MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2c07c0af480731bc946ef69a0238c54f45586f7907c99b03ae84587908d78f1d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 2c07c0af480731bc946ef69a0238c54f45586f7907c99b03ae84587908d78f1d
SHA3-384 hash: 45ed85a236f5960710541ee79b2e7aaf70a8e883eec3749a55f8fbdda6486ad67937558823e091460f4831194fab6fcc
SHA1 hash: e0f052e46a832b90bab2a536c7401ec10ae71f06
MD5 hash: 96609a3b32b4ef8af06a0709d1003198
humanhash: massachusetts-chicken-high-fish
File name:dvr.sh
Download: download sample
Signature Mirai
File size:2'387 bytes
First seen:2025-09-24 17:29:23 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:Sc5YAuHk+U5kmQwzILEpzILKlPBetx4Th7Dn49PchAs6x4Th0:Sc5YDHkJkmQwzILEhILYpetx4Th7U9Pj
TLSH T16341D3CF7522062A554F9E0BB3F5A8E87033C4D720418B28EE8C3CA9F388E5A7144E25
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/arm1c6ad7da3701f41af453d1701d5656e256a6dcf08023270b2926685b82a19d07 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget
http://45.125.66.56/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraiddos DEU elf gafgyt geofenced mirai
http://45.125.66.56/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 MiraiDEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-24T15:43:00Z UTC
Last seen:
2025-09-24T15:43:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=ad650f2a-1800-0000-d5a8-c101660c0000 pid=3174 /usr/bin/sudo guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175 /tmp/sample.bin guuid=ad650f2a-1800-0000-d5a8-c101660c0000 pid=3174->guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175 execve guuid=2b3fa92c-1800-0000-d5a8-c101680c0000 pid=3176 /usr/bin/cp guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=2b3fa92c-1800-0000-d5a8-c101680c0000 pid=3176 execve guuid=b13e0134-1800-0000-d5a8-c101690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=b13e0134-1800-0000-d5a8-c101690c0000 pid=3177 execve guuid=37a11042-1800-0000-d5a8-c101740c0000 pid=3188 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=37a11042-1800-0000-d5a8-c101740c0000 pid=3188 execve guuid=2d1c4351-1800-0000-d5a8-c1018f0c0000 pid=3215 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=2d1c4351-1800-0000-d5a8-c1018f0c0000 pid=3215 clone guuid=35dc5e51-1800-0000-d5a8-c101900c0000 pid=3216 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=35dc5e51-1800-0000-d5a8-c101900c0000 pid=3216 execve guuid=d346c351-1800-0000-d5a8-c101910c0000 pid=3217 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=d346c351-1800-0000-d5a8-c101910c0000 pid=3217 clone guuid=5bd7bf53-1800-0000-d5a8-c101930c0000 pid=3219 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=5bd7bf53-1800-0000-d5a8-c101930c0000 pid=3219 execve guuid=10fc2354-1800-0000-d5a8-c101940c0000 pid=3220 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=10fc2354-1800-0000-d5a8-c101940c0000 pid=3220 execve guuid=e7b9525f-1800-0000-d5a8-c101950c0000 pid=3221 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=e7b9525f-1800-0000-d5a8-c101950c0000 pid=3221 execve guuid=5eb7866d-1800-0000-d5a8-c101a40c0000 pid=3236 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=5eb7866d-1800-0000-d5a8-c101a40c0000 pid=3236 clone guuid=4afec36d-1800-0000-d5a8-c101a50c0000 pid=3237 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=4afec36d-1800-0000-d5a8-c101a50c0000 pid=3237 execve guuid=89d39b6e-1800-0000-d5a8-c101a60c0000 pid=3238 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=89d39b6e-1800-0000-d5a8-c101a60c0000 pid=3238 clone guuid=7643ba6f-1800-0000-d5a8-c101a90c0000 pid=3241 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7643ba6f-1800-0000-d5a8-c101a90c0000 pid=3241 execve guuid=56b21270-1800-0000-d5a8-c101aa0c0000 pid=3242 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=56b21270-1800-0000-d5a8-c101aa0c0000 pid=3242 execve guuid=4f7d4c7b-1800-0000-d5a8-c101b80c0000 pid=3256 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=4f7d4c7b-1800-0000-d5a8-c101b80c0000 