MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d
SHA3-384 hash: 24663217324392cef4aa39e49163c8943f33934b5d4291a24fff8171c6211ff498447f17a47bebba6b22cb4aa705144c
SHA1 hash: fc3445fa2df83774dab571ddca5e8c4a100289d1
MD5 hash: 9cee945fd48295da4ca0810fc1900e49
humanhash: oranges-network-single-jig
File name:WSW0
Download: download sample
File size:263 bytes
First seen:2026-05-24 00:23:34 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTBGjs8kndaVqDlHt/2HAulNXYq4HvXDG+NjVsNXYrkJ:VQjqn2qDlHV0Piq4HvXDGmKi2
TLSH T194D02EE262B302B080F27924FAC6B000B0100BBE2D68FA1D7A0338711F44318B0907A0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
47
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=1ffd22f9-1600-0000-6738-25855c0e0000 pid=3676 /usr/bin/sudo guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684 /tmp/sample.bin guuid=1ffd22f9-1600-0000-6738-25855c0e0000 pid=3676->guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684 execve guuid=995c1ffb-1600-0000-6738-2585650e0000 pid=3685 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=995c1ffb-1600-0000-6738-2585650e0000 pid=3685 execve guuid=4b9b52fc-1600-0000-6738-2585670e0000 pid=3687 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4b9b52fc-1600-0000-6738-2585670e0000 pid=3687 execve guuid=d1a0e22f-1700-0000-6738-2585d00e0000 pid=3792 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=d1a0e22f-1700-0000-6738-2585d00e0000 pid=3792 execve guuid=d2c63530-1700-0000-6738-2585d20e0000 pid=3794 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=d2c63530-1700-0000-6738-2585d20e0000 pid=3794 clone guuid=ae43ce30-1700-0000-6738-2585d80e0000 pid=3800 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ae43ce30-1700-0000-6738-2585d80e0000 pid=3800 execve guuid=4fba1631-1700-0000-6738-2585db0e0000 pid=3803 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4fba1631-1700-0000-6738-2585db0e0000 pid=3803 execve guuid=97d4146e-1700-0000-6738-2585ac0f0000 pid=4012 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=97d4146e-1700-0000-6738-2585ac0f0000 pid=4012 execve guuid=f124836e-1700-0000-6738-2585ad0f0000 pid=4013 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=f124836e-1700-0000-6738-2585ad0f0000 pid=4013 clone guuid=0e86696f-1700-0000-6738-2585b20f0000 pid=4018 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=0e86696f-1700-0000-6738-2585b20f0000 pid=4018 execve guuid=783fd76f-1700-0000-6738-2585b40f0000 pid=4020 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=783fd76f-1700-0000-6738-2585b40f0000 pid=4020 execve guuid=563bfe96-1700-0000-6738-258512100000 pid=4114 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=563bfe96-1700-0000-6738-258512100000 pid=4114 execve guuid=ae927297-1700-0000-6738-258514100000 pid=4116 /tmp/MYUP guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ae927297-1700-0000-6738-258514100000 pid=4116 execve guuid=7964a597-1700-0000-6738-258516100000 pid=4118 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=7964a597-1700-0000-6738-258516100000 pid=4118 execve guuid=0e332298-1700-0000-6738-258518100000 pid=4120 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=0e332298-1700-0000-6738-258518100000 pid=4120 execve guuid=5b6720bf-1700-0000-6738-258560100000 pid=4192 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=5b6720bf-1700-0000-6738-258560100000 pid=4192 execve guuid=94b688bf-1700-0000-6738-258562100000 pid=4194 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=94b688bf-1700-0000-6738-258562100000 pid=4194 clone guuid=96741dc0-1700-0000-6738-258568100000 pid=4200 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=96741dc0-1700-0000-6738-258568100000 pid=4200 execve guuid=301b77c0-1700-0000-6738-258569100000 pid=4201 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=301b77c0-1700-0000-6738-258569100000 pid=4201 execve guuid=ecbc71e7-1700-0000-6738-2585f9100000 pid=4345 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ecbc71e7-1700-0000-6738-2585f9100000 pid=4345 execve guuid=b5e1aae7-1700-0000-6738-2585fb100000 pid=4347 /tmp/TSJR guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=b5e1aae7-1700-0000-6738-2585fb100000 pid=4347 execve guuid=89bbc1e7-1700-0000-6738-2585fd100000 pid=4349 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=89bbc1e7-1700-0000-6738-2585fd100000 pid=4349 execve guuid=63c6f6e7-1700-0000-6738-258501110000 pid=4353 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=63c6f6e7-1700-0000-6738-258501110000 pid=4353 execve guuid=af208d0e-1800-0000-6738-258577110000 pid=4471 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=af208d0e-1800-0000-6738-258577110000 pid=4471 execve guuid=a4b3060f-1800-0000-6738-25857b110000 pid=4475 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=a4b3060f-1800-0000-6738-25857b110000 pid=4475 clone guuid=4caefa0f-1800-0000-6738-25857e110000 pid=4478 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4caefa0f-1800-0000-6738-25857e110000 pid=4478 execve guuid=7e476f10-1800-0000-6738-258580110000 pid=4480 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=7e476f10-1800-0000-6738-258580110000 pid=4480 execve guuid=78827237-1800-0000-6738-2585d1110000 pid=4561 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=78827237-1800-0000-6738-2585d1110000 pid=4561 execve guuid=e48cf137-1800-0000-6738-2585d3110000 pid=4563 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=e48cf137-1800-0000-6738-2585d3110000 pid=4563 clone guuid=a31fe338-1800-0000-6738-2585d8110000 pid=4568 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=a31fe338-1800-0000-6738-2585d8110000 pid=4568 execve guuid=85ce5a39-1800-0000-6738-2585dc110000 pid=4572 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=85ce5a39-1800-0000-6738-2585dc110000 pid=4572 execve guuid=74771362-1800-0000-6738-25853a120000 pid=4666 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=74771362-1800-0000-6738-25853a120000 pid=4666 execve guuid=e9076062-1800-0000-6738-25853b120000 pid=4667 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=e9076062-1800-0000-6738-25853b120000 pid=4667 clone guuid=ef274864-1800-0000-6738-258540120000 pid=4672 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ef274864-1800-0000-6738-258540120000 pid=4672 execve guuid=4e64f864-1800-0000-6738-258544120000 pid=4676 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4e64f864-1800-0000-6738-258544120000 pid=4676 execve guuid=e835a484-1800-0000-6738-2585a0120000 pid=4768 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=e835a484-1800-0000-6738-2585a0120000 pid=4768 execve guuid=e7e30685-1800-0000-6738-2585a1120000 pid=4769 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=e7e30685-1800-0000-6738-2585a1120000 pid=4769 clone guuid=95dee885-1800-0000-6738-2585a5120000 pid=4773 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=95dee885-1800-0000-6738-2585a5120000 pid=4773 execve guuid=8f5f5e86-1800-0000-6738-2585a7120000 pid=4775 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8f5f5e86-1800-0000-6738-2585a7120000 pid=4775 execve guuid=7b3159ad-1800-0000-6738-258515130000 pid=4885 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=7b3159ad-1800-0000-6738-258515130000 pid=4885 execve guuid=1ab51bae-1800-0000-6738-258517130000 pid=4887 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=1ab51bae-1800-0000-6738-258517130000 pid=4887 clone guuid=845022b0-1800-0000-6738-25851d130000 pid=4893 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=845022b0-1800-0000-6738-25851d130000 pid=4893 execve guuid=8a4e62b0-1800-0000-6738-25851f130000 pid=4895 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8a4e62b0-1800-0000-6738-25851f130000 pid=4895 execve guuid=b8e04ed7-1800-0000-6738-258571130000 pid=4977 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=b8e04ed7-1800-0000-6738-258571130000 pid=4977 execve guuid=4c5e14d8-1800-0000-6738-258573130000 pid=4979 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4c5e14d8-1800-0000-6738-258573130000 pid=4979 clone guuid=250e88da-1800-0000-6738-25857b130000 pid=4987 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=250e88da-1800-0000-6738-25857b130000 pid=4987 execve guuid=18f7fbda-1800-0000-6738-25857d130000 pid=4989 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=18f7fbda-1800-0000-6738-25857d130000 pid=4989 execve guuid=08d8b140-1900-0000-6738-25854c140000 pid=5196 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=08d8b140-1900-0000-6738-25854c140000 pid=5196 execve guuid=ae230341-1900-0000-6738-25854e140000 pid=5198 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ae230341-1900-0000-6738-25854e140000 pid=5198 clone guuid=3794b341-1900-0000-6738-258551140000 pid=5201 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=3794b341-1900-0000-6738-258551140000 pid=5201 execve guuid=35a35942-1900-0000-6738-258553140000 pid=5203 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=35a35942-1900-0000-6738-258553140000 pid=5203 execve guuid=8b0a346a-1900-0000-6738-25859c140000 pid=5276 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8b0a346a-1900-0000-6738-25859c140000 pid=5276 execve guuid=9e4f906a-1900-0000-6738-25859d140000 pid=5277 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=9e4f906a-1900-0000-6738-25859d140000 pid=5277 clone guuid=7548336c-1900-0000-6738-25859f140000 pid=5279 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=7548336c-1900-0000-6738-25859f140000 pid=5279 execve guuid=bf7d7a6c-1900-0000-6738-2585a0140000 pid=5280 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=bf7d7a6c-1900-0000-6738-2585a0140000 pid=5280 execve guuid=dd059c93-1900-0000-6738-2585ac140000 pid=5292 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=dd059c93-1900-0000-6738-2585ac140000 pid=5292 execve guuid=7444f293-1900-0000-6738-2585ad140000 pid=5293 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=7444f293-1900-0000-6738-2585ad140000 pid=5293 clone guuid=5ad9b194-1900-0000-6738-2585af140000 pid=5295 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=5ad9b194-1900-0000-6738-2585af140000 pid=5295 execve guuid=f52c0895-1900-0000-6738-2585b0140000 pid=5296 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=f52c0895-1900-0000-6738-2585b0140000 pid=5296 execve guuid=6b5724bc-1900-0000-6738-2585b1140000 pid=5297 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=6b5724bc-1900-0000-6738-2585b1140000 pid=5297 execve guuid=b25d6ebc-1900-0000-6738-2585b2140000 pid=5298 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=b25d6ebc-1900-0000-6738-2585b2140000 pid=5298 clone guuid=070700bd-1900-0000-6738-2585b4140000 pid=5300 /usr/bin/rm guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=070700bd-1900-0000-6738-2585b4140000 pid=5300 execve guuid=61fd43bd-1900-0000-6738-2585b5140000 pid=5301 /usr/bin/wget net send-data write-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=61fd43bd-1900-0000-6738-2585b5140000 pid=5301 execve guuid=79c5d6e3-1900-0000-6738-2585b6140000 pid=5302 /usr/bin/chmod guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=79c5d6e3-1900-0000-6738-2585b6140000 pid=5302 execve guuid=0e401ce4-1900-0000-6738-2585b7140000 pid=5303 /usr/bin/dash guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=0e401ce4-1900-0000-6738-2585b7140000 pid=5303 clone guuid=3160bde4-1900-0000-6738-2585b9140000 pid=5305 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=3160bde4-1900-0000-6738-2585b9140000 pid=5305 execve guuid=2d8206e5-1900-0000-6738-2585ba140000 pid=5306 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=2d8206e5-1900-0000-6738-2585ba140000 pid=5306 execve guuid=239455e5-1900-0000-6738-2585bb140000 pid=5307 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=239455e5-1900-0000-6738-2585bb140000 pid=5307 execve guuid=0abf9be5-1900-0000-6738-2585bc140000 pid=5308 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=0abf9be5-1900-0000-6738-2585bc140000 pid=5308 execve guuid=05a1e4e5-1900-0000-6738-2585bd140000 pid=5309 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=05a1e4e5-1900-0000-6738-2585bd140000 pid=5309 execve guuid=8cb92ee6-1900-0000-6738-2585be140000 pid=5310 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8cb92ee6-1900-0000-6738-2585be140000 pid=5310 execve guuid=ac2f75e6-1900-0000-6738-2585bf140000 pid=5311 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=ac2f75e6-1900-0000-6738-2585bf140000 pid=5311 execve guuid=e8b0bbe6-1900-0000-6738-2585c0140000 pid=5312 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=e8b0bbe6-1900-0000-6738-2585c0140000 pid=5312 execve guuid=560508e7-1900-0000-6738-2585c1140000 pid=5313 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=560508e7-1900-0000-6738-2585c1140000 pid=5313 execve guuid=d47f50e7-1900-0000-6738-2585c2140000 pid=5314 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=d47f50e7-1900-0000-6738-2585c2140000 pid=5314 execve guuid=4f0b98e7-1900-0000-6738-2585c3140000 pid=5315 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=4f0b98e7-1900-0000-6738-2585c3140000 pid=5315 execve guuid=f505dae7-1900-0000-6738-2585c4140000 pid=5316 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=f505dae7-1900-0000-6738-2585c4140000 pid=5316 execve guuid=6a4c21e8-1900-0000-6738-2585c5140000 pid=5317 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=6a4c21e8-1900-0000-6738-2585c5140000 pid=5317 execve guuid=0a786ce8-1900-0000-6738-2585c6140000 pid=5318 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=0a786ce8-1900-0000-6738-2585c6140000 pid=5318 execve guuid=8207b7e8-1900-0000-6738-2585c7140000 pid=5319 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8207b7e8-1900-0000-6738-2585c7140000 pid=5319 execve guuid=8e1f00e9-1900-0000-6738-2585c8140000 pid=5320 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=8e1f00e9-1900-0000-6738-2585c8140000 pid=5320 execve guuid=cd6b3de9-1900-0000-6738-2585c9140000 pid=5321 /usr/bin/rm delete-file guuid=3f65e7fa-1600-0000-6738-2585640e0000 pid=3684->guuid=cd6b3de9-1900-0000-6738-2585c9140000 pid=5321 execve 83c32eec-0d9a-58b4-94be-04059aaf3255 202.155.8.56:80 guuid=4b9b52fc-1600-0000-6738-2585670e0000 pid=3687->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=4fba1631-1700-0000-6738-2585db0e0000 pid=3803->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=783fd76f-1700-0000-6738-2585b40f0000 pid=4020->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=13c59597-1700-0000-6738-258515100000 pid=4117 /tmp/MYUP net send-data write-file zombie guuid=ae927297-1700-0000-6738-258514100000 pid=4116->guuid=13c59597-1700-0000-6738-258515100000 pid=4117 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=13c59597-1700-0000-6738-258515100000 pid=4117->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=13c59597-1700-0000-6738-258515100000 pid=4117->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=13c59597-1700-0000-6738-258515100000 pid=4117->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=4a2d2ba7-1700-0000-6738-258525100000 pid=4133 /usr/bin/uname guuid=13c59597-1700-0000-6738-258515100000 pid=4117->guuid=4a2d2ba7-1700-0000-6738-258525100000 pid=4133 execve guuid=0e332298-1700-0000-6738-258518100000 pid=4120->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=301b77c0-1700-0000-6738-258569100000 pid=4201->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=543fbae7-1700-0000-6738-2585fc100000 pid=4348 /tmp/TSJR zombie guuid=b5e1aae7-1700-0000-6738-2585fb100000 pid=4347->guuid=543fbae7-1700-0000-6738-2585fc100000 pid=4348 clone guuid=63c6f6e7-1700-0000-6738-258501110000 pid=4353->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=7e476f10-1800-0000-6738-258580110000 pid=4480->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=85ce5a39-1800-0000-6738-2585dc110000 pid=4572->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=4e64f864-1800-0000-6738-258544120000 pid=4676->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8f5f5e86-1800-0000-6738-2585a7120000 pid=4775->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=8a4e62b0-1800-0000-6738-25851f130000 pid=4895->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=18f7fbda-1800-0000-6738-25857d130000 pid=4989->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=35a35942-1900-0000-6738-258553140000 pid=5203->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=bf7d7a6c-1900-0000-6738-2585a0140000 pid=5280->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=f52c0895-1900-0000-6738-2585b0140000 pid=5296->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B guuid=61fd43bd-1900-0000-6738-2585b5140000 pid=5301->83c32eec-0d9a-58b4-94be-04059aaf3255 send: 131B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-05-24 00:26:26 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh c85d12d6427041849ce0c973e8639a4e2bfc23cdd0feb564d29cde873367446d

(this sample)

  
Delivery method
Distributed via web download

Comments