a6-2300-0000-e66d-7ed21c150000 pid=5404 execve guuid=261b08a8-2300-0000-e66d-7ed21e150000 pid=5406 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=261b08a8-2300-0000-e66d-7ed21e150000 pid=5406 execve guuid=5ffcaea9-2300-0000-e66d-7ed220150000 pid=5408 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=5ffcaea9-2300-0000-e66d-7ed220150000 pid=5408 execve guuid=4c1049ab-2300-0000-e66d-7ed222150000 pid=5410 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=4c1049ab-2300-0000-e66d-7ed222150000 pid=5410 execve guuid=b98296ac-2300-0000-e66d-7ed224150000 pid=5412 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b98296ac-2300-0000-e66d-7ed224150000 pid=5412 execve guuid=e0edefad-2300-0000-e66d-7ed226150000 pid=5414 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e0edefad-2300-0000-e66d-7ed226150000 pid=5414 execve guuid=81da6caf-2300-0000-e66d-7ed228150000 pid=5416 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=81da6caf-2300-0000-e66d-7ed228150000 pid=5416 execve guuid=3207d5b0-2300-0000-e66d-7ed22a150000 pid=5418 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=3207d5b0-2300-0000-e66d-7ed22a150000 pid=5418 execve guuid=0521bae0-2400-0000-e66d-7ed22c150000 pid=5420 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=0521bae0-2400-0000-e66d-7ed22c150000 pid=5420 execve guuid=b0004fe5-2400-0000-e66d-7ed22e150000 pid=5422 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=b0004fe5-2400-0000-e66d-7ed22e150000 pid=5422 execve guuid=f7bef2e6-2400-0000-e66d-7ed230150000 pid=5424 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=f7bef2e6-2400-0000-e66d-7ed230150000 pid=5424 execve guuid=7693bfe8-2400-0000-e66d-7ed232150000 pid=5426 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=7693bfe8-2400-0000-e66d-7ed232150000 pid=5426 execve guuid=1c5c86ea-2400-0000-e66d-7ed234150000 pid=5428 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1c5c86ea-2400-0000-e66d-7ed234150000 pid=5428 execve guuid=c81249ec-2400-0000-e66d-7ed236150000 pid=5430 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=c81249ec-2400-0000-e66d-7ed236150000 pid=5430 execve guuid=ae640cee-2400-0000-e66d-7ed238150000 pid=5432 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=ae640cee-2400-0000-e66d-7ed238150000 pid=5432 execve guuid=1d02ccef-2400-0000-e66d-7ed23a150000 pid=5434 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1d02ccef-2400-0000-e66d-7ed23a150000 pid=5434 execve guuid=9b7c00f1-2400-0000-e66d-7ed23c150000 pid=5436 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=9b7c00f1-2400-0000-e66d-7ed23c150000 pid=5436 execve guuid=141a1120-2600-0000-e66d-7ed240150000 pid=5440 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=141a1120-2600-0000-e66d-7ed240150000 pid=5440 execve guuid=87deeb22-2600-0000-e66d-7ed242150000 pid=5442 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=87deeb22-2600-0000-e66d-7ed242150000 pid=5442 execve guuid=1acfd023-2600-0000-e66d-7ed244150000 pid=5444 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=1acfd023-2600-0000-e66d-7ed244150000 pid=5444 execve guuid=62f5ba24-2600-0000-e66d-7ed246150000 pid=5446 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=62f5ba24-2600-0000-e66d-7ed246150000 pid=5446 execve guuid=30a38f25-2600-0000-e66d-7ed248150000 pid=5448 