MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 63b7f1a4db8928360637160e67622eae244656df1c090c6f2ac8dc6f12ae5c14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 63b7f1a4db8928360637160e67622eae244656df1c090c6f2ac8dc6f12ae5c14
SHA3-384 hash: 4f54cfe3c880879490f80d2ab3eef446db0a4c30f2daa2c60521a20dbe89ab6f82a8d22ce7432bcbce14048621844519
SHA1 hash: b457d0c331f99832bbb45da0416ded0629579a7d
MD5 hash: 9d8b49712e2aed0d3bc39a901fec3505
humanhash: sodium-paris-nitrogen-orange
File name:rondo.aqu.sh
Download: download sample
Signature Mirai
File size:9'731 bytes
First seen:2025-12-19 05:24:18 UTC
Last seen:2025-12-19 16:03:55 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:raPEcac/iRoLngD5w5cfqp4f2tK5CFQ+eC8OSwfo+Qz:mPEcac/goLng+sCtI
TLSH T1C61285CC76E112BF2DA98E06F1F342BD9F0C85D0E5A68EB6D84488BEF97884C705D645
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i686293a3a492aef65a88cf5434ee66ad55875deb66885871c9199296e707fb17926 Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700a448a233d175276ab77aa4cf9fd63dd02f9e6fd5f4ee160ce99f177df7d27d11 Miraimirai ua-wget
http://41.231.37.153/rondo.sh487b5360fc1a9b326ab7cdece074614eb30e23bd0ff7b179cb121e29aac0edb31 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc8ccaa9a601ec1a1750338b8074d60609b53cde76135f1761fd705428dd195bb7 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68k9aedf0f1ae99ae01eed2d8edec1dd9f2a2257435a91c6a57d4b368946b0f1d18 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Verdict:
Adware
File Type:
unix shell
First seen:
2025-12-19T02:30:00Z UTC
Last seen:
2025-12-19T03:23:00Z UTC
Hits:
~10
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=d6ed1c87-1900-0000-0159-4765730b0000 pid=2931 /usr/bin/sudo guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936 /tmp/sample.bin write-file guuid=d6ed1c87-1900-0000-0159-4765730b0000 pid=2931->guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936 execve guuid=3c97078a-1900-0000-0159-47657a0b0000 pid=2938 /usr/bin/rm guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=3c97078a-1900-0000-0159-47657a0b0000 pid=2938 execve guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939 execve guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949 execve guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965 execve guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976 execve guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994 execve guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006 execve guuid=bfdbbca6-1900-0000-0159-4765ca0b0000 pid=3018 /usr/bin/killall guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=bfdbbca6-1900-0000-0159-4765ca0b0000 pid=3018 execve guuid=0f8884a7-1900-0000-0159-4765cb0b0000 pid=3019 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=0f8884a7-1900-0000-0159-4765cb0b0000 pid=3019 execve guuid=912fcfa9-1900-0000-0159-4765cc0b0000 pid=3020 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=912fcfa9-1900-0000-0159-4765cc0b0000 pid=3020 execve guuid=f0c73bac-1900-0000-0159-4765d20b0000 pid=3026 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=f0c73bac-1900-0000-0159-4765d20b0000 pid=3026 execve guuid=60c68aae-1900-0000-0159-4765dc0b0000 pid=3036 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=60c68aae-1900-0000-0159-4765dc0b0000 pid=3036 execve guuid=938eeab0-1900-0000-0159-4765e50b0000 pid=3045 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=938eeab0-1900-0000-0159-4765e50b0000 pid=3045 execve guuid=0c465fb3-1900-0000-0159-4765ef0b0000 pid=3055 /usr/bin/systemctl guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=0c465fb3-1900-0000-0159-4765ef0b0000 pid=3055 execve guuid=827b1cb5-1900-0000-0159-4765f50b0000 pid=3061 /usr/bin/systemctl guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=827b1cb5-1900-0000-0159-4765f50b0000 pid=3061 execve guuid=708a13b6-1900-0000-0159-4765fa0b0000 pid=3066 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=708a13b6-1900-0000-0159-4765fa0b0000 pid=3066 execve guuid=de75adb6-1900-0000-0159-4765fd0b0000 pid=3069 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=de75adb6-1900-0000-0159-4765fd0b0000 pid=3069 execve guuid=29ae12b7-1900-0000-0159-4765000c0000 pid=3072 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=29ae12b7-1900-0000-0159-4765000c0000 pid=3072 execve guuid=31d06db7-1900-0000-0159-4765020c0000 