MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 424b1beaea68c353b10c7d5ef22a950be13c75a5417176ecd995c5aa71bb38af. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 424b1beaea68c353b10c7d5ef22a950be13c75a5417176ecd995c5aa71bb38af
SHA3-384 hash: 844e876b601f089cc2d3d04205f453bcd81ae827e32cf3095ab1a228a3088d801392d474b1b6f1fac565e1f3240a99e4
SHA1 hash: 568f47a33a9557a6724a650f59f9d07ebd56f7d2
MD5 hash: 1e0ac4e2a61f799c74a4d8f8ac9ee399
humanhash: vegan-table-oregon-low
File name:loader.sh
Download: download sample
File size:9'582 bytes
First seen:2026-05-02 17:27:11 UTC
Last seen:2026-05-03 09:48:49 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:mla21T1IVoF6mdiydTdI9E1q2xW2lTlIFI2aZ2aO26nC52JE2JT2pYd02Y/2Yk2r:e
TLSH T1081216E9B3E5143BA1617F4CF140C449E8716CACC053BD06A9219B5E9F8C738B36EE99
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://axodoyin.alwaysdata.net/dl/client-android-arm64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-darwin-amd64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-darwin-arm64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-freebsd-386n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-freebsd-amd64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-freebsd-arm64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-386n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-amd64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-arm64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-armv5n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-armv6n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-armv7n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mipsn/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mips-hfn/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mips64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mips64len/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mipslen/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-mipsle-hfn/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-ppc64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-ppc64len/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-riscv64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-linux-s390xn/an/an/a
http://axodoyin.alwaysdata.net/dl/client-netbsd-386n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-netbsd-amd64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-openbsd-386n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-openbsd-amd64n/an/an/a
http://axodoyin.alwaysdata.net/dl/client-openbsd-arm64n/an/an/a

Intelligence


File Origin
# of uploads :
3
# of downloads :
38
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=a8df4753-1900-0000-a721-5319f70a0000 pid=2807 /usr/bin/sudo guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812 /tmp/sample.bin guuid=a8df4753-1900-0000-a721-5319f70a0000 pid=2807->guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812 execve guuid=ac394156-1900-0000-a721-5319fe0a0000 pid=2814 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=ac394156-1900-0000-a721-5319fe0a0000 pid=2814 execve guuid=60d19371-1900-0000-a721-5319250b0000 pid=2853 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=60d19371-1900-0000-a721-5319250b0000 pid=2853 execve guuid=684afe71-1900-0000-a721-5319280b0000 pid=2856 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=684afe71-1900-0000-a721-5319280b0000 pid=2856 clone guuid=70010472-1900-0000-a721-5319290b0000 pid=2857 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=70010472-1900-0000-a721-5319290b0000 pid=2857 execve guuid=1c245d8d-1900-0000-a721-5319620b0000 pid=2914 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=1c245d8d-1900-0000-a721-5319620b0000 pid=2914 execve guuid=6092ac8d-1900-0000-a721-5319630b0000 pid=2915 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6092ac8d-1900-0000-a721-5319630b0000 pid=2915 clone guuid=dc9db08d-1900-0000-a721-5319640b0000 pid=2916 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=dc9db08d-1900-0000-a721-5319640b0000 pid=2916 execve guuid=83601aa1-1900-0000-a721-53197f0b0000 pid=2943 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=83601aa1-1900-0000-a721-53197f0b0000 pid=2943 execve guuid=08e068a1-1900-0000-a721-5319800b0000 pid=2944 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=08e068a1-1900-0000-a721-5319800b0000 pid=2944 clone guuid=f3456fa1-1900-0000-a721-5319820b0000 pid=2946 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=f3456fa1-1900-0000-a721-5319820b0000 pid=2946 execve guuid=bd3175ba-1900-0000-a721-5319a20b0000 pid=2978 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=bd3175ba-1900-0000-a721-5319a20b0000 pid=2978 execve guuid=951d5bbb-1900-0000-a721-5319a40b0000 pid=2980 /tmp/client-freebsd-386 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=951d5bbb-1900-0000-a721-5319a40b0000 pid=2980 execve guuid=1bb262bb-1900-0000-a721-5319a50b0000 pid=2981 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=1bb262bb-1900-0000-a721-5319a50b0000 pid=2981 execve guuid=111ca8d6-1900-0000-a721-5319c50b0000 pid=3013 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=111ca8d6-1900-0000-a721-5319c50b0000 pid=3013 execve guuid=e8cb36d7-1900-0000-a721-5319c60b0000 pid=3014 /tmp/client-freebsd-amd64 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e8cb36d7-1900-0000-a721-5319c60b0000 pid=3014 execve guuid=53003fd7-1900-0000-a721-5319c70b0000 pid=3015 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=53003fd7-1900-0000-a721-5319c70b0000 pid=3015 execve guuid=9d668cef-1900-0000-a721-5319fa0b0000 pid=3066 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=9d668cef-1900-0000-a721-5319fa0b0000 pid=3066 execve guuid=ae2312f0-1900-0000-a721-5319fc0b0000 pid=3068 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=ae2312f0-1900-0000-a721-5319fc0b0000 pid=3068 clone guuid=6ca11af0-1900-0000-a721-5319fe0b0000 pid=3070 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6ca11af0-1900-0000-a721-5319fe0b0000 pid=3070 execve guuid=555a6f09-1a00-0000-a721-53192c0c0000 pid=3116 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=555a6f09-1a00-0000-a721-53192c0c0000 pid=3116 execve guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117 /tmp/client-linux-386 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117 execve guuid=22e7e309-1a00-0000-a721-53192e0c0000 pid=3118 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=22e7e309-1a00-0000-a721-53192e0c0000 pid=3118 execve guuid=e5a87d21-1a00-0000-a721-5319600c0000 pid=3168 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e5a87d21-1a00-0000-a721-5319600c0000 pid=3168 execve guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171 /tmp/client-linux-amd64 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171 execve guuid=6984e821-1a00-0000-a721-5319640c0000 pid=3172 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6984e821-1a00-0000-a721-5319640c0000 pid=3172 execve guuid=6758073c-1a00-0000-a721-53199d0c0000 pid=3229 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6758073c-1a00-0000-a721-53199d0c0000 pid=3229 execve guuid=e67d403c-1a00-0000-a721-53199e0c0000 pid=3230 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e67d403c-1a00-0000-a721-53199e0c0000 pid=3230 clone guuid=6ea4473c-1a00-0000-a721-5319a00c0000 pid=3232 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6ea4473c-1a00-0000-a721-5319a00c0000 pid=3232 execve guuid=c09de453-1a00-0000-a721-5319a70c0000 pid=3239 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c09de453-1a00-0000-a721-5319a70c0000 pid=3239 execve guuid=c8252b54-1a00-0000-a721-5319a90c0000 pid=3241 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c8252b54-1a00-0000-a721-5319a90c0000 pid=3241 clone guuid=50842f54-1a00-0000-a721-5319aa0c0000 pid=3242 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=50842f54-1a00-0000-a721-5319aa0c0000 pid=3242 execve guuid=26227a6a-1a00-0000-a721-5319c40c0000 pid=3268 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=26227a6a-1a00-0000-a721-5319c40c0000 pid=3268 execve guuid=a25cbc6a-1a00-0000-a721-5319c50c0000 pid=3269 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=a25cbc6a-1a00-0000-a721-5319c50c0000 pid=3269 clone guuid=a2c3c56a-1a00-0000-a721-5319c60c0000 pid=3270 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=a2c3c56a-1a00-0000-a721-5319c60c0000 pid=3270 execve guuid=699e1682-1a00-0000-a721-5319cf0c0000 pid=3279 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=699e1682-1a00-0000-a721-5319cf0c0000 pid=3279 execve guuid=c7a78182-1a00-0000-a721-5319d00c0000 pid=3280 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c7a78182-1a00-0000-a721-5319d00c0000 pid=3280 clone guuid=c22b8e82-1a00-0000-a721-5319d10c0000 pid=3281 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c22b8e82-1a00-0000-a721-5319d10c0000 pid=3281 execve guuid=0709c19b-1a00-0000-a721-5319e80c0000 pid=3304 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=0709c19b-1a00-0000-a721-5319e80c0000 pid=3304 execve guuid=f0c6259c-1a00-0000-a721-5319e90c0000 pid=3305 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=f0c6259c-1a00-0000-a721-5319e90c0000 pid=3305 clone guuid=e688319c-1a00-0000-a721-5319ea0c0000 pid=3306 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e688319c-1a00-0000-a721-5319ea0c0000 pid=3306 execve guuid=7dedfcb3-1a00-0000-a721-5319010d0000 pid=3329 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=7dedfcb3-1a00-0000-a721-5319010d0000 pid=3329 execve guuid=e5c950b4-1a00-0000-a721-5319020d0000 pid=3330 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e5c950b4-1a00-0000-a721-5319020d0000 pid=3330 clone guuid=905857b4-1a00-0000-a721-5319030d0000 pid=3331 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=905857b4-1a00-0000-a721-5319030d0000 pid=3331 execve guuid=46be28cd-1a00-0000-a721-5319240d0000 pid=3364 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=46be28cd-1a00-0000-a721-5319240d0000 pid=3364 execve guuid=8eef6fcd-1a00-0000-a721-5319250d0000 pid=3365 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=8eef6fcd-1a00-0000-a721-5319250d0000 pid=3365 clone guuid=ca8579cd-1a00-0000-a721-5319270d0000 pid=3367 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=ca8579cd-1a00-0000-a721-5319270d0000 pid=3367 execve guuid=95ce80e8-1a00-0000-a721-5319500d0000 pid=3408 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=95ce80e8-1a00-0000-a721-5319500d0000 pid=3408 execve guuid=6dc0efe8-1a00-0000-a721-5319510d0000 pid=3409 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6dc0efe8-1a00-0000-a721-5319510d0000 pid=3409 clone guuid=db77f6e8-1a00-0000-a721-5319520d0000 pid=3410 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=db77f6e8-1a00-0000-a721-5319520d0000 pid=3410 execve guuid=09e1130d-1b00-0000-a721-53195f0d0000 pid=3423 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=09e1130d-1b00-0000-a721-53195f0d0000 pid=3423 execve guuid=a403ab0d-1b00-0000-a721-5319600d0000 pid=3424 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=a403ab0d-1b00-0000-a721-5319600d0000 pid=3424 clone guuid=0c69b60d-1b00-0000-a721-5319610d0000 pid=3425 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=0c69b60d-1b00-0000-a721-5319610d0000 pid=3425 execve guuid=a2a32128-1b00-0000-a721-53196b0d0000 pid=3435 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=a2a32128-1b00-0000-a721-53196b0d0000 pid=3435 execve guuid=768abf28-1b00-0000-a721-53196c0d0000 pid=3436 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=768abf28-1b00-0000-a721-53196c0d0000 pid=3436 clone guuid=c7dbc828-1b00-0000-a721-53196d0d0000 pid=3437 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c7dbc828-1b00-0000-a721-53196d0d0000 pid=3437 execve guuid=352c413e-1b00-0000-a721-5319840d0000 pid=3460 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=352c413e-1b00-0000-a721-5319840d0000 pid=3460 execve guuid=ed4f983e-1b00-0000-a721-5319860d0000 pid=3462 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=ed4f983e-1b00-0000-a721-5319860d0000 pid=3462 clone guuid=742ba23e-1b00-0000-a721-5319870d0000 pid=3463 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=742ba23e-1b00-0000-a721-5319870d0000 pid=3463 execve guuid=92444957-1b00-0000-a721-5319b00d0000 pid=3504 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=92444957-1b00-0000-a721-5319b00d0000 pid=3504 execve guuid=7ae6aa57-1b00-0000-a721-5319b20d0000 pid=3506 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=7ae6aa57-1b00-0000-a721-5319b20d0000 pid=3506 clone guuid=3e35ba57-1b00-0000-a721-5319b50d0000 pid=3509 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=3e35ba57-1b00-0000-a721-5319b50d0000 pid=3509 execve guuid=195af66c-1b00-0000-a721-5319e80d0000 pid=3560 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=195af66c-1b00-0000-a721-5319e80d0000 pid=3560 execve guuid=65af376d-1b00-0000-a721-5319ea0d0000 pid=3562 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=65af376d-1b00-0000-a721-5319ea0d0000 pid=3562 clone guuid=c415446d-1b00-0000-a721-5319eb0d0000 pid=3563 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=c415446d-1b00-0000-a721-5319eb0d0000 pid=3563 execve guuid=22ac6282-1b00-0000-a721-5319110e0000 pid=3601 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=22ac6282-1b00-0000-a721-5319110e0000 pid=3601 execve guuid=f51dfd82-1b00-0000-a721-5319140e0000 pid=3604 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=f51dfd82-1b00-0000-a721-5319140e0000 pid=3604 clone guuid=58aa0283-1b00-0000-a721-5319150e0000 pid=3605 /usr/bin/busybox dns net send-data guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=58aa0283-1b00-0000-a721-5319150e0000 pid=3605 execve guuid=f7649385-1b00-0000-a721-53191c0e0000 pid=3612 /usr/bin/wget dns net send-data guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=f7649385-1b00-0000-a721-53191c0e0000 pid=3612 execve guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3620 /usr/bin/curl net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3620 execve guuid=79655a94-1b00-0000-a721-5319330e0000 pid=3635 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=79655a94-1b00-0000-a721-5319330e0000 pid=3635 execve guuid=33701d95-1b00-0000-a721-5319350e0000 pid=3637 /tmp/client-netbsd-386 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=33701d95-1b00-0000-a721-5319350e0000 pid=3637 execve guuid=6d302295-1b00-0000-a721-5319360e0000 pid=3638 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=6d302295-1b00-0000-a721-5319360e0000 pid=3638 execve guuid=8e3911af-1b00-0000-a721-5319670e0000 pid=3687 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=8e3911af-1b00-0000-a721-5319670e0000 pid=3687 execve guuid=8e1955af-1b00-0000-a721-5319690e0000 pid=3689 /tmp/client-netbsd-amd64 guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=8e1955af-1b00-0000-a721-5319690e0000 pid=3689 execve guuid=e6335aaf-1b00-0000-a721-53196a0e0000 pid=3690 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e6335aaf-1b00-0000-a721-53196a0e0000 pid=3690 execve guuid=fdf518c6-1b00-0000-a721-53199b0e0000 pid=3739 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=fdf518c6-1b00-0000-a721-53199b0e0000 pid=3739 execve guuid=0b935bc6-1b00-0000-a721-53199f0e0000 pid=3743 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=0b935bc6-1b00-0000-a721-53199f0e0000 pid=3743 clone guuid=e06a61c6-1b00-0000-a721-5319a00e0000 pid=3744 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=e06a61c6-1b00-0000-a721-5319a00e0000 pid=3744 execve guuid=b3f5d7de-1b00-0000-a721-5319c60e0000 pid=3782 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=b3f5d7de-1b00-0000-a721-5319c60e0000 pid=3782 execve guuid=50ae37df-1b00-0000-a721-5319c70e0000 pid=3783 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=50ae37df-1b00-0000-a721-5319c70e0000 