MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b7a9a0ba03113005d17ef270177fed0cd993c126f59288eb3f8c242decd19a14. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: b7a9a0ba03113005d17ef270177fed0cd993c126f59288eb3f8c242decd19a14
SHA3-384 hash: a88c182cce118696a7d3d613d48e0cd041fe873571cde813af4ffb7bbffa35814478ee5dbb578f1066869b736af4fd27
SHA1 hash: bd30d0b757e0b25548ca4f055175b29604bd63ce
MD5 hash: 7ba017660954d101c4a28663764f95de
humanhash: cat-one-oven-arkansas
File name:jaws.sh
Download: download sample
Signature Mirai
File size:2'447 bytes
First seen:2025-08-23 06:14:39 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:Su32Dtuwf3rHubK7L5u2tL3uGdbugvHurhr4QyuSpbudPomIuiZxueFRuh4Wazul:SH3HHr33DoZMXbXfEKusHI
TLSH T1915192CE1C3465229F4BDE5B63B5B4A86072CAF734410E39DC8CCC69E98C957317BA94
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://163.61.39.201/arm92e2bf91fdb4d0617289191aef154951a3b71df4f9da76e3a670389bb60aaa48 Mirai32-bit elf mirai Mozi
http://163.61.39.201/arm5ff2d4387cb624cfb0eb01dfe59d09c8acc09eec41873016cc1590b6cffdd10c7 Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/arm65e29e6ac19c524f249a4e5800d6458735f5d131a6d9d59ea37dc716f7215dc31 Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/arm7b772d55640399dee9b277a0ffd7ef8f65bb87363dbfdd0634cb88328528f369d Miraiarm elf geofenced mirai ua-wget USA
http://163.61.39.201/i486d1d4d3b6ffb937a022a8978c4d01811ab7c5ddd912e0e94c4cd7a025d73a3843 Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/i6866509dcd8caa3035a09bbb926b0f93a63c80a76ecd9e8f5c6e74e0811fe3e200c Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/m68k7db99f0dd794e8e049d0d0d4fa86f3c2c3b95f2e9bc24e623ca11c1bcb02bf80 Miraielf geofenced m68k mirai ua-wget USA
http://163.61.39.201/mips6d8b92be20e13565fd61d105c44acadca0a7dac38eca5bc5693c5867b84fe62f Miraielf geofenced mips mirai ua-wget USA
http://163.61.39.201/mpsl3c2e72b972e03e620def95ca99d0af072db842dd0d016891fc30527770190a92 Miraielf geofenced mips mirai ua-wget USA
http://163.61.39.201/ppcfd07238570884beaa7f26c644408b18524fd2cc7c3b765ec24a0e9a36069d45a Miraielf geofenced mirai PowerPC ua-wget USA
http://163.61.39.201/sh4ac4a61edcb0c971f8f6b4b13f51e4105b4c838a344022091f1dcf351240a80b5 Miraielf geofenced mirai SuperH ua-wget USA
http://163.61.39.201/spc39fae3e0e9e2ba27ffa0eb62a244b16552abc21083dfceeb66dfc080c316696c Miraielf geofenced mirai sparc ua-wget USA
http://163.61.39.201/x86b137e7049facd81bf0e15a0bb6b0135732a43e126b799e903798f05ef87ca98e Miraielf geofenced mirai ua-wget USA x86
http://163.61.39.201/x86_64c39196e5ab865850c997492cc40ea9e9533ce1bcf915b255647f4ad82418be25 Miraielf geofenced mirai ua-wget USA x86

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=5785db61-1900-0000-0340-fae68b0a0000 pid=2699 /usr/bin/sudo guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704 /tmp/sample.bin guuid=5785db61-1900-0000-0340-fae68b0a0000 pid=2699->guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704 execve guuid=58697264-1900-0000-0340-fae6920a0000 pid=2706 /usr/bin/cp guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=58697264-1900-0000-0340-fae6920a0000 pid=2706 execve guuid=dfc46269-1900-0000-0340-fae69c0a0000 pid=2716 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=dfc46269-1900-0000-0340-fae69c0a0000 pid=2716 execve guuid=94a3e2a9-1900-0000-0340-fae6f80a0000 pid=2808 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=94a3e2a9-1900-0000-0340-fae6f80a0000 pid=2808 execve guuid=a8cf72e1-1900-0000-0340-fae6710b0000 pid=2929 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=a8cf72e1-1900-0000-0340-fae6710b0000 pid=2929 clone guuid=3c92a1e1-1900-0000-0340-fae6720b0000 pid=2930 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3c92a1e1-1900-0000-0340-fae6720b0000 pid=2930 execve guuid=9c3246e2-1900-0000-0340-fae6740b0000 pid=2932 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=9c3246e2-1900-0000-0340-fae6740b0000 pid=2932 clone guuid=28496ae4-1900-0000-0340-fae6760b0000 pid=2934 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=28496ae4-1900-0000-0340-fae6760b0000 pid=2934 execve guuid=df5ec0e4-1900-0000-0340-fae6780b0000 pid=2936 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=df5ec0e4-1900-0000-0340-fae6780b0000 pid=2936 execve guuid=5b791d12-1a00-0000-0340-fae6cc0b0000 