MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 aec725fa640c11c35d73d7f3e267cd4b79f05f1158a0c263a9ba3a8783c5cc63. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 29 File information Comments

SHA256 hash: aec725fa640c11c35d73d7f3e267cd4b79f05f1158a0c263a9ba3a8783c5cc63
SHA3-384 hash: b67e50436db968a89f4185e0e2915eae69f3ac2848c23ba071bce4421bf4899f1306ab91e0e6746f135a3dc8c7a54895
SHA1 hash: 5c6d9e61ec86e7fa882e4ac92ae72bfc685a2f08
MD5 hash: eef2c947ef2ff028d1096025232791cc
humanhash: aspen-arkansas-north-five
File name:ssh
Download: download sample
Signature Mirai
File size:121'068 bytes
First seen:2025-07-13 00:47:46 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:6fQtdvzgR5RBWJz58fm0lUKqR/P2VH+WcmmFT8hBAkDlLgNU:6ZbNmcoR/rWcmmFT8hBAkDlLgNU
TLSH T136C33A27A555CA7AC09752F027DBE6619813FCBD0B32320B73D4BDA52B798C81E29F11
telfhash t181315622943546142fb3a928acfd56b315322b2323596f71af26c5cc49360f1e93dd4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
20
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
DNS request
Creating a file
Sets a written file as executable
Launching a process
Kills processes
Sends data to a server
Connection attempt
Substitutes an application name
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=f91a64f6-1900-0000-b86c-2b150c090000 pid=2316 /usr/bin/sudo guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320 /tmp/sample.bin net guuid=f91a64f6-1900-0000-b86c-2b150c090000 pid=2316->guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322 /tmp/sample.bin zombie guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320->guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322 clone guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323 /usr/bin/dash zombie guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320->guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323 execve guuid=5d87ecf9-1900-0000-b86c-2b1514090000 pid=2324 /tmp/sample.bin guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320->guuid=5d87ecf9-1900-0000-b86c-2b1514090000 pid=2324 clone guuid=b1a4eff9-1900-0000-b86c-2b1515090000 pid=2325 /tmp/sample.bin guuid=d786b0f9-1900-0000-b86c-2b1510090000 pid=2320->guuid=b1a4eff9-1900-0000-b86c-2b1515090000 pid=2325 clone guuid=cd295c29-1a00-0000-b86c-2b1574090000 pid=2420 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=cd295c29-1a00-0000-b86c-2b1574090000 pid=2420 execve guuid=00bf1d2d-1a00-0000-b86c-2b157e090000 pid=2430 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=00bf1d2d-1a00-0000-b86c-2b157e090000 pid=2430 execve guuid=327e7a2e-1a00-0000-b86c-2b1582090000 pid=2434 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=327e7a2e-1a00-0000-b86c-2b1582090000 pid=2434 execve guuid=1c240030-1a00-0000-b86c-2b1588090000 pid=2440 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=1c240030-1a00-0000-b86c-2b1588090000 pid=2440 execve guuid=df9ce630-1a00-0000-b86c-2b158c090000 pid=2444 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=df9ce630-1a00-0000-b86c-2b158c090000 pid=2444 execve guuid=c8d25232-1a00-0000-b86c-2b1591090000 pid=2449 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=c8d25232-1a00-0000-b86c-2b1591090000 pid=2449 execve guuid=62703a33-1a00-0000-b86c-2b1595090000 pid=2453 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=62703a33-1a00-0000-b86c-2b1595090000 pid=2453 execve guuid=5f917134-1a00-0000-b86c-2b159c090000 pid=2460 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=5f917134-1a00-0000-b86c-2b159c090000 pid=2460 execve guuid=d969ca35-1a00-0000-b86c-2b15a1090000 pid=2465 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=d969ca35-1a00-0000-b86c-2b15a1090000 pid=2465 execve guuid=d5f35161-1b00-0000-b86c-2b15860c0000 pid=3206 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=d5f35161-1b00-0000-b86c-2b15860c0000 pid=3206 execve guuid=7e970865-1b00-0000-b86c-2b158f0c0000 pid=3215 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=7e970865-1b00-0000-b86c-2b158f0c0000 pid=3215 execve guuid=849c2966-1b00-0000-b86c-2b15940c0000 pid=3220 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=849c2966-1b00-0000-b86c-2b15940c0000 pid=3220 execve guuid=32b66567-1b00-0000-b86c-2b15990c0000 pid=3225 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=32b66567-1b00-0000-b86c-2b15990c0000 pid=3225 execve guuid=dba1a068-1b00-0000-b86c-2b159b0c0000 pid=3227 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=dba1a068-1b00-0000-b86c-2b159b0c0000 pid=3227 execve guuid=37b0656a-1b00-0000-b86c-2b159f0c0000 pid=3231 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=37b0656a-1b00-0000-b86c-2b159f0c0000 pid=3231 execve guuid=fd609c6b-1b00-0000-b86c-2b15a40c0000 pid=3236 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=fd609c6b-1b00-0000-b86c-2b15a40c0000 pid=3236 execve guuid=fd09c96c-1b00-0000-b86c-2b15a90c0000 pid=3241 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=fd09c96c-1b00-0000-b86c-2b15a90c0000 pid=3241 execve guuid=8febb36d-1b00-0000-b86c-2b15ad0c0000 pid=3245 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=8febb36d-1b00-0000-b86c-2b15ad0c0000 pid=3245 execve guuid=c44b02aa-1c00-0000-b86c-2b15b40f0000 pid=4020 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=c44b02aa-1c00-0000-b86c-2b15b40f0000 pid=4020 execve guuid=85fa09ae-1c00-0000-b86c-2b15b70f0000 pid=4023 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=85fa09ae-1c00-0000-b86c-2b15b70f0000 pid=4023 execve guuid=2c91e5ae-1c00-0000-b86c-2b15bb0f0000 pid=4027 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=2c91e5ae-1c00-0000-b86c-2b15bb0f0000 pid=4027 execve guuid=4d12bbaf-1c00-0000-b86c-2b15c00f0000 pid=4032 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=4d12bbaf-1c00-0000-b86c-2b15c00f0000 pid=4032 execve guuid=4be7a9b0-1c00-0000-b86c-2b15c20f0000 pid=4034 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=4be7a9b0-1c00-0000-b86c-2b15c20f0000 pid=4034 execve guuid=3ebf9eb1-1c00-0000-b86c-2b15c40f0000 pid=4036 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=3ebf9eb1-1c00-0000-b86c-2b15c40f0000 pid=4036 execve guuid=e66c88b2-1c00-0000-b86c-2b15c60f0000 pid=4038 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=e66c88b2-1c00-0000-b86c-2b15c60f0000 pid=4038 execve guuid=956865b3-1c00-0000-b86c-2b15c80f0000 pid=4040 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=956865b3-1c00-0000-b86c-2b15c80f0000 pid=4040 execve guuid=e92f3bb4-1c00-0000-b86c-2b15ca0f0000 pid=4042 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=e92f3bb4-1c00-0000-b86c-2b15ca0f0000 pid=4042 execve guuid=a1969adf-1d00-0000-b86c-2b15cc0f0000 pid=4044 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=a1969adf-1d00-0000-b86c-2b15cc0f0000 pid=4044 execve guuid=f196f6e4-1d00-0000-b86c-2b15ce0f0000 pid=4046 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f196f6e4-1d00-0000-b86c-2b15ce0f0000 pid=4046 execve guuid=39a07fe6-1d00-0000-b86c-2b15d00f0000 pid=4048 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=39a07fe6-1d00-0000-b86c-2b15d00f0000 pid=4048 execve guuid=02a86de7-1d00-0000-b86c-2b15d20f0000 pid=4050 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=02a86de7-1d00-0000-b86c-2b15d20f0000 pid=4050 execve guuid=f4738fe8-1d00-0000-b86c-2b15d40f0000 pid=4052 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f4738fe8-1d00-0000-b86c-2b15d40f0000 pid=4052 execve guuid=4fc071e9-1d00-0000-b86c-2b15d60f0000 pid=4054 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=4fc071e9-1d00-0000-b86c-2b15d60f0000 pid=4054 execve guuid=1aa23bea-1d00-0000-b86c-2b15d80f0000 pid=4056 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=1aa23bea-1d00-0000-b86c-2b15d80f0000 pid=4056 execve guuid=d73c22eb-1d00-0000-b86c-2b15da0f0000 pid=4058 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=d73c22eb-1d00-0000-b86c-2b15da0f0000 pid=4058 execve guuid=cadd07ec-1d00-0000-b86c-2b15dc0f0000 pid=4060 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=cadd07ec-1d00-0000-b86c-2b15dc0f0000 pid=4060 execve guuid=93b3ec17-1f00-0000-b86c-2b15de0f0000 pid=4062 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=93b3ec17-1f00-0000-b86c-2b15de0f0000 pid=4062 execve guuid=7a97db1b-1f00-0000-b86c-2b15e00f0000 pid=4064 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=7a97db1b-1f00-0000-b86c-2b15e00f0000 pid=4064 execve guuid=b7ee051e-1f00-0000-b86c-2b15e20f0000 pid=4066 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b7ee051e-1f00-0000-b86c-2b15e20f0000 pid=4066 execve guuid=6c4fc71f-1f00-0000-b86c-2b15e40f0000 pid=4068 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=6c4fc71f-1f00-0000-b86c-2b15e40f0000 pid=4068 execve guuid=bbfdf620-1f00-0000-b86c-2b15e60f0000 pid=4070 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=bbfdf620-1f00-0000-b86c-2b15e60f0000 pid=4070 execve guuid=0f944122-1f00-0000-b86c-2b15e80f0000 pid=4072 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=0f944122-1f00-0000-b86c-2b15e80f0000 pid=4072 execve guuid=10067423-1f00-0000-b86c-2b15ea0f0000 pid=4074 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=10067423-1f00-0000-b86c-2b15ea0f0000 pid=4074 execve guuid=570d8924-1f00-0000-b86c-2b15ec0f0000 pid=4076 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=570d8924-1f00-0000-b86c-2b15ec0f0000 pid=4076 execve guuid=fc9fa625-1f00-0000-b86c-2b15ee0f0000 pid=4078 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=fc9fa625-1f00-0000-b86c-2b15ee0f0000 pid=4078 execve guuid=55594f51-2000-0000-b86c-2b15f00f0000 pid=4080 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=55594f51-2000-0000-b86c-2b15f00f0000 pid=4080 execve guuid=6a7f6855-2000-0000-b86c-2b15f20f0000 pid=4082 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=6a7f6855-2000-0000-b86c-2b15f20f0000 pid=4082 execve guuid=21df2157-2000-0000-b86c-2b15f40f0000 pid=4084 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=21df2157-2000-0000-b86c-2b15f40f0000 pid=4084 execve guuid=f5292e5a-2000-0000-b86c-2b15f60f0000 pid=4086 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f5292e5a-2000-0000-b86c-2b15f60f0000 pid=4086 execve guuid=931d895b-2000-0000-b86c-2b15f80f0000 pid=4088 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=931d895b-2000-0000-b86c-2b15f80f0000 pid=4088 execve guuid=b396fb5c-2000-0000-b86c-2b15fa0f0000 pid=4090 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b396fb5c-2000-0000-b86c-2b15fa0f0000 pid=4090 execve guuid=01ef645e-2000-0000-b86c-2b15fc0f0000 pid=4092 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=01ef645e-2000-0000-b86c-2b15fc0f0000 pid=4092 execve guuid=736ea35f-2000-0000-b86c-2b15fe0f0000 pid=4094 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=736ea35f-2000-0000-b86c-2b15fe0f0000 pid=4094 execve guuid=7de9ef60-2000-0000-b86c-2b1500100000 pid=4096 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=7de9ef60-2000-0000-b86c-2b1500100000 pid=4096 execve guuid=140f678c-2100-0000-b86c-2b1502100000 pid=4098 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=140f678c-2100-0000-b86c-2b1502100000 pid=4098 execve guuid=e124d98e-2100-0000-b86c-2b1504100000 pid=4100 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=e124d98e-2100-0000-b86c-2b1504100000 pid=4100 execve guuid=8b75ae8f-2100-0000-b86c-2b1506100000 pid=4102 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=8b75ae8f-2100-0000-b86c-2b1506100000 pid=4102 execve guuid=5ded6f90-2100-0000-b86c-2b1508100000 pid=4104 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=5ded6f90-2100-0000-b86c-2b1508100000 pid=4104 execve guuid=33145291-2100-0000-b86c-2b150a100000 pid=4106 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=33145291-2100-0000-b86c-2b150a100000 pid=4106 execve guuid=bc334592-2100-0000-b86c-2b150c100000 pid=4108 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=bc334592-2100-0000-b86c-2b150c100000 pid=4108 execve guuid=ca972d93-2100-0000-b86c-2b150e100000 pid=4110 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=ca972d93-2100-0000-b86c-2b150e100000 pid=4110 execve guuid=4a5b1b94-2100-0000-b86c-2b1510100000 pid=4112 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=4a5b1b94-2100-0000-b86c-2b1510100000 pid=4112 execve guuid=531d0695-2100-0000-b86c-2b1512100000 pid=4114 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=531d0695-2100-0000-b86c-2b1512100000 pid=4114 execve guuid=893067c0-2200-0000-b86c-2b1514100000 pid=4116 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=893067c0-2200-0000-b86c-2b1514100000 pid=4116 execve guuid=03f9a0c3-2200-0000-b86c-2b1516100000 pid=4118 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=03f9a0c3-2200-0000-b86c-2b1516100000 pid=4118 execve guuid=c65890c4-2200-0000-b86c-2b1518100000 pid=4120 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=c65890c4-2200-0000-b86c-2b1518100000 pid=4120 execve guuid=6e536ec5-2200-0000-b86c-2b151a100000 pid=4122 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=6e536ec5-2200-0000-b86c-2b151a100000 pid=4122 execve guuid=b3aa3dc6-2200-0000-b86c-2b151c100000 pid=4124 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b3aa3dc6-2200-0000-b86c-2b151c100000 pid=4124 execve guuid=6bef27c7-2200-0000-b86c-2b151e100000 pid=4126 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=6bef27c7-2200-0000-b86c-2b151e100000 pid=4126 execve guuid=7e7903c8-2200-0000-b86c-2b1520100000 pid=4128 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=7e7903c8-2200-0000-b86c-2b1520100000 pid=4128 execve guuid=b5faf3c8-2200-0000-b86c-2b1522100000 pid=4130 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b5faf3c8-2200-0000-b86c-2b1522100000 pid=4130 execve guuid=3e22dfc9-2200-0000-b86c-2b1524100000 pid=4132 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=3e22dfc9-2200-0000-b86c-2b1524100000 pid=4132 execve guuid=c7b788f5-2300-0000-b86c-2b1526100000 pid=4134 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=c7b788f5-2300-0000-b86c-2b1526100000 pid=4134 execve guuid=5fc8e7f9-2300-0000-b86c-2b1528100000 pid=4136 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=5fc8e7f9-2300-0000-b86c-2b1528100000 pid=4136 execve guuid=b38741fb-2300-0000-b86c-2b152a100000 pid=4138 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b38741fb-2300-0000-b86c-2b152a100000 pid=4138 execve guuid=cd03e0fc-2300-0000-b86c-2b152c100000 pid=4140 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=cd03e0fc-2300-0000-b86c-2b152c100000 pid=4140 execve guuid=208eb3fe-2300-0000-b86c-2b152e100000 pid=4142 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=208eb3fe-2300-0000-b86c-2b152e100000 pid=4142 execve guuid=f1513b00-2400-0000-b86c-2b1530100000 pid=4144 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f1513b00-2400-0000-b86c-2b1530100000 pid=4144 execve guuid=2e22e801-2400-0000-b86c-2b1532100000 pid=4146 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=2e22e801-2400-0000-b86c-2b1532100000 pid=4146 execve guuid=b8e57c03-2400-0000-b86c-2b1534100000 pid=4148 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=b8e57c03-2400-0000-b86c-2b1534100000 pid=4148 execve guuid=a6890805-2400-0000-b86c-2b1536100000 pid=4150 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=a6890805-2400-0000-b86c-2b1536100000 pid=4150 execve guuid=9e281c31-2500-0000-b86c-2b1538100000 pid=4152 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=9e281c31-2500-0000-b86c-2b1538100000 pid=4152 execve guuid=aadfcd35-2500-0000-b86c-2b153a100000 pid=4154 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=aadfcd35-2500-0000-b86c-2b153a100000 pid=4154 execve guuid=d8857d37-2500-0000-b86c-2b153c100000 pid=4156 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=d8857d37-2500-0000-b86c-2b153c100000 pid=4156 execve guuid=95393439-2500-0000-b86c-2b153e100000 pid=4158 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=95393439-2500-0000-b86c-2b153e100000 pid=4158 execve guuid=8c80de3a-2500-0000-b86c-2b1540100000 pid=4160 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=8c80de3a-2500-0000-b86c-2b1540100000 pid=4160 execve guuid=09f56c3c-2500-0000-b86c-2b1542100000 pid=4162 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=09f56c3c-2500-0000-b86c-2b1542100000 pid=4162 execve guuid=4617043e-2500-0000-b86c-2b1544100000 pid=4164 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=4617043e-2500-0000-b86c-2b1544100000 pid=4164 execve guuid=a0de763f-2500-0000-b86c-2b1546100000 pid=4166 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=a0de763f-2500-0000-b86c-2b1546100000 pid=4166 execve guuid=0f95c640-2500-0000-b86c-2b1548100000 pid=4168 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=0f95c640-2500-0000-b86c-2b1548100000 pid=4168 execve guuid=f7ccc96c-2600-0000-b86c-2b154a100000 pid=4170 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f7ccc96c-2600-0000-b86c-2b154a100000 pid=4170 execve guuid=26190d71-2600-0000-b86c-2b154c100000 pid=4172 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=26190d71-2600-0000-b86c-2b154c100000 pid=4172 execve guuid=2e7a8b72-2600-0000-b86c-2b154e100000 pid=4174 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=2e7a8b72-2600-0000-b86c-2b154e100000 pid=4174 execve guuid=01a2f973-2600-0000-b86c-2b1550100000 pid=4176 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=01a2f973-2600-0000-b86c-2b1550100000 pid=4176 execve guuid=f11e3175-2600-0000-b86c-2b1552100000 pid=4178 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f11e3175-2600-0000-b86c-2b1552100000 pid=4178 execve guuid=e0197e76-2600-0000-b86c-2b1554100000 pid=4180 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=e0197e76-2600-0000-b86c-2b1554100000 pid=4180 execve guuid=f3170d78-2600-0000-b86c-2b1556100000 pid=4182 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=f3170d78-2600-0000-b86c-2b1556100000 pid=4182 execve guuid=172ac679-2600-0000-b86c-2b1558100000 pid=4184 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=172ac679-2600-0000-b86c-2b1558100000 pid=4184 execve guuid=8608727b-2600-0000-b86c-2b155a100000 pid=4186 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=8608727b-2600-0000-b86c-2b155a100000 pid=4186 execve guuid=12d6a5a7-2700-0000-b86c-2b155c100000 pid=4188 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=12d6a5a7-2700-0000-b86c-2b155c100000 pid=4188 execve guuid=e96b6eac-2700-0000-b86c-2b155e100000 pid=4190 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=e96b6eac-2700-0000-b86c-2b155e100000 pid=4190 execve guuid=dfa432ae-2700-0000-b86c-2b1560100000 pid=4192 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=dfa432ae-2700-0000-b86c-2b1560100000 pid=4192 execve guuid=ff07ccaf-2700-0000-b86c-2b1562100000 pid=4194 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=ff07ccaf-2700-0000-b86c-2b1562100000 pid=4194 execve guuid=43f18ab1-2700-0000-b86c-2b1564100000 pid=4196 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=43f18ab1-2700-0000-b86c-2b1564100000 pid=4196 execve guuid=239a3db3-2700-0000-b86c-2b1566100000 pid=4198 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=239a3db3-2700-0000-b86c-2b1566100000 pid=4198 execve guuid=86eab9b4-2700-0000-b86c-2b1568100000 pid=4200 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=86eab9b4-2700-0000-b86c-2b1568100000 pid=4200 execve guuid=700849b6-2700-0000-b86c-2b156a100000 pid=4202 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=700849b6-2700-0000-b86c-2b156a100000 pid=4202 execve guuid=8783f3b7-2700-0000-b86c-2b156c100000 pid=4204 /usr/bin/dash guuid=298ce5f9-1900-0000-b86c-2b1512090000 pid=2322->guuid=8783f3b7-2700-0000-b86c-2b156c100000 pid=4204 execve guuid=426260fa-1900-0000-b86c-2b1517090000 pid=2327 /usr/bin/wget dns net send-data guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323->guuid=426260fa-1900-0000-b86c-2b1517090000 pid=2327 execve guuid=6a39e100-1a00-0000-b86c-2b151f090000 pid=2335 /usr/bin/chmod guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323->guuid=6a39e100-1a00-0000-b86c-2b151f090000 pid=2335 execve guuid=919d1401-1a00-0000-b86c-2b1520090000 pid=2336 /home/sandbox/..... guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323->guuid=919d1401-1a00-0000-b86c-2b1520090000 pid=2336 execve guuid=c4e0c101-1a00-0000-b86c-2b1525090000 pid=2341 /usr/bin/rm delete-file guuid=d6b9e8f9-1900-0000-b86c-2b1513090000 pid=2323->guuid=c4e0c101-1a00-0000-b86c-2b1525090000 pid=2341 execve guuid=282f08fa-1900-0000-b86c-2b1516090000 pid=2326 /tmp/sample.bin net send-data zombie guuid=b1a4eff9-1900-0000-b86c-2b1515090000 pid=2325->guuid=282f08fa-1900-0000-b86c-2b1516090000 pid=2326 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=282f08fa-1900-0000-b86c-2b1516090000 pid=2326->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 9B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=426260fa-1900-0000-b86c-2b1517090000 pid=2327->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=b0a8bd29-1a00-0000-b86c-2b1576090000 pid=2422 /usr/bin/pgrep guuid=cd295c29-1a00-0000-b86c-2b1574090000 pid=2420->guuid=b0a8bd29-1a00-0000-b86c-2b1576090000 pid=2422 execve guuid=2eb94f2d-1a00-0000-b86c-2b157f090000 pid=2431 /usr/bin/killall guuid=00bf1d2d-1a00-0000-b86c-2b157e090000 pid=2430->guuid=2eb94f2d-1a00-0000-b86c-2b157f090000 pid=2431 execve guuid=54d2ba2e-1a00-0000-b86c-2b1584090000 pid=2436 /usr/bin/killall guuid=327e7a2e-1a00-0000-b86c-2b1582090000 pid=2434->guuid=54d2ba2e-1a00-0000-b86c-2b1584090000 pid=2436 execve guuid=f2f62830-1a00-0000-b86c-2b158a090000 pid=2442 /usr/bin/killall guuid=1c240030-1a00-0000-b86c-2b1588090000 pid=2440->guuid=f2f62830-1a00-0000-b86c-2b158a090000 pid=2442 execve guuid=f8892431-1a00-0000-b86c-2b158e090000 pid=2446 /usr/bin/killall guuid=df9ce630-1a00-0000-b86c-2b158c090000 pid=2444->guuid=f8892431-1a00-0000-b86c-2b158e090000 pid=2446 execve guuid=773e7f32-1a00-0000-b86c-2b1592090000 pid=2450 /usr/bin/killall guuid=c8d25232-1a00-0000-b86c-2b1591090000 pid=2449->guuid=773e7f32-1a00-0000-b86c-2b1592090000 pid=2450 execve guuid=1c577433-1a00-0000-b86c-2b1597090000 pid=2455 /usr/bin/killall guuid=62703a33-1a00-0000-b86c-2b1595090000 pid=2453->guuid=1c577433-1a00-0000-b86c-2b1597090000 pid=2455 execve guuid=1fb89834-1a00-0000-b86c-2b159d090000 pid=2461 /usr/bin/killall guuid=5f917134-1a00-0000-b86c-2b159c090000 pid=2460->guuid=1fb89834-1a00-0000-b86c-2b159d090000 pid=2461 execve guuid=12eef335-1a00-0000-b86c-2b15a3090000 pid=2467 /usr/bin/killall guuid=d969ca35-1a00-0000-b86c-2b15a1090000 pid=2465->guuid=12eef335-1a00-0000-b86c-2b15a3090000 pid=2467 execve guuid=56afba61-1b00-0000-b86c-2b15870c0000 pid=3207 /usr/bin/pgrep guuid=d5f35161-1b00-0000-b86c-2b15860c0000 pid=3206->guuid=56afba61-1b00-0000-b86c-2b15870c0000 pid=3207 execve guuid=d9b13665-1b00-0000-b86c-2b15900c0000 pid=3216 /usr/bin/killall guuid=7e970865-1b00-0000-b86c-2b158f0c0000 pid=3215->guuid=d9b13665-1b00-0000-b86c-2b15900c0000 pid=3216 execve guuid=30045766-1b00-0000-b86c-2b15950c0000 pid=3221 /usr/bin/killall guuid=849c2966-1b00-0000-b86c-2b15940c0000 pid=3220->guuid=30045766-1b00-0000-b86c-2b15950c0000 pid=3221 execve guuid=6d4fab67-1b00-0000-b86c-2b159a0c0000 pid=3226 /usr/bin/killall guuid=32b66567-1b00-0000-b86c-2b15990c0000 pid=3225->guuid=6d4fab67-1b00-0000-b86c-2b159a0c0000 pid=3226 execve guuid=e9e80169-1b00-0000-b86c-2b159c0c0000 pid=3228 /usr/bin/killall guuid=dba1a068-1b00-0000-b86c-2b159b0c0000 pid=3227->guuid=e9e80169-1b00-0000-b86c-2b159c0c0000 pid=3228 execve guuid=1d2aa16a-1b00-0000-b86c-2b15a10c0000 pid=3233 /usr/bin/killall guuid=37b0656a-1b00-0000-b86c-2b159f0c0000 pid=3231->guuid=1d2aa16a-1b00-0000-b86c-2b15a10c0000 pid=3233 execve guuid=73adca6b-1b00-0000-b86c-2b15a50c0000 pid=3237 /usr/bin/killall guuid=fd609c6b-1b00-0000-b86c-2b15a40c0000 pid=3236->guuid=73adca6b-1b00-0000-b86c-2b15a50c0000 pid=3237 execve guuid=8e4df36c-1b00-0000-b86c-2b15ab0c0000 pid=3243 /usr/bin/killall guuid=fd09c96c-1b00-0000-b86c-2b15a90c0000 pid=3241->guuid=8e4df36c-1b00-0000-b86c-2b15ab0c0000 pid=3243 execve guuid=c820ee6d-1b00-0000-b86c-2b15ae0c0000 pid=3246 /usr/bin/killall guuid=8febb36d-1b00-0000-b86c-2b15ad0c0000 pid=3245->guuid=c820ee6d-1b00-0000-b86c-2b15ae0c0000 pid=3246 execve guuid=bceb4baa-1c00-0000-b86c-2b15b60f0000 pid=4022 /usr/bin/pgrep guuid=c44b02aa-1c00-0000-b86c-2b15b40f0000 pid=4020->guuid=bceb4baa-1c00-0000-b86c-2b15b60f0000 pid=4022 execve guuid=406237ae-1c00-0000-b86c-2b15b80f0000 pid=4024 /usr/bin/killall guuid=85fa09ae-1c00-0000-b86c-2b15b70f0000 pid=4023->guuid=406237ae-1c00-0000-b86c-2b15b80f0000 pid=4024 execve guuid=83e30daf-1c00-0000-b86c-2b15bd0f0000 pid=4029 /usr/bin/killall guuid=2c91e5ae-1c00-0000-b86c-2b15bb0f0000 pid=4027->guuid=83e30daf-1c00-0000-b86c-2b15bd0f0000 pid=4029 execve guuid=70fdfbaf-1c00-0000-b86c-2b15c10f0000 pid=4033 /usr/bin/killall guuid=4d12bbaf-1c00-0000-b86c-2b15c00f0000 pid=4032->guuid=70fdfbaf-1c00-0000-b86c-2b15c10f0000 pid=4033 execve guuid=59a4deb0-1c00-0000-b86c-2b15c30f0000 pid=4035 /usr/bin/killall guuid=4be7a9b0-1c00-0000-b86c-2b15c20f0000 pid=4034->guuid=59a4deb0-1c00-0000-b86c-2b15c30f0000 pid=4035 execve guuid=c794ccb1-1c00-0000-b86c-2b15c50f0000 pid=4037 /usr/bin/killall guuid=3ebf9eb1-1c00-0000-b86c-2b15c40f0000 pid=4036->guuid=c794ccb1-1c00-0000-b86c-2b15c50f0000 pid=4037 execve guuid=b631b9b2-1c00-0000-b86c-2b15c70f0000 pid=4039 /usr/bin/killall guuid=e66c88b2-1c00-0000-b86c-2b15c60f0000 pid=4038->guuid=b631b9b2-1c00-0000-b86c-2b15c70f0000 pid=4039 execve guuid=7c1691b3-1c00-0000-b86c-2b15c90f0000 pid=4041 /usr/bin/killall guuid=956865b3-1c00-0000-b86c-2b15c80f0000 pid=4040->guuid=7c1691b3-1c00-0000-b86c-2b15c90f0000 pid=4041 execve guuid=de946ab4-1c00-0000-b86c-2b15cb0f0000 pid=4043 /usr/bin/killall guuid=e92f3bb4-1c00-0000-b86c-2b15ca0f0000 pid=4042->guuid=de946ab4-1c00-0000-b86c-2b15cb0f0000 pid=4043 execve guuid=d3d7d0df-1d00-0000-b86c-2b15cd0f0000 pid=4045 /usr/bin/pgrep guuid=a1969adf-1d00-0000-b86c-2b15cc0f0000 pid=4044->guuid=d3d7d0df-1d00-0000-b86c-2b15cd0f0000 pid=4045 execve guuid=f8ba2ae5-1d00-0000-b86c-2b15cf0f0000 pid=4047 /usr/bin/killall guuid=f196f6e4-1d00-0000-b86c-2b15ce0f0000 pid=4046->guuid=f8ba2ae5-1d00-0000-b86c-2b15cf0f0000 pid=4047 execve guuid=b5d2b6e6-1d00-0000-b86c-2b15d10f0000 pid=4049 /usr/bin/killall guuid=39a07fe6-1d00-0000-b86c-2b15d00f0000 pid=4048->guuid=b5d2b6e6-1d00-0000-b86c-2b15d10f0000 pid=4049 execve guuid=837da7e7-1d00-0000-b86c-2b15d30f0000 pid=4051 /usr/bin/killall guuid=02a86de7-1d00-0000-b86c-2b15d20f0000 pid=4050->guuid=837da7e7-1d00-0000-b86c-2b15d30f0000 pid=4051 execve guuid=cc7ec3e8-1d00-0000-b86c-2b15d50f0000 pid=4053 /usr/bin/killall guuid=f4738fe8-1d00-0000-b86c-2b15d40f0000 pid=4052->guuid=cc7ec3e8-1d00-0000-b86c-2b15d50f0000 pid=4053 execve guuid=8c729ee9-1d00-0000-b86c-2b15d70f0000 pid=4055 /usr/bin/killall guuid=4fc071e9-1d00-0000-b86c-2b15d60f0000 pid=4054->guuid=8c729ee9-1d00-0000-b86c-2b15d70f0000 pid=4055 execve guuid=4c017bea-1d00-0000-b86c-2b15d90f0000 pid=4057 /usr/bin/killall guuid=1aa23bea-1d00-0000-b86c-2b15d80f0000 pid=4056->guuid=4c017bea-1d00-0000-b86c-2b15d90f0000 pid=4057 execve guuid=1ecb5eeb-1d00-0000-b86c-2b15db0f0000 pid=4059 /usr/bin/killall guuid=d73c22eb-1d00-0000-b86c-2b15da0f0000 pid=4058->guuid=1ecb5eeb-1d00-0000-b86c-2b15db0f0000 pid=4059 execve guuid=956642ec-1d00-0000-b86c-2b15dd0f0000 pid=4061 /usr/bin/killall guuid=cadd07ec-1d00-0000-b86c-2b15dc0f0000 pid=4060->guuid=956642ec-1d00-0000-b86c-2b15dd0f0000 pid=4061 execve guuid=5c404518-1f00-0000-b86c-2b15df0f0000 pid=4063 /usr/bin/pgrep guuid=93b3ec17-1f00-0000-b86c-2b15de0f0000 pid=4062->guuid=5c404518-1f00-0000-b86c-2b15df0f0000 pid=4063 execve guuid=2767561c-1f00-0000-b86c-2b15e10f0000 pid=4065 /usr/bin/killall guuid=7a97db1b-1f00-0000-b86c-2b15e00f0000 pid=4064->guuid=2767561c-1f00-0000-b86c-2b15e10f0000 pid=4065 execve guuid=18d0591e-1f00-0000-b86c-2b15e30f0000 pid=4067 /usr/bin/killall guuid=b7ee051e-1f00-0000-b86c-2b15e20f0000 pid=4066->guuid=18d0591e-1f00-0000-b86c-2b15e30f0000 pid=4067 execve guuid=d7db0720-1f00-0000-b86c-2b15e50f0000 pid=4069 /usr/bin/killall guuid=6c4fc71f-1f00-0000-b86c-2b15e40f0000 pid=4068->guuid=d7db0720-1f00-0000-b86c-2b15e50f0000 pid=4069 execve guuid=930f3421-1f00-0000-b86c-2b15e70f0000 pid=4071 /usr/bin/killall guuid=bbfdf620-1f00-0000-b86c-2b15e60f0000 pid=4070->guuid=930f3421-1f00-0000-b86c-2b15e70f0000 pid=4071 execve guuid=2f718922-1f00-0000-b86c-2b15e90f0000 pid=4073 /usr/bin/killall guuid=0f944122-1f00-0000-b86c-2b15e80f0000 pid=4072->guuid=2f718922-1f00-0000-b86c-2b15e90f0000 pid=4073 execve guuid=b62bb423-1f00-0000-b86c-2b15eb0f0000 pid=4075 /usr/bin/killall guuid=10067423-1f00-0000-b86c-2b15ea0f0000 pid=4074->guuid=b62bb423-1f00-0000-b86c-2b15eb0f0000 pid=4075 execve guuid=7cc3b424-1f00-0000-b86c-2b15ed0f0000 pid=4077 /usr/bin/killall guuid=570d8924-1f00-0000-b86c-2b15ec0f0000 pid=4076->guuid=7cc3b424-1f00-0000-b86c-2b15ed0f0000 pid=4077 execve guuid=691e0c26-1f00-0000-b86c-2b15ef0f0000 pid=4079 /usr/bin/killall guuid=fc9fa625-1f00-0000-b86c-2b15ee0f0000 pid=4078->guuid=691e0c26-1f00-0000-b86c-2b15ef0f0000 pid=4079 execve guuid=53e7a451-2000-0000-b86c-2b15f10f0000 pid=4081 /usr/bin/pgrep guuid=55594f51-2000-0000-b86c-2b15f00f0000 pid=4080->guuid=53e7a451-2000-0000-b86c-2b15f10f0000 pid=4081 execve guuid=c1adbf55-2000-0000-b86c-2b15f30f0000 pid=4083 /usr/bin/killall guuid=6a7f6855-2000-0000-b86c-2b15f20f0000 pid=4082->guuid=c1adbf55-2000-0000-b86c-2b15f30f0000 pid=4083 execve guuid=4f42a957-2000-0000-b86c-2b15f50f0000 pid=4085 /usr/bin/killall guuid=21df2157-2000-0000-b86c-2b15f40f0000 pid=4084->guuid=4f42a957-2000-0000-b86c-2b15f50f0000 pid=4085 execve guuid=e8a98b5a-2000-0000-b86c-2b15f70f0000 pid=4087 /usr/bin/killall guuid=f5292e5a-2000-0000-b86c-2b15f60f0000 pid=4086->guuid=e8a98b5a-2000-0000-b86c-2b15f70f0000 pid=4087 execve guuid=2331ce5b-2000-0000-b86c-2b15f90f0000 pid=4089 /usr/bin/killall guuid=931d895b-2000-0000-b86c-2b15f80f0000 pid=4088->guuid=2331ce5b-2000-0000-b86c-2b15f90f0000 pid=4089 execve guuid=63f73c5d-2000-0000-b86c-2b15fb0f0000 pid=4091 /usr/bin/killall guuid=b396fb5c-2000-0000-b86c-2b15fa0f0000 pid=4090->guuid=63f73c5d-2000-0000-b86c-2b15fb0f0000 pid=4091 execve guuid=2f76a95e-2000-0000-b86c-2b15fd0f0000 pid=4093 /usr/bin/killall guuid=01ef645e-2000-0000-b86c-2b15fc0f0000 pid=4092->guuid=2f76a95e-2000-0000-b86c-2b15fd0f0000 pid=4093 execve guuid=a013e65f-2000-0000-b86c-2b15ff0f0000 pid=4095 /usr/bin/killall guuid=736ea35f-2000-0000-b86c-2b15fe0f0000 pid=4094->guuid=a013e65f-2000-0000-b86c-2b15ff0f0000 pid=4095 execve guuid=9f4e3761-2000-0000-b86c-2b1501100000 pid=4097 /usr/bin/killall guuid=7de9ef60-2000-0000-b86c-2b1500100000 pid=4096->guuid=9f4e3761-2000-0000-b86c-2b1501100000 pid=4097 execve guuid=3046a28c-2100-0000-b86c-2b1503100000 pid=4099 /usr/bin/pgrep guuid=140f678c-2100-0000-b86c-2b1502100000 pid=4098->guuid=3046a28c-2100-0000-b86c-2b1503100000 pid=4099 execve guuid=3208088f-2100-0000-b86c-2b1505100000 pid=4101 /usr/bin/killall guuid=e124d98e-2100-0000-b86c-2b1504100000 pid=4100->guuid=3208088f-2100-0000-b86c-2b1505100000 pid=4101 execve guuid=b57cd68f-2100-0000-b86c-2b1507100000 pid=4103 /usr/bin/killall guuid=8b75ae8f-2100-0000-b86c-2b1506100000 pid=4102->guuid=b57cd68f-2100-0000-b86c-2b1507100000 pid=4103 execve guuid=63a59790-2100-0000-b86c-2b1509100000 pid=4105 /usr/bin/killall guuid=5ded6f90-2100-0000-b86c-2b1508100000 pid=4104->guuid=63a59790-2100-0000-b86c-2b1509100000 pid=4105 execve guuid=454f9591-2100-0000-b86c-2b150b100000 pid=4107 /usr/bin/killall guuid=33145291-2100-0000-b86c-2b150a100000 pid=4106->guuid=454f9591-2100-0000-b86c-2b150b100000 pid=4107 execve guuid=10c68792-2100-0000-b86c-2b150d100000 pid=4109 /usr/bin/killall guuid=bc334592-2100-0000-b86c-2b150c100000 pid=4108->guuid=10c68792-2100-0000-b86c-2b150d100000 pid=4109 execve guuid=74207093-2100-0000-b86c-2b150f100000 pid=4111 /usr/bin/killall guuid=ca972d93-2100-0000-b86c-2b150e100000 pid=4110->guuid=74207093-2100-0000-b86c-2b150f100000 pid=4111 execve guuid=b5aa5b94-2100-0000-b86c-2b1511100000 pid=4113 /usr/bin/killall guuid=4a5b1b94-2100-0000-b86c-2b1510100000 pid=4112->guuid=b5aa5b94-2100-0000-b86c-2b1511100000 pid=4113 execve guuid=7a954995-2100-0000-b86c-2b1513100000 pid=4115 /usr/bin/killall guuid=531d0695-2100-0000-b86c-2b1512100000 pid=4114->guuid=7a954995-2100-0000-b86c-2b1513100000 pid=4115 execve guuid=a2b59ec0-2200-0000-b86c-2b1515100000 pid=4117 /usr/bin/pgrep guuid=893067c0-2200-0000-b86c-2b1514100000 pid=4116->guuid=a2b59ec0-2200-0000-b86c-2b1515100000 pid=4117 execve guuid=0113d5c3-2200-0000-b86c-2b1517100000 pid=4119 /usr/bin/killall guuid=03f9a0c3-2200-0000-b86c-2b1516100000 pid=4118->guuid=0113d5c3-2200-0000-b86c-2b1517100000 pid=4119 execve guuid=a5bfbcc4-2200-0000-b86c-2b1519100000 pid=4121 /usr/bin/killall guuid=c65890c4-2200-0000-b86c-2b1518100000 pid=4120->guuid=a5bfbcc4-2200-0000-b86c-2b1519100000 pid=4121 execve guuid=5ac697c5-2200-0000-b86c-2b151b100000 pid=4123 /usr/bin/killall guuid=6e536ec5-2200-0000-b86c-2b151a100000 pid=4122->guuid=5ac697c5-2200-0000-b86c-2b151b100000 pid=4123 execve guuid=f10467c6-2200-0000-b86c-2b151d100000 pid=4125 /usr/bin/killall guuid=b3aa3dc6-2200-0000-b86c-2b151c100000 pid=4124->guuid=f10467c6-2200-0000-b86c-2b151d100000 pid=4125 execve guuid=b6b754c7-2200-0000-b86c-2b151f100000 pid=4127 /usr/bin/killall guuid=6bef27c7-2200-0000-b86c-2b151e100000 pid=4126->guuid=b6b754c7-2200-0000-b86c-2b151f100000 pid=4127 execve guuid=60d545c8-2200-0000-b86c-2b1521100000 pid=4129 /usr/bin/killall guuid=7e7903c8-2200-0000-b86c-2b1520100000 pid=4128->guuid=60d545c8-2200-0000-b86c-2b1521100000 pid=4129 execve guuid=77651cc9-2200-0000-b86c-2b1523100000 pid=4131 /usr/bin/killall guuid=b5faf3c8-2200-0000-b86c-2b1522100000 pid=4130->guuid=77651cc9-2200-0000-b86c-2b1523100000 pid=4131 execve guuid=4d4e10ca-2200-0000-b86c-2b1525100000 pid=4133 /usr/bin/killall guuid=3e22dfc9-2200-0000-b86c-2b1524100000 pid=4132->guuid=4d4e10ca-2200-0000-b86c-2b1525100000 pid=4133 execve guuid=de5ceaf5-2300-0000-b86c-2b1527100000 pid=4135 /usr/bin/pgrep guuid=c7b788f5-2300-0000-b86c-2b1526100000 pid=4134->guuid=de5ceaf5-2300-0000-b86c-2b1527100000 pid=4135 execve guuid=69dd16fa-2300-0000-b86c-2b1529100000 pid=4137 /usr/bin/killall guuid=5fc8e7f9-2300-0000-b86c-2b1528100000 pid=4136->guuid=69dd16fa-2300-0000-b86c-2b1529100000 pid=4137 execve guuid=532585fb-2300-0000-b86c-2b152b100000 pid=4139 /usr/bin/killall guuid=b38741fb-2300-0000-b86c-2b152a100000 pid=4138->guuid=532585fb-2300-0000-b86c-2b152b100000 pid=4139 execve guuid=679a48fd-2300-0000-b86c-2b152d100000 pid=4141 /usr/bin/killall guuid=cd03e0fc-2300-0000-b86c-2b152c100000 pid=4140->guuid=679a48fd-2300-0000-b86c-2b152d100000 pid=4141 execve guuid=03d209ff-2300-0000-b86c-2b152f100000 pid=4143 /usr/bin/killall guuid=208eb3fe-2300-0000-b86c-2b152e100000 pid=4142->guuid=03d209ff-2300-0000-b86c-2b152f100000 pid=4143 execve guuid=2ffe9f00-2400-0000-b86c-2b1531100000 pid=4145 /usr/bin/killall guuid=f1513b00-2400-0000-b86c-2b1530100000 pid=4144->guuid=2ffe9f00-2400-0000-b86c-2b1531100000 pid=4145 execve guuid=af793e02-2400-0000-b86c-2b1533100000 pid=4147 /usr/bin/killall guuid=2e22e801-2400-0000-b86c-2b1532100000 pid=4146->guuid=af793e02-2400-0000-b86c-2b1533100000 pid=4147 execve guuid=ca33ca03-2400-0000-b86c-2b1535100000 pid=4149 /usr/bin/killall guuid=b8e57c03-2400-0000-b86c-2b1534100000 pid=4148->guuid=ca33ca03-2400-0000-b86c-2b1535100000 pid=4149 execve guuid=d39c5a05-2400-0000-b86c-2b1537100000 pid=4151 /usr/bin/killall guuid=a6890805-2400-0000-b86c-2b1536100000 pid=4150->guuid=d39c5a05-2400-0000-b86c-2b1537100000 pid=4151 execve guuid=8b3a7b31-2500-0000-b86c-2b1539100000 pid=4153 /usr/bin/pgrep guuid=9e281c31-2500-0000-b86c-2b1538100000 pid=4152->guuid=8b3a7b31-2500-0000-b86c-2b1539100000 pid=4153 execve guuid=c4950d36-2500-0000-b86c-2b153b100000 pid=4155 /usr/bin/killall guuid=aadfcd35-2500-0000-b86c-2b153a100000 pid=4154->guuid=c4950d36-2500-0000-b86c-2b153b100000 pid=4155 execve guuid=2234d537-2500-0000-b86c-2b153d100000 pid=4157 /usr/bin/killall guuid=d8857d37-2500-0000-b86c-2b153c100000 pid=4156->guuid=2234d537-2500-0000-b86c-2b153d100000 pid=4157 execve guuid=32f38339-2500-0000-b86c-2b153f100000 pid=4159 /usr/bin/killall guuid=95393439-2500-0000-b86c-2b153e100000 pid=4158->guuid=32f38339-2500-0000-b86c-2b153f100000 pid=4159 execve guuid=b021303b-2500-0000-b86c-2b1541100000 pid=4161 /usr/bin/killall guuid=8c80de3a-2500-0000-b86c-2b1540100000 pid=4160->guuid=b021303b-2500-0000-b86c-2b1541100000 pid=4161 execve guuid=9119bc3c-2500-0000-b86c-2b1543100000 pid=4163 /usr/bin/killall guuid=09f56c3c-2500-0000-b86c-2b1542100000 pid=4162->guuid=9119bc3c-2500-0000-b86c-2b1543100000 pid=4163 execve guuid=8636543e-2500-0000-b86c-2b1545100000 pid=4165 /usr/bin/killall guuid=4617043e-2500-0000-b86c-2b1544100000 pid=4164->guuid=8636543e-2500-0000-b86c-2b1545100000 pid=4165 execve guuid=1a2dc73f-2500-0000-b86c-2b1547100000 pid=4167 /usr/bin/killall guuid=a0de763f-2500-0000-b86c-2b1546100000 pid=4166->guuid=1a2dc73f-2500-0000-b86c-2b1547100000 pid=4167 execve guuid=231b0641-2500-0000-b86c-2b1549100000 pid=4169 /usr/bin/killall guuid=0f95c640-2500-0000-b86c-2b1548100000 pid=4168->guuid=231b0641-2500-0000-b86c-2b1549100000 pid=4169 execve guuid=8b98356d-2600-0000-b86c-2b154b100000 pid=4171 /usr/bin/pgrep guuid=f7ccc96c-2600-0000-b86c-2b154a100000 pid=4170->guuid=8b98356d-2600-0000-b86c-2b154b100000 pid=4171 execve guuid=52663f71-2600-0000-b86c-2b154d100000 pid=4173 /usr/bin/killall guuid=26190d71-2600-0000-b86c-2b154c100000 pid=4172->guuid=52663f71-2600-0000-b86c-2b154d100000 pid=4173 execve guuid=c83ef072-2600-0000-b86c-2b154f100000 pid=4175 /usr/bin/killall guuid=2e7a8b72-2600-0000-b86c-2b154e100000 pid=4174->guuid=c83ef072-2600-0000-b86c-2b154f100000 pid=4175 execve guuid=02874a74-2600-0000-b86c-2b1551100000 pid=4177 /usr/bin/killall guuid=01a2f973-2600-0000-b86c-2b1550100000 pid=4176->guuid=02874a74-2600-0000-b86c-2b1551100000 pid=4177 execve guuid=dd3a8d75-2600-0000-b86c-2b1553100000 pid=4179 /usr/bin/killall guuid=f11e3175-2600-0000-b86c-2b1552100000 pid=4178->guuid=dd3a8d75-2600-0000-b86c-2b1553100000 pid=4179 execve guuid=9796bb76-2600-0000-b86c-2b1555100000 pid=4181 /usr/bin/killall guuid=e0197e76-2600-0000-b86c-2b1554100000 pid=4180->guuid=9796bb76-2600-0000-b86c-2b1555100000 pid=4181 execve guuid=85be6c78-2600-0000-b86c-2b1557100000 pid=4183 /usr/bin/killall guuid=f3170d78-2600-0000-b86c-2b1556100000 pid=4182->guuid=85be6c78-2600-0000-b86c-2b1557100000 pid=4183 execve guuid=2ec61c7a-2600-0000-b86c-2b1559100000 pid=4185 /usr/bin/killall guuid=172ac679-2600-0000-b86c-2b1558100000 pid=4184->guuid=2ec61c7a-2600-0000-b86c-2b1559100000 pid=4185 execve guuid=3572c47b-2600-0000-b86c-2b155b100000 pid=4187 /usr/bin/killall guuid=8608727b-2600-0000-b86c-2b155a100000 pid=4186->guuid=3572c47b-2600-0000-b86c-2b155b100000 pid=4187 execve guuid=2e65d7a7-2700-0000-b86c-2b155d100000 pid=4189 /usr/bin/pgrep guuid=12d6a5a7-2700-0000-b86c-2b155c100000 pid=4188->guuid=2e65d7a7-2700-0000-b86c-2b155d100000 pid=4189 execve guuid=a8f8c5ac-2700-0000-b86c-2b155f100000 pid=4191 /usr/bin/killall guuid=e96b6eac-2700-0000-b86c-2b155e100000 pid=4190->guuid=a8f8c5ac-2700-0000-b86c-2b155f100000 pid=4191 execve guuid=aebc83ae-2700-0000-b86c-2b1561100000 pid=4193 /usr/bin/killall guuid=dfa432ae-2700-0000-b86c-2b1560100000 pid=4192->guuid=aebc83ae-2700-0000-b86c-2b1561100000 pid=4193 execve guuid=75e01ab0-2700-0000-b86c-2b1563100000 pid=4195 /usr/bin/killall guuid=ff07ccaf-2700-0000-b86c-2b1562100000 pid=4194->guuid=75e01ab0-2700-0000-b86c-2b1563100000 pid=4195 execve guuid=703de9b1-2700-0000-b86c-2b1565100000 pid=4197 /usr/bin/killall guuid=43f18ab1-2700-0000-b86c-2b1564100000 pid=4196->guuid=703de9b1-2700-0000-b86c-2b1565100000 pid=4197 execve guuid=21d894b3-2700-0000-b86c-2b1567100000 pid=4199 /usr/bin/killall guuid=239a3db3-2700-0000-b86c-2b1566100000 pid=4198->guuid=21d894b3-2700-0000-b86c-2b1567100000 pid=4199 execve guuid=d1d2f7b4-2700-0000-b86c-2b1569100000 pid=4201 /usr/bin/killall guuid=86eab9b4-2700-0000-b86c-2b1568100000 pid=4200->guuid=d1d2f7b4-2700-0000-b86c-2b1569100000 pid=4201 execve guuid=e941a3b6-2700-0000-b86c-2b156b100000 pid=4203 /usr/bin/killall guuid=700849b6-2700-0000-b86c-2b156a100000 pid=4202->guuid=e941a3b6-2700-0000-b86c-2b156b100000 pid=4203 execve guuid=b1174ab8-2700-0000-b86c-2b156d100000 pid=4205 /usr/bin/killall guuid=8783f3b7-2700-0000-b86c-2b156c100000 pid=4204->guuid=b1174ab8-2700-0000-b86c-2b156d100000 pid=4205 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
96 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1735016 Sample: ssh.elf Startdate: 13/07/2025 Architecture: LINUX Score: 96 37 206.123.128.67, 52850, 65481 LEASEWEB-USA-NYC-11US United States 2->37 39 gay.energy 2->39 41 daisy.ubuntu.com 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 4 other signatures 2->49 9 ssh.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 ssh.elf 9->12         started        process6 process7 14 ssh.elf sh 12->14         started        16 ssh.elf sh 12->16         started        18 ssh.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-13 00:48:11 UTC
File Type:
ELF64 Little (Exe)
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan mirai gafgyt Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_a6a2adb9 Linux_Trojan_Gafgyt_9e9530a7 Linux_Trojan_Gafgyt_f3d83a74 Linux_Trojan_Gafgyt_807911a2 Linux_Trojan_Gafgyt_e0673a90 Linux_Trojan_Gafgyt_a0a4de11 Linux_Trojan_Gafgyt_d4227dbf Linux_Trojan_Gafgyt_09c3070e Linux_Trojan_Gafgyt_46eec778 Linux_Trojan_Gafgyt_d996d335 Linux_Trojan_Gafgyt_d0c57a2e Linux_Trojan_Gafgyt_656bf077 Linux_Trojan_Gafgyt_620087b9 Linux_Trojan_Gafgyt_dd0d6173 Linux_Trojan_Gafgyt_779e142f Linux_Trojan_Gafgyt_cf84c9f2 Linux_Trojan_Gafgyt_0cd591cd Linux_Trojan_Gafgyt_33b4111a Linux_Trojan_Gafgyt_862c4e0e Linux_Trojan_Gafgyt_32eb0c81 Linux_Trojan_Gafgyt_a33a8363 Linux_Trojan_Mirai_3fe3c668 Linux_Trojan_Mirai_637f2c04 elf_bashlite_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:elf_bashlite_auto
Author:Felix Bilstein - yara-signator at cocacoding dot com
Description:Detects elf.bashlite.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_09c3070e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_0cd591cd
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_32eb0c81
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_33b4111a
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_46eec778
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_620087b9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_656bf077
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_779e142f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_807911a2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_862c4e0e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_9e9530a7
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a0a4de11
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a33a8363
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_a6a2adb9
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_cf84c9f2
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d0c57a2e
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d4227dbf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_d996d335
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_dd0d6173
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_e0673a90
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_f3d83a74
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_3fe3c668
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_637f2c04
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf aec725fa640c11c35d73d7f3e267cd4b79f05f1158a0c263a9ba3a8783c5cc63

(this sample)

  
Delivery method
Distributed via web download

BLint


The following table provides more information about this file using BLint. BLint is a Binary Linter to check the security properties, and capabilities in executables.

Findings
IDTitleSeverity
CHECK_PIEMissing Position-Independent Executable (PIE) Protectionhigh

Comments