MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 20cefb1a22a2b1f9f33bf9e04478491d1e7577dd2d17e331e0dddfecd88b0e48. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 20cefb1a22a2b1f9f33bf9e04478491d1e7577dd2d17e331e0dddfecd88b0e48
SHA3-384 hash: 052869425eb7c12512cb780986a245f2c16c8ec2d819c42550893d015a82305916610476df44a8797157f90dd97324e2
SHA1 hash: 095934b12695dce729186ab0189658c95c188ffd
MD5 hash: 7a5888f643b9fda5e76e2b61c4ef3e09
humanhash: sink-river-cold-bulldog
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-06-13 01:13:21 UTC
Last seen:2026-06-13 08:34:50 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hT13JNy0Tw+YAulNXYq9DG+NjVsNXYrkJ:V7gdPiq9DGmKi2
TLSH T1D2D097A34273013029616448F2E2A0C07420873F0C85C02DFE273C386F1128AF0D0360
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=224d2da9-1600-0000-cf96-6559c20c0000 pid=3266 /usr/bin/sudo guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276 /tmp/sample.bin guuid=224d2da9-1600-0000-cf96-6559c20c0000 pid=3266->guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276 execve guuid=0965f3ab-1600-0000-cf96-6559ce0c0000 pid=3278 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=0965f3ab-1600-0000-cf96-6559ce0c0000 pid=3278 execve guuid=8a4f97ac-1600-0000-cf96-6559d20c0000 pid=3282 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=8a4f97ac-1600-0000-cf96-6559d20c0000 pid=3282 execve guuid=13de3cca-1600-0000-cf96-6559f90c0000 pid=3321 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=13de3cca-1600-0000-cf96-6559f90c0000 pid=3321 execve guuid=dff5e6ca-1600-0000-cf96-6559fb0c0000 pid=3323 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=dff5e6ca-1600-0000-cf96-6559fb0c0000 pid=3323 clone guuid=7bfefdcc-1600-0000-cf96-6559000d0000 pid=3328 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=7bfefdcc-1600-0000-cf96-6559000d0000 pid=3328 execve guuid=bfde3fcd-1600-0000-cf96-6559020d0000 pid=3330 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=bfde3fcd-1600-0000-cf96-6559020d0000 pid=3330 execve guuid=3f8680ed-1600-0000-cf96-6559390d0000 pid=3385 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=3f8680ed-1600-0000-cf96-6559390d0000 pid=3385 execve guuid=34a1f6ed-1600-0000-cf96-65593a0d0000 pid=3386 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=34a1f6ed-1600-0000-cf96-65593a0d0000 pid=3386 clone guuid=9011ffee-1600-0000-cf96-65593e0d0000 pid=3390 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=9011ffee-1600-0000-cf96-65593e0d0000 pid=3390 execve guuid=44b762ef-1600-0000-cf96-6559400d0000 pid=3392 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=44b762ef-1600-0000-cf96-6559400d0000 pid=3392 execve guuid=3f98060c-1700-0000-cf96-6559830d0000 pid=3459 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=3f98060c-1700-0000-cf96-6559830d0000 pid=3459 execve guuid=b6024f0c-1700-0000-cf96-6559850d0000 pid=3461 /tmp/KGJT guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=b6024f0c-1700-0000-cf96-6559850d0000 pid=3461 execve guuid=39f16b0c-1700-0000-cf96-6559870d0000 pid=3463 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=39f16b0c-1700-0000-cf96-6559870d0000 pid=3463 execve guuid=0d8cb70c-1700-0000-cf96-6559890d0000 pid=3465 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=0d8cb70c-1700-0000-cf96-6559890d0000 pid=3465 execve guuid=43dd2a28-1700-0000-cf96-6559c50d0000 pid=3525 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=43dd2a28-1700-0000-cf96-6559c50d0000 pid=3525 execve guuid=bed37e28-1700-0000-cf96-6559c70d0000 pid=3527 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=bed37e28-1700-0000-cf96-6559c70d0000 pid=3527 clone guuid=dc522c29-1700-0000-cf96-6559ca0d0000 pid=3530 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=dc522c29-1700-0000-cf96-6559ca0d0000 pid=3530 execve guuid=a3526e29-1700-0000-cf96-6559cc0d0000 pid=3532 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=a3526e29-1700-0000-cf96-6559cc0d0000 pid=3532 execve guuid=e6656544-1700-0000-cf96-6559230e0000 pid=3619 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=e6656544-1700-0000-cf96-6559230e0000 pid=3619 execve guuid=f35ca144-1700-0000-cf96-6559250e0000 pid=3621 /tmp/XFUU guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=f35ca144-1700-0000-cf96-6559250e0000 pid=3621 execve guuid=cfa6b944-1700-0000-cf96-6559280e0000 pid=3624 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=cfa6b944-1700-0000-cf96-6559280e0000 pid=3624 execve guuid=5021f744-1700-0000-cf96-65592a0e0000 pid=3626 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=5021f744-1700-0000-cf96-65592a0e0000 pid=3626 execve guuid=7e0ac55f-1700-0000-cf96-6559960e0000 pid=3734 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=7e0ac55f-1700-0000-cf96-6559960e0000 pid=3734 execve guuid=cfeb0b60-1700-0000-cf96-65599a0e0000 pid=3738 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=cfeb0b60-1700-0000-cf96-65599a0e0000 pid=3738 clone guuid=26b09b60-1700-0000-cf96-65599f0e0000 pid=3743 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=26b09b60-1700-0000-cf96-65599f0e0000 pid=3743 execve guuid=a2c30061-1700-0000-cf96-6559a00e0000 pid=3744 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=a2c30061-1700-0000-cf96-6559a00e0000 pid=3744 execve guuid=3e89247c-1700-0000-cf96-6559190f0000 pid=3865 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=3e89247c-1700-0000-cf96-6559190f0000 pid=3865 execve guuid=782b787c-1700-0000-cf96-65591b0f0000 pid=3867 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=782b787c-1700-0000-cf96-65591b0f0000 pid=3867 clone guuid=fb94547d-1700-0000-cf96-6559200f0000 pid=3872 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=fb94547d-1700-0000-cf96-6559200f0000 pid=3872 execve guuid=b4dfac7d-1700-0000-cf96-6559220f0000 pid=3874 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=b4dfac7d-1700-0000-cf96-6559220f0000 pid=3874 execve guuid=7df60799-1700-0000-cf96-6559610f0000 pid=3937 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=7df60799-1700-0000-cf96-6559610f0000 pid=3937 execve guuid=48187f99-1700-0000-cf96-6559650f0000 pid=3941 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=48187f99-1700-0000-cf96-6559650f0000 pid=3941 clone guuid=a0a3a79a-1700-0000-cf96-6559670f0000 pid=3943 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=a0a3a79a-1700-0000-cf96-6559670f0000 pid=3943 execve guuid=6f933d9b-1700-0000-cf96-65596a0f0000 pid=3946 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=6f933d9b-1700-0000-cf96-65596a0f0000 pid=3946 execve guuid=681958b3-1700-0000-cf96-6559a20f0000 pid=4002 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=681958b3-1700-0000-cf96-6559a20f0000 pid=4002 execve guuid=819bedb3-1700-0000-cf96-6559a30f0000 pid=4003 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=819bedb3-1700-0000-cf96-6559a30f0000 pid=4003 clone guuid=e4df0fb5-1700-0000-cf96-6559a80f0000 pid=4008 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=e4df0fb5-1700-0000-cf96-6559a80f0000 pid=4008 execve guuid=7f3473b5-1700-0000-cf96-6559aa0f0000 pid=4010 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=7f3473b5-1700-0000-cf96-6559aa0f0000 pid=4010 execve guuid=e5a2cad1-1700-0000-cf96-6559e90f0000 pid=4073 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=e5a2cad1-1700-0000-cf96-6559e90f0000 pid=4073 execve guuid=868735d2-1700-0000-cf96-6559eb0f0000 pid=4075 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=868735d2-1700-0000-cf96-6559eb0f0000 pid=4075 clone guuid=416e50d4-1700-0000-cf96-6559f00f0000 pid=4080 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=416e50d4-1700-0000-cf96-6559f00f0000 pid=4080 execve guuid=48b3c5d4-1700-0000-cf96-6559f10f0000 pid=4081 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=48b3c5d4-1700-0000-cf96-6559f10f0000 pid=4081 execve guuid=f22867f0-1700-0000-cf96-655936100000 pid=4150 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=f22867f0-1700-0000-cf96-655936100000 pid=4150 execve guuid=89a4fff0-1700-0000-cf96-655938100000 pid=4152 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=89a4fff0-1700-0000-cf96-655938100000 pid=4152 clone guuid=a56e17f2-1700-0000-cf96-65593e100000 pid=4158 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=a56e17f2-1700-0000-cf96-65593e100000 pid=4158 execve guuid=955099f2-1700-0000-cf96-65593f100000 pid=4159 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=955099f2-1700-0000-cf96-65593f100000 pid=4159 execve guuid=1f45d80d-1800-0000-cf96-655978100000 pid=4216 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=1f45d80d-1800-0000-cf96-655978100000 pid=4216 execve guuid=6f10690e-1800-0000-cf96-65597b100000 pid=4219 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=6f10690e-1800-0000-cf96-65597b100000 pid=4219 clone guuid=ba80a20f-1800-0000-cf96-655981100000 pid=4225 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=ba80a20f-1800-0000-cf96-655981100000 pid=4225 execve guuid=8ab6dc0f-1800-0000-cf96-655983100000 pid=4227 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=8ab6dc0f-1800-0000-cf96-655983100000 pid=4227 execve guuid=0bd6fa2a-1800-0000-cf96-6559cc100000 pid=4300 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=0bd6fa2a-1800-0000-cf96-6559cc100000 pid=4300 execve guuid=ad9b7b2b-1800-0000-cf96-6559cd100000 pid=4301 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=ad9b7b2b-1800-0000-cf96-6559cd100000 pid=4301 clone guuid=8fb2cf2c-1800-0000-cf96-6559d2100000 pid=4306 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=8fb2cf2c-1800-0000-cf96-6559d2100000 pid=4306 execve guuid=c04d3c2d-1800-0000-cf96-6559d4100000 pid=4308 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=c04d3c2d-1800-0000-cf96-6559d4100000 pid=4308 execve guuid=8f634954-1800-0000-cf96-655902110000 pid=4354 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=8f634954-1800-0000-cf96-655902110000 pid=4354 execve guuid=2508db54-1800-0000-cf96-655903110000 pid=4355 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=2508db54-1800-0000-cf96-655903110000 pid=4355 clone guuid=8c5f5656-1800-0000-cf96-655905110000 pid=4357 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=8c5f5656-1800-0000-cf96-655905110000 pid=4357 execve guuid=f9f89f56-1800-0000-cf96-655908110000 pid=4360 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=f9f89f56-1800-0000-cf96-655908110000 pid=4360 execve guuid=9fa52872-1800-0000-cf96-65596c110000 pid=4460 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=9fa52872-1800-0000-cf96-65596c110000 pid=4460 execve guuid=88486172-1800-0000-cf96-65596f110000 pid=4463 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=88486172-1800-0000-cf96-65596f110000 pid=4463 clone guuid=18980573-1800-0000-cf96-655973110000 pid=4467 /usr/bin/rm guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=18980573-1800-0000-cf96-655973110000 pid=4467 execve guuid=e4224973-1800-0000-cf96-655975110000 pid=4469 /usr/bin/wget net send-data write-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=e4224973-1800-0000-cf96-655975110000 pid=4469 execve guuid=05543f8e-1800-0000-cf96-6559f1110000 pid=4593 /usr/bin/chmod guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=05543f8e-1800-0000-cf96-6559f1110000 pid=4593 execve guuid=2dbf7a8e-1800-0000-cf96-6559f4110000 pid=4596 /usr/bin/dash guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=2dbf7a8e-1800-0000-cf96-6559f4110000 pid=4596 clone guuid=b3580b8f-1800-0000-cf96-6559f8110000 pid=4600 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=b3580b8f-1800-0000-cf96-6559f8110000 pid=4600 execve guuid=2cc24a8f-1800-0000-cf96-6559fc110000 pid=4604 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=2cc24a8f-1800-0000-cf96-6559fc110000 pid=4604 execve guuid=65d7868f-1800-0000-cf96-6559fd110000 pid=4605 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=65d7868f-1800-0000-cf96-6559fd110000 pid=4605 execve guuid=c90ac28f-1800-0000-cf96-655901120000 pid=4609 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=c90ac28f-1800-0000-cf96-655901120000 pid=4609 execve guuid=2e470090-1800-0000-cf96-655903120000 pid=4611 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=2e470090-1800-0000-cf96-655903120000 pid=4611 execve guuid=f52b3c90-1800-0000-cf96-655905120000 pid=4613 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=f52b3c90-1800-0000-cf96-655905120000 pid=4613 execve guuid=f5037a90-1800-0000-cf96-655907120000 