MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 7f89d99237f2b6601d8edb53307aed1edf5df1f72522ccd57e1e975f67a716ec. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Tsunami


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 7f89d99237f2b6601d8edb53307aed1edf5df1f72522ccd57e1e975f67a716ec
SHA3-384 hash: 94e665ffd2a7ca4de96577f2ba8f967a2be0700f521d6622bddc5c2d484d03192be3f5d922505c4aaaa3f5309e18c60b
SHA1 hash: d713b47365b934b142e46946e5c674b52dfc6764
MD5 hash: ba8e1ad9207754839af7f33715a16fcd
humanhash: pennsylvania-ohio-nevada-montana
File name:3sh
Download: download sample
Signature Tsunami
File size:777 bytes
First seen:2026-01-26 01:24:36 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 12:3J3lJK1xks/4ambzFt5KPaR5XxwEUugcRwXD:3J3lJ9jZ8E1Y
TLSH T179011AD43DBA70A92640CC45B5A140886009E2CC2AE65F6AF32D1EB0948D718F7753D9
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://37.120.167.228/.s/pty3a7682d1edc81925c3d7d2738db2283c742144d8321cfaf1888cdb66c1cd6ae83 Tsunamielf geofenced Tsunami ua-wget USA x86
http://37.120.167.228/.s/pty10aebc7d622eaef343c462ac1f4442191798c3f59563f222fa8cf386d15fe44225 Tsunamiarm elf geofenced mirai Tsunami ua-wget USA
http://37.120.167.228/.s/pty47d22fabcc98916294775e10101526492c105b583ccc9cf3e2edad9187dab4f14 Tsunamielf geofenced Tsunami ua-wget USA x86
http://37.120.167.228/.s/pty1184dba33e23297345d0c88fea4c0931a692a143c6d6cbbaae5ace19e08f83833 Tsunamielf geofenced mips Tsunami ua-wget USA
http://37.120.167.228/.s/pty27651345acd772a4048ed69490bdd02d7dab39d0fb02e9a1aec565a5f1503969c Tsunamielf geofenced mips Tsunami ua-wget USA
http://37.120.167.228/.s/pty5cd22d7a8e1ff2749ada4d254975a374dd40b27ad1203ecef4b777b32e0909477 Tsunamiarm elf geofenced Tsunami ua-wget USA

Intelligence


File Origin
# of uploads :
1
# of downloads :
82
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
mirai
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=ad3655cc-1600-0000-59d4-a656460f0000 pid=3910 /usr/bin/sudo guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918 /tmp/sample.bin guuid=ad3655cc-1600-0000-59d4-a656460f0000 pid=3910->guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918 execve guuid=b7f182ce-1600-0000-59d4-a6564f0f0000 pid=3919 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=b7f182ce-1600-0000-59d4-a6564f0f0000 pid=3919 execve guuid=f0ca66d6-1600-0000-59d4-a6566f0f0000 pid=3951 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=f0ca66d6-1600-0000-59d4-a6566f0f0000 pid=3951 execve guuid=615fa0d6-1600-0000-59d4-a656730f0000 pid=3955 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=615fa0d6-1600-0000-59d4-a656730f0000 pid=3955 execve guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956 /tmp/pty3 mprotect-exec guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956 execve guuid=297fdcd6-1600-0000-59d4-a656750f0000 pid=3957 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=297fdcd6-1600-0000-59d4-a656750f0000 pid=3957 execve guuid=8710a9df-1600-0000-59d4-a656a70f0000 pid=4007 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=8710a9df-1600-0000-59d4-a656a70f0000 pid=4007 execve guuid=f9123ee0-1600-0000-59d4-a656ac0f0000 pid=4012 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=f9123ee0-1600-0000-59d4-a656ac0f0000 pid=4012 execve guuid=a2cb82e0-1600-0000-59d4-a656ad0f0000 pid=4013 /usr/bin/dash guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=a2cb82e0-1600-0000-59d4-a656ad0f0000 pid=4013 clone guuid=fe404ee1-1600-0000-59d4-a656b50f0000 pid=4021 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=fe404ee1-1600-0000-59d4-a656b50f0000 pid=4021 execve guuid=52d001e7-1600-0000-59d4-a656e80f0000 pid=4072 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=52d001e7-1600-0000-59d4-a656e80f0000 pid=4072 execve guuid=5bdf39e7-1600-0000-59d4-a656eb0f0000 pid=4075 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=5bdf39e7-1600-0000-59d4-a656eb0f0000 pid=4075 execve guuid=a88d70e7-1600-0000-59d4-a656ee0f0000 pid=4078 /home/sandbox/pty3 mprotect-exec guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=a88d70e7-1600-0000-59d4-a656ee0f0000 pid=4078 execve guuid=fd5b7eea-1600-0000-59d4-a65614100000 pid=4116 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=fd5b7eea-1600-0000-59d4-a65614100000 pid=4116 execve guuid=d1d1d8ef-1600-0000-59d4-a6562b100000 pid=4139 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=d1d1d8ef-1600-0000-59d4-a6562b100000 pid=4139 execve guuid=95c313f0-1600-0000-59d4-a6562c100000 pid=4140 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=95c313f0-1600-0000-59d4-a6562c100000 pid=4140 execve guuid=d93e4bf0-1600-0000-59d4-a65630100000 pid=4144 /home/sandbox/pty4 guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=d93e4bf0-1600-0000-59d4-a65630100000 pid=4144 execve guuid=942441f4-1600-0000-59d4-a65640100000 pid=4160 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=942441f4-1600-0000-59d4-a65640100000 pid=4160 execve guuid=14b961fd-1600-0000-59d4-a65662100000 pid=4194 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=14b961fd-1600-0000-59d4-a65662100000 pid=4194 execve guuid=8f4dd0fe-1600-0000-59d4-a65667100000 pid=4199 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=8f4dd0fe-1600-0000-59d4-a65667100000 pid=4199 execve guuid=7ba924ff-1600-0000-59d4-a65669100000 pid=4201 /usr/bin/dash guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=7ba924ff-1600-0000-59d4-a65669100000 pid=4201 clone guuid=eafa28ff-1600-0000-59d4-a6566a100000 pid=4202 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=eafa28ff-1600-0000-59d4-a6566a100000 pid=4202 execve guuid=b8abba04-1700-0000-59d4-a6567b100000 pid=4219 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=b8abba04-1700-0000-59d4-a6567b100000 pid=4219 execve guuid=d90f0a05-1700-0000-59d4-a6567d100000 pid=4221 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=d90f0a05-1700-0000-59d4-a6567d100000 pid=4221 execve guuid=65455305-1700-0000-59d4-a6567f100000 pid=4223 /usr/bin/dash guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=65455305-1700-0000-59d4-a6567f100000 pid=4223 clone guuid=c6b15605-1700-0000-59d4-a65680100000 pid=4224 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=c6b15605-1700-0000-59d4-a65680100000 pid=4224 execve guuid=892afd0d-1700-0000-59d4-a6569d100000 pid=4253 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=892afd0d-1700-0000-59d4-a6569d100000 pid=4253 execve guuid=80394e0e-1700-0000-59d4-a6569f100000 pid=4255 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=80394e0e-1700-0000-59d4-a6569f100000 pid=4255 execve guuid=0bc29c0e-1700-0000-59d4-a656a1100000 pid=4257 /usr/bin/dash guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=0bc29c0e-1700-0000-59d4-a656a1100000 pid=4257 clone guuid=ecdca10e-1700-0000-59d4-a656a2100000 pid=4258 /usr/bin/curl net send-data write-file guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=ecdca10e-1700-0000-59d4-a656a2100000 pid=4258 execve guuid=02b2a714-1700-0000-59d4-a656b4100000 pid=4276 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=02b2a714-1700-0000-59d4-a656b4100000 pid=4276 execve guuid=48d1ed14-1700-0000-59d4-a656b8100000 pid=4280 /usr/bin/chmod guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=48d1ed14-1700-0000-59d4-a656b8100000 pid=4280 execve guuid=a4e03215-1700-0000-59d4-a656b9100000 pid=4281 /usr/bin/dash zombie guuid=d5eb52ce-1600-0000-59d4-a6564e0f0000 pid=3918->guuid=a4e03215-1700-0000-59d4-a656b9100000 pid=4281 clone 5fd23025-ff01-5a85-92ed-f5105fe81372 37.120.167.228:80 guuid=b7f182ce-1600-0000-59d4-a6564f0f0000 pid=3919->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B guuid=092d07d7-1600-0000-59d4-a656760f0000 pid=3958 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=092d07d7-1600-0000-59d4-a656760f0000 pid=3958 execve guuid=f98e66d9-1600-0000-59d4-a656820f0000 pid=3970 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=f98e66d9-1600-0000-59d4-a656820f0000 pid=3970 execve guuid=7c7d69db-1600-0000-59d4-a656880f0000 pid=3976 /tmp/pty3 guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=7c7d69db-1600-0000-59d4-a656880f0000 pid=3976 clone guuid=28766ddb-1600-0000-59d4-a656890f0000 pid=3977 /tmp/pty3 guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=28766ddb-1600-0000-59d4-a656890f0000 pid=3977 clone guuid=a21770db-1600-0000-59d4-a6568a0f0000 pid=3978 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=a21770db-1600-0000-59d4-a6568a0f0000 pid=3978 execve guuid=646cb2dc-1600-0000-59d4-a656910f0000 pid=3985 /usr/bin/dash write-config guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=646cb2dc-1600-0000-59d4-a656910f0000 pid=3985 execve guuid=41c3eedc-1600-0000-59d4-a656920f0000 pid=3986 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=41c3eedc-1600-0000-59d4-a656920f0000 pid=3986 execve guuid=a4825edd-1600-0000-59d4-a656960f0000 pid=3990 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=a4825edd-1600-0000-59d4-a656960f0000 pid=3990 execve guuid=67beeadd-1600-0000-59d4-a6569a0f0000 pid=3994 /usr/bin/dash guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=67beeadd-1600-0000-59d4-a6569a0f0000 pid=3994 execve guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998 /tmp/pty3 zombie guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998 clone guuid=acefccde-1600-0000-59d4-a6569f0f0000 pid=3999 /tmp/pty3 dns net send-data zombie guuid=8e2ed9d6-1600-0000-59d4-a656740f0000 pid=3956->guuid=acefccde-1600-0000-59d4-a6569f0f0000 pid=3999 clone guuid=297fdcd6-1600-0000-59d4-a656750f0000 pid=3957->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 86B guuid=c785e2d7-1600-0000-59d4-a6567c0f0000 pid=3964 /usr/sbin/killall5 guuid=092d07d7-1600-0000-59d4-a656760f0000 pid=3958->guuid=c785e2d7-1600-0000-59d4-a6567c0f0000 pid=3964 execve guuid=bd698fd9-1600-0000-59d4-a656840f0000 pid=3972 /usr/sbin/killall5 guuid=f98e66d9-1600-0000-59d4-a656820f0000 pid=3970->guuid=bd698fd9-1600-0000-59d4-a656840f0000 pid=3972 execve guuid=8411efdb-1600-0000-59d4-a6568b0f0000 pid=3979 /usr/bin/cat guuid=a21770db-1600-0000-59d4-a6568a0f0000 pid=3978->guuid=8411efdb-1600-0000-59d4-a6568b0f0000 pid=3979 execve guuid=4497fadb-1600-0000-59d4-a6568d0f0000 pid=3981 /usr/bin/grep guuid=a21770db-1600-0000-59d4-a6568a0f0000 pid=3978->guuid=4497fadb-1600-0000-59d4-a6568d0f0000 pid=3981 execve guuid=bbd513dd-1600-0000-59d4-a656940f0000 pid=3988 /usr/bin/cat guuid=41c3eedc-1600-0000-59d4-a656920f0000 pid=3986->guuid=bbd513dd-1600-0000-59d4-a656940f0000 pid=3988 execve guuid=e7bc8bdd-1600-0000-59d4-a656980f0000 pid=3992 /usr/bin/rm delete-file guuid=a4825edd-1600-0000-59d4-a656960f0000 pid=3990->guuid=e7bc8bdd-1600-0000-59d4-a656980f0000 pid=3992 execve guuid=c10915de-1600-0000-59d4-a6569b0f0000 pid=3995 /usr/bin/touch guuid=67beeadd-1600-0000-59d4-a6569a0f0000 pid=3994->guuid=c10915de-1600-0000-59d4-a6569b0f0000 pid=3995 execve guuid=2d07cede-1600-0000-59d4-a656a00f0000 pid=4000 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=2d07cede-1600-0000-59d4-a656a00f0000 pid=4000 execve guuid=6e45b5e0-1600-0000-59d4-a656b00f0000 pid=4016 /tmp/pty3 guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=6e45b5e0-1600-0000-59d4-a656b00f0000 pid=4016 clone guuid=1165fce0-1600-0000-59d4-a656b20f0000 pid=4018 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=1165fce0-1600-0000-59d4-a656b20f0000 pid=4018 execve guuid=0b659de1-1600-0000-59d4-a656b90f0000 pid=4025 /usr/bin/dash write-config guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=0b659de1-1600-0000-59d4-a656b90f0000 pid=4025 execve guuid=0726c9e1-1600-0000-59d4-a656ba0f0000 pid=4026 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=0726c9e1-1600-0000-59d4-a656ba0f0000 pid=4026 execve guuid=594b4ae2-1600-0000-59d4-a656bf0f0000 pid=4031 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=594b4ae2-1600-0000-59d4-a656bf0f0000 pid=4031 execve guuid=4ee2aee2-1600-0000-59d4-a656c30f0000 pid=4035 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=4ee2aee2-1600-0000-59d4-a656c30f0000 pid=4035 execve guuid=6d6f08e3-1600-0000-59d4-a656c60f0000 pid=4038 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=6d6f08e3-1600-0000-59d4-a656c60f0000 pid=4038 execve guuid=1e658ce3-1600-0000-59d4-a656cb0f0000 pid=4043 /tmp/pty3 guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=1e658ce3-1600-0000-59d4-a656cb0f0000 pid=4043 clone guuid=07a08ee3-1600-0000-59d4-a656cc0f0000 pid=4044 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=07a08ee3-1600-0000-59d4-a656cc0f0000 pid=4044 execve guuid=4ef50ae4-1600-0000-59d4-a656d00f0000 pid=4048 /usr/bin/dash write-config guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=4ef50ae4-1600-0000-59d4-a656d00f0000 pid=4048 execve guuid=d45239e4-1600-0000-59d4-a656d10f0000 pid=4049 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=d45239e4-1600-0000-59d4-a656d10f0000 pid=4049 execve guuid=6b32dee4-1600-0000-59d4-a656d30f0000 pid=4051 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=6b32dee4-1600-0000-59d4-a656d30f0000 pid=4051 execve guuid=84b76fe5-1600-0000-59d4-a656d90f0000 pid=4057 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=84b76fe5-1600-0000-59d4-a656d90f0000 pid=4057 execve guuid=37a5d8e5-1600-0000-59d4-a656de0f0000 pid=4062 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=37a5d8e5-1600-0000-59d4-a656de0f0000 pid=4062 execve guuid=fe1678e6-1600-0000-59d4-a656e20f0000 pid=4066 /tmp/pty3 guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=fe1678e6-1600-0000-59d4-a656e20f0000 pid=4066 clone guuid=9f797ee6-1600-0000-59d4-a656e30f0000 pid=4067 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=9f797ee6-1600-0000-59d4-a656e30f0000 pid=4067 execve guuid=182f1fe7-1600-0000-59d4-a656e90f0000 pid=4073 /usr/bin/dash write-config guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=182f1fe7-1600-0000-59d4-a656e90f0000 pid=4073 execve guuid=07684de7-1600-0000-59d4-a656ec0f0000 pid=4076 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=07684de7-1600-0000-59d4-a656ec0f0000 pid=4076 execve guuid=196aaee7-1600-0000-59d4-a656f20f0000 pid=4082 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=196aaee7-1600-0000-59d4-a656f20f0000 pid=4082 execve guuid=cd6e10e8-1600-0000-59d4-a656f60f0000 pid=4086 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=cd6e10e8-1600-0000-59d4-a656f60f0000 pid=4086 execve guuid=6c766ae8-1600-0000-59d4-a656fb0f0000 pid=4091 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=6c766ae8-1600-0000-59d4-a656fb0f0000 pid=4091 execve guuid=e693efe8-1600-0000-59d4-a65600100000 pid=4096 /tmp/pty3 guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=e693efe8-1600-0000-59d4-a65600100000 pid=4096 clone guuid=9651f4e8-1600-0000-59d4-a65601100000 pid=4097 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=9651f4e8-1600-0000-59d4-a65601100000 pid=4097 execve guuid=47abaee9-1600-0000-59d4-a6560b100000 pid=4107 /usr/bin/dash write-config guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=47abaee9-1600-0000-59d4-a6560b100000 pid=4107 execve guuid=7a73d6e9-1600-0000-59d4-a6560c100000 pid=4108 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=7a73d6e9-1600-0000-59d4-a6560c100000 pid=4108 execve guuid=03c72fea-1600-0000-59d4-a65611100000 pid=4113 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=03c72fea-1600-0000-59d4-a65611100000 pid=4113 execve guuid=53b091ea-1600-0000-59d4-a65616100000 pid=4118 /usr/bin/dash guuid=587ec0de-1600-0000-59d4-a6569e0f0000 pid=3998->guuid=53b091ea-1600-0000-59d4-a65616100000 pid=4118 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=acefccde-1600-0000-59d4-a6569f0f0000 pid=3999->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 37B 80464654-9126-53d4-81fd-4f2194cb67fa irc.shadow-mods.net:8080 guuid=acefccde-1600-0000-59d4-a6569f0f0000 pid=3999->80464654-9126-53d4-81fd-4f2194cb67fa send: 172B guuid=4d8182df-1600-0000-59d4-a656a40f0000 pid=4004 /usr/bin/dash guuid=acefccde-1600-0000-59d4-a6569f0f0000 pid=3999->guuid=4d8182df-1600-0000-59d4-a656a40f0000 pid=4004 execve guuid=ea0149df-1600-0000-59d4-a656a20f0000 pid=4002 /usr/bin/cp write-file guuid=2d07cede-1600-0000-59d4-a656a00f0000 pid=4000->guuid=ea0149df-1600-0000-59d4-a656a20f0000 pid=4002 execve guuid=9756aedf-1600-0000-59d4-a656a80f0000 pid=4008 /usr/bin/uname guuid=4d8182df-1600-0000-59d4-a656a40f0000 pid=4004->guuid=9756aedf-1600-0000-59d4-a656a80f0000 pid=4008 execve guuid=137235e1-1600-0000-59d4-a656b30f0000 pid=4019 /usr/bin/cat guuid=1165fce0-1600-0000-59d4-a656b20f0000 pid=4018->guuid=137235e1-1600-0000-59d4-a656b30f0000 pid=4019 execve guuid=c19439e1-1600-0000-59d4-a656b40f0000 pid=4020 /usr/bin/grep write-config guuid=1165fce0-1600-0000-59d4-a656b20f0000 pid=4018->guuid=c19439e1-1600-0000-59d4-a656b40f0000 pid=4020 execve guuid=fe404ee1-1600-0000-59d4-a656b50f0000 pid=4021->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B guuid=38040ce2-1600-0000-59d4-a656be0f0000 pid=4030 /usr/bin/cat guuid=0726c9e1-1600-0000-59d4-a656ba0f0000 pid=4026->guuid=38040ce2-1600-0000-59d4-a656be0f0000 pid=4030 execve guuid=62d177e2-1600-0000-59d4-a656c10f0000 pid=4033 /usr/bin/rm delete-file guuid=594b4ae2-1600-0000-59d4-a656bf0f0000 pid=4031->guuid=62d177e2-1600-0000-59d4-a656c10f0000 pid=4033 execve guuid=a357d1e2-1600-0000-59d4-a656c40f0000 pid=4036 /usr/bin/touch guuid=4ee2aee2-1600-0000-59d4-a656c30f0000 pid=4035->guuid=a357d1e2-1600-0000-59d4-a656c40f0000 pid=4036 execve guuid=715f2fe3-1600-0000-59d4-a656c80f0000 pid=4040 /usr/bin/cp guuid=6d6f08e3-1600-0000-59d4-a656c60f0000 pid=4038->guuid=715f2fe3-1600-0000-59d4-a656c80f0000 pid=4040 execve guuid=4656b0e3-1600-0000-59d4-a656cd0f0000 pid=4045 /usr/bin/cat guuid=07a08ee3-1600-0000-59d4-a656cc0f0000 pid=4044->guuid=4656b0e3-1600-0000-59d4-a656cd0f0000 pid=4045 execve guuid=23fbb3e3-1600-0000-59d4-a656ce0f0000 pid=4046 /usr/bin/grep write-config guuid=07a08ee3-1600-0000-59d4-a656cc0f0000 pid=4044->guuid=23fbb3e3-1600-0000-59d4-a656ce0f0000 pid=4046 execve guuid=71a55fe4-1600-0000-59d4-a656d20f0000 pid=4050 /usr/bin/cat guuid=d45239e4-1600-0000-59d4-a656d10f0000 pid=4049->guuid=71a55fe4-1600-0000-59d4-a656d20f0000 pid=4050 execve guuid=171c03e5-1600-0000-59d4-a656d50f0000 pid=4053 /usr/bin/rm delete-file guuid=6b32dee4-1600-0000-59d4-a656d30f0000 pid=4051->guuid=171c03e5-1600-0000-59d4-a656d50f0000 pid=4053 execve guuid=a4e398e5-1600-0000-59d4-a656da0f0000 pid=4058 /usr/bin/touch guuid=84b76fe5-1600-0000-59d4-a656d90f0000 pid=4057->guuid=a4e398e5-1600-0000-59d4-a656da0f0000 pid=4058 execve guuid=5e6702e6-1600-0000-59d4-a656df0f0000 pid=4063 /usr/bin/cp write-file guuid=37a5d8e5-1600-0000-59d4-a656de0f0000 pid=4062->guuid=5e6702e6-1600-0000-59d4-a656df0f0000 pid=4063 execve guuid=de45a4e6-1600-0000-59d4-a656e40f0000 pid=4068 /usr/bin/cat guuid=9f797ee6-1600-0000-59d4-a656e30f0000 pid=4067->guuid=de45a4e6-1600-0000-59d4-a656e40f0000 pid=4068 execve guuid=151da9e6-1600-0000-59d4-a656e60f0000 pid=4070 /usr/bin/grep write-config guuid=9f797ee6-1600-0000-59d4-a656e30f0000 pid=4067->guuid=151da9e6-1600-0000-59d4-a656e60f0000 pid=4070 execve guuid=f77577e7-1600-0000-59d4-a656ef0f0000 pid=4079 /usr/bin/cat guuid=07684de7-1600-0000-59d4-a656ec0f0000 pid=4076->guuid=f77577e7-1600-0000-59d4-a656ef0f0000 pid=4079 execve guuid=059490e7-1600-0000-59d4-a656f00f0000 pid=4080 /usr/bin/dash guuid=a88d70e7-1600-0000-59d4-a656ee0f0000 pid=4078->guuid=059490e7-1600-0000-59d4-a656f00f0000 pid=4080 execve guuid=619e5be9-1600-0000-59d4-a65606100000 pid=4102 /usr/bin/dash guuid=a88d70e7-1600-0000-59d4-a656ee0f0000 pid=4078->guuid=619e5be9-1600-0000-59d4-a65606100000 pid=4102 execve guuid=2177bbe7-1600-0000-59d4-a656f30f0000 pid=4083 /usr/sbin/killall5 guuid=059490e7-1600-0000-59d4-a656f00f0000 pid=4080->guuid=2177bbe7-1600-0000-59d4-a656f30f0000 pid=4083 execve guuid=fb92cfe7-1600-0000-59d4-a656f40f0000 pid=4084 /usr/bin/rm delete-file guuid=196aaee7-1600-0000-59d4-a656f20f0000 pid=4082->guuid=fb92cfe7-1600-0000-59d4-a656f40f0000 pid=4084 execve guuid=c90b34e8-1600-0000-59d4-a656f70f0000 pid=4087 /usr/bin/touch guuid=cd6e10e8-1600-0000-59d4-a656f60f0000 pid=4086->guuid=c90b34e8-1600-0000-59d4-a656f70f0000 pid=4087 execve guuid=c7e78ce8-1600-0000-59d4-a656fc0f0000 pid=4092 /usr/bin/cp write-file guuid=6c766ae8-1600-0000-59d4-a656fb0f0000 pid=4091->guuid=c7e78ce8-1600-0000-59d4-a656fc0f0000 pid=4092 execve guuid=182024e9-1600-0000-59d4-a65603100000 pid=4099 /usr/bin/cat guuid=9651f4e8-1600-0000-59d4-a65601100000 pid=4097->guuid=182024e9-1600-0000-59d4-a65603100000 pid=4099 execve guuid=07f927e9-1600-0000-59d4-a65604100000 pid=4100 /usr/bin/grep write-config guuid=9651f4e8-1600-0000-59d4-a65601100000 pid=4097->guuid=07f927e9-1600-0000-59d4-a65604100000 pid=4100 execve guuid=a72180e9-1600-0000-59d4-a65607100000 pid=4103 /usr/sbin/killall5 guuid=619e5be9-1600-0000-59d4-a65606100000 pid=4102->guuid=a72180e9-1600-0000-59d4-a65607100000 pid=4103 execve guuid=166bf8e9-1600-0000-59d4-a6560f100000 pid=4111 /usr/bin/cat guuid=7a73d6e9-1600-0000-59d4-a6560c100000 pid=4108->guuid=166bf8e9-1600-0000-59d4-a6560f100000 pid=4111 execve guuid=547e54ea-1600-0000-59d4-a65613100000 pid=4115 /usr/bin/rm delete-file guuid=03c72fea-1600-0000-59d4-a65611100000 pid=4113->guuid=547e54ea-1600-0000-59d4-a65613100000 pid=4115 execve guuid=fd5b7eea-1600-0000-59d4-a65614100000 pid=4116->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B guuid=9ecab2ea-1600-0000-59d4-a65617100000 pid=4119 /usr/bin/touch guuid=53b091ea-1600-0000-59d4-a65616100000 pid=4118->guuid=9ecab2ea-1600-0000-59d4-a65617100000 pid=4119 execve guuid=6704fbf0-1600-0000-59d4-a65633100000 pid=4147 /usr/bin/dash guuid=d93e4bf0-1600-0000-59d4-a65630100000 pid=4144->guuid=6704fbf0-1600-0000-59d4-a65633100000 pid=4147 execve guuid=792c97f2-1600-0000-59d4-a6563b100000 pid=4155 /usr/bin/dash guuid=d93e4bf0-1600-0000-59d4-a65630100000 pid=4144->guuid=792c97f2-1600-0000-59d4-a6563b100000 pid=4155 execve guuid=da6d24f1-1600-0000-59d4-a65635100000 pid=4149 /usr/sbin/killall5 guuid=6704fbf0-1600-0000-59d4-a65633100000 pid=4147->guuid=da6d24f1-1600-0000-59d4-a65635100000 pid=4149 execve guuid=3897cdf2-1600-0000-59d4-a6563c100000 pid=4156 /usr/sbin/killall5 guuid=792c97f2-1600-0000-59d4-a6563b100000 pid=4155->guuid=3897cdf2-1600-0000-59d4-a6563c100000 pid=4156 execve guuid=942441f4-1600-0000-59d4-a65640100000 pid=4160->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 86B guuid=eafa28ff-1600-0000-59d4-a6566a100000 pid=4202->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B guuid=c6b15605-1700-0000-59d4-a65680100000 pid=4224->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B guuid=ecdca10e-1700-0000-59d4-a656a2100000 pid=4258->5fd23025-ff01-5a85-92ed-f5105fe81372 send: 85B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-26 01:29:34 UTC
File Type:
Text (Shell)
AV detection:
6 of 36 (16.67%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

Tsunami

sh 7f89d99237f2b6601d8edb53307aed1edf5df1f72522ccd57e1e975f67a716ec

(this sample)

  
Delivery method
Distributed via web download

Comments