MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81aa3a1cec78008abbe0506a44c20fc80efe006f5c4d84fdec6c8ed9d84521d6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 9


Intelligence 9 IOCs YARA 1 File information Comments

SHA256 hash: 81aa3a1cec78008abbe0506a44c20fc80efe006f5c4d84fdec6c8ed9d84521d6
SHA3-384 hash: d190d465a0f9446da92b1222b9c1af6a3f3d1703001f18a2ed6319f453b06a681c081a966cbded9d37eb49607341131c
SHA1 hash: 0f6984b214aef7b49866d3fe709cbe26957eda4d
MD5 hash: c64014c3f8103bd49ddf1e0036f46ed4
humanhash: beer-cardinal-winter-rugby
File name:px86
Download: download sample
Signature Mirai
File size:20'880 bytes
First seen:2026-01-03 12:32:53 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 384:MsVFrtKI6ZBT9OIpbzDwEYrR8N66DG0Sx++I9B9AXtOJHqsYuO8+iyl029v1R/:NWBT9OiHwRR8A6DG0JBS8HqlKM/
TLSH T18692C16451884797DA1EF13FD24F4D1E36A0DB0A864AE7AFFA4003A8F99F055627CEC1
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Changes access rights for a written file
Sets a written file as executable
Changes the time when the file was created, accessed, or modified
Runs as daemon
Manages services
Creating a file
Opens a port
Sends data to a server
Launching a process
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Deleting of the original file
Creates or modifies files to set up autorun
Creates or modifies symbolic links in /init.d to set up autorun
Creates or modifies files in /init.d to set up autorun
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
packed upx
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2026-01-03T08:49:00Z UTC
Last seen:
2026-01-04T01:46:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=c1f0b26a-1d00-0000-80b9-95ff6e0b0000 pid=2926 /usr/bin/sudo guuid=c381126d-1d00-0000-80b9-95ff730b0000 pid=2931 /tmp/sample.bin delete-file net guuid=c1f0b26a-1d00-0000-80b9-95ff6e0b0000 pid=2926->guuid=c381126d-1d00-0000-80b9-95ff730b0000 pid=2931 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c381126d-1d00-0000-80b9-95ff730b0000 pid=2931->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=af527c6d-1d00-0000-80b9-95ff740b0000 pid=2932 /usr/bin/dash guuid=c381126d-1d00-0000-80b9-95ff730b0000 pid=2931->guuid=af527c6d-1d00-0000-80b9-95ff740b0000 pid=2932 execve guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934 /tmp/sample.bin net send-data write-config zombie guuid=c381126d-1d00-0000-80b9-95ff730b0000 pid=2931->guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934 clone acbee371-eca0-5786-9a2f-b70666f1e8a8 158.94.208.27:18129 guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->acbee371-eca0-5786-9a2f-b70666f1e8a8 send: 5B guuid=877a696e-1d00-0000-80b9-95ff770b0000 pid=2935 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=877a696e-1d00-0000-80b9-95ff770b0000 pid=2935 execve guuid=e88d036f-1d00-0000-80b9-95ff7a0b0000 pid=2938 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=e88d036f-1d00-0000-80b9-95ff7a0b0000 pid=2938 execve guuid=b7e798a6-1d00-0000-80b9-95ff150c0000 pid=3093 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=b7e798a6-1d00-0000-80b9-95ff150c0000 pid=3093 execve guuid=d1daf7db-1d00-0000-80b9-95ff840c0000 pid=3204 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=d1daf7db-1d00-0000-80b9-95ff840c0000 pid=3204 execve guuid=8ffed8e0-1d00-0000-80b9-95ff920c0000 pid=3218 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=8ffed8e0-1d00-0000-80b9-95ff920c0000 pid=3218 execve guuid=91287fe1-1d00-0000-80b9-95ff950c0000 pid=3221 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=91287fe1-1d00-0000-80b9-95ff950c0000 pid=3221 execve guuid=4b17221a-1e00-0000-80b9-95ffd90c0000 pid=3289 /usr/bin/dash write-config guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=4b17221a-1e00-0000-80b9-95ffd90c0000 pid=3289 execve guuid=9483c31a-1e00-0000-80b9-95ffdc0c0000 pid=3292 /usr/bin/dash write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=9483c31a-1e00-0000-80b9-95ffdc0c0000 pid=3292 execve guuid=db76581b-1e00-0000-80b9-95ffdf0c0000 pid=3295 /usr/bin/dash write-config guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=db76581b-1e00-0000-80b9-95ffdf0c0000 pid=3295 execve guuid=d879e31b-1e00-0000-80b9-95ffe20c0000 pid=3298 /usr/bin/dash guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=d879e31b-1e00-0000-80b9-95ffe20c0000 pid=3298 execve guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302 /tmp/sample.bin delete-file write-config write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302 clone guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308 /tmp/sample.bin write-config write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308 clone guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315 /tmp/sample.bin write-config write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315 clone guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322 /tmp/sample.bin write-config write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322 clone guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329 /tmp/sample.bin write-config write-file guuid=c33a556e-1d00-0000-80b9-95ff760b0000 pid=2934->guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329 clone guuid=5d12b66e-1d00-0000-80b9-95ff780b0000 pid=2936 /usr/bin/dash guuid=877a696e-1d00-0000-80b9-95ff770b0000 pid=2935->guuid=5d12b66e-1d00-0000-80b9-95ff780b0000 pid=2936 clone guuid=3339c96e-1d00-0000-80b9-95ff790b0000 pid=2937 /usr/bin/dash guuid=877a696e-1d00-0000-80b9-95ff770b0000 pid=2935->guuid=3339c96e-1d00-0000-80b9-95ff790b0000 pid=2937 clone guuid=d9f02f6f-1d00-0000-80b9-95ff7b0b0000 pid=2939 /usr/bin/systemctl guuid=e88d036f-1d00-0000-80b9-95ff7a0b0000 pid=2938->guuid=d9f02f6f-1d00-0000-80b9-95ff7b0b0000 pid=2939 execve guuid=866ec9a6-1d00-0000-80b9-95ff170c0000 pid=3095 /usr/bin/systemctl guuid=b7e798a6-1d00-0000-80b9-95ff150c0000 pid=3093->guuid=866ec9a6-1d00-0000-80b9-95ff170c0000 pid=3095 execve guuid=03ad3fdc-1d00-0000-80b9-95ff850c0000 pid=3205 /usr/bin/systemctl guuid=d1daf7db-1d00-0000-80b9-95ff840c0000 pid=3204->guuid=03ad3fdc-1d00-0000-80b9-95ff850c0000 pid=3205 execve guuid=885d0fe1-1d00-0000-80b9-95ff930c0000 pid=3219 /usr/bin/chmod guuid=8ffed8e0-1d00-0000-80b9-95ff920c0000 pid=3218->guuid=885d0fe1-1d00-0000-80b9-95ff930c0000 pid=3219 execve guuid=010aade1-1d00-0000-80b9-95ff960c0000 pid=3222 /usr/sbin/update-rc.d guuid=91287fe1-1d00-0000-80b9-95ff950c0000 pid=3221->guuid=010aade1-1d00-0000-80b9-95ff960c0000 pid=3222 execve guuid=969f3de3-1d00-0000-80b9-95ff990c0000 pid=3225 /usr/bin/systemctl guuid=010aade1-1d00-0000-80b9-95ff960c0000 pid=3222->guuid=969f3de3-1d00-0000-80b9-95ff990c0000 pid=3225 execve guuid=d2bb591a-1e00-0000-80b9-95ffda0c0000 pid=3290 /usr/bin/grep guuid=4b17221a-1e00-0000-80b9-95ffd90c0000 pid=3289->guuid=d2bb591a-1e00-0000-80b9-95ffda0c0000 pid=3290 execve guuid=b2c9f11a-1e00-0000-80b9-95ffde0c0000 pid=3294 /usr/bin/grep guuid=9483c31a-1e00-0000-80b9-95ffdc0c0000 pid=3292->guuid=b2c9f11a-1e00-0000-80b9-95ffde0c0000 pid=3294 execve guuid=3dc9851b-1e00-0000-80b9-95ffe10c0000 pid=3297 /usr/bin/grep guuid=db76581b-1e00-0000-80b9-95ffdf0c0000 pid=3295->guuid=3dc9851b-1e00-0000-80b9-95ffe10c0000 pid=3297 execve guuid=cae40e1c-1e00-0000-80b9-95ffe40c0000 pid=3300 /usr/bin/chattr guuid=d879e31b-1e00-0000-80b9-95ffe20c0000 pid=3298->guuid=cae40e1c-1e00-0000-80b9-95ffe40c0000 pid=3300 execve guuid=b7da9a1c-1e00-0000-80b9-95ffe70c0000 pid=3303 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=b7da9a1c-1e00-0000-80b9-95ffe70c0000 pid=3303 execve guuid=2032ff1c-1e00-0000-80b9-95ffeb0c0000 pid=3307 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=2032ff1c-1e00-0000-80b9-95ffeb0c0000 pid=3307 execve guuid=3bd2775b-1e00-0000-80b9-95ff650d0000 pid=3429 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=3bd2775b-1e00-0000-80b9-95ff650d0000 pid=3429 execve guuid=946a3416-2100-0000-80b9-95ff42160000 pid=5698 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=946a3416-2100-0000-80b9-95ff42160000 pid=5698 execve guuid=f2a6fd3d-2200-0000-80b9-95ffa9160000 pid=5801 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=f2a6fd3d-2200-0000-80b9-95ffa9160000 pid=5801 execve guuid=a0cc2240-2200-0000-80b9-95ffad160000 pid=5805 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=a0cc2240-2200-0000-80b9-95ffad160000 pid=5805 execve guuid=ae9dd0d2-2200-0000-80b9-95ffe7160000 pid=5863 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=ae9dd0d2-2200-0000-80b9-95ffe7160000 pid=5863 execve guuid=d93396d4-2200-0000-80b9-95ffe9160000 pid=5865 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=d93396d4-2200-0000-80b9-95ffe9160000 pid=5865 execve guuid=20e271d5-2200-0000-80b9-95ffeb160000 pid=5867 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=20e271d5-2200-0000-80b9-95ffeb160000 pid=5867 execve guuid=a48fb4d6-2200-0000-80b9-95ffed160000 pid=5869 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=a48fb4d6-2200-0000-80b9-95ffed160000 pid=5869 execve guuid=3afe2b61-2b00-0000-80b9-95ff92170000 pid=6034 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=3afe2b61-2b00-0000-80b9-95ff92170000 pid=6034 execve guuid=8fba9761-2b00-0000-80b9-95ff9c170000 pid=6044 /usr/bin/dash guuid=ca50821c-1e00-0000-80b9-95ffe60c0000 pid=3302->guuid=8fba9761-2b00-0000-80b9-95ff9c170000 pid=6044 execve guuid=0e30d11c-1e00-0000-80b9-95ffe80c0000 pid=3304 /usr/bin/dash guuid=b7da9a1c-1e00-0000-80b9-95ffe70c0000 pid=3303->guuid=0e30d11c-1e00-0000-80b9-95ffe80c0000 pid=3304 clone guuid=e858d71c-1e00-0000-80b9-95ffe90c0000 pid=3305 /usr/bin/dash guuid=b7da9a1c-1e00-0000-80b9-95ffe70c0000 pid=3303->guuid=e858d71c-1e00-0000-80b9-95ffe90c0000 pid=3305 clone guuid=718e4b1d-1e00-0000-80b9-95ffed0c0000 pid=3309 /usr/bin/systemctl guuid=2032ff1c-1e00-0000-80b9-95ffeb0c0000 pid=3307->guuid=718e4b1d-1e00-0000-80b9-95ffed0c0000 pid=3309 execve guuid=e9a15c1d-1e00-0000-80b9-95ffee0c0000 pid=3310 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=e9a15c1d-1e00-0000-80b9-95ffee0c0000 pid=3310 execve guuid=9ca3191e-1e00-0000-80b9-95fff20c0000 pid=3314 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=9ca3191e-1e00-0000-80b9-95fff20c0000 pid=3314 execve guuid=6b3c877c-1e00-0000-80b9-95ffcb0d0000 pid=3531 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=6b3c877c-1e00-0000-80b9-95ffcb0d0000 pid=3531 execve guuid=7c82ed46-2100-0000-80b9-95ff58160000 pid=5720 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=7c82ed46-2100-0000-80b9-95ff58160000 pid=5720 execve guuid=d786f93d-2200-0000-80b9-95ffa7160000 pid=5799 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=d786f93d-2200-0000-80b9-95ffa7160000 pid=5799 execve guuid=a504a746-2200-0000-80b9-95ffb1160000 pid=5809 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=a504a746-2200-0000-80b9-95ffb1160000 pid=5809 execve guuid=efe17211-2300-0000-80b9-95ff03170000 pid=5891 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=efe17211-2300-0000-80b9-95ff03170000 pid=5891 execve guuid=d17b0112-2300-0000-80b9-95ff05170000 pid=5893 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=d17b0112-2300-0000-80b9-95ff05170000 pid=5893 execve guuid=b3a28f12-2300-0000-80b9-95ff07170000 pid=5895 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=b3a28f12-2300-0000-80b9-95ff07170000 pid=5895 execve guuid=51e62f13-2300-0000-80b9-95ff0a170000 pid=5898 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=51e62f13-2300-0000-80b9-95ff0a170000 pid=5898 execve guuid=3e331a61-2b00-0000-80b9-95ff8f170000 pid=6031 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=3e331a61-2b00-0000-80b9-95ff8f170000 pid=6031 execve guuid=790abf61-2b00-0000-80b9-95ffa2170000 pid=6050 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=790abf61-2b00-0000-80b9-95ffa2170000 pid=6050 execve guuid=ae3fcba5-2b00-0000-80b9-95ffdb170000 pid=6107 /usr/bin/dash guuid=8b69261d-1e00-0000-80b9-95ffec0c0000 pid=3308->guuid=ae3fcba5-2b00-0000-80b9-95ffdb170000 pid=6107 execve guuid=7e92b91d-1e00-0000-80b9-95fff00c0000 pid=3312 /usr/bin/dash guuid=e9a15c1d-1e00-0000-80b9-95ffee0c0000 pid=3310->guuid=7e92b91d-1e00-0000-80b9-95fff00c0000 pid=3312 clone guuid=6954d31d-1e00-0000-80b9-95fff10c0000 pid=3313 /usr/bin/dash guuid=e9a15c1d-1e00-0000-80b9-95ffee0c0000 pid=3310->guuid=6954d31d-1e00-0000-80b9-95fff10c0000 pid=3313 clone guuid=87a1ae1e-1e00-0000-80b9-95fff90c0000 pid=3321 /usr/bin/systemctl guuid=9ca3191e-1e00-0000-80b9-95fff20c0000 pid=3314->guuid=87a1ae1e-1e00-0000-80b9-95fff90c0000 pid=3321 execve guuid=7d21471e-1e00-0000-80b9-95fff40c0000 pid=3316 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=7d21471e-1e00-0000-80b9-95fff40c0000 pid=3316 execve guuid=7ed1af23-1e00-0000-80b9-95ff160d0000 pid=3350 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=7ed1af23-1e00-0000-80b9-95ff160d0000 pid=3350 execve guuid=4417f1dc-1e00-0000-80b9-95ffdc0e0000 pid=3804 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=4417f1dc-1e00-0000-80b9-95ffdc0e0000 pid=3804 execve guuid=4b5941d3-2100-0000-80b9-95ff89160000 pid=5769 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=4b5941d3-2100-0000-80b9-95ff89160000 pid=5769 execve guuid=b6ca283c-2200-0000-80b9-95ffa5160000 pid=5797 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=b6ca283c-2200-0000-80b9-95ffa5160000 pid=5797 execve guuid=3ceff93d-2200-0000-80b9-95ffa8160000 pid=5800 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=3ceff93d-2200-0000-80b9-95ffa8160000 pid=5800 execve guuid=91f66f9b-2200-0000-80b9-95ffcb160000 pid=5835 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=91f66f9b-2200-0000-80b9-95ffcb160000 pid=5835 execve guuid=466d329c-2200-0000-80b9-95ffcd160000 pid=5837 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=466d329c-2200-0000-80b9-95ffcd160000 pid=5837 execve guuid=2dcb209d-2200-0000-80b9-95ffcf160000 pid=5839 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=2dcb209d-2200-0000-80b9-95ffcf160000 pid=5839 execve guuid=d2bf459f-2200-0000-80b9-95ffd1160000 pid=5841 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=d2bf459f-2200-0000-80b9-95ffd1160000 pid=5841 execve guuid=0f701961-2b00-0000-80b9-95ff8e170000 pid=6030 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=0f701961-2b00-0000-80b9-95ff8e170000 pid=6030 execve guuid=0dc6af61-2b00-0000-80b9-95ff9f170000 pid=6047 /usr/bin/dash guuid=71b8201e-1e00-0000-80b9-95fff30c0000 pid=3315->guuid=0dc6af61-2b00-0000-80b9-95ff9f170000 pid=6047 execve guuid=d293931e-1e00-0000-80b9-95fff60c0000 pid=3318 /usr/bin/dash guuid=7d21471e-1e00-0000-80b9-95fff40c0000 pid=3316->guuid=d293931e-1e00-0000-80b9-95fff60c0000 pid=3318 clone guuid=5cf4a81e-1e00-0000-80b9-95fff80c0000 pid=3320 /usr/bin/dash guuid=7d21471e-1e00-0000-80b9-95fff40c0000 pid=3316->guuid=5cf4a81e-1e00-0000-80b9-95fff80c0000 pid=3320 clone guuid=3fd6dc1e-1e00-0000-80b9-95fffc0c0000 pid=3324 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=3fd6dc1e-1e00-0000-80b9-95fffc0c0000 pid=3324 execve guuid=6ef4be23-1e00-0000-80b9-95ff170d0000 pid=3351 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=6ef4be23-1e00-0000-80b9-95ff170d0000 pid=3351 execve guuid=894fb7b2-1e00-0000-80b9-95ff620e0000 pid=3682 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=894fb7b2-1e00-0000-80b9-95ff620e0000 pid=3682 execve guuid=f170299f-2100-0000-80b9-95ff6e160000 pid=5742 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=f170299f-2100-0000-80b9-95ff6e160000 pid=5742 execve guuid=1731c76f-2300-0000-80b9-95ff28170000 pid=5928 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=1731c76f-2300-0000-80b9-95ff28170000 pid=5928 execve guuid=c2063f70-2300-0000-80b9-95ff2c170000 pid=5932 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=c2063f70-2300-0000-80b9-95ff2c170000 pid=5932 execve guuid=abdb1c95-2300-0000-80b9-95ff4f170000 pid=5967 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=abdb1c95-2300-0000-80b9-95ff4f170000 pid=5967 execve guuid=fe1acb95-2300-0000-80b9-95ff51170000 pid=5969 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=fe1acb95-2300-0000-80b9-95ff51170000 pid=5969 execve guuid=67c35096-2300-0000-80b9-95ff53170000 pid=5971 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=67c35096-2300-0000-80b9-95ff53170000 pid=5971 execve guuid=7f7ede96-2300-0000-80b9-95ff55170000 pid=5973 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=7f7ede96-2300-0000-80b9-95ff55170000 pid=5973 execve guuid=ddd62361-2b00-0000-80b9-95ff91170000 pid=6033 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=ddd62361-2b00-0000-80b9-95ff91170000 pid=6033 execve guuid=0c27ea61-2b00-0000-80b9-95ffa5170000 pid=6053 /usr/bin/dash guuid=fee4c51e-1e00-0000-80b9-95fffa0c0000 pid=3322->guuid=0c27ea61-2b00-0000-80b9-95ffa5170000 pid=6053 execve guuid=9fdd071f-1e00-0000-80b9-95fffd0c0000 pid=3325 /usr/bin/dash guuid=3fd6dc1e-1e00-0000-80b9-95fffc0c0000 pid=3324->guuid=9fdd071f-1e00-0000-80b9-95fffd0c0000 pid=3325 clone guuid=d9730b1f-1e00-0000-80b9-95fffe0c0000 pid=3326 /usr/bin/dash guuid=3fd6dc1e-1e00-0000-80b9-95fffc0c0000 pid=3324->guuid=d9730b1f-1e00-0000-80b9-95fffe0c0000 pid=3326 clone guuid=b6450f20-1e00-0000-80b9-95ff030d0000 pid=3331 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=b6450f20-1e00-0000-80b9-95ff030d0000 pid=3331 execve guuid=856ad023-1e00-0000-80b9-95ff180d0000 pid=3352 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=856ad023-1e00-0000-80b9-95ff180d0000 pid=3352 execve guuid=a2c7ad10-1f00-0000-80b9-95ff5c0f0000 pid=3932 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=a2c7ad10-1f00-0000-80b9-95ff5c0f0000 pid=3932 execve guuid=ba5e9230-2200-0000-80b9-95ffa1160000 pid=5793 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=ba5e9230-2200-0000-80b9-95ffa1160000 pid=5793 execve guuid=70d5c96f-2300-0000-80b9-95ff29170000 pid=5929 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=70d5c96f-2300-0000-80b9-95ff29170000 pid=5929 execve guuid=454c7670-2300-0000-80b9-95ff2e170000 pid=5934 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=454c7670-2300-0000-80b9-95ff2e170000 pid=5934 execve guuid=27624fc2-2300-0000-80b9-95ff7c170000 pid=6012 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=27624fc2-2300-0000-80b9-95ff7c170000 pid=6012 execve guuid=36502cc3-2300-0000-80b9-95ff7e170000 pid=6014 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=36502cc3-2300-0000-80b9-95ff7e170000 pid=6014 execve guuid=fa94e3c3-2300-0000-80b9-95ff80170000 pid=6016 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=fa94e3c3-2300-0000-80b9-95ff80170000 pid=6016 execve guuid=ae3a9ac4-2300-0000-80b9-95ff82170000 pid=6018 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=ae3a9ac4-2300-0000-80b9-95ff82170000 pid=6018 execve guuid=5cc11a61-2b00-0000-80b9-95ff90170000 pid=6032 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=5cc11a61-2b00-0000-80b9-95ff90170000 pid=6032 execve guuid=d23f9c61-2b00-0000-80b9-95ff9d170000 pid=6045 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=d23f9c61-2b00-0000-80b9-95ff9d170000 pid=6045 execve guuid=5d24ee84-2b00-0000-80b9-95ffc1170000 pid=6081 /usr/bin/dash guuid=c6a5cb1f-1e00-0000-80b9-95ff010d0000 pid=3329->guuid=5d24ee84-2b00-0000-80b9-95ffc1170000 pid=6081 execve guuid=ea3d7c20-1e00-0000-80b9-95ff040d0000 pid=3332 /usr/bin/dash guuid=b6450f20-1e00-0000-80b9-95ff030d0000 pid=3331->guuid=ea3d7c20-1e00-0000-80b9-95ff040d0000 pid=3332 clone guuid=09c28820-1e00-0000-80b9-95ff050d0000 pid=3333 /usr/bin/dash guuid=b6450f20-1e00-0000-80b9-95ff030d0000 pid=3331->guuid=09c28820-1e00-0000-80b9-95ff050d0000 pid=3333 clone guuid=24812125-1e00-0000-80b9-95ff1b0d0000 pid=3355 /usr/bin/systemctl guuid=7ed1af23-1e00-0000-80b9-95ff160d0000 pid=3350->guuid=24812125-1e00-0000-80b9-95ff1b0d0000 pid=3355 execve guuid=416c2725-1e00-0000-80b9-95ff1c0d0000 pid=3356 /usr/bin/systemctl guuid=6ef4be23-1e00-0000-80b9-95ff170d0000 pid=3351->guuid=416c2725-1e00-0000-80b9-95ff1c0d0000 pid=3356 execve guuid=cbae0f27-1e00-0000-80b9-95ff1d0d0000 pid=3357 /usr/bin/systemctl guuid=856ad023-1e00-0000-80b9-95ff180d0000 pid=3352->guuid=cbae0f27-1e00-0000-80b9-95ff1d0d0000 pid=3357 execve guuid=96f9c65b-1e00-0000-80b9-95ff670d0000 pid=3431 /usr/bin/systemctl guuid=3bd2775b-1e00-0000-80b9-95ff650d0000 pid=3429->guuid=96f9c65b-1e00-0000-80b9-95ff670d0000 pid=3431 execve guuid=eb0dc25d-1e00-0000-80b9-95ff6b0d0000 pid=3435 /usr/lib/systemd/systemd-sysv-install guuid=96f9c65b-1e00-0000-80b9-95ff670d0000 pid=3431->guuid=eb0dc25d-1e00-0000-80b9-95ff6b0d0000 pid=3435 execve guuid=38ec9a5e-1e00-0000-80b9-95ff6d0d0000 pid=3437 /usr/bin/getopt guuid=eb0dc25d-1e00-0000-80b9-95ff6b0d0000 pid=3435->guuid=38ec9a5e-1e00-0000-80b9-95ff6d0d0000 pid=3437 execve guuid=ea2cf05e-1e00-0000-80b9-95ff6f0d0000 pid=3439 /usr/sbin/update-rc.d guuid=eb0dc25d-1e00-0000-80b9-95ff6b0d0000 pid=3435->guuid=ea2cf05e-1e00-0000-80b9-95ff6f0d0000 pid=3439 execve guuid=d69a7940-1f00-0000-80b9-95fffd0f0000 pid=4093 /usr/sbin/update-rc.d guuid=eb0dc25d-1e00-0000-80b9-95ff6b0d0000 pid=3435->guuid=d69a7940-1f00-0000-80b9-95fffd0f0000 pid=4093 execve guuid=9f7d4361-1e00-0000-80b9-95ff850d0000 pid=3461 /usr/bin/systemctl guuid=ea2cf05e-1e00-0000-80b9-95ff6f0d0000 pid=3439->guuid=9f7d4361-1e00-0000-80b9-95ff850d0000 pid=3461 execve guuid=388cbf7c-1e00-0000-80b9-95ffcc0d0000 pid=3532 /usr/bin/systemctl guuid=6b3c877c-1e00-0000-80b9-95ffcb0d0000 pid=3531->guuid=388cbf7c-1e00-0000-80b9-95ffcc0d0000 pid=3532 execve guuid=c8d63f7e-1e00-0000-80b9-95ffd30d0000 pid=3539 /usr/lib/systemd/systemd-sysv-install guuid=388cbf7c-1e00-0000-80b9-95ffcc0d0000 pid=3532->guuid=c8d63f7e-1e00-0000-80b9-95ffd30d0000 pid=3539 execve guuid=bd447a7e-1e00-0000-80b9-95ffd40d0000 pid=3540 /usr/bin/getopt guuid=c8d63f7e-1e00-0000-80b9-95ffd30d0000 pid=3539->guuid=bd447a7e-1e00-0000-80b9-95ffd40d0000 pid=3540 execve guuid=84c2677f-1e00-0000-80b9-95ffd90d0000 pid=3545 /usr/sbin/update-rc.d guuid=c8d63f7e-1e00-0000-80b9-95ffd30d0000 pid=3539->guuid=84c2677f-1e00-0000-80b9-95ffd90d0000 pid=3545 execve guuid=a5c9f881-1f00-0000-80b9-95ffe1100000 pid=4321 /usr/sbin/update-rc.d guuid=c8d63f7e-1e00-0000-80b9-95ffd30d0000 pid=3539->guuid=a5c9f881-1f00-0000-80b9-95ffe1100000 pid=4321 execve guuid=2ece9d80-1e00-0000-80b9-95ffe10d0000 pid=3553 /usr/bin/systemctl guuid=84c2677f-1e00-0000-80b9-95ffd90d0000 pid=3545->guuid=2ece9d80-1e00-0000-80b9-95ffe10d0000 pid=3553 execve guuid=6d4ce4b2-1e00-0000-80b9-95ff630e0000 pid=3683 /usr/bin/systemctl guuid=894fb7b2-1e00-0000-80b9-95ff620e0000 pid=3682->guuid=6d4ce4b2-1e00-0000-80b9-95ff630e0000 pid=3683 execve guuid=3ed3d9b3-1e00-0000-80b9-95ff670e0000 pid=3687 /usr/lib/systemd/systemd-sysv-install guuid=6d4ce4b2-1e00-0000-80b9-95ff630e0000 pid=3683->guuid=3ed3d9b3-1e00-0000-80b9-95ff670e0000 pid=3687 execve guuid=93a114b4-1e00-0000-80b9-95ff680e0000 pid=3688 /usr/bin/getopt guuid=3ed3d9b3-1e00-0000-80b9-95ff670e0000 pid=3687->guuid=93a114b4-1e00-0000-80b9-95ff680e0000 pid=3688 execve guuid=c9784db4-1e00-0000-80b9-95ff690e0000 pid=3689 /usr/sbin/update-rc.d guuid=3ed3d9b3-1e00-0000-80b9-95ff670e0000 pid=3687->guuid=c9784db4-1e00-0000-80b9-95ff690e0000 pid=3689 execve guuid=11aec6a7-1f00-0000-80b9-95ff68110000 pid=4456 /usr/sbin/update-rc.d guuid=3ed3d9b3-1e00-0000-80b9-95ff670e0000 pid=3687->guuid=11aec6a7-1f00-0000-80b9-95ff68110000 pid=4456 execve guuid=e79a4db6-1e00-0000-80b9-95ff720e0000 pid=3698 /usr/bin/systemctl guuid=c9784db4-1e00-0000-80b9-95ff690e0000 pid=3689->guuid=e79a4db6-1e00-0000-80b9-95ff720e0000 pid=3698 execve guuid=098534dd-1e00-0000-80b9-95ffdd0e0000 pid=3805 /usr/bin/systemctl guuid=4417f1dc-1e00-0000-80b9-95ffdc0e0000 pid=3804->guuid=098534dd-1e00-0000-80b9-95ffdd0e0000 pid=3805 execve guuid=95cad6de-1e00-0000-80b9-95ffe10e0000 pid=3809 /usr/lib/systemd/systemd-sysv-install guuid=098534dd-1e00-0000-80b9-95ffdd0e0000 pid=3805->guuid=95cad6de-1e00-0000-80b9-95ffe10e0000 pid=3809 execve guuid=163723df-1e00-0000-80b9-95ffe20e0000 pid=3810 /usr/bin/getopt guuid=95cad6de-1e00-0000-80b9-95ffe10e0000 pid=3809->guuid=163723df-1e00-0000-80b9-95ffe20e0000 pid=3810 execve guuid=861dd8e0-1e00-0000-80b9-95ffe60e0000 pid=3814 /usr/sbin/update-rc.d guuid=95cad6de-1e00-0000-80b9-95ffe10e0000 pid=3809->guuid=861dd8e0-1e00-0000-80b9-95ffe60e0000 pid=3814 execve guuid=c0125bcf-1f00-0000-80b9-95fffc110000 pid=4604 /usr/sbin/update-rc.d guuid=95cad6de-1e00-0000-80b9-95ffe10e0000 pid=3809->guuid=c0125bcf-1f00-0000-80b9-95fffc110000 pid=4604 execve guuid=d23a14e4-1e00-0000-80b9-95fff90e0000 pid=3833 /usr/bin/systemctl guuid=861dd8e0-1e00-0000-80b9-95ffe60e0000 pid=3814->guuid=d23a14e4-1e00-0000-80b9-95fff90e0000 pid=3833 execve guuid=ad1a1311-1f00-0000-80b9-95ff5d0f0000 pid=3933 /usr/bin/systemctl guuid=a2c7ad10-1f00-0000-80b9-95ff5c0f0000 pid=3932->guuid=ad1a1311-1f00-0000-80b9-95ff5d0f0000 pid=3933 execve guuid=ac440f14-1f00-0000-80b9-95ff660f0000 pid=3942 /usr/lib/systemd/systemd-sysv-install guuid=ad1a1311-1f00-0000-80b9-95ff5d0f0000 pid=3933->guuid=ac440f14-1f00-0000-80b9-95ff660f0000 pid=3942 execve guuid=ba1dce16-1f00-0000-80b9-95ff750f0000 pid=3957 /usr/bin/getopt guuid=ac440f14-1f00-0000-80b9-95ff660f0000 pid=3942->guuid=ba1dce16-1f00-0000-80b9-95ff750f0000 pid=3957 execve guuid=90902818-1f00-0000-80b9-95ff790f0000 pid=3961 /usr/sbin/update-rc.d guuid=ac440f14-1f00-0000-80b9-95ff660f0000 pid=3942->guuid=90902818-1f00-0000-80b9-95ff790f0000 pid=3961 execve guuid=c0cd90f7-1f00-0000-80b9-95ffae120000 pid=4782 /usr/sbin/update-rc.d guuid=ac440f14-1f00-0000-80b9-95ff660f0000 pid=3942->guuid=c0cd90f7-1f00-0000-80b9-95ffae120000 pid=4782 execve guuid=9efb1421-1f00-0000-80b9-95ff890f0000 pid=3977 /usr/bin/systemctl guuid=90902818-1f00-0000-80b9-95ff790f0000 pid=3961->guuid=9efb1421-1f00-0000-80b9-95ff890f0000 pid=3977 execve guuid=b1e0df41-1f00-0000-80b9-95ff05100000 pid=4101 /usr/bin/systemctl guuid=d69a7940-1f00-0000-80b9-95fffd0f0000 pid=4093->guuid=b1e0df41-1f00-0000-80b9-95ff05100000 pid=4101 execve guuid=df6a5383-1f00-0000-80b9-95ffe9100000 pid=4329 /usr/bin/systemctl guuid=a5c9f881-1f00-0000-80b9-95ffe1100000 pid=4321->guuid=df6a5383-1f00-0000-80b9-95ffe9100000 pid=4329 execve guuid=6dd70faa-1f00-0000-80b9-95ff6d110000 pid=4461 /usr/bin/systemctl guuid=11aec6a7-1f00-0000-80b9-95ff68110000 pid=4456->guuid=6dd70faa-1f00-0000-80b9-95ff6d110000 pid=4461 execve guuid=aa9cb5d0-1f00-0000-80b9-95ff01120000 pid=4609 /usr/bin/systemctl guuid=c0125bcf-1f00-0000-80b9-95fffc110000 pid=4604->guuid=aa9cb5d0-1f00-0000-80b9-95ff01120000 pid=4609 execve guuid=1d8c9df9-1f00-0000-80b9-95ffbc120000 pid=4796 /usr/bin/systemctl guuid=c0cd90f7-1f00-0000-80b9-95ffae120000 pid=4782->guuid=1d8c9df9-1f00-0000-80b9-95ffbc120000 pid=4796 execve guuid=8a967716-2100-0000-80b9-95ff43160000 pid=5699 /usr/bin/systemctl guuid=946a3416-2100-0000-80b9-95ff42160000 pid=5698->guuid=8a967716-2100-0000-80b9-95ff43160000 pid=5699 execve guuid=a62d3b47-2100-0000-80b9-95ff59160000 pid=5721 /usr/bin/systemctl guuid=7c82ed46-2100-0000-80b9-95ff58160000 pid=5720->guuid=a62d3b47-2100-0000-80b9-95ff59160000 pid=5721 execve guuid=06885d9f-2100-0000-80b9-95ff6f160000 pid=5743 /usr/bin/systemctl guuid=f170299f-2100-0000-80b9-95ff6e160000 pid=5742->guuid=06885d9f-2100-0000-80b9-95ff6f160000 pid=5743 execve guuid=9a2991d3-2100-0000-80b9-95ff8a160000 pid=5770 /usr/bin/systemctl guuid=4b5941d3-2100-0000-80b9-95ff89160000 pid=5769->guuid=9a2991d3-2100-0000-80b9-95ff8a160000 pid=5770 execve guuid=a0343a31-2200-0000-80b9-95ffa2160000 pid=5794 /usr/bin/systemctl guuid=ba5e9230-2200-0000-80b9-95ffa1160000 