MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 bca3e5ca3be21f841fb6f5e1bd8c0bac3850a68cdd517059783978f879b5e669. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: bca3e5ca3be21f841fb6f5e1bd8c0bac3850a68cdd517059783978f879b5e669
SHA3-384 hash: 9e6fc3c63cc7e41823d6ca14cf126b7b923f053ffbc01d59359d65f058d6ec2223c68693896a4e9c6d44ca2abd651412
SHA1 hash: 1f94f56c37691f19ca57090f93a5ff764533baf9
MD5 hash: 35ade1b85d2f4a3563622625c1af0862
humanhash: king-comet-uniform-mango
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-06-27 00:19:15 UTC
Last seen:2026-06-27 21:00:12 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTCYUDtvqu6teuFAulNXYq9DG+NjVsNXYrkJ:VCpvq64Piq9DGmKi2
TLSH T1CED05EA2A57312F420669914F2A2A800B115876E4C8A865DBA4B38B45E8834AF1D16D2
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
2
# of downloads :
65
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
downloader
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-26T21:26:00Z UTC
Last seen:
2026-06-26T23:55:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=a7068a19-1900-0000-ade9-699124140000 pid=5156 /usr/bin/sudo guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157 /tmp/sample.bin guuid=a7068a19-1900-0000-ade9-699124140000 pid=5156->guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157 execve guuid=fcde161d-1900-0000-ade9-699126140000 pid=5158 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=fcde161d-1900-0000-ade9-699126140000 pid=5158 execve guuid=e1ccbc1d-1900-0000-ade9-699127140000 pid=5159 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=e1ccbc1d-1900-0000-ade9-699127140000 pid=5159 execve guuid=9715283b-1900-0000-ade9-699128140000 pid=5160 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=9715283b-1900-0000-ade9-699128140000 pid=5160 execve guuid=0733773b-1900-0000-ade9-699129140000 pid=5161 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=0733773b-1900-0000-ade9-699129140000 pid=5161 clone guuid=9ade7f3d-1900-0000-ade9-69912b140000 pid=5163 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=9ade7f3d-1900-0000-ade9-69912b140000 pid=5163 execve guuid=41c1e53d-1900-0000-ade9-69912c140000 pid=5164 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=41c1e53d-1900-0000-ade9-69912c140000 pid=5164 execve guuid=3b099959-1900-0000-ade9-69912d140000 pid=5165 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=3b099959-1900-0000-ade9-69912d140000 pid=5165 execve guuid=89bbf659-1900-0000-ade9-69912e140000 pid=5166 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=89bbf659-1900-0000-ade9-69912e140000 pid=5166 clone guuid=e4d8d85a-1900-0000-ade9-699130140000 pid=5168 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=e4d8d85a-1900-0000-ade9-699130140000 pid=5168 execve guuid=3317425b-1900-0000-ade9-699131140000 pid=5169 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=3317425b-1900-0000-ade9-699131140000 pid=5169 execve guuid=cdbc7576-1900-0000-ade9-699132140000 pid=5170 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=cdbc7576-1900-0000-ade9-699132140000 pid=5170 execve guuid=d737c076-1900-0000-ade9-699133140000 pid=5171 /tmp/BRCC guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d737c076-1900-0000-ade9-699133140000 pid=5171 execve guuid=5ae7dc76-1900-0000-ade9-699135140000 pid=5173 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=5ae7dc76-1900-0000-ade9-699135140000 pid=5173 execve guuid=32412677-1900-0000-ade9-699136140000 pid=5174 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=32412677-1900-0000-ade9-699136140000 pid=5174 execve guuid=c96ef992-1900-0000-ade9-699137140000 pid=5175 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=c96ef992-1900-0000-ade9-699137140000 pid=5175 execve guuid=a01e4893-1900-0000-ade9-699138140000 pid=5176 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=a01e4893-1900-0000-ade9-699138140000 pid=5176 clone guuid=01a4b394-1900-0000-ade9-69913a140000 pid=5178 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=01a4b394-1900-0000-ade9-69913a140000 pid=5178 execve guuid=66f5f994-1900-0000-ade9-69913b140000 pid=5179 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=66f5f994-1900-0000-ade9-69913b140000 pid=5179 execve guuid=a14ec3af-1900-0000-ade9-69913c140000 pid=5180 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=a14ec3af-1900-0000-ade9-69913c140000 pid=5180 execve guuid=051708b0-1900-0000-ade9-69913d140000 pid=5181 /tmp/RWHO guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=051708b0-1900-0000-ade9-69913d140000 pid=5181 execve guuid=78b721b0-1900-0000-ade9-69913f140000 pid=5183 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=78b721b0-1900-0000-ade9-69913f140000 pid=5183 execve guuid=0d4867b0-1900-0000-ade9-699140140000 pid=5184 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=0d4867b0-1900-0000-ade9-699140140000 pid=5184 execve guuid=1da0dfcc-1900-0000-ade9-699142140000 pid=5186 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=1da0dfcc-1900-0000-ade9-699142140000 pid=5186 execve guuid=ab0625cd-1900-0000-ade9-699143140000 pid=5187 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=ab0625cd-1900-0000-ade9-699143140000 pid=5187 clone guuid=1c91b7cd-1900-0000-ade9-699145140000 pid=5189 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=1c91b7cd-1900-0000-ade9-699145140000 pid=5189 execve guuid=836700ce-1900-0000-ade9-699146140000 pid=5190 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=836700ce-1900-0000-ade9-699146140000 pid=5190 execve guuid=cf5a7de9-1900-0000-ade9-69914e140000 pid=5198 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=cf5a7de9-1900-0000-ade9-69914e140000 pid=5198 execve guuid=7a0acfe9-1900-0000-ade9-69914f140000 pid=5199 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=7a0acfe9-1900-0000-ade9-69914f140000 pid=5199 clone guuid=f04196ea-1900-0000-ade9-699151140000 pid=5201 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f04196ea-1900-0000-ade9-699151140000 pid=5201 execve guuid=d7b3e7ea-1900-0000-ade9-699152140000 pid=5202 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d7b3e7ea-1900-0000-ade9-699152140000 pid=5202 execve guuid=86273106-1a00-0000-ade9-699153140000 pid=5203 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=86273106-1a00-0000-ade9-699153140000 pid=5203 execve guuid=27dbcf06-1a00-0000-ade9-699154140000 pid=5204 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=27dbcf06-1a00-0000-ade9-699154140000 pid=5204 clone guuid=f811a108-1a00-0000-ade9-699156140000 pid=5206 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f811a108-1a00-0000-ade9-699156140000 pid=5206 execve guuid=08f70309-1a00-0000-ade9-699157140000 pid=5207 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=08f70309-1a00-0000-ade9-699157140000 pid=5207 execve guuid=714e2e23-1a00-0000-ade9-699158140000 pid=5208 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=714e2e23-1a00-0000-ade9-699158140000 pid=5208 execve guuid=da208a23-1a00-0000-ade9-699159140000 pid=5209 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=da208a23-1a00-0000-ade9-699159140000 pid=5209 clone guuid=305f4d26-1a00-0000-ade9-69915b140000 pid=5211 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=305f4d26-1a00-0000-ade9-69915b140000 pid=5211 execve guuid=ace9bf26-1a00-0000-ade9-69915c140000 pid=5212 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=ace9bf26-1a00-0000-ade9-69915c140000 pid=5212 execve guuid=d4465545-1a00-0000-ade9-69915d140000 pid=5213 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d4465545-1a00-0000-ade9-69915d140000 pid=5213 execve guuid=d0524b4b-1a00-0000-ade9-69915e140000 pid=5214 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d0524b4b-1a00-0000-ade9-69915e140000 pid=5214 clone guuid=95afe151-1a00-0000-ade9-699160140000 pid=5216 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=95afe151-1a00-0000-ade9-699160140000 pid=5216 execve guuid=b5b18552-1a00-0000-ade9-699161140000 pid=5217 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=b5b18552-1a00-0000-ade9-699161140000 pid=5217 execve guuid=c1dcd873-1a00-0000-ade9-699162140000 pid=5218 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=c1dcd873-1a00-0000-ade9-699162140000 pid=5218 execve guuid=304fdf77-1a00-0000-ade9-699163140000 pid=5219 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=304fdf77-1a00-0000-ade9-699163140000 pid=5219 clone guuid=8e0fd378-1a00-0000-ade9-699165140000 pid=5221 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=8e0fd378-1a00-0000-ade9-699165140000 pid=5221 execve guuid=cf725d7a-1a00-0000-ade9-699166140000 pid=5222 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=cf725d7a-1a00-0000-ade9-699166140000 pid=5222 execve guuid=eca5659a-1a00-0000-ade9-699167140000 pid=5223 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=eca5659a-1a00-0000-ade9-699167140000 pid=5223 execve guuid=b214a79a-1a00-0000-ade9-699168140000 pid=5224 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=b214a79a-1a00-0000-ade9-699168140000 pid=5224 clone guuid=e6573a9b-1a00-0000-ade9-69916a140000 pid=5226 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=e6573a9b-1a00-0000-ade9-69916a140000 pid=5226 execve guuid=c559969b-1a00-0000-ade9-69916b140000 pid=5227 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=c559969b-1a00-0000-ade9-69916b140000 pid=5227 execve guuid=436bd2b6-1a00-0000-ade9-69916c140000 pid=5228 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=436bd2b6-1a00-0000-ade9-69916c140000 pid=5228 execve guuid=c9440eb7-1a00-0000-ade9-69916d140000 pid=5229 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=c9440eb7-1a00-0000-ade9-69916d140000 pid=5229 clone guuid=d4cf93b7-1a00-0000-ade9-69916f140000 pid=5231 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d4cf93b7-1a00-0000-ade9-69916f140000 pid=5231 execve guuid=29cfd3b7-1a00-0000-ade9-699170140000 pid=5232 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=29cfd3b7-1a00-0000-ade9-699170140000 pid=5232 execve guuid=8a9e5ddc-1a00-0000-ade9-699177140000 pid=5239 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=8a9e5ddc-1a00-0000-ade9-699177140000 pid=5239 execve guuid=2db2dadc-1a00-0000-ade9-699178140000 pid=5240 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=2db2dadc-1a00-0000-ade9-699178140000 pid=5240 clone guuid=a56781de-1a00-0000-ade9-69917a140000 pid=5242 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=a56781de-1a00-0000-ade9-69917a140000 pid=5242 execve guuid=0c340ddf-1a00-0000-ade9-69917b140000 pid=5243 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=0c340ddf-1a00-0000-ade9-69917b140000 pid=5243 execve guuid=b305c3fa-1a00-0000-ade9-699184140000 pid=5252 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=b305c3fa-1a00-0000-ade9-699184140000 pid=5252 execve guuid=f15404fb-1a00-0000-ade9-699185140000 pid=5253 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f15404fb-1a00-0000-ade9-699185140000 pid=5253 clone guuid=e4198efb-1a00-0000-ade9-699187140000 pid=5255 /usr/bin/rm guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=e4198efb-1a00-0000-ade9-699187140000 pid=5255 execve guuid=d05acffb-1a00-0000-ade9-699189140000 pid=5257 /usr/bin/wget net send-data write-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=d05acffb-1a00-0000-ade9-699189140000 pid=5257 execve guuid=ede01217-1b00-0000-ade9-699195140000 pid=5269 /usr/bin/chmod guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=ede01217-1b00-0000-ade9-699195140000 pid=5269 execve guuid=f2437c17-1b00-0000-ade9-699196140000 pid=5270 /usr/bin/dash guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f2437c17-1b00-0000-ade9-699196140000 pid=5270 clone guuid=12dc3918-1b00-0000-ade9-699199140000 pid=5273 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=12dc3918-1b00-0000-ade9-699199140000 pid=5273 execve guuid=33859818-1b00-0000-ade9-69919b140000 pid=5275 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=33859818-1b00-0000-ade9-69919b140000 pid=5275 execve guuid=4078f118-1b00-0000-ade9-69919c140000 pid=5276 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=4078f118-1b00-0000-ade9-69919c140000 pid=5276 execve guuid=56923d19-1b00-0000-ade9-69919e140000 pid=5278 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=56923d19-1b00-0000-ade9-69919e140000 pid=5278 execve guuid=f9d78719-1b00-0000-ade9-69919f140000 pid=5279 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f9d78719-1b00-0000-ade9-69919f140000 pid=5279 execve guuid=c460e719-1b00-0000-ade9-6991a1140000 pid=5281 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=c460e719-1b00-0000-ade9-6991a1140000 pid=5281 execve guuid=38f8481a-1b00-0000-ade9-6991a3140000 pid=5283 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=38f8481a-1b00-0000-ade9-6991a3140000 pid=5283 execve guuid=4f659d1a-1b00-0000-ade9-6991a4140000 pid=5284 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=4f659d1a-1b00-0000-ade9-6991a4140000 pid=5284 execve guuid=28b1091b-1b00-0000-ade9-6991a6140000 pid=5286 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=28b1091b-1b00-0000-ade9-6991a6140000 pid=5286 execve guuid=ad7f1129-1b00-0000-ade9-6991a7140000 pid=5287 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=ad7f1129-1b00-0000-ade9-6991a7140000 pid=5287 execve guuid=1ef48329-1b00-0000-ade9-6991a8140000 pid=5288 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=1ef48329-1b00-0000-ade9-6991a8140000 pid=5288 execve guuid=40fb0d2a-1b00-0000-ade9-6991a9140000 pid=5289 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=40fb0d2a-1b00-0000-ade9-6991a9140000 pid=5289 execve guuid=9d3d852a-1b00-0000-ade9-6991aa140000 pid=5290 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=9d3d852a-1b00-0000-ade9-6991aa140000 pid=5290 execve guuid=42a5062b-1b00-0000-ade9-6991ab140000 pid=5291 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=42a5062b-1b00-0000-ade9-6991ab140000 pid=5291 execve guuid=9ed4852b-1b00-0000-ade9-6991ac140000 pid=5292 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=9ed4852b-1b00-0000-ade9-6991ac140000 pid=5292 execve guuid=f0f8092c-1b00-0000-ade9-6991ad140000 pid=5293 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=f0f8092c-1b00-0000-ade9-6991ad140000 pid=5293 execve guuid=a283982c-1b00-0000-ade9-6991ae140000 pid=5294 /usr/bin/rm delete-file guuid=38ccac1c-1900-0000-ade9-699125140000 pid=5157->guuid=a283982c-1b00-0000-ade9-6991ae140000 pid=5294 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=e1ccbc1d-1900-0000-ade9-699127140000 pid=5159->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=41c1e53d-1900-0000-ade9-69912c140000 pid=5164->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=3317425b-1900-0000-ade9-699131140000 pid=5169->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=8079d376-1900-0000-ade9-699134140000 pid=5172 /tmp/BRCC net send-data write-file zombie guuid=d737c076-1900-0000-ade9-699133140000 pid=5171->guuid=8079d376-1900-0000-ade9-699134140000 pid=5172 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=8079d376-1900-0000-ade9-699134140000 pid=5172->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=8079d376-1900-0000-ade9-699134140000 pid=5172->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=8079d376-1900-0000-ade9-699134140000 pid=5172->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=a3680eb7-1900-0000-ade9-699141140000 pid=5185 /usr/bin/uname guuid=8079d376-1900-0000-ade9-699134140000 pid=5172->guuid=a3680eb7-1900-0000-ade9-699141140000 pid=5185 execve guuid=32412677-1900-0000-ade9-699136140000 pid=5174->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=66f5f994-1900-0000-ade9-69913b140000 pid=5179->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=f19d19b0-1900-0000-ade9-69913e140000 pid=5182 /tmp/RWHO zombie guuid=051708b0-1900-0000-ade9-69913d140000 pid=5181->guuid=f19d19b0-1900-0000-ade9-69913e140000 pid=5182 clone guuid=0d4867b0-1900-0000-ade9-699140140000 pid=5184->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=836700ce-1900-0000-ade9-699146140000 pid=5190->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d7b3e7ea-1900-0000-ade9-699152140000 pid=5202->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=08f70309-1a00-0000-ade9-699157140000 pid=5207->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=ace9bf26-1a00-0000-ade9-69915c140000 pid=5212->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b5b18552-1a00-0000-ade9-699161140000 pid=5217->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=cf725d7a-1a00-0000-ade9-699166140000 pid=5222->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=c559969b-1a00-0000-ade9-69916b140000 pid=5227->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=29cfd3b7-1a00-0000-ade9-699170140000 pid=5232->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=0c340ddf-1a00-0000-ade9-69917b140000 pid=5243->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d05acffb-1a00-0000-ade9-699189140000 pid=5257->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-27 00:20:45 UTC
File Type:
Text (Shell)
AV detection:
11 of 24 (45.83%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh bca3e5ca3be21f841fb6f5e1bd8c0bac3850a68cdd517059783978f879b5e669

(this sample)

  
Delivery method
Distributed via web download

Comments