MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 2f0d467950e0d37e9f26aa75e039c2ddf967d5ce89867dc96cc0fc51793ea332. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 2f0d467950e0d37e9f26aa75e039c2ddf967d5ce89867dc96cc0fc51793ea332
SHA3-384 hash: b683f13e9d7f41b72c034ad49b1e048dbed4e9affee279dcdab7abc190c6082549e6eac3732d29d0714a1a663f69f16e
SHA1 hash: f2666c10833916a989d8483ee10130569a65178e
MD5 hash: 1545e05d20a0e3d37bc1d256b0c96a09
humanhash: ack-nuts-emma-sweet
File name:2f0d467950e0d37e9f26aa75e039c2ddf967d5ce89867dc96cc0fc51793ea332
Download: download sample
File size:387'276 bytes
First seen:2026-05-15 06:49:10 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 3072:+HqqZt78mOq9UZiuTq69Hf5cgpJBPPgMJgZt9aVpNpOAaP+/u6b8iDahTwoBMy:+HqqD8iQTt5PgMSM3NpOAam/ah9
TLSH T1B984950BA941D4220A96D13B5BB7F781EC15167BCEA1EEFDB24CB39D1F8A220D0641F5
TrID 50.0% (.) Unix-like shebang (var.1) (gen) (7000/1)
28.5% (.PL) Perl script (4000/1/1)
21.4% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter Hassan_Pouladi

Intelligence


File Origin
# of uploads :
1
# of downloads :
36
Origin country :
CA CA
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=e38952d7-1900-0000-0102-21331b0a0000 pid=2587 /usr/bin/sudo guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594 /usr/bin/bash write-file guuid=e38952d7-1900-0000-0102-21331b0a0000 pid=2587->guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594 execve guuid=86d00be4-1900-0000-0102-21333e0a0000 pid=2622 /usr/bin/uname guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=86d00be4-1900-0000-0102-21333e0a0000 pid=2622 execve guuid=8ffa64e5-1900-0000-0102-2133420a0000 pid=2626 /usr/bin/mkdir guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=8ffa64e5-1900-0000-0102-2133420a0000 pid=2626 execve guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628 /usr/bin/lsb_release guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628 execve guuid=7f6bc0e9-1900-0000-0102-21335c0a0000 pid=2652 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=7f6bc0e9-1900-0000-0102-21335c0a0000 pid=2652 clone guuid=5ab3e8e9-1900-0000-0102-21335e0a0000 pid=2654 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=5ab3e8e9-1900-0000-0102-21335e0a0000 pid=2654 clone guuid=66612aea-1900-0000-0102-2133600a0000 pid=2656 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=66612aea-1900-0000-0102-2133600a0000 pid=2656 clone guuid=2d585cea-1900-0000-0102-2133610a0000 pid=2657 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=2d585cea-1900-0000-0102-2133610a0000 pid=2657 clone guuid=746179ea-1900-0000-0102-2133630a0000 pid=2659 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=746179ea-1900-0000-0102-2133630a0000 pid=2659 clone guuid=c8f4a4ea-1900-0000-0102-2133640a0000 pid=2660 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=c8f4a4ea-1900-0000-0102-2133640a0000 pid=2660 clone guuid=e41fd3ea-1900-0000-0102-2133660a0000 pid=2662 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=e41fd3ea-1900-0000-0102-2133660a0000 pid=2662 clone guuid=dbf5fdea-1900-0000-0102-2133670a0000 pid=2663 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=dbf5fdea-1900-0000-0102-2133670a0000 pid=2663 clone guuid=a7124beb-1900-0000-0102-2133690a0000 pid=2665 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a7124beb-1900-0000-0102-2133690a0000 pid=2665 clone guuid=c6c274eb-1900-0000-0102-21336a0a0000 pid=2666 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=c6c274eb-1900-0000-0102-21336a0a0000 pid=2666 clone guuid=e25696eb-1900-0000-0102-21336b0a0000 pid=2667 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=e25696eb-1900-0000-0102-21336b0a0000 pid=2667 clone