MalwareBazaar Database

You are currently viewing the MalwareBazaar entry for SHA256 0f7ba6fd0ff64c1115352b8fc30dc36fe8fd5d81154f2f54ac0e00f5fcf8a45f. While MalwareBazaar tries to identify whether the sample provided is malicious or not, there is no guarantee that a sample in MalwareBazaar is malicious.

Database Entry



Threat unknown


Vendor detections: 5


Intelligence 5 IOCs YARA 1 File information Comments

SHA256 hash: 0f7ba6fd0ff64c1115352b8fc30dc36fe8fd5d81154f2f54ac0e00f5fcf8a45f
SHA3-384 hash: a3dbb736c85ca4baff1850e0c7d5496d63338c8f365ae02db0c897eb0c151b6b24faf6dc0a74787a710ed37b514d01bb
SHA1 hash: 02c07f6016c10311b04d09d4db7ea339187c9eec
MD5 hash: b9545ad728f0fed3d7a49ea94dacc9a0
humanhash: minnesota-undress-uranus-oscar
File name:ok
Download: download sample
File size:1'608 bytes
First seen:2026-06-08 09:06:42 UTC
Last seen:2026-06-09 01:17:49 UTC
File type: sh
MIME type:text/x-shellscript
ssdeep 12:5MrrkqDhNtarEWrQrrktKtCrdxZlRorrlRx9tR4rRf3VfzrVf9+grwQQrrxxtCrq:qn1NtA9bobXvQfVkP98bqFS/I
TLSH T13231C9AB5B293B9C5401DDAA73AA2048E460D5CA704FE794FF8C0C7AE5C855C3359B4B
TrID 70.0% (.SH) Linux/UNIX shell script (7000/1)
30.0% (.) Unix-like shebang (var.3) (gen) (3000/1)
Magika shell
Reporter abuse_ch
Tags:sh
URLMalware sample (SHA256 hash)SignatureTags
http://45.205.1.59/b1e187n/an/aelf ua-wget
http://45.205.1.59/626343n/an/aelf ua-wget
http://45.205.1.59/add984n/an/aelf ua-wget
http://45.205.1.59/cab2e5n/an/aelf ua-wget
http://45.205.1.59/ae418an/an/aelf ua-wget
http://45.205.1.59/0cd571n/an/aelf ua-wget
http://45.205.1.59/42ac6cn/an/aelf ua-wget
http://45.205.1.59/964d78n/an/aelf ua-wget
http://45.205.1.59/95d387n/an/aelf ua-wget
http://45.205.1.59/7f1fc5n/an/aelf ua-wget
http://45.205.1.59/5e939dn/an/aelf ua-wget
http://45.205.1.59/c25933n/an/aelf ua-wget

