MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8c40b12b75b8a2480dfd2930bcfcbf434d02c7fd9b4bd8252fe2d7239fa20a00. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 12 File information Comments

SHA256 hash: 8c40b12b75b8a2480dfd2930bcfcbf434d02c7fd9b4bd8252fe2d7239fa20a00
SHA3-384 hash: 5c1b880604078af5ac6870ad44273f5470478db07af10e019d42b7e5f67bff4c8bcd7714ef684483397ac8c7f09297c5
SHA1 hash: fbdfd5e3e6d628e14374010075912534ac7d80d4
MD5 hash: 0d1fd9883ec3a9000b9c845ce95633d3
humanhash: kilo-golf-hamper-autumn
File name:cron
Download: download sample
Signature Mirai
File size:138'735 bytes
First seen:2025-07-11 23:10:20 UTC
Last seen:2025-07-12 04:09:07 UTC
File type: elf
MIME type:application/x-executable
ssdeep 3072:qFGVP4kHIqRrKgr/GXIuZiIaP2PZLnlPGp3wmpFEthq9aTemT:qFRk5rS0/P2PZJ63wmpFEthq9aTemT
TLSH T166D3CB29F103C373D5930671228EEE662C306BD537DAB55AB3B43AB4A9B34473911E8C
telfhash t1f0315611943546142fb39928acbd56b315221b2323586f716f25c5cc49260e1e93dd0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
2
# of downloads :
17
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
DNS request
Creating a file
Connection attempt
Launching a process
Substitutes an application name
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=55c5d678-1900-0000-12eb-3de19d0b0000 pid=2973 /usr/bin/sudo guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982 /tmp/sample.bin net guuid=55c5d678-1900-0000-12eb-3de19d0b0000 pid=2973->guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985 /tmp/sample.bin zombie guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982->guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985 clone guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987 /usr/bin/dash zombie guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982->guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987 execve guuid=3f60bc7c-1900-0000-12eb-3de1ac0b0000 pid=2988 /tmp/sample.bin guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982->guuid=3f60bc7c-1900-0000-12eb-3de1ac0b0000 pid=2988 clone guuid=08d2c07c-1900-0000-12eb-3de1ad0b0000 pid=2989 /tmp/sample.bin guuid=586c0e7b-1900-0000-12eb-3de1a60b0000 pid=2982->guuid=08d2c07c-1900-0000-12eb-3de1ad0b0000 pid=2989 clone guuid=fd0ec3ae-1900-0000-12eb-3de1250c0000 pid=3109 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=fd0ec3ae-1900-0000-12eb-3de1250c0000 pid=3109 execve guuid=0a6e24b2-1900-0000-12eb-3de12f0c0000 pid=3119 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=0a6e24b2-1900-0000-12eb-3de12f0c0000 pid=3119 execve guuid=1b6c42b3-1900-0000-12eb-3de1350c0000 pid=3125 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1b6c42b3-1900-0000-12eb-3de1350c0000 pid=3125 execve guuid=4c523db4-1900-0000-12eb-3de13b0c0000 pid=3131 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=4c523db4-1900-0000-12eb-3de13b0c0000 pid=3131 execve guuid=13de10b5-1900-0000-12eb-3de1400c0000 pid=3136 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=13de10b5-1900-0000-12eb-3de1400c0000 pid=3136 execve guuid=c421edb5-1900-0000-12eb-3de1450c0000 pid=3141 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c421edb5-1900-0000-12eb-3de1450c0000 pid=3141 execve guuid=129efdb6-1900-0000-12eb-3de14a0c0000 pid=3146 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=129efdb6-1900-0000-12eb-3de14a0c0000 pid=3146 execve guuid=cd7d1eb8-1900-0000-12eb-3de14f0c0000 pid=3151 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=cd7d1eb8-1900-0000-12eb-3de14f0c0000 pid=3151 execve guuid=ab2bf2b8-1900-0000-12eb-3de1550c0000 pid=3157 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ab2bf2b8-1900-0000-12eb-3de1550c0000 pid=3157 execve guuid=51ba24e7-1a00-0000-12eb-3de1e60e0000 pid=3814 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=51ba24e7-1a00-0000-12eb-3de1e60e0000 pid=3814 execve guuid=2ad182ea-1a00-0000-12eb-3de1f50e0000 pid=3829 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=2ad182ea-1a00-0000-12eb-3de1f50e0000 pid=3829 execve guuid=f82e2dec-1a00-0000-12eb-3de1000f0000 pid=3840 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f82e2dec-1a00-0000-12eb-3de1000f0000 pid=3840 execve guuid=e345c0ed-1a00-0000-12eb-3de1070f0000 pid=3847 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=e345c0ed-1a00-0000-12eb-3de1070f0000 pid=3847 execve guuid=48960aef-1a00-0000-12eb-3de10e0f0000 pid=3854 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=48960aef-1a00-0000-12eb-3de10e0f0000 pid=3854 execve guuid=47b44af0-1a00-0000-12eb-3de1150f0000 pid=3861 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=47b44af0-1a00-0000-12eb-3de1150f0000 pid=3861 execve guuid=8b6c81f1-1a00-0000-12eb-3de11e0f0000 pid=3870 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=8b6c81f1-1a00-0000-12eb-3de11e0f0000 pid=3870 execve guuid=af5794f2-1a00-0000-12eb-3de1230f0000 pid=3875 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=af5794f2-1a00-0000-12eb-3de1230f0000 pid=3875 execve guuid=dc1fa4f3-1a00-0000-12eb-3de1280f0000 pid=3880 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=dc1fa4f3-1a00-0000-12eb-3de1280f0000 pid=3880 execve guuid=91219022-1c00-0000-12eb-3de17b120000 pid=4731 