MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8b944f00ebb2e5f2c8fd8257724808980d2ace4353a4a76b7da6ae7e90ee6dac. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 12


Intelligence 12 IOCs YARA 13 File information Comments

SHA256 hash: 8b944f00ebb2e5f2c8fd8257724808980d2ace4353a4a76b7da6ae7e90ee6dac
SHA3-384 hash: fc1881e955c447851438eedd7b709a62e09e4bf1cfc3d83749a5ec0081d167cd29a9a17eac7303798c29d800b9496a63
SHA1 hash: 028f62c240b835f11c42d9354234aaa34aa14f02
MD5 hash: 9363a4175657e9c2249494432a0d9bfc
humanhash: california-florida-monkey-purple
File name:x86
Download: download sample
Signature Mirai
File size:95'368 bytes
First seen:2025-12-17 18:24:17 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 1536:BjCDWXjbDcRTp/swfQVy0QggkmUCdhGAYe8Tl+7bO3ibAMLE1rLo/ongWsmrVq6e:B+DWXj0ZNswfsy5ggkmUghGi2lSAMQvs
TLSH T1B3938EC0EA43D8F5EC1605747137F7338A76E93E112ADE87CB985E329966A01C92736C
telfhash t14731e5f956ab1ce95bd0a442a24e5f31ec0d6a7b046076a102f3e835321b942527ac3d
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
Malware configuration found for:
Mirai
Details
Mirai
an XOR decryption key and at least a c2 socket address
Result
Verdict:
Malware
Maliciousness:

Behaviour
Connection attempt
Kills processes
Launching a process
Creating a file in the %temp% directory
Manages services
Creating a file
Runs as daemon
Sets a written file as executable
Opens a port
DNS request
Creates or modifies files in /cron to set up autorun
Substitutes an application name
Writes files to system directory
Creates or modifies files in /init.d to set up autorun
Creates or modifies files to set up autorun
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
opendir
Verdict:
Malicious
File Type:
elf.32.le
First seen:
2025-12-17T16:15:00Z UTC
Last seen:
2025-12-19T05:58:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=7805c1fd-1a00-0000-0bbd-68f01f0c0000 pid=3103 /usr/bin/sudo guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109 /tmp/sample.bin dns net send-data write-config write-file guuid=7805c1fd-1a00-0000-0bbd-68f01f0c0000 pid=3103->guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B guuid=42470604-1b00-0000-0bbd-68f0330c0000 pid=3123 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=42470604-1b00-0000-0bbd-68f0330c0000 pid=3123 execve guuid=6a86a804-1b00-0000-0bbd-68f0370c0000 pid=3127 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=6a86a804-1b00-0000-0bbd-68f0370c0000 pid=3127 execve guuid=a4858f43-1b00-0000-0bbd-68f0a30c0000 pid=3235 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=a4858f43-1b00-0000-0bbd-68f0a30c0000 pid=3235 execve guuid=b49ca149-1b00-0000-0bbd-68f0a60c0000 pid=3238 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=b49ca149-1b00-0000-0bbd-68f0a60c0000 pid=3238 execve guuid=c543a74a-1b00-0000-0bbd-68f0a80c0000 pid=3240 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=c543a74a-1b00-0000-0bbd-68f0a80c0000 pid=3240 execve guuid=7646b84b-1b00-0000-0bbd-68f0aa0c0000 pid=3242 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=7646b84b-1b00-0000-0bbd-68f0aa0c0000 pid=3242 execve guuid=6a24a44c-1b00-0000-0bbd-68f0ac0c0000 pid=3244 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=6a24a44c-1b00-0000-0bbd-68f0ac0c0000 pid=3244 execve guuid=97d1c34d-1b00-0000-0bbd-68f0ae0c0000 pid=3246 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=97d1c34d-1b00-0000-0bbd-68f0ae0c0000 pid=3246 execve guuid=a28f8d4e-1b00-0000-0bbd-68f0b00c0000 pid=3248 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=a28f8d4e-1b00-0000-0bbd-68f0b00c0000 pid=3248 execve guuid=c57b5c4f-1b00-0000-0bbd-68f0b40c0000 pid=3252 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=c57b5c4f-1b00-0000-0bbd-68f0b40c0000 pid=3252 execve guuid=2a7f2850-1b00-0000-0bbd-68f0b80c0000 pid=3256 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=2a7f2850-1b00-0000-0bbd-68f0b80c0000 pid=3256 execve guuid=53ab1a51-1b00-0000-0bbd-68f0bc0c0000 pid=3260 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=53ab1a51-1b00-0000-0bbd-68f0bc0c0000 pid=3260 execve guuid=58a13652-1b00-0000-0bbd-68f0bf0c0000 pid=3263 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=58a13652-1b00-0000-0bbd-68f0bf0c0000 pid=3263 execve guuid=442d5553-1b00-0000-0bbd-68f0c40c0000 pid=3268 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=442d5553-1b00-0000-0bbd-68f0c40c0000 pid=3268 execve guuid=d32bfa53-1b00-0000-0bbd-68f0c70c0000 pid=3271 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=d32bfa53-1b00-0000-0bbd-68f0c70c0000 pid=3271 execve guuid=e9371155-1b00-0000-0bbd-68f0cd0c0000 pid=3277 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=e9371155-1b00-0000-0bbd-68f0cd0c0000 pid=3277 execve guuid=5776b055-1b00-0000-0bbd-68f0d00c0000 pid=3280 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=5776b055-1b00-0000-0bbd-68f0d00c0000 pid=3280 execve guuid=0cfac356-1b00-0000-0bbd-68f0d30c0000 pid=3283 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=0cfac356-1b00-0000-0bbd-68f0d30c0000 pid=3283 execve guuid=73d35357-1b00-0000-0bbd-68f0d70c0000 pid=3287 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=73d35357-1b00-0000-0bbd-68f0d70c0000 pid=3287 execve guuid=4ef44658-1b00-0000-0bbd-68f0dd0c0000 pid=3293 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=4ef44658-1b00-0000-0bbd-68f0dd0c0000 pid=3293 execve guuid=5860c858-1b00-0000-0bbd-68f0e10c0000 pid=3297 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=5860c858-1b00-0000-0bbd-68f0e10c0000 pid=3297 execve guuid=ce95c559-1b00-0000-0bbd-68f0e40c0000 pid=3300 /usr/bin/dash guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=ce95c559-1b00-0000-0bbd-68f0e40c0000 pid=3300 execve guuid=cf6f8b5a-1b00-0000-0bbd-68f0e60c0000 pid=3302 /tmp/sample.bin dns net send-data zombie guuid=a4a19eff-1a00-0000-0bbd-68f0250c0000 pid=3109->guuid=cf6f8b5a-1b00-0000-0bbd-68f0e60c0000 pid=3302 clone guuid=3a813804-1b00-0000-0bbd-68f0350c0000 pid=3125 /usr/bin/grep guuid=42470604-1b00-0000-0bbd-68f0330c0000 pid=3123->guuid=3a813804-1b00-0000-0bbd-68f0350c0000 pid=3125 execve guuid=e2d9d904-1b00-0000-0bbd-68f0380c0000 pid=3128 /usr/bin/systemctl guuid=6a86a804-1b00-0000-0bbd-68f0370c0000 pid=3127->guuid=e2d9d904-1b00-0000-0bbd-68f0380c0000 pid=3128 execve guuid=7edde043-1b00-0000-0bbd-68f0a40c0000 pid=3236 /usr/bin/systemctl guuid=a4858f43-1b00-0000-0bbd-68f0a30c0000 pid=3235->guuid=7edde043-1b00-0000-0bbd-68f0a40c0000 pid=3236 execve guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1 /usr/lib/systemd/systemd guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237 /tmp/sample.bin dns net send-data write-config write-file guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1->guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237 execve guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361 /tmp/sample.bin dns net send-data write-config write-file guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1->guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361 execve guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444 /tmp/sample.bin dns net send-data write-config write-file guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1->guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444 execve guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490 /tmp/sample.bin dns net send-data write-config write-file guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1->guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490 execve guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536 /tmp/sample.bin dns net send-data write-config write-file guuid=2fdaba13-0000-0000-0bbd-68f001000000 pid=1->guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536 execve guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B b5c8e465-9e6f-50a0-a577-9d1ee496ad49 0.0.0.0:24233 guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->b5c8e465-9e6f-50a0-a577-9d1ee496ad49 con guuid=31ffbc75-1c00-0000-0bbd-68f0690f0000 pid=3945 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=31ffbc75-1c00-0000-0bbd-68f0690f0000 pid=3945 execve guuid=a4fa7876-1c00-0000-0bbd-68f06d0f0000 pid=3949 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=a4fa7876-1c00-0000-0bbd-68f06d0f0000 pid=3949 execve guuid=d02f6fa7-1c00-0000-0bbd-68f01d100000 pid=4125 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=d02f6fa7-1c00-0000-0bbd-68f01d100000 pid=4125 execve guuid=3c6332a9-1c00-0000-0bbd-68f025100000 pid=4133 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=3c6332a9-1c00-0000-0bbd-68f025100000 pid=4133 execve guuid=99ebcba9-1c00-0000-0bbd-68f029100000 pid=4137 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=99ebcba9-1c00-0000-0bbd-68f029100000 pid=4137 execve guuid=32d768aa-1c00-0000-0bbd-68f02e100000 pid=4142 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=32d768aa-1c00-0000-0bbd-68f02e100000 pid=4142 execve guuid=6114eaaa-1c00-0000-0bbd-68f030100000 pid=4144 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=6114eaaa-1c00-0000-0bbd-68f030100000 pid=4144 execve guuid=86de89ab-1c00-0000-0bbd-68f036100000 pid=4150 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=86de89ab-1c00-0000-0bbd-68f036100000 pid=4150 execve guuid=aeef2dac-1c00-0000-0bbd-68f03a100000 pid=4154 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=aeef2dac-1c00-0000-0bbd-68f03a100000 pid=4154 execve guuid=5c9cbdac-1c00-0000-0bbd-68f041100000 pid=4161 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=5c9cbdac-1c00-0000-0bbd-68f041100000 pid=4161 execve guuid=c9a33dad-1c00-0000-0bbd-68f045100000 pid=4165 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=c9a33dad-1c00-0000-0bbd-68f045100000 pid=4165 execve guuid=999ac6ad-1c00-0000-0bbd-68f049100000 pid=4169 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=999ac6ad-1c00-0000-0bbd-68f049100000 pid=4169 execve guuid=fed24dae-1c00-0000-0bbd-68f04c100000 pid=4172 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=fed24dae-1c00-0000-0bbd-68f04c100000 pid=4172 execve guuid=937d27af-1c00-0000-0bbd-68f053100000 pid=4179 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=937d27af-1c00-0000-0bbd-68f053100000 pid=4179 execve guuid=e454adaf-1c00-0000-0bbd-68f058100000 pid=4184 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=e454adaf-1c00-0000-0bbd-68f058100000 pid=4184 execve guuid=e31d8bb0-1c00-0000-0bbd-68f05f100000 pid=4191 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=e31d8bb0-1c00-0000-0bbd-68f05f100000 pid=4191 execve guuid=38f70cb1-1c00-0000-0bbd-68f063100000 pid=4195 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=38f70cb1-1c00-0000-0bbd-68f063100000 pid=4195 execve guuid=f764d9b1-1c00-0000-0bbd-68f069100000 pid=4201 /usr/bin/dash guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=f764d9b1-1c00-0000-0bbd-68f069100000 pid=4201 execve guuid=cb376ab2-1c00-0000-0bbd-68f06d100000 pid=4205 /tmp/sample.bin guuid=a1690446-1b00-0000-0bbd-68f0a50c0000 pid=3237->guuid=cb376ab2-1c00-0000-0bbd-68f06d100000 pid=4205 clone guuid=19d9294a-1b00-0000-0bbd-68f0a70c0000 pid=3239 /usr/bin/grep guuid=b49ca149-1b00-0000-0bbd-68f0a60c0000 pid=3238->guuid=19d9294a-1b00-0000-0bbd-68f0a70c0000 pid=3239 execve guuid=d8b5ef4a-1b00-0000-0bbd-68f0a90c0000 pid=3241 /usr/bin/grep guuid=c543a74a-1b00-0000-0bbd-68f0a80c0000 pid=3240->guuid=d8b5ef4a-1b00-0000-0bbd-68f0a90c0000 pid=3241 execve guuid=e77a194c-1b00-0000-0bbd-68f0ab0c0000 pid=3243 /usr/bin/grep guuid=7646b84b-1b00-0000-0bbd-68f0aa0c0000 pid=3242->guuid=e77a194c-1b00-0000-0bbd-68f0ab0c0000 pid=3243 execve guuid=bf7cfe4c-1b00-0000-0bbd-68f0ad0c0000 pid=3245 /usr/bin/grep guuid=6a24a44c-1b00-0000-0bbd-68f0ac0c0000 pid=3244->guuid=bf7cfe4c-1b00-0000-0bbd-68f0ad0c0000 pid=3245 execve guuid=5f20fc4d-1b00-0000-0bbd-68f0af0c0000 pid=3247 /usr/bin/grep guuid=97d1c34d-1b00-0000-0bbd-68f0ae0c0000 pid=3246->guuid=5f20fc4d-1b00-0000-0bbd-68f0af0c0000 pid=3247 execve guuid=c192cc4e-1b00-0000-0bbd-68f0b20c0000 pid=3250 /usr/bin/grep guuid=a28f8d4e-1b00-0000-0bbd-68f0b00c0000 pid=3248->guuid=c192cc4e-1b00-0000-0bbd-68f0b20c0000 pid=3250 execve guuid=53f7874f-1b00-0000-0bbd-68f0b60c0000 pid=3254 /usr/bin/grep guuid=c57b5c4f-1b00-0000-0bbd-68f0b40c0000 pid=3252->guuid=53f7874f-1b00-0000-0bbd-68f0b60c0000 pid=3254 execve guuid=eef08050-1b00-0000-0bbd-68f0ba0c0000 pid=3258 /usr/bin/grep guuid=2a7f2850-1b00-0000-0bbd-68f0b80c0000 pid=3256->guuid=eef08050-1b00-0000-0bbd-68f0ba0c0000 pid=3258 execve guuid=de346151-1b00-0000-0bbd-68f0be0c0000 pid=3262 /usr/bin/grep guuid=53ab1a51-1b00-0000-0bbd-68f0bc0c0000 pid=3260->guuid=de346151-1b00-0000-0bbd-68f0be0c0000 pid=3262 execve guuid=68be8a52-1b00-0000-0bbd-68f0c10c0000 pid=3265 /usr/bin/cp guuid=58a13652-1b00-0000-0bbd-68f0bf0c0000 pid=3263->guuid=68be8a52-1b00-0000-0bbd-68f0c10c0000 pid=3265 execve guuid=3d630653-1b00-0000-0bbd-68f0c20c0000 pid=3266 /usr/bin/chmod guuid=58a13652-1b00-0000-0bbd-68f0bf0c0000 pid=3263->guuid=3d630653-1b00-0000-0bbd-68f0c20c0000 pid=3266 execve guuid=04578353-1b00-0000-0bbd-68f0c50c0000 pid=3269 /usr/bin/grep guuid=442d5553-1b00-0000-0bbd-68f0c40c0000 pid=3268->guuid=04578353-1b00-0000-0bbd-68f0c50c0000 pid=3269 execve guuid=2bb52d54-1b00-0000-0bbd-68f0c90c0000 pid=3273 /usr/bin/cp guuid=d32bfa53-1b00-0000-0bbd-68f0c70c0000 pid=3271->guuid=2bb52d54-1b00-0000-0bbd-68f0c90c0000 pid=3273 execve guuid=add7ad54-1b00-0000-0bbd-68f0cb0c0000 pid=3275 /usr/bin/chmod guuid=d32bfa53-1b00-0000-0bbd-68f0c70c0000 pid=3271->guuid=add7ad54-1b00-0000-0bbd-68f0cb0c0000 pid=3275 execve guuid=96b34555-1b00-0000-0bbd-68f0cf0c0000 pid=3279 /usr/bin/grep guuid=e9371155-1b00-0000-0bbd-68f0cd0c0000 pid=3277->guuid=96b34555-1b00-0000-0bbd-68f0cf0c0000 pid=3279 execve guuid=aceee355-1b00-0000-0bbd-68f0d10c0000 pid=3281 /usr/bin/cp guuid=5776b055-1b00-0000-0bbd-68f0d00c0000 pid=3280->guuid=aceee355-1b00-0000-0bbd-68f0d10c0000 pid=3281 execve guuid=9a0c6a56-1b00-0000-0bbd-68f0d20c0000 pid=3282 /usr/bin/chmod guuid=5776b055-1b00-0000-0bbd-68f0d00c0000 pid=3280->guuid=9a0c6a56-1b00-0000-0bbd-68f0d20c0000 pid=3282 execve guuid=c654fc56-1b00-0000-0bbd-68f0d50c0000 pid=3285 /usr/bin/grep guuid=0cfac356-1b00-0000-0bbd-68f0d30c0000 pid=3283->guuid=c654fc56-1b00-0000-0bbd-68f0d50c0000 pid=3285 execve guuid=7c677957-1b00-0000-0bbd-68f0d80c0000 pid=3288 /usr/bin/cp guuid=73d35357-1b00-0000-0bbd-68f0d70c0000 pid=3287->guuid=7c677957-1b00-0000-0bbd-68f0d80c0000 pid=3288 execve guuid=507fef57-1b00-0000-0bbd-68f0db0c0000 pid=3291 /usr/bin/chmod guuid=73d35357-1b00-0000-0bbd-68f0d70c0000 pid=3287->guuid=507fef57-1b00-0000-0bbd-68f0db0c0000 pid=3291 execve guuid=b1f67458-1b00-0000-0bbd-68f0df0c0000 pid=3295 /usr/bin/grep guuid=4ef44658-1b00-0000-0bbd-68f0dd0c0000 pid=3293->guuid=b1f67458-1b00-0000-0bbd-68f0df0c0000 pid=3295 execve guuid=03bff258-1b00-0000-0bbd-68f0e20c0000 pid=3298 /usr/bin/cp guuid=5860c858-1b00-0000-0bbd-68f0e10c0000 pid=3297->guuid=03bff258-1b00-0000-0bbd-68f0e20c0000 pid=3298 execve guuid=f5dd6b59-1b00-0000-0bbd-68f0e30c0000 pid=3299 /usr/bin/chmod guuid=5860c858-1b00-0000-0bbd-68f0e10c0000 pid=3297->guuid=f5dd6b59-1b00-0000-0bbd-68f0e30c0000 pid=3299 execve guuid=5584f459-1b00-0000-0bbd-68f0e50c0000 pid=3301 /usr/bin/grep guuid=ce95c559-1b00-0000-0bbd-68f0e40c0000 pid=3300->guuid=5584f459-1b00-0000-0bbd-68f0e50c0000 pid=3301 execve guuid=cf6f8b5a-1b00-0000-0bbd-68f0e60c0000 pid=3302->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B 41a640a2-e439-5bd5-a73e-310f0a6373f1 boberkurwa.phoneparts.icu:32465 guuid=cf6f8b5a-1b00-0000-0bbd-68f0e60c0000 pid=3302->41a640a2-e439-5bd5-a73e-310f0a6373f1 con guuid=de28ff75-1c00-0000-0bbd-68f06b0f0000 pid=3947 /usr/bin/grep guuid=31ffbc75-1c00-0000-0bbd-68f0690f0000 pid=3945->guuid=de28ff75-1c00-0000-0bbd-68f06b0f0000 pid=3947 execve guuid=bf96b276-1c00-0000-0bbd-68f06f0f0000 pid=3951 /usr/bin/systemctl guuid=a4fa7876-1c00-0000-0bbd-68f06d0f0000 pid=3949->guuid=bf96b276-1c00-0000-0bbd-68f06f0f0000 pid=3951 execve guuid=8afc9fa7-1c00-0000-0bbd-68f01e100000 pid=4126 /usr/bin/systemctl guuid=d02f6fa7-1c00-0000-0bbd-68f01d100000 pid=4125->guuid=8afc9fa7-1c00-0000-0bbd-68f01e100000 pid=4126 execve guuid=6cc471a9-1c00-0000-0bbd-68f026100000 pid=4134 /usr/bin/grep guuid=3c6332a9-1c00-0000-0bbd-68f025100000 pid=4133->guuid=6cc471a9-1c00-0000-0bbd-68f026100000 pid=4134 execve guuid=d7fc02aa-1c00-0000-0bbd-68f02a100000 pid=4138 /usr/bin/grep guuid=99ebcba9-1c00-0000-0bbd-68f029100000 pid=4137->guuid=d7fc02aa-1c00-0000-0bbd-68f02a100000 pid=4138 execve guuid=7bb992aa-1c00-0000-0bbd-68f02f100000 pid=4143 /usr/bin/grep guuid=32d768aa-1c00-0000-0bbd-68f02e100000 pid=4142->guuid=7bb992aa-1c00-0000-0bbd-68f02f100000 pid=4143 execve guuid=11a720ab-1c00-0000-0bbd-68f033100000 pid=4147 /usr/bin/grep guuid=6114eaaa-1c00-0000-0bbd-68f030100000 pid=4144->guuid=11a720ab-1c00-0000-0bbd-68f033100000 pid=4147 execve guuid=5465bfab-1c00-0000-0bbd-68f039100000 pid=4153 /usr/bin/grep guuid=86de89ab-1c00-0000-0bbd-68f036100000 pid=4150->guuid=5465bfab-1c00-0000-0bbd-68f039100000 pid=4153 execve guuid=79676cac-1c00-0000-0bbd-68f03e100000 pid=4158 /usr/bin/grep guuid=aeef2dac-1c00-0000-0bbd-68f03a100000 pid=4154->guuid=79676cac-1c00-0000-0bbd-68f03e100000 pid=4158 execve guuid=b011ebac-1c00-0000-0bbd-68f043100000 pid=4163 /usr/bin/grep guuid=5c9cbdac-1c00-0000-0bbd-68f041100000 pid=4161->guuid=b011ebac-1c00-0000-0bbd-68f043100000 pid=4163 execve guuid=df0a74ad-1c00-0000-0bbd-68f047100000 pid=4167 /usr/bin/grep guuid=c9a33dad-1c00-0000-0bbd-68f045100000 pid=4165->guuid=df0a74ad-1c00-0000-0bbd-68f047100000 pid=4167 execve guuid=faa6f8ad-1c00-0000-0bbd-68f04a100000 pid=4170 /usr/bin/grep guuid=999ac6ad-1c00-0000-0bbd-68f049100000 pid=4169->guuid=faa6f8ad-1c00-0000-0bbd-68f04a100000 pid=4170 execve guuid=dbc68cae-1c00-0000-0bbd-68f04e100000 pid=4174 /usr/bin/cp guuid=fed24dae-1c00-0000-0bbd-68f04c100000 pid=4172->guuid=dbc68cae-1c00-0000-0bbd-68f04e100000 pid=4174 execve guuid=1d5ae5ae-1c00-0000-0bbd-68f051100000 pid=4177 /usr/bin/chmod guuid=fed24dae-1c00-0000-0bbd-68f04c100000 pid=4172->guuid=1d5ae5ae-1c00-0000-0bbd-68f051100000 pid=4177 execve guuid=23b14daf-1c00-0000-0bbd-68f054100000 pid=4180 /usr/bin/grep guuid=937d27af-1c00-0000-0bbd-68f053100000 pid=4179->guuid=23b14daf-1c00-0000-0bbd-68f054100000 pid=4180 execve guuid=9332e7af-1c00-0000-0bbd-68f059100000 pid=4185 /usr/bin/cp guuid=e454adaf-1c00-0000-0bbd-68f058100000 pid=4184->guuid=9332e7af-1c00-0000-0bbd-68f059100000 pid=4185 execve guuid=7dc746b0-1c00-0000-0bbd-68f05d100000 pid=4189 /usr/bin/chmod guuid=e454adaf-1c00-0000-0bbd-68f058100000 pid=4184->guuid=7dc746b0-1c00-0000-0bbd-68f05d100000 pid=4189 execve guuid=f73ab3b0-1c00-0000-0bbd-68f061100000 pid=4193 /usr/bin/grep guuid=e31d8bb0-1c00-0000-0bbd-68f05f100000 pid=4191->guuid=f73ab3b0-1c00-0000-0bbd-68f061100000 pid=4193 execve guuid=f19936b1-1c00-0000-0bbd-68f065100000 pid=4197 /usr/bin/cp guuid=38f70cb1-1c00-0000-0bbd-68f063100000 pid=4195->guuid=f19936b1-1c00-0000-0bbd-68f065100000 pid=4197 execve guuid=c4b68fb1-1c00-0000-0bbd-68f067100000 pid=4199 /usr/bin/chmod guuid=38f70cb1-1c00-0000-0bbd-68f063100000 pid=4195->guuid=c4b68fb1-1c00-0000-0bbd-68f067100000 pid=4199 execve guuid=a2de03b2-1c00-0000-0bbd-68f06b100000 pid=4203 /usr/bin/grep guuid=f764d9b1-1c00-0000-0bbd-68f069100000 pid=4201->guuid=a2de03b2-1c00-0000-0bbd-68f06b100000 pid=4203 execve guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B guuid=b4e5ea12-1f00-0000-0bbd-68f0f2140000 pid=5362 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=b4e5ea12-1f00-0000-0bbd-68f0f2140000 pid=5362 execve guuid=e6cc1e14-1f00-0000-0bbd-68f0f4140000 pid=5364 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=e6cc1e14-1f00-0000-0bbd-68f0f4140000 pid=5364 execve guuid=08e36c97-1f00-0000-0bbd-68f00a150000 pid=5386 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=08e36c97-1f00-0000-0bbd-68f00a150000 pid=5386 execve guuid=0023ce9b-1f00-0000-0bbd-68f00c150000 pid=5388 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=0023ce9b-1f00-0000-0bbd-68f00c150000 pid=5388 execve guuid=f516b89d-1f00-0000-0bbd-68f00e150000 pid=5390 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=f516b89d-1f00-0000-0bbd-68f00e150000 pid=5390 execve guuid=37bda09f-1f00-0000-0bbd-68f010150000 pid=5392 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=37bda09f-1f00-0000-0bbd-68f010150000 pid=5392 execve guuid=3b3605a2-1f00-0000-0bbd-68f012150000 pid=5394 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=3b3605a2-1f00-0000-0bbd-68f012150000 pid=5394 execve guuid=9579afa3-1f00-0000-0bbd-68f014150000 pid=5396 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=9579afa3-1f00-0000-0bbd-68f014150000 pid=5396 execve guuid=e8aaa9a9-1f00-0000-0bbd-68f016150000 pid=5398 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=e8aaa9a9-1f00-0000-0bbd-68f016150000 pid=5398 execve guuid=24374fab-1f00-0000-0bbd-68f018150000 pid=5400 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=24374fab-1f00-0000-0bbd-68f018150000 pid=5400 execve guuid=b58538ad-1f00-0000-0bbd-68f01a150000 pid=5402 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=b58538ad-1f00-0000-0bbd-68f01a150000 pid=5402 execve guuid=a22ca3af-1f00-0000-0bbd-68f01c150000 pid=5404 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=a22ca3af-1f00-0000-0bbd-68f01c150000 pid=5404 execve guuid=d3eb4bb2-1f00-0000-0bbd-68f01e150000 pid=5406 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=d3eb4bb2-1f00-0000-0bbd-68f01e150000 pid=5406 execve guuid=389dbeb6-1f00-0000-0bbd-68f021150000 pid=5409 /usr/bin/dash guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=389dbeb6-1f00-0000-0bbd-68f021150000 pid=5409 execve guuid=9836a7b7-1f00-0000-0bbd-68f023150000 pid=5411 /tmp/sample.bin zombie guuid=82d84d0d-1f00-0000-0bbd-68f0f1140000 pid=5361->guuid=9836a7b7-1f00-0000-0bbd-68f023150000 pid=5411 clone guuid=d5de9213-1f00-0000-0bbd-68f0f3140000 pid=5363 /usr/bin/grep guuid=b4e5ea12-1f00-0000-0bbd-68f0f2140000 pid=5362->guuid=d5de9213-1f00-0000-0bbd-68f0f3140000 pid=5363 execve guuid=4ede5a14-1f00-0000-0bbd-68f0f5140000 pid=5365 /usr/bin/systemctl guuid=e6cc1e14-1f00-0000-0bbd-68f0f4140000 pid=5364->guuid=4ede5a14-1f00-0000-0bbd-68f0f5140000 pid=5365 execve guuid=30cb4a98-1f00-0000-0bbd-68f00b150000 pid=5387 /usr/bin/systemctl guuid=08e36c97-1f00-0000-0bbd-68f00a150000 pid=5386->guuid=30cb4a98-1f00-0000-0bbd-68f00b150000 pid=5387 execve guuid=3402d09c-1f00-0000-0bbd-68f00d150000 pid=5389 /usr/bin/grep guuid=0023ce9b-1f00-0000-0bbd-68f00c150000 pid=5388->guuid=3402d09c-1f00-0000-0bbd-68f00d150000 pid=5389 execve guuid=07d3b89e-1f00-0000-0bbd-68f00f150000 pid=5391 /usr/bin/grep guuid=f516b89d-1f00-0000-0bbd-68f00e150000 pid=5390->guuid=07d3b89e-1f00-0000-0bbd-68f00f150000 pid=5391 execve guuid=b9a41aa1-1f00-0000-0bbd-68f011150000 pid=5393 /usr/bin/grep guuid=37bda09f-1f00-0000-0bbd-68f010150000 pid=5392->guuid=b9a41aa1-1f00-0000-0bbd-68f011150000 pid=5393 execve guuid=4e6cc1a2-1f00-0000-0bbd-68f013150000 pid=5395 /usr/bin/grep guuid=3b3605a2-1f00-0000-0bbd-68f012150000 pid=5394->guuid=4e6cc1a2-1f00-0000-0bbd-68f013150000 pid=5395 execve guuid=1b765ca8-1f00-0000-0bbd-68f015150000 pid=5397 /usr/bin/grep guuid=9579afa3-1f00-0000-0bbd-68f014150000 pid=5396->guuid=1b765ca8-1f00-0000-0bbd-68f015150000 pid=5397 execve guuid=b95f6daa-1f00-0000-0bbd-68f017150000 pid=5399 /usr/bin/grep guuid=e8aaa9a9-1f00-0000-0bbd-68f016150000 pid=5398->guuid=b95f6daa-1f00-0000-0bbd-68f017150000 pid=5399 execve guuid=69ba53ac-1f00-0000-0bbd-68f019150000 pid=5401 /usr/bin/grep guuid=24374fab-1f00-0000-0bbd-68f018150000 pid=5400->guuid=69ba53ac-1f00-0000-0bbd-68f019150000 pid=5401 execve guuid=89fcffad-1f00-0000-0bbd-68f01b150000 pid=5403 /usr/bin/grep guuid=b58538ad-1f00-0000-0bbd-68f01a150000 pid=5402->guuid=89fcffad-1f00-0000-0bbd-68f01b150000 pid=5403 execve guuid=52faddb0-1f00-0000-0bbd-68f01d150000 pid=5405 /usr/bin/grep guuid=a22ca3af-1f00-0000-0bbd-68f01c150000 pid=5404->guuid=52faddb0-1f00-0000-0bbd-68f01d150000 pid=5405 execve guuid=044d8ab2-1f00-0000-0bbd-68f01f150000 pid=5407 /usr/bin/cp guuid=d3eb4bb2-1f00-0000-0bbd-68f01e150000 pid=5406->guuid=044d8ab2-1f00-0000-0bbd-68f01f150000 pid=5407 execve guuid=c6b275b6-1f00-0000-0bbd-68f020150000 pid=5408 /usr/bin/chmod guuid=d3eb4bb2-1f00-0000-0bbd-68f01e150000 pid=5406->guuid=c6b275b6-1f00-0000-0bbd-68f020150000 pid=5408 execve guuid=f87502b7-1f00-0000-0bbd-68f022150000 pid=5410 /usr/bin/grep guuid=389dbeb6-1f00-0000-0bbd-68f021150000 pid=5409->guuid=f87502b7-1f00-0000-0bbd-68f022150000 pid=5410 execve guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B guuid=5ff50b1a-2200-0000-0bbd-68f045150000 pid=5445 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=5ff50b1a-2200-0000-0bbd-68f045150000 pid=5445 execve guuid=5fd93c1b-2200-0000-0bbd-68f047150000 pid=5447 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=5fd93c1b-2200-0000-0bbd-68f047150000 pid=5447 execve guuid=00526745-2200-0000-0bbd-68f05d150000 pid=5469 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=00526745-2200-0000-0bbd-68f05d150000 pid=5469 execve guuid=79a1b146-2200-0000-0bbd-68f05f150000 pid=5471 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=79a1b146-2200-0000-0bbd-68f05f150000 pid=5471 execve guuid=c3d02947-2200-0000-0bbd-68f061150000 pid=5473 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=c3d02947-2200-0000-0bbd-68f061150000 pid=5473 execve guuid=9fcb9e47-2200-0000-0bbd-68f063150000 pid=5475 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=9fcb9e47-2200-0000-0bbd-68f063150000 pid=5475 execve guuid=9a0d2648-2200-0000-0bbd-68f065150000 pid=5477 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=9a0d2648-2200-0000-0bbd-68f065150000 pid=5477 execve guuid=a758e748-2200-0000-0bbd-68f067150000 pid=5479 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=a758e748-2200-0000-0bbd-68f067150000 pid=5479 execve guuid=d7ed7149-2200-0000-0bbd-68f069150000 pid=5481 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=d7ed7149-2200-0000-0bbd-68f069150000 pid=5481 execve guuid=8b34f349-2200-0000-0bbd-68f06b150000 pid=5483 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=8b34f349-2200-0000-0bbd-68f06b150000 pid=5483 execve guuid=6387824a-2200-0000-0bbd-68f06d150000 pid=5485 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=6387824a-2200-0000-0bbd-68f06d150000 pid=5485 execve guuid=ca77124b-2200-0000-0bbd-68f06f150000 pid=5487 /usr/bin/dash guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=ca77124b-2200-0000-0bbd-68f06f150000 pid=5487 execve guuid=91b8c04b-2200-0000-0bbd-68f071150000 pid=5489 /tmp/sample.bin guuid=49212414-2200-0000-0bbd-68f044150000 pid=5444->guuid=91b8c04b-2200-0000-0bbd-68f071150000 pid=5489 clone guuid=0888601a-2200-0000-0bbd-68f046150000 pid=5446 /usr/bin/grep guuid=5ff50b1a-2200-0000-0bbd-68f045150000 pid=5445->guuid=0888601a-2200-0000-0bbd-68f046150000 pid=5446 execve guuid=8e8d971b-2200-0000-0bbd-68f048150000 pid=5448 /usr/bin/systemctl guuid=5fd93c1b-2200-0000-0bbd-68f047150000 pid=5447->guuid=8e8d971b-2200-0000-0bbd-68f048150000 pid=5448 execve guuid=5e7f9445-2200-0000-0bbd-68f05e150000 pid=5470 /usr/bin/systemctl guuid=00526745-2200-0000-0bbd-68f05d150000 pid=5469->guuid=5e7f9445-2200-0000-0bbd-68f05e150000 pid=5470 execve guuid=248edc46-2200-0000-0bbd-68f060150000 pid=5472 /usr/bin/grep guuid=79a1b146-2200-0000-0bbd-68f05f150000 pid=5471->guuid=248edc46-2200-0000-0bbd-68f060150000 pid=5472 execve guuid=95935247-2200-0000-0bbd-68f062150000 pid=5474 /usr/bin/grep guuid=c3d02947-2200-0000-0bbd-68f061150000 pid=5473->guuid=95935247-2200-0000-0bbd-68f062150000 pid=5474 execve guuid=cbcdc647-2200-0000-0bbd-68f064150000 pid=5476 /usr/bin/grep guuid=9fcb9e47-2200-0000-0bbd-68f063150000 pid=5475->guuid=cbcdc647-2200-0000-0bbd-68f064150000 pid=5476 execve guuid=d3438848-2200-0000-0bbd-68f066150000 pid=5478 /usr/bin/grep guuid=9a0d2648-2200-0000-0bbd-68f065150000 pid=5477->guuid=d3438848-2200-0000-0bbd-68f066150000 pid=5478 execve guuid=40711c49-2200-0000-0bbd-68f068150000 pid=5480 /usr/bin/grep guuid=a758e748-2200-0000-0bbd-68f067150000 pid=5479->guuid=40711c49-2200-0000-0bbd-68f068150000 pid=5480 execve guuid=90079d49-2200-0000-0bbd-68f06a150000 pid=5482 /usr/bin/grep guuid=d7ed7149-2200-0000-0bbd-68f069150000 pid=5481->guuid=90079d49-2200-0000-0bbd-68f06a150000 pid=5482 execve guuid=371f294a-2200-0000-0bbd-68f06c150000 pid=5484 /usr/bin/grep guuid=8b34f349-2200-0000-0bbd-68f06b150000 pid=5483->guuid=371f294a-2200-0000-0bbd-68f06c150000 pid=5484 execve guuid=e1abb54a-2200-0000-0bbd-68f06e150000 pid=5486 /usr/bin/grep guuid=6387824a-2200-0000-0bbd-68f06d150000 pid=5485->guuid=e1abb54a-2200-0000-0bbd-68f06e150000 pid=5486 execve guuid=71e5484b-2200-0000-0bbd-68f070150000 pid=5488 /usr/bin/grep guuid=ca77124b-2200-0000-0bbd-68f06f150000 pid=5487->guuid=71e5484b-2200-0000-0bbd-68f070150000 pid=5488 execve guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B guuid=7fcd09a9-2400-0000-0bbd-68f073150000 pid=5491 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=7fcd09a9-2400-0000-0bbd-68f073150000 pid=5491 execve guuid=ec2430aa-2400-0000-0bbd-68f075150000 pid=5493 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=ec2430aa-2400-0000-0bbd-68f075150000 pid=5493 execve guuid=bd49adc9-2400-0000-0bbd-68f08b150000 pid=5515 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=bd49adc9-2400-0000-0bbd-68f08b150000 pid=5515 execve guuid=7d53e8ca-2400-0000-0bbd-68f08d150000 pid=5517 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=7d53e8ca-2400-0000-0bbd-68f08d150000 pid=5517 execve guuid=fccb66cb-2400-0000-0bbd-68f08f150000 pid=5519 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=fccb66cb-2400-0000-0bbd-68f08f150000 pid=5519 execve guuid=905ee8cb-2400-0000-0bbd-68f091150000 pid=5521 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=905ee8cb-2400-0000-0bbd-68f091150000 pid=5521 execve guuid=39116ccc-2400-0000-0bbd-68f093150000 pid=5523 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=39116ccc-2400-0000-0bbd-68f093150000 pid=5523 execve guuid=ddaaf4cc-2400-0000-0bbd-68f095150000 pid=5525 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=ddaaf4cc-2400-0000-0bbd-68f095150000 pid=5525 execve guuid=d44d96cd-2400-0000-0bbd-68f097150000 pid=5527 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=d44d96cd-2400-0000-0bbd-68f097150000 pid=5527 execve guuid=a7f33cce-2400-0000-0bbd-68f099150000 pid=5529 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=a7f33cce-2400-0000-0bbd-68f099150000 pid=5529 execve guuid=fb6cf6ce-2400-0000-0bbd-68f09b150000 pid=5531 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=fb6cf6ce-2400-0000-0bbd-68f09b150000 pid=5531 execve guuid=8e9ac2cf-2400-0000-0bbd-68f09d150000 pid=5533 /usr/bin/dash guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=8e9ac2cf-2400-0000-0bbd-68f09d150000 pid=5533 execve guuid=c01782d0-2400-0000-0bbd-68f09f150000 pid=5535 /tmp/sample.bin guuid=edf9bca3-2400-0000-0bbd-68f072150000 pid=5490->guuid=c01782d0-2400-0000-0bbd-68f09f150000 pid=5535 clone guuid=939c58a9-2400-0000-0bbd-68f074150000 pid=5492 /usr/bin/grep guuid=7fcd09a9-2400-0000-0bbd-68f073150000 pid=5491->guuid=939c58a9-2400-0000-0bbd-68f074150000 pid=5492 execve guuid=f9947eaa-2400-0000-0bbd-68f076150000 pid=5494 /usr/bin/systemctl guuid=ec2430aa-2400-0000-0bbd-68f075150000 pid=5493->guuid=f9947eaa-2400-0000-0bbd-68f076150000 pid=5494 execve guuid=b711d7c9-2400-0000-0bbd-68f08c150000 pid=5516 /usr/bin/systemctl guuid=bd49adc9-2400-0000-0bbd-68f08b150000 pid=5515->guuid=b711d7c9-2400-0000-0bbd-68f08c150000 pid=5516 execve guuid=4a8c12cb-2400-0000-0bbd-68f08e150000 pid=5518 /usr/bin/grep guuid=7d53e8ca-2400-0000-0bbd-68f08d150000 pid=5517->guuid=4a8c12cb-2400-0000-0bbd-68f08e150000 pid=5518 execve guuid=cea590cb-2400-0000-0bbd-68f090150000 pid=5520 /usr/bin/grep guuid=fccb66cb-2400-0000-0bbd-68f08f150000 pid=5519->guuid=cea590cb-2400-0000-0bbd-68f090150000 pid=5520 execve guuid=491915cc-2400-0000-0bbd-68f092150000 pid=5522 /usr/bin/grep guuid=905ee8cb-2400-0000-0bbd-68f091150000 pid=5521->guuid=491915cc-2400-0000-0bbd-68f092150000 pid=5522 execve guuid=8c4293cc-2400-0000-0bbd-68f094150000 pid=5524 /usr/bin/grep guuid=39116ccc-2400-0000-0bbd-68f093150000 pid=5523->guuid=8c4293cc-2400-0000-0bbd-68f094150000 pid=5524 execve guuid=c5a43dcd-2400-0000-0bbd-68f096150000 pid=5526 /usr/bin/grep guuid=ddaaf4cc-2400-0000-0bbd-68f095150000 pid=5525->guuid=c5a43dcd-2400-0000-0bbd-68f096150000 pid=5526 execve guuid=0f1be2cd-2400-0000-0bbd-68f098150000 pid=5528 /usr/bin/grep guuid=d44d96cd-2400-0000-0bbd-68f097150000 pid=5527->guuid=0f1be2cd-2400-0000-0bbd-68f098150000 pid=5528 execve guuid=5ea887ce-2400-0000-0bbd-68f09a150000 pid=5530 /usr/bin/grep guuid=a7f33cce-2400-0000-0bbd-68f099150000 pid=5529->guuid=5ea887ce-2400-0000-0bbd-68f09a150000 pid=5530 execve guuid=dcae2fcf-2400-0000-0bbd-68f09c150000 pid=5532 /usr/bin/grep guuid=fb6cf6ce-2400-0000-0bbd-68f09b150000 pid=5531->guuid=dcae2fcf-2400-0000-0bbd-68f09c150000 pid=5532 execve guuid=355b06d0-2400-0000-0bbd-68f09e150000 pid=5534 /usr/bin/grep guuid=8e9ac2cf-2400-0000-0bbd-68f09d150000 pid=5533->guuid=355b06d0-2400-0000-0bbd-68f09e150000 pid=5534 execve guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 43B guuid=3e635838-2700-0000-0bbd-68f0a1150000 pid=5537 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=3e635838-2700-0000-0bbd-68f0a1150000 pid=5537 execve guuid=14787639-2700-0000-0bbd-68f0a3150000 pid=5539 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=14787639-2700-0000-0bbd-68f0a3150000 pid=5539 execve guuid=611f7d68-2700-0000-0bbd-68f0b9150000 pid=5561 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=611f7d68-2700-0000-0bbd-68f0b9150000 pid=5561 execve guuid=4379e769-2700-0000-0bbd-68f0bb150000 pid=5563 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=4379e769-2700-0000-0bbd-68f0bb150000 pid=5563 execve guuid=564b706a-2700-0000-0bbd-68f0bd150000 pid=5565 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=564b706a-2700-0000-0bbd-68f0bd150000 pid=5565 execve guuid=838ef96a-2700-0000-0bbd-68f0bf150000 pid=5567 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=838ef96a-2700-0000-0bbd-68f0bf150000 pid=5567 execve guuid=4092866b-2700-0000-0bbd-68f0c1150000 pid=5569 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=4092866b-2700-0000-0bbd-68f0c1150000 pid=5569 execve guuid=501d176c-2700-0000-0bbd-68f0c3150000 pid=5571 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=501d176c-2700-0000-0bbd-68f0c3150000 pid=5571 execve guuid=730db46c-2700-0000-0bbd-68f0c5150000 pid=5573 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=730db46c-2700-0000-0bbd-68f0c5150000 pid=5573 execve guuid=112a486d-2700-0000-0bbd-68f0c7150000 pid=5575 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=112a486d-2700-0000-0bbd-68f0c7150000 pid=5575 execve guuid=d988e76d-2700-0000-0bbd-68f0c9150000 pid=5577 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=d988e76d-2700-0000-0bbd-68f0c9150000 pid=5577 execve guuid=63b2776e-2700-0000-0bbd-68f0cb150000 pid=5579 /usr/bin/dash guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=63b2776e-2700-0000-0bbd-68f0cb150000 pid=5579 execve guuid=ae26356f-2700-0000-0bbd-68f0cd150000 pid=5581 /tmp/sample.bin guuid=b8d86d33-2700-0000-0bbd-68f0a0150000 pid=5536->guuid=ae26356f-2700-0000-0bbd-68f0cd150000 pid=5581 clone guuid=d33a8538-2700-0000-0bbd-68f0a2150000 pid=5538 /usr/bin/grep guuid=3e635838-2700-0000-0bbd-68f0a1150000 pid=5537->guuid=d33a8538-2700-0000-0bbd-68f0a2150000 pid=5538 execve guuid=dc5ea039-2700-0000-0bbd-68f0a4150000 pid=5540 /usr/bin/systemctl guuid=14787639-2700-0000-0bbd-68f0a3150000 pid=5539->guuid=dc5ea039-2700-0000-0bbd-68f0a4150000 pid=5540 execve guuid=2962aa68-2700-0000-0bbd-68f0ba150000 pid=5562 /usr/bin/systemctl guuid=611f7d68-2700-0000-0bbd-68f0b9150000 pid=5561->guuid=2962aa68-2700-0000-0bbd-68f0ba150000 pid=5562 execve guuid=b53d146a-2700-0000-0bbd-68f0bc150000 pid=5564 /usr/bin/grep guuid=4379e769-2700-0000-0bbd-68f0bb150000 pid=5563->guuid=b53d146a-2700-0000-0bbd-68f0bc150000 pid=5564 execve guuid=ea5ea56a-2700-0000-0bbd-68f0be150000 pid=5566 /usr/bin/grep guuid=564b706a-2700-0000-0bbd-68f0bd150000 pid=5565->guuid=ea5ea56a-2700-0000-0bbd-68f0be150000 pid=5566 execve guuid=ea0b236b-2700-0000-0bbd-68f0c0150000 pid=5568 /usr/bin/grep guuid=838ef96a-2700-0000-0bbd-68f0bf150000 pid=5567->guuid=ea0b236b-2700-0000-0bbd-68f0c0150000 pid=5568 execve guuid=d0b3bc6b-2700-0000-0bbd-68f0c2150000 pid=5570 /usr/bin/grep guuid=4092866b-2700-0000-0bbd-68f0c1150000 pid=5569->guuid=d0b3bc6b-2700-0000-0bbd-68f0c2150000 pid=5570 execve guuid=f0eb546c-2700-0000-0bbd-68f0c4150000 pid=5572 /usr/bin/grep guuid=501d176c-2700-0000-0bbd-68f0c3150000 pid=5571->guuid=f0eb546c-2700-0000-0bbd-68f0c4150000 pid=5572 execve guuid=32abeb6c-2700-0000-0bbd-68f0c6150000 pid=5574 /usr/bin/grep guuid=730db46c-2700-0000-0bbd-68f0c5150000 pid=5573->guuid=32abeb6c-2700-0000-0bbd-68f0c6150000 pid=5574 execve guuid=d898796d-2700-0000-0bbd-68f0c8150000 pid=5576 /usr/bin/grep guuid=112a486d-2700-0000-0bbd-68f0c7150000 pid=5575->guuid=d898796d-2700-0000-0bbd-68f0c8150000 pid=5576 execve guuid=b3ad226e-2700-0000-0bbd-68f0ca150000 pid=5578 /usr/bin/grep guuid=d988e76d-2700-0000-0bbd-68f0c9150000 pid=5577->guuid=b3ad226e-2700-0000-0bbd-68f0ca150000 pid=5578 execve guuid=e6809e6e-2700-0000-0bbd-68f0cc150000 pid=5580 /usr/bin/grep guuid=63b2776e-2700-0000-0bbd-68f0cb150000 pid=5579->guuid=e6809e6e-2700-0000-0bbd-68f0cc150000 pid=5580 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Connects to many ports of the same IP (likely port scanning)
Drops files in suspicious directories
Malicious sample detected (through community Yara rule)
Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions
Multi AV Scanner detection for submitted file
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to persist itself using System V runlevels
Writes identical ELF files to multiple locations
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1835196 Sample: x86.elf Startdate: 17/12/2025 Architecture: LINUX Score: 100 76 boberkurwa.phoneparts.icu 89.32.41.172, 32465, 58928, 58930 HOSTMAZEHOSTMAZERO Romania 2->76 78 34.243.160.129, 443 AMAZON-02US United States 2->78 80 54.247.62.1, 443, 52482 AMAZON-02US United States 2->80 82 Malicious sample detected (through community Yara rule) 2->82 84 Multi AV Scanner detection for submitted file 2->84 86 Yara detected Mirai 2->86 88 Connects to many ports of the same IP (likely port scanning) 2->88 8 x86.elf 2->8         started        12 systemd x86.elf 2->12         started        14 systemd x86.elf 2->14         started        16 26 other processes 2->16 signatures3 process4 file5 62 /var/spool/cron/root, ASCII 8->62 dropped 64 /var/spool/cron/crontabs/root, ASCII 8->64 dropped 66 /root/.bashrc, ASCII 8->66 dropped 74 3 other malicious files 8->74 dropped 94 Sample tries to persist itself using /etc/profile 8->94 96 Drops files in suspicious directories 8->96 98 Modifies the '.bashrc' or '.bash_profile' file typically for persisting actions 8->98 100 Sample tries to persist itself using cron 8->100 18 x86.elf sh 8->18         started        20 x86.elf sh 8->20         started        28 21 other processes 8->28 102 Sample tries to persist itself using System V runlevels 12->102 22 x86.elf sh 12->22         started        24 x86.elf sh 12->24         started        30 17 other processes 12->30 26 x86.elf sh 14->26         started        32 14 other processes 14->32 68 /etc/rcS.d/S99sysinit, POSIX 16->68 dropped 70 /etc/init.d/S99sysinit, POSIX 16->70 dropped 72 /etc/network/if-up.d/sysinit, POSIX 16->72 dropped 34 129 other processes 16->34 signatures6 process7 process8 36 2 other processes 18->36 39 2 other processes 20->39 42 2 other processes 22->42 44 2 other processes 24->44 46 2 other processes 26->46 48 23 other processes 28->48 50 17 other processes 30->50 52 13 other processes 32->52 54 120 other processes 34->54 file9 56 /usr/bin/sysinit, ELF 39->56 dropped 58 /usr/sbin/sysinit, ELF 44->58 dropped 60 /usr/lib/libsysinit.so, ELF 46->60 dropped 90 Writes identical ELF files to multiple locations 46->90 92 Drops files in suspicious directories 50->92 signatures10
Threat name:
Linux.Worm.Mirai
Status:
Malicious
First seen:
2025-12-17 18:26:24 UTC
File Type:
ELF32 Little (Exe)
AV detection:
20 of 38 (52.63%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:wicked botnet defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Modifies init.d
Modifies rc script
Modifies systemd
Write file to user bin folder
File and Directory Permissions Modification
Mirai
Mirai family
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Dropper.Mirai-7136015-0
YARA:
Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Mirai_fa3ad9d0 Linux_Trojan_Mirai_b14f4c5d Linux_Trojan_Mirai_93fc3657 Linux_Trojan_Mirai_99d78950 Linux_Trojan_Mirai_5f7b67b8 Linux_Trojan_Mirai_a68e498c Linux_Trojan_Mirai_88de437f Linux_Trojan_Mirai_ae9d0fa6 Linux_Trojan_Mirai_389ee3e9 Linux_Trojan_Mirai_cc93863b Linux_Trojan_Mirai_8aa7b5d3
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_5f7b67b8
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_88de437f
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_8aa7b5d3
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_93fc3657
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_99d78950
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_a68e498c
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_ae9d0fa6
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_b14f4c5d
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_cc93863b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_fa3ad9d0
Author:Elastic Security
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 8b944f00ebb2e5f2c8fd8257724808980d2ace4353a4a76b7da6ae7e90ee6dac

(this sample)

  
Delivery method
Distributed via web download

Comments