Intelligence


File Origin
# of uploads :
2
# of downloads :
28
Origin country :
DE DE
Vendor Threat Intelligence
No detections
Verdict:
Malicious
Threat level:
  10/10
Confidence:
100%
Tags:
evasive
Status:
terminated
Behavior Graph:
%3 guuid=2d43cba5-2f00-0000-65b9-b7ecff030000 pid=1023 /usr/bin/sudo guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030 /tmp/sample.bin guuid=2d43cba5-2f00-0000-65b9-b7ecff030000 pid=1023->guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030 execve guuid=3e096dc4-2f00-0000-65b9-b7ec09040000 pid=1033 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=3e096dc4-2f00-0000-65b9-b7ec09040000 pid=1033 execve guuid=b53a09e2-2f00-0000-65b9-b7ec5c040000 pid=1116 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=b53a09e2-2f00-0000-65b9-b7ec5c040000 pid=1116 execve guuid=809ce4fe-2f00-0000-65b9-b7eca8040000 pid=1192 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=809ce4fe-2f00-0000-65b9-b7eca8040000 pid=1192 execve guuid=f00d3eff-2f00-0000-65b9-b7ecaa040000 pid=1194 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f00d3eff-2f00-0000-65b9-b7ecaa040000 pid=1194 clone guuid=747580ff-2f00-0000-65b9-b7ecad040000 pid=1197 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=747580ff-2f00-0000-65b9-b7ecad040000 pid=1197 execve guuid=20cfc6ff-2f00-0000-65b9-b7ecaf040000 pid=1199 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=20cfc6ff-2f00-0000-65b9-b7ecaf040000 pid=1199 execve guuid=8ad51b00-3000-0000-65b9-b7ecb1040000 pid=1201 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=8ad51b00-3000-0000-65b9-b7ecb1040000 pid=1201 execve guuid=9fa1f11b-3000-0000-65b9-b7ecfa040000 pid=1274 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=9fa1f11b-3000-0000-65b9-b7ecfa040000 pid=1274 execve guuid=3e1ace37-3000-0000-65b9-b7ec4f050000 pid=1359 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=3e1ace37-3000-0000-65b9-b7ec4f050000 pid=1359 execve guuid=cc9c1038-3000-0000-65b9-b7ec50050000 pid=1360 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=cc9c1038-3000-0000-65b9-b7ec50050000 pid=1360 clone guuid=94486338-3000-0000-65b9-b7ec53050000 pid=1363 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=94486338-3000-0000-65b9-b7ec53050000 pid=1363 execve guuid=1f02cf38-3000-0000-65b9-b7ec55050000 pid=1365 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=1f02cf38-3000-0000-65b9-b7ec55050000 pid=1365 execve guuid=18c02b39-3000-0000-65b9-b7ec56050000 pid=1366 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=18c02b39-3000-0000-65b9-b7ec56050000 pid=1366 execve guuid=455b3155-3000-0000-65b9-b7ec8f050000 pid=1423 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=455b3155-3000-0000-65b9-b7ec8f050000 pid=1423 execve guuid=c2c43d72-3000-0000-65b9-b7ece4050000 pid=1508 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=c2c43d72-3000-0000-65b9-b7ece4050000 pid=1508 execve guuid=6d3c8e72-3000-0000-65b9-b7ece5050000 pid=1509 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=6d3c8e72-3000-0000-65b9-b7ece5050000 pid=1509 clone guuid=dd40c572-3000-0000-65b9-b7ece8050000 pid=1512 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=dd40c572-3000-0000-65b9-b7ece8050000 pid=1512 execve guuid=2cc50f73-3000-0000-65b9-b7ece9050000 pid=1513 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=2cc50f73-3000-0000-65b9-b7ece9050000 pid=1513 execve guuid=de955473-3000-0000-65b9-b7ecea050000 pid=1514 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=de955473-3000-0000-65b9-b7ecea050000 pid=1514 execve guuid=81f3818e-3000-0000-65b9-b7ec44060000 pid=1604 