MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4bbbe5e8fbfb58e8bdc5d2275b61ebae9cedd6ba0bf6f35d3db63426312482a2. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 2


Intelligence 2 IOCs YARA File information Comments

SHA256 hash: 4bbbe5e8fbfb58e8bdc5d2275b61ebae9cedd6ba0bf6f35d3db63426312482a2
SHA3-384 hash: 39a21615446bceb60e08e14ad951088b42f8b1bd13af1c8df443650217280aad0e5181e70b9cb54a09e2419c96b3a13f
SHA1 hash: 0d91c49549c4e9ccc70d1b97196f59eff7003da6
MD5 hash: d3d363c1a41a6e5905c94dd93ce3f3ee
humanhash: fourteen-west-foxtrot-paris
File name:test22.sh
Download: download sample
File size:3'650 bytes
First seen:2025-07-16 02:45:06 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:vL/5miMT3vKybWgRHZ+d/T4pKhnShcAanliDz+yQhK44T7D02K42cgMQzd/uAE:1mi7om7ZhnShcAal1yv7D1K42crAVE
TLSH T171712116388092BD111AC4B4A2CA94553A04C11B0B483E3C7AEED4361F757F4B7FA7E6
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
22
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=1f56fa4b-1900-0000-fd51-4facbf070000 pid=1983 /usr/bin/sudo guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989 /tmp/sample.bin guuid=1f56fa4b-1900-0000-fd51-4facbf070000 pid=1983->guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989 execve guuid=f49f9f4f-1900-0000-fd51-4facc7070000 pid=1991 /usr/bin/date guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=f49f9f4f-1900-0000-fd51-4facc7070000 pid=1991 execve guuid=38364250-1900-0000-fd51-4facc9070000 pid=1993 /usr/bin/id guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=38364250-1900-0000-fd51-4facc9070000 pid=1993 execve guuid=df836051-1900-0000-fd51-4facca070000 pid=1994 /usr/bin/apt-get delete-file write-file guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=df836051-1900-0000-fd51-4facca070000 pid=1994 execve guuid=c552061b-1b00-0000-fd51-4facbf0b0000 pid=3007 /usr/bin/apt-get guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=c552061b-1b00-0000-fd51-4facbf0b0000 pid=3007 execve guuid=f70b981d-1b00-0000-fd51-4facc30b0000 pid=3011 /usr/bin/rm guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=f70b981d-1b00-0000-fd51-4facc30b0000 pid=3011 execve guuid=924eee1d-1b00-0000-fd51-4facc50b0000 pid=3013 /usr/bin/rm guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=924eee1d-1b00-0000-fd51-4facc50b0000 pid=3013 execve guuid=3a09331e-1b00-0000-fd51-4facc70b0000 pid=3015 /usr/bin/rm guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=3a09331e-1b00-0000-fd51-4facc70b0000 pid=3015 execve guuid=d322771e-1b00-0000-fd51-4facca0b0000 pid=3018 /usr/bin/rm guuid=deb8a54e-1900-0000-fd51-4facc5070000 pid=1989->guuid=d322771e-1b00-0000-fd51-4facca0b0000 pid=3018 execve guuid=ab8bd652-1900-0000-fd51-4facd1070000 pid=2001 /usr/bin/dpkg guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=ab8bd652-1900-0000-fd51-4facd1070000 pid=2001 execve guuid=87ad2459-1900-0000-fd51-4facda070000 pid=2010 /usr/lib/apt/methods/mirror guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=87ad2459-1900-0000-fd51-4facda070000 pid=2010 execve guuid=e5fbec5a-1900-0000-fd51-4facdc070000 pid=2012 /usr/lib/apt/methods/mirror guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=e5fbec5a-1900-0000-fd51-4facdc070000 pid=2012 execve guuid=99ebf55b-1900-0000-fd51-4face1070000 pid=2017 /usr/lib/apt/methods/file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=99ebf55b-1900-0000-fd51-4face1070000 pid=2017 execve guuid=63d2bc5c-1900-0000-fd51-4face5070000 pid=2021 /usr/lib/apt/methods/file delete-file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=63d2bc5c-1900-0000-fd51-4face5070000 pid=2021 execve guuid=3aa1dc5d-1900-0000-fd51-4face9070000 pid=2025 /usr/lib/apt/methods/http guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=3aa1dc5d-1900-0000-fd51-4face9070000 pid=2025 execve guuid=3657d75f-1900-0000-fd51-4facf0070000 pid=2032 /usr/lib/apt/methods/http dns net send-data write-file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=3657d75f-1900-0000-fd51-4facf0070000 pid=2032 execve guuid=a3475f72-1900-0000-fd51-4fac14080000 pid=2068 /usr/lib/apt/methods/gpgv guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=a3475f72-1900-0000-fd51-4fac14080000 pid=2068 execve guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074 /usr/lib/apt/methods/gpgv guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074 execve guuid=0169b5a6-1900-0000-fd51-4facc6080000 pid=2246 /usr/lib/apt/methods/rred guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=0169b5a6-1900-0000-fd51-4facc6080000 pid=2246 execve guuid=12fa22ad-1900-0000-fd51-4facd6080000 pid=2262 /usr/lib/apt/methods/rred write-file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=12fa22ad-1900-0000-fd51-4facd6080000 pid=2262 execve guuid=1070f0ad-1900-0000-fd51-4facda080000 pid=2266 /usr/lib/apt/methods/rred write-file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=1070f0ad-1900-0000-fd51-4facda080000 pid=2266 execve guuid=d212b7cd-1900-0000-fd51-4fac4b090000 pid=2379 /usr/lib/apt/methods/store guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=d212b7cd-1900-0000-fd51-4fac4b090000 pid=2379 execve guuid=c77bd9d1-1900-0000-fd51-4fac57090000 pid=2391 /usr/lib/apt/methods/store write-file guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=c77bd9d1-1900-0000-fd51-4fac57090000 pid=2391 execve guuid=f43c4aff-1900-0000-fd51-4fac89090000 pid=2441 /usr/bin/dpkg guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=f43c4aff-1900-0000-fd51-4fac89090000 pid=2441 execve guuid=f21e8d16-1b00-0000-fd51-4facbb0b0000 pid=3003 /usr/bin/dpkg guuid=df836051-1900-0000-fd51-4facca070000 pid=1994->guuid=f21e8d16-1b00-0000-fd51-4facbb0b0000 pid=3003 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=3657d75f-1900-0000-fd51-4facf0070000 pid=2032->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=3657d75f-1900-0000-fd51-4facf0070000 pid=2032->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=cbe22577-1900-0000-fd51-4fac20080000 pid=2080 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074->guuid=cbe22577-1900-0000-fd51-4fac20080000 pid=2080 clone guuid=5c4d7a93-1900-0000-fd51-4fac71080000 pid=2161 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074->guuid=5c4d7a93-1900-0000-fd51-4fac71080000 pid=2161 clone guuid=984df2a2-1900-0000-fd51-4facb9080000 pid=2233 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074->guuid=984df2a2-1900-0000-fd51-4facb9080000 pid=2233 clone guuid=6bca7ab7-1900-0000-fd51-4fac07090000 pid=2311 /usr/lib/apt/methods/gpgv delete-file write-file guuid=e68b5b75-1900-0000-fd51-4fac1a080000 pid=2074->guuid=6bca7ab7-1900-0000-fd51-4fac07090000 pid=2311 clone guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087 /usr/bin/apt-key write-file guuid=cbe22577-1900-0000-fd51-4fac20080000 pid=2080->guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087 execve guuid=d8e45c7a-1900-0000-fd51-4fac28080000 pid=2088 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=d8e45c7a-1900-0000-fd51-4fac28080000 pid=2088 clone guuid=e663787a-1900-0000-fd51-4fac29080000 pid=2089 /usr/bin/apt-config guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=e663787a-1900-0000-fd51-4fac29080000 pid=2089 execve guuid=084e7681-1900-0000-fd51-4fac33080000 pid=2099 /usr/bin/apt-config guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=084e7681-1900-0000-fd51-4fac33080000 pid=2099 execve guuid=9d18a983-1900-0000-fd51-4fac39080000 pid=2105 /usr/bin/apt-config guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=9d18a983-1900-0000-fd51-4fac39080000 pid=2105 execve guuid=85863e85-1900-0000-fd51-4fac3f080000 pid=2111 /usr/bin/apt-config guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=85863e85-1900-0000-fd51-4fac3f080000 pid=2111 execve guuid=fcf2918c-1900-0000-fd51-4fac4d080000 pid=2125 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=fcf2918c-1900-0000-fd51-4fac4d080000 pid=2125 clone guuid=66f6b28c-1900-0000-fd51-4fac4e080000 pid=2126 /usr/bin/apt-config guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=66f6b28c-1900-0000-fd51-4fac4e080000 pid=2126 execve guuid=2d6d4a8e-1900-0000-fd51-4fac56080000 pid=2134 /usr/bin/mktemp guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=2d6d4a8e-1900-0000-fd51-4fac56080000 pid=2134 execve guuid=551d8d8e-1900-0000-fd51-4fac57080000 pid=2135 /usr/bin/chmod guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=551d8d8e-1900-0000-fd51-4fac57080000 pid=2135 execve guuid=5e26c08e-1900-0000-fd51-4fac59080000 pid=2137 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=5e26c08e-1900-0000-fd51-4fac59080000 pid=2137 clone guuid=f25acf8e-1900-0000-fd51-4fac5a080000 pid=2138 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=f25acf8e-1900-0000-fd51-4fac5a080000 pid=2138 clone guuid=676b2f8f-1900-0000-fd51-4fac5d080000 pid=2141 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=676b2f8f-1900-0000-fd51-4fac5d080000 pid=2141 clone guuid=bf9c9a8f-1900-0000-fd51-4fac61080000 pid=2145 /usr/bin/dash guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=bf9c9a8f-1900-0000-fd51-4fac61080000 pid=2145 clone guuid=4b9cb68f-1900-0000-fd51-4fac62080000 pid=2146 /usr/bin/gpgv guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=4b9cb68f-1900-0000-fd51-4fac62080000 pid=2146 execve guuid=2e3a3792-1900-0000-fd51-4fac6c080000 pid=2156 /usr/bin/rm delete-file guuid=19cee479-1900-0000-fd51-4fac27080000 pid=2087->guuid=2e3a3792-1900-0000-fd51-4fac6c080000 pid=2156 execve guuid=6eba687c-1900-0000-fd51-4fac2b080000 pid=2091 /usr/bin/dpkg guuid=e663787a-1900-0000-fd51-4fac29080000 pid=2089->guuid=6eba687c-1900-0000-fd51-4fac2b080000 pid=2091 execve guuid=f9653883-1900-0000-fd51-4fac36080000 pid=2102 /usr/bin/dpkg guuid=084e7681-1900-0000-fd51-4fac33080000 pid=2099->guuid=f9653883-1900-0000-fd51-4fac36080000 pid=2102 execve guuid=f27b8b84-1900-0000-fd51-4fac3d080000 pid=2109 /usr/bin/dpkg guuid=9d18a983-1900-0000-fd51-4fac39080000 pid=2105->guuid=f27b8b84-1900-0000-fd51-4fac3d080000 pid=2109 execve guuid=385c3986-1900-0000-fd51-4fac41080000 pid=2113 /usr/bin/dpkg guuid=85863e85-1900-0000-fd51-4fac3f080000 pid=2111->guuid=385c3986-1900-0000-fd51-4fac41080000 pid=2113 execve guuid=9bc4ad8d-1900-0000-fd51-4fac53080000 pid=2131 /usr/bin/dpkg guuid=66f6b28c-1900-0000-fd51-4fac4e080000 pid=2126->guuid=9bc4ad8d-1900-0000-fd51-4fac53080000 pid=2131 execve guuid=8814d78e-1900-0000-fd51-4fac5b080000 pid=2139 /usr/bin/dash guuid=f25acf8e-1900-0000-fd51-4fac5a080000 pid=2138->guuid=8814d78e-1900-0000-fd51-4fac5b080000 pid=2139 clone guuid=586cdc8e-1900-0000-fd51-4fac5c080000 pid=2140 /usr/bin/sed guuid=f25acf8e-1900-0000-fd51-4fac5a080000 pid=2138->guuid=586cdc8e-1900-0000-fd51-4fac5c080000 pid=2140 execve guuid=ab22388f-1900-0000-fd51-4fac5e080000 pid=2142 /usr/bin/dash guuid=676b2f8f-1900-0000-fd51-4fac5d080000 pid=2141->guuid=ab22388f-1900-0000-fd51-4fac5e080000 pid=2142 clone guuid=6ed23c8f-1900-0000-fd51-4fac5f080000 pid=2143 /usr/bin/sed guuid=676b2f8f-1900-0000-fd51-4fac5d080000 pid=2141->guuid=6ed23c8f-1900-0000-fd51-4fac5f080000 pid=2143 execve guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165 /usr/bin/apt-key write-file guuid=5c4d7a93-1900-0000-fd51-4fac71080000 pid=2161->guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165 execve guuid=54c9be94-1900-0000-fd51-4fac76080000 pid=2166 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=54c9be94-1900-0000-fd51-4fac76080000 pid=2166 clone guuid=bfd7d394-1900-0000-fd51-4fac78080000 pid=2168 /usr/bin/apt-config guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=bfd7d394-1900-0000-fd51-4fac78080000 pid=2168 execve guuid=db0ae096-1900-0000-fd51-4fac81080000 pid=2177 /usr/bin/apt-config guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=db0ae096-1900-0000-fd51-4fac81080000 pid=2177 execve guuid=49704b99-1900-0000-fd51-4fac89080000 pid=2185 /usr/bin/apt-config guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=49704b99-1900-0000-fd51-4fac89080000 pid=2185 execve guuid=ed31469b-1900-0000-fd51-4fac8f080000 pid=2191 /usr/bin/apt-config guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=ed31469b-1900-0000-fd51-4fac8f080000 pid=2191 execve guuid=1bc4e49c-1900-0000-fd51-4fac96080000 pid=2198 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=1bc4e49c-1900-0000-fd51-4fac96080000 pid=2198 clone guuid=ecf21f9d-1900-0000-fd51-4fac98080000 pid=2200 /usr/bin/apt-config guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=ecf21f9d-1900-0000-fd51-4fac98080000 pid=2200 execve guuid=da66b49e-1900-0000-fd51-4fac9f080000 pid=2207 /usr/bin/mktemp guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=da66b49e-1900-0000-fd51-4fac9f080000 pid=2207 execve guuid=567e029f-1900-0000-fd51-4faca1080000 pid=2209 /usr/bin/chmod guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=567e029f-1900-0000-fd51-4faca1080000 pid=2209 execve guuid=4ea6359f-1900-0000-fd51-4faca3080000 pid=2211 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=4ea6359f-1900-0000-fd51-4faca3080000 pid=2211 clone guuid=d5c84a9f-1900-0000-fd51-4faca4080000 pid=2212 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=d5c84a9f-1900-0000-fd51-4faca4080000 pid=2212 clone guuid=945fab9f-1900-0000-fd51-4faca8080000 pid=2216 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=945fab9f-1900-0000-fd51-4faca8080000 pid=2216 clone guuid=b5c408a0-1900-0000-fd51-4facad080000 pid=2221 /usr/bin/dash guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=b5c408a0-1900-0000-fd51-4facad080000 pid=2221 clone guuid=b9161fa0-1900-0000-fd51-4facae080000 pid=2222 /usr/bin/gpgv guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=b9161fa0-1900-0000-fd51-4facae080000 pid=2222 execve guuid=ed81fea1-1900-0000-fd51-4facb5080000 pid=2229 /usr/bin/rm delete-file guuid=25618b94-1900-0000-fd51-4fac75080000 pid=2165->guuid=ed81fea1-1900-0000-fd51-4facb5080000 pid=2229 execve guuid=52256596-1900-0000-fd51-4fac7f080000 pid=2175 /usr/bin/dpkg guuid=bfd7d394-1900-0000-fd51-4fac78080000 pid=2168->guuid=52256596-1900-0000-fd51-4fac7f080000 pid=2175 execve guuid=f30cdb98-1900-0000-fd51-4fac87080000 pid=2183 /usr/bin/dpkg guuid=db0ae096-1900-0000-fd51-4fac81080000 pid=2177->guuid=f30cdb98-1900-0000-fd51-4fac87080000 pid=2183 execve guuid=6173c39a-1900-0000-fd51-4fac8d080000 pid=2189 /usr/bin/dpkg guuid=49704b99-1900-0000-fd51-4fac89080000 pid=2185->guuid=6173c39a-1900-0000-fd51-4fac8d080000 pid=2189 execve guuid=3fad349c-1900-0000-fd51-4fac92080000 pid=2194 /usr/bin/dpkg guuid=ed31469b-1900-0000-fd51-4fac8f080000 pid=2191->guuid=3fad349c-1900-0000-fd51-4fac92080000 pid=2194 execve guuid=727a3c9e-1900-0000-fd51-4fac9d080000 pid=2205 /usr/bin/dpkg guuid=ecf21f9d-1900-0000-fd51-4fac98080000 pid=2200->guuid=727a3c9e-1900-0000-fd51-4fac9d080000 pid=2205 execve guuid=c25a549f-1900-0000-fd51-4faca5080000 pid=2213 /usr/bin/dash guuid=d5c84a9f-1900-0000-fd51-4faca4080000 pid=2212->guuid=c25a549f-1900-0000-fd51-4faca5080000 pid=2213 clone guuid=595e599f-1900-0000-fd51-4faca6080000 pid=2214 /usr/bin/sed guuid=d5c84a9f-1900-0000-fd51-4faca4080000 pid=2212->guuid=595e599f-1900-0000-fd51-4faca6080000 pid=2214 execve guuid=1904b49f-1900-0000-fd51-4faca9080000 pid=2217 /usr/bin/dash guuid=945fab9f-1900-0000-fd51-4faca8080000 pid=2216->guuid=1904b49f-1900-0000-fd51-4faca9080000 pid=2217 clone guuid=3393b99f-1900-0000-fd51-4facaa080000 pid=2218 /usr/bin/sed guuid=945fab9f-1900-0000-fd51-4faca8080000 pid=2216->guuid=3393b99f-1900-0000-fd51-4facaa080000 pid=2218 execve guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237 /usr/bin/apt-key write-file guuid=984df2a2-1900-0000-fd51-4facb9080000 pid=2233->guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237 execve guuid=aa22b2a4-1900-0000-fd51-4facbf080000 pid=2239 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=aa22b2a4-1900-0000-fd51-4facbf080000 pid=2239 clone guuid=9245c6a4-1900-0000-fd51-4facc0080000 pid=2240 /usr/bin/apt-config guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=9245c6a4-1900-0000-fd51-4facc0080000 pid=2240 execve guuid=8fb4a2ac-1900-0000-fd51-4facd3080000 pid=2259 /usr/bin/apt-config guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=8fb4a2ac-1900-0000-fd51-4facd3080000 pid=2259 execve guuid=905ffaad-1900-0000-fd51-4facdb080000 pid=2267 /usr/bin/apt-config guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=905ffaad-1900-0000-fd51-4facdb080000 pid=2267 execve guuid=dd0b68af-1900-0000-fd51-4face0080000 pid=2272 /usr/bin/apt-config guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=dd0b68af-1900-0000-fd51-4face0080000 pid=2272 execve guuid=9d7ff5b0-1900-0000-fd51-4face4080000 pid=2276 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=9d7ff5b0-1900-0000-fd51-4face4080000 pid=2276 clone guuid=ce6e2eb1-1900-0000-fd51-4face6080000 pid=2278 /usr/bin/apt-config guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=ce6e2eb1-1900-0000-fd51-4face6080000 pid=2278 execve guuid=813e98b2-1900-0000-fd51-4faceb080000 pid=2283 /usr/bin/mktemp guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=813e98b2-1900-0000-fd51-4faceb080000 pid=2283 execve guuid=7c55d4b2-1900-0000-fd51-4faced080000 pid=2285 /usr/bin/chmod guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=7c55d4b2-1900-0000-fd51-4faced080000 pid=2285 execve guuid=661402b3-1900-0000-fd51-4facee080000 pid=2286 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=661402b3-1900-0000-fd51-4facee080000 pid=2286 clone guuid=fd3311b3-1900-0000-fd51-4facf0080000 pid=2288 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=fd3311b3-1900-0000-fd51-4facf0080000 pid=2288 clone guuid=74567bb3-1900-0000-fd51-4facf4080000 pid=2292 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=74567bb3-1900-0000-fd51-4facf4080000 pid=2292 clone guuid=fb4be0b3-1900-0000-fd51-4facf9080000 pid=2297 /usr/bin/dash guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=fb4be0b3-1900-0000-fd51-4facf9080000 pid=2297 clone guuid=818af9b3-1900-0000-fd51-4facfa080000 pid=2298 /usr/bin/gpgv guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=818af9b3-1900-0000-fd51-4facfa080000 pid=2298 execve guuid=632f47b6-1900-0000-fd51-4fac04090000 pid=2308 /usr/bin/rm delete-file guuid=80935aa4-1900-0000-fd51-4facbd080000 pid=2237->guuid=632f47b6-1900-0000-fd51-4fac04090000 pid=2308 execve guuid=c7f6b5a7-1900-0000-fd51-4facca080000 pid=2250 /usr/bin/dpkg guuid=9245c6a4-1900-0000-fd51-4facc0080000 pid=2240->guuid=c7f6b5a7-1900-0000-fd51-4facca080000 pid=2250 execve guuid=c78590ad-1900-0000-fd51-4facd8080000 pid=2264 /usr/bin/dpkg guuid=8fb4a2ac-1900-0000-fd51-4facd3080000 pid=2259->guuid=c78590ad-1900-0000-fd51-4facd8080000 pid=2264 execve guuid=d064faae-1900-0000-fd51-4facde080000 pid=2270 /usr/bin/dpkg guuid=905ffaad-1900-0000-fd51-4facdb080000 pid=2267->guuid=d064faae-1900-0000-fd51-4facde080000 pid=2270 execve guuid=3ecb87b0-1900-0000-fd51-4face2080000 pid=2274 /usr/bin/dpkg guuid=dd0b68af-1900-0000-fd51-4face0080000 pid=2272->guuid=3ecb87b0-1900-0000-fd51-4face2080000 pid=2274 execve guuid=8ffa2eb2-1900-0000-fd51-4face9080000 pid=2281 /usr/bin/dpkg guuid=ce6e2eb1-1900-0000-fd51-4face6080000 pid=2278->guuid=8ffa2eb2-1900-0000-fd51-4face9080000 pid=2281 execve guuid=0a3c1eb3-1900-0000-fd51-4facf1080000 pid=2289 /usr/bin/dash guuid=fd3311b3-1900-0000-fd51-4facf0080000 pid=2288->guuid=0a3c1eb3-1900-0000-fd51-4facf1080000 pid=2289 clone guuid=d59728b3-1900-0000-fd51-4facf2080000 pid=2290 /usr/bin/sed guuid=fd3311b3-1900-0000-fd51-4facf0080000 pid=2288->guuid=d59728b3-1900-0000-fd51-4facf2080000 pid=2290 execve guuid=ab3288b3-1900-0000-fd51-4facf5080000 pid=2293 /usr/bin/dash guuid=74567bb3-1900-0000-fd51-4facf4080000 pid=2292->guuid=ab3288b3-1900-0000-fd51-4facf5080000 pid=2293 clone guuid=260292b3-1900-0000-fd51-4facf7080000 pid=2295 /usr/bin/sed guuid=74567bb3-1900-0000-fd51-4facf4080000 pid=2292->guuid=260292b3-1900-0000-fd51-4facf7080000 pid=2295 execve guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316 /usr/bin/apt-key write-file guuid=6bca7ab7-1900-0000-fd51-4fac07090000 pid=2311->guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316 execve guuid=a6702db9-1900-0000-fd51-4fac0e090000 pid=2318 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=a6702db9-1900-0000-fd51-4fac0e090000 pid=2318 clone guuid=333d40b9-1900-0000-fd51-4fac0f090000 pid=2319 /usr/bin/apt-config guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=333d40b9-1900-0000-fd51-4fac0f090000 pid=2319 execve guuid=8cf60dbb-1900-0000-fd51-4fac16090000 pid=2326 /usr/bin/apt-config guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=8cf60dbb-1900-0000-fd51-4fac16090000 pid=2326 execve guuid=001b5fbc-1900-0000-fd51-4fac1d090000 pid=2333 /usr/bin/apt-config guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=001b5fbc-1900-0000-fd51-4fac1d090000 pid=2333 execve guuid=2983b5c3-1900-0000-fd51-4fac27090000 pid=2343 /usr/bin/apt-config guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=2983b5c3-1900-0000-fd51-4fac27090000 pid=2343 execve guuid=c96c87c9-1900-0000-fd51-4fac33090000 pid=2355 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=c96c87c9-1900-0000-fd51-4fac33090000 pid=2355 clone guuid=9af4aec9-1900-0000-fd51-4fac34090000 pid=2356 /usr/bin/apt-config guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=9af4aec9-1900-0000-fd51-4fac34090000 pid=2356 execve guuid=1edd4bcb-1900-0000-fd51-4fac3c090000 pid=2364 /usr/bin/mktemp guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=1edd4bcb-1900-0000-fd51-4fac3c090000 pid=2364 execve guuid=e3767fcb-1900-0000-fd51-4fac3e090000 pid=2366 /usr/bin/chmod guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=e3767fcb-1900-0000-fd51-4fac3e090000 pid=2366 execve guuid=1a82a7cb-1900-0000-fd51-4fac3f090000 pid=2367 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=1a82a7cb-1900-0000-fd51-4fac3f090000 pid=2367 clone guuid=7fd8cccb-1900-0000-fd51-4fac41090000 pid=2369 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=7fd8cccb-1900-0000-fd51-4fac41090000 pid=2369 clone guuid=b34414cd-1900-0000-fd51-4fac46090000 pid=2374 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=b34414cd-1900-0000-fd51-4fac46090000 pid=2374 clone guuid=381999cd-1900-0000-fd51-4fac49090000 pid=2377 /usr/bin/dash guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=381999cd-1900-0000-fd51-4fac49090000 pid=2377 clone guuid=3b4fa9cd-1900-0000-fd51-4fac4a090000 pid=2378 /usr/bin/gpgv guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=3b4fa9cd-1900-0000-fd51-4fac4a090000 pid=2378 execve guuid=f643c4cf-1900-0000-fd51-4fac4e090000 pid=2382 /usr/bin/rm delete-file guuid=7165d6b8-1900-0000-fd51-4fac0c090000 pid=2316->guuid=f643c4cf-1900-0000-fd51-4fac4e090000 pid=2382 execve guuid=e4773eba-1900-0000-fd51-4fac13090000 pid=2323 /usr/bin/dpkg guuid=333d40b9-1900-0000-fd51-4fac0f090000 pid=2319->guuid=e4773eba-1900-0000-fd51-4fac13090000 pid=2323 execve guuid=23adfbbb-1900-0000-fd51-4fac1b090000 pid=2331 /usr/bin/dpkg guuid=8cf60dbb-1900-0000-fd51-4fac16090000 pid=2326->guuid=23adfbbb-1900-0000-fd51-4fac1b090000 pid=2331 execve guuid=223657bd-1900-0000-fd51-4fac1f090000 pid=2335 /usr/bin/dpkg guuid=001b5fbc-1900-0000-fd51-4fac1d090000 pid=2333->guuid=223657bd-1900-0000-fd51-4fac1f090000 pid=2335 execve guuid=37e192c4-1900-0000-fd51-4fac2b090000 pid=2347 /usr/bin/dpkg guuid=2983b5c3-1900-0000-fd51-4fac27090000 pid=2343->guuid=37e192c4-1900-0000-fd51-4fac2b090000 pid=2347 execve guuid=724ac9ca-1900-0000-fd51-4fac39090000 pid=2361 /usr/bin/dpkg guuid=9af4aec9-1900-0000-fd51-4fac34090000 pid=2356->guuid=724ac9ca-1900-0000-fd51-4fac39090000 pid=2361 execve guuid=b871d6cb-1900-0000-fd51-4fac42090000 pid=2370 /usr/bin/dash guuid=7fd8cccb-1900-0000-fd51-4fac41090000 pid=2369->guuid=b871d6cb-1900-0000-fd51-4fac42090000 pid=2370 clone guuid=7652e5cb-1900-0000-fd51-4fac43090000 pid=2371 /usr/bin/sed guuid=7fd8cccb-1900-0000-fd51-4fac41090000 pid=2369->guuid=7652e5cb-1900-0000-fd51-4fac43090000 pid=2371 execve guuid=b2bc1bcd-1900-0000-fd51-4fac47090000 pid=2375 /usr/bin/dash guuid=b34414cd-1900-0000-fd51-4fac46090000 pid=2374->guuid=b2bc1bcd-1900-0000-fd51-4fac47090000 pid=2375 clone guuid=645c22cd-1900-0000-fd51-4fac48090000 pid=2376 /usr/bin/sed guuid=b34414cd-1900-0000-fd51-4fac46090000 pid=2374->guuid=645c22cd-1900-0000-fd51-4fac48090000 pid=2376 execve guuid=9c83a31c-1b00-0000-fd51-4facc00b0000 pid=3008 /usr/bin/dpkg guuid=c552061b-1b00-0000-fd51-4facbf0b0000 pid=3007->guuid=9c83a31c-1b00-0000-fd51-4facc00b0000 pid=3008 execve
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery execution linux privilege_escalation
Behaviour
Software Deployment Tools
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Legitimate hosting services abused for malware hosting/C2
Reads Bash history
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4bbbe5e8fbfb58e8bdc5d2275b61ebae9cedd6ba0bf6f35d3db63426312482a2

(this sample)

  
Delivery method
Distributed via web download

Comments