pid=5793->guuid=a0343a31-2200-0000-80b9-95ffa2160000 pid=5794 execve guuid=062f703c-2200-0000-80b9-95ffa6160000 pid=5798 /usr/bin/chmod guuid=b6ca283c-2200-0000-80b9-95ffa5160000 pid=5797->guuid=062f703c-2200-0000-80b9-95ffa6160000 pid=5798 execve guuid=53ba763e-2200-0000-80b9-95ffaa160000 pid=5802 /usr/bin/chmod guuid=d786f93d-2200-0000-80b9-95ffa7160000 pid=5799->guuid=53ba763e-2200-0000-80b9-95ffaa160000 pid=5802 execve guuid=bc778d3e-2200-0000-80b9-95ffab160000 pid=5803 /usr/sbin/update-rc.d guuid=3ceff93d-2200-0000-80b9-95ffa8160000 pid=5800->guuid=bc778d3e-2200-0000-80b9-95ffab160000 pid=5803 execve guuid=fe3adc3e-2200-0000-80b9-95ffac160000 pid=5804 /usr/bin/chmod guuid=f2a6fd3d-2200-0000-80b9-95ffa9160000 pid=5801->guuid=fe3adc3e-2200-0000-80b9-95ffac160000 pid=5804 execve guuid=4e05d446-2200-0000-80b9-95ffb2160000 pid=5810 /usr/bin/systemctl guuid=bc778d3e-2200-0000-80b9-95ffab160000 pid=5803->guuid=4e05d446-2200-0000-80b9-95ffb2160000 pid=5810 execve guuid=909a8140-2200-0000-80b9-95ffae160000 pid=5806 /usr/sbin/update-rc.d guuid=a0cc2240-2200-0000-80b9-95ffad160000 pid=5805->guuid=909a8140-2200-0000-80b9-95ffae160000 pid=5806 execve guuid=025abe44-2200-0000-80b9-95ffaf160000 pid=5807 /usr/bin/systemctl guuid=909a8140-2200-0000-80b9-95ffae160000 pid=5806->guuid=025abe44-2200-0000-80b9-95ffaf160000 pid=5807 execve guuid=75410b47-2200-0000-80b9-95ffb3160000 pid=5811 /usr/sbin/update-rc.d guuid=a504a746-2200-0000-80b9-95ffb1160000 pid=5809->guuid=75410b47-2200-0000-80b9-95ffb3160000 pid=5811 execve guuid=65ddaf4a-2200-0000-80b9-95ffb5160000 pid=5813 /usr/bin/systemctl guuid=75410b47-2200-0000-80b9-95ffb3160000 pid=5811->guuid=65ddaf4a-2200-0000-80b9-95ffb5160000 pid=5813 execve guuid=4214a09b-2200-0000-80b9-95ffcc160000 pid=5836 /usr/bin/grep guuid=91f66f9b-2200-0000-80b9-95ffcb160000 pid=5835->guuid=4214a09b-2200-0000-80b9-95ffcc160000 pid=5836 execve guuid=fa695d9c-2200-0000-80b9-95ffce160000 pid=5838 /usr/bin/grep guuid=466d329c-2200-0000-80b9-95ffcd160000 pid=5837->guuid=fa695d9c-2200-0000-80b9-95ffce160000 pid=5838 execve guuid=e462b89d-2200-0000-80b9-95ffd0160000 pid=5840 /usr/bin/grep guuid=2dcb209d-2200-0000-80b9-95ffcf160000 pid=5839->guuid=e462b89d-2200-0000-80b9-95ffd0160000 pid=5840 execve guuid=7df8a09f-2200-0000-80b9-95ffd2160000 pid=5842 /usr/bin/chattr guuid=d2bf459f-2200-0000-80b9-95ffd1160000 pid=5841->guuid=7df8a09f-2200-0000-80b9-95ffd2160000 pid=5842 execve guuid=63435ed3-2200-0000-80b9-95ffe8160000 pid=5864 /usr/bin/grep guuid=ae9dd0d2-2200-0000-80b9-95ffe7160000 pid=5863->guuid=63435ed3-2200-0000-80b9-95ffe8160000 pid=5864 execve guuid=0d7a10d5-2200-0000-80b9-95ffea160000 pid=5866 /usr/bin/grep guuid=d93396d4-2200-0000-80b9-95ffe9160000 pid=5865->guuid=0d7a10d5-2200-0000-80b9-95ffea160000 pid=5866 execve guuid=10abd8d5-2200-0000-80b9-95ffec160000 pid=5868 /usr/bin/grep guuid=20e271d5-2200-0000-80b9-95ffeb160000 pid=5867->guuid=10abd8d5-2200-0000-80b9-95ffec160000 pid=5868 execve guuid=c66e5dd7-2200-0000-80b9-95ffef160000 pid=5871 /usr/bin/chattr guuid=a48fb4d6-2200-0000-80b9-95ffed160000 pid=5869->guuid=c66e5dd7-2200-0000-80b9-95ffef160000 pid=5871 execve guuid=7b4dae11-2300-0000-80b9-95ff04170000 pid=5892 /usr/bin/grep guuid=efe17211-2300-0000-80b9-95ff03170000 pid=5891->guuid=7b4dae11-2300-0000-80b9-95ff04170000 pid=5892 execve guuid=5ed13912-2300-0000-80b9-95ff06170000 pid=5894 /usr/bin/grep guuid=d17b0112-2300-0000-80b9-95ff05170000 pid=5893->guuid=5ed13912-2300-0000-80b9-95ff06170000 pid=5894 execve guuid=7403c212-2300-0000-80b9-95ff09170000 pid=5897 /usr/bin/grep guuid=b3a28f12-2300-0000-80b9-95ff07170000 pid=5895->guuid=7403c212-2300-0000-80b9-95ff09170000 pid=5897 execve guuid=8c6b5c13-2300-0000-80b9-95ff0b170000 pid=5899 /usr/bin/chattr guuid=51e62f13-2300-0000-80b9-95ff0a170000 pid=5898->guuid=8c6b5c13-2300-0000-80b9-95ff0b170000 pid=5899 execve guuid=d2aefa6f-2300-0000-80b9-95ff2a170000 pid=5930 /usr/bin/chmod guuid=1731c76f-2300-0000-80b9-95ff28170000 pid=5928->guuid=d2aefa6f-2300-0000-80b9-95ff2a170000 pid=5930 execve guuid=d9e01570-2300-0000-80b9-95ff2b170000 pid=5931 /usr/bin/chmod guuid=70d5c96f-2300-0000-80b9-95ff29170000 pid=5929->guuid=d9e01570-2300-0000-80b9-95ff2b170000 pid=5931 execve guuid=00396870-2300-0000-80b9-95ff2d170000 pid=5933 /usr/sbin/update-rc.d guuid=c2063f70-2300-0000-80b9-95ff2c170000 pid=5932->guuid=00396870-2300-0000-80b9-95ff2d170000 pid=5933 execve guuid=f1559471-2300-0000-80b9-95ff30170000 pid=5936 /usr/bin/systemctl guuid=00396870-2300-0000-80b9-95ff2d170000 pid=5933->guuid=f1559471-2300-0000-80b9-95ff30170000 pid=5936 execve guuid=e7c3b570-2300-0000-80b9-95ff2f170000 pid=5935 /usr/sbin/update-rc.d guuid=454c7670-2300-0000-80b9-95ff2e170000 pid=5934->guuid=e7c3b570-2300-0000-80b9-95ff2f170000 pid=5935 execve guuid=40884872-2300-0000-80b9-95ff31170000 pid=5937 /usr/bin/systemctl guuid=e7c3b570-2300-0000-80b9-95ff2f170000 pid=5935->guuid=40884872-2300-0000-80b9-95ff31170000 pid=5937 execve guuid=14366595-2300-0000-80b9-95ff50170000 pid=5968 /usr/bin/grep guuid=abdb1c95-2300-0000-80b9-95ff4f170000 pid=5967->guuid=14366595-2300-0000-80b9-95ff50170000 pid=5968 execve guuid=7417f695-2300-0000-80b9-95ff52170000 pid=5970 /usr/bin/grep guuid=fe1acb95-2300-0000-80b9-95ff51170000 pid=5969->guuid=7417f695-2300-0000-80b9-95ff52170000 pid=5970 execve guuid=e76a8196-2300-0000-80b9-95ff54170000 pid=5972 /usr/bin/grep guuid=67c35096-2300-0000-80b9-95ff53170000 pid=5971->guuid=e76a8196-2300-0000-80b9-95ff54170000 