MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0cc3feb64eb5d4e0f124361b8af0a1002da294fbf268794e44cf28f9bb89552a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 13


Intelligence 13 IOCs YARA 30 File information Comments

SHA256 hash: 0cc3feb64eb5d4e0f124361b8af0a1002da294fbf268794e44cf28f9bb89552a
SHA3-384 hash: 0ab409bc641b0904e2654e3cf587ddfc3635ee6911e5b897e213bf83e4ab6bb6ebd90245f1ad3af0ce915f9203a206ae
SHA1 hash: 09b415edc616592efda40781417945d2ddaa3981
MD5 hash: 9eba032a61a458403a87ae207979003c
humanhash: fix-cat-fourteen-blossom
File name:ssh
Download: download sample
Signature Mirai
File size:152'252 bytes
First seen:2025-07-09 23:47:43 UTC
Last seen:2025-07-10 09:22:32 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:nQtmZ6KSLLIREatem0ccqBxH6xHO9hurmmmFA8hNhDlL6NU:5VSLL/m5/BZZ9hu6mmFA8hNhDlL6NU
TLSH T1AAE3A92AF1428777D197427022DDEE226C316FE4379AB01B33B07AB46AB74572D15E8C
telfhash t1c2313322953556142fb3a928acbd56b315222b2323586f71af26c5cc49260e2e93dd4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
20
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Creating a file
Sets a written file as executable
Kills processes
Launching a process
Sends data to a server
Connection attempt
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc lolbin obfuscated remote
Status:
terminated
Behavior Graph:
%3 guuid=04913ce8-1800-0000-dea3-a564570b0000 pid=2903 /usr/bin/sudo guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909 /tmp/sample.bin net guuid=04913ce8-1800-0000-dea3-a564570b0000 pid=2903->guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911 /tmp/sample.bin zombie guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909->guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911 clone guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912 /usr/bin/dash zombie guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909->guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912 execve guuid=6d48f7ea-1800-0000-dea3-a564610b0000 pid=2913 /tmp/sample.bin guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909->guuid=6d48f7ea-1800-0000-dea3-a564610b0000 pid=2913 clone guuid=aac1faea-1800-0000-dea3-a564620b0000 pid=2914 /tmp/sample.bin guuid=d4ccb4ea-1800-0000-dea3-a5645d0b0000 pid=2909->guuid=aac1faea-1800-0000-dea3-a564620b0000 pid=2914 clone guuid=977d6c1a-1900-0000-dea3-a564b80b0000 pid=3000 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=977d6c1a-1900-0000-dea3-a564b80b0000 pid=3000 execve guuid=354fad1e-1900-0000-dea3-a564c00b0000 pid=3008 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=354fad1e-1900-0000-dea3-a564c00b0000 pid=3008 execve guuid=c6cb2e20-1900-0000-dea3-a564c60b0000 pid=3014 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c6cb2e20-1900-0000-dea3-a564c60b0000 pid=3014 execve guuid=9d925221-1900-0000-dea3-a564cb0b0000 pid=3019 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=9d925221-1900-0000-dea3-a564cb0b0000 pid=3019 execve guuid=32df7e22-1900-0000-dea3-a564cf0b0000 pid=3023 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=32df7e22-1900-0000-dea3-a564cf0b0000 pid=3023 execve guuid=48358123-1900-0000-dea3-a564d30b0000 pid=3027 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=48358123-1900-0000-dea3-a564d30b0000 pid=3027 execve guuid=c4129a24-1900-0000-dea3-a564d70b0000 pid=3031 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c4129a24-1900-0000-dea3-a564d70b0000 pid=3031 execve guuid=793c9925-1900-0000-dea3-a564dc0b0000 pid=3036 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=793c9925-1900-0000-dea3-a564dc0b0000 pid=3036 execve guuid=593f7e26-1900-0000-dea3-a564e10b0000 pid=3041 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=593f7e26-1900-0000-dea3-a564e10b0000 pid=3041 execve guuid=eee87775-1a00-0000-dea3-a564460e0000 pid=3654 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=eee87775-1a00-0000-dea3-a564460e0000 pid=3654 execve guuid=6312fe79-1a00-0000-dea3-a564510e0000 pid=3665 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=6312fe79-1a00-0000-dea3-a564510e0000 pid=3665 execve guuid=7eabf97a-1a00-0000-dea3-a564560e0000 pid=3670 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=7eabf97a-1a00-0000-dea3-a564560e0000 pid=3670 execve guuid=0e2e607c-1a00-0000-dea3-a5645a0e0000 pid=3674 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=0e2e607c-1a00-0000-dea3-a5645a0e0000 pid=3674 execve guuid=5bf8827d-1a00-0000-dea3-a564600e0000 pid=3680 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5bf8827d-1a00-0000-dea3-a564600e0000 pid=3680 execve guuid=edd2957e-1a00-0000-dea3-a564660e0000 pid=3686 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=edd2957e-1a00-0000-dea3-a564660e0000 pid=3686 execve guuid=fa58b27f-1a00-0000-dea3-a5646d0e0000 pid=3693 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=fa58b27f-1a00-0000-dea3-a5646d0e0000 pid=3693 execve guuid=5c58b380-1a00-0000-dea3-a564720e0000 pid=3698 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5c58b380-1a00-0000-dea3-a564720e0000 pid=3698 execve guuid=d1152182-1a00-0000-dea3-a5647d0e0000 pid=3709 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=d1152182-1a00-0000-dea3-a5647d0e0000 pid=3709 execve guuid=5137c0ad-1b00-0000-dea3-a56494110000 pid=4500 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5137c0ad-1b00-0000-dea3-a56494110000 pid=4500 execve guuid=8f07fcb1-1b00-0000-dea3-a564a6110000 