MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c73399fceb767ad85b497a8a102dac689a5fdcf0cf614b863e4d08904f63fca8. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: c73399fceb767ad85b497a8a102dac689a5fdcf0cf614b863e4d08904f63fca8
SHA3-384 hash: 759e7cdbc2d9ebc8ddb96f70708b49e51530ffa9e64c20abfa6f1c1ed93546512007082ad97b75653a74f29b640dbbca
SHA1 hash: 0f2696fe72ac8679beec22164521f3ddda33265d
MD5 hash: c46308c4e7af97972e178e49f75f82c1
humanhash: pennsylvania-bulldog-mike-moon
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-06-16 02:17:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hT7/I2CSKwEOAHAulNXYq9DG+NjVsNXYrkJ:VT5EOAHPiq9DGmKi2
TLSH T1A5D097A3B1F3027420720A48F1C2E840B916C73EEC04CA28BB1B24709F40348F4C03D4
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
113
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-15T23:25:00Z UTC
Last seen:
2026-06-17T22:36:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=cddf12f2-1600-0000-5541-1656610e0000 pid=3681 /usr/bin/sudo guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691 /tmp/sample.bin guuid=cddf12f2-1600-0000-5541-1656610e0000 pid=3681->guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691 execve guuid=f8d3f9f4-1600-0000-5541-16566c0e0000 pid=3692 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=f8d3f9f4-1600-0000-5541-16566c0e0000 pid=3692 execve guuid=3b989df5-1600-0000-5541-16566f0e0000 pid=3695 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=3b989df5-1600-0000-5541-16566f0e0000 pid=3695 execve guuid=009f5612-1700-0000-5541-1656e00e0000 pid=3808 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=009f5612-1700-0000-5541-1656e00e0000 pid=3808 execve guuid=cacbaf12-1700-0000-5541-1656e30e0000 pid=3811 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=cacbaf12-1700-0000-5541-1656e30e0000 pid=3811 clone guuid=88b2ab13-1700-0000-5541-1656ea0e0000 pid=3818 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=88b2ab13-1700-0000-5541-1656ea0e0000 pid=3818 execve guuid=17e91314-1700-0000-5541-1656eb0e0000 pid=3819 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=17e91314-1700-0000-5541-1656eb0e0000 pid=3819 execve guuid=35fb0230-1700-0000-5541-16563f0f0000 pid=3903 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=35fb0230-1700-0000-5541-16563f0f0000 pid=3903 execve guuid=37ec3c30-1700-0000-5541-1656400f0000 pid=3904 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=37ec3c30-1700-0000-5541-1656400f0000 pid=3904 clone guuid=0e37ba30-1700-0000-5541-1656440f0000 pid=3908 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=0e37ba30-1700-0000-5541-1656440f0000 pid=3908 execve guuid=9b73f230-1700-0000-5541-1656460f0000 pid=3910 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=9b73f230-1700-0000-5541-1656460f0000 pid=3910 execve guuid=5710374c-1700-0000-5541-1656910f0000 pid=3985 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=5710374c-1700-0000-5541-1656910f0000 pid=3985 execve guuid=d368954c-1700-0000-5541-1656930f0000 pid=3987 /tmp/PBVB guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d368954c-1700-0000-5541-1656930f0000 pid=3987 execve guuid=9676ae4c-1700-0000-5541-1656950f0000 pid=3989 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=9676ae4c-1700-0000-5541-1656950f0000 pid=3989 execve guuid=6edff34c-1700-0000-5541-1656970f0000 pid=3991 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=6edff34c-1700-0000-5541-1656970f0000 pid=3991 execve guuid=051df368-1700-0000-5541-1656e30f0000 pid=4067 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=051df368-1700-0000-5541-1656e30f0000 pid=4067 execve guuid=34355169-1700-0000-5541-1656e40f0000 pid=4068 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=34355169-1700-0000-5541-1656e40f0000 pid=4068 clone guuid=f995fa69-1700-0000-5541-1656e90f0000 pid=4073 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=f995fa69-1700-0000-5541-1656e90f0000 pid=4073 execve guuid=7c3c5b6a-1700-0000-5541-1656eb0f0000 pid=4075 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=7c3c5b6a-1700-0000-5541-1656eb0f0000 pid=4075 execve guuid=6e746b85-1700-0000-5541-16564a100000 pid=4170 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=6e746b85-1700-0000-5541-16564a100000 