MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 f5856ea37a4c461ea5b8a0d177fc8e657cc002b6bd750d3984aa8e3cb2b6df45. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA File information Comments

SHA256 hash: f5856ea37a4c461ea5b8a0d177fc8e657cc002b6bd750d3984aa8e3cb2b6df45
SHA3-384 hash: d94649397d8582fc9478236fb4cdaf2cba933643628781b67f2c99cab20256cf7d4dc33a2b112d684663078e1f2d1e7f
SHA1 hash: 00d998b9bbe042e350c57a8641f688620e0add69
MD5 hash: c5477850a3cceab702fcd9156653e57c
humanhash: stairway-aspen-white-alanine
File name:WSW0
Download: download sample
File size:266 bytes
First seen:2026-06-17 12:09:19 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 6:hTyx65gpy2n7x1mZYAulNXYq9DG+NjVsNXYrkJ:Vyx65sy2nmYPiq9DGmKi2
TLSH T1CED02EE2A923023120639C24E1C275A0B014D77F8C8AC32CBB1A20796E00A0DF1C02A0
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://216.107.139.197/n/an/an/a

Intelligence


File Origin
# of uploads :
1
# of downloads :
60
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Status:
terminated
Behavior Graph:
%3 guuid=b243ec4c-1900-0000-11a4-95de22140000 pid=5154 /usr/bin/sudo guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158 /tmp/sample.bin guuid=b243ec4c-1900-0000-11a4-95de22140000 pid=5154->guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158 execve guuid=17ba904f-1900-0000-11a4-95de27140000 pid=5159 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=17ba904f-1900-0000-11a4-95de27140000 pid=5159 execve guuid=4126db4f-1900-0000-11a4-95de28140000 pid=5160 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=4126db4f-1900-0000-11a4-95de28140000 pid=5160 execve guuid=512ba471-1900-0000-11a4-95de31140000 pid=5169 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=512ba471-1900-0000-11a4-95de31140000 pid=5169 execve guuid=0480f771-1900-0000-11a4-95de32140000 pid=5170 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=0480f771-1900-0000-11a4-95de32140000 pid=5170 clone guuid=1091d773-1900-0000-11a4-95de34140000 pid=5172 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=1091d773-1900-0000-11a4-95de34140000 pid=5172 execve guuid=da252174-1900-0000-11a4-95de35140000 pid=5173 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=da252174-1900-0000-11a4-95de35140000 pid=5173 execve guuid=e89ce28f-1900-0000-11a4-95de36140000 pid=5174 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=e89ce28f-1900-0000-11a4-95de36140000 pid=5174 execve guuid=a0f62490-1900-0000-11a4-95de37140000 pid=5175 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=a0f62490-1900-0000-11a4-95de37140000 pid=5175 clone guuid=31ebb990-1900-0000-11a4-95de39140000 pid=5177 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=31ebb990-1900-0000-11a4-95de39140000 pid=5177 execve guuid=fb5b0791-1900-0000-11a4-95de3a140000 pid=5178 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=fb5b0791-1900-0000-11a4-95de3a140000 pid=5178 execve guuid=3e9de5ab-1900-0000-11a4-95de3b140000 pid=5179 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=3e9de5ab-1900-0000-11a4-95de3b140000 pid=5179 execve guuid=b37e30ac-1900-0000-11a4-95de3c140000 pid=5180 /tmp/KANC guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=b37e30ac-1900-0000-11a4-95de3c140000 pid=5180 execve guuid=c66ae4ac-1900-0000-11a4-95de3e140000 pid=5182 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=c66ae4ac-1900-0000-11a4-95de3e140000 pid=5182 execve guuid=8c934dad-1900-0000-11a4-95de3f140000 pid=5183 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=8c934dad-1900-0000-11a4-95de3f140000 pid=5183 execve guuid=dda2b7f2-1900-0000-11a4-95de40140000 pid=5184 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=dda2b7f2-1900-0000-11a4-95de40140000 pid=5184 execve guuid=565244f3-1900-0000-11a4-95de41140000 pid=5185 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=565244f3-1900-0000-11a4-95de41140000 pid=5185 clone guuid=d14505f5-1900-0000-11a4-95de43140000 pid=5187 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=d14505f5-1900-0000-11a4-95de43140000 pid=5187 execve guuid=f86878f5-1900-0000-11a4-95de44140000 pid=5188 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=f86878f5-1900-0000-11a4-95de44140000 pid=5188 execve guuid=c7a2a210-1a00-0000-11a4-95de46140000 pid=5190 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=c7a2a210-1a00-0000-11a4-95de46140000 pid=5190 execve guuid=e521e410-1a00-0000-11a4-95de47140000 pid=5191 /tmp/ZOLB guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=e521e410-1a00-0000-11a4-95de47140000 pid=5191 execve guuid=8daff910-1a00-0000-11a4-95de49140000 pid=5193 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=8daff910-1a00-0000-11a4-95de49140000 pid=5193 execve guuid=a2043c11-1a00-0000-11a4-95de4a140000 pid=5194 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=a2043c11-1a00-0000-11a4-95de4a140000 pid=5194 execve guuid=e092072c-1a00-0000-11a4-95de4b140000 pid=5195 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=e092072c-1a00-0000-11a4-95de4b140000 pid=5195 execve guuid=11904f2c-1a00-0000-11a4-95de4c140000 pid=5196 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=11904f2c-1a00-0000-11a4-95de4c140000 pid=5196 clone guuid=fc2a0a2e-1a00-0000-11a4-95de4e140000 pid=5198 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=fc2a0a2e-1a00-0000-11a4-95de4e140000 pid=5198 execve guuid=86d0512e-1a00-0000-11a4-95de4f140000 pid=5199 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=86d0512e-1a00-0000-11a4-95de4f140000 pid=5199 execve guuid=1f886f4a-1a00-0000-11a4-95de57140000 pid=5207 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=1f886f4a-1a00-0000-11a4-95de57140000 pid=5207 execve guuid=9708894b-1a00-0000-11a4-95de58140000 pid=5208 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=9708894b-1a00-0000-11a4-95de58140000 pid=5208 clone guuid=aab7784d-1a00-0000-11a4-95de5a140000 pid=5210 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=aab7784d-1a00-0000-11a4-95de5a140000 pid=5210 execve guuid=7aadc74d-1a00-0000-11a4-95de5b140000 pid=5211 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=7aadc74d-1a00-0000-11a4-95de5b140000 pid=5211 execve guuid=3ecb286a-1a00-0000-11a4-95de5c140000 pid=5212 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=3ecb286a-1a00-0000-11a4-95de5c140000 pid=5212 execve guuid=df49dd6a-1a00-0000-11a4-95de5d140000 pid=5213 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=df49dd6a-1a00-0000-11a4-95de5d140000 pid=5213 clone guuid=53c3a16b-1a00-0000-11a4-95de5f140000 pid=5215 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=53c3a16b-1a00-0000-11a4-95de5f140000 pid=5215 execve guuid=b633f66b-1a00-0000-11a4-95de60140000 pid=5216 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=b633f66b-1a00-0000-11a4-95de60140000 pid=5216 execve guuid=f0503a82-1a00-0000-11a4-95de61140000 pid=5217 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=f0503a82-1a00-0000-11a4-95de61140000 pid=5217 execve guuid=56378882-1a00-0000-11a4-95de62140000 pid=5218 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=56378882-1a00-0000-11a4-95de62140000 pid=5218 clone guuid=d1ab4483-1a00-0000-11a4-95de64140000 pid=5220 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=d1ab4483-1a00-0000-11a4-95de64140000 pid=5220 execve guuid=0a019c83-1a00-0000-11a4-95de65140000 pid=5221 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=0a019c83-1a00-0000-11a4-95de65140000 pid=5221 execve guuid=eb8d969f-1a00-0000-11a4-95de66140000 pid=5222 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=eb8d969f-1a00-0000-11a4-95de66140000 pid=5222 execve guuid=ed9beb9f-1a00-0000-11a4-95de67140000 pid=5223 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=ed9beb9f-1a00-0000-11a4-95de67140000 pid=5223 clone guuid=9a26d5a0-1a00-0000-11a4-95de69140000 pid=5225 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=9a26d5a0-1a00-0000-11a4-95de69140000 pid=5225 execve guuid=b6c563a1-1a00-0000-11a4-95de6a140000 pid=5226 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=b6c563a1-1a00-0000-11a4-95de6a140000 pid=5226 execve guuid=2d0248c0-1a00-0000-11a4-95de6b140000 pid=5227 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=2d0248c0-1a00-0000-11a4-95de6b140000 pid=5227 execve guuid=26f1ebc0-1a00-0000-11a4-95de6c140000 pid=5228 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=26f1ebc0-1a00-0000-11a4-95de6c140000 pid=5228 clone guuid=f56a0ac3-1a00-0000-11a4-95de6e140000 pid=5230 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=f56a0ac3-1a00-0000-11a4-95de6e140000 pid=5230 execve guuid=a76f57c3-1a00-0000-11a4-95de6f140000 pid=5231 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=a76f57c3-1a00-0000-11a4-95de6f140000 pid=5231 execve guuid=1e0e39e4-1a00-0000-11a4-95de70140000 pid=5232 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=1e0e39e4-1a00-0000-11a4-95de70140000 pid=5232 execve guuid=ab3996e4-1a00-0000-11a4-95de71140000 