MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1b45f9d89cf03c56afa6ec5cce472e4b36680d792a47f728ee30ef993cf16648. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 1b45f9d89cf03c56afa6ec5cce472e4b36680d792a47f728ee30ef993cf16648
SHA3-384 hash: 5614d53ba57848fd07783aa09fd4521d00a5b2f969a7ce422a72dce81c2198a52722630b66479e2f1e8b1c6798e60b92
SHA1 hash: e281e054f83bdc08db0ec8784d7216884ce7bc18
MD5 hash: cecac625fd8738c61c3ddf0d0d4b716b
humanhash: lima-golf-neptune-football
File name:check_bot_m
Download: download sample
File size:31'468 bytes
First seen:2026-06-26 18:47:10 UTC
Last seen:2026-06-27 09:32:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 384:o8DvSH1Zx9r9DxwSmOJ/bQwxCQhG6JEXscloecOBvQZVgWKPBj1Beoc:osED9L2QtG6iXsclkgzPBj1ooc
TLSH T159E2D4AA8891DD64C2E5DF2459FE3783B209268FECD3048A1326371D570ECACD1DB25B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
3
# of downloads :
61
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
base64 bash lolbin
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-26T11:55:00Z UTC
Last seen:
2026-06-26T14:33:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan.Shell.Agent.do
Status:
terminated
Behavior Graph:
%3 guuid=a2ed9816-1a00-0000-3a7f-65d8ab100000 pid=4267 /usr/bin/sudo guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268 /tmp/sample.bin guuid=a2ed9816-1a00-0000-3a7f-65d8ab100000 pid=4267->guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268 execve guuid=2984151b-1a00-0000-3a7f-65d8ad100000 pid=4269 /usr/bin/bash guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=2984151b-1a00-0000-3a7f-65d8ad100000 pid=4269 clone guuid=c902351b-1a00-0000-3a7f-65d8ae100000 pid=4270 /usr/bin/rm guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=c902351b-1a00-0000-3a7f-65d8ae100000 pid=4270 execve guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271 /usr/bin/bash write-file guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271 execve guuid=ad54b31b-1a00-0000-3a7f-65d8b0100000 pid=4272 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=ad54b31b-1a00-0000-3a7f-65d8b0100000 pid=4272 execve guuid=b4794a59-1a00-0000-3a7f-65d896110000 pid=4502 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=b4794a59-1a00-0000-3a7f-65d896110000 pid=4502 execve guuid=f2855e95-1a00-0000-3a7f-65d85c120000 pid=4700 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=f2855e95-1a00-0000-3a7f-65d85c120000 pid=4700 execve guuid=43c084d1-1a00-0000-3a7f-65d8ea120000 pid=4842 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=43c084d1-1a00-0000-3a7f-65d8ea120000 pid=4842 execve guuid=eae9700d-1b00-0000-3a7f-65d88a130000 pid=5002 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=eae9700d-1b00-0000-3a7f-65d88a130000 pid=5002 execve guuid=62b86549-1b00-0000-3a7f-65d838140000 pid=5176 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=62b86549-1b00-0000-3a7f-65d838140000 pid=5176 execve guuid=e18f9585-1b00-0000-3a7f-65d83c140000 pid=5180 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=e18f9585-1b00-0000-3a7f-65d83c140000 pid=5180 execve guuid=f6dadbc1-1b00-0000-3a7f-65d845140000 pid=5189 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=f6dadbc1-1b00-0000-3a7f-65d845140000 pid=5189 execve guuid=d88cf2fd-1b00-0000-3a7f-65d846140000 pid=5190 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=d88cf2fd-1b00-0000-3a7f-65d846140000 pid=5190 execve guuid=744a353a-1c00-0000-3a7f-65d847140000 pid=5191 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=744a353a-1c00-0000-3a7f-65d847140000 pid=5191 execve guuid=530f4276-1c00-0000-3a7f-65d84f140000 pid=5199 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=530f4276-1c00-0000-3a7f-65d84f140000 pid=5199 execve guuid=8c45aeb2-1c00-0000-3a7f-65d850140000 pid=5200 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=8c45aeb2-1c00-0000-3a7f-65d850140000 pid=5200 execve guuid=b8fa1aef-1c00-0000-3a7f-65d851140000 pid=5201 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=b8fa1aef-1c00-0000-3a7f-65d851140000 pid=5201 execve guuid=debd362b-1d00-0000-3a7f-65d852140000 pid=5202 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=debd362b-1d00-0000-3a7f-65d852140000 pid=5202 execve guuid=1bb62a68-1d00-0000-3a7f-65d853140000 pid=5203 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=1bb62a68-1d00-0000-3a7f-65d853140000 pid=5203 execve guuid=d8143ba4-1d00-0000-3a7f-65d854140000 pid=5204 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=d8143ba4-1d00-0000-3a7f-65d854140000 pid=5204 execve guuid=0b7b2ce0-1d00-0000-3a7f-65d85b140000 pid=5211 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=0b7b2ce0-1d00-0000-3a7f-65d85b140000 pid=5211 execve guuid=087f271c-1e00-0000-3a7f-65d866140000 pid=5222 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=087f271c-1e00-0000-3a7f-65d866140000 pid=5222 execve guuid=d90d5758-1e00-0000-3a7f-65d878140000 pid=5240 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=d90d5758-1e00-0000-3a7f-65d878140000 pid=5240 execve guuid=f9966094-1e00-0000-3a7f-65d879140000 pid=5241 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=f9966094-1e00-0000-3a7f-65d879140000 pid=5241 execve guuid=ae31c0d0-1e00-0000-3a7f-65d87a140000 pid=5242 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=ae31c0d0-1e00-0000-3a7f-65d87a140000 pid=5242 execve guuid=b221e50c-1f00-0000-3a7f-65d87b140000 pid=5243 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=b221e50c-1f00-0000-3a7f-65d87b140000 pid=5243 execve guuid=02cd3149-1f00-0000-3a7f-65d87c140000 pid=5244 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=02cd3149-1f00-0000-3a7f-65d87c140000 pid=5244 execve guuid=0f5a4e85-1f00-0000-3a7f-65d87d140000 pid=5245 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=0f5a4e85-1f00-0000-3a7f-65d87d140000 pid=5245 execve guuid=4a105cc1-1f00-0000-3a7f-65d87e140000 pid=5246 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=4a105cc1-1f00-0000-3a7f-65d87e140000 pid=5246 execve guuid=fdce8dfd-1f00-0000-3a7f-65d87f140000 pid=5247 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=fdce8dfd-1f00-0000-3a7f-65d87f140000 pid=5247 execve guuid=39becf39-2000-0000-3a7f-65d880140000 pid=5248 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=39becf39-2000-0000-3a7f-65d880140000 pid=5248 execve guuid=6fc53876-2000-0000-3a7f-65d881140000 pid=5249 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=6fc53876-2000-0000-3a7f-65d881140000 pid=5249 execve guuid=7b893db2-2000-0000-3a7f-65d882140000 pid=5250 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=7b893db2-2000-0000-3a7f-65d882140000 pid=5250 execve guuid=fcc548ee-2000-0000-3a7f-65d883140000 pid=5251 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=fcc548ee-2000-0000-3a7f-65d883140000 pid=5251 execve guuid=abf66e2a-2100-0000-3a7f-65d884140000 pid=5252 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=abf66e2a-2100-0000-3a7f-65d884140000 pid=5252 execve guuid=436d8466-2100-0000-3a7f-65d885140000 pid=5253 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=436d8466-2100-0000-3a7f-65d885140000 pid=5253 execve guuid=643e76a2-2100-0000-3a7f-65d886140000 pid=5254 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=643e76a2-2100-0000-3a7f-65d886140000 pid=5254 execve guuid=7e196bde-2100-0000-3a7f-65d887140000 pid=5255 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=7e196bde-2100-0000-3a7f-65d887140000 pid=5255 execve guuid=078a651a-2200-0000-3a7f-65d889140000 pid=5257 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=078a651a-2200-0000-3a7f-65d889140000 pid=5257 execve guuid=a1c15756-2200-0000-3a7f-65d88a140000 pid=5258 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=a1c15756-2200-0000-3a7f-65d88a140000 pid=5258 execve guuid=b6114c92-2200-0000-3a7f-65d88b140000 pid=5259 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=b6114c92-2200-0000-3a7f-65d88b140000 pid=5259 execve guuid=241382ce-2200-0000-3a7f-65d88c140000 pid=5260 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=241382ce-2200-0000-3a7f-65d88c140000 pid=5260 execve guuid=fa8c770a-2300-0000-3a7f-65d88d140000 pid=5261 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=fa8c770a-2300-0000-3a7f-65d88d140000 pid=5261 execve guuid=e30cb746-2300-0000-3a7f-65d88e140000 pid=5262 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=e30cb746-2300-0000-3a7f-65d88e140000 pid=5262 execve guuid=0a31f282-2300-0000-3a7f-65d88f140000 pid=5263 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=0a31f282-2300-0000-3a7f-65d88f140000 pid=5263 execve guuid=b47647bf-2300-0000-3a7f-65d890140000 pid=5264 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=b47647bf-2300-0000-3a7f-65d890140000 pid=5264 execve guuid=d37a7afb-2300-0000-3a7f-65d891140000 pid=5265 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=d37a7afb-2300-0000-3a7f-65d891140000 pid=5265 execve guuid=46947337-2400-0000-3a7f-65d892140000 pid=5266 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=46947337-2400-0000-3a7f-65d892140000 pid=5266 execve guuid=56308b73-2400-0000-3a7f-65d893140000 pid=5267 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=56308b73-2400-0000-3a7f-65d893140000 pid=5267 execve guuid=924dc8af-2400-0000-3a7f-65d894140000 pid=5268 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=924dc8af-2400-0000-3a7f-65d894140000 pid=5268 execve guuid=fda0dbeb-2400-0000-3a7f-65d895140000 pid=5269 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=fda0dbeb-2400-0000-3a7f-65d895140000 pid=5269 execve guuid=a14adf27-2500-0000-3a7f-65d896140000 pid=5270 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=a14adf27-2500-0000-3a7f-65d896140000 pid=5270 execve guuid=ff25ee63-2500-0000-3a7f-65d897140000 pid=5271 /usr/bin/sleep guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=ff25ee63-2500-0000-3a7f-65d897140000 pid=5271 execve guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5290 /usr/bin/curl guuid=dc51071a-1a00-0000-3a7f-65d8ac100000 pid=4268->guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5290 execve guuid=7ac66f1d-1a00-0000-3a7f-65d8b4100000 pid=4276 /usr/bin/date guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=7ac66f1d-1a00-0000-3a7f-65d8b4100000 pid=4276 execve guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4283 /usr/bin/curl guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4283 execve guuid=24ddd692-2500-0000-3a7f-65d898140000 pid=5272 /usr/bin/mktemp guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=24ddd692-2500-0000-3a7f-65d898140000 pid=5272 execve guuid=467f3893-2500-0000-3a7f-65d899140000 pid=5273 /usr/bin/bash guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=467f3893-2500-0000-3a7f-65d899140000 pid=5273 clone guuid=470b4193-2500-0000-3a7f-65d89a140000 pid=5274 /usr/bin/base64 write-file guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=470b4193-2500-0000-3a7f-65d89a140000 pid=5274 execve guuid=2b95c893-2500-0000-3a7f-65d89b140000 pid=5275 /usr/bin/chmod guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=2b95c893-2500-0000-3a7f-65d89b140000 pid=5275 execve guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276 /usr/bin/bash write-file guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276 execve guuid=7e001496-2500-0000-3a7f-65d8a2140000 pid=5282 /usr/bin/bash zombie guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=7e001496-2500-0000-3a7f-65d8a2140000 pid=5282 clone guuid=e0422596-2500-0000-3a7f-65d8a3140000 pid=5283 /usr/bin/rm delete-file guuid=1a64901b-1a00-0000-3a7f-65d8af100000 pid=4271->guuid=e0422596-2500-0000-3a7f-65d8a3140000 pid=5283 execve guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4310 /usr/bin/curl net send-data guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4283->guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4310 clone guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5221 /usr/bin/curl net send-data guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4283->guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5221 