MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 3de040df634251cd6244247d87d80ebeebf3018e220e6ee9618d070ca3eb3371. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 3de040df634251cd6244247d87d80ebeebf3018e220e6ee9618d070ca3eb3371
SHA3-384 hash: 6482466b752bc0bf341448483571f70080f6ec3eeb79f5ccdf8254a2f904292b95768707c1a7fcc06a05e6d76abd8eb9
SHA1 hash: ea7a1433c6930570d6c9ddd830ce2720775ebfb9
MD5 hash: 587d0ad299fbdd43ff8808080f41a73e
humanhash: zulu-mockingbird-eighteen-victor
File name:run.sh
Download: download sample
File size:748 bytes
First seen:2026-05-14 17:00:11 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:Izzfsx80+af5LeHt4LZ/uPfFFHsFQzBct7j3FAVkVFhx:o5TasHt4LUnF1GQzqt7phx
TLSH T15701999B61B0AC706875893CFD9746B01047181768451D19709F6E04FF2CA4CF6A1656
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
38
Origin country :
GB GB
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-14T14:11:00Z UTC
Last seen:
2026-05-15T01:07:00Z UTC
Hits:
~100
Status:
terminated
Behavior Graph:
%3 guuid=40adace6-1a00-0000-b32b-d90a09080000 pid=2057 /usr/bin/sudo guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062 /tmp/sample.bin guuid=40adace6-1a00-0000-b32b-d90a09080000 pid=2057->guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062 execve guuid=cc3c16e9-1a00-0000-b32b-d90a11080000 pid=2065 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=cc3c16e9-1a00-0000-b32b-d90a11080000 pid=2065 clone guuid=5b54d2ea-1a00-0000-b32b-d90a19080000 pid=2073 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=5b54d2ea-1a00-0000-b32b-d90a19080000 pid=2073 execve guuid=1a6baa84-1b00-0000-b32b-d90a2d090000 pid=2349 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=1a6baa84-1b00-0000-b32b-d90a2d090000 pid=2349 execve guuid=1672f584-1b00-0000-b32b-d90a2e090000 pid=2350 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=1672f584-1b00-0000-b32b-d90a2e090000 pid=2350 clone guuid=ddf2ff84-1b00-0000-b32b-d90a2f090000 pid=2351 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=ddf2ff84-1b00-0000-b32b-d90a2f090000 pid=2351 execve guuid=d8fa4485-1b00-0000-b32b-d90a31090000 pid=2353 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=d8fa4485-1b00-0000-b32b-d90a31090000 pid=2353 clone guuid=d9a18c86-1b00-0000-b32b-d90a38090000 pid=2360 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=d9a18c86-1b00-0000-b32b-d90a38090000 pid=2360 execve guuid=a8c1082a-1c00-0000-b32b-d90a890a0000 pid=2697 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=a8c1082a-1c00-0000-b32b-d90a890a0000 pid=2697 execve guuid=d1e7582a-1c00-0000-b32b-d90a8a0a0000 pid=2698 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=d1e7582a-1c00-0000-b32b-d90a8a0a0000 pid=2698 clone guuid=4e12602a-1c00-0000-b32b-d90a8c0a0000 pid=2700 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=4e12602a-1c00-0000-b32b-d90a8c0a0000 pid=2700 execve guuid=eb84c92a-1c00-0000-b32b-d90a8f0a0000 pid=2703 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=eb84c92a-1c00-0000-b32b-d90a8f0a0000 pid=2703 clone guuid=94a29c2b-1c00-0000-b32b-d90a950a0000 pid=2709 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=94a29c2b-1c00-0000-b32b-d90a950a0000 pid=2709 execve guuid=436254b8-1c00-0000-b32b-d90a7c0b0000 pid=2940 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=436254b8-1c00-0000-b32b-d90a7c0b0000 pid=2940 execve guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941 /tmp/u4ur4n guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941 execve guuid=3500a8b8-1c00-0000-b32b-d90a7f0b0000 pid=2943 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=3500a8b8-1c00-0000-b32b-d90a7f0b0000 pid=2943 execve guuid=377219b9-1c00-0000-b32b-d90a800b0000 pid=2944 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=377219b9-1c00-0000-b32b-d90a800b0000 pid=2944 clone guuid=9fcf3bba-1c00-0000-b32b-d90a860b0000 pid=2950 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=9fcf3bba-1c00-0000-b32b-d90a860b0000 pid=2950 execve guuid=b899b947-1d00-0000-b32b-d90a8b0c0000 pid=3211 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=b899b947-1d00-0000-b32b-d90a8b0c0000 pid=3211 execve guuid=ed181b48-1d00-0000-b32b-d90a8c0c0000 pid=3212 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=ed181b48-1d00-0000-b32b-d90a8c0c0000 pid=3212 clone guuid=35192348-1d00-0000-b32b-d90a8d0c0000 pid=3213 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=35192348-1d00-0000-b32b-d90a8d0c0000 pid=3213 execve guuid=1c798048-1d00-0000-b32b-d90a8f0c0000 pid=3215 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=1c798048-1d00-0000-b32b-d90a8f0c0000 pid=3215 clone guuid=81fe8549-1d00-0000-b32b-d90a930c0000 pid=3219 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=81fe8549-1d00-0000-b32b-d90a930c0000 pid=3219 execve guuid=73b04cdb-1d00-0000-b32b-d90a460d0000 pid=3398 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=73b04cdb-1d00-0000-b32b-d90a460d0000 pid=3398 execve guuid=067990db-1d00-0000-b32b-d90a470d0000 pid=3399 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=067990db-1d00-0000-b32b-d90a470d0000 pid=3399 clone guuid=f42294db-1d00-0000-b32b-d90a480d0000 pid=3400 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=f42294db-1d00-0000-b32b-d90a480d0000 pid=3400 execve guuid=6f4a01dc-1d00-0000-b32b-d90a4b0d0000 pid=3403 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=6f4a01dc-1d00-0000-b32b-d90a4b0d0000 pid=3403 clone guuid=060beedc-1d00-0000-b32b-d90a520d0000 pid=3410 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=060beedc-1d00-0000-b32b-d90a520d0000 pid=3410 execve guuid=4b16886a-1e00-0000-b32b-d90a4d0e0000 pid=3661 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=4b16886a-1e00-0000-b32b-d90a4d0e0000 pid=3661 execve guuid=8733db6a-1e00-0000-b32b-d90a4f0e0000 pid=3663 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=8733db6a-1e00-0000-b32b-d90a4f0e0000 pid=3663 clone guuid=87e9de6a-1e00-0000-b32b-d90a500e0000 pid=3664 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=87e9de6a-1e00-0000-b32b-d90a500e0000 pid=3664 execve guuid=1f3f826b-1e00-0000-b32b-d90a530e0000 pid=3667 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=1f3f826b-1e00-0000-b32b-d90a530e0000 pid=3667 clone guuid=0191c76c-1e00-0000-b32b-d90a5a0e0000 pid=3674 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=0191c76c-1e00-0000-b32b-d90a5a0e0000 pid=3674 execve guuid=df6226ae-1e00-0000-b32b-d90a1e0f0000 pid=3870 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=df6226ae-1e00-0000-b32b-d90a1e0f0000 pid=3870 execve guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871 /tmp/bzpcsc guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871 execve guuid=eb3273ae-1e00-0000-b32b-d90a200f0000 pid=3872 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=eb3273ae-1e00-0000-b32b-d90a200f0000 pid=3872 execve guuid=207fe1ae-1e00-0000-b32b-d90a260f0000 pid=3878 /usr/bin/dash guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=207fe1ae-1e00-0000-b32b-d90a260f0000 pid=3878 clone guuid=d0b980b0-1e00-0000-b32b-d90a2c0f0000 pid=3884 /usr/bin/wget net send-data write-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=d0b980b0-1e00-0000-b32b-d90a2c0f0000 pid=3884 execve guuid=316f1b02-1f00-0000-b32b-d90a910f0000 pid=3985 /usr/bin/chmod guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=316f1b02-1f00-0000-b32b-d90a910f0000 pid=3985 execve guuid=e26e7702-1f00-0000-b32b-d90a920f0000 pid=3986 /usr/bin/dash zombie guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=e26e7702-1f00-0000-b32b-d90a920f0000 pid=3986 clone guuid=f82e7e02-1f00-0000-b32b-d90a930f0000 pid=3987 /usr/bin/rm delete-file guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=f82e7e02-1f00-0000-b32b-d90a930f0000 pid=3987 execve guuid=2560d602-1f00-0000-b32b-d90a950f0000 pid=3989 /usr/bin/rm delete-file zombie guuid=c3a5aae8-1a00-0000-b32b-d90a0e080000 pid=2062->guuid=2560d602-1f00-0000-b32b-d90a950f0000 pid=3989 execve guuid=fbe238e9-1a00-0000-b32b-d90a12080000 pid=2066 /usr/bin/head guuid=cc3c16e9-1a00-0000-b32b-d90a11080000 pid=2065->guuid=fbe238e9-1a00-0000-b32b-d90a12080000 pid=2066 execve guuid=ba5c4be9-1a00-0000-b32b-d90a14080000 pid=2068 /usr/bin/tr guuid=cc3c16e9-1a00-0000-b32b-d90a11080000 pid=2065->guuid=ba5c4be9-1a00-0000-b32b-d90a14080000 pid=2068 execve guuid=3f1d58e9-1a00-0000-b32b-d90a15080000 pid=2069 /usr/bin/head guuid=cc3c16e9-1a00-0000-b32b-d90a11080000 pid=2065->guuid=3f1d58e9-1a00-0000-b32b-d90a15080000 pid=2069 execve 24bef21c-1b62-5002-af3d-6b17b122b0c7 81.29.156.127:80 guuid=5b54d2ea-1a00-0000-b32b-d90a19080000 pid=2073->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 132B guuid=ca5f4f85-1b00-0000-b32b-d90a32090000 pid=2354 /usr/bin/head guuid=d8fa4485-1b00-0000-b32b-d90a31090000 pid=2353->guuid=ca5f4f85-1b00-0000-b32b-d90a32090000 pid=2354 execve guuid=59fb5485-1b00-0000-b32b-d90a33090000 pid=2355 /usr/bin/tr guuid=d8fa4485-1b00-0000-b32b-d90a31090000 pid=2353->guuid=59fb5485-1b00-0000-b32b-d90a33090000 pid=2355 execve guuid=b6385985-1b00-0000-b32b-d90a35090000 pid=2357 /usr/bin/head guuid=d8fa4485-1b00-0000-b32b-d90a31090000 pid=2353->guuid=b6385985-1b00-0000-b32b-d90a35090000 pid=2357 execve guuid=d9a18c86-1b00-0000-b32b-d90a38090000 pid=2360->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 134B guuid=d4eed22a-1c00-0000-b32b-d90a900a0000 pid=2704 /usr/bin/head guuid=eb84c92a-1c00-0000-b32b-d90a8f0a0000 pid=2703->guuid=d4eed22a-1c00-0000-b32b-d90a900a0000 pid=2704 execve guuid=0161db2a-1c00-0000-b32b-d90a910a0000 pid=2705 /usr/bin/tr guuid=eb84c92a-1c00-0000-b32b-d90a8f0a0000 pid=2703->guuid=0161db2a-1c00-0000-b32b-d90a910a0000 pid=2705 execve guuid=c04de02a-1c00-0000-b32b-d90a920a0000 pid=2706 /usr/bin/head guuid=eb84c92a-1c00-0000-b32b-d90a8f0a0000 pid=2703->guuid=c04de02a-1c00-0000-b32b-d90a920a0000 pid=2706 execve guuid=94a29c2b-1c00-0000-b32b-d90a950a0000 pid=2709->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 131B guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2956 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2956 clone guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2957 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2957 clone guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2958 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2958 clone guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2959 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2959 clone guuid=5ff1a7bf-1c00-0000-b32b-d90a910b0000 pid=2961 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=5ff1a7bf-1c00-0000-b32b-d90a910b0000 pid=2961 clone guuid=6583bebf-1c00-0000-b32b-d90a920b0000 pid=2962 /tmp/u4ur4n guuid=aee4a3b8-1c00-0000-b32b-d90a7d0b0000 pid=2941->guuid=6583bebf-1c00-0000-b32b-d90a920b0000 pid=2962 clone guuid=4f7f22b9-1c00-0000-b32b-d90a810b0000 pid=2945 /usr/bin/head guuid=377219b9-1c00-0000-b32b-d90a800b0000 pid=2944->guuid=4f7f22b9-1c00-0000-b32b-d90a810b0000 pid=2945 execve guuid=f00828b9-1c00-0000-b32b-d90a820b0000 pid=2946 /usr/bin/tr guuid=377219b9-1c00-0000-b32b-d90a800b0000 pid=2944->guuid=f00828b9-1c00-0000-b32b-d90a820b0000 pid=2946 execve guuid=20f82db9-1c00-0000-b32b-d90a830b0000 pid=2947 /usr/bin/head guuid=377219b9-1c00-0000-b32b-d90a800b0000 pid=2944->guuid=20f82db9-1c00-0000-b32b-d90a830b0000 pid=2947 execve guuid=9fcf3bba-1c00-0000-b32b-d90a860b0000 pid=2950->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 134B guuid=04c78b48-1d00-0000-b32b-d90a900c0000 pid=3216 /usr/bin/head guuid=1c798048-1d00-0000-b32b-d90a8f0c0000 pid=3215->guuid=04c78b48-1d00-0000-b32b-d90a900c0000 pid=3216 execve guuid=a20e9248-1d00-0000-b32b-d90a910c0000 pid=3217 /usr/bin/tr guuid=1c798048-1d00-0000-b32b-d90a8f0c0000 pid=3215->guuid=a20e9248-1d00-0000-b32b-d90a910c0000 pid=3217 execve guuid=87b19a48-1d00-0000-b32b-d90a920c0000 pid=3218 /usr/bin/head guuid=1c798048-1d00-0000-b32b-d90a8f0c0000 pid=3215->guuid=87b19a48-1d00-0000-b32b-d90a920c0000 pid=3218 execve guuid=81fe8549-1d00-0000-b32b-d90a930c0000 pid=3219->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 134B guuid=a48f0bdc-1d00-0000-b32b-d90a4d0d0000 pid=3405 /usr/bin/head guuid=6f4a01dc-1d00-0000-b32b-d90a4b0d0000 pid=3403->guuid=a48f0bdc-1d00-0000-b32b-d90a4d0d0000 pid=3405 execve guuid=b26511dc-1d00-0000-b32b-d90a4e0d0000 pid=3406 /usr/bin/tr guuid=6f4a01dc-1d00-0000-b32b-d90a4b0d0000 pid=3403->guuid=b26511dc-1d00-0000-b32b-d90a4e0d0000 pid=3406 execve guuid=282217dc-1d00-0000-b32b-d90a4f0d0000 pid=3407 /usr/bin/head guuid=6f4a01dc-1d00-0000-b32b-d90a4b0d0000 pid=3403->guuid=282217dc-1d00-0000-b32b-d90a4f0d0000 pid=3407 execve guuid=060beedc-1d00-0000-b32b-d90a520d0000 pid=3410->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 134B guuid=93ef8f6b-1e00-0000-b32b-d90a540e0000 pid=3668 /usr/bin/head guuid=1f3f826b-1e00-0000-b32b-d90a530e0000 pid=3667->guuid=93ef8f6b-1e00-0000-b32b-d90a540e0000 pid=3668 execve guuid=5fad996b-1e00-0000-b32b-d90a550e0000 pid=3669 /usr/bin/tr guuid=1f3f826b-1e00-0000-b32b-d90a530e0000 pid=3667->guuid=5fad996b-1e00-0000-b32b-d90a550e0000 pid=3669 execve guuid=219ca36b-1e00-0000-b32b-d90a560e0000 pid=3670 /usr/bin/head guuid=1f3f826b-1e00-0000-b32b-d90a530e0000 pid=3667->guuid=219ca36b-1e00-0000-b32b-d90a560e0000 pid=3670 execve guuid=0191c76c-1e00-0000-b32b-d90a5a0e0000 pid=3674->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 132B guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3894 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3894 clone guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3895 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3895 clone guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3896 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3896 clone guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3897 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3897 clone guuid=bcddbab4-1e00-0000-b32b-d90a3d0f0000 pid=3901 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=bcddbab4-1e00-0000-b32b-d90a3d0f0000 pid=3901 clone guuid=2bc007b5-1e00-0000-b32b-d90a3e0f0000 pid=3902 /tmp/bzpcsc guuid=20376dae-1e00-0000-b32b-d90a1f0f0000 pid=3871->guuid=2bc007b5-1e00-0000-b32b-d90a3e0f0000 pid=3902 clone guuid=fae6f6ae-1e00-0000-b32b-d90a270f0000 pid=3879 /usr/bin/head guuid=207fe1ae-1e00-0000-b32b-d90a260f0000 pid=3878->guuid=fae6f6ae-1e00-0000-b32b-d90a270f0000 pid=3879 execve guuid=c00d03af-1e00-0000-b32b-d90a280f0000 pid=3880 /usr/bin/tr guuid=207fe1ae-1e00-0000-b32b-d90a260f0000 pid=3878->guuid=c00d03af-1e00-0000-b32b-d90a280f0000 pid=3880 execve guuid=5be50baf-1e00-0000-b32b-d90a290f0000 pid=3881 /usr/bin/head guuid=207fe1ae-1e00-0000-b32b-d90a260f0000 pid=3878->guuid=5be50baf-1e00-0000-b32b-d90a290f0000 pid=3881 execve guuid=d0b980b0-1e00-0000-b32b-d90a2c0f0000 pid=3884->24bef21c-1b62-5002-af3d-6b17b122b0c7 send: 133B guuid=36aee402-1f00-0000-b32b-d90a960f0000 pid=3990 /usr/bin/sleep guuid=2560d602-1f00-0000-b32b-d90a950f0000 pid=3989->guuid=36aee402-1f00-0000-b32b-d90a960f0000 pid=3990 execve
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments