MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 666b6557380bd9c9f3bda1bf018bff40364444c74ebfde4063835f4a540ffbf5. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: 666b6557380bd9c9f3bda1bf018bff40364444c74ebfde4063835f4a540ffbf5
SHA3-384 hash: ed68a751ef56ed8f3c7f2caaa6dd1a7ba5a45b045f7f092dfd7132141440ba20d4b2254a4b130f744167bed8f06e1a90
SHA1 hash: de41db1ff15fd334796874ec4661b9fd6499a7db
MD5 hash: 07ed3452186bd2ba2c609345c2815e22
humanhash: burger-ink-north-nuts
File name:chk.sh
Download: download sample
File size:1'695 bytes
First seen:2025-07-16 02:41:57 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 48:ww0lA/8OTL/ZTNMK3JD36K8lEbyaesS91UxWL4iT:b0q/8OTLleZbaeX91uW7
TLSH T12F31442EA7541374296D93D4608F71A5674C000AD2252C303CFEAA482B47DB5A2B747E
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
23
Origin country :
DE DE
Vendor Threat Intelligence
Verdict:
Unknown
Threat level:
  2.5/10
Confidence:
100%
Tags:
fingerprint
Status:
terminated
Behavior Graph:
%3 guuid=836f0a47-1900-0000-2b7f-bab6210b0000 pid=2849 /usr/bin/sudo guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856 /tmp/sample.bin guuid=836f0a47-1900-0000-2b7f-bab6210b0000 pid=2849->guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856 execve guuid=97d3024d-1900-0000-2b7f-bab62b0b0000 pid=2859 /usr/bin/id guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=97d3024d-1900-0000-2b7f-bab62b0b0000 pid=2859 execve guuid=a0271f4f-1900-0000-2b7f-bab62f0b0000 pid=2863 /usr/bin/nproc guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=a0271f4f-1900-0000-2b7f-bab62f0b0000 pid=2863 execve guuid=fc1d8a50-1900-0000-2b7f-bab6330b0000 pid=2867 /usr/bin/bash guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=fc1d8a50-1900-0000-2b7f-bab6330b0000 pid=2867 clone guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870 /usr/bin/sudo net guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870 execve guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109 /usr/bin/sudo net guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109 execve guuid=78f550f9-1b00-0000-2b7f-bab622100000 pid=4130 /usr/bin/bash guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=78f550f9-1b00-0000-2b7f-bab622100000 pid=4130 clone guuid=be5871f9-1b00-0000-2b7f-bab625100000 pid=4133 /usr/bin/sleep guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=be5871f9-1b00-0000-2b7f-bab625100000 pid=4133 execve guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4629 /usr/bin/curl net send-data guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4629 execve guuid=d4e4d487-1c00-0000-2b7f-bab65c120000 pid=4700 /usr/bin/bash guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=d4e4d487-1c00-0000-2b7f-bab65c120000 pid=4700 clone guuid=3f720488-1c00-0000-2b7f-bab65d120000 pid=4701 /usr/bin/pgrep guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=3f720488-1c00-0000-2b7f-bab65d120000 pid=4701 execve guuid=74acf18c-1c00-0000-2b7f-bab676120000 pid=4726 /usr/bin/pgrep guuid=0bd7f34b-1900-0000-2b7f-bab6280b0000 pid=2856->guuid=74acf18c-1c00-0000-2b7f-bab676120000 pid=4726 execve 0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 10.0.2.15:0 guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con 558177e1-1f18-5f39-990b-d68b1c194e8a fec0::5054:ff:fe12:3456:0 guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870->558177e1-1f18-5f39-990b-d68b1c194e8a con cbc59886-1795-52e1-b014-449ae22fd09b fe80::5054:ff:fe12:3456:0 guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878 /usr/bin/apt-get delete-file write-file guuid=e4b61b51-1900-0000-2b7f-bab6360b0000 pid=2870->guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878 execve guuid=4a8aa858-1900-0000-2b7f-bab6470b0000 pid=2887 /usr/bin/dpkg guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=4a8aa858-1900-0000-2b7f-bab6470b0000 pid=2887 execve guuid=f5a2945a-1900-0000-2b7f-bab64c0b0000 pid=2892 /usr/lib/apt/methods/mirror guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=f5a2945a-1900-0000-2b7f-bab64c0b0000 pid=2892 execve guuid=1b48085d-1900-0000-2b7f-bab6550b0000 pid=2901 /usr/lib/apt/methods/mirror guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=1b48085d-1900-0000-2b7f-bab6550b0000 pid=2901 execve guuid=c3449c5f-1900-0000-2b7f-bab6590b0000 pid=2905 /usr/lib/apt/methods/file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=c3449c5f-1900-0000-2b7f-bab6590b0000 pid=2905 execve guuid=15130d63-1900-0000-2b7f-bab6600b0000 pid=2912 /usr/lib/apt/methods/file delete-file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=15130d63-1900-0000-2b7f-bab6600b0000 pid=2912 execve guuid=93e82366-1900-0000-2b7f-bab6670b0000 pid=2919 /usr/lib/apt/methods/http guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=93e82366-1900-0000-2b7f-bab6670b0000 pid=2919 execve guuid=6ef8936b-1900-0000-2b7f-bab66c0b0000 pid=2924 /usr/lib/apt/methods/http dns net send-data write-file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=6ef8936b-1900-0000-2b7f-bab66c0b0000 pid=2924 execve guuid=92ccfc84-1900-0000-2b7f-bab6880b0000 pid=2952 /usr/lib/apt/methods/gpgv guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=92ccfc84-1900-0000-2b7f-bab6880b0000 pid=2952 execve guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955 /usr/lib/apt/methods/gpgv guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955 execve guuid=625d97c5-1900-0000-2b7f-bab6420c0000 pid=3138 /usr/lib/apt/methods/rred guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=625d97c5-1900-0000-2b7f-bab6420c0000 pid=3138 execve guuid=7c55d4c8-1900-0000-2b7f-bab6510c0000 pid=3153 /usr/lib/apt/methods/rred write-file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=7c55d4c8-1900-0000-2b7f-bab6510c0000 pid=3153 execve guuid=030fcdc9-1900-0000-2b7f-bab6540c0000 pid=3156 /usr/lib/apt/methods/rred write-file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=030fcdc9-1900-0000-2b7f-bab6540c0000 pid=3156 execve guuid=8f5a85ea-1900-0000-2b7f-bab6bc0c0000 pid=3260 /usr/lib/apt/methods/store guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=8f5a85ea-1900-0000-2b7f-bab6bc0c0000 pid=3260 execve guuid=1c7d2dee-1900-0000-2b7f-bab6c40c0000 pid=3268 /usr/lib/apt/methods/store write-file guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=1c7d2dee-1900-0000-2b7f-bab6c40c0000 pid=3268 execve guuid=0089652c-1a00-0000-2b7f-bab60b0d0000 pid=3339 /usr/bin/dpkg guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=0089652c-1a00-0000-2b7f-bab60b0d0000 pid=3339 execve guuid=5d210dee-1b00-0000-2b7f-bab6ff0f0000 pid=4095 /usr/bin/dpkg guuid=8a092354-1900-0000-2b7f-bab63e0b0000 pid=2878->guuid=5d210dee-1b00-0000-2b7f-bab6ff0f0000 pid=4095 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=6ef8936b-1900-0000-2b7f-bab66c0b0000 pid=2924->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=6ef8936b-1900-0000-2b7f-bab66c0b0000 