MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 77118b438e2442a04d8f1ef8e86a5a0f89d9be9c35dd9cf5d592c899ffe82b1b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 8


Intelligence 8 IOCs YARA 1 File information Comments

SHA256 hash: 77118b438e2442a04d8f1ef8e86a5a0f89d9be9c35dd9cf5d592c899ffe82b1b
SHA3-384 hash: c6608a1e6793f58dfcc974b5ac953ed1664c655f574736d781e520b18a8f846179fe269ac45335479622db72c877e11f
SHA1 hash: d6b9999630ebaf16491f921bffa958a93bb30074
MD5 hash: 0126d7dd0ef83c00733d1e7695fabc67
humanhash: undress-whiskey-whiskey-delaware
File name:mass
Download: download sample
Signature Mirai
File size:2'447 bytes
First seen:2025-08-23 13:42:46 UTC
Last seen:2025-08-23 15:10:43 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:Su32wuwf30HubK7S5u2tLauGdOugvyurhr4Q/uSp+udPomZuiZQueFQuh4WPzuzA:SKAHaraaOoZV62qKELKid
TLSH T1C751A4CE2C3065229F0BCE5B6375B8A860728DF734910E35DC9CCC69D98C967317BAA4
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://163.61.39.201/arm92e2bf91fdb4d0617289191aef154951a3b71df4f9da76e3a670389bb60aaa48 Mirai32-bit elf mirai Mozi
http://163.61.39.201/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 Miraielf geofenced m68k mirai ua-wget USA
http://163.61.39.201/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraielf geofenced mips mirai ua-wget USA
http://163.61.39.201/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraielf geofenced mips mirai ua-wget USA
http://163.61.39.201/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a Miraielf geofenced mirai PowerPC ua-wget USA
http://163.61.39.201/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 Miraielf geofenced mirai SuperH ua-wget USA
http://163.61.39.201/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c Miraielf geofenced mirai sparc ua-wget USA
http://163.61.39.201/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.cx HEUR:Trojan-Downloader.Shell.Agent.a HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=aea1d799-1900-0000-1694-97c8fa0b0000 pid=3066 /usr/bin/sudo guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073 /tmp/sample.bin guuid=aea1d799-1900-0000-1694-97c8fa0b0000 pid=3066->guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073 execve guuid=59de0f9c-1900-0000-1694-97c8030c0000 pid=3075 /usr/bin/cp guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=59de0f9c-1900-0000-1694-97c8030c0000 pid=3075 execve guuid=8daebfa1-1900-0000-1694-97c8150c0000 pid=3093 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=8daebfa1-1900-0000-1694-97c8150c0000 pid=3093 execve guuid=8690c3d3-1900-0000-1694-97c8690c0000 pid=3177 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=8690c3d3-1900-0000-1694-97c8690c0000 pid=3177 execve guuid=43480806-1a00-0000-1694-97c88e0c0000 pid=3214 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=43480806-1a00-0000-1694-97c88e0c0000 pid=3214 clone guuid=569f2706-1a00-0000-1694-97c88f0c0000 pid=3215 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=569f2706-1a00-0000-1694-97c88f0c0000 pid=3215 execve guuid=c6ea7e06-1a00-0000-1694-97c8900c0000 pid=3216 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=c6ea7e06-1a00-0000-1694-97c8900c0000 pid=3216 clone guuid=66489e07-1a00-0000-1694-97c8920c0000 pid=3218 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=66489e07-1a00-0000-1694-97c8920c0000 pid=3218 execve guuid=b7b40c0e-1a00-0000-1694-97c8930c0000 pid=3219 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=b7b40c0e-1a00-0000-1694-97c8930c0000 pid=3219 execve guuid=91166e41-1a00-0000-1694-97c8d80c0000 pid=3288 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=91166e41-1a00-0000-1694-97c8d80c0000 pid=3288 execve