MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d29e4352ae66c81057ee4ca4434857ca062ca4617442d969acd42adf46de0e8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 6d29e4352ae66c81057ee4ca4434857ca062ca4617442d969acd42adf46de0e8
SHA3-384 hash: 836e693549c6221d0feb2185e29e91d044489f3fcb9eb876ffd30ae25970b952913bfcfd04774673d3a4c392bcadc265
SHA1 hash: ccc5c3cacece29f225526b66afbaea000cb47958
MD5 hash: 246a5fa21f25f4461a89ca53040f4600
humanhash: purple-tennis-oranges-cold
File name:massload
Download: download sample
File size:3'191 bytes
First seen:2025-11-21 20:38:35 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:QvZi4whMSGdnHxDUPUq5EIIICmvYTndPrHcYHcPBr5JMIVMICiz8Wv+156fPgf9:AZijlZz3C1
TLSH T18E61D7A83BD1573B82C68F47F221BA697B0F99CED8850ED865DF68F5CAAC8047031517
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.146.23.141/mips8940a2d83740ea74154a6ede90488eb87e10ca22f092597e9c27f00ae380f8cb Miraielf geofenced mips mirai ua-wget USA
http://103.146.23.141/mpsl5add3655c138947e54f6e93f583e7704a9a33ea87a1c76eb5322358d9d6d992e Miraielf geofenced mips mirai ua-wget USA
http://103.146.23.141/arm4fe97cfdc07d40ad61d688edb30b6d7fdb500c0d6db85f7d1f9e639173922f4ab Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/arm55b94659fba807f800bca96cbf40d6be1da4306e21b0f6f2579c41f70585690e9 Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/arm721c9e1189e8447ddb5e233401d47ac4be0321d988e081a75a074d4414cf1a5a8 Miraiarm elf geofenced mirai ua-wget USA
http://103.146.23.141/powerpc102596c6c0ac0201bb8eff29e1e210540f192026927a79e23d27b11dc25e4b33 Miraielf geofenced mirai PowerPC ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-11-21T18:59:00Z UTC
Last seen:
2025-11-22T08:32:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=38da9d61-1900-0000-e18f-075d530f0000 pid=3923 /usr/bin/sudo guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933 /tmp/sample.bin guuid=38da9d61-1900-0000-e18f-075d530f0000 pid=3923->guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933 execve guuid=33ba9e63-1900-0000-e18f-075d600f0000 pid=3936 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=33ba9e63-1900-0000-e18f-075d600f0000 pid=3936 execve guuid=04114264-1900-0000-e18f-075d620f0000 pid=3938 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=04114264-1900-0000-e18f-075d620f0000 pid=3938 execve guuid=a3909364-1900-0000-e18f-075d640f0000 pid=3940 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=a3909364-1900-0000-e18f-075d640f0000 pid=3940 execve guuid=35170765-1900-0000-e18f-075d660f0000 pid=3942 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=35170765-1900-0000-e18f-075d660f0000 pid=3942 execve guuid=c1b67265-1900-0000-e18f-075d690f0000 pid=3945 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c1b67265-1900-0000-e18f-075d690f0000 pid=3945 execve guuid=b7c1d865-1900-0000-e18f-075d6b0f0000 pid=3947 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=b7c1d865-1900-0000-e18f-075d6b0f0000 pid=3947 execve guuid=5cf53966-1900-0000-e18f-075d6d0f0000 pid=3949 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=5cf53966-1900-0000-e18f-075d6d0f0000 pid=3949 execve guuid=c77ea866-1900-0000-e18f-075d6e0f0000 pid=3950 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c77ea866-1900-0000-e18f-075d6e0f0000 pid=3950 execve guuid=0ec61867-1900-0000-e18f-075d700f0000 pid=3952 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=0ec61867-1900-0000-e18f-075d700f0000 pid=3952 execve guuid=ddf8e467-1900-0000-e18f-075d750f0000 pid=3957 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ddf8e467-1900-0000-e18f-075d750f0000 pid=3957 execve guuid=ede74068-1900-0000-e18f-075d780f0000 pid=3960 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ede74068-1900-0000-e18f-075d780f0000 pid=3960 execve guuid=28c1a868-1900-0000-e18f-075d7b0f0000 pid=3963 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=28c1a868-1900-0000-e18f-075d7b0f0000 pid=3963 execve guuid=09137769-1900-0000-e18f-075d7f0f0000 pid=3967 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=09137769-1900-0000-e18f-075d7f0f0000 pid=3967 execve guuid=74a2e069-1900-0000-e18f-075d830f0000 