MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 b3d4a54802ac6045fd28b492693b73f8d1c96a4b57d95ee331a58ac2a3b460a0. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 4


Intelligence 4 IOCs YARA File information Comments

SHA256 hash: b3d4a54802ac6045fd28b492693b73f8d1c96a4b57d95ee331a58ac2a3b460a0
SHA3-384 hash: c6e6f316b9fa59d2b42c20a56b164f7d716f29cba3574f6977a2a1e4ad74172b9228602a92100168c2bce5320f87267e
SHA1 hash: 63ccfe59a806899d28b50791f93223e4bfbdc101
MD5 hash: 8442044ca86f602c321b265ad8676145
humanhash: alabama-colorado-artist-asparagus
File name:infect.sh
Download: download sample
File size:2'449 bytes
First seen:2026-01-12 10:00:39 UTC
Last seen:2026-01-12 23:26:34 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 48:cS16kuWX5wRjadORjnCjQjQ7wRjcijrjqRj725Rj2w4JMt5RjD5Rjs92kJyJ3:j15mRjbRjCjQjQMRj9jrjqRj7gRj2JMN
TLSH T1C6510DCCA86EB032B1068668A441C3913A6FD8671C4A1D1CF4FEAC347F4DA18F1A96D6
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
2
# of downloads :
41
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash busybox lolbin
Result
Gathering data
Status:
terminated
Behavior Graph:
%3 guuid=33d9de38-1900-0000-26f3-6025690b0000 pid=2921 /usr/bin/sudo guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928 /tmp/sample.bin guuid=33d9de38-1900-0000-26f3-6025690b0000 pid=2921->guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928 execve guuid=6ef07c3c-1900-0000-26f3-6025710b0000 pid=2929 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=6ef07c3c-1900-0000-26f3-6025710b0000 pid=2929 execve guuid=3909033f-1900-0000-26f3-6025730b0000 pid=2931 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=3909033f-1900-0000-26f3-6025730b0000 pid=2931 execve guuid=70517144-1900-0000-26f3-60257d0b0000 pid=2941 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=70517144-1900-0000-26f3-60257d0b0000 pid=2941 execve guuid=0966b245-1900-0000-26f3-6025830b0000 pid=2947 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=0966b245-1900-0000-26f3-6025830b0000 pid=2947 execve guuid=1c266048-1900-0000-26f3-6025880b0000 pid=2952 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=1c266048-1900-0000-26f3-6025880b0000 pid=2952 execve guuid=bf6c2149-1900-0000-26f3-60258c0b0000 pid=2956 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=bf6c2149-1900-0000-26f3-60258c0b0000 pid=2956 execve guuid=f11f1d4c-1900-0000-26f3-6025910b0000 pid=2961 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=f11f1d4c-1900-0000-26f3-6025910b0000 pid=2961 execve guuid=e45ad14c-1900-0000-26f3-6025940b0000 pid=2964 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=e45ad14c-1900-0000-26f3-6025940b0000 pid=2964 execve guuid=1699024f-1900-0000-26f3-60259a0b0000 pid=2970 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=1699024f-1900-0000-26f3-60259a0b0000 pid=2970 execve guuid=fe84c14f-1900-0000-26f3-60259d0b0000 pid=2973 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=fe84c14f-1900-0000-26f3-60259d0b0000 pid=2973 execve guuid=96cc2f53-1900-0000-26f3-6025a50b0000 pid=2981 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=96cc2f53-1900-0000-26f3-6025a50b0000 pid=2981 execve guuid=2cf81b54-1900-0000-26f3-6025a90b0000 pid=2985 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=2cf81b54-1900-0000-26f3-6025a90b0000 pid=2985 execve guuid=62836d57-1900-0000-26f3-6025b20b0000 pid=2994 /usr/bin/killall guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=62836d57-1900-0000-26f3-6025b20b0000 pid=2994 execve guuid=4eaea058-1900-0000-26f3-6025b40b0000 pid=2996 /usr/bin/pgrep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=4eaea058-1900-0000-26f3-6025b40b0000 pid=2996 execve guuid=4560215c-1900-0000-26f3-6025bf0b0000 pid=3007 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=4560215c-1900-0000-26f3-6025bf0b0000 pid=3007 clone guuid=9d48065d-1900-0000-26f3-6025c40b0000 pid=3012 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=9d48065d-1900-0000-26f3-6025c40b0000 pid=3012 clone guuid=db090e5d-1900-0000-26f3-6025c50b0000 pid=3013 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=db090e5d-1900-0000-26f3-6025c50b0000 pid=3013 clone guuid=8540485f-1900-0000-26f3-6025d10b0000 pid=3025 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=8540485f-1900-0000-26f3-6025d10b0000 pid=3025 clone guuid=6ecc525f-1900-0000-26f3-6025d20b0000 pid=3026 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=6ecc525f-1900-0000-26f3-6025d20b0000 pid=3026 clone guuid=861fbc60-1900-0000-26f3-6025da0b0000 pid=3034 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=861fbc60-1900-0000-26f3-6025da0b0000 pid=3034 clone guuid=f9aac760-1900-0000-26f3-6025db0b0000 pid=3035 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=f9aac760-1900-0000-26f3-6025db0b0000 pid=3035 clone guuid=b21a0c62-1900-0000-26f3-6025e10b0000 pid=3041 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=b21a0c62-1900-0000-26f3-6025e10b0000 pid=3041 clone guuid=ceff2062-1900-0000-26f3-6025e20b0000 pid=3042 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=ceff2062-1900-0000-26f3-6025e20b0000 pid=3042 clone guuid=6b09d563-1900-0000-26f3-6025e80b0000 pid=3048 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=6b09d563-1900-0000-26f3-6025e80b0000 pid=3048 clone guuid=0a74dc63-1900-0000-26f3-6025e90b0000 pid=3049 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=0a74dc63-1900-0000-26f3-6025e90b0000 pid=3049 clone guuid=0ff90e66-1900-0000-26f3-6025f30b0000 pid=3059 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=0ff90e66-1900-0000-26f3-6025f30b0000 pid=3059 clone guuid=8a071a66-1900-0000-26f3-6025f40b0000 pid=3060 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=8a071a66-1900-0000-26f3-6025f40b0000 pid=3060 clone guuid=a2e21a68-1900-0000-26f3-6025fe0b0000 pid=3070 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=a2e21a68-1900-0000-26f3-6025fe0b0000 pid=3070 clone guuid=26b12468-1900-0000-26f3-6025ff0b0000 pid=3071 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=26b12468-1900-0000-26f3-6025ff0b0000 pid=3071 clone guuid=d3d1146a-1900-0000-26f3-6025080c0000 pid=3080 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=d3d1146a-1900-0000-26f3-6025080c0000 pid=3080 clone guuid=f868216a-1900-0000-26f3-6025090c0000 pid=3081 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=f868216a-1900-0000-26f3-6025090c0000 pid=3081 clone guuid=cae8da6b-1900-0000-26f3-6025110c0000 pid=3089 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=cae8da6b-1900-0000-26f3-6025110c0000 pid=3089 clone guuid=9afff76b-1900-0000-26f3-6025120c0000 pid=3090 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=9afff76b-1900-0000-26f3-6025120c0000 pid=3090 clone guuid=1e7fe06e-1900-0000-26f3-60251b0c0000 pid=3099 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=1e7fe06e-1900-0000-26f3-60251b0c0000 pid=3099 clone guuid=f17cea6e-1900-0000-26f3-60251c0c0000 pid=3100 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=f17cea6e-1900-0000-26f3-60251c0c0000 pid=3100 clone guuid=d27d2971-1900-0000-26f3-6025250c0000 pid=3109 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=d27d2971-1900-0000-26f3-6025250c0000 pid=3109 clone guuid=3d793371-1900-0000-26f3-6025260c0000 pid=3110 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=3d793371-1900-0000-26f3-6025260c0000 pid=3110 clone guuid=56f53072-1900-0000-26f3-60252d0c0000 pid=3117 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=56f53072-1900-0000-26f3-60252d0c0000 pid=3117 clone guuid=98bd3c72-1900-0000-26f3-60252e0c0000 pid=3118 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=98bd3c72-1900-0000-26f3-60252e0c0000 pid=3118 clone guuid=85a74775-1900-0000-26f3-6025380c0000 pid=3128 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=85a74775-1900-0000-26f3-6025380c0000 pid=3128 clone guuid=b1036275-1900-0000-26f3-6025390c0000 pid=3129 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=b1036275-1900-0000-26f3-6025390c0000 pid=3129 clone guuid=850ba176-1900-0000-26f3-6025410c0000 pid=3137 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=850ba176-1900-0000-26f3-6025410c0000 pid=3137 clone guuid=62b5aa76-1900-0000-26f3-6025420c0000 pid=3138 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=62b5aa76-1900-0000-26f3-6025420c0000 pid=3138 clone guuid=e7c62a79-1900-0000-26f3-60254d0c0000 pid=3149 /usr/bin/bash guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=e7c62a79-1900-0000-26f3-60254d0c0000 pid=3149 clone guuid=52723679-1900-0000-26f3-60254e0c0000 pid=3150 /usr/bin/sleep guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=52723679-1900-0000-26f3-60254e0c0000 pid=3150 execve guuid=64b14af1-1900-0000-26f3-6025fc0c0000 pid=3324 /usr/bin/rm guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=64b14af1-1900-0000-26f3-6025fc0c0000 pid=3324 execve guuid=834aaaf1-1900-0000-26f3-6025fe0c0000 pid=3326 /usr/bin/rm guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=834aaaf1-1900-0000-26f3-6025fe0c0000 pid=3326 execve guuid=833a08f2-1900-0000-26f3-6025000d0000 pid=3328 /usr/bin/cat guuid=e6e0153c-1900-0000-26f3-6025700b0000 pid=2928->guuid=833a08f2-1900-0000-26f3-6025000d0000 pid=3328 execve guuid=b2b7345c-1900-0000-26f3-6025c00b0000 pid=3008 /usr/bin/cat guuid=4560215c-1900-0000-26f3-6025bf0b0000 pid=3007->guuid=b2b7345c-1900-0000-26f3-6025c00b0000 pid=3008 execve guuid=87d33b5c-1900-0000-26f3-6025c10b0000 pid=3009 /usr/bin/tr guuid=4560215c-1900-0000-26f3-6025bf0b0000 pid=3007->guuid=87d33b5c-1900-0000-26f3-6025c10b0000 pid=3009 execve guuid=c4da425c-1900-0000-26f3-6025c20b0000 pid=3010 /usr/bin/head guuid=4560215c-1900-0000-26f3-6025bf0b0000 pid=3007->guuid=c4da425c-1900-0000-26f3-6025c20b0000 pid=3010 execve guuid=ff6a165d-1900-0000-26f3-6025c60b0000 pid=3014 /usr/bin/wget guuid=9d48065d-1900-0000-26f3-6025c40b0000 pid=3012->guuid=ff6a165d-1900-0000-26f3-6025c60b0000 pid=3014 execve guuid=e40a1c5d-1900-0000-26f3-6025c70b0000 pid=3015 /usr/bin/cat guuid=db090e5d-1900-0000-26f3-6025c50b0000 pid=3013->guuid=e40a1c5d-1900-0000-26f3-6025c70b0000 pid=3015 execve guuid=c7fc325d-1900-0000-26f3-6025c80b0000 pid=3016 /usr/bin/tr guuid=db090e5d-1900-0000-26f3-6025c50b0000 pid=3013->guuid=c7fc325d-1900-0000-26f3-6025c80b0000 pid=3016 execve guuid=8852595d-1900-0000-26f3-6025c90b0000 pid=3017 /usr/bin/head guuid=db090e5d-1900-0000-26f3-6025c50b0000 pid=3013->guuid=8852595d-1900-0000-26f3-6025c90b0000 pid=3017 execve guuid=3fed925f-1900-0000-26f3-6025d60b0000 pid=3030 /usr/bin/wget guuid=8540485f-1900-0000-26f3-6025d10b0000 pid=3025->guuid=3fed925f-1900-0000-26f3-6025d60b0000 pid=3030 execve guuid=6c4b625f-1900-0000-26f3-6025d30b0000 pid=3027 /usr/bin/cat guuid=6ecc525f-1900-0000-26f3-6025d20b0000 pid=3026->guuid=6c4b625f-1900-0000-26f3-6025d30b0000 pid=3027 execve guuid=762b6e5f-1900-0000-26f3-6025d40b0000 pid=3028 /usr/bin/tr guuid=6ecc525f-1900-0000-26f3-6025d20b0000 pid=3026->guuid=762b6e5f-1900-0000-26f3-6025d40b0000 pid=3028 execve guuid=8af7755f-1900-0000-26f3-6025d50b0000 pid=3029 /usr/bin/head guuid=6ecc525f-1900-0000-26f3-6025d20b0000 pid=3026->guuid=8af7755f-1900-0000-26f3-6025d50b0000 pid=3029 execve guuid=4088cf60-1900-0000-26f3-6025dc0b0000 pid=3036 /usr/bin/wget net send-data write-file guuid=861fbc60-1900-0000-26f3-6025da0b0000 pid=3034->guuid=4088cf60-1900-0000-26f3-6025dc0b0000 pid=3036 execve guuid=ea2dd560-1900-0000-26f3-6025dd0b0000 pid=3037 /usr/bin/cat guuid=f9aac760-1900-0000-26f3-6025db0b0000 pid=3035->guuid=ea2dd560-1900-0000-26f3-6025dd0b0000 pid=3037 execve guuid=3935dd60-1900-0000-26f3-6025de0b0000 pid=3038 /usr/bin/tr guuid=f9aac760-1900-0000-26f3-6025db0b0000 pid=3035->guuid=3935dd60-1900-0000-26f3-6025de0b0000 pid=3038 execve guuid=c2d5e560-1900-0000-26f3-6025df0b0000 pid=3039 /usr/bin/head guuid=f9aac760-1900-0000-26f3-6025db0b0000 pid=3035->guuid=c2d5e560-1900-0000-26f3-6025df0b0000 pid=3039 execve 3dfa287e-9a81-5d6e-9241-a6532d2ede50 87.121.84.45:80 guuid=4088cf60-1900-0000-26f3-6025dc0b0000 pid=3036->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 139B guuid=02f02662-1900-0000-26f3-6025e30b0000 pid=3043 /usr/bin/wget net send-data guuid=b21a0c62-1900-0000-26f3-6025e10b0000 pid=3041->guuid=02f02662-1900-0000-26f3-6025e30b0000 pid=3043 execve guuid=b8e33562-1900-0000-26f3-6025e40b0000 pid=3044 /usr/bin/cat guuid=ceff2062-1900-0000-26f3-6025e20b0000 pid=3042->guuid=b8e33562-1900-0000-26f3-6025e40b0000 pid=3044 execve guuid=32974062-1900-0000-26f3-6025e50b0000 pid=3045 /usr/bin/tr guuid=ceff2062-1900-0000-26f3-6025e20b0000 pid=3042->guuid=32974062-1900-0000-26f3-6025e50b0000 pid=3045 execve guuid=13dc4962-1900-0000-26f3-6025e60b0000 pid=3046 /usr/bin/head guuid=ceff2062-1900-0000-26f3-6025e20b0000 pid=3042->guuid=13dc4962-1900-0000-26f3-6025e60b0000 pid=3046 execve guuid=02f02662-1900-0000-26f3-6025e30b0000 pid=3043->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 138B guuid=971f0a64-1900-0000-26f3-6025ed0b0000 pid=3053 /usr/bin/wget net send-data guuid=6b09d563-1900-0000-26f3-6025e80b0000 pid=3048->guuid=971f0a64-1900-0000-26f3-6025ed0b0000 pid=3053 execve guuid=3193e963-1900-0000-26f3-6025ea0b0000 pid=3050 /usr/bin/cat guuid=0a74dc63-1900-0000-26f3-6025e90b0000 pid=3049->guuid=3193e963-1900-0000-26f3-6025ea0b0000 pid=3050 execve guuid=064ff063-1900-0000-26f3-6025eb0b0000 pid=3051 /usr/bin/tr guuid=0a74dc63-1900-0000-26f3-6025e90b0000 pid=3049->guuid=064ff063-1900-0000-26f3-6025eb0b0000 pid=3051 execve guuid=5925f663-1900-0000-26f3-6025ec0b0000 pid=3052 /usr/bin/head guuid=0a74dc63-1900-0000-26f3-6025e90b0000 pid=3049->guuid=5925f663-1900-0000-26f3-6025ec0b0000 pid=3052 execve guuid=971f0a64-1900-0000-26f3-6025ed0b0000 pid=3053->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 137B guuid=4fcc1b66-1900-0000-26f3-6025f50b0000 pid=3061 /usr/bin/wget net send-data guuid=0ff90e66-1900-0000-26f3-6025f30b0000 pid=3059->guuid=4fcc1b66-1900-0000-26f3-6025f50b0000 pid=3061 execve guuid=1baf2b66-1900-0000-26f3-6025f70b0000 pid=3063 /usr/bin/cat guuid=8a071a66-1900-0000-26f3-6025f40b0000 pid=3060->guuid=1baf2b66-1900-0000-26f3-6025f70b0000 pid=3063 execve guuid=fef73b66-1900-0000-26f3-6025f80b0000 pid=3064 /usr/bin/tr guuid=8a071a66-1900-0000-26f3-6025f40b0000 pid=3060->guuid=fef73b66-1900-0000-26f3-6025f80b0000 pid=3064 execve guuid=99e56e66-1900-0000-26f3-6025f90b0000 pid=3065 /usr/bin/head guuid=8a071a66-1900-0000-26f3-6025f40b0000 pid=3060->guuid=99e56e66-1900-0000-26f3-6025f90b0000 pid=3065 execve guuid=4fcc1b66-1900-0000-26f3-6025f50b0000 pid=3061->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 138B guuid=28062a68-1900-0000-26f3-6025000c0000 pid=3072 /usr/bin/wget guuid=a2e21a68-1900-0000-26f3-6025fe0b0000 pid=3070->guuid=28062a68-1900-0000-26f3-6025000c0000 pid=3072 execve guuid=80ac3368-1900-0000-26f3-6025010c0000 pid=3073 /usr/bin/cat guuid=26b12468-1900-0000-26f3-6025ff0b0000 pid=3071->guuid=80ac3368-1900-0000-26f3-6025010c0000 pid=3073 execve guuid=dacc5468-1900-0000-26f3-6025030c0000 pid=3075 /usr/bin/tr guuid=26b12468-1900-0000-26f3-6025ff0b0000 pid=3071->guuid=dacc5468-1900-0000-26f3-6025030c0000 pid=3075 execve guuid=ba4e8068-1900-0000-26f3-6025040c0000 pid=3076 /usr/bin/head guuid=26b12468-1900-0000-26f3-6025ff0b0000 pid=3071->guuid=ba4e8068-1900-0000-26f3-6025040c0000 pid=3076 execve guuid=2aa9596a-1900-0000-26f3-60250e0c0000 pid=3086 /usr/bin/wget guuid=d3d1146a-1900-0000-26f3-6025080c0000 pid=3080->guuid=2aa9596a-1900-0000-26f3-60250e0c0000 pid=3086 execve guuid=cdf02c6a-1900-0000-26f3-60250a0c0000 pid=3082 /usr/bin/cat guuid=f868216a-1900-0000-26f3-6025090c0000 pid=3081->guuid=cdf02c6a-1900-0000-26f3-60250a0c0000 pid=3082 execve guuid=7dfa376a-1900-0000-26f3-60250c0c0000 pid=3084 /usr/bin/tr guuid=f868216a-1900-0000-26f3-6025090c0000 pid=3081->guuid=7dfa376a-1900-0000-26f3-60250c0c0000 pid=3084 execve guuid=e9773f6a-1900-0000-26f3-60250d0c0000 pid=3085 /usr/bin/head guuid=f868216a-1900-0000-26f3-6025090c0000 pid=3081->guuid=e9773f6a-1900-0000-26f3-60250d0c0000 pid=3085 execve guuid=52a4f96b-1900-0000-26f3-6025130c0000 pid=3091 /usr/bin/wget net send-data guuid=cae8da6b-1900-0000-26f3-6025110c0000 pid=3089->guuid=52a4f96b-1900-0000-26f3-6025130c0000 pid=3091 execve guuid=8acde86c-1900-0000-26f3-6025160c0000 pid=3094 /usr/bin/cat guuid=9afff76b-1900-0000-26f3-6025120c0000 pid=3090->guuid=8acde86c-1900-0000-26f3-6025160c0000 pid=3094 execve guuid=bde3896d-1900-0000-26f3-6025170c0000 pid=3095 /usr/bin/tr guuid=9afff76b-1900-0000-26f3-6025120c0000 pid=3090->guuid=bde3896d-1900-0000-26f3-6025170c0000 pid=3095 execve guuid=8135bc6d-1900-0000-26f3-6025180c0000 pid=3096 /usr/bin/head guuid=9afff76b-1900-0000-26f3-6025120c0000 pid=3090->guuid=8135bc6d-1900-0000-26f3-6025180c0000 pid=3096 execve guuid=52a4f96b-1900-0000-26f3-6025130c0000 pid=3091->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 140B guuid=c6f1ee6e-1900-0000-26f3-60251d0c0000 pid=3101 /usr/bin/wget guuid=1e7fe06e-1900-0000-26f3-60251b0c0000 pid=3099->guuid=c6f1ee6e-1900-0000-26f3-60251d0c0000 pid=3101 execve guuid=6ccff66e-1900-0000-26f3-60251e0c0000 pid=3102 /usr/bin/cat guuid=f17cea6e-1900-0000-26f3-60251c0c0000 pid=3100->guuid=6ccff66e-1900-0000-26f3-60251e0c0000 pid=3102 execve guuid=73df286f-1900-0000-26f3-60251f0c0000 pid=3103 /usr/bin/tr guuid=f17cea6e-1900-0000-26f3-60251c0c0000 pid=3100->guuid=73df286f-1900-0000-26f3-60251f0c0000 pid=3103 execve guuid=6035616f-1900-0000-26f3-6025200c0000 pid=3104 /usr/bin/head guuid=f17cea6e-1900-0000-26f3-60251c0c0000 pid=3100->guuid=6035616f-1900-0000-26f3-6025200c0000 pid=3104 execve guuid=c6716d71-1900-0000-26f3-60252b0c0000 pid=3115 /usr/bin/wget guuid=d27d2971-1900-0000-26f3-6025250c0000 pid=3109->guuid=c6716d71-1900-0000-26f3-60252b0c0000 pid=3115 execve guuid=bbe34071-1900-0000-26f3-6025270c0000 pid=3111 /usr/bin/cat guuid=3d793371-1900-0000-26f3-6025260c0000 pid=3110->guuid=bbe34071-1900-0000-26f3-6025270c0000 pid=3111 execve guuid=49f14971-1900-0000-26f3-6025280c0000 pid=3112 /usr/bin/tr guuid=3d793371-1900-0000-26f3-6025260c0000 pid=3110->guuid=49f14971-1900-0000-26f3-6025280c0000 pid=3112 execve guuid=d8c74e71-1900-0000-26f3-6025290c0000 pid=3113 /usr/bin/head guuid=3d793371-1900-0000-26f3-6025260c0000 pid=3110->guuid=d8c74e71-1900-0000-26f3-6025290c0000 pid=3113 execve guuid=974f6472-1900-0000-26f3-6025320c0000 pid=3122 /usr/bin/wget send-data guuid=56f53072-1900-0000-26f3-60252d0c0000 pid=3117->guuid=974f6472-1900-0000-26f3-6025320c0000 pid=3122 execve guuid=deea4572-1900-0000-26f3-60252f0c0000 pid=3119 /usr/bin/cat guuid=98bd3c72-1900-0000-26f3-60252e0c0000 pid=3118->guuid=deea4572-1900-0000-26f3-60252f0c0000 pid=3119 execve guuid=cfcc4b72-1900-0000-26f3-6025300c0000 pid=3120 /usr/bin/tr guuid=98bd3c72-1900-0000-26f3-60252e0c0000 pid=3118->guuid=cfcc4b72-1900-0000-26f3-6025300c0000 pid=3120 execve guuid=851a5472-1900-0000-26f3-6025310c0000 pid=3121 /usr/bin/head guuid=98bd3c72-1900-0000-26f3-60252e0c0000 pid=3118->guuid=851a5472-1900-0000-26f3-6025310c0000 pid=3121 execve guuid=974f6472-1900-0000-26f3-6025320c0000 pid=3122->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 143B guuid=4e95b775-1900-0000-26f3-60253e0c0000 pid=3134 /usr/bin/wget send-data guuid=85a74775-1900-0000-26f3-6025380c0000 pid=3128->guuid=4e95b775-1900-0000-26f3-60253e0c0000 pid=3134 execve guuid=3d958475-1900-0000-26f3-60253a0c0000 pid=3130 /usr/bin/cat guuid=b1036275-1900-0000-26f3-6025390c0000 pid=3129->guuid=3d958475-1900-0000-26f3-60253a0c0000 pid=3130 execve guuid=00a58e75-1900-0000-26f3-60253b0c0000 pid=3131 /usr/bin/tr guuid=b1036275-1900-0000-26f3-6025390c0000 pid=3129->guuid=00a58e75-1900-0000-26f3-60253b0c0000 pid=3131 execve guuid=c2999d75-1900-0000-26f3-60253d0c0000 pid=3133 /usr/bin/head guuid=b1036275-1900-0000-26f3-6025390c0000 pid=3129->guuid=c2999d75-1900-0000-26f3-60253d0c0000 pid=3133 execve guuid=4e95b775-1900-0000-26f3-60253e0c0000 pid=3134->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 141B guuid=ab71d376-1900-0000-26f3-6025460c0000 pid=3142 /usr/bin/wget guuid=850ba176-1900-0000-26f3-6025410c0000 pid=3137->guuid=ab71d376-1900-0000-26f3-6025460c0000 pid=3142 execve guuid=d7f1b776-1900-0000-26f3-6025430c0000 pid=3139 /usr/bin/cat guuid=62b5aa76-1900-0000-26f3-6025420c0000 pid=3138->guuid=d7f1b776-1900-0000-26f3-6025430c0000 pid=3139 execve guuid=a490bc76-1900-0000-26f3-6025440c0000 pid=3140 /usr/bin/tr guuid=62b5aa76-1900-0000-26f3-6025420c0000 pid=3138->guuid=a490bc76-1900-0000-26f3-6025440c0000 pid=3140 execve guuid=23d0c376-1900-0000-26f3-6025450c0000 pid=3141 /usr/bin/head guuid=62b5aa76-1900-0000-26f3-6025420c0000 pid=3138->guuid=23d0c376-1900-0000-26f3-6025450c0000 pid=3141 execve guuid=d4369479-1900-0000-26f3-6025500c0000 pid=3152 /usr/bin/wget send-data guuid=e7c62a79-1900-0000-26f3-60254d0c0000 pid=3149->guuid=d4369479-1900-0000-26f3-6025500c0000 pid=3152 execve guuid=d4369479-1900-0000-26f3-6025500c0000 pid=3152->3dfa287e-9a81-5d6e-9241-a6532d2ede50 send: 139B
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Reads CPU attributes
Enumerates running processes
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh b3d4a54802ac6045fd28b492693b73f8d1c96a4b57d95ee331a58ac2a3b460a0

(this sample)

  
Delivery method
Distributed via web download

Comments