MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 db7d35613111dbbdba0d349093986aa6788c9a50f1c88478960ee9732adbf278. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 3


Intelligence 3 IOCs YARA File information Comments

SHA256 hash: db7d35613111dbbdba0d349093986aa6788c9a50f1c88478960ee9732adbf278
SHA3-384 hash: 5caba3f1bdc2dfcb12cc335fdfc21be91a201212ee686e671596af45630de9bdd915dcbb8a26757d0e964be1c14435c8
SHA1 hash: 78a0fe1a7a4d5eaeb42f14f1e5c4b15de5cb77d9
MD5 hash: d6ad33e4b3be871516b23a36110579bf
humanhash: purple-steak-xray-lima
File name:cln
Download: download sample
File size:8'601 bytes
First seen:2025-07-16 02:36:03 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:O4X70EHgspTwBXL8+BH2P3ZJG62EduWghW5yLjlhgYUySwn:eyMlLHMZJLLghW5wpSwn
TLSH T1EE024227F56A36722099C17D5847A08526A5050B0B401C3CFE7DF5187F6D36CB2F67AB
Magika shell
Reporter abuse_ch
Tags:sh

Intelligence


File Origin
# of uploads :
1
# of downloads :
19
Origin country :
DE DE
Vendor Threat Intelligence
Status:
terminated
Behavior Graph:
%3 guuid=d5ee7c02-1800-0000-3b74-639e000c0000 pid=3072 /usr/bin/sudo guuid=a92f3f04-1800-0000-3b74-639e080c0000 pid=3080 /tmp/sample.bin write-config guuid=d5ee7c02-1800-0000-3b74-639e000c0000 pid=3072->guuid=a92f3f04-1800-0000-3b74-639e080c0000 pid=3080 execve guuid=3e36ca04-1800-0000-3b74-639e0a0c0000 pid=3082 /usr/bin/mkdir guuid=a92f3f04-1800-0000-3b74-639e080c0000 pid=3080->guuid=3e36ca04-1800-0000-3b74-639e0a0c0000 pid=3082 execve guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083 /usr/bin/apt-get delete-file write-file guuid=a92f3f04-1800-0000-3b74-639e080c0000 pid=3080->guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083 execve guuid=1f0a23ae-1900-0000-3b74-639e700f0000 pid=3952 /usr/bin/apt-get guuid=a92f3f04-1800-0000-3b74-639e080c0000 pid=3080->guuid=1f0a23ae-1900-0000-3b74-639e700f0000 pid=3952 execve guuid=98f63107-1800-0000-3b74-639e120c0000 pid=3090 /usr/bin/dpkg guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=98f63107-1800-0000-3b74-639e120c0000 pid=3090 execve guuid=119f2f0c-1800-0000-3b74-639e200c0000 pid=3104 /usr/lib/apt/methods/mirror guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=119f2f0c-1800-0000-3b74-639e200c0000 pid=3104 execve guuid=a4bb130d-1800-0000-3b74-639e250c0000 pid=3109 /usr/lib/apt/methods/mirror guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=a4bb130d-1800-0000-3b74-639e250c0000 pid=3109 execve guuid=95b3f40d-1800-0000-3b74-639e290c0000 pid=3113 /usr/lib/apt/methods/file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=95b3f40d-1800-0000-3b74-639e290c0000 pid=3113 execve guuid=aad0bc0e-1800-0000-3b74-639e2d0c0000 pid=3117 /usr/lib/apt/methods/file delete-file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=aad0bc0e-1800-0000-3b74-639e2d0c0000 pid=3117 execve guuid=0ee3df0f-1800-0000-3b74-639e320c0000 pid=3122 /usr/lib/apt/methods/http guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=0ee3df0f-1800-0000-3b74-639e320c0000 pid=3122 execve guuid=ca5c2c11-1800-0000-3b74-639e390c0000 pid=3129 /usr/lib/apt/methods/http dns net send-data write-file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=ca5c2c11-1800-0000-3b74-639e390c0000 pid=3129 execve guuid=ea8e8a24-1800-0000-3b74-639e640c0000 pid=3172 /usr/lib/apt/methods/gpgv guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=ea8e8a24-1800-0000-3b74-639e640c0000 pid=3172 execve guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175 /usr/lib/apt/methods/gpgv guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175 execve guuid=e1ed5961-1800-0000-3b74-639edc0c0000 pid=3292 /usr/lib/apt/methods/rred guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=e1ed5961-1800-0000-3b74-639edc0c0000 pid=3292 execve guuid=95068265-1800-0000-3b74-639ee10c0000 pid=3297 /usr/lib/apt/methods/rred write-file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=95068265-1800-0000-3b74-639ee10c0000 pid=3297 execve guuid=ee4ead66-1800-0000-3b74-639ee40c0000 pid=3300 /usr/lib/apt/methods/rred write-file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=ee4ead66-1800-0000-3b74-639ee40c0000 pid=3300 execve guuid=ed88de82-1800-0000-3b74-639e400d0000 pid=3392 /usr/lib/apt/methods/store guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=ed88de82-1800-0000-3b74-639e400d0000 pid=3392 execve guuid=702f8b86-1800-0000-3b74-639e490d0000 pid=3401 /usr/lib/apt/methods/store write-file guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=702f8b86-1800-0000-3b74-639e490d0000 pid=3401 execve guuid=3baae4b8-1800-0000-3b74-639eaa0d0000 pid=3498 /usr/bin/dpkg guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=3baae4b8-1800-0000-3b74-639eaa0d0000 pid=3498 execve guuid=0a22c4aa-1900-0000-3b74-639e630f0000 pid=3939 /usr/bin/dpkg guuid=038f5b05-1800-0000-3b74-639e0b0c0000 pid=3083->guuid=0a22c4aa-1900-0000-3b74-639e630f0000 pid=3939 execve 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=ca5c2c11-1800-0000-3b74-639e390c0000 pid=3129->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 122B 869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf debian.map.fastly.net:443 guuid=ca5c2c11-1800-0000-3b74-639e390c0000 pid=3129->869ebe88-8c1e-5fbb-adb0-cfe48d8d7faf con guuid=f8508726-1800-0000-3b74-639e680c0000 pid=3176 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175->guuid=f8508726-1800-0000-3b74-639e680c0000 pid=3176 clone guuid=59206846-1800-0000-3b74-639e9a0c0000 pid=3226 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175->guuid=59206846-1800-0000-3b74-639e9a0c0000 pid=3226 clone guuid=08b03a5d-1800-0000-3b74-639ecf0c0000 pid=3279 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175->guuid=08b03a5d-1800-0000-3b74-639ecf0c0000 pid=3279 clone guuid=0362786b-1800-0000-3b74-639efd0c0000 pid=3325 /usr/lib/apt/methods/gpgv delete-file write-file guuid=8f927025-1800-0000-3b74-639e670c0000 pid=3175->guuid=0362786b-1800-0000-3b74-639efd0c0000 pid=3325 clone guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177 /usr/bin/apt-key write-file guuid=f8508726-1800-0000-3b74-639e680c0000 pid=3176->guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177 execve guuid=c90b3d2a-1800-0000-3b74-639e6a0c0000 pid=3178 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=c90b3d2a-1800-0000-3b74-639e6a0c0000 pid=3178 clone guuid=7c0d782a-1800-0000-3b74-639e6b0c0000 pid=3179 /usr/bin/apt-config guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=7c0d782a-1800-0000-3b74-639e6b0c0000 pid=3179 execve guuid=c3d2322f-1800-0000-3b74-639e6d0c0000 pid=3181 /usr/bin/apt-config guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=c3d2322f-1800-0000-3b74-639e6d0c0000 pid=3181 execve guuid=0ee7c332-1800-0000-3b74-639e6f0c0000 pid=3183 /usr/bin/apt-config guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=0ee7c332-1800-0000-3b74-639e6f0c0000 pid=3183 execve guuid=28fabd38-1800-0000-3b74-639e710c0000 pid=3185 /usr/bin/apt-config guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=28fabd38-1800-0000-3b74-639e710c0000 pid=3185 execve guuid=ccb0f13b-1800-0000-3b74-639e730c0000 pid=3187 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=ccb0f13b-1800-0000-3b74-639e730c0000 pid=3187 clone guuid=ad921a3c-1800-0000-3b74-639e740c0000 pid=3188 /usr/bin/apt-config guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=ad921a3c-1800-0000-3b74-639e740c0000 pid=3188 execve guuid=4b6abe41-1800-0000-3b74-639e800c0000 pid=3200 /usr/bin/mktemp guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=4b6abe41-1800-0000-3b74-639e800c0000 pid=3200 execve guuid=5aa9f841-1800-0000-3b74-639e810c0000 pid=3201 /usr/bin/chmod guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=5aa9f841-1800-0000-3b74-639e810c0000 pid=3201 execve guuid=3e302842-1800-0000-3b74-639e820c0000 pid=3202 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=3e302842-1800-0000-3b74-639e820c0000 pid=3202 clone guuid=76c93842-1800-0000-3b74-639e830c0000 pid=3203 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=76c93842-1800-0000-3b74-639e830c0000 pid=3203 clone guuid=406cbb42-1800-0000-3b74-639e880c0000 pid=3208 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=406cbb42-1800-0000-3b74-639e880c0000 pid=3208 clone guuid=9c2c2243-1800-0000-3b74-639e8c0c0000 pid=3212 /usr/bin/dash guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=9c2c2243-1800-0000-3b74-639e8c0c0000 pid=3212 clone guuid=54c33643-1800-0000-3b74-639e8e0c0000 pid=3214 /usr/bin/gpgv guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=54c33643-1800-0000-3b74-639e8e0c0000 pid=3214 execve guuid=51b28845-1800-0000-3b74-639e950c0000 pid=3221 /usr/bin/rm delete-file guuid=c3016d29-1800-0000-3b74-639e690c0000 pid=3177->guuid=51b28845-1800-0000-3b74-639e950c0000 pid=3221 execve guuid=371d592e-1800-0000-3b74-639e6c0c0000 pid=3180 /usr/bin/dpkg guuid=7c0d782a-1800-0000-3b74-639e6b0c0000 pid=3179->guuid=371d592e-1800-0000-3b74-639e6c0c0000 pid=3180 execve guuid=edd84832-1800-0000-3b74-639e6e0c0000 pid=3182 /usr/bin/dpkg guuid=c3d2322f-1800-0000-3b74-639e6d0c0000 pid=3181->guuid=edd84832-1800-0000-3b74-639e6e0c0000 pid=3182 execve guuid=adf1b933-1800-0000-3b74-639e700c0000 pid=3184 /usr/bin/dpkg guuid=0ee7c332-1800-0000-3b74-639e6f0c0000 pid=3183->guuid=adf1b933-1800-0000-3b74-639e700c0000 pid=3184 execve guuid=d0ad1d3b-1800-0000-3b74-639e720c0000 pid=3186 /usr/bin/dpkg guuid=28fabd38-1800-0000-3b74-639e710c0000 pid=3185->guuid=d0ad1d3b-1800-0000-3b74-639e720c0000 pid=3186 execve guuid=50d9213d-1800-0000-3b74-639e760c0000 pid=3190 /usr/bin/dpkg guuid=ad921a3c-1800-0000-3b74-639e740c0000 pid=3188->guuid=50d9213d-1800-0000-3b74-639e760c0000 pid=3190 execve guuid=98454242-1800-0000-3b74-639e840c0000 pid=3204 /usr/bin/dash guuid=76c93842-1800-0000-3b74-639e830c0000 pid=3203->guuid=98454242-1800-0000-3b74-639e840c0000 pid=3204 clone guuid=b4424842-1800-0000-3b74-639e850c0000 pid=3205 /usr/bin/sed guuid=76c93842-1800-0000-3b74-639e830c0000 pid=3203->guuid=b4424842-1800-0000-3b74-639e850c0000 pid=3205 execve guuid=bb38c442-1800-0000-3b74-639e890c0000 pid=3209 /usr/bin/dash guuid=406cbb42-1800-0000-3b74-639e880c0000 pid=3208->guuid=bb38c442-1800-0000-3b74-639e890c0000 pid=3209 clone guuid=f73bc842-1800-0000-3b74-639e8a0c0000 pid=3210 /usr/bin/sed guuid=406cbb42-1800-0000-3b74-639e880c0000 pid=3208->guuid=f73bc842-1800-0000-3b74-639e8a0c0000 pid=3210 execve guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228 /usr/bin/apt-key write-file guuid=59206846-1800-0000-3b74-639e9a0c0000 pid=3226->guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228 execve guuid=a5583f47-1800-0000-3b74-639e9e0c0000 pid=3230 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=a5583f47-1800-0000-3b74-639e9e0c0000 pid=3230 clone guuid=adc94c47-1800-0000-3b74-639e9f0c0000 pid=3231 /usr/bin/apt-config guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=adc94c47-1800-0000-3b74-639e9f0c0000 pid=3231 execve guuid=6bfc5749-1800-0000-3b74-639ea40c0000 pid=3236 /usr/bin/apt-config guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=6bfc5749-1800-0000-3b74-639ea40c0000 pid=3236 execve guuid=c589b14a-1800-0000-3b74-639eab0c0000 pid=3243 /usr/bin/apt-config guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=c589b14a-1800-0000-3b74-639eab0c0000 pid=3243 execve guuid=f3922851-1800-0000-3b74-639eaf0c0000 pid=3247 /usr/bin/apt-config guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=f3922851-1800-0000-3b74-639eaf0c0000 pid=3247 execve guuid=20ac0458-1800-0000-3b74-639eb20c0000 pid=3250 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=20ac0458-1800-0000-3b74-639eb20c0000 pid=3250 clone guuid=91823258-1800-0000-3b74-639eb30c0000 pid=3251 /usr/bin/apt-config guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=91823258-1800-0000-3b74-639eb30c0000 pid=3251 execve guuid=4c3f9c59-1800-0000-3b74-639eb90c0000 pid=3257 /usr/bin/mktemp guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=4c3f9c59-1800-0000-3b74-639eb90c0000 pid=3257 execve guuid=2e46d259-1800-0000-3b74-639ebb0c0000 pid=3259 /usr/bin/chmod guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=2e46d259-1800-0000-3b74-639ebb0c0000 pid=3259 execve guuid=8cba025a-1800-0000-3b74-639ebd0c0000 pid=3261 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=8cba025a-1800-0000-3b74-639ebd0c0000 pid=3261 clone guuid=45ce155a-1800-0000-3b74-639ebe0c0000 