MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 6d6b5320e19cf931959185618a2d7d3a910ac4f42e5fe171a4dfdc856c06e255. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 6d6b5320e19cf931959185618a2d7d3a910ac4f42e5fe171a4dfdc856c06e255
SHA3-384 hash: 157e5606356a120ef6304e81abc4684082aafc7f916d992d2bf074eccaa15dbb5999d588089b2a69fa1049a66dc820ff
SHA1 hash: 27665c70ee52d5275718e7b722a3e4b0609246f6
MD5 hash: 071c75573101f72568ee241d1ff9604c
humanhash: saturn-ack-florida-zulu
File name:1.sh
Download: download sample
Signature Mirai
File size:2'761 bytes
First seen:2025-07-17 17:24:56 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ircwZrEyElhrO8rNerycynnrEnE2ErJc1JMprJXJ11UrJIJeDrJ9JRvmr21CrDFo:ircwZrEyElhrO8rNerlOrEnE2ErJc1Jt
TLSH T16C51D2C54E8341762C769E37BABA46883E96DC6338C86D9795EC3CEB444DE0530B1E63
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://161.97.77.188/HBTs/top1miku.i58663d867a35531716d2e18314fbe4d2b0ffc3cc4bbb56d61a49ad1a42220746dac Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mips6dba5a43486ad2c883f236754e25806a860f5063fcf73e225f4f86c1c1741ead Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.arc380cdfff39fab66e0d2f0e3217f0e2573374ebbde28f6a96343e2cb72c0ca944 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.i686b80576044beece1b4d384a03a1cf722b0859177e554946eb0a6b0c96ae98d92d Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.x86_645c03e74290ffbc6332f3d357d54853000ea53f19ee0fa3fb36d466989c48826f Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.mipseld1fab6b2f50e0ff23b55efacb28d56953902bd7bf276d1bbb0e8b8008cdbb7e6 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv4l861077a289df2f605a07e5054d37a41cc087751a1347d57c0c5977d91197e7b3 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv5le32f0af161e9dc5d213b9dc2d291da8dda9e836b9478d13a773a051a27075b89 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv6l6541c73c5c61b39d318d6e8e2c84a512824d846e03dce12a05ce5749315e10d7 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.armv7l21fde295094321e113cc7fe87fb3dc1230c4f602a21ea1919997e9289d683194 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.powerpcf9619daee99e761f7ef1df5c67a70f966af51d6f5c603bd3cf09a68f7f00b26f Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.powerpc-440fp050fb23f00a9e0583cc357a453959ec9f7d6e5268b285caec9476eef5b25c618 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.m68kaf5ef5773b4f244557be125fa269d59bfa897f6ad5ddbbd600a224a7fe38fdb8 Miraielf mirai opendir ua-wget
http://161.97.77.188/HBTs/top1miku.sh4200f50c4e8e10d7cd12823b2ff9dcc4fd4643094ee0cb1bbd321a636af1acdc4 Miraielf mirai opendir ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=73c968d0-1a00-0000-5e60-1ad6080a0000 pid=2568 /usr/bin/sudo guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574 /tmp/sample.bin guuid=73c968d0-1a00-0000-5e60-1ad6080a0000 pid=2568->guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574 execve guuid=79eaa4d2-1a00-0000-5e60-1ad6110a0000 pid=2577 /usr/bin/cp guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=79eaa4d2-1a00-0000-5e60-1ad6110a0000 pid=2577 execve guuid=36156ed8-1a00-0000-5e60-1ad61f0a0000 pid=2591 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=36156ed8-1a00-0000-5e60-1ad61f0a0000 pid=2591 execve guuid=d7ea49e1-1a00-0000-5e60-1ad63a0a0000 pid=2618 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=d7ea49e1-1a00-0000-5e60-1ad63a0a0000 pid=2618 execve guuid=f66ea2ef-1a00-0000-5e60-1ad65f0a0000 pid=2655 /usr/bin/cat guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f66ea2ef-1a00-0000-5e60-1ad65f0a0000 pid=2655 execve guuid=e950f3ef-1a00-0000-5e60-1ad6610a0000 pid=2657 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=e950f3ef-1a00-0000-5e60-1ad6610a0000 pid=2657 execve guuid=e74f37f0-1a00-0000-5e60-1ad6630a0000 pid=2659 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=e74f37f0-1a00-0000-5e60-1ad6630a0000 pid=2659 execve guuid=89acd9f0-1a00-0000-5e60-1ad6690a0000 pid=2665 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=89acd9f0-1a00-0000-5e60-1ad6690a0000 pid=2665 execve guuid=f2407ef4-1a00-0000-5e60-1ad6770a0000 pid=2679 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f2407ef4-1a00-0000-5e60-1ad6770a0000 pid=2679 execve guuid=eb9e04fb-1a00-0000-5e60-1ad68f0a0000 pid=2703 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=eb9e04fb-1a00-0000-5e60-1ad68f0a0000 pid=2703 clone guuid=abb427fb-1a00-0000-5e60-1ad6900a0000 pid=2704 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=abb427fb-1a00-0000-5e60-1ad6900a0000 pid=2704 execve guuid=c6d094fb-1a00-0000-5e60-1ad6930a0000 pid=2707 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=c6d094fb-1a00-0000-5e60-1ad6930a0000 pid=2707 execve guuid=567bd9fb-1a00-0000-5e60-1ad6960a0000 pid=2710 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=567bd9fb-1a00-0000-5e60-1ad6960a0000 pid=2710 execve guuid=5c599d06-1b00-0000-5e60-1ad6c10a0000 pid=2753 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=5c599d06-1b00-0000-5e60-1ad6c10a0000 pid=2753 execve guuid=7172440e-1b00-0000-5e60-1ad6d60a0000 pid=2774 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=7172440e-1b00-0000-5e60-1ad6d60a0000 pid=2774 clone guuid=46f6690e-1b00-0000-5e60-1ad6d70a0000 pid=2775 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=46f6690e-1b00-0000-5e60-1ad6d70a0000 pid=2775 execve guuid=17fbd90e-1b00-0000-5e60-1ad6d90a0000 pid=2777 