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=81f3818e-3000-0000-65b9-b7ec44060000 pid=1604 execve guuid=04560eab-3000-0000-65b9-b7ecb2060000 pid=1714 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=04560eab-3000-0000-65b9-b7ecb2060000 pid=1714 execve guuid=348956ab-3000-0000-65b9-b7ecb4060000 pid=1716 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=348956ab-3000-0000-65b9-b7ecb4060000 pid=1716 clone guuid=fd068dab-3000-0000-65b9-b7ecb7060000 pid=1719 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=fd068dab-3000-0000-65b9-b7ecb7060000 pid=1719 execve guuid=f8e6dbab-3000-0000-65b9-b7ecb8060000 pid=1720 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f8e6dbab-3000-0000-65b9-b7ecb8060000 pid=1720 execve guuid=5dfc27ac-3000-0000-65b9-b7ecba060000 pid=1722 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=5dfc27ac-3000-0000-65b9-b7ecba060000 pid=1722 execve guuid=fb5604c8-3000-0000-65b9-b7ec07070000 pid=1799 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=fb5604c8-3000-0000-65b9-b7ec07070000 pid=1799 execve guuid=9804e8e4-3000-0000-65b9-b7ec2b070000 pid=1835 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=9804e8e4-3000-0000-65b9-b7ec2b070000 pid=1835 execve guuid=9bac55e5-3000-0000-65b9-b7ec2c070000 pid=1836 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=9bac55e5-3000-0000-65b9-b7ec2c070000 pid=1836 clone guuid=2365c6e5-3000-0000-65b9-b7ec2e070000 pid=1838 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=2365c6e5-3000-0000-65b9-b7ec2e070000 pid=1838 execve guuid=9a3c7be6-3000-0000-65b9-b7ec31070000 pid=1841 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=9a3c7be6-3000-0000-65b9-b7ec31070000 pid=1841 execve guuid=30511be7-3000-0000-65b9-b7ec34070000 pid=1844 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=30511be7-3000-0000-65b9-b7ec34070000 pid=1844 execve guuid=f3e8c103-3100-0000-65b9-b7ec77070000 pid=1911 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f3e8c103-3100-0000-65b9-b7ec77070000 pid=1911 execve guuid=67032421-3100-0000-65b9-b7eca4070000 pid=1956 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=67032421-3100-0000-65b9-b7eca4070000 pid=1956 execve guuid=f5c17221-3100-0000-65b9-b7eca5070000 pid=1957 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f5c17221-3100-0000-65b9-b7eca5070000 pid=1957 clone guuid=f4a0c221-3100-0000-65b9-b7eca8070000 pid=1960 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f4a0c221-3100-0000-65b9-b7eca8070000 pid=1960 execve guuid=2a741022-3100-0000-65b9-b7ecaa070000 pid=1962 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=2a741022-3100-0000-65b9-b7ecaa070000 pid=1962 execve guuid=37fb7922-3100-0000-65b9-b7ecac070000 pid=1964 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=37fb7922-3100-0000-65b9-b7ecac070000 pid=1964 execve guuid=03f2483e-3100-0000-65b9-b7ecd3070000 pid=2003 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=03f2483e-3100-0000-65b9-b7ecd3070000 pid=2003 execve guuid=2d674b5d-3100-0000-65b9-b7ec05080000 pid=2053 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=2d674b5d-3100-0000-65b9-b7ec05080000 pid=2053 execve guuid=a7baac5d-3100-0000-65b9-b7ec07080000 pid=2055 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=a7baac5d-3100-0000-65b9-b7ec07080000 pid=2055 clone guuid=cebaf65d-3100-0000-65b9-b7ec09080000 pid=2057 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=cebaf65d-3100-0000-65b9-b7ec09080000 pid=2057 execve guuid=f4874d5e-3100-0000-65b9-b7ec0b080000 pid=2059 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f4874d5e-3100-0000-65b9-b7ec0b080000 pid=2059 execve guuid=87cea45e-3100-0000-65b9-b7ec0d080000 pid=2061 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=87cea45e-3100-0000-65b9-b7ec0d080000 pid=2061 execve guuid=637ade7a-3100-0000-65b9-b7ec29080000 pid=2089 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=637ade7a-3100-0000-65b9-b7ec29080000 pid=2089 execve guuid=f760499a-3100-0000-65b9-b7ec59080000 pid=2137 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f760499a-3100-0000-65b9-b7ec59080000 pid=2137 execve guuid=f137939a-3100-0000-65b9-b7ec5b080000 pid=2139 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f137939a-3100-0000-65b9-b7ec5b080000 pid=2139 clone guuid=e7accf9a-3100-0000-65b9-b7ec5e080000 pid=2142 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=e7accf9a-3100-0000-65b9-b7ec5e080000 pid=2142 execve guuid=5961209b-3100-0000-65b9-b7ec60080000 pid=2144 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=5961209b-3100-0000-65b9-b7ec60080000 pid=2144 execve guuid=770a6d9b-3100-0000-65b9-b7ec62080000 pid=2146 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=770a6d9b-3100-0000-65b9-b7ec62080000 pid=2146 execve guuid=5df739b7-3100-0000-65b9-b7ec90080000 pid=2192 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=5df739b7-3100-0000-65b9-b7ec90080000 pid=2192 execve guuid=29fec1d6-3100-0000-65b9-b7ecd6080000 pid=2262 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=29fec1d6-3100-0000-65b9-b7ecd6080000 pid=2262 execve guuid=b03e5ad7-3100-0000-65b9-b7ecd9080000 pid=2265 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=b03e5ad7-3100-0000-65b9-b7ecd9080000 pid=2265 clone guuid=f23bbfd7-3100-0000-65b9-b7ecdb080000 pid=2267 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f23bbfd7-3100-0000-65b9-b7ecdb080000 pid=2267 execve guuid=ddc54cd8-3100-0000-65b9-b7ecde080000 pid=2270 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=ddc54cd8-3100-0000-65b9-b7ecde080000 pid=2270 execve guuid=ab8bd3d8-3100-0000-65b9-b7ecdf080000 pid=2271 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=ab8bd3d8-3100-0000-65b9-b7ecdf080000 pid=2271 execve guuid=f6f76bf5-3100-0000-65b9-b7ec27090000 pid=2343 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=f6f76bf5-3100-0000-65b9-b7ec27090000 pid=2343 execve guuid=41a0bc4f-3200-0000-65b9-b7ec43090000 pid=2371 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=41a0bc4f-3200-0000-65b9-b7ec43090000 pid=2371 execve guuid=6cf25050-3200-0000-65b9-b7ec44090000 pid=2372 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=6cf25050-3200-0000-65b9-b7ec44090000 pid=2372 clone guuid=44a8ba50-3200-0000-65b9-b7ec46090000 pid=2374 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=44a8ba50-3200-0000-65b9-b7ec46090000 pid=2374 execve guuid=4c834651-3200-0000-65b9-b7ec47090000 pid=2375 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=4c834651-3200-0000-65b9-b7ec47090000 pid=2375 execve guuid=73acde51-3200-0000-65b9-b7ec48090000 pid=2376 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=73acde51-3200-0000-65b9-b7ec48090000 pid=2376 execve guuid=4d701f6e-3200-0000-65b9-b7ec5d090000 pid=2397 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=4d701f6e-3200-0000-65b9-b7ec5d090000 pid=2397 execve guuid=ea139b8b-3200-0000-65b9-b7ec93090000 pid=2451 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=ea139b8b-3200-0000-65b9-b7ec93090000 pid=2451 execve guuid=046ff28b-3200-0000-65b9-b7ec95090000 pid=2453 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=046ff28b-3200-0000-65b9-b7ec95090000 pid=2453 clone guuid=526d288c-3200-0000-65b9-b7ec97090000 pid=2455 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=526d288c-3200-0000-65b9-b7ec97090000 pid=2455 execve guuid=52438d8c-3200-0000-65b9-b7ec98090000 pid=2456 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=52438d8c-3200-0000-65b9-b7ec98090000 pid=2456 execve guuid=ef0af88c-3200-0000-65b9-b7ec99090000 pid=2457 /usr/bin/wget net send-data guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=ef0af88c-3200-0000-65b9-b7ec99090000 pid=2457 execve guuid=0c986fa8-3200-0000-65b9-b7ecd8090000 pid=2520 /usr/bin/curl net send-data write-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=0c986fa8-3200-0000-65b9-b7ecd8090000 pid=2520 execve guuid=e34932c7-3200-0000-65b9-b7ec1e0a0000 pid=2590 /usr/bin/chmod guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=e34932c7-3200-0000-65b9-b7ec1e0a0000 pid=2590 execve guuid=85cfa0c7-3200-0000-65b9-b7ec200a0000 pid=2592 /usr/bin/bash guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=85cfa0c7-3200-0000-65b9-b7ec200a0000 pid=2592 clone guuid=56f9f5c7-3200-0000-65b9-b7ec230a0000 pid=2595 /usr/bin/rm delete-file guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=56f9f5c7-3200-0000-65b9-b7ec230a0000 pid=2595 execve guuid=4f9463c8-3200-0000-65b9-b7ec250a0000 pid=2597 /usr/bin/rm guuid=885147a8-2f00-0000-65b9-b7ec06040000 pid=1030->guuid=4f9463c8-3200-0000-65b9-b7ec250a0000 pid=2597 execve c66e9db5-1465-5188-8e8d-233eabfef671 45.205.1.59:80 guuid=3e096dc4-2f00-0000-65b9-b7ec09040000 pid=1033->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=b53a09e2-2f00-0000-65b9-b7ec5c040000 pid=1116->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=ccef55ff-2f00-0000-65b9-b7ecab040000 pid=1195 /usr/bin/bash guuid=f00d3eff-2f00-0000-65b9-b7ecaa040000 pid=1194->guuid=ccef55ff-2f00-0000-65b9-b7ecab040000 pid=1195 clone guuid=8ad51b00-3000-0000-65b9-b7ecb1040000 pid=1201->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=9fa1f11b-3000-0000-65b9-b7ecfa040000 pid=1274->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=980c3838-3000-0000-65b9-b7ec52050000 pid=1362 /usr/bin/bash guuid=cc9c1038-3000-0000-65b9-b7ec50050000 pid=1360->guuid=980c3838-3000-0000-65b9-b7ec52050000 pid=1362 clone guuid=18c02b39-3000-0000-65b9-b7ec56050000 pid=1366->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=455b3155-3000-0000-65b9-b7ec8f050000 pid=1423->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=af65a872-3000-0000-65b9-b7ece7050000 pid=1511 /usr/bin/bash guuid=6d3c8e72-3000-0000-65b9-b7ece5050000 pid=1509->guuid=af65a872-3000-0000-65b9-b7ece7050000 pid=1511 clone guuid=de955473-3000-0000-65b9-b7ecea050000 pid=1514->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=81f3818e-3000-0000-65b9-b7ec44060000 pid=1604->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=98ce70ab-3000-0000-65b9-b7ecb5060000 pid=1717 /usr/bin/bash guuid=348956ab-3000-0000-65b9-b7ecb4060000 pid=1716->guuid=98ce70ab-3000-0000-65b9-b7ecb5060000 pid=1717 clone guuid=5dfc27ac-3000-0000-65b9-b7ecba060000 pid=1722->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=fb5604c8-3000-0000-65b9-b7ec07070000 pid=1799->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=642a7ae5-3000-0000-65b9-b7ec2d070000 pid=1837 /usr/bin/bash guuid=9bac55e5-3000-0000-65b9-b7ec2c070000 pid=1836->guuid=642a7ae5-3000-0000-65b9-b7ec2d070000 pid=1837 clone guuid=30511be7-3000-0000-65b9-b7ec34070000 pid=1844->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f3e8c103-3100-0000-65b9-b7ec77070000 pid=1911->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=afaf9121-3100-0000-65b9-b7eca7070000 pid=1959 /usr/bin/bash guuid=f5c17221-3100-0000-65b9-b7eca5070000 pid=1957->guuid=afaf9121-3100-0000-65b9-b7eca7070000 pid=1959 clone guuid=37fb7922-3100-0000-65b9-b7ecac070000 pid=1964->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=03f2483e-3100-0000-65b9-b7ecd3070000 pid=2003->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=d503cb5d-3100-0000-65b9-b7ec08080000 pid=2056 /usr/bin/bash guuid=a7baac5d-3100-0000-65b9-b7ec07080000 pid=2055->guuid=d503cb5d-3100-0000-65b9-b7ec08080000 pid=2056 clone guuid=87cea45e-3100-0000-65b9-b7ec0d080000 pid=2061->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=637ade7a-3100-0000-65b9-b7ec29080000 pid=2089->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=5adeb09a-3100-0000-65b9-b7ec5c080000 pid=2140 /usr/bin/bash guuid=f137939a-3100-0000-65b9-b7ec5b080000 pid=2139->guuid=5adeb09a-3100-0000-65b9-b7ec5c080000 pid=2140 clone guuid=770a6d9b-3100-0000-65b9-b7ec62080000 pid=2146->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=5df739b7-3100-0000-65b9-b7ec90080000 pid=2192->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=fff789d7-3100-0000-65b9-b7ecda080000 pid=2266 /usr/bin/bash guuid=b03e5ad7-3100-0000-65b9-b7ecd9080000 pid=2265->guuid=fff789d7-3100-0000-65b9-b7ecda080000 pid=2266 clone guuid=ab8bd3d8-3100-0000-65b9-b7ecdf080000 pid=2271->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=f6f76bf5-3100-0000-65b9-b7ec27090000 pid=2343->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=19967f50-3200-0000-65b9-b7ec45090000 pid=2373 /usr/bin/bash guuid=6cf25050-3200-0000-65b9-b7ec44090000 pid=2372->guuid=19967f50-3200-0000-65b9-b7ec45090000 pid=2373 clone guuid=73acde51-3200-0000-65b9-b7ec48090000 pid=2376->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=4d701f6e-3200-0000-65b9-b7ec5d090000 pid=2397->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=c2ba088c-3200-0000-65b9-b7ec96090000 pid=2454 /usr/bin/bash guuid=046ff28b-3200-0000-65b9-b7ec95090000 pid=2453->guuid=c2ba088c-3200-0000-65b9-b7ec96090000 pid=2454 clone guuid=ef0af88c-3200-0000-65b9-b7ec99090000 pid=2457->c66e9db5-1465-5188-8e8d-233eabfef671 send: 132B guuid=0c986fa8-3200-0000-65b9-b7ecd8090000 pid=2520->c66e9db5-1465-5188-8e8d-233eabfef671 send: 81B guuid=277dc2c7-3200-0000-65b9-b7ec220a0000 pid=2594 /usr/bin/bash guuid=85cfa0c7-3200-0000-65b9-b7ec200a0000 pid=2592->guuid=277dc2c7-3200-0000-65b9-b7ec220a0000 pid=2594 clone
Threat name:
Document-HTML.Hacktool.Heuristic
Status:
Malicious
First seen:
2026-06-08 09:08:44 UTC
File Type:
Text (Shell)
AV detection:
9 of 36 (25.00%)
Threat level:
  1/5
Result
Malware family:
n/a
Score:
  7/10
Tags:
antivm defense_evasion discovery linux
Behaviour
Reads runtime system information
Writes file to tmp directory
Checks CPU configuration
File and Directory Permissions Modification
Executes dropped EXE
Please note that we are no longer able to provide a coverage score for Virus Total.

YARA Signatures


MalwareBazaar uses YARA rules from several public and non-public repositories, such as YARAhub and Malpedia. Those are being matched against malware samples uploaded to MalwareBazaar as well as against any suspicious process dumps they may create. Please note that only results from TLP:CLEAR rules are being displayed.

Rule name:ach_202412_suspect_bash_script
Author:abuse.ch
Description:Detects suspicious Linux bash scripts

File information


The table below shows additional information about this malware sample such as delivery method and external references.

Web download

sh 0f7ba6fd0ff64c1115352b8fc30dc36fe8fd5d81154f2f54ac0e00f5fcf8a45f

(this sample)

  
Delivery method
Distributed via web download

Comments