guuid=91975373-1a00-0000-1694-97c80e0d0000 pid=3342 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=91975373-1a00-0000-1694-97c80e0d0000 pid=3342 clone guuid=0b717573-1a00-0000-1694-97c8100d0000 pid=3344 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=0b717573-1a00-0000-1694-97c8100d0000 pid=3344 execve guuid=2e0fd973-1a00-0000-1694-97c8110d0000 pid=3345 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=2e0fd973-1a00-0000-1694-97c8110d0000 pid=3345 clone guuid=180ae174-1a00-0000-1694-97c8150d0000 pid=3349 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=180ae174-1a00-0000-1694-97c8150d0000 pid=3349 execve guuid=f071f877-1a00-0000-1694-97c8170d0000 pid=3351 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=f071f877-1a00-0000-1694-97c8170d0000 pid=3351 execve guuid=22be4ca7-1a00-0000-1694-97c8610d0000 pid=3425 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=22be4ca7-1a00-0000-1694-97c8610d0000 pid=3425 execve guuid=16721bd7-1a00-0000-1694-97c8b70d0000 pid=3511 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=16721bd7-1a00-0000-1694-97c8b70d0000 pid=3511 clone guuid=251c36d7-1a00-0000-1694-97c8b80d0000 pid=3512 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=251c36d7-1a00-0000-1694-97c8b80d0000 pid=3512 execve guuid=c2adb1d7-1a00-0000-1694-97c8ba0d0000 pid=3514 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=c2adb1d7-1a00-0000-1694-97c8ba0d0000 pid=3514 clone guuid=2e2206d9-1a00-0000-1694-97c8bf0d0000 pid=3519 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=2e2206d9-1a00-0000-1694-97c8bf0d0000 pid=3519 execve guuid=cedf97e2-1a00-0000-1694-97c8c20d0000 pid=3522 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=cedf97e2-1a00-0000-1694-97c8c20d0000 pid=3522 execve guuid=5e6b1012-1b00-0000-1694-97c8db0d0000 pid=3547 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5e6b1012-1b00-0000-1694-97c8db0d0000 pid=3547 execve guuid=45b74d47-1b00-0000-1694-97c8400e0000 pid=3648 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=45b74d47-1b00-0000-1694-97c8400e0000 pid=3648 clone guuid=71897f47-1b00-0000-1694-97c8410e0000 pid=3649 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=71897f47-1b00-0000-1694-97c8410e0000 pid=3649 execve guuid=0e750a48-1b00-0000-1694-97c8440e0000 pid=3652 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=0e750a48-1b00-0000-1694-97c8440e0000 pid=3652 clone guuid=433aee48-1b00-0000-1694-97c8480e0000 pid=3656 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=433aee48-1b00-0000-1694-97c8480e0000 pid=3656 execve guuid=e2d84e49-1b00-0000-1694-97c84a0e0000 pid=3658 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=e2d84e49-1b00-0000-1694-97c84a0e0000 pid=3658 execve guuid=af8ab276-1b00-0000-1694-97c8a00e0000 pid=3744 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=af8ab276-1b00-0000-1694-97c8a00e0000 pid=3744 execve guuid=f03867a8-1b00-0000-1694-97c8310f0000 pid=3889 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=f03867a8-1b00-0000-1694-97c8310f0000 pid=3889 clone guuid=524385a8-1b00-0000-1694-97c8320f0000 pid=3890 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=524385a8-1b00-0000-1694-97c8320f0000 pid=3890 execve guuid=73a215a9-1b00-0000-1694-97c8340f0000 pid=3892 /tmp/i486 guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=73a215a9-1b00-0000-1694-97c8340f0000 pid=3892 execve guuid=9bdee1af-1b00-0000-1694-97c8510f0000 pid=3921 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=9bdee1af-1b00-0000-1694-97c8510f0000 pid=3921 execve guuid=86975bb0-1b00-0000-1694-97c8540f0000 pid=3924 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=86975bb0-1b00-0000-1694-97c8540f0000 pid=3924 execve guuid=0a9203e1-1b00-0000-1694-97c8fc0f0000 