MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7c45ee3bc05dd0e1ea8254600adb490dffaa7ea65105f5c59387e75210ea0da9. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 7c45ee3bc05dd0e1ea8254600adb490dffaa7ea65105f5c59387e75210ea0da9
SHA3-384 hash: e66ab706473f5a9816da0903dff7de3007867a7cfd2eee0bf1887c1ded1b05fa71d1769c8cd1b1ee76cddd3c64d98032
SHA1 hash: dd0e01cae9f88d1492d035d95f388e2c7ba96a1d
MD5 hash: 7551cf6a6d8cff8fab7865737f7563ea
humanhash: equal-sixteen-utah-zulu
File name:check1.sh
Download: download sample
File size:1'384 bytes
First seen:2026-06-16 15:18:42 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:VUeYj+H1TrEDMK9CFdYhEnHQBYcduuD9IdMzrirCwPrpUrpARiy3AnQZaZl1cSRc:VUeYj+H1TrEDMK9CnYhEkDqMzrirCqrt
TLSH T15221D2825731ADB82888455DA2A7505EA083021F565F6FECB5D69BFB0F0D8C1F5D8FB0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
65
Origin country :
ES ES
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=a36f713f-1b00-0000-5c3f-af19790b0000 pid=2937 /usr/bin/sudo guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940 /tmp/sample.bin guuid=a36f713f-1b00-0000-5c3f-af19790b0000 pid=2937->guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940 execve guuid=5e34f242-1b00-0000-5c3f-af19800b0000 pid=2944 /usr/bin/bash guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=5e34f242-1b00-0000-5c3f-af19800b0000 pid=2944 clone guuid=ced41843-1b00-0000-5c3f-af19810b0000 pid=2945 /usr/bin/grep guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=ced41843-1b00-0000-5c3f-af19810b0000 pid=2945 execve guuid=e402f543-1b00-0000-5c3f-af19850b0000 pid=2949 /usr/bin/bash guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=e402f543-1b00-0000-5c3f-af19850b0000 pid=2949 clone guuid=b7effd43-1b00-0000-5c3f-af19860b0000 pid=2950 /usr/bin/bash guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=b7effd43-1b00-0000-5c3f-af19860b0000 pid=2950 clone guuid=a85e6444-1b00-0000-5c3f-af19880b0000 pid=2952 /usr/bin/pgrep guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=a85e6444-1b00-0000-5c3f-af19880b0000 pid=2952 execve guuid=9fca9948-1b00-0000-5c3f-af19900b0000 pid=2960 /usr/bin/flock guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=9fca9948-1b00-0000-5c3f-af19900b0000 pid=2960 execve guuid=8f68704b-1b00-0000-5c3f-af19980b0000 pid=2968 /usr/bin/rm delete-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=8f68704b-1b00-0000-5c3f-af19980b0000 pid=2968 execve guuid=6e6f4e4e-1b00-0000-5c3f-af19a20b0000 pid=2978 /usr/bin/sleep guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=6e6f4e4e-1b00-0000-5c3f-af19a20b0000 pid=2978 execve guuid=77f75379-1c00-0000-5c3f-af196a0e0000 pid=3690 /usr/bin/wget net send-data write-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=77f75379-1c00-0000-5c3f-af196a0e0000 pid=3690 execve guuid=6c35497d-1c00-0000-5c3f-af19710e0000 pid=3697 /usr/bin/curl net send-data write-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=6c35497d-1c00-0000-5c3f-af19710e0000 pid=3697 execve guuid=5df47090-1c00-0000-5c3f-af19860e0000 pid=3718 /usr/bin/chmod guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=5df47090-1c00-0000-5c3f-af19860e0000 pid=3718 execve guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719 /usr/bin/bash guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719 clone guuid=dc5ed090-1c00-0000-5c3f-af19880e0000 pid=3720 /usr/bin/curl net send-data write-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=dc5ed090-1c00-0000-5c3f-af19880e0000 pid=3720 execve guuid=eb625bee-1c00-0000-5c3f-af19590f0000 pid=3929 /usr/bin/wget net send-data write-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=eb625bee-1c00-0000-5c3f-af19590f0000 pid=3929 execve guuid=01d4bb39-1d00-0000-5c3f-af1905100000 pid=4101 /usr/bin/sleep guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=01d4bb39-1d00-0000-5c3f-af1905100000 pid=4101 execve guuid=119d9528-1e00-0000-5c3f-af1923100000 pid=4131 /usr/bin/chmod guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=119d9528-1e00-0000-5c3f-af1923100000 pid=4131 execve guuid=68aaf828-1e00-0000-5c3f-af1924100000 pid=4132 /usr/bin/bash guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=68aaf828-1e00-0000-5c3f-af1924100000 pid=4132 clone guuid=01990129-1e00-0000-5c3f-af1925100000 pid=4133 /usr/bin/rm guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=01990129-1e00-0000-5c3f-af1925100000 pid=4133 execve guuid=347d4529-1e00-0000-5c3f-af1927100000 pid=4135 /usr/bin/sleep guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=347d4529-1e00-0000-5c3f-af1927100000 pid=4135 execve guuid=1669b953-1f00-0000-5c3f-af192d100000 pid=4141 /usr/bin/rm guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=1669b953-1f00-0000-5c3f-af192d100000 pid=4141 execve guuid=cb961a54-1f00-0000-5c3f-af192e100000 pid=4142 /usr/bin/rm delete-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=cb961a54-1f00-0000-5c3f-af192e100000 pid=4142 execve guuid=a509aa54-1f00-0000-5c3f-af192f100000 pid=4143 /usr/bin/rm delete-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=a509aa54-1f00-0000-5c3f-af192f100000 pid=4143 execve guuid=b2222a55-1f00-0000-5c3f-af1930100000 pid=4144 /usr/bin/rm delete-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=b2222a55-1f00-0000-5c3f-af1930100000 pid=4144 execve guuid=a054a755-1f00-0000-5c3f-af1931100000 pid=4145 /usr/bin/rm delete-file guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=a054a755-1f00-0000-5c3f-af1931100000 pid=4145 execve guuid=53a3f655-1f00-0000-5c3f-af1932100000 pid=4146 /usr/bin/rm guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=53a3f655-1f00-0000-5c3f-af1932100000 pid=4146 execve guuid=8da16e56-1f00-0000-5c3f-af1933100000 pid=4147 /usr/bin/clear guuid=16831942-1b00-0000-5c3f-af197c0b0000 pid=2940->guuid=8da16e56-1f00-0000-5c3f-af1933100000 pid=4147 execve guuid=07380444-1b00-0000-5c3f-af19870b0000 pid=2951 /usr/bin/bash guuid=e402f543-1b00-0000-5c3f-af19850b0000 pid=2949->guuid=07380444-1b00-0000-5c3f-af19870b0000 pid=2951 clone guuid=4fbd0c49-1b00-0000-5c3f-af19920b0000 pid=2962 /usr/bin/bash guuid=9fca9948-1b00-0000-5c3f-af19900b0000 pid=2960->guuid=4fbd0c49-1b00-0000-5c3f-af19920b0000 pid=2962 execve guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966 /usr/bin/bash zombie guuid=4fbd0c49-1b00-0000-5c3f-af19920b0000 pid=2962->guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966 execve guuid=9bdf624c-1b00-0000-5c3f-af199c0b0000 pid=2972 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=9bdf624c-1b00-0000-5c3f-af199c0b0000 pid=2972 execve guuid=ca73a74f-1b00-0000-5c3f-af19a70b0000 pid=2983 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=ca73a74f-1b00-0000-5c3f-af19a70b0000 pid=2983 execve guuid=b9d31352-1b00-0000-5c3f-af19af0b0000 pid=2991 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=b9d31352-1b00-0000-5c3f-af19af0b0000 pid=2991 execve guuid=99e46454-1b00-0000-5c3f-af19b70b0000 pid=2999 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=99e46454-1b00-0000-5c3f-af19b70b0000 pid=2999 execve guuid=f4fba356-1b00-0000-5c3f-af19bf0b0000 pid=3007 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=f4fba356-1b00-0000-5c3f-af19bf0b0000 pid=3007 execve guuid=d4b12881-1c00-0000-5c3f-af197b0e0000 pid=3707 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=d4b12881-1c00-0000-5c3f-af197b0e0000 pid=3707 execve guuid=9a99fd89-1c00-0000-5c3f-af197c0e0000 pid=3708 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=9a99fd89-1c00-0000-5c3f-af197c0e0000 pid=3708 execve guuid=0e12bb8f-1c00-0000-5c3f-af19830e0000 pid=3715 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=0e12bb8f-1c00-0000-5c3f-af19830e0000 pid=3715 execve guuid=2aafa692-1c00-0000-5c3f-af198e0e0000 pid=3726 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=2aafa692-1c00-0000-5c3f-af198e0e0000 pid=3726 execve guuid=3ef6d79a-1c00-0000-5c3f-af19970e0000 pid=3735 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=3ef6d79a-1c00-0000-5c3f-af19970e0000 pid=3735 execve guuid=8c52a8c5-1d00-0000-5c3f-af190e100000 pid=4110 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=8c52a8c5-1d00-0000-5c3f-af190e100000 pid=4110 execve guuid=a137bac9-1d00-0000-5c3f-af190f100000 pid=4111 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=a137bac9-1d00-0000-5c3f-af190f100000 pid=4111 execve guuid=5ed959cc-1d00-0000-5c3f-af1910100000 pid=4112 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=5ed959cc-1d00-0000-5c3f-af1910100000 pid=4112 execve guuid=ef2ab3ce-1d00-0000-5c3f-af1911100000 pid=4113 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=ef2ab3ce-1d00-0000-5c3f-af1911100000 pid=4113 execve guuid=c0a370d1-1d00-0000-5c3f-af1912100000 pid=4114 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=c0a370d1-1d00-0000-5c3f-af1912100000 pid=4114 execve guuid=874acffb-1e00-0000-5c3f-af1928100000 pid=4136 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=874acffb-1e00-0000-5c3f-af1928100000 pid=4136 execve guuid=027e3efe-1e00-0000-5c3f-af1929100000 pid=4137 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=027e3efe-1e00-0000-5c3f-af1929100000 pid=4137 execve guuid=8f7e1301-1f00-0000-5c3f-af192a100000 pid=4138 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=8f7e1301-1f00-0000-5c3f-af192a100000 pid=4138 execve guuid=015eaf03-1f00-0000-5c3f-af192b100000 pid=4139 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=015eaf03-1f00-0000-5c3f-af192b100000 pid=4139 execve guuid=d3d8d107-1f00-0000-5c3f-af192c100000 pid=4140 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=d3d8d107-1f00-0000-5c3f-af192c100000 pid=4140 execve guuid=eb715e32-2000-0000-5c3f-af1934100000 pid=4148 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=eb715e32-2000-0000-5c3f-af1934100000 pid=4148 execve guuid=568c7c35-2000-0000-5c3f-af1935100000 pid=4149 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=568c7c35-2000-0000-5c3f-af1935100000 pid=4149 execve guuid=cdaa9a37-2000-0000-5c3f-af1936100000 pid=4150 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=cdaa9a37-2000-0000-5c3f-af1936100000 pid=4150 execve guuid=60fae539-2000-0000-5c3f-af1937100000 pid=4151 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=60fae539-2000-0000-5c3f-af1937100000 pid=4151 execve guuid=ed1a043c-2000-0000-5c3f-af1938100000 pid=4152 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=ed1a043c-2000-0000-5c3f-af1938100000 pid=4152 execve guuid=03bf6266-2100-0000-5c3f-af1939100000 pid=4153 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=03bf6266-2100-0000-5c3f-af1939100000 pid=4153 execve guuid=fb119569-2100-0000-5c3f-af193a100000 pid=4154 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=fb119569-2100-0000-5c3f-af193a100000 pid=4154 execve guuid=fe791b6c-2100-0000-5c3f-af193b100000 pid=4155 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=fe791b6c-2100-0000-5c3f-af193b100000 pid=4155 execve guuid=7eb5bd6e-2100-0000-5c3f-af193c100000 pid=4156 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=7eb5bd6e-2100-0000-5c3f-af193c100000 pid=4156 execve guuid=e9502d71-2100-0000-5c3f-af193d100000 pid=4157 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=e9502d71-2100-0000-5c3f-af193d100000 pid=4157 execve guuid=5ef7af9b-2200-0000-5c3f-af193e100000 pid=4158 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=5ef7af9b-2200-0000-5c3f-af193e100000 pid=4158 execve guuid=1e1eec9d-2200-0000-5c3f-af193f100000 pid=4159 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=1e1eec9d-2200-0000-5c3f-af193f100000 pid=4159 execve guuid=85a821a0-2200-0000-5c3f-af1940100000 pid=4160 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=85a821a0-2200-0000-5c3f-af1940100000 pid=4160 execve guuid=2e4b5da2-2200-0000-5c3f-af1941100000 pid=4161 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=2e4b5da2-2200-0000-5c3f-af1941100000 pid=4161 execve guuid=0193a6a4-2200-0000-5c3f-af1942100000 pid=4162 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=0193a6a4-2200-0000-5c3f-af1942100000 pid=4162 execve guuid=c9cb07cf-2300-0000-5c3f-af1943100000 pid=4163 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=c9cb07cf-2300-0000-5c3f-af1943100000 pid=4163 execve guuid=0b8cd4d2-2300-0000-5c3f-af1944100000 pid=4164 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=0b8cd4d2-2300-0000-5c3f-af1944100000 pid=4164 execve guuid=60d3dbd6-2300-0000-5c3f-af1945100000 pid=4165 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=60d3dbd6-2300-0000-5c3f-af1945100000 pid=4165 execve guuid=37294cd9-2300-0000-5c3f-af1946100000 pid=4166 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=37294cd9-2300-0000-5c3f-af1946100000 pid=4166 execve guuid=09869cdb-2300-0000-5c3f-af1947100000 pid=4167 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=09869cdb-2300-0000-5c3f-af1947100000 pid=4167 execve guuid=7b51fc05-2500-0000-5c3f-af1948100000 pid=4168 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=7b51fc05-2500-0000-5c3f-af1948100000 pid=4168 execve guuid=a3be1908-2500-0000-5c3f-af1949100000 pid=4169 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=a3be1908-2500-0000-5c3f-af1949100000 pid=4169 execve guuid=9954030c-2500-0000-5c3f-af194a100000 pid=4170 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=9954030c-2500-0000-5c3f-af194a100000 pid=4170 execve guuid=67732d0e-2500-0000-5c3f-af194b100000 pid=4171 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=67732d0e-2500-0000-5c3f-af194b100000 pid=4171 execve guuid=d6ea5c10-2500-0000-5c3f-af194c100000 pid=4172 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=d6ea5c10-2500-0000-5c3f-af194c100000 pid=4172 execve guuid=0be7ba3a-2600-0000-5c3f-af194d100000 pid=4173 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=0be7ba3a-2600-0000-5c3f-af194d100000 pid=4173 execve guuid=92011b3d-2600-0000-5c3f-af194e100000 pid=4174 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=92011b3d-2600-0000-5c3f-af194e100000 pid=4174 execve guuid=75b54240-2600-0000-5c3f-af194f100000 pid=4175 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=75b54240-2600-0000-5c3f-af194f100000 pid=4175 execve guuid=fb4eb042-2600-0000-5c3f-af1950100000 pid=4176 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=fb4eb042-2600-0000-5c3f-af1950100000 pid=4176 execve guuid=ab86ff44-2600-0000-5c3f-af1951100000 pid=4177 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=ab86ff44-2600-0000-5c3f-af1951100000 pid=4177 execve guuid=d85e696f-2700-0000-5c3f-af1952100000 pid=4178 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=d85e696f-2700-0000-5c3f-af1952100000 pid=4178 execve guuid=96d5ce71-2700-0000-5c3f-af1953100000 pid=4179 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=96d5ce71-2700-0000-5c3f-af1953100000 pid=4179 execve guuid=881a7074-2700-0000-5c3f-af1954100000 pid=4180 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=881a7074-2700-0000-5c3f-af1954100000 pid=4180 execve guuid=c517be76-2700-0000-5c3f-af1955100000 pid=4181 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=c517be76-2700-0000-5c3f-af1955100000 pid=4181 execve guuid=ebd60679-2700-0000-5c3f-af1956100000 pid=4182 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=ebd60679-2700-0000-5c3f-af1956100000 pid=4182 execve guuid=c92d8ea3-2800-0000-5c3f-af1957100000 pid=4183 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=c92d8ea3-2800-0000-5c3f-af1957100000 pid=4183 execve guuid=df91fea8-2800-0000-5c3f-af1958100000 pid=4184 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=df91fea8-2800-0000-5c3f-af1958100000 pid=4184 execve guuid=f46ea5ac-2800-0000-5c3f-af1959100000 pid=4185 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=f46ea5ac-2800-0000-5c3f-af1959100000 pid=4185 execve guuid=fdfeabaf-2800-0000-5c3f-af195a100000 pid=4186 /usr/bin/pgrep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=fdfeabaf-2800-0000-5c3f-af195a100000 pid=4186 execve guuid=c919e2b1-2800-0000-5c3f-af195b100000 pid=4187 /usr/bin/sleep guuid=4a4f2f4b-1b00-0000-5c3f-af19960b0000 pid=2966->guuid=c919e2b1-2800-0000-5c3f-af195b100000 pid=4187 execve ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 94.26.106.195:80 guuid=77f75379-1c00-0000-5c3f-af196a0e0000 pid=3690->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 138B guuid=6c35497d-1c00-0000-5c3f-af19710e0000 pid=3697->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 87B guuid=6c1c2191-1c00-0000-5c3f-af198a0e0000 pid=3722 /usr/bin/curl net send-data write-file guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719->guuid=6c1c2191-1c00-0000-5c3f-af198a0e0000 pid=3722 execve guuid=4d0df8be-1c00-0000-5c3f-af19ed0e0000 pid=3821 /usr/bin/wget net send-data write-file guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719->guuid=4d0df8be-1c00-0000-5c3f-af19ed0e0000 pid=3821 execve guuid=eb2005db-1c00-0000-5c3f-af19210f0000 pid=3873 /usr/bin/chmod guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719->guuid=eb2005db-1c00-0000-5c3f-af19210f0000 pid=3873 execve guuid=f6e143db-1c00-0000-5c3f-af19220f0000 pid=3874 /usr/bin/bash zombie guuid=657ebd90-1c00-0000-5c3f-af19870e0000 pid=3719->guuid=f6e143db-1c00-0000-5c3f-af19220f0000 pid=3874 clone guuid=dc5ed090-1c00-0000-5c3f-af19880e0000 pid=3720->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 84B guuid=6c1c2191-1c00-0000-5c3f-af198a0e0000 pid=3722->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 85B guuid=4d0df8be-1c00-0000-5c3f-af19ed0e0000 pid=3821->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 136B guuid=eb625bee-1c00-0000-5c3f-af19590f0000 pid=3929->ba1fb6e1-666d-58e6-bb35-2cb60c3c5a49 send: 135B
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-06-16 15:09:34 UTC
File Type:
Text (Shell)
AV detection:
5 of 36 (13.89%)
Threat level:
  3/5
Result
Malware family:
Score:
  10/10
Tags:
family:xmrig antivm defense_evasion discovery execution linux miner persistence privilege_escalation
Behaviour
Command and Scripting Interpreter: Unix Shell
Reads runtime system information
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Deletes log files
Enumerates running processes
File and Directory Permissions Modification
Indicator Removal: Clear Command History
Executes dropped EXE
Family: xmrig
XMRig Miner payload
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7c45ee3bc05dd0e1ea8254600adb490dffaa7ea65105f5c59387e75210ea0da9

(this sample)

  
Delivery method
Distributed via web download

Comments