MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 d9f8e0d3cac3ba5e8b4244d21093a3a69578fd55b2b4213b5296c2f9ffa44018. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA File information Comments

SHA256 hash: d9f8e0d3cac3ba5e8b4244d21093a3a69578fd55b2b4213b5296c2f9ffa44018
SHA3-384 hash: 595db2fe781871f56b638c08019800c1ae4648ade74469294c72219236fc15b3ddab2a5a52826e3000cd0e9edbd7f0ce
SHA1 hash: 50fec3c510b4a49307c1143915b5bf636a1815fb
MD5 hash: a0698c2c4db3918e0fd9c4bfaece1798
humanhash: zulu-tango-happy-yankee
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-06-17 20:43:46 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTwwhD/TnsjdMht30bAulNXYq9DG+NjVsNXYrkJ:V3bfhJ0bPiq9DGmKi2
TLSH T181D02B735237017620961994F1C2E460F4148B2F0C05C91CFA4BA4316E40745F090754
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
58
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
Detections:
HEUR:Trojan-Downloader.Shell.Agent.p
Status:
terminated
Behavior Graph:
%3 guuid=359947fc-1800-0000-92e8-8fa422140000 pid=5154 /usr/bin/sudo guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155 /tmp/sample.bin guuid=359947fc-1800-0000-92e8-8fa422140000 pid=5154->guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155 execve guuid=38b76bfe-1800-0000-92e8-8fa424140000 pid=5156 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=38b76bfe-1800-0000-92e8-8fa424140000 pid=5156 execve guuid=8dfcf3fe-1800-0000-92e8-8fa425140000 pid=5157 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8dfcf3fe-1800-0000-92e8-8fa425140000 pid=5157 execve guuid=5d0eec1b-1900-0000-92e8-8fa426140000 pid=5158 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=5d0eec1b-1900-0000-92e8-8fa426140000 pid=5158 execve guuid=84f2341c-1900-0000-92e8-8fa427140000 pid=5159 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=84f2341c-1900-0000-92e8-8fa427140000 pid=5159 clone guuid=9f8fc41c-1900-0000-92e8-8fa429140000 pid=5161 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=9f8fc41c-1900-0000-92e8-8fa429140000 pid=5161 execve guuid=ef24141d-1900-0000-92e8-8fa42a140000 pid=5162 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=ef24141d-1900-0000-92e8-8fa42a140000 pid=5162 execve guuid=b080bd39-1900-0000-92e8-8fa42b140000 pid=5163 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=b080bd39-1900-0000-92e8-8fa42b140000 pid=5163 execve guuid=7a28073a-1900-0000-92e8-8fa42c140000 pid=5164 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=7a28073a-1900-0000-92e8-8fa42c140000 pid=5164 clone guuid=8229873b-1900-0000-92e8-8fa42e140000 pid=5166 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8229873b-1900-0000-92e8-8fa42e140000 pid=5166 execve guuid=3d4acd3b-1900-0000-92e8-8fa42f140000 pid=5167 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=3d4acd3b-1900-0000-92e8-8fa42f140000 pid=5167 execve guuid=2facc056-1900-0000-92e8-8fa430140000 pid=5168 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=2facc056-1900-0000-92e8-8fa430140000 pid=5168 execve guuid=aa480957-1900-0000-92e8-8fa431140000 pid=5169 /tmp/SIFV guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=aa480957-1900-0000-92e8-8fa431140000 pid=5169 execve guuid=38b02757-1900-0000-92e8-8fa433140000 pid=5171 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=38b02757-1900-0000-92e8-8fa433140000 pid=5171 execve guuid=6cd59557-1900-0000-92e8-8fa434140000 pid=5172 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=6cd59557-1900-0000-92e8-8fa434140000 pid=5172 execve guuid=53601773-1900-0000-92e8-8fa436140000 pid=5174 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=53601773-1900-0000-92e8-8fa436140000 pid=5174 execve guuid=4f3c6073-1900-0000-92e8-8fa437140000 pid=5175 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=4f3c6073-1900-0000-92e8-8fa437140000 pid=5175 clone guuid=9c54f473-1900-0000-92e8-8fa439140000 pid=5177 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=9c54f473-1900-0000-92e8-8fa439140000 pid=5177 execve guuid=fc543c74-1900-0000-92e8-8fa43a140000 pid=5178 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=fc543c74-1900-0000-92e8-8fa43a140000 pid=5178 execve guuid=4e3d178f-1900-0000-92e8-8fa43b140000 pid=5179 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=4e3d178f-1900-0000-92e8-8fa43b140000 pid=5179 execve guuid=8843648f-1900-0000-92e8-8fa43c140000 pid=5180 /tmp/LOAR guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8843648f-1900-0000-92e8-8fa43c140000 pid=5180 execve guuid=949e7d8f-1900-0000-92e8-8fa43e140000 pid=5182 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=949e7d8f-1900-0000-92e8-8fa43e140000 pid=5182 execve guuid=8ee20190-1900-0000-92e8-8fa43f140000 pid=5183 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8ee20190-1900-0000-92e8-8fa43f140000 pid=5183 execve guuid=cd63fbab-1900-0000-92e8-8fa447140000 pid=5191 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=cd63fbab-1900-0000-92e8-8fa447140000 pid=5191 execve guuid=505953ac-1900-0000-92e8-8fa448140000 pid=5192 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=505953ac-1900-0000-92e8-8fa448140000 pid=5192 clone guuid=9c8b1dad-1900-0000-92e8-8fa44a140000 pid=5194 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=9c8b1dad-1900-0000-92e8-8fa44a140000 pid=5194 execve guuid=6ad378ad-1900-0000-92e8-8fa44b140000 pid=5195 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=6ad378ad-1900-0000-92e8-8fa44b140000 pid=5195 execve guuid=aaaa53ca-1900-0000-92e8-8fa44c140000 pid=5196 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=aaaa53ca-1900-0000-92e8-8fa44c140000 pid=5196 execve guuid=c1efb7ca-1900-0000-92e8-8fa44d140000 pid=5197 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=c1efb7ca-1900-0000-92e8-8fa44d140000 pid=5197 clone guuid=00af7dcb-1900-0000-92e8-8fa44f140000 pid=5199 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=00af7dcb-1900-0000-92e8-8fa44f140000 pid=5199 execve guuid=ccbdeecb-1900-0000-92e8-8fa450140000 pid=5200 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=ccbdeecb-1900-0000-92e8-8fa450140000 pid=5200 execve guuid=583390e7-1900-0000-92e8-8fa451140000 pid=5201 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=583390e7-1900-0000-92e8-8fa451140000 pid=5201 execve guuid=f4c134e8-1900-0000-92e8-8fa452140000 pid=5202 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f4c134e8-1900-0000-92e8-8fa452140000 pid=5202 clone guuid=8be5dbe9-1900-0000-92e8-8fa454140000 pid=5204 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8be5dbe9-1900-0000-92e8-8fa454140000 pid=5204 execve guuid=d23a32ea-1900-0000-92e8-8fa455140000 pid=5205 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=d23a32ea-1900-0000-92e8-8fa455140000 pid=5205 execve guuid=79f58200-1a00-0000-92e8-8fa456140000 pid=5206 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=79f58200-1a00-0000-92e8-8fa456140000 pid=5206 execve guuid=acfe1201-1a00-0000-92e8-8fa457140000 pid=5207 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=acfe1201-1a00-0000-92e8-8fa457140000 pid=5207 clone guuid=09c40002-1a00-0000-92e8-8fa459140000 pid=5209 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=09c40002-1a00-0000-92e8-8fa459140000 pid=5209 execve guuid=9ddf7102-1a00-0000-92e8-8fa45a140000 pid=5210 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=9ddf7102-1a00-0000-92e8-8fa45a140000 pid=5210 execve guuid=651aeb24-1a00-0000-92e8-8fa45b140000 pid=5211 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=651aeb24-1a00-0000-92e8-8fa45b140000 pid=5211 execve guuid=a25b6926-1a00-0000-92e8-8fa45c140000 pid=5212 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=a25b6926-1a00-0000-92e8-8fa45c140000 pid=5212 clone guuid=33188227-1a00-0000-92e8-8fa45e140000 pid=5214 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=33188227-1a00-0000-92e8-8fa45e140000 pid=5214 execve guuid=ffdf0428-1a00-0000-92e8-8fa45f140000 pid=5215 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=ffdf0428-1a00-0000-92e8-8fa45f140000 pid=5215 execve guuid=a45fc446-1a00-0000-92e8-8fa460140000 pid=5216 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=a45fc446-1a00-0000-92e8-8fa460140000 pid=5216 execve guuid=25f53b47-1a00-0000-92e8-8fa461140000 pid=5217 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=25f53b47-1a00-0000-92e8-8fa461140000 pid=5217 clone guuid=f20f8548-1a00-0000-92e8-8fa463140000 pid=5219 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f20f8548-1a00-0000-92e8-8fa463140000 pid=5219 execve guuid=a0252449-1a00-0000-92e8-8fa464140000 pid=5220 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=a0252449-1a00-0000-92e8-8fa464140000 pid=5220 execve guuid=d654a966-1a00-0000-92e8-8fa465140000 pid=5221 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=d654a966-1a00-0000-92e8-8fa465140000 pid=5221 execve guuid=c13b0167-1a00-0000-92e8-8fa466140000 pid=5222 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=c13b0167-1a00-0000-92e8-8fa466140000 pid=5222 clone guuid=7ef0db67-1a00-0000-92e8-8fa468140000 pid=5224 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=7ef0db67-1a00-0000-92e8-8fa468140000 pid=5224 execve guuid=46f65868-1a00-0000-92e8-8fa469140000 pid=5225 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=46f65868-1a00-0000-92e8-8fa469140000 pid=5225 execve guuid=c86db484-1a00-0000-92e8-8fa46a140000 pid=5226 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=c86db484-1a00-0000-92e8-8fa46a140000 pid=5226 execve guuid=77103585-1a00-0000-92e8-8fa46b140000 pid=5227 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=77103585-1a00-0000-92e8-8fa46b140000 pid=5227 clone guuid=22db4186-1a00-0000-92e8-8fa46d140000 pid=5229 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=22db4186-1a00-0000-92e8-8fa46d140000 pid=5229 execve guuid=137bc186-1a00-0000-92e8-8fa46e140000 pid=5230 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=137bc186-1a00-0000-92e8-8fa46e140000 pid=5230 execve guuid=fa17a8a2-1a00-0000-92e8-8fa472140000 pid=5234 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=fa17a8a2-1a00-0000-92e8-8fa472140000 pid=5234 execve guuid=2d110fa3-1a00-0000-92e8-8fa473140000 pid=5235 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=2d110fa3-1a00-0000-92e8-8fa473140000 pid=5235 clone guuid=f6eca0a3-1a00-0000-92e8-8fa475140000 pid=5237 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f6eca0a3-1a00-0000-92e8-8fa475140000 pid=5237 execve guuid=e0c7d7a3-1a00-0000-92e8-8fa477140000 pid=5239 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=e0c7d7a3-1a00-0000-92e8-8fa477140000 pid=5239 execve guuid=50b820bf-1a00-0000-92e8-8fa47a140000 pid=5242 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=50b820bf-1a00-0000-92e8-8fa47a140000 pid=5242 execve guuid=e2df6fbf-1a00-0000-92e8-8fa47b140000 pid=5243 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=e2df6fbf-1a00-0000-92e8-8fa47b140000 pid=5243 clone guuid=5c7e55c0-1a00-0000-92e8-8fa47d140000 pid=5245 /usr/bin/rm guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=5c7e55c0-1a00-0000-92e8-8fa47d140000 pid=5245 execve guuid=f00008c1-1a00-0000-92e8-8fa47e140000 pid=5246 /usr/bin/wget net send-data write-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f00008c1-1a00-0000-92e8-8fa47e140000 pid=5246 execve guuid=f9dcb2dd-1a00-0000-92e8-8fa487140000 pid=5255 /usr/bin/chmod guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f9dcb2dd-1a00-0000-92e8-8fa487140000 pid=5255 execve guuid=d68f11de-1a00-0000-92e8-8fa488140000 pid=5256 /usr/bin/dash guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=d68f11de-1a00-0000-92e8-8fa488140000 pid=5256 clone guuid=7de2c5de-1a00-0000-92e8-8fa48a140000 pid=5258 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=7de2c5de-1a00-0000-92e8-8fa48a140000 pid=5258 execve guuid=010e13df-1a00-0000-92e8-8fa48b140000 pid=5259 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=010e13df-1a00-0000-92e8-8fa48b140000 pid=5259 execve guuid=a7865fdf-1a00-0000-92e8-8fa48c140000 pid=5260 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=a7865fdf-1a00-0000-92e8-8fa48c140000 pid=5260 execve guuid=90a9a3df-1a00-0000-92e8-8fa48d140000 pid=5261 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=90a9a3df-1a00-0000-92e8-8fa48d140000 pid=5261 execve guuid=26bce8df-1a00-0000-92e8-8fa48e140000 pid=5262 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=26bce8df-1a00-0000-92e8-8fa48e140000 pid=5262 execve guuid=a70a2ce0-1a00-0000-92e8-8fa48f140000 pid=5263 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=a70a2ce0-1a00-0000-92e8-8fa48f140000 pid=5263 execve guuid=bcdd6ce0-1a00-0000-92e8-8fa490140000 pid=5264 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=bcdd6ce0-1a00-0000-92e8-8fa490140000 pid=5264 execve guuid=89a1bae0-1a00-0000-92e8-8fa491140000 pid=5265 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=89a1bae0-1a00-0000-92e8-8fa491140000 pid=5265 execve guuid=b2721de1-1a00-0000-92e8-8fa492140000 pid=5266 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=b2721de1-1a00-0000-92e8-8fa492140000 pid=5266 execve guuid=7a3b73e1-1a00-0000-92e8-8fa493140000 pid=5267 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=7a3b73e1-1a00-0000-92e8-8fa493140000 pid=5267 execve guuid=f79ed0e1-1a00-0000-92e8-8fa494140000 pid=5268 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=f79ed0e1-1a00-0000-92e8-8fa494140000 pid=5268 execve guuid=e3b530e2-1a00-0000-92e8-8fa495140000 pid=5269 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=e3b530e2-1a00-0000-92e8-8fa495140000 pid=5269 execve guuid=b7e991e2-1a00-0000-92e8-8fa496140000 pid=5270 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=b7e991e2-1a00-0000-92e8-8fa496140000 pid=5270 execve guuid=2a0efee2-1a00-0000-92e8-8fa497140000 pid=5271 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=2a0efee2-1a00-0000-92e8-8fa497140000 pid=5271 execve guuid=8b995de3-1a00-0000-92e8-8fa498140000 pid=5272 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=8b995de3-1a00-0000-92e8-8fa498140000 pid=5272 execve guuid=e8afc7e3-1a00-0000-92e8-8fa499140000 pid=5273 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=e8afc7e3-1a00-0000-92e8-8fa499140000 pid=5273 execve guuid=fa5f26e4-1a00-0000-92e8-8fa49a140000 pid=5274 /usr/bin/rm delete-file guuid=b68538fe-1800-0000-92e8-8fa423140000 pid=5155->guuid=fa5f26e4-1a00-0000-92e8-8fa49a140000 pid=5274 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=8dfcf3fe-1800-0000-92e8-8fa425140000 pid=5157->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=ef24141d-1900-0000-92e8-8fa42a140000 pid=5162->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=3d4acd3b-1900-0000-92e8-8fa42f140000 pid=5167->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170 /tmp/SIFV net send-data write-file zombie guuid=aa480957-1900-0000-92e8-8fa431140000 pid=5169->guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=f4306c5f-1900-0000-92e8-8fa435140000 pid=5173 /usr/bin/uname guuid=20eb1d57-1900-0000-92e8-8fa432140000 pid=5170->guuid=f4306c5f-1900-0000-92e8-8fa435140000 pid=5173 execve guuid=6cd59557-1900-0000-92e8-8fa434140000 pid=5172->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=fc543c74-1900-0000-92e8-8fa43a140000 pid=5178->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=cdab738f-1900-0000-92e8-8fa43d140000 pid=5181 /tmp/LOAR zombie guuid=8843648f-1900-0000-92e8-8fa43c140000 pid=5180->guuid=cdab738f-1900-0000-92e8-8fa43d140000 pid=5181 clone guuid=8ee20190-1900-0000-92e8-8fa43f140000 pid=5183->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=6ad378ad-1900-0000-92e8-8fa44b140000 pid=5195->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=ccbdeecb-1900-0000-92e8-8fa450140000 pid=5200->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=d23a32ea-1900-0000-92e8-8fa455140000 pid=5205->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=9ddf7102-1a00-0000-92e8-8fa45a140000 pid=5210->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=ffdf0428-1a00-0000-92e8-8fa45f140000 pid=5215->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a0252449-1a00-0000-92e8-8fa464140000 pid=5220->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=46f65868-1a00-0000-92e8-8fa469140000 pid=5225->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=137bc186-1a00-0000-92e8-8fa46e140000 pid=5230->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=e0c7d7a3-1a00-0000-92e8-8fa477140000 pid=5239->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=f00008c1-1a00-0000-92e8-8fa47e140000 pid=5246->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-17 20:44:52 UTC
File Type:
Text (Shell)
AV detection:
7 of 36 (19.44%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh d9f8e0d3cac3ba5e8b4244d21093a3a69578fd55b2b4213b5296c2f9ffa44018

(this sample)

  
Delivery method
Distributed via web download

Comments