MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f3304c7200d6bd5b4c4131a3eb8e4021fc56b6feefea3bf403a2304e96ee938. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 12 File information Comments

SHA256 hash: 2f3304c7200d6bd5b4c4131a3eb8e4021fc56b6feefea3bf403a2304e96ee938
SHA3-384 hash: 9b03b95720100270c9b549352ebee1954c1bc0d985ab178ae95a51911585e1d33656daca81ef6300f44146095fa0f44e
SHA1 hash: 8415c73c8a0be24d3cfce140ea1c78efe349509d
MD5 hash: 33e7a99a9d450c0af478953449685983
humanhash: four-bluebird-spring-asparagus
File name:cron
Download: download sample
Signature Mirai
File size:121'814 bytes
First seen:2025-07-05 09:54:37 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:w4LRz7grT8cWEXWuDPPFUPnXcB1zmpFEthq9aTeMT:wuzUrPG8PPFUvcHmpFEthq9aTeMT
TLSH T156C34329F503C373D49306B1219EEE262D306FE5379AB906B3B47AB4A9734877501E9C
telfhash t1c2313322953556142fb3a928acbd56b315222b2323586f71af26c5cc49260e2e93dd4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
15
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Launching a process
Connection attempt
Substitutes an application name
Status:
terminated
Behavior Graph:
%3 guuid=495a97e3-1a00-0000-7c31-0c7af70b0000 pid=3063 /usr/bin/sudo guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067 /tmp/sample.bin net guuid=495a97e3-1a00-0000-7c31-0c7af70b0000 pid=3063->guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071 /tmp/sample.bin zombie guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067->guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071 clone guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072 /usr/bin/dash zombie guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067->guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072 execve guuid=dd8d16e6-1a00-0000-7c31-0c7a010c0000 pid=3073 /tmp/sample.bin guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067->guuid=dd8d16e6-1a00-0000-7c31-0c7a010c0000 pid=3073 clone guuid=cb8b19e6-1a00-0000-7c31-0c7a020c0000 pid=3074 /tmp/sample.bin guuid=41e129e5-1a00-0000-7c31-0c7afb0b0000 pid=3067->guuid=cb8b19e6-1a00-0000-7c31-0c7a020c0000 pid=3074 clone guuid=a01aef18-1b00-0000-7c31-0c7a700c0000 pid=3184 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a01aef18-1b00-0000-7c31-0c7a700c0000 pid=3184 execve guuid=4ddb291c-1b00-0000-7c31-0c7a770c0000 pid=3191 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=4ddb291c-1b00-0000-7c31-0c7a770c0000 pid=3191 execve guuid=a516691d-1b00-0000-7c31-0c7a7c0c0000 pid=3196 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a516691d-1b00-0000-7c31-0c7a7c0c0000 pid=3196 execve guuid=28c2f71e-1b00-0000-7c31-0c7a820c0000 pid=3202 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=28c2f71e-1b00-0000-7c31-0c7a820c0000 pid=3202 execve guuid=73c62b20-1b00-0000-7c31-0c7a880c0000 pid=3208 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=73c62b20-1b00-0000-7c31-0c7a880c0000 pid=3208 execve guuid=c9439321-1b00-0000-7c31-0c7a8d0c0000 pid=3213 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=c9439321-1b00-0000-7c31-0c7a8d0c0000 pid=3213 execve guuid=42bb0223-1b00-0000-7c31-0c7a940c0000 pid=3220 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=42bb0223-1b00-0000-7c31-0c7a940c0000 pid=3220 execve guuid=e3981b24-1b00-0000-7c31-0c7a980c0000 pid=3224 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=e3981b24-1b00-0000-7c31-0c7a980c0000 pid=3224 execve guuid=b2761725-1b00-0000-7c31-0c7a9b0c0000 pid=3227 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=b2761725-1b00-0000-7c31-0c7a9b0c0000 pid=3227 execve guuid=e183d852-1c00-0000-7c31-0c7a870f0000 pid=3975 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=e183d852-1c00-0000-7c31-0c7a870f0000 pid=3975 execve guuid=8b2acd55-1c00-0000-7c31-0c7a930f0000 pid=3987 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=8b2acd55-1c00-0000-7c31-0c7a930f0000 pid=3987 execve guuid=c077c356-1c00-0000-7c31-0c7a980f0000 pid=3992 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=c077c356-1c00-0000-7c31-0c7a980f0000 pid=3992 execve guuid=954ed557-1c00-0000-7c31-0c7aa00f0000 pid=4000 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=954ed557-1c00-0000-7c31-0c7aa00f0000 pid=4000 execve guuid=6158fb58-1c00-0000-7c31-0c7aa70f0000 pid=4007 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=6158fb58-1c00-0000-7c31-0c7aa70f0000 pid=4007 execve guuid=19e2f659-1c00-0000-7c31-0c7aac0f0000 pid=4012 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=19e2f659-1c00-0000-7c31-0c7aac0f0000 pid=4012 execve guuid=4f86e15a-1c00-0000-7c31-0c7ab10f0000 pid=4017 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=4f86e15a-1c00-0000-7c31-0c7ab10f0000 pid=4017 execve guuid=d98eed5b-1c00-0000-7c31-0c7ab90f0000 pid=4025 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=d98eed5b-1c00-0000-7c31-0c7ab90f0000 pid=4025 execve guuid=66e45c5d-1c00-0000-7c31-0c7ac10f0000 pid=4033 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=66e45c5d-1c00-0000-7c31-0c7ac10f0000 pid=4033 execve guuid=5193ef8b-1d00-0000-7c31-0c7aa2130000 pid=5026 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=5193ef8b-1d00-0000-7c31-0c7aa2130000 pid=5026 execve guuid=d7cf5a8f-1d00-0000-7c31-0c7aaf130000 pid=5039 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=d7cf5a8f-1d00-0000-7c31-0c7aaf130000 pid=5039 execve guuid=f185ba90-1d00-0000-7c31-0c7ab5130000 pid=5045 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f185ba90-1d00-0000-7c31-0c7ab5130000 pid=5045 execve guuid=708eb891-1d00-0000-7c31-0c7ab9130000 pid=5049 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=708eb891-1d00-0000-7c31-0c7ab9130000 pid=5049 execve guuid=fa3aac92-1d00-0000-7c31-0c7abe130000 pid=5054 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=fa3aac92-1d00-0000-7c31-0c7abe130000 pid=5054 execve guuid=47384394-1d00-0000-7c31-0c7ac5130000 pid=5061 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=47384394-1d00-0000-7c31-0c7ac5130000 pid=5061 execve guuid=296a7695-1d00-0000-7c31-0c7acb130000 pid=5067 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=296a7695-1d00-0000-7c31-0c7acb130000 pid=5067 execve guuid=2592a696-1d00-0000-7c31-0c7ad0130000 pid=5072 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2592a696-1d00-0000-7c31-0c7ad0130000 pid=5072 execve guuid=5b810b98-1d00-0000-7c31-0c7ad4130000 pid=5076 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=5b810b98-1d00-0000-7c31-0c7ad4130000 pid=5076 execve guuid=fc6a0ac6-1e00-0000-7c31-0c7ab6140000 pid=5302 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=fc6a0ac6-1e00-0000-7c31-0c7ab6140000 pid=5302 execve guuid=d4f5d0c8-1e00-0000-7c31-0c7ab8140000 pid=5304 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=d4f5d0c8-1e00-0000-7c31-0c7ab8140000 pid=5304 execve guuid=a73ecac9-1e00-0000-7c31-0c7aba140000 pid=5306 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a73ecac9-1e00-0000-7c31-0c7aba140000 pid=5306 execve guuid=f655e8ca-1e00-0000-7c31-0c7abc140000 pid=5308 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f655e8ca-1e00-0000-7c31-0c7abc140000 pid=5308 execve guuid=f1ccdccb-1e00-0000-7c31-0c7abe140000 pid=5310 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f1ccdccb-1e00-0000-7c31-0c7abe140000 pid=5310 execve guuid=eeb5bbcc-1e00-0000-7c31-0c7ac0140000 pid=5312 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=eeb5bbcc-1e00-0000-7c31-0c7ac0140000 pid=5312 execve guuid=5d3892cd-1e00-0000-7c31-0c7ac2140000 pid=5314 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=5d3892cd-1e00-0000-7c31-0c7ac2140000 pid=5314 execve guuid=f2ec77ce-1e00-0000-7c31-0c7ac4140000 pid=5316 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f2ec77ce-1e00-0000-7c31-0c7ac4140000 pid=5316 execve guuid=31b6c6cf-1e00-0000-7c31-0c7ac6140000 pid=5318 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=31b6c6cf-1e00-0000-7c31-0c7ac6140000 pid=5318 execve guuid=888c24ff-1f00-0000-7c31-0c7ad5140000 pid=5333 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=888c24ff-1f00-0000-7c31-0c7ad5140000 pid=5333 execve guuid=a126d902-2000-0000-7c31-0c7add140000 pid=5341 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a126d902-2000-0000-7c31-0c7add140000 pid=5341 execve guuid=37c31304-2000-0000-7c31-0c7ae0140000 pid=5344 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=37c31304-2000-0000-7c31-0c7ae0140000 pid=5344 execve guuid=24014305-2000-0000-7c31-0c7ae2140000 pid=5346 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=24014305-2000-0000-7c31-0c7ae2140000 pid=5346 execve guuid=f1b16f06-2000-0000-7c31-0c7ae4140000 pid=5348 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f1b16f06-2000-0000-7c31-0c7ae4140000 pid=5348 execve guuid=6ecc9807-2000-0000-7c31-0c7ae6140000 pid=5350 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=6ecc9807-2000-0000-7c31-0c7ae6140000 pid=5350 execve guuid=5d2fae08-2000-0000-7c31-0c7ae8140000 pid=5352 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=5d2fae08-2000-0000-7c31-0c7ae8140000 pid=5352 execve guuid=98d9ec09-2000-0000-7c31-0c7aea140000 pid=5354 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=98d9ec09-2000-0000-7c31-0c7aea140000 pid=5354 execve guuid=92daf10a-2000-0000-7c31-0c7aec140000 pid=5356 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=92daf10a-2000-0000-7c31-0c7aec140000 pid=5356 execve guuid=98708739-2100-0000-7c31-0c7aee140000 pid=5358 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=98708739-2100-0000-7c31-0c7aee140000 pid=5358 execve guuid=9fe5a03d-2100-0000-7c31-0c7af0140000 pid=5360 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=9fe5a03d-2100-0000-7c31-0c7af0140000 pid=5360 execve guuid=6117993f-2100-0000-7c31-0c7af2140000 pid=5362 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=6117993f-2100-0000-7c31-0c7af2140000 pid=5362 execve guuid=bc724241-2100-0000-7c31-0c7af4140000 pid=5364 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=bc724241-2100-0000-7c31-0c7af4140000 pid=5364 execve guuid=ed7ae642-2100-0000-7c31-0c7af6140000 pid=5366 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=ed7ae642-2100-0000-7c31-0c7af6140000 pid=5366 execve guuid=14afc644-2100-0000-7c31-0c7af8140000 pid=5368 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=14afc644-2100-0000-7c31-0c7af8140000 pid=5368 execve guuid=58bc6a46-2100-0000-7c31-0c7afa140000 pid=5370 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=58bc6a46-2100-0000-7c31-0c7afa140000 pid=5370 execve guuid=1e1a1048-2100-0000-7c31-0c7afc140000 pid=5372 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=1e1a1048-2100-0000-7c31-0c7afc140000 pid=5372 execve guuid=2390ed49-2100-0000-7c31-0c7afe140000 pid=5374 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2390ed49-2100-0000-7c31-0c7afe140000 pid=5374 execve guuid=cfdd7e79-2200-0000-7c31-0c7a00150000 pid=5376 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=cfdd7e79-2200-0000-7c31-0c7a00150000 pid=5376 execve guuid=6241c67c-2200-0000-7c31-0c7a02150000 pid=5378 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=6241c67c-2200-0000-7c31-0c7a02150000 pid=5378 execve guuid=c0dbf77d-2200-0000-7c31-0c7a04150000 pid=5380 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=c0dbf77d-2200-0000-7c31-0c7a04150000 pid=5380 execve guuid=2faa207f-2200-0000-7c31-0c7a06150000 pid=5382 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2faa207f-2200-0000-7c31-0c7a06150000 pid=5382 execve guuid=50e85880-2200-0000-7c31-0c7a08150000 pid=5384 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=50e85880-2200-0000-7c31-0c7a08150000 pid=5384 execve guuid=d0038581-2200-0000-7c31-0c7a0a150000 pid=5386 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=d0038581-2200-0000-7c31-0c7a0a150000 pid=5386 execve guuid=5a07ab82-2200-0000-7c31-0c7a0c150000 pid=5388 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=5a07ab82-2200-0000-7c31-0c7a0c150000 pid=5388 execve guuid=3db22b84-2200-0000-7c31-0c7a0e150000 pid=5390 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=3db22b84-2200-0000-7c31-0c7a0e150000 pid=5390 execve guuid=2fa3ac85-2200-0000-7c31-0c7a10150000 pid=5392 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2fa3ac85-2200-0000-7c31-0c7a10150000 pid=5392 execve guuid=0b87edb4-2300-0000-7c31-0c7a12150000 pid=5394 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=0b87edb4-2300-0000-7c31-0c7a12150000 pid=5394 execve guuid=045e6ab9-2300-0000-7c31-0c7a14150000 pid=5396 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=045e6ab9-2300-0000-7c31-0c7a14150000 pid=5396 execve guuid=f62971ba-2300-0000-7c31-0c7a16150000 pid=5398 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f62971ba-2300-0000-7c31-0c7a16150000 pid=5398 execve guuid=81b877bb-2300-0000-7c31-0c7a18150000 pid=5400 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=81b877bb-2300-0000-7c31-0c7a18150000 pid=5400 execve guuid=9b84babc-2300-0000-7c31-0c7a1a150000 pid=5402 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=9b84babc-2300-0000-7c31-0c7a1a150000 pid=5402 execve guuid=a6d2f6bd-2300-0000-7c31-0c7a1c150000 pid=5404 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a6d2f6bd-2300-0000-7c31-0c7a1c150000 pid=5404 execve guuid=dd4333bf-2300-0000-7c31-0c7a1e150000 pid=5406 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=dd4333bf-2300-0000-7c31-0c7a1e150000 pid=5406 execve guuid=824785c0-2300-0000-7c31-0c7a20150000 pid=5408 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=824785c0-2300-0000-7c31-0c7a20150000 pid=5408 execve guuid=aaabd5c1-2300-0000-7c31-0c7a22150000 pid=5410 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=aaabd5c1-2300-0000-7c31-0c7a22150000 pid=5410 execve guuid=1ca38ff1-2400-0000-7c31-0c7a24150000 pid=5412 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=1ca38ff1-2400-0000-7c31-0c7a24150000 pid=5412 execve guuid=752e2cf6-2400-0000-7c31-0c7a26150000 pid=5414 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=752e2cf6-2400-0000-7c31-0c7a26150000 pid=5414 execve guuid=dab83cf7-2400-0000-7c31-0c7a28150000 pid=5416 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=dab83cf7-2400-0000-7c31-0c7a28150000 pid=5416 execve guuid=7e21ebf8-2400-0000-7c31-0c7a2a150000 pid=5418 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=7e21ebf8-2400-0000-7c31-0c7a2a150000 pid=5418 execve guuid=35bdbafa-2400-0000-7c31-0c7a2c150000 pid=5420 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=35bdbafa-2400-0000-7c31-0c7a2c150000 pid=5420 execve guuid=7424dffb-2400-0000-7c31-0c7a2e150000 pid=5422 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=7424dffb-2400-0000-7c31-0c7a2e150000 pid=5422 execve guuid=aaa8effc-2400-0000-7c31-0c7a30150000 pid=5424 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=aaa8effc-2400-0000-7c31-0c7a30150000 pid=5424 execve guuid=251fe8fd-2400-0000-7c31-0c7a32150000 pid=5426 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=251fe8fd-2400-0000-7c31-0c7a32150000 pid=5426 execve guuid=9decebfe-2400-0000-7c31-0c7a34150000 pid=5428 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=9decebfe-2400-0000-7c31-0c7a34150000 pid=5428 execve guuid=2a585f2e-2600-0000-7c31-0c7a36150000 pid=5430 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2a585f2e-2600-0000-7c31-0c7a36150000 pid=5430 execve guuid=c8c25e33-2600-0000-7c31-0c7a38150000 pid=5432 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=c8c25e33-2600-0000-7c31-0c7a38150000 pid=5432 execve guuid=c4fee635-2600-0000-7c31-0c7a3a150000 pid=5434 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=c4fee635-2600-0000-7c31-0c7a3a150000 pid=5434 execve guuid=ac655538-2600-0000-7c31-0c7a3c150000 pid=5436 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=ac655538-2600-0000-7c31-0c7a3c150000 pid=5436 execve guuid=6c6d6e3a-2600-0000-7c31-0c7a3e150000 pid=5438 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=6c6d6e3a-2600-0000-7c31-0c7a3e150000 pid=5438 execve guuid=2f55a43c-2600-0000-7c31-0c7a40150000 pid=5440 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2f55a43c-2600-0000-7c31-0c7a40150000 pid=5440 execve guuid=1408d63e-2600-0000-7c31-0c7a42150000 pid=5442 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=1408d63e-2600-0000-7c31-0c7a42150000 pid=5442 execve guuid=b1dd2f41-2600-0000-7c31-0c7a44150000 pid=5444 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=b1dd2f41-2600-0000-7c31-0c7a44150000 pid=5444 execve guuid=574a4443-2600-0000-7c31-0c7a46150000 pid=5446 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=574a4443-2600-0000-7c31-0c7a46150000 pid=5446 execve guuid=62608571-2700-0000-7c31-0c7a48150000 pid=5448 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=62608571-2700-0000-7c31-0c7a48150000 pid=5448 execve guuid=67982d76-2700-0000-7c31-0c7a4a150000 pid=5450 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=67982d76-2700-0000-7c31-0c7a4a150000 pid=5450 execve guuid=3c6a7577-2700-0000-7c31-0c7a4c150000 pid=5452 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=3c6a7577-2700-0000-7c31-0c7a4c150000 pid=5452 execve guuid=88851e79-2700-0000-7c31-0c7a4e150000 pid=5454 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=88851e79-2700-0000-7c31-0c7a4e150000 pid=5454 execve guuid=a316127b-2700-0000-7c31-0c7a50150000 pid=5456 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=a316127b-2700-0000-7c31-0c7a50150000 pid=5456 execve guuid=11b5d87c-2700-0000-7c31-0c7a52150000 pid=5458 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=11b5d87c-2700-0000-7c31-0c7a52150000 pid=5458 execve guuid=f5fbb27e-2700-0000-7c31-0c7a54150000 pid=5460 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=f5fbb27e-2700-0000-7c31-0c7a54150000 pid=5460 execve guuid=900a7d80-2700-0000-7c31-0c7a56150000 pid=5462 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=900a7d80-2700-0000-7c31-0c7a56150000 pid=5462 execve guuid=fba73082-2700-0000-7c31-0c7a58150000 pid=5464 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=fba73082-2700-0000-7c31-0c7a58150000 pid=5464 execve guuid=bb883eb2-2800-0000-7c31-0c7a5a150000 pid=5466 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=bb883eb2-2800-0000-7c31-0c7a5a150000 pid=5466 execve guuid=2e950fb6-2800-0000-7c31-0c7a5c150000 pid=5468 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=2e950fb6-2800-0000-7c31-0c7a5c150000 pid=5468 execve guuid=1de75cb7-2800-0000-7c31-0c7a5e150000 pid=5470 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=1de75cb7-2800-0000-7c31-0c7a5e150000 pid=5470 execve guuid=eb4cbeb8-2800-0000-7c31-0c7a60150000 pid=5472 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=eb4cbeb8-2800-0000-7c31-0c7a60150000 pid=5472 execve guuid=eeae24ba-2800-0000-7c31-0c7a62150000 pid=5474 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=eeae24ba-2800-0000-7c31-0c7a62150000 pid=5474 execve guuid=846d96bb-2800-0000-7c31-0c7a64150000 pid=5476 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=846d96bb-2800-0000-7c31-0c7a64150000 pid=5476 execve guuid=b79c02bd-2800-0000-7c31-0c7a66150000 pid=5478 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=b79c02bd-2800-0000-7c31-0c7a66150000 pid=5478 execve guuid=57b165be-2800-0000-7c31-0c7a68150000 pid=5480 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=57b165be-2800-0000-7c31-0c7a68150000 pid=5480 execve guuid=dbb85bbf-2800-0000-7c31-0c7a6b150000 pid=5483 /usr/bin/dash guuid=ba3a0ee6-1a00-0000-7c31-0c7aff0b0000 pid=3071->guuid=dbb85bbf-2800-0000-7c31-0c7a6b150000 pid=5483 execve guuid=9b4966e6-1a00-0000-7c31-0c7a060c0000 pid=3078 /usr/bin/wget dns net send-data guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072->guuid=9b4966e6-1a00-0000-7c31-0c7a060c0000 pid=3078 execve guuid=b26ab2eb-1a00-0000-7c31-0c7a0f0c0000 pid=3087 /usr/bin/chmod guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072->guuid=b26ab2eb-1a00-0000-7c31-0c7a0f0c0000 pid=3087 execve guuid=90e3e7eb-1a00-0000-7c31-0c7a110c0000 pid=3089 /home/sandbox/..... guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072->guuid=90e3e7eb-1a00-0000-7c31-0c7a110c0000 pid=3089 execve guuid=74fa05ee-1a00-0000-7c31-0c7a180c0000 pid=3096 /usr/bin/rm delete-file guuid=83f911e6-1a00-0000-7c31-0c7a000c0000 pid=3072->guuid=74fa05ee-1a00-0000-7c31-0c7a180c0000 pid=3096 execve guuid=fccc35e6-1a00-0000-7c31-0c7a040c0000 pid=3076 /tmp/sample.bin net send-data zombie guuid=cb8b19e6-1a00-0000-7c31-0c7a020c0000 pid=3074->guuid=fccc35e6-1a00-0000-7c31-0c7a040c0000 pid=3076 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=fccc35e6-1a00-0000-7c31-0c7a040c0000 pid=3076->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 65B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9b4966e6-1a00-0000-7c31-0c7a060c0000 pid=3078->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=b6922919-1b00-0000-7c31-0c7a710c0000 pid=3185 /usr/bin/pgrep guuid=a01aef18-1b00-0000-7c31-0c7a700c0000 pid=3184->guuid=b6922919-1b00-0000-7c31-0c7a710c0000 pid=3185 execve guuid=d72e741c-1b00-0000-7c31-0c7a790c0000 pid=3193 /usr/bin/killall guuid=4ddb291c-1b00-0000-7c31-0c7a770c0000 pid=3191->guuid=d72e741c-1b00-0000-7c31-0c7a790c0000 pid=3193 execve guuid=767d9a1d-1b00-0000-7c31-0c7a7e0c0000 pid=3198 /usr/bin/killall guuid=a516691d-1b00-0000-7c31-0c7a7c0c0000 pid=3196->guuid=767d9a1d-1b00-0000-7c31-0c7a7e0c0000 pid=3198 execve guuid=7bb23d1f-1b00-0000-7c31-0c7a840c0000 pid=3204 /usr/bin/killall guuid=28c2f71e-1b00-0000-7c31-0c7a820c0000 pid=3202->guuid=7bb23d1f-1b00-0000-7c31-0c7a840c0000 pid=3204 execve guuid=40fe6e20-1b00-0000-7c31-0c7a8a0c0000 pid=3210 /usr/bin/killall guuid=73c62b20-1b00-0000-7c31-0c7a880c0000 pid=3208->guuid=40fe6e20-1b00-0000-7c31-0c7a8a0c0000 pid=3210 execve guuid=97d3c021-1b00-0000-7c31-0c7a8e0c0000 pid=3214 /usr/bin/killall guuid=c9439321-1b00-0000-7c31-0c7a8d0c0000 pid=3213->guuid=97d3c021-1b00-0000-7c31-0c7a8e0c0000 pid=3214 execve guuid=4b6d4723-1b00-0000-7c31-0c7a960c0000 pid=3222 /usr/bin/killall guuid=42bb0223-1b00-0000-7c31-0c7a940c0000 pid=3220->guuid=4b6d4723-1b00-0000-7c31-0c7a960c0000 pid=3222 execve guuid=7ae04c24-1b00-0000-7c31-0c7a990c0000 pid=3225 /usr/bin/killall guuid=e3981b24-1b00-0000-7c31-0c7a980c0000 pid=3224->guuid=7ae04c24-1b00-0000-7c31-0c7a990c0000 pid=3225 execve guuid=73754625-1b00-0000-7c31-0c7a9d0c0000 pid=3229 /usr/bin/killall guuid=b2761725-1b00-0000-7c31-0c7a9b0c0000 pid=3227->guuid=73754625-1b00-0000-7c31-0c7a9d0c0000 pid=3229 execve guuid=cd651153-1c00-0000-7c31-0c7a880f0000 pid=3976 /usr/bin/pgrep guuid=e183d852-1c00-0000-7c31-0c7a870f0000 pid=3975->guuid=cd651153-1c00-0000-7c31-0c7a880f0000 pid=3976 execve guuid=e9700156-1c00-0000-7c31-0c7a940f0000 pid=3988 /usr/bin/killall guuid=8b2acd55-1c00-0000-7c31-0c7a930f0000 pid=3987->guuid=e9700156-1c00-0000-7c31-0c7a940f0000 pid=3988 execve guuid=41d3ec56-1c00-0000-7c31-0c7a990f0000 pid=3993 /usr/bin/killall guuid=c077c356-1c00-0000-7c31-0c7a980f0000 pid=3992->guuid=41d3ec56-1c00-0000-7c31-0c7a990f0000 pid=3993 execve guuid=fa221a58-1c00-0000-7c31-0c7aa10f0000 pid=4001 /usr/bin/killall guuid=954ed557-1c00-0000-7c31-0c7aa00f0000 pid=4000->guuid=fa221a58-1c00-0000-7c31-0c7aa10f0000 pid=4001 execve guuid=30582459-1c00-0000-7c31-0c7aa90f0000 pid=4009 /usr/bin/killall guuid=6158fb58-1c00-0000-7c31-0c7aa70f0000 pid=4007->guuid=30582459-1c00-0000-7c31-0c7aa90f0000 pid=4009 execve guuid=57092b5a-1c00-0000-7c31-0c7aae0f0000 pid=4014 /usr/bin/killall guuid=19e2f659-1c00-0000-7c31-0c7aac0f0000 pid=4012->guuid=57092b5a-1c00-0000-7c31-0c7aae0f0000 pid=4014 execve guuid=fe21305b-1c00-0000-7c31-0c7ab40f0000 pid=4020 /usr/bin/killall guuid=4f86e15a-1c00-0000-7c31-0c7ab10f0000 pid=4017->guuid=fe21305b-1c00-0000-7c31-0c7ab40f0000 pid=4020 execve guuid=ef3c1d5c-1c00-0000-7c31-0c7aba0f0000 pid=4026 /usr/bin/killall guuid=d98eed5b-1c00-0000-7c31-0c7ab90f0000 pid=4025->guuid=ef3c1d5c-1c00-0000-7c31-0c7aba0f0000 pid=4026 execve guuid=f676885d-1c00-0000-7c31-0c7ac20f0000 pid=4034 /usr/bin/killall guuid=66e45c5d-1c00-0000-7c31-0c7ac10f0000 pid=4033->guuid=f676885d-1c00-0000-7c31-0c7ac20f0000 pid=4034 execve guuid=59f12f8c-1d00-0000-7c31-0c7aa4130000 pid=5028 /usr/bin/pgrep guuid=5193ef8b-1d00-0000-7c31-0c7aa2130000 pid=5026->guuid=59f12f8c-1d00-0000-7c31-0c7aa4130000 pid=5028 execve guuid=60a58d8f-1d00-0000-7c31-0c7ab1130000 pid=5041 /usr/bin/killall guuid=d7cf5a8f-1d00-0000-7c31-0c7aaf130000 pid=5039->guuid=60a58d8f-1d00-0000-7c31-0c7ab1130000 pid=5041 execve guuid=7732eb90-1d00-0000-7c31-0c7ab6130000 pid=5046 /usr/bin/killall guuid=f185ba90-1d00-0000-7c31-0c7ab5130000 pid=5045->guuid=7732eb90-1d00-0000-7c31-0c7ab6130000 pid=5046 execve guuid=f4f5ec91-1d00-0000-7c31-0c7abb130000 pid=5051 /usr/bin/killall guuid=708eb891-1d00-0000-7c31-0c7ab9130000 pid=5049->guuid=f4f5ec91-1d00-0000-7c31-0c7abb130000 pid=5051 execve guuid=2009ec92-1d00-0000-7c31-0c7ac0130000 pid=5056 /usr/bin/killall guuid=fa3aac92-1d00-0000-7c31-0c7abe130000 pid=5054->guuid=2009ec92-1d00-0000-7c31-0c7ac0130000 pid=5056 execve guuid=50bf8794-1d00-0000-7c31-0c7ac7130000 pid=5063 /usr/bin/killall guuid=47384394-1d00-0000-7c31-0c7ac5130000 pid=5061->guuid=50bf8794-1d00-0000-7c31-0c7ac7130000 pid=5063 execve guuid=422ca495-1d00-0000-7c31-0c7acc130000 pid=5068 /usr/bin/killall guuid=296a7695-1d00-0000-7c31-0c7acb130000 pid=5067->guuid=422ca495-1d00-0000-7c31-0c7acc130000 pid=5068 execve guuid=811ce896-1d00-0000-7c31-0c7ad1130000 pid=5073 /usr/bin/killall guuid=2592a696-1d00-0000-7c31-0c7ad0130000 pid=5072->guuid=811ce896-1d00-0000-7c31-0c7ad1130000 pid=5073 execve guuid=4ba24998-1d00-0000-7c31-0c7ad5130000 pid=5077 /usr/bin/killall guuid=5b810b98-1d00-0000-7c31-0c7ad4130000 pid=5076->guuid=4ba24998-1d00-0000-7c31-0c7ad5130000 pid=5077 execve guuid=fd183ec6-1e00-0000-7c31-0c7ab7140000 pid=5303 /usr/bin/pgrep guuid=fc6a0ac6-1e00-0000-7c31-0c7ab6140000 pid=5302->guuid=fd183ec6-1e00-0000-7c31-0c7ab7140000 pid=5303 execve guuid=622702c9-1e00-0000-7c31-0c7ab9140000 pid=5305 /usr/bin/killall guuid=d4f5d0c8-1e00-0000-7c31-0c7ab8140000 pid=5304->guuid=622702c9-1e00-0000-7c31-0c7ab9140000 pid=5305 execve guuid=3c34fdc9-1e00-0000-7c31-0c7abb140000 pid=5307 /usr/bin/killall guuid=a73ecac9-1e00-0000-7c31-0c7aba140000 pid=5306->guuid=3c34fdc9-1e00-0000-7c31-0c7abb140000 pid=5307 execve guuid=564b20cb-1e00-0000-7c31-0c7abd140000 pid=5309 /usr/bin/killall guuid=f655e8ca-1e00-0000-7c31-0c7abc140000 pid=5308->guuid=564b20cb-1e00-0000-7c31-0c7abd140000 pid=5309 execve guuid=1de50ccc-1e00-0000-7c31-0c7abf140000 pid=5311 /usr/bin/killall guuid=f1ccdccb-1e00-0000-7c31-0c7abe140000 pid=5310->guuid=1de50ccc-1e00-0000-7c31-0c7abf140000 pid=5311 execve guuid=6897eacc-1e00-0000-7c31-0c7ac1140000 pid=5313 /usr/bin/killall guuid=eeb5bbcc-1e00-0000-7c31-0c7ac0140000 pid=5312->guuid=6897eacc-1e00-0000-7c31-0c7ac1140000 pid=5313 execve guuid=9f22c6cd-1e00-0000-7c31-0c7ac3140000 pid=5315 /usr/bin/killall guuid=5d3892cd-1e00-0000-7c31-0c7ac2140000 pid=5314->guuid=9f22c6cd-1e00-0000-7c31-0c7ac3140000 pid=5315 execve guuid=6dc0a9ce-1e00-0000-7c31-0c7ac5140000 pid=5317 /usr/bin/killall guuid=f2ec77ce-1e00-0000-7c31-0c7ac4140000 pid=5316->guuid=6dc0a9ce-1e00-0000-7c31-0c7ac5140000 pid=5317 execve guuid=70def8cf-1e00-0000-7c31-0c7ac7140000 pid=5319 /usr/bin/killall guuid=31b6c6cf-1e00-0000-7c31-0c7ac6140000 pid=5318->guuid=70def8cf-1e00-0000-7c31-0c7ac7140000 pid=5319 execve guuid=0ead75ff-1f00-0000-7c31-0c7ad6140000 pid=5334 /usr/bin/pgrep guuid=888c24ff-1f00-0000-7c31-0c7ad5140000 pid=5333->guuid=0ead75ff-1f00-0000-7c31-0c7ad6140000 pid=5334 execve guuid=f2651303-2000-0000-7c31-0c7ade140000 pid=5342 /usr/bin/killall guuid=a126d902-2000-0000-7c31-0c7add140000 pid=5341->guuid=f2651303-2000-0000-7c31-0c7ade140000 pid=5342 execve guuid=a6e04e04-2000-0000-7c31-0c7ae1140000 pid=5345 /usr/bin/killall guuid=37c31304-2000-0000-7c31-0c7ae0140000 pid=5344->guuid=a6e04e04-2000-0000-7c31-0c7ae1140000 pid=5345 execve guuid=09b67f05-2000-0000-7c31-0c7ae3140000 pid=5347 /usr/bin/killall guuid=24014305-2000-0000-7c31-0c7ae2140000 pid=5346->guuid=09b67f05-2000-0000-7c31-0c7ae3140000 pid=5347 execve guuid=ac09b006-2000-0000-7c31-0c7ae5140000 pid=5349 /usr/bin/killall guuid=f1b16f06-2000-0000-7c31-0c7ae4140000 pid=5348->guuid=ac09b006-2000-0000-7c31-0c7ae5140000 pid=5349 execve guuid=8783d807-2000-0000-7c31-0c7ae7140000 pid=5351 /usr/bin/killall guuid=6ecc9807-2000-0000-7c31-0c7ae6140000 pid=5350->guuid=8783d807-2000-0000-7c31-0c7ae7140000 pid=5351 execve guuid=0e5ae608-2000-0000-7c31-0c7ae9140000 pid=5353 /usr/bin/killall guuid=5d2fae08-2000-0000-7c31-0c7ae8140000 pid=5352->guuid=0e5ae608-2000-0000-7c31-0c7ae9140000 pid=5353 execve guuid=4335280a-2000-0000-7c31-0c7aeb140000 pid=5355 /usr/bin/killall guuid=98d9ec09-2000-0000-7c31-0c7aea140000 pid=5354->guuid=4335280a-2000-0000-7c31-0c7aeb140000 pid=5355 execve guuid=d2e0310b-2000-0000-7c31-0c7aed140000 pid=5357 /usr/bin/killall guuid=92daf10a-2000-0000-7c31-0c7aec140000 pid=5356->guuid=d2e0310b-2000-0000-7c31-0c7aed140000 pid=5357 execve guuid=cda6d939-2100-0000-7c31-0c7aef140000 pid=5359 /usr/bin/pgrep guuid=98708739-2100-0000-7c31-0c7aee140000 pid=5358->guuid=cda6d939-2100-0000-7c31-0c7aef140000 pid=5359 execve guuid=a414dc3d-2100-0000-7c31-0c7af1140000 pid=5361 /usr/bin/killall guuid=9fe5a03d-2100-0000-7c31-0c7af0140000 pid=5360->guuid=a414dc3d-2100-0000-7c31-0c7af1140000 pid=5361 execve guuid=187ae23f-2100-0000-7c31-0c7af3140000 pid=5363 /usr/bin/killall guuid=6117993f-2100-0000-7c31-0c7af2140000 pid=5362->guuid=187ae23f-2100-0000-7c31-0c7af3140000 pid=5363 execve guuid=be0b9e41-2100-0000-7c31-0c7af5140000 pid=5365 /usr/bin/killall guuid=bc724241-2100-0000-7c31-0c7af4140000 pid=5364->guuid=be0b9e41-2100-0000-7c31-0c7af5140000 pid=5365 execve guuid=c8b23543-2100-0000-7c31-0c7af7140000 pid=5367 /usr/bin/killall guuid=ed7ae642-2100-0000-7c31-0c7af6140000 pid=5366->guuid=c8b23543-2100-0000-7c31-0c7af7140000 pid=5367 execve guuid=a4cc1d45-2100-0000-7c31-0c7af9140000 pid=5369 /usr/bin/killall guuid=14afc644-2100-0000-7c31-0c7af8140000 pid=5368->guuid=a4cc1d45-2100-0000-7c31-0c7af9140000 pid=5369 execve guuid=dce9c546-2100-0000-7c31-0c7afb140000 pid=5371 /usr/bin/killall guuid=58bc6a46-2100-0000-7c31-0c7afa140000 pid=5370->guuid=dce9c546-2100-0000-7c31-0c7afb140000 pid=5371 execve guuid=41a89248-2100-0000-7c31-0c7afd140000 pid=5373 /usr/bin/killall guuid=1e1a1048-2100-0000-7c31-0c7afc140000 pid=5372->guuid=41a89248-2100-0000-7c31-0c7afd140000 pid=5373 execve guuid=4ecf3b4a-2100-0000-7c31-0c7aff140000 pid=5375 /usr/bin/killall guuid=2390ed49-2100-0000-7c31-0c7afe140000 pid=5374->guuid=4ecf3b4a-2100-0000-7c31-0c7aff140000 pid=5375 execve guuid=8a72c779-2200-0000-7c31-0c7a01150000 pid=5377 /usr/bin/pgrep guuid=cfdd7e79-2200-0000-7c31-0c7a00150000 pid=5376->guuid=8a72c779-2200-0000-7c31-0c7a01150000 pid=5377 execve guuid=2961037d-2200-0000-7c31-0c7a03150000 pid=5379 /usr/bin/killall guuid=6241c67c-2200-0000-7c31-0c7a02150000 pid=5378->guuid=2961037d-2200-0000-7c31-0c7a03150000 pid=5379 execve guuid=fcbc2f7e-2200-0000-7c31-0c7a05150000 pid=5381 /usr/bin/killall guuid=c0dbf77d-2200-0000-7c31-0c7a04150000 pid=5380->guuid=fcbc2f7e-2200-0000-7c31-0c7a05150000 pid=5381 execve guuid=3824747f-2200-0000-7c31-0c7a07150000 pid=5383 /usr/bin/killall guuid=2faa207f-2200-0000-7c31-0c7a06150000 pid=5382->guuid=3824747f-2200-0000-7c31-0c7a07150000 pid=5383 execve guuid=8a88a380-2200-0000-7c31-0c7a09150000 pid=5385 /usr/bin/killall guuid=50e85880-2200-0000-7c31-0c7a08150000 pid=5384->guuid=8a88a380-2200-0000-7c31-0c7a09150000 pid=5385 execve guuid=2b9ec781-2200-0000-7c31-0c7a0b150000 pid=5387 /usr/bin/killall guuid=d0038581-2200-0000-7c31-0c7a0a150000 pid=5386->guuid=2b9ec781-2200-0000-7c31-0c7a0b150000 pid=5387 execve guuid=5139e682-2200-0000-7c31-0c7a0d150000 pid=5389 /usr/bin/killall guuid=5a07ab82-2200-0000-7c31-0c7a0c150000 pid=5388->guuid=5139e682-2200-0000-7c31-0c7a0d150000 pid=5389 execve guuid=9f4d6684-2200-0000-7c31-0c7a0f150000 pid=5391 /usr/bin/killall guuid=3db22b84-2200-0000-7c31-0c7a0e150000 pid=5390->guuid=9f4d6684-2200-0000-7c31-0c7a0f150000 pid=5391 execve guuid=7f3ae985-2200-0000-7c31-0c7a11150000 pid=5393 /usr/bin/killall guuid=2fa3ac85-2200-0000-7c31-0c7a10150000 pid=5392->guuid=7f3ae985-2200-0000-7c31-0c7a11150000 pid=5393 execve guuid=28dc33b5-2300-0000-7c31-0c7a13150000 pid=5395 /usr/bin/pgrep guuid=0b87edb4-2300-0000-7c31-0c7a12150000 pid=5394->guuid=28dc33b5-2300-0000-7c31-0c7a13150000 pid=5395 execve guuid=9ed1b4b9-2300-0000-7c31-0c7a15150000 pid=5397 /usr/bin/killall guuid=045e6ab9-2300-0000-7c31-0c7a14150000 pid=5396->guuid=9ed1b4b9-2300-0000-7c31-0c7a15150000 pid=5397 execve guuid=df8cb7ba-2300-0000-7c31-0c7a17150000 pid=5399 /usr/bin/killall guuid=f62971ba-2300-0000-7c31-0c7a16150000 pid=5398->guuid=df8cb7ba-2300-0000-7c31-0c7a17150000 pid=5399 execve guuid=7b00adbb-2300-0000-7c31-0c7a19150000 pid=5401 /usr/bin/killall guuid=81b877bb-2300-0000-7c31-0c7a18150000 pid=5400->guuid=7b00adbb-2300-0000-7c31-0c7a19150000 pid=5401 execve guuid=43c9fbbc-2300-0000-7c31-0c7a1b150000 pid=5403 /usr/bin/killall guuid=9b84babc-2300-0000-7c31-0c7a1a150000 pid=5402->guuid=43c9fbbc-2300-0000-7c31-0c7a1b150000 pid=5403 execve guuid=ee5f38be-2300-0000-7c31-0c7a1d150000 pid=5405 /usr/bin/killall guuid=a6d2f6bd-2300-0000-7c31-0c7a1c150000 pid=5404->guuid=ee5f38be-2300-0000-7c31-0c7a1d150000 pid=5405 execve guuid=9d9e8cbf-2300-0000-7c31-0c7a1f150000 pid=5407 /usr/bin/killall guuid=dd4333bf-2300-0000-7c31-0c7a1e150000 pid=5406->guuid=9d9e8cbf-2300-0000-7c31-0c7a1f150000 pid=5407 execve guuid=30aec5c0-2300-0000-7c31-0c7a21150000 pid=5409 /usr/bin/killall guuid=824785c0-2300-0000-7c31-0c7a20150000 pid=5408->guuid=30aec5c0-2300-0000-7c31-0c7a21150000 pid=5409 execve guuid=5e591cc2-2300-0000-7c31-0c7a23150000 pid=5411 /usr/bin/killall guuid=aaabd5c1-2300-0000-7c31-0c7a22150000 pid=5410->guuid=5e591cc2-2300-0000-7c31-0c7a23150000 pid=5411 execve guuid=c65ffbf1-2400-0000-7c31-0c7a25150000 pid=5413 /usr/bin/pgrep guuid=1ca38ff1-2400-0000-7c31-0c7a24150000 pid=5412->guuid=c65ffbf1-2400-0000-7c31-0c7a25150000 pid=5413 execve guuid=e91466f6-2400-0000-7c31-0c7a27150000 pid=5415 /usr/bin/killall guuid=752e2cf6-2400-0000-7c31-0c7a26150000 pid=5414->guuid=e91466f6-2400-0000-7c31-0c7a27150000 pid=5415 execve guuid=5901aaf7-2400-0000-7c31-0c7a29150000 pid=5417 /usr/bin/killall guuid=dab83cf7-2400-0000-7c31-0c7a28150000 pid=5416->guuid=5901aaf7-2400-0000-7c31-0c7a29150000 pid=5417 execve guuid=198e43f9-2400-0000-7c31-0c7a2b150000 pid=5419 /usr/bin/killall guuid=7e21ebf8-2400-0000-7c31-0c7a2a150000 pid=5418->guuid=198e43f9-2400-0000-7c31-0c7a2b150000 pid=5419 execve guuid=f50df5fa-2400-0000-7c31-0c7a2d150000 pid=5421 /usr/bin/killall guuid=35bdbafa-2400-0000-7c31-0c7a2c150000 pid=5420->guuid=f50df5fa-2400-0000-7c31-0c7a2d150000 pid=5421 execve guuid=d3a03efc-2400-0000-7c31-0c7a2f150000 pid=5423 /usr/bin/killall guuid=7424dffb-2400-0000-7c31-0c7a2e150000 pid=5422->guuid=d3a03efc-2400-0000-7c31-0c7a2f150000 pid=5423 execve guuid=35bb2ffd-2400-0000-7c31-0c7a31150000 pid=5425 /usr/bin/killall guuid=aaa8effc-2400-0000-7c31-0c7a30150000 pid=5424->guuid=35bb2ffd-2400-0000-7c31-0c7a31150000 pid=5425 execve guuid=c7292bfe-2400-0000-7c31-0c7a33150000 pid=5427 /usr/bin/killall guuid=251fe8fd-2400-0000-7c31-0c7a32150000 pid=5426->guuid=c7292bfe-2400-0000-7c31-0c7a33150000 pid=5427 execve guuid=214c27ff-2400-0000-7c31-0c7a35150000 pid=5429 /usr/bin/killall guuid=9decebfe-2400-0000-7c31-0c7a34150000 pid=5428->guuid=214c27ff-2400-0000-7c31-0c7a35150000 pid=5429 execve guuid=383ac32e-2600-0000-7c31-0c7a37150000 pid=5431 /usr/bin/pgrep guuid=2a585f2e-2600-0000-7c31-0c7a36150000 pid=5430->guuid=383ac32e-2600-0000-7c31-0c7a37150000 pid=5431 execve guuid=32c59e33-2600-0000-7c31-0c7a39150000 pid=5433 /usr/bin/killall guuid=c8c25e33-2600-0000-7c31-0c7a38150000 pid=5432->guuid=32c59e33-2600-0000-7c31-0c7a39150000 pid=5433 execve guuid=8c3f2b36-2600-0000-7c31-0c7a3b150000 pid=5435 /usr/bin/killall guuid=c4fee635-2600-0000-7c31-0c7a3a150000 pid=5434->guuid=8c3f2b36-2600-0000-7c31-0c7a3b150000 pid=5435 execve guuid=e12deb38-2600-0000-7c31-0c7a3d150000 pid=5437 /usr/bin/killall guuid=ac655538-2600-0000-7c31-0c7a3c150000 pid=5436->guuid=e12deb38-2600-0000-7c31-0c7a3d150000 pid=5437 execve guuid=f479cf3a-2600-0000-7c31-0c7a3f150000 pid=5439 /usr/bin/killall guuid=6c6d6e3a-2600-0000-7c31-0c7a3e150000 pid=5438->guuid=f479cf3a-2600-0000-7c31-0c7a3f150000 pid=5439 execve guuid=fbbffb3c-2600-0000-7c31-0c7a41150000 pid=5441 /usr/bin/killall guuid=2f55a43c-2600-0000-7c31-0c7a40150000 pid=5440->guuid=fbbffb3c-2600-0000-7c31-0c7a41150000 pid=5441 execve guuid=5761303f-2600-0000-7c31-0c7a43150000 pid=5443 /usr/bin/killall guuid=1408d63e-2600-0000-7c31-0c7a42150000 pid=5442->guuid=5761303f-2600-0000-7c31-0c7a43150000 pid=5443 execve guuid=e6d37641-2600-0000-7c31-0c7a45150000 pid=5445 /usr/bin/killall guuid=b1dd2f41-2600-0000-7c31-0c7a44150000 pid=5444->guuid=e6d37641-2600-0000-7c31-0c7a45150000 pid=5445 execve guuid=67fba643-2600-0000-7c31-0c7a47150000 pid=5447 /usr/bin/killall guuid=574a4443-2600-0000-7c31-0c7a46150000 pid=5446->guuid=67fba643-2600-0000-7c31-0c7a47150000 pid=5447 execve guuid=0910b471-2700-0000-7c31-0c7a49150000 pid=5449 /usr/bin/pgrep guuid=62608571-2700-0000-7c31-0c7a48150000 pid=5448->guuid=0910b471-2700-0000-7c31-0c7a49150000 pid=5449 execve guuid=12c55d76-2700-0000-7c31-0c7a4b150000 pid=5451 /usr/bin/killall guuid=67982d76-2700-0000-7c31-0c7a4a150000 pid=5450->guuid=12c55d76-2700-0000-7c31-0c7a4b150000 pid=5451 execve guuid=ea68d177-2700-0000-7c31-0c7a4d150000 pid=5453 /usr/bin/killall guuid=3c6a7577-2700-0000-7c31-0c7a4c150000 pid=5452->guuid=ea68d177-2700-0000-7c31-0c7a4d150000 pid=5453 execve guuid=e69f8379-2700-0000-7c31-0c7a4f150000 pid=5455 /usr/bin/killall guuid=88851e79-2700-0000-7c31-0c7a4e150000 pid=5454->guuid=e69f8379-2700-0000-7c31-0c7a4f150000 pid=5455 execve guuid=adf8647b-2700-0000-7c31-0c7a51150000 pid=5457 /usr/bin/killall guuid=a316127b-2700-0000-7c31-0c7a50150000 pid=5456->guuid=adf8647b-2700-0000-7c31-0c7a51150000 pid=5457 execve guuid=2a9c2e7d-2700-0000-7c31-0c7a53150000 pid=5459 /usr/bin/killall guuid=11b5d87c-2700-0000-7c31-0c7a52150000 pid=5458->guuid=2a9c2e7d-2700-0000-7c31-0c7a53150000 pid=5459 execve guuid=8b90167f-2700-0000-7c31-0c7a55150000 pid=5461 /usr/bin/killall guuid=f5fbb27e-2700-0000-7c31-0c7a54150000 pid=5460->guuid=8b90167f-2700-0000-7c31-0c7a55150000 pid=5461 execve guuid=2cced780-2700-0000-7c31-0c7a57150000 pid=5463 /usr/bin/killall guuid=900a7d80-2700-0000-7c31-0c7a56150000 pid=5462->guuid=2cced780-2700-0000-7c31-0c7a57150000 pid=5463 execve guuid=e8459182-2700-0000-7c31-0c7a59150000 pid=5465 /usr/bin/killall guuid=fba73082-2700-0000-7c31-0c7a58150000 pid=5464->guuid=e8459182-2700-0000-7c31-0c7a59150000 pid=5465 execve guuid=d35a87b2-2800-0000-7c31-0c7a5b150000 pid=5467 /usr/bin/pgrep guuid=bb883eb2-2800-0000-7c31-0c7a5a150000 pid=5466->guuid=d35a87b2-2800-0000-7c31-0c7a5b150000 pid=5467 execve guuid=d96f41b6-2800-0000-7c31-0c7a5d150000 pid=5469 /usr/bin/killall guuid=2e950fb6-2800-0000-7c31-0c7a5c150000 pid=5468->guuid=d96f41b6-2800-0000-7c31-0c7a5d150000 pid=5469 execve guuid=6f219fb7-2800-0000-7c31-0c7a5f150000 pid=5471 /usr/bin/killall guuid=1de75cb7-2800-0000-7c31-0c7a5e150000 pid=5470->guuid=6f219fb7-2800-0000-7c31-0c7a5f150000 pid=5471 execve guuid=abde11b9-2800-0000-7c31-0c7a61150000 pid=5473 /usr/bin/killall guuid=eb4cbeb8-2800-0000-7c31-0c7a60150000 pid=5472->guuid=abde11b9-2800-0000-7c31-0c7a61150000 pid=5473 execve guuid=1b7c7bba-2800-0000-7c31-0c7a63150000 pid=5475 /usr/bin/killall guuid=eeae24ba-2800-0000-7c31-0c7a62150000 pid=5474->guuid=1b7c7bba-2800-0000-7c31-0c7a63150000 pid=5475 execve guuid=83ceedbb-2800-0000-7c31-0c7a65150000 pid=5477 /usr/bin/killall guuid=846d96bb-2800-0000-7c31-0c7a64150000 pid=5476->guuid=83ceedbb-2800-0000-7c31-0c7a65150000 pid=5477 execve guuid=092c5abd-2800-0000-7c31-0c7a67150000 pid=5479 /usr/bin/killall guuid=b79c02bd-2800-0000-7c31-0c7a66150000 pid=5478->guuid=092c5abd-2800-0000-7c31-0c7a67150000 pid=5479 execve guuid=83a0b0be-2800-0000-7c31-0c7a6a150000 pid=5482 /usr/bin/killall guuid=57b165be-2800-0000-7c31-0c7a68150000 pid=5480->guuid=83a0b0be-2800-0000-7c31-0c7a6a150000 pid=5482 execve guuid=1f0e84bf-2800-0000-7c31-0c7a6c150000 pid=5484 /usr/bin/killall guuid=dbb85bbf-2800-0000-7c31-0c7a6b150000 pid=5483->guuid=1f0e84bf-2800-0000-7c31-0c7a6c150000 pid=5484 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample tries to kill multiple processes (SIGKILL)
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1729126 Sample: cron.elf Startdate: 05/07/2025 Architecture: LINUX Score: 100 38 206.123.128.67, 47102, 47104, 47106 LEASEWEB-USA-NYC-11US United States 2->38 40 gay.energy 2->40 42 daisy.ubuntu.com 2->42 44 Suricata IDS alerts for network traffic 2->44 46 Malicious sample detected (through community Yara rule) 2->46 48 Antivirus / Scanner detection for submitted sample 2->48 50 5 other signatures 2->50 9 cron.elf 2->9         started        signatures3 process4 signatures5 54 Opens /proc/net/* files useful for finding connected devices and routers 9->54 12 cron.elf 9->12         started        process6 signatures7 56 Sample tries to kill multiple processes (SIGKILL) 12->56 15 cron.elf sh 12->15         started        17 cron.elf sh 12->17         started        19 cron.elf sh 12->19         started        21 59 other processes 12->21 process8 process9 23 sh killall 15->23         started        26 sh killall 17->26         started        28 sh killall 19->28         started        30 sh killall 21->30         started        32 sh killall 21->32         started        34 sh killall 21->34         started        36 56 other processes 21->36 signatures10 52 Terminates several processes with shell command 'killall' 23->52
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-05 09:57:46 UTC
File Type:
ELF32 Little (Exe)
AV detection:
18 of 24 (75.00%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_83715433 Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_f51c5ac3 Linux_Trojan_Gafgyt_27de1106 Linux_Trojan_Gafgyt_1b2e2a3a Linux_Trojan_Gafgyt_9127f7be Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_1b2e2a3a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_27de1106
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_83715433
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9127f7be
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f51c5ac3
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 2f3304c7200d6bd5b4c4131a3eb8e4021fc56b6feefea3bf403a2304e96ee938

(this sample)

  
Delivery method
Distributed via web download

Comments