pid=4092 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=0a9203e1-1b00-0000-1694-97c8fc0f0000 pid=4092 execve guuid=c8b60412-1c00-0000-1694-97c8b0100000 pid=4272 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=c8b60412-1c00-0000-1694-97c8b0100000 pid=4272 clone guuid=5f3c1d12-1c00-0000-1694-97c8b1100000 pid=4273 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5f3c1d12-1c00-0000-1694-97c8b1100000 pid=4273 execve guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275 /tmp/i686 guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275 execve guuid=9ff4534e-1c00-0000-1694-97c8b3110000 pid=4531 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=9ff4534e-1c00-0000-1694-97c8b3110000 pid=4531 execve guuid=5d20984e-1c00-0000-1694-97c8b4110000 pid=4532 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5d20984e-1c00-0000-1694-97c8b4110000 pid=4532 execve guuid=e2dc147f-1c00-0000-1694-97c8dd110000 pid=4573 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=e2dc147f-1c00-0000-1694-97c8dd110000 pid=4573 execve guuid=d44618ae-1c00-0000-1694-97c8df110000 pid=4575 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=d44618ae-1c00-0000-1694-97c8df110000 pid=4575 clone guuid=9f3e3bae-1c00-0000-1694-97c8e0110000 pid=4576 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=9f3e3bae-1c00-0000-1694-97c8e0110000 pid=4576 execve guuid=38179dae-1c00-0000-1694-97c8e1110000 pid=4577 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=38179dae-1c00-0000-1694-97c8e1110000 pid=4577 clone guuid=0c026eaf-1c00-0000-1694-97c8e3110000 pid=4579 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=0c026eaf-1c00-0000-1694-97c8e3110000 pid=4579 execve guuid=137e5eb0-1c00-0000-1694-97c8e4110000 pid=4580 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=137e5eb0-1c00-0000-1694-97c8e4110000 pid=4580 execve guuid=244545df-1c00-0000-1694-97c8e7110000 pid=4583 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=244545df-1c00-0000-1694-97c8e7110000 pid=4583 execve guuid=157c661f-1d00-0000-1694-97c806120000 pid=4614 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=157c661f-1d00-0000-1694-97c806120000 pid=4614 clone guuid=b8e1851f-1d00-0000-1694-97c807120000 pid=4615 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=b8e1851f-1d00-0000-1694-97c807120000 pid=4615 execve guuid=452e1c20-1d00-0000-1694-97c808120000 pid=4616 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=452e1c20-1d00-0000-1694-97c808120000 pid=4616 clone guuid=4be94e21-1d00-0000-1694-97c80a120000 pid=4618 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=4be94e21-1d00-0000-1694-97c80a120000 pid=4618 execve guuid=4b29cb26-1d00-0000-1694-97c80b120000 pid=4619 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=4b29cb26-1d00-0000-1694-97c80b120000 pid=4619 execve guuid=8cb2db55-1d00-0000-1694-97c80c120000 pid=4620 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=8cb2db55-1d00-0000-1694-97c80c120000 pid=4620 execve guuid=ae5bac85-1d00-0000-1694-97c80d120000 pid=4621 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ae5bac85-1d00-0000-1694-97c80d120000 pid=4621 clone guuid=ed59cb85-1d00-0000-1694-97c80e120000 pid=4622 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ed59cb85-1d00-0000-1694-97c80e120000 pid=4622 execve guuid=5b8a2e86-1d00-0000-1694-97c80f120000 pid=4623 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5b8a2e86-1d00-0000-1694-97c80f120000 pid=4623 clone guuid=73d0fa86-1d00-0000-1694-97c811120000 pid=4625 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=73d0fa86-1d00-0000-1694-97c811120000 pid=4625 execve guuid=ec427a87-1d00-0000-1694-97c812120000 pid=4626 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ec427a87-1d00-0000-1694-97c812120000 pid=4626 execve guuid=7e6ac1b7-1d00-0000-1694-97c813120000 pid=4627 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=7e6ac1b7-1d00-0000-1694-97c813120000 pid=4627 execve guuid=ccad94e9-1d00-0000-1694-97c814120000 pid=4628 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ccad94e9-1d00-0000-1694-97c814120000 pid=4628 clone guuid=9017b2e9-1d00-0000-1694-97c815120000 pid=4629 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=9017b2e9-1d00-0000-1694-97c815120000 pid=4629 execve guuid=e40ff8e9-1d00-0000-1694-97c816120000 pid=4630 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=e40ff8e9-1d00-0000-1694-97c816120000 pid=4630 clone guuid=3b7c9aea-1d00-0000-1694-97c818120000 pid=4632 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=3b7c9aea-1d00-0000-1694-97c818120000 pid=4632 execve guuid=c0d6dfea-1d00-0000-1694-97c819120000 pid=4633 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=c0d6dfea-1d00-0000-1694-97c819120000 pid=4633 execve guuid=7022b70d-1e00-0000-1694-97c81a120000 pid=4634 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=7022b70d-1e00-0000-1694-97c81a120000 pid=4634 execve guuid=35876f32-1e00-0000-1694-97c81b120000 pid=4635 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=35876f32-1e00-0000-1694-97c81b120000 pid=4635 clone guuid=c5a79732-1e00-0000-1694-97c81c120000 pid=4636 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=c5a79732-1e00-0000-1694-97c81c120000 pid=4636 execve guuid=6a32e632-1e00-0000-1694-97c81d120000 pid=4637 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=6a32e632-1e00-0000-1694-97c81d120000 pid=4637 clone guuid=d20b2734-1e00-0000-1694-97c81f120000 pid=4639 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=d20b2734-1e00-0000-1694-97c81f120000 pid=4639 execve guuid=e636f434-1e00-0000-1694-97c820120000 pid=4640 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=e636f434-1e00-0000-1694-97c820120000 pid=4640 execve guuid=36835062-1e00-0000-1694-97c821120000 pid=4641 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=36835062-1e00-0000-1694-97c821120000 pid=4641 execve guuid=71d6b192-1e00-0000-1694-97c822120000 pid=4642 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=71d6b192-1e00-0000-1694-97c822120000 pid=4642 clone guuid=021fcb92-1e00-0000-1694-97c823120000 pid=4643 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=021fcb92-1e00-0000-1694-97c823120000 pid=4643 execve guuid=3a391893-1e00-0000-1694-97c824120000 pid=4644 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=3a391893-1e00-0000-1694-97c824120000 pid=4644 clone guuid=52bba193-1e00-0000-1694-97c826120000 pid=4646 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=52bba193-1e00-0000-1694-97c826120000 pid=4646 execve guuid=a1a0f094-1e00-0000-1694-97c827120000 pid=4647 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=a1a0f094-1e00-0000-1694-97c827120000 pid=4647 execve guuid=96aa53c5-1e00-0000-1694-97c828120000 pid=4648 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=96aa53c5-1e00-0000-1694-97c828120000 pid=4648 execve guuid=f8717905-1f00-0000-1694-97c829120000 pid=4649 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=f8717905-1f00-0000-1694-97c829120000 pid=4649 clone guuid=e56da305-1f00-0000-1694-97c82a120000 pid=4650 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=e56da305-1f00-0000-1694-97c82a120000 pid=4650 execve guuid=beec0b06-1f00-0000-1694-97c82b120000 pid=4651 /tmp/x86 guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=beec0b06-1f00-0000-1694-97c82b120000 pid=4651 execve guuid=a1c2aa2e-1f00-0000-1694-97c82f120000 pid=4655 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=a1c2aa2e-1f00-0000-1694-97c82f120000 pid=4655 execve guuid=13030f2f-1f00-0000-1694-97c831120000 pid=4657 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=13030f2f-1f00-0000-1694-97c831120000 pid=4657 execve guuid=563f1f5f-1f00-0000-1694-97c832120000 pid=4658 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=563f1f5f-1f00-0000-1694-97c832120000 pid=4658 execve guuid=b6c6f88f-1f00-0000-1694-97c833120000 pid=4659 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=b6c6f88f-1f00-0000-1694-97c833120000 pid=4659 clone guuid=8ba92b90-1f00-0000-1694-97c834120000 pid=4660 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=8ba92b90-1f00-0000-1694-97c834120000 pid=4660 execve guuid=cfe4ae90-1f00-0000-1694-97c835120000 pid=4661 /tmp/x86_64 guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=cfe4ae90-1f00-0000-1694-97c835120000 pid=4661 execve guuid=d7027796-1f00-0000-1694-97c839120000 pid=4665 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=d7027796-1f00-0000-1694-97c839120000 pid=4665 execve guuid=5fddb396-1f00-0000-1694-97c83b120000 pid=4667 /usr/bin/wget net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5fddb396-1f00-0000-1694-97c83b120000 pid=4667 execve guuid=db0f36b9-1f00-0000-1694-97c83c120000 pid=4668 /usr/bin/curl net send-data write-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=db0f36b9-1f00-0000-1694-97c83c120000 pid=4668 execve guuid=215c12de-1f00-0000-1694-97c83d120000 pid=4669 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=215c12de-1f00-0000-1694-97c83d120000 pid=4669 clone guuid=ab8f40de-1f00-0000-1694-97c83e120000 pid=4670 /usr/bin/chmod guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ab8f40de-1f00-0000-1694-97c83e120000 pid=4670 execve guuid=5b2cccde-1f00-0000-1694-97c83f120000 pid=4671 /usr/bin/bash guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=5b2cccde-1f00-0000-1694-97c83f120000 pid=4671 clone guuid=ff35e8df-1f00-0000-1694-97c841120000 pid=4673 /usr/bin/rm delete-file guuid=8f34b39b-1900-0000-1694-97c8010c0000 pid=3073->guuid=ff35e8df-1f00-0000-1694-97c841120000 pid=4673 execve 861e64a3-ade7-5eac-b8d2-11a0362764a4 163.61.39.201:80 guuid=8daebfa1-1900-0000-1694-97c8150c0000 pid=3093->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=8690c3d3-1900-0000-1694-97c8690c0000 pid=3177->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=b7b40c0e-1a00-0000-1694-97c8930c0000 pid=3219->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=91166e41-1a00-0000-1694-97c8d80c0000 pid=3288->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=f071f877-1a00-0000-1694-97c8170d0000 pid=3351->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=22be4ca7-1a00-0000-1694-97c8610d0000 pid=3425->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=cedf97e2-1a00-0000-1694-97c8c20d0000 pid=3522->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=5e6b1012-1b00-0000-1694-97c8db0d0000 pid=3547->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=e2d84e49-1b00-0000-1694-97c84a0e0000 pid=3658->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=af8ab276-1b00-0000-1694-97c8a00e0000 pid=3744->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=5f1ed7af-1b00-0000-1694-97c8500f0000 pid=3920 /tmp/i486 net send-data zombie guuid=73a215a9-1b00-0000-1694-97c8340f0000 pid=3892->guuid=5f1ed7af-1b00-0000-1694-97c8500f0000 pid=3920 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=5f1ed7af-1b00-0000-1694-97c8500f0000 pid=3920->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 2b659683-be59-5022-8f04-927e151f5c7e 217.60.248.199:1025 guuid=5f1ed7af-1b00-0000-1694-97c8500f0000 pid=3920->2b659683-be59-5022-8f04-927e151f5c7e send: 19B guuid=1f3af2af-1b00-0000-1694-97c8520f0000 pid=3922 /tmp/i486 guuid=5f1ed7af-1b00-0000-1694-97c8500f0000 pid=3920->guuid=1f3af2af-1b00-0000-1694-97c8520f0000 pid=3922 clone guuid=86975bb0-1b00-0000-1694-97c8540f0000 pid=3924->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=0a9203e1-1b00-0000-1694-97c8fc0f0000 pid=4092->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=3091f918-1c00-0000-1694-97c8d2100000 pid=4306 /tmp/i686 net send-data guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275->guuid=3091f918-1c00-0000-1694-97c8d2100000 pid=4306 clone guuid=bed3d84d-1c00-0000-1694-97c8ad110000 pid=4525 /tmp/i686 net zombie guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275->guuid=bed3d84d-1c00-0000-1694-97c8ad110000 pid=4525 clone guuid=4ef3e34d-1c00-0000-1694-97c8af110000 pid=4527 /tmp/i686 net send-data zombie guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275->guuid=4ef3e34d-1c00-0000-1694-97c8af110000 pid=4527 clone guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528 /tmp/i686 net send-data zombie guuid=774a6512-1c00-0000-1694-97c8b3100000 pid=4275->guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=3091f918-1c00-0000-1694-97c8d2100000 pid=4306->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 33B guuid=bed3d84d-1c00-0000-1694-97c8ad110000 pid=4525->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=4ef3e34d-1c00-0000-1694-97c8af110000 pid=4527->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 6f05dfaf-c0f5-52cc-a0cf-5ed00ddec0a3 31.56.138.76:1025 guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528->6f05dfaf-c0f5-52cc-a0cf-5ed00ddec0a3 con ef45816d-a8af-52a5-bd2c-76d22ae1894f 94.183.184.60:1025 guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528->ef45816d-a8af-52a5-bd2c-76d22ae1894f send: 19B guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530 /tmp/i686 guuid=a4ebf34d-1c00-0000-1694-97c8b0110000 pid=4528->guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530 clone guuid=47025157-1c00-0000-1694-97c8c7110000 pid=4551 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=47025157-1c00-0000-1694-97c8c7110000 pid=4551 clone guuid=3eee9f59-1c00-0000-1694-97c8cc110000 pid=4556 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=3eee9f59-1c00-0000-1694-97c8cc110000 pid=4556 clone guuid=a3d0435d-1c00-0000-1694-97c8d5110000 pid=4565 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=a3d0435d-1c00-0000-1694-97c8d5110000 pid=4565 clone guuid=8cff525d-1c00-0000-1694-97c8d6110000 pid=4566 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=8cff525d-1c00-0000-1694-97c8d6110000 pid=4566 clone guuid=26453ce7-1c00-0000-1694-97c8eb110000 pid=4587 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=26453ce7-1c00-0000-1694-97c8eb110000 pid=4587 clone guuid=cad945e7-1c00-0000-1694-97c8ec110000 pid=4588 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=cad945e7-1c00-0000-1694-97c8ec110000 pid=4588 clone guuid=fc7ae5e8-1c00-0000-1694-97c8ef110000 pid=4591 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=fc7ae5e8-1c00-0000-1694-97c8ef110000 pid=4591 clone guuid=e077efe8-1c00-0000-1694-97c8f0110000 pid=4592 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=e077efe8-1c00-0000-1694-97c8f0110000 pid=4592 clone guuid=f5dc25e9-1c00-0000-1694-97c8f2110000 pid=4594 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=f5dc25e9-1c00-0000-1694-97c8f2110000 pid=4594 clone guuid=8cd746e9-1c00-0000-1694-97c8f4110000 pid=4596 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=8cd746e9-1c00-0000-1694-97c8f4110000 pid=4596 clone guuid=d58e24ea-1c00-0000-1694-97c8f6110000 pid=4598 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=d58e24ea-1c00-0000-1694-97c8f6110000 pid=4598 clone guuid=873a3aea-1c00-0000-1694-97c8f8110000 pid=4600 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=873a3aea-1c00-0000-1694-97c8f8110000 pid=4600 clone guuid=941e9dea-1c00-0000-1694-97c8fa110000 pid=4602 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=941e9dea-1c00-0000-1694-97c8fa110000 pid=4602 clone guuid=85e1bcea-1c00-0000-1694-97c8fc110000 pid=4604 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=85e1bcea-1c00-0000-1694-97c8fc110000 pid=4604 clone guuid=0effd7ea-1c00-0000-1694-97c8fe110000 pid=4606 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=0effd7ea-1c00-0000-1694-97c8fe110000 pid=4606 clone guuid=7bb2f2ea-1c00-0000-1694-97c800120000 pid=4608 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=7bb2f2ea-1c00-0000-1694-97c800120000 pid=4608 clone guuid=ce53f3eb-1c00-0000-1694-97c803120000 pid=4611 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=ce53f3eb-1c00-0000-1694-97c803120000 pid=4611 clone guuid=ce9f10ec-1c00-0000-1694-97c805120000 pid=4613 /tmp/i686 net send-data guuid=c5ff204e-1c00-0000-1694-97c8b2110000 pid=4530->guuid=ce9f10ec-1c00-0000-1694-97c805120000 pid=4613 clone guuid=5d20984e-1c00-0000-1694-97c8b4110000 pid=4532->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=47025157-1c00-0000-1694-97c8c7110000 pid=4551->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=3eee9f59-1c00-0000-1694-97c8cc110000 pid=4556->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=a3d0435d-1c00-0000-1694-97c8d5110000 pid=4565->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 41B guuid=8cff525d-1c00-0000-1694-97c8d6110000 pid=4566->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=e2dc147f-1c00-0000-1694-97c8dd110000 pid=4573->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=137e5eb0-1c00-0000-1694-97c8e4110000 pid=4580->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=244545df-1c00-0000-1694-97c8e7110000 pid=4583->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=26453ce7-1c00-0000-1694-97c8eb110000 pid=4587->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 43B guuid=cad945e7-1c00-0000-1694-97c8ec110000 pid=4588->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=fc7ae5e8-1c00-0000-1694-97c8ef110000 pid=4591->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=e077efe8-1c00-0000-1694-97c8f0110000 pid=4592->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=f5dc25e9-1c00-0000-1694-97c8f2110000 pid=4594->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=8cd746e9-1c00-0000-1694-97c8f4110000 pid=4596->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=d58e24ea-1c00-0000-1694-97c8f6110000 pid=4598->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=873a3aea-1c00-0000-1694-97c8f8110000 pid=4600->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=941e9dea-1c00-0000-1694-97c8fa110000 pid=4602->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=85e1bcea-1c00-0000-1694-97c8fc110000 pid=4604->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=0effd7ea-1c00-0000-1694-97c8fe110000 pid=4606->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=7bb2f2ea-1c00-0000-1694-97c800120000 pid=4608->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=ce53f3eb-1c00-0000-1694-97c803120000 pid=4611->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=ce9f10ec-1c00-0000-1694-97c805120000 pid=4613->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=4b29cb26-1d00-0000-1694-97c80b120000 pid=4619->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=8cb2db55-1d00-0000-1694-97c80c120000 pid=4620->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=ec427a87-1d00-0000-1694-97c812120000 pid=4626->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=7e6ac1b7-1d00-0000-1694-97c813120000 