MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f29f960878e8dcf72d02f9a7e3e7b5de4fc20b00a079f2571a70e6d63edae050. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA File information Comments

SHA256 hash: f29f960878e8dcf72d02f9a7e3e7b5de4fc20b00a079f2571a70e6d63edae050
SHA3-384 hash: 50099e7062153013b337294ebfc306ac483dc122cabe521dc476460403aef9e1edd6b3099189cf7f4efb0ba19c2cb566
SHA1 hash: 6cf06d65a5ec0c536a7726b7376e10996ec6d896
MD5 hash: 99f3711e7698b0d5f83efd1c16a6dcf7
humanhash: fix-california-wyoming-autumn
File name:run.sh
Download: download sample
File size:748 bytes
First seen:2026-05-31 07:44:22 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 12:Izzfsx80+asLeHt4LZ/uPfFFHsFQzBct7j3FAVkVFhx:o5TaVHt4LUnF1GQzqt7phx
TLSH T10201999B61B0AC3068758A3CFD9786A0104714176804190D709F6E04EF2CA4CF6A1656
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter BlinkzSec

Intelligence


File Origin
# of uploads :
1
# of downloads :
48
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-05-21T19:56:00Z UTC
Last seen:
2026-05-31T06:58:00Z UTC
Hits:
~100
Detections:
HEUR:Trojan-Downloader.Shell.Agent.bc
Status:
terminated
Behavior Graph:
%3 guuid=2d193d78-1a00-0000-cbfd-32512c0b0000 pid=2860 /usr/bin/sudo guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866 /tmp/sample.bin guuid=2d193d78-1a00-0000-cbfd-32512c0b0000 pid=2860->guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866 execve guuid=733a3d7c-1a00-0000-cbfd-3251330b0000 pid=2867 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=733a3d7c-1a00-0000-cbfd-3251330b0000 pid=2867 clone guuid=da6f437d-1a00-0000-cbfd-3251380b0000 pid=2872 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=da6f437d-1a00-0000-cbfd-3251380b0000 pid=2872 execve guuid=b7a9cbaf-1a00-0000-cbfd-3251820b0000 pid=2946 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=b7a9cbaf-1a00-0000-cbfd-3251820b0000 pid=2946 execve guuid=71293fb0-1a00-0000-cbfd-3251840b0000 pid=2948 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=71293fb0-1a00-0000-cbfd-3251840b0000 pid=2948 clone guuid=068b50b0-1a00-0000-cbfd-3251860b0000 pid=2950 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=068b50b0-1a00-0000-cbfd-3251860b0000 pid=2950 execve guuid=a95dfab0-1a00-0000-cbfd-3251890b0000 pid=2953 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=a95dfab0-1a00-0000-cbfd-3251890b0000 pid=2953 clone guuid=a44decb1-1a00-0000-cbfd-32518e0b0000 pid=2958 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=a44decb1-1a00-0000-cbfd-32518e0b0000 pid=2958 execve guuid=5c4147d7-1a00-0000-cbfd-3251d10b0000 pid=3025 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=5c4147d7-1a00-0000-cbfd-3251d10b0000 pid=3025 execve guuid=81ec97d7-1a00-0000-cbfd-3251d30b0000 pid=3027 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=81ec97d7-1a00-0000-cbfd-3251d30b0000 pid=3027 clone guuid=b9569cd7-1a00-0000-cbfd-3251d40b0000 pid=3028 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=b9569cd7-1a00-0000-cbfd-3251d40b0000 pid=3028 execve guuid=e0bfd3d7-1a00-0000-cbfd-3251d70b0000 pid=3031 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=e0bfd3d7-1a00-0000-cbfd-3251d70b0000 pid=3031 clone guuid=6a555fd8-1a00-0000-cbfd-3251dc0b0000 pid=3036 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=6a555fd8-1a00-0000-cbfd-3251dc0b0000 pid=3036 execve guuid=a06e26fa-1a00-0000-cbfd-32512c0c0000 pid=3116 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=a06e26fa-1a00-0000-cbfd-32512c0c0000 pid=3116 execve guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118 /tmp/ubq1ni guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118 execve guuid=66e697fa-1a00-0000-cbfd-32512f0c0000 pid=3119 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=66e697fa-1a00-0000-cbfd-32512f0c0000 pid=3119 execve guuid=d649d9fa-1a00-0000-cbfd-3251310c0000 pid=3121 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=d649d9fa-1a00-0000-cbfd-3251310c0000 