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=30a38f25-2600-0000-e66d-7ed248150000 pid=5448 execve guuid=e61e6f26-2600-0000-e66d-7ed24a150000 pid=5450 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=e61e6f26-2600-0000-e66d-7ed24a150000 pid=5450 execve guuid=cf6b5927-2600-0000-e66d-7ed24c150000 pid=5452 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=cf6b5927-2600-0000-e66d-7ed24c150000 pid=5452 execve guuid=660c8228-2600-0000-e66d-7ed24e150000 pid=5454 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=660c8228-2600-0000-e66d-7ed24e150000 pid=5454 execve guuid=f01dbb29-2600-0000-e66d-7ed250150000 pid=5456 /usr/bin/dash guuid=5a8b3246-1800-0000-e66d-7ed24d090000 pid=2381->guuid=f01dbb29-2600-0000-e66d-7ed250150000 pid=5456 execve guuid=8df14a46-1800-0000-e66d-7ed250090000 pid=2384 /tmp/sample.bin net send-data zombie guuid=916e3e46-1800-0000-e66d-7ed24f090000 pid=2383->guuid=8df14a46-1800-0000-e66d-7ed250090000 pid=2384 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=8df14a46-1800-0000-e66d-7ed250090000 pid=2384->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B guuid=3a330f79-1800-0000-e66d-7ed2be090000 pid=2494 /usr/bin/pgrep guuid=aa12ce78-1800-0000-e66d-7ed2bd090000 pid=2493->guuid=3a330f79-1800-0000-e66d-7ed2be090000 pid=2494 execve guuid=680b907c-1800-0000-e66d-7ed2c9090000 pid=2505 /usr/bin/killall guuid=1b804e7c-1800-0000-e66d-7ed2c7090000 pid=2503->guuid=680b907c-1800-0000-e66d-7ed2c9090000 pid=2505 execve guuid=a7be987d-1800-0000-e66d-7ed2ce090000 pid=2510 /usr/bin/killall guuid=8bcb707d-1800-0000-e66d-7ed2cd090000 pid=2509->guuid=a7be987d-1800-0000-e66d-7ed2ce090000 pid=2510 execve guuid=5a647d7e-1800-0000-e66d-7ed2d2090000 pid=2514 /usr/bin/killall guuid=a011547e-1800-0000-e66d-7ed2d1090000 pid=2513->guuid=5a647d7e-1800-0000-e66d-7ed2d2090000 pid=2514 execve guuid=124e637f-1800-0000-e66d-7ed2d7090000 pid=2519 /usr/bin/killall guuid=e943397f-1800-0000-e66d-7ed2d5090000 pid=2517->guuid=124e637f-1800-0000-e66d-7ed2d7090000 pid=2519 execve guuid=662c8980-1800-0000-e66d-7ed2db090000 pid=2523 /usr/bin/killall guuid=950c5680-1800-0000-e66d-7ed2da090000 pid=2522->guuid=662c8980-1800-0000-e66d-7ed2db090000 pid=2523 execve guuid=3e777881-1800-0000-e66d-7ed2e0090000 pid=2528 /usr/bin/killall guuid=9c214d81-1800-0000-e66d-7ed2de090000 pid=2526->guuid=3e777881-1800-0000-e66d-7ed2e0090000 pid=2528 execve guuid=23cc6d82-1800-0000-e66d-7ed2e5090000 pid=2533 /usr/bin/killall guuid=726b2982-1800-0000-e66d-7ed2e3090000 pid=2531->guuid=23cc6d82-1800-0000-e66d-7ed2e5090000 pid=2533 execve guuid=05244e83-1800-0000-e66d-7ed2e9090000 pid=2537 /usr/bin/killall guuid=64912283-1800-0000-e66d-7ed2e8090000 pid=2536->guuid=05244e83-1800-0000-e66d-7ed2e9090000 pid=2537 execve guuid=3e32c6b0-1900-0000-e66d-7ed2c20c0000 pid=3266 /usr/bin/pgrep guuid=80129fb0-1900-0000-e66d-7ed2c10c0000 pid=3265->guuid=3e32c6b0-1900-0000-e66d-7ed2c20c0000 pid=3266 execve guuid=906e0fb5-1900-0000-e66d-7ed2ce0c0000 pid=3278 /usr/bin/killall guuid=b9c1ceb4-1900-0000-e66d-7ed2cc0c0000 pid=3276->guuid=906e0fb5-1900-0000-e66d-7ed2ce0c0000 pid=3278 execve guuid=f59311b6-1900-0000-e66d-7ed2d10c0000 pid=3281 /usr/bin/killall guuid=5949e4b5-1900-0000-e66d-7ed2d00c0000 pid=3280->guuid=f59311b6-1900-0000-e66d-7ed2d10c0000 pid=3281 execve guuid=ffd8f5b6-1900-0000-e66d-7ed2d60c0000 pid=3286 /usr/bin/killall guuid=b9cccab6-1900-0000-e66d-7ed2d50c0000 pid=3285->guuid=ffd8f5b6-1900-0000-e66d-7ed2d60c0000 pid=3286 execve guuid=445ad9b7-1900-0000-e66d-7ed2db0c0000 pid=3291 /usr/bin/killall guuid=fe37a5b7-1900-0000-e66d-7ed2da0c0000 pid=3290->guuid=445ad9b7-1900-0000-e66d-7ed2db0c0000 pid=3291 execve guuid=281ec5b8-1900-0000-e66d-7ed2de0c0000 pid=3294 /usr/bin/killall guuid=333d95b8-1900-0000-e66d-7ed2dc0c0000 pid=3292->guuid=281ec5b8-1900-0000-e66d-7ed2de0c0000 pid=3294 execve guuid=795fdfb9-1900-0000-e66d-7ed2e30c0000 pid=3299 /usr/bin/killall guuid=d5efb2b9-1900-0000-e66d-7ed2e10c0000 pid=3297->guuid=795fdfb9-1900-0000-e66d-7ed2e30c0000 pid=3299 execve guuid=e61b6ebb-1900-0000-e66d-7ed2ea0c0000 pid=3306 /usr/bin/killall guuid=61f935bb-1900-0000-e66d-7ed2e90c0000 pid=3305->guuid=e61b6ebb-1900-0000-e66d-7ed2ea0c0000 pid=3306 execve guuid=472154bc-1900-0000-e66d-7ed2f00c0000 pid=3312 /usr/bin/killall guuid=c07b21bc-1900-0000-e66d-7ed2ee0c0000 pid=3310->guuid=472154bc-1900-0000-e66d-7ed2f00c0000 pid=3312 execve guuid=b45ed4ea-1a00-0000-e66d-7ed2f60e0000 pid=3830 /usr/bin/pgrep guuid=b6c655ea-1a00-0000-e66d-7ed2f30e0000 pid=3827->guuid=b45ed4ea-1a00-0000-e66d-7ed2f60e0000 pid=3830 execve guuid=fc63f7ef-1a00-0000-e66d-7ed20e0f0000 pid=3854 /usr/bin/killall guuid=78cc8fef-1a00-0000-e66d-7ed20a0f0000 pid=3850->guuid=fc63f7ef-1a00-0000-e66d-7ed20e0f0000 pid=3854 execve guuid=46419cf1-1a00-0000-e66d-7ed21a0f0000 pid=3866 /usr/bin/killall guuid=98fb5df1-1a00-0000-e66d-7ed2130f0000 pid=3859->guuid=46419cf1-1a00-0000-e66d-7ed21a0f0000 pid=3866 execve guuid=139ce3f3-1a00-0000-e66d-7ed21c0f0000 pid=3868 /usr/bin/killall guuid=db8768f3-1a00-0000-e66d-7ed21b0f0000 pid=3867->guuid=139ce3f3-1a00-0000-e66d-7ed21c0f0000 pid=3868 execve guuid=8c0801f5-1a00-0000-e66d-7ed2220f0000 pid=3874 /usr/bin/killall guuid=e8c5cff4-1a00-0000-e66d-7ed2200f0000 pid=3872->guuid=8c0801f5-1a00-0000-e66d-7ed2220f0000 pid=3874 execve guuid=34c51af6-1a00-0000-e66d-7ed2270f0000 pid=3879 /usr/bin/killall guuid=a2f4daf5-1a00-0000-e66d-7ed2250f0000 pid=3877->guuid=34c51af6-1a00-0000-e66d-7ed2270f0000 pid=3879 execve guuid=245b55f7-1a00-0000-e66d-7ed22e0f0000 pid=3886 /usr/bin/killall guuid=fa0e1df7-1a00-0000-e66d-7ed22a0f0000 pid=3882->guuid=245b55f7-1a00-0000-e66d-7ed22e0f0000 pid=3886 execve guuid=49485df8-1a00-0000-e66d-7ed2330f0000 pid=3891 /usr/bin/killall guuid=980d31f8-1a00-0000-e66d-7ed2310f0000 pid=3889->guuid=49485df8-1a00-0000-e66d-7ed2330f0000 pid=3891 execve guuid=e3d864f9-1a00-0000-e66d-7ed23d0f0000 pid=3901 /usr/bin/killall guuid=0e8b2af9-1a00-0000-e66d-7ed23a0f0000 pid=3898->guuid=e3d864f9-1a00-0000-e66d-7ed23d0f0000 pid=3901 execve guuid=62186427-1c00-0000-e66d-7ed2c0120000 pid=4800 /usr/bin/pgrep guuid=1e962a27-1c00-0000-e66d-7ed2bf120000 pid=4799->guuid=62186427-1c00-0000-e66d-7ed2c0120000 pid=4800 execve guuid=4666c12a-1c00-0000-e66d-7ed2d2120000 pid=4818 /usr/bin/killall guuid=d188962a-1c00-0000-e66d-7ed2d0120000 pid=4816->guuid=4666c12a-1c00-0000-e66d-7ed2d2120000 pid=4818 execve guuid=48329b2b-1c00-0000-e66d-7ed2d8120000 pid=4824 /usr/bin/killall guuid=c46e6f2b-1c00-0000-e66d-7ed2d6120000 pid=4822->guuid=48329b2b-1c00-0000-e66d-7ed2d8120000 pid=4824 execve guuid=5b84702c-1c00-0000-e66d-7ed2dd120000 pid=4829 /usr/bin/killall guuid=9f0b452c-1c00-0000-e66d-7ed2dc120000 pid=4828->guuid=5b84702c-1c00-0000-e66d-7ed2dd120000 pid=4829 execve guuid=729b4d2d-1c00-0000-e66d-7ed2e3120000 pid=4835 /usr/bin/killall guuid=63ae222d-1c00-0000-e66d-7ed2e1120000 pid=4833->guuid=729b4d2d-1c00-0000-e66d-7ed2e3120000 pid=4835 execve guuid=20ee212e-1c00-0000-e66d-7ed2e9120000 pid=4841 /usr/bin/killall guuid=1836f72d-1c00-0000-e66d-7ed2e7120000 pid=4839->guuid=20ee212e-1c00-0000-e66d-7ed2e9120000 pid=4841 execve guuid=eb4ff92e-1c00-0000-e66d-7ed2ee120000 pid=4846 /usr/bin/killall guuid=816ad12e-1c00-0000-e66d-7ed2ed120000 pid=4845->guuid=eb4ff92e-1c00-0000-e66d-7ed2ee120000 pid=4846 execve guuid=7172d22f-1c00-0000-e66d-7ed2f4120000 pid=4852 /usr/bin/killall guuid=fb31ab2f-1c00-0000-e66d-7ed2f2120000 pid=4850->guuid=7172d22f-1c00-0000-e66d-7ed2f4120000 pid=4852 execve guuid=2593a430-1c00-0000-e66d-7ed2f9120000 pid=4857 /usr/bin/killall guuid=1eb27930-1c00-0000-e66d-7ed2f8120000 pid=4856->guuid=2593a430-1c00-0000-e66d-7ed2f9120000 pid=4857 execve guuid=ecf5ea6f-1d00-0000-e66d-7ed2bb140000 pid=5307 /usr/bin/pgrep guuid=86d5866f-1d00-0000-e66d-7ed2ba140000 pid=5306->guuid=ecf5ea6f-1d00-0000-e66d-7ed2bb140000 pid=5307 execve guuid=a28d5974-1d00-0000-e66d-7ed2be140000 pid=5310 /usr/bin/killall guuid=56f52174-1d00-0000-e66d-7ed2bd140000 pid=5309->guuid=a28d5974-1d00-0000-e66d-7ed2be140000 pid=5310 execve guuid=6262af75-1d00-0000-e66d-7ed2c0140000 pid=5312 /usr/bin/killall guuid=d9e98075-1d00-0000-e66d-7ed2bf140000 pid=5311->guuid=6262af75-1d00-0000-e66d-7ed2c0140000 pid=5312 execve guuid=fdfc7b76-1d00-0000-e66d-7ed2c2140000 pid=5314 /usr/bin/killall guuid=12305176-1d00-0000-e66d-7ed2c1140000 pid=5313->guuid=fdfc7b76-1d00-0000-e66d-7ed2c2140000 pid=5314 execve guuid=c9494877-1d00-0000-e66d-7ed2c4140000 pid=5316 /usr/bin/killall guuid=5ae92177-1d00-0000-e66d-7ed2c3140000 pid=5315->guuid=c9494877-1d00-0000-e66d-7ed2c4140000 pid=5316 execve guuid=86b61b78-1d00-0000-e66d-7ed2c6140000 pid=5318 /usr/bin/killall guuid=a29cf277-1d00-0000-e66d-7ed2c5140000 pid=5317->guuid=86b61b78-1d00-0000-e66d-7ed2c6140000 pid=5318 execve guuid=61bbec78-1d00-0000-e66d-7ed2c8140000 pid=5320 /usr/bin/killall guuid=118ec578-1d00-0000-e66d-7ed2c7140000 pid=5319->guuid=61bbec78-1d00-0000-e66d-7ed2c8140000 pid=5320 execve guuid=754cbb79-1d00-0000-e66d-7ed2ca140000 pid=5322 /usr/bin/killall guuid=99bd9379-1d00-0000-e66d-7ed2c9140000 pid=5321->guuid=754cbb79-1d00-0000-e66d-7ed2ca140000 pid=5322 execve guuid=880e8d7a-1d00-0000-e66d-7ed2cc140000 pid=5324 /usr/bin/killall guuid=3d37657a-1d00-0000-e66d-7ed2cb140000 pid=5323->guuid=880e8d7a-1d00-0000-e66d-7ed2cc140000 pid=5324 execve guuid=1f8a67a9-1e00-0000-e66d-7ed2d3140000 pid=5331 /usr/bin/pgrep guuid=4e560fa9-1e00-0000-e66d-7ed2d2140000 pid=5330->guuid=1f8a67a9-1e00-0000-e66d-7ed2d3140000 pid=5331 execve guuid=d675ebad-1e00-0000-e66d-7ed2d5140000 pid=5333 /usr/bin/killall guuid=389ba1ad-1e00-0000-e66d-7ed2d4140000 pid=5332->guuid=d675ebad-1e00-0000-e66d-7ed2d5140000 pid=5333 execve guuid=2ba17faf-1e00-0000-e66d-7ed2d7140000 pid=5335 /usr/bin/killall guuid=ff553baf-1e00-0000-e66d-7ed2d6140000 pid=5334->guuid=2ba17faf-1e00-0000-e66d-7ed2d7140000 pid=5335 execve guuid=917ffdb0-1e00-0000-e66d-7ed2d9140000 pid=5337 /usr/bin/killall guuid=68e5b7b0-1e00-0000-e66d-7ed2d8140000 pid=5336->guuid=917ffdb0-1e00-0000-e66d-7ed2d9140000 pid=5337 execve guuid=c93783b2-1e00-0000-e66d-7ed2db140000 pid=5339 /usr/bin/killall guuid=e09e45b2-1e00-0000-e66d-7ed2da140000 pid=5338->guuid=c93783b2-1e00-0000-e66d-7ed2db140000 pid=5339 execve guuid=7e1b09b4-1e00-0000-e66d-7ed2dd140000 pid=5341 /usr/bin/killall guuid=f2ffd8b3-1e00-0000-e66d-7ed2dc140000 pid=5340->guuid=7e1b09b4-1e00-0000-e66d-7ed2dd140000 pid=5341 execve guuid=ef8691b5-1e00-0000-e66d-7ed2df140000 pid=5343 /usr/bin/killall guuid=611f5db5-1e00-0000-e66d-7ed2de140000 pid=5342->guuid=ef8691b5-1e00-0000-e66d-7ed2df140000 pid=5343 execve guuid=c455f6b6-1e00-0000-e66d-7ed2e1140000 pid=5345 /usr/bin/killall guuid=e99ec4b6-1e00-0000-e66d-7ed2e0140000 pid=5344->guuid=c455f6b6-1e00-0000-e66d-7ed2e1140000 pid=5345 execve guuid=3084dfb7-1e00-0000-e66d-7ed2e3140000 pid=5347 /usr/bin/killall guuid=3221abb7-1e00-0000-e66d-7ed2e2140000 pid=5346->guuid=3084dfb7-1e00-0000-e66d-7ed2e3140000 pid=5347 execve guuid=c9b3c4e6-1f00-0000-e66d-7ed2e5140000 pid=5349 /usr/bin/pgrep guuid=ca8170e6-1f00-0000-e66d-7ed2e4140000 pid=5348->guuid=c9b3c4e6-1f00-0000-e66d-7ed2e5140000 pid=5349 execve guuid=f97628eb-1f00-0000-e66d-7ed2e7140000 pid=5351 /usr/bin/killall guuid=902dd2ea-1f00-0000-e66d-7ed2e6140000 pid=5350->guuid=f97628eb-1f00-0000-e66d-7ed2e7140000 pid=5351 execve guuid=deb494ec-1f00-0000-e66d-7ed2e9140000 pid=5353 /usr/bin/killall guuid=d39c3bec-1f00-0000-e66d-7ed2e8140000 pid=5352->guuid=deb494ec-1f00-0000-e66d-7ed2e9140000 pid=5353 execve guuid=530afaed-1f00-0000-e66d-7ed2eb140000 pid=5355 /usr/bin/killall guuid=0c44a2ed-1f00-0000-e66d-7ed2ea140000 pid=5354->guuid=530afaed-1f00-0000-e66d-7ed2eb140000 pid=5355 execve guuid=146049ef-1f00-0000-e66d-7ed2ed140000 pid=5357 /usr/bin/killall guuid=fdab03ef-1f00-0000-e66d-7ed2ec140000 pid=5356->guuid=146049ef-1f00-0000-e66d-7ed2ed140000 pid=5357 execve guuid=957ff0f0-1f00-0000-e66d-7ed2ef140000 pid=5359 /usr/bin/killall guuid=8a639cf0-1f00-0000-e66d-7ed2ee140000 pid=5358->guuid=957ff0f0-1f00-0000-e66d-7ed2ef140000 pid=5359 execve guuid=bef291f2-1f00-0000-e66d-7ed2f1140000 pid=5361 /usr/bin/killall guuid=e4b139f2-1f00-0000-e66d-7ed2f0140000 pid=5360->guuid=bef291f2-1f00-0000-e66d-7ed2f1140000 pid=5361 execve guuid=761423f4-1f00-0000-e66d-7ed2f3140000 pid=5363 /usr/bin/killall guuid=985ad2f3-1f00-0000-e66d-7ed2f2140000 pid=5362->guuid=761423f4-1f00-0000-e66d-7ed2f3140000 pid=5363 execve guuid=457697f5-1f00-0000-e66d-7ed2f5140000 pid=5365 /usr/bin/killall guuid=0b0f42f5-1f00-0000-e66d-7ed2f4140000 pid=5364->guuid=457697f5-1f00-0000-e66d-7ed2f5140000 pid=5365 execve guuid=1d505125-2100-0000-e66d-7ed2f7140000 pid=5367 /usr/bin/pgrep guuid=cc8af724-2100-0000-e66d-7ed2f6140000 pid=5366->guuid=1d505125-2100-0000-e66d-7ed2f7140000 pid=5367 execve guuid=1b2a9828-2100-0000-e66d-7ed2f9140000 pid=5369 /usr/bin/killall guuid=acea3b28-2100-0000-e66d-7ed2f8140000 pid=5368->guuid=1b2a9828-2100-0000-e66d-7ed2f9140000 pid=5369 execve guuid=42bd9a29-2100-0000-e66d-7ed2fb140000 pid=5371 /usr/bin/killall guuid=01b06f29-2100-0000-e66d-7ed2fa140000 pid=5370->guuid=42bd9a29-2100-0000-e66d-7ed2fb140000 pid=5371 execve guuid=1c611b2b-2100-0000-e66d-7ed2fd140000 pid=5373 /usr/bin/killall guuid=1f10c32a-2100-0000-e66d-7ed2fc140000 pid=5372->guuid=1c611b2b-2100-0000-e66d-7ed2fd140000 pid=5373 execve guuid=4094542c-2100-0000-e66d-7ed2ff140000 pid=5375 /usr/bin/killall guuid=69e9f52b-2100-0000-e66d-7ed2fe140000 pid=5374->guuid=4094542c-2100-0000-e66d-7ed2ff140000 pid=5375 execve guuid=db18172e-2100-0000-e66d-7ed201150000 pid=5377 /usr/bin/killall guuid=e6e4c12d-2100-0000-e66d-7ed200150000 pid=5376->guuid=db18172e-2100-0000-e66d-7ed201150000 pid=5377 execve guuid=45f3ee2f-2100-0000-e66d-7ed203150000 pid=5379 /usr/bin/killall guuid=d6708b2f-2100-0000-e66d-7ed202150000 pid=5378->guuid=45f3ee2f-2100-0000-e66d-7ed203150000 pid=5379 execve guuid=a80da431-2100-0000-e66d-7ed205150000 pid=5381 /usr/bin/killall guuid=b3e64e31-2100-0000-e66d-7ed204150000 pid=5380->guuid=a80da431-2100-0000-e66d-7ed205150000 pid=5381 execve guuid=0d335a33-2100-0000-e66d-7ed207150000 pid=5383 /usr/bin/killall guuid=42900733-2100-0000-e66d-7ed206150000 pid=5382->guuid=0d335a33-2100-0000-e66d-7ed207150000 pid=5383 execve guuid=5f6a8763-2200-0000-e66d-7ed209150000 pid=5385 /usr/bin/pgrep guuid=9e1c2463-2200-0000-e66d-7ed208150000 pid=5384->guuid=5f6a8763-2200-0000-e66d-7ed209150000 pid=5385 execve guuid=f0c57e67-2200-0000-e66d-7ed20b150000 pid=5387 /usr/bin/killall guuid=b0ef4667-2200-0000-e66d-7ed20a150000 pid=5386->guuid=f0c57e67-2200-0000-e66d-7ed20b150000 pid=5387 execve guuid=e9b30b69-2200-0000-e66d-7ed20d150000 pid=5389 /usr/bin/killall guuid=24bac868-2200-0000-e66d-7ed20c150000 pid=5388->guuid=e9b30b69-2200-0000-e66d-7ed20d150000 pid=5389 execve guuid=bc39cf6a-2200-0000-e66d-7ed20f150000 pid=5391 /usr/bin/killall guuid=3e3d726a-2200-0000-e66d-7ed20e150000 pid=5390->guuid=bc39cf6a-2200-0000-e66d-7ed20f150000 pid=5391 execve guuid=ad13906c-2200-0000-e66d-7ed211150000 pid=5393 /usr/bin/killall guuid=0542376c-2200-0000-e66d-7ed210150000 pid=5392->guuid=ad13906c-2200-0000-e66d-7ed211150000 pid=5393 execve guuid=73b15b6e-2200-0000-e66d-7ed213150000 pid=5395 /usr/bin/killall guuid=171dfe6d-2200-0000-e66d-7ed212150000 pid=5394->guuid=73b15b6e-2200-0000-e66d-7ed213150000 pid=5395 execve guuid=b6dea36f-2200-0000-e66d-7ed215150000 pid=5397 /usr/bin/killall guuid=d33d656f-2200-0000-e66d-7ed214150000 pid=5396->guuid=b6dea36f-2200-0000-e66d-7ed215150000 pid=5397 execve guuid=923b7d71-2200-0000-e66d-7ed217150000 pid=5399 /usr/bin/killall guuid=3ed41e71-2200-0000-e66d-7ed216150000 pid=5398->guuid=923b7d71-2200-0000-e66d-7ed217150000 pid=5399 execve guuid=9dbf5273-2200-0000-e66d-7ed219150000 pid=5401 /usr/bin/killall guuid=951bf972-2200-0000-e66d-7ed218150000 pid=5400->guuid=9dbf5273-2200-0000-e66d-7ed219150000 pid=5401 execve guuid=5cabe8a2-2300-0000-e66d-7ed21b150000 pid=5403 /usr/bin/pgrep guuid=833d82a2-2300-0000-e66d-7ed21a150000 pid=5402->guuid=5cabe8a2-2300-0000-e66d-7ed21b150000 pid=5403 execve guuid=808da0a6-2300-0000-e66d-7ed21d150000 pid=5405 /usr/bin/killall guuid=18fc72a6-2300-0000-e66d-7ed21c150000 pid=5404->guuid=808da0a6-2300-0000-e66d-7ed21d150000 pid=5405 execve guuid=b7c54ca8-2300-0000-e66d-7ed21f150000 pid=5407 /usr/bin/killall guuid=261b08a8-2300-0000-e66d-7ed21e150000 pid=5406->guuid=b7c54ca8-2300-0000-e66d-7ed21f150000 pid=5407 execve guuid=dc92eea9-2300-0000-e66d-7ed221150000 pid=5409 /usr/bin/killall guuid=5ffcaea9-2300-0000-e66d-7ed220150000 pid=5408->guuid=dc92eea9-2300-0000-e66d-7ed221150000 pid=5409 execve guuid=5fed8cab-2300-0000-e66d-7ed223150000 pid=5411 /usr/bin/killall guuid=4c1049ab-2300-0000-e66d-7ed222150000 pid=5410->guuid=5fed8cab-2300-0000-e66d-7ed223150000 pid=5411 execve guuid=64d3f0ac-2300-0000-e66d-7ed225150000 pid=5413 /usr/bin/killall guuid=b98296ac-2300-0000-e66d-7ed224150000 pid=5412->guuid=64d3f0ac-2300-0000-e66d-7ed225150000 pid=5413 execve guuid=ba2332ae-2300-0000-e66d-7ed227150000 pid=5415 /usr/bin/killall guuid=e0edefad-2300-0000-e66d-7ed226150000 pid=5414->guuid=ba2332ae-2300-0000-e66d-7ed227150000 pid=5415 execve guuid=0644acaf-2300-0000-e66d-7ed229150000 pid=5417 /usr/bin/killall guuid=81da6caf-2300-0000-e66d-7ed228150000 pid=5416->guuid=0644acaf-2300-0000-e66d-7ed229150000 pid=5417 execve guuid=ed9536b1-2300-0000-e66d-7ed22b150000 pid=5419 /usr/bin/killall guuid=3207d5b0-2300-0000-e66d-7ed22a150000 pid=5418->guuid=ed9536b1-2300-0000-e66d-7ed22b150000 pid=5419 execve guuid=ff4c18e1-2400-0000-e66d-7ed22d150000 pid=5421 /usr/bin/pgrep guuid=0521bae0-2400-0000-e66d-7ed22c150000 pid=5420->guuid=ff4c18e1-2400-0000-e66d-7ed22d150000 pid=5421 execve guuid=e2eb7de5-2400-0000-e66d-7ed22f150000 pid=5423 /usr/bin/killall guuid=b0004fe5-2400-0000-e66d-7ed22e150000 pid=5422->guuid=e2eb7de5-2400-0000-e66d-7ed22f150000 pid=5423 execve guuid=8e0049e7-2400-0000-e66d-7ed231150000 pid=5425 /usr/bin/killall guuid=f7bef2e6-2400-0000-e66d-7ed230150000 pid=5424->guuid=8e0049e7-2400-0000-e66d-7ed231150000 pid=5425 execve guuid=65961be9-2400-0000-e66d-7ed233150000 pid=5427 /usr/bin/killall guuid=7693bfe8-2400-0000-e66d-7ed232150000 pid=5426->guuid=65961be9-2400-0000-e66d-7ed233150000 pid=5427 execve guuid=21b1e1ea-2400-0000-e66d-7ed235150000 pid=5429 /usr/bin/killall guuid=1c5c86ea-2400-0000-e66d-7ed234150000 pid=5428->guuid=21b1e1ea-2400-0000-e66d-7ed235150000 pid=5429 execve guuid=caddabec-2400-0000-e66d-7ed237150000 pid=5431 /usr/bin/killall guuid=c81249ec-2400-0000-e66d-7ed236150000 pid=5430->guuid=caddabec-2400-0000-e66d-7ed237150000 pid=5431 execve guuid=60d766ee-2400-0000-e66d-7ed239150000 pid=5433 /usr/bin/killall guuid=ae640cee-2400-0000-e66d-7ed238150000 pid=5432->guuid=60d766ee-2400-0000-e66d-7ed239150000 pid=5433 execve guuid=951017f0-2400-0000-e66d-7ed23b150000 pid=5435 /usr/bin/killall guuid=1d02ccef-2400-0000-e66d-7ed23a150000 pid=5434->guuid=951017f0-2400-0000-e66d-7ed23b150000 pid=5435 execve guuid=d28b35f1-2400-0000-e66d-7ed23d150000 pid=5437 /usr/bin/killall guuid=9b7c00f1-2400-0000-e66d-7ed23c150000 pid=5436->guuid=d28b35f1-2400-0000-e66d-7ed23d150000 pid=5437 execve guuid=bc433e20-2600-0000-e66d-7ed241150000 pid=5441 /usr/bin/pgrep guuid=141a1120-2600-0000-e66d-7ed240150000 pid=5440->guuid=bc433e20-2600-0000-e66d-7ed241150000 pid=5441 execve guuid=27822323-2600-0000-e66d-7ed243150000 pid=5443 /usr/bin/killall guuid=87deeb22-2600-0000-e66d-7ed242150000 pid=5442->guuid=27822323-2600-0000-e66d-7ed243150000 pid=5443 execve guuid=388d0d24-2600-0000-e66d-7ed245150000 pid=5445 /usr/bin/killall guuid=1acfd023-2600-0000-e66d-7ed244150000 pid=5444->guuid=388d0d24-2600-0000-e66d-7ed245150000 pid=5445 execve guuid=6d38e424-2600-0000-e66d-7ed247150000 pid=5447 /usr/bin/killall