pid=4627->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=c0d6dfea-1d00-0000-1694-97c819120000 pid=4633->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=7022b70d-1e00-0000-1694-97c81a120000 pid=4634->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=e636f434-1e00-0000-1694-97c820120000 pid=4640->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=36835062-1e00-0000-1694-97c821120000 pid=4641->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=a1a0f094-1e00-0000-1694-97c827120000 pid=4647->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=96aa53c5-1e00-0000-1694-97c828120000 pid=4648->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=e0bc9e0c-1f00-0000-1694-97c82c120000 pid=4652 /tmp/x86 net send-data guuid=beec0b06-1f00-0000-1694-97c82b120000 pid=4651->guuid=e0bc9e0c-1f00-0000-1694-97c82c120000 pid=4652 clone guuid=783c7a2e-1f00-0000-1694-97c82d120000 pid=4653 /tmp/x86 net zombie guuid=beec0b06-1f00-0000-1694-97c82b120000 pid=4651->guuid=783c7a2e-1f00-0000-1694-97c82d120000 pid=4653 clone guuid=8b109d2e-1f00-0000-1694-97c82e120000 pid=4654 /tmp/x86 net zombie guuid=beec0b06-1f00-0000-1694-97c82b120000 pid=4651->guuid=8b109d2e-1f00-0000-1694-97c82e120000 pid=4654 clone guuid=e0bc9e0c-1f00-0000-1694-97c82c120000 pid=4652->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 32B guuid=783c7a2e-1f00-0000-1694-97c82d120000 pid=4653->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=8b109d2e-1f00-0000-1694-97c82e120000 pid=4654->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=8b109d2e-1f00-0000-1694-97c82e120000 pid=4654->6f05dfaf-c0f5-52cc-a0cf-5ed00ddec0a3 con guuid=92f8c92e-1f00-0000-1694-97c830120000 pid=4656 /tmp/x86 guuid=8b109d2e-1f00-0000-1694-97c82e120000 pid=4654->guuid=92f8c92e-1f00-0000-1694-97c830120000 pid=4656 clone guuid=13030f2f-1f00-0000-1694-97c831120000 pid=4657->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 134B guuid=563f1f5f-1f00-0000-1694-97c832120000 pid=4658->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 83B guuid=a2b2fa91-1f00-0000-1694-97c836120000 pid=4662 /tmp/x86_64 net send-data guuid=cfe4ae90-1f00-0000-1694-97c835120000 pid=4661->guuid=a2b2fa91-1f00-0000-1694-97c836120000 pid=4662 clone guuid=1ab95d96-1f00-0000-1694-97c837120000 pid=4663 /tmp/x86_64 net zombie guuid=cfe4ae90-1f00-0000-1694-97c835120000 pid=4661->guuid=1ab95d96-1f00-0000-1694-97c837120000 pid=4663 clone guuid=325c6996-1f00-0000-1694-97c838120000 pid=4664 /tmp/x86_64 net send-data zombie guuid=cfe4ae90-1f00-0000-1694-97c835120000 pid=4661->guuid=325c6996-1f00-0000-1694-97c838120000 pid=4664 clone guuid=a2b2fa91-1f00-0000-1694-97c836120000 pid=4662->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 35B guuid=1ab95d96-1f00-0000-1694-97c837120000 pid=4663->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=325c6996-1f00-0000-1694-97c838120000 pid=4664->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e9010b07-def5-5d53-bd9f-ed886898ca33 103.136.69.242:1025 guuid=325c6996-1f00-0000-1694-97c838120000 pid=4664->e9010b07-def5-5d53-bd9f-ed886898ca33 send: 23B guuid=10b97e96-1f00-0000-1694-97c83a120000 pid=4666 /tmp/x86_64 guuid=325c6996-1f00-0000-1694-97c838120000 pid=4664->guuid=10b97e96-1f00-0000-1694-97c83a120000 pid=4666 clone guuid=5fddb396-1f00-0000-1694-97c83b120000 pid=4667->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=db0f36b9-1f00-0000-1694-97c83c120000 pid=4668->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-23 13:43:42 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 77118b438e2442a04d8f1ef8e86a5a0f89d9be9c35dd9cf5d592c899ffe82b1b

(this sample)

  
Delivery method
Distributed via web download

Comments