MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c795a6a91fefa05abdccdd953e16563b5347af1517ff49293fe90e41d411c806. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: c795a6a91fefa05abdccdd953e16563b5347af1517ff49293fe90e41d411c806
SHA3-384 hash: aa46fea77aada378f22387209315a71784cbe127306c4ed8e8f6ee23a8a73c3fe76245889bd66b2d1e086e8dab2937d6
SHA1 hash: 5bebb9a25c8ca3de751dfbbe8e510586ccc47cee
MD5 hash: fb126406ab90519bc30fd9ae7ed49289
humanhash: grey-london-chicken-montana
File name:massload
Download: download sample
Signature Mirai
File size:2'264 bytes
First seen:2025-11-16 20:35:20 UTC
Last seen:2025-11-17 06:38:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:qi4wYwFRbxuV+LzKXMOg3Pe3omDUgHZgHJLvmkKXW4952n3KXmatkk0:qi4wtlu6zPgZHuHhrIy3Tat/0
TLSH T1FE41FBDCBE919F232049CFC0F6231A5D600FEBDA68844DF8E8DEBC9D857C9097416641
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://183.81.33.194/mips12affec37ead42f73dd183de74725c5bd3d6621478fe4e0d1b81f1eb46d0c18f MiraiDEU elf geofenced mips mirai ua-wget USA
http://183.81.33.194/mpsl21f65a0f5404263e2abcf0b9cc9a60b35e9ef8c505724c969bb9b3f8427cb44b MiraiDEU elf geofenced mips mirai ua-wget
http://183.81.33.194/arm4f4d312c31b3f1170621721ea7dda0ceb50977bda8f04527cf060f85dda15c513 Miraielf mirai ua-wget
http://183.81.33.194/arm5feec495f2b4a0a7c82f2333569e242ba31197ed563675b92a2319dbc3c77364f Miraiarm elf geofenced mirai ua-wget USA
http://183.81.33.194/arm7b1c2458d22bbb0b7580470d9481654fae096a2bc0e8aab742ba9ac584568094d Miraiarm elf geofenced mirai ua-wget USA

Intelligence


File Origin
# of uploads :
2
# of downloads :
46
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox expand lolbin mirai
Verdict:
Malicious
Labled as:
Trojan[Downloader]/Shell.Agent
Verdict:
Malicious
File Type:
unix shell
First seen:
2025-11-16T18:11:00Z UTC
Last seen:
2025-11-17T10:20:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=ce143dd7-1800-0000-8f44-ce4f5c140000 pid=5212 /usr/bin/sudo guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213 /tmp/sample.bin guuid=ce143dd7-1800-0000-8f44-ce4f5c140000 pid=5212->guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213 execve guuid=986222d9-1800-0000-8f44-ce4f5e140000 pid=5214 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=986222d9-1800-0000-8f44-ce4f5e140000 pid=5214 execve guuid=bb19e7d9-1800-0000-8f44-ce4f5f140000 pid=5215 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=bb19e7d9-1800-0000-8f44-ce4f5f140000 pid=5215 execve guuid=dfac4dda-1800-0000-8f44-ce4f60140000 pid=5216 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=dfac4dda-1800-0000-8f44-ce4f60140000 pid=5216 execve guuid=3301b6da-1800-0000-8f44-ce4f61140000 pid=5217 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=3301b6da-1800-0000-8f44-ce4f61140000 pid=5217 execve guuid=cbd622db-1800-0000-8f44-ce4f62140000 pid=5218 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=cbd622db-1800-0000-8f44-ce4f62140000 pid=5218 execve guuid=4b6387db-1800-0000-8f44-ce4f63140000 pid=5219 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=4b6387db-1800-0000-8f44-ce4f63140000 pid=5219 execve guuid=87bef3db-1800-0000-8f44-ce4f64140000 pid=5220 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=87bef3db-1800-0000-8f44-ce4f64140000 pid=5220 execve guuid=092458dc-1800-0000-8f44-ce4f65140000 pid=5221 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=092458dc-1800-0000-8f44-ce4f65140000 pid=5221 execve guuid=6a0abcdc-1800-0000-8f44-ce4f66140000 pid=5222 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6a0abcdc-1800-0000-8f44-ce4f66140000 pid=5222 execve guuid=1ba420dd-1800-0000-8f44-ce4f67140000 pid=5223 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=1ba420dd-1800-0000-8f44-ce4f67140000 pid=5223 execve guuid=a04a83dd-1800-0000-8f44-ce4f68140000 pid=5224 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=a04a83dd-1800-0000-8f44-ce4f68140000 pid=5224 execve guuid=f26aecdd-1800-0000-8f44-ce4f69140000 pid=5225 