MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 edcb5dae889756267c1c1c2fdc0d4d0cc1c02240971500dcc0dcff28259a47ba. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Mirai


Vendor detections: 11


Intelligence 11 IOCs YARA 11 File information Comments

SHA256 hash: edcb5dae889756267c1c1c2fdc0d4d0cc1c02240971500dcc0dcff28259a47ba
SHA3-384 hash: cc323ee95b230b9148fe5e49c7a1a54c8802c31a2d9d6f432511dbb0182de4082afe2b0d9fa2790dcb1526fe4d8d0bfd
SHA1 hash: b2faa6fe44cabf3734af993e875a5c0baa2334e3
MD5 hash: e17e93b47db020a3a06505d3f8413606
humanhash: robert-seventeen-eleven-michigan
File name:getty
Download: download sample
Signature Mirai
File size:105'494 bytes
First seen:2025-07-12 19:36:23 UTC
Last seen:Never
File type: elf
MIME type:application/x-executable
ssdeep 3072:9XSpcwxU1KRC5ctlCNuIWXS/SCn9n/QmpFXthVnQaTemT:9XSPnU5gQ8rS/SSn/QmpFXthVnQaTemT
TLSH T1F5A33A42A745D673D14309F212A79B250532FEBB1E2A9E06F3697CB49F354C4B221FAC
telfhash t181315622943546142fb3a928acfd56b315322b2323596f71af26c5cc49360f1e93dd4f
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf gafgyt mirai

Intelligence


File Origin
# of uploads :
1
# of downloads :
14
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Kills processes
Launching a process
Connection attempt
Substitutes an application name
Verdict:
Unknown
Threat level:
  0/10
Confidence:
100%
Tags:
gcc
Status:
terminated
Behavior Graph:
%3 guuid=b507c81b-1900-0000-0fb0-8eaa17120000 pid=4631 /usr/bin/sudo guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639 /tmp/sample.bin net guuid=b507c81b-1900-0000-0fb0-8eaa17120000 pid=4631->guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639 execve 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644 /tmp/sample.bin zombie guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639->guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644 clone guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645 /usr/bin/dash zombie guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639->guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645 execve guuid=27d48b1e-1900-0000-0fb0-8eaa26120000 pid=4646 /tmp/sample.bin guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639->guuid=27d48b1e-1900-0000-0fb0-8eaa26120000 pid=4646 clone guuid=b58d901e-1900-0000-0fb0-8eaa27120000 pid=4647 /tmp/sample.bin guuid=f1c4591d-1900-0000-0fb0-8eaa1f120000 pid=4639->guuid=b58d901e-1900-0000-0fb0-8eaa27120000 pid=4647 clone guuid=e3461d51-1900-0000-0fb0-8eaad8120000 pid=4824 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e3461d51-1900-0000-0fb0-8eaad8120000 pid=4824 execve guuid=886c155a-1900-0000-0fb0-8eaaed120000 pid=4845 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=886c155a-1900-0000-0fb0-8eaaed120000 pid=4845 execve guuid=8c4c5a62-1900-0000-0fb0-8eaa05130000 pid=4869 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=8c4c5a62-1900-0000-0fb0-8eaa05130000 pid=4869 execve guuid=9e4c6263-1900-0000-0fb0-8eaa0b130000 pid=4875 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=9e4c6263-1900-0000-0fb0-8eaa0b130000 pid=4875 execve guuid=d3386764-1900-0000-0fb0-8eaa10130000 pid=4880 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d3386764-1900-0000-0fb0-8eaa10130000 pid=4880 execve guuid=ce606765-1900-0000-0fb0-8eaa16130000 pid=4886 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=ce606765-1900-0000-0fb0-8eaa16130000 pid=4886 execve guuid=30c46a66-1900-0000-0fb0-8eaa1a130000 pid=4890 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=30c46a66-1900-0000-0fb0-8eaa1a130000 pid=4890 execve guuid=eef86367-1900-0000-0fb0-8eaa20130000 pid=4896 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=eef86367-1900-0000-0fb0-8eaa20130000 pid=4896 execve guuid=2d825468-1900-0000-0fb0-8eaa26130000 pid=4902 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=2d825468-1900-0000-0fb0-8eaa26130000 pid=4902 execve guuid=e73dd995-1a00-0000-0fb0-8eaaac140000 pid=5292 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e73dd995-1a00-0000-0fb0-8eaaac140000 pid=5292 execve guuid=cadac59b-1a00-0000-0fb0-8eaaae140000 pid=5294 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=cadac59b-1a00-0000-0fb0-8eaaae140000 pid=5294 execve guuid=5b3f019d-1a00-0000-0fb0-8eaab0140000 pid=5296 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=5b3f019d-1a00-0000-0fb0-8eaab0140000 pid=5296 execve guuid=fc56469e-1a00-0000-0fb0-8eaab2140000 pid=5298 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=fc56469e-1a00-0000-0fb0-8eaab2140000 pid=5298 execve guuid=9bb78e9f-1a00-0000-0fb0-8eaab4140000 pid=5300 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=9bb78e9f-1a00-0000-0fb0-8eaab4140000 pid=5300 execve guuid=7b79d1a0-1a00-0000-0fb0-8eaab6140000 pid=5302 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=7b79d1a0-1a00-0000-0fb0-8eaab6140000 pid=5302 execve guuid=488b33a2-1a00-0000-0fb0-8eaab8140000 pid=5304 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=488b33a2-1a00-0000-0fb0-8eaab8140000 pid=5304 execve guuid=6aa773a3-1a00-0000-0fb0-8eaaba140000 pid=5306 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=6aa773a3-1a00-0000-0fb0-8eaaba140000 pid=5306 execve guuid=508ce5a4-1a00-0000-0fb0-8eaabc140000 pid=5308 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=508ce5a4-1a00-0000-0fb0-8eaabc140000 pid=5308 execve guuid=9abb68d5-1b00-0000-0fb0-8eaacb140000 pid=5323 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=9abb68d5-1b00-0000-0fb0-8eaacb140000 pid=5323 execve guuid=9d7483d8-1b00-0000-0fb0-8eaacd140000 pid=5325 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=9d7483d8-1b00-0000-0fb0-8eaacd140000 pid=5325 execve guuid=92b88dd9-1b00-0000-0fb0-8eaacf140000 pid=5327 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=92b88dd9-1b00-0000-0fb0-8eaacf140000 pid=5327 execve guuid=937f8eda-1b00-0000-0fb0-8eaad1140000 pid=5329 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=937f8eda-1b00-0000-0fb0-8eaad1140000 pid=5329 execve guuid=dcec9ddb-1b00-0000-0fb0-8eaad3140000 pid=5331 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=dcec9ddb-1b00-0000-0fb0-8eaad3140000 pid=5331 execve guuid=31e532dd-1b00-0000-0fb0-8eaad5140000 pid=5333 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=31e532dd-1b00-0000-0fb0-8eaad5140000 pid=5333 execve guuid=f776e1de-1b00-0000-0fb0-8eaad7140000 pid=5335 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=f776e1de-1b00-0000-0fb0-8eaad7140000 pid=5335 execve guuid=595691e0-1b00-0000-0fb0-8eaad9140000 pid=5337 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=595691e0-1b00-0000-0fb0-8eaad9140000 pid=5337 execve guuid=ad4e36e2-1b00-0000-0fb0-8eaadb140000 pid=5339 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=ad4e36e2-1b00-0000-0fb0-8eaadb140000 pid=5339 execve guuid=601a5b12-1d00-0000-0fb0-8eaadd140000 pid=5341 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=601a5b12-1d00-0000-0fb0-8eaadd140000 pid=5341 execve guuid=b3295c16-1d00-0000-0fb0-8eaadf140000 pid=5343 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=b3295c16-1d00-0000-0fb0-8eaadf140000 pid=5343 execve guuid=1422a817-1d00-0000-0fb0-8eaae1140000 pid=5345 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=1422a817-1d00-0000-0fb0-8eaae1140000 pid=5345 execve guuid=e4b2e718-1d00-0000-0fb0-8eaae3140000 pid=5347 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e4b2e718-1d00-0000-0fb0-8eaae3140000 pid=5347 execve guuid=b056291a-1d00-0000-0fb0-8eaae5140000 pid=5349 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=b056291a-1d00-0000-0fb0-8eaae5140000 pid=5349 execve guuid=4fc3ac1b-1d00-0000-0fb0-8eaae7140000 pid=5351 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=4fc3ac1b-1d00-0000-0fb0-8eaae7140000 pid=5351 execve guuid=2cf13b1d-1d00-0000-0fb0-8eaae9140000 pid=5353 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=2cf13b1d-1d00-0000-0fb0-8eaae9140000 pid=5353 execve guuid=d3f7801e-1d00-0000-0fb0-8eaaeb140000 pid=5355 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d3f7801e-1d00-0000-0fb0-8eaaeb140000 pid=5355 execve guuid=63270c20-1d00-0000-0fb0-8eaaed140000 pid=5357 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=63270c20-1d00-0000-0fb0-8eaaed140000 pid=5357 execve guuid=55a53150-1e00-0000-0fb0-8eaaef140000 pid=5359 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=55a53150-1e00-0000-0fb0-8eaaef140000 pid=5359 execve guuid=95b51454-1e00-0000-0fb0-8eaaf1140000 pid=5361 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=95b51454-1e00-0000-0fb0-8eaaf1140000 pid=5361 execve guuid=98466255-1e00-0000-0fb0-8eaaf3140000 pid=5363 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=98466255-1e00-0000-0fb0-8eaaf3140000 pid=5363 execve guuid=82efef56-1e00-0000-0fb0-8eaaf5140000 pid=5365 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=82efef56-1e00-0000-0fb0-8eaaf5140000 pid=5365 execve guuid=e6507a58-1e00-0000-0fb0-8eaaf7140000 pid=5367 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e6507a58-1e00-0000-0fb0-8eaaf7140000 pid=5367 execve guuid=cdd3c559-1e00-0000-0fb0-8eaaf9140000 pid=5369 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=cdd3c559-1e00-0000-0fb0-8eaaf9140000 pid=5369 execve guuid=4e8a155b-1e00-0000-0fb0-8eaafb140000 pid=5371 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=4e8a155b-1e00-0000-0fb0-8eaafb140000 pid=5371 execve guuid=980da35c-1e00-0000-0fb0-8eaafd140000 pid=5373 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=980da35c-1e00-0000-0fb0-8eaafd140000 pid=5373 execve guuid=d977625e-1e00-0000-0fb0-8eaaff140000 pid=5375 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d977625e-1e00-0000-0fb0-8eaaff140000 pid=5375 execve guuid=5bca128e-1f00-0000-0fb0-8eaa01150000 pid=5377 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=5bca128e-1f00-0000-0fb0-8eaa01150000 pid=5377 execve guuid=14cfad92-1f00-0000-0fb0-8eaa03150000 pid=5379 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=14cfad92-1f00-0000-0fb0-8eaa03150000 pid=5379 execve guuid=98864a94-1f00-0000-0fb0-8eaa05150000 pid=5381 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=98864a94-1f00-0000-0fb0-8eaa05150000 pid=5381 execve guuid=3ddc0a96-1f00-0000-0fb0-8eaa07150000 pid=5383 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=3ddc0a96-1f00-0000-0fb0-8eaa07150000 pid=5383 execve guuid=fe93c597-1f00-0000-0fb0-8eaa09150000 pid=5385 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=fe93c597-1f00-0000-0fb0-8eaa09150000 pid=5385 execve guuid=00fe8399-1f00-0000-0fb0-8eaa0b150000 pid=5387 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=00fe8399-1f00-0000-0fb0-8eaa0b150000 pid=5387 execve guuid=dba6459b-1f00-0000-0fb0-8eaa0d150000 pid=5389 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=dba6459b-1f00-0000-0fb0-8eaa0d150000 pid=5389 execve guuid=4946f89c-1f00-0000-0fb0-8eaa0f150000 pid=5391 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=4946f89c-1f00-0000-0fb0-8eaa0f150000 pid=5391 execve guuid=f159a39e-1f00-0000-0fb0-8eaa11150000 pid=5393 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=f159a39e-1f00-0000-0fb0-8eaa11150000 pid=5393 execve guuid=e7023dce-2000-0000-0fb0-8eaa13150000 pid=5395 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e7023dce-2000-0000-0fb0-8eaa13150000 pid=5395 execve guuid=6cdee2d2-2000-0000-0fb0-8eaa15150000 pid=5397 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=6cdee2d2-2000-0000-0fb0-8eaa15150000 pid=5397 execve guuid=a1677bd4-2000-0000-0fb0-8eaa17150000 pid=5399 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=a1677bd4-2000-0000-0fb0-8eaa17150000 pid=5399 execve guuid=dbe036d6-2000-0000-0fb0-8eaa19150000 pid=5401 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=dbe036d6-2000-0000-0fb0-8eaa19150000 pid=5401 execve guuid=b313eed7-2000-0000-0fb0-8eaa1b150000 pid=5403 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=b313eed7-2000-0000-0fb0-8eaa1b150000 pid=5403 execve guuid=68c5b1d9-2000-0000-0fb0-8eaa1d150000 pid=5405 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=68c5b1d9-2000-0000-0fb0-8eaa1d150000 pid=5405 execve guuid=74a264db-2000-0000-0fb0-8eaa1f150000 pid=5407 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=74a264db-2000-0000-0fb0-8eaa1f150000 pid=5407 execve guuid=495b2edd-2000-0000-0fb0-8eaa21150000 pid=5409 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=495b2edd-2000-0000-0fb0-8eaa21150000 pid=5409 execve guuid=d19ad9de-2000-0000-0fb0-8eaa23150000 pid=5411 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d19ad9de-2000-0000-0fb0-8eaa23150000 pid=5411 execve guuid=dcef750e-2200-0000-0fb0-8eaa25150000 pid=5413 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=dcef750e-2200-0000-0fb0-8eaa25150000 pid=5413 execve guuid=3a312313-2200-0000-0fb0-8eaa27150000 pid=5415 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=3a312313-2200-0000-0fb0-8eaa27150000 pid=5415 execve guuid=6802ba14-2200-0000-0fb0-8eaa29150000 pid=5417 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=6802ba14-2200-0000-0fb0-8eaa29150000 pid=5417 execve guuid=be847416-2200-0000-0fb0-8eaa2b150000 pid=5419 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=be847416-2200-0000-0fb0-8eaa2b150000 pid=5419 execve guuid=22372d18-2200-0000-0fb0-8eaa2d150000 pid=5421 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=22372d18-2200-0000-0fb0-8eaa2d150000 pid=5421 execve guuid=53b6ea19-2200-0000-0fb0-8eaa2f150000 pid=5423 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=53b6ea19-2200-0000-0fb0-8eaa2f150000 pid=5423 execve guuid=f0a4a61b-2200-0000-0fb0-8eaa31150000 pid=5425 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=f0a4a61b-2200-0000-0fb0-8eaa31150000 pid=5425 execve guuid=7a8b641d-2200-0000-0fb0-8eaa33150000 pid=5427 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=7a8b641d-2200-0000-0fb0-8eaa33150000 pid=5427 execve guuid=fcd1ef1e-2200-0000-0fb0-8eaa35150000 pid=5429 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=fcd1ef1e-2200-0000-0fb0-8eaa35150000 pid=5429 execve guuid=df58974f-2300-0000-0fb0-8eaa37150000 pid=5431 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=df58974f-2300-0000-0fb0-8eaa37150000 pid=5431 execve guuid=1ac13f54-2300-0000-0fb0-8eaa39150000 pid=5433 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=1ac13f54-2300-0000-0fb0-8eaa39150000 pid=5433 execve guuid=340b3f56-2300-0000-0fb0-8eaa3b150000 pid=5435 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=340b3f56-2300-0000-0fb0-8eaa3b150000 pid=5435 execve guuid=f3a61058-2300-0000-0fb0-8eaa3d150000 pid=5437 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=f3a61058-2300-0000-0fb0-8eaa3d150000 pid=5437 execve guuid=da9bfa59-2300-0000-0fb0-8eaa3f150000 pid=5439 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=da9bfa59-2300-0000-0fb0-8eaa3f150000 pid=5439 execve guuid=adddc85b-2300-0000-0fb0-8eaa41150000 pid=5441 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=adddc85b-2300-0000-0fb0-8eaa41150000 pid=5441 execve guuid=7e46a55d-2300-0000-0fb0-8eaa43150000 pid=5443 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=7e46a55d-2300-0000-0fb0-8eaa43150000 pid=5443 execve guuid=05ee905f-2300-0000-0fb0-8eaa45150000 pid=5445 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=05ee905f-2300-0000-0fb0-8eaa45150000 pid=5445 execve guuid=19a47161-2300-0000-0fb0-8eaa47150000 pid=5447 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=19a47161-2300-0000-0fb0-8eaa47150000 pid=5447 execve guuid=2f55f791-2400-0000-0fb0-8eaa49150000 pid=5449 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=2f55f791-2400-0000-0fb0-8eaa49150000 pid=5449 execve guuid=003d1697-2400-0000-0fb0-8eaa4b150000 pid=5451 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=003d1697-2400-0000-0fb0-8eaa4b150000 pid=5451 execve guuid=b290ce98-2400-0000-0fb0-8eaa4d150000 pid=5453 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=b290ce98-2400-0000-0fb0-8eaa4d150000 pid=5453 execve guuid=4eeeb99a-2400-0000-0fb0-8eaa4f150000 pid=5455 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=4eeeb99a-2400-0000-0fb0-8eaa4f150000 pid=5455 execve guuid=bdb9899c-2400-0000-0fb0-8eaa51150000 pid=5457 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=bdb9899c-2400-0000-0fb0-8eaa51150000 pid=5457 execve guuid=e2b24c9e-2400-0000-0fb0-8eaa53150000 pid=5459 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=e2b24c9e-2400-0000-0fb0-8eaa53150000 pid=5459 execve guuid=834406a0-2400-0000-0fb0-8eaa55150000 pid=5461 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=834406a0-2400-0000-0fb0-8eaa55150000 pid=5461 execve guuid=3fc5c3a1-2400-0000-0fb0-8eaa57150000 pid=5463 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=3fc5c3a1-2400-0000-0fb0-8eaa57150000 pid=5463 execve guuid=45e379a3-2400-0000-0fb0-8eaa59150000 pid=5465 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=45e379a3-2400-0000-0fb0-8eaa59150000 pid=5465 execve guuid=c648a4d3-2500-0000-0fb0-8eaa5b150000 pid=5467 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=c648a4d3-2500-0000-0fb0-8eaa5b150000 pid=5467 execve guuid=cf5006d8-2500-0000-0fb0-8eaa5d150000 pid=5469 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=cf5006d8-2500-0000-0fb0-8eaa5d150000 pid=5469 execve guuid=1bbe2dd9-2500-0000-0fb0-8eaa5f150000 pid=5471 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=1bbe2dd9-2500-0000-0fb0-8eaa5f150000 pid=5471 execve guuid=d79ebbda-2500-0000-0fb0-8eaa61150000 pid=5473 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d79ebbda-2500-0000-0fb0-8eaa61150000 pid=5473 execve guuid=a07059dc-2500-0000-0fb0-8eaa63150000 pid=5475 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=a07059dc-2500-0000-0fb0-8eaa63150000 pid=5475 execve guuid=ac0ae6dd-2500-0000-0fb0-8eaa65150000 pid=5477 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=ac0ae6dd-2500-0000-0fb0-8eaa65150000 pid=5477 execve guuid=a61348df-2500-0000-0fb0-8eaa67150000 pid=5479 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=a61348df-2500-0000-0fb0-8eaa67150000 pid=5479 execve guuid=d88fdae0-2500-0000-0fb0-8eaa69150000 pid=5481 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=d88fdae0-2500-0000-0fb0-8eaa69150000 pid=5481 execve guuid=70ba6de2-2500-0000-0fb0-8eaa6b150000 pid=5483 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=70ba6de2-2500-0000-0fb0-8eaa6b150000 pid=5483 execve guuid=886cee11-2700-0000-0fb0-8eaa6f150000 pid=5487 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=886cee11-2700-0000-0fb0-8eaa6f150000 pid=5487 execve guuid=dfa1f915-2700-0000-0fb0-8eaa71150000 pid=5489 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=dfa1f915-2700-0000-0fb0-8eaa71150000 pid=5489 execve guuid=9c645a17-2700-0000-0fb0-8eaa75150000 pid=5493 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=9c645a17-2700-0000-0fb0-8eaa75150000 pid=5493 execve guuid=efc4c118-2700-0000-0fb0-8eaa7a150000 pid=5498 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=efc4c118-2700-0000-0fb0-8eaa7a150000 pid=5498 execve guuid=07a01a1a-2700-0000-0fb0-8eaa7e150000 pid=5502 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=07a01a1a-2700-0000-0fb0-8eaa7e150000 pid=5502 execve guuid=1472571b-2700-0000-0fb0-8eaa80150000 pid=5504 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=1472571b-2700-0000-0fb0-8eaa80150000 pid=5504 execve guuid=3199a71c-2700-0000-0fb0-8eaa83150000 pid=5507 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=3199a71c-2700-0000-0fb0-8eaa83150000 pid=5507 execve guuid=ec53dd1d-2700-0000-0fb0-8eaa85150000 pid=5509 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=ec53dd1d-2700-0000-0fb0-8eaa85150000 pid=5509 execve guuid=3092011f-2700-0000-0fb0-8eaa87150000 pid=5511 /usr/bin/dash guuid=ae3d801e-1900-0000-0fb0-8eaa24120000 pid=4644->guuid=3092011f-2700-0000-0fb0-8eaa87150000 pid=5511 execve guuid=ac5b061f-1900-0000-0fb0-8eaa2a120000 pid=4650 /usr/bin/wget dns net send-data guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645->guuid=ac5b061f-1900-0000-0fb0-8eaa2a120000 pid=4650 execve guuid=4cb82f26-1900-0000-0fb0-8eaa47120000 pid=4679 /usr/bin/chmod guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645->guuid=4cb82f26-1900-0000-0fb0-8eaa47120000 pid=4679 execve guuid=640c9826-1900-0000-0fb0-8eaa4a120000 pid=4682 /home/sandbox/..... guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645->guuid=640c9826-1900-0000-0fb0-8eaa4a120000 pid=4682 execve guuid=6c16e427-1900-0000-0fb0-8eaa52120000 pid=4690 /usr/bin/rm delete-file guuid=bda2831e-1900-0000-0fb0-8eaa25120000 pid=4645->guuid=6c16e427-1900-0000-0fb0-8eaa52120000 pid=4690 execve guuid=2661a01e-1900-0000-0fb0-8eaa28120000 pid=4648 /tmp/sample.bin net send-data zombie guuid=b58d901e-1900-0000-0fb0-8eaa27120000 pid=4647->guuid=2661a01e-1900-0000-0fb0-8eaa28120000 pid=4648 clone aa741c27-8342-57db-90e7-58fe0cd14bd8 206.123.128.67:65481 guuid=2661a01e-1900-0000-0fb0-8eaa28120000 pid=4648->aa741c27-8342-57db-90e7-58fe0cd14bd8 send: 13B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ac5b061f-1900-0000-0fb0-8eaa2a120000 pid=4650->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 112B guuid=7f737251-1900-0000-0fb0-8eaad9120000 pid=4825 /usr/bin/pgrep guuid=e3461d51-1900-0000-0fb0-8eaad8120000 pid=4824->guuid=7f737251-1900-0000-0fb0-8eaad9120000 pid=4825 execve guuid=2497515a-1900-0000-0fb0-8eaaef120000 pid=4847 /usr/bin/killall guuid=886c155a-1900-0000-0fb0-8eaaed120000 pid=4845->guuid=2497515a-1900-0000-0fb0-8eaaef120000 pid=4847 execve guuid=4deb9662-1900-0000-0fb0-8eaa07130000 pid=4871 /usr/bin/killall guuid=8c4c5a62-1900-0000-0fb0-8eaa05130000 pid=4869->guuid=4deb9662-1900-0000-0fb0-8eaa07130000 pid=4871 execve guuid=3a459963-1900-0000-0fb0-8eaa0c130000 pid=4876 /usr/bin/killall guuid=9e4c6263-1900-0000-0fb0-8eaa0b130000 pid=4875->guuid=3a459963-1900-0000-0fb0-8eaa0c130000 pid=4876 execve guuid=ff70a564-1900-0000-0fb0-8eaa12130000 pid=4882 /usr/bin/killall guuid=d3386764-1900-0000-0fb0-8eaa10130000 pid=4880->guuid=ff70a564-1900-0000-0fb0-8eaa12130000 pid=4882 execve guuid=b0e0ab65-1900-0000-0fb0-8eaa17130000 pid=4887 /usr/bin/killall guuid=ce606765-1900-0000-0fb0-8eaa16130000 pid=4886->guuid=b0e0ab65-1900-0000-0fb0-8eaa17130000 pid=4887 execve guuid=88db9e66-1900-0000-0fb0-8eaa1c130000 pid=4892 /usr/bin/killall guuid=30c46a66-1900-0000-0fb0-8eaa1a130000 pid=4890->guuid=88db9e66-1900-0000-0fb0-8eaa1c130000 pid=4892 execve guuid=6256a267-1900-0000-0fb0-8eaa22130000 pid=4898 /usr/bin/killall guuid=eef86367-1900-0000-0fb0-8eaa20130000 pid=4896->guuid=6256a267-1900-0000-0fb0-8eaa22130000 pid=4898 execve guuid=52d27a68-1900-0000-0fb0-8eaa27130000 pid=4903 /usr/bin/killall guuid=2d825468-1900-0000-0fb0-8eaa26130000 pid=4902->guuid=52d27a68-1900-0000-0fb0-8eaa27130000 pid=4903 execve guuid=3fbb4a96-1a00-0000-0fb0-8eaaad140000 pid=5293 /usr/bin/pgrep guuid=e73dd995-1a00-0000-0fb0-8eaaac140000 pid=5292->guuid=3fbb4a96-1a00-0000-0fb0-8eaaad140000 pid=5293 execve guuid=d185009c-1a00-0000-0fb0-8eaaaf140000 pid=5295 /usr/bin/killall guuid=cadac59b-1a00-0000-0fb0-8eaaae140000 pid=5294->guuid=d185009c-1a00-0000-0fb0-8eaaaf140000 pid=5295 execve guuid=57b0369d-1a00-0000-0fb0-8eaab1140000 pid=5297 /usr/bin/killall guuid=5b3f019d-1a00-0000-0fb0-8eaab0140000 pid=5296->guuid=57b0369d-1a00-0000-0fb0-8eaab1140000 pid=5297 execve guuid=5497799e-1a00-0000-0fb0-8eaab3140000 pid=5299 /usr/bin/killall guuid=fc56469e-1a00-0000-0fb0-8eaab2140000 pid=5298->guuid=5497799e-1a00-0000-0fb0-8eaab3140000 pid=5299 execve guuid=8c56c79f-1a00-0000-0fb0-8eaab5140000 pid=5301 /usr/bin/killall guuid=9bb78e9f-1a00-0000-0fb0-8eaab4140000 pid=5300->guuid=8c56c79f-1a00-0000-0fb0-8eaab5140000 pid=5301 execve guuid=dcab08a1-1a00-0000-0fb0-8eaab7140000 pid=5303 /usr/bin/killall guuid=7b79d1a0-1a00-0000-0fb0-8eaab6140000 pid=5302->guuid=dcab08a1-1a00-0000-0fb0-8eaab7140000 pid=5303 execve guuid=a9b86ca2-1a00-0000-0fb0-8eaab9140000 pid=5305 /usr/bin/killall guuid=488b33a2-1a00-0000-0fb0-8eaab8140000 pid=5304->guuid=a9b86ca2-1a00-0000-0fb0-8eaab9140000 pid=5305 execve guuid=37dcaea3-1a00-0000-0fb0-8eaabb140000 pid=5307 /usr/bin/killall guuid=6aa773a3-1a00-0000-0fb0-8eaaba140000 pid=5306->guuid=37dcaea3-1a00-0000-0fb0-8eaabb140000 pid=5307 execve guuid=708e1ba5-1a00-0000-0fb0-8eaabd140000 pid=5309 /usr/bin/killall guuid=508ce5a4-1a00-0000-0fb0-8eaabc140000 pid=5308->guuid=708e1ba5-1a00-0000-0fb0-8eaabd140000 pid=5309 execve guuid=9971afd5-1b00-0000-0fb0-8eaacc140000 pid=5324 /usr/bin/pgrep guuid=9abb68d5-1b00-0000-0fb0-8eaacb140000 pid=5323->guuid=9971afd5-1b00-0000-0fb0-8eaacc140000 pid=5324 execve guuid=9227d2d8-1b00-0000-0fb0-8eaace140000 pid=5326 /usr/bin/killall guuid=9d7483d8-1b00-0000-0fb0-8eaacd140000 pid=5325->guuid=9227d2d8-1b00-0000-0fb0-8eaace140000 pid=5326 execve guuid=33b2cbd9-1b00-0000-0fb0-8eaad0140000 pid=5328 /usr/bin/killall guuid=92b88dd9-1b00-0000-0fb0-8eaacf140000 pid=5327->guuid=33b2cbd9-1b00-0000-0fb0-8eaad0140000 pid=5328 execve guuid=d3fcd9da-1b00-0000-0fb0-8eaad2140000 pid=5330 /usr/bin/killall guuid=937f8eda-1b00-0000-0fb0-8eaad1140000 pid=5329->guuid=d3fcd9da-1b00-0000-0fb0-8eaad2140000 pid=5330 execve guuid=c442eadb-1b00-0000-0fb0-8eaad4140000 pid=5332 /usr/bin/killall guuid=dcec9ddb-1b00-0000-0fb0-8eaad3140000 pid=5331->guuid=c442eadb-1b00-0000-0fb0-8eaad4140000 pid=5332 execve guuid=33b385dd-1b00-0000-0fb0-8eaad6140000 pid=5334 /usr/bin/killall guuid=31e532dd-1b00-0000-0fb0-8eaad5140000 pid=5333->guuid=33b385dd-1b00-0000-0fb0-8eaad6140000 pid=5334 execve guuid=7d963bdf-1b00-0000-0fb0-8eaad8140000 pid=5336 /usr/bin/killall guuid=f776e1de-1b00-0000-0fb0-8eaad7140000 pid=5335->guuid=7d963bdf-1b00-0000-0fb0-8eaad8140000 pid=5336 execve guuid=8627e3e0-1b00-0000-0fb0-8eaada140000 pid=5338 /usr/bin/killall guuid=595691e0-1b00-0000-0fb0-8eaad9140000 pid=5337->guuid=8627e3e0-1b00-0000-0fb0-8eaada140000 pid=5338 execve guuid=055592e2-1b00-0000-0fb0-8eaadc140000 pid=5340 /usr/bin/killall guuid=ad4e36e2-1b00-0000-0fb0-8eaadb140000 pid=5339->guuid=055592e2-1b00-0000-0fb0-8eaadc140000 pid=5340 execve guuid=e2afbf12-1d00-0000-0fb0-8eaade140000 pid=5342 /usr/bin/pgrep guuid=601a5b12-1d00-0000-0fb0-8eaadd140000 pid=5341->guuid=e2afbf12-1d00-0000-0fb0-8eaade140000 pid=5342 execve guuid=5a8cb016-1d00-0000-0fb0-8eaae0140000 pid=5344 /usr/bin/killall guuid=b3295c16-1d00-0000-0fb0-8eaadf140000 pid=5343->guuid=5a8cb016-1d00-0000-0fb0-8eaae0140000 pid=5344 execve guuid=be87fd17-1d00-0000-0fb0-8eaae2140000 pid=5346 /usr/bin/killall guuid=1422a817-1d00-0000-0fb0-8eaae1140000 pid=5345->guuid=be87fd17-1d00-0000-0fb0-8eaae2140000 pid=5346 execve guuid=30b84019-1d00-0000-0fb0-8eaae4140000 pid=5348 /usr/bin/killall guuid=e4b2e718-1d00-0000-0fb0-8eaae3140000 pid=5347->guuid=30b84019-1d00-0000-0fb0-8eaae4140000 pid=5348 execve guuid=f7ea691a-1d00-0000-0fb0-8eaae6140000 pid=5350 /usr/bin/killall guuid=b056291a-1d00-0000-0fb0-8eaae5140000 pid=5349->guuid=f7ea691a-1d00-0000-0fb0-8eaae6140000 pid=5350 execve guuid=b0aeed1b-1d00-0000-0fb0-8eaae8140000 pid=5352 /usr/bin/killall guuid=4fc3ac1b-1d00-0000-0fb0-8eaae7140000 pid=5351->guuid=b0aeed1b-1d00-0000-0fb0-8eaae8140000 pid=5352 execve guuid=73e6931d-1d00-0000-0fb0-8eaaea140000 pid=5354 /usr/bin/killall guuid=2cf13b1d-1d00-0000-0fb0-8eaae9140000 pid=5353->guuid=73e6931d-1d00-0000-0fb0-8eaaea140000 pid=5354 execve guuid=09d2be1e-1d00-0000-0fb0-8eaaec140000 pid=5356 /usr/bin/killall guuid=d3f7801e-1d00-0000-0fb0-8eaaeb140000 pid=5355->guuid=09d2be1e-1d00-0000-0fb0-8eaaec140000 pid=5356 execve guuid=65e94520-1d00-0000-0fb0-8eaaee140000 pid=5358 /usr/bin/killall guuid=63270c20-1d00-0000-0fb0-8eaaed140000 pid=5357->guuid=65e94520-1d00-0000-0fb0-8eaaee140000 pid=5358 execve guuid=a4297d50-1e00-0000-0fb0-8eaaf0140000 pid=5360 /usr/bin/pgrep guuid=55a53150-1e00-0000-0fb0-8eaaef140000 pid=5359->guuid=a4297d50-1e00-0000-0fb0-8eaaf0140000 pid=5360 execve guuid=e05d6e54-1e00-0000-0fb0-8eaaf2140000 pid=5362 /usr/bin/killall guuid=95b51454-1e00-0000-0fb0-8eaaf1140000 pid=5361->guuid=e05d6e54-1e00-0000-0fb0-8eaaf2140000 pid=5362 execve guuid=a5229f55-1e00-0000-0fb0-8eaaf4140000 pid=5364 /usr/bin/killall guuid=98466255-1e00-0000-0fb0-8eaaf3140000 pid=5363->guuid=a5229f55-1e00-0000-0fb0-8eaaf4140000 pid=5364 execve guuid=f8642f57-1e00-0000-0fb0-8eaaf6140000 pid=5366 /usr/bin/killall guuid=82efef56-1e00-0000-0fb0-8eaaf5140000 pid=5365->guuid=f8642f57-1e00-0000-0fb0-8eaaf6140000 pid=5366 execve guuid=bed3cd58-1e00-0000-0fb0-8eaaf8140000 pid=5368 /usr/bin/killall guuid=e6507a58-1e00-0000-0fb0-8eaaf7140000 pid=5367->guuid=bed3cd58-1e00-0000-0fb0-8eaaf8140000 pid=5368 execve guuid=9fcb1f5a-1e00-0000-0fb0-8eaafa140000 pid=5370 /usr/bin/killall guuid=cdd3c559-1e00-0000-0fb0-8eaaf9140000 pid=5369->guuid=9fcb1f5a-1e00-0000-0fb0-8eaafa140000 pid=5370 execve guuid=5b64505b-1e00-0000-0fb0-8eaafc140000 pid=5372 /usr/bin/killall guuid=4e8a155b-1e00-0000-0fb0-8eaafb140000 pid=5371->guuid=5b64505b-1e00-0000-0fb0-8eaafc140000 pid=5372 execve guuid=612a025d-1e00-0000-0fb0-8eaafe140000 pid=5374 /usr/bin/killall guuid=980da35c-1e00-0000-0fb0-8eaafd140000 pid=5373->guuid=612a025d-1e00-0000-0fb0-8eaafe140000 pid=5374 execve guuid=93b6b45e-1e00-0000-0fb0-8eaa00150000 pid=5376 /usr/bin/killall guuid=d977625e-1e00-0000-0fb0-8eaaff140000 pid=5375->guuid=93b6b45e-1e00-0000-0fb0-8eaa00150000 pid=5376 execve guuid=8177748e-1f00-0000-0fb0-8eaa02150000 pid=5378 /usr/bin/pgrep guuid=5bca128e-1f00-0000-0fb0-8eaa01150000 pid=5377->guuid=8177748e-1f00-0000-0fb0-8eaa02150000 pid=5378 execve guuid=415eed92-1f00-0000-0fb0-8eaa04150000 pid=5380 /usr/bin/killall guuid=14cfad92-1f00-0000-0fb0-8eaa03150000 pid=5379->guuid=415eed92-1f00-0000-0fb0-8eaa04150000 pid=5380 execve guuid=cdd3a694-1f00-0000-0fb0-8eaa06150000 pid=5382 /usr/bin/killall guuid=98864a94-1f00-0000-0fb0-8eaa05150000 pid=5381->guuid=cdd3a694-1f00-0000-0fb0-8eaa06150000 pid=5382 execve guuid=2f8f6396-1f00-0000-0fb0-8eaa08150000 pid=5384 /usr/bin/killall guuid=3ddc0a96-1f00-0000-0fb0-8eaa07150000 pid=5383->guuid=2f8f6396-1f00-0000-0fb0-8eaa08150000 pid=5384 execve guuid=45b22698-1f00-0000-0fb0-8eaa0a150000 pid=5386 /usr/bin/killall guuid=fe93c597-1f00-0000-0fb0-8eaa09150000 pid=5385->guuid=45b22698-1f00-0000-0fb0-8eaa0a150000 pid=5386 execve guuid=595ee499-1f00-0000-0fb0-8eaa0c150000 pid=5388 /usr/bin/killall guuid=00fe8399-1f00-0000-0fb0-8eaa0b150000 pid=5387->guuid=595ee499-1f00-0000-0fb0-8eaa0c150000 pid=5388 execve guuid=a0ac9d9b-1f00-0000-0fb0-8eaa0e150000 pid=5390 /usr/bin/killall guuid=dba6459b-1f00-0000-0fb0-8eaa0d150000 pid=5389->guuid=a0ac9d9b-1f00-0000-0fb0-8eaa0e150000 pid=5390 execve guuid=4552449d-1f00-0000-0fb0-8eaa10150000 pid=5392 /usr/bin/killall guuid=4946f89c-1f00-0000-0fb0-8eaa0f150000 pid=5391->guuid=4552449d-1f00-0000-0fb0-8eaa10150000 pid=5392 execve guuid=4d8efa9e-1f00-0000-0fb0-8eaa12150000 pid=5394 /usr/bin/killall guuid=f159a39e-1f00-0000-0fb0-8eaa11150000 pid=5393->guuid=4d8efa9e-1f00-0000-0fb0-8eaa12150000 pid=5394 execve guuid=4020a6ce-2000-0000-0fb0-8eaa14150000 pid=5396 /usr/bin/pgrep guuid=e7023dce-2000-0000-0fb0-8eaa13150000 pid=5395->guuid=4020a6ce-2000-0000-0fb0-8eaa14150000 pid=5396 execve guuid=fee723d3-2000-0000-0fb0-8eaa16150000 pid=5398 /usr/bin/killall guuid=6cdee2d2-2000-0000-0fb0-8eaa15150000 pid=5397->guuid=fee723d3-2000-0000-0fb0-8eaa16150000 pid=5398 execve guuid=deadd9d4-2000-0000-0fb0-8eaa18150000 pid=5400 /usr/bin/killall guuid=a1677bd4-2000-0000-0fb0-8eaa17150000 pid=5399->guuid=deadd9d4-2000-0000-0fb0-8eaa18150000 pid=5400 execve guuid=09d989d6-2000-0000-0fb0-8eaa1a150000 pid=5402 /usr/bin/killall guuid=dbe036d6-2000-0000-0fb0-8eaa19150000 pid=5401->guuid=09d989d6-2000-0000-0fb0-8eaa1a150000 pid=5402 execve guuid=9e154ed8-2000-0000-0fb0-8eaa1c150000 pid=5404 /usr/bin/killall guuid=b313eed7-2000-0000-0fb0-8eaa1b150000 pid=5403->guuid=9e154ed8-2000-0000-0fb0-8eaa1c150000 pid=5404 execve guuid=236b0eda-2000-0000-0fb0-8eaa1e150000 pid=5406 /usr/bin/killall guuid=68c5b1d9-2000-0000-0fb0-8eaa1d150000 pid=5405->guuid=236b0eda-2000-0000-0fb0-8eaa1e150000 pid=5406 execve guuid=9912c1db-2000-0000-0fb0-8eaa20150000 pid=5408 /usr/bin/killall guuid=74a264db-2000-0000-0fb0-8eaa1f150000 pid=5407->guuid=9912c1db-2000-0000-0fb0-8eaa20150000 pid=5408 execve guuid=e65c7fdd-2000-0000-0fb0-8eaa22150000 pid=5410 /usr/bin/killall guuid=495b2edd-2000-0000-0fb0-8eaa21150000 pid=5409->guuid=e65c7fdd-2000-0000-0fb0-8eaa22150000 pid=5410 execve guuid=040531df-2000-0000-0fb0-8eaa24150000 pid=5412 /usr/bin/killall guuid=d19ad9de-2000-0000-0fb0-8eaa23150000 pid=5411->guuid=040531df-2000-0000-0fb0-8eaa24150000 pid=5412 execve guuid=f226db0e-2200-0000-0fb0-8eaa26150000 pid=5414 /usr/bin/pgrep guuid=dcef750e-2200-0000-0fb0-8eaa25150000 pid=5413->guuid=f226db0e-2200-0000-0fb0-8eaa26150000 pid=5414 execve guuid=442e6313-2200-0000-0fb0-8eaa28150000 pid=5416 /usr/bin/killall guuid=3a312313-2200-0000-0fb0-8eaa27150000 pid=5415->guuid=442e6313-2200-0000-0fb0-8eaa28150000 pid=5416 execve guuid=a8a00f15-2200-0000-0fb0-8eaa2a150000 pid=5418 /usr/bin/killall guuid=6802ba14-2200-0000-0fb0-8eaa29150000 pid=5417->guuid=a8a00f15-2200-0000-0fb0-8eaa2a150000 pid=5418 execve guuid=773dcd16-2200-0000-0fb0-8eaa2c150000 pid=5420 /usr/bin/killall guuid=be847416-2200-0000-0fb0-8eaa2b150000 pid=5419->guuid=773dcd16-2200-0000-0fb0-8eaa2c150000 pid=5420 execve guuid=8e578c18-2200-0000-0fb0-8eaa2e150000 pid=5422 /usr/bin/killall guuid=22372d18-2200-0000-0fb0-8eaa2d150000 pid=5421->guuid=8e578c18-2200-0000-0fb0-8eaa2e150000 pid=5422 execve guuid=4863481a-2200-0000-0fb0-8eaa30150000 pid=5424 /usr/bin/killall guuid=53b6ea19-2200-0000-0fb0-8eaa2f150000 pid=5423->guuid=4863481a-2200-0000-0fb0-8eaa30150000 pid=5424 execve guuid=df84091c-2200-0000-0fb0-8eaa32150000 pid=5426 /usr/bin/killall guuid=f0a4a61b-2200-0000-0fb0-8eaa31150000 pid=5425->guuid=df84091c-2200-0000-0fb0-8eaa32150000 pid=5426 execve guuid=2c7ba31d-2200-0000-0fb0-8eaa34150000 pid=5428 /usr/bin/killall guuid=7a8b641d-2200-0000-0fb0-8eaa33150000 pid=5427->guuid=2c7ba31d-2200-0000-0fb0-8eaa34150000 pid=5428 execve guuid=94ee781f-2200-0000-0fb0-8eaa36150000 pid=5430 /usr/bin/killall guuid=fcd1ef1e-2200-0000-0fb0-8eaa35150000 pid=5429->guuid=94ee781f-2200-0000-0fb0-8eaa36150000 pid=5430 execve guuid=0fd2ff4f-2300-0000-0fb0-8eaa38150000 pid=5432 /usr/bin/pgrep guuid=df58974f-2300-0000-0fb0-8eaa37150000 pid=5431->guuid=0fd2ff4f-2300-0000-0fb0-8eaa38150000 pid=5432 execve guuid=5de7cb54-2300-0000-0fb0-8eaa3a150000 pid=5434 /usr/bin/killall guuid=1ac13f54-2300-0000-0fb0-8eaa39150000 pid=5433->guuid=5de7cb54-2300-0000-0fb0-8eaa3a150000 pid=5434 execve guuid=aad6a956-2300-0000-0fb0-8eaa3c150000 pid=5436 /usr/bin/killall guuid=340b3f56-2300-0000-0fb0-8eaa3b150000 pid=5435->guuid=aad6a956-2300-0000-0fb0-8eaa3c150000 pid=5436 execve guuid=24596858-2300-0000-0fb0-8eaa3e150000 pid=5438 /usr/bin/killall guuid=f3a61058-2300-0000-0fb0-8eaa3d150000 pid=5437->guuid=24596858-2300-0000-0fb0-8eaa3e150000 pid=5438 execve guuid=ac055b5a-2300-0000-0fb0-8eaa40150000 pid=5440 /usr/bin/killall guuid=da9bfa59-2300-0000-0fb0-8eaa3f150000 pid=5439->guuid=ac055b5a-2300-0000-0fb0-8eaa40150000 pid=5440 execve guuid=a86f325c-2300-0000-0fb0-8eaa42150000 pid=5442 /usr/bin/killall guuid=adddc85b-2300-0000-0fb0-8eaa41150000 pid=5441->guuid=a86f325c-2300-0000-0fb0-8eaa42150000 pid=5442 execve guuid=deb31c5e-2300-0000-0fb0-8eaa44150000 pid=5444 /usr/bin/killall guuid=7e46a55d-2300-0000-0fb0-8eaa43150000 pid=5443->guuid=deb31c5e-2300-0000-0fb0-8eaa44150000 pid=5444 execve guuid=e3380860-2300-0000-0fb0-8eaa46150000 pid=5446 /usr/bin/killall guuid=05ee905f-2300-0000-0fb0-8eaa45150000 pid=5445->guuid=e3380860-2300-0000-0fb0-8eaa46150000 pid=5446 execve guuid=c571e661-2300-0000-0fb0-8eaa48150000 pid=5448 /usr/bin/killall guuid=19a47161-2300-0000-0fb0-8eaa47150000 pid=5447->guuid=c571e661-2300-0000-0fb0-8eaa48150000 pid=5448 execve guuid=a6525792-2400-0000-0fb0-8eaa4a150000 pid=5450 /usr/bin/pgrep guuid=2f55f791-2400-0000-0fb0-8eaa49150000 pid=5449->guuid=a6525792-2400-0000-0fb0-8eaa4a150000 pid=5450 execve guuid=7f555d97-2400-0000-0fb0-8eaa4c150000 pid=5452 /usr/bin/killall guuid=003d1697-2400-0000-0fb0-8eaa4b150000 pid=5451->guuid=7f555d97-2400-0000-0fb0-8eaa4c150000 pid=5452 execve guuid=eb112899-2400-0000-0fb0-8eaa4e150000 pid=5454 /usr/bin/killall guuid=b290ce98-2400-0000-0fb0-8eaa4d150000 pid=5453->guuid=eb112899-2400-0000-0fb0-8eaa4e150000 pid=5454 execve guuid=9f15189b-2400-0000-0fb0-8eaa50150000 pid=5456 /usr/bin/killall guuid=4eeeb99a-2400-0000-0fb0-8eaa4f150000 pid=5455->guuid=9f15189b-2400-0000-0fb0-8eaa50150000 pid=5456 execve guuid=1576e29c-2400-0000-0fb0-8eaa52150000 pid=5458 /usr/bin/killall guuid=bdb9899c-2400-0000-0fb0-8eaa51150000 pid=5457->guuid=1576e29c-2400-0000-0fb0-8eaa52150000 pid=5458 execve guuid=aeb3a69e-2400-0000-0fb0-8eaa54150000 pid=5460 /usr/bin/killall guuid=e2b24c9e-2400-0000-0fb0-8eaa53150000 pid=5459->guuid=aeb3a69e-2400-0000-0fb0-8eaa54150000 pid=5460 execve guuid=d06c61a0-2400-0000-0fb0-8eaa56150000 pid=5462 /usr/bin/killall guuid=834406a0-2400-0000-0fb0-8eaa55150000 pid=5461->guuid=d06c61a0-2400-0000-0fb0-8eaa56150000 pid=5462 execve guuid=77bd12a2-2400-0000-0fb0-8eaa58150000 pid=5464 /usr/bin/killall guuid=3fc5c3a1-2400-0000-0fb0-8eaa57150000 pid=5463->guuid=77bd12a2-2400-0000-0fb0-8eaa58150000 pid=5464 execve guuid=0b93cca3-2400-0000-0fb0-8eaa5a150000 pid=5466 /usr/bin/killall guuid=45e379a3-2400-0000-0fb0-8eaa59150000 pid=5465->guuid=0b93cca3-2400-0000-0fb0-8eaa5a150000 pid=5466 execve guuid=124909d4-2500-0000-0fb0-8eaa5c150000 pid=5468 /usr/bin/pgrep guuid=c648a4d3-2500-0000-0fb0-8eaa5b150000 pid=5467->guuid=124909d4-2500-0000-0fb0-8eaa5c150000 pid=5468 execve guuid=e46f5cd8-2500-0000-0fb0-8eaa5e150000 pid=5470 /usr/bin/killall guuid=cf5006d8-2500-0000-0fb0-8eaa5d150000 pid=5469->guuid=e46f5cd8-2500-0000-0fb0-8eaa5e150000 pid=5470 execve guuid=989362d9-2500-0000-0fb0-8eaa60150000 pid=5472 /usr/bin/killall guuid=1bbe2dd9-2500-0000-0fb0-8eaa5f150000 pid=5471->guuid=989362d9-2500-0000-0fb0-8eaa60150000 pid=5472 execve guuid=8d09fdda-2500-0000-0fb0-8eaa62150000 pid=5474 /usr/bin/killall guuid=d79ebbda-2500-0000-0fb0-8eaa61150000 pid=5473->guuid=8d09fdda-2500-0000-0fb0-8eaa62150000 pid=5474 execve guuid=bea997dc-2500-0000-0fb0-8eaa64150000 pid=5476 /usr/bin/killall guuid=a07059dc-2500-0000-0fb0-8eaa63150000 pid=5475->guuid=bea997dc-2500-0000-0fb0-8eaa64150000 pid=5476 execve guuid=1ed43cde-2500-0000-0fb0-8eaa66150000 pid=5478 /usr/bin/killall guuid=ac0ae6dd-2500-0000-0fb0-8eaa65150000 pid=5477->guuid=1ed43cde-2500-0000-0fb0-8eaa66150000 pid=5478 execve guuid=97fd7ddf-2500-0000-0fb0-8eaa68150000 pid=5480 /usr/bin/killall guuid=a61348df-2500-0000-0fb0-8eaa67150000 pid=5479->guuid=97fd7ddf-2500-0000-0fb0-8eaa68150000 pid=5480 execve guuid=09fe1ae1-2500-0000-0fb0-8eaa6a150000 pid=5482 /usr/bin/killall guuid=d88fdae0-2500-0000-0fb0-8eaa69150000 pid=5481->guuid=09fe1ae1-2500-0000-0fb0-8eaa6a150000 pid=5482 execve guuid=03d0c1e2-2500-0000-0fb0-8eaa6c150000 pid=5484 /usr/bin/killall guuid=70ba6de2-2500-0000-0fb0-8eaa6b150000 pid=5483->guuid=03d0c1e2-2500-0000-0fb0-8eaa6c150000 pid=5484 execve guuid=76391f12-2700-0000-0fb0-8eaa70150000 pid=5488 /usr/bin/pgrep guuid=886cee11-2700-0000-0fb0-8eaa6f150000 pid=5487->guuid=76391f12-2700-0000-0fb0-8eaa70150000 pid=5488 execve guuid=90742f16-2700-0000-0fb0-8eaa72150000 pid=5490 /usr/bin/killall guuid=dfa1f915-2700-0000-0fb0-8eaa71150000 pid=5489->guuid=90742f16-2700-0000-0fb0-8eaa72150000 pid=5490 execve guuid=bdd2a317-2700-0000-0fb0-8eaa77150000 pid=5495 /usr/bin/killall guuid=9c645a17-2700-0000-0fb0-8eaa75150000 pid=5493->guuid=bdd2a317-2700-0000-0fb0-8eaa77150000 pid=5495 execve guuid=471c0319-2700-0000-0fb0-8eaa7b150000 pid=5499 /usr/bin/killall guuid=efc4c118-2700-0000-0fb0-8eaa7a150000 pid=5498->guuid=471c0319-2700-0000-0fb0-8eaa7b150000 pid=5499 execve guuid=15ca611a-2700-0000-0fb0-8eaa7f150000 pid=5503 /usr/bin/killall guuid=07a01a1a-2700-0000-0fb0-8eaa7e150000 pid=5502->guuid=15ca611a-2700-0000-0fb0-8eaa7f150000 pid=5503 execve guuid=c68ea11b-2700-0000-0fb0-8eaa81150000 pid=5505 /usr/bin/killall guuid=1472571b-2700-0000-0fb0-8eaa80150000 pid=5504->guuid=c68ea11b-2700-0000-0fb0-8eaa81150000 pid=5505 execve guuid=e772ef1c-2700-0000-0fb0-8eaa84150000 pid=5508 /usr/bin/killall guuid=3199a71c-2700-0000-0fb0-8eaa83150000 pid=5507->guuid=e772ef1c-2700-0000-0fb0-8eaa84150000 pid=5508 execve guuid=cedf221e-2700-0000-0fb0-8eaa86150000 pid=5510 /usr/bin/killall guuid=ec53dd1d-2700-0000-0fb0-8eaa85150000 pid=5509->guuid=cedf221e-2700-0000-0fb0-8eaa86150000 pid=5510 execve guuid=7a1d3b1f-2700-0000-0fb0-8eaa88150000 pid=5512 /usr/bin/killall guuid=3092011f-2700-0000-0fb0-8eaa87150000 pid=5511->guuid=7a1d3b1f-2700-0000-0fb0-8eaa88150000 pid=5512 execve
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
100 / 100
Signature
Antivirus / Scanner detection for submitted sample
Connects to many ports of the same IP (likely port scanning)
Contains symbols with names commonly found in malware
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for submitted file
Opens /proc/net/* files useful for finding connected devices and routers
Sample tries to kill multiple processes (SIGKILL)
Suricata IDS alerts for network traffic
Terminates several processes with shell command 'killall'
Yara detected Gafgyt
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1734945 Sample: getty.elf Startdate: 12/07/2025 Architecture: LINUX Score: 100 38 206.123.128.67, 47098, 65481 LEASEWEB-USA-NYC-11US United States 2->38 40 gay.energy 2->40 42 daisy.ubuntu.com 2->42 44 Suricata IDS alerts for network traffic 2->44 46 Malicious sample detected (through community Yara rule) 2->46 48 Antivirus / Scanner detection for submitted sample 2->48 50 4 other signatures 2->50 9 getty.elf 2->9         started        signatures3 process4 signatures5 54 Opens /proc/net/* files useful for finding connected devices and routers 9->54 12 getty.elf 9->12         started        process6 signatures7 56 Sample tries to kill multiple processes (SIGKILL) 12->56 15 getty.elf sh 12->15         started        17 getty.elf sh 12->17         started        19 getty.elf sh 12->19         started        21 59 other processes 12->21 process8 process9 23 sh killall 15->23         started        26 sh killall 17->26         started        28 sh killall 19->28         started        30 sh killall 21->30         started        32 sh killall 21->32         started        34 sh killall 21->34         started        36 56 other processes 21->36 signatures10 52 Terminates several processes with shell command 'killall' 23->52
Threat name:
Linux.Backdoor.Gafgyt
Status:
Malicious
First seen:
2025-07-12 19:37:25 UTC
File Type:
ELF32 Little (Exe)
AV detection:
21 of 38 (55.26%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:gafgyt defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Changes its process name
Reads CPU attributes
Reads system network configuration
Enumerates running processes
Reads system routing table
File and Directory Permissions Modification
Executes dropped EXE
Modifies Watchdog functionality
Verdict:
Malicious
Tags:
trojan gafgyt mirai Unix.Trojan.Gafgyt-6981154-0
YARA:
Linux_Trojan_Gafgyt_c573932b Linux_Trojan_Gafgyt_5bf62ce4 Linux_Trojan_Gafgyt_6122acdf Linux_Trojan_Gafgyt_71e487ea Linux_Trojan_Gafgyt_7167d08f Linux_Trojan_Mirai_389ee3e9 elf_bashlite_auto
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:Linux_Gafgyt_Generic
Author:albertzsigovits
Description:Generic Approach to Mirai/Gafgyt samples
Rule name:Linux_Trojan_Gafgyt_5bf62ce4
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_6122acdf
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_7167d08f
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_71e487ea
Author:Elastic Security
Rule name:Linux_Trojan_Gafgyt_c573932b
Author:Elastic Security
Rule name:Linux_Trojan_Mirai_389ee3e9
Author:Elastic Security
Rule name:Mal_LNX_Gafgyt_Botnet_ELF
Author:Phatcharadol Thangplub
Description:Use to detect Gafgyt botnet, and there variants.
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Mirai

elf edcb5dae889756267c1c1c2fdc0d4d0cc1c02240971500dcc0dcff28259a47ba

(this sample)

  
Delivery method
Distributed via web download

Comments