guuid=574bb4eb-1900-0000-0102-21336d0a0000 pid=2669 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=574bb4eb-1900-0000-0102-21336d0a0000 pid=2669 clone guuid=63c0d0eb-1900-0000-0102-21336e0a0000 pid=2670 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=63c0d0eb-1900-0000-0102-21336e0a0000 pid=2670 clone guuid=359befeb-1900-0000-0102-21336f0a0000 pid=2671 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=359befeb-1900-0000-0102-21336f0a0000 pid=2671 clone guuid=9c2243ec-1900-0000-0102-2133710a0000 pid=2673 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=9c2243ec-1900-0000-0102-2133710a0000 pid=2673 clone guuid=6d5d07ed-1900-0000-0102-2133740a0000 pid=2676 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=6d5d07ed-1900-0000-0102-2133740a0000 pid=2676 clone guuid=b34c36ed-1900-0000-0102-2133760a0000 pid=2678 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=b34c36ed-1900-0000-0102-2133760a0000 pid=2678 clone guuid=d05da9ed-1900-0000-0102-2133770a0000 pid=2679 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=d05da9ed-1900-0000-0102-2133770a0000 pid=2679 clone guuid=cd455eee-1900-0000-0102-21337a0a0000 pid=2682 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=cd455eee-1900-0000-0102-21337a0a0000 pid=2682 clone guuid=46f099ee-1900-0000-0102-21337c0a0000 pid=2684 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=46f099ee-1900-0000-0102-21337c0a0000 pid=2684 clone guuid=0675c3ee-1900-0000-0102-21337e0a0000 pid=2686 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=0675c3ee-1900-0000-0102-21337e0a0000 pid=2686 clone guuid=1877e7ee-1900-0000-0102-21337f0a0000 pid=2687 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=1877e7ee-1900-0000-0102-21337f0a0000 pid=2687 clone guuid=14ee4aef-1900-0000-0102-2133820a0000 pid=2690 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=14ee4aef-1900-0000-0102-2133820a0000 pid=2690 clone guuid=848b9def-1900-0000-0102-2133840a0000 pid=2692 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=848b9def-1900-0000-0102-2133840a0000 pid=2692 clone guuid=a721d3ef-1900-0000-0102-2133850a0000 pid=2693 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a721d3ef-1900-0000-0102-2133850a0000 pid=2693 clone guuid=d5be01f0-1900-0000-0102-2133870a0000 pid=2695 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=d5be01f0-1900-0000-0102-2133870a0000 pid=2695 clone guuid=3fd528f0-1900-0000-0102-2133880a0000 pid=2696 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=3fd528f0-1900-0000-0102-2133880a0000 pid=2696 clone guuid=243775f0-1900-0000-0102-21338a0a0000 pid=2698 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=243775f0-1900-0000-0102-21338a0a0000 pid=2698 clone guuid=f70826f1-1900-0000-0102-21338c0a0000 pid=2700 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=f70826f1-1900-0000-0102-21338c0a0000 pid=2700 clone guuid=a3ea6df1-1900-0000-0102-21338e0a0000 pid=2702 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a3ea6df1-1900-0000-0102-21338e0a0000 pid=2702 clone guuid=558baef1-1900-0000-0102-2133900a0000 pid=2704 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=558baef1-1900-0000-0102-2133900a0000 pid=2704 clone guuid=64d70cf2-1900-0000-0102-2133920a0000 pid=2706 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=64d70cf2-1900-0000-0102-2133920a0000 pid=2706 clone guuid=62403af2-1900-0000-0102-2133930a0000 pid=2707 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=62403af2-1900-0000-0102-2133930a0000 pid=2707 clone guuid=9d3a6af2-1900-0000-0102-2133950a0000 pid=2709 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=9d3a6af2-1900-0000-0102-2133950a0000 pid=2709 clone guuid=231326f3-1900-0000-0102-2133980a0000 pid=2712 