MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 683e263918425ae499c8f51ea8d76fa71292ab56bbf567d2b767122b092adf0e. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 683e263918425ae499c8f51ea8d76fa71292ab56bbf567d2b767122b092adf0e
SHA3-384 hash: 2e9c2aced4bd2a4f642a7b378d8f1c71f2a95e68d8a8cae54f6765592dbea59abf9e041616389f47e67058e180b03153
SHA1 hash: 40193579fa3d20e4c8111e746b4a1c1038abdab9
MD5 hash: 0fe4d46039005a2c87e0cddd05e7a0df
humanhash: pasta-august-massachusetts-bulldog
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-05-21 01:19:33 UTC
Last seen:2026-05-21 18:24:52 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTuIF2fMWsXo2Fx4/2DHAulNXYq4HvXDG+NjVsNXYrkJ:VJ4rsXrFm/2DHPiq4HvXDGmKi2
TLSH T1D1D097B200A302B0E8634923F9C6F50271458F7E9D22EB6DF45B46303E81A09F0D13B1
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.155.8.56/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
63
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-20T22:28:00Z UTC
Last seen:
2026-05-20T23:03:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=1a6c0513-1600-0000-4356-756ba20c0000 pid=3234 /usr/bin/sudo guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236 /tmp/sample.bin guuid=1a6c0513-1600-0000-4356-756ba20c0000 pid=3234->guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236 execve guuid=ec1e5c16-1600-0000-4356-756ba50c0000 pid=3237 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ec1e5c16-1600-0000-4356-756ba50c0000 pid=3237 execve guuid=ce02ed16-1600-0000-4356-756ba70c0000 pid=3239 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ce02ed16-1600-0000-4356-756ba70c0000 pid=3239 execve guuid=2c93ce40-1600-0000-4356-756be40c0000 pid=3300 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=2c93ce40-1600-0000-4356-756be40c0000 pid=3300 execve guuid=c6565141-1600-0000-4356-756be50c0000 pid=3301 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c6565141-1600-0000-4356-756be50c0000 pid=3301 clone guuid=21580942-1600-0000-4356-756be70c0000 pid=3303 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=21580942-1600-0000-4356-756be70c0000 pid=3303 execve guuid=ba255942-1600-0000-4356-756be90c0000 pid=3305 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ba255942-1600-0000-4356-756be90c0000 pid=3305 execve guuid=c8dacd6a-1600-0000-4356-756b270d0000 pid=3367 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c8dacd6a-1600-0000-4356-756b270d0000 pid=3367 execve guuid=90da446b-1600-0000-4356-756b280d0000 pid=3368 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=90da446b-1600-0000-4356-756b280d0000 pid=3368 clone guuid=c2c17c6d-1600-0000-4356-756b2b0d0000 pid=3371 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c2c17c6d-1600-0000-4356-756b2b0d0000 pid=3371 execve guuid=b3a0ec6d-1600-0000-4356-756b2c0d0000 pid=3372 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=b3a0ec6d-1600-0000-4356-756b2c0d0000 pid=3372 execve guuid=a64e5295-1600-0000-4356-756b9b0d0000 pid=3483 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=a64e5295-1600-0000-4356-756b9b0d0000 pid=3483 execve guuid=41a8f195-1600-0000-4356-756b9d0d0000 pid=3485 /tmp/DRSA guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=41a8f195-1600-0000-4356-756b9d0d0000 pid=3485 execve guuid=68ff1196-1600-0000-4356-756ba00d0000 pid=3488 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=68ff1196-1600-0000-4356-756ba00d0000 pid=3488 execve guuid=52eb6096-1600-0000-4356-756ba20d0000 pid=3490 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=52eb6096-1600-0000-4356-756ba20d0000 pid=3490 execve guuid=83be8abd-1600-0000-4356-756bf00d0000 pid=3568 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=83be8abd-1600-0000-4356-756bf00d0000 pid=3568 execve guuid=963bd5bd-1600-0000-4356-756bf10d0000 pid=3569 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=963bd5bd-1600-0000-4356-756bf10d0000 pid=3569 clone guuid=c37574be-1600-0000-4356-756bf30d0000 pid=3571 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c37574be-1600-0000-4356-756bf30d0000 pid=3571 execve guuid=9366b3be-1600-0000-4356-756bf50d0000 pid=3573 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=9366b3be-1600-0000-4356-756bf50d0000 pid=3573 execve