MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1cfed5e3963fd22823a63fe44ba533a014dff9528b44c9c2b620c81963d595ce. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 1cfed5e3963fd22823a63fe44ba533a014dff9528b44c9c2b620c81963d595ce
SHA3-384 hash: e7af6b5370e8556f65307e4d27733c79482cbb4545bfba4855c54f6a7ed0ab654e3c81f33db27b491e1c002c95fcb60e
SHA1 hash: 3232310db72ddc733ffa825bfec96025b930ab49
MD5 hash: 42566c3c0ed2ead8e191f6dbffebeca1
humanhash: may-cat-one-oxygen
File name:rondo.dcn.sh
Download: download sample
Signature Mirai
File size:13'784 bytes
First seen:2025-08-13 07:37:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:DUIzkLhZoC1NSNigJQKlTjPXzR1lBgMPhVVn2eB/HQ:DWX
TLSH T12C52588914D006F391DD494BB3C3DAAC6C49A1FFB0A3BEB9E864A8BFD530944B46D744
Magika shell
Reporter smica83
Tags:74-194-191-52 HUN sh
URLMalware sample (SHA256 hash)SignatureTags
http://74.194.191.52/rondo.loln/an/aelf ua-wget
http://74.194.191.52/rondo.armv6ln/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.armv5lbb0069de1a2b09dab1947e8c9a7668c422a6fbc188b41d6808b23f5396766296 RondoDoxelf geofenced ITA mirai RondoDox ua-wget
http://74.194.191.52/rondo.armv4ln/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.armv7ln/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.mipsel9424c99087c5ee58e153eb7e6ac57dad449093bee74ddeb12a5f1ca344a95a1e RondoDoxelf geofenced HUN mirai ua-wget
http://74.194.191.52/rondo.mipsn/an/aelf mirai ua-wget
http://74.194.191.52/rondo.x86_64n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.powerpcn/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.powerpc-440fpn/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.i686n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.i586n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.i486n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.fbsdamd64n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.fbsdi386n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.fbsdpowerpcn/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.fbsdarm64n/an/aelf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.arc700n/an/aCHE elf geofenced mirai ua-wget USA
http://74.194.191.52/rondo.sh4ee62ba350ea11f7f3d18db104eaa339ca21459c9e986859e356add6d95aa88b8 RondoDoxelf geofenced HUN mirai ua-wget
http://74.194.191.52/rondo.sparc0e8c75c260f3e61faa02cbe9b33546b86ace79b89725124b6f10f1809fabe764 RondoDoxDEU elf geofenced mirai ua-wget
http://74.194.191.52/rondo.m68kn/an/aelf geofenced HNG mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
HU HU
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=176c9926-1700-0000-f8e3-4b48a40c0000 pid=3236 /usr/bin/sudo guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242 /tmp/sample.bin write-file guuid=176c9926-1700-0000-f8e3-4b48a40c0000 pid=3236->guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242 execve guuid=6bd0a829-1700-0000-f8e3-4b48ab0c0000 pid=3243 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=6bd0a829-1700-0000-f8e3-4b48ab0c0000 pid=3243 execve guuid=38f6412b-1700-0000-f8e3-4b48ac0c0000 pid=3244 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=38f6412b-1700-0000-f8e3-4b48ac0c0000 pid=3244 execve guuid=fd8bd32b-1700-0000-f8e3-4b48ae0c0000 pid=3246 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=fd8bd32b-1700-0000-f8e3-4b48ae0c0000 pid=3246 execve guuid=2015c62c-1700-0000-f8e3-4b48af0c0000 pid=3247 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=2015c62c-1700-0000-f8e3-4b48af0c0000 pid=3247 execve guuid=1fb0412d-1700-0000-f8e3-4b48b00c0000 pid=3248 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=1fb0412d-1700-0000-f8e3-4b48b00c0000 pid=3248 execve guuid=2940ae2d-1700-0000-f8e3-4b48b30c0000 pid=3251 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=2940ae2d-1700-0000-f8e3-4b48b30c0000 pid=3251 execve guuid=ce400d2e-1700-0000-f8e3-4b48b50c0000 pid=3253 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=ce400d2e-1700-0000-f8e3-4b48b50c0000 pid=3253 execve guuid=1adb742e-1700-0000-f8e3-4b48b80c0000 pid=3256 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=1adb742e-1700-0000-f8e3-4b48b80c0000 pid=3256 execve guuid=d461da2e-1700-0000-f8e3-4b48ba0c0000 pid=3258 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=d461da2e-1700-0000-f8e3-4b48ba0c0000 pid=3258 execve guuid=e9bd402f-1700-0000-f8e3-4b48bd0c0000 pid=3261 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=e9bd402f-1700-0000-f8e3-4b48bd0c0000 pid=3261 execve guuid=ba42952f-1700-0000-f8e3-4b48bf0c0000 pid=3263 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=ba42952f-1700-0000-f8e3-4b48bf0c0000 pid=3263 execve guuid=c68bf12f-1700-0000-f8e3-4b48c20c0000 pid=3266 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=c68bf12f-1700-0000-f8e3-4b48c20c0000 pid=3266 execve guuid=ab63bb30-1700-0000-f8e3-4b48c60c0000 pid=3270 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=ab63bb30-1700-0000-f8e3-4b48c60c0000 pid=3270 execve guuid=72d83e31-1700-0000-f8e3-4b48c90c0000 pid=3273 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=72d83e31-1700-0000-f8e3-4b48c90c0000 pid=3273 execve guuid=cedcb731-1700-0000-f8e3-4b48cc0c0000 pid=3276 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=cedcb731-1700-0000-f8e3-4b48cc0c0000 pid=3276 execve guuid=450b3d32-1700-0000-f8e3-4b48cd0c0000 pid=3277 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=450b3d32-1700-0000-f8e3-4b48cd0c0000 pid=3277 execve guuid=5981bd32-1700-0000-f8e3-4b48cf0c0000 pid=3279 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=5981bd32-1700-0000-f8e3-4b48cf0c0000 pid=3279 execve guuid=25915833-1700-0000-f8e3-4b48d00c0000 pid=3280 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=25915833-1700-0000-f8e3-4b48d00c0000 pid=3280 execve guuid=cd5ed433-1700-0000-f8e3-4b48d20c0000 pid=3282 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=cd5ed433-1700-0000-f8e3-4b48d20c0000 pid=3282 execve guuid=e8d94734-1700-0000-f8e3-4b48d50c0000 pid=3285 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=e8d94734-1700-0000-f8e3-4b48d50c0000 pid=3285 execve guuid=444baa34-1700-0000-f8e3-4b48d70c0000 pid=3287 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=444baa34-1700-0000-f8e3-4b48d70c0000 pid=3287 execve guuid=48131335-1700-0000-f8e3-4b48da0c0000 pid=3290 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=48131335-1700-0000-f8e3-4b48da0c0000 pid=3290 execve guuid=f9b10a36-1700-0000-f8e3-4b48de0c0000 pid=3294 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=f9b10a36-1700-0000-f8e3-4b48de0c0000 pid=3294 execve guuid=04f16536-1700-0000-f8e3-4b48e10c0000 pid=3297 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=04f16536-1700-0000-f8e3-4b48e10c0000 pid=3297 execve guuid=63a5f336-1700-0000-f8e3-4b48e40c0000 pid=3300 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=63a5f336-1700-0000-f8e3-4b48e40c0000 pid=3300 execve guuid=04b56137-1700-0000-f8e3-4b48e70c0000 pid=3303 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=04b56137-1700-0000-f8e3-4b48e70c0000 pid=3303 execve guuid=1ba3d037-1700-0000-f8e3-4b48e90c0000 pid=3305 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=1ba3d037-1700-0000-f8e3-4b48e90c0000 pid=3305 execve guuid=8f002738-1700-0000-f8e3-4b48ec0c0000 pid=3308 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8f002738-1700-0000-f8e3-4b48ec0c0000 pid=3308 execve guuid=70958738-1700-0000-f8e3-4b48ed0c0000 pid=3309 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=70958738-1700-0000-f8e3-4b48ed0c0000 pid=3309 execve guuid=785bed38-1700-0000-f8e3-4b48ef0c0000 pid=3311 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=785bed38-1700-0000-f8e3-4b48ef0c0000 pid=3311 execve guuid=789f6a39-1700-0000-f8e3-4b48f00c0000 pid=3312 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=789f6a39-1700-0000-f8e3-4b48f00c0000 pid=3312 execve guuid=9d1bdc39-1700-0000-f8e3-4b48f10c0000 pid=3313 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=9d1bdc39-1700-0000-f8e3-4b48f10c0000 pid=3313 execve guuid=52c5403a-1700-0000-f8e3-4b48f30c0000 pid=3315 /usr/bin/ls guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=52c5403a-1700-0000-f8e3-4b48f30c0000 pid=3315 execve guuid=6c76ab3a-1700-0000-f8e3-4b48f60c0000 pid=3318 /usr/bin/systemctl guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=6c76ab3a-1700-0000-f8e3-4b48f60c0000 pid=3318 execve guuid=0a7f3f65-1800-0000-f8e3-4b48190e0000 pid=3609 /usr/bin/mount write-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0a7f3f65-1800-0000-f8e3-4b48190e0000 pid=3609 execve guuid=35ebe566-1800-0000-f8e3-4b481f0e0000 pid=3615 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=35ebe566-1800-0000-f8e3-4b481f0e0000 pid=3615 execve guuid=a589ea69-1800-0000-f8e3-4b482a0e0000 pid=3626 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=a589ea69-1800-0000-f8e3-4b482a0e0000 pid=3626 execve guuid=347f3c6a-1800-0000-f8e3-4b482c0e0000 pid=3628 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=347f3c6a-1800-0000-f8e3-4b482c0e0000 pid=3628 execve guuid=95ca886a-1800-0000-f8e3-4b482e0e0000 pid=3630 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=95ca886a-1800-0000-f8e3-4b482e0e0000 pid=3630 execve guuid=da8be36a-1800-0000-f8e3-4b48300e0000 pid=3632 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=da8be36a-1800-0000-f8e3-4b48300e0000 pid=3632 execve guuid=9664236b-1800-0000-f8e3-4b48320e0000 pid=3634 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=9664236b-1800-0000-f8e3-4b48320e0000 pid=3634 execve guuid=63ac716b-1800-0000-f8e3-4b48340e0000 pid=3636 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=63ac716b-1800-0000-f8e3-4b48340e0000 pid=3636 execve guuid=9375bc6b-1800-0000-f8e3-4b48350e0000 pid=3637 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=9375bc6b-1800-0000-f8e3-4b48350e0000 pid=3637 execve guuid=06621c6c-1800-0000-f8e3-4b48360e0000 pid=3638 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=06621c6c-1800-0000-f8e3-4b48360e0000 pid=3638 execve guuid=45325f6c-1800-0000-f8e3-4b48370e0000 pid=3639 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=45325f6c-1800-0000-f8e3-4b48370e0000 pid=3639 execve guuid=83cfa96c-1800-0000-f8e3-4b48390e0000 pid=3641 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=83cfa96c-1800-0000-f8e3-4b48390e0000 pid=3641 execve guuid=30f7e76c-1800-0000-f8e3-4b483b0e0000 pid=3643 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=30f7e76c-1800-0000-f8e3-4b483b0e0000 pid=3643 execve guuid=1910286d-1800-0000-f8e3-4b483d0e0000 pid=3645 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=1910286d-1800-0000-f8e3-4b483d0e0000 pid=3645 execve guuid=9a8f666d-1800-0000-f8e3-4b483f0e0000 pid=3647 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=9a8f666d-1800-0000-f8e3-4b483f0e0000 pid=3647 execve guuid=092aa56d-1800-0000-f8e3-4b48410e0000 pid=3649 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=092aa56d-1800-0000-f8e3-4b48410e0000 pid=3649 execve guuid=ba2bea6d-1800-0000-f8e3-4b48430e0000 pid=3651 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=ba2bea6d-1800-0000-f8e3-4b48430e0000 pid=3651 execve guuid=400d416e-1800-0000-f8e3-4b48450e0000 pid=3653 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=400d416e-1800-0000-f8e3-4b48450e0000 pid=3653 execve guuid=d426836e-1800-0000-f8e3-4b48460e0000 pid=3654 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=d426836e-1800-0000-f8e3-4b48460e0000 pid=3654 execve guuid=f813d46e-1800-0000-f8e3-4b48490e0000 pid=3657 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=f813d46e-1800-0000-f8e3-4b48490e0000 pid=3657 execve guuid=46bc166f-1800-0000-f8e3-4b484b0e0000 pid=3659 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=46bc166f-1800-0000-f8e3-4b484b0e0000 pid=3659 execve guuid=7a20626f-1800-0000-f8e3-4b484d0e0000 pid=3661 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=7a20626f-1800-0000-f8e3-4b484d0e0000 pid=3661 execve guuid=13e8ab6f-1800-0000-f8e3-4b484e0e0000 pid=3662 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=13e8ab6f-1800-0000-f8e3-4b484e0e0000 pid=3662 execve guuid=57e6ea6f-1800-0000-f8e3-4b48520e0000 pid=3666 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=57e6ea6f-1800-0000-f8e3-4b48520e0000 pid=3666 execve guuid=0e272570-1800-0000-f8e3-4b48530e0000 pid=3667 /usr/bin/mkdir guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0e272570-1800-0000-f8e3-4b48530e0000 pid=3667 execve guuid=0e457870-1800-0000-f8e3-4b48550e0000 pid=3669 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0e457870-1800-0000-f8e3-4b48550e0000 pid=3669 clone guuid=8abfd670-1800-0000-f8e3-4b48590e0000 pid=3673 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8abfd670-1800-0000-f8e3-4b48590e0000 pid=3673 execve guuid=8e241671-1800-0000-f8e3-4b485c0e0000 pid=3676 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8e241671-1800-0000-f8e3-4b485c0e0000 pid=3676 