MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0a250561ca65c5f2dfda31b2023438463ce1133d350937949908af44118c4a43. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 0a250561ca65c5f2dfda31b2023438463ce1133d350937949908af44118c4a43
SHA3-384 hash: 33619cb706a7cf76287bd957179d42972f8dd9d4c78695858bd8a4048f99b8466b187f2c9ff3cc73aedf17eb4818b735
SHA1 hash: 93e82598a742029d62856e67d0e020b25a333652
MD5 hash: 2ee620371105f60b122d4253ea9d995a
humanhash: stairway-solar-juliet-video
File name:run-ss.sh
Download: download sample
File size:3'658 bytes
First seen:2025-07-16 02:41:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vL/5miMcHzybWgRHZ+d/T4pKhnShcAanliDz+yQhK44T7D02K42cgMQzd/uAE:1miJzom7ZhnShcAal1yv7D1K42crAVE
TLSH T1E8713216788092BD111AC4B4A2CE94553A04C11B0B483E3C7AEED4361F757F4B7FA7E6
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=3c1b64bf-1600-0000-c5e7-ed03d40c0000 pid=3284 /usr/bin/sudo guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289 /tmp/sample.bin guuid=3c1b64bf-1600-0000-c5e7-ed03d40c0000 pid=3284->guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289 execve guuid=ebb608c2-1600-0000-c5e7-ed03da0c0000 pid=3290 /usr/bin/date guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=ebb608c2-1600-0000-c5e7-ed03da0c0000 pid=3290 execve guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291 /usr/bin/apt-get delete-file write-file guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291 execve guuid=b5dddb5c-1800-0000-c5e7-ed03e8110000 pid=4584 /usr/bin/apt-get guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=b5dddb5c-1800-0000-c5e7-ed03e8110000 pid=4584 execve guuid=c0030c6a-1800-0000-c5e7-ed03ea110000 pid=4586 /usr/bin/rm guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=c0030c6a-1800-0000-c5e7-ed03ea110000 pid=4586 execve guuid=e9d8ae6a-1800-0000-c5e7-ed03eb110000 pid=4587 /usr/bin/rm guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=e9d8ae6a-1800-0000-c5e7-ed03eb110000 pid=4587 execve guuid=760c416b-1800-0000-c5e7-ed03ec110000 pid=4588 /usr/bin/rm guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=760c416b-1800-0000-c5e7-ed03ec110000 pid=4588 execve guuid=1703db6b-1800-0000-c5e7-ed03ee110000 pid=4590 /usr/bin/rm guuid=ecba88c1-1600-0000-c5e7-ed03d90c0000 pid=3289->guuid=1703db6b-1800-0000-c5e7-ed03ee110000 pid=4590 execve guuid=54c0cbc3-1600-0000-c5e7-ed03e10c0000 pid=3297 /usr/bin/dpkg guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=54c0cbc3-1600-0000-c5e7-ed03e10c0000 pid=3297 execve guuid=6b24b8c4-1600-0000-c5e7-ed03e40c0000 pid=3300 /usr/lib/apt/methods/mirror guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=6b24b8c4-1600-0000-c5e7-ed03e40c0000 pid=3300 execve guuid=b52b1ac6-1600-0000-c5e7-ed03ea0c0000 pid=3306 /usr/lib/apt/methods/mirror guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=b52b1ac6-1600-0000-c5e7-ed03ea0c0000 pid=3306 execve guuid=151eb8c7-1600-0000-c5e7-ed03ef0c0000 pid=3311 /usr/lib/apt/methods/file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=151eb8c7-1600-0000-c5e7-ed03ef0c0000 pid=3311 execve guuid=297f97c8-1600-0000-c5e7-ed03f20c0000 pid=3314 /usr/lib/apt/methods/file delete-file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=297f97c8-1600-0000-c5e7-ed03f20c0000 pid=3314 execve guuid=9a3612ca-1600-0000-c5e7-ed03f40c0000 pid=3316 /usr/lib/apt/methods/http guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=9a3612ca-1600-0000-c5e7-ed03f40c0000 pid=3316 execve guuid=d818fecb-1600-0000-c5e7-ed03fb0c0000 pid=3323 /usr/lib/apt/methods/http dns net send-data write-file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=d818fecb-1600-0000-c5e7-ed03fb0c0000 pid=3323 execve guuid=2619e7e1-1600-0000-c5e7-ed031a0d0000 pid=3354 /usr/lib/apt/methods/gpgv guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=2619e7e1-1600-0000-c5e7-ed031a0d0000 pid=3354 execve guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360 /usr/lib/apt/methods/gpgv guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360 execve guuid=c4bab30f-1700-0000-c5e7-ed03db0d0000 pid=3547 /usr/lib/apt/methods/rred guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=c4bab30f-1700-0000-c5e7-ed03db0d0000 pid=3547 execve guuid=ac886114-1700-0000-c5e7-ed03e10d0000 pid=3553 /usr/lib/apt/methods/rred write-file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=ac886114-1700-0000-c5e7-ed03e10d0000 pid=3553 execve guuid=c63e7e15-1700-0000-c5e7-ed03e50d0000 pid=3557 /usr/lib/apt/methods/rred write-file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=c63e7e15-1700-0000-c5e7-ed03e50d0000 pid=3557 execve guuid=aa6bd939-1700-0000-c5e7-ed033c0e0000 pid=3644 /usr/lib/apt/methods/store guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=aa6bd939-1700-0000-c5e7-ed033c0e0000 pid=3644 execve guuid=87ea933a-1700-0000-c5e7-ed03410e0000 pid=3649 /usr/lib/apt/methods/store write-file guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=87ea933a-1700-0000-c5e7-ed03410e0000 pid=3649 execve guuid=7dcce156-1700-0000-c5e7-ed039a0e0000 pid=3738 /usr/bin/dpkg guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=7dcce156-1700-0000-c5e7-ed039a0e0000 pid=3738 execve guuid=4870c358-1800-0000-c5e7-ed03e7110000 pid=4583 /usr/bin/dpkg guuid=8c468ac2-1600-0000-c5e7-ed03db0c0000 pid=3291->guuid=4870c358-1800-0000-c5e7-ed03e7110000 pid=4583 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=d818fecb-1600-0000-c5e7-ed03fb0c0000 pid=3323->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=d818fecb-1600-0000-c5e7-ed03fb0c0000 pid=3323->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf send: 5132B guuid=806f2ee4-1600-0000-c5e7-ed03230d0000 pid=3363 /usr/lib/apt/methods/gpgv delete-file write-file guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360->guuid=806f2ee4-1600-0000-c5e7-ed03230d0000 pid=3363 clone guuid=8ed33df7-1600-0000-c5e7-ed03730d0000 pid=3443 /usr/lib/apt/methods/gpgv delete-file write-file guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360->guuid=8ed33df7-1600-0000-c5e7-ed03730d0000 pid=3443 clone guuid=f6c14f0a-1700-0000-c5e7-ed03c90d0000 pid=3529 /usr/lib/apt/methods/gpgv delete-file write-file guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360->guuid=f6c14f0a-1700-0000-c5e7-ed03c90d0000 pid=3529 clone guuid=d6a0851f-1700-0000-c5e7-ed03060e0000 pid=3590 /usr/lib/apt/methods/gpgv delete-file write-file guuid=66b946e3-1600-0000-c5e7-ed03200d0000 pid=3360->guuid=d6a0851f-1700-0000-c5e7-ed03060e0000 pid=3590 clone guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371 /usr/bin/apt-key write-file guuid=806f2ee4-1600-0000-c5e7-ed03230d0000 pid=3363->guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371 execve guuid=cfa348e6-1600-0000-c5e7-ed032c0d0000 pid=3372 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=cfa348e6-1600-0000-c5e7-ed032c0d0000 pid=3372 clone guuid=461956e6-1600-0000-c5e7-ed032d0d0000 pid=3373 /usr/bin/apt-config guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=461956e6-1600-0000-c5e7-ed032d0d0000 pid=3373 execve guuid=0dcf2ee9-1600-0000-c5e7-ed03340d0000 pid=3380 /usr/bin/apt-config guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=0dcf2ee9-1600-0000-c5e7-ed03340d0000 pid=3380 execve guuid=0c59c7ea-1600-0000-c5e7-ed033c0d0000 pid=3388 /usr/bin/apt-config guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=0c59c7ea-1600-0000-c5e7-ed033c0d0000 pid=3388 execve guuid=c8fc36ec-1600-0000-c5e7-ed03430d0000 pid=3395 /usr/bin/apt-config guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=c8fc36ec-1600-0000-c5e7-ed03430d0000 pid=3395 execve guuid=7c697fed-1600-0000-c5e7-ed03470d0000 pid=3399 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=7c697fed-1600-0000-c5e7-ed03470d0000 pid=3399 clone guuid=74c79fed-1600-0000-c5e7-ed03490d0000 pid=3401 /usr/bin/apt-config guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=74c79fed-1600-0000-c5e7-ed03490d0000 pid=3401 execve guuid=0e5d5df3-1600-0000-c5e7-ed03570d0000 pid=3415 /usr/bin/mktemp guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=0e5d5df3-1600-0000-c5e7-ed03570d0000 pid=3415 execve guuid=5fc29bf3-1600-0000-c5e7-ed03590d0000 pid=3417 /usr/bin/chmod guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=5fc29bf3-1600-0000-c5e7-ed03590d0000 pid=3417 execve guuid=65f2caf3-1600-0000-c5e7-ed035b0d0000 pid=3419 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=65f2caf3-1600-0000-c5e7-ed035b0d0000 pid=3419 clone guuid=6befe3f3-1600-0000-c5e7-ed035c0d0000 pid=3420 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=6befe3f3-1600-0000-c5e7-ed035c0d0000 pid=3420 clone guuid=ffed4bf4-1600-0000-c5e7-ed03610d0000 pid=3425 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=ffed4bf4-1600-0000-c5e7-ed03610d0000 pid=3425 clone guuid=131badf4-1600-0000-c5e7-ed03650d0000 pid=3429 /usr/bin/dash guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=131badf4-1600-0000-c5e7-ed03650d0000 pid=3429 clone guuid=1152bdf4-1600-0000-c5e7-ed03670d0000 pid=3431 /usr/bin/gpgv guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=1152bdf4-1600-0000-c5e7-ed03670d0000 pid=3431 execve guuid=498b82f6-1600-0000-c5e7-ed036f0d0000 pid=3439 /usr/bin/rm delete-file guuid=1cbf13e6-1600-0000-c5e7-ed032b0d0000 pid=3371->guuid=498b82f6-1600-0000-c5e7-ed036f0d0000 pid=3439 execve guuid=66d655e8-1600-0000-c5e7-ed03320d0000 pid=3378 /usr/bin/dpkg guuid=461956e6-1600-0000-c5e7-ed032d0d0000 pid=3373->guuid=66d655e8-1600-0000-c5e7-ed03320d0000 pid=3378 execve guuid=66272dea-1600-0000-c5e7-ed03390d0000 pid=3385 /usr/bin/dpkg guuid=0dcf2ee9-1600-0000-c5e7-ed03340d0000 pid=3380->guuid=66272dea-1600-0000-c5e7-ed03390d0000 pid=3385 execve guuid=94989beb-1600-0000-c5e7-ed03400d0000 pid=3392 /usr/bin/dpkg guuid=0c59c7ea-1600-0000-c5e7-ed033c0d0000 pid=3388->guuid=94989beb-1600-0000-c5e7-ed03400d0000 pid=3392 execve guuid=873807ed-1600-0000-c5e7-ed03460d0000 pid=3398 /usr/bin/dpkg guuid=c8fc36ec-1600-0000-c5e7-ed03430d0000 pid=3395->guuid=873807ed-1600-0000-c5e7-ed03460d0000 pid=3398 execve guuid=cbe6c6ee-1600-0000-c5e7-ed034a0d0000 pid=3402 /usr/bin/dpkg guuid=74c79fed-1600-0000-c5e7-ed03490d0000 pid=3401->guuid=cbe6c6ee-1600-0000-c5e7-ed034a0d0000 pid=3402 execve guuid=8429f5f3-1600-0000-c5e7-ed035e0d0000 pid=3422 /usr/bin/dash guuid=6befe3f3-1600-0000-c5e7-ed035c0d0000 pid=3420->guuid=8429f5f3-1600-0000-c5e7-ed035e0d0000 pid=3422 clone guuid=7766faf3-1600-0000-c5e7-ed035f0d0000 pid=3423 /usr/bin/sed guuid=6befe3f3-1600-0000-c5e7-ed035c0d0000 pid=3420->guuid=7766faf3-1600-0000-c5e7-ed035f0d0000 pid=3423 execve guuid=047255f4-1600-0000-c5e7-ed03620d0000 pid=3426 /usr/bin/dash guuid=ffed4bf4-1600-0000-c5e7-ed03610d0000 pid=3425->guuid=047255f4-1600-0000-c5e7-ed03620d0000 pid=3426 clone guuid=a6db5af4-1600-0000-c5e7-ed03630d0000 pid=3427 /usr/bin/sed guuid=ffed4bf4-1600-0000-c5e7-ed03610d0000 pid=3425->guuid=a6db5af4-1600-0000-c5e7-ed03630d0000 pid=3427 execve guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447 /usr/bin/apt-key write-file guuid=8ed33df7-1600-0000-c5e7-ed03730d0000 pid=3443->guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447 execve guuid=85d717f8-1600-0000-c5e7-ed03790d0000 pid=3449 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=85d717f8-1600-0000-c5e7-ed03790d0000 pid=3449 clone guuid=16c62bf8-1600-0000-c5e7-ed037a0d0000 pid=3450 /usr/bin/apt-config guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=16c62bf8-1600-0000-c5e7-ed037a0d0000 pid=3450 execve guuid=99f988fe-1600-0000-c5e7-ed038f0d0000 pid=3471 /usr/bin/apt-config guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=99f988fe-1600-0000-c5e7-ed038f0d0000 pid=3471 execve guuid=639a9b00-1700-0000-c5e7-ed03980d0000 pid=3480 /usr/bin/apt-config guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=639a9b00-1700-0000-c5e7-ed03980d0000 pid=3480 execve guuid=90aa4502-1700-0000-c5e7-ed039f0d0000 pid=3487 /usr/bin/apt-config guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=90aa4502-1700-0000-c5e7-ed039f0d0000 pid=3487 execve guuid=cf00f703-1700-0000-c5e7-ed03a50d0000 pid=3493 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=cf00f703-1700-0000-c5e7-ed03a50d0000 pid=3493 clone guuid=8a412604-1700-0000-c5e7-ed03a70d0000 pid=3495 /usr/bin/apt-config guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=8a412604-1700-0000-c5e7-ed03a70d0000 pid=3495 execve guuid=d87e0906-1700-0000-c5e7-ed03af0d0000 pid=3503 /usr/bin/mktemp guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=d87e0906-1700-0000-c5e7-ed03af0d0000 pid=3503 execve guuid=6cf24606-1700-0000-c5e7-ed03b10d0000 pid=3505 /usr/bin/chmod guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=6cf24606-1700-0000-c5e7-ed03b10d0000 pid=3505 execve guuid=34957806-1700-0000-c5e7-ed03b30d0000 pid=3507 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=34957806-1700-0000-c5e7-ed03b30d0000 pid=3507 clone guuid=90228906-1700-0000-c5e7-ed03b40d0000 pid=3508 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=90228906-1700-0000-c5e7-ed03b40d0000 pid=3508 clone guuid=253bfe06-1700-0000-c5e7-ed03b80d0000 pid=3512 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=253bfe06-1700-0000-c5e7-ed03b80d0000 pid=3512 clone guuid=fbc57907-1700-0000-c5e7-ed03bd0d0000 pid=3517 /usr/bin/dash guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=fbc57907-1700-0000-c5e7-ed03bd0d0000 pid=3517 clone guuid=adfa8b07-1700-0000-c5e7-ed03be0d0000 pid=3518 /usr/bin/gpgv guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=adfa8b07-1700-0000-c5e7-ed03be0d0000 pid=3518 execve guuid=40d05c09-1700-0000-c5e7-ed03c50d0000 pid=3525 /usr/bin/rm delete-file guuid=7bc3e0f7-1600-0000-c5e7-ed03770d0000 pid=3447->guuid=40d05c09-1700-0000-c5e7-ed03c50d0000 pid=3525 execve guuid=c24ef3f9-1600-0000-c5e7-ed03810d0000 pid=3457 /usr/bin/dpkg guuid=16c62bf8-1600-0000-c5e7-ed037a0d0000 pid=3450->guuid=c24ef3f9-1600-0000-c5e7-ed03810d0000 pid=3457 execve guuid=4bc6bdff-1600-0000-c5e7-ed03940d0000 pid=3476 /usr/bin/dpkg guuid=99f988fe-1600-0000-c5e7-ed038f0d0000 pid=3471->guuid=4bc6bdff-1600-0000-c5e7-ed03940d0000 pid=3476 execve guuid=cc47cd01-1700-0000-c5e7-ed039c0d0000 pid=3484 /usr/bin/dpkg guuid=639a9b00-1700-0000-c5e7-ed03980d0000 pid=3480->guuid=cc47cd01-1700-0000-c5e7-ed039c0d0000 pid=3484 execve guuid=2eb17a03-1700-0000-c5e7-ed03a30d0000 pid=3491 /usr/bin/dpkg guuid=90aa4502-1700-0000-c5e7-ed039f0d0000 pid=3487->guuid=2eb17a03-1700-0000-c5e7-ed03a30d0000 pid=3491 execve guuid=f6bb5105-1700-0000-c5e7-ed03ac0d0000 pid=3500 /usr/bin/dpkg guuid=8a412604-1700-0000-c5e7-ed03a70d0000 pid=3495->guuid=f6bb5105-1700-0000-c5e7-ed03ac0d0000 pid=3500 execve guuid=ddf89106-1700-0000-c5e7-ed03b50d0000 pid=3509 /usr/bin/dash guuid=90228906-1700-0000-c5e7-ed03b40d0000 pid=3508->guuid=ddf89106-1700-0000-c5e7-ed03b50d0000 pid=3509 clone guuid=55079906-1700-0000-c5e7-ed03b60d0000 pid=3510 /usr/bin/sed guuid=90228906-1700-0000-c5e7-ed03b40d0000 pid=3508->guuid=55079906-1700-0000-c5e7-ed03b60d0000 pid=3510 execve guuid=6a2c0707-1700-0000-c5e7-ed03b90d0000 pid=3513 /usr/bin/dash guuid=253bfe06-1700-0000-c5e7-ed03b80d0000 pid=3512->guuid=6a2c0707-1700-0000-c5e7-ed03b90d0000 pid=3513 clone guuid=d4830c07-1700-0000-c5e7-ed03ba0d0000 pid=3514 /usr/bin/sed guuid=253bfe06-1700-0000-c5e7-ed03b80d0000 pid=3512->guuid=d4830c07-1700-0000-c5e7-ed03ba0d0000 pid=3514 execve guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533 /usr/bin/apt-key write-file guuid=f6c14f0a-1700-0000-c5e7-ed03c90d0000 pid=3529->guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533 execve guuid=4579a90b-1700-0000-c5e7-ed03cf0d0000 pid=3535 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=4579a90b-1700-0000-c5e7-ed03cf0d0000 pid=3535 clone guuid=b48ebd0b-1700-0000-c5e7-ed03d00d0000 pid=3536 /usr/bin/apt-config guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=b48ebd0b-1700-0000-c5e7-ed03d00d0000 pid=3536 execve guuid=e212410e-1700-0000-c5e7-ed03da0d0000 pid=3546 /usr/bin/apt-config guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=e212410e-1700-0000-c5e7-ed03da0d0000 pid=3546 execve guuid=46ab4911-1700-0000-c5e7-ed03dd0d0000 pid=3549 /usr/bin/apt-config guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=46ab4911-1700-0000-c5e7-ed03dd0d0000 pid=3549 execve guuid=fa470113-1700-0000-c5e7-ed03df0d0000 pid=3551 /usr/bin/apt-config guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=fa470113-1700-0000-c5e7-ed03df0d0000 pid=3551 execve guuid=d0995c1a-1700-0000-c5e7-ed03f10d0000 pid=3569 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=d0995c1a-1700-0000-c5e7-ed03f10d0000 pid=3569 clone guuid=04e5931a-1700-0000-c5e7-ed03f20d0000 pid=3570 /usr/bin/apt-config guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=04e5931a-1700-0000-c5e7-ed03f20d0000 pid=3570 execve guuid=4d61151c-1700-0000-c5e7-ed03f90d0000 pid=3577 /usr/bin/mktemp guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=4d61151c-1700-0000-c5e7-ed03f90d0000 pid=3577 execve guuid=a9c1441c-1700-0000-c5e7-ed03fa0d0000 pid=3578 /usr/bin/chmod guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=a9c1441c-1700-0000-c5e7-ed03fa0d0000 pid=3578 execve guuid=3eb0711c-1700-0000-c5e7-ed03fc0d0000 pid=3580 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=3eb0711c-1700-0000-c5e7-ed03fc0d0000 pid=3580 clone guuid=470d811c-1700-0000-c5e7-ed03fd0d0000 pid=3581 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=470d811c-1700-0000-c5e7-ed03fd0d0000 pid=3581 clone guuid=bc21d51c-1700-0000-c5e7-ed03000e0000 pid=3584 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=bc21d51c-1700-0000-c5e7-ed03000e0000 pid=3584 clone guuid=3343371d-1700-0000-c5e7-ed03030e0000 pid=3587 /usr/bin/dash guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=3343371d-1700-0000-c5e7-ed03030e0000 pid=3587 clone guuid=9803461d-1700-0000-c5e7-ed03040e0000 pid=3588 /usr/bin/gpgv guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=9803461d-1700-0000-c5e7-ed03040e0000 pid=3588 execve guuid=713e7b1e-1700-0000-c5e7-ed03050e0000 pid=3589 /usr/bin/rm delete-file guuid=560f690b-1700-0000-c5e7-ed03cd0d0000 pid=3533->guuid=713e7b1e-1700-0000-c5e7-ed03050e0000 pid=3589 execve guuid=f685ba0d-1700-0000-c5e7-ed03d90d0000 pid=3545 /usr/bin/dpkg guuid=b48ebd0b-1700-0000-c5e7-ed03d00d0000 pid=3536->guuid=f685ba0d-1700-0000-c5e7-ed03d90d0000 pid=3545 execve guuid=5fa29210-1700-0000-c5e7-ed03dc0d0000 pid=3548 /usr/bin/dpkg guuid=e212410e-1700-0000-c5e7-ed03da0d0000 pid=3546->guuid=5fa29210-1700-0000-c5e7-ed03dc0d0000 pid=3548 execve guuid=a26b8312-1700-0000-c5e7-ed03de0d0000 pid=3550 /usr/bin/dpkg guuid=46ab4911-1700-0000-c5e7-ed03dd0d0000 pid=3549->guuid=a26b8312-1700-0000-c5e7-ed03de0d0000 pid=3550 execve guuid=9d9e2214-1700-0000-c5e7-ed03e00d0000 pid=3552 /usr/bin/dpkg guuid=fa470113-1700-0000-c5e7-ed03df0d0000 pid=3551->guuid=9d9e2214-1700-0000-c5e7-ed03e00d0000 pid=3552 execve guuid=85ba991b-1700-0000-c5e7-ed03f60d0000 pid=3574 /usr/bin/dpkg guuid=04e5931a-1700-0000-c5e7-ed03f20d0000 pid=3570->guuid=85ba991b-1700-0000-c5e7-ed03f60d0000 pid=3574 execve guuid=c31f891c-1700-0000-c5e7-ed03fe0d0000 pid=3582 /usr/bin/dash guuid=470d811c-1700-0000-c5e7-ed03fd0d0000 pid=3581->guuid=c31f891c-1700-0000-c5e7-ed03fe0d0000 pid=3582 clone guuid=39ca8d1c-1700-0000-c5e7-ed03ff0d0000 pid=3583 /usr/bin/sed guuid=470d811c-1700-0000-c5e7-ed03fd0d0000 pid=3581->guuid=39ca8d1c-1700-0000-c5e7-ed03ff0d0000 pid=3583 execve guuid=7893de1c-1700-0000-c5e7-ed03010e0000 pid=3585 /usr/bin/dash guuid=bc21d51c-1700-0000-c5e7-ed03000e0000 pid=3584->guuid=7893de1c-1700-0000-c5e7-ed03010e0000 pid=3585 clone guuid=043ce31c-1700-0000-c5e7-ed03020e0000 pid=3586 /usr/bin/sed guuid=bc21d51c-1700-0000-c5e7-ed03000e0000 pid=3584->guuid=043ce31c-1700-0000-c5e7-ed03020e0000 pid=3586 execve guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591 /usr/bin/apt-key write-file guuid=d6a0851f-1700-0000-c5e7-ed03060e0000 pid=3590->guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591 execve guuid=16c47f20-1700-0000-c5e7-ed03080e0000 pid=3592 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=16c47f20-1700-0000-c5e7-ed03080e0000 pid=3592 clone guuid=05899820-1700-0000-c5e7-ed03090e0000 pid=3593 /usr/bin/apt-config guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=05899820-1700-0000-c5e7-ed03090e0000 pid=3593 execve guuid=ace17722-1700-0000-c5e7-ed030b0e0000 pid=3595 /usr/bin/apt-config guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=ace17722-1700-0000-c5e7-ed030b0e0000 pid=3595 execve guuid=5bd62624-1700-0000-c5e7-ed030d0e0000 pid=3597 /usr/bin/apt-config guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=5bd62624-1700-0000-c5e7-ed030d0e0000 pid=3597 execve guuid=f09e5125-1700-0000-c5e7-ed030f0e0000 pid=3599 /usr/bin/apt-config guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=f09e5125-1700-0000-c5e7-ed030f0e0000 pid=3599 execve guuid=56537626-1700-0000-c5e7-ed03110e0000 pid=3601 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=56537626-1700-0000-c5e7-ed03110e0000 pid=3601 clone guuid=a68da926-1700-0000-c5e7-ed03120e0000 pid=3602 /usr/bin/apt-config guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=a68da926-1700-0000-c5e7-ed03120e0000 pid=3602 execve guuid=40195428-1700-0000-c5e7-ed03140e0000 pid=3604 /usr/bin/mktemp guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=40195428-1700-0000-c5e7-ed03140e0000 pid=3604 execve guuid=d9d09628-1700-0000-c5e7-ed03150e0000 pid=3605 /usr/bin/chmod guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=d9d09628-1700-0000-c5e7-ed03150e0000 pid=3605 execve guuid=38abce28-1700-0000-c5e7-ed03170e0000 pid=3607 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=38abce28-1700-0000-c5e7-ed03170e0000 pid=3607 clone guuid=394de228-1700-0000-c5e7-ed03180e0000 pid=3608 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=394de228-1700-0000-c5e7-ed03180e0000 pid=3608 clone guuid=8a064229-1700-0000-c5e7-ed031b0e0000 pid=3611 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=8a064229-1700-0000-c5e7-ed031b0e0000 pid=3611 clone guuid=ac8aae29-1700-0000-c5e7-ed031f0e0000 pid=3615 /usr/bin/dash guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=ac8aae29-1700-0000-c5e7-ed031f0e0000 pid=3615 clone guuid=8d91c129-1700-0000-c5e7-ed03200e0000 pid=3616 /usr/bin/gpgv guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=8d91c129-1700-0000-c5e7-ed03200e0000 pid=3616 execve guuid=5d3a3b2b-1700-0000-c5e7-ed03240e0000 pid=3620 /usr/bin/rm delete-file guuid=d4192320-1700-0000-c5e7-ed03070e0000 pid=3591->guuid=5d3a3b2b-1700-0000-c5e7-ed03240e0000 pid=3620 execve guuid=e67ad021-1700-0000-c5e7-ed030a0e0000 pid=3594 /usr/bin/dpkg guuid=05899820-1700-0000-c5e7-ed03090e0000 pid=3593->guuid=e67ad021-1700-0000-c5e7-ed030a0e0000 pid=3594 execve guuid=3ff29c23-1700-0000-c5e7-ed030c0e0000 pid=3596 /usr/bin/dpkg guuid=ace17722-1700-0000-c5e7-ed030b0e0000 pid=3595->guuid=3ff29c23-1700-0000-c5e7-ed030c0e0000 pid=3596 execve guuid=87a4ed24-1700-0000-c5e7-ed030e0e0000 pid=3598 /usr/bin/dpkg guuid=5bd62624-1700-0000-c5e7-ed030d0e0000 pid=3597->guuid=87a4ed24-1700-0000-c5e7-ed030e0e0000 pid=3598 execve guuid=d8ec1726-1700-0000-c5e7-ed03100e0000 pid=3600 /usr/bin/dpkg guuid=f09e5125-1700-0000-c5e7-ed030f0e0000 pid=3599->guuid=d8ec1726-1700-0000-c5e7-ed03100e0000 pid=3600 execve guuid=316e9627-1700-0000-c5e7-ed03130e0000 pid=3603 /usr/bin/dpkg guuid=a68da926-1700-0000-c5e7-ed03120e0000 pid=3602->guuid=316e9627-1700-0000-c5e7-ed03130e0000 pid=3603 execve guuid=52f8e928-1700-0000-c5e7-ed03190e0000 pid=3609 /usr/bin/dash guuid=394de228-1700-0000-c5e7-ed03180e0000 pid=3608->guuid=52f8e928-1700-0000-c5e7-ed03190e0000 pid=3609 clone guuid=a572f028-1700-0000-c5e7-ed031a0e0000 pid=3610 /usr/bin/sed guuid=394de228-1700-0000-c5e7-ed03180e0000 pid=3608->guuid=a572f028-1700-0000-c5e7-ed031a0e0000 pid=3610 execve guuid=aab84b29-1700-0000-c5e7-ed031c0e0000 pid=3612 /usr/bin/dash guuid=8a064229-1700-0000-c5e7-ed031b0e0000 pid=3611->guuid=aab84b29-1700-0000-c5e7-ed031c0e0000 pid=3612 clone guuid=b5f15129-1700-0000-c5e7-ed031d0e0000 pid=3613 /usr/bin/sed guuid=8a064229-1700-0000-c5e7-ed031b0e0000 pid=3611->guuid=b5f15129-1700-0000-c5e7-ed031d0e0000 pid=3613 execve guuid=bde3ae68-1800-0000-c5e7-ed03e9110000 pid=4585 /usr/bin/dpkg guuid=b5dddb5c-1800-0000-c5e7-ed03e8110000 pid=4584->guuid=bde3ae68-1800-0000-c5e7-ed03e9110000 pid=4585 execve
Threat name:
Win32.Trojan.Generic
Status:
Suspicious
First seen:
2025-07-16 02:42:26 UTC
File Type:
Text (Shell)
AV detection:
5 of 24 (20.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery execution linux privilege_escalation
Behaviour
Software Deployment Tools
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Legitimate hosting services abused for malware hosting/C2
Reads Bash history
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0a250561ca65c5f2dfda31b2023438463ce1133d350937949908af44118c4a43

(this sample)

  
Delivery method
Distributed via web download

Comments