pid=3256 execve guuid=5d519989-1800-0000-d5a8-c101c80c0000 pid=3272 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=5d519989-1800-0000-d5a8-c101c80c0000 pid=3272 clone guuid=8eeae289-1800-0000-d5a8-c101c90c0000 pid=3273 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=8eeae289-1800-0000-d5a8-c101c90c0000 pid=3273 execve guuid=7ca69b8a-1800-0000-d5a8-c101ca0c0000 pid=3274 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7ca69b8a-1800-0000-d5a8-c101ca0c0000 pid=3274 clone guuid=d841468c-1800-0000-d5a8-c101d00c0000 pid=3280 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=d841468c-1800-0000-d5a8-c101d00c0000 pid=3280 execve guuid=abbca08c-1800-0000-d5a8-c101d20c0000 pid=3282 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=abbca08c-1800-0000-d5a8-c101d20c0000 pid=3282 execve guuid=4db43896-1800-0000-d5a8-c101ea0c0000 pid=3306 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=4db43896-1800-0000-d5a8-c101ea0c0000 pid=3306 execve guuid=a00706a3-1800-0000-d5a8-c101060d0000 pid=3334 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=a00706a3-1800-0000-d5a8-c101060d0000 pid=3334 clone guuid=e9f52fa3-1800-0000-d5a8-c101080d0000 pid=3336 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=e9f52fa3-1800-0000-d5a8-c101080d0000 pid=3336 execve guuid=769193a3-1800-0000-d5a8-c1010a0d0000 pid=3338 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=769193a3-1800-0000-d5a8-c1010a0d0000 pid=3338 clone guuid=01a9baa4-1800-0000-d5a8-c1010f0d0000 pid=3343 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=01a9baa4-1800-0000-d5a8-c1010f0d0000 pid=3343 execve guuid=c46f86a8-1800-0000-d5a8-c101140d0000 pid=3348 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=c46f86a8-1800-0000-d5a8-c101140d0000 pid=3348 execve guuid=86276ab2-1800-0000-d5a8-c1011e0d0000 pid=3358 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=86276ab2-1800-0000-d5a8-c1011e0d0000 pid=3358 execve guuid=25a8a6bd-1800-0000-d5a8-c101380d0000 pid=3384 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=25a8a6bd-1800-0000-d5a8-c101380d0000 pid=3384 clone guuid=e6aae7bd-1800-0000-d5a8-c1013a0d0000 pid=3386 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=e6aae7bd-1800-0000-d5a8-c1013a0d0000 pid=3386 execve guuid=aa2636be-1800-0000-d5a8-c1013c0d0000 pid=3388 /tmp/i486 guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=aa2636be-1800-0000-d5a8-c1013c0d0000 pid=3388 execve guuid=d29242c0-1800-0000-d5a8-c101470d0000 pid=3399 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=d29242c0-1800-0000-d5a8-c101470d0000 pid=3399 execve guuid=7c6492c0-1800-0000-d5a8-c101480d0000 pid=3400 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7c6492c0-1800-0000-d5a8-c101480d0000 pid=3400 execve guuid=57df97c9-1800-0000-d5a8-c101600d0000 pid=3424 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=57df97c9-1800-0000-d5a8-c101600d0000 pid=3424 execve guuid=e5ae1ed4-1800-0000-d5a8-c1017e0d0000 pid=3454 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=e5ae1ed4-1800-0000-d5a8-c1017e0d0000 pid=3454 clone guuid=b21943d4-1800-0000-d5a8-c101800d0000 pid=3456 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=b21943d4-1800-0000-d5a8-c101800d0000 pid=3456 execve guuid=172b86d4-1800-0000-d5a8-c101810d0000 pid=3457 /tmp/i686 guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=172b86d4-1800-0000-d5a8-c101810d0000 pid=3457 execve guuid=155327e2-1800-0000-d5a8-c101b60d0000 pid=3510 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=155327e2-1800-0000-d5a8-c101b60d0000 pid=3510 execve guuid=353388e2-1800-0000-d5a8-c101b90d0000 pid=3513 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=353388e2-1800-0000-d5a8-c101b90d0000 pid=3513 execve guuid=f8b3eced-1800-0000-d5a8-c101d40d0000 pid=3540 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=f8b3eced-1800-0000-d5a8-c101d40d0000 pid=3540 execve guuid=3a7745fb-1800-0000-d5a8-c101e90d0000 pid=3561 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=3a7745fb-1800-0000-d5a8-c101e90d0000 pid=3561 clone guuid=ed497afb-1800-0000-d5a8-c101ea0d0000 pid=3562 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=ed497afb-1800-0000-d5a8-c101ea0d0000 pid=3562 execve guuid=2dd314fc-1800-0000-d5a8-c101eb0d0000 pid=3563 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=2dd314fc-1800-0000-d5a8-c101eb0d0000 pid=3563 clone guuid=578e62fc-1800-0000-d5a8-c101ee0d0000 pid=3566 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=578e62fc-1800-0000-d5a8-c101ee0d0000 pid=3566 execve guuid=0a275808-1900-0000-d5a8-c101ef0d0000 pid=3567 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=0a275808-1900-0000-d5a8-c101ef0d0000 pid=3567 execve guuid=537f6e16-1900-0000-d5a8-c101040e0000 pid=3588 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=537f6e16-1900-0000-d5a8-c101040e0000 pid=3588 execve guuid=40600427-1900-0000-d5a8-c1012a0e0000 pid=3626 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=40600427-1900-0000-d5a8-c1012a0e0000 pid=3626 clone guuid=95735d27-1900-0000-d5a8-c1012c0e0000 pid=3628 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=95735d27-1900-0000-d5a8-c1012c0e0000 pid=3628 execve guuid=6863dc27-1900-0000-d5a8-c1012e0e0000 pid=3630 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=6863dc27-1900-0000-d5a8-c1012e0e0000 pid=3630 clone guuid=39aa3828-1900-0000-d5a8-c101310e0000 pid=3633 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=39aa3828-1900-0000-d5a8-c101310e0000 pid=3633 execve guuid=344bbf28-1900-0000-d5a8-c101330e0000 pid=3635 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=344bbf28-1900-0000-d5a8-c101330e0000 pid=3635 execve guuid=4a475936-1900-0000-d5a8-c1014e0e0000 pid=3662 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=4a475936-1900-0000-d5a8-c1014e0e0000 pid=3662 execve guuid=fc277f44-1900-0000-d5a8-c1016e0e0000 pid=3694 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=fc277f44-1900-0000-d5a8-c1016e0e0000 pid=3694 clone guuid=8ec19844-1900-0000-d5a8-c101700e0000 pid=3696 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=8ec19844-1900-0000-d5a8-c101700e0000 pid=3696 execve guuid=ac951c45-1900-0000-d5a8-c101740e0000 pid=3700 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=ac951c45-1900-0000-d5a8-c101740e0000 pid=3700 clone guuid=6c725545-1900-0000-d5a8-c101770e0000 pid=3703 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=6c725545-1900-0000-d5a8-c101770e0000 pid=3703 execve guuid=90250d49-1900-0000-d5a8-c101830e0000 pid=3715 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=90250d49-1900-0000-d5a8-c101830e0000 pid=3715 execve guuid=ec211854-1900-0000-d5a8-c101b90e0000 pid=3769 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=ec211854-1900-0000-d5a8-c101b90e0000 pid=3769 execve guuid=64ed5d60-1900-0000-d5a8-c101e40e0000 pid=3812 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=64ed5d60-1900-0000-d5a8-c101e40e0000 pid=3812 clone guuid=171c8c60-1900-0000-d5a8-c101e60e0000 pid=3814 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=171c8c60-1900-0000-d5a8-c101e60e0000 pid=3814 execve guuid=32a4d460-1900-0000-d5a8-c101e80e0000 pid=3816 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=32a4d460-1900-0000-d5a8-c101e80e0000 pid=3816 clone guuid=94e11361-1900-0000-d5a8-c101ec0e0000 pid=3820 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=94e11361-1900-0000-d5a8-c101ec0e0000 pid=3820 execve guuid=60c67a61-1900-0000-d5a8-c101ee0e0000 pid=3822 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=60c67a61-1900-0000-d5a8-c101ee0e0000 pid=3822 execve guuid=39dd436c-1900-0000-d5a8-c101170f0000 pid=3863 /usr/bin/curl send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=39dd436c-1900-0000-d5a8-c101170f0000 pid=3863 execve guuid=39061d78-1900-0000-d5a8-c101430f0000 pid=3907 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=39061d78-1900-0000-d5a8-c101430f0000 pid=3907 clone guuid=2cc33978-1900-0000-d5a8-c101440f0000 pid=3908 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=2cc33978-1900-0000-d5a8-c101440f0000 pid=3908 execve guuid=cbbe9478-1900-0000-d5a8-c101470f0000 pid=3911 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=cbbe9478-1900-0000-d5a8-c101470f0000 pid=3911 clone guuid=9884ec78-1900-0000-d5a8-c1014b0f0000 pid=3915 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=9884ec78-1900-0000-d5a8-c1014b0f0000 pid=3915 execve guuid=a5a4267a-1900-0000-d5a8-c101510f0000 pid=3921 /usr/bin/wget send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=a5a4267a-1900-0000-d5a8-c101510f0000 pid=3921 execve guuid=7ed72085-1900-0000-d5a8-c101730f0000 pid=3955 /usr/bin/curl send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7ed72085-1900-0000-d5a8-c101730f0000 pid=3955 execve guuid=47057a91-1900-0000-d5a8-c101910f0000 pid=3985 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=47057a91-1900-0000-d5a8-c101910f0000 pid=3985 clone guuid=aa53a191-1900-0000-d5a8-c101920f0000 pid=3986 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=aa53a191-1900-0000-d5a8-c101920f0000 pid=3986 execve guuid=ee7af291-1900-0000-d5a8-c101930f0000 pid=3987 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=ee7af291-1900-0000-d5a8-c101930f0000 pid=3987 clone guuid=d95d3a92-1900-0000-d5a8-c101970f0000 pid=3991 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=d95d3a92-1900-0000-d5a8-c101970f0000 pid=3991 execve guuid=31bf8e92-1900-0000-d5a8-c101990f0000 pid=3993 /usr/bin/wget send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=31bf8e92-1900-0000-d5a8-c101990f0000 pid=3993 execve guuid=7c3cdc9b-1900-0000-d5a8-c101b40f0000 pid=4020 /usr/bin/curl send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7c3cdc9b-1900-0000-d5a8-c101b40f0000 pid=4020 execve guuid=9f126abd-1900-0000-d5a8-c101fb0f0000 pid=4091 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=9f126abd-1900-0000-d5a8-c101fb0f0000 pid=4091 clone guuid=6a5c80bd-1900-0000-d5a8-c101fd0f0000 pid=4093 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=6a5c80bd-1900-0000-d5a8-c101fd0f0000 pid=4093 execve guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094 /tmp/x86 guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094 execve guuid=501a44cb-1900-0000-d5a8-c1011b100000 pid=4123 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=501a44cb-1900-0000-d5a8-c1011b100000 pid=4123 execve guuid=af6082cb-1900-0000-d5a8-c1011e100000 pid=4126 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=af6082cb-1900-0000-d5a8-c1011e100000 pid=4126 execve guuid=8c2455d6-1900-0000-d5a8-c10140100000 pid=4160 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=8c2455d6-1900-0000-d5a8-c10140100000 pid=4160 execve guuid=604fa6e2-1900-0000-d5a8-c1017f100000 pid=4223 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=604fa6e2-1900-0000-d5a8-c1017f100000 pid=4223 clone guuid=7135bae2-1900-0000-d5a8-c10181100000 pid=4225 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=7135bae2-1900-0000-d5a8-c10181100000 pid=4225 execve guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226 /tmp/x86_64 guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226 execve guuid=436489e4-1900-0000-d5a8-c10189100000 pid=4233 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=436489e4-1900-0000-d5a8-c10189100000 pid=4233 execve guuid=18aacce4-1900-0000-d5a8-c1018a100000 pid=4234 /usr/bin/wget net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=18aacce4-1900-0000-d5a8-c1018a100000 pid=4234 execve guuid=4edaa9ef-1900-0000-d5a8-c1018f100000 pid=4239 /usr/bin/curl net send-data write-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=4edaa9ef-1900-0000-d5a8-c1018f100000 pid=4239 execve guuid=d26556fb-1900-0000-d5a8-c10198100000 pid=4248 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=d26556fb-1900-0000-d5a8-c10198100000 pid=4248 clone guuid=e7c86dfb-1900-0000-d5a8-c10199100000 pid=4249 /usr/bin/chmod guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=e7c86dfb-1900-0000-d5a8-c10199100000 pid=4249 execve guuid=ea9caefb-1900-0000-d5a8-c1019a100000 pid=4250 /usr/bin/bash guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=ea9caefb-1900-0000-d5a8-c1019a100000 pid=4250 clone guuid=3da4d9fb-1900-0000-d5a8-c1019d100000 pid=4253 /usr/bin/rm delete-file guuid=6daa132c-1800-0000-d5a8-c101670c0000 pid=3175->guuid=3da4d9fb-1900-0000-d5a8-c1019d100000 pid=4253 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=b13e0134-1800-0000-d5a8-c101690c0000 pid=3177->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=37a11042-1800-0000-d5a8-c101740c0000 pid=3188->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=10fc2354-1800-0000-d5a8-c101940c0000 pid=3220->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=e7b9525f-1800-0000-d5a8-c101950c0000 pid=3221->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=56b21270-1800-0000-d5a8-c101aa0c0000 pid=3242->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=4f7d4c7b-1800-0000-d5a8-c101b80c0000 pid=3256->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=abbca08c-1800-0000-d5a8-c101d20c0000 pid=3282->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=4db43896-1800-0000-d5a8-c101ea0c0000 pid=3306->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=c46f86a8-1800-0000-d5a8-c101140d0000 pid=3348->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=86276ab2-1800-0000-d5a8-c1011e0d0000 pid=3358->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=751215bf-1800-0000-d5a8-c101400d0000 pid=3392 /tmp/i486 net zombie guuid=aa2636be-1800-0000-d5a8-c1013c0d0000 pid=3388->guuid=751215bf-1800-0000-d5a8-c101400d0000 pid=3392 clone guuid=d09822bf-1800-0000-d5a8-c101410d0000 pid=3393 /tmp/i486 net zombie guuid=aa2636be-1800-0000-d5a8-c1013c0d0000 pid=3388->guuid=d09822bf-1800-0000-d5a8-c101410d0000 pid=3393 clone guuid=6b802dc0-1800-0000-d5a8-c101450d0000 pid=3397 /tmp/i486 guuid=aa2636be-1800-0000-d5a8-c1013c0d0000 pid=3388->guuid=6b802dc0-1800-0000-d5a8-c101450d0000 pid=3397 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=751215bf-1800-0000-d5a8-c101400d0000 pid=3392->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=d09822bf-1800-0000-d5a8-c101410d0000 pid=3393->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=c05b36c0-1800-0000-d5a8-c101460d0000 pid=3398 /tmp/i486 net zombie guuid=6b802dc0-1800-0000-d5a8-c101450d0000 pid=3397->guuid=c05b36c0-1800-0000-d5a8-c101460d0000 pid=3398 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c05b36c0-1800-0000-d5a8-c101460d0000 pid=3398->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con d41ff612-c494-5ad2-835e-cba99e77da4d 194.113.37.21:1025 guuid=c05b36c0-1800-0000-d5a8-c101460d0000 pid=3398->d41ff612-c494-5ad2-835e-cba99e77da4d con guuid=d83adec0-1800-0000-d5a8-c101490d0000 pid=3401 /tmp/i486 guuid=c05b36c0-1800-0000-d5a8-c101460d0000 pid=3398->guuid=d83adec0-1800-0000-d5a8-c101490d0000 pid=3401 clone guuid=7c6492c0-1800-0000-d5a8-c101480d0000 pid=3400->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=57df97c9-1800-0000-d5a8-c101600d0000 pid=3424->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=c99f48db-1800-0000-d5a8-c1019a0d0000 pid=3482 /tmp/i686 net zombie guuid=172b86d4-1800-0000-d5a8-c101810d0000 pid=3457->guuid=c99f48db-1800-0000-d5a8-c1019a0d0000 pid=3482 clone guuid=4d164edb-1800-0000-d5a8-c1019b0d0000 pid=3483 /tmp/i686 net zombie guuid=172b86d4-1800-0000-d5a8-c101810d0000 pid=3457->guuid=4d164edb-1800-0000-d5a8-c1019b0d0000 pid=3483 clone guuid=f2b408e2-1800-0000-d5a8-c101b40d0000 pid=3508 /tmp/i686 guuid=172b86d4-1800-0000-d5a8-c101810d0000 pid=3457->guuid=f2b408e2-1800-0000-d5a8-c101b40d0000 pid=3508 clone guuid=c99f48db-1800-0000-d5a8-c1019a0d0000 pid=3482->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=4d164edb-1800-0000-d5a8-c1019b0d0000 pid=3483->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509 /tmp/i686 net send-data write-file zombie guuid=f2b408e2-1800-0000-d5a8-c101b40d0000 pid=3508->guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509 clone guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ec24d88-10a2-533e-9815-5add425c4ddb 109.248.162.59:1025 guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509->8ec24d88-10a2-533e-9815-5add425c4ddb send: 18B 97202e5a-0145-5b2c-b892-9514ea1b5595 217.60.248.121:1025 guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509->97202e5a-0145-5b2c-b892-9514ea1b5595 send: 18B guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533 /tmp/i686 zombie guuid=a6351ce2-1800-0000-d5a8-c101b50d0000 pid=3509->guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533 clone guuid=353388e2-1800-0000-d5a8-c101b90d0000 pid=3513->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=b56635fc-1800-0000-d5a8-c101ed0d0000 pid=3565 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=b56635fc-1800-0000-d5a8-c101ed0d0000 pid=3565 clone guuid=af870428-1900-0000-d5a8-c101300e0000 pid=3632 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=af870428-1900-0000-d5a8-c101300e0000 pid=3632 clone guuid=4fce4b40-1900-0000-d5a8-c101640e0000 pid=3684 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=4fce4b40-1900-0000-d5a8-c101640e0000 pid=3684 clone guuid=a290bf44-1900-0000-d5a8-c101720e0000 pid=3698 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=a290bf44-1900-0000-d5a8-c101720e0000 pid=3698 clone guuid=a7843145-1900-0000-d5a8-c101760e0000 pid=3702 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=a7843145-1900-0000-d5a8-c101760e0000 pid=3702 clone guuid=6bd3c957-1900-0000-d5a8-c101c60e0000 pid=3782 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=6bd3c957-1900-0000-d5a8-c101c60e0000 pid=3782 clone guuid=dcae655b-1900-0000-d5a8-c101d30e0000 pid=3795 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=dcae655b-1900-0000-d5a8-c101d30e0000 pid=3795 clone guuid=1746e65e-1900-0000-d5a8-c101df0e0000 pid=3807 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=1746e65e-1900-0000-d5a8-c101df0e0000 pid=3807 clone guuid=7f8af160-1900-0000-d5a8-c101ea0e0000 pid=3818 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=7f8af160-1900-0000-d5a8-c101ea0e0000 pid=3818 clone guuid=dcf01963-1900-0000-d5a8-c101f50e0000 pid=3829 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=dcf01963-1900-0000-d5a8-c101f50e0000 pid=3829 clone guuid=91ab2f66-1900-0000-d5a8-c101020f0000 pid=3842 /tmp/i686 net zombie guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=91ab2f66-1900-0000-d5a8-c101020f0000 pid=3842 clone guuid=850c2069-1900-0000-d5a8-c1010d0f0000 pid=3853 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=850c2069-1900-0000-d5a8-c1010d0f0000 pid=3853 clone guuid=c337b96c-1900-0000-d5a8-c1011a0f0000 pid=3866 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=c337b96c-1900-0000-d5a8-c1011a0f0000 pid=3866 clone guuid=eece7870-1900-0000-d5a8-c101270f0000 pid=3879 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=eece7870-1900-0000-d5a8-c101270f0000 pid=3879 clone guuid=54f55a73-1900-0000-d5a8-c101320f0000 pid=3890 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=54f55a73-1900-0000-d5a8-c101320f0000 pid=3890 clone guuid=9eb94f76-1900-0000-d5a8-c1013d0f0000 pid=3901 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=9eb94f76-1900-0000-d5a8-c1013d0f0000 pid=3901 clone guuid=2f82bd78-1900-0000-d5a8-c1014a0f0000 pid=3914 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=2f82bd78-1900-0000-d5a8-c1014a0f0000 pid=3914 clone guuid=f38d8079-1900-0000-d5a8-c1014e0f0000 pid=3918 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=f38d8079-1900-0000-d5a8-c1014e0f0000 pid=3918 clone guuid=f1e9ad7c-1900-0000-d5a8-c1015a0f0000 pid=3930 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=f1e9ad7c-1900-0000-d5a8-c1015a0f0000 pid=3930 clone guuid=09fc6f8e-1900-0000-d5a8-c101890f0000 pid=3977 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=09fc6f8e-1900-0000-d5a8-c101890f0000 pid=3977 clone guuid=f49a1092-1900-0000-d5a8-c101960f0000 pid=3990 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=f49a1092-1900-0000-d5a8-c101960f0000 pid=3990 clone guuid=61b46b9a-1900-0000-d5a8-c101ae0f0000 pid=4014 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=61b46b9a-1900-0000-d5a8-c101ae0f0000 pid=4014 clone guuid=c548399d-1900-0000-d5a8-c101bb0f0000 pid=4027 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=c548399d-1900-0000-d5a8-c101bb0f0000 pid=4027 clone guuid=165059a0-1900-0000-d5a8-c101c70f0000 pid=4039 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=165059a0-1900-0000-d5a8-c101c70f0000 pid=4039 clone guuid=fcaba9a4-1900-0000-d5a8-c101d50f0000 pid=4053 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=fcaba9a4-1900-0000-d5a8-c101d50f0000 pid=4053 clone guuid=b68c23a5-1900-0000-d5a8-c101d70f0000 pid=4055 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=b68c23a5-1900-0000-d5a8-c101d70f0000 pid=4055 clone guuid=38e6bfaf-1900-0000-d5a8-c101e90f0000 pid=4073 /tmp/i686 guuid=2b7f31e9-1800-0000-d5a8-c101cd0d0000 pid=3533->guuid=38e6bfaf-1900-0000-d5a8-c101e90f0000 pid=4073 clone guuid=f8b3eced-1800-0000-d5a8-c101d40d0000 pid=3540->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=b56635fc-1800-0000-d5a8-c101ed0d0000 pid=3565->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=0a275808-1900-0000-d5a8-c101ef0d0000 pid=3567->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=537f6e16-1900-0000-d5a8-c101040e0000 pid=3588->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=af870428-1900-0000-d5a8-c101300e0000 pid=3632->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=344bbf28-1900-0000-d5a8-c101330e0000 pid=3635->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=4a475936-1900-0000-d5a8-c1014e0e0000 pid=3662->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=4fce4b40-1900-0000-d5a8-c101640e0000 pid=3684->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=a290bf44-1900-0000-d5a8-c101720e0000 pid=3698->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=a7843145-1900-0000-d5a8-c101760e0000 pid=3702->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=90250d49-1900-0000-d5a8-c101830e0000 pid=3715->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=ec211854-1900-0000-d5a8-c101b90e0000 pid=3769->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=6bd3c957-1900-0000-d5a8-c101c60e0000 pid=3782->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=dcae655b-1900-0000-d5a8-c101d30e0000 pid=3795->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=1746e65e-1900-0000-d5a8-c101df0e0000 pid=3807->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=7f8af160-1900-0000-d5a8-c101ea0e0000 pid=3818->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=60c67a61-1900-0000-d5a8-c101ee0e0000 pid=3822->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=91ab2f66-1900-0000-d5a8-c101020f0000 pid=3842->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=39dd436c-1900-0000-d5a8-c101170f0000 pid=3863->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=a5a4267a-1900-0000-d5a8-c101510f0000 pid=3921->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=7ed72085-1900-0000-d5a8-c101730f0000 pid=3955->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=31bf8e92-1900-0000-d5a8-c101990f0000 pid=3993->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=7c3cdc9b-1900-0000-d5a8-c101b40f0000 pid=4020->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=7ff542c4-1900-0000-d5a8-c10108100000 pid=4104 /tmp/x86 guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094->guuid=7ff542c4-1900-0000-d5a8-c10108100000 pid=4104 clone guuid=615e49c4-1900-0000-d5a8-c10109100000 pid=4105 /tmp/x86 guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094->guuid=615e49c4-1900-0000-d5a8-c10109100000 pid=4105 clone guuid=dd3491c5-1900-0000-d5a8-c1010c100000 pid=4108 /tmp/x86 net zombie guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094->guuid=dd3491c5-1900-0000-d5a8-c1010c100000 pid=4108 clone guuid=d37636cb-1900-0000-d5a8-c1011a100000 pid=4122 /tmp/x86 guuid=7f51d1bd-1900-0000-d5a8-c101fe0f0000 pid=4094->guuid=d37636cb-1900-0000-d5a8-c1011a100000 pid=4122 clone guuid=dd3491c5-1900-0000-d5a8-c1010c100000 pid=4108->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=45445acb-1900-0000-d5a8-c1011c100000 pid=4124 /tmp/x86 net send-data write-file zombie guuid=d37636cb-1900-0000-d5a8-c1011a100000 pid=4122->guuid=45445acb-1900-0000-d5a8-c1011c100000 pid=4124 clone guuid=45445acb-1900-0000-d5a8-c1011c100000 pid=4124->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con ef45816d-a8af-52a5-bd2c-76d22ae1894f 94.183.184.60:1025 guuid=45445acb-1900-0000-d5a8-c1011c100000 pid=4124->ef45816d-a8af-52a5-bd2c-76d22ae1894f send: 17B guuid=0dc59fd2-1900-0000-d5a8-c10133100000 pid=4147 /tmp/x86 guuid=45445acb-1900-0000-d5a8-c1011c100000 pid=4124->guuid=0dc59fd2-1900-0000-d5a8-c10133100000 pid=4147 clone guuid=af6082cb-1900-0000-d5a8-c1011e100000 pid=4126->28318de2-8d63-5b31-be23-c532c58983b9 send: 133B guuid=8c2455d6-1900-0000-d5a8-c10140100000 pid=4160->28318de2-8d63-5b31-be23-c532c58983b9 send: 82B guuid=1f0381e3-1900-0000-d5a8-c10183100000 pid=4227 /tmp/x86_64 net zombie guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226->guuid=1f0381e3-1900-0000-d5a8-c10183100000 pid=4227 clone guuid=b6c08ee3-1900-0000-d5a8-c10184100000 pid=4228 /tmp/x86_64 net zombie guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226->guuid=b6c08ee3-1900-0000-d5a8-c10184100000 pid=4228 clone guuid=7709a2e3-1900-0000-d5a8-c10185100000 pid=4229 /tmp/x86_64 net zombie guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226->guuid=7709a2e3-1900-0000-d5a8-c10185100000 pid=4229 clone guuid=a297a5e3-1900-0000-d5a8-c10186100000 pid=4230 /tmp/x86_64 net zombie guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226->guuid=a297a5e3-1900-0000-d5a8-c10186100000 pid=4230 clone guuid=73977be4-1900-0000-d5a8-c10187100000 pid=4231 /tmp/x86_64 zombie guuid=5435fce2-1900-0000-d5a8-c10182100000 pid=4226->guuid=73977be4-1900-0000-d5a8-c10187100000 pid=4231 clone guuid=1f0381e3-1900-0000-d5a8-c10183100000 pid=4227->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=b6c08ee3-1900-0000-d5a8-c10184100000 pid=4228->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=7709a2e3-1900-0000-d5a8-c10185100000 pid=4229->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=a297a5e3-1900-0000-d5a8-c10186100000 pid=4230->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=62ff82e4-1900-0000-d5a8-c10188100000 pid=4232 /tmp/x86_64 net send-data zombie guuid=73977be4-1900-0000-d5a8-c10187100000 pid=4231->guuid=62ff82e4-1900-0000-d5a8-c10188100000 pid=4232 clone guuid=62ff82e4-1900-0000-d5a8-c10188100000 pid=4232->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=62ff82e4-1900-0000-d5a8-c10188100000 pid=4232->d41ff612-c494-5ad2-835e-cba99e77da4d send: 24B guuid=0d2040e5-1900-0000-d5a8-c1018b100000 pid=4235 /tmp/x86_64 guuid=62ff82e4-1900-0000-d5a8-c10188100000 pid=4232->guuid=0d2040e5-1900-0000-d5a8-c1018b100000 pid=4235 clone guuid=18aacce4-1900-0000-d5a8-c1018a100000 pid=4234->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=1490c2fb-1900-0000-d5a8-c1019c100000 pid=4252 /tmp/x86_64 guuid=0d2040e5-1900-0000-d5a8-c1018b100000 pid=4235->guuid=1490c2fb-1900-0000-d5a8-c1019c100000 pid=4252 clone guuid=4edaa9ef-1900-0000-d5a8-c1018f100000 pid=4239->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-24 17:11:17 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2c07c0af480731bc946ef69a0238c54f45586f7907c99b03ae84587908d78f1d

(this sample)

  
Delivery method
Distributed via web download

Comments