pid=4518 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=8f07fcb1-1b00-0000-dea3-a564a6110000 pid=4518 execve guuid=8fffddb2-1b00-0000-dea3-a564a8110000 pid=4520 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=8fffddb2-1b00-0000-dea3-a564a8110000 pid=4520 execve guuid=1388b8b3-1b00-0000-dea3-a564aa110000 pid=4522 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=1388b8b3-1b00-0000-dea3-a564aa110000 pid=4522 execve guuid=860ba6b4-1b00-0000-dea3-a564ae110000 pid=4526 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=860ba6b4-1b00-0000-dea3-a564ae110000 pid=4526 execve guuid=4f31cbb5-1b00-0000-dea3-a564b7110000 pid=4535 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=4f31cbb5-1b00-0000-dea3-a564b7110000 pid=4535 execve guuid=f74646b7-1b00-0000-dea3-a564c1110000 pid=4545 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=f74646b7-1b00-0000-dea3-a564c1110000 pid=4545 execve guuid=520522b8-1b00-0000-dea3-a564c7110000 pid=4551 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=520522b8-1b00-0000-dea3-a564c7110000 pid=4551 execve guuid=9e8c05b9-1b00-0000-dea3-a564cd110000 pid=4557 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=9e8c05b9-1b00-0000-dea3-a564cd110000 pid=4557 execve guuid=a81ce4f6-1c00-0000-dea3-a564c5140000 pid=5317 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a81ce4f6-1c00-0000-dea3-a564c5140000 pid=5317 execve guuid=bc6803fa-1c00-0000-dea3-a564c7140000 pid=5319 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=bc6803fa-1c00-0000-dea3-a564c7140000 pid=5319 execve guuid=d395f9fa-1c00-0000-dea3-a564c9140000 pid=5321 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=d395f9fa-1c00-0000-dea3-a564c9140000 pid=5321 execve guuid=5ca9fdfb-1c00-0000-dea3-a564cb140000 pid=5323 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5ca9fdfb-1c00-0000-dea3-a564cb140000 pid=5323 execve guuid=ffcc19fd-1c00-0000-dea3-a564cd140000 pid=5325 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=ffcc19fd-1c00-0000-dea3-a564cd140000 pid=5325 execve guuid=c4bb41fe-1c00-0000-dea3-a564cf140000 pid=5327 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c4bb41fe-1c00-0000-dea3-a564cf140000 pid=5327 execve guuid=89009bff-1c00-0000-dea3-a564d1140000 pid=5329 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=89009bff-1c00-0000-dea3-a564d1140000 pid=5329 execve guuid=ea96b000-1d00-0000-dea3-a564d3140000 pid=5331 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=ea96b000-1d00-0000-dea3-a564d3140000 pid=5331 execve guuid=83f7ec01-1d00-0000-dea3-a564d5140000 pid=5333 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=83f7ec01-1d00-0000-dea3-a564d5140000 pid=5333 execve guuid=e718a02d-1e00-0000-dea3-a564e9140000 pid=5353 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=e718a02d-1e00-0000-dea3-a564e9140000 pid=5353 execve guuid=47945034-1e00-0000-dea3-a564eb140000 pid=5355 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=47945034-1e00-0000-dea3-a564eb140000 pid=5355 execve guuid=28af0236-1e00-0000-dea3-a564ed140000 pid=5357 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=28af0236-1e00-0000-dea3-a564ed140000 pid=5357 execve guuid=c9c5bd37-1e00-0000-dea3-a564ef140000 pid=5359 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c9c5bd37-1e00-0000-dea3-a564ef140000 pid=5359 execve guuid=d024c939-1e00-0000-dea3-a564f1140000 pid=5361 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=d024c939-1e00-0000-dea3-a564f1140000 pid=5361 execve guuid=561b533b-1e00-0000-dea3-a564f3140000 pid=5363 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=561b533b-1e00-0000-dea3-a564f3140000 pid=5363 execve guuid=0363de3c-1e00-0000-dea3-a564f5140000 pid=5365 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=0363de3c-1e00-0000-dea3-a564f5140000 pid=5365 execve guuid=e7ce703e-1e00-0000-dea3-a564f7140000 pid=5367 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=e7ce703e-1e00-0000-dea3-a564f7140000 pid=5367 execve guuid=b2d97248-1e00-0000-dea3-a564f9140000 pid=5369 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=b2d97248-1e00-0000-dea3-a564f9140000 pid=5369 execve guuid=55080f77-1f00-0000-dea3-a56408150000 pid=5384 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=55080f77-1f00-0000-dea3-a56408150000 pid=5384 execve guuid=861f267a-1f00-0000-dea3-a5640a150000 pid=5386 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=861f267a-1f00-0000-dea3-a5640a150000 pid=5386 execve guuid=a7a7c37b-1f00-0000-dea3-a5640c150000 pid=5388 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a7a7c37b-1f00-0000-dea3-a5640c150000 pid=5388 execve guuid=28d93f7d-1f00-0000-dea3-a5640e150000 pid=5390 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=28d93f7d-1f00-0000-dea3-a5640e150000 pid=5390 execve guuid=bf63e67e-1f00-0000-dea3-a56410150000 pid=5392 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=bf63e67e-1f00-0000-dea3-a56410150000 pid=5392 execve guuid=c36a1580-1f00-0000-dea3-a56412150000 pid=5394 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c36a1580-1f00-0000-dea3-a56412150000 pid=5394 execve guuid=3428eb80-1f00-0000-dea3-a56414150000 pid=5396 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3428eb80-1f00-0000-dea3-a56414150000 pid=5396 execve guuid=949ac181-1f00-0000-dea3-a56416150000 pid=5398 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=949ac181-1f00-0000-dea3-a56416150000 pid=5398 execve