MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9
SHA3-384 hash: 4774c15528c15a145665189b44586076a3694c8136501474bd891fced1c6903214675c12f22c96e7d72852ab663e5a4c
SHA1 hash: a506841b1b182f3fb33f344f9c04b9c1157c38ec
MD5 hash: f472c9a409f62d3f1327ffc18fe33da9
humanhash: pip-white-mississippi-early
File name:rondo.aqu.sh
Download: download sample
Signature Gafgyt
File size:9'432 bytes
First seen:2025-12-25 13:10:49 UTC
Last seen:2025-12-26 05:57:44 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:Ax0iRoLngD0J5StYf+d83foYjOoeCuNXPWo+Kz:g0goLng8eCyt
TLSH T160121888FAC482FE26E749D611D38B7C4E2882E064738DB6DF4894F2AD7844F605F761
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_64a5f035343b91205375751e0fb4d828aef261532508ef80129ffe7a9ba8a30ed0 Gafgytgafgyt RondoDox ua-wget
http://41.231.37.153/rondo.i686293a3a492aef65a88cf5434ee66ad55875deb66885871c9199296e707fb17926 Miraimirai ua-wget
http://41.231.37.153/rondo.i58638b3192b7e792073bde272b917f53336ad35d17482d5140b362f697861bd2c55 Miraimirai ua-wget
http://41.231.37.153/rondo.i486f1beda333a121d1fc43ca60075f62a6e9848b5d9e41ef177d934ebc7138a696f Miraimirai ua-wget
http://41.231.37.153/rondo.armv6l29ed805642950a7709d058067ec1882d877beb02e67b56b673b5e2d2b17272d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l635916119ab6903aa6f8672e8c59d9c658c279b6fee9b7490abfff1b58395402 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4l92a92f68af94dfc82046ebe54a51a639d972608d2516255250cd222ad2b8fddd Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7lec6125b2e7dba1419d5cb0d0ffbcd40de93826062968999d29a933f1485249dc Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpc852713af646fc9ebe10d87b98556f42763cd8490bcb855847a46e6db0fced634 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp2311ce1f03fd7a7c7b2130ebcd7cf84c346e22cec9e00749835746cfd2f2efa5 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips5075648683ceb6822b87509f97f7d15436d510feb0a019053084cb63eb44520d Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld4d72de0e0335c9a3f3eec7cdfd93f7fcc5ee85fc1b8692b8fdab77355db7190 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.arc700a448a233d175276ab77aa4cf9fd63dd02f9e6fd5f4ee160ce99f177df7d27d11 Miraimirai ua-wget
http://41.231.37.153/rondo.sh487b5360fc1a9b326ab7cdece074614eb30e23bd0ff7b179cb121e29aac0edb31 Miraimirai ua-wget
http://41.231.37.153/rondo.sparc8ccaa9a601ec1a1750338b8074d60609b53cde76135f1761fd705428dd195bb7 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68k9aedf0f1ae99ae01eed2d8edec1dd9f2a2257435a91c6a57d4b368946b0f1d18 Miraimirai ua-wget
http://41.231.37.153/rondo.armebb335b5eeaf8ea4f275a66c22322e2f35a36707979aa430ea3dadc29564f3ba09 MiraiRondoDox ua-wget
http://41.231.37.153/rondo.armebhf4e7384185cdff726ae05bad052983c0b3854bd5a3a69897d980cacef2f9a06fc RondoDoxua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Status:
terminated
Behavior Graph:
%3 guuid=0731be59-1a00-0000-09c2-a92649090000 pid=2377 /usr/bin/sudo guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384 /tmp/sample.bin write-file guuid=0731be59-1a00-0000-09c2-a92649090000 pid=2377->guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384 execve guuid=81034b5c-1a00-0000-09c2-a92651090000 pid=2385 /usr/bin/rm guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=81034b5c-1a00-0000-09c2-a92651090000 pid=2385 execve guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387 execve guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399 execve guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410 execve guuid=c432e76a-1a00-0000-09c2-a92675090000 pid=2421 /usr/bin/killall guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c432e76a-1a00-0000-09c2-a92675090000 pid=2421 execve guuid=01d3086c-1a00-0000-09c2-a92679090000 pid=2425 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=01d3086c-1a00-0000-09c2-a92679090000 pid=2425 execve guuid=d114a36f-1a00-0000-09c2-a92683090000 pid=2435 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d114a36f-1a00-0000-09c2-a92683090000 pid=2435 execve guuid=3b3ba872-1a00-0000-09c2-a9268e090000 pid=2446 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=3b3ba872-1a00-0000-09c2-a9268e090000 pid=2446 execve guuid=73c36173-1a00-0000-09c2-a92691090000 pid=2449 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=73c36173-1a00-0000-09c2-a92691090000 pid=2449 execve guuid=c460ca73-1a00-0000-09c2-a92693090000 pid=2451 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c460ca73-1a00-0000-09c2-a92693090000 pid=2451 execve guuid=b78a3974-1a00-0000-09c2-a92696090000 pid=2454 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b78a3974-1a00-0000-09c2-a92696090000 pid=2454 execve guuid=13499e74-1a00-0000-09c2-a92698090000 pid=2456 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=13499e74-1a00-0000-09c2-a92698090000 pid=2456 execve guuid=10af0a75-1a00-0000-09c2-a9269a090000 pid=2458 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=10af0a75-1a00-0000-09c2-a9269a090000 pid=2458 execve guuid=c35e9075-1a00-0000-09c2-a9269c090000 pid=2460 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c35e9075-1a00-0000-09c2-a9269c090000 pid=2460 execve guuid=ba1e4776-1a00-0000-09c2-a9269e090000 pid=2462 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ba1e4776-1a00-0000-09c2-a9269e090000 pid=2462 execve guuid=b154d776-1a00-0000-09c2-a9269f090000 pid=2463 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b154d776-1a00-0000-09c2-a9269f090000 pid=2463 execve guuid=6e19aa77-1a00-0000-09c2-a926a0090000 pid=2464 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e19aa77-1a00-0000-09c2-a926a0090000 pid=2464 execve guuid=44892778-1a00-0000-09c2-a926a3090000 pid=2467 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=44892778-1a00-0000-09c2-a926a3090000 pid=2467 execve guuid=f890a178-1a00-0000-09c2-a926a5090000 pid=2469 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=f890a178-1a00-0000-09c2-a926a5090000 pid=2469 execve guuid=ca260f79-1a00-0000-09c2-a926a7090000 pid=2471 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ca260f79-1a00-0000-09c2-a926a7090000 pid=2471 execve guuid=64e88679-1a00-0000-09c2-a926aa090000 pid=2474 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=64e88679-1a00-0000-09c2-a926aa090000 pid=2474 execve guuid=20c91a7a-1a00-0000-09c2-a926ad090000 pid=2477 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=20c91a7a-1a00-0000-09c2-a926ad090000 pid=2477 execve guuid=9bf3c67a-1a00-0000-09c2-a926b0090000 pid=2480 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9bf3c67a-1a00-0000-09c2-a926b0090000 pid=2480 execve guuid=a6fb487b-1a00-0000-09c2-a926b2090000 pid=2482 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a6fb487b-1a00-0000-09c2-a926b2090000 pid=2482 execve guuid=1943b27b-1a00-0000-09c2-a926b3090000 pid=2483 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=1943b27b-1a00-0000-09c2-a926b3090000 pid=2483 execve guuid=e7be1a7c-1a00-0000-09c2-a926b5090000 pid=2485 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=e7be1a7c-1a00-0000-09c2-a926b5090000 pid=2485 execve guuid=d0b2917c-1a00-0000-09c2-a926b8090000 pid=2488 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d0b2917c-1a00-0000-09c2-a926b8090000 pid=2488 execve guuid=6a86337d-1a00-0000-09c2-a926ba090000 pid=2490 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6a86337d-1a00-0000-09c2-a926ba090000 pid=2490 execve guuid=d3d6d07d-1a00-0000-09c2-a926be090000 pid=2494 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d3d6d07d-1a00-0000-09c2-a926be090000 pid=2494 execve guuid=5eb86b7e-1a00-0000-09c2-a926c1090000 pid=2497 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=5eb86b7e-1a00-0000-09c2-a926c1090000 pid=2497 execve guuid=a7fe267f-1a00-0000-09c2-a926c4090000 pid=2500 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a7fe267f-1a00-0000-09c2-a926c4090000 pid=2500 execve guuid=f6a3c17f-1a00-0000-09c2-a926c7090000 pid=2503 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=f6a3c17f-1a00-0000-09c2-a926c7090000 pid=2503 execve guuid=d2dd7b80-1a00-0000-09c2-a926ca090000 pid=2506 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d2dd7b80-1a00-0000-09c2-a926ca090000 pid=2506 execve guuid=a718f880-1a00-0000-09c2-a926cd090000 pid=2509 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a718f880-1a00-0000-09c2-a926cd090000 pid=2509 execve guuid=60846981-1a00-0000-09c2-a926d0090000 pid=2512 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=60846981-1a00-0000-09c2-a926d0090000 pid=2512 execve guuid=264ae381-1a00-0000-09c2-a926d2090000 pid=2514 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=264ae381-1a00-0000-09c2-a926d2090000 pid=2514 execve guuid=faf45782-1a00-0000-09c2-a926d5090000 pid=2517 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=faf45782-1a00-0000-09c2-a926d5090000 pid=2517 execve guuid=d7f9ba82-1a00-0000-09c2-a926d7090000 pid=2519 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d7f9ba82-1a00-0000-09c2-a926d7090000 pid=2519 execve guuid=1b78d683-1a00-0000-09c2-a926d8090000 pid=2520 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=1b78d683-1a00-0000-09c2-a926d8090000 pid=2520 execve guuid=db577684-1a00-0000-09c2-a926da090000 pid=2522 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=db577684-1a00-0000-09c2-a926da090000 pid=2522 execve guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525 /usr/bin/systemctl guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525 execve guuid=6f43b406-1b00-0000-09c2-a926160b0000 pid=2838 /usr/bin/mount write-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6f43b406-1b00-0000-09c2-a926160b0000 pid=2838 execve guuid=b263ab08-1b00-0000-09c2-a926180b0000 pid=2840 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b263ab08-1b00-0000-09c2-a926180b0000 pid=2840 execve guuid=57dc9c0c-1b00-0000-09c2-a926200b0000 pid=2848 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=57dc9c0c-1b00-0000-09c2-a926200b0000 pid=2848 execve guuid=d64ff40c-1b00-0000-09c2-a926210b0000 pid=2849 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d64ff40c-1b00-0000-09c2-a926210b0000 pid=2849 execve guuid=3671450d-1b00-0000-09c2-a926230b0000 pid=2851 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=3671450d-1b00-0000-09c2-a926230b0000 pid=2851 execve guuid=2e73a80d-1b00-0000-09c2-a926250b0000 pid=2853 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=2e73a80d-1b00-0000-09c2-a926250b0000 pid=2853 execve guuid=b8c6f90d-1b00-0000-09c2-a926270b0000 pid=2855 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b8c6f90d-1b00-0000-09c2-a926270b0000 pid=2855 execve guuid=4c04540e-1b00-0000-09c2-a926290b0000 pid=2857 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=4c04540e-1b00-0000-09c2-a926290b0000 pid=2857 execve guuid=9860a90e-1b00-0000-09c2-a9262b0b0000 pid=2859 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9860a90e-1b00-0000-09c2-a9262b0b0000 pid=2859 execve guuid=6e9c180f-1b00-0000-09c2-a9262d0b0000 pid=2861 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e9c180f-1b00-0000-09c2-a9262d0b0000 pid=2861 execve guuid=daf7810f-1b00-0000-09c2-a9262e0b0000 pid=2862 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=daf7810f-1b00-0000-09c2-a9262e0b0000 pid=2862 execve guuid=97e5f20f-1b00-0000-09c2-a926300b0000 pid=2864 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=97e5f20f-1b00-0000-09c2-a926300b0000 pid=2864 execve guuid=46a74410-1b00-0000-09c2-a926310b0000 pid=2865 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=46a74410-1b00-0000-09c2-a926310b0000 pid=2865 execve guuid=d1b29210-1b00-0000-09c2-a926330b0000 pid=2867 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d1b29210-1b00-0000-09c2-a926330b0000 pid=2867 execve guuid=ae51d810-1b00-0000-09c2-a926350b0000 pid=2869 /usr/bin/mkdir guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ae51d810-1b00-0000-09c2-a926350b0000 pid=2869 execve guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871 /usr/bin/dash guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871 clone guuid=8ae48711-1b00-0000-09c2-a926390b0000 pid=2873 /usr/bin/rm guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=8ae48711-1b00-0000-09c2-a926390b0000 pid=2873 execve guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876 /usr/bin/wget net send-data write-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876 execve guuid=9b5bad20-1b00-0000-09c2-a926610b0000 pid=2913 /usr/bin/cat guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9b5bad20-1b00-0000-09c2-a926610b0000 pid=2913 execve guuid=ac9ef520-1b00-0000-09c2-a926630b0000 pid=2915 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ac9ef520-1b00-0000-09c2-a926630b0000 pid=2915 execve guuid=fc3e4521-1b00-0000-09c2-a926650b0000 pid=2917 /usr/bin/chmod guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fc3e4521-1b00-0000-09c2-a926650b0000 pid=2917 execve guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919 execve guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931 execve guuid=872fc628-1b00-0000-09c2-a926810b0000 pid=2945 /usr/bin/killall guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=872fc628-1b00-0000-09c2-a926810b0000 pid=2945 execve guuid=c9556429-1b00-0000-09c2-a926840b0000 pid=2948 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c9556429-1b00-0000-09c2-a926840b0000 pid=2948 execve guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f1523d5f-1a00-0000-09c2-a92659090000 pid=2393 /usr/bin/killall guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->guuid=f1523d5f-1a00-0000-09c2-a92659090000 pid=2393 execve guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=589a8662-1a00-0000-09c2-a92661090000 pid=2401 /usr/bin/pgrep guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->guuid=589a8662-1a00-0000-09c2-a92661090000 pid=2401 execve guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=67803d68-1a00-0000-09c2-a9266c090000 pid=2412 /usr/bin/pgrep guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->guuid=67803d68-1a00-0000-09c2-a9266c090000 pid=2412 execve guuid=62cf3c85-1a00-0000-09c2-a926df090000 pid=2527 /usr/bin/basename guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=62cf3c85-1a00-0000-09c2-a926df090000 pid=2527 execve guuid=840e7d85-1a00-0000-09c2-a926e0090000 pid=2528 /usr/bin/basename guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=840e7d85-1a00-0000-09c2-a926e0090000 pid=2528 execve guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531 /usr/bin/dash guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531 clone guuid=a2adce85-1a00-0000-09c2-a926e4090000 pid=2532 /usr/bin/systemctl guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531->guuid=a2adce85-1a00-0000-09c2-a926e4090000 pid=2532 execve guuid=ebfcd385-1a00-0000-09c2-a926e5090000 pid=2533 /usr/bin/sed guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531->guuid=ebfcd385-1a00-0000-09c2-a926e5090000 pid=2533 execve guuid=ded74011-1b00-0000-09c2-a926380b0000 pid=2872 /usr/bin/chmod guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871->guuid=ded74011-1b00-0000-09c2-a926380b0000 pid=2872 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=07919a23-1b00-0000-09c2-a9266e0b0000 pid=2926 /usr/bin/killall guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->guuid=07919a23-1b00-0000-09c2-a9266e0b0000 pid=2926 execve guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=c2a22d26-1b00-0000-09c2-a926780b0000 pid=2936 /usr/bin/pgrep guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->guuid=c2a22d26-1b00-0000-09c2-a926780b0000 pid=2936 execve guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960 /usr/bin/lib/rondo guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960 execve guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961 /usr/bin/lib/rondo write-file zombie guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960->guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961 clone guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962 /usr/bin/lib/rondo write-file zombie guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961->guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962 clone guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966 /usr/lib/systemd/surpmsbwl delete-file net send-data write-config write-file zombie guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962->guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966 clone guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=a54b8c2e-1b00-0000-09c2-a926990b0000 pid=2969 /usr/lib/systemd/surpmsbwl write-file zombie guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=a54b8c2e-1b00-0000-09c2-a926990b0000 pid=2969 clone guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970 /usr/lib/systemd/surpmsbwl net write-file zombie guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970 clone guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061 /usr/lib/systemd/surpmsbwl write-file guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061 clone guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970->c6d3c8d1-ccce-5272-b764-c5a3ff34618d con guuid=bc5c886d-1b00-0000-09c2-a9262e0c0000 pid=3118 /usr/lib/systemd/surpmsbwl write-file guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970->guuid=bc5c886d-1b00-0000-09c2-a9262e0c0000 pid=3118 clone guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062 /usr/bin/dash guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061->guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062 execve guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063 /usr/bin/softirq mprotect-exec guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062->guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063 execve guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074 /usr/bin/softirq net send-data zombie guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3077 /usr/bin/softirq write-file zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3077 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3081 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3081 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3082 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3082 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3083 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3083 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3084 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3084 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3143 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3143 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3144 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3144 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3145 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3145 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3146 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3146 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3167 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3167 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3168 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3168 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3170 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3170 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3171 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3171 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3189 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3189 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3190 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3190 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3191 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3191 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3192 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3192 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3211 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3211 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3212 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3212 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3213 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3213 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3214 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3214 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3232 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3232 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3233 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3233 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3234 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3234 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3235 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3235 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3252 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3252 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3253 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3253 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3254 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3254 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3255 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3255 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3271 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3271 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3272 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3272 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3273 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3273 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3274 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3274 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3288 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3288 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3289 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3289 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3290 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3290 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3291 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3291 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3306 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3306 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3307 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3307 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3308 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3308 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3309 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3309 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3315 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3315 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3316 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3316 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3317 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3317 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3318 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3318 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3335 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3335 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3336 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3336 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3337 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3337 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3338 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3338 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3346 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3346 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3347 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3347 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3348 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3348 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3349 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3349 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-12-25 13:11:19 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9

(this sample)

  
Delivery method
Distributed via web download

Comments