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f26aecdd-1800-0000-8f44-ce4f69140000 pid=5225 execve guuid=5c1f50de-1800-0000-8f44-ce4f6a140000 pid=5226 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5c1f50de-1800-0000-8f44-ce4f6a140000 pid=5226 execve guuid=e5f1acde-1800-0000-8f44-ce4f6b140000 pid=5227 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e5f1acde-1800-0000-8f44-ce4f6b140000 pid=5227 execve guuid=f3b20cdf-1800-0000-8f44-ce4f6c140000 pid=5228 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f3b20cdf-1800-0000-8f44-ce4f6c140000 pid=5228 execve guuid=3f4c6bdf-1800-0000-8f44-ce4f6d140000 pid=5229 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=3f4c6bdf-1800-0000-8f44-ce4f6d140000 pid=5229 execve guuid=ede9c7df-1800-0000-8f44-ce4f6e140000 pid=5230 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=ede9c7df-1800-0000-8f44-ce4f6e140000 pid=5230 execve guuid=384c2be0-1800-0000-8f44-ce4f6f140000 pid=5231 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=384c2be0-1800-0000-8f44-ce4f6f140000 pid=5231 execve guuid=dac18ae0-1800-0000-8f44-ce4f70140000 pid=5232 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=dac18ae0-1800-0000-8f44-ce4f70140000 pid=5232 execve guuid=91a1f0e0-1800-0000-8f44-ce4f71140000 pid=5233 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=91a1f0e0-1800-0000-8f44-ce4f71140000 pid=5233 execve guuid=fe0e5de1-1800-0000-8f44-ce4f72140000 pid=5234 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=fe0e5de1-1800-0000-8f44-ce4f72140000 pid=5234 execve guuid=79b9c5e1-1800-0000-8f44-ce4f73140000 pid=5235 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=79b9c5e1-1800-0000-8f44-ce4f73140000 pid=5235 execve guuid=96172ee2-1800-0000-8f44-ce4f74140000 pid=5236 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=96172ee2-1800-0000-8f44-ce4f74140000 pid=5236 execve guuid=16de99e2-1800-0000-8f44-ce4f75140000 pid=5237 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=16de99e2-1800-0000-8f44-ce4f75140000 pid=5237 execve guuid=77d001e3-1800-0000-8f44-ce4f76140000 pid=5238 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=77d001e3-1800-0000-8f44-ce4f76140000 pid=5238 execve guuid=b35e6de3-1800-0000-8f44-ce4f77140000 pid=5239 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=b35e6de3-1800-0000-8f44-ce4f77140000 pid=5239 execve guuid=3d0ddce3-1800-0000-8f44-ce4f78140000 pid=5240 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=3d0ddce3-1800-0000-8f44-ce4f78140000 pid=5240 execve guuid=5a9546e4-1800-0000-8f44-ce4f79140000 pid=5241 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5a9546e4-1800-0000-8f44-ce4f79140000 pid=5241 execve guuid=6f2d98e5-1800-0000-8f44-ce4f7a140000 pid=5242 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6f2d98e5-1800-0000-8f44-ce4f7a140000 pid=5242 execve guuid=50202be6-1800-0000-8f44-ce4f7b140000 pid=5243 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=50202be6-1800-0000-8f44-ce4f7b140000 pid=5243 execve guuid=5609bde6-1800-0000-8f44-ce4f7c140000 pid=5244 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5609bde6-1800-0000-8f44-ce4f7c140000 pid=5244 execve guuid=330a49e7-1800-0000-8f44-ce4f7d140000 pid=5245 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=330a49e7-1800-0000-8f44-ce4f7d140000 pid=5245 execve guuid=c93cd2e7-1800-0000-8f44-ce4f7e140000 pid=5246 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c93cd2e7-1800-0000-8f44-ce4f7e140000 pid=5246 execve guuid=62d45ae8-1800-0000-8f44-ce4f7f140000 pid=5247 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=62d45ae8-1800-0000-8f44-ce4f7f140000 pid=5247 execve guuid=9dfbe6e8-1800-0000-8f44-ce4f80140000 pid=5248 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=9dfbe6e8-1800-0000-8f44-ce4f80140000 pid=5248 execve guuid=e46164e9-1800-0000-8f44-ce4f81140000 pid=5249 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e46164e9-1800-0000-8f44-ce4f81140000 pid=5249 execve guuid=019adbe9-1800-0000-8f44-ce4f82140000 pid=5250 