MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2bbb387226de2faa8f60eaa2988e6a9a05c6d41b191ef0f24f029b184f260677. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 11 File information Comments

SHA256 hash: 2bbb387226de2faa8f60eaa2988e6a9a05c6d41b191ef0f24f029b184f260677
SHA3-384 hash: 82a901779fadd089e26d07cee4e148c27fedcc0a5f8f29f9bf0d03b059c3bce92fe30f1536f89a58d5b68eecbad6f8ff
SHA1 hash: 5a2a2c89a627d25df9013c6d8e9566c51bd09a40
MD5 hash: 0ec02e392287789c6f424831250c6be5
humanhash: oregon-failed-arkansas-summer
File name:nx86
Download: download sample
Signature Mirai
File size:156'176 bytes
First seen:2026-04-09 04:51:13 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:jWI5PyDWnIhlSa9vsGJhYrBA6NWvY3yjXyHmLhE:B5PyanIhlRvvBw38COhE
TLSH T155E31781BB43DAF3E85300F011B79B314A32FC3A582BDA91E3797DA1A9515C1E61A77C
telfhash t19c7129ba6dea0ce8bbd08800d24f1721fe1de23f256036a546b399743376f4151aac3d
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
Mirai
Details
Mirai
an XOR decryption key and at least a c2 socket address
Result
Verdict:
Malware
Maliciousness:

Behaviour
Runs as daemon
Connection attempt
Opens a port
Manages services
Launching a process
Sets a written file as executable
Creating a file
Collects information on the CPU
Collects information on the OS
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Deleting of the original file
Creates or modifies files in /init.d to set up autorun
Creates or modifies files to set up autorun
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
103
Number of processes launched:
7
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Persistence
Process Renaming
Anti-Debugging
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Result
Gathering data
Verdict:
Malicious
File Type:
elf.32.le
Detections:
HEUR:Trojan.Linux.Mirai.gen HEUR:Backdoor.Linux.Mirai.b
Status:
terminated
Behavior Graph:
%3 guuid=b4ef0fe7-1800-0000-1d91-8d42e50d0000 pid=3557 /usr/bin/sudo guuid=2eaadce8-1800-0000-1d91-8d42ec0d0000 pid=3564 /tmp/sample.bin delete-file net guuid=b4ef0fe7-1800-0000-1d91-8d42e50d0000 pid=3557->guuid=2eaadce8-1800-0000-1d91-8d42ec0d0000 pid=3564 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2eaadce8-1800-0000-1d91-8d42ec0d0000 pid=3564->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2a8f11e9-1800-0000-1d91-8d42ee0d0000 pid=3566 /tmp/sample.bin net zombie guuid=2eaadce8-1800-0000-1d91-8d42ec0d0000 pid=3564->guuid=2a8f11e9-1800-0000-1d91-8d42ee0d0000 pid=3566 clone 9a84751b-fec6-5c61-8d2a-f11015e11dad 94.156.152.233:18129 guuid=2a8f11e9-1800-0000-1d91-8d42ee0d0000 pid=3566->9a84751b-fec6-5c61-8d2a-f11015e11dad con guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567 /tmp/sample.bin write-config write-file guuid=2a8f11e9-1800-0000-1d91-8d42ee0d0000 pid=3566->guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567 clone guuid=f5bb1fe9-1800-0000-1d91-8d42f00d0000 pid=3568 /tmp/sample.bin guuid=2a8f11e9-1800-0000-1d91-8d42ee0d0000 pid=3566->guuid=f5bb1fe9-1800-0000-1d91-8d42f00d0000 pid=3568 clone guuid=306e4fe9-1800-0000-1d91-8d42f10d0000 pid=3569 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=306e4fe9-1800-0000-1d91-8d42f10d0000 pid=3569 execve guuid=b6b588e9-1800-0000-1d91-8d42f30d0000 pid=3571 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=b6b588e9-1800-0000-1d91-8d42f30d0000 pid=3571 execve guuid=305565ea-1800-0000-1d91-8d42f80d0000 pid=3576 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=305565ea-1800-0000-1d91-8d42f80d0000 pid=3576 execve guuid=8159c6ea-1800-0000-1d91-8d42fc0d0000 pid=3580 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=8159c6ea-1800-0000-1d91-8d42fc0d0000 pid=3580 execve guuid=6a6df7ea-1800-0000-1d91-8d42fd0d0000 pid=3581 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=6a6df7ea-1800-0000-1d91-8d42fd0d0000 pid=3581 execve guuid=2f2e79eb-1800-0000-1d91-8d42010e0000 pid=3585 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2f2e79eb-1800-0000-1d91-8d42010e0000 pid=3585 execve guuid=4cf1d2eb-1800-0000-1d91-8d42030e0000 pid=3587 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=4cf1d2eb-1800-0000-1d91-8d42030e0000 pid=3587 execve guuid=09be02ec-1800-0000-1d91-8d42050e0000 pid=3589 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=09be02ec-1800-0000-1d91-8d42050e0000 pid=3589 execve guuid=10e967ec-1800-0000-1d91-8d42080e0000 pid=3592 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=10e967ec-1800-0000-1d91-8d42080e0000 pid=3592 execve guuid=7dbbcaec-1800-0000-1d91-8d420b0e0000 pid=3595 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=7dbbcaec-1800-0000-1d91-8d420b0e0000 pid=3595 execve guuid=e0cfffec-1800-0000-1d91-8d420c0e0000 pid=3596 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e0cfffec-1800-0000-1d91-8d420c0e0000 pid=3596 execve guuid=735673ed-1800-0000-1d91-8d420f0e0000 pid=3599 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=735673ed-1800-0000-1d91-8d420f0e0000 pid=3599 execve guuid=a80acced-1800-0000-1d91-8d42120e0000 pid=3602 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=a80acced-1800-0000-1d91-8d42120e0000 pid=3602 execve guuid=30b3f8ed-1800-0000-1d91-8d42130e0000 pid=3603 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=30b3f8ed-1800-0000-1d91-8d42130e0000 pid=3603 execve guuid=7bf568ee-1800-0000-1d91-8d42170e0000 pid=3607 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=7bf568ee-1800-0000-1d91-8d42170e0000 pid=3607 execve guuid=1499deee-1800-0000-1d91-8d421a0e0000 pid=3610 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=1499deee-1800-0000-1d91-8d421a0e0000 pid=3610 execve guuid=2ec01aef-1800-0000-1d91-8d421b0e0000 pid=3611 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2ec01aef-1800-0000-1d91-8d421b0e0000 pid=3611 execve guuid=e7cecdef-1800-0000-1d91-8d421f0e0000 pid=3615 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e7cecdef-1800-0000-1d91-8d421f0e0000 pid=3615 execve guuid=e34142f0-1800-0000-1d91-8d42220e0000 pid=3618 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e34142f0-1800-0000-1d91-8d42220e0000 