MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0e7af68125450f1a0071d23518fa90f4c9f7d6342d7edd077cc4888e8da1ca2c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 0e7af68125450f1a0071d23518fa90f4c9f7d6342d7edd077cc4888e8da1ca2c
SHA3-384 hash: 14fc931370c3a0e5ed735224d1502f0597f38945f2b9758079f43aec87c77461a3751c62b560a64a2aedaf288a65877b
SHA1 hash: 4bad0a76d2cccc8014461f969e2c108ff1541bf2
MD5 hash: ab778dde6547652461c88b872b521014
humanhash: lamp-bacon-golf-lactose
File name:dddd.sh
Download: download sample
File size:2'396 bytes
First seen:2026-03-19 21:18:26 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:kn5S62iw079ymGW+DKpbuA/MzLoFa9vXyBQlcqD:QXdt6
TLSH T1B34192CA0B79D832B5D57D18BABAC048DD9DAAC7ACD1041AC5E41F345974AA432C3FE2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://libs.9tb.org/linux_386n/an/aelf mirai ua-wget x86
http://libs.9tb.org/linux_aarch64n/an/aarm elf mirai ua-wget
http://libs.9tb.org/linux_amd64n/an/aelf mirai ua-wget x86
http://libs.9tb.org/linux_arm57b45e5dc85e06ce7d05fef0596066df3a584200b25d9808051253152e886a963 Gafgytarm elf mirai ua-wget
http://libs.9tb.org/linux_arm68c2ebd1990cb95e7ded08c14cf1a273921fb14a941f280f60e8fbcea4a9961e4 Gafgytarm elf mirai ua-wget
http://libs.9tb.org/linux_arm70090764bcf2db6ec2c2dfac1726190d219b05174727f330c998452cef71edab2 Gafgytarm elf mirai ua-wget
http://libs.9tb.org/linux_mips64n/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_mips64eln/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_mips_hardfloatn/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_mips_softfloatn/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_mipsel_hardfloatn/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_mipsel_softfloatn/an/aelf mips mirai ua-wget
http://libs.9tb.org/linux_ppc64n/an/aelf mirai PowerPC ua-wget
http://libs.9tb.org/linux_ppc64eln/an/aelf mirai PowerPC ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=bd73aa6e-1a00-0000-8ec6-6d864d0a0000 pid=2637 /usr/bin/sudo guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644 /tmp/sample.bin guuid=bd73aa6e-1a00-0000-8ec6-6d864d0a0000 pid=2637->guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644 execve guuid=f1043372-1a00-0000-8ec6-6d86560a0000 pid=2646 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=f1043372-1a00-0000-8ec6-6d86560a0000 pid=2646 execve guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2930 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2930 execve guuid=32274429-1c00-0000-8ec6-6d86440d0000 pid=3396 /usr/bin/cat guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=32274429-1c00-0000-8ec6-6d86440d0000 pid=3396 execve guuid=e3f9282d-1c00-0000-8ec6-6d864d0d0000 pid=3405 /usr/bin/chmod guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=e3f9282d-1c00-0000-8ec6-6d864d0d0000 pid=3405 execve guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406 /tmp/run_386 guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406 execve guuid=a33c9a34-1c00-0000-8ec6-6d86650d0000 pid=3429 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=a33c9a34-1c00-0000-8ec6-6d86650d0000 pid=3429 execve guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4699 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4699 execve guuid=4d8029fe-1e00-0000-8ec6-6d864b140000 pid=5195 /usr/bin/cat guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=4d8029fe-1e00-0000-8ec6-6d864b140000 pid=5195 execve guuid=8cd9f6ff-1e00-0000-8ec6-6d8651140000 pid=5201 /usr/bin/chmod guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=8cd9f6ff-1e00-0000-8ec6-6d8651140000 pid=5201 execve guuid=25c16700-1f00-0000-8ec6-6d8653140000 pid=5203 /usr/bin/bash guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=25c16700-1f00-0000-8ec6-6d8653140000 pid=5203 clone guuid=c9ee0f01-1f00-0000-8ec6-6d8657140000 pid=5207 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=c9ee0f01-1f00-0000-8ec6-6d8657140000 pid=5207 execve guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5492 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5492 execve guuid=20ddce4a-2000-0000-8ec6-6d8681150000 pid=5505 /usr/bin/cat guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=20ddce4a-2000-0000-8ec6-6d8681150000 pid=5505 execve guuid=3b9efa55-2000-0000-8ec6-6d8682150000 pid=5506 /usr/bin/chmod guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=3b9efa55-2000-0000-8ec6-6d8682150000 pid=5506 execve guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507 /tmp/run_amd64 guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507 execve guuid=e7bf1b5d-2000-0000-8ec6-6d868a150000 pid=5514 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=e7bf1b5d-2000-0000-8ec6-6d868a150000 pid=5514 execve guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5534 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5534 execve guuid=ef552546-2300-0000-8ec6-6d86ba150000 pid=5562 /usr/bin/cat guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=ef552546-2300-0000-8ec6-6d86ba150000 pid=5562 execve guuid=d55cf846-2300-0000-8ec6-6d86bb150000 pid=5563 /usr/bin/chmod guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=d55cf846-2300-0000-8ec6-6d86bb150000 pid=5563 execve guuid=217f4247-2300-0000-8ec6-6d86bc150000 pid=5564 /usr/bin/bash guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=217f4247-2300-0000-8ec6-6d86bc150000 pid=5564 clone guuid=c158e247-2300-0000-8ec6-6d86be150000 pid=5566 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=c158e247-2300-0000-8ec6-6d86be150000 pid=5566 execve guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5567 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5567 execve guuid=d61596ec-2600-0000-8ec6-6d86c7150000 pid=5575 /usr/bin/cat guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=d61596ec-2600-0000-8ec6-6d86c7150000 pid=5575 execve guuid=c2038bed-2600-0000-8ec6-6d86c8150000 pid=5576 /usr/bin/chmod guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=c2038bed-2600-0000-8ec6-6d86c8150000 pid=5576 execve guuid=4272d0ed-2600-0000-8ec6-6d86c9150000 pid=5577 /usr/bin/bash guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=4272d0ed-2600-0000-8ec6-6d86c9150000 pid=5577 clone guuid=4ded6aee-2600-0000-8ec6-6d86cb150000 pid=5579 /usr/bin/wget dns net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=4ded6aee-2600-0000-8ec6-6d86cb150000 pid=5579 execve guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5580 /usr/bin/curl net send-data write-file guuid=20d52871-1a00-0000-8ec6-6d86540a0000 pid=2644->guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5580 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=f1043372-1a00-0000-8ec6-6d86560a0000 pid=2646->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B 3aef9358-7064-5f08-859a-54c3dace5eb2 nx87cgk6.seckd-cname.com:80 guuid=f1043372-1a00-0000-8ec6-6d86560a0000 pid=2646->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 136B guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2930->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 85B guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2942 /usr/bin/curl dns net send-data guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2930->guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2942 clone guuid=a26ac81a-1b00-0000-8ec6-6d86720b0000 pid=2942->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3421 /tmp/run_386 guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406->guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3421 clone guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3422 /tmp/run_386 guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406->guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3422 clone guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3423 /tmp/run_386 guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406->guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3423 clone guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3424 /tmp/run_386 guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406->guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3424 clone guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426 /tmp/run_386 delete-file write-config write-file zombie guuid=24ba8c2d-1c00-0000-8ec6-6d864e0d0000 pid=3406->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426 execve guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3445 /tmp/run_386 zombie guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3445 clone guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3446 /tmp/run_386 guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3446 clone guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3447 /tmp/run_386 zombie guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3447 clone guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3448 /tmp/run_386 guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3448 clone guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3460 /tmp/run_386 guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3460 clone guuid=c4afd459-1c00-0000-8ec6-6d86b80d0000 pid=3512 /usr/bin/dash guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=c4afd459-1c00-0000-8ec6-6d86b80d0000 pid=3512 execve guuid=4cbd145b-1c00-0000-8ec6-6d86bb0d0000 pid=3515 /usr/bin/systemctl guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=4cbd145b-1c00-0000-8ec6-6d86bb0d0000 pid=3515 execve guuid=dbaadfa0-1c00-0000-8ec6-6d86350e0000 pid=3637 /usr/bin/systemctl guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=dbaadfa0-1c00-0000-8ec6-6d86350e0000 pid=3637 execve guuid=76e600da-1c00-0000-8ec6-6d86b50e0000 pid=3765 /usr/bin/systemctl guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=76e600da-1c00-0000-8ec6-6d86b50e0000 pid=3765 execve guuid=2f7d23ea-1c00-0000-8ec6-6d86ee0e0000 pid=3822 /usr/sbin/update-rc.d guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=2f7d23ea-1c00-0000-8ec6-6d86ee0e0000 pid=3822 execve guuid=5bb71043-1d00-0000-8ec6-6d86760f0000 pid=3958 /usr/sbin/update-rc.d guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=5bb71043-1d00-0000-8ec6-6d86760f0000 pid=3958 execve guuid=347266a6-1d00-0000-8ec6-6d86ae100000 pid=4270 /etc/init.d/systemd-logind guuid=c9e53434-1c00-0000-8ec6-6d86620d0000 pid=3426->guuid=347266a6-1d00-0000-8ec6-6d86ae100000 pid=4270 execve guuid=a33c9a34-1c00-0000-8ec6-6d86650d0000 pid=3429->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=a33c9a34-1c00-0000-8ec6-6d86650d0000 pid=3429->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 140B guuid=16f4935a-1c00-0000-8ec6-6d86b90d0000 pid=3513 /boot/System zombie guuid=c4afd459-1c00-0000-8ec6-6d86b80d0000 pid=3512->guuid=16f4935a-1c00-0000-8ec6-6d86b90d0000 pid=3513 execve guuid=4fa3f95a-1c00-0000-8ec6-6d86ba0d0000 pid=3514 /usr/bin/sleep guuid=16f4935a-1c00-0000-8ec6-6d86b90d0000 pid=3513->guuid=4fa3f95a-1c00-0000-8ec6-6d86ba0d0000 pid=3514 execve guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569 /boot/System.img-6.8.0-8 delete-file write-file guuid=16f4935a-1c00-0000-8ec6-6d86b90d0000 pid=3513->guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569 execve guuid=d99d7bac-2500-0000-8ec6-6d86c6150000 pid=5574 /usr/bin/sleep guuid=16f4935a-1c00-0000-8ec6-6d86b90d0000 pid=3513->guuid=d99d7bac-2500-0000-8ec6-6d86c6150000 pid=5574 execve guuid=a7c866ed-1c00-0000-8ec6-6d86010f0000 pid=3841 /usr/bin/systemctl guuid=2f7d23ea-1c00-0000-8ec6-6d86ee0e0000 pid=3822->guuid=a7c866ed-1c00-0000-8ec6-6d86010f0000 pid=3841 execve guuid=a98df045-1d00-0000-8ec6-6d867d0f0000 pid=3965 /usr/bin/systemctl guuid=5bb71043-1d00-0000-8ec6-6d86760f0000 pid=3958->guuid=a98df045-1d00-0000-8ec6-6d867d0f0000 pid=3965 execve guuid=a0649447-1d00-0000-8ec6-6d86830f0000 pid=3971 /usr/bin/systemctl guuid=5bb71043-1d00-0000-8ec6-6d86760f0000 pid=3958->guuid=a0649447-1d00-0000-8ec6-6d86830f0000 pid=3971 execve guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274 /boot/System.img-6.8.0-8 delete-file write-file guuid=347266a6-1d00-0000-8ec6-6d86ae100000 pid=4270->guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274 execve guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4292 /boot/System.img-6.8.0-8 guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274->guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4292 clone guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4293 /boot/System.img-6.8.0-8 guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274->guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4293 clone guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4294 /boot/System.img-6.8.0-8 guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274->guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4294 clone guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4295 /boot/System.img-6.8.0-8 guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4274->guuid=039f0ca8-1d00-0000-8ec6-6d86b2100000 pid=4295 clone guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4699->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 89B guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4701 /usr/bin/curl dns net send-data guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4699->guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4701 clone guuid=79800562-1e00-0000-8ec6-6d865b120000 pid=4701->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=c9ee0f01-1f00-0000-8ec6-6d8657140000 pid=5207->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=c9ee0f01-1f00-0000-8ec6-6d8657140000 pid=5207->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 138B guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5492->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 87B guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5493 /usr/bin/curl dns net send-data guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5492->guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5493 clone guuid=ef24c2a2-1f00-0000-8ec6-6d8674150000 pid=5493->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5508 /tmp/run_amd64 guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5508 clone guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5509 /tmp/run_amd64 guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5509 clone guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5510 /tmp/run_amd64 guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5510 clone guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5511 /tmp/run_amd64 guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5511 clone guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5512 /tmp/run_amd64 guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5507->guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5512 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513 /tmp/run_amd64 delete-file write-file zombie guuid=e7986156-2000-0000-8ec6-6d8683150000 pid=5508->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513 execve guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5515 /tmp/run_amd64 zombie guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5515 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5516 /tmp/run_amd64 guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5516 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5517 /tmp/run_amd64 zombie guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5517 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5518 /tmp/run_amd64 guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5518 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5519 /tmp/run_amd64 guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5519 clone guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5520 /tmp/run_amd64 guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5513->guuid=681eea5c-2000-0000-8ec6-6d8689150000 pid=5520 clone guuid=e7bf1b5d-2000-0000-8ec6-6d868a150000 pid=5514->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=e7bf1b5d-2000-0000-8ec6-6d868a150000 pid=5514->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 137B guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5534->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 86B guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5535 /usr/bin/curl dns net send-data guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5534->guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5535 clone guuid=554c64ff-2100-0000-8ec6-6d869e150000 pid=5535->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=c158e247-2300-0000-8ec6-6d86be150000 pid=5566->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=c158e247-2300-0000-8ec6-6d86be150000 pid=5566->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 137B guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5567->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 86B guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5568 /usr/bin/curl dns net send-data guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5567->guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5568 clone guuid=0613f429-2500-0000-8ec6-6d86bf150000 pid=5568->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5570 /boot/System.img-6.8.0-8 guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569->guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5570 clone guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5571 /boot/System.img-6.8.0-8 guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569->guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5571 clone guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5572 /boot/System.img-6.8.0-8 guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569->guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5572 clone guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5573 /boot/System.img-6.8.0-8 guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5569->guuid=bb3ab3ab-2500-0000-8ec6-6d86c1150000 pid=5573 clone guuid=4ded6aee-2600-0000-8ec6-6d86cb150000 pid=5579->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B guuid=4ded6aee-2600-0000-8ec6-6d86cb150000 pid=5579->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 137B guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5580->3aef9358-7064-5f08-859a-54c3dace5eb2 send: 86B guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5581 /usr/bin/curl dns net send-data guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5580->guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5581 clone guuid=9cf07c8b-2700-0000-8ec6-6d86cc150000 pid=5581->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 60B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.SAgnt
Status:
Malicious
First seen:
2026-03-19 21:19:26 UTC
File Type:
Text (Shell)
AV detection:
14 of 37 (37.84%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Modifies Bash startup script
Creates/modifies environment variables
Modifies init.d
Modifies rc script
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0e7af68125450f1a0071d23518fa90f4c9f7d6342d7edd077cc4888e8da1ca2c

(this sample)

  
Delivery method
Distributed via web download

Comments