pid=3074 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=31d06db7-1900-0000-0159-4765020c0000 pid=3074 execve guuid=4c06cbb7-1900-0000-0159-4765050c0000 pid=3077 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=4c06cbb7-1900-0000-0159-4765050c0000 pid=3077 execve guuid=92ba26b8-1900-0000-0159-4765070c0000 pid=3079 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=92ba26b8-1900-0000-0159-4765070c0000 pid=3079 execve guuid=b1597eb8-1900-0000-0159-47650a0c0000 pid=3082 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=b1597eb8-1900-0000-0159-47650a0c0000 pid=3082 execve guuid=c0ccd2b8-1900-0000-0159-47650c0c0000 pid=3084 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=c0ccd2b8-1900-0000-0159-47650c0c0000 pid=3084 execve guuid=a60d31b9-1900-0000-0159-47650e0c0000 pid=3086 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=a60d31b9-1900-0000-0159-47650e0c0000 pid=3086 execve guuid=6dd083b9-1900-0000-0159-4765100c0000 pid=3088 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=6dd083b9-1900-0000-0159-4765100c0000 pid=3088 execve guuid=86d9e9b9-1900-0000-0159-4765130c0000 pid=3091 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=86d9e9b9-1900-0000-0159-4765130c0000 pid=3091 execve guuid=d7ee59ba-1900-0000-0159-4765150c0000 pid=3093 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=d7ee59ba-1900-0000-0159-4765150c0000 pid=3093 execve guuid=14e4b9ba-1900-0000-0159-4765190c0000 pid=3097 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=14e4b9ba-1900-0000-0159-4765190c0000 pid=3097 execve guuid=a0e72fbb-1900-0000-0159-47651a0c0000 pid=3098 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=a0e72fbb-1900-0000-0159-47651a0c0000 pid=3098 execve guuid=89fa90bb-1900-0000-0159-47651c0c0000 pid=3100 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=89fa90bb-1900-0000-0159-47651c0c0000 pid=3100 execve guuid=ee0bffbb-1900-0000-0159-47651f0c0000 pid=3103 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=ee0bffbb-1900-0000-0159-47651f0c0000 pid=3103 execve guuid=6f12a6bc-1900-0000-0159-4765220c0000 pid=3106 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=6f12a6bc-1900-0000-0159-4765220c0000 pid=3106 execve guuid=90b711bd-1900-0000-0159-4765240c0000 pid=3108 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=90b711bd-1900-0000-0159-4765240c0000 pid=3108 execve guuid=7e8278bd-1900-0000-0159-4765270c0000 pid=3111 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=7e8278bd-1900-0000-0159-4765270c0000 pid=3111 execve guuid=3323dbbd-1900-0000-0159-4765290c0000 pid=3113 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=3323dbbd-1900-0000-0159-4765290c0000 pid=3113 execve guuid=bb9f4abe-1900-0000-0159-47652c0c0000 pid=3116 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=bb9f4abe-1900-0000-0159-47652c0c0000 pid=3116 execve guuid=ff06aabe-1900-0000-0159-47652e0c0000 pid=3118 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=ff06aabe-1900-0000-0159-47652e0c0000 pid=3118 execve guuid=92211bbf-1900-0000-0159-4765300c0000 pid=3120 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=92211bbf-1900-0000-0159-4765300c0000 pid=3120 execve guuid=9d0f88bf-1900-0000-0159-4765310c0000 pid=3121 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=9d0f88bf-1900-0000-0159-4765310c0000 pid=3121 execve guuid=e3ebf3bf-1900-0000-0159-4765340c0000 pid=3124 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=e3ebf3bf-1900-0000-0159-4765340c0000 pid=3124 execve guuid=e4f77dc0-1900-0000-0159-4765380c0000 pid=3128 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=e4f77dc0-1900-0000-0159-4765380c0000 pid=3128 execve guuid=b296f0c0-1900-0000-0159-47653a0c0000 pid=3130 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=b296f0c0-1900-0000-0159-47653a0c0000 pid=3130 execve guuid=01b871c1-1900-0000-0159-47653c0c0000 pid=3132 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=01b871c1-1900-0000-0159-47653c0c0000 pid=3132 execve guuid=6c2bdbc1-1900-0000-0159-47653f0c0000 pid=3135 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=6c2bdbc1-1900-0000-0159-47653f0c0000 pid=3135 execve guuid=b58f32c2-1900-0000-0159-4765410c0000 pid=3137 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=b58f32c2-1900-0000-0159-4765410c0000 pid=3137 execve guuid=349989c2-1900-0000-0159-4765430c0000 pid=3139 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=349989c2-1900-0000-0159-4765430c0000 pid=3139 execve guuid=327be1c2-1900-0000-0159-4765450c0000 pid=3141 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=327be1c2-1900-0000-0159-4765450c0000 pid=3141 execve guuid=c0536ac3-1900-0000-0159-4765470c0000 pid=3143 /usr/bin/ls guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=c0536ac3-1900-0000-0159-4765470c0000 pid=3143 execve guuid=e4d1c5c3-1900-0000-0159-4765480c0000 pid=3144 /usr/bin/systemctl guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=e4d1c5c3-1900-0000-0159-4765480c0000 pid=3144 execve guuid=bb7c7b3f-1a00-0000-0159-4765f20c0000 pid=3314 /usr/bin/mount write-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=bb7c7b3f-1a00-0000-0159-4765f20c0000 pid=3314 execve guuid=f9f50a41-1a00-0000-0159-4765f80c0000 pid=3320 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=f9f50a41-1a00-0000-0159-4765f80c0000 pid=3320 execve guuid=1cc0a143-1a00-0000-0159-4765040d0000 pid=3332 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=1cc0a143-1a00-0000-0159-4765040d0000 pid=3332 execve guuid=f8bbea43-1a00-0000-0159-4765060d0000 pid=3334 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=f8bbea43-1a00-0000-0159-4765060d0000 pid=3334 execve guuid=65963844-1a00-0000-0159-4765070d0000 pid=3335 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=65963844-1a00-0000-0159-4765070d0000 pid=3335 execve guuid=75a78544-1a00-0000-0159-4765090d0000 pid=3337 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=75a78544-1a00-0000-0159-4765090d0000 pid=3337 execve guuid=7f8bc744-1a00-0000-0159-47650a0d0000 pid=3338 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=7f8bc744-1a00-0000-0159-47650a0d0000 pid=3338 execve guuid=555f0e45-1a00-0000-0159-47650c0d0000 pid=3340 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=555f0e45-1a00-0000-0159-47650c0d0000 pid=3340 execve guuid=d6755545-1a00-0000-0159-47650e0d0000 pid=3342 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=d6755545-1a00-0000-0159-47650e0d0000 pid=3342 execve guuid=5360a045-1a00-0000-0159-4765100d0000 pid=3344 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=5360a045-1a00-0000-0159-4765100d0000 pid=3344 execve guuid=5646e045-1a00-0000-0159-4765120d0000 pid=3346 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=5646e045-1a00-0000-0159-4765120d0000 pid=3346 execve guuid=aaa6084f-1a00-0000-0159-4765210d0000 pid=3361 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=aaa6084f-1a00-0000-0159-4765210d0000 pid=3361 execve guuid=f934704f-1a00-0000-0159-4765230d0000 pid=3363 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=f934704f-1a00-0000-0159-4765230d0000 pid=3363 execve guuid=00980650-1a00-0000-0159-4765240d0000 pid=3364 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=00980650-1a00-0000-0159-4765240d0000 pid=3364 execve guuid=df626350-1a00-0000-0159-4765250d0000 pid=3365 /usr/bin/mkdir guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=df626350-1a00-0000-0159-4765250d0000 pid=3365 execve guuid=63fdb650-1a00-0000-0159-4765260d0000 pid=3366 /usr/bin/dash guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=63fdb650-1a00-0000-0159-4765260d0000 pid=3366 clone guuid=abc01251-1a00-0000-0159-47652a0d0000 pid=3370 /usr/bin/rm guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=abc01251-1a00-0000-0159-47652a0d0000 pid=3370 execve guuid=62cf5451-1a00-0000-0159-47652c0d0000 pid=3372 /usr/bin/wget net send-data write-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=62cf5451-1a00-0000-0159-47652c0d0000 pid=3372 execve guuid=3cdbd56a-1a00-0000-0159-47654b0d0000 pid=3403 /usr/bin/cat guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=3cdbd56a-1a00-0000-0159-47654b0d0000 pid=3403 execve guuid=6d59166b-1a00-0000-0159-47654d0d0000 pid=3405 /usr/bin/rm delete-file guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=6d59166b-1a00-0000-0159-47654d0d0000 pid=3405 execve guuid=10604f6b-1a00-0000-0159-47654f0d0000 pid=3407 /usr/bin/chmod guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=10604f6b-1a00-0000-0159-47654f0d0000 pid=3407 execve guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408 execve guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416 execve guuid=9742ac71-1a00-0000-0159-4765630d0000 pid=3427 /usr/bin/killall guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=9742ac71-1a00-0000-0159-4765630d0000 pid=3427 execve guuid=21f54872-1a00-0000-0159-4765660d0000 pid=3430 /usr/bin/pgrep guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=21f54872-1a00-0000-0159-4765660d0000 pid=3430 execve guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439 /usr/bin/sudo net guuid=2cc89f89-1900-0000-0159-4765780b0000 pid=2936->guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=e06c608d-1900-0000-0159-4765810b0000 pid=2945 /usr/bin/killall guuid=35bb9e8a-1900-0000-0159-47657b0b0000 pid=2939->guuid=e06c608d-1900-0000-0159-4765810b0000 pid=2945 execve guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=2d1e0291-1900-0000-0159-4765880b0000 pid=2952 /usr/bin/pgrep guuid=57ac878f-1900-0000-0159-4765850b0000 pid=2949->guuid=2d1e0291-1900-0000-0159-4765880b0000 pid=2952 execve guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=9f9f5397-1900-0000-0159-47659b0b0000 pid=2971 /usr/bin/pgrep guuid=613c8795-1900-0000-0159-4765950b0000 pid=2965->guuid=9f9f5397-1900-0000-0159-47659b0b0000 pid=2971 execve guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=c8ae109b-1900-0000-0159-4765a50b0000 pid=2981 /usr/bin/pgrep guuid=e3bee299-1900-0000-0159-4765a00b0000 pid=2976->guuid=c8ae109b-1900-0000-0159-4765a50b0000 pid=2981 execve guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=472f2aa0-1900-0000-0159-4765b60b0000 pid=2998 /usr/bin/pgrep guuid=d0701a9f-1900-0000-0159-4765b20b0000 pid=2994->guuid=472f2aa0-1900-0000-0159-4765b60b0000 pid=2998 execve guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=738e14a4-1900-0000-0159-4765c50b0000 pid=3013 /usr/bin/pgrep guuid=e1258aa2-1900-0000-0159-4765be0b0000 pid=3006->guuid=738e14a4-1900-0000-0159-4765c50b0000 pid=3013 execve guuid=066904c4-1900-0000-0159-4765490c0000 pid=3145 /usr/bin/basename guuid=e4d1c5c3-1900-0000-0159-4765480c0000 pid=3144->guuid=066904c4-1900-0000-0159-4765490c0000 pid=3145 execve guuid=37be43c4-1900-0000-0159-47654a0c0000 pid=3146 /usr/bin/basename guuid=e4d1c5c3-1900-0000-0159-4765480c0000 pid=3144->guuid=37be43c4-1900-0000-0159-47654a0c0000 pid=3146 execve guuid=69888fc4-1900-0000-0159-47654b0c0000 pid=3147 /usr/bin/dash guuid=e4d1c5c3-1900-0000-0159-4765480c0000 pid=3144->guuid=69888fc4-1900-0000-0159-47654b0c0000 pid=3147 clone guuid=31eb98c4-1900-0000-0159-47654c0c0000 pid=3148 /usr/bin/systemctl guuid=69888fc4-1900-0000-0159-47654b0c0000 pid=3147->guuid=31eb98c4-1900-0000-0159-47654c0c0000 pid=3148 execve guuid=df149dc4-1900-0000-0159-47654d0c0000 pid=3149 /usr/bin/sed guuid=69888fc4-1900-0000-0159-47654b0c0000 pid=3147->guuid=df149dc4-1900-0000-0159-47654d0c0000 pid=3149 execve guuid=0fdfc550-1a00-0000-0159-4765280d0000 pid=3368 /usr/bin/chmod guuid=63fdb650-1a00-0000-0159-4765260d0000 pid=3366->guuid=0fdfc550-1a00-0000-0159-4765280d0000 pid=3368 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=62cf5451-1a00-0000-0159-47652c0d0000 pid=3372->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=2d72ba6c-1a00-0000-0159-4765530d0000 pid=3411 /usr/bin/killall guuid=d17e856b-1a00-0000-0159-4765500d0000 pid=3408->guuid=2d72ba6c-1a00-0000-0159-4765530d0000 pid=3411 execve guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=15451d6f-1a00-0000-0159-47655c0d0000 pid=3420 /usr/bin/pgrep guuid=90b8ca6d-1a00-0000-0159-4765580d0000 pid=3416->guuid=15451d6f-1a00-0000-0159-47655c0d0000 pid=3420 execve guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b751af75-1a00-0000-0159-4765740d0000 pid=3444 /usr/bin/lib/rondo guuid=19688174-1a00-0000-0159-47656f0d0000 pid=3439->guuid=b751af75-1a00-0000-0159-4765740d0000 pid=3444 execve guuid=f535c575-1a00-0000-0159-4765750d0000 pid=3445 /usr/bin/lib/rondo write-file zombie guuid=b751af75-1a00-0000-0159-4765740d0000 pid=3444->guuid=f535c575-1a00-0000-0159-4765750d0000 pid=3445 clone guuid=5063d075-1a00-0000-0159-4765770d0000 pid=3447 /usr/bin/lib/rondo write-file zombie guuid=f535c575-1a00-0000-0159-4765750d0000 pid=3445->guuid=5063d075-1a00-0000-0159-4765770d0000 pid=3447 clone guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449 /usr/lib/systemd/ivhlxem delete-file net send-data write-config write-file zombie guuid=5063d075-1a00-0000-0159-4765770d0000 pid=3447->guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449 clone guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->c6d3c8d1-ccce-5272-b764-c5a3ff34618d con guuid=1eabbb78-1a00-0000-0159-47657d0d0000 pid=3453 /usr/lib/systemd/ivhlxem write-file guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->guuid=1eabbb78-1a00-0000-0159-47657d0d0000 pid=3453 clone guuid=d6893079-1a00-0000-0159-4765800d0000 pid=3456 /usr/lib/systemd/ivhlxem write-file guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->guuid=d6893079-1a00-0000-0159-4765800d0000 pid=3456 clone guuid=c6e53579-1a00-0000-0159-4765810d0000 pid=3457 /usr/lib/systemd/ivhlxem write-file guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->guuid=c6e53579-1a00-0000-0159-4765810d0000 pid=3457 clone guuid=36ab69ea-1b00-0000-0159-4765220f0000 pid=3874 /usr/lib/systemd/ivhlxem write-file guuid=11f33876-1a00-0000-0159-4765790d0000 pid=3449->guuid=36ab69ea-1b00-0000-0159-4765220f0000 pid=3874 clone guuid=8d0fc978-1a00-0000-0159-47657e0d0000 pid=3454 /usr/bin/dash guuid=1eabbb78-1a00-0000-0159-47657d0d0000 pid=3453->guuid=8d0fc978-1a00-0000-0159-47657e0d0000 pid=3454 execve guuid=0a2d0779-1a00-0000-0159-47657f0d0000 pid=3455 /usr/bin/systemctl guuid=8d0fc978-1a00-0000-0159-47657e0d0000 pid=3454->guuid=0a2d0779-1a00-0000-0159-47657f0d0000 pid=3455 execve guuid=28d34c7a-1a00-0000-0159-4765860d0000 pid=3462 /usr/bin/systemctl guuid=8d0fc978-1a00-0000-0159-47657e0d0000 pid=3454->guuid=28d34c7a-1a00-0000-0159-4765860d0000 pid=3462 execve guuid=c972687b-1a00-0000-0159-47658a0d0000 pid=3466 /usr/sbin/update-rc.d guuid=8d0fc978-1a00-0000-0159-47657e0d0000 pid=3454->guuid=c972687b-1a00-0000-0159-47658a0d0000 pid=3466 execve guuid=d24c7aea-1b00-0000-0159-4765230f0000 pid=3875 /usr/bin/dash guuid=36ab69ea-1b00-0000-0159-4765220f0000 pid=3874->guuid=d24c7aea-1b00-0000-0159-4765230f0000 pid=3875 execve guuid=86c7c8ea-1b00-0000-0159-4765240f0000 pid=3876 /usr/bin/softirq mprotect-exec guuid=d24c7aea-1b00-0000-0159-4765230f0000 pid=3875->guuid=86c7c8ea-1b00-0000-0159-4765240f0000 pid=3876 execve guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877 /usr/bin/softirq net send-data zombie guuid=86c7c8ea-1b00-0000-0159-4765240f0000 pid=3876->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3878 /usr/bin/softirq write-file zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3878 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3879 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3879 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3880 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3880 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3881 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3881 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3882 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3882 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3883 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3883 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3884 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3884 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3885 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3885 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3886 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3886 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3887 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3887 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3888 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3888 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3889 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3889 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3890 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3890 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3891 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3891 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3892 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3892 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3893 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3893 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3894 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3894 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3895 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3895 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3896 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3896 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3897 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3897 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3898 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3898 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3899 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3899 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3900 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3900 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3901 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3901 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3902 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3902 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3903 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3903 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3904 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3904 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3905 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3905 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3906 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3906 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3907 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3907 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3908 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3908 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3909 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3909 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3910 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3910 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3911 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3911 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3912 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3912 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3913 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3913 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3914 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3914 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3915 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3915 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3916 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3916 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3917 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3917 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3918 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3918 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3919 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3919 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3920 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3920 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3921 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3921 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3922 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3922 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3923 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3923 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3924 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3924 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3925 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3925 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3926 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3926 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3927 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3927 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3928 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3928 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3929 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3929 clone guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3930 /usr/bin/softirq zombie guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3877->guuid=0b4db0ed-1b00-0000-0159-4765250f0000 pid=3930 clone
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-12-19 05:25:29 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 63b7f1a4db8928360637160e67622eae244656df1c090c6f2ac8dc6f12ae5c14

(this sample)

  
Delivery method
Distributed via web download

Comments