pid=5972 execve guuid=89071197-2300-0000-80b9-95ff56170000 pid=5974 /usr/bin/chattr guuid=7f7ede96-2300-0000-80b9-95ff55170000 pid=5973->guuid=89071197-2300-0000-80b9-95ff56170000 pid=5974 execve guuid=2e6387c2-2300-0000-80b9-95ff7d170000 pid=6013 /usr/bin/grep guuid=27624fc2-2300-0000-80b9-95ff7c170000 pid=6012->guuid=2e6387c2-2300-0000-80b9-95ff7d170000 pid=6013 execve guuid=cbeb5dc3-2300-0000-80b9-95ff7f170000 pid=6015 /usr/bin/grep guuid=36502cc3-2300-0000-80b9-95ff7e170000 pid=6014->guuid=cbeb5dc3-2300-0000-80b9-95ff7f170000 pid=6015 execve guuid=33b011c4-2300-0000-80b9-95ff81170000 pid=6017 /usr/bin/grep guuid=fa94e3c3-2300-0000-80b9-95ff80170000 pid=6016->guuid=33b011c4-2300-0000-80b9-95ff81170000 pid=6017 execve guuid=45c7cac4-2300-0000-80b9-95ff83170000 pid=6019 /usr/bin/chattr guuid=ae3a9ac4-2300-0000-80b9-95ff82170000 pid=6018->guuid=45c7cac4-2300-0000-80b9-95ff83170000 pid=6019 execve guuid=d4d14161-2b00-0000-80b9-95ff94170000 pid=6036 /usr/bin/dash guuid=0f701961-2b00-0000-80b9-95ff8e170000 pid=6030->guuid=d4d14161-2b00-0000-80b9-95ff94170000 pid=6036 clone guuid=dd704761-2b00-0000-80b9-95ff96170000 pid=6038 /usr/bin/dash guuid=0f701961-2b00-0000-80b9-95ff8e170000 pid=6030->guuid=dd704761-2b00-0000-80b9-95ff96170000 pid=6038 clone guuid=fcc14161-2b00-0000-80b9-95ff93170000 pid=6035 /usr/bin/dash guuid=3e331a61-2b00-0000-80b9-95ff8f170000 pid=6031->guuid=fcc14161-2b00-0000-80b9-95ff93170000 pid=6035 clone guuid=f14c4661-2b00-0000-80b9-95ff95170000 pid=6037 /usr/bin/dash guuid=3e331a61-2b00-0000-80b9-95ff8f170000 pid=6031->guuid=f14c4661-2b00-0000-80b9-95ff95170000 pid=6037 clone guuid=fec86f61-2b00-0000-80b9-95ff99170000 pid=6041 /usr/bin/dash guuid=5cc11a61-2b00-0000-80b9-95ff90170000 pid=6032->guuid=fec86f61-2b00-0000-80b9-95ff99170000 pid=6041 clone guuid=693f7461-2b00-0000-80b9-95ff9b170000 pid=6043 /usr/bin/dash guuid=5cc11a61-2b00-0000-80b9-95ff90170000 pid=6032->guuid=693f7461-2b00-0000-80b9-95ff9b170000 pid=6043 clone guuid=eedfb361-2b00-0000-80b9-95ffa0170000 pid=6048 /usr/bin/dash guuid=ddd62361-2b00-0000-80b9-95ff91170000 pid=6033->guuid=eedfb361-2b00-0000-80b9-95ffa0170000 pid=6048 clone guuid=2accb761-2b00-0000-80b9-95ffa1170000 pid=6049 /usr/bin/dash guuid=ddd62361-2b00-0000-80b9-95ff91170000 pid=6033->guuid=2accb761-2b00-0000-80b9-95ffa1170000 pid=6049 clone guuid=c20d6161-2b00-0000-80b9-95ff97170000 pid=6039 /usr/bin/dash guuid=3afe2b61-2b00-0000-80b9-95ff92170000 pid=6034->guuid=c20d6161-2b00-0000-80b9-95ff97170000 pid=6039 clone guuid=1df86761-2b00-0000-80b9-95ff98170000 pid=6040 /usr/bin/dash guuid=3afe2b61-2b00-0000-80b9-95ff92170000 pid=6034->guuid=1df86761-2b00-0000-80b9-95ff98170000 pid=6040 clone guuid=e120d261-2b00-0000-80b9-95ffa3170000 pid=6051 /usr/bin/systemctl guuid=8fba9761-2b00-0000-80b9-95ff9c170000 pid=6044->guuid=e120d261-2b00-0000-80b9-95ffa3170000 pid=6051 execve guuid=b11d1962-2b00-0000-80b9-95ffa8170000 pid=6056 /usr/bin/systemctl guuid=d23f9c61-2b00-0000-80b9-95ff9d170000 pid=6045->guuid=b11d1962-2b00-0000-80b9-95ffa8170000 pid=6056 execve guuid=8ff9fa61-2b00-0000-80b9-95ffa7170000 pid=6055 /usr/bin/systemctl guuid=0dc6af61-2b00-0000-80b9-95ff9f170000 pid=6047->guuid=8ff9fa61-2b00-0000-80b9-95ffa7170000 pid=6055 execve guuid=eb7ded61-2b00-0000-80b9-95ffa6170000 pid=6054 /usr/bin/systemctl guuid=790abf61-2b00-0000-80b9-95ffa2170000 pid=6050->guuid=eb7ded61-2b00-0000-80b9-95ffa6170000 pid=6054 execve guuid=4f1f9d62-2b00-0000-80b9-95ffaa170000 pid=6058 /usr/bin/systemctl guuid=0c27ea61-2b00-0000-80b9-95ffa5170000 pid=6053->guuid=4f1f9d62-2b00-0000-80b9-95ffaa170000 pid=6058 execve guuid=38eb1c85-2b00-0000-80b9-95ffc2170000 pid=6082 /usr/bin/systemctl guuid=5d24ee84-2b00-0000-80b9-95ffc1170000 pid=6081->guuid=38eb1c85-2b00-0000-80b9-95ffc2170000 pid=6082 execve guuid=fa7cf585-2b00-0000-80b9-95ffc3170000 pid=6083 /usr/lib/systemd/systemd-sysv-install guuid=38eb1c85-2b00-0000-80b9-95ffc2170000 pid=6082->guuid=fa7cf585-2b00-0000-80b9-95ffc3170000 pid=6083 execve guuid=1e153386-2b00-0000-80b9-95ffc4170000 pid=6084 /usr/bin/getopt guuid=fa7cf585-2b00-0000-80b9-95ffc3170000 pid=6083->guuid=1e153386-2b00-0000-80b9-95ffc4170000 pid=6084 execve guuid=3934a786-2b00-0000-80b9-95ffc5170000 pid=6085 /usr/sbin/update-rc.d guuid=fa7cf585-2b00-0000-80b9-95ffc3170000 pid=6083->guuid=3934a786-2b00-0000-80b9-95ffc5170000 pid=6085 execve guuid=81b35d89-2b00-0000-80b9-95ffc7170000 pid=6087 /usr/bin/systemctl guuid=3934a786-2b00-0000-80b9-95ffc5170000 pid=6085->guuid=81b35d89-2b00-0000-80b9-95ffc7170000 pid=6087 execve guuid=cb3912a6-2b00-0000-80b9-95ffdc170000 pid=6108 /usr/bin/systemctl guuid=ae3fcba5-2b00-0000-80b9-95ffdb170000 pid=6107->guuid=cb3912a6-2b00-0000-80b9-95ffdc170000 pid=6108 execve guuid=299ee6a6-2b00-0000-80b9-95ffdd170000 pid=6109 /usr/lib/systemd/systemd-sysv-install guuid=cb3912a6-2b00-0000-80b9-95ffdc170000 pid=6108->guuid=299ee6a6-2b00-0000-80b9-95ffdd170000 pid=6109 execve guuid=f229aaa7-2b00-0000-80b9-95ffde170000 pid=6110 /usr/bin/getopt guuid=299ee6a6-2b00-0000-80b9-95ffdd170000 pid=6109->guuid=f229aaa7-2b00-0000-80b9-95ffde170000 pid=6110 execve guuid=ad9feea7-2b00-0000-80b9-95ffdf170000 pid=6111 /usr/sbin/update-rc.d guuid=299ee6a6-2b00-0000-80b9-95ffdd170000 pid=6109->guuid=ad9feea7-2b00-0000-80b9-95ffdf170000 pid=6111 execve guuid=8bd2f7aa-2b00-0000-80b9-95fff1170000 pid=6129 /usr/bin/systemctl guuid=ad9feea7-2b00-0000-80b9-95ffdf170000 pid=6111->guuid=8bd2f7aa-2b00-0000-80b9-95fff1170000 pid=6129 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Drops files in suspicious directories
Executes the "crontab" command typically for achieving persistence
Malicious sample detected (through community Yara rule)
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Protects files from modification
Sample deletes itself
Sample is packed with UPX
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Sample tries to set files in /etc globally writable
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1844108 Sample: px86.elf Startdate: 03/01/2026 Architecture: LINUX Score: 100 153 158.94.208.27, 18129, 46088 JANETJiscServicesLimitedGB United Kingdom 2->153 161 Malicious sample detected (through community Yara rule) 2->161 163 Multi AV Scanner detection for submitted file 2->163 165 Yara detected Mirai 2->165 167 Sample is packed with UPX 2->167 13 px86.elf 2->13         started        16 systemd snap-failure 2->16         started        18 systemd snapd-env-generator 2->18         started        20 51 other processes 2->20 signatures3 process4 signatures5 179 Sample deletes itself 13->179 22 px86.elf 13->22         started        25 px86.elf sh 13->25         started        27 snap-failure systemctl 16->27         started        29 snap-failure 16->29         started        process6 signatures7 169 Drops files in suspicious directories 22->169 31 px86.elf 22->31         started        35 px86.elf 22->35         started        37 px86.elf 22->37         started        39 12 other processes 22->39 process8 file9 147 /etc/init.d/cloud-metrics, POSIX 31->147 dropped 155 Drops files in suspicious directories 31->155 41 px86.elf sh 31->41         started        51 9 other processes 31->51 43 px86.elf sh 35->43         started        53 9 other processes 35->53 45 px86.elf sh 37->45         started        55 9 other processes 37->55 149 /root/.bashrc, ASCII 39->149 dropped 151 /etc/profile, ASCII 39->151 dropped 157 Sample tries to persist itself using /etc/profile 39->157 159 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 39->159 47 px86.elf sh 39->47         started        49 px86.elf sh 39->49         started        57 29 other processes 39->57 signatures10 process11 file12 61 2 other processes 41->61 65 2 other processes 43->65 67 2 other processes 45->67 69 2 other processes 47->69 71 2 other processes 49->71 73 9 other processes 51->73 75 9 other processes 53->75 77 9 other processes 55->77 135 /var/spool/cron/crontabs/tmp.ZdzoBD, ASCII 57->135 dropped 171 Sample tries to set files in /etc globally writable 57->171 173 Protects files from modification 57->173 175 Sample tries to persist itself using cron 57->175 177 2 other signatures 57->177 79 19 other processes 57->79 signatures13 process14 file15 137 /var/spool/cron/crontabs/tmp.RJrJV5, ASCII 61->137 dropped 139 /var/spool/cron/crontabs/tmp.xUbvDg, ASCII 65->139 dropped 141 /var/spool/cron/crontabs/tmp.bx34nL, ASCII 67->141 dropped 143 /var/spool/cron/crontabs/tmp.5aA1Gw, ASCII 69->143 dropped 145 /var/spool/cron/crontabs/tmp.X6T6YT, ASCII 71->145 dropped 181 Sample tries to persist itself using cron 71->181 183 Executes the "crontab" command typically for achieving persistence 71->183 81 systemctl systemd-sysv-install 73->81         started        83 update-rc.d systemctl 73->83         started        85 systemctl systemd-sysv-install 75->85         started        87 update-rc.d systemctl 75->87         started        89 systemctl systemd-sysv-install 77->89         started        91 update-rc.d systemctl 77->91         started        185 Sample tries to set files in /etc globally writable 79->185 187 Protects files from modification 79->187 93 systemctl systemd-sysv-install 79->93         started        95 systemctl systemd-sysv-install 79->95         started        97 2 other processes 79->97 signatures16 process17 process18 109 3 other processes 81->109 99 systemd-sysv-install update-rc.d 85->99         started        101 systemd-sysv-install update-rc.d 85->101         started        103 systemd-sysv-install getopt 85->103         started        105 systemd-sysv-install update-rc.d 89->105         started        111 2 other processes 89->111 107 systemd-sysv-install update-rc.d 93->107         started        113 2 other processes 93->113 115 3 other processes 95->115 process19 117 update-rc.d systemctl 99->117         started        119 update-rc.d systemctl 101->119         started        121 update-rc.d systemctl 105->121         started        123 update-rc.d systemctl 107->123         started        125 update-rc.d systemctl 109->125         started        127 update-rc.d systemctl 109->127         started        129 update-rc.d systemctl 111->129         started        131 update-rc.d systemctl 113->131         started        133 2 other processes 115->133
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2026-01-03 12:33:18 UTC
File Type:
ELF32 Little (Exe)
AV detection:
19 of 38 (50.00%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Reads runtime system information
Changes its process name
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Modifies systemd
File and Directory Permissions Modification
Deletes itself
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:upx_packed_elf_v1
Author:RandomMalware

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 81aa3a1cec78008abbe0506a44c20fc80efe006f5c4d84fdec6c8ed9d84521d6

(this sample)

  
Delivery method
Distributed via web download

Comments