MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2e7b8b20114f302ee6f4c8b77a6a0dc7bd786c026f89f956d92dffa923c6450d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 2e7b8b20114f302ee6f4c8b77a6a0dc7bd786c026f89f956d92dffa923c6450d
SHA3-384 hash: 753ff56f849523448918d747cd0dd9d0a62472a50978bcdd6c14eb7f08920e6b35cc52a5f79a99e1bedd5d870c2a98ac
SHA1 hash: aeb8fa0f9cdf57b839b8f0fb592c56be3f0271ac
MD5 hash: b918f7f9c55b534b5f2c4da65a259fb4
humanhash: sad-quiet-twelve-avocado
File name:jaws.sh
Download: download sample
Signature Mirai
File size:2'402 bytes
First seen:2025-09-12 07:52:45 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ScQtYArHk+L5km3wiISEpyIKKlPIe4x4TQDn49azcTsAX6x4T/:ScAY4Hkokm3wiISEgIKYwe4x4TQU9KcL
TLSH T19741D4CF7522562A598F9E0BB3F594E87033C5D720518B39EECC78A9F38CD5A7044A25
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.125.66.56/arm1c6ad7da3701f41af453d1701d5656e256a6dcf08023270b2926685b82a19d07 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Mirai404 censys DEU elf geofenced mirai ua-wget
http://45.125.66.56/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraiddos DEU elf geofenced mirai
http://45.125.66.56/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraiddos DEU elf geofenced mirai
http://45.125.66.56/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c MiraiDEU elf geofenced mirai ua-wget
http://45.125.66.56/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraiddos DEU elf gafgyt geofenced mirai
http://45.125.66.56/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 MiraiDEU elf geofenced mirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
32
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-09-12T06:14:00Z UTC
Last seen:
2025-09-12T06:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=1b46a2cb-1600-0000-071b-cbbe9d0c0000 pid=3229 /usr/bin/sudo guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231 /tmp/sample.bin guuid=1b46a2cb-1600-0000-071b-cbbe9d0c0000 pid=3229->guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231 execve guuid=d0eedbcd-1600-0000-071b-cbbea10c0000 pid=3233 /usr/bin/cp guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=d0eedbcd-1600-0000-071b-cbbea10c0000 pid=3233 execve guuid=0756d6d1-1600-0000-071b-cbbea80c0000 pid=3240 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0756d6d1-1600-0000-071b-cbbea80c0000 pid=3240 execve guuid=7b728fde-1600-0000-071b-cbbebb0c0000 pid=3259 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=7b728fde-1600-0000-071b-cbbebb0c0000 pid=3259 execve guuid=2d1968ee-1600-0000-071b-cbbedf0c0000 pid=3295 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=2d1968ee-1600-0000-071b-cbbedf0c0000 pid=3295 clone guuid=4e938dee-1600-0000-071b-cbbee00c0000 pid=3296 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=4e938dee-1600-0000-071b-cbbee00c0000 pid=3296 execve guuid=c27bfcee-1600-0000-071b-cbbee20c0000 pid=3298 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=c27bfcee-1600-0000-071b-cbbee20c0000 pid=3298 clone guuid=850ee0ef-1600-0000-071b-cbbee70c0000 pid=3303 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=850ee0ef-1600-0000-071b-cbbee70c0000 pid=3303 execve guuid=3a304ff0-1600-0000-071b-cbbee90c0000 pid=3305 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3a304ff0-1600-0000-071b-cbbee90c0000 pid=3305 execve guuid=a22bacfb-1600-0000-071b-cbbefd0c0000 pid=3325 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=a22bacfb-1600-0000-071b-cbbefd0c0000 pid=3325 execve guuid=8be7240a-1700-0000-071b-cbbe100d0000 pid=3344 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=8be7240a-1700-0000-071b-cbbe100d0000 pid=3344 clone guuid=82cb420a-1700-0000-071b-cbbe110d0000 pid=3345 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=82cb420a-1700-0000-071b-cbbe110d0000 pid=3345 execve guuid=966bb60a-1700-0000-071b-cbbe130d0000 pid=3347 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=966bb60a-1700-0000-071b-cbbe130d0000 pid=3347 clone guuid=6984770b-1700-0000-071b-cbbe160d0000 pid=3350 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=6984770b-1700-0000-071b-cbbe160d0000 pid=3350 execve guuid=380cd50b-1700-0000-071b-cbbe190d0000 pid=3353 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=380cd50b-1700-0000-071b-cbbe190d0000 pid=3353 execve