MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 5839d9cdeac8ae10c74362bb44efa419d09d1a2aa6514684e8cfc931d2aee09c. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: 5839d9cdeac8ae10c74362bb44efa419d09d1a2aa6514684e8cfc931d2aee09c
SHA3-384 hash: d1f24611601ea25432b26fb38d11b0c6075401136c69c6d4db1a55defbbc0300a99623fe0ca1bf20473fcdf18f119c1c
SHA1 hash: 0cd37d8be02716c4d37f55f55d72c8be3503ec2b
MD5 hash: 52daadae14ae93063518fe5a90482f40
humanhash: utah-football-fix-three
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-06-13 02:07:31 UTC
Last seen:2026-06-13 06:25:16 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTf78Cry6VtOhJrxuHAulNXYq4HvXDG+NjVsNXYrkJ:Vf7Rr55Piq4HvXDGmKi2
TLSH T1C5D02E625563023004A2AC01E0C2A800F6148B7F4882C21B721720306F02345F4E03A0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.155.8.56/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=a6403b93-1900-0000-4b68-b481380b0000 pid=2872 /usr/bin/sudo guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884 /tmp/sample.bin guuid=a6403b93-1900-0000-4b68-b481380b0000 pid=2872->guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884 execve guuid=db562a97-1900-0000-4b68-b481450b0000 pid=2885 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=db562a97-1900-0000-4b68-b481450b0000 pid=2885 execve guuid=28cef897-1900-0000-4b68-b481490b0000 pid=2889 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=28cef897-1900-0000-4b68-b481490b0000 pid=2889 execve guuid=ec27dcc0-1900-0000-4b68-b481890b0000 pid=2953 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ec27dcc0-1900-0000-4b68-b481890b0000 pid=2953 execve guuid=e14b2ec1-1900-0000-4b68-b4818b0b0000 pid=2955 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=e14b2ec1-1900-0000-4b68-b4818b0b0000 pid=2955 clone guuid=899202c3-1900-0000-4b68-b481910b0000 pid=2961 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=899202c3-1900-0000-4b68-b481910b0000 pid=2961 execve guuid=30ad53c3-1900-0000-4b68-b481920b0000 pid=2962 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=30ad53c3-1900-0000-4b68-b481920b0000 pid=2962 execve guuid=df327dea-1900-0000-4b68-b481cc0b0000 pid=3020 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=df327dea-1900-0000-4b68-b481cc0b0000 pid=3020 execve guuid=8c90ecea-1900-0000-4b68-b481ce0b0000 pid=3022 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=8c90ecea-1900-0000-4b68-b481ce0b0000 pid=3022 clone guuid=ea35f8eb-1900-0000-4b68-b481d20b0000 pid=3026 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ea35f8eb-1900-0000-4b68-b481d20b0000 pid=3026 execve guuid=3f9359ec-1900-0000-4b68-b481d40b0000 pid=3028 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=3f9359ec-1900-0000-4b68-b481d40b0000 pid=3028 execve guuid=24bb2c13-1a00-0000-4b68-b4811b0c0000 pid=3099 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=24bb2c13-1a00-0000-4b68-b4811b0c0000 pid=3099 execve guuid=c63a8a13-1a00-0000-4b68-b4811c0c0000 pid=3100 /tmp/JSDD guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=c63a8a13-1a00-0000-4b68-b4811c0c0000 pid=3100 execve guuid=26daa913-1a00-0000-4b68-b4811f0c0000 pid=3103 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=26daa913-1a00-0000-4b68-b4811f0c0000 pid=3103 execve guuid=64f7fd13-1a00-0000-4b68-b481200c0000 pid=3104 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=64f7fd13-1a00-0000-4b68-b481200c0000 pid=3104 execve guuid=e598bf3a-1a00-0000-4b68-b481610c0000 pid=3169 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=e598bf3a-1a00-0000-4b68-b481610c0000 pid=3169 execve guuid=448a1e3b-1a00-0000-4b68-b481620c0000 pid=3170 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=448a1e3b-1a00-0000-4b68-b481620c0000 pid=3170 clone guuid=dd242b3d-1a00-0000-4b68-b481670c0000 pid=3175 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=dd242b3d-1a00-0000-4b68-b481670c0000 pid=3175 execve guuid=c8bd9d3d-1a00-0000-4b68-b481690c0000 pid=3177 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=c8bd9d3d-1a00-0000-4b68-b481690c0000 pid=3177 execve guuid=1a356064-1a00-0000-4b68-b481900c0000 pid=3216 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=1a356064-1a00-0000-4b68-b481900c0000 pid=3216 execve guuid=9486a464-1a00-0000-4b68-b481920c0000 pid=3218 /tmp/QKRC guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=9486a464-1a00-0000-4b68-b481920c0000 pid=3218 execve guuid=b43bbb64-1a00-0000-4b68-b481940c0000 pid=3220 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=b43bbb64-1a00-0000-4b68-b481940c0000 pid=3220 execve guuid=d3410365-1a00-0000-4b68-b481950c0000 pid=3221 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=d3410365-1a00-0000-4b68-b481950c0000 pid=3221 execve guuid=7772758b-1a00-0000-4b68-b481bc0c0000 pid=3260 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=7772758b-1a00-0000-4b68-b481bc0c0000 pid=3260 execve guuid=9898c28b-1a00-0000-4b68-b481bd0c0000 pid=3261 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=9898c28b-1a00-0000-4b68-b481bd0c0000 pid=3261 clone guuid=ecf0b58c-1a00-0000-4b68-b481bf0c0000 pid=3263 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ecf0b58c-1a00-0000-4b68-b481bf0c0000 pid=3263 execve guuid=8042838d-1a00-0000-4b68-b481c00c0000 pid=3264 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=8042838d-1a00-0000-4b68-b481c00c0000 pid=3264 execve guuid=1a4476b5-1a00-0000-4b68-b481ec0c0000 pid=3308 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=1a4476b5-1a00-0000-4b68-b481ec0c0000 pid=3308 execve guuid=65fe34b6-1a00-0000-4b68-b481f00c0000 pid=3312 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=65fe34b6-1a00-0000-4b68-b481f00c0000 pid=3312 clone guuid=50f3efb7-1a00-0000-4b68-b481f70c0000 pid=3319 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=50f3efb7-1a00-0000-4b68-b481f70c0000 pid=3319 execve guuid=6e2530b8-1a00-0000-4b68-b481f80c0000 pid=3320 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=6e2530b8-1a00-0000-4b68-b481f80c0000 pid=3320 execve guuid=9e45b9de-1a00-0000-4b68-b481240d0000 pid=3364 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=9e45b9de-1a00-0000-4b68-b481240d0000 pid=3364 execve guuid=f2f0f8de-1a00-0000-4b68-b481260d0000 pid=3366 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=f2f0f8de-1a00-0000-4b68-b481260d0000 pid=3366 clone guuid=684587df-1a00-0000-4b68-b4812a0d0000 pid=3370 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=684587df-1a00-0000-4b68-b4812a0d0000 pid=3370 execve guuid=8b111fe0-1a00-0000-4b68-b4812d0d0000 pid=3373 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=8b111fe0-1a00-0000-4b68-b4812d0d0000 pid=3373 execve guuid=486bee00-1b00-0000-4b68-b4816f0d0000 pid=3439 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=486bee00-1b00-0000-4b68-b4816f0d0000 pid=3439 execve guuid=93164701-1b00-0000-4b68-b481700d0000 pid=3440 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=93164701-1b00-0000-4b68-b481700d0000 pid=3440 clone guuid=ca5df401-1b00-0000-4b68-b481740d0000 pid=3444 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ca5df401-1b00-0000-4b68-b481740d0000 pid=3444 execve guuid=ffe24b02-1b00-0000-4b68-b481750d0000 pid=3445 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ffe24b02-1b00-0000-4b68-b481750d0000 pid=3445 execve guuid=589c9d29-1b00-0000-4b68-b481bf0d0000 pid=3519 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=589c9d29-1b00-0000-4b68-b481bf0d0000 pid=3519 execve guuid=9b574a2a-1b00-0000-4b68-b481c20d0000 pid=3522 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=9b574a2a-1b00-0000-4b68-b481c20d0000 pid=3522 clone guuid=90f83d2c-1b00-0000-4b68-b481c70d0000 pid=3527 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=90f83d2c-1b00-0000-4b68-b481c70d0000 pid=3527 execve guuid=68b6a02c-1b00-0000-4b68-b481c90d0000 pid=3529 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=68b6a02c-1b00-0000-4b68-b481c90d0000 pid=3529 execve guuid=3cd54a54-1b00-0000-4b68-b481fa0d0000 pid=3578 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=3cd54a54-1b00-0000-4b68-b481fa0d0000 pid=3578 execve guuid=6992aa54-1b00-0000-4b68-b481fb0d0000 pid=3579 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=6992aa54-1b00-0000-4b68-b481fb0d0000 pid=3579 clone guuid=3ef89955-1b00-0000-4b68-b481fe0d0000 pid=3582 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=3ef89955-1b00-0000-4b68-b481fe0d0000 pid=3582 execve guuid=3b44f355-1b00-0000-4b68-b481000e0000 pid=3584 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=3b44f355-1b00-0000-4b68-b481000e0000 pid=3584 execve guuid=a7f3bd7d-1b00-0000-4b68-b4813e0e0000 pid=3646 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=a7f3bd7d-1b00-0000-4b68-b4813e0e0000 pid=3646 execve guuid=b4c74a7e-1b00-0000-4b68-b4813f0e0000 pid=3647 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=b4c74a7e-1b00-0000-4b68-b4813f0e0000 pid=3647 clone guuid=1e09687f-1b00-0000-4b68-b481410e0000 pid=3649 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=1e09687f-1b00-0000-4b68-b481410e0000 pid=3649 execve guuid=3388c27f-1b00-0000-4b68-b481420e0000 pid=3650 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=3388c27f-1b00-0000-4b68-b481420e0000 pid=3650 execve guuid=81abfaa6-1b00-0000-4b68-b4814e0e0000 pid=3662 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=81abfaa6-1b00-0000-4b68-b4814e0e0000 pid=3662 execve guuid=fa6c55a7-1b00-0000-4b68-b481500e0000 pid=3664 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=fa6c55a7-1b00-0000-4b68-b481500e0000 pid=3664 clone guuid=87cc62a8-1b00-0000-4b68-b481550e0000 pid=3669 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=87cc62a8-1b00-0000-4b68-b481550e0000 pid=3669 execve guuid=0159f7a8-1b00-0000-4b68-b481580e0000 pid=3672 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=0159f7a8-1b00-0000-4b68-b481580e0000 pid=3672 execve guuid=e3a9bdd0-1b00-0000-4b68-b4819a0e0000 pid=3738 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=e3a9bdd0-1b00-0000-4b68-b4819a0e0000 pid=3738 execve guuid=c4171dd1-1b00-0000-4b68-b4819b0e0000 pid=3739 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=c4171dd1-1b00-0000-4b68-b4819b0e0000 pid=3739 clone guuid=da91d1d1-1b00-0000-4b68-b481a00e0000 pid=3744 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=da91d1d1-1b00-0000-4b68-b481a00e0000 pid=3744 execve guuid=dfde2ad2-1b00-0000-4b68-b481a40e0000 pid=3748 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=dfde2ad2-1b00-0000-4b68-b481a40e0000 pid=3748 execve guuid=ae7df7f8-1b00-0000-4b68-b481280f0000 pid=3880 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ae7df7f8-1b00-0000-4b68-b481280f0000 pid=3880 execve guuid=7aea31f9-1b00-0000-4b68-b481290f0000 pid=3881 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=7aea31f9-1b00-0000-4b68-b481290f0000 pid=3881 clone guuid=2132b5f9-1b00-0000-4b68-b481310f0000 pid=3889 /usr/bin/rm guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=2132b5f9-1b00-0000-4b68-b481310f0000 pid=3889 execve guuid=87b35afa-1b00-0000-4b68-b481330f0000 pid=3891 /usr/bin/wget net send-data write-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=87b35afa-1b00-0000-4b68-b481330f0000 pid=3891 execve guuid=7ef44921-1c00-0000-4b68-b481b70f0000 pid=4023 /usr/bin/chmod guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=7ef44921-1c00-0000-4b68-b481b70f0000 pid=4023 execve guuid=137cc821-1c00-0000-4b68-b481ba0f0000 pid=4026 /usr/bin/dash guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=137cc821-1c00-0000-4b68-b481ba0f0000 pid=4026 clone guuid=37b1f322-1c00-0000-4b68-b481c00f0000 pid=4032 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=37b1f322-1c00-0000-4b68-b481c00f0000 pid=4032 execve guuid=eb465223-1c00-0000-4b68-b481c10f0000 pid=4033 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=eb465223-1c00-0000-4b68-b481c10f0000 pid=4033 execve guuid=c6939923-1c00-0000-4b68-b481c50f0000 pid=4037 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=c6939923-1c00-0000-4b68-b481c50f0000 pid=4037 execve guuid=4c99da23-1c00-0000-4b68-b481c60f0000 pid=4038 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=4c99da23-1c00-0000-4b68-b481c60f0000 pid=4038 execve guuid=405b1724-1c00-0000-4b68-b481c70f0000 pid=4039 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=405b1724-1c00-0000-4b68-b481c70f0000 pid=4039 execve guuid=9ee46c24-1c00-0000-4b68-b481cb0f0000 pid=4043 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=9ee46c24-1c00-0000-4b68-b481cb0f0000 pid=4043 execve guuid=a651cc24-1c00-0000-4b68-b481cd0f0000 pid=4045 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=a651cc24-1c00-0000-4b68-b481cd0f0000 pid=4045 execve guuid=73c32925-1c00-0000-4b68-b481d00f0000 pid=4048 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=73c32925-1c00-0000-4b68-b481d00f0000 pid=4048 execve guuid=f778a625-1c00-0000-4b68-b481d20f0000 pid=4050 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=f778a625-1c00-0000-4b68-b481d20f0000 pid=4050 execve guuid=77f50d26-1c00-0000-4b68-b481d50f0000 pid=4053 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=77f50d26-1c00-0000-4b68-b481d50f0000 pid=4053 execve guuid=50157426-1c00-0000-4b68-b481d70f0000 pid=4055 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=50157426-1c00-0000-4b68-b481d70f0000 pid=4055 execve guuid=fa50ac26-1c00-0000-4b68-b481d90f0000 pid=4057 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=fa50ac26-1c00-0000-4b68-b481d90f0000 pid=4057 execve guuid=e17e0927-1c00-0000-4b68-b481dd0f0000 pid=4061 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=e17e0927-1c00-0000-4b68-b481dd0f0000 pid=4061 execve guuid=2b9b6427-1c00-0000-4b68-b481de0f0000 pid=4062 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=2b9b6427-1c00-0000-4b68-b481de0f0000 pid=4062 execve guuid=f22da027-1c00-0000-4b68-b481e20f0000 pid=4066 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=f22da027-1c00-0000-4b68-b481e20f0000 pid=4066 execve guuid=f3c2da27-1c00-0000-4b68-b481e40f0000 pid=4068 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=f3c2da27-1c00-0000-4b68-b481e40f0000 pid=4068 execve guuid=ce381228-1c00-0000-4b68-b481e50f0000 pid=4069 /usr/bin/rm delete-file guuid=187dd196-1900-0000-4b68-b481440b0000 pid=2884->guuid=ce381228-1c00-0000-4b68-b481e50f0000 pid=4069 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=28cef897-1900-0000-4b68-b481490b0000 pid=2889->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=30ad53c3-1900-0000-4b68-b481920b0000 pid=2962->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=3f9359ec-1900-0000-4b68-b481d40b0000 pid=3028->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102 /tmp/JSDD net send-data write-file zombie guuid=c63a8a13-1a00-0000-4b68-b4811c0c0000 pid=3100->guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=e02bd328-1a00-0000-4b68-b481350c0000 pid=3125 /usr/bin/uname guuid=7992a113-1a00-0000-4b68-b4811e0c0000 pid=3102->guuid=e02bd328-1a00-0000-4b68-b481350c0000 pid=3125 execve guuid=64f7fd13-1a00-0000-4b68-b481200c0000 pid=3104->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=c8bd9d3d-1a00-0000-4b68-b481690c0000 pid=3177->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=cbcfb164-1a00-0000-4b68-b481930c0000 pid=3219 /tmp/QKRC zombie guuid=9486a464-1a00-0000-4b68-b481920c0000 pid=3218->guuid=cbcfb164-1a00-0000-4b68-b481930c0000 pid=3219 clone guuid=d3410365-1a00-0000-4b68-b481950c0000 pid=3221->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8042838d-1a00-0000-4b68-b481c00c0000 pid=3264->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=6e2530b8-1a00-0000-4b68-b481f80c0000 pid=3320->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8b111fe0-1a00-0000-4b68-b4812d0d0000 pid=3373->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ffe24b02-1b00-0000-4b68-b481750d0000 pid=3445->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=68b6a02c-1b00-0000-4b68-b481c90d0000 pid=3529->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=3b44f355-1b00-0000-4b68-b481000e0000 pid=3584->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=3388c27f-1b00-0000-4b68-b481420e0000 pid=3650->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=0159f7a8-1b00-0000-4b68-b481580e0000 pid=3672->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=dfde2ad2-1b00-0000-4b68-b481a40e0000 pid=3748->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=87b35afa-1b00-0000-4b68-b481330f0000 pid=3891->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 5839d9cdeac8ae10c74362bb44efa419d09d1a2aa6514684e8cfc931d2aee09c

(this sample)

  
Delivery method
Distributed via web download

Comments