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=019adbe9-1800-0000-8f44-ce4f82140000 pid=5250 execve guuid=1bed4aea-1800-0000-8f44-ce4f83140000 pid=5251 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=1bed4aea-1800-0000-8f44-ce4f83140000 pid=5251 execve guuid=62fabbea-1800-0000-8f44-ce4f84140000 pid=5252 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=62fabbea-1800-0000-8f44-ce4f84140000 pid=5252 execve guuid=c93127eb-1800-0000-8f44-ce4f85140000 pid=5253 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c93127eb-1800-0000-8f44-ce4f85140000 pid=5253 execve guuid=f74a8ceb-1800-0000-8f44-ce4f86140000 pid=5254 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f74a8ceb-1800-0000-8f44-ce4f86140000 pid=5254 execve guuid=f394f6eb-1800-0000-8f44-ce4f87140000 pid=5255 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f394f6eb-1800-0000-8f44-ce4f87140000 pid=5255 execve guuid=d79a60ec-1800-0000-8f44-ce4f88140000 pid=5256 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d79a60ec-1800-0000-8f44-ce4f88140000 pid=5256 execve guuid=4feac9ec-1800-0000-8f44-ce4f89140000 pid=5257 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=4feac9ec-1800-0000-8f44-ce4f89140000 pid=5257 execve guuid=d61237ed-1800-0000-8f44-ce4f8a140000 pid=5258 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d61237ed-1800-0000-8f44-ce4f8a140000 pid=5258 execve guuid=63c3a6ed-1800-0000-8f44-ce4f8b140000 pid=5259 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=63c3a6ed-1800-0000-8f44-ce4f8b140000 pid=5259 execve guuid=e15d0aee-1800-0000-8f44-ce4f8c140000 pid=5260 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e15d0aee-1800-0000-8f44-ce4f8c140000 pid=5260 execve guuid=7f8d6bee-1800-0000-8f44-ce4f8d140000 pid=5261 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=7f8d6bee-1800-0000-8f44-ce4f8d140000 pid=5261 execve guuid=e2c6d6ee-1800-0000-8f44-ce4f8e140000 pid=5262 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e2c6d6ee-1800-0000-8f44-ce4f8e140000 pid=5262 execve guuid=d35942ef-1800-0000-8f44-ce4f8f140000 pid=5263 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d35942ef-1800-0000-8f44-ce4f8f140000 pid=5263 execve guuid=2f22aeef-1800-0000-8f44-ce4f90140000 pid=5264 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=2f22aeef-1800-0000-8f44-ce4f90140000 pid=5264 execve guuid=552320f0-1800-0000-8f44-ce4f91140000 pid=5265 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=552320f0-1800-0000-8f44-ce4f91140000 pid=5265 execve guuid=e0ad92f0-1800-0000-8f44-ce4f92140000 pid=5266 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e0ad92f0-1800-0000-8f44-ce4f92140000 pid=5266 execve guuid=70fb04f1-1800-0000-8f44-ce4f93140000 pid=5267 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=70fb04f1-1800-0000-8f44-ce4f93140000 pid=5267 execve guuid=44587af1-1800-0000-8f44-ce4f94140000 pid=5268 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=44587af1-1800-0000-8f44-ce4f94140000 pid=5268 execve guuid=a189f1f1-1800-0000-8f44-ce4f95140000 pid=5269 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=a189f1f1-1800-0000-8f44-ce4f95140000 pid=5269 execve guuid=bf6561f2-1800-0000-8f44-ce4f96140000 pid=5270 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=bf6561f2-1800-0000-8f44-ce4f96140000 pid=5270 execve guuid=6d95d2f2-1800-0000-8f44-ce4f97140000 pid=5271 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6d95d2f2-1800-0000-8f44-ce4f97140000 pid=5271 execve guuid=0c0544f3-1800-0000-8f44-ce4f98140000 pid=5272 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=0c0544f3-1800-0000-8f44-ce4f98140000 pid=5272 execve guuid=2b95bef3-1800-0000-8f44-ce4f99140000 pid=5273 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=2b95bef3-1800-0000-8f44-ce4f99140000 pid=5273 execve guuid=167930f4-1800-0000-8f44-ce4f9a140000 pid=5274 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=167930f4-1800-0000-8f44-ce4f9a140000 pid=5274 execve guuid=8427a0f4-1800-0000-8f44-ce4f9b140000 pid=5275 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=8427a0f4-1800-0000-8f44-ce4f9b140000 pid=5275 execve guuid=96d716f5-1800-0000-8f44-ce4f9c140000 pid=5276 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=96d716f5-1800-0000-8f44-ce4f9c140000 pid=5276 execve guuid=096586f5-1800-0000-8f44-ce4f9d140000 pid=5277 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=096586f5-1800-0000-8f44-ce4f9d140000 pid=5277 execve guuid=4b28eff5-1800-0000-8f44-ce4f9e140000 pid=5278 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=4b28eff5-1800-0000-8f44-ce4f9e140000 pid=5278 execve guuid=67c56df7-1800-0000-8f44-ce4f9f140000 pid=5279 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=67c56df7-1800-0000-8f44-ce4f9f140000 pid=5279 execve guuid=283057f8-1800-0000-8f44-ce4fa0140000 pid=5280 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=283057f8-1800-0000-8f44-ce4fa0140000 pid=5280 execve guuid=73b031f9-1800-0000-8f44-ce4fa1140000 pid=5281 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=73b031f9-1800-0000-8f44-ce4fa1140000 pid=5281 execve guuid=bea69bf9-1800-0000-8f44-ce4fa2140000 pid=5282 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=bea69bf9-1800-0000-8f44-ce4fa2140000 pid=5282 execve guuid=607c0ffa-1800-0000-8f44-ce4fa3140000 pid=5283 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=607c0ffa-1800-0000-8f44-ce4fa3140000 pid=5283 execve guuid=b58782fa-1800-0000-8f44-ce4fa4140000 pid=5284 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=b58782fa-1800-0000-8f44-ce4fa4140000 pid=5284 execve guuid=02f5f1fa-1800-0000-8f44-ce4fa5140000 pid=5285 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=02f5f1fa-1800-0000-8f44-ce4fa5140000 pid=5285 execve guuid=c05b68fb-1800-0000-8f44-ce4fa6140000 pid=5286 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c05b68fb-1800-0000-8f44-ce4fa6140000 pid=5286 execve guuid=5d46edfb-1800-0000-8f44-ce4fa7140000 pid=5287 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5d46edfb-1800-0000-8f44-ce4fa7140000 pid=5287 execve guuid=536c63fc-1800-0000-8f44-ce4fa8140000 pid=5288 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=536c63fc-1800-0000-8f44-ce4fa8140000 pid=5288 execve guuid=1456e1fc-1800-0000-8f44-ce4fa9140000 pid=5289 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=1456e1fc-1800-0000-8f44-ce4fa9140000 pid=5289 execve guuid=5a454bfd-1800-0000-8f44-ce4faa140000 pid=5290 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5a454bfd-1800-0000-8f44-ce4faa140000 pid=5290 execve guuid=02aeb8fd-1800-0000-8f44-ce4fab140000 pid=5291 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=02aeb8fd-1800-0000-8f44-ce4fab140000 pid=5291 execve guuid=e6fe28fe-1800-0000-8f44-ce4fac140000 pid=5292 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e6fe28fe-1800-0000-8f44-ce4fac140000 pid=5292 execve guuid=21e497fe-1800-0000-8f44-ce4fad140000 pid=5293 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=21e497fe-1800-0000-8f44-ce4fad140000 pid=5293 execve guuid=6f6c0bff-1800-0000-8f44-ce4fae140000 pid=5294 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6f6c0bff-1800-0000-8f44-ce4fae140000 pid=5294 execve guuid=2a4f85ff-1800-0000-8f44-ce4faf140000 pid=5295 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=2a4f85ff-1800-0000-8f44-ce4faf140000 pid=5295 execve guuid=c019f9ff-1800-0000-8f44-ce4fb0140000 pid=5296 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c019f9ff-1800-0000-8f44-ce4fb0140000 pid=5296 execve guuid=0dad6300-1900-0000-8f44-ce4fb1140000 pid=5297 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=0dad6300-1900-0000-8f44-ce4fb1140000 pid=5297 execve guuid=813dd000-1900-0000-8f44-ce4fb2140000 pid=5298 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=813dd000-1900-0000-8f44-ce4fb2140000 pid=5298 execve guuid=4cd33f01-1900-0000-8f44-ce4fb3140000 pid=5299 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=4cd33f01-1900-0000-8f44-ce4fb3140000 pid=5299 execve guuid=fc70b201-1900-0000-8f44-ce4fb4140000 pid=5300 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=fc70b201-1900-0000-8f44-ce4fb4140000 pid=5300 execve guuid=5b662c02-1900-0000-8f44-ce4fb5140000 pid=5301 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5b662c02-1900-0000-8f44-ce4fb5140000 pid=5301 execve guuid=ffbf9e02-1900-0000-8f44-ce4fb6140000 pid=5302 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=ffbf9e02-1900-0000-8f44-ce4fb6140000 pid=5302 execve guuid=b3f70d03-1900-0000-8f44-ce4fb7140000 pid=5303 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=b3f70d03-1900-0000-8f44-ce4fb7140000 pid=5303 execve guuid=caa08603-1900-0000-8f44-ce4fb8140000 pid=5304 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=caa08603-1900-0000-8f44-ce4fb8140000 pid=5304 execve guuid=b058f703-1900-0000-8f44-ce4fb9140000 pid=5305 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=b058f703-1900-0000-8f44-ce4fb9140000 pid=5305 execve guuid=b4e76004-1900-0000-8f44-ce4fba140000 pid=5306 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=b4e76004-1900-0000-8f44-ce4fba140000 pid=5306 execve guuid=d111cd04-1900-0000-8f44-ce4fbb140000 pid=5307 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d111cd04-1900-0000-8f44-ce4fbb140000 pid=5307 execve guuid=88a64405-1900-0000-8f44-ce4fbc140000 pid=5308 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=88a64405-1900-0000-8f44-ce4fbc140000 pid=5308 execve guuid=f2faa805-1900-0000-8f44-ce4fbd140000 pid=5309 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f2faa805-1900-0000-8f44-ce4fbd140000 pid=5309 execve guuid=adee0b06-1900-0000-8f44-ce4fbe140000 pid=5310 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=adee0b06-1900-0000-8f44-ce4fbe140000 pid=5310 execve guuid=6ced6806-1900-0000-8f44-ce4fbf140000 pid=5311 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6ced6806-1900-0000-8f44-ce4fbf140000 pid=5311 execve guuid=0d8dc706-1900-0000-8f44-ce4fc0140000 pid=5312 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=0d8dc706-1900-0000-8f44-ce4fc0140000 pid=5312 execve guuid=61853307-1900-0000-8f44-ce4fc1140000 pid=5313 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=61853307-1900-0000-8f44-ce4fc1140000 pid=5313 execve guuid=21520208-1900-0000-8f44-ce4fc2140000 pid=5314 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=21520208-1900-0000-8f44-ce4fc2140000 pid=5314 execve guuid=540e7208-1900-0000-8f44-ce4fc3140000 pid=5315 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=540e7208-1900-0000-8f44-ce4fc3140000 pid=5315 execve guuid=37fbd408-1900-0000-8f44-ce4fc4140000 pid=5316 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=37fbd408-1900-0000-8f44-ce4fc4140000 pid=5316 execve guuid=01023f09-1900-0000-8f44-ce4fc5140000 pid=5317 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=01023f09-1900-0000-8f44-ce4fc5140000 pid=5317 execve guuid=df18b009-1900-0000-8f44-ce4fc6140000 pid=5318 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=df18b009-1900-0000-8f44-ce4fc6140000 pid=5318 execve guuid=9085330a-1900-0000-8f44-ce4fc8140000 pid=5320 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=9085330a-1900-0000-8f44-ce4fc8140000 pid=5320 execve guuid=a572d60a-1900-0000-8f44-ce4fca140000 pid=5322 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=a572d60a-1900-0000-8f44-ce4fca140000 pid=5322 execve guuid=a95d3e0b-1900-0000-8f44-ce4fcc140000 pid=5324 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=a95d3e0b-1900-0000-8f44-ce4fcc140000 pid=5324 execve guuid=fdab2e0c-1900-0000-8f44-ce4fcd140000 pid=5325 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=fdab2e0c-1900-0000-8f44-ce4fcd140000 pid=5325 execve guuid=fe0b9a0c-1900-0000-8f44-ce4fce140000 pid=5326 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=fe0b9a0c-1900-0000-8f44-ce4fce140000 pid=5326 execve guuid=d3f3170d-1900-0000-8f44-ce4fcf140000 pid=5327 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d3f3170d-1900-0000-8f44-ce4fcf140000 pid=5327 execve guuid=f1289e0d-1900-0000-8f44-ce4fd0140000 pid=5328 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f1289e0d-1900-0000-8f44-ce4fd0140000 pid=5328 execve guuid=06f9180e-1900-0000-8f44-ce4fd1140000 pid=5329 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=06f9180e-1900-0000-8f44-ce4fd1140000 pid=5329 execve guuid=51da6d0f-1900-0000-8f44-ce4fd2140000 pid=5330 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=51da6d0f-1900-0000-8f44-ce4fd2140000 pid=5330 execve guuid=7b103110-1900-0000-8f44-ce4fd3140000 pid=5331 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=7b103110-1900-0000-8f44-ce4fd3140000 pid=5331 execve guuid=10e1e910-1900-0000-8f44-ce4fd8140000 pid=5336 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=10e1e910-1900-0000-8f44-ce4fd8140000 pid=5336 execve guuid=f6c0b611-1900-0000-8f44-ce4fd9140000 pid=5337 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f6c0b611-1900-0000-8f44-ce4fd9140000 pid=5337 execve guuid=df056012-1900-0000-8f44-ce4fda140000 pid=5338 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=df056012-1900-0000-8f44-ce4fda140000 pid=5338 execve guuid=8f77eb12-1900-0000-8f44-ce4fdb140000 pid=5339 /usr/bin/ls guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=8f77eb12-1900-0000-8f44-ce4fdb140000 pid=5339 execve guuid=973a6813-1900-0000-8f44-ce4fdc140000 pid=5340 /usr/bin/rm guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=973a6813-1900-0000-8f44-ce4fdc140000 pid=5340 execve guuid=fa37d313-1900-0000-8f44-ce4fdd140000 pid=5341 /usr/bin/wget net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=fa37d313-1900-0000-8f44-ce4fdd140000 pid=5341 execve guuid=029d755a-1900-0000-8f44-ce4fde140000 pid=5342 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=029d755a-1900-0000-8f44-ce4fde140000 pid=5342 execve guuid=bc9fc15a-1900-0000-8f44-ce4fdf140000 pid=5343 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=bc9fc15a-1900-0000-8f44-ce4fdf140000 pid=5343 clone guuid=13774a5b-1900-0000-8f44-ce4fe1140000 pid=5345 /usr/bin/wget net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=13774a5b-1900-0000-8f44-ce4fe1140000 pid=5345 execve guuid=c42d18be-1900-0000-8f44-ce4fe2140000 pid=5346 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c42d18be-1900-0000-8f44-ce4fe2140000 pid=5346 execve guuid=6b7569be-1900-0000-8f44-ce4fe3140000 pid=5347 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=6b7569be-1900-0000-8f44-ce4fe3140000 pid=5347 clone guuid=5daf02bf-1900-0000-8f44-ce4fe5140000 pid=5349 /usr/bin/wget net send-data guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5daf02bf-1900-0000-8f44-ce4fe5140000 pid=5349 execve guuid=4f68e2ed-1900-0000-8f44-ce4fe6140000 pid=5350 /usr/bin/busybox net send-data guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=4f68e2ed-1900-0000-8f44-ce4fe6140000 pid=5350 execve guuid=3690ec15-1a00-0000-8f44-ce4fed140000 pid=5357 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=3690ec15-1a00-0000-8f44-ce4fed140000 pid=5357 execve guuid=44e17116-1a00-0000-8f44-ce4fee140000 pid=5358 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=44e17116-1a00-0000-8f44-ce4fee140000 pid=5358 clone guuid=e7868a16-1a00-0000-8f44-ce4fef140000 pid=5359 /usr/bin/wget net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e7868a16-1a00-0000-8f44-ce4fef140000 pid=5359 execve guuid=8eb04475-1a00-0000-8f44-ce4f0a150000 pid=5386 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=8eb04475-1a00-0000-8f44-ce4f0a150000 pid=5386 execve guuid=5f1bbf75-1a00-0000-8f44-ce4f0b150000 pid=5387 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5f1bbf75-1a00-0000-8f44-ce4f0b150000 pid=5387 clone guuid=0d76bd76-1a00-0000-8f44-ce4f0d150000 pid=5389 /usr/bin/wget net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=0d76bd76-1a00-0000-8f44-ce4f0d150000 pid=5389 execve guuid=aa91d2d2-1a00-0000-8f44-ce4f0e150000 pid=5390 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=aa91d2d2-1a00-0000-8f44-ce4f0e150000 pid=5390 execve guuid=d78a53d3-1a00-0000-8f44-ce4f0f150000 pid=5391 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=d78a53d3-1a00-0000-8f44-ce4f0f150000 pid=5391 clone guuid=378e6cd4-1a00-0000-8f44-ce4f11150000 pid=5393 /usr/bin/curl net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=378e6cd4-1a00-0000-8f44-ce4f11150000 pid=5393 execve guuid=1cbee61a-1b00-0000-8f44-ce4f12150000 pid=5394 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=1cbee61a-1b00-0000-8f44-ce4f12150000 pid=5394 execve guuid=eff2721b-1b00-0000-8f44-ce4f13150000 pid=5395 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=eff2721b-1b00-0000-8f44-ce4f13150000 pid=5395 clone guuid=f46c711c-1b00-0000-8f44-ce4f15150000 pid=5397 /usr/bin/curl net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=f46c711c-1b00-0000-8f44-ce4f15150000 pid=5397 execve guuid=91759985-1b00-0000-8f44-ce4f16150000 pid=5398 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=91759985-1b00-0000-8f44-ce4f16150000 pid=5398 execve guuid=5c681f86-1b00-0000-8f44-ce4f17150000 pid=5399 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=5c681f86-1b00-0000-8f44-ce4f17150000 pid=5399 clone guuid=64d04287-1b00-0000-8f44-ce4f19150000 pid=5401 /usr/bin/curl net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=64d04287-1b00-0000-8f44-ce4f19150000 pid=5401 execve guuid=3eedd7a3-1b00-0000-8f44-ce4f1a150000 pid=5402 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=3eedd7a3-1b00-0000-8f44-ce4f1a150000 pid=5402 execve guuid=dde362a4-1b00-0000-8f44-ce4f1b150000 pid=5403 /home/arm4 guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=dde362a4-1b00-0000-8f44-ce4f1b150000 pid=5403 execve guuid=070ca5a4-1b00-0000-8f44-ce4f1c150000 pid=5404 /usr/bin/curl net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=070ca5a4-1b00-0000-8f44-ce4f1c150000 pid=5404 execve guuid=9a7eaaea-1b00-0000-8f44-ce4f1d150000 pid=5405 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=9a7eaaea-1b00-0000-8f44-ce4f1d150000 pid=5405 execve guuid=276932eb-1b00-0000-8f44-ce4f1e150000 pid=5406 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=276932eb-1b00-0000-8f44-ce4f1e150000 pid=5406 clone guuid=49af4cec-1b00-0000-8f44-ce4f20150000 pid=5408 /usr/bin/curl net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=49af4cec-1b00-0000-8f44-ce4f20150000 pid=5408 execve guuid=18e6f03a-1c00-0000-8f44-ce4f21150000 pid=5409 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=18e6f03a-1c00-0000-8f44-ce4f21150000 pid=5409 execve guuid=a9e12a3b-1c00-0000-8f44-ce4f22150000 pid=5410 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=a9e12a3b-1c00-0000-8f44-ce4f22150000 pid=5410 clone guuid=55fde43b-1c00-0000-8f44-ce4f24150000 pid=5412 /usr/bin/busybox net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=55fde43b-1c00-0000-8f44-ce4f24150000 pid=5412 execve guuid=71da92f6-1c00-0000-8f44-ce4f25150000 pid=5413 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=71da92f6-1c00-0000-8f44-ce4f25150000 pid=5413 execve guuid=03b118f7-1c00-0000-8f44-ce4f26150000 pid=5414 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=03b118f7-1c00-0000-8f44-ce4f26150000 pid=5414 clone guuid=707522f8-1c00-0000-8f44-ce4f28150000 pid=5416 /usr/bin/busybox net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=707522f8-1c00-0000-8f44-ce4f28150000 pid=5416 execve guuid=c1baeecf-1d00-0000-8f44-ce4f29150000 pid=5417 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=c1baeecf-1d00-0000-8f44-ce4f29150000 pid=5417 execve guuid=719b7dd0-1d00-0000-8f44-ce4f2a150000 pid=5418 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=719b7dd0-1d00-0000-8f44-ce4f2a150000 pid=5418 clone guuid=56ca96d1-1d00-0000-8f44-ce4f2c150000 pid=5420 /usr/bin/busybox net send-data guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=56ca96d1-1d00-0000-8f44-ce4f2c150000 pid=5420 execve guuid=2880b065-1e00-0000-8f44-ce4f2d150000 pid=5421 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=2880b065-1e00-0000-8f44-ce4f2d150000 pid=5421 execve guuid=e8bd4e66-1e00-0000-8f44-ce4f2e150000 pid=5422 /home/arm4 guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=e8bd4e66-1e00-0000-8f44-ce4f2e150000 pid=5422 execve guuid=1b2bc466-1e00-0000-8f44-ce4f2f150000 pid=5423 /usr/bin/busybox net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=1b2bc466-1e00-0000-8f44-ce4f2f150000 pid=5423 execve guuid=61e1d37b-1f00-0000-8f44-ce4f30150000 pid=5424 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=61e1d37b-1f00-0000-8f44-ce4f30150000 pid=5424 execve guuid=16e45d7c-1f00-0000-8f44-ce4f31150000 pid=5425 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=16e45d7c-1f00-0000-8f44-ce4f31150000 pid=5425 clone guuid=bfeb6f7d-1f00-0000-8f44-ce4f33150000 pid=5427 /usr/bin/busybox net send-data write-file guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=bfeb6f7d-1f00-0000-8f44-ce4f33150000 pid=5427 execve guuid=784d0c38-2000-0000-8f44-ce4f34150000 pid=5428 /usr/bin/chmod guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=784d0c38-2000-0000-8f44-ce4f34150000 pid=5428 execve guuid=696cbb38-2000-0000-8f44-ce4f35150000 pid=5429 /usr/bin/dash guuid=9535ebd8-1800-0000-8f44-ce4f5d140000 pid=5213->guuid=696cbb38-2000-0000-8f44-ce4f35150000 pid=5429 clone 3e6fbf2c-0051-5851-89c0-e187a4cef436 183.81.33.194:80 guuid=fa37d313-1900-0000-8f44-ce4fdd140000 pid=5341->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 132B guuid=13774a5b-1900-0000-8f44-ce4fe1140000 pid=5345->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 132B guuid=5daf02bf-1900-0000-8f44-ce4fe5140000 pid=5349->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 132B guuid=4f68e2ed-1900-0000-8f44-ce4fe6140000 pid=5350->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 80B guuid=e7868a16-1a00-0000-8f44-ce4fef140000 pid=5359->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 132B guuid=0d76bd76-1a00-0000-8f44-ce4f0d150000 pid=5389->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 132B guuid=378e6cd4-1a00-0000-8f44-ce4f11150000 pid=5393->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 81B guuid=f46c711c-1b00-0000-8f44-ce4f15150000 pid=5397->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 81B guuid=64d04287-1b00-0000-8f44-ce4f19150000 pid=5401->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 81B guuid=070ca5a4-1b00-0000-8f44-ce4f1c150000 pid=5404->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 81B guuid=49af4cec-1b00-0000-8f44-ce4f20150000 pid=5408->3e6fbf2c-0051-5851-89c0-e187a4cef436 send: 81B c528ee0d-0141-553c-b836-6c133fbdf232 183.81.33.194:21 guuid=55fde43b-1c00-0000-8f44-ce4f24150000 pid=5412->c528ee0d-0141-553c-b836-6c133fbdf232 send: 78B 6bd2ea23-9a8b-5225-b8e0-a771dc82c454 183.81.33.194:42233 guuid=55fde43b-1c00-0000-8f44-ce4f24150000 pid=5412->6bd2ea23-9a8b-5225-b8e0-a771dc82c454 con guuid=707522f8-1c00-0000-8f44-ce4f28150000 pid=5416->c528ee0d-0141-553c-b836-6c133fbdf232 send: 78B 6cbfe92c-f3ca-5e1f-8d85-aedb79e92a6c 183.81.33.194:37027 guuid=707522f8-1c00-0000-8f44-ce4f28150000 pid=5416->6cbfe92c-f3ca-5e1f-8d85-aedb79e92a6c con guuid=56ca96d1-1d00-0000-8f44-ce4f2c150000 pid=5420->c528ee0d-0141-553c-b836-6c133fbdf232 send: 72B 70c4587f-1b11-5004-8683-e1e0d02f4203 183.81.33.194:45343 guuid=56ca96d1-1d00-0000-8f44-ce4f2c150000 pid=5420->70c4587f-1b11-5004-8683-e1e0d02f4203 con guuid=1b2bc466-1e00-0000-8f44-ce4f2f150000 pid=5423->c528ee0d-0141-553c-b836-6c133fbdf232 send: 78B 9c9de87d-257c-5c7e-a4e4-887662c140b1 183.81.33.194:40255 guuid=1b2bc466-1e00-0000-8f44-ce4f2f150000 pid=5423->9c9de87d-257c-5c7e-a4e4-887662c140b1 con guuid=bfeb6f7d-1f00-0000-8f44-ce4f33150000 pid=5427->c528ee0d-0141-553c-b836-6c133fbdf232 send: 78B cc8a5440-17af-53d5-b4e7-d335e49f94bb 183.81.33.194:42161 guuid=bfeb6f7d-1f00-0000-8f44-ce4f33150000 pid=5427->cc8a5440-17af-53d5-b4e7-d335e49f94bb con
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2025-11-16 23:19:47 UTC
File Type:
Text (Shell)
AV detection:
15 of 24 (62.50%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh c795a6a91fefa05abdccdd953e16563b5347af1517ff49293fe90e41d411c806

(this sample)

  
Delivery method
Distributed via web download

Comments