pid=3783 clone guuid=43023edf-1b00-0000-a721-5319c80e0000 pid=3784 /usr/bin/busybox dns net send-data write-file guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=43023edf-1b00-0000-a721-5319c80e0000 pid=3784 execve guuid=7d4daeea-1b00-0000-a721-5319d50e0000 pid=3797 /usr/bin/chmod guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=7d4daeea-1b00-0000-a721-5319d50e0000 pid=3797 execve guuid=567712eb-1b00-0000-a721-5319d60e0000 pid=3798 /usr/bin/dash guuid=38e4ff55-1900-0000-a721-5319fc0a0000 pid=2812->guuid=567712eb-1b00-0000-a721-5319d60e0000 pid=3798 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ac394156-1900-0000-a721-5319fe0a0000 pid=2814->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B 7fb363f6-c6e0-53b9-a0aa-a68611fe863d axodoyin.alwaysdata.net:0 guuid=ac394156-1900-0000-a721-5319fe0a0000 pid=2814->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con 67d61213-6ed8-566a-bd8a-57fd3af58931 axodoyin.alwaysdata.net:80 guuid=ac394156-1900-0000-a721-5319fe0a0000 pid=2814->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=70010472-1900-0000-a721-5319290b0000 pid=2857->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=70010472-1900-0000-a721-5319290b0000 pid=2857->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=70010472-1900-0000-a721-5319290b0000 pid=2857->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 108B guuid=dc9db08d-1900-0000-a721-5319640b0000 pid=2916->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=dc9db08d-1900-0000-a721-5319640b0000 pid=2916->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=dc9db08d-1900-0000-a721-5319640b0000 pid=2916->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 108B guuid=f3456fa1-1900-0000-a721-5319820b0000 pid=2946->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=f3456fa1-1900-0000-a721-5319820b0000 pid=2946->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=f3456fa1-1900-0000-a721-5319820b0000 pid=2946->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=1bb262bb-1900-0000-a721-5319a50b0000 pid=2981->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=1bb262bb-1900-0000-a721-5319a50b0000 pid=2981->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=1bb262bb-1900-0000-a721-5319a50b0000 pid=2981->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=53003fd7-1900-0000-a721-5319c70b0000 pid=3015->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=53003fd7-1900-0000-a721-5319c70b0000 pid=3015->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=53003fd7-1900-0000-a721-5319c70b0000 pid=3015->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=6ca11af0-1900-0000-a721-5319fe0b0000 pid=3070->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=6ca11af0-1900-0000-a721-5319fe0b0000 pid=3070->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=6ca11af0-1900-0000-a721-5319fe0b0000 pid=3070->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 105B guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3132 /tmp/client-linux-386 guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3132 clone guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3133 /tmp/client-linux-386 guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3133 clone guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3134 /tmp/client-linux-386 guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3134 clone guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3135 /tmp/client-linux-386 guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3135 clone guuid=f41d4c10-1a00-0000-a721-5319400c0000 pid=3136 /tmp/client-linux-386 guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=f41d4c10-1a00-0000-a721-5319400c0000 pid=3136 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137 /tmp/client-linux-386 zombie guuid=8aeedd09-1a00-0000-a721-53192d0c0000 pid=3117->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137 execve guuid=22e7e309-1a00-0000-a721-53192e0c0000 pid=3118->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=22e7e309-1a00-0000-a721-53192e0c0000 pid=3118->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=22e7e309-1a00-0000-a721-53192e0c0000 pid=3118->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3147 /tmp/client-linux-386 zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3147 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3148 /tmp/client-linux-386 send-data zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3148 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3150 /tmp/client-linux-386 net zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3150 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3151 /tmp/client-linux-386 send-data zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3151 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3152 /tmp/client-linux-386 send-data zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3152 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3153 /tmp/client-linux-386 guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3153 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5353 /tmp/client-linux-386 send-data zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5353 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5393 /tmp/client-linux-386 send-data zombie guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3137->guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5393 clone guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3148->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 203B guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3150->67d61213-6ed8-566a-bd8a-57fd3af58931 con guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3151->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 323B guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=3152->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 547B guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3173 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3173 clone guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3174 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3174 clone guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3175 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3175 clone guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3176 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3176 clone guuid=683c8022-1a00-0000-a721-53196a0c0000 pid=3178 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=683c8022-1a00-0000-a721-53196a0c0000 pid=3178 clone guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3179 /tmp/client-linux-amd64 guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3179 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180 /tmp/client-linux-amd64 zombie guuid=2990e421-1a00-0000-a721-5319630c0000 pid=3171->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180 execve guuid=6984e821-1a00-0000-a721-5319640c0000 pid=3172->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=6984e821-1a00-0000-a721-5319640c0000 pid=3172->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=6984e821-1a00-0000-a721-5319640c0000 pid=3172->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3202 /tmp/client-linux-amd64 zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3202 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3203 /tmp/client-linux-amd64 send-data zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3203 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3204 /tmp/client-linux-amd64 net zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3204 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3205 /tmp/client-linux-amd64 send-data zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3205 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3207 /tmp/client-linux-amd64 guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3207 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3208 /tmp/client-linux-amd64 guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3208 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3209 /tmp/client-linux-amd64 send-data zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3209 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=5394 /tmp/client-linux-amd64 send-data zombie guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3180->guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=5394 clone guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3203->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 282B guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3204->67d61213-6ed8-566a-bd8a-57fd3af58931 con guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3205->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 513B guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=3209->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 690B guuid=6ea4473c-1a00-0000-a721-5319a00c0000 pid=3232->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=6ea4473c-1a00-0000-a721-5319a00c0000 pid=3232->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=6ea4473c-1a00-0000-a721-5319a00c0000 pid=3232->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=50842f54-1a00-0000-a721-5319aa0c0000 pid=3242->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=50842f54-1a00-0000-a721-5319aa0c0000 pid=3242->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=50842f54-1a00-0000-a721-5319aa0c0000 pid=3242->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=a2c3c56a-1a00-0000-a721-5319c60c0000 pid=3270->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=a2c3c56a-1a00-0000-a721-5319c60c0000 pid=3270->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=a2c3c56a-1a00-0000-a721-5319c60c0000 pid=3270->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=c22b8e82-1a00-0000-a721-5319d10c0000 pid=3281->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=c22b8e82-1a00-0000-a721-5319d10c0000 pid=3281->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=c22b8e82-1a00-0000-a721-5319d10c0000 pid=3281->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 106B guuid=e688319c-1a00-0000-a721-5319ea0c0000 pid=3306->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=e688319c-1a00-0000-a721-5319ea0c0000 pid=3306->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=e688319c-1a00-0000-a721-5319ea0c0000 pid=3306->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=905857b4-1a00-0000-a721-5319030d0000 pid=3331->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=905857b4-1a00-0000-a721-5319030d0000 pid=3331->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=905857b4-1a00-0000-a721-5319030d0000 pid=3331->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 108B guuid=ca8579cd-1a00-0000-a721-5319270d0000 pid=3367->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=ca8579cd-1a00-0000-a721-5319270d0000 pid=3367->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=ca8579cd-1a00-0000-a721-5319270d0000 pid=3367->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 110B guuid=db77f6e8-1a00-0000-a721-5319520d0000 pid=3410->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=db77f6e8-1a00-0000-a721-5319520d0000 pid=3410->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=db77f6e8-1a00-0000-a721-5319520d0000 pid=3410->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 108B guuid=0c69b60d-1b00-0000-a721-5319610d0000 pid=3425->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=0c69b60d-1b00-0000-a721-5319610d0000 pid=3425->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=0c69b60d-1b00-0000-a721-5319610d0000 pid=3425->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 111B guuid=c7dbc828-1b00-0000-a721-53196d0d0000 pid=3437->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=c7dbc828-1b00-0000-a721-53196d0d0000 pid=3437->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=c7dbc828-1b00-0000-a721-53196d0d0000 pid=3437->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=742ba23e-1b00-0000-a721-5319870d0000 pid=3463->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=742ba23e-1b00-0000-a721-5319870d0000 pid=3463->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=742ba23e-1b00-0000-a721-5319870d0000 pid=3463->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=3e35ba57-1b00-0000-a721-5319b50d0000 pid=3509->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=3e35ba57-1b00-0000-a721-5319b50d0000 pid=3509->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=3e35ba57-1b00-0000-a721-5319b50d0000 pid=3509->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=c415446d-1b00-0000-a721-5319eb0d0000 pid=3563->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=c415446d-1b00-0000-a721-5319eb0d0000 pid=3563->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=c415446d-1b00-0000-a721-5319eb0d0000 pid=3563->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=58aa0283-1b00-0000-a721-5319150e0000 pid=3605->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=58aa0283-1b00-0000-a721-5319150e0000 pid=3605->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=58aa0283-1b00-0000-a721-5319150e0000 pid=3605->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 106B guuid=f7649385-1b00-0000-a721-53191c0e0000 pid=3612->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=f7649385-1b00-0000-a721-53191c0e0000 pid=3612->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=f7649385-1b00-0000-a721-53191c0e0000 pid=3612->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 158B guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3620->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3627 /usr/bin/curl dns net send-data guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3620->guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3627 clone guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3627->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=3b658d8a-1b00-0000-a721-5319240e0000 pid=3627->67d61213-6ed8-566a-bd8a-57fd3af58931 con guuid=6d302295-1b00-0000-a721-5319360e0000 pid=3638->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=6d302295-1b00-0000-a721-5319360e0000 pid=3638->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=6d302295-1b00-0000-a721-5319360e0000 pid=3638->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 108B guuid=e6335aaf-1b00-0000-a721-53196a0e0000 pid=3690->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=e6335aaf-1b00-0000-a721-53196a0e0000 pid=3690->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=e6335aaf-1b00-0000-a721-53196a0e0000 pid=3690->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 107B guuid=e06a61c6-1b00-0000-a721-5319a00e0000 pid=3744->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=e06a61c6-1b00-0000-a721-5319a00e0000 pid=3744->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=e06a61c6-1b00-0000-a721-5319a00e0000 pid=3744->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=43023edf-1b00-0000-a721-5319c80e0000 pid=3784->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 82B guuid=43023edf-1b00-0000-a721-5319c80e0000 pid=3784->7fb363f6-c6e0-53b9-a0aa-a68611fe863d con guuid=43023edf-1b00-0000-a721-5319c80e0000 pid=3784->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 109B guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5353->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 104B guuid=49ef5a10-1a00-0000-a721-5319410c0000 pid=5393->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 356B guuid=014b8e22-1a00-0000-a721-53196c0c0000 pid=5394->67d61213-6ed8-566a-bd8a-57fd3af58931 send: 26B
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 424b1beaea68c353b10c7d5ef22a950be13c75a5417176ecd995c5aa71bb38af

(this sample)

  
Delivery method
Distributed via web download

Comments