pid=4170 execve guuid=d2e2c485-1700-0000-5541-16564c100000 pid=4172 /tmp/EXWE guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d2e2c485-1700-0000-5541-16564c100000 pid=4172 execve guuid=5440df85-1700-0000-5541-16564e100000 pid=4174 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=5440df85-1700-0000-5541-16564e100000 pid=4174 execve guuid=9cc82886-1700-0000-5541-165650100000 pid=4176 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=9cc82886-1700-0000-5541-165650100000 pid=4176 execve guuid=16617da1-1700-0000-5541-1656a6100000 pid=4262 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=16617da1-1700-0000-5541-1656a6100000 pid=4262 execve guuid=eda2e8a1-1700-0000-5541-1656a7100000 pid=4263 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=eda2e8a1-1700-0000-5541-1656a7100000 pid=4263 clone guuid=eca8d2a2-1700-0000-5541-1656af100000 pid=4271 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=eca8d2a2-1700-0000-5541-1656af100000 pid=4271 execve guuid=c0ed2ea3-1700-0000-5541-1656b0100000 pid=4272 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=c0ed2ea3-1700-0000-5541-1656b0100000 pid=4272 execve guuid=4b31eebe-1700-0000-5541-1656f9100000 pid=4345 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=4b31eebe-1700-0000-5541-1656f9100000 pid=4345 execve guuid=2e2460bf-1700-0000-5541-1656fb100000 pid=4347 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=2e2460bf-1700-0000-5541-1656fb100000 pid=4347 clone guuid=5cfd3bc0-1700-0000-5541-1656fe100000 pid=4350 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=5cfd3bc0-1700-0000-5541-1656fe100000 pid=4350 execve guuid=5ec39dc0-1700-0000-5541-165600110000 pid=4352 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=5ec39dc0-1700-0000-5541-165600110000 pid=4352 execve guuid=2ef74ede-1700-0000-5541-165656110000 pid=4438 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=2ef74ede-1700-0000-5541-165656110000 pid=4438 execve guuid=1ab399de-1700-0000-5541-16565a110000 pid=4442 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=1ab399de-1700-0000-5541-16565a110000 pid=4442 clone guuid=1b1877df-1700-0000-5541-16565c110000 pid=4444 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=1b1877df-1700-0000-5541-16565c110000 pid=4444 execve guuid=d880c2df-1700-0000-5541-165660110000 pid=4448 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d880c2df-1700-0000-5541-165660110000 pid=4448 execve guuid=b50d56f6-1700-0000-5541-1656ba110000 pid=4538 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=b50d56f6-1700-0000-5541-1656ba110000 pid=4538 execve guuid=b06e98f6-1700-0000-5541-1656bc110000 pid=4540 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=b06e98f6-1700-0000-5541-1656bc110000 pid=4540 clone guuid=b90520f7-1700-0000-5541-1656bf110000 pid=4543 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=b90520f7-1700-0000-5541-1656bf110000 pid=4543 execve guuid=355d6af7-1700-0000-5541-1656c0110000 pid=4544 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=355d6af7-1700-0000-5541-1656c0110000 pid=4544 execve guuid=177f3726-1800-0000-5541-16565e120000 pid=4702 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=177f3726-1800-0000-5541-16565e120000 pid=4702 execve guuid=0c61ab26-1800-0000-5541-165660120000 pid=4704 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=0c61ab26-1800-0000-5541-165660120000 pid=4704 clone guuid=88403327-1800-0000-5541-165664120000 pid=4708 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=88403327-1800-0000-5541-165664120000 pid=4708 execve guuid=d44b7127-1800-0000-5541-165665120000 pid=4709 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d44b7127-1800-0000-5541-165665120000 pid=4709 execve guuid=21e4ab42-1800-0000-5541-1656c6120000 pid=4806 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=21e4ab42-1800-0000-5541-1656c6120000 pid=4806 execve guuid=1cbde842-1800-0000-5541-1656c8120000 pid=4808 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=1cbde842-1800-0000-5541-1656c8120000 pid=4808 clone guuid=455ce343-1800-0000-5541-1656cd120000 pid=4813 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=455ce343-1800-0000-5541-1656cd120000 pid=4813 execve guuid=1d173644-1800-0000-5541-1656d0120000 pid=4816 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=1d173644-1800-0000-5541-1656d0120000 pid=4816 execve guuid=bc17e15f-1800-0000-5541-165627130000 pid=4903 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=bc17e15f-1800-0000-5541-165627130000 pid=4903 execve guuid=fc8f6560-1800-0000-5541-165629130000 pid=4905 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=fc8f6560-1800-0000-5541-165629130000 pid=4905 clone guuid=fa015e61-1800-0000-5541-16562d130000 pid=4909 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=fa015e61-1800-0000-5541-16562d130000 pid=4909 execve guuid=a59ca661-1800-0000-5541-16562f130000 pid=4911 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=a59ca661-1800-0000-5541-16562f130000 pid=4911 execve guuid=b127607e-1800-0000-5541-165690130000 pid=5008 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=b127607e-1800-0000-5541-165690130000 pid=5008 execve guuid=558b9b7e-1800-0000-5541-165692130000 pid=5010 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=558b9b7e-1800-0000-5541-165692130000 pid=5010 clone guuid=d85e277f-1800-0000-5541-165696130000 pid=5014 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d85e277f-1800-0000-5541-165696130000 pid=5014 execve guuid=c1d6ad7f-1800-0000-5541-165699130000 pid=5017 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=c1d6ad7f-1800-0000-5541-165699130000 pid=5017 execve guuid=de57139c-1800-0000-5541-165614140000 pid=5140 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=de57139c-1800-0000-5541-165614140000 pid=5140 execve guuid=23ae519c-1800-0000-5541-165616140000 pid=5142 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=23ae519c-1800-0000-5541-165616140000 pid=5142 clone guuid=af1edb9d-1800-0000-5541-16561f140000 pid=5151 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=af1edb9d-1800-0000-5541-16561f140000 pid=5151 execve guuid=9249289e-1800-0000-5541-165621140000 pid=5153 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=9249289e-1800-0000-5541-165621140000 pid=5153 execve guuid=e6e361b9-1800-0000-5541-16566b140000 pid=5227 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=e6e361b9-1800-0000-5541-16566b140000 pid=5227 execve guuid=a7c4a3b9-1800-0000-5541-16566c140000 pid=5228 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=a7c4a3b9-1800-0000-5541-16566c140000 pid=5228 clone guuid=23b03dba-1800-0000-5541-165670140000 pid=5232 /usr/bin/rm guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=23b03dba-1800-0000-5541-165670140000 pid=5232 execve guuid=fdc883ba-1800-0000-5541-165672140000 pid=5234 /usr/bin/wget net send-data write-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=fdc883ba-1800-0000-5541-165672140000 pid=5234 execve guuid=c39db9d5-1800-0000-5541-1656a9140000 pid=5289 /usr/bin/chmod guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=c39db9d5-1800-0000-5541-1656a9140000 pid=5289 execve guuid=88373bd6-1800-0000-5541-1656aa140000 pid=5290 /usr/bin/dash guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=88373bd6-1800-0000-5541-1656aa140000 pid=5290 clone guuid=ee562ed9-1800-0000-5541-1656ac140000 pid=5292 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=ee562ed9-1800-0000-5541-1656ac140000 pid=5292 execve guuid=b4c6c9d9-1800-0000-5541-1656ad140000 pid=5293 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=b4c6c9d9-1800-0000-5541-1656ad140000 pid=5293 execve guuid=56f156da-1800-0000-5541-1656ae140000 pid=5294 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=56f156da-1800-0000-5541-1656ae140000 pid=5294 execve guuid=2e74c6da-1800-0000-5541-1656af140000 pid=5295 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=2e74c6da-1800-0000-5541-1656af140000 pid=5295 execve guuid=c7f54edb-1800-0000-5541-1656b0140000 pid=5296 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=c7f54edb-1800-0000-5541-1656b0140000 pid=5296 execve guuid=cc1bd1db-1800-0000-5541-1656b1140000 pid=5297 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=cc1bd1db-1800-0000-5541-1656b1140000 pid=5297 execve guuid=f9cb3adc-1800-0000-5541-1656b2140000 pid=5298 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=f9cb3adc-1800-0000-5541-1656b2140000 pid=5298 execve guuid=d9759cdc-1800-0000-5541-1656b3140000 pid=5299 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=d9759cdc-1800-0000-5541-1656b3140000 pid=5299 execve guuid=3fa4f1dc-1800-0000-5541-1656b4140000 pid=5300 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=3fa4f1dc-1800-0000-5541-1656b4140000 pid=5300 execve guuid=ed6d47dd-1800-0000-5541-1656b5140000 pid=5301 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=ed6d47dd-1800-0000-5541-1656b5140000 pid=5301 execve guuid=9f019add-1800-0000-5541-1656b8140000 pid=5304 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=9f019add-1800-0000-5541-1656b8140000 pid=5304 execve guuid=fa6dd9dd-1800-0000-5541-1656b9140000 pid=5305 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=fa6dd9dd-1800-0000-5541-1656b9140000 pid=5305 execve guuid=7e6d1ade-1800-0000-5541-1656bb140000 pid=5307 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=7e6d1ade-1800-0000-5541-1656bb140000 pid=5307 execve guuid=4e9659de-1800-0000-5541-1656bc140000 pid=5308 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=4e9659de-1800-0000-5541-1656bc140000 pid=5308 execve guuid=fd8196de-1800-0000-5541-1656bd140000 pid=5309 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=fd8196de-1800-0000-5541-1656bd140000 pid=5309 execve guuid=cfa6d0de-1800-0000-5541-1656be140000 pid=5310 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=cfa6d0de-1800-0000-5541-1656be140000 pid=5310 execve guuid=583e0fdf-1800-0000-5541-1656bf140000 pid=5311 /usr/bin/rm delete-file guuid=74e5a7f4-1600-0000-5541-16566b0e0000 pid=3691->guuid=583e0fdf-1800-0000-5541-1656bf140000 pid=5311 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=3b989df5-1600-0000-5541-16566f0e0000 pid=3695->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=17e91314-1700-0000-5541-1656eb0e0000 pid=3819->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9b73f230-1700-0000-5541-1656460f0000 pid=3910->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988 /tmp/PBVB net send-data write-file zombie guuid=d368954c-1700-0000-5541-1656930f0000 pid=3987->guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 0734f5ed-e253-55cb-b667-c800d7698d2a 34.27.195.76:443 guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988->0734f5ed-e253-55cb-b667-c800d7698d2a send: 471B 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=9ef55953-1700-0000-5541-1656a30f0000 pid=4003 /usr/bin/uname guuid=6dcfa74c-1700-0000-5541-1656940f0000 pid=3988->guuid=9ef55953-1700-0000-5541-1656a30f0000 pid=4003 execve guuid=6edff34c-1700-0000-5541-1656970f0000 pid=3991->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=7c3c5b6a-1700-0000-5541-1656eb0f0000 pid=4075->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=bb24d685-1700-0000-5541-16564d100000 pid=4173 /tmp/EXWE zombie guuid=d2e2c485-1700-0000-5541-16564c100000 pid=4172->guuid=bb24d685-1700-0000-5541-16564d100000 pid=4173 clone guuid=9cc82886-1700-0000-5541-165650100000 pid=4176->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=c0ed2ea3-1700-0000-5541-1656b0100000 pid=4272->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=5ec39dc0-1700-0000-5541-165600110000 pid=4352->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d880c2df-1700-0000-5541-165660110000 pid=4448->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=355d6af7-1700-0000-5541-1656c0110000 pid=4544->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d44b7127-1800-0000-5541-165665120000 pid=4709->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=1d173644-1800-0000-5541-1656d0120000 pid=4816->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a59ca661-1800-0000-5541-16562f130000 pid=4911->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=c1d6ad7f-1800-0000-5541-165699130000 pid=5017->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9249289e-1800-0000-5541-165621140000 pid=5153->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=fdc883ba-1800-0000-5541-165672140000 pid=5234->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-16 02:18:32 UTC
File Type:
Text (Shell)
AV detection:
9 of 23 (39.13%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c73399fceb767ad85b497a8a102dac689a5fdcf0cf614b863e4d08904f63fca8

(this sample)

  
Delivery method
Distributed via web download

Comments