guuid=b39958e6-1600-0000-4356-756b580e0000 pid=3672 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=b39958e6-1600-0000-4356-756b580e0000 pid=3672 execve guuid=0d889de6-1600-0000-4356-756b590e0000 pid=3673 /tmp/YELN guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=0d889de6-1600-0000-4356-756b590e0000 pid=3673 execve guuid=605ab9e6-1600-0000-4356-756b5c0e0000 pid=3676 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=605ab9e6-1600-0000-4356-756b5c0e0000 pid=3676 execve guuid=319a04e7-1600-0000-4356-756b5e0e0000 pid=3678 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=319a04e7-1600-0000-4356-756b5e0e0000 pid=3678 execve guuid=d6bf610f-1700-0000-4356-756b960e0000 pid=3734 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d6bf610f-1700-0000-4356-756b960e0000 pid=3734 execve guuid=cea4c00f-1700-0000-4356-756b980e0000 pid=3736 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=cea4c00f-1700-0000-4356-756b980e0000 pid=3736 clone guuid=57520411-1700-0000-4356-756b9c0e0000 pid=3740 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=57520411-1700-0000-4356-756b9c0e0000 pid=3740 execve guuid=fde29111-1700-0000-4356-756b9e0e0000 pid=3742 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=fde29111-1700-0000-4356-756b9e0e0000 pid=3742 execve guuid=04bd273a-1700-0000-4356-756b000f0000 pid=3840 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=04bd273a-1700-0000-4356-756b000f0000 pid=3840 execve guuid=deb8a23a-1700-0000-4356-756b030f0000 pid=3843 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=deb8a23a-1700-0000-4356-756b030f0000 pid=3843 clone guuid=2205b63b-1700-0000-4356-756b070f0000 pid=3847 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=2205b63b-1700-0000-4356-756b070f0000 pid=3847 execve guuid=1c29293c-1700-0000-4356-756b0a0f0000 pid=3850 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=1c29293c-1700-0000-4356-756b0a0f0000 pid=3850 execve guuid=d05fb363-1700-0000-4356-756b9a0f0000 pid=3994 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d05fb363-1700-0000-4356-756b9a0f0000 pid=3994 execve guuid=9f8dfe63-1700-0000-4356-756b9b0f0000 pid=3995 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=9f8dfe63-1700-0000-4356-756b9b0f0000 pid=3995 clone guuid=77c29264-1700-0000-4356-756b9e0f0000 pid=3998 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=77c29264-1700-0000-4356-756b9e0f0000 pid=3998 execve guuid=d49edb64-1700-0000-4356-756ba00f0000 pid=4000 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d49edb64-1700-0000-4356-756ba00f0000 pid=4000 execve guuid=b10bf184-1700-0000-4356-756bf90f0000 pid=4089 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=b10bf184-1700-0000-4356-756bf90f0000 pid=4089 execve guuid=ff2b6f85-1700-0000-4356-756bfa0f0000 pid=4090 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ff2b6f85-1700-0000-4356-756bfa0f0000 pid=4090 clone guuid=6d793586-1700-0000-4356-756bfe0f0000 pid=4094 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=6d793586-1700-0000-4356-756bfe0f0000 pid=4094 execve guuid=ff0f9086-1700-0000-4356-756b02100000 pid=4098 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ff0f9086-1700-0000-4356-756b02100000 pid=4098 execve guuid=d5ecd4ae-1700-0000-4356-756b6e100000 pid=4206 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d5ecd4ae-1700-0000-4356-756b6e100000 pid=4206 execve guuid=b9214caf-1700-0000-4356-756b70100000 pid=4208 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=b9214caf-1700-0000-4356-756b70100000 pid=4208 clone guuid=94b812b0-1700-0000-4356-756b74100000 pid=4212 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=94b812b0-1700-0000-4356-756b74100000 pid=4212 execve guuid=990c71b0-1700-0000-4356-756b76100000 pid=4214 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=990c71b0-1700-0000-4356-756b76100000 pid=4214 execve guuid=a9cd82e0-1700-0000-4356-756b26110000 pid=4390 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=a9cd82e0-1700-0000-4356-756b26110000 pid=4390 execve guuid=eb1cfae0-1700-0000-4356-756b28110000 pid=4392 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=eb1cfae0-1700-0000-4356-756b28110000 pid=4392 clone guuid=3ec1c1e1-1700-0000-4356-756b2c110000 pid=4396 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=3ec1c1e1-1700-0000-4356-756b2c110000 pid=4396 execve guuid=6d9728e2-1700-0000-4356-756b2e110000 pid=4398 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=6d9728e2-1700-0000-4356-756b2e110000 pid=4398 execve guuid=dcbb570a-1800-0000-4356-756b9a110000 pid=4506 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=dcbb570a-1800-0000-4356-756b9a110000 pid=4506 execve guuid=b0a0c40a-1800-0000-4356-756b9e110000 pid=4510 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=b0a0c40a-1800-0000-4356-756b9e110000 pid=4510 clone guuid=f47ab80b-1800-0000-4356-756ba3110000 pid=4515 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=f47ab80b-1800-0000-4356-756ba3110000 pid=4515 execve guuid=732c2b0c-1800-0000-4356-756ba4110000 pid=4516 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=732c2b0c-1800-0000-4356-756ba4110000 pid=4516 execve guuid=128e5335-1800-0000-4356-756b02120000 pid=4610 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=128e5335-1800-0000-4356-756b02120000 pid=4610 execve guuid=d4a9d035-1800-0000-4356-756b04120000 pid=4612 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d4a9d035-1800-0000-4356-756b04120000 pid=4612 clone guuid=3190ec36-1800-0000-4356-756b09120000 pid=4617 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=3190ec36-1800-0000-4356-756b09120000 pid=4617 execve guuid=f20d4037-1800-0000-4356-756b0a120000 pid=4618 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=f20d4037-1800-0000-4356-756b0a120000 pid=4618 execve guuid=2c88d35f-1800-0000-4356-756b68120000 pid=4712 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=2c88d35f-1800-0000-4356-756b68120000 pid=4712 execve guuid=f8eb3760-1800-0000-4356-756b69120000 pid=4713 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=f8eb3760-1800-0000-4356-756b69120000 pid=4713 clone guuid=e096d162-1800-0000-4356-756b73120000 pid=4723 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=e096d162-1800-0000-4356-756b73120000 pid=4723 execve guuid=ca251d63-1800-0000-4356-756b74120000 pid=4724 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=ca251d63-1800-0000-4356-756b74120000 pid=4724 execve guuid=e549268d-1800-0000-4356-756bdd120000 pid=4829 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=e549268d-1800-0000-4356-756bdd120000 pid=4829 execve guuid=eb9fc68d-1800-0000-4356-756be0120000 pid=4832 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=eb9fc68d-1800-0000-4356-756be0120000 pid=4832 clone guuid=c704538e-1800-0000-4356-756be5120000 pid=4837 /usr/bin/rm guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c704538e-1800-0000-4356-756be5120000 pid=4837 execve guuid=cbca898e-1800-0000-4356-756be7120000 pid=4839 /usr/bin/wget net send-data write-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=cbca898e-1800-0000-4356-756be7120000 pid=4839 execve guuid=1b9cccb6-1800-0000-4356-756b8e130000 pid=5006 /usr/bin/chmod guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=1b9cccb6-1800-0000-4356-756b8e130000 pid=5006 execve guuid=34ac08b7-1800-0000-4356-756b90130000 pid=5008 /usr/bin/dash guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=34ac08b7-1800-0000-4356-756b90130000 pid=5008 clone guuid=396bb5b8-1800-0000-4356-756b98130000 pid=5016 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=396bb5b8-1800-0000-4356-756b98130000 pid=5016 execve guuid=9502f4b8-1800-0000-4356-756b9a130000 pid=5018 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=9502f4b8-1800-0000-4356-756b9a130000 pid=5018 execve guuid=67ec2eb9-1800-0000-4356-756b9c130000 pid=5020 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=67ec2eb9-1800-0000-4356-756b9c130000 pid=5020 execve guuid=f19067b9-1800-0000-4356-756b9e130000 pid=5022 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=f19067b9-1800-0000-4356-756b9e130000 pid=5022 execve guuid=1f6ca1b9-1800-0000-4356-756ba0130000 pid=5024 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=1f6ca1b9-1800-0000-4356-756ba0130000 pid=5024 execve guuid=c064d9b9-1800-0000-4356-756ba2130000 pid=5026 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=c064d9b9-1800-0000-4356-756ba2130000 pid=5026 execve guuid=645511ba-1800-0000-4356-756ba4130000 pid=5028 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=645511ba-1800-0000-4356-756ba4130000 pid=5028 execve guuid=d5bf46ba-1800-0000-4356-756ba6130000 pid=5030 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d5bf46ba-1800-0000-4356-756ba6130000 pid=5030 execve guuid=de7e81ba-1800-0000-4356-756ba8130000 pid=5032 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=de7e81ba-1800-0000-4356-756ba8130000 pid=5032 execve guuid=fd20b7ba-1800-0000-4356-756baa130000 pid=5034 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=fd20b7ba-1800-0000-4356-756baa130000 pid=5034 execve guuid=2dd3f0ba-1800-0000-4356-756bac130000 pid=5036 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=2dd3f0ba-1800-0000-4356-756bac130000 pid=5036 execve guuid=a3aa30bb-1800-0000-4356-756bae130000 pid=5038 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=a3aa30bb-1800-0000-4356-756bae130000 pid=5038 execve guuid=16b270bb-1800-0000-4356-756bb0130000 pid=5040 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=16b270bb-1800-0000-4356-756bb0130000 pid=5040 execve guuid=d316abbb-1800-0000-4356-756bb2130000 pid=5042 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=d316abbb-1800-0000-4356-756bb2130000 pid=5042 execve guuid=5312e8bb-1800-0000-4356-756bb4130000 pid=5044 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=5312e8bb-1800-0000-4356-756bb4130000 pid=5044 execve guuid=e54223bc-1800-0000-4356-756bb6130000 pid=5046 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=e54223bc-1800-0000-4356-756bb6130000 pid=5046 execve guuid=9f3061bc-1800-0000-4356-756bb8130000 pid=5048 /usr/bin/rm delete-file guuid=85d21e16-1600-0000-4356-756ba40c0000 pid=3236->guuid=9f3061bc-1800-0000-4356-756bb8130000 pid=5048 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=ce02ed16-1600-0000-4356-756ba70c0000 pid=3239->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ba255942-1600-0000-4356-756be90c0000 pid=3305->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=b3a0ec6d-1600-0000-4356-756b2c0d0000 pid=3372->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487 /tmp/DRSA net send-data write-file zombie guuid=41a8f195-1600-0000-4356-756b9d0d0000 pid=3485->guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=8af45da8-1600-0000-4356-756bc90d0000 pid=3529 /usr/bin/uname guuid=1b2f0996-1600-0000-4356-756b9f0d0000 pid=3487->guuid=8af45da8-1600-0000-4356-756bc90d0000 pid=3529 execve guuid=52eb6096-1600-0000-4356-756ba20d0000 pid=3490->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=9366b3be-1600-0000-4356-756bf50d0000 pid=3573->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=a31dade6-1600-0000-4356-756b5a0e0000 pid=3674 /tmp/YELN zombie guuid=0d889de6-1600-0000-4356-756b590e0000 pid=3673->guuid=a31dade6-1600-0000-4356-756b5a0e0000 pid=3674 clone guuid=319a04e7-1600-0000-4356-756b5e0e0000 pid=3678->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=fde29111-1700-0000-4356-756b9e0e0000 pid=3742->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=1c29293c-1700-0000-4356-756b0a0f0000 pid=3850->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=d49edb64-1700-0000-4356-756ba00f0000 pid=4000->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ff0f9086-1700-0000-4356-756b02100000 pid=4098->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=990c71b0-1700-0000-4356-756b76100000 pid=4214->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=6d9728e2-1700-0000-4356-756b2e110000 pid=4398->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=732c2b0c-1800-0000-4356-756ba4110000 pid=4516->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f20d4037-1800-0000-4356-756b0a120000 pid=4618->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ca251d63-1800-0000-4356-756b74120000 pid=4724->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=cbca898e-1800-0000-4356-756be7120000 pid=4839->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-21 01:20:54 UTC
File Type:
Text (Shell)
AV detection:
10 of 24 (41.67%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 683e263918425ae499c8f51ea8d76fa71292ab56bbf567d2b767122b092adf0e

(this sample)

  
Delivery method
Distributed via web download

Comments