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=91219022-1c00-0000-12eb-3de17b120000 pid=4731 execve guuid=dad14f26-1c00-0000-12eb-3de18d120000 pid=4749 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=dad14f26-1c00-0000-12eb-3de18d120000 pid=4749 execve guuid=b0f02627-1c00-0000-12eb-3de193120000 pid=4755 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=b0f02627-1c00-0000-12eb-3de193120000 pid=4755 execve guuid=02b0f627-1c00-0000-12eb-3de19b120000 pid=4763 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=02b0f627-1c00-0000-12eb-3de19b120000 pid=4763 execve guuid=1574c628-1c00-0000-12eb-3de1a0120000 pid=4768 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1574c628-1c00-0000-12eb-3de1a0120000 pid=4768 execve guuid=3a27b929-1c00-0000-12eb-3de1a9120000 pid=4777 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=3a27b929-1c00-0000-12eb-3de1a9120000 pid=4777 execve guuid=55a5b62a-1c00-0000-12eb-3de1b0120000 pid=4784 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=55a5b62a-1c00-0000-12eb-3de1b0120000 pid=4784 execve guuid=11d7fa2b-1c00-0000-12eb-3de1bb120000 pid=4795 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=11d7fa2b-1c00-0000-12eb-3de1bb120000 pid=4795 execve guuid=01b1ba2c-1c00-0000-12eb-3de1c0120000 pid=4800 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=01b1ba2c-1c00-0000-12eb-3de1c0120000 pid=4800 execve guuid=2949c66b-1d00-0000-12eb-3de1b7140000 pid=5303 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=2949c66b-1d00-0000-12eb-3de1b7140000 pid=5303 execve guuid=c378dd6e-1d00-0000-12eb-3de1ba140000 pid=5306 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c378dd6e-1d00-0000-12eb-3de1ba140000 pid=5306 execve guuid=ac4dd46f-1d00-0000-12eb-3de1bc140000 pid=5308 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ac4dd46f-1d00-0000-12eb-3de1bc140000 pid=5308 execve guuid=c972ad70-1d00-0000-12eb-3de1be140000 pid=5310 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c972ad70-1d00-0000-12eb-3de1be140000 pid=5310 execve guuid=1b9f8671-1d00-0000-12eb-3de1c0140000 pid=5312 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1b9f8671-1d00-0000-12eb-3de1c0140000 pid=5312 execve guuid=338c5572-1d00-0000-12eb-3de1c2140000 pid=5314 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=338c5572-1d00-0000-12eb-3de1c2140000 pid=5314 execve guuid=ce872973-1d00-0000-12eb-3de1c4140000 pid=5316 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ce872973-1d00-0000-12eb-3de1c4140000 pid=5316 execve guuid=42cd0874-1d00-0000-12eb-3de1c6140000 pid=5318 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=42cd0874-1d00-0000-12eb-3de1c6140000 pid=5318 execve guuid=17e1dd74-1d00-0000-12eb-3de1c8140000 pid=5320 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=17e1dd74-1d00-0000-12eb-3de1c8140000 pid=5320 execve guuid=42450da2-1e00-0000-12eb-3de1cf140000 pid=5327 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=42450da2-1e00-0000-12eb-3de1cf140000 pid=5327 execve guuid=d62971a4-1e00-0000-12eb-3de1d1140000 pid=5329 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d62971a4-1e00-0000-12eb-3de1d1140000 pid=5329 execve guuid=716e4ea5-1e00-0000-12eb-3de1d3140000 pid=5331 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=716e4ea5-1e00-0000-12eb-3de1d3140000 pid=5331 execve guuid=d9a72ea6-1e00-0000-12eb-3de1d5140000 pid=5333 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d9a72ea6-1e00-0000-12eb-3de1d5140000 pid=5333 execve guuid=e48020a7-1e00-0000-12eb-3de1d7140000 pid=5335 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=e48020a7-1e00-0000-12eb-3de1d7140000 pid=5335 execve guuid=964b02a8-1e00-0000-12eb-3de1d9140000 pid=5337 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=964b02a8-1e00-0000-12eb-3de1d9140000 pid=5337 execve guuid=6bb4dfa8-1e00-0000-12eb-3de1db140000 pid=5339 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=6bb4dfa8-1e00-0000-12eb-3de1db140000 pid=5339 execve guuid=f2e7bca9-1e00-0000-12eb-3de1dd140000 pid=5341 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f2e7bca9-1e00-0000-12eb-3de1dd140000 pid=5341 execve guuid=89ce9faa-1e00-0000-12eb-3de1df140000 pid=5343 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=89ce9faa-1e00-0000-12eb-3de1df140000 pid=5343 execve guuid=d0a1eed9-1f00-0000-12eb-3de1e1140000 pid=5345 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d0a1eed9-1f00-0000-12eb-3de1e1140000 pid=5345 execve guuid=122b6fde-1f00-0000-12eb-3de1e3140000 pid=5347 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=122b6fde-1f00-0000-12eb-3de1e3140000 pid=5347 execve guuid=917640e0-1f00-0000-12eb-3de1e5140000 pid=5349 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=917640e0-1f00-0000-12eb-3de1e5140000 pid=5349 execve guuid=f00354e2-1f00-0000-12eb-3de1e7140000 pid=5351 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f00354e2-1f00-0000-12eb-3de1e7140000 pid=5351 execve guuid=483131e4-1f00-0000-12eb-3de1e9140000 pid=5353 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=483131e4-1f00-0000-12eb-3de1e9140000 pid=5353 execve guuid=00493ce6-1f00-0000-12eb-3de1eb140000 pid=5355 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=00493ce6-1f00-0000-12eb-3de1eb140000 pid=5355 execve guuid=c80a0ae8-1f00-0000-12eb-3de1ed140000 pid=5357 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c80a0ae8-1f00-0000-12eb-3de1ed140000 pid=5357 execve guuid=1e0fcfe9-1f00-0000-12eb-3de1ef140000 pid=5359 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1e0fcfe9-1f00-0000-12eb-3de1ef140000 pid=5359 execve guuid=38d141eb-1f00-0000-12eb-3de1f1140000 pid=5361 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=38d141eb-1f00-0000-12eb-3de1f1140000 pid=5361 execve guuid=39b5171b-2100-0000-12eb-3de1f3140000 pid=5363 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=39b5171b-2100-0000-12eb-3de1f3140000 pid=5363 execve guuid=a633a01f-2100-0000-12eb-3de1f5140000 pid=5365 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=a633a01f-2100-0000-12eb-3de1f5140000 pid=5365 execve guuid=fd1a3421-2100-0000-12eb-3de1f7140000 pid=5367 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=fd1a3421-2100-0000-12eb-3de1f7140000 pid=5367 execve guuid=f4e9ec22-2100-0000-12eb-3de1f9140000 pid=5369 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f4e9ec22-2100-0000-12eb-3de1f9140000 pid=5369 execve guuid=350fa324-2100-0000-12eb-3de1fb140000 pid=5371 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=350fa324-2100-0000-12eb-3de1fb140000 pid=5371 execve guuid=c96c6326-2100-0000-12eb-3de1fd140000 pid=5373 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c96c6326-2100-0000-12eb-3de1fd140000 pid=5373 execve guuid=305f1928-2100-0000-12eb-3de1ff140000 pid=5375 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=305f1928-2100-0000-12eb-3de1ff140000 pid=5375 execve guuid=7137d629-2100-0000-12eb-3de101150000 pid=5377 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=7137d629-2100-0000-12eb-3de101150000 pid=5377 execve guuid=53838c2b-2100-0000-12eb-3de103150000 pid=5379 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=53838c2b-2100-0000-12eb-3de103150000 pid=5379 execve guuid=6d7ae75b-2200-0000-12eb-3de105150000 pid=5381 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=6d7ae75b-2200-0000-12eb-3de105150000 pid=5381 execve guuid=094b6f60-2200-0000-12eb-3de107150000 pid=5383 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=094b6f60-2200-0000-12eb-3de107150000 pid=5383 execve guuid=692e1d62-2200-0000-12eb-3de109150000 pid=5385 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=692e1d62-2200-0000-12eb-3de109150000 pid=5385 execve guuid=ff42b063-2200-0000-12eb-3de10b150000 pid=5387 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ff42b063-2200-0000-12eb-3de10b150000 pid=5387 execve guuid=00f35e65-2200-0000-12eb-3de10d150000 pid=5389 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=00f35e65-2200-0000-12eb-3de10d150000 pid=5389 execve guuid=1a802367-2200-0000-12eb-3de10f150000 pid=5391 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1a802367-2200-0000-12eb-3de10f150000 pid=5391 execve guuid=582ad868-2200-0000-12eb-3de111150000 pid=5393 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=582ad868-2200-0000-12eb-3de111150000 pid=5393 execve guuid=b410976a-2200-0000-12eb-3de113150000 pid=5395 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=b410976a-2200-0000-12eb-3de113150000 pid=5395 execve guuid=0da12f6c-2200-0000-12eb-3de115150000 pid=5397 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=0da12f6c-2200-0000-12eb-3de115150000 pid=5397 execve guuid=8680659c-2300-0000-12eb-3de117150000 pid=5399 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=8680659c-2300-0000-12eb-3de117150000 pid=5399 execve guuid=b6a7f9a0-2300-0000-12eb-3de119150000 pid=5401 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=b6a7f9a0-2300-0000-12eb-3de119150000 pid=5401 execve guuid=eaba99a2-2300-0000-12eb-3de11b150000 pid=5403 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=eaba99a2-2300-0000-12eb-3de11b150000 pid=5403 execve guuid=55b853a4-2300-0000-12eb-3de11d150000 pid=5405 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=55b853a4-2300-0000-12eb-3de11d150000 pid=5405 execve guuid=f2d0f0a5-2300-0000-12eb-3de11f150000 pid=5407 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f2d0f0a5-2300-0000-12eb-3de11f150000 pid=5407 execve guuid=45a3a7a7-2300-0000-12eb-3de121150000 pid=5409 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=45a3a7a7-2300-0000-12eb-3de121150000 pid=5409 execve guuid=53b572a9-2300-0000-12eb-3de123150000 pid=5411 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=53b572a9-2300-0000-12eb-3de123150000 pid=5411 execve guuid=7c1a27ab-2300-0000-12eb-3de125150000 pid=5413 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=7c1a27ab-2300-0000-12eb-3de125150000 pid=5413 execve guuid=aa99d8ac-2300-0000-12eb-3de127150000 pid=5415 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=aa99d8ac-2300-0000-12eb-3de127150000 pid=5415 execve guuid=ac3ae2dc-2400-0000-12eb-3de129150000 pid=5417 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ac3ae2dc-2400-0000-12eb-3de129150000 pid=5417 execve guuid=1fedf6e1-2400-0000-12eb-3de12b150000 pid=5419 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1fedf6e1-2400-0000-12eb-3de12b150000 pid=5419 execve guuid=f506a5e3-2400-0000-12eb-3de12d150000 pid=5421 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f506a5e3-2400-0000-12eb-3de12d150000 pid=5421 execve guuid=9b3699e5-2400-0000-12eb-3de12f150000 pid=5423 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=9b3699e5-2400-0000-12eb-3de12f150000 pid=5423 execve guuid=76e4fbe6-2400-0000-12eb-3de131150000 pid=5425 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=76e4fbe6-2400-0000-12eb-3de131150000 pid=5425 execve guuid=5a4669e8-2400-0000-12eb-3de133150000 pid=5427 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=5a4669e8-2400-0000-12eb-3de133150000 pid=5427 execve guuid=a2a64eea-2400-0000-12eb-3de135150000 pid=5429 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=a2a64eea-2400-0000-12eb-3de135150000 pid=5429 execve guuid=eaebd0eb-2400-0000-12eb-3de137150000 pid=5431 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=eaebd0eb-2400-0000-12eb-3de137150000 pid=5431 execve guuid=afa450ed-2400-0000-12eb-3de139150000 pid=5433 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=afa450ed-2400-0000-12eb-3de139150000 pid=5433 execve guuid=94a0391b-2600-0000-12eb-3de13b150000 pid=5435 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=94a0391b-2600-0000-12eb-3de13b150000 pid=5435 execve guuid=dc209d1f-2600-0000-12eb-3de13d150000 pid=5437 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=dc209d1f-2600-0000-12eb-3de13d150000 pid=5437 execve guuid=11477820-2600-0000-12eb-3de13f150000 pid=5439 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=11477820-2600-0000-12eb-3de13f150000 pid=5439 execve guuid=55d54c21-2600-0000-12eb-3de141150000 pid=5441 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=55d54c21-2600-0000-12eb-3de141150000 pid=5441 execve guuid=97332822-2600-0000-12eb-3de143150000 pid=5443 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=97332822-2600-0000-12eb-3de143150000 pid=5443 execve guuid=c0e12023-2600-0000-12eb-3de145150000 pid=5445 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c0e12023-2600-0000-12eb-3de145150000 pid=5445 execve guuid=d461f423-2600-0000-12eb-3de147150000 pid=5447 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d461f423-2600-0000-12eb-3de147150000 pid=5447 execve guuid=f6b2f624-2600-0000-12eb-3de149150000 pid=5449 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=f6b2f624-2600-0000-12eb-3de149150000 pid=5449 execve guuid=c607d225-2600-0000-12eb-3de14b150000 pid=5451 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c607d225-2600-0000-12eb-3de14b150000 pid=5451 execve guuid=1a1a0653-2700-0000-12eb-3de14d150000 pid=5453 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=1a1a0653-2700-0000-12eb-3de14d150000 pid=5453 execve guuid=ef5faa58-2700-0000-12eb-3de150150000 pid=5456 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=ef5faa58-2700-0000-12eb-3de150150000 pid=5456 execve guuid=c6558959-2700-0000-12eb-3de153150000 pid=5459 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=c6558959-2700-0000-12eb-3de153150000 pid=5459 execve guuid=d7e0945a-2700-0000-12eb-3de155150000 pid=5461 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d7e0945a-2700-0000-12eb-3de155150000 pid=5461 execve guuid=a658365c-2700-0000-12eb-3de157150000 pid=5463 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=a658365c-2700-0000-12eb-3de157150000 pid=5463 execve guuid=d8f11f5d-2700-0000-12eb-3de159150000 pid=5465 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=d8f11f5d-2700-0000-12eb-3de159150000 pid=5465 execve guuid=a61be75d-2700-0000-12eb-3de15b150000 pid=5467 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=a61be75d-2700-0000-12eb-3de15b150000 pid=5467 execve guuid=6a77b95e-2700-0000-12eb-3de15d150000 pid=5469 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=6a77b95e-2700-0000-12eb-3de15d150000 pid=5469 execve guuid=21bf7f5f-2700-0000-12eb-3de15f150000 pid=5471 /usr/bin/dash guuid=e194a97c-1900-0000-12eb-3de1a90b0000 pid=2985->guuid=21bf7f5f-2700-0000-12eb-3de15f150000 pid=5471 execve guuid=e07d307d-1900-0000-12eb-3de1af0b0000 pid=2991 /usr/bin/wget dns net send-data guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987->guuid=e07d307d-1900-0000-12eb-3de1af0b0000 pid=2991 execve guuid=d80d7883-1900-0000-12eb-3de1bc0b0000 pid=3004 /usr/bin/chmod guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987->guuid=d80d7883-1900-0000-12eb-3de1bc0b0000 pid=3004 execve guuid=5d87b283-1900-0000-12eb-3de1bd0b0000 pid=3005 /home/sandbox/..... guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987->guuid=5d87b283-1900-0000-12eb-3de1bd0b0000 pid=3005 execve guuid=b4138384-1900-0000-12eb-3de1c30b0000 pid=3011 /usr/bin/rm delete-file guuid=3ae6ae7c-1900-0000-12eb-3de1ab0b0000 pid=2987->guuid=b4138384-1900-0000-12eb-3de1c30b0000 pid=3011 execve guuid=0fb0c87c-1900-0000-12eb-3de1ae0b0000 pid=2990 /tmp/sample.bin net send-data zombie guuid=08d2c07c-1900-0000-12eb-3de1ad0b0000 pid=2989->guuid=0fb0c87c-1900-0000-12eb-3de1ae0b0000 pid=2990 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=0fb0c87c-1900-0000-12eb-3de1ae0b0000 pid=2990->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e07d307d-1900-0000-12eb-3de1af0b0000 pid=2991->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=746101af-1900-0000-12eb-3de1270c0000 pid=3111 /usr/bin/pgrep guuid=fd0ec3ae-1900-0000-12eb-3de1250c0000 pid=3109->guuid=746101af-1900-0000-12eb-3de1270c0000 pid=3111 execve guuid=771d5ab2-1900-0000-12eb-3de1310c0000 pid=3121 /usr/bin/killall guuid=0a6e24b2-1900-0000-12eb-3de12f0c0000 pid=3119->guuid=771d5ab2-1900-0000-12eb-3de1310c0000 pid=3121 execve guuid=c58c8fb3-1900-0000-12eb-3de1370c0000 pid=3127 /usr/bin/killall guuid=1b6c42b3-1900-0000-12eb-3de1350c0000 pid=3125->guuid=c58c8fb3-1900-0000-12eb-3de1370c0000 pid=3127 execve guuid=783d66b4-1900-0000-12eb-3de13c0c0000 pid=3132 /usr/bin/killall guuid=4c523db4-1900-0000-12eb-3de13b0c0000 pid=3131->guuid=783d66b4-1900-0000-12eb-3de13c0c0000 pid=3132 execve guuid=e7a63eb5-1900-0000-12eb-3de1410c0000 pid=3137 /usr/bin/killall guuid=13de10b5-1900-0000-12eb-3de1400c0000 pid=3136->guuid=e7a63eb5-1900-0000-12eb-3de1410c0000 pid=3137 execve guuid=5abb1ab6-1900-0000-12eb-3de1460c0000 pid=3142 /usr/bin/killall guuid=c421edb5-1900-0000-12eb-3de1450c0000 pid=3141->guuid=5abb1ab6-1900-0000-12eb-3de1460c0000 pid=3142 execve guuid=f2a928b7-1900-0000-12eb-3de14b0c0000 pid=3147 /usr/bin/killall guuid=129efdb6-1900-0000-12eb-3de14a0c0000 pid=3146->guuid=f2a928b7-1900-0000-12eb-3de14b0c0000 pid=3147 execve guuid=a66447b8-1900-0000-12eb-3de1510c0000 pid=3153 /usr/bin/killall guuid=cd7d1eb8-1900-0000-12eb-3de14f0c0000 pid=3151->guuid=a66447b8-1900-0000-12eb-3de1510c0000 pid=3153 execve guuid=77e01cb9-1900-0000-12eb-3de1560c0000 pid=3158 /usr/bin/killall guuid=ab2bf2b8-1900-0000-12eb-3de1550c0000 pid=3157->guuid=77e01cb9-1900-0000-12eb-3de1560c0000 pid=3158 execve guuid=863e7be7-1a00-0000-12eb-3de1e70e0000 pid=3815 /usr/bin/pgrep guuid=51ba24e7-1a00-0000-12eb-3de1e60e0000 pid=3814->guuid=863e7be7-1a00-0000-12eb-3de1e70e0000 pid=3815 execve guuid=b8a1b0ea-1a00-0000-12eb-3de1f70e0000 pid=3831 /usr/bin/killall guuid=2ad182ea-1a00-0000-12eb-3de1f50e0000 pid=3829->guuid=b8a1b0ea-1a00-0000-12eb-3de1f70e0000 pid=3831 execve guuid=b94963ec-1a00-0000-12eb-3de1010f0000 pid=3841 /usr/bin/killall guuid=f82e2dec-1a00-0000-12eb-3de1000f0000 pid=3840->guuid=b94963ec-1a00-0000-12eb-3de1010f0000 pid=3841 execve guuid=fd16f1ed-1a00-0000-12eb-3de1090f0000 pid=3849 /usr/bin/killall guuid=e345c0ed-1a00-0000-12eb-3de1070f0000 pid=3847->guuid=fd16f1ed-1a00-0000-12eb-3de1090f0000 pid=3849 execve guuid=47eb3cef-1a00-0000-12eb-3de1110f0000 pid=3857 /usr/bin/killall guuid=48960aef-1a00-0000-12eb-3de10e0f0000 pid=3854->guuid=47eb3cef-1a00-0000-12eb-3de1110f0000 pid=3857 execve guuid=b9208df0-1a00-0000-12eb-3de1160f0000 pid=3862 /usr/bin/killall guuid=47b44af0-1a00-0000-12eb-3de1150f0000 pid=3861->guuid=b9208df0-1a00-0000-12eb-3de1160f0000 pid=3862 execve guuid=94d8adf1-1a00-0000-12eb-3de11f0f0000 pid=3871 /usr/bin/killall guuid=8b6c81f1-1a00-0000-12eb-3de11e0f0000 pid=3870->guuid=94d8adf1-1a00-0000-12eb-3de11f0f0000 pid=3871 execve guuid=bbb6dbf2-1a00-0000-12eb-3de1250f0000 pid=3877 /usr/bin/killall guuid=af5794f2-1a00-0000-12eb-3de1230f0000 pid=3875->guuid=bbb6dbf2-1a00-0000-12eb-3de1250f0000 pid=3877 execve guuid=326fd3f3-1a00-0000-12eb-3de12a0f0000 pid=3882 /usr/bin/killall guuid=dc1fa4f3-1a00-0000-12eb-3de1280f0000 pid=3880->guuid=326fd3f3-1a00-0000-12eb-3de12a0f0000 pid=3882 execve guuid=1cedba22-1c00-0000-12eb-3de17d120000 pid=4733 /usr/bin/pgrep guuid=91219022-1c00-0000-12eb-3de17b120000 pid=4731->guuid=1cedba22-1c00-0000-12eb-3de17d120000 pid=4733 execve guuid=f9997c26-1c00-0000-12eb-3de18f120000 pid=4751 /usr/bin/killall guuid=dad14f26-1c00-0000-12eb-3de18d120000 pid=4749->guuid=f9997c26-1c00-0000-12eb-3de18f120000 pid=4751 execve guuid=733a5027-1c00-0000-12eb-3de195120000 pid=4757 /usr/bin/killall guuid=b0f02627-1c00-0000-12eb-3de193120000 pid=4755->guuid=733a5027-1c00-0000-12eb-3de195120000 pid=4757 execve guuid=4aa51f28-1c00-0000-12eb-3de19c120000 pid=4764 /usr/bin/killall guuid=02b0f627-1c00-0000-12eb-3de19b120000 pid=4763->guuid=4aa51f28-1c00-0000-12eb-3de19c120000 pid=4764 execve guuid=dd2af028-1c00-0000-12eb-3de1a4120000 pid=4772 /usr/bin/killall guuid=1574c628-1c00-0000-12eb-3de1a0120000 pid=4768->guuid=dd2af028-1c00-0000-12eb-3de1a4120000 pid=4772 execve guuid=0051df29-1c00-0000-12eb-3de1ab120000 pid=4779 /usr/bin/killall guuid=3a27b929-1c00-0000-12eb-3de1a9120000 pid=4777->guuid=0051df29-1c00-0000-12eb-3de1ab120000 pid=4779 execve guuid=0862de2a-1c00-0000-12eb-3de1b2120000 pid=4786 /usr/bin/killall guuid=55a5b62a-1c00-0000-12eb-3de1b0120000 pid=4784->guuid=0862de2a-1c00-0000-12eb-3de1b2120000 pid=4786 execve guuid=5fbd222c-1c00-0000-12eb-3de1bc120000 pid=4796 /usr/bin/killall guuid=11d7fa2b-1c00-0000-12eb-3de1bb120000 pid=4795->guuid=5fbd222c-1c00-0000-12eb-3de1bc120000 pid=4796 execve guuid=767be72c-1c00-0000-12eb-3de1c1120000 pid=4801 /usr/bin/killall guuid=01b1ba2c-1c00-0000-12eb-3de1c0120000 pid=4800->guuid=767be72c-1c00-0000-12eb-3de1c1120000 pid=4801 execve guuid=aa64036c-1d00-0000-12eb-3de1b8140000 pid=5304 /usr/bin/pgrep guuid=2949c66b-1d00-0000-12eb-3de1b7140000 pid=5303->guuid=aa64036c-1d00-0000-12eb-3de1b8140000 pid=5304 execve guuid=28e70c6f-1d00-0000-12eb-3de1bb140000 pid=5307 /usr/bin/killall guuid=c378dd6e-1d00-0000-12eb-3de1ba140000 pid=5306->guuid=28e70c6f-1d00-0000-12eb-3de1bb140000 pid=5307 execve guuid=6cf50170-1d00-0000-12eb-3de1bd140000 pid=5309 /usr/bin/killall guuid=ac4dd46f-1d00-0000-12eb-3de1bc140000 pid=5308->guuid=6cf50170-1d00-0000-12eb-3de1bd140000 pid=5309 execve guuid=b966d870-1d00-0000-12eb-3de1bf140000 pid=5311 /usr/bin/killall guuid=c972ad70-1d00-0000-12eb-3de1be140000 pid=5310->guuid=b966d870-1d00-0000-12eb-3de1bf140000 pid=5311 execve guuid=adc9ad71-1d00-0000-12eb-3de1c1140000 pid=5313 /usr/bin/killall guuid=1b9f8671-1d00-0000-12eb-3de1c0140000 pid=5312->guuid=adc9ad71-1d00-0000-12eb-3de1c1140000 pid=5313 execve guuid=3d937c72-1d00-0000-12eb-3de1c3140000 pid=5315 /usr/bin/killall guuid=338c5572-1d00-0000-12eb-3de1c2140000 pid=5314->guuid=3d937c72-1d00-0000-12eb-3de1c3140000 pid=5315 execve guuid=661a5673-1d00-0000-12eb-3de1c5140000 pid=5317 /usr/bin/killall guuid=ce872973-1d00-0000-12eb-3de1c4140000 pid=5316->guuid=661a5673-1d00-0000-12eb-3de1c5140000 pid=5317 execve guuid=c9fd3174-1d00-0000-12eb-3de1c7140000 pid=5319 /usr/bin/killall guuid=42cd0874-1d00-0000-12eb-3de1c6140000 pid=5318->guuid=c9fd3174-1d00-0000-12eb-3de1c7140000 pid=5319 execve guuid=0fb80875-1d00-0000-12eb-3de1c9140000 pid=5321 /usr/bin/killall guuid=17e1dd74-1d00-0000-12eb-3de1c8140000 pid=5320->guuid=0fb80875-1d00-0000-12eb-3de1c9140000 pid=5321 execve guuid=5f2b40a2-1e00-0000-12eb-3de1d0140000 pid=5328 /usr/bin/pgrep guuid=42450da2-1e00-0000-12eb-3de1cf140000 pid=5327->guuid=5f2b40a2-1e00-0000-12eb-3de1d0140000 pid=5328 execve guuid=db63a2a4-1e00-0000-12eb-3de1d2140000 pid=5330 /usr/bin/killall guuid=d62971a4-1e00-0000-12eb-3de1d1140000 pid=5329->guuid=db63a2a4-1e00-0000-12eb-3de1d2140000 pid=5330 execve guuid=56ef7fa5-1e00-0000-12eb-3de1d4140000 pid=5332 /usr/bin/killall guuid=716e4ea5-1e00-0000-12eb-3de1d3140000 pid=5331->guuid=56ef7fa5-1e00-0000-12eb-3de1d4140000 pid=5332 execve guuid=e59568a6-1e00-0000-12eb-3de1d6140000 pid=5334 /usr/bin/killall guuid=d9a72ea6-1e00-0000-12eb-3de1d5140000 pid=5333->guuid=e59568a6-1e00-0000-12eb-3de1d6140000 pid=5334 execve guuid=3c8556a7-1e00-0000-12eb-3de1d8140000 pid=5336 /usr/bin/killall guuid=e48020a7-1e00-0000-12eb-3de1d7140000 pid=5335->guuid=3c8556a7-1e00-0000-12eb-3de1d8140000 pid=5336 execve guuid=d1e631a8-1e00-0000-12eb-3de1da140000 pid=5338 /usr/bin/killall guuid=964b02a8-1e00-0000-12eb-3de1d9140000 pid=5337->guuid=d1e631a8-1e00-0000-12eb-3de1da140000 pid=5338 execve guuid=c87210a9-1e00-0000-12eb-3de1dc140000 pid=5340 /usr/bin/killall guuid=6bb4dfa8-1e00-0000-12eb-3de1db140000 pid=5339->guuid=c87210a9-1e00-0000-12eb-3de1dc140000 pid=5340 execve guuid=4ef2e8a9-1e00-0000-12eb-3de1de140000 pid=5342 /usr/bin/killall guuid=f2e7bca9-1e00-0000-12eb-3de1dd140000 pid=5341->guuid=4ef2e8a9-1e00-0000-12eb-3de1de140000 pid=5342 execve guuid=3e1ad4aa-1e00-0000-12eb-3de1e0140000 pid=5344 /usr/bin/killall guuid=89ce9faa-1e00-0000-12eb-3de1df140000 pid=5343->guuid=3e1ad4aa-1e00-0000-12eb-3de1e0140000 pid=5344 execve guuid=b0fc5bda-1f00-0000-12eb-3de1e2140000 pid=5346 /usr/bin/pgrep guuid=d0a1eed9-1f00-0000-12eb-3de1e1140000 pid=5345->guuid=b0fc5bda-1f00-0000-12eb-3de1e2140000 pid=5346 execve guuid=c163aade-1f00-0000-12eb-3de1e4140000 pid=5348 /usr/bin/killall guuid=122b6fde-1f00-0000-12eb-3de1e3140000 pid=5347->guuid=c163aade-1f00-0000-12eb-3de1e4140000 pid=5348 execve guuid=b727b2e0-1f00-0000-12eb-3de1e6140000 pid=5350 /usr/bin/killall guuid=917640e0-1f00-0000-12eb-3de1e5140000 pid=5349->guuid=b727b2e0-1f00-0000-12eb-3de1e6140000 pid=5350 execve guuid=06bcb2e2-1f00-0000-12eb-3de1e8140000 pid=5352 /usr/bin/killall guuid=f00354e2-1f00-0000-12eb-3de1e7140000 pid=5351->guuid=06bcb2e2-1f00-0000-12eb-3de1e8140000 pid=5352 execve guuid=32f086e4-1f00-0000-12eb-3de1ea140000 pid=5354 /usr/bin/killall guuid=483131e4-1f00-0000-12eb-3de1e9140000 pid=5353->guuid=32f086e4-1f00-0000-12eb-3de1ea140000 pid=5354 execve guuid=246697e6-1f00-0000-12eb-3de1ec140000 pid=5356 /usr/bin/killall guuid=00493ce6-1f00-0000-12eb-3de1eb140000 pid=5355->guuid=246697e6-1f00-0000-12eb-3de1ec140000 pid=5356 execve guuid=7ac762e8-1f00-0000-12eb-3de1ee140000 pid=5358 /usr/bin/killall guuid=c80a0ae8-1f00-0000-12eb-3de1ed140000 pid=5357->guuid=7ac762e8-1f00-0000-12eb-3de1ee140000 pid=5358 execve guuid=25952aea-1f00-0000-12eb-3de1f0140000 pid=5360 /usr/bin/killall guuid=1e0fcfe9-1f00-0000-12eb-3de1ef140000 pid=5359->guuid=25952aea-1f00-0000-12eb-3de1f0140000 pid=5360 execve guuid=4a819aeb-1f00-0000-12eb-3de1f2140000 pid=5362 /usr/bin/killall guuid=38d141eb-1f00-0000-12eb-3de1f1140000 pid=5361->guuid=4a819aeb-1f00-0000-12eb-3de1f2140000 pid=5362 execve guuid=3393721b-2100-0000-12eb-3de1f4140000 pid=5364 /usr/bin/pgrep guuid=39b5171b-2100-0000-12eb-3de1f3140000 pid=5363->guuid=3393721b-2100-0000-12eb-3de1f4140000 pid=5364 execve guuid=1c47e51f-2100-0000-12eb-3de1f6140000 pid=5366 /usr/bin/killall guuid=a633a01f-2100-0000-12eb-3de1f5140000 pid=5365->guuid=1c47e51f-2100-0000-12eb-3de1f6140000 pid=5366 execve guuid=5af58921-2100-0000-12eb-3de1f8140000 pid=5368 /usr/bin/killall guuid=fd1a3421-2100-0000-12eb-3de1f7140000 pid=5367->guuid=5af58921-2100-0000-12eb-3de1f8140000 pid=5368 execve guuid=da724523-2100-0000-12eb-3de1fa140000 pid=5370 /usr/bin/killall guuid=f4e9ec22-2100-0000-12eb-3de1f9140000 pid=5369->guuid=da724523-2100-0000-12eb-3de1fa140000 pid=5370 execve guuid=a1ebf724-2100-0000-12eb-3de1fc140000 pid=5372 /usr/bin/killall guuid=350fa324-2100-0000-12eb-3de1fb140000 pid=5371->guuid=a1ebf724-2100-0000-12eb-3de1fc140000 pid=5372 execve guuid=9f5cbb26-2100-0000-12eb-3de1fe140000 pid=5374 /usr/bin/killall guuid=c96c6326-2100-0000-12eb-3de1fd140000 pid=5373->guuid=9f5cbb26-2100-0000-12eb-3de1fe140000 pid=5374 execve guuid=4b987528-2100-0000-12eb-3de100150000 pid=5376 /usr/bin/killall guuid=305f1928-2100-0000-12eb-3de1ff140000 pid=5375->guuid=4b987528-2100-0000-12eb-3de100150000 pid=5376 execve guuid=ac5e352a-2100-0000-12eb-3de102150000 pid=5378 /usr/bin/killall guuid=7137d629-2100-0000-12eb-3de101150000 pid=5377->guuid=ac5e352a-2100-0000-12eb-3de102150000 pid=5378 execve guuid=9e60db2b-2100-0000-12eb-3de104150000 pid=5380 /usr/bin/killall guuid=53838c2b-2100-0000-12eb-3de103150000 pid=5379->guuid=9e60db2b-2100-0000-12eb-3de104150000 pid=5380 execve guuid=e961525c-2200-0000-12eb-3de106150000 pid=5382 /usr/bin/pgrep guuid=6d7ae75b-2200-0000-12eb-3de105150000 pid=5381->guuid=e961525c-2200-0000-12eb-3de106150000 pid=5382 execve guuid=6e7bcb60-2200-0000-12eb-3de108150000 pid=5384 /usr/bin/killall guuid=094b6f60-2200-0000-12eb-3de107150000 pid=5383->guuid=6e7bcb60-2200-0000-12eb-3de108150000 pid=5384 execve guuid=70ee7062-2200-0000-12eb-3de10a150000 pid=5386 /usr/bin/killall guuid=692e1d62-2200-0000-12eb-3de109150000 pid=5385->guuid=70ee7062-2200-0000-12eb-3de10a150000 pid=5386 execve guuid=f8240664-2200-0000-12eb-3de10c150000 pid=5388 /usr/bin/killall guuid=ff42b063-2200-0000-12eb-3de10b150000 pid=5387->guuid=f8240664-2200-0000-12eb-3de10c150000 pid=5388 execve guuid=6a69cb65-2200-0000-12eb-3de10e150000 pid=5390 /usr/bin/killall guuid=00f35e65-2200-0000-12eb-3de10d150000 pid=5389->guuid=6a69cb65-2200-0000-12eb-3de10e150000 pid=5390 execve guuid=3cb97d67-2200-0000-12eb-3de110150000 pid=5392 /usr/bin/killall guuid=1a802367-2200-0000-12eb-3de10f150000 pid=5391->guuid=3cb97d67-2200-0000-12eb-3de110150000 pid=5392 execve guuid=d1b43f69-2200-0000-12eb-3de112150000 pid=5394 /usr/bin/killall guuid=582ad868-2200-0000-12eb-3de111150000 pid=5393->guuid=d1b43f69-2200-0000-12eb-3de112150000 pid=5394 execve guuid=f504ed6a-2200-0000-12eb-3de114150000 pid=5396 /usr/bin/killall guuid=b410976a-2200-0000-12eb-3de113150000 pid=5395->guuid=f504ed6a-2200-0000-12eb-3de114150000 pid=5396 execve guuid=089c896c-2200-0000-12eb-3de116150000 pid=5398 /usr/bin/killall guuid=0da12f6c-2200-0000-12eb-3de115150000 pid=5397->guuid=089c896c-2200-0000-12eb-3de116150000 pid=5398 execve guuid=6c06be9c-2300-0000-12eb-3de118150000 pid=5400 /usr/bin/pgrep guuid=8680659c-2300-0000-12eb-3de117150000 pid=5399->guuid=6c06be9c-2300-0000-12eb-3de118150000 pid=5400 execve guuid=fdbc45a1-2300-0000-12eb-3de11a150000 pid=5402 /usr/bin/killall guuid=b6a7f9a0-2300-0000-12eb-3de119150000 pid=5401->guuid=fdbc45a1-2300-0000-12eb-3de11a150000 pid=5402 execve guuid=bf18fda2-2300-0000-12eb-3de11c150000 pid=5404 /usr/bin/killall guuid=eaba99a2-2300-0000-12eb-3de11b150000 pid=5403->guuid=bf18fda2-2300-0000-12eb-3de11c150000 pid=5404 execve guuid=3a9ba9a4-2300-0000-12eb-3de11e150000 pid=5406 /usr/bin/killall guuid=55b853a4-2300-0000-12eb-3de11d150000 pid=5405->guuid=3a9ba9a4-2300-0000-12eb-3de11e150000 pid=5406 execve guuid=d2404da6-2300-0000-12eb-3de120150000 pid=5408 /usr/bin/killall guuid=f2d0f0a5-2300-0000-12eb-3de11f150000 pid=5407->guuid=d2404da6-2300-0000-12eb-3de120150000 pid=5408 execve guuid=a59df6a7-2300-0000-12eb-3de122150000 pid=5410 /usr/bin/killall guuid=45a3a7a7-2300-0000-12eb-3de121150000 pid=5409->guuid=a59df6a7-2300-0000-12eb-3de122150000 pid=5410 execve guuid=d0f6d4a9-2300-0000-12eb-3de124150000 pid=5412 /usr/bin/killall guuid=53b572a9-2300-0000-12eb-3de123150000 pid=5411->guuid=d0f6d4a9-2300-0000-12eb-3de124150000 pid=5412 execve guuid=03ac81ab-2300-0000-12eb-3de126150000 pid=5414 /usr/bin/killall guuid=7c1a27ab-2300-0000-12eb-3de125150000 pid=5413->guuid=03ac81ab-2300-0000-12eb-3de126150000 pid=5414 execve guuid=86dd32ad-2300-0000-12eb-3de128150000 pid=5416 /usr/bin/killall guuid=aa99d8ac-2300-0000-12eb-3de127150000 pid=5415->guuid=86dd32ad-2300-0000-12eb-3de128150000 pid=5416 execve guuid=e6173add-2400-0000-12eb-3de12a150000 pid=5418 /usr/bin/pgrep guuid=ac3ae2dc-2400-0000-12eb-3de129150000 pid=5417->guuid=e6173add-2400-0000-12eb-3de12a150000 pid=5418 execve guuid=4ddb3fe2-2400-0000-12eb-3de12c150000 pid=5420 /usr/bin/killall guuid=1fedf6e1-2400-0000-12eb-3de12b150000 pid=5419->guuid=4ddb3fe2-2400-0000-12eb-3de12c150000 pid=5420 execve guuid=c40005e4-2400-0000-12eb-3de12e150000 pid=5422 /usr/bin/killall guuid=f506a5e3-2400-0000-12eb-3de12d150000 pid=5421->guuid=c40005e4-2400-0000-12eb-3de12e150000 pid=5422 execve guuid=42b3f2e5-2400-0000-12eb-3de130150000 pid=5424 /usr/bin/killall guuid=9b3699e5-2400-0000-12eb-3de12f150000 pid=5423->guuid=42b3f2e5-2400-0000-12eb-3de130150000 pid=5424 execve guuid=27ce50e7-2400-0000-12eb-3de132150000 pid=5426 /usr/bin/killall guuid=76e4fbe6-2400-0000-12eb-3de131150000 pid=5425->guuid=27ce50e7-2400-0000-12eb-3de132150000 pid=5426 execve guuid=7290b3e8-2400-0000-12eb-3de134150000 pid=5428 /usr/bin/killall guuid=5a4669e8-2400-0000-12eb-3de133150000 pid=5427->guuid=7290b3e8-2400-0000-12eb-3de134150000 pid=5428 execve guuid=e8bcbaea-2400-0000-12eb-3de136150000 pid=5430 /usr/bin/killall guuid=a2a64eea-2400-0000-12eb-3de135150000 pid=5429->guuid=e8bcbaea-2400-0000-12eb-3de136150000 pid=5430 execve guuid=61c736ec-2400-0000-12eb-3de138150000 pid=5432 /usr/bin/killall guuid=eaebd0eb-2400-0000-12eb-3de137150000 pid=5431->guuid=61c736ec-2400-0000-12eb-3de138150000 pid=5432 execve guuid=8ad899ed-2400-0000-12eb-3de13a150000 pid=5434 /usr/bin/killall guuid=afa450ed-2400-0000-12eb-3de139150000 pid=5433->guuid=8ad899ed-2400-0000-12eb-3de13a150000 pid=5434 execve guuid=72776d1b-2600-0000-12eb-3de13c150000 pid=5436 /usr/bin/pgrep guuid=94a0391b-2600-0000-12eb-3de13b150000 pid=5435->guuid=72776d1b-2600-0000-12eb-3de13c150000 pid=5436 execve guuid=477ad11f-2600-0000-12eb-3de13e150000 pid=5438 /usr/bin/killall guuid=dc209d1f-2600-0000-12eb-3de13d150000 pid=5437->guuid=477ad11f-2600-0000-12eb-3de13e150000 pid=5438 execve guuid=a97baa20-2600-0000-12eb-3de140150000 pid=5440 /usr/bin/killall guuid=11477820-2600-0000-12eb-3de13f150000 pid=5439->guuid=a97baa20-2600-0000-12eb-3de140150000 pid=5440 execve guuid=b5de7821-2600-0000-12eb-3de142150000 pid=5442 /usr/bin/killall guuid=55d54c21-2600-0000-12eb-3de141150000 pid=5441->guuid=b5de7821-2600-0000-12eb-3de142150000 pid=5442 execve guuid=36885622-2600-0000-12eb-3de144150000 pid=5444 /usr/bin/killall guuid=97332822-2600-0000-12eb-3de143150000 pid=5443->guuid=36885622-2600-0000-12eb-3de144150000 pid=5444 execve guuid=4bf65723-2600-0000-12eb-3de146150000 pid=5446 /usr/bin/killall guuid=c0e12023-2600-0000-12eb-3de145150000 pid=5445->guuid=4bf65723-2600-0000-12eb-3de146150000 pid=5446 execve guuid=589a1f24-2600-0000-12eb-3de148150000 pid=5448 /usr/bin/killall guuid=d461f423-2600-0000-12eb-3de147150000 pid=5447->guuid=589a1f24-2600-0000-12eb-3de148150000 pid=5448 execve guuid=80e73125-2600-0000-12eb-3de14a150000 pid=5450 /usr/bin/killall guuid=f6b2f624-2600-0000-12eb-3de149150000 pid=5449->guuid=80e73125-2600-0000-12eb-3de14a150000 pid=5450 execve guuid=350d0b26-2600-0000-12eb-3de14c150000 pid=5452 /usr/bin/killall guuid=c607d225-2600-0000-12eb-3de14b150000 pid=5451->guuid=350d0b26-2600-0000-12eb-3de14c150000 pid=5452 execve guuid=222e6b53-2700-0000-12eb-3de14e150000 pid=5454 /usr/bin/pgrep guuid=1a1a0653-2700-0000-12eb-3de14d150000 pid=5453->guuid=222e6b53-2700-0000-12eb-3de14e150000 pid=5454 execve guuid=de88dd58-2700-0000-12eb-3de152150000 pid=5458 /usr/bin/killall guuid=ef5faa58-2700-0000-12eb-3de150150000 pid=5456->guuid=de88dd58-2700-0000-12eb-3de152150000 pid=5458 execve guuid=e925b759-2700-0000-12eb-3de154150000 pid=5460 /usr/bin/killall guuid=c6558959-2700-0000-12eb-3de153150000 pid=5459->guuid=e925b759-2700-0000-12eb-3de154150000 pid=5460 execve guuid=d308265b-2700-0000-12eb-3de156150000 pid=5462 /usr/bin/killall guuid=d7e0945a-2700-0000-12eb-3de155150000 pid=5461->guuid=d308265b-2700-0000-12eb-3de156150000 pid=5462 execve guuid=2d54765c-2700-0000-12eb-3de158150000 pid=5464 /usr/bin/killall guuid=a658365c-2700-0000-12eb-3de157150000 pid=5463->guuid=2d54765c-2700-0000-12eb-3de158150000 pid=5464 execve guuid=bb284a5d-2700-0000-12eb-3de15a150000 pid=5466 /usr/bin/killall guuid=d8f11f5d-2700-0000-12eb-3de159150000 pid=5465->guuid=bb284a5d-2700-0000-12eb-3de15a150000 pid=5466 execve guuid=06f51b5e-2700-0000-12eb-3de15c150000 pid=5468 /usr/bin/killall guuid=a61be75d-2700-0000-12eb-3de15b150000 pid=5467->guuid=06f51b5e-2700-0000-12eb-3de15c150000 pid=5468 execve guuid=a034de5e-2700-0000-12eb-3de15e150000 pid=5470 /usr/bin/killall guuid=6a77b95e-2700-0000-12eb-3de15d150000 pid=5469->guuid=a034de5e-2700-0000-12eb-3de15e150000 pid=5470 execve guuid=7636b35f-2700-0000-12eb-3de160150000 pid=5472 /usr/bin/killall guuid=21bf7f5f-2700-0000-12eb-3de15f150000 pid=5471->guuid=7636b35f-2700-0000-12eb-3de160150000 pid=5472 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734336 Sample: cron.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 37 206.123.128.67, 51850, 51852, 51854 LEASEWEB-USA-NYC-11US United States 2->37 39 109.202.202.202, 80 INIT7CH Switzerland 2->39 41 3 other IPs or domains 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 cron.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 cron.elf 9->12         started        process6 process7 14 cron.elf sh 12->14         started        16 cron.elf sh 12->16         started        18 cron.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-11 23:11:05 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_83715433 Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_f51c5ac3 Linux_Trojan_Gafgyt_27de1106 Linux_Trojan_Gafgyt_1b2e2a3a Linux_Trojan_Gafgyt_9127f7be elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_1b2e2a3a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_27de1106
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_83715433
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9127f7be
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f51c5ac3
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf 8c40b12b75b8a2480dfd2930bcfcbf434d02c7fd9b4bd8252fe2d7239fa20a00

(this sample)

  
Delivery method
Distributed via web download

Comments