MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 9a4747fb4ca166cf3ba048b21b377a4a0748d0b0d388a3f183f9b9d14a69c00a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 9a4747fb4ca166cf3ba048b21b377a4a0748d0b0d388a3f183f9b9d14a69c00a
SHA3-384 hash: d8acbb880d7f6407cc23d590e4d3e2743081f666c715757f53068c3339aea775d9f1086b671038c1c9c97df82c35489e
SHA1 hash: cc9d499978e6c4c4b2db02dadaada2b3fdb0a2c9
MD5 hash: 69965a37592c156eaa799278828fd246
humanhash: charlie-louisiana-chicken-xray
File name:painbins.sh
Download: download sample
Signature Mirai
File size:3'621 bytes
First seen:2025-07-14 18:09:40 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:DXbjsMXbY0Xblx2c4+XbRo9YXb4txsLXbZ0XGXb0hhMXbqqEGXbQr9hUDXb79xX4:HDjL42i9A3LkhU3Q3UHZV+kTzzjybCoR
TLSH T14671B5CB11E71CB3BDE29A2BB67A684870E26A9F50C99F149CCCBCE6105DD09F091753
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://213.232.114.169/mips1f7072ebad1c250291f017280a187391b0d68c3794922704358f9d1be61ad5c8 Miraielf mirai ua-wget
http://213.232.114.169/mipsel006a4aa7cff6188a9909a4f920edda3f250e12889a23da4fa962f45c8b2eeb89 Miraielf mirai ua-wget
http://213.232.114.169/sh40515af001cfbc5f9643a35c2f4a87e7ffc5b966a49bf54e078ee5cb00792b285 Miraielf mirai ua-wget
http://213.232.114.169/x86_64557c3e6e7d59d96137630377e8a018a6725adec14b4fc861e636df8b1a15825c Miraielf mirai ua-wget
http://213.232.114.169/armv6l062f4c8cd05261b1e10a9b79c5a70eee7c5cde71f99ee9760a8490f7f347fc6d Miraielf mirai ua-wget
http://213.232.114.169/i6860ea7f9c899753840c12cc3132cc246663457e7f5adbfb3f42292443adf199110 Miraielf mirai ua-wget
http://213.232.114.169/powerpc0f84febd68bf405ce11e919846f7eac5d53e0a3901d0720bbd8998fb4b35e355 Miraimirai ua-wget
http://213.232.114.169/i5868ab5de147cccce1eccea9bd3503b08710b02605951c0c75554b53e492976038a Miraielf mirai ua-wget
http://213.232.114.169/m68k8743ee05aa26d3946bbcbf4c00fc19f1a39a051a5c69ae82ece778d1b3563731 Miraielf mirai ua-wget
http://213.232.114.169/sparcfedeed737e3ba9346f84a53808827e9f36851d8d9ee49c5dfcbb44bebfbcffb6 Miraielf mirai ua-wget
http://213.232.114.169/armv4lf9c0cd0ddb36a527080de2f95bf6f707f6a9fe210573aec3f89d0168a7b651f9 Gafgytelf gafgyt ua-wget
http://213.232.114.169/armv5l04e4727b0fe9af4c94417df2482a6463f2d80dcc6c116cf055c5f29d692d401a Gafgytelf gafgyt ua-wget
http://213.232.114.169/armv7l719e096fd74a1431123d6475f1427d93863dfa379757a08ab80568e79a48a311 Miraielf mirai ua-wget
http://213.232.114.169/i48614ee8dac8148d57fccb5f6d05dfb445642281c123d8cdf0c07b9dc8474fdd3d1 Miraielf mirai ua-wget
http://213.232.114.169/powerpc-440fpbef88844fa5733cfb644609f7862cab21c1aaf75102faf7fd6bc65713e37d46d Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=dcc8f5c9-1900-0000-33bf-c2dc0c0a0000 pid=2572 /usr/bin/sudo guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581 /tmp/sample.bin guuid=dcc8f5c9-1900-0000-33bf-c2dc0c0a0000 pid=2572->guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581 execve guuid=2acebdcc-1900-0000-33bf-c2dc170a0000 pid=2583 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=2acebdcc-1900-0000-33bf-c2dc170a0000 pid=2583 execve guuid=8409cfd5-1900-0000-33bf-c2dc340a0000 pid=2612 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=8409cfd5-1900-0000-33bf-c2dc340a0000 pid=2612 execve guuid=a762c5e3-1900-0000-33bf-c2dc540a0000 pid=2644 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=a762c5e3-1900-0000-33bf-c2dc540a0000 pid=2644 execve guuid=85741ce4-1900-0000-33bf-c2dc560a0000 pid=2646 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=85741ce4-1900-0000-33bf-c2dc560a0000 pid=2646 clone guuid=cab4dae4-1900-0000-33bf-c2dc5a0a0000 pid=2650 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=cab4dae4-1900-0000-33bf-c2dc5a0a0000 pid=2650 execve guuid=1ade29e5-1900-0000-33bf-c2dc5c0a0000 pid=2652 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=1ade29e5-1900-0000-33bf-c2dc5c0a0000 pid=2652 execve guuid=3d72a5eb-1900-0000-33bf-c2dc700a0000 pid=2672 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=3d72a5eb-1900-0000-33bf-c2dc700a0000 pid=2672 execve guuid=e1f27af3-1900-0000-33bf-c2dc860a0000 pid=2694 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=e1f27af3-1900-0000-33bf-c2dc860a0000 pid=2694 execve guuid=fc63b9f3-1900-0000-33bf-c2dc870a0000 pid=2695 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=fc63b9f3-1900-0000-33bf-c2dc870a0000 pid=2695 clone guuid=b143ebf4-1900-0000-33bf-c2dc8c0a0000 pid=2700 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=b143ebf4-1900-0000-33bf-c2dc8c0a0000 pid=2700 execve guuid=254a5af5-1900-0000-33bf-c2dc8e0a0000 pid=2702 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=254a5af5-1900-0000-33bf-c2dc8e0a0000 pid=2702 execve guuid=418009fc-1900-0000-33bf-c2dca50a0000 pid=2725 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=418009fc-1900-0000-33bf-c2dca50a0000 pid=2725 execve guuid=b86e0306-1a00-0000-33bf-c2dcb70a0000 pid=2743 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=b86e0306-1a00-0000-33bf-c2dcb70a0000 pid=2743 execve guuid=7c8f6b06-1a00-0000-33bf-c2dcb90a0000 pid=2745 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=7c8f6b06-1a00-0000-33bf-c2dcb90a0000 pid=2745 clone guuid=d63e5d07-1a00-0000-33bf-c2dcbd0a0000 pid=2749 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=d63e5d07-1a00-0000-33bf-c2dcbd0a0000 pid=2749 execve guuid=b3cf2308-1a00-0000-33bf-c2dcbf0a0000 pid=2751 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=b3cf2308-1a00-0000-33bf-c2dcbf0a0000 pid=2751 execve guuid=c657c40f-1a00-0000-33bf-c2dccd0a0000 pid=2765 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=c657c40f-1a00-0000-33bf-c2dccd0a0000 pid=2765 execve guuid=b5778819-1a00-0000-33bf-c2dcd80a0000 pid=2776 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=b5778819-1a00-0000-33bf-c2dcd80a0000 pid=2776 execve guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778 /tmp/x86_64 net guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778 execve guuid=70842628-1a00-0000-33bf-c2dc280b0000 pid=2856 /usr/bin/rm guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=70842628-1a00-0000-33bf-c2dc280b0000 pid=2856 execve guuid=dcc28d28-1a00-0000-33bf-c2dc290b0000 pid=2857 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=dcc28d28-1a00-0000-33bf-c2dc290b0000 pid=2857 execve guuid=db6bf62f-1a00-0000-33bf-c2dc350b0000 pid=2869 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=db6bf62f-1a00-0000-33bf-c2dc350b0000 pid=2869 execve guuid=8a22bb38-1a00-0000-33bf-c2dc450b0000 pid=2885 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=8a22bb38-1a00-0000-33bf-c2dc450b0000 pid=2885 execve guuid=88e30c39-1a00-0000-33bf-c2dc470b0000 pid=2887 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=88e30c39-1a00-0000-33bf-c2dc470b0000 pid=2887 clone guuid=1297b139-1a00-0000-33bf-c2dc490b0000 pid=2889 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=1297b139-1a00-0000-33bf-c2dc490b0000 pid=2889 execve guuid=9f01fe39-1a00-0000-33bf-c2dc4b0b0000 pid=2891 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=9f01fe39-1a00-0000-33bf-c2dc4b0b0000 pid=2891 execve guuid=ead89640-1a00-0000-33bf-c2dc5a0b0000 pid=2906 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ead89640-1a00-0000-33bf-c2dc5a0b0000 pid=2906 execve guuid=f8b88d48-1a00-0000-33bf-c2dc6c0b0000 pid=2924 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=f8b88d48-1a00-0000-33bf-c2dc6c0b0000 pid=2924 execve guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927 /tmp/i686 net guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927 execve guuid=71b44b52-1a00-0000-33bf-c2dcb90b0000 pid=3001 /usr/bin/rm guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=71b44b52-1a00-0000-33bf-c2dcb90b0000 pid=3001 execve guuid=ea8f9e52-1a00-0000-33bf-c2dcbb0b0000 pid=3003 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ea8f9e52-1a00-0000-33bf-c2dcbb0b0000 pid=3003 execve guuid=05a3b459-1a00-0000-33bf-c2dcc80b0000 pid=3016 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=05a3b459-1a00-0000-33bf-c2dcc80b0000 pid=3016 execve guuid=3d9c8b61-1a00-0000-33bf-c2dcdf0b0000 pid=3039 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=3d9c8b61-1a00-0000-33bf-c2dcdf0b0000 pid=3039 execve guuid=044bda61-1a00-0000-33bf-c2dce10b0000 pid=3041 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=044bda61-1a00-0000-33bf-c2dce10b0000 pid=3041 clone guuid=10a57762-1a00-0000-33bf-c2dce50b0000 pid=3045 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=10a57762-1a00-0000-33bf-c2dce50b0000 pid=3045 execve guuid=d8debd62-1a00-0000-33bf-c2dce60b0000 pid=3046 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=d8debd62-1a00-0000-33bf-c2dce60b0000 pid=3046 execve guuid=0a6a1069-1a00-0000-33bf-c2dcf50b0000 pid=3061 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=0a6a1069-1a00-0000-33bf-c2dcf50b0000 pid=3061 execve guuid=9c97a679-1a00-0000-33bf-c2dcff0b0000 pid=3071 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=9c97a679-1a00-0000-33bf-c2dcff0b0000 pid=3071 execve guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073 /tmp/i586 net guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073 execve guuid=ac37d584-1a00-0000-33bf-c2dc570c0000 pid=3159 /usr/bin/rm guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ac37d584-1a00-0000-33bf-c2dc570c0000 pid=3159 execve guuid=64061885-1a00-0000-33bf-c2dc590c0000 pid=3161 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=64061885-1a00-0000-33bf-c2dc590c0000 pid=3161 execve guuid=725ffd8b-1a00-0000-33bf-c2dc670c0000 pid=3175 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=725ffd8b-1a00-0000-33bf-c2dc670c0000 pid=3175 execve guuid=9c299d94-1a00-0000-33bf-c2dc7b0c0000 pid=3195 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=9c299d94-1a00-0000-33bf-c2dc7b0c0000 pid=3195 execve guuid=9399ea94-1a00-0000-33bf-c2dc7c0c0000 pid=3196 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=9399ea94-1a00-0000-33bf-c2dc7c0c0000 pid=3196 clone guuid=374f7d95-1a00-0000-33bf-c2dc800c0000 pid=3200 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=374f7d95-1a00-0000-33bf-c2dc800c0000 pid=3200 execve guuid=ff41e395-1a00-0000-33bf-c2dc820c0000 pid=3202 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ff41e395-1a00-0000-33bf-c2dc820c0000 pid=3202 execve guuid=2175ee9c-1a00-0000-33bf-c2dc940c0000 pid=3220 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=2175ee9c-1a00-0000-33bf-c2dc940c0000 pid=3220 execve guuid=92f39ea4-1a00-0000-33bf-c2dca70c0000 pid=3239 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=92f39ea4-1a00-0000-33bf-c2dca70c0000 pid=3239 execve guuid=ebbbf6a4-1a00-0000-33bf-c2dca90c0000 pid=3241 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ebbbf6a4-1a00-0000-33bf-c2dca90c0000 pid=3241 clone guuid=bbe1b9a5-1a00-0000-33bf-c2dcad0c0000 pid=3245 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=bbe1b9a5-1a00-0000-33bf-c2dcad0c0000 pid=3245 execve guuid=22f220a6-1a00-0000-33bf-c2dcaf0c0000 pid=3247 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=22f220a6-1a00-0000-33bf-c2dcaf0c0000 pid=3247 execve guuid=7c0d19ad-1a00-0000-33bf-c2dcbe0c0000 pid=3262 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=7c0d19ad-1a00-0000-33bf-c2dcbe0c0000 pid=3262 execve guuid=bab49fb4-1a00-0000-33bf-c2dcd00c0000 pid=3280 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=bab49fb4-1a00-0000-33bf-c2dcd00c0000 pid=3280 execve guuid=6f0704b5-1a00-0000-33bf-c2dcd20c0000 pid=3282 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=6f0704b5-1a00-0000-33bf-c2dcd20c0000 pid=3282 clone guuid=165ec3b5-1a00-0000-33bf-c2dcd60c0000 pid=3286 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=165ec3b5-1a00-0000-33bf-c2dcd60c0000 pid=3286 execve guuid=27733cb6-1a00-0000-33bf-c2dcd80c0000 pid=3288 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=27733cb6-1a00-0000-33bf-c2dcd80c0000 pid=3288 execve guuid=ec6686bd-1a00-0000-33bf-c2dcea0c0000 pid=3306 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ec6686bd-1a00-0000-33bf-c2dcea0c0000 pid=3306 execve guuid=aa4d68c5-1a00-0000-33bf-c2dcfd0c0000 pid=3325 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=aa4d68c5-1a00-0000-33bf-c2dcfd0c0000 pid=3325 execve guuid=2b90bac5-1a00-0000-33bf-c2dcfe0c0000 pid=3326 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=2b90bac5-1a00-0000-33bf-c2dcfe0c0000 pid=3326 clone guuid=ba20a3c6-1a00-0000-33bf-c2dc030d0000 pid=3331 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=ba20a3c6-1a00-0000-33bf-c2dc030d0000 pid=3331 execve guuid=281ef5c6-1a00-0000-33bf-c2dc050d0000 pid=3333 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=281ef5c6-1a00-0000-33bf-c2dc050d0000 pid=3333 execve guuid=21d8f4cd-1a00-0000-33bf-c2dc130d0000 pid=3347 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=21d8f4cd-1a00-0000-33bf-c2dc130d0000 pid=3347 execve guuid=cf1336d7-1a00-0000-33bf-c2dc270d0000 pid=3367 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=cf1336d7-1a00-0000-33bf-c2dc270d0000 pid=3367 execve guuid=c5a98cd7-1a00-0000-33bf-c2dc290d0000 pid=3369 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=c5a98cd7-1a00-0000-33bf-c2dc290d0000 pid=3369 clone guuid=f7914cd8-1a00-0000-33bf-c2dc2d0d0000 pid=3373 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=f7914cd8-1a00-0000-33bf-c2dc2d0d0000 pid=3373 execve guuid=2d1565dc-1a00-0000-33bf-c2dc380d0000 pid=3384 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=2d1565dc-1a00-0000-33bf-c2dc380d0000 pid=3384 execve guuid=86805ee3-1a00-0000-33bf-c2dc4b0d0000 pid=3403 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=86805ee3-1a00-0000-33bf-c2dc4b0d0000 pid=3403 execve guuid=3e3f84eb-1a00-0000-33bf-c2dc620d0000 pid=3426 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=3e3f84eb-1a00-0000-33bf-c2dc620d0000 pid=3426 execve guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427 /tmp/i486 net guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427 execve guuid=f89a93f3-1a00-0000-33bf-c2dcaa0d0000 pid=3498 /usr/bin/rm guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=f89a93f3-1a00-0000-33bf-c2dcaa0d0000 pid=3498 execve guuid=b03df4f3-1a00-0000-33bf-c2dcad0d0000 pid=3501 /usr/bin/wget net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=b03df4f3-1a00-0000-33bf-c2dcad0d0000 pid=3501 execve guuid=8f5076fa-1a00-0000-33bf-c2dcc00d0000 pid=3520 /usr/bin/curl net send-data write-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=8f5076fa-1a00-0000-33bf-c2dcc00d0000 pid=3520 execve guuid=01da8e01-1b00-0000-33bf-c2dcd30d0000 pid=3539 /usr/bin/chmod guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=01da8e01-1b00-0000-33bf-c2dcd30d0000 pid=3539 execve guuid=c344ec01-1b00-0000-33bf-c2dcd50d0000 pid=3541 /usr/bin/bash guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=c344ec01-1b00-0000-33bf-c2dcd50d0000 pid=3541 clone guuid=576c7902-1b00-0000-33bf-c2dcd90d0000 pid=3545 /usr/bin/rm delete-file guuid=4d5267cc-1900-0000-33bf-c2dc150a0000 pid=2581->guuid=576c7902-1b00-0000-33bf-c2dcd90d0000 pid=3545 execve d8eba8ce-adde-5f84-a2f4-d877f7f68596 213.232.114.169:80 guuid=2acebdcc-1900-0000-33bf-c2dc170a0000 pid=2583->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 134B guuid=8409cfd5-1900-0000-33bf-c2dc340a0000 pid=2612->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 83B guuid=1ade29e5-1900-0000-33bf-c2dc5c0a0000 pid=2652->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=3d72a5eb-1900-0000-33bf-c2dc700a0000 pid=2672->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B guuid=254a5af5-1900-0000-33bf-c2dc8e0a0000 pid=2702->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 133B guuid=418009fc-1900-0000-33bf-c2dca50a0000 pid=2725->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 82B guuid=b3cf2308-1a00-0000-33bf-c2dcbf0a0000 pid=2751->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=c657c40f-1a00-0000-33bf-c2dccd0a0000 pid=2765->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779 /tmp/x86_64 zombie guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779 clone guuid=625bd11a-1a00-0000-33bf-c2dcdc0a0000 pid=2780 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=625bd11a-1a00-0000-33bf-c2dcdc0a0000 pid=2780 execve guuid=ea60b51c-1a00-0000-33bf-c2dce20a0000 pid=2786 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=ea60b51c-1a00-0000-33bf-c2dce20a0000 pid=2786 execve guuid=3db36420-1a00-0000-33bf-c2dce90a0000 pid=2793 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=3db36420-1a00-0000-33bf-c2dce90a0000 pid=2793 execve guuid=fc1cf220-1a00-0000-33bf-c2dcee0a0000 pid=2798 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=fc1cf220-1a00-0000-33bf-c2dcee0a0000 pid=2798 execve guuid=d7d6ae21-1a00-0000-33bf-c2dcf30a0000 pid=2803 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=d7d6ae21-1a00-0000-33bf-c2dcf30a0000 pid=2803 execve guuid=85473622-1a00-0000-33bf-c2dcf70a0000 pid=2807 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=85473622-1a00-0000-33bf-c2dcf70a0000 pid=2807 execve guuid=23c0ee22-1a00-0000-33bf-c2dcfe0a0000 pid=2814 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=23c0ee22-1a00-0000-33bf-c2dcfe0a0000 pid=2814 execve guuid=19319723-1a00-0000-33bf-c2dc040b0000 pid=2820 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=19319723-1a00-0000-33bf-c2dc040b0000 pid=2820 execve guuid=13794d24-1a00-0000-33bf-c2dc090b0000 pid=2825 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=13794d24-1a00-0000-33bf-c2dc090b0000 pid=2825 execve guuid=0ef8e124-1a00-0000-33bf-c2dc0e0b0000 pid=2830 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=0ef8e124-1a00-0000-33bf-c2dc0e0b0000 pid=2830 execve guuid=1f7b7d25-1a00-0000-33bf-c2dc130b0000 pid=2835 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=1f7b7d25-1a00-0000-33bf-c2dc130b0000 pid=2835 execve guuid=a19e3226-1a00-0000-33bf-c2dc190b0000 pid=2841 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=a19e3226-1a00-0000-33bf-c2dc190b0000 pid=2841 execve guuid=f7c3e426-1a00-0000-33bf-c2dc1f0b0000 pid=2847 /usr/bin/dash guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=f7c3e426-1a00-0000-33bf-c2dc1f0b0000 pid=2847 execve guuid=e14aef27-1a00-0000-33bf-c2dc250b0000 pid=2853 /tmp/x86_64 zombie guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=e14aef27-1a00-0000-33bf-c2dc250b0000 pid=2853 clone guuid=3b85f827-1a00-0000-33bf-c2dc260b0000 pid=2854 /tmp/x86_64 guuid=24065b1a-1a00-0000-33bf-c2dcda0a0000 pid=2778->guuid=3b85f827-1a00-0000-33bf-c2dc260b0000 pid=2854 clone guuid=c32ed21a-1a00-0000-33bf-c2dcdd0a0000 pid=2781 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=c32ed21a-1a00-0000-33bf-c2dcdd0a0000 pid=2781 execve guuid=9bd23f1c-1a00-0000-33bf-c2dce00a0000 pid=2784 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=9bd23f1c-1a00-0000-33bf-c2dce00a0000 pid=2784 execve guuid=75186c20-1a00-0000-33bf-c2dcea0a0000 pid=2794 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=75186c20-1a00-0000-33bf-c2dcea0a0000 pid=2794 execve guuid=c5590b21-1a00-0000-33bf-c2dcef0a0000 pid=2799 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=c5590b21-1a00-0000-33bf-c2dcef0a0000 pid=2799 execve guuid=1282d421-1a00-0000-33bf-c2dcf40a0000 pid=2804 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=1282d421-1a00-0000-33bf-c2dcf40a0000 pid=2804 execve guuid=f0ee4c22-1a00-0000-33bf-c2dcf80a0000 pid=2808 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=f0ee4c22-1a00-0000-33bf-c2dcf80a0000 pid=2808 execve guuid=94d3de22-1a00-0000-33bf-c2dcfd0a0000 pid=2813 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=94d3de22-1a00-0000-33bf-c2dcfd0a0000 pid=2813 execve guuid=63898a23-1a00-0000-33bf-c2dc030b0000 pid=2819 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=63898a23-1a00-0000-33bf-c2dc030b0000 pid=2819 execve guuid=6f2f5424-1a00-0000-33bf-c2dc0a0b0000 pid=2826 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=6f2f5424-1a00-0000-33bf-c2dc0a0b0000 pid=2826 execve guuid=74e4f024-1a00-0000-33bf-c2dc0f0b0000 pid=2831 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=74e4f024-1a00-0000-33bf-c2dc0f0b0000 pid=2831 execve guuid=b0bd8425-1a00-0000-33bf-c2dc140b0000 pid=2836 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=b0bd8425-1a00-0000-33bf-c2dc140b0000 pid=2836 execve guuid=9b2f3626-1a00-0000-33bf-c2dc1a0b0000 pid=2842 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=9b2f3626-1a00-0000-33bf-c2dc1a0b0000 pid=2842 execve guuid=c70cf526-1a00-0000-33bf-c2dc200b0000 pid=2848 /usr/bin/dash guuid=a37ec91a-1a00-0000-33bf-c2dcdb0a0000 pid=2779->guuid=c70cf526-1a00-0000-33bf-c2dc200b0000 pid=2848 execve guuid=9961ff1b-1a00-0000-33bf-c2dcdf0a0000 pid=2783 /usr/bin/rm guuid=625bd11a-1a00-0000-33bf-c2dcdc0a0000 pid=2780->guuid=9961ff1b-1a00-0000-33bf-c2dcdf0a0000 pid=2783 execve guuid=df39b81b-1a00-0000-33bf-c2dcde0a0000 pid=2782 /usr/bin/rm delete-file guuid=c32ed21a-1a00-0000-33bf-c2dcdd0a0000 pid=2781->guuid=df39b81b-1a00-0000-33bf-c2dcde0a0000 pid=2782 execve guuid=3f9a721c-1a00-0000-33bf-c2dce10a0000 pid=2785 /usr/bin/rm delete-file guuid=9bd23f1c-1a00-0000-33bf-c2dce00a0000 pid=2784->guuid=3f9a721c-1a00-0000-33bf-c2dce10a0000 pid=2785 execve guuid=d2e11e1d-1a00-0000-33bf-c2dce30a0000 pid=2787 /usr/bin/rm delete-file guuid=ea60b51c-1a00-0000-33bf-c2dce20a0000 pid=2786->guuid=d2e11e1d-1a00-0000-33bf-c2dce30a0000 pid=2787 execve guuid=da56a220-1a00-0000-33bf-c2dceb0a0000 pid=2795 /usr/bin/rm guuid=3db36420-1a00-0000-33bf-c2dce90a0000 pid=2793->guuid=da56a220-1a00-0000-33bf-c2dceb0a0000 pid=2795 execve guuid=5d0ebb20-1a00-0000-33bf-c2dced0a0000 pid=2797 /usr/bin/rm guuid=75186c20-1a00-0000-33bf-c2dcea0a0000 pid=2794->guuid=5d0ebb20-1a00-0000-33bf-c2dced0a0000 pid=2797 execve guuid=63852821-1a00-0000-33bf-c2dcf00a0000 pid=2800 /usr/bin/rm delete-file guuid=fc1cf220-1a00-0000-33bf-c2dcee0a0000 pid=2798->guuid=63852821-1a00-0000-33bf-c2dcf00a0000 pid=2800 execve guuid=0da75f21-1a00-0000-33bf-c2dcf10a0000 pid=2801 /usr/bin/rm guuid=c5590b21-1a00-0000-33bf-c2dcef0a0000 pid=2799->guuid=0da75f21-1a00-0000-33bf-c2dcf10a0000 pid=2801 execve guuid=be7ce421-1a00-0000-33bf-c2dcf50a0000 pid=2805 /usr/bin/rm guuid=d7d6ae21-1a00-0000-33bf-c2dcf30a0000 pid=2803->guuid=be7ce421-1a00-0000-33bf-c2dcf50a0000 pid=2805 execve guuid=a3f10322-1a00-0000-33bf-c2dcf60a0000 pid=2806 /usr/bin/rm guuid=1282d421-1a00-0000-33bf-c2dcf40a0000 pid=2804->guuid=a3f10322-1a00-0000-33bf-c2dcf60a0000 pid=2806 execve guuid=42ed7722-1a00-0000-33bf-c2dcf90a0000 pid=2809 /usr/bin/rm guuid=85473622-1a00-0000-33bf-c2dcf70a0000 pid=2807->guuid=42ed7722-1a00-0000-33bf-c2dcf90a0000 pid=2809 execve guuid=279b7a22-1a00-0000-33bf-c2dcfa0a0000 pid=2810 /usr/bin/rm delete-file guuid=f0ee4c22-1a00-0000-33bf-c2dcf80a0000 pid=2808->guuid=279b7a22-1a00-0000-33bf-c2dcfa0a0000 pid=2810 execve guuid=2dd91923-1a00-0000-33bf-c2dc000b0000 pid=2816 /usr/bin/rm guuid=94d3de22-1a00-0000-33bf-c2dcfd0a0000 pid=2813->guuid=2dd91923-1a00-0000-33bf-c2dc000b0000 pid=2816 execve guuid=8ae63323-1a00-0000-33bf-c2dc010b0000 pid=2817 /usr/bin/rm guuid=23c0ee22-1a00-0000-33bf-c2dcfe0a0000 pid=2814->guuid=8ae63323-1a00-0000-33bf-c2dc010b0000 pid=2817 execve guuid=5b3fd923-1a00-0000-33bf-c2dc060b0000 pid=2822 /usr/bin/rm guuid=63898a23-1a00-0000-33bf-c2dc030b0000 pid=2819->guuid=5b3fd923-1a00-0000-33bf-c2dc060b0000 pid=2822 execve guuid=56c8db23-1a00-0000-33bf-c2dc070b0000 pid=2823 /usr/bin/rm guuid=19319723-1a00-0000-33bf-c2dc040b0000 pid=2820->guuid=56c8db23-1a00-0000-33bf-c2dc070b0000 pid=2823 execve guuid=098a8824-1a00-0000-33bf-c2dc0b0b0000 pid=2827 /usr/bin/rm guuid=13794d24-1a00-0000-33bf-c2dc090b0000 pid=2825->guuid=098a8824-1a00-0000-33bf-c2dc0b0b0000 pid=2827 execve guuid=edba9124-1a00-0000-33bf-c2dc0c0b0000 pid=2828 /usr/bin/rm guuid=6f2f5424-1a00-0000-33bf-c2dc0a0b0000 pid=2826->guuid=edba9124-1a00-0000-33bf-c2dc0c0b0000 pid=2828 execve guuid=8a761e25-1a00-0000-33bf-c2dc100b0000 pid=2832 /usr/bin/rm guuid=0ef8e124-1a00-0000-33bf-c2dc0e0b0000 pid=2830->guuid=8a761e25-1a00-0000-33bf-c2dc100b0000 pid=2832 execve guuid=67de2725-1a00-0000-33bf-c2dc110b0000 pid=2833 /usr/bin/rm guuid=74e4f024-1a00-0000-33bf-c2dc0f0b0000 pid=2831->guuid=67de2725-1a00-0000-33bf-c2dc110b0000 pid=2833 execve guuid=66ddd225-1a00-0000-33bf-c2dc160b0000 pid=2838 /usr/bin/rm delete-file guuid=1f7b7d25-1a00-0000-33bf-c2dc130b0000 pid=2835->guuid=66ddd225-1a00-0000-33bf-c2dc160b0000 pid=2838 execve guuid=5b32d425-1a00-0000-33bf-c2dc170b0000 pid=2839 /usr/bin/rm delete-file guuid=b0bd8425-1a00-0000-33bf-c2dc140b0000 pid=2836->guuid=5b32d425-1a00-0000-33bf-c2dc170b0000 pid=2839 execve guuid=5c468126-1a00-0000-33bf-c2dc1d0b0000 pid=2845 /usr/bin/rm delete-file guuid=a19e3226-1a00-0000-33bf-c2dc190b0000 pid=2841->guuid=5c468126-1a00-0000-33bf-c2dc1d0b0000 pid=2845 execve guuid=f9e36d26-1a00-0000-33bf-c2dc1b0b0000 pid=2843 /usr/bin/rm guuid=9b2f3626-1a00-0000-33bf-c2dc1a0b0000 pid=2842->guuid=f9e36d26-1a00-0000-33bf-c2dc1b0b0000 pid=2843 execve guuid=97333627-1a00-0000-33bf-c2dc220b0000 pid=2850 /usr/bin/rm guuid=f7c3e426-1a00-0000-33bf-c2dc1f0b0000 pid=2847->guuid=97333627-1a00-0000-33bf-c2dc220b0000 pid=2850 execve guuid=15fd5927-1a00-0000-33bf-c2dc230b0000 pid=2851 /usr/bin/rm guuid=c70cf526-1a00-0000-33bf-c2dc200b0000 pid=2848->guuid=15fd5927-1a00-0000-33bf-c2dc230b0000 pid=2851 execve guuid=24af0428-1a00-0000-33bf-c2dc270b0000 pid=2855 /tmp/x86_64 net send-data zombie guuid=3b85f827-1a00-0000-33bf-c2dc260b0000 pid=2854->guuid=24af0428-1a00-0000-33bf-c2dc270b0000 pid=2855 clone 856512cb-2529-595d-b709-43376a7f4d6f 213.232.114.169:180 guuid=24af0428-1a00-0000-33bf-c2dc270b0000 pid=2855->856512cb-2529-595d-b709-43376a7f4d6f send: 13B guuid=dcc28d28-1a00-0000-33bf-c2dc290b0000 pid=2857->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=db6bf62f-1a00-0000-33bf-c2dc350b0000 pid=2869->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B guuid=9f01fe39-1a00-0000-33bf-c2dc4b0b0000 pid=2891->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 134B guuid=ead89640-1a00-0000-33bf-c2dc5a0b0000 pid=2906->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 83B guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930 /tmp/i686 zombie guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930 clone guuid=85c2984a-1a00-0000-33bf-c2dc750b0000 pid=2933 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=85c2984a-1a00-0000-33bf-c2dc750b0000 pid=2933 execve guuid=e0f2494b-1a00-0000-33bf-c2dc7c0b0000 pid=2940 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=e0f2494b-1a00-0000-33bf-c2dc7c0b0000 pid=2940 execve guuid=a6a8e54b-1a00-0000-33bf-c2dc820b0000 pid=2946 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=a6a8e54b-1a00-0000-33bf-c2dc820b0000 pid=2946 execve guuid=1287874c-1a00-0000-33bf-c2dc890b0000 pid=2953 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=1287874c-1a00-0000-33bf-c2dc890b0000 pid=2953 execve guuid=61510b4d-1a00-0000-33bf-c2dc8e0b0000 pid=2958 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=61510b4d-1a00-0000-33bf-c2dc8e0b0000 pid=2958 execve guuid=1f4c974d-1a00-0000-33bf-c2dc930b0000 pid=2963 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=1f4c974d-1a00-0000-33bf-c2dc930b0000 pid=2963 execve guuid=b368374e-1a00-0000-33bf-c2dc980b0000 pid=2968 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=b368374e-1a00-0000-33bf-c2dc980b0000 pid=2968 execve guuid=8d02d84e-1a00-0000-33bf-c2dc9e0b0000 pid=2974 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=8d02d84e-1a00-0000-33bf-c2dc9e0b0000 pid=2974 execve guuid=3906784f-1a00-0000-33bf-c2dca50b0000 pid=2981 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=3906784f-1a00-0000-33bf-c2dca50b0000 pid=2981 execve guuid=fdf8eb4f-1a00-0000-33bf-c2dcaa0b0000 pid=2986 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=fdf8eb4f-1a00-0000-33bf-c2dcaa0b0000 pid=2986 execve guuid=0ca88050-1a00-0000-33bf-c2dcad0b0000 pid=2989 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=0ca88050-1a00-0000-33bf-c2dcad0b0000 pid=2989 execve guuid=86d62651-1a00-0000-33bf-c2dcb00b0000 pid=2992 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=86d62651-1a00-0000-33bf-c2dcb00b0000 pid=2992 execve guuid=03f7bd51-1a00-0000-33bf-c2dcb30b0000 pid=2995 /usr/bin/dash guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=03f7bd51-1a00-0000-33bf-c2dcb30b0000 pid=2995 execve guuid=9cd73952-1a00-0000-33bf-c2dcb60b0000 pid=2998 /tmp/i686 guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=9cd73952-1a00-0000-33bf-c2dcb60b0000 pid=2998 clone guuid=b9ce3c52-1a00-0000-33bf-c2dcb70b0000 pid=2999 /tmp/i686 guuid=89e1f848-1a00-0000-33bf-c2dc6f0b0000 pid=2927->guuid=b9ce3c52-1a00-0000-33bf-c2dcb70b0000 pid=2999 clone guuid=77fa964a-1a00-0000-33bf-c2dc740b0000 pid=2932 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=77fa964a-1a00-0000-33bf-c2dc740b0000 pid=2932 execve guuid=58be044b-1a00-0000-33bf-c2dc790b0000 pid=2937 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=58be044b-1a00-0000-33bf-c2dc790b0000 pid=2937 execve guuid=4faeb14b-1a00-0000-33bf-c2dc7f0b0000 pid=2943 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=4faeb14b-1a00-0000-33bf-c2dc7f0b0000 pid=2943 execve guuid=333d134c-1a00-0000-33bf-c2dc840b0000 pid=2948 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=333d134c-1a00-0000-33bf-c2dc840b0000 pid=2948 execve guuid=12f5714c-1a00-0000-33bf-c2dc880b0000 pid=2952 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=12f5714c-1a00-0000-33bf-c2dc880b0000 pid=2952 execve guuid=dd08d34c-1a00-0000-33bf-c2dc8c0b0000 pid=2956 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=dd08d34c-1a00-0000-33bf-c2dc8c0b0000 pid=2956 execve guuid=defd324d-1a00-0000-33bf-c2dc8f0b0000 pid=2959 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=defd324d-1a00-0000-33bf-c2dc8f0b0000 pid=2959 execve guuid=b027904d-1a00-0000-33bf-c2dc920b0000 pid=2962 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=b027904d-1a00-0000-33bf-c2dc920b0000 pid=2962 execve guuid=d590f64d-1a00-0000-33bf-c2dc960b0000 pid=2966 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=d590f64d-1a00-0000-33bf-c2dc960b0000 pid=2966 execve guuid=6f0a524e-1a00-0000-33bf-c2dc990b0000 pid=2969 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=6f0a524e-1a00-0000-33bf-c2dc990b0000 pid=2969 execve guuid=ebb0b34e-1a00-0000-33bf-c2dc9c0b0000 pid=2972 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=ebb0b34e-1a00-0000-33bf-c2dc9c0b0000 pid=2972 execve guuid=c344104f-1a00-0000-33bf-c2dca10b0000 pid=2977 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=c344104f-1a00-0000-33bf-c2dca10b0000 pid=2977 execve guuid=37967e4f-1a00-0000-33bf-c2dca60b0000 pid=2982 /usr/bin/dash guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=37967e4f-1a00-0000-33bf-c2dca60b0000 pid=2982 execve guuid=5c4612ff-2500-0000-33bf-c2dc8b120000 pid=4747 /tmp/i686 guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=5c4612ff-2500-0000-33bf-c2dc8b120000 pid=4747 clone guuid=37d320ff-2500-0000-33bf-c2dc8c120000 pid=4748 /tmp/i686 guuid=fe7f8b4a-1a00-0000-33bf-c2dc720b0000 pid=2930->guuid=37d320ff-2500-0000-33bf-c2dc8c120000 pid=4748 clone guuid=71ccc44a-1a00-0000-33bf-c2dc760b0000 pid=2934 /usr/bin/rm delete-file guuid=77fa964a-1a00-0000-33bf-c2dc740b0000 pid=2932->guuid=71ccc44a-1a00-0000-33bf-c2dc760b0000 pid=2934 execve guuid=f4afe34a-1a00-0000-33bf-c2dc780b0000 pid=2936 /usr/bin/rm guuid=85c2984a-1a00-0000-33bf-c2dc750b0000 pid=2933->guuid=f4afe34a-1a00-0000-33bf-c2dc780b0000 pid=2936 execve guuid=2120304b-1a00-0000-33bf-c2dc7a0b0000 pid=2938 /usr/bin/rm delete-file guuid=58be044b-1a00-0000-33bf-c2dc790b0000 pid=2937->guuid=2120304b-1a00-0000-33bf-c2dc7a0b0000 pid=2938 execve guuid=d8308d4b-1a00-0000-33bf-c2dc7e0b0000 pid=2942 /usr/bin/rm guuid=e0f2494b-1a00-0000-33bf-c2dc7c0b0000 pid=2940->guuid=d8308d4b-1a00-0000-33bf-c2dc7e0b0000 pid=2942 execve guuid=d810d84b-1a00-0000-33bf-c2dc810b0000 pid=2945 /usr/bin/rm guuid=4faeb14b-1a00-0000-33bf-c2dc7f0b0000 pid=2943->guuid=d810d84b-1a00-0000-33bf-c2dc810b0000 pid=2945 execve guuid=5684234c-1a00-0000-33bf-c2dc850b0000 pid=2949 /usr/bin/rm guuid=a6a8e54b-1a00-0000-33bf-c2dc820b0000 pid=2946->guuid=5684234c-1a00-0000-33bf-c2dc850b0000 pid=2949 execve guuid=2ba6374c-1a00-0000-33bf-c2dc860b0000 pid=2950 /usr/bin/rm guuid=333d134c-1a00-0000-33bf-c2dc840b0000 pid=2948->guuid=2ba6374c-1a00-0000-33bf-c2dc860b0000 pid=2950 execve guuid=f3e3994c-1a00-0000-33bf-c2dc8a0b0000 pid=2954 /usr/bin/rm guuid=12f5714c-1a00-0000-33bf-c2dc880b0000 pid=2952->guuid=f3e3994c-1a00-0000-33bf-c2dc8a0b0000 pid=2954 execve guuid=2c5dc34c-1a00-0000-33bf-c2dc8b0b0000 pid=2955 /usr/bin/rm guuid=1287874c-1a00-0000-33bf-c2dc890b0000 pid=2953->guuid=2c5dc34c-1a00-0000-33bf-c2dc8b0b0000 pid=2955 execve guuid=79e0f94c-1a00-0000-33bf-c2dc8d0b0000 pid=2957 /usr/bin/rm guuid=dd08d34c-1a00-0000-33bf-c2dc8c0b0000 pid=2956->guuid=79e0f94c-1a00-0000-33bf-c2dc8d0b0000 pid=2957 execve guuid=00b63b4d-1a00-0000-33bf-c2dc900b0000 pid=2960 /usr/bin/rm guuid=61510b4d-1a00-0000-33bf-c2dc8e0b0000 pid=2958->guuid=00b63b4d-1a00-0000-33bf-c2dc900b0000 pid=2960 execve guuid=0273574d-1a00-0000-33bf-c2dc910b0000 pid=2961 /usr/bin/rm guuid=defd324d-1a00-0000-33bf-c2dc8f0b0000 pid=2959->guuid=0273574d-1a00-0000-33bf-c2dc910b0000 pid=2961 execve guuid=dbc9bc4d-1a00-0000-33bf-c2dc940b0000 pid=2964 /usr/bin/rm guuid=b027904d-1a00-0000-33bf-c2dc920b0000 pid=2962->guuid=dbc9bc4d-1a00-0000-33bf-c2dc940b0000 pid=2964 execve guuid=58dad94d-1a00-0000-33bf-c2dc950b0000 pid=2965 /usr/bin/rm guuid=1f4c974d-1a00-0000-33bf-c2dc930b0000 pid=2963->guuid=58dad94d-1a00-0000-33bf-c2dc950b0000 pid=2965 execve guuid=76f01a4e-1a00-0000-33bf-c2dc970b0000 pid=2967 /usr/bin/rm guuid=d590f64d-1a00-0000-33bf-c2dc960b0000 pid=2966->guuid=76f01a4e-1a00-0000-33bf-c2dc970b0000 pid=2967 execve guuid=923e774e-1a00-0000-33bf-c2dc9a0b0000 pid=2970 /usr/bin/rm guuid=b368374e-1a00-0000-33bf-c2dc980b0000 pid=2968->guuid=923e774e-1a00-0000-33bf-c2dc9a0b0000 pid=2970 execve guuid=b7b0784e-1a00-0000-33bf-c2dc9b0b0000 pid=2971 /usr/bin/rm guuid=6f0a524e-1a00-0000-33bf-c2dc990b0000 pid=2969->guuid=b7b0784e-1a00-0000-33bf-c2dc9b0b0000 pid=2971 execve guuid=0202d84e-1a00-0000-33bf-c2dc9f0b0000 pid=2975 /usr/bin/rm guuid=ebb0b34e-1a00-0000-33bf-c2dc9c0b0000 pid=2972->guuid=0202d84e-1a00-0000-33bf-c2dc9f0b0000 pid=2975 execve guuid=bb6c1f4f-1a00-0000-33bf-c2dca20b0000 pid=2978 /usr/bin/rm guuid=8d02d84e-1a00-0000-33bf-c2dc9e0b0000 pid=2974->guuid=bb6c1f4f-1a00-0000-33bf-c2dca20b0000 pid=2978 execve guuid=219b374f-1a00-0000-33bf-c2dca30b0000 pid=2979 /usr/bin/rm guuid=c344104f-1a00-0000-33bf-c2dca10b0000 pid=2977->guuid=219b374f-1a00-0000-33bf-c2dca30b0000 pid=2979 execve guuid=d763a74f-1a00-0000-33bf-c2dca70b0000 pid=2983 /usr/bin/rm guuid=3906784f-1a00-0000-33bf-c2dca50b0000 pid=2981->guuid=d763a74f-1a00-0000-33bf-c2dca70b0000 pid=2983 execve guuid=b1feb54f-1a00-0000-33bf-c2dca80b0000 pid=2984 /usr/bin/rm guuid=37967e4f-1a00-0000-33bf-c2dca60b0000 pid=2982->guuid=b1feb54f-1a00-0000-33bf-c2dca80b0000 pid=2984 execve guuid=c8a81350-1a00-0000-33bf-c2dcab0b0000 pid=2987 /usr/bin/rm guuid=fdf8eb4f-1a00-0000-33bf-c2dcaa0b0000 pid=2986->guuid=c8a81350-1a00-0000-33bf-c2dcab0b0000 pid=2987 execve guuid=61e7aa50-1a00-0000-33bf-c2dcae0b0000 pid=2990 /usr/bin/rm guuid=0ca88050-1a00-0000-33bf-c2dcad0b0000 pid=2989->guuid=61e7aa50-1a00-0000-33bf-c2dcae0b0000 pid=2990 execve guuid=d7a56251-1a00-0000-33bf-c2dcb10b0000 pid=2993 /usr/bin/rm guuid=86d62651-1a00-0000-33bf-c2dcb00b0000 pid=2992->guuid=d7a56251-1a00-0000-33bf-c2dcb10b0000 pid=2993 execve guuid=66a7e751-1a00-0000-33bf-c2dcb40b0000 pid=2996 /usr/bin/rm guuid=03f7bd51-1a00-0000-33bf-c2dcb30b0000 pid=2995->guuid=66a7e751-1a00-0000-33bf-c2dcb40b0000 pid=2996 execve guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000 /tmp/i686 net send-data zombie guuid=b9ce3c52-1a00-0000-33bf-c2dcb70b0000 pid=2999->guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000 clone guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000->856512cb-2529-595d-b709-43376a7f4d6f send: 13B 77b342fc-65c9-5d9f-9dbd-f9ae84ef0505 232.114.169.180:180 guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000->77b342fc-65c9-5d9f-9dbd-f9ae84ef0505 con 0719df9c-054b-541b-a283-391e930ff772 114.169.180.0:180 guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000->0719df9c-054b-541b-a283-391e930ff772 con 813c3043-c758-5627-8505-cecdc76ed2dc 169.180.0.0:180 guuid=65c54152-1a00-0000-33bf-c2dcb80b0000 pid=3000->813c3043-c758-5627-8505-cecdc76ed2dc con guuid=ea8f9e52-1a00-0000-33bf-c2dcbb0b0000 pid=3003->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 137B guuid=05a3b459-1a00-0000-33bf-c2dcc80b0000 pid=3016->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 86B guuid=d8debd62-1a00-0000-33bf-c2dce60b0000 pid=3046->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 134B guuid=0a6a1069-1a00-0000-33bf-c2dcf50b0000 pid=3061->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 83B guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078 /tmp/i586 zombie guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078 clone guuid=99ac8a7b-1a00-0000-33bf-c2dc070c0000 pid=3079 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=99ac8a7b-1a00-0000-33bf-c2dc070c0000 pid=3079 execve guuid=e11e007c-1a00-0000-33bf-c2dc0d0c0000 pid=3085 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=e11e007c-1a00-0000-33bf-c2dc0d0c0000 pid=3085 execve guuid=03fab57c-1a00-0000-33bf-c2dc110c0000 pid=3089 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=03fab57c-1a00-0000-33bf-c2dc110c0000 pid=3089 execve guuid=785eb07d-1a00-0000-33bf-c2dc190c0000 pid=3097 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=785eb07d-1a00-0000-33bf-c2dc190c0000 pid=3097 execve guuid=fdd6bd7e-1a00-0000-33bf-c2dc220c0000 pid=3106 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=fdd6bd7e-1a00-0000-33bf-c2dc220c0000 pid=3106 execve guuid=b3bbb37f-1a00-0000-33bf-c2dc2c0c0000 pid=3116 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=b3bbb37f-1a00-0000-33bf-c2dc2c0c0000 pid=3116 execve guuid=75d53080-1a00-0000-33bf-c2dc310c0000 pid=3121 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=75d53080-1a00-0000-33bf-c2dc310c0000 pid=3121 execve guuid=34ccfa80-1a00-0000-33bf-c2dc370c0000 pid=3127 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=34ccfa80-1a00-0000-33bf-c2dc370c0000 pid=3127 execve guuid=84ed9b81-1a00-0000-33bf-c2dc3e0c0000 pid=3134 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=84ed9b81-1a00-0000-33bf-c2dc3e0c0000 pid=3134 execve guuid=1b088182-1a00-0000-33bf-c2dc450c0000 pid=3141 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=1b088182-1a00-0000-33bf-c2dc450c0000 pid=3141 execve guuid=7e5b1983-1a00-0000-33bf-c2dc4a0c0000 pid=3146 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=7e5b1983-1a00-0000-33bf-c2dc4a0c0000 pid=3146 execve guuid=6beca083-1a00-0000-33bf-c2dc4d0c0000 pid=3149 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=6beca083-1a00-0000-33bf-c2dc4d0c0000 pid=3149 execve guuid=a8a72e84-1a00-0000-33bf-c2dc500c0000 pid=3152 /usr/bin/dash guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=a8a72e84-1a00-0000-33bf-c2dc500c0000 pid=3152 execve guuid=282db884-1a00-0000-33bf-c2dc540c0000 pid=3156 /tmp/i586 guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=282db884-1a00-0000-33bf-c2dc540c0000 pid=3156 clone guuid=64ffbe84-1a00-0000-33bf-c2dc550c0000 pid=3157 /tmp/i586 guuid=de6f327a-1a00-0000-33bf-c2dc010c0000 pid=3073->guuid=64ffbe84-1a00-0000-33bf-c2dc550c0000 pid=3157 clone guuid=fd9c907b-1a00-0000-33bf-c2dc080c0000 pid=3080 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=fd9c907b-1a00-0000-33bf-c2dc080c0000 pid=3080 execve guuid=f5a8817c-1a00-0000-33bf-c2dc100c0000 pid=3088 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=f5a8817c-1a00-0000-33bf-c2dc100c0000 pid=3088 execve guuid=90fc647d-1a00-0000-33bf-c2dc170c0000 pid=3095 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=90fc647d-1a00-0000-33bf-c2dc170c0000 pid=3095 execve guuid=e3330c7e-1a00-0000-33bf-c2dc1d0c0000 pid=3101 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=e3330c7e-1a00-0000-33bf-c2dc1d0c0000 pid=3101 execve guuid=c40a947e-1a00-0000-33bf-c2dc200c0000 pid=3104 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=c40a947e-1a00-0000-33bf-c2dc200c0000 pid=3104 execve guuid=992d437f-1a00-0000-33bf-c2dc270c0000 pid=3111 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=992d437f-1a00-0000-33bf-c2dc270c0000 pid=3111 execve guuid=fba7a87f-1a00-0000-33bf-c2dc2a0c0000 pid=3114 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=fba7a87f-1a00-0000-33bf-c2dc2a0c0000 pid=3114 execve guuid=371d1780-1a00-0000-33bf-c2dc2f0c0000 pid=3119 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=371d1780-1a00-0000-33bf-c2dc2f0c0000 pid=3119 execve guuid=10199e80-1a00-0000-33bf-c2dc350c0000 pid=3125 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=10199e80-1a00-0000-33bf-c2dc350c0000 pid=3125 execve guuid=ce3fff80-1a00-0000-33bf-c2dc380c0000 pid=3128 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=ce3fff80-1a00-0000-33bf-c2dc380c0000 pid=3128 execve guuid=9cab6881-1a00-0000-33bf-c2dc3b0c0000 pid=3131 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=9cab6881-1a00-0000-33bf-c2dc3b0c0000 pid=3131 execve guuid=dd3fee81-1a00-0000-33bf-c2dc400c0000 pid=3136 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=dd3fee81-1a00-0000-33bf-c2dc400c0000 pid=3136 execve guuid=88a85582-1a00-0000-33bf-c2dc440c0000 pid=3140 /usr/bin/dash guuid=3c59827b-1a00-0000-33bf-c2dc060c0000 pid=3078->guuid=88a85582-1a00-0000-33bf-c2dc440c0000 pid=3140 execve guuid=3d6bbd7b-1a00-0000-33bf-c2dc0a0c0000 pid=3082 /usr/bin/rm delete-file guuid=99ac8a7b-1a00-0000-33bf-c2dc070c0000 pid=3079->guuid=3d6bbd7b-1a00-0000-33bf-c2dc0a0c0000 pid=3082 execve guuid=3191e27b-1a00-0000-33bf-c2dc0b0c0000 pid=3083 /usr/bin/rm guuid=fd9c907b-1a00-0000-33bf-c2dc080c0000 pid=3080->guuid=3191e27b-1a00-0000-33bf-c2dc0b0c0000 pid=3083 execve guuid=c9112e7c-1a00-0000-33bf-c2dc0e0c0000 pid=3086 /usr/bin/rm delete-file guuid=e11e007c-1a00-0000-33bf-c2dc0d0c0000 pid=3085->guuid=c9112e7c-1a00-0000-33bf-c2dc0e0c0000 pid=3086 execve guuid=69afea7c-1a00-0000-33bf-c2dc130c0000 pid=3091 /usr/bin/rm guuid=f5a8817c-1a00-0000-33bf-c2dc100c0000 pid=3088->guuid=69afea7c-1a00-0000-33bf-c2dc130c0000 pid=3091 execve guuid=572e447d-1a00-0000-33bf-c2dc160c0000 pid=3094 /usr/bin/rm guuid=03fab57c-1a00-0000-33bf-c2dc110c0000 pid=3089->guuid=572e447d-1a00-0000-33bf-c2dc160c0000 pid=3094 execve guuid=9383ce7d-1a00-0000-33bf-c2dc1b0c0000 pid=3099 /usr/bin/rm guuid=90fc647d-1a00-0000-33bf-c2dc170c0000 pid=3095->guuid=9383ce7d-1a00-0000-33bf-c2dc1b0c0000 pid=3099 execve guuid=b1b4087e-1a00-0000-33bf-c2dc1c0c0000 pid=3100 /usr/bin/rm guuid=785eb07d-1a00-0000-33bf-c2dc190c0000 pid=3097->guuid=b1b4087e-1a00-0000-33bf-c2dc1c0c0000 pid=3100 execve guuid=6d9f3c7e-1a00-0000-33bf-c2dc1f0c0000 pid=3103 /usr/bin/rm guuid=e3330c7e-1a00-0000-33bf-c2dc1d0c0000 pid=3101->guuid=6d9f3c7e-1a00-0000-33bf-c2dc1f0c0000 pid=3103 execve guuid=6026fa7e-1a00-0000-33bf-c2dc250c0000 pid=3109 /usr/bin/rm guuid=c40a947e-1a00-0000-33bf-c2dc200c0000 pid=3104->guuid=6026fa7e-1a00-0000-33bf-c2dc250c0000 pid=3109 execve guuid=5db4ec7e-1a00-0000-33bf-c2dc240c0000 pid=3108 /usr/bin/rm guuid=fdd6bd7e-1a00-0000-33bf-c2dc220c0000 pid=3106->guuid=5db4ec7e-1a00-0000-33bf-c2dc240c0000 pid=3108 execve guuid=5f366d7f-1a00-0000-33bf-c2dc280c0000 pid=3112 /usr/bin/rm guuid=992d437f-1a00-0000-33bf-c2dc270c0000 pid=3111->guuid=5f366d7f-1a00-0000-33bf-c2dc280c0000 pid=3112 execve guuid=7040cf7f-1a00-0000-33bf-c2dc2d0c0000 pid=3117 /usr/bin/rm guuid=fba7a87f-1a00-0000-33bf-c2dc2a0c0000 pid=3114->guuid=7040cf7f-1a00-0000-33bf-c2dc2d0c0000 pid=3117 execve guuid=5693e97f-1a00-0000-33bf-c2dc2e0c0000 pid=3118 /usr/bin/rm guuid=b3bbb37f-1a00-0000-33bf-c2dc2c0c0000 pid=3116->guuid=5693e97f-1a00-0000-33bf-c2dc2e0c0000 pid=3118 execve guuid=ea6c5980-1a00-0000-33bf-c2dc320c0000 pid=3122 /usr/bin/rm guuid=371d1780-1a00-0000-33bf-c2dc2f0c0000 pid=3119->guuid=ea6c5980-1a00-0000-33bf-c2dc320c0000 pid=3122 execve guuid=efc98380-1a00-0000-33bf-c2dc340c0000 pid=3124 /usr/bin/rm guuid=75d53080-1a00-0000-33bf-c2dc310c0000 pid=3121->guuid=efc98380-1a00-0000-33bf-c2dc340c0000 pid=3124 execve guuid=e75bc580-1a00-0000-33bf-c2dc360c0000 pid=3126 /usr/bin/rm guuid=10199e80-1a00-0000-33bf-c2dc350c0000 pid=3125->guuid=e75bc580-1a00-0000-33bf-c2dc360c0000 pid=3126 execve guuid=16b93881-1a00-0000-33bf-c2dc3a0c0000 pid=3130 /usr/bin/rm guuid=34ccfa80-1a00-0000-33bf-c2dc370c0000 pid=3127->guuid=16b93881-1a00-0000-33bf-c2dc3a0c0000 pid=3130 execve guuid=71af3181-1a00-0000-33bf-c2dc390c0000 pid=3129 /usr/bin/rm guuid=ce3fff80-1a00-0000-33bf-c2dc380c0000 pid=3128->guuid=71af3181-1a00-0000-33bf-c2dc390c0000 pid=3129 execve guuid=fbc49081-1a00-0000-33bf-c2dc3d0c0000 pid=3133 /usr/bin/rm guuid=9cab6881-1a00-0000-33bf-c2dc3b0c0000 pid=3131->guuid=fbc49081-1a00-0000-33bf-c2dc3d0c0000 pid=3133 execve guuid=30d50c82-1a00-0000-33bf-c2dc410c0000 pid=3137 /usr/bin/rm guuid=84ed9b81-1a00-0000-33bf-c2dc3e0c0000 pid=3134->guuid=30d50c82-1a00-0000-33bf-c2dc410c0000 pid=3137 execve guuid=dabf1982-1a00-0000-33bf-c2dc420c0000 pid=3138 /usr/bin/rm guuid=dd3fee81-1a00-0000-33bf-c2dc400c0000 pid=3136->guuid=dabf1982-1a00-0000-33bf-c2dc420c0000 pid=3138 execve guuid=756f8c82-1a00-0000-33bf-c2dc460c0000 pid=3142 /usr/bin/rm guuid=88a85582-1a00-0000-33bf-c2dc440c0000 pid=3140->guuid=756f8c82-1a00-0000-33bf-c2dc460c0000 pid=3142 execve guuid=80edc082-1a00-0000-33bf-c2dc480c0000 pid=3144 /usr/bin/rm guuid=1b088182-1a00-0000-33bf-c2dc450c0000 pid=3141->guuid=80edc082-1a00-0000-33bf-c2dc480c0000 pid=3144 execve guuid=fd794683-1a00-0000-33bf-c2dc4c0c0000 pid=3148 /usr/bin/rm guuid=7e5b1983-1a00-0000-33bf-c2dc4a0c0000 pid=3146->guuid=fd794683-1a00-0000-33bf-c2dc4c0c0000 pid=3148 execve guuid=1999d083-1a00-0000-33bf-c2dc4f0c0000 pid=3151 /usr/bin/rm guuid=6beca083-1a00-0000-33bf-c2dc4d0c0000 pid=3149->guuid=1999d083-1a00-0000-33bf-c2dc4f0c0000 pid=3151 execve guuid=aa367284-1a00-0000-33bf-c2dc520c0000 pid=3154 /usr/bin/rm guuid=a8a72e84-1a00-0000-33bf-c2dc500c0000 pid=3152->guuid=aa367284-1a00-0000-33bf-c2dc520c0000 pid=3154 execve guuid=97c6c384-1a00-0000-33bf-c2dc560c0000 pid=3158 /tmp/i586 net send-data zombie guuid=64ffbe84-1a00-0000-33bf-c2dc550c0000 pid=3157->guuid=97c6c384-1a00-0000-33bf-c2dc560c0000 pid=3158 clone guuid=97c6c384-1a00-0000-33bf-c2dc560c0000 pid=3158->856512cb-2529-595d-b709-43376a7f4d6f send: 13B guuid=97c6c384-1a00-0000-33bf-c2dc560c0000 pid=3158->77b342fc-65c9-5d9f-9dbd-f9ae84ef0505 con guuid=97c6c384-1a00-0000-33bf-c2dc560c0000 pid=3158->0719df9c-054b-541b-a283-391e930ff772 con guuid=64061885-1a00-0000-33bf-c2dc590c0000 pid=3161->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 134B guuid=725ffd8b-1a00-0000-33bf-c2dc670c0000 pid=3175->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 83B guuid=ff41e395-1a00-0000-33bf-c2dc820c0000 pid=3202->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 135B guuid=2175ee9c-1a00-0000-33bf-c2dc940c0000 pid=3220->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 84B guuid=22f220a6-1a00-0000-33bf-c2dcaf0c0000 pid=3247->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=7c0d19ad-1a00-0000-33bf-c2dcbe0c0000 pid=3262->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B guuid=27733cb6-1a00-0000-33bf-c2dcd80c0000 pid=3288->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=ec6686bd-1a00-0000-33bf-c2dcea0c0000 pid=3306->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B guuid=281ef5c6-1a00-0000-33bf-c2dc050d0000 pid=3333->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 136B guuid=21d8f4cd-1a00-0000-33bf-c2dc130d0000 pid=3347->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 85B guuid=2d1565dc-1a00-0000-33bf-c2dc380d0000 pid=3384->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 134B guuid=86805ee3-1a00-0000-33bf-c2dc4b0d0000 pid=3403->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 83B guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431 /tmp/i486 zombie guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431 clone guuid=655155ec-1a00-0000-33bf-c2dc680d0000 pid=3432 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=655155ec-1a00-0000-33bf-c2dc680d0000 pid=3432 execve guuid=7cec5ced-1a00-0000-33bf-c2dc6d0d0000 pid=3437 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=7cec5ced-1a00-0000-33bf-c2dc6d0d0000 pid=3437 execve guuid=61a788ee-1a00-0000-33bf-c2dc740d0000 pid=3444 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=61a788ee-1a00-0000-33bf-c2dc740d0000 pid=3444 execve guuid=cbddebee-1a00-0000-33bf-c2dc790d0000 pid=3449 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=cbddebee-1a00-0000-33bf-c2dc790d0000 pid=3449 execve guuid=53755cef-1a00-0000-33bf-c2dc7c0d0000 pid=3452 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=53755cef-1a00-0000-33bf-c2dc7c0d0000 pid=3452 execve guuid=2843b5ef-1a00-0000-33bf-c2dc810d0000 pid=3457 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=2843b5ef-1a00-0000-33bf-c2dc810d0000 pid=3457 execve guuid=40dd25f0-1a00-0000-33bf-c2dc840d0000 pid=3460 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=40dd25f0-1a00-0000-33bf-c2dc840d0000 pid=3460 execve guuid=a8c584f0-1a00-0000-33bf-c2dc8a0d0000 pid=3466 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=a8c584f0-1a00-0000-33bf-c2dc8a0d0000 pid=3466 execve guuid=a4bae1f0-1a00-0000-33bf-c2dc8f0d0000 pid=3471 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=a4bae1f0-1a00-0000-33bf-c2dc8f0d0000 pid=3471 execve guuid=f87648f1-1a00-0000-33bf-c2dc930d0000 pid=3475 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=f87648f1-1a00-0000-33bf-c2dc930d0000 pid=3475 execve guuid=120fdef1-1a00-0000-33bf-c2dc980d0000 pid=3480 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=120fdef1-1a00-0000-33bf-c2dc980d0000 pid=3480 execve guuid=6db058f2-1a00-0000-33bf-c2dc9d0d0000 pid=3485 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=6db058f2-1a00-0000-33bf-c2dc9d0d0000 pid=3485 execve guuid=8d7cc2f2-1a00-0000-33bf-c2dca20d0000 pid=3490 /usr/bin/dash guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=8d7cc2f2-1a00-0000-33bf-c2dca20d0000 pid=3490 execve guuid=ea817ff3-1a00-0000-33bf-c2dca70d0000 pid=3495 /tmp/i486 guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=ea817ff3-1a00-0000-33bf-c2dca70d0000 pid=3495 clone guuid=2e4383f3-1a00-0000-33bf-c2dca80d0000 pid=3496 /tmp/i486 guuid=155cf7eb-1a00-0000-33bf-c2dc630d0000 pid=3427->guuid=2e4383f3-1a00-0000-33bf-c2dca80d0000 pid=3496 clone guuid=6fdb55ec-1a00-0000-33bf-c2dc690d0000 pid=3433 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=6fdb55ec-1a00-0000-33bf-c2dc690d0000 pid=3433 execve guuid=0b833bed-1a00-0000-33bf-c2dc6c0d0000 pid=3436 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=0b833bed-1a00-0000-33bf-c2dc6c0d0000 pid=3436 execve guuid=761eb5ee-1a00-0000-33bf-c2dc760d0000 pid=3446 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=761eb5ee-1a00-0000-33bf-c2dc760d0000 pid=3446 execve guuid=8d195def-1a00-0000-33bf-c2dc7d0d0000 pid=3453 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=8d195def-1a00-0000-33bf-c2dc7d0d0000 pid=3453 execve guuid=4817eaef-1a00-0000-33bf-c2dc830d0000 pid=3459 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=4817eaef-1a00-0000-33bf-c2dc830d0000 pid=3459 execve guuid=a5a976f0-1a00-0000-33bf-c2dc890d0000 pid=3465 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=a5a976f0-1a00-0000-33bf-c2dc890d0000 pid=3465 execve guuid=70e9d5f0-1a00-0000-33bf-c2dc8e0d0000 pid=3470 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=70e9d5f0-1a00-0000-33bf-c2dc8e0d0000 pid=3470 execve guuid=21884cf1-1a00-0000-33bf-c2dc940d0000 pid=3476 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=21884cf1-1a00-0000-33bf-c2dc940d0000 pid=3476 execve guuid=ad1ef7f1-1a00-0000-33bf-c2dc9a0d0000 pid=3482 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=ad1ef7f1-1a00-0000-33bf-c2dc9a0d0000 pid=3482 execve guuid=294583f2-1a00-0000-33bf-c2dc9f0d0000 pid=3487 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=294583f2-1a00-0000-33bf-c2dc9f0d0000 pid=3487 execve guuid=409615f3-1a00-0000-33bf-c2dca40d0000 pid=3492 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=409615f3-1a00-0000-33bf-c2dca40d0000 pid=3492 execve guuid=66f8c0f3-1a00-0000-33bf-c2dcab0d0000 pid=3499 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=66f8c0f3-1a00-0000-33bf-c2dcab0d0000 pid=3499 execve guuid=da8f67f4-1a00-0000-33bf-c2dcb00d0000 pid=3504 /usr/bin/dash guuid=b6804dec-1a00-0000-33bf-c2dc670d0000 pid=3431->guuid=da8f67f4-1a00-0000-33bf-c2dcb00d0000 pid=3504 execve guuid=1d04c5ec-1a00-0000-33bf-c2dc6b0d0000 pid=3435 /usr/bin/rm guuid=655155ec-1a00-0000-33bf-c2dc680d0000 pid=3432->guuid=1d04c5ec-1a00-0000-33bf-c2dc6b0d0000 pid=3435 execve guuid=8e17a8ec-1a00-0000-33bf-c2dc6a0d0000 pid=3434 /usr/bin/rm delete-file guuid=6fdb55ec-1a00-0000-33bf-c2dc690d0000 pid=3433->guuid=8e17a8ec-1a00-0000-33bf-c2dc6a0d0000 pid=3434 execve guuid=4b417fed-1a00-0000-33bf-c2dc6e0d0000 pid=3438 /usr/bin/rm delete-file guuid=0b833bed-1a00-0000-33bf-c2dc6c0d0000 pid=3436->guuid=4b417fed-1a00-0000-33bf-c2dc6e0d0000 pid=3438 execve guuid=beabaded-1a00-0000-33bf-c2dc6f0d0000 pid=3439 /usr/bin/rm delete-file guuid=7cec5ced-1a00-0000-33bf-c2dc6d0d0000 pid=3437->guuid=beabaded-1a00-0000-33bf-c2dc6f0d0000 pid=3439 execve guuid=65eab1ee-1a00-0000-33bf-c2dc750d0000 pid=3445 /usr/bin/rm guuid=61a788ee-1a00-0000-33bf-c2dc740d0000 pid=3444->guuid=65eab1ee-1a00-0000-33bf-c2dc750d0000 pid=3445 execve guuid=a417e9ee-1a00-0000-33bf-c2dc780d0000 pid=3448 /usr/bin/rm guuid=761eb5ee-1a00-0000-33bf-c2dc760d0000 pid=3446->guuid=a417e9ee-1a00-0000-33bf-c2dc780d0000 pid=3448 execve guuid=a1550def-1a00-0000-33bf-c2dc7b0d0000 pid=3451 /usr/bin/rm guuid=cbddebee-1a00-0000-33bf-c2dc790d0000 pid=3449->guuid=a1550def-1a00-0000-33bf-c2dc7b0d0000 pid=3451 execve guuid=d32180ef-1a00-0000-33bf-c2dc7f0d0000 pid=3455 /usr/bin/rm guuid=53755cef-1a00-0000-33bf-c2dc7c0d0000 pid=3452->guuid=d32180ef-1a00-0000-33bf-c2dc7f0d0000 pid=3455 execve guuid=53df8def-1a00-0000-33bf-c2dc800d0000 pid=3456 /usr/bin/rm guuid=8d195def-1a00-0000-33bf-c2dc7d0d0000 pid=3453->guuid=53df8def-1a00-0000-33bf-c2dc800d0000 pid=3456 execve guuid=4f6fe3ef-1a00-0000-33bf-c2dc820d0000 pid=3458 /usr/bin/rm guuid=2843b5ef-1a00-0000-33bf-c2dc810d0000 pid=3457->guuid=4f6fe3ef-1a00-0000-33bf-c2dc820d0000 pid=3458 execve guuid=5b3e2af0-1a00-0000-33bf-c2dc850d0000 pid=3461 /usr/bin/rm guuid=4817eaef-1a00-0000-33bf-c2dc830d0000 pid=3459->guuid=5b3e2af0-1a00-0000-33bf-c2dc850d0000 pid=3461 execve guuid=d7b94af0-1a00-0000-33bf-c2dc870d0000 pid=3463 /usr/bin/rm guuid=40dd25f0-1a00-0000-33bf-c2dc840d0000 pid=3460->guuid=d7b94af0-1a00-0000-33bf-c2dc870d0000 pid=3463 execve guuid=e4c89df0-1a00-0000-33bf-c2dc8b0d0000 pid=3467 /usr/bin/rm guuid=a5a976f0-1a00-0000-33bf-c2dc890d0000 pid=3465->guuid=e4c89df0-1a00-0000-33bf-c2dc8b0d0000 pid=3467 execve guuid=93f8a5f0-1a00-0000-33bf-c2dc8c0d0000 pid=3468 /usr/bin/rm guuid=a8c584f0-1a00-0000-33bf-c2dc8a0d0000 pid=3466->guuid=93f8a5f0-1a00-0000-33bf-c2dc8c0d0000 pid=3468 execve guuid=3d4e0bf1-1a00-0000-33bf-c2dc910d0000 pid=3473 /usr/bin/rm guuid=70e9d5f0-1a00-0000-33bf-c2dc8e0d0000 pid=3470->guuid=3d4e0bf1-1a00-0000-33bf-c2dc910d0000 pid=3473 execve guuid=ad080bf1-1a00-0000-33bf-c2dc900d0000 pid=3472 /usr/bin/rm guuid=a4bae1f0-1a00-0000-33bf-c2dc8f0d0000 pid=3471->guuid=ad080bf1-1a00-0000-33bf-c2dc900d0000 pid=3472 execve guuid=95ab82f1-1a00-0000-33bf-c2dc950d0000 pid=3477 /usr/bin/rm guuid=f87648f1-1a00-0000-33bf-c2dc930d0000 pid=3475->guuid=95ab82f1-1a00-0000-33bf-c2dc950d0000 pid=3477 execve guuid=4e4b8bf1-1a00-0000-33bf-c2dc960d0000 pid=3478 /usr/bin/rm guuid=21884cf1-1a00-0000-33bf-c2dc940d0000 pid=3476->guuid=4e4b8bf1-1a00-0000-33bf-c2dc960d0000 pid=3478 execve guuid=3d1514f2-1a00-0000-33bf-c2dc9b0d0000 pid=3483 /usr/bin/rm guuid=120fdef1-1a00-0000-33bf-c2dc980d0000 pid=3480->guuid=3d1514f2-1a00-0000-33bf-c2dc9b0d0000 pid=3483 execve guuid=b42734f2-1a00-0000-33bf-c2dc9c0d0000 pid=3484 /usr/bin/rm guuid=ad1ef7f1-1a00-0000-33bf-c2dc9a0d0000 pid=3482->guuid=b42734f2-1a00-0000-33bf-c2dc9c0d0000 pid=3484 execve guuid=39fc7bf2-1a00-0000-33bf-c2dc9e0d0000 pid=3486 /usr/bin/rm guuid=6db058f2-1a00-0000-33bf-c2dc9d0d0000 pid=3485->guuid=39fc7bf2-1a00-0000-33bf-c2dc9e0d0000 pid=3486 execve guuid=61febef2-1a00-0000-33bf-c2dca10d0000 pid=3489 /usr/bin/rm guuid=294583f2-1a00-0000-33bf-c2dc9f0d0000 pid=3487->guuid=61febef2-1a00-0000-33bf-c2dca10d0000 pid=3489 execve guuid=85c5f2f2-1a00-0000-33bf-c2dca30d0000 pid=3491 /usr/bin/rm guuid=8d7cc2f2-1a00-0000-33bf-c2dca20d0000 pid=3490->guuid=85c5f2f2-1a00-0000-33bf-c2dca30d0000 pid=3491 execve guuid=f03f53f3-1a00-0000-33bf-c2dca50d0000 pid=3493 /usr/bin/rm guuid=409615f3-1a00-0000-33bf-c2dca40d0000 pid=3492->guuid=f03f53f3-1a00-0000-33bf-c2dca50d0000 pid=3493 execve guuid=ff1d8cf3-1a00-0000-33bf-c2dca90d0000 pid=3497 /tmp/i486 net send-data zombie guuid=2e4383f3-1a00-0000-33bf-c2dca80d0000 pid=3496->guuid=ff1d8cf3-1a00-0000-33bf-c2dca90d0000 pid=3497 clone guuid=ff1d8cf3-1a00-0000-33bf-c2dca90d0000 pid=3497->856512cb-2529-595d-b709-43376a7f4d6f send: 13B guuid=ff1d8cf3-1a00-0000-33bf-c2dca90d0000 pid=3497->77b342fc-65c9-5d9f-9dbd-f9ae84ef0505 con guuid=ff1d8cf3-1a00-0000-33bf-c2dca90d0000 pid=3497->0719df9c-054b-541b-a283-391e930ff772 con guuid=44ba03f4-1a00-0000-33bf-c2dcae0d0000 pid=3502 /usr/bin/rm guuid=66f8c0f3-1a00-0000-33bf-c2dcab0d0000 pid=3499->guuid=44ba03f4-1a00-0000-33bf-c2dcae0d0000 pid=3502 execve guuid=b03df4f3-1a00-0000-33bf-c2dcad0d0000 pid=3501->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 143B guuid=e1b0acf4-1a00-0000-33bf-c2dcb20d0000 pid=3506 /usr/bin/rm guuid=da8f67f4-1a00-0000-33bf-c2dcb00d0000 pid=3504->guuid=e1b0acf4-1a00-0000-33bf-c2dcb20d0000 pid=3506 execve guuid=8f5076fa-1a00-0000-33bf-c2dcc00d0000 pid=3520->d8eba8ce-adde-5f84-a2f4-d877f7f68596 send: 92B guuid=26202dff-2500-0000-33bf-c2dc8d120000 pid=4749 /tmp/i686 net send-data zombie guuid=37d320ff-2500-0000-33bf-c2dc8c120000 pid=4748->guuid=26202dff-2500-0000-33bf-c2dc8d120000 pid=4749 clone guuid=26202dff-2500-0000-33bf-c2dc8d120000 pid=4749->856512cb-2529-595d-b709-43376a7f4d6f send: 13B
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-07-14 11:50:34 UTC
File Type:
Text (Shell)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt antivm botnet defense_evasion discovery execution linux privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Enumerates active TCP sockets
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Detected Gafgyt variant
Gafgyt family
Gafgyt/Bashlite
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh 9a4747fb4ca166cf3ba048b21b377a4a0748d0b0d388a3f183f9b9d14a69c00a

(this sample)

  
Delivery method
Distributed via web download

Comments