pid=3618 execve guuid=f7d57bf0-1800-0000-1d91-8d42240e0000 pid=3620 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=f7d57bf0-1800-0000-1d91-8d42240e0000 pid=3620 execve guuid=7ef0fdf0-1800-0000-1d91-8d42270e0000 pid=3623 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=7ef0fdf0-1800-0000-1d91-8d42270e0000 pid=3623 execve guuid=69e75cf1-1800-0000-1d91-8d422a0e0000 pid=3626 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=69e75cf1-1800-0000-1d91-8d422a0e0000 pid=3626 execve guuid=2c948cf1-1800-0000-1d91-8d422c0e0000 pid=3628 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2c948cf1-1800-0000-1d91-8d422c0e0000 pid=3628 execve guuid=a2b0fef1-1800-0000-1d91-8d422f0e0000 pid=3631 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=a2b0fef1-1800-0000-1d91-8d422f0e0000 pid=3631 execve guuid=9ccf5df2-1800-0000-1d91-8d42330e0000 pid=3635 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=9ccf5df2-1800-0000-1d91-8d42330e0000 pid=3635 execve guuid=487f8ef2-1800-0000-1d91-8d42340e0000 pid=3636 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=487f8ef2-1800-0000-1d91-8d42340e0000 pid=3636 execve guuid=c19702f3-1800-0000-1d91-8d42370e0000 pid=3639 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=c19702f3-1800-0000-1d91-8d42370e0000 pid=3639 execve guuid=103373f3-1800-0000-1d91-8d42390e0000 pid=3641 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=103373f3-1800-0000-1d91-8d42390e0000 pid=3641 execve guuid=2712b1f3-1800-0000-1d91-8d423b0e0000 pid=3643 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2712b1f3-1800-0000-1d91-8d423b0e0000 pid=3643 execve guuid=432440f4-1800-0000-1d91-8d423e0e0000 pid=3646 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=432440f4-1800-0000-1d91-8d423e0e0000 pid=3646 execve guuid=162adcf4-1800-0000-1d91-8d42410e0000 pid=3649 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=162adcf4-1800-0000-1d91-8d42410e0000 pid=3649 execve guuid=ac5e2a2e-1900-0000-1d91-8d42e00e0000 pid=3808 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=ac5e2a2e-1900-0000-1d91-8d42e00e0000 pid=3808 execve guuid=8ebc0e66-1900-0000-1d91-8d42a70f0000 pid=4007 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=8ebc0e66-1900-0000-1d91-8d42a70f0000 pid=4007 execve guuid=3d00ac66-1900-0000-1d91-8d42ac0f0000 pid=4012 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=3d00ac66-1900-0000-1d91-8d42ac0f0000 pid=4012 execve guuid=939ff196-1900-0000-1d91-8d4271100000 pid=4209 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=939ff196-1900-0000-1d91-8d4271100000 pid=4209 execve guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214 /tmp/sample.bin guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214 clone guuid=e0e1d497-1900-0000-1d91-8d4278100000 pid=4216 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e0e1d497-1900-0000-1d91-8d4278100000 pid=4216 execve guuid=2a222ec8-1900-0000-1d91-8d42fd100000 pid=4349 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2a222ec8-1900-0000-1d91-8d42fd100000 pid=4349 execve guuid=aaa8b2c8-1900-0000-1d91-8d42ff100000 pid=4351 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=aaa8b2c8-1900-0000-1d91-8d42ff100000 pid=4351 execve guuid=4ba0aff3-1900-0000-1d91-8d4236110000 pid=4406 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=4ba0aff3-1900-0000-1d91-8d4236110000 pid=4406 execve guuid=1c477ba4-1a00-0000-1d91-8d428f110000 pid=4495 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=1c477ba4-1a00-0000-1d91-8d428f110000 pid=4495 execve guuid=f159f6a4-1a00-0000-1d91-8d4291110000 pid=4497 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=f159f6a4-1a00-0000-1d91-8d4291110000 pid=4497 execve guuid=df2f77a5-1a00-0000-1d91-8d4293110000 pid=4499 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=df2f77a5-1a00-0000-1d91-8d4293110000 pid=4499 execve guuid=ec4af7a5-1a00-0000-1d91-8d4295110000 pid=4501 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=ec4af7a5-1a00-0000-1d91-8d4295110000 pid=4501 execve guuid=c8677aa6-1a00-0000-1d91-8d4297110000 pid=4503 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=c8677aa6-1a00-0000-1d91-8d4297110000 pid=4503 execve guuid=d41206a7-1a00-0000-1d91-8d4299110000 pid=4505 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=d41206a7-1a00-0000-1d91-8d4299110000 pid=4505 execve guuid=2bfcb0a7-1a00-0000-1d91-8d429b110000 pid=4507 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=2bfcb0a7-1a00-0000-1d91-8d429b110000 pid=4507 execve guuid=253f57a8-1a00-0000-1d91-8d429d110000 pid=4509 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=253f57a8-1a00-0000-1d91-8d429d110000 pid=4509 execve guuid=60c9fda8-1a00-0000-1d91-8d429f110000 pid=4511 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=60c9fda8-1a00-0000-1d91-8d429f110000 pid=4511 execve guuid=c898b3a9-1a00-0000-1d91-8d42a1110000 pid=4513 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=c898b3a9-1a00-0000-1d91-8d42a1110000 pid=4513 execve guuid=4aa833aa-1a00-0000-1d91-8d42a3110000 pid=4515 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=4aa833aa-1a00-0000-1d91-8d42a3110000 pid=4515 execve guuid=9173abaa-1a00-0000-1d91-8d42a5110000 pid=4517 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=9173abaa-1a00-0000-1d91-8d42a5110000 pid=4517 execve guuid=b7e668ab-1a00-0000-1d91-8d42a7110000 pid=4519 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=b7e668ab-1a00-0000-1d91-8d42a7110000 pid=4519 execve guuid=0eb7ecab-1a00-0000-1d91-8d42a9110000 pid=4521 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=0eb7ecab-1a00-0000-1d91-8d42a9110000 pid=4521 execve guuid=48b195ac-1a00-0000-1d91-8d42ab110000 pid=4523 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=48b195ac-1a00-0000-1d91-8d42ab110000 pid=4523 execve guuid=94ad2dad-1a00-0000-1d91-8d42ad110000 pid=4525 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=94ad2dad-1a00-0000-1d91-8d42ad110000 pid=4525 execve guuid=ac98a1ad-1a00-0000-1d91-8d42af110000 pid=4527 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=ac98a1ad-1a00-0000-1d91-8d42af110000 pid=4527 execve guuid=d82bd4ad-1a00-0000-1d91-8d42b0110000 pid=4528 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=d82bd4ad-1a00-0000-1d91-8d42b0110000 pid=4528 execve guuid=3f6e35ae-1a00-0000-1d91-8d42b2110000 pid=4530 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=3f6e35ae-1a00-0000-1d91-8d42b2110000 pid=4530 execve guuid=c32974ba-1a00-0000-1d91-8d42ba110000 pid=4538 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=c32974ba-1a00-0000-1d91-8d42ba110000 pid=4538 execve guuid=fbec1fbb-1a00-0000-1d91-8d42bc110000 pid=4540 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=fbec1fbb-1a00-0000-1d91-8d42bc110000 pid=4540 execve guuid=0707ddbb-1a00-0000-1d91-8d42be110000 pid=4542 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=0707ddbb-1a00-0000-1d91-8d42be110000 pid=4542 execve guuid=115c7abc-1a00-0000-1d91-8d42c0110000 pid=4544 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=115c7abc-1a00-0000-1d91-8d42c0110000 pid=4544 execve guuid=944833bd-1a00-0000-1d91-8d42c2110000 pid=4546 /usr/bin/dash guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=944833bd-1a00-0000-1d91-8d42c2110000 pid=4546 execve guuid=e9e980bd-1a00-0000-1d91-8d42c3110000 pid=4547 /tmp/sample.bin guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e9e980bd-1a00-0000-1d91-8d42c3110000 pid=4547 clone guuid=e3bc85bd-1a00-0000-1d91-8d42c4110000 pid=4548 /tmp/sample.bin guuid=36d31be9-1800-0000-1d91-8d42ef0d0000 pid=3567->guuid=e3bc85bd-1a00-0000-1d91-8d42c4110000 pid=4548 clone guuid=08d0b1e9-1800-0000-1d91-8d42f50d0000 pid=3573 /usr/bin/chattr guuid=b6b588e9-1800-0000-1d91-8d42f30d0000 pid=3571->guuid=08d0b1e9-1800-0000-1d91-8d42f50d0000 pid=3573 execve guuid=49e78eea-1800-0000-1d91-8d42fa0d0000 pid=3578 /usr/bin/chmod guuid=305565ea-1800-0000-1d91-8d42f80d0000 pid=3576->guuid=49e78eea-1800-0000-1d91-8d42fa0d0000 pid=3578 execve guuid=44e83ceb-1800-0000-1d91-8d42ff0d0000 pid=3583 /usr/bin/chattr guuid=6a6df7ea-1800-0000-1d91-8d42fd0d0000 pid=3581->guuid=44e83ceb-1800-0000-1d91-8d42ff0d0000 pid=3583 execve guuid=30e2a1eb-1800-0000-1d91-8d42020e0000 pid=3586 /usr/bin/chmod guuid=2f2e79eb-1800-0000-1d91-8d42010e0000 pid=3585->guuid=30e2a1eb-1800-0000-1d91-8d42020e0000 pid=3586 execve guuid=ff6c2eec-1800-0000-1d91-8d42060e0000 pid=3590 /usr/bin/chattr guuid=09be02ec-1800-0000-1d91-8d42050e0000 pid=3589->guuid=ff6c2eec-1800-0000-1d91-8d42060e0000 pid=3590 execve guuid=02178cec-1800-0000-1d91-8d42090e0000 pid=3593 /usr/bin/chmod guuid=10e967ec-1800-0000-1d91-8d42080e0000 pid=3592->guuid=02178cec-1800-0000-1d91-8d42090e0000 pid=3593 execve guuid=31b72ded-1800-0000-1d91-8d420d0e0000 pid=3597 /usr/bin/chattr guuid=e0cfffec-1800-0000-1d91-8d420c0e0000 pid=3596->guuid=31b72ded-1800-0000-1d91-8d420d0e0000 pid=3597 execve guuid=3bca9bed-1800-0000-1d91-8d42100e0000 pid=3600 /usr/bin/chmod guuid=735673ed-1800-0000-1d91-8d420f0e0000 pid=3599->guuid=3bca9bed-1800-0000-1d91-8d42100e0000 pid=3600 execve guuid=614921ee-1800-0000-1d91-8d42150e0000 pid=3605 /usr/bin/chattr guuid=30b3f8ed-1800-0000-1d91-8d42130e0000 pid=3603->guuid=614921ee-1800-0000-1d91-8d42150e0000 pid=3605 execve guuid=1e8da5ee-1800-0000-1d91-8d42190e0000 pid=3609 /usr/bin/chmod guuid=7bf568ee-1800-0000-1d91-8d42170e0000 pid=3607->guuid=1e8da5ee-1800-0000-1d91-8d42190e0000 pid=3609 execve guuid=baec7def-1800-0000-1d91-8d421d0e0000 pid=3613 /usr/bin/chattr guuid=2ec01aef-1800-0000-1d91-8d421b0e0000 pid=3611->guuid=baec7def-1800-0000-1d91-8d421d0e0000 pid=3613 execve guuid=c273ffef-1800-0000-1d91-8d42200e0000 pid=3616 /usr/bin/chmod guuid=e7cecdef-1800-0000-1d91-8d421f0e0000 pid=3615->guuid=c273ffef-1800-0000-1d91-8d42200e0000 pid=3616 execve guuid=ece8a9f0-1800-0000-1d91-8d42250e0000 pid=3621 /usr/bin/chattr guuid=f7d57bf0-1800-0000-1d91-8d42240e0000 pid=3620->guuid=ece8a9f0-1800-0000-1d91-8d42250e0000 pid=3621 execve guuid=786a29f1-1800-0000-1d91-8d42280e0000 pid=3624 /usr/bin/chmod guuid=7ef0fdf0-1800-0000-1d91-8d42270e0000 pid=3623->guuid=786a29f1-1800-0000-1d91-8d42280e0000 pid=3624 execve guuid=b0ffb4f1-1800-0000-1d91-8d422e0e0000 pid=3630 /usr/bin/chattr guuid=2c948cf1-1800-0000-1d91-8d422c0e0000 pid=3628->guuid=b0ffb4f1-1800-0000-1d91-8d422e0e0000 pid=3630 execve guuid=a56629f2-1800-0000-1d91-8d42310e0000 pid=3633 /usr/bin/chmod guuid=a2b0fef1-1800-0000-1d91-8d422f0e0000 pid=3631->guuid=a56629f2-1800-0000-1d91-8d42310e0000 pid=3633 execve guuid=70d8bbf2-1800-0000-1d91-8d42360e0000 pid=3638 /usr/bin/chattr guuid=487f8ef2-1800-0000-1d91-8d42340e0000 pid=3636->guuid=70d8bbf2-1800-0000-1d91-8d42360e0000 pid=3638 execve guuid=76622df3-1800-0000-1d91-8d42380e0000 pid=3640 /usr/bin/chmod guuid=c19702f3-1800-0000-1d91-8d42370e0000 pid=3639->guuid=76622df3-1800-0000-1d91-8d42380e0000 pid=3640 execve guuid=0153e1f3-1800-0000-1d91-8d423c0e0000 pid=3644 /usr/bin/chattr guuid=2712b1f3-1800-0000-1d91-8d423b0e0000 pid=3643->guuid=0153e1f3-1800-0000-1d91-8d423c0e0000 pid=3644 execve guuid=fa3468f4-1800-0000-1d91-8d423f0e0000 pid=3647 /usr/bin/chmod guuid=432440f4-1800-0000-1d91-8d423e0e0000 pid=3646->guuid=fa3468f4-1800-0000-1d91-8d423f0e0000 pid=3647 execve guuid=03760df5-1800-0000-1d91-8d42430e0000 pid=3651 /usr/bin/systemctl guuid=162adcf4-1800-0000-1d91-8d42410e0000 pid=3649->guuid=03760df5-1800-0000-1d91-8d42430e0000 pid=3651 execve guuid=4578552e-1900-0000-1d91-8d42e10e0000 pid=3809 /usr/bin/systemctl guuid=ac5e2a2e-1900-0000-1d91-8d42e00e0000 pid=3808->guuid=4578552e-1900-0000-1d91-8d42e10e0000 pid=3809 execve guuid=ae4b6266-1900-0000-1d91-8d42a80f0000 pid=4008 /etc/init.d/watchdog-systemd guuid=8ebc0e66-1900-0000-1d91-8d42a70f0000 pid=4007->guuid=ae4b6266-1900-0000-1d91-8d42a80f0000 pid=4008 execve guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010 /usr/bin/dash guuid=ae4b6266-1900-0000-1d91-8d42a80f0000 pid=4008->guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010 clone guuid=14caac66-1900-0000-1d91-8d42ad0f0000 pid=4013 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=14caac66-1900-0000-1d91-8d42ad0f0000 pid=4013 execve guuid=eebaf96b-1900-0000-1d91-8d42c60f0000 pid=4038 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=eebaf96b-1900-0000-1d91-8d42c60f0000 pid=4038 execve guuid=68ee95c0-1b00-0000-1d91-8d42c6110000 pid=4550 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=68ee95c0-1b00-0000-1d91-8d42c6110000 pid=4550 execve guuid=7aed01c3-1b00-0000-1d91-8d42c7110000 pid=4551 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=7aed01c3-1b00-0000-1d91-8d42c7110000 pid=4551 execve guuid=9d716317-1e00-0000-1d91-8d42ca110000 pid=4554 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=9d716317-1e00-0000-1d91-8d42ca110000 pid=4554 execve guuid=4a356b1a-1e00-0000-1d91-8d42cb110000 pid=4555 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=4a356b1a-1e00-0000-1d91-8d42cb110000 pid=4555 execve guuid=69f7ca6e-2000-0000-1d91-8d42ce110000 pid=4558 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=69f7ca6e-2000-0000-1d91-8d42ce110000 pid=4558 execve guuid=93e2ed72-2000-0000-1d91-8d42cf110000 pid=4559 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=93e2ed72-2000-0000-1d91-8d42cf110000 pid=4559 execve guuid=c85a4bc7-2200-0000-1d91-8d420b120000 pid=4619 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=c85a4bc7-2200-0000-1d91-8d420b120000 pid=4619 execve guuid=027c13ca-2200-0000-1d91-8d420c120000 pid=4620 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=027c13ca-2200-0000-1d91-8d420c120000 pid=4620 execve guuid=4915611e-2500-0000-1d91-8d420f120000 pid=4623 /usr/bin/pgrep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=4915611e-2500-0000-1d91-8d420f120000 pid=4623 execve guuid=4d828920-2500-0000-1d91-8d4210120000 pid=4624 /usr/bin/sleep guuid=d40b9066-1900-0000-1d91-8d42aa0f0000 pid=4010->guuid=4d828920-2500-0000-1d91-8d4210120000 pid=4624 execve guuid=e395f066-1900-0000-1d91-8d42af0f0000 pid=4015 /usr/bin/systemctl guuid=3d00ac66-1900-0000-1d91-8d42ac0f0000 pid=4012->guuid=e395f066-1900-0000-1d91-8d42af0f0000 pid=4015 execve guuid=e2f8e667-1900-0000-1d91-8d42b30f0000 pid=4019 /usr/lib/systemd/systemd-sysv-install guuid=e395f066-1900-0000-1d91-8d42af0f0000 pid=4015->guuid=e2f8e667-1900-0000-1d91-8d42b30f0000 pid=4019 execve guuid=d58e6568-1900-0000-1d91-8d42b40f0000 pid=4020 /usr/bin/getopt guuid=e2f8e667-1900-0000-1d91-8d42b30f0000 pid=4019->guuid=d58e6568-1900-0000-1d91-8d42b40f0000 pid=4020 execve guuid=54b8a068-1900-0000-1d91-8d42b60f0000 pid=4022 /usr/sbin/update-rc.d guuid=e2f8e667-1900-0000-1d91-8d42b30f0000 pid=4019->guuid=54b8a068-1900-0000-1d91-8d42b60f0000 pid=4022 execve guuid=1add5795-1900-0000-1d91-8d4268100000 pid=4200 /usr/sbin/update-rc.d guuid=e2f8e667-1900-0000-1d91-8d42b30f0000 pid=4019->guuid=1add5795-1900-0000-1d91-8d4268100000 pid=4200 execve guuid=dd8a446b-1900-0000-1d91-8d42c10f0000 pid=4033 /usr/bin/systemctl guuid=54b8a068-1900-0000-1d91-8d42b60f0000 pid=4022->guuid=dd8a446b-1900-0000-1d91-8d42c10f0000 pid=4033 execve guuid=3a391997-1900-0000-1d91-8d4273100000 pid=4211 /usr/bin/mount guuid=939ff196-1900-0000-1d91-8d4271100000 pid=4209->guuid=3a391997-1900-0000-1d91-8d4273100000 pid=4211 execve guuid=dedc0898-1900-0000-1d91-8d427a100000 pid=4218 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=dedc0898-1900-0000-1d91-8d427a100000 pid=4218 execve guuid=881d3798-1900-0000-1d91-8d427b100000 pid=4219 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=881d3798-1900-0000-1d91-8d427b100000 pid=4219 execve guuid=7a569e98-1900-0000-1d91-8d427d100000 pid=4221 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=7a569e98-1900-0000-1d91-8d427d100000 pid=4221 execve guuid=2e310699-1900-0000-1d91-8d4280100000 pid=4224 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=2e310699-1900-0000-1d91-8d4280100000 pid=4224 execve guuid=1fe94e99-1900-0000-1d91-8d4282100000 pid=4226 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=1fe94e99-1900-0000-1d91-8d4282100000 pid=4226 execve guuid=9bbc0d9a-1900-0000-1d91-8d4287100000 pid=4231 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=9bbc0d9a-1900-0000-1d91-8d4287100000 pid=4231 execve guuid=42c4ad9b-1900-0000-1d91-8d4290100000 pid=4240 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=42c4ad9b-1900-0000-1d91-8d4290100000 pid=4240 execve guuid=57c47e9c-1900-0000-1d91-8d4294100000 pid=4244 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=57c47e9c-1900-0000-1d91-8d4294100000 pid=4244 execve guuid=7139ef9c-1900-0000-1d91-8d4296100000 pid=4246 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=7139ef9c-1900-0000-1d91-8d4296100000 pid=4246 execve guuid=04375c9d-1900-0000-1d91-8d4298100000 pid=4248 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=04375c9d-1900-0000-1d91-8d4298100000 pid=4248 execve guuid=f8f18c9d-1900-0000-1d91-8d4299100000 pid=4249 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=f8f18c9d-1900-0000-1d91-8d4299100000 pid=4249 execve guuid=4c2ff09d-1900-0000-1d91-8d429b100000 pid=4251 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=4c2ff09d-1900-0000-1d91-8d429b100000 pid=4251 execve guuid=0e3e669e-1900-0000-1d91-8d429d100000 pid=4253 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=0e3e669e-1900-0000-1d91-8d429d100000 pid=4253 execve guuid=8e3c9c9e-1900-0000-1d91-8d429e100000 pid=4254 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=8e3c9c9e-1900-0000-1d91-8d429e100000 pid=4254 execve guuid=3ccd49a2-1900-0000-1d91-8d42b0100000 pid=4272 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=3ccd49a2-1900-0000-1d91-8d42b0100000 pid=4272 execve guuid=925246a3-1900-0000-1d91-8d42b3100000 pid=4275 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=925246a3-1900-0000-1d91-8d42b3100000 pid=4275 execve guuid=47b3f9a3-1900-0000-1d91-8d42b5100000 pid=4277 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=47b3f9a3-1900-0000-1d91-8d42b5100000 pid=4277 execve guuid=29fc62a5-1900-0000-1d91-8d42b7100000 pid=4279 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=29fc62a5-1900-0000-1d91-8d42b7100000 pid=4279 execve guuid=5b125bac-1900-0000-1d91-8d42bb100000 pid=4283 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=5b125bac-1900-0000-1d91-8d42bb100000 pid=4283 execve guuid=671302ad-1900-0000-1d91-8d42bd100000 pid=4285 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=671302ad-1900-0000-1d91-8d42bd100000 pid=4285 execve guuid=94092daf-1900-0000-1d91-8d42bf100000 pid=4287 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=94092daf-1900-0000-1d91-8d42bf100000 pid=4287 execve guuid=2c8b50b1-1900-0000-1d91-8d42c4100000 pid=4292 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=2c8b50b1-1900-0000-1d91-8d42c4100000 pid=4292 execve guuid=545a8cb1-1900-0000-1d91-8d42c5100000 pid=4293 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=545a8cb1-1900-0000-1d91-8d42c5100000 pid=4293 execve guuid=6a83c4b2-1900-0000-1d91-8d42cb100000 pid=4299 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=6a83c4b2-1900-0000-1d91-8d42cb100000 pid=4299 execve guuid=2f863fb3-1900-0000-1d91-8d42ce100000 pid=4302 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=2f863fb3-1900-0000-1d91-8d42ce100000 pid=4302 execve guuid=7aaab3b3-1900-0000-1d91-8d42d0100000 pid=4304 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=7aaab3b3-1900-0000-1d91-8d42d0100000 pid=4304 execve guuid=577925b4-1900-0000-1d91-8d42d3100000 pid=4307 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=577925b4-1900-0000-1d91-8d42d3100000 pid=4307 execve guuid=c23581b4-1900-0000-1d91-8d42d5100000 pid=4309 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=c23581b4-1900-0000-1d91-8d42d5100000 pid=4309 execve guuid=b6e3b0b4-1900-0000-1d91-8d42d6100000 pid=4310 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=b6e3b0b4-1900-0000-1d91-8d42d6100000 pid=4310 execve guuid=e9b91eb5-1900-0000-1d91-8d42d8100000 pid=4312 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=e9b91eb5-1900-0000-1d91-8d42d8100000 pid=4312 execve guuid=6c6582b5-1900-0000-1d91-8d42db100000 pid=4315 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=6c6582b5-1900-0000-1d91-8d42db100000 pid=4315 execve guuid=a35c28b9-1900-0000-1d91-8d42e3100000 pid=4323 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=a35c28b9-1900-0000-1d91-8d42e3100000 pid=4323 execve guuid=2e23c9f6-1900-0000-1d91-8d423c110000 pid=4412 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=2e23c9f6-1900-0000-1d91-8d423c110000 pid=4412 execve guuid=9f12f6f4-2000-0000-1d91-8d42d0110000 pid=4560 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=9f12f6f4-2000-0000-1d91-8d42d0110000 pid=4560 execve guuid=0f6637f5-2000-0000-1d91-8d42d1110000 pid=4561 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=0f6637f5-2000-0000-1d91-8d42d1110000 pid=4561 execve guuid=2f13b0f5-2000-0000-1d91-8d42d3110000 pid=4563 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=2f13b0f5-2000-0000-1d91-8d42d3110000 pid=4563 execve guuid=743b18f6-2000-0000-1d91-8d42d5110000 pid=4565 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=743b18f6-2000-0000-1d91-8d42d5110000 pid=4565 execve guuid=cc1c50f6-2000-0000-1d91-8d42d6110000 pid=4566 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=cc1c50f6-2000-0000-1d91-8d42d6110000 pid=4566 execve guuid=9d61c2f6-2000-0000-1d91-8d42d8110000 pid=4568 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=9d61c2f6-2000-0000-1d91-8d42d8110000 pid=4568 execve guuid=dc6c2cf7-2000-0000-1d91-8d42da110000 pid=4570 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=dc6c2cf7-2000-0000-1d91-8d42da110000 pid=4570 execve guuid=c6fe62f7-2000-0000-1d91-8d42db110000 pid=4571 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=c6fe62f7-2000-0000-1d91-8d42db110000 pid=4571 execve guuid=a830f1f7-2000-0000-1d91-8d42dd110000 pid=4573 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=a830f1f7-2000-0000-1d91-8d42dd110000 pid=4573 execve guuid=05d15ef8-2000-0000-1d91-8d42df110000 pid=4575 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=05d15ef8-2000-0000-1d91-8d42df110000 pid=4575 execve guuid=671696f8-2000-0000-1d91-8d42e0110000 pid=4576 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=671696f8-2000-0000-1d91-8d42e0110000 pid=4576 execve guuid=6d360ff9-2000-0000-1d91-8d42e2110000 pid=4578 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=6d360ff9-2000-0000-1d91-8d42e2110000 pid=4578 execve guuid=77f778f9-2000-0000-1d91-8d42e4110000 pid=4580 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=77f778f9-2000-0000-1d91-8d42e4110000 pid=4580 execve guuid=e7bcaef9-2000-0000-1d91-8d42e5110000 pid=4581 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=e7bcaef9-2000-0000-1d91-8d42e5110000 pid=4581 execve guuid=42f721fa-2000-0000-1d91-8d42e7110000 pid=4583 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=42f721fa-2000-0000-1d91-8d42e7110000 pid=4583 execve guuid=f1228afa-2000-0000-1d91-8d42e9110000 pid=4585 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=f1228afa-2000-0000-1d91-8d42e9110000 pid=4585 execve guuid=7329c5fa-2000-0000-1d91-8d42ea110000 pid=4586 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=7329c5fa-2000-0000-1d91-8d42ea110000 pid=4586 execve guuid=f37f45fb-2000-0000-1d91-8d42ec110000 pid=4588 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=f37f45fb-2000-0000-1d91-8d42ec110000 pid=4588 execve guuid=1bddb2fb-2000-0000-1d91-8d42ee110000 pid=4590 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=1bddb2fb-2000-0000-1d91-8d42ee110000 pid=4590 execve guuid=eb05f3fb-2000-0000-1d91-8d42ef110000 pid=4591 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=eb05f3fb-2000-0000-1d91-8d42ef110000 pid=4591 execve guuid=cc8d6afc-2000-0000-1d91-8d42f1110000 pid=4593 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=cc8d6afc-2000-0000-1d91-8d42f1110000 pid=4593 execve guuid=4c8dd7fc-2000-0000-1d91-8d42f3110000 pid=4595 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=4c8dd7fc-2000-0000-1d91-8d42f3110000 pid=4595 execve guuid=e7440dfd-2000-0000-1d91-8d42f4110000 pid=4596 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=e7440dfd-2000-0000-1d91-8d42f4110000 pid=4596 execve guuid=dbc689fd-2000-0000-1d91-8d42f6110000 pid=4598 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=dbc689fd-2000-0000-1d91-8d42f6110000 pid=4598 execve guuid=9a1bf3fd-2000-0000-1d91-8d42f8110000 pid=4600 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=9a1bf3fd-2000-0000-1d91-8d42f8110000 pid=4600 execve guuid=bc692afe-2000-0000-1d91-8d42f9110000 pid=4601 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=bc692afe-2000-0000-1d91-8d42f9110000 pid=4601 execve guuid=96d09afe-2000-0000-1d91-8d42fb110000 pid=4603 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=96d09afe-2000-0000-1d91-8d42fb110000 pid=4603 execve guuid=303107ff-2000-0000-1d91-8d42fd110000 pid=4605 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=303107ff-2000-0000-1d91-8d42fd110000 pid=4605 execve guuid=e36744ff-2000-0000-1d91-8d42fe110000 pid=4606 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=e36744ff-2000-0000-1d91-8d42fe110000 pid=4606 execve guuid=9f8bbeff-2000-0000-1d91-8d4200120000 pid=4608 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=9f8bbeff-2000-0000-1d91-8d4200120000 pid=4608 execve guuid=f1052e00-2100-0000-1d91-8d4202120000 pid=4610 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=f1052e00-2100-0000-1d91-8d4202120000 pid=4610 execve guuid=fe0d8802-2100-0000-1d91-8d4204120000 pid=4612 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=fe0d8802-2100-0000-1d91-8d4204120000 pid=4612 execve guuid=7493c344-2100-0000-1d91-8d4208120000 pid=4616 /usr/bin/dash guuid=abebc797-1900-0000-1d91-8d4276100000 pid=4214->guuid=7493c344-2100-0000-1d91-8d4208120000 pid=4616 execve guuid=d2a70298-1900-0000-1d91-8d4279100000 pid=4217 /usr/sbin/update-rc.d guuid=e0e1d497-1900-0000-1d91-8d4278100000 pid=4216->guuid=d2a70298-1900-0000-1d91-8d4279100000 pid=4217 execve guuid=a7f6f899-1900-0000-1d91-8d4286100000 pid=4230 /usr/bin/systemctl guuid=d2a70298-1900-0000-1d91-8d4279100000 pid=4217->guuid=a7f6f899-1900-0000-1d91-8d4286100000 pid=4230 execve guuid=2bd26198-1900-0000-1d91-8d427c100000 pid=4220 /usr/bin/chattr guuid=881d3798-1900-0000-1d91-8d427b100000 pid=4219->guuid=2bd26198-1900-0000-1d91-8d427c100000 pid=4220 execve guuid=3b50c898-1900-0000-1d91-8d427e100000 pid=4222 /usr/bin/chmod guuid=7a569e98-1900-0000-1d91-8d427d100000 pid=4221->guuid=3b50c898-1900-0000-1d91-8d427e100000 pid=4222 execve guuid=2deaa399-1900-0000-1d91-8d4284100000 pid=4228 /usr/bin/chattr guuid=1fe94e99-1900-0000-1d91-8d4282100000 pid=4226->guuid=2deaa399-1900-0000-1d91-8d4284100000 pid=4228 execve guuid=7c19849a-1900-0000-1d91-8d4288100000 pid=4232 /usr/bin/chmod guuid=9bbc0d9a-1900-0000-1d91-8d4287100000 pid=4231->guuid=7c19849a-1900-0000-1d91-8d4288100000 pid=4232 execve guuid=a68eac9c-1900-0000-1d91-8d4295100000 pid=4245 /usr/bin/chattr guuid=57c47e9c-1900-0000-1d91-8d4294100000 pid=4244->guuid=a68eac9c-1900-0000-1d91-8d4295100000 pid=4245 execve guuid=eb76269d-1900-0000-1d91-8d4297100000 pid=4247 /usr/bin/chmod guuid=7139ef9c-1900-0000-1d91-8d4296100000 pid=4246->guuid=eb76269d-1900-0000-1d91-8d4297100000 pid=4247 execve guuid=51b1ba9d-1900-0000-1d91-8d429a100000 pid=4250 /usr/bin/chattr guuid=f8f18c9d-1900-0000-1d91-8d4299100000 pid=4249->guuid=51b1ba9d-1900-0000-1d91-8d429a100000 pid=4250 execve guuid=e4c41a9e-1900-0000-1d91-8d429c100000 pid=4252 /usr/bin/chmod guuid=4c2ff09d-1900-0000-1d91-8d429b100000 pid=4251->guuid=e4c41a9e-1900-0000-1d91-8d429c100000 pid=4252 execve guuid=5b21e59e-1900-0000-1d91-8d42a1100000 pid=4257 /usr/bin/chattr guuid=8e3c9c9e-1900-0000-1d91-8d429e100000 pid=4254->guuid=5b21e59e-1900-0000-1d91-8d42a1100000 pid=4257 execve guuid=773c76a2-1900-0000-1d91-8d42b1100000 pid=4273 /usr/bin/chmod guuid=3ccd49a2-1900-0000-1d91-8d42b0100000 pid=4272->guuid=773c76a2-1900-0000-1d91-8d42b1100000 pid=4273 execve guuid=39c86da4-1900-0000-1d91-8d42b6100000 pid=4278 /usr/bin/chattr guuid=47b3f9a3-1900-0000-1d91-8d42b5100000 pid=4277->guuid=39c86da4-1900-0000-1d91-8d42b6100000 pid=4278 execve guuid=4a68dda8-1900-0000-1d91-8d42b9100000 pid=4281 /usr/bin/chmod guuid=29fc62a5-1900-0000-1d91-8d42b7100000 pid=4279->guuid=4a68dda8-1900-0000-1d91-8d42b9100000 pid=4281 execve guuid=4550f9ad-1900-0000-1d91-8d42be100000 pid=4286 /usr/bin/chattr guuid=671302ad-1900-0000-1d91-8d42bd100000 pid=4285->guuid=4550f9ad-1900-0000-1d91-8d42be100000 pid=4286 execve guuid=557c58af-1900-0000-1d91-8d42c0100000 pid=4288 /usr/bin/chmod guuid=94092daf-1900-0000-1d91-8d42bf100000 pid=4287->guuid=557c58af-1900-0000-1d91-8d42c0100000 pid=4288 execve guuid=6c2b75b2-1900-0000-1d91-8d42ca100000 pid=4298 /usr/bin/chattr guuid=545a8cb1-1900-0000-1d91-8d42c5100000 pid=4293->guuid=6c2b75b2-1900-0000-1d91-8d42ca100000 pid=4298 execve guuid=321df3b2-1900-0000-1d91-8d42cc100000 pid=4300 /usr/bin/chmod guuid=6a83c4b2-1900-0000-1d91-8d42cb100000 pid=4299->guuid=321df3b2-1900-0000-1d91-8d42cc100000 pid=4300 execve guuid=c2ffdfb3-1900-0000-1d91-8d42d2100000 pid=4306 /usr/bin/chattr guuid=7aaab3b3-1900-0000-1d91-8d42d0100000 pid=4304->guuid=c2ffdfb3-1900-0000-1d91-8d42d2100000 pid=4306 execve guuid=d5134db4-1900-0000-1d91-8d42d4100000 pid=4308 /usr/bin/chmod guuid=577925b4-1900-0000-1d91-8d42d3100000 pid=4307->guuid=d5134db4-1900-0000-1d91-8d42d4100000 pid=4308 execve guuid=e306dcb4-1900-0000-1d91-8d42d7100000 pid=4311 /usr/bin/chattr guuid=b6e3b0b4-1900-0000-1d91-8d42d6100000 pid=4310->guuid=e306dcb4-1900-0000-1d91-8d42d7100000 pid=4311 execve guuid=66464ab5-1900-0000-1d91-8d42d9100000 pid=4313 /usr/bin/chmod guuid=e9b91eb5-1900-0000-1d91-8d42d8100000 pid=4312->guuid=66464ab5-1900-0000-1d91-8d42d9100000 pid=4313 execve guuid=3ecfcab6-1900-0000-1d91-8d42dc100000 pid=4316 /usr/bin/pgrep guuid=6c6582b5-1900-0000-1d91-8d42db100000 pid=4315->guuid=3ecfcab6-1900-0000-1d91-8d42dc100000 pid=4316 execve guuid=b33c50b9-1900-0000-1d91-8d42e5100000 pid=4325 /usr/bin/systemctl guuid=a35c28b9-1900-0000-1d91-8d42e3100000 pid=4323->guuid=b33c50b9-1900-0000-1d91-8d42e5100000 pid=4325 execve guuid=0a0a88c7-1900-0000-1d91-8d42fa100000 pid=4346 /usr/bin/systemctl guuid=a35c28b9-1900-0000-1d91-8d42e3100000 pid=4323->guuid=0a0a88c7-1900-0000-1d91-8d42fa100000 pid=4346 execve guuid=5556e2c8-1900-0000-1d91-8d4200110000 pid=4352 /usr/bin/systemctl guuid=aaa8b2c8-1900-0000-1d91-8d42ff100000 pid=4351->guuid=5556e2c8-1900-0000-1d91-8d4200110000 pid=4352 execve guuid=9e5502f4-1900-0000-1d91-8d4237110000 pid=4407 /usr/bin/systemctl guuid=4ba0aff3-1900-0000-1d91-8d4236110000 pid=4406->guuid=9e5502f4-1900-0000-1d91-8d4237110000 pid=4407 execve guuid=46766ef5-1900-0000-1d91-8d4239110000 pid=4409 /usr/lib/systemd/systemd-sysv-install guuid=9e5502f4-1900-0000-1d91-8d4237110000 pid=4407->guuid=46766ef5-1900-0000-1d91-8d4239110000 pid=4409 execve guuid=0625eaf5-1900-0000-1d91-8d423a110000 pid=4410 /usr/bin/getopt guuid=46766ef5-1900-0000-1d91-8d4239110000 pid=4409->guuid=0625eaf5-1900-0000-1d91-8d423a110000 pid=4410 execve guuid=9e12b5f6-1900-0000-1d91-8d423b110000 pid=4411 /usr/sbin/update-rc.d guuid=46766ef5-1900-0000-1d91-8d4239110000 pid=4409->guuid=9e12b5f6-1900-0000-1d91-8d423b110000 pid=4411 execve guuid=199a3b3b-1a00-0000-1d91-8d4253110000 pid=4435 /usr/sbin/update-rc.d guuid=46766ef5-1900-0000-1d91-8d4239110000 pid=4409->guuid=199a3b3b-1a00-0000-1d91-8d4253110000 pid=4435 execve guuid=efdf2dfa-1900-0000-1d91-8d423e110000 pid=4414 /usr/bin/systemctl guuid=9e12b5f6-1900-0000-1d91-8d423b110000 pid=4411->guuid=efdf2dfa-1900-0000-1d91-8d423e110000 pid=4414 execve guuid=fcaa14f7-1900-0000-1d91-8d423d110000 pid=4413 /usr/bin/systemctl guuid=2e23c9f6-1900-0000-1d91-8d423c110000 pid=4412->guuid=fcaa14f7-1900-0000-1d91-8d423d110000 pid=4413 execve guuid=59fda13d-1a00-0000-1d91-8d4254110000 pid=4436 /usr/bin/systemctl guuid=199a3b3b-1a00-0000-1d91-8d4253110000 pid=4435->guuid=59fda13d-1a00-0000-1d91-8d4254110000 pid=4436 execve guuid=52f5b2a4-1a00-0000-1d91-8d4290110000 pid=4496 /usr/bin/chattr guuid=1c477ba4-1a00-0000-1d91-8d428f110000 pid=4495->guuid=52f5b2a4-1a00-0000-1d91-8d4290110000 pid=4496 execve guuid=fa192ca5-1a00-0000-1d91-8d4292110000 pid=4498 /usr/bin/chattr guuid=f159f6a4-1a00-0000-1d91-8d4291110000 pid=4497->guuid=fa192ca5-1a00-0000-1d91-8d4292110000 pid=4498 execve guuid=2468aba5-1a00-0000-1d91-8d4294110000 pid=4500 /usr/bin/chattr guuid=df2f77a5-1a00-0000-1d91-8d4293110000 pid=4499->guuid=2468aba5-1a00-0000-1d91-8d4294110000 pid=4500 execve guuid=8eab25a6-1a00-0000-1d91-8d4296110000 pid=4502 /usr/bin/chattr guuid=ec4af7a5-1a00-0000-1d91-8d4295110000 pid=4501->guuid=8eab25a6-1a00-0000-1d91-8d4296110000 pid=4502 execve guuid=5f51b0a6-1a00-0000-1d91-8d4298110000 pid=4504 /usr/bin/chattr guuid=c8677aa6-1a00-0000-1d91-8d4297110000 pid=4503->guuid=5f51b0a6-1a00-0000-1d91-8d4298110000 pid=4504 execve guuid=3e773ca7-1a00-0000-1d91-8d429a110000 pid=4506 /usr/bin/mount guuid=d41206a7-1a00-0000-1d91-8d4299110000 pid=4505->guuid=3e773ca7-1a00-0000-1d91-8d429a110000 pid=4506 execve guuid=fae2e8a7-1a00-0000-1d91-8d429c110000 pid=4508 /usr/bin/chattr guuid=2bfcb0a7-1a00-0000-1d91-8d429b110000 pid=4507->guuid=fae2e8a7-1a00-0000-1d91-8d429c110000 pid=4508 execve guuid=7f74a4a8-1a00-0000-1d91-8d429e110000 pid=4510 /usr/bin/chattr guuid=253f57a8-1a00-0000-1d91-8d429d110000 pid=4509->guuid=7f74a4a8-1a00-0000-1d91-8d429e110000 pid=4510 execve guuid=0fd03fa9-1a00-0000-1d91-8d42a0110000 pid=4512 /usr/bin/mount guuid=60c9fda8-1a00-0000-1d91-8d429f110000 pid=4511->guuid=0fd03fa9-1a00-0000-1d91-8d42a0110000 pid=4512 execve guuid=6f38dfa9-1a00-0000-1d91-8d42a2110000 pid=4514 /usr/bin/chattr guuid=c898b3a9-1a00-0000-1d91-8d42a1110000 pid=4513->guuid=6f38dfa9-1a00-0000-1d91-8d42a2110000 pid=4514 execve guuid=3fb260aa-1a00-0000-1d91-8d42a4110000 pid=4516 /usr/bin/chattr guuid=4aa833aa-1a00-0000-1d91-8d42a3110000 pid=4515->guuid=3fb260aa-1a00-0000-1d91-8d42a4110000 pid=4516 execve guuid=eef3d5aa-1a00-0000-1d91-8d42a6110000 pid=4518 /usr/bin/mount guuid=9173abaa-1a00-0000-1d91-8d42a5110000 pid=4517->guuid=eef3d5aa-1a00-0000-1d91-8d42a6110000 pid=4518 execve guuid=e4d895ab-1a00-0000-1d91-8d42a8110000 pid=4520 /usr/bin/chattr guuid=b7e668ab-1a00-0000-1d91-8d42a7110000 pid=4519->guuid=e4d895ab-1a00-0000-1d91-8d42a8110000 pid=4520 execve guuid=1fd21cac-1a00-0000-1d91-8d42aa110000 pid=4522 /usr/bin/chattr guuid=0eb7ecab-1a00-0000-1d91-8d42a9110000 pid=4521->guuid=1fd21cac-1a00-0000-1d91-8d42aa110000 pid=4522 execve guuid=14b4c5ac-1a00-0000-1d91-8d42ac110000 pid=4524 /usr/bin/mount guuid=48b195ac-1a00-0000-1d91-8d42ab110000 pid=4523->guuid=14b4c5ac-1a00-0000-1d91-8d42ac110000 pid=4524 execve guuid=1a4b5ead-1a00-0000-1d91-8d42ae110000 pid=4526 /usr/bin/chattr guuid=94ad2dad-1a00-0000-1d91-8d42ad110000 pid=4525->guuid=1a4b5ead-1a00-0000-1d91-8d42ae110000 pid=4526 execve guuid=28bdfcad-1a00-0000-1d91-8d42b1110000 pid=4529 /usr/bin/rm delete-file guuid=d82bd4ad-1a00-0000-1d91-8d42b0110000 pid=4528->guuid=28bdfcad-1a00-0000-1d91-8d42b1110000 pid=4529 execve guuid=0b866dae-1a00-0000-1d91-8d42b3110000 pid=4531 /usr/sbin/xtables-nft-multi guuid=3f6e35ae-1a00-0000-1d91-8d42b2110000 pid=4530->guuid=0b866dae-1a00-0000-1d91-8d42b3110000 pid=4531 execve guuid=5b2aaaba-1a00-0000-1d91-8d42bb110000 pid=4539 /usr/sbin/xtables-nft-multi guuid=c32974ba-1a00-0000-1d91-8d42ba110000 pid=4538->guuid=5b2aaaba-1a00-0000-1d91-8d42bb110000 pid=4539 execve guuid=668f4fbb-1a00-0000-1d91-8d42bd110000 pid=4541 /usr/sbin/xtables-nft-multi net guuid=fbec1fbb-1a00-0000-1d91-8d42bc110000 pid=4540->guuid=668f4fbb-1a00-0000-1d91-8d42bd110000 pid=4541 execve a6d67785-33c2-5752-823a-f0f93898c6c0 ::1:69 guuid=668f4fbb-1a00-0000-1d91-8d42bd110000 pid=4541->a6d67785-33c2-5752-823a-f0f93898c6c0 con e0bf5d61-49c5-55e5-bd8d-1372a3652280 127.0.0.1:69 guuid=668f4fbb-1a00-0000-1d91-8d42bd110000 pid=4541->e0bf5d61-49c5-55e5-bd8d-1372a3652280 con guuid=af270fbc-1a00-0000-1d91-8d42bf110000 pid=4543 /usr/sbin/xtables-nft-multi guuid=0707ddbb-1a00-0000-1d91-8d42be110000 pid=4542->guuid=af270fbc-1a00-0000-1d91-8d42bf110000 pid=4543 execve guuid=c172adbc-1a00-0000-1d91-8d42c1110000 pid=4545 /usr/sbin/xtables-nft-multi guuid=115c7abc-1a00-0000-1d91-8d42c0110000 pid=4544->guuid=c172adbc-1a00-0000-1d91-8d42c1110000 pid=4545 execve guuid=477462f5-2000-0000-1d91-8d42d2110000 pid=4562 /usr/bin/chattr guuid=0f6637f5-2000-0000-1d91-8d42d1110000 pid=4561->guuid=477462f5-2000-0000-1d91-8d42d2110000 pid=4562 execve guuid=23bedaf5-2000-0000-1d91-8d42d4110000 pid=4564 /usr/bin/chmod guuid=2f13b0f5-2000-0000-1d91-8d42d3110000 pid=4563->guuid=23bedaf5-2000-0000-1d91-8d42d4110000 pid=4564 execve guuid=7aff7af6-2000-0000-1d91-8d42d7110000 pid=4567 /usr/bin/chattr guuid=cc1c50f6-2000-0000-1d91-8d42d6110000 pid=4566->guuid=7aff7af6-2000-0000-1d91-8d42d7110000 pid=4567 execve guuid=f519eff6-2000-0000-1d91-8d42d9110000 pid=4569 /usr/bin/chmod guuid=9d61c2f6-2000-0000-1d91-8d42d8110000 pid=4568->guuid=f519eff6-2000-0000-1d91-8d42d9110000 pid=4569 execve guuid=af5f93f7-2000-0000-1d91-8d42dc110000 pid=4572 /usr/bin/chattr guuid=c6fe62f7-2000-0000-1d91-8d42db110000 pid=4571->guuid=af5f93f7-2000-0000-1d91-8d42dc110000 pid=4572 execve guuid=5ac11df8-2000-0000-1d91-8d42de110000 pid=4574 /usr/bin/chmod guuid=a830f1f7-2000-0000-1d91-8d42dd110000 pid=4573->guuid=5ac11df8-2000-0000-1d91-8d42de110000 pid=4574 execve guuid=cc35c7f8-2000-0000-1d91-8d42e1110000 pid=4577 /usr/bin/chattr guuid=671696f8-2000-0000-1d91-8d42e0110000 pid=4576->guuid=cc35c7f8-2000-0000-1d91-8d42e1110000 pid=4577 execve guuid=c2ee3cf9-2000-0000-1d91-8d42e3110000 pid=4579 /usr/bin/chmod guuid=6d360ff9-2000-0000-1d91-8d42e2110000 pid=4578->guuid=c2ee3cf9-2000-0000-1d91-8d42e3110000 pid=4579 execve guuid=bd2eddf9-2000-0000-1d91-8d42e6110000 pid=4582 /usr/bin/chattr guuid=e7bcaef9-2000-0000-1d91-8d42e5110000 pid=4581->guuid=bd2eddf9-2000-0000-1d91-8d42e6110000 pid=4582 execve guuid=9d2250fa-2000-0000-1d91-8d42e8110000 pid=4584 /usr/bin/chmod guuid=42f721fa-2000-0000-1d91-8d42e7110000 pid=4583->guuid=9d2250fa-2000-0000-1d91-8d42e8110000 pid=4584 execve guuid=104bfbfa-2000-0000-1d91-8d42eb110000 pid=4587 /usr/bin/chattr guuid=7329c5fa-2000-0000-1d91-8d42ea110000 pid=4586->guuid=104bfbfa-2000-0000-1d91-8d42eb110000 pid=4587 execve guuid=0a5774fb-2000-0000-1d91-8d42ed110000 pid=4589 /usr/bin/chmod guuid=f37f45fb-2000-0000-1d91-8d42ec110000 pid=4588->guuid=0a5774fb-2000-0000-1d91-8d42ed110000 pid=4589 execve guuid=469f22fc-2000-0000-1d91-8d42f0110000 pid=4592 /usr/bin/chattr guuid=eb05f3fb-2000-0000-1d91-8d42ef110000 pid=4591->guuid=469f22fc-2000-0000-1d91-8d42f0110000 pid=4592 execve guuid=a2149efc-2000-0000-1d91-8d42f2110000 pid=4594 /usr/bin/chmod guuid=cc8d6afc-2000-0000-1d91-8d42f1110000 pid=4593->guuid=a2149efc-2000-0000-1d91-8d42f2110000 pid=4594 execve guuid=75ec3dfd-2000-0000-1d91-8d42f5110000 pid=4597 /usr/bin/chattr guuid=e7440dfd-2000-0000-1d91-8d42f4110000 pid=4596->guuid=75ec3dfd-2000-0000-1d91-8d42f5110000 pid=4597 execve guuid=8401b7fd-2000-0000-1d91-8d42f7110000 pid=4599 /usr/bin/chmod guuid=dbc689fd-2000-0000-1d91-8d42f6110000 pid=4598->guuid=8401b7fd-2000-0000-1d91-8d42f7110000 pid=4599 execve guuid=101755fe-2000-0000-1d91-8d42fa110000 pid=4602 /usr/bin/chattr guuid=bc692afe-2000-0000-1d91-8d42f9110000 pid=4601->guuid=101755fe-2000-0000-1d91-8d42fa110000 pid=4602 execve guuid=0ac6c8fe-2000-0000-1d91-8d42fc110000 pid=4604 /usr/bin/chmod guuid=96d09afe-2000-0000-1d91-8d42fb110000 pid=4603->guuid=0ac6c8fe-2000-0000-1d91-8d42fc110000 pid=4604 execve guuid=16b274ff-2000-0000-1d91-8d42ff110000 pid=4607 /usr/bin/chattr guuid=e36744ff-2000-0000-1d91-8d42fe110000 pid=4606->guuid=16b274ff-2000-0000-1d91-8d42ff110000 pid=4607 execve guuid=5256efff-2000-0000-1d91-8d4201120000 pid=4609 /usr/bin/chmod guuid=9f8bbeff-2000-0000-1d91-8d4200120000 pid=4608->guuid=5256efff-2000-0000-1d91-8d4201120000 pid=4609 execve guuid=e4fa5700-2100-0000-1d91-8d4203120000 pid=4611 /usr/bin/pgrep guuid=f1052e00-2100-0000-1d91-8d4202120000 pid=4610->guuid=e4fa5700-2100-0000-1d91-8d4203120000 pid=4611 execve guuid=7eb2b802-2100-0000-1d91-8d4205120000 pid=4613 /usr/bin/systemctl guuid=fe0d8802-2100-0000-1d91-8d4204120000 pid=4612->guuid=7eb2b802-2100-0000-1d91-8d4205120000 pid=4613 execve guuid=aabab003-2100-0000-1d91-8d4206120000 pid=4614 /usr/bin/systemctl guuid=fe0d8802-2100-0000-1d91-8d4204120000 pid=4612->guuid=aabab003-2100-0000-1d91-8d4206120000 pid=4614 execve guuid=29ca1345-2100-0000-1d91-8d4209120000 pid=4617 /usr/bin/systemctl guuid=7493c344-2100-0000-1d91-8d4208120000 pid=4616->guuid=29ca1345-2100-0000-1d91-8d4209120000 pid=4617 execve
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-04-09 04:52:38 UTC
File Type:
ELF32 Little (Exe)
AV detection:
15 of 36 (41.67%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:mirai credential_access defense_evasion discovery exection execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Modifies Bash startup script
Reads process memory
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
Modifies Watchdog functionality
Modifies hosts file
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies the dynamic linker configuration file
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ELF_IoT_Persistence_Hunt
Author:4r4
Description:Hunts for ELF files with persistence and download capabilities
Rule name:ELF_Mirai
Author:NDA0E
Description:Detects multiple Mirai variants
Rule name:ELF_Toriilike_persist
Author:4r4
Description:Detects Torii IoT Botnet (stealthier Mirai alternative)
Reference:Identified via researched data
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_88de437f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_8aa7b5d3
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_ae9d0fa6
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_b14f4c5d
Author:Elastic Security
Rule name:TH_Generic_MassHunt_Linux_Malware_2026_CYFARE
Author:CYFARE
Description:Generic Linux malware mass-hunt rule - 2026
Reference:https://cyfare.net/
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 2bbb387226de2faa8f60eaa2988e6a9a05c6d41b191ef0f24f029b184f260677

(this sample)

  
Delivery method
Distributed via web download

Comments