MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 09f9fd11a2a48a7703cb3294717b29ff5a5fe49d6ae742c836481756a7779555. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 6


Intelligence 6 IOCs YARA 1 File information Comments

SHA256 hash: 09f9fd11a2a48a7703cb3294717b29ff5a5fe49d6ae742c836481756a7779555
SHA3-384 hash: 198e1c44b178b894d00033dc4ceae7607ef9da13ad9af02bae995526108f4291d9710d8b8d0a20c8850068621ebf58e4
SHA1 hash: f5dca69980e621ccd64c5a7058f788faf7abc6ba
MD5 hash: b5e2ae34cb9e595eb3346d83e481a889
humanhash: uniform-potato-lithium-dakota
File name:run.sh
Download: download sample
File size:2'907 bytes
First seen:2026-01-20 19:14:04 UTC
Last seen:Never
File type: sh
MIME type:text/plain
ssdeep 48:XKrK6K0DK02JMJKdvKdbiBVKpgKpuZdKIdKIcvyvKlKSKAgKAbw8KQKaKmKaKjK1:XsfPDP2JMJ8v8biBVIgIuZdh70Hxgxbl
TLSH T12D51B49A410C8F30A20E894F73F832B4124FA4C356FFCB01AA92581E0ECAE0CF694E50
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnaarch64xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxni386xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnloongarch64xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnm68kxnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnmicroblazexnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnmipsxnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnor1kxnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnpowerpcxnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnriscv32xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnriscv64xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnsh2xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnsh4xnxnn/an/acensys elf ua-wget
http://194.110.247.71/bins/xnxnxnxnxnxnxnxnx86_64xnxnn/an/acensys elf ua-wget

Intelligence


File Origin
# of uploads :
1
# of downloads :
37
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
File Type:
text
First seen:
2026-01-20T16:37:00Z UTC
Last seen:
2026-01-20T23:33:00Z UTC
Hits:
~10
Detections:
HEUR:Trojan-Downloader.Shell.Agent.gen HEUR:Trojan-Downloader.Shell.Agent.a
Status:
terminated
Behavior Graph:
%3 guuid=016b103f-1800-0000-8ee3-1ce2bd040000 pid=1213 /usr/bin/sudo guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218 /tmp/sample.bin guuid=016b103f-1800-0000-8ee3-1ce2bd040000 pid=1213->guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218 execve guuid=2feb1c41-1800-0000-8ee3-1ce2c5040000 pid=1221 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=2feb1c41-1800-0000-8ee3-1ce2c5040000 pid=1221 execve guuid=c61e2b4d-1800-0000-8ee3-1ce2de040000 pid=1246 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=c61e2b4d-1800-0000-8ee3-1ce2de040000 pid=1246 execve guuid=3310f95e-1800-0000-8ee3-1ce206050000 pid=1286 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=3310f95e-1800-0000-8ee3-1ce206050000 pid=1286 execve guuid=5020345f-1800-0000-8ee3-1ce208050000 pid=1288 /home/sandbox/xnxnxnxnxnxnxnxnaarch64xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=5020345f-1800-0000-8ee3-1ce208050000 pid=1288 execve guuid=2c35635f-1800-0000-8ee3-1ce209050000 pid=1289 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=2c35635f-1800-0000-8ee3-1ce209050000 pid=1289 execve guuid=93dd9d5f-1800-0000-8ee3-1ce20b050000 pid=1291 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=93dd9d5f-1800-0000-8ee3-1ce20b050000 pid=1291 execve guuid=caa26368-1800-0000-8ee3-1ce222050000 pid=1314 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=caa26368-1800-0000-8ee3-1ce222050000 pid=1314 execve guuid=9d10f377-1800-0000-8ee3-1ce24d050000 pid=1357 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=9d10f377-1800-0000-8ee3-1ce24d050000 pid=1357 execve guuid=20664778-1800-0000-8ee3-1ce24f050000 pid=1359 /home/sandbox/xnxnxnxnxnxnxnxni386xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=20664778-1800-0000-8ee3-1ce24f050000 pid=1359 execve guuid=9e949078-1800-0000-8ee3-1ce251050000 pid=1361 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=9e949078-1800-0000-8ee3-1ce251050000 pid=1361 execve guuid=4f43eb78-1800-0000-8ee3-1ce252050000 pid=1362 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=4f43eb78-1800-0000-8ee3-1ce252050000 pid=1362 execve guuid=e3007887-1800-0000-8ee3-1ce279050000 pid=1401 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=e3007887-1800-0000-8ee3-1ce279050000 pid=1401 execve guuid=098d3795-1800-0000-8ee3-1ce29e050000 pid=1438 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=098d3795-1800-0000-8ee3-1ce29e050000 pid=1438 execve guuid=7d2e7b95-1800-0000-8ee3-1ce2a0050000 pid=1440 /home/sandbox/xnxnxnxnxnxnxnxnloongarch64xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=7d2e7b95-1800-0000-8ee3-1ce2a0050000 pid=1440 execve guuid=259fb095-1800-0000-8ee3-1ce2a1050000 pid=1441 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=259fb095-1800-0000-8ee3-1ce2a1050000 pid=1441 execve guuid=1cd7f595-1800-0000-8ee3-1ce2a3050000 pid=1443 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=1cd7f595-1800-0000-8ee3-1ce2a3050000 pid=1443 execve guuid=f0909ca1-1800-0000-8ee3-1ce2b8050000 pid=1464 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=f0909ca1-1800-0000-8ee3-1ce2b8050000 pid=1464 execve guuid=0d023eac-1800-0000-8ee3-1ce2cb050000 pid=1483 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=0d023eac-1800-0000-8ee3-1ce2cb050000 pid=1483 execve guuid=99ee87ac-1800-0000-8ee3-1ce2cc050000 pid=1484 /home/sandbox/xnxnxnxnxnxnxnxnm68kxnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=99ee87ac-1800-0000-8ee3-1ce2cc050000 pid=1484 execve guuid=271fd5ac-1800-0000-8ee3-1ce2ce050000 pid=1486 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=271fd5ac-1800-0000-8ee3-1ce2ce050000 pid=1486 execve guuid=884916ad-1800-0000-8ee3-1ce2d0050000 pid=1488 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=884916ad-1800-0000-8ee3-1ce2d0050000 pid=1488 execve guuid=b928e8b6-1800-0000-8ee3-1ce2e0050000 pid=1504 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=b928e8b6-1800-0000-8ee3-1ce2e0050000 pid=1504 execve guuid=f3661ac6-1800-0000-8ee3-1ce20b060000 pid=1547 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=f3661ac6-1800-0000-8ee3-1ce20b060000 pid=1547 execve guuid=5b1b58c6-1800-0000-8ee3-1ce20c060000 pid=1548 /home/sandbox/xnxnxnxnxnxnxnxnmicroblazexnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=5b1b58c6-1800-0000-8ee3-1ce20c060000 pid=1548 execve guuid=8fdfb7c6-1800-0000-8ee3-1ce20f060000 pid=1551 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=8fdfb7c6-1800-0000-8ee3-1ce20f060000 pid=1551 execve guuid=11c42bc7-1800-0000-8ee3-1ce211060000 pid=1553 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=11c42bc7-1800-0000-8ee3-1ce211060000 pid=1553 execve guuid=4812f3d8-1800-0000-8ee3-1ce23c060000 pid=1596 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=4812f3d8-1800-0000-8ee3-1ce23c060000 pid=1596 execve guuid=aa4dc0fd-1800-0000-8ee3-1ce28d060000 pid=1677 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=aa4dc0fd-1800-0000-8ee3-1ce28d060000 pid=1677 execve guuid=3c9539fe-1800-0000-8ee3-1ce28f060000 pid=1679 /home/sandbox/xnxnxnxnxnxnxnxnmipsxnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=3c9539fe-1800-0000-8ee3-1ce28f060000 pid=1679 execve guuid=895488fe-1800-0000-8ee3-1ce291060000 pid=1681 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=895488fe-1800-0000-8ee3-1ce291060000 pid=1681 execve guuid=1c4dd5fe-1800-0000-8ee3-1ce293060000 pid=1683 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=1c4dd5fe-1800-0000-8ee3-1ce293060000 pid=1683 execve guuid=a20e1409-1900-0000-8ee3-1ce2ac060000 pid=1708 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=a20e1409-1900-0000-8ee3-1ce2ac060000 pid=1708 execve guuid=82f88b14-1900-0000-8ee3-1ce2c9060000 pid=1737 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=82f88b14-1900-0000-8ee3-1ce2c9060000 pid=1737 execve guuid=75e0e614-1900-0000-8ee3-1ce2cb060000 pid=1739 /home/sandbox/xnxnxnxnxnxnxnxnor1kxnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=75e0e614-1900-0000-8ee3-1ce2cb060000 pid=1739 execve guuid=e8b62a15-1900-0000-8ee3-1ce2cc060000 pid=1740 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=e8b62a15-1900-0000-8ee3-1ce2cc060000 pid=1740 execve guuid=f0898615-1900-0000-8ee3-1ce2ce060000 pid=1742 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=f0898615-1900-0000-8ee3-1ce2ce060000 pid=1742 execve guuid=65e77f24-1900-0000-8ee3-1ce2f0060000 pid=1776 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=65e77f24-1900-0000-8ee3-1ce2f0060000 pid=1776 execve guuid=9ba8cb35-1900-0000-8ee3-1ce211070000 pid=1809 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=9ba8cb35-1900-0000-8ee3-1ce211070000 pid=1809 execve guuid=737b1d36-1900-0000-8ee3-1ce212070000 pid=1810 /home/sandbox/xnxnxnxnxnxnxnxnpowerpcxnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=737b1d36-1900-0000-8ee3-1ce212070000 pid=1810 execve guuid=f5e77336-1900-0000-8ee3-1ce216070000 pid=1814 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=f5e77336-1900-0000-8ee3-1ce216070000 pid=1814 execve guuid=1f57e836-1900-0000-8ee3-1ce217070000 pid=1815 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=1f57e836-1900-0000-8ee3-1ce217070000 pid=1815 execve guuid=9cf37347-1900-0000-8ee3-1ce23e070000 pid=1854 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=9cf37347-1900-0000-8ee3-1ce23e070000 pid=1854 execve guuid=5062ba59-1900-0000-8ee3-1ce261070000 pid=1889 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=5062ba59-1900-0000-8ee3-1ce261070000 pid=1889 execve guuid=684dfa59-1900-0000-8ee3-1ce263070000 pid=1891 /home/sandbox/xnxnxnxnxnxnxnxnriscv32xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=684dfa59-1900-0000-8ee3-1ce263070000 pid=1891 execve guuid=80954f5a-1900-0000-8ee3-1ce266070000 pid=1894 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=80954f5a-1900-0000-8ee3-1ce266070000 pid=1894 execve guuid=8442af5a-1900-0000-8ee3-1ce267070000 pid=1895 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=8442af5a-1900-0000-8ee3-1ce267070000 pid=1895 execve guuid=d7d4b56a-1900-0000-8ee3-1ce28e070000 pid=1934 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=d7d4b56a-1900-0000-8ee3-1ce28e070000 pid=1934 execve guuid=2da9f079-1900-0000-8ee3-1ce2b4070000 pid=1972 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=2da9f079-1900-0000-8ee3-1ce2b4070000 pid=1972 execve guuid=7dd0477a-1900-0000-8ee3-1ce2b6070000 pid=1974 /home/sandbox/xnxnxnxnxnxnxnxnriscv64xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=7dd0477a-1900-0000-8ee3-1ce2b6070000 pid=1974 execve guuid=d7a9967a-1900-0000-8ee3-1ce2b8070000 pid=1976 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=d7a9967a-1900-0000-8ee3-1ce2b8070000 pid=1976 execve guuid=0359f47a-1900-0000-8ee3-1ce2ba070000 pid=1978 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=0359f47a-1900-0000-8ee3-1ce2ba070000 pid=1978 execve guuid=57b93289-1900-0000-8ee3-1ce2c9070000 pid=1993 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=57b93289-1900-0000-8ee3-1ce2c9070000 pid=1993 execve guuid=c57d5e99-1900-0000-8ee3-1ce2cb070000 pid=1995 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=c57d5e99-1900-0000-8ee3-1ce2cb070000 pid=1995 execve guuid=6301569a-1900-0000-8ee3-1ce2cd070000 pid=1997 /home/sandbox/xnxnxnxnxnxnxnxnsh2xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=6301569a-1900-0000-8ee3-1ce2cd070000 pid=1997 execve guuid=2069be9a-1900-0000-8ee3-1ce2cf070000 pid=1999 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=2069be9a-1900-0000-8ee3-1ce2cf070000 pid=1999 execve guuid=fe62239b-1900-0000-8ee3-1ce2d1070000 pid=2001 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=fe62239b-1900-0000-8ee3-1ce2d1070000 pid=2001 execve guuid=a905a8aa-1900-0000-8ee3-1ce2d7070000 pid=2007 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=a905a8aa-1900-0000-8ee3-1ce2d7070000 pid=2007 execve guuid=685319ba-1900-0000-8ee3-1ce2eb070000 pid=2027 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=685319ba-1900-0000-8ee3-1ce2eb070000 pid=2027 execve guuid=e6f2c8ba-1900-0000-8ee3-1ce2ee070000 pid=2030 /home/sandbox/xnxnxnxnxnxnxnxnsh4xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=e6f2c8ba-1900-0000-8ee3-1ce2ee070000 pid=2030 execve guuid=16071fbb-1900-0000-8ee3-1ce2f0070000 pid=2032 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=16071fbb-1900-0000-8ee3-1ce2f0070000 pid=2032 execve guuid=9bef66bb-1900-0000-8ee3-1ce2f2070000 pid=2034 /usr/bin/wget net send-data guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=9bef66bb-1900-0000-8ee3-1ce2f2070000 pid=2034 execve guuid=d0472fc8-1900-0000-8ee3-1ce2ff070000 pid=2047 /usr/bin/curl net send-data write-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=d0472fc8-1900-0000-8ee3-1ce2ff070000 pid=2047 execve guuid=1d9527db-1900-0000-8ee3-1ce218080000 pid=2072 /usr/bin/chmod guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=1d9527db-1900-0000-8ee3-1ce218080000 pid=2072 execve guuid=8aa282db-1900-0000-8ee3-1ce21a080000 pid=2074 /home/sandbox/xnxnxnxnxnxnxnxnx86_64xnxn guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=8aa282db-1900-0000-8ee3-1ce21a080000 pid=2074 execve guuid=7a6acddb-1900-0000-8ee3-1ce21c080000 pid=2076 /usr/bin/rm delete-file guuid=a01cd140-1800-0000-8ee3-1ce2c2040000 pid=1218->guuid=7a6acddb-1900-0000-8ee3-1ce21c080000 pid=2076 execve f773c0d3-dbbc-5349-a7bc-010af40ec8df 194.110.247.71:80 guuid=2feb1c41-1800-0000-8ee3-1ce2c5040000 pid=1221->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 161B guuid=c61e2b4d-1800-0000-8ee3-1ce2de040000 pid=1246->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 110B guuid=93dd9d5f-1800-0000-8ee3-1ce20b050000 pid=1291->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 158B guuid=caa26368-1800-0000-8ee3-1ce222050000 pid=1314->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 107B guuid=4f43eb78-1800-0000-8ee3-1ce252050000 pid=1362->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 165B guuid=e3007887-1800-0000-8ee3-1ce279050000 pid=1401->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 114B guuid=1cd7f595-1800-0000-8ee3-1ce2a3050000 pid=1443->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 158B guuid=f0909ca1-1800-0000-8ee3-1ce2b8050000 pid=1464->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 107B guuid=884916ad-1800-0000-8ee3-1ce2d0050000 pid=1488->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 164B guuid=b928e8b6-1800-0000-8ee3-1ce2e0050000 pid=1504->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 113B guuid=11c42bc7-1800-0000-8ee3-1ce211060000 pid=1553->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 158B guuid=4812f3d8-1800-0000-8ee3-1ce23c060000 pid=1596->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 107B guuid=1c4dd5fe-1800-0000-8ee3-1ce293060000 pid=1683->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 158B guuid=a20e1409-1900-0000-8ee3-1ce2ac060000 pid=1708->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 107B guuid=f0898615-1900-0000-8ee3-1ce2ce060000 pid=1742->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 161B guuid=65e77f24-1900-0000-8ee3-1ce2f0060000 pid=1776->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 110B guuid=1f57e836-1900-0000-8ee3-1ce217070000 pid=1815->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 161B guuid=9cf37347-1900-0000-8ee3-1ce23e070000 pid=1854->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 110B guuid=8442af5a-1900-0000-8ee3-1ce267070000 pid=1895->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 161B guuid=d7d4b56a-1900-0000-8ee3-1ce28e070000 pid=1934->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 110B guuid=0359f47a-1900-0000-8ee3-1ce2ba070000 pid=1978->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 157B guuid=57b93289-1900-0000-8ee3-1ce2c9070000 pid=1993->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 106B guuid=fe62239b-1900-0000-8ee3-1ce2d1070000 pid=2001->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 157B guuid=a905a8aa-1900-0000-8ee3-1ce2d7070000 pid=2007->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 106B guuid=9bef66bb-1900-0000-8ee3-1ce2f2070000 pid=2034->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 160B guuid=d0472fc8-1900-0000-8ee3-1ce2ff070000 pid=2047->f773c0d3-dbbc-5349-a7bc-010af40ec8df send: 109B
Verdict:
Malicious
Threat:
Trojan-Downloader.Shell.Agent
Threat name:
Linux.Downloader.Generic
Status:
Suspicious
First seen:
2026-01-20 19:16:19 UTC
File Type:
Text (Shell)
AV detection:
9 of 38 (23.68%)
Threat level:
  3/5
Result
Malware family:
n/a
Score:
  3/10
Tags:
n/a
Behaviour
Modifies registry class
Suspicious use of SetWindowsHookEx
Enumerates physical storage devices
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 09f9fd11a2a48a7703cb3294717b29ff5a5fe49d6ae742c836481756a7779555

(this sample)

  
Delivery method
Distributed via web download

Comments