MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 72d7c63cf91728a7d8843539dfcdff923795fb9ad6d7a7adf44d026376cf1600. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 12 File information Comments

SHA256 hash: 72d7c63cf91728a7d8843539dfcdff923795fb9ad6d7a7adf44d026376cf1600
SHA3-384 hash: 1926f49b29868365cba3964e545f8daf9aff60b98bfd8f58a1e89982d340c37804547cfffb4e639e7697e9f374fed460
SHA1 hash: bd50aee3c19e832e2974b525f299fc4323dd16c3
MD5 hash: 01554bd08d7108259ad36ba941ab5607
humanhash: emma-dakota-six-lemon
File name:cron
Download: download sample
Signature Mirai
File size:138'223 bytes
First seen:2025-07-12 05:24:41 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:/WVApgrZVtlzwCWu/PYInRn8uL/OmpFEthq9aTemT:/dSrMNEPYInW6/OmpFEthq9aTemT
TLSH T1B4D3A829F103C373D5930671228EEF662D305BD5379AB51AB3B43AB4AAB34473911E9C
telfhash t1f0315611943546142fb39928acbd56b315221b2323586f716f25c5cc49260e1e93dd0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
16
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Creating a file
Launching a process
Kills processes
Connection attempt
Substitutes an application name
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=7f7669f7-1800-0000-8bb4-3627100a0000 pid=2576 /usr/bin/sudo guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582 /tmp/sample.bin net guuid=7f7669f7-1800-0000-8bb4-3627100a0000 pid=2576->guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587 /tmp/sample.bin zombie guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582->guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587 clone guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588 /usr/bin/dash zombie guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582->guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588 execve guuid=b1b2aafa-1800-0000-8bb4-36271d0a0000 pid=2589 /tmp/sample.bin guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582->guuid=b1b2aafa-1800-0000-8bb4-36271d0a0000 pid=2589 clone guuid=8b08b0fa-1800-0000-8bb4-36271e0a0000 pid=2590 /tmp/sample.bin guuid=d38d35f9-1800-0000-8bb4-3627160a0000 pid=2582->guuid=8b08b0fa-1800-0000-8bb4-36271e0a0000 pid=2590 clone guuid=0433f32d-1900-0000-8bb4-3627bd0a0000 pid=2749 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=0433f32d-1900-0000-8bb4-3627bd0a0000 pid=2749 execve guuid=6a3b1c31-1900-0000-8bb4-3627c50a0000 pid=2757 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=6a3b1c31-1900-0000-8bb4-3627c50a0000 pid=2757 execve guuid=ff105432-1900-0000-8bb4-3627c90a0000 pid=2761 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=ff105432-1900-0000-8bb4-3627c90a0000 pid=2761 execve guuid=324df733-1900-0000-8bb4-3627cf0a0000 pid=2767 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=324df733-1900-0000-8bb4-3627cf0a0000 pid=2767 execve guuid=0879d335-1900-0000-8bb4-3627d10a0000 pid=2769 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=0879d335-1900-0000-8bb4-3627d10a0000 pid=2769 execve guuid=ebf61937-1900-0000-8bb4-3627d30a0000 pid=2771 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=ebf61937-1900-0000-8bb4-3627d30a0000 pid=2771 execve guuid=1e159138-1900-0000-8bb4-3627d50a0000 pid=2773 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1e159138-1900-0000-8bb4-3627d50a0000 pid=2773 execve guuid=7ca58039-1900-0000-8bb4-3627d70a0000 pid=2775 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=7ca58039-1900-0000-8bb4-3627d70a0000 pid=2775 execve guuid=21f88e3a-1900-0000-8bb4-3627d90a0000 pid=2777 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=21f88e3a-1900-0000-8bb4-3627d90a0000 pid=2777 execve guuid=4e493c68-1a00-0000-8bb4-3627830d0000 pid=3459 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4e493c68-1a00-0000-8bb4-3627830d0000 pid=3459 execve guuid=a92c4a6b-1a00-0000-8bb4-36278f0d0000 pid=3471 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=a92c4a6b-1a00-0000-8bb4-36278f0d0000 pid=3471 execve guuid=d9d89a6c-1a00-0000-8bb4-3627940d0000 pid=3476 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d9d89a6c-1a00-0000-8bb4-3627940d0000 pid=3476 execve guuid=2d4bd06d-1a00-0000-8bb4-3627990d0000 pid=3481 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=2d4bd06d-1a00-0000-8bb4-3627990d0000 pid=3481 execve guuid=69070f6f-1a00-0000-8bb4-36279f0d0000 pid=3487 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=69070f6f-1a00-0000-8bb4-36279f0d0000 pid=3487 execve guuid=b0784170-1a00-0000-8bb4-3627a60d0000 pid=3494 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=b0784170-1a00-0000-8bb4-3627a60d0000 pid=3494 execve guuid=d43a1b71-1a00-0000-8bb4-3627ab0d0000 pid=3499 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d43a1b71-1a00-0000-8bb4-3627ab0d0000 pid=3499 execve guuid=fb965272-1a00-0000-8bb4-3627b10d0000 pid=3505 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=fb965272-1a00-0000-8bb4-3627b10d0000 pid=3505 execve guuid=18935f73-1a00-0000-8bb4-3627b50d0000 pid=3509 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=18935f73-1a00-0000-8bb4-3627b50d0000 pid=3509 execve guuid=1b9236a2-1b00-0000-8bb4-362734110000 pid=4404 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1b9236a2-1b00-0000-8bb4-362734110000 pid=4404 execve