MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 a464fc665f3c380c70d724b8dd20fcfaec823a40dde38314ca845410891241c1. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: a464fc665f3c380c70d724b8dd20fcfaec823a40dde38314ca845410891241c1
SHA3-384 hash: 04fcf460a36c88fa8e031a2a08b61bb2b5df0d3b0f029e0406d0442f1e5b1eafd9b907da0bf3ef2fec6e70e0f0525959
SHA1 hash: 58f74e4c86fc78d650319d74174dc9a25d77063d
MD5 hash: e7976be8a2f6dbe2ff9f39703aa7115a
humanhash: august-saturn-rugby-bakerloo
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-05-12 12:18:28 UTC
Last seen:2026-05-12 15:01:19 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTuDuYEg8kpj1udQBo/AulNXYq9DG+NjVsNXYrkJ:VuD4kNkvPiq9DGmKi2
TLSH T1BDD097E280A30170B0774C52F5C3B400720893BECC928D2EBF8321BA2E38796F8C02C4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
98
# of downloads :
3
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=1df8e7a7-1b00-0000-4c99-45f5030d0000 pid=3331 /usr/bin/sudo guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332 /tmp/sample.bin guuid=1df8e7a7-1b00-0000-4c99-45f5030d0000 pid=3331->guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332 execve guuid=db82f8ab-1b00-0000-4c99-45f5050d0000 pid=3333 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=db82f8ab-1b00-0000-4c99-45f5050d0000 pid=3333 execve guuid=db43a1ac-1b00-0000-4c99-45f5060d0000 pid=3334 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=db43a1ac-1b00-0000-4c99-45f5060d0000 pid=3334 execve guuid=7935c5d1-1b00-0000-4c99-45f5530d0000 pid=3411 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=7935c5d1-1b00-0000-4c99-45f5530d0000 pid=3411 execve guuid=3f9e3fd2-1b00-0000-4c99-45f5550d0000 pid=3413 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=3f9e3fd2-1b00-0000-4c99-45f5550d0000 pid=3413 clone guuid=33a790d3-1b00-0000-4c99-45f5590d0000 pid=3417 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=33a790d3-1b00-0000-4c99-45f5590d0000 pid=3417 execve guuid=583729d4-1b00-0000-4c99-45f55b0d0000 pid=3419 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=583729d4-1b00-0000-4c99-45f55b0d0000 pid=3419 execve guuid=a5c7e4f2-1b00-0000-4c99-45f5990d0000 pid=3481 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=a5c7e4f2-1b00-0000-4c99-45f5990d0000 pid=3481 execve guuid=aba527f3-1b00-0000-4c99-45f59c0d0000 pid=3484 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=aba527f3-1b00-0000-4c99-45f59c0d0000 pid=3484 clone guuid=23faa5f3-1b00-0000-4c99-45f59f0d0000 pid=3487 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=23faa5f3-1b00-0000-4c99-45f59f0d0000 pid=3487 execve guuid=2612f4f3-1b00-0000-4c99-45f5a10d0000 pid=3489 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=2612f4f3-1b00-0000-4c99-45f5a10d0000 pid=3489 execve guuid=6365790f-1c00-0000-4c99-45f5df0d0000 pid=3551 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=6365790f-1c00-0000-4c99-45f5df0d0000 pid=3551 execve guuid=8477c10f-1c00-0000-4c99-45f5e00d0000 pid=3552 /tmp/XDLE guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=8477c10f-1c00-0000-4c99-45f5e00d0000 pid=3552 execve guuid=9158dc0f-1c00-0000-4c99-45f5e30d0000 pid=3555 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=9158dc0f-1c00-0000-4c99-45f5e30d0000 pid=3555 execve guuid=d9eb3110-1c00-0000-4c99-45f5e50d0000 pid=3557 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=d9eb3110-1c00-0000-4c99-45f5e50d0000 pid=3557 execve guuid=ff92822d-1c00-0000-4c99-45f52d0e0000 pid=3629 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=ff92822d-1c00-0000-4c99-45f52d0e0000 pid=3629 execve guuid=202ede2d-1c00-0000-4c99-45f52f0e0000 pid=3631 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=202ede2d-1c00-0000-4c99-45f52f0e0000 pid=3631 clone guuid=55c9722e-1c00-0000-4c99-45f5330e0000 pid=3635 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=55c9722e-1c00-0000-4c99-45f5330e0000 pid=3635 execve guuid=dc7abe2e-1c00-0000-4c99-45f5350e0000 pid=3637 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=dc7abe2e-1c00-0000-4c99-45f5350e0000 pid=3637 execve guuid=a34b234c-1c00-0000-4c99-45f58d0e0000 pid=3725 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=a34b234c-1c00-0000-4c99-45f58d0e0000 pid=3725 execve guuid=faf8834c-1c00-0000-4c99-45f58e0e0000 pid=3726 /tmp/ZPFE guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=faf8834c-1c00-0000-4c99-45f58e0e0000 pid=3726 execve guuid=50c1984c-1c00-0000-4c99-45f5900e0000 pid=3728 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=50c1984c-1c00-0000-4c99-45f5900e0000 pid=3728 execve guuid=73f6de4c-1c00-0000-4c99-45f5930e0000 pid=3731 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=73f6de4c-1c00-0000-4c99-45f5930e0000 pid=3731 execve guuid=deadba6a-1c00-0000-4c99-45f5040f0000 pid=3844 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=deadba6a-1c00-0000-4c99-45f5040f0000 pid=3844 execve guuid=b307f66a-1c00-0000-4c99-45f5060f0000 pid=3846 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=b307f66a-1c00-0000-4c99-45f5060f0000 pid=3846 clone guuid=0d03ef6b-1c00-0000-4c99-45f50e0f0000 pid=3854 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=0d03ef6b-1c00-0000-4c99-45f50e0f0000 pid=3854 execve guuid=6bb44a6c-1c00-0000-4c99-45f50f0f0000 pid=3855 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=6bb44a6c-1c00-0000-4c99-45f50f0f0000 pid=3855 execve guuid=25ebdc88-1c00-0000-4c99-45f5250f0000 pid=3877 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=25ebdc88-1c00-0000-4c99-45f5250f0000 pid=3877 execve guuid=2bee4389-1c00-0000-4c99-45f5290f0000 pid=3881 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=2bee4389-1c00-0000-4c99-45f5290f0000 pid=3881 clone guuid=57750d8a-1c00-0000-4c99-45f52d0f0000 pid=3885 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=57750d8a-1c00-0000-4c99-45f52d0f0000 pid=3885 execve guuid=90e7eb8a-1c00-0000-4c99-45f52f0f0000 pid=3887 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=90e7eb8a-1c00-0000-4c99-45f52f0f0000 pid=3887 execve guuid=462c6eac-1c00-0000-4c99-45f5980f0000 pid=3992 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=462c6eac-1c00-0000-4c99-45f5980f0000 pid=3992 execve guuid=389ba6ac-1c00-0000-4c99-45f5990f0000 pid=3993 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=389ba6ac-1c00-0000-4c99-45f5990f0000 pid=3993 clone guuid=1b5b2bad-1c00-0000-4c99-45f59b0f0000 pid=3995 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=1b5b2bad-1c00-0000-4c99-45f59b0f0000 pid=3995 execve guuid=028175ad-1c00-0000-4c99-45f59d0f0000 pid=3997 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=028175ad-1c00-0000-4c99-45f59d0f0000 pid=3997 execve guuid=9be6efc3-1c00-0000-4c99-45f5f10f0000 pid=4081 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=9be6efc3-1c00-0000-4c99-45f5f10f0000 pid=4081 execve guuid=20a72ac4-1c00-0000-4c99-45f5f20f0000 pid=4082 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=20a72ac4-1c00-0000-4c99-45f5f20f0000 pid=4082 clone guuid=7cb48bc5-1c00-0000-4c99-45f5f80f0000 pid=4088 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=7cb48bc5-1c00-0000-4c99-45f5f80f0000 pid=4088 execve guuid=e5acc8c5-1c00-0000-4c99-45f5f90f0000 pid=4089 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=e5acc8c5-1c00-0000-4c99-45f5f90f0000 pid=4089 execve guuid=743f40e1-1c00-0000-4c99-45f54f100000 pid=4175 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=743f40e1-1c00-0000-4c99-45f54f100000 pid=4175 execve guuid=d0eca6e1-1c00-0000-4c99-45f551100000 pid=4177 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=d0eca6e1-1c00-0000-4c99-45f551100000 pid=4177 clone guuid=32ab44e3-1c00-0000-4c99-45f55a100000 pid=4186 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=32ab44e3-1c00-0000-4c99-45f55a100000 pid=4186 execve guuid=919c9ce3-1c00-0000-4c99-45f55c100000 pid=4188 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=919c9ce3-1c00-0000-4c99-45f55c100000 pid=4188 execve guuid=c99f85ff-1c00-0000-4c99-45f5af100000 pid=4271 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=c99f85ff-1c00-0000-4c99-45f5af100000 pid=4271 execve guuid=993ce9ff-1c00-0000-4c99-45f5b0100000 pid=4272 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=993ce9ff-1c00-0000-4c99-45f5b0100000 pid=4272 clone guuid=69f27e00-1d00-0000-4c99-45f5b4100000 pid=4276 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=69f27e00-1d00-0000-4c99-45f5b4100000 pid=4276 execve guuid=a1b3dc00-1d00-0000-4c99-45f5b8100000 pid=4280 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=a1b3dc00-1d00-0000-4c99-45f5b8100000 pid=4280 execve guuid=8c2f4620-1d00-0000-4c99-45f522110000 pid=4386 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=8c2f4620-1d00-0000-4c99-45f522110000 pid=4386 execve guuid=13f98820-1d00-0000-4c99-45f524110000 pid=4388 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=13f98820-1d00-0000-4c99-45f524110000 pid=4388 clone guuid=95e85f22-1d00-0000-4c99-45f52e110000 pid=4398 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=95e85f22-1d00-0000-4c99-45f52e110000 pid=4398 execve guuid=c0af9b22-1d00-0000-4c99-45f52f110000 pid=4399 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=c0af9b22-1d00-0000-4c99-45f52f110000 pid=4399 execve guuid=9b2a4349-1d00-0000-4c99-45f5cc110000 pid=4556 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=9b2a4349-1d00-0000-4c99-45f5cc110000 pid=4556 execve guuid=d5cf8749-1d00-0000-4c99-45f5cd110000 pid=4557 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=d5cf8749-1d00-0000-4c99-45f5cd110000 pid=4557 clone guuid=760c3f4a-1d00-0000-4c99-45f5d1110000 pid=4561 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=760c3f4a-1d00-0000-4c99-45f5d1110000 pid=4561 execve guuid=e6308b4a-1d00-0000-4c99-45f5d3110000 pid=4563 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=e6308b4a-1d00-0000-4c99-45f5d3110000 pid=4563 execve guuid=4e985666-1d00-0000-4c99-45f52b120000 pid=4651 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=4e985666-1d00-0000-4c99-45f52b120000 pid=4651 execve guuid=fdc0b466-1d00-0000-4c99-45f52d120000 pid=4653 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=fdc0b466-1d00-0000-4c99-45f52d120000 pid=4653 clone guuid=f51bed67-1d00-0000-4c99-45f533120000 pid=4659 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=f51bed67-1d00-0000-4c99-45f533120000 pid=4659 execve guuid=52502c68-1d00-0000-4c99-45f537120000 pid=4663 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=52502c68-1d00-0000-4c99-45f537120000 pid=4663 execve guuid=9cc0e187-1d00-0000-4c99-45f581120000 pid=4737 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=9cc0e187-1d00-0000-4c99-45f581120000 pid=4737 execve guuid=2fcd2a88-1d00-0000-4c99-45f582120000 pid=4738 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=2fcd2a88-1d00-0000-4c99-45f582120000 pid=4738 clone guuid=e4fd0089-1d00-0000-4c99-45f584120000 pid=4740 /usr/bin/rm guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=e4fd0089-1d00-0000-4c99-45f584120000 pid=4740 execve guuid=41ea4a89-1d00-0000-4c99-45f585120000 pid=4741 /usr/bin/wget net send-data write-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=41ea4a89-1d00-0000-4c99-45f585120000 pid=4741 execve guuid=a85950a5-1d00-0000-4c99-45f59a120000 pid=4762 /usr/bin/chmod guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=a85950a5-1d00-0000-4c99-45f59a120000 pid=4762 execve guuid=a50eaea5-1d00-0000-4c99-45f59e120000 pid=4766 /usr/bin/dash guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=a50eaea5-1d00-0000-4c99-45f59e120000 pid=4766 clone guuid=33112ba7-1d00-0000-4c99-45f5a2120000 pid=4770 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=33112ba7-1d00-0000-4c99-45f5a2120000 pid=4770 execve guuid=1cc47fa7-1d00-0000-4c99-45f5a3120000 pid=4771 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=1cc47fa7-1d00-0000-4c99-45f5a3120000 pid=4771 execve guuid=2df6bfa7-1d00-0000-4c99-45f5a5120000 pid=4773 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=2df6bfa7-1d00-0000-4c99-45f5a5120000 pid=4773 execve guuid=b26c2aa8-1d00-0000-4c99-45f5a7120000 pid=4775 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=b26c2aa8-1d00-0000-4c99-45f5a7120000 pid=4775 execve guuid=61d077a8-1d00-0000-4c99-45f5a8120000 pid=4776 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=61d077a8-1d00-0000-4c99-45f5a8120000 pid=4776 execve guuid=dc25bda8-1d00-0000-4c99-45f5aa120000 pid=4778 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=dc25bda8-1d00-0000-4c99-45f5aa120000 pid=4778 execve guuid=d18e05a9-1d00-0000-4c99-45f5ac120000 pid=4780 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=d18e05a9-1d00-0000-4c99-45f5ac120000 pid=4780 execve guuid=b5d76ca9-1d00-0000-4c99-45f5af120000 pid=4783 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=b5d76ca9-1d00-0000-4c99-45f5af120000 pid=4783 execve guuid=c82ab4a9-1d00-0000-4c99-45f5b0120000 pid=4784 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=c82ab4a9-1d00-0000-4c99-45f5b0120000 pid=4784 execve guuid=571813aa-1d00-0000-4c99-45f5b4120000 pid=4788 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=571813aa-1d00-0000-4c99-45f5b4120000 pid=4788 execve guuid=5b2b5daa-1d00-0000-4c99-45f5b6120000 pid=4790 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=5b2b5daa-1d00-0000-4c99-45f5b6120000 pid=4790 execve guuid=518298aa-1d00-0000-4c99-45f5b8120000 pid=4792 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=518298aa-1d00-0000-4c99-45f5b8120000 pid=4792 execve guuid=2d69daaa-1d00-0000-4c99-45f5ba120000 pid=4794 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=2d69daaa-1d00-0000-4c99-45f5ba120000 pid=4794 execve guuid=560535ab-1d00-0000-4c99-45f5be120000 pid=4798 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=560535ab-1d00-0000-4c99-45f5be120000 pid=4798 execve guuid=0e178eab-1d00-0000-4c99-45f5c0120000 pid=4800 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=0e178eab-1d00-0000-4c99-45f5c0120000 pid=4800 execve guuid=6ca6caab-1d00-0000-4c99-45f5c3120000 pid=4803 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=6ca6caab-1d00-0000-4c99-45f5c3120000 pid=4803 execve guuid=9d3226ac-1d00-0000-4c99-45f5c7120000 pid=4807 /usr/bin/rm delete-file guuid=6450afab-1b00-0000-4c99-45f5040d0000 pid=3332->guuid=9d3226ac-1d00-0000-4c99-45f5c7120000 pid=4807 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=db43a1ac-1b00-0000-4c99-45f5060d0000 pid=3334->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=583729d4-1b00-0000-4c99-45f55b0d0000 pid=3419->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=2612f4f3-1b00-0000-4c99-45f5a10d0000 pid=3489->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553 /tmp/XDLE net send-data write-file zombie guuid=8477c10f-1c00-0000-4c99-45f5e00d0000 pid=3552->guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 0734f5ed-e253-55cb-b667-c800d7698d2a 34.27.195.76:443 guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553->0734f5ed-e253-55cb-b667-c800d7698d2a send: 459B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=34d3db15-1c00-0000-4c99-45f5f70d0000 pid=3575 /usr/bin/uname guuid=a30dd50f-1c00-0000-4c99-45f5e10d0000 pid=3553->guuid=34d3db15-1c00-0000-4c99-45f5f70d0000 pid=3575 execve guuid=d9eb3110-1c00-0000-4c99-45f5e50d0000 pid=3557->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=dc7abe2e-1c00-0000-4c99-45f5350e0000 pid=3637->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a743914c-1c00-0000-4c99-45f58f0e0000 pid=3727 /tmp/ZPFE zombie guuid=faf8834c-1c00-0000-4c99-45f58e0e0000 pid=3726->guuid=a743914c-1c00-0000-4c99-45f58f0e0000 pid=3727 clone guuid=73f6de4c-1c00-0000-4c99-45f5930e0000 pid=3731->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=6bb44a6c-1c00-0000-4c99-45f50f0f0000 pid=3855->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=90e7eb8a-1c00-0000-4c99-45f52f0f0000 pid=3887->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=028175ad-1c00-0000-4c99-45f59d0f0000 pid=3997->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=e5acc8c5-1c00-0000-4c99-45f5f90f0000 pid=4089->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=919c9ce3-1c00-0000-4c99-45f55c100000 pid=4188->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a1b3dc00-1d00-0000-4c99-45f5b8100000 pid=4280->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=c0af9b22-1d00-0000-4c99-45f52f110000 pid=4399->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=e6308b4a-1d00-0000-4c99-45f5d3110000 pid=4563->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=52502c68-1d00-0000-4c99-45f537120000 pid=4663->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=41ea4a89-1d00-0000-4c99-45f585120000 pid=4741->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Gathering data
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh a464fc665f3c380c70d724b8dd20fcfaec823a40dde38314ca845410891241c1

(this sample)

  
Delivery method
Distributed via web download

Comments