guuid=4cff9e82-1f00-0000-dea3-a56418150000 pid=5400 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=4cff9e82-1f00-0000-dea3-a56418150000 pid=5400 execve guuid=fc7a63ae-2000-0000-dea3-a5641a150000 pid=5402 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=fc7a63ae-2000-0000-dea3-a5641a150000 pid=5402 execve guuid=a2a7edb2-2000-0000-dea3-a5641c150000 pid=5404 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a2a7edb2-2000-0000-dea3-a5641c150000 pid=5404 execve guuid=a08191b4-2000-0000-dea3-a5641e150000 pid=5406 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a08191b4-2000-0000-dea3-a5641e150000 pid=5406 execve guuid=b6e963b6-2000-0000-dea3-a56420150000 pid=5408 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=b6e963b6-2000-0000-dea3-a56420150000 pid=5408 execve guuid=3a0b39b8-2000-0000-dea3-a56422150000 pid=5410 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3a0b39b8-2000-0000-dea3-a56422150000 pid=5410 execve guuid=8c45f5b9-2000-0000-dea3-a56424150000 pid=5412 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=8c45f5b9-2000-0000-dea3-a56424150000 pid=5412 execve guuid=f445d3bb-2000-0000-dea3-a56426150000 pid=5414 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=f445d3bb-2000-0000-dea3-a56426150000 pid=5414 execve guuid=21e482bd-2000-0000-dea3-a56428150000 pid=5416 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=21e482bd-2000-0000-dea3-a56428150000 pid=5416 execve guuid=3bb03dbf-2000-0000-dea3-a5642a150000 pid=5418 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3bb03dbf-2000-0000-dea3-a5642a150000 pid=5418 execve guuid=4cca70eb-2100-0000-dea3-a5642c150000 pid=5420 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=4cca70eb-2100-0000-dea3-a5642c150000 pid=5420 execve guuid=166f02f0-2100-0000-dea3-a5642e150000 pid=5422 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=166f02f0-2100-0000-dea3-a5642e150000 pid=5422 execve guuid=65849bf1-2100-0000-dea3-a56430150000 pid=5424 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=65849bf1-2100-0000-dea3-a56430150000 pid=5424 execve guuid=3d256cf3-2100-0000-dea3-a56432150000 pid=5426 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3d256cf3-2100-0000-dea3-a56432150000 pid=5426 execve guuid=208f2df5-2100-0000-dea3-a56434150000 pid=5428 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=208f2df5-2100-0000-dea3-a56434150000 pid=5428 execve guuid=4003d4f6-2100-0000-dea3-a56436150000 pid=5430 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=4003d4f6-2100-0000-dea3-a56436150000 pid=5430 execve guuid=ed56c7f8-2100-0000-dea3-a56438150000 pid=5432 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=ed56c7f8-2100-0000-dea3-a56438150000 pid=5432 execve guuid=374597fa-2100-0000-dea3-a5643a150000 pid=5434 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=374597fa-2100-0000-dea3-a5643a150000 pid=5434 execve guuid=78155afc-2100-0000-dea3-a5643c150000 pid=5436 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=78155afc-2100-0000-dea3-a5643c150000 pid=5436 execve guuid=c428b028-2300-0000-dea3-a5643e150000 pid=5438 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c428b028-2300-0000-dea3-a5643e150000 pid=5438 execve guuid=1b30c32c-2300-0000-dea3-a56440150000 pid=5440 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=1b30c32c-2300-0000-dea3-a56440150000 pid=5440 execve guuid=5e7a222e-2300-0000-dea3-a56442150000 pid=5442 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5e7a222e-2300-0000-dea3-a56442150000 pid=5442 execve guuid=7bdacd2f-2300-0000-dea3-a56444150000 pid=5444 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=7bdacd2f-2300-0000-dea3-a56444150000 pid=5444 execve guuid=716c7231-2300-0000-dea3-a56446150000 pid=5446 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=716c7231-2300-0000-dea3-a56446150000 pid=5446 execve guuid=4cabe832-2300-0000-dea3-a56448150000 pid=5448 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=4cabe832-2300-0000-dea3-a56448150000 pid=5448 execve guuid=11129b34-2300-0000-dea3-a5644a150000 pid=5450 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=11129b34-2300-0000-dea3-a5644a150000 pid=5450 execve guuid=00364b36-2300-0000-dea3-a5644c150000 pid=5452 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=00364b36-2300-0000-dea3-a5644c150000 pid=5452 execve guuid=472ed937-2300-0000-dea3-a5644e150000 pid=5454 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=472ed937-2300-0000-dea3-a5644e150000 pid=5454 execve guuid=b9f61264-2400-0000-dea3-a56450150000 pid=5456 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=b9f61264-2400-0000-dea3-a56450150000 pid=5456 execve guuid=e97c0b68-2400-0000-dea3-a56452150000 pid=5458 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=e97c0b68-2400-0000-dea3-a56452150000 pid=5458 execve guuid=c99a4b69-2400-0000-dea3-a56454150000 pid=5460 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=c99a4b69-2400-0000-dea3-a56454150000 pid=5460 execve guuid=2aedd66a-2400-0000-dea3-a56456150000 pid=5462 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=2aedd66a-2400-0000-dea3-a56456150000 pid=5462 execve guuid=454a6d6c-2400-0000-dea3-a56458150000 pid=5464 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=454a6d6c-2400-0000-dea3-a56458150000 pid=5464 execve guuid=574e0e6e-2400-0000-dea3-a5645a150000 pid=5466 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=574e0e6e-2400-0000-dea3-a5645a150000 