pid=4615 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=f5037a90-1800-0000-cf96-655907120000 pid=4615 execve guuid=48cfb090-1800-0000-cf96-65590a120000 pid=4618 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=48cfb090-1800-0000-cf96-65590a120000 pid=4618 execve guuid=7c66ed90-1800-0000-cf96-65590d120000 pid=4621 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=7c66ed90-1800-0000-cf96-65590d120000 pid=4621 execve guuid=e9d22691-1800-0000-cf96-65590f120000 pid=4623 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=e9d22691-1800-0000-cf96-65590f120000 pid=4623 execve guuid=10196c91-1800-0000-cf96-655911120000 pid=4625 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=10196c91-1800-0000-cf96-655911120000 pid=4625 execve guuid=dcbbab91-1800-0000-cf96-655913120000 pid=4627 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=dcbbab91-1800-0000-cf96-655913120000 pid=4627 execve guuid=73cbe591-1800-0000-cf96-655917120000 pid=4631 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=73cbe591-1800-0000-cf96-655917120000 pid=4631 execve guuid=43012492-1800-0000-cf96-655918120000 pid=4632 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=43012492-1800-0000-cf96-655918120000 pid=4632 execve guuid=6b116292-1800-0000-cf96-65591c120000 pid=4636 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=6b116292-1800-0000-cf96-65591c120000 pid=4636 execve guuid=d4de9b92-1800-0000-cf96-65591e120000 pid=4638 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=d4de9b92-1800-0000-cf96-65591e120000 pid=4638 execve guuid=025edc92-1800-0000-cf96-655920120000 pid=4640 /usr/bin/rm delete-file guuid=97889cab-1600-0000-cf96-6559cc0c0000 pid=3276->guuid=025edc92-1800-0000-cf96-655920120000 pid=4640 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=8a4f97ac-1600-0000-cf96-6559d20c0000 pid=3282->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=bfde3fcd-1600-0000-cf96-6559020d0000 pid=3330->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=44b762ef-1600-0000-cf96-6559400d0000 pid=3392->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462 /tmp/KGJT net send-data write-file zombie guuid=b6024f0c-1700-0000-cf96-6559850d0000 pid=3461->guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=f0581e12-1700-0000-cf96-6559980d0000 pid=3480 /usr/bin/uname guuid=2e8b650c-1700-0000-cf96-6559860d0000 pid=3462->guuid=f0581e12-1700-0000-cf96-6559980d0000 pid=3480 execve guuid=0d8cb70c-1700-0000-cf96-6559890d0000 pid=3465->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a3526e29-1700-0000-cf96-6559cc0d0000 pid=3532->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d4c0b144-1700-0000-cf96-6559260e0000 pid=3622 /tmp/XFUU zombie guuid=f35ca144-1700-0000-cf96-6559250e0000 pid=3621->guuid=d4c0b144-1700-0000-cf96-6559260e0000 pid=3622 clone guuid=5021f744-1700-0000-cf96-65592a0e0000 pid=3626->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a2c30061-1700-0000-cf96-6559a00e0000 pid=3744->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b4dfac7d-1700-0000-cf96-6559220f0000 pid=3874->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=6f933d9b-1700-0000-cf96-65596a0f0000 pid=3946->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=7f3473b5-1700-0000-cf96-6559aa0f0000 pid=4010->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=48b3c5d4-1700-0000-cf96-6559f10f0000 pid=4081->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=955099f2-1700-0000-cf96-65593f100000 pid=4159->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=8ab6dc0f-1800-0000-cf96-655983100000 pid=4227->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=c04d3c2d-1800-0000-cf96-6559d4100000 pid=4308->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=f9f89f56-1800-0000-cf96-655908110000 pid=4360->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=e4224973-1800-0000-cf96-655975110000 pid=4469->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-13 01:14:28 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 20cefb1a22a2b1f9f33bf9e04478491d1e7577dd2d17e331e0dddfecd88b0e48

(this sample)

  
Delivery method
Distributed via web download

Comments