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=231326f3-1900-0000-0102-2133980a0000 pid=2712 clone guuid=f93199f3-1900-0000-0102-21339a0a0000 pid=2714 /usr/bin/dpkg-query guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=f93199f3-1900-0000-0102-21339a0a0000 pid=2714 execve guuid=45853af9-1900-0000-0102-2133a70a0000 pid=2727 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=45853af9-1900-0000-0102-2133a70a0000 pid=2727 clone guuid=dc2a6ef9-1900-0000-0102-2133a90a0000 pid=2729 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=dc2a6ef9-1900-0000-0102-2133a90a0000 pid=2729 clone guuid=a2f79ff9-1900-0000-0102-2133ab0a0000 pid=2731 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a2f79ff9-1900-0000-0102-2133ab0a0000 pid=2731 clone guuid=22a0d2f9-1900-0000-0102-2133ac0a0000 pid=2732 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=22a0d2f9-1900-0000-0102-2133ac0a0000 pid=2732 clone guuid=f8591cfa-1900-0000-0102-2133ae0a0000 pid=2734 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=f8591cfa-1900-0000-0102-2133ae0a0000 pid=2734 clone guuid=c51e5ffa-1900-0000-0102-2133b00a0000 pid=2736 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=c51e5ffa-1900-0000-0102-2133b00a0000 pid=2736 clone guuid=16198ffa-1900-0000-0102-2133b20a0000 pid=2738 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=16198ffa-1900-0000-0102-2133b20a0000 pid=2738 clone guuid=5ac039fb-1900-0000-0102-2133b40a0000 pid=2740 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=5ac039fb-1900-0000-0102-2133b40a0000 pid=2740 clone guuid=a71084fb-1900-0000-0102-2133b60a0000 pid=2742 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a71084fb-1900-0000-0102-2133b60a0000 pid=2742 clone guuid=3467bafb-1900-0000-0102-2133b80a0000 pid=2744 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=3467bafb-1900-0000-0102-2133b80a0000 pid=2744 clone guuid=c6e3effb-1900-0000-0102-2133b90a0000 pid=2745 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=c6e3effb-1900-0000-0102-2133b90a0000 pid=2745 clone guuid=b1df22fc-1900-0000-0102-2133bb0a0000 pid=2747 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=b1df22fc-1900-0000-0102-2133bb0a0000 pid=2747 clone guuid=82d960fc-1900-0000-0102-2133bc0a0000 pid=2748 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=82d960fc-1900-0000-0102-2133bc0a0000 pid=2748 clone guuid=544d93fc-1900-0000-0102-2133be0a0000 pid=2750 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=544d93fc-1900-0000-0102-2133be0a0000 pid=2750 clone guuid=12ffc8fc-1900-0000-0102-2133bf0a0000 pid=2751 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=12ffc8fc-1900-0000-0102-2133bf0a0000 pid=2751 clone guuid=4a2502fd-1900-0000-0102-2133c10a0000 pid=2753 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=4a2502fd-1900-0000-0102-2133c10a0000 pid=2753 clone guuid=34f137fd-1900-0000-0102-2133c30a0000 pid=2755 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=34f137fd-1900-0000-0102-2133c30a0000 pid=2755 clone guuid=765110fe-1900-0000-0102-2133c60a0000 pid=2758 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=765110fe-1900-0000-0102-2133c60a0000 pid=2758 clone guuid=f28e4dfe-1900-0000-0102-2133c70a0000 pid=2759 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=f28e4dfe-1900-0000-0102-2133c70a0000 pid=2759 clone guuid=da2091fe-1900-0000-0102-2133c90a0000 pid=2761 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=da2091fe-1900-0000-0102-2133c90a0000 pid=2761 clone guuid=e2b9d3fe-1900-0000-0102-2133cb0a0000 pid=2763 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=e2b9d3fe-1900-0000-0102-2133cb0a0000 pid=2763 clone guuid=3e2a0fff-1900-0000-0102-2133cd0a0000 pid=2765 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=3e2a0fff-1900-0000-0102-2133cd0a0000 pid=2765 clone guuid=b19f1401-1a00-0000-0102-2133d40a0000 pid=2772 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=b19f1401-1a00-0000-0102-2133d40a0000 pid=2772 clone guuid=c5b44f01-1a00-0000-0102-2133d50a0000 pid=2773 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=c5b44f01-1a00-0000-0102-2133d50a0000 pid=2773 clone guuid=bcee8001-1a00-0000-0102-2133d70a0000 pid=2775 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=bcee8001-1a00-0000-0102-2133d70a0000 pid=2775 clone guuid=da7eb101-1a00-0000-0102-2133d80a0000 pid=2776 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=da7eb101-1a00-0000-0102-2133d80a0000 pid=2776 clone guuid=a0b0de01-1a00-0000-0102-2133da0a0000 pid=2778 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a0b0de01-1a00-0000-0102-2133da0a0000 pid=2778 clone guuid=57be1302-1a00-0000-0102-2133db0a0000 pid=2779 /usr/bin/mawk guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=57be1302-1a00-0000-0102-2133db0a0000 pid=2779 execve guuid=d79f8502-1a00-0000-0102-2133dd0a0000 pid=2781 /usr/bin/mawk guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=d79f8502-1a00-0000-0102-2133dd0a0000 pid=2781 execve guuid=37bbfc02-1a00-0000-0102-2133e00a0000 pid=2784 /usr/bin/grep guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=37bbfc02-1a00-0000-0102-2133e00a0000 pid=2784 execve guuid=e54b8103-1a00-0000-0102-2133e20a0000 pid=2786 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=e54b8103-1a00-0000-0102-2133e20a0000 pid=2786 clone guuid=96d7c503-1a00-0000-0102-2133e40a0000 pid=2788 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=96d7c503-1a00-0000-0102-2133e40a0000 pid=2788 clone guuid=9032f903-1a00-0000-0102-2133e60a0000 pid=2790 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=9032f903-1a00-0000-0102-2133e60a0000 pid=2790 clone guuid=ab0d3704-1a00-0000-0102-2133e70a0000 pid=2791 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=ab0d3704-1a00-0000-0102-2133e70a0000 pid=2791 clone guuid=23d18904-1a00-0000-0102-2133e90a0000 pid=2793 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=23d18904-1a00-0000-0102-2133e90a0000 pid=2793 clone guuid=5e1e8414-1a00-0000-0102-21330d0b0000 pid=2829 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=5e1e8414-1a00-0000-0102-21330d0b0000 pid=2829 clone guuid=731dd314-1a00-0000-0102-21330f0b0000 pid=2831 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=731dd314-1a00-0000-0102-21330f0b0000 pid=2831 clone guuid=ac260e15-1a00-0000-0102-2133100b0000 pid=2832 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=ac260e15-1a00-0000-0102-2133100b0000 pid=2832 clone guuid=a5574715-1a00-0000-0102-2133120b0000 pid=2834 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a5574715-1a00-0000-0102-2133120b0000 pid=2834 clone guuid=50d8f915-1a00-0000-0102-2133150b0000 pid=2837 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=50d8f915-1a00-0000-0102-2133150b0000 pid=2837 clone guuid=65d83116-1a00-0000-0102-2133160b0000 pid=2838 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=65d83116-1a00-0000-0102-2133160b0000 pid=2838 clone guuid=dd1d6816-1a00-0000-0102-2133180b0000 pid=2840 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=dd1d6816-1a00-0000-0102-2133180b0000 pid=2840 clone guuid=14cca416-1a00-0000-0102-2133190b0000 pid=2841 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=14cca416-1a00-0000-0102-2133190b0000 pid=2841 clone guuid=98720317-1a00-0000-0102-21331b0b0000 pid=2843 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=98720317-1a00-0000-0102-21331b0b0000 pid=2843 clone guuid=a9563517-1a00-0000-0102-21331d0b0000 pid=2845 /usr/bin/bash guuid=67b4f8d8-1900-0000-0102-2133220a0000 pid=2594->guuid=a9563517-1a00-0000-0102-21331d0b0000 pid=2845 clone guuid=8b2d7ee6-1900-0000-0102-2133470a0000 pid=2631 /usr/bin/getopt guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628->guuid=8b2d7ee6-1900-0000-0102-2133470a0000 pid=2631 execve guuid=7521ebe6-1900-0000-0102-2133490a0000 pid=2633 /usr/bin/dash guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628->guuid=7521ebe6-1900-0000-0102-2133490a0000 pid=2633 clone guuid=3cb92be8-1900-0000-0102-21334f0a0000 pid=2639 /usr/bin/dash guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628->guuid=3cb92be8-1900-0000-0102-21334f0a0000 pid=2639 clone guuid=8900b3e8-1900-0000-0102-2133530a0000 pid=2643 /usr/bin/dash guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628->guuid=8900b3e8-1900-0000-0102-2133530a0000 pid=2643 clone guuid=b63154e9-1900-0000-0102-2133580a0000 pid=2648 /usr/bin/dash guuid=fe6b0ee6-1900-0000-0102-2133440a0000 pid=2628->guuid=b63154e9-1900-0000-0102-2133580a0000 pid=2648 clone guuid=3a5815e7-1900-0000-0102-21334a0a0000 pid=2634 /usr/bin/dash guuid=7521ebe6-1900-0000-0102-2133490a0000 pid=2633->guuid=3a5815e7-1900-0000-0102-21334a0a0000 pid=2634 clone guuid=24693ae7-1900-0000-0102-21334b0a0000 pid=2635 /usr/bin/cut guuid=7521ebe6-1900-0000-0102-2133490a0000 pid=2633->guuid=24693ae7-1900-0000-0102-21334b0a0000 pid=2635 execve guuid=81444ee7-1900-0000-0102-21334c0a0000 pid=2636 /usr/bin/tr guuid=7521ebe6-1900-0000-0102-2133490a0000 pid=2633->guuid=81444ee7-1900-0000-0102-21334c0a0000 pid=2636 execve guuid=dfa536e8-1900-0000-0102-2133500a0000 pid=2640 /usr/bin/dash guuid=3cb92be8-1900-0000-0102-21334f0a0000 pid=2639->guuid=dfa536e8-1900-0000-0102-2133500a0000 pid=2640 clone guuid=075340e8-1900-0000-0102-2133510a0000 pid=2641 /usr/bin/cut guuid=3cb92be8-1900-0000-0102-21334f0a0000 pid=2639->guuid=075340e8-1900-0000-0102-2133510a0000 pid=2641 execve guuid=7616bfe8-1900-0000-0102-2133540a0000 pid=2644 /usr/bin/dash guuid=8900b3e8-1900-0000-0102-2133530a0000 pid=2643->guuid=7616bfe8-1900-0000-0102-2133540a0000 pid=2644 clone guuid=011cc6e8-1900-0000-0102-2133560a0000 pid=2646 /usr/bin/tr guuid=8900b3e8-1900-0000-0102-2133530a0000 pid=2643->guuid=011cc6e8-1900-0000-0102-2133560a0000 pid=2646 execve guuid=69855fe9-1900-0000-0102-2133590a0000 pid=2649 /usr/bin/dash guuid=b63154e9-1900-0000-0102-2133580a0000 pid=2648->guuid=69855fe9-1900-0000-0102-2133590a0000 pid=2649 clone guuid=81df65e9-1900-0000-0102-21335a0a0000 pid=2650 /usr/bin/tr guuid=b63154e9-1900-0000-0102-2133580a0000 pid=2648->guuid=81df65e9-1900-0000-0102-21335a0a0000 pid=2650 execve guuid=bd9426ff-1900-0000-0102-2133ce0a0000 pid=2766 /usr/bin/grep guuid=3e2a0fff-1900-0000-0102-2133cd0a0000 pid=2765->guuid=bd9426ff-1900-0000-0102-2133ce0a0000 pid=2766 execve guuid=6d99aa00-1a00-0000-0102-2133d20a0000 pid=2770 /usr/bin/bash guuid=3e2a0fff-1900-0000-0102-2133cd0a0000 pid=2765->guuid=6d99aa00-1a00-0000-0102-2133d20a0000 pid=2770 clone guuid=d271a404-1a00-0000-0102-2133eb0a0000 pid=2795 /usr/bin/lspci guuid=23d18904-1a00-0000-0102-2133e90a0000 pid=2793->guuid=d271a404-1a00-0000-0102-2133eb0a0000 pid=2795 execve guuid=89a9b004-1a00-0000-0102-2133ec0a0000 pid=2796 /usr/bin/mawk guuid=23d18904-1a00-0000-0102-2133e90a0000 pid=2793->guuid=89a9b004-1a00-0000-0102-2133ec0a0000 pid=2796 execve
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm discovery execution linux
Behaviour
Software Deployment Tools
Enumerates kernel/hardware configuration
Reads runtime system information
System Information Discovery
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Enumerates running processes
Reads hardware information
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments