MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 4f49ff8f307e2c92e88ccf16f58460741df58f48a94238e6cb39e7f9afec4875. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 4f49ff8f307e2c92e88ccf16f58460741df58f48a94238e6cb39e7f9afec4875
SHA3-384 hash: 7ea57ebf564f80df5bfcbd4bd94936f40b4ab9627f54433ab3897eb379bcfd9dbb9353670afac5934ecb9bce9f73e18e
SHA1 hash: 365528c689b2d24adc2ea56e558eff5ce6e9d80b
MD5 hash: e3a81cb45131855896ce727e4d5de8c7
humanhash: massachusetts-table-bravo-montana
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-05-30 20:01:59 UTC
Last seen:2026-05-31 02:43:54 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTdUBppm7iq2AulNXYq4HvXDG+NjVsNXYrkJ:VdUJm7ipPiq4HvXDGmKi2
TLSH T166D097A7602301B4A8F2CC11F6DA68147004ABBE1C68E21FB92304B06F05314B0C0372
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.155.8.56/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
54
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-30T17:20:00Z UTC
Last seen:
2026-05-31T23:44:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=3daf8037-1800-0000-7e4a-141d520c0000 pid=3154 /usr/bin/sudo guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163 /tmp/sample.bin guuid=3daf8037-1800-0000-7e4a-141d520c0000 pid=3154->guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163 execve guuid=ff48e83a-1800-0000-7e4a-141d5d0c0000 pid=3165 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=ff48e83a-1800-0000-7e4a-141d5d0c0000 pid=3165 execve guuid=e5e8b33b-1800-0000-7e4a-141d600c0000 pid=3168 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=e5e8b33b-1800-0000-7e4a-141d600c0000 pid=3168 execve guuid=7713d573-1800-0000-7e4a-141d8e0c0000 pid=3214 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=7713d573-1800-0000-7e4a-141d8e0c0000 pid=3214 execve guuid=0cf51174-1800-0000-7e4a-141d900c0000 pid=3216 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0cf51174-1800-0000-7e4a-141d900c0000 pid=3216 clone guuid=1543ad75-1800-0000-7e4a-141d970c0000 pid=3223 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=1543ad75-1800-0000-7e4a-141d970c0000 pid=3223 execve guuid=0370f275-1800-0000-7e4a-141d980c0000 pid=3224 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0370f275-1800-0000-7e4a-141d980c0000 pid=3224 execve guuid=8927b0cc-1800-0000-7e4a-141d0a0d0000 pid=3338 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=8927b0cc-1800-0000-7e4a-141d0a0d0000 pid=3338 execve guuid=382938cd-1800-0000-7e4a-141d0c0d0000 pid=3340 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=382938cd-1800-0000-7e4a-141d0c0d0000 pid=3340 clone guuid=2fafd9cd-1800-0000-7e4a-141d0f0d0000 pid=3343 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=2fafd9cd-1800-0000-7e4a-141d0f0d0000 pid=3343 execve guuid=6ec81dce-1800-0000-7e4a-141d110d0000 pid=3345 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=6ec81dce-1800-0000-7e4a-141d110d0000 pid=3345 execve guuid=87cc5501-1900-0000-7e4a-141d4d0d0000 pid=3405 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=87cc5501-1900-0000-7e4a-141d4d0d0000 pid=3405 execve guuid=904f8a01-1900-0000-7e4a-141d4e0d0000 pid=3406 /tmp/RENO guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=904f8a01-1900-0000-7e4a-141d4e0d0000 pid=3406 execve guuid=b0d1a501-1900-0000-7e4a-141d510d0000 pid=3409 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=b0d1a501-1900-0000-7e4a-141d510d0000 pid=3409 execve guuid=8981e301-1900-0000-7e4a-141d520d0000 pid=3410 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=8981e301-1900-0000-7e4a-141d520d0000 pid=3410 execve guuid=5ed47241-1900-0000-7e4a-141ddd0d0000 pid=3549 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=5ed47241-1900-0000-7e4a-141ddd0d0000 pid=3549 execve guuid=fbd6af41-1900-0000-7e4a-141ddf0d0000 pid=3551 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=fbd6af41-1900-0000-7e4a-141ddf0d0000 pid=3551 clone guuid=af5e7642-1900-0000-7e4a-141de40d0000 pid=3556 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=af5e7642-1900-0000-7e4a-141de40d0000 pid=3556 execve guuid=a1570043-1900-0000-7e4a-141de60d0000 pid=3558 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=a1570043-1900-0000-7e4a-141de60d0000 pid=3558 execve guuid=a793b874-1900-0000-7e4a-141d500e0000 pid=3664 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=a793b874-1900-0000-7e4a-141d500e0000 pid=3664 execve guuid=a3c20575-1900-0000-7e4a-141d520e0000 pid=3666 /tmp/REXJ guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=a3c20575-1900-0000-7e4a-141d520e0000 pid=3666 execve guuid=68a02175-1900-0000-7e4a-141d550e0000 pid=3669 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=68a02175-1900-0000-7e4a-141d550e0000 pid=3669 execve guuid=cded7475-1900-0000-7e4a-141d560e0000 pid=3670 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=cded7475-1900-0000-7e4a-141d560e0000 pid=3670 execve guuid=134be7b5-1900-0000-7e4a-141dca0e0000 pid=3786 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=134be7b5-1900-0000-7e4a-141dca0e0000 pid=3786 execve guuid=c8ab5cb6-1900-0000-7e4a-141dcc0e0000 pid=3788 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=c8ab5cb6-1900-0000-7e4a-141dcc0e0000 pid=3788 clone guuid=93e0b7b8-1900-0000-7e4a-141dd70e0000 pid=3799 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=93e0b7b8-1900-0000-7e4a-141dd70e0000 pid=3799 execve guuid=bb07f2b8-1900-0000-7e4a-141dd80e0000 pid=3800 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=bb07f2b8-1900-0000-7e4a-141dd80e0000 pid=3800 execve guuid=0af45508-1a00-0000-7e4a-141d8f0f0000 pid=3983 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0af45508-1a00-0000-7e4a-141d8f0f0000 pid=3983 execve guuid=bf6be908-1a00-0000-7e4a-141d910f0000 pid=3985 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=bf6be908-1a00-0000-7e4a-141d910f0000 pid=3985 clone guuid=5120ea09-1a00-0000-7e4a-141d960f0000 pid=3990 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=5120ea09-1a00-0000-7e4a-141d960f0000 pid=3990 execve guuid=5eb4730a-1a00-0000-7e4a-141d9a0f0000 pid=3994 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=5eb4730a-1a00-0000-7e4a-141d9a0f0000 pid=3994 execve guuid=8dd9cd3a-1a00-0000-7e4a-141d02100000 pid=4098 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=8dd9cd3a-1a00-0000-7e4a-141d02100000 pid=4098 execve guuid=ae7b493b-1a00-0000-7e4a-141d03100000 pid=4099 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=ae7b493b-1a00-0000-7e4a-141d03100000 pid=4099 clone guuid=bca33d3c-1a00-0000-7e4a-141d06100000 pid=4102 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=bca33d3c-1a00-0000-7e4a-141d06100000 pid=4102 execve guuid=8880383d-1a00-0000-7e4a-141d07100000 pid=4103 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=8880383d-1a00-0000-7e4a-141d07100000 pid=4103 execve guuid=3189b27c-1a00-0000-7e4a-141d97100000 pid=4247 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=3189b27c-1a00-0000-7e4a-141d97100000 pid=4247 execve guuid=0fdef87c-1a00-0000-7e4a-141d99100000 pid=4249 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0fdef87c-1a00-0000-7e4a-141d99100000 pid=4249 clone guuid=1d4c6e7e-1a00-0000-7e4a-141d9e100000 pid=4254 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=1d4c6e7e-1a00-0000-7e4a-141d9e100000 pid=4254 execve guuid=f353f97e-1a00-0000-7e4a-141da0100000 pid=4256 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=f353f97e-1a00-0000-7e4a-141da0100000 pid=4256 execve guuid=09c695b1-1a00-0000-7e4a-141d41110000 pid=4417 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=09c695b1-1a00-0000-7e4a-141d41110000 pid=4417 execve guuid=83a5d2b1-1a00-0000-7e4a-141d43110000 pid=4419 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=83a5d2b1-1a00-0000-7e4a-141d43110000 pid=4419 clone guuid=15ce20b3-1a00-0000-7e4a-141d49110000 pid=4425 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=15ce20b3-1a00-0000-7e4a-141d49110000 pid=4425 execve guuid=511c5eb3-1a00-0000-7e4a-141d4d110000 pid=4429 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=511c5eb3-1a00-0000-7e4a-141d4d110000 pid=4429 execve guuid=7a6814fc-1a00-0000-7e4a-141dd8110000 pid=4568 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=7a6814fc-1a00-0000-7e4a-141dd8110000 pid=4568 execve guuid=487666fc-1a00-0000-7e4a-141dd9110000 pid=4569 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=487666fc-1a00-0000-7e4a-141dd9110000 pid=4569 clone guuid=729420fe-1a00-0000-7e4a-141de3110000 pid=4579 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=729420fe-1a00-0000-7e4a-141de3110000 pid=4579 execve guuid=e25759fe-1a00-0000-7e4a-141de4110000 pid=4580 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=e25759fe-1a00-0000-7e4a-141de4110000 pid=4580 execve guuid=ab9ee836-1b00-0000-7e4a-141d78120000 pid=4728 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=ab9ee836-1b00-0000-7e4a-141d78120000 pid=4728 execve guuid=e4cd7f37-1b00-0000-7e4a-141d79120000 pid=4729 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=e4cd7f37-1b00-0000-7e4a-141d79120000 pid=4729 clone guuid=59857239-1b00-0000-7e4a-141d81120000 pid=4737 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=59857239-1b00-0000-7e4a-141d81120000 pid=4737 execve guuid=8200b839-1b00-0000-7e4a-141d84120000 pid=4740 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=8200b839-1b00-0000-7e4a-141d84120000 pid=4740 execve guuid=628dbb88-1b00-0000-7e4a-141d43130000 pid=4931 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=628dbb88-1b00-0000-7e4a-141d43130000 pid=4931 execve guuid=33858a89-1b00-0000-7e4a-141d46130000 pid=4934 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=33858a89-1b00-0000-7e4a-141d46130000 pid=4934 clone guuid=bdd0058b-1b00-0000-7e4a-141d4b130000 pid=4939 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=bdd0058b-1b00-0000-7e4a-141d4b130000 pid=4939 execve guuid=9a4b748b-1b00-0000-7e4a-141d4d130000 pid=4941 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=9a4b748b-1b00-0000-7e4a-141d4d130000 pid=4941 execve guuid=a7d0c1c1-1b00-0000-7e4a-141ddf130000 pid=5087 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=a7d0c1c1-1b00-0000-7e4a-141ddf130000 pid=5087 execve guuid=abf635c2-1b00-0000-7e4a-141de3130000 pid=5091 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=abf635c2-1b00-0000-7e4a-141de3130000 pid=5091 clone guuid=d942a6c4-1b00-0000-7e4a-141dea130000 pid=5098 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=d942a6c4-1b00-0000-7e4a-141dea130000 pid=5098 execve guuid=f08af5c4-1b00-0000-7e4a-141dec130000 pid=5100 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=f08af5c4-1b00-0000-7e4a-141dec130000 pid=5100 execve guuid=04b7b6ed-1b00-0000-7e4a-141d61140000 pid=5217 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=04b7b6ed-1b00-0000-7e4a-141d61140000 pid=5217 execve guuid=16df1eee-1b00-0000-7e4a-141d63140000 pid=5219 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=16df1eee-1b00-0000-7e4a-141d63140000 pid=5219 clone guuid=1eb7fbee-1b00-0000-7e4a-141d67140000 pid=5223 /usr/bin/rm guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=1eb7fbee-1b00-0000-7e4a-141d67140000 pid=5223 execve guuid=06a54eef-1b00-0000-7e4a-141d68140000 pid=5224 /usr/bin/wget net send-data write-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=06a54eef-1b00-0000-7e4a-141d68140000 pid=5224 execve guuid=9e0b7621-1c00-0000-7e4a-141dad140000 pid=5293 /usr/bin/chmod guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=9e0b7621-1c00-0000-7e4a-141dad140000 pid=5293 execve guuid=4b04b121-1c00-0000-7e4a-141dae140000 pid=5294 /usr/bin/dash guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=4b04b121-1c00-0000-7e4a-141dae140000 pid=5294 clone guuid=a71c4a22-1c00-0000-7e4a-141db0140000 pid=5296 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=a71c4a22-1c00-0000-7e4a-141db0140000 pid=5296 execve guuid=c7dfba22-1c00-0000-7e4a-141db1140000 pid=5297 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=c7dfba22-1c00-0000-7e4a-141db1140000 pid=5297 execve guuid=bf932e23-1c00-0000-7e4a-141db2140000 pid=5298 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=bf932e23-1c00-0000-7e4a-141db2140000 pid=5298 execve guuid=b3679823-1c00-0000-7e4a-141db3140000 pid=5299 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=b3679823-1c00-0000-7e4a-141db3140000 pid=5299 execve guuid=95ebff23-1c00-0000-7e4a-141db4140000 pid=5300 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=95ebff23-1c00-0000-7e4a-141db4140000 pid=5300 execve guuid=0f436924-1c00-0000-7e4a-141db5140000 pid=5301 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0f436924-1c00-0000-7e4a-141db5140000 pid=5301 execve guuid=f223bb24-1c00-0000-7e4a-141db6140000 pid=5302 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=f223bb24-1c00-0000-7e4a-141db6140000 pid=5302 execve guuid=09e61125-1c00-0000-7e4a-141db7140000 pid=5303 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=09e61125-1c00-0000-7e4a-141db7140000 pid=5303 execve guuid=eb105e25-1c00-0000-7e4a-141db8140000 pid=5304 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=eb105e25-1c00-0000-7e4a-141db8140000 pid=5304 execve guuid=17a5a925-1c00-0000-7e4a-141db9140000 pid=5305 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=17a5a925-1c00-0000-7e4a-141db9140000 pid=5305 execve guuid=c1371426-1c00-0000-7e4a-141dba140000 pid=5306 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=c1371426-1c00-0000-7e4a-141dba140000 pid=5306 execve guuid=2c8b9a26-1c00-0000-7e4a-141dbd140000 pid=5309 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=2c8b9a26-1c00-0000-7e4a-141dbd140000 pid=5309 execve guuid=cf9c1a27-1c00-0000-7e4a-141dbe140000 pid=5310 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=cf9c1a27-1c00-0000-7e4a-141dbe140000 pid=5310 execve guuid=5a338d27-1c00-0000-7e4a-141dc0140000 pid=5312 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=5a338d27-1c00-0000-7e4a-141dc0140000 pid=5312 execve guuid=0b2a0728-1c00-0000-7e4a-141dc6140000 pid=5318 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0b2a0728-1c00-0000-7e4a-141dc6140000 pid=5318 execve guuid=72b95d28-1c00-0000-7e4a-141dc7140000 pid=5319 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=72b95d28-1c00-0000-7e4a-141dc7140000 pid=5319 execve guuid=0cbfbe28-1c00-0000-7e4a-141dc8140000 pid=5320 /usr/bin/rm delete-file guuid=1f49a33a-1800-0000-7e4a-141d5b0c0000 pid=3163->guuid=0cbfbe28-1c00-0000-7e4a-141dc8140000 pid=5320 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=e5e8b33b-1800-0000-7e4a-141d600c0000 pid=3168->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=0370f275-1800-0000-7e4a-141d980c0000 pid=3224->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=6ec81dce-1800-0000-7e4a-141d110d0000 pid=3345->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407 /tmp/RENO net send-data write-file zombie guuid=904f8a01-1900-0000-7e4a-141d4e0d0000 pid=3406->guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=06aa710c-1900-0000-7e4a-141d6f0d0000 pid=3439 /usr/bin/uname guuid=e5cb9d01-1900-0000-7e4a-141d4f0d0000 pid=3407->guuid=06aa710c-1900-0000-7e4a-141d6f0d0000 pid=3439 execve guuid=8981e301-1900-0000-7e4a-141d520d0000 pid=3410->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=a1570043-1900-0000-7e4a-141de60d0000 pid=3558->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f0e81775-1900-0000-7e4a-141d540e0000 pid=3668 /tmp/REXJ zombie guuid=a3c20575-1900-0000-7e4a-141d520e0000 pid=3666->guuid=f0e81775-1900-0000-7e4a-141d540e0000 pid=3668 clone guuid=cded7475-1900-0000-7e4a-141d560e0000 pid=3670->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=bb07f2b8-1900-0000-7e4a-141dd80e0000 pid=3800->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=5eb4730a-1a00-0000-7e4a-141d9a0f0000 pid=3994->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8880383d-1a00-0000-7e4a-141d07100000 pid=4103->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f353f97e-1a00-0000-7e4a-141da0100000 pid=4256->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=511c5eb3-1a00-0000-7e4a-141d4d110000 pid=4429->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=e25759fe-1a00-0000-7e4a-141de4110000 pid=4580->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8200b839-1b00-0000-7e4a-141d84120000 pid=4740->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=9a4b748b-1b00-0000-7e4a-141d4d130000 pid=4941->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f08af5c4-1b00-0000-7e4a-141dec130000 pid=5100->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=06a54eef-1b00-0000-7e4a-141d68140000 pid=5224->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-30 20:02:26 UTC
File Type:
Text (Shell)
AV detection:
8 of 24 (33.33%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 4f49ff8f307e2c92e88ccf16f58460741df58f48a94238e6cb39e7f9afec4875

(this sample)

  
Delivery method
Distributed via web download

Comments