MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 776b383cdfb704ff81b0db67e14d0d65db9cf107db70ce4023aac9efd5320d0a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 776b383cdfb704ff81b0db67e14d0d65db9cf107db70ce4023aac9efd5320d0a
SHA3-384 hash: 58b498c2b02e01a99ca93e68e2b17cce881561e73208606e35fa31c242aaad185b2431e4a4caf784fe17b50cac557a5b
SHA1 hash: 343e43950cf5d8226535512d3ac9a68d68382af9
MD5 hash: 06aea395d297514dda9dae71cc1545bb
humanhash: minnesota-floor-mountain-freddie
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-04-07 19:54:02 UTC
Last seen:2026-04-08 06:25:13 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTa39wK+tn8sbs7JCinx9bAulNXYq9DG+NjVsNXYrkJ:V9K+HQJnVPiq9DGmKi2
TLSH T103D02E627827013460964C64F2C77000F1D093BE6C6AD22CEE2B20701F0260AF084A80
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
99
# of downloads :
4
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Gathering data
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-04-07T16:59:00Z UTC
Last seen:
2026-04-09T07:14:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=f32604cb-1600-0000-046f-0d8ab00d0000 pid=3504 /usr/bin/sudo guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506 /tmp/sample.bin guuid=f32604cb-1600-0000-046f-0d8ab00d0000 pid=3504->guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506 execve guuid=81cbf6cd-1600-0000-046f-0d8ab30d0000 pid=3507 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=81cbf6cd-1600-0000-046f-0d8ab30d0000 pid=3507 execve guuid=41a73dce-1600-0000-046f-0d8ab50d0000 pid=3509 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=41a73dce-1600-0000-046f-0d8ab50d0000 pid=3509 execve guuid=df20aae9-1600-0000-046f-0d8afd0d0000 pid=3581 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=df20aae9-1600-0000-046f-0d8afd0d0000 pid=3581 execve guuid=c6d1e8e9-1600-0000-046f-0d8aff0d0000 pid=3583 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=c6d1e8e9-1600-0000-046f-0d8aff0d0000 pid=3583 clone guuid=2fe999eb-1600-0000-046f-0d8a050e0000 pid=3589 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2fe999eb-1600-0000-046f-0d8a050e0000 pid=3589 execve guuid=9026d2eb-1600-0000-046f-0d8a070e0000 pid=3591 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9026d2eb-1600-0000-046f-0d8a070e0000 pid=3591 execve guuid=b0a6b90b-1700-0000-046f-0d8a560e0000 pid=3670 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=b0a6b90b-1700-0000-046f-0d8a560e0000 pid=3670 execve guuid=84aefc0b-1700-0000-046f-0d8a570e0000 pid=3671 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=84aefc0b-1700-0000-046f-0d8a570e0000 pid=3671 clone guuid=51a69a0c-1700-0000-046f-0d8a590e0000 pid=3673 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=51a69a0c-1700-0000-046f-0d8a590e0000 pid=3673 execve guuid=9aeaf80c-1700-0000-046f-0d8a5a0e0000 pid=3674 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9aeaf80c-1700-0000-046f-0d8a5a0e0000 pid=3674 execve guuid=15ea3328-1700-0000-046f-0d8aa90e0000 pid=3753 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=15ea3328-1700-0000-046f-0d8aa90e0000 pid=3753 execve guuid=25749c28-1700-0000-046f-0d8aab0e0000 pid=3755 /tmp/XSDX guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=25749c28-1700-0000-046f-0d8aab0e0000 pid=3755 execve guuid=9531cb28-1700-0000-046f-0d8aad0e0000 pid=3757 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9531cb28-1700-0000-046f-0d8aad0e0000 pid=3757 execve guuid=b95f3829-1700-0000-046f-0d8aaf0e0000 pid=3759 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=b95f3829-1700-0000-046f-0d8aaf0e0000 pid=3759 execve guuid=4be75944-1700-0000-046f-0d8adf0e0000 pid=3807 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=4be75944-1700-0000-046f-0d8adf0e0000 pid=3807 execve guuid=68cad444-1700-0000-046f-0d8ae20e0000 pid=3810 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=68cad444-1700-0000-046f-0d8ae20e0000 pid=3810 clone guuid=71f2cd45-1700-0000-046f-0d8ae80e0000 pid=3816 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=71f2cd45-1700-0000-046f-0d8ae80e0000 pid=3816 execve guuid=a3f33c46-1700-0000-046f-0d8aea0e0000 pid=3818 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=a3f33c46-1700-0000-046f-0d8aea0e0000 pid=3818 execve guuid=fb4e3662-1700-0000-046f-0d8a320f0000 pid=3890 