pid=3971 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=74a2e069-1900-0000-e18f-075d830f0000 pid=3971 execve guuid=37b2406a-1900-0000-e18f-075d860f0000 pid=3974 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=37b2406a-1900-0000-e18f-075d860f0000 pid=3974 execve guuid=3b0da86a-1900-0000-e18f-075d880f0000 pid=3976 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3b0da86a-1900-0000-e18f-075d880f0000 pid=3976 execve guuid=df480a6b-1900-0000-e18f-075d8b0f0000 pid=3979 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=df480a6b-1900-0000-e18f-075d8b0f0000 pid=3979 execve guuid=cdc16d6b-1900-0000-e18f-075d8d0f0000 pid=3981 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=cdc16d6b-1900-0000-e18f-075d8d0f0000 pid=3981 execve guuid=0c98dc6b-1900-0000-e18f-075d900f0000 pid=3984 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=0c98dc6b-1900-0000-e18f-075d900f0000 pid=3984 execve guuid=8570756c-1900-0000-e18f-075d940f0000 pid=3988 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8570756c-1900-0000-e18f-075d940f0000 pid=3988 execve guuid=858c1f6d-1900-0000-e18f-075d970f0000 pid=3991 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=858c1f6d-1900-0000-e18f-075d970f0000 pid=3991 execve guuid=68b47d6d-1900-0000-e18f-075d990f0000 pid=3993 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=68b47d6d-1900-0000-e18f-075d990f0000 pid=3993 execve guuid=710af56d-1900-0000-e18f-075d9c0f0000 pid=3996 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=710af56d-1900-0000-e18f-075d9c0f0000 pid=3996 execve guuid=4f6b696e-1900-0000-e18f-075d9e0f0000 pid=3998 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4f6b696e-1900-0000-e18f-075d9e0f0000 pid=3998 execve guuid=7484ca6e-1900-0000-e18f-075da10f0000 pid=4001 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7484ca6e-1900-0000-e18f-075da10f0000 pid=4001 execve guuid=02692e6f-1900-0000-e18f-075da40f0000 pid=4004 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=02692e6f-1900-0000-e18f-075da40f0000 pid=4004 execve guuid=e4b8896f-1900-0000-e18f-075da60f0000 pid=4006 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e4b8896f-1900-0000-e18f-075da60f0000 pid=4006 execve guuid=49dedd6f-1900-0000-e18f-075daa0f0000 pid=4010 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=49dedd6f-1900-0000-e18f-075daa0f0000 pid=4010 execve guuid=8b913870-1900-0000-e18f-075dae0f0000 pid=4014 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8b913870-1900-0000-e18f-075dae0f0000 pid=4014 execve guuid=145e8b70-1900-0000-e18f-075db00f0000 pid=4016 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=145e8b70-1900-0000-e18f-075db00f0000 pid=4016 execve guuid=8c8ce870-1900-0000-e18f-075db20f0000 pid=4018 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8c8ce870-1900-0000-e18f-075db20f0000 pid=4018 execve guuid=9a404671-1900-0000-e18f-075db60f0000 pid=4022 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9a404671-1900-0000-e18f-075db60f0000 pid=4022 execve guuid=4acca471-1900-0000-e18f-075dba0f0000 pid=4026 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4acca471-1900-0000-e18f-075dba0f0000 pid=4026 execve guuid=4ce30272-1900-0000-e18f-075dbc0f0000 pid=4028 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4ce30272-1900-0000-e18f-075dbc0f0000 pid=4028 execve guuid=7f4b6872-1900-0000-e18f-075dbf0f0000 pid=4031 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7f4b6872-1900-0000-e18f-075dbf0f0000 pid=4031 execve guuid=2c9fc772-1900-0000-e18f-075dc10f0000 pid=4033 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=2c9fc772-1900-0000-e18f-075dc10f0000 pid=4033 execve guuid=29342673-1900-0000-e18f-075dc40f0000 pid=4036 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=29342673-1900-0000-e18f-075dc40f0000 pid=4036 execve guuid=6ae07f73-1900-0000-e18f-075dc60f0000 pid=4038 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=6ae07f73-1900-0000-e18f-075dc60f0000 pid=4038 execve guuid=cde5d973-1900-0000-e18f-075dc80f0000 pid=4040 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=cde5d973-1900-0000-e18f-075dc80f0000 pid=4040 execve