MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 2 File information Comments

SHA256 hash: e41c635e4c3514e266d143d544ad1abde5db3dcfe6cccdf9bb7a218003f8ab6a
SHA3-384 hash: 2bfff486ba48316a195bd5909f01e0d668155f9cbd20f84288105aea1bba04d4c4f44ac1d724f6beda8610cea043aa1b
SHA1 hash: c2dd8051d89c4efa71bd67d2df7d9b4bc3e67810
MD5 hash: b8e7288656eca9750a5490aa96d3594b
humanhash: florida-kansas-spring-harry
File name:bootstrap.sh
Download: download sample
File size:8'167 bytes
First seen:2026-04-28 20:47:59 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 192:OPFbBHTK+gLZKa3+I2kesQGtMD4uVX2yR:OtbRbgLZKauIqGmD4QX2U
TLSH T140F186B67530D6703959D02CA347826095E7377BBC147888B0EEB968AFDF9486174F32
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter smica83
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
https://api.telegram.org/botn/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
59
Origin country :
HU HU
Vendor Threat Intelligence
No detections
Verdict:
Suspicious
Threat level:
  5/10
Confidence:
100%
Tags:
bash lolbin
Verdict:
Adware
File Type:
unix shell
First seen:
2026-02-16T03:21:00Z UTC
Last seen:
2026-04-30T03:00:00Z UTC
Hits:
~10
Detections:
not-a-virus:HEUR:Downloader.Shell.Miner.a
Status:
terminated
Behavior Graph:
%3 guuid=b016c9d6-1600-0000-7c33-d1288d0d0000 pid=3469 /usr/bin/sudo guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476 /tmp/sample.bin guuid=b016c9d6-1600-0000-7c33-d1288d0d0000 pid=3469->guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476 execve guuid=32e0f9d8-1600-0000-7c33-d128960d0000 pid=3478 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=32e0f9d8-1600-0000-7c33-d128960d0000 pid=3478 clone guuid=d145b1ec-1600-0000-7c33-d128b60d0000 pid=3510 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d145b1ec-1600-0000-7c33-d128b60d0000 pid=3510 execve guuid=0b9ef3ef-1600-0000-7c33-d128c00d0000 pid=3520 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=0b9ef3ef-1600-0000-7c33-d128c00d0000 pid=3520 execve guuid=a0937ff2-1600-0000-7c33-d128c80d0000 pid=3528 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=a0937ff2-1600-0000-7c33-d128c80d0000 pid=3528 execve guuid=d495d9f5-1600-0000-7c33-d128cc0d0000 pid=3532 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d495d9f5-1600-0000-7c33-d128cc0d0000 pid=3532 execve guuid=6c8e59f8-1600-0000-7c33-d128d60d0000 pid=3542 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=6c8e59f8-1600-0000-7c33-d128d60d0000 pid=3542 execve guuid=143eb5fa-1600-0000-7c33-d128e00d0000 pid=3552 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=143eb5fa-1600-0000-7c33-d128e00d0000 pid=3552 execve guuid=699207fd-1600-0000-7c33-d128e90d0000 pid=3561 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=699207fd-1600-0000-7c33-d128e90d0000 pid=3561 execve guuid=6996cf00-1700-0000-7c33-d128f00d0000 pid=3568 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=6996cf00-1700-0000-7c33-d128f00d0000 pid=3568 execve guuid=0fe15007-1700-0000-7c33-d128f90d0000 pid=3577 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=0fe15007-1700-0000-7c33-d128f90d0000 pid=3577 execve guuid=53a8260b-1700-0000-7c33-d128040e0000 pid=3588 /usr/bin/pgrep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=53a8260b-1700-0000-7c33-d128040e0000 pid=3588 execve guuid=671a0d0f-1700-0000-7c33-d1280f0e0000 pid=3599 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=671a0d0f-1700-0000-7c33-d1280f0e0000 pid=3599 execve guuid=9ca7a410-1700-0000-7c33-d128140e0000 pid=3604 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=9ca7a410-1700-0000-7c33-d128140e0000 pid=3604 execve guuid=6c7dc012-1700-0000-7c33-d1281b0e0000 pid=3611 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=6c7dc012-1700-0000-7c33-d1281b0e0000 pid=3611 execve guuid=0d9c1d13-1700-0000-7c33-d1281d0e0000 pid=3613 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=0d9c1d13-1700-0000-7c33-d1281d0e0000 pid=3613 execve guuid=726cc114-1700-0000-7c33-d128200e0000 pid=3616 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=726cc114-1700-0000-7c33-d128200e0000 pid=3616 execve guuid=7d138116-1700-0000-7c33-d128250e0000 pid=3621 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=7d138116-1700-0000-7c33-d128250e0000 pid=3621 execve guuid=c207e416-1700-0000-7c33-d128270e0000 pid=3623 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=c207e416-1700-0000-7c33-d128270e0000 pid=3623 execve guuid=99226d18-1700-0000-7c33-d1282f0e0000 pid=3631 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=99226d18-1700-0000-7c33-d1282f0e0000 pid=3631 execve guuid=573df11a-1700-0000-7c33-d128360e0000 pid=3638 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=573df11a-1700-0000-7c33-d128360e0000 pid=3638 execve guuid=cf28491b-1700-0000-7c33-d1283a0e0000 pid=3642 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=cf28491b-1700-0000-7c33-d1283a0e0000 pid=3642 execve guuid=4b27c11c-1700-0000-7c33-d128400e0000 pid=3648 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=4b27c11c-1700-0000-7c33-d128400e0000 pid=3648 execve guuid=f35a3e1e-1700-0000-7c33-d128460e0000 pid=3654 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=f35a3e1e-1700-0000-7c33-d128460e0000 pid=3654 execve guuid=50307f1e-1700-0000-7c33-d128480e0000 pid=3656 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=50307f1e-1700-0000-7c33-d128480e0000 pid=3656 execve guuid=74bf951f-1700-0000-7c33-d128500e0000 pid=3664 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=74bf951f-1700-0000-7c33-d128500e0000 pid=3664 execve guuid=d32ae620-1700-0000-7c33-d128550e0000 pid=3669 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d32ae620-1700-0000-7c33-d128550e0000 pid=3669 execve guuid=31311f21-1700-0000-7c33-d128570e0000 pid=3671 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=31311f21-1700-0000-7c33-d128570e0000 pid=3671 execve guuid=d23c2722-1700-0000-7c33-d1285d0e0000 pid=3677 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d23c2722-1700-0000-7c33-d1285d0e0000 pid=3677 execve guuid=b4a49c23-1700-0000-7c33-d128640e0000 pid=3684 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b4a49c23-1700-0000-7c33-d128640e0000 pid=3684 execve guuid=a345dd23-1700-0000-7c33-d128660e0000 pid=3686 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=a345dd23-1700-0000-7c33-d128660e0000 pid=3686 execve guuid=544b0b25-1700-0000-7c33-d128690e0000 pid=3689 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=544b0b25-1700-0000-7c33-d128690e0000 pid=3689 execve guuid=1c4f7126-1700-0000-7c33-d128710e0000 pid=3697 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=1c4f7126-1700-0000-7c33-d128710e0000 pid=3697 execve guuid=3e79b126-1700-0000-7c33-d128730e0000 pid=3699 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=3e79b126-1700-0000-7c33-d128730e0000 pid=3699 execve guuid=9080f226-1700-0000-7c33-d128750e0000 pid=3701 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=9080f226-1700-0000-7c33-d128750e0000 pid=3701 execve guuid=969c3027-1700-0000-7c33-d128770e0000 pid=3703 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=969c3027-1700-0000-7c33-d128770e0000 pid=3703 execve guuid=d9ef6e27-1700-0000-7c33-d128790e0000 pid=3705 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d9ef6e27-1700-0000-7c33-d128790e0000 pid=3705 execve guuid=772daf27-1700-0000-7c33-d1287b0e0000 pid=3707 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=772daf27-1700-0000-7c33-d1287b0e0000 pid=3707 execve guuid=b04af327-1700-0000-7c33-d1287c0e0000 pid=3708 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b04af327-1700-0000-7c33-d1287c0e0000 pid=3708 execve guuid=2c593828-1700-0000-7c33-d128800e0000 pid=3712 /usr/bin/rm guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=2c593828-1700-0000-7c33-d128800e0000 pid=3712 execve guuid=ea647f28-1700-0000-7c33-d128820e0000 pid=3714 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=ea647f28-1700-0000-7c33-d128820e0000 pid=3714 clone guuid=c11a8a28-1700-0000-7c33-d128840e0000 pid=3716 /usr/bin/grep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=c11a8a28-1700-0000-7c33-d128840e0000 pid=3716 execve guuid=e3269628-1700-0000-7c33-d128860e0000 pid=3718 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=e3269628-1700-0000-7c33-d128860e0000 pid=3718 clone guuid=4d3ded28-1700-0000-7c33-d128870e0000 pid=3719 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=4d3ded28-1700-0000-7c33-d128870e0000 pid=3719 execve guuid=ef86275a-1700-0000-7c33-d128620f0000 pid=3938 /usr/bin/python3.11 guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=ef86275a-1700-0000-7c33-d128620f0000 pid=3938 execve guuid=b211135d-1700-0000-7c33-d1286f0f0000 pid=3951 /usr/bin/mkdir guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b211135d-1700-0000-7c33-d1286f0f0000 pid=3951 execve guuid=2b7d595d-1700-0000-7c33-d128710f0000 pid=3953 /usr/bin/python3.11 write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=2b7d595d-1700-0000-7c33-d128710f0000 pid=3953 execve guuid=eff11476-1700-0000-7c33-d128c10f0000 pid=4033 /usr/bin/apt-get guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=eff11476-1700-0000-7c33-d128c10f0000 pid=4033 execve guuid=8ca89b7c-1700-0000-7c33-d128d90f0000 pid=4057 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=8ca89b7c-1700-0000-7c33-d128d90f0000 pid=4057 clone guuid=ce82b37c-1700-0000-7c33-d128da0f0000 pid=4058 /usr/bin/rm delete-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=ce82b37c-1700-0000-7c33-d128da0f0000 pid=4058 execve guuid=cdce0e7d-1700-0000-7c33-d128de0f0000 pid=4062 /usr/bin/python3.11 write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=cdce0e7d-1700-0000-7c33-d128de0f0000 pid=4062 execve guuid=a3b9e087-1700-0000-7c33-d1280c100000 pid=4108 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=a3b9e087-1700-0000-7c33-d1280c100000 pid=4108 clone guuid=4c160188-1700-0000-7c33-d1280e100000 pid=4110 /usr/bin/rm delete-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=4c160188-1700-0000-7c33-d1280e100000 pid=4110 execve guuid=b8a46188-1700-0000-7c33-d12810100000 pid=4112 /usr/bin/python3.11 guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b8a46188-1700-0000-7c33-d12810100000 pid=4112 execve guuid=e9c5178b-1700-0000-7c33-d1281c100000 pid=4124 /usr/bin/mkdir guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=e9c5178b-1700-0000-7c33-d1281c100000 pid=4124 execve guuid=80ef618b-1700-0000-7c33-d12820100000 pid=4128 /usr/bin/which.debianutils guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=80ef618b-1700-0000-7c33-d12820100000 pid=4128 execve guuid=b6f8b58b-1700-0000-7c33-d12824100000 pid=4132 /usr/bin/ln guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b6f8b58b-1700-0000-7c33-d12824100000 pid=4132 execve guuid=aa84f38b-1700-0000-7c33-d12825100000 pid=4133 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=aa84f38b-1700-0000-7c33-d12825100000 pid=4133 clone guuid=7aa3088c-1700-0000-7c33-d12827100000 pid=4135 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=7aa3088c-1700-0000-7c33-d12827100000 pid=4135 clone guuid=03e0208c-1700-0000-7c33-d12828100000 pid=4136 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=03e0208c-1700-0000-7c33-d12828100000 pid=4136 execve guuid=d9f2c903-1800-0000-7c33-d1287f110000 pid=4479 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d9f2c903-1800-0000-7c33-d1287f110000 pid=4479 clone guuid=2765e203-1800-0000-7c33-d12880110000 pid=4480 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=2765e203-1800-0000-7c33-d12880110000 pid=4480 clone guuid=406bf703-1800-0000-7c33-d12881110000 pid=4481 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=406bf703-1800-0000-7c33-d12881110000 pid=4481 execve guuid=18dcbcf2-1800-0000-7c33-d12849140000 pid=5193 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=18dcbcf2-1800-0000-7c33-d12849140000 pid=5193 clone guuid=d987f2f2-1800-0000-7c33-d1284b140000 pid=5195 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d987f2f2-1800-0000-7c33-d1284b140000 pid=5195 clone guuid=e13e20f3-1800-0000-7c33-d1284c140000 pid=5196 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=e13e20f3-1800-0000-7c33-d1284c140000 pid=5196 execve guuid=256e5a59-1a00-0000-7c33-d128c7140000 pid=5319 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=256e5a59-1a00-0000-7c33-d128c7140000 pid=5319 clone guuid=d4f59c59-1a00-0000-7c33-d128c8140000 pid=5320 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d4f59c59-1a00-0000-7c33-d128c8140000 pid=5320 clone guuid=fbb6bc59-1a00-0000-7c33-d128c9140000 pid=5321 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=fbb6bc59-1a00-0000-7c33-d128c9140000 pid=5321 execve guuid=83b664d1-1a00-0000-7c33-d128ca140000 pid=5322 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=83b664d1-1a00-0000-7c33-d128ca140000 pid=5322 clone guuid=13ee9cd1-1a00-0000-7c33-d128cb140000 pid=5323 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=13ee9cd1-1a00-0000-7c33-d128cb140000 pid=5323 clone guuid=12bcccd1-1a00-0000-7c33-d128cc140000 pid=5324 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=12bcccd1-1a00-0000-7c33-d128cc140000 pid=5324 execve guuid=a75ab0c0-1b00-0000-7c33-d128ed140000 pid=5357 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=a75ab0c0-1b00-0000-7c33-d128ed140000 pid=5357 clone guuid=69bbecc0-1b00-0000-7c33-d128ee140000 pid=5358 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=69bbecc0-1b00-0000-7c33-d128ee140000 pid=5358 clone guuid=f8c519c1-1b00-0000-7c33-d128ef140000 pid=5359 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=f8c519c1-1b00-0000-7c33-d128ef140000 pid=5359 execve guuid=80535b27-1d00-0000-7c33-d128f0140000 pid=5360 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=80535b27-1d00-0000-7c33-d128f0140000 pid=5360 clone guuid=1a9a7327-1d00-0000-7c33-d128f1140000 pid=5361 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=1a9a7327-1d00-0000-7c33-d128f1140000 pid=5361 clone guuid=94068d27-1d00-0000-7c33-d128f2140000 pid=5362 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=94068d27-1d00-0000-7c33-d128f2140000 pid=5362 execve guuid=eb19199f-1d00-0000-7c33-d128f3140000 pid=5363 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=eb19199f-1d00-0000-7c33-d128f3140000 pid=5363 clone guuid=b253379f-1d00-0000-7c33-d128f4140000 pid=5364 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=b253379f-1d00-0000-7c33-d128f4140000 pid=5364 clone guuid=02bd519f-1d00-0000-7c33-d128f5140000 pid=5365 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=02bd519f-1d00-0000-7c33-d128f5140000 pid=5365 execve guuid=0735288e-1e00-0000-7c33-d128f6140000 pid=5366 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=0735288e-1e00-0000-7c33-d128f6140000 pid=5366 clone guuid=0283748e-1e00-0000-7c33-d128f7140000 pid=5367 /usr/bin/bash guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=0283748e-1e00-0000-7c33-d128f7140000 pid=5367 clone guuid=5223ab8e-1e00-0000-7c33-d128f8140000 pid=5368 /usr/bin/sleep guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=5223ab8e-1e00-0000-7c33-d128f8140000 pid=5368 execve guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5369 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5369 execve guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5371 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5371 execve guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5373 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5373 execve guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5375 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5375 execve guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5377 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5377 execve guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5379 /usr/bin/curl net send-data write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5379 execve guuid=55b232ae-2000-0000-7c33-d12805150000 pid=5381 /usr/bin/python3.11 write-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=55b232ae-2000-0000-7c33-d12805150000 pid=5381 execve guuid=17c1d8b2-2000-0000-7c33-d12806150000 pid=5382 /usr/bin/id guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=17c1d8b2-2000-0000-7c33-d12806150000 pid=5382 execve guuid=1014f7b3-2000-0000-7c33-d12807150000 pid=5383 /usr/bin/cat write-config guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=1014f7b3-2000-0000-7c33-d12807150000 pid=5383 execve guuid=8cde6fb4-2000-0000-7c33-d12808150000 pid=5384 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=8cde6fb4-2000-0000-7c33-d12808150000 pid=5384 execve guuid=c77a5bd5-2000-0000-7c33-d1281d150000 pid=5405 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=c77a5bd5-2000-0000-7c33-d1281d150000 pid=5405 execve guuid=98d45ff4-2000-0000-7c33-d12832150000 pid=5426 /usr/bin/systemctl guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=98d45ff4-2000-0000-7c33-d12832150000 pid=5426 execve guuid=947f3df7-2000-0000-7c33-d12834150000 pid=5428 /usr/bin/rm delete-file guuid=1462a9d8-1600-0000-7c33-d128940d0000 pid=3476->guuid=947f3df7-2000-0000-7c33-d12834150000 pid=5428 execve guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3479 /usr/bin/curl net send-data guuid=32e0f9d8-1600-0000-7c33-d128960d0000 pid=3478->guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3479 execve e1f9bcbd-fc59-5429-9359-3d4eca276af4 ifconfig.me:80 guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3479->e1f9bcbd-fc59-5429-9359-3d4eca276af4 send: 75B guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3488 /usr/bin/curl dns net send-data guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3479->guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3488 clone guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3488->e1f9bcbd-fc59-5429-9359-3d4eca276af4 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=5d7908d9-1600-0000-7c33-d128970d0000 pid=3488->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 58B guuid=068c126b-1700-0000-7c33-d128a70f0000 pid=4007 /usr/bin/python3.11 guuid=2b7d595d-1700-0000-7c33-d128710f0000 pid=3953->guuid=068c126b-1700-0000-7c33-d128a70f0000 pid=4007 execve guuid=38f1d277-1700-0000-7c33-d128c90f0000 pid=4041 /usr/bin/dpkg guuid=eff11476-1700-0000-7c33-d128c10f0000 pid=4033->guuid=38f1d277-1700-0000-7c33-d128c90f0000 pid=4041 execve guuid=14990883-1700-0000-7c33-d128f80f0000 pid=4088 /usr/bin/python3.11 guuid=cdce0e7d-1700-0000-7c33-d128de0f0000 pid=4062->guuid=14990883-1700-0000-7c33-d128f80f0000 pid=4088 execve e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f s3-r-w.us-east-2.amazonaws.com:443 guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5369->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 749B guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5370 /usr/bin/curl dns net send-data guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5369->guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5370 clone guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5370->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=732bfef4-1f00-0000-7c33-d128f9140000 pid=5370->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5371->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 751B guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5372 /usr/bin/curl dns net send-data guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5371->guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5372 clone guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5372->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=681eb21e-2000-0000-7c33-d128fb140000 pid=5372->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5373->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 752B guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5374 /usr/bin/curl dns net send-data guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5373->guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5374 clone guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5374->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=d785133b-2000-0000-7c33-d128fd140000 pid=5374->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5375->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 756B guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5376 /usr/bin/curl dns net send-data guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5375->guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5376 clone guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5376->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=9e35ec5d-2000-0000-7c33-d128ff140000 pid=5376->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5377->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 757B guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5378 /usr/bin/curl dns net send-data guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5377->guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5378 clone guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5378->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=7cde5278-2000-0000-7c33-d12801150000 pid=5378->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5379->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f send: 755B guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5380 /usr/bin/curl dns net send-data guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5379->guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5380 clone guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5380->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 138B guuid=f58c5a93-2000-0000-7c33-d12803150000 pid=5380->e30cc7d4-7cb1-5fe1-b87f-9b4152a4b27f con
Result
Malware family:
n/a
Score:
  9/10
Tags:
antivm credential_access defense_evasion discovery execution linux persistence privilege_escalation ransomware
Behaviour
Software Deployment Tools
Command and Scripting Interpreter: Python
Command and Scripting Interpreter: Unix Shell
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
Changes its process name
Checks CPU configuration
Reads CPU attributes
Creates/modifies Cron job
Deletes log files
Enumerates running processes
Looks up external IP address via web service
Modifies systemd
Write file to user bin folder
Executes dropped EXE
OS Credential Dumping
Renames multiple (96) files with added filename extension
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:telebot_framework
Author:vietdx.mb
Rule name:telegram_bot_api
Author:rectifyq
Description:Detects file containing Telegram Bot API

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments