MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20c192d7082c8cf898e3bbafb77dc45037c93eaee18ce9b1d11d381de835f222. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 11 File information Comments

SHA256 hash: 20c192d7082c8cf898e3bbafb77dc45037c93eaee18ce9b1d11d381de835f222
SHA3-384 hash: 9a618072175c8294442f77153e87341a72d22983c66d31df69dec32a9df3ee46a35cd8606d07f9cab4cb43497557f17d
SHA1 hash: 228de212b70f1286cc9973109809ef14a289d584
MD5 hash: d93f4a5437dcc920c895c494702e394a
humanhash: white-delaware-hawaii-two
File name:cron
Download: download sample
Signature Mirai
File size:105'494 bytes
First seen:2025-07-13 00:50:52 UTC
Last seen:2025-07-13 13:56:32 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:yAm2ANgrTJmX5zCuuPqd3Jn1rw2mpFXthVnQaTemT:ywAGryOpPqd37rw2mpFXthVnQaTemT
TLSH T1FCA33E42E747C6B3C8430AF20297AA6A4921BE7B0D365E49F32D7DB4AB324CC7115F65
telfhash t181315622943546142fb3a928acfd56b315322b2323596f71af26c5cc49360f1e93dd4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
19
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
DNS request
Creating a file
Connection attempt
Launching a process
Substitutes an application name
Status:
terminated
Behavior Graph:
%3 guuid=6fd2e704-1a00-0000-9669-c8683d0a0000 pid=2621 /usr/bin/sudo guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626 /tmp/sample.bin net guuid=6fd2e704-1a00-0000-9669-c8683d0a0000 pid=2621->guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629 /tmp/sample.bin zombie guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626->guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629 clone guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630 /usr/bin/dash zombie guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626->guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630 execve guuid=2648ad07-1a00-0000-9669-c868470a0000 pid=2631 /tmp/sample.bin guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626->guuid=2648ad07-1a00-0000-9669-c868470a0000 pid=2631 clone guuid=716cb007-1a00-0000-9669-c868480a0000 pid=2632 /tmp/sample.bin guuid=9e18c606-1a00-0000-9669-c868420a0000 pid=2626->guuid=716cb007-1a00-0000-9669-c868480a0000 pid=2632 clone guuid=d9f3cf39-1a00-0000-9669-c868cc0a0000 pid=2764 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d9f3cf39-1a00-0000-9669-c868cc0a0000 pid=2764 execve guuid=c5e2e63c-1a00-0000-9669-c868d20a0000 pid=2770 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c5e2e63c-1a00-0000-9669-c868d20a0000 pid=2770 execve guuid=61d81e3e-1a00-0000-9669-c868d80a0000 pid=2776 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=61d81e3e-1a00-0000-9669-c868d80a0000 pid=2776 execve guuid=c15f013f-1a00-0000-9669-c868dc0a0000 pid=2780 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c15f013f-1a00-0000-9669-c868dc0a0000 pid=2780 execve guuid=22814340-1a00-0000-9669-c868e10a0000 pid=2785 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=22814340-1a00-0000-9669-c868e10a0000 pid=2785 execve guuid=f609a141-1a00-0000-9669-c868e60a0000 pid=2790 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f609a141-1a00-0000-9669-c868e60a0000 pid=2790 execve guuid=9234d142-1a00-0000-9669-c868e90a0000 pid=2793 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=9234d142-1a00-0000-9669-c868e90a0000 pid=2793 execve guuid=f72b3844-1a00-0000-9669-c868ef0a0000 pid=2799 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f72b3844-1a00-0000-9669-c868ef0a0000 pid=2799 execve guuid=ffe81c45-1a00-0000-9669-c868f30a0000 pid=2803 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=ffe81c45-1a00-0000-9669-c868f30a0000 pid=2803 execve guuid=76cdfe72-1b00-0000-9669-c868730d0000 pid=3443 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=76cdfe72-1b00-0000-9669-c868730d0000 pid=3443 execve guuid=8f0e0c76-1b00-0000-9669-c8687f0d0000 pid=3455 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=8f0e0c76-1b00-0000-9669-c8687f0d0000 pid=3455 execve guuid=9b5b2b77-1b00-0000-9669-c868850d0000 pid=3461 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=9b5b2b77-1b00-0000-9669-c868850d0000 pid=3461 execve guuid=0d0f7679-1b00-0000-9669-c8688d0d0000 pid=3469 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0d0f7679-1b00-0000-9669-c8688d0d0000 pid=3469 execve guuid=c7757d7a-1b00-0000-9669-c868920d0000 pid=3474 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c7757d7a-1b00-0000-9669-c868920d0000 pid=3474 execve guuid=12a1757b-1b00-0000-9669-c868960d0000 pid=3478 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=12a1757b-1b00-0000-9669-c868960d0000 pid=3478 execve guuid=955b7f7c-1b00-0000-9669-c8689c0d0000 pid=3484 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=955b7f7c-1b00-0000-9669-c8689c0d0000 pid=3484 execve guuid=ab86ca7d-1b00-0000-9669-c868a20d0000 pid=3490 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=ab86ca7d-1b00-0000-9669-c868a20d0000 pid=3490 execve guuid=29e0517f-1b00-0000-9669-c868aa0d0000 pid=3498 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=29e0517f-1b00-0000-9669-c868aa0d0000 pid=3498 execve guuid=c4ed30ae-1c00-0000-9669-c8688b110000 pid=4491 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c4ed30ae-1c00-0000-9669-c8688b110000 pid=4491 execve guuid=eb5aadb1-1c00-0000-9669-c8689e110000 pid=4510 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=eb5aadb1-1c00-0000-9669-c8689e110000 pid=4510 execve guuid=e9d333b3-1c00-0000-9669-c868a7110000 pid=4519 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=e9d333b3-1c00-0000-9669-c868a7110000 pid=4519 execve guuid=32dd81b4-1c00-0000-9669-c868b1110000 pid=4529 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=32dd81b4-1c00-0000-9669-c868b1110000 pid=4529 execve guuid=de866cb5-1c00-0000-9669-c868b5110000 pid=4533 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=de866cb5-1c00-0000-9669-c868b5110000 pid=4533 execve guuid=12ea93b6-1c00-0000-9669-c868b9110000 pid=4537 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=12ea93b6-1c00-0000-9669-c868b9110000 pid=4537 execve guuid=d6d08cb7-1c00-0000-9669-c868be110000 pid=4542 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d6d08cb7-1c00-0000-9669-c868be110000 pid=4542 execve guuid=a6e516b9-1c00-0000-9669-c868c3110000 pid=4547 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=a6e516b9-1c00-0000-9669-c868c3110000 pid=4547 execve guuid=f1faf2b9-1c00-0000-9669-c868cb110000 pid=4555 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f1faf2b9-1c00-0000-9669-c868cb110000 pid=4555 execve guuid=84179efa-1d00-0000-9669-c868b7140000 pid=5303 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=84179efa-1d00-0000-9669-c868b7140000 pid=5303 execve guuid=85e22dfe-1d00-0000-9669-c868ba140000 pid=5306 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=85e22dfe-1d00-0000-9669-c868ba140000 pid=5306 execve guuid=3a0543ff-1d00-0000-9669-c868bc140000 pid=5308 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=3a0543ff-1d00-0000-9669-c868bc140000 pid=5308 execve guuid=7a712400-1e00-0000-9669-c868be140000 pid=5310 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=7a712400-1e00-0000-9669-c868be140000 pid=5310 execve guuid=dee1f400-1e00-0000-9669-c868c0140000 pid=5312 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=dee1f400-1e00-0000-9669-c868c0140000 pid=5312 execve guuid=269ec201-1e00-0000-9669-c868c2140000 pid=5314 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=269ec201-1e00-0000-9669-c868c2140000 pid=5314 execve guuid=fd09a502-1e00-0000-9669-c868c4140000 pid=5316 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=fd09a502-1e00-0000-9669-c868c4140000 pid=5316 execve guuid=0beacf03-1e00-0000-9669-c868c7140000 pid=5319 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0beacf03-1e00-0000-9669-c868c7140000 pid=5319 execve guuid=d1b4f804-1e00-0000-9669-c868cd140000 pid=5325 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d1b4f804-1e00-0000-9669-c868cd140000 pid=5325 execve guuid=60a72b34-1f00-0000-9669-c868cf140000 pid=5327 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=60a72b34-1f00-0000-9669-c868cf140000 pid=5327 execve guuid=a83b0039-1f00-0000-9669-c868d1140000 pid=5329 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=a83b0039-1f00-0000-9669-c868d1140000 pid=5329 execve guuid=67e6633b-1f00-0000-9669-c868d3140000 pid=5331 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=67e6633b-1f00-0000-9669-c868d3140000 pid=5331 execve guuid=5a37f93c-1f00-0000-9669-c868d5140000 pid=5333 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=5a37f93c-1f00-0000-9669-c868d5140000 pid=5333 execve guuid=26e0803e-1f00-0000-9669-c868d7140000 pid=5335 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=26e0803e-1f00-0000-9669-c868d7140000 pid=5335 execve guuid=d9ed2940-1f00-0000-9669-c868d9140000 pid=5337 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d9ed2940-1f00-0000-9669-c868d9140000 pid=5337 execve guuid=a55ae941-1f00-0000-9669-c868db140000 pid=5339 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=a55ae941-1f00-0000-9669-c868db140000 pid=5339 execve guuid=24dc8d43-1f00-0000-9669-c868dd140000 pid=5341 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=24dc8d43-1f00-0000-9669-c868dd140000 pid=5341 execve guuid=f1e68844-1f00-0000-9669-c868df140000 pid=5343 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f1e68844-1f00-0000-9669-c868df140000 pid=5343 execve guuid=f2b9a273-2000-0000-9669-c868e1140000 pid=5345 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f2b9a273-2000-0000-9669-c868e1140000 pid=5345 execve guuid=5c0bf276-2000-0000-9669-c868e3140000 pid=5347 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=5c0bf276-2000-0000-9669-c868e3140000 pid=5347 execve guuid=23b7db77-2000-0000-9669-c868e5140000 pid=5349 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=23b7db77-2000-0000-9669-c868e5140000 pid=5349 execve guuid=76b2e278-2000-0000-9669-c868e7140000 pid=5351 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=76b2e278-2000-0000-9669-c868e7140000 pid=5351 execve guuid=e3ac1c7a-2000-0000-9669-c868e9140000 pid=5353 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=e3ac1c7a-2000-0000-9669-c868e9140000 pid=5353 execve guuid=8265247b-2000-0000-9669-c868eb140000 pid=5355 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=8265247b-2000-0000-9669-c868eb140000 pid=5355 execve guuid=1eee277c-2000-0000-9669-c868ed140000 pid=5357 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=1eee277c-2000-0000-9669-c868ed140000 pid=5357 execve guuid=0639567e-2000-0000-9669-c868ef140000 pid=5359 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0639567e-2000-0000-9669-c868ef140000 pid=5359 execve guuid=7f6d5a80-2000-0000-9669-c868f1140000 pid=5361 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=7f6d5a80-2000-0000-9669-c868f1140000 pid=5361 execve guuid=e8722eaf-2100-0000-9669-c868f3140000 pid=5363 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=e8722eaf-2100-0000-9669-c868f3140000 pid=5363 execve guuid=ef8299b1-2100-0000-9669-c868f5140000 pid=5365 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=ef8299b1-2100-0000-9669-c868f5140000 pid=5365 execve guuid=aae46bb2-2100-0000-9669-c868f7140000 pid=5367 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=aae46bb2-2100-0000-9669-c868f7140000 pid=5367 execve guuid=76843fb3-2100-0000-9669-c868f9140000 pid=5369 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=76843fb3-2100-0000-9669-c868f9140000 pid=5369 execve guuid=d13d1bb4-2100-0000-9669-c868fb140000 pid=5371 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d13d1bb4-2100-0000-9669-c868fb140000 pid=5371 execve guuid=f2fdf4b4-2100-0000-9669-c868fd140000 pid=5373 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f2fdf4b4-2100-0000-9669-c868fd140000 pid=5373 execve guuid=c38ed2b5-2100-0000-9669-c868ff140000 pid=5375 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c38ed2b5-2100-0000-9669-c868ff140000 pid=5375 execve guuid=23cdecb6-2100-0000-9669-c86801150000 pid=5377 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=23cdecb6-2100-0000-9669-c86801150000 pid=5377 execve guuid=969effb7-2100-0000-9669-c86803150000 pid=5379 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=969effb7-2100-0000-9669-c86803150000 pid=5379 execve guuid=3f18ace5-2200-0000-9669-c86805150000 pid=5381 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=3f18ace5-2200-0000-9669-c86805150000 pid=5381 execve guuid=abefafe8-2200-0000-9669-c86807150000 pid=5383 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=abefafe8-2200-0000-9669-c86807150000 pid=5383 execve guuid=b83ed3e9-2200-0000-9669-c86809150000 pid=5385 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=b83ed3e9-2200-0000-9669-c86809150000 pid=5385 execve guuid=2923e6ea-2200-0000-9669-c8680b150000 pid=5387 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=2923e6ea-2200-0000-9669-c8680b150000 pid=5387 execve guuid=65be58ec-2200-0000-9669-c8680d150000 pid=5389 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=65be58ec-2200-0000-9669-c8680d150000 pid=5389 execve guuid=f2f3bced-2200-0000-9669-c8680f150000 pid=5391 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f2f3bced-2200-0000-9669-c8680f150000 pid=5391 execve guuid=33c65fef-2200-0000-9669-c86811150000 pid=5393 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=33c65fef-2200-0000-9669-c86811150000 pid=5393 execve guuid=2bb5f2f0-2200-0000-9669-c86813150000 pid=5395 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=2bb5f2f0-2200-0000-9669-c86813150000 pid=5395 execve guuid=ad7833f2-2200-0000-9669-c86815150000 pid=5397 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=ad7833f2-2200-0000-9669-c86815150000 pid=5397 execve guuid=77648521-2400-0000-9669-c86817150000 pid=5399 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=77648521-2400-0000-9669-c86817150000 pid=5399 execve guuid=03267525-2400-0000-9669-c86819150000 pid=5401 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=03267525-2400-0000-9669-c86819150000 pid=5401 execve guuid=0566a026-2400-0000-9669-c8681b150000 pid=5403 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0566a026-2400-0000-9669-c8681b150000 pid=5403 execve guuid=2e392d28-2400-0000-9669-c8681d150000 pid=5405 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=2e392d28-2400-0000-9669-c8681d150000 pid=5405 execve guuid=4c99c129-2400-0000-9669-c8681f150000 pid=5407 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=4c99c129-2400-0000-9669-c8681f150000 pid=5407 execve guuid=5f58532b-2400-0000-9669-c86821150000 pid=5409 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=5f58532b-2400-0000-9669-c86821150000 pid=5409 execve guuid=59c2f02c-2400-0000-9669-c86823150000 pid=5411 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=59c2f02c-2400-0000-9669-c86823150000 pid=5411 execve guuid=79329a2e-2400-0000-9669-c86825150000 pid=5413 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=79329a2e-2400-0000-9669-c86825150000 pid=5413 execve guuid=71f14930-2400-0000-9669-c86827150000 pid=5415 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=71f14930-2400-0000-9669-c86827150000 pid=5415 execve guuid=b3bb3c60-2500-0000-9669-c86829150000 pid=5417 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=b3bb3c60-2500-0000-9669-c86829150000 pid=5417 execve guuid=226ffa64-2500-0000-9669-c8682b150000 pid=5419 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=226ffa64-2500-0000-9669-c8682b150000 pid=5419 execve guuid=d12cbd66-2500-0000-9669-c8682d150000 pid=5421 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=d12cbd66-2500-0000-9669-c8682d150000 pid=5421 execve guuid=f36c7168-2500-0000-9669-c8682f150000 pid=5423 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f36c7168-2500-0000-9669-c8682f150000 pid=5423 execve guuid=0de5166a-2500-0000-9669-c86831150000 pid=5425 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0de5166a-2500-0000-9669-c86831150000 pid=5425 execve guuid=f934c86b-2500-0000-9669-c86833150000 pid=5427 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=f934c86b-2500-0000-9669-c86833150000 pid=5427 execve guuid=8ee15d6d-2500-0000-9669-c86835150000 pid=5429 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=8ee15d6d-2500-0000-9669-c86835150000 pid=5429 execve guuid=7d48196f-2500-0000-9669-c86837150000 pid=5431 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=7d48196f-2500-0000-9669-c86837150000 pid=5431 execve guuid=891fd670-2500-0000-9669-c86839150000 pid=5433 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=891fd670-2500-0000-9669-c86839150000 pid=5433 execve guuid=caabc3a0-2600-0000-9669-c8683b150000 pid=5435 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=caabc3a0-2600-0000-9669-c8683b150000 pid=5435 execve guuid=1a697ba5-2600-0000-9669-c8683d150000 pid=5437 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=1a697ba5-2600-0000-9669-c8683d150000 pid=5437 execve guuid=732d3ba7-2600-0000-9669-c8683f150000 pid=5439 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=732d3ba7-2600-0000-9669-c8683f150000 pid=5439 execve guuid=32ae07a9-2600-0000-9669-c86841150000 pid=5441 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=32ae07a9-2600-0000-9669-c86841150000 pid=5441 execve guuid=6206c5aa-2600-0000-9669-c86843150000 pid=5443 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=6206c5aa-2600-0000-9669-c86843150000 pid=5443 execve guuid=fcdb8cac-2600-0000-9669-c86845150000 pid=5445 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=fcdb8cac-2600-0000-9669-c86845150000 pid=5445 execve guuid=64ed50ae-2600-0000-9669-c86847150000 pid=5447 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=64ed50ae-2600-0000-9669-c86847150000 pid=5447 execve guuid=388217b0-2600-0000-9669-c86849150000 pid=5449 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=388217b0-2600-0000-9669-c86849150000 pid=5449 execve guuid=061ddfb1-2600-0000-9669-c8684b150000 pid=5451 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=061ddfb1-2600-0000-9669-c8684b150000 pid=5451 execve guuid=7fee19e2-2700-0000-9669-c8684e150000 pid=5454 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=7fee19e2-2700-0000-9669-c8684e150000 pid=5454 execve guuid=df5ea7e5-2700-0000-9669-c86851150000 pid=5457 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=df5ea7e5-2700-0000-9669-c86851150000 pid=5457 execve guuid=0cafc8e6-2700-0000-9669-c86853150000 pid=5459 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=0cafc8e6-2700-0000-9669-c86853150000 pid=5459 execve guuid=c88ee6e7-2700-0000-9669-c86855150000 pid=5461 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=c88ee6e7-2700-0000-9669-c86855150000 pid=5461 execve guuid=5b19ebe8-2700-0000-9669-c86857150000 pid=5463 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=5b19ebe8-2700-0000-9669-c86857150000 pid=5463 execve guuid=46fe84ea-2700-0000-9669-c86859150000 pid=5465 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=46fe84ea-2700-0000-9669-c86859150000 pid=5465 execve guuid=aa171aec-2700-0000-9669-c8685b150000 pid=5467 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=aa171aec-2700-0000-9669-c8685b150000 pid=5467 execve guuid=db0f9aed-2700-0000-9669-c8685d150000 pid=5469 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=db0f9aed-2700-0000-9669-c8685d150000 pid=5469 execve guuid=52d0e9ee-2700-0000-9669-c8685f150000 pid=5471 /usr/bin/dash guuid=bd46a507-1a00-0000-9669-c868450a0000 pid=2629->guuid=52d0e9ee-2700-0000-9669-c8685f150000 pid=5471 execve guuid=085e1808-1a00-0000-9669-c8684b0a0000 pid=2635 /usr/bin/wget dns net send-data guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630->guuid=085e1808-1a00-0000-9669-c8684b0a0000 pid=2635 execve guuid=227abb0e-1a00-0000-9669-c8685d0a0000 pid=2653 /usr/bin/chmod guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630->guuid=227abb0e-1a00-0000-9669-c8685d0a0000 pid=2653 execve guuid=365d0a0f-1a00-0000-9669-c8685e0a0000 pid=2654 /home/sandbox/..... guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630->guuid=365d0a0f-1a00-0000-9669-c8685e0a0000 pid=2654 execve guuid=45edc710-1a00-0000-9669-c868640a0000 pid=2660 /usr/bin/rm delete-file guuid=9d8da907-1a00-0000-9669-c868460a0000 pid=2630->guuid=45edc710-1a00-0000-9669-c868640a0000 pid=2660 execve guuid=1b27bc07-1a00-0000-9669-c868490a0000 pid=2633 /tmp/sample.bin net send-data zombie guuid=716cb007-1a00-0000-9669-c868480a0000 pid=2632->guuid=1b27bc07-1a00-0000-9669-c868490a0000 pid=2633 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=1b27bc07-1a00-0000-9669-c868490a0000 pid=2633->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=085e1808-1a00-0000-9669-c8684b0a0000 pid=2635->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=1e60ff39-1a00-0000-9669-c868cd0a0000 pid=2765 /usr/bin/pgrep guuid=d9f3cf39-1a00-0000-9669-c868cc0a0000 pid=2764->guuid=1e60ff39-1a00-0000-9669-c868cd0a0000 pid=2765 execve guuid=3708193d-1a00-0000-9669-c868d40a0000 pid=2772 /usr/bin/killall guuid=c5e2e63c-1a00-0000-9669-c868d20a0000 pid=2770->guuid=3708193d-1a00-0000-9669-c868d40a0000 pid=2772 execve guuid=1bed493e-1a00-0000-9669-c868da0a0000 pid=2778 /usr/bin/killall guuid=61d81e3e-1a00-0000-9669-c868d80a0000 pid=2776->guuid=1bed493e-1a00-0000-9669-c868da0a0000 pid=2778 execve guuid=9c982e3f-1a00-0000-9669-c868de0a0000 pid=2782 /usr/bin/killall guuid=c15f013f-1a00-0000-9669-c868dc0a0000 pid=2780->guuid=9c982e3f-1a00-0000-9669-c868de0a0000 pid=2782 execve guuid=56547640-1a00-0000-9669-c868e20a0000 pid=2786 /usr/bin/killall guuid=22814340-1a00-0000-9669-c868e10a0000 pid=2785->guuid=56547640-1a00-0000-9669-c868e20a0000 pid=2786 execve guuid=3d8ae741-1a00-0000-9669-c868e80a0000 pid=2792 /usr/bin/killall guuid=f609a141-1a00-0000-9669-c868e60a0000 pid=2790->guuid=3d8ae741-1a00-0000-9669-c868e80a0000 pid=2792 execve guuid=d597ff42-1a00-0000-9669-c868eb0a0000 pid=2795 /usr/bin/killall guuid=9234d142-1a00-0000-9669-c868e90a0000 pid=2793->guuid=d597ff42-1a00-0000-9669-c868eb0a0000 pid=2795 execve guuid=70376744-1a00-0000-9669-c868f00a0000 pid=2800 /usr/bin/killall guuid=f72b3844-1a00-0000-9669-c868ef0a0000 pid=2799->guuid=70376744-1a00-0000-9669-c868f00a0000 pid=2800 execve guuid=bd284945-1a00-0000-9669-c868f50a0000 pid=2805 /usr/bin/killall guuid=ffe81c45-1a00-0000-9669-c868f30a0000 pid=2803->guuid=bd284945-1a00-0000-9669-c868f50a0000 pid=2805 execve guuid=11df4973-1b00-0000-9669-c868750d0000 pid=3445 /usr/bin/pgrep guuid=76cdfe72-1b00-0000-9669-c868730d0000 pid=3443->guuid=11df4973-1b00-0000-9669-c868750d0000 pid=3445 execve guuid=d0294776-1b00-0000-9669-c868810d0000 pid=3457 /usr/bin/killall guuid=8f0e0c76-1b00-0000-9669-c8687f0d0000 pid=3455->guuid=d0294776-1b00-0000-9669-c868810d0000 pid=3457 execve guuid=043a6c77-1b00-0000-9669-c868860d0000 pid=3462 /usr/bin/killall guuid=9b5b2b77-1b00-0000-9669-c868850d0000 pid=3461->guuid=043a6c77-1b00-0000-9669-c868860d0000 pid=3462 execve guuid=4ef8bc79-1b00-0000-9669-c8688f0d0000 pid=3471 /usr/bin/killall guuid=0d0f7679-1b00-0000-9669-c8688d0d0000 pid=3469->guuid=4ef8bc79-1b00-0000-9669-c8688f0d0000 pid=3471 execve guuid=ed48c17a-1b00-0000-9669-c868940d0000 pid=3476 /usr/bin/killall guuid=c7757d7a-1b00-0000-9669-c868920d0000 pid=3474->guuid=ed48c17a-1b00-0000-9669-c868940d0000 pid=3476 execve guuid=2911a07b-1b00-0000-9669-c868980d0000 pid=3480 /usr/bin/killall guuid=12a1757b-1b00-0000-9669-c868960d0000 pid=3478->guuid=2911a07b-1b00-0000-9669-c868980d0000 pid=3480 execve guuid=8970ca7c-1b00-0000-9669-c8689e0d0000 pid=3486 /usr/bin/killall guuid=955b7f7c-1b00-0000-9669-c8689c0d0000 pid=3484->guuid=8970ca7c-1b00-0000-9669-c8689e0d0000 pid=3486 execve guuid=f128f97d-1b00-0000-9669-c868a40d0000 pid=3492 /usr/bin/killall guuid=ab86ca7d-1b00-0000-9669-c868a20d0000 pid=3490->guuid=f128f97d-1b00-0000-9669-c868a40d0000 pid=3492 execve guuid=be26837f-1b00-0000-9669-c868ac0d0000 pid=3500 /usr/bin/killall guuid=29e0517f-1b00-0000-9669-c868aa0d0000 pid=3498->guuid=be26837f-1b00-0000-9669-c868ac0d0000 pid=3500 execve guuid=60d271ae-1c00-0000-9669-c8688d110000 pid=4493 /usr/bin/pgrep guuid=c4ed30ae-1c00-0000-9669-c8688b110000 pid=4491->guuid=60d271ae-1c00-0000-9669-c8688d110000 pid=4493 execve guuid=8ebbd9b1-1c00-0000-9669-c8689f110000 pid=4511 /usr/bin/killall guuid=eb5aadb1-1c00-0000-9669-c8689e110000 pid=4510->guuid=8ebbd9b1-1c00-0000-9669-c8689f110000 pid=4511 execve guuid=703463b3-1c00-0000-9669-c868a8110000 pid=4520 /usr/bin/killall guuid=e9d333b3-1c00-0000-9669-c868a7110000 pid=4519->guuid=703463b3-1c00-0000-9669-c868a8110000 pid=4520 execve guuid=fd3aaeb4-1c00-0000-9669-c868b2110000 pid=4530 /usr/bin/killall guuid=32dd81b4-1c00-0000-9669-c868b1110000 pid=4529->guuid=fd3aaeb4-1c00-0000-9669-c868b2110000 pid=4530 execve guuid=251bdcb5-1c00-0000-9669-c868b7110000 pid=4535 /usr/bin/killall guuid=de866cb5-1c00-0000-9669-c868b5110000 pid=4533->guuid=251bdcb5-1c00-0000-9669-c868b7110000 pid=4535 execve guuid=b75ed1b6-1c00-0000-9669-c868bb110000 pid=4539 /usr/bin/killall guuid=12ea93b6-1c00-0000-9669-c868b9110000 pid=4537->guuid=b75ed1b6-1c00-0000-9669-c868bb110000 pid=4539 execve guuid=b49ab7b7-1c00-0000-9669-c868bf110000 pid=4543 /usr/bin/killall guuid=d6d08cb7-1c00-0000-9669-c868be110000 pid=4542->guuid=b49ab7b7-1c00-0000-9669-c868bf110000 pid=4543 execve guuid=a29840b9-1c00-0000-9669-c868c5110000 pid=4549 /usr/bin/killall guuid=a6e516b9-1c00-0000-9669-c868c3110000 pid=4547->guuid=a29840b9-1c00-0000-9669-c868c5110000 pid=4549 execve guuid=1c701bba-1c00-0000-9669-c868cc110000 pid=4556 /usr/bin/killall guuid=f1faf2b9-1c00-0000-9669-c868cb110000 pid=4555->guuid=1c701bba-1c00-0000-9669-c868cc110000 pid=4556 execve guuid=3a0dd7fa-1d00-0000-9669-c868b8140000 pid=5304 /usr/bin/pgrep guuid=84179efa-1d00-0000-9669-c868b7140000 pid=5303->guuid=3a0dd7fa-1d00-0000-9669-c868b8140000 pid=5304 execve guuid=c3b566fe-1d00-0000-9669-c868bb140000 pid=5307 /usr/bin/killall guuid=85e22dfe-1d00-0000-9669-c868ba140000 pid=5306->guuid=c3b566fe-1d00-0000-9669-c868bb140000 pid=5307 execve guuid=fc536dff-1d00-0000-9669-c868bd140000 pid=5309 /usr/bin/killall guuid=3a0543ff-1d00-0000-9669-c868bc140000 pid=5308->guuid=fc536dff-1d00-0000-9669-c868bd140000 pid=5309 execve guuid=147f4c00-1e00-0000-9669-c868bf140000 pid=5311 /usr/bin/killall guuid=7a712400-1e00-0000-9669-c868be140000 pid=5310->guuid=147f4c00-1e00-0000-9669-c868bf140000 pid=5311 execve guuid=8aa71a01-1e00-0000-9669-c868c1140000 pid=5313 /usr/bin/killall guuid=dee1f400-1e00-0000-9669-c868c0140000 pid=5312->guuid=8aa71a01-1e00-0000-9669-c868c1140000 pid=5313 execve guuid=7245eb01-1e00-0000-9669-c868c3140000 pid=5315 /usr/bin/killall guuid=269ec201-1e00-0000-9669-c868c2140000 pid=5314->guuid=7245eb01-1e00-0000-9669-c868c3140000 pid=5315 execve guuid=0e67d502-1e00-0000-9669-c868c5140000 pid=5317 /usr/bin/killall guuid=fd09a502-1e00-0000-9669-c868c4140000 pid=5316->guuid=0e67d502-1e00-0000-9669-c868c5140000 pid=5317 execve guuid=e4e30904-1e00-0000-9669-c868c9140000 pid=5321 /usr/bin/killall guuid=0beacf03-1e00-0000-9669-c868c7140000 pid=5319->guuid=e4e30904-1e00-0000-9669-c868c9140000 pid=5321 execve guuid=abae2905-1e00-0000-9669-c868ce140000 pid=5326 /usr/bin/killall guuid=d1b4f804-1e00-0000-9669-c868cd140000 pid=5325->guuid=abae2905-1e00-0000-9669-c868ce140000 pid=5326 execve guuid=2b7e9c34-1f00-0000-9669-c868d0140000 pid=5328 /usr/bin/pgrep guuid=60a72b34-1f00-0000-9669-c868cf140000 pid=5327->guuid=2b7e9c34-1f00-0000-9669-c868d0140000 pid=5328 execve guuid=c7855939-1f00-0000-9669-c868d2140000 pid=5330 /usr/bin/killall guuid=a83b0039-1f00-0000-9669-c868d1140000 pid=5329->guuid=c7855939-1f00-0000-9669-c868d2140000 pid=5330 execve guuid=c2dfef3b-1f00-0000-9669-c868d4140000 pid=5332 /usr/bin/killall guuid=67e6633b-1f00-0000-9669-c868d3140000 pid=5331->guuid=c2dfef3b-1f00-0000-9669-c868d4140000 pid=5332 execve guuid=eae66c3d-1f00-0000-9669-c868d6140000 pid=5334 /usr/bin/killall guuid=5a37f93c-1f00-0000-9669-c868d5140000 pid=5333->guuid=eae66c3d-1f00-0000-9669-c868d6140000 pid=5334 execve guuid=324cea3e-1f00-0000-9669-c868d8140000 pid=5336 /usr/bin/killall guuid=26e0803e-1f00-0000-9669-c868d7140000 pid=5335->guuid=324cea3e-1f00-0000-9669-c868d8140000 pid=5336 execve guuid=31047c40-1f00-0000-9669-c868da140000 pid=5338 /usr/bin/killall guuid=d9ed2940-1f00-0000-9669-c868d9140000 pid=5337->guuid=31047c40-1f00-0000-9669-c868da140000 pid=5338 execve guuid=49ea4542-1f00-0000-9669-c868dc140000 pid=5340 /usr/bin/killall guuid=a55ae941-1f00-0000-9669-c868db140000 pid=5339->guuid=49ea4542-1f00-0000-9669-c868dc140000 pid=5340 execve guuid=5005d243-1f00-0000-9669-c868de140000 pid=5342 /usr/bin/killall guuid=24dc8d43-1f00-0000-9669-c868dd140000 pid=5341->guuid=5005d243-1f00-0000-9669-c868de140000 pid=5342 execve guuid=806acc44-1f00-0000-9669-c868e0140000 pid=5344 /usr/bin/killall guuid=f1e68844-1f00-0000-9669-c868df140000 pid=5343->guuid=806acc44-1f00-0000-9669-c868e0140000 pid=5344 execve guuid=f53ddf73-2000-0000-9669-c868e2140000 pid=5346 /usr/bin/pgrep guuid=f2b9a273-2000-0000-9669-c868e1140000 pid=5345->guuid=f53ddf73-2000-0000-9669-c868e2140000 pid=5346 execve guuid=7ba42077-2000-0000-9669-c868e4140000 pid=5348 /usr/bin/killall guuid=5c0bf276-2000-0000-9669-c868e3140000 pid=5347->guuid=7ba42077-2000-0000-9669-c868e4140000 pid=5348 execve guuid=634b1b78-2000-0000-9669-c868e6140000 pid=5350 /usr/bin/killall guuid=23b7db77-2000-0000-9669-c868e5140000 pid=5349->guuid=634b1b78-2000-0000-9669-c868e6140000 pid=5350 execve guuid=5eb84779-2000-0000-9669-c868e8140000 pid=5352 /usr/bin/killall guuid=76b2e278-2000-0000-9669-c868e7140000 pid=5351->guuid=5eb84779-2000-0000-9669-c868e8140000 pid=5352 execve guuid=d9095a7a-2000-0000-9669-c868ea140000 pid=5354 /usr/bin/killall guuid=e3ac1c7a-2000-0000-9669-c868e9140000 pid=5353->guuid=d9095a7a-2000-0000-9669-c868ea140000 pid=5354 execve guuid=6610537b-2000-0000-9669-c868ec140000 pid=5356 /usr/bin/killall guuid=8265247b-2000-0000-9669-c868eb140000 pid=5355->guuid=6610537b-2000-0000-9669-c868ec140000 pid=5356 execve guuid=f7bf607c-2000-0000-9669-c868ee140000 pid=5358 /usr/bin/killall guuid=1eee277c-2000-0000-9669-c868ed140000 pid=5357->guuid=f7bf607c-2000-0000-9669-c868ee140000 pid=5358 execve guuid=19ccbb7e-2000-0000-9669-c868f0140000 pid=5360 /usr/bin/killall guuid=0639567e-2000-0000-9669-c868ef140000 pid=5359->guuid=19ccbb7e-2000-0000-9669-c868f0140000 pid=5360 execve guuid=ceeaa880-2000-0000-9669-c868f2140000 pid=5362 /usr/bin/killall guuid=7f6d5a80-2000-0000-9669-c868f1140000 pid=5361->guuid=ceeaa880-2000-0000-9669-c868f2140000 pid=5362 execve guuid=4f1866af-2100-0000-9669-c868f4140000 pid=5364 /usr/bin/pgrep guuid=e8722eaf-2100-0000-9669-c868f3140000 pid=5363->guuid=4f1866af-2100-0000-9669-c868f4140000 pid=5364 execve guuid=b3bcc8b1-2100-0000-9669-c868f6140000 pid=5366 /usr/bin/killall guuid=ef8299b1-2100-0000-9669-c868f5140000 pid=5365->guuid=b3bcc8b1-2100-0000-9669-c868f6140000 pid=5366 execve guuid=834f99b2-2100-0000-9669-c868f8140000 pid=5368 /usr/bin/killall guuid=aae46bb2-2100-0000-9669-c868f7140000 pid=5367->guuid=834f99b2-2100-0000-9669-c868f8140000 pid=5368 execve guuid=020a6eb3-2100-0000-9669-c868fa140000 pid=5370 /usr/bin/killall guuid=76843fb3-2100-0000-9669-c868f9140000 pid=5369->guuid=020a6eb3-2100-0000-9669-c868fa140000 pid=5370 execve guuid=050450b4-2100-0000-9669-c868fc140000 pid=5372 /usr/bin/killall guuid=d13d1bb4-2100-0000-9669-c868fb140000 pid=5371->guuid=050450b4-2100-0000-9669-c868fc140000 pid=5372 execve guuid=cb8227b5-2100-0000-9669-c868fe140000 pid=5374 /usr/bin/killall guuid=f2fdf4b4-2100-0000-9669-c868fd140000 pid=5373->guuid=cb8227b5-2100-0000-9669-c868fe140000 pid=5374 execve guuid=f678fcb5-2100-0000-9669-c86800150000 pid=5376 /usr/bin/killall guuid=c38ed2b5-2100-0000-9669-c868ff140000 pid=5375->guuid=f678fcb5-2100-0000-9669-c86800150000 pid=5376 execve guuid=5b4317b7-2100-0000-9669-c86802150000 pid=5378 /usr/bin/killall guuid=23cdecb6-2100-0000-9669-c86801150000 pid=5377->guuid=5b4317b7-2100-0000-9669-c86802150000 pid=5378 execve guuid=80a628b8-2100-0000-9669-c86804150000 pid=5380 /usr/bin/killall guuid=969effb7-2100-0000-9669-c86803150000 pid=5379->guuid=80a628b8-2100-0000-9669-c86804150000 pid=5380 execve guuid=9f8ffde5-2200-0000-9669-c86806150000 pid=5382 /usr/bin/pgrep guuid=3f18ace5-2200-0000-9669-c86805150000 pid=5381->guuid=9f8ffde5-2200-0000-9669-c86806150000 pid=5382 execve guuid=5a6be1e8-2200-0000-9669-c86808150000 pid=5384 /usr/bin/killall guuid=abefafe8-2200-0000-9669-c86807150000 pid=5383->guuid=5a6be1e8-2200-0000-9669-c86808150000 pid=5384 execve guuid=47540fea-2200-0000-9669-c8680a150000 pid=5386 /usr/bin/killall guuid=b83ed3e9-2200-0000-9669-c86809150000 pid=5385->guuid=47540fea-2200-0000-9669-c8680a150000 pid=5386 execve guuid=842617eb-2200-0000-9669-c8680c150000 pid=5388 /usr/bin/killall guuid=2923e6ea-2200-0000-9669-c8680b150000 pid=5387->guuid=842617eb-2200-0000-9669-c8680c150000 pid=5388 execve guuid=b05586ec-2200-0000-9669-c8680e150000 pid=5390 /usr/bin/killall guuid=65be58ec-2200-0000-9669-c8680d150000 pid=5389->guuid=b05586ec-2200-0000-9669-c8680e150000 pid=5390 execve guuid=7f32eeed-2200-0000-9669-c86810150000 pid=5392 /usr/bin/killall guuid=f2f3bced-2200-0000-9669-c8680f150000 pid=5391->guuid=7f32eeed-2200-0000-9669-c86810150000 pid=5392 execve guuid=5fcaa7ef-2200-0000-9669-c86812150000 pid=5394 /usr/bin/killall guuid=33c65fef-2200-0000-9669-c86811150000 pid=5393->guuid=5fcaa7ef-2200-0000-9669-c86812150000 pid=5394 execve guuid=924438f1-2200-0000-9669-c86814150000 pid=5396 /usr/bin/killall guuid=2bb5f2f0-2200-0000-9669-c86813150000 pid=5395->guuid=924438f1-2200-0000-9669-c86814150000 pid=5396 execve guuid=22915df2-2200-0000-9669-c86816150000 pid=5398 /usr/bin/killall guuid=ad7833f2-2200-0000-9669-c86815150000 pid=5397->guuid=22915df2-2200-0000-9669-c86816150000 pid=5398 execve guuid=42b0e821-2400-0000-9669-c86818150000 pid=5400 /usr/bin/pgrep guuid=77648521-2400-0000-9669-c86817150000 pid=5399->guuid=42b0e821-2400-0000-9669-c86818150000 pid=5400 execve guuid=eaeaca25-2400-0000-9669-c8681a150000 pid=5402 /usr/bin/killall guuid=03267525-2400-0000-9669-c86819150000 pid=5401->guuid=eaeaca25-2400-0000-9669-c8681a150000 pid=5402 execve guuid=e843f726-2400-0000-9669-c8681c150000 pid=5404 /usr/bin/killall guuid=0566a026-2400-0000-9669-c8681b150000 pid=5403->guuid=e843f726-2400-0000-9669-c8681c150000 pid=5404 execve guuid=12537c28-2400-0000-9669-c8681e150000 pid=5406 /usr/bin/killall guuid=2e392d28-2400-0000-9669-c8681d150000 pid=5405->guuid=12537c28-2400-0000-9669-c8681e150000 pid=5406 execve guuid=91dd112a-2400-0000-9669-c86820150000 pid=5408 /usr/bin/killall guuid=4c99c129-2400-0000-9669-c8681f150000 pid=5407->guuid=91dd112a-2400-0000-9669-c86820150000 pid=5408 execve guuid=2fcba12b-2400-0000-9669-c86822150000 pid=5410 /usr/bin/killall guuid=5f58532b-2400-0000-9669-c86821150000 pid=5409->guuid=2fcba12b-2400-0000-9669-c86822150000 pid=5410 execve guuid=a4bf3e2d-2400-0000-9669-c86824150000 pid=5412 /usr/bin/killall guuid=59c2f02c-2400-0000-9669-c86823150000 pid=5411->guuid=a4bf3e2d-2400-0000-9669-c86824150000 pid=5412 execve guuid=879cf62e-2400-0000-9669-c86826150000 pid=5414 /usr/bin/killall guuid=79329a2e-2400-0000-9669-c86825150000 pid=5413->guuid=879cf62e-2400-0000-9669-c86826150000 pid=5414 execve guuid=c4f6a030-2400-0000-9669-c86828150000 pid=5416 /usr/bin/killall guuid=71f14930-2400-0000-9669-c86827150000 pid=5415->guuid=c4f6a030-2400-0000-9669-c86828150000 pid=5416 execve guuid=9eaf9260-2500-0000-9669-c8682a150000 pid=5418 /usr/bin/pgrep guuid=b3bb3c60-2500-0000-9669-c86829150000 pid=5417->guuid=9eaf9260-2500-0000-9669-c8682a150000 pid=5418 execve guuid=a1065b65-2500-0000-9669-c8682c150000 pid=5420 /usr/bin/killall guuid=226ffa64-2500-0000-9669-c8682b150000 pid=5419->guuid=a1065b65-2500-0000-9669-c8682c150000 pid=5420 execve guuid=c7931567-2500-0000-9669-c8682e150000 pid=5422 /usr/bin/killall guuid=d12cbd66-2500-0000-9669-c8682d150000 pid=5421->guuid=c7931567-2500-0000-9669-c8682e150000 pid=5422 execve guuid=8b69ca68-2500-0000-9669-c86830150000 pid=5424 /usr/bin/killall guuid=f36c7168-2500-0000-9669-c8682f150000 pid=5423->guuid=8b69ca68-2500-0000-9669-c86830150000 pid=5424 execve guuid=471b5b6a-2500-0000-9669-c86832150000 pid=5426 /usr/bin/killall guuid=0de5166a-2500-0000-9669-c86831150000 pid=5425->guuid=471b5b6a-2500-0000-9669-c86832150000 pid=5426 execve guuid=cbe4116c-2500-0000-9669-c86834150000 pid=5428 /usr/bin/killall guuid=f934c86b-2500-0000-9669-c86833150000 pid=5427->guuid=cbe4116c-2500-0000-9669-c86834150000 pid=5428 execve guuid=a4afb66d-2500-0000-9669-c86836150000 pid=5430 /usr/bin/killall guuid=8ee15d6d-2500-0000-9669-c86835150000 