guuid=62f5ba24-2600-0000-e66d-7ed246150000 pid=5446->guuid=6d38e424-2600-0000-e66d-7ed247150000 pid=5447 execve guuid=a32ac725-2600-0000-e66d-7ed249150000 pid=5449 /usr/bin/killall guuid=30a38f25-2600-0000-e66d-7ed248150000 pid=5448->guuid=a32ac725-2600-0000-e66d-7ed249150000 pid=5449 execve guuid=0224ad26-2600-0000-e66d-7ed24b150000 pid=5451 /usr/bin/killall guuid=e61e6f26-2600-0000-e66d-7ed24a150000 pid=5450->guuid=0224ad26-2600-0000-e66d-7ed24b150000 pid=5451 execve guuid=32fc8427-2600-0000-e66d-7ed24d150000 pid=5453 /usr/bin/killall guuid=cf6b5927-2600-0000-e66d-7ed24c150000 pid=5452->guuid=32fc8427-2600-0000-e66d-7ed24d150000 pid=5453 execve guuid=5b8dc328-2600-0000-e66d-7ed24f150000 pid=5455 /usr/bin/killall guuid=660c8228-2600-0000-e66d-7ed24e150000 pid=5454->guuid=5b8dc328-2600-0000-e66d-7ed24f150000 pid=5455 execve guuid=55eee329-2600-0000-e66d-7ed251150000 pid=5457 /usr/bin/killall guuid=f01dbb29-2600-0000-e66d-7ed250150000 pid=5456->guuid=55eee329-2600-0000-e66d-7ed251150000 pid=5457 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample tries to kill multiple processes (SIGKILL)
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1736781 Sample: getty.elf Startdate: 15/07/2025 Architecture: LINUX Score: 100 38 206.123.128.67, 47098, 65481 LEASEWEB-USA-NYC-11US United States 2->38 40 daisy.ubuntu.com 2->40 42 Suricata IDS alerts for network traffic 2->42 44 Malicious sample detected (through community Yara rule) 2->44 46 Antivirus / Scanner detection for submitted sample 2->46 48 4 other signatures 2->48 9 getty.elf 2->9         started        signatures3 process4 signatures5 52 Opens /proc/net/* files useful for finding connected devices and routers 9->52 12 getty.elf 9->12         started        process6 signatures7 54 Sample tries to kill multiple processes (SIGKILL) 12->54 15 getty.elf sh 12->15         started        17 getty.elf sh 12->17         started        19 getty.elf sh 12->19         started        21 59 other processes 12->21 process8 process9 23 sh killall 15->23         started        26 sh killall 17->26         started        28 sh killall 19->28         started        30 sh killall 21->30         started        32 sh killall 21->32         started        34 sh killall 21->34         started        36 56 other processes 21->36 signatures10 50 Terminates several processes with shell command 'killall' 23->50
Threat name:
Linux.Backdoor.Bashlite
Status:
Malicious
First seen:
2025-07-15 06:40:29 UTC
File Type:
ELF32 Little (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt discovery linux rootkit
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Reads CPU attributes
Enumerates running processes
Loads a kernel module
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_c573932b Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_71e487ea Linux_Trojan_Gafgyt_7167d08f Linux_Trojan_Mirai_389ee3e9 elf_bashlite_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_7167d08f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_71e487ea
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_c573932b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 09e7aefe2c812b2488c500ac4154b8cd8774e9b5cbb1ba670974a1adb7836849

(this sample)

  
Delivery method
Distributed via web download

Comments