MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09e57d2500dec545a35f98b083afb9d9b9956ce3107c34fe2ff14b082cb9aaea. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 7


Intelligence 7 IOCs YARA 1 File information Comments

SHA256 hash: 09e57d2500dec545a35f98b083afb9d9b9956ce3107c34fe2ff14b082cb9aaea
SHA3-384 hash: a333a63aae4e0c36ce004e93fa8bb098cac0d1b8459bf9c26d70c4dbe8eadcde2bd7eab8127997635d365b0952ef6656
SHA1 hash: 01cb669fd4689fc6c563ef99ac68d1d155dbff0b
MD5 hash: 5548d76d145e096025e2fa8b59cd8c33
humanhash: vegan-neptune-angel-fix
File name:p
Download: download sample
File size:834 bytes
First seen:2026-06-11 05:44:44 UTC
Last seen:Never
File type: sh
MIME type:text/x-shellscript
ssdeep 24:kXCKysE2hi0ziQvZohayFTz8BjpOeXTN7:e9Qp+MsyFv8BjpOeXTN7
TLSH T1C401EFCEC002EBB04195E85E66A751807812C3CB15414FA83FDC843D9BE96587059F49
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://188.132.232.81/MEzEn/an/aelf ua-wget
http://188.132.232.81/xdD5n/an/aelf ua-wget
http://188.132.232.81/dEvYn/an/aelf ua-wget
http://188.132.232.81/augn/an/aelf ua-wget
http://188.132.232.81/Ylcn/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
62
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Verdict:
Malicious
File Type:
unix shell
First seen:
2026-06-11T02:49:00Z UTC
Last seen:
2026-06-12T18:38:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=0423b159-1800-0000-b2cd-107f440b0000 pid=2884 /usr/bin/sudo guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890 /tmp/sample.bin write-file guuid=0423b159-1800-0000-b2cd-107f440b0000 pid=2884->guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890 execve guuid=92cd905c-1800-0000-b2cd-107f4e0b0000 pid=2894 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=92cd905c-1800-0000-b2cd-107f4e0b0000 pid=2894 execve guuid=9545c45d-1800-0000-b2cd-107f4f0b0000 pid=2895 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9545c45d-1800-0000-b2cd-107f4f0b0000 pid=2895 execve guuid=cea23d5e-1800-0000-b2cd-107f500b0000 pid=2896 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=cea23d5e-1800-0000-b2cd-107f500b0000 pid=2896 execve guuid=abd3ff5e-1800-0000-b2cd-107f530b0000 pid=2899 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=abd3ff5e-1800-0000-b2cd-107f530b0000 pid=2899 execve guuid=3cf19b5f-1800-0000-b2cd-107f550b0000 pid=2901 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=3cf19b5f-1800-0000-b2cd-107f550b0000 pid=2901 execve guuid=26500a60-1800-0000-b2cd-107f580b0000 pid=2904 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=26500a60-1800-0000-b2cd-107f580b0000 pid=2904 execve guuid=76e47b60-1800-0000-b2cd-107f5a0b0000 pid=2906 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=76e47b60-1800-0000-b2cd-107f5a0b0000 pid=2906 execve guuid=ecf7f660-1800-0000-b2cd-107f5c0b0000 pid=2908 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=ecf7f660-1800-0000-b2cd-107f5c0b0000 pid=2908 execve guuid=7e7d7161-1800-0000-b2cd-107f5d0b0000 pid=2909 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=7e7d7161-1800-0000-b2cd-107f5d0b0000 pid=2909 execve guuid=0bf72f62-1800-0000-b2cd-107f5e0b0000 pid=2910 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0bf72f62-1800-0000-b2cd-107f5e0b0000 pid=2910 execve guuid=59ede262-1800-0000-b2cd-107f5f0b0000 pid=2911 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=59ede262-1800-0000-b2cd-107f5f0b0000 pid=2911 execve guuid=9ace4f63-1800-0000-b2cd-107f610b0000 pid=2913 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9ace4f63-1800-0000-b2cd-107f610b0000 pid=2913 execve guuid=8e9ab363-1800-0000-b2cd-107f640b0000 pid=2916 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=8e9ab363-1800-0000-b2cd-107f640b0000 pid=2916 execve guuid=1fd97b64-1800-0000-b2cd-107f670b0000 pid=2919 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1fd97b64-1800-0000-b2cd-107f670b0000 pid=2919 execve guuid=2b8d0d65-1800-0000-b2cd-107f690b0000 pid=2921 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=2b8d0d65-1800-0000-b2cd-107f690b0000 pid=2921 execve guuid=82dc7c65-1800-0000-b2cd-107f6b0b0000 pid=2923 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=82dc7c65-1800-0000-b2cd-107f6b0b0000 pid=2923 execve guuid=b5d9f565-1800-0000-b2cd-107f6c0b0000 pid=2924 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b5d9f565-1800-0000-b2cd-107f6c0b0000 pid=2924 execve guuid=58337766-1800-0000-b2cd-107f6d0b0000 pid=2925 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=58337766-1800-0000-b2cd-107f6d0b0000 pid=2925 execve guuid=fe941a67-1800-0000-b2cd-107f6f0b0000 pid=2927 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=fe941a67-1800-0000-b2cd-107f6f0b0000 pid=2927 execve guuid=fb638f67-1800-0000-b2cd-107f720b0000 pid=2930 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=fb638f67-1800-0000-b2cd-107f720b0000 pid=2930 execve guuid=71d2eb67-1800-0000-b2cd-107f740b0000 pid=2932 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=71d2eb67-1800-0000-b2cd-107f740b0000 pid=2932 execve guuid=adf24f68-1800-0000-b2cd-107f770b0000 pid=2935 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=adf24f68-1800-0000-b2cd-107f770b0000 pid=2935 execve guuid=aebce868-1800-0000-b2cd-107f7a0b0000 pid=2938 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=aebce868-1800-0000-b2cd-107f7a0b0000 pid=2938 execve guuid=d18d8069-1800-0000-b2cd-107f7d0b0000 pid=2941 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d18d8069-1800-0000-b2cd-107f7d0b0000 pid=2941 execve guuid=0cf54a6a-1800-0000-b2cd-107f7e0b0000 pid=2942 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0cf54a6a-1800-0000-b2cd-107f7e0b0000 pid=2942 execve guuid=d0f83c6b-1800-0000-b2cd-107f7f0b0000 pid=2943 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d0f83c6b-1800-0000-b2cd-107f7f0b0000 pid=2943 execve guuid=dc53ec6b-1800-0000-b2cd-107f800b0000 pid=2944 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=dc53ec6b-1800-0000-b2cd-107f800b0000 pid=2944 execve guuid=1532826c-1800-0000-b2cd-107f810b0000 pid=2945 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1532826c-1800-0000-b2cd-107f810b0000 pid=2945 execve guuid=7146186d-1800-0000-b2cd-107f820b0000 pid=2946 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=7146186d-1800-0000-b2cd-107f820b0000 pid=2946 execve guuid=0537a96d-1800-0000-b2cd-107f830b0000 pid=2947 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0537a96d-1800-0000-b2cd-107f830b0000 pid=2947 execve guuid=2d07246e-1800-0000-b2cd-107f850b0000 pid=2949 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=2d07246e-1800-0000-b2cd-107f850b0000 pid=2949 execve guuid=9c40876e-1800-0000-b2cd-107f860b0000 pid=2950 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9c40876e-1800-0000-b2cd-107f860b0000 pid=2950 execve guuid=c3361e6f-1800-0000-b2cd-107f880b0000 pid=2952 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c3361e6f-1800-0000-b2cd-107f880b0000 pid=2952 execve guuid=b8b0cb6f-1800-0000-b2cd-107f8b0b0000 pid=2955 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b8b0cb6f-1800-0000-b2cd-107f8b0b0000 pid=2955 execve guuid=e5f34e70-1800-0000-b2cd-107f8e0b0000 pid=2958 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=e5f34e70-1800-0000-b2cd-107f8e0b0000 pid=2958 execve