MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 837cf0cbfead5b2a27946fec4d8ac1435811948eded06cf6e9c47199e0f089ca. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 13


Intelligence 13 IOCs YARA 30 File information Comments

SHA256 hash: 837cf0cbfead5b2a27946fec4d8ac1435811948eded06cf6e9c47199e0f089ca
SHA3-384 hash: fd6a0bd31ed2a9f8f79de6d7ad70ab936472e523bf835997e0f22f1f5a6ee198dd9ed849d3147d87a52532819b64b5d5
SHA1 hash: 68e8cedd3373db55ad8f4ab3777d45e489850efa
MD5 hash: 237e77d0c05cf9c6520ceace58eebc17
humanhash: undress-lake-sink-music
File name:ssh
Download: download sample
Signature Mirai
File size:154'205 bytes
First seen:2025-07-11 23:05:51 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:8QtM6BgpO9RofRxL5qwGm01EUMAG8nHOD1lHCsy2Q6mmFA8hNhDlLgNU:wVkfmEJMzRDrdmmFA8hNhDlLgNU
TLSH T16AE3CA2AF1428777D193427022DDEE626C316EE4379AB01B33B07AB46DB74872D15E8D
telfhash t1f0315611943546142fb39928acbd56b315221b2323586f716f25c5cc49260e1e93dd0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
19
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Sends data to a server
Creating a file
Sets a written file as executable
Launching a process
Deleting a recently created file
Connection attempt
Kills processes
DNS request
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc lolbin obfuscated remote
Verdict:
Malicious
Uses P2P?:
false
Uses anti-vm?:
false
Architecture:
x86
Packer:
not packed
Botnet:
unknown
Number of open files:
58
Number of processes launched:
9
Processes remaning?
true
Remote TCP ports scanned:
not identified
Behaviour
Process Renaming
Botnet C2s
TCP botnet C2(s):
not identified
UDP botnet C2(s):
not identified
Status:
terminated
Behavior Graph:
%3 guuid=22dff81c-2100-0000-38a8-f4e1f0070000 pid=2032 /usr/bin/sudo guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039 /tmp/sample.bin net guuid=22dff81c-2100-0000-38a8-f4e1f0070000 pid=2032->guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041 /tmp/sample.bin zombie guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039->guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041 clone guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042 /usr/bin/dash zombie guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039->guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042 execve guuid=ba22bd1f-2100-0000-38a8-f4e1fb070000 pid=2043 /tmp/sample.bin zombie guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039->guuid=ba22bd1f-2100-0000-38a8-f4e1fb070000 pid=2043 clone guuid=e33cc61f-2100-0000-38a8-f4e1fc070000 pid=2044 /tmp/sample.bin guuid=453b581f-2100-0000-38a8-f4e1f7070000 pid=2039->guuid=e33cc61f-2100-0000-38a8-f4e1fc070000 pid=2044 clone guuid=fe944a4f-2100-0000-38a8-f4e16d080000 pid=2157 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=fe944a4f-2100-0000-38a8-f4e16d080000 pid=2157 execve guuid=996f6b52-2100-0000-38a8-f4e17a080000 pid=2170 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=996f6b52-2100-0000-38a8-f4e17a080000 pid=2170 execve guuid=c7b1b053-2100-0000-38a8-f4e181080000 pid=2177 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c7b1b053-2100-0000-38a8-f4e181080000 pid=2177 execve guuid=2b1b9a54-2100-0000-38a8-f4e186080000 pid=2182 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=2b1b9a54-2100-0000-38a8-f4e186080000 pid=2182 execve guuid=11b1ac55-2100-0000-38a8-f4e18c080000 pid=2188 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=11b1ac55-2100-0000-38a8-f4e18c080000 pid=2188 execve guuid=9b74b556-2100-0000-38a8-f4e191080000 pid=2193 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9b74b556-2100-0000-38a8-f4e191080000 pid=2193 execve guuid=b021b457-2100-0000-38a8-f4e196080000 pid=2198 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=b021b457-2100-0000-38a8-f4e196080000 pid=2198 execve guuid=66ac1d59-2100-0000-38a8-f4e19d080000 pid=2205 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=66ac1d59-2100-0000-38a8-f4e19d080000 pid=2205 execve guuid=91461e5a-2100-0000-38a8-f4e1a2080000 pid=2210 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=91461e5a-2100-0000-38a8-f4e1a2080000 pid=2210 execve guuid=1ecad485-2200-0000-38a8-f4e1a90b0000 pid=2985 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=1ecad485-2200-0000-38a8-f4e1a90b0000 pid=2985 execve guuid=3431b589-2200-0000-38a8-f4e1b20b0000 pid=2994 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=3431b589-2200-0000-38a8-f4e1b20b0000 pid=2994 execve guuid=260e018b-2200-0000-38a8-f4e1b50b0000 pid=2997 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=260e018b-2200-0000-38a8-f4e1b50b0000 pid=2997 execve guuid=1398ba8c-2200-0000-38a8-f4e1bc0b0000 pid=3004 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=1398ba8c-2200-0000-38a8-f4e1bc0b0000 pid=3004 execve guuid=01b99f8d-2200-0000-38a8-f4e1c00b0000 pid=3008 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=01b99f8d-2200-0000-38a8-f4e1c00b0000 pid=3008 execve guuid=d0b1758e-2200-0000-38a8-f4e1c40b0000 pid=3012 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d0b1758e-2200-0000-38a8-f4e1c40b0000 pid=3012 execve guuid=88c6608f-2200-0000-38a8-f4e1c90b0000 pid=3017 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=88c6608f-2200-0000-38a8-f4e1c90b0000 pid=3017 execve guuid=9a2c8b90-2200-0000-38a8-f4e1ce0b0000 pid=3022 