pid=5233 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=ab3996e4-1a00-0000-11a4-95de71140000 pid=5233 clone guuid=9eaec8e5-1a00-0000-11a4-95de73140000 pid=5235 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=9eaec8e5-1a00-0000-11a4-95de73140000 pid=5235 execve guuid=68bd80e6-1a00-0000-11a4-95de74140000 pid=5236 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=68bd80e6-1a00-0000-11a4-95de74140000 pid=5236 execve guuid=fc92d302-1b00-0000-11a4-95de75140000 pid=5237 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=fc92d302-1b00-0000-11a4-95de75140000 pid=5237 execve guuid=52a12a03-1b00-0000-11a4-95de76140000 pid=5238 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=52a12a03-1b00-0000-11a4-95de76140000 pid=5238 clone guuid=fe52b204-1b00-0000-11a4-95de78140000 pid=5240 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=fe52b204-1b00-0000-11a4-95de78140000 pid=5240 execve guuid=49651705-1b00-0000-11a4-95de79140000 pid=5241 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=49651705-1b00-0000-11a4-95de79140000 pid=5241 execve guuid=3eb76220-1b00-0000-11a4-95de7a140000 pid=5242 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=3eb76220-1b00-0000-11a4-95de7a140000 pid=5242 execve guuid=e570a420-1b00-0000-11a4-95de7b140000 pid=5243 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=e570a420-1b00-0000-11a4-95de7b140000 pid=5243 clone guuid=33e17222-1b00-0000-11a4-95de7d140000 pid=5245 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=33e17222-1b00-0000-11a4-95de7d140000 pid=5245 execve guuid=3966ad22-1b00-0000-11a4-95de7e140000 pid=5246 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=3966ad22-1b00-0000-11a4-95de7e140000 pid=5246 execve guuid=6caae23d-1b00-0000-11a4-95de85140000 pid=5253 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=6caae23d-1b00-0000-11a4-95de85140000 pid=5253 execve guuid=0064483e-1b00-0000-11a4-95de86140000 pid=5254 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=0064483e-1b00-0000-11a4-95de86140000 pid=5254 clone guuid=856d043f-1b00-0000-11a4-95de88140000 pid=5256 /usr/bin/rm guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=856d043f-1b00-0000-11a4-95de88140000 pid=5256 execve guuid=838e6e3f-1b00-0000-11a4-95de89140000 pid=5257 /usr/bin/wget net send-data write-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=838e6e3f-1b00-0000-11a4-95de89140000 pid=5257 execve guuid=264fec5c-1b00-0000-11a4-95de8a140000 pid=5258 /usr/bin/chmod guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=264fec5c-1b00-0000-11a4-95de8a140000 pid=5258 execve guuid=a680715d-1b00-0000-11a4-95de8b140000 pid=5259 /usr/bin/dash guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=a680715d-1b00-0000-11a4-95de8b140000 pid=5259 clone guuid=d3e98c5e-1b00-0000-11a4-95de8d140000 pid=5261 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=d3e98c5e-1b00-0000-11a4-95de8d140000 pid=5261 execve guuid=b815135f-1b00-0000-11a4-95de8e140000 pid=5262 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=b815135f-1b00-0000-11a4-95de8e140000 pid=5262 execve guuid=cfc0a35f-1b00-0000-11a4-95de8f140000 pid=5263 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=cfc0a35f-1b00-0000-11a4-95de8f140000 pid=5263 execve guuid=b95d2860-1b00-0000-11a4-95de90140000 pid=5264 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=b95d2860-1b00-0000-11a4-95de90140000 pid=5264 execve guuid=ac2eaf60-1b00-0000-11a4-95de91140000 pid=5265 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=ac2eaf60-1b00-0000-11a4-95de91140000 pid=5265 execve guuid=7ba23161-1b00-0000-11a4-95de92140000 pid=5266 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=7ba23161-1b00-0000-11a4-95de92140000 pid=5266 execve guuid=6a6db261-1b00-0000-11a4-95de93140000 pid=5267 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=6a6db261-1b00-0000-11a4-95de93140000 pid=5267 execve guuid=a3033662-1b00-0000-11a4-95de94140000 pid=5268 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=a3033662-1b00-0000-11a4-95de94140000 pid=5268 execve guuid=601dbe62-1b00-0000-11a4-95de95140000 pid=5269 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=601dbe62-1b00-0000-11a4-95de95140000 pid=5269 execve guuid=4b263963-1b00-0000-11a4-95de96140000 pid=5270 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=4b263963-1b00-0000-11a4-95de96140000 pid=5270 execve guuid=beb6b263-1b00-0000-11a4-95de97140000 pid=5271 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=beb6b263-1b00-0000-11a4-95de97140000 pid=5271 execve guuid=85693264-1b00-0000-11a4-95de98140000 pid=5272 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=85693264-1b00-0000-11a4-95de98140000 pid=5272 execve guuid=aa54bc64-1b00-0000-11a4-95de99140000 pid=5273 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=aa54bc64-1b00-0000-11a4-95de99140000 pid=5273 execve guuid=e0ef3e65-1b00-0000-11a4-95de9a140000 pid=5274 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=e0ef3e65-1b00-0000-11a4-95de9a140000 pid=5274 execve guuid=0ba5bc65-1b00-0000-11a4-95de9b140000 pid=5275 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=0ba5bc65-1b00-0000-11a4-95de9b140000 pid=5275 execve guuid=c0be5166-1b00-0000-11a4-95de9c140000 pid=5276 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=c0be5166-1b00-0000-11a4-95de9c140000 pid=5276 execve guuid=693cd766-1b00-0000-11a4-95de9d140000 pid=5277 /usr/bin/rm delete-file guuid=88e8574f-1900-0000-11a4-95de26140000 pid=5158->guuid=693cd766-1b00-0000-11a4-95de9d140000 pid=5277 execve d7be7143-8a84-51ae-b4d7-8e2f14064a79 216.107.139.197:80 guuid=4126db4f-1900-0000-11a4-95de28140000 pid=5160->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=da252174-1900-0000-11a4-95de35140000 pid=5173->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=fb5b0791-1900-0000-11a4-95de3a140000 pid=5178->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181 /tmp/KANC net send-data write-file zombie guuid=b37e30ac-1900-0000-11a4-95de3c140000 pid=5180->guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181 clone aaf9c0a7-7302-5ede-b172-9a9351bb3b01 2000:::0 guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181->aaf9c0a7-7302-5ede-b172-9a9351bb3b01 con 4f6baed0-9587-596c-82b3-fd721afe4cc1 10.0.2.3:53 guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181->4f6baed0-9587-596c-82b3-fd721afe4cc1 send: 495B e0ec34da-6728-5421-bf74-e67eb37a76fd 127.0.0.1:53 guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181->e0ec34da-6728-5421-bf74-e67eb37a76fd send: 495B guuid=4f5a380b-1a00-0000-11a4-95de45140000 pid=5189 /usr/bin/uname guuid=e04f45ac-1900-0000-11a4-95de3d140000 pid=5181->guuid=4f5a380b-1a00-0000-11a4-95de45140000 pid=5189 execve guuid=8c934dad-1900-0000-11a4-95de3f140000 pid=5183->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=f86878f5-1900-0000-11a4-95de44140000 pid=5188->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=3aa9f110-1a00-0000-11a4-95de48140000 pid=5192 /tmp/ZOLB zombie guuid=e521e410-1a00-0000-11a4-95de47140000 pid=5191->guuid=3aa9f110-1a00-0000-11a4-95de48140000 pid=5192 clone guuid=a2043c11-1a00-0000-11a4-95de4a140000 pid=5194->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=86d0512e-1a00-0000-11a4-95de4f140000 pid=5199->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=7aadc74d-1a00-0000-11a4-95de5b140000 pid=5211->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b633f66b-1a00-0000-11a4-95de60140000 pid=5216->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=0a019c83-1a00-0000-11a4-95de65140000 pid=5221->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=b6c563a1-1a00-0000-11a4-95de6a140000 pid=5226->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=a76f57c3-1a00-0000-11a4-95de6f140000 pid=5231->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=68bd80e6-1a00-0000-11a4-95de74140000 pid=5236->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=49651705-1b00-0000-11a4-95de79140000 pid=5241->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=3966ad22-1b00-0000-11a4-95de7e140000 pid=5246->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B guuid=838e6e3f-1b00-0000-11a4-95de89140000 pid=5257->d7be7143-8a84-51ae-b4d7-8e2f14064a79 send: 134B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Script-Shell.Downloader.Heuristic
Status:
Malicious
First seen:
2026-06-17 12:11:06 UTC
File Type:
Text (Shell)
AV detection:
8 of 36 (22.22%)
Threat level:
  2/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm credential_access defense_evasion linux
Behaviour
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
OS Credential Dumping
Please note that we are no longer able to provide a coverage score for Virus Total.

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh f5856ea37a4c461ea5b8a0d177fc8e657cc002b6bd750d3984aa8e3cb2b6df45

(this sample)

  
Delivery method
Distributed via web download

Comments