MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 fb58552f2e41f83d38518142997eab68d9f1068b597ad43549ab44f9b2621af5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Kaiji


Vendor detections: 11


Intelligence 11 IOCs YARA 24 File information Comments

SHA256 hash: fb58552f2e41f83d38518142997eab68d9f1068b597ad43549ab44f9b2621af5
SHA3-384 hash: 4453999abe05d6fe4560a0b20a842242849ca3bbc3b2a847f071cc068f15e4fdfe78fc8a069a8e7f3072ba0b599a44f1
SHA1 hash: 6a2dac23924884669dbfff312188509ddbe4e7ee
MD5 hash: 1582d96a93c2000b5d625bac7a963584
humanhash: kitten-missouri-island-hydrogen
File name:bin.x86
Download: download sample
Signature Kaiji
File size:5'545'984 bytes
First seen:2025-09-27 21:18:27 UTC
Last seen:2025-09-28 03:44:13 UTC
File type: elf
MIME type:application/x-executable
ssdeep 49152:4W90Ga1nPZbrb/TKvO90dL3BmAFd4A64nsfJUTS/E6NepnIovmixGSqQcSiSZeTq:3OzpUsLaeVPSEDzu
TLSH T11F463B03F89191A4C0EED130C666D2A3BA717C955B3423D32B61FBBA1B36BD46E79314
telfhash t1f7a22f744abc70b1a666c966f3b370b4e23359b553f474b100277d52efe0e891ca682b
gimphash a8339da982f99d99395c680393c0ca2d196d5312ac4b6b80c1cdcaae4eb15388
TrID 50.1% (.) ELF Executable and Linkable format (Linux) (4022/12)
49.8% (.O) ELF Executable and Linkable format (generic) (4000/1)
Magika elf
Reporter abuse_ch
Tags:elf kaiji

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
Result
Verdict:
Malware
Maliciousness:

Behaviour
Changes the time when the file was created, accessed, or modified
Sends data to a server
Receives data from a server
Connection attempt
Kills processes
DNS request
Creating a file
Sets a written file as executable
Creates directories in a system directory
Launching a process
Locks files
Mounts file systems
Manages services
Creating a process from a recently created file
Substitutes an application name
Replaces system binary files
Writes files to system subdirectory
Writes files to system directory
Creates or modifies files in /cron to set up autorun
Creates or modifies files in /init.d to set up autorun
Creates or modifies files to set up autorun
Performs a bruteforce attack in the network
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
base64 crypto expand golang lolbin masquerade
Verdict:
Malicious
File Type:
elf.64.le
First seen:
2025-09-27T18:26:00Z UTC
Last seen:
2025-09-27T18:26:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Linux.Chaos.mj
Status:
terminated
Behavior Graph:
%3 guuid=041620f2-1600-0000-f1de-17a48e0c0000 pid=3214 /usr/bin/sudo guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220 /tmp/sample.bin write-config guuid=041620f2-1600-0000-f1de-17a48e0c0000 pid=3214->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220 execve guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3222 /tmp/sample.bin guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3222 clone guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3223 /tmp/sample.bin guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3223 clone guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3224 /tmp/sample.bin guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3224 clone guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3225 /tmp/sample.bin guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3225 clone guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3226 /tmp/sample.bin guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3226 clone guuid=80a27806-1700-0000-f1de-17a4b00c0000 pid=3248 /usr/bin/bash zombie guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=80a27806-1700-0000-f1de-17a4b00c0000 pid=3248 execve guuid=05809106-1700-0000-f1de-17a4b10c0000 pid=3249 /usr/bin/systemctl zombie guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=05809106-1700-0000-f1de-17a4b10c0000 pid=3249 execve guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250 /tmp/sample.bin zombie guuid=e3c105f4-1600-0000-f1de-17a4940c0000 pid=3220->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250 execve guuid=8e591008-1700-0000-f1de-17a4b50c0000 pid=3253 /etc/32678 zombie guuid=80a27806-1700-0000-f1de-17a4b00c0000 pid=3248->guuid=8e591008-1700-0000-f1de-17a4b50c0000 pid=3253 execve guuid=5b88e907-1700-0000-f1de-17a4b30c0000 pid=3251 /usr/bin/basename guuid=05809106-1700-0000-f1de-17a4b10c0000 pid=3249->guuid=5b88e907-1700-0000-f1de-17a4b30c0000 pid=3251 execve guuid=033a9a0a-1700-0000-f1de-17a4c00c0000 pid=3264 /usr/bin/basename guuid=05809106-1700-0000-f1de-17a4b10c0000 pid=3249->guuid=033a9a0a-1700-0000-f1de-17a4c00c0000 pid=3264 execve guuid=0ec2000b-1700-0000-f1de-17a4c10c0000 pid=3265 /usr/bin/dash guuid=05809106-1700-0000-f1de-17a4b10c0000 pid=3249->guuid=0ec2000b-1700-0000-f1de-17a4c10c0000 pid=3265 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3252 /tmp/sample.bin zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3252 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3254 /tmp/sample.bin guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3254 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255 /tmp/sample.bin net send-data write-config write-file zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256 /tmp/sample.bin net send-data zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3257 /tmp/sample.bin guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3257 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3258 /tmp/sample.bin guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3258 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3261 /tmp/sample.bin guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3261 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3262 /tmp/sample.bin net zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3262 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263 /tmp/sample.bin dns net send-data zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276 /tmp/sample.bin net send-data zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276 clone guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277 /tmp/sample.bin net send-data zombie guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3250->guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277 clone guuid=8d44f509-1700-0000-f1de-17a4bc0c0000 pid=3260 /usr/bin/sleep zombie guuid=8e591008-1700-0000-f1de-17a4b50c0000 pid=3253->guuid=8d44f509-1700-0000-f1de-17a4bc0c0000 pid=3260 execve 1ad9c798-25f3-5a56-b8ae-a2779943332c 202.61.139.18:808 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->1ad9c798-25f3-5a56-b8ae-a2779943332c con 83d81d2f-e15b-5db8-a3f9-a15962842b53 10.0.2.14:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->83d81d2f-e15b-5db8-a3f9-a15962842b53 con 97a8e555-7010-54a1-b7eb-3a0ae0d51945 10.0.2.9:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->97a8e555-7010-54a1-b7eb-3a0ae0d51945 con c613df2b-4db8-51ba-8db8-ba18de711dbf 10.0.2.12:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->c613df2b-4db8-51ba-8db8-ba18de711dbf con a315db70-8a33-56a9-b636-8a3eaebc21bd 10.0.2.13:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->a315db70-8a33-56a9-b636-8a3eaebc21bd con 3f636370-bb4c-5fae-86cc-2fd067dbf3b8 10.0.2.17:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->3f636370-bb4c-5fae-86cc-2fd067dbf3b8 con 9d817cf9-7be2-53fd-a4cf-174d7b98a152 10.0.2.15:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->9d817cf9-7be2-53fd-a4cf-174d7b98a152 send: 152B 2dc3b51e-82a3-5c56-868c-3ade17200e35 10.0.2.19:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->2dc3b51e-82a3-5c56-868c-3ade17200e35 con 28a4a7b2-7c8d-5800-912c-89c1c8c61701 10.0.2.23:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->28a4a7b2-7c8d-5800-912c-89c1c8c61701 con 73c90e7c-5f9c-5244-876d-0a2ec8869add 10.0.2.41:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->73c90e7c-5f9c-5244-876d-0a2ec8869add con 9074c81a-b4bc-5b85-ae06-4a973085219b 10.0.2.48:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->9074c81a-b4bc-5b85-ae06-4a973085219b con a04e7d2f-5f23-5ac2-8aa3-39d423a1e6fc 10.0.2.61:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->a04e7d2f-5f23-5ac2-8aa3-39d423a1e6fc con 5d337c40-36dd-5c87-a47b-c44cde958109 10.0.2.68:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->5d337c40-36dd-5c87-a47b-c44cde958109 con c83fe412-d0b8-57b7-b440-fefaf79edcde 10.0.2.73:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->c83fe412-d0b8-57b7-b440-fefaf79edcde con b89627d6-0cbb-5795-b84c-7b845573d36c 10.0.2.78:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->b89627d6-0cbb-5795-b84c-7b845573d36c con d68e7d4f-ddc3-517d-a4cd-a8807aebf639 10.0.2.84:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->d68e7d4f-ddc3-517d-a4cd-a8807aebf639 con 7b226ccd-3c97-5380-aa45-7beafbe544a5 10.0.2.85:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->7b226ccd-3c97-5380-aa45-7beafbe544a5 con 16fd670a-3fe8-558b-a4c1-add08ae321d6 10.0.2.90:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->16fd670a-3fe8-558b-a4c1-add08ae321d6 con f624398e-0d58-5578-aa62-3551ec812023 10.0.2.92:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->f624398e-0d58-5578-aa62-3551ec812023 con e8778b18-35db-52e6-bdc2-4e28433888e0 10.0.2.96:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->e8778b18-35db-52e6-bdc2-4e28433888e0 con ed80c3e0-b746-5d62-8d98-3d7f5a9d6c01 10.0.2.101:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->ed80c3e0-b746-5d62-8d98-3d7f5a9d6c01 con 33d38012-89e7-516c-8916-9defed2ee8cf 10.0.2.104:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->33d38012-89e7-516c-8916-9defed2ee8cf con 00286612-d7e5-58a5-98ad-529a83accb32 10.0.2.116:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->00286612-d7e5-58a5-98ad-529a83accb32 con d8db1263-8f85-5c6e-ba9c-f45c97718131 10.0.2.110:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->d8db1263-8f85-5c6e-ba9c-f45c97718131 con 3c3c62d7-7a37-5279-ba88-caeb3e6fceeb 10.0.2.111:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->3c3c62d7-7a37-5279-ba88-caeb3e6fceeb con 8f26c6b8-bfc2-5153-9a8f-a87efbcfa72d 10.0.2.115:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->8f26c6b8-bfc2-5153-9a8f-a87efbcfa72d con 04e78cdb-4982-5a45-9795-f322b551e7e4 10.0.2.140:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->04e78cdb-4982-5a45-9795-f322b551e7e4 con 0e000216-6b04-5e47-a53c-d2c475bf323d 10.0.2.147:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->0e000216-6b04-5e47-a53c-d2c475bf323d con 8bbfe728-9370-55fd-b676-d22caae775ec 10.0.2.149:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->8bbfe728-9370-55fd-b676-d22caae775ec con 0819ce4e-ebf3-5770-8005-5da255f90737 10.0.2.151:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->0819ce4e-ebf3-5770-8005-5da255f90737 con 5b6ac79e-2fcd-50e6-834f-e66bae2c880b 10.0.2.155:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->5b6ac79e-2fcd-50e6-834f-e66bae2c880b con b2b10218-0f1b-569d-a402-75de74f6dd16 10.0.2.157:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->b2b10218-0f1b-569d-a402-75de74f6dd16 con 645f66f3-6b5a-5ea9-8e70-eeb2da652a6d 10.0.2.160:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->645f66f3-6b5a-5ea9-8e70-eeb2da652a6d con 7f6f92f7-d3ec-5ff6-bf96-84d69fe0fe5a 10.0.2.164:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->7f6f92f7-d3ec-5ff6-bf96-84d69fe0fe5a con 4fa9b29c-c2d2-5945-bb5f-475cf86151ca 10.0.2.173:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->4fa9b29c-c2d2-5945-bb5f-475cf86151ca con 2d696f32-f293-5d60-b7aa-6128652ea4ad 10.0.2.181:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->2d696f32-f293-5d60-b7aa-6128652ea4ad con 29568ba1-78f5-584e-a649-3ea1395d810e 10.0.2.184:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->29568ba1-78f5-584e-a649-3ea1395d810e con 1a72ec62-2cbe-5f59-b335-eb25c9f87e4f 10.0.2.193:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->1a72ec62-2cbe-5f59-b335-eb25c9f87e4f con f1d4ed24-6e6d-5916-9581-67e2ffa0898c 10.0.2.195:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->f1d4ed24-6e6d-5916-9581-67e2ffa0898c con 077abc65-4e66-5c18-bc43-0727387542d6 10.0.2.197:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->077abc65-4e66-5c18-bc43-0727387542d6 con 97d6a838-8319-5033-bae4-91b24b871ceb 10.0.2.200:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->97d6a838-8319-5033-bae4-91b24b871ceb con 56292268-8421-56ff-94f6-50e781478c93 10.0.2.224:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->56292268-8421-56ff-94f6-50e781478c93 con 599a96cb-e27c-5371-a667-cde64c94ec68 10.0.2.228:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->599a96cb-e27c-5371-a667-cde64c94ec68 con 4f3237ce-23e2-5fc0-8e6f-a91196e53124 10.0.2.232:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->4f3237ce-23e2-5fc0-8e6f-a91196e53124 con 0707eacc-02f1-54e6-a3c6-08ac18926fac 10.0.2.234:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->0707eacc-02f1-54e6-a3c6-08ac18926fac con bd243c4c-e836-597e-867e-d10eef46fac2 10.0.2.237:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->bd243c4c-e836-597e-867e-d10eef46fac2 con 4211ca01-125e-5b46-9bd2-9c16927b27cc 10.0.2.241:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->4211ca01-125e-5b46-9bd2-9c16927b27cc con 1ac3e29e-ca9d-52b4-ac45-f04760c9fc15 10.0.2.242:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->1ac3e29e-ca9d-52b4-ac45-f04760c9fc15 con 70ef233e-bffa-5cfd-9cac-e3ed029b8831 10.0.2.244:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->70ef233e-bffa-5cfd-9cac-e3ed029b8831 con 2d271a68-cd6e-5b3f-a2a8-ef41b1188340 10.0.2.246:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->2d271a68-cd6e-5b3f-a2a8-ef41b1188340 con a8b194bd-d0da-50a5-889f-34f4840e36ab 10.0.2.248:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->a8b194bd-d0da-50a5-889f-34f4840e36ab con 7983d538-98dc-56d3-974f-6a66d01985f5 10.0.2.251:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->7983d538-98dc-56d3-974f-6a66d01985f5 con 4a1ce4a5-46fa-5c5a-aeec-fb14fa637143 10.0.2.254:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->4a1ce4a5-46fa-5c5a-aeec-fb14fa637143 con guuid=f6090f09-1700-0000-f1de-17a4bb0c0000 pid=3259 /usr/sbin/update-rc.d guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=f6090f09-1700-0000-f1de-17a4bb0c0000 pid=3259 execve guuid=2c4cf040-1700-0000-f1de-17a4510d0000 pid=3409 /usr/bin/journalctl guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=2c4cf040-1700-0000-f1de-17a4510d0000 pid=3409 execve guuid=5041fb01-1800-0000-f1de-17a4cc0f0000 pid=4044 /usr/bin/bash guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=5041fb01-1800-0000-f1de-17a4cc0f0000 pid=4044 execve guuid=b18f4c13-1800-0000-f1de-17a41b100000 pid=4123 /usr/bin/bash write-config guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=b18f4c13-1800-0000-f1de-17a41b100000 pid=4123 execve guuid=cc1ab063-1800-0000-f1de-17a431110000 pid=4401 /usr/bin/renice guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=cc1ab063-1800-0000-f1de-17a431110000 pid=4401 execve guuid=a3a01190-1800-0000-f1de-17a44a110000 pid=4426 /usr/bin/mount guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=a3a01190-1800-0000-f1de-17a44a110000 pid=4426 execve guuid=cf712a91-1800-0000-f1de-17a44d110000 pid=4429 /usr/bin/systemctl guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=cf712a91-1800-0000-f1de-17a44d110000 pid=4429 execve guuid=d133b3ee-1800-0000-f1de-17a4de120000 pid=4830 /usr/bin/systemctl guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3255->guuid=d133b3ee-1800-0000-f1de-17a4de120000 pid=4830 execve guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->1ad9c798-25f3-5a56-b8ae-a2779943332c send: 110B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->9d817cf9-7be2-53fd-a4cf-174d7b98a152 send: 28B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 32B c9041850-3bfa-5e0c-abba-99d02e90d717 10.0.2.20:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->c9041850-3bfa-5e0c-abba-99d02e90d717 con 46060b3c-beda-5a05-92a3-d50934c0c593 10.0.2.1:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->46060b3c-beda-5a05-92a3-d50934c0c593 con 0887288c-3010-55d3-880f-1bb7a8a0028d 10.0.2.2:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->0887288c-3010-55d3-880f-1bb7a8a0028d send: 988B 3afe4f29-1a44-51cc-8601-5d536a47b53e 10.0.2.3:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->3afe4f29-1a44-51cc-8601-5d536a47b53e con 873b101d-ab7a-51c3-89e6-9d8cee4ff4bc 10.0.2.4:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->873b101d-ab7a-51c3-89e6-9d8cee4ff4bc con 2eeafc02-30dd-515b-9154-ef855a93c813 10.0.2.5:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->2eeafc02-30dd-515b-9154-ef855a93c813 con 5a808136-519a-562c-93f5-ae3bd75dfda9 10.0.2.6:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->5a808136-519a-562c-93f5-ae3bd75dfda9 con 1cf83d00-3234-5ea9-a764-a14eeaf9e554 10.0.2.7:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->1cf83d00-3234-5ea9-a764-a14eeaf9e554 con e16771d7-2ecb-58da-a206-66602c03b902 10.0.2.8:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->e16771d7-2ecb-58da-a206-66602c03b902 con b0c121e7-74cd-5ef7-bbfa-710344193727 10.0.2.29:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->b0c121e7-74cd-5ef7-bbfa-710344193727 con 92eb57bc-9e2e-58e4-8912-89b7921a3ee7 10.0.2.30:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->92eb57bc-9e2e-58e4-8912-89b7921a3ee7 con 52ff7862-8827-58b2-ac9a-5f1e91d392ce 10.0.2.34:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->52ff7862-8827-58b2-ac9a-5f1e91d392ce con 1290d51f-7744-5283-90d1-052603da0e61 10.0.2.38:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->1290d51f-7744-5283-90d1-052603da0e61 con 7b702052-5ac5-5fcf-9b2c-5b979883c9f2 10.0.2.39:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->7b702052-5ac5-5fcf-9b2c-5b979883c9f2 con 9bc9ea8f-97f3-56a3-9c23-ef9f0fb09a41 10.0.2.45:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->9bc9ea8f-97f3-56a3-9c23-ef9f0fb09a41 con 6a602653-9951-5ff3-ad8b-1220139fd9b4 10.0.2.47:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->6a602653-9951-5ff3-ad8b-1220139fd9b4 con e47004ce-4bce-5a9d-a6ec-f3846742649b 10.0.2.51:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->e47004ce-4bce-5a9d-a6ec-f3846742649b con f1793252-8556-549c-b7dd-d668a3e4c175 10.0.2.54:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->f1793252-8556-549c-b7dd-d668a3e4c175 con 67041296-0d31-5ed7-9e5e-f94efbe82a4b 10.0.2.58:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->67041296-0d31-5ed7-9e5e-f94efbe82a4b con 21a59105-7405-52df-bf28-9df00a5fb48c 10.0.2.62:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->21a59105-7405-52df-bf28-9df00a5fb48c con 25aceb63-897f-5910-a489-c30be3e70379 10.0.2.72:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->25aceb63-897f-5910-a489-c30be3e70379 con d25252cd-3e21-59df-9a6b-86597511b136 10.0.2.75:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->d25252cd-3e21-59df-9a6b-86597511b136 con 029d3efd-b0db-56d9-a3b5-3560a9b97b05 10.0.2.79:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->029d3efd-b0db-56d9-a3b5-3560a9b97b05 con ca563dfe-f18a-530e-bc8d-82c58b3565b8 10.0.2.91:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->ca563dfe-f18a-530e-bc8d-82c58b3565b8 con 5025470c-55a8-5c87-8a8b-120e77387a9b 10.0.2.95:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->5025470c-55a8-5c87-8a8b-120e77387a9b con bc9af807-24ba-5fe4-8fd8-299e88a591e7 10.0.2.87:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->bc9af807-24ba-5fe4-8fd8-299e88a591e7 con 56d0dd2a-1011-52ee-b1d1-291c8f56e314 10.0.2.98:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->56d0dd2a-1011-52ee-b1d1-291c8f56e314 con 4feb4446-0514-5d8e-8716-5ee0f045f0c4 10.0.2.103:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->4feb4446-0514-5d8e-8716-5ee0f045f0c4 con dbef3c27-25f8-5dde-b1f0-f6fba17635f0 10.0.2.109:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->dbef3c27-25f8-5dde-b1f0-f6fba17635f0 con c40f1a1b-1d7e-5402-8953-75cd977950b7 10.0.2.106:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->c40f1a1b-1d7e-5402-8953-75cd977950b7 con f6b0a73d-bbb3-5da4-8e03-6ec08cdfe666 10.0.2.108:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->f6b0a73d-bbb3-5da4-8e03-6ec08cdfe666 con db3b7e50-1f07-581f-abf4-a5bc35ddd274 10.0.2.113:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->db3b7e50-1f07-581f-abf4-a5bc35ddd274 con e90472f0-76aa-5fff-89db-1c4b5043f174 10.0.2.121:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->e90472f0-76aa-5fff-89db-1c4b5043f174 con eae85a6b-401b-50cf-87c5-e076f6893ca6 10.0.2.125:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->eae85a6b-401b-50cf-87c5-e076f6893ca6 con 2f485b89-a93f-5a15-af10-7d9bbf811951 10.0.2.143:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->2f485b89-a93f-5a15-af10-7d9bbf811951 con d6891daa-e462-5904-8996-bdea1b6bd2f5 10.0.2.146:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->d6891daa-e462-5904-8996-bdea1b6bd2f5 con 7f48cc57-7e41-5517-861b-9b2324680374 10.0.2.148:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->7f48cc57-7e41-5517-861b-9b2324680374 con d576447a-6147-5dcc-8870-9511643230e2 10.0.2.152:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->d576447a-6147-5dcc-8870-9511643230e2 con bff3a5c6-6f20-5ae6-b63d-e6fbf222bea7 10.0.2.154:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->bff3a5c6-6f20-5ae6-b63d-e6fbf222bea7 con 1d21602e-f497-5c63-92b9-b447233c12b3 10.0.2.158:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->1d21602e-f497-5c63-92b9-b447233c12b3 con f9fc8235-7f45-5943-a658-7dc4d8feee86 10.0.2.161:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->f9fc8235-7f45-5943-a658-7dc4d8feee86 con 53f46b30-3f94-5203-a639-71694db5fceb 10.0.2.180:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->53f46b30-3f94-5203-a639-71694db5fceb con c7d5f8c8-53b4-59b1-a23b-b869747591b5 10.0.2.196:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->c7d5f8c8-53b4-59b1-a23b-b869747591b5 con 110fb964-abd4-5d32-a533-fe0b7952591e 10.0.2.199:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->110fb964-abd4-5d32-a533-fe0b7952591e con 215fbe0e-90dc-5683-99fe-df52cd87035f 10.0.2.205:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->215fbe0e-90dc-5683-99fe-df52cd87035f con fd8b1a83-d4cf-5eba-ad98-254bbf9aab49 10.0.2.209:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->fd8b1a83-d4cf-5eba-ad98-254bbf9aab49 con d94c2864-70da-5612-8e81-2d2940d2842b 10.0.2.213:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->d94c2864-70da-5612-8e81-2d2940d2842b con e8ca8269-05c6-5f85-9bd8-a483b0a0cdb6 10.0.2.217:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->e8ca8269-05c6-5f85-9bd8-a483b0a0cdb6 con 13e0699f-29a2-535e-8f62-5c4cf72e91ca 10.0.2.221:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->13e0699f-29a2-535e-8f62-5c4cf72e91ca con 42ec2164-a66d-5326-ba40-6dfbce7b3ab7 10.0.2.223:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->42ec2164-a66d-5326-ba40-6dfbce7b3ab7 con c0dd4847-72c5-52dd-b3fc-ac96bf781518 10.0.2.225:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->c0dd4847-72c5-52dd-b3fc-ac96bf781518 con 402a10e9-6485-5d2a-90ba-96afb21fb42f 10.0.2.240:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->402a10e9-6485-5d2a-90ba-96afb21fb42f con ab68c68c-c1d9-5f25-ab9c-80608d469a9e 202.61.139.18:8080 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3256->ab68c68c-c1d9-5f25-ab9c-80608d469a9e send: 439B guuid=7d2d8d0d-1700-0000-f1de-17a4c50c0000 pid=3269 /usr/bin/systemctl guuid=f6090f09-1700-0000-f1de-17a4bb0c0000 pid=3259->guuid=7d2d8d0d-1700-0000-f1de-17a4c50c0000 pid=3269 execve 7d9f530b-05c9-562b-88bc-04ea8a494b08 10.0.2.191:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3262->7d9f530b-05c9-562b-88bc-04ea8a494b08 con guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 32B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->0887288c-3010-55d3-880f-1bb7a8a0028d send: 100B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->ab68c68c-c1d9-5f25-ab9c-80608d469a9e send: 46B cd1e13fc-e338-52a2-99d9-63be1d9b9f9c www.google.com:9 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->cd1e13fc-e338-52a2-99d9-63be1d9b9f9c con e59fa316-f30f-5826-b67e-a26293327f71 10.0.2.26:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->e59fa316-f30f-5826-b67e-a26293327f71 con 0835d023-26d7-53d8-ba0a-0d8fede4bc78 10.0.2.36:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->0835d023-26d7-53d8-ba0a-0d8fede4bc78 con 50ddd700-acd6-54bd-952f-159b28a772d5 10.0.2.40:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->50ddd700-acd6-54bd-952f-159b28a772d5 con 5130a867-34a9-5428-a70f-0dd20e5099d6 10.0.2.43:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->5130a867-34a9-5428-a70f-0dd20e5099d6 con d0500f71-9e99-5332-aa99-abd4682c1e36 10.0.2.46:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->d0500f71-9e99-5332-aa99-abd4682c1e36 con 6f0ce902-2705-531c-8575-5fbef04d6336 10.0.2.49:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->6f0ce902-2705-531c-8575-5fbef04d6336 con 3649289a-223a-52c9-a896-282ede22de23 10.0.2.52:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->3649289a-223a-52c9-a896-282ede22de23 con 5b0cdcd6-8af3-547c-9a5b-5ed63aca3eff 10.0.2.55:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->5b0cdcd6-8af3-547c-9a5b-5ed63aca3eff con 57aa760d-bb86-57ca-95c2-8cb5ef2741da 10.0.2.59:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->57aa760d-bb86-57ca-95c2-8cb5ef2741da con 4a948a0a-c613-51a1-b3c7-addb262d9be6 10.0.2.65:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->4a948a0a-c613-51a1-b3c7-addb262d9be6 con f193af0c-80ed-54c6-b177-0e35be894156 10.0.2.67:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->f193af0c-80ed-54c6-b177-0e35be894156 con af97b281-d767-54d7-a8d4-10f7c34411c0 10.0.2.69:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->af97b281-d767-54d7-a8d4-10f7c34411c0 con 53fef550-8d60-5f16-b045-ae449f89dc0e 10.0.2.86:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->53fef550-8d60-5f16-b045-ae449f89dc0e con d0edc03e-b4b9-5d74-b451-70e3c7910f8e 10.0.2.89:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->d0edc03e-b4b9-5d74-b451-70e3c7910f8e con 33052f64-c949-5d14-bd48-51f41874ca35 10.0.2.93:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->33052f64-c949-5d14-bd48-51f41874ca35 con b2bbfc93-9d65-5b09-a167-2d2fb3ed5026 10.0.2.97:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->b2bbfc93-9d65-5b09-a167-2d2fb3ed5026 con dc1e59ab-4532-5ead-95c5-94da57ac704d 10.0.2.99:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->dc1e59ab-4532-5ead-95c5-94da57ac704d con beee456c-6f07-5a03-acb5-d48b92993aee 10.0.2.117:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->beee456c-6f07-5a03-acb5-d48b92993aee con aa41fe19-bec3-508e-92b8-f9697c9e7d38 10.0.2.107:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->aa41fe19-bec3-508e-92b8-f9697c9e7d38 con 01aaec74-021b-5c51-ab7a-1f3f235c122a 10.0.2.119:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->01aaec74-021b-5c51-ab7a-1f3f235c122a con ef1245bc-ecbe-5d59-a82d-938836979c1d 10.0.2.114:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->ef1245bc-ecbe-5d59-a82d-938836979c1d con fbb548e4-a46c-56cb-81ce-f872523dca7a 10.0.2.126:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->fbb548e4-a46c-56cb-81ce-f872523dca7a con f529807f-e334-5748-9ce4-9d69d9dc02b5 10.0.2.128:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->f529807f-e334-5748-9ce4-9d69d9dc02b5 con 42bf344d-7648-55a0-9e09-1935a66b3b90 10.0.2.131:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->42bf344d-7648-55a0-9e09-1935a66b3b90 con 037fbdd1-d5c1-504c-97ec-1b76092dbdaf 10.0.2.135:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->037fbdd1-d5c1-504c-97ec-1b76092dbdaf con abddd3e4-be32-5507-babe-ac4e4cdde2a0 10.0.2.138:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->abddd3e4-be32-5507-babe-ac4e4cdde2a0 con 5ed081dc-1705-5602-9ef5-dff6142f9a41 10.0.2.144:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->5ed081dc-1705-5602-9ef5-dff6142f9a41 con 27f8307d-0b0d-5581-bc40-64203af3c161 10.0.2.150:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->27f8307d-0b0d-5581-bc40-64203af3c161 con 612e1dd4-cee2-52fd-9905-7f3ed5cfd915 10.0.2.153:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->612e1dd4-cee2-52fd-9905-7f3ed5cfd915 con 9ff8ca48-e7e3-5e23-82b0-91740cb63c23 10.0.2.156:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->9ff8ca48-e7e3-5e23-82b0-91740cb63c23 con cdc1bbd7-e41e-5446-9f82-9c8dfa1cc50a 10.0.2.159:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->cdc1bbd7-e41e-5446-9f82-9c8dfa1cc50a con 8d22ed82-beca-579d-858a-6a5e5ab3ad34 10.0.2.169:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->8d22ed82-beca-579d-858a-6a5e5ab3ad34 con 139671ff-4c8b-5946-8965-533b2d0d1556 10.0.2.172:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->139671ff-4c8b-5946-8965-533b2d0d1556 con f1a3ad2a-9f06-5e44-93b3-8cf07a24726a 10.0.2.178:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->f1a3ad2a-9f06-5e44-93b3-8cf07a24726a con 0776b344-e84e-50cf-ad99-390e9d774129 10.0.2.183:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->0776b344-e84e-50cf-ad99-390e9d774129 con 60254c9f-f5b6-517b-bdb4-e8898ae93e3b 10.0.2.185:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->60254c9f-f5b6-517b-bdb4-e8898ae93e3b con 19f5584c-9086-5198-b1f5-ca4d27eec8e0 10.0.2.187:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->19f5584c-9086-5198-b1f5-ca4d27eec8e0 con 4a91e367-02ab-59bf-962c-279a78ace13c 10.0.2.190:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->4a91e367-02ab-59bf-962c-279a78ace13c con d05e4a21-98b2-5783-b944-307d9fd84172 10.0.2.194:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->d05e4a21-98b2-5783-b944-307d9fd84172 con 5cb622d2-76e8-59c6-ab3c-745916ce8e6a 10.0.2.198:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->5cb622d2-76e8-59c6-ab3c-745916ce8e6a con 619443d1-62ee-5b83-8d55-dacef8c91288 10.0.2.206:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->619443d1-62ee-5b83-8d55-dacef8c91288 con 456943d8-618e-5e02-941b-40afa0101e38 10.0.2.208:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->456943d8-618e-5e02-941b-40afa0101e38 con 5388836b-27b5-58fa-85c6-94dc23d51cd1 10.0.2.212:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->5388836b-27b5-58fa-85c6-94dc23d51cd1 con 30d07de2-8100-5efa-8e81-6f2a24f36012 10.0.2.222:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->30d07de2-8100-5efa-8e81-6f2a24f36012 con 7002f9ee-d06c-5737-97f2-52bd3bcc1550 10.0.2.243:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->7002f9ee-d06c-5737-97f2-52bd3bcc1550 con d20ccdfa-9ff2-5770-bd30-16bb42ed7e80 10.0.2.250:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->d20ccdfa-9ff2-5770-bd30-16bb42ed7e80 con 077eabbc-1b0a-5329-abb4-d3769852117f 10.0.2.253:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3263->077eabbc-1b0a-5329-abb4-d3769852117f con guuid=1bb3090b-1700-0000-f1de-17a4c20c0000 pid=3266 /usr/bin/systemctl guuid=0ec2000b-1700-0000-f1de-17a4c10c0000 pid=3265->guuid=1bb3090b-1700-0000-f1de-17a4c20c0000 pid=3266 execve guuid=03e00e0b-1700-0000-f1de-17a4c30c0000 pid=3267 /usr/bin/sed guuid=0ec2000b-1700-0000-f1de-17a4c10c0000 pid=3265->guuid=03e00e0b-1700-0000-f1de-17a4c30c0000 pid=3267 execve guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->9d817cf9-7be2-53fd-a4cf-174d7b98a152 send: 68B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->ab68c68c-c1d9-5f25-ab9c-80608d469a9e send: 162B b6c05b6e-212d-5e56-b294-c835d54c1ddd 10.0.2.24:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->b6c05b6e-212d-5e56-b294-c835d54c1ddd con 7c23ac2e-5c21-599c-a9af-1356577dc6e7 10.0.2.25:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->7c23ac2e-5c21-599c-a9af-1356577dc6e7 con 009b4003-f323-5782-ab6b-0fe99a07438f 10.0.2.27:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->009b4003-f323-5782-ab6b-0fe99a07438f con 05c264a8-b233-5970-8c2c-42ebfdc39370 10.0.2.32:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->05c264a8-b233-5970-8c2c-42ebfdc39370 con c4f24e32-dec0-564c-9196-41c143ef6f4b 10.0.2.33:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->c4f24e32-dec0-564c-9196-41c143ef6f4b con b4656088-50d8-5fe1-9dd4-ce1237be1719 10.0.2.60:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->b4656088-50d8-5fe1-9dd4-ce1237be1719 con 32531e1a-ad9e-51fb-902a-6c39b25b760a 10.0.2.64:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->32531e1a-ad9e-51fb-902a-6c39b25b760a