MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 8f5596aa92afb1658451983bb8c01529e97ad5bce91513dcff1e6d9317affc8d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: 8f5596aa92afb1658451983bb8c01529e97ad5bce91513dcff1e6d9317affc8d
SHA3-384 hash: 80a9e8788ac739e42fd3a2ec3659d42216657d0edf399352aaa317e6b6327fe719ed56fbf060749d89d6c537d9666ef6
SHA1 hash: f564c1881f5c89da9853690e9bf368f028c986bf
MD5 hash: e318e551721319418aa4bd3ecc73d4b0
humanhash: avocado-delta-sixteen-summer
File name:zok
Download: download sample
File size:477 bytes
First seen:2026-06-09 01:09:35 UTC
Last seen:2026-06-09 05:59:16 UTC
File type: sh
MIME type:text/plain
ssdeep 12:/VJ+TNLI5zqiYzkbfEiuy4ghsesFrFBEGghgu+hYuTyisJF8EpASNyiiuyw:NwTNLI5zq7zgyZrTBEGCnuoLpvH
TLSH T124F0270AE88844BFA03FC89FBBE63DCD110F51552A8B2E2D96B92C47B8B9C4850D1433
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
236
# of downloads :
5
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-06-02T03:55:00Z UTC
Last seen:
2026-06-09T12:58:00Z UTC
Hits:
~10
Status:
terminated
Behavior Graph:
%3 guuid=053a4569-3f00-0000-7903-f71215040000 pid=1045 /usr/bin/sudo guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046 /tmp/sample.bin guuid=053a4569-3f00-0000-7903-f71215040000 pid=1045->guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046 execve guuid=bd60816c-3f00-0000-7903-f71217040000 pid=1047 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=bd60816c-3f00-0000-7903-f71217040000 pid=1047 execve guuid=a160f86c-3f00-0000-7903-f71218040000 pid=1048 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=a160f86c-3f00-0000-7903-f71218040000 pid=1048 execve guuid=b35e646d-3f00-0000-7903-f71219040000 pid=1049 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b35e646d-3f00-0000-7903-f71219040000 pid=1049 execve guuid=a754eed9-3f00-0000-7903-f7121a040000 pid=1050 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=a754eed9-3f00-0000-7903-f7121a040000 pid=1050 execve guuid=c1cc9dda-3f00-0000-7903-f7121b040000 pid=1051 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c1cc9dda-3f00-0000-7903-f7121b040000 pid=1051 clone guuid=8a89aadb-3f00-0000-7903-f7121d040000 pid=1053 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=8a89aadb-3f00-0000-7903-f7121d040000 pid=1053 execve guuid=293e40dc-3f00-0000-7903-f7121e040000 pid=1054 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=293e40dc-3f00-0000-7903-f7121e040000 pid=1054 execve guuid=5f15ebdc-3f00-0000-7903-f7121f040000 pid=1055 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=5f15ebdc-3f00-0000-7903-f7121f040000 pid=1055 execve guuid=f8d297dd-3f00-0000-7903-f71220040000 pid=1056 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f8d297dd-3f00-0000-7903-f71220040000 pid=1056 execve guuid=39fa1cde-3f00-0000-7903-f71221040000 pid=1057 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=39fa1cde-3f00-0000-7903-f71221040000 pid=1057 execve guuid=7b37ea28-4000-0000-7903-f71222040000 pid=1058 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=7b37ea28-4000-0000-7903-f71222040000 pid=1058 execve guuid=ed242929-4000-0000-7903-f71223040000 pid=1059 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=ed242929-4000-0000-7903-f71223040000 pid=1059 clone guuid=839edd29-4000-0000-7903-f71225040000 pid=1061 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=839edd29-4000-0000-7903-f71225040000 pid=1061 execve guuid=45142a2a-4000-0000-7903-f71226040000 pid=1062 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=45142a2a-4000-0000-7903-f71226040000 pid=1062 execve guuid=4651722a-4000-0000-7903-f71227040000 pid=1063 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=4651722a-4000-0000-7903-f71227040000 pid=1063 execve guuid=257bb72a-4000-0000-7903-f71228040000 pid=1064 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=257bb72a-4000-0000-7903-f71228040000 pid=1064 execve guuid=b2f1002b-4000-0000-7903-f71229040000 pid=1065 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b2f1002b-4000-0000-7903-f71229040000 pid=1065 execve guuid=52399c36-4000-0000-7903-f7122a040000 pid=1066 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=52399c36-4000-0000-7903-f7122a040000 pid=1066 execve guuid=e3ecf036-4000-0000-7903-f7122b040000 pid=1067 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e3ecf036-4000-0000-7903-f7122b040000 pid=1067 clone guuid=e3b3db37-4000-0000-7903-f7122d040000 pid=1069 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e3b3db37-4000-0000-7903-f7122d040000 pid=1069 execve guuid=1cda2338-4000-0000-7903-f7122e040000 pid=1070 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=1cda2338-4000-0000-7903-f7122e040000 pid=1070 execve guuid=55957a38-4000-0000-7903-f7122f040000 pid=1071 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=55957a38-4000-0000-7903-f7122f040000 pid=1071 execve guuid=3d11bf38-4000-0000-7903-f71230040000 pid=1072 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=3d11bf38-4000-0000-7903-f71230040000 pid=1072 execve guuid=a0b70739-4000-0000-7903-f71231040000 pid=1073 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=a0b70739-4000-0000-7903-f71231040000 pid=1073 execve guuid=c4cb2353-4000-0000-7903-f71232040000 pid=1074 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c4cb2353-4000-0000-7903-f71232040000 pid=1074 execve guuid=9a658a53-4000-0000-7903-f71233040000 pid=1075 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=9a658a53-4000-0000-7903-f71233040000 pid=1075 clone guuid=01425254-4000-0000-7903-f71235040000 pid=1077 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=01425254-4000-0000-7903-f71235040000 pid=1077 execve guuid=2707e354-4000-0000-7903-f71236040000 pid=1078 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=2707e354-4000-0000-7903-f71236040000 pid=1078 execve guuid=f9176455-4000-0000-7903-f71237040000 pid=1079 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f9176455-4000-0000-7903-f71237040000 pid=1079 execve guuid=0107f155-4000-0000-7903-f71238040000 pid=1080 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=0107f155-4000-0000-7903-f71238040000 pid=1080 execve guuid=b43f5c56-4000-0000-7903-f71239040000 pid=1081 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b43f5c56-4000-0000-7903-f71239040000 pid=1081 execve guuid=f44da466-4000-0000-7903-f7123a040000 pid=1082 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f44da466-4000-0000-7903-f7123a040000 pid=1082 execve guuid=9cc50767-4000-0000-7903-f7123b040000 pid=1083 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=9cc50767-4000-0000-7903-f7123b040000 pid=1083 clone guuid=d1da4068-4000-0000-7903-f7123d040000 pid=1085 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=d1da4068-4000-0000-7903-f7123d040000 pid=1085 execve guuid=97fcb268-4000-0000-7903-f7123e040000 pid=1086 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=97fcb268-4000-0000-7903-f7123e040000 pid=1086 execve guuid=4d0b6e69-4000-0000-7903-f7123f040000 pid=1087 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=4d0b6e69-4000-0000-7903-f7123f040000 pid=1087 execve guuid=53d1f469-4000-0000-7903-f71240040000 pid=1088 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=53d1f469-4000-0000-7903-f71240040000 pid=1088 execve guuid=99396d6a-4000-0000-7903-f71241040000 pid=1089 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=99396d6a-4000-0000-7903-f71241040000 pid=1089 execve guuid=517b1677-4000-0000-7903-f71242040000 pid=1090 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=517b1677-4000-0000-7903-f71242040000 pid=1090 execve guuid=8156bb77-4000-0000-7903-f71243040000 pid=1091 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=8156bb77-4000-0000-7903-f71243040000 pid=1091 clone guuid=b552c378-4000-0000-7903-f71245040000 pid=1093 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b552c378-4000-0000-7903-f71245040000 pid=1093 execve guuid=4c6b4d79-4000-0000-7903-f71246040000 pid=1094 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=4c6b4d79-4000-0000-7903-f71246040000 pid=1094 execve guuid=b1f9ed79-4000-0000-7903-f71247040000 pid=1095 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b1f9ed79-4000-0000-7903-f71247040000 pid=1095 execve guuid=adb66a7a-4000-0000-7903-f71248040000 pid=1096 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=adb66a7a-4000-0000-7903-f71248040000 pid=1096 execve guuid=ec7d297b-4000-0000-7903-f71249040000 pid=1097 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=ec7d297b-4000-0000-7903-f71249040000 pid=1097 execve guuid=f3140785-4000-0000-7903-f7124a040000 pid=1098 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f3140785-4000-0000-7903-f7124a040000 pid=1098 execve guuid=e4166e85-4000-0000-7903-f7124b040000 pid=1099 /home/sandbox/cron.azsxd net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e4166e85-4000-0000-7903-f7124b040000 pid=1099 execve guuid=8e69af85-4000-0000-7903-f7124e040000 pid=1102 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=8e69af85-4000-0000-7903-f7124e040000 pid=1102 execve guuid=47860d86-4000-0000-7903-f71250040000 pid=1104 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=47860d86-4000-0000-7903-f71250040000 pid=1104 execve guuid=45d1c686-4000-0000-7903-f71251040000 pid=1105 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=45d1c686-4000-0000-7903-f71251040000 pid=1105 execve guuid=f15b4a87-4000-0000-7903-f71252040000 pid=1106 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f15b4a87-4000-0000-7903-f71252040000 pid=1106 execve guuid=bd31cf87-4000-0000-7903-f71253040000 pid=1107 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=bd31cf87-4000-0000-7903-f71253040000 pid=1107 execve guuid=3d8a45a5-4000-0000-7903-f71254040000 pid=1108 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=3d8a45a5-4000-0000-7903-f71254040000 pid=1108 execve guuid=34e9c9a5-4000-0000-7903-f71255040000 pid=1109 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=34e9c9a5-4000-0000-7903-f71255040000 pid=1109 clone guuid=ed4ceea6-4000-0000-7903-f71257040000 pid=1111 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=ed4ceea6-4000-0000-7903-f71257040000 pid=1111 execve guuid=a26d76a7-4000-0000-7903-f71258040000 pid=1112 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=a26d76a7-4000-0000-7903-f71258040000 pid=1112 execve guuid=c5b1eaa7-4000-0000-7903-f71259040000 pid=1113 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c5b1eaa7-4000-0000-7903-f71259040000 pid=1113 execve guuid=1e574ea8-4000-0000-7903-f7125a040000 pid=1114 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=1e574ea8-4000-0000-7903-f7125a040000 pid=1114 execve guuid=8f27a4a8-4000-0000-7903-f7125b040000 pid=1115 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=8f27a4a8-4000-0000-7903-f7125b040000 pid=1115 execve guuid=c7a8edb1-4000-0000-7903-f7125c040000 pid=1116 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c7a8edb1-4000-0000-7903-f7125c040000 pid=1116 execve guuid=0c1852b2-4000-0000-7903-f7125d040000 pid=1117 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=0c1852b2-4000-0000-7903-f7125d040000 pid=1117 clone guuid=c793d4b2-4000-0000-7903-f7125f040000 pid=1119 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c793d4b2-4000-0000-7903-f7125f040000 pid=1119 execve guuid=0f3f0eb3-4000-0000-7903-f71260040000 pid=1120 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=0f3f0eb3-4000-0000-7903-f71260040000 pid=1120 execve guuid=e45152b3-4000-0000-7903-f71261040000 pid=1121 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e45152b3-4000-0000-7903-f71261040000 pid=1121 execve guuid=b63e8bb3-4000-0000-7903-f71262040000 pid=1122 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b63e8bb3-4000-0000-7903-f71262040000 pid=1122 execve guuid=4469c7b3-4000-0000-7903-f71263040000 pid=1123 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=4469c7b3-4000-0000-7903-f71263040000 pid=1123 execve guuid=e4f3ddbc-4000-0000-7903-f71264040000 pid=1124 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e4f3ddbc-4000-0000-7903-f71264040000 pid=1124 execve guuid=f47360bd-4000-0000-7903-f71265040000 pid=1125 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f47360bd-4000-0000-7903-f71265040000 pid=1125 clone guuid=3be5f9be-4000-0000-7903-f71267040000 pid=1127 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=3be5f9be-4000-0000-7903-f71267040000 pid=1127 execve guuid=7d695fbf-4000-0000-7903-f71268040000 pid=1128 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=7d695fbf-4000-0000-7903-f71268040000 pid=1128 execve guuid=47d3b8bf-4000-0000-7903-f71269040000 pid=1129 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=47d3b8bf-4000-0000-7903-f71269040000 pid=1129 execve guuid=43bf0ac0-4000-0000-7903-f7126a040000 pid=1130 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=43bf0ac0-4000-0000-7903-f7126a040000 pid=1130 execve guuid=56496ac0-4000-0000-7903-f7126b040000 pid=1131 /usr/bin/wget net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=56496ac0-4000-0000-7903-f7126b040000 pid=1131 execve guuid=c524b9e6-4000-0000-7903-f7126c040000 pid=1132 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=c524b9e6-4000-0000-7903-f7126c040000 pid=1132 execve guuid=36094de7-4000-0000-7903-f7126d040000 pid=1133 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=36094de7-4000-0000-7903-f7126d040000 pid=1133 clone guuid=24e775e8-4000-0000-7903-f7126f040000 pid=1135 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=24e775e8-4000-0000-7903-f7126f040000 pid=1135 execve guuid=1b540de9-4000-0000-7903-f71270040000 pid=1136 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=1b540de9-4000-0000-7903-f71270040000 pid=1136 execve guuid=406b9fe9-4000-0000-7903-f71271040000 pid=1137 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=406b9fe9-4000-0000-7903-f71271040000 pid=1137 execve guuid=45bc2fea-4000-0000-7903-f71272040000 pid=1138 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=45bc2fea-4000-0000-7903-f71272040000 pid=1138 execve guuid=16d3aaea-4000-0000-7903-f71273040000 pid=1139 /usr/bin/wget net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=16d3aaea-4000-0000-7903-f71273040000 pid=1139 execve guuid=273a10ed-4000-0000-7903-f71274040000 pid=1140 /usr/bin/curl net send-data write-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=273a10ed-4000-0000-7903-f71274040000 pid=1140 execve guuid=ed24f2ba-4100-0000-7903-f71275040000 pid=1141 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=ed24f2ba-4100-0000-7903-f71275040000 pid=1141 execve guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142 /home/sandbox/cron.azsxd net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142 execve guuid=0243dfe5-4200-0000-7903-f712c4050000 pid=1476 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=0243dfe5-4200-0000-7903-f712c4050000 pid=1476 execve guuid=34f529e6-4200-0000-7903-f712c6050000 pid=1478 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=34f529e6-4200-0000-7903-f712c6050000 pid=1478 execve guuid=6996eee6-4200-0000-7903-f712c9050000 pid=1481 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=6996eee6-4200-0000-7903-f712c9050000 pid=1481 execve guuid=f9d48be7-4200-0000-7903-f712cb050000 pid=1483 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f9d48be7-4200-0000-7903-f712cb050000 pid=1483 execve guuid=4c8856e8-4200-0000-7903-f712cc050000 pid=1484 /usr/bin/wget guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=4c8856e8-4200-0000-7903-f712cc050000 pid=1484 execve guuid=556a7ce9-4200-0000-7903-f712cd050000 pid=1485 /usr/bin/curl net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=556a7ce9-4200-0000-7903-f712cd050000 pid=1485 execve guuid=2582a6ed-4200-0000-7903-f712ce050000 pid=1486 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=2582a6ed-4200-0000-7903-f712ce050000 pid=1486 execve guuid=974ff0ed-4200-0000-7903-f712cf050000 pid=1487 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=974ff0ed-4200-0000-7903-f712cf050000 pid=1487 clone guuid=2a58ffed-4200-0000-7903-f712d0050000 pid=1488 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=2a58ffed-4200-0000-7903-f712d0050000 pid=1488 execve guuid=95f640ee-4200-0000-7903-f712d1050000 pid=1489 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=95f640ee-4200-0000-7903-f712d1050000 pid=1489 execve guuid=b1d483ee-4200-0000-7903-f712d2050000 pid=1490 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=b1d483ee-4200-0000-7903-f712d2050000 pid=1490 execve guuid=0739bdee-4200-0000-7903-f712d3050000 pid=1491 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=0739bdee-4200-0000-7903-f712d3050000 pid=1491 execve guuid=04dcfaee-4200-0000-7903-f712d4050000 pid=1492 /usr/bin/wget net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=04dcfaee-4200-0000-7903-f712d4050000 pid=1492 execve guuid=db379cf1-4200-0000-7903-f712d5050000 pid=1493 /usr/bin/curl net guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=db379cf1-4200-0000-7903-f712d5050000 pid=1493 execve guuid=f8ae5df5-4200-0000-7903-f712d6050000 pid=1494 /usr/bin/chmod guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=f8ae5df5-4200-0000-7903-f712d6050000 pid=1494 execve guuid=ba50abf5-4200-0000-7903-f712d7050000 pid=1495 /usr/bin/dash guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=ba50abf5-4200-0000-7903-f712d7050000 pid=1495 clone guuid=e39a80f6-4200-0000-7903-f712d9050000 pid=1497 /usr/bin/rm guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=e39a80f6-4200-0000-7903-f712d9050000 pid=1497 execve guuid=d3ddc9f6-4200-0000-7903-f712da050000 pid=1498 /usr/bin/rm delete-file guuid=f1ff256c-3f00-0000-7903-f71216040000 pid=1046->guuid=d3ddc9f6-4200-0000-7903-f712da050000 pid=1498 execve 1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 185.228.26.16:80 guuid=b35e646d-3f00-0000-7903-f71219040000 pid=1049->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 138B guuid=39fa1cde-3f00-0000-7903-f71221040000 pid=1057->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 138B guuid=b2f1002b-4000-0000-7903-f71229040000 pid=1065->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B guuid=a0b70739-4000-0000-7903-f71231040000 pid=1073->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 138B guuid=b43f5c56-4000-0000-7903-f71239040000 pid=1081->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 138B guuid=99396d6a-4000-0000-7903-f71241040000 pid=1089->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 138B guuid=ec7d297b-4000-0000-7903-f71249040000 pid=1097->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B 8b0a01dc-0728-52c1-8024-c4ba7801b8d6 8.8.8.8:53 guuid=e4166e85-4000-0000-7903-f7124b040000 pid=1099->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=1d128c85-4000-0000-7903-f7124c040000 pid=1100 /home/sandbox/cron.azsxd zombie guuid=e4166e85-4000-0000-7903-f7124b040000 pid=1099->guuid=1d128c85-4000-0000-7903-f7124c040000 pid=1100 clone guuid=f8d7a285-4000-0000-7903-f7124d040000 pid=1101 /home/sandbox/cron.azsxd net send-data zombie guuid=e4166e85-4000-0000-7903-f7124b040000 pid=1099->guuid=f8d7a285-4000-0000-7903-f7124d040000 pid=1101 clone guuid=f8d7a285-4000-0000-7903-f7124d040000 pid=1101->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con 2ed7521f-dd4c-5c26-a2d7-2ef7fa36035a 185.228.26.16:63445 guuid=f8d7a285-4000-0000-7903-f7124d040000 pid=1101->2ed7521f-dd4c-5c26-a2d7-2ef7fa36035a send: 24B guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103 /home/sandbox/cron.azsxd net net-scan send-data guuid=f8d7a285-4000-0000-7903-f7124d040000 pid=1101->guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103 clone guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103|send-data send-data to 4097 IP addresses review logs to see them all guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103->guuid=9004b185-4000-0000-7903-f7124f040000 pid=1103|send-data send guuid=bd31cf87-4000-0000-7903-f71253040000 pid=1107->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B guuid=8f27a4a8-4000-0000-7903-f7125b040000 pid=1115->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B guuid=4469c7b3-4000-0000-7903-f71263040000 pid=1123->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B guuid=56496ac0-4000-0000-7903-f7126b040000 pid=1131->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 137B guuid=16d3aaea-4000-0000-7903-f71273040000 pid=1139->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 con guuid=273a10ed-4000-0000-7903-f71274040000 pid=1140->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 send: 85B guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con f3f05e9b-2e44-5d58-8711-11ca213e45b1 0.0.0.0:55625 guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142->f3f05e9b-2e44-5d58-8711-11ca213e45b1 con guuid=376d75bb-4100-0000-7903-f71277040000 pid=1143 /home/sandbox/cron.azsxd zombie guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142->guuid=376d75bb-4100-0000-7903-f71277040000 pid=1143 clone guuid=35aed0e5-4200-0000-7903-f712c2050000 pid=1474 /home/sandbox/cron.azsxd net zombie guuid=7ca05fbb-4100-0000-7903-f71276040000 pid=1142->guuid=35aed0e5-4200-0000-7903-f712c2050000 pid=1474 clone guuid=35aed0e5-4200-0000-7903-f712c2050000 pid=1474->2ed7521f-dd4c-5c26-a2d7-2ef7fa36035a con guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477 /home/sandbox/cron.azsxd net net-scan send-data guuid=35aed0e5-4200-0000-7903-f712c2050000 pid=1474->guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477 clone guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477->8b0a01dc-0728-52c1-8024-c4ba7801b8d6 con guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477|send-data send-data to 229 IP addresses review logs to see them all guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477->guuid=c375e6e5-4200-0000-7903-f712c5050000 pid=1477|send-data send guuid=556a7ce9-4200-0000-7903-f712cd050000 pid=1485->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 con guuid=04dcfaee-4200-0000-7903-f712d4050000 pid=1492->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 con guuid=db379cf1-4200-0000-7903-f712d5050000 pid=1493->1233d5c7-a9c0-5b09-ba51-a6770cc2ca80 con
Gathering data
Threat name:
Script-Shell.Trojan.Geninst
Status:
Malicious
First seen:
2026-06-02 06:41:30 UTC
File Type:
Text (Shell)
AV detection:
14 of 36 (38.89%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 8f5596aa92afb1658451983bb8c01529e97ad5bce91513dcff1e6d9317affc8d

(this sample)

  
Delivery method
Distributed via web download

Comments