pid=2924->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=560fa388-1900-0000-2b7f-bab68e0b0000 pid=2958 /usr/lib/apt/methods/gpgv delete-file write-file guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955->guuid=560fa388-1900-0000-2b7f-bab68e0b0000 pid=2958 clone guuid=619bdfa3-1900-0000-2b7f-bab6d10b0000 pid=3025 /usr/lib/apt/methods/gpgv delete-file write-file guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955->guuid=619bdfa3-1900-0000-2b7f-bab6d10b0000 pid=3025 clone guuid=5b86b9c1-1900-0000-2b7f-bab62f0c0000 pid=3119 /usr/lib/apt/methods/gpgv delete-file write-file guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955->guuid=5b86b9c1-1900-0000-2b7f-bab62f0c0000 pid=3119 clone guuid=3f8bacd2-1900-0000-2b7f-bab6790c0000 pid=3193 /usr/lib/apt/methods/gpgv delete-file write-file guuid=28e40387-1900-0000-2b7f-bab68b0b0000 pid=2955->guuid=3f8bacd2-1900-0000-2b7f-bab6790c0000 pid=3193 clone guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966 /usr/bin/apt-key write-file guuid=560fa388-1900-0000-2b7f-bab68e0b0000 pid=2958->guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966 execve guuid=b6cb0c8e-1900-0000-2b7f-bab6970b0000 pid=2967 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=b6cb0c8e-1900-0000-2b7f-bab6970b0000 pid=2967 clone guuid=483c3b8e-1900-0000-2b7f-bab6980b0000 pid=2968 /usr/bin/apt-config guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=483c3b8e-1900-0000-2b7f-bab6980b0000 pid=2968 execve guuid=e2e55097-1900-0000-2b7f-bab6a10b0000 pid=2977 /usr/bin/apt-config guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=e2e55097-1900-0000-2b7f-bab6a10b0000 pid=2977 execve guuid=27817e99-1900-0000-2b7f-bab6a90b0000 pid=2985 /usr/bin/apt-config guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=27817e99-1900-0000-2b7f-bab6a90b0000 pid=2985 execve guuid=26d2469b-1900-0000-2b7f-bab6ad0b0000 pid=2989 /usr/bin/apt-config guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=26d2469b-1900-0000-2b7f-bab6ad0b0000 pid=2989 execve guuid=8071e59c-1900-0000-2b7f-bab6b00b0000 pid=2992 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=8071e59c-1900-0000-2b7f-bab6b00b0000 pid=2992 clone guuid=10840d9d-1900-0000-2b7f-bab6b10b0000 pid=2993 /usr/bin/apt-config guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=10840d9d-1900-0000-2b7f-bab6b10b0000 pid=2993 execve guuid=e2cd219f-1900-0000-2b7f-bab6b80b0000 pid=3000 /usr/bin/mktemp guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=e2cd219f-1900-0000-2b7f-bab6b80b0000 pid=3000 execve guuid=de317c9f-1900-0000-2b7f-bab6ba0b0000 pid=3002 /usr/bin/chmod guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=de317c9f-1900-0000-2b7f-bab6ba0b0000 pid=3002 execve guuid=64f6bd9f-1900-0000-2b7f-bab6bc0b0000 pid=3004 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=64f6bd9f-1900-0000-2b7f-bab6bc0b0000 pid=3004 clone guuid=20e8d69f-1900-0000-2b7f-bab6bd0b0000 pid=3005 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=20e8d69f-1900-0000-2b7f-bab6bd0b0000 pid=3005 clone guuid=bf0441a0-1900-0000-2b7f-bab6c10b0000 pid=3009 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=bf0441a0-1900-0000-2b7f-bab6c10b0000 pid=3009 clone guuid=d869a7a0-1900-0000-2b7f-bab6c50b0000 pid=3013 /usr/bin/dash guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=d869a7a0-1900-0000-2b7f-bab6c50b0000 pid=3013 clone guuid=b787b4a0-1900-0000-2b7f-bab6c60b0000 pid=3014 /usr/bin/gpgv guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=b787b4a0-1900-0000-2b7f-bab6c60b0000 pid=3014 execve guuid=7a30e2a2-1900-0000-2b7f-bab6cd0b0000 pid=3021 /usr/bin/rm delete-file guuid=c077d78d-1900-0000-2b7f-bab6960b0000 pid=2966->guuid=7a30e2a2-1900-0000-2b7f-bab6cd0b0000 pid=3021 execve guuid=ce8dae91-1900-0000-2b7f-bab69f0b0000 pid=2975 /usr/bin/dpkg guuid=483c3b8e-1900-0000-2b7f-bab6980b0000 pid=2968->guuid=ce8dae91-1900-0000-2b7f-bab69f0b0000 pid=2975 execve guuid=eb2cd998-1900-0000-2b7f-bab6a60b0000 pid=2982 /usr/bin/dpkg guuid=e2e55097-1900-0000-2b7f-bab6a10b0000 pid=2977->guuid=eb2cd998-1900-0000-2b7f-bab6a60b0000 pid=2982 execve guuid=1011c29a-1900-0000-2b7f-bab6ac0b0000 pid=2988 /usr/bin/dpkg guuid=27817e99-1900-0000-2b7f-bab6a90b0000 pid=2985->guuid=1011c29a-1900-0000-2b7f-bab6ac0b0000 pid=2988 execve guuid=64b1429c-1900-0000-2b7f-bab6ae0b0000 pid=2990 /usr/bin/dpkg guuid=26d2469b-1900-0000-2b7f-bab6ad0b0000 pid=2989->guuid=64b1429c-1900-0000-2b7f-bab6ae0b0000 pid=2990 execve guuid=0cec669e-1900-0000-2b7f-bab6b50b0000 pid=2997 /usr/bin/dpkg guuid=10840d9d-1900-0000-2b7f-bab6b10b0000 pid=2993->guuid=0cec669e-1900-0000-2b7f-bab6b50b0000 pid=2997 execve guuid=0967e89f-1900-0000-2b7f-bab6bf0b0000 pid=3007 /usr/bin/dash guuid=20e8d69f-1900-0000-2b7f-bab6bd0b0000 pid=3005->guuid=0967e89f-1900-0000-2b7f-bab6bf0b0000 pid=3007 clone guuid=b441ef9f-1900-0000-2b7f-bab6c00b0000 pid=3008 /usr/bin/sed guuid=20e8d69f-1900-0000-2b7f-bab6bd0b0000 pid=3005->guuid=b441ef9f-1900-0000-2b7f-bab6c00b0000 pid=3008 execve guuid=d7434fa0-1900-0000-2b7f-bab6c20b0000 pid=3010 /usr/bin/dash guuid=bf0441a0-1900-0000-2b7f-bab6c10b0000 pid=3009->guuid=d7434fa0-1900-0000-2b7f-bab6c20b0000 pid=3010 clone guuid=86175aa0-1900-0000-2b7f-bab6c30b0000 pid=3011 /usr/bin/sed guuid=bf0441a0-1900-0000-2b7f-bab6c10b0000 pid=3009->guuid=86175aa0-1900-0000-2b7f-bab6c30b0000 pid=3011 execve guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029 /usr/bin/apt-key write-file guuid=619bdfa3-1900-0000-2b7f-bab6d10b0000 pid=3025->guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029 execve guuid=8a990fa5-1900-0000-2b7f-bab6d70b0000 pid=3031 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=8a990fa5-1900-0000-2b7f-bab6d70b0000 pid=3031 clone guuid=07e823a5-1900-0000-2b7f-bab6d80b0000 pid=3032 /usr/bin/apt-config guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=07e823a5-1900-0000-2b7f-bab6d80b0000 pid=3032 execve guuid=119e93a8-1900-0000-2b7f-bab6e00b0000 pid=3040 /usr/bin/apt-config guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=119e93a8-1900-0000-2b7f-bab6e00b0000 pid=3040 execve guuid=ecd40eaa-1900-0000-2b7f-bab6e60b0000 pid=3046 /usr/bin/apt-config guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=ecd40eaa-1900-0000-2b7f-bab6e60b0000 pid=3046 execve guuid=dfef68b0-1900-0000-2b7f-bab6ef0b0000 pid=3055 /usr/bin/apt-config guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=dfef68b0-1900-0000-2b7f-bab6ef0b0000 pid=3055 execve guuid=c36dccb6-1900-0000-2b7f-bab6000c0000 pid=3072 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=c36dccb6-1900-0000-2b7f-bab6000c0000 pid=3072 clone guuid=9402f4b6-1900-0000-2b7f-bab6010c0000 pid=3073 /usr/bin/apt-config guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=9402f4b6-1900-0000-2b7f-bab6010c0000 pid=3073 execve guuid=500e48bd-1900-0000-2b7f-bab6140c0000 pid=3092 /usr/bin/mktemp guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=500e48bd-1900-0000-2b7f-bab6140c0000 pid=3092 execve guuid=5eb79bbd-1900-0000-2b7f-bab6160c0000 pid=3094 /usr/bin/chmod guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=5eb79bbd-1900-0000-2b7f-bab6160c0000 pid=3094 execve guuid=df12e2bd-1900-0000-2b7f-bab6180c0000 pid=3096 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=df12e2bd-1900-0000-2b7f-bab6180c0000 pid=3096 clone guuid=71d7f7bd-1900-0000-2b7f-bab6190c0000 pid=3097 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=71d7f7bd-1900-0000-2b7f-bab6190c0000 pid=3097 clone guuid=68995bbe-1900-0000-2b7f-bab61e0c0000 pid=3102 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=68995bbe-1900-0000-2b7f-bab61e0c0000 pid=3102 clone guuid=c8dd27bf-1900-0000-2b7f-bab6230c0000 pid=3107 /usr/bin/dash guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=c8dd27bf-1900-0000-2b7f-bab6230c0000 pid=3107 clone guuid=714b3abf-1900-0000-2b7f-bab6240c0000 pid=3108 /usr/bin/gpgv guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=714b3abf-1900-0000-2b7f-bab6240c0000 pid=3108 execve guuid=f570f9c0-1900-0000-2b7f-bab62b0c0000 pid=3115 /usr/bin/rm delete-file guuid=157fd5a4-1900-0000-2b7f-bab6d50b0000 pid=3029->guuid=f570f9c0-1900-0000-2b7f-bab62b0c0000 pid=3115 execve guuid=a9b9d6a7-1900-0000-2b7f-bab6df0b0000 pid=3039 /usr/bin/dpkg guuid=07e823a5-1900-0000-2b7f-bab6d80b0000 pid=3032->guuid=a9b9d6a7-1900-0000-2b7f-bab6df0b0000 pid=3039 execve guuid=c37184a9-1900-0000-2b7f-bab6e40b0000 pid=3044 /usr/bin/dpkg guuid=119e93a8-1900-0000-2b7f-bab6e00b0000 pid=3040->guuid=c37184a9-1900-0000-2b7f-bab6e40b0000 pid=3044 execve guuid=da0d75ab-1900-0000-2b7f-bab6ea0b0000 pid=3050 /usr/bin/dpkg guuid=ecd40eaa-1900-0000-2b7f-bab6e60b0000 pid=3046->guuid=da0d75ab-1900-0000-2b7f-bab6ea0b0000 pid=3050 execve guuid=39f3efb1-1900-0000-2b7f-bab6f50b0000 pid=3061 /usr/bin/dpkg guuid=dfef68b0-1900-0000-2b7f-bab6ef0b0000 pid=3055->guuid=39f3efb1-1900-0000-2b7f-bab6f50b0000 pid=3061 execve guuid=e49ae6b7-1900-0000-2b7f-bab6060c0000 pid=3078 /usr/bin/dpkg guuid=9402f4b6-1900-0000-2b7f-bab6010c0000 pid=3073->guuid=e49ae6b7-1900-0000-2b7f-bab6060c0000 pid=3078 execve guuid=55ee01be-1900-0000-2b7f-bab61b0c0000 pid=3099 /usr/bin/dash guuid=71d7f7bd-1900-0000-2b7f-bab6190c0000 pid=3097->guuid=55ee01be-1900-0000-2b7f-bab61b0c0000 pid=3099 clone guuid=f08e07be-1900-0000-2b7f-bab61c0c0000 pid=3100 /usr/bin/sed guuid=71d7f7bd-1900-0000-2b7f-bab6190c0000 pid=3097->guuid=f08e07be-1900-0000-2b7f-bab61c0c0000 pid=3100 execve guuid=b1c57bbe-1900-0000-2b7f-bab61f0c0000 pid=3103 /usr/bin/dash guuid=68995bbe-1900-0000-2b7f-bab61e0c0000 pid=3102->guuid=b1c57bbe-1900-0000-2b7f-bab61f0c0000 pid=3103 clone guuid=f7d792be-1900-0000-2b7f-bab6200c0000 pid=3104 /usr/bin/sed guuid=68995bbe-1900-0000-2b7f-bab61e0c0000 pid=3102->guuid=f7d792be-1900-0000-2b7f-bab6200c0000 pid=3104 execve guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123 /usr/bin/apt-key write-file guuid=5b86b9c1-1900-0000-2b7f-bab62f0c0000 pid=3119->guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123 execve guuid=ded2bac2-1900-0000-2b7f-bab6350c0000 pid=3125 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=ded2bac2-1900-0000-2b7f-bab6350c0000 pid=3125 clone guuid=2cf4c5c2-1900-0000-2b7f-bab6360c0000 pid=3126 /usr/bin/apt-config guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=2cf4c5c2-1900-0000-2b7f-bab6360c0000 pid=3126 execve guuid=476eb6c4-1900-0000-2b7f-bab63e0c0000 pid=3134 /usr/bin/apt-config guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=476eb6c4-1900-0000-2b7f-bab63e0c0000 pid=3134 execve guuid=c517c4c6-1900-0000-2b7f-bab6480c0000 pid=3144 /usr/bin/apt-config guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=c517c4c6-1900-0000-2b7f-bab6480c0000 pid=3144 execve guuid=3fb88ec8-1900-0000-2b7f-bab6500c0000 pid=3152 /usr/bin/apt-config guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=3fb88ec8-1900-0000-2b7f-bab6500c0000 pid=3152 execve guuid=fb7480cb-1900-0000-2b7f-bab6590c0000 pid=3161 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=fb7480cb-1900-0000-2b7f-bab6590c0000 pid=3161 clone guuid=786ecacb-1900-0000-2b7f-bab65b0c0000 pid=3163 /usr/bin/apt-config guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=786ecacb-1900-0000-2b7f-bab65b0c0000 pid=3163 execve guuid=9b7587ce-1900-0000-2b7f-bab6630c0000 pid=3171 /usr/bin/mktemp guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=9b7587ce-1900-0000-2b7f-bab6630c0000 pid=3171 execve guuid=ebaec9ce-1900-0000-2b7f-bab6640c0000 pid=3172 /usr/bin/chmod guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=ebaec9ce-1900-0000-2b7f-bab6640c0000 pid=3172 execve guuid=b84c0dcf-1900-0000-2b7f-bab6660c0000 pid=3174 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=b84c0dcf-1900-0000-2b7f-bab6660c0000 pid=3174 clone guuid=1c9928cf-1900-0000-2b7f-bab6670c0000 pid=3175 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=1c9928cf-1900-0000-2b7f-bab6670c0000 pid=3175 clone guuid=e18e84cf-1900-0000-2b7f-bab66b0c0000 pid=3179 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=e18e84cf-1900-0000-2b7f-bab66b0c0000 pid=3179 clone guuid=7967efcf-1900-0000-2b7f-bab6700c0000 pid=3184 /usr/bin/dash guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=7967efcf-1900-0000-2b7f-bab6700c0000 pid=3184 clone guuid=5f48fdcf-1900-0000-2b7f-bab6710c0000 pid=3185 /usr/bin/gpgv guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=5f48fdcf-1900-0000-2b7f-bab6710c0000 pid=3185 execve guuid=4b8692d1-1900-0000-2b7f-bab6750c0000 pid=3189 /usr/bin/rm delete-file guuid=0e2d81c2-1900-0000-2b7f-bab6330c0000 pid=3123->guuid=4b8692d1-1900-0000-2b7f-bab6750c0000 pid=3189 execve guuid=043e10c4-1900-0000-2b7f-bab63b0c0000 pid=3131 /usr/bin/dpkg guuid=2cf4c5c2-1900-0000-2b7f-bab6360c0000 pid=3126->guuid=043e10c4-1900-0000-2b7f-bab63b0c0000 pid=3131 execve guuid=2e1f32c6-1900-0000-2b7f-bab6450c0000 pid=3141 /usr/bin/dpkg guuid=476eb6c4-1900-0000-2b7f-bab63e0c0000 pid=3134->guuid=2e1f32c6-1900-0000-2b7f-bab6450c0000 pid=3141 execve guuid=2004ffc7-1900-0000-2b7f-bab64e0c0000 pid=3150 /usr/bin/dpkg guuid=c517c4c6-1900-0000-2b7f-bab6480c0000 pid=3144->guuid=2004ffc7-1900-0000-2b7f-bab64e0c0000 pid=3150 execve guuid=a68251ca-1900-0000-2b7f-bab6560c0000 pid=3158 /usr/bin/dpkg guuid=3fb88ec8-1900-0000-2b7f-bab6500c0000 pid=3152->guuid=a68251ca-1900-0000-2b7f-bab6560c0000 pid=3158 execve guuid=edeb7ecd-1900-0000-2b7f-bab6610c0000 pid=3169 /usr/bin/dpkg guuid=786ecacb-1900-0000-2b7f-bab65b0c0000 pid=3163->guuid=edeb7ecd-1900-0000-2b7f-bab6610c0000 pid=3169 execve guuid=189832cf-1900-0000-2b7f-bab6680c0000 pid=3176 /usr/bin/dash guuid=1c9928cf-1900-0000-2b7f-bab6670c0000 pid=3175->guuid=189832cf-1900-0000-2b7f-bab6680c0000 pid=3176 clone guuid=7ff537cf-1900-0000-2b7f-bab6690c0000 pid=3177 /usr/bin/sed guuid=1c9928cf-1900-0000-2b7f-bab6670c0000 pid=3175->guuid=7ff537cf-1900-0000-2b7f-bab6690c0000 pid=3177 execve guuid=79968ecf-1900-0000-2b7f-bab66c0c0000 pid=3180 /usr/bin/dash guuid=e18e84cf-1900-0000-2b7f-bab66b0c0000 pid=3179->guuid=79968ecf-1900-0000-2b7f-bab66c0c0000 pid=3180 clone guuid=b81b93cf-1900-0000-2b7f-bab66d0c0000 pid=3181 /usr/bin/sed guuid=e18e84cf-1900-0000-2b7f-bab66b0c0000 pid=3179->guuid=b81b93cf-1900-0000-2b7f-bab66d0c0000 pid=3181 execve guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196 /usr/bin/apt-key write-file guuid=3f8bacd2-1900-0000-2b7f-bab6790c0000 pid=3193->guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196 execve guuid=77f9c8d3-1900-0000-2b7f-bab67d0c0000 pid=3197 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=77f9c8d3-1900-0000-2b7f-bab67d0c0000 pid=3197 clone guuid=d9bbe0d3-1900-0000-2b7f-bab67e0c0000 pid=3198 /usr/bin/apt-config guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=d9bbe0d3-1900-0000-2b7f-bab67e0c0000 pid=3198 execve guuid=2a02abd5-1900-0000-2b7f-bab6830c0000 pid=3203 /usr/bin/apt-config guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=2a02abd5-1900-0000-2b7f-bab6830c0000 pid=3203 execve guuid=0da3c5d7-1900-0000-2b7f-bab68a0c0000 pid=3210 /usr/bin/apt-config guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=0da3c5d7-1900-0000-2b7f-bab68a0c0000 pid=3210 execve guuid=e913edd9-1900-0000-2b7f-bab6910c0000 pid=3217 /usr/bin/apt-config guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=e913edd9-1900-0000-2b7f-bab6910c0000 pid=3217 execve guuid=ab29eddb-1900-0000-2b7f-bab6930c0000 pid=3219 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=ab29eddb-1900-0000-2b7f-bab6930c0000 pid=3219 clone guuid=082a2bdc-1900-0000-2b7f-bab6940c0000 pid=3220 /usr/bin/apt-config guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=082a2bdc-1900-0000-2b7f-bab6940c0000 pid=3220 execve guuid=14ee44de-1900-0000-2b7f-bab6960c0000 pid=3222 /usr/bin/mktemp guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=14ee44de-1900-0000-2b7f-bab6960c0000 pid=3222 execve guuid=a76d8dde-1900-0000-2b7f-bab6970c0000 pid=3223 /usr/bin/chmod guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=a76d8dde-1900-0000-2b7f-bab6970c0000 pid=3223 execve guuid=f56be0de-1900-0000-2b7f-bab6980c0000 pid=3224 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=f56be0de-1900-0000-2b7f-bab6980c0000 pid=3224 clone guuid=88e3fade-1900-0000-2b7f-bab6990c0000 pid=3225 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=88e3fade-1900-0000-2b7f-bab6990c0000 pid=3225 clone guuid=dcac98df-1900-0000-2b7f-bab69c0c0000 pid=3228 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=dcac98df-1900-0000-2b7f-bab69c0c0000 pid=3228 clone guuid=73ce2de0-1900-0000-2b7f-bab6a00c0000 pid=3232 /usr/bin/dash guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=73ce2de0-1900-0000-2b7f-bab6a00c0000 pid=3232 clone guuid=53f644e0-1900-0000-2b7f-bab6a10c0000 pid=3233 /usr/bin/gpgv guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=53f644e0-1900-0000-2b7f-bab6a10c0000 pid=3233 execve guuid=950b5de2-1900-0000-2b7f-bab6a80c0000 pid=3240 /usr/bin/rm delete-file guuid=995380d3-1900-0000-2b7f-bab67c0c0000 pid=3196->guuid=950b5de2-1900-0000-2b7f-bab6a80c0000 pid=3240 execve guuid=f6dc08d5-1900-0000-2b7f-bab6810c0000 pid=3201 /usr/bin/dpkg guuid=d9bbe0d3-1900-0000-2b7f-bab67e0c0000 pid=3198->guuid=f6dc08d5-1900-0000-2b7f-bab6810c0000 pid=3201 execve guuid=675326d7-1900-0000-2b7f-bab6880c0000 pid=3208 /usr/bin/dpkg guuid=2a02abd5-1900-0000-2b7f-bab6830c0000 pid=3203->guuid=675326d7-1900-0000-2b7f-bab6880c0000 pid=3208 execve guuid=43f449d9-1900-0000-2b7f-bab68f0c0000 pid=3215 /usr/bin/dpkg guuid=0da3c5d7-1900-0000-2b7f-bab68a0c0000 pid=3210->guuid=43f449d9-1900-0000-2b7f-bab68f0c0000 pid=3215 execve guuid=0f0f6ddb-1900-0000-2b7f-bab6920c0000 pid=3218 /usr/bin/dpkg guuid=e913edd9-1900-0000-2b7f-bab6910c0000 pid=3217->guuid=0f0f6ddb-1900-0000-2b7f-bab6920c0000 pid=3218 execve guuid=f0eeb8dd-1900-0000-2b7f-bab6950c0000 pid=3221 /usr/bin/dpkg guuid=082a2bdc-1900-0000-2b7f-bab6940c0000 pid=3220->guuid=f0eeb8dd-1900-0000-2b7f-bab6950c0000 pid=3221 execve guuid=84ff0bdf-1900-0000-2b7f-bab69a0c0000 pid=3226 /usr/bin/dash guuid=88e3fade-1900-0000-2b7f-bab6990c0000 pid=3225->guuid=84ff0bdf-1900-0000-2b7f-bab69a0c0000 pid=3226 clone guuid=798c14df-1900-0000-2b7f-bab69b0c0000 pid=3227 /usr/bin/sed guuid=88e3fade-1900-0000-2b7f-bab6990c0000 pid=3225->guuid=798c14df-1900-0000-2b7f-bab69b0c0000 pid=3227 execve guuid=4050a2df-1900-0000-2b7f-bab69d0c0000 pid=3229 /usr/bin/dash guuid=dcac98df-1900-0000-2b7f-bab69c0c0000 pid=3228->guuid=4050a2df-1900-0000-2b7f-bab69d0c0000 pid=3229 clone guuid=13a8a8df-1900-0000-2b7f-bab69f0c0000 pid=3231 /usr/bin/sed guuid=dcac98df-1900-0000-2b7f-bab69c0c0000 pid=3228->guuid=13a8a8df-1900-0000-2b7f-bab69f0c0000 pid=3231 execve guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109->0fd0acc8-dfb6-529f-8986-56cdc3ae41d6 con guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109->558177e1-1f18-5f39-990b-d68b1c194e8a con guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109->cbc59886-1795-52e1-b014-449ae22fd09b con guuid=fa71abf6-1b00-0000-2b7f-bab615100000 pid=4117 /usr/bin/apt-get guuid=b69a70f4-1b00-0000-2b7f-bab60d100000 pid=4109->guuid=fa71abf6-1b00-0000-2b7f-bab615100000 pid=4117 execve guuid=93d559f8-1b00-0000-2b7f-bab61b100000 pid=4123 /usr/bin/dpkg guuid=fa71abf6-1b00-0000-2b7f-bab615100000 pid=4117->guuid=93d559f8-1b00-0000-2b7f-bab61b100000 pid=4123 execve guuid=d1d05df9-1b00-0000-2b7f-bab623100000 pid=4131 /usr/bin/bash zombie guuid=78f550f9-1b00-0000-2b7f-bab622100000 pid=4130->guuid=d1d05df9-1b00-0000-2b7f-bab623100000 pid=4131 clone e1f9bcbd-fc59-5429-9359-3d4eca276af4 ifconfig.me:80 guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4629->e1f9bcbd-fc59-5429-9359-3d4eca276af4 send: 75B guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4644 /usr/bin/curl dns net send-data guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4629->guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4644 clone guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4644->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 58B guuid=54c2e273-1c00-0000-2b7f-bab615120000 pid=4644->e1f9bcbd-fc59-5429-9359-3d4eca276af4 con
Threat name:
Linux.Trojan.Generic
Status:
Suspicious
First seen:
2025-06-27 03:16:57 UTC
File Type:
Text (Shell)
AV detection:
5 of 23 (21.74%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  6/10
Tags:
antivm defense_evasion discovery execution linux privilege_escalation
Behaviour
Software Deployment Tools
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
Reads CPU attributes
Abuse Elevation Control Mechanism: Sudo and Sudo Caching
Enumerates running processes
Looks up external IP address via web service
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 666b6557380bd9c9f3bda1bf018bff40364444c74ebfde4063835f4a540ffbf5

(this sample)

  
Delivery method
Distributed via web download

Comments