MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d0e164aca64197432f7bd969a66d5395498278368c14e414bd2c706d6b750d74. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: d0e164aca64197432f7bd969a66d5395498278368c14e414bd2c706d6b750d74
SHA3-384 hash: 11a6690f01daab142f0f0dd641a5da8943297878ca5d1f07148cc2ec68d5e6a25d147b5e975093cb8d2d75211f5b220d
SHA1 hash: e94977ec4a389a3d048e0e2a6d2e13928c1bc3ce
MD5 hash: 8cf104e0cbc31c780aca4689925eaf6d
humanhash: skylark-utah-victor-venus
File name:1.sh
Download: download sample
Signature Mirai
File size:2'426 bytes
First seen:2025-12-18 18:46:24 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:h4qbtUHzcS/ka/amyUyfAkTyXq8vdBxRBx0ek:JbtUH9kmz/gAkTyXq8vdBEek
TLSH T1214100C5A323BD02064FBE2EFB6007DEA0E14B4DB05F4FF8ACD84A6E5498991A024B45
Magika csv
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.77.241.135/mpsl8d673568ad17c7fedba6c16d4a114db83f82e1703ac7e8ecc0f10150d42c5393 Miraielf geofenced mips mirai ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive mirai
Verdict:
Malicious
File Type:
text
First seen:
2025-12-18T19:25:00Z UTC
Last seen:
2025-12-19T07:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=18884e04-1900-0000-396c-a9c201130000 pid=4865 /usr/bin/sudo guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873 /tmp/sample.bin guuid=18884e04-1900-0000-396c-a9c201130000 pid=4865->guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873 execve guuid=72e6ee06-1900-0000-396c-a9c20b130000 pid=4875 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=72e6ee06-1900-0000-396c-a9c20b130000 pid=4875 execve guuid=c73c6707-1900-0000-396c-a9c20e130000 pid=4878 /usr/bin/wget net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c73c6707-1900-0000-396c-a9c20e130000 pid=4878 execve guuid=84c62034-1900-0000-396c-a9c286130000 pid=4998 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=84c62034-1900-0000-396c-a9c286130000 pid=4998 execve guuid=af188e34-1900-0000-396c-a9c288130000 pid=5000 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=af188e34-1900-0000-396c-a9c288130000 pid=5000 clone guuid=096c7536-1900-0000-396c-a9c28b130000 pid=5003 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=096c7536-1900-0000-396c-a9c28b130000 pid=5003 execve guuid=2e65d836-1900-0000-396c-a9c28c130000 pid=5004 /usr/bin/curl net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2e65d836-1900-0000-396c-a9c28c130000 pid=5004 execve guuid=71344b84-1900-0000-396c-a9c203140000 pid=5123 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=71344b84-1900-0000-396c-a9c203140000 pid=5123 execve guuid=c7031c90-1900-0000-396c-a9c205140000 pid=5125 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c7031c90-1900-0000-396c-a9c205140000 pid=5125 clone guuid=c2020f91-1900-0000-396c-a9c209140000 pid=5129 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c2020f91-1900-0000-396c-a9c209140000 pid=5129 execve guuid=6a019491-1900-0000-396c-a9c20a140000 pid=5130 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=6a019491-1900-0000-396c-a9c20a140000 pid=5130 execve guuid=e82f1492-1900-0000-396c-a9c20d140000 pid=5133 /usr/bin/wget net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=e82f1492-1900-0000-396c-a9c20d140000 pid=5133 execve guuid=81b777bb-1900-0000-396c-a9c245140000 pid=5189 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=81b777bb-1900-0000-396c-a9c245140000 pid=5189 execve guuid=65fee9bb-1900-0000-396c-a9c247140000 pid=5191 /tmp/i686 net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=65fee9bb-1900-0000-396c-a9c247140000 pid=5191 execve guuid=824141bc-1900-0000-396c-a9c24a140000 pid=5194 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=824141bc-1900-0000-396c-a9c24a140000 pid=5194 execve guuid=5a3dc4bc-1900-0000-396c-a9c253140000 pid=5203 /usr/bin/curl net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=5a3dc4bc-1900-0000-396c-a9c253140000 pid=5203 execve guuid=f0b338eb-1900-0000-396c-a9c26c140000 pid=5228 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=f0b338eb-1900-0000-396c-a9c26c140000 pid=5228 execve guuid=194eb3eb-1900-0000-396c-a9c26e140000 pid=5230 /tmp/i686 net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=194eb3eb-1900-0000-396c-a9c26e140000 pid=5230 execve guuid=bd204f1c-1b00-0000-396c-a9c27e140000 pid=5246 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=bd204f1c-1b00-0000-396c-a9c27e140000 pid=5246 execve guuid=3a1c1529-1b00-0000-396c-a9c282140000 pid=5250 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=3a1c1529-1b00-0000-396c-a9c282140000 pid=5250 execve guuid=edfa2a2b-1b00-0000-396c-a9c283140000 pid=5251 /usr/bin/wget net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=edfa2a2b-1b00-0000-396c-a9c283140000 pid=5251 execve guuid=029cdc54-1b00-0000-396c-a9c284140000 pid=5252 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=029cdc54-1b00-0000-396c-a9c284140000 pid=5252 execve guuid=adc51b55-1b00-0000-396c-a9c285140000 pid=5253 /tmp/x86 net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=adc51b55-1b00-0000-396c-a9c285140000 pid=5253 execve guuid=426d4f87-1c00-0000-396c-a9c2a7140000 pid=5287 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=426d4f87-1c00-0000-396c-a9c2a7140000 pid=5287 execve guuid=d5998f87-1c00-0000-396c-a9c2ab140000 pid=5291 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d5998f87-1c00-0000-396c-a9c2ab140000 pid=5291 execve guuid=8a14d58a-1c00-0000-396c-a9c2ac140000 pid=5292 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=8a14d58a-1c00-0000-396c-a9c2ac140000 pid=5292 execve guuid=94911e8b-1c00-0000-396c-a9c2ad140000 pid=5293 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=94911e8b-1c00-0000-396c-a9c2ad140000 pid=5293 clone guuid=712a268b-1c00-0000-396c-a9c2ae140000 pid=5294 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=712a268b-1c00-0000-396c-a9c2ae140000 pid=5294 execve guuid=aa2a5b8b-1c00-0000-396c-a9c2af140000 pid=5295 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=aa2a5b8b-1c00-0000-396c-a9c2af140000 pid=5295 execve guuid=2a848f8b-1c00-0000-396c-a9c2b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2a848f8b-1c00-0000-396c-a9c2b0140000 pid=5296 execve guuid=f49b7cbf-1c00-0000-396c-a9c2b1140000 pid=5297 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=f49b7cbf-1c00-0000-396c-a9c2b1140000 pid=5297 execve guuid=d399ffbf-1c00-0000-396c-a9c2b2140000 pid=5298 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d399ffbf-1c00-0000-396c-a9c2b2140000 pid=5298 clone guuid=da7d0ec1-1c00-0000-396c-a9c2b4140000 pid=5300 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=da7d0ec1-1c00-0000-396c-a9c2b4140000 pid=5300 execve guuid=00808fc1-1c00-0000-396c-a9c2b5140000 pid=5301 /usr/bin/curl net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=00808fc1-1c00-0000-396c-a9c2b5140000 pid=5301 execve guuid=e092f7f7-1c00-0000-396c-a9c2b6140000 pid=5302 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=e092f7f7-1c00-0000-396c-a9c2b6140000 pid=5302 execve guuid=f62547f8-1c00-0000-396c-a9c2b7140000 pid=5303 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=f62547f8-1c00-0000-396c-a9c2b7140000 pid=5303 clone guuid=b39523fa-1c00-0000-396c-a9c2b9140000 pid=5305 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=b39523fa-1c00-0000-396c-a9c2b9140000 pid=5305 execve guuid=00bb6bfa-1c00-0000-396c-a9c2ba140000 pid=5306 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=00bb6bfa-1c00-0000-396c-a9c2ba140000 pid=5306 execve guuid=02ddaafa-1c00-0000-396c-a9c2bb140000 pid=5307 /usr/bin/wget net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=02ddaafa-1c00-0000-396c-a9c2bb140000 pid=5307 execve guuid=4226c32f-1d00-0000-396c-a9c2bc140000 pid=5308 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=4226c32f-1d00-0000-396c-a9c2bc140000 pid=5308 execve guuid=3ee94f30-1d00-0000-396c-a9c2bd140000 pid=5309 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=3ee94f30-1d00-0000-396c-a9c2bd140000 pid=5309 clone guuid=b3c0be31-1d00-0000-396c-a9c2bf140000 pid=5311 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=b3c0be31-1d00-0000-396c-a9c2bf140000 pid=5311 execve guuid=866c3832-1d00-0000-396c-a9c2c0140000 pid=5312 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=866c3832-1d00-0000-396c-a9c2c0140000 pid=5312 execve guuid=86951536-1d00-0000-396c-a9c2c1140000 pid=5313 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=86951536-1d00-0000-396c-a9c2c1140000 pid=5313 execve guuid=7abb9236-1d00-0000-396c-a9c2c2140000 pid=5314 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7abb9236-1d00-0000-396c-a9c2c2140000 pid=5314 clone guuid=7391a936-1d00-0000-396c-a9c2c3140000 pid=5315 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7391a936-1d00-0000-396c-a9c2c3140000 pid=5315 execve guuid=e85b1f37-1d00-0000-396c-a9c2c4140000 pid=5316 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=e85b1f37-1d00-0000-396c-a9c2c4140000 pid=5316 execve guuid=13e99d37-1d00-0000-396c-a9c2c5140000 pid=5317 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=13e99d37-1d00-0000-396c-a9c2c5140000 pid=5317 execve guuid=54792a39-1d00-0000-396c-a9c2c6140000 pid=5318 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=54792a39-1d00-0000-396c-a9c2c6140000 pid=5318 execve guuid=9f4b9939-1d00-0000-396c-a9c2c7140000 pid=5319 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=9f4b9939-1d00-0000-396c-a9c2c7140000 pid=5319 clone guuid=df89ae39-1d00-0000-396c-a9c2c8140000 pid=5320 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=df89ae39-1d00-0000-396c-a9c2c8140000 pid=5320 execve guuid=2a401f3a-1d00-0000-396c-a9c2c9140000 pid=5321 /usr/bin/curl net send-data write-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2a401f3a-1d00-0000-396c-a9c2c9140000 pid=5321 execve guuid=9b510570-1d00-0000-396c-a9c2ca140000 pid=5322 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=9b510570-1d00-0000-396c-a9c2ca140000 pid=5322 execve guuid=08a54f70-1d00-0000-396c-a9c2cb140000 pid=5323 /tmp/i486 net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=08a54f70-1d00-0000-396c-a9c2cb140000 pid=5323 execve guuid=32df2a9c-1e00-0000-396c-a9c2cd140000 pid=5325 /usr/bin/rm delete-file guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=32df2a9c-1e00-0000-396c-a9c2cd140000 pid=5325 execve guuid=21ddfa9c-1e00-0000-396c-a9c2d1140000 pid=5329 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=21ddfa9c-1e00-0000-396c-a9c2d1140000 pid=5329 execve guuid=08ffb09d-1e00-0000-396c-a9c2d2140000 pid=5330 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=08ffb09d-1e00-0000-396c-a9c2d2140000 pid=5330 execve guuid=985b45a0-1e00-0000-396c-a9c2d3140000 pid=5331 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=985b45a0-1e00-0000-396c-a9c2d3140000 pid=5331 execve guuid=7a707ea0-1e00-0000-396c-a9c2d4140000 pid=5332 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7a707ea0-1e00-0000-396c-a9c2d4140000 pid=5332 clone guuid=459888a0-1e00-0000-396c-a9c2d5140000 pid=5333 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=459888a0-1e00-0000-396c-a9c2d5140000 pid=5333 execve guuid=81a6c1a0-1e00-0000-396c-a9c2d6140000 pid=5334 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=81a6c1a0-1e00-0000-396c-a9c2d6140000 pid=5334 execve guuid=603d5da2-1e00-0000-396c-a9c2d7140000 pid=5335 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=603d5da2-1e00-0000-396c-a9c2d7140000 pid=5335 execve guuid=26b49aa2-1e00-0000-396c-a9c2d8140000 pid=5336 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=26b49aa2-1e00-0000-396c-a9c2d8140000 pid=5336 clone guuid=9584a8a2-1e00-0000-396c-a9c2d9140000 pid=5337 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=9584a8a2-1e00-0000-396c-a9c2d9140000 pid=5337 execve guuid=76f5dfa2-1e00-0000-396c-a9c2da140000 pid=5338 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=76f5dfa2-1e00-0000-396c-a9c2da140000 pid=5338 execve guuid=a4ea1ba3-1e00-0000-396c-a9c2db140000 pid=5339 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=a4ea1ba3-1e00-0000-396c-a9c2db140000 pid=5339 execve guuid=c113eca3-1e00-0000-396c-a9c2dc140000 pid=5340 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c113eca3-1e00-0000-396c-a9c2dc140000 pid=5340 execve guuid=e4bb2aa4-1e00-0000-396c-a9c2dd140000 pid=5341 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=e4bb2aa4-1e00-0000-396c-a9c2dd140000 pid=5341 clone guuid=ac4135a4-1e00-0000-396c-a9c2de140000 pid=5342 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=ac4135a4-1e00-0000-396c-a9c2de140000 pid=5342 execve guuid=c62c8ea4-1e00-0000-396c-a9c2df140000 pid=5343 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c62c8ea4-1e00-0000-396c-a9c2df140000 pid=5343 execve guuid=501cfca5-1e00-0000-396c-a9c2e0140000 pid=5344 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=501cfca5-1e00-0000-396c-a9c2e0140000 pid=5344 execve guuid=9e2f51a6-1e00-0000-396c-a9c2e1140000 pid=5345 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=9e2f51a6-1e00-0000-396c-a9c2e1140000 pid=5345 clone guuid=0a315fa6-1e00-0000-396c-a9c2e2140000 pid=5346 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=0a315fa6-1e00-0000-396c-a9c2e2140000 pid=5346 execve guuid=58b793a6-1e00-0000-396c-a9c2e3140000 pid=5347 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=58b793a6-1e00-0000-396c-a9c2e3140000 pid=5347 execve guuid=953ae9a6-1e00-0000-396c-a9c2e4140000 pid=5348 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=953ae9a6-1e00-0000-396c-a9c2e4140000 pid=5348 execve guuid=3300b0a7-1e00-0000-396c-a9c2e5140000 pid=5349 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=3300b0a7-1e00-0000-396c-a9c2e5140000 pid=5349 execve guuid=47db0aa8-1e00-0000-396c-a9c2e6140000 pid=5350 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=47db0aa8-1e00-0000-396c-a9c2e6140000 pid=5350 clone guuid=62e519a8-1e00-0000-396c-a9c2e7140000 pid=5351 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=62e519a8-1e00-0000-396c-a9c2e7140000 pid=5351 execve guuid=fb9f53a8-1e00-0000-396c-a9c2e8140000 pid=5352 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=fb9f53a8-1e00-0000-396c-a9c2e8140000 pid=5352 execve guuid=2116e4a9-1e00-0000-396c-a9c2e9140000 pid=5353 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2116e4a9-1e00-0000-396c-a9c2e9140000 pid=5353 execve guuid=7a181caa-1e00-0000-396c-a9c2ea140000 pid=5354 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7a181caa-1e00-0000-396c-a9c2ea140000 pid=5354 clone guuid=657f2aaa-1e00-0000-396c-a9c2eb140000 pid=5355 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=657f2aaa-1e00-0000-396c-a9c2eb140000 pid=5355 execve guuid=873879aa-1e00-0000-396c-a9c2ec140000 pid=5356 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=873879aa-1e00-0000-396c-a9c2ec140000 pid=5356 execve guuid=b758d1aa-1e00-0000-396c-a9c2ed140000 pid=5357 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=b758d1aa-1e00-0000-396c-a9c2ed140000 pid=5357 execve guuid=a102c2ab-1e00-0000-396c-a9c2ee140000 pid=5358 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=a102c2ab-1e00-0000-396c-a9c2ee140000 pid=5358 execve guuid=98c321ac-1e00-0000-396c-a9c2ef140000 pid=5359 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=98c321ac-1e00-0000-396c-a9c2ef140000 pid=5359 clone guuid=d6a330ac-1e00-0000-396c-a9c2f0140000 pid=5360 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d6a330ac-1e00-0000-396c-a9c2f0140000 pid=5360 execve guuid=261182ac-1e00-0000-396c-a9c2f1140000 pid=5361 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=261182ac-1e00-0000-396c-a9c2f1140000 pid=5361 execve guuid=d83219af-1e00-0000-396c-a9c2f2140000 pid=5362 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d83219af-1e00-0000-396c-a9c2f2140000 pid=5362 execve guuid=babd76af-1e00-0000-396c-a9c2f3140000 pid=5363 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=babd76af-1e00-0000-396c-a9c2f3140000 pid=5363 clone guuid=75b388af-1e00-0000-396c-a9c2f4140000 pid=5364 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=75b388af-1e00-0000-396c-a9c2f4140000 pid=5364 execve guuid=616711b0-1e00-0000-396c-a9c2f5140000 pid=5365 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=616711b0-1e00-0000-396c-a9c2f5140000 pid=5365 execve guuid=413f7db0-1e00-0000-396c-a9c2f6140000 pid=5366 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=413f7db0-1e00-0000-396c-a9c2f6140000 pid=5366 execve guuid=62efa8b1-1e00-0000-396c-a9c2f7140000 pid=5367 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=62efa8b1-1e00-0000-396c-a9c2f7140000 pid=5367 execve guuid=a1c9f0b1-1e00-0000-396c-a9c2f8140000 pid=5368 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=a1c9f0b1-1e00-0000-396c-a9c2f8140000 pid=5368 clone guuid=614704b2-1e00-0000-396c-a9c2f9140000 pid=5369 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=614704b2-1e00-0000-396c-a9c2f9140000 pid=5369 execve guuid=221d41b2-1e00-0000-396c-a9c2fa140000 pid=5370 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=221d41b2-1e00-0000-396c-a9c2fa140000 pid=5370 execve guuid=fa8f93b4-1e00-0000-396c-a9c2fb140000 pid=5371 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=fa8f93b4-1e00-0000-396c-a9c2fb140000 pid=5371 execve guuid=ee5303b5-1e00-0000-396c-a9c2fc140000 pid=5372 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=ee5303b5-1e00-0000-396c-a9c2fc140000 pid=5372 clone guuid=bc5d12b5-1e00-0000-396c-a9c2fd140000 pid=5373 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=bc5d12b5-1e00-0000-396c-a9c2fd140000 pid=5373 execve guuid=0a5a7eb5-1e00-0000-396c-a9c2fe140000 pid=5374 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=0a5a7eb5-1e00-0000-396c-a9c2fe140000 pid=5374 execve guuid=2162d0b5-1e00-0000-396c-a9c2ff140000 pid=5375 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2162d0b5-1e00-0000-396c-a9c2ff140000 pid=5375 execve guuid=a9b134b7-1e00-0000-396c-a9c200150000 pid=5376 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=a9b134b7-1e00-0000-396c-a9c200150000 pid=5376 execve guuid=c14da0b7-1e00-0000-396c-a9c201150000 pid=5377 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c14da0b7-1e00-0000-396c-a9c201150000 pid=5377 clone guuid=283fb7b7-1e00-0000-396c-a9c202150000 pid=5378 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=283fb7b7-1e00-0000-396c-a9c202150000 pid=5378 execve guuid=270232b8-1e00-0000-396c-a9c203150000 pid=5379 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=270232b8-1e00-0000-396c-a9c203150000 pid=5379 execve guuid=7e04f6ba-1e00-0000-396c-a9c204150000 pid=5380 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7e04f6ba-1e00-0000-396c-a9c204150000 pid=5380 execve guuid=d5746dbb-1e00-0000-396c-a9c205150000 pid=5381 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d5746dbb-1e00-0000-396c-a9c205150000 pid=5381 clone guuid=b6b983bb-1e00-0000-396c-a9c206150000 pid=5382 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=b6b983bb-1e00-0000-396c-a9c206150000 pid=5382 execve guuid=7cfdfbbb-1e00-0000-396c-a9c207150000 pid=5383 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=7cfdfbbb-1e00-0000-396c-a9c207150000 pid=5383 execve guuid=c8c054bc-1e00-0000-396c-a9c208150000 pid=5384 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c8c054bc-1e00-0000-396c-a9c208150000 pid=5384 execve guuid=1454cdbd-1e00-0000-396c-a9c209150000 pid=5385 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=1454cdbd-1e00-0000-396c-a9c209150000 pid=5385 execve guuid=a9651ebe-1e00-0000-396c-a9c20a150000 pid=5386 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=a9651ebe-1e00-0000-396c-a9c20a150000 pid=5386 clone guuid=4c7131be-1e00-0000-396c-a9c20b150000 pid=5387 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=4c7131be-1e00-0000-396c-a9c20b150000 pid=5387 execve guuid=88d07ebe-1e00-0000-396c-a9c20c150000 pid=5388 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=88d07ebe-1e00-0000-396c-a9c20c150000 pid=5388 execve guuid=ade1ebc0-1e00-0000-396c-a9c20d150000 pid=5389 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=ade1ebc0-1e00-0000-396c-a9c20d150000 pid=5389 execve guuid=c50962c1-1e00-0000-396c-a9c20e150000 pid=5390 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=c50962c1-1e00-0000-396c-a9c20e150000 pid=5390 clone guuid=d9dd76c1-1e00-0000-396c-a9c20f150000 pid=5391 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d9dd76c1-1e00-0000-396c-a9c20f150000 pid=5391 execve guuid=3aa8ebc1-1e00-0000-396c-a9c210150000 pid=5392 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=3aa8ebc1-1e00-0000-396c-a9c210150000 pid=5392 execve guuid=6eef4bc2-1e00-0000-396c-a9c211150000 pid=5393 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=6eef4bc2-1e00-0000-396c-a9c211150000 pid=5393 execve guuid=f82ad2c3-1e00-0000-396c-a9c212150000 pid=5394 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=f82ad2c3-1e00-0000-396c-a9c212150000 pid=5394 execve guuid=97ca27c4-1e00-0000-396c-a9c213150000 pid=5395 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=97ca27c4-1e00-0000-396c-a9c213150000 pid=5395 clone guuid=39ae42c4-1e00-0000-396c-a9c214150000 pid=5396 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=39ae42c4-1e00-0000-396c-a9c214150000 pid=5396 execve guuid=ea33afc4-1e00-0000-396c-a9c215150000 pid=5397 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=ea33afc4-1e00-0000-396c-a9c215150000 pid=5397 execve guuid=26dbb8c6-1e00-0000-396c-a9c216150000 pid=5398 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=26dbb8c6-1e00-0000-396c-a9c216150000 pid=5398 execve guuid=fde529c7-1e00-0000-396c-a9c217150000 pid=5399 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=fde529c7-1e00-0000-396c-a9c217150000 pid=5399 clone guuid=d1b13dc7-1e00-0000-396c-a9c218150000 pid=5400 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=d1b13dc7-1e00-0000-396c-a9c218150000 pid=5400 execve guuid=f63fb1c7-1e00-0000-396c-a9c219150000 pid=5401 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=f63fb1c7-1e00-0000-396c-a9c219150000 pid=5401 execve guuid=b4bd01c8-1e00-0000-396c-a9c21a150000 pid=5402 /usr/bin/wget net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=b4bd01c8-1e00-0000-396c-a9c21a150000 pid=5402 execve guuid=813282c9-1e00-0000-396c-a9c21b150000 pid=5403 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=813282c9-1e00-0000-396c-a9c21b150000 pid=5403 execve guuid=34a6fec9-1e00-0000-396c-a9c21c150000 pid=5404 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=34a6fec9-1e00-0000-396c-a9c21c150000 pid=5404 clone guuid=bd461bca-1e00-0000-396c-a9c21d150000 pid=5405 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=bd461bca-1e00-0000-396c-a9c21d150000 pid=5405 execve guuid=1c4491ca-1e00-0000-396c-a9c21e150000 pid=5406 /usr/bin/curl net guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=1c4491ca-1e00-0000-396c-a9c21e150000 pid=5406 execve guuid=2a0c2dcd-1e00-0000-396c-a9c21f150000 pid=5407 /usr/bin/chmod guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=2a0c2dcd-1e00-0000-396c-a9c21f150000 pid=5407 execve guuid=897699cd-1e00-0000-396c-a9c220150000 pid=5408 /usr/bin/dash guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=897699cd-1e00-0000-396c-a9c220150000 pid=5408 clone guuid=8308a8cd-1e00-0000-396c-a9c221150000 pid=5409 /usr/bin/rm guuid=e80bb706-1900-0000-396c-a9c209130000 pid=4873->guuid=8308a8cd-1e00-0000-396c-a9c221150000 pid=5409 execve 017ae759-64ed-575c-af4d-3774b3807a6e 103.77.241.135:80 guuid=c73c6707-1900-0000-396c-a9c20e130000 pid=4878->017ae759-64ed-575c-af4d-3774b3807a6e send: 132B guuid=2e65d836-1900-0000-396c-a9c28c130000 pid=5004->017ae759-64ed-575c-af4d-3774b3807a6e send: 81B guuid=e82f1492-1900-0000-396c-a9c20d140000 pid=5133->017ae759-64ed-575c-af4d-3774b3807a6e send: 133B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=65fee9bb-1900-0000-396c-a9c247140000 pid=5191->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192 /tmp/i686 dns net send-data zombie guuid=65fee9bb-1900-0000-396c-a9c247140000 pid=5191->guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192 clone guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 195B 7c3e25c9-e6e1-5506-9f6b-5662657a9ce5 103.77.241.135:38241 guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192->7c3e25c9-e6e1-5506-9f6b-5662657a9ce5 send: 9B guuid=d8f449bc-1900-0000-396c-a9c24b140000 pid=5195 /tmp/i686 guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192->guuid=d8f449bc-1900-0000-396c-a9c24b140000 pid=5195 clone guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197 /tmp/i686 net net-scan send-data guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192->guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197 clone guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199 /tmp/i686 net net-scan send-data guuid=fe7631bc-1900-0000-396c-a9c248140000 pid=5192->guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199 clone guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197|send-data send-data to 256 IP addresses review logs to see them all guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197->guuid=78eb50bc-1900-0000-396c-a9c24d140000 pid=5197|send-data send guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199|send-data send-data to 512 IP addresses review logs to see them all guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199->guuid=94c558bc-1900-0000-396c-a9c24f140000 pid=5199|send-data send guuid=5a3dc4bc-1900-0000-396c-a9c253140000 pid=5203->017ae759-64ed-575c-af4d-3774b3807a6e send: 82B guuid=194eb3eb-1900-0000-396c-a9c26e140000 pid=5230->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 4945e811-daa2-5999-bd89-4cdaa6badb43 0.0.0.0:8345 guuid=194eb3eb-1900-0000-396c-a9c26e140000 pid=5230->4945e811-daa2-5999-bd89-4cdaa6badb43 con guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245 /tmp/i686 dns net send-data zombie guuid=194eb3eb-1900-0000-396c-a9c26e140000 pid=5230->guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245 clone guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 195B guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245->7c3e25c9-e6e1-5506-9f6b-5662657a9ce5 send: 9B guuid=f7e5521c-1b00-0000-396c-a9c27f140000 pid=5247 /tmp/i686 guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245->guuid=f7e5521c-1b00-0000-396c-a9c27f140000 pid=5247 clone guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248 /tmp/i686 net net-scan send-data guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245->guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248 clone guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249 /tmp/i686 net net-scan send-data guuid=b48b401c-1b00-0000-396c-a9c27d140000 pid=5245->guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249 clone guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248|send-data send-data to 256 IP addresses review logs to see them all guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248->guuid=a9c6591c-1b00-0000-396c-a9c280140000 pid=5248|send-data send guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249|send-data send-data to 512 IP addresses review logs to see them all guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249->guuid=cf7d671c-1b00-0000-396c-a9c281140000 pid=5249|send-data send guuid=edfa2a2b-1b00-0000-396c-a9c283140000 pid=5251->017ae759-64ed-575c-af4d-3774b3807a6e send: 132B guuid=adc51b55-1b00-0000-396c-a9c285140000 pid=5253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=adc51b55-1b00-0000-396c-a9c285140000 pid=5253->4945e811-daa2-5999-bd89-4cdaa6badb43 con guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286 /tmp/x86 dns net send-data zombie guuid=adc51b55-1b00-0000-396c-a9c285140000 pid=5253->guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286 clone guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 195B guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286->7c3e25c9-e6e1-5506-9f6b-5662657a9ce5 send: 8B guuid=bebb5887-1c00-0000-396c-a9c2a8140000 pid=5288 /tmp/x86 guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286->guuid=bebb5887-1c00-0000-396c-a9c2a8140000 pid=5288 clone guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289 /tmp/x86 net net-scan send-data guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286->guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289 clone guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290 /tmp/x86 net net-scan send-data guuid=981e4487-1c00-0000-396c-a9c2a6140000 pid=5286->guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290 clone guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289|send-data send-data to 1024 IP addresses review logs to see them all guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289->guuid=4c8c6287-1c00-0000-396c-a9c2a9140000 pid=5289|send-data send guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290|send-data send-data to 2048 IP addresses review logs to see them all guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290->guuid=b2cc6a87-1c00-0000-396c-a9c2aa140000 pid=5290|send-data send guuid=d5998f87-1c00-0000-396c-a9c2ab140000 pid=5291->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=2a848f8b-1c00-0000-396c-a9c2b0140000 pid=5296->017ae759-64ed-575c-af4d-3774b3807a6e send: 132B guuid=00808fc1-1c00-0000-396c-a9c2b5140000 pid=5301->017ae759-64ed-575c-af4d-3774b3807a6e send: 81B guuid=02ddaafa-1c00-0000-396c-a9c2bb140000 pid=5307->017ae759-64ed-575c-af4d-3774b3807a6e send: 133B guuid=866c3832-1d00-0000-396c-a9c2c0140000 pid=5312->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=13e99d37-1d00-0000-396c-a9c2c5140000 pid=5317->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=2a401f3a-1d00-0000-396c-a9c2c9140000 pid=5321->017ae759-64ed-575c-af4d-3774b3807a6e send: 82B guuid=08a54f70-1d00-0000-396c-a9c2cb140000 pid=5323->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=08a54f70-1d00-0000-396c-a9c2cb140000 pid=5323->4945e811-daa2-5999-bd89-4cdaa6badb43 con guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324 /tmp/i486 dns net send-data zombie guuid=08a54f70-1d00-0000-396c-a9c2cb140000 pid=5323->guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324 clone guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 190B guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324->7c3e25c9-e6e1-5506-9f6b-5662657a9ce5 send: 11B guuid=2c602f9c-1e00-0000-396c-a9c2ce140000 pid=5326 /tmp/i486 guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324->guuid=2c602f9c-1e00-0000-396c-a9c2ce140000 pid=5326 clone guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327 /tmp/i486 net net-scan send-data guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324->guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327 clone guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328 /tmp/i486 net net-scan send-data guuid=4ff9169c-1e00-0000-396c-a9c2cc140000 pid=5324->guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328 clone guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327|send-data send-data to 4097 IP addresses review logs to see them all guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327->guuid=6f7f3a9c-1e00-0000-396c-a9c2cf140000 pid=5327|send-data send guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328|send-data send-data to 4097 IP addresses review logs to see them all guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328->guuid=2ea9489c-1e00-0000-396c-a9c2d0140000 pid=5328|send-data send guuid=08ffb09d-1e00-0000-396c-a9c2d2140000 pid=5330->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=81a6c1a0-1e00-0000-396c-a9c2d6140000 pid=5334->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=a4ea1ba3-1e00-0000-396c-a9c2db140000 pid=5339->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=c62c8ea4-1e00-0000-396c-a9c2df140000 pid=5343->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=953ae9a6-1e00-0000-396c-a9c2e4140000 pid=5348->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=fb9f53a8-1e00-0000-396c-a9c2e8140000 pid=5352->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=b758d1aa-1e00-0000-396c-a9c2ed140000 pid=5357->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=261182ac-1e00-0000-396c-a9c2f1140000 pid=5361->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=413f7db0-1e00-0000-396c-a9c2f6140000 pid=5366->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=221d41b2-1e00-0000-396c-a9c2fa140000 pid=5370->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=2162d0b5-1e00-0000-396c-a9c2ff140000 pid=5375->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=270232b8-1e00-0000-396c-a9c203150000 pid=5379->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=c8c054bc-1e00-0000-396c-a9c208150000 pid=5384->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=88d07ebe-1e00-0000-396c-a9c20c150000 pid=5388->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=6eef4bc2-1e00-0000-396c-a9c211150000 pid=5393->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=ea33afc4-1e00-0000-396c-a9c215150000 pid=5397->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=b4bd01c8-1e00-0000-396c-a9c21a150000 pid=5402->017ae759-64ed-575c-af4d-3774b3807a6e con guuid=1c4491ca-1e00-0000-396c-a9c21e150000 pid=5406->017ae759-64ed-575c-af4d-3774b3807a6e con
Threat name:
Script-Shell.Trojan.Multiverze
Status:
Malicious
First seen:
2025-12-18 18:47:13 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d0e164aca64197432f7bd969a66d5395498278368c14e414bd2c706d6b750d74

(this sample)

  
Delivery method
Distributed via web download

Comments