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9a2c8b90-2200-0000-38a8-f4e1ce0b0000 pid=3022 execve guuid=c8147691-2200-0000-38a8-f4e1d10b0000 pid=3025 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c8147691-2200-0000-38a8-f4e1d10b0000 pid=3025 execve guuid=fb51b0cd-2300-0000-38a8-f4e1980e0000 pid=3736 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=fb51b0cd-2300-0000-38a8-f4e1980e0000 pid=3736 execve guuid=a48066d3-2300-0000-38a8-f4e1a90e0000 pid=3753 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=a48066d3-2300-0000-38a8-f4e1a90e0000 pid=3753 execve guuid=5e7e7dd5-2300-0000-38a8-f4e1b20e0000 pid=3762 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=5e7e7dd5-2300-0000-38a8-f4e1b20e0000 pid=3762 execve guuid=3ed2acd6-2300-0000-38a8-f4e1bb0e0000 pid=3771 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=3ed2acd6-2300-0000-38a8-f4e1bb0e0000 pid=3771 execve guuid=fd76b6d7-2300-0000-38a8-f4e1c20e0000 pid=3778 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=fd76b6d7-2300-0000-38a8-f4e1c20e0000 pid=3778 execve guuid=0008eed8-2300-0000-38a8-f4e1cc0e0000 pid=3788 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=0008eed8-2300-0000-38a8-f4e1cc0e0000 pid=3788 execve guuid=b9fdfbd9-2300-0000-38a8-f4e1d10e0000 pid=3793 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=b9fdfbd9-2300-0000-38a8-f4e1d10e0000 pid=3793 execve guuid=d69de5da-2300-0000-38a8-f4e1d70e0000 pid=3799 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d69de5da-2300-0000-38a8-f4e1d70e0000 pid=3799 execve guuid=15081cdc-2300-0000-38a8-f4e1db0e0000 pid=3803 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=15081cdc-2300-0000-38a8-f4e1db0e0000 pid=3803 execve guuid=8bb82009-2500-0000-38a8-f4e146120000 pid=4678 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8bb82009-2500-0000-38a8-f4e146120000 pid=4678 execve guuid=cd065d0e-2500-0000-38a8-f4e14f120000 pid=4687 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=cd065d0e-2500-0000-38a8-f4e14f120000 pid=4687 execve guuid=17560f10-2500-0000-38a8-f4e155120000 pid=4693 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=17560f10-2500-0000-38a8-f4e155120000 pid=4693 execve guuid=18088711-2500-0000-38a8-f4e15a120000 pid=4698 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=18088711-2500-0000-38a8-f4e15a120000 pid=4698 execve guuid=5a469612-2500-0000-38a8-f4e15e120000 pid=4702 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=5a469612-2500-0000-38a8-f4e15e120000 pid=4702 execve guuid=9f909413-2500-0000-38a8-f4e162120000 pid=4706 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9f909413-2500-0000-38a8-f4e162120000 pid=4706 execve guuid=98fcb514-2500-0000-38a8-f4e166120000 pid=4710 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=98fcb514-2500-0000-38a8-f4e166120000 pid=4710 execve guuid=c1fcca15-2500-0000-38a8-f4e16b120000 pid=4715 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c1fcca15-2500-0000-38a8-f4e16b120000 pid=4715 execve guuid=f58bc016-2500-0000-38a8-f4e170120000 pid=4720 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=f58bc016-2500-0000-38a8-f4e170120000 pid=4720 execve guuid=e9792154-2600-0000-38a8-f4e1cf140000 pid=5327 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=e9792154-2600-0000-38a8-f4e1cf140000 pid=5327 execve guuid=5c72c257-2600-0000-38a8-f4e1d1140000 pid=5329 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=5c72c257-2600-0000-38a8-f4e1d1140000 pid=5329 execve guuid=f8d91059-2600-0000-38a8-f4e1d3140000 pid=5331 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=f8d91059-2600-0000-38a8-f4e1d3140000 pid=5331 execve guuid=7583a75a-2600-0000-38a8-f4e1d5140000 pid=5333 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=7583a75a-2600-0000-38a8-f4e1d5140000 pid=5333 execve guuid=d583f15b-2600-0000-38a8-f4e1d7140000 pid=5335 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d583f15b-2600-0000-38a8-f4e1d7140000 pid=5335 execve guuid=f6c8675d-2600-0000-38a8-f4e1d9140000 pid=5337 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=f6c8675d-2600-0000-38a8-f4e1d9140000 pid=5337 execve guuid=2e77f65e-2600-0000-38a8-f4e1db140000 pid=5339 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=2e77f65e-2600-0000-38a8-f4e1db140000 pid=5339 execve guuid=a82a3460-2600-0000-38a8-f4e1dd140000 pid=5341 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=a82a3460-2600-0000-38a8-f4e1dd140000 pid=5341 execve guuid=16858361-2600-0000-38a8-f4e1df140000 pid=5343 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=16858361-2600-0000-38a8-f4e1df140000 pid=5343 execve guuid=2537638d-2700-0000-38a8-f4e1e1140000 pid=5345 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=2537638d-2700-0000-38a8-f4e1e1140000 pid=5345 execve guuid=8bcb4090-2700-0000-38a8-f4e1e3140000 pid=5347 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8bcb4090-2700-0000-38a8-f4e1e3140000 pid=5347 execve guuid=78c31d91-2700-0000-38a8-f4e1e5140000 pid=5349 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=78c31d91-2700-0000-38a8-f4e1e5140000 pid=5349 execve guuid=6a86e091-2700-0000-38a8-f4e1e7140000 pid=5351 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=6a86e091-2700-0000-38a8-f4e1e7140000 pid=5351 execve guuid=365fb292-2700-0000-38a8-f4e1e9140000 pid=5353 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=365fb292-2700-0000-38a8-f4e1e9140000 