guuid=a2da4374-1900-0000-e18f-075dcc0f0000 pid=4044 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=a2da4374-1900-0000-e18f-075dcc0f0000 pid=4044 execve guuid=7bad9f74-1900-0000-e18f-075dd00f0000 pid=4048 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7bad9f74-1900-0000-e18f-075dd00f0000 pid=4048 execve guuid=1e80fe74-1900-0000-e18f-075dd20f0000 pid=4050 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=1e80fe74-1900-0000-e18f-075dd20f0000 pid=4050 execve guuid=4c1d5d75-1900-0000-e18f-075dd40f0000 pid=4052 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4c1d5d75-1900-0000-e18f-075dd40f0000 pid=4052 execve guuid=bacfbe75-1900-0000-e18f-075dd70f0000 pid=4055 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=bacfbe75-1900-0000-e18f-075dd70f0000 pid=4055 execve guuid=d4572076-1900-0000-e18f-075dd90f0000 pid=4057 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=d4572076-1900-0000-e18f-075dd90f0000 pid=4057 execve guuid=27fd8076-1900-0000-e18f-075ddc0f0000 pid=4060 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=27fd8076-1900-0000-e18f-075ddc0f0000 pid=4060 execve guuid=9ce9d676-1900-0000-e18f-075dde0f0000 pid=4062 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9ce9d676-1900-0000-e18f-075dde0f0000 pid=4062 execve guuid=20802c77-1900-0000-e18f-075de20f0000 pid=4066 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=20802c77-1900-0000-e18f-075de20f0000 pid=4066 execve guuid=0a5c8677-1900-0000-e18f-075de60f0000 pid=4070 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=0a5c8677-1900-0000-e18f-075de60f0000 pid=4070 execve guuid=aea6ea77-1900-0000-e18f-075de80f0000 pid=4072 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=aea6ea77-1900-0000-e18f-075de80f0000 pid=4072 execve guuid=e7044478-1900-0000-e18f-075dea0f0000 pid=4074 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e7044478-1900-0000-e18f-075dea0f0000 pid=4074 execve guuid=a86da178-1900-0000-e18f-075dee0f0000 pid=4078 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=a86da178-1900-0000-e18f-075dee0f0000 pid=4078 execve guuid=66f60779-1900-0000-e18f-075df20f0000 pid=4082 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=66f60779-1900-0000-e18f-075df20f0000 pid=4082 execve guuid=ae607279-1900-0000-e18f-075df30f0000 pid=4083 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ae607279-1900-0000-e18f-075df30f0000 pid=4083 execve guuid=9955d279-1900-0000-e18f-075df60f0000 pid=4086 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9955d279-1900-0000-e18f-075df60f0000 pid=4086 execve guuid=b5d1347a-1900-0000-e18f-075df80f0000 pid=4088 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=b5d1347a-1900-0000-e18f-075df80f0000 pid=4088 execve guuid=5e69927a-1900-0000-e18f-075dfb0f0000 pid=4091 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=5e69927a-1900-0000-e18f-075dfb0f0000 pid=4091 execve guuid=1a471b7b-1900-0000-e18f-075dfe0f0000 pid=4094 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=1a471b7b-1900-0000-e18f-075dfe0f0000 pid=4094 execve guuid=40777d7b-1900-0000-e18f-075d00100000 pid=4096 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=40777d7b-1900-0000-e18f-075d00100000 pid=4096 execve guuid=3c9cd17b-1900-0000-e18f-075d02100000 pid=4098 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3c9cd17b-1900-0000-e18f-075d02100000 pid=4098 execve guuid=b10f1d7c-1900-0000-e18f-075d06100000 pid=4102 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=b10f1d7c-1900-0000-e18f-075d06100000 pid=4102 execve guuid=1789767c-1900-0000-e18f-075d07100000 pid=4103 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=1789767c-1900-0000-e18f-075d07100000 pid=4103 execve guuid=ec08d27c-1900-0000-e18f-075d0b100000 pid=4107 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ec08d27c-1900-0000-e18f-075d0b100000 pid=4107 execve guuid=5e224f7d-1900-0000-e18f-075d0f100000 pid=4111 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=5e224f7d-1900-0000-e18f-075d0f100000 pid=4111 execve guuid=4e86a17d-1900-0000-e18f-075d10100000 pid=4112 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4e86a17d-1900-0000-e18f-075d10100000 pid=4112 execve guuid=9683f97d-1900-0000-e18f-075d14100000 pid=4116 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9683f97d-1900-0000-e18f-075d14100000 pid=4116 execve guuid=6e715c7e-1900-0000-e18f-075d17100000 pid=4119 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=6e715c7e-1900-0000-e18f-075d17100000 pid=4119 execve guuid=94b6ad7e-1900-0000-e18f-075d19100000 pid=4121 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=94b6ad7e-1900-0000-e18f-075d19100000 pid=4121 execve guuid=591d067f-1900-0000-e18f-075d1c100000 pid=4124 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=591d067f-1900-0000-e18f-075d1c100000 pid=4124 execve guuid=6beb5a7f-1900-0000-e18f-075d1e100000 pid=4126 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=6beb5a7f-1900-0000-e18f-075d1e100000 pid=4126 execve guuid=3bb6b57f-1900-0000-e18f-075d20100000 pid=4128 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3bb6b57f-1900-0000-e18f-075d20100000 pid=4128 execve guuid=4cf11680-1900-0000-e18f-075d23100000 pid=4131 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4cf11680-1900-0000-e18f-075d23100000 pid=4131 execve guuid=49b87d80-1900-0000-e18f-075d25100000 pid=4133 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=49b87d80-1900-0000-e18f-075d25100000 pid=4133 execve guuid=bfc7e580-1900-0000-e18f-075d27100000 pid=4135 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=bfc7e580-1900-0000-e18f-075d27100000 pid=4135 execve guuid=4bf86681-1900-0000-e18f-075d28100000 pid=4136 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4bf86681-1900-0000-e18f-075d28100000 pid=4136 execve guuid=ce6ee981-1900-0000-e18f-075d29100000 pid=4137 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ce6ee981-1900-0000-e18f-075d29100000 pid=4137 execve guuid=76a44782-1900-0000-e18f-075d2d100000 pid=4141 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=76a44782-1900-0000-e18f-075d2d100000 pid=4141 execve guuid=655fa782-1900-0000-e18f-075d31100000 pid=4145 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=655fa782-1900-0000-e18f-075d31100000 pid=4145 execve guuid=81af0283-1900-0000-e18f-075d32100000 pid=4146 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=81af0283-1900-0000-e18f-075d32100000 pid=4146 execve guuid=5dd65983-1900-0000-e18f-075d34100000 pid=4148 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=5dd65983-1900-0000-e18f-075d34100000 pid=4148 execve guuid=88b5b283-1900-0000-e18f-075d36100000 pid=4150 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=88b5b283-1900-0000-e18f-075d36100000 pid=4150 execve guuid=fdb20b84-1900-0000-e18f-075d38100000 pid=4152 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=fdb20b84-1900-0000-e18f-075d38100000 pid=4152 execve guuid=dfc66284-1900-0000-e18f-075d3a100000 pid=4154 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=dfc66284-1900-0000-e18f-075d3a100000 pid=4154 execve guuid=82d4cc84-1900-0000-e18f-075d3c100000 pid=4156 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=82d4cc84-1900-0000-e18f-075d3c100000 pid=4156 execve guuid=ad012d85-1900-0000-e18f-075d3f100000 pid=4159 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ad012d85-1900-0000-e18f-075d3f100000 pid=4159 execve guuid=214a8e85-1900-0000-e18f-075d41100000 pid=4161 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=214a8e85-1900-0000-e18f-075d41100000 pid=4161 execve guuid=925aef85-1900-0000-e18f-075d45100000 pid=4165 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=925aef85-1900-0000-e18f-075d45100000 pid=4165 execve guuid=8fb45686-1900-0000-e18f-075d46100000 pid=4166 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8fb45686-1900-0000-e18f-075d46100000 pid=4166 execve guuid=096bbe86-1900-0000-e18f-075d4a100000 pid=4170 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=096bbe86-1900-0000-e18f-075d4a100000 pid=4170 execve guuid=e7b22987-1900-0000-e18f-075d4c100000 pid=4172 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e7b22987-1900-0000-e18f-075d4c100000 pid=4172 execve guuid=10df8b87-1900-0000-e18f-075d4f100000 pid=4175 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=10df8b87-1900-0000-e18f-075d4f100000 