MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7e94637b5fee7aa4fae48b6025d4ac02a02bcd0dd077c15fa3445a0a26f3c511. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 7e94637b5fee7aa4fae48b6025d4ac02a02bcd0dd077c15fa3445a0a26f3c511
SHA3-384 hash: 68b0d388b94c184cbab7e394b02ed43b28b434cf14e8fbb85430b152712db5dc684c199dac4066c9fb1fc900f6f8f324
SHA1 hash: fe254343ae003240161efbac57d4c84a7313a829
MD5 hash: 998bf854d2bd74133c4c8834111ea35c
humanhash: nitrogen-oxygen-king-queen
File name:init.sh
Download: download sample
File size:11'966 bytes
First seen:2026-06-20 16:06:30 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:Ys/MEhrlqT/QKZPVmhxZPKgjlhtVZDmh5RDKlE3O+SUmlT0P3V6JG8zWJmH76N2x:xlGS1LBYRQEZT384BpA
TLSH T113329651FD32A530262D80F5AACA2500F14B513B0A1C7905B1BF9664BF3CBAC61FD6FA
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
35
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
opendir
Verdict:
Adware
File Type:
Script
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=7504445c-1e00-0000-ecbc-c3e82e140000 pid=5166 /usr/bin/sudo guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167 /tmp/sample.bin write-file guuid=7504445c-1e00-0000-ecbc-c3e82e140000 pid=5166->guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167 execve guuid=945bd460-1e00-0000-ecbc-c3e830140000 pid=5168 /usr/bin/uname guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=945bd460-1e00-0000-ecbc-c3e830140000 pid=5168 execve guuid=c1b35061-1e00-0000-ecbc-c3e831140000 pid=5169 /usr/bin/grep guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=c1b35061-1e00-0000-ecbc-c3e831140000 pid=5169 execve guuid=7b850f62-1e00-0000-ecbc-c3e832140000 pid=5170 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=7b850f62-1e00-0000-ecbc-c3e832140000 pid=5170 execve guuid=b9e8c962-1e00-0000-ecbc-c3e833140000 pid=5171 /usr/bin/bash guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=b9e8c962-1e00-0000-ecbc-c3e833140000 pid=5171 clone guuid=e5623d63-1e00-0000-ecbc-c3e835140000 pid=5173 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=e5623d63-1e00-0000-ecbc-c3e835140000 pid=5173 execve guuid=2b88af63-1e00-0000-ecbc-c3e836140000 pid=5174 /usr/bin/wget net send-data write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=2b88af63-1e00-0000-ecbc-c3e836140000 pid=5174 execve guuid=2588af67-1e00-0000-ecbc-c3e837140000 pid=5175 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=2588af67-1e00-0000-ecbc-c3e837140000 pid=5175 execve guuid=50f9f167-1e00-0000-ecbc-c3e838140000 pid=5176 /tmp/.d write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=50f9f167-1e00-0000-ecbc-c3e838140000 pid=5176 execve guuid=ac9ffa67-1e00-0000-ecbc-c3e839140000 pid=5177 /usr/bin/sleep guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=ac9ffa67-1e00-0000-ecbc-c3e839140000 pid=5177 execve guuid=86e7c6df-1e00-0000-ecbc-c3e85a140000 pid=5210 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=86e7c6df-1e00-0000-ecbc-c3e85a140000 pid=5210 execve guuid=260703e7-1e00-0000-ecbc-c3e85b140000 pid=5211 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=260703e7-1e00-0000-ecbc-c3e85b140000 pid=5211 execve guuid=5a4755e7-1e00-0000-ecbc-c3e85c140000 pid=5212 /usr/bin/bash guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=5a4755e7-1e00-0000-ecbc-c3e85c140000 pid=5212 clone guuid=c40284e7-1e00-0000-ecbc-c3e85e140000 pid=5214 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=c40284e7-1e00-0000-ecbc-c3e85e140000 pid=5214 execve guuid=39e4dce7-1e00-0000-ecbc-c3e85f140000 pid=5215 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=39e4dce7-1e00-0000-ecbc-c3e85f140000 pid=5215 execve guuid=82bc28e8-1e00-0000-ecbc-c3e860140000 pid=5216 /usr/bin/bash guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=82bc28e8-1e00-0000-ecbc-c3e860140000 pid=5216 clone guuid=dd5a85e8-1e00-0000-ecbc-c3e862140000 pid=5218 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=dd5a85e8-1e00-0000-ecbc-c3e862140000 pid=5218 execve guuid=317306e9-1e00-0000-ecbc-c3e863140000 pid=5219 /usr/bin/wget net send-data write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=317306e9-1e00-0000-ecbc-c3e863140000 pid=5219 execve guuid=0d59b6ec-1e00-0000-ecbc-c3e864140000 pid=5220 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=0d59b6ec-1e00-0000-ecbc-c3e864140000 pid=5220 execve guuid=47ff11ed-1e00-0000-ecbc-c3e865140000 pid=5221 /dev/shm/.d write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=47ff11ed-1e00-0000-ecbc-c3e865140000 pid=5221 execve guuid=627e1fed-1e00-0000-ecbc-c3e866140000 pid=5222 /usr/bin/sleep guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=627e1fed-1e00-0000-ecbc-c3e866140000 pid=5222 execve guuid=2766e467-1f00-0000-ecbc-c3e86f140000 pid=5231 /usr/bin/rm guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=2766e467-1f00-0000-ecbc-c3e86f140000 pid=5231 execve guuid=37e26368-1f00-0000-ecbc-c3e870140000 pid=5232 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=37e26368-1f00-0000-ecbc-c3e870140000 pid=5232 execve guuid=4c7cda68-1f00-0000-ecbc-c3e871140000 pid=5233 /usr/bin/bash guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=4c7cda68-1f00-0000-ecbc-c3e871140000 pid=5233 clone guuid=31718869-1f00-0000-ecbc-c3e873140000 pid=5235 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=31718869-1f00-0000-ecbc-c3e873140000 pid=5235 execve guuid=3a5f0a6a-1f00-0000-ecbc-c3e874140000 pid=5236 /usr/bin/wget net send-data write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=3a5f0a6a-1f00-0000-ecbc-c3e874140000 pid=5236 execve guuid=4919756e-1f00-0000-ecbc-c3e875140000 pid=5237 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=4919756e-1f00-0000-ecbc-c3e875140000 pid=5237 execve guuid=412b296f-1f00-0000-ecbc-c3e876140000 pid=5238 /root/.d write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=412b296f-1f00-0000-ecbc-c3e876140000 pid=5238 execve guuid=e650326f-1f00-0000-ecbc-c3e877140000 pid=5239 /usr/bin/sleep guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=e650326f-1f00-0000-ecbc-c3e877140000 pid=5239 execve guuid=3bef0fe7-1f00-0000-ecbc-c3e880140000 pid=5248 /usr/bin/rm guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=3bef0fe7-1f00-0000-ecbc-c3e880140000 pid=5248 execve guuid=66de8ce7-1f00-0000-ecbc-c3e881140000 pid=5249 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=66de8ce7-1f00-0000-ecbc-c3e881140000 pid=5249 execve guuid=8f49f5e7-1f00-0000-ecbc-c3e882140000 pid=5250 /usr/bin/bash guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=8f49f5e7-1f00-0000-ecbc-c3e882140000 pid=5250 clone guuid=be267fe8-1f00-0000-ecbc-c3e884140000 pid=5252 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=be267fe8-1f00-0000-ecbc-c3e884140000 