MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 1ebb03f11c7356520fc8bac4a7b49c83760740a3e00eb00309096cacca50bcc0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 1ebb03f11c7356520fc8bac4a7b49c83760740a3e00eb00309096cacca50bcc0
SHA3-384 hash: cab65ac20df8e86f44e22cca614e5127c8ae64158741c85e47cd121324fe4580d41fbd55af6db795d09154a95a4f40d5
SHA1 hash: 9a00284bf536a41fec125ac1786e8107408f258b
MD5 hash: b3223c74932a92e79c7a9875759906b0
humanhash: eighteen-quebec-south-chicken
File name:O.sh
Download: download sample
File size:365 bytes
First seen:2026-04-10 02:11:48 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 6:/24J+d9FENsRV6M5dOuRVYyttxYZo0I9nZKY3FsDKVKhOXqIKLsVKhOXqIKa03Ix:/24J+zF8sbYuRrFYZoDZYWghsOLsghsX
TLSH T1B2E0C00C74800873BD369CF9BAD73584810FC35E3D0EB59CC294241FB4F4890A000833
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
44
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Result
Gathering data
Verdict:
Malicious
File Type:
ps1
First seen:
2026-04-09T23:17:00Z UTC
Last seen:
2026-04-09T23:17:00Z UTC
Hits:
~10
Detections:
Trojan-Downloader.Shell.Agent.bi HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=f141f0c4-1600-0000-7563-e6f2800c0000 pid=3200 /usr/bin/sudo guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201 /tmp/sample.bin guuid=f141f0c4-1600-0000-7563-e6f2800c0000 pid=3200->guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201 execve guuid=098c5ac8-1600-0000-7563-e6f2820c0000 pid=3202 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=098c5ac8-1600-0000-7563-e6f2820c0000 pid=3202 execve guuid=2d276ee1-1600-0000-7563-e6f2980c0000 pid=3224 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=2d276ee1-1600-0000-7563-e6f2980c0000 pid=3224 execve guuid=a94749fd-1600-0000-7563-e6f2b80c0000 pid=3256 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a94749fd-1600-0000-7563-e6f2b80c0000 pid=3256 execve guuid=1df4bdfd-1600-0000-7563-e6f2ba0c0000 pid=3258 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=1df4bdfd-1600-0000-7563-e6f2ba0c0000 pid=3258 execve guuid=c7c922fe-1600-0000-7563-e6f2bb0c0000 pid=3259 /tmp/XoClipzoX mprotect-exec net guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=c7c922fe-1600-0000-7563-e6f2bb0c0000 pid=3259 execve guuid=ec2ce1fe-1600-0000-7563-e6f2c10c0000 pid=3265 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=ec2ce1fe-1600-0000-7563-e6f2c10c0000 pid=3265 execve guuid=5bda59ff-1600-0000-7563-e6f2c20c0000 pid=3266 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=5bda59ff-1600-0000-7563-e6f2c20c0000 pid=3266 execve guuid=9ad3c316-1700-0000-7563-e6f2f60c0000 pid=3318 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=9ad3c316-1700-0000-7563-e6f2f60c0000 pid=3318 execve guuid=6e151a30-1700-0000-7563-e6f23c0d0000 pid=3388 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=6e151a30-1700-0000-7563-e6f23c0d0000 pid=3388 execve guuid=62225530-1700-0000-7563-e6f23d0d0000 pid=3389 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=62225530-1700-0000-7563-e6f23d0d0000 pid=3389 execve guuid=c79a9130-1700-0000-7563-e6f23f0d0000 pid=3391 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=c79a9130-1700-0000-7563-e6f23f0d0000 pid=3391 clone guuid=b3961431-1700-0000-7563-e6f2420d0000 pid=3394 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b3961431-1700-0000-7563-e6f2420d0000 pid=3394 execve guuid=e3375031-1700-0000-7563-e6f2440d0000 pid=3396 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e3375031-1700-0000-7563-e6f2440d0000 pid=3396 execve guuid=e1576f48-1700-0000-7563-e6f2920d0000 pid=3474 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e1576f48-1700-0000-7563-e6f2920d0000 pid=3474 execve guuid=36930161-1700-0000-7563-e6f2c10d0000 pid=3521 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=36930161-1700-0000-7563-e6f2c10d0000 pid=3521 execve guuid=804b4261-1700-0000-7563-e6f2c30d0000 pid=3523 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=804b4261-1700-0000-7563-e6f2c30d0000 