pid=5353 execve guuid=18ae8893-2700-0000-38a8-f4e1eb140000 pid=5355 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=18ae8893-2700-0000-38a8-f4e1eb140000 pid=5355 execve guuid=86345e94-2700-0000-38a8-f4e1ed140000 pid=5357 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=86345e94-2700-0000-38a8-f4e1ed140000 pid=5357 execve guuid=83212195-2700-0000-38a8-f4e1ef140000 pid=5359 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=83212195-2700-0000-38a8-f4e1ef140000 pid=5359 execve guuid=4fa4e995-2700-0000-38a8-f4e1f1140000 pid=5361 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=4fa4e995-2700-0000-38a8-f4e1f1140000 pid=5361 execve guuid=3a8629c1-2800-0000-38a8-f4e1f3140000 pid=5363 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=3a8629c1-2800-0000-38a8-f4e1f3140000 pid=5363 execve guuid=70147ec4-2800-0000-38a8-f4e1f5140000 pid=5365 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=70147ec4-2800-0000-38a8-f4e1f5140000 pid=5365 execve guuid=d5a395c5-2800-0000-38a8-f4e1f7140000 pid=5367 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d5a395c5-2800-0000-38a8-f4e1f7140000 pid=5367 execve guuid=23588fc6-2800-0000-38a8-f4e1f9140000 pid=5369 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=23588fc6-2800-0000-38a8-f4e1f9140000 pid=5369 execve guuid=9c4092c7-2800-0000-38a8-f4e1fb140000 pid=5371 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9c4092c7-2800-0000-38a8-f4e1fb140000 pid=5371 execve guuid=e0d6bfc8-2800-0000-38a8-f4e1fd140000 pid=5373 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=e0d6bfc8-2800-0000-38a8-f4e1fd140000 pid=5373 execve guuid=50dea5c9-2800-0000-38a8-f4e1ff140000 pid=5375 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=50dea5c9-2800-0000-38a8-f4e1ff140000 pid=5375 execve guuid=b8247bca-2800-0000-38a8-f4e101150000 pid=5377 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=b8247bca-2800-0000-38a8-f4e101150000 pid=5377 execve guuid=368e5ecb-2800-0000-38a8-f4e103150000 pid=5379 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=368e5ecb-2800-0000-38a8-f4e103150000 pid=5379 execve guuid=236ecef6-2900-0000-38a8-f4e105150000 pid=5381 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=236ecef6-2900-0000-38a8-f4e105150000 pid=5381 execve guuid=219e73fb-2900-0000-38a8-f4e107150000 pid=5383 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=219e73fb-2900-0000-38a8-f4e107150000 pid=5383 execve guuid=99581ffd-2900-0000-38a8-f4e109150000 pid=5385 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=99581ffd-2900-0000-38a8-f4e109150000 pid=5385 execve guuid=bf259afe-2900-0000-38a8-f4e10b150000 pid=5387 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=bf259afe-2900-0000-38a8-f4e10b150000 pid=5387 execve guuid=1de54400-2a00-0000-38a8-f4e10d150000 pid=5389 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=1de54400-2a00-0000-38a8-f4e10d150000 pid=5389 execve guuid=c668d801-2a00-0000-38a8-f4e10f150000 pid=5391 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c668d801-2a00-0000-38a8-f4e10f150000 pid=5391 execve guuid=40705803-2a00-0000-38a8-f4e111150000 pid=5393 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=40705803-2a00-0000-38a8-f4e111150000 pid=5393 execve guuid=c84df804-2a00-0000-38a8-f4e113150000 pid=5395 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c84df804-2a00-0000-38a8-f4e113150000 pid=5395 execve guuid=6c37ab06-2a00-0000-38a8-f4e115150000 pid=5397 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=6c37ab06-2a00-0000-38a8-f4e115150000 pid=5397 execve guuid=8814a432-2b00-0000-38a8-f4e117150000 pid=5399 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8814a432-2b00-0000-38a8-f4e117150000 pid=5399 execve guuid=0ed12137-2b00-0000-38a8-f4e119150000 pid=5401 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=0ed12137-2b00-0000-38a8-f4e119150000 pid=5401 execve guuid=a169ab38-2b00-0000-38a8-f4e11b150000 pid=5403 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=a169ab38-2b00-0000-38a8-f4e11b150000 pid=5403 execve guuid=08e2033a-2b00-0000-38a8-f4e11d150000 pid=5405 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=08e2033a-2b00-0000-38a8-f4e11d150000 pid=5405 execve guuid=d300d93b-2b00-0000-38a8-f4e11f150000 pid=5407 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d300d93b-2b00-0000-38a8-f4e11f150000 pid=5407 execve guuid=8b0f9f3d-2b00-0000-38a8-f4e121150000 pid=5409 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8b0f9f3d-2b00-0000-38a8-f4e121150000 pid=5409 execve guuid=79bc4b3f-2b00-0000-38a8-f4e123150000 pid=5411 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=79bc4b3f-2b00-0000-38a8-f4e123150000 pid=5411 execve guuid=d05b3141-2b00-0000-38a8-f4e125150000 pid=5413 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d05b3141-2b00-0000-38a8-f4e125150000 pid=5413 execve guuid=8111e042-2b00-0000-38a8-f4e127150000 pid=5415 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8111e042-2b00-0000-38a8-f4e127150000 pid=5415 execve guuid=8a59396f-2c00-0000-38a8-f4e129150000 pid=5417 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8a59396f-2c00-0000-38a8-f4e129150000 pid=5417 execve guuid=99722474-2c00-0000-38a8-f4e12b150000 pid=5419 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=99722474-2c00-0000-38a8-f4e12b150000 pid=5419 execve guuid=00b5cc75-2c00-0000-38a8-f4e12d150000 