MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Gafgyt


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9
SHA3-384 hash: 4774c15528c15a145665189b44586076a3694c8136501474bd891fced1c6903214675c12f22c96e7d72852ab663e5a4c
SHA1 hash: a506841b1b182f3fb33f344f9c04b9c1157c38ec
MD5 hash: f472c9a409f62d3f1327ffc18fe33da9
humanhash: pip-white-mississippi-early
File name:rondo.aqu.sh
Download: download sample
Signature Gafgyt
File size:9'432 bytes
First seen:2025-12-25 13:10:49 UTC
Last seen:2025-12-26 05:57:44 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 96:Ax0iRoLngD0J5StYf+d83foYjOoeCuNXPWo+Kz:g0goLng8eCyt
TLSH T160121888FAC482FE26E749D611D38B7C4E2882E064738DB6DF4894F2AD7844F605F761
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://41.231.37.153/rondo.loln/an/aua-wget
http://41.231.37.153/rondo.x86_647aeb450c57b466d9a280a02f5bbdb2166d6b092a5a6aa7a440b854cc2af333b5 RondoDoxgafgyt mirai RondoDox ua-wget
http://41.231.37.153/rondo.i6868d87fd06b2d964c414affc277c1a34762a24ac10136fa5be9c2cf393f2095a17 Miraimirai ua-wget
http://41.231.37.153/rondo.i586eb40a3a7f8ba5edd91bfa225d9f9f31358bc5233fc50561d382b518f7774980a Miraimirai ua-wget
http://41.231.37.153/rondo.i4867732e3ac296300ee478d9e11dbc87080658130c9d9274c7d39fa891ac0a08b1d Miraimirai ua-wget
http://41.231.37.153/rondo.armv6lf6dd15cb2803eb1a8866104e0bbfa469f8fbe0255106a8cf472d69c81f724b9f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv5l9affdd7320dda529271f43090f8b8c3e82963d382e21a73d00cde6068090252f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv4le2c0b7f64c6a8f8cbe51452349c56d8a340c98bb8a6b55d44cf33fabf8766d7f Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armv7l2d6cb85fb16a5fa70f9fe9478f6ed924280b74846f12686912105891fac17959 RondoDoxmirai RondoDox ua-wget
http://41.231.37.153/rondo.powerpcc7faf8d356dec3f94a6ea63d22e5ea588083941bd3ff760b5c8d01c112008dc0 Miraimirai ua-wget
http://41.231.37.153/rondo.powerpc-440fp57f9ba41f0cb4f774a98099fb2dda6a9cd6d9c780ecfca87e8618167c79006d2 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.mips31e825d0017b4eb68b7afd69a80f84c0a5a079ef31d3fa420088c39a3ebc4547 Gafgytgafgyt ua-wget
http://41.231.37.153/rondo.mipseld2fe03bc659bb4c6ebd78984ac7c6ee6b0cd02d1bf99387679d4ce38a1f1aafe Miraigafgyt mirai ua-wget
http://41.231.37.153/rondo.arc70078d383029563304ded927d7d82613328f6763724fa7192fcaf4f23e882a65bd3 Miraimirai ua-wget
http://41.231.37.153/rondo.sh435d9009800989ef6dfa78d8305e1486ea4cf9d1d89f6483082874493f364fca1 Miraimirai ua-wget
http://41.231.37.153/rondo.sparca501ee00340a2cc0b1a8441c888b6df1d5e52d6ca360e6996973ae85cea51966 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.m68ka78f8c90eea0183dbf8d64bd03f34696159980cf3a24937138d50be267865c95 Miraimirai ua-wget
http://41.231.37.153/rondo.armeb67219e9776b9a374c618e948f220f1871647189364487254d5cea968023b6fc9 Miraimirai RondoDox ua-wget
http://41.231.37.153/rondo.armebhf848464e44045c74124c228af6b76665adc8c8ea3994e2b70045a95db862bba21 Miraimirai ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
57
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
busybox masquerade
Status:
terminated
Behavior Graph:
%3 guuid=0731be59-1a00-0000-09c2-a92649090000 pid=2377 /usr/bin/sudo guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384 /tmp/sample.bin write-file guuid=0731be59-1a00-0000-09c2-a92649090000 pid=2377->guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384 execve guuid=81034b5c-1a00-0000-09c2-a92651090000 pid=2385 /usr/bin/rm guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=81034b5c-1a00-0000-09c2-a92651090000 pid=2385 execve guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387 execve guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399 execve guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410 execve guuid=c432e76a-1a00-0000-09c2-a92675090000 pid=2421 /usr/bin/killall guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c432e76a-1a00-0000-09c2-a92675090000 pid=2421 execve guuid=01d3086c-1a00-0000-09c2-a92679090000 pid=2425 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=01d3086c-1a00-0000-09c2-a92679090000 pid=2425 execve guuid=d114a36f-1a00-0000-09c2-a92683090000 pid=2435 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d114a36f-1a00-0000-09c2-a92683090000 pid=2435 execve guuid=3b3ba872-1a00-0000-09c2-a9268e090000 pid=2446 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=3b3ba872-1a00-0000-09c2-a9268e090000 pid=2446 execve guuid=73c36173-1a00-0000-09c2-a92691090000 pid=2449 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=73c36173-1a00-0000-09c2-a92691090000 pid=2449 execve guuid=c460ca73-1a00-0000-09c2-a92693090000 pid=2451 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c460ca73-1a00-0000-09c2-a92693090000 pid=2451 execve guuid=b78a3974-1a00-0000-09c2-a92696090000 pid=2454 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b78a3974-1a00-0000-09c2-a92696090000 pid=2454 execve guuid=13499e74-1a00-0000-09c2-a92698090000 pid=2456 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=13499e74-1a00-0000-09c2-a92698090000 pid=2456 execve guuid=10af0a75-1a00-0000-09c2-a9269a090000 pid=2458 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=10af0a75-1a00-0000-09c2-a9269a090000 pid=2458 execve guuid=c35e9075-1a00-0000-09c2-a9269c090000 pid=2460 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c35e9075-1a00-0000-09c2-a9269c090000 pid=2460 execve guuid=ba1e4776-1a00-0000-09c2-a9269e090000 pid=2462 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ba1e4776-1a00-0000-09c2-a9269e090000 pid=2462 execve guuid=b154d776-1a00-0000-09c2-a9269f090000 pid=2463 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b154d776-1a00-0000-09c2-a9269f090000 pid=2463 execve guuid=6e19aa77-1a00-0000-09c2-a926a0090000 pid=2464 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e19aa77-1a00-0000-09c2-a926a0090000 pid=2464 execve guuid=44892778-1a00-0000-09c2-a926a3090000 pid=2467 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=44892778-1a00-0000-09c2-a926a3090000 pid=2467 execve guuid=f890a178-1a00-0000-09c2-a926a5090000 pid=2469 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=f890a178-1a00-0000-09c2-a926a5090000 pid=2469 execve guuid=ca260f79-1a00-0000-09c2-a926a7090000 pid=2471 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ca260f79-1a00-0000-09c2-a926a7090000 pid=2471 execve guuid=64e88679-1a00-0000-09c2-a926aa090000 pid=2474 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=64e88679-1a00-0000-09c2-a926aa090000 pid=2474 execve guuid=20c91a7a-1a00-0000-09c2-a926ad090000 pid=2477 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=20c91a7a-1a00-0000-09c2-a926ad090000 pid=2477 execve guuid=9bf3c67a-1a00-0000-09c2-a926b0090000 pid=2480 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9bf3c67a-1a00-0000-09c2-a926b0090000 pid=2480 execve guuid=a6fb487b-1a00-0000-09c2-a926b2090000 pid=2482 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a6fb487b-1a00-0000-09c2-a926b2090000 pid=2482 execve guuid=1943b27b-1a00-0000-09c2-a926b3090000 pid=2483 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=1943b27b-1a00-0000-09c2-a926b3090000 pid=2483 execve guuid=e7be1a7c-1a00-0000-09c2-a926b5090000 pid=2485 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=e7be1a7c-1a00-0000-09c2-a926b5090000 pid=2485 execve guuid=d0b2917c-1a00-0000-09c2-a926b8090000 pid=2488 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d0b2917c-1a00-0000-09c2-a926b8090000 pid=2488 execve guuid=6a86337d-1a00-0000-09c2-a926ba090000 pid=2490 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6a86337d-1a00-0000-09c2-a926ba090000 pid=2490 execve guuid=d3d6d07d-1a00-0000-09c2-a926be090000 pid=2494 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d3d6d07d-1a00-0000-09c2-a926be090000 pid=2494 execve guuid=5eb86b7e-1a00-0000-09c2-a926c1090000 pid=2497 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=5eb86b7e-1a00-0000-09c2-a926c1090000 pid=2497 execve guuid=a7fe267f-1a00-0000-09c2-a926c4090000 pid=2500 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a7fe267f-1a00-0000-09c2-a926c4090000 pid=2500 execve guuid=f6a3c17f-1a00-0000-09c2-a926c7090000 pid=2503 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=f6a3c17f-1a00-0000-09c2-a926c7090000 pid=2503 execve guuid=d2dd7b80-1a00-0000-09c2-a926ca090000 pid=2506 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d2dd7b80-1a00-0000-09c2-a926ca090000 pid=2506 execve guuid=a718f880-1a00-0000-09c2-a926cd090000 pid=2509 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=a718f880-1a00-0000-09c2-a926cd090000 pid=2509 execve guuid=60846981-1a00-0000-09c2-a926d0090000 pid=2512 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=60846981-1a00-0000-09c2-a926d0090000 pid=2512 execve guuid=264ae381-1a00-0000-09c2-a926d2090000 pid=2514 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=264ae381-1a00-0000-09c2-a926d2090000 pid=2514 execve guuid=faf45782-1a00-0000-09c2-a926d5090000 pid=2517 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=faf45782-1a00-0000-09c2-a926d5090000 pid=2517 execve guuid=d7f9ba82-1a00-0000-09c2-a926d7090000 pid=2519 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d7f9ba82-1a00-0000-09c2-a926d7090000 pid=2519 execve guuid=1b78d683-1a00-0000-09c2-a926d8090000 pid=2520 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=1b78d683-1a00-0000-09c2-a926d8090000 pid=2520 execve guuid=db577684-1a00-0000-09c2-a926da090000 pid=2522 /usr/bin/ls guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=db577684-1a00-0000-09c2-a926da090000 pid=2522 execve guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525 /usr/bin/systemctl guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525 execve guuid=6f43b406-1b00-0000-09c2-a926160b0000 pid=2838 /usr/bin/mount write-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6f43b406-1b00-0000-09c2-a926160b0000 pid=2838 execve guuid=b263ab08-1b00-0000-09c2-a926180b0000 pid=2840 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b263ab08-1b00-0000-09c2-a926180b0000 pid=2840 execve guuid=57dc9c0c-1b00-0000-09c2-a926200b0000 pid=2848 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=57dc9c0c-1b00-0000-09c2-a926200b0000 pid=2848 execve guuid=d64ff40c-1b00-0000-09c2-a926210b0000 pid=2849 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d64ff40c-1b00-0000-09c2-a926210b0000 pid=2849 execve guuid=3671450d-1b00-0000-09c2-a926230b0000 pid=2851 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=3671450d-1b00-0000-09c2-a926230b0000 pid=2851 execve guuid=2e73a80d-1b00-0000-09c2-a926250b0000 pid=2853 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=2e73a80d-1b00-0000-09c2-a926250b0000 pid=2853 execve guuid=b8c6f90d-1b00-0000-09c2-a926270b0000 pid=2855 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b8c6f90d-1b00-0000-09c2-a926270b0000 pid=2855 execve guuid=4c04540e-1b00-0000-09c2-a926290b0000 pid=2857 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=4c04540e-1b00-0000-09c2-a926290b0000 pid=2857 execve guuid=9860a90e-1b00-0000-09c2-a9262b0b0000 pid=2859 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9860a90e-1b00-0000-09c2-a9262b0b0000 pid=2859 execve guuid=6e9c180f-1b00-0000-09c2-a9262d0b0000 pid=2861 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e9c180f-1b00-0000-09c2-a9262d0b0000 pid=2861 execve guuid=daf7810f-1b00-0000-09c2-a9262e0b0000 pid=2862 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=daf7810f-1b00-0000-09c2-a9262e0b0000 pid=2862 execve guuid=97e5f20f-1b00-0000-09c2-a926300b0000 pid=2864 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=97e5f20f-1b00-0000-09c2-a926300b0000 pid=2864 execve guuid=46a74410-1b00-0000-09c2-a926310b0000 pid=2865 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=46a74410-1b00-0000-09c2-a926310b0000 pid=2865 execve guuid=d1b29210-1b00-0000-09c2-a926330b0000 pid=2867 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=d1b29210-1b00-0000-09c2-a926330b0000 pid=2867 execve guuid=ae51d810-1b00-0000-09c2-a926350b0000 pid=2869 /usr/bin/mkdir guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ae51d810-1b00-0000-09c2-a926350b0000 pid=2869 execve guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871 /usr/bin/dash guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871 clone guuid=8ae48711-1b00-0000-09c2-a926390b0000 pid=2873 /usr/bin/rm guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=8ae48711-1b00-0000-09c2-a926390b0000 pid=2873 execve guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876 /usr/bin/wget net send-data write-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876 execve guuid=9b5bad20-1b00-0000-09c2-a926610b0000 pid=2913 /usr/bin/cat guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=9b5bad20-1b00-0000-09c2-a926610b0000 pid=2913 execve guuid=ac9ef520-1b00-0000-09c2-a926630b0000 pid=2915 /usr/bin/rm delete-file guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=ac9ef520-1b00-0000-09c2-a926630b0000 pid=2915 execve guuid=fc3e4521-1b00-0000-09c2-a926650b0000 pid=2917 /usr/bin/chmod guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fc3e4521-1b00-0000-09c2-a926650b0000 pid=2917 execve guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919 execve guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931 execve guuid=872fc628-1b00-0000-09c2-a926810b0000 pid=2945 /usr/bin/killall guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=872fc628-1b00-0000-09c2-a926810b0000 pid=2945 execve guuid=c9556429-1b00-0000-09c2-a926840b0000 pid=2948 /usr/bin/pgrep guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=c9556429-1b00-0000-09c2-a926840b0000 pid=2948 execve guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956 /usr/bin/sudo net guuid=20260d5c-1a00-0000-09c2-a92650090000 pid=2384->guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=f1523d5f-1a00-0000-09c2-a92659090000 pid=2393 /usr/bin/killall guuid=9910d75c-1a00-0000-09c2-a92653090000 pid=2387->guuid=f1523d5f-1a00-0000-09c2-a92659090000 pid=2393 execve guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=589a8662-1a00-0000-09c2-a92661090000 pid=2401 /usr/bin/pgrep guuid=fa320b61-1a00-0000-09c2-a9265f090000 pid=2399->guuid=589a8662-1a00-0000-09c2-a92661090000 pid=2401 execve guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=67803d68-1a00-0000-09c2-a9266c090000 pid=2412 /usr/bin/pgrep guuid=28bc9566-1a00-0000-09c2-a9266a090000 pid=2410->guuid=67803d68-1a00-0000-09c2-a9266c090000 pid=2412 execve guuid=62cf3c85-1a00-0000-09c2-a926df090000 pid=2527 /usr/bin/basename guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=62cf3c85-1a00-0000-09c2-a926df090000 pid=2527 execve guuid=840e7d85-1a00-0000-09c2-a926e0090000 pid=2528 /usr/bin/basename guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=840e7d85-1a00-0000-09c2-a926e0090000 pid=2528 execve guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531 /usr/bin/dash guuid=be6ef184-1a00-0000-09c2-a926dd090000 pid=2525->guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531 clone guuid=a2adce85-1a00-0000-09c2-a926e4090000 pid=2532 /usr/bin/systemctl guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531->guuid=a2adce85-1a00-0000-09c2-a926e4090000 pid=2532 execve guuid=ebfcd385-1a00-0000-09c2-a926e5090000 pid=2533 /usr/bin/sed guuid=92afc485-1a00-0000-09c2-a926e3090000 pid=2531->guuid=ebfcd385-1a00-0000-09c2-a926e5090000 pid=2533 execve guuid=ded74011-1b00-0000-09c2-a926380b0000 pid=2872 /usr/bin/chmod guuid=98f23811-1b00-0000-09c2-a926370b0000 pid=2871->guuid=ded74011-1b00-0000-09c2-a926380b0000 pid=2872 execve 723b36fb-85d9-5b1d-80ec-f5ebefab4936 41.231.37.153:80 guuid=b9becd11-1b00-0000-09c2-a9263c0b0000 pid=2876->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 140B guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=07919a23-1b00-0000-09c2-a9266e0b0000 pid=2926 /usr/bin/killall guuid=6e819921-1b00-0000-09c2-a926670b0000 pid=2919->guuid=07919a23-1b00-0000-09c2-a9266e0b0000 pid=2926 execve guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=c2a22d26-1b00-0000-09c2-a926780b0000 pid=2936 /usr/bin/pgrep guuid=b516bb24-1b00-0000-09c2-a926730b0000 pid=2931->guuid=c2a22d26-1b00-0000-09c2-a926780b0000 pid=2936 execve guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960 /usr/bin/lib/rondo guuid=fb52be2b-1b00-0000-09c2-a9268c0b0000 pid=2956->guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960 execve guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961 /usr/bin/lib/rondo write-file zombie guuid=b6fa042d-1b00-0000-09c2-a926900b0000 pid=2960->guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961 clone guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962 /usr/bin/lib/rondo write-file zombie guuid=38792b2d-1b00-0000-09c2-a926910b0000 pid=2961->guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962 clone guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966 /usr/lib/systemd/surpmsbwl delete-file net send-data write-config write-file zombie guuid=073d372d-1b00-0000-09c2-a926920b0000 pid=2962->guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966 clone guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->723b36fb-85d9-5b1d-80ec-f5ebefab4936 send: 91B c6d3c8d1-ccce-5272-b764-c5a3ff34618d 45.94.31.89:8443 guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->c6d3c8d1-ccce-5272-b764-c5a3ff34618d send: 21B guuid=a54b8c2e-1b00-0000-09c2-a926990b0000 pid=2969 /usr/lib/systemd/surpmsbwl write-file zombie guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=a54b8c2e-1b00-0000-09c2-a926990b0000 pid=2969 clone guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970 /usr/lib/systemd/surpmsbwl net write-file zombie guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970 clone guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061 /usr/lib/systemd/surpmsbwl write-file guuid=7ab6d92d-1b00-0000-09c2-a926960b0000 pid=2966->guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061 clone guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970->c6d3c8d1-ccce-5272-b764-c5a3ff34618d con guuid=bc5c886d-1b00-0000-09c2-a9262e0c0000 pid=3118 /usr/lib/systemd/surpmsbwl write-file guuid=6fe98f2e-1b00-0000-09c2-a9269a0b0000 pid=2970->guuid=bc5c886d-1b00-0000-09c2-a9262e0c0000 pid=3118 clone guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062 /usr/bin/dash guuid=181a6c5f-1b00-0000-09c2-a926f50b0000 pid=3061->guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062 execve guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063 /usr/bin/softirq mprotect-exec guuid=c1e9765f-1b00-0000-09c2-a926f60b0000 pid=3062->guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063 execve guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074 /usr/bin/softirq net send-data zombie guuid=bb1da35f-1b00-0000-09c2-a926f70b0000 pid=3063->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074 clone 5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 45.94.31.89:443 guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->5b4f37ef-41f0-5901-b8f0-5c79c4d5f639 send: 862B guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3077 /usr/bin/softirq write-file zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3077 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3081 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3081 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3082 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3082 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3083 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3083 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3084 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3084 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3143 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3143 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3144 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3144 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3145 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3145 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3146 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3146 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3167 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3167 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3168 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3168 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3170 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3170 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3171 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3171 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3189 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3189 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3190 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3190 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3191 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3191 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3192 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3192 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3211 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3211 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3212 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3212 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3213 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3213 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3214 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3214 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3232 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3232 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3233 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3233 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3234 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3234 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3235 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3235 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3252 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3252 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3253 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3253 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3254 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3254 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3255 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3255 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3271 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3271 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3272 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3272 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3273 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3273 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3274 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3274 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3288 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3288 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3289 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3289 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3290 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3290 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3291 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3291 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3306 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3306 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3307 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3307 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3308 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3308 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3309 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3309 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3315 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3315 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3316 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3316 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3317 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3317 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3318 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3318 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3335 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3335 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3336 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3336 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3337 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3337 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3338 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3338 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3346 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3346 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3347 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3347 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3348 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3348 clone guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3349 /usr/bin/softirq zombie guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3074->guuid=2760e461-1b00-0000-09c2-a926020c0000 pid=3349 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2025-12-25 13:11:19 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Deletes log files
Disables AppArmor
Disables SELinux
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:MAL_Linux_IoT_MultiArch_BotnetLoader_Generic
Author:Anish Bogati
Description:Technique-based detection of IoT/Linux botnet loader shell scripts downloading binaries from numeric IPs, chmodding, and executing multi-architecture payloads
Reference:MalwareBazaar sample lilin.sh

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Gafgyt

sh 152e82c6383a68baeb5a453ba03c4ee910c53765ea9d93ee042af548d607add9

(this sample)

  
Delivery method
Distributed via web download

Comments