pid=5466 execve guuid=d230596f-2400-0000-dea3-a5645c150000 pid=5468 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=d230596f-2400-0000-dea3-a5645c150000 pid=5468 execve guuid=ba9af570-2400-0000-dea3-a5645e150000 pid=5470 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=ba9af570-2400-0000-dea3-a5645e150000 pid=5470 execve guuid=91548372-2400-0000-dea3-a56460150000 pid=5472 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=91548372-2400-0000-dea3-a56460150000 pid=5472 execve guuid=ae77c29e-2500-0000-dea3-a56462150000 pid=5474 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=ae77c29e-2500-0000-dea3-a56462150000 pid=5474 execve guuid=1330d6a2-2500-0000-dea3-a56464150000 pid=5476 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=1330d6a2-2500-0000-dea3-a56464150000 pid=5476 execve guuid=3e5af8a3-2500-0000-dea3-a56466150000 pid=5478 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3e5af8a3-2500-0000-dea3-a56466150000 pid=5478 execve guuid=7bbb90a5-2500-0000-dea3-a56468150000 pid=5480 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=7bbb90a5-2500-0000-dea3-a56468150000 pid=5480 execve guuid=e8a0f8a6-2500-0000-dea3-a5646a150000 pid=5482 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=e8a0f8a6-2500-0000-dea3-a5646a150000 pid=5482 execve guuid=a4cd0da9-2500-0000-dea3-a5646c150000 pid=5484 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a4cd0da9-2500-0000-dea3-a5646c150000 pid=5484 execve guuid=9098acaa-2500-0000-dea3-a5646e150000 pid=5486 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=9098acaa-2500-0000-dea3-a5646e150000 pid=5486 execve guuid=6b5ffeab-2500-0000-dea3-a56470150000 pid=5488 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=6b5ffeab-2500-0000-dea3-a56470150000 pid=5488 execve guuid=1c4576ad-2500-0000-dea3-a56472150000 pid=5490 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=1c4576ad-2500-0000-dea3-a56472150000 pid=5490 execve guuid=107094d9-2600-0000-dea3-a56476150000 pid=5494 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=107094d9-2600-0000-dea3-a56476150000 pid=5494 execve guuid=3c6e77e1-2600-0000-dea3-a56478150000 pid=5496 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3c6e77e1-2600-0000-dea3-a56478150000 pid=5496 execve guuid=a9d746e3-2600-0000-dea3-a5647e150000 pid=5502 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=a9d746e3-2600-0000-dea3-a5647e150000 pid=5502 execve guuid=5bc5eae4-2600-0000-dea3-a56482150000 pid=5506 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=5bc5eae4-2600-0000-dea3-a56482150000 pid=5506 execve guuid=36b650e6-2600-0000-dea3-a56485150000 pid=5509 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=36b650e6-2600-0000-dea3-a56485150000 pid=5509 execve guuid=3474aee7-2600-0000-dea3-a56487150000 pid=5511 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=3474aee7-2600-0000-dea3-a56487150000 pid=5511 execve guuid=62033de9-2600-0000-dea3-a5648a150000 pid=5514 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=62033de9-2600-0000-dea3-a5648a150000 pid=5514 execve guuid=78cb10eb-2600-0000-dea3-a5648c150000 pid=5516 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=78cb10eb-2600-0000-dea3-a5648c150000 pid=5516 execve guuid=b7e403ec-2600-0000-dea3-a5648e150000 pid=5518 /usr/bin/dash guuid=fd38f2ea-1800-0000-dea3-a5645f0b0000 pid=2911->guuid=b7e403ec-2600-0000-dea3-a5648e150000 pid=5518 execve guuid=2fc330eb-1800-0000-dea3-a564650b0000 pid=2917 /usr/bin/wget dns net send-data guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912->guuid=2fc330eb-1800-0000-dea3-a564650b0000 pid=2917 execve guuid=89138cf1-1800-0000-dea3-a5646b0b0000 pid=2923 /usr/bin/chmod guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912->guuid=89138cf1-1800-0000-dea3-a5646b0b0000 pid=2923 execve guuid=9b68f3f1-1800-0000-dea3-a5646c0b0000 pid=2924 /home/sandbox/..... guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912->guuid=9b68f3f1-1800-0000-dea3-a5646c0b0000 pid=2924 execve guuid=5becdff2-1800-0000-dea3-a5646f0b0000 pid=2927 /usr/bin/rm delete-file guuid=36aaf4ea-1800-0000-dea3-a564600b0000 pid=2912->guuid=5becdff2-1800-0000-dea3-a5646f0b0000 pid=2927 execve guuid=631c05eb-1800-0000-dea3-a564630b0000 pid=2915 /tmp/sample.bin net send-data zombie guuid=aac1faea-1800-0000-dea3-a564620b0000 pid=2914->guuid=631c05eb-1800-0000-dea3-a564630b0000 pid=2915 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=631c05eb-1800-0000-dea3-a564630b0000 pid=2915->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 9B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=2fc330eb-1800-0000-dea3-a564650b0000 pid=2917->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=fd08b51a-1900-0000-dea3-a564b90b0000 pid=3001 /usr/bin/pgrep guuid=977d6c1a-1900-0000-dea3-a564b80b0000 pid=3000->guuid=fd08b51a-1900-0000-dea3-a564b90b0000 pid=3001 execve guuid=e652ea1e-1900-0000-dea3-a564c20b0000 pid=3010 /usr/bin/killall guuid=354fad1e-1900-0000-dea3-a564c00b0000 pid=3008->guuid=e652ea1e-1900-0000-dea3-a564c20b0000 pid=3010 execve guuid=13497a20-1900-0000-dea3-a564c80b0000 pid=3016 /usr/bin/killall guuid=c6cb2e20-1900-0000-dea3-a564c60b0000 pid=3014->guuid=13497a20-1900-0000-dea3-a564c80b0000 pid=3016 execve guuid=c5ab8421-1900-0000-dea3-a564cc0b0000 pid=3020 /usr/bin/killall guuid=9d925221-1900-0000-dea3-a564cb0b0000 pid=3019->guuid=c5ab8421-1900-0000-dea3-a564cc0b0000 pid=3020 execve guuid=122aad22-1900-0000-dea3-a564d10b0000 pid=3025 /usr/bin/killall guuid=32df7e22-1900-0000-dea3-a564cf0b0000 pid=3023->guuid=122aad22-1900-0000-dea3-a564d10b0000 pid=3025 execve guuid=975fc023-1900-0000-dea3-a564d40b0000 pid=3028 /usr/bin/killall guuid=48358123-1900-0000-dea3-a564d30b0000 pid=3027->guuid=975fc023-1900-0000-dea3-a564d40b0000 pid=3028 execve guuid=e035c524-1900-0000-dea3-a564d90b0000 pid=3033 /usr/bin/killall guuid=c4129a24-1900-0000-dea3-a564d70b0000 pid=3031->guuid=e035c524-1900-0000-dea3-a564d90b0000 pid=3033 execve guuid=ff66c125-1900-0000-dea3-a564de0b0000 pid=3038 /usr/bin/killall guuid=793c9925-1900-0000-dea3-a564dc0b0000 pid=3036->guuid=ff66c125-1900-0000-dea3-a564de0b0000 pid=3038 execve guuid=2aaab826-1900-0000-dea3-a564e30b0000 pid=3043 /usr/bin/killall guuid=593f7e26-1900-0000-dea3-a564e10b0000 pid=3041->guuid=2aaab826-1900-0000-dea3-a564e30b0000 pid=3043 execve guuid=5671dc75-1a00-0000-dea3-a564480e0000 pid=3656 /usr/bin/pgrep guuid=eee87775-1a00-0000-dea3-a564460e0000 pid=3654->guuid=5671dc75-1a00-0000-dea3-a564480e0000 pid=3656 execve guuid=12fa4d7a-1a00-0000-dea3-a564530e0000 pid=3667 /usr/bin/killall guuid=6312fe79-1a00-0000-dea3-a564510e0000 pid=3665->guuid=12fa4d7a-1a00-0000-dea3-a564530e0000 pid=3667 execve guuid=ae1e1d7b-1a00-0000-dea3-a564570e0000 pid=3671 /usr/bin/killall guuid=7eabf97a-1a00-0000-dea3-a564560e0000 pid=3670->guuid=ae1e1d7b-1a00-0000-dea3-a564570e0000 pid=3671 execve guuid=1cb48b7c-1a00-0000-dea3-a5645b0e0000 pid=3675 /usr/bin/killall guuid=0e2e607c-1a00-0000-dea3-a5645a0e0000 pid=3674->guuid=1cb48b7c-1a00-0000-dea3-a5645b0e0000 pid=3675 execve guuid=e429a97d-1a00-0000-dea3-a564620e0000 pid=3682 /usr/bin/killall guuid=5bf8827d-1a00-0000-dea3-a564600e0000 pid=3680->guuid=e429a97d-1a00-0000-dea3-a564620e0000 pid=3682 execve guuid=aeb2bc7e-1a00-0000-dea3-a564680e0000 pid=3688 /usr/bin/killall guuid=edd2957e-1a00-0000-dea3-a564660e0000 pid=3686->guuid=aeb2bc7e-1a00-0000-dea3-a564680e0000 pid=3688 execve guuid=520fe57f-1a00-0000-dea3-a5646e0e0000 pid=3694 /usr/bin/killall guuid=fa58b27f-1a00-0000-dea3-a5646d0e0000 pid=3693->guuid=520fe57f-1a00-0000-dea3-a5646e0e0000 pid=3694 execve guuid=c229f280-1a00-0000-dea3-a564760e0000 pid=3702 /usr/bin/killall guuid=5c58b380-1a00-0000-dea3-a564720e0000 pid=3698->guuid=c229f280-1a00-0000-dea3-a564760e0000 pid=3702 execve guuid=7ac74482-1a00-0000-dea3-a5647e0e0000 pid=3710 /usr/bin/killall guuid=d1152182-1a00-0000-dea3-a5647d0e0000 pid=3709->guuid=7ac74482-1a00-0000-dea3-a5647e0e0000 pid=3710 execve guuid=725200ae-1b00-0000-dea3-a56495110000 pid=4501 /usr/bin/pgrep guuid=5137c0ad-1b00-0000-dea3-a56494110000 pid=4500->guuid=725200ae-1b00-0000-dea3-a56495110000 pid=4501 execve guuid=4b872eb2-1b00-0000-dea3-a564a7110000 pid=4519 /usr/bin/killall guuid=8f07fcb1-1b00-0000-dea3-a564a6110000 pid=4518->guuid=4b872eb2-1b00-0000-dea3-a564a7110000 pid=4519 execve guuid=8ead07b3-1b00-0000-dea3-a564a9110000 pid=4521 /usr/bin/killall guuid=8fffddb2-1b00-0000-dea3-a564a8110000 pid=4520->guuid=8ead07b3-1b00-0000-dea3-a564a9110000 pid=4521 execve guuid=4199f1b3-1b00-0000-dea3-a564ab110000 pid=4523 /usr/bin/killall guuid=1388b8b3-1b00-0000-dea3-a564aa110000 pid=4522->guuid=4199f1b3-1b00-0000-dea3-a564ab110000 pid=4523 execve guuid=b314d5b4-1b00-0000-dea3-a564b2110000 pid=4530 /usr/bin/killall guuid=860ba6b4-1b00-0000-dea3-a564ae110000 pid=4526->guuid=b314d5b4-1b00-0000-dea3-a564b2110000 pid=4530 execve guuid=700401b6-1b00-0000-dea3-a564b9110000 pid=4537 /usr/bin/killall guuid=4f31cbb5-1b00-0000-dea3-a564b7110000 pid=4535->guuid=700401b6-1b00-0000-dea3-a564b9110000 pid=4537 execve guuid=8d3273b7-1b00-0000-dea3-a564c2110000 pid=4546 /usr/bin/killall guuid=f74646b7-1b00-0000-dea3-a564c1110000 pid=4545->guuid=8d3273b7-1b00-0000-dea3-a564c2110000 pid=4546 execve guuid=7d6f47b8-1b00-0000-dea3-a564cb110000 pid=4555 /usr/bin/killall guuid=520522b8-1b00-0000-dea3-a564c7110000 pid=4551->guuid=7d6f47b8-1b00-0000-dea3-a564cb110000 pid=4555 execve guuid=bf9d2cb9-1b00-0000-dea3-a564cf110000 pid=4559 /usr/bin/killall guuid=9e8c05b9-1b00-0000-dea3-a564cd110000 pid=4557->guuid=bf9d2cb9-1b00-0000-dea3-a564cf110000 pid=4559 execve guuid=f76142f7-1c00-0000-dea3-a564c6140000 pid=5318 /usr/bin/pgrep guuid=a81ce4f6-1c00-0000-dea3-a564c5140000 pid=5317->guuid=f76142f7-1c00-0000-dea3-a564c6140000 pid=5318 execve guuid=72f13afa-1c00-0000-dea3-a564c8140000 pid=5320 /usr/bin/killall guuid=bc6803fa-1c00-0000-dea3-a564c7140000 pid=5319->guuid=72f13afa-1c00-0000-dea3-a564c8140000 pid=5320 execve guuid=57d73afb-1c00-0000-dea3-a564ca140000 pid=5322 /usr/bin/killall guuid=d395f9fa-1c00-0000-dea3-a564c9140000 pid=5321->guuid=57d73afb-1c00-0000-dea3-a564ca140000 pid=5322 execve guuid=89b446fc-1c00-0000-dea3-a564cc140000 pid=5324 /usr/bin/killall guuid=5ca9fdfb-1c00-0000-dea3-a564cb140000 pid=5323->guuid=89b446fc-1c00-0000-dea3-a564cc140000 pid=5324 execve guuid=6f9f54fd-1c00-0000-dea3-a564ce140000 pid=5326 /usr/bin/killall guuid=ffcc19fd-1c00-0000-dea3-a564cd140000 pid=5325->guuid=6f9f54fd-1c00-0000-dea3-a564ce140000 pid=5326 execve guuid=8b4899fe-1c00-0000-dea3-a564d0140000 pid=5328 /usr/bin/killall guuid=c4bb41fe-1c00-0000-dea3-a564cf140000 pid=5327->guuid=8b4899fe-1c00-0000-dea3-a564d0140000 pid=5328 execve guuid=c8c1d9ff-1c00-0000-dea3-a564d2140000 pid=5330 /usr/bin/killall guuid=89009bff-1c00-0000-dea3-a564d1140000 pid=5329->guuid=c8c1d9ff-1c00-0000-dea3-a564d2140000 pid=5330 execve guuid=2a77fb00-1d00-0000-dea3-a564d4140000 pid=5332 /usr/bin/killall guuid=ea96b000-1d00-0000-dea3-a564d3140000 pid=5331->guuid=2a77fb00-1d00-0000-dea3-a564d4140000 pid=5332 execve guuid=e6af2d02-1d00-0000-dea3-a564d6140000 pid=5334 /usr/bin/killall guuid=83f7ec01-1d00-0000-dea3-a564d5140000 pid=5333->guuid=e6af2d02-1d00-0000-dea3-a564d6140000 pid=5334 execve guuid=9c37262e-1e00-0000-dea3-a564ea140000 pid=5354 /usr/bin/pgrep guuid=e718a02d-1e00-0000-dea3-a564e9140000 pid=5353->guuid=9c37262e-1e00-0000-dea3-a564ea140000 pid=5354 execve guuid=ad3f9c34-1e00-0000-dea3-a564ec140000 pid=5356 /usr/bin/killall guuid=47945034-1e00-0000-dea3-a564eb140000 pid=5355->guuid=ad3f9c34-1e00-0000-dea3-a564ec140000 pid=5356 execve guuid=bbd75236-1e00-0000-dea3-a564ee140000 pid=5358 /usr/bin/killall guuid=28af0236-1e00-0000-dea3-a564ed140000 pid=5357->guuid=bbd75236-1e00-0000-dea3-a564ee140000 pid=5358 execve guuid=f74afd37-1e00-0000-dea3-a564f0140000 pid=5360 /usr/bin/killall guuid=c9c5bd37-1e00-0000-dea3-a564ef140000 pid=5359->guuid=f74afd37-1e00-0000-dea3-a564f0140000 pid=5360 execve guuid=6a21113a-1e00-0000-dea3-a564f2140000 pid=5362 /usr/bin/killall guuid=d024c939-1e00-0000-dea3-a564f1140000 pid=5361->guuid=6a21113a-1e00-0000-dea3-a564f2140000 pid=5362 execve guuid=8940963b-1e00-0000-dea3-a564f4140000 pid=5364 /usr/bin/killall guuid=561b533b-1e00-0000-dea3-a564f3140000 pid=5363->guuid=8940963b-1e00-0000-dea3-a564f4140000 pid=5364 execve guuid=4ecf1d3d-1e00-0000-dea3-a564f6140000 pid=5366 /usr/bin/killall guuid=0363de3c-1e00-0000-dea3-a564f5140000 pid=5365->guuid=4ecf1d3d-1e00-0000-dea3-a564f6140000 pid=5366 execve guuid=2bba3b3f-1e00-0000-dea3-a564f8140000 pid=5368 /usr/bin/killall guuid=e7ce703e-1e00-0000-dea3-a564f7140000 pid=5367->guuid=2bba3b3f-1e00-0000-dea3-a564f8140000 pid=5368 execve guuid=db75ba48-1e00-0000-dea3-a564fa140000 pid=5370 /usr/bin/killall guuid=b2d97248-1e00-0000-dea3-a564f9140000 pid=5369->guuid=db75ba48-1e00-0000-dea3-a564fa140000 pid=5370 execve guuid=7aae6677-1f00-0000-dea3-a56409150000 pid=5385 /usr/bin/pgrep guuid=55080f77-1f00-0000-dea3-a56408150000 pid=5384->guuid=7aae6677-1f00-0000-dea3-a56409150000 pid=5385 execve guuid=69415e7a-1f00-0000-dea3-a5640b150000 pid=5387 /usr/bin/killall guuid=861f267a-1f00-0000-dea3-a5640a150000 pid=5386->guuid=69415e7a-1f00-0000-dea3-a5640b150000 pid=5387 execve guuid=0f6c1d7c-1f00-0000-dea3-a5640d150000 pid=5389 /usr/bin/killall guuid=a7a7c37b-1f00-0000-dea3-a5640c150000 pid=5388->guuid=0f6c1d7c-1f00-0000-dea3-a5640d150000 pid=5389 execve guuid=1def817d-1f00-0000-dea3-a5640f150000 pid=5391 /usr/bin/killall guuid=28d93f7d-1f00-0000-dea3-a5640e150000 pid=5390->guuid=1def817d-1f00-0000-dea3-a5640f150000 pid=5391 execve guuid=7fef277f-1f00-0000-dea3-a56411150000 pid=5393 /usr/bin/killall guuid=bf63e67e-1f00-0000-dea3-a56410150000 pid=5392->guuid=7fef277f-1f00-0000-dea3-a56411150000 pid=5393 execve guuid=d7d34280-1f00-0000-dea3-a56413150000 pid=5395 /usr/bin/killall guuid=c36a1580-1f00-0000-dea3-a56412150000 pid=5394->guuid=d7d34280-1f00-0000-dea3-a56413150000 pid=5395 execve guuid=45a51881-1f00-0000-dea3-a56415150000 pid=5397 /usr/bin/killall guuid=3428eb80-1f00-0000-dea3-a56414150000 pid=5396->guuid=45a51881-1f00-0000-dea3-a56415150000 pid=5397 execve guuid=fde0e881-1f00-0000-dea3-a56417150000 pid=5399 /usr/bin/killall guuid=949ac181-1f00-0000-dea3-a56416150000 pid=5398->guuid=fde0e881-1f00-0000-dea3-a56417150000 pid=5399 execve guuid=46f4ce82-1f00-0000-dea3-a56419150000 pid=5401 /usr/bin/killall guuid=4cff9e82-1f00-0000-dea3-a56418150000 pid=5400->guuid=46f4ce82-1f00-0000-dea3-a56419150000 pid=5401 execve guuid=056caaae-2000-0000-dea3-a5641b150000 pid=5403 /usr/bin/pgrep guuid=fc7a63ae-2000-0000-dea3-a5641a150000 pid=5402->guuid=056caaae-2000-0000-dea3-a5641b150000 pid=5403 execve guuid=439928b3-2000-0000-dea3-a5641d150000 pid=5405 /usr/bin/killall guuid=a2a7edb2-2000-0000-dea3-a5641c150000 pid=5404->guuid=439928b3-2000-0000-dea3-a5641d150000 pid=5405 execve guuid=d6c2e5b4-2000-0000-dea3-a5641f150000 pid=5407 /usr/bin/killall guuid=a08191b4-2000-0000-dea3-a5641e150000 pid=5406->guuid=d6c2e5b4-2000-0000-dea3-a5641f150000 pid=5407 execve guuid=15f6c7b6-2000-0000-dea3-a56421150000 pid=5409 /usr/bin/killall guuid=b6e963b6-2000-0000-dea3-a56420150000 pid=5408->guuid=15f6c7b6-2000-0000-dea3-a56421150000 pid=5409 execve guuid=09808fb8-2000-0000-dea3-a56423150000 pid=5411 /usr/bin/killall guuid=3a0b39b8-2000-0000-dea3-a56422150000 pid=5410->guuid=09808fb8-2000-0000-dea3-a56423150000 pid=5411 execve guuid=9ba552ba-2000-0000-dea3-a56425150000 pid=5413 /usr/bin/killall guuid=8c45f5b9-2000-0000-dea3-a56424150000 pid=5412->guuid=9ba552ba-2000-0000-dea3-a56425150000 pid=5413 execve guuid=b24b28bc-2000-0000-dea3-a56427150000 pid=5415 /usr/bin/killall guuid=f445d3bb-2000-0000-dea3-a56426150000 pid=5414->guuid=b24b28bc-2000-0000-dea3-a56427150000 pid=5415 execve guuid=a686d6bd-2000-0000-dea3-a56429150000 pid=5417 /usr/bin/killall guuid=21e482bd-2000-0000-dea3-a56428150000 pid=5416->guuid=a686d6bd-2000-0000-dea3-a56429150000 pid=5417 execve guuid=89e693bf-2000-0000-dea3-a5642b150000 pid=5419 /usr/bin/killall guuid=3bb03dbf-2000-0000-dea3-a5642a150000 pid=5418->guuid=89e693bf-2000-0000-dea3-a5642b150000 pid=5419 execve guuid=2987daeb-2100-0000-dea3-a5642d150000 pid=5421 /usr/bin/pgrep