guuid=d59e2617-1700-0000-071b-cbbe320d0000 pid=3378 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=d59e2617-1700-0000-071b-cbbe320d0000 pid=3378 execve guuid=a1badb25-1700-0000-071b-cbbe5a0d0000 pid=3418 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=a1badb25-1700-0000-071b-cbbe5a0d0000 pid=3418 clone guuid=271b0326-1700-0000-071b-cbbe5b0d0000 pid=3419 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=271b0326-1700-0000-071b-cbbe5b0d0000 pid=3419 execve guuid=364e7d26-1700-0000-071b-cbbe5d0d0000 pid=3421 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=364e7d26-1700-0000-071b-cbbe5d0d0000 pid=3421 clone guuid=083a8a27-1700-0000-071b-cbbe610d0000 pid=3425 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=083a8a27-1700-0000-071b-cbbe610d0000 pid=3425 execve guuid=c6f4252a-1700-0000-071b-cbbe680d0000 pid=3432 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=c6f4252a-1700-0000-071b-cbbe680d0000 pid=3432 execve guuid=44269233-1700-0000-071b-cbbe7e0d0000 pid=3454 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=44269233-1700-0000-071b-cbbe7e0d0000 pid=3454 execve guuid=46ed463e-1700-0000-071b-cbbe960d0000 pid=3478 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=46ed463e-1700-0000-071b-cbbe960d0000 pid=3478 clone guuid=9fb96b3e-1700-0000-071b-cbbe980d0000 pid=3480 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=9fb96b3e-1700-0000-071b-cbbe980d0000 pid=3480 execve guuid=a23ce63e-1700-0000-071b-cbbe9a0d0000 pid=3482 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=a23ce63e-1700-0000-071b-cbbe9a0d0000 pid=3482 clone guuid=20c7d13f-1700-0000-071b-cbbe9e0d0000 pid=3486 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=20c7d13f-1700-0000-071b-cbbe9e0d0000 pid=3486 execve guuid=4258b640-1700-0000-071b-cbbea10d0000 pid=3489 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=4258b640-1700-0000-071b-cbbea10d0000 pid=3489 execve guuid=0286754e-1700-0000-071b-cbbeb50d0000 pid=3509 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0286754e-1700-0000-071b-cbbeb50d0000 pid=3509 execve guuid=5e0ecb58-1700-0000-071b-cbbec60d0000 pid=3526 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=5e0ecb58-1700-0000-071b-cbbec60d0000 pid=3526 clone guuid=4a25f458-1700-0000-071b-cbbec80d0000 pid=3528 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=4a25f458-1700-0000-071b-cbbec80d0000 pid=3528 execve guuid=3f266d59-1700-0000-071b-cbbeca0d0000 pid=3530 /tmp/i486 guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3f266d59-1700-0000-071b-cbbeca0d0000 pid=3530 execve guuid=1d81335c-1700-0000-071b-cbbed20d0000 pid=3538 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=1d81335c-1700-0000-071b-cbbed20d0000 pid=3538 execve guuid=6767a55c-1700-0000-071b-cbbed40d0000 pid=3540 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=6767a55c-1700-0000-071b-cbbed40d0000 pid=3540 execve guuid=71e7c065-1700-0000-071b-cbbefa0d0000 pid=3578 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=71e7c065-1700-0000-071b-cbbefa0d0000 pid=3578 execve guuid=ba4fd86f-1700-0000-071b-cbbe350e0000 pid=3637 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=ba4fd86f-1700-0000-071b-cbbe350e0000 pid=3637 clone guuid=c528f66f-1700-0000-071b-cbbe360e0000 pid=3638 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=c528f66f-1700-0000-071b-cbbe360e0000 pid=3638 execve guuid=c7812c70-1700-0000-071b-cbbe380e0000 pid=3640 /tmp/i686 guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=c7812c70-1700-0000-071b-cbbe380e0000 pid=3640 execve guuid=a204c37c-1700-0000-071b-cbbe520e0000 pid=3666 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=a204c37c-1700-0000-071b-cbbe520e0000 pid=3666 execve guuid=0fb20c7d-1700-0000-071b-cbbe550e0000 pid=3669 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0fb20c7d-1700-0000-071b-cbbe550e0000 pid=3669 execve guuid=ce3cbd87-1700-0000-071b-cbbe870e0000 pid=3719 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=ce3cbd87-1700-0000-071b-cbbe870e0000 pid=3719 execve guuid=945d9c93-1700-0000-071b-cbbeac0e0000 pid=3756 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=945d9c93-1700-0000-071b-cbbeac0e0000 pid=3756 clone guuid=bb1ac493-1700-0000-071b-cbbeae0e0000 pid=3758 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=bb1ac493-1700-0000-071b-cbbeae0e0000 pid=3758 execve guuid=6ced1794-1700-0000-071b-cbbeaf0e0000 pid=3759 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=6ced1794-1700-0000-071b-cbbeaf0e0000 pid=3759 clone guuid=fe836994-1700-0000-071b-cbbeb30e0000 pid=3763 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=fe836994-1700-0000-071b-cbbeb30e0000 pid=3763 execve guuid=62efb594-1700-0000-071b-cbbeb50e0000 pid=3765 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=62efb594-1700-0000-071b-cbbeb50e0000 pid=3765 execve guuid=088f23a2-1700-0000-071b-cbbed50e0000 pid=3797 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=088f23a2-1700-0000-071b-cbbed50e0000 pid=3797 execve guuid=596ea9b1-1700-0000-071b-cbbe0c0f0000 pid=3852 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=596ea9b1-1700-0000-071b-cbbe0c0f0000 pid=3852 clone guuid=4d27d4b1-1700-0000-071b-cbbe0d0f0000 pid=3853 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=4d27d4b1-1700-0000-071b-cbbe0d0f0000 pid=3853 execve guuid=d25763b2-1700-0000-071b-cbbe100f0000 pid=3856 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=d25763b2-1700-0000-071b-cbbe100f0000 pid=3856 clone guuid=fe72bab2-1700-0000-071b-cbbe130f0000 pid=3859 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=fe72bab2-1700-0000-071b-cbbe130f0000 pid=3859 execve guuid=9adb20b3-1700-0000-071b-cbbe150f0000 pid=3861 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=9adb20b3-1700-0000-071b-cbbe150f0000 pid=3861 execve guuid=94a180be-1700-0000-071b-cbbe330f0000 pid=3891 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=94a180be-1700-0000-071b-cbbe330f0000 pid=3891 execve guuid=7ae7dfcc-1700-0000-071b-cbbe580f0000 pid=3928 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=7ae7dfcc-1700-0000-071b-cbbe580f0000 pid=3928 clone guuid=79a912cd-1700-0000-071b-cbbe590f0000 pid=3929 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=79a912cd-1700-0000-071b-cbbe590f0000 pid=3929 execve guuid=3b2c91cd-1700-0000-071b-cbbe5b0f0000 pid=3931 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3b2c91cd-1700-0000-071b-cbbe5b0f0000 pid=3931 clone guuid=40d901ce-1700-0000-071b-cbbe5f0f0000 pid=3935 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=40d901ce-1700-0000-071b-cbbe5f0f0000 pid=3935 execve guuid=48f785ce-1700-0000-071b-cbbe610f0000 pid=3937 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=48f785ce-1700-0000-071b-cbbe610f0000 pid=3937 execve guuid=47fdd2d9-1700-0000-071b-cbbe7e0f0000 pid=3966 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=47fdd2d9-1700-0000-071b-cbbe7e0f0000 pid=3966 execve guuid=dc0340e6-1700-0000-071b-cbbea60f0000 pid=4006 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=dc0340e6-1700-0000-071b-cbbea60f0000 pid=4006 clone guuid=2bb557e6-1700-0000-071b-cbbea70f0000 pid=4007 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=2bb557e6-1700-0000-071b-cbbea70f0000 pid=4007 execve guuid=953abae6-1700-0000-071b-cbbeaa0f0000 pid=4010 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=953abae6-1700-0000-071b-cbbeaa0f0000 pid=4010 clone guuid=a06f36e7-1700-0000-071b-cbbeae0f0000 pid=4014 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=a06f36e7-1700-0000-071b-cbbeae0f0000 pid=4014 execve guuid=077a93ec-1700-0000-071b-cbbec00f0000 pid=4032 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=077a93ec-1700-0000-071b-cbbec00f0000 pid=4032 execve guuid=62f721f8-1700-0000-071b-cbbeda0f0000 pid=4058 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=62f721f8-1700-0000-071b-cbbeda0f0000 pid=4058 execve guuid=3adc1805-1800-0000-071b-cbbef90f0000 pid=4089 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3adc1805-1800-0000-071b-cbbef90f0000 pid=4089 clone guuid=06cc4e05-1800-0000-071b-cbbefb0f0000 pid=4091 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=06cc4e05-1800-0000-071b-cbbefb0f0000 pid=4091 execve guuid=e872cf05-1800-0000-071b-cbbefd0f0000 pid=4093 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=e872cf05-1800-0000-071b-cbbefd0f0000 pid=4093 clone guuid=26272306-1800-0000-071b-cbbe01100000 pid=4097 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=26272306-1800-0000-071b-cbbe01100000 pid=4097 execve guuid=e5f6c808-1800-0000-071b-cbbe03100000 pid=4099 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=e5f6c808-1800-0000-071b-cbbe03100000 pid=4099 execve guuid=0900f713-1800-0000-071b-cbbe2a100000 pid=4138 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0900f713-1800-0000-071b-cbbe2a100000 pid=4138 execve guuid=6d44d51f-1800-0000-071b-cbbe4d100000 pid=4173 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=6d44d51f-1800-0000-071b-cbbe4d100000 pid=4173 clone guuid=e354f41f-1800-0000-071b-cbbe4e100000 pid=4174 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=e354f41f-1800-0000-071b-cbbe4e100000 pid=4174 execve guuid=c1c65b20-1800-0000-071b-cbbe4f100000 pid=4175 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=c1c65b20-1800-0000-071b-cbbe4f100000 pid=4175 clone guuid=0f3eba20-1800-0000-071b-cbbe52100000 pid=4178 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0f3eba20-1800-0000-071b-cbbe52100000 pid=4178 execve guuid=cc386523-1800-0000-071b-cbbe53100000 pid=4179 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=cc386523-1800-0000-071b-cbbe53100000 pid=4179 execve guuid=824dce2c-1800-0000-071b-cbbe63100000 pid=4195 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=824dce2c-1800-0000-071b-cbbe63100000 pid=4195 execve guuid=2778e74d-1800-0000-071b-cbbe6e100000 pid=4206 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=2778e74d-1800-0000-071b-cbbe6e100000 pid=4206 clone guuid=46090d4e-1800-0000-071b-cbbe6f100000 pid=4207 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=46090d4e-1800-0000-071b-cbbe6f100000 pid=4207 execve guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209 /tmp/x86 guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209 execve guuid=9d02cb5c-1800-0000-071b-cbbe90100000 pid=4240 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=9d02cb5c-1800-0000-071b-cbbe90100000 pid=4240 execve guuid=3b710d5d-1800-0000-071b-cbbe93100000 pid=4243 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3b710d5d-1800-0000-071b-cbbe93100000 pid=4243 execve guuid=3e871b68-1800-0000-071b-cbbec2100000 pid=4290 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3e871b68-1800-0000-071b-cbbec2100000 pid=4290 execve guuid=9752338a-1800-0000-071b-cbbed9100000 pid=4313 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=9752338a-1800-0000-071b-cbbed9100000 pid=4313 clone guuid=3e49678a-1800-0000-071b-cbbeda100000 pid=4314 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=3e49678a-1800-0000-071b-cbbeda100000 pid=4314 execve guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316 /tmp/x86_64 guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316 execve guuid=1fa2fa8d-1800-0000-071b-cbbee5100000 pid=4325 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=1fa2fa8d-1800-0000-071b-cbbee5100000 pid=4325 execve guuid=1e3f528e-1800-0000-071b-cbbee6100000 pid=4326 /usr/bin/wget net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=1e3f528e-1800-0000-071b-cbbee6100000 pid=4326 execve guuid=8c585799-1800-0000-071b-cbbeef100000 pid=4335 /usr/bin/curl net send-data write-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=8c585799-1800-0000-071b-cbbeef100000 pid=4335 execve guuid=189b48a6-1800-0000-071b-cbbef1100000 pid=4337 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=189b48a6-1800-0000-071b-cbbef1100000 pid=4337 clone guuid=dd4a74a6-1800-0000-071b-cbbef2100000 pid=4338 /usr/bin/chmod guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=dd4a74a6-1800-0000-071b-cbbef2100000 pid=4338 execve guuid=be6300a7-1800-0000-071b-cbbef3100000 pid=4339 /usr/bin/bash guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=be6300a7-1800-0000-071b-cbbef3100000 pid=4339 clone guuid=5e6959a7-1800-0000-071b-cbbef6100000 pid=4342 /usr/bin/rm delete-file guuid=787655cd-1600-0000-071b-cbbe9f0c0000 pid=3231->guuid=5e6959a7-1800-0000-071b-cbbef6100000 pid=4342 execve 28318de2-8d63-5b31-be23-c532c58983b9 45.125.66.56:80 guuid=0756d6d1-1600-0000-071b-cbbea80c0000 pid=3240->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=7b728fde-1600-0000-071b-cbbebb0c0000 pid=3259->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=3a304ff0-1600-0000-071b-cbbee90c0000 pid=3305->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=a22bacfb-1600-0000-071b-cbbefd0c0000 pid=3325->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=380cd50b-1700-0000-071b-cbbe190d0000 pid=3353->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=d59e2617-1700-0000-071b-cbbe320d0000 pid=3378->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=c6f4252a-1700-0000-071b-cbbe680d0000 pid=3432->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=44269233-1700-0000-071b-cbbe7e0d0000 pid=3454->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=4258b640-1700-0000-071b-cbbea10d0000 pid=3489->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=0286754e-1700-0000-071b-cbbeb50d0000 pid=3509->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=27d3be5a-1700-0000-071b-cbbecd0d0000 pid=3533 /tmp/i486 net send-data guuid=3f266d59-1700-0000-071b-cbbeca0d0000 pid=3530->guuid=27d3be5a-1700-0000-071b-cbbecd0d0000 pid=3533 clone guuid=d550ce5a-1700-0000-071b-cbbece0d0000 pid=3534 /tmp/i486 net send-data guuid=3f266d59-1700-0000-071b-cbbeca0d0000 pid=3530->guuid=d550ce5a-1700-0000-071b-cbbece0d0000 pid=3534 clone guuid=39a2275c-1700-0000-071b-cbbed00d0000 pid=3536 /tmp/i486 guuid=3f266d59-1700-0000-071b-cbbeca0d0000 pid=3530->guuid=39a2275c-1700-0000-071b-cbbed00d0000 pid=3536 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=27d3be5a-1700-0000-071b-cbbecd0d0000 pid=3533->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 43B guuid=d550ce5a-1700-0000-071b-cbbece0d0000 pid=3534->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=331d315c-1700-0000-071b-cbbed30d0000 pid=3539 /tmp/i486 net zombie guuid=39a2275c-1700-0000-071b-cbbed00d0000 pid=3536->guuid=331d315c-1700-0000-071b-cbbed30d0000 pid=3539 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=331d315c-1700-0000-071b-cbbed30d0000 pid=3539->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con d41ff612-c494-5ad2-835e-cba99e77da4d 194.113.37.21:1025 guuid=331d315c-1700-0000-071b-cbbed30d0000 pid=3539->d41ff612-c494-5ad2-835e-cba99e77da4d con guuid=008fd65c-1700-0000-071b-cbbed50d0000 pid=3541 /tmp/i486 guuid=331d315c-1700-0000-071b-cbbed30d0000 pid=3539->guuid=008fd65c-1700-0000-071b-cbbed50d0000 pid=3541 clone guuid=6767a55c-1700-0000-071b-cbbed40d0000 pid=3540->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=71e7c065-1700-0000-071b-cbbefa0d0000 pid=3578->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=7266df76-1700-0000-071b-cbbe460e0000 pid=3654 /tmp/i686 net send-data guuid=c7812c70-1700-0000-071b-cbbe380e0000 pid=3640->guuid=7266df76-1700-0000-071b-cbbe460e0000 pid=3654 clone guuid=1e76f076-1700-0000-071b-cbbe470e0000 pid=3655 /tmp/i686 net send-data guuid=c7812c70-1700-0000-071b-cbbe380e0000 pid=3640->guuid=1e76f076-1700-0000-071b-cbbe470e0000 pid=3655 clone guuid=278bb87c-1700-0000-071b-cbbe510e0000 pid=3665 /tmp/i686 guuid=c7812c70-1700-0000-071b-cbbe380e0000 pid=3640->guuid=278bb87c-1700-0000-071b-cbbe510e0000 pid=3665 clone guuid=7266df76-1700-0000-071b-cbbe460e0000 pid=3654->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 43B guuid=1e76f076-1700-0000-071b-cbbe470e0000 pid=3655->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=0844c37c-1700-0000-071b-cbbe530e0000 pid=3667 /tmp/i686 net send-data write-file zombie guuid=278bb87c-1700-0000-071b-cbbe510e0000 pid=3665->guuid=0844c37c-1700-0000-071b-cbbe530e0000 pid=3667 clone guuid=0844c37c-1700-0000-071b-cbbe530e0000 pid=3667->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con db96774e-46a5-59dd-83b1-9c87ef6aad62 104.252.127.190:1025 guuid=0844c37c-1700-0000-071b-cbbe530e0000 pid=3667->db96774e-46a5-59dd-83b1-9c87ef6aad62 send: 19B guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699 /tmp/i686 guuid=0844c37c-1700-0000-071b-cbbe530e0000 pid=3667->guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699 clone guuid=0fb20c7d-1700-0000-071b-cbbe550e0000 pid=3669->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=1fc53d94-1700-0000-071b-cbbeb20e0000 pid=3762 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=1fc53d94-1700-0000-071b-cbbeb20e0000 pid=3762 clone guuid=62210e97-1700-0000-071b-cbbebd0e0000 pid=3773 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=62210e97-1700-0000-071b-cbbebd0e0000 pid=3773 clone guuid=c53d8bb2-1700-0000-071b-cbbe120f0000 pid=3858 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=c53d8bb2-1700-0000-071b-cbbe120f0000 pid=3858 clone guuid=6c02aeb6-1700-0000-071b-cbbe1f0f0000 pid=3871 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=6c02aeb6-1700-0000-071b-cbbe1f0f0000 pid=3871 clone guuid=bb6477bb-1700-0000-071b-cbbe2b0f0000 pid=3883 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=bb6477bb-1700-0000-071b-cbbe2b0f0000 pid=3883 clone guuid=c924eebb-1700-0000-071b-cbbe2d0f0000 pid=3885 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=c924eebb-1700-0000-071b-cbbe2d0f0000 pid=3885 clone guuid=a000c4c1-1700-0000-071b-cbbe3d0f0000 pid=3901 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=a000c4c1-1700-0000-071b-cbbe3d0f0000 pid=3901 clone guuid=85f659c7-1700-0000-071b-cbbe4a0f0000 pid=3914 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=85f659c7-1700-0000-071b-cbbe4a0f0000 pid=3914 clone guuid=3845e7cb-1700-0000-071b-cbbe550f0000 pid=3925 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=3845e7cb-1700-0000-071b-cbbe550f0000 pid=3925 clone guuid=2f73c5cd-1700-0000-071b-cbbe5d0f0000 pid=3933 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=2f73c5cd-1700-0000-071b-cbbe5d0f0000 pid=3933 clone guuid=e66624d1-1700-0000-071b-cbbe680f0000 pid=3944 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=e66624d1-1700-0000-071b-cbbe680f0000 pid=3944 clone guuid=68c227d6-1700-0000-071b-cbbe750f0000 pid=3957 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=68c227d6-1700-0000-071b-cbbe750f0000 pid=3957 clone guuid=869e28da-1700-0000-071b-cbbe810f0000 pid=3969 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=869e28da-1700-0000-071b-cbbe810f0000 pid=3969 clone guuid=f7eec7dd-1700-0000-071b-cbbe8c0f0000 pid=3980 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=f7eec7dd-1700-0000-071b-cbbe8c0f0000 pid=3980 clone guuid=22c240e1-1700-0000-071b-cbbe970f0000 pid=3991 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=22c240e1-1700-0000-071b-cbbe970f0000 pid=3991 clone guuid=6d4910e5-1700-0000-071b-cbbea20f0000 pid=4002 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=6d4910e5-1700-0000-071b-cbbea20f0000 pid=4002 clone guuid=52e70be7-1700-0000-071b-cbbeac0f0000 pid=4012 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=52e70be7-1700-0000-071b-cbbeac0f0000 pid=4012 clone guuid=36e722f7-1700-0000-071b-cbbed70f0000 pid=4055 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=36e722f7-1700-0000-071b-cbbed70f0000 pid=4055 clone guuid=49eb4a04-1800-0000-071b-cbbef60f0000 pid=4086 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=49eb4a04-1800-0000-071b-cbbef60f0000 pid=4086 clone guuid=dd31f305-1800-0000-071b-cbbeff0f0000 pid=4095 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=dd31f305-1800-0000-071b-cbbeff0f0000 pid=4095 clone guuid=24d02e0a-1800-0000-071b-cbbe09100000 pid=4105 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=24d02e0a-1800-0000-071b-cbbe09100000 pid=4105 clone guuid=038efd0d-1800-0000-071b-cbbe15100000 pid=4117 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=038efd0d-1800-0000-071b-cbbe15100000 pid=4117 clone guuid=0fe7f012-1800-0000-071b-cbbe23100000 pid=4131 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=0fe7f012-1800-0000-071b-cbbe23100000 pid=4131 clone guuid=c3ab2813-1800-0000-071b-cbbe25100000 pid=4133 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=c3ab2813-1800-0000-071b-cbbe25100000 pid=4133 clone guuid=c0b58113-1800-0000-071b-cbbe27100000 pid=4135 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=c0b58113-1800-0000-071b-cbbe27100000 pid=4135 clone guuid=167c3e18-1800-0000-071b-cbbe39100000 pid=4153 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=167c3e18-1800-0000-071b-cbbe39100000 pid=4153 clone guuid=d8ab8920-1800-0000-071b-cbbe51100000 pid=4177 /tmp/i686 net send-data guuid=e6b73e83-1700-0000-071b-cbbe730e0000 pid=3699->guuid=d8ab8920-1800-0000-071b-cbbe51100000 pid=4177 clone guuid=ce3cbd87-1700-0000-071b-cbbe870e0000 pid=3719->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=1fc53d94-1700-0000-071b-cbbeb20e0000 pid=3762->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=62efb594-1700-0000-071b-cbbeb50e0000 pid=3765->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=62210e97-1700-0000-071b-cbbebd0e0000 pid=3773->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=088f23a2-1700-0000-071b-cbbed50e0000 pid=3797->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=c53d8bb2-1700-0000-071b-cbbe120f0000 pid=3858->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=9adb20b3-1700-0000-071b-cbbe150f0000 pid=3861->28318de2-8d63-5b31-be23-c532c58983b9 send: 131B guuid=6c02aeb6-1700-0000-071b-cbbe1f0f0000 pid=3871->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=bb6477bb-1700-0000-071b-cbbe2b0f0000 pid=3883->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=c924eebb-1700-0000-071b-cbbe2d0f0000 pid=3885->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=94a180be-1700-0000-071b-cbbe330f0000 pid=3891->28318de2-8d63-5b31-be23-c532c58983b9 send: 80B guuid=a000c4c1-1700-0000-071b-cbbe3d0f0000 pid=3901->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=85f659c7-1700-0000-071b-cbbe4a0f0000 pid=3914->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=3845e7cb-1700-0000-071b-cbbe550f0000 pid=3925->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=2f73c5cd-1700-0000-071b-cbbe5d0f0000 pid=3933->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=48f785ce-1700-0000-071b-cbbe610f0000 pid=3937->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=e66624d1-1700-0000-071b-cbbe680f0000 pid=3944->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=68c227d6-1700-0000-071b-cbbe750f0000 pid=3957->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=47fdd2d9-1700-0000-071b-cbbe7e0f0000 pid=3966->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=869e28da-1700-0000-071b-cbbe810f0000 pid=3969->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=f7eec7dd-1700-0000-071b-cbbe8c0f0000 pid=3980->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=22c240e1-1700-0000-071b-cbbe970f0000 pid=3991->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=6d4910e5-1700-0000-071b-cbbea20f0000 pid=4002->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=52e70be7-1700-0000-071b-cbbeac0f0000 pid=4012->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=077a93ec-1700-0000-071b-cbbec00f0000 pid=4032->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=36e722f7-1700-0000-071b-cbbed70f0000 pid=4055->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=62f721f8-1700-0000-071b-cbbeda0f0000 pid=4058->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=49eb4a04-1800-0000-071b-cbbef60f0000 pid=4086->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=dd31f305-1800-0000-071b-cbbeff0f0000 pid=4095->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=e5f6c808-1800-0000-071b-cbbe03100000 pid=4099->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=24d02e0a-1800-0000-071b-cbbe09100000 pid=4105->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=038efd0d-1800-0000-071b-cbbe15100000 pid=4117->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=0fe7f012-1800-0000-071b-cbbe23100000 pid=4131->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=c3ab2813-1800-0000-071b-cbbe25100000 pid=4133->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=c0b58113-1800-0000-071b-cbbe27100000 pid=4135->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=0900f713-1800-0000-071b-cbbe2a100000 pid=4138->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=167c3e18-1800-0000-071b-cbbe39100000 pid=4153->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 85B guuid=d8ab8920-1800-0000-071b-cbbe51100000 pid=4177->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=cc386523-1800-0000-071b-cbbe53100000 pid=4179->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=824dce2c-1800-0000-071b-cbbe63100000 pid=4195->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=0e927956-1800-0000-071b-cbbe80100000 pid=4224 /tmp/x86 net send-data guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209->guuid=0e927956-1800-0000-071b-cbbe80100000 pid=4224 clone guuid=27457e56-1800-0000-071b-cbbe81100000 pid=4225 /tmp/x86 net send-data guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209->guuid=27457e56-1800-0000-071b-cbbe81100000 pid=4225 clone guuid=212af056-1800-0000-071b-cbbe83100000 pid=4227 /tmp/x86 net send-data guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209->guuid=212af056-1800-0000-071b-cbbe83100000 pid=4227 clone guuid=6d51f556-1800-0000-071b-cbbe84100000 pid=4228 /tmp/x86 net send-data guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209->guuid=6d51f556-1800-0000-071b-cbbe84100000 pid=4228 clone guuid=ce38c15c-1800-0000-071b-cbbe8f100000 pid=4239 /tmp/x86 guuid=0260924e-1800-0000-071b-cbbe71100000 pid=4209->guuid=ce38c15c-1800-0000-071b-cbbe8f100000 pid=4239 clone guuid=0e927956-1800-0000-071b-cbbe80100000 pid=4224->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=27457e56-1800-0000-071b-cbbe81100000 pid=4225->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=212af056-1800-0000-071b-cbbe83100000 pid=4227->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 42B guuid=6d51f556-1800-0000-071b-cbbe84100000 pid=4228->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 44B guuid=c6cdd35c-1800-0000-071b-cbbe91100000 pid=4241 /tmp/x86 net send-data write-file zombie guuid=ce38c15c-1800-0000-071b-cbbe8f100000 pid=4239->guuid=c6cdd35c-1800-0000-071b-cbbe91100000 pid=4241 clone guuid=c6cdd35c-1800-0000-071b-cbbe91100000 pid=4241->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con c6203332-51f0-5ada-b496-18efd14e4d3d 217.60.249.53:1025 guuid=c6cdd35c-1800-0000-071b-cbbe91100000 pid=4241->c6203332-51f0-5ada-b496-18efd14e4d3d send: 18B guuid=b6e20d64-1800-0000-071b-cbbea8100000 pid=4264 /tmp/x86 guuid=c6cdd35c-1800-0000-071b-cbbe91100000 pid=4241->guuid=b6e20d64-1800-0000-071b-cbbea8100000 pid=4264 clone guuid=3b710d5d-1800-0000-071b-cbbe93100000 pid=4243->28318de2-8d63-5b31-be23-c532c58983b9 send: 133B guuid=3e871b68-1800-0000-071b-cbbec2100000 pid=4290->28318de2-8d63-5b31-be23-c532c58983b9 send: 82B guuid=3ffb228c-1800-0000-071b-cbbedf100000 pid=4319 /tmp/x86_64 net send-data guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316->guuid=3ffb228c-1800-0000-071b-cbbedf100000 pid=4319 clone guuid=87273a8c-1800-0000-071b-cbbee0100000 pid=4320 /tmp/x86_64 net send-data guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316->guuid=87273a8c-1800-0000-071b-cbbee0100000 pid=4320 clone guuid=e4495e8c-1800-0000-071b-cbbee1100000 pid=4321 /tmp/x86_64 net zombie guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316->guuid=e4495e8c-1800-0000-071b-cbbee1100000 pid=4321 clone guuid=bb74648c-1800-0000-071b-cbbee2100000 pid=4322 /tmp/x86_64 net send-data guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316->guuid=bb74648c-1800-0000-071b-cbbee2100000 pid=4322 clone guuid=8f6ae18d-1800-0000-071b-cbbee3100000 pid=4323 /tmp/x86_64 zombie guuid=97c9e58a-1800-0000-071b-cbbedc100000 pid=4316->guuid=8f6ae18d-1800-0000-071b-cbbee3100000 pid=4323 clone guuid=3ffb228c-1800-0000-071b-cbbedf100000 pid=4319->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=87273a8c-1800-0000-071b-cbbee0100000 pid=4320->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=e4495e8c-1800-0000-071b-cbbee1100000 pid=4321->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=bb74648c-1800-0000-071b-cbbee2100000 pid=4322->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324 /tmp/x86_64 net send-data zombie guuid=8f6ae18d-1800-0000-071b-cbbee3100000 pid=4323->guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324 clone guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324->db96774e-46a5-59dd-83b1-9c87ef6aad62 send: 21B ea494a48-4f87-555b-a374-5bcf7d498d0d 51.83.147.130:1025 guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324->ea494a48-4f87-555b-a374-5bcf7d498d0d send: 25B guuid=7ea5c98e-1800-0000-071b-cbbee7100000 pid=4327 /tmp/x86_64 guuid=4059ef8d-1800-0000-071b-cbbee4100000 pid=4324->guuid=7ea5c98e-1800-0000-071b-cbbee7100000 pid=4327 clone guuid=1e3f528e-1800-0000-071b-cbbee6100000 pid=4326->28318de2-8d63-5b31-be23-c532c58983b9 send: 130B guuid=4eaf2da7-1800-0000-071b-cbbef5100000 pid=4341 /tmp/x86_64 net send-data guuid=7ea5c98e-1800-0000-071b-cbbee7100000 pid=4327->guuid=4eaf2da7-1800-0000-071b-cbbef5100000 pid=4341 clone guuid=8c585799-1800-0000-071b-cbbeef100000 pid=4335->28318de2-8d63-5b31-be23-c532c58983b9 send: 79B guuid=4eaf2da7-1800-0000-071b-cbbef5100000 pid=4341->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B
Threat name:
Linux.Trojan.Vigorf
Status:
Malicious
First seen:
2025-09-12 07:54:32 UTC
File Type:
Text (Shell)
AV detection:
17 of 38 (44.74%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 2e7b8b20114f302ee6f4c8b77a6a0dc7bd786c026f89f956d92dffa923c6450d

(this sample)

  
Delivery method
Distributed via web download

Comments