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=fb4e3662-1700-0000-046f-0d8a320f0000 pid=3890 execve guuid=0db59262-1700-0000-046f-0d8a360f0000 pid=3894 /tmp/YJPA guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=0db59262-1700-0000-046f-0d8a360f0000 pid=3894 execve guuid=103bb062-1700-0000-046f-0d8a380f0000 pid=3896 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=103bb062-1700-0000-046f-0d8a380f0000 pid=3896 execve guuid=d60bfd62-1700-0000-046f-0d8a390f0000 pid=3897 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=d60bfd62-1700-0000-046f-0d8a390f0000 pid=3897 execve guuid=2fe63580-1700-0000-046f-0d8abf0f0000 pid=4031 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2fe63580-1700-0000-046f-0d8abf0f0000 pid=4031 execve guuid=0ffd8f80-1700-0000-046f-0d8ac00f0000 pid=4032 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=0ffd8f80-1700-0000-046f-0d8ac00f0000 pid=4032 clone guuid=f7c35281-1700-0000-046f-0d8ac50f0000 pid=4037 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=f7c35281-1700-0000-046f-0d8ac50f0000 pid=4037 execve guuid=ae1ca481-1700-0000-046f-0d8ac70f0000 pid=4039 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=ae1ca481-1700-0000-046f-0d8ac70f0000 pid=4039 execve guuid=425bd19c-1700-0000-046f-0d8a26100000 pid=4134 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=425bd19c-1700-0000-046f-0d8a26100000 pid=4134 execve guuid=568f109d-1700-0000-046f-0d8a28100000 pid=4136 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=568f109d-1700-0000-046f-0d8a28100000 pid=4136 clone guuid=8d2d9e9d-1700-0000-046f-0d8a2d100000 pid=4141 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=8d2d9e9d-1700-0000-046f-0d8a2d100000 pid=4141 execve guuid=0e63db9d-1700-0000-046f-0d8a2e100000 pid=4142 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=0e63db9d-1700-0000-046f-0d8a2e100000 pid=4142 execve guuid=f6b7dfb8-1700-0000-046f-0d8a80100000 pid=4224 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=f6b7dfb8-1700-0000-046f-0d8a80100000 pid=4224 execve guuid=2a1854b9-1700-0000-046f-0d8a82100000 pid=4226 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2a1854b9-1700-0000-046f-0d8a82100000 pid=4226 clone guuid=3a5d07ba-1700-0000-046f-0d8a85100000 pid=4229 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=3a5d07ba-1700-0000-046f-0d8a85100000 pid=4229 execve guuid=44cf48ba-1700-0000-046f-0d8a86100000 pid=4230 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=44cf48ba-1700-0000-046f-0d8a86100000 pid=4230 execve guuid=9a4beacf-1700-0000-046f-0d8aec100000 pid=4332 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9a4beacf-1700-0000-046f-0d8aec100000 pid=4332 execve guuid=2a202bd0-1700-0000-046f-0d8aee100000 pid=4334 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2a202bd0-1700-0000-046f-0d8aee100000 pid=4334 clone guuid=40ddafd0-1700-0000-046f-0d8af2100000 pid=4338 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=40ddafd0-1700-0000-046f-0d8af2100000 pid=4338 execve guuid=9251ead0-1700-0000-046f-0d8af4100000 pid=4340 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9251ead0-1700-0000-046f-0d8af4100000 pid=4340 execve guuid=c63b2eec-1700-0000-046f-0d8a45110000 pid=4421 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=c63b2eec-1700-0000-046f-0d8a45110000 pid=4421 execve guuid=ecf16bec-1700-0000-046f-0d8a49110000 pid=4425 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=ecf16bec-1700-0000-046f-0d8a49110000 pid=4425 clone guuid=7cafe9ec-1700-0000-046f-0d8a4d110000 pid=4429 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=7cafe9ec-1700-0000-046f-0d8a4d110000 pid=4429 execve guuid=1acd3bed-1700-0000-046f-0d8a4f110000 pid=4431 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=1acd3bed-1700-0000-046f-0d8a4f110000 pid=4431 execve guuid=ce045a08-1800-0000-046f-0d8ab1110000 pid=4529 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=ce045a08-1800-0000-046f-0d8ab1110000 pid=4529 execve guuid=b5959208-1800-0000-046f-0d8ab3110000 pid=4531 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=b5959208-1800-0000-046f-0d8ab3110000 pid=4531 clone guuid=6098660a-1800-0000-046f-0d8ab9110000 pid=4537 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=6098660a-1800-0000-046f-0d8ab9110000 pid=4537 execve guuid=b8719f0a-1800-0000-046f-0d8aba110000 pid=4538 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=b8719f0a-1800-0000-046f-0d8aba110000 pid=4538 execve guuid=bb950a26-1800-0000-046f-0d8a1c120000 pid=4636 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=bb950a26-1800-0000-046f-0d8a1c120000 pid=4636 execve guuid=14a95126-1800-0000-046f-0d8a1d120000 pid=4637 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=14a95126-1800-0000-046f-0d8a1d120000 pid=4637 clone guuid=d85a6d27-1800-0000-046f-0d8a24120000 pid=4644 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=d85a6d27-1800-0000-046f-0d8a24120000 pid=4644 execve guuid=02c3aa27-1800-0000-046f-0d8a28120000 pid=4648 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=02c3aa27-1800-0000-046f-0d8a28120000 pid=4648 execve guuid=59abde42-1800-0000-046f-0d8a71120000 pid=4721 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=59abde42-1800-0000-046f-0d8a71120000 pid=4721 execve guuid=4b668b43-1800-0000-046f-0d8a75120000 pid=4725 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=4b668b43-1800-0000-046f-0d8a75120000 pid=4725 clone guuid=e5532e44-1800-0000-046f-0d8a7a120000 pid=4730 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=e5532e44-1800-0000-046f-0d8a7a120000 pid=4730 execve guuid=b9dc7044-1800-0000-046f-0d8a7d120000 pid=4733 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=b9dc7044-1800-0000-046f-0d8a7d120000 pid=4733 execve guuid=84b0f55f-1800-0000-046f-0d8ac9120000 pid=4809 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=84b0f55f-1800-0000-046f-0d8ac9120000 pid=4809 execve guuid=02143d60-1800-0000-046f-0d8acb120000 pid=4811 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=02143d60-1800-0000-046f-0d8acb120000 pid=4811 clone guuid=eb8b1061-1800-0000-046f-0d8acf120000 pid=4815 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=eb8b1061-1800-0000-046f-0d8acf120000 pid=4815 execve guuid=6b437161-1800-0000-046f-0d8ad0120000 pid=4816 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=6b437161-1800-0000-046f-0d8ad0120000 pid=4816 execve guuid=a5565d7c-1800-0000-046f-0d8a1a130000 pid=4890 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=a5565d7c-1800-0000-046f-0d8a1a130000 pid=4890 execve guuid=c0caa87c-1800-0000-046f-0d8a1c130000 pid=4892 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=c0caa87c-1800-0000-046f-0d8a1c130000 pid=4892 clone guuid=f44d237e-1800-0000-046f-0d8a23130000 pid=4899 /usr/bin/rm guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=f44d237e-1800-0000-046f-0d8a23130000 pid=4899 execve guuid=a038a47e-1800-0000-046f-0d8a26130000 pid=4902 /usr/bin/wget net send-data write-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=a038a47e-1800-0000-046f-0d8a26130000 pid=4902 execve guuid=9ced5499-1800-0000-046f-0d8a6f130000 pid=4975 /usr/bin/chmod guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=9ced5499-1800-0000-046f-0d8a6f130000 pid=4975 execve guuid=059b419a-1800-0000-046f-0d8a72130000 pid=4978 /usr/bin/dash guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=059b419a-1800-0000-046f-0d8a72130000 pid=4978 clone guuid=d8cb369d-1800-0000-046f-0d8a7a130000 pid=4986 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=d8cb369d-1800-0000-046f-0d8a7a130000 pid=4986 execve guuid=1a198c9d-1800-0000-046f-0d8a7c130000 pid=4988 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=1a198c9d-1800-0000-046f-0d8a7c130000 pid=4988 execve guuid=2b43eb9d-1800-0000-046f-0d8a7e130000 pid=4990 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2b43eb9d-1800-0000-046f-0d8a7e130000 pid=4990 execve guuid=4548509e-1800-0000-046f-0d8a80130000 pid=4992 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=4548509e-1800-0000-046f-0d8a80130000 pid=4992 execve guuid=8343b89e-1800-0000-046f-0d8a82130000 pid=4994 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=8343b89e-1800-0000-046f-0d8a82130000 pid=4994 execve guuid=4ea41b9f-1800-0000-046f-0d8a84130000 pid=4996 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=4ea41b9f-1800-0000-046f-0d8a84130000 pid=4996 execve guuid=07e0879f-1800-0000-046f-0d8a86130000 pid=4998 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=07e0879f-1800-0000-046f-0d8a86130000 pid=4998 execve guuid=2d8fee9f-1800-0000-046f-0d8a88130000 pid=5000 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=2d8fee9f-1800-0000-046f-0d8a88130000 pid=5000 execve guuid=960d57a0-1800-0000-046f-0d8a8a130000 pid=5002 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=960d57a0-1800-0000-046f-0d8a8a130000 pid=5002 execve guuid=16c8b1a0-1800-0000-046f-0d8a8c130000 pid=5004 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=16c8b1a0-1800-0000-046f-0d8a8c130000 pid=5004 execve guuid=40590fa1-1800-0000-046f-0d8a8e130000 pid=5006 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=40590fa1-1800-0000-046f-0d8a8e130000 pid=5006 execve guuid=e40b6aa1-1800-0000-046f-0d8a90130000 pid=5008 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=e40b6aa1-1800-0000-046f-0d8a90130000 pid=5008 execve guuid=60d9c1a1-1800-0000-046f-0d8a92130000 pid=5010 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=60d9c1a1-1800-0000-046f-0d8a92130000 pid=5010 execve guuid=301012a2-1800-0000-046f-0d8a94130000 pid=5012 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=301012a2-1800-0000-046f-0d8a94130000 pid=5012 execve guuid=bb6463a2-1800-0000-046f-0d8a97130000 pid=5015 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=bb6463a2-1800-0000-046f-0d8a97130000 pid=5015 execve guuid=24ceb1a2-1800-0000-046f-0d8a99130000 pid=5017 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=24ceb1a2-1800-0000-046f-0d8a99130000 pid=5017 execve guuid=df1d11a3-1800-0000-046f-0d8a9b130000 pid=5019 /usr/bin/rm delete-file guuid=5af594cd-1600-0000-046f-0d8ab20d0000 pid=3506->guuid=df1d11a3-1800-0000-046f-0d8a9b130000 pid=5019 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=41a73dce-1600-0000-046f-0d8ab50d0000 pid=3509->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9026d2eb-1600-0000-046f-0d8a070e0000 pid=3591->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9aeaf80c-1700-0000-046f-0d8a5a0e0000 pid=3674->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756 /tmp/XSDX net send-data write-file zombie guuid=25749c28-1700-0000-046f-0d8aab0e0000 pid=3755->guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 0734f5ed-e253-55cb-b667-c800d7698d2a 34.27.195.76:443 guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756->0734f5ed-e253-55cb-b667-c800d7698d2a send: 469B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=7eb45935-1700-0000-046f-0d8ab70e0000 pid=3767 /usr/bin/uname guuid=5e59b528-1700-0000-046f-0d8aac0e0000 pid=3756->guuid=7eb45935-1700-0000-046f-0d8ab70e0000 pid=3767 execve guuid=b95f3829-1700-0000-046f-0d8aaf0e0000 pid=3759->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a3f33c46-1700-0000-046f-0d8aea0e0000 pid=3818->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=08caa562-1700-0000-046f-0d8a370f0000 pid=3895 /tmp/YJPA zombie guuid=0db59262-1700-0000-046f-0d8a360f0000 pid=3894->guuid=08caa562-1700-0000-046f-0d8a370f0000 pid=3895 clone guuid=d60bfd62-1700-0000-046f-0d8a390f0000 pid=3897->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=ae1ca481-1700-0000-046f-0d8ac70f0000 pid=4039->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=0e63db9d-1700-0000-046f-0d8a2e100000 pid=4142->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=44cf48ba-1700-0000-046f-0d8a86100000 pid=4230->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9251ead0-1700-0000-046f-0d8af4100000 pid=4340->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=1acd3bed-1700-0000-046f-0d8a4f110000 pid=4431->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b8719f0a-1800-0000-046f-0d8aba110000 pid=4538->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=02c3aa27-1800-0000-046f-0d8a28120000 pid=4648->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b9dc7044-1800-0000-046f-0d8a7d120000 pid=4733->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=6b437161-1800-0000-046f-0d8ad0120000 pid=4816->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a038a47e-1800-0000-046f-0d8a26130000 pid=4902->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Gathering data
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-04-07 20:22:22 UTC
File Type:
Text (Shell)
AV detection:
12 of 38 (31.58%)
Threat level:
  5/5
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 776b383cdfb704ff81b0db67e14d0d65db9cf107db70ce4023aac9efd5320d0a

(this sample)

  
Delivery method
Distributed via web download

Comments