clone guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5256 /usr/bin/curl net send-data guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4283->guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5256 clone 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=4310->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 280B guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5221->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 280B guuid=3f9ad01e-1a00-0000-3a7f-65d8bb100000 pid=5256->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 210B guuid=88b88d94-2500-0000-3a7f-65d89d140000 pid=5277 /usr/bin/date guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276->guuid=88b88d94-2500-0000-3a7f-65d89d140000 pid=5277 execve guuid=4111f994-2500-0000-3a7f-65d89e140000 pid=5278 /usr/bin/mkdir guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276->guuid=4111f994-2500-0000-3a7f-65d89e140000 pid=5278 execve guuid=162a5795-2500-0000-3a7f-65d89f140000 pid=5279 /usr/bin/cat write-file guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276->guuid=162a5795-2500-0000-3a7f-65d89f140000 pid=5279 execve guuid=b3fbad95-2500-0000-3a7f-65d8a0140000 pid=5280 /usr/bin/chmod guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276->guuid=b3fbad95-2500-0000-3a7f-65d8a0140000 pid=5280 execve guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281 /usr/bin/bash write-file zombie guuid=d5f11394-2500-0000-3a7f-65d89c140000 pid=5276->guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281 execve guuid=e390e996-2500-0000-3a7f-65d8a6140000 pid=5286 /usr/bin/mkdir guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=e390e996-2500-0000-3a7f-65d8a6140000 pid=5286 execve guuid=cc5b7997-2500-0000-3a7f-65d8a7140000 pid=5287 /usr/bin/mkdir guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=cc5b7997-2500-0000-3a7f-65d8a7140000 pid=5287 execve guuid=e5f4d497-2500-0000-3a7f-65d8a8140000 pid=5288 /usr/bin/date guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=e5f4d497-2500-0000-3a7f-65d8a8140000 pid=5288 execve guuid=15003198-2500-0000-3a7f-65d8a9140000 pid=5289 /usr/bin/sleep guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=15003198-2500-0000-3a7f-65d8a9140000 pid=5289 execve guuid=561854b6-2500-0000-3a7f-65d8ac140000 pid=5292 /usr/bin/date guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=561854b6-2500-0000-3a7f-65d8ac140000 pid=5292 execve guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5293 /usr/bin/curl guuid=5da9f495-2500-0000-3a7f-65d8a1140000 pid=5281->guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5293 execve guuid=f7c42796-2500-0000-3a7f-65d8a4140000 pid=5284 /usr/bin/rm delete-file guuid=7e001496-2500-0000-3a7f-65d8a2140000 pid=5282->guuid=f7c42796-2500-0000-3a7f-65d8a4140000 pid=5284 execve guuid=a3499796-2500-0000-3a7f-65d8a5140000 pid=5285 /usr/bin/rm guuid=7e001496-2500-0000-3a7f-65d8a2140000 pid=5282->guuid=a3499796-2500-0000-3a7f-65d8a5140000 pid=5285 execve guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5291 /usr/bin/curl net send-data guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5290->guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5291 clone guuid=03dc31a0-2500-0000-3a7f-65d8aa140000 pid=5291->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 210B guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5294 /usr/bin/curl net send-data guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5293->guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5294 clone guuid=aa6dcab6-2500-0000-3a7f-65d8ad140000 pid=5294->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 210B
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Checks CPU configuration
File and Directory Permissions Modification
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1b45f9d89cf03c56afa6ec5cce472e4b36680d792a47f728ee30ef993cf16648

(this sample)

  
Delivery method
Distributed via web download

Comments