MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8def1ebecb7f52c55229bee652449ca379847f7c2f8bf8a37efcff479d3c3298. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8def1ebecb7f52c55229bee652449ca379847f7c2f8bf8a37efcff479d3c3298
SHA3-384 hash: 6c2b01024eb54fad5dc8a15ec49a626daaf340f5af0738b6cf66158c63656994ef8d8bd0a79c801232de7bfd1ff204b0
SHA1 hash: 156fcb118ab551d7e05fa9cf1b688480b164a0a5
MD5 hash: 954dbf202716981aef8ba18ddbfe08c0
humanhash: triple-artist-alabama-delaware
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-06-19 03:04:53 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hToWlQ9qcZ3/F7W4HwAulNXYq4HvXDG+NjVsNXYrkJ:VIjZoKwPiq4HvXDGmKi2
TLSH T14ED09793D17301B010E98829E0D3B980B6224F7F4E84C22EB86328742F09A08B0C0364
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://202.155.8.56/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
52
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
Script
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=8a41cb91-1900-0000-eb6a-996335140000 pid=5173 /usr/bin/sudo guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174 /tmp/sample.bin guuid=8a41cb91-1900-0000-eb6a-996335140000 pid=5173->guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174 execve guuid=462a829e-1900-0000-eb6a-996337140000 pid=5175 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=462a829e-1900-0000-eb6a-996337140000 pid=5175 execve guuid=13eb2c9f-1900-0000-eb6a-996338140000 pid=5176 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=13eb2c9f-1900-0000-eb6a-996338140000 pid=5176 execve guuid=59da6ace-1900-0000-eb6a-996339140000 pid=5177 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=59da6ace-1900-0000-eb6a-996339140000 pid=5177 execve guuid=455d28cf-1900-0000-eb6a-99633a140000 pid=5178 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=455d28cf-1900-0000-eb6a-99633a140000 pid=5178 clone guuid=be7ae8d0-1900-0000-eb6a-99633c140000 pid=5180 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=be7ae8d0-1900-0000-eb6a-99633c140000 pid=5180 execve guuid=582751d1-1900-0000-eb6a-99633d140000 pid=5181 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=582751d1-1900-0000-eb6a-99633d140000 pid=5181 execve guuid=d6d2d7fb-1900-0000-eb6a-99633e140000 pid=5182 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=d6d2d7fb-1900-0000-eb6a-99633e140000 pid=5182 execve guuid=4a522cfc-1900-0000-eb6a-99633f140000 pid=5183 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=4a522cfc-1900-0000-eb6a-99633f140000 pid=5183 clone guuid=b8a9dffc-1900-0000-eb6a-996341140000 pid=5185 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=b8a9dffc-1900-0000-eb6a-996341140000 pid=5185 execve guuid=a71b47fd-1900-0000-eb6a-996342140000 pid=5186 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=a71b47fd-1900-0000-eb6a-996342140000 pid=5186 execve guuid=1d806029-1a00-0000-eb6a-996343140000 pid=5187 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=1d806029-1a00-0000-eb6a-996343140000 pid=5187 execve guuid=4832eb29-1a00-0000-eb6a-996344140000 pid=5188 /tmp/OAQT guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=4832eb29-1a00-0000-eb6a-996344140000 pid=5188 execve guuid=96ab262a-1a00-0000-eb6a-996346140000 pid=5190 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=96ab262a-1a00-0000-eb6a-996346140000 pid=5190 execve guuid=e05c042b-1a00-0000-eb6a-996347140000 pid=5191 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=e05c042b-1a00-0000-eb6a-996347140000 pid=5191 execve guuid=b37c5454-1a00-0000-eb6a-996349140000 pid=5193 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=b37c5454-1a00-0000-eb6a-996349140000 pid=5193 execve guuid=091d9d54-1a00-0000-eb6a-99634a140000 pid=5194 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=091d9d54-1a00-0000-eb6a-99634a140000 pid=5194 clone guuid=9bbdcd55-1a00-0000-eb6a-99634c140000 pid=5196 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=9bbdcd55-1a00-0000-eb6a-99634c140000 pid=5196 execve guuid=60b00d56-1a00-0000-eb6a-99634d140000 pid=5197 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=60b00d56-1a00-0000-eb6a-99634d140000 pid=5197 execve guuid=2786d07c-1a00-0000-eb6a-99634f140000 