pid=3262 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=45ce155a-1800-0000-3b74-639ebe0c0000 pid=3262 clone guuid=e897745a-1800-0000-3b74-639ec20c0000 pid=3266 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=e897745a-1800-0000-3b74-639ec20c0000 pid=3266 clone guuid=531d175b-1800-0000-3b74-639ec60c0000 pid=3270 /usr/bin/dash guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=531d175b-1800-0000-3b74-639ec60c0000 pid=3270 clone guuid=e3022a5b-1800-0000-3b74-639ec70c0000 pid=3271 /usr/bin/gpgv guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=e3022a5b-1800-0000-3b74-639ec70c0000 pid=3271 execve guuid=08687c5c-1800-0000-3b74-639ecd0c0000 pid=3277 /usr/bin/rm delete-file guuid=40201047-1800-0000-3b74-639e9c0c0000 pid=3228->guuid=08687c5c-1800-0000-3b74-639ecd0c0000 pid=3277 execve guuid=6e52f348-1800-0000-3b74-639ea10c0000 pid=3233 /usr/bin/dpkg guuid=adc94c47-1800-0000-3b74-639e9f0c0000 pid=3231->guuid=6e52f348-1800-0000-3b74-639ea10c0000 pid=3233 execve guuid=e21f3d4a-1800-0000-3b74-639ea80c0000 pid=3240 /usr/bin/dpkg guuid=6bfc5749-1800-0000-3b74-639ea40c0000 pid=3236->guuid=e21f3d4a-1800-0000-3b74-639ea80c0000 pid=3240 execve guuid=45d3fe4b-1800-0000-3b74-639eae0c0000 pid=3246 /usr/bin/dpkg guuid=c589b14a-1800-0000-3b74-639eab0c0000 pid=3243->guuid=45d3fe4b-1800-0000-3b74-639eae0c0000 pid=3246 execve guuid=d075eb52-1800-0000-3b74-639eb00c0000 pid=3248 /usr/bin/dpkg guuid=f3922851-1800-0000-3b74-639eaf0c0000 pid=3247->guuid=d075eb52-1800-0000-3b74-639eb00c0000 pid=3248 execve guuid=a4452459-1800-0000-3b74-639eb70c0000 pid=3255 /usr/bin/dpkg guuid=91823258-1800-0000-3b74-639eb30c0000 pid=3251->guuid=a4452459-1800-0000-3b74-639eb70c0000 pid=3255 execve guuid=eca7205a-1800-0000-3b74-639ebf0c0000 pid=3263 /usr/bin/dash guuid=45ce155a-1800-0000-3b74-639ebe0c0000 pid=3262->guuid=eca7205a-1800-0000-3b74-639ebf0c0000 pid=3263 clone guuid=bd59255a-1800-0000-3b74-639ec00c0000 pid=3264 /usr/bin/sed guuid=45ce155a-1800-0000-3b74-639ebe0c0000 pid=3262->guuid=bd59255a-1800-0000-3b74-639ec00c0000 pid=3264 execve guuid=176e7d5a-1800-0000-3b74-639ec30c0000 pid=3267 /usr/bin/dash guuid=e897745a-1800-0000-3b74-639ec20c0000 pid=3266->guuid=176e7d5a-1800-0000-3b74-639ec30c0000 pid=3267 clone guuid=9fa8825a-1800-0000-3b74-639ec40c0000 pid=3268 /usr/bin/sed guuid=e897745a-1800-0000-3b74-639ec20c0000 pid=3266->guuid=9fa8825a-1800-0000-3b74-639ec40c0000 pid=3268 execve guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280 /usr/bin/apt-key write-file guuid=08b03a5d-1800-0000-3b74-639ecf0c0000 pid=3279->guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280 execve guuid=87696e5e-1800-0000-3b74-639ed10c0000 pid=3281 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=87696e5e-1800-0000-3b74-639ed10c0000 pid=3281 clone guuid=e8758a5e-1800-0000-3b74-639ed20c0000 pid=3282 /usr/bin/apt-config guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=e8758a5e-1800-0000-3b74-639ed20c0000 pid=3282 execve guuid=a5e04060-1800-0000-3b74-639ed90c0000 pid=3289 /usr/bin/apt-config guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=a5e04060-1800-0000-3b74-639ed90c0000 pid=3289 execve guuid=a2440662-1800-0000-3b74-639edd0c0000 pid=3293 /usr/bin/apt-config guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=a2440662-1800-0000-3b74-639edd0c0000 pid=3293 execve guuid=b3139f63-1800-0000-3b74-639edf0c0000 pid=3295 /usr/bin/apt-config guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=b3139f63-1800-0000-3b74-639edf0c0000 pid=3295 execve guuid=0e21a165-1800-0000-3b74-639ee20c0000 pid=3298 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=0e21a165-1800-0000-3b74-639ee20c0000 pid=3298 clone guuid=3ad3cb65-1800-0000-3b74-639ee30c0000 pid=3299 /usr/bin/apt-config guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=3ad3cb65-1800-0000-3b74-639ee30c0000 pid=3299 execve guuid=1b880a68-1800-0000-3b74-639ee70c0000 pid=3303 /usr/bin/mktemp guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=1b880a68-1800-0000-3b74-639ee70c0000 pid=3303 execve guuid=45303768-1800-0000-3b74-639ee80c0000 pid=3304 /usr/bin/chmod guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=45303768-1800-0000-3b74-639ee80c0000 pid=3304 execve guuid=3f276068-1800-0000-3b74-639ee90c0000 pid=3305 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=3f276068-1800-0000-3b74-639ee90c0000 pid=3305 clone guuid=ca9d6c68-1800-0000-3b74-639eeb0c0000 pid=3307 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=ca9d6c68-1800-0000-3b74-639eeb0c0000 pid=3307 clone guuid=f4ebef68-1800-0000-3b74-639ef00c0000 pid=3312 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=f4ebef68-1800-0000-3b74-639ef00c0000 pid=3312 clone guuid=a8645369-1800-0000-3b74-639ef40c0000 pid=3316 /usr/bin/dash guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=a8645369-1800-0000-3b74-639ef40c0000 pid=3316 clone guuid=ce4d6469-1800-0000-3b74-639ef50c0000 pid=3317 /usr/bin/gpgv guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=ce4d6469-1800-0000-3b74-639ef50c0000 pid=3317 execve guuid=adf9ba6a-1800-0000-3b74-639efa0c0000 pid=3322 /usr/bin/rm delete-file guuid=e2e22a5e-1800-0000-3b74-639ed00c0000 pid=3280->guuid=adf9ba6a-1800-0000-3b74-639efa0c0000 pid=3322 execve guuid=77c4735f-1800-0000-3b74-639ed50c0000 pid=3285 /usr/bin/dpkg guuid=e8758a5e-1800-0000-3b74-639ed20c0000 pid=3282->guuid=77c4735f-1800-0000-3b74-639ed50c0000 pid=3285 execve guuid=401a4e61-1800-0000-3b74-639edb0c0000 pid=3291 /usr/bin/dpkg guuid=a5e04060-1800-0000-3b74-639ed90c0000 pid=3289->guuid=401a4e61-1800-0000-3b74-639edb0c0000 pid=3291 execve guuid=fadcf662-1800-0000-3b74-639ede0c0000 pid=3294 /usr/bin/dpkg guuid=a2440662-1800-0000-3b74-639edd0c0000 pid=3293->guuid=fadcf662-1800-0000-3b74-639ede0c0000 pid=3294 execve guuid=b885b664-1800-0000-3b74-639ee00c0000 pid=3296 /usr/bin/dpkg guuid=b3139f63-1800-0000-3b74-639edf0c0000 pid=3295->guuid=b885b664-1800-0000-3b74-639ee00c0000 pid=3296 execve guuid=74f32767-1800-0000-3b74-639ee50c0000 pid=3301 /usr/bin/dpkg guuid=3ad3cb65-1800-0000-3b74-639ee30c0000 pid=3299->guuid=74f32767-1800-0000-3b74-639ee50c0000 pid=3301 execve guuid=caee7168-1800-0000-3b74-639eec0c0000 pid=3308 /usr/bin/dash guuid=ca9d6c68-1800-0000-3b74-639eeb0c0000 pid=3307->guuid=caee7168-1800-0000-3b74-639eec0c0000 pid=3308 clone guuid=e01e7668-1800-0000-3b74-639eed0c0000 pid=3309 /usr/bin/sed guuid=ca9d6c68-1800-0000-3b74-639eeb0c0000 pid=3307->guuid=e01e7668-1800-0000-3b74-639eed0c0000 pid=3309 execve guuid=7d62f968-1800-0000-3b74-639ef10c0000 pid=3313 /usr/bin/dash guuid=f4ebef68-1800-0000-3b74-639ef00c0000 pid=3312->guuid=7d62f968-1800-0000-3b74-639ef10c0000 pid=3313 clone guuid=8c43fe68-1800-0000-3b74-639ef20c0000 pid=3314 /usr/bin/sed guuid=f4ebef68-1800-0000-3b74-639ef00c0000 pid=3312->guuid=8c43fe68-1800-0000-3b74-639ef20c0000 pid=3314 execve guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328 /usr/bin/apt-key write-file guuid=0362786b-1800-0000-3b74-639efd0c0000 pid=3325->guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328 execve guuid=33fe3b6c-1800-0000-3b74-639e020d0000 pid=3330 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=33fe3b6c-1800-0000-3b74-639e020d0000 pid=3330 clone guuid=0e524c6c-1800-0000-3b74-639e030d0000 pid=3331 /usr/bin/apt-config guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=0e524c6c-1800-0000-3b74-639e030d0000 pid=3331 execve guuid=b7d21b6e-1800-0000-3b74-639e0a0d0000 pid=3338 /usr/bin/apt-config guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=b7d21b6e-1800-0000-3b74-639e0a0d0000 pid=3338 execve guuid=06e0666f-1800-0000-3b74-639e0e0d0000 pid=3342 /usr/bin/apt-config guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=06e0666f-1800-0000-3b74-639e0e0d0000 pid=3342 execve guuid=a2859b70-1800-0000-3b74-639e100d0000 pid=3344 /usr/bin/apt-config guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=a2859b70-1800-0000-3b74-639e100d0000 pid=3344 execve guuid=120deb71-1800-0000-3b74-639e120d0000 pid=3346 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=120deb71-1800-0000-3b74-639e120d0000 pid=3346 clone guuid=75cd1572-1800-0000-3b74-639e130d0000 pid=3347 /usr/bin/apt-config guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=75cd1572-1800-0000-3b74-639e130d0000 pid=3347 execve guuid=039f3b73-1800-0000-3b74-639e150d0000 pid=3349 /usr/bin/mktemp guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=039f3b73-1800-0000-3b74-639e150d0000 pid=3349 execve guuid=dfc06d73-1800-0000-3b74-639e160d0000 pid=3350 /usr/bin/chmod guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=dfc06d73-1800-0000-3b74-639e160d0000 pid=3350 execve guuid=540b3074-1800-0000-3b74-639e170d0000 pid=3351 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=540b3074-1800-0000-3b74-639e170d0000 pid=3351 clone guuid=a2ab4474-1800-0000-3b74-639e180d0000 pid=3352 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=a2ab4474-1800-0000-3b74-639e180d0000 pid=3352 clone guuid=13edc974-1800-0000-3b74-639e1b0d0000 pid=3355 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=13edc974-1800-0000-3b74-639e1b0d0000 pid=3355 clone guuid=e5374d75-1800-0000-3b74-639e1e0d0000 pid=3358 /usr/bin/dash guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=e5374d75-1800-0000-3b74-639e1e0d0000 pid=3358 clone guuid=1cf06175-1800-0000-3b74-639e1f0d0000 pid=3359 /usr/bin/gpgv guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=1cf06175-1800-0000-3b74-639e1f0d0000 pid=3359 execve guuid=a1289c77-1800-0000-3b74-639e200d0000 pid=3360 /usr/bin/rm delete-file guuid=a393076c-1800-0000-3b74-639e000d0000 pid=3328->guuid=a1289c77-1800-0000-3b74-639e200d0000 pid=3360 execve guuid=1c59c36d-1800-0000-3b74-639e080d0000 pid=3336 /usr/bin/dpkg guuid=0e524c6c-1800-0000-3b74-639e030d0000 pid=3331->guuid=1c59c36d-1800-0000-3b74-639e080d0000 pid=3336 execve guuid=ca5d036f-1800-0000-3b74-639e0d0d0000 pid=3341 /usr/bin/dpkg guuid=b7d21b6e-1800-0000-3b74-639e0a0d0000 pid=3338->guuid=ca5d036f-1800-0000-3b74-639e0d0d0000 pid=3341 execve guuid=39b33d70-1800-0000-3b74-639e0f0d0000 pid=3343 /usr/bin/dpkg guuid=06e0666f-1800-0000-3b74-639e0e0d0000 pid=3342->guuid=39b33d70-1800-0000-3b74-639e0f0d0000 pid=3343 execve guuid=4a267271-1800-0000-3b74-639e110d0000 pid=3345 /usr/bin/dpkg guuid=a2859b70-1800-0000-3b74-639e100d0000 pid=3344->guuid=4a267271-1800-0000-3b74-639e110d0000 pid=3345 execve guuid=fb1bde72-1800-0000-3b74-639e140d0000 pid=3348 /usr/bin/dpkg guuid=75cd1572-1800-0000-3b74-639e130d0000 pid=3347->guuid=fb1bde72-1800-0000-3b74-639e140d0000 pid=3348 execve guuid=245f4d74-1800-0000-3b74-639e190d0000 pid=3353 /usr/bin/dash guuid=a2ab4474-1800-0000-3b74-639e180d0000 pid=3352->guuid=245f4d74-1800-0000-3b74-639e190d0000 pid=3353 clone guuid=77335374-1800-0000-3b74-639e1a0d0000 pid=3354 /usr/bin/sed guuid=a2ab4474-1800-0000-3b74-639e180d0000 pid=3352->guuid=77335374-1800-0000-3b74-639e1a0d0000 pid=3354 execve guuid=9d34d574-1800-0000-3b74-639e1c0d0000 pid=3356 /usr/bin/dash guuid=13edc974-1800-0000-3b74-639e1b0d0000 pid=3355->guuid=9d34d574-1800-0000-3b74-639e1c0d0000 pid=3356 clone guuid=e256dc74-1800-0000-3b74-639e1d0d0000 pid=3357 /usr/bin/sed guuid=13edc974-1800-0000-3b74-639e1b0d0000 pid=3355->guuid=e256dc74-1800-0000-3b74-639e1d0d0000 pid=3357 execve guuid=490c1aaf-1900-0000-3b74-639e760f0000 pid=3958 /usr/bin/dpkg guuid=1f0a23ae-1900-0000-3b74-639e700f0000 pid=3952->guuid=490c1aaf-1900-0000-3b74-639e760f0000 pid=3958 execve
Threat name:
Text.Trojan.Generic
Status:
Suspicious
First seen:
2025-01-11 07:02:25 UTC
File Type:
Text (Shell)
AV detection:
3 of 24 (12.50%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion discovery execution linux persistence
Behaviour
Software Deployment Tools
Process Discovery
Reads runtime system information
Remote System Discovery
System Network Configuration Discovery
Writes file to tmp directory
Deobfuscate/Decode Files or Information
Changes its process name
Checks CPU configuration
Reads CPU attributes
Reads system network configuration
Deletes log files
Enumerates active TCP sockets
Enumerates running processes
Write file to user bin folder
Writes file to system bin folder
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh db7d35613111dbbdba0d349093986aa6788c9a50f1c88478960ee9732adbf278

(this sample)

  
Delivery method
Distributed via web download

Comments