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=17fbd90e-1b00-0000-5e60-1ad6d90a0000 pid=2777 execve guuid=9231140f-1b00-0000-5e60-1ad6dc0a0000 pid=2780 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=9231140f-1b00-0000-5e60-1ad6dc0a0000 pid=2780 execve guuid=2dbcc815-1b00-0000-5e60-1ad6e20a0000 pid=2786 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=2dbcc815-1b00-0000-5e60-1ad6e20a0000 pid=2786 execve guuid=acd3cc23-1b00-0000-5e60-1ad6fb0a0000 pid=2811 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=acd3cc23-1b00-0000-5e60-1ad6fb0a0000 pid=2811 clone guuid=f9cc1624-1b00-0000-5e60-1ad6fc0a0000 pid=2812 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f9cc1624-1b00-0000-5e60-1ad6fc0a0000 pid=2812 execve guuid=d4da9b24-1b00-0000-5e60-1ad6fe0a0000 pid=2814 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=d4da9b24-1b00-0000-5e60-1ad6fe0a0000 pid=2814 execve guuid=f985ba26-1b00-0000-5e60-1ad6080b0000 pid=2824 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f985ba26-1b00-0000-5e60-1ad6080b0000 pid=2824 execve guuid=bfb5312f-1b00-0000-5e60-1ad6170b0000 pid=2839 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=bfb5312f-1b00-0000-5e60-1ad6170b0000 pid=2839 execve guuid=9b21533a-1b00-0000-5e60-1ad6340b0000 pid=2868 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=9b21533a-1b00-0000-5e60-1ad6340b0000 pid=2868 clone guuid=ea217f3a-1b00-0000-5e60-1ad6360b0000 pid=2870 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=ea217f3a-1b00-0000-5e60-1ad6360b0000 pid=2870 execve guuid=30581b3b-1b00-0000-5e60-1ad6380b0000 pid=2872 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=30581b3b-1b00-0000-5e60-1ad6380b0000 pid=2872 execve guuid=992ad63b-1b00-0000-5e60-1ad63a0b0000 pid=2874 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=992ad63b-1b00-0000-5e60-1ad63a0b0000 pid=2874 execve guuid=641faf41-1b00-0000-5e60-1ad64c0b0000 pid=2892 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=641faf41-1b00-0000-5e60-1ad64c0b0000 pid=2892 execve guuid=8817324e-1b00-0000-5e60-1ad6750b0000 pid=2933 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=8817324e-1b00-0000-5e60-1ad6750b0000 pid=2933 clone guuid=0e0b6b4e-1b00-0000-5e60-1ad6760b0000 pid=2934 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=0e0b6b4e-1b00-0000-5e60-1ad6760b0000 pid=2934 execve guuid=5ba6f64e-1b00-0000-5e60-1ad6790b0000 pid=2937 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=5ba6f64e-1b00-0000-5e60-1ad6790b0000 pid=2937 execve guuid=eae63e4f-1b00-0000-5e60-1ad67c0b0000 pid=2940 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=eae63e4f-1b00-0000-5e60-1ad67c0b0000 pid=2940 execve guuid=a8ba6853-1b00-0000-5e60-1ad6890b0000 pid=2953 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=a8ba6853-1b00-0000-5e60-1ad6890b0000 pid=2953 execve guuid=8b27c55f-1b00-0000-5e60-1ad6a20b0000 pid=2978 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=8b27c55f-1b00-0000-5e60-1ad6a20b0000 pid=2978 clone guuid=f56b2860-1b00-0000-5e60-1ad6a40b0000 pid=2980 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f56b2860-1b00-0000-5e60-1ad6a40b0000 pid=2980 execve guuid=d64bd260-1b00-0000-5e60-1ad6a70b0000 pid=2983 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=d64bd260-1b00-0000-5e60-1ad6a70b0000 pid=2983 execve guuid=49bb3f61-1b00-0000-5e60-1ad6a90b0000 pid=2985 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=49bb3f61-1b00-0000-5e60-1ad6a90b0000 pid=2985 execve guuid=87ce2269-1b00-0000-5e60-1ad6b10b0000 pid=2993 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=87ce2269-1b00-0000-5e60-1ad6b10b0000 pid=2993 execve guuid=c4bcb474-1b00-0000-5e60-1ad6c30b0000 pid=3011 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=c4bcb474-1b00-0000-5e60-1ad6c30b0000 pid=3011 clone guuid=aea9cc74-1b00-0000-5e60-1ad6c40b0000 pid=3012 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=aea9cc74-1b00-0000-5e60-1ad6c40b0000 pid=3012 execve guuid=1d151b75-1b00-0000-5e60-1ad6c50b0000 pid=3013 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=1d151b75-1b00-0000-5e60-1ad6c50b0000 pid=3013 execve guuid=7d705a75-1b00-0000-5e60-1ad6c80b0000 pid=3016 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=7d705a75-1b00-0000-5e60-1ad6c80b0000 pid=3016 execve guuid=35578e79-1b00-0000-5e60-1ad6cb0b0000 pid=3019 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=35578e79-1b00-0000-5e60-1ad6cb0b0000 pid=3019 execve guuid=12a84a85-1b00-0000-5e60-1ad6ea0b0000 pid=3050 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=12a84a85-1b00-0000-5e60-1ad6ea0b0000 pid=3050 clone guuid=2e6c0286-1b00-0000-5e60-1ad6eb0b0000 pid=3051 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=2e6c0286-1b00-0000-5e60-1ad6eb0b0000 pid=3051 execve guuid=62689286-1b00-0000-5e60-1ad6ee0b0000 pid=3054 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=62689286-1b00-0000-5e60-1ad6ee0b0000 pid=3054 execve guuid=11110587-1b00-0000-5e60-1ad6f20b0000 pid=3058 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=11110587-1b00-0000-5e60-1ad6f20b0000 pid=3058 execve guuid=4a001c8c-1b00-0000-5e60-1ad6030c0000 pid=3075 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=4a001c8c-1b00-0000-5e60-1ad6030c0000 pid=3075 execve guuid=686f4e99-1b00-0000-5e60-1ad6290c0000 pid=3113 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=686f4e99-1b00-0000-5e60-1ad6290c0000 pid=3113 clone guuid=f26a6499-1b00-0000-5e60-1ad62a0c0000 pid=3114 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f26a6499-1b00-0000-5e60-1ad62a0c0000 pid=3114 execve guuid=b89fa999-1b00-0000-5e60-1ad62c0c0000 pid=3116 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=b89fa999-1b00-0000-5e60-1ad62c0c0000 pid=3116 execve guuid=03f3d599-1b00-0000-5e60-1ad62e0c0000 pid=3118 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=03f3d599-1b00-0000-5e60-1ad62e0c0000 pid=3118 execve guuid=49f61d9e-1b00-0000-5e60-1ad63b0c0000 pid=3131 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=49f61d9e-1b00-0000-5e60-1ad63b0c0000 pid=3131 execve guuid=5a8aa4aa-1b00-0000-5e60-1ad65a0c0000 pid=3162 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=5a8aa4aa-1b00-0000-5e60-1ad65a0c0000 pid=3162 clone guuid=f373c3ab-1b00-0000-5e60-1ad65e0c0000 pid=3166 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=f373c3ab-1b00-0000-5e60-1ad65e0c0000 pid=3166 execve guuid=621b2bad-1b00-0000-5e60-1ad6630c0000 pid=3171 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=621b2bad-1b00-0000-5e60-1ad6630c0000 pid=3171 execve guuid=c89ecfad-1b00-0000-5e60-1ad6650c0000 pid=3173 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=c89ecfad-1b00-0000-5e60-1ad6650c0000 pid=3173 execve guuid=d012fdb3-1b00-0000-5e60-1ad6740c0000 pid=3188 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=d012fdb3-1b00-0000-5e60-1ad6740c0000 pid=3188 execve guuid=6c0436cb-1b00-0000-5e60-1ad6af0c0000 pid=3247 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=6c0436cb-1b00-0000-5e60-1ad6af0c0000 pid=3247 clone guuid=eb7f94cb-1b00-0000-5e60-1ad6b10c0000 pid=3249 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=eb7f94cb-1b00-0000-5e60-1ad6b10c0000 pid=3249 execve guuid=385e85cc-1b00-0000-5e60-1ad6b40c0000 pid=3252 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=385e85cc-1b00-0000-5e60-1ad6b40c0000 pid=3252 execve guuid=ee58afcc-1b00-0000-5e60-1ad6b70c0000 pid=3255 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=ee58afcc-1b00-0000-5e60-1ad6b70c0000 pid=3255 execve guuid=66986dd6-1b00-0000-5e60-1ad6cc0c0000 pid=3276 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=66986dd6-1b00-0000-5e60-1ad6cc0c0000 pid=3276 execve guuid=8eb4ffe3-1b00-0000-5e60-1ad6e20c0000 pid=3298 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=8eb4ffe3-1b00-0000-5e60-1ad6e20c0000 pid=3298 clone guuid=fbbcdce5-1b00-0000-5e60-1ad6e30c0000 pid=3299 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=fbbcdce5-1b00-0000-5e60-1ad6e30c0000 pid=3299 execve guuid=739ea7e6-1b00-0000-5e60-1ad6e40c0000 pid=3300 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=739ea7e6-1b00-0000-5e60-1ad6e40c0000 pid=3300 execve guuid=4b3254e7-1b00-0000-5e60-1ad6e60c0000 pid=3302 /usr/bin/wget net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=4b3254e7-1b00-0000-5e60-1ad6e60c0000 pid=3302 execve guuid=8dd12cf5-1b00-0000-5e60-1ad6030d0000 pid=3331 /usr/bin/curl net send-data write-file guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=8dd12cf5-1b00-0000-5e60-1ad6030d0000 pid=3331 execve guuid=e8f0eefa-1b00-0000-5e60-1ad6100d0000 pid=3344 /usr/bin/bash guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=e8f0eefa-1b00-0000-5e60-1ad6100d0000 pid=3344 clone guuid=50afebfb-1b00-0000-5e60-1ad6110d0000 pid=3345 /usr/bin/chmod guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=50afebfb-1b00-0000-5e60-1ad6110d0000 pid=3345 execve guuid=a8363cfd-1b00-0000-5e60-1ad6120d0000 pid=3346 /tmp/WTF net guuid=771e2ad2-1a00-0000-5e60-1ad60e0a0000 pid=2574->guuid=a8363cfd-1b00-0000-5e60-1ad6120d0000 pid=3346 execve 7a155949-225c-5534-9d46-ce85bc851092 161.97.77.188:80 guuid=36156ed8-1a00-0000-5e60-1ad61f0a0000 pid=2591->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=d7ea49e1-1a00-0000-5e60-1ad63a0a0000 pid=2618->7a155949-225c-5534-9d46-ce85bc851092 send: 95B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e74f37f0-1a00-0000-5e60-1ad6630a0000 pid=2659->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1405cef0-1a00-0000-5e60-1ad6670a0000 pid=2663 /tmp/WTF guuid=e74f37f0-1a00-0000-5e60-1ad6630a0000 pid=2659->guuid=1405cef0-1a00-0000-5e60-1ad6670a0000 pid=2663 clone guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664 /tmp/WTF write-config zombie guuid=1405cef0-1a00-0000-5e60-1ad6670a0000 pid=2663->guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664 clone guuid=d9309ff4-1a00-0000-5e60-1ad6780a0000 pid=2680 /usr/bin/dash guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664->guuid=d9309ff4-1a00-0000-5e60-1ad6780a0000 pid=2680 execve guuid=e1ae29f8-1a00-0000-5e60-1ad6850a0000 pid=2693 /tmp/WTF delete-file guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664->guuid=e1ae29f8-1a00-0000-5e60-1ad6850a0000 pid=2693 clone guuid=d96282ab-1e00-0000-5e60-1ad6d7130000 pid=5079 /tmp/WTF guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664->guuid=d96282ab-1e00-0000-5e60-1ad6d7130000 pid=5079 clone guuid=9d2eb45d-2200-0000-5e60-1ad627150000 pid=5415 /tmp/WTF dns net send-data guuid=790ad7f0-1a00-0000-5e60-1ad6680a0000 pid=2664->guuid=9d2eb45d-2200-0000-5e60-1ad627150000 pid=5415 clone guuid=89acd9f0-1a00-0000-5e60-1ad6690a0000 pid=2665->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=f2407ef4-1a00-0000-5e60-1ad6770a0000 pid=2679->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=bd6cdcf4-1a00-0000-5e60-1ad67a0a0000 pid=2682 /usr/bin/cp guuid=d9309ff4-1a00-0000-5e60-1ad6780a0000 pid=2680->guuid=bd6cdcf4-1a00-0000-5e60-1ad67a0a0000 pid=2682 execve guuid=c6d094fb-1a00-0000-5e60-1ad6930a0000 pid=2707->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=eae1ccfb-1a00-0000-5e60-1ad6940a0000 pid=2708 /tmp/WTF guuid=c6d094fb-1a00-0000-5e60-1ad6930a0000 pid=2707->guuid=eae1ccfb-1a00-0000-5e60-1ad6940a0000 pid=2708 clone guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711 /tmp/WTF write-config zombie guuid=eae1ccfb-1a00-0000-5e60-1ad6940a0000 pid=2708->guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711 clone guuid=567bd9fb-1a00-0000-5e60-1ad6960a0000 pid=2710->7a155949-225c-5534-9d46-ce85bc851092 send: 145B guuid=63a52202-1b00-0000-5e60-1ad6b10a0000 pid=2737 /usr/bin/dash guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711->guuid=63a52202-1b00-0000-5e60-1ad6b10a0000 pid=2737 execve guuid=a83b6f07-1b00-0000-5e60-1ad6c40a0000 pid=2756 /tmp/WTF delete-file dns net send-data guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711->guuid=a83b6f07-1b00-0000-5e60-1ad6c40a0000 pid=2756 clone guuid=1d98a986-2000-0000-5e60-1ad605150000 pid=5381 /tmp/WTF guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711->guuid=1d98a986-2000-0000-5e60-1ad605150000 pid=5381 clone guuid=769b3538-2400-0000-5e60-1ad630150000 pid=5424 /tmp/WTF dns net send-data guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711->guuid=769b3538-2400-0000-5e60-1ad630150000 pid=5424 clone guuid=33fd7b10-2800-0000-5e60-1ad63c150000 pid=5436 /tmp/WTF guuid=cbaff8fb-1a00-0000-5e60-1ad6970a0000 pid=2711->guuid=33fd7b10-2800-0000-5e60-1ad63c150000 pid=5436 clone guuid=f39ae702-1b00-0000-5e60-1ad6b50a0000 pid=2741 /usr/bin/cp guuid=63a52202-1b00-0000-5e60-1ad6b10a0000 pid=2737->guuid=f39ae702-1b00-0000-5e60-1ad6b50a0000 pid=2741 execve guuid=5c599d06-1b00-0000-5e60-1ad6c10a0000 pid=2753->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=a83b6f07-1b00-0000-5e60-1ad6c40a0000 pid=2756->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=a83b6f07-1b00-0000-5e60-1ad6c40a0000 pid=2756->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=17fbd90e-1b00-0000-5e60-1ad6d90a0000 pid=2777->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d2280a0f-1b00-0000-5e60-1ad6db0a0000 pid=2779 /tmp/WTF guuid=17fbd90e-1b00-0000-5e60-1ad6d90a0000 pid=2777->guuid=d2280a0f-1b00-0000-5e60-1ad6db0a0000 pid=2779 clone guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781 /tmp/WTF write-config zombie guuid=d2280a0f-1b00-0000-5e60-1ad6db0a0000 pid=2779->guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781 clone guuid=9231140f-1b00-0000-5e60-1ad6dc0a0000 pid=2780->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=00874618-1b00-0000-5e60-1ad6e60a0000 pid=2790 /usr/bin/dash guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781->guuid=00874618-1b00-0000-5e60-1ad6e60a0000 pid=2790 execve guuid=b459eb1e-1b00-0000-5e60-1ad6f30a0000 pid=2803 /tmp/WTF delete-file guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781->guuid=b459eb1e-1b00-0000-5e60-1ad6f30a0000 pid=2803 clone guuid=866d4dc3-1e00-0000-5e60-1ad620140000 pid=5152 /tmp/WTF dns net send-data guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781->guuid=866d4dc3-1e00-0000-5e60-1ad620140000 pid=5152 clone guuid=eea46b90-2300-0000-5e60-1ad62d150000 pid=5421 /tmp/WTF guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781->guuid=eea46b90-2300-0000-5e60-1ad62d150000 pid=5421 clone guuid=67cd104b-2700-0000-5e60-1ad639150000 pid=5433 /tmp/WTF guuid=459b1d0f-1b00-0000-5e60-1ad6dd0a0000 pid=2781->guuid=67cd104b-2700-0000-5e60-1ad639150000 pid=5433 clone guuid=2dbcc815-1b00-0000-5e60-1ad6e20a0000 pid=2786->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=13f67418-1b00-0000-5e60-1ad6e80a0000 pid=2792 /usr/bin/cp guuid=00874618-1b00-0000-5e60-1ad6e60a0000 pid=2790->guuid=13f67418-1b00-0000-5e60-1ad6e80a0000 pid=2792 execve guuid=d4da9b24-1b00-0000-5e60-1ad6fe0a0000 pid=2814->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=94e17c26-1b00-0000-5e60-1ad6050b0000 pid=2821 /tmp/WTF guuid=d4da9b24-1b00-0000-5e60-1ad6fe0a0000 pid=2814->guuid=94e17c26-1b00-0000-5e60-1ad6050b0000 pid=2821 clone guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823 /tmp/WTF write-config zombie guuid=94e17c26-1b00-0000-5e60-1ad6050b0000 pid=2821->guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823 clone guuid=55939c2d-1b00-0000-5e60-1ad6140b0000 pid=2836 /usr/bin/dash guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823->guuid=55939c2d-1b00-0000-5e60-1ad6140b0000 pid=2836 execve guuid=17527030-1b00-0000-5e60-1ad61c0b0000 pid=2844 /tmp/WTF delete-file dns net send-data guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823->guuid=17527030-1b00-0000-5e60-1ad61c0b0000 pid=2844 clone guuid=de3f042b-2000-0000-5e60-1ad604150000 pid=5380 /tmp/WTF dns net send-data guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823->guuid=de3f042b-2000-0000-5e60-1ad604150000 pid=5380 clone guuid=8e04580f-2400-0000-5e60-1ad62f150000 pid=5423 /tmp/WTF guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823->guuid=8e04580f-2400-0000-5e60-1ad62f150000 pid=5423 clone guuid=8fd4e2c5-2700-0000-5e60-1ad63b150000 pid=5435 /tmp/WTF guuid=ec3cb226-1b00-0000-5e60-1ad6070b0000 pid=2823->guuid=8fd4e2c5-2700-0000-5e60-1ad63b150000 pid=5435 clone guuid=f985ba26-1b00-0000-5e60-1ad6080b0000 pid=2824->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=ac17d42d-1b00-0000-5e60-1ad6150b0000 pid=2837 /usr/bin/cp guuid=55939c2d-1b00-0000-5e60-1ad6140b0000 