guuid=1731c870-1800-0000-b2cd-107f900b0000 pid=2960 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1731c870-1800-0000-b2cd-107f900b0000 pid=2960 execve guuid=c4b04b71-1800-0000-b2cd-107f920b0000 pid=2962 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c4b04b71-1800-0000-b2cd-107f920b0000 pid=2962 execve guuid=6f3ed671-1800-0000-b2cd-107f930b0000 pid=2963 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=6f3ed671-1800-0000-b2cd-107f930b0000 pid=2963 execve guuid=32245672-1800-0000-b2cd-107f940b0000 pid=2964 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=32245672-1800-0000-b2cd-107f940b0000 pid=2964 execve guuid=b0cdca72-1800-0000-b2cd-107f950b0000 pid=2965 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b0cdca72-1800-0000-b2cd-107f950b0000 pid=2965 execve guuid=1dbc4073-1800-0000-b2cd-107f970b0000 pid=2967 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1dbc4073-1800-0000-b2cd-107f970b0000 pid=2967 execve guuid=cc4ea473-1800-0000-b2cd-107f990b0000 pid=2969 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=cc4ea473-1800-0000-b2cd-107f990b0000 pid=2969 execve guuid=67db0a74-1800-0000-b2cd-107f9b0b0000 pid=2971 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=67db0a74-1800-0000-b2cd-107f9b0b0000 pid=2971 execve guuid=20c65c74-1800-0000-b2cd-107f9d0b0000 pid=2973 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=20c65c74-1800-0000-b2cd-107f9d0b0000 pid=2973 execve guuid=9953ce74-1800-0000-b2cd-107fa00b0000 pid=2976 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9953ce74-1800-0000-b2cd-107fa00b0000 pid=2976 execve guuid=07b92b75-1800-0000-b2cd-107fa10b0000 pid=2977 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=07b92b75-1800-0000-b2cd-107fa10b0000 pid=2977 execve guuid=220fd875-1800-0000-b2cd-107fa30b0000 pid=2979 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=220fd875-1800-0000-b2cd-107fa30b0000 pid=2979 execve guuid=b4126676-1800-0000-b2cd-107fa40b0000 pid=2980 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b4126676-1800-0000-b2cd-107fa40b0000 pid=2980 execve guuid=65e1e076-1800-0000-b2cd-107fa50b0000 pid=2981 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=65e1e076-1800-0000-b2cd-107fa50b0000 pid=2981 execve guuid=b17c5877-1800-0000-b2cd-107fa70b0000 pid=2983 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b17c5877-1800-0000-b2cd-107fa70b0000 pid=2983 execve guuid=24e42f78-1800-0000-b2cd-107faa0b0000 pid=2986 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=24e42f78-1800-0000-b2cd-107faa0b0000 pid=2986 execve guuid=c9099978-1800-0000-b2cd-107fac0b0000 pid=2988 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c9099978-1800-0000-b2cd-107fac0b0000 pid=2988 execve guuid=b8edf678-1800-0000-b2cd-107fae0b0000 pid=2990 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b8edf678-1800-0000-b2cd-107fae0b0000 pid=2990 execve guuid=b8657c79-1800-0000-b2cd-107fb00b0000 pid=2992 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b8657c79-1800-0000-b2cd-107fb00b0000 pid=2992 execve guuid=a5efd579-1800-0000-b2cd-107fb10b0000 pid=2993 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=a5efd579-1800-0000-b2cd-107fb10b0000 pid=2993 execve guuid=d1a02e7a-1800-0000-b2cd-107fb20b0000 pid=2994 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d1a02e7a-1800-0000-b2cd-107fb20b0000 pid=2994 execve guuid=0a7d957a-1800-0000-b2cd-107fb30b0000 pid=2995 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0a7d957a-1800-0000-b2cd-107fb30b0000 pid=2995 execve guuid=0012fb7a-1800-0000-b2cd-107fb40b0000 pid=2996 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0012fb7a-1800-0000-b2cd-107fb40b0000 pid=2996 execve guuid=a4247e7b-1800-0000-b2cd-107fb50b0000 pid=2997 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=a4247e7b-1800-0000-b2cd-107fb50b0000 pid=2997 execve guuid=6d84167c-1800-0000-b2cd-107fb60b0000 pid=2998 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=6d84167c-1800-0000-b2cd-107fb60b0000 pid=2998 execve guuid=e4eca47c-1800-0000-b2cd-107fb70b0000 pid=2999 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=e4eca47c-1800-0000-b2cd-107fb70b0000 pid=2999 execve guuid=3751347d-1800-0000-b2cd-107fb90b0000 pid=3001 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=3751347d-1800-0000-b2cd-107fb90b0000 pid=3001 execve guuid=9d87be7d-1800-0000-b2cd-107fba0b0000 pid=3002 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9d87be7d-1800-0000-b2cd-107fba0b0000 pid=3002 execve guuid=e0553f7e-1800-0000-b2cd-107fbb0b0000 pid=3003 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=e0553f7e-1800-0000-b2cd-107fbb0b0000 pid=3003 execve guuid=9c64af7e-1800-0000-b2cd-107fbd0b0000 pid=3005 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=9c64af7e-1800-0000-b2cd-107fbd0b0000 pid=3005 execve guuid=20370f7f-1800-0000-b2cd-107fbf0b0000 pid=3007 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=20370f7f-1800-0000-b2cd-107fbf0b0000 pid=3007 execve guuid=2570da7f-1800-0000-b2cd-107fc30b0000 pid=3011 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=2570da7f-1800-0000-b2cd-107fc30b0000 pid=3011 execve guuid=f6c64080-1800-0000-b2cd-107fc50b0000 pid=3013 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=f6c64080-1800-0000-b2cd-107fc50b0000 pid=3013 execve guuid=0a32aa80-1800-0000-b2cd-107fc80b0000 pid=3016 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=0a32aa80-1800-0000-b2cd-107fc80b0000 pid=3016 execve guuid=43da0f81-1800-0000-b2cd-107fca0b0000 pid=3018 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=43da0f81-1800-0000-b2cd-107fca0b0000 pid=3018 execve guuid=ee467d81-1800-0000-b2cd-107fcb0b0000 pid=3019 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=ee467d81-1800-0000-b2cd-107fcb0b0000 pid=3019 execve guuid=b4a7f081-1800-0000-b2cd-107fcd0b0000 pid=3021 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b4a7f081-1800-0000-b2cd-107fcd0b0000 pid=3021 execve guuid=48db5a82-1800-0000-b2cd-107fcf0b0000 pid=3023 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=48db5a82-1800-0000-b2cd-107fcf0b0000 pid=3023 execve guuid=3135bb82-1800-0000-b2cd-107fd20b0000 pid=3026 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=3135bb82-1800-0000-b2cd-107fd20b0000 pid=3026 execve guuid=55811d83-1800-0000-b2cd-107fd40b0000 pid=3028 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=55811d83-1800-0000-b2cd-107fd40b0000 pid=3028 execve guuid=6e1f8683-1800-0000-b2cd-107fd70b0000 pid=3031 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=6e1f8683-1800-0000-b2cd-107fd70b0000 pid=3031 execve guuid=3639f383-1800-0000-b2cd-107fd90b0000 pid=3033 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=3639f383-1800-0000-b2cd-107fd90b0000 pid=3033 execve guuid=4bc85984-1800-0000-b2cd-107fdb0b0000 pid=3035 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=4bc85984-1800-0000-b2cd-107fdb0b0000 pid=3035 execve guuid=b1a8cb84-1800-0000-b2cd-107fdc0b0000 pid=3036 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b1a8cb84-1800-0000-b2cd-107fdc0b0000 pid=3036 execve guuid=d3004d85-1800-0000-b2cd-107fdd0b0000 pid=3037 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d3004d85-1800-0000-b2cd-107fdd0b0000 pid=3037 execve guuid=8d17ac85-1800-0000-b2cd-107fe00b0000 pid=3040 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=8d17ac85-1800-0000-b2cd-107fe00b0000 pid=3040 execve guuid=15f31486-1800-0000-b2cd-107fe20b0000 pid=3042 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=15f31486-1800-0000-b2cd-107fe20b0000 pid=3042 execve guuid=730c9986-1800-0000-b2cd-107fe40b0000 pid=3044 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=730c9986-1800-0000-b2cd-107fe40b0000 pid=3044 execve guuid=fd2f0787-1800-0000-b2cd-107fe60b0000 pid=3046 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=fd2f0787-1800-0000-b2cd-107fe60b0000 pid=3046 execve guuid=1e296e87-1800-0000-b2cd-107fe90b0000 pid=3049 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1e296e87-1800-0000-b2cd-107fe90b0000 pid=3049 execve guuid=1e23d387-1800-0000-b2cd-107feb0b0000 pid=3051 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=1e23d387-1800-0000-b2cd-107feb0b0000 pid=3051 execve guuid=ee235288-1800-0000-b2cd-107fec0b0000 pid=3052 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=ee235288-1800-0000-b2cd-107fec0b0000 pid=3052 execve guuid=f2384489-1800-0000-b2cd-107fed0b0000 pid=3053 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=f2384489-1800-0000-b2cd-107fed0b0000 pid=3053 execve guuid=eab0088a-1800-0000-b2cd-107fef0b0000 pid=3055 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=eab0088a-1800-0000-b2cd-107fef0b0000 pid=3055 execve guuid=2da57d8a-1800-0000-b2cd-107ff00b0000 pid=3056 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=2da57d8a-1800-0000-b2cd-107ff00b0000 pid=3056 execve guuid=c429f58a-1800-0000-b2cd-107ff10b0000 pid=3057 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c429f58a-1800-0000-b2cd-107ff10b0000 pid=3057 execve guuid=d30e668b-1800-0000-b2cd-107ff30b0000 pid=3059 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d30e668b-1800-0000-b2cd-107ff30b0000 pid=3059 execve guuid=5064da8b-1800-0000-b2cd-107ff60b0000 pid=3062 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=5064da8b-1800-0000-b2cd-107ff60b0000 pid=3062 execve guuid=21ba5f8c-1800-0000-b2cd-107ff80b0000 pid=3064 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=21ba5f8c-1800-0000-b2cd-107ff80b0000 pid=3064 execve guuid=b019b78c-1800-0000-b2cd-107ffa0b0000 pid=3066 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b019b78c-1800-0000-b2cd-107ffa0b0000 pid=3066 execve guuid=bb1a278d-1800-0000-b2cd-107ffd0b0000 pid=3069 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=bb1a278d-1800-0000-b2cd-107ffd0b0000 pid=3069 execve guuid=f424828d-1800-0000-b2cd-107f000c0000 pid=3072 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=f424828d-1800-0000-b2cd-107f000c0000 pid=3072 execve guuid=77b8da8d-1800-0000-b2cd-107f020c0000 pid=3074 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=77b8da8d-1800-0000-b2cd-107f020c0000 pid=3074 execve guuid=729e328e-1800-0000-b2cd-107f050c0000 pid=3077 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=729e328e-1800-0000-b2cd-107f050c0000 pid=3077 execve guuid=faad8f8e-1800-0000-b2cd-107f070c0000 pid=3079 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=faad8f8e-1800-0000-b2cd-107f070c0000 pid=3079 execve guuid=6ce4eb8e-1800-0000-b2cd-107f0a0c0000 pid=3082 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=6ce4eb8e-1800-0000-b2cd-107f0a0c0000 pid=3082 execve guuid=59264b8f-1800-0000-b2cd-107f0c0c0000 pid=3084 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=59264b8f-1800-0000-b2cd-107f0c0c0000 pid=3084 execve guuid=8a08a68f-1800-0000-b2cd-107f0e0c0000 pid=3086 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=8a08a68f-1800-0000-b2cd-107f0e0c0000 pid=3086 execve guuid=b4c50590-1800-0000-b2cd-107f100c0000 pid=3088 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=b4c50590-1800-0000-b2cd-107f100c0000 pid=3088 execve guuid=260a6590-1800-0000-b2cd-107f120c0000 pid=3090 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=260a6590-1800-0000-b2cd-107f120c0000 pid=3090 execve guuid=4100cc90-1800-0000-b2cd-107f130c0000 pid=3091 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=4100cc90-1800-0000-b2cd-107f130c0000 pid=3091 execve guuid=58a73391-1800-0000-b2cd-107f150c0000 pid=3093 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=58a73391-1800-0000-b2cd-107f150c0000 pid=3093 execve guuid=37f09291-1800-0000-b2cd-107f170c0000 pid=3095 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=37f09291-1800-0000-b2cd-107f170c0000 pid=3095 execve guuid=969bf391-1800-0000-b2cd-107f1a0c0000 pid=3098 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=969bf391-1800-0000-b2cd-107f1a0c0000 pid=3098 execve guuid=84955392-1800-0000-b2cd-107f1c0c0000 pid=3100 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=84955392-1800-0000-b2cd-107f1c0c0000 pid=3100 execve guuid=a98bb692-1800-0000-b2cd-107f1e0c0000 pid=3102 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=a98bb692-1800-0000-b2cd-107f1e0c0000 pid=3102 execve guuid=d41a1a93-1800-0000-b2cd-107f200c0000 pid=3104 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d41a1a93-1800-0000-b2cd-107f200c0000 pid=3104 execve guuid=c3e97993-1800-0000-b2cd-107f230c0000 pid=3107 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c3e97993-1800-0000-b2cd-107f230c0000 pid=3107 execve guuid=378e4294-1800-0000-b2cd-107f250c0000 pid=3109 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=378e4294-1800-0000-b2cd-107f250c0000 pid=3109 execve guuid=76cba694-1800-0000-b2cd-107f270c0000 pid=3111 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=76cba694-1800-0000-b2cd-107f270c0000 pid=3111 execve guuid=f47e0e95-1800-0000-b2cd-107f280c0000 pid=3112 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=f47e0e95-1800-0000-b2cd-107f280c0000 pid=3112 execve guuid=08ac9c95-1800-0000-b2cd-107f2a0c0000 pid=3114 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=08ac9c95-1800-0000-b2cd-107f2a0c0000 pid=3114 execve guuid=a963f295-1800-0000-b2cd-107f2c0c0000 pid=3116 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=a963f295-1800-0000-b2cd-107f2c0c0000 pid=3116 execve guuid=ba7a5496-1800-0000-b2cd-107f2e0c0000 pid=3118 /usr/bin/ls guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=ba7a5496-1800-0000-b2cd-107f2e0c0000 pid=3118 execve guuid=899ebd96-1800-0000-b2cd-107f310c0000 pid=3121 /usr/bin/rm guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=899ebd96-1800-0000-b2cd-107f310c0000 pid=3121 execve guuid=d3c4f996-1800-0000-b2cd-107f320c0000 pid=3122 /usr/bin/wget net send-data write-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=d3c4f996-1800-0000-b2cd-107f320c0000 pid=3122 execve guuid=91f62ae9-1800-0000-b2cd-107fe00c0000 pid=3296 /usr/bin/chmod guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=91f62ae9-1800-0000-b2cd-107fe00c0000 pid=3296 execve guuid=af4788e9-1800-0000-b2cd-107fe10c0000 pid=3297 /usr/bin/dash guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=af4788e9-1800-0000-b2cd-107fe10c0000 pid=3297 clone guuid=61436dea-1800-0000-b2cd-107fe30c0000 pid=3299 /usr/bin/rm guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=61436dea-1800-0000-b2cd-107fe30c0000 pid=3299 execve guuid=2f00c5ea-1800-0000-b2cd-107fe40c0000 pid=3300 /usr/bin/wget net send-data write-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=2f00c5ea-1800-0000-b2cd-107fe40c0000 pid=3300 execve guuid=908825f1-1800-0000-b2cd-107fe70c0000 pid=3303 /usr/bin/chmod guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=908825f1-1800-0000-b2cd-107fe70c0000 pid=3303 execve guuid=c9ac80f1-1800-0000-b2cd-107fe90c0000 pid=3305 /tmp/xdD5 guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c9ac80f1-1800-0000-b2cd-107fe90c0000 pid=3305 execve guuid=bf0662f2-1800-0000-b2cd-107fee0c0000 pid=3310 /usr/bin/rm guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=bf0662f2-1800-0000-b2cd-107fee0c0000 pid=3310 execve guuid=275fd6f2-1800-0000-b2cd-107ff00c0000 pid=3312 /usr/bin/wget net send-data write-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=275fd6f2-1800-0000-b2cd-107ff00c0000 pid=3312 execve guuid=e7d94ff9-1800-0000-b2cd-107f020d0000 pid=3330 /usr/bin/chmod guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=e7d94ff9-1800-0000-b2cd-107f020d0000 pid=3330 execve guuid=96ba8ff9-1800-0000-b2cd-107f030d0000 pid=3331 /tmp/dEvY guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=96ba8ff9-1800-0000-b2cd-107f030d0000 pid=3331 execve guuid=de004cfa-1800-0000-b2cd-107f060d0000 pid=3334 /usr/bin/rm guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=de004cfa-1800-0000-b2cd-107f060d0000 pid=3334 execve guuid=69648bfa-1800-0000-b2cd-107f070d0000 pid=3335 /usr/bin/wget net send-data write-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=69648bfa-1800-0000-b2cd-107f070d0000 pid=3335 execve guuid=e8ff1f01-1900-0000-b2cd-107f130d0000 pid=3347 /usr/bin/chmod guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=e8ff1f01-1900-0000-b2cd-107f130d0000 pid=3347 execve guuid=34837a01-1900-0000-b2cd-107f140d0000 pid=3348 /tmp/aug guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=34837a01-1900-0000-b2cd-107f140d0000 pid=3348 execve guuid=a9e33003-1900-0000-b2cd-107f160d0000 pid=3350 /usr/bin/rm guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=a9e33003-1900-0000-b2cd-107f160d0000 pid=3350 execve guuid=eac47f03-1900-0000-b2cd-107f170d0000 pid=3351 /usr/bin/wget net send-data write-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=eac47f03-1900-0000-b2cd-107f170d0000 pid=3351 execve guuid=c736cf44-1900-0000-b2cd-107f5f0d0000 pid=3423 /usr/bin/chmod guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c736cf44-1900-0000-b2cd-107f5f0d0000 pid=3423 execve guuid=28877545-1900-0000-b2cd-107f620d0000 pid=3426 /tmp/Ylc guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=28877545-1900-0000-b2cd-107f620d0000 pid=3426 execve guuid=c9a72446-1900-0000-b2cd-107f670d0000 pid=3431 /usr/bin/rm delete-file guuid=00fe0b5c-1800-0000-b2cd-107f4a0b0000 pid=2890->guuid=c9a72446-1900-0000-b2cd-107f670d0000 pid=3431 execve 9554d36e-3083-568e-90da-bb8e3c487b07 188.132.232.81:80 guuid=d3c4f996-1800-0000-b2cd-107f320c0000 pid=3122->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=2f00c5ea-1800-0000-b2cd-107fe40c0000 pid=3300->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=275fd6f2-1800-0000-b2cd-107ff00c0000 pid=3312->9554d36e-3083-568e-90da-bb8e3c487b07 send: 133B guuid=69648bfa-1800-0000-b2cd-107f070d0000 pid=3335->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B guuid=eac47f03-1900-0000-b2cd-107f170d0000 pid=3351->9554d36e-3083-568e-90da-bb8e3c487b07 send: 132B
Threat name:
Win32.Trojan.Vigorf
Status:
Malicious
First seen:
2026-06-11 05:45:56 UTC
File Type:
Text (Shell)
AV detection:
12 of 23 (52.17%)
Threat level:
  5/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 09e57d2500dec545a35f98b083afb9d9b9956ce3107c34fe2ff14b082cb9aaea

(this sample)

  
Delivery method
Distributed via web download

Comments