pid=5252 execve guuid=443ddfe8-1f00-0000-ecbc-c3e885140000 pid=5253 /usr/bin/wget net send-data write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=443ddfe8-1f00-0000-ecbc-c3e885140000 pid=5253 execve guuid=0b5d6bee-1f00-0000-ecbc-c3e886140000 pid=5254 /usr/bin/chmod guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=0b5d6bee-1f00-0000-ecbc-c3e886140000 pid=5254 execve guuid=b8eff3ee-1f00-0000-ecbc-c3e887140000 pid=5255 /.d write-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=b8eff3ee-1f00-0000-ecbc-c3e887140000 pid=5255 execve guuid=ec173cef-1f00-0000-ecbc-c3e888140000 pid=5256 /usr/bin/sleep guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=ec173cef-1f00-0000-ecbc-c3e888140000 pid=5256 execve guuid=56f73567-2000-0000-ecbc-c3e8a1140000 pid=5281 /usr/bin/rm guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=56f73567-2000-0000-ecbc-c3e8a1140000 pid=5281 execve guuid=c8d88e67-2000-0000-ecbc-c3e8a2140000 pid=5282 /usr/bin/basename guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=c8d88e67-2000-0000-ecbc-c3e8a2140000 pid=5282 execve guuid=8805e467-2000-0000-ecbc-c3e8a3140000 pid=5283 /usr/bin/rm delete-file guuid=e5982a60-1e00-0000-ecbc-c3e82f140000 pid=5167->guuid=8805e467-2000-0000-ecbc-c3e8a3140000 pid=5283 execve guuid=7529d962-1e00-0000-ecbc-c3e834140000 pid=5172 /tmp/.exectest.5167 guuid=b9e8c962-1e00-0000-ecbc-c3e833140000 pid=5171->guuid=7529d962-1e00-0000-ecbc-c3e834140000 pid=5172 execve 859a4cbe-44a6-5949-a757-ee7cf89fbd69 91.239.211.89:80 guuid=2b88af63-1e00-0000-ecbc-c3e836140000 pid=5174->859a4cbe-44a6-5949-a757-ee7cf89fbd69 send: 141B guuid=c6296969-1e00-0000-ecbc-c3e83a140000 pid=5178 /tmp/.d zombie guuid=50f9f167-1e00-0000-ecbc-c3e838140000 pid=5176->guuid=c6296969-1e00-0000-ecbc-c3e83a140000 pid=5178 clone guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179 /tmp/.d net send-data write-config write-file zombie guuid=c6296969-1e00-0000-ecbc-c3e83a140000 pid=5178->guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179 clone ffee5cfb-bb94-52c2-8935-ae3a87e774db 127.0.0.1:42780 guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179->ffee5cfb-bb94-52c2-8935-ae3a87e774db con 54d92a3b-1447-55af-b534-047898c60c8d 1.1.1.1:53 guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179->54d92a3b-1447-55af-b534-047898c60c8d send: 40B guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5180 /tmp/.d zombie guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179->guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5180 clone guuid=e48cec6a-1e00-0000-ecbc-c3e83d140000 pid=5181 /usr/bin/dash zombie guuid=9aec7169-1e00-0000-ecbc-c3e83b140000 pid=5179->guuid=e48cec6a-1e00-0000-ecbc-c3e83d140000 pid=5181 execve guuid=a4a71c6b-1e00-0000-ecbc-c3e83e140000 pid=5182 /usr/bin/systemctl guuid=e48cec6a-1e00-0000-ecbc-c3e83d140000 pid=5181->guuid=a4a71c6b-1e00-0000-ecbc-c3e83e140000 pid=5182 execve guuid=1b1a63e7-1e00-0000-ecbc-c3e85d140000 pid=5213 /usr/bin/bash guuid=5a4755e7-1e00-0000-ecbc-c3e85c140000 pid=5212->guuid=1b1a63e7-1e00-0000-ecbc-c3e85d140000 pid=5213 clone guuid=1a4037e8-1e00-0000-ecbc-c3e861140000 pid=5217 /dev/shm/.exectest.5167 guuid=82bc28e8-1e00-0000-ecbc-c3e860140000 pid=5216->guuid=1a4037e8-1e00-0000-ecbc-c3e861140000 pid=5217 execve guuid=317306e9-1e00-0000-ecbc-c3e863140000 pid=5219->859a4cbe-44a6-5949-a757-ee7cf89fbd69 send: 141B guuid=5c9729f2-1e00-0000-ecbc-c3e867140000 pid=5223 /dev/shm/.d zombie guuid=47ff11ed-1e00-0000-ecbc-c3e865140000 pid=5221->guuid=5c9729f2-1e00-0000-ecbc-c3e867140000 pid=5223 clone guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224 /dev/shm/.d delete-file net send-data write-file zombie guuid=5c9729f2-1e00-0000-ecbc-c3e867140000 pid=5223->guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224 clone guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->ffee5cfb-bb94-52c2-8935-ae3a87e774db send: 15B guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->54d92a3b-1447-55af-b534-047898c60c8d send: 80B 0a8043c9-917f-591f-8444-89639bba3210 91.239.211.89:8000 guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->0a8043c9-917f-591f-8444-89639bba3210 send: 325B guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5225 /dev/shm/.d zombie guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5225 clone guuid=fcce4915-1f00-0000-ecbc-c3e86a140000 pid=5226 /usr/bin/dash guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->guuid=fcce4915-1f00-0000-ecbc-c3e86a140000 pid=5226 execve guuid=f5827716-1f00-0000-ecbc-c3e86c140000 pid=5228 /usr/bin/dash guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->guuid=f5827716-1f00-0000-ecbc-c3e86c140000 pid=5228 execve guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5230 /dev/shm/.d guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5224->guuid=a0b73ff2-1e00-0000-ecbc-c3e868140000 pid=5230 clone guuid=6261d515-1f00-0000-ecbc-c3e86b140000 pid=5227 /usr/bin/dash guuid=fcce4915-1f00-0000-ecbc-c3e86a140000 pid=5226->guuid=6261d515-1f00-0000-ecbc-c3e86b140000 pid=5227 clone guuid=76414e19-1f00-0000-ecbc-c3e86d140000 pid=5229 /usr/bin/dash guuid=f5827716-1f00-0000-ecbc-c3e86c140000 pid=5228->guuid=76414e19-1f00-0000-ecbc-c3e86d140000 pid=5229 clone guuid=f31d0469-1f00-0000-ecbc-c3e872140000 pid=5234 /root/.exectest.5167 guuid=4c7cda68-1f00-0000-ecbc-c3e871140000 pid=5233->guuid=f31d0469-1f00-0000-ecbc-c3e872140000 pid=5234 execve guuid=3a5f0a6a-1f00-0000-ecbc-c3e874140000 pid=5236->859a4cbe-44a6-5949-a757-ee7cf89fbd69 send: 141B guuid=4020fd73-1f00-0000-ecbc-c3e878140000 pid=5240 /root/.d zombie guuid=412b296f-1f00-0000-ecbc-c3e876140000 pid=5238->guuid=4020fd73-1f00-0000-ecbc-c3e878140000 pid=5240 clone guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241 /root/.d delete-file net send-data write-file zombie guuid=4020fd73-1f00-0000-ecbc-c3e878140000 pid=5240->guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241 clone guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->ffee5cfb-bb94-52c2-8935-ae3a87e774db send: 15B guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->54d92a3b-1447-55af-b534-047898c60c8d send: 80B guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->0a8043c9-917f-591f-8444-89639bba3210 send: 325B guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5242 /root/.d zombie guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5242 clone guuid=e1a90d95-1f00-0000-ecbc-c3e87b140000 pid=5243 /usr/bin/dash guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->guuid=e1a90d95-1f00-0000-ecbc-c3e87b140000 pid=5243 execve guuid=f81e4696-1f00-0000-ecbc-c3e87d140000 pid=5245 /usr/bin/dash guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->guuid=f81e4696-1f00-0000-ecbc-c3e87d140000 pid=5245 execve guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5247 /root/.d guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5241->guuid=3a2e0f74-1f00-0000-ecbc-c3e879140000 pid=5247 clone guuid=93a1d095-1f00-0000-ecbc-c3e87c140000 pid=5244 /usr/bin/dash guuid=e1a90d95-1f00-0000-ecbc-c3e87b140000 pid=5243->guuid=93a1d095-1f00-0000-ecbc-c3e87c140000 pid=5244 clone guuid=873bc396-1f00-0000-ecbc-c3e87e140000 pid=5246 /usr/bin/dash guuid=f81e4696-1f00-0000-ecbc-c3e87d140000 pid=5245->guuid=873bc396-1f00-0000-ecbc-c3e87e140000 pid=5246 clone guuid=9f200fe8-1f00-0000-ecbc-c3e883140000 pid=5251 /.exectest.5167 guuid=8f49f5e7-1f00-0000-ecbc-c3e882140000 pid=5250->guuid=9f200fe8-1f00-0000-ecbc-c3e883140000 pid=5251 execve guuid=443ddfe8-1f00-0000-ecbc-c3e885140000 pid=5253->859a4cbe-44a6-5949-a757-ee7cf89fbd69 send: 141B guuid=02f10ff2-1f00-0000-ecbc-c3e889140000 pid=5257 /.d zombie guuid=b8eff3ee-1f00-0000-ecbc-c3e887140000 pid=5255->guuid=02f10ff2-1f00-0000-ecbc-c3e889140000 pid=5257 clone guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258 /.d delete-file net send-data write-file zombie guuid=02f10ff2-1f00-0000-ecbc-c3e889140000 pid=5257->guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258 clone guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->ffee5cfb-bb94-52c2-8935-ae3a87e774db send: 15B guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->54d92a3b-1447-55af-b534-047898c60c8d send: 80B guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->0a8043c9-917f-591f-8444-89639bba3210 send: 350B guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5265 /.d guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5265 clone guuid=c2ee071c-2000-0000-ecbc-c3e892140000 pid=5266 /usr/bin/dash guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->guuid=c2ee071c-2000-0000-ecbc-c3e892140000 pid=5266 execve guuid=2739a91c-2000-0000-ecbc-c3e894140000 pid=5268 /usr/bin/dash guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->guuid=2739a91c-2000-0000-ecbc-c3e894140000 pid=5268 execve guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5270 /.d guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5258->guuid=a8da1ef2-1f00-0000-ecbc-c3e88a140000 pid=5270 clone guuid=6f166f1c-2000-0000-ecbc-c3e893140000 pid=5267 /usr/bin/dash guuid=c2ee071c-2000-0000-ecbc-c3e892140000 pid=5266->guuid=6f166f1c-2000-0000-ecbc-c3e893140000 pid=5267 clone guuid=7c7ae31c-2000-0000-ecbc-c3e895140000 pid=5269 /usr/bin/dash guuid=2739a91c-2000-0000-ecbc-c3e894140000 pid=5268->guuid=7c7ae31c-2000-0000-ecbc-c3e895140000 pid=5269 clone
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery execution linux persistence privilege_escalation upx
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
Writes file to shm directory
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads system network configuration
UPX packed file
Creates/modifies Cron job
Enumerates active TCP sockets
Enumerates running processes
Modifies systemd
Reads MAC address of network interface
File and Directory Permissions Modification
Deletes itself
Executes dropped EXE
Modifies Watchdog functionality
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 7e94637b5fee7aa4fae48b6025d4ac02a02bcd0dd077c15fa3445a0a26f3c511

(this sample)

  
Delivery method
Distributed via web download

Comments