pid=3020 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=5b791d12-1a00-0000-0340-fae6cc0b0000 pid=3020 execve guuid=495e3243-1a00-0000-0340-fae64b0c0000 pid=3147 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=495e3243-1a00-0000-0340-fae64b0c0000 pid=3147 clone guuid=fa4c5143-1a00-0000-0340-fae64d0c0000 pid=3149 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=fa4c5143-1a00-0000-0340-fae64d0c0000 pid=3149 execve guuid=c4b3ad43-1a00-0000-0340-fae64e0c0000 pid=3150 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=c4b3ad43-1a00-0000-0340-fae64e0c0000 pid=3150 clone guuid=4e476245-1a00-0000-0340-fae6550c0000 pid=3157 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=4e476245-1a00-0000-0340-fae6550c0000 pid=3157 execve guuid=a432ac45-1a00-0000-0340-fae6570c0000 pid=3159 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=a432ac45-1a00-0000-0340-fae6570c0000 pid=3159 execve guuid=6db62b78-1a00-0000-0340-fae6a30c0000 pid=3235 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=6db62b78-1a00-0000-0340-fae6a30c0000 pid=3235 execve guuid=887629aa-1a00-0000-0340-fae6c00c0000 pid=3264 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=887629aa-1a00-0000-0340-fae6c00c0000 pid=3264 clone guuid=bf3e48aa-1a00-0000-0340-fae6c10c0000 pid=3265 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=bf3e48aa-1a00-0000-0340-fae6c10c0000 pid=3265 execve guuid=9f7ebeaa-1a00-0000-0340-fae6c20c0000 pid=3266 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=9f7ebeaa-1a00-0000-0340-fae6c20c0000 pid=3266 clone guuid=a7198bab-1a00-0000-0340-fae6c40c0000 pid=3268 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=a7198bab-1a00-0000-0340-fae6c40c0000 pid=3268 execve guuid=040e78ad-1a00-0000-0340-fae6c50c0000 pid=3269 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=040e78ad-1a00-0000-0340-fae6c50c0000 pid=3269 execve guuid=dd9da1db-1a00-0000-0340-fae61b0d0000 pid=3355 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=dd9da1db-1a00-0000-0340-fae61b0d0000 pid=3355 execve guuid=883f0c0f-1b00-0000-0340-fae6900d0000 pid=3472 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=883f0c0f-1b00-0000-0340-fae6900d0000 pid=3472 clone guuid=f87b220f-1b00-0000-0340-fae6920d0000 pid=3474 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=f87b220f-1b00-0000-0340-fae6920d0000 pid=3474 execve guuid=cddc860f-1b00-0000-0340-fae6940d0000 pid=3476 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=cddc860f-1b00-0000-0340-fae6940d0000 pid=3476 clone guuid=b1adc510-1b00-0000-0340-fae6990d0000 pid=3481 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b1adc510-1b00-0000-0340-fae6990d0000 pid=3481 execve guuid=9b463811-1b00-0000-0340-fae69b0d0000 pid=3483 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=9b463811-1b00-0000-0340-fae69b0d0000 pid=3483 execve guuid=5fe9ad3e-1b00-0000-0340-fae6f70d0000 pid=3575 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=5fe9ad3e-1b00-0000-0340-fae6f70d0000 pid=3575 execve guuid=45ba9d71-1b00-0000-0340-fae6710e0000 pid=3697 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=45ba9d71-1b00-0000-0340-fae6710e0000 pid=3697 clone guuid=f59bd571-1b00-0000-0340-fae6720e0000 pid=3698 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=f59bd571-1b00-0000-0340-fae6720e0000 pid=3698 execve guuid=853fb372-1b00-0000-0340-fae6730e0000 pid=3699 /tmp/i486 guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=853fb372-1b00-0000-0340-fae6730e0000 pid=3699 execve guuid=910cc77d-1b00-0000-0340-fae67d0e0000 pid=3709 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=910cc77d-1b00-0000-0340-fae67d0e0000 pid=3709 execve guuid=e764267e-1b00-0000-0340-fae6800e0000 pid=3712 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=e764267e-1b00-0000-0340-fae6800e0000 pid=3712 execve guuid=f1b1bcac-1b00-0000-0340-fae6000f0000 pid=3840 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=f1b1bcac-1b00-0000-0340-fae6000f0000 pid=3840 execve guuid=98dca1db-1b00-0000-0340-fae6700f0000 pid=3952 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=98dca1db-1b00-0000-0340-fae6700f0000 pid=3952 clone guuid=0f81e3db-1b00-0000-0340-fae6710f0000 pid=3953 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=0f81e3db-1b00-0000-0340-fae6710f0000 pid=3953 execve guuid=b43257dc-1b00-0000-0340-fae6740f0000 pid=3956 /tmp/i686 guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b43257dc-1b00-0000-0340-fae6740f0000 pid=3956 execve guuid=c3b0a91b-1c00-0000-0340-fae657100000 pid=4183 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=c3b0a91b-1c00-0000-0340-fae657100000 pid=4183 execve guuid=82321f1c-1c00-0000-0340-fae65c100000 pid=4188 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=82321f1c-1c00-0000-0340-fae65c100000 pid=4188 execve guuid=e0fbca4a-1c00-0000-0340-fae66a100000 pid=4202 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=e0fbca4a-1c00-0000-0340-fae66a100000 pid=4202 execve guuid=3a74067d-1c00-0000-0340-fae66b100000 pid=4203 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3a74067d-1c00-0000-0340-fae66b100000 pid=4203 clone guuid=c8ce237d-1c00-0000-0340-fae66c100000 pid=4204 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=c8ce237d-1c00-0000-0340-fae66c100000 pid=4204 execve guuid=4dd38c7d-1c00-0000-0340-fae66d100000 pid=4205 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=4dd38c7d-1c00-0000-0340-fae66d100000 pid=4205 clone guuid=fb63607e-1c00-0000-0340-fae66f100000 pid=4207 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=fb63607e-1c00-0000-0340-fae66f100000 pid=4207 execve guuid=76c2c17e-1c00-0000-0340-fae672100000 pid=4210 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=76c2c17e-1c00-0000-0340-fae672100000 pid=4210 execve guuid=846407ad-1c00-0000-0340-fae675100000 pid=4213 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=846407ad-1c00-0000-0340-fae675100000 pid=4213 execve guuid=f4762bee-1c00-0000-0340-fae695100000 pid=4245 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=f4762bee-1c00-0000-0340-fae695100000 pid=4245 clone guuid=297a4dee-1c00-0000-0340-fae696100000 pid=4246 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=297a4dee-1c00-0000-0340-fae696100000 pid=4246 execve guuid=5acaaaee-1c00-0000-0340-fae697100000 pid=4247 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=5acaaaee-1c00-0000-0340-fae697100000 pid=4247 clone guuid=f20ffeee-1c00-0000-0340-fae69a100000 pid=4250 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=f20ffeee-1c00-0000-0340-fae69a100000 pid=4250 execve guuid=b65b2eef-1c00-0000-0340-fae69c100000 pid=4252 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b65b2eef-1c00-0000-0340-fae69c100000 pid=4252 execve guuid=3014eb1f-1d00-0000-0340-fae69d100000 pid=4253 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3014eb1f-1d00-0000-0340-fae69d100000 pid=4253 execve guuid=017d8a4e-1d00-0000-0340-fae69e100000 pid=4254 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=017d8a4e-1d00-0000-0340-fae69e100000 pid=4254 clone guuid=b7eea54e-1d00-0000-0340-fae69f100000 pid=4255 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b7eea54e-1d00-0000-0340-fae69f100000 pid=4255 execve guuid=39cfe74e-1d00-0000-0340-fae6a0100000 pid=4256 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=39cfe74e-1d00-0000-0340-fae6a0100000 pid=4256 clone guuid=97942a4f-1d00-0000-0340-fae6a3100000 pid=4259 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=97942a4f-1d00-0000-0340-fae6a3100000 pid=4259 execve guuid=c708614f-1d00-0000-0340-fae6a5100000 pid=4261 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=c708614f-1d00-0000-0340-fae6a5100000 pid=4261 execve guuid=18dd807f-1d00-0000-0340-fae6a6100000 pid=4262 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=18dd807f-1d00-0000-0340-fae6a6100000 pid=4262 execve guuid=be3797af-1d00-0000-0340-fae6a7100000 pid=4263 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=be3797af-1d00-0000-0340-fae6a7100000 pid=4263 clone guuid=5fdab8af-1d00-0000-0340-fae6a8100000 pid=4264 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=5fdab8af-1d00-0000-0340-fae6a8100000 pid=4264 execve guuid=753341b0-1d00-0000-0340-fae6a9100000 pid=4265 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=753341b0-1d00-0000-0340-fae6a9100000 pid=4265 clone guuid=3952a0b0-1d00-0000-0340-fae6ac100000 pid=4268 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3952a0b0-1d00-0000-0340-fae6ac100000 pid=4268 execve guuid=693ed5b0-1d00-0000-0340-fae6ae100000 pid=4270 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=693ed5b0-1d00-0000-0340-fae6ae100000 pid=4270 execve guuid=e1e7a6d6-1d00-0000-0340-fae6af100000 pid=4271 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=e1e7a6d6-1d00-0000-0340-fae6af100000 pid=4271 execve guuid=b2e3eff9-1d00-0000-0340-fae6b0100000 pid=4272 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b2e3eff9-1d00-0000-0340-fae6b0100000 pid=4272 clone guuid=34cc09fa-1d00-0000-0340-fae6b1100000 pid=4273 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=34cc09fa-1d00-0000-0340-fae6b1100000 pid=4273 execve guuid=2d4951fa-1d00-0000-0340-fae6b2100000 pid=4274 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=2d4951fa-1d00-0000-0340-fae6b2100000 pid=4274 clone guuid=fab887fa-1d00-0000-0340-fae6b5100000 pid=4277 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=fab887fa-1d00-0000-0340-fae6b5100000 pid=4277 execve guuid=2b71acfa-1d00-0000-0340-fae6b7100000 pid=4279 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=2b71acfa-1d00-0000-0340-fae6b7100000 pid=4279 execve guuid=25493328-1e00-0000-0340-fae6b8100000 pid=4280 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=25493328-1e00-0000-0340-fae6b8100000 pid=4280 execve guuid=e50ded56-1e00-0000-0340-fae6b9100000 pid=4281 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=e50ded56-1e00-0000-0340-fae6b9100000 pid=4281 clone guuid=9b681157-1e00-0000-0340-fae6ba100000 pid=4282 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=9b681157-1e00-0000-0340-fae6ba100000 pid=4282 execve guuid=71a26057-1e00-0000-0340-fae6bb100000 pid=4283 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=71a26057-1e00-0000-0340-fae6bb100000 pid=4283 clone guuid=efbdbc57-1e00-0000-0340-fae6be100000 pid=4286 /usr/bin/rm guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=efbdbc57-1e00-0000-0340-fae6be100000 pid=4286 execve guuid=fa71e757-1e00-0000-0340-fae6c0100000 pid=4288 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=fa71e757-1e00-0000-0340-fae6c0100000 pid=4288 execve guuid=133dc986-1e00-0000-0340-fae6c1100000 pid=4289 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=133dc986-1e00-0000-0340-fae6c1100000 pid=4289 execve guuid=a469cbb7-1e00-0000-0340-fae6c2100000 pid=4290 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=a469cbb7-1e00-0000-0340-fae6c2100000 pid=4290 clone guuid=09d3e4b7-1e00-0000-0340-fae6c3100000 pid=4291 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=09d3e4b7-1e00-0000-0340-fae6c3100000 pid=4291 execve guuid=08eb29b8-1e00-0000-0340-fae6c4100000 pid=4292 /tmp/x86 guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=08eb29b8-1e00-0000-0340-fae6c4100000 pid=4292 execve guuid=823bdae1-1e00-0000-0340-fae6c8100000 pid=4296 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=823bdae1-1e00-0000-0340-fae6c8100000 pid=4296 execve guuid=ed8d24e2-1e00-0000-0340-fae6ca100000 pid=4298 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=ed8d24e2-1e00-0000-0340-fae6ca100000 pid=4298 execve guuid=782fb312-1f00-0000-0340-fae6cb100000 pid=4299 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=782fb312-1f00-0000-0340-fae6cb100000 pid=4299 execve guuid=b6f55744-1f00-0000-0340-fae6cc100000 pid=4300 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=b6f55744-1f00-0000-0340-fae6cc100000 pid=4300 clone guuid=62fd7744-1f00-0000-0340-fae6cd100000 pid=4301 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=62fd7744-1f00-0000-0340-fae6cd100000 pid=4301 execve guuid=3cf0c544-1f00-0000-0340-fae6ce100000 pid=4302 /tmp/x86_64 guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3cf0c544-1f00-0000-0340-fae6ce100000 pid=4302 execve guuid=939b5d48-1f00-0000-0340-fae6d3100000 pid=4307 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=939b5d48-1f00-0000-0340-fae6d3100000 pid=4307 execve guuid=aaf1bf48-1f00-0000-0340-fae6d4100000 pid=4308 /usr/bin/wget net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=aaf1bf48-1f00-0000-0340-fae6d4100000 pid=4308 execve guuid=3d703c6b-1f00-0000-0340-fae6d5100000 pid=4309 /usr/bin/curl net send-data write-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=3d703c6b-1f00-0000-0340-fae6d5100000 pid=4309 execve guuid=62d16390-1f00-0000-0340-fae6d6100000 pid=4310 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=62d16390-1f00-0000-0340-fae6d6100000 pid=4310 clone guuid=dede8690-1f00-0000-0340-fae6d7100000 pid=4311 /usr/bin/chmod guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=dede8690-1f00-0000-0340-fae6d7100000 pid=4311 execve guuid=4f01df90-1f00-0000-0340-fae6d8100000 pid=4312 /usr/bin/bash guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=4f01df90-1f00-0000-0340-fae6d8100000 pid=4312 clone guuid=9e3add91-1f00-0000-0340-fae6da100000 pid=4314 /usr/bin/rm delete-file guuid=4146bc63-1900-0000-0340-fae6900a0000 pid=2704->guuid=9e3add91-1f00-0000-0340-fae6da100000 pid=4314 execve 861e64a3-ade7-5eac-b8d2-11a0362764a4 163.61.39.201:80 guuid=dfc46269-1900-0000-0340-fae69c0a0000 pid=2716->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=94a3e2a9-1900-0000-0340-fae6f80a0000 pid=2808->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=df5ec0e4-1900-0000-0340-fae6780b0000 pid=2936->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=5b791d12-1a00-0000-0340-fae6cc0b0000 pid=3020->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=a432ac45-1a00-0000-0340-fae6570c0000 pid=3159->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=6db62b78-1a00-0000-0340-fae6a30c0000 pid=3235->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=040e78ad-1a00-0000-0340-fae6c50c0000 pid=3269->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=dd9da1db-1a00-0000-0340-fae61b0d0000 pid=3355->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=9b463811-1b00-0000-0340-fae69b0d0000 pid=3483->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=5fe9ad3e-1b00-0000-0340-fae6f70d0000 pid=3575->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=f794c07d-1b00-0000-0340-fae67c0e0000 pid=3708 /tmp/i486 net send-data zombie guuid=853fb372-1b00-0000-0340-fae6730e0000 pid=3699->guuid=f794c07d-1b00-0000-0340-fae67c0e0000 pid=3708 clone 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f794c07d-1b00-0000-0340-fae67c0e0000 pid=3708->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 8ec24d88-10a2-533e-9815-5add425c4ddb 109.248.162.59:1025 guuid=f794c07d-1b00-0000-0340-fae67c0e0000 pid=3708->8ec24d88-10a2-533e-9815-5add425c4ddb send: 19B guuid=e670d17d-1b00-0000-0340-fae67e0e0000 pid=3710 /tmp/i486 guuid=f794c07d-1b00-0000-0340-fae67c0e0000 pid=3708->guuid=e670d17d-1b00-0000-0340-fae67e0e0000 pid=3710 clone guuid=e764267e-1b00-0000-0340-fae6800e0000 pid=3712->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=f1b1bcac-1b00-0000-0340-fae6000f0000 pid=3840->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=3b79b5e3-1b00-0000-0340-fae6820f0000 pid=3970 /tmp/i686 net send-data guuid=b43257dc-1b00-0000-0340-fae6740f0000 pid=3956->guuid=3b79b5e3-1b00-0000-0340-fae6820f0000 pid=3970 clone guuid=9541641b-1c00-0000-0340-fae655100000 pid=4181 /tmp/i686 net zombie guuid=b43257dc-1b00-0000-0340-fae6740f0000 pid=3956->guuid=9541641b-1c00-0000-0340-fae655100000 pid=4181 clone guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182 /tmp/i686 net send-data zombie guuid=b43257dc-1b00-0000-0340-fae6740f0000 pid=3956->guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182 clone d7e75a5d-65d1-5941-aac4-e4015a0a0899 31.56.39.76:6969 guuid=3b79b5e3-1b00-0000-0340-fae6820f0000 pid=3970->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 33B guuid=9541641b-1c00-0000-0340-fae655100000 pid=4181->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con b2c2ad8f-4321-5ca8-994b-072c20344629 31.59.120.38:1025 guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182->b2c2ad8f-4321-5ca8-994b-072c20344629 con db96774e-46a5-59dd-83b1-9c87ef6aad62 104.252.127.190:1025 guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182->db96774e-46a5-59dd-83b1-9c87ef6aad62 send: 19B guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184 /tmp/i686 guuid=8fcc8f1b-1c00-0000-0340-fae656100000 pid=4182->guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184 clone guuid=0b0cf61c-1c00-0000-0340-fae65f100000 pid=4191 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=0b0cf61c-1c00-0000-0340-fae65f100000 pid=4191 clone guuid=22a7031d-1c00-0000-0340-fae660100000 pid=4192 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=22a7031d-1c00-0000-0340-fae660100000 pid=4192 clone guuid=e9e9411d-1c00-0000-0340-fae662100000 pid=4194 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=e9e9411d-1c00-0000-0340-fae662100000 pid=4194 clone guuid=bc519223-1c00-0000-0340-fae665100000 pid=4197 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=bc519223-1c00-0000-0340-fae665100000 pid=4197 clone guuid=2980a623-1c00-0000-0340-fae666100000 pid=4198 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=2980a623-1c00-0000-0340-fae666100000 pid=4198 clone guuid=47a64b24-1c00-0000-0340-fae668100000 pid=4200 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=47a64b24-1c00-0000-0340-fae668100000 pid=4200 clone guuid=61e9997e-1c00-0000-0340-fae670100000 pid=4208 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=61e9997e-1c00-0000-0340-fae670100000 pid=4208 clone guuid=9044a77e-1c00-0000-0340-fae671100000 pid=4209 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=9044a77e-1c00-0000-0340-fae671100000 pid=4209 clone guuid=89ea8fb3-1c00-0000-0340-fae679100000 pid=4217 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=89ea8fb3-1c00-0000-0340-fae679100000 pid=4217 clone guuid=08eca6b3-1c00-0000-0340-fae67a100000 pid=4218 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=08eca6b3-1c00-0000-0340-fae67a100000 pid=4218 clone guuid=c602a1b4-1c00-0000-0340-fae67d100000 pid=4221 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=c602a1b4-1c00-0000-0340-fae67d100000 pid=4221 clone guuid=7d9badb4-1c00-0000-0340-fae67e100000 pid=4222 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=7d9badb4-1c00-0000-0340-fae67e100000 pid=4222 clone guuid=68cee6b4-1c00-0000-0340-fae680100000 pid=4224 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=68cee6b4-1c00-0000-0340-fae680100000 pid=4224 clone guuid=10560cb5-1c00-0000-0340-fae682100000 pid=4226 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=10560cb5-1c00-0000-0340-fae682100000 pid=4226 clone guuid=c8d92fb5-1c00-0000-0340-fae684100000 pid=4228 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=c8d92fb5-1c00-0000-0340-fae684100000 pid=4228 clone guuid=1fc44cb5-1c00-0000-0340-fae686100000 pid=4230 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=1fc44cb5-1c00-0000-0340-fae686100000 pid=4230 clone guuid=ee2393b5-1c00-0000-0340-fae688100000 pid=4232 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=ee2393b5-1c00-0000-0340-fae688100000 pid=4232 clone guuid=652fc2b5-1c00-0000-0340-fae68a100000 pid=4234 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=652fc2b5-1c00-0000-0340-fae68a100000 pid=4234 clone guuid=1f04e7b5-1c00-0000-0340-fae68c100000 pid=4236 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=1f04e7b5-1c00-0000-0340-fae68c100000 pid=4236 clone guuid=612809b6-1c00-0000-0340-fae68e100000 pid=4238 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=612809b6-1c00-0000-0340-fae68e100000 pid=4238 clone guuid=f801afb6-1c00-0000-0340-fae691100000 pid=4241 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=f801afb6-1c00-0000-0340-fae691100000 pid=4241 clone guuid=cfabbcb6-1c00-0000-0340-fae692100000 pid=4242 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=cfabbcb6-1c00-0000-0340-fae692100000 pid=4242 clone guuid=877702b7-1c00-0000-0340-fae694100000 pid=4244 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=877702b7-1c00-0000-0340-fae694100000 pid=4244 clone guuid=bce2d5ee-1c00-0000-0340-fae699100000 pid=4249 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=bce2d5ee-1c00-0000-0340-fae699100000 pid=4249 clone guuid=f4d818ef-1c00-0000-0340-fae69b100000 pid=4251 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=f4d818ef-1c00-0000-0340-fae69b100000 pid=4251 clone guuid=75950a4f-1d00-0000-0340-fae6a2100000 pid=4258 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=75950a4f-1d00-0000-0340-fae6a2100000 pid=4258 clone guuid=23084d4f-1d00-0000-0340-fae6a4100000 pid=4260 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=23084d4f-1d00-0000-0340-fae6a4100000 pid=4260 clone guuid=b3c474b0-1d00-0000-0340-fae6ab100000 pid=4267 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=b3c474b0-1d00-0000-0340-fae6ab100000 pid=4267 clone guuid=ff57bcb0-1d00-0000-0340-fae6ad100000 pid=4269 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=ff57bcb0-1d00-0000-0340-fae6ad100000 pid=4269 clone guuid=a5ce69fa-1d00-0000-0340-fae6b4100000 pid=4276 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=a5ce69fa-1d00-0000-0340-fae6b4100000 pid=4276 clone guuid=4cb29bfa-1d00-0000-0340-fae6b6100000 pid=4278 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=4cb29bfa-1d00-0000-0340-fae6b6100000 pid=4278 clone guuid=7cff8957-1e00-0000-0340-fae6bd100000 pid=4285 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=7cff8957-1e00-0000-0340-fae6bd100000 pid=4285 clone guuid=11b2d757-1e00-0000-0340-fae6bf100000 pid=4287 /tmp/i686 net send-data guuid=867ed71b-1c00-0000-0340-fae658100000 pid=4184->guuid=11b2d757-1e00-0000-0340-fae6bf100000 pid=4287 clone guuid=82321f1c-1c00-0000-0340-fae65c100000 pid=4188->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=0b0cf61c-1c00-0000-0340-fae65f100000 pid=4191->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=22a7031d-1c00-0000-0340-fae660100000 pid=4192->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=e9e9411d-1c00-0000-0340-fae662100000 pid=4194->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 51B guuid=bc519223-1c00-0000-0340-fae665100000 pid=4197->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 39B guuid=2980a623-1c00-0000-0340-fae666100000 pid=4198->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=47a64b24-1c00-0000-0340-fae668100000 pid=4200->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=e0fbca4a-1c00-0000-0340-fae66a100000 pid=4202->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=61e9997e-1c00-0000-0340-fae670100000 pid=4208->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 41B guuid=9044a77e-1c00-0000-0340-fae671100000 pid=4209->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=76c2c17e-1c00-0000-0340-fae672100000 pid=4210->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=846407ad-1c00-0000-0340-fae675100000 pid=4213->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=89ea8fb3-1c00-0000-0340-fae679100000 pid=4217->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 43B guuid=08eca6b3-1c00-0000-0340-fae67a100000 pid=4218->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=c602a1b4-1c00-0000-0340-fae67d100000 pid=4221->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=7d9badb4-1c00-0000-0340-fae67e100000 pid=4222->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=68cee6b4-1c00-0000-0340-fae680100000 pid=4224->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=10560cb5-1c00-0000-0340-fae682100000 pid=4226->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=c8d92fb5-1c00-0000-0340-fae684100000 pid=4228->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=1fc44cb5-1c00-0000-0340-fae686100000 pid=4230->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=ee2393b5-1c00-0000-0340-fae688100000 pid=4232->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 53B guuid=652fc2b5-1c00-0000-0340-fae68a100000 pid=4234->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=1f04e7b5-1c00-0000-0340-fae68c100000 pid=4236->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=612809b6-1c00-0000-0340-fae68e100000 pid=4238->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 49B guuid=f801afb6-1c00-0000-0340-fae691100000 pid=4241->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 40B guuid=cfabbcb6-1c00-0000-0340-fae692100000 pid=4242->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=877702b7-1c00-0000-0340-fae694100000 pid=4244->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 46B guuid=bce2d5ee-1c00-0000-0340-fae699100000 pid=4249->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=f4d818ef-1c00-0000-0340-fae69b100000 pid=4251->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=b65b2eef-1c00-0000-0340-fae69c100000 pid=4252->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 132B guuid=3014eb1f-1d00-0000-0340-fae69d100000 pid=4253->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 81B guuid=75950a4f-1d00-0000-0340-fae6a2100000 pid=4258->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=23084d4f-1d00-0000-0340-fae6a4100000 pid=4260->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=c708614f-1d00-0000-0340-fae6a5100000 pid=4261->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=18dd807f-1d00-0000-0340-fae6a6100000 pid=4262->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=b3c474b0-1d00-0000-0340-fae6ab100000 pid=4267->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=ff57bcb0-1d00-0000-0340-fae6ad100000 pid=4269->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=693ed5b0-1d00-0000-0340-fae6ae100000 pid=4270->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=e1e7a6d6-1d00-0000-0340-fae6af100000 pid=4271->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=a5ce69fa-1d00-0000-0340-fae6b4100000 pid=4276->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=4cb29bfa-1d00-0000-0340-fae6b6100000 pid=4278->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=2b71acfa-1d00-0000-0340-fae6b7100000 pid=4279->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=25493328-1e00-0000-0340-fae6b8100000 pid=4280->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=7cff8957-1e00-0000-0340-fae6bd100000 pid=4285->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 47B guuid=11b2d757-1e00-0000-0340-fae6bf100000 pid=4287->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 45B guuid=fa71e757-1e00-0000-0340-fae6c0100000 pid=4288->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=133dc986-1e00-0000-0340-fae6c1100000 pid=4289->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B guuid=e05951be-1e00-0000-0340-fae6c5100000 pid=4293 /tmp/x86 net send-data guuid=08eb29b8-1e00-0000-0340-fae6c4100000 pid=4292->guuid=e05951be-1e00-0000-0340-fae6c5100000 pid=4293 clone guuid=e9c5b2e1-1e00-0000-0340-fae6c6100000 pid=4294 /tmp/x86 net zombie guuid=08eb29b8-1e00-0000-0340-fae6c4100000 pid=4292->guuid=e9c5b2e1-1e00-0000-0340-fae6c6100000 pid=4294 clone guuid=4661cae1-1e00-0000-0340-fae6c7100000 pid=4295 /tmp/x86 net send-data zombie guuid=08eb29b8-1e00-0000-0340-fae6c4100000 pid=4292->guuid=4661cae1-1e00-0000-0340-fae6c7100000 pid=4295 clone guuid=e05951be-1e00-0000-0340-fae6c5100000 pid=4293->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 32B guuid=e9c5b2e1-1e00-0000-0340-fae6c6100000 pid=4294->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=4661cae1-1e00-0000-0340-fae6c7100000 pid=4295->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4661cae1-1e00-0000-0340-fae6c7100000 pid=4295->db96774e-46a5-59dd-83b1-9c87ef6aad62 send: 18B guuid=929eeae1-1e00-0000-0340-fae6c9100000 pid=4297 /tmp/x86 guuid=4661cae1-1e00-0000-0340-fae6c7100000 pid=4295->guuid=929eeae1-1e00-0000-0340-fae6c9100000 pid=4297 clone guuid=ed8d24e2-1e00-0000-0340-fae6ca100000 pid=4298->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 134B guuid=782fb312-1f00-0000-0340-fae6cb100000 pid=4299->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 83B guuid=628c6d45-1f00-0000-0340-fae6cf100000 pid=4303 /tmp/x86_64 net send-data guuid=3cf0c544-1f00-0000-0340-fae6ce100000 pid=4302->guuid=628c6d45-1f00-0000-0340-fae6cf100000 pid=4303 clone guuid=4b692748-1f00-0000-0340-fae6d0100000 pid=4304 /tmp/x86_64 net zombie guuid=3cf0c544-1f00-0000-0340-fae6ce100000 pid=4302->guuid=4b692748-1f00-0000-0340-fae6d0100000 pid=4304 clone guuid=27da4548-1f00-0000-0340-fae6d1100000 pid=4305 /tmp/x86_64 net send-data zombie guuid=3cf0c544-1f00-0000-0340-fae6ce100000 pid=4302->guuid=27da4548-1f00-0000-0340-fae6d1100000 pid=4305 clone guuid=628c6d45-1f00-0000-0340-fae6cf100000 pid=4303->d7e75a5d-65d1-5941-aac4-e4015a0a0899 send: 35B guuid=4b692748-1f00-0000-0340-fae6d0100000 pid=4304->d7e75a5d-65d1-5941-aac4-e4015a0a0899 con guuid=27da4548-1f00-0000-0340-fae6d1100000 pid=4305->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e9010b07-def5-5d53-bd9f-ed886898ca33 103.136.69.242:1025 guuid=27da4548-1f00-0000-0340-fae6d1100000 pid=4305->e9010b07-def5-5d53-bd9f-ed886898ca33 send: 23B guuid=a0175b48-1f00-0000-0340-fae6d2100000 pid=4306 /tmp/x86_64 guuid=27da4548-1f00-0000-0340-fae6d1100000 pid=4305->guuid=a0175b48-1f00-0000-0340-fae6d2100000 pid=4306 clone guuid=aaf1bf48-1f00-0000-0340-fae6d4100000 pid=4308->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 131B guuid=3d703c6b-1f00-0000-0340-fae6d5100000 pid=4309->861e64a3-ade7-5eac-b8d2-11a0362764a4 send: 80B
Threat name:
Linux.Trojan.Multiverze
Status:
Malicious
First seen:
2025-08-23 06:16:52 UTC
File Type:
Text (Shell)
AV detection:
13 of 24 (54.17%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai botnet:botnet antivm botnet credential_access defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh b7a9a0ba03113005d17ef270177fed0cd993c126f59288eb3f8c242decd19a14

(this sample)

  
Delivery method
Distributed via web download

Comments