pid=4175 execve guuid=c34eec87-1900-0000-e18f-075d51100000 pid=4177 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c34eec87-1900-0000-e18f-075d51100000 pid=4177 execve guuid=b8b34e88-1900-0000-e18f-075d54100000 pid=4180 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=b8b34e88-1900-0000-e18f-075d54100000 pid=4180 execve guuid=8453ae88-1900-0000-e18f-075d56100000 pid=4182 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8453ae88-1900-0000-e18f-075d56100000 pid=4182 execve guuid=46550f89-1900-0000-e18f-075d58100000 pid=4184 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=46550f89-1900-0000-e18f-075d58100000 pid=4184 execve guuid=f0c67a89-1900-0000-e18f-075d5c100000 pid=4188 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=f0c67a89-1900-0000-e18f-075d5c100000 pid=4188 execve guuid=13c1ed89-1900-0000-e18f-075d5d100000 pid=4189 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=13c1ed89-1900-0000-e18f-075d5d100000 pid=4189 execve guuid=3b81528a-1900-0000-e18f-075d61100000 pid=4193 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3b81528a-1900-0000-e18f-075d61100000 pid=4193 execve guuid=89c5c78a-1900-0000-e18f-075d62100000 pid=4194 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=89c5c78a-1900-0000-e18f-075d62100000 pid=4194 execve guuid=e440228b-1900-0000-e18f-075d65100000 pid=4197 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e440228b-1900-0000-e18f-075d65100000 pid=4197 execve guuid=7650848b-1900-0000-e18f-075d67100000 pid=4199 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7650848b-1900-0000-e18f-075d67100000 pid=4199 execve guuid=4e7ddb8b-1900-0000-e18f-075d69100000 pid=4201 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4e7ddb8b-1900-0000-e18f-075d69100000 pid=4201 execve guuid=a362348c-1900-0000-e18f-075d6b100000 pid=4203 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=a362348c-1900-0000-e18f-075d6b100000 pid=4203 execve guuid=b240858c-1900-0000-e18f-075d6d100000 pid=4205 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=b240858c-1900-0000-e18f-075d6d100000 pid=4205 execve guuid=be1bdc8c-1900-0000-e18f-075d6f100000 pid=4207 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=be1bdc8c-1900-0000-e18f-075d6f100000 pid=4207 execve guuid=3b96398d-1900-0000-e18f-075d71100000 pid=4209 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3b96398d-1900-0000-e18f-075d71100000 pid=4209 execve guuid=6308968d-1900-0000-e18f-075d72100000 pid=4210 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=6308968d-1900-0000-e18f-075d72100000 pid=4210 execve guuid=ab19e88d-1900-0000-e18f-075d73100000 pid=4211 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ab19e88d-1900-0000-e18f-075d73100000 pid=4211 execve guuid=bd4b408e-1900-0000-e18f-075d74100000 pid=4212 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=bd4b408e-1900-0000-e18f-075d74100000 pid=4212 execve guuid=adf7998e-1900-0000-e18f-075d75100000 pid=4213 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=adf7998e-1900-0000-e18f-075d75100000 pid=4213 execve guuid=561cef8e-1900-0000-e18f-075d76100000 pid=4214 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=561cef8e-1900-0000-e18f-075d76100000 pid=4214 execve guuid=bcee408f-1900-0000-e18f-075d77100000 pid=4215 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=bcee408f-1900-0000-e18f-075d77100000 pid=4215 execve guuid=2131cc8f-1900-0000-e18f-075d78100000 pid=4216 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=2131cc8f-1900-0000-e18f-075d78100000 pid=4216 execve guuid=92412490-1900-0000-e18f-075d79100000 pid=4217 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=92412490-1900-0000-e18f-075d79100000 pid=4217 execve guuid=34be7d90-1900-0000-e18f-075d7a100000 pid=4218 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=34be7d90-1900-0000-e18f-075d7a100000 pid=4218 execve guuid=4c9adf90-1900-0000-e18f-075d7e100000 pid=4222 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=4c9adf90-1900-0000-e18f-075d7e100000 pid=4222 execve guuid=1323cc91-1900-0000-e18f-075d83100000 pid=4227 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=1323cc91-1900-0000-e18f-075d83100000 pid=4227 execve guuid=23202d92-1900-0000-e18f-075d85100000 pid=4229 /usr/bin/ls guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=23202d92-1900-0000-e18f-075d85100000 pid=4229 execve guuid=7ad09892-1900-0000-e18f-075d89100000 pid=4233 /usr/bin/rm guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7ad09892-1900-0000-e18f-075d89100000 pid=4233 execve guuid=40dfd392-1900-0000-e18f-075d8d100000 pid=4237 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=40dfd392-1900-0000-e18f-075d8d100000 pid=4237 execve guuid=d87fd9d7-1900-0000-e18f-075d76110000 pid=4470 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=d87fd9d7-1900-0000-e18f-075d76110000 pid=4470 execve guuid=13b334d8-1900-0000-e18f-075d77110000 pid=4471 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=13b334d8-1900-0000-e18f-075d77110000 pid=4471 clone guuid=eab7dad8-1900-0000-e18f-075d79110000 pid=4473 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=eab7dad8-1900-0000-e18f-075d79110000 pid=4473 execve guuid=f348c12c-1a00-0000-e18f-075da7120000 pid=4775 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=f348c12c-1a00-0000-e18f-075da7120000 pid=4775 execve guuid=a1ae332d-1a00-0000-e18f-075da9120000 pid=4777 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=a1ae332d-1a00-0000-e18f-075da9120000 pid=4777 clone guuid=dcba672e-1a00-0000-e18f-075dae120000 pid=4782 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=dcba672e-1a00-0000-e18f-075dae120000 pid=4782 execve guuid=23065b7a-1a00-0000-e18f-075de6120000 pid=4838 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=23065b7a-1a00-0000-e18f-075de6120000 pid=4838 execve guuid=77b2c17a-1a00-0000-e18f-075de8120000 pid=4840 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=77b2c17a-1a00-0000-e18f-075de8120000 pid=4840 clone guuid=69f7f27c-1a00-0000-e18f-075df1120000 pid=4849 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=69f7f27c-1a00-0000-e18f-075df1120000 pid=4849 execve guuid=0645e5bf-1a00-0000-e18f-075d7a130000 pid=4986 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=0645e5bf-1a00-0000-e18f-075d7a130000 pid=4986 execve guuid=197625c0-1a00-0000-e18f-075d7b130000 pid=4987 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=197625c0-1a00-0000-e18f-075d7b130000 pid=4987 clone guuid=094aaec0-1a00-0000-e18f-075d7e130000 pid=4990 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=094aaec0-1a00-0000-e18f-075d7e130000 pid=4990 execve guuid=8f5f7d00-1b00-0000-e18f-075d05140000 pid=5125 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8f5f7d00-1b00-0000-e18f-075d05140000 pid=5125 execve guuid=670cb000-1b00-0000-e18f-075d07140000 pid=5127 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=670cb000-1b00-0000-e18f-075d07140000 pid=5127 clone guuid=fd3ef502-1b00-0000-e18f-075d0e140000 pid=5134 /usr/bin/wget net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=fd3ef502-1b00-0000-e18f-075d0e140000 pid=5134 execve guuid=6a9bfc42-1b00-0000-e18f-075de9140000 pid=5353 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=6a9bfc42-1b00-0000-e18f-075de9140000 pid=5353 execve guuid=36869443-1b00-0000-e18f-075dea140000 pid=5354 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=36869443-1b00-0000-e18f-075dea140000 pid=5354 clone guuid=038c4b44-1b00-0000-e18f-075dec140000 pid=5356 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=038c4b44-1b00-0000-e18f-075dec140000 pid=5356 execve guuid=3c09908b-1b00-0000-e18f-075df8140000 pid=5368 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3c09908b-1b00-0000-e18f-075df8140000 pid=5368 execve guuid=485edd8b-1b00-0000-e18f-075df9140000 pid=5369 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=485edd8b-1b00-0000-e18f-075df9140000 pid=5369 clone guuid=c301d28e-1b00-0000-e18f-075dfb140000 pid=5371 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c301d28e-1b00-0000-e18f-075dfb140000 pid=5371 execve guuid=7062db07-1c00-0000-e18f-075dfc140000 pid=5372 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7062db07-1c00-0000-e18f-075dfc140000 pid=5372 execve guuid=cdaf3108-1c00-0000-e18f-075dfd140000 pid=5373 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=cdaf3108-1c00-0000-e18f-075dfd140000 pid=5373 clone guuid=ae8d3909-1c00-0000-e18f-075dff140000 pid=5375 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ae8d3909-1c00-0000-e18f-075dff140000 pid=5375 execve guuid=e53b634b-1c00-0000-e18f-075d07150000 pid=5383 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e53b634b-1c00-0000-e18f-075d07150000 pid=5383 execve guuid=8e1a7c4c-1c00-0000-e18f-075d08150000 pid=5384 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8e1a7c4c-1c00-0000-e18f-075d08150000 pid=5384 clone guuid=78cd6f4e-1c00-0000-e18f-075d0a150000 pid=5386 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=78cd6f4e-1c00-0000-e18f-075d0a150000 pid=5386 execve guuid=f92d4aae-1c00-0000-e18f-075d0b150000 pid=5387 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=f92d4aae-1c00-0000-e18f-075d0b150000 pid=5387 execve guuid=2a2bb4ae-1c00-0000-e18f-075d0c150000 pid=5388 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=2a2bb4ae-1c00-0000-e18f-075d0c150000 pid=5388 clone guuid=110b4cb7-1c00-0000-e18f-075d0e150000 pid=5390 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=110b4cb7-1c00-0000-e18f-075d0e150000 pid=5390 execve guuid=27f8d8fc-1c00-0000-e18f-075d0f150000 pid=5391 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=27f8d8fc-1c00-0000-e18f-075d0f150000 pid=5391 execve guuid=f6771bfd-1c00-0000-e18f-075d10150000 pid=5392 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=f6771bfd-1c00-0000-e18f-075d10150000 pid=5392 clone guuid=438fbefd-1c00-0000-e18f-075d12150000 pid=5394 /usr/bin/curl net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=438fbefd-1c00-0000-e18f-075d12150000 pid=5394 execve guuid=7d39b443-1d00-0000-e18f-075d20150000 pid=5408 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=7d39b443-1d00-0000-e18f-075d20150000 pid=5408 execve guuid=c4543444-1d00-0000-e18f-075d21150000 pid=5409 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c4543444-1d00-0000-e18f-075d21150000 pid=5409 clone guuid=70845f45-1d00-0000-e18f-075d23150000 pid=5411 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=70845f45-1d00-0000-e18f-075d23150000 pid=5411 execve guuid=24276f14-1e00-0000-e18f-075d37150000 pid=5431 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=24276f14-1e00-0000-e18f-075d37150000 pid=5431 execve guuid=c25cb714-1e00-0000-e18f-075d38150000 pid=5432 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=c25cb714-1e00-0000-e18f-075d38150000 pid=5432 clone guuid=0bdf4415-1e00-0000-e18f-075d3a150000 pid=5434 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=0bdf4415-1e00-0000-e18f-075d3a150000 pid=5434 execve guuid=2c6f2eca-1e00-0000-e18f-075d3b150000 pid=5435 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=2c6f2eca-1e00-0000-e18f-075d3b150000 pid=5435 execve guuid=460c72ca-1e00-0000-e18f-075d3c150000 pid=5436 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=460c72ca-1e00-0000-e18f-075d3c150000 pid=5436 clone guuid=134507cb-1e00-0000-e18f-075d3e150000 pid=5438 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=134507cb-1e00-0000-e18f-075d3e150000 pid=5438 execve guuid=5c775e81-1f00-0000-e18f-075d3f150000 pid=5439 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=5c775e81-1f00-0000-e18f-075d3f150000 pid=5439 execve guuid=afe1ec81-1f00-0000-e18f-075d40150000 pid=5440 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=afe1ec81-1f00-0000-e18f-075d40150000 pid=5440 clone guuid=588c0b83-1f00-0000-e18f-075d42150000 pid=5442 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=588c0b83-1f00-0000-e18f-075d42150000 pid=5442 execve guuid=9adcbf98-2000-0000-e18f-075d43150000 pid=5443 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9adcbf98-2000-0000-e18f-075d43150000 pid=5443 execve guuid=8bc84299-2000-0000-e18f-075d44150000 pid=5444 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=8bc84299-2000-0000-e18f-075d44150000 pid=5444 clone guuid=e034629a-2000-0000-e18f-075d46150000 pid=5446 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=e034629a-2000-0000-e18f-075d46150000 pid=5446 execve guuid=9f0ef65d-2100-0000-e18f-075d47150000 pid=5447 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=9f0ef65d-2100-0000-e18f-075d47150000 pid=5447 execve guuid=19c87f5e-2100-0000-e18f-075d48150000 pid=5448 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=19c87f5e-2100-0000-e18f-075d48150000 pid=5448 clone guuid=ac5a8e5f-2100-0000-e18f-075d4a150000 pid=5450 /usr/bin/busybox net send-data write-file guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=ac5a8e5f-2100-0000-e18f-075d4a150000 pid=5450 execve guuid=d312d11e-2200-0000-e18f-075d4b150000 pid=5451 /usr/bin/chmod guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=d312d11e-2200-0000-e18f-075d4b150000 pid=5451 execve guuid=3cdb581f-2200-0000-e18f-075d4c150000 pid=5452 /usr/bin/dash guuid=dac95c63-1900-0000-e18f-075d5d0f0000 pid=3933->guuid=3cdb581f-2200-0000-e18f-075d4c150000 pid=5452 clone c56865db-3b4b-54b6-a6ba-cee0ad256cff 103.146.23.141:80 guuid=40dfd392-1900-0000-e18f-075d8d100000 pid=4237->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=eab7dad8-1900-0000-e18f-075d79110000 pid=4473->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=dcba672e-1a00-0000-e18f-075dae120000 pid=4782->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=69f7f27c-1a00-0000-e18f-075df1120000 pid=4849->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=094aaec0-1a00-0000-e18f-075d7e130000 pid=4990->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 133B guuid=fd3ef502-1b00-0000-e18f-075d0e140000 pid=5134->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 136B guuid=038c4b44-1b00-0000-e18f-075dec140000 pid=5356->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 82B guuid=c301d28e-1b00-0000-e18f-075dfb140000 pid=5371->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 82B guuid=ae8d3909-1c00-0000-e18f-075dff140000 pid=5375->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 82B guuid=78cd6f4e-1c00-0000-e18f-075d0a150000 pid=5386->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 82B guuid=110b4cb7-1c00-0000-e18f-075d0e150000 pid=5390->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 82B guuid=438fbefd-1c00-0000-e18f-075d12150000 pid=5394->c56865db-3b4b-54b6-a6ba-cee0ad256cff send: 85B 7c706caf-da59-5941-b7ca-e7556f839526 103.146.23.141:21 guuid=70845f45-1d00-0000-e18f-075d23150000 pid=5411->7c706caf-da59-5941-b7ca-e7556f839526 send: 78B d01cd1a9-b51c-5a62-8491-78d64ee90cad 103.146.23.141:39009 guuid=70845f45-1d00-0000-e18f-075d23150000 pid=5411->d01cd1a9-b51c-5a62-8491-78d64ee90cad con guuid=0bdf4415-1e00-0000-e18f-075d3a150000 pid=5434->7c706caf-da59-5941-b7ca-e7556f839526 send: 78B 2a5d8c79-6b6d-57d1-a1f2-b276e653139f 103.146.23.141:38793 guuid=0bdf4415-1e00-0000-e18f-075d3a150000 pid=5434->2a5d8c79-6b6d-57d1-a1f2-b276e653139f con guuid=134507cb-1e00-0000-e18f-075d3e150000 pid=5438->7c706caf-da59-5941-b7ca-e7556f839526 send: 78B 82bcf53e-417f-5369-9f04-9555db9af3e2 103.146.23.141:41083 guuid=134507cb-1e00-0000-e18f-075d3e150000 pid=5438->82bcf53e-417f-5369-9f04-9555db9af3e2 con guuid=588c0b83-1f00-0000-e18f-075d42150000 pid=5442->7c706caf-da59-5941-b7ca-e7556f839526 send: 78B 9e939409-3d66-5254-88aa-b17c6152eca6 103.146.23.141:36861 guuid=588c0b83-1f00-0000-e18f-075d42150000 pid=5442->9e939409-3d66-5254-88aa-b17c6152eca6 con guuid=e034629a-2000-0000-e18f-075d46150000 pid=5446->7c706caf-da59-5941-b7ca-e7556f839526 send: 78B 40ce3159-24fc-5255-82f3-7ddbdbb629f6 103.146.23.141:33689 guuid=e034629a-2000-0000-e18f-075d46150000 pid=5446->40ce3159-24fc-5255-82f3-7ddbdbb629f6 con guuid=ac5a8e5f-2100-0000-e18f-075d4a150000 pid=5450->7c706caf-da59-5941-b7ca-e7556f839526 send: 84B d3aabef8-8bcd-59b2-b808-ad88b92a7ff4 103.146.23.141:36205 guuid=ac5a8e5f-2100-0000-e18f-075d4a150000 pid=5450->d3aabef8-8bcd-59b2-b808-ad88b92a7ff4 con
Threat name:
Script-Shell.Worm.Mirai
Status:
Malicious
First seen:
2025-11-21 21:23:30 UTC
File Type:
Text (Shell)
AV detection:
13 of 38 (34.21%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 6d29e4352ae66c81057ee4ca4434857ca062ca4617442d969acd42adf46de0e8

(this sample)

  
Delivery method
Distributed via web download

Comments