pid=5429->guuid=a4afb66d-2500-0000-9669-c86836150000 pid=5430 execve guuid=18cc776f-2500-0000-9669-c86838150000 pid=5432 /usr/bin/killall guuid=7d48196f-2500-0000-9669-c86837150000 pid=5431->guuid=18cc776f-2500-0000-9669-c86838150000 pid=5432 execve guuid=90373671-2500-0000-9669-c8683a150000 pid=5434 /usr/bin/killall guuid=891fd670-2500-0000-9669-c86839150000 pid=5433->guuid=90373671-2500-0000-9669-c8683a150000 pid=5434 execve guuid=2fdd30a1-2600-0000-9669-c8683c150000 pid=5436 /usr/bin/pgrep guuid=caabc3a0-2600-0000-9669-c8683b150000 pid=5435->guuid=2fdd30a1-2600-0000-9669-c8683c150000 pid=5436 execve guuid=5e9bbaa5-2600-0000-9669-c8683e150000 pid=5438 /usr/bin/killall guuid=1a697ba5-2600-0000-9669-c8683d150000 pid=5437->guuid=5e9bbaa5-2600-0000-9669-c8683e150000 pid=5438 execve guuid=e8b4a0a7-2600-0000-9669-c86840150000 pid=5440 /usr/bin/killall guuid=732d3ba7-2600-0000-9669-c8683f150000 pid=5439->guuid=e8b4a0a7-2600-0000-9669-c86840150000 pid=5440 execve guuid=ed465da9-2600-0000-9669-c86842150000 pid=5442 /usr/bin/killall guuid=32ae07a9-2600-0000-9669-c86841150000 pid=5441->guuid=ed465da9-2600-0000-9669-c86842150000 pid=5442 execve guuid=c4ca1eab-2600-0000-9669-c86844150000 pid=5444 /usr/bin/killall guuid=6206c5aa-2600-0000-9669-c86843150000 pid=5443->guuid=c4ca1eab-2600-0000-9669-c86844150000 pid=5444 execve guuid=7666ebac-2600-0000-9669-c86846150000 pid=5446 /usr/bin/killall guuid=fcdb8cac-2600-0000-9669-c86845150000 pid=5445->guuid=7666ebac-2600-0000-9669-c86846150000 pid=5446 execve guuid=69f5abae-2600-0000-9669-c86848150000 pid=5448 /usr/bin/killall guuid=64ed50ae-2600-0000-9669-c86847150000 pid=5447->guuid=69f5abae-2600-0000-9669-c86848150000 pid=5448 execve guuid=061f72b0-2600-0000-9669-c8684a150000 pid=5450 /usr/bin/killall guuid=388217b0-2600-0000-9669-c86849150000 pid=5449->guuid=061f72b0-2600-0000-9669-c8684a150000 pid=5450 execve guuid=59f43bb2-2600-0000-9669-c8684c150000 pid=5452 /usr/bin/killall guuid=061ddfb1-2600-0000-9669-c8684b150000 pid=5451->guuid=59f43bb2-2600-0000-9669-c8684c150000 pid=5452 execve guuid=e8be72e2-2700-0000-9669-c8684f150000 pid=5455 /usr/bin/pgrep guuid=7fee19e2-2700-0000-9669-c8684e150000 pid=5454->guuid=e8be72e2-2700-0000-9669-c8684f150000 pid=5455 execve guuid=1607fee5-2700-0000-9669-c86852150000 pid=5458 /usr/bin/killall guuid=df5ea7e5-2700-0000-9669-c86851150000 pid=5457->guuid=1607fee5-2700-0000-9669-c86852150000 pid=5458 execve guuid=3d7226e7-2700-0000-9669-c86854150000 pid=5460 /usr/bin/killall guuid=0cafc8e6-2700-0000-9669-c86853150000 pid=5459->guuid=3d7226e7-2700-0000-9669-c86854150000 pid=5460 execve guuid=d13a3ae8-2700-0000-9669-c86856150000 pid=5462 /usr/bin/killall guuid=c88ee6e7-2700-0000-9669-c86855150000 pid=5461->guuid=d13a3ae8-2700-0000-9669-c86856150000 pid=5462 execve guuid=953117e9-2700-0000-9669-c86858150000 pid=5464 /usr/bin/killall guuid=5b19ebe8-2700-0000-9669-c86857150000 pid=5463->guuid=953117e9-2700-0000-9669-c86858150000 pid=5464 execve guuid=897db0ea-2700-0000-9669-c8685a150000 pid=5466 /usr/bin/killall guuid=46fe84ea-2700-0000-9669-c86859150000 pid=5465->guuid=897db0ea-2700-0000-9669-c8685a150000 pid=5466 execve guuid=d53544ec-2700-0000-9669-c8685c150000 pid=5468 /usr/bin/killall guuid=aa171aec-2700-0000-9669-c8685b150000 pid=5467->guuid=d53544ec-2700-0000-9669-c8685c150000 pid=5468 execve guuid=0fd7dced-2700-0000-9669-c8685e150000 pid=5470 /usr/bin/killall guuid=db0f9aed-2700-0000-9669-c8685d150000 pid=5469->guuid=0fd7dced-2700-0000-9669-c8685e150000 pid=5470 execve guuid=1f741def-2700-0000-9669-c86860150000 pid=5472 /usr/bin/killall guuid=52d0e9ee-2700-0000-9669-c8685f150000 pid=5471->guuid=1f741def-2700-0000-9669-c86860150000 pid=5472 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
96 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1735019 Sample: cron.elf Startdate: 13/07/2025 Architecture: LINUX Score: 96 37 206.123.128.67, 52852, 52856, 52858 LEASEWEB-USA-NYC-11US United States 2->37 39 gay.energy 2->39 41 daisy.ubuntu.com 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 4 other signatures 2->49 9 cron.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 cron.elf 9->12         started        process6 process7 14 cron.elf sh 12->14         started        16 cron.elf sh 12->16         started        18 cron.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Bashlite
Status:
Malicious
First seen:
2025-07-13 00:51:08 UTC
File Type:
ELF32 Little (Exe)
AV detection:
16 of 24 (66.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_83715433 Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_f51c5ac3 Linux_Trojan_Gafgyt_27de1106 Linux_Trojan_Gafgyt_1b2e2a3a Linux_Trojan_Gafgyt_9127f7be elf_bashlite_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_1b2e2a3a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_27de1106
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_83715433
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9127f7be
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f51c5ac3
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 20c192d7082c8cf898e3bbafb77dc45037c93eaee18ce9b1d11d381de835f222

(this sample)

  
Delivery method
Distributed via web download

Comments