MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 263a01a4757a908020ca1a8c639b72db94bfe19ec174d2d5495c80fb007f65c6. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 263a01a4757a908020ca1a8c639b72db94bfe19ec174d2d5495c80fb007f65c6
SHA3-384 hash: 8270f3855b038e0acac55dc8da283edf362bd67f0c65e4af357fa0f16648186aa4f785c5bf34a204bfb6fe2979291d11
SHA1 hash: fc829395d1ad5537cb4dc247f87948e6421b62a0
MD5 hash: 42f99b78ae7e8209f5c8450c746bb62e
humanhash: oranges-crazy-undress-potato
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-06-10 21:31:33 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTlVFnaKJeepKlmccWgl0DHAulNXYq4HvXDG+NjVsNXYrkJ:VlvaK8epKlmcgl0bPiq4HvXDGmKi2
TLSH T14CD097A29323033084628C21F2C37A00B2140B3EACDA835ABA2B98B21F41788F1D02B4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.155.8.56/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
76
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-10T18:39:00Z UTC
Last seen:
2026-06-12T18:16:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=461c0a15-1800-0000-8f1a-bf75e40b0000 pid=3044 /usr/bin/sudo guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053 /tmp/sample.bin guuid=461c0a15-1800-0000-8f1a-bf75e40b0000 pid=3044->guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053 execve guuid=860b8117-1800-0000-8f1a-bf75ef0b0000 pid=3055 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=860b8117-1800-0000-8f1a-bf75ef0b0000 pid=3055 execve guuid=4901e717-1800-0000-8f1a-bf75f10b0000 pid=3057 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=4901e717-1800-0000-8f1a-bf75f10b0000 pid=3057 execve guuid=5cd2ac40-1800-0000-8f1a-bf755c0c0000 pid=3164 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=5cd2ac40-1800-0000-8f1a-bf755c0c0000 pid=3164 execve guuid=9ad52b41-1800-0000-8f1a-bf755f0c0000 pid=3167 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9ad52b41-1800-0000-8f1a-bf755f0c0000 pid=3167 clone guuid=9fb4b642-1800-0000-8f1a-bf75630c0000 pid=3171 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9fb4b642-1800-0000-8f1a-bf75630c0000 pid=3171 execve guuid=149bf642-1800-0000-8f1a-bf75640c0000 pid=3172 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=149bf642-1800-0000-8f1a-bf75640c0000 pid=3172 execve guuid=5a02556b-1800-0000-8f1a-bf75910c0000 pid=3217 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=5a02556b-1800-0000-8f1a-bf75910c0000 pid=3217 execve guuid=2808e26b-1800-0000-8f1a-bf75920c0000 pid=3218 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=2808e26b-1800-0000-8f1a-bf75920c0000 pid=3218 clone guuid=4987d06c-1800-0000-8f1a-bf75940c0000 pid=3220 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=4987d06c-1800-0000-8f1a-bf75940c0000 pid=3220 execve guuid=676e576d-1800-0000-8f1a-bf75950c0000 pid=3221 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=676e576d-1800-0000-8f1a-bf75950c0000 pid=3221 execve guuid=ed4a2a94-1800-0000-8f1a-bf75b70c0000 pid=3255 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ed4a2a94-1800-0000-8f1a-bf75b70c0000 pid=3255 execve guuid=08618794-1800-0000-8f1a-bf75b90c0000 pid=3257 /tmp/PUWA guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=08618794-1800-0000-8f1a-bf75b90c0000 pid=3257 execve guuid=e200be94-1800-0000-8f1a-bf75bb0c0000 pid=3259 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=e200be94-1800-0000-8f1a-bf75bb0c0000 pid=3259 execve guuid=025fcb95-1800-0000-8f1a-bf75bd0c0000 pid=3261 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=025fcb95-1800-0000-8f1a-bf75bd0c0000 pid=3261 execve guuid=f77f6dbd-1800-0000-8f1a-bf75f00c0000 pid=3312 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=f77f6dbd-1800-0000-8f1a-bf75f00c0000 pid=3312 execve guuid=ee29cabd-1800-0000-8f1a-bf75f10c0000 pid=3313 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ee29cabd-1800-0000-8f1a-bf75f10c0000 pid=3313 clone guuid=aa86aebe-1800-0000-8f1a-bf75f50c0000 pid=3317 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=aa86aebe-1800-0000-8f1a-bf75f50c0000 pid=3317 execve guuid=bdacf9be-1800-0000-8f1a-bf75f70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=bdacf9be-1800-0000-8f1a-bf75f70c0000 pid=3319 execve guuid=0e9f88e6-1800-0000-8f1a-bf75280d0000 pid=3368 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=0e9f88e6-1800-0000-8f1a-bf75280d0000 pid=3368 execve guuid=b90dc2e6-1800-0000-8f1a-bf752a0d0000 pid=3370 /tmp/ULBG guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=b90dc2e6-1800-0000-8f1a-bf752a0d0000 pid=3370 execve guuid=ef5ddce6-1800-0000-8f1a-bf752c0d0000 pid=3372 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ef5ddce6-1800-0000-8f1a-bf752c0d0000 pid=3372 execve guuid=3cfe26e7-1800-0000-8f1a-bf752e0d0000 pid=3374 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=3cfe26e7-1800-0000-8f1a-bf752e0d0000 pid=3374 execve guuid=6e770e0e-1900-0000-8f1a-bf75890d0000 pid=3465 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=6e770e0e-1900-0000-8f1a-bf75890d0000 pid=3465 execve guuid=4b586f0e-1900-0000-8f1a-bf758b0d0000 pid=3467 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=4b586f0e-1900-0000-8f1a-bf758b0d0000 pid=3467 clone guuid=eb2b170f-1900-0000-8f1a-bf758e0d0000 pid=3470 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=eb2b170f-1900-0000-8f1a-bf758e0d0000 pid=3470 execve guuid=ab3d9b0f-1900-0000-8f1a-bf75900d0000 pid=3472 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ab3d9b0f-1900-0000-8f1a-bf75900d0000 pid=3472 execve guuid=2f20ea36-1900-0000-8f1a-bf75bf0d0000 pid=3519 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=2f20ea36-1900-0000-8f1a-bf75bf0d0000 pid=3519 execve guuid=58017637-1900-0000-8f1a-bf75c00d0000 pid=3520 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=58017637-1900-0000-8f1a-bf75c00d0000 pid=3520 clone guuid=9f661339-1900-0000-8f1a-bf75c50d0000 pid=3525 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9f661339-1900-0000-8f1a-bf75c50d0000 pid=3525 execve guuid=19e5e839-1900-0000-8f1a-bf75c70d0000 pid=3527 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=19e5e839-1900-0000-8f1a-bf75c70d0000 pid=3527 execve guuid=52769360-1900-0000-8f1a-bf75e90d0000 pid=3561 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=52769360-1900-0000-8f1a-bf75e90d0000 pid=3561 execve guuid=288ae360-1900-0000-8f1a-bf75ea0d0000 pid=3562 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=288ae360-1900-0000-8f1a-bf75ea0d0000 pid=3562 clone guuid=587c2262-1900-0000-8f1a-bf75ec0d0000 pid=3564 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=587c2262-1900-0000-8f1a-bf75ec0d0000 pid=3564 execve guuid=4bbc8b62-1900-0000-8f1a-bf75ed0d0000 pid=3565 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=4bbc8b62-1900-0000-8f1a-bf75ed0d0000 pid=3565 execve guuid=33954082-1900-0000-8f1a-bf753f0e0000 pid=3647 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=33954082-1900-0000-8f1a-bf753f0e0000 pid=3647 execve guuid=e63c9682-1900-0000-8f1a-bf75420e0000 pid=3650 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=e63c9682-1900-0000-8f1a-bf75420e0000 pid=3650 clone guuid=ae7c6d83-1900-0000-8f1a-bf75460e0000 pid=3654 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ae7c6d83-1900-0000-8f1a-bf75460e0000 pid=3654 execve guuid=e1acba83-1900-0000-8f1a-bf75470e0000 pid=3655 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=e1acba83-1900-0000-8f1a-bf75470e0000 pid=3655 execve guuid=799151aa-1900-0000-8f1a-bf75930e0000 pid=3731 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=799151aa-1900-0000-8f1a-bf75930e0000 pid=3731 execve guuid=411e91aa-1900-0000-8f1a-bf75940e0000 pid=3732 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=411e91aa-1900-0000-8f1a-bf75940e0000 pid=3732 clone guuid=6d2e21ac-1900-0000-8f1a-bf75990e0000 pid=3737 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=6d2e21ac-1900-0000-8f1a-bf75990e0000 pid=3737 execve guuid=ba285dac-1900-0000-8f1a-bf759b0e0000 pid=3739 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ba285dac-1900-0000-8f1a-bf759b0e0000 pid=3739 execve guuid=9f9bb2da-1900-0000-8f1a-bf753a0f0000 pid=3898 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9f9bb2da-1900-0000-8f1a-bf753a0f0000 pid=3898 execve guuid=e49507db-1900-0000-8f1a-bf753b0f0000 pid=3899 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=e49507db-1900-0000-8f1a-bf753b0f0000 pid=3899 clone guuid=89adeddc-1900-0000-8f1a-bf75430f0000 pid=3907 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=89adeddc-1900-0000-8f1a-bf75430f0000 pid=3907 execve guuid=5f9826dd-1900-0000-8f1a-bf75440f0000 pid=3908 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=5f9826dd-1900-0000-8f1a-bf75440f0000 pid=3908 execve guuid=1faeb603-1a00-0000-8f1a-bf75bc0f0000 pid=4028 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=1faeb603-1a00-0000-8f1a-bf75bc0f0000 pid=4028 execve guuid=7060f403-1a00-0000-8f1a-bf75be0f0000 pid=4030 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=7060f403-1a00-0000-8f1a-bf75be0f0000 pid=4030 clone guuid=abeb7804-1a00-0000-8f1a-bf75c10f0000 pid=4033 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=abeb7804-1a00-0000-8f1a-bf75c10f0000 pid=4033 execve guuid=b883c704-1a00-0000-8f1a-bf75c30f0000 pid=4035 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=b883c704-1a00-0000-8f1a-bf75c30f0000 pid=4035 execve guuid=16d39c2b-1a00-0000-8f1a-bf7544100000 pid=4164 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=16d39c2b-1a00-0000-8f1a-bf7544100000 pid=4164 execve guuid=5bcef82b-1a00-0000-8f1a-bf7545100000 pid=4165 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=5bcef82b-1a00-0000-8f1a-bf7545100000 pid=4165 clone guuid=c2b56a2d-1a00-0000-8f1a-bf754b100000 pid=4171 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=c2b56a2d-1a00-0000-8f1a-bf754b100000 pid=4171 execve guuid=8a81d02d-1a00-0000-8f1a-bf754f100000 pid=4175 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=8a81d02d-1a00-0000-8f1a-bf754f100000 pid=4175 execve guuid=19f8a356-1a00-0000-8f1a-bf75cd100000 pid=4301 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=19f8a356-1a00-0000-8f1a-bf75cd100000 pid=4301 execve guuid=24caf156-1a00-0000-8f1a-bf75cf100000 pid=4303 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=24caf156-1a00-0000-8f1a-bf75cf100000 pid=4303 clone guuid=22f68f57-1a00-0000-8f1a-bf75d4100000 pid=4308 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=22f68f57-1a00-0000-8f1a-bf75d4100000 pid=4308 execve guuid=08f1f457-1a00-0000-8f1a-bf75d8100000 pid=4312 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=08f1f457-1a00-0000-8f1a-bf75d8100000 pid=4312 execve guuid=d4f4e080-1a00-0000-8f1a-bf7561110000 pid=4449 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=d4f4e080-1a00-0000-8f1a-bf7561110000 pid=4449 execve guuid=ca2a3281-1a00-0000-8f1a-bf7563110000 pid=4451 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ca2a3281-1a00-0000-8f1a-bf7563110000 pid=4451 clone guuid=d5e96682-1a00-0000-8f1a-bf7568110000 pid=4456 /usr/bin/rm guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=d5e96682-1a00-0000-8f1a-bf7568110000 pid=4456 execve guuid=0f1ba882-1a00-0000-8f1a-bf756a110000 pid=4458 /usr/bin/wget net send-data write-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=0f1ba882-1a00-0000-8f1a-bf756a110000 pid=4458 execve guuid=2c4927aa-1a00-0000-8f1a-bf75e4110000 pid=4580 /usr/bin/chmod guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=2c4927aa-1a00-0000-8f1a-bf75e4110000 pid=4580 execve guuid=b020b0aa-1a00-0000-8f1a-bf75e5110000 pid=4581 /usr/bin/dash guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=b020b0aa-1a00-0000-8f1a-bf75e5110000 pid=4581 clone guuid=1780fcac-1a00-0000-8f1a-bf75ed110000 pid=4589 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=1780fcac-1a00-0000-8f1a-bf75ed110000 pid=4589 execve guuid=10f86bad-1a00-0000-8f1a-bf75ef110000 pid=4591 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=10f86bad-1a00-0000-8f1a-bf75ef110000 pid=4591 execve guuid=2ebf1aae-1a00-0000-8f1a-bf75f2110000 pid=4594 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=2ebf1aae-1a00-0000-8f1a-bf75f2110000 pid=4594 execve guuid=0c2a60ae-1a00-0000-8f1a-bf75f3110000 pid=4595 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=0c2a60ae-1a00-0000-8f1a-bf75f3110000 pid=4595 execve guuid=43d0aeae-1a00-0000-8f1a-bf75f7110000 pid=4599 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=43d0aeae-1a00-0000-8f1a-bf75f7110000 pid=4599 execve guuid=aff00aaf-1a00-0000-8f1a-bf75fb110000 pid=4603 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=aff00aaf-1a00-0000-8f1a-bf75fb110000 pid=4603 execve guuid=682f68af-1a00-0000-8f1a-bf75fc110000 pid=4604 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=682f68af-1a00-0000-8f1a-bf75fc110000 pid=4604 execve guuid=ce02b6af-1a00-0000-8f1a-bf75fe110000 pid=4606 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=ce02b6af-1a00-0000-8f1a-bf75fe110000 pid=4606 execve guuid=9334ffaf-1a00-0000-8f1a-bf7500120000 pid=4608 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9334ffaf-1a00-0000-8f1a-bf7500120000 pid=4608 execve guuid=7f084fb0-1a00-0000-8f1a-bf7504120000 pid=4612 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=7f084fb0-1a00-0000-8f1a-bf7504120000 pid=4612 execve guuid=d21797b0-1a00-0000-8f1a-bf7505120000 pid=4613 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=d21797b0-1a00-0000-8f1a-bf7505120000 pid=4613 execve guuid=99e8e3b0-1a00-0000-8f1a-bf7509120000 pid=4617 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=99e8e3b0-1a00-0000-8f1a-bf7509120000 pid=4617 execve guuid=9fe22bb1-1a00-0000-8f1a-bf750b120000 pid=4619 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=9fe22bb1-1a00-0000-8f1a-bf750b120000 pid=4619 execve guuid=d1558ab1-1a00-0000-8f1a-bf750d120000 pid=4621 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=d1558ab1-1a00-0000-8f1a-bf750d120000 pid=4621 execve guuid=4083efb1-1a00-0000-8f1a-bf7511120000 pid=4625 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=4083efb1-1a00-0000-8f1a-bf7511120000 pid=4625 execve guuid=fa2152b2-1a00-0000-8f1a-bf7513120000 pid=4627 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=fa2152b2-1a00-0000-8f1a-bf7513120000 pid=4627 execve guuid=8eb3b1b2-1a00-0000-8f1a-bf7516120000 pid=4630 /usr/bin/rm delete-file guuid=c2d82917-1800-0000-8f1a-bf75ed0b0000 pid=3053->guuid=8eb3b1b2-1a00-0000-8f1a-bf7516120000 pid=4630 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=4901e717-1800-0000-8f1a-bf75f10b0000 pid=3057->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=149bf642-1800-0000-8f1a-bf75640c0000 pid=3172->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=676e576d-1800-0000-8f1a-bf75950c0000 pid=3221->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258 /tmp/PUWA net send-data write-file zombie guuid=08618794-1800-0000-8f1a-bf75b90c0000 pid=3257->guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=b1f324a2-1800-0000-8f1a-bf75c00c0000 pid=3264 /usr/bin/uname guuid=1292b094-1800-0000-8f1a-bf75ba0c0000 pid=3258->guuid=b1f324a2-1800-0000-8f1a-bf75c00c0000 pid=3264 execve guuid=025fcb95-1800-0000-8f1a-bf75bd0c0000 pid=3261->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=bdacf9be-1800-0000-8f1a-bf75f70c0000 pid=3319->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=2444d2e6-1800-0000-8f1a-bf752b0d0000 pid=3371 /tmp/ULBG zombie guuid=b90dc2e6-1800-0000-8f1a-bf752a0d0000 pid=3370->guuid=2444d2e6-1800-0000-8f1a-bf752b0d0000 pid=3371 clone guuid=3cfe26e7-1800-0000-8f1a-bf752e0d0000 pid=3374->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ab3d9b0f-1900-0000-8f1a-bf75900d0000 pid=3472->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=19e5e839-1900-0000-8f1a-bf75c70d0000 pid=3527->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=4bbc8b62-1900-0000-8f1a-bf75ed0d0000 pid=3565->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=e1acba83-1900-0000-8f1a-bf75470e0000 pid=3655->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ba285dac-1900-0000-8f1a-bf759b0e0000 pid=3739->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=5f9826dd-1900-0000-8f1a-bf75440f0000 pid=3908->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=b883c704-1a00-0000-8f1a-bf75c30f0000 pid=4035->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8a81d02d-1a00-0000-8f1a-bf754f100000 pid=4175->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=08f1f457-1a00-0000-8f1a-bf75d8100000 pid=4312->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=0f1ba882-1a00-0000-8f1a-bf756a110000 pid=4458->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-10 21:32:42 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 263a01a4757a908020ca1a8c639b72db94bfe19ec174d2d5495c80fb007f65c6

(this sample)

  
Delivery method
Distributed via web download

Comments