guuid=4cca70eb-2100-0000-dea3-a5642c150000 pid=5420->guuid=2987daeb-2100-0000-dea3-a5642d150000 pid=5421 execve guuid=553a43f0-2100-0000-dea3-a5642f150000 pid=5423 /usr/bin/killall guuid=166f02f0-2100-0000-dea3-a5642e150000 pid=5422->guuid=553a43f0-2100-0000-dea3-a5642f150000 pid=5423 execve guuid=b4ccf5f1-2100-0000-dea3-a56431150000 pid=5425 /usr/bin/killall guuid=65849bf1-2100-0000-dea3-a56430150000 pid=5424->guuid=b4ccf5f1-2100-0000-dea3-a56431150000 pid=5425 execve guuid=17cfc3f3-2100-0000-dea3-a56433150000 pid=5427 /usr/bin/killall guuid=3d256cf3-2100-0000-dea3-a56432150000 pid=5426->guuid=17cfc3f3-2100-0000-dea3-a56433150000 pid=5427 execve guuid=cb7f84f5-2100-0000-dea3-a56435150000 pid=5429 /usr/bin/killall guuid=208f2df5-2100-0000-dea3-a56434150000 pid=5428->guuid=cb7f84f5-2100-0000-dea3-a56435150000 pid=5429 execve guuid=f0782df7-2100-0000-dea3-a56437150000 pid=5431 /usr/bin/killall guuid=4003d4f6-2100-0000-dea3-a56436150000 pid=5430->guuid=f0782df7-2100-0000-dea3-a56437150000 pid=5431 execve guuid=791335f9-2100-0000-dea3-a56439150000 pid=5433 /usr/bin/killall guuid=ed56c7f8-2100-0000-dea3-a56438150000 pid=5432->guuid=791335f9-2100-0000-dea3-a56439150000 pid=5433 execve guuid=cc2303fb-2100-0000-dea3-a5643b150000 pid=5435 /usr/bin/killall guuid=374597fa-2100-0000-dea3-a5643a150000 pid=5434->guuid=cc2303fb-2100-0000-dea3-a5643b150000 pid=5435 execve guuid=4519d7fc-2100-0000-dea3-a5643d150000 pid=5437 /usr/bin/killall guuid=78155afc-2100-0000-dea3-a5643c150000 pid=5436->guuid=4519d7fc-2100-0000-dea3-a5643d150000 pid=5437 execve guuid=60933029-2300-0000-dea3-a5643f150000 pid=5439 /usr/bin/pgrep guuid=c428b028-2300-0000-dea3-a5643e150000 pid=5438->guuid=60933029-2300-0000-dea3-a5643f150000 pid=5439 execve guuid=eb17362d-2300-0000-dea3-a56441150000 pid=5441 /usr/bin/killall guuid=1b30c32c-2300-0000-dea3-a56440150000 pid=5440->guuid=eb17362d-2300-0000-dea3-a56441150000 pid=5441 execve guuid=49175e2e-2300-0000-dea3-a56443150000 pid=5443 /usr/bin/killall guuid=5e7a222e-2300-0000-dea3-a56442150000 pid=5442->guuid=49175e2e-2300-0000-dea3-a56443150000 pid=5443 execve guuid=1afa0b30-2300-0000-dea3-a56445150000 pid=5445 /usr/bin/killall guuid=7bdacd2f-2300-0000-dea3-a56444150000 pid=5444->guuid=1afa0b30-2300-0000-dea3-a56445150000 pid=5445 execve guuid=80b9c531-2300-0000-dea3-a56447150000 pid=5447 /usr/bin/killall guuid=716c7231-2300-0000-dea3-a56446150000 pid=5446->guuid=80b9c531-2300-0000-dea3-a56447150000 pid=5447 execve guuid=bdba3633-2300-0000-dea3-a56449150000 pid=5449 /usr/bin/killall guuid=4cabe832-2300-0000-dea3-a56448150000 pid=5448->guuid=bdba3633-2300-0000-dea3-a56449150000 pid=5449 execve guuid=629ded34-2300-0000-dea3-a5644b150000 pid=5451 /usr/bin/killall guuid=11129b34-2300-0000-dea3-a5644a150000 pid=5450->guuid=629ded34-2300-0000-dea3-a5644b150000 pid=5451 execve guuid=df839936-2300-0000-dea3-a5644d150000 pid=5453 /usr/bin/killall guuid=00364b36-2300-0000-dea3-a5644c150000 pid=5452->guuid=df839936-2300-0000-dea3-a5644d150000 pid=5453 execve guuid=2e892738-2300-0000-dea3-a5644f150000 pid=5455 /usr/bin/killall guuid=472ed937-2300-0000-dea3-a5644e150000 pid=5454->guuid=2e892738-2300-0000-dea3-a5644f150000 pid=5455 execve guuid=0d216d64-2400-0000-dea3-a56451150000 pid=5457 /usr/bin/pgrep guuid=b9f61264-2400-0000-dea3-a56450150000 pid=5456->guuid=0d216d64-2400-0000-dea3-a56451150000 pid=5457 execve guuid=7db05c68-2400-0000-dea3-a56453150000 pid=5459 /usr/bin/killall guuid=e97c0b68-2400-0000-dea3-a56452150000 pid=5458->guuid=7db05c68-2400-0000-dea3-a56453150000 pid=5459 execve guuid=b4d28969-2400-0000-dea3-a56455150000 pid=5461 /usr/bin/killall guuid=c99a4b69-2400-0000-dea3-a56454150000 pid=5460->guuid=b4d28969-2400-0000-dea3-a56455150000 pid=5461 execve guuid=4454186b-2400-0000-dea3-a56457150000 pid=5463 /usr/bin/killall guuid=2aedd66a-2400-0000-dea3-a56456150000 pid=5462->guuid=4454186b-2400-0000-dea3-a56457150000 pid=5463 execve guuid=77bfac6c-2400-0000-dea3-a56459150000 pid=5465 /usr/bin/killall guuid=454a6d6c-2400-0000-dea3-a56458150000 pid=5464->guuid=77bfac6c-2400-0000-dea3-a56459150000 pid=5465 execve guuid=fcd0616e-2400-0000-dea3-a5645b150000 pid=5467 /usr/bin/killall guuid=574e0e6e-2400-0000-dea3-a5645a150000 pid=5466->guuid=fcd0616e-2400-0000-dea3-a5645b150000 pid=5467 execve guuid=b872b26f-2400-0000-dea3-a5645d150000 pid=5469 /usr/bin/killall guuid=d230596f-2400-0000-dea3-a5645c150000 pid=5468->guuid=b872b26f-2400-0000-dea3-a5645d150000 pid=5469 execve guuid=44a04b71-2400-0000-dea3-a5645f150000 pid=5471 /usr/bin/killall guuid=ba9af570-2400-0000-dea3-a5645e150000 pid=5470->guuid=44a04b71-2400-0000-dea3-a5645f150000 pid=5471 execve guuid=2d0bdc72-2400-0000-dea3-a56461150000 pid=5473 /usr/bin/killall guuid=91548372-2400-0000-dea3-a56460150000 pid=5472->guuid=2d0bdc72-2400-0000-dea3-a56461150000 pid=5473 execve guuid=6b6e269f-2500-0000-dea3-a56463150000 pid=5475 /usr/bin/pgrep guuid=ae77c29e-2500-0000-dea3-a56462150000 pid=5474->guuid=6b6e269f-2500-0000-dea3-a56463150000 pid=5475 execve guuid=59a027a3-2500-0000-dea3-a56465150000 pid=5477 /usr/bin/killall guuid=1330d6a2-2500-0000-dea3-a56464150000 pid=5476->guuid=59a027a3-2500-0000-dea3-a56465150000 pid=5477 execve guuid=fb1826a4-2500-0000-dea3-a56467150000 pid=5479 /usr/bin/killall guuid=3e5af8a3-2500-0000-dea3-a56466150000 pid=5478->guuid=fb1826a4-2500-0000-dea3-a56467150000 pid=5479 execve guuid=2761eba5-2500-0000-dea3-a56469150000 pid=5481 /usr/bin/killall guuid=7bbb90a5-2500-0000-dea3-a56468150000 pid=5480->guuid=2761eba5-2500-0000-dea3-a56469150000 pid=5481 execve guuid=1a2c5aa7-2500-0000-dea3-a5646b150000 pid=5483 /usr/bin/killall guuid=e8a0f8a6-2500-0000-dea3-a5646a150000 pid=5482->guuid=1a2c5aa7-2500-0000-dea3-a5646b150000 pid=5483 execve guuid=b36550a9-2500-0000-dea3-a5646d150000 pid=5485 /usr/bin/killall guuid=a4cd0da9-2500-0000-dea3-a5646c150000 pid=5484->guuid=b36550a9-2500-0000-dea3-a5646d150000 pid=5485 execve guuid=4193fdaa-2500-0000-dea3-a5646f150000 pid=5487 /usr/bin/killall guuid=9098acaa-2500-0000-dea3-a5646e150000 pid=5486->guuid=4193fdaa-2500-0000-dea3-a5646f150000 pid=5487 execve guuid=422959ac-2500-0000-dea3-a56471150000 pid=5489 /usr/bin/killall guuid=6b5ffeab-2500-0000-dea3-a56470150000 pid=5488->guuid=422959ac-2500-0000-dea3-a56471150000 pid=5489 execve guuid=799fb9ad-2500-0000-dea3-a56473150000 pid=5491 /usr/bin/killall guuid=1c4576ad-2500-0000-dea3-a56472150000 pid=5490->guuid=799fb9ad-2500-0000-dea3-a56473150000 pid=5491 execve guuid=8d0135da-2600-0000-dea3-a56477150000 pid=5495 /usr/bin/pgrep guuid=107094d9-2600-0000-dea3-a56476150000 pid=5494->guuid=8d0135da-2600-0000-dea3-a56477150000 pid=5495 execve guuid=c701c3e1-2600-0000-dea3-a5647a150000 pid=5498 /usr/bin/killall guuid=3c6e77e1-2600-0000-dea3-a56478150000 pid=5496->guuid=c701c3e1-2600-0000-dea3-a5647a150000 pid=5498 execve guuid=23df90e3-2600-0000-dea3-a56480150000 pid=5504 /usr/bin/killall guuid=a9d746e3-2600-0000-dea3-a5647e150000 pid=5502->guuid=23df90e3-2600-0000-dea3-a56480150000 pid=5504 execve guuid=96e635e5-2600-0000-dea3-a56484150000 pid=5508 /usr/bin/killall guuid=5bc5eae4-2600-0000-dea3-a56482150000 pid=5506->guuid=96e635e5-2600-0000-dea3-a56484150000 pid=5508 execve guuid=6aa08be6-2600-0000-dea3-a56486150000 pid=5510 /usr/bin/killall guuid=36b650e6-2600-0000-dea3-a56485150000 pid=5509->guuid=6aa08be6-2600-0000-dea3-a56486150000 pid=5510 execve guuid=2758ebe7-2600-0000-dea3-a56488150000 pid=5512 /usr/bin/killall guuid=3474aee7-2600-0000-dea3-a56487150000 pid=5511->guuid=2758ebe7-2600-0000-dea3-a56488150000 pid=5512 execve guuid=9ffa8ce9-2600-0000-dea3-a5648b150000 pid=5515 /usr/bin/killall guuid=62033de9-2600-0000-dea3-a5648a150000 pid=5514->guuid=9ffa8ce9-2600-0000-dea3-a5648b150000 pid=5515 execve guuid=e37a3ceb-2600-0000-dea3-a5648d150000 pid=5517 /usr/bin/killall guuid=78cb10eb-2600-0000-dea3-a5648c150000 pid=5516->guuid=e37a3ceb-2600-0000-dea3-a5648d150000 pid=5517 execve guuid=30f429ec-2600-0000-dea3-a5648f150000 pid=5519 /usr/bin/killall guuid=b7e403ec-2600-0000-dea3-a5648e150000 pid=5518->guuid=30f429ec-2600-0000-dea3-a5648f150000 pid=5519 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample tries to kill multiple processes (SIGKILL)
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1732269 Sample: ssh.elf Startdate: 10/07/2025 Architecture: LINUX Score: 100 38 206.123.128.67, 52842, 52844, 52846 LEASEWEB-USA-NYC-11US United States 2->38 40 54.217.10.153, 443, 49566 AMAZON-02US United States 2->40 42 2 other IPs or domains 2->42 44 Suricata IDS alerts for network traffic 2->44 46 Malicious sample detected (through community Yara rule) 2->46 48 Antivirus / Scanner detection for submitted sample 2->48 50 5 other signatures 2->50 9 ssh.elf 2->9         started        signatures3 process4 signatures5 54 Opens /proc/net/* files useful for finding connected devices and routers 9->54 12 ssh.elf 9->12         started        process6 signatures7 56 Sample tries to kill multiple processes (SIGKILL) 12->56 15 ssh.elf sh 12->15         started        17 ssh.elf sh 12->17         started        19 ssh.elf sh 12->19         started        21 59 other processes 12->21 process8 process9 23 sh killall 15->23         started        26 sh killall 17->26         started        28 sh killall 19->28         started        30 sh killall 21->30         started        32 sh killall 21->32         started        34 sh killall 21->34         started        36 56 other processes 21->36 signatures10 52 Terminates several processes with shell command 'killall' 23->52
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-09 23:48:23 UTC
File Type:
ELF64 Little (Exe)
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_a6a2adb9 Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_f3d83a74 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_e0673a90 Linux_Trojan_Gafgyt_a0a4de11 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_09c3070e Linux_Trojan_Gafgyt_46eec778 Linux_Trojan_Gafgyt_d996d335 Linux_Trojan_Gafgyt_d0c57a2e Linux_Trojan_Gafgyt_656bf077 Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_dd0d6173 Linux_Trojan_Gafgyt_779e142f Linux_Trojan_Gafgyt_cf84c9f2 Linux_Trojan_Gafgyt_0cd591cd Linux_Trojan_Gafgyt_33b4111a Linux_Trojan_Gafgyt_862c4e0e Linux_Trojan_Gafgyt_32eb0c81 Linux_Trojan_Gafgyt_a33a8363 Linux_Trojan_Mirai_3fe3c668 Linux_Trojan_Mirai_637f2c04 elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_46eec778
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_862c4e0e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_3fe3c668
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_637f2c04
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 0cc3feb64eb5d4e0f124361b8af0a1002da294fbf268794e44cf28f9bb89552a

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments