MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 ab25962702b71fe70387339874670dd411659dc44235f2886aac47693354a3a1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 12 File information Comments

SHA256 hash: ab25962702b71fe70387339874670dd411659dc44235f2886aac47693354a3a1
SHA3-384 hash: 666ad4ad79a62cb75018eb0db94300fcc43a2da709268be97253fc0e8af5fd108efd6bab97f5f66e166e30ee1ed2813d
SHA1 hash: 2a266234ed8f8d364df11385cbb5a5ff06f7f51f
MD5 hash: f2221fb749f75cf332939bad933cb458
humanhash: king-uncle-cardinal-mississippi
File name:getty
Download: download sample
Signature Mirai
File size:138'223 bytes
First seen:2025-07-11 23:05:45 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:CU9Hj9ULsoAC5LndvmHGHIAJnfLfCmpFEthq9aTemT:CUPKsoH5z8GIAZrCmpFEthq9aTemT
TLSH T115D3AA29F142C773D1930271229DEF222C319BE537CAB51AB3B47AB4A9B70477911E9C
telfhash t1f0315611943546142fb39928acbd56b315221b2323586f716f25c5cc49260e1e93dd0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
16
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sets a written file as executable
Launching a process
Kills processes
Connection attempt
Substitutes an application name
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
gcc lolbin obfuscated remote
Status:
terminated
Behavior Graph:
%3 guuid=4313cff1-1900-0000-d615-22df4c090000 pid=2380 /usr/bin/sudo guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386 /tmp/sample.bin net guuid=4313cff1-1900-0000-d615-22df4c090000 pid=2380->guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392 /tmp/sample.bin zombie guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386->guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392 clone guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393 /usr/bin/dash zombie guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386->guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393 execve guuid=059f5bf5-1900-0000-d615-22df5a090000 pid=2394 /tmp/sample.bin guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386->guuid=059f5bf5-1900-0000-d615-22df5a090000 pid=2394 clone guuid=ad9960f5-1900-0000-d615-22df5b090000 pid=2395 /tmp/sample.bin guuid=9b84ddf3-1900-0000-d615-22df52090000 pid=2386->guuid=ad9960f5-1900-0000-d615-22df5b090000 pid=2395 clone guuid=2adabc27-1a00-0000-d615-22dfd0090000 pid=2512 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=2adabc27-1a00-0000-d615-22dfd0090000 pid=2512 execve guuid=b6cf062b-1a00-0000-d615-22dfd9090000 pid=2521 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=b6cf062b-1a00-0000-d615-22dfd9090000 pid=2521 execve guuid=a501912c-1a00-0000-d615-22dfdf090000 pid=2527 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=a501912c-1a00-0000-d615-22dfdf090000 pid=2527 execve guuid=79e7282e-1a00-0000-d615-22dfe6090000 pid=2534 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=79e7282e-1a00-0000-d615-22dfe6090000 pid=2534 execve guuid=4866ac2f-1a00-0000-d615-22dfed090000 pid=2541 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=4866ac2f-1a00-0000-d615-22dfed090000 pid=2541 execve guuid=b596c530-1a00-0000-d615-22dff2090000 pid=2546 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=b596c530-1a00-0000-d615-22dff2090000 pid=2546 execve guuid=a4d9ed31-1a00-0000-d615-22dff6090000 pid=2550 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=a4d9ed31-1a00-0000-d615-22dff6090000 pid=2550 execve guuid=23da4b33-1a00-0000-d615-22dffc090000 pid=2556 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=23da4b33-1a00-0000-d615-22dffc090000 pid=2556 execve guuid=52815034-1a00-0000-d615-22df000a0000 pid=2560 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=52815034-1a00-0000-d615-22df000a0000 pid=2560 execve guuid=14140063-1b00-0000-d615-22dfb70b0000 pid=2999 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=14140063-1b00-0000-d615-22dfb70b0000 pid=2999 execve guuid=536eae67-1b00-0000-d615-22dfc40b0000 pid=3012 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=536eae67-1b00-0000-d615-22dfc40b0000 pid=3012 execve guuid=31b7ff68-1b00-0000-d615-22dfca0b0000 pid=3018 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=31b7ff68-1b00-0000-d615-22dfca0b0000 pid=3018 execve guuid=a963316a-1b00-0000-d615-22dfcf0b0000 pid=3023 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=a963316a-1b00-0000-d615-22dfcf0b0000 pid=3023 execve guuid=85e8396b-1b00-0000-d615-22dfd50b0000 pid=3029 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=85e8396b-1b00-0000-d615-22dfd50b0000 pid=3029 execve guuid=94b6416c-1b00-0000-d615-22dfdb0b0000 pid=3035 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=94b6416c-1b00-0000-d615-22dfdb0b0000 pid=3035 execve guuid=02614c6d-1b00-0000-d615-22dfe00b0000 pid=3040 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=02614c6d-1b00-0000-d615-22dfe00b0000 pid=3040 execve guuid=154a686e-1b00-0000-d615-22dfe50b0000 pid=3045 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=154a686e-1b00-0000-d615-22dfe50b0000 pid=3045 execve guuid=f91d966f-1b00-0000-d615-22dfeb0b0000 pid=3051 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=f91d966f-1b00-0000-d615-22dfeb0b0000 pid=3051 execve guuid=53bb60af-1c00-0000-d615-22df860e0000 pid=3718 