MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e7fed3b06801890122be87fbac365b559a5d7ed3f2993dbfe3db70a7c6eddfd7. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 10


Intelligence 10 IOCs YARA 12 File information Comments

SHA256 hash: e7fed3b06801890122be87fbac365b559a5d7ed3f2993dbfe3db70a7c6eddfd7
SHA3-384 hash: 4dafd06566b1e83110ba8d4c81fdce8590d4ed5c9ab751325f8a8bc9f927f295299676bce57c6aa72d30356a85d293b4
SHA1 hash: 0060accee3db1e839e24f01d02253e0ec44483c7
MD5 hash: dcc2f92c8ecc2bc09f35768e607c47b7
humanhash: nine-lactose-march-social
File name:getty
Download: download sample
Signature Mirai
File size:138'223 bytes
First seen:2025-07-12 05:04:43 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:i3fdrSURZC5k0HQ0NWNLsInykTCampFEthq9aTemT:i34Gc5xdWLszgFmpFEthq9aTemT
TLSH T1DCD3A929F102C733D1930671229DEF222C319BE537DAB51AB3B47AB4ADB70476911E9C
telfhash t1f0315611943546142fb39928acbd56b315221b2323586f716f25c5cc49260e1e93dd0f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
18
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Creating a file
Sets a written file as executable
Launching a process
Connection attempt
Kills processes
Substitutes an application name
Status:
terminated
Behavior Graph:
%3 guuid=916eaf97-1a00-0000-a9f6-d5bc640b0000 pid=2916 /usr/bin/sudo guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923 /tmp/sample.bin net guuid=916eaf97-1a00-0000-a9f6-d5bc640b0000 pid=2916->guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925 /tmp/sample.bin zombie guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923->guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925 clone guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926 /usr/bin/dash zombie guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923->guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926 execve guuid=1652e29c-1a00-0000-a9f6-d5bc6f0b0000 pid=2927 /tmp/sample.bin guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923->guuid=1652e29c-1a00-0000-a9f6-d5bc6f0b0000 pid=2927 clone guuid=6897e69c-1a00-0000-a9f6-d5bc700b0000 pid=2928 /tmp/sample.bin guuid=2bffc59b-1a00-0000-a9f6-d5bc6b0b0000 pid=2923->guuid=6897e69c-1a00-0000-a9f6-d5bc700b0000 pid=2928 clone guuid=a47c6dcf-1a00-0000-a9f6-d5bce50b0000 pid=3045 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a47c6dcf-1a00-0000-a9f6-d5bce50b0000 pid=3045 execve guuid=5b6360d2-1a00-0000-a9f6-d5bcef0b0000 pid=3055 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5b6360d2-1a00-0000-a9f6-d5bcef0b0000 pid=3055 execve guuid=e9f998d3-1a00-0000-a9f6-d5bcf60b0000 pid=3062 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e9f998d3-1a00-0000-a9f6-d5bcf60b0000 pid=3062 execve guuid=4cb1cbd4-1a00-0000-a9f6-d5bcfb0b0000 pid=3067 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=4cb1cbd4-1a00-0000-a9f6-d5bcfb0b0000 pid=3067 execve guuid=606203d6-1a00-0000-a9f6-d5bc000c0000 pid=3072 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=606203d6-1a00-0000-a9f6-d5bc000c0000 pid=3072 execve guuid=e8a42fd7-1a00-0000-a9f6-d5bc050c0000 pid=3077 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e8a42fd7-1a00-0000-a9f6-d5bc050c0000 pid=3077 execve guuid=0908c2d8-1a00-0000-a9f6-d5bc0b0c0000 pid=3083 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=0908c2d8-1a00-0000-a9f6-d5bc0b0c0000 pid=3083 execve guuid=bc4545da-1a00-0000-a9f6-d5bc120c0000 pid=3090 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=bc4545da-1a00-0000-a9f6-d5bc120c0000 pid=3090 execve guuid=a1ded2db-1a00-0000-a9f6-d5bc170c0000 pid=3095 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a1ded2db-1a00-0000-a9f6-d5bc170c0000 pid=3095 execve guuid=85beb409-1c00-0000-a9f6-d5bc410e0000 pid=3649 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=85beb409-1c00-0000-a9f6-d5bc410e0000 pid=3649 execve guuid=57872b0c-1c00-0000-a9f6-d5bc4c0e0000 pid=3660 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=57872b0c-1c00-0000-a9f6-d5bc4c0e0000 pid=3660 execve guuid=91ca750d-1c00-0000-a9f6-d5bc550e0000 pid=3669 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=91ca750d-1c00-0000-a9f6-d5bc550e0000 pid=3669 execve guuid=4dcb710e-1c00-0000-a9f6-d5bc5c0e0000 pid=3676 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=4dcb710e-1c00-0000-a9f6-d5bc5c0e0000 pid=3676 execve guuid=a9fea70f-1c00-0000-a9f6-d5bc630e0000 pid=3683 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a9fea70f-1c00-0000-a9f6-d5bc630e0000 pid=3683 execve guuid=3a67a810-1c00-0000-a9f6-d5bc690e0000 pid=3689 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=3a67a810-1c00-0000-a9f6-d5bc690e0000 pid=3689 execve guuid=fe234312-1c00-0000-a9f6-d5bc710e0000 pid=3697 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=fe234312-1c00-0000-a9f6-d5bc710e0000 pid=3697 execve guuid=178d1513-1c00-0000-a9f6-d5bc750e0000 pid=3701 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=178d1513-1c00-0000-a9f6-d5bc750e0000 pid=3701 execve guuid=11336b14-1c00-0000-a9f6-d5bc7b0e0000 pid=3707 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=11336b14-1c00-0000-a9f6-d5bc7b0e0000 pid=3707 execve guuid=b33e4342-1d00-0000-a9f6-d5bc8f120000 pid=4751 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=b33e4342-1d00-0000-a9f6-d5bc8f120000 pid=4751 execve guuid=ee13bd46-1d00-0000-a9f6-d5bc9f120000 pid=4767 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=ee13bd46-1d00-0000-a9f6-d5bc9f120000 pid=4767 execve guuid=c84cab47-1d00-0000-a9f6-d5bca7120000 pid=4775 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c84cab47-1d00-0000-a9f6-d5bca7120000 pid=4775 execve guuid=6b59b248-1d00-0000-a9f6-d5bcae120000 pid=4782 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=6b59b248-1d00-0000-a9f6-d5bcae120000 pid=4782 execve guuid=740c9949-1d00-0000-a9f6-d5bcb4120000 pid=4788 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=740c9949-1d00-0000-a9f6-d5bcb4120000 pid=4788 execve guuid=4ab57d4a-1d00-0000-a9f6-d5bcb9120000 pid=4793 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=4ab57d4a-1d00-0000-a9f6-d5bcb9120000 pid=4793 execve guuid=c4b5c14b-1d00-0000-a9f6-d5bcbf120000 pid=4799 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c4b5c14b-1d00-0000-a9f6-d5bcbf120000 pid=4799 execve guuid=1def774d-1d00-0000-a9f6-d5bcc3120000 pid=4803 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=1def774d-1d00-0000-a9f6-d5bcc3120000 pid=4803 execve guuid=6e5dfe4e-1d00-0000-a9f6-d5bcc5120000 pid=4805 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=6e5dfe4e-1d00-0000-a9f6-d5bcc5120000 pid=4805 execve guuid=e9d3958e-1e00-0000-a9f6-d5bcb7140000 pid=5303 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e9d3958e-1e00-0000-a9f6-d5bcb7140000 pid=5303 execve guuid=30686b93-1e00-0000-a9f6-d5bcba140000 pid=5306 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=30686b93-1e00-0000-a9f6-d5bcba140000 pid=5306 execve guuid=f2144194-1e00-0000-a9f6-d5bcbc140000 pid=5308 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=f2144194-1e00-0000-a9f6-d5bcbc140000 pid=5308 execve guuid=a67e2095-1e00-0000-a9f6-d5bcbe140000 pid=5310 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a67e2095-1e00-0000-a9f6-d5bcbe140000 pid=5310 execve guuid=47cdf495-1e00-0000-a9f6-d5bcc0140000 pid=5312 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=47cdf495-1e00-0000-a9f6-d5bcc0140000 pid=5312 execve guuid=f686c896-1e00-0000-a9f6-d5bcc2140000 pid=5314 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=f686c896-1e00-0000-a9f6-d5bcc2140000 pid=5314 execve guuid=358ca197-1e00-0000-a9f6-d5bcc4140000 pid=5316 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=358ca197-1e00-0000-a9f6-d5bcc4140000 pid=5316 execve guuid=b13f6c98-1e00-0000-a9f6-d5bcc6140000 pid=5318 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=b13f6c98-1e00-0000-a9f6-d5bcc6140000 pid=5318 execve guuid=bc304599-1e00-0000-a9f6-d5bcca140000 pid=5322 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=bc304599-1e00-0000-a9f6-d5bcca140000 pid=5322 execve guuid=d5fd12c8-1f00-0000-a9f6-d5bccf140000 pid=5327 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=d5fd12c8-1f00-0000-a9f6-d5bccf140000 pid=5327 execve guuid=a4ebc0cb-1f00-0000-a9f6-d5bcd1140000 pid=5329 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a4ebc0cb-1f00-0000-a9f6-d5bcd1140000 pid=5329 execve guuid=3daa9bcc-1f00-0000-a9f6-d5bcd3140000 pid=5331 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=3daa9bcc-1f00-0000-a9f6-d5bcd3140000 pid=5331 execve guuid=5a22d9cd-1f00-0000-a9f6-d5bcd5140000 pid=5333 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5a22d9cd-1f00-0000-a9f6-d5bcd5140000 pid=5333 execve guuid=68f5e3ce-1f00-0000-a9f6-d5bcd7140000 pid=5335 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=68f5e3ce-1f00-0000-a9f6-d5bcd7140000 pid=5335 execve guuid=80560dd0-1f00-0000-a9f6-d5bcd9140000 pid=5337 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=80560dd0-1f00-0000-a9f6-d5bcd9140000 pid=5337 execve guuid=60ba36d1-1f00-0000-a9f6-d5bcdb140000 pid=5339 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=60ba36d1-1f00-0000-a9f6-d5bcdb140000 pid=5339 execve guuid=0af7f0d2-1f00-0000-a9f6-d5bcdd140000 pid=5341 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=0af7f0d2-1f00-0000-a9f6-d5bcdd140000 pid=5341 execve guuid=473980d4-1f00-0000-a9f6-d5bcdf140000 pid=5343 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=473980d4-1f00-0000-a9f6-d5bcdf140000 pid=5343 execve guuid=62a32603-2100-0000-a9f6-d5bce1140000 pid=5345 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=62a32603-2100-0000-a9f6-d5bce1140000 pid=5345 execve guuid=8e7b2a08-2100-0000-a9f6-d5bce3140000 pid=5347 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=8e7b2a08-2100-0000-a9f6-d5bce3140000 pid=5347 execve guuid=62884209-2100-0000-a9f6-d5bce5140000 pid=5349 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=62884209-2100-0000-a9f6-d5bce5140000 pid=5349 execve guuid=bc40d40a-2100-0000-a9f6-d5bce7140000 pid=5351 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=bc40d40a-2100-0000-a9f6-d5bce7140000 pid=5351 execve guuid=4526aa0c-2100-0000-a9f6-d5bce9140000 pid=5353 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=4526aa0c-2100-0000-a9f6-d5bce9140000 pid=5353 execve guuid=c146310e-2100-0000-a9f6-d5bceb140000 pid=5355 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c146310e-2100-0000-a9f6-d5bceb140000 pid=5355 execve guuid=8f289d0f-2100-0000-a9f6-d5bced140000 pid=5357 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=8f289d0f-2100-0000-a9f6-d5bced140000 pid=5357 execve guuid=3667fc10-2100-0000-a9f6-d5bcef140000 pid=5359 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=3667fc10-2100-0000-a9f6-d5bcef140000 pid=5359 execve guuid=6ca76e12-2100-0000-a9f6-d5bcf1140000 pid=5361 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=6ca76e12-2100-0000-a9f6-d5bcf1140000 pid=5361 execve guuid=e1659a42-2200-0000-a9f6-d5bcf3140000 pid=5363 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e1659a42-2200-0000-a9f6-d5bcf3140000 pid=5363 execve guuid=fdaff046-2200-0000-a9f6-d5bcf5140000 pid=5365 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=fdaff046-2200-0000-a9f6-d5bcf5140000 pid=5365 execve guuid=02df0e48-2200-0000-a9f6-d5bcf7140000 pid=5367 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=02df0e48-2200-0000-a9f6-d5bcf7140000 pid=5367 execve guuid=a768fc49-2200-0000-a9f6-d5bcf9140000 pid=5369 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a768fc49-2200-0000-a9f6-d5bcf9140000 pid=5369 execve guuid=952ddd4b-2200-0000-a9f6-d5bcfb140000 pid=5371 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=952ddd4b-2200-0000-a9f6-d5bcfb140000 pid=5371 execve guuid=66fa934d-2200-0000-a9f6-d5bcfd140000 pid=5373 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=66fa934d-2200-0000-a9f6-d5bcfd140000 pid=5373 execve guuid=52aa554f-2200-0000-a9f6-d5bcff140000 pid=5375 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=52aa554f-2200-0000-a9f6-d5bcff140000 pid=5375 execve guuid=c45c0d51-2200-0000-a9f6-d5bc01150000 pid=5377 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c45c0d51-2200-0000-a9f6-d5bc01150000 pid=5377 execve guuid=5e02cf52-2200-0000-a9f6-d5bc03150000 pid=5379 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5e02cf52-2200-0000-a9f6-d5bc03150000 pid=5379 execve guuid=f06cff82-2300-0000-a9f6-d5bc05150000 pid=5381 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=f06cff82-2300-0000-a9f6-d5bc05150000 pid=5381 execve guuid=a8f0d987-2300-0000-a9f6-d5bc07150000 pid=5383 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a8f0d987-2300-0000-a9f6-d5bc07150000 pid=5383 execve guuid=e8c36989-2300-0000-a9f6-d5bc09150000 pid=5385 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e8c36989-2300-0000-a9f6-d5bc09150000 pid=5385 execve guuid=5b83338b-2300-0000-a9f6-d5bc0b150000 pid=5387 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5b83338b-2300-0000-a9f6-d5bc0b150000 pid=5387 execve guuid=75fd0c8d-2300-0000-a9f6-d5bc0d150000 pid=5389 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=75fd0c8d-2300-0000-a9f6-d5bc0d150000 pid=5389 execve guuid=7f09eb8e-2300-0000-a9f6-d5bc0f150000 pid=5391 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=7f09eb8e-2300-0000-a9f6-d5bc0f150000 pid=5391 execve guuid=722e9e90-2300-0000-a9f6-d5bc11150000 pid=5393 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=722e9e90-2300-0000-a9f6-d5bc11150000 pid=5393 execve guuid=6d126392-2300-0000-a9f6-d5bc13150000 pid=5395 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=6d126392-2300-0000-a9f6-d5bc13150000 pid=5395 execve guuid=52fa3094-2300-0000-a9f6-d5bc15150000 pid=5397 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=52fa3094-2300-0000-a9f6-d5bc15150000 pid=5397 execve guuid=ad3bcdc3-2400-0000-a9f6-d5bc17150000 pid=5399 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=ad3bcdc3-2400-0000-a9f6-d5bc17150000 pid=5399 execve guuid=96d4a1c8-2400-0000-a9f6-d5bc19150000 pid=5401 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=96d4a1c8-2400-0000-a9f6-d5bc19150000 pid=5401 execve guuid=0fc159ca-2400-0000-a9f6-d5bc1b150000 pid=5403 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=0fc159ca-2400-0000-a9f6-d5bc1b150000 pid=5403 execve guuid=803113cc-2400-0000-a9f6-d5bc1d150000 pid=5405 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=803113cc-2400-0000-a9f6-d5bc1d150000 pid=5405 execve guuid=7e4dc7cd-2400-0000-a9f6-d5bc1f150000 pid=5407 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=7e4dc7cd-2400-0000-a9f6-d5bc1f150000 pid=5407 execve guuid=f16794cf-2400-0000-a9f6-d5bc21150000 pid=5409 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=f16794cf-2400-0000-a9f6-d5bc21150000 pid=5409 execve guuid=e7e866d1-2400-0000-a9f6-d5bc23150000 pid=5411 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e7e866d1-2400-0000-a9f6-d5bc23150000 pid=5411 execve guuid=93885bd3-2400-0000-a9f6-d5bc25150000 pid=5413 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=93885bd3-2400-0000-a9f6-d5bc25150000 pid=5413 execve guuid=fbaa18d5-2400-0000-a9f6-d5bc27150000 pid=5415 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=fbaa18d5-2400-0000-a9f6-d5bc27150000 pid=5415 execve guuid=d11e7c04-2600-0000-a9f6-d5bc29150000 pid=5417 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=d11e7c04-2600-0000-a9f6-d5bc29150000 pid=5417 execve guuid=e1ec0709-2600-0000-a9f6-d5bc2b150000 pid=5419 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e1ec0709-2600-0000-a9f6-d5bc2b150000 pid=5419 execve guuid=b123790a-2600-0000-a9f6-d5bc2d150000 pid=5421 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=b123790a-2600-0000-a9f6-d5bc2d150000 pid=5421 execve guuid=c8e6b20b-2600-0000-a9f6-d5bc2f150000 pid=5423 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c8e6b20b-2600-0000-a9f6-d5bc2f150000 pid=5423 execve guuid=e26c4a0d-2600-0000-a9f6-d5bc31150000 pid=5425 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e26c4a0d-2600-0000-a9f6-d5bc31150000 pid=5425 execve guuid=5b59140f-2600-0000-a9f6-d5bc33150000 pid=5427 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5b59140f-2600-0000-a9f6-d5bc33150000 pid=5427 execve guuid=3f79d710-2600-0000-a9f6-d5bc35150000 pid=5429 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=3f79d710-2600-0000-a9f6-d5bc35150000 pid=5429 execve guuid=25f0b212-2600-0000-a9f6-d5bc37150000 pid=5431 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=25f0b212-2600-0000-a9f6-d5bc37150000 pid=5431 execve guuid=07f6b914-2600-0000-a9f6-d5bc39150000 pid=5433 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=07f6b914-2600-0000-a9f6-d5bc39150000 pid=5433 execve guuid=e568fa44-2700-0000-a9f6-d5bc3c150000 pid=5436 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=e568fa44-2700-0000-a9f6-d5bc3c150000 pid=5436 execve guuid=d48e8347-2700-0000-a9f6-d5bc3e150000 pid=5438 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=d48e8347-2700-0000-a9f6-d5bc3e150000 pid=5438 execve guuid=74605948-2700-0000-a9f6-d5bc40150000 pid=5440 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=74605948-2700-0000-a9f6-d5bc40150000 pid=5440 execve guuid=74ae2b49-2700-0000-a9f6-d5bc42150000 pid=5442 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=74ae2b49-2700-0000-a9f6-d5bc42150000 pid=5442 execve guuid=d889024a-2700-0000-a9f6-d5bc44150000 pid=5444 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=d889024a-2700-0000-a9f6-d5bc44150000 pid=5444 execve guuid=17d2cf4a-2700-0000-a9f6-d5bc46150000 pid=5446 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=17d2cf4a-2700-0000-a9f6-d5bc46150000 pid=5446 execve guuid=5b68974b-2700-0000-a9f6-d5bc48150000 pid=5448 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=5b68974b-2700-0000-a9f6-d5bc48150000 pid=5448 execve guuid=09b1794c-2700-0000-a9f6-d5bc4a150000 pid=5450 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=09b1794c-2700-0000-a9f6-d5bc4a150000 pid=5450 execve guuid=c19b8a4d-2700-0000-a9f6-d5bc4c150000 pid=5452 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=c19b8a4d-2700-0000-a9f6-d5bc4c150000 pid=5452 execve guuid=a1ac667b-2800-0000-a9f6-d5bc50150000 pid=5456 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=a1ac667b-2800-0000-a9f6-d5bc50150000 pid=5456 execve guuid=18c2087e-2800-0000-a9f6-d5bc52150000 pid=5458 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=18c2087e-2800-0000-a9f6-d5bc52150000 pid=5458 execve guuid=db9eba7f-2800-0000-a9f6-d5bc54150000 pid=5460 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=db9eba7f-2800-0000-a9f6-d5bc54150000 pid=5460 execve guuid=f31fbc80-2800-0000-a9f6-d5bc56150000 pid=5462 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=f31fbc80-2800-0000-a9f6-d5bc56150000 pid=5462 execve guuid=95f53d82-2800-0000-a9f6-d5bc58150000 pid=5464 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=95f53d82-2800-0000-a9f6-d5bc58150000 pid=5464 execve guuid=90a06b83-2800-0000-a9f6-d5bc5a150000 pid=5466 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=90a06b83-2800-0000-a9f6-d5bc5a150000 pid=5466 execve guuid=bf6a4884-2800-0000-a9f6-d5bc5c150000 pid=5468 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=bf6a4884-2800-0000-a9f6-d5bc5c150000 pid=5468 execve guuid=18fd2885-2800-0000-a9f6-d5bc5e150000 pid=5470 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=18fd2885-2800-0000-a9f6-d5bc5e150000 pid=5470 execve guuid=52d40886-2800-0000-a9f6-d5bc60150000 pid=5472 /usr/bin/dash guuid=4294d89c-1a00-0000-a9f6-d5bc6d0b0000 pid=2925->guuid=52d40886-2800-0000-a9f6-d5bc60150000 pid=5472 execve guuid=2755df9d-1a00-0000-a9f6-d5bc720b0000 pid=2930 /usr/bin/wget dns net send-data guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926->guuid=2755df9d-1a00-0000-a9f6-d5bc720b0000 pid=2930 execve guuid=5df067a5-1a00-0000-a9f6-d5bc810b0000 pid=2945 /usr/bin/chmod guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926->guuid=5df067a5-1a00-0000-a9f6-d5bc810b0000 pid=2945 execve guuid=c7d59aa5-1a00-0000-a9f6-d5bc820b0000 pid=2946 /home/sandbox/..... guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926->guuid=c7d59aa5-1a00-0000-a9f6-d5bc820b0000 pid=2946 execve guuid=51245da6-1a00-0000-a9f6-d5bc840b0000 pid=2948 /usr/bin/rm delete-file guuid=6832dd9c-1a00-0000-a9f6-d5bc6e0b0000 pid=2926->guuid=51245da6-1a00-0000-a9f6-d5bc840b0000 pid=2948 execve guuid=1308ff9c-1a00-0000-a9f6-d5bc710b0000 pid=2929 /tmp/sample.bin net send-data zombie guuid=6897e69c-1a00-0000-a9f6-d5bc700b0000 pid=2928->guuid=1308ff9c-1a00-0000-a9f6-d5bc710b0000 pid=2929 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=1308ff9c-1a00-0000-a9f6-d5bc710b0000 pid=2929->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B guuid=3c767a35-2700-0000-a9f6-d5bc3b150000 pid=5435 /tmp/sample.bin send-data guuid=1308ff9c-1a00-0000-a9f6-d5bc710b0000 pid=2929->guuid=3c767a35-2700-0000-a9f6-d5bc3b150000 pid=5435 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=2755df9d-1a00-0000-a9f6-d5bc720b0000 pid=2930->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=5900a1cf-1a00-0000-a9f6-d5bce60b0000 pid=3046 /usr/bin/pgrep guuid=a47c6dcf-1a00-0000-a9f6-d5bce50b0000 pid=3045->guuid=5900a1cf-1a00-0000-a9f6-d5bce60b0000 pid=3046 execve guuid=4e768cd2-1a00-0000-a9f6-d5bcf10b0000 pid=3057 /usr/bin/killall guuid=5b6360d2-1a00-0000-a9f6-d5bcef0b0000 pid=3055->guuid=4e768cd2-1a00-0000-a9f6-d5bcf10b0000 pid=3057 execve guuid=c040dfd3-1a00-0000-a9f6-d5bcf80b0000 pid=3064 /usr/bin/killall guuid=e9f998d3-1a00-0000-a9f6-d5bcf60b0000 pid=3062->guuid=c040dfd3-1a00-0000-a9f6-d5bcf80b0000 pid=3064 execve guuid=9d210dd5-1a00-0000-a9f6-d5bcfd0b0000 pid=3069 /usr/bin/killall guuid=4cb1cbd4-1a00-0000-a9f6-d5bcfb0b0000 pid=3067->guuid=9d210dd5-1a00-0000-a9f6-d5bcfd0b0000 pid=3069 execve guuid=19514ed6-1a00-0000-a9f6-d5bc020c0000 pid=3074 /usr/bin/killall guuid=606203d6-1a00-0000-a9f6-d5bc000c0000 pid=3072->guuid=19514ed6-1a00-0000-a9f6-d5bc020c0000 pid=3074 execve guuid=f4b062d7-1a00-0000-a9f6-d5bc070c0000 pid=3079 /usr/bin/killall guuid=e8a42fd7-1a00-0000-a9f6-d5bc050c0000 pid=3077->guuid=f4b062d7-1a00-0000-a9f6-d5bc070c0000 pid=3079 execve guuid=5fc801d9-1a00-0000-a9f6-d5bc0d0c0000 pid=3085 /usr/bin/killall guuid=0908c2d8-1a00-0000-a9f6-d5bc0b0c0000 pid=3083->guuid=5fc801d9-1a00-0000-a9f6-d5bc0d0c0000 pid=3085 execve guuid=265884da-1a00-0000-a9f6-d5bc130c0000 pid=3091 /usr/bin/killall guuid=bc4545da-1a00-0000-a9f6-d5bc120c0000 pid=3090->guuid=265884da-1a00-0000-a9f6-d5bc130c0000 pid=3091 execve guuid=6207fcdb-1a00-0000-a9f6-d5bc190c0000 pid=3097 /usr/bin/killall guuid=a1ded2db-1a00-0000-a9f6-d5bc170c0000 pid=3095->guuid=6207fcdb-1a00-0000-a9f6-d5bc190c0000 pid=3097 execve guuid=9e20e709-1c00-0000-a9f6-d5bc430e0000 pid=3651 /usr/bin/pgrep guuid=85beb409-1c00-0000-a9f6-d5bc410e0000 pid=3649->guuid=9e20e709-1c00-0000-a9f6-d5bc430e0000 pid=3651 execve guuid=5e2f590c-1c00-0000-a9f6-d5bc4e0e0000 pid=3662 /usr/bin/killall guuid=57872b0c-1c00-0000-a9f6-d5bc4c0e0000 pid=3660->guuid=5e2f590c-1c00-0000-a9f6-d5bc4e0e0000 pid=3662 execve guuid=9ab3b60d-1c00-0000-a9f6-d5bc590e0000 pid=3673 /usr/bin/killall guuid=91ca750d-1c00-0000-a9f6-d5bc550e0000 pid=3669->guuid=9ab3b60d-1c00-0000-a9f6-d5bc590e0000 pid=3673 execve guuid=4fc2b00e-1c00-0000-a9f6-d5bc5e0e0000 pid=3678 /usr/bin/killall guuid=4dcb710e-1c00-0000-a9f6-d5bc5c0e0000 pid=3676->guuid=4fc2b00e-1c00-0000-a9f6-d5bc5e0e0000 pid=3678 execve guuid=d39fd70f-1c00-0000-a9f6-d5bc640e0000 pid=3684 /usr/bin/killall guuid=a9fea70f-1c00-0000-a9f6-d5bc630e0000 pid=3683->guuid=d39fd70f-1c00-0000-a9f6-d5bc640e0000 pid=3684 execve guuid=0ebcf510-1c00-0000-a9f6-d5bc6b0e0000 pid=3691 /usr/bin/killall guuid=3a67a810-1c00-0000-a9f6-d5bc690e0000 pid=3689->guuid=0ebcf510-1c00-0000-a9f6-d5bc6b0e0000 pid=3691 execve guuid=c1667112-1c00-0000-a9f6-d5bc730e0000 pid=3699 /usr/bin/killall guuid=fe234312-1c00-0000-a9f6-d5bc710e0000 pid=3697->guuid=c1667112-1c00-0000-a9f6-d5bc730e0000 pid=3699 execve guuid=f8f23d13-1c00-0000-a9f6-d5bc770e0000 pid=3703 /usr/bin/killall guuid=178d1513-1c00-0000-a9f6-d5bc750e0000 pid=3701->guuid=f8f23d13-1c00-0000-a9f6-d5bc770e0000 pid=3703 execve guuid=cc129714-1c00-0000-a9f6-d5bc7e0e0000 pid=3710 /usr/bin/killall guuid=11336b14-1c00-0000-a9f6-d5bc7b0e0000 pid=3707->guuid=cc129714-1c00-0000-a9f6-d5bc7e0e0000 pid=3710 execve guuid=f62f7942-1d00-0000-a9f6-d5bc90120000 pid=4752 /usr/bin/pgrep guuid=b33e4342-1d00-0000-a9f6-d5bc8f120000 pid=4751->guuid=f62f7942-1d00-0000-a9f6-d5bc90120000 pid=4752 execve guuid=c7a2f146-1d00-0000-a9f6-d5bca0120000 pid=4768 /usr/bin/killall guuid=ee13bd46-1d00-0000-a9f6-d5bc9f120000 pid=4767->guuid=c7a2f146-1d00-0000-a9f6-d5bca0120000 pid=4768 execve guuid=e887f247-1d00-0000-a9f6-d5bca8120000 pid=4776 /usr/bin/killall guuid=c84cab47-1d00-0000-a9f6-d5bca7120000 pid=4775->guuid=e887f247-1d00-0000-a9f6-d5bca8120000 pid=4776 execve guuid=d988dd48-1d00-0000-a9f6-d5bcaf120000 pid=4783 /usr/bin/killall guuid=6b59b248-1d00-0000-a9f6-d5bcae120000 pid=4782->guuid=d988dd48-1d00-0000-a9f6-d5bcaf120000 pid=4783 execve guuid=fe73c249-1d00-0000-a9f6-d5bcb6120000 pid=4790 /usr/bin/killall guuid=740c9949-1d00-0000-a9f6-d5bcb4120000 pid=4788->guuid=fe73c249-1d00-0000-a9f6-d5bcb6120000 pid=4790 execve guuid=20c3b24a-1d00-0000-a9f6-d5bcba120000 pid=4794 /usr/bin/killall guuid=4ab57d4a-1d00-0000-a9f6-d5bcb9120000 pid=4793->guuid=20c3b24a-1d00-0000-a9f6-d5bcba120000 pid=4794 execve guuid=78df034c-1d00-0000-a9f6-d5bcc1120000 pid=4801 /usr/bin/killall guuid=c4b5c14b-1d00-0000-a9f6-d5bcbf120000 pid=4799->guuid=78df034c-1d00-0000-a9f6-d5bcc1120000 pid=4801 execve guuid=487bc34d-1d00-0000-a9f6-d5bcc4120000 pid=4804 /usr/bin/killall guuid=1def774d-1d00-0000-a9f6-d5bcc3120000 pid=4803->guuid=487bc34d-1d00-0000-a9f6-d5bcc4120000 pid=4804 execve guuid=de1d3f4f-1d00-0000-a9f6-d5bcc6120000 pid=4806 /usr/bin/killall guuid=6e5dfe4e-1d00-0000-a9f6-d5bcc5120000 pid=4805->guuid=de1d3f4f-1d00-0000-a9f6-d5bcc6120000 pid=4806 execve guuid=49ebc68e-1e00-0000-a9f6-d5bcb8140000 pid=5304 /usr/bin/pgrep guuid=e9d3958e-1e00-0000-a9f6-d5bcb7140000 pid=5303->guuid=49ebc68e-1e00-0000-a9f6-d5bcb8140000 pid=5304 execve guuid=e44c9693-1e00-0000-a9f6-d5bcbb140000 pid=5307 /usr/bin/killall guuid=30686b93-1e00-0000-a9f6-d5bcba140000 pid=5306->guuid=e44c9693-1e00-0000-a9f6-d5bcbb140000 pid=5307 execve guuid=68037494-1e00-0000-a9f6-d5bcbd140000 pid=5309 /usr/bin/killall guuid=f2144194-1e00-0000-a9f6-d5bcbc140000 pid=5308->guuid=68037494-1e00-0000-a9f6-d5bcbd140000 pid=5309 execve guuid=eeda4a95-1e00-0000-a9f6-d5bcbf140000 pid=5311 /usr/bin/killall guuid=a67e2095-1e00-0000-a9f6-d5bcbe140000 pid=5310->guuid=eeda4a95-1e00-0000-a9f6-d5bcbf140000 pid=5311 execve guuid=d7311d96-1e00-0000-a9f6-d5bcc1140000 pid=5313 /usr/bin/killall guuid=47cdf495-1e00-0000-a9f6-d5bcc0140000 pid=5312->guuid=d7311d96-1e00-0000-a9f6-d5bcc1140000 pid=5313 execve guuid=e009f596-1e00-0000-a9f6-d5bcc3140000 pid=5315 /usr/bin/killall guuid=f686c896-1e00-0000-a9f6-d5bcc2140000 pid=5314->guuid=e009f596-1e00-0000-a9f6-d5bcc3140000 pid=5315 execve guuid=7e4acb97-1e00-0000-a9f6-d5bcc5140000 pid=5317 /usr/bin/killall guuid=358ca197-1e00-0000-a9f6-d5bcc4140000 pid=5316->guuid=7e4acb97-1e00-0000-a9f6-d5bcc5140000 pid=5317 execve guuid=19099798-1e00-0000-a9f6-d5bcc7140000 pid=5319 /usr/bin/killall guuid=b13f6c98-1e00-0000-a9f6-d5bcc6140000 pid=5318->guuid=19099798-1e00-0000-a9f6-d5bcc7140000 pid=5319 execve guuid=1f807199-1e00-0000-a9f6-d5bccb140000 pid=5323 /usr/bin/killall guuid=bc304599-1e00-0000-a9f6-d5bcca140000 pid=5322->guuid=1f807199-1e00-0000-a9f6-d5bccb140000 pid=5323 execve guuid=65ca7bc8-1f00-0000-a9f6-d5bcd0140000 pid=5328 /usr/bin/pgrep guuid=d5fd12c8-1f00-0000-a9f6-d5bccf140000 pid=5327->guuid=65ca7bc8-1f00-0000-a9f6-d5bcd0140000 pid=5328 execve guuid=40d8f0cb-1f00-0000-a9f6-d5bcd2140000 pid=5330 /usr/bin/killall guuid=a4ebc0cb-1f00-0000-a9f6-d5bcd1140000 pid=5329->guuid=40d8f0cb-1f00-0000-a9f6-d5bcd2140000 pid=5330 execve guuid=da63c7cc-1f00-0000-a9f6-d5bcd4140000 pid=5332 /usr/bin/killall guuid=3daa9bcc-1f00-0000-a9f6-d5bcd3140000 pid=5331->guuid=da63c7cc-1f00-0000-a9f6-d5bcd4140000 pid=5332 execve guuid=57fa1fce-1f00-0000-a9f6-d5bcd6140000 pid=5334 /usr/bin/killall guuid=5a22d9cd-1f00-0000-a9f6-d5bcd5140000 pid=5333->guuid=57fa1fce-1f00-0000-a9f6-d5bcd6140000 pid=5334 execve guuid=653639cf-1f00-0000-a9f6-d5bcd8140000 pid=5336 /usr/bin/killall guuid=68f5e3ce-1f00-0000-a9f6-d5bcd7140000 pid=5335->guuid=653639cf-1f00-0000-a9f6-d5bcd8140000 pid=5336 execve guuid=9a2d65d0-1f00-0000-a9f6-d5bcda140000 pid=5338 /usr/bin/killall guuid=80560dd0-1f00-0000-a9f6-d5bcd9140000 pid=5337->guuid=9a2d65d0-1f00-0000-a9f6-d5bcda140000 pid=5338 execve guuid=3a2c67d1-1f00-0000-a9f6-d5bcdc140000 pid=5340 /usr/bin/killall guuid=60ba36d1-1f00-0000-a9f6-d5bcdb140000 pid=5339->guuid=3a2c67d1-1f00-0000-a9f6-d5bcdc140000 pid=5340 execve guuid=df7a28d3-1f00-0000-a9f6-d5bcde140000 pid=5342 /usr/bin/killall guuid=0af7f0d2-1f00-0000-a9f6-d5bcdd140000 pid=5341->guuid=df7a28d3-1f00-0000-a9f6-d5bcde140000 pid=5342 execve guuid=c095b2d4-1f00-0000-a9f6-d5bce0140000 pid=5344 /usr/bin/killall guuid=473980d4-1f00-0000-a9f6-d5bcdf140000 pid=5343->guuid=c095b2d4-1f00-0000-a9f6-d5bce0140000 pid=5344 execve guuid=2eb08c03-2100-0000-a9f6-d5bce2140000 pid=5346 /usr/bin/pgrep guuid=62a32603-2100-0000-a9f6-d5bce1140000 pid=5345->guuid=2eb08c03-2100-0000-a9f6-d5bce2140000 pid=5346 execve guuid=c7c77b08-2100-0000-a9f6-d5bce4140000 pid=5348 /usr/bin/killall guuid=8e7b2a08-2100-0000-a9f6-d5bce3140000 pid=5347->guuid=c7c77b08-2100-0000-a9f6-d5bce4140000 pid=5348 execve guuid=dea37309-2100-0000-a9f6-d5bce6140000 pid=5350 /usr/bin/killall guuid=62884209-2100-0000-a9f6-d5bce5140000 pid=5349->guuid=dea37309-2100-0000-a9f6-d5bce6140000 pid=5350 execve guuid=23461e0b-2100-0000-a9f6-d5bce8140000 pid=5352 /usr/bin/killall guuid=bc40d40a-2100-0000-a9f6-d5bce7140000 pid=5351->guuid=23461e0b-2100-0000-a9f6-d5bce8140000 pid=5352 execve guuid=89d4ee0c-2100-0000-a9f6-d5bcea140000 pid=5354 /usr/bin/killall guuid=4526aa0c-2100-0000-a9f6-d5bce9140000 pid=5353->guuid=89d4ee0c-2100-0000-a9f6-d5bcea140000 pid=5354 execve guuid=38b0870e-2100-0000-a9f6-d5bcec140000 pid=5356 /usr/bin/killall guuid=c146310e-2100-0000-a9f6-d5bceb140000 pid=5355->guuid=38b0870e-2100-0000-a9f6-d5bcec140000 pid=5356 execve guuid=a2a3f10f-2100-0000-a9f6-d5bcee140000 pid=5358 /usr/bin/killall guuid=8f289d0f-2100-0000-a9f6-d5bced140000 pid=5357->guuid=a2a3f10f-2100-0000-a9f6-d5bcee140000 pid=5358 execve guuid=0c115d11-2100-0000-a9f6-d5bcf0140000 pid=5360 /usr/bin/killall guuid=3667fc10-2100-0000-a9f6-d5bcef140000 pid=5359->guuid=0c115d11-2100-0000-a9f6-d5bcf0140000 pid=5360 execve guuid=e10acc12-2100-0000-a9f6-d5bcf2140000 pid=5362 /usr/bin/killall guuid=6ca76e12-2100-0000-a9f6-d5bcf1140000 pid=5361->guuid=e10acc12-2100-0000-a9f6-d5bcf2140000 pid=5362 execve guuid=bb470b43-2200-0000-a9f6-d5bcf4140000 pid=5364 /usr/bin/pgrep guuid=e1659a42-2200-0000-a9f6-d5bcf3140000 pid=5363->guuid=bb470b43-2200-0000-a9f6-d5bcf4140000 pid=5364 execve guuid=b01b4847-2200-0000-a9f6-d5bcf6140000 pid=5366 /usr/bin/killall guuid=fdaff046-2200-0000-a9f6-d5bcf5140000 pid=5365->guuid=b01b4847-2200-0000-a9f6-d5bcf6140000 pid=5366 execve guuid=e11b6448-2200-0000-a9f6-d5bcf8140000 pid=5368 /usr/bin/killall guuid=02df0e48-2200-0000-a9f6-d5bcf7140000 pid=5367->guuid=e11b6448-2200-0000-a9f6-d5bcf8140000 pid=5368 execve guuid=8cac654a-2200-0000-a9f6-d5bcfa140000 pid=5370 /usr/bin/killall guuid=a768fc49-2200-0000-a9f6-d5bcf9140000 pid=5369->guuid=8cac654a-2200-0000-a9f6-d5bcfa140000 pid=5370 execve guuid=867e304c-2200-0000-a9f6-d5bcfc140000 pid=5372 /usr/bin/killall guuid=952ddd4b-2200-0000-a9f6-d5bcfb140000 pid=5371->guuid=867e304c-2200-0000-a9f6-d5bcfc140000 pid=5372 execve guuid=f1d9ef4d-2200-0000-a9f6-d5bcfe140000 pid=5374 /usr/bin/killall guuid=66fa934d-2200-0000-a9f6-d5bcfd140000 pid=5373->guuid=f1d9ef4d-2200-0000-a9f6-d5bcfe140000 pid=5374 execve guuid=4231b54f-2200-0000-a9f6-d5bc00150000 pid=5376 /usr/bin/killall guuid=52aa554f-2200-0000-a9f6-d5bcff140000 pid=5375->guuid=4231b54f-2200-0000-a9f6-d5bc00150000 pid=5376 execve guuid=c2116051-2200-0000-a9f6-d5bc02150000 pid=5378 /usr/bin/killall guuid=c45c0d51-2200-0000-a9f6-d5bc01150000 pid=5377->guuid=c2116051-2200-0000-a9f6-d5bc02150000 pid=5378 execve guuid=2e463353-2200-0000-a9f6-d5bc04150000 pid=5380 /usr/bin/killall guuid=5e02cf52-2200-0000-a9f6-d5bc03150000 pid=5379->guuid=2e463353-2200-0000-a9f6-d5bc04150000 pid=5380 execve guuid=66485d83-2300-0000-a9f6-d5bc06150000 pid=5382 /usr/bin/pgrep guuid=f06cff82-2300-0000-a9f6-d5bc05150000 pid=5381->guuid=66485d83-2300-0000-a9f6-d5bc06150000 pid=5382 execve guuid=108e3788-2300-0000-a9f6-d5bc08150000 pid=5384 /usr/bin/killall guuid=a8f0d987-2300-0000-a9f6-d5bc07150000 pid=5383->guuid=108e3788-2300-0000-a9f6-d5bc08150000 pid=5384 execve guuid=1da0b389-2300-0000-a9f6-d5bc0a150000 pid=5386 /usr/bin/killall guuid=e8c36989-2300-0000-a9f6-d5bc09150000 pid=5385->guuid=1da0b389-2300-0000-a9f6-d5bc0a150000 pid=5386 execve guuid=0e7c8e8b-2300-0000-a9f6-d5bc0c150000 pid=5388 /usr/bin/killall guuid=5b83338b-2300-0000-a9f6-d5bc0b150000 pid=5387->guuid=0e7c8e8b-2300-0000-a9f6-d5bc0c150000 pid=5388 execve guuid=af206e8d-2300-0000-a9f6-d5bc0e150000 pid=5390 /usr/bin/killall guuid=75fd0c8d-2300-0000-a9f6-d5bc0d150000 pid=5389->guuid=af206e8d-2300-0000-a9f6-d5bc0e150000 pid=5390 execve guuid=16d03e8f-2300-0000-a9f6-d5bc10150000 pid=5392 /usr/bin/killall guuid=7f09eb8e-2300-0000-a9f6-d5bc0f150000 pid=5391->guuid=16d03e8f-2300-0000-a9f6-d5bc10150000 pid=5392 execve guuid=4328f490-2300-0000-a9f6-d5bc12150000 pid=5394 /usr/bin/killall guuid=722e9e90-2300-0000-a9f6-d5bc11150000 pid=5393->guuid=4328f490-2300-0000-a9f6-d5bc12150000 pid=5394 execve guuid=0863ca92-2300-0000-a9f6-d5bc14150000 pid=5396 /usr/bin/killall guuid=6d126392-2300-0000-a9f6-d5bc13150000 pid=5395->guuid=0863ca92-2300-0000-a9f6-d5bc14150000 pid=5396 execve guuid=d0d48794-2300-0000-a9f6-d5bc16150000 pid=5398 /usr/bin/killall guuid=52fa3094-2300-0000-a9f6-d5bc15150000 pid=5397->guuid=d0d48794-2300-0000-a9f6-d5bc16150000 pid=5398 execve guuid=b2242fc4-2400-0000-a9f6-d5bc18150000 pid=5400 /usr/bin/pgrep guuid=ad3bcdc3-2400-0000-a9f6-d5bc17150000 pid=5399->guuid=b2242fc4-2400-0000-a9f6-d5bc18150000 pid=5400 execve guuid=ea70e9c8-2400-0000-a9f6-d5bc1a150000 pid=5402 /usr/bin/killall guuid=96d4a1c8-2400-0000-a9f6-d5bc19150000 pid=5401->guuid=ea70e9c8-2400-0000-a9f6-d5bc1a150000 pid=5402 execve guuid=4e61b2ca-2400-0000-a9f6-d5bc1c150000 pid=5404 /usr/bin/killall guuid=0fc159ca-2400-0000-a9f6-d5bc1b150000 pid=5403->guuid=4e61b2ca-2400-0000-a9f6-d5bc1c150000 pid=5404 execve guuid=17266ecc-2400-0000-a9f6-d5bc1e150000 pid=5406 /usr/bin/killall guuid=803113cc-2400-0000-a9f6-d5bc1d150000 pid=5405->guuid=17266ecc-2400-0000-a9f6-d5bc1e150000 pid=5406 execve guuid=2e062ace-2400-0000-a9f6-d5bc20150000 pid=5408 /usr/bin/killall guuid=7e4dc7cd-2400-0000-a9f6-d5bc1f150000 pid=5407->guuid=2e062ace-2400-0000-a9f6-d5bc20150000 pid=5408 execve guuid=6094ebcf-2400-0000-a9f6-d5bc22150000 pid=5410 /usr/bin/killall guuid=f16794cf-2400-0000-a9f6-d5bc21150000 pid=5409->guuid=6094ebcf-2400-0000-a9f6-d5bc22150000 pid=5410 execve guuid=a164d3d1-2400-0000-a9f6-d5bc24150000 pid=5412 /usr/bin/killall guuid=e7e866d1-2400-0000-a9f6-d5bc23150000 pid=5411->guuid=a164d3d1-2400-0000-a9f6-d5bc24150000 pid=5412 execve guuid=3795b9d3-2400-0000-a9f6-d5bc26150000 pid=5414 /usr/bin/killall guuid=93885bd3-2400-0000-a9f6-d5bc25150000 pid=5413->guuid=3795b9d3-2400-0000-a9f6-d5bc26150000 pid=5414 execve guuid=4a2d6fd5-2400-0000-a9f6-d5bc28150000 pid=5416 /usr/bin/killall guuid=fbaa18d5-2400-0000-a9f6-d5bc27150000 pid=5415->guuid=4a2d6fd5-2400-0000-a9f6-d5bc28150000 pid=5416 execve guuid=20bfe304-2600-0000-a9f6-d5bc2a150000 pid=5418 /usr/bin/pgrep guuid=d11e7c04-2600-0000-a9f6-d5bc29150000 pid=5417->guuid=20bfe304-2600-0000-a9f6-d5bc2a150000 pid=5418 execve guuid=7d6c3009-2600-0000-a9f6-d5bc2c150000 pid=5420 /usr/bin/killall guuid=e1ec0709-2600-0000-a9f6-d5bc2b150000 pid=5419->guuid=7d6c3009-2600-0000-a9f6-d5bc2c150000 pid=5420 execve guuid=bda8cd0a-2600-0000-a9f6-d5bc2e150000 pid=5422 /usr/bin/killall guuid=b123790a-2600-0000-a9f6-d5bc2d150000 pid=5421->guuid=bda8cd0a-2600-0000-a9f6-d5bc2e150000 pid=5422 execve guuid=db33ed0b-2600-0000-a9f6-d5bc30150000 pid=5424 /usr/bin/killall guuid=c8e6b20b-2600-0000-a9f6-d5bc2f150000 pid=5423->guuid=db33ed0b-2600-0000-a9f6-d5bc30150000 pid=5424 execve guuid=3048ad0d-2600-0000-a9f6-d5bc32150000 pid=5426 /usr/bin/killall guuid=e26c4a0d-2600-0000-a9f6-d5bc31150000 pid=5425->guuid=3048ad0d-2600-0000-a9f6-d5bc32150000 pid=5426 execve guuid=96f9640f-2600-0000-a9f6-d5bc34150000 pid=5428 /usr/bin/killall guuid=5b59140f-2600-0000-a9f6-d5bc33150000 pid=5427->guuid=96f9640f-2600-0000-a9f6-d5bc34150000 pid=5428 execve guuid=b0af4211-2600-0000-a9f6-d5bc36150000 pid=5430 /usr/bin/killall guuid=3f79d710-2600-0000-a9f6-d5bc35150000 pid=5429->guuid=b0af4211-2600-0000-a9f6-d5bc36150000 pid=5430 execve guuid=43480d13-2600-0000-a9f6-d5bc38150000 pid=5432 /usr/bin/killall guuid=25f0b212-2600-0000-a9f6-d5bc37150000 pid=5431->guuid=43480d13-2600-0000-a9f6-d5bc38150000 pid=5432 execve guuid=55ab3815-2600-0000-a9f6-d5bc3a150000 pid=5434 /usr/bin/killall guuid=07f6b914-2600-0000-a9f6-d5bc39150000 pid=5433->guuid=55ab3815-2600-0000-a9f6-d5bc3a150000 pid=5434 execve 13476252-6f37-5afe-8276-ccd5dcea14eb 76.38.239.116:80 guuid=3c767a35-2700-0000-a9f6-d5bc3b150000 pid=5435->13476252-6f37-5afe-8276-ccd5dcea14eb send: 4195328B guuid=bb432e45-2700-0000-a9f6-d5bc3d150000 pid=5437 /usr/bin/pgrep guuid=e568fa44-2700-0000-a9f6-d5bc3c150000 pid=5436->guuid=bb432e45-2700-0000-a9f6-d5bc3d150000 pid=5437 execve guuid=d1fcae47-2700-0000-a9f6-d5bc3f150000 pid=5439 /usr/bin/killall guuid=d48e8347-2700-0000-a9f6-d5bc3e150000 pid=5438->guuid=d1fcae47-2700-0000-a9f6-d5bc3f150000 pid=5439 execve guuid=ee268348-2700-0000-a9f6-d5bc41150000 pid=5441 /usr/bin/killall guuid=74605948-2700-0000-a9f6-d5bc40150000 pid=5440->guuid=ee268348-2700-0000-a9f6-d5bc41150000 pid=5441 execve guuid=e4545849-2700-0000-a9f6-d5bc43150000 pid=5443 /usr/bin/killall guuid=74ae2b49-2700-0000-a9f6-d5bc42150000 pid=5442->guuid=e4545849-2700-0000-a9f6-d5bc43150000 pid=5443 execve guuid=ad002f4a-2700-0000-a9f6-d5bc45150000 pid=5445 /usr/bin/killall guuid=d889024a-2700-0000-a9f6-d5bc44150000 pid=5444->guuid=ad002f4a-2700-0000-a9f6-d5bc45150000 pid=5445 execve guuid=a5ddf94a-2700-0000-a9f6-d5bc47150000 pid=5447 /usr/bin/killall guuid=17d2cf4a-2700-0000-a9f6-d5bc46150000 pid=5446->guuid=a5ddf94a-2700-0000-a9f6-d5bc47150000 pid=5447 execve guuid=3f12c54b-2700-0000-a9f6-d5bc49150000 pid=5449 /usr/bin/killall guuid=5b68974b-2700-0000-a9f6-d5bc48150000 pid=5448->guuid=3f12c54b-2700-0000-a9f6-d5bc49150000 pid=5449 execve guuid=45cca84c-2700-0000-a9f6-d5bc4b150000 pid=5451 /usr/bin/killall guuid=09b1794c-2700-0000-a9f6-d5bc4a150000 pid=5450->guuid=45cca84c-2700-0000-a9f6-d5bc4b150000 pid=5451 execve guuid=7718b64d-2700-0000-a9f6-d5bc4d150000 pid=5453 /usr/bin/killall guuid=c19b8a4d-2700-0000-a9f6-d5bc4c150000 pid=5452->guuid=7718b64d-2700-0000-a9f6-d5bc4d150000 pid=5453 execve guuid=5658b37b-2800-0000-a9f6-d5bc51150000 pid=5457 /usr/bin/pgrep guuid=a1ac667b-2800-0000-a9f6-d5bc50150000 pid=5456->guuid=5658b37b-2800-0000-a9f6-d5bc51150000 pid=5457 execve guuid=21df527e-2800-0000-a9f6-d5bc53150000 pid=5459 /usr/bin/killall guuid=18c2087e-2800-0000-a9f6-d5bc52150000 pid=5458->guuid=21df527e-2800-0000-a9f6-d5bc53150000 pid=5459 execve guuid=39a6ff7f-2800-0000-a9f6-d5bc55150000 pid=5461 /usr/bin/killall guuid=db9eba7f-2800-0000-a9f6-d5bc54150000 pid=5460->guuid=39a6ff7f-2800-0000-a9f6-d5bc55150000 pid=5461 execve guuid=70dae680-2800-0000-a9f6-d5bc57150000 pid=5463 /usr/bin/killall guuid=f31fbc80-2800-0000-a9f6-d5bc56150000 pid=5462->guuid=70dae680-2800-0000-a9f6-d5bc57150000 pid=5463 execve guuid=003d6782-2800-0000-a9f6-d5bc59150000 pid=5465 /usr/bin/killall guuid=95f53d82-2800-0000-a9f6-d5bc58150000 pid=5464->guuid=003d6782-2800-0000-a9f6-d5bc59150000 pid=5465 execve guuid=3b939483-2800-0000-a9f6-d5bc5b150000 pid=5467 /usr/bin/killall guuid=90a06b83-2800-0000-a9f6-d5bc5a150000 pid=5466->guuid=3b939483-2800-0000-a9f6-d5bc5b150000 pid=5467 execve guuid=fe087484-2800-0000-a9f6-d5bc5d150000 pid=5469 /usr/bin/killall guuid=bf6a4884-2800-0000-a9f6-d5bc5c150000 pid=5468->guuid=fe087484-2800-0000-a9f6-d5bc5d150000 pid=5469 execve guuid=1c854f85-2800-0000-a9f6-d5bc5f150000 pid=5471 /usr/bin/killall guuid=18fd2885-2800-0000-a9f6-d5bc5e150000 pid=5470->guuid=1c854f85-2800-0000-a9f6-d5bc5f150000 pid=5471 execve guuid=8b823586-2800-0000-a9f6-d5bc61150000 pid=5473 /usr/bin/killall guuid=52d40886-2800-0000-a9f6-d5bc60150000 pid=5472->guuid=8b823586-2800-0000-a9f6-d5bc61150000 pid=5473 execve
Result
Threat name:
Gafgyt, Mirai
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Yara detected Mirai
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734475 Sample: getty.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 37 206.123.128.67, 47100, 65481 LEASEWEB-USA-NYC-11US United States 2->37 39 gay.energy 2->39 41 daisy.ubuntu.com 2->41 43 Suricata IDS alerts for network traffic 2->43 45 Malicious sample detected (through community Yara rule) 2->45 47 Antivirus / Scanner detection for submitted sample 2->47 49 5 other signatures 2->49 9 getty.elf 2->9         started        signatures3 process4 signatures5 53 Opens /proc/net/* files useful for finding connected devices and routers 9->53 12 getty.elf 9->12         started        process6 process7 14 getty.elf sh 12->14         started        16 getty.elf sh 12->16         started        18 getty.elf sh 12->18         started        20 59 other processes 12->20 process8 22 sh killall 14->22         started        25 sh killall 16->25         started        27 sh killall 18->27         started        29 sh killall 20->29         started        31 sh killall 20->31         started        33 sh killall 20->33         started        35 56 other processes 20->35 signatures9 51 Terminates several processes with shell command 'killall' 22->51
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-12 05:05:25 UTC
File Type:
ELF32 Little (Exe)
AV detection:
22 of 38 (57.89%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_28a2fe0c Linux_Trojan_Gafgyt_c573932b Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_71e487ea Linux_Trojan_Gafgyt_7167d08f Linux_Trojan_Mirai_389ee3e9 elf_bashlite_auto Linux_Gafgyt_May_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_28a2fe0c
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_7167d08f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_71e487ea
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_c573932b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf e7fed3b06801890122be87fbac365b559a5d7ed3f2993dbfe3db70a7c6eddfd7

(this sample)

  
Delivery method
Distributed via web download

Comments