MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e067f622e732b809876f95f19fc254d4c09cf281fdedc81492ec1f1af85cda2d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: e067f622e732b809876f95f19fc254d4c09cf281fdedc81492ec1f1af85cda2d
SHA3-384 hash: 53a9821343bcfd4b6a00b880e9dd2a6d079d0198c4c1ba3ab89d42d272e84bb4ae11b69100584a323cf207b46a7427cc
SHA1 hash: e2e185e60717fd4afbdd98a08b88435a1b92309b
MD5 hash: 926ab553ef08848db63511c764333a4c
humanhash: earth-fruit-twenty-cola
File name:giga.sh
Download: download sample
Signature Mirai
File size:2'556 bytes
First seen:2025-08-11 17:52:00 UTC
Last seen:2025-08-12 13:12:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 24:Iv3rFWQ/rN/XJ/q///A/YYad/2/98/W/9GqGjG/hdZ/2z/qdE:SzttyH8YYa5m9AGk9ihdtkL
TLSH T11251D8CC206583F02EA7C93775F64115788C909A26C5AEFAD5ED38E4484CF0675C8EF2
Magika shell
Reporter abuse_ch
Tags:mirai sh
URLMalware sample (SHA256 hash)SignatureTags
http://160.191.55.60/HBTs/top1miku.arcn/an/aopendir ua-wget
http://160.191.55.60/HBTs/.ksysda999f47eecd7e38895349eb39c6d2350815b5de5dc06629cd3008ab712b95a49 Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.dbusd4fca520cba6b303a00db04c5525f9ebcd91027396a8daea21428623d9c000cd9 Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/top1miku.i686n/an/aopendir ua-wget
http://160.191.55.60/HBTs/.udevmonebf5b2fe63545dd6486a8424d3660e89fec0f5b4d9f5697cf639c71a30e5084f Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.upstart5f346db94dd74ca9f5b9bbef9a3acede4ff545868d9302ce9e9f6afadd174c3e Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.netd3fe3f07475a7f97dbd70d217568915acf9107cf6ac1225758d3068dcca3b894d Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.syncd2e03f8c53cfdc53d28de4014c6d1bf599f6db13e805ddf40ec63fc2728d99615 Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.irqbal2cc247d74f81b12e13cfee4617575ac1e0ab5dca352947af77072916b3f91532 Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.rsysl739aef07d54c89858d617dcfaa25a44ea5d28f75efab5c14f884d3b89c24181b Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.modprobea4c5d10e0484cc0b3005ba65e1499780acb68a18b476f846bc8fce1d318f07bf Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.systemd-jdn/an/aopendir ua-wget
http://160.191.55.60/HBTs/.kthreadd188e8c19cfc165712b2e5d83a4a79eb6c0f68fe0a03d0811cd2972da755be0ed Miraimirai opendir ua-wget
http://160.191.55.60/HBTs/.klogda2d1334928d5ae1368924865254295e14290e36a88dc01c309ae66c04b1ab468 Miraimirai opendir ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
34
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=b894957d-1700-0000-f984-dc0f750b0000 pid=2933 /usr/bin/sudo guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939 /tmp/sample.bin guuid=b894957d-1700-0000-f984-dc0f750b0000 pid=2933->guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939 execve guuid=0393e47f-1700-0000-f984-dc0f7d0b0000 pid=2941 /usr/bin/cp guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=0393e47f-1700-0000-f984-dc0f7d0b0000 pid=2941 execve guuid=73c20f84-1700-0000-f984-dc0f860b0000 pid=2950 /usr/bin/wget net send-data guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=73c20f84-1700-0000-f984-dc0f860b0000 pid=2950 execve guuid=2a0d6da1-1700-0000-f984-dc0fc30b0000 pid=3011 /usr/bin/curl net send-data write-file guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=2a0d6da1-1700-0000-f984-dc0fc30b0000 pid=3011 execve guuid=4f2230c6-1700-0000-f984-dc0ff30b0000 pid=3059 /usr/bin/cat guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=4f2230c6-1700-0000-f984-dc0ff30b0000 pid=3059 execve guuid=ffe449c7-1700-0000-f984-dc0ff50b0000 pid=3061 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ffe449c7-1700-0000-f984-dc0ff50b0000 pid=3061 execve guuid=10cde6c7-1700-0000-f984-dc0ff60b0000 pid=3062 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=10cde6c7-1700-0000-f984-dc0ff60b0000 pid=3062 clone guuid=4fc51fc9-1700-0000-f984-dc0ff90b0000 pid=3065 /usr/bin/wget net send-data write-file guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=4fc51fc9-1700-0000-f984-dc0ff90b0000 pid=3065 execve guuid=8687fb09-1800-0000-f984-dc0f580c0000 pid=3160 /usr/bin/curl net send-data write-file guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=8687fb09-1800-0000-f984-dc0f580c0000 