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=53bb60af-1c00-0000-d615-22df860e0000 pid=3718 execve guuid=266103b5-1c00-0000-d615-22df970e0000 pid=3735 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=266103b5-1c00-0000-d615-22df970e0000 pid=3735 execve guuid=2ae7eab6-1c00-0000-d615-22df9f0e0000 pid=3743 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=2ae7eab6-1c00-0000-d615-22df9f0e0000 pid=3743 execve guuid=9e9d15b8-1c00-0000-d615-22dfa60e0000 pid=3750 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=9e9d15b8-1c00-0000-d615-22dfa60e0000 pid=3750 execve guuid=abfd39b9-1c00-0000-d615-22dfad0e0000 pid=3757 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=abfd39b9-1c00-0000-d615-22dfad0e0000 pid=3757 execve guuid=210130ba-1c00-0000-d615-22dfb50e0000 pid=3765 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=210130ba-1c00-0000-d615-22dfb50e0000 pid=3765 execve guuid=3fd14abb-1c00-0000-d615-22dfbb0e0000 pid=3771 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=3fd14abb-1c00-0000-d615-22dfbb0e0000 pid=3771 execve guuid=24f6a8bc-1c00-0000-d615-22dfc20e0000 pid=3778 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=24f6a8bc-1c00-0000-d615-22dfc20e0000 pid=3778 execve guuid=61f4a6bd-1c00-0000-d615-22dfc80e0000 pid=3784 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=61f4a6bd-1c00-0000-d615-22dfc80e0000 pid=3784 execve guuid=cd9812ff-1d00-0000-d615-22dfbb120000 pid=4795 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=cd9812ff-1d00-0000-d615-22dfbb120000 pid=4795 execve guuid=53d34203-1e00-0000-d615-22dfbd120000 pid=4797 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=53d34203-1e00-0000-d615-22dfbd120000 pid=4797 execve guuid=51486204-1e00-0000-d615-22dfbf120000 pid=4799 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=51486204-1e00-0000-d615-22dfbf120000 pid=4799 execve guuid=d0858605-1e00-0000-d615-22dfc1120000 pid=4801 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d0858605-1e00-0000-d615-22dfc1120000 pid=4801 execve guuid=29eba906-1e00-0000-d615-22dfc3120000 pid=4803 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=29eba906-1e00-0000-d615-22dfc3120000 pid=4803 execve guuid=8b6d1308-1e00-0000-d615-22dfc5120000 pid=4805 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=8b6d1308-1e00-0000-d615-22dfc5120000 pid=4805 execve guuid=7c991d09-1e00-0000-d615-22dfc7120000 pid=4807 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=7c991d09-1e00-0000-d615-22dfc7120000 pid=4807 execve guuid=9ef8160a-1e00-0000-d615-22dfc9120000 pid=4809 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=9ef8160a-1e00-0000-d615-22dfc9120000 pid=4809 execve guuid=492bfc0a-1e00-0000-d615-22dfcb120000 pid=4811 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=492bfc0a-1e00-0000-d615-22dfcb120000 pid=4811 execve guuid=0364dc39-1f00-0000-d615-22dfcd120000 pid=4813 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=0364dc39-1f00-0000-d615-22dfcd120000 pid=4813 execve guuid=1391a03c-1f00-0000-d615-22dfcf120000 pid=4815 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=1391a03c-1f00-0000-d615-22dfcf120000 pid=4815 execve guuid=5d9e7b3d-1f00-0000-d615-22dfd1120000 pid=4817 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=5d9e7b3d-1f00-0000-d615-22dfd1120000 pid=4817 execve guuid=8d25623e-1f00-0000-d615-22dfd3120000 pid=4819 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=8d25623e-1f00-0000-d615-22dfd3120000 pid=4819 execve guuid=6fcfa23f-1f00-0000-d615-22dfd5120000 pid=4821 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=6fcfa23f-1f00-0000-d615-22dfd5120000 pid=4821 execve guuid=ce3de140-1f00-0000-d615-22dfd7120000 pid=4823 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=ce3de140-1f00-0000-d615-22dfd7120000 pid=4823 execve guuid=c5991b42-1f00-0000-d615-22dfd9120000 pid=4825 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=c5991b42-1f00-0000-d615-22dfd9120000 pid=4825 execve guuid=78e50a43-1f00-0000-d615-22dfdb120000 pid=4827 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=78e50a43-1f00-0000-d615-22dfdb120000 pid=4827 execve guuid=bfe0e043-1f00-0000-d615-22dfdd120000 pid=4829 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=bfe0e043-1f00-0000-d615-22dfdd120000 pid=4829 execve guuid=707ef071-2000-0000-d615-22dfdf120000 pid=4831 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=707ef071-2000-0000-d615-22dfdf120000 pid=4831 execve guuid=bd0dd174-2000-0000-d615-22dfe1120000 pid=4833 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=bd0dd174-2000-0000-d615-22dfe1120000 pid=4833 execve guuid=127fd175-2000-0000-d615-22dfe3120000 pid=4835 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=127fd175-2000-0000-d615-22dfe3120000 pid=4835 execve guuid=15e6c076-2000-0000-d615-22dfe5120000 pid=4837 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=15e6c076-2000-0000-d615-22dfe5120000 pid=4837 execve guuid=553eaa77-2000-0000-d615-22dfe7120000 pid=4839 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=553eaa77-2000-0000-d615-22dfe7120000 pid=4839 execve guuid=d0508878-2000-0000-d615-22dfe9120000 pid=4841 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d0508878-2000-0000-d615-22dfe9120000 pid=4841 execve guuid=d66c6979-2000-0000-d615-22dfeb120000 pid=4843 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d66c6979-2000-0000-d615-22dfeb120000 pid=4843 execve guuid=0494627a-2000-0000-d615-22dfed120000 pid=4845 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=0494627a-2000-0000-d615-22dfed120000 pid=4845 execve guuid=9fc17d7b-2000-0000-d615-22dfef120000 pid=4847 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=9fc17d7b-2000-0000-d615-22dfef120000 pid=4847 execve guuid=34b90bab-2100-0000-d615-22dff1120000 pid=4849 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=34b90bab-2100-0000-d615-22dff1120000 pid=4849 execve guuid=c8f5adae-2100-0000-d615-22dff3120000 pid=4851 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=c8f5adae-2100-0000-d615-22dff3120000 pid=4851 execve guuid=7cb4ebaf-2100-0000-d615-22dff5120000 pid=4853 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=7cb4ebaf-2100-0000-d615-22dff5120000 pid=4853 execve guuid=700492b1-2100-0000-d615-22dff7120000 pid=4855 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=700492b1-2100-0000-d615-22dff7120000 pid=4855 execve guuid=149248b3-2100-0000-d615-22dff9120000 pid=4857 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=149248b3-2100-0000-d615-22dff9120000 pid=4857 execve guuid=fc4e0fb5-2100-0000-d615-22dffb120000 pid=4859 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=fc4e0fb5-2100-0000-d615-22dffb120000 pid=4859 execve guuid=c394d2b6-2100-0000-d615-22dffd120000 pid=4861 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=c394d2b6-2100-0000-d615-22dffd120000 pid=4861 execve guuid=22027db8-2100-0000-d615-22dfff120000 pid=4863 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=22027db8-2100-0000-d615-22dfff120000 pid=4863 execve guuid=283e44ba-2100-0000-d615-22df01130000 pid=4865 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=283e44ba-2100-0000-d615-22df01130000 pid=4865 execve guuid=a8f793ea-2200-0000-d615-22df03130000 pid=4867 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=a8f793ea-2200-0000-d615-22df03130000 pid=4867 execve guuid=262d38ef-2200-0000-d615-22df05130000 pid=4869 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=262d38ef-2200-0000-d615-22df05130000 pid=4869 execve guuid=898d1af1-2200-0000-d615-22df07130000 pid=4871 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=898d1af1-2200-0000-d615-22df07130000 pid=4871 execve guuid=d036fbf2-2200-0000-d615-22df09130000 pid=4873 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d036fbf2-2200-0000-d615-22df09130000 pid=4873 execve guuid=5b34bdf4-2200-0000-d615-22df0b130000 pid=4875 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=5b34bdf4-2200-0000-d615-22df0b130000 pid=4875 execve guuid=29d8a1f6-2200-0000-d615-22df0d130000 pid=4877 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=29d8a1f6-2200-0000-d615-22df0d130000 pid=4877 execve guuid=adca76f8-2200-0000-d615-22df0f130000 pid=4879 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=adca76f8-2200-0000-d615-22df0f130000 pid=4879 execve guuid=0d3022fa-2200-0000-d615-22df11130000 pid=4881 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=0d3022fa-2200-0000-d615-22df11130000 pid=4881 execve guuid=e8d3edfb-2200-0000-d615-22df13130000 pid=4883 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=e8d3edfb-2200-0000-d615-22df13130000 pid=4883 execve guuid=aaae202c-2400-0000-d615-22df15130000 pid=4885 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=aaae202c-2400-0000-d615-22df15130000 pid=4885 execve guuid=93a8eb30-2400-0000-d615-22df17130000 pid=4887 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=93a8eb30-2400-0000-d615-22df17130000 pid=4887 execve guuid=667cd532-2400-0000-d615-22df19130000 pid=4889 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=667cd532-2400-0000-d615-22df19130000 pid=4889 execve guuid=37d39034-2400-0000-d615-22df1b130000 pid=4891 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=37d39034-2400-0000-d615-22df1b130000 pid=4891 execve guuid=bb584036-2400-0000-d615-22df1d130000 pid=4893 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=bb584036-2400-0000-d615-22df1d130000 pid=4893 execve guuid=763a0d38-2400-0000-d615-22df1f130000 pid=4895 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=763a0d38-2400-0000-d615-22df1f130000 pid=4895 execve guuid=6fa3d339-2400-0000-d615-22df21130000 pid=4897 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=6fa3d339-2400-0000-d615-22df21130000 pid=4897 execve guuid=b437973b-2400-0000-d615-22df23130000 pid=4899 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=b437973b-2400-0000-d615-22df23130000 pid=4899 execve guuid=ee0d3c3d-2400-0000-d615-22df25130000 pid=4901 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=ee0d3c3d-2400-0000-d615-22df25130000 pid=4901 execve guuid=8d70336d-2500-0000-d615-22df27130000 pid=4903 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=8d70336d-2500-0000-d615-22df27130000 pid=4903 execve guuid=f0fd4771-2500-0000-d615-22df29130000 pid=4905 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=f0fd4771-2500-0000-d615-22df29130000 pid=4905 execve guuid=c40b1f73-2500-0000-d615-22df2b130000 pid=4907 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=c40b1f73-2500-0000-d615-22df2b130000 pid=4907 execve guuid=cd5d8374-2500-0000-d615-22df2d130000 pid=4909 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=cd5d8374-2500-0000-d615-22df2d130000 pid=4909 execve guuid=22bb3376-2500-0000-d615-22df2f130000 pid=4911 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=22bb3376-2500-0000-d615-22df2f130000 pid=4911 execve guuid=adf98b77-2500-0000-d615-22df31130000 pid=4913 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=adf98b77-2500-0000-d615-22df31130000 pid=4913 execve guuid=d59ef878-2500-0000-d615-22df33130000 pid=4915 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d59ef878-2500-0000-d615-22df33130000 pid=4915 execve guuid=db756e7a-2500-0000-d615-22df35130000 pid=4917 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=db756e7a-2500-0000-d615-22df35130000 pid=4917 execve guuid=c6334f7c-2500-0000-d615-22df37130000 pid=4919 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=c6334f7c-2500-0000-d615-22df37130000 pid=4919 execve guuid=8d9ee5ab-2600-0000-d615-22df39130000 pid=4921 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=8d9ee5ab-2600-0000-d615-22df39130000 pid=4921 execve guuid=bb0fb7af-2600-0000-d615-22df3b130000 pid=4923 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=bb0fb7af-2600-0000-d615-22df3b130000 pid=4923 execve guuid=10d2a7b0-2600-0000-d615-22df3d130000 pid=4925 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=10d2a7b0-2600-0000-d615-22df3d130000 pid=4925 execve guuid=539ceab1-2600-0000-d615-22df3f130000 pid=4927 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=539ceab1-2600-0000-d615-22df3f130000 pid=4927 execve guuid=143906b3-2600-0000-d615-22df41130000 pid=4929 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=143906b3-2600-0000-d615-22df41130000 pid=4929 execve guuid=83db6eb4-2600-0000-d615-22df43130000 pid=4931 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=83db6eb4-2600-0000-d615-22df43130000 pid=4931 execve guuid=b60487b5-2600-0000-d615-22df45130000 pid=4933 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=b60487b5-2600-0000-d615-22df45130000 pid=4933 execve guuid=ec319eb6-2600-0000-d615-22df47130000 pid=4935 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=ec319eb6-2600-0000-d615-22df47130000 pid=4935 execve guuid=68e21cb8-2600-0000-d615-22df49130000 pid=4937 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=68e21cb8-2600-0000-d615-22df49130000 pid=4937 execve guuid=fe94ade5-2700-0000-d615-22df55130000 pid=4949 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=fe94ade5-2700-0000-d615-22df55130000 pid=4949 execve guuid=f67f24e8-2700-0000-d615-22df57130000 pid=4951 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=f67f24e8-2700-0000-d615-22df57130000 pid=4951 execve guuid=d5f313e9-2700-0000-d615-22df59130000 pid=4953 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=d5f313e9-2700-0000-d615-22df59130000 pid=4953 execve guuid=245f05ea-2700-0000-d615-22df5b130000 pid=4955 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=245f05ea-2700-0000-d615-22df5b130000 pid=4955 execve guuid=fc51edea-2700-0000-d615-22df5d130000 pid=4957 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=fc51edea-2700-0000-d615-22df5d130000 pid=4957 execve guuid=ef2bd4eb-2700-0000-d615-22df5f130000 pid=4959 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=ef2bd4eb-2700-0000-d615-22df5f130000 pid=4959 execve guuid=32a39cec-2700-0000-d615-22df61130000 pid=4961 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=32a39cec-2700-0000-d615-22df61130000 pid=4961 execve guuid=124361ed-2700-0000-d615-22df63130000 pid=4963 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=124361ed-2700-0000-d615-22df63130000 pid=4963 execve guuid=ec3326ee-2700-0000-d615-22df65130000 pid=4965 /usr/bin/dash guuid=77164cf5-1900-0000-d615-22df58090000 pid=2392->guuid=ec3326ee-2700-0000-d615-22df65130000 pid=4965 execve guuid=ec1c1ef6-1900-0000-d615-22df5f090000 pid=2399 /usr/bin/wget dns net send-data guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393->guuid=ec1c1ef6-1900-0000-d615-22df5f090000 pid=2399 execve guuid=9740c901-1a00-0000-d615-22df6e090000 pid=2414 /usr/bin/chmod guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393->guuid=9740c901-1a00-0000-d615-22df6e090000 pid=2414 execve guuid=1c111e02-1a00-0000-d615-22df70090000 pid=2416 /home/sandbox/..... guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393->guuid=1c111e02-1a00-0000-d615-22df70090000 pid=2416 execve guuid=a7f92b05-1a00-0000-d615-22df79090000 pid=2425 /usr/bin/rm delete-file guuid=14ef51f5-1900-0000-d615-22df59090000 pid=2393->guuid=a7f92b05-1a00-0000-d615-22df79090000 pid=2425 execve guuid=32ee73f5-1900-0000-d615-22df5c090000 pid=2396 /tmp/sample.bin net send-data zombie guuid=ad9960f5-1900-0000-d615-22df5b090000 pid=2395->guuid=32ee73f5-1900-0000-d615-22df5c090000 pid=2396 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=32ee73f5-1900-0000-d615-22df5c090000 pid=2396->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ec1c1ef6-1900-0000-d615-22df5f090000 pid=2399->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=6d3df827-1a00-0000-d615-22dfd1090000 pid=2513 /usr/bin/pgrep guuid=2adabc27-1a00-0000-d615-22dfd0090000 pid=2512->guuid=6d3df827-1a00-0000-d615-22dfd1090000 pid=2513 execve guuid=34bd632b-1a00-0000-d615-22dfdb090000 pid=2523 /usr/bin/killall guuid=b6cf062b-1a00-0000-d615-22dfd9090000 pid=2521->guuid=34bd632b-1a00-0000-d615-22dfdb090000 pid=2523 execve guuid=36bede2c-1a00-0000-d615-22dfe1090000 pid=2529 /usr/bin/killall guuid=a501912c-1a00-0000-d615-22dfdf090000 pid=2527->guuid=36bede2c-1a00-0000-d615-22dfe1090000 pid=2529 execve guuid=89ae572e-1a00-0000-d615-22dfe8090000 pid=2536 /usr/bin/killall guuid=79e7282e-1a00-0000-d615-22dfe6090000 pid=2534->guuid=89ae572e-1a00-0000-d615-22dfe8090000 pid=2536 execve guuid=f097e32f-1a00-0000-d615-22dfef090000 pid=2543 /usr/bin/killall guuid=4866ac2f-1a00-0000-d615-22dfed090000 pid=2541->guuid=f097e32f-1a00-0000-d615-22dfef090000 pid=2543 execve guuid=1afcfb30-1a00-0000-d615-22dff3090000 pid=2547 /usr/bin/killall guuid=b596c530-1a00-0000-d615-22dff2090000 pid=2546->guuid=1afcfb30-1a00-0000-d615-22dff3090000 pid=2547 execve guuid=c2182032-1a00-0000-d615-22dff8090000 pid=2552 /usr/bin/killall guuid=a4d9ed31-1a00-0000-d615-22dff6090000 pid=2550->guuid=c2182032-1a00-0000-d615-22dff8090000 pid=2552 execve guuid=e9258c33-1a00-0000-d615-22dffe090000 pid=2558 /usr/bin/killall guuid=23da4b33-1a00-0000-d615-22dffc090000 pid=2556->guuid=e9258c33-1a00-0000-d615-22dffe090000 pid=2558 execve guuid=6d887c34-1a00-0000-d615-22df020a0000 pid=2562 /usr/bin/killall guuid=52815034-1a00-0000-d615-22df000a0000 pid=2560->guuid=6d887c34-1a00-0000-d615-22df020a0000 pid=2562 execve guuid=567d3663-1b00-0000-d615-22dfb80b0000 pid=3000 /usr/bin/pgrep guuid=14140063-1b00-0000-d615-22dfb70b0000 pid=2999->guuid=567d3663-1b00-0000-d615-22dfb80b0000 pid=3000 execve guuid=687bee67-1b00-0000-d615-22dfc60b0000 pid=3014 /usr/bin/killall guuid=536eae67-1b00-0000-d615-22dfc40b0000 pid=3012->guuid=687bee67-1b00-0000-d615-22dfc60b0000 pid=3014 execve guuid=56552d69-1b00-0000-d615-22dfcc0b0000 pid=3020 /usr/bin/killall guuid=31b7ff68-1b00-0000-d615-22dfca0b0000 pid=3018->guuid=56552d69-1b00-0000-d615-22dfcc0b0000 pid=3020 execve guuid=c8245c6a-1b00-0000-d615-22dfd10b0000 pid=3025 /usr/bin/killall guuid=a963316a-1b00-0000-d615-22dfcf0b0000 pid=3023->guuid=c8245c6a-1b00-0000-d615-22dfd10b0000 pid=3025 execve guuid=9c85676b-1b00-0000-d615-22dfd70b0000 pid=3031 /usr/bin/killall guuid=85e8396b-1b00-0000-d615-22dfd50b0000 pid=3029->guuid=9c85676b-1b00-0000-d615-22dfd70b0000 pid=3031 execve guuid=d355716c-1b00-0000-d615-22dfdd0b0000 pid=3037 /usr/bin/killall guuid=94b6416c-1b00-0000-d615-22dfdb0b0000 pid=3035->guuid=d355716c-1b00-0000-d615-22dfdd0b0000 pid=3037 execve guuid=5bff7c6d-1b00-0000-d615-22dfe10b0000 pid=3041 /usr/bin/killall guuid=02614c6d-1b00-0000-d615-22dfe00b0000 pid=3040->guuid=5bff7c6d-1b00-0000-d615-22dfe10b0000 pid=3041 execve guuid=cd98bd6e-1b00-0000-d615-22dfe80b0000 pid=3048 /usr/bin/killall guuid=154a686e-1b00-0000-d615-22dfe50b0000 pid=3045->guuid=cd98bd6e-1b00-0000-d615-22dfe80b0000 pid=3048 execve guuid=72cce46f-1b00-0000-d615-22dfed0b0000 pid=3053 /usr/bin/killall guuid=f91d966f-1b00-0000-d615-22dfeb0b0000 pid=3051->guuid=72cce46f-1b00-0000-d615-22dfed0b0000 pid=3053 execve guuid=3398a5af-1c00-0000-d615-22df880e0000 pid=3720 /usr/bin/pgrep guuid=53bb60af-1c00-0000-d615-22df860e0000 pid=3718->guuid=3398a5af-1c00-0000-d615-22df880e0000 pid=3720 execve guuid=4fba34b5-1c00-0000-d615-22df980e0000 pid=3736 /usr/bin/killall guuid=266103b5-1c00-0000-d615-22df970e0000 pid=3735->guuid=4fba34b5-1c00-0000-d615-22df980e0000 pid=3736 execve guuid=c08718b7-1c00-0000-d615-22dfa10e0000 pid=3745 /usr/bin/killall guuid=2ae7eab6-1c00-0000-d615-22df9f0e0000 pid=3743->guuid=c08718b7-1c00-0000-d615-22dfa10e0000 pid=3745 execve guuid=c6124fb8-1c00-0000-d615-22dfaa0e0000 pid=3754 /usr/bin/killall guuid=9e9d15b8-1c00-0000-d615-22dfa60e0000 pid=3750->guuid=c6124fb8-1c00-0000-d615-22dfaa0e0000 pid=3754 execve guuid=4e1c6db9-1c00-0000-d615-22dfb10e0000 pid=3761 /usr/bin/killall guuid=abfd39b9-1c00-0000-d615-22dfad0e0000 pid=3757->guuid=4e1c6db9-1c00-0000-d615-22dfb10e0000 pid=3761 execve guuid=8a506fba-1c00-0000-d615-22dfb60e0000 pid=3766 /usr/bin/killall guuid=210130ba-1c00-0000-d615-22dfb50e0000 pid=3765->guuid=8a506fba-1c00-0000-d615-22dfb60e0000 pid=3766 execve guuid=24be73bb-1c00-0000-d615-22dfbd0e0000 pid=3773 /usr/bin/killall guuid=3fd14abb-1c00-0000-d615-22dfbb0e0000 pid=3771->guuid=24be73bb-1c00-0000-d615-22dfbd0e0000 pid=3773 execve guuid=459ee1bc-1c00-0000-d615-22dfc40e0000 pid=3780 /usr/bin/killall guuid=24f6a8bc-1c00-0000-d615-22dfc20e0000 pid=3778->guuid=459ee1bc-1c00-0000-d615-22dfc40e0000 pid=3780 execve guuid=8da3e1bd-1c00-0000-d615-22dfca0e0000 pid=3786 /usr/bin/killall guuid=61f4a6bd-1c00-0000-d615-22dfc80e0000 pid=3784->guuid=8da3e1bd-1c00-0000-d615-22dfca0e0000 pid=3786 execve guuid=0ea88aff-1d00-0000-d615-22dfbc120000 pid=4796 /usr/bin/pgrep guuid=cd9812ff-1d00-0000-d615-22dfbb120000 pid=4795->guuid=0ea88aff-1d00-0000-d615-22dfbc120000 pid=4796 execve guuid=65589d03-1e00-0000-d615-22dfbe120000 pid=4798 /usr/bin/killall guuid=53d34203-1e00-0000-d615-22dfbd120000 pid=4797->guuid=65589d03-1e00-0000-d615-22dfbe120000 pid=4798 execve guuid=b5cac904-1e00-0000-d615-22dfc0120000 pid=4800 /usr/bin/killall guuid=51486204-1e00-0000-d615-22dfbf120000 pid=4799->guuid=b5cac904-1e00-0000-d615-22dfc0120000 pid=4800 execve guuid=9ea1d805-1e00-0000-d615-22dfc2120000 pid=4802 /usr/bin/killall guuid=d0858605-1e00-0000-d615-22dfc1120000 pid=4801->guuid=9ea1d805-1e00-0000-d615-22dfc2120000 pid=4802 execve guuid=dedf0007-1e00-0000-d615-22dfc4120000 pid=4804 /usr/bin/killall guuid=29eba906-1e00-0000-d615-22dfc3120000 pid=4803->guuid=dedf0007-1e00-0000-d615-22dfc4120000 pid=4804 execve guuid=2bed4708-1e00-0000-d615-22dfc6120000 pid=4806 /usr/bin/killall guuid=8b6d1308-1e00-0000-d615-22dfc5120000 pid=4805->guuid=2bed4708-1e00-0000-d615-22dfc6120000 pid=4806 execve guuid=b51b5809-1e00-0000-d615-22dfc8120000 pid=4808 /usr/bin/killall guuid=7c991d09-1e00-0000-d615-22dfc7120000 pid=4807->guuid=b51b5809-1e00-0000-d615-22dfc8120000 pid=4808 execve guuid=b315480a-1e00-0000-d615-22dfca120000 pid=4810 /usr/bin/killall guuid=9ef8160a-1e00-0000-d615-22dfc9120000 pid=4809->guuid=b315480a-1e00-0000-d615-22dfca120000 pid=4810 execve guuid=13362c0b-1e00-0000-d615-22dfcc120000 pid=4812 /usr/bin/killall guuid=492bfc0a-1e00-0000-d615-22dfcb120000 pid=4811->guuid=13362c0b-1e00-0000-d615-22dfcc120000 pid=4812 execve guuid=87f7323a-1f00-0000-d615-22dfce120000 pid=4814 /usr/bin/pgrep guuid=0364dc39-1f00-0000-d615-22dfcd120000 pid=4813->guuid=87f7323a-1f00-0000-d615-22dfce120000 pid=4814 execve guuid=9593d33c-1f00-0000-d615-22dfd0120000 pid=4816 /usr/bin/killall guuid=1391a03c-1f00-0000-d615-22dfcf120000 pid=4815->guuid=9593d33c-1f00-0000-d615-22dfd0120000 pid=4816 execve guuid=0577ae3d-1f00-0000-d615-22dfd2120000 pid=4818 /usr/bin/killall guuid=5d9e7b3d-1f00-0000-d615-22dfd1120000 pid=4817->guuid=0577ae3d-1f00-0000-d615-22dfd2120000 pid=4818 execve guuid=40b2aa3e-1f00-0000-d615-22dfd4120000 pid=4820 /usr/bin/killall guuid=8d25623e-1f00-0000-d615-22dfd3120000 pid=4819->guuid=40b2aa3e-1f00-0000-d615-22dfd4120000 pid=4820 execve guuid=c788f23f-1f00-0000-d615-22dfd6120000 pid=4822 /usr/bin/killall guuid=6fcfa23f-1f00-0000-d615-22dfd5120000 pid=4821->guuid=c788f23f-1f00-0000-d615-22dfd6120000 pid=4822 execve guuid=2c463141-1f00-0000-d615-22dfd8120000 pid=4824 /usr/bin/killall guuid=ce3de140-1f00-0000-d615-22dfd7120000 pid=4823->guuid=2c463141-1f00-0000-d615-22dfd8120000 pid=4824 execve guuid=dfb24e42-1f00-0000-d615-22dfda120000 pid=4826 /usr/bin/killall guuid=c5991b42-1f00-0000-d615-22dfd9120000 pid=4825->guuid=dfb24e42-1f00-0000-d615-22dfda120000 pid=4826 execve guuid=3d7e3443-1f00-0000-d615-22dfdc120000 pid=4828 /usr/bin/killall guuid=78e50a43-1f00-0000-d615-22dfdb120000 pid=4827->guuid=3d7e3443-1f00-0000-d615-22dfdc120000 pid=4828 execve guuid=acd21244-1f00-0000-d615-22dfde120000 pid=4830 /usr/bin/killall guuid=bfe0e043-1f00-0000-d615-22dfdd120000 pid=4829->guuid=acd21244-1f00-0000-d615-22dfde120000 pid=4830 execve guuid=8eef2d72-2000-0000-d615-22dfe0120000 pid=4832 /usr/bin/pgrep guuid=707ef071-2000-0000-d615-22dfdf120000 pid=4831->guuid=8eef2d72-2000-0000-d615-22dfe0120000 pid=4832 execve guuid=54240b75-2000-0000-d615-22dfe2120000 pid=4834 /usr/bin/killall guuid=bd0dd174-2000-0000-d615-22dfe1120000 pid=4833->guuid=54240b75-2000-0000-d615-22dfe2120000 pid=4834 execve guuid=bf720976-2000-0000-d615-22dfe4120000 pid=4836 /usr/bin/killall guuid=127fd175-2000-0000-d615-22dfe3120000 pid=4835->guuid=bf720976-2000-0000-d615-22dfe4120000 pid=4836 execve guuid=79a1f176-2000-0000-d615-22dfe6120000 pid=4838 /usr/bin/killall guuid=15e6c076-2000-0000-d615-22dfe5120000 pid=4837->guuid=79a1f176-2000-0000-d615-22dfe6120000 pid=4838 execve guuid=c45cda77-2000-0000-d615-22dfe8120000 pid=4840 /usr/bin/killall guuid=553eaa77-2000-0000-d615-22dfe7120000 pid=4839->guuid=c45cda77-2000-0000-d615-22dfe8120000 pid=4840 execve guuid=0a6eb478-2000-0000-d615-22dfea120000 pid=4842 /usr/bin/killall guuid=d0508878-2000-0000-d615-22dfe9120000 pid=4841->guuid=0a6eb478-2000-0000-d615-22dfea120000 pid=4842 execve guuid=2b879a79-2000-0000-d615-22dfec120000 pid=4844 /usr/bin/killall guuid=d66c6979-2000-0000-d615-22dfeb120000 pid=4843->guuid=2b879a79-2000-0000-d615-22dfec120000 pid=4844 execve guuid=0e21907a-2000-0000-d615-22dfee120000 pid=4846 /usr/bin/killall guuid=0494627a-2000-0000-d615-22dfed120000 pid=4845->guuid=0e21907a-2000-0000-d615-22dfee120000 pid=4846 execve guuid=0251b07b-2000-0000-d615-22dff0120000 pid=4848 /usr/bin/killall guuid=9fc17d7b-2000-0000-d615-22dfef120000 pid=4847->guuid=0251b07b-2000-0000-d615-22dff0120000 pid=4848 execve guuid=52e163ab-2100-0000-d615-22dff2120000 pid=4850 /usr/bin/pgrep guuid=34b90bab-2100-0000-d615-22dff1120000 pid=4849->guuid=52e163ab-2100-0000-d615-22dff2120000 pid=4850 execve guuid=bb77ffae-2100-0000-d615-22dff4120000 pid=4852 /usr/bin/killall guuid=c8f5adae-2100-0000-d615-22dff3120000 pid=4851->guuid=bb77ffae-2100-0000-d615-22dff4120000 pid=4852 execve guuid=5cd531b0-2100-0000-d615-22dff6120000 pid=4854 /usr/bin/killall guuid=7cb4ebaf-2100-0000-d615-22dff5120000 pid=4853->guuid=5cd531b0-2100-0000-d615-22dff6120000 pid=4854 execve guuid=c75fe6b1-2100-0000-d615-22dff8120000 pid=4856 /usr/bin/killall guuid=700492b1-2100-0000-d615-22dff7120000 pid=4855->guuid=c75fe6b1-2100-0000-d615-22dff8120000 pid=4856 execve guuid=ca31a3b3-2100-0000-d615-22dffa120000 pid=4858 /usr/bin/killall guuid=149248b3-2100-0000-d615-22dff9120000 pid=4857->guuid=ca31a3b3-2100-0000-d615-22dffa120000 pid=4858 execve guuid=bc5e6bb5-2100-0000-d615-22dffc120000 pid=4860 /usr/bin/killall guuid=fc4e0fb5-2100-0000-d615-22dffb120000 pid=4859->guuid=bc5e6bb5-2100-0000-d615-22dffc120000 pid=4860 execve guuid=7b7322b7-2100-0000-d615-22dffe120000 pid=4862 /usr/bin/killall guuid=c394d2b6-2100-0000-d615-22dffd120000 pid=4861->guuid=7b7322b7-2100-0000-d615-22dffe120000 pid=4862 execve guuid=de49d8b8-2100-0000-d615-22df00130000 pid=4864 /usr/bin/killall guuid=22027db8-2100-0000-d615-22dfff120000 pid=4863->guuid=de49d8b8-2100-0000-d615-22df00130000 pid=4864 execve guuid=eac09dba-2100-0000-d615-22df02130000 pid=4866 /usr/bin/killall guuid=283e44ba-2100-0000-d615-22df01130000 pid=4865->guuid=eac09dba-2100-0000-d615-22df02130000 pid=4866 execve guuid=8b87eaea-2200-0000-d615-22df04130000 pid=4868 /usr/bin/pgrep guuid=a8f793ea-2200-0000-d615-22df03130000 pid=4867->guuid=8b87eaea-2200-0000-d615-22df04130000 pid=4868 execve guuid=14c4a5ef-2200-0000-d615-22df06130000 pid=4870 /usr/bin/killall guuid=262d38ef-2200-0000-d615-22df05130000 pid=4869->guuid=14c4a5ef-2200-0000-d615-22df06130000 pid=4870 execve guuid=9ac181f1-2200-0000-d615-22df08130000 pid=4872 /usr/bin/killall guuid=898d1af1-2200-0000-d615-22df07130000 pid=4871->guuid=9ac181f1-2200-0000-d615-22df08130000 pid=4872 execve guuid=7d4146f3-2200-0000-d615-22df0a130000 pid=4874 /usr/bin/killall guuid=d036fbf2-2200-0000-d615-22df09130000 pid=4873->guuid=7d4146f3-2200-0000-d615-22df0a130000 pid=4874 execve guuid=149e39f5-2200-0000-d615-22df0c130000 pid=4876 /usr/bin/killall guuid=5b34bdf4-2200-0000-d615-22df0b130000 pid=4875->guuid=149e39f5-2200-0000-d615-22df0c130000 pid=4876 execve guuid=863b07f7-2200-0000-d615-22df0e130000 pid=4878 /usr/bin/killall guuid=29d8a1f6-2200-0000-d615-22df0d130000 pid=4877->guuid=863b07f7-2200-0000-d615-22df0e130000 pid=4878 execve guuid=8bd3d1f8-2200-0000-d615-22df10130000 pid=4880 /usr/bin/killall guuid=adca76f8-2200-0000-d615-22df0f130000 pid=4879->guuid=8bd3d1f8-2200-0000-d615-22df10130000 pid=4880 execve guuid=539f73fa-2200-0000-d615-22df12130000 pid=4882 /usr/bin/killall guuid=0d3022fa-2200-0000-d615-22df11130000 pid=4881->guuid=539f73fa-2200-0000-d615-22df12130000 pid=4882 execve guuid=934e52fc-2200-0000-d615-22df14130000 pid=4884 /usr/bin/killall guuid=e8d3edfb-2200-0000-d615-22df13130000 pid=4883->guuid=934e52fc-2200-0000-d615-22df14130000 pid=4884 execve guuid=e2768e2c-2400-0000-d615-22df16130000 pid=4886 /usr/bin/pgrep guuid=aaae202c-2400-0000-d615-22df15130000 pid=4885->guuid=e2768e2c-2400-0000-d615-22df16130000 pid=4886 execve guuid=f3344b31-2400-0000-d615-22df18130000 pid=4888 /usr/bin/killall guuid=93a8eb30-2400-0000-d615-22df17130000 pid=4887->guuid=f3344b31-2400-0000-d615-22df18130000 pid=4888 execve guuid=af9a3033-2400-0000-d615-22df1a130000 pid=4890 /usr/bin/killall guuid=667cd532-2400-0000-d615-22df19130000 pid=4889->guuid=af9a3033-2400-0000-d615-22df1a130000 pid=4890 execve guuid=e72ee334-2400-0000-d615-22df1c130000 pid=4892 /usr/bin/killall guuid=37d39034-2400-0000-d615-22df1b130000 pid=4891->guuid=e72ee334-2400-0000-d615-22df1c130000 pid=4892 execve guuid=a3c29936-2400-0000-d615-22df1e130000 pid=4894 /usr/bin/killall guuid=bb584036-2400-0000-d615-22df1d130000 pid=4893->guuid=a3c29936-2400-0000-d615-22df1e130000 pid=4894 execve guuid=5b246c38-2400-0000-d615-22df20130000 pid=4896 /usr/bin/killall guuid=763a0d38-2400-0000-d615-22df1f130000 pid=4895->guuid=5b246c38-2400-0000-d615-22df20130000 pid=4896 execve guuid=ce852f3a-2400-0000-d615-22df22130000 pid=4898 /usr/bin/killall guuid=6fa3d339-2400-0000-d615-22df21130000 pid=4897->guuid=ce852f3a-2400-0000-d615-22df22130000 pid=4898 execve guuid=62e8f73b-2400-0000-d615-22df24130000 pid=4900 /usr/bin/killall guuid=b437973b-2400-0000-d615-22df23130000 pid=4899->guuid=62e8f73b-2400-0000-d615-22df24130000 pid=4900 execve guuid=27018d3d-2400-0000-d615-22df26130000 pid=4902 /usr/bin/killall guuid=ee0d3c3d-2400-0000-d615-22df25130000 pid=4901->guuid=27018d3d-2400-0000-d615-22df26130000 pid=4902 execve guuid=b8b09e6d-2500-0000-d615-22df28130000 pid=4904 /usr/bin/pgrep guuid=8d70336d-2500-0000-d615-22df27130000 pid=4903->guuid=b8b09e6d-2500-0000-d615-22df28130000 pid=4904 execve guuid=76d58471-2500-0000-d615-22df2a130000 pid=4906 /usr/bin/killall guuid=f0fd4771-2500-0000-d615-22df29130000 pid=4905->guuid=76d58471-2500-0000-d615-22df2a130000 pid=4906 execve guuid=46827a73-2500-0000-d615-22df2c130000 pid=4908 /usr/bin/killall guuid=c40b1f73-2500-0000-d615-22df2b130000 pid=4907->guuid=46827a73-2500-0000-d615-22df2c130000 pid=4908 execve guuid=c4bfc974-2500-0000-d615-22df2e130000 pid=4910 /usr/bin/killall guuid=cd5d8374-2500-0000-d615-22df2d130000 pid=4909->guuid=c4bfc974-2500-0000-d615-22df2e130000 pid=4910 execve guuid=7ed38c76-2500-0000-d615-22df30130000 pid=4912 /usr/bin/killall guuid=22bb3376-2500-0000-d615-22df2f130000 pid=4911->guuid=7ed38c76-2500-0000-d615-22df30130000 pid=4912 execve guuid=d325ee77-2500-0000-d615-22df32130000 pid=4914 /usr/bin/killall guuid=adf98b77-2500-0000-d615-22df31130000 pid=4913->guuid=d325ee77-2500-0000-d615-22df32130000 pid=4914 execve guuid=87f66279-2500-0000-d615-22df34130000 pid=4916 /usr/bin/killall guuid=d59ef878-2500-0000-d615-22df33130000 pid=4915->guuid=87f66279-2500-0000-d615-22df34130000 pid=4916 execve guuid=b684bb7a-2500-0000-d615-22df36130000 pid=4918 /usr/bin/killall guuid=db756e7a-2500-0000-d615-22df35130000 pid=4917->guuid=b684bb7a-2500-0000-d615-22df36130000 pid=4918 execve guuid=a460b17c-2500-0000-d615-22df38130000 pid=4920 /usr/bin/killall guuid=c6334f7c-2500-0000-d615-22df37130000 pid=4919->guuid=a460b17c-2500-0000-d615-22df38130000 pid=4920 execve guuid=a44616ac-2600-0000-d615-22df3a130000 pid=4922 /usr/bin/pgrep guuid=8d9ee5ab-2600-0000-d615-22df39130000 pid=4921->guuid=a44616ac-2600-0000-d615-22df3a130000 pid=4922 execve guuid=f1e0e6af-2600-0000-d615-22df3c130000 pid=4924 /usr/bin/killall guuid=bb0fb7af-2600-0000-d615-22df3b130000 pid=4923->guuid=f1e0e6af-2600-0000-d615-22df3c130000 pid=4924 execve guuid=eb52d6b0-2600-0000-d615-22df3e130000 pid=4926 /usr/bin/killall guuid=10d2a7b0-2600-0000-d615-22df3d130000 pid=4925->guuid=eb52d6b0-2600-0000-d615-22df3e130000 pid=4926 execve guuid=76c219b2-2600-0000-d615-22df40130000 pid=4928 /usr/bin/killall guuid=539ceab1-2600-0000-d615-22df3f130000 pid=4927->guuid=76c219b2-2600-0000-d615-22df40130000 pid=4928 execve guuid=6ce139b3-2600-0000-d615-22df42130000 pid=4930 /usr/bin/killall guuid=143906b3-2600-0000-d615-22df41130000 pid=4929->guuid=6ce139b3-2600-0000-d615-22df42130000 pid=4930 execve guuid=4dee9ab4-2600-0000-d615-22df44130000 pid=4932 /usr/bin/killall guuid=83db6eb4-2600-0000-d615-22df43130000 pid=4931->guuid=4dee9ab4-2600-0000-d615-22df44130000 pid=4932 execve guuid=a3d3b1b5-2600-0000-d615-22df46130000 pid=4934 /usr/bin/killall guuid=b60487b5-2600-0000-d615-22df45130000 pid=4933->guuid=a3d3b1b5-2600-0000-d615-22df46130000 pid=4934 execve guuid=42eddcb6-2600-0000-d615-22df48130000 pid=4936 /usr/bin/killall guuid=ec319eb6-2600-0000-d615-22df47130000 pid=4935->guuid=42eddcb6-2600-0000-d615-22df48130000 pid=4936 execve guuid=7c7248b8-2600-0000-d615-22df4a130000 pid=4938 /usr/bin/killall guuid=68e21cb8-2600-0000-d615-22df49130000 pid=4937->guuid=7c7248b8-2600-0000-d615-22df4a130000 pid=4938 execve guuid=3a62dee5-2700-0000-d615-22df56130000 pid=4950 /usr/bin/pgrep guuid=fe94ade5-2700-0000-d615-22df55130000 pid=4949->guuid=3a62dee5-2700-0000-d615-22df56130000 pid=4950 execve guuid=e74f58e8-2700-0000-d615-22df58130000 pid=4952 /usr/bin/killall guuid=f67f24e8-2700-0000-d615-22df57130000 pid=4951->guuid=e74f58e8-2700-0000-d615-22df58130000 pid=4952 execve guuid=168d48e9-2700-0000-d615-22df5a130000 pid=4954 /usr/bin/killall guuid=d5f313e9-2700-0000-d615-22df59130000 pid=4953->guuid=168d48e9-2700-0000-d615-22df5a130000 pid=4954 execve guuid=8e0539ea-2700-0000-d615-22df5c130000 pid=4956 /usr/bin/killall guuid=245f05ea-2700-0000-d615-22df5b130000 pid=4955->guuid=8e0539ea-2700-0000-d615-22df5c130000 pid=4956 execve guuid=d48f18eb-2700-0000-d615-22df5e130000 pid=4958 /usr/bin/killall guuid=fc51edea-2700-0000-d615-22df5d130000 pid=4957->guuid=d48f18eb-2700-0000-d615-22df5e130000 pid=4958 execve guuid=4c3ffdeb-2700-0000-d615-22df60130000 pid=4960 /usr/bin/killall guuid=ef2bd4eb-2700-0000-d615-22df5f130000 pid=4959->guuid=4c3ffdeb-2700-0000-d615-22df60130000 pid=4960 execve guuid=1851c8ec-2700-0000-d615-22df62130000 pid=4962 /usr/bin/killall guuid=32a39cec-2700-0000-d615-22df61130000 pid=4961->guuid=1851c8ec-2700-0000-d615-22df62130000 pid=4962 execve guuid=d9d38ded-2700-0000-d615-22df64130000 pid=4964 /usr/bin/killall guuid=124361ed-2700-0000-d615-22df63130000 pid=4963->guuid=d9d38ded-2700-0000-d615-22df64130000 pid=4964 execve guuid=5b434eee-2700-0000-d615-22df66130000 pid=4966 /usr/bin/killall guuid=ec3326ee-2700-0000-d615-22df65130000 pid=4965->guuid=5b434eee-2700-0000-d615-22df66130000 pid=4966 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734331 Sample: getty.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 37 206.123.128.67, 51850, 51852, 51854 LEASEWEB-USA-NYC-11US United States 2->37 39 109.202.202.202, 80 INIT7CH Switzerland 2->39 41 3 other IPs or domains 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 getty.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 getty.elf 9->12         started        process6 process7 14 getty.elf sh 12->14         started        16 getty.elf sh 12->16         started        18 getty.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-11 23:06:09 UTC
File Type:
ELF32 Little (Exe)
AV detection:
17 of 24 (70.83%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan mirai gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_c573932b Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_71e487ea Linux_Trojan_Gafgyt_7167d08f Linux_Trojan_Mirai_389ee3e9 elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_7167d08f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_71e487ea
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_c573932b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf ab25962702b71fe70387339874670dd411659dc44235f2886aac47693354a3a1

(this sample)

  
Delivery method
Distributed via web download

Comments