pid=3523 execve guuid=7daa8861-1700-0000-7563-e6f2c40d0000 pid=3524 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7daa8861-1700-0000-7563-e6f2c40d0000 pid=3524 clone guuid=6cbe0a62-1700-0000-7563-e6f2c70d0000 pid=3527 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=6cbe0a62-1700-0000-7563-e6f2c70d0000 pid=3527 execve guuid=18f84562-1700-0000-7563-e6f2c90d0000 pid=3529 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=18f84562-1700-0000-7563-e6f2c90d0000 pid=3529 execve guuid=33c2af78-1700-0000-7563-e6f2100e0000 pid=3600 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=33c2af78-1700-0000-7563-e6f2100e0000 pid=3600 execve guuid=cf792c91-1700-0000-7563-e6f2650e0000 pid=3685 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=cf792c91-1700-0000-7563-e6f2650e0000 pid=3685 execve guuid=8f7a6591-1700-0000-7563-e6f2670e0000 pid=3687 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=8f7a6591-1700-0000-7563-e6f2670e0000 pid=3687 execve guuid=a20bb591-1700-0000-7563-e6f2680e0000 pid=3688 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a20bb591-1700-0000-7563-e6f2680e0000 pid=3688 clone guuid=1c1c5e93-1700-0000-7563-e6f26a0e0000 pid=3690 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=1c1c5e93-1700-0000-7563-e6f26a0e0000 pid=3690 execve guuid=8455bd93-1700-0000-7563-e6f26b0e0000 pid=3691 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=8455bd93-1700-0000-7563-e6f26b0e0000 pid=3691 execve guuid=70ca7caa-1700-0000-7563-e6f2c60e0000 pid=3782 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=70ca7caa-1700-0000-7563-e6f2c60e0000 pid=3782 execve guuid=b17506c3-1700-0000-7563-e6f2310f0000 pid=3889 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b17506c3-1700-0000-7563-e6f2310f0000 pid=3889 execve guuid=e8e83fc3-1700-0000-7563-e6f2330f0000 pid=3891 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e8e83fc3-1700-0000-7563-e6f2330f0000 pid=3891 execve guuid=622b7bc3-1700-0000-7563-e6f2350f0000 pid=3893 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=622b7bc3-1700-0000-7563-e6f2350f0000 pid=3893 clone guuid=5c4f32c5-1700-0000-7563-e6f2400f0000 pid=3904 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=5c4f32c5-1700-0000-7563-e6f2400f0000 pid=3904 execve guuid=45aa6fc5-1700-0000-7563-e6f2410f0000 pid=3905 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=45aa6fc5-1700-0000-7563-e6f2410f0000 pid=3905 execve guuid=0975e3dc-1700-0000-7563-e6f2aa0f0000 pid=4010 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=0975e3dc-1700-0000-7563-e6f2aa0f0000 pid=4010 execve guuid=70e412f6-1700-0000-7563-e6f212100000 pid=4114 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=70e412f6-1700-0000-7563-e6f212100000 pid=4114 execve guuid=e3ac54f6-1700-0000-7563-e6f214100000 pid=4116 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e3ac54f6-1700-0000-7563-e6f214100000 pid=4116 execve guuid=8c5d91f6-1700-0000-7563-e6f216100000 pid=4118 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=8c5d91f6-1700-0000-7563-e6f216100000 pid=4118 clone guuid=4c9baaf7-1700-0000-7563-e6f21b100000 pid=4123 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=4c9baaf7-1700-0000-7563-e6f21b100000 pid=4123 execve guuid=7de8edf7-1700-0000-7563-e6f21f100000 pid=4127 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7de8edf7-1700-0000-7563-e6f21f100000 pid=4127 execve guuid=7c457f0d-1800-0000-7563-e6f26b100000 pid=4203 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7c457f0d-1800-0000-7563-e6f26b100000 pid=4203 execve guuid=1fde3925-1800-0000-7563-e6f2b3100000 pid=4275 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=1fde3925-1800-0000-7563-e6f2b3100000 pid=4275 execve guuid=0ddeb525-1800-0000-7563-e6f2b7100000 pid=4279 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=0ddeb525-1800-0000-7563-e6f2b7100000 pid=4279 execve guuid=cde82c26-1800-0000-7563-e6f2b8100000 pid=4280 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=cde82c26-1800-0000-7563-e6f2b8100000 pid=4280 clone guuid=ec8ff626-1800-0000-7563-e6f2bc100000 pid=4284 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=ec8ff626-1800-0000-7563-e6f2bc100000 pid=4284 execve guuid=b3044227-1800-0000-7563-e6f2c0100000 pid=4288 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b3044227-1800-0000-7563-e6f2c0100000 pid=4288 execve guuid=80bb983f-1800-0000-7563-e6f213110000 pid=4371 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=80bb983f-1800-0000-7563-e6f213110000 pid=4371 execve guuid=b239835a-1800-0000-7563-e6f262110000 pid=4450 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b239835a-1800-0000-7563-e6f262110000 pid=4450 execve guuid=7916e95a-1800-0000-7563-e6f264110000 pid=4452 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7916e95a-1800-0000-7563-e6f264110000 pid=4452 execve guuid=8d50565b-1800-0000-7563-e6f265110000 pid=4453 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=8d50565b-1800-0000-7563-e6f265110000 pid=4453 clone guuid=2a12a85d-1800-0000-7563-e6f26b110000 pid=4459 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=2a12a85d-1800-0000-7563-e6f26b110000 pid=4459 execve guuid=d6c61c5e-1800-0000-7563-e6f26d110000 pid=4461 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=d6c61c5e-1800-0000-7563-e6f26d110000 pid=4461 execve guuid=fc496176-1800-0000-7563-e6f2bf110000 pid=4543 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=fc496176-1800-0000-7563-e6f2bf110000 pid=4543 execve guuid=b890648f-1800-0000-7563-e6f222120000 pid=4642 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b890648f-1800-0000-7563-e6f222120000 pid=4642 execve guuid=807e9f8f-1800-0000-7563-e6f223120000 pid=4643 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=807e9f8f-1800-0000-7563-e6f223120000 pid=4643 execve guuid=7d23e08f-1800-0000-7563-e6f225120000 pid=4645 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7d23e08f-1800-0000-7563-e6f225120000 pid=4645 clone guuid=7cb67790-1800-0000-7563-e6f22d120000 pid=4653 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7cb67790-1800-0000-7563-e6f22d120000 pid=4653 execve guuid=58f0b890-1800-0000-7563-e6f22e120000 pid=4654 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=58f0b890-1800-0000-7563-e6f22e120000 pid=4654 execve guuid=e75d25ae-1800-0000-7563-e6f2ab120000 pid=4779 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e75d25ae-1800-0000-7563-e6f2ab120000 pid=4779 execve guuid=3a2617cf-1800-0000-7563-e6f2e4120000 pid=4836 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=3a2617cf-1800-0000-7563-e6f2e4120000 pid=4836 execve guuid=73d7accf-1800-0000-7563-e6f2e7120000 pid=4839 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=73d7accf-1800-0000-7563-e6f2e7120000 pid=4839 execve guuid=fa6425d0-1800-0000-7563-e6f2e9120000 pid=4841 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=fa6425d0-1800-0000-7563-e6f2e9120000 pid=4841 clone guuid=027814d1-1800-0000-7563-e6f2ed120000 pid=4845 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=027814d1-1800-0000-7563-e6f2ed120000 pid=4845 execve guuid=f54086d1-1800-0000-7563-e6f2ee120000 pid=4846 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=f54086d1-1800-0000-7563-e6f2ee120000 pid=4846 execve guuid=992d63f2-1800-0000-7563-e6f235130000 pid=4917 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=992d63f2-1800-0000-7563-e6f235130000 pid=4917 execve guuid=28ab3112-1900-0000-7563-e6f273130000 pid=4979 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=28ab3112-1900-0000-7563-e6f273130000 pid=4979 execve guuid=4537ac12-1900-0000-7563-e6f275130000 pid=4981 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=4537ac12-1900-0000-7563-e6f275130000 pid=4981 execve guuid=32b12513-1900-0000-7563-e6f278130000 pid=4984 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=32b12513-1900-0000-7563-e6f278130000 pid=4984 clone guuid=95f91c14-1900-0000-7563-e6f27c130000 pid=4988 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=95f91c14-1900-0000-7563-e6f27c130000 pid=4988 execve guuid=9bdf9114-1900-0000-7563-e6f27e130000 pid=4990 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=9bdf9114-1900-0000-7563-e6f27e130000 pid=4990 execve guuid=ec06d131-1900-0000-7563-e6f2d1130000 pid=5073 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=ec06d131-1900-0000-7563-e6f2d1130000 pid=5073 execve guuid=71a4e350-1900-0000-7563-e6f243140000 pid=5187 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=71a4e350-1900-0000-7563-e6f243140000 pid=5187 execve guuid=c0332851-1900-0000-7563-e6f244140000 pid=5188 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=c0332851-1900-0000-7563-e6f244140000 pid=5188 execve guuid=a57f6151-1900-0000-7563-e6f246140000 pid=5190 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a57f6151-1900-0000-7563-e6f246140000 pid=5190 clone guuid=b942e552-1900-0000-7563-e6f24c140000 pid=5196 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b942e552-1900-0000-7563-e6f24c140000 pid=5196 execve guuid=60ec2553-1900-0000-7563-e6f24d140000 pid=5197 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=60ec2553-1900-0000-7563-e6f24d140000 pid=5197 execve guuid=b9d4d969-1900-0000-7563-e6f287140000 pid=5255 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=b9d4d969-1900-0000-7563-e6f287140000 pid=5255 execve guuid=3e962e83-1900-0000-7563-e6f2ab140000 pid=5291 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=3e962e83-1900-0000-7563-e6f2ab140000 pid=5291 execve guuid=5b07d083-1900-0000-7563-e6f2ac140000 pid=5292 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=5b07d083-1900-0000-7563-e6f2ac140000 pid=5292 execve guuid=78ff1684-1900-0000-7563-e6f2ad140000 pid=5293 /tmp/XoClipzoX net guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=78ff1684-1900-0000-7563-e6f2ad140000 pid=5293 execve guuid=ea3f7b84-1900-0000-7563-e6f2b1140000 pid=5297 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=ea3f7b84-1900-0000-7563-e6f2b1140000 pid=5297 execve guuid=641cf584-1900-0000-7563-e6f2b2140000 pid=5298 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=641cf584-1900-0000-7563-e6f2b2140000 pid=5298 execve guuid=e7ef879c-1900-0000-7563-e6f2be140000 pid=5310 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=e7ef879c-1900-0000-7563-e6f2be140000 pid=5310 execve guuid=bbe1eeb3-1900-0000-7563-e6f2bf140000 pid=5311 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=bbe1eeb3-1900-0000-7563-e6f2bf140000 pid=5311 execve guuid=0dd834b4-1900-0000-7563-e6f2c0140000 pid=5312 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=0dd834b4-1900-0000-7563-e6f2c0140000 pid=5312 execve guuid=6a9575b4-1900-0000-7563-e6f2c1140000 pid=5313 /tmp/XoClipzoX net guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=6a9575b4-1900-0000-7563-e6f2c1140000 pid=5313 execve guuid=a4bc81b5-1900-0000-7563-e6f2c5140000 pid=5317 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a4bc81b5-1900-0000-7563-e6f2c5140000 pid=5317 execve guuid=8c12d7b5-1900-0000-7563-e6f2c6140000 pid=5318 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=8c12d7b5-1900-0000-7563-e6f2c6140000 pid=5318 execve guuid=400899cc-1900-0000-7563-e6f2c7140000 pid=5319 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=400899cc-1900-0000-7563-e6f2c7140000 pid=5319 execve guuid=9714d4e5-1900-0000-7563-e6f2c8140000 pid=5320 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=9714d4e5-1900-0000-7563-e6f2c8140000 pid=5320 execve guuid=690782e6-1900-0000-7563-e6f2c9140000 pid=5321 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=690782e6-1900-0000-7563-e6f2c9140000 pid=5321 execve guuid=7fcb1de7-1900-0000-7563-e6f2ca140000 pid=5322 /tmp/XoClipzoX net guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=7fcb1de7-1900-0000-7563-e6f2ca140000 pid=5322 execve guuid=a45b80e9-1900-0000-7563-e6f2ce140000 pid=5326 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a45b80e9-1900-0000-7563-e6f2ce140000 pid=5326 execve guuid=a701d3e9-1900-0000-7563-e6f2cf140000 pid=5327 /usr/bin/wget net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=a701d3e9-1900-0000-7563-e6f2cf140000 pid=5327 execve guuid=812f3702-1a00-0000-7563-e6f2d0140000 pid=5328 /usr/bin/curl net send-data write-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=812f3702-1a00-0000-7563-e6f2d0140000 pid=5328 execve guuid=4ea49d1e-1a00-0000-7563-e6f2d1140000 pid=5329 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=4ea49d1e-1a00-0000-7563-e6f2d1140000 pid=5329 execve guuid=ea16eb1e-1a00-0000-7563-e6f2d2140000 pid=5330 /usr/bin/chmod guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=ea16eb1e-1a00-0000-7563-e6f2d2140000 pid=5330 execve guuid=1a05371f-1a00-0000-7563-e6f2d3140000 pid=5331 /usr/bin/dash guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=1a05371f-1a00-0000-7563-e6f2d3140000 pid=5331 clone guuid=6db2ea1f-1a00-0000-7563-e6f2d5140000 pid=5333 /usr/bin/rm delete-file guuid=7661d9c7-1600-0000-7563-e6f2810c0000 pid=3201->guuid=6db2ea1f-1a00-0000-7563-e6f2d5140000 pid=5333 execve cae535db-9f08-5a52-8cd1-4287aa3d4f98 62.164.130.55:80 guuid=098c5ac8-1600-0000-7563-e6f2820c0000 pid=3202->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 137B guuid=2d276ee1-1600-0000-7563-e6f2980c0000 pid=3224->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 86B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=c7c922fe-1600-0000-7563-e6f2bb0c0000 pid=3259->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=bd02a2fe-1600-0000-7563-e6f2bd0c0000 pid=3261 /tmp/XoClipzoX guuid=c7c922fe-1600-0000-7563-e6f2bb0c0000 pid=3259->guuid=bd02a2fe-1600-0000-7563-e6f2bd0c0000 pid=3261 clone guuid=9c1ba6fe-1600-0000-7563-e6f2be0c0000 pid=3262 /tmp/XoClipzoX guuid=c7c922fe-1600-0000-7563-e6f2bb0c0000 pid=3259->guuid=9c1ba6fe-1600-0000-7563-e6f2be0c0000 pid=3262 clone guuid=048babfe-1600-0000-7563-e6f2bf0c0000 pid=3263 /tmp/XoClipzoX net zombie guuid=9c1ba6fe-1600-0000-7563-e6f2be0c0000 pid=3262->guuid=048babfe-1600-0000-7563-e6f2bf0c0000 pid=3263 clone 2368a1af-75f7-59b7-804c-b6fb7498d572 107.172.193.48:326 guuid=048babfe-1600-0000-7563-e6f2bf0c0000 pid=3263->2368a1af-75f7-59b7-804c-b6fb7498d572 con guuid=5bda59ff-1600-0000-7563-e6f2c20c0000 pid=3266->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=9ad3c316-1700-0000-7563-e6f2f60c0000 pid=3318->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=e3375031-1700-0000-7563-e6f2440d0000 pid=3396->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=e1576f48-1700-0000-7563-e6f2920d0000 pid=3474->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=18f84562-1700-0000-7563-e6f2c90d0000 pid=3529->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=33c2af78-1700-0000-7563-e6f2100e0000 pid=3600->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=8455bd93-1700-0000-7563-e6f26b0e0000 pid=3691->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=70ca7caa-1700-0000-7563-e6f2c60e0000 pid=3782->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=45aa6fc5-1700-0000-7563-e6f2410f0000 pid=3905->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=0975e3dc-1700-0000-7563-e6f2aa0f0000 pid=4010->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=7de8edf7-1700-0000-7563-e6f21f100000 pid=4127->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=7c457f0d-1800-0000-7563-e6f26b100000 pid=4203->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=b3044227-1800-0000-7563-e6f2c0100000 pid=4288->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 137B guuid=80bb983f-1800-0000-7563-e6f213110000 pid=4371->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 86B guuid=d6c61c5e-1800-0000-7563-e6f26d110000 pid=4461->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 143B guuid=fc496176-1800-0000-7563-e6f2bf110000 pid=4543->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 92B guuid=58f0b890-1800-0000-7563-e6f22e120000 pid=4654->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 137B guuid=e75d25ae-1800-0000-7563-e6f2ab120000 pid=4779->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 86B guuid=f54086d1-1800-0000-7563-e6f2ee120000 pid=4846->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=992d63f2-1800-0000-7563-e6f235130000 pid=4917->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=9bdf9114-1900-0000-7563-e6f27e130000 pid=4990->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 137B guuid=ec06d131-1900-0000-7563-e6f2d1130000 pid=5073->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 86B guuid=60ec2553-1900-0000-7563-e6f24d140000 pid=5197->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=b9d4d969-1900-0000-7563-e6f287140000 pid=5255->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=78ff1684-1900-0000-7563-e6f2ad140000 pid=5293->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=f1ff6984-1900-0000-7563-e6f2ae140000 pid=5294 /tmp/XoClipzoX guuid=78ff1684-1900-0000-7563-e6f2ad140000 pid=5293->guuid=f1ff6984-1900-0000-7563-e6f2ae140000 pid=5294 clone guuid=8c1e6e84-1900-0000-7563-e6f2af140000 pid=5295 /tmp/XoClipzoX guuid=78ff1684-1900-0000-7563-e6f2ad140000 pid=5293->guuid=8c1e6e84-1900-0000-7563-e6f2af140000 pid=5295 clone guuid=6db37584-1900-0000-7563-e6f2b0140000 pid=5296 /tmp/XoClipzoX net send-data zombie guuid=8c1e6e84-1900-0000-7563-e6f2af140000 pid=5295->guuid=6db37584-1900-0000-7563-e6f2b0140000 pid=5296 clone 87f14979-beab-5a58-b48c-0a1508a0ecfa 107.172.193.48:356 guuid=6db37584-1900-0000-7563-e6f2b0140000 pid=5296->87f14979-beab-5a58-b48c-0a1508a0ecfa send: 13B guuid=641cf584-1900-0000-7563-e6f2b2140000 pid=5298->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=e7ef879c-1900-0000-7563-e6f2be140000 pid=5310->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=6a9575b4-1900-0000-7563-e6f2c1140000 pid=5313->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=fea36cb5-1900-0000-7563-e6f2c2140000 pid=5314 /tmp/XoClipzoX guuid=6a9575b4-1900-0000-7563-e6f2c1140000 pid=5313->guuid=fea36cb5-1900-0000-7563-e6f2c2140000 pid=5314 clone guuid=308970b5-1900-0000-7563-e6f2c3140000 pid=5315 /tmp/XoClipzoX guuid=6a9575b4-1900-0000-7563-e6f2c1140000 pid=5313->guuid=308970b5-1900-0000-7563-e6f2c3140000 pid=5315 clone guuid=b44275b5-1900-0000-7563-e6f2c4140000 pid=5316 /tmp/XoClipzoX net send-data zombie guuid=308970b5-1900-0000-7563-e6f2c3140000 pid=5315->guuid=b44275b5-1900-0000-7563-e6f2c4140000 pid=5316 clone guuid=b44275b5-1900-0000-7563-e6f2c4140000 pid=5316->87f14979-beab-5a58-b48c-0a1508a0ecfa send: 2977B guuid=8c12d7b5-1900-0000-7563-e6f2c6140000 pid=5318->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 138B guuid=400899cc-1900-0000-7563-e6f2c7140000 pid=5319->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 87B guuid=7fcb1de7-1900-0000-7563-e6f2ca140000 pid=5322->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9c3b50e9-1900-0000-7563-e6f2cb140000 pid=5323 /tmp/XoClipzoX guuid=7fcb1de7-1900-0000-7563-e6f2ca140000 pid=5322->guuid=9c3b50e9-1900-0000-7563-e6f2cb140000 pid=5323 clone guuid=a35558e9-1900-0000-7563-e6f2cc140000 pid=5324 /tmp/XoClipzoX guuid=7fcb1de7-1900-0000-7563-e6f2ca140000 pid=5322->guuid=a35558e9-1900-0000-7563-e6f2cc140000 pid=5324 clone guuid=3c196ce9-1900-0000-7563-e6f2cd140000 pid=5325 /tmp/XoClipzoX net send-data zombie guuid=a35558e9-1900-0000-7563-e6f2cc140000 pid=5324->guuid=3c196ce9-1900-0000-7563-e6f2cd140000 pid=5325 clone guuid=3c196ce9-1900-0000-7563-e6f2cd140000 pid=5325->87f14979-beab-5a58-b48c-0a1508a0ecfa send: 2912B guuid=a701d3e9-1900-0000-7563-e6f2cf140000 pid=5327->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 137B guuid=812f3702-1a00-0000-7563-e6f2d0140000 pid=5328->cae535db-9f08-5a52-8cd1-4287aa3d4f98 send: 86B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-04-10 02:12:45 UTC
File Type:
Text (Shell)
AV detection:
12 of 36 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 1ebb03f11c7356520fc8bac4a7b49c83760740a3e00eb00309096cacca50bcc0

(this sample)

  
Delivery method
Distributed via web download

Comments