MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 34d2e47fa8f6b64e346623b4ed66898b86d53891900b953e69f02e2b3ffb2cc9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments 1

SHA256 hash: 34d2e47fa8f6b64e346623b4ed66898b86d53891900b953e69f02e2b3ffb2cc9
SHA3-384 hash: 5a0eec3b7b98f3ae827212b8a43d12dd1d66358dd2b88afa2cd60e805c69f3b22211ad8582ba15526cdeeb856899a353
SHA1 hash: 62787eb954262bd7cd8ae01df8c95de54eb51671
MD5 hash: 122b1825c4c0ceb3537a0986300c1019
humanhash: tennessee-four-skylark-rugby
File name:dropper_34d2e47f.sh
Download: download sample
File size:2'110 bytes
First seen:2026-06-24 19:34:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:jx/1aMvM5MCYhuIhLxMlvheNbt0f/NQ6SCLIeB:jx/1aMvM5MCKuIhLxMl5Obt0f/NQ6lk+
TLSH T17B415EF1E8B49833B86FCA18F11CD0A45EF76E3F156B3588B472996D6D1E408271D722
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter nullblue67
Tags:bash botnet ddos dropper sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
64
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-23T08:17:00Z UTC
Last seen:
2026-06-24T23:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen
Status:
terminated
Behavior Graph:
%3 guuid=02997003-1f00-0000-c03a-08bf5e140000 pid=5214 /usr/bin/sudo guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215 /tmp/sample.bin guuid=02997003-1f00-0000-c03a-08bf5e140000 pid=5214->guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215 execve guuid=6124d105-1f00-0000-c03a-08bf60140000 pid=5216 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=6124d105-1f00-0000-c03a-08bf60140000 pid=5216 execve guuid=6516e80a-1f00-0000-c03a-08bf61140000 pid=5217 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=6516e80a-1f00-0000-c03a-08bf61140000 pid=5217 execve guuid=d16f3c0b-1f00-0000-c03a-08bf62140000 pid=5218 /tmp/client_x86_64 guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=d16f3c0b-1f00-0000-c03a-08bf62140000 pid=5218 execve guuid=dbbe480b-1f00-0000-c03a-08bf63140000 pid=5219 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=dbbe480b-1f00-0000-c03a-08bf63140000 pid=5219 execve guuid=f729bb0f-1f00-0000-c03a-08bf6c140000 pid=5228 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=f729bb0f-1f00-0000-c03a-08bf6c140000 pid=5228 execve guuid=29bf1410-1f00-0000-c03a-08bf6d140000 pid=5229 /tmp/client_i686 guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=29bf1410-1f00-0000-c03a-08bf6d140000 pid=5229 execve guuid=d4bb1e10-1f00-0000-c03a-08bf6e140000 pid=5230 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=d4bb1e10-1f00-0000-c03a-08bf6e140000 pid=5230 execve guuid=d511a614-1f00-0000-c03a-08bf77140000 pid=5239 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=d511a614-1f00-0000-c03a-08bf77140000 pid=5239 execve guuid=9eb51315-1f00-0000-c03a-08bf78140000 pid=5240 /tmp/client_i586 guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=9eb51315-1f00-0000-c03a-08bf78140000 pid=5240 execve guuid=91882215-1f00-0000-c03a-08bf79140000 pid=5241 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=91882215-1f00-0000-c03a-08bf79140000 pid=5241 execve guuid=534a971a-1f00-0000-c03a-08bf82140000 pid=5250 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=534a971a-1f00-0000-c03a-08bf82140000 pid=5250 execve guuid=d5e8d61a-1f00-0000-c03a-08bf83140000 pid=5251 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=d5e8d61a-1f00-0000-c03a-08bf83140000 pid=5251 clone guuid=0298df1a-1f00-0000-c03a-08bf84140000 pid=5252 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=0298df1a-1f00-0000-c03a-08bf84140000 pid=5252 execve guuid=2089a41f-1f00-0000-c03a-08bf86140000 pid=5254 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=2089a41f-1f00-0000-c03a-08bf86140000 pid=5254 execve guuid=7ddcf11f-1f00-0000-c03a-08bf87140000 pid=5255 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=7ddcf11f-1f00-0000-c03a-08bf87140000 pid=5255 clone guuid=a30fff1f-1f00-0000-c03a-08bf88140000 pid=5256 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=a30fff1f-1f00-0000-c03a-08bf88140000 pid=5256 execve guuid=2bb3b124-1f00-0000-c03a-08bf8a140000 pid=5258 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=2bb3b124-1f00-0000-c03a-08bf8a140000 pid=5258 execve guuid=f0050325-1f00-0000-c03a-08bf8b140000 pid=5259 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=f0050325-1f00-0000-c03a-08bf8b140000 pid=5259 clone guuid=19980e25-1f00-0000-c03a-08bf8c140000 pid=5260 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=19980e25-1f00-0000-c03a-08bf8c140000 pid=5260 execve guuid=8ffcf429-1f00-0000-c03a-08bf8e140000 pid=5262 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=8ffcf429-1f00-0000-c03a-08bf8e140000 pid=5262 execve guuid=9428492a-1f00-0000-c03a-08bf8f140000 pid=5263 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=9428492a-1f00-0000-c03a-08bf8f140000 pid=5263 clone guuid=3f2e582a-1f00-0000-c03a-08bf90140000 pid=5264 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=3f2e582a-1f00-0000-c03a-08bf90140000 pid=5264 execve guuid=c0e1512f-1f00-0000-c03a-08bf92140000 pid=5266 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=c0e1512f-1f00-0000-c03a-08bf92140000 pid=5266 execve guuid=8d80f12f-1f00-0000-c03a-08bf93140000 pid=5267 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=8d80f12f-1f00-0000-c03a-08bf93140000 pid=5267 clone guuid=621afd2f-1f00-0000-c03a-08bf94140000 pid=5268 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=621afd2f-1f00-0000-c03a-08bf94140000 pid=5268 execve guuid=457e6635-1f00-0000-c03a-08bf96140000 pid=5270 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=457e6635-1f00-0000-c03a-08bf96140000 pid=5270 execve guuid=ea29ec35-1f00-0000-c03a-08bf97140000 pid=5271 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=ea29ec35-1f00-0000-c03a-08bf97140000 pid=5271 clone guuid=60a3f835-1f00-0000-c03a-08bf98140000 pid=5272 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=60a3f835-1f00-0000-c03a-08bf98140000 pid=5272 execve guuid=98d9343b-1f00-0000-c03a-08bf9a140000 pid=5274 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=98d9343b-1f00-0000-c03a-08bf9a140000 pid=5274 execve guuid=b573ae3b-1f00-0000-c03a-08bf9b140000 pid=5275 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=b573ae3b-1f00-0000-c03a-08bf9b140000 pid=5275 clone guuid=1d9cb53b-1f00-0000-c03a-08bf9c140000 pid=5276 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=1d9cb53b-1f00-0000-c03a-08bf9c140000 pid=5276 execve guuid=70e01141-1f00-0000-c03a-08bf9e140000 pid=5278 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=70e01141-1f00-0000-c03a-08bf9e140000 pid=5278 execve guuid=50517041-1f00-0000-c03a-08bf9f140000 pid=5279 /usr/bin/bash guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=50517041-1f00-0000-c03a-08bf9f140000 pid=5279 clone guuid=316f7b41-1f00-0000-c03a-08bfa0140000 pid=5280 /usr/bin/wget net send-data write-file guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=316f7b41-1f00-0000-c03a-08bfa0140000 pid=5280 execve guuid=93911147-1f00-0000-c03a-08bfa2140000 pid=5282 /usr/bin/chmod guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=93911147-1f00-0000-c03a-08bfa2140000 pid=5282 execve guuid=56165c47-1f00-0000-c03a-08bfa3140000 pid=5283 /usr/bin/bash zombie guuid=ee046b05-1f00-0000-c03a-08bf5f140000 pid=5215->guuid=56165c47-1f00-0000-c03a-08bfa3140000 pid=5283 clone 18923433-5a00-5e7a-bb73-68afbe950382 144.31.151.138:5000 guuid=6124d105-1f00-0000-c03a-08bf60140000 pid=5216->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=02b0510b-1f00-0000-c03a-08bf64140000 pid=5220 /tmp/client_x86_64 zombie guuid=d16f3c0b-1f00-0000-c03a-08bf62140000 pid=5218->guuid=02b0510b-1f00-0000-c03a-08bf64140000 pid=5220 clone guuid=dbbe480b-1f00-0000-c03a-08bf63140000 pid=5219->18923433-5a00-5e7a-bb73-68afbe950382 send: 158B guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221 /tmp/client_x86_64 net send-data zombie guuid=02b0510b-1f00-0000-c03a-08bf64140000 pid=5220->guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221 clone f3fadc59-7044-50e6-a59d-bc2ea6300c15 104.26.10.85:80 guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221->f3fadc59-7044-50e6-a59d-bc2ea6300c15 send: 94B baa223f2-87c6-545c-8b23-055da8a594b2 144.31.151.138:7777 guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221->baa223f2-87c6-545c-8b23-055da8a594b2 send: 277B guuid=cd6bf70d-1f00-0000-c03a-08bf66140000 pid=5222 /tmp/client_x86_64 write-file guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221->guuid=cd6bf70d-1f00-0000-c03a-08bf66140000 pid=5222 clone guuid=6d49fc0d-1f00-0000-c03a-08bf67140000 pid=5223 /tmp/client_x86_64 guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221->guuid=6d49fc0d-1f00-0000-c03a-08bf67140000 pid=5223 clone guuid=01010e0e-1f00-0000-c03a-08bf68140000 pid=5224 /usr/bin/dash guuid=eec3590b-1f00-0000-c03a-08bf65140000 pid=5221->guuid=01010e0e-1f00-0000-c03a-08bf68140000 pid=5224 execve guuid=b16f1462-2100-0000-c03a-08bfa9140000 pid=5289 /tmp/client_x86_64 zombie guuid=6d49fc0d-1f00-0000-c03a-08bf67140000 pid=5223->guuid=b16f1462-2100-0000-c03a-08bfa9140000 pid=5289 clone guuid=fb515f0e-1f00-0000-c03a-08bf69140000 pid=5225 /usr/bin/df guuid=01010e0e-1f00-0000-c03a-08bf68140000 pid=5224->guuid=fb515f0e-1f00-0000-c03a-08bf69140000 pid=5225 execve guuid=f153670e-1f00-0000-c03a-08bf6a140000 pid=5226 /usr/bin/tail guuid=01010e0e-1f00-0000-c03a-08bf68140000 pid=5224->guuid=f153670e-1f00-0000-c03a-08bf6a140000 pid=5226 execve guuid=7bd66e0e-1f00-0000-c03a-08bf6b140000 pid=5227 /usr/bin/mawk guuid=01010e0e-1f00-0000-c03a-08bf68140000 pid=5224->guuid=7bd66e0e-1f00-0000-c03a-08bf6b140000 pid=5227 execve guuid=e5c03410-1f00-0000-c03a-08bf6f140000 pid=5231 /tmp/client_i686 guuid=29bf1410-1f00-0000-c03a-08bf6d140000 pid=5229->guuid=e5c03410-1f00-0000-c03a-08bf6f140000 pid=5231 clone guuid=d4bb1e10-1f00-0000-c03a-08bf6e140000 pid=5230->18923433-5a00-5e7a-bb73-68afbe950382 send: 158B guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232 /tmp/client_i686 net send-data zombie guuid=e5c03410-1f00-0000-c03a-08bf6f140000 pid=5231->guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232 clone guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232->f3fadc59-7044-50e6-a59d-bc2ea6300c15 send: 94B guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232->baa223f2-87c6-545c-8b23-055da8a594b2 send: 274B guuid=dbd7ce12-1f00-0000-c03a-08bf71140000 pid=5233 /tmp/client_i686 write-file guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232->guuid=dbd7ce12-1f00-0000-c03a-08bf71140000 pid=5233 clone guuid=29a6d312-1f00-0000-c03a-08bf72140000 pid=5234 /tmp/client_i686 guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232->guuid=29a6d312-1f00-0000-c03a-08bf72140000 pid=5234 clone guuid=e3f54b13-1f00-0000-c03a-08bf73140000 pid=5235 /usr/bin/dash guuid=ca6c4110-1f00-0000-c03a-08bf70140000 pid=5232->guuid=e3f54b13-1f00-0000-c03a-08bf73140000 pid=5235 execve guuid=3e3a0167-2100-0000-c03a-08bfaa140000 pid=5290 /tmp/client_i686 guuid=29a6d312-1f00-0000-c03a-08bf72140000 pid=5234->guuid=3e3a0167-2100-0000-c03a-08bfaa140000 pid=5290 clone guuid=abbea213-1f00-0000-c03a-08bf74140000 pid=5236 /usr/bin/df guuid=e3f54b13-1f00-0000-c03a-08bf73140000 pid=5235->guuid=abbea213-1f00-0000-c03a-08bf74140000 pid=5236 execve guuid=95deaa13-1f00-0000-c03a-08bf75140000 pid=5237 /usr/bin/tail guuid=e3f54b13-1f00-0000-c03a-08bf73140000 pid=5235->guuid=95deaa13-1f00-0000-c03a-08bf75140000 pid=5237 execve guuid=b5eab013-1f00-0000-c03a-08bf76140000 pid=5238 /usr/bin/mawk guuid=e3f54b13-1f00-0000-c03a-08bf73140000 pid=5235->guuid=b5eab013-1f00-0000-c03a-08bf76140000 pid=5238 execve guuid=d0bb4915-1f00-0000-c03a-08bf7a140000 pid=5242 /tmp/client_i586 guuid=9eb51315-1f00-0000-c03a-08bf78140000 pid=5240->guuid=d0bb4915-1f00-0000-c03a-08bf7a140000 pid=5242 clone guuid=91882215-1f00-0000-c03a-08bf79140000 pid=5241->18923433-5a00-5e7a-bb73-68afbe950382 send: 158B guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243 /tmp/client_i586 net send-data zombie guuid=d0bb4915-1f00-0000-c03a-08bf7a140000 pid=5242->guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243 clone guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->f3fadc59-7044-50e6-a59d-bc2ea6300c15 send: 94B guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->baa223f2-87c6-545c-8b23-055da8a594b2 send: 3288B guuid=88b52d19-1f00-0000-c03a-08bf7c140000 pid=5244 /tmp/client_i586 write-file guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=88b52d19-1f00-0000-c03a-08bf7c140000 pid=5244 clone guuid=1f2d3419-1f00-0000-c03a-08bf7d140000 pid=5245 /tmp/client_i586 guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=1f2d3419-1f00-0000-c03a-08bf7d140000 pid=5245 clone guuid=98df5d19-1f00-0000-c03a-08bf7e140000 pid=5246 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=98df5d19-1f00-0000-c03a-08bf7e140000 pid=5246 execve guuid=80245245-2000-0000-c03a-08bfa5140000 pid=5285 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=80245245-2000-0000-c03a-08bfa5140000 pid=5285 execve guuid=16100a71-2100-0000-c03a-08bfac140000 pid=5292 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=16100a71-2100-0000-c03a-08bfac140000 pid=5292 execve guuid=ced4db9c-2200-0000-c03a-08bfb0140000 pid=5296 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=ced4db9c-2200-0000-c03a-08bfb0140000 pid=5296 execve guuid=9d41ecc8-2300-0000-c03a-08bfb7140000 pid=5303 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=9d41ecc8-2300-0000-c03a-08bfb7140000 pid=5303 execve guuid=8ebec1f4-2400-0000-c03a-08bfbb140000 pid=5307 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=8ebec1f4-2400-0000-c03a-08bfbb140000 pid=5307 execve guuid=cbce0421-2600-0000-c03a-08bfbf140000 pid=5311 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=cbce0421-2600-0000-c03a-08bfbf140000 pid=5311 execve guuid=adc82a4d-2700-0000-c03a-08bfc3140000 pid=5315 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=adc82a4d-2700-0000-c03a-08bfc3140000 pid=5315 execve guuid=f988dd78-2800-0000-c03a-08bfc7140000 pid=5319 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=f988dd78-2800-0000-c03a-08bfc7140000 pid=5319 execve guuid=415c59e3-2900-0000-c03a-08bfcb140000 pid=5323 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=415c59e3-2900-0000-c03a-08bfcb140000 pid=5323 execve guuid=211f0a10-2b00-0000-c03a-08bfcf140000 pid=5327 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=211f0a10-2b00-0000-c03a-08bfcf140000 pid=5327 execve guuid=ebed903c-2c00-0000-c03a-08bfd3140000 pid=5331 /usr/bin/dash guuid=5eaf5515-1f00-0000-c03a-08bf7b140000 pid=5243->guuid=ebed903c-2c00-0000-c03a-08bfd3140000 pid=5331 execve guuid=2c5f586d-2100-0000-c03a-08bfab140000 pid=5291 /tmp/client_i586 guuid=1f2d3419-1f00-0000-c03a-08bf7d140000 pid=5245->guuid=2c5f586d-2100-0000-c03a-08bfab140000 pid=5291 clone guuid=1c789d19-1f00-0000-c03a-08bf7f140000 pid=5247 /usr/bin/df guuid=98df5d19-1f00-0000-c03a-08bf7e140000 pid=5246->guuid=1c789d19-1f00-0000-c03a-08bf7f140000 pid=5247 execve guuid=62d4a619-1f00-0000-c03a-08bf80140000 pid=5248 /usr/bin/tail guuid=98df5d19-1f00-0000-c03a-08bf7e140000 pid=5246->guuid=62d4a619-1f00-0000-c03a-08bf80140000 pid=5248 execve guuid=aca6ab19-1f00-0000-c03a-08bf81140000 pid=5249 /usr/bin/mawk guuid=98df5d19-1f00-0000-c03a-08bf7e140000 pid=5246->guuid=aca6ab19-1f00-0000-c03a-08bf81140000 pid=5249 execve guuid=0298df1a-1f00-0000-c03a-08bf84140000 pid=5252->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=a30fff1f-1f00-0000-c03a-08bf88140000 pid=5256->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=19980e25-1f00-0000-c03a-08bf8c140000 pid=5260->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=3f2e582a-1f00-0000-c03a-08bf90140000 pid=5264->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=621afd2f-1f00-0000-c03a-08bf94140000 pid=5268->18923433-5a00-5e7a-bb73-68afbe950382 send: 160B guuid=60a3f835-1f00-0000-c03a-08bf98140000 pid=5272->18923433-5a00-5e7a-bb73-68afbe950382 send: 161B guuid=1d9cb53b-1f00-0000-c03a-08bf9c140000 pid=5276->18923433-5a00-5e7a-bb73-68afbe950382 send: 158B guuid=316f7b41-1f00-0000-c03a-08bfa0140000 pid=5280->18923433-5a00-5e7a-bb73-68afbe950382 send: 157B guuid=490c8c45-2000-0000-c03a-08bfa6140000 pid=5286 /usr/bin/df guuid=80245245-2000-0000-c03a-08bfa5140000 pid=5285->guuid=490c8c45-2000-0000-c03a-08bfa6140000 pid=5286 execve guuid=1c509245-2000-0000-c03a-08bfa7140000 pid=5287 /usr/bin/tail guuid=80245245-2000-0000-c03a-08bfa5140000 pid=5285->guuid=1c509245-2000-0000-c03a-08bfa7140000 pid=5287 execve guuid=fc8f9945-2000-0000-c03a-08bfa8140000 pid=5288 /usr/bin/mawk guuid=80245245-2000-0000-c03a-08bfa5140000 pid=5285->guuid=fc8f9945-2000-0000-c03a-08bfa8140000 pid=5288 execve guuid=b96a32b6-2300-0000-c03a-08bfb4140000 pid=5300 /tmp/client_x86_64 zombie guuid=b16f1462-2100-0000-c03a-08bfa9140000 pid=5289->guuid=b96a32b6-2300-0000-c03a-08bfb4140000 pid=5300 clone guuid=c66246bb-2300-0000-c03a-08bfb5140000 pid=5301 /tmp/client_i686 zombie guuid=3e3a0167-2100-0000-c03a-08bfaa140000 pid=5290->guuid=c66246bb-2300-0000-c03a-08bfb5140000 pid=5301 clone guuid=e36479c1-2300-0000-c03a-08bfb6140000 pid=5302 /tmp/client_i586 zombie guuid=2c5f586d-2100-0000-c03a-08bfab140000 pid=5291->guuid=e36479c1-2300-0000-c03a-08bfb6140000 pid=5302 clone guuid=15094071-2100-0000-c03a-08bfad140000 pid=5293 /usr/bin/df guuid=16100a71-2100-0000-c03a-08bfac140000 pid=5292->guuid=15094071-2100-0000-c03a-08bfad140000 pid=5293 execve guuid=2e034671-2100-0000-c03a-08bfae140000 pid=5294 /usr/bin/tail guuid=16100a71-2100-0000-c03a-08bfac140000 pid=5292->guuid=2e034671-2100-0000-c03a-08bfae140000 pid=5294 execve guuid=8a984d71-2100-0000-c03a-08bfaf140000 pid=5295 /usr/bin/mawk guuid=16100a71-2100-0000-c03a-08bfac140000 pid=5292->guuid=8a984d71-2100-0000-c03a-08bfaf140000 pid=5295 execve guuid=35ba399d-2200-0000-c03a-08bfb1140000 pid=5297 /usr/bin/df guuid=ced4db9c-2200-0000-c03a-08bfb0140000 pid=5296->guuid=35ba399d-2200-0000-c03a-08bfb1140000 pid=5297 execve guuid=81fa439d-2200-0000-c03a-08bfb2140000 pid=5298 /usr/bin/tail guuid=ced4db9c-2200-0000-c03a-08bfb0140000 pid=5296->guuid=81fa439d-2200-0000-c03a-08bfb2140000 pid=5298 execve guuid=1c4d559d-2200-0000-c03a-08bfb3140000 pid=5299 /usr/bin/mawk guuid=ced4db9c-2200-0000-c03a-08bfb0140000 pid=5296->guuid=1c4d559d-2200-0000-c03a-08bfb3140000 pid=5299 execve guuid=2a041ec9-2300-0000-c03a-08bfb8140000 pid=5304 /usr/bin/df guuid=9d41ecc8-2300-0000-c03a-08bfb7140000 pid=5303->guuid=2a041ec9-2300-0000-c03a-08bfb8140000 pid=5304 execve guuid=951224c9-2300-0000-c03a-08bfb9140000 pid=5305 /usr/bin/tail guuid=9d41ecc8-2300-0000-c03a-08bfb7140000 pid=5303->guuid=951224c9-2300-0000-c03a-08bfb9140000 pid=5305 execve guuid=f7d629c9-2300-0000-c03a-08bfba140000 pid=5306 /usr/bin/mawk guuid=9d41ecc8-2300-0000-c03a-08bfb7140000 pid=5303->guuid=f7d629c9-2300-0000-c03a-08bfba140000 pid=5306 execve guuid=c53925f5-2400-0000-c03a-08bfbc140000 pid=5308 /usr/bin/df guuid=8ebec1f4-2400-0000-c03a-08bfbb140000 pid=5307->guuid=c53925f5-2400-0000-c03a-08bfbc140000 pid=5308 execve guuid=e39534f5-2400-0000-c03a-08bfbd140000 pid=5309 /usr/bin/tail guuid=8ebec1f4-2400-0000-c03a-08bfbb140000 pid=5307->guuid=e39534f5-2400-0000-c03a-08bfbd140000 pid=5309 execve guuid=b02340f5-2400-0000-c03a-08bfbe140000 pid=5310 /usr/bin/mawk guuid=8ebec1f4-2400-0000-c03a-08bfbb140000 pid=5307->guuid=b02340f5-2400-0000-c03a-08bfbe140000 pid=5310 execve guuid=09c87221-2600-0000-c03a-08bfc0140000 pid=5312 /usr/bin/df guuid=cbce0421-2600-0000-c03a-08bfbf140000 pid=5311->guuid=09c87221-2600-0000-c03a-08bfc0140000 pid=5312 execve guuid=57937d21-2600-0000-c03a-08bfc1140000 pid=5313 /usr/bin/tail guuid=cbce0421-2600-0000-c03a-08bfbf140000 pid=5311->guuid=57937d21-2600-0000-c03a-08bfc1140000 pid=5313 execve guuid=1e758821-2600-0000-c03a-08bfc2140000 pid=5314 /usr/bin/mawk guuid=cbce0421-2600-0000-c03a-08bfbf140000 pid=5311->guuid=1e758821-2600-0000-c03a-08bfc2140000 pid=5314 execve guuid=b777624d-2700-0000-c03a-08bfc4140000 pid=5316 /usr/bin/df guuid=adc82a4d-2700-0000-c03a-08bfc3140000 pid=5315->guuid=b777624d-2700-0000-c03a-08bfc4140000 pid=5316 execve guuid=59f8694d-2700-0000-c03a-08bfc5140000 pid=5317 /usr/bin/tail guuid=adc82a4d-2700-0000-c03a-08bfc3140000 pid=5315->guuid=59f8694d-2700-0000-c03a-08bfc5140000 pid=5317 execve guuid=7bc0714d-2700-0000-c03a-08bfc6140000 pid=5318 /usr/bin/mawk guuid=adc82a4d-2700-0000-c03a-08bfc3140000 pid=5315->guuid=7bc0714d-2700-0000-c03a-08bfc6140000 pid=5318 execve guuid=da1c1479-2800-0000-c03a-08bfc8140000 pid=5320 /usr/bin/df guuid=f988dd78-2800-0000-c03a-08bfc7140000 pid=5319->guuid=da1c1479-2800-0000-c03a-08bfc8140000 pid=5320 execve guuid=1f681a79-2800-0000-c03a-08bfc9140000 pid=5321 /usr/bin/tail guuid=f988dd78-2800-0000-c03a-08bfc7140000 pid=5319->guuid=1f681a79-2800-0000-c03a-08bfc9140000 pid=5321 execve guuid=540e2079-2800-0000-c03a-08bfca140000 pid=5322 /usr/bin/mawk guuid=f988dd78-2800-0000-c03a-08bfc7140000 pid=5319->guuid=540e2079-2800-0000-c03a-08bfca140000 pid=5322 execve guuid=7158cae3-2900-0000-c03a-08bfcc140000 pid=5324 /usr/bin/df guuid=415c59e3-2900-0000-c03a-08bfcb140000 pid=5323->guuid=7158cae3-2900-0000-c03a-08bfcc140000 pid=5324 execve guuid=8c04dae3-2900-0000-c03a-08bfcd140000 pid=5325 /usr/bin/tail guuid=415c59e3-2900-0000-c03a-08bfcb140000 pid=5323->guuid=8c04dae3-2900-0000-c03a-08bfcd140000 pid=5325 execve guuid=5226e1e3-2900-0000-c03a-08bfce140000 pid=5326 /usr/bin/mawk guuid=415c59e3-2900-0000-c03a-08bfcb140000 pid=5323->guuid=5226e1e3-2900-0000-c03a-08bfce140000 pid=5326 execve guuid=6ce68510-2b00-0000-c03a-08bfd0140000 pid=5328 /usr/bin/df guuid=211f0a10-2b00-0000-c03a-08bfcf140000 pid=5327->guuid=6ce68510-2b00-0000-c03a-08bfd0140000 pid=5328 execve guuid=9fbc9310-2b00-0000-c03a-08bfd1140000 pid=5329 /usr/bin/tail guuid=211f0a10-2b00-0000-c03a-08bfcf140000 pid=5327->guuid=9fbc9310-2b00-0000-c03a-08bfd1140000 pid=5329 execve guuid=de60a010-2b00-0000-c03a-08bfd2140000 pid=5330 /usr/bin/mawk guuid=211f0a10-2b00-0000-c03a-08bfcf140000 pid=5327->guuid=de60a010-2b00-0000-c03a-08bfd2140000 pid=5330 execve guuid=dad60e3d-2c00-0000-c03a-08bfd4140000 pid=5332 /usr/bin/df guuid=ebed903c-2c00-0000-c03a-08bfd3140000 pid=5331->guuid=dad60e3d-2c00-0000-c03a-08bfd4140000 pid=5332 execve guuid=f3d3173d-2c00-0000-c03a-08bfd5140000 pid=5333 /usr/bin/tail guuid=ebed903c-2c00-0000-c03a-08bfd3140000 pid=5331->guuid=f3d3173d-2c00-0000-c03a-08bfd5140000 pid=5333 execve guuid=00062f3d-2c00-0000-c03a-08bfd6140000 pid=5334 /usr/bin/mawk guuid=ebed903c-2c00-0000-c03a-08bfd3140000 pid=5331->guuid=00062f3d-2c00-0000-c03a-08bfd6140000 pid=5334 execve
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux persistence
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads system network configuration
Enumerates active TCP sockets
Enumerates running processes
Write file to user bin folder
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments



Avatar
commented on 2026-06-24 19:38:07 UTC

🍯 Captured by NullBlue67 via Redis honeypot — 2026-06-24.

Bash dropper for a Go multi-vector DDoS botnet ("client" family).

Behavior:
• Downloads client_x86_64 / client_i686 / client_i586 from http://144.31.151.138:5000/payload/bins/ and executes each in background
• cd fallback chain /tmp → /var/run → /mnt → /root → /
• Delivered via Redis SET from 62.238.37.207

Companion ELF DDoS bot: sha256 404df61aa1d3bfcfc14288b9cc0131642cbafb31256f28c5fd7e5ef51bbe2d69

#dropper #bash #ddos #botnet #redis #linux