MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 853f57f10f84ee3693b67fd18dc67346fa6ad735f8950ecf33443600322c874b. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: 853f57f10f84ee3693b67fd18dc67346fa6ad735f8950ecf33443600322c874b
SHA3-384 hash: 5003a8d43b010ee83bac31843858edd8cf71940afc5de1ee63a9c2d7d14f7a4f2e88d1f9b52ff377f1038d969b011228
SHA1 hash: 398624d48f4e562c7c2fa8ef99d77abe4696256a
MD5 hash: 625cafe4c186f09ebce1f0f323c1ccf6
humanhash: freddie-william-thirteen-moon
File name:shr
Download: download sample
File size:472 bytes
First seen:2026-03-26 03:58:25 UTC
Last seen:2026-03-26 07:12:51 UTC
File type: sh
MIME type:text/plain
ssdeep 12:/VJ+TNLI5epY6iuy4ghsesFrFBEGghgu+hYuTyisJF8EpASNyiiuyw:NwTNLI5e2sZrTBEGCnuoLpvH
TLSH T1BFF02E19D88448BEA07FC89FBBE73DCE110F5150464B2E2D96B61C03B4BDD185091433
Magika shell
Reporter adliwahid
Tags:sh

Intelligence


File Origin
# of uploads :
6
# of downloads :
8
Origin country :
NL NL
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=5b88a29b-1900-0000-ee68-6efe760a0000 pid=2678 /usr/bin/sudo guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685 /tmp/sample.bin guuid=5b88a29b-1900-0000-ee68-6efe760a0000 pid=2678->guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685 execve guuid=436e6e9e-1900-0000-ee68-6efe7f0a0000 pid=2687 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=436e6e9e-1900-0000-ee68-6efe7f0a0000 pid=2687 execve guuid=0cdeac9e-1900-0000-ee68-6efe810a0000 pid=2689 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=0cdeac9e-1900-0000-ee68-6efe810a0000 pid=2689 execve guuid=718d009f-1900-0000-ee68-6efe830a0000 pid=2691 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=718d009f-1900-0000-ee68-6efe830a0000 pid=2691 execve guuid=f8bc77c9-1900-0000-ee68-6efee60a0000 pid=2790 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=f8bc77c9-1900-0000-ee68-6efee60a0000 pid=2790 execve guuid=801bccc9-1900-0000-ee68-6efee80a0000 pid=2792 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=801bccc9-1900-0000-ee68-6efee80a0000 pid=2792 clone guuid=e42d81ca-1900-0000-ee68-6efeeb0a0000 pid=2795 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=e42d81ca-1900-0000-ee68-6efeeb0a0000 pid=2795 execve guuid=6c1dc2ca-1900-0000-ee68-6efeed0a0000 pid=2797 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=6c1dc2ca-1900-0000-ee68-6efeed0a0000 pid=2797 execve guuid=04d707cb-1900-0000-ee68-6efeee0a0000 pid=2798 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=04d707cb-1900-0000-ee68-6efeee0a0000 pid=2798 execve guuid=a27d44cb-1900-0000-ee68-6efeef0a0000 pid=2799 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=a27d44cb-1900-0000-ee68-6efeef0a0000 pid=2799 execve guuid=93d2a6cb-1900-0000-ee68-6efef10a0000 pid=2801 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=93d2a6cb-1900-0000-ee68-6efef10a0000 pid=2801 execve guuid=37143bf5-1900-0000-ee68-6efe4c0b0000 pid=2892 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=37143bf5-1900-0000-ee68-6efe4c0b0000 pid=2892 execve guuid=b0777bf5-1900-0000-ee68-6efe4e0b0000 pid=2894 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=b0777bf5-1900-0000-ee68-6efe4e0b0000 pid=2894 clone guuid=29a5fff5-1900-0000-ee68-6efe510b0000 pid=2897 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=29a5fff5-1900-0000-ee68-6efe510b0000 pid=2897 execve guuid=8bb650f6-1900-0000-ee68-6efe520b0000 pid=2898 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=8bb650f6-1900-0000-ee68-6efe520b0000 pid=2898 execve guuid=a0faa5f6-1900-0000-ee68-6efe540b0000 pid=2900 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=a0faa5f6-1900-0000-ee68-6efe540b0000 pid=2900 execve guuid=e7bcdef6-1900-0000-ee68-6efe550b0000 pid=2901 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=e7bcdef6-1900-0000-ee68-6efe550b0000 pid=2901 execve guuid=47c54cf7-1900-0000-ee68-6efe580b0000 pid=2904 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=47c54cf7-1900-0000-ee68-6efe580b0000 pid=2904 execve guuid=8d21f616-1a00-0000-ee68-6efe800b0000 pid=2944 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=8d21f616-1a00-0000-ee68-6efe800b0000 pid=2944 execve guuid=09596b17-1a00-0000-ee68-6efe810b0000 pid=2945 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=09596b17-1a00-0000-ee68-6efe810b0000 pid=2945 clone guuid=e2a35c19-1a00-0000-ee68-6efe830b0000 pid=2947 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=e2a35c19-1a00-0000-ee68-6efe830b0000 pid=2947 execve guuid=0f2ea719-1a00-0000-ee68-6efe840b0000 pid=2948 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=0f2ea719-1a00-0000-ee68-6efe840b0000 pid=2948 execve guuid=9a34131a-1a00-0000-ee68-6efe850b0000 pid=2949 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=9a34131a-1a00-0000-ee68-6efe850b0000 pid=2949 execve guuid=8f75541a-1a00-0000-ee68-6efe860b0000 pid=2950 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=8f75541a-1a00-0000-ee68-6efe860b0000 pid=2950 execve guuid=13dabf1a-1a00-0000-ee68-6efe870b0000 pid=2951 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=13dabf1a-1a00-0000-ee68-6efe870b0000 pid=2951 execve guuid=481ccc39-1a00-0000-ee68-6efe900b0000 pid=2960 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=481ccc39-1a00-0000-ee68-6efe900b0000 pid=2960 execve guuid=2de1743a-1a00-0000-ee68-6efe920b0000 pid=2962 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=2de1743a-1a00-0000-ee68-6efe920b0000 pid=2962 clone guuid=d3f1763b-1a00-0000-ee68-6efe960b0000 pid=2966 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=d3f1763b-1a00-0000-ee68-6efe960b0000 pid=2966 execve guuid=ee88f43b-1a00-0000-ee68-6efe990b0000 pid=2969 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=ee88f43b-1a00-0000-ee68-6efe990b0000 pid=2969 execve guuid=26d99a3c-1a00-0000-ee68-6efe9b0b0000 pid=2971 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=26d99a3c-1a00-0000-ee68-6efe9b0b0000 pid=2971 execve guuid=b19ced3c-1a00-0000-ee68-6efe9d0b0000 pid=2973 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=b19ced3c-1a00-0000-ee68-6efe9d0b0000 pid=2973 execve guuid=7b0c4f3d-1a00-0000-ee68-6efe9e0b0000 pid=2974 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=7b0c4f3d-1a00-0000-ee68-6efe9e0b0000 pid=2974 execve guuid=a0ac5867-1a00-0000-ee68-6efef50b0000 pid=3061 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=a0ac5867-1a00-0000-ee68-6efef50b0000 pid=3061 execve guuid=928bba67-1a00-0000-ee68-6efef70b0000 pid=3063 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=928bba67-1a00-0000-ee68-6efef70b0000 pid=3063 clone guuid=99f37a68-1a00-0000-ee68-6efefc0b0000 pid=3068 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=99f37a68-1a00-0000-ee68-6efefc0b0000 pid=3068 execve guuid=df08c068-1a00-0000-ee68-6efefe0b0000 pid=3070 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=df08c068-1a00-0000-ee68-6efefe0b0000 pid=3070 execve guuid=524f0269-1a00-0000-ee68-6efe000c0000 pid=3072 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=524f0269-1a00-0000-ee68-6efe000c0000 pid=3072 execve guuid=3eb35969-1a00-0000-ee68-6efe020c0000 pid=3074 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=3eb35969-1a00-0000-ee68-6efe020c0000 pid=3074 execve guuid=5dd49769-1a00-0000-ee68-6efe040c0000 pid=3076 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=5dd49769-1a00-0000-ee68-6efe040c0000 pid=3076 execve guuid=108c189d-1a00-0000-ee68-6efe850c0000 pid=3205 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=108c189d-1a00-0000-ee68-6efe850c0000 pid=3205 execve guuid=da32689d-1a00-0000-ee68-6efe870c0000 pid=3207 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=da32689d-1a00-0000-ee68-6efe870c0000 pid=3207 clone guuid=db49f89d-1a00-0000-ee68-6efe8a0c0000 pid=3210 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=db49f89d-1a00-0000-ee68-6efe8a0c0000 pid=3210 execve guuid=cac45e9e-1a00-0000-ee68-6efe8c0c0000 pid=3212 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=cac45e9e-1a00-0000-ee68-6efe8c0c0000 pid=3212 execve guuid=b23ab29e-1a00-0000-ee68-6efe8e0c0000 pid=3214 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=b23ab29e-1a00-0000-ee68-6efe8e0c0000 pid=3214 execve guuid=a60eef9e-1a00-0000-ee68-6efe900c0000 pid=3216 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=a60eef9e-1a00-0000-ee68-6efe900c0000 pid=3216 execve guuid=41562e9f-1a00-0000-ee68-6efe910c0000 pid=3217 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=41562e9f-1a00-0000-ee68-6efe910c0000 pid=3217 execve guuid=ef05e4be-1a00-0000-ee68-6efeb30c0000 pid=3251 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=ef05e4be-1a00-0000-ee68-6efeb30c0000 pid=3251 execve guuid=9e152cbf-1a00-0000-ee68-6efeb50c0000 pid=3253 /home/sandbox/sshd net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=9e152cbf-1a00-0000-ee68-6efeb50c0000 pid=3253 execve guuid=fb084fbf-1a00-0000-ee68-6efeb90c0000 pid=3257 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=fb084fbf-1a00-0000-ee68-6efeb90c0000 pid=3257 execve guuid=da3c20c0-1a00-0000-ee68-6efeba0c0000 pid=3258 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=da3c20c0-1a00-0000-ee68-6efeba0c0000 pid=3258 execve guuid=84ad57c1-1a00-0000-ee68-6efebb0c0000 pid=3259 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=84ad57c1-1a00-0000-ee68-6efebb0c0000 pid=3259 execve guuid=c26fc1c1-1a00-0000-ee68-6efebc0c0000 pid=3260 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=c26fc1c1-1a00-0000-ee68-6efebc0c0000 pid=3260 execve guuid=2fbdffc1-1a00-0000-ee68-6efebe0c0000 pid=3262 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=2fbdffc1-1a00-0000-ee68-6efebe0c0000 pid=3262 execve guuid=76d312e5-1a00-0000-ee68-6efec90c0000 pid=3273 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=76d312e5-1a00-0000-ee68-6efec90c0000 pid=3273 execve guuid=3ea376e5-1a00-0000-ee68-6efecb0c0000 pid=3275 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=3ea376e5-1a00-0000-ee68-6efecb0c0000 pid=3275 clone guuid=4bde92e6-1a00-0000-ee68-6efecf0c0000 pid=3279 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=4bde92e6-1a00-0000-ee68-6efecf0c0000 pid=3279 execve guuid=eee1e8e6-1a00-0000-ee68-6efed10c0000 pid=3281 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=eee1e8e6-1a00-0000-ee68-6efed10c0000 pid=3281 execve guuid=c02540e7-1a00-0000-ee68-6efed30c0000 pid=3283 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=c02540e7-1a00-0000-ee68-6efed30c0000 pid=3283 execve guuid=bec48fe7-1a00-0000-ee68-6efed50c0000 pid=3285 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=bec48fe7-1a00-0000-ee68-6efed50c0000 pid=3285 execve guuid=de06dde7-1a00-0000-ee68-6efed60c0000 pid=3286 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=de06dde7-1a00-0000-ee68-6efed60c0000 pid=3286 execve guuid=ac506f09-1b00-0000-ee68-6efefa0c0000 pid=3322 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=ac506f09-1b00-0000-ee68-6efefa0c0000 pid=3322 execve guuid=9fc6c109-1b00-0000-ee68-6efefb0c0000 pid=3323 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=9fc6c109-1b00-0000-ee68-6efefb0c0000 pid=3323 clone guuid=037c7f0a-1b00-0000-ee68-6efefd0c0000 pid=3325 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=037c7f0a-1b00-0000-ee68-6efefd0c0000 pid=3325 execve guuid=dd2fd00a-1b00-0000-ee68-6efeff0c0000 pid=3327 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=dd2fd00a-1b00-0000-ee68-6efeff0c0000 pid=3327 execve guuid=739b1b0b-1b00-0000-ee68-6efe000d0000 pid=3328 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=739b1b0b-1b00-0000-ee68-6efe000d0000 pid=3328 execve guuid=1f3e520b-1b00-0000-ee68-6efe010d0000 pid=3329 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=1f3e520b-1b00-0000-ee68-6efe010d0000 pid=3329 execve guuid=551a8f0b-1b00-0000-ee68-6efe030d0000 pid=3331 /usr/bin/wget net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=551a8f0b-1b00-0000-ee68-6efe030d0000 pid=3331 execve guuid=7f49390d-1b00-0000-ee68-6efe090d0000 pid=3337 /usr/bin/curl net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=7f49390d-1b00-0000-ee68-6efe090d0000 pid=3337 execve guuid=89b85412-1b00-0000-ee68-6efe160d0000 pid=3350 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=89b85412-1b00-0000-ee68-6efe160d0000 pid=3350 execve guuid=1d83e312-1b00-0000-ee68-6efe180d0000 pid=3352 /home/sandbox/sshd guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=1d83e312-1b00-0000-ee68-6efe180d0000 pid=3352 execve guuid=d40a8a14-1b00-0000-ee68-6efe1c0d0000 pid=3356 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=d40a8a14-1b00-0000-ee68-6efe1c0d0000 pid=3356 execve guuid=df00c314-1b00-0000-ee68-6efe1e0d0000 pid=3358 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=df00c314-1b00-0000-ee68-6efe1e0d0000 pid=3358 execve guuid=266cf614-1b00-0000-ee68-6efe1f0d0000 pid=3359 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=266cf614-1b00-0000-ee68-6efe1f0d0000 pid=3359 execve guuid=dcde6115-1b00-0000-ee68-6efe220d0000 pid=3362 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=dcde6115-1b00-0000-ee68-6efe220d0000 pid=3362 execve guuid=0d2db115-1b00-0000-ee68-6efe240d0000 pid=3364 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=0d2db115-1b00-0000-ee68-6efe240d0000 pid=3364 execve guuid=4e789240-1b00-0000-ee68-6efe680d0000 pid=3432 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=4e789240-1b00-0000-ee68-6efe680d0000 pid=3432 execve guuid=69a7f540-1b00-0000-ee68-6efe6a0d0000 pid=3434 /usr/bin/dash guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=69a7f540-1b00-0000-ee68-6efe6a0d0000 pid=3434 clone guuid=3cf9c541-1b00-0000-ee68-6efe6e0d0000 pid=3438 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=3cf9c541-1b00-0000-ee68-6efe6e0d0000 pid=3438 execve guuid=55d40442-1b00-0000-ee68-6efe6f0d0000 pid=3439 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=55d40442-1b00-0000-ee68-6efe6f0d0000 pid=3439 execve guuid=818e7c42-1b00-0000-ee68-6efe710d0000 pid=3441 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=818e7c42-1b00-0000-ee68-6efe710d0000 pid=3441 execve guuid=deb2e342-1b00-0000-ee68-6efe720d0000 pid=3442 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=deb2e342-1b00-0000-ee68-6efe720d0000 pid=3442 execve guuid=3bb25143-1b00-0000-ee68-6efe730d0000 pid=3443 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=3bb25143-1b00-0000-ee68-6efe730d0000 pid=3443 execve guuid=dcb6db62-1b00-0000-ee68-6efebb0d0000 pid=3515 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=dcb6db62-1b00-0000-ee68-6efebb0d0000 pid=3515 execve guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516 /home/sandbox/sshd net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516 execve guuid=ff21c08d-1c00-0000-ee68-6efe7f100000 pid=4223 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=ff21c08d-1c00-0000-ee68-6efe7f100000 pid=4223 execve guuid=c755418e-1c00-0000-ee68-6efe81100000 pid=4225 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=c755418e-1c00-0000-ee68-6efe81100000 pid=4225 execve guuid=772ac58e-1c00-0000-ee68-6efe83100000 pid=4227 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=772ac58e-1c00-0000-ee68-6efe83100000 pid=4227 execve guuid=73cf1e8f-1c00-0000-ee68-6efe85100000 pid=4229 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=73cf1e8f-1c00-0000-ee68-6efe85100000 pid=4229 execve guuid=93d8ad8f-1c00-0000-ee68-6efe89100000 pid=4233 /usr/bin/wget net send-data write-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=93d8ad8f-1c00-0000-ee68-6efe89100000 pid=4233 execve guuid=1892abaf-1c00-0000-ee68-6efef1100000 pid=4337 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=1892abaf-1c00-0000-ee68-6efef1100000 pid=4337 execve guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338 /home/sandbox/sshd net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338 execve guuid=4d4fa3da-1d00-0000-ee68-6efe45140000 pid=5189 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=4d4fa3da-1d00-0000-ee68-6efe45140000 pid=5189 execve guuid=dd6a38db-1d00-0000-ee68-6efe48140000 pid=5192 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=dd6a38db-1d00-0000-ee68-6efe48140000 pid=5192 execve guuid=564790db-1d00-0000-ee68-6efe4c140000 pid=5196 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=564790db-1d00-0000-ee68-6efe4c140000 pid=5196 execve guuid=9074e2db-1d00-0000-ee68-6efe4d140000 pid=5197 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=9074e2db-1d00-0000-ee68-6efe4d140000 pid=5197 execve guuid=aee843dc-1d00-0000-ee68-6efe4e140000 pid=5198 /usr/bin/wget net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=aee843dc-1d00-0000-ee68-6efe4e140000 pid=5198 execve guuid=c7d087df-1d00-0000-ee68-6efe55140000 pid=5205 /usr/bin/curl net guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=c7d087df-1d00-0000-ee68-6efe55140000 pid=5205 execve guuid=c5a20de6-1d00-0000-ee68-6efe5f140000 pid=5215 /usr/bin/chmod guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=c5a20de6-1d00-0000-ee68-6efe5f140000 pid=5215 execve guuid=85b34fe6-1d00-0000-ee68-6efe60140000 pid=5216 /home/sandbox/sshd guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=85b34fe6-1d00-0000-ee68-6efe60140000 pid=5216 execve guuid=004765e7-1d00-0000-ee68-6efe64140000 pid=5220 /usr/bin/rm guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=004765e7-1d00-0000-ee68-6efe64140000 pid=5220 execve guuid=087497e7-1d00-0000-ee68-6efe65140000 pid=5221 /usr/bin/rm delete-file guuid=b5dc329e-1900-0000-ee68-6efe7d0a0000 pid=2685->guuid=087497e7-1d00-0000-ee68-6efe65140000 pid=5221 execve 7837f143-69b5-589a-a950-6c9f4c81c4ec 202.155.10.112:80 guuid=718d009f-1900-0000-ee68-6efe830a0000 pid=2691->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 139B guuid=93d2a6cb-1900-0000-ee68-6efef10a0000 pid=2801->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 139B guuid=47c54cf7-1900-0000-ee68-6efe580b0000 pid=2904->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 138B guuid=13dabf1a-1a00-0000-ee68-6efe870b0000 pid=2951->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 139B guuid=7b0c4f3d-1a00-0000-ee68-6efe9e0b0000 pid=2974->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 139B guuid=5dd49769-1a00-0000-ee68-6efe040c0000 pid=3076->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 139B guuid=41562e9f-1a00-0000-ee68-6efe910c0000 pid=3217->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 138B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=9e152cbf-1a00-0000-ee68-6efeb50c0000 pid=3253->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=2c043bbf-1a00-0000-ee68-6efeb60c0000 pid=3254 /home/sandbox/sshd guuid=9e152cbf-1a00-0000-ee68-6efeb50c0000 pid=3253->guuid=2c043bbf-1a00-0000-ee68-6efeb60c0000 pid=3254 clone guuid=fd5f46bf-1a00-0000-ee68-6efeb70c0000 pid=3255 /home/sandbox/sshd net send-data zombie guuid=9e152cbf-1a00-0000-ee68-6efeb50c0000 pid=3253->guuid=fd5f46bf-1a00-0000-ee68-6efeb70c0000 pid=3255 clone guuid=fd5f46bf-1a00-0000-ee68-6efeb70c0000 pid=3255->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con e056ed1b-d38d-5b7b-989d-b8674c401c7d 202.155.10.112:55526 guuid=fd5f46bf-1a00-0000-ee68-6efeb70c0000 pid=3255->e056ed1b-d38d-5b7b-989d-b8674c401c7d send: 9B guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256 /home/sandbox/sshd net net-scan send-data guuid=fd5f46bf-1a00-0000-ee68-6efeb70c0000 pid=3255->guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256 clone guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 0e594a42-d893-5744-ad41-9bff223ad397 203.231.152.7:23 guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256->0e594a42-d893-5744-ad41-9bff223ad397 send: 40B guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256|send-data send-data to 4097 IP addresses review logs to see them all guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256->guuid=29824ebf-1a00-0000-ee68-6efeb80c0000 pid=3256|send-data send guuid=2fbdffc1-1a00-0000-ee68-6efebe0c0000 pid=3262->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 138B guuid=de06dde7-1a00-0000-ee68-6efed60c0000 pid=3286->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 138B guuid=551a8f0b-1b00-0000-ee68-6efe030d0000 pid=3331->7837f143-69b5-589a-a950-6c9f4c81c4ec con guuid=7f49390d-1b00-0000-ee68-6efe090d0000 pid=3337->7837f143-69b5-589a-a950-6c9f4c81c4ec con guuid=0d2db115-1b00-0000-ee68-6efe240d0000 pid=3364->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 138B guuid=3bb25143-1b00-0000-ee68-6efe730d0000 pid=3443->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 137B guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con bf2558f1-e30a-5484-8e7e-95c1ec233cd3 0.0.0.0:55511 guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516->bf2558f1-e30a-5484-8e7e-95c1ec233cd3 con guuid=343b3b63-1b00-0000-ee68-6efebe0d0000 pid=3518 /home/sandbox/sshd guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516->guuid=343b3b63-1b00-0000-ee68-6efebe0d0000 pid=3518 clone guuid=e249b38d-1c00-0000-ee68-6efe7e100000 pid=4222 /home/sandbox/sshd net send-data zombie guuid=d0012863-1b00-0000-ee68-6efebc0d0000 pid=3516->guuid=e249b38d-1c00-0000-ee68-6efe7e100000 pid=4222 clone guuid=e249b38d-1c00-0000-ee68-6efe7e100000 pid=4222->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=e249b38d-1c00-0000-ee68-6efe7e100000 pid=4222->e056ed1b-d38d-5b7b-989d-b8674c401c7d send: 8B guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224 /home/sandbox/sshd net net-scan send-data guuid=e249b38d-1c00-0000-ee68-6efe7e100000 pid=4222->guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224 clone guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224|send-data send-data to 1452 IP addresses review logs to see them all guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224->guuid=5760c48d-1c00-0000-ee68-6efe80100000 pid=4224|send-data send guuid=93d8ad8f-1c00-0000-ee68-6efe89100000 pid=4233->7837f143-69b5-589a-a950-6c9f4c81c4ec send: 137B guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338->bf2558f1-e30a-5484-8e7e-95c1ec233cd3 con guuid=188c1fb0-1c00-0000-ee68-6efef3100000 pid=4339 /home/sandbox/sshd guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338->guuid=188c1fb0-1c00-0000-ee68-6efef3100000 pid=4339 clone guuid=a7109dda-1d00-0000-ee68-6efe43140000 pid=5187 /home/sandbox/sshd net send-data zombie guuid=25b709b0-1c00-0000-ee68-6efef2100000 pid=4338->guuid=a7109dda-1d00-0000-ee68-6efe43140000 pid=5187 clone guuid=a7109dda-1d00-0000-ee68-6efe43140000 pid=5187->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=a7109dda-1d00-0000-ee68-6efe43140000 pid=5187->e056ed1b-d38d-5b7b-989d-b8674c401c7d send: 10B guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190 /home/sandbox/sshd net net-scan send-data guuid=a7109dda-1d00-0000-ee68-6efe43140000 pid=5187->guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190 clone guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190|send-data send-data to 4097 IP addresses review logs to see them all guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190->guuid=adc4a9da-1d00-0000-ee68-6efe46140000 pid=5190|send-data send guuid=aee843dc-1d00-0000-ee68-6efe4e140000 pid=5198->7837f143-69b5-589a-a950-6c9f4c81c4ec con guuid=c7d087df-1d00-0000-ee68-6efe55140000 pid=5205->7837f143-69b5-589a-a950-6c9f4c81c4ec con
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-03-26 04:42:49 UTC
File Type:
Text (Shell)
AV detection:
13 of 36 (36.11%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 853f57f10f84ee3693b67fd18dc67346fa6ad735f8950ecf33443600322c874b

(this sample)

  
Delivery method
Distributed via web download

Comments