pid=3160 execve guuid=1791ec4e-1800-0000-f984-dc0f920c0000 pid=3218 /usr/bin/cat guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=1791ec4e-1800-0000-f984-dc0f920c0000 pid=3218 execve guuid=19f66e4f-1800-0000-f984-dc0f940c0000 pid=3220 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=19f66e4f-1800-0000-f984-dc0f940c0000 pid=3220 execve guuid=1dfdca4f-1800-0000-f984-dc0f960c0000 pid=3222 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=1dfdca4f-1800-0000-f984-dc0f960c0000 pid=3222 clone guuid=ece04b51-1800-0000-f984-dc0f9b0c0000 pid=3227 /usr/bin/wget net send-data write-file guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ece04b51-1800-0000-f984-dc0f9b0c0000 pid=3227 execve guuid=da659191-1800-0000-f984-dc0fe70c0000 pid=3303 /usr/bin/curl net send-data write-file guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=da659191-1800-0000-f984-dc0fe70c0000 pid=3303 execve guuid=45c430d7-1800-0000-f984-dc0f810d0000 pid=3457 /usr/bin/cat guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=45c430d7-1800-0000-f984-dc0f810d0000 pid=3457 execve guuid=3463b2d7-1800-0000-f984-dc0f830d0000 pid=3459 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=3463b2d7-1800-0000-f984-dc0f830d0000 pid=3459 execve guuid=f4a31ed8-1800-0000-f984-dc0f850d0000 pid=3461 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=f4a31ed8-1800-0000-f984-dc0f850d0000 pid=3461 execve guuid=c8adf2d8-1800-0000-f984-dc0f8d0d0000 pid=3469 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=c8adf2d8-1800-0000-f984-dc0f8d0d0000 pid=3469 execve guuid=1b2d1dd9-1800-0000-f984-dc0f8f0d0000 pid=3471 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=1b2d1dd9-1800-0000-f984-dc0f8f0d0000 pid=3471 execve guuid=e65576d9-1800-0000-f984-dc0f910d0000 pid=3473 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=e65576d9-1800-0000-f984-dc0f910d0000 pid=3473 clone guuid=895b8fd9-1800-0000-f984-dc0f920d0000 pid=3474 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=895b8fd9-1800-0000-f984-dc0f920d0000 pid=3474 execve guuid=9499ead9-1800-0000-f984-dc0f950d0000 pid=3477 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=9499ead9-1800-0000-f984-dc0f950d0000 pid=3477 execve guuid=f9a91cda-1800-0000-f984-dc0f990d0000 pid=3481 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=f9a91cda-1800-0000-f984-dc0f990d0000 pid=3481 execve guuid=966aa9da-1800-0000-f984-dc0f9c0d0000 pid=3484 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=966aa9da-1800-0000-f984-dc0f9c0d0000 pid=3484 execve guuid=a1731cdb-1800-0000-f984-dc0fa00d0000 pid=3488 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=a1731cdb-1800-0000-f984-dc0fa00d0000 pid=3488 clone guuid=ca9284db-1800-0000-f984-dc0fa30d0000 pid=3491 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ca9284db-1800-0000-f984-dc0fa30d0000 pid=3491 execve guuid=59f726dc-1800-0000-f984-dc0fa50d0000 pid=3493 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=59f726dc-1800-0000-f984-dc0fa50d0000 pid=3493 execve guuid=7e044bdc-1800-0000-f984-dc0fa90d0000 pid=3497 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=7e044bdc-1800-0000-f984-dc0fa90d0000 pid=3497 execve guuid=630971dc-1800-0000-f984-dc0fab0d0000 pid=3499 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=630971dc-1800-0000-f984-dc0fab0d0000 pid=3499 execve guuid=e1cab3dc-1800-0000-f984-dc0fad0d0000 pid=3501 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=e1cab3dc-1800-0000-f984-dc0fad0d0000 pid=3501 clone guuid=3c22cfdc-1800-0000-f984-dc0fae0d0000 pid=3502 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=3c22cfdc-1800-0000-f984-dc0fae0d0000 pid=3502 execve guuid=7b96aadd-1800-0000-f984-dc0fb40d0000 pid=3508 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=7b96aadd-1800-0000-f984-dc0fb40d0000 pid=3508 execve guuid=73230edf-1800-0000-f984-dc0fbd0d0000 pid=3517 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=73230edf-1800-0000-f984-dc0fbd0d0000 pid=3517 execve guuid=7d93b8e0-1800-0000-f984-dc0fc90d0000 pid=3529 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=7d93b8e0-1800-0000-f984-dc0fc90d0000 pid=3529 execve guuid=f4dd80e1-1800-0000-f984-dc0fcf0d0000 pid=3535 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=f4dd80e1-1800-0000-f984-dc0fcf0d0000 pid=3535 clone guuid=50f99ee2-1800-0000-f984-dc0fd00d0000 pid=3536 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=50f99ee2-1800-0000-f984-dc0fd00d0000 pid=3536 execve guuid=923b53e3-1800-0000-f984-dc0fd10d0000 pid=3537 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=923b53e3-1800-0000-f984-dc0fd10d0000 pid=3537 execve guuid=f4a772e3-1800-0000-f984-dc0fd40d0000 pid=3540 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=f4a772e3-1800-0000-f984-dc0fd40d0000 pid=3540 execve guuid=66bdbae4-1800-0000-f984-dc0fd80d0000 pid=3544 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=66bdbae4-1800-0000-f984-dc0fd80d0000 pid=3544 execve guuid=65fe98e5-1800-0000-f984-dc0fda0d0000 pid=3546 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=65fe98e5-1800-0000-f984-dc0fda0d0000 pid=3546 clone guuid=bcf12de7-1800-0000-f984-dc0fdf0d0000 pid=3551 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=bcf12de7-1800-0000-f984-dc0fdf0d0000 pid=3551 execve guuid=ac03e5e8-1800-0000-f984-dc0fe10d0000 pid=3553 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ac03e5e8-1800-0000-f984-dc0fe10d0000 pid=3553 execve guuid=c978f2e9-1800-0000-f984-dc0fe80d0000 pid=3560 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=c978f2e9-1800-0000-f984-dc0fe80d0000 pid=3560 execve guuid=ae0e5aeb-1800-0000-f984-dc0fee0d0000 pid=3566 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ae0e5aeb-1800-0000-f984-dc0fee0d0000 pid=3566 execve guuid=ffa5f7eb-1800-0000-f984-dc0ff00d0000 pid=3568 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ffa5f7eb-1800-0000-f984-dc0ff00d0000 pid=3568 clone guuid=e1f354ed-1800-0000-f984-dc0ff20d0000 pid=3570 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=e1f354ed-1800-0000-f984-dc0ff20d0000 pid=3570 execve guuid=69afaaed-1800-0000-f984-dc0ff40d0000 pid=3572 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=69afaaed-1800-0000-f984-dc0ff40d0000 pid=3572 execve guuid=800eefed-1800-0000-f984-dc0ff80d0000 pid=3576 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=800eefed-1800-0000-f984-dc0ff80d0000 pid=3576 execve guuid=b21dccef-1800-0000-f984-dc0ffa0d0000 pid=3578 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=b21dccef-1800-0000-f984-dc0ffa0d0000 pid=3578 execve guuid=33531ef1-1800-0000-f984-dc0f010e0000 pid=3585 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=33531ef1-1800-0000-f984-dc0f010e0000 pid=3585 clone guuid=d02078f1-1800-0000-f984-dc0f040e0000 pid=3588 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=d02078f1-1800-0000-f984-dc0f040e0000 pid=3588 execve guuid=923689f4-1800-0000-f984-dc0f080e0000 pid=3592 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=923689f4-1800-0000-f984-dc0f080e0000 pid=3592 execve guuid=6b1b35f6-1800-0000-f984-dc0f0d0e0000 pid=3597 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=6b1b35f6-1800-0000-f984-dc0f0d0e0000 pid=3597 execve guuid=a98625f7-1800-0000-f984-dc0f100e0000 pid=3600 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=a98625f7-1800-0000-f984-dc0f100e0000 pid=3600 execve guuid=3b9119f8-1800-0000-f984-dc0f110e0000 pid=3601 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=3b9119f8-1800-0000-f984-dc0f110e0000 pid=3601 clone guuid=fdfd5df8-1800-0000-f984-dc0f130e0000 pid=3603 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=fdfd5df8-1800-0000-f984-dc0f130e0000 pid=3603 execve guuid=ad99d6f8-1800-0000-f984-dc0f140e0000 pid=3604 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=ad99d6f8-1800-0000-f984-dc0f140e0000 pid=3604 execve guuid=b2203df9-1800-0000-f984-dc0f170e0000 pid=3607 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=b2203df9-1800-0000-f984-dc0f170e0000 pid=3607 execve guuid=83cb0afa-1800-0000-f984-dc0f190e0000 pid=3609 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=83cb0afa-1800-0000-f984-dc0f190e0000 pid=3609 execve guuid=3d1cc7fa-1800-0000-f984-dc0f1c0e0000 pid=3612 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=3d1cc7fa-1800-0000-f984-dc0f1c0e0000 pid=3612 clone guuid=12dd8afd-1800-0000-f984-dc0f260e0000 pid=3622 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=12dd8afd-1800-0000-f984-dc0f260e0000 pid=3622 execve guuid=4f5f6dff-1800-0000-f984-dc0f280e0000 pid=3624 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=4f5f6dff-1800-0000-f984-dc0f280e0000 pid=3624 execve guuid=de3ff400-1900-0000-f984-dc0f2b0e0000 pid=3627 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=de3ff400-1900-0000-f984-dc0f2b0e0000 pid=3627 execve guuid=d5463702-1900-0000-f984-dc0f2d0e0000 pid=3629 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=d5463702-1900-0000-f984-dc0f2d0e0000 pid=3629 execve guuid=d119b703-1900-0000-f984-dc0f2f0e0000 pid=3631 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=d119b703-1900-0000-f984-dc0f2f0e0000 pid=3631 clone guuid=d9d6eb04-1900-0000-f984-dc0f310e0000 pid=3633 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=d9d6eb04-1900-0000-f984-dc0f310e0000 pid=3633 execve guuid=def1e806-1900-0000-f984-dc0f320e0000 pid=3634 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=def1e806-1900-0000-f984-dc0f320e0000 pid=3634 execve guuid=4d8e8208-1900-0000-f984-dc0f350e0000 pid=3637 /usr/bin/wget guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=4d8e8208-1900-0000-f984-dc0f350e0000 pid=3637 execve guuid=83e49309-1900-0000-f984-dc0f360e0000 pid=3638 /usr/bin/curl guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=83e49309-1900-0000-f984-dc0f360e0000 pid=3638 execve guuid=71358a0a-1900-0000-f984-dc0f380e0000 pid=3640 /usr/bin/bash guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=71358a0a-1900-0000-f984-dc0f380e0000 pid=3640 clone guuid=b1c2e30b-1900-0000-f984-dc0f3a0e0000 pid=3642 /usr/bin/chmod guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=b1c2e30b-1900-0000-f984-dc0f3a0e0000 pid=3642 execve guuid=a22b0c19-1900-0000-f984-dc0f560e0000 pid=3670 /tmp/x net guuid=ce073a7f-1700-0000-f984-dc0f7b0b0000 pid=2939->guuid=a22b0c19-1900-0000-f984-dc0f560e0000 pid=3670 execve b2331ca0-b7d5-523d-86de-9cf5e3f8a592 160.191.55.60:80 guuid=73c20f84-1700-0000-f984-dc0f860b0000 pid=2950->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 145B guuid=2a0d6da1-1700-0000-f984-dc0fc30b0000 pid=3011->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 94B guuid=4fc51fc9-1700-0000-f984-dc0ff90b0000 pid=3065->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 139B guuid=8687fb09-1800-0000-f984-dc0f580c0000 pid=3160->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 88B guuid=ece04b51-1800-0000-f984-dc0f9b0c0000 pid=3227->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 139B guuid=da659191-1800-0000-f984-dc0fe70c0000 pid=3303->b2331ca0-b7d5-523d-86de-9cf5e3f8a592 send: 88B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f4a31ed8-1800-0000-f984-dc0f850d0000 pid=3461->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=cb0c36d8-1800-0000-f984-dc0f860d0000 pid=3462 /tmp/x zombie guuid=f4a31ed8-1800-0000-f984-dc0f850d0000 pid=3461->guuid=cb0c36d8-1800-0000-f984-dc0f860d0000 pid=3462 clone guuid=85f53bd8-1800-0000-f984-dc0f870d0000 pid=3463 /tmp/x zombie guuid=f4a31ed8-1800-0000-f984-dc0f850d0000 pid=3461->guuid=85f53bd8-1800-0000-f984-dc0f870d0000 pid=3463 clone guuid=890247d8-1800-0000-f984-dc0f880d0000 pid=3464 /tmp/x write-config zombie guuid=85f53bd8-1800-0000-f984-dc0f870d0000 pid=3463->guuid=890247d8-1800-0000-f984-dc0f880d0000 pid=3464 clone guuid=66059cd8-1800-0000-f984-dc0f8a0d0000 pid=3466 /usr/bin/dash guuid=890247d8-1800-0000-f984-dc0f880d0000 pid=3464->guuid=66059cd8-1800-0000-f984-dc0f8a0d0000 pid=3466 execve guuid=b4e7c2d9-1800-0000-f984-dc0f940d0000 pid=3476 /tmp/x dns net send-data guuid=890247d8-1800-0000-f984-dc0f880d0000 pid=3464->guuid=b4e7c2d9-1800-0000-f984-dc0f940d0000 pid=3476 clone guuid=51faced8-1800-0000-f984-dc0f8c0d0000 pid=3468 /usr/bin/cp guuid=66059cd8-1800-0000-f984-dc0f8a0d0000 pid=3466->guuid=51faced8-1800-0000-f984-dc0f8c0d0000 pid=3468 execve guuid=b4e7c2d9-1800-0000-f984-dc0f940d0000 pid=3476->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1824B a1cb65f6-afd3-5a3a-9fa0-f13741392136 top1miku.duckdns.org:2004 guuid=b4e7c2d9-1800-0000-f984-dc0f940d0000 pid=3476->a1cb65f6-afd3-5a3a-9fa0-f13741392136 con f37c51d7-2bb3-53a8-b958-5a758a36d238 top1miku.duckdns.org:0 guuid=b4e7c2d9-1800-0000-f984-dc0f940d0000 pid=3476->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 72B guuid=9499ead9-1800-0000-f984-dc0f950d0000 pid=3477->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=01790ada-1800-0000-f984-dc0f960d0000 pid=3478 /tmp/x zombie guuid=9499ead9-1800-0000-f984-dc0f950d0000 pid=3477->guuid=01790ada-1800-0000-f984-dc0f960d0000 pid=3478 clone guuid=3a4110da-1800-0000-f984-dc0f980d0000 pid=3480 /tmp/x zombie guuid=9499ead9-1800-0000-f984-dc0f950d0000 pid=3477->guuid=3a4110da-1800-0000-f984-dc0f980d0000 pid=3480 clone guuid=88303bda-1800-0000-f984-dc0f9a0d0000 pid=3482 /tmp/x write-config zombie guuid=3a4110da-1800-0000-f984-dc0f980d0000 pid=3480->guuid=88303bda-1800-0000-f984-dc0f9a0d0000 pid=3482 clone guuid=f17616db-1800-0000-f984-dc0f9f0d0000 pid=3487 /usr/bin/dash guuid=88303bda-1800-0000-f984-dc0f9a0d0000 pid=3482->guuid=f17616db-1800-0000-f984-dc0f9f0d0000 pid=3487 execve guuid=d5ce76dd-1800-0000-f984-dc0fb20d0000 pid=3506 /tmp/x dns net send-data guuid=88303bda-1800-0000-f984-dc0f9a0d0000 pid=3482->guuid=d5ce76dd-1800-0000-f984-dc0fb20d0000 pid=3506 clone guuid=1eee51db-1800-0000-f984-dc0fa10d0000 pid=3489 /usr/bin/cp guuid=f17616db-1800-0000-f984-dc0f9f0d0000 pid=3487->guuid=1eee51db-1800-0000-f984-dc0fa10d0000 pid=3489 execve guuid=59f726dc-1800-0000-f984-dc0fa50d0000 pid=3493->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=281d3cdc-1800-0000-f984-dc0fa70d0000 pid=3495 /tmp/x zombie guuid=59f726dc-1800-0000-f984-dc0fa50d0000 pid=3493->guuid=281d3cdc-1800-0000-f984-dc0fa70d0000 pid=3495 clone guuid=6ee63fdc-1800-0000-f984-dc0fa80d0000 pid=3496 /tmp/x zombie guuid=59f726dc-1800-0000-f984-dc0fa50d0000 pid=3493->guuid=6ee63fdc-1800-0000-f984-dc0fa80d0000 pid=3496 clone guuid=fe1614dd-1800-0000-f984-dc0fb00d0000 pid=3504 /tmp/x write-config zombie guuid=6ee63fdc-1800-0000-f984-dc0fa80d0000 pid=3496->guuid=fe1614dd-1800-0000-f984-dc0fb00d0000 pid=3504 clone guuid=d8d363de-1800-0000-f984-dc0fb70d0000 pid=3511 /usr/bin/dash guuid=fe1614dd-1800-0000-f984-dc0fb00d0000 pid=3504->guuid=d8d363de-1800-0000-f984-dc0fb70d0000 pid=3511 execve guuid=72167de0-1800-0000-f984-dc0fc60d0000 pid=3526 /tmp/x dns net send-data guuid=fe1614dd-1800-0000-f984-dc0fb00d0000 pid=3504->guuid=72167de0-1800-0000-f984-dc0fc60d0000 pid=3526 clone guuid=d5ce76dd-1800-0000-f984-dc0fb20d0000 pid=3506->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1406B guuid=d5ce76dd-1800-0000-f984-dc0fb20d0000 pid=3506->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 324B guuid=7b96aadd-1800-0000-f984-dc0fb40d0000 pid=3508->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=737b02df-1800-0000-f984-dc0fbb0d0000 pid=3515 /tmp/x zombie guuid=7b96aadd-1800-0000-f984-dc0fb40d0000 pid=3508->guuid=737b02df-1800-0000-f984-dc0fbb0d0000 pid=3515 clone guuid=cb6b06df-1800-0000-f984-dc0fbc0d0000 pid=3516 /tmp/x zombie guuid=7b96aadd-1800-0000-f984-dc0fb40d0000 pid=3508->guuid=cb6b06df-1800-0000-f984-dc0fbc0d0000 pid=3516 clone guuid=15811ddf-1800-0000-f984-dc0fbe0d0000 pid=3518 /usr/bin/cp guuid=d8d363de-1800-0000-f984-dc0fb70d0000 pid=3511->guuid=15811ddf-1800-0000-f984-dc0fbe0d0000 pid=3518 execve guuid=f14031e0-1800-0000-f984-dc0fc30d0000 pid=3523 /tmp/x write-config zombie guuid=cb6b06df-1800-0000-f984-dc0fbc0d0000 pid=3516->guuid=f14031e0-1800-0000-f984-dc0fc30d0000 pid=3523 clone guuid=0312a9e0-1800-0000-f984-dc0fc70d0000 pid=3527 /usr/bin/dash guuid=f14031e0-1800-0000-f984-dc0fc30d0000 pid=3523->guuid=0312a9e0-1800-0000-f984-dc0fc70d0000 pid=3527 execve guuid=b957e6e6-1800-0000-f984-dc0fdb0d0000 pid=3547 /tmp/x dns net send-data guuid=f14031e0-1800-0000-f984-dc0fc30d0000 pid=3523->guuid=b957e6e6-1800-0000-f984-dc0fdb0d0000 pid=3547 clone guuid=72167de0-1800-0000-f984-dc0fc60d0000 pid=3526->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2204B guuid=72167de0-1800-0000-f984-dc0fc60d0000 pid=3526->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 486B guuid=72167de0-1800-0000-f984-dc0fc60d0000 pid=3526->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 27B guuid=275143e1-1800-0000-f984-dc0fce0d0000 pid=3534 /usr/bin/cp guuid=0312a9e0-1800-0000-f984-dc0fc70d0000 pid=3527->guuid=275143e1-1800-0000-f984-dc0fce0d0000 pid=3534 execve guuid=923b53e3-1800-0000-f984-dc0fd10d0000 pid=3537->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d65463e3-1800-0000-f984-dc0fd20d0000 pid=3538 /tmp/x zombie guuid=923b53e3-1800-0000-f984-dc0fd10d0000 pid=3537->guuid=d65463e3-1800-0000-f984-dc0fd20d0000 pid=3538 clone guuid=8e7768e3-1800-0000-f984-dc0fd30d0000 pid=3539 /tmp/x zombie guuid=923b53e3-1800-0000-f984-dc0fd10d0000 pid=3537->guuid=8e7768e3-1800-0000-f984-dc0fd30d0000 pid=3539 clone guuid=358685e3-1800-0000-f984-dc0fd50d0000 pid=3541 /tmp/x write-config zombie guuid=8e7768e3-1800-0000-f984-dc0fd30d0000 pid=3539->guuid=358685e3-1800-0000-f984-dc0fd50d0000 pid=3541 clone guuid=7a6bece3-1800-0000-f984-dc0fd60d0000 pid=3542 /usr/bin/dash guuid=358685e3-1800-0000-f984-dc0fd50d0000 pid=3541->guuid=7a6bece3-1800-0000-f984-dc0fd60d0000 pid=3542 execve guuid=351b30e5-1800-0000-f984-dc0fd90d0000 pid=3545 /tmp/x dns net send-data guuid=358685e3-1800-0000-f984-dc0fd50d0000 pid=3541->guuid=351b30e5-1800-0000-f984-dc0fd90d0000 pid=3545 clone guuid=c3825ae4-1800-0000-f984-dc0fd70d0000 pid=3543 /usr/bin/cp guuid=7a6bece3-1800-0000-f984-dc0fd60d0000 pid=3542->guuid=c3825ae4-1800-0000-f984-dc0fd70d0000 pid=3543 execve guuid=351b30e5-1800-0000-f984-dc0fd90d0000 pid=3545->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1102B guuid=351b30e5-1800-0000-f984-dc0fd90d0000 pid=3545->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 225B guuid=351b30e5-1800-0000-f984-dc0fd90d0000 pid=3545->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 27B guuid=b957e6e6-1800-0000-f984-dc0fdb0d0000 pid=3547->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 722B guuid=b957e6e6-1800-0000-f984-dc0fdb0d0000 pid=3547->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 135B guuid=b957e6e6-1800-0000-f984-dc0fdb0d0000 pid=3547->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B guuid=ac03e5e8-1800-0000-f984-dc0fe10d0000 pid=3553->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=84e1dae9-1800-0000-f984-dc0fe60d0000 pid=3558 /tmp/x zombie guuid=ac03e5e8-1800-0000-f984-dc0fe10d0000 pid=3553->guuid=84e1dae9-1800-0000-f984-dc0fe60d0000 pid=3558 clone guuid=235edfe9-1800-0000-f984-dc0fe70d0000 pid=3559 /tmp/x zombie guuid=ac03e5e8-1800-0000-f984-dc0fe10d0000 pid=3553->guuid=235edfe9-1800-0000-f984-dc0fe70d0000 pid=3559 clone guuid=949462eb-1800-0000-f984-dc0fef0d0000 pid=3567 /tmp/x write-config zombie guuid=235edfe9-1800-0000-f984-dc0fe70d0000 pid=3559->guuid=949462eb-1800-0000-f984-dc0fef0d0000 pid=3567 clone guuid=df867ded-1800-0000-f984-dc0ff30d0000 pid=3571 /usr/bin/dash guuid=949462eb-1800-0000-f984-dc0fef0d0000 pid=3567->guuid=df867ded-1800-0000-f984-dc0ff30d0000 pid=3571 execve guuid=f205edf0-1800-0000-f984-dc0f000e0000 pid=3584 /tmp/x dns net send-data guuid=949462eb-1800-0000-f984-dc0fef0d0000 pid=3567->guuid=f205edf0-1800-0000-f984-dc0f000e0000 pid=3584 clone guuid=c138cfed-1800-0000-f984-dc0ff50d0000 pid=3573 /usr/bin/cp guuid=df867ded-1800-0000-f984-dc0ff30d0000 pid=3571->guuid=c138cfed-1800-0000-f984-dc0ff50d0000 pid=3573 execve guuid=69afaaed-1800-0000-f984-dc0ff40d0000 pid=3572->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4051dded-1800-0000-f984-dc0ff60d0000 pid=3574 /tmp/x zombie guuid=69afaaed-1800-0000-f984-dc0ff40d0000 pid=3572->guuid=4051dded-1800-0000-f984-dc0ff60d0000 pid=3574 clone guuid=8454e0ed-1800-0000-f984-dc0ff70d0000 pid=3575 /tmp/x zombie guuid=69afaaed-1800-0000-f984-dc0ff40d0000 pid=3572->guuid=8454e0ed-1800-0000-f984-dc0ff70d0000 pid=3575 clone guuid=2fe632ef-1800-0000-f984-dc0ff90d0000 pid=3577 /tmp/x write-config zombie guuid=8454e0ed-1800-0000-f984-dc0ff70d0000 pid=3575->guuid=2fe632ef-1800-0000-f984-dc0ff90d0000 pid=3577 clone guuid=d97e8ff0-1800-0000-f984-dc0ffe0d0000 pid=3582 /usr/bin/dash guuid=2fe632ef-1800-0000-f984-dc0ff90d0000 pid=3577->guuid=d97e8ff0-1800-0000-f984-dc0ffe0d0000 pid=3582 execve guuid=5b1674f4-1800-0000-f984-dc0f070e0000 pid=3591 /tmp/x dns net send-data guuid=2fe632ef-1800-0000-f984-dc0ff90d0000 pid=3577->guuid=5b1674f4-1800-0000-f984-dc0f070e0000 pid=3591 clone guuid=977762f1-1800-0000-f984-dc0f030e0000 pid=3587 /usr/bin/cp guuid=d97e8ff0-1800-0000-f984-dc0ffe0d0000 pid=3582->guuid=977762f1-1800-0000-f984-dc0f030e0000 pid=3587 execve guuid=f205edf0-1800-0000-f984-dc0f000e0000 pid=3584->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 2546B guuid=f205edf0-1800-0000-f984-dc0f000e0000 pid=3584->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 513B guuid=f205edf0-1800-0000-f984-dc0f000e0000 pid=3584->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 90B guuid=5b1674f4-1800-0000-f984-dc0f070e0000 pid=3591->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1406B guuid=5b1674f4-1800-0000-f984-dc0f070e0000 pid=3591->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 306B guuid=5b1674f4-1800-0000-f984-dc0f070e0000 pid=3591->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B guuid=923689f4-1800-0000-f984-dc0f080e0000 pid=3592->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dbf127f6-1800-0000-f984-dc0f0a0e0000 pid=3594 /tmp/x zombie guuid=923689f4-1800-0000-f984-dc0f080e0000 pid=3592->guuid=dbf127f6-1800-0000-f984-dc0f0a0e0000 pid=3594 clone guuid=1a282bf6-1800-0000-f984-dc0f0b0e0000 pid=3595 /tmp/x zombie guuid=923689f4-1800-0000-f984-dc0f080e0000 pid=3592->guuid=1a282bf6-1800-0000-f984-dc0f0b0e0000 pid=3595 clone guuid=a18b30f6-1800-0000-f984-dc0f0c0e0000 pid=3596 /tmp/x write-config zombie guuid=1a282bf6-1800-0000-f984-dc0f0b0e0000 pid=3595->guuid=a18b30f6-1800-0000-f984-dc0f0c0e0000 pid=3596 clone guuid=001e66f6-1800-0000-f984-dc0f0e0e0000 pid=3598 /usr/bin/dash guuid=a18b30f6-1800-0000-f984-dc0f0c0e0000 pid=3596->guuid=001e66f6-1800-0000-f984-dc0f0e0e0000 pid=3598 execve guuid=a8832ff8-1800-0000-f984-dc0f120e0000 pid=3602 /tmp/x dns net send-data guuid=a18b30f6-1800-0000-f984-dc0f0c0e0000 pid=3596->guuid=a8832ff8-1800-0000-f984-dc0f120e0000 pid=3602 clone guuid=f580f4f6-1800-0000-f984-dc0f0f0e0000 pid=3599 /usr/bin/cp guuid=001e66f6-1800-0000-f984-dc0f0e0e0000 pid=3598->guuid=f580f4f6-1800-0000-f984-dc0f0f0e0000 pid=3599 execve guuid=a8832ff8-1800-0000-f984-dc0f120e0000 pid=3602->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 494B guuid=a8832ff8-1800-0000-f984-dc0f120e0000 pid=3602->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 90B guuid=ad99d6f8-1800-0000-f984-dc0f140e0000 pid=3604->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=d82f2df9-1800-0000-f984-dc0f150e0000 pid=3605 /tmp/x guuid=ad99d6f8-1800-0000-f984-dc0f140e0000 pid=3604->guuid=d82f2df9-1800-0000-f984-dc0f150e0000 pid=3605 clone guuid=69df34f9-1800-0000-f984-dc0f160e0000 pid=3606 /tmp/x zombie guuid=ad99d6f8-1800-0000-f984-dc0f140e0000 pid=3604->guuid=69df34f9-1800-0000-f984-dc0f160e0000 pid=3606 clone guuid=463c77f9-1800-0000-f984-dc0f180e0000 pid=3608 /tmp/x write-config zombie guuid=69df34f9-1800-0000-f984-dc0f160e0000 pid=3606->guuid=463c77f9-1800-0000-f984-dc0f180e0000 pid=3608 clone guuid=93a139fa-1800-0000-f984-dc0f1a0e0000 pid=3610 /usr/bin/dash guuid=463c77f9-1800-0000-f984-dc0f180e0000 pid=3608->guuid=93a139fa-1800-0000-f984-dc0f1a0e0000 pid=3610 execve guuid=6832e3fd-1800-0000-f984-dc0f270e0000 pid=3623 /tmp/x dns net send-data guuid=463c77f9-1800-0000-f984-dc0f180e0000 pid=3608->guuid=6832e3fd-1800-0000-f984-dc0f270e0000 pid=3623 clone guuid=42d9abfa-1800-0000-f984-dc0f1b0e0000 pid=3611 /usr/bin/cp guuid=93a139fa-1800-0000-f984-dc0f1a0e0000 pid=3610->guuid=42d9abfa-1800-0000-f984-dc0f1b0e0000 pid=3611 execve guuid=6832e3fd-1800-0000-f984-dc0f270e0000 pid=3623->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 950B guuid=6832e3fd-1800-0000-f984-dc0f270e0000 pid=3623->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 198B guuid=6832e3fd-1800-0000-f984-dc0f270e0000 pid=3623->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 9B guuid=4f5f6dff-1800-0000-f984-dc0f280e0000 pid=3624->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4724e600-1900-0000-f984-dc0f290e0000 pid=3625 /tmp/x zombie guuid=4f5f6dff-1800-0000-f984-dc0f280e0000 pid=3624->guuid=4724e600-1900-0000-f984-dc0f290e0000 pid=3625 clone guuid=68dde900-1900-0000-f984-dc0f2a0e0000 pid=3626 /tmp/x zombie guuid=4f5f6dff-1800-0000-f984-dc0f280e0000 pid=3624->guuid=68dde900-1900-0000-f984-dc0f2a0e0000 pid=3626 clone guuid=e648cc01-1900-0000-f984-dc0f2c0e0000 pid=3628 /tmp/x write-config zombie guuid=68dde900-1900-0000-f984-dc0f2a0e0000 pid=3626->guuid=e648cc01-1900-0000-f984-dc0f2c0e0000 pid=3628 clone guuid=ef89ef02-1900-0000-f984-dc0f2e0e0000 pid=3630 /usr/bin/dash guuid=e648cc01-1900-0000-f984-dc0f2c0e0000 pid=3628->guuid=ef89ef02-1900-0000-f984-dc0f2e0e0000 pid=3630 execve guuid=4d26100e-1900-0000-f984-dc0f3f0e0000 pid=3647 /tmp/x dns net send-data guuid=e648cc01-1900-0000-f984-dc0f2c0e0000 pid=3628->guuid=4d26100e-1900-0000-f984-dc0f3f0e0000 pid=3647 clone guuid=ad45e803-1900-0000-f984-dc0f300e0000 pid=3632 /usr/bin/cp guuid=ef89ef02-1900-0000-f984-dc0f2e0e0000 pid=3630->guuid=ad45e803-1900-0000-f984-dc0f300e0000 pid=3632 execve guuid=def1e806-1900-0000-f984-dc0f320e0000 pid=3634->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=dea86f08-1900-0000-f984-dc0f330e0000 pid=3635 /tmp/x guuid=def1e806-1900-0000-f984-dc0f320e0000 pid=3634->guuid=dea86f08-1900-0000-f984-dc0f330e0000 pid=3635 clone guuid=33de7308-1900-0000-f984-dc0f340e0000 pid=3636 /tmp/x zombie guuid=def1e806-1900-0000-f984-dc0f320e0000 pid=3634->guuid=33de7308-1900-0000-f984-dc0f340e0000 pid=3636 clone guuid=2ae1260a-1900-0000-f984-dc0f370e0000 pid=3639 /tmp/x write-config zombie guuid=33de7308-1900-0000-f984-dc0f340e0000 pid=3636->guuid=2ae1260a-1900-0000-f984-dc0f370e0000 pid=3639 clone guuid=8330080b-1900-0000-f984-dc0f390e0000 pid=3641 /usr/bin/dash guuid=2ae1260a-1900-0000-f984-dc0f370e0000 pid=3639->guuid=8330080b-1900-0000-f984-dc0f390e0000 pid=3641 execve guuid=5376c70f-1900-0000-f984-dc0f430e0000 pid=3651 /tmp/x dns net send-data guuid=2ae1260a-1900-0000-f984-dc0f370e0000 pid=3639->guuid=5376c70f-1900-0000-f984-dc0f430e0000 pid=3651 clone guuid=1c7a7b0c-1900-0000-f984-dc0f3b0e0000 pid=3643 /usr/bin/cp guuid=8330080b-1900-0000-f984-dc0f390e0000 pid=3641->guuid=1c7a7b0c-1900-0000-f984-dc0f3b0e0000 pid=3643 execve guuid=4d26100e-1900-0000-f984-dc0f3f0e0000 pid=3647->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 1862B guuid=4d26100e-1900-0000-f984-dc0f3f0e0000 pid=3647->a1cb65f6-afd3-5a3a-9fa0-f13741392136 con guuid=4d26100e-1900-0000-f984-dc0f3f0e0000 pid=3647->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 63B guuid=5376c70f-1900-0000-f984-dc0f430e0000 pid=3651->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 950B guuid=5376c70f-1900-0000-f984-dc0f430e0000 pid=3651->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 2B guuid=5376c70f-1900-0000-f984-dc0f430e0000 pid=3651->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 27B guuid=a22b0c19-1900-0000-f984-dc0f560e0000 pid=3670->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=68c52219-1900-0000-f984-dc0f580e0000 pid=3672 /tmp/x guuid=a22b0c19-1900-0000-f984-dc0f560e0000 pid=3670->guuid=68c52219-1900-0000-f984-dc0f580e0000 pid=3672 clone guuid=7da22919-1900-0000-f984-dc0f590e0000 pid=3673 /tmp/x zombie guuid=a22b0c19-1900-0000-f984-dc0f560e0000 pid=3670->guuid=7da22919-1900-0000-f984-dc0f590e0000 pid=3673 clone guuid=db5a131b-1900-0000-f984-dc0f600e0000 pid=3680 /tmp/x write-config zombie guuid=7da22919-1900-0000-f984-dc0f590e0000 pid=3673->guuid=db5a131b-1900-0000-f984-dc0f600e0000 pid=3680 clone guuid=c4c6541c-1900-0000-f984-dc0f650e0000 pid=3685 /usr/bin/dash guuid=db5a131b-1900-0000-f984-dc0f600e0000 pid=3680->guuid=c4c6541c-1900-0000-f984-dc0f650e0000 pid=3685 execve guuid=7f732f1e-1900-0000-f984-dc0f670e0000 pid=3687 /tmp/x dns net send-data guuid=db5a131b-1900-0000-f984-dc0f600e0000 pid=3680->guuid=7f732f1e-1900-0000-f984-dc0f670e0000 pid=3687 clone guuid=3de8e41c-1900-0000-f984-dc0f660e0000 pid=3686 /usr/bin/cp guuid=c4c6541c-1900-0000-f984-dc0f650e0000 pid=3685->guuid=3de8e41c-1900-0000-f984-dc0f660e0000 pid=3686 execve guuid=7f732f1e-1900-0000-f984-dc0f670e0000 pid=3687->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 send: 912B guuid=7f732f1e-1900-0000-f984-dc0f670e0000 pid=3687->a1cb65f6-afd3-5a3a-9fa0-f13741392136 send: 180B guuid=7f732f1e-1900-0000-f984-dc0f670e0000 pid=3687->f37c51d7-2bb3-53a8-b958-5a758a36d238 send: 18B
Threat name:
Linux.Downloader.Medusa
Status:
Malicious
First seen:
2025-08-11 17:53:28 UTC
File Type:
Text (Shell)
AV detection:
23 of 38 (60.53%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:mirai antivm botnet credential_access defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads process memory
Enumerates running processes
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Mirai
Mirai family
Malware Config
C2 Extraction:
top1miku.duckdns.org
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

sh e067f622e732b809876f95f19fc254d4c09cf281fdedc81492ec1f1af85cda2d

(this sample)

  
Delivery method
Distributed via web download

Comments