guuid=d9519ba6-1b00-0000-8bb4-36273e110000 pid=4414 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d9519ba6-1b00-0000-8bb4-36273e110000 pid=4414 execve guuid=2ada94a8-1b00-0000-8bb4-362749110000 pid=4425 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=2ada94a8-1b00-0000-8bb4-362749110000 pid=4425 execve guuid=c246a4a9-1b00-0000-8bb4-36274f110000 pid=4431 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=c246a4a9-1b00-0000-8bb4-36274f110000 pid=4431 execve guuid=5f4a7faa-1b00-0000-8bb4-362758110000 pid=4440 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=5f4a7faa-1b00-0000-8bb4-362758110000 pid=4440 execve guuid=dfce5eab-1b00-0000-8bb4-36275c110000 pid=4444 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=dfce5eab-1b00-0000-8bb4-36275c110000 pid=4444 execve guuid=e00951ac-1b00-0000-8bb4-362764110000 pid=4452 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=e00951ac-1b00-0000-8bb4-362764110000 pid=4452 execve guuid=53013cad-1b00-0000-8bb4-36276a110000 pid=4458 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=53013cad-1b00-0000-8bb4-36276a110000 pid=4458 execve guuid=cda124ae-1b00-0000-8bb4-36276f110000 pid=4463 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=cda124ae-1b00-0000-8bb4-36276f110000 pid=4463 execve guuid=514b92ee-1c00-0000-8bb4-3627b0140000 pid=5296 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=514b92ee-1c00-0000-8bb4-3627b0140000 pid=5296 execve guuid=b740ecf3-1c00-0000-8bb4-3627bb140000 pid=5307 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=b740ecf3-1c00-0000-8bb4-3627bb140000 pid=5307 execve guuid=7d965af5-1c00-0000-8bb4-3627bd140000 pid=5309 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=7d965af5-1c00-0000-8bb4-3627bd140000 pid=5309 execve guuid=d56f99f6-1c00-0000-8bb4-3627bf140000 pid=5311 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d56f99f6-1c00-0000-8bb4-3627bf140000 pid=5311 execve guuid=3276e8f7-1c00-0000-8bb4-3627c1140000 pid=5313 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=3276e8f7-1c00-0000-8bb4-3627c1140000 pid=5313 execve guuid=64e705f9-1c00-0000-8bb4-3627c3140000 pid=5315 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=64e705f9-1c00-0000-8bb4-3627c3140000 pid=5315 execve guuid=532a36fa-1c00-0000-8bb4-3627c5140000 pid=5317 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=532a36fa-1c00-0000-8bb4-3627c5140000 pid=5317 execve guuid=1ab14afb-1c00-0000-8bb4-3627c7140000 pid=5319 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1ab14afb-1c00-0000-8bb4-3627c7140000 pid=5319 execve guuid=eb1ae9fc-1c00-0000-8bb4-3627c9140000 pid=5321 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=eb1ae9fc-1c00-0000-8bb4-3627c9140000 pid=5321 execve guuid=5eb8bd2a-1e00-0000-8bb4-3627cc140000 pid=5324 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=5eb8bd2a-1e00-0000-8bb4-3627cc140000 pid=5324 execve guuid=b188d42d-1e00-0000-8bb4-3627ce140000 pid=5326 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=b188d42d-1e00-0000-8bb4-3627ce140000 pid=5326 execve guuid=1e06122f-1e00-0000-8bb4-3627d0140000 pid=5328 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1e06122f-1e00-0000-8bb4-3627d0140000 pid=5328 execve guuid=361b5e30-1e00-0000-8bb4-3627d2140000 pid=5330 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=361b5e30-1e00-0000-8bb4-3627d2140000 pid=5330 execve guuid=95a1df32-1e00-0000-8bb4-3627d4140000 pid=5332 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=95a1df32-1e00-0000-8bb4-3627d4140000 pid=5332 execve guuid=8101d133-1e00-0000-8bb4-3627d6140000 pid=5334 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=8101d133-1e00-0000-8bb4-3627d6140000 pid=5334 execve guuid=5cd9b534-1e00-0000-8bb4-3627d8140000 pid=5336 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=5cd9b534-1e00-0000-8bb4-3627d8140000 pid=5336 execve guuid=676d9135-1e00-0000-8bb4-3627da140000 pid=5338 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=676d9135-1e00-0000-8bb4-3627da140000 pid=5338 execve guuid=426e2537-1e00-0000-8bb4-3627dc140000 pid=5340 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=426e2537-1e00-0000-8bb4-3627dc140000 pid=5340 execve guuid=9e4e7165-1f00-0000-8bb4-3627ea140000 pid=5354 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=9e4e7165-1f00-0000-8bb4-3627ea140000 pid=5354 execve guuid=cdb06869-1f00-0000-8bb4-3627ec140000 pid=5356 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=cdb06869-1f00-0000-8bb4-3627ec140000 pid=5356 execve guuid=20ba686a-1f00-0000-8bb4-3627ee140000 pid=5358 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=20ba686a-1f00-0000-8bb4-3627ee140000 pid=5358 execve guuid=883f496b-1f00-0000-8bb4-3627f0140000 pid=5360 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=883f496b-1f00-0000-8bb4-3627f0140000 pid=5360 execve guuid=ada0256c-1f00-0000-8bb4-3627f2140000 pid=5362 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=ada0256c-1f00-0000-8bb4-3627f2140000 pid=5362 execve guuid=8f79ff6c-1f00-0000-8bb4-3627f4140000 pid=5364 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=8f79ff6c-1f00-0000-8bb4-3627f4140000 pid=5364 execve guuid=cdedf96d-1f00-0000-8bb4-3627f6140000 pid=5366 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=cdedf96d-1f00-0000-8bb4-3627f6140000 pid=5366 execve guuid=4d96f06e-1f00-0000-8bb4-3627f8140000 pid=5368 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4d96f06e-1f00-0000-8bb4-3627f8140000 pid=5368 execve guuid=c2dbf86f-1f00-0000-8bb4-3627fa140000 pid=5370 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=c2dbf86f-1f00-0000-8bb4-3627fa140000 pid=5370 execve guuid=df74629f-2000-0000-8bb4-36271d150000 pid=5405 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=df74629f-2000-0000-8bb4-36271d150000 pid=5405 execve guuid=7adf25a4-2000-0000-8bb4-36271f150000 pid=5407 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=7adf25a4-2000-0000-8bb4-36271f150000 pid=5407 execve guuid=f01dbea5-2000-0000-8bb4-362721150000 pid=5409 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=f01dbea5-2000-0000-8bb4-362721150000 pid=5409 execve guuid=c5e482a7-2000-0000-8bb4-362723150000 pid=5411 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=c5e482a7-2000-0000-8bb4-362723150000 pid=5411 execve guuid=3db335a9-2000-0000-8bb4-362725150000 pid=5413 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=3db335a9-2000-0000-8bb4-362725150000 pid=5413 execve guuid=81aa00ab-2000-0000-8bb4-362727150000 pid=5415 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=81aa00ab-2000-0000-8bb4-362727150000 pid=5415 execve guuid=f0f6c0ac-2000-0000-8bb4-362729150000 pid=5417 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=f0f6c0ac-2000-0000-8bb4-362729150000 pid=5417 execve guuid=cc0960ae-2000-0000-8bb4-36272b150000 pid=5419 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=cc0960ae-2000-0000-8bb4-36272b150000 pid=5419 execve guuid=fcab02b0-2000-0000-8bb4-36272d150000 pid=5421 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=fcab02b0-2000-0000-8bb4-36272d150000 pid=5421 execve guuid=7ad5bddf-2100-0000-8bb4-36272f150000 pid=5423 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=7ad5bddf-2100-0000-8bb4-36272f150000 pid=5423 execve guuid=daba34e4-2100-0000-8bb4-362731150000 pid=5425 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=daba34e4-2100-0000-8bb4-362731150000 pid=5425 execve guuid=4e594ee5-2100-0000-8bb4-362733150000 pid=5427 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4e594ee5-2100-0000-8bb4-362733150000 pid=5427 execve guuid=06849ce6-2100-0000-8bb4-362735150000 pid=5429 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=06849ce6-2100-0000-8bb4-362735150000 pid=5429 execve guuid=27440fe8-2100-0000-8bb4-362737150000 pid=5431 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=27440fe8-2100-0000-8bb4-362737150000 pid=5431 execve guuid=ba2435e9-2100-0000-8bb4-362739150000 pid=5433 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=ba2435e9-2100-0000-8bb4-362739150000 pid=5433 execve guuid=640337ea-2100-0000-8bb4-36273b150000 pid=5435 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=640337ea-2100-0000-8bb4-36273b150000 pid=5435 execve guuid=1a6917eb-2100-0000-8bb4-36273d150000 pid=5437 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1a6917eb-2100-0000-8bb4-36273d150000 pid=5437 execve guuid=36d3fceb-2100-0000-8bb4-36273f150000 pid=5439 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=36d3fceb-2100-0000-8bb4-36273f150000 pid=5439 execve guuid=6a9bdd1a-2300-0000-8bb4-362741150000 pid=5441 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=6a9bdd1a-2300-0000-8bb4-362741150000 pid=5441 execve guuid=93c0591f-2300-0000-8bb4-362743150000 pid=5443 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=93c0591f-2300-0000-8bb4-362743150000 pid=5443 execve guuid=1ac21221-2300-0000-8bb4-362745150000 pid=5445 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1ac21221-2300-0000-8bb4-362745150000 pid=5445 execve guuid=d000b922-2300-0000-8bb4-362747150000 pid=5447 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d000b922-2300-0000-8bb4-362747150000 pid=5447 execve guuid=e6a16524-2300-0000-8bb4-362749150000 pid=5449 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=e6a16524-2300-0000-8bb4-362749150000 pid=5449 execve guuid=60542326-2300-0000-8bb4-36274b150000 pid=5451 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=60542326-2300-0000-8bb4-36274b150000 pid=5451 execve guuid=4d6cc127-2300-0000-8bb4-36274d150000 pid=5453 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4d6cc127-2300-0000-8bb4-36274d150000 pid=5453 execve guuid=a6853729-2300-0000-8bb4-36274f150000 pid=5455 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=a6853729-2300-0000-8bb4-36274f150000 pid=5455 execve guuid=a563b92a-2300-0000-8bb4-362751150000 pid=5457 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=a563b92a-2300-0000-8bb4-362751150000 pid=5457 execve guuid=f5457a5a-2400-0000-8bb4-362753150000 pid=5459 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=f5457a5a-2400-0000-8bb4-362753150000 pid=5459 execve guuid=4e2a2b5f-2400-0000-8bb4-362755150000 pid=5461 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4e2a2b5f-2400-0000-8bb4-362755150000 pid=5461 execve guuid=c96abe60-2400-0000-8bb4-362757150000 pid=5463 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=c96abe60-2400-0000-8bb4-362757150000 pid=5463 execve guuid=02bd8662-2400-0000-8bb4-362759150000 pid=5465 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=02bd8662-2400-0000-8bb4-362759150000 pid=5465 execve guuid=5f205064-2400-0000-8bb4-36275b150000 pid=5467 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=5f205064-2400-0000-8bb4-36275b150000 pid=5467 execve guuid=2c4f1866-2400-0000-8bb4-36275d150000 pid=5469 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=2c4f1866-2400-0000-8bb4-36275d150000 pid=5469 execve guuid=1029e867-2400-0000-8bb4-36275f150000 pid=5471 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=1029e867-2400-0000-8bb4-36275f150000 pid=5471 execve guuid=baf9d769-2400-0000-8bb4-362761150000 pid=5473 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=baf9d769-2400-0000-8bb4-362761150000 pid=5473 execve guuid=d9c1c26b-2400-0000-8bb4-362763150000 pid=5475 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=d9c1c26b-2400-0000-8bb4-362763150000 pid=5475 execve guuid=566f7d9b-2500-0000-8bb4-362765150000 pid=5477 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=566f7d9b-2500-0000-8bb4-362765150000 pid=5477 execve guuid=89ff64a0-2500-0000-8bb4-362767150000 pid=5479 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=89ff64a0-2500-0000-8bb4-362767150000 pid=5479 execve guuid=fda8d7a1-2500-0000-8bb4-362769150000 pid=5481 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=fda8d7a1-2500-0000-8bb4-362769150000 pid=5481 execve guuid=02d9a0a3-2500-0000-8bb4-36276b150000 pid=5483 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=02d9a0a3-2500-0000-8bb4-36276b150000 pid=5483 execve guuid=17df7ea5-2500-0000-8bb4-36276d150000 pid=5485 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=17df7ea5-2500-0000-8bb4-36276d150000 pid=5485 execve guuid=8ef7e6a6-2500-0000-8bb4-36276f150000 pid=5487 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=8ef7e6a6-2500-0000-8bb4-36276f150000 pid=5487 execve guuid=b7a29da8-2500-0000-8bb4-362771150000 pid=5489 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=b7a29da8-2500-0000-8bb4-362771150000 pid=5489 execve guuid=f5a14baa-2500-0000-8bb4-362773150000 pid=5491 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=f5a14baa-2500-0000-8bb4-362773150000 pid=5491 execve guuid=4185f5ab-2500-0000-8bb4-362775150000 pid=5493 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=4185f5ab-2500-0000-8bb4-362775150000 pid=5493 execve guuid=00bd6ada-2600-0000-8bb4-362779150000 pid=5497 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=00bd6ada-2600-0000-8bb4-362779150000 pid=5497 execve guuid=0b1f53dd-2600-0000-8bb4-36277b150000 pid=5499 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=0b1f53dd-2600-0000-8bb4-36277b150000 pid=5499 execve guuid=42d721de-2600-0000-8bb4-36277d150000 pid=5501 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=42d721de-2600-0000-8bb4-36277d150000 pid=5501 execve guuid=5d08e8de-2600-0000-8bb4-36277f150000 pid=5503 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=5d08e8de-2600-0000-8bb4-36277f150000 pid=5503 execve guuid=2a05b2df-2600-0000-8bb4-362781150000 pid=5505 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=2a05b2df-2600-0000-8bb4-362781150000 pid=5505 execve guuid=42c587e0-2600-0000-8bb4-362783150000 pid=5507 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=42c587e0-2600-0000-8bb4-362783150000 pid=5507 execve guuid=342967e1-2600-0000-8bb4-362785150000 pid=5509 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=342967e1-2600-0000-8bb4-362785150000 pid=5509 execve guuid=b5f341e2-2600-0000-8bb4-362787150000 pid=5511 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=b5f341e2-2600-0000-8bb4-362787150000 pid=5511 execve guuid=321130e3-2600-0000-8bb4-362789150000 pid=5513 /usr/bin/dash guuid=61459bfa-1800-0000-8bb4-36271b0a0000 pid=2587->guuid=321130e3-2600-0000-8bb4-362789150000 pid=5513 execve guuid=befbd2fa-1800-0000-8bb4-36271f0a0000 pid=2591 /usr/bin/wget dns net send-data guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588->guuid=befbd2fa-1800-0000-8bb4-36271f0a0000 pid=2591 execve guuid=4c597f00-1900-0000-8bb4-3627320a0000 pid=2610 /usr/bin/chmod guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588->guuid=4c597f00-1900-0000-8bb4-3627320a0000 pid=2610 execve guuid=5574b700-1900-0000-8bb4-3627340a0000 pid=2612 /home/sandbox/..... guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588->guuid=5574b700-1900-0000-8bb4-3627340a0000 pid=2612 execve guuid=ef8ad101-1900-0000-8bb4-36273a0a0000 pid=2618 /usr/bin/rm delete-file guuid=24c2a3fa-1800-0000-8bb4-36271c0a0000 pid=2588->guuid=ef8ad101-1900-0000-8bb4-36273a0a0000 pid=2618 execve guuid=2b4edbfa-1800-0000-8bb4-3627200a0000 pid=2592 /tmp/sample.bin net send-data zombie guuid=8b08b0fa-1800-0000-8bb4-36271e0a0000 pid=2590->guuid=2b4edbfa-1800-0000-8bb4-3627200a0000 pid=2592 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=befbd2fa-1800-0000-8bb4-36271f0a0000 pid=2591->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=2b4edbfa-1800-0000-8bb4-3627200a0000 pid=2592->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B guuid=959f432e-1900-0000-8bb4-3627bf0a0000 pid=2751 /usr/bin/pgrep guuid=0433f32d-1900-0000-8bb4-3627bd0a0000 pid=2749->guuid=959f432e-1900-0000-8bb4-3627bf0a0000 pid=2751 execve guuid=e8596e31-1900-0000-8bb4-3627c60a0000 pid=2758 /usr/bin/killall guuid=6a3b1c31-1900-0000-8bb4-3627c50a0000 pid=2757->guuid=e8596e31-1900-0000-8bb4-3627c60a0000 pid=2758 execve guuid=d3017d32-1900-0000-8bb4-3627cb0a0000 pid=2763 /usr/bin/killall guuid=ff105432-1900-0000-8bb4-3627c90a0000 pid=2761->guuid=d3017d32-1900-0000-8bb4-3627cb0a0000 pid=2763 execve guuid=09b43634-1900-0000-8bb4-3627d00a0000 pid=2768 /usr/bin/killall guuid=324df733-1900-0000-8bb4-3627cf0a0000 pid=2767->guuid=09b43634-1900-0000-8bb4-3627d00a0000 pid=2768 execve guuid=ded00736-1900-0000-8bb4-3627d20a0000 pid=2770 /usr/bin/killall guuid=0879d335-1900-0000-8bb4-3627d10a0000 pid=2769->guuid=ded00736-1900-0000-8bb4-3627d20a0000 pid=2770 execve guuid=65684d37-1900-0000-8bb4-3627d40a0000 pid=2772 /usr/bin/killall guuid=ebf61937-1900-0000-8bb4-3627d30a0000 pid=2771->guuid=65684d37-1900-0000-8bb4-3627d40a0000 pid=2772 execve guuid=0e75c438-1900-0000-8bb4-3627d60a0000 pid=2774 /usr/bin/killall guuid=1e159138-1900-0000-8bb4-3627d50a0000 pid=2773->guuid=0e75c438-1900-0000-8bb4-3627d60a0000 pid=2774 execve guuid=df7cb339-1900-0000-8bb4-3627d80a0000 pid=2776 /usr/bin/killall guuid=7ca58039-1900-0000-8bb4-3627d70a0000 pid=2775->guuid=df7cb339-1900-0000-8bb4-3627d80a0000 pid=2776 execve guuid=9afdc73a-1900-0000-8bb4-3627da0a0000 pid=2778 /usr/bin/killall guuid=21f88e3a-1900-0000-8bb4-3627d90a0000 pid=2777->guuid=9afdc73a-1900-0000-8bb4-3627da0a0000 pid=2778 execve guuid=e9736868-1a00-0000-8bb4-3627850d0000 pid=3461 /usr/bin/pgrep guuid=4e493c68-1a00-0000-8bb4-3627830d0000 pid=3459->guuid=e9736868-1a00-0000-8bb4-3627850d0000 pid=3461 execve guuid=3f467d6b-1a00-0000-8bb4-3627900d0000 pid=3472 /usr/bin/killall guuid=a92c4a6b-1a00-0000-8bb4-36278f0d0000 pid=3471->guuid=3f467d6b-1a00-0000-8bb4-3627900d0000 pid=3472 execve guuid=5b6cc86c-1a00-0000-8bb4-3627950d0000 pid=3477 /usr/bin/killall guuid=d9d89a6c-1a00-0000-8bb4-3627940d0000 pid=3476->guuid=5b6cc86c-1a00-0000-8bb4-3627950d0000 pid=3477 execve guuid=4cae046e-1a00-0000-8bb4-36279b0d0000 pid=3483 /usr/bin/killall guuid=2d4bd06d-1a00-0000-8bb4-3627990d0000 pid=3481->guuid=4cae046e-1a00-0000-8bb4-36279b0d0000 pid=3483 execve guuid=0959386f-1a00-0000-8bb4-3627a10d0000 pid=3489 /usr/bin/killall guuid=69070f6f-1a00-0000-8bb4-36279f0d0000 pid=3487->guuid=0959386f-1a00-0000-8bb4-3627a10d0000 pid=3489 execve guuid=a0576970-1a00-0000-8bb4-3627a70d0000 pid=3495 /usr/bin/killall guuid=b0784170-1a00-0000-8bb4-3627a60d0000 pid=3494->guuid=a0576970-1a00-0000-8bb4-3627a70d0000 pid=3495 execve guuid=865c4171-1a00-0000-8bb4-3627ac0d0000 pid=3500 /usr/bin/killall guuid=d43a1b71-1a00-0000-8bb4-3627ab0d0000 pid=3499->guuid=865c4171-1a00-0000-8bb4-3627ac0d0000 pid=3500 execve guuid=ff41a472-1a00-0000-8bb4-3627b20d0000 pid=3506 /usr/bin/killall guuid=fb965272-1a00-0000-8bb4-3627b10d0000 pid=3505->guuid=ff41a472-1a00-0000-8bb4-3627b20d0000 pid=3506 execve guuid=28548e73-1a00-0000-8bb4-3627b70d0000 pid=3511 /usr/bin/killall guuid=18935f73-1a00-0000-8bb4-3627b50d0000 pid=3509->guuid=28548e73-1a00-0000-8bb4-3627b70d0000 pid=3511 execve guuid=0ca687a2-1b00-0000-8bb4-362735110000 pid=4405 /usr/bin/pgrep guuid=1b9236a2-1b00-0000-8bb4-362734110000 pid=4404->guuid=0ca687a2-1b00-0000-8bb4-362735110000 pid=4405 execve guuid=5fe81ca7-1b00-0000-8bb4-362741110000 pid=4417 /usr/bin/killall guuid=d9519ba6-1b00-0000-8bb4-36273e110000 pid=4414->guuid=5fe81ca7-1b00-0000-8bb4-362741110000 pid=4417 execve guuid=069ebda8-1b00-0000-8bb4-36274a110000 pid=4426 /usr/bin/killall guuid=2ada94a8-1b00-0000-8bb4-362749110000 pid=4425->guuid=069ebda8-1b00-0000-8bb4-36274a110000 pid=4426 execve guuid=0585cfa9-1b00-0000-8bb4-362751110000 pid=4433 /usr/bin/killall guuid=c246a4a9-1b00-0000-8bb4-36274f110000 pid=4431->guuid=0585cfa9-1b00-0000-8bb4-362751110000 pid=4433 execve guuid=ab2faeaa-1b00-0000-8bb4-362759110000 pid=4441 /usr/bin/killall guuid=5f4a7faa-1b00-0000-8bb4-362758110000 pid=4440->guuid=ab2faeaa-1b00-0000-8bb4-362759110000 pid=4441 execve guuid=ba5e98ab-1b00-0000-8bb4-362760110000 pid=4448 /usr/bin/killall guuid=dfce5eab-1b00-0000-8bb4-36275c110000 pid=4444->guuid=ba5e98ab-1b00-0000-8bb4-362760110000 pid=4448 execve guuid=11a98aac-1b00-0000-8bb4-362766110000 pid=4454 /usr/bin/killall guuid=e00951ac-1b00-0000-8bb4-362764110000 pid=4452->guuid=11a98aac-1b00-0000-8bb4-362766110000 pid=4454 execve guuid=c14d72ad-1b00-0000-8bb4-36276b110000 pid=4459 /usr/bin/killall guuid=53013cad-1b00-0000-8bb4-36276a110000 pid=4458->guuid=c14d72ad-1b00-0000-8bb4-36276b110000 pid=4459 execve guuid=9ff45dae-1b00-0000-8bb4-362770110000 pid=4464 /usr/bin/killall guuid=cda124ae-1b00-0000-8bb4-36276f110000 pid=4463->guuid=9ff45dae-1b00-0000-8bb4-362770110000 pid=4464 execve guuid=8002d5ee-1c00-0000-8bb4-3627b2140000 pid=5298 /usr/bin/pgrep guuid=514b92ee-1c00-0000-8bb4-3627b0140000 pid=5296->guuid=8002d5ee-1c00-0000-8bb4-3627b2140000 pid=5298 execve guuid=46c035f4-1c00-0000-8bb4-3627bc140000 pid=5308 /usr/bin/killall guuid=b740ecf3-1c00-0000-8bb4-3627bb140000 pid=5307->guuid=46c035f4-1c00-0000-8bb4-3627bc140000 pid=5308 execve guuid=856f9cf5-1c00-0000-8bb4-3627be140000 pid=5310 /usr/bin/killall guuid=7d965af5-1c00-0000-8bb4-3627bd140000 pid=5309->guuid=856f9cf5-1c00-0000-8bb4-3627be140000 pid=5310 execve guuid=a128f7f6-1c00-0000-8bb4-3627c0140000 pid=5312 /usr/bin/killall guuid=d56f99f6-1c00-0000-8bb4-3627bf140000 pid=5311->guuid=a128f7f6-1c00-0000-8bb4-3627c0140000 pid=5312 execve guuid=12cc17f8-1c00-0000-8bb4-3627c2140000 pid=5314 /usr/bin/killall guuid=3276e8f7-1c00-0000-8bb4-3627c1140000 pid=5313->guuid=12cc17f8-1c00-0000-8bb4-3627c2140000 pid=5314 execve guuid=b5854cf9-1c00-0000-8bb4-3627c4140000 pid=5316 /usr/bin/killall guuid=64e705f9-1c00-0000-8bb4-3627c3140000 pid=5315->guuid=b5854cf9-1c00-0000-8bb4-3627c4140000 pid=5316 execve guuid=3b3b81fa-1c00-0000-8bb4-3627c6140000 pid=5318 /usr/bin/killall guuid=532a36fa-1c00-0000-8bb4-3627c5140000 pid=5317->guuid=3b3b81fa-1c00-0000-8bb4-3627c6140000 pid=5318 execve guuid=2b3f95fb-1c00-0000-8bb4-3627c8140000 pid=5320 /usr/bin/killall guuid=1ab14afb-1c00-0000-8bb4-3627c7140000 pid=5319->guuid=2b3f95fb-1c00-0000-8bb4-3627c8140000 pid=5320 execve guuid=df8f2ffd-1c00-0000-8bb4-3627ca140000 pid=5322 /usr/bin/killall guuid=eb1ae9fc-1c00-0000-8bb4-3627c9140000 pid=5321->guuid=df8f2ffd-1c00-0000-8bb4-3627ca140000 pid=5322 execve guuid=a1cd0e2b-1e00-0000-8bb4-3627cd140000 pid=5325 /usr/bin/pgrep guuid=5eb8bd2a-1e00-0000-8bb4-3627cc140000 pid=5324->guuid=a1cd0e2b-1e00-0000-8bb4-3627cd140000 pid=5325 execve guuid=e0e9422e-1e00-0000-8bb4-3627cf140000 pid=5327 /usr/bin/killall guuid=b188d42d-1e00-0000-8bb4-3627ce140000 pid=5326->guuid=e0e9422e-1e00-0000-8bb4-3627cf140000 pid=5327 execve guuid=d0b38e2f-1e00-0000-8bb4-3627d1140000 pid=5329 /usr/bin/killall guuid=1e06122f-1e00-0000-8bb4-3627d0140000 pid=5328->guuid=d0b38e2f-1e00-0000-8bb4-3627d1140000 pid=5329 execve guuid=30509e30-1e00-0000-8bb4-3627d3140000 pid=5331 /usr/bin/killall guuid=361b5e30-1e00-0000-8bb4-3627d2140000 pid=5330->guuid=30509e30-1e00-0000-8bb4-3627d3140000 pid=5331 execve guuid=9dc11233-1e00-0000-8bb4-3627d5140000 pid=5333 /usr/bin/killall guuid=95a1df32-1e00-0000-8bb4-3627d4140000 pid=5332->guuid=9dc11233-1e00-0000-8bb4-3627d5140000 pid=5333 execve guuid=30a50134-1e00-0000-8bb4-3627d7140000 pid=5335 /usr/bin/killall guuid=8101d133-1e00-0000-8bb4-3627d6140000 pid=5334->guuid=30a50134-1e00-0000-8bb4-3627d7140000 pid=5335 execve guuid=5a24e234-1e00-0000-8bb4-3627d9140000 pid=5337 /usr/bin/killall guuid=5cd9b534-1e00-0000-8bb4-3627d8140000 pid=5336->guuid=5a24e234-1e00-0000-8bb4-3627d9140000 pid=5337 execve guuid=49cfcf35-1e00-0000-8bb4-3627db140000 pid=5339 /usr/bin/killall guuid=676d9135-1e00-0000-8bb4-3627da140000 pid=5338->guuid=49cfcf35-1e00-0000-8bb4-3627db140000 pid=5339 execve guuid=fb9a9f37-1e00-0000-8bb4-3627dd140000 pid=5341 /usr/bin/killall guuid=426e2537-1e00-0000-8bb4-3627dc140000 pid=5340->guuid=fb9a9f37-1e00-0000-8bb4-3627dd140000 pid=5341 execve guuid=1e82b065-1f00-0000-8bb4-3627eb140000 pid=5355 /usr/bin/pgrep guuid=9e4e7165-1f00-0000-8bb4-3627ea140000 pid=5354->guuid=1e82b065-1f00-0000-8bb4-3627eb140000 pid=5355 execve guuid=8f399c69-1f00-0000-8bb4-3627ed140000 pid=5357 /usr/bin/killall guuid=cdb06869-1f00-0000-8bb4-3627ec140000 pid=5356->guuid=8f399c69-1f00-0000-8bb4-3627ed140000 pid=5357 execve guuid=dbf2986a-1f00-0000-8bb4-3627ef140000 pid=5359 /usr/bin/killall guuid=20ba686a-1f00-0000-8bb4-3627ee140000 pid=5358->guuid=dbf2986a-1f00-0000-8bb4-3627ef140000 pid=5359 execve guuid=ea6d766b-1f00-0000-8bb4-3627f1140000 pid=5361 /usr/bin/killall guuid=883f496b-1f00-0000-8bb4-3627f0140000 pid=5360->guuid=ea6d766b-1f00-0000-8bb4-3627f1140000 pid=5361 execve guuid=b446526c-1f00-0000-8bb4-3627f3140000 pid=5363 /usr/bin/killall guuid=ada0256c-1f00-0000-8bb4-3627f2140000 pid=5362->guuid=b446526c-1f00-0000-8bb4-3627f3140000 pid=5363 execve guuid=2b23266d-1f00-0000-8bb4-3627f5140000 pid=5365 /usr/bin/killall guuid=8f79ff6c-1f00-0000-8bb4-3627f4140000 pid=5364->guuid=2b23266d-1f00-0000-8bb4-3627f5140000 pid=5365 execve guuid=515d2b6e-1f00-0000-8bb4-3627f7140000 pid=5367 /usr/bin/killall guuid=cdedf96d-1f00-0000-8bb4-3627f6140000 pid=5366->guuid=515d2b6e-1f00-0000-8bb4-3627f7140000 pid=5367 execve guuid=c312206f-1f00-0000-8bb4-3627f9140000 pid=5369 /usr/bin/killall guuid=4d96f06e-1f00-0000-8bb4-3627f8140000 pid=5368->guuid=c312206f-1f00-0000-8bb4-3627f9140000 pid=5369 execve guuid=f9c27c70-1f00-0000-8bb4-3627fb140000 pid=5371 /usr/bin/killall guuid=c2dbf86f-1f00-0000-8bb4-3627fa140000 pid=5370->guuid=f9c27c70-1f00-0000-8bb4-3627fb140000 pid=5371 execve guuid=9f51c89f-2000-0000-8bb4-36271e150000 pid=5406 /usr/bin/pgrep guuid=df74629f-2000-0000-8bb4-36271d150000 pid=5405->guuid=9f51c89f-2000-0000-8bb4-36271e150000 pid=5406 execve guuid=ac0d81a4-2000-0000-8bb4-362720150000 pid=5408 /usr/bin/killall guuid=7adf25a4-2000-0000-8bb4-36271f150000 pid=5407->guuid=ac0d81a4-2000-0000-8bb4-362720150000 pid=5408 execve guuid=a24f10a6-2000-0000-8bb4-362722150000 pid=5410 /usr/bin/killall guuid=f01dbea5-2000-0000-8bb4-362721150000 pid=5409->guuid=a24f10a6-2000-0000-8bb4-362722150000 pid=5410 execve guuid=bbe8cda7-2000-0000-8bb4-362724150000 pid=5412 /usr/bin/killall guuid=c5e482a7-2000-0000-8bb4-362723150000 pid=5411->guuid=bbe8cda7-2000-0000-8bb4-362724150000 pid=5412 execve guuid=cf6e8fa9-2000-0000-8bb4-362726150000 pid=5414 /usr/bin/killall guuid=3db335a9-2000-0000-8bb4-362725150000 pid=5413->guuid=cf6e8fa9-2000-0000-8bb4-362726150000 pid=5414 execve guuid=68755fab-2000-0000-8bb4-362728150000 pid=5416 /usr/bin/killall guuid=81aa00ab-2000-0000-8bb4-362727150000 pid=5415->guuid=68755fab-2000-0000-8bb4-362728150000 pid=5416 execve guuid=ff9d17ad-2000-0000-8bb4-36272a150000 pid=5418 /usr/bin/killall guuid=f0f6c0ac-2000-0000-8bb4-362729150000 pid=5417->guuid=ff9d17ad-2000-0000-8bb4-36272a150000 pid=5418 execve guuid=03b5aaae-2000-0000-8bb4-36272c150000 pid=5420 /usr/bin/killall guuid=cc0960ae-2000-0000-8bb4-36272b150000 pid=5419->guuid=03b5aaae-2000-0000-8bb4-36272c150000 pid=5420 execve guuid=5f1d7ab0-2000-0000-8bb4-36272e150000 pid=5422 /usr/bin/killall guuid=fcab02b0-2000-0000-8bb4-36272d150000 pid=5421->guuid=5f1d7ab0-2000-0000-8bb4-36272e150000 pid=5422 execve guuid=becc25e0-2100-0000-8bb4-362730150000 pid=5424 /usr/bin/pgrep guuid=7ad5bddf-2100-0000-8bb4-36272f150000 pid=5423->guuid=becc25e0-2100-0000-8bb4-362730150000 pid=5424 execve guuid=2b9991e4-2100-0000-8bb4-362732150000 pid=5426 /usr/bin/killall guuid=daba34e4-2100-0000-8bb4-362731150000 pid=5425->guuid=2b9991e4-2100-0000-8bb4-362732150000 pid=5426 execve guuid=604c7ae5-2100-0000-8bb4-362734150000 pid=5428 /usr/bin/killall guuid=4e594ee5-2100-0000-8bb4-362733150000 pid=5427->guuid=604c7ae5-2100-0000-8bb4-362734150000 pid=5428 execve guuid=3712fbe6-2100-0000-8bb4-362736150000 pid=5430 /usr/bin/killall guuid=06849ce6-2100-0000-8bb4-362735150000 pid=5429->guuid=3712fbe6-2100-0000-8bb4-362736150000 pid=5430 execve guuid=83854ae8-2100-0000-8bb4-362738150000 pid=5432 /usr/bin/killall guuid=27440fe8-2100-0000-8bb4-362737150000 pid=5431->guuid=83854ae8-2100-0000-8bb4-362738150000 pid=5432 execve guuid=45c16be9-2100-0000-8bb4-36273a150000 pid=5434 /usr/bin/killall guuid=ba2435e9-2100-0000-8bb4-362739150000 pid=5433->guuid=45c16be9-2100-0000-8bb4-36273a150000 pid=5434 execve guuid=e39762ea-2100-0000-8bb4-36273c150000 pid=5436 /usr/bin/killall guuid=640337ea-2100-0000-8bb4-36273b150000 pid=5435->guuid=e39762ea-2100-0000-8bb4-36273c150000 pid=5436 execve guuid=d21641eb-2100-0000-8bb4-36273e150000 pid=5438 /usr/bin/killall guuid=1a6917eb-2100-0000-8bb4-36273d150000 pid=5437->guuid=d21641eb-2100-0000-8bb4-36273e150000 pid=5438 execve guuid=8f8431ec-2100-0000-8bb4-362740150000 pid=5440 /usr/bin/killall guuid=36d3fceb-2100-0000-8bb4-36273f150000 pid=5439->guuid=8f8431ec-2100-0000-8bb4-362740150000 pid=5440 execve guuid=69e23e1b-2300-0000-8bb4-362742150000 pid=5442 /usr/bin/pgrep guuid=6a9bdd1a-2300-0000-8bb4-362741150000 pid=5441->guuid=69e23e1b-2300-0000-8bb4-362742150000 pid=5442 execve guuid=16b8971f-2300-0000-8bb4-362744150000 pid=5444 /usr/bin/killall guuid=93c0591f-2300-0000-8bb4-362743150000 pid=5443->guuid=16b8971f-2300-0000-8bb4-362744150000 pid=5444 execve guuid=a7726021-2300-0000-8bb4-362746150000 pid=5446 /usr/bin/killall guuid=1ac21221-2300-0000-8bb4-362745150000 pid=5445->guuid=a7726021-2300-0000-8bb4-362746150000 pid=5446 execve guuid=30200723-2300-0000-8bb4-362748150000 pid=5448 /usr/bin/killall guuid=d000b922-2300-0000-8bb4-362747150000 pid=5447->guuid=30200723-2300-0000-8bb4-362748150000 pid=5448 execve guuid=4771c224-2300-0000-8bb4-36274a150000 pid=5450 /usr/bin/killall guuid=e6a16524-2300-0000-8bb4-362749150000 pid=5449->guuid=4771c224-2300-0000-8bb4-36274a150000 pid=5450 execve guuid=952c7d26-2300-0000-8bb4-36274c150000 pid=5452 /usr/bin/killall guuid=60542326-2300-0000-8bb4-36274b150000 pid=5451->guuid=952c7d26-2300-0000-8bb4-36274c150000 pid=5452 execve guuid=cefb1e28-2300-0000-8bb4-36274e150000 pid=5454 /usr/bin/killall guuid=4d6cc127-2300-0000-8bb4-36274d150000 pid=5453->guuid=cefb1e28-2300-0000-8bb4-36274e150000 pid=5454 execve guuid=79459329-2300-0000-8bb4-362750150000 pid=5456 /usr/bin/killall guuid=a6853729-2300-0000-8bb4-36274f150000 pid=5455->guuid=79459329-2300-0000-8bb4-362750150000 pid=5456 execve guuid=5f54ff2a-2300-0000-8bb4-362752150000 pid=5458 /usr/bin/killall guuid=a563b92a-2300-0000-8bb4-362751150000 pid=5457->guuid=5f54ff2a-2300-0000-8bb4-362752150000 pid=5458 execve guuid=c858d25a-2400-0000-8bb4-362754150000 pid=5460 /usr/bin/pgrep guuid=f5457a5a-2400-0000-8bb4-362753150000 pid=5459->guuid=c858d25a-2400-0000-8bb4-362754150000 pid=5460 execve guuid=17ed975f-2400-0000-8bb4-362756150000 pid=5462 /usr/bin/killall guuid=4e2a2b5f-2400-0000-8bb4-362755150000 pid=5461->guuid=17ed975f-2400-0000-8bb4-362756150000 pid=5462 execve guuid=018d1561-2400-0000-8bb4-362758150000 pid=5464 /usr/bin/killall guuid=c96abe60-2400-0000-8bb4-362757150000 pid=5463->guuid=018d1561-2400-0000-8bb4-362758150000 pid=5464 execve guuid=5114ed62-2400-0000-8bb4-36275a150000 pid=5466 /usr/bin/killall guuid=02bd8662-2400-0000-8bb4-362759150000 pid=5465->guuid=5114ed62-2400-0000-8bb4-36275a150000 pid=5466 execve guuid=0ae9a164-2400-0000-8bb4-36275c150000 pid=5468 /usr/bin/killall guuid=5f205064-2400-0000-8bb4-36275b150000 pid=5467->guuid=0ae9a164-2400-0000-8bb4-36275c150000 pid=5468 execve guuid=c5007b66-2400-0000-8bb4-36275e150000 pid=5470 /usr/bin/killall guuid=2c4f1866-2400-0000-8bb4-36275d150000 pid=5469->guuid=c5007b66-2400-0000-8bb4-36275e150000 pid=5470 execve guuid=bf1a4c68-2400-0000-8bb4-362760150000 pid=5472 /usr/bin/killall guuid=1029e867-2400-0000-8bb4-36275f150000 pid=5471->guuid=bf1a4c68-2400-0000-8bb4-362760150000 pid=5472 execve guuid=295f416a-2400-0000-8bb4-362762150000 pid=5474 /usr/bin/killall guuid=baf9d769-2400-0000-8bb4-362761150000 pid=5473->guuid=295f416a-2400-0000-8bb4-362762150000 pid=5474 execve guuid=8168236c-2400-0000-8bb4-362764150000 pid=5476 /usr/bin/killall guuid=d9c1c26b-2400-0000-8bb4-362763150000 pid=5475->guuid=8168236c-2400-0000-8bb4-362764150000 pid=5476 execve guuid=5469e49b-2500-0000-8bb4-362766150000 pid=5478 /usr/bin/pgrep guuid=566f7d9b-2500-0000-8bb4-362765150000 pid=5477->guuid=5469e49b-2500-0000-8bb4-362766150000 pid=5478 execve guuid=762ec7a0-2500-0000-8bb4-362768150000 pid=5480 /usr/bin/killall guuid=89ff64a0-2500-0000-8bb4-362767150000 pid=5479->guuid=762ec7a0-2500-0000-8bb4-362768150000 pid=5480 execve guuid=33f928a2-2500-0000-8bb4-36276a150000 pid=5482 /usr/bin/killall guuid=fda8d7a1-2500-0000-8bb4-362769150000 pid=5481->guuid=33f928a2-2500-0000-8bb4-36276a150000 pid=5482 execve guuid=114bffa3-2500-0000-8bb4-36276c150000 pid=5484 /usr/bin/killall guuid=02d9a0a3-2500-0000-8bb4-36276b150000 pid=5483->guuid=114bffa3-2500-0000-8bb4-36276c150000 pid=5484 execve guuid=5ee1caa5-2500-0000-8bb4-36276e150000 pid=5486 /usr/bin/killall guuid=17df7ea5-2500-0000-8bb4-36276d150000 pid=5485->guuid=5ee1caa5-2500-0000-8bb4-36276e150000 pid=5486 execve guuid=e0d72fa7-2500-0000-8bb4-362770150000 pid=5488 /usr/bin/killall guuid=8ef7e6a6-2500-0000-8bb4-36276f150000 pid=5487->guuid=e0d72fa7-2500-0000-8bb4-362770150000 pid=5488 execve guuid=79b6e6a8-2500-0000-8bb4-362772150000 pid=5490 /usr/bin/killall guuid=b7a29da8-2500-0000-8bb4-362771150000 pid=5489->guuid=79b6e6a8-2500-0000-8bb4-362772150000 pid=5490 execve guuid=a5e496aa-2500-0000-8bb4-362774150000 pid=5492 /usr/bin/killall guuid=f5a14baa-2500-0000-8bb4-362773150000 pid=5491->guuid=a5e496aa-2500-0000-8bb4-362774150000 pid=5492 execve guuid=16284aac-2500-0000-8bb4-362776150000 pid=5494 /usr/bin/killall guuid=4185f5ab-2500-0000-8bb4-362775150000 pid=5493->guuid=16284aac-2500-0000-8bb4-362776150000 pid=5494 execve guuid=c2cfa3da-2600-0000-8bb4-36277a150000 pid=5498 /usr/bin/pgrep guuid=00bd6ada-2600-0000-8bb4-362779150000 pid=5497->guuid=c2cfa3da-2600-0000-8bb4-36277a150000 pid=5498 execve guuid=ca437ddd-2600-0000-8bb4-36277c150000 pid=5500 /usr/bin/killall guuid=0b1f53dd-2600-0000-8bb4-36277b150000 pid=5499->guuid=ca437ddd-2600-0000-8bb4-36277c150000 pid=5500 execve guuid=65cd48de-2600-0000-8bb4-36277e150000 pid=5502 /usr/bin/killall guuid=42d721de-2600-0000-8bb4-36277d150000 pid=5501->guuid=65cd48de-2600-0000-8bb4-36277e150000 pid=5502 execve guuid=9cd40edf-2600-0000-8bb4-362780150000 pid=5504 /usr/bin/killall guuid=5d08e8de-2600-0000-8bb4-36277f150000 pid=5503->guuid=9cd40edf-2600-0000-8bb4-362780150000 pid=5504 execve guuid=9e93eadf-2600-0000-8bb4-362782150000 pid=5506 /usr/bin/killall guuid=2a05b2df-2600-0000-8bb4-362781150000 pid=5505->guuid=9e93eadf-2600-0000-8bb4-362782150000 pid=5506 execve guuid=ad56bde0-2600-0000-8bb4-362784150000 pid=5508 /usr/bin/killall guuid=42c587e0-2600-0000-8bb4-362783150000 pid=5507->guuid=ad56bde0-2600-0000-8bb4-362784150000 pid=5508 execve guuid=90979fe1-2600-0000-8bb4-362786150000 pid=5510 /usr/bin/killall guuid=342967e1-2600-0000-8bb4-362785150000 pid=5509->guuid=90979fe1-2600-0000-8bb4-362786150000 pid=5510 execve guuid=fa996ae2-2600-0000-8bb4-362788150000 pid=5512 /usr/bin/killall guuid=b5f341e2-2600-0000-8bb4-362787150000 pid=5511->guuid=fa996ae2-2600-0000-8bb4-362788150000 pid=5512 execve guuid=a5f785e3-2600-0000-8bb4-36278a150000 pid=5514 /usr/bin/killall guuid=321130e3-2600-0000-8bb4-362789150000 pid=5513->guuid=a5f785e3-2600-0000-8bb4-36278a150000 pid=5514 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734499 Sample: cron.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 37 206.123.128.67, 47096, 47098, 47100 LEASEWEB-USA-NYC-11US United States 2->37 39 185.125.190.26, 443 CANONICAL-ASGB United Kingdom 2->39 41 2 other IPs or domains 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 cron.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 cron.elf 9->12         started        process6 process7 14 cron.elf sh 12->14         started        16 cron.elf sh 12->16         started        18 cron.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-12 05:25:17 UTC
File Type:
ELF32 Little (Exe)
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_83715433 Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_f51c5ac3 Linux_Trojan_Gafgyt_27de1106 Linux_Trojan_Gafgyt_1b2e2a3a Linux_Trojan_Gafgyt_9127f7be elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_1b2e2a3a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_27de1106
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_83715433
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9127f7be
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f51c5ac3
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 72d7c63cf91728a7d8843539dfcdff923795fb9ad6d7a7adf44d026376cf1600

(this sample)

  
Delivery method
Distributed via web download

Comments