pid=5421 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=00b5cc75-2c00-0000-38a8-f4e12d150000 pid=5421 execve guuid=faa57e77-2c00-0000-38a8-f4e12f150000 pid=5423 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=faa57e77-2c00-0000-38a8-f4e12f150000 pid=5423 execve guuid=12be2279-2c00-0000-38a8-f4e131150000 pid=5425 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=12be2279-2c00-0000-38a8-f4e131150000 pid=5425 execve guuid=3d5cd27a-2c00-0000-38a8-f4e133150000 pid=5427 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=3d5cd27a-2c00-0000-38a8-f4e133150000 pid=5427 execve guuid=d817777c-2c00-0000-38a8-f4e135150000 pid=5429 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d817777c-2c00-0000-38a8-f4e135150000 pid=5429 execve guuid=546e247e-2c00-0000-38a8-f4e137150000 pid=5431 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=546e247e-2c00-0000-38a8-f4e137150000 pid=5431 execve guuid=24ced87f-2c00-0000-38a8-f4e139150000 pid=5433 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=24ced87f-2c00-0000-38a8-f4e139150000 pid=5433 execve guuid=fe860bac-2d00-0000-38a8-f4e13b150000 pid=5435 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=fe860bac-2d00-0000-38a8-f4e13b150000 pid=5435 execve guuid=9aeec2b0-2d00-0000-38a8-f4e13d150000 pid=5437 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9aeec2b0-2d00-0000-38a8-f4e13d150000 pid=5437 execve guuid=c92ef7b1-2d00-0000-38a8-f4e13f150000 pid=5439 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=c92ef7b1-2d00-0000-38a8-f4e13f150000 pid=5439 execve guuid=9f0432b3-2d00-0000-38a8-f4e141150000 pid=5441 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=9f0432b3-2d00-0000-38a8-f4e141150000 pid=5441 execve guuid=ab51dcb4-2d00-0000-38a8-f4e143150000 pid=5443 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=ab51dcb4-2d00-0000-38a8-f4e143150000 pid=5443 execve guuid=846e77b6-2d00-0000-38a8-f4e145150000 pid=5445 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=846e77b6-2d00-0000-38a8-f4e145150000 pid=5445 execve guuid=4252e0b7-2d00-0000-38a8-f4e147150000 pid=5447 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=4252e0b7-2d00-0000-38a8-f4e147150000 pid=5447 execve guuid=82fb4fb9-2d00-0000-38a8-f4e149150000 pid=5449 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=82fb4fb9-2d00-0000-38a8-f4e149150000 pid=5449 execve guuid=af78bbba-2d00-0000-38a8-f4e14b150000 pid=5451 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=af78bbba-2d00-0000-38a8-f4e14b150000 pid=5451 execve guuid=e84793e6-2e00-0000-38a8-f4e14d150000 pid=5453 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=e84793e6-2e00-0000-38a8-f4e14d150000 pid=5453 execve guuid=d58523eb-2e00-0000-38a8-f4e14f150000 pid=5455 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=d58523eb-2e00-0000-38a8-f4e14f150000 pid=5455 execve guuid=1e98b7ec-2e00-0000-38a8-f4e151150000 pid=5457 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=1e98b7ec-2e00-0000-38a8-f4e151150000 pid=5457 execve guuid=fabe5eee-2e00-0000-38a8-f4e153150000 pid=5459 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=fabe5eee-2e00-0000-38a8-f4e153150000 pid=5459 execve guuid=89d6f0ef-2e00-0000-38a8-f4e155150000 pid=5461 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=89d6f0ef-2e00-0000-38a8-f4e155150000 pid=5461 execve guuid=8836b7f1-2e00-0000-38a8-f4e157150000 pid=5463 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=8836b7f1-2e00-0000-38a8-f4e157150000 pid=5463 execve guuid=af8271f3-2e00-0000-38a8-f4e159150000 pid=5465 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=af8271f3-2e00-0000-38a8-f4e159150000 pid=5465 execve guuid=92cf01f5-2e00-0000-38a8-f4e15b150000 pid=5467 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=92cf01f5-2e00-0000-38a8-f4e15b150000 pid=5467 execve guuid=1cf084f6-2e00-0000-38a8-f4e15d150000 pid=5469 /usr/bin/dash guuid=b06faf1f-2100-0000-38a8-f4e1f9070000 pid=2041->guuid=1cf084f6-2e00-0000-38a8-f4e15d150000 pid=5469 execve guuid=c7923a20-2100-0000-38a8-f4e1ff070000 pid=2047 /usr/bin/wget dns net send-data guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042->guuid=c7923a20-2100-0000-38a8-f4e1ff070000 pid=2047 execve guuid=83bf2826-2100-0000-38a8-f4e10b080000 pid=2059 /usr/bin/chmod guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042->guuid=83bf2826-2100-0000-38a8-f4e10b080000 pid=2059 execve guuid=99eb8b26-2100-0000-38a8-f4e10c080000 pid=2060 /home/sandbox/..... guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042->guuid=99eb8b26-2100-0000-38a8-f4e10c080000 pid=2060 execve guuid=5f0ba528-2100-0000-38a8-f4e112080000 pid=2066 /usr/bin/rm delete-file guuid=778eb21f-2100-0000-38a8-f4e1fa070000 pid=2042->guuid=5f0ba528-2100-0000-38a8-f4e112080000 pid=2066 execve guuid=835ed11f-2100-0000-38a8-f4e1fd070000 pid=2045 /tmp/sample.bin net send-data zombie guuid=e33cc61f-2100-0000-38a8-f4e1fc070000 pid=2044->guuid=835ed11f-2100-0000-38a8-f4e1fd070000 pid=2045 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=835ed11f-2100-0000-38a8-f4e1fd070000 pid=2045->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 9B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=c7923a20-2100-0000-38a8-f4e1ff070000 pid=2047->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=1e02764f-2100-0000-38a8-f4e16e080000 pid=2158 /usr/bin/pgrep guuid=fe944a4f-2100-0000-38a8-f4e16d080000 pid=2157->guuid=1e02764f-2100-0000-38a8-f4e16e080000 pid=2158 execve guuid=39999752-2100-0000-38a8-f4e17c080000 pid=2172 /usr/bin/killall guuid=996f6b52-2100-0000-38a8-f4e17a080000 pid=2170->guuid=39999752-2100-0000-38a8-f4e17c080000 pid=2172 execve guuid=3125dd53-2100-0000-38a8-f4e182080000 pid=2178 /usr/bin/killall guuid=c7b1b053-2100-0000-38a8-f4e181080000 pid=2177->guuid=3125dd53-2100-0000-38a8-f4e182080000 pid=2178 execve guuid=ea7bc154-2100-0000-38a8-f4e188080000 pid=2184 /usr/bin/killall guuid=2b1b9a54-2100-0000-38a8-f4e186080000 pid=2182->guuid=ea7bc154-2100-0000-38a8-f4e188080000 pid=2184 execve guuid=c40ddf55-2100-0000-38a8-f4e18e080000 pid=2190 /usr/bin/killall guuid=11b1ac55-2100-0000-38a8-f4e18c080000 pid=2188->guuid=c40ddf55-2100-0000-38a8-f4e18e080000 pid=2190 execve guuid=1697f856-2100-0000-38a8-f4e193080000 pid=2195 /usr/bin/killall guuid=9b74b556-2100-0000-38a8-f4e191080000 pid=2193->guuid=1697f856-2100-0000-38a8-f4e193080000 pid=2195 execve guuid=ff6bd757-2100-0000-38a8-f4e198080000 pid=2200 /usr/bin/killall guuid=b021b457-2100-0000-38a8-f4e196080000 pid=2198->guuid=ff6bd757-2100-0000-38a8-f4e198080000 pid=2200 execve guuid=a2e94759-2100-0000-38a8-f4e19f080000 pid=2207 /usr/bin/killall guuid=66ac1d59-2100-0000-38a8-f4e19d080000 pid=2205->guuid=a2e94759-2100-0000-38a8-f4e19f080000 pid=2207 execve guuid=d3994d5a-2100-0000-38a8-f4e1a4080000 pid=2212 /usr/bin/killall guuid=91461e5a-2100-0000-38a8-f4e1a2080000 pid=2210->guuid=d3994d5a-2100-0000-38a8-f4e1a4080000 pid=2212 execve guuid=4a042186-2200-0000-38a8-f4e1aa0b0000 pid=2986 /usr/bin/pgrep guuid=1ecad485-2200-0000-38a8-f4e1a90b0000 pid=2985->guuid=4a042186-2200-0000-38a8-f4e1aa0b0000 pid=2986 execve guuid=cff3e889-2200-0000-38a8-f4e1b30b0000 pid=2995 /usr/bin/killall guuid=3431b589-2200-0000-38a8-f4e1b20b0000 pid=2994->guuid=cff3e889-2200-0000-38a8-f4e1b30b0000 pid=2995 execve guuid=01e25f8b-2200-0000-38a8-f4e1b70b0000 pid=2999 /usr/bin/killall guuid=260e018b-2200-0000-38a8-f4e1b50b0000 pid=2997->guuid=01e25f8b-2200-0000-38a8-f4e1b70b0000 pid=2999 execve guuid=d989e48c-2200-0000-38a8-f4e1bd0b0000 pid=3005 /usr/bin/killall guuid=1398ba8c-2200-0000-38a8-f4e1bc0b0000 pid=3004->guuid=d989e48c-2200-0000-38a8-f4e1bd0b0000 pid=3005 execve guuid=528ec98d-2200-0000-38a8-f4e1c10b0000 pid=3009 /usr/bin/killall guuid=01b99f8d-2200-0000-38a8-f4e1c00b0000 pid=3008->guuid=528ec98d-2200-0000-38a8-f4e1c10b0000 pid=3009 execve guuid=da5da18e-2200-0000-38a8-f4e1c50b0000 pid=3013 /usr/bin/killall guuid=d0b1758e-2200-0000-38a8-f4e1c40b0000 pid=3012->guuid=da5da18e-2200-0000-38a8-f4e1c50b0000 pid=3013 execve guuid=086fab8f-2200-0000-38a8-f4e1cb0b0000 pid=3019 /usr/bin/killall guuid=88c6608f-2200-0000-38a8-f4e1c90b0000 pid=3017->guuid=086fab8f-2200-0000-38a8-f4e1cb0b0000 pid=3019 execve guuid=095fbe90-2200-0000-38a8-f4e1cf0b0000 pid=3023 /usr/bin/killall guuid=9a2c8b90-2200-0000-38a8-f4e1ce0b0000 pid=3022->guuid=095fbe90-2200-0000-38a8-f4e1cf0b0000 pid=3023 execve guuid=7e4fa291-2200-0000-38a8-f4e1d30b0000 pid=3027 /usr/bin/killall guuid=c8147691-2200-0000-38a8-f4e1d10b0000 pid=3025->guuid=7e4fa291-2200-0000-38a8-f4e1d30b0000 pid=3027 execve guuid=3f1bedcd-2300-0000-38a8-f4e19a0e0000 pid=3738 /usr/bin/pgrep guuid=fb51b0cd-2300-0000-38a8-f4e1980e0000 pid=3736->guuid=3f1bedcd-2300-0000-38a8-f4e19a0e0000 pid=3738 execve guuid=8b6fa5d3-2300-0000-38a8-f4e1aa0e0000 pid=3754 /usr/bin/killall guuid=a48066d3-2300-0000-38a8-f4e1a90e0000 pid=3753->guuid=8b6fa5d3-2300-0000-38a8-f4e1aa0e0000 pid=3754 execve guuid=49dea7d5-2300-0000-38a8-f4e1b40e0000 pid=3764 /usr/bin/killall guuid=5e7e7dd5-2300-0000-38a8-f4e1b20e0000 pid=3762->guuid=49dea7d5-2300-0000-38a8-f4e1b40e0000 pid=3764 execve guuid=988bcfd6-2300-0000-38a8-f4e1bd0e0000 pid=3773 /usr/bin/killall guuid=3ed2acd6-2300-0000-38a8-f4e1bb0e0000 pid=3771->guuid=988bcfd6-2300-0000-38a8-f4e1bd0e0000 pid=3773 execve guuid=fb67ddd7-2300-0000-38a8-f4e1c60e0000 pid=3782 /usr/bin/killall guuid=fd76b6d7-2300-0000-38a8-f4e1c20e0000 pid=3778->guuid=fb67ddd7-2300-0000-38a8-f4e1c60e0000 pid=3782 execve guuid=744319d9-2300-0000-38a8-f4e1cd0e0000 pid=3789 /usr/bin/killall guuid=0008eed8-2300-0000-38a8-f4e1cc0e0000 pid=3788->guuid=744319d9-2300-0000-38a8-f4e1cd0e0000 pid=3789 execve guuid=26ca2dda-2300-0000-38a8-f4e1d30e0000 pid=3795 /usr/bin/killall guuid=b9fdfbd9-2300-0000-38a8-f4e1d10e0000 pid=3793->guuid=26ca2dda-2300-0000-38a8-f4e1d30e0000 pid=3795 execve guuid=e96e0edb-2300-0000-38a8-f4e1d80e0000 pid=3800 /usr/bin/killall guuid=d69de5da-2300-0000-38a8-f4e1d70e0000 pid=3799->guuid=e96e0edb-2300-0000-38a8-f4e1d80e0000 pid=3800 execve guuid=4cbd54dc-2300-0000-38a8-f4e1dc0e0000 pid=3804 /usr/bin/killall guuid=15081cdc-2300-0000-38a8-f4e1db0e0000 pid=3803->guuid=4cbd54dc-2300-0000-38a8-f4e1dc0e0000 pid=3804 execve guuid=83d57609-2500-0000-38a8-f4e147120000 pid=4679 /usr/bin/pgrep guuid=8bb82009-2500-0000-38a8-f4e146120000 pid=4678->guuid=83d57609-2500-0000-38a8-f4e147120000 pid=4679 execve guuid=c049b60e-2500-0000-38a8-f4e151120000 pid=4689 /usr/bin/killall guuid=cd065d0e-2500-0000-38a8-f4e14f120000 pid=4687->guuid=c049b60e-2500-0000-38a8-f4e151120000 pid=4689 execve guuid=99d24210-2500-0000-38a8-f4e157120000 pid=4695 /usr/bin/killall guuid=17560f10-2500-0000-38a8-f4e155120000 pid=4693->guuid=99d24210-2500-0000-38a8-f4e157120000 pid=4695 execve guuid=908eae11-2500-0000-38a8-f4e15c120000 pid=4700 /usr/bin/killall guuid=18088711-2500-0000-38a8-f4e15a120000 pid=4698->guuid=908eae11-2500-0000-38a8-f4e15c120000 pid=4700 execve guuid=78cdc812-2500-0000-38a8-f4e160120000 pid=4704 /usr/bin/killall guuid=5a469612-2500-0000-38a8-f4e15e120000 pid=4702->guuid=78cdc812-2500-0000-38a8-f4e160120000 pid=4704 execve guuid=31bfc013-2500-0000-38a8-f4e163120000 pid=4707 /usr/bin/killall guuid=9f909413-2500-0000-38a8-f4e162120000 pid=4706->guuid=31bfc013-2500-0000-38a8-f4e163120000 pid=4707 execve guuid=5cb40515-2500-0000-38a8-f4e168120000 pid=4712 /usr/bin/killall guuid=98fcb514-2500-0000-38a8-f4e166120000 pid=4710->guuid=5cb40515-2500-0000-38a8-f4e168120000 pid=4712 execve guuid=24bd0a16-2500-0000-38a8-f4e16d120000 pid=4717 /usr/bin/killall guuid=c1fcca15-2500-0000-38a8-f4e16b120000 pid=4715->guuid=24bd0a16-2500-0000-38a8-f4e16d120000 pid=4717 execve guuid=e169e816-2500-0000-38a8-f4e171120000 pid=4721 /usr/bin/killall guuid=f58bc016-2500-0000-38a8-f4e170120000 pid=4720->guuid=e169e816-2500-0000-38a8-f4e171120000 pid=4721 execve guuid=52f06554-2600-0000-38a8-f4e1d0140000 pid=5328 /usr/bin/pgrep guuid=e9792154-2600-0000-38a8-f4e1cf140000 pid=5327->guuid=52f06554-2600-0000-38a8-f4e1d0140000 pid=5328 execve guuid=98d8f357-2600-0000-38a8-f4e1d2140000 pid=5330 /usr/bin/killall guuid=5c72c257-2600-0000-38a8-f4e1d1140000 pid=5329->guuid=98d8f357-2600-0000-38a8-f4e1d2140000 pid=5330 execve guuid=040b8c59-2600-0000-38a8-f4e1d4140000 pid=5332 /usr/bin/killall guuid=f8d91059-2600-0000-38a8-f4e1d3140000 pid=5331->guuid=040b8c59-2600-0000-38a8-f4e1d4140000 pid=5332 execve guuid=bbbedb5a-2600-0000-38a8-f4e1d6140000 pid=5334 /usr/bin/killall guuid=7583a75a-2600-0000-38a8-f4e1d5140000 pid=5333->guuid=bbbedb5a-2600-0000-38a8-f4e1d6140000 pid=5334 execve guuid=ebdc445c-2600-0000-38a8-f4e1d8140000 pid=5336 /usr/bin/killall guuid=d583f15b-2600-0000-38a8-f4e1d7140000 pid=5335->guuid=ebdc445c-2600-0000-38a8-f4e1d8140000 pid=5336 execve guuid=39a9ab5d-2600-0000-38a8-f4e1da140000 pid=5338 /usr/bin/killall guuid=f6c8675d-2600-0000-38a8-f4e1d9140000 pid=5337->guuid=39a9ab5d-2600-0000-38a8-f4e1da140000 pid=5338 execve guuid=b43f405f-2600-0000-38a8-f4e1dc140000 pid=5340 /usr/bin/killall guuid=2e77f65e-2600-0000-38a8-f4e1db140000 pid=5339->guuid=b43f405f-2600-0000-38a8-f4e1dc140000 pid=5340 execve guuid=42498d60-2600-0000-38a8-f4e1de140000 pid=5342 /usr/bin/killall guuid=a82a3460-2600-0000-38a8-f4e1dd140000 pid=5341->guuid=42498d60-2600-0000-38a8-f4e1de140000 pid=5342 execve guuid=e70cc661-2600-0000-38a8-f4e1e0140000 pid=5344 /usr/bin/killall guuid=16858361-2600-0000-38a8-f4e1df140000 pid=5343->guuid=e70cc661-2600-0000-38a8-f4e1e0140000 pid=5344 execve guuid=5139978d-2700-0000-38a8-f4e1e2140000 pid=5346 /usr/bin/pgrep guuid=2537638d-2700-0000-38a8-f4e1e1140000 pid=5345->guuid=5139978d-2700-0000-38a8-f4e1e2140000 pid=5346 execve guuid=c9216d90-2700-0000-38a8-f4e1e4140000 pid=5348 /usr/bin/killall guuid=8bcb4090-2700-0000-38a8-f4e1e3140000 pid=5347->guuid=c9216d90-2700-0000-38a8-f4e1e4140000 pid=5348 execve guuid=7f474691-2700-0000-38a8-f4e1e6140000 pid=5350 /usr/bin/killall guuid=78c31d91-2700-0000-38a8-f4e1e5140000 pid=5349->guuid=7f474691-2700-0000-38a8-f4e1e6140000 pid=5350 execve guuid=5dac0a92-2700-0000-38a8-f4e1e8140000 pid=5352 /usr/bin/killall guuid=6a86e091-2700-0000-38a8-f4e1e7140000 pid=5351->guuid=5dac0a92-2700-0000-38a8-f4e1e8140000 pid=5352 execve guuid=9a6cd892-2700-0000-38a8-f4e1ea140000 pid=5354 /usr/bin/killall guuid=365fb292-2700-0000-38a8-f4e1e9140000 pid=5353->guuid=9a6cd892-2700-0000-38a8-f4e1ea140000 pid=5354 execve guuid=772ab193-2700-0000-38a8-f4e1ec140000 pid=5356 /usr/bin/killall guuid=18ae8893-2700-0000-38a8-f4e1eb140000 pid=5355->guuid=772ab193-2700-0000-38a8-f4e1ec140000 pid=5356 execve guuid=a4de8494-2700-0000-38a8-f4e1ee140000 pid=5358 /usr/bin/killall guuid=86345e94-2700-0000-38a8-f4e1ed140000 pid=5357->guuid=a4de8494-2700-0000-38a8-f4e1ee140000 pid=5358 execve guuid=90e64895-2700-0000-38a8-f4e1f0140000 pid=5360 /usr/bin/killall guuid=83212195-2700-0000-38a8-f4e1ef140000 pid=5359->guuid=90e64895-2700-0000-38a8-f4e1f0140000 pid=5360 execve guuid=0ac31896-2700-0000-38a8-f4e1f2140000 pid=5362 /usr/bin/killall guuid=4fa4e995-2700-0000-38a8-f4e1f1140000 pid=5361->guuid=0ac31896-2700-0000-38a8-f4e1f2140000 pid=5362 execve guuid=597677c1-2800-0000-38a8-f4e1f4140000 pid=5364 /usr/bin/pgrep guuid=3a8629c1-2800-0000-38a8-f4e1f3140000 pid=5363->guuid=597677c1-2800-0000-38a8-f4e1f4140000 pid=5364 execve guuid=46e4c4c4-2800-0000-38a8-f4e1f6140000 pid=5366 /usr/bin/killall guuid=70147ec4-2800-0000-38a8-f4e1f5140000 pid=5365->guuid=46e4c4c4-2800-0000-38a8-f4e1f6140000 pid=5366 execve guuid=117ddcc5-2800-0000-38a8-f4e1f8140000 pid=5368 /usr/bin/killall guuid=d5a395c5-2800-0000-38a8-f4e1f7140000 pid=5367->guuid=117ddcc5-2800-0000-38a8-f4e1f8140000 pid=5368 execve guuid=3d15d4c6-2800-0000-38a8-f4e1fa140000 pid=5370 /usr/bin/killall guuid=23588fc6-2800-0000-38a8-f4e1f9140000 pid=5369->guuid=3d15d4c6-2800-0000-38a8-f4e1fa140000 pid=5370 execve guuid=4502dcc7-2800-0000-38a8-f4e1fc140000 pid=5372 /usr/bin/killall guuid=9c4092c7-2800-0000-38a8-f4e1fb140000 pid=5371->guuid=4502dcc7-2800-0000-38a8-f4e1fc140000 pid=5372 execve guuid=d335efc8-2800-0000-38a8-f4e1fe140000 pid=5374 /usr/bin/killall guuid=e0d6bfc8-2800-0000-38a8-f4e1fd140000 pid=5373->guuid=d335efc8-2800-0000-38a8-f4e1fe140000 pid=5374 execve guuid=d177d1c9-2800-0000-38a8-f4e100150000 pid=5376 /usr/bin/killall guuid=50dea5c9-2800-0000-38a8-f4e1ff140000 pid=5375->guuid=d177d1c9-2800-0000-38a8-f4e100150000 pid=5376 execve guuid=c4bcacca-2800-0000-38a8-f4e102150000 pid=5378 /usr/bin/killall guuid=b8247bca-2800-0000-38a8-f4e101150000 pid=5377->guuid=c4bcacca-2800-0000-38a8-f4e102150000 pid=5378 execve guuid=1d3a8dcb-2800-0000-38a8-f4e104150000 pid=5380 /usr/bin/killall guuid=368e5ecb-2800-0000-38a8-f4e103150000 pid=5379->guuid=1d3a8dcb-2800-0000-38a8-f4e104150000 pid=5380 execve guuid=475534f7-2900-0000-38a8-f4e106150000 pid=5382 /usr/bin/pgrep guuid=236ecef6-2900-0000-38a8-f4e105150000 pid=5381->guuid=475534f7-2900-0000-38a8-f4e106150000 pid=5382 execve guuid=4656dcfb-2900-0000-38a8-f4e108150000 pid=5384 /usr/bin/killall guuid=219e73fb-2900-0000-38a8-f4e107150000 pid=5383->guuid=4656dcfb-2900-0000-38a8-f4e108150000 pid=5384 execve guuid=35f476fd-2900-0000-38a8-f4e10a150000 pid=5386 /usr/bin/killall guuid=99581ffd-2900-0000-38a8-f4e109150000 pid=5385->guuid=35f476fd-2900-0000-38a8-f4e10a150000 pid=5386 execve guuid=4171defe-2900-0000-38a8-f4e10c150000 pid=5388 /usr/bin/killall guuid=bf259afe-2900-0000-38a8-f4e10b150000 pid=5387->guuid=4171defe-2900-0000-38a8-f4e10c150000 pid=5388 execve guuid=21939a00-2a00-0000-38a8-f4e10e150000 pid=5390 /usr/bin/killall guuid=1de54400-2a00-0000-38a8-f4e10d150000 pid=5389->guuid=21939a00-2a00-0000-38a8-f4e10e150000 pid=5390 execve guuid=67a23102-2a00-0000-38a8-f4e110150000 pid=5392 /usr/bin/killall guuid=c668d801-2a00-0000-38a8-f4e10f150000 pid=5391->guuid=67a23102-2a00-0000-38a8-f4e110150000 pid=5392 execve guuid=7e8d9f03-2a00-0000-38a8-f4e112150000 pid=5394 /usr/bin/killall guuid=40705803-2a00-0000-38a8-f4e111150000 pid=5393->guuid=7e8d9f03-2a00-0000-38a8-f4e112150000 pid=5394 execve guuid=d9f33905-2a00-0000-38a8-f4e114150000 pid=5396 /usr/bin/killall guuid=c84df804-2a00-0000-38a8-f4e113150000 pid=5395->guuid=d9f33905-2a00-0000-38a8-f4e114150000 pid=5396 execve guuid=11540207-2a00-0000-38a8-f4e116150000 pid=5398 /usr/bin/killall guuid=6c37ab06-2a00-0000-38a8-f4e115150000 pid=5397->guuid=11540207-2a00-0000-38a8-f4e116150000 pid=5398 execve guuid=6546ff32-2b00-0000-38a8-f4e118150000 pid=5400 /usr/bin/pgrep guuid=8814a432-2b00-0000-38a8-f4e117150000 pid=5399->guuid=6546ff32-2b00-0000-38a8-f4e118150000 pid=5400 execve guuid=399e6037-2b00-0000-38a8-f4e11a150000 pid=5402 /usr/bin/killall guuid=0ed12137-2b00-0000-38a8-f4e119150000 pid=5401->guuid=399e6037-2b00-0000-38a8-f4e11a150000 pid=5402 execve guuid=9d540639-2b00-0000-38a8-f4e11c150000 pid=5404 /usr/bin/killall guuid=a169ab38-2b00-0000-38a8-f4e11b150000 pid=5403->guuid=9d540639-2b00-0000-38a8-f4e11c150000 pid=5404 execve guuid=2e7c533a-2b00-0000-38a8-f4e11e150000 pid=5406 /usr/bin/killall guuid=08e2033a-2b00-0000-38a8-f4e11d150000 pid=5405->guuid=2e7c533a-2b00-0000-38a8-f4e11e150000 pid=5406 execve guuid=fa122b3c-2b00-0000-38a8-f4e120150000 pid=5408 /usr/bin/killall guuid=d300d93b-2b00-0000-38a8-f4e11f150000 pid=5407->guuid=fa122b3c-2b00-0000-38a8-f4e120150000 pid=5408 execve guuid=9037ea3d-2b00-0000-38a8-f4e122150000 pid=5410 /usr/bin/killall guuid=8b0f9f3d-2b00-0000-38a8-f4e121150000 pid=5409->guuid=9037ea3d-2b00-0000-38a8-f4e122150000 pid=5410 execve guuid=7a50a43f-2b00-0000-38a8-f4e124150000 pid=5412 /usr/bin/killall guuid=79bc4b3f-2b00-0000-38a8-f4e123150000 pid=5411->guuid=7a50a43f-2b00-0000-38a8-f4e124150000 pid=5412 execve guuid=6eab8741-2b00-0000-38a8-f4e126150000 pid=5414 /usr/bin/killall guuid=d05b3141-2b00-0000-38a8-f4e125150000 pid=5413->guuid=6eab8741-2b00-0000-38a8-f4e126150000 pid=5414 execve guuid=3d453243-2b00-0000-38a8-f4e128150000 pid=5416 /usr/bin/killall guuid=8111e042-2b00-0000-38a8-f4e127150000 pid=5415->guuid=3d453243-2b00-0000-38a8-f4e128150000 pid=5416 execve guuid=dd0f986f-2c00-0000-38a8-f4e12a150000 pid=5418 /usr/bin/pgrep guuid=8a59396f-2c00-0000-38a8-f4e129150000 pid=5417->guuid=dd0f986f-2c00-0000-38a8-f4e12a150000 pid=5418 execve guuid=7cf27f74-2c00-0000-38a8-f4e12c150000 pid=5420 /usr/bin/killall guuid=99722474-2c00-0000-38a8-f4e12b150000 pid=5419->guuid=7cf27f74-2c00-0000-38a8-f4e12c150000 pid=5420 execve guuid=bb002876-2c00-0000-38a8-f4e12e150000 pid=5422 /usr/bin/killall guuid=00b5cc75-2c00-0000-38a8-f4e12d150000 pid=5421->guuid=bb002876-2c00-0000-38a8-f4e12e150000 pid=5422 execve guuid=fe37d777-2c00-0000-38a8-f4e130150000 pid=5424 /usr/bin/killall guuid=faa57e77-2c00-0000-38a8-f4e12f150000 pid=5423->guuid=fe37d777-2c00-0000-38a8-f4e130150000 pid=5424 execve guuid=bd157b79-2c00-0000-38a8-f4e132150000 pid=5426 /usr/bin/killall guuid=12be2279-2c00-0000-38a8-f4e131150000 pid=5425->guuid=bd157b79-2c00-0000-38a8-f4e132150000 pid=5426 execve guuid=1f0b297b-2c00-0000-38a8-f4e134150000 pid=5428 /usr/bin/killall guuid=3d5cd27a-2c00-0000-38a8-f4e133150000 pid=5427->guuid=1f0b297b-2c00-0000-38a8-f4e134150000 pid=5428 execve guuid=679cc47c-2c00-0000-38a8-f4e136150000 pid=5430 /usr/bin/killall guuid=d817777c-2c00-0000-38a8-f4e135150000 pid=5429->guuid=679cc47c-2c00-0000-38a8-f4e136150000 pid=5430 execve guuid=f3a8787e-2c00-0000-38a8-f4e138150000 pid=5432 /usr/bin/killall guuid=546e247e-2c00-0000-38a8-f4e137150000 pid=5431->guuid=f3a8787e-2c00-0000-38a8-f4e138150000 pid=5432 execve guuid=ffbd3080-2c00-0000-38a8-f4e13a150000 pid=5434 /usr/bin/killall guuid=24ced87f-2c00-0000-38a8-f4e139150000 pid=5433->guuid=ffbd3080-2c00-0000-38a8-f4e13a150000 pid=5434 execve guuid=fb6d70ac-2d00-0000-38a8-f4e13c150000 pid=5436 /usr/bin/pgrep guuid=fe860bac-2d00-0000-38a8-f4e13b150000 pid=5435->guuid=fb6d70ac-2d00-0000-38a8-f4e13c150000 pid=5436 execve guuid=aa130db1-2d00-0000-38a8-f4e13e150000 pid=5438 /usr/bin/killall guuid=9aeec2b0-2d00-0000-38a8-f4e13d150000 pid=5437->guuid=aa130db1-2d00-0000-38a8-f4e13e150000 pid=5438 execve guuid=bb3448b2-2d00-0000-38a8-f4e140150000 pid=5440 /usr/bin/killall guuid=c92ef7b1-2d00-0000-38a8-f4e13f150000 pid=5439->guuid=bb3448b2-2d00-0000-38a8-f4e140150000 pid=5440 execve guuid=e41d6fb3-2d00-0000-38a8-f4e142150000 pid=5442 /usr/bin/killall guuid=9f0432b3-2d00-0000-38a8-f4e141150000 pid=5441->guuid=e41d6fb3-2d00-0000-38a8-f4e142150000 pid=5442 execve guuid=7fd630b5-2d00-0000-38a8-f4e144150000 pid=5444 /usr/bin/killall guuid=ab51dcb4-2d00-0000-38a8-f4e143150000 pid=5443->guuid=7fd630b5-2d00-0000-38a8-f4e144150000 pid=5444 execve guuid=9f91c4b6-2d00-0000-38a8-f4e146150000 pid=5446 /usr/bin/killall guuid=846e77b6-2d00-0000-38a8-f4e145150000 pid=5445->guuid=9f91c4b6-2d00-0000-38a8-f4e146150000 pid=5446 execve guuid=560c34b8-2d00-0000-38a8-f4e148150000 pid=5448 /usr/bin/killall guuid=4252e0b7-2d00-0000-38a8-f4e147150000 pid=5447->guuid=560c34b8-2d00-0000-38a8-f4e148150000 pid=5448 execve guuid=5e6b9fb9-2d00-0000-38a8-f4e14a150000 pid=5450 /usr/bin/killall guuid=82fb4fb9-2d00-0000-38a8-f4e149150000 pid=5449->guuid=5e6b9fb9-2d00-0000-38a8-f4e14a150000 pid=5450 execve guuid=5cd008bb-2d00-0000-38a8-f4e14c150000 pid=5452 /usr/bin/killall guuid=af78bbba-2d00-0000-38a8-f4e14b150000 pid=5451->guuid=5cd008bb-2d00-0000-38a8-f4e14c150000 pid=5452 execve guuid=6e60eee6-2e00-0000-38a8-f4e14e150000 pid=5454 /usr/bin/pgrep guuid=e84793e6-2e00-0000-38a8-f4e14d150000 pid=5453->guuid=6e60eee6-2e00-0000-38a8-f4e14e150000 pid=5454 execve guuid=7e146aeb-2e00-0000-38a8-f4e150150000 pid=5456 /usr/bin/killall guuid=d58523eb-2e00-0000-38a8-f4e14f150000 pid=5455->guuid=7e146aeb-2e00-0000-38a8-f4e150150000 pid=5456 execve guuid=204810ed-2e00-0000-38a8-f4e152150000 pid=5458 /usr/bin/killall guuid=1e98b7ec-2e00-0000-38a8-f4e151150000 pid=5457->guuid=204810ed-2e00-0000-38a8-f4e152150000 pid=5458 execve guuid=a7a3b1ee-2e00-0000-38a8-f4e154150000 pid=5460 /usr/bin/killall guuid=fabe5eee-2e00-0000-38a8-f4e153150000 pid=5459->guuid=a7a3b1ee-2e00-0000-38a8-f4e154150000 pid=5460 execve guuid=959033f0-2e00-0000-38a8-f4e156150000 pid=5462 /usr/bin/killall guuid=89d6f0ef-2e00-0000-38a8-f4e155150000 pid=5461->guuid=959033f0-2e00-0000-38a8-f4e156150000 pid=5462 execve guuid=3b2215f2-2e00-0000-38a8-f4e158150000 pid=5464 /usr/bin/killall guuid=8836b7f1-2e00-0000-38a8-f4e157150000 pid=5463->guuid=3b2215f2-2e00-0000-38a8-f4e158150000 pid=5464 execve guuid=1af4c3f3-2e00-0000-38a8-f4e15a150000 pid=5466 /usr/bin/killall guuid=af8271f3-2e00-0000-38a8-f4e159150000 pid=5465->guuid=1af4c3f3-2e00-0000-38a8-f4e15a150000 pid=5466 execve guuid=add556f5-2e00-0000-38a8-f4e15c150000 pid=5468 /usr/bin/killall guuid=92cf01f5-2e00-0000-38a8-f4e15b150000 pid=5467->guuid=add556f5-2e00-0000-38a8-f4e15c150000 pid=5468 execve guuid=577dcdf6-2e00-0000-38a8-f4e15e150000 pid=5470 /usr/bin/killall guuid=1cf084f6-2e00-0000-38a8-f4e15d150000 pid=5469->guuid=577dcdf6-2e00-0000-38a8-f4e15e150000 pid=5470 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734326 Sample: ssh.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 37 206.123.128.67, 51842, 65481 LEASEWEB-USA-NYC-11US United States 2->37 39 109.202.202.202, 80 INIT7CH Switzerland 2->39 41 2 other IPs or domains 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 ssh.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 ssh.elf 9->12         started        process6 process7 14 ssh.elf sh 12->14         started        16 ssh.elf sh 12->16         started        18 ssh.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-11 23:06:15 UTC
File Type:
ELF64 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_a6a2adb9 Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_f3d83a74 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_e0673a90 Linux_Trojan_Gafgyt_a0a4de11 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_09c3070e Linux_Trojan_Gafgyt_46eec778 Linux_Trojan_Gafgyt_d996d335 Linux_Trojan_Gafgyt_d0c57a2e Linux_Trojan_Gafgyt_656bf077 Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_dd0d6173 Linux_Trojan_Gafgyt_779e142f Linux_Trojan_Gafgyt_cf84c9f2 Linux_Trojan_Gafgyt_0cd591cd Linux_Trojan_Gafgyt_33b4111a Linux_Trojan_Gafgyt_862c4e0e Linux_Trojan_Gafgyt_32eb0c81 Linux_Trojan_Gafgyt_a33a8363 Linux_Trojan_Mirai_3fe3c668 Linux_Trojan_Mirai_637f2c04 elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_46eec778
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_862c4e0e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_3fe3c668
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_637f2c04
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 837cf0cbfead5b2a27946fec4d8ac1435811948eded06cf6e9c47199e0f089ca

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments