MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4958d312870cc240592ec5e299a07c5f5edf53c82214e407582c11abdb57d07f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 4958d312870cc240592ec5e299a07c5f5edf53c82214e407582c11abdb57d07f
SHA3-384 hash: 6b01c66d389f14971f8fba5d962343a0df4983fd4422f9e42d5bc337ca7252f1bf3f98b902f41131ff06fe29641851a6
SHA1 hash: 4331c9f5dc0d95559a6cb75097b84a7ba614ffb0
MD5 hash: e1b4f06e073d132a13cfd19347e0399c
humanhash: tango-florida-south-victor
File name:bins.sh
Download: download sample
File size:425 bytes
First seen:2026-02-21 14:09:41 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:v0FpEFNivEFNdeCEadefmuEwoIElNl+EbEUEz:UslImjPl+EbEUEz
TLSH T11AE092FC3CB0383C14999411A7F10D0072559193C4754EFF4DC8D8A848CFE0865DC149
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://103.125.219.204/huh.shn/an/amirai opendir

Intelligence


File Origin
# of uploads :
1
# of downloads :
50
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
evasive
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=1361f379-1800-0000-4ecd-f2b3880c0000 pid=3208 /usr/bin/sudo guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209 /tmp/sample.bin guuid=1361f379-1800-0000-4ecd-f2b3880c0000 pid=3208->guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209 execve guuid=6d928d7c-1800-0000-4ecd-f2b38a0c0000 pid=3210 /usr/bin/wget net send-data write-file guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=6d928d7c-1800-0000-4ecd-f2b38a0c0000 pid=3210 execve guuid=c40735a0-1800-0000-4ecd-f2b3b70c0000 pid=3255 /usr/bin/curl net send-data write-file guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=c40735a0-1800-0000-4ecd-f2b3b70c0000 pid=3255 execve guuid=8e9e0cc6-1800-0000-4ecd-f2b3fd0c0000 pid=3325 /usr/bin/chmod guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=8e9e0cc6-1800-0000-4ecd-f2b3fd0c0000 pid=3325 execve guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326 /usr/bin/dash guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326 execve guuid=5a1c6baf-1d00-0000-4ecd-f2b3e1140000 pid=5345 /usr/bin/chmod guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=5a1c6baf-1d00-0000-4ecd-f2b3e1140000 pid=5345 execve guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346 /usr/bin/dash guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346 execve guuid=423ab832-2200-0000-4ecd-f2b333150000 pid=5427 /usr/bin/chmod guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=423ab832-2200-0000-4ecd-f2b333150000 pid=5427 execve guuid=23ec4433-2200-0000-4ecd-f2b334150000 pid=5428 /usr/bin/dash guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=23ec4433-2200-0000-4ecd-f2b334150000 pid=5428 execve guuid=8a36b533-2200-0000-4ecd-f2b335150000 pid=5429 /usr/bin/dash guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=8a36b533-2200-0000-4ecd-f2b335150000 pid=5429 execve guuid=a1821034-2200-0000-4ecd-f2b336150000 pid=5430 /usr/bin/rm delete-file guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=a1821034-2200-0000-4ecd-f2b336150000 pid=5430 execve guuid=b1e89434-2200-0000-4ecd-f2b337150000 pid=5431 /usr/bin/rm delete-file guuid=8b76297c-1800-0000-4ecd-f2b3890c0000 pid=3209->guuid=b1e89434-2200-0000-4ecd-f2b337150000 pid=5431 execve f96f48b5-ff72-5c40-8094-b594149323d5 103.125.219.204:80 guuid=6d928d7c-1800-0000-4ecd-f2b38a0c0000 pid=3210->f96f48b5-ff72-5c40-8094-b594149323d5 send: 136B guuid=c40735a0-1800-0000-4ecd-f2b3b70c0000 pid=3255->f96f48b5-ff72-5c40-8094-b594149323d5 send: 85B guuid=bca4fac6-1800-0000-4ecd-f2b3ff0c0000 pid=3327 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=bca4fac6-1800-0000-4ecd-f2b3ff0c0000 pid=3327 execve guuid=ea18b3e9-1800-0000-4ecd-f2b33f0d0000 pid=3391 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=ea18b3e9-1800-0000-4ecd-f2b33f0d0000 pid=3391 execve guuid=0f9a0f0e-1900-0000-4ecd-f2b3990d0000 pid=3481 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=0f9a0f0e-1900-0000-4ecd-f2b3990d0000 pid=3481 execve guuid=f9028a0e-1900-0000-4ecd-f2b39a0d0000 pid=3482 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f9028a0e-1900-0000-4ecd-f2b39a0d0000 pid=3482 execve guuid=70f2f30e-1900-0000-4ecd-f2b39c0d0000 pid=3484 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=70f2f30e-1900-0000-4ecd-f2b39c0d0000 pid=3484 execve guuid=4761480f-1900-0000-4ecd-f2b39d0d0000 pid=3485 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=4761480f-1900-0000-4ecd-f2b39d0d0000 pid=3485 execve guuid=f8dc1631-1900-0000-4ecd-f2b3cd0d0000 pid=3533 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f8dc1631-1900-0000-4ecd-f2b3cd0d0000 pid=3533 execve guuid=ffb29955-1900-0000-4ecd-f2b3190e0000 pid=3609 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=ffb29955-1900-0000-4ecd-f2b3190e0000 pid=3609 execve guuid=f9bc0256-1900-0000-4ecd-f2b31b0e0000 pid=3611 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f9bc0256-1900-0000-4ecd-f2b31b0e0000 pid=3611 execve guuid=11587c56-1900-0000-4ecd-f2b31c0e0000 pid=3612 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=11587c56-1900-0000-4ecd-f2b31c0e0000 pid=3612 execve guuid=d9c6cb56-1900-0000-4ecd-f2b31e0e0000 pid=3614 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=d9c6cb56-1900-0000-4ecd-f2b31e0e0000 pid=3614 execve guuid=cb08b077-1900-0000-4ecd-f2b3580e0000 pid=3672 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=cb08b077-1900-0000-4ecd-f2b3580e0000 pid=3672 execve guuid=57c6359c-1900-0000-4ecd-f2b3bd0e0000 pid=3773 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=57c6359c-1900-0000-4ecd-f2b3bd0e0000 pid=3773 execve guuid=cd6c949c-1900-0000-4ecd-f2b3bf0e0000 pid=3775 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=cd6c949c-1900-0000-4ecd-f2b3bf0e0000 pid=3775 execve guuid=a1bfe79c-1900-0000-4ecd-f2b3c10e0000 pid=3777 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=a1bfe79c-1900-0000-4ecd-f2b3c10e0000 pid=3777 execve guuid=6818249d-1900-0000-4ecd-f2b3c30e0000 pid=3779 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=6818249d-1900-0000-4ecd-f2b3c30e0000 pid=3779 execve guuid=9fe5cebe-1900-0000-4ecd-f2b33a0f0000 pid=3898 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=9fe5cebe-1900-0000-4ecd-f2b33a0f0000 pid=3898 execve guuid=03dbb6e1-1900-0000-4ecd-f2b37a0f0000 pid=3962 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=03dbb6e1-1900-0000-4ecd-f2b37a0f0000 pid=3962 execve guuid=5fb405e2-1900-0000-4ecd-f2b37b0f0000 pid=3963 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=5fb405e2-1900-0000-4ecd-f2b37b0f0000 pid=3963 execve guuid=f1b555e2-1900-0000-4ecd-f2b37f0f0000 pid=3967 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f1b555e2-1900-0000-4ecd-f2b37f0f0000 pid=3967 execve guuid=66a9b6e2-1900-0000-4ecd-f2b3800f0000 pid=3968 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=66a9b6e2-1900-0000-4ecd-f2b3800f0000 pid=3968 execve guuid=20ee2b41-1a00-0000-4ecd-f2b3d9100000 pid=4313 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=20ee2b41-1a00-0000-4ecd-f2b3d9100000 pid=4313 execve guuid=a1a38d63-1a00-0000-4ecd-f2b363110000 pid=4451 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=a1a38d63-1a00-0000-4ecd-f2b363110000 pid=4451 execve guuid=2350dc63-1a00-0000-4ecd-f2b367110000 pid=4455 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=2350dc63-1a00-0000-4ecd-f2b367110000 pid=4455 execve guuid=835c1964-1a00-0000-4ecd-f2b368110000 pid=4456 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=835c1964-1a00-0000-4ecd-f2b368110000 pid=4456 execve guuid=c9875064-1a00-0000-4ecd-f2b36a110000 pid=4458 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=c9875064-1a00-0000-4ecd-f2b36a110000 pid=4458 execve guuid=ff6ce285-1a00-0000-4ecd-f2b3d8110000 pid=4568 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=ff6ce285-1a00-0000-4ecd-f2b3d8110000 pid=4568 execve guuid=7e9837a8-1a00-0000-4ecd-f2b34d120000 pid=4685 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=7e9837a8-1a00-0000-4ecd-f2b34d120000 pid=4685 execve guuid=2310d4ac-1a00-0000-4ecd-f2b356120000 pid=4694 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=2310d4ac-1a00-0000-4ecd-f2b356120000 pid=4694 execve guuid=8f7a28ad-1a00-0000-4ecd-f2b357120000 pid=4695 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=8f7a28ad-1a00-0000-4ecd-f2b357120000 pid=4695 execve guuid=e1c070ad-1a00-0000-4ecd-f2b359120000 pid=4697 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=e1c070ad-1a00-0000-4ecd-f2b359120000 pid=4697 execve guuid=33b555cf-1a00-0000-4ecd-f2b3dd120000 pid=4829 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=33b555cf-1a00-0000-4ecd-f2b3dd120000 pid=4829 execve guuid=27f8eaf1-1a00-0000-4ecd-f2b33c130000 pid=4924 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=27f8eaf1-1a00-0000-4ecd-f2b33c130000 pid=4924 execve guuid=688e63f2-1a00-0000-4ecd-f2b33e130000 pid=4926 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=688e63f2-1a00-0000-4ecd-f2b33e130000 pid=4926 execve guuid=5ea8c8f2-1a00-0000-4ecd-f2b340130000 pid=4928 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=5ea8c8f2-1a00-0000-4ecd-f2b340130000 pid=4928 execve guuid=88833ff3-1a00-0000-4ecd-f2b343130000 pid=4931 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=88833ff3-1a00-0000-4ecd-f2b343130000 pid=4931 execve guuid=4da14715-1b00-0000-4ecd-f2b3c5130000 pid=5061 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=4da14715-1b00-0000-4ecd-f2b3c5130000 pid=5061 execve guuid=2745c838-1b00-0000-4ecd-f2b336140000 pid=5174 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=2745c838-1b00-0000-4ecd-f2b336140000 pid=5174 execve guuid=ba920e39-1b00-0000-4ecd-f2b338140000 pid=5176 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=ba920e39-1b00-0000-4ecd-f2b338140000 pid=5176 execve guuid=6672c639-1b00-0000-4ecd-f2b33a140000 pid=5178 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=6672c639-1b00-0000-4ecd-f2b33a140000 pid=5178 execve guuid=c36a4d3a-1b00-0000-4ecd-f2b33c140000 pid=5180 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=c36a4d3a-1b00-0000-4ecd-f2b33c140000 pid=5180 execve guuid=3c03735b-1b00-0000-4ecd-f2b388140000 pid=5256 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=3c03735b-1b00-0000-4ecd-f2b388140000 pid=5256 execve guuid=df0a4c7f-1b00-0000-4ecd-f2b394140000 pid=5268 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=df0a4c7f-1b00-0000-4ecd-f2b394140000 pid=5268 execve guuid=1aa78e7f-1b00-0000-4ecd-f2b395140000 pid=5269 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=1aa78e7f-1b00-0000-4ecd-f2b395140000 pid=5269 execve guuid=4d83c67f-1b00-0000-4ecd-f2b396140000 pid=5270 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=4d83c67f-1b00-0000-4ecd-f2b396140000 pid=5270 execve guuid=d783f87f-1b00-0000-4ecd-f2b397140000 pid=5271 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=d783f87f-1b00-0000-4ecd-f2b397140000 pid=5271 execve guuid=fa45e2a0-1b00-0000-4ecd-f2b398140000 pid=5272 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=fa45e2a0-1b00-0000-4ecd-f2b398140000 pid=5272 execve guuid=8fd1abc2-1b00-0000-4ecd-f2b399140000 pid=5273 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=8fd1abc2-1b00-0000-4ecd-f2b399140000 pid=5273 execve guuid=3a08c9c3-1b00-0000-4ecd-f2b39a140000 pid=5274 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=3a08c9c3-1b00-0000-4ecd-f2b39a140000 pid=5274 execve guuid=e3236ec4-1b00-0000-4ecd-f2b39b140000 pid=5275 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=e3236ec4-1b00-0000-4ecd-f2b39b140000 pid=5275 execve guuid=f44ed2c4-1b00-0000-4ecd-f2b39c140000 pid=5276 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f44ed2c4-1b00-0000-4ecd-f2b39c140000 pid=5276 execve guuid=b6adb7e7-1b00-0000-4ecd-f2b39d140000 pid=5277 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=b6adb7e7-1b00-0000-4ecd-f2b39d140000 pid=5277 execve guuid=2a61d30a-1c00-0000-4ecd-f2b39e140000 pid=5278 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=2a61d30a-1c00-0000-4ecd-f2b39e140000 pid=5278 execve guuid=f04e230b-1c00-0000-4ecd-f2b39f140000 pid=5279 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f04e230b-1c00-0000-4ecd-f2b39f140000 pid=5279 execve guuid=ab8c6b0b-1c00-0000-4ecd-f2b3a0140000 pid=5280 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=ab8c6b0b-1c00-0000-4ecd-f2b3a0140000 pid=5280 execve guuid=984aaa0b-1c00-0000-4ecd-f2b3a1140000 pid=5281 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=984aaa0b-1c00-0000-4ecd-f2b3a1140000 pid=5281 execve guuid=2764846a-1c00-0000-4ecd-f2b3a9140000 pid=5289 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=2764846a-1c00-0000-4ecd-f2b3a9140000 pid=5289 execve guuid=b212eb8e-1c00-0000-4ecd-f2b3aa140000 pid=5290 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=b212eb8e-1c00-0000-4ecd-f2b3aa140000 pid=5290 execve guuid=534c0890-1c00-0000-4ecd-f2b3ab140000 pid=5291 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=534c0890-1c00-0000-4ecd-f2b3ab140000 pid=5291 execve guuid=56e9b890-1c00-0000-4ecd-f2b3ac140000 pid=5292 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=56e9b890-1c00-0000-4ecd-f2b3ac140000 pid=5292 execve guuid=47772391-1c00-0000-4ecd-f2b3ad140000 pid=5293 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=47772391-1c00-0000-4ecd-f2b3ad140000 pid=5293 execve guuid=b09827b6-1c00-0000-4ecd-f2b3ae140000 pid=5294 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=b09827b6-1c00-0000-4ecd-f2b3ae140000 pid=5294 execve guuid=a105f2dd-1c00-0000-4ecd-f2b3af140000 pid=5295 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=a105f2dd-1c00-0000-4ecd-f2b3af140000 pid=5295 execve guuid=e9e8a0de-1c00-0000-4ecd-f2b3b0140000 pid=5296 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=e9e8a0de-1c00-0000-4ecd-f2b3b0140000 pid=5296 execve guuid=c9932adf-1c00-0000-4ecd-f2b3b1140000 pid=5297 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=c9932adf-1c00-0000-4ecd-f2b3b1140000 pid=5297 execve guuid=64d66de0-1c00-0000-4ecd-f2b3b2140000 pid=5298 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=64d66de0-1c00-0000-4ecd-f2b3b2140000 pid=5298 execve guuid=03816003-1d00-0000-4ecd-f2b3b3140000 pid=5299 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=03816003-1d00-0000-4ecd-f2b3b3140000 pid=5299 execve guuid=0832f325-1d00-0000-4ecd-f2b3b5140000 pid=5301 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=0832f325-1d00-0000-4ecd-f2b3b5140000 pid=5301 execve guuid=28e43426-1d00-0000-4ecd-f2b3b6140000 pid=5302 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=28e43426-1d00-0000-4ecd-f2b3b6140000 pid=5302 execve guuid=d5877626-1d00-0000-4ecd-f2b3b7140000 pid=5303 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=d5877626-1d00-0000-4ecd-f2b3b7140000 pid=5303 execve guuid=cdefae26-1d00-0000-4ecd-f2b3b8140000 pid=5304 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=cdefae26-1d00-0000-4ecd-f2b3b8140000 pid=5304 execve guuid=eb7fbc47-1d00-0000-4ecd-f2b3c5140000 pid=5317 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=eb7fbc47-1d00-0000-4ecd-f2b3c5140000 pid=5317 execve guuid=f1600269-1d00-0000-4ecd-f2b3c9140000 pid=5321 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=f1600269-1d00-0000-4ecd-f2b3c9140000 pid=5321 execve guuid=17144169-1d00-0000-4ecd-f2b3ca140000 pid=5322 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=17144169-1d00-0000-4ecd-f2b3ca140000 pid=5322 execve guuid=48647d69-1d00-0000-4ecd-f2b3cc140000 pid=5324 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=48647d69-1d00-0000-4ecd-f2b3cc140000 pid=5324 execve guuid=d679ab69-1d00-0000-4ecd-f2b3cd140000 pid=5325 /usr/bin/wget net send-data guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=d679ab69-1d00-0000-4ecd-f2b3cd140000 pid=5325 execve guuid=b5f18e8a-1d00-0000-4ecd-f2b3dd140000 pid=5341 /usr/bin/curl net send-data write-file guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=b5f18e8a-1d00-0000-4ecd-f2b3dd140000 pid=5341 execve guuid=9a3951ae-1d00-0000-4ecd-f2b3de140000 pid=5342 /usr/bin/cat guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=9a3951ae-1d00-0000-4ecd-f2b3de140000 pid=5342 execve guuid=158bd9ae-1d00-0000-4ecd-f2b3df140000 pid=5343 /usr/bin/chmod guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=158bd9ae-1d00-0000-4ecd-f2b3df140000 pid=5343 execve guuid=d02720af-1d00-0000-4ecd-f2b3e0140000 pid=5344 /tmp/SSH-scanner guuid=b98c94c6-1800-0000-4ecd-f2b3fe0c0000 pid=3326->guuid=d02720af-1d00-0000-4ecd-f2b3e0140000 pid=5344 execve guuid=bca4fac6-1800-0000-4ecd-f2b3ff0c0000 pid=3327->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=ea18b3e9-1800-0000-4ecd-f2b33f0d0000 pid=3391->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=4761480f-1900-0000-4ecd-f2b39d0d0000 pid=3485->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=f8dc1631-1900-0000-4ecd-f2b3cd0d0000 pid=3533->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=d9c6cb56-1900-0000-4ecd-f2b31e0e0000 pid=3614->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=cb08b077-1900-0000-4ecd-f2b3580e0000 pid=3672->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=6818249d-1900-0000-4ecd-f2b3c30e0000 pid=3779->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=9fe5cebe-1900-0000-4ecd-f2b33a0f0000 pid=3898->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=66a9b6e2-1900-0000-4ecd-f2b3800f0000 pid=3968->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=20ee2b41-1a00-0000-4ecd-f2b3d9100000 pid=4313->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=c9875064-1a00-0000-4ecd-f2b36a110000 pid=4458->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=ff6ce285-1a00-0000-4ecd-f2b3d8110000 pid=4568->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=e1c070ad-1a00-0000-4ecd-f2b359120000 pid=4697->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=33b555cf-1a00-0000-4ecd-f2b3dd120000 pid=4829->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=88833ff3-1a00-0000-4ecd-f2b343130000 pid=4931->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=4da14715-1b00-0000-4ecd-f2b3c5130000 pid=5061->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=c36a4d3a-1b00-0000-4ecd-f2b33c140000 pid=5180->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=3c03735b-1b00-0000-4ecd-f2b388140000 pid=5256->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=d783f87f-1b00-0000-4ecd-f2b397140000 pid=5271->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=fa45e2a0-1b00-0000-4ecd-f2b398140000 pid=5272->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=f44ed2c4-1b00-0000-4ecd-f2b39c140000 pid=5276->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=b6adb7e7-1b00-0000-4ecd-f2b39d140000 pid=5277->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=984aaa0b-1c00-0000-4ecd-f2b3a1140000 pid=5281->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=2764846a-1c00-0000-4ecd-f2b3a9140000 pid=5289->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=47772391-1c00-0000-4ecd-f2b3ad140000 pid=5293->f96f48b5-ff72-5c40-8094-b594149323d5 send: 147B guuid=b09827b6-1c00-0000-4ecd-f2b3ae140000 pid=5294->f96f48b5-ff72-5c40-8094-b594149323d5 send: 96B guuid=64d66de0-1c00-0000-4ecd-f2b3b2140000 pid=5298->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=03816003-1d00-0000-4ecd-f2b3b3140000 pid=5299->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=cdefae26-1d00-0000-4ecd-f2b3b8140000 pid=5304->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=eb7fbc47-1d00-0000-4ecd-f2b3c5140000 pid=5317->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=d679ab69-1d00-0000-4ecd-f2b3cd140000 pid=5325->f96f48b5-ff72-5c40-8094-b594149323d5 send: 147B guuid=b5f18e8a-1d00-0000-4ecd-f2b3dd140000 pid=5341->f96f48b5-ff72-5c40-8094-b594149323d5 send: 96B guuid=032ee3af-1d00-0000-4ecd-f2b3e3140000 pid=5347 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=032ee3af-1d00-0000-4ecd-f2b3e3140000 pid=5347 execve guuid=bdca8ed0-1d00-0000-4ecd-f2b3e4140000 pid=5348 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=bdca8ed0-1d00-0000-4ecd-f2b3e4140000 pid=5348 execve guuid=81bd84f2-1d00-0000-4ecd-f2b3e5140000 pid=5349 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=81bd84f2-1d00-0000-4ecd-f2b3e5140000 pid=5349 execve guuid=1bfce7f2-1d00-0000-4ecd-f2b3e6140000 pid=5350 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=1bfce7f2-1d00-0000-4ecd-f2b3e6140000 pid=5350 execve guuid=750c41f3-1d00-0000-4ecd-f2b3e7140000 pid=5351 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=750c41f3-1d00-0000-4ecd-f2b3e7140000 pid=5351 execve guuid=2cbbc3f3-1d00-0000-4ecd-f2b3e8140000 pid=5352 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=2cbbc3f3-1d00-0000-4ecd-f2b3e8140000 pid=5352 execve guuid=cf523b15-1e00-0000-4ecd-f2b3e9140000 pid=5353 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=cf523b15-1e00-0000-4ecd-f2b3e9140000 pid=5353 execve guuid=d7bd2c38-1e00-0000-4ecd-f2b3ea140000 pid=5354 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d7bd2c38-1e00-0000-4ecd-f2b3ea140000 pid=5354 execve guuid=a921ba38-1e00-0000-4ecd-f2b3eb140000 pid=5355 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=a921ba38-1e00-0000-4ecd-f2b3eb140000 pid=5355 execve guuid=4d443a39-1e00-0000-4ecd-f2b3ec140000 pid=5356 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=4d443a39-1e00-0000-4ecd-f2b3ec140000 pid=5356 execve guuid=d658b339-1e00-0000-4ecd-f2b3ed140000 pid=5357 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d658b339-1e00-0000-4ecd-f2b3ed140000 pid=5357 execve guuid=7cb7f15a-1e00-0000-4ecd-f2b3ee140000 pid=5358 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=7cb7f15a-1e00-0000-4ecd-f2b3ee140000 pid=5358 execve guuid=fc9d4e81-1e00-0000-4ecd-f2b3ef140000 pid=5359 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=fc9d4e81-1e00-0000-4ecd-f2b3ef140000 pid=5359 execve guuid=a9e00682-1e00-0000-4ecd-f2b3f0140000 pid=5360 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=a9e00682-1e00-0000-4ecd-f2b3f0140000 pid=5360 execve guuid=e78e9c82-1e00-0000-4ecd-f2b3f1140000 pid=5361 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=e78e9c82-1e00-0000-4ecd-f2b3f1140000 pid=5361 execve guuid=7bfe0283-1e00-0000-4ecd-f2b3f2140000 pid=5362 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=7bfe0283-1e00-0000-4ecd-f2b3f2140000 pid=5362 execve guuid=7b9461a4-1e00-0000-4ecd-f2b3f3140000 pid=5363 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=7b9461a4-1e00-0000-4ecd-f2b3f3140000 pid=5363 execve guuid=5cad79c7-1e00-0000-4ecd-f2b3f4140000 pid=5364 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=5cad79c7-1e00-0000-4ecd-f2b3f4140000 pid=5364 execve guuid=359f03c8-1e00-0000-4ecd-f2b3f5140000 pid=5365 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=359f03c8-1e00-0000-4ecd-f2b3f5140000 pid=5365 execve guuid=bf2689c8-1e00-0000-4ecd-f2b3f6140000 pid=5366 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=bf2689c8-1e00-0000-4ecd-f2b3f6140000 pid=5366 execve guuid=60b4f7c8-1e00-0000-4ecd-f2b3f7140000 pid=5367 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=60b4f7c8-1e00-0000-4ecd-f2b3f7140000 pid=5367 execve guuid=be6ae2ea-1e00-0000-4ecd-f2b3f8140000 pid=5368 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=be6ae2ea-1e00-0000-4ecd-f2b3f8140000 pid=5368 execve guuid=5bf5ec0d-1f00-0000-4ecd-f2b3f9140000 pid=5369 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=5bf5ec0d-1f00-0000-4ecd-f2b3f9140000 pid=5369 execve guuid=0191370e-1f00-0000-4ecd-f2b3fa140000 pid=5370 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=0191370e-1f00-0000-4ecd-f2b3fa140000 pid=5370 execve guuid=2621810e-1f00-0000-4ecd-f2b3fb140000 pid=5371 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=2621810e-1f00-0000-4ecd-f2b3fb140000 pid=5371 execve guuid=ac4ab80e-1f00-0000-4ecd-f2b3fc140000 pid=5372 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ac4ab80e-1f00-0000-4ecd-f2b3fc140000 pid=5372 execve guuid=0f67512f-1f00-0000-4ecd-f2b3fd140000 pid=5373 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=0f67512f-1f00-0000-4ecd-f2b3fd140000 pid=5373 execve guuid=151bfa50-1f00-0000-4ecd-f2b3fe140000 pid=5374 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=151bfa50-1f00-0000-4ecd-f2b3fe140000 pid=5374 execve guuid=75854c51-1f00-0000-4ecd-f2b3ff140000 pid=5375 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=75854c51-1f00-0000-4ecd-f2b3ff140000 pid=5375 execve guuid=d88aa251-1f00-0000-4ecd-f2b300150000 pid=5376 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d88aa251-1f00-0000-4ecd-f2b300150000 pid=5376 execve guuid=05a5e351-1f00-0000-4ecd-f2b301150000 pid=5377 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=05a5e351-1f00-0000-4ecd-f2b301150000 pid=5377 execve guuid=2849b972-1f00-0000-4ecd-f2b302150000 pid=5378 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=2849b972-1f00-0000-4ecd-f2b302150000 pid=5378 execve guuid=f5e718c2-1f00-0000-4ecd-f2b303150000 pid=5379 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=f5e718c2-1f00-0000-4ecd-f2b303150000 pid=5379 execve guuid=af5b65c2-1f00-0000-4ecd-f2b304150000 pid=5380 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=af5b65c2-1f00-0000-4ecd-f2b304150000 pid=5380 execve guuid=da4c0ac3-1f00-0000-4ecd-f2b305150000 pid=5381 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=da4c0ac3-1f00-0000-4ecd-f2b305150000 pid=5381 execve guuid=ae234ac3-1f00-0000-4ecd-f2b306150000 pid=5382 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ae234ac3-1f00-0000-4ecd-f2b306150000 pid=5382 execve guuid=bfe4d6e4-1f00-0000-4ecd-f2b307150000 pid=5383 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=bfe4d6e4-1f00-0000-4ecd-f2b307150000 pid=5383 execve guuid=6da31708-2000-0000-4ecd-f2b308150000 pid=5384 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=6da31708-2000-0000-4ecd-f2b308150000 pid=5384 execve guuid=ef199b08-2000-0000-4ecd-f2b309150000 pid=5385 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ef199b08-2000-0000-4ecd-f2b309150000 pid=5385 execve guuid=fed91d09-2000-0000-4ecd-f2b30a150000 pid=5386 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=fed91d09-2000-0000-4ecd-f2b30a150000 pid=5386 execve guuid=987d8e09-2000-0000-4ecd-f2b30b150000 pid=5387 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=987d8e09-2000-0000-4ecd-f2b30b150000 pid=5387 execve guuid=d32cde2a-2000-0000-4ecd-f2b30c150000 pid=5388 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d32cde2a-2000-0000-4ecd-f2b30c150000 pid=5388 execve guuid=94913d4c-2000-0000-4ecd-f2b30d150000 pid=5389 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=94913d4c-2000-0000-4ecd-f2b30d150000 pid=5389 execve guuid=f62d894c-2000-0000-4ecd-f2b30e150000 pid=5390 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=f62d894c-2000-0000-4ecd-f2b30e150000 pid=5390 execve guuid=e5aecb4c-2000-0000-4ecd-f2b30f150000 pid=5391 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=e5aecb4c-2000-0000-4ecd-f2b30f150000 pid=5391 execve guuid=42c0034d-2000-0000-4ecd-f2b310150000 pid=5392 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=42c0034d-2000-0000-4ecd-f2b310150000 pid=5392 execve guuid=1be98b6d-2000-0000-4ecd-f2b311150000 pid=5393 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=1be98b6d-2000-0000-4ecd-f2b311150000 pid=5393 execve guuid=1577bb90-2000-0000-4ecd-f2b312150000 pid=5394 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=1577bb90-2000-0000-4ecd-f2b312150000 pid=5394 execve guuid=3a405291-2000-0000-4ecd-f2b313150000 pid=5395 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=3a405291-2000-0000-4ecd-f2b313150000 pid=5395 execve guuid=fe5ad291-2000-0000-4ecd-f2b314150000 pid=5396 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=fe5ad291-2000-0000-4ecd-f2b314150000 pid=5396 execve guuid=5e134292-2000-0000-4ecd-f2b315150000 pid=5397 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=5e134292-2000-0000-4ecd-f2b315150000 pid=5397 execve guuid=bfd209b4-2000-0000-4ecd-f2b316150000 pid=5398 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=bfd209b4-2000-0000-4ecd-f2b316150000 pid=5398 execve guuid=1e29dcd7-2000-0000-4ecd-f2b317150000 pid=5399 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=1e29dcd7-2000-0000-4ecd-f2b317150000 pid=5399 execve guuid=0f9a61d8-2000-0000-4ecd-f2b318150000 pid=5400 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=0f9a61d8-2000-0000-4ecd-f2b318150000 pid=5400 execve guuid=a6c7e8d8-2000-0000-4ecd-f2b319150000 pid=5401 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=a6c7e8d8-2000-0000-4ecd-f2b319150000 pid=5401 execve guuid=51a84dd9-2000-0000-4ecd-f2b31a150000 pid=5402 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=51a84dd9-2000-0000-4ecd-f2b31a150000 pid=5402 execve guuid=ef513ffb-2000-0000-4ecd-f2b31b150000 pid=5403 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ef513ffb-2000-0000-4ecd-f2b31b150000 pid=5403 execve guuid=7c8d891e-2100-0000-4ecd-f2b31c150000 pid=5404 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=7c8d891e-2100-0000-4ecd-f2b31c150000 pid=5404 execve guuid=ad63101f-2100-0000-4ecd-f2b31d150000 pid=5405 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ad63101f-2100-0000-4ecd-f2b31d150000 pid=5405 execve guuid=b0a18f1f-2100-0000-4ecd-f2b31e150000 pid=5406 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=b0a18f1f-2100-0000-4ecd-f2b31e150000 pid=5406 execve guuid=ebe90220-2100-0000-4ecd-f2b31f150000 pid=5407 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=ebe90220-2100-0000-4ecd-f2b31f150000 pid=5407 execve guuid=2bfb6241-2100-0000-4ecd-f2b320150000 pid=5408 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=2bfb6241-2100-0000-4ecd-f2b320150000 pid=5408 execve guuid=8db7b664-2100-0000-4ecd-f2b321150000 pid=5409 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=8db7b664-2100-0000-4ecd-f2b321150000 pid=5409 execve guuid=44874165-2100-0000-4ecd-f2b322150000 pid=5410 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=44874165-2100-0000-4ecd-f2b322150000 pid=5410 execve guuid=431cc065-2100-0000-4ecd-f2b323150000 pid=5411 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=431cc065-2100-0000-4ecd-f2b323150000 pid=5411 execve guuid=0d982966-2100-0000-4ecd-f2b324150000 pid=5412 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=0d982966-2100-0000-4ecd-f2b324150000 pid=5412 execve guuid=61545787-2100-0000-4ecd-f2b325150000 pid=5413 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=61545787-2100-0000-4ecd-f2b325150000 pid=5413 execve guuid=a5eec7a8-2100-0000-4ecd-f2b326150000 pid=5414 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=a5eec7a8-2100-0000-4ecd-f2b326150000 pid=5414 execve guuid=e3430da9-2100-0000-4ecd-f2b327150000 pid=5415 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=e3430da9-2100-0000-4ecd-f2b327150000 pid=5415 execve guuid=23e973a9-2100-0000-4ecd-f2b328150000 pid=5416 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=23e973a9-2100-0000-4ecd-f2b328150000 pid=5416 execve guuid=a405aba9-2100-0000-4ecd-f2b329150000 pid=5417 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=a405aba9-2100-0000-4ecd-f2b329150000 pid=5417 execve guuid=6a9d46ca-2100-0000-4ecd-f2b32a150000 pid=5418 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=6a9d46ca-2100-0000-4ecd-f2b32a150000 pid=5418 execve guuid=19f450ed-2100-0000-4ecd-f2b32b150000 pid=5419 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=19f450ed-2100-0000-4ecd-f2b32b150000 pid=5419 execve guuid=d1ad91ed-2100-0000-4ecd-f2b32c150000 pid=5420 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d1ad91ed-2100-0000-4ecd-f2b32c150000 pid=5420 execve guuid=29d6d0ed-2100-0000-4ecd-f2b32d150000 pid=5421 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=29d6d0ed-2100-0000-4ecd-f2b32d150000 pid=5421 execve guuid=d8ce04ee-2100-0000-4ecd-f2b32e150000 pid=5422 /usr/bin/wget net send-data guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d8ce04ee-2100-0000-4ecd-f2b32e150000 pid=5422 execve guuid=9860830e-2200-0000-4ecd-f2b32f150000 pid=5423 /usr/bin/curl net send-data write-file guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=9860830e-2200-0000-4ecd-f2b32f150000 pid=5423 execve guuid=c6c33031-2200-0000-4ecd-f2b330150000 pid=5424 /usr/bin/cat guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=c6c33031-2200-0000-4ecd-f2b330150000 pid=5424 execve guuid=d095ba31-2200-0000-4ecd-f2b331150000 pid=5425 /usr/bin/chmod guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=d095ba31-2200-0000-4ecd-f2b331150000 pid=5425 execve guuid=79d93a32-2200-0000-4ecd-f2b332150000 pid=5426 /tmp/SSH-scanner guuid=d3b9b0af-1d00-0000-4ecd-f2b3e2140000 pid=5346->guuid=79d93a32-2200-0000-4ecd-f2b332150000 pid=5426 execve guuid=032ee3af-1d00-0000-4ecd-f2b3e3140000 pid=5347->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=bdca8ed0-1d00-0000-4ecd-f2b3e4140000 pid=5348->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=2cbbc3f3-1d00-0000-4ecd-f2b3e8140000 pid=5352->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=cf523b15-1e00-0000-4ecd-f2b3e9140000 pid=5353->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=d658b339-1e00-0000-4ecd-f2b3ed140000 pid=5357->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=7cb7f15a-1e00-0000-4ecd-f2b3ee140000 pid=5358->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=7bfe0283-1e00-0000-4ecd-f2b3f2140000 pid=5362->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=7b9461a4-1e00-0000-4ecd-f2b3f3140000 pid=5363->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=60b4f7c8-1e00-0000-4ecd-f2b3f7140000 pid=5367->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=be6ae2ea-1e00-0000-4ecd-f2b3f8140000 pid=5368->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=ac4ab80e-1f00-0000-4ecd-f2b3fc140000 pid=5372->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=0f67512f-1f00-0000-4ecd-f2b3fd140000 pid=5373->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=05a5e351-1f00-0000-4ecd-f2b301150000 pid=5377->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=2849b972-1f00-0000-4ecd-f2b302150000 pid=5378->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=ae234ac3-1f00-0000-4ecd-f2b306150000 pid=5382->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=bfe4d6e4-1f00-0000-4ecd-f2b307150000 pid=5383->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=987d8e09-2000-0000-4ecd-f2b30b150000 pid=5387->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=d32cde2a-2000-0000-4ecd-f2b30c150000 pid=5388->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=42c0034d-2000-0000-4ecd-f2b310150000 pid=5392->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=1be98b6d-2000-0000-4ecd-f2b311150000 pid=5393->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=5e134292-2000-0000-4ecd-f2b315150000 pid=5397->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=bfd209b4-2000-0000-4ecd-f2b316150000 pid=5398->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=51a84dd9-2000-0000-4ecd-f2b31a150000 pid=5402->f96f48b5-ff72-5c40-8094-b594149323d5 send: 144B guuid=ef513ffb-2000-0000-4ecd-f2b31b150000 pid=5403->f96f48b5-ff72-5c40-8094-b594149323d5 send: 93B guuid=ebe90220-2100-0000-4ecd-f2b31f150000 pid=5407->f96f48b5-ff72-5c40-8094-b594149323d5 send: 147B guuid=2bfb6241-2100-0000-4ecd-f2b320150000 pid=5408->f96f48b5-ff72-5c40-8094-b594149323d5 send: 96B guuid=0d982966-2100-0000-4ecd-f2b324150000 pid=5412->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=61545787-2100-0000-4ecd-f2b325150000 pid=5413->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=a405aba9-2100-0000-4ecd-f2b329150000 pid=5417->f96f48b5-ff72-5c40-8094-b594149323d5 send: 145B guuid=6a9d46ca-2100-0000-4ecd-f2b32a150000 pid=5418->f96f48b5-ff72-5c40-8094-b594149323d5 send: 94B guuid=d8ce04ee-2100-0000-4ecd-f2b32e150000 pid=5422->f96f48b5-ff72-5c40-8094-b594149323d5 send: 147B guuid=9860830e-2200-0000-4ecd-f2b32f150000 pid=5423->f96f48b5-ff72-5c40-8094-b594149323d5 send: 96B
Gathering data
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4958d312870cc240592ec5e299a07c5f5edf53c82214e407582c11abdb57d07f

(this sample)

  
Delivery method
Distributed via web download

Comments