MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 30cd1987c91bee55bafc93ad6ccb54874d86d3e35604c404a855c3ade7504f24. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 30cd1987c91bee55bafc93ad6ccb54874d86d3e35604c404a855c3ade7504f24
SHA3-384 hash: 1d8a81817ba009f826bef7bf646bdd953371680b2cec6f9a51e76561eb5f3f2f640083ef893a61a8160f4be440df6a73
SHA1 hash: 02481e4caa84793ef870bbc0a1b7757c604e2c0f
MD5 hash: 7765e75c6d18ad60dd3d3b2db8e52e96
humanhash: artist-aspen-jersey-freddie
File name:all.sh
Download: download sample
Signature Mirai
File size:556 bytes
First seen:2025-07-26 11:24:47 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:YkF1kcClZF70SSHFkHF7HFMU6FSjKMFMDgFnA1LRPb:ZDkH/FbSHFkHF7HFMU6F27FMDgFneD
TLSH T1F3F0C2E5363111B0BAEB9DF606730C887090E0073E829EBCF965A0DA8494C04E0865AF
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.187.246.23/huhu/titanjr.n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=b25af8c1-1700-0000-8a4d-c57d5a0b0000 pid=2906 /usr/bin/sudo guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908 /tmp/sample.bin zombie guuid=b25af8c1-1700-0000-8a4d-c57d5a0b0000 pid=2906->guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908 execve guuid=84511bc5-1700-0000-8a4d-c57d5f0b0000 pid=2911 /usr/bin/wget net send-data write-file guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=84511bc5-1700-0000-8a4d-c57d5f0b0000 pid=2911 execve guuid=c3cb69fc-1700-0000-8a4d-c57ded0b0000 pid=3053 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=c3cb69fc-1700-0000-8a4d-c57ded0b0000 pid=3053 execve guuid=77f1acfc-1700-0000-8a4d-c57def0b0000 pid=3055 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=77f1acfc-1700-0000-8a4d-c57def0b0000 pid=3055 execve guuid=2c7bd3fc-1700-0000-8a4d-c57df20b0000 pid=3058 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=2c7bd3fc-1700-0000-8a4d-c57df20b0000 pid=3058 execve guuid=f285b2fd-1700-0000-8a4d-c57df60b0000 pid=3062 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f285b2fd-1700-0000-8a4d-c57df60b0000 pid=3062 execve guuid=fa8d7003-1800-0000-8a4d-c57d0b0c0000 pid=3083 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=fa8d7003-1800-0000-8a4d-c57d0b0c0000 pid=3083 execve guuid=c54cab2a-1800-0000-8a4d-c57d5f0c0000 pid=3167 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=c54cab2a-1800-0000-8a4d-c57d5f0c0000 pid=3167 clone guuid=1dadd62a-1800-0000-8a4d-c57d610c0000 pid=3169 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=1dadd62a-1800-0000-8a4d-c57d610c0000 pid=3169 clone guuid=0391062b-1800-0000-8a4d-c57d620c0000 pid=3170 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0391062b-1800-0000-8a4d-c57d620c0000 pid=3170 clone guuid=e222332b-1800-0000-8a4d-c57d630c0000 pid=3171 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=e222332b-1800-0000-8a4d-c57d630c0000 pid=3171 execve guuid=e09cab2b-1800-0000-8a4d-c57d650c0000 pid=3173 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=e09cab2b-1800-0000-8a4d-c57d650c0000 pid=3173 execve guuid=295cf02b-1800-0000-8a4d-c57d680c0000 pid=3176 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=295cf02b-1800-0000-8a4d-c57d680c0000 pid=3176 execve guuid=3ff7f12d-1800-0000-8a4d-c57d6c0c0000 pid=3180 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3ff7f12d-1800-0000-8a4d-c57d6c0c0000 pid=3180 execve guuid=11a6c931-1800-0000-8a4d-c57d750c0000 pid=3189 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=11a6c931-1800-0000-8a4d-c57d750c0000 pid=3189 execve guuid=73085d3a-1800-0000-8a4d-c57d790c0000 pid=3193 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=73085d3a-1800-0000-8a4d-c57d790c0000 pid=3193 clone guuid=f1ca8b3a-1800-0000-8a4d-c57d7a0c0000 pid=3194 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f1ca8b3a-1800-0000-8a4d-c57d7a0c0000 pid=3194 clone guuid=8d46a33a-1800-0000-8a4d-c57d7b0c0000 pid=3195 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=8d46a33a-1800-0000-8a4d-c57d7b0c0000 pid=3195 clone guuid=a018b93a-1800-0000-8a4d-c57d7c0c0000 pid=3196 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a018b93a-1800-0000-8a4d-c57d7c0c0000 pid=3196 execve guuid=58f8243b-1800-0000-8a4d-c57d7d0c0000 pid=3197 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=58f8243b-1800-0000-8a4d-c57d7d0c0000 pid=3197 execve guuid=86bfa53b-1800-0000-8a4d-c57d800c0000 pid=3200 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=86bfa53b-1800-0000-8a4d-c57d800c0000 pid=3200 execve guuid=23391a3d-1800-0000-8a4d-c57d810c0000 pid=3201 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=23391a3d-1800-0000-8a4d-c57d810c0000 pid=3201 execve guuid=794af13f-1800-0000-8a4d-c57d820c0000 pid=3202 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=794af13f-1800-0000-8a4d-c57d820c0000 pid=3202 execve guuid=ba75e359-1800-0000-8a4d-c57da70c0000 pid=3239 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=ba75e359-1800-0000-8a4d-c57da70c0000 pid=3239 clone guuid=02931c5a-1800-0000-8a4d-c57da80c0000 pid=3240 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=02931c5a-1800-0000-8a4d-c57da80c0000 pid=3240 clone guuid=0a834e5a-1800-0000-8a4d-c57da90c0000 pid=3241 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0a834e5a-1800-0000-8a4d-c57da90c0000 pid=3241 clone guuid=e86cd85a-1800-0000-8a4d-c57daa0c0000 pid=3242 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=e86cd85a-1800-0000-8a4d-c57daa0c0000 pid=3242 execve guuid=058f465b-1800-0000-8a4d-c57dab0c0000 pid=3243 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=058f465b-1800-0000-8a4d-c57dab0c0000 pid=3243 execve guuid=f49c785b-1800-0000-8a4d-c57dad0c0000 pid=3245 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f49c785b-1800-0000-8a4d-c57dad0c0000 pid=3245 execve guuid=1a82145d-1800-0000-8a4d-c57daf0c0000 pid=3247 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=1a82145d-1800-0000-8a4d-c57daf0c0000 pid=3247 execve guuid=90230861-1800-0000-8a4d-c57db00c0000 pid=3248 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=90230861-1800-0000-8a4d-c57db00c0000 pid=3248 execve guuid=3acabe68-1800-0000-8a4d-c57dc20c0000 pid=3266 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3acabe68-1800-0000-8a4d-c57dc20c0000 pid=3266 clone guuid=8294d968-1800-0000-8a4d-c57dc40c0000 pid=3268 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=8294d968-1800-0000-8a4d-c57dc40c0000 pid=3268 clone guuid=7e8eec68-1800-0000-8a4d-c57dc50c0000 pid=3269 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=7e8eec68-1800-0000-8a4d-c57dc50c0000 pid=3269 clone guuid=18360369-1800-0000-8a4d-c57dc70c0000 pid=3271 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=18360369-1800-0000-8a4d-c57dc70c0000 pid=3271 execve guuid=e2d93769-1800-0000-8a4d-c57dc80c0000 pid=3272 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=e2d93769-1800-0000-8a4d-c57dc80c0000 pid=3272 execve guuid=daa15569-1800-0000-8a4d-c57dca0c0000 pid=3274 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=daa15569-1800-0000-8a4d-c57dca0c0000 pid=3274 execve guuid=a8392c6b-1800-0000-8a4d-c57dcd0c0000 pid=3277 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a8392c6b-1800-0000-8a4d-c57dcd0c0000 pid=3277 execve guuid=61b3a36d-1800-0000-8a4d-c57dd40c0000 pid=3284 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=61b3a36d-1800-0000-8a4d-c57dd40c0000 pid=3284 execve guuid=5b685d88-1800-0000-8a4d-c57df20c0000 pid=3314 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=5b685d88-1800-0000-8a4d-c57df20c0000 pid=3314 clone guuid=fcf28a88-1800-0000-8a4d-c57df30c0000 pid=3315 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=fcf28a88-1800-0000-8a4d-c57df30c0000 pid=3315 clone guuid=5da2b288-1800-0000-8a4d-c57df40c0000 pid=3316 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=5da2b288-1800-0000-8a4d-c57df40c0000 pid=3316 clone guuid=d24edf88-1800-0000-8a4d-c57df60c0000 pid=3318 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=d24edf88-1800-0000-8a4d-c57df60c0000 pid=3318 execve guuid=c7196089-1800-0000-8a4d-c57df80c0000 pid=3320 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=c7196089-1800-0000-8a4d-c57df80c0000 pid=3320 execve guuid=a7d8b089-1800-0000-8a4d-c57dfb0c0000 pid=3323 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a7d8b089-1800-0000-8a4d-c57dfb0c0000 pid=3323 execve guuid=4587518c-1800-0000-8a4d-c57d050d0000 pid=3333 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=4587518c-1800-0000-8a4d-c57d050d0000 pid=3333 execve guuid=9d690c90-1800-0000-8a4d-c57d120d0000 pid=3346 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=9d690c90-1800-0000-8a4d-c57d120d0000 pid=3346 execve guuid=4688eb94-1800-0000-8a4d-c57d240d0000 pid=3364 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=4688eb94-1800-0000-8a4d-c57d240d0000 pid=3364 clone guuid=412c0495-1800-0000-8a4d-c57d250d0000 pid=3365 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=412c0495-1800-0000-8a4d-c57d250d0000 pid=3365 clone guuid=c9552695-1800-0000-8a4d-c57d270d0000 pid=3367 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=c9552695-1800-0000-8a4d-c57d270d0000 pid=3367 clone guuid=38f63895-1800-0000-8a4d-c57d280d0000 pid=3368 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=38f63895-1800-0000-8a4d-c57d280d0000 pid=3368 execve guuid=3dcb8495-1800-0000-8a4d-c57d2a0d0000 pid=3370 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3dcb8495-1800-0000-8a4d-c57d2a0d0000 pid=3370 execve guuid=5ca1a595-1800-0000-8a4d-c57d2d0d0000 pid=3373 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=5ca1a595-1800-0000-8a4d-c57d2d0d0000 pid=3373 execve guuid=a6e5d596-1800-0000-8a4d-c57d2f0d0000 pid=3375 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a6e5d596-1800-0000-8a4d-c57d2f0d0000 pid=3375 execve guuid=d2de819a-1800-0000-8a4d-c57d3d0d0000 pid=3389 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=d2de819a-1800-0000-8a4d-c57d3d0d0000 pid=3389 execve guuid=56ad84b6-1800-0000-8a4d-c57d660d0000 pid=3430 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=56ad84b6-1800-0000-8a4d-c57d660d0000 pid=3430 clone guuid=f98fa6b6-1800-0000-8a4d-c57d670d0000 pid=3431 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f98fa6b6-1800-0000-8a4d-c57d670d0000 pid=3431 clone guuid=1d4ac9b6-1800-0000-8a4d-c57d680d0000 pid=3432 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=1d4ac9b6-1800-0000-8a4d-c57d680d0000 pid=3432 clone guuid=15dbf1b6-1800-0000-8a4d-c57d690d0000 pid=3433 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=15dbf1b6-1800-0000-8a4d-c57d690d0000 pid=3433 execve guuid=0ae962b7-1800-0000-8a4d-c57d6b0d0000 pid=3435 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0ae962b7-1800-0000-8a4d-c57d6b0d0000 pid=3435 execve guuid=f3e6b3b7-1800-0000-8a4d-c57d6f0d0000 pid=3439 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f3e6b3b7-1800-0000-8a4d-c57d6f0d0000 pid=3439 execve guuid=36cffcb8-1800-0000-8a4d-c57d720d0000 pid=3442 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=36cffcb8-1800-0000-8a4d-c57d720d0000 pid=3442 execve guuid=5bf2e2bb-1800-0000-8a4d-c57d7b0d0000 pid=3451 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=5bf2e2bb-1800-0000-8a4d-c57d7b0d0000 pid=3451 execve guuid=19e66dc2-1800-0000-8a4d-c57d990d0000 pid=3481 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=19e66dc2-1800-0000-8a4d-c57d990d0000 pid=3481 clone guuid=f5f688c2-1800-0000-8a4d-c57d9a0d0000 pid=3482 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f5f688c2-1800-0000-8a4d-c57d9a0d0000 pid=3482 clone guuid=54eda0c2-1800-0000-8a4d-c57d9c0d0000 pid=3484 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=54eda0c2-1800-0000-8a4d-c57d9c0d0000 pid=3484 clone guuid=305bb2c2-1800-0000-8a4d-c57d9d0d0000 pid=3485 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=305bb2c2-1800-0000-8a4d-c57d9d0d0000 pid=3485 execve guuid=82cdedc2-1800-0000-8a4d-c57d9f0d0000 pid=3487 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=82cdedc2-1800-0000-8a4d-c57d9f0d0000 pid=3487 execve guuid=a92d0cc3-1800-0000-8a4d-c57da10d0000 pid=3489 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a92d0cc3-1800-0000-8a4d-c57da10d0000 pid=3489 execve guuid=8c28ebc3-1800-0000-8a4d-c57da70d0000 pid=3495 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=8c28ebc3-1800-0000-8a4d-c57da70d0000 pid=3495 execve guuid=484a91c6-1800-0000-8a4d-c57db10d0000 pid=3505 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=484a91c6-1800-0000-8a4d-c57db10d0000 pid=3505 execve guuid=0ba8d5e0-1800-0000-8a4d-c57df50d0000 pid=3573 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0ba8d5e0-1800-0000-8a4d-c57df50d0000 pid=3573 clone guuid=a41f04e1-1800-0000-8a4d-c57df60d0000 pid=3574 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a41f04e1-1800-0000-8a4d-c57df60d0000 pid=3574 clone guuid=89b42ee1-1800-0000-8a4d-c57df80d0000 pid=3576 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=89b42ee1-1800-0000-8a4d-c57df80d0000 pid=3576 clone guuid=78c655e1-1800-0000-8a4d-c57df90d0000 pid=3577 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=78c655e1-1800-0000-8a4d-c57df90d0000 pid=3577 execve guuid=03f5e4e1-1800-0000-8a4d-c57dfb0d0000 pid=3579 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=03f5e4e1-1800-0000-8a4d-c57dfb0d0000 pid=3579 execve guuid=a13e33e2-1800-0000-8a4d-c57dff0d0000 pid=3583 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a13e33e2-1800-0000-8a4d-c57dff0d0000 pid=3583 execve guuid=0cde9ae3-1800-0000-8a4d-c57d030e0000 pid=3587 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0cde9ae3-1800-0000-8a4d-c57d030e0000 pid=3587 execve guuid=3b6b70e5-1800-0000-8a4d-c57d0a0e0000 pid=3594 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3b6b70e5-1800-0000-8a4d-c57d0a0e0000 pid=3594 execve guuid=89673eed-1800-0000-8a4d-c57d1e0e0000 pid=3614 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=89673eed-1800-0000-8a4d-c57d1e0e0000 pid=3614 clone guuid=fc9c51ed-1800-0000-8a4d-c57d200e0000 pid=3616 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=fc9c51ed-1800-0000-8a4d-c57d200e0000 pid=3616 clone guuid=d07e62ed-1800-0000-8a4d-c57d210e0000 pid=3617 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=d07e62ed-1800-0000-8a4d-c57d210e0000 pid=3617 clone guuid=57117ced-1800-0000-8a4d-c57d220e0000 pid=3618 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=57117ced-1800-0000-8a4d-c57d220e0000 pid=3618 execve guuid=0b32bded-1800-0000-8a4d-c57d240e0000 pid=3620 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0b32bded-1800-0000-8a4d-c57d240e0000 pid=3620 execve guuid=495914ee-1800-0000-8a4d-c57d290e0000 pid=3625 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=495914ee-1800-0000-8a4d-c57d290e0000 pid=3625 execve guuid=fec0e7ee-1800-0000-8a4d-c57d2b0e0000 pid=3627 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=fec0e7ee-1800-0000-8a4d-c57d2b0e0000 pid=3627 execve guuid=01090ff1-1800-0000-8a4d-c57d320e0000 pid=3634 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=01090ff1-1800-0000-8a4d-c57d320e0000 pid=3634 execve guuid=3da54c0b-1900-0000-8a4d-c57d560e0000 pid=3670 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3da54c0b-1900-0000-8a4d-c57d560e0000 pid=3670 clone guuid=f400720b-1900-0000-8a4d-c57d570e0000 pid=3671 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=f400720b-1900-0000-8a4d-c57d570e0000 pid=3671 clone guuid=ecb29f0b-1900-0000-8a4d-c57d590e0000 pid=3673 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=ecb29f0b-1900-0000-8a4d-c57d590e0000 pid=3673 clone guuid=d8f2bf0b-1900-0000-8a4d-c57d5a0e0000 pid=3674 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=d8f2bf0b-1900-0000-8a4d-c57d5a0e0000 pid=3674 execve guuid=c68b540c-1900-0000-8a4d-c57d5c0e0000 pid=3676 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=c68b540c-1900-0000-8a4d-c57d5c0e0000 pid=3676 execve guuid=d0a9b70c-1900-0000-8a4d-c57d600e0000 pid=3680 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=d0a9b70c-1900-0000-8a4d-c57d600e0000 pid=3680 execve guuid=902d130e-1900-0000-8a4d-c57d620e0000 pid=3682 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=902d130e-1900-0000-8a4d-c57d620e0000 pid=3682 execve guuid=56605012-1900-0000-8a4d-c57d6f0e0000 pid=3695 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=56605012-1900-0000-8a4d-c57d6f0e0000 pid=3695 execve guuid=674fa318-1900-0000-8a4d-c57d890e0000 pid=3721 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=674fa318-1900-0000-8a4d-c57d890e0000 pid=3721 clone guuid=3aeabc18-1900-0000-8a4d-c57d8a0e0000 pid=3722 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3aeabc18-1900-0000-8a4d-c57d8a0e0000 pid=3722 clone guuid=8548d018-1900-0000-8a4d-c57d8b0e0000 pid=3723 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=8548d018-1900-0000-8a4d-c57d8b0e0000 pid=3723 clone guuid=8a7be318-1900-0000-8a4d-c57d8c0e0000 pid=3724 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=8a7be318-1900-0000-8a4d-c57d8c0e0000 pid=3724 execve guuid=a4fc1d19-1900-0000-8a4d-c57d8e0e0000 pid=3726 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=a4fc1d19-1900-0000-8a4d-c57d8e0e0000 pid=3726 execve guuid=9aa03d19-1900-0000-8a4d-c57d910e0000 pid=3729 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=9aa03d19-1900-0000-8a4d-c57d910e0000 pid=3729 execve guuid=4d81271a-1900-0000-8a4d-c57d960e0000 pid=3734 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=4d81271a-1900-0000-8a4d-c57d960e0000 pid=3734 execve guuid=26a5261c-1900-0000-8a4d-c57d9f0e0000 pid=3743 /usr/bin/busybox net send-data guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=26a5261c-1900-0000-8a4d-c57d9f0e0000 pid=3743 execve guuid=b5967d36-1900-0000-8a4d-c57ddb0e0000 pid=3803 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=b5967d36-1900-0000-8a4d-c57ddb0e0000 pid=3803 clone guuid=6edba536-1900-0000-8a4d-c57dde0e0000 pid=3806 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=6edba536-1900-0000-8a4d-c57dde0e0000 pid=3806 clone guuid=722ed736-1900-0000-8a4d-c57ddf0e0000 pid=3807 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=722ed736-1900-0000-8a4d-c57ddf0e0000 pid=3807 clone guuid=b568fc36-1900-0000-8a4d-c57de00e0000 pid=3808 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=b568fc36-1900-0000-8a4d-c57de00e0000 pid=3808 execve guuid=79d08837-1900-0000-8a4d-c57de10e0000 pid=3809 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=79d08837-1900-0000-8a4d-c57de10e0000 pid=3809 execve guuid=0444de37-1900-0000-8a4d-c57de40e0000 pid=3812 /usr/bin/wget guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=0444de37-1900-0000-8a4d-c57de40e0000 pid=3812 execve guuid=3a84e539-1900-0000-8a4d-c57dea0e0000 pid=3818 /usr/bin/curl guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=3a84e539-1900-0000-8a4d-c57dea0e0000 pid=3818 execve guuid=390acc3d-1900-0000-8a4d-c57dee0e0000 pid=3822 /usr/bin/busybox net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=390acc3d-1900-0000-8a4d-c57dee0e0000 pid=3822 execve guuid=9658bf46-1900-0000-8a4d-c57dfe0e0000 pid=3838 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=9658bf46-1900-0000-8a4d-c57dfe0e0000 pid=3838 clone guuid=475b2247-1900-0000-8a4d-c57dff0e0000 pid=3839 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=475b2247-1900-0000-8a4d-c57dff0e0000 pid=3839 clone guuid=49d36c47-1900-0000-8a4d-c57d000f0000 pid=3840 /usr/bin/bash guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=49d36c47-1900-0000-8a4d-c57d000f0000 pid=3840 clone guuid=044dd947-1900-0000-8a4d-c57d010f0000 pid=3841 /usr/bin/chmod guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=044dd947-1900-0000-8a4d-c57d010f0000 pid=3841 execve guuid=ce0b2b48-1900-0000-8a4d-c57d020f0000 pid=3842 /tmp/newcron net guuid=d88b7dc4-1700-0000-8a4d-c57d5c0b0000 pid=2908->guuid=ce0b2b48-1900-0000-8a4d-c57d020f0000 pid=3842 execve 52e4f383-e1cf-597c-813f-d95056dafc56 160.187.246.23:80 guuid=84511bc5-1700-0000-8a4d-c57d5f0b0000 pid=2911->52e4f383-e1cf-597c-813f-d95056dafc56 send: 148B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=77f1acfc-1700-0000-8a4d-c57def0b0000 pid=3055->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=03e8c6fc-1700-0000-8a4d-c57df00b0000 pid=3056 /tmp/newcron guuid=77f1acfc-1700-0000-8a4d-c57def0b0000 pid=3055->guuid=03e8c6fc-1700-0000-8a4d-c57df00b0000 pid=3056 clone guuid=5de0d2fc-1700-0000-8a4d-c57df10b0000 pid=3057 /tmp/newcron write-config zombie guuid=03e8c6fc-1700-0000-8a4d-c57df00b0000 pid=3056->guuid=5de0d2fc-1700-0000-8a4d-c57df10b0000 pid=3057 clone guuid=81304101-1800-0000-8a4d-c57d030c0000 pid=3075 /usr/bin/dash guuid=5de0d2fc-1700-0000-8a4d-c57df10b0000 pid=3057->guuid=81304101-1800-0000-8a4d-c57d030c0000 pid=3075 execve guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086 /tmp/newcron net send-data zombie guuid=5de0d2fc-1700-0000-8a4d-c57df10b0000 pid=3057->guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086 clone guuid=fbaa8d01-1800-0000-8a4d-c57d040c0000 pid=3076 /usr/bin/cp guuid=81304101-1800-0000-8a4d-c57d030c0000 pid=3075->guuid=fbaa8d01-1800-0000-8a4d-c57d040c0000 pid=3076 execve guuid=fa8d7003-1800-0000-8a4d-c57d0b0c0000 pid=3083->52e4f383-e1cf-597c-813f-d95056dafc56 send: 94B guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B 310a0ed0-c544-54ca-bf3f-fca55e459297 65.222.202.53:80 guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=73fbfd03-1800-0000-8a4d-c57d0f0c0000 pid=3087 /tmp/newcron guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086->guuid=73fbfd03-1800-0000-8a4d-c57d0f0c0000 pid=3087 clone guuid=33590204-1800-0000-8a4d-c57d100c0000 pid=3088 /tmp/newcron guuid=b932f603-1800-0000-8a4d-c57d0e0c0000 pid=3086->guuid=33590204-1800-0000-8a4d-c57d100c0000 pid=3088 clone guuid=e09cab2b-1800-0000-8a4d-c57d650c0000 pid=3173->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=60c9dc2b-1800-0000-8a4d-c57d670c0000 pid=3175 /tmp/newcron guuid=e09cab2b-1800-0000-8a4d-c57d650c0000 pid=3173->guuid=60c9dc2b-1800-0000-8a4d-c57d670c0000 pid=3175 clone guuid=7a49f32b-1800-0000-8a4d-c57d690c0000 pid=3177 /tmp/newcron write-config zombie guuid=60c9dc2b-1800-0000-8a4d-c57d670c0000 pid=3175->guuid=7a49f32b-1800-0000-8a4d-c57d690c0000 pid=3177 clone guuid=065f8d30-1800-0000-8a4d-c57d730c0000 pid=3187 /usr/bin/dash guuid=7a49f32b-1800-0000-8a4d-c57d690c0000 pid=3177->guuid=065f8d30-1800-0000-8a4d-c57d730c0000 pid=3187 execve guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190 /tmp/newcron net send-data zombie guuid=7a49f32b-1800-0000-8a4d-c57d690c0000 pid=3177->guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190 clone guuid=4a50e630-1800-0000-8a4d-c57d740c0000 pid=3188 /usr/bin/cp guuid=065f8d30-1800-0000-8a4d-c57d730c0000 pid=3187->guuid=4a50e630-1800-0000-8a4d-c57d740c0000 pid=3188 execve guuid=11a6c931-1800-0000-8a4d-c57d750c0000 pid=3189->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=b45fb934-1800-0000-8a4d-c57d770c0000 pid=3191 /tmp/newcron guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190->guuid=b45fb934-1800-0000-8a4d-c57d770c0000 pid=3191 clone guuid=1b77c134-1800-0000-8a4d-c57d780c0000 pid=3192 /tmp/newcron guuid=3e9bac34-1800-0000-8a4d-c57d760c0000 pid=3190->guuid=1b77c134-1800-0000-8a4d-c57d780c0000 pid=3192 clone guuid=58f8243b-1800-0000-8a4d-c57d7d0c0000 pid=3197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ed8e5b3b-1800-0000-8a4d-c57d7e0c0000 pid=3198 /tmp/newcron guuid=58f8243b-1800-0000-8a4d-c57d7d0c0000 pid=3197->guuid=ed8e5b3b-1800-0000-8a4d-c57d7e0c0000 pid=3198 clone guuid=0102673b-1800-0000-8a4d-c57d7f0c0000 pid=3199 /tmp/newcron guuid=ed8e5b3b-1800-0000-8a4d-c57d7e0c0000 pid=3198->guuid=0102673b-1800-0000-8a4d-c57d7f0c0000 pid=3199 clone guuid=794af13f-1800-0000-8a4d-c57d820c0000 pid=3202->52e4f383-e1cf-597c-813f-d95056dafc56 send: 93B guuid=058f465b-1800-0000-8a4d-c57dab0c0000 pid=3243->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c9086c5b-1800-0000-8a4d-c57dac0c0000 pid=3244 /tmp/newcron guuid=058f465b-1800-0000-8a4d-c57dab0c0000 pid=3243->guuid=c9086c5b-1800-0000-8a4d-c57dac0c0000 pid=3244 clone guuid=4a817f5b-1800-0000-8a4d-c57dae0c0000 pid=3246 /tmp/newcron write-config zombie guuid=c9086c5b-1800-0000-8a4d-c57dac0c0000 pid=3244->guuid=4a817f5b-1800-0000-8a4d-c57dae0c0000 pid=3246 clone guuid=697e7e61-1800-0000-8a4d-c57db10c0000 pid=3249 /usr/bin/dash guuid=4a817f5b-1800-0000-8a4d-c57dae0c0000 pid=3246->guuid=697e7e61-1800-0000-8a4d-c57db10c0000 pid=3249 execve guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252 /tmp/newcron net send-data zombie guuid=4a817f5b-1800-0000-8a4d-c57dae0c0000 pid=3246->guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252 clone guuid=90230861-1800-0000-8a4d-c57db00c0000 pid=3248->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=126cb761-1800-0000-8a4d-c57db20c0000 pid=3250 /usr/bin/cp guuid=697e7e61-1800-0000-8a4d-c57db10c0000 pid=3249->guuid=126cb761-1800-0000-8a4d-c57db20c0000 pid=3250 execve guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=6db40964-1800-0000-8a4d-c57db50c0000 pid=3253 /tmp/newcron guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252->guuid=6db40964-1800-0000-8a4d-c57db50c0000 pid=3253 clone guuid=148b0e64-1800-0000-8a4d-c57db60c0000 pid=3254 /tmp/newcron guuid=59d1ff63-1800-0000-8a4d-c57db40c0000 pid=3252->guuid=148b0e64-1800-0000-8a4d-c57db60c0000 pid=3254 clone guuid=e2d93769-1800-0000-8a4d-c57dc80c0000 pid=3272->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70584d69-1800-0000-8a4d-c57dc90c0000 pid=3273 /tmp/newcron guuid=e2d93769-1800-0000-8a4d-c57dc80c0000 pid=3272->guuid=70584d69-1800-0000-8a4d-c57dc90c0000 pid=3273 clone guuid=0d735669-1800-0000-8a4d-c57dcb0c0000 pid=3275 /tmp/newcron guuid=70584d69-1800-0000-8a4d-c57dc90c0000 pid=3273->guuid=0d735669-1800-0000-8a4d-c57dcb0c0000 pid=3275 clone guuid=61b3a36d-1800-0000-8a4d-c57dd40c0000 pid=3284->52e4f383-e1cf-597c-813f-d95056dafc56 send: 96B guuid=c7196089-1800-0000-8a4d-c57df80c0000 pid=3320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dbd89489-1800-0000-8a4d-c57df90c0000 pid=3321 /tmp/newcron guuid=c7196089-1800-0000-8a4d-c57df80c0000 pid=3320->guuid=dbd89489-1800-0000-8a4d-c57df90c0000 pid=3321 clone guuid=f0c8aa89-1800-0000-8a4d-c57dfa0c0000 pid=3322 /tmp/newcron write-config zombie guuid=dbd89489-1800-0000-8a4d-c57df90c0000 pid=3321->guuid=f0c8aa89-1800-0000-8a4d-c57dfa0c0000 pid=3322 clone guuid=c310ee8d-1800-0000-8a4d-c57d090d0000 pid=3337 /usr/bin/dash guuid=f0c8aa89-1800-0000-8a4d-c57dfa0c0000 pid=3322->guuid=c310ee8d-1800-0000-8a4d-c57d090d0000 pid=3337 execve guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348 /tmp/newcron net send-data zombie guuid=f0c8aa89-1800-0000-8a4d-c57dfa0c0000 pid=3322->guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348 clone guuid=8f83208e-1800-0000-8a4d-c57d0b0d0000 pid=3339 /usr/bin/cp guuid=c310ee8d-1800-0000-8a4d-c57d090d0000 pid=3337->guuid=8f83208e-1800-0000-8a4d-c57d0b0d0000 pid=3339 execve guuid=9d690c90-1800-0000-8a4d-c57d120d0000 pid=3346->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=5af03e90-1800-0000-8a4d-c57d150d0000 pid=3349 /tmp/newcron guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348->guuid=5af03e90-1800-0000-8a4d-c57d150d0000 pid=3349 clone guuid=966e4490-1800-0000-8a4d-c57d160d0000 pid=3350 /tmp/newcron guuid=c9613690-1800-0000-8a4d-c57d140d0000 pid=3348->guuid=966e4490-1800-0000-8a4d-c57d160d0000 pid=3350 clone guuid=3dcb8495-1800-0000-8a4d-c57d2a0d0000 pid=3370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e02d9f95-1800-0000-8a4d-c57d2b0d0000 pid=3371 /tmp/newcron guuid=3dcb8495-1800-0000-8a4d-c57d2a0d0000 pid=3370->guuid=e02d9f95-1800-0000-8a4d-c57d2b0d0000 pid=3371 clone guuid=d322a595-1800-0000-8a4d-c57d2c0d0000 pid=3372 /tmp/newcron guuid=e02d9f95-1800-0000-8a4d-c57d2b0d0000 pid=3371->guuid=d322a595-1800-0000-8a4d-c57d2c0d0000 pid=3372 clone guuid=d2de819a-1800-0000-8a4d-c57d3d0d0000 pid=3389->52e4f383-e1cf-597c-813f-d95056dafc56 send: 93B guuid=0ae962b7-1800-0000-8a4d-c57d6b0d0000 pid=3435->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=211097b7-1800-0000-8a4d-c57d6d0d0000 pid=3437 /tmp/newcron guuid=0ae962b7-1800-0000-8a4d-c57d6b0d0000 pid=3435->guuid=211097b7-1800-0000-8a4d-c57d6d0d0000 pid=3437 clone guuid=4ca3acb7-1800-0000-8a4d-c57d6e0d0000 pid=3438 /tmp/newcron write-config zombie guuid=211097b7-1800-0000-8a4d-c57d6d0d0000 pid=3437->guuid=4ca3acb7-1800-0000-8a4d-c57d6e0d0000 pid=3438 clone guuid=6a7ef7bb-1800-0000-8a4d-c57d7c0d0000 pid=3452 /usr/bin/dash guuid=4ca3acb7-1800-0000-8a4d-c57d6e0d0000 pid=3438->guuid=6a7ef7bb-1800-0000-8a4d-c57d7c0d0000 pid=3452 execve guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462 /tmp/newcron net send-data zombie guuid=4ca3acb7-1800-0000-8a4d-c57d6e0d0000 pid=3438->guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462 clone guuid=5bf2e2bb-1800-0000-8a4d-c57d7b0d0000 pid=3451->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=db161ebc-1800-0000-8a4d-c57d7e0d0000 pid=3454 /usr/bin/cp guuid=6a7ef7bb-1800-0000-8a4d-c57d7c0d0000 pid=3452->guuid=db161ebc-1800-0000-8a4d-c57d7e0d0000 pid=3454 execve guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=f615ffbd-1800-0000-8a4d-c57d870d0000 pid=3463 /tmp/newcron guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462->guuid=f615ffbd-1800-0000-8a4d-c57d870d0000 pid=3463 clone guuid=f57403be-1800-0000-8a4d-c57d880d0000 pid=3464 /tmp/newcron guuid=b997fabd-1800-0000-8a4d-c57d860d0000 pid=3462->guuid=f57403be-1800-0000-8a4d-c57d880d0000 pid=3464 clone guuid=82cdedc2-1800-0000-8a4d-c57d9f0d0000 pid=3487->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e35505c3-1800-0000-8a4d-c57da00d0000 pid=3488 /tmp/newcron guuid=82cdedc2-1800-0000-8a4d-c57d9f0d0000 pid=3487->guuid=e35505c3-1800-0000-8a4d-c57da00d0000 pid=3488 clone guuid=3e9a11c3-1800-0000-8a4d-c57da30d0000 pid=3491 /tmp/newcron guuid=e35505c3-1800-0000-8a4d-c57da00d0000 pid=3488->guuid=3e9a11c3-1800-0000-8a4d-c57da30d0000 pid=3491 clone guuid=484a91c6-1800-0000-8a4d-c57db10d0000 pid=3505->52e4f383-e1cf-597c-813f-d95056dafc56 send: 94B guuid=03f5e4e1-1800-0000-8a4d-c57dfb0d0000 pid=3579->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d421ce2-1800-0000-8a4d-c57dfd0d0000 pid=3581 /tmp/newcron guuid=03f5e4e1-1800-0000-8a4d-c57dfb0d0000 pid=3579->guuid=4d421ce2-1800-0000-8a4d-c57dfd0d0000 pid=3581 clone guuid=e9792ce2-1800-0000-8a4d-c57dfe0d0000 pid=3582 /tmp/newcron write-config zombie guuid=4d421ce2-1800-0000-8a4d-c57dfd0d0000 pid=3581->guuid=e9792ce2-1800-0000-8a4d-c57dfe0d0000 pid=3582 clone guuid=ae9a33e6-1800-0000-8a4d-c57d100e0000 pid=3600 /usr/bin/dash guuid=e9792ce2-1800-0000-8a4d-c57dfe0d0000 pid=3582->guuid=ae9a33e6-1800-0000-8a4d-c57d100e0000 pid=3600 execve guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602 /tmp/newcron net send-data zombie guuid=e9792ce2-1800-0000-8a4d-c57dfe0d0000 pid=3582->guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602 clone guuid=3b6b70e5-1800-0000-8a4d-c57d0a0e0000 pid=3594->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=79046ae6-1800-0000-8a4d-c57d110e0000 pid=3601 /usr/bin/cp guuid=ae9a33e6-1800-0000-8a4d-c57d100e0000 pid=3600->guuid=79046ae6-1800-0000-8a4d-c57d110e0000 pid=3601 execve guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=e38790e8-1800-0000-8a4d-c57d130e0000 pid=3603 /tmp/newcron guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602->guuid=e38790e8-1800-0000-8a4d-c57d130e0000 pid=3603 clone guuid=02b494e8-1800-0000-8a4d-c57d140e0000 pid=3604 /tmp/newcron guuid=f3ee87e8-1800-0000-8a4d-c57d120e0000 pid=3602->guuid=02b494e8-1800-0000-8a4d-c57d140e0000 pid=3604 clone guuid=0b32bded-1800-0000-8a4d-c57d240e0000 pid=3620->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dc1edaed-1800-0000-8a4d-c57d250e0000 pid=3621 /tmp/newcron guuid=0b32bded-1800-0000-8a4d-c57d240e0000 pid=3620->guuid=dc1edaed-1800-0000-8a4d-c57d250e0000 pid=3621 clone guuid=cbb5e2ed-1800-0000-8a4d-c57d270e0000 pid=3623 /tmp/newcron guuid=dc1edaed-1800-0000-8a4d-c57d250e0000 pid=3621->guuid=cbb5e2ed-1800-0000-8a4d-c57d270e0000 pid=3623 clone guuid=01090ff1-1800-0000-8a4d-c57d320e0000 pid=3634->52e4f383-e1cf-597c-813f-d95056dafc56 send: 93B guuid=c68b540c-1900-0000-8a4d-c57d5c0e0000 pid=3676->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9517970c-1900-0000-8a4d-c57d5d0e0000 pid=3677 /tmp/newcron guuid=c68b540c-1900-0000-8a4d-c57d5c0e0000 pid=3676->guuid=9517970c-1900-0000-8a4d-c57d5d0e0000 pid=3677 clone guuid=1791a70c-1900-0000-8a4d-c57d5f0e0000 pid=3679 /tmp/newcron write-config zombie guuid=9517970c-1900-0000-8a4d-c57d5d0e0000 pid=3677->guuid=1791a70c-1900-0000-8a4d-c57d5f0e0000 pid=3679 clone guuid=1684ba11-1900-0000-8a4d-c57d6e0e0000 pid=3694 /usr/bin/dash guuid=1791a70c-1900-0000-8a4d-c57d5f0e0000 pid=3679->guuid=1684ba11-1900-0000-8a4d-c57d6e0e0000 pid=3694 execve guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703 /tmp/newcron net send-data zombie guuid=1791a70c-1900-0000-8a4d-c57d5f0e0000 pid=3679->guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703 clone guuid=c53b5512-1900-0000-8a4d-c57d710e0000 pid=3697 /usr/bin/cp guuid=1684ba11-1900-0000-8a4d-c57d6e0e0000 pid=3694->guuid=c53b5512-1900-0000-8a4d-c57d710e0000 pid=3697 execve guuid=56605012-1900-0000-8a4d-c57d6f0e0000 pid=3695->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=97d45314-1900-0000-8a4d-c57d780e0000 pid=3704 /tmp/newcron guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703->guuid=97d45314-1900-0000-8a4d-c57d780e0000 pid=3704 clone guuid=98475814-1900-0000-8a4d-c57d790e0000 pid=3705 /tmp/newcron guuid=51634c14-1900-0000-8a4d-c57d770e0000 pid=3703->guuid=98475814-1900-0000-8a4d-c57d790e0000 pid=3705 clone guuid=a4fc1d19-1900-0000-8a4d-c57d8e0e0000 pid=3726->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=0c803719-1900-0000-8a4d-c57d900e0000 pid=3728 /tmp/newcron guuid=a4fc1d19-1900-0000-8a4d-c57d8e0e0000 pid=3726->guuid=0c803719-1900-0000-8a4d-c57d900e0000 pid=3728 clone guuid=5f016619-1900-0000-8a4d-c57d930e0000 pid=3731 /tmp/newcron guuid=0c803719-1900-0000-8a4d-c57d900e0000 pid=3728->guuid=5f016619-1900-0000-8a4d-c57d930e0000 pid=3731 clone guuid=26a5261c-1900-0000-8a4d-c57d9f0e0000 pid=3743->52e4f383-e1cf-597c-813f-d95056dafc56 send: 94B guuid=79d08837-1900-0000-8a4d-c57de10e0000 pid=3809->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7965c437-1900-0000-8a4d-c57de20e0000 pid=3810 /tmp/newcron guuid=79d08837-1900-0000-8a4d-c57de10e0000 pid=3809->guuid=7965c437-1900-0000-8a4d-c57de20e0000 pid=3810 clone guuid=5fe7d837-1900-0000-8a4d-c57de30e0000 pid=3811 /tmp/newcron write-config zombie guuid=7965c437-1900-0000-8a4d-c57de20e0000 pid=3810->guuid=5fe7d837-1900-0000-8a4d-c57de30e0000 pid=3811 clone guuid=02f9d83c-1900-0000-8a4d-c57dec0e0000 pid=3820 /usr/bin/dash guuid=5fe7d837-1900-0000-8a4d-c57de30e0000 pid=3811->guuid=02f9d83c-1900-0000-8a4d-c57dec0e0000 pid=3820 execve guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823 /tmp/newcron net send-data zombie guuid=5fe7d837-1900-0000-8a4d-c57de30e0000 pid=3811->guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823 clone guuid=ba773a3d-1900-0000-8a4d-c57ded0e0000 pid=3821 /usr/bin/cp guuid=02f9d83c-1900-0000-8a4d-c57dec0e0000 pid=3820->guuid=ba773a3d-1900-0000-8a4d-c57ded0e0000 pid=3821 execve guuid=390acc3d-1900-0000-8a4d-c57dee0e0000 pid=3822->52e4f383-e1cf-597c-813f-d95056dafc56 con guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 945B guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823->310a0ed0-c544-54ca-bf3f-fca55e459297 con guuid=a4ac4940-1900-0000-8a4d-c57df00e0000 pid=3824 /tmp/newcron guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823->guuid=a4ac4940-1900-0000-8a4d-c57df00e0000 pid=3824 clone guuid=67d04f40-1900-0000-8a4d-c57df10e0000 pid=3825 /tmp/newcron guuid=33c84140-1900-0000-8a4d-c57def0e0000 pid=3823->guuid=67d04f40-1900-0000-8a4d-c57df10e0000 pid=3825 clone guuid=ce0b2b48-1900-0000-8a4d-c57d020f0000 pid=3842->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c5bc4948-1900-0000-8a4d-c57d030f0000 pid=3843 /tmp/newcron guuid=ce0b2b48-1900-0000-8a4d-c57d020f0000 pid=3842->guuid=c5bc4948-1900-0000-8a4d-c57d030f0000 pid=3843 clone guuid=4dc76a48-1900-0000-8a4d-c57d040f0000 pid=3844 /tmp/newcron write-config zombie guuid=c5bc4948-1900-0000-8a4d-c57d030f0000 pid=3843->guuid=4dc76a48-1900-0000-8a4d-c57d040f0000 pid=3844 clone guuid=95740e4c-1900-0000-8a4d-c57d130f0000 pid=3859 /usr/bin/dash guuid=4dc76a48-1900-0000-8a4d-c57d040f0000 pid=3844->guuid=95740e4c-1900-0000-8a4d-c57d130f0000 pid=3859 execve guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870 /tmp/newcron net send-data zombie guuid=4dc76a48-1900-0000-8a4d-c57d040f0000 pid=3844->guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870 clone guuid=7ad73d4c-1900-0000-8a4d-c57d140f0000 pid=3860 /usr/bin/cp guuid=95740e4c-1900-0000-8a4d-c57d130f0000 pid=3859->guuid=7ad73d4c-1900-0000-8a4d-c57d140f0000 pid=3860 execve guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2845B guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870->310a0ed0-c544-54ca-bf3f-fca55e459297 send: 2B guuid=2d851f4e-1900-0000-8a4d-c57d1f0f0000 pid=3871 /tmp/newcron guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870->guuid=2d851f4e-1900-0000-8a4d-c57d1f0f0000 pid=3871 clone guuid=9372224e-1900-0000-8a4d-c57d200f0000 pid=3872 /tmp/newcron guuid=5cc7194e-1900-0000-8a4d-c57d1e0f0000 pid=3870->guuid=9372224e-1900-0000-8a4d-c57d200f0000 pid=3872 clone
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Text.Browser.Generic
Status:
Suspicious
First seen:
2025-07-26 06:05:00 UTC
AV detection:
2 of 24 (8.33%)
Threat level:
  4/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Reads system network configuration
Reads process memory
Enumerates active TCP sockets
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
asdfavae.duckdns.org
cvawrs.duckdns.org
fasdv.duckdns.org
savaswsd.duckdns.org
vmklsfdv.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 30cd1987c91bee55bafc93ad6ccb54874d86d3e35604c404a855c3ade7504f24

(this sample)

  
Delivery method
Distributed via web download

Comments