MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 81f8a4d33b2d8fa5614e66e9e30d13d6d685bb65e10819ebb18da74164d2a446. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: 81f8a4d33b2d8fa5614e66e9e30d13d6d685bb65e10819ebb18da74164d2a446
SHA3-384 hash: 9c4990a8b11794f9b7798017da2f4e250ea38b76b6eb13158743b3dfac63eaff8d4c2b59d363c4001f046adc8df300c8
SHA1 hash: 3dd3bdd64b1de89d15a9d847dfdad6b742dafb1e
MD5 hash: eac473b2d9dec215b8462cfa92a9d894
humanhash: delta-minnesota-music-missouri
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-06-16 21:36:12 UTC
Last seen:2026-06-16 23:35:22 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTG/sp+4RxaPMbAulNXYq4HvXDG+NjVsNXYrkJ:VGkp+4HXbPiq4HvXDGmKi2
TLSH T158D02E2262730A3094B29824E0CAAC80B2080B7F0E0AA2AE788B60313F40304F2D26A4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
69
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=46a8db0a-1800-0000-9a1e-9f7f9d0c0000 pid=3229 /usr/bin/sudo guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235 /tmp/sample.bin guuid=46a8db0a-1800-0000-9a1e-9f7f9d0c0000 pid=3229->guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235 execve guuid=1ebc1a0f-1800-0000-9a1e-9f7fa50c0000 pid=3237 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=1ebc1a0f-1800-0000-9a1e-9f7fa50c0000 pid=3237 execve guuid=b03f910f-1800-0000-9a1e-9f7fa70c0000 pid=3239 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=b03f910f-1800-0000-9a1e-9f7fa70c0000 pid=3239 execve guuid=4177d838-1800-0000-9a1e-9f7ff30c0000 pid=3315 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=4177d838-1800-0000-9a1e-9f7ff30c0000 pid=3315 execve guuid=27fb1039-1800-0000-9a1e-9f7ff40c0000 pid=3316 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=27fb1039-1800-0000-9a1e-9f7ff40c0000 pid=3316 clone guuid=3333ae3a-1800-0000-9a1e-9f7ff90c0000 pid=3321 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3333ae3a-1800-0000-9a1e-9f7ff90c0000 pid=3321 execve guuid=54570f3b-1800-0000-9a1e-9f7ffb0c0000 pid=3323 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=54570f3b-1800-0000-9a1e-9f7ffb0c0000 pid=3323 execve guuid=b8690769-1800-0000-9a1e-9f7f520d0000 pid=3410 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=b8690769-1800-0000-9a1e-9f7f520d0000 pid=3410 execve guuid=b2958069-1800-0000-9a1e-9f7f540d0000 pid=3412 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=b2958069-1800-0000-9a1e-9f7f540d0000 pid=3412 clone guuid=6bc1bc6a-1800-0000-9a1e-9f7f590d0000 pid=3417 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=6bc1bc6a-1800-0000-9a1e-9f7f590d0000 pid=3417 execve guuid=101c146b-1800-0000-9a1e-9f7f5b0d0000 pid=3419 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=101c146b-1800-0000-9a1e-9f7f5b0d0000 pid=3419 execve guuid=16cd9691-1800-0000-9a1e-9f7fb90d0000 pid=3513 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=16cd9691-1800-0000-9a1e-9f7fb90d0000 pid=3513 execve guuid=e38dee91-1800-0000-9a1e-9f7fbb0d0000 pid=3515 /tmp/GBXN guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=e38dee91-1800-0000-9a1e-9f7fbb0d0000 pid=3515 execve guuid=7ec40f92-1800-0000-9a1e-9f7fbd0d0000 pid=3517 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=7ec40f92-1800-0000-9a1e-9f7fbd0d0000 pid=3517 execve guuid=10eb7e92-1800-0000-9a1e-9f7fbf0d0000 pid=3519 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=10eb7e92-1800-0000-9a1e-9f7fbf0d0000 pid=3519 execve guuid=4ad303bb-1800-0000-9a1e-9f7fdb0d0000 pid=3547 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=4ad303bb-1800-0000-9a1e-9f7fdb0d0000 pid=3547 execve guuid=845549bb-1800-0000-9a1e-9f7fdc0d0000 pid=3548 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=845549bb-1800-0000-9a1e-9f7fdc0d0000 pid=3548 clone guuid=fe0606bc-1800-0000-9a1e-9f7fe00d0000 pid=3552 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=fe0606bc-1800-0000-9a1e-9f7fe00d0000 pid=3552 execve guuid=ce174fbc-1800-0000-9a1e-9f7fe20d0000 pid=3554 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=ce174fbc-1800-0000-9a1e-9f7fe20d0000 pid=3554 execve guuid=2047b1f2-1800-0000-9a1e-9f7f600e0000 pid=3680 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=2047b1f2-1800-0000-9a1e-9f7f600e0000 pid=3680 execve guuid=3a9018f3-1800-0000-9a1e-9f7f610e0000 pid=3681 /tmp/BUDG guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3a9018f3-1800-0000-9a1e-9f7f610e0000 pid=3681 execve guuid=775d45f3-1800-0000-9a1e-9f7f630e0000 pid=3683 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=775d45f3-1800-0000-9a1e-9f7f630e0000 pid=3683 execve guuid=dcbac1f3-1800-0000-9a1e-9f7f640e0000 pid=3684 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=dcbac1f3-1800-0000-9a1e-9f7f640e0000 pid=3684 execve guuid=3d637a1b-1900-0000-9a1e-9f7fdf0e0000 pid=3807 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3d637a1b-1900-0000-9a1e-9f7fdf0e0000 pid=3807 execve guuid=670bb91b-1900-0000-9a1e-9f7fe10e0000 pid=3809 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=670bb91b-1900-0000-9a1e-9f7fe10e0000 pid=3809 clone guuid=8e77d91e-1900-0000-9a1e-9f7ff00e0000 pid=3824 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=8e77d91e-1900-0000-9a1e-9f7ff00e0000 pid=3824 execve guuid=8e582d1f-1900-0000-9a1e-9f7ff30e0000 pid=3827 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=8e582d1f-1900-0000-9a1e-9f7ff30e0000 pid=3827 execve guuid=b39ad945-1900-0000-9a1e-9f7f570f0000 pid=3927 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=b39ad945-1900-0000-9a1e-9f7f570f0000 pid=3927 execve guuid=3a994546-1900-0000-9a1e-9f7f590f0000 pid=3929 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3a994546-1900-0000-9a1e-9f7f590f0000 pid=3929 clone guuid=99e7a748-1900-0000-9a1e-9f7f5f0f0000 pid=3935 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=99e7a748-1900-0000-9a1e-9f7f5f0f0000 pid=3935 execve guuid=2ec7f048-1900-0000-9a1e-9f7f610f0000 pid=3937 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=2ec7f048-1900-0000-9a1e-9f7f610f0000 pid=3937 execve guuid=42c4f56f-1900-0000-9a1e-9f7f9e0f0000 pid=3998 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=42c4f56f-1900-0000-9a1e-9f7f9e0f0000 pid=3998 execve guuid=5aa59870-1900-0000-9a1e-9f7fa10f0000 pid=4001 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=5aa59870-1900-0000-9a1e-9f7fa10f0000 pid=4001 clone guuid=bc818271-1900-0000-9a1e-9f7fa50f0000 pid=4005 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=bc818271-1900-0000-9a1e-9f7fa50f0000 pid=4005 execve guuid=995ff571-1900-0000-9a1e-9f7fa80f0000 pid=4008 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=995ff571-1900-0000-9a1e-9f7fa80f0000 pid=4008 execve guuid=3e290693-1900-0000-9a1e-9f7ffc0f0000 pid=4092 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3e290693-1900-0000-9a1e-9f7ffc0f0000 pid=4092 execve guuid=9da05c93-1900-0000-9a1e-9f7ffd0f0000 pid=4093 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=9da05c93-1900-0000-9a1e-9f7ffd0f0000 pid=4093 clone guuid=329afa93-1900-0000-9a1e-9f7f02100000 pid=4098 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=329afa93-1900-0000-9a1e-9f7f02100000 pid=4098 execve guuid=17a15d94-1900-0000-9a1e-9f7f05100000 pid=4101 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=17a15d94-1900-0000-9a1e-9f7f05100000 pid=4101 execve guuid=09364dbb-1900-0000-9a1e-9f7f6d100000 pid=4205 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=09364dbb-1900-0000-9a1e-9f7f6d100000 pid=4205 execve guuid=6684a9bb-1900-0000-9a1e-9f7f6f100000 pid=4207 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=6684a9bb-1900-0000-9a1e-9f7f6f100000 pid=4207 clone guuid=9d495dbd-1900-0000-9a1e-9f7f76100000 pid=4214 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=9d495dbd-1900-0000-9a1e-9f7f76100000 pid=4214 execve guuid=ed7ab8bd-1900-0000-9a1e-9f7f77100000 pid=4215 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=ed7ab8bd-1900-0000-9a1e-9f7f77100000 pid=4215 execve guuid=ef7d83eb-1900-0000-9a1e-9f7fef100000 pid=4335 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=ef7d83eb-1900-0000-9a1e-9f7fef100000 pid=4335 execve guuid=0537fdeb-1900-0000-9a1e-9f7ff0100000 pid=4336 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=0537fdeb-1900-0000-9a1e-9f7ff0100000 pid=4336 clone guuid=aa1e00ee-1900-0000-9a1e-9f7ff9100000 pid=4345 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=aa1e00ee-1900-0000-9a1e-9f7ff9100000 pid=4345 execve guuid=77d550ee-1900-0000-9a1e-9f7ffb100000 pid=4347 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=77d550ee-1900-0000-9a1e-9f7ffb100000 pid=4347 execve guuid=ba64e514-1a00-0000-9a1e-9f7f5d110000 pid=4445 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=ba64e514-1a00-0000-9a1e-9f7f5d110000 pid=4445 execve guuid=3874ba15-1a00-0000-9a1e-9f7f61110000 pid=4449 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3874ba15-1a00-0000-9a1e-9f7f61110000 pid=4449 clone guuid=21f1cc16-1a00-0000-9a1e-9f7f65110000 pid=4453 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=21f1cc16-1a00-0000-9a1e-9f7f65110000 pid=4453 execve guuid=f50c3917-1a00-0000-9a1e-9f7f66110000 pid=4454 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=f50c3917-1a00-0000-9a1e-9f7f66110000 pid=4454 execve guuid=06ce7b3e-1a00-0000-9a1e-9f7fd5110000 pid=4565 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=06ce7b3e-1a00-0000-9a1e-9f7fd5110000 pid=4565 execve guuid=2fc5e93e-1a00-0000-9a1e-9f7fd6110000 pid=4566 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=2fc5e93e-1a00-0000-9a1e-9f7fd6110000 pid=4566 clone guuid=e8ec7940-1a00-0000-9a1e-9f7fd8110000 pid=4568 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=e8ec7940-1a00-0000-9a1e-9f7fd8110000 pid=4568 execve guuid=f162ea40-1a00-0000-9a1e-9f7fd9110000 pid=4569 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=f162ea40-1a00-0000-9a1e-9f7fd9110000 pid=4569 execve guuid=3b2e8b69-1a00-0000-9a1e-9f7f42120000 pid=4674 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3b2e8b69-1a00-0000-9a1e-9f7f42120000 pid=4674 execve guuid=0866e969-1a00-0000-9a1e-9f7f43120000 pid=4675 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=0866e969-1a00-0000-9a1e-9f7f43120000 pid=4675 clone guuid=7b2f966a-1a00-0000-9a1e-9f7f46120000 pid=4678 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=7b2f966a-1a00-0000-9a1e-9f7f46120000 pid=4678 execve guuid=6552e56a-1a00-0000-9a1e-9f7f47120000 pid=4679 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=6552e56a-1a00-0000-9a1e-9f7f47120000 pid=4679 execve guuid=3da34392-1a00-0000-9a1e-9f7f77120000 pid=4727 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=3da34392-1a00-0000-9a1e-9f7f77120000 pid=4727 execve guuid=00e7d992-1a00-0000-9a1e-9f7f78120000 pid=4728 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=00e7d992-1a00-0000-9a1e-9f7f78120000 pid=4728 clone guuid=4ff21e94-1a00-0000-9a1e-9f7f7a120000 pid=4730 /usr/bin/rm guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=4ff21e94-1a00-0000-9a1e-9f7f7a120000 pid=4730 execve guuid=84df7e94-1a00-0000-9a1e-9f7f7b120000 pid=4731 /usr/bin/wget net send-data write-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=84df7e94-1a00-0000-9a1e-9f7f7b120000 pid=4731 execve guuid=b3c6e6c5-1a00-0000-9a1e-9f7fc2120000 pid=4802 /usr/bin/chmod guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=b3c6e6c5-1a00-0000-9a1e-9f7fc2120000 pid=4802 execve guuid=ef6733c6-1a00-0000-9a1e-9f7fc4120000 pid=4804 /usr/bin/dash guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=ef6733c6-1a00-0000-9a1e-9f7fc4120000 pid=4804 clone guuid=7b3dd2c6-1a00-0000-9a1e-9f7fc7120000 pid=4807 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=7b3dd2c6-1a00-0000-9a1e-9f7fc7120000 pid=4807 execve guuid=2ad732c7-1a00-0000-9a1e-9f7fc8120000 pid=4808 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=2ad732c7-1a00-0000-9a1e-9f7fc8120000 pid=4808 execve guuid=c19092c7-1a00-0000-9a1e-9f7fc9120000 pid=4809 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=c19092c7-1a00-0000-9a1e-9f7fc9120000 pid=4809 execve guuid=8f06eac7-1a00-0000-9a1e-9f7fca120000 pid=4810 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=8f06eac7-1a00-0000-9a1e-9f7fca120000 pid=4810 execve guuid=68e250c8-1a00-0000-9a1e-9f7fcb120000 pid=4811 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=68e250c8-1a00-0000-9a1e-9f7fcb120000 pid=4811 execve guuid=5771a2c8-1a00-0000-9a1e-9f7fcc120000 pid=4812 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=5771a2c8-1a00-0000-9a1e-9f7fcc120000 pid=4812 execve guuid=0479fbc8-1a00-0000-9a1e-9f7fcd120000 pid=4813 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=0479fbc8-1a00-0000-9a1e-9f7fcd120000 pid=4813 execve guuid=d6605fc9-1a00-0000-9a1e-9f7fce120000 pid=4814 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=d6605fc9-1a00-0000-9a1e-9f7fce120000 pid=4814 execve guuid=9127bbc9-1a00-0000-9a1e-9f7fcf120000 pid=4815 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=9127bbc9-1a00-0000-9a1e-9f7fcf120000 pid=4815 execve guuid=41aa0eca-1a00-0000-9a1e-9f7fd0120000 pid=4816 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=41aa0eca-1a00-0000-9a1e-9f7fd0120000 pid=4816 execve guuid=477c62ca-1a00-0000-9a1e-9f7fd1120000 pid=4817 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=477c62ca-1a00-0000-9a1e-9f7fd1120000 pid=4817 execve guuid=1f5ab3ca-1a00-0000-9a1e-9f7fd2120000 pid=4818 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=1f5ab3ca-1a00-0000-9a1e-9f7fd2120000 pid=4818 execve guuid=fde802cb-1a00-0000-9a1e-9f7fd3120000 pid=4819 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=fde802cb-1a00-0000-9a1e-9f7fd3120000 pid=4819 execve guuid=89ba4dcb-1a00-0000-9a1e-9f7fd4120000 pid=4820 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=89ba4dcb-1a00-0000-9a1e-9f7fd4120000 pid=4820 execve guuid=be018dcb-1a00-0000-9a1e-9f7fd8120000 pid=4824 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=be018dcb-1a00-0000-9a1e-9f7fd8120000 pid=4824 execve guuid=c40bcbcb-1a00-0000-9a1e-9f7fd9120000 pid=4825 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=c40bcbcb-1a00-0000-9a1e-9f7fd9120000 pid=4825 execve guuid=461b2fcc-1a00-0000-9a1e-9f7fda120000 pid=4826 /usr/bin/rm delete-file guuid=a769bc0e-1800-0000-9a1e-9f7fa30c0000 pid=3235->guuid=461b2fcc-1a00-0000-9a1e-9f7fda120000 pid=4826 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=b03f910f-1800-0000-9a1e-9f7fa70c0000 pid=3239->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=54570f3b-1800-0000-9a1e-9f7ffb0c0000 pid=3323->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=101c146b-1800-0000-9a1e-9f7f5b0d0000 pid=3419->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516 /tmp/GBXN net send-data write-file zombie guuid=e38dee91-1800-0000-9a1e-9f7fbb0d0000 pid=3515->guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 0734f5ed-e253-55cb-b667-c800d7698d2a 34.27.195.76:443 guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->0734f5ed-e253-55cb-b667-c800d7698d2a send: 463B 2e14e858-22de-5506-91bb-cc6e421fb188 34.173.152.68:443 guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->2e14e858-22de-5506-91bb-cc6e421fb188 send: 400B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=accb2da6-1800-0000-9a1e-9f7fc30d0000 pid=3523 /usr/bin/uname guuid=d2dc0792-1800-0000-9a1e-9f7fbc0d0000 pid=3516->guuid=accb2da6-1800-0000-9a1e-9f7fc30d0000 pid=3523 execve guuid=10eb7e92-1800-0000-9a1e-9f7fbf0d0000 pid=3519->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ce174fbc-1800-0000-9a1e-9f7fe20d0000 pid=3554->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=982e33f3-1800-0000-9a1e-9f7f620e0000 pid=3682 /tmp/BUDG zombie guuid=3a9018f3-1800-0000-9a1e-9f7f610e0000 pid=3681->guuid=982e33f3-1800-0000-9a1e-9f7f620e0000 pid=3682 clone guuid=dcbac1f3-1800-0000-9a1e-9f7f640e0000 pid=3684->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8e582d1f-1900-0000-9a1e-9f7ff30e0000 pid=3827->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=2ec7f048-1900-0000-9a1e-9f7f610f0000 pid=3937->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=995ff571-1900-0000-9a1e-9f7fa80f0000 pid=4008->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=17a15d94-1900-0000-9a1e-9f7f05100000 pid=4101->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ed7ab8bd-1900-0000-9a1e-9f7f77100000 pid=4215->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=77d550ee-1900-0000-9a1e-9f7ffb100000 pid=4347->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f50c3917-1a00-0000-9a1e-9f7f66110000 pid=4454->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f162ea40-1a00-0000-9a1e-9f7fd9110000 pid=4569->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=6552e56a-1a00-0000-9a1e-9f7f47120000 pid=4679->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=84df7e94-1a00-0000-9a1e-9f7f7b120000 pid=4731->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-16 21:37:29 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery linux
Behaviour
System Network Configuration Discovery
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 81f8a4d33b2d8fa5614e66e9e30d13d6d685bb65e10819ebb18da74164d2a446

(this sample)

  
Delivery method
Distributed via web download

Comments