execve guuid=4d7a4e71-1800-0000-f8e3-4b485e0e0000 pid=3678 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=4d7a4e71-1800-0000-f8e3-4b485e0e0000 pid=3678 clone guuid=2c0b429f-1800-0000-f8e3-4b48cf0e0000 pid=3791 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=2c0b429f-1800-0000-f8e3-4b48cf0e0000 pid=3791 clone guuid=8107ed9f-1800-0000-f8e3-4b48d20e0000 pid=3794 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8107ed9f-1800-0000-f8e3-4b48d20e0000 pid=3794 execve guuid=ec3580a0-1800-0000-f8e3-4b48d50e0000 pid=3797 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=ec3580a0-1800-0000-f8e3-4b48d50e0000 pid=3797 clone guuid=5b6f11a1-1800-0000-f8e3-4b48d90e0000 pid=3801 /usr/bin/killall guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=5b6f11a1-1800-0000-f8e3-4b48d90e0000 pid=3801 execve guuid=a203f8ae-1800-0000-f8e3-4b48f50e0000 pid=3829 /usr/bin/pgrep guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=a203f8ae-1800-0000-f8e3-4b48f50e0000 pid=3829 execve guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841 execve guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843 execve guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864 execve guuid=94e158cc-1800-0000-f8e3-4b482a0f0000 pid=3882 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=94e158cc-1800-0000-f8e3-4b482a0f0000 pid=3882 clone guuid=a4e5d2cc-1800-0000-f8e3-4b48320f0000 pid=3890 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=a4e5d2cc-1800-0000-f8e3-4b48320f0000 pid=3890 execve guuid=efd610cd-1800-0000-f8e3-4b48340f0000 pid=3892 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=efd610cd-1800-0000-f8e3-4b48340f0000 pid=3892 clone guuid=81bce601-1900-0000-f8e3-4b48be0f0000 pid=4030 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=81bce601-1900-0000-f8e3-4b48be0f0000 pid=4030 clone guuid=38e87d02-1900-0000-f8e3-4b48c20f0000 pid=4034 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=38e87d02-1900-0000-f8e3-4b48c20f0000 pid=4034 execve guuid=0eb5f602-1900-0000-f8e3-4b48c30f0000 pid=4035 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0eb5f602-1900-0000-f8e3-4b48c30f0000 pid=4035 clone guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040 execve guuid=19d3f906-1900-0000-f8e3-4b48d40f0000 pid=4052 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=19d3f906-1900-0000-f8e3-4b48d40f0000 pid=4052 clone guuid=b9f57607-1900-0000-f8e3-4b48d70f0000 pid=4055 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=b9f57607-1900-0000-f8e3-4b48d70f0000 pid=4055 execve guuid=8573b407-1900-0000-f8e3-4b48d90f0000 pid=4057 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=8573b407-1900-0000-f8e3-4b48d90f0000 pid=4057 clone guuid=89b66345-1900-0000-f8e3-4b4870100000 pid=4208 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=89b66345-1900-0000-f8e3-4b4870100000 pid=4208 clone guuid=b7b1fd45-1900-0000-f8e3-4b4875100000 pid=4213 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=b7b1fd45-1900-0000-f8e3-4b4875100000 pid=4213 execve guuid=0ee47646-1900-0000-f8e3-4b4876100000 pid=4214 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0ee47646-1900-0000-f8e3-4b4876100000 pid=4214 clone guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217 execve guuid=c4639b4a-1900-0000-f8e3-4b488b100000 pid=4235 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=c4639b4a-1900-0000-f8e3-4b488b100000 pid=4235 clone guuid=889e444b-1900-0000-f8e3-4b488e100000 pid=4238 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=889e444b-1900-0000-f8e3-4b488e100000 pid=4238 execve guuid=6217914b-1900-0000-f8e3-4b4890100000 pid=4240 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=6217914b-1900-0000-f8e3-4b4890100000 pid=4240 clone guuid=a550bd99-1900-0000-f8e3-4b4856110000 pid=4438 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=a550bd99-1900-0000-f8e3-4b4856110000 pid=4438 clone guuid=2ce8599a-1900-0000-f8e3-4b4859110000 pid=4441 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=2ce8599a-1900-0000-f8e3-4b4859110000 pid=4441 execve guuid=169acf9a-1900-0000-f8e3-4b485b110000 pid=4443 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=169acf9a-1900-0000-f8e3-4b485b110000 pid=4443 clone guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448 execve guuid=9b5ec29e-1900-0000-f8e3-4b486c110000 pid=4460 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=9b5ec29e-1900-0000-f8e3-4b486c110000 pid=4460 clone guuid=75274c9f-1900-0000-f8e3-4b486f110000 pid=4463 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=75274c9f-1900-0000-f8e3-4b486f110000 pid=4463 clone guuid=5cbb90e2-1900-0000-f8e3-4b4811120000 pid=4625 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=5cbb90e2-1900-0000-f8e3-4b4811120000 pid=4625 clone guuid=f097fae2-1900-0000-f8e3-4b4813120000 pid=4627 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=f097fae2-1900-0000-f8e3-4b4813120000 pid=4627 execve guuid=af0c6ee3-1900-0000-f8e3-4b4816120000 pid=4630 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=af0c6ee3-1900-0000-f8e3-4b4816120000 pid=4630 clone guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636 execve guuid=1b582be7-1900-0000-f8e3-4b4827120000 pid=4647 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=1b582be7-1900-0000-f8e3-4b4827120000 pid=4647 clone guuid=3e2bd8e7-1900-0000-f8e3-4b482c120000 pid=4652 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=3e2bd8e7-1900-0000-f8e3-4b482c120000 pid=4652 execve guuid=c39f3ce8-1900-0000-f8e3-4b4830120000 pid=4656 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=c39f3ce8-1900-0000-f8e3-4b4830120000 pid=4656 clone guuid=09513826-1a00-0000-f8e3-4b48b3120000 pid=4787 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=09513826-1a00-0000-f8e3-4b48b3120000 pid=4787 clone guuid=e81ae526-1a00-0000-f8e3-4b48b5120000 pid=4789 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=e81ae526-1a00-0000-f8e3-4b48b5120000 pid=4789 execve guuid=82356827-1a00-0000-f8e3-4b48b6120000 pid=4790 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=82356827-1a00-0000-f8e3-4b48b6120000 pid=4790 clone guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792 execve guuid=b4cae72b-1a00-0000-f8e3-4b48bb120000 pid=4795 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=b4cae72b-1a00-0000-f8e3-4b48bb120000 pid=4795 clone guuid=2319c52c-1a00-0000-f8e3-4b48bd120000 pid=4797 /usr/bin/rm guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=2319c52c-1a00-0000-f8e3-4b48bd120000 pid=4797 execve guuid=3985182d-1a00-0000-f8e3-4b48be120000 pid=4798 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=3985182d-1a00-0000-f8e3-4b48be120000 pid=4798 clone guuid=e311ba5c-1a00-0000-f8e3-4b481a130000 pid=4890 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=e311ba5c-1a00-0000-f8e3-4b481a130000 pid=4890 clone guuid=07d2575d-1a00-0000-f8e3-4b481d130000 pid=4893 /usr/bin/rm delete-file guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=07d2575d-1a00-0000-f8e3-4b481d130000 pid=4893 execve guuid=0621db5d-1a00-0000-f8e3-4b4820130000 pid=4896 /usr/bin/dash guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=0621db5d-1a00-0000-f8e3-4b4820130000 pid=4896 clone guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899 /usr/bin/sudo net guuid=7f40e228-1700-0000-f8e3-4b48aa0c0000 pid=3242->guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899 execve guuid=84a6103b-1700-0000-f8e3-4b48f80c0000 pid=3320 /usr/bin/basename guuid=6c76ab3a-1700-0000-f8e3-4b48f60c0000 pid=3318->guuid=84a6103b-1700-0000-f8e3-4b48f80c0000 pid=3320 execve guuid=ec1d503b-1700-0000-f8e3-4b48fa0c0000 pid=3322 /usr/bin/basename guuid=6c76ab3a-1700-0000-f8e3-4b48f60c0000 pid=3318->guuid=ec1d503b-1700-0000-f8e3-4b48fa0c0000 pid=3322 execve guuid=6770993b-1700-0000-f8e3-4b48fc0c0000 pid=3324 /usr/bin/dash guuid=6c76ab3a-1700-0000-f8e3-4b48f60c0000 pid=3318->guuid=6770993b-1700-0000-f8e3-4b48fc0c0000 pid=3324 clone guuid=8d60a03b-1700-0000-f8e3-4b48fd0c0000 pid=3325 /usr/bin/systemctl guuid=6770993b-1700-0000-f8e3-4b48fc0c0000 pid=3324->guuid=8d60a03b-1700-0000-f8e3-4b48fd0c0000 pid=3325 execve guuid=2a06a63b-1700-0000-f8e3-4b48fe0c0000 pid=3326 /usr/bin/sed guuid=6770993b-1700-0000-f8e3-4b48fc0c0000 pid=3324->guuid=2a06a63b-1700-0000-f8e3-4b48fe0c0000 pid=3326 execve guuid=e0dd8470-1800-0000-f8e3-4b48570e0000 pid=3671 /usr/bin/chmod guuid=0e457870-1800-0000-f8e3-4b48550e0000 pid=3669->guuid=e0dd8470-1800-0000-f8e3-4b48570e0000 pid=3671 execve guuid=52905571-1800-0000-f8e3-4b485f0e0000 pid=3679 /usr/bin/wget net send-data write-file guuid=4d7a4e71-1800-0000-f8e3-4b485e0e0000 pid=3678->guuid=52905571-1800-0000-f8e3-4b485f0e0000 pid=3679 execve 3e7234c3-faf5-52ca-baba-2f6c79023ab4 74.194.191.52:80 guuid=52905571-1800-0000-f8e3-4b485f0e0000 pid=3679->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=11b5669f-1800-0000-f8e3-4b48d00e0000 pid=3792 /usr/bin/cat guuid=2c0b429f-1800-0000-f8e3-4b48cf0e0000 pid=3791->guuid=11b5669f-1800-0000-f8e3-4b48d00e0000 pid=3792 execve guuid=2eb78ba0-1800-0000-f8e3-4b48d60e0000 pid=3798 /usr/bin/chmod guuid=ec3580a0-1800-0000-f8e3-4b48d50e0000 pid=3797->guuid=2eb78ba0-1800-0000-f8e3-4b48d60e0000 pid=3798 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=2cb4d2c1-1800-0000-f8e3-4b48020f0000 pid=3842 /usr/bin/killall guuid=a0ad4bbf-1800-0000-f8e3-4b48010f0000 pid=3841->guuid=2cb4d2c1-1800-0000-f8e3-4b48020f0000 pid=3842 execve guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=3cd81bc6-1800-0000-f8e3-4b48080f0000 pid=3848 /usr/bin/pgrep guuid=8c71a4c3-1800-0000-f8e3-4b48030f0000 pid=3843->guuid=3cd81bc6-1800-0000-f8e3-4b48080f0000 pid=3848 execve guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=cc4079cb-1800-0000-f8e3-4b48240f0000 pid=3876 /usr/bin/lib/rondo guuid=cb3ccac9-1800-0000-f8e3-4b48180f0000 pid=3864->guuid=cc4079cb-1800-0000-f8e3-4b48240f0000 pid=3876 execve guuid=640922cd-1800-0000-f8e3-4b48360f0000 pid=3894 /usr/bin/wget net send-data write-file guuid=efd610cd-1800-0000-f8e3-4b48340f0000 pid=3892->guuid=640922cd-1800-0000-f8e3-4b48360f0000 pid=3894 execve guuid=640922cd-1800-0000-f8e3-4b48360f0000 pid=3894->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=21f5f401-1900-0000-f8e3-4b48bf0f0000 pid=4031 /usr/bin/cat guuid=81bce601-1900-0000-f8e3-4b48be0f0000 pid=4030->guuid=21f5f401-1900-0000-f8e3-4b48bf0f0000 pid=4031 execve guuid=d84c0503-1900-0000-f8e3-4b48c40f0000 pid=4036 /usr/bin/chmod guuid=0eb5f602-1900-0000-f8e3-4b48c30f0000 pid=4035->guuid=d84c0503-1900-0000-f8e3-4b48c40f0000 pid=4036 execve guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=51acb605-1900-0000-f8e3-4b48cf0f0000 pid=4047 /usr/bin/lib/rondo guuid=377b7003-1900-0000-f8e3-4b48c80f0000 pid=4040->guuid=51acb605-1900-0000-f8e3-4b48cf0f0000 pid=4047 execve guuid=c945bb07-1900-0000-f8e3-4b48da0f0000 pid=4058 /usr/bin/wget net send-data write-file guuid=8573b407-1900-0000-f8e3-4b48d90f0000 pid=4057->guuid=c945bb07-1900-0000-f8e3-4b48da0f0000 pid=4058 execve guuid=c945bb07-1900-0000-f8e3-4b48da0f0000 pid=4058->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=49ca7845-1900-0000-f8e3-4b4871100000 pid=4209 /usr/bin/cat guuid=89b66345-1900-0000-f8e3-4b4870100000 pid=4208->guuid=49ca7845-1900-0000-f8e3-4b4871100000 pid=4209 execve guuid=ffd28546-1900-0000-f8e3-4b4877100000 pid=4215 /usr/bin/chmod guuid=0ee47646-1900-0000-f8e3-4b4876100000 pid=4214->guuid=ffd28546-1900-0000-f8e3-4b4877100000 pid=4215 execve guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b2206449-1900-0000-f8e3-4b4882100000 pid=4226 /usr/bin/lib/rondo guuid=7aff0647-1900-0000-f8e3-4b4879100000 pid=4217->guuid=b2206449-1900-0000-f8e3-4b4882100000 pid=4226 execve guuid=27489a4b-1900-0000-f8e3-4b4892100000 pid=4242 /usr/bin/wget net send-data write-file guuid=6217914b-1900-0000-f8e3-4b4890100000 pid=4240->guuid=27489a4b-1900-0000-f8e3-4b4892100000 pid=4242 execve guuid=27489a4b-1900-0000-f8e3-4b4892100000 pid=4242->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=1d71cf99-1900-0000-f8e3-4b4857110000 pid=4439 /usr/bin/cat guuid=a550bd99-1900-0000-f8e3-4b4856110000 pid=4438->guuid=1d71cf99-1900-0000-f8e3-4b4857110000 pid=4439 execve guuid=5e2ce29a-1900-0000-f8e3-4b485c110000 pid=4444 /usr/bin/chmod guuid=169acf9a-1900-0000-f8e3-4b485b110000 pid=4443->guuid=5e2ce29a-1900-0000-f8e3-4b485c110000 pid=4444 execve guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=341dac9d-1900-0000-f8e3-4b4867110000 pid=4455 /usr/bin/lib/rondo guuid=583a6b9b-1900-0000-f8e3-4b4860110000 pid=4448->guuid=341dac9d-1900-0000-f8e3-4b4867110000 pid=4455 execve guuid=a0ef569f-1900-0000-f8e3-4b4870110000 pid=4464 /usr/bin/wget net send-data write-file guuid=75274c9f-1900-0000-f8e3-4b486f110000 pid=4463->guuid=a0ef569f-1900-0000-f8e3-4b4870110000 pid=4464 execve guuid=a0ef569f-1900-0000-f8e3-4b4870110000 pid=4464->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=9e3b9fe2-1900-0000-f8e3-4b4812120000 pid=4626 /usr/bin/cat guuid=5cbb90e2-1900-0000-f8e3-4b4811120000 pid=4625->guuid=9e3b9fe2-1900-0000-f8e3-4b4812120000 pid=4626 execve guuid=97357be3-1900-0000-f8e3-4b4817120000 pid=4631 /usr/bin/chmod guuid=af0c6ee3-1900-0000-f8e3-4b4816120000 pid=4630->guuid=97357be3-1900-0000-f8e3-4b4817120000 pid=4631 execve guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=9c3f08e6-1900-0000-f8e3-4b4823120000 pid=4643 /usr/bin/lib/rondo guuid=d9f7fce3-1900-0000-f8e3-4b481c120000 pid=4636->guuid=9c3f08e6-1900-0000-f8e3-4b4823120000 pid=4643 execve guuid=b1804ae8-1900-0000-f8e3-4b4831120000 pid=4657 /usr/bin/wget net send-data write-file guuid=c39f3ce8-1900-0000-f8e3-4b4830120000 pid=4656->guuid=b1804ae8-1900-0000-f8e3-4b4831120000 pid=4657 execve guuid=b1804ae8-1900-0000-f8e3-4b4831120000 pid=4657->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 138B guuid=101f4b26-1a00-0000-f8e3-4b48b4120000 pid=4788 /usr/bin/cat guuid=09513826-1a00-0000-f8e3-4b48b3120000 pid=4787->guuid=101f4b26-1a00-0000-f8e3-4b48b4120000 pid=4788 execve guuid=2c627827-1a00-0000-f8e3-4b48b7120000 pid=4791 /usr/bin/chmod guuid=82356827-1a00-0000-f8e3-4b48b6120000 pid=4790->guuid=2c627827-1a00-0000-f8e3-4b48b7120000 pid=4791 execve guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=6428562a-1a00-0000-f8e3-4b48b9120000 pid=4793 /usr/bin/lib/rondo guuid=eee60e28-1a00-0000-f8e3-4b48b8120000 pid=4792->guuid=6428562a-1a00-0000-f8e3-4b48b9120000 pid=4793 execve guuid=73b3272d-1a00-0000-f8e3-4b48bf120000 pid=4799 /usr/bin/wget net send-data write-file guuid=3985182d-1a00-0000-f8e3-4b48be120000 pid=4798->guuid=73b3272d-1a00-0000-f8e3-4b48bf120000 pid=4799 execve guuid=73b3272d-1a00-0000-f8e3-4b48bf120000 pid=4799->3e7234c3-faf5-52ca-baba-2f6c79023ab4 send: 140B guuid=0331c75c-1a00-0000-f8e3-4b481b130000 pid=4891 /usr/bin/cat guuid=e311ba5c-1a00-0000-f8e3-4b481a130000 pid=4890->guuid=0331c75c-1a00-0000-f8e3-4b481b130000 pid=4891 execve guuid=3c46e95d-1a00-0000-f8e3-4b4821130000 pid=4897 /usr/bin/chmod guuid=0621db5d-1a00-0000-f8e3-4b4820130000 pid=4896->guuid=3c46e95d-1a00-0000-f8e3-4b4821130000 pid=4897 execve guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=71283260-1a00-0000-f8e3-4b482a130000 pid=4906 /usr/bin/lib/rondo guuid=71d6495e-1a00-0000-f8e3-4b4823130000 pid=4899->guuid=71283260-1a00-0000-f8e3-4b482a130000 pid=4906 execve guuid=13dc4c60-1a00-0000-f8e3-4b482b130000 pid=4907 /usr/bin/lib/rondo zombie guuid=71283260-1a00-0000-f8e3-4b482a130000 pid=4906->guuid=13dc4c60-1a00-0000-f8e3-4b482b130000 pid=4907 clone guuid=be625860-1a00-0000-f8e3-4b482d130000 pid=4909 /usr/bin/lib/rondo zombie guuid=13dc4c60-1a00-0000-f8e3-4b482b130000 pid=4907->guuid=be625860-1a00-0000-f8e3-4b482d130000 pid=4909 clone guuid=b5e4a760-1a00-0000-f8e3-4b482f130000 pid=4911 /usr/lib/systemd/qilimyeo delete-file net send-data write-config write-file zombie guuid=be625860-1a00-0000-f8e3-4b482d130000 pid=4909->guuid=b5e4a760-1a00-0000-f8e3-4b482f130000 pid=4911 clone fea20613-7763-559d-8c2b-52d62620f7b4 83.150.218.93:65534 guuid=b5e4a760-1a00-0000-f8e3-4b482f130000 pid=4911->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=38f40961-1a00-0000-f8e3-4b4831130000 pid=4913 /usr/lib/systemd/qilimyeo zombie guuid=b5e4a760-1a00-0000-f8e3-4b482f130000 pid=4911->guuid=38f40961-1a00-0000-f8e3-4b4831130000 pid=4913 clone guuid=2c1f0f61-1a00-0000-f8e3-4b4832130000 pid=4914 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=b5e4a760-1a00-0000-f8e3-4b482f130000 pid=4911->guuid=2c1f0f61-1a00-0000-f8e3-4b4832130000 pid=4914 clone guuid=2c1f0f61-1a00-0000-f8e3-4b4832130000 pid=4914->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=d3343ba1-1a00-0000-f8e3-4b48bc130000 pid=5052 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=2c1f0f61-1a00-0000-f8e3-4b4832130000 pid=4914->guuid=d3343ba1-1a00-0000-f8e3-4b48bc130000 pid=5052 clone guuid=d3343ba1-1a00-0000-f8e3-4b48bc130000 pid=5052->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=3fc0d0a2-1a00-0000-f8e3-4b48c1130000 pid=5057 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=d3343ba1-1a00-0000-f8e3-4b48bc130000 pid=5052->guuid=3fc0d0a2-1a00-0000-f8e3-4b48c1130000 pid=5057 clone guuid=3fc0d0a2-1a00-0000-f8e3-4b48c1130000 pid=5057->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=7a8d82a4-1a00-0000-f8e3-4b48c6130000 pid=5062 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=3fc0d0a2-1a00-0000-f8e3-4b48c1130000 pid=5057->guuid=7a8d82a4-1a00-0000-f8e3-4b48c6130000 pid=5062 clone guuid=7a8d82a4-1a00-0000-f8e3-4b48c6130000 pid=5062->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=05a21fa6-1a00-0000-f8e3-4b48ca130000 pid=5066 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=7a8d82a4-1a00-0000-f8e3-4b48c6130000 pid=5062->guuid=05a21fa6-1a00-0000-f8e3-4b48ca130000 pid=5066 clone guuid=05a21fa6-1a00-0000-f8e3-4b48ca130000 pid=5066->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=4fe418ab-1a00-0000-f8e3-4b48d6130000 pid=5078 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=05a21fa6-1a00-0000-f8e3-4b48ca130000 pid=5066->guuid=4fe418ab-1a00-0000-f8e3-4b48d6130000 pid=5078 clone guuid=4fe418ab-1a00-0000-f8e3-4b48d6130000 pid=5078->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=14133334-1f00-0000-f8e3-4b48e2140000 pid=5346 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=4fe418ab-1a00-0000-f8e3-4b48d6130000 pid=5078->guuid=14133334-1f00-0000-f8e3-4b48e2140000 pid=5346 clone guuid=14133334-1f00-0000-f8e3-4b48e2140000 pid=5346->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=1768f435-1f00-0000-f8e3-4b48e3140000 pid=5347 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=14133334-1f00-0000-f8e3-4b48e2140000 pid=5346->guuid=1768f435-1f00-0000-f8e3-4b48e3140000 pid=5347 clone guuid=1768f435-1f00-0000-f8e3-4b48e3140000 pid=5347->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=d7f89e37-1f00-0000-f8e3-4b48e4140000 pid=5348 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=1768f435-1f00-0000-f8e3-4b48e3140000 pid=5347->guuid=d7f89e37-1f00-0000-f8e3-4b48e4140000 pid=5348 clone guuid=d7f89e37-1f00-0000-f8e3-4b48e4140000 pid=5348->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=59ac3339-1f00-0000-f8e3-4b48e5140000 pid=5349 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=d7f89e37-1f00-0000-f8e3-4b48e4140000 pid=5348->guuid=59ac3339-1f00-0000-f8e3-4b48e5140000 pid=5349 clone guuid=59ac3339-1f00-0000-f8e3-4b48e5140000 pid=5349->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=081bd13a-1f00-0000-f8e3-4b48e6140000 pid=5350 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=59ac3339-1f00-0000-f8e3-4b48e5140000 pid=5349->guuid=081bd13a-1f00-0000-f8e3-4b48e6140000 pid=5350 clone guuid=081bd13a-1f00-0000-f8e3-4b48e6140000 pid=5350->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=0b1cf3bb-2300-0000-f8e3-4b48e7140000 pid=5351 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=081bd13a-1f00-0000-f8e3-4b48e6140000 pid=5350->guuid=0b1cf3bb-2300-0000-f8e3-4b48e7140000 pid=5351 clone guuid=0b1cf3bb-2300-0000-f8e3-4b48e7140000 pid=5351->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=f6eeadbd-2300-0000-f8e3-4b48e8140000 pid=5352 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=0b1cf3bb-2300-0000-f8e3-4b48e7140000 pid=5351->guuid=f6eeadbd-2300-0000-f8e3-4b48e8140000 pid=5352 clone guuid=f6eeadbd-2300-0000-f8e3-4b48e8140000 pid=5352->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=8ec64dbf-2300-0000-f8e3-4b48e9140000 pid=5353 /usr/lib/systemd/qilimyeo net send-data write-file zombie guuid=f6eeadbd-2300-0000-f8e3-4b48e8140000 pid=5352->guuid=8ec64dbf-2300-0000-f8e3-4b48e9140000 pid=5353 clone guuid=8ec64dbf-2300-0000-f8e3-4b48e9140000 pid=5353->fea20613-7763-559d-8c2b-52d62620f7b4 send: 22B guuid=b8f27cc4-2300-0000-f8e3-4b48ea140000 pid=5354 /usr/lib/systemd/qilimyeo net write-file zombie guuid=8ec64dbf-2300-0000-f8e3-4b48e9140000 pid=5353->guuid=b8f27cc4-2300-0000-f8e3-4b48ea140000 pid=5354 clone guuid=b8f27cc4-2300-0000-f8e3-4b48ea140000 pid=5354->fea20613-7763-559d-8c2b-52d62620f7b4 con guuid=f20808c7-2300-0000-f8e3-4b48eb140000 pid=5355 /usr/lib/systemd/qilimyeo guuid=b8f27cc4-2300-0000-f8e3-4b48ea140000 pid=5354->guuid=f20808c7-2300-0000-f8e3-4b48eb140000 pid=5355 clone
Threat name:
Script.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-11 15:08:15 UTC
File Type:
Text (Shell)
AV detection:
6 of 24 (25.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Mirai

sh 1cfed5e3963fd22823a63fe44ba533a014dff9528b44c9c2b620c81963d595ce

(this sample)

Comments