pid=2836->guuid=ac17d42d-1b00-0000-5e60-1ad6150b0000 pid=2837 execve guuid=bfb5312f-1b00-0000-5e60-1ad6170b0000 pid=2839->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=17527030-1b00-0000-5e60-1ad61c0b0000 pid=2844->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=17527030-1b00-0000-5e60-1ad61c0b0000 pid=2844->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=30581b3b-1b00-0000-5e60-1ad6380b0000 pid=2872->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a995c03b-1b00-0000-5e60-1ad6390b0000 pid=2873 /tmp/WTF guuid=30581b3b-1b00-0000-5e60-1ad6380b0000 pid=2872->guuid=a995c03b-1b00-0000-5e60-1ad6390b0000 pid=2873 clone guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881 /tmp/WTF write-config zombie guuid=a995c03b-1b00-0000-5e60-1ad6390b0000 pid=2873->guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881 clone guuid=992ad63b-1b00-0000-5e60-1ad63a0b0000 pid=2874->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=f632a343-1b00-0000-5e60-1ad6520b0000 pid=2898 /usr/bin/dash guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881->guuid=f632a343-1b00-0000-5e60-1ad6520b0000 pid=2898 execve guuid=15037f47-1b00-0000-5e60-1ad6600b0000 pid=2912 /tmp/WTF delete-file guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881->guuid=15037f47-1b00-0000-5e60-1ad6600b0000 pid=2912 clone guuid=251310f1-1e00-0000-5e60-1ad6ea140000 pid=5354 /tmp/WTF guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881->guuid=251310f1-1e00-0000-5e60-1ad6ea140000 pid=5354 clone guuid=8055f49a-2200-0000-5e60-1ad628150000 pid=5416 /tmp/WTF guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881->guuid=8055f49a-2200-0000-5e60-1ad628150000 pid=5416 clone guuid=b12adf3d-2600-0000-5e60-1ad635150000 pid=5429 /tmp/WTF dns net send-data guuid=48174b3d-1b00-0000-5e60-1ad6410b0000 pid=2881->guuid=b12adf3d-2600-0000-5e60-1ad635150000 pid=5429 clone guuid=641faf41-1b00-0000-5e60-1ad64c0b0000 pid=2892->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=9e874744-1b00-0000-5e60-1ad6550b0000 pid=2901 /usr/bin/cp guuid=f632a343-1b00-0000-5e60-1ad6520b0000 pid=2898->guuid=9e874744-1b00-0000-5e60-1ad6550b0000 pid=2901 execve guuid=5ba6f64e-1b00-0000-5e60-1ad6790b0000 pid=2937->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=814f314f-1b00-0000-5e60-1ad67b0b0000 pid=2939 /tmp/WTF guuid=5ba6f64e-1b00-0000-5e60-1ad6790b0000 pid=2937->guuid=814f314f-1b00-0000-5e60-1ad67b0b0000 pid=2939 clone guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941 /tmp/WTF write-config zombie guuid=814f314f-1b00-0000-5e60-1ad67b0b0000 pid=2939->guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941 clone guuid=eae63e4f-1b00-0000-5e60-1ad67c0b0000 pid=2940->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=f7324d54-1b00-0000-5e60-1ad68b0b0000 pid=2955 /usr/bin/dash guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941->guuid=f7324d54-1b00-0000-5e60-1ad68b0b0000 pid=2955 execve guuid=ecb0a159-1b00-0000-5e60-1ad6930b0000 pid=2963 /tmp/WTF delete-file dns net send-data guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941->guuid=ecb0a159-1b00-0000-5e60-1ad6930b0000 pid=2963 clone guuid=99e58ef7-1f00-0000-5e60-1ad603150000 pid=5379 /tmp/WTF dns net send-data guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941->guuid=99e58ef7-1f00-0000-5e60-1ad603150000 pid=5379 clone guuid=55a431ee-2500-0000-5e60-1ad634150000 pid=5428 /tmp/WTF dns net send-data guuid=97cb414f-1b00-0000-5e60-1ad67d0b0000 pid=2941->guuid=55a431ee-2500-0000-5e60-1ad634150000 pid=5428 clone guuid=a8ba6853-1b00-0000-5e60-1ad6890b0000 pid=2953->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=a00a7b54-1b00-0000-5e60-1ad68c0b0000 pid=2956 /usr/bin/cp guuid=f7324d54-1b00-0000-5e60-1ad68b0b0000 pid=2955->guuid=a00a7b54-1b00-0000-5e60-1ad68c0b0000 pid=2956 execve guuid=ecb0a159-1b00-0000-5e60-1ad6930b0000 pid=2963->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=ecb0a159-1b00-0000-5e60-1ad6930b0000 pid=2963->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=d64bd260-1b00-0000-5e60-1ad6a70b0000 pid=2983->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6c632361-1b00-0000-5e60-1ad6a80b0000 pid=2984 /tmp/WTF guuid=d64bd260-1b00-0000-5e60-1ad6a70b0000 pid=2983->guuid=6c632361-1b00-0000-5e60-1ad6a80b0000 pid=2984 clone guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986 /tmp/WTF write-config zombie guuid=6c632361-1b00-0000-5e60-1ad6a80b0000 pid=2984->guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986 clone guuid=49bb3f61-1b00-0000-5e60-1ad6a90b0000 pid=2985->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=2192e36b-1b00-0000-5e60-1ad6b40b0000 pid=2996 /usr/bin/dash guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986->guuid=2192e36b-1b00-0000-5e60-1ad6b40b0000 pid=2996 execve guuid=93c7e676-1b00-0000-5e60-1ad6c90b0000 pid=3017 /tmp/WTF delete-file guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986->guuid=93c7e676-1b00-0000-5e60-1ad6c90b0000 pid=3017 clone guuid=f89f4512-1f00-0000-5e60-1ad6f7140000 pid=5367 /tmp/WTF guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986->guuid=f89f4512-1f00-0000-5e60-1ad6f7140000 pid=5367 clone guuid=9fbc50af-2200-0000-5e60-1ad629150000 pid=5417 /tmp/WTF dns net send-data guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986->guuid=9fbc50af-2200-0000-5e60-1ad629150000 pid=5417 clone guuid=7cf39908-2700-0000-5e60-1ad638150000 pid=5432 /tmp/WTF guuid=b9396461-1b00-0000-5e60-1ad6aa0b0000 pid=2986->guuid=7cf39908-2700-0000-5e60-1ad638150000 pid=5432 clone guuid=87ce2269-1b00-0000-5e60-1ad6b10b0000 pid=2993->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=764b576d-1b00-0000-5e60-1ad6ba0b0000 pid=3002 /usr/bin/cp guuid=2192e36b-1b00-0000-5e60-1ad6b40b0000 pid=2996->guuid=764b576d-1b00-0000-5e60-1ad6ba0b0000 pid=3002 execve guuid=1d151b75-1b00-0000-5e60-1ad6c50b0000 pid=3013->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a73e4b75-1b00-0000-5e60-1ad6c60b0000 pid=3014 /tmp/WTF guuid=1d151b75-1b00-0000-5e60-1ad6c50b0000 pid=3013->guuid=a73e4b75-1b00-0000-5e60-1ad6c60b0000 pid=3014 clone guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015 /tmp/WTF write-config zombie guuid=a73e4b75-1b00-0000-5e60-1ad6c60b0000 pid=3014->guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015 clone guuid=39d8947a-1b00-0000-5e60-1ad6cf0b0000 pid=3023 /usr/bin/dash guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015->guuid=39d8947a-1b00-0000-5e60-1ad6cf0b0000 pid=3023 execve guuid=7427517d-1b00-0000-5e60-1ad6d80b0000 pid=3032 /tmp/WTF delete-file dns net send-data guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015->guuid=7427517d-1b00-0000-5e60-1ad6d80b0000 pid=3032 clone guuid=5d5fac48-2500-0000-5e60-1ad633150000 pid=5427 /tmp/WTF guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015->guuid=5d5fac48-2500-0000-5e60-1ad633150000 pid=5427 clone guuid=8a34cce0-2800-0000-5e60-1ad649150000 pid=5449 /tmp/WTF guuid=d8475875-1b00-0000-5e60-1ad6c70b0000 pid=3015->guuid=8a34cce0-2800-0000-5e60-1ad649150000 pid=5449 clone guuid=7d705a75-1b00-0000-5e60-1ad6c80b0000 pid=3016->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=35578e79-1b00-0000-5e60-1ad6cb0b0000 pid=3019->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=c163cf7a-1b00-0000-5e60-1ad6d10b0000 pid=3025 /usr/bin/cp guuid=39d8947a-1b00-0000-5e60-1ad6cf0b0000 pid=3023->guuid=c163cf7a-1b00-0000-5e60-1ad6d10b0000 pid=3025 execve guuid=7427517d-1b00-0000-5e60-1ad6d80b0000 pid=3032->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 114B guuid=7427517d-1b00-0000-5e60-1ad6d80b0000 pid=3032->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 15B guuid=62689286-1b00-0000-5e60-1ad6ee0b0000 pid=3054->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=018bb086-1b00-0000-5e60-1ad6ef0b0000 pid=3055 /tmp/WTF guuid=62689286-1b00-0000-5e60-1ad6ee0b0000 pid=3054->guuid=018bb086-1b00-0000-5e60-1ad6ef0b0000 pid=3055 clone guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059 /tmp/WTF write-config zombie guuid=018bb086-1b00-0000-5e60-1ad6ef0b0000 pid=3055->guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059 clone guuid=11110587-1b00-0000-5e60-1ad6f20b0000 pid=3058->7a155949-225c-5534-9d46-ce85bc851092 send: 148B guuid=8e2ae98c-1b00-0000-5e60-1ad6040c0000 pid=3076 /usr/bin/dash guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059->guuid=8e2ae98c-1b00-0000-5e60-1ad6040c0000 pid=3076 execve guuid=dccb1e92-1b00-0000-5e60-1ad6140c0000 pid=3092 /tmp/WTF delete-file guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059->guuid=dccb1e92-1b00-0000-5e60-1ad6140c0000 pid=3092 clone guuid=1120073a-1f00-0000-5e60-1ad6f8140000 pid=5368 /tmp/WTF guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059->guuid=1120073a-1f00-0000-5e60-1ad6f8140000 pid=5368 clone guuid=5e3f6beb-2200-0000-5e60-1ad62a150000 pid=5418 /tmp/WTF guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059->guuid=5e3f6beb-2200-0000-5e60-1ad62a150000 pid=5418 clone guuid=926e2681-2600-0000-5e60-1ad636150000 pid=5430 /tmp/WTF dns net send-data guuid=07553487-1b00-0000-5e60-1ad6f30b0000 pid=3059->guuid=926e2681-2600-0000-5e60-1ad636150000 pid=5430 clone guuid=4a001c8c-1b00-0000-5e60-1ad6030c0000 pid=3075->7a155949-225c-5534-9d46-ce85bc851092 send: 97B guuid=fe9c488d-1b00-0000-5e60-1ad6070c0000 pid=3079 /usr/bin/cp guuid=8e2ae98c-1b00-0000-5e60-1ad6040c0000 pid=3076->guuid=fe9c488d-1b00-0000-5e60-1ad6070c0000 pid=3079 execve guuid=b89fa999-1b00-0000-5e60-1ad62c0c0000 pid=3116->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dd45cd99-1b00-0000-5e60-1ad62d0c0000 pid=3117 /tmp/WTF guuid=b89fa999-1b00-0000-5e60-1ad62c0c0000 pid=3116->guuid=dd45cd99-1b00-0000-5e60-1ad62d0c0000 pid=3117 clone guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121 /tmp/WTF write-config zombie guuid=dd45cd99-1b00-0000-5e60-1ad62d0c0000 pid=3117->guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121 clone guuid=03f3d599-1b00-0000-5e60-1ad62e0c0000 pid=3118->7a155949-225c-5534-9d46-ce85bc851092 send: 149B guuid=ae71af9e-1b00-0000-5e60-1ad63e0c0000 pid=3134 /usr/bin/dash guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121->guuid=ae71af9e-1b00-0000-5e60-1ad63e0c0000 pid=3134 execve guuid=7a5441a7-1b00-0000-5e60-1ad6520c0000 pid=3154 /tmp/WTF delete-file guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121->guuid=7a5441a7-1b00-0000-5e60-1ad6520c0000 pid=3154 clone guuid=16519c5a-1f00-0000-5e60-1ad6f9140000 pid=5369 /tmp/WTF dns net send-data guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121->guuid=16519c5a-1f00-0000-5e60-1ad6f9140000 pid=5369 clone guuid=5d961318-2300-0000-5e60-1ad62b150000 pid=5419 /tmp/WTF guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121->guuid=5d961318-2300-0000-5e60-1ad62b150000 pid=5419 clone guuid=4705a9c0-2600-0000-5e60-1ad637150000 pid=5431 /tmp/WTF guuid=8bc6829a-1b00-0000-5e60-1ad6310c0000 pid=3121->guuid=4705a9c0-2600-0000-5e60-1ad637150000 pid=5431 clone guuid=49f61d9e-1b00-0000-5e60-1ad63b0c0000 pid=3131->7a155949-225c-5534-9d46-ce85bc851092 send: 98B guuid=5119569f-1b00-0000-5e60-1ad6400c0000 pid=3136 /usr/bin/cp guuid=ae71af9e-1b00-0000-5e60-1ad63e0c0000 pid=3134->guuid=5119569f-1b00-0000-5e60-1ad6400c0000 pid=3136 execve guuid=621b2bad-1b00-0000-5e60-1ad6630c0000 pid=3171->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d176c1ad-1b00-0000-5e60-1ad6640c0000 pid=3172 /tmp/WTF guuid=621b2bad-1b00-0000-5e60-1ad6630c0000 pid=3171->guuid=d176c1ad-1b00-0000-5e60-1ad6640c0000 pid=3172 clone guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175 /tmp/WTF write-config zombie guuid=d176c1ad-1b00-0000-5e60-1ad6640c0000 pid=3172->guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175 clone guuid=c89ecfad-1b00-0000-5e60-1ad6650c0000 pid=3173->7a155949-225c-5534-9d46-ce85bc851092 send: 155B guuid=4fb19cb7-1b00-0000-5e60-1ad67e0c0000 pid=3198 /usr/bin/dash guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175->guuid=4fb19cb7-1b00-0000-5e60-1ad67e0c0000 pid=3198 execve guuid=19617fbc-1b00-0000-5e60-1ad68d0c0000 pid=3213 /tmp/WTF dns net send-data guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175->guuid=19617fbc-1b00-0000-5e60-1ad68d0c0000 pid=3213 clone guuid=abc4500c-2100-0000-5e60-1ad606150000 pid=5382 /tmp/WTF dns net send-data guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175->guuid=abc4500c-2100-0000-5e60-1ad606150000 pid=5382 clone guuid=5a1f0bbe-2400-0000-5e60-1ad632150000 pid=5426 /tmp/WTF dns net send-data guuid=035050ae-1b00-0000-5e60-1ad6670c0000 pid=3175->guuid=5a1f0bbe-2400-0000-5e60-1ad632150000 pid=5426 clone guuid=d012fdb3-1b00-0000-5e60-1ad6740c0000 pid=3188->7a155949-225c-5534-9d46-ce85bc851092 send: 104B guuid=cb69dcb7-1b00-0000-5e60-1ad6800c0000 pid=3200 /usr/bin/cp guuid=4fb19cb7-1b00-0000-5e60-1ad67e0c0000 pid=3198->guuid=cb69dcb7-1b00-0000-5e60-1ad6800c0000 pid=3200 execve guuid=19617fbc-1b00-0000-5e60-1ad68d0c0000 pid=3213->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=19617fbc-1b00-0000-5e60-1ad68d0c0000 pid=3213->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=385e85cc-1b00-0000-5e60-1ad6b40c0000 pid=3252->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=29fea7cc-1b00-0000-5e60-1ad6b60c0000 pid=3254 /tmp/WTF guuid=385e85cc-1b00-0000-5e60-1ad6b40c0000 pid=3252->guuid=29fea7cc-1b00-0000-5e60-1ad6b60c0000 pid=3254 clone guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256 /tmp/WTF write-config zombie guuid=29fea7cc-1b00-0000-5e60-1ad6b60c0000 pid=3254->guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256 clone guuid=ee58afcc-1b00-0000-5e60-1ad6b70c0000 pid=3255->7a155949-225c-5534-9d46-ce85bc851092 send: 146B guuid=632880d1-1b00-0000-5e60-1ad6c50c0000 pid=3269 /usr/bin/dash guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256->guuid=632880d1-1b00-0000-5e60-1ad6c50c0000 pid=3269 execve guuid=1d76edd5-1b00-0000-5e60-1ad6cb0c0000 pid=3275 /tmp/WTF delete-file guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256->guuid=1d76edd5-1b00-0000-5e60-1ad6cb0c0000 pid=3275 clone guuid=e62bb982-1f00-0000-5e60-1ad6fa140000 pid=5370 /tmp/WTF dns net send-data guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256->guuid=e62bb982-1f00-0000-5e60-1ad6fa140000 pid=5370 clone guuid=06d1d1d9-2300-0000-5e60-1ad62e150000 pid=5422 /tmp/WTF guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256->guuid=06d1d1d9-2300-0000-5e60-1ad62e150000 pid=5422 clone guuid=567db883-2700-0000-5e60-1ad63a150000 pid=5434 /tmp/WTF guuid=f3e5b7cc-1b00-0000-5e60-1ad6b80c0000 pid=3256->guuid=567db883-2700-0000-5e60-1ad63a150000 pid=5434 clone guuid=6e4ec7d1-1b00-0000-5e60-1ad6c70c0000 pid=3271 /usr/bin/cp guuid=632880d1-1b00-0000-5e60-1ad6c50c0000 pid=3269->guuid=6e4ec7d1-1b00-0000-5e60-1ad6c70c0000 pid=3271 execve guuid=66986dd6-1b00-0000-5e60-1ad6cc0c0000 pid=3276->7a155949-225c-5534-9d46-ce85bc851092 send: 95B guuid=739ea7e6-1b00-0000-5e60-1ad6e40c0000 pid=3300->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c7453ee7-1b00-0000-5e60-1ad6e50c0000 pid=3301 /tmp/WTF guuid=739ea7e6-1b00-0000-5e60-1ad6e40c0000 pid=3300->guuid=c7453ee7-1b00-0000-5e60-1ad6e50c0000 pid=3301 clone guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303 /tmp/WTF write-config zombie guuid=c7453ee7-1b00-0000-5e60-1ad6e50c0000 pid=3301->guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303 clone guuid=4b3254e7-1b00-0000-5e60-1ad6e60c0000 pid=3302->7a155949-225c-5534-9d46-ce85bc851092 send: 145B guuid=cd6e33f0-1b00-0000-5e60-1ad6f90c0000 pid=3321 /usr/bin/dash guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303->guuid=cd6e33f0-1b00-0000-5e60-1ad6f90c0000 pid=3321 execve guuid=dc397bf9-1b00-0000-5e60-1ad60f0d0000 pid=3343 /tmp/WTF delete-file guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303->guuid=dc397bf9-1b00-0000-5e60-1ad60f0d0000 pid=3343 clone guuid=4705b19e-1f00-0000-5e60-1ad6fb140000 pid=5371 /tmp/WTF guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303->guuid=4705b19e-1f00-0000-5e60-1ad6fb140000 pid=5371 clone guuid=76140332-2300-0000-5e60-1ad62c150000 pid=5420 /tmp/WTF dns net send-data guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303->guuid=76140332-2300-0000-5e60-1ad62c150000 pid=5420 clone guuid=f5497ba3-2800-0000-5e60-1ad63e150000 pid=5438 /tmp/WTF guuid=25da7ce8-1b00-0000-5e60-1ad6e70c0000 pid=3303->guuid=f5497ba3-2800-0000-5e60-1ad63e150000 pid=5438 clone guuid=bce2bcf2-1b00-0000-5e60-1ad6fc0c0000 pid=3324 /usr/bin/cp guuid=cd6e33f0-1b00-0000-5e60-1ad6f90c0000 pid=3321->guuid=bce2bcf2-1b00-0000-5e60-1ad6fc0c0000 pid=3324 execve guuid=8dd12cf5-1b00-0000-5e60-1ad6030d0000 pid=3331->7a155949-225c-5534-9d46-ce85bc851092 send: 94B guuid=a8363cfd-1b00-0000-5e60-1ad6120d0000 pid=3346->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=18ca08fe-1b00-0000-5e60-1ad6130d0000 pid=3347 /tmp/WTF guuid=a8363cfd-1b00-0000-5e60-1ad6120d0000 pid=3346->guuid=18ca08fe-1b00-0000-5e60-1ad6130d0000 pid=3347 clone guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348 /tmp/WTF write-config zombie guuid=18ca08fe-1b00-0000-5e60-1ad6130d0000 pid=3347->guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348 clone guuid=a075c305-1c00-0000-5e60-1ad6200d0000 pid=3360 /usr/bin/dash guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348->guuid=a075c305-1c00-0000-5e60-1ad6200d0000 pid=3360 execve guuid=442a3b08-1c00-0000-5e60-1ad62a0d0000 pid=3370 /tmp/WTF dns net send-data guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348->guuid=442a3b08-1c00-0000-5e60-1ad62a0d0000 pid=3370 clone guuid=00e4a69a-2400-0000-5e60-1ad631150000 pid=5425 /tmp/WTF guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348->guuid=00e4a69a-2400-0000-5e60-1ad631150000 pid=5425 clone guuid=2bfaf54b-2800-0000-5e60-1ad63d150000 pid=5437 /tmp/WTF guuid=b0dad8ff-1b00-0000-5e60-1ad6140d0000 pid=3348->guuid=2bfaf54b-2800-0000-5e60-1ad63d150000 pid=5437 clone guuid=19e4ef05-1c00-0000-5e60-1ad6220d0000 pid=3362 /usr/bin/cp guuid=a075c305-1c00-0000-5e60-1ad6200d0000 pid=3360->guuid=19e4ef05-1c00-0000-5e60-1ad6220d0000 pid=3362 execve guuid=442a3b08-1c00-0000-5e60-1ad62a0d0000 pid=3370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 114B guuid=442a3b08-1c00-0000-5e60-1ad62a0d0000 pid=3370->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=866d4dc3-1e00-0000-5e60-1ad620140000 pid=5152->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=866d4dc3-1e00-0000-5e60-1ad620140000 pid=5152->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=16519c5a-1f00-0000-5e60-1ad6f9140000 pid=5369->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=16519c5a-1f00-0000-5e60-1ad6f9140000 pid=5369->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=e62bb982-1f00-0000-5e60-1ad6fa140000 pid=5370->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=e62bb982-1f00-0000-5e60-1ad6fa140000 pid=5370->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=99e58ef7-1f00-0000-5e60-1ad603150000 pid=5379->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=99e58ef7-1f00-0000-5e60-1ad603150000 pid=5379->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=de3f042b-2000-0000-5e60-1ad604150000 pid=5380->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=de3f042b-2000-0000-5e60-1ad604150000 pid=5380->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=abc4500c-2100-0000-5e60-1ad606150000 pid=5382->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=abc4500c-2100-0000-5e60-1ad606150000 pid=5382->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=9d2eb45d-2200-0000-5e60-1ad627150000 pid=5415->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 76B guuid=9d2eb45d-2200-0000-5e60-1ad627150000 pid=5415->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 10B guuid=9fbc50af-2200-0000-5e60-1ad629150000 pid=5417->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=9fbc50af-2200-0000-5e60-1ad629150000 pid=5417->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=76140332-2300-0000-5e60-1ad62c150000 pid=5420->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=76140332-2300-0000-5e60-1ad62c150000 pid=5420->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=769b3538-2400-0000-5e60-1ad630150000 pid=5424->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=769b3538-2400-0000-5e60-1ad630150000 pid=5424->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=5a1f0bbe-2400-0000-5e60-1ad632150000 pid=5426->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=5a1f0bbe-2400-0000-5e60-1ad632150000 pid=5426->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=55a431ee-2500-0000-5e60-1ad634150000 pid=5428->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=55a431ee-2500-0000-5e60-1ad634150000 pid=5428->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=b12adf3d-2600-0000-5e60-1ad635150000 pid=5429->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=b12adf3d-2600-0000-5e60-1ad635150000 pid=5429->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B guuid=926e2681-2600-0000-5e60-1ad636150000 pid=5430->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 38B guuid=926e2681-2600-0000-5e60-1ad636150000 pid=5430->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 5B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-07-17 17:25:34 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Reads process memory
Enumerates running processes
Modifies init.d
Modifies rc script
Enumerates active TCP sockets
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
top1miku.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Shellscript_Downloader
Author:albertzsigovits
Description:Generic Approach to Shellscript downloaders

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 6d6b5320e19cf931959185618a2d7d3a910ac4f42e5fe171a4dfdc856c06e255

(this sample)

  
Delivery method
Distributed via web download

Comments