MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 53554c8b213ad04cd5c7a14edfc92cef19d19060acef548091a4a3504aeb5941. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 9


Intelligence 9 IOCs YARA File information Comments

SHA256 hash: 53554c8b213ad04cd5c7a14edfc92cef19d19060acef548091a4a3504aeb5941
SHA3-384 hash: 5968500ac8e715a00541cd39aa0abdf2c191ab443cca9be7f1ce9698c4686c41ba116eb22f597ea01d1c952bfdde3345
SHA1 hash: 2833525e2009030aea15555e5f9f0a6724f8286a
MD5 hash: 3715512fa60287e2a940fb8c0ab01f30
humanhash: fish-cola-pip-magazine
File name:check.sh
Download: download sample
File size:917 bytes
First seen:2026-01-13 16:17:41 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:VUeYj+H1LDMK9CFdYhEnHQ6Yw9I5TRrQZaZl1cSRs/:VUeYj+H1LDMK9CnYhEjwSjSu
TLSH T1A8117D82B6357D742CC8812E72E69CAD6046017F5A9B7F9878DE99B60F08980B054FF4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
33
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Likely Malicious
Threat level:
  7.5/10
Confidence:
100%
Tags:
bash lolbin
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=246b4c6b-1800-0000-673c-28dd12090000 pid=2322 /usr/bin/sudo guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324 /tmp/sample.bin guuid=246b4c6b-1800-0000-673c-28dd12090000 pid=2322->guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324 execve guuid=1995ac6e-1800-0000-673c-28dd16090000 pid=2326 /usr/bin/bash guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=1995ac6e-1800-0000-673c-28dd16090000 pid=2326 clone guuid=2643d66e-1800-0000-673c-28dd17090000 pid=2327 /usr/bin/grep guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=2643d66e-1800-0000-673c-28dd17090000 pid=2327 execve guuid=0f4e4b6f-1800-0000-673c-28dd19090000 pid=2329 /usr/bin/bash guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=0f4e4b6f-1800-0000-673c-28dd19090000 pid=2329 clone guuid=a1a55b6f-1800-0000-673c-28dd1a090000 pid=2330 /usr/bin/bash guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=a1a55b6f-1800-0000-673c-28dd1a090000 pid=2330 clone guuid=11b9c56f-1800-0000-673c-28dd1e090000 pid=2334 /usr/bin/pgrep guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=11b9c56f-1800-0000-673c-28dd1e090000 pid=2334 execve guuid=2fd74076-1800-0000-673c-28dd2e090000 pid=2350 /usr/bin/rm delete-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=2fd74076-1800-0000-673c-28dd2e090000 pid=2350 execve guuid=38dd5f79-1800-0000-673c-28dd36090000 pid=2358 /usr/bin/sleep guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=38dd5f79-1800-0000-673c-28dd36090000 pid=2358 execve guuid=90d705a4-1900-0000-673c-28dd100c0000 pid=3088 /usr/bin/curl net send-data write-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=90d705a4-1900-0000-673c-28dd100c0000 pid=3088 execve guuid=2d77bddf-1900-0000-673c-28dd8e0c0000 pid=3214 /usr/bin/wget net send-data write-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=2d77bddf-1900-0000-673c-28dd8e0c0000 pid=3214 execve guuid=5f18de1a-1a00-0000-673c-28ddd40c0000 pid=3284 /usr/bin/sleep guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=5f18de1a-1a00-0000-673c-28ddd40c0000 pid=3284 execve guuid=fb619709-1b00-0000-673c-28ddcd0e0000 pid=3789 /usr/bin/chmod guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=fb619709-1b00-0000-673c-28ddcd0e0000 pid=3789 execve guuid=d0b6f809-1b00-0000-673c-28ddd10e0000 pid=3793 /var/tmp/syst3md mprotect-exec guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=d0b6f809-1b00-0000-673c-28ddd10e0000 pid=3793 execve guuid=7827cb0d-1b00-0000-673c-28dddf0e0000 pid=3807 /usr/bin/rm guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=7827cb0d-1b00-0000-673c-28dddf0e0000 pid=3807 execve guuid=a83d200e-1b00-0000-673c-28dde50e0000 pid=3813 /usr/bin/sleep guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=a83d200e-1b00-0000-673c-28dde50e0000 pid=3813 execve guuid=9b7e9a38-1c00-0000-673c-28dd2b100000 pid=4139 /usr/bin/rm guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=9b7e9a38-1c00-0000-673c-28dd2b100000 pid=4139 execve guuid=fc9a3e39-1c00-0000-673c-28dd2c100000 pid=4140 /usr/bin/rm delete-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=fc9a3e39-1c00-0000-673c-28dd2c100000 pid=4140 execve guuid=45ab003a-1c00-0000-673c-28dd2d100000 pid=4141 /usr/bin/rm delete-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=45ab003a-1c00-0000-673c-28dd2d100000 pid=4141 execve guuid=24d3d13a-1c00-0000-673c-28dd2e100000 pid=4142 /usr/bin/rm delete-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=24d3d13a-1c00-0000-673c-28dd2e100000 pid=4142 execve guuid=88374f3b-1c00-0000-673c-28dd2f100000 pid=4143 /usr/bin/rm delete-file guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=88374f3b-1c00-0000-673c-28dd2f100000 pid=4143 execve guuid=e3a2b43b-1c00-0000-673c-28dd30100000 pid=4144 /usr/bin/rm guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=e3a2b43b-1c00-0000-673c-28dd30100000 pid=4144 execve guuid=7785203c-1c00-0000-673c-28dd31100000 pid=4145 /usr/bin/clear guuid=5c68086e-1800-0000-673c-28dd14090000 pid=2324->guuid=7785203c-1c00-0000-673c-28dd31100000 pid=4145 execve guuid=bfdb5d6f-1800-0000-673c-28dd1c090000 pid=2332 /usr/bin/bash guuid=0f4e4b6f-1800-0000-673c-28dd19090000 pid=2329->guuid=bfdb5d6f-1800-0000-673c-28dd1c090000 pid=2332 clone 66bedfa7-f5b5-5fb6-937f-c65dc36db775 77.221.152.211:80 guuid=90d705a4-1900-0000-673c-28dd100c0000 pid=3088->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 85B guuid=2d77bddf-1900-0000-673c-28dd8e0c0000 pid=3214->66bedfa7-f5b5-5fb6-937f-c65dc36db775 send: 136B guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803 /var/tmp/syst3md net send-data zombie guuid=d0b6f809-1b00-0000-673c-28ddd10e0000 pid=3793->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803 clone 264d1a60-de56-5988-9f1d-ff71ad4aa4d6 141.94.96.71:3333 guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->264d1a60-de56-5988-9f1d-ff71ad4aa4d6 send: 546B guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3808 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3808 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3809 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3809 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3810 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3810 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3811 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3811 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3812 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3812 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3822 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3822 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3823 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3823 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3824 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3824 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3825 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3825 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3840 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3840 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3841 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3841 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3842 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3842 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3843 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3843 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3864 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3864 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3865 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3865 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3866 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3866 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3867 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3867 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3888 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3888 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3889 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3889 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3890 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3890 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3891 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3891 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3900 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3900 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3901 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3901 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3902 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3902 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3903 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3903 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3919 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3919 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3920 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3920 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3922 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3922 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3923 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3923 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3945 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3945 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3946 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3946 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3947 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3947 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3948 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3948 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3966 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3966 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3967 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3967 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3968 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3968 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3969 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3969 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3993 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3993 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3994 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3994 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3995 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3995 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3996 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3996 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4019 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4019 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4020 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4020 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4021 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4021 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4022 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4022 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4045 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4045 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4046 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4046 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4047 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4047 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4048 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4048 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4070 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4070 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4071 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4071 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4072 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4072 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4073 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4073 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4146 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4146 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4147 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4147 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4148 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4148 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4149 /var/tmp/syst3md zombie guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4149 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4152 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4152 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4153 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4153 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4154 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4154 clone guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4155 /var/tmp/syst3md guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=3803->guuid=0a2b6b0d-1b00-0000-673c-28dddb0e0000 pid=4155 clone
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-13 16:10:20 UTC
File Type:
Text (Shell)
AV detection:
4 of 36 (11.11%)
Threat level:
  3/5
Result
Malware family:
xmrig_linux
Score:
  10/10
Tags:
family:xmrig family:xmrig_linux antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Checks hardware identifiers (DMI)
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Reads hardware information
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
XMRig Miner payload
Xmrig family
Xmrig_linux family
xmrig
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 53554c8b213ad04cd5c7a14edfc92cef19d19060acef548091a4a3504aeb5941

(this sample)

  
Delivery method
Distributed via web download

Comments