pid=3121 clone guuid=dfc1c1fb-1a00-0000-cbfd-3251370c0000 pid=3127 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=dfc1c1fb-1a00-0000-cbfd-3251370c0000 pid=3127 execve guuid=edd5311e-1b00-0000-cbfd-3251810c0000 pid=3201 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=edd5311e-1b00-0000-cbfd-3251810c0000 pid=3201 execve guuid=52e69b1e-1b00-0000-cbfd-3251830c0000 pid=3203 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=52e69b1e-1b00-0000-cbfd-3251830c0000 pid=3203 clone guuid=fed99f1e-1b00-0000-cbfd-3251840c0000 pid=3204 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=fed99f1e-1b00-0000-cbfd-3251840c0000 pid=3204 execve guuid=ba3d271f-1b00-0000-cbfd-3251880c0000 pid=3208 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=ba3d271f-1b00-0000-cbfd-3251880c0000 pid=3208 clone guuid=eaf0e91f-1b00-0000-cbfd-32518e0c0000 pid=3214 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=eaf0e91f-1b00-0000-cbfd-32518e0c0000 pid=3214 execve guuid=d3a10c56-1b00-0000-cbfd-3251ab0c0000 pid=3243 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=d3a10c56-1b00-0000-cbfd-3251ab0c0000 pid=3243 execve guuid=6b737356-1b00-0000-cbfd-3251ad0c0000 pid=3245 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=6b737356-1b00-0000-cbfd-3251ad0c0000 pid=3245 clone guuid=a1f47856-1b00-0000-cbfd-3251ae0c0000 pid=3246 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=a1f47856-1b00-0000-cbfd-3251ae0c0000 pid=3246 execve guuid=7e2bc056-1b00-0000-cbfd-3251b00c0000 pid=3248 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=7e2bc056-1b00-0000-cbfd-3251b00c0000 pid=3248 clone guuid=88b3c357-1b00-0000-cbfd-3251b70c0000 pid=3255 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=88b3c357-1b00-0000-cbfd-3251b70c0000 pid=3255 execve guuid=515b6e86-1b00-0000-cbfd-3251ec0c0000 pid=3308 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=515b6e86-1b00-0000-cbfd-3251ec0c0000 pid=3308 execve guuid=5918c186-1b00-0000-cbfd-3251ed0c0000 pid=3309 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=5918c186-1b00-0000-cbfd-3251ed0c0000 pid=3309 clone guuid=b886c986-1b00-0000-cbfd-3251ee0c0000 pid=3310 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=b886c986-1b00-0000-cbfd-3251ee0c0000 pid=3310 execve guuid=b70b1a87-1b00-0000-cbfd-3251f10c0000 pid=3313 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=b70b1a87-1b00-0000-cbfd-3251f10c0000 pid=3313 clone guuid=bee0e087-1b00-0000-cbfd-3251f70c0000 pid=3319 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=bee0e087-1b00-0000-cbfd-3251f70c0000 pid=3319 execve guuid=54b74cac-1b00-0000-cbfd-3251460d0000 pid=3398 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=54b74cac-1b00-0000-cbfd-3251460d0000 pid=3398 execve guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400 /tmp/4jq3g7 guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400 execve guuid=bfb3f1ac-1b00-0000-cbfd-3251490d0000 pid=3401 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=bfb3f1ac-1b00-0000-cbfd-3251490d0000 pid=3401 execve guuid=34e573ad-1b00-0000-cbfd-32514b0d0000 pid=3403 /usr/bin/dash guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=34e573ad-1b00-0000-cbfd-32514b0d0000 pid=3403 clone guuid=9dac5eaf-1b00-0000-cbfd-3251510d0000 pid=3409 /usr/bin/wget net send-data write-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=9dac5eaf-1b00-0000-cbfd-3251510d0000 pid=3409 execve guuid=a89395d4-1b00-0000-cbfd-32517f0d0000 pid=3455 /usr/bin/chmod guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=a89395d4-1b00-0000-cbfd-32517f0d0000 pid=3455 execve guuid=75ba20d5-1b00-0000-cbfd-3251810d0000 pid=3457 /usr/bin/dash zombie guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=75ba20d5-1b00-0000-cbfd-3251810d0000 pid=3457 clone guuid=f66c27d5-1b00-0000-cbfd-3251820d0000 pid=3458 /usr/bin/rm delete-file guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=f66c27d5-1b00-0000-cbfd-3251820d0000 pid=3458 execve guuid=17cf05d6-1b00-0000-cbfd-3251860d0000 pid=3462 /usr/bin/rm delete-file zombie guuid=c38caf7b-1a00-0000-cbfd-3251320b0000 pid=2866->guuid=17cf05d6-1b00-0000-cbfd-3251860d0000 pid=3462 execve guuid=a9ec527c-1a00-0000-cbfd-3251340b0000 pid=2868 /usr/bin/head guuid=733a3d7c-1a00-0000-cbfd-3251330b0000 pid=2867->guuid=a9ec527c-1a00-0000-cbfd-3251340b0000 pid=2868 execve guuid=6c845d7c-1a00-0000-cbfd-3251350b0000 pid=2869 /usr/bin/tr guuid=733a3d7c-1a00-0000-cbfd-3251330b0000 pid=2867->guuid=6c845d7c-1a00-0000-cbfd-3251350b0000 pid=2869 execve guuid=dc1b697c-1a00-0000-cbfd-3251360b0000 pid=2870 /usr/bin/head guuid=733a3d7c-1a00-0000-cbfd-3251330b0000 pid=2867->guuid=dc1b697c-1a00-0000-cbfd-3251360b0000 pid=2870 execve 10dbcbef-d840-53b3-a06d-d8ede6d0e936 103.83.87.122:80 guuid=da6f437d-1a00-0000-cbfd-3251380b0000 pid=2872->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 132B guuid=ea4101b1-1a00-0000-cbfd-32518a0b0000 pid=2954 /usr/bin/head guuid=a95dfab0-1a00-0000-cbfd-3251890b0000 pid=2953->guuid=ea4101b1-1a00-0000-cbfd-32518a0b0000 pid=2954 execve guuid=e9370ab1-1a00-0000-cbfd-32518b0b0000 pid=2955 /usr/bin/tr guuid=a95dfab0-1a00-0000-cbfd-3251890b0000 pid=2953->guuid=e9370ab1-1a00-0000-cbfd-32518b0b0000 pid=2955 execve guuid=48c018b1-1a00-0000-cbfd-32518c0b0000 pid=2956 /usr/bin/head guuid=a95dfab0-1a00-0000-cbfd-3251890b0000 pid=2953->guuid=48c018b1-1a00-0000-cbfd-32518c0b0000 pid=2956 execve guuid=a44decb1-1a00-0000-cbfd-32518e0b0000 pid=2958->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 134B guuid=58ebd9d7-1a00-0000-cbfd-3251d80b0000 pid=3032 /usr/bin/head guuid=e0bfd3d7-1a00-0000-cbfd-3251d70b0000 pid=3031->guuid=58ebd9d7-1a00-0000-cbfd-3251d80b0000 pid=3032 execve guuid=ef7bdfd7-1a00-0000-cbfd-3251d90b0000 pid=3033 /usr/bin/tr guuid=e0bfd3d7-1a00-0000-cbfd-3251d70b0000 pid=3031->guuid=ef7bdfd7-1a00-0000-cbfd-3251d90b0000 pid=3033 execve guuid=ded2e2d7-1a00-0000-cbfd-3251da0b0000 pid=3034 /usr/bin/head guuid=e0bfd3d7-1a00-0000-cbfd-3251d70b0000 pid=3031->guuid=ded2e2d7-1a00-0000-cbfd-3251da0b0000 pid=3034 execve guuid=6a555fd8-1a00-0000-cbfd-3251dc0b0000 pid=3036->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 131B guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3135 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3135 clone guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3136 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3136 clone guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3137 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3137 clone guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3138 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3138 clone guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3140 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3118->guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3140 clone guuid=ca97e0fa-1a00-0000-cbfd-3251320c0000 pid=3122 /usr/bin/head guuid=d649d9fa-1a00-0000-cbfd-3251310c0000 pid=3121->guuid=ca97e0fa-1a00-0000-cbfd-3251320c0000 pid=3122 execve guuid=94d0e5fa-1a00-0000-cbfd-3251330c0000 pid=3123 /usr/bin/tr guuid=d649d9fa-1a00-0000-cbfd-3251310c0000 pid=3121->guuid=94d0e5fa-1a00-0000-cbfd-3251330c0000 pid=3123 execve guuid=fc1debfa-1a00-0000-cbfd-3251340c0000 pid=3124 /usr/bin/head guuid=d649d9fa-1a00-0000-cbfd-3251310c0000 pid=3121->guuid=fc1debfa-1a00-0000-cbfd-3251340c0000 pid=3124 execve guuid=dfc1c1fb-1a00-0000-cbfd-3251370c0000 pid=3127->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 134B guuid=82004302-1b00-0000-cbfd-3251450c0000 pid=3141 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3137->guuid=82004302-1b00-0000-cbfd-3251450c0000 pid=3141 clone guuid=17857502-1b00-0000-cbfd-3251470c0000 pid=3143 /tmp/ubq1ni guuid=7dff91fa-1a00-0000-cbfd-32512e0c0000 pid=3137->guuid=17857502-1b00-0000-cbfd-3251470c0000 pid=3143 clone guuid=f3d52e1f-1b00-0000-cbfd-3251890c0000 pid=3209 /usr/bin/head guuid=ba3d271f-1b00-0000-cbfd-3251880c0000 pid=3208->guuid=f3d52e1f-1b00-0000-cbfd-3251890c0000 pid=3209 execve guuid=e0ff331f-1b00-0000-cbfd-32518a0c0000 pid=3210 /usr/bin/tr guuid=ba3d271f-1b00-0000-cbfd-3251880c0000 pid=3208->guuid=e0ff331f-1b00-0000-cbfd-32518a0c0000 pid=3210 execve guuid=6f68371f-1b00-0000-cbfd-32518b0c0000 pid=3211 /usr/bin/head guuid=ba3d271f-1b00-0000-cbfd-3251880c0000 pid=3208->guuid=6f68371f-1b00-0000-cbfd-32518b0c0000 pid=3211 execve guuid=eaf0e91f-1b00-0000-cbfd-32518e0c0000 pid=3214->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 134B guuid=a946d056-1b00-0000-cbfd-3251b10c0000 pid=3249 /usr/bin/head guuid=7e2bc056-1b00-0000-cbfd-3251b00c0000 pid=3248->guuid=a946d056-1b00-0000-cbfd-3251b10c0000 pid=3249 execve guuid=5f19d756-1b00-0000-cbfd-3251b20c0000 pid=3250 /usr/bin/tr guuid=7e2bc056-1b00-0000-cbfd-3251b00c0000 pid=3248->guuid=5f19d756-1b00-0000-cbfd-3251b20c0000 pid=3250 execve guuid=700fde56-1b00-0000-cbfd-3251b30c0000 pid=3251 /usr/bin/head guuid=7e2bc056-1b00-0000-cbfd-3251b00c0000 pid=3248->guuid=700fde56-1b00-0000-cbfd-3251b30c0000 pid=3251 execve guuid=88b3c357-1b00-0000-cbfd-3251b70c0000 pid=3255->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 134B guuid=43c92487-1b00-0000-cbfd-3251f20c0000 pid=3314 /usr/bin/head guuid=b70b1a87-1b00-0000-cbfd-3251f10c0000 pid=3313->guuid=43c92487-1b00-0000-cbfd-3251f20c0000 pid=3314 execve guuid=46f12987-1b00-0000-cbfd-3251f30c0000 pid=3315 /usr/bin/tr guuid=b70b1a87-1b00-0000-cbfd-3251f10c0000 pid=3313->guuid=46f12987-1b00-0000-cbfd-3251f30c0000 pid=3315 execve guuid=96552d87-1b00-0000-cbfd-3251f40c0000 pid=3316 /usr/bin/head guuid=b70b1a87-1b00-0000-cbfd-3251f10c0000 pid=3313->guuid=96552d87-1b00-0000-cbfd-3251f40c0000 pid=3316 execve guuid=bee0e087-1b00-0000-cbfd-3251f70c0000 pid=3319->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 132B guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3413 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3413 clone guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3414 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3414 clone guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3415 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3415 clone guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3416 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3416 clone guuid=7bcb7cb3-1b00-0000-cbfd-32515b0d0000 pid=3419 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=7bcb7cb3-1b00-0000-cbfd-32515b0d0000 pid=3419 clone guuid=96548db3-1b00-0000-cbfd-32515c0d0000 pid=3420 /tmp/4jq3g7 guuid=3197eaac-1b00-0000-cbfd-3251480d0000 pid=3400->guuid=96548db3-1b00-0000-cbfd-32515c0d0000 pid=3420 clone guuid=987f83ad-1b00-0000-cbfd-32514c0d0000 pid=3404 /usr/bin/head guuid=34e573ad-1b00-0000-cbfd-32514b0d0000 pid=3403->guuid=987f83ad-1b00-0000-cbfd-32514c0d0000 pid=3404 execve guuid=601d8fad-1b00-0000-cbfd-32514d0d0000 pid=3405 /usr/bin/tr guuid=34e573ad-1b00-0000-cbfd-32514b0d0000 pid=3403->guuid=601d8fad-1b00-0000-cbfd-32514d0d0000 pid=3405 execve guuid=11dd9aad-1b00-0000-cbfd-32514e0d0000 pid=3406 /usr/bin/head guuid=34e573ad-1b00-0000-cbfd-32514b0d0000 pid=3403->guuid=11dd9aad-1b00-0000-cbfd-32514e0d0000 pid=3406 execve guuid=9dac5eaf-1b00-0000-cbfd-3251510d0000 pid=3409->10dbcbef-d840-53b3-a06d-d8ede6d0e936 send: 133B guuid=72c712d6-1b00-0000-cbfd-3251870d0000 pid=3463 /usr/bin/sleep guuid=17cf05d6-1b00-0000-cbfd-3251860d0000 pid=3462->guuid=72c712d6-1b00-0000-cbfd-3251870d0000 pid=3463 execve
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-05-25 22:07:29 UTC
File Type:
Text (Shell)
AV detection:
10 of 22 (45.45%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Enumerates kernel/hardware configuration
Reads runtime system information
System Network Configuration Discovery
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Comments