con 159af6c9-f120-5f16-854e-8343b414e3a9 10.0.2.66:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->159af6c9-f120-5f16-854e-8343b414e3a9 con 9ee84a9c-eab8-52b9-beef-c5018d83f92a 10.0.2.70:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->9ee84a9c-eab8-52b9-beef-c5018d83f92a con 04e0b6a9-dffb-5ea7-8051-b8d84cf47445 10.0.2.74:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->04e0b6a9-dffb-5ea7-8051-b8d84cf47445 con 2671927a-d343-5490-bd4e-b6f0f47e59e8 10.0.2.77:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->2671927a-d343-5490-bd4e-b6f0f47e59e8 con b71f9504-40fb-551f-8664-c1a884e46de0 10.0.2.81:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->b71f9504-40fb-551f-8664-c1a884e46de0 con 0f2915fe-a44e-5728-924c-c8faebe01fd0 10.0.2.102:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->0f2915fe-a44e-5728-924c-c8faebe01fd0 con b8bc7bf0-6322-5435-93d8-e2da8a4c4d71 10.0.2.105:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->b8bc7bf0-6322-5435-93d8-e2da8a4c4d71 con 8374969d-d2ce-5e67-9201-dcec4b18f345 10.0.2.118:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->8374969d-d2ce-5e67-9201-dcec4b18f345 con 7c0becb3-d71d-5062-b512-0f0480f1597a 10.0.2.120:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->7c0becb3-d71d-5062-b512-0f0480f1597a con 6727a3bf-0d0d-56a2-8445-72cf933de715 10.0.2.112:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->6727a3bf-0d0d-56a2-8445-72cf933de715 con 7bfcd18c-caba-5709-9f15-5b0b8318e59f 10.0.2.122:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->7bfcd18c-caba-5709-9f15-5b0b8318e59f con 3dcf8c22-8e17-5d8f-a01a-1f9568ac6f67 10.0.2.124:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->3dcf8c22-8e17-5d8f-a01a-1f9568ac6f67 con 96d84990-0d7b-5455-800e-716d389ca250 10.0.2.127:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->96d84990-0d7b-5455-800e-716d389ca250 con cd24bf9c-c187-5b3f-b1a0-0466a775269f 10.0.2.130:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->cd24bf9c-c187-5b3f-b1a0-0466a775269f con 4631a9be-e435-535f-902c-bfe2c8f044d7 10.0.2.132:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->4631a9be-e435-535f-902c-bfe2c8f044d7 con 06e4b707-31b5-5146-8daf-6ddd65ebde1c 10.0.2.134:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->06e4b707-31b5-5146-8daf-6ddd65ebde1c con c639471f-c7a6-568f-aa03-9e6cd8cfddae 10.0.2.137:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->c639471f-c7a6-568f-aa03-9e6cd8cfddae con a7663d4b-a229-55e9-9a38-f45af09c31a8 10.0.2.141:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->a7663d4b-a229-55e9-9a38-f45af09c31a8 con c99b30ab-816a-535b-9c40-1e9d9a054eff 10.0.2.142:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->c99b30ab-816a-535b-9c40-1e9d9a054eff con 41cabb7a-1576-56e5-a6e2-4ff508f35697 10.0.2.162:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->41cabb7a-1576-56e5-a6e2-4ff508f35697 con a99f7b8b-33da-5605-be16-2a5fcd86eeec 10.0.2.163:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->a99f7b8b-33da-5605-be16-2a5fcd86eeec con 0ea558a1-c26f-5768-b248-c7f51d92d5e3 10.0.2.165:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->0ea558a1-c26f-5768-b248-c7f51d92d5e3 con b463e198-5778-5b6b-85da-07dc85d7c972 10.0.2.166:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->b463e198-5778-5b6b-85da-07dc85d7c972 con 753405a9-b2b6-5cb7-ae65-72eb0f4b06d8 10.0.2.168:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->753405a9-b2b6-5cb7-ae65-72eb0f4b06d8 con cd18bc58-7c96-5c1a-9f41-da1e591863ea 10.0.2.171:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->cd18bc58-7c96-5c1a-9f41-da1e591863ea con 8e5bc407-988e-53c8-977c-fced0e01f324 10.0.2.176:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->8e5bc407-988e-53c8-977c-fced0e01f324 con c03a267a-9eee-5b95-af7d-ce255e114faf 10.0.2.175:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->c03a267a-9eee-5b95-af7d-ce255e114faf con 72b1fc1f-5a5b-5940-b030-51428608cea2 10.0.2.201:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->72b1fc1f-5a5b-5940-b030-51428608cea2 con 8b65df6f-7f4f-51f9-9a9a-b0a305e41d9b 10.0.2.202:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->8b65df6f-7f4f-51f9-9a9a-b0a305e41d9b con 76c692a1-b1ac-53bc-8b57-7eef186e385a 10.0.2.203:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->76c692a1-b1ac-53bc-8b57-7eef186e385a con e84688dd-2416-5b21-9876-df467d344955 10.0.2.207:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->e84688dd-2416-5b21-9876-df467d344955 con 076a69d5-3dde-5c03-9337-b98cf6db44a6 10.0.2.210:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->076a69d5-3dde-5c03-9337-b98cf6db44a6 con 35db970a-8417-550f-b204-19e7c1bc82d0 10.0.2.214:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->35db970a-8417-550f-b204-19e7c1bc82d0 con 7331ad21-2598-5c36-87b3-e9b954c28a4d 10.0.2.218:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->7331ad21-2598-5c36-87b3-e9b954c28a4d con 33c22d8f-966e-5327-a118-45469a7ab8c8 10.0.2.219:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->33c22d8f-966e-5327-a118-45469a7ab8c8 con 08adccb3-9af8-51cc-b6b1-dddf8e312395 10.0.2.227:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->08adccb3-9af8-51cc-b6b1-dddf8e312395 con 28f70d51-4cc6-56ab-90b8-674b4b692820 10.0.2.229:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->28f70d51-4cc6-56ab-90b8-674b4b692820 con 166bc0ce-c8bf-58f2-9ba4-4d8efac83382 10.0.2.231:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->166bc0ce-c8bf-58f2-9ba4-4d8efac83382 con 4d71c607-2cbd-58a1-a41f-e970b25a3684 10.0.2.235:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->4d71c607-2cbd-58a1-a41f-e970b25a3684 con 435a5fcc-4a60-5739-8178-48cd7b8b4a71 10.0.2.236:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->435a5fcc-4a60-5739-8178-48cd7b8b4a71 con a469d357-9d6e-59bc-b3d8-28740cc3d807 10.0.2.245:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->a469d357-9d6e-59bc-b3d8-28740cc3d807 con f10d82cd-18bb-52f1-a5e9-f0e08f6173fb 10.0.2.249:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->f10d82cd-18bb-52f1-a5e9-f0e08f6173fb con bc65579d-3e1f-5ee0-8d62-09b44becc373 10.0.2.252:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3276->bc65579d-3e1f-5ee0-8d62-09b44becc373 con guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->9d817cf9-7be2-53fd-a4cf-174d7b98a152 send: 2232B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->0887288c-3010-55d3-880f-1bb7a8a0028d send: 68B guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->ab68c68c-c1d9-5f25-ab9c-80608d469a9e send: 23B a986940d-ed4d-5ea7-b963-82f2e5b52cb7 10.0.2.21:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->a986940d-ed4d-5ea7-b963-82f2e5b52cb7 con 2b9fb6e0-3baf-55d0-91cb-002832be391f 10.0.2.11:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->2b9fb6e0-3baf-55d0-91cb-002832be391f con bd936fc3-a037-5d5b-8704-0f4a616ae4f4 10.0.2.10:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->bd936fc3-a037-5d5b-8704-0f4a616ae4f4 con 53739cb2-0554-554a-8a1f-63979db5472f 10.0.2.18:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->53739cb2-0554-554a-8a1f-63979db5472f con 9fd2e189-b843-5517-a9d3-69e680e1b1a7 10.0.2.16:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->9fd2e189-b843-5517-a9d3-69e680e1b1a7 con 6c2a853a-5e0f-59be-82ba-016631aeb6e8 10.0.2.22:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->6c2a853a-5e0f-59be-82ba-016631aeb6e8 con 180fcb7c-e66d-5376-adfe-3e622a9d30dd 10.0.2.28:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->180fcb7c-e66d-5376-adfe-3e622a9d30dd con b86b5e37-4fc4-5417-9634-c61996acb808 10.0.2.31:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->b86b5e37-4fc4-5417-9634-c61996acb808 con 38ef701b-a44c-5c92-b919-6ea8264e1879 10.0.2.37:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->38ef701b-a44c-5c92-b919-6ea8264e1879 con a22075bb-8726-5bbd-9568-343c0a5a5f27 10.0.2.35:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->a22075bb-8726-5bbd-9568-343c0a5a5f27 con dcae47e3-d751-5aac-9959-f13d98318678 10.0.2.42:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->dcae47e3-d751-5aac-9959-f13d98318678 con efcf5ce1-02fa-5f41-a0e0-d5e6b0469102 10.0.2.44:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->efcf5ce1-02fa-5f41-a0e0-d5e6b0469102 con 8bb776fc-4ea3-5582-82df-b67236773748 10.0.2.50:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->8bb776fc-4ea3-5582-82df-b67236773748 con c91b6ec0-bc93-51af-a897-5185067d162f 10.0.2.53:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->c91b6ec0-bc93-51af-a897-5185067d162f con b3b4a7fd-9f98-5f70-bf32-02dacfbb9b53 10.0.2.56:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->b3b4a7fd-9f98-5f70-bf32-02dacfbb9b53 con 1f39095f-da34-5d2f-bb49-cf3c30940c55 10.0.2.57:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->1f39095f-da34-5d2f-bb49-cf3c30940c55 con 93428481-4aff-5ebf-954d-ca11d00613b1 10.0.2.63:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->93428481-4aff-5ebf-954d-ca11d00613b1 con eea75d2a-1449-5b13-b095-b690b80c52be 10.0.2.71:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->eea75d2a-1449-5b13-b095-b690b80c52be con bf532ea9-0da7-5beb-8c46-e1d4a0cf390e 10.0.2.76:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->bf532ea9-0da7-5beb-8c46-e1d4a0cf390e con f7eb6467-e866-5205-815f-553887be2481 10.0.2.80:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->f7eb6467-e866-5205-815f-553887be2481 con 0d5d4d97-ea7f-5212-9c92-90a7420dd154 10.0.2.82:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->0d5d4d97-ea7f-5212-9c92-90a7420dd154 con 01d73926-1544-58ee-95eb-86a04596b79f 10.0.2.83:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->01d73926-1544-58ee-95eb-86a04596b79f con d7ded370-27bc-500b-bcdb-73a6e6f0d38d 10.0.2.88:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d7ded370-27bc-500b-bcdb-73a6e6f0d38d con 8bd8cd88-05c7-50bf-bc9f-5bf819548114 10.0.2.94:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->8bd8cd88-05c7-50bf-bc9f-5bf819548114 con 2c7672bf-0597-54f2-9df3-7c3303c2eecd 10.0.2.100:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->2c7672bf-0597-54f2-9df3-7c3303c2eecd con 6f91c899-4601-534c-bcff-841da76d2107 10.0.2.123:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->6f91c899-4601-534c-bcff-841da76d2107 con db4a220b-b627-5cdb-a228-e7d911b2c932 10.0.2.129:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->db4a220b-b627-5cdb-a228-e7d911b2c932 con a14834cb-1104-5230-8d8c-a76294d4f7e8 10.0.2.133:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->a14834cb-1104-5230-8d8c-a76294d4f7e8 con efb0290c-4ade-5d29-85f6-37861e862ddd 10.0.2.136:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->efb0290c-4ade-5d29-85f6-37861e862ddd con 7bb0e4b2-67ee-5963-a3fd-7e1f903b99aa 10.0.2.139:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->7bb0e4b2-67ee-5963-a3fd-7e1f903b99aa con 24139e1a-937e-5641-b14f-789af3d2b32a 10.0.2.145:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->24139e1a-937e-5641-b14f-789af3d2b32a con 82d832df-5b0c-5c7e-a7d0-821c411a6d7a 10.0.2.167:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->82d832df-5b0c-5c7e-a7d0-821c411a6d7a con b64f7e37-70be-5d7b-ba08-b46a0564a034 10.0.2.170:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->b64f7e37-70be-5d7b-ba08-b46a0564a034 con 057ae678-e02c-58c6-81c4-e5cd6fbc0edc 10.0.2.174:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->057ae678-e02c-58c6-81c4-e5cd6fbc0edc con e8469aa0-e52b-5731-ba88-ae1c2e58016f 10.0.2.177:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->e8469aa0-e52b-5731-ba88-ae1c2e58016f con d903d590-5421-520e-b69d-bc059ce5bea9 10.0.2.179:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d903d590-5421-520e-b69d-bc059ce5bea9 con d3ecbf92-60a3-5a99-a6a7-1aa84cf73b07 10.0.2.182:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d3ecbf92-60a3-5a99-a6a7-1aa84cf73b07 con 025c0966-4de0-5a30-971c-8b83c2cc3d6e 10.0.2.186:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->025c0966-4de0-5a30-971c-8b83c2cc3d6e con e85462c0-e4c3-5a15-9171-01338c070ce9 10.0.2.188:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->e85462c0-e4c3-5a15-9171-01338c070ce9 con d0bcc857-2bbe-5832-a4b5-cf14a93d9abf 10.0.2.192:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d0bcc857-2bbe-5832-a4b5-cf14a93d9abf con 8553768e-e529-5e11-993b-acd173c21088 10.0.2.189:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->8553768e-e529-5e11-993b-acd173c21088 con d21a8d0d-a79c-5634-bcea-4b73be1eebdf 10.0.2.204:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d21a8d0d-a79c-5634-bcea-4b73be1eebdf con f52be5da-e3b7-55ef-b42b-ad6cc693381a 10.0.2.211:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->f52be5da-e3b7-55ef-b42b-ad6cc693381a con 6f4faafb-3aca-545d-913b-66b1c394fec9 10.0.2.215:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->6f4faafb-3aca-545d-913b-66b1c394fec9 con 5d877d1d-4178-53a7-ab3c-537bae7c6d61 10.0.2.216:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->5d877d1d-4178-53a7-ab3c-537bae7c6d61 con d8c8bec3-291e-5359-8e75-f189f4ad1e7d 10.0.2.220:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d8c8bec3-291e-5359-8e75-f189f4ad1e7d con 33fe96e8-8641-51a9-813d-c2fe0f1ade61 10.0.2.226:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->33fe96e8-8641-51a9-813d-c2fe0f1ade61 con d29881f0-6e8b-5a1c-973e-2b70aba7443c 10.0.2.230:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->d29881f0-6e8b-5a1c-973e-2b70aba7443c con 1bda5fb5-d34b-5255-b497-e65a25eceee8 10.0.2.233:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->1bda5fb5-d34b-5255-b497-e65a25eceee8 con 86b3cb90-017f-57be-89a2-4e61e8013221 10.0.2.238:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->86b3cb90-017f-57be-89a2-4e61e8013221 con 8ac0bf94-e2b9-51f8-9275-294f3de5fa3b 10.0.2.239:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->8ac0bf94-e2b9-51f8-9275-294f3de5fa3b con bed43a8a-54b4-5432-ab22-92d12da3eab8 10.0.2.247:22 guuid=f23a0607-1700-0000-f1de-17a4b20c0000 pid=3277->bed43a8a-54b4-5432-ab22-92d12da3eab8 con guuid=112d3241-1700-0000-f1de-17a4530d0000 pid=3411 /usr/bin/systemctl guuid=2c4cf040-1700-0000-f1de-17a4510d0000 pid=3409->guuid=112d3241-1700-0000-f1de-17a4530d0000 pid=3411 execve guuid=792eefc2-1700-0000-f1de-17a4de0e0000 pid=3806 /usr/bin/systemctl guuid=2c4cf040-1700-0000-f1de-17a4510d0000 pid=3409->guuid=792eefc2-1700-0000-f1de-17a4de0e0000 pid=3806 execve guuid=f8b661f0-1700-0000-f1de-17a4790f0000 pid=3961 /usr/bin/systemctl guuid=2c4cf040-1700-0000-f1de-17a4510d0000 pid=3409->guuid=f8b661f0-1700-0000-f1de-17a4790f0000 pid=3961 execve guuid=2fdaba13-0000-0000-f1de-17a401000000 pid=1 /usr/lib/systemd/systemd guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968 /boot/System.img.config guuid=2fdaba13-0000-0000-f1de-17a401000000 pid=1->guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968 execve guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3986 /boot/System.img.config guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3986 clone guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3987 /boot/System.img.config guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3987 clone guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3989 /boot/System.img.config guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3989 clone guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3990 /boot/System.img.config guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3990 clone guuid=0dbde8f7-1700-0000-f1de-17a4970f0000 pid=3991 /usr/bin/pgrep guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=0dbde8f7-1700-0000-f1de-17a4970f0000 pid=3991 execve guuid=cb1b6dfa-1700-0000-f1de-17a4a50f0000 pid=4005 /usr/bin/dash guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=cb1b6dfa-1700-0000-f1de-17a4a50f0000 pid=4005 execve guuid=7a7177fa-1700-0000-f1de-17a4a60f0000 pid=4006 /usr/bin/systemctl zombie guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=7a7177fa-1700-0000-f1de-17a4a60f0000 pid=4006 execve guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008 /boot/System.img.config zombie guuid=11ce9ff1-1700-0000-f1de-17a4800f0000 pid=3968->guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008 execve guuid=3f8899fa-1700-0000-f1de-17a4a70f0000 pid=4007 /etc/32678 zombie guuid=cb1b6dfa-1700-0000-f1de-17a4a50f0000 pid=4005->guuid=3f8899fa-1700-0000-f1de-17a4a70f0000 pid=4007 execve guuid=e313c5fa-1700-0000-f1de-17a4a90f0000 pid=4009 /usr/bin/basename guuid=7a7177fa-1700-0000-f1de-17a4a60f0000 pid=4006->guuid=e313c5fa-1700-0000-f1de-17a4a90f0000 pid=4009 execve guuid=38afdffd-1700-0000-f1de-17a4b20f0000 pid=4018 /usr/bin/basename guuid=7a7177fa-1700-0000-f1de-17a4a60f0000 pid=4006->guuid=38afdffd-1700-0000-f1de-17a4b20f0000 pid=4018 execve guuid=73d87bfe-1700-0000-f1de-17a4b50f0000 pid=4021 /usr/bin/dash guuid=7a7177fa-1700-0000-f1de-17a4a60f0000 pid=4006->guuid=73d87bfe-1700-0000-f1de-17a4b50f0000 pid=4021 clone guuid=0272f2fb-1700-0000-f1de-17a4ad0f0000 pid=4013 /usr/bin/sleep guuid=3f8899fa-1700-0000-f1de-17a4a70f0000 pid=4007->guuid=0272f2fb-1700-0000-f1de-17a4ad0f0000 pid=4013 execve guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4026 /boot/System.img.config guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008->guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4026 clone guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4027 /boot/System.img.config guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008->guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4027 clone guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4028 /boot/System.img.config guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008->guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4028 clone guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4029 /boot/System.img.config guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4008->guuid=e323a6fa-1700-0000-f1de-17a4a80f0000 pid=4029 clone guuid=5d64a6fe-1700-0000-f1de-17a4b60f0000 pid=4022 /usr/bin/systemctl guuid=73d87bfe-1700-0000-f1de-17a4b50f0000 pid=4021->guuid=5d64a6fe-1700-0000-f1de-17a4b60f0000 pid=4022 execve guuid=2bc9acfe-1700-0000-f1de-17a4b80f0000 pid=4024 /usr/bin/sed guuid=73d87bfe-1700-0000-f1de-17a4b50f0000 pid=4021->guuid=2bc9acfe-1700-0000-f1de-17a4b80f0000 pid=4024 execve guuid=c887c102-1800-0000-f1de-17a4d20f0000 pid=4050 /usr/bin/bash guuid=5041fb01-1800-0000-f1de-17a4cc0f0000 pid=4044->guuid=c887c102-1800-0000-f1de-17a4d20f0000 pid=4050 clone guuid=8b58c602-1800-0000-f1de-17a4d30f0000 pid=4051 /usr/bin/bash guuid=5041fb01-1800-0000-f1de-17a4cc0f0000 pid=4044->guuid=8b58c602-1800-0000-f1de-17a4d30f0000 pid=4051 clone guuid=4e298b91-1800-0000-f1de-17a44f110000 pid=4431 /usr/bin/basename guuid=cf712a91-1800-0000-f1de-17a44d110000 pid=4429->guuid=4e298b91-1800-0000-f1de-17a44f110000 pid=4431 execve guuid=c8953992-1800-0000-f1de-17a453110000 pid=4435 /usr/bin/basename guuid=cf712a91-1800-0000-f1de-17a44d110000 pid=4429->guuid=c8953992-1800-0000-f1de-17a453110000 pid=4435 execve guuid=4bc19d92-1800-0000-f1de-17a454110000 pid=4436 /usr/bin/dash guuid=cf712a91-1800-0000-f1de-17a44d110000 pid=4429->guuid=4bc19d92-1800-0000-f1de-17a454110000 pid=4436 clone guuid=d18fa892-1800-0000-f1de-17a455110000 pid=4437 /usr/bin/systemctl guuid=4bc19d92-1800-0000-f1de-17a454110000 pid=4436->guuid=d18fa892-1800-0000-f1de-17a455110000 pid=4437 execve guuid=eb1fb692-1800-0000-f1de-17a456110000 pid=4438 /usr/bin/sed guuid=4bc19d92-1800-0000-f1de-17a454110000 pid=4436->guuid=eb1fb692-1800-0000-f1de-17a456110000 pid=4438 execve guuid=2c7419bc-1800-0000-f1de-17a4ff110000 pid=4607 /usr/share/initramfs-tools/hooks/udev guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719 /usr/bin/find guuid=2c7419bc-1800-0000-f1de-17a4ff110000 pid=4607->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719 execve guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728 /usr/bin/find guuid=2c7419bc-1800-0000-f1de-17a4ff110000 pid=4607->guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728 execve guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4720 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4720 clone guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4721 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4721 clone guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4722 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4722 clone guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4723 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4723 clone guuid=5e6d52d8-1800-0000-f1de-17a474120000 pid=4724 /usr/bin/lib/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=5e6d52d8-1800-0000-f1de-17a474120000 pid=4724 execve guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4725 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4725 clone guuid=3b5370d9-1800-0000-f1de-17a477120000 pid=4727 /usr/bin/find guuid=d20353d4-1800-0000-f1de-17a46f120000 pid=4719->guuid=3b5370d9-1800-0000-f1de-17a477120000 pid=4727 clone guuid=32c09dd8-1800-0000-f1de-17a476120000 pid=4726 /usr/bin/cp guuid=5e6d52d8-1800-0000-f1de-17a474120000 pid=4724->guuid=32c09dd8-1800-0000-f1de-17a476120000 pid=4726 execve guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4729 /usr/bin/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4729 clone guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4730 /usr/bin/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4730 clone guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4731 /usr/bin/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4731 clone guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4732 /usr/bin/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4732 clone guuid=24eddcd9-1800-0000-f1de-17a47d120000 pid=4733 /usr/bin/lib/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=24eddcd9-1800-0000-f1de-17a47d120000 pid=4733 execve guuid=b0d125da-1800-0000-f1de-17a47e120000 pid=4734 /usr/bin/find guuid=223b87d9-1800-0000-f1de-17a478120000 pid=4728->guuid=b0d125da-1800-0000-f1de-17a47e120000 pid=4734 clone guuid=284ce5bd-1200-0000-f1de-17a401030000 pid=769 /usr/bin/dash guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292 /usr/bin/find guuid=284ce5bd-1200-0000-f1de-17a401030000 pid=769->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292 execve guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344 /usr/bin/find guuid=284ce5bd-1200-0000-f1de-17a401030000 pid=769->guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344 execve guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5293 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5293 clone guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5294 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5294 clone guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5295 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5295 clone guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5296 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5296 clone guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5297 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5297 clone guuid=468e3ec7-1900-0000-f1de-17a4b2140000 pid=5298 /usr/bin/lib/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=468e3ec7-1900-0000-f1de-17a4b2140000 pid=5298 execve guuid=1a2a6dcb-1900-0000-f1de-17a4b3140000 pid=5299 /usr/bin/find guuid=e840ebc1-1900-0000-f1de-17a4ac140000 pid=5292->guuid=1a2a6dcb-1900-0000-f1de-17a4b3140000 pid=5299 clone guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5346 /usr/bin/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5346 clone guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5347 /usr/bin/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5347 clone guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5348 /usr/bin/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5348 clone guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5349 /usr/bin/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5349 clone guuid=2026d1da-1900-0000-f1de-17a4e6140000 pid=5350 /usr/bin/lib/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=2026d1da-1900-0000-f1de-17a4e6140000 pid=5350 execve guuid=1838cddb-1900-0000-f1de-17a4e7140000 pid=5351 /usr/bin/find guuid=323020d6-1900-0000-f1de-17a4e0140000 pid=5344->guuid=1838cddb-1900-0000-f1de-17a4e7140000 pid=5351 clone guuid=1472c6ea-1900-0000-f1de-17a4ef140000 pid=5359 /usr/bin/dash guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361 /usr/bin/find guuid=1472c6ea-1900-0000-f1de-17a4ef140000 pid=5359->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361 execve guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5364 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5364 clone guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5365 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5365 clone guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5366 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5366 clone guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5367 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5367 clone guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5368 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5368 clone guuid=e8b258eb-1900-0000-f1de-17a4f9140000 pid=5369 /usr/bin/lib/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5361->guuid=e8b258eb-1900-0000-f1de-17a4f9140000 pid=5369 execve guuid=8a93b2ef-1900-0000-f1de-17a4fa140000 pid=5370 /usr/bin/find guuid=6c5fd5ea-1900-0000-f1de-17a4f1140000 pid=5365->guuid=8a93b2ef-1900-0000-f1de-17a4fa140000 pid=5370 clone
Result
Threat name:
Detection:
malicious
Classification:
spre.troj.evad
Score:
76 / 100
Signature
Drops files in suspicious directories
Multi AV Scanner detection for submitted file
Sample tries to persist itself using /etc/profile
Sample tries to persist itself using cron
Sample tries to set files in /etc globally writable
Uses known network protocols on non-standard ports
Yara detected Chaos
Behaviour
Behavior Graph:
behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1785277 Sample: bin.x86.elf Startdate: 27/09/2025 Architecture: LINUX Score: 76 120 202.61.139.18, 35194, 38500, 808 TH-AS-APTianhaiInfoTechCN Australia 2->120 122 109.202.202.202, 80 INIT7CH Switzerland 2->122 124 4 other IPs or domains 2->124 126 Multi AV Scanner detection for submitted file 2->126 128 Yara detected Chaos 2->128 130 Uses known network protocols on non-standard ports 2->130 12 dash rm bin.x86.elf 2->12         started        16 systemd System.img.config 2->16         started        18 systemd cron 2->18         started        20 18 other processes 2->20 signatures3 process4 file5 118 /etc/32678, POSIX 12->118 dropped 140 Sample tries to set files in /etc globally writable 12->140 22 bin.x86.elf bin.x86.elf 12->22         started        26 bin.x86.elf service systemctl 12->26         started        28 bin.x86.elf bash 12->28         started        30 System.img.config sh 16->30         started        32 System.img.config service systemctl 16->32         started        38 2 other processes 16->38 34 cron 18->34         started        36 cron 20->36         started        40 2 other processes 20->40 signatures6 process7 file8 108 /etc/profile.d/bash_config.sh, a 22->108 dropped 110 /etc/init.d/ssh, POSIX 22->110 dropped 112 /etc/init.d/linux_kill, POSIX 22->112 dropped 114 /.img, a 22->114 dropped 132 Sample tries to set files in /etc globally writable 22->132 134 Sample tries to persist itself using /etc/profile 22->134 136 Drops files in suspicious directories 22->136 42 bin.x86.elf bash 22->42         started        46 bin.x86.elf service systemctl 22->46         started        56 6 other processes 22->56 58 4 other processes 26->58 48 bash 32678 28->48         started        50 sh 32678 30->50         started        60 4 other processes 32->60 52 cron sh 34->52         started        54 cron sh 36->54         started        signatures9 process10 file11 116 /etc/crontab, ASCII 42->116 dropped 138 Sample tries to persist itself using cron 42->138 72 4 other processes 46->72 62 32678 sleep 48->62         started        64 32678 id.services.conf 50->64         started        66 32678 sleep 50->66         started        68 sh 52->68         started        70 sh 54->70         started        74 8 other processes 56->74 76 2 other processes 58->76 78 2 other processes 60->78 signatures12 process13 process14 80 id.services.conf service systemctl 64->80         started        82 id.services.conf sh 64->82         started        84 id.services.conf pkill 64->84         started        86 id.services.conf id.services.conf 64->86         started        88 service systemctl 72->88         started        90 service sed 72->90         started        process15 92 service 80->92         started        94 service basename 80->94         started        96 service basename 80->96         started        98 service systemctl 80->98         started        100 sh 32678 82->100         started        process16 102 service systemctl 92->102         started        104 service sed 92->104         started        106 32678 sleep 100->106         started       
Threat name:
Linux.Trojan.Kaiji
Status:
Malicious
First seen:
2025-09-27 21:19:28 UTC
File Type:
ELF64 Little (Exe)
AV detection:
14 of 24 (58.33%)
Threat level:
  5/5
Result
Malware family:
Score:
  10/10
Tags:
family:kaiji defense_evasion discovery execution linux persistence privilege_escalation
Behaviour
GoLang User-Agent
Enumerates kernel/hardware configuration
Reads runtime system information
Changes its process name
Reads CPU attributes
Modifies Bash startup script
Creates/modifies Cron job
Creates/modifies environment variables
Enumerates running processes
Modifies init.d
Write file to user bin folder
Executes dropped EXE
Modifies Watchdog functionality
Kaiji
Kaiji family
kaiji_chaosbot
Malware Config
C2 Extraction:
202.61.139.18:8080
Verdict:
Unknown
Tags:
trojan chaos kaiji
YARA:
Linux_Trojan_Kaiji_dcf6565e ELF_Kaiji_Chaos_April_2024
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:botnet_plaintext_c2
Author:cip
Description:Attempts to match at least some of the strings used in some botnet variants which use plaintext communication protocols.
Rule name:CP_AllMal_Detector
Author:DiegoAnalytics
Description:CrossPlatform All Malwares Detector: Detect PE, ELF, Mach-O, scripts, archives; overlay, obfuscation, encryption, spoofing, hiding, high entropy, network communication
Rule name:CP_Script_Inject_Detector
Author:DiegoAnalytics
Description:Detects attempts to inject code into another process across PE, ELF, Mach-O binaries
Rule name:DetectEncryptedVariants
Author:Zinyth
Description:Detects 'encrypted' in ASCII, Unicode, base64, or hex-encoded
Rule name:DetectGoMethodSignatures
Author:Wyatt Tauber
Description:Detects Go method signatures in unpacked Go binaries
Rule name:Detect_Go_GOMAXPROCS
Author:Obscurity Labs LLC
Description:Detects Go binaries by the presence of runtime.GOMAXPROCS in the runtime metadata
Rule name:enterpriseapps2
Author:Tim Brown @timb_machine
Description:Enterprise apps
Rule name:F01_s1ckrule
Author:s1ckb017
Rule name:GoBinTest
Rule name:golang
Rule name:golang_binary_string
Description:Golang strings present
Rule name:golang_duffcopy_amd64
Rule name:identity_golang
Author:Eric Yocam
Description:find Golang malware
Rule name:Linux_Generic_Threat_a40aaa96
Author:Elastic Security
Rule name:Linux_Trojan_Kaiji_dcf6565e
Author:Elastic Security
Rule name:MD5_Constants
Author:phoul (@phoul)
Description:Look for MD5 constants
Rule name:NET
Author:malware-lu
Rule name:ProgramLanguage_Golang
Author:albertzsigovits
Description:Application written in Golang programming language
Rule name:RANSOMWARE
Author:ToroGuitar
Rule name:RIPEMD160_Constants
Author:phoul (@phoul)
Description:Look for RIPEMD-160 constants
Rule name:setsockopt
Author:Tim Brown @timb_machine
Description:Hunts for setsockopt() red flags
Rule name:SHA1_Constants
Author:phoul (@phoul)
Description:Look for SHA1 constants
Rule name:SHA512_Constants
Author:phoul (@phoul)
Description:Look for SHA384/SHA512 constants
Rule name:unixredflags3
Author:Tim Brown @timb_machine
Description:Hunts for UNIX red flags

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Kaiji

elf fb58552f2e41f83d38518142997eab68d9f1068b597ad43549ab44f9b2621af5

(this sample)

  
Delivery method
Distributed via web download

Comments