pid=5199 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=2786d07c-1a00-0000-eb6a-99634f140000 pid=5199 execve guuid=16740e7d-1a00-0000-eb6a-996350140000 pid=5200 /tmp/OGSC guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=16740e7d-1a00-0000-eb6a-996350140000 pid=5200 execve guuid=17fb2c7d-1a00-0000-eb6a-996352140000 pid=5202 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=17fb2c7d-1a00-0000-eb6a-996352140000 pid=5202 execve guuid=89296a7d-1a00-0000-eb6a-996353140000 pid=5203 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=89296a7d-1a00-0000-eb6a-996353140000 pid=5203 execve guuid=f0ebaca8-1a00-0000-eb6a-996360140000 pid=5216 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=f0ebaca8-1a00-0000-eb6a-996360140000 pid=5216 execve guuid=7f7417a9-1a00-0000-eb6a-996361140000 pid=5217 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=7f7417a9-1a00-0000-eb6a-996361140000 pid=5217 clone guuid=7da8e8a9-1a00-0000-eb6a-996363140000 pid=5219 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=7da8e8a9-1a00-0000-eb6a-996363140000 pid=5219 execve guuid=092a38aa-1a00-0000-eb6a-996364140000 pid=5220 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=092a38aa-1a00-0000-eb6a-996364140000 pid=5220 execve guuid=256da8d5-1a00-0000-eb6a-996369140000 pid=5225 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=256da8d5-1a00-0000-eb6a-996369140000 pid=5225 execve guuid=8e2de9d5-1a00-0000-eb6a-99636a140000 pid=5226 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=8e2de9d5-1a00-0000-eb6a-99636a140000 pid=5226 clone guuid=10636cd6-1a00-0000-eb6a-99636c140000 pid=5228 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=10636cd6-1a00-0000-eb6a-99636c140000 pid=5228 execve guuid=4107a6d6-1a00-0000-eb6a-99636d140000 pid=5229 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=4107a6d6-1a00-0000-eb6a-99636d140000 pid=5229 execve guuid=6dd9f8fc-1a00-0000-eb6a-99637d140000 pid=5245 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=6dd9f8fc-1a00-0000-eb6a-99637d140000 pid=5245 execve guuid=cded82fd-1a00-0000-eb6a-99637e140000 pid=5246 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=cded82fd-1a00-0000-eb6a-99637e140000 pid=5246 clone guuid=0ae785fe-1a00-0000-eb6a-996380140000 pid=5248 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=0ae785fe-1a00-0000-eb6a-996380140000 pid=5248 execve guuid=4edd06ff-1a00-0000-eb6a-996381140000 pid=5249 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=4edd06ff-1a00-0000-eb6a-996381140000 pid=5249 execve guuid=d7912723-1b00-0000-eb6a-996382140000 pid=5250 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=d7912723-1b00-0000-eb6a-996382140000 pid=5250 execve guuid=5a99ac23-1b00-0000-eb6a-996383140000 pid=5251 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=5a99ac23-1b00-0000-eb6a-996383140000 pid=5251 clone guuid=11b7ce24-1b00-0000-eb6a-996385140000 pid=5253 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=11b7ce24-1b00-0000-eb6a-996385140000 pid=5253 execve guuid=9d295d25-1b00-0000-eb6a-996386140000 pid=5254 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=9d295d25-1b00-0000-eb6a-996386140000 pid=5254 execve guuid=0a6e3d52-1b00-0000-eb6a-996387140000 pid=5255 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=0a6e3d52-1b00-0000-eb6a-996387140000 pid=5255 execve guuid=49adcc52-1b00-0000-eb6a-996388140000 pid=5256 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=49adcc52-1b00-0000-eb6a-996388140000 pid=5256 clone guuid=365be453-1b00-0000-eb6a-99638a140000 pid=5258 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=365be453-1b00-0000-eb6a-99638a140000 pid=5258 execve guuid=84467d54-1b00-0000-eb6a-99638b140000 pid=5259 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=84467d54-1b00-0000-eb6a-99638b140000 pid=5259 execve guuid=9c39cc7e-1b00-0000-eb6a-99638c140000 pid=5260 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=9c39cc7e-1b00-0000-eb6a-99638c140000 pid=5260 execve guuid=450f497f-1b00-0000-eb6a-99638d140000 pid=5261 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=450f497f-1b00-0000-eb6a-99638d140000 pid=5261 clone guuid=ce426680-1b00-0000-eb6a-99638f140000 pid=5263 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=ce426680-1b00-0000-eb6a-99638f140000 pid=5263 execve guuid=51c8ee80-1b00-0000-eb6a-996390140000 pid=5264 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=51c8ee80-1b00-0000-eb6a-996390140000 pid=5264 execve guuid=43f3b0ac-1b00-0000-eb6a-996391140000 pid=5265 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=43f3b0ac-1b00-0000-eb6a-996391140000 pid=5265 execve guuid=46c93cad-1b00-0000-eb6a-996392140000 pid=5266 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=46c93cad-1b00-0000-eb6a-996392140000 pid=5266 clone guuid=01724cae-1b00-0000-eb6a-996394140000 pid=5268 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=01724cae-1b00-0000-eb6a-996394140000 pid=5268 execve guuid=e45d03af-1b00-0000-eb6a-996395140000 pid=5269 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=e45d03af-1b00-0000-eb6a-996395140000 pid=5269 execve guuid=e4f669d9-1b00-0000-eb6a-996396140000 pid=5270 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=e4f669d9-1b00-0000-eb6a-996396140000 pid=5270 execve guuid=83b7abd9-1b00-0000-eb6a-996397140000 pid=5271 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=83b7abd9-1b00-0000-eb6a-996397140000 pid=5271 clone guuid=7a8a99da-1b00-0000-eb6a-996399140000 pid=5273 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=7a8a99da-1b00-0000-eb6a-996399140000 pid=5273 execve guuid=1dd521db-1b00-0000-eb6a-99639a140000 pid=5274 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=1dd521db-1b00-0000-eb6a-99639a140000 pid=5274 execve guuid=e3483c0a-1c00-0000-eb6a-99639b140000 pid=5275 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=e3483c0a-1c00-0000-eb6a-99639b140000 pid=5275 execve guuid=0e92c20a-1c00-0000-eb6a-99639c140000 pid=5276 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=0e92c20a-1c00-0000-eb6a-99639c140000 pid=5276 clone guuid=f8a9530b-1c00-0000-eb6a-99639e140000 pid=5278 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=f8a9530b-1c00-0000-eb6a-99639e140000 pid=5278 execve guuid=9b14930b-1c00-0000-eb6a-99639f140000 pid=5279 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=9b14930b-1c00-0000-eb6a-99639f140000 pid=5279 execve guuid=b9bb9135-1c00-0000-eb6a-9963a0140000 pid=5280 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=b9bb9135-1c00-0000-eb6a-9963a0140000 pid=5280 execve guuid=9e011e36-1c00-0000-eb6a-9963a1140000 pid=5281 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=9e011e36-1c00-0000-eb6a-9963a1140000 pid=5281 clone guuid=1ddd3837-1c00-0000-eb6a-9963a3140000 pid=5283 /usr/bin/rm guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=1ddd3837-1c00-0000-eb6a-9963a3140000 pid=5283 execve guuid=ef0cc437-1c00-0000-eb6a-9963a4140000 pid=5284 /usr/bin/wget net send-data write-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=ef0cc437-1c00-0000-eb6a-9963a4140000 pid=5284 execve guuid=b75b8d61-1c00-0000-eb6a-9963a5140000 pid=5285 /usr/bin/chmod guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=b75b8d61-1c00-0000-eb6a-9963a5140000 pid=5285 execve guuid=7aa81562-1c00-0000-eb6a-9963a6140000 pid=5286 /usr/bin/dash guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=7aa81562-1c00-0000-eb6a-9963a6140000 pid=5286 clone guuid=7e803763-1c00-0000-eb6a-9963a8140000 pid=5288 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=7e803763-1c00-0000-eb6a-9963a8140000 pid=5288 execve guuid=1623c863-1c00-0000-eb6a-9963a9140000 pid=5289 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=1623c863-1c00-0000-eb6a-9963a9140000 pid=5289 execve guuid=76e24f64-1c00-0000-eb6a-9963aa140000 pid=5290 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=76e24f64-1c00-0000-eb6a-9963aa140000 pid=5290 execve guuid=c7a0d464-1c00-0000-eb6a-9963ab140000 pid=5291 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=c7a0d464-1c00-0000-eb6a-9963ab140000 pid=5291 execve guuid=c7d55c65-1c00-0000-eb6a-9963ac140000 pid=5292 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=c7d55c65-1c00-0000-eb6a-9963ac140000 pid=5292 execve guuid=80fde565-1c00-0000-eb6a-9963ad140000 pid=5293 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=80fde565-1c00-0000-eb6a-9963ad140000 pid=5293 execve guuid=4dc47a66-1c00-0000-eb6a-9963ae140000 pid=5294 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=4dc47a66-1c00-0000-eb6a-9963ae140000 pid=5294 execve guuid=aff9fe66-1c00-0000-eb6a-9963af140000 pid=5295 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=aff9fe66-1c00-0000-eb6a-9963af140000 pid=5295 execve guuid=61078867-1c00-0000-eb6a-9963b0140000 pid=5296 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=61078867-1c00-0000-eb6a-9963b0140000 pid=5296 execve guuid=541d2568-1c00-0000-eb6a-9963b1140000 pid=5297 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=541d2568-1c00-0000-eb6a-9963b1140000 pid=5297 execve guuid=816fa368-1c00-0000-eb6a-9963b2140000 pid=5298 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=816fa368-1c00-0000-eb6a-9963b2140000 pid=5298 execve guuid=e6cb2b69-1c00-0000-eb6a-9963b3140000 pid=5299 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=e6cb2b69-1c00-0000-eb6a-9963b3140000 pid=5299 execve guuid=78e3b769-1c00-0000-eb6a-9963b4140000 pid=5300 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=78e3b769-1c00-0000-eb6a-9963b4140000 pid=5300 execve guuid=41aa486a-1c00-0000-eb6a-9963b5140000 pid=5301 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=41aa486a-1c00-0000-eb6a-9963b5140000 pid=5301 execve guuid=8410cf6a-1c00-0000-eb6a-9963b6140000 pid=5302 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=8410cf6a-1c00-0000-eb6a-9963b6140000 pid=5302 execve guuid=47245f6b-1c00-0000-eb6a-9963b7140000 pid=5303 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=47245f6b-1c00-0000-eb6a-9963b7140000 pid=5303 execve guuid=22ffef6b-1c00-0000-eb6a-9963b8140000 pid=5304 /usr/bin/rm delete-file guuid=f4f23695-1900-0000-eb6a-996336140000 pid=5174->guuid=22ffef6b-1c00-0000-eb6a-9963b8140000 pid=5304 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=13eb2c9f-1900-0000-eb6a-996338140000 pid=5176->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=582751d1-1900-0000-eb6a-99633d140000 pid=5181->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=a71b47fd-1900-0000-eb6a-996342140000 pid=5186->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189 /tmp/OAQT net send-data write-file zombie guuid=4832eb29-1a00-0000-eb6a-996344140000 pid=5188->guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=4d03cb32-1a00-0000-eb6a-996348140000 pid=5192 /usr/bin/uname guuid=9fd6022a-1a00-0000-eb6a-996345140000 pid=5189->guuid=4d03cb32-1a00-0000-eb6a-996348140000 pid=5192 execve guuid=e05c042b-1a00-0000-eb6a-996347140000 pid=5191->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=60b00d56-1a00-0000-eb6a-99634d140000 pid=5197->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=d627237d-1a00-0000-eb6a-996351140000 pid=5201 /tmp/OGSC zombie guuid=16740e7d-1a00-0000-eb6a-996350140000 pid=5200->guuid=d627237d-1a00-0000-eb6a-996351140000 pid=5201 clone guuid=89296a7d-1a00-0000-eb6a-996353140000 pid=5203->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=092a38aa-1a00-0000-eb6a-996364140000 pid=5220->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=4107a6d6-1a00-0000-eb6a-99636d140000 pid=5229->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=4edd06ff-1a00-0000-eb6a-996381140000 pid=5249->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=9d295d25-1b00-0000-eb6a-996386140000 pid=5254->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=84467d54-1b00-0000-eb6a-99638b140000 pid=5259->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=51c8ee80-1b00-0000-eb6a-996390140000 pid=5264->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=e45d03af-1b00-0000-eb6a-996395140000 pid=5269->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=1dd521db-1b00-0000-eb6a-99639a140000 pid=5274->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=9b14930b-1c00-0000-eb6a-99639f140000 pid=5279->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=ef0cc437-1c00-0000-eb6a-9963a4140000 pid=5284->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8def1ebecb7f52c55229bee652449ca379847f7c2f8bf8a37efcff479d3c3298

(this sample)

  
Delivery method
Distributed via web download

Comments