MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d1cc2ab9ba5338df6b6eb6d7010eb64ee9d642fdb6a6281fbb21f16a29ae57c7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d1cc2ab9ba5338df6b6eb6d7010eb64ee9d642fdb6a6281fbb21f16a29ae57c7
SHA3-384 hash: b67c45557440f22dff51d5cf38edb2f2454dc84cd6cd67b4b84244a51fc9dc7e32584fb9fd9f14f11089c7f9fbf2d9de
SHA1 hash: f22f8e13223709a5da57a02d7d1b78bb5d00c62b
MD5 hash: 07a3341977ce10b7f1de432db2a9e627
humanhash: magnesium-moon-oregon-black
File name:giga.sh
Download: download sample
Signature Mirai
File size:2'584 bytes
First seen:2025-08-03 05:48:16 UTC
Last seen:2025-08-04 04:00:31 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Iv3cA+AWQ/cReN/cpkJ/cSq/cPa/c2+/cpcpad/cAW/ciB8/cUW/ceG9eGjG/cMG:SXd1oTOgga5ELAEcLipNt2t
TLSH T1E051958807A6827CBEE66E3775E6C1143A8D909D67C1DFE690F938F0584CD04E582E93
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://196.251.115.36/HBTs/top1miku.arc22a0259442cc186e532dc5869fb4f71f759cccfb2457c815d25cc86a0e1dfe74 Miraielf mirai opendir ua-wget
http://196.251.115.36/HBTs/.ksysda999f47eecd7e38895349eb39c6d2350815b5de5dc06629cd3008ab712b95a49 Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.dbusd4fca520cba6b303a00db04c5525f9ebcd91027396a8daea21428623d9c000cd9 Miraielf mirai ua-wget
http://196.251.115.36/HBTs/top1miku.i686d35606a53e34a64f61406a84c406478ebeab1759e43c7b9d8821bf7b707ae2ac Gafgytelf gafgyt geofenced opendir ua-wget USA
http://196.251.115.36/HBTs/.udevmonebf5b2fe63545dd6486a8424d3660e89fec0f5b4d9f5697cf639c71a30e5084f Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.upstart5f346db94dd74ca9f5b9bbef9a3acede4ff545868d9302ce9e9f6afadd174c3e Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.netd3fe3f07475a7f97dbd70d217568915acf9107cf6ac1225758d3068dcca3b894d Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.syncd2e03f8c53cfdc53d28de4014c6d1bf599f6db13e805ddf40ec63fc2728d99615 Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.irqbal2cc247d74f81b12e13cfee4617575ac1e0ab5dca352947af77072916b3f91532 Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.rsysl739aef07d54c89858d617dcfaa25a44ea5d28f75efab5c14f884d3b89c24181b Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.modprobea4c5d10e0484cc0b3005ba65e1499780acb68a18b476f846bc8fce1d318f07bf Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.systemd-jdn/an/aelf ua-wget
http://196.251.115.36/HBTs/.kthreadd188e8c19cfc165712b2e5d83a4a79eb6c0f68fe0a03d0811cd2972da755be0ed Miraielf mirai ua-wget
http://196.251.115.36/HBTs/.klogda2d1334928d5ae1368924865254295e14290e36a88dc01c309ae66c04b1ab468 Miraielf mirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
29
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=d368b5ba-1700-0000-eb29-8902a10a0000 pid=2721 /usr/bin/sudo guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727 /tmp/sample.bin guuid=d368b5ba-1700-0000-eb29-8902a10a0000 pid=2721->guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727 execve guuid=56ccf8be-1700-0000-eb29-8902ab0a0000 pid=2731 /usr/bin/cp guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=56ccf8be-1700-0000-eb29-8902ab0a0000 pid=2731 execve guuid=783614c5-1700-0000-eb29-8902b90a0000 pid=2745 /usr/bin/wget net send-data guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=783614c5-1700-0000-eb29-8902b90a0000 pid=2745 execve guuid=e7c49aca-1700-0000-eb29-8902bd0a0000 pid=2749 /usr/bin/curl net send-data write-file guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=e7c49aca-1700-0000-eb29-8902bd0a0000 pid=2749 execve guuid=497f31d3-1700-0000-eb29-8902cd0a0000 pid=2765 /usr/bin/cat guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=497f31d3-1700-0000-eb29-8902cd0a0000 pid=2765 execve guuid=bd858bd3-1700-0000-eb29-8902cf0a0000 pid=2767 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=bd858bd3-1700-0000-eb29-8902cf0a0000 pid=2767 execve guuid=885ad4d3-1700-0000-eb29-8902d10a0000 pid=2769 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=885ad4d3-1700-0000-eb29-8902d10a0000 pid=2769 clone guuid=8a7926d4-1700-0000-eb29-8902d30a0000 pid=2771 /usr/bin/wget net send-data write-file guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=8a7926d4-1700-0000-eb29-8902d30a0000 pid=2771 execve guuid=3fd431d9-1700-0000-eb29-8902db0a0000 pid=2779 /usr/bin/curl net send-data write-file guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=3fd431d9-1700-0000-eb29-8902db0a0000 pid=2779 execve guuid=3d2888de-1700-0000-eb29-8902ea0a0000 pid=2794 /usr/bin/cat guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=3d2888de-1700-0000-eb29-8902ea0a0000 pid=2794 execve guuid=59c131df-1700-0000-eb29-8902eb0a0000 pid=2795 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=59c131df-1700-0000-eb29-8902eb0a0000 pid=2795 execve guuid=82cc70df-1700-0000-eb29-8902ec0a0000 pid=2796 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=82cc70df-1700-0000-eb29-8902ec0a0000 pid=2796 clone guuid=b134eae0-1700-0000-eb29-8902ee0a0000 pid=2798 /usr/bin/wget net send-data write-file guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=b134eae0-1700-0000-eb29-8902ee0a0000 pid=2798 execve guuid=f7924ae6-1700-0000-eb29-8902f00a0000 pid=2800 /usr/bin/curl net send-data write-file guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=f7924ae6-1700-0000-eb29-8902f00a0000 pid=2800 execve guuid=339b31ee-1700-0000-eb29-8902010b0000 pid=2817 /usr/bin/cat guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=339b31ee-1700-0000-eb29-8902010b0000 pid=2817 execve guuid=6898deee-1700-0000-eb29-8902020b0000 pid=2818 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=6898deee-1700-0000-eb29-8902020b0000 pid=2818 execve guuid=fb1262ef-1700-0000-eb29-8902030b0000 pid=2819 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=fb1262ef-1700-0000-eb29-8902030b0000 pid=2819 execve guuid=e1949cef-1700-0000-eb29-8902070b0000 pid=2823 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=e1949cef-1700-0000-eb29-8902070b0000 pid=2823 execve guuid=c88eb5f0-1700-0000-eb29-89020f0b0000 pid=2831 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=c88eb5f0-1700-0000-eb29-89020f0b0000 pid=2831 execve guuid=47894ff1-1700-0000-eb29-8902120b0000 pid=2834 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=47894ff1-1700-0000-eb29-8902120b0000 pid=2834 clone guuid=61cc6bf1-1700-0000-eb29-8902130b0000 pid=2835 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=61cc6bf1-1700-0000-eb29-8902130b0000 pid=2835 execve guuid=cfe6acf1-1700-0000-eb29-8902140b0000 pid=2836 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=cfe6acf1-1700-0000-eb29-8902140b0000 pid=2836 execve guuid=5a33d1f1-1700-0000-eb29-8902170b0000 pid=2839 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=5a33d1f1-1700-0000-eb29-8902170b0000 pid=2839 execve guuid=f24b2bf2-1700-0000-eb29-8902190b0000 pid=2841 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=f24b2bf2-1700-0000-eb29-8902190b0000 pid=2841 execve guuid=ac97caf2-1700-0000-eb29-89021c0b0000 pid=2844 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=ac97caf2-1700-0000-eb29-89021c0b0000 pid=2844 clone guuid=9e8648f3-1700-0000-eb29-89021f0b0000 pid=2847 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=9e8648f3-1700-0000-eb29-89021f0b0000 pid=2847 execve guuid=fcc1e9f4-1700-0000-eb29-8902260b0000 pid=2854 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=fcc1e9f4-1700-0000-eb29-8902260b0000 pid=2854 execve guuid=9f2e45f5-1700-0000-eb29-8902290b0000 pid=2857 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=9f2e45f5-1700-0000-eb29-8902290b0000 pid=2857 execve guuid=020a40f7-1700-0000-eb29-89022c0b0000 pid=2860 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=020a40f7-1700-0000-eb29-89022c0b0000 pid=2860 execve guuid=bf7da7f7-1700-0000-eb29-89022e0b0000 pid=2862 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=bf7da7f7-1700-0000-eb29-89022e0b0000 pid=2862 clone guuid=f49b15f8-1700-0000-eb29-8902310b0000 pid=2865 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=f49b15f8-1700-0000-eb29-8902310b0000 pid=2865 execve guuid=2a0e10f9-1700-0000-eb29-8902360b0000 pid=2870 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=2a0e10f9-1700-0000-eb29-8902360b0000 pid=2870 execve guuid=770173fa-1700-0000-eb29-89023d0b0000 pid=2877 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=770173fa-1700-0000-eb29-89023d0b0000 pid=2877 execve guuid=df6bccfb-1700-0000-eb29-8902420b0000 pid=2882 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=df6bccfb-1700-0000-eb29-8902420b0000 pid=2882 execve guuid=fb7804fc-1700-0000-eb29-8902440b0000 pid=2884 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=fb7804fc-1700-0000-eb29-8902440b0000 pid=2884 clone guuid=233023fc-1700-0000-eb29-8902450b0000 pid=2885 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=233023fc-1700-0000-eb29-8902450b0000 pid=2885 execve guuid=02ae61fc-1700-0000-eb29-8902470b0000 pid=2887 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=02ae61fc-1700-0000-eb29-8902470b0000 pid=2887 execve guuid=08997afd-1700-0000-eb29-89024e0b0000 pid=2894 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=08997afd-1700-0000-eb29-89024e0b0000 pid=2894 execve guuid=fb0222fe-1700-0000-eb29-8902520b0000 pid=2898 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=fb0222fe-1700-0000-eb29-8902520b0000 pid=2898 execve guuid=887260ff-1700-0000-eb29-8902570b0000 pid=2903 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=887260ff-1700-0000-eb29-8902570b0000 pid=2903 clone guuid=c4878bff-1700-0000-eb29-8902580b0000 pid=2904 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=c4878bff-1700-0000-eb29-8902580b0000 pid=2904 execve guuid=17f42601-1800-0000-eb29-89025d0b0000 pid=2909 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=17f42601-1800-0000-eb29-89025d0b0000 pid=2909 execve guuid=ce71ab01-1800-0000-eb29-8902610b0000 pid=2913 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=ce71ab01-1800-0000-eb29-8902610b0000 pid=2913 execve guuid=e54f4302-1800-0000-eb29-8902630b0000 pid=2915 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=e54f4302-1800-0000-eb29-8902630b0000 pid=2915 execve guuid=1a1da802-1800-0000-eb29-8902650b0000 pid=2917 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=1a1da802-1800-0000-eb29-8902650b0000 pid=2917 clone guuid=731df002-1800-0000-eb29-8902670b0000 pid=2919 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=731df002-1800-0000-eb29-8902670b0000 pid=2919 execve guuid=3b09f303-1800-0000-eb29-8902690b0000 pid=2921 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=3b09f303-1800-0000-eb29-8902690b0000 pid=2921 execve guuid=9d601f04-1800-0000-eb29-89026c0b0000 pid=2924 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=9d601f04-1800-0000-eb29-89026c0b0000 pid=2924 execve guuid=026aac04-1800-0000-eb29-8902700b0000 pid=2928 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=026aac04-1800-0000-eb29-8902700b0000 pid=2928 execve guuid=7f916506-1800-0000-eb29-89027a0b0000 pid=2938 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=7f916506-1800-0000-eb29-89027a0b0000 pid=2938 clone guuid=7a56b006-1800-0000-eb29-89027b0b0000 pid=2939 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=7a56b006-1800-0000-eb29-89027b0b0000 pid=2939 execve guuid=1e05ed06-1800-0000-eb29-89027c0b0000 pid=2940 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=1e05ed06-1800-0000-eb29-89027c0b0000 pid=2940 execve guuid=c3261007-1800-0000-eb29-8902800b0000 pid=2944 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=c3261007-1800-0000-eb29-8902800b0000 pid=2944 execve guuid=9e05fa07-1800-0000-eb29-8902830b0000 pid=2947 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=9e05fa07-1800-0000-eb29-8902830b0000 pid=2947 execve guuid=aeb06c09-1800-0000-eb29-8902850b0000 pid=2949 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=aeb06c09-1800-0000-eb29-8902850b0000 pid=2949 clone guuid=6a429409-1800-0000-eb29-8902860b0000 pid=2950 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=6a429409-1800-0000-eb29-8902860b0000 pid=2950 execve guuid=013fd909-1800-0000-eb29-8902880b0000 pid=2952 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=013fd909-1800-0000-eb29-8902880b0000 pid=2952 execve guuid=b7b0f709-1800-0000-eb29-89028b0b0000 pid=2955 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=b7b0f709-1800-0000-eb29-89028b0b0000 pid=2955 execve guuid=bbb7350a-1800-0000-eb29-89028e0b0000 pid=2958 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=bbb7350a-1800-0000-eb29-89028e0b0000 pid=2958 execve guuid=33a92c0b-1800-0000-eb29-8902900b0000 pid=2960 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=33a92c0b-1800-0000-eb29-8902900b0000 pid=2960 clone guuid=101f900b-1800-0000-eb29-8902920b0000 pid=2962 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=101f900b-1800-0000-eb29-8902920b0000 pid=2962 execve guuid=e48f1b0c-1800-0000-eb29-8902930b0000 pid=2963 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=e48f1b0c-1800-0000-eb29-8902930b0000 pid=2963 execve guuid=40c91f0d-1800-0000-eb29-8902980b0000 pid=2968 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=40c91f0d-1800-0000-eb29-8902980b0000 pid=2968 execve guuid=403cf40e-1800-0000-eb29-89029a0b0000 pid=2970 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=403cf40e-1800-0000-eb29-89029a0b0000 pid=2970 execve guuid=8d661610-1800-0000-eb29-89029e0b0000 pid=2974 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=8d661610-1800-0000-eb29-89029e0b0000 pid=2974 clone guuid=8c087710-1800-0000-eb29-89029f0b0000 pid=2975 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=8c087710-1800-0000-eb29-89029f0b0000 pid=2975 execve guuid=32130811-1800-0000-eb29-8902a10b0000 pid=2977 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=32130811-1800-0000-eb29-8902a10b0000 pid=2977 execve guuid=4dffb212-1800-0000-eb29-8902a70b0000 pid=2983 /usr/bin/wget guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=4dffb212-1800-0000-eb29-8902a70b0000 pid=2983 execve guuid=fbe9d414-1800-0000-eb29-8902ab0b0000 pid=2987 /usr/bin/curl guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=fbe9d414-1800-0000-eb29-8902ab0b0000 pid=2987 execve guuid=3b0fca15-1800-0000-eb29-8902ac0b0000 pid=2988 /usr/bin/bash guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=3b0fca15-1800-0000-eb29-8902ac0b0000 pid=2988 clone guuid=b159f415-1800-0000-eb29-8902ad0b0000 pid=2989 /usr/bin/chmod guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=b159f415-1800-0000-eb29-8902ad0b0000 pid=2989 execve guuid=4e778316-1800-0000-eb29-8902af0b0000 pid=2991 /tmp/x net guuid=6bd9acbd-1700-0000-eb29-8902a70a0000 pid=2727->guuid=4e778316-1800-0000-eb29-8902af0b0000 pid=2991 execve 7c78b54a-8c85-5adc-a27d-cc08a14544fc 196.251.115.36:80 guuid=783614c5-1700-0000-eb29-8902b90a0000 pid=2745->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 146B guuid=e7c49aca-1700-0000-eb29-8902bd0a0000 pid=2749->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 95B guuid=8a7926d4-1700-0000-eb29-8902d30a0000 pid=2771->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 140B guuid=3fd431d9-1700-0000-eb29-8902db0a0000 pid=2779->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 89B guuid=b134eae0-1700-0000-eb29-8902ee0a0000 pid=2798->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 140B guuid=f7924ae6-1700-0000-eb29-8902f00a0000 pid=2800->7c78b54a-8c85-5adc-a27d-cc08a14544fc send: 89B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=fb1262ef-1700-0000-eb29-8902030b0000 pid=2819->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ea057fef-1700-0000-eb29-8902040b0000 pid=2820 /tmp/x zombie guuid=fb1262ef-1700-0000-eb29-8902030b0000 pid=2819->guuid=ea057fef-1700-0000-eb29-8902040b0000 pid=2820 clone guuid=79d586ef-1700-0000-eb29-8902050b0000 pid=2821 /tmp/x zombie guuid=fb1262ef-1700-0000-eb29-8902030b0000 pid=2819->guuid=79d586ef-1700-0000-eb29-8902050b0000 pid=2821 clone guuid=15c195ef-1700-0000-eb29-8902060b0000 pid=2822 /tmp/x write-config zombie guuid=79d586ef-1700-0000-eb29-8902050b0000 pid=2821->guuid=15c195ef-1700-0000-eb29-8902060b0000 pid=2822 clone guuid=655af6ef-1700-0000-eb29-89020a0b0000 pid=2826 /usr/bin/dash guuid=15c195ef-1700-0000-eb29-8902060b0000 pid=2822->guuid=655af6ef-1700-0000-eb29-89020a0b0000 pid=2826 execve guuid=e8e80bf1-1700-0000-eb29-8902110b0000 pid=2833 /tmp/x dns net send-data guuid=15c195ef-1700-0000-eb29-8902060b0000 pid=2822->guuid=e8e80bf1-1700-0000-eb29-8902110b0000 pid=2833 clone guuid=075a26f0-1700-0000-eb29-89020b0b0000 pid=2827 /usr/bin/cp guuid=655af6ef-1700-0000-eb29-89020a0b0000 pid=2826->guuid=075a26f0-1700-0000-eb29-89020b0b0000 pid=2827 execve guuid=e8e80bf1-1700-0000-eb29-8902110b0000 pid=2833->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7296B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=e8e80bf1-1700-0000-eb29-8902110b0000 pid=2833->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1683B f37c51d7-2bb3-53a8-b958-5a758a36d238 top1miku.duckdns.org:0 guuid=e8e80bf1-1700-0000-eb29-8902110b0000 pid=2833->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=cfe6acf1-1700-0000-eb29-8902140b0000 pid=2836->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d45abdf1-1700-0000-eb29-8902150b0000 pid=2837 /tmp/x zombie guuid=cfe6acf1-1700-0000-eb29-8902140b0000 pid=2836->guuid=d45abdf1-1700-0000-eb29-8902150b0000 pid=2837 clone guuid=4fc5c7f1-1700-0000-eb29-8902160b0000 pid=2838 /tmp/x zombie guuid=cfe6acf1-1700-0000-eb29-8902140b0000 pid=2836->guuid=4fc5c7f1-1700-0000-eb29-8902160b0000 pid=2838 clone guuid=ccc4d4f1-1700-0000-eb29-8902180b0000 pid=2840 /tmp/x write-config zombie guuid=4fc5c7f1-1700-0000-eb29-8902160b0000 pid=2838->guuid=ccc4d4f1-1700-0000-eb29-8902180b0000 pid=2840 clone guuid=0ec0a0f2-1700-0000-eb29-89021b0b0000 pid=2843 /usr/bin/dash guuid=ccc4d4f1-1700-0000-eb29-8902180b0000 pid=2840->guuid=0ec0a0f2-1700-0000-eb29-89021b0b0000 pid=2843 execve guuid=44d582f4-1700-0000-eb29-8902230b0000 pid=2851 /tmp/x dns net send-data guuid=ccc4d4f1-1700-0000-eb29-8902180b0000 pid=2840->guuid=44d582f4-1700-0000-eb29-8902230b0000 pid=2851 clone guuid=7f4ef5f2-1700-0000-eb29-89021d0b0000 pid=2845 /usr/bin/cp guuid=0ec0a0f2-1700-0000-eb29-89021b0b0000 pid=2843->guuid=7f4ef5f2-1700-0000-eb29-89021d0b0000 pid=2845 execve guuid=44d582f4-1700-0000-eb29-8902230b0000 pid=2851->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 6802B guuid=44d582f4-1700-0000-eb29-8902230b0000 pid=2851->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1557B guuid=44d582f4-1700-0000-eb29-8902230b0000 pid=2851->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B guuid=fcc1e9f4-1700-0000-eb29-8902260b0000 pid=2854->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1a912ff5-1700-0000-eb29-8902270b0000 pid=2855 /tmp/x zombie guuid=fcc1e9f4-1700-0000-eb29-8902260b0000 pid=2854->guuid=1a912ff5-1700-0000-eb29-8902270b0000 pid=2855 clone guuid=c88d33f5-1700-0000-eb29-8902280b0000 pid=2856 /tmp/x zombie guuid=fcc1e9f4-1700-0000-eb29-8902260b0000 pid=2854->guuid=c88d33f5-1700-0000-eb29-8902280b0000 pid=2856 clone guuid=0553d1f5-1700-0000-eb29-89022a0b0000 pid=2858 /tmp/x write-config zombie guuid=c88d33f5-1700-0000-eb29-8902280b0000 pid=2856->guuid=0553d1f5-1700-0000-eb29-89022a0b0000 pid=2858 clone guuid=5f8b57f7-1700-0000-eb29-89022d0b0000 pid=2861 /usr/bin/dash guuid=0553d1f5-1700-0000-eb29-89022a0b0000 pid=2858->guuid=5f8b57f7-1700-0000-eb29-89022d0b0000 pid=2861 execve guuid=4b8b3ff9-1700-0000-eb29-8902380b0000 pid=2872 /tmp/x dns net send-data guuid=0553d1f5-1700-0000-eb29-89022a0b0000 pid=2858->guuid=4b8b3ff9-1700-0000-eb29-8902380b0000 pid=2872 clone guuid=2a1105f8-1700-0000-eb29-8902300b0000 pid=2864 /usr/bin/cp guuid=5f8b57f7-1700-0000-eb29-89022d0b0000 pid=2861->guuid=2a1105f8-1700-0000-eb29-8902300b0000 pid=2864 execve guuid=2a0e10f9-1700-0000-eb29-8902360b0000 pid=2870->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=7d4060fa-1700-0000-eb29-89023a0b0000 pid=2874 /tmp/x zombie guuid=2a0e10f9-1700-0000-eb29-8902360b0000 pid=2870->guuid=7d4060fa-1700-0000-eb29-89023a0b0000 pid=2874 clone guuid=192865fa-1700-0000-eb29-89023c0b0000 pid=2876 /tmp/x zombie guuid=2a0e10f9-1700-0000-eb29-8902360b0000 pid=2870->guuid=192865fa-1700-0000-eb29-89023c0b0000 pid=2876 clone guuid=4b8b3ff9-1700-0000-eb29-8902380b0000 pid=2872->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 6954B guuid=4b8b3ff9-1700-0000-eb29-8902380b0000 pid=2872->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1602B guuid=4b8b3ff9-1700-0000-eb29-8902380b0000 pid=2872->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=285f54fb-1700-0000-eb29-8902400b0000 pid=2880 /tmp/x write-config zombie guuid=192865fa-1700-0000-eb29-89023c0b0000 pid=2876->guuid=285f54fb-1700-0000-eb29-8902400b0000 pid=2880 clone guuid=dbeff5fb-1700-0000-eb29-8902430b0000 pid=2883 /usr/bin/dash guuid=285f54fb-1700-0000-eb29-8902400b0000 pid=2880->guuid=dbeff5fb-1700-0000-eb29-8902430b0000 pid=2883 execve guuid=ebd7d8fc-1700-0000-eb29-89024c0b0000 pid=2892 /tmp/x dns net send-data guuid=285f54fb-1700-0000-eb29-8902400b0000 pid=2880->guuid=ebd7d8fc-1700-0000-eb29-89024c0b0000 pid=2892 clone guuid=175733fc-1700-0000-eb29-8902460b0000 pid=2886 /usr/bin/cp guuid=dbeff5fb-1700-0000-eb29-8902430b0000 pid=2883->guuid=175733fc-1700-0000-eb29-8902460b0000 pid=2886 execve guuid=02ae61fc-1700-0000-eb29-8902470b0000 pid=2887->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4d1a72fc-1700-0000-eb29-8902480b0000 pid=2888 /tmp/x zombie guuid=02ae61fc-1700-0000-eb29-8902470b0000 pid=2887->guuid=4d1a72fc-1700-0000-eb29-8902480b0000 pid=2888 clone guuid=cb57affc-1700-0000-eb29-89024b0b0000 pid=2891 /tmp/x zombie guuid=02ae61fc-1700-0000-eb29-8902470b0000 pid=2887->guuid=cb57affc-1700-0000-eb29-89024b0b0000 pid=2891 clone guuid=e065eafd-1700-0000-eb29-8902500b0000 pid=2896 /tmp/x write-config zombie guuid=cb57affc-1700-0000-eb29-89024b0b0000 pid=2891->guuid=e065eafd-1700-0000-eb29-8902500b0000 pid=2896 clone guuid=ebd7d8fc-1700-0000-eb29-89024c0b0000 pid=2892->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7790B guuid=ebd7d8fc-1700-0000-eb29-89024c0b0000 pid=2892->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1773B guuid=ebd7d8fc-1700-0000-eb29-89024c0b0000 pid=2892->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 45B guuid=dacb7ffe-1700-0000-eb29-8902540b0000 pid=2900 /usr/bin/dash guuid=e065eafd-1700-0000-eb29-8902500b0000 pid=2896->guuid=dacb7ffe-1700-0000-eb29-8902540b0000 pid=2900 execve guuid=16514200-1800-0000-eb29-89025b0b0000 pid=2907 /tmp/x dns net send-data guuid=e065eafd-1700-0000-eb29-8902500b0000 pid=2896->guuid=16514200-1800-0000-eb29-89025b0b0000 pid=2907 clone guuid=34cd1eff-1700-0000-eb29-8902560b0000 pid=2902 /usr/bin/cp guuid=dacb7ffe-1700-0000-eb29-8902540b0000 pid=2900->guuid=34cd1eff-1700-0000-eb29-8902560b0000 pid=2902 execve guuid=16514200-1800-0000-eb29-89025b0b0000 pid=2907->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7790B guuid=16514200-1800-0000-eb29-89025b0b0000 pid=2907->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1818B guuid=17f42601-1800-0000-eb29-89025d0b0000 pid=2909->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1b7f9d01-1800-0000-eb29-89025f0b0000 pid=2911 /tmp/x zombie guuid=17f42601-1800-0000-eb29-89025d0b0000 pid=2909->guuid=1b7f9d01-1800-0000-eb29-89025f0b0000 pid=2911 clone guuid=ac78a101-1800-0000-eb29-8902600b0000 pid=2912 /tmp/x zombie guuid=17f42601-1800-0000-eb29-89025d0b0000 pid=2909->guuid=ac78a101-1800-0000-eb29-8902600b0000 pid=2912 clone guuid=780e8e02-1800-0000-eb29-8902640b0000 pid=2916 /tmp/x write-config zombie guuid=ac78a101-1800-0000-eb29-8902600b0000 pid=2912->guuid=780e8e02-1800-0000-eb29-8902640b0000 pid=2916 clone guuid=ea1ecc02-1800-0000-eb29-8902660b0000 pid=2918 /usr/bin/dash guuid=780e8e02-1800-0000-eb29-8902640b0000 pid=2916->guuid=ea1ecc02-1800-0000-eb29-8902660b0000 pid=2918 execve guuid=0e52e204-1800-0000-eb29-8902720b0000 pid=2930 /tmp/x dns net send-data guuid=780e8e02-1800-0000-eb29-8902640b0000 pid=2916->guuid=0e52e204-1800-0000-eb29-8902720b0000 pid=2930 clone guuid=f2799903-1800-0000-eb29-8902680b0000 pid=2920 /usr/bin/cp guuid=ea1ecc02-1800-0000-eb29-8902660b0000 pid=2918->guuid=f2799903-1800-0000-eb29-8902680b0000 pid=2920 execve guuid=3b09f303-1800-0000-eb29-8902690b0000 pid=2921->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=70d70a04-1800-0000-eb29-89026a0b0000 pid=2922 /tmp/x zombie guuid=3b09f303-1800-0000-eb29-8902690b0000 pid=2921->guuid=70d70a04-1800-0000-eb29-89026a0b0000 pid=2922 clone guuid=cc971004-1800-0000-eb29-89026b0b0000 pid=2923 /tmp/x zombie guuid=3b09f303-1800-0000-eb29-8902690b0000 pid=2921->guuid=cc971004-1800-0000-eb29-89026b0b0000 pid=2923 clone guuid=e7705e04-1800-0000-eb29-89026e0b0000 pid=2926 /tmp/x write-config zombie guuid=cc971004-1800-0000-eb29-89026b0b0000 pid=2923->guuid=e7705e04-1800-0000-eb29-89026e0b0000 pid=2926 clone guuid=a33a6805-1800-0000-eb29-8902750b0000 pid=2933 /usr/bin/dash guuid=e7705e04-1800-0000-eb29-89026e0b0000 pid=2926->guuid=a33a6805-1800-0000-eb29-8902750b0000 pid=2933 execve guuid=4abaac09-1800-0000-eb29-8902870b0000 pid=2951 /tmp/x dns net send-data guuid=e7705e04-1800-0000-eb29-89026e0b0000 pid=2926->guuid=4abaac09-1800-0000-eb29-8902870b0000 pid=2951 clone guuid=0e52e204-1800-0000-eb29-8902720b0000 pid=2930->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7790B guuid=0e52e204-1800-0000-eb29-8902720b0000 pid=2930->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1809B guuid=0e52e204-1800-0000-eb29-8902720b0000 pid=2930->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B guuid=3b5c2207-1800-0000-eb29-8902810b0000 pid=2945 /usr/bin/cp guuid=a33a6805-1800-0000-eb29-8902750b0000 pid=2933->guuid=3b5c2207-1800-0000-eb29-8902810b0000 pid=2945 execve guuid=1e05ed06-1800-0000-eb29-89027c0b0000 pid=2940->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e7c40207-1800-0000-eb29-89027d0b0000 pid=2941 /tmp/x zombie guuid=1e05ed06-1800-0000-eb29-89027c0b0000 pid=2940->guuid=e7c40207-1800-0000-eb29-89027d0b0000 pid=2941 clone guuid=9dee0507-1800-0000-eb29-89027e0b0000 pid=2942 /tmp/x zombie guuid=1e05ed06-1800-0000-eb29-89027c0b0000 pid=2940->guuid=9dee0507-1800-0000-eb29-89027e0b0000 pid=2942 clone guuid=28980c07-1800-0000-eb29-89027f0b0000 pid=2943 /tmp/x write-config zombie guuid=9dee0507-1800-0000-eb29-89027e0b0000 pid=2942->guuid=28980c07-1800-0000-eb29-89027f0b0000 pid=2943 clone guuid=91374407-1800-0000-eb29-8902820b0000 pid=2946 /usr/bin/dash guuid=28980c07-1800-0000-eb29-89027f0b0000 pid=2943->guuid=91374407-1800-0000-eb29-8902820b0000 pid=2946 execve guuid=1acf280a-1800-0000-eb29-89028d0b0000 pid=2957 /tmp/x dns net send-data guuid=28980c07-1800-0000-eb29-89027f0b0000 pid=2943->guuid=1acf280a-1800-0000-eb29-89028d0b0000 pid=2957 clone guuid=5fbf2508-1800-0000-eb29-8902840b0000 pid=2948 /usr/bin/cp guuid=91374407-1800-0000-eb29-8902820b0000 pid=2946->guuid=5fbf2508-1800-0000-eb29-8902840b0000 pid=2948 execve guuid=4abaac09-1800-0000-eb29-8902870b0000 pid=2951->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 8360B guuid=4abaac09-1800-0000-eb29-8902870b0000 pid=2951->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1953B guuid=4abaac09-1800-0000-eb29-8902870b0000 pid=2951->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=013fd909-1800-0000-eb29-8902880b0000 pid=2952->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c1dfe909-1800-0000-eb29-8902890b0000 pid=2953 /tmp/x zombie guuid=013fd909-1800-0000-eb29-8902880b0000 pid=2952->guuid=c1dfe909-1800-0000-eb29-8902890b0000 pid=2953 clone guuid=ac71ee09-1800-0000-eb29-89028a0b0000 pid=2954 /tmp/x zombie guuid=013fd909-1800-0000-eb29-8902880b0000 pid=2952->guuid=ac71ee09-1800-0000-eb29-89028a0b0000 pid=2954 clone guuid=0374140a-1800-0000-eb29-89028c0b0000 pid=2956 /tmp/x write-config zombie guuid=ac71ee09-1800-0000-eb29-89028a0b0000 pid=2954->guuid=0374140a-1800-0000-eb29-89028c0b0000 pid=2956 clone guuid=8bbeba0a-1800-0000-eb29-89028f0b0000 pid=2959 /usr/bin/dash guuid=0374140a-1800-0000-eb29-89028c0b0000 pid=2956->guuid=8bbeba0a-1800-0000-eb29-89028f0b0000 pid=2959 execve guuid=56870b10-1800-0000-eb29-89029d0b0000 pid=2973 /tmp/x dns net send-data guuid=0374140a-1800-0000-eb29-89028c0b0000 pid=2956->guuid=56870b10-1800-0000-eb29-89029d0b0000 pid=2973 clone guuid=1acf280a-1800-0000-eb29-89028d0b0000 pid=2957->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 8664B guuid=1acf280a-1800-0000-eb29-89028d0b0000 pid=2957->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 2025B guuid=1acf280a-1800-0000-eb29-89028d0b0000 pid=2957->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=e26c6f0b-1800-0000-eb29-8902910b0000 pid=2961 /usr/bin/cp guuid=8bbeba0a-1800-0000-eb29-89028f0b0000 pid=2959->guuid=e26c6f0b-1800-0000-eb29-8902910b0000 pid=2961 execve guuid=e48f1b0c-1800-0000-eb29-8902930b0000 pid=2963->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a896120d-1800-0000-eb29-8902960b0000 pid=2966 /tmp/x zombie guuid=e48f1b0c-1800-0000-eb29-8902930b0000 pid=2963->guuid=a896120d-1800-0000-eb29-8902960b0000 pid=2966 clone guuid=9f29170d-1800-0000-eb29-8902970b0000 pid=2967 /tmp/x zombie guuid=e48f1b0c-1800-0000-eb29-8902930b0000 pid=2963->guuid=9f29170d-1800-0000-eb29-8902970b0000 pid=2967 clone guuid=d708ec0d-1800-0000-eb29-8902990b0000 pid=2969 /tmp/x write-config zombie guuid=9f29170d-1800-0000-eb29-8902970b0000 pid=2967->guuid=d708ec0d-1800-0000-eb29-8902990b0000 pid=2969 clone guuid=409c050f-1800-0000-eb29-89029b0b0000 pid=2971 /usr/bin/dash guuid=d708ec0d-1800-0000-eb29-8902990b0000 pid=2969->guuid=409c050f-1800-0000-eb29-89029b0b0000 pid=2971 execve guuid=fc01f810-1800-0000-eb29-8902a00b0000 pid=2976 /tmp/x dns net send-data guuid=d708ec0d-1800-0000-eb29-8902990b0000 pid=2969->guuid=fc01f810-1800-0000-eb29-8902a00b0000 pid=2976 clone guuid=fb76610f-1800-0000-eb29-89029c0b0000 pid=2972 /usr/bin/cp guuid=409c050f-1800-0000-eb29-89029b0b0000 pid=2971->guuid=fb76610f-1800-0000-eb29-89029c0b0000 pid=2972 execve guuid=56870b10-1800-0000-eb29-89029d0b0000 pid=2973->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7486B guuid=56870b10-1800-0000-eb29-89029d0b0000 pid=2973->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1728B guuid=56870b10-1800-0000-eb29-89029d0b0000 pid=2973->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B guuid=fc01f810-1800-0000-eb29-8902a00b0000 pid=2976->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7752B guuid=fc01f810-1800-0000-eb29-8902a00b0000 pid=2976->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1791B guuid=fc01f810-1800-0000-eb29-8902a00b0000 pid=2976->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=32130811-1800-0000-eb29-8902a10b0000 pid=2977->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4fb05d12-1800-0000-eb29-8902a50b0000 pid=2981 /tmp/x zombie guuid=32130811-1800-0000-eb29-8902a10b0000 pid=2977->guuid=4fb05d12-1800-0000-eb29-8902a50b0000 pid=2981 clone guuid=7a356112-1800-0000-eb29-8902a60b0000 pid=2982 /tmp/x zombie guuid=32130811-1800-0000-eb29-8902a10b0000 pid=2977->guuid=7a356112-1800-0000-eb29-8902a60b0000 pid=2982 clone guuid=b67dc312-1800-0000-eb29-8902a80b0000 pid=2984 /tmp/x write-config zombie guuid=7a356112-1800-0000-eb29-8902a60b0000 pid=2982->guuid=b67dc312-1800-0000-eb29-8902a80b0000 pid=2984 clone guuid=33f48d13-1800-0000-eb29-8902a90b0000 pid=2985 /usr/bin/dash guuid=b67dc312-1800-0000-eb29-8902a80b0000 pid=2984->guuid=33f48d13-1800-0000-eb29-8902a90b0000 pid=2985 execve guuid=b7a67b16-1800-0000-eb29-8902ae0b0000 pid=2990 /tmp/x dns net send-data guuid=b67dc312-1800-0000-eb29-8902a80b0000 pid=2984->guuid=b7a67b16-1800-0000-eb29-8902ae0b0000 pid=2990 clone guuid=5218bf13-1800-0000-eb29-8902aa0b0000 pid=2986 /usr/bin/cp guuid=33f48d13-1800-0000-eb29-8902a90b0000 pid=2985->guuid=5218bf13-1800-0000-eb29-8902aa0b0000 pid=2986 execve guuid=b7a67b16-1800-0000-eb29-8902ae0b0000 pid=2990->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 7828B guuid=b7a67b16-1800-0000-eb29-8902ae0b0000 pid=2990->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1818B guuid=b7a67b16-1800-0000-eb29-8902ae0b0000 pid=2990->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=4e778316-1800-0000-eb29-8902af0b0000 pid=2991->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=b9895317-1800-0000-eb29-8902b00b0000 pid=2992 /tmp/x guuid=4e778316-1800-0000-eb29-8902af0b0000 pid=2991->guuid=b9895317-1800-0000-eb29-8902b00b0000 pid=2992 clone guuid=ae3c5717-1800-0000-eb29-8902b10b0000 pid=2993 /tmp/x zombie guuid=4e778316-1800-0000-eb29-8902af0b0000 pid=2991->guuid=ae3c5717-1800-0000-eb29-8902b10b0000 pid=2993 clone guuid=5709ab17-1800-0000-eb29-8902b20b0000 pid=2994 /tmp/x write-config zombie guuid=ae3c5717-1800-0000-eb29-8902b10b0000 pid=2993->guuid=5709ab17-1800-0000-eb29-8902b20b0000 pid=2994 clone guuid=e6394918-1800-0000-eb29-8902b30b0000 pid=2995 /usr/bin/dash guuid=5709ab17-1800-0000-eb29-8902b20b0000 pid=2994->guuid=e6394918-1800-0000-eb29-8902b30b0000 pid=2995 execve guuid=22fe0f1a-1800-0000-eb29-8902b50b0000 pid=2997 /tmp/x dns net send-data guuid=5709ab17-1800-0000-eb29-8902b20b0000 pid=2994->guuid=22fe0f1a-1800-0000-eb29-8902b50b0000 pid=2997 clone guuid=d7658f18-1800-0000-eb29-8902b40b0000 pid=2996 /usr/bin/cp guuid=e6394918-1800-0000-eb29-8902b30b0000 pid=2995->guuid=d7658f18-1800-0000-eb29-8902b40b0000 pid=2996 execve guuid=22fe0f1a-1800-0000-eb29-8902b50b0000 pid=2997->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 6992B guuid=22fe0f1a-1800-0000-eb29-8902b50b0000 pid=2997->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 1611B guuid=22fe0f1a-1800-0000-eb29-8902b50b0000 pid=2997->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B
Verdict:
Malicious
Threat:
HEUR:Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-03 05:49:09 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
top1miku.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh d1cc2ab9ba5338df6b6eb6d7010eb64